Islam-Hacker

PHP Find Admin Page www.is-sec.com by JM511

Dec 18th, 2012
418
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 12.01 KB | None | 0 0
  1. <?php
  2. set_time_limit(0); //JM511 //Greeting //To //www.is-sec.com/vb/
  3. error_reporting(0);
  4. $list['front'] ="admin
  5. adm
  6. admincp
  7. admcp
  8. cp
  9. modcp
  10. ADMINCPCP
  11. admincpcp
  12. adminsec
  13. adm1
  14. adm2
  15. adm4
  16. moderatorcp
  17. adminare
  18. admins
  19. cpanel
  20. admin1.html
  21. admin2.php
  22. admin2.html
  23. yonetim.php
  24. yonetim.html
  25. yonetici.php
  26. yonetici.html
  27. ccms/
  28. ccms/login.php
  29. ccms/index.php
  30. maintenance/
  31. webmaster/
  32. adm/
  33. configuration/
  34. configure/
  35. websvn/
  36. admin/
  37. admin.php
  38. admin.html
  39. admin/cp.php
  40. admin/cp.html
  41. cp.php
  42. cp.html
  43. administrator/
  44. administrator/index.html
  45. administrator/index.php
  46. administrator/login.html
  47. administrator/login.php
  48. administrator/account.html
  49. administrator/account.php
  50. administrator.php
  51. administrator.html
  52. login.php
  53. login.html
  54. modelsearch/login.php
  55. moderator.php
  56. moderator.html
  57. moderator/login.php
  58. moderator/login.html
  59. moderator/admin.php
  60. moderator/admin.html
  61. moderator/
  62. account.php
  63. account.html
  64. controlpanel/
  65. controlpanel.php
  66. controlpanel.html
  67. admincontrol.php
  68. admincontrol.html
  69. adminpanel.php
  70. adminpanel.html
  71. admin1.asp
  72. admin2.asp
  73. yonetim.asp
  74. yonetici.asp
  75. admin/account.asp
  76. admin/index.asp
  77. admin/login.asp
  78. admin/home.asp
  79. admin/controlpanel.asp
  80. admin.asp
  81. admin/cp.asp
  82. cp.asp
  83. administrator/index.asp
  84. administrator/login.asp
  85. administrator/account.asp
  86. administrator.asp
  87. login.asp
  88. modelsearch/login.asp
  89. moderator.asp
  90. sysadmin.php
  91. sysadmin.html
  92. phpmyadmin/
  93. myadmin/
  94. sysadmin.asp
  95. sysadmin/
  96. ur-admin.asp
  97. ur-admin.php
  98. ur-admin.html
  99. ur-admin/
  100. Server.php
  101. Server.html
  102. controlpanel";
  103. $list['end'] = "admin1.php
  104. admin1.html
  105. admin2.php
  106. admin2.html
  107. yonetim.php
  108. yonetim.html
  109. yonetici.php
  110. yonetici.html
  111. ccms/
  112. ccms/login.php
  113. ccms/index.php
  114. maintenance/
  115. webmaster/
  116. adm/
  117. configuration/
  118. configure/
  119. websvn/
  120. admin/
  121. admin/account.php
  122. admin/account.html
  123. admin/index.php
  124. admin/index.html
  125. admin/login.php
  126. admin/login.html
  127. admin/home.php
  128. admin/controlpanel.html
  129. admin/controlpanel.php
  130. admin.php
  131. admin.html
  132. admin/cp.php
  133. admin/cp.html
  134. cp.php
  135. cp.html
  136. administrator/
  137. administrator/index.html
  138. administrator/index.php
  139. administrator/login.html
  140. administrator/login.php
  141. administrator/account.html
  142. administrator/account.php
  143. administrator.php
  144. administrator.html
  145. login.php
  146. login.html
  147. modelsearch/login.php
  148. moderator.php
  149. moderator.html
  150. moderator/login.php
  151. moderator/login.html
  152. moderator/admin.php
  153. moderator/admin.html
  154. moderator/
  155. account.php
  156. account.html
  157. controlpanel/
  158. controlpanel.php
  159. controlpanel.html
  160. admincontrol.php
  161. admincontrol.html
  162. adminpanel.php
  163. adminpanel.html
  164. admin1.asp
  165. admin2.asp
  166. yonetim.asp
  167. yonetici.asp
  168. admin/account.asp
  169. admin/index.asp
  170. admin/login.asp
  171. admin/home.asp
  172. admin/controlpanel.asp
  173. admin.asp
  174. admin/cp.asp
  175. cp.asp
  176. administrator/index.asp
  177. administrator/login.asp
  178. administrator/account.asp
  179. administrator.asp
  180. login.asp
  181. modelsearch/login.asp
  182. moderator.asp
  183. moderator/login.asp
  184. moderator/admin.asp
  185. account.asp
  186. controlpanel.asp
  187. admincontrol.asp
  188. adminpanel.asp
  189. fileadmin/
  190. fileadmin.php
  191. fileadmin.asp
  192. fileadmin.html
  193. administration/
  194. administration.php
  195. administration.html
  196. sysadmin.php
  197. sysadmin.html
  198. phpmyadmin/
  199. myadmin/
  200. sysadmin.asp
  201. sysadmin/
  202. ur-admin.asp
  203. ur-admin.php
  204. ur-admin.html
  205. ur-admin/
  206. Server.php
  207. Server.html
  208. Server.asp
  209. Server/
  210. wp-admin/
  211. administr8.php
  212. administr8.html
  213. administr8/
  214. administr8.asp
  215. webadmin/
  216. webadmin.php
  217. webadmin.asp
  218. webadmin.html
  219. administratie/
  220. admins/
  221. admins.php
  222. admins.asp
  223. admins.html
  224. administrivia/
  225. Database_Administration/
  226. WebAdmin/
  227. useradmin/
  228. sysadmins/
  229. admin1/
  230. system-administration/
  231. administrators/
  232. pgadmin/
  233. directadmin/
  234. staradmin/
  235. ServerAdministrator/
  236. SysAdmin/
  237. administer/
  238. LiveUser_Admin/
  239. sys-admin/
  240. typo3/
  241. panel/
  242. cpanel/
  243. cPanel/
  244. cpanel_file/
  245. platz_login/
  246. rcLogin/
  247. blogindex/
  248. formslogin/
  249. autologin/
  250. support_login/
  251. meta_login/
  252. manuallogin/
  253. simpleLogin/
  254. loginflat/
  255. utility_login/
  256. showlogin/
  257. memlogin/
  258. members/
  259. login-redirect/
  260. sub-login/
  261. wp-login/
  262. login1/
  263. dir-login/
  264. login_db/
  265. xlogin/
  266. smblogin/
  267. customer_login/
  268. UserLogin/
  269. login-us/
  270. acct_login/
  271. admin_area/
  272. bigadmin/
  273. project-admins/
  274. phppgadmin/
  275. pureadmin/
  276. sql-admin/
  277. radmind/
  278. openvpnadmin/
  279. wizmysqladmin/
  280. vadmind/
  281. ezsqliteadmin/
  282. hpwebjetadmin/
  283. newsadmin/
  284. adminpro/
  285. Lotus_Domino_Admin/
  286. bbadmin/
  287. vmailadmin/
  288. Indy_admin/
  289. ccp14admin/
  290. irc-macadmin/
  291. banneradmin/
  292. sshadmin/
  293. phpldapadmin/
  294. macadmin/
  295. administratoraccounts/
  296. admin4_account/
  297. admin4_colon/
  298. radmind-1/
  299. Super-Admin/
  300. AdminTools/
  301. cmsadmin/
  302. SysAdmin2/
  303. globes_admin/
  304. cadmins/
  305. phpSQLiteAdmin/
  306. navSiteAdmin/
  307. server_admin_small/
  308. logo_sysadmin/
  309. server/
  310. database_administration/
  311. power_user/
  312. system_administration/
  313. ss_vms_admin_sm/
  314. adminarea/
  315. bb-admin/
  316. adminLogin/
  317. panel-administracion/
  318. instadmin/
  319. memberadmin/
  320. administratorlogin/
  321. admin/admin.php
  322. admin_area/admin.php
  323. admin_area/login.php
  324. siteadmin/login.php
  325. siteadmin/index.php
  326. siteadmin/login.html
  327. admin/admin.html
  328. admin_area/index.php
  329. bb-admin/index.php
  330. bb-admin/login.php
  331. bb-admin/admin.php
  332. admin_area/login.html
  333. admin_area/index.html
  334. admincp/index.asp
  335. admincp/login.asp
  336. admincp/index.html
  337. webadmin/index.html
  338. webadmin/admin.html
  339. webadmin/login.html
  340. admin/admin_login.html
  341. admin_login.html
  342. panel-administracion/login.html
  343. nsw/admin/login.php
  344. webadmin/login.php
  345. admin/admin_login.php
  346. admin_login.php
  347. admin_area/admin.html
  348. pages/admin/admin-login.php
  349. admin/admin-login.php
  350. admin-login.php
  351. bb-admin/index.html
  352. bb-admin/login.html
  353. bb-admin/admin.html
  354. admin/home.html
  355. pages/admin/admin-login.html
  356. admin/admin-login.html
  357. admin-login.html
  358. admin/adminLogin.html
  359. adminLogin.html
  360. home.html
  361. rcjakar/admin/login.php
  362. adminarea/index.html
  363. adminarea/admin.html
  364. webadmin/index.php
  365. webadmin/admin.php
  366. user.html
  367. modelsearch/login.html
  368. adminarea/login.html
  369. panel-administracion/index.html
  370. panel-administracion/admin.html
  371. modelsearch/index.html
  372. modelsearch/admin.html
  373. admincontrol/login.html
  374. adm/index.html
  375. adm.html
  376. user.php
  377. panel-administracion/login.php
  378. wp-login.php
  379. adminLogin.php
  380. admin/adminLogin.php
  381. home.php
  382. adminarea/index.php
  383. adminarea/admin.php
  384. adminarea/login.php
  385. panel-administracion/index.php
  386. panel-administracion/admin.php
  387. modelsearch/index.php
  388. modelsearch/admin.php
  389. admincontrol/login.php
  390. adm/admloginuser.php
  391. admloginuser.php
  392. admin2/login.php
  393. admin2/index.php
  394. adm/index.php
  395. adm.php
  396. affiliate.php
  397. adm_auth.php
  398. memberadmin.php
  399. administratorlogin.php
  400. admin/admin.asp
  401. admin_area/admin.asp
  402. admin_area/login.asp
  403. admin_area/index.asp
  404. bb-admin/index.asp
  405. bb-admin/login.asp
  406. bb-admin/admin.asp
  407. pages/admin/admin-login.asp
  408. admin/admin-login.asp
  409. admin-login.asp
  410. user.asp
  411. webadmin/index.asp
  412. webadmin/admin.asp
  413. webadmin/login.asp
  414. admin/admin_login.asp
  415. admin_login.asp
  416. panel-administracion/login.asp
  417. adminLogin.asp
  418. admin/adminLogin.asp
  419. home.asp
  420. adminarea/index.asp
  421. adminarea/admin.asp
  422. adminarea/login.asp
  423. panel-administracion/index.asp
  424. panel-administracion/admin.asp
  425. modelsearch/index.asp
  426. modelsearch/admin.asp
  427. admincontrol/login.asp
  428. adm/admloginuser.asp
  429. admloginuser.asp
  430. admin2/login.asp
  431. admin2/index.asp
  432. adm/index.asp
  433. adm.asp
  434. affiliate.asp
  435. adm_auth.asp
  436. memberadmin.asp
  437. administratorlogin.asp
  438. siteadmin/login.asp
  439. siteadmin/index.asp
  440. ADMIN/
  441. paneldecontrol/
  442. login/
  443. cms/
  444. admon/
  445. ADMON/
  446. administrador/
  447. ADMIN/login.php
  448. panelc/
  449. ADMIN/login.html";
  450. function template() {
  451. echo '
  452. <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
  453. <html xmlns="http://www.w3.org/1999/xhtml">
  454. <head>
  455. <meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
  456. <title>Admin page Finder ::JM511:: www.is-sec.com/vb || Islam Security ||</title>
  457. <style type="text/css">
  458. body{
  459.     background: #000;
  460.     margin: 0;
  461.     padding: 0;
  462.     padding-top: 10px;
  463.     color: #FFF;
  464.     font-family: Calibri;
  465.     font-size: 13px;
  466. }
  467. a{
  468.     color: #FFF;
  469.     text-decoration: none;
  470.     font-weight: bold;
  471. }
  472. .wrapper{
  473.     width: 1000px;
  474.     margin: 0 auto;
  475. }
  476. .tube{
  477.     padding: 10px;
  478. }
  479. .red{
  480.     width: 998px;
  481.     border: 1px solid #e52224;
  482.     background: #191919;
  483.     color: #e52224
  484. }
  485. .red input{
  486.     background: #000;
  487.     border: 1px solid #e52224;
  488.     color: #FFF;
  489. }
  490. .blue{
  491.     float: left;
  492.     width: 1000px;
  493.     border: 1px solid #1d7fc3;
  494.     background: #191919;
  495.     color: #1d7fc3;
  496. }
  497. .green{
  498.     float: left;
  499.     width: 1000px;
  500.     border: 1px solid #5fd419;
  501.     background: #191919;
  502.     color: #5fd419;
  503. }
  504. </style>
  505. <script type="text/javascript">
  506. <!--
  507. function insertcode($text, $place, $replace)
  508. {
  509.     var $this = $text;
  510.     var logbox = document.getElementById($place);
  511.     if($replace == 0)
  512.         document.getElementById($place).innerHTML = logbox.innerHTML+$this;
  513.     else
  514.         document.getElementById($place).innerHTML = $this;
  515. //document.getElementById("helpbox").innerHTML = $this;
  516. }
  517. -->
  518. </script>
  519. </head>
  520. <body>
  521. <br />
  522. <br />
  523. <div class="wrapper">
  524. <div class="red">
  525. <div class="tube">
  526. <form action="" method="post" name="xploit_form">
  527. URL:<br /><input type="text" name="xploit_url" value="'.$_POST['xploit_url'].'" style="width: 100%;" /><br /><br />
  528. 404string:<br /><input type="text" name="xploit_404string" value="'.$_POST['xploit_404string'].'" style="width: 100%;" /><br /><br />
  529. <span style="float: right;"><input type="submit" name="xploit_submit" value="go for it" align="right" /></span>
  530. </form>
  531. <br />
  532. </div> <!-- /tube -->
  533. </div> <!-- /red -->
  534. <br />
  535. <div class="green">
  536. <div class="tube" id="rightcol">
  537. Verificat: <span id="verified">0</span> / <span id="total">0</span><br />
  538. Found ones:<br />
  539. </div> <!-- /tube -->
  540. </div> <!-- /green -->
  541. <br clear="all" /><br />
  542. <div class="blue">
  543. <div class="tube" id="logbox">
  544. <br />
  545. <br />
  546. www.is-sec.com || islam security || <br />
  547. </div> <!-- /tube -->
  548. </div> <!-- /blue -->
  549. </div> <!-- /wrapper -->
  550. <br clear="all">';
  551. }
  552. function show($msg, $br=1, $stop=0, $place='logbox', $replace=0) {
  553.     if($br == 1) $msg .= "<br />";
  554.     echo "<script type=\"text/javascript\">insertcode('".$msg."', '".$place."', '".$replace."');</script>";
  555.     if($stop == 1) exit;
  556.     @flush();@ob_flush();
  557. }
  558. function check($x, $front=0) {
  559.     global $_POST,$site,$false;
  560.     if($front == 0) $t = $site.$x;
  561.     else $t = 'http://'.$x.'.'.$site.'/';
  562.     $headers = get_headers($t);
  563.     if (!eregi('200', $headers[0])) return 0;
  564.     $data = @file_get_contents($t);
  565.     if($_POST['xploit_404string'] == "") if($data == $false) return 0;
  566.     if($_POST['xploit_404string'] != "") if(strpos($data, $_POST['xploit_404string'])) return 0;
  567.     return 1;
  568. }
  569.    
  570. // --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
  571. template();
  572. if(!isset($_POST['xploit_url'])) die;
  573. if($_POST['xploit_url'] == '') die;
  574. $site = $_POST['xploit_url'];
  575. if ($site[strlen($site)-1] != "/") $site .= "/";
  576. if($_POST['xploit_404string'] == "") $false = @file_get_contents($site."d65897f5380a21a42db94b3927b823d56ee1099a-this_can-t_exist.html");
  577. $list['end'] = str_replace("\r", "", $list['end']);
  578. $list['front'] = str_replace("\r", "", $list['front']);
  579. $pathes = explode("\n", $list['end']);
  580. $frontpathes = explode("\n", $list['front']);
  581. show(count($pathes)+count($frontpathes), 1, 0, 'total', 1);
  582. $verificate = 0;
  583. foreach($pathes as $path) {
  584.     show('Checking '.$site.$path.' : ', 0, 0, 'logbox', 0);
  585.     $verificate++; show($verificate, 0, 0, 'verified', 1);
  586.     if(check($path) == 0) show('not found', 1, 0, 'logbox', 0);
  587.     else{
  588.         show('<span style="color: #00FF00;"><strong>found</strong></span>', 1, 0, 'logbox', 0);
  589.         show('<a href="'.$site.$path.'">'.$site.$path.'</a>', 1, 0, 'rightcol', 0);
  590.     }
  591. }
  592. preg_match("/\/\/(.*?)\//i", $site, $xx); $site = $xx[1];
  593. if(substr($site, 0, 3) == "www") $site = substr($site, 4);
  594. foreach($frontpathes as $frontpath) {
  595.     show('Checking http://'.$frontpath.'.'.$site.'/ : ', 0, 0, 'logbox', 0);
  596.     $verificate++; show($verificate, 0, 0, 'verified', 1);
  597.     if(check($frontpath, 1) == 0) show('not found', 1, 0, 'logbox', 0);
  598.     else{
  599.         show('<span style="color: #00FF00;"><strong>found</strong></span>', 1, 0, 'logbox', 0);
  600.         show('<a href="http://'.$frontpath.'.'.$site.'/">'.$frontpath.'.'.$site.'</a>', 1, 0, 'rightcol', 0);
  601.     }
  602.    
  603. }
  604. ?>
Add Comment
Please, Sign In to add comment