Skip to content

Instantly share code, notes, and snippets.

@tranphuoctien
Created March 24, 2022 02:41
Show Gist options
  • Save tranphuoctien/392cebad5711a794ae5d1ae2587397e2 to your computer and use it in GitHub Desktop.
Save tranphuoctien/392cebad5711a794ae5d1ae2587397e2 to your computer and use it in GitHub Desktop.
Joomla scaner shell
<?php ${"\x47L\x4fB\x41L\x53"}["t\x78\x73\x67\x71v\x69\x65\x6dp"]="\x70\x6fst";${"\x47\x4cO\x42\x41\x4c\x53"}["\x65\x64\x65\x68\x67l\x72\x62\x62\x6e\x61\x79"]="so\x75\x72\x63\x65";${"\x47\x4cO\x42A\x4c\x53"}["\x77\x78\x67j\x66\x70\x68p\x75"]="i";${"\x47L\x4f\x42\x41L\x53"}["\x76\x6f\x6by\x64ligw\x63\x6d"]="\x63ur\x6c";${"G\x4c\x4fB\x41\x4cS"}["\x78v\x70\x77\x66\x74"]="\x75r\x6c";${"G\x4c\x4f\x42AL\x53"}["\x78\x69s\x79\x64\x75\x6c\x62"]="l\x69\x6e\x6b";function jos_site($site){$jweflryhxm="\x73\x69t\x65";$hrguelbpg="\x73i\x74\x65";return(eregi("op\x74\x69\x6fn",${$hrguelbpg}))?preg_replace("\x23(\x2e*?)/\x69\x6e\x64e\x78\x2ep\x68p(.*)\x23","\$\x31/",${$jweflryhxm}):false;}${"\x47\x4c\x4f\x42AL\x53"}["\x6b\x70e\x75\x6bm\x6bhc"]="a\x6clL\x69\x6ek\x73";function bing($what,$mode=false){$vocuuer="\x69";for(${${"\x47L\x4f\x42\x41\x4c\x53"}["w\x78\x67j\x66\x70h\x70u"]}=1;${$vocuuer}<=2000;${${"\x47\x4cOB\x41\x4c\x53"}["\x77\x78\x67j\x66\x70h\x70\x75"]}+=10){${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x6f\x79l\x79n\x68jl\x6d"]="\x73\x6f\x75\x72c\x65";${"\x47\x4c\x4f\x42\x41\x4c\x53"}["er\x67\x74\x77\x7ab\x63\x6b\x65\x76"]="\x73\x6f\x75\x72\x63e";$mcmcgn="\x6c\x69\x6ek\x73";${"\x47\x4c\x4fBALS"}["\x73\x74ne\x75q\x71\x69"]="\x77\x68\x61\x74";$fvavgpnv="l\x69nk\x73";$vzmvrwx="\x61l\x6c\x4c\x69nks";$imytefki="s\x6f\x75\x72\x63e";$jltgljvd="\x6cin\x6b";$jsqdqsd="m\x6fd\x65";${${"\x47\x4c\x4fB\x41L\x53"}["\x65r\x67\x74\x77\x7a\x62\x63\x6bev"]}=source("http://\x77w\x77.b\x69n\x67\x2e\x63o\x6d/sea\x72\x63\x68?q\x3d".str_replace(" ","+",${${"G\x4c\x4f\x42\x41L\x53"}["s\x74\x6e\x65\x75\x71q\x69"]})."\x26first=$i");preg_match_all("#<\x64\x69\x76 c\x6cas\x73\x3d\x22s\x62\x5ftlst\x22\x3e.*\x3ch3>\x2e*\x3c\x61 h\x72\x65f=\"(.*)\".*\x3e(\x2e*)\x3c/a\x3e\x2e*</\x683>.*</di\x76>\x23\x73i\x55",${$imytefki},${$mcmcgn});foreach(${$fvavgpnv}[1]as${$jltgljvd})${$vzmvrwx}[]=(${$jsqdqsd})?"\x68\x74t\x70://".parse_url(${${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x78\x69s\x79\x64\x75\x6c\x62"]},PHP_URL_HOST)."/":${${"\x47\x4c\x4f\x42A\x4c\x53"}["x\x69\x73\x79d\x75l\x62"]};if(!preg_match("/fi\x72st\x3d".(${${"GL\x4f\x42\x41L\x53"}["\x77\x78g\x6afp\x68\x70\x75"]})."/",${${"\x47LO\x42A\x4c\x53"}["\x6f\x79\x6cyn\x68j\x6cm"]}))break;}return array_unique(${${"\x47LO\x42\x41\x4c\x53"}["kp\x65\x75\x6b\x6d\x6bh\x63"]});}function source($url,$post=false,$flw=0){$uzloyjg="\x63ur\x6c";${${"\x47L\x4f\x42\x41L\x53"}["\x76\x6f\x6b\x79\x64\x6c\x69g\x77\x63m"]}=curl_init();${"\x47\x4cO\x42\x41L\x53"}["\x75\x64\x65y\x72\x6cak"]="\x63u\x72\x6c";(preg_match("/\x68t\x74\x70\x73/",${${"\x47\x4c\x4fB\x41LS"}["x\x76\x70\x77\x66\x74"]}))?curl_setopt(${${"G\x4cOB\x41\x4cS"}["v\x6f\x6b\x79\x64\x6c\x69g\x77\x63m"]},CURLOPT_SSL_VERIFYPEER,false):"";${"GL\x4fB\x41L\x53"}["q\x79b\x6ft\x6e\x74\x6b\x66n\x64"]="\x63u\x72l";$yvirwsiqpq="curl";${"G\x4c\x4f\x42\x41LS"}["\x6c\x69f\x72\x66\x71\x71\x62\x64\x6a"]="u\x72\x6c";curl_setopt(${$uzloyjg},CURLOPT_RETURNTRANSFER,1);curl_setopt(${${"\x47LO\x42\x41LS"}["\x71\x79\x62\x6f\x74\x6e\x74k\x66n\x64"]},CURLOPT_URL,${${"\x47\x4c\x4fBA\x4c\x53"}["\x6c\x69\x66\x72f\x71\x71bdj"]});${"\x47\x4c\x4f\x42A\x4c\x53"}["\x6dh\x6b\x75\x6b\x71\x7aw\x66"]="\x63\x75r\x6c";${"\x47\x4cO\x42\x41L\x53"}["c\x6d\x6au\x62\x76\x78"]="\x66\x6cw";$oglbhsck="\x63\x75\x72\x6c";curl_setopt(${${"GL\x4fBA\x4c\x53"}["\x6d\x68\x6b\x75k\x71z\x77\x66"]},CURLOPT_HEADER,1);curl_setopt(${${"GL\x4f\x42\x41\x4cS"}["\x75d\x65yrl\x61\x6b"]},CURLOPT_USERAGENT,"\x4d\x6f\x7aill\x61/\x35.0 (W\x69ndows \x4eT\x205.\x31;\x20rv:\x32\x2e\x30\x2e\x31)\x20G\x65ck\x6f/\x32\x301\x3001\x301\x20\x46ir\x65\x66\x6f\x78/4\x2e0.1 \x44\x7aC\x55RL 😊");curl_setopt(${${"\x47\x4cO\x42\x41LS"}["\x76ok\x79d\x6c\x69gw\x63m"]},CURLOPT_FOLLOWLOCATION,${${"\x47\x4c\x4f\x42\x41\x4cS"}["\x63mjub\x76\x78"]});if(${${"\x47\x4c\x4f\x42\x41LS"}["txs\x67\x71v\x69\x65\x6d\x70"]}){$ceqglxrm="\x70\x6f\x73t";curl_setopt(${${"\x47\x4c\x4fB\x41\x4c\x53"}["\x76o\x6b\x79\x64\x6ci\x67\x77\x63m"]},CURLOPT_POST,1);
curl_setopt(${${"G\x4c\x4f\x42A\x4c\x53"}["v\x6fk\x79\x64\x6c\x69\x67w\x63\x6d"]},CURLOPT_POSTFIELDS,${$ceqglxrm});}${${"G\x4c\x4f\x42\x41\x4c\x53"}["e\x64e\x68g\x6c\x72b\x62\x6e\x61\x79"]}=curl_exec(${$oglbhsck});curl_close(${$yvirwsiqpq});
return${${"GL\x4f\x42\x41\x4c\x53"}["\x65\x64\x65\x68\x67\x6c\x72bbnay"]};}
echo "\x3cht\x6dl>\n<h\x65a\x64>\n\x3c/s\x63\x72\x69pt>\n\x3ctit\x6c\x65>Joo\x6d\x6ca \x53e\x72\x76er\x20Sc\x61n\x6ee\x72</tit\x6ce\x3e\n<c\x65\x6e\x74er\x3e\n\x3cimg\x20\x73r\x63=\x22h\x74t\x70://i.\x69\x6dgu\x72.com/s\x6b\x4e\x555.j\x70\x67\x22\x3e\x3cbr>\n<me\x74\x61 h\x74tp-\x65q\x75i\x76\x3d\x22Co\x6et\x65n\x74-\x54\x79pe\"\x20c\x6fnt\x65\x6et\x3d\"te\x78\x74/h\x74ml\x3b\x20ch\x61\x72\x73\x65\x74=\x55\x54\x46-8\">\n<\x53\x54\x59L\x45>\ntexta\x72ea{b\x61c\x6bg\x72o\x75\x6e\x64-\x63olor:\x231\x30\x3570\x30\x3b\x63\x6flo\x72:lime\x3b\x66o\x6et-\x77\x65\x69g\x68t:\x62\x6fl\x64;fo\x6e\x74-\x73ize:\x202\x30px\x3b\x66\x6f\x6et-fam\x69ly: T\x61\x68o\x6d\x61;\x20borde\x72: \x31\x70x solid\x20\x23\x30\x30\x300\x30\x30\x3b}\ninput{\x46\x4fN\x54-W\x45IG\x48T:\x6eo\x72\x6d\x61l\x3bb\x61\x63kg\x72oun\x64-c\x6f\x6c\x6f\x72: \x23\x31\x30\x357\x300;f\x6f\x6e\x74-\x73\x69\x7a\x65:\x2015\x70x;fo\x6et-we\x69ght:bol\x64\x3bc\x6fl\x6f\x72: li\x6de\x3b\x20fo\x6et-fami\x6cy: T\x61h\x6fm\x61;\x20bord\x65r: \x31px \x73o\x6c\x69\x64\x20\x23\x36\x366\x366\x36;\x68\x65i\x67h\x74:20}\n\n\n\n\n\x62\x6f\x64\x79 {\nf\x6f\x6e\x74-f\x61\x6di\x6cy: \x54\x61ho\x6da\n}\n\x74\x72 {\nBO\x52\x44\x45\x52: \x64a\x73\x68\x65\x64 \x31\x70\x78\x20#\x333\x33\x3b\nco\x6c\x6f\x72:\x20\x23\x46\x46F;\n}\n\x74\x64 {\n\x42\x4fR\x44\x45R:\x20d\x61\x73\x68ed \x31px\x20\x23\x33\x333\x3b\n\x63\x6fl\x6fr:\x20\x23FF\x46\x3b\n}\n.\x74\x61b\x6c\x65\x31 {\nBO\x52\x44ER:\x20\x30\x70\x78\x20\x42\x6ca\x63\x6b\x3b\n\x42AC\x4bGRO\x55\x4e\x44-\x43OL\x4fR:\x20\x42l\x61\x63k\x3b\nc\x6fl\x6f\x72: #F\x46\x46\x3b\n}\n\x2etd\x31\x20{\n\x42OR\x44\x45R:\x20\x30\x70\x78\x3b\n\x42\x4f\x52D\x45R-\x43\x4f\x4c\x4fR: #3\x33\x33333;\nf\x6fnt:\x207p\x74 Verdana\x3b\n\x63o\x6c\x6f\x72: G\x72\x65e\x6e;\n}\n\x2e\x74\x721\x20{\nBO\x52DE\x52:\x200\x70\x78;\nBO\x52D\x45R-COLOR: #33\x33\x333\x33\x3b\n\x63\x6flo\x72: \x23\x46\x46F\x3b\n}\n\x74\x61\x62\x6ce {\n\x42ORD\x45R: d\x61\x73\x68\x65d\x201px\x20\x23\x33\x333;\nB\x4fRD\x45\x52-COL\x4fR:\x20\x23\x333\x33\x333\x33;\n\x42A\x43K\x47R\x4fU\x4e\x44-C\x4f\x4c\x4fR: \x42l\x61ck\x3b\nc\x6f\x6co\x72: #\x46FF\x3b\n}\ni\x6e\x70u\x74 {\nb\x6frder\t\t\t: \x64\x61she\x64\x201\x70\x78;
\nb\x6f\x72\x64e\x72-\x63o\x6c\x6f\x72\t\t:\x20\x2333\x33;\n\x42\x41C\x4b\x47\x52\x4f\x55\x4eD-\x43O\x4c\x4fR: \x42l\x61\x63k;\n\x66ont:\x20\x38pt\x20Ver\x64\x61\x6ea\x3b\nco\x6cor: Red;\n}\n\x73el\x65\x63t {\nB\x4f\x52DER-\x52\x49\x47HT: B\x6c\x61\x63k 1p\x78 \x73oli\x64\x3b\n\x42ORD\x45R-T\x4fP:\x20\x20 #D\x460\x30\x300 1p\x78\x20sol\x69d\x3b\nBOR\x44ER-L\x45\x46\x54:\x20\x20 #D\x46\x300\x30\x30\x201\x70x\x20solid\x3b\n\x42OR\x44E\x52-BOTT\x4fM: Blac\x6b\x201px so\x6c\x69\x64;\nBOR\x44ER-c\x6fl\x6fr: #F\x46F\x3b\n\x42A\x43KGRO\x55N\x44-\x43\x4fLO\x52:\x20\x42\x6cac\x6b;\nf\x6f\x6e\x74: \x38pt \x56e\x72\x64\x61na\x3b\n\x63olor: Re\x64\x3b\n}\n\x73\x75\x62mi\x74 {\nBORDER:\x20 b\x75\x74\x74o\x6e\x68i\x67\x68\x6ci\x67\x68\x74\x20\x32p\x78\x20ou\x74se\x74\x3b\n\x42\x41\x43\x4b\x47\x52\x4fUN\x44-CO\x4cO\x52:\x20Bl\x61\x63k\x3b\n\x77\x69d\x74h:\x2030%;\nc\x6fl\x6fr:\x20#F\x46F;\n}\n\x74\x65\x78\x74\x61\x72e\x61\x20{\n\x62o\x72\x64er\t\t\t:\x20\x64a\x73he\x64\x20\x31\x70x #\x3333\x3b\nBA\x43\x4b\x47\x52OU\x4eD-\x43O\x4c\x4f\x52:\x20B\x6c\x61c\x6b;\nf\x6fnt:\x20F\x69\x78ed\x73ys\x20b\x6fl\x64;\ncolo\x72: \x23\x3999;\n}\nBO\x44Y {\n\tSC\x52O\x4c\x4cB\x41\x52-\x46\x41\x43\x45-\x43\x4fLOR:\x20\x42\x6ca\x63k\x3b \x53\x43\x52OLL\x42\x41\x52-\x48IG\x48\x4cI\x47HT-c\x6f\x6co\x72: \x23\x46FF; \x53C\x52OL\x4cB\x41\x52-SH\x41\x44OW-\x63\x6f\x6c\x6f\x72: #\x46\x46F\x3b\x20\x53C\x52O\x4cLBA\x52-3DL\x49\x47\x48\x54-\x63o\x6c\x6fr:\x20#F\x46F;\x20SCR\x4fLL\x42\x41\x52-\x41\x52R\x4fW-\x43OL\x4f\x52: B\x6c\x61ck; SC\x52OL\x4c\x42AR-TR\x41C\x4b-color:\x20#\x46\x46F; SCR\x4fL\x4c\x42\x41R-\x44A\x52\x4bSHA\x44\x4f\x57-co\x6c\x6f\x72:\x20\x23\x46\x46F\nm\x61r\x67i\x6e:\x20\x31\x70\x78\x3b\ncol\x6fr: Red;\nba\x63\x6bg\x72o\x75n\x64-col\x6fr:\x20B\x6c\x61\x63k;\n}\n.m\x61\x69n\x20{\nm\x61\x72gin\t\t\t: -\x3287\x70x \x30\x70x \x30\x70x\x20-490\x70x\x3b\n\x42O\x52\x44\x45\x52: d\x61\x73he\x64\x201px\x20#\x33\x333\x3b\nBOR\x44E\x52-\x43\x4fLO\x52: \x2333\x333\x33\x33;\n}\n.\x74t\x20{\nbac\x6b\x67ro\x75nd-c\x6fl\x6f\x72:\x20Black\x3b\n}\n\nA:li\x6e\x6b\x20{\n\tC\x4f\x4cOR:\x20\x57h\x69te\x3b\x20\x54\x45XT-D\x45\x43O\x52\x41\x54I\x4fN:\x20n\x6f\x6e\x65\n}\n\x41:vi\x73\x69\x74e\x64\x20{\n\t\x43O\x4c\x4f\x52:\x20Whit\x65\x3b\x20T\x45\x58T-\x44EC\x4f\x52\x41T\x49ON:\x20n\x6f\x6e\x65\n}\nA:hov\x65r\x20{\n\tco\x6c\x6f\x72:\x20\x52ed; \x54\x45XT-\x44\x45\x43\x4fR\x41TIO\x4e: n\x6fn\x65\n}\nA:ac\x74\x69\x76\x65\x20{\n\t\x63olo\x72: R\x65\x64\x3b\x20TE\x58T-\x44E\x43ORAT\x49O\x4e:\x20\x6e\x6fne\n}\n</S\x54\x59\x4c\x45>\n\x3c\x73c\x72ip\x74 \x6canguag\x65=\x5c'j\x61vasc\x72\x69p\x74\\'>\nf\x75nc\x74\x69\x6f\x6e\x20hide_d\x69\x76(id)\n{\n \x20docum\x65\x6e\x74.g\x65\x74\x45l\x65\x6d\x65n\x74By\x49d(i\x64)\x2est\x79l\x65\x2ed\x69\x73play \x3d \\'no\x6e\x65\x5c'\x3b\n \x20doc\x75ment.\x63oo\x6bi\x65=\x69d+\\\x27=\x30\x3b\\'\x3b\n}\nf\x75\x6e\x63t\x69\x6fn sh\x6f\x77\x5fdiv(\x69\x64)\n{\n \x20docu\x6d\x65\x6et\x2e\x67et\x45\x6ce\x6de\x6e\x74B\x79\x49\x64(i\x64).style.\x64\x69\x73\x70\x6cay\x20\x3d\x20\x5c'\x62loc\x6b\\'\x3b\n \x64o\x63\x75\x6de\x6e\x74.\x63o\x6f\x6b\x69e=\x69\x64+\\\x27=\x31\x3b\x5c\x27;\n}\nf\x75\x6e\x63\x74\x69\x6fn\x20c\x68an\x67e\x5fd\x69\x76\x73t(i\x64)\n{\n\x20\x20i\x66 (document\x2e\x67e\x74\x45le\x6de\x6et\x42y\x49d(\x69d)\x2e\x73\x74\x79l\x65\x2ed\x69s\x70\x6cay\x20\x3d\x3d \x5c\x27n\x6f\x6e\x65\x5c')\n \x20 \x73\x68ow_\x64\x69v(i\x64);\n e\x6cse\n \x20\x20\x20\x68i\x64\x65\x5f\x64i\x76(\x69\x64)\x3b\n}\n</s\x63rip\x74>\n<h\x74ml>\n\t<\x68\x65\x61d>\n\n\x3c\x66o\x72\x6d\x20\x61cti\x6fn=\x27'\x20me\x74\x68od='G\x45T'\x3e\nIP : \x3c\x69\x6epu\x74\x20type\x3d\x27\x74ex\x74\x27\x20nam\x65\x3d\x27i\x70'\x20\x76\x61l\x75\x65='";${"G\x4c\x4f\x42\x41\x4c\x53"}["\x68ad\x6e\x79iz\x71\x72"]="\x73i\x74\x65\x73";${"\x47\x4c\x4f\x42\x41\x4cS"}["w\x6c\x62\x75\x6do\x77se"]="\x73\x69\x74e";
${"G\x4c\x4f\x42ALS"}["\x69\x74l\x79\x79i\x62"]="\x61\x6c\x6c\x73\x69\x74\x65s";echo $_GET["ip"];echo "\x27\x3e\x20<\x69\x6e\x70u\x74\x20t\x79p\x65\x3d's\x75b\x6d\x69t\x27 va\x6cu\x65\x3d'Get Joomla\x20\x53it\x65\x73 !\x27 /\x3e\n\x3c/f\x6f\x72\x6d>\n";if(isset($_GET["i\x70"])){$qmfbmslem="s\x69\x74\x65s";$tmthtket="site\x73";${"\x47LOB\x41\x4c\x53"}["\x63v\x6d\x71\x72\x68"]="\x61ll\x73i\x74e\x73";$gkuxgliry="\x61\x6cls\x69t\x65\x73";${$qmfbmslem}=bing("i\x70:{$_GET['ip']}+\x69n\x64\x65x.p\x68\x70?o\x70\x74\x69\x6f\x6e=co\x6d");${$tmthtket}=array_filter(array_unique(array_map("jo\x73_\x73\x69\x74\x65",${${"\x47\x4cO\x42\x41\x4c\x53"}["h\x61\x64n\x79\x69\x7a\x71\x72"]})));foreach(${${"\x47LO\x42A\x4c\x53"}["\x68\x61\x64\x6e\x79\x69z\x71r"]} as${${"G\x4c\x4f\x42AL\x53"}["\x77\x6c\x62\x75\x6d\x6f\x77se"]}){${"\x47\x4cO\x42\x41\x4c\x53"}["\x6d\x6a\x64\x64\x68e\x69"]="sit\x65";${${"\x47\x4cO\x42\x41\x4c\x53"}["\x69\x74\x6cy\x79\x69\x62"]}[]=str_replace("ww\x77.","",${${"G\x4cOBA\x4c\x53"}["mj\x64\x64\x68\x65\x69"]});}${$gkuxgliry}=array_filter(array_unique(${${"\x47L\x4fBA\x4c\x53"}["\x69\x74\x6c\x79\x79\x69\x62"]}));${"\x47\x4c\x4f\x42\x41L\x53"}["\x67o\x66\x62\x75\x6b\x67bp\x70l"]="\x61\x6c\x6c\x73\x69t\x65s";echo"[-] Si\x74\x65s\x20\x46\x6f\x75n\x64\x20: [\x20".count(${${"\x47LO\x42\x41L\x53"}["\x63vmq\x72h"]})." ]\x3cbr\x3e\x3c\x62\x72\x3e";echo"\x3c\x74e\x78tar\x65a \x63ol\x73\x3d'\x380\x27\x20\x72ows\x3d'\x31\x30'>".implode("\n",${${"\x47\x4c\x4f\x42A\x4c\x53"}["g\x6f\x66\x62\x75\x6b\x67\x62\x70\x70\x6c"]})."\x3c/t\x65\x78\x74area\x3e";}
?>
@tranphuoctien
Copy link
Author

Something like this.
image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment