Cara Scan Website yang Ada Backdoornya - Script ini akan menscan file2 yang ada di root yang di curigai atau berpotensi sebagai shell
#!/usr/bin/php
array(“c999shexit();”, “setcookie(\”c999sh_surl\”);”, “c999_buff_prepare();”),
“c100″ => array(“\$back_connect_c=\”f0VMRgEBAQA”, “function myshellexec(\$command) {“, “tEY87ExcilDfgAMhwqM74s6o”),
“r57″ => array(“if(strpos(ex(\”echo abcr57\”),\”r57\”)!=3)”, “function ex(\$cfe)”, “\$port_bind_bd_c=\”I2luY2x1ZGUg”),
“erne”=> array(“function unix2DosTime(\$unixtime = 0)”, “eh(\$errno, \$er”, “\$mtime=@date(\”Y-m-d H:i:s\”,@filemti”),
“Safe_Over” => array(“function walkArray(\$array){“, “function printpagelink(\$a, \$b, \$link = \”\”)”, “if (\$cmd != \”downl\”)”),
“cmd_asp” => array(” ‘ — Read th”, “ll oFileSys.D”, “Author: Maceo”)
);
//the script work
$euristic_active = true;
$euristic_sens = 40;
for ($i = 1; $i “.$file.”\tprobably “.$shell.” shell\n”;
}
else if ($euristic_active)
if ($t = check_euristic($l) and $t > $euristic_sens)
{
echo “[_ALERT] euristic $t%> “.$file.”\tprobably is a shell\n”;
}
}
else
{
echo “i can’t open $file file\n”;
}
}
function check($string)
{
$check = 0;
global $word__;
foreach($word__ as $shell => $code)
foreach($code as $microcode)
if (stripos($string, $microcode) !== false)
{
$check ++;
if ($check == 3) return $shell;
}
return false;
}
function check_euristic($string)
{
global $euristic__;
$check = 0;
foreach($euristic__ as $code)
if (stripos($string, $code) !== false)
$check++;
return intval(($check * 100) / count($euristic__));
}
function help($me)
{
echo “indonesianhacker shell scanner\n”.
“$me {-e [euristic method default = Y] Y/N -p [[0-100] euristic sensibility fewer == most feeble ] [-d [directory] / -f [file] ]}\n”.
“exemple: $me -e N -d /tmp\n”
;
exit;
}
?>
simpan dengan nama amankan.php atau terserah anda
coba urlnya http://situsanda/amankan.php
Terus anda bisa lihat hasilnya
nb : berfungsi pada folder dimana dia ditempatkan dan tidak jalan pada server windows. (IIS)
sumber : http://blog.seneng.web.id/scan-file-file-backdoor-di-directory-web-anda.html
Rating: 5
{ 0 komentar... read them below or add one }
Posting Komentar
Blog Ini Bersifat Do Follow yg Berarti dpt Memberikan Backlink Gratis Kpd Blog Anda Jika Berkomentar Dibawah ini :
"Komentar Harus Bersifat Membangun Dan Tidak Menjatuhkan akan Kami Hargai"