Well,this article should be read by N00BZ only!
Here are some steps you could follow in order to find hacked servers with phpshell backdoors hosted in it , and to upload Rapidleech script on the hacked servers by yourself.
1.finding phpshell backdoors
There are many kinds of phpshells out there , and what we are gonna do is to find them using some Google Dorks
. Based on my own experiences, the most powerful google dork syntax to find those phpshells is by using “allintext” syntax , which will simply grab any sites with your desired text on its content. If you’ve been familiar enough with phpshells , you must have known what ’s the main characteristic on phpshells themselves , you should know what kind of texts should be appeared on phpshells
. Just let’s go straight to the dork :
*To get more complete services of Rapidleech and Rapidshare Premium Account , you can go here : WWW.XDFG.NET for a full version of the rapidleech list !*
allintext:”Safe-mode: OFF (not secure)”
The google dork above will find any type of phpshells , c99 , r57 , or even c100 ?
you’ll simply get ‘em all
And of course, it’s not the only way to get phpshells by google dorking , there are still many working google dorks to find those shits
, just be creative , okay ? ![]()
2.Upload the script!
Just go get yourself rapidleech script , which can be downloaded on www.rapidleech.com. You’ll get it downloaded as *.zip or *.rar files. Since most of phpshells hosted in hacked *nix servers , it means you can’t extract *.zip/*rar there. The recognized compressed archive filetype in *nix should be *.tar , *.tar.gz or *.tar.bz2. So , all you have to do is extract the *.zip/*.rar files , and then convert it back to *.tar files .If you don’t know how to do it , just go get yourself a guide to Linux command lines ..LOL
After you get yourself the rapidleech.tar file , now you should explore the phpshells you just already got. In order to get your script uploaded , you must find any directory with 777 permissions on it (as long as it’s still under webserver’s directory) , which means it enables you to read,write, and execute scripts on it. You can find them by using the linux command :
find / -type d -perm 777
Then you’ll get the list of any writable directories! And then change your current working directory to the directory with 777 permission on it(eg. /var/wwwroot/hacked.com/hacked_dir/). And then upload your rapidleech.tar ! and get it extracted ! ![]()
Now you could access your rapidleech on www.hacked.com/hacked_dir/ . It’s just that simple.
Rapidleech : how to create your own private rapidleechers using hacked server is posted on September 22nd, 2007 by admin. This post is filed under: Security, Tutorial, google dorks, Hacking, how to, RapidLeechs, RapidShare, Security, tutorials, Web Hacking .
Some people come to this post with this search term: rapidleech server, rapidleech, rapidleech tutorial, rapidleech script, free rapidleech server, how to make rapidleech, Rapidleech List, rapidleech linux, tutorial rapidleech, Rapidleech 2008, rapidleech premium, rapidleech upload, rapidleech hack, r57 download shell, rapidleechers, rapidleech guide, private rapidleech, how to make rapidleech server, rapidleech password, hack friendster password,
And here is the related entries of this post:
hmm.,, cool as always dude
What a day! Anyway, hello. Nice blog posting about ech : how to create your own private rapidleechers using hacked server | LifeDork. I would have to agree with you on this one. I am going to look more into how to create a website. This Monday I have time.
Hi from the Design World! Nice blog posting about ech : how to create your own private rapidleechers using hacked server | LifeDork. I would have to agree with you on this one. I am going to look more into create a website. This Friday I have time.
[...] read more | digg story [...]
Nice trick
However, there is a small thing that i need to point: you say that *nix servers don’t deal with ZIP-files. That’s false: almost every webserver that i’ve seen has the “unzip” tool, it installs by default in most distros. Also, i’ve experienced in some servers that you can’t unTAR files, so unzip is the way to go…
Resuming: Get RapidLeech (it’s RARed) -> ZIP it -> upload -> unZIP -> (protect - optional) -> F.U. MegaShit :p
Also, TAKE CARE OF YOUR PHPSHELL! Some other “google hackers” can kill your RapidLeech if you leave the script wide open. Try to move the shell elsewhere (if you have permissions to do so), or try to hide your RapidLeech as best as you can do (some hostings are SO BADLY SECURED that you can reach another domains from a single shell!!!). Losing 2 gigs of downloads due to a script kiddie is NOT fun!
Tom : Yeah , sorry my bad , dude.
invisible.
that’s why i always make my rapidleech private , and uncrawled by googlebot or something else.
if the server of the target is using windows, how to get it upload, I always get this error message : Error uploading file user.zip (can’t copy “C:WINDOWSTempphp11F.tmp” to “C:\Inetpub\vhosts\bagcilargorelilerdernegi.com\httpdocs\usr\local\user.zip”
oh user.zip is my rapidleech compressed file
I’ve tried with the user.tar.gz but it doesn’t work and I got the same error
@olis : it should be like the usual way when it works for Linux , maybe it’s the permission problem bro .
just look for some other writable directories.
yeah i create this rapidleech system with my own modification. you can check and use it at http://www.rapidhelp.us.
is this for real noobs or advanced noobs? i just realized what to search! but i don’t understand where to upload the files and how to it (in windows xp). anybody can help me please?
@rapidhelp : thanks
@mia : you can do it from windows xp too , there’s nothing to do with it actually
Thank you lain, I finally got it!
Nice tutorial dude,
Also check out Rapidleech @ 100mbps of speed
Visit: http://www.stuffloaded.org/rs