Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- <?php
- $secret = '<img src="qq.jpeg">';
- highlight_file(__FILE__);
- include("config.php");
- if (($op = @$_GET['op']) && (@strlen($op) < 3 && @($op + 8) < 'A_A')) {
- if (($_ = @$_GET['Σ>―(#°ω°#)♡→']) && (preg_match('/[\x00-!\'0-9"`&$.,|^[{_zdxfegavpos\x7F]+/i', $_) || @strlen(count_chars(strtolower($_), 3)) > 13 || @strlen($_) > 19)) {
- exit($secret);
- } else {
- // eval(return $_) with some replace
- $ch = curl_init();
- @curl_setopt($ch, CURLOPT_URL, str_replace("int", ":DD", str_replace("%69%6e%74", "XDDD", str_replace("%2e%2e", "Q___Q", str_replace("..", "QAQ", str_replace("%33%33%61", ">__<", str_replace("%63%3a", "WTF", str_replace("633a", ":)", str_replace("433a", ":(", str_replace("\x63:", "ggininder", strtolower(eval("return $_;"))))))))))));
- @curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
- @curl_setopt($ch, CURLOPT_TIMEOUT, 1);
- @curl_EXEC($ch);
- }
- } else {
- if (@strlen($op) < 4 && @($op + 78) < 'A__A') {
- if (($_ = @$_GET['']) && (
- (strtolower(substr($_, -4)) === '.php')
- || (strtolower(substr($_, -4)) === 'php.')
- || (stripos($_, "\"") !== FALSE)
- || (stripos($_, "\x3e") !== FALSE)
- || (stripos($_, "\x3c") !== FALSE)
- || (stripos(strtolower($_), "amp") !== FALSE))) {
- die($secret);
- } else {
- // filter .., "\x24"
- if (stripos($_, "..") !== FALSE) {
- die($secret);
- } else {
- if (stripos($_, "\x24") !== FALSE) {
- die($secret);
- } else {
- print_r(substr(@file_get_contents($_), 0, 155));
- }
- } // read file
- }
- } else {
- die($secret);
- system($_GET[0x9487945]);
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement