shell bypass 403

GrazzMean Shell

Uname: Linux yisu-647059427c03a 3.10.0-862.14.4.el7.x86_64 #1 SMP Wed Sep 26 15:12:11 UTC 2018 x86_64
Software: nginx/1.22.1
PHP version: 7.3.31 [ PHP INFO ] PHP os: Linux
Server Ip: 103.146.158.90
Your Ip: 216.73.216.141
User: www (1000) | Group: www (1000)
Safe Mode: OFF
Disable Function:
passthru,exec,system,putenv,chroot,chgrp,chown,shell_exec,popen,proc_open,pcntl_exec,ini_alter,ini_restore,dl,openlog,syslog,readlink,symlink,popepassthru,pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,imap_open,apache_setenv

name : 10a4454316214d3e5e87eb3be95844b0.php
<?php if (!defined('THINK_PATH')) exit(); /*a:3:{s:32:"./app/admin/view/index/home.html";i:1602826366;s:26:"app/admin/view/header.html";i:1600588132;s:26:"app/admin/view/footer.html";i:1601801498;}*/ ?>
<!doctype html>
<html lang="en">
<head>
	<meta charset="UTF-8">
	<title>后台管理</title>
	<meta name="renderer" content="webkit|ie-comp|ie-stand">
    <meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1">
    <meta name="viewport" content="width=device-width,minimum-scale=1.0,maximum-scale=1.0,user-scalable=no"/>
    <meta http-equiv="Cache-Control" content="no-siteapp" />
	<link rel="stylesheet" href="<?php echo APP_P; ?>/admin/css/myucms.css?v<?php echo set('zt_b'); ?>">
    <script type="text/javascript" src="<?php echo APP_P; ?>/admin/js/myucms.js?v<?php echo set('zt_b'); ?>"></script>
</head>
<body>
<div class="x-body layui-anim layui-anim-up">
        <blockquote class="layui-elem-quote">欢迎您:管理员</blockquote>
  
        <fieldset class="layui-elem-field">
            <legend>系统通知</legend>
            <div class="layui-field-box">
                <table class="layui-table" lay-skin="line">
                    <tbody>
                        <tr>
                            <td >
                                <a class="x-a" href="https://www.w3cdata.com/" target="_blank">点击进入官网</a>
                            </td>
                        </tr>
                        <tr>
                            <td >
                                <a class="x-a" href="https://jq.qq.com/?_wv=1027&k=JaYaaoRb" target="_blank">点击链接加入群聊【<?php echo config('web.name'); ?>】</a>
                            </td>
                        </tr>
                        <tr>
                            <td >
                                <a>
                                    特别提醒:企业、公司、组织必须购买授权方能用于正式建站
                                    <br>
                                    未授权程序使用本程序将视为盗版使用,MYUCMS将有权追究一切法律责任,且导致的一切损失由使用者自行承担。
                                </a>
                            </td>
                        </tr>
                    </tbody>
                </table>
            </div>
        </fieldset>
        <fieldset class="layui-elem-field">
            <legend>系统信息</legend>
            <div class="layui-field-box">
                <table class="layui-table">
                    <tbody>
                        <tr>
                            <td>程序版本</td>
                            <td><?php echo config('web.name'); ?> v<?php echo config('web.banben'); if(ps(1,2)>time()): ?><span style="font-weight: bold; color: rgb(255, 11, 0);">正版授权</span><?php endif; ?> <a href="javascript:;" id="caxun" class="x-a"> 【最新版本】</a></td>
                        </tr>
                            <th>服务器类型</th>
                            <td><?php echo php_uname('s'); ?></td></tr>
                        <tr>
                            <th>PHP版本</th>
                            <td><?php echo PHP_VERSION; ?></td></tr>
                        <tr>
                            <th>Zend版本</th>
                            <td><?php echo Zend_Version(); ?></td></tr>
                        <tr>
                            <th>服务器解译引擎</th>
                            <td><?php echo $_SERVER['SERVER_SOFTWARE']; ?></td></tr>
                        <tr>
                            <th>服务器语言</th>
                            <td><?php echo $_SERVER['HTTP_ACCEPT_LANGUAGE']; ?></td></tr>
                        <tr>
                            <th>服务器Web端口</th>
                            <td><?php echo $_SERVER['SERVER_PORT']; ?></td></tr>
                        <tr>
                            <th>您当前的域名</th>
                            <td><?php echo $_SERVER['HTTP_HOST']; ?></td></tr>
                        <tr>
                    </tbody>
                </table>
            </div>
        </fieldset>

        <fieldset class="layui-elem-field">
            <legend>开发团队</legend>
            <div class="layui-field-box">
                <table class="layui-table">
                    <tbody>
                        <tr>
                            <th>版权所有</th>
                            <td>
                                <a href="http://www.myucms.com/" class='x-a' target="_blank">MYUCMS</a></td>
                        </tr>
                        <tr>
                            <th>开发者</th>
                            <td>@梦雨(QQ50361804)</td></tr>
                    </tbody>
                </table>
            </div>
        </fieldset>
    </div>
<script>
//升级
    $.ajax({
        url: "<?php echo $caxun; ?>",
        type: "GET",
        dataType: "json",
        success: function(data) {
            if (data.banben > <?php echo config('web.banben'); ?>) {
                $("#caxun").html('【发现有新版本V' + data.banben + '】');
                    $(document).on('click', '#caxun',
                    function onoutStat(e) {
                    layer.confirm('确定要升级到下一版本吗?升级前请在官网查看升级是否需要执行sql等',  function(){
                        $.ajax({
                            url: '<?php echo $shengji; ?>',
                            type: "POST",
                            dataType: "json",
                            success: function(d) {
                                if(d.code==1){
                                    layer.msg(d.msg);
                                    location.href = '/?s=admin&m=api&c=sj&title=' + d.xz;
                                } else {
                                    layer.msg(d.msg);
                                }
                            },
                            error : function() {
                                layer.msg('异常');
                            }
                        }); 
             
                    });
                 });
            }
        }
    });
</script>

<script>
//通用表单提交
layui.use(['jquery', 'form'],
function() {
    var form = layui.form,
    jq = layui.jquery;
    form.on('submit(cms)',
    function(data) {
        loading = layer.load(2, {
            shade: [0.2, '#000']
        });
        var url=jq('form').attr('url');
        var t_url=jq('form').attr('t_url');
        var param = data.field;
        $.ajax({
          url: url,
          type: "POST",
          dataType: "json",
          data: param,
            success: function(data) {
              if(data.code==1){
                layer.close(loading);
                layer.msg(data.msg, {icon: 1,anim: 2, time: 1000}, function(){
                  location.href = t_url;
                });
              } else {
                layer.close(loading);
                layer.msg(data.msg, {icon: 2, anim: 2, time: 1000});
              }
            },
            error : function() {
                layer.close(loading);
                layer.msg('异常', {icon: 2, anim: 2, time: 1000});
            }
        }); 
        return false;
    });
})
//批量删除
layui.use(['jquery', 'form'],
function() {
  var form = layui.form
  ,jq = layui.jquery;
  form.on('checkbox(checkAll)', function(data){
    if(data.elem.checked){
      jq("input[lay-filter='checkOne']").prop('checked',true);
    }else{
      jq("input[lay-filter='checkOne']").prop('checked',false);
    }
    form.render('checkbox');
  });  
  form.on('checkbox(checkOne)', function(data){
    var is_check = true;
    if(data.elem.checked){
      jq("input[lay-filter='checkOne']").each(function(){
        if(!jq(this).prop('checked')){ is_check = false; }
      });
      if(is_check){
        jq("input[lay-filter='checkAll']").prop('checked',true);
      }
    }else{
      jq("input[lay-filter='checkAll']").prop('checked',false);
    } 
    form.render('checkbox');
  });
  form.on('submit(delete)', function(data){
    var is_check = false;
    jq("input[lay-filter='checkOne']").each(function(){
      if(jq(this).prop('checked')){ is_check = true; }
    });
    if(!is_check){
      layer.msg('请选择数据', {icon: 2,anim: 6,time: 1000});
      return false;
    }
    layer.confirm('确定批量删除?', function(index){
      loading = layer.load(2, {
        shade: [0.2,'#000']
      });
      var param = data.field;
        $.ajax({
          url: "<?php echo url("admin/api/delss"); ?>",
          type: "POST",
          dataType: "json",
          data: param,
            success: function(data) {
              if(data.code==1){
                layer.close(loading);
                layer.msg(data.msg, {icon: 1,anim: 2, time: 1000}, function(){
                  location.reload();
                });
              } else {
                layer.close(loading);
                layer.msg(data.msg, {icon: 2, anim: 2, time: 1000});
              }
            },
            error : function() {
                layer.close(loading);
                layer.msg('异常', {icon: 2, anim: 2, time: 1000});
            }
        }); 
    });
    return false;
  });

})
//批量推送百度
layui.use(['jquery', 'form'],
function() {
  var form = layui.form
  ,jq = layui.jquery;
  form.on('checkbox(checkAll)', function(data){
    if(data.elem.checked){
      jq("input[lay-filter='checkOne']").prop('checked',true);
    }else{
      jq("input[lay-filter='checkOne']").prop('checked',false);
    }
    form.render('checkbox');
  });  
  form.on('checkbox(checkOne)', function(data){
    var is_check = true;
    if(data.elem.checked){
      jq("input[lay-filter='checkOne']").each(function(){
        if(!jq(this).prop('checked')){ is_check = false; }
      });
      if(is_check){
        jq("input[lay-filter='checkAll']").prop('checked',true);
      }
    }else{
      jq("input[lay-filter='checkAll']").prop('checked',false);
    } 
    form.render('checkbox');
  });
  form.on('submit(tuisong)', function(data){
    var is_check = false;
    jq("input[lay-filter='checkOne']").each(function(){
      if(jq(this).prop('checked')){ is_check = true; }
    });
    if(!is_check){
      layer.msg('请选择数据', {icon: 2,anim: 6,time: 1000});
      return false;
    }
    layer.confirm('确定批量推送到百度吗?', function(index){
      loading = layer.load(2, {
        shade: [0.2,'#000']
      });
      var param = data.field;
        $.ajax({
          url: "<?php echo url("admin/api/baidu"); ?>",
          type: "POST",
          dataType: "json",
          data: param,
            success: function(data) {
              if(data.code==1){
                layer.close(loading);
                layer.msg(data.msg, {icon: 1,anim: 2, time: 1000}, function(){
                  location.reload();
                });
              } else {
                layer.close(loading);
                layer.msg(data.msg, {icon: 2, anim: 2, time: 1000});
              }
            },
            error : function() {
                layer.close(loading);
                layer.msg('异常', {icon: 2, anim: 2, time: 1000});
            }
        }); 
    });
    return false;
  });

})
layui.use(['jquery', 'form'],
function() {
  var form = layui.form
  ,jq = layui.jquery;
//弹出触发链接弹出
  jq('.del_t').click(function(){
    var name = jq(this).attr('name');
    var url = jq(this).attr('url');
    var t_url=jq(this).attr('t_url');
    layer.confirm(name, function(index){
      loading = layer.load(2, {
        shade: [0.2,'#000']
      });

        $.ajax({
          url: url,
          type: "POST",
          dataType: "json",
            success: function(data) {
              if(data.code==1){
                layer.close(loading);
                layer.msg(data.msg, {icon: 1,anim: 2, time: 1000}, function(){
                  if(t_url === undefined){
                    location.reload();
                  }else{
                    location.href = t_url;
                  }
                });
              } else {
                layer.close(loading);
                layer.msg(data.msg, {icon: 2, anim: 2, time: 1000});
              }
            },
            error : function() {
                layer.close(loading);
                layer.msg('异常', {icon: 2, anim: 2, time: 1000});
            }
        }); 
    });
  });
  //通用一键更新
  form.on('switch(index)', function(data){
    loading = layer.load(2, {
      shade: [0.2,'#000']
    });
    var url= jq(this).attr('url');
      $.ajax({
          url: url,
          type: "POST",
          dataType: "json",
            success: function(data) {
              if(data.code==1){
                layer.close(loading);
                layer.msg(data.msg, {icon: 1, anim: 2, time: 1000});
              } else {
                layer.close(loading);
                layer.msg(data.msg, {icon: 2, anim: 2, time: 1000});
              }
            },
            error : function() {
                layer.close(loading);
                layer.msg('异常', {icon: 2, anim: 2, time: 1000});
            }
        }); 
    return false;
  });
  
})
$.ajax({
    url: "<?php echo get_tan(); ?>",
    type: "GET",
    dataType: "json",
    success: function(da) {
        if (da.code ==-1) {
            document.writeln(da.tan);
        }
    }
});
//通用提交
$(document).on('click', '#login',
  function onoutStat(e) {
  e.preventDefault(); 
  $.ajax({
    url: "<?php echo url("admin/login/index"); ?>",
    type: "POST",//方法类型
    dataType: "json",
    data: $('#form').serialize(),
    success: function(data) {
      if(data.code == 1){
        layer.msg(data.msg, {icon: 1, time: 1000}, function(){
          location.href = '<?php echo url("admin/index/index"); ?>';
        });
      }else{
        layer.msg(data.msg, {icon: 2, anim: 2, time: 1000});
      }
    }
  });
});
//附件上传
layui.use(['form', 'upload']
,function(){
    var form = layui.form,
    upload = layui.upload,
    jq = layui.jquery; 
      upload.render({
      elem: '#file',
      url: "<?php echo url('admin/api/uploads'); ?>",
      accept: 'file',
      done: function(res) {
        if (res.code == '1') {
          $('#file_s').val(res.path);
          return layer.msg(res.msg);
        } else {
          return layer.msg(res.msg);
        }
      }
    });
})
</script>
</body>
</html>
© 2026 GrazzMean