shell bypass 403

UnknownSec Shell

: /var/softaculous/unmark/ [ drwxr-xr-x ]
Uname: Linux dedi-15171674.espacofacial.com.br 5.14.0-687.36.1.el9_8.x86_64 #1 SMP PREEMPT_DYNAMIC Fri Aug 7 05:40:49 EDT 2026 x86_64
Software: Apache
PHP version: 8.2.33 [ PHP INFO ] PHP os: Linux
Server Ip: 172.67.154.186
Your Ip: 216.73.217.20
User: espa7358 (1004) | Group: espa7358 (1003)
Safe Mode: OFF
Disable Function:
NONE

name : update_pass.php
<?php

function __generateToken($len=20){
    $token  = NULL;
    $chars  = '1234567890abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ';
    $i      = 1;
    while ($i <= $len) {
        $token  .= substr($chars, mt_rand(0, strlen($chars) - 1), 1);
        $i      += 1;
    }
    return $token;
}

function __generateHash($str){
    $salt = __generateToken(50);

    if (CRYPT_SHA512 == 1) {
        return crypt($str, '$6$rounds=5000$' . $salt . '$');
    }

    if (CRYPT_SHA256 == 1) {
        return crypt($str, '$5$rounds=5000$' . $salt . '$');
    }

    if (CRYPT_BLOWFISH == 1) {
        return crypt($str, '$2a$07$' . $salt . '$');
    }

    if (CRYPT_MD5 == 1) {
        return crypt($str, '$1$' . $salt . '$');
    }

    if (CRYPT_EXT_DES == 1) {
        return crypt($str, '_J9' . $salt);
    }

    if (CRYPT_STD_DES == 1) {
        return crypt($str, $salt);
    }

    return false;
    // Throw exception once everything is hooked up
}

$resp = __generateHash('[[admin_pass]]');
echo '<update_pass>'.$resp.'</update_pass>';

// We do not need this file any more
@unlink('update_pass.php');

?>
© 2026 UnknownSec