403Webshell
Server IP : 103.234.187.230  /  Your IP : 216.73.216.216
Web Server : Apache
System : Linux lserver42043-ind.megavelocity.net 3.10.0-1160.108.1.el7.x86_64 #1 SMP Thu Jan 25 16:17:31 UTC 2024 x86_64
User : apache ( 48)
PHP Version : 7.4.33
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/html/b2bzend/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/html/b2bzend/payOnline.php
<?php

$baseUrl = 'https://globaltravelexchange.com/';
require_once 'cronjob/init.php';
error_reporting(E_ALL);
$TblAgency = new Travel_Model_TblAgency();
$crmcustomerObj = new Travel_Model_CRM_Customer();
$crmagencyleadaccountObj = new Travel_Model_CRM_AgencyLeadAccount();
$agencycustomerObj = new Travel_Model_CRM_AgencyCustomer();
$resultArr = array();
if ($_POST) {
//    $ATOMPAYMENTURL = "https://paynetzuat.atomtech.in/paynetz/epi/fts";
//    $ATOMLOGIN = "197";
//    $ATOMPASS = "Test@123";
//    $ATOMPRODID = "NSE";
//    $REQHASHKEY = "KEY123657234";
//    $RESPHASHKEY = "KEYRESP123657234";
    $ru = "https://globaltravelexchange.com/payReturn.php";
    $ATOMPAYMENTURL = "https://payment.atomtech.in/paynetz/epi/fts";
    $ATOMLOGIN = "23860";
    $ATOMPASS = "CATABATIC@123";
    $ATOMPRODID = "CATABATIC";
    $REQHASHKEY = "5a1507a1ad2b194e5b";
    $RESPHASHKEY = "0d3c1adc88d7f02ca6";

    $paymentMdl = new Payment_Model_Payment();
    $txnid = time();
    $login = trim($ATOMLOGIN);
    $pass = trim($ATOMPASS);
    $ttype = trim("NBFundTransfer");
    $prodid = trim($ATOMPRODID);
    $amount = 5310;
    $txncurr = trim("INR");
    $signatureVal = $login . $pass . $ttype . $prodid . $txnid . $amount . $txncurr;
    $signature = hash_hmac("sha512", $signatureVal, $REQHASHKEY, false);
    $AgencySysId = (int) $_POST['AgencySysId'];
    $datenow = date("d/m/Y h:m:s");
    $modifiedDate = str_replace(" ", "%20", $datenow);
    $Salutation = (isset($_POST['Salutation']) && $_POST['Salutation'] != '') ? $_POST['Salutation'] : '';
    $firstName = (isset($_POST['FirstName']) && $_POST['FirstName'] != '') ? $_POST['FirstName'] : '';
    $LastName = (isset($_POST['LastName']) && $_POST['LastName'] != '') ? $_POST['LastName'] : '';
    $fullName = $Salutation . ' ' . $firstName . ' ' . $LastName;
    $EmailId = isset($_POST['EmailId']) ? $_POST['EmailId'] : '';
    $MobileNo = isset($_POST['MobileNo']) ? $_POST['MobileNo'] : '';
    $companyName = isset($_POST['AgencyName']) ? $_POST['AgencyName'] : '';
    $websiteURL = isset($_POST['websiteURL']) && $_POST['websiteURL'] != '' ? $_POST['websiteURL'] : 'NO Web site';
    $postFields = "";
    $postFields .= "&login=$login";
    $postFields .= "&pass=$pass";
    $postFields .= "&ttype=$ttype";
    $postFields .= "&prodid=$prodid";
    $postFields .= "&amt=$amount";
    $postFields .= "&txncurr=$txncurr";
    $postFields .= "&txnscamt=0";
    $postFields .= "&signature=$signature";
    $postFields .= "&clientcode=" . urlencode(base64_encode($AgencySysId));
    $postFields .= "&txnid=" . $txnid;
    $postFields .= "&date=" . $modifiedDate;
    $postFields .= "&custacc=123456789";
    $postFields .= "&udf1=$fullName";
    $postFields .= "&udf2=$EmailId";
    $postFields .= "&udf3=$MobileNo";
    $postFields .= "&udf4=$companyName";
    $postFields .= "&udf9=$websiteURL";
    $postFields .= "&ru=$ru";
    $sendUrl = $ATOMPAYMENTURL . "?" . substr($postFields, 1) . "\n";
    $paymentMdl->writeLog($sendUrl);
    header("Location: " . $sendUrl);
    exit;
}

function sanitize_data($input_data) {
    $searchArr = array("document", "write", "alert", "%", "$", ";", "+", "|", "#", "<", ">", "\'");
    $input_data = str_replace("script", "", $input_data);
    $input_data = str_replace("iframe", "", $input_data);
    $input_data = str_replace($searchArr, "", $input_data);
    return htmlentities(stripslashes($input_data), ENT_QUOTES);
}

Youez - 2016 - github.com/yon3zu
LinuXploit