‰PNG  IHDR 3 ( S°Âr 7iCCPsRGB IEC61966-2.1 xœ–wTSهϽ7½P’Š”ÐkhRH ½H‘.*1 JÀ "6DTpDQ‘¦2(à€£C‘±"Š…Q±ëDÔqp–Id­ß¼yïÍ›ß÷~kŸ½ÏÝgï}Öº üƒÂLX € ¡Xáçň‹g` ð l àp³³BøF™|ØŒl™ø½º ùû*Ó?ŒÁ ÿŸ”¹Y"1 P˜ŒçòøÙ\É8=Wœ%·Oɘ¶4MÎ0JÎ"Y‚2V“sò,[|ö™e9ó2„<ËsÎâeðäÜ'ã9¾Œ‘`çø¹2¾&cƒtI†@Æoä±|N6 (’Ü.æsSdl-c’(2‚-ãy àHÉ_ðÒ/XÌÏËÅÎÌZ.$§ˆ&\S†“‹áÏÏMç‹ÅÌ07#â1Ø™Yár fÏüYym²";Ø8980m-m¾(Ô]ü›’÷v–^„îDøÃöW~™ °¦eµÙú‡mi ]ëP»ý‡Í`/ в¾u}qº|^RÄâ,g+«ÜÜ\KŸk)/èïúŸC_|ÏR¾Ýïåaxó“8’t1C^7nfz¦DÄÈÎâpù 柇øþuü$¾ˆ/”ED˦L L–µ[Ȉ™B†@øŸšøÃþ¤Ù¹–‰ÚøЖX¥!@~ (* {d+Ðï} ÆGù͋љ˜ûÏ‚þ}W¸LþÈ$ŽcGD2¸QÎìšüZ4 E@ê@èÀ¶À¸ àA(ˆq`1à‚D €µ ”‚­`'¨u 4ƒ6ptcà48.Ë`ÜR0ž€)ð Ì@„…ÈR‡t CȲ…XäCP”%CBH@ë R¨ª†ê¡fè[è(tº C· Qhúz#0 ¦ÁZ°l³`O8Ž„ÁÉð28.‚·À•p|î„O×àX ?§€:¢‹0ÂFB‘x$ !«¤i@ڐ¤¹ŠH‘§È[EE1PL” Ê…⢖¡V¡6£ªQP¨>ÔUÔ(j õMFk¢ÍÑÎè t,:‹.FW ›Ðè³èô8úƒ¡cŒ1ŽL&³³³ÓŽ9…ÆŒa¦±X¬:ÖëŠ År°bl1¶ {{{;Ž}ƒ#âtp¶8_\¡8áú"ãEy‹.,ÖXœ¾øøÅ%œ%Gщ1‰-‰ï9¡œÎôÒ€¥µK§¸lî.îžoo’ïÊ/çO$¹&•'=JvMÞž<™âžR‘òTÀT ž§ú§Ö¥¾N MÛŸö)=&½=—‘˜qTH¦ û2µ3ó2‡³Ì³Š³¤Ëœ—í\6% 5eCÙ‹²»Å4ÙÏÔ€ÄD²^2šã–S“ó&7:÷Hžrž0o`¹ÙòMË'ò}ó¿^ZÁ]Ñ[ [°¶`t¥çÊúUЪ¥«zWë¯.Z=¾Æóµ„µik(´.,/|¹.f]O‘VÑš¢±õ~ë[‹ŠEÅ76¸l¨ÛˆÚ(Ø8¸iMKx%K­K+Jßoæn¾ø•ÍW•_}Ú’´e°Ì¡lÏVÌVáÖëÛÜ·(W.Ï/Û²½scGÉŽ—;—ì¼PaWQ·‹°K²KZ\Ù]ePµµê}uJõHWM{­fí¦Ú×»y»¯ìñØÓV§UWZ÷n¯`ïÍz¿úΣ†Š}˜}9û6F7öÍúº¹I£©´éÃ~á~遈}ÍŽÍÍ-š-e­p«¤uò`ÂÁËßxÓÝÆl«o§·—‡$‡›øíõÃA‡{°Ž´}gø]mµ£¤ê\Þ9Õ•Ò%íŽë>x´·Ç¥§ã{Ëï÷Ó=Vs\åx٠‰¢ŸN柜>•uêééäÓc½Kz=s­/¼oðlÐÙóç|ϝé÷ì?yÞõü± ÎŽ^d]ìºäp©sÀ~ ãû:;‡‡º/;]îž7|âŠû•ÓW½¯ž»píÒÈü‘áëQ×oÞH¸!½É»ùèVú­ç·snÏÜYs}·äžÒ½Šûš÷~4ý±]ê =>ê=:ð`Áƒ;cܱ'?eÿô~¼è!ùaÅ„ÎDó#ÛGÇ&}'/?^øxüIÖ“™§Å?+ÿ\ûÌäÙw¿xü20;5þ\ôüÓ¯›_¨¿ØÿÒîeïtØôýW¯f^—¼Qsà-ëmÿ»˜w3¹ï±ï+?˜~èùôñî§ŒOŸ~÷„óûpf* pHYs  Ê&ó? ÉIDATxœí™mh[UÇo’Û·´iWi`×b;Ym­`p Œ¬­n¢8Dh7ýà‡²‰ƒ9Q?t²f-(¢›:?±(Žiˆ:W¦‚m†…Vi‰ö…®±)KÚ4ñwºÜr“Ü›·¶YÊú‡'çí9ç>ÿsžsÎsoäp8, ŒŽŽÔÖÖv †ç)>€äK·>äòòòr¯,Ë¿¥ÒA?@`g]]‹lÓFZ—&J&“é‰P(ôªÑh<“¬ƒì÷ûwüL~ûÆÛ—LxK„<ú"‘¢ ‘³RîY„ހ̗ ëé7{<‹6­÷ø|¾»HÿÑSd ³gÏÚÀþIh«œ-C²-2¹ŠÛ’ÌUä;ää²-î·ˆiDžBŒ:z7'2ŽØ"’28¢“ˆ`þ˜˜ø¡¦¦ÆŸ ™KCCCO[­Ö%Qà’íånú…ìŽXE>Ê]ðR&9@ù+ BóÁ`Ж——wUÕ÷C’#©’áÞy$Tª®®Å®G’’ᡯ+D Ç™•>y'Fõ1ÔyÚV+8J¿ÁÈÉ>£û‰šÈ »ùùN‹ÅÒ!º¥JH…Lð™¤d`<΃c«4TÇungFÝõØŠÒÒÒëÁeY2›t°?)™âââ}$Õu¬Ê^ Õ½^ï¶²²²9¥ÂétšÚÚÚöhè>ŠØÕxÀnV2S"–¤d0ü¾ÿ«óýððp^}}ýêžÑŒÙufÉG =* ò6õ÷jèîaúfffNVVVú ò0D>[‘¤r T²‰/ BÒÍwœD!Ek~~þ†zYQ‹¤’ ¯¨¨8*\ "åé­‡tî™Ò4tSu±×…ˆÀmyin l‘ÉUl‘ÉU2^)ó"«XZZšçBÖmdÞGNdÍ¢Ìq¥¤¤dFd¸Ä \âq©ÜÓÓs²««ËLþ%Đm SÄ_„Iϱ¯æææÄE]Èv»]Äì/³„Ÿ‹žVéf<•±PDŒZÉ"‚vî\ôx<ŽªªªJ¡ÒCZV ÉA’Džþ ¹_ç!"Ì¿ ùÞ©©©1‡ÃˆLÈ*º»»---“šžž···/‹¼xù‚HT;nv,! ÛÍfs£ÎsÜøê1Vð åÊC §!Šï¾6ÌÎΖ–——Ÿ&û¤V{™¢¢¢ýR¼‹‰§.—Ëu^™1Hµ1CÙú*6KDv“ë)Å‘aYÕ¯¸bv?fµNp’LCD­w7IÇúÙ»f£ÈD޼}‘â¯äãR¿C$®'{æk\M¼|åÊÅ;eÇŸø&€K= ‰ ‰¾¸sy]£ý+Ô»áf¦ lî"³¸¸8922²«¡¡aQý•E¬äiô&#„nÕß"bÂûÝn÷›Qd8¿'!’ÖHúhpp°¿©©©‘üe•(G´ú„iPJ~â1œá>ÒWs‹pø5Ü݉—ŒY­Öõñ÷Èw5÷zŒ¥¿ßïÀà·ÈŒi "J!W6oBÆüMrˆ©•ÕWŠü÷ʪ‰h圢·)È(0™L? Xm6Û‹9EÕ^m(Ȧ"#ÐÜÜ,öÚYŸÏ÷9{ÜÞÙÙ¹‹òŸ¢íº›|¬– IEND®B`‚ AnonSec Shell
AnonSec Shell
Server IP : 20.73.19.71  /  Your IP : 10.112.20.21
Web Server : nginx/1.15.12
System : Linux a10deea3d6b7 6.8.0-1044-azure #50~22.04.1-Ubuntu SMP Wed Dec 3 15:13:22 UTC 2025 x86_64
User :  ( 1000)
PHP Version : 7.4.33
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : OFF  |  Perl : ON  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /var/www/html/wp-content/plugins/backupbuddy/lib/updater/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ HOME ]     

Current File : /var/www/html/wp-content/plugins/backupbuddy/lib/updater/server.php
<?php

/*
Provides an easy to use interface for communicating with the iThemes updater server.
Written by Chris Jean for iThemes.com
Version 1.1.0

Version History
	1.0.0 - 2013-04-11 - Chris Jean
		Release ready
	1.0.1 - 2013-06-21 - Chris Jean
		Updated the http_build_query call to force a separator of & in order to avoid issues with servers that change the arg_separator.output php.ini value.
	1.0.2 - 2013-09-19 - Chris Jean
		Updated ithemes-updater-object to ithemes-updater-settings.
	1.0.3 - 2013-12-18 - Chris Jean
		Updated the way that the site URL is generated to ensure consistency across multisite sites.
	1.0.4 - 2014-01-31 - Chris Jean
		Updated to normalize the site URL used for password hash generation and for sending to the server.
	1.1.0 - 2014-10-23 - Chris Jean
		Updated auth token generation to use new password hashing.
		Added CA patch code.
		Updated code to meet WordPress coding standards.
*/


class Ithemes_Updater_Server {
	private static $secure_server_url = 'https://api.ithemes.com/updater';
	private static $insecure_server_url = 'http://api.ithemes.com/updater';

	private static $password_iterations = 8;


	public static function activate_package( $username, $password, $packages ) {
		$query = array(
			'user' => $username
		);

		$data = array(
			'auth_token' => self::get_password_hash( $username, $password ),
			'packages'   => $packages,
		);

		return Ithemes_Updater_Server::request( 'package-activate', $query, $data );
	}

	public static function deactivate_package( $username, $password, $packages ) {
		$query = array(
			'user' => $username
		);

		$data = array(
			'auth_token' => self::get_password_hash( $username, $password ),
			'packages'   => $packages,
		);

		return Ithemes_Updater_Server::request( 'package-deactivate', $query, $data );
	}

	public static function get_package_details( $packages ) {
		$query = array();

		$data = array(
			'packages' => $packages
		);

		return Ithemes_Updater_Server::request( 'package-details', $query, $data );
	}

	public static function request( $action, $query = array(), $data = array() ) {
		require_once( $GLOBALS['ithemes_updater_path'] . '/settings.php' );

		if ( false !== ( $timeout_start = get_site_option( 'ithemes-updater-server-timed-out' ) ) ) {
			// Hold off updates for 30 minutes.
			$time_remaining = 1800 - ( time() - $timeout_start );
			$minutes_remaining = ceil( $time_remaining / 60 );

			if ( $time_remaining < 0 ) {
				delete_site_option( 'ithemes-updater-server-timed-out' );
			} else {
				return new WP_Error( 'ithemes-updater-timed-out-server', sprintf( _n( 'The server could not be contacted. Requests are delayed for %d minute to allow the server to recover.', 'The server could not be contacted. Requests are delayed for %d minutes to allow the server to recover.', $minutes_remaining, 'it-l10n-backupbuddy' ), $minutes_remaining ) );
			}
		}


		if ( isset( $data['auth_token'] ) ) {
			$data['iterations'] = self::$password_iterations;
		}


		$site_url = self::get_site_url();


		$default_query = array(
			'wp'           => $GLOBALS['wp_version'],
			'site'         => $site_url,
			'timestamp'    => time(),
			'auth_version' => '2',
		);

		if ( is_multisite() ) {
			$default_query['ms'] = 1;
		}

		$query = array_merge( $default_query, $query );
		$request = "/$action/?" . http_build_query( $query, '', '&' );

		$post_data = array(
			'request' => json_encode( $data ),
		);

		$remote_post_args = array(
			'timeout' => 10,
			'body'    => $post_data,
		);


		$options = array(
			'use_ca_patch' => false,
			'use_ssl'      => true,
		);

		$patch_enabled = $GLOBALS['ithemes-updater-settings']->get_option( 'use_ca_patch' );

		if ( $patch_enabled ) {
			self::disable_ssl_ca_patch();
		}


		$response = wp_remote_post( self::$secure_server_url . $request, $remote_post_args );

		if ( is_wp_error( $response ) && ( 'connect() timed out!' != $response->get_error_message() ) ) {
			self::enable_ssl_ca_patch();
			$response = wp_remote_post( self::$secure_server_url . $request, $remote_post_args );

			if ( ! is_wp_error( $response ) ) {
				$options['use_ca_patch'] = true;
			}
		}

		if ( is_wp_error( $response ) && ( 'connect() timed out!' != $response->get_error_message() ) ) {
			$response = wp_remote_post( self::$insecure_server_url . $request, $remote_post_args );

			$options['use_ssl'] = false;
		}

		if ( ! $options['use_ca_patch'] ) {
			self::disable_ssl_ca_patch();
		}

		$GLOBALS['ithemes-updater-settings']->update_options( $options );

		if ( is_wp_error( $response ) ) {
			if ( 'connect() timed out!' == $response->get_error_message() ) {
				// Set option to delay server checks for a period of time.
				update_site_option( 'ithemes-updater-server-timed-out', time() );

				return new WP_Error( 'http_request_failed', __( 'The server was unable to be contacted.', 'it-l10n-backupbuddy' ) );
			}

			return $response;
		}


		$body = json_decode( $response['body'], true );

		if ( ! empty( $body['error'] ) ) {
			return new WP_Error( $body['error']['type'], sprintf( __( 'An error occurred when communicating with the iThemes update server: %s (%s)', 'it-l10n-backupbuddy' ), $body['error']['message'], $body['error']['code'] ) );
		}


		return $body;
	}

	private static function get_site_url() {
		if ( is_callable( 'network_home_url' ) ) {
			$site_url = network_home_url();
		} else {
			$site_url = get_bloginfo( 'url' );
		}

		$site_url = preg_replace( '/^https/', 'http', $site_url );
		$site_url = preg_replace( '|/$|', '', $site_url );

		return $site_url;
	}

	private static function get_password_hash( $username, $password ) {
		require_once( ABSPATH . WPINC . '/class-phpass.php' );
		require_once( dirname( __FILE__ ) . '/class-ithemes-credentials.php' );

		$password = iThemes_Credentials::get_password_hash( $username, $password );

		$salted_password = $password . $username . self::get_site_url() . $GLOBALS['wp_version'];
		$salted_password = substr( $salted_password, 0, max( strlen( $password ), 512 ) );

		$hasher = new PasswordHash( self::$password_iterations, true );
		$auth_token = $hasher->HashPassword( $salted_password );

		return $auth_token;
	}

	public static function enable_ssl_ca_patch() {
		add_action( 'http_api_curl', array( __CLASS__, 'add_ca_patch_to_curl_opts' ) );
	}

	public static function disable_ssl_ca_patch() {
		remove_action( 'http_api_curl', array( __CLASS__, 'add_ca_patch_to_curl_opts' ) );
	}

	public static function add_ca_patch_to_curl_opts( $handle ) {
		$url = curl_getinfo( $handle, CURLINFO_EFFECTIVE_URL );

		if ( ! preg_match( '{^https://(api|downloads)\.ithemes\.com}', $url ) ) {
			return;
		}

		curl_setopt( $handle, CURLOPT_CAINFO, $GLOBALS['ithemes_updater_path'] . '/ca/roots.crt' );
	}
}

Anon7 - 2022
AnonSec Team