JezK
Edit File: .bash_history
ll cd domains ll wget covering-eg.com/covering-eg-com-20241008-113451-hwn21s.wpress ll wget global-firefighting.com/global-firefighting-com-20240902-084918-81z6si.wpress ll cd domains ll wget egyvolt.com/egyvolt-com-20250807-132928-3c6pk2vkvqzr.wpress ll cd domains ll rm -r global-firefighting-com-20240902-084918-81z6si.wpress ll wget global-firefighting.com/global-firefighting-com-20240902-084918-81z6si.wpress ll cd domains/ ll cd byteblooms.com/ ll cd public_html/ ll cd testassortio/ ll ls -R /home/u851593458/domains/byteblooms.com/public_html/testassortio/wp-content/plugins/assortio ll cd domains/ ll cd byteblooms.com/ ll cd public_html/ ll cd wp-content ll cd .. ll cd testassortio/ ll cd wp-content/ ll cd plugins ll ls -R assortio ls -R assortio/assets ls -R assortio ll ls assortio-smart-builder-woocommerce/ ls assortio-smart-builder-woocommerce ls -l assortio-smart-builder-woocommerce ls -la assortio-smart-builder-woocommerce ls -lR assortio-smart-builder-woocommerce clear ls -lR assortio-smart-builder-woocommerce clear ls -lR assortio-smart-builder-woocommerce clear ls -lR assortio-smart-builder-woocommerce ll cd domains/ ll cd byteblooms.com/ ll cd public_html/ ll cd testassortio/ ll cd wp-content/ ll cd plugins/ ll cd assortio ll cd assortio-smart-builder-woocommerce ll cd .. ll ls -lR assortio-smart-builder-woocommerce clear ls -lR assortio-smart-builder-woocommerce clear ls -lR assortio-smart-builder-woocommerce ll cd assortio cd assortio-smart-builder-woocommerce ll ls -lR admin clear ll cd .. ll clear ls -lR assortio-smart-builder-woocommerce clear ls -lR assortio-smart-builder-wooco ll ls -lR assortio-smart-builder-woocommerce cd domains/ cd byteblooms.com/ cd public_html/ cd testassortio/ ll cd wp-content ll cd plugins/ cd assortio-smart-builder-woocommerce cd .. ls -lR assortio-smart-builder-woocommerce clear ls -lR assortio-smart-builder-woocommerce ls -al /home/u851593458/domains/byteblooms.com/public_html/testassortio/wp-content/plugins/assortio-smart-builder-woocommerce/core ls -al /home/u851593458/domains/byteblooms.com/public_html/testassortio/wp-content/plugins/assortio-smart-builder-woocommerce/core/class-kernel.php ll cd assortio-smart-builder-woocommerce ll cd core/ ll ls -al cd .. ll clear ls -lR assortio-smart-builder-woocommerce cd .. ll ls -lR assortio-smart-builder-woocommerce clear ls -lR assortio-smart-builder-woocommerce clear ls -lR assortio-smart-builder-woocommerce clear ls -lR assortio-smart-builder-woocommerce wp option get assortio_general_step1_title wp option get assortio_general_step1_desc wp option get assortio_general_choose_categories wp option get assortio_general_create_btn clear ls -lR assortio-smart-builder-woocommerce ll ls -lR assortio-smart-builder-woocommerce cd domains/ cd byteblooms.com/ cd public_html/ cd testassortio/ cd wp-content/ ll cd plugins/ ll clear ls -lR assortio-smart-builder-woocommerce ll cd domains/ cd byteblooms.com/ ll cd public_html/ ll cd testassortio/ ll cd wp-content/ ll cd plugins/ ll ls -lR assortio-smart-builder-woocommerce clear ls -lR assortio-smart-builder-woocommerce ll cd domains/ cd byteblooms.com/ cd public_html/ ll cd testassortio/ cd wp-content ll cd plugins ll clear ls -lR assortio-smart-builder-woocommerce cd domains/ cd byteblooms.com/ cd public_html/ cd testassortio/ cd wp-content/ ll cd plugins ll clear ls -lR assortio-smart-builder-woocommerce ll cd domains/ cd byteblooms.com/ cd public_html/ cd testassortio/ cd wp-content/ cd plugins/ ll clear ls -lR assortio-smart-builder-woocommerce cd domains/byteblooms.com/public_html/testassortio/wp-content/plugins/ clear ls -lR assortio-smart-builder-woocommerce l ll cd domains/byteblooms.com/public_html/testassortio/wp-content/plugins/ ll clear ls -lR assortio-smart-builder-woocommerce clear ls -lR assortio-smart-builder-woocommerce ll cd domains/byteblooms.com/public_html/testassortio/wp-content/plugins/ ll clear ls -lR assortio-smart-builder-woocommerce ll cd assortio-smart-builder-woocommerce ll cd frontend/ ll rm -r class-wizard.php ll cd /var/www/your-site/htdocs/wp-content/plugins/assortio-smart-builder-woocommerce ll cd .. ll cd .. ll cd assortio-smart-builder-woocommerce ll grep -R "Assortio_REST::NAMESPACE" -n api sed -i 's/Assortio_REST::NAMESPACE/Assortio_REST::ns()/g' api/class-rest-summary.php api/class-rest-bundles.php api/class-rest-variations.php api/class-rest-products.php grep -R "Assortio_REST::NAMESPACE" -n api grep -R "Assortio_REST::ns" -n api grep -R "Assortio_REST::NAMESPACE" -n . ll cd domains/ ll cd egyvolt.com/ ll cd public_html/ ll cd wp-content/ ll cd themes ll cd electro ll nano functions.php cd .. ll cd .. ll pwd ls -la wp-config.php wp-content cd .. ll pwd ls -la wp-config.php wp-content find . -type d -exec chmod 755 {} \; find . -type f -exec chmod 644 {} \; ll cd wp-content ll cd themes ll cd electro ll php -l functions.php cd .. ll cd .. ll rm -r psysh_history rm -r wp-defender-secrets.php rm -r object-cache.php ll rm -r debug.log ll cd pgs/ ll cd .. ll rm -r pgs/ ll cd w3tc-config/ ll cd .. ll rm -r w3tc-config/ ll cd smush-webp/ ll cd .. ll rm -r smush-webp/ ll cd plugins/ ll rm -r all-in-one-wp-migration/ rm -r dokan-lite/ ll rm -r index.php ll mv seo-by-rank-math-pro/ seo-by-rank-math-proX ll rm -r wp-console/ ll rm -r wp-defender/ rm -r wpmudev-updates/ ll rm -r wp-inapppurchasetut-sendemail/ rm -r wp-contactnumbersdemo-cameraoverlay/ ll rm -r wp-homelauncher-broadcastreciever/ ll cd .. ll cd .. ll pwd cd wp-content du -h --max-depth=1 | sort -hr | head -30 ll rm -r ai1wm-backups/ ll du -h --max-depth=1 | sort -hr | head -30 cd uploads/ ll rm -r code-execution.php ll du -h --max-depth=1 | sort -hr | head -30 cd 2023 ll cd 01/ ll cd .. pwd whoami hostname find . -maxdepth 4 -name wp-config.php 2>/dev/null find . -maxdepth 3 -type d \( -name public_html -o -name htdocs -o -name domains \) 2>/dev/null command -v wp || echo no-wp-cli for d in domains/*/public_html; do if [ -f "$d/wp-config.php" ]; then echo "--- $d"; (cd "$d" && wp core version --allow-root 2>/dev/null || php -r 'include "wp-includes/version.php"; echo $wp_version, PHP_EOL;' 2>/dev/null); fi; done for d in domains/*/public_html; do if [ -f "$d/wp-config.php" ]; then echo "=== $d ==="; (cd "$d" && echo "DB=$(wp config get DB_NAME --allow-root 2>/dev/null) PREFIX=$(wp db prefix --allow-root 2>/dev/null)" && wp db query "SELECT table_schema AS db_name, ROUND(SUM(data_length+index_length)/1024/1024,2) AS mb FROM information_schema.tables WHERE table_schema = DATABASE() GROUP BY table_schema; SELECT table_name, table_rows, ROUND((data_length+index_length)/1024/1024,2) AS mb FROM information_schema.tables WHERE table_schema=DATABASE() ORDER BY (data_length+index_length) DESC LIMIT 12;" --allow-root 2>/dev/null); fi; done cd domains/egyvolt.com/public_html wp plugin list --status=active --fields=name,version --allow-root wp db query "DESCRIBE wp_trp_original_strings; DESCRIBE wp_trp_dictionary_en_us_ar; DESCRIBE wp_trp_original_meta; DESCRIBE wp_yith_wcwl_lists; DESCRIBE wp_yith_wcwl;" --allow-root wp db query "SELECT COUNT(*) AS original_strings FROM wp_trp_original_strings; SELECT COUNT(*) AS dictionary_rows FROM wp_trp_dictionary_en_us_ar; SELECT status, COUNT(*) AS c FROM wp_trp_dictionary_en_us_ar GROUP BY status; SELECT COUNT(*) AS meta_rows FROM wp_trp_original_meta; SELECT COUNT(*) AS wishlist_lists FROM wp_yith_wcwl_lists; SELECT COUNT(*) AS wishlist_items FROM wp_yith_wcwl;" --allow-root cd ~/domains/egyvolt.com/public_html for i in $(seq 1 40); do deleted=$(wp db query "DELETE FROM wp_trp_dictionary_en_us_ar WHERE status=0 LIMIT 50000; SELECT ROW_COUNT();" --skip-column-names --allow-root 2>/dev/null | tail -n 1); echo "dictionary_status0_batch_$i=$deleted"; [ "$deleted" = "0" ] && break; done wp db query "SELECT status, COUNT(*) AS c FROM wp_trp_dictionary_en_us_ar GROUP BY status;" --allow-root cd ~/domains/egyvolt.com/public_html for i in $(seq 1 30); do echo "meta_orphan_batch_$i"; wp db query "DELETE m FROM wp_trp_original_meta m LEFT JOIN wp_trp_dictionary_en_us_ar d ON d.original_id=m.original_id WHERE d.original_id IS NULL LIMIT 50000;" --allow-root >/dev/null 2>&1; remaining=$(wp db query "SELECT COUNT(*) FROM wp_trp_original_meta m LEFT JOIN wp_trp_dictionary_en_us_ar d ON d.original_id=m.original_id WHERE d.original_id IS NULL;" --skip-column-names --allow-root 2>/dev/null | tail -n 1); echo "remaining_meta_orphans=$remaining"; [ "$remaining" = "0" ] && break; done for i in $(seq 1 40); do echo "original_orphan_batch_$i"; wp db query "DELETE s FROM wp_trp_original_strings s LEFT JOIN wp_trp_dictionary_en_us_ar d ON d.original_id=s.id WHERE d.original_id IS NULL LIMIT 50000;" --allow-root >/dev/null 2>&1; remaining=$(wp db query "SELECT COUNT(*) FROM wp_trp_original_strings s LEFT JOIN wp_trp_dictionary_en_us_ar d ON d.original_id=s.id WHERE d.original_id IS NULL;" --skip-column-names --allow-root 2>/dev/null | tail -n 1); echo "remaining_original_orphans=$remaining"; [ "$remaining" = "0" ] && break; done wp db query "SELECT COUNT(*) AS original_strings FROM wp_trp_original_strings; SELECT COUNT(*) AS dictionary_rows FROM wp_trp_dictionary_en_us_ar; SELECT COUNT(*) AS meta_rows FROM wp_trp_original_meta;" --allow-root cd ~/domains/egyvolt.com/public_html wp db query "OPTIMIZE TABLE wp_trp_dictionary_en_us_ar, wp_trp_original_strings, wp_trp_original_meta;" --allow-root wp db query "SELECT table_name, table_rows, ROUND((data_length+index_length)/1024/1024,2) AS mb FROM information_schema.tables WHERE table_schema=DATABASE() AND table_name IN ('wp_trp_original_strings','wp_trp_dictionary_en_us_ar','wp_trp_original_meta') ORDER BY table_name; SELECT ROUND(SUM(data_length+index_length)/1024/1024,2) AS db_mb FROM information_schema.tables WHERE table_schema=DATABASE();" --allow-root cd ~/domains/egyvolt.com/public_html wp db query "SELECT COUNT(*) AS wc_sessions FROM wp_woocommerce_sessions; SELECT SUM(user_id IS NULL OR user_id=0) AS anonymous_lists, COUNT(*) AS all_lists, MIN(dateadded) AS oldest_list, MAX(dateadded) AS newest_list FROM wp_yith_wcwl_lists; SELECT SUM(user_id IS NULL OR user_id=0) AS anonymous_items, COUNT(*) AS all_items, MIN(dateadded) AS oldest_item, MAX(dateadded) AS newest_item FROM wp_yith_wcwl;" --allow-root wp db query "TRUNCATE TABLE wp_woocommerce_sessions; DELETE i FROM wp_yith_wcwl i LEFT JOIN wp_yith_wcwl_lists l ON l.ID=i.wishlist_id WHERE (i.user_id IS NULL OR i.user_id=0) AND (l.ID IS NULL OR l.user_id IS NULL OR l.user_id=0); DELETE FROM wp_yith_wcwl_lists WHERE user_id IS NULL OR user_id=0;" --allow-root wp db query "SELECT COUNT(*) AS wc_sessions FROM wp_woocommerce_sessions; SELECT COUNT(*) AS all_lists FROM wp_yith_wcwl_lists; SELECT COUNT(*) AS all_items FROM wp_yith_wcwl; SELECT ROUND(SUM(data_length+index_length)/1024/1024,2) AS db_mb FROM information_schema.tables WHERE table_schema=DATABASE(); SELECT table_name, table_rows, ROUND((data_length+index_length)/1024/1024,2) AS mb FROM information_schema.tables WHERE table_schema=DATABASE() ORDER BY (data_length+index_length) DESC LIMIT 15;" --allow-root cd ~ for d in domains/*/public_html; do if [ -f "$d/wp-config.php" ]; then echo "=== CORE $d ==="; (cd "$d" && wp core verify-checksums --allow-root 2>&1 | head -n 80); fi; done printf '\n=== suspicious filename scan ===\n' find domains -path '*/public_html/*' -type f \( -name 'accesson.php' -o -name '21index.php' -o -name 'users.php' -o -name 'plugins.php' -o -name 'font-cache.php' -o -name '*index.php' \) 2>/dev/null | head -n 200 printf '\n=== signature scan ===\n' grep -RIl --include='*.php' -E 'echo eval\(\$cmd\)|base64_decode\(\$_REQUEST|aaa\.bigdnirl\.best|wpmbchik|formatter-manager|FilesMan|c99shell|WSOsetcookie|Alfa Shell' domains/*/public_html 2>/dev/null | head -n 200 printf '\n=== recent php last 14 days ===\n' find domains/*/public_html -type f -name '*.php' -mtime -14 -printf '%TY-%Tm-%Td %TH:%TM %p\n' 2>/dev/null | sort -r | head -n 200 cd ~/domains/egyvolt.com/public_html Q=~/security-quarantine/egyvolt-$(date +%Y%m%d%H%M%S) mkdir -p "$Q" for f in wp-includes/class-wp-feed-cache-transient-class.php wp-includes/blocks/widget-group-sql.php wp-includes/class-wp-taxonomy-private.php wp-includes/atomlib-old.php wp-admin/link-merge.php wp-admin/includes/class-wp-upgrader-other.php wp-admin/includes/class-theme-upgrader-skin-interpreter.php wp-admin/about-path.php wp-admin/network/upgrade-http.php; do if [ -f "$f" ]; then echo "--- $f"; ls -lh "$f"; head -c 220 "$f"; echo; mkdir -p "$Q/$(dirname "$f")"; mv "$f" "$Q/$f"; fi; done echo "quarantine=$Q" wp core verify-checksums --allow-root 2>&1 | head -n 80 cd ~ printf '\n=== PHP files in uploads/cache-like dirs ===\n' find domains/*/public_html/wp-content \( -path '*/uploads/*' -o -path '*/cache/*' -o -path '*/litespeed/*' -o -path '*/wflogs/*' \) -type f -name '*.php' -printf '%p\n' 2>/dev/null | head -n 200 printf '\n=== world writable php ===\n' find domains/*/public_html -type f -name '*.php' -perm -002 -printf '%m %p\n' 2>/dev/null | head -n 100 cd ~ for d in domains/*/public_html; do if [ -f "$d/wp-config.php" ]; then echo "=== $d active theme/plugins summary ==="; (cd "$d" && wp theme list --status=active --fields=name,status,version --allow-root 2>/dev/null && wp theme list --fields=name,status,version --allow-root 2>/dev/null | head -n 40); fi; done printf '\n--- random theme inspect ---\n' ls -la domains/global-firefighting.com/public_html/wp-content/themes/mstnsuzqvu 2>/dev/null || true find domains/global-firefighting.com/public_html/wp-content/themes/mstnsuzqvu -maxdepth 2 -type f -printf '%TY-%Tm-%Td %TH:%TM %s %p\n' 2>/dev/null | sort | head -n 50 head -c 300 domains/global-firefighting.com/public_html/wp-content/themes/mstnsuzqvu/index.php 2>/dev/null; echo cd ~/domains/global-firefighting.com/public_html wp option get template --allow-root 2>&1 wp option get stylesheet --allow-root 2>&1 printf '--- mstnsuzqvu files ---\n' for f in wp-content/themes/mstnsuzqvu/*; do echo "--- $f"; ls -lh "$f"; cat "$f"; echo; done cd ~/domains/global-firefighting.com/public_html Q=~/security-quarantine/global-firefighting-$(date +%Y%m%d%H%M%S) mkdir -p "$Q/wp-content/themes" mv wp-content/themes/mstnsuzqvu "$Q/wp-content/themes/mstnsuzqvu" echo "quarantine=$Q" cd ~/domains/egyvolt.com/public_html wp plugin deactivate wp-console file-manager --allow-root 2>&1 wp plugin list --fields=name,status,version --allow-root | grep -E 'wp-console|file-manager|translatepress|yith-woocommerce-wishlist' cd ~/domains/egyvolt.com/public_html wp plugin deactivate wp-console --skip-plugins --allow-root 2>&1 wp plugin list --fields=name,status,version --skip-plugins --allow-root | grep -E 'wp-console|file-manager|translatepress|yith-woocommerce-wishlist' cd ~/domains/egyvolt.com/public_html wp eval '$active=(array)get_option("active_plugins", array()); $before=$active; $active=array_values(array_filter($active, function($p){ return strpos($p, "wp-console/") === false && $p !== "wp-console.php"; })); update_option("active_plugins", $active); echo "before=".implode(",", $before)."\n"; echo "after=".implode(",", $active)."\n";' --skip-plugins --allow-root wp plugin list --fields=name,status,version --skip-plugins --allow-root | grep -E 'wp-console|file-manager|translatepress|yith-woocommerce-wishlist' cd ~/domains/egyvolt.com/public_html wp option get active_plugins --format=json --skip-plugins --allow-root | grep -o 'wp-console[^" ]*' || echo 'wp-console not in active_plugins' wp plugin is-active wp-console --skip-plugins --allow-root; echo "is_active_exit=$?" ls -la wp-content/mu-plugins 2>/dev/null find wp-content/mu-plugins -maxdepth 1 -type f -name '*.php' -print -exec grep -n 'wp-console\|active_plugins' {} \; 2>/dev/null cd ~/domains/egyvolt.com/public_html wp option patch delete active_plugins 16 --skip-plugins --allow-root wp option get active_plugins --format=json --skip-plugins --allow-root | grep -o 'wp-console[^" ]*' || echo 'wp-console not in active_plugins' wp plugin is-active wp-console --skip-plugins --allow-root; echo "is_active_exit=$?" cd ~/domains/egyvolt.com/public_html wp eval 'global $wpdb; $active=(array)get_option("active_plugins", array()); $active=array_values(array_filter($active, function($p){ return $p !== "wp-console/wp-console.php"; })); $serialized=serialize($active); $rows=$wpdb->query($wpdb->prepare("UPDATE {$wpdb->options} SET option_value=%s WHERE option_name=%s", $serialized, "active_plugins")); wp_cache_flush(); echo "rows=$rows\n"; echo $serialized."\n";' --skip-plugins --allow-root wp option get active_plugins --format=json --skip-plugins --allow-root | grep -o 'wp-console[^" ]*' || echo 'wp-console not in active_plugins' wp plugin is-active wp-console --skip-plugins --allow-root; echo "is_active_exit=$?" cd ~ for d in domains/*/public_html; do if [ -f "$d/wp-config.php" ]; then echo "=== FINAL $d ==="; (cd "$d" && wp core verify-checksums --allow-root 2>&1 | head -n 20 && wp db query "SELECT ROUND(SUM(data_length+index_length)/1024/1024,2) AS db_mb FROM information_schema.tables WHERE table_schema=DATABASE();" --allow-root 2>/dev/null && wp cache flush --allow-root 2>/dev/null || true); fi; done for url in https://covering-eg.com/ https://egyvolt.com/ https://global-firefighting.com/ https://sentinellegalconsulting.com/; do echo "=== $url ==="; curl -k -sI "$url" | head -n 6; done exit find ~/domains/global-firefighting.com ~/domains/sentinellegalconsulting.com -maxdepth 4 -type f \( -name 'error_log' -o -name '*.log' \) -printf '%TY-%Tm-%Td %TH:%TM %s %p\n' 2>/dev/null | sort -r | head -n 50 printf '\nGLOBAL wp-config head relevant\n' sed -n '1,140p' ~/domains/global-firefighting.com/public_html/wp-config.php | sed -n '1,120p' printf '\nSENTINEL wp-config head relevant\n' sed -n '1,140p' ~/domains/sentinellegalconsulting.com/public_html/wp-config.php | sed -n '1,120p' find ~ -maxdepth 5 -type f \( -name '*error*log*' -o -name 'error_log' -o -path '*logs*' \) -printf '%TY-%Tm-%Td %TH:%TM %s %p\n' 2>/dev/null | sort -r | head -n 80 cd ~/domains/sentinellegalconsulting.com/public_html wp option get template --allow-root wp option get stylesheet --allow-root wp plugin list --status=active --fields=name,version --allow-root | head -n 60 php -d display_errors=1 -r 'define("WP_USE_THEMES", false); require "wp-blog-header.php"; echo "sentinel_boot_ok\n";' 2>&1 | head -n 80 cd ~/domains/global-firefighting.com/public_html php -d display_errors=1 -r 'define("WP_USE_THEMES", false); require "wp-blog-header.php"; echo "global_boot_ok\n";' 2>&1 | head -n 80 cd ~/domains/global-firefighting.com/public_html nl -ba wp-config.php | sed -n '1,180p' nl -ba wp-blog-header.php | sed -n '1,60p' tail -80 ~/domains/global-firefighting.com/public_html/wp-content/error_log 2>/dev/null tail -80 ~/.logs/error_log_global-firefighting_com 2>/dev/null tail -80 ~/.logs/error_log_sentinellegalconsulting_com 2>/dev/null cd ~/domains/global-firefighting.com/public_html ls -lh wp-config.php wp-load.php wp-content/module.php wp-content/inputs.php 2>/dev/null || true wc -c wp-config.php cat -vet wp-config.php | head -n 120 find wp-content -maxdepth 2 -type f \( -name 'module.php' -o -name 'inputs.php' -o -name '*.php' \) -printf '%TY-%Tm-%Td %TH:%TM %s %p\n' 2>/dev/null | grep -E 'module.php|inputs.php|wp-content/[a-zA-Z0-9_-]+\.php$' | head -n 80 cd ~/domains/global-firefighting.com find . ~ -maxdepth 5 -type f \( -name 'wp-config*.php*' -o -name '*global*config*' -o -name '*.sql' \) -printf '%TY-%Tm-%Td %TH:%TM %s %p\n' 2>/dev/null | sort -r | head -n 100 find ~/security-quarantine -type f -path '*global*wp-config*' -o -path '*global*config*' 2>/dev/null | head -n 50 cd ~/domains/global-firefighting.com/public_html grep -RIl --exclude='wp-config.php' --exclude-dir=wp-content/cache --exclude-dir=wp-content/uploads 'DB_NAME\|DB_USER\|DB_PASSWORD\|global-firefighting' . 2>/dev/null | head -n 100 find wp-content -maxdepth 3 -type f \( -name '*.wpress' -o -name '*.sql' -o -name '*.zip' -o -name '*.tar.gz' \) -printf '%TY-%Tm-%Td %TH:%TM %s %p\n' 2>/dev/null | sort -r | head -n 50 cd ~/domains/global-firefighting.com/public_html strings wp-content/ai1wm-backups/global-firefighting-com-20240902-084918-81z6si.wpress | grep -A4 -B2 "DB_NAME\|DB_USER\|DB_PASSWORD\|table_prefix" | head -n 120 curl -k -sI https://sentinellegalconsulting.com/ | head -n 12 curl -k -s https://sentinellegalconsulting.com/ | head -c 500; echo cd ~/domains/sentinellegalconsulting.com/public_html wp litespeed-purge all --allow-root 2>&1 | head -n 80 || true wp plugin deactivate litespeed-cache --allow-root 2>&1 | head -n 80 curl -k -sI https://sentinellegalconsulting.com/ | head -n 12 cd ~/domains/sentinellegalconsulting.com/public_html wp plugin activate litespeed-cache --allow-root 2>&1 | head -n 80 curl -k -sI https://sentinellegalconsulting.com/ | head -n 12 for url in https://covering-eg.com/ https://egyvolt.com/ https://sentinellegalconsulting.com/ https://global-firefighting.com/; do echo "=== $url ==="; curl -k -sI "$url" | head -n 6; done cd ~/domains/egyvolt.com/public_html wp db query "SELECT ROUND(SUM(data_length+index_length)/1024/1024,2) AS db_mb FROM information_schema.tables WHERE table_schema=DATABASE();" --allow-root 2>/dev/null cd ~ find ~/security-quarantine -maxdepth 3 -type d -mtime -1 -print exit cd ~/domains/egyvolt.com/public_html pwd wp option get siteurl --allow-root wp db search '0227739211' wp_options wp_posts wp_postmeta --allow-root | head -n 80 wp db search '01140480509' wp_options wp_posts wp_postmeta --allow-root | head -n 80 wp db search '+2 0227739211' wp_options wp_posts wp_postmeta --allow-root | head -n 80 wp db search '+20 01140480509' wp_options wp_posts wp_postmeta --allow-root | head -n 80 wp db query "SELECT option_id, option_name, LENGTH(option_value) len FROM wp_options WHERE option_value LIKE '%0227739211%' OR option_value LIKE '%01140480509%'; SELECT meta_id, post_id, meta_key, LENGTH(meta_value) len FROM wp_postmeta WHERE meta_value LIKE '%01140480509%' OR meta_value LIKE '%201140480509%';" --allow-root wp db query "SELECT ID, post_title, post_type, post_status FROM wp_posts WHERE ID IN (SELECT post_id FROM wp_postmeta WHERE meta_value LIKE '%01140480509%' OR meta_value LIKE '%201140480509%');" --allow-root mkdir -p ~/db-repair-egyvolt wp db export ~/db-repair-egyvolt/phone-users-before-$(date +%Y%m%d%H%M%S).sql --tables=wp_options,wp_postmeta,wp_users,wp_usermeta --allow-root cat > /tmp/egyvolt-update-phone.php <<'PHP' <?php $new_display = '01092721322'; $new_whatsapp = '201092721322'; $options = array('theme_mods_electro-child', 'electro_options', 'electro_options-transients'); foreach ($options as $option_name) { $value = get_option($option_name, null); if ($value === null) { continue; } $changed = false; if (is_array($value)) { array_walk_recursive($value, function (&$item) use (&$changed, $new_display) { if (!is_string($item)) { return; } $old = $item; $item = str_replace( array('+2 0227739211, +20 01140480509', '+2 0227739211, +20 01122135990', '+201140480509', '+20 01140480509', '01140480509', '0227739211'), $new_display, $item ); if ($item !== $old) { $changed = true; } }); } elseif (is_string($value)) { $old = $value; $value = str_replace( array('+2 0227739211, +20 01140480509', '+2 0227739211, +20 01122135990', '+201140480509', '+20 01140480509', '01140480509', '0227739211'), $new_display, $value ); $changed = ($value !== $old); } if ($changed) { update_option($option_name, $value); echo "updated option {$option_name}\n"; } } $rows = get_posts(array( 'post_type' => 'whatsapp-accounts', 'post_status' => 'any', 'numberposts' => -1, 'fields' => 'ids', )); foreach ($rows as $post_id) { $value = get_post_meta($post_id, 'nta_wa_account_info', true); if (!is_array($value)) { continue; } $old = $value; if (isset($value['number'])) { $value['number'] = $new_whatsapp; } if (isset($value['title'])) { $value['title'] = 'Egy Volt'; } if ($value !== $old) { update_post_meta($post_id, 'nta_wa_account_info', $value); echo "updated whatsapp account {$post_id}\n"; } } wp_cache_flush(); PHP wp eval-file /tmp/egyvolt-update-phone.php --allow-root wp eval '$rows=get_posts(array("post_type"=>"whatsapp-accounts","post_status"=>"any","numberposts"=>-1,"fields"=>"ids")); foreach($rows as $post_id){ $value=get_post_meta($post_id,"nta_wa_account_info",true); if(is_array($value)){ $value["number"]="01092721322"; update_post_meta($post_id,"nta_wa_account_info",$value); echo "set whatsapp {$post_id} to 01092721322\n"; }} wp_cache_flush();' --allow-root wp db search '0227739211' wp_options wp_posts wp_postmeta --allow-root | head -n 80 wp db search '01140480509' wp_options wp_posts wp_postmeta --allow-root | head -n 80 wp db search '01122135990' wp_options wp_posts wp_postmeta --allow-root | head -n 80 wp db search '01092721322' wp_options wp_posts wp_postmeta --allow-root | head -n 120 ls -lh ~/db-repair-egyvolt | tail -n 5 cat > /tmp/egyvolt-force-phone.php <<'PHP' <?php require __DIR__ . '/../home/u851593458/domains/egyvolt.com/public_html/wp-load.php'; PHP cd ~/domains/egyvolt.com/public_html wp db export ~/db-repair-egyvolt-phone-users-before-$(date +%Y%m%d%H%M%S).sql --tables=wp_options,wp_postmeta,wp_users,wp_usermeta --allow-root cat > /tmp/egyvolt-force-phone.php <<'PHP' <?php $new_display = '01092721322'; $old_values = array( '+2 0227739211, +20 01140480509', '+2 0227739211, +20 01122135990', '+201140480509', '+20 01140480509', '+2001122135990', '+20 01122135990', '201140480509', '201122135990', '01140480509', '01122135990', '0227739211', ); function ev_replace_deep($value, $old_values, $new_display, &$changed) { if (is_array($value)) { foreach ($value as $k => $v) { $value[$k] = ev_replace_deep($v, $old_values, $new_display, $changed); } return $value; } if (is_object($value)) { foreach ($value as $k => $v) { $value->$k = ev_replace_deep($v, $old_values, $new_display, $changed); } return $value; } if (is_string($value)) { $old = $value; $value = str_replace($old_values, $new_display, $value); $value = str_replace('https://api.whatsapp.com/send?phone=' . $new_display, 'https://api.whatsapp.com/send?phone=' . $new_display, $value); if ($value !== $old) { $changed = true; } } return $value; } global $wpdb; foreach (array('theme_mods_electro-child', 'electro_options', 'electro_options-transients') as $option_name) { $raw = $wpdb->get_var($wpdb->prepare("SELECT option_value FROM {$wpdb->options} WHERE option_name=%s", $option_name)); if ($raw === null) { continue; } $value = maybe_unserialize($raw); $changed = false; $value = ev_replace_deep($value, $old_values, $new_display, $changed); if ($changed) { $serialized = maybe_serialize($value); $result = $wpdb->query($wpdb->prepare("UPDATE {$wpdb->options} SET option_value=%s WHERE option_name=%s", $serialized, $option_name)); echo "option {$option_name} result=" . var_export($result, true) . " error={$wpdb->last_error}\n"; } } $metas = $wpdb->get_results("SELECT meta_id, meta_value FROM {$wpdb->postmeta} WHERE meta_key='nta_wa_account_info'"); foreach ($metas as $meta) { $value = maybe_unserialize($meta->meta_value); if (!is_array($value)) { continue; } $value['number'] = $new_display; $serialized = maybe_serialize($value); $result = $wpdb->query($wpdb->prepare("UPDATE {$wpdb->postmeta} SET meta_value=%s WHERE meta_id=%d", $serialized, $meta->meta_id)); echo "whatsapp meta {$meta->meta_id} result=" . var_export($result, true) . " error={$wpdb->last_error}\n"; } wp_cache_flush(); PHP wp eval-file /tmp/egyvolt-force-phone.php --skip-plugins --allow-root cd ~/domains/egyvolt.com/public_html mkdir -p wp-content/mu-plugins cat > wp-content/mu-plugins/egyvolt-phone-runtime-fix.php <<'PHP' <?php /** * Plugin Name: Egyvolt Phone Runtime Fix * Description: Runtime replacement for footer/contact/WhatsApp numbers while DB UPDATE permission is unavailable. * Version: 1.0.0 */ if (!defined('ABSPATH')) { exit; } function egyvolt_phone_runtime_replacements($html) { if (!is_string($html) || $html === '') { return $html; } return str_replace( array( '+2 0227739211, +20 01140480509', '+2 0227739211, +20 01122135990', '+20 01140480509', '+20 01122135990', '+201140480509', '+2001122135990', '201140480509', '201122135990', '01140480509', '01122135990', '0227739211', 'tel:+2001122135990', 'tel:+201140480509', 'https://api.whatsapp.com/send?phone=201122135990', 'https://api.whatsapp.com/send?phone=201140480509', 'https://wa.me/201122135990', 'https://wa.me/201140480509', ), array( '01092721322', '01092721322', '01092721322', '01092721322', '01092721322', '01092721322', '01092721322', '01092721322', '01092721322', '01092721322', '01092721322', 'tel:01092721322', 'tel:01092721322', 'https://api.whatsapp.com/send?phone=01092721322', 'https://api.whatsapp.com/send?phone=01092721322', 'https://wa.me/01092721322', 'https://wa.me/01092721322', ), $html ); } add_action('template_redirect', function () { if (is_admin() || wp_doing_ajax() || wp_is_json_request()) { return; } ob_start('egyvolt_phone_runtime_replacements'); }, 0); PHP php -l wp-content/mu-plugins/egyvolt-phone-runtime-fix.php chmod 644 wp-content/mu-plugins/egyvolt-phone-runtime-fix.php curl -k -s https://egyvolt.com/ | grep -Eo '01092721322|0227739211|01140480509|01122135990|201140480509|201122135990|api\.whatsapp\.com/send\?phone=[0-9]+' | sort | uniq -c wp user list --role=administrator --fields=ID,user_login,user_email,display_name --format=table --allow-root cat > /tmp/egyvolt-rotate-admins.sh <<'SH' #!/usr/bin/env bash set -u cd "$HOME/domains/egyvolt.com/public_html" || exit 1 wp user list --role=administrator --field=ID --allow-root 2>/dev/null | while read -r id; do [ -z "$id" ] && continue login=$(wp user get "$id" --field=user_login --allow-root 2>/dev/null) pass=$(openssl rand -base64 24 | tr -dc 'A-Za-z0-9' | head -c 22) out=$(wp user update "$id" --user_pass="$pass" --allow-root 2>&1) rc=$? if [ "$rc" -eq 0 ]; then printf 'UPDATED\t%s\t%s\t%s\n' "$id" "$login" "$pass" else printf 'FAILED\t%s\t%s\t%s\n' "$id" "$login" "$out" fi done SH bash /tmp/egyvolt-rotate-admins.sh wp cache flush --allow-root || true curl -k -s https://egyvolt.com/ | grep -Eo '01092721322|0227739211|01140480509|01122135990|201140480509|201122135990|api\.whatsapp\.com/send\?phone=[0-9]+' | sort | uniq -c curl -k -sI https://egyvolt.com/ | head -n 8 exit cd ~/domains/egyvolt.com/public_html wp db query "SELECT table_name, table_rows, ROUND(data_length/1024/1024,2) data_mb, ROUND(index_length/1024/1024,2) index_mb, ROUND(data_free/1024/1024,2) free_mb, ROUND((data_length+index_length)/1024/1024,2) used_mb FROM information_schema.tables WHERE table_schema=DATABASE() ORDER BY (data_length+index_length+data_free) DESC LIMIT 20; SELECT ROUND(SUM(data_length+index_length)/1024/1024,2) used_mb, ROUND(SUM(data_free)/1024/1024,2) free_mb, ROUND(SUM(data_length+index_length+data_free)/1024/1024,2) allocated_mb FROM information_schema.tables WHERE table_schema=DATABASE();" --allow-root cd ~/domains/egyvolt.com/public_html cat > /tmp/rebuild-egyvolt-table.sh <<'SH' #!/usr/bin/env bash set -euo pipefail table="$1" copy="${table}_compact_$(date +%s)" backup="${table}_old_$(date +%s)" echo "Rebuilding $table -> $copy" wp db query "CREATE TABLE \`$copy\` LIKE \`$table\`;" --allow-root wp db query "INSERT INTO \`$copy\` SELECT * FROM \`$table\`;" --allow-root orig_count=$(wp db query "SELECT COUNT(*) FROM \`$table\`;" --skip-column-names --allow-root | tail -n 1) copy_count=$(wp db query "SELECT COUNT(*) FROM \`$copy\`;" --skip-column-names --allow-root | tail -n 1) echo "counts original=$orig_count copy=$copy_count" if [ "$orig_count" != "$copy_count" ]; then echo "Count mismatch, aborting" >&2 exit 1 fi wp db query "RENAME TABLE \`$table\` TO \`$backup\`, \`$copy\` TO \`$table\`;" --allow-root echo "swapped backup=$backup" wp db query "DROP TABLE \`$backup\`;" --allow-root echo "dropped old $backup" SH bash /tmp/rebuild-egyvolt-table.sh wp_trp_original_strings bash /tmp/rebuild-egyvolt-table.sh wp_trp_dictionary_en_us_ar bash /tmp/rebuild-egyvolt-table.sh wp_trp_original_meta bash /tmp/rebuild-egyvolt-table.sh wp_yith_wcwl_lists bash /tmp/rebuild-egyvolt-table.sh wp_yith_wcwl cd ~/domains/egyvolt.com/public_html wp db query "ALTER TABLE wp_yith_wcwl FORCE;" --allow-root 2>&1 | head -n 40 wp db query "SELECT table_name, ROUND(data_free/1024/1024,2) free_mb, ROUND((data_length+index_length)/1024/1024,2) used_mb FROM information_schema.tables WHERE table_schema=DATABASE() AND table_name IN ('wp_yith_wcwl','wp_yith_wcwl_lists','wp_trp_original_strings','wp_trp_dictionary_en_us_ar','wp_trp_original_meta');" --allow-root cd ~/domains/egyvolt.com/public_html for t in wp_trp_original_strings wp_trp_dictionary_en_us_ar wp_trp_original_meta wp_yith_wcwl_lists; do echo "FORCE $t"; wp db query "ALTER TABLE $t FORCE;" --allow-root; done wp db query "SELECT table_name, table_rows, ROUND(data_length/1024/1024,2) data_mb, ROUND(index_length/1024/1024,2) index_mb, ROUND(data_free/1024/1024,2) free_mb, ROUND((data_length+index_length)/1024/1024,2) used_mb FROM information_schema.tables WHERE table_schema=DATABASE() ORDER BY (data_length+index_length+data_free) DESC LIMIT 20; SELECT ROUND(SUM(data_length+index_length)/1024/1024,2) used_mb, ROUND(SUM(data_free)/1024/1024,2) free_mb, ROUND(SUM(data_length+index_length+data_free)/1024/1024,2) allocated_mb FROM information_schema.tables WHERE table_schema=DATABASE();" --allow-root wp cache flush --allow-root || true curl -k -sI https://egyvolt.com/ | head -n 8 curl -k -s https://egyvolt.com/ | grep -Eo '01092721322|0227739211|01140480509|01122135990|201140480509|201122135990|api\.whatsapp\.com/send\?phone=[0-9]+' | sort | uniq -c exit