|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 51
Members: 0
Total: 51
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
help me decode this script |
|
Posted: Tue Apr 03, 2012 11:49 pm |
|
|
botak |
Beginner |
|
|
Joined: Apr 04, 2012 |
Posts: 1 |
|
|
|
|
|
|
|
hello,
can anyone help me decode this code and tell me step by step how to decode it:
Code: | <?php if (!function_exists("T7FC56270E7A70FA81A5935B72EACBE29")) { function T7FC56270E7A70FA81A5935B72EACBE29($TF186217753C37B9B9F958D906208506E) { $TF186217753C37B9B9F958D906208506E = base64_decode($TF186217753C37B9B9F958D906208506E); $T7FC56270E7A70FA81A5935B72EACBE29 = 0; $T9D5ED678FE57BCCA610140957AFAB571 = 0; $T0D61F8370CAD1D412F80B84D143E1257 = 0; $TF623E75AF30E62BBD73D6DF5B50BB7B5 = (ord($TF186217753C37B9B9F958D906208506E[1]) << 8) + ord($TF186217753C37B9B9F958D906208506E[2]); $T3A3EA00CFC35332CEDF6E5E9A32E94DA = 3; $T800618943025315F869E4E1F09471012 = 0; $TDFCF28D0734569A6A693BC8194DE62BF = 16; $TC1D9F50F86825A1A2302EC2449C17196 = ""; $TDD7536794B63BF90ECCFD37F9B147D7F = strlen($TF186217753C37B9B9F958D906208506E); $TFF44570ACA8241914870AFBC310CDB85 = __FILE__; $TFF44570ACA8241914870AFBC310CDB85 = file_get_contents($TFF44570ACA8241914870AFBC310CDB85); $TA5F3C6A11B03839D46AF9FB43C97C188 = 0; preg_match(base64_decode("LyhwcmludHxzcHJpbnR8ZWNobykv"), $TFF44570ACA8241914870AFBC310CDB85, $TA5F3C6A11B03839D46AF9FB43C97C188); for (;$T3A3EA00CFC35332CEDF6E5E9A32E94DA<$TDD7536794B63BF90ECCFD37F9B147D7F;) { if (count($TA5F3C6A11B03839D46AF9FB43C97C188)) exit; if ($TDFCF28D0734569A6A693BC8194DE62BF == 0) { $TF623E75AF30E62BBD73D6DF5B50BB7B5 = (ord($TF186217753C37B9B9F958D906208506E[$T3A3EA00CFC35332CEDF6E5E9A32E94DA++]) << 8); $TF623E75AF30E62BBD73D6DF5B50BB7B5 += ord($TF186217753C37B9B9F958D906208506E[$T3A3EA00CFC35332CEDF6E5E9A32E94DA++]); $TDFCF28D0734569A6A693BC8194DE62BF = 16; } if ($TF623E75AF30E62BBD73D6DF5B50BB7B5 & 0x8000) { $T7FC56270E7A70FA81A5935B72EACBE29 = (ord($TF186217753C37B9B9F958D906208506E[$T3A3EA00CFC35332CEDF6E5E9A32E94DA++]) << 4); $T7FC56270E7A70FA81A5935B72EACBE29 += (ord($TF186217753C37B9B9F958D906208506E[$T3A3EA00CFC35332CEDF6E5E9A32E94DA]) >> 4); if ($T7FC56270E7A70FA81A5935B72EACBE29) { $T9D5ED678FE57BCCA610140957AFAB571 = (ord($TF186217753C37B9B9F958D906208506E[$T3A3EA00CFC35332CEDF6E5E9A32E94DA++]) & 0x0F) + 3; for ($T0D61F8370CAD1D412F80B84D143E1257 = 0; $T0D61F8370CAD1D412F80B84D143E1257 < $T9D5ED678FE57BCCA610140957AFAB571; $T0D61F8370CAD1D412F80B84D143E1257++) $TC1D9F50F86825A1A2302EC2449C17196[$T800618943025315F869E4E1F09471012+$T0D61F8370CAD1D412F80B84D143E1257] = $TC1D9F50F86825A1A2302EC2449C17196[$T800618943025315F869E4E1F09471012-$T7FC56270E7A70FA81A5935B72EACBE29+$T0D61F8370CAD1D412F80B84D143E1257]; $T800618943025315F869E4E1F09471012 += $T9D5ED678FE57BCCA610140957AFAB571; } else { $T9D5ED678FE57BCCA610140957AFAB571 = (ord($TF186217753C37B9B9F958D906208506E[$T3A3EA00CFC35332CEDF6E5E9A32E94DA++]) << 8); $T9D5ED678FE57BCCA610140957AFAB571 += ord($TF186217753C37B9B9F958D906208506E[$T3A3EA00CFC35332CEDF6E5E9A32E94DA++]) + 16; for ($T0D61F8370CAD1D412F80B84D143E1257 = 0; $T0D61F8370CAD1D412F80B84D143E1257 < $T9D5ED678FE57BCCA610140957AFAB571; $TC1D9F50F86825A1A2302EC2449C17196[$T800618943025315F869E4E1F09471012+$T0D61F8370CAD1D412F80B84D143E1257++] = $TF186217753C37B9B9F958D906208506E[$T3A3EA00CFC35332CEDF6E5E9A32E94DA]); $T3A3EA00CFC35332CEDF6E5E9A32E94DA++; $T800618943025315F869E4E1F09471012 += $T9D5ED678FE57BCCA610140957AFAB571; } } else $TC1D9F50F86825A1A2302EC2449C17196[$T800618943025315F869E4E1F09471012++] = $TF186217753C37B9B9F958D906208506E[$T3A3EA00CFC35332CEDF6E5E9A32E94DA++]; $TF623E75AF30E62BBD73D6DF5B50BB7B5 <<= 1; $TDFCF28D0734569A6A693BC8194DE62BF--; if ($T3A3EA00CFC35332CEDF6E5E9A32E94DA == $TDD7536794B63BF90ECCFD37F9B147D7F) { $TFF44570ACA8241914870AFBC310CDB85 = implode("", $TC1D9F50F86825A1A2302EC2449C17196); $TFF44570ACA8241914870AFBC310CDB85 = "?".">".$TFF44570ACA8241914870AFBC310CDB85."<"."?"; return $TFF44570ACA8241914870AFBC310CDB85; } } } } echo(T7FC56270E7A70FA81A5935B72EACBE29("QAABPGxpbmsgaHJlZj0iLi4vADAAAHN0eWxlLmNzcyIgcmVsPSKAAAECc2hlZXQiIHR5cGU9InRlEAB4dC8CEi8+DQoNCjw/DQokZAACID0gJF9HRVRbJ2QnXTsBIGagRwEnZgEjYnV0dG9uAXJQT1MCoAETAdMA8GtlbG9tcG9rBHEB4wElAgNjaGVjDgdrYm94A/gBNQITZmlsdGVyAfIIcgEDh4oBw2Rlc2MBpwDhAYIKYGRlbAGWIgDQIoQBC8FpZigkAMApew0KCSRpZF8IpegqAqEBgA3gIAAQRGVsMSgBtSwCeCwDSSmgOALgCQK6X2tvbnRhawMvECQDIiRzccAACZEJMWV0ZSBmcm9tIGhwIG5hABh0dXJhbCBqb2luIAfFBRQgd2gNEGVyZSAImAsAJwjJJyAiCOFteXNxAN5sX3F1ZXJ5KAaBBxF9HKEAQQ/BGYM9AYA9IkNBUkkiEHEO8CAgJG5hbWGeAAVAJF8aEgDhEuEBw3EgLj0iIGFuZIAvCXYgTElLRSAnJSQKhSUIAwayBnEaI6m5BfYgAUAhF4BzYwE3BcIgAVIHkBDgc2MMMcEsAXMAYyR0YXV0IXEiJh2RPQLSAld9ZR/1bHNlHJAC0wBjAjIFAQJ3AZQEwQyQIATEMQIWyAELUAIyJHEDgU9SREVSIEJZICQMQ/s6CiMC1gkyBHMCAz0ChAIhDQoEwCegBrFhMOEiJ5o/ZAtQJmYCUAOSAlEAkmFuDXIB/HgCAQ0AAApyZXF1aXJlKCJpbmNsdWQAAGVfbGliL3BhZ2luYWNhby4AHWNsYXNzLnBocCIpHzAG8B7yMgvQgIYf6SJTRUxFQ1QjSkZST00cRyVPIQYBPScwJyAQgAWiJHF1YW50b3MFlgBsbnVtX3Jvd3MoAaAmEDIH8wpUICKfBgoiZy4BAAnSCcAoIUZwZWxlY3QImTICYQL4dGVnb3JpOCYsJMUxIwDmCn4KZkxJTQAASVQgJGluaWNpbywgJGxpbQgAaXRlXxMQcmVzdWx0YWRvc18CB3Bvcl9wZzHiJGRhdGE9ElkKEQxhA8QkY2JhcmkOr0LAAzACIQ0KP1EjdGEAAGJsZSB3aWR0aD0iMTAwJSIAACBib3JkZXI9IjAiIGNlbGwAQ3BhZGRpbmc9MwDic3BhYwDjBAAQADx0cgBiZCBoZWlnaHQ9IjI2AAAiID48ZGl2IGFsaWduPSJjOABlbk7ABKAeYT0iaGVhZCI+IEtFAIJMT01QT0s8LwKwPjwvdGQEgS+3BQTzLwlCARFiBfFbcACCPEZPUk1FcG1dkIABVQVmb3JtIiBtZXRob2Q9Ij7BBQIiIGVuY1/jbRNAaXBhcnQtAnEtgPoS4SIgYWN0aW8JgApwBZAGog/lNw/fbE+7cw70IjEMMBDYAQAKEDaCIBBjAMMAYjwM8gCyn2AAVjxha8QyQCDFNJAAtS4KMRGQSW5wdXTD8C1HHHB1PC9hBrYE8xMEANMAYwcxJm5iczMWcDsB3woQZCA2YnEgZF9yGqEiBTwEZGntwAfyE/Nz0SIXBAp1Ii9wBFB1cGZpZWxkImj4IHWBAAACIDwEiXN1YiyABKVbEwSDAMV2YWx/3XUdUFwyBS4NCgDQITEAcCtxDEA8HC8r/yvyMSv6NjYxIAPQIBFyEaUpoWxpc4PAAaRkLJAbVTwjDj89ToU/PiZSpGv4Ij5ObxqBCZAsonSHYAPfdXRhbgPHFRYwyWEwpQmRZD5KTUwChCBLT05UQTJwdAV0PlNNUwZXPkH5gCziARU0AwPQjnFpPUSkS5B3aGlsZSgkwA1O0EL0ZmV0Y2hfYXJyYXWAMZEpbJEwEw0KIHF4eT1zdHJpcHM7wGhlUoAEEC/cWyIPeV1EwQNWUD0D7wPjAo0iBHcRhQO/WyLiAAHFAvNikGkrKw3QaWYgKCRpICUgAIAyICE9IDApIHQ0JGJnY29sb4B3loEiI0RGREZGRmkBdmkCOkUAEgIyheFZgD8gdHJMrQV0PSIhUQDUPz4iIG9uTQIIb3VzZU92U8F0aGlzLqkSLmJhAABja2dyb3VuZD0nI0YwRkZCF7w4JzsC93VTYALvAuIGGic7MR3AJbIo8Gk/4A8i5T/ALFR0ZF9sZWZ0PiBG6pxCRsEAkldvLi5RJhxYPQZxAQgMwD4BMRb1PwTwSDAmVAgoSv1joeM9Qw3AdKYHXwFzcVKihKZ7C5oGsCAngiwBCQmVUCQFRCjhCQkJZWNobyAiDNWPwFOgb3V0tZAMwACTU2IMyivZPjxpbWcgAABzcmM9aW1hZ2VzL3NlbXVhCk4ucG5nbjUwFDBhPh8xCQkhhQd3A+91Pf5hZB1wBBADRbdgCQz7DMELFZLxFGULQAC1C2NhGoVtcDsXaBhvIgwHIgwUZWRpdAwCIilQ74AjgAEBewovDRIIQQBBCIYc8V9TRVJWRVIAAVsnUkVRVUVTVF9VUkknXUkg8AAIkcKwCB8qQWNsaWNrPSJyZXR1cgAobiBjb25maXJtTNigKCtBLCAnAQtIQVBVUyBCt+BTICcpC08vBbALMf4dCyQA4AsfC1BOAiXATDcgfSA/ODZr5FpBMnui+OcCsDCQPgB6EHzgNSI+b+M7oQ+xICArBiXwAMD9AWNxA1EAgTMRixkEdjMFwEp1bWxhaCATMZP+oxQ/PnhwaXMEUFhUjuoD1gmQCnQ4cHZTZCA/QAAgLFIkaW5zdGFuY2lhLT5nZRHwcmFQr/UoKTsOgAXFD/aQRgtAU0NSSQAAUFQgTEFOR1VBR0U9IkphdhQIYVNjWZB0QUQhLS0gQmW1EA0KZmhgdY/wjiAgkjJBbGwoURKF8CAodmFyJMkgaq/wMDsAcDw9DkKioz8+ATArKwKyUBdi66JleVAoImRvY3VtnCAuBOIBoASAQh5tANZbIiArBKArICJdtiJYoQJAAgNlhIP2gD0gZmHNQCkgAWogdHJ1ZVuQxdD/7AAwCzgLsPOxC18LX63xC18LX/iSC19qC5ALX2Nr+D8LUwoBC00MkgtfbiBzd2l0wAtPC08LT9NRC0/sIgtPFp0U+yEA+AomLy8gRe4gLS0+JCAvc+BzIuIAsADQPyABwEjGYOHOAShQDQo=")); ?> |
Thanks, |
|
_________________ newbie in the house |
|
|
|
|
|
kelompok exploit |
|
Posted: Fri Apr 06, 2012 9:03 pm |
|
|
Alfraid |
Beginner |
|
|
Joined: Apr 06, 2012 |
Posts: 2 |
|
|
|
|
|
|
|
It is Indonesian.
comment out the part:
if (count($TA5F3C6A11B03839D46AF9FB43C97C188)) exit;
otherwise it will not work.
Then copy it in a run.php file run it in linux box:
php run.php> injected.php
the result will be the exploit that expects GET parameters:
g,f,button,kelompok,checkbox,filter,desc,del |
|
|
|
|
|
|
|
|
Posted: Tue Jul 03, 2012 1:32 pm |
|
|
astra1993 |
Advanced user |
|
|
Joined: Jun 20, 2012 |
Posts: 125 |
|
|
|
|
|
|
|
This is the decoded form. Also it is very confusing that the script 'echo's the PHP code instead of evaluating it.
Code: |
<link href="../../style.css" rel="stylesheet" type="text/css" />
<?
$d = $_GET['d'];
$f = $_GET['f'];
$button = $_POST['button'];
$kelompok= $_POST['kelompok'];
$checkbox = $_POST['checkbox'];
$filter = $_GET['filter'];
$desc = $_GET['desc'];
$del = $_GET["del"];
if($del){
$id_kelompok = $del;
Del1(kelompok,id_kelompok,$id_kelompok);
Del1(kelompok_kontak,id_kelompok,$id_kelompok);
$sql = "delete from hp natural join kelompok_kontak where id_kelompok = '$id_kelompok' ";
mysql_query($sql);
}
if($button=="CARI"){
$nama = $_POST[nama];
$q .=" and kelompok LIKE '%$kelompok%' ";
}
if($filter){
if(!$desc){
$desc = "desc";
$tautx = "&desc=$desc";
}else{
$desc = "";
$taut .= "&desc=1";
}
$q = "ORDER BY $filter $desc";
$taut .= "&filter=$filter";
}
$tautan = "?d=$d&f=$f$taut";
$tautanx = "?d=$d&f=$f$tautx";
require("include_lib/paginacao.class.php");
$query2 = mysql_query("SELECT id_kelompok FROM kelompok where id_kelompok !='0' $q ");
$quantos = mysql_num_rows($query2);
include "paging.inc.php";
$sql="select id_kelompok,id_kategori_kelompok,kelompok from kelompok where id_kelompok!='0' $q LIMIT $inicio, $limite_de_resultados_por_pg ";
$data=mysql_query($sql);
$cbaris = mysql_num_rows($data);
?>
<table width="100%" border="0" cellpadding=3 cellspacing=3 >
<tr>
<td height="26" ><div align="center" class="head"> KELOMPOK</div></td>
</tr>
</table>
<br>
<br>
<FORM name="checkboxform" method="POST" enctype="multipart-form-data" action="" >
<table width="70%" border="0" cellspacing="1" cellpadding="1">
<tr>
<td>
<a href="?d=kelompok&f=kelompok.form"> Input kelompok baru</a>
</td>
<td> ;;</td>
<td class="td_right">
<input type="text" name="kelompok" id="textfield" />
<input type="submit" name="button" id="button" value="CARI" />
</td>
</tr>
</table>
<table width="70%" border="0" cellpadding=1 cellspacing=1 >
<tr class="headlist" >
<td ><a href="<?=$tautanx?>&filter=id_kelompok">No</a></td>
<td ><a href="<?=$tautan?>&filter=kelompok"> KELOMPOK</a></td>
<td>JML KONTAK</td>
<td>SMS</td>
<td>Action</td>
</tr>
<?
$i=$inicio;
while($row=mysql_fetch_array($data)){
$id_kelompok=stripslashes($row["id_kelompok"]);
$id_kategori_kelompok=stripslashes($row["id_kategori_kelompok"]);
$kelompok=stripslashes($row["kelompok"]);
$i++;
if ($i % 2 != 0) {
$bgcolor = "#DFDFFF";
}else{
$bgcolor = "#EEEEEE";
}
?>
<tr align="center" bgcolor="<?=$bgcolor?>" onMouseOver="this.style.background='#F0FFB8';" onMouseOut="this.style.background='<?=$bgcolor?>'">
<td ><?=$i?></td>
<td class=td_left> <a href="?d=kontak&f=kontak.list&id_kelompok=<?=$id_kelompok?>"><?=$kelompok?> </a></td>
<td ><?=$ckontak=Count1(kelompok_kontak,id_kelompok,$id_kelompok)?></td>
<td ><?
if($ckontak){
echo "<a href=?d=outbox&f=outbox.form&id_kelompok=$id_kelompok><img src=images/semua.png border=0></a>";
}else{
echo "<img src=images/semuadis.png>";
}
?></td>
<td >
<a href="?d=kelompok&f=kelompok.form&id_kelompok=<?=$id_kelompok?>"><img src="images/edit.png " alt="edit" border="0" /></a>
<a href="<?=$_SERVER['REQUEST_URI']?>&del=<?=$id_kelompok?>" onclick="return confirmLink(this, 'HAPUS BARIS ')"><img src="images/del.png" alt="del" border="0" /></a></td>
</tr>
<? } ?>
<tr class="head2" >
<td colspan="5"> ;;
</td>
</tr>
<tr>
<td height="26" colspan="3" >Jumlah <?=$quantos?>baris</td>
<td height="26" colspan="2" class="td_right" ><? echo $instancia->geraPaginacao(); ?></td>
</tr>
</table>
<SCRIPT LANGUAGE="JavaScript">
<!-- Begin
function checkAll() {
for (var j = 0; j <= <?=$cbaris?>; j++) {
box = eval("document.checkboxform.checkbox[" + j + "]");
if (box.checked == false) box.checked = true;
}
}
function uncheckAll() {
for (var j = 0; j <= <?=$cbaris?>; j++) {
box = eval("document.checkboxform.checkbox[" + j + "]");
if (box.checked == true) box.checked = false;
}
}
function switchAll() {
for (var j = 0; j <= <?=$cbaris?>; j++) {
box = eval("document.checkboxform.checkbox[" + j + "]");
box.checked = !box.checked;
}
}
// End -->
</script>
<? // kelompok.list.php ?>
|
|
|
|
|
|
|
www.waraxe.us Forum Index -> PHP script decode requests
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|