|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 109
Members: 0
Total: 109
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
please help to decode base64 php file. |
|
Posted: Fri Feb 26, 2010 5:59 pm |
|
|
scarto2011 |
Beginner |
|
|
Joined: Feb 26, 2010 |
Posts: 1 |
|
|
|
|
|
|
|
I have obfuscated php file and I have followed the steps used tools that other members recommend in this forum. I have decoded part of the file but I got stacked with the second part.
So here is original file:
Code: | <?php /* WARNING: This file is protected by copyright law. To reverse engineer or decode this file is strictly prohibited. */
$o="QAAADjtjbnEnbmM6JWFoaHNidQAAJSdka2Z0dDolZGhrKmFyawOLayU5Cg0OADACkwHUc2h3AYIOAaIBs4AOBEFwbmNgYnMqa2JhcwSaARIEkQ4AAA4OOzh3b3cnY35pZmpuZFgAQHRuY2JlZnUvIAfzKjYgLjwnGIA4OScAEAdRDjsoCgA5OyYqKicoYfAkAkQGZDYnKioFQwKjApAMkgH0dW5gb/71CGsBIwMxBeAAMgjfCNo1CNcLkAZjCQ8qBxQ1CQ+D7xTVYW5/JTkMswRiAFEA8w2jKRUQA+UBwgzBgcMWxGVoc3NoahbzAcEW52Rod34NQwaFxIAbURbKdzkhAmE8JxdjYmRvaCdjZgYAc2IvIF4NxAGTZWtoYG5pYWgvqCAX4ikC9FgCgEZraydVFLF0J1VidAAQYnVxYmMpICsnIHAi8G9iamIR+HQgLhsAOyh3FYEd4BICCoIAUiX2ZHViLMJjbhkPcw2TA5B3OQizB1FXaHBiAwAnIABlfga/JztmJ291YmE6JW9zcwAAdz0oKHBwcClwaHVjd3VidACEdClodWAlOVAA9TsoZjkM6UNiAwZ0bmBpYmMFrwxQIWlldHcSsAYPKQEgcG5kbGJjKgZ2KnMPwilkaGoogAEBXShoaWtuaWIqdHNodWIoCNgv/CdUASEnA7IJkRNfNQMhqh/zIdgB6TEkAeQKDYLHAcpkaGlzZgiQdQHzFeNwd1g0Yx6jAzDwQDjyHOABggFmKGVoY34dMDsob3NqawAAOQ==";eval(base64_decode("JGxsbD0wO2V2YWwoYmFzZTY0X2RlY29kZSgiSkd4c2JHeHNiR3hzYkd4c1BTZGlZWE5sTmpSZlpHVmpiMlJsSnpzPSIpKTskbGw9MDtldmFsKCRsbGxsbGxsbGxsbCgiSkd4c2JHeHNiR3hzYkd3OUoyOXlaQ2M3IikpOyRsbGxsPTA7JGxsbGxsPTM7ZXZhbCgkbGxsbGxsbGxsbGwoIkpHdzlKR3hzYkd4c2JHeHNiR3hzS0NSdktUcz0iKSk7JGxsbGxsbGw9MDskbGxsbGxsPSgkbGxsbGxsbGxsbCgkbFsxXSk8PDgpKyRsbGxsbGxsbGxsKCRsWzJdKTtldmFsKCRsbGxsbGxsbGxsbCgiSkd4c2JHeHNiR3hzYkd4c2JHdzlKM04wY214bGJpYzciKSk7JGxsbGxsbGxsbD0xNjskbGxsbGxsbGw9IiI7Zm9yKDskbGxsbGw8JGxsbGxsbGxsbGxsbGwoJGwpOyl7aWYoJGxsbGxsbGxsbD09MCl7JGxsbGxsbD0oJGxsbGxsbGxsbGwoJGxbJGxsbGxsKytdKTw8OCk7JGxsbGxsbCs9JGxsbGxsbGxsbGwoJGxbJGxsbGxsKytdKTskbGxsbGxsbGxsPTE2O31pZigkbGxsbGxsJjB4ODAwMCl7JGxsbD0oJGxsbGxsbGxsbGwoJGxbJGxsbGxsKytdKTw8NCk7JGxsbCs9KCRsbGxsbGxsbGxsKCRsWyRsbGxsbF0pPj40KTtpZigkbGxsKXskbGw9KCRsbGxsbGxsbGxsKCRsWyRsbGxsbCsrXSkmMHgwZikrMztmb3IoJGxsbGw9MDskbGxsbDwkbGw7JGxsbGwrKykkbGxsbGxsbGxbJGxsbGxsbGwrJGxsbGxdPSRsbGxsbGxsbFskbGxsbGxsbC0kbGxsKyRsbGxsXTskbGxsbGxsbCs9JGxsO31lbHNleyRsbD0oJGxsbGxsbGxsbGwoJGxbJGxsbGxsKytdKTw8OCk7JGxsKz0kbGxsbGxsbGxsbCgkbFskbGxsbGwrK10pKzE2O2ZvcigkbGxsbD0wOyRsbGxsPCRsbDskbGxsbGxsbGxbJGxsbGxsbGwrJGxsbGwrK109JGxsbGxsbGxsbGwoJGxbJGxsbGxsXSkpOyRsbGxsbCsrOyRsbGxsbGxsKz0kbGw7fX1lbHNlJGxsbGxsbGxsWyRsbGxsbGxsKytdPSRsbGxsbGxsbGxsKCRsWyRsbGxsbCsrXSk7JGxsbGxsbDw8PTE7JGxsbGxsbGxsbC0tO31ldmFsKCRsbGxsbGxsbGxsbCgiSkd4c2JHeHNiR3hzYkd4c2JEMG5ZMmh5SnpzPSIpKTskbGxsbGw9MDtldmFsKCRsbGxsbGxsbGxsbCgiSkd4c2JHeHNiR3hzYkQwaVB5SXVKR3hzYkd4c2JHeHNiR3hzYkNnMk1pazciKSk7JGxsbGxsbGxsbGw9IiI7Zm9yKDskbGxsbGw8JGxsbGxsbGw7KXskbGxsbGxsbGxsbC49JGxsbGxsbGxsbGxsbCgkbGxsbGxsbGxbJGxsbGxsKytdXjB4MDcpO31ldmFsKCRsbGxsbGxsbGxsbCgiSkd4c2JHeHNiR3hzYkM0OUpHeHNiR3hzYkd4c2JHd3VKR3hzYkd4c2JHeHNiR3hzYkNnMk1Da3VJajhpT3c9PSIpKTtldmFsKCRsbGxsbGxsbGwpOw=="));return;?> |
I decoded first part starting with
Code: | $o="QAAADjtjbnEnbmM6JWFoaHN..." |
and then decoded second part starting with
Code: | eval(base64_decode("JGxsbD0wO2V2YWwo...." |
to this
Code: | $lll=0;eval(base64_decode("JGxsbGxsbGxsbGxsPSdiYXNlNjRfZGVjb2RlJzs="));$ll=0;eval($lllllllllll("JGxsbGxsbGxsbGw9J29yZCc7"));$llll=0;$lllll=3;eval($lllllllllll("JGw9JGxsbGxsbGxsbGxsKCRvKTs="));$lllllll=0;$llllll=($llllllllll($l[1])<<8)+$llllllllll($l[2]);eval($lllllllllll("JGxsbGxsbGxsbGxsbGw9J3N0cmxlbic7"));$lllllllll=16;$llllllll="";for(;$lllll<$lllllllllllll($l);){if($lllllllll==0){$llllll=($llllllllll($l[$lllll++])<<8);$llllll+=$llllllllll($l[$lllll++]);$lllllllll=16;}if($llllll&0x8000){$lll=($llllllllll($l[$lllll++])<<4);$lll+=($llllllllll($l[$lllll])>>4);if($lll){$ll=($llllllllll($l[$lllll++])&0x0f)+3;for($llll=0;$llll<$ll;$llll++)$llllllll[$lllllll+$llll]=$llllllll[$lllllll-$lll+$llll];$lllllll+=$ll;}else{$ll=($llllllllll($l[$lllll++])<<8);$ll+=$llllllllll($l[$lllll++])+16;for($llll=0;$llll<$ll;$llllllll[$lllllll+$llll++]=$llllllllll($l[$lllll]));$lllll++;$lllllll+=$ll;}}else$llllllll[$lllllll++]=$llllllllll($l[$lllll++]);$llllll<<=1;$lllllllll--;}eval($lllllllllll("JGxsbGxsbGxsbGxsbD0nY2hyJzs="));$lllll=0;eval($lllllllllll("JGxsbGxsbGxsbD0iPyIuJGxsbGxsbGxsbGxsbCg2Mik7"));$llllllllll="";for(;$lllll<$lllllll;){$llllllllll.=$llllllllllll($llllllll[$lllll++]^0x07);}eval($lllllllllll("JGxsbGxsbGxsbC49JGxsbGxsbGxsbGwuJGxsbGxsbGxsbGxsbCg2MCkuIj8iOw=="));eval($lllllllll); |
and then I don't know what to do with this part.
Please help to decode. I know it is probably small thing that I am missing so would appreciate any help. |
|
|
|
|
|
|
|
|
Posted: Sun Feb 28, 2010 5:18 pm |
|
|
vince213333 |
Advanced user |
|
|
Joined: Aug 03, 2009 |
Posts: 737 |
Location: Belgium |
|
|
|
|
|
|
There you are
Code: | <div id="footer" class="col-full">
<div class="top">
<div id="widget-left" class="col-left">
<?php dynamic_sidebar('footer-1'); ?>
</div><!-- /#footer-widget-1 -->
<div id="widget-right" class="col-right">
<?php dynamic_sidebar('footer-2'); ?>
</div><!-- /#footer-widget-2 -->
<div class="fix"></div>
</div><!-- /.top -->
<div class="bottom">
<div id="copyright" class="col-left">
<p>© <?php echo date('Y'); ?> <?php bloginfo(); ?>. <?php _e('All Rights Reserved.', 'woothemes') ?></p>
</div>
<div id="credit" class="col-right">
<p><?php _e('Powered by', 'woothemes') ?> <a href="http://www.wordpress.org">Wordpress</a>. <?php _e('Designed by', 'woothemes') ?> ;; <a href="http://www.wicked-wordpress-themes.com/wordpress-themes/online-store/">Wordpress Store theme</a></p>
</div>
</div><!-- /.bottom -->
</div><!-- /#footer -->
</div><!-- /#container -->
<?php wp_footer(); ?>
<?php woo_foot(); ?>
</body>
</html> |
|
|
|
|
|
|
www.waraxe.us Forum Index -> PHP script decode requests
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|