Waraxe IT Security Portal
Login or Register
September 20, 2024
Menu
Home
Logout
Discussions
Forums
Members List
IRC chat
Tools
Base64 coder
MD5 hash
CRC32 checksum
ROT13 coder
SHA-1 hash
URL-decoder
Sql Char Encoder
Affiliates
y3dips ITsec
Md5 Cracker
User Manuals
AlbumNow
Content
Content
Sections
FAQ
Top
Info
Feedback
Recommend Us
Search
Journal
Your Account
User Info
Welcome, Anonymous
Nickname
Password
(Register)

Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144

People Online:
Visitors: 422
Members: 0
Total: 422
Full disclosure
Stored XSS in "Edit Profile" - htmlyv2.9.9
Stored XSS in "Menu Editor" - htmlyv2.9.9
Backdoor.Win32.BlackAngel .13 / Unauthenticated Remote CommandExecution
Backdoor.Win32.CCInvader. 10 / Authentication Bypass
Backdoor.Win32.Delf.yj / Information Disclosure
SEC Consult blog :: Microsoft Windows MSI Installer - Repair to SYSTEM - A detailed journey (CVE-2024-38014) + msiscan tool release
Stored XSS to Account Takeover - htmlyv2.9.9
APPLE-SA-09-16-2024-10 macOS Ventura 13.7
APPLE-SA-09-16-2024-9 macOS Sonoma 14.7
APPLE-SA-09-16-2024-8 iOS 17.7 and iPadOS 17.7
APPLE-SA-09-16-2024-7 Xcode 16
APPLE-SA-09-16-2024-6 Safari 18
APPLE-SA-09-16-2024-5 visionOS 2
APPLE-SA-09-16-2024-4 watchOS 11
APPLE-SA-09-16-2024-3 tvOS 18
Log in Register Forum FAQ Memberlist Search
IT Security and Insecurity Portal

www.waraxe.us Forum Index -> PHP script decode requests -> PHPLockIt! Decode Request! Thank you!
Post new topicReply to topic View previous topic :: View next topic
PHPLockIt! Decode Request! Thank you!
PostPosted: Tue Apr 13, 2010 10:14 am Reply with quote
dikozall
Beginner
Beginner
Joined: Apr 13, 2010
Posts: 1




Hi guys. I've tried all decoders that i found, but still can't decode this wordpress footer. I eventually found that this is PHPlockit encryption. Can you please help me decode it.

Code:
<?php // This file is protected by copyright law and provided under license. Reverse engineering of this file is strictly prohibited.
$OOO0O0O00=__FILE__;$O00O00O00=__LINE__;$OO00O0000=1196;eval((base64_decode('JE8wMDBPME8wMD1mb3BlbigkT09PME8wTzAwLCdyYicpO3doaWxlKC0tJE8wME8wME8wMClmZ2V0cygkTzAwME8wTzAwLDEwMjQpO2ZnZXRzKCRPMDAwTzBPMDAsNDA5Nik7JE9PMDBPMDBPMD0oYmFzZTY0X2RlY29kZShzdHJ0cihmcmVhZCgkTzAwME8wTzAwLDM3MiksJ0VudGVyeW91d2toUkhZS05XT1VUQWFCYkNjRGRGZkdnSWlKakxsTW1QcFFxU3NWdlh4WnowMTIzNDU2Nzg5Ky89JywnQUJDREVGR0hJSktMTU5PUFFSU1RVVldYWVphYmNkZWZnaGlqa2xtbm9wcXJzdHV2d3h5ejAxMjM0NTY3ODkrLycpKSk7ZXZhbCgkT08wME8wME8wKTs=')));return;?>
kr9NHenNHenNHe1lFMamb3klFoxiC2APk19gOLlHOa9gkZXJkZwVkr9NTznNHr8XHt4JkZwShokiF2A2Yy9LcBYvcoAPF3OZfuwPcmklCBWPkr8XHenNHr8XHtXLT08XHr8XHeEXhUXmOB50cbk5d3a3D2iUUylRTlfNaaOnCAkJW2YrcrcMO2fkDApQToxYdanXAbyTF1c2BuiDGjExHjH0YTC3KeLqRz0mRtfnWLYrOAcuUrlhU0xYTL9WAakTayaBa1icBMyJC2OlcMfPDBpqdo1Vd3nxFmY0fbc3Gul6HerZHzW1YjF4KUSvkZLphUL7cMYSd3YlhtONHeEXTznNHeEpK2a2CBXPkr9NHenNHenNHtL7cBYPdZEmtWLmKZnpcJIiDbYgDo9scUIpwux8woflfy9vFuOpd24PkzrzcMxvd3kgcMaifuaZcBWmhUE9NUEmcMySF2AmhUn7weslC2ivwtFktWLkNt9LDbC+weXiRU0IcB5LwtYjd250cB50wt0sNILYtILktTXvcol2NJE8wU0swoaVctEjC29VfoaVfufZCbEIRU0+eWPktWLYtILktTxLDbCIDBW9wMYvdmOldmWsCM90fo9swj48R2Opfj4YtILktW0htWLkNoOpfJnpce0JcM9vfoaZRbOvFtw+Nt9LDbC+eWPktWL8col2wolLNUkMd290cbwJwoYSCbYzNUkjdoaiFMcpGtw+eWPktWLkkzSIDBCIhtEicmaVC3Opd25gcbipF3OzhtfLGB5idBljb3YpcoaJCbwmhUn8gtEiculVCB1pC19zDBOlCMyZhtfod290cbwmhUEpwePIK2ajDo8IkZEYtILktWLmKZnldMOpcjSIK2ajDo8IkXLktTXvcol2NJE8wU0swoaVctEjcM9vfoaZwt0sNI0htWLmKZn9KZE7cBYPdZEmtWLktW0htWL8col2wolLNUkjd3n5FMlmDuWJwoYSCbYzNUkjdoaiFMcpGtw+eWPktWL8Fe4mKZngcUImAo93cbklctnJGUEmRtFxH2cSd29ZkZL7weslC2ivwtFINorIDuklcj0JDuO0FePvR3f3fZ53d3kLFuklF3HVC29swj5bd3kLAuklF3H8R2r+wuXIkzSIb2APk1YPCbklctnJGUEmRtFxH2cSd29ZkZL7weslC2ivwtFINorIDuklcj0JDuO0FePvR3f3fZ5MFMalRbnZcB1pfB0sf29ZcunZcbYzRbOPcB1lFZ5jd20Jwuklde0Jco9Md2xSd3FJNLcZcBAIAukldBl1dUnbd3kLFuklF3HIaoildBazNt9iNjXvFe4YtILkNt9LDbC+weXiRU0IcB5LwtYjd3n5FMlmDuWIRU0+eWPktWLYtIL8R2Opfj4INtrsRUnldMWIw3fZCbEIRU0+eWPkeWPkkzSIDB5jduaLcUiAOA1WTryAOannarIIRJEmR2lVC2x1coazR3YjFMlXfuHVFoiXkZL7weslC2ivwtFkkzSIf3ngcM9vfoaZhtL7weslC2ivwtFkeWP8R2kvcuL+eWP8R2i0dBX+kzS=


Thank you very much. I will post more if i find a way do decode it.
View user's profile Send private message
PostPosted: Tue Apr 13, 2010 3:03 pm Reply with quote
Cyko
Moderator
Moderator
Joined: Jul 21, 2009
Posts: 375




Code:
<?php
if (!is_home() || get_option('13floor_featured') == 'false') {
echo ' </div> <!-- end #content -->
</div> <!-- end #contentwrap -->

<div id="content-bottom"></div>

<div id="footer-top"></div>
<div id="footer" class="clearfix">
';
if (!function_exists('dynamic_sidebar') || !dynamic_sidebar('Footer'))
: endif;
echo ' </div> <!-- end #footer -->
';
}
echo '
<div id="copyright" class="clearfix">
<p>';
_e('Powered by ', '13floor');
echo ' <a href="http://www.wordpress.com">WordPress</a> | ';
_e('Shared by ', '13floor');
echo ' <a href="http://www.free-premium-wordpress-themes.com" rel="dofollow">Free Premium Wordpress Themes</a></p>
</div> <!-- end #copyright -->

</div> <!-- end #wrap -->

';
include(TEMPLATEPATH . '/includes/scripts.php');
wp_footer();
echo '
</body>
</html>';
?>


Edit: Updated decoded output


Last edited by Cyko on Tue Apr 13, 2010 4:12 pm; edited 1 time in total
View user's profile Send private message
PostPosted: Tue Apr 13, 2010 3:24 pm Reply with quote
vince213333
Advanced user
Advanced user
Joined: Aug 03, 2009
Posts: 737
Location: Belgium




Cyko, I'm not sure but this is my outcome:

Code:
<?php
echo ' ';
if(!is_home() || get_option('13floor_featured') == 'false') {
echo ' </div> <!-- end #content -->
</div> <!-- end #contentwrap -->

<div id="content-bottom"></div>

<div id="footer-top"></div>
<div id="footer" class="clearfix">
';
if ( !function_exists('dynamic_sidebar') || !dynamic_sidebar('Footer') ) : echo '
'; endif;
echo ' </div> <!-- end #footer -->
';
}
echo '
<div id="copyright" class="clearfix">
<p>';
_e('Powered by ','13floor');
echo ' <a href="http://www.wordpress.com">WordPress</a> | ';
_e('Shared by ','13floor');
echo ' <a href="http://www.free-premium-wordpress-themes.com" rel="dofollow">Free Premium Wordpress Themes</a></p>
</div> <!-- end #copyright -->

</div> <!-- end #wrap -->

';
include(TEMPLATEPATH . '/includes/scripts.php');
echo ' ';
wp_footer();
echo '
</body>
</html>';
?>


It does contain some more echo codes Confused
View user's profile Send private message
PostPosted: Tue Apr 13, 2010 4:08 pm Reply with quote
Cyko
Moderator
Moderator
Joined: Jul 21, 2009
Posts: 375




PHPLockit scrambles/rearranges the order of code and adds excess echos in place of php tags (so it can execute...).

So my decoder, strips those excess echos, however in this case; it seems it has malfunctioned as your's contains html (beside the empty echos).

Thanks for the report - shall debug.
View user's profile Send private message
PostPosted: Tue Apr 13, 2010 4:21 pm Reply with quote
Cyko
Moderator
Moderator
Joined: Jul 21, 2009
Posts: 375




Example PHPLockit! Scenario:

This may be an output when decoded:

Code:
<?
ob_start();
echo ' ';

;echo '<body>';

;echo ' <img src="';echo $xs_live_site;;echo '/components/com_xhtmlsuite/includes/images/loading_xhtmlsuite.gif" style="display: none;" />
';

ob_flush();

?>



Which should look something like:
Code:
<?
ob_start();
echo '<body>';

echo '<img src="<?php echo $xs_live_site; ?>/components/com_xhtmlsuite/includes/images/loading_xhtmlsuite.gif" style="display: none;" />';

ob_flush();

?>


Theirfore a decoder is not human, which is why it may not know how to autocorrect, which is why when you decode PHPLockit!, you have to be cautious and correct manually the code.
View user's profile Send private message
PostPosted: Tue Apr 13, 2010 4:31 pm Reply with quote
vince213333
Advanced user
Advanced user
Joined: Aug 03, 2009
Posts: 737
Location: Belgium




Ok thanks for the info.

I thought it was supposed to be that way.

I'm a coder myself and I do use such things like
Code:

echo " <div>
bla
</div>";

sometimes because I'd like to have a readable source code.

But your explanation is more understandable. I was wondering why i always had the semicolon in front of the echo commands ^^
View user's profile Send private message
PostPosted: Tue Apr 13, 2010 4:38 pm Reply with quote
Cyko
Moderator
Moderator
Joined: Jul 21, 2009
Posts: 375




vince213333 wrote:
Ok thanks for the info.

I thought it was supposed to be that way.

I'm a coder myself and I do use such things like
Code:

echo " <div>
bla
</div>";

sometimes because I'd like to have a readable source code.

But your explanation is more understandable. I was wondering why i always had the semicolon in front of the echo commands ^^



Your example is ofcourse part of the code, but semicolons infront of echo's or empty/blank echos is not part of the code - they're added when encoded, theirfore when decoded they need to be removed, so it can be fully converted to how it looked like before it was encoded Smile
View user's profile Send private message
PostPosted: Tue Apr 13, 2010 4:52 pm Reply with quote
vince213333
Advanced user
Advanced user
Joined: Aug 03, 2009
Posts: 737
Location: Belgium




That's exactly what I did Wink
View user's profile Send private message
PHPLockIt! Decode Request! Thank you!
www.waraxe.us Forum Index -> PHP script decode requests
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT
Page 1 of 1

Post new topicReply to topic


Powered by phpBB © 2001-2008 phpBB Group



Space Raider game for Android, free download - Space Raider gameplay video - Zone Raider mobile games
All logos and trademarks in this site are property of their respective owner. The comments and posts are property of their posters, all the rest (c) 2004-2024 Janek Vind "waraxe"
Page Generation: 0.034 Seconds