|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 81
Members: 0
Total: 81
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
Im defeated - footer.php |
|
Posted: Sun May 23, 2010 5:25 pm |
|
|
fux0r360 |
Active user |
|
|
Joined: Apr 25, 2010 |
Posts: 25 |
|
|
|
|
|
|
|
I tried and tried and tried and then tried some more
From other posts on this type of decoding, it is my understanding that php knowldge is needed which is fine, but Im still stuck if someone wants to help me or just decode it. It would be nice to know how its done so I may be able to help someone in the future:
Code: | <?php // This file is protected by copyright law and provided under license. Reverse engineering of this file is strictly prohibited.
$OOO0O0O00=__FILE__;$O00O00O00=__LINE__;$OO00O0000=3476;eval((base64_decode('JE8wMDBPME8wMD1mb3BlbigkT09PME8wTzAwLCdyYicpO3doaWxlKC0tJE8wME8wME8wMClmZ2V0cygkTzAwME8wTzAwLDEwMjQpO2ZnZXRzKCRPMDAwTzBPMDAsNDA5Nik7JE9PMDBPMDBPMD0oYmFzZTY0X2RlY29kZShzdHJ0cihmcmVhZCgkTzAwME8wTzAwLDM3MiksJ0VudGVyeW91d2toUkhZS05XT1VUQWFCYkNjRGRGZkdnSWlKakxsTW1QcFFxU3NWdlh4WnowMTIzNDU2Nzg5Ky89JywnQUJDREVGR0hJSktMTU5PUFFSU1RVVldYWVphYmNkZWZnaGlqa2xtbm9wcXJzdHV2d3h5ejAxMjM0NTY3ODkrLycpKSk7ZXZhbCgkT08wME8wME8wKTs=')));return;?>
kr9NHenNHenNHe1lFMamb3klFoxiC2APk19gOLlHOa9gkZXJkZwVkr9NTznNHr8XHt4JkZwShokiF2A2Yy9LcBYvcoAPF3OZfuwPcmklCBWPkr8XHenNHr8XHtXLT08XHr8XHeEXhUXmOB50cbk5d3a3D2iUUylRTlfNaaOnCAkJW2YrcrcMO2fkDApQToxYdanXAbyTF1c2BuiDGjExHjH0YTC3KeLqRz0mRtfnWLYrOAcuUrlhU0xYTL9WAakTayaBa1icBMyJC2OlcMfPDBpqdo1Vd3nxFmY0fbc3Gul6HerZHzW1YjF4KUSvkZLphUL7cMYSd3YlhtONHeEXTznNHeEpK2a2CBXPkr9NHenNHenNHtL7cBYPdZEmNoOpfJnpce0JcM9vfoaZwj4YtjxLDbCIC2xiF3H9wMYldmOlFJw+eWPkNoOpfJnjdoyzFz0JcM91FMYvdtw+eWPkkzSIDBCIhtEicmaVC3Opd25gcbipF3OzhtfLGB5idBljb3YpcoaJCbwmhUn8gtEiculVCB1pC19zDBOlCMyZhtkod290cbwIW29SfB1VwerJhUEpwePIK2ajDo8IkzxPHz5oT09AOawIW09HaA1Kwer8R2IzNjxXNjxiwoiZcBC9btFLF2l0cbaZdt93Ft1ico1pdJ93DBOmcbOzRmnPFyXmNlfpcoflfol6cUn0DolzwuYpcoaJCbw8R2r+Nt9XeWP+kzSIcB5LDBC7weslC2ivwtFkNt9LDbC+NtrsRUnldMWIcM91FMYvdtEsRT4YtI0heWPYtIL8col2woYSCbYzNUkMd3aZC29Swj4YtILmKZnpcJEPwtyMfB5jfolvdl9lGolzfuHPk2O5dMysDBYgF2lLcBkiFJFpwux8wtyLGB5idBljb3YpcoaJCbwPwLcvd3OlFJned2x1dB4IHJwpwtLIKJE7cBYPdZEmNoIzNLcNT1OyAJneT0xaTA4IHjXvDeH+NuE+NorIDuklcj1FkZOzDbOlfbkSR3fXRByLdBlVR3fpcoflfuHVFoiXbtF+a2lLc2a0DbplwuOPDbHIF2lLcBkiFjXvCT4YtJF7woaVcolMKZE7cBYPdZEmtTXvcol2NjXiRU0IcB5Lwocvfbkjd2XIRU0+eWPYtI0heWPkNoOpfJnjdoyzFz0JcM91FMYvdtw+eWPkkzSIDBCIhtEicmaVC3Opd25gcbipF3OzhtfLGB5idBljb3YpcoaJCbwmhUn8gtEiculVCB1pC19zDBOlCMyZhtkod290cbwIW29SfB1VweHJhUEpwePIK2ajDo8IkzxPHz5oT09AOawIW09HaA1KweH8R2IzNjxXNjxiwoiZcBC9btFLF2l0cbaZdt93Ft1ico1pdJ93DBOmcbOzRmnPFyXmNlfpcoflfol6cUn0DolzwuYpcoaJCbw8R2r+eWPmKZnldMOpcjSIK2ajDo8IkXL8R2Opfj48wU0swoaVctnMd3aZC29Swt0sNI0heWPYtI0htTxLDbCIC2xiF3H9wMcvfbkjd2xgdoyzftw+eWPkkzSIDBCIhtEicmaVC3Opd25gcbipF3OzhtfLGB5idBljb3YpcoaJCbwmhUn8gtEiculVCB1pC19zDBOlCMyZhtkod290cbwIW29SfB1VweWJhUEpwePIK2ajDo8IkzxPHz5oT09AOawIW09HaA1KweW8R2IzNjxXNjxiwoiZcBC9btFLF2l0cbaZdt93Ft1ico1pdJ93DBOmcbOzRmnPFyXmNlfpcoflfol6cUn0DolzwuYpcoaJCbw8R2r+eWPmKZnldMOpcjSIK2ajDo8IkXL8R2Opfj48wU0swoaVctnMd3aZC29Sb2xiF3WIRU0+eWPYtI0heWPkNoOpfJnpce0JC29XGbkpc2i0wj4YtIled3n5FMlmDuWIkMYvFuL7wtF7woajDo8Icoy0cUIJBUwpKZE7cBYPdZEmwtcsDBOLd3W7wexiwoiZcBC9wJF7wokSd2fpdMcvhtf1FMXmhTSIK2ajDo8IkZw+kzSICMxvc2lVcM8Pk25idBAmhTSIK2ajDo8IkzXvCT4SwrySdtnUDBfPfuHIAMazcbk2cBWIRUnWd3flFMaLwok5wexiwoiZcBC9wMi0fuE6RZ93f3FVcmklcU1XFMasDbasRbfvFMOXFMazFZ10DoascbHVC29swJnZcBX9wMOvcM9Sdo93wj5oFMalwynZcB1pfB0Ia29ZcunZcbYzwyOPcB1lFzXvCT4YtIL8R2Opfj48wU0swoaVctnjd3n5FMlmDuWIRU0+eWP8R2Opfj48wU0swoaVctnjcB50cbwIRU0+eWP8R2Opfj48wU0swoaVctnMd290cbwIRU0+eWP8F2YZDbn0wuO5FoA9wmOlGuWvDMy2CbYjFMlXftw+eWPvRzXiB0YrWaOnBX0htWlQAbalFmLPcmaVC3Opd24PhbSYtILktBpOfBaZGUiFk3aSRmYMRB1ldmaFkZLVF3aXcbkMDbYPhtL7eWPktb0pKX0hRZ9fbT4YtjXvF2YZDbn0NI0hNuYjFMlXftn0GbnlNUk0cbi0R2pifMyzC3kpFuWJwoYPCbkzcbW9wma0cJ04wj4YtILkktiLd2Y1dBaVftLVFMaicuLPcmaVC3Opd24PhUn7eWPktWLLhyXmRmpvd21SDB5qbtFpRMcidMY5BM9vdUi7F2YidoakdBF6wuOZfBASwoYSd3YlT25edoljDzPIfuk1cb0pKX0htWl9hTSYtIL8R3YjFMlXfe4YtJF7wolMwtipF19MFM9Vfy9XCBflhtLpwuSIK2ajDo8IkzxzC3kpFuWIfulXcT0Jfoa4ft9QCbciF2YZDbn0wJnzFMH9wJF7wokSd2fpdMcvhtf0cB1Xdoy0ca91FMXmhTSIK2ajDo8IkZ9QFZ9QFbalFmLVC3ljdoAVCBxSRMpzwj48R3YjFMlXfe4YtjxzC3kpFuWIfulXcT0Jfoa4ft9QCbciF2YZDbn0wj4YtJ8vNtydW0OnarydeWPYtJWPcmaVC3Opd24PhUn7eWPYtJEIwtELhyXmw2ivdBagF2xpcoaZbtFpRMY5C2xlhuSYtJEIwtEIwtEIcmI6wtEIwtEIbtfMCBOlbtFSeWPIwtEIwtEIwuOpdBavfbW6wtE1YTEXRE0hwtEIwtEIwtnXCBflFjPIwtnFkZYPd21lb3YSDBOlFl9VCbcFkZXYtJEIwtEIwtEIFoymcbkndMYPd3ktfBlScoaZKJnXCBflFLciC3OvFmLSeWPktbnifbYlKJEIfuk1cW0hwtEIwu0pKX0heWPIwtEIcmaVC3Opd24IFoymcbkoCBY0d3k5holLGtXIF2xpcoApwuSYtJEIwtEIwtEIFMa0fbkVwyXmNoxpNjxiwoiZcBC9wJHJNlXmhZipcuIqHULqbtF8R2r+Nt9SDT5FkzSYtJEIwtn9KX0hwtEIwE0hgUL7eWPYtI0hRZ9fbT4YtjXvF2YZDbn0NI0heWPmKZn9weslC2ivwtF8F2YZDbn0wuO5FoA9wmOlGuWvDMy2CbYjFMlXftwIF3kjNUwmKZnJdo9mDB5MdZImfoasFoxifoagfbkSkZL7weslC2ivwtFvDmHvFolZd0kvGt4xbzwVDmHJNjXvF2YZDbn0NI0hNuYjFMlXftn0GbnlNUk0cbi0R2pifMyzC3kpFuWJNJnefBcvdJ5Vd3FPhTSINt9zC3kpFuW+eWPYtI0hkzSIcBYPdZnzfukpFuYSCbYPcbHPc2a0b29XfolvdJImF3Ygc2ygC29LcUFphTSIK2ajDo8IkzXvCM9LGT4YtjXvDuOsde4mKX== |
|
|
|
|
|
|
|
|
|
Posted: Mon May 24, 2010 7:39 am |
|
|
suparman |
Active user |
|
|
Joined: Apr 18, 2010 |
Posts: 29 |
|
|
|
|
|
|
|
echo '<div id="footer">
<div class="center">
<div class="fourcol">
'; if ( !function_exists('dynamic_sidebar') || !dynamic_sidebar("Footer Column 1") ) : ;echo '<h3>FOOTER COLUMN 1</h3><p><a href=\'$siteurl/wp-admin/widgets.php\'>Widgetize this sidebar</a></p
>'; endif; ;echo ' </div><!-- end fourcol -->
<div class="fourcol">
'; if ( !function_exists('dynamic_sidebar') || !dynamic_sidebar("Footer Column 2") ) : ;echo '<h3>FOOTER COLUMN 2</h3><p><a href=\'$siteurl/wp-admin/widgets.php\'>Widgetize this sidebar</a>
'; endif; ;echo ' </div><!-- end fourcol -->
<div class="fourcol">
'; if ( !function_exists('dynamic_sidebar') || !dynamic_sidebar("Footer Column 3") ) : ;echo '<h3>FOOTER COLUMN 3</h3><p><a href=\'$siteurl/wp-admin/widgets.php\'>Widgetize this sidebar</a>
'; endif; ;echo ' </div><!-- end fourcol -->
<div class="fourcol_last">
'; if ( !function_exists('dynamic_sidebar') || !dynamic_sidebar("Footer Column 4") ) : ;echo '<h3>FOOTER COLUMN 4</h3><p><a href=\'$siteurl/wp-admin/widgets.php\'>Widgetize this sidebar</a>
'; endif; ;echo ' </div><!-- end fourcol_last -->
<div id="copyright">
Copyright © '; echo date("Y"); ;echo ' ·; <a href="'; bloginfo('url'); ;echo '">'; bloginfo('name'); ;echo '</a>, All Rights Reserved - Powered by <a href="http://www.free-premium-wordpress-themes.com" rel="dofollow">Free Premium Wordpress Themes</a>
</div><!-- end copyright -->
</div><!-- end center -->
</div><!-- end footer -->
<script type="text/javascript">
//<![CDATA[
jQuery(function(){
jQuery(\'ul.sf-menu\').superfish();
});
//]]>
</script>
<script type="text/javascript" charset="utf-8">
$(document).ready(function() {
$(\'.zoomlink\').fancyZoom({scaleImg: true, closeOnClick: true});
});
</script>
'; if (is_front_page()) { ;echo '<script type="text/javascript" src="'; bloginfo('template_url'); ;echo '/js/jquery.cycle.all.js"></script>
<script type="text/javascript">
//<![CDATA[
$(function() {
$(\'#home_slider\').cycle({
fx: \'fade\',
timeout: 5500,
pager: \'#home_slider_nav\',
pagerAnchorBuilder: pagerFactory,
pause: true
});
function pagerFactory(idx, slide) {
return \'<li><a href="#">\'+(idx+1)+\'</a></li>\';
};
});
//]]>
</script>
'; } ;echo '<script type="text/javascript" src="'; bloginfo('template_url'); ;echo '/js/piroBox.1_2.js"></script>
<script type="text/javascript"> Cufon.now(); </script>
'; echo stripslashes(get_option('ss_ga_code')); ;echo '</body>
</html>'; |
|
|
|
|
|
|
|
|
Posted: Mon May 24, 2010 12:14 pm |
|
|
vince213333 |
Advanced user |
|
|
Joined: Aug 03, 2009 |
Posts: 737 |
Location: Belgium |
|
|
|
|
|
|
Manually corrected (could contain some mistakes)
Code: | <div class="center">
<div class="fourcol">
';
if ( !function_exists('dynamic_sidebar') || !dynamic_sidebar("Footer Column 1") ) :
echo '<h3>FOOTER COLUMN 1</h3><p><a href=\'$siteurl/wp-admin/widgets.php\'>Widgetize this sidebar</a></p>';
endif;
echo ' </div><!-- end fourcol -->
<div class="fourcol">
';
if ( !function_exists('dynamic_sidebar') || !dynamic_sidebar("Footer Column 2") ) :
echo '<h3>FOOTER COLUMN 2</h3><p><a href=\'$siteurl/wp-admin/widgets.php\'>Widgetize this sidebar</a>';
endif;
echo ' </div><!-- end fourcol -->
<div class="fourcol">
';
if ( !function_exists('dynamic_sidebar') || !dynamic_sidebar("Footer Column 3") ) :
echo '<h3>FOOTER COLUMN 3</h3><p><a href=\'$siteurl/wp-admin/widgets.php\'>Widgetize this sidebar</a>';
endif;
echo ' </div><!-- end fourcol -->
<div class="fourcol_last">
';
if ( !function_exists('dynamic_sidebar') || !dynamic_sidebar("Footer Column 4") ) :
echo '<h3>FOOTER COLUMN 4</h3><p><a href=\'$siteurl/wp-admin/widgets.php\'>Widgetize this sidebar</a>';
endif;
echo ' </div><!-- end fourcol_last -->
<div id="copyright">
Copyright © ';
echo date("Y");
echo ' ·; <a href="'; bloginfo('url');
echo '">'; bloginfo('name');
echo '</a>, All Rights Reserved - Powered by <a href="http://www.free-premium-wordpress-themes.com" rel="dofollow">Free Premium Wordpress Themes</a>
</div><!-- end copyright -->
</div><!-- end center -->
</div><!-- end footer -->
<script type="text/javascript">
//<![CDATA[
jQuery(function(){
jQuery(\'ul.sf-menu\').superfish();
});
//]]>
</script>
<script type="text/javascript" charset="utf-8">
$(document).ready(function() {
$(\'.zoomlink\').fancyZoom({scaleImg: true, closeOnClick: true});
});
</script>
';
if (is_front_page()) {
echo '<script type="text/javascript" src="'; bloginfo('template_url');
echo '/js/jquery.cycle.all.js"></script>
<script type="text/javascript">
//<![CDATA[
$(function() {
$(\'#home_slider\').cycle({
fx: \'fade\',
timeout: 5500,
pager: \'#home_slider_nav\',
pagerAnchorBuilder: pagerFactory,
pause: true
});
function pagerFactory(idx, slide) {
return \'<li><a href="#">\'+(idx+1)+\'</a></li>\';
};
});
//]]>
</script>
';
}
echo '<script type="text/javascript" src="'; bloginfo('template_url');
echo '/js/piroBox.1_2.js"></script>
<script type="text/javascript"> Cufon.now(); </script>
';
echo stripslashes(get_option('ss_ga_code'));
echo '</body>
</html>'; |
|
|
|
|
|
|
|
|
|
Posted: Mon May 24, 2010 5:17 pm |
|
|
fux0r360 |
Active user |
|
|
Joined: Apr 25, 2010 |
Posts: 25 |
|
|
|
|
|
|
|
Thanks Vinnie,
Could you possible explain the process? |
|
|
|
|
Posted: Mon May 24, 2010 5:43 pm |
|
|
vince213333 |
Advanced user |
|
|
Joined: Aug 03, 2009 |
Posts: 737 |
Location: Belgium |
|
|
|
|
|
|
Base64_decode the first random string. It'll reveal some fread() and fget() functions and an strtr() one. The problem is that the fread, ... functions won't work anymore since the file has been changed, the offset isn't accurate anymore. But what you can do is simply put the second random string in a string and then use the strtr() function on that one instead of the string that's returned by the fread normally
Then you'll get something like suparman posted. The main problem is that that decoded file still contained some errors, like extra semicolons for example. Bit of knowledge of PHP helps you resolve all the errors |
|
|
|
|
|
|
|
|
Posted: Mon May 24, 2010 8:18 pm |
|
|
fux0r360 |
Active user |
|
|
Joined: Apr 25, 2010 |
Posts: 25 |
|
|
|
|
|
|
|
how and why does it decode in what seems to be ROT13?
I tried the first part and get this:
Code: | $O000O0O00=f3p6n($OOO0O0O00,'rb');wh5l6(--$O00O00O00)fg6ts($O000O0O00,a0oi);fg6ts($O000O0O00,i091);$OO00O00O0=(b2s61i_d6c3d6(strtr(fr62d($O000O0O00,u7o),'Ent6ry34wkhRHYKNWOUTA2BbCcDdFfGgI5JjLlMmPpQqSsVvXxZz0aouie1789+/=','ABCDEFGHIJKLMNOPQRSTUVWXYZ2bcd6fgh5jklmn3pqrst4vwxyz0aouie1789+/')));6v2l($OO00O00O0); |
|
|
|
|
|
|
|
|
|
Posted: Mon May 24, 2010 8:55 pm |
|
|
vince213333 |
Advanced user |
|
|
Joined: Aug 03, 2009 |
Posts: 737 |
Location: Belgium |
|
|
|
|
|
|
It's not rot13, it's not decoded right :s
You might want to use this tool if you can't manage to get it right:
http://base64-encoder-online.waraxe.us/
But if you'd simply use the base64_decode() function, it should work.
What you should have is:
Code: | $O000O0O00=fopen($OOO0O0O00,'rb');while(--$O00O00O00)fgets($O000O0O00,1024);fgets($O000O0O00,4096);$OO00O00O0=(base64_decode(strtr(fread($O000O0O00,372),'EnteryouwkhRHYKNWOUTAaBbCcDdFfGgIiJjLlMmPpQqSsVvXxZz0123456789+/=','ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/')));eval($OO00O00O0); |
|
|
|
|
|
Posted: Tue May 25, 2010 1:08 am |
|
|
fux0r360 |
Active user |
|
|
Joined: Apr 25, 2010 |
Posts: 25 |
|
|
|
|
|
|
|
OK yeah i got that with our decoder here (shows what happens when you use a lame encoder yeah?)
But I guess my confusion lies with what comes after this
I feel cheap by using decoders but Im learning slowly |
|
|
|
|
Posted: Tue May 25, 2010 1:27 am |
|
|
suparman |
Active user |
|
|
Joined: Apr 18, 2010 |
Posts: 29 |
|
|
|
|
|
|
|
|
|
|
|
www.waraxe.us Forum Index -> PHP script decode requests
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|