| 
  
    | 
	|  | Menu |  |  
     
     | 
      
       | 
        
         | 
          
           | 
						|  |  |  Home |  |  |  |  |  |  |  |  Discussions |  |  |  |  |  |  |  |  Tools |  |  |  |  |  |  |  |  Affiliates |  |  |  |  |  |  |  |  Content |  |  |  |  |  |  |  |  Info |  |  |  |  |  |  |  |  |  |  
  
    | 
	|  | User Info |  |  
     
     | 
      
       | 
        
         | 
          
           |  Membership: 
  Latest: MichaelSnaRe 
  New Today: 0 
  New Yesterday: 0 
  Overall: 9144 
 
  People Online: 
  Visitors: 186 
  Members: 0 
  Total: 186 
 |  |  |  |  |  
  
    | 
	|  | Full disclosure |  |  |  | 
  
    | 
	|  |  |  |  
        
          | 
              
                | 
                    
                      | 
                          
                            | 
	| 
	
		|  |  |  
		|  | IT Security and Insecurity Portal |  |  
 
	|  | obfuscate file |  |  
	| 
	
		|  Posted: Sat Dec 22, 2012 6:18 pm |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| amin |  | Regular user |  |  
  |  |  |  | Joined: Aug 08, 2012 |  | Posts: 10 |  |  |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			| hello there 
 i have multiple files that are encoded with zend guard
 
 when i decode them with dezender.net.2011
 
 they become like this :
 http://pastebin.com/1040ND6s
 
 there are some codes like this :
 _obfuscate_CXIZARoUBQt7HD8ÿ( $sql )
 
 can they be decoded?
 
 with prior thanks
 |  |  
		|  |  |  
	|  |  
	|  | dezend |  |  
	| 
	
		|  Posted: Thu Dec 27, 2012 10:10 pm |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| amin |  | Regular user |  |  
  |  |  |  | Joined: Aug 08, 2012 |  | Posts: 10 |  |  |  |  
 
 |  |  
			|  |  |  
 
 |  |  
		|  |  |  
	|  |  
	| 
	
		|  Posted: Thu Dec 27, 2012 10:14 pm |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| pirate-sky |  | Advanced user |  |  
  |  |  |  | Joined: Dec 17, 2012 |  | Posts: 75 |  |  |  |  
 
 |  |  
			|  |  |  
 
 |  |  
		|  |  |  
	|  |  
	| 
	
		|  Posted: Fri Dec 28, 2012 6:08 am |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| amin |  | Regular user |  |  
  |  |  |  | Joined: Aug 08, 2012 |  | Posts: 10 |  |  |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			| thank you but as you see there is some names that is not decoded properly such as _obfuscate_eGVobXo4aWIя
 in here
 http://pastebin.com/M3U6y5Ky
 
 and i have bunch of this files and i need the decoder to decode them.
 
 
 thanks
 |  |  
		|  |  |  
	|  |  
	|  | opf db |  |  
	| 
	
		|  Posted: Fri Dec 28, 2012 4:09 pm |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| amin |  | Regular user |  |  
  |  |  |  | Joined: Aug 08, 2012 |  | Posts: 10 |  |  |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			| i have found a opf db like this ; 
 array('jdate','_obfuscate_ZC8rHHoÿ'),
 array('$ip','$_obfuscate_Asÿ'),
 array('$get_user_info','$_obfuscate_amyM0UI2ZB2Hlodoxwÿÿ'),
 array('get_user_info','_obfuscate_bh16aDByCiogAWBubQÿÿ'),
 
 that i can replace obfuscated names with real ones:
 
 for example $ip=$_obfuscate_Asÿ;
 
 does any body have complete db?
 
 thanks
 |  |  
		|  |  |  
	|  |  
	|  | Re: opf db |  |  
	| 
	
		|  Posted: Fri Dec 28, 2012 8:51 pm |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| Cyko |  | Moderator |  |  
  |  |  |  | Joined: Jul 21, 2009 |  | Posts: 375 |  |  |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			|  	  | amin wrote: |  	  | i have found a opf db like this ; 
 array('jdate','_obfuscate_ZC8rHHoÿ'),
 array('$ip','$_obfuscate_Asÿ'),
 array('$get_user_info','$_obfuscate_amyM0UI2ZB2Hlodoxwÿÿ'),
 array('get_user_info','_obfuscate_bh16aDByCiogAWBubQÿÿ'),
 
 that i can replace obfuscated names with real ones:
 
 for example $ip=$_obfuscate_Asÿ;
 
 does any body have complete db?
 
 thanks
 | 
 
 I have not bothered to look at your file, but...
 
 
 If the file was originally encoded with zend:
 
 If you run the file through the db you have - at least all obfuscated internal functions should be replaced to there equivalents (assuming the db you have, has not been changed from the original publication). Any remaining obfuscates will be user defined - so these could equate to almost anything! (which means the db can never be 'complete'
  ). 
 If the file was originally encoded with ioncube:
 
 Unfourtanetly this makes it slightly more difficult then the above - as a unique key is used for the obfuscation, so the db you have will not even replace the obfuscated internal functions!
 
 So how do you deobfuscate the obfuscates not covered?
 
 Analyse the whole PHP script - looking for trends, and then add to the db - this should not be too difficult if you have sufficient PHP knowledge.
 |  |  
		|  |  |  
	|  |  |  | 
 
	|  |  |  |  
	| 
	
		|  Posted: Fri Dec 28, 2012 9:01 pm |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| amin |  | Regular user |  |  
  |  |  |  | Joined: Aug 08, 2012 |  | Posts: 10 |  |  |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			| thank you cyko i know that the file was originally encoded with zend
 
 all i want is a bigger db of this dictionary because there is many obfuscated names yet.
 
 some one told me :
 
  	  | Quote: |  	  | eg. under NWS-core and run the cmd line: php.exe /level:4,3 /dic
 and then you can get the dic file php_info.log, Making them to obs's php array by Base64 encoder...
 | 
 
 but i did not know what he said.
 |  |  
		|  |  |  
	|  |  
	| 
	
		|  Posted: Sun Jan 27, 2013 5:14 pm |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| anandinvit |  | Regular user |  |  
  |  |  |  | Joined: Jan 26, 2013 |  | Posts: 6 |  |  |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			| it is hard to decode some php if they are coded again and again i.e if there are many layers. so if we decode 1 layer we will find the second layer and this may continue to some steps. |  |  
		|  |  |  
	|  |  
	| www.waraxe.us Forum Index -> Php 
 
	
		| You cannot post new topics in this forum You cannot reply to topics in this forum
 You cannot edit your posts in this forum
 You cannot delete your posts in this forum
 You cannot vote in polls in this forum
 
 | All times are GMT Page 1 of 1
 
 |  |  
	|  |  
 Powered by phpBB © 2001-2008 phpBB Group
 
 
 
 
 |  |  |  |  |  |