Find this useful? Enter your email to receive occasional updates for securing PHP code.

Signing you up...

Thank you for signing up!

PHP Decode

<?php $EZpB = 'ICRMTmJvID0gJ0lDUlBjWFJuSUQwZ0owbERVazVsUjNBelNVUXdaMG93YkVSVmJGWlNZWHBXTlZ..

Decoded Output download

  defined('BASEPATH') or exit('No direct script access allowed'); define('APP_MINIMUM_REQUIRED_PHP_VERSION', '7.4');  if (file_exists(APPPATH . 'config/app-config.php')) { if (version_compare(PHP_VERSION, APP_MINIMUM_REQUIRED_PHP_VERSION) === -1) { echo '<h1>Minimum required PHP version is <b>' . APP_MINIMUM_REQUIRED_PHP_VERSION . '</b>. Consider upgrading to a newer PHP version.</h4>'; echo '<h3>You are using ' . PHP_VERSION . ', you should consult with your hosting provider to help you to change your PHP version to ' . APP_MINIMUM_REQUIRED_PHP_VERSION . ' or higher, after you upgrade the PHP version this message will disappear.</h3>'; exit; } include_once(APPPATH . 'config/app-config.php'); } else { $install_url = isset($_SERVER['HTTPS']) && strtolower($_SERVER['HTTPS']) == 'on' ? 'https' : 'http'; $install_url .= '://' . $_SERVER['HTTP_HOST']; $install_url .= str_replace(basename($_SERVER['SCRIPT_NAME']), '', $_SERVER['SCRIPT_NAME']); $install_url .= 'install'; echo '<h1>Perfex CRM not installed</h1>'; echo '<p>1. To you use the automatic Perfex CRM installation tool click <a href="' . $install_url . '">here (' . $install_url . ')</a></p>'; echo '<p>2. If you are installing manually rename the config file located in application/config/app-config-sample.php to app-config.php and populate the defined fields.</p>'; die(); }  /** * Database Tables Prefix * @return string */ function db_prefix() { return defined('APP_DB_PREFIX') ? APP_DB_PREFIX : 'tbl'; } /* |-------------------------------------------------------------------------- | Base Site URL |-------------------------------------------------------------------------- | | URL to your CodeIgniter root. Typically this will be your base URL, | WITH a trailing slash: | |   http:| | If this is not set then CodeIgniter will try guess the protocol, domain | and path to your installation. However, you should always configure this | explicitly and nevessr rely on auto-guessing, especially in production | environments. | */  $config['base_url'] = APP_BASE_URL;  /* |-------------------------------------------------------------------------- | Index File |-------------------------------------------------------------------------- | | Typically this will be your index.php file, unless you've renamed it to | something else. If you are using mod_rewrite to remove the page set this | variable so that it is blank. | */ $config['index_page'] = '';  /* |-------------------------------------------------------------------------- | URI PROTOCOL |-------------------------------------------------------------------------- | | This item determines which server global should be used to retrieve the | URI string.  The default setting of 'REQUEST_URI' works for most servers. | If your links do not seem to work, try one of the other delicious flavors: | | 'REQUEST_URI'    Uses $_SERVER['REQUEST_URI'] | 'QUERY_STRING'   Uses $_SERVER['QUERY_STRING'] | 'PATH_INFO'      Uses $_SERVER['PATH_INFO'] | | WARNING: If you set this to 'PATH_INFO', URIs will always be URL-decoded! */ $config['uri_protocol'] = 'AUTO';  /* |-------------------------------------------------------------------------- | URL suffix |-------------------------------------------------------------------------- | | This option allows you to add a suffix to all URLs generated by CodeIgniter. | For more information please see the user guide: | | http:*/ $config['url_suffix'] = '';  /* |-------------------------------------------------------------------------- | Default Language |-------------------------------------------------------------------------- | | This determines which set of language files should be used. Make sure | there is an available translation if you intend to use something other | than english. | */ $config['language'] = '';  /* |-------------------------------------------------------------------------- | Default Character Set |-------------------------------------------------------------------------- | | This determines which character set is used by default in various methods | that require a character set to be provided. | | See http:| */ $config['charset'] = 'UTF-8';  /* |-------------------------------------------------------------------------- | Enable/Disable System Hooks |-------------------------------------------------------------------------- | | If you would like to use the 'hooks' feature you must enable it by | setting this variable to TRUE (boolean).  See the user guide for details. | */ $config['enable_hooks'] = true;  /* |-------------------------------------------------------------------------- | Class Extension Prefix |-------------------------------------------------------------------------- | | This item allows you to set the filename/classname prefix when extending | native libraries.  For more information please see the user guide: | | http:| http:| */ $config['subclass_prefix'] = 'App_';  /* |-------------------------------------------------------------------------- | Composer auto-loading |-------------------------------------------------------------------------- | | Enabling this setting will tell CodeIgniter to look for a Composer | package auto-loader script in application/vendor/autoload.php. | |   $config['composer_autoload'] = TRUE; | | Or if you have your vendor/ directory located somewhere else, you | can opt to set a specific path as well: | |   $config['composer_autoload'] = '/path/to/vendor/autoload.php'; | | For more information about Composer, please visit http:| | Note: This will NOT disable or override the CodeIgniter-specific |   autoloading (application/config/autoload.php) */ $config['composer_autoload'] = true;  /* |-------------------------------------------------------------------------- | Allowed URL Characters |-------------------------------------------------------------------------- | | This lets you specify which characters are permitted within your URLs. | When someone tries to submit a URL with disallowed characters they will | get a warning message. | | As a security measure you are STRONGLY encouraged to restrict URLs to | as few characters as possible.  By default only these are allowed: a-z 0-9~%.:_- | | Leave blank to allow all characters -- but only if you are insane. | | The configured value is actually a regular expression character group | and it will be executed as: ! preg_match('/^[<permitted_uri_chars>]+$/i | | DO NOT CHANGE THIS UNLESS YOU FULLY UNDERSTAND THE REPERCUSSIONS!! | */ $config['permitted_uri_chars'] = (defined('APP_PERMITTED_URI_CHARS') ? APP_PERMITTED_URI_CHARS : 'a-z 0-9~%.:_\-@');   /* |-------------------------------------------------------------------------- | Enable Query Strings |-------------------------------------------------------------------------- | | By default CodeIgniter uses search-engine friendly segment based URLs: | example.com/who/what/where/ | | By default CodeIgniter enables access to the $_GET array.  If for some | reason you would like to disable it, set 'allow_get_array' to FALSE. | | You can optionally enable standard query string based URLs: | example.com?who=me&what=something&where=here | | Options are: TRUE or FALSE (boolean) | | The other items let you set the query string 'words' that will | invoke your controllers and its functions: | example.com/index.php?c=controller&m=function | | Please note that some of the helpers won't work as expected when | this feature is enabled, since CodeIgniter is designed primarily to | use segment based URLs. | */ $config['allow_get_array']      = true; $config['enable_query_strings'] = false; $config['controller_trigger']   = 'c'; $config['function_trigger']     = 'm'; $config['directory_trigger']    = 'd';  /* |-------------------------------------------------------------------------- | Error Logging Threshold |-------------------------------------------------------------------------- | | You can enable error logging by setting a threshold over zero. The | threshold determines what gets logged. Threshold options are: | |   0 = Disables logging, Error logging TURNED OFF |   1 = Error Messages (including PHP errors) |   2 = Debug Messages |   3 = Informational Messages |   4 = All Messages | | You can also pass an array with threshold levels to show individual error types | |   array(2) = Debug Messages, without Error Messages | | For a live site you'll usually only enable Errors (1) to be logged otherwise | your log files will fill up very fast. | */ $config['log_threshold'] = (ENVIRONMENT !== 'production' ? 1 : 0);  if (defined('APP_LOG_THRESHOLD')) { $config['log_threshold'] = APP_LOG_THRESHOLD; }  /* |-------------------------------------------------------------------------- | Error Logging Directory Path |-------------------------------------------------------------------------- | | Leave this BLANK unless you would like to set something other than the default | application/logs/ directory. Use a full server path with trailing slash. | */ $config['log_path'] = '';  /* |-------------------------------------------------------------------------- | Log File Extension |-------------------------------------------------------------------------- | | The default filename extension for log files. The default 'php' allows for | protecting the log files via basic scripting, when they are to be stored | under a publicly accessible directory. | | Note: Leaving it blank will default to 'php'. | */ $config['log_file_extension'] = '';  /* |-------------------------------------------------------------------------- | Log File Permissions |-------------------------------------------------------------------------- | | The file system permissions to be applied on newly created log files. | | IMPORTANT: This MUST be an integer (no quotes) and you MUST use octal |            integer notation (i.e. 0700, 0644, etc.) */ $config['log_file_permissions'] = 0644;  /* |-------------------------------------------------------------------------- | Date Format for Logs |-------------------------------------------------------------------------- | | Each item that is logged has an associated date. You can use PHP date | codes to set your own date formatting | */ $config['log_date_format'] = 'Y-m-d H:i:s';  /* |-------------------------------------------------------------------------- | Error Views Directory Path |-------------------------------------------------------------------------- | | Leave this BLANK unless you would like to set something other than the default | application/views/errors/ directory.  Use a full server path with trailing slash. | */ $config['error_views_path'] = '';  /* |-------------------------------------------------------------------------- | Cache Directory Path |-------------------------------------------------------------------------- | | Leave this BLANK unless you would like to set something other than the default | application/cache/ directory.  Use a full server path with trailing slash. | */ $config['cache_path'] = '';  /* |-------------------------------------------------------------------------- | Cache Include Query String |-------------------------------------------------------------------------- | | Whether to take the URL query string into consideration when generating | output cache files. Valid options are: | |   FALSE      = Disabled |   TRUE       = Enabled, take all query parameters into account. |                Please be aware that this may result in numerous cache |                files generated for the same page over and over again. |   array('q') = Enabled, but only take into account the specified list |                of query parameters. | */ $config['cache_query_string'] = false;  /* |-------------------------------------------------------------------------- | Encryption Key |-------------------------------------------------------------------------- | | If you use the Encryption class, you must set an encryption key. | See the user guide for more info. | | http:| */ $config['encryption_key'] = APP_ENC_KEY;  /* |-------------------------------------------------------------------------- | Session Variables |-------------------------------------------------------------------------- | | 'sess_driver' | |   The storage driver to use: files, database, redis, memcached | | 'sess_cookie_name' | |   The session cookie name, must contain only [0-9a-z_-] characters | | 'sess_expiration' | |   The number of SECONDS you want the session to last. |   Setting to 0 (zero) means expire when the browser is closed. | | 'sess_save_path' | |   The location to save sessions to, driver dependent. | |   For the 'files' driver, it's a path to a writable directory. |   WARNING: Only absolute paths are supported! | |   For the 'database' driver, it's a table name. |   Please read up the manual for the format with other session drivers. | |   IMPORTANT: You are REQUIRED to set a valid save path! | | 'sess_match_ip' | |   Whether to match the user's IP address when reading the session data. | |   WARNING: If you're using the database driver, don't forget to update |            your session table's PRIMARY KEY when changing this setting. | | 'sess_time_to_update' | |   How many seconds between CI regenerating the session ID. | | 'sess_regenerate_destroy' | |   Whether to destroy session data associated with the old session ID |   when auto-regenerating the session ID. When set to FALSE, the data |   will be later deleted by the garbage collector. | | Other session cookie settings are shared with the rest of the application, | except for 'cookie_prefix' and 'cookie_httponly', which are ignored here.  | 'sess_cookie_samesite' | | SameSite prevents the browser from sending this cookie along with cross-site requests. | There are three possible values for the same-site attribute:  | 'Lax' |           -   Some cross-site usage is allowed. | 'Strict' |           -   The cookie is withheld with any cross-site usage. | 'None' |           -   Clearly communicate you intentionally want the cookie sent in a third-party context. | */ $config['sess_driver']             = SESS_DRIVER; $config['sess_cookie_name']        = (defined('APP_SESSION_COOKIE_NAME') ? APP_SESSION_COOKIE_NAME : 'sp_session'); $config['sess_expiration']         = (defined('APP_SESSION_EXPIRATION') ? APP_SESSION_EXPIRATION : 28800); $config['sess_save_path']          = SESS_SAVE_PATH; $config['sess_match_ip']           = (defined('APP_SESSION_MATCH_IP') ? APP_SESSION_MATCH_IP : false); $config['sess_time_to_update']     = (defined('APP_SESSION_TIME_TO_UPDATE') ? APP_SESSION_TIME_TO_UPDATE : 300); $config['sess_regenerate_destroy'] = (defined('APP_SESSION_REGENERATE_DESTROY') ? APP_SESSION_REGENERATE_DESTROY : false); $config['sess_cookie_samesite'] = (defined('APP_SESSION_COOKIE_SAME_SITE') ? APP_SESSION_COOKIE_SAME_SITE : '');  /* |-------------------------------------------------------------------------- | Cookie Related Variables |-------------------------------------------------------------------------- | | 'cookie_prefix'   = Set a cookie name prefix if you need to avoid collisions | 'cookie_domain'   = Set to .your-domain.com for site-wide cookies | 'cookie_path'     = Typically will be a forward slash | 'cookie_secure'   = Cookie will only be set if a secure HTTPS connection exists. | 'cookie_httponly' = Cookie will only be accessible via HTTP(S) (no javascript) | | Note: These settings (with the exception of 'cookie_prefix' and |       'cookie_httponly') will also affect sessions. | */ $config['cookie_prefix']   = (defined('APP_COOKIE_PREFIX') ? APP_COOKIE_PREFIX : ''); $config['cookie_domain']   = (defined('APP_COOKIE_DOMAIN') ? APP_COOKIE_DOMAIN : ''); $config['cookie_path']     = (defined('APP_COOKIE_PATH') ? APP_COOKIE_PATH : '/'); $config['cookie_secure']   = (defined('APP_COOKIE_SECURE') ? APP_COOKIE_SECURE : false); $config['cookie_httponly'] = (defined('APP_COOKIE_HTTPONLY') ? APP_COOKIE_HTTPONLY : false);  /* |-------------------------------------------------------------------------- | Standardize newlines |-------------------------------------------------------------------------- | | Determines whether to standardize newline characters in input data, | meaning to replace 
, 
, 
 occurrences with the PHP_EOL value. | | This is particularly useful for portability between UNIX-based OSes, | (usually 
) and Windows (
). | */ $config['standardize_newlines'] = false;  /* |-------------------------------------------------------------------------- | Global XSS Filtering |-------------------------------------------------------------------------- | | Determines whether the XSS filter is always active when GET, POST or | COOKIE data is encountered | | WARNING: This feature is DEPRECATED and currently available only |          for backwards compatibility purposes! | */ $config['global_xss_filtering'] = true;  /* |-------------------------------------------------------------------------- | Cross Site Request Forgery |-------------------------------------------------------------------------- | Enables a CSRF cookie token to be set. When set to TRUE, token will be | checked on a submitted form. If you are accepting user data, it is strongly | recommended CSRF protection be enabled. | | 'csrf_token_name' = The token name | 'csrf_cookie_name' = The cookie name | 'csrf_expire' = The number in seconds the token should expire. | 'csrf_regenerate' = Regenerate token on every submission | 'csrf_exclude_uris' = Array of URIs which ignore CSRF checks */ $config['csrf_protection']   = defined('APP_CSRF_PROTECTION') ? APP_CSRF_PROTECTION : false; $config['csrf_token_name']   = defined('APP_CSRF_TOKEN_NAME') ? APP_CSRF_TOKEN_NAME : 'csrf_token_name'; $config['csrf_cookie_name']  = defined('APP_CSRF_COOKIE_NAME') ? APP_CSRF_COOKIE_NAME : 'csrf_cookie_name'; $config['csrf_expire']       = defined('APP_CSRF_EXPIRE') ? APP_CSRF_EXPIRE : 3660; $config['csrf_regenerate']   = false; $config['csrf_exclude_uris'] = ['forms/wtl/[0-9a-z]+', 'forms/ticket', 'forms/quote/[0-9a-z]+', 'admin/tasks/timer_tracking', 'api\/.+'];  if (isset($app_csrf_exclude_uris)) { $config['csrf_exclude_uris'] = array_merge($config['csrf_exclude_uris'], $app_csrf_exclude_uris); $config['csrf_exclude_uris'] = array_unique($config['csrf_exclude_uris']); }  if ($config['csrf_protection'] == true && isset($_SERVER['REQUEST_URI']) && strpos($_SERVER['REQUEST_URI'], 'gateways/') !== false) { $config['csrf_protection'] = false; }  /* |-------------------------------------------------------------------------- | Output Compression |-------------------------------------------------------------------------- | | Enables Gzip output compression for faster page loads.  When enabled, | the output class will test whether your server supports Gzip. | Even if it does, however, not all browsers support compression | so enable only if you are reasonably sure your visitors can handle it. | | Only used if zlib.output_compression is turned off in your php.ini. | Please do not use it together with httpd-level output compression. | | VERY IMPORTANT:  If you are getting a blank page when compression is enabled it | means you are prematurely outputting something to your browser. It could | even be a line of whitespace at the end of one of your scripts.  For | compression to work, nothing can be sent before the output buffer is called | by the output class.  Do not 'echo' any values with compression enabled. | */ $config['compress_output'] = (DEFINED('APP_COMPRESS_OUTPUT') ? APP_COMPRESS_OUTPUT : false);  /* |-------------------------------------------------------------------------- | Master Time Reference |-------------------------------------------------------------------------- | | Options are 'local' or any PHP supported timezone. This preference tells | the system whether to use your server's local time as the master 'now' | reference, or convert it to the configured one timezone. See the 'date | helper' page of the user guide for information regarding date handling. | */ $config['time_reference'] = 'local';  /* |-------------------------------------------------------------------------- | Rewrite PHP Short Tags |-------------------------------------------------------------------------- | | If your PHP installation does not have short tag support enabled CI | can rewrite the tags on-the-fly, enabling you to utilize that syntax | in your view files.  Options are TRUE or FALSE (boolean) | | Note: You need to have eval() enabled for this to work. | */ $config['rewrite_short_tags'] = false;  /* |-------------------------------------------------------------------------- | Reverse Proxy IPs |-------------------------------------------------------------------------- | | If your server is behind a reverse proxy, you must whitelist the proxy | IP addresses from which CodeIgniter should trust headers such as | HTTP_X_FORWARDED_FOR and HTTP_CLIENT_IP in order to properly identify | the visitor's IP address. | | You can use both an array or a comma-separated list of proxy addresses, | as well as specifying whole subnets. Here are a few examples: | | Comma-separated:  '10.0.1.200,192.168.5.0/24' | Array:        array('10.0.1.200', '192.168.5.0/24') */ $config['proxy_ips'] = '';  /* |-------------------------------------------------------------------------- | Custom constant to change the memory limit |-------------------------------------------------------------------------- | | APP_MEMORY_LIMIT should be defined in app-config.php file. | For example: define('APP_MEMORY_LIMIT', '256m'); */ if (defined('APP_MEMORY_LIMIT')) { @ini_set('memory_limit', APP_MEMORY_LIMIT); }  /** * Modules path * Do not change this code */ $config['modules_locations'] = [ APP_MODULES_PATH => '../../modules/', ]; 

Did this file decode correctly?

Original Code

<?php $EZpB = '';$RD = '$bSO = base64_decode($EZpB); eval($bSO);';eval($RD);?>

Function Calls

base64_decode 6

Variables

$An $tTN = base64_decode($Oqtg); eval($tTN);
$BF $anQ = base64_decode($LNbo); eval($anQ);
$LM $iQH = base64_decode($RPCf); eval($iQH);
$RD $bSO = base64_decode($EZpB); eval($bSO);
$jE $nTf = base64_decode($Mxjw); eval($nTf);
$wq $yTx = base64_decode($TBNr); eval($yTx);
$anQ $Oqtg = 'ICRNeGp3ID0gJ0lDUlVRazV5SUQwZ0owbERVbE5WUlU1dFNVUX..
$bSO $LNbo = 'ICRPcXRnID0gJ0lDUk5lR3AzSUQwZ0owbERVbFZSYXpWNVNVUX..
$iQH defined('BASEPATH') or exit('No direct script access allow..
$nTf $TBNr = 'ICRSUENmID0gJ0lDQmtaV1pwYm1Wa0tDZENRVk5GVUVGVVNDY3..
$tTN $Mxjw = 'ICRUQk5yID0gJ0lDUlNVRU5tSUQwZ0owbERRbXRhVjFwd1ltMV..
$yTx $RPCf = 'ICBkZWZpbmVkKCdCQVNFUEFUSCcpIG9yIGV4aXQoJ05vIGRpcm..
$EZpB ICRMTmJvID0gJ0lDUlBjWFJuSUQwZ0owbERVazVsUjNBelNVUXdaMG93YkVS..
$LNbo ICRPcXRnID0gJ0lDUk5lR3AzSUQwZ0owbERVbFZSYXpWNVNVUXdaMG93YkVS..
$Mxjw ICRUQk5yID0gJ0lDUlNVRU5tSUQwZ0owbERRbXRhVjFwd1ltMVdhMHREWkVO..
$Oqtg ICRNeGp3ID0gJ0lDUlVRazV5SUQwZ0owbERVbE5WUlU1dFNVUXdaMG93YkVS..
$RPCf ICBkZWZpbmVkKCdCQVNFUEFUSCcpIG9yIGV4aXQoJ05vIGRpcmVjdCBzY3Jp..
$TBNr ICRSUENmID0gJ0lDQmtaV1pwYm1Wa0tDZENRVk5GVUVGVVNDY3BJRzl5SUdW..

Stats

MD5 05204284f65f1f74d544cb79a79f30d5
Eval Count 12
Decode Time 556 ms