Welcome to WebmasterWorld Guest from 54.242.94.72

Forum Moderators: coopster & jatar k

Message Too Old, No Replies

what type of encryption is this

what type of php encryption

     

dhruva

10:22 am on Jan 29, 2011 (gmt 0)



please tell me what type of encryption is this and how to decode it
<?php $OOO000000=urldecode('%66%67%36%73%62%65%68%70%72%61%34%63%6f%5f%74%6e%64');
$OOO0000O0=$OOO000000{4}.$OOO000000{9}.$OOO000000{3}.$OOO000000{5};
$OOO0000O0.=$OOO000000{2}.$OOO000000{10}.$OOO000000{13}.$OOO000000{16};
$OOO0000O0.=$OOO0000O0{3}.$OOO000000{11}.$OOO000000{12}.$OOO0000O0{7}.$OOO000000{5};
$OOO000O00=$OOO000000{0}.$OOO000000{12}.$OOO000000{7}.$OOO000000{5}.$OOO000000{15};
$O0O000O00=$OOO000000{0}.$OOO000000{1}.$OOO000000{5}.$OOO000000{14};$O0O000O0O=$O0O000O00.$OOO000000{11};
$O0O000O00=$O0O000O00.$OOO000000{3};
$O0O00OO00=$OOO000000{0}.$OOO000000{8}.$OOO000000{5}.$OOO000000{9}.$OOO000000{16};
$OOO00000O=$OOO000000{3}.$OOO000000{14}.$OOO000000{8}.$OOO000000{14}.$OOO000000{8};
$OOO0O0O00=__FILE__;$OO00O0000=0x1280;
eval($OOO0000O0('[i]<long string of characters here>[/i]'));return;?>[i]<long string of characters here>[/i]

[edited by: coopster at 2:45 pm (utc) on Jan 31, 2011]
[edit reason] removed eval potential to protect future readers [/edit]

Jonesy

11:41 pm on Jan 29, 2011 (gmt 0)

5+ Year Member



"Protection Through Obfuscation" ?

What did you get when you executed all the statements?
I got "fg6sbehpra4co_tnd" for the first statement...
I din'na have the patience to break down the whole thing.

Maybe "Protection Through Frustration" ?

You did notice the oh-so 'clever' use of similar-looking variable names
all beginning with the letter "OH" and followed by various mixes of other
letter "OH"s and numeral "ZEROES" -- did you not?

Would appear you're attempting to hack around in someone else's code --
written by a contractor/consultant?

Jonesy

coopster

2:48 pm on Jan 31, 2011 (gmt 0)

WebmasterWorld Administrator coopster is a WebmasterWorld Top Contributor of All Time 10+ Year Member



Welcome to WebmasterWorld, dhruva.

I removed the potentially malicious strings of data and also broke the string up into chunks to remove the sidescroll on the display.

The code is urlencoded and base64 encoded, loaded with eval() statements, which are used to evaluate PHP code and execute it from a string value. The code itself opens the file that it is in, reads itself, peels itself apart and executes PHP code on the server which it is located.

dhruva

3:47 pm on Feb 6, 2011 (gmt 0)



i tried to decode it with urlecncoded but it was failure , some time its work but with error may be its my fault
 

Featured Threads

Hot Threads This Week

Hot Threads This Month