PDA

View Full Version : WHAT IS THIS?!



Dentafrice,
18-11-2007, 09:35 PM
<?php $_F=__FILE__;$_X='Pz48ZDR2IDRkPSJmMjJ0NXIiPjxwPjw/cGhwIGJsMmc0bmYyKCduMW01Jyk7ID8+IDRzIHByMjNkbHkgcD J3NXI1ZCBieSA8MSBocjVmPSJodHRwOi8vdzJyZHByNXNzLjJy Zy8iPlcycmRQcjVzczwvMT4uIEQ1czRnbjVkIGJ5OiA8MSBocj VmPSJodHRwOi8vd3d3Lm9laWsxcm0xLmMybSI+b2VpIEsxcm0x PC8xPjxicj4NClNwMm5zMnI1ZCBieTogPDEgaHI1Zj0iaHR0cD ovL3d3dy5teXI0bmd0Mm41c2gzYi5jMm0vIj5EMndubDIxZCBS NG5ndDJuNXM8LzE+IHwgPDEgaHI1Zj0iaHR0cDovLzRudjVzdD RuZy02MDYuMnJnLyI+SW52NXN0NG5nIDYwNjwvMT4gfCA8MSBo cjVmPSJodHRwOi8vc2s0bi1kNHM1MXM1Lm41dC8iPlNrNG4gRD RzNTFzNTwvMT4NCjwvc2NyNHB0PjwhLS0gfCA8P3BocCA1Y2gy IGc1dF9uM21fcTM1cjQ1cygpOyA/PiBxMzVyNDVzLiA8P3BocCB0NG01cl9zdDJwKDYpOyA/PiBzNWMybmRzLi0tPiA8P3BocCB3cF9mMjJ0NXIoKTsgPz48L3 A+PC9kNHY+';eval(base64_decode('JF9YPWJhc2U2NF9kZW NvZGUoJF9YKTskX1g9c3RydHIoJF9YLCcxMjM0NTZhb3VpZScs J2FvdWllMTIzNDU2Jyk7JF9SPWVyZWdfcmVwbGFjZSgnX19GSU xFX18nLCInIi4kX0YuIiciLCRfWCk7ZXZhbCgkX1IpOyRfUj0w OyRfWD0wOw=='));?>
It was on a wordpress theme.. and I can't figure out how to decrypt it.

FIGURED IT OUT! :)

Florx
18-11-2007, 09:43 PM
SHARE! >:)

Dentafrice,
18-11-2007, 10:18 PM
<?php
$_F=__FILE__;$_X='Pz48ZDR2IDRkPSJmMjJ0NXIiPjxwPjw/cGhwIGJsMmc0bmYyKCduMW01Jyk7ID8+IDRzIHByMjNkbHkgcD J3NXI1ZCBieSA8MSBocjVmPSJodHRwOi8vdzJyZHByNXNzLjJy Zy8iPlcycmRQcjVzczwvMT4uIEQ1czRnbjVkIGJ5OiA8MSBocj VmPSJodHRwOi8vd3d3Lm9laWsxcm0xLmMybSI+b2VpIEsxcm0x PC8xPjxicj4NClNwMm5zMnI1ZCBieTogPDEgaHI1Zj0iaHR0cD ovL3d3dy5teXI0bmd0Mm41c2gzYi5jMm0vIj5EMndubDIxZCBS NG5ndDJuNXM8LzE+IHwgPDEgaHI1Zj0iaHR0cDovLzRudjVzdD RuZy02MDYuMnJnLyI+SW52NXN0NG5nIDYwNjwvMT4gfCA8MSBo cjVmPSJodHRwOi8vc2s0bi1kNHM1MXM1Lm41dC8iPlNrNG4gRD RzNTFzNTwvMT4NCjwvc2NyNHB0PjwhLS0gfCA8P3BocCA1Y2gy IGc1dF9uM21fcTM1cjQ1cygpOyA/PiBxMzVyNDVzLiA8P3BocCB0NG01cl9zdDJwKDYpOyA/PiBzNWMybmRzLi0tPiA8P3BocCB3cF9mMjJ0NXIoKTsgPz48L3 A+PC9kNHY+';

eval(base64_decode('JF9YPWJhc2U2NF9kZWNvZGUoJF9YKT skX1g9c3RydHIoJF9YLCcxMjM0NTZhb3VpZScsJ2FvdWllMTIz NDU2Jyk7JF9SPWVyZWdfcmVwbGFjZSgnX19GSUxFX18nLCInIi 4kX0YuIiciLCRfWCk7ZXZhbCgkX1IpOyRfUj0wOyRfWD0wOw== '));
?>



then



<?php

$test = base64_decode('JF9YPWJhc2U2NF9kZWNvZGUoJF9YKTskX1g 9c3RydHIoJF9YLCcxMjM0NTZhb3VpZScsJ2FvdWllMTIzNDU2J yk7JF9SPWVyZWdfcmVwbGFjZSgnX19GSUxFX18nLCInIi4kX0Y uIiciLCRfWCk7ZXZhbCgkX1IpOyRfUj0wOyRfWD0wOw==');

echo $test;
?>


$_X=base64_decode($_X);$_X=strtr($_X,'123456aouie' ,'aouie123456');$_R=ereg_replace('__FILE__',"'".$_F."'",$_X);eval($_R);$_R=0;$_X=0;



<?php
$_F=__FILE__;$_X='Pz48ZDR2IDRkPSJmMjJ0NXIiPjxwPjw/cGhwIGJsMmc0bmYyKCduMW01Jyk7ID8+IDRzIHByMjNkbHkgcD J3NXI1ZCBieSA8MSBocjVmPSJodHRwOi8vdzJyZHByNXNzLjJy Zy8iPlcycmRQcjVzczwvMT4uIEQ1czRnbjVkIGJ5OiA8MSBocj VmPSJodHRwOi8vd3d3Lm9laWsxcm0xLmMybSI+b2VpIEsxcm0x PC8xPjxicj4NClNwMm5zMnI1ZCBieTogPDEgaHI1Zj0iaHR0cD ovL3d3dy5teXI0bmd0Mm41c2gzYi5jMm0vIj5EMndubDIxZCBS NG5ndDJuNXM8LzE+IHwgPDEgaHI1Zj0iaHR0cDovLzRudjVzdD RuZy02MDYuMnJnLyI+SW52NXN0NG5nIDYwNjwvMT4gfCA8MSBo cjVmPSJodHRwOi8vc2s0bi1kNHM1MXM1Lm41dC8iPlNrNG4gRD RzNTFzNTwvMT4NCjwvc2NyNHB0PjwhLS0gfCA8P3BocCA1Y2gy IGc1dF9uM21fcTM1cjQ1cygpOyA/PiBxMzVyNDVzLiA8P3BocCB0NG01cl9zdDJwKDYpOyA/PiBzNWMybmRzLi0tPiA8P3BocCB3cF9mMjJ0NXIoKTsgPz48L3 A+PC9kNHY+';

$_X=base64_decode($_X);
$_X=strtr($_X,'123456aouie','aouie123456');
$_R=ereg_replace('__FILE__',"'".$_F."'",$_X);
echo $_R;
?>


=



?><div id="footer"><p><?php bloginfo('name'); ?> is proudly powered by <a href="http://wordpress.org/">WordPress</a>. Designed by: <a href="http://www.365karma.com">365 Karma</a><br>
Sponsored by: <a href="http://www.myringtoneshub.com/">Download Ringtones</a> | <a href="http://investing-101.org/">Investing 101</a> | <a href="http://skin-disease.net/">Skin Disease</a>
</script><!-- | <?php echo get_num_queries(); ?> queries. <?php timer_stop(1); ?> seconds.--> <?php wp_footer(); ?></p></div>

Florx
18-11-2007, 10:20 PM
O.K.......

And how did you figure that out?

Dentafrice,
18-11-2007, 10:23 PM
Simple PHP after I broke it down and looked at it :)

Stephen
18-11-2007, 10:26 PM
Simple PHP after I broke it down and looked at it :)

Omg you php boff! :P

MrCraig
24-11-2007, 07:56 PM
*Text Removed*

Nice find though =]

It looks like the code was originally generated by byterun :P

Edited by opensourcehost (Forum Super Moderator): Please do not discuss illegal activities or activities that would be prohibited on Habbo Hotel in conjunction with the Habbo Way.

RedCrisps
24-11-2007, 08:00 PM
if radiodjpanel was decoded i am not sure people will majourly edit it except the frontend maybe

Florx
24-11-2007, 08:09 PM
if radiodjpanel was decoded i am not sure people will majourly edit it except the frontend maybe
It has been decoded actually :p

MrCraig
24-11-2007, 08:10 PM
yeh, but loads of people would remove copyright, and radiodjpanel would have as many styles as housecall has like nobody would know what system it actually is.

And my mates server doesnt like file_get_contents for some reason. so that would be removed.

+ SHARE FLORX
++ Sorry mod :S Whats it got to do with Habbo Hotel :|

Florx
24-11-2007, 08:13 PM
No I don't have a copy of the decoded cause I deleted it due to I was making my own.

redtom
24-11-2007, 08:14 PM
+ SHARE FLORX

No don't some one worked hard on it and gave it to people to use, if he doesn't want people messing with it then don't, decode it yourself and if you can decode it you should beable to make your own, so it's not really that usefull decoding it.

QuickScriptz
24-11-2007, 08:15 PM
And my mates server doesnt like file_get_contents for some reason. so that would be removed.

It doesn't use the file_get_contents.....?

MrCraig
24-11-2007, 08:18 PM
well fopen and stuff like that.. its for the check update thing.
Thats the only reason i asked florx to share due to my friend not being able to use it for that reason.

These go 10x down the page


Warning: fopen() [function.fopen]: URL file-access is disabled in the server configuration in /home/ci/public_html/radiodjpanel/home.php(7) : eval()'d code(1) : eval()'d code on line 39

Warning: fopen(http://www.quickscriptz.ca/radiodjpanel_update.txt) [function.fopen]: failed to open stream: no suitable wrapper could be found in /home/ci/public_html/radiodjpanel/home.php(7) : eval()'d code(1) : eval()'d code on line 39

Warning: feof(): supplied argument is not a valid stream resource in /home/ci/public_html/radiodjpanel/home.php(7) : eval()'d code(1) : eval()'d code on line 41

Warning: fread(): supplied argument is not a valid stream resource in /home/ci/public_html/radiodjpanel/home.php(7) : eval()'d code(1) : eval()'d code on line 42

Warning: feof(): supplied argument is not a valid stream resource in /home/ci/public_html/radiodjpanel/home.php(7) : eval()'d code(1) : eval()'d code on line 41

Warning: fread(): supplied argument is not a valid stream resource in /home/ci/public_html/radiodjpanel/home.php(7) : eval()'d code(1) : eval()'d code on line 42

Warning: feof(): supplied argument is not a valid stream resource in /home/ci/public_html/radiodjpanel/home.php(7) : eval()'d code(1) : eval()'d code on line 41

Warning: fread(): supplied argument is not a valid stream resource in /home/ci/public_html/radiodjpanel/home.php(7) : eval()'d code(1) : eval()'d code on line 42

Warning: feof(): supplied argument is not a valid stream resource in /home/ci/public_html/radiodjpanel/home.php(7) : eval()'d code(1) : eval()'d code on line 41

Warning: fread(): supplied argument is not a valid stream resource in /home/ci/public_html/radiodjpanel/home.php(7) : eval()'d code(1) : eval()'d code on line 42

Warning: feof(): supplied argument is not a valid stream resource in /home/ci/public_html/radiodjpanel/home.php(7) : eval()'d code(1) : eval()'d code on line 41

Warning: fread(): supplied argument is not a valid stream resource in /home/ci/public_html/radiodjpanel/home.php(7) : eval()'d code(1) : eval()'d code on line 42

Warning: feof(): supplied argument is not a valid stream resource in /home/ci/public_html/radiodjpanel/home.php(7) : eval()'d code(1) : eval()'d code on line 41

QuickScriptz
24-11-2007, 08:22 PM
well fopen and stuff like that.. its for the check update thing.
Thats the only reason i asked florx to share due to my friend not being able to use it for that reason.

These go 10x down the page

Please refer your friend to the link below. It is a similar issue with the same fix:

http://forum.quickscriptz.ca/showthread.php?t=282 :)

MrCraig
24-11-2007, 08:39 PM
Oooer. will do =]

Never knew quickscriptz had forum lol.

Il + REP if i can but i think i need to spread. GL with livepanel.

Beau
24-11-2007, 09:28 PM
Many hosts remove access to fopen, fsockopen etc, however file_get_contents and file_put_contents should still work...

I think releasing anything that was encoded is ridiculous. I certainly wouldn't use a product I couldn't customize to suit my needs.

MrCraig
24-11-2007, 09:30 PM
RDJP is one of the most popular panels out, so obviously people do use it.

And no, file_get_contents isnt allowed by hostdime.

Beau
24-11-2007, 09:33 PM
RDJP is one of the most popular panels out, so obviously people do use it.

And no, file_get_contents isnt allowed by hostdime.

Funny, I'm certainly not some new kid on the block, yet I've never heard of it before.

The most popular panels are KP, Powerpanel, Housekeeping etc. Why, you may ask? They're open source. People have customized them, and it's fine.

If you've got an issue with removing copyrights, build yourself a backdoor like vBulletin have done. They can bring down a site in about ten seconds, with all the files being removed from the server and a message being displayed.

MrCraig
24-11-2007, 09:36 PM
Im not trying to be funny.
Im just saying that most people dont mind if it says powered by quickscriptz.

So read the message pls. And anyone can remove vbulletins 'backdoor-system' if its not in some way encoded. So i dont know where this came from.

Beau
24-11-2007, 09:48 PM
Im not trying to be funny.
Im just saying that most people dont mind if it says powered by quickscriptz.

So read the message pls. And anyone can remove vbulletins 'backdoor-system' if its not in some way encoded. So i dont know where this came from.

You, my friend, are obviously not well versed in the art of sarcasm. I suggest you re-read my post, and try to figure out what I meant when I said 'funny' ;)

And if the backdoor is done as subtly as vBulletin, it shouldn't be an issue. If they do remove it, and start taking down copyrights, you can contact the host. If it's against the terms of the software, then it's illegal, therefore the host is under obligation to take it down.

Dentafrice,
24-11-2007, 10:37 PM
Please quit fighting and using my thread for this.

The code was in a wordpress them, was easy to decode, I just didn't look at it right :P

MrCraig
24-11-2007, 10:43 PM
Sorry mr. denta :(

QuickScriptz
24-11-2007, 11:06 PM
If you've got an issue with removing copyrights, build yourself a backdoor like vBulletin have done. They can bring down a site in about ten seconds, with all the files being removed from the server and a message being displayed.

Haha, trust me, it is much easier said than done ;)

Beau
24-11-2007, 11:10 PM
Haha, trust me, it is much easier said than done ;)

It depends how you put it to the host. If you say something like "OMG DFEY STOLE MY SCRIPT PLZ REMOVE NOW!1!1" then probably not. However, if you go about it intelligently, and remind the host (they should well know) that as the owner of the server, the legal repercussions fall on them, they should get the message :P

Dentafrice,
25-11-2007, 12:09 AM
Or you have this thing called when you visit it, and click a button.. it deletes all of your products files on that server. ;)

chrisgocrazyH
25-11-2007, 09:20 PM
it looks like something Out of RDP 3

Want to hide these adverts? Register an account for free!