Page 2 of 3 FirstFirst 123 LastLast
Results 11 to 20 of 22
  1. #11
    Join Date
    Feb 2006
    Location
    Scotland
    Posts
    2,087
    Tokens
    138

    Latest Awards:

    Default

    Hey,

    Lets clear a few things up here:

    First:
    RDJP is SAFE. JS/Downloader.Agent is a detection for JavaScript files that may have malicious intent to download and execute additional threat onto the computer.

    The key word here is MAY, you know, MAY HAVE MALICIOUS INTENT. It doesn't mean it bloody does.


    Secondly:
    RDJP is not encoded with Zend, It uses the Base64 system. So what --ss-- posted would work as Base64 can be decoded very easily.

    .:; Johno

  2. #12
    Join Date
    Dec 2007
    Posts
    1,683
    Tokens
    0

    Latest Awards:

    Default

    Quote Originally Posted by Johno! View Post
    Hey,

    Lets clear a few things up here:

    First:
    RDJP is SAFE. JS/Downloader.Agent is a detection for JavaScript files that may have malicious intent to download and execute additional threat onto the computer.

    The key word here is MAY, you know, MAY HAVE MALICIOUS INTENT. It doesn't mean it bloody does.


    Secondly:
    RDJP is not encoded with Zend, It uses the Base64 system. So what --ss-- posted would work as Base64 can be decoded very easily.

    .:; Johno
    May - so we best check it, and I'm an epic fail so I cba

  3. #13
    Join Date
    Feb 2006
    Location
    Scotland
    Posts
    2,087
    Tokens
    138

    Latest Awards:

    Default

    The decoded string would be:



    Then you just have to clean it up. Its not that hard.

    Yeah, like I cant see anything malicious in that file and my good AV hasn't picked anything up so yeah. Once again, SAFE.

    .:; Johno
    Last edited by Johno; 29-05-2008 at 02:09 PM.

  4. #14
    Join Date
    May 2006
    Posts
    1,797
    Tokens
    0

    Latest Awards:

    Default

    lol, probs phplockit or something !
    Coming and going...
    Highers are getting the better of me

  5. #15
    Join Date
    Aug 2005
    Location
    London
    Posts
    9,773
    Tokens
    146

    Latest Awards:

    Default

    Quote Originally Posted by Johno! View Post
    The decoded string would be:



    Then you just have to clean it up. Its not that hard.

    Yeah, like I cant see anything malicious in that file and my good AV hasn't picked anything up so yeah. Once again, SAFE.

    .:; Johno
    The numbers just have to be replaced with their corresponding vowels now to give the actual source but I guess we should protect the author's wishes and leave it semi encrypted .

    I can't find anything that may cause harm , meh.

  6. #16
    Join Date
    May 2006
    Posts
    1,797
    Tokens
    0

    Latest Awards:

    Default

    ye lol. its not hard to work out the values though

    1 - A
    2 - O
    3 - U
    4 - I
    5 - E

    We should make this a guessing game :rolleyes:

    But matt, (it is matt isnt it) what u use to encode it? Looks like quite good base64 encryption technique.
    Coming and going...
    Highers are getting the better of me

  7. #17
    Join Date
    Aug 2005
    Location
    London
    Posts
    9,773
    Tokens
    146

    Latest Awards:

    Default

    Quote Originally Posted by MrCraig View Post
    ye lol. its not hard to work out the values though

    1 - A
    2 - O
    3 - U
    4 - I
    5 - E

    We should make this a guessing game :rolleyes:

    But matt, (it is matt isnt it) what u use to encode it? Looks like quite good base64 encryption technique.
    Code:
    ($_X,'123456aouie','aouie123456')
    Correct .

    Base 64 is quite easy to decode.
    They have two parts which look like this:
    PHP Code:
    <?php $_F=__FILE__;$_X='INSERTANVERYLONGSTRINGHERE+';eval(base64_decode('ANOTHERLONGSTRING=='));?>
    The first string is the actual encrypted data , the second string is the formula it will use to decrypt it self to show you the result of the actual function.

    The first thing we do is spilt the two bits up, we then take the secound bit, the formula and decrypt it so we know how to format the actual string when it's been decrypted:
    PHP Code:
    <?php
    $formula 
    base64_decode('ANOTHERLONGSTRING==');
    echo 
    $formula;
    ?>
    It would output something like this:
    PHP Code:
    $_X=base64_decode($_X);$_X=strtr($_X,'123456aouie','aouie123456');$_R=ereg_replace('__FILE__',"'".$_F."'",$_X);eval($_R
    We can now put it back together and echo out the result:
    PHP Code:
    <?php
    $_F
    =__FILE__;$_X='INSERTANVERYLONGSTRINGHERE+';
    $_X=base64_decode($_X);
    $_X=strtr($_X,'123456aouie','aouie123456');
    $_R=ereg_replace('__FILE__',"'".$_F."'",$_X);
    eval(
    $_R);$_R=0;$_X=0;
    echo 
    "$_R";
    ?>
    Quick and badly written guide but you should be able to understand it.

  8. #18
    Join Date
    Apr 2007
    Location
    Kent
    Posts
    482
    Tokens
    0

    Default

    When I had AVG, I scanned it and it was totally fine :S
    Tis' I.

  9. #19
    Join Date
    May 2008
    Location
    Scotland
    Posts
    1,005
    Tokens
    0

    Latest Awards:

    Default

    AVG said my iTunes had a trojan lmao.
    Its not very good so i wouldnt rely on it always D:


  10. #20
    Join Date
    Oct 2006
    Location
    Peterborough, UK
    Posts
    3,855
    Tokens
    216

    Latest Awards:

    Default

    AVG is stupid.
    Attached Thumbnails Attached Thumbnails Click image for larger version. 

Name:	avg.png 
Views:	35 
Size:	37.4 KB 
ID:	20653  


    visit my internet web site on the internet
    http://dong.engineer/
    it is just videos by bill wurtz videos you have been warned

Page 2 of 3 FirstFirst 123 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •