{"id":1255,"date":"2012-02-27T15:02:06","date_gmt":"2012-02-27T13:02:06","guid":{"rendered":"http:\/\/netspider.com.ua\/?p=1255"},"modified":"2012-02-27T19:41:37","modified_gmt":"2012-02-27T17:41:37","slug":"skrytie-koda-metod-8","status":"publish","type":"post","link":"https:\/\/netspider.com.ua\/index.php\/2012\/02\/27\/skrytie-koda-metod-8\/","title":{"rendered":"\u0421\u043a\u0440\u044b\u0442\u0438\u0435 \u043a\u043e\u0434\u0430, \u043c\u0435\u0442\u043e\u0434 8"},"content":{"rendered":"<pre class=\"brush: php; auto-links: true; collapse: false; first-line: 1; gutter: true; html-script: false; light: false; ruler: false; smart-tabs: true; tab-size: 4; toolbar: true;\">&lt;?php # Web Shell by oRb\n$auth_pass = &quot;63a9f0ea7bb98050796b649e85481845&quot;;\n$color = &quot;#df5&quot;;\n$default_action = 'FilesMan';\n$default_use_ajax = true;\n$default_charset = 'Windows-1251';\npreg_replace(&quot;\/.*\/e&quot;,&quot;\\x65\\x76\\x61\\x6C\\x28\\x67\\x7A\\x69\\x6E\\x66\n\\x6C\\x61\\x74\\x65\\x28\\x62\\x61\\x73\\x65\\x36\\x34\\x5F\\x64\\x65\\x63\\x6F\n\\x64\\x65\\x28'5b1pdx...Kn6fwE='\\x29\\x29\\x29\\x3B&quot;,&quot;.&quot;);?&gt;<\/pre>\n\n<p>\u0427\u0435\u0440\u0442\u043e\u0432\u0441\u043a\u0438 \u0433\u0435\u043d\u0438\u0430\u043b\u044c\u043d\u043e!) preg_replace <em>\u043d\u0438\u0447\u0435\u0433\u043e \u043d\u0435 \u0437\u0430\u043c\u0435\u043d\u044f\u0435\u0442<\/em>, \u0430 \u043f\u0440\u043e\u0441\u0442\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u0442 \u0440\u043e\u043b\u044c eval(), \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u044f \u0432\u0435\u0441\u044c \u043a\u043e\u0434 \u0438\u0437 \u0432\u0442\u043e\u0440\u043e\u0433\u043e \u0430\u0440\u0433\u0443\u043c\u0435\u043d\u0442\u0430!<\/p>\n\n<blockquote>\n  <p><\/p>\n  <dt><i><tt>pattern<\/tt><\/i>\n\n    <p><\/p>\n  <\/dt><dd>\n    <p>\u0418\u0441\u043a\u043e\u043c\u044b\u0439 \u0448\u0430\u0431\u043b\u043e\u043d. \u041c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u043a\u0430\u043a \u0441\u0442\u0440\u043e\u043a\u043e\u0439, \u0442\u0430\u043a \u0438 \u043c\u0430\u0441\u0441\u0438\u0432\u043e\u043c \u0441\u0442\u0440\u043e\u043a.<\/p>\n\n    <p>\u0422\u0430\u043a\u0436\u0435 \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u044b \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 <a href=\"https:\/\/www.php.net\/manual\/ru\/reference.pcre.pattern.modifiers.php\">\u043c\u043e\u0434\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0440\u044b PCRE<\/a>, \u0432\u043a\u043b\u044e\u0447\u0430\u044f &#8216;<i><strong>e<\/strong><\/i>&#8216; (<strong>PREG_REPLACE_EVAL<\/strong>), \u0441\u043f\u0435\u0446\u0438\u0444\u0438\u0447\u043d\u044b\u0439 \u0442\u043e\u043b\u044c\u043a\u043e \u0434\u043b\u044f \u044d\u0442\u043e\u0439 \u0444\u0443\u043d\u043a\u0446\u0438\u0438.<\/p>\n  <\/dd><\/blockquote>\n\n<p>\u0420\u0430\u0441\u043a\u043e\u0434\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0441\u0438\u043c\u0432\u043e\u043b\u044b \u0432\u0438\u0434\u0430 \u201c\\x65\u201d \u043c\u043e\u0436\u043d\u043e \u0434\u0432\u0443\u043c\u044f \u0441\u043f\u043e\u0441\u043e\u0431\u0430\u043c\u0438:<\/p><!--more--><pre class=\"brush: php; auto-links: true; collapse: false; first-line: 1; gutter: true; html-script: false; light: false; ruler: false; smart-tabs: true; tab-size: 4; toolbar: true;\">$string1 = '';\n$string2 = '';\n\n$hex1 = '6576616C28677A696E';\n$hex2 = &quot;\\x65\\x76\\x61\\x6C\\x28\\x67\\x7A\\x69\\x6E&quot;;\n\nfor ($i=0; $i &amp;lt; strlen($hex1)-1; $i+=2){\n    $string1 .= chr(hexdec($hex1[$i].$hex1[$i+1]));\n}\necho $string1;\necho &quot;\\n\\n&quot;;\n\n$string2 = utf8_decode( $hex2 );\necho $string2;\necho &quot;\\n\\n&quot;;<\/pre>\n\n<p>\u0412 \u044d\u0442\u043e\u043c \u043a\u043e\u0434\u0435 \u0437\u0430\u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u044b \u0441\u0442\u0430\u0440\u044b\u0435 \u0434\u043e\u0431\u0440\u044b\u0435:<\/p>\n\n<pre class=\"brush: php; auto-links: true; collapse: false; first-line: 1; gutter: true; html-script: false; light: false; ruler: false; smart-tabs: true; tab-size: 4; toolbar: true;\">eval(gzinflate(base64_decode()));<\/pre>\n\n<p>\u0427\u0442\u043e\u0431\u044b \u0440\u0430\u0441\u043a\u043e\u0434\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0444\u0430\u0439\u043b, \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u0432\u044b\u0440\u0435\u0437\u0430\u0442\u044c \u0441\u0442\u0440\u043e\u043a\u0443 \u043c\u0435\u0436\u0434\u0443 \u043e\u0434\u0438\u043d\u0430\u0440\u043d\u044b\u043c\u0438 \u043a\u0430\u0432\u044b\u0447\u043a\u0430\u043c\u0438 \u0438 \u0432\u0441\u0442\u0430\u0432\u0438\u0442\u044c \u0432 \u043a\u043e\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044e:<\/p>\n\n<pre class=\"brush: php; auto-links: true; collapse: false; first-line: 1; gutter: true; html-script: false; light: false; ruler: false; smart-tabs: true; tab-size: 4; toolbar: true;\">$text0 = &quot;5b1pdxrHEjD82fe...&quot;;\n$text = gzinflate( base64_decode( $text0 ) );\n$fp = fopen('deobfuscated.txt', 'w');\nfwrite($fp, $text);\nfclose($fp);<\/pre>","protected":false},"excerpt":{"rendered":"&lt;?php # Web Shell by oRb $auth_pass = &quot;63a9f0ea7bb98050796b649e85481845&quot;; $color = &quot;#df5&quot;; $default_action = &#8216;FilesMan&#8217;; $default_use_ajax = true; $default_charset = &#8216;Windows-1251&#8217;; preg_replace(&quot;\/.*\/e&quot;,&quot;\\x65\\x76\\x61\\x6C\\x28\\x67\\x7A\\x69\\x6E\\x66 \\x6C\\x61\\x74\\x65\\x28\\x62\\x61\\x73\\x65\\x36\\x34\\x5F\\x64\\x65\\x63\\x6F \\x64\\x65\\x28&#8217;5b1pdx&#8230;Kn6fwE=&#8217;\\x29\\x29\\x29\\x3B&quot;,&quot;.&quot;);?&gt; \u0427\u0435\u0440\u0442\u043e\u0432\u0441\u043a\u0438 \u0433\u0435\u043d\u0438\u0430\u043b\u044c\u043d\u043e!) preg_replace \u043d\u0438\u0447\u0435\u0433\u043e \u043d\u0435 \u0437\u0430\u043c\u0435\u043d\u044f\u0435\u0442, \u0430 \u043f\u0440\u043e\u0441\u0442\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u0442 \u0440\u043e\u043b\u044c eval(), \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u044f \u0432\u0435\u0441\u044c \u043a\u043e\u0434 \u0438\u0437 \u0432\u0442\u043e\u0440\u043e\u0433\u043e \u0430\u0440\u0433\u0443\u043c\u0435\u043d\u0442\u0430! pattern \u0418\u0441\u043a\u043e\u043c\u044b\u0439 \u0448\u0430\u0431\u043b\u043e\u043d. \u041c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u043a\u0430\u043a \u0441\u0442\u0440\u043e\u043a\u043e\u0439, \u0442\u0430\u043a \u0438 \u043c\u0430\u0441\u0441\u0438\u0432\u043e\u043c \u0441\u0442\u0440\u043e\u043a. \u0422\u0430\u043a\u0436\u0435 \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u044b \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435\u2026 <span class=\"read-more\"><a href=\"https:\/\/netspider.com.ua\/index.php\/2012\/02\/27\/skrytie-koda-metod-8\/\">\u0427\u0438\u0442\u0430\u0442\u044c \u0434\u0430\u043b\u0435\u0435 &raquo;<\/a><\/span>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1575,1557,665,1568,674,1558,662,1559],"class_list":["post-1255","post","type-post","status-publish","format-standard","hentry","category-main","tag-deobfuscation","tag-obfuscation","tag-php","tag-deobfuskaciya","tag-kod","tag-obfuskaciya","tag-skriptyi","tag-shifrovanie"],"_links":{"self":[{"href":"https:\/\/netspider.com.ua\/index.php\/wp-json\/wp\/v2\/posts\/1255","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/netspider.com.ua\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/netspider.com.ua\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/netspider.com.ua\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/netspider.com.ua\/index.php\/wp-json\/wp\/v2\/comments?post=1255"}],"version-history":[{"count":0,"href":"https:\/\/netspider.com.ua\/index.php\/wp-json\/wp\/v2\/posts\/1255\/revisions"}],"wp:attachment":[{"href":"https:\/\/netspider.com.ua\/index.php\/wp-json\/wp\/v2\/media?parent=1255"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/netspider.com.ua\/index.php\/wp-json\/wp\/v2\/categories?post=1255"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/netspider.com.ua\/index.php\/wp-json\/wp\/v2\/tags?post=1255"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}