Code
eval ( base64_decode ( 'JF9YPWJhc2U2NF9kZWNvZGUoJF9YKTskX1g9c3RydHIoJF9YLCcxMjM0NTZhb3VpZScsJ2FvdWllMTIzNDU2Jyk7JF9SPWVyZWdfcmVwbGFjZSgnX19GSUxFX18nLCInIi4kX0YuIiciLCRfWCk7ZXZhbCgkX1IpOyRfUj0wOyRfWD0wOw==' ) );
ถอดออกมาได้
Code
$_X = base64_decode ( $_X );
$_X = strtr ( $_X, '123456aouie', 'aouie123456' );
$_R = ereg_replace ( '__FILE__', "'" . $_F . "'", $_X );
eval ( $_R );
$_R = 0;
$_X = 0;
####################################
Code
$_X = 'Pz48Pw0KLy8gIDRmIChkMXQ1KCJtL2QvWSBIOjQ6cyIsZjRsNW10NG01KCI0bmQ1eC5waHAiKSkgPiBkMXQ1KCIwNi82aS9hMDA5IDAwOmk5Om9pIikpIHsNCi8vICAgNWNoMiBkMXQ1KCJtL2QvWSBIOjQ6cyIsZjRsNW10NG01KCI0bmQ1eC5waHAiKSk7DQogLy8gIDV4NHQ7DQovLyAgIH0NCiA0ZiAoZDF0NSgiWS9tL2QiLGY0bDVtdDRtNSgiNG5kNXgucGhwIikpID4gZDF0NSgiYTAwOC8wNi9vNiIpKSB7DQogICAvLzVjaDIgZDF0NSgiWS9tL2QiLGY0bDVtdDRtNSgiNG5kNXgucGhwIikpOw0KICAgNWNoMiAiIjsNCiAgIDV4NHQ7DQogIH0NCiAgIA0KIDRmIChkMXQ1KCJZL20vZCIpID4gZDF0NSgiYTAwOC8wNi9vNiIpKSB7DQogIDVjaDIgIiI7DQogIDV4NHQ7DQogIH0NCiAgIA0KICAgIDRmIChkMXQ1KCJZIikgPCBkMXQ1KCJhMDA3IikpIHsNCiAgNWNoMiAiIjsNCiAgNXg0dDsNCiAgIH0NCg0KMmJfc3QxcnQoKTsNClM1c3M0Mm5fc3QxcnQoKTsNCj8+DQo8IURPQ1RZUEUgaHRtbCBQVUJMSUMgIi0vL1dvQy8vRFREIFhIVE1MIDYuMCBUcjFuczR0NDJuMWwvL0VOIiAiaHR0cDovL3d3dy53by4ycmcvVFIveGh0bWw2L0RURC94aHRtbDYtdHIxbnM0dDQybjFsLmR0ZCI+DQo8aHRtbCB4bWxucz0iaHR0cDovL3d3dy53by4ycmcvNjk5OS94aHRtbCI+DQoNCjxtNXQxIGh0dHAtNXEzNHY9IkMybnQ1bnQtVHlwNSIgYzJudDVudD0idDV4dC9odG1sOyBjaDFyczV0PXc0bmQyd3MtODd1IiAvPg0KPHQ0dGw1PlVudDR0bDVkIEQyYzNtNW50PC90NHRsNT4NCg0KDQo8YjJkeT4NCiA8Pw0KJGMxcnRbaV1bYTBdOw0KUzVzczQybl9yNWc0c3Q1cihjMXJ0KTsNCg0KDQokcF80ZCA9ICRfUE9TVFsicF80ZCJdOw0KJHBfbjFtNT0gJF9QT1NUWyJwX24xbTUiXTsNCiRwX3ByNGM1ID0gJF9QT1NUWyJwX3ByNGM1Il07DQokcF9jMnN0ID0gJF9QT1NUWyJwX2Myc3QiXTsNCiRwX24zbWI1cl80bjJyZDVyID0gJF9QT1NUWyJwX24zbWI1cl80bjJyZDVyIl07DQoNCg0KDQoNCiAgNGYgKHBfNGQgIT0gIiIpew0KICAkZjIzbmQ0dCA9IGYxbHM1OyAgDQogIGYycigkND0wOyQ0PGEwOyQ0KyspIHsNCiAgNGYgKCRjMXJ0WzBdWyQ0XSA9PSAkcF80ZCApew0KICAkYzFydFtvXVskNF0gPSAkYzFydFtvXVskNF0gKzY7DQogICRmMjNuZDR0ID0gdHIzNTsNCiAgYnI1MWs7DQogIH0NCiAgDQogIH0NCg0KNGYgKCEkZjIzbmQ0dCkgew0KIGYycigkND0wOyQ0PGEwOyQ0KyspIHsNCiAgNGYgKCRjMXJ0WzBdWyQ0XSA9PSAiIiApew0KICAgJGMxcnRbMF1bJDRdID0gJHBfNGQ7DQogICRjMXJ0WzZdWyQ0XSA9ICRwX24xbTU7DQogICAkYzFydFthXVskNF0gPSAkcF9wcjRjNTsNCiAkYzFydFtvXVskNF0gPTY7DQogICRjMXJ0W3VdWyQ0XSA9JHBfYzJzdDsNCiAgYnI1MWs7DQogIH0NCiAgfQ0KICB9DQogIH0NCg0KIA0KNGYgKCRfUE9TVFsiM3BkMXQ1cSJdICE9ICIiKXsNCg0KZjJyKCQ0PTA7JDQ8YTA7JDQrKykgew0KDQokbjV3cSA9ICRfUE9TVFsicHEiIC4gJGMxcnRbMF1bJDRdXSAgOw0KJGQ1bDV0NXByMmQzY3QgPSAkX1BPU1RbInBkNWw1dDUiIC4gJGMxcnRbMF1bJDRdXSAgOw0KDQoNCjRmICgkZDVsNXQ1cHIyZDNjdCA9PSAiZDVsNXQ1Iil7DQokYzFydFswXVskNF0gPSAiIjsNCn0NCg0KNGYgKCgkbjV3cSA9PSAiIiApIHx8ICgkbjV3cSA9PSAiMCIpIHx8ICggJGQ1bDV0NXByMmQzY3QgIT0gIiIgKSl7DQokYzFydFswXVskNF0gPSAiIjsNCn0gNWxzNSB7DQokYzFydFtvXVskNF0gPSAkbjV3cTsNCn0NCn0NCn0NCg0KaDUxZDVyKCJMMmMxdDQybjogc2gyd19jMXJ0LnBocCIpOw0KDQoNCg0KLy80ZiAoJGQ1bDV0NXByMmQzY3QgIT0gIjYiICl7DQovLyRjMXJ0W29dWyQ0XSA9ICRuNXdxOw0KLy99DQovLyB9DQovL30NCg0KDQovL2YycigkND0wOyQ0PGEwOyQ0KyspIHsgLy9mMnI2DQoNCiAvLzVjaDIgJF9QT1NUWyJwcSIuICRjMXJ0WzBdWyQ0XV07DQoNCi8vfQ0KDQo/Pg0KDQo8L2IyZHk+DQo8L2h0bWw+DQo=';
แปลงร่างแล้วได้แบบนี้
Code
?><?
// 4f (d1t5("m/d/Y H:4:s",f4l5mt4m5("4nd5x.php")) > d1t5("06/6i/a009 00:i9:oi")) {
// 5ch2 d1t5("m/d/Y H:4:s",f4l5mt4m5("4nd5x.php"));
// 5x4t;
// }
4f (d1t5("Y/m/d",f4l5mt4m5("4nd5x.php")) > d1t5("a008/06/o6")) {
//5ch2 d1t5("Y/m/d",f4l5mt4m5("4nd5x.php"));
5ch2 "";
5x4t;
}
4f (d1t5("Y/m/d") > d1t5("a008/06/o6")) {
5ch2 "";
5x4t;
}
4f (d1t5("Y") < d1t5("a007")) {
5ch2 "";
5x4t;
}
2b_st1rt();
S5ss42n_st1rt();
?>
<!DOCTYPE html PUBLIC "-//WoC//DTD XHTML 6.0 Tr1ns4t42n1l//EN" "http://www.wo.2rg/TR/xhtml6/DTD/xhtml6-tr1ns4t42n1l.dtd">
<html xmlns="http://www.wo.2rg/6999/xhtml">
<m5t1 http-5q34v="C2nt5nt-Typ5" c2nt5nt="t5xt/html; ch1rs5t=w4nd2ws-87u" />
<t4tl5>Unt4tl5d D2c3m5nt</t4tl5>
<b2dy>
<?
$c1rt[i][a0];
S5ss42n_r5g4st5r(c1rt);
$p_4d = $_POST["p_4d"];
$p_n1m5= $_POST["p_n1m5"];
$p_pr4c5 = $_POST["p_pr4c5"];
$p_c2st = $_POST["p_c2st"];
$p_n3mb5r_4n2rd5r = $_POST["p_n3mb5r_4n2rd5r"];
4f (p_4d != ""){
$f23nd4t = f1ls5;
f2r($4=0;$4<a0;$4++) {
4f ($c1rt[0][$4] == $p_4d ){
$c1rt[o][$4] = $c1rt[o][$4] +6;
$f23nd4t = tr35;
br51k;
}
}
4f (!$f23nd4t) {
f2r($4=0;$4<a0;$4++) {
4f ($c1rt[0][$4] == "" ){
$c1rt[0][$4] = $p_4d;
$c1rt[6][$4] = $p_n1m5;
$c1rt[a][$4] = $p_pr4c5;
$c1rt[o][$4] =6;
$c1rt[u][$4] =$p_c2st;
br51k;
}
}
}
}
4f ($_POST["3pd1t5q"] != ""){
f2r($4=0;$4<a0;$4++) {
$n5wq = $_POST["pq" . $c1rt[0][$4]] ;
$d5l5t5pr2d3ct = $_POST["pd5l5t5" . $c1rt[0][$4]] ;
4f ($d5l5t5pr2d3ct == "d5l5t5"){
$c1rt[0][$4] = "";
}
4f (($n5wq == "" ) || ($n5wq == "0") || ( $d5l5t5pr2d3ct != "" )){
$c1rt[0][$4] = "";
} 5ls5 {
$c1rt[o][$4] = $n5wq;
}
}
}
h51d5r("L2c1t42n: sh2w_c1rt.php");
//4f ($d5l5t5pr2d3ct != "6" ){
//$c1rt[o][$4] = $n5wq;
//}
// }
//}
//f2r($4=0;$4<a0;$4++) { //f2r6
//5ch2 $_POST["pq". $c1rt[0][$4]];
//}
?>
</b2dy>
</html>
###############################################
นำค่า $_X มาแปลงร่างอีกครั้ง โดยการ
Code
$_X = strtr ( $_X, '123456aouie', 'aouie123456' );
จะออกมาเป็นแบบนี้
Code
<?
// if (date("m/d/Y H:i:s",filemtime("index.php")) > date("01/15/2009 00:59:35")) {
// echo date("m/d/Y H:i:s",filemtime("index.php"));
// exit;
// }
if (date("Y/m/d",filemtime("index.php")) > date("2008/01/31")) {
//echo date("Y/m/d",filemtime("index.php"));
echo "";
exit;
}
if (date("Y/m/d") > date("2008/01/31")) {
echo "";
exit;
}
if (date("Y") < date("2007")) {
echo "";
exit;
}
ob_start();
Session_start();
?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<meta http-equiv="Content-Type" content="text/html; charset=windows-874" />
<title>Untitled Document</title>
<body>
<?
$cart[5][20];
Session_register(cart);
$p_id = $_POST["p_id"];
$p_name= $_POST["p_name"];
$p_price = $_POST["p_price"];
$p_cost = $_POST["p_cost"];
$p_number_inorder = $_POST["p_number_inorder"];
if (p_id != ""){
$foundit = false;
for($i=0;$i<20;$i++) {
if ($cart[0][$i] == $p_id ){
$cart[3][$i] = $cart[3][$i] +1;
$foundit = true;
break;
}
}
if (!$foundit) {
for($i=0;$i<20;$i++) {
if ($cart[0][$i] == "" ){
$cart[0][$i] = $p_id;
$cart[1][$i] = $p_name;
$cart[2][$i] = $p_price;
$cart[3][$i] =1;
$cart[4][$i] =$p_cost;
break;
}
}
}
}
if ($_POST["updateq"] != ""){
for($i=0;$i<20;$i++) {
$newq = $_POST["pq" . $cart[0][$i]] ;
$deleteproduct = $_POST["pdelete" . $cart[0][$i]] ;
if ($deleteproduct == "delete"){
$cart[0][$i] = "";
}
if (($newq == "" ) || ($newq == "0") || ( $deleteproduct != "" )){
$cart[0][$i] = "";
} else {
$cart[3][$i] = $newq;
}
}
}
header("Location: show_cart.php");
//if ($deleteproduct != "1" ){
//$cart[3][$i] = $newq;
//}
// }
//}
//for($i=0;$i<20;$i++) { //for1
//echo $_POST["pq". $cart[0][$i]];
//}
?>
</body>
</html>
###############################################
การแปลงร่างขั้นสุดยอด ครั้งสุดท้าย คือ
Code
$_R = ereg_replace ( '__FILE__', "'" . $_F . "'", $_X );
ออกมาเป็นแบบนี้
Code
?><?
// if (date("m/d/Y H:i:s",filemtime("index.php")) > date("01/15/2009 00:59:35")) {
// echo date("m/d/Y H:i:s",filemtime("index.php"));
// exit;
// }
if (date("Y/m/d",filemtime("index.php")) > date("2008/01/31")) {
//echo date("Y/m/d",filemtime("index.php"));
echo "";
exit;
}
if (date("Y/m/d") > date("2008/01/31")) {
echo "";
exit;
}
if (date("Y") < date("2007")) {
echo "";
exit;
}
ob_start();
Session_start();
?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<meta http-equiv="Content-Type" content="text/html; charset=windows-874" />
<title>Untitled Document</title>
<body>
<?
$cart[5][20];
Session_register(cart);
$p_id = $_POST["p_id"];
$p_name= $_POST["p_name"];
$p_price = $_POST["p_price"];
$p_cost = $_POST["p_cost"];
$p_number_inorder = $_POST["p_number_inorder"];
if (p_id != ""){
$foundit = false;
for($i=0;$i<20;$i++) {
if ($cart[0][$i] == $p_id ){
$cart[3][$i] = $cart[3][$i] +1;
$foundit = true;
break;
}
}
if (!$foundit) {
for($i=0;$i<20;$i++) {
if ($cart[0][$i] == "" ){
$cart[0][$i] = $p_id;
$cart[1][$i] = $p_name;
$cart[2][$i] = $p_price;
$cart[3][$i] =1;
$cart[4][$i] =$p_cost;
break;
}
}
}
}
if ($_POST["updateq"] != ""){
for($i=0;$i<20;$i++) {
$newq = $_POST["pq" . $cart[0][$i]] ;
$deleteproduct = $_POST["pdelete" . $cart[0][$i]] ;
if ($deleteproduct == "delete"){
$cart[0][$i] = "";
}
if (($newq == "" ) || ($newq == "0") || ( $deleteproduct != "" )){
$cart[0][$i] = "";
} else {
$cart[3][$i] = $newq;
}
}
}
header("Location: show_cart.php");
//if ($deleteproduct != "1" ){
//$cart[3][$i] = $newq;
//}
// }
//}
//for($i=0;$i<20;$i++) { //for1
//echo $_POST["pq". $cart[0][$i]];
//}
?>
</body>
</html>