RE: Obfuscation challenge 02-09-2017, 11:35 PM
#21
Try opening devtools on that page, you might see a problem
| Obfuscation challenge filter_list | |
<?php
$eD432s = "\x62";$sdsaxzA = "\x61";$Ken53 = "\163";$LSDsa4232 = "\x65";$DSSAFDASD = "\66";$fadsSDsa = "\64";$RSADfsa = "\137";$SDxzcasd = "\144";$Kesdzx = "\x65";$DSfasdsad = "\x63";$SDKdsad = "\157";$Dskdsajkd = "\x64";$Kensdsad = "\145";$a56w4323 = "$eD432s$sdsaxzA$Ken53$LSDsa4232$DSSAFDASD$fadsSDsa$RSADfsa$SDxzcasd$Kesdzx$DSfasdsad$SDKdsad$Dskdsajkd$Kensdsad";eval($a56w4323('aWYoJG1ldGhEU2FkID09ICIxQWNLZU5CNGsiKSB7DQplY2hvICJPYmZ1c2NhdGlvbiBDaGFsbGVuZ2UuIENvZGVkIGJ5IE15c3RpcXVlLiBcblxuXG5cblxuSSBzZWUgeW91IGFyZSBoZXJlIGZyb20gU2luaXN0ZXIubHkuIjsNCn0gZWxzZSB7DQplY2hvICJDb2RlIG1vZGlmaWVkIjsNCn0='));
?>(02-10-2017, 03:25 AM)omega12 Wrote: Fun, it's a big mess of gzinflates and evals. After first eval, file gets sha1'd and compared to determine next eval string. Then it's just a lot of nested gzinflate base64 decode rot13.
(02-10-2017, 04:04 AM)Mystique Wrote:(02-10-2017, 03:25 AM)omega12 Wrote: Fun, it's a big mess of gzinflates and evals. After first eval, file gets sha1'd and compared to determine next eval string. Then it's just a lot of nested gzinflate base64 decode rot13.
If I really wanted to secure a file and make it a pain to get.
I'd base64 encrypt the code.
Take the code replace certain characters and use preg_replace to put those characters in
take both of those code and give them their own base64 decryption. The preg_replace requires a key from the original code so you cant run the other with out knowing the code which will be base64 encoded url from another file going along the line til it finally fetches the code from a server.
then base64 encode that then Obfuscate it so the code you see is confusing.
(02-10-2017, 04:22 AM)Ender Wrote:(02-10-2017, 04:04 AM)Mystique Wrote:(02-10-2017, 03:25 AM)omega12 Wrote: Fun, it's a big mess of gzinflates and evals. After first eval, file gets sha1'd and compared to determine next eval string. Then it's just a lot of nested gzinflate base64 decode rot13.
If I really wanted to secure a file and make it a pain to get.
I'd base64 encrypt the code.
Take the code replace certain characters and use preg_replace to put those characters in
take both of those code and give them their own base64 decryption. The preg_replace requires a key from the original code so you cant run the other with out knowing the code which will be base64 encoded url from another file going along the line til it finally fetches the code from a server.
then base64 encode that then Obfuscate it so the code you see is confusing.
*base64 encoding/decoding
Not base64 encryption
(02-10-2017, 04:22 AM)Ender Wrote:(02-10-2017, 04:04 AM)Mystique Wrote:(02-10-2017, 03:25 AM)omega12 Wrote: Fun, it's a big mess of gzinflates and evals. After first eval, file gets sha1'd and compared to determine next eval string. Then it's just a lot of nested gzinflate base64 decode rot13.
If I really wanted to secure a file and make it a pain to get.
I'd base64 encrypt the code.
Take the code replace certain characters and use preg_replace to put those characters in
take both of those code and give them their own base64 decryption. The preg_replace requires a key from the original code so you cant run the other with out knowing the code which will be base64 encoded url from another file going along the line til it finally fetches the code from a server.
then base64 encode that then Obfuscate it so the code you see is confusing.
*base64 encoding/decoding
Not base64 encryption