aa471355795 发表于 2022-7-23 21:02

求助 php 这是什么加密方式

求助 php这是什么加密方式

if(!defined("WeEtzwQ"))define("WeEtzwQ","ZsbCABv");$GLOBALS=explode("|E|e|%", "H*|E|e|%4961715342464A");if(!defined("mKDyLLv"))define("mKDyLLv","CaFRmiv");$GLOBALS=explode("|G|P|_", "H*|G|P|_2E2F436F6D6D6F6E2F436F72655F627261696E2E706870|G|P|_3C21444F43545950452068746D6C3E0D|G|P|_0A3C68746D6C206C616E673D22656E223E0D|G|P|_0A3C686561643E0D|G|P|_0A3C6D65746120636861727365743D227574662D38223E0D|G|P|_0A3C6D65746120636F6E74656E743D22|G|P|_446573637269707469736F6E|G|P|_22206E616D653D226465736372697074696F6E223E0D|G|P|_0A3C6D65746120636F6E74656E743D2277696474683D6465766963652D77696474682C20696E697469616C2D7363616C653D312E3022206E616D653D2276696577706F7274223E0D|G|P|_0A3C7469746C653E|G|P|_4E616D65|G|P|_202D20|G|P|_536974654E616D65|G|P|_3C2F7469746C653E0D|G|P|_4B6579776F726473|G|P|_22206E616D653D226B6579776F726473223E0D|G|P|_0A3C212D2D2046617669636F6E73202D2D3E0D|G|P|_0A3C6C696E6B20687265663D226173736574732F696D672F66617669636F6E2E706E67222072656C3D2269636F6E223E0D|G|P|_0A3C6C696E6B20687265663D226173736574732F696D672F6170706C652D746F7563682D69636F6E2E706E67222072656C3D226170706C652D746F7563682D69636F6E223E0D|G|P|_0A3C212D2D20476F6F676C6520466F6E7473202D2D3E0D|G|P|_0A3C6C696E6B20687265663D2268747470733A2F2F666F6E74732E676F6F676C65617069732E636F6D2F6373733F66616D696C793D4F70656E2B53616E733A3330302C333030692C3430302C343030692C3630302C363030692C3730302C373030697C526F626F746F3A3330302C333030692C3430302C343030692C3530302C353030692C3730302C373030697C506F7070696E733A3330302C333030692C3430302C343030692C3530302C353030692C3630302C363030692C3730302C37303069222072656C3D227374796C657368656574223E0D|G|P|_0A3C212D2D2056656E646F72204353532046696C6573202D2D3E0D|G|P|_0A3C6C696E6B20687265663D226173736574732F76656E646F722F626F6F7473747261702F6373732F626F6F7473747261702E6D696E2E637373222072656C3D227374796C657368656574223E0D|G|P|_0A3C6C696E6B20687265663D226173736574732F76656E646F722F69636F666F6E742F69636F666F6E742E6D696E2E637373222072656C3D227374796C657368656574223E0D|G|P|_0A3C6C696E6B20687265663D226173736574732F76656E646F722F626F7869636F6E732F6373732F626F7869636F6E732E6D696E2E637373222072656C3D227374796C657368656574223E0D|G|P|_0A3C6C696E6B20687265663D222F2F61742E616C6963646E2E636F6D2F742F666F6E745F313838363539305F76367A786A676863776C692E637373222072656C3D227374796C657368656574223E0D|G|P|_0A3C6C696E6B20687265663D226173736574732F76656E646F722F616E696D6174652E6373732F616E696D6174652E6D696E2E637373222072656C3D227374796C657368656574223E0D|G|P|_0A3C6C696E6B20687265663D226173736574732F76656E646F722F6F776C2E6361726F7573656C2F6173736574732F6F776C2E6361726F7573656C2E6D696E2E637373222072656C3D227374796C657368656574223E0D|G|P|_0A3C6C696E6B20687265663D226173736574732F76656E646F722F76656E6F626F782F76656E6F626F782E637373222072656C3D227374796C657368656574223E0D|G|P|_0A3C212D2D2054656D706C617465204D61696E204353532046696C65202D2D3E0D|G|P|_0A3C6C696E6B20687265663D226173736574732F6373732F7374796C652E637373222072656C3D227374796C657368656574223E0D|G|P|_0A3C2F686561643E0D|G|P|_0A3C626F64793E0D|G|P|_0A3C212D2D203D3D3D3D3D3D3D204865726F2053656374696F6E203D3D3D3D3D3D3D202D2D3E3C73656374696F6E2069643D226865726F223E0D|G|P|_0A3C64697620636C6173733D226865726F2D636F6E7461696E6572223E0D|G|P|_0A20203C6469762069643D226865726F4361726F7573656C2220636C6173733D226361726F7573656C20736C696465206361726F7573656C2D666164652220646174612D726964653D226361726F7573656C223E0D|G|P|_0A202020203C6F6C20636C6173733D226361726F7573656C2D696E64696361746F7273222069643D226865726F2D6361726F7573656C2D696E64696361746F7273223E0D|G|P|_0A202020203C2F6F6C3E0D|G|P|_0A202020203C64697620636C6173733D226361726F7573656C2D696E6E65722220726F6C653D226C697374626F78223E0D|G|P|_0A2020202020203C212D2D20536C6964652031202D2D3E0D|G|P|_0A2020202020203C64697620636C6173733D226361726F7573656C2D6974656D20616374697665223E0D|G|P|_0A20202020202020203C64697620636C6173733D226361726F7573656C2D6261636B67726F756E64223E0D|G|P|_0A202020202020202020203C696D67207372633D226173736574732F696D616765732F626A312E6A70672220616C743D2231223E0D|G|P|_0A20202020202020203C2F6469763E0D|G|P|_0A20202020202020203C64697620636C6173733D226361726F7573656C2D636F6E7461696E6572223E0D|G|P|_0A202020202020202020203C64697620636C6173733D226361726F7573656C2D636F6E74656E74223E0D|G|P|_0A2020202020202020202020203C683220636C6173733D22616E696D6174655F5F616E696D6174656420616E696D6174655F5F66616465496E446F776E223E3C7370616E3E|G|P|_2020202020202020202020203C2F7370616E3E3C2F68323E0D|G|P|_0A2020202020202020202020203C7020636C6173733D22616E696D6174655F5F616E696D6174656420616E696D6174655F5F66616465496E5570223E0D|G|P|_0A090909E8B685E7BAA7E78EA9E5AEB6E4B8ADE5BF83E5908EE58FB00D|G|P|_0A2020202020202020202020203C2F703E0D|G|P|_0A2020202020202020202020203C6120687265663D222F757365722220636C6173733D2262746E2D6765742D7374617274656420616E696D6174655F5F616E696D6174656420616E696D6174655F5F66616465496E5570207363726F6C6C746F223EE7AB8BE588BBE4BD93E9AA8C3C2F613E0D|G|P|_0A202020202020202020203C2F6469763E0D|G|P|_0A2020202020203C2F6469763E0D|G|P|_0A093C2F6469763E0D|G|P|_0A20203C2F6469763E0D|G|P|_0A3C2F6469763E");if(!defined(pack($GLOBALS,$GLOBALS)))define(pack($GLOBALS,$GLOBALS), ord(37));unset($F31cV1);$F31bN8N="__file__"==5;if($F31bN8N)goto F31eWjgx4;$F31bN8L=1+1;$F31bN8M=E_STRICT==$F31bN8L;if($F31bN8M)goto F31eWjgx4;if(is_array($GLOBALS))goto F31eWjgx4;goto F31ldMhx4;F31eWjgx4:$F31cV1=&$GLOBALS;goto F31x3;F31ldMhx4:$F31cV1=$GLOBALS;F31x3:unset($F31cV2);if(is_array($GLOBALS))goto F31eWjgx2;$F31bN8J=E_ERROR-1;unset($F31tIbN8K);$F31tIbN8K=$F31bN8J;$A3zIODK=$F31tIbN8K;if($F31tIbN8K)goto F31eWjgx2;$F31eFbN4=call_user_func_array("strpos",array("oY","CxL"));if($F31eFbN4)goto F31eWjgx2;goto F31ldMhx2;F31eWjgx2:$F31cV2=&$GLOBALS;goto F31x1;F31ldMhx2:$F31cV2=$GLOBALS;F31x1:$F31eF0=call_user_func_array("pack",array(&$F31cV1,&$F31cV2));$F318I=include $F31eF0;unset($F31cV1);$F31bN8N=1+1;$F31bN8O=1>$F31bN8N;if($F31bN8O)goto F31eWjgx8;unset($F31tIvPbN8L);$F31tIvPbN8L="RqVwK";$A3zIODK=$F31tIvPbN8L;$F31eFbN5=call_user_func_array("strlen",array(&$F31tIvPbN8L));$F31bN8M=!$F31eFbN5;if($F31bN8M)goto F31eWjgx8;if(is_array($GLOBALS))goto F31eWjgx8;goto F31ldMhx8;F31eWjgx8:$F31cV1=&$GLOBALS;goto F31x7;F31ldMhx8:$F31cV1=$GLOBALS;F31x7:unset($F31cV2);if(is_array($GLOBALS))goto F31eWjgx6;$F31bN8K=$_GET=="PbjpCM";if($F31bN8K)goto F31eWjgx6;$F31bN8I=E_ERROR-1;unset($F31tIbN8J);$F31tIbN8J=$F31bN8I;$A3zIODK=$F31tIbN8J;if($F31tIbN8J)goto F31eWjgx6;goto F31ldMhx6;F31eWjgx6:$F31cV2=&$GLOBALS;goto F31x5;F31ldMhx6:$F31cV2=$GLOBALS;F31x5:$F31eF0=call_user_func_array("pack",array(&$F31cV1,&$F31cV2));echo $F31eF0;unset($F31cV1);if(is_array($GLOBALS))goto F31eWjgxc;$F31zAvPbN6=array();$F31zAvPbN6[]=1;$F31eFbN7=call_user_func_array("key",array(&$F31zAvPbN6));if($F31eFbN7)goto F31eWjgxc;$F31bN8M=1-1;$F31bN8N=$F31bN8M/2;

完整代码地址微云:https://share.weiyun.com/AbT5Ul5Z

爱飞的猫 发表于 2022-7-23 22:11

本帖最后由 爱飞的猫 于 2022-7-23 22:17 编辑

这是混淆 + goto 打乱顺序,只能手动修复,自动处理的脚本写起来麻烦。

解密的字符串:


```text
1: ./Common/Core_brain.php
2: <!DOCTYPE html>
3:
<html lang="en">
4:
<head>
5:
<meta charset="utf-8">
6:
<meta content="
7: Descriptison
8: " name="description">
9:
<meta content="width=device-width, initial-scale=1.0" name="viewport">
10:
<title>
11: Name
12:-
13: SiteName
14: </title>
15: Keywords
16: " name="keywords">
17:
<!-- Favicons -->
18:
<link href="assets/img/favicon.png" rel="icon">
19:
<link href="assets/img/apple-touch-icon.png" rel="apple-touch-icon">
20:
<!-- Google Fonts -->
21:
<link href="https://fonts.googleapis.com/css?family=Open+Sans:300,300i,400,400i,600,600i,700,700i|Roboto:300,300i,400,400i,500,500i,700,700i|Poppins:300,300i,400,400i,500,500i,600,600i,700,700i" rel="stylesheet">
22:
<!-- Vendor CSS Files -->
23:
<link href="assets/vendor/bootstrap/css/bootstrap.min.css" rel="stylesheet">
24:
<link href="assets/vendor/icofont/icofont.min.css" rel="stylesheet">
25:
<link href="assets/vendor/boxicons/css/boxicons.min.css" rel="stylesheet">
26:
<link href="//at.alicdn.com/t/font_1886590_v6zxjghcwli.css" rel="stylesheet">
27:
<link href="assets/vendor/animate.css/animate.min.css" rel="stylesheet">
28:
<link href="assets/vendor/owl.carousel/assets/owl.carousel.min.css" rel="stylesheet">
29:
<link href="assets/vendor/venobox/venobox.css" rel="stylesheet">
30:
<!-- Template Main CSS File -->
31:
<link href="assets/css/style.css" rel="stylesheet">
32:
</head>
33:
<body>
34:
<!-- ======= Hero Section ======= --><section id="hero">
35:
<div class="hero-container">
36:
<div id="heroCarousel" class="carousel slide carousel-fade" data-ride="carousel">
37:
    <ol class="carousel-indicators" id="hero-carousel-indicators">
38:
    </ol>
39:
    <div class="carousel-inner" role="listbox">
40:
      <!-- Slide 1 -->
41:
      <div class="carousel-item active">
42:
      <div class="carousel-background">
43:
          <img src="assets/images/bj1.jpg" alt="1">
44:
      </div>
45:
      <div class="carousel-container">
46:
          <div class="carousel-content">
47:
            <h2 class="animate__animated animate__fadeInDown"><span>
48:             </span></h2>
49:
            <p class="animate__animated animate__fadeInUp">
50:
                        超级玩家中心后台
51:
            </p>
52:
            <a href="/user" class="btn-get-started animate__animated animate__fadeInUp scrollto">立刻体验</a>
53:
          </div>
54:
      </div>
55:
      </div>
56:
</div>
57:
</div>
```

应该是批量插入花指令 + 字符串简单加密,然后用 https://github.com/pk-fr/yakpro-po 把执行顺序用 goto 打乱。

BuWenGuiQi0513 发表于 2022-7-23 21:14

goto吧!!!!

FirstExecution 发表于 2022-7-23 21:15

aa471355795 发表于 2022-7-23 21:24

BuWenGuiQi0513 发表于 2022-7-23 21:14
goto吧!!!!

感觉不全是,怪怪的

aa471355795 发表于 2022-7-23 21:29

FirstExecution 发表于 2022-7-23 21:15
是不是webpack打包的

这我就不清楚啦,买得文件。 整个包都是加密的,被坑了。 连个老鼠屎那么大的明文文件都没留

qqdns 发表于 2022-7-24 09:50

学习了,还有没有php最好加密方式是哪一种

aa471355795 发表于 2022-7-24 11:52

爱飞的猫 发表于 2022-7-23 22:11
这是混淆 + goto 打乱顺序,只能手动修复,自动处理的脚本写起来麻烦。

解密的字符串:


弱弱的问下,有修复的解密思路嘛? 全部文件都是加密的。要靠自己慢慢一个一个解。几十上百个文件。

caihong325 发表于 2022-7-24 14:13

一人没看懂,这是什么?可以下载吗

爱飞的猫 发表于 2022-7-26 01:53

aa471355795 发表于 2022-7-24 11:52
弱弱的问下,有修复的解密思路嘛? 全部文件都是加密的。要靠自己慢慢一个一个解。几十上百个文件。

我只会手动慢慢解,这玩意太折腾了。
页: [1] 2
查看完整版本: 求助 php 这是什么加密方式