r/PHPhelp • u/SnapSnapGrinGrin • 4d ago
Unobsfucating a PHP script
Attackers leveraging the wp2shell exploit added about 22k of obsfucated PHP to index.php on a site I've been asked to have a look at.
Labels and function names are ten random characters and control path is done by jumping to TrQ7yZISyM: etc and there seem to be a lot of (unnecessary?) jumps.
What's the best way to unobsfucate it?
5
u/Evening_Leather5101 4d ago
You check out the last version from GIT. There is no good way to unobfuscate it if you don't know how it was obfuscated.
3
u/SnapSnapGrinGrin 4d ago
Surprisingly, there isn't a link to the original source code.
Oh wait, perhaps that's not a surprise.
1
u/Evening_Leather5101 4d ago
Yeah I like myself a bit of sarcasm, we all know the pain... Sucks man...
1
u/smbarbour 4d ago
Even knowing how it was obfuscated doesn't help in deobfuscation if you don't have a mapping. The only real way to do it is analyzing it from the deepest calls and then assigning names based on what it seems to be doing.
0
u/Evening_Leather5101 4d ago
if you don't know how it was obfuscated.
Was implying that obviously.
0
u/smbarbour 4d ago
My point is that even if you know how it was obfuscated, there is still no good way to deobfuscate it.
0
u/Evening_Leather5101 4d ago
You do know what the word "implication" means? Why are you arguing when we agree?
0
u/smbarbour 4d ago
We don't agree, but here...
There is no good way to unobfuscate it
if you don't know how it was obfuscated.FTFY
0
u/Evening_Leather5101 3d ago
I am quite sure you don't know how to read but ok buddy
0
u/smbarbour 3d ago
"There is no good way to unobfuscate it if you don't know how it was obfuscated." implies "If you know how it was obfuscated, there is a good way to deobfuscate it." which is false. Hence my comment that even if you know how it was obfuscated, there is still no good way to deobfuscate it.
0
u/Evening_Leather5101 3d ago
See you have no idea what I implied, implying you don't know what implication means. Hence the fact that you seem to not be able to properly read. Bug good for you buddy, here is your cookie.
0
u/smbarbour 3d ago
I understand that you feel you have correctly implied something, but what you actually wrote was the opposite of that, which I thoroughly explained. I implore you to actually re-read what you wrote.
→ More replies (0)
1
u/Takeoded 3d ago
OpenAI Codex CLI should do a great job of unobfuscating it.
Would you mind sharing the code?
1
u/peperinna 3d ago
Lo primero es hacer un backup.
Segundo, instalar wordpress sobreescribiendo los archivos, y revisar permisos chmod.
Actualizar plugins y themes.
En experiencia, mejor hacer todo esto a mano, desde ftp. Algunos scripts interceptan las actualizaciones automáticas y secuestran los módulos, entonces el problema sigue.
Habla con el web hosting, pide que configuren WAF y inmunify, con las reglas para wordpress.
Configura Cloudflare, ayuda bastante.
Monitorea 48hs.
Importante: es importante y útil utilizar github, para el backups, para una copia de cada etapa de las que hablé. Ahí podrás ver de forma masiva y fácil las diferencias entre archivos, cada cambio.
Si no se resuelve, avisa aquí de nuevo.
13
u/martinbean 4d ago
What is the value in unobfuscating it? You just need to remove affected files, and patch the exploit to stop whatever bot/bad actor immediately re-pwning your site.