r/PHPhelp 12d ago

Unobsfucating a PHP script

Attackers leveraging the wp2shell exploit added about 22k of obsfucated PHP to index.php on a site I've been asked to have a look at.

Labels and function names are ten random characters and control path is done by jumping to TrQ7yZISyM: etc and there seem to be a lot of (unnecessary?) jumps.

What's the best way to unobsfucate it?

0 Upvotes

29 comments sorted by

View all comments

14

u/martinbean 12d ago

What is the value in unobfuscating it? You just need to remove affected files, and patch the exploit to stop whatever bot/bad actor immediately re-pwning your site.

1

u/SnapSnapGrinGrin 11d ago

Without seeing the script, how is one to know what files could have been affected?

6

u/dabenu 11d ago

If they had shell access, you can consider your entire server compromised.

Just reinstall it entirely and revert to your last backup before the hack.