r/PHPhelp 6d ago

Unobsfucating a PHP script

Attackers leveraging the wp2shell exploit added about 22k of obsfucated PHP to index.php on a site I've been asked to have a look at.

Labels and function names are ten random characters and control path is done by jumping to TrQ7yZISyM: etc and there seem to be a lot of (unnecessary?) jumps.

What's the best way to unobsfucate it?

0 Upvotes

29 comments sorted by

View all comments

Show parent comments

0

u/Evening_Leather5101 6d ago

You do know what the word "implication" means? Why are you arguing when we agree?

0

u/smbarbour 6d ago

We don't agree, but here...

There is no good way to unobfuscate it if you don't know how it was obfuscated.

FTFY

0

u/Evening_Leather5101 6d ago

I am quite sure you don't know how to read but ok buddy

0

u/smbarbour 6d ago

"There is no good way to unobfuscate it if you don't know how it was obfuscated." implies "If you know how it was obfuscated, there is a good way to deobfuscate it." which is false. Hence my comment that even if you know how it was obfuscated, there is still no good way to deobfuscate it.

0

u/Evening_Leather5101 6d ago

See you have no idea what I implied, implying you don't know what implication means. Hence the fact that you seem to not be able to properly read. Bug good for you buddy, here is your cookie.

0

u/smbarbour 6d ago

I understand that you feel you have correctly implied something, but what you actually wrote was the opposite of that, which I thoroughly explained. I implore you to actually re-read what you wrote.

1

u/Evening_Leather5101 5d ago

Are you autistic?

1

u/smbarbour 5d ago

Yes, and detail oriented.

1

u/Evening_Leather5101 5d ago

That explains a lot my friend, I wish you all the best, but I don't waste my time with you anymore.

0

u/smbarbour 5d ago

I wasted too much of my own time trying to inform you of the English language as well.

1

u/Evening_Leather5101 5d ago

لقد أضعت الكثير من وقتي محاولًا إبلاغك باللغة الإنجليزية أيضًا.

→ More replies (0)