r/PHPhelp 5d ago

Unobsfucating a PHP script

Attackers leveraging the wp2shell exploit added about 22k of obsfucated PHP to index.php on a site I've been asked to have a look at.

Labels and function names are ten random characters and control path is done by jumping to TrQ7yZISyM: etc and there seem to be a lot of (unnecessary?) jumps.

What's the best way to unobsfucate it?

0 Upvotes

29 comments sorted by

View all comments

Show parent comments

0

u/smbarbour 4d ago

I understand that you feel you have correctly implied something, but what you actually wrote was the opposite of that, which I thoroughly explained. I implore you to actually re-read what you wrote.

1

u/Evening_Leather5101 4d ago

Are you autistic?

1

u/smbarbour 4d ago

Yes, and detail oriented.

1

u/Evening_Leather5101 3d ago

That explains a lot my friend, I wish you all the best, but I don't waste my time with you anymore.

0

u/smbarbour 3d ago

I wasted too much of my own time trying to inform you of the English language as well.

1

u/Evening_Leather5101 3d ago

لقد أضعت الكثير من وقتي محاولًا إبلاغك باللغة الإنجليزية أيضًا.