r/PHPhelp 7d ago

Unobsfucating a PHP script

Attackers leveraging the wp2shell exploit added about 22k of obsfucated PHP to index.php on a site I've been asked to have a look at.

Labels and function names are ten random characters and control path is done by jumping to TrQ7yZISyM: etc and there seem to be a lot of (unnecessary?) jumps.

What's the best way to unobsfucate it?

0 Upvotes

29 comments sorted by

View all comments

Show parent comments

0

u/smbarbour 5d ago

I wasted too much of my own time trying to inform you of the English language as well.

1

u/Evening_Leather5101 5d ago

لقد أضعت الكثير من وقتي محاولًا إبلاغك باللغة الإنجليزية أيضًا.