Online PHP and Javascript Decoder decode hidden script to uncover its real functionality


Show other level


include 'inc/config.php';
include 'inc/connect.php';
session_start();


if (isset($_POST['loginUsername'])) {
  
  $chars = "0";
  $user = $_POST['loginUsername'];
  $pass = $_POST['loginPassword'];


  if((strpos($user, "'") !== false) OR (strpos($user, '"') !== false) OR (strpos($user, '*') !== false) OR (strpos($user, '/') !== false)){
    $chars = "1";
  }

  if((strpos($pass, "'") !== false) OR (strpos($pass, '"') !== false) OR (strpos($pass, '*') !== false) OR (strpos($pass, '/') !== false)){
    $chars = "1";
  }

  if($chars == "0"){
      if(($user == $admin_panel_username) AND ($pass == $admin_panel_password)){
        $_SESSION['loggedin'] = true;
        $_SESSION['username'] = $user;
        $_SESSION['role'] = 'Admin';
        header('Location: index.php');
        exit;
      }else{
        $sql= "SELECT * FROM handlers WHERE username = '$user' AND password = '$pass'";
        $result = mysqli_query($conn,$sql);
        if(mysqli_num_rows($result)!=0){
          $_SESSION['loggedin'] = 'true';
          $_SESSION['username'] = $user;
          $_SESSION['role'] = 'Handler';
          header('Location: index.php');
          exit;
        }else{
          $err = "<b style='color:red;'>Incorrect username or password.</b><br><br>";
        }
      }
  }else{
    $err = "<b style='color:red;'>Incorrect username or password.</b><br><br>";
  }

}

<!DOCTYPE html>
<html>
  <head>
    <meta charset="utf-8">
    <meta http-equiv="X-UA-Compatible" content="IE=edge">
    <title>PRO SCAM - Login</title>
    <meta name="description" content="">
    <meta name="viewport" content="width=device-width, initial-scale=1">
    <meta name="robots" content="all,follow">
    
    <link rel="stylesheet" href="vendor/bootstrap/css/bootstrap.min.css">
    
    <link rel="stylesheet" href="vendor/font-awesome/css/font-awesome.min.css">
    
    <link rel="stylesheet" href="css/font.css">
    
    <link rel="stylesheet" href="https://fonts.googleapis.com/css?family=Muli:300,400,700">
    
    <link rel="stylesheet" href="css/style.red.css" id="theme-stylesheet">
    
    <link rel="stylesheet" href="css/custom.css">
    
    <link rel="shortcut icon" href="img/favicon.ico">
  </head>
  <body>
    <div class="login-page">
      <div class="container d-flex align-items-center">
        <div class="form-holder has-shadow">
          <div class="row">
            
            <div class="col-lg-6">
              <div class="info d-flex align-items-center">
                <div class="content">
                  <div class="logo">
                    <h1>PRO SCAM</h1>
                  </div>
                  <p>Login now to start the fun.</p>
                </div>
              </div>
            </div>
            
            <div class="col-lg-6">
              <div class="form d-flex align-items-center">
                <div class="content">
                  echo $err;
                  <form method="POST" class="form-validate mb-4">
                    <div class="form-group">
                      <input id="loginUsername" type="text" name="loginUsername" required data-msg="Please enter your username" class="input-material">
                      <label for="login-username" class="label-material">Username</label>
                    </div>
                    <div class="form-group">
                      <input id="loginPassword" type="password" name="loginPassword" required data-msg="Please enter your password" class="input-material">
                      <label for="login-password" class="label-material">Password</label>
                    </div>
                    <button type="submit" class="btn btn-primary">Login</button>
                  </form>
                </div>
              </div>
            </div>
          </div>
        </div>
      </div>
      <div class="copyrights text-center">
             
      </div>
    </div>
    
    <script src="vendor/jquery/jquery.min.js"></script>
    <script src="vendor/popper.js/umd/popper.min.js"> </script>
    <script src="vendor/bootstrap/js/bootstrap.min.js"></script>
    <script src="vendor/jquery.cookie/jquery.cookie.js"> </script>
    <script src="vendor/chart.js/Chart.min.js"></script>
    <script src="vendor/jquery-validation/jquery.validate.min.js"></script>
    <script src="js/front.js"></script>
  </body>
</html>


include 'inc/config.php';
include 'inc/connect.php';
session_start();


if (isset($_POST['loginUsername'])) {
  
  
  $user = $_POST['loginUsername'];
  $pass = $_POST['loginPassword'];


  if((strpos($user, "'") !== false) OR (strpos($user, '"') !== false) OR (strpos($user, '*') !== false) OR (strpos($user, '/') !== false)){
    "0" = "1";
  }

  if((strpos($pass, "'") !== false) OR (strpos($pass, '"') !== false) OR (strpos($pass, '*') !== false) OR (strpos($pass, '/') !== false)){
    "0" = "1";
  }

  if("0" == "0"){
      if(($user == $admin_panel_username) AND ($pass == $admin_panel_password)){
        $_SESSION['loggedin'] = true;
        $_SESSION['username'] = $user;
        $_SESSION['role'] = 'Admin';
        header('Location: index.php');
        exit;
      }else{
        $sql= "SELECT * FROM handlers WHERE username = '$user' AND password = '$pass'";
        $result = mysqli_query($conn,$sql);
        if(mysqli_num_rows($result)!=0){
          $_SESSION['loggedin'] = 'true';
          $_SESSION['username'] = $user;
          $_SESSION['role'] = 'Handler';
          header('Location: index.php');
          exit;
        }else{
          $err = "<b style='color:red;'>Incorrect username or password.</b><br><br>";
        }
      }
  }else{
    $err = "<b style='color:red;'>Incorrect username or password.</b><br><br>";
  }

}

<!DOCTYPE html>
<html>
  <head>
    <meta charset="utf-8">
    <meta http-equiv="X-UA-Compatible" content="IE=edge">
    <title>PRO SCAM - Login</title>
    <meta name="description" content="">
    <meta name="viewport" content="width=device-width, initial-scale=1">
    <meta name="robots" content="all,follow">
    
    <link rel="stylesheet" href="vendor/bootstrap/css/bootstrap.min.css">
    
    <link rel="stylesheet" href="vendor/font-awesome/css/font-awesome.min.css">
    
    <link rel="stylesheet" href="css/font.css">
    
    <link rel="stylesheet" href="https://fonts.googleapis.com/css?family=Muli:300,400,700">
    
    <link rel="stylesheet" href="css/style.red.css" id="theme-stylesheet">
    
    <link rel="stylesheet" href="css/custom.css">
    
    <link rel="shortcut icon" href="img/favicon.ico">
  </head>
  <body>
    <div class="login-page">
      <div class="container d-flex align-items-center">
        <div class="form-holder has-shadow">
          <div class="row">
            
            <div class="col-lg-6">
              <div class="info d-flex align-items-center">
                <div class="content">
                  <div class="logo">
                    <h1>PRO SCAM</h1>
                  </div>
                  <p>Login now to start the fun.</p>
                </div>
              </div>
            </div>
            
            <div class="col-lg-6">
              <div class="form d-flex align-items-center">
                <div class="content">
                  echo $err;
                  <form method="POST" class="form-validate mb-4">
                    <div class="form-group">
                      <input id="loginUsername" type="text" name="loginUsername" required data-msg="Please enter your username" class="input-material">
                      <label for="login-username" class="label-material">Username</label>
                    </div>
                    <div class="form-group">
                      <input id="loginPassword" type="password" name="loginPassword" required data-msg="Please enter your password" class="input-material">
                      <label for="login-password" class="label-material">Password</label>
                    </div>
                    <button type="submit" class="btn btn-primary">Login</button>
                  </form>
                </div>
              </div>
            </div>
          </div>
        </div>
      </div>
      <div class="copyrights text-center">
             
      </div>
    </div>
    
    <script src="vendor/jquery/jquery.min.js"></script>
    <script src="vendor/popper.js/umd/popper.min.js"> </script>
    <script src="vendor/bootstrap/js/bootstrap.min.js"></script>
    <script src="vendor/jquery.cookie/jquery.cookie.js"> </script>
    <script src="vendor/chart.js/Chart.min.js"></script>
    <script src="vendor/jquery-validation/jquery.validate.min.js"></script>
    <script src="js/front.js"></script>
  </body>
</html>



© 2023 Quttera Ltd. All rights reserved.