Online PHP and Javascript Decoder decode hidden script to uncover its real functionality



$load_addons = 'CS_Poke';
require_once('../../../system/config_addons.php');

$selfid = isset($_POST['user_id']) ? (int)$_POST['user_id'] : 0;

$query = "
    SELECT hunter, message FROM boom_poke_messages 
    WHERE target = '$selfid' AND show_modal = 1
    ORDER BY time DESC LIMIT 1
";

$result = $mysqli->query($query);

if ($result->num_rows > 0) {
    $poke = $result->fetch_assoc();
    $message = $poke['message'];
    $senderId = $poke['hunter'];
    $senderQuery = "SELECT user_name, user_tumb FROM boom_users WHERE user_id = '$senderId'";
    $senderResult = $mysqli->query($senderQuery);
    $sender = $senderResult->fetch_assoc();

echo "
<div class='poke_modal'>
    <div class='poke_header'>
        <i class='fa-solid fa-hand-point-right poke_icon'></i>
        <img class='poke_avatar' src='" . htmlspecialchars(myavatar($sender['user_tumb']), ENT_QUOTES, 'UTF-8') . "' alt='User Avatar'>
        <h3 class='poke_header_text'>" . htmlspecialchars($sender['user_name'], ENT_QUOTES, 'UTF-8') . ' ' . $lang['poked'] . "</h3>
    </div>
    <p class='poke_message'>" . htmlspecialchars($message, ENT_QUOTES, 'UTF-8') . "</p>
    <div class='poke_actions'>
        <button id='poke_accept' class='poke_button accept_button' data-id='" . htmlspecialchars($senderId, ENT_QUOTES, 'UTF-8') . "'>" . $lang['accept'] . "</button>
        <button id='poke_close' class='poke_button close_button'>" . $lang['close'] . "</button>
    </div>
</div>";

    $mysqli->query("UPDATE boom_poke_messages SET show_modal = 0 WHERE target = '$selfid'");
}



© 2023 Quttera Ltd. All rights reserved.