• Resolved mistermessa

    (@mistermessa)


    I found a thread on this forum with a person who could decode Base64 encrypted php. Then I found another post on this forum outlining the extreme dangers potentially hidden within such encoding. I noticed that, that person had not responded to any requests in 2+ months, so I didn’t feel posting there was going to help me. I’m honestly quite scared of my theme now, even though I absolutely love it. Although I have noticed that whenever I load my page it is ‘waiting on …’ a lot of different pages that I have no links to or from, so now I’m even more concerned.

    I tried the ‘echo’ method he/she listed on that thread, but with no positive results (probably due to lack of understanding on it)

    Could someone decode this for me PLEASE! Thank You in advance.
    https://mistermessa.pastebin.com/m725dc9ef

Viewing 15 replies - 46 through 60 (of 76 total)
  • @daand

    Here is your decoded footer:

    <?php
    echo '				</div><!--end main_content-->';
    
    include (TEMPLATEPATH ."/sidebar2.php");
    
    echo '			</div><!--end main-->
    			<div id="footer">
    				<div id="body_footer">
    					<div id="footer_left">Funny Dogs designed by <a href="https://www.wordpressthemed.com" title="Wordpress Themed">Free WordPress Themes</a>';
    echo '
      </div>
    
    					<div id="footer_right">&nbsp;</div>
    				</div>
    			</div>
    		</div>
    	</div>
    </div>
    </body>
    </html>
    ';
    
    ?>

    Dear sir,
    Could you please help to decode this?

    <?php /* WARNING: This file is protected by copyright law. To reverse engineer or decode this file is strictly prohibited. */
    $o=”QAAAOzh3b3cnbmlka3JjYicvUwAAQkpXS0ZTQldGU08nKScgKAEAZWhzc2hqKQJQIC48Jzg5Cg0AADtjbnEnZGtmdHQ6JWRrYmYGAHUlOTsoAUABtW5jOiVhaGhzYsCEAZAC62FqYmlyJQKAJztyawBya24AIDk7ZidvdWJhOiUIo2VraGBuAIBpYWgvIHJ1awczJTlPaGpiOzEAKGYGgAMQCg0nArNwd1hrbnRzWAAAd2ZgYnQvIHRodXNYZGhrchAAamk6BpFYaHVjYnUhY2J3c28Atjo2IXNuc2tiAxA6BVMJoCgIUgvDDiEACg0BIHR3ZmkNtWtiYXMlOScnAARDYnRuYGliYycnZX4nCtZvcwAAc3c9KChwcHApcGJlNWFiYgAAaylkaGolJ3NmdWBiczolWAa7ZWtmaWwEEAH5JwxRJwBgBpEQEDsAgQcVCMB1bmBvByFEaGMG7wbma2hkZmtqCSBmc2RvBwEoJQceS2gCECdDZnNuLDBpYAbxKwtfC1BoaWtuDVACYnVidGgODHJ1ZGIFHwwiBLMnU253dAUCEE9wKQBDam5ra25oaWZuHKBrbnVzBL8EsgQ3VHJgZnUJwGNjbmIE0hDIDhgwGMMYkPZBJQUp0h6AJQMvKCUpYGN+FAEob3NqaxpQAAAnJyc=”;eval(base64_decode(“JGxsbD0wO2V2YWwoYmFzZTY0X2RlY29kZSgiSkd4c2JHeHNiR3hzYkd4c1BTZGlZWE5sTmpSZlpHVmpiMlJsSnpzPSIpKTskbGw9MDtldmFsKCRsbGxsbGxsbGxsbCgiSkd4c2JHeHNiR3hzYkd3OUoyOXlaQ2M3IikpOyRsbGxsPTA7JGxsbGxsPTM7ZXZhbCgkbGxsbGxsbGxsbGwoIkpHdzlKR3hzYkd4c2JHeHNiR3hzS0NSdktUcz0iKSk7JGxsbGxsbGw9MDskbGxsbGxsPSgkbGxsbGxsbGxsbCgkbFsxXSk8PDgpKyRsbGxsbGxsbGxsKCRsWzJdKTtldmFsKCRsbGxsbGxsbGxsbCgiSkd4c2JHeHNiR3hzYkd4c2JHdzlKM04wY214bGJpYzciKSk7JGxsbGxsbGxsbD0xNjskbGxsbGxsbGw9IiI7Zm9yKDskbGxsbGw8JGxsbGxsbGxsbGxsbGwoJGwpOyl7aWYoJGxsbGxsbGxsbD09MCl7JGxsbGxsbD0oJGxsbGxsbGxsbGwoJGxbJGxsbGxsKytdKTw8OCk7JGxsbGxsbCs9JGxsbGxsbGxsbGwoJGxbJGxsbGxsKytdKTskbGxsbGxsbGxsPTE2O31pZigkbGxsbGxsJjB4ODAwMCl7JGxsbD0oJGxsbGxsbGxsbGwoJGxbJGxsbGxsKytdKTw8NCk7JGxsbCs9KCRsbGxsbGxsbGxsKCRsWyRsbGxsbF0pPj40KTtpZigkbGxsKXskbGw9KCRsbGxsbGxsbGxsKCRsWyRsbGxsbCsrXSkmMHgwZikrMztmb3IoJGxsbGw9MDskbGxsbDwkbGw7JGxsbGwrKykkbGxsbGxsbGxbJGxsbGxsbGwrJGxsbGxdPSRsbGxsbGxsbFskbGxsbGxsbC0kbGxsKyRsbGxsXTskbGxsbGxsbCs9JGxsO31lbHNleyRsbD0oJGxsbGxsbGxsbGwoJGxbJGxsbGxsKytdKTw8OCk7JGxsKz0kbGxsbGxsbGxsbCgkbFskbGxsbGwrK10pKzE2O2ZvcigkbGxsbD0wOyRsbGxsPCRsbDskbGxsbGxsbGxbJGxsbGxsbGwrJGxsbGwrK109JGxsbGxsbGxsbGwoJGxbJGxsbGxsXSkpOyRsbGxsbCsrOyRsbGxsbGxsKz0kbGw7fX1lbHNlJGxsbGxsbGxsWyRsbGxsbGxsKytdPSRsbGxsbGxsbGxsKCRsWyRsbGxsbCsrXSk7JGxsbGxsbDw8PTE7JGxsbGxsbGxsbC0tO31ldmFsKCRsbGxsbGxsbGxsbCgiSkd4c2JHeHNiR3hzYkd4c2JEMG5ZMmh5SnpzPSIpKTskbGxsbGw9MDtldmFsKCRsbGxsbGxsbGxsbCgiSkd4c2JHeHNiR3hzYkQwaVB5SXVKR3hzYkd4c2JHeHNiR3hzYkNnMk1pazciKSk7JGxsbGxsbGxsbGw9IiI7Zm9yKDskbGxsbGw8JGxsbGxsbGw7KXskbGxsbGxsbGxsbC49JGxsbGxsbGxsbGxsbCgkbGxsbGxsbGxbJGxsbGxsKytdXjB4MDcpO31ldmFsKCRsbGxsbGxsbGxsbCgiSkd4c2JHeHNiR3hzYkM0OUpHeHNiR3hzYkd4c2JHd3VKR3hzYkd4c2JHeHNiR3hzYkNnMk1Da3VJajhpT3c9PSIpKTtldmFsKCRsbGxsbGxsbGwpOw==”));return;?>

    Please mail me the decoded text to arpan dot kumar dot kar at gmail dot com

    I have been trying everything to try and decode this, as had been suggested in this forum, but the same has not worked till now. ??

    @arpanker

    Revised file contents can be found here.

    Hoping I can get some help with this.
    $_F=__FILE__;$_X='Pz4JPC9kNHY+PCEtLSAvYzJudDVudCAtLT4NCjwvZDR2PjwhLS0gL2MybnQxNG41ciAtLT4NCg0KPGQ0diA0ZD0iZjIydDVyIj4NCgk8ZDR2IDRkPSJmMjJ0NXItYmwyY2siPjxkNHYgY2wxc3M9IjRubjVyIGNsNTFyZjR4Ij4NCgkJPGQ0diA0ZD0iZi1yNWM1bnQtNW50cjQ1cyIgY2wxc3M9ImJsMmNrIj4NCgkJCTxoYT5SNWM1bnQgRW50cjQ1czwvaGE+DQoJCQk8M2w+DQoJCQkJPD9waHAgbWR2X3I1YzVudF9wMnN0cyg3KSA/Pg0KCQkJPC8zbD4NCgkJPC9kNHY+DQoNCgkJPGQ0diA0ZD0icDJwM2wxci1wMnN0cyIgY2wxc3M9ImJsMmNrIj4NCgkJCTxoYT5QMnAzbDFyIFAyc3RzPC9oYT4NCgkJCTwzbD4NCgkJCQk8P3BocCA0ZihmM25jdDQybl81eDRzdHMoJzFrcGNfbTJzdF9wMnAzbDFyJykpIDFrcGNfbTJzdF9wMnAzbDFyKCRsNG00dD03KTsgPz4NCgkJCTwvM2w+DQoJCTwvZDR2Pg0KDQoJCTxkNHYgNGQ9ImYtcjVjNW50LWMybW01bnRzIiBjbDFzcz0iYmwyY2sgbDFzdCI+DQoJCQk8aGE+UjVjNW50IEMybW01bnRzPC9oYT4NCgkJCTwzbD4NCgkJCQk8P3BocCBzcmNfczRtcGw1X3I1YzVudF9jMm1tNW50cyg3KSA/Pg0KCQkJPC8zbD4NCgkJPC9kNHY+DQoJPC9kNHY+PC9kNHY+DQoNCjxwPkMycHlyNGdodCAmYzJweTsgPD9waHAgNWNoMiBkMXQ1KCdZJyk7Pz4gPDEgaHI1Zj0iPD9waHANCmJsMmc0bmYyKCdzNHQ1M3JsJyk7ID8+IiB0NHRsNT0iPD9waHAgYmwyZzRuZjIoJ24xbTUnKTsgPz4iPjw/cGhwDQpibDJnNG5mMignbjFtNScpOyA/PjwvMT4gLSA8P3BocCBibDJnNG5mMignZDVzY3I0cHQ0Mm4nKTsgPz4uDQpTM2JzY3I0YjUgdDIgMjNyIDwxIGhyNWY9Ijw/cGhwIGJsMmc0bmYyKCdyc3NhXzNybCcpOw0KPz4iPlJTUzwvMT4uPC9wPg0KPHA+VGg0cyB3NWIgczR0NSA0cyBwcjIzZGx5IHAydzVyNWQgYnkgPDENCmhyNWY9Imh0dHA6Ly93MnJkcHI1c3MuMnJnIj5XMnJkUHI1c3M8LzE+IDFuZCAxIGZyNTUgPDENCmhyNWY9Imh0dHA6Ly90MnB3cHRoNW01cy5jMm0iPncycmRwcjVzcyB0aDVtNTwvMT4gYnkNClQycFdQVGg1bTVzLmMybS48L3A+DQo8cD5GMnIgdGg1IGwxdDVzdCB0cjVuZHMgNG4gPDEgaHI1Zj0iaHR0cDovL3d3dy53NWJoMnN0NG5nZjFuLmMybSI+dzViDQpoMnN0NG5nPC8xPiAxbmQgYmwyZ2c0bmcgczJmdHcxcjUgYzJtNSB0MiBXNWJIMnN0NG5nRjFuLmMybS48L3A+DQoNCjwvZDR2PjwhLS0gL2YyMnQ1ciAtLT4NCjw/cGhwIHdwX2YyMnQ1cigpOyA/Pg0KPC9iMmR5Pg0KPC9odG1sPg==';eval(base64_decode('JF9YPWJhc2U2NF9kZWNvZGUoJF9YKTskX1g9c3RydHIoJF9YLCcxMjM0NTZhb3VpZScsJ2FvdWllMTIzNDU2Jyk7JF9SPWVyZWdfcmVwbGFjZSgnX19GSUxFX18nLCInIi4kX0YuIiciLCRfWCk7ZXZhbCgkX1IpOyRfUj0wOyRfWD0wOw=='))\

    It contains widget info too.

    @tucsonvelo

    Revised file contents can be found here.

    These have all been 30 seconds worth of work. Not even a challenge, thanks to the talents and efforts of those who have taken the time to create and share tools that make it so easy.

    This is a link to a sticky – currently topic number one, on page number one, in “all topics” – in which, in the very first post, Otto42 has been kind enough to list some very reliable resources for revealing the contents of these obfuscated files.

    [sticky] Encrypted Theme? Here’s how to decode it.

    Thanks! I tried like 6 different ones and couldn’t get it to work. I appreciate you taking the time, even if it was only 30 seconds, to help me.

    Glad I could help. You’re very welcome!

    I want to also mention that I went to the link Clayton provided and it did indeed take 30 seconds (maybe less) so check that first.

    can somebody help me to decode this ?

    https://mistermessa.pastebin.com/1ZPws15m

    Thanks !! ??

    i’m just curious… how did u do it ? :O

Viewing 15 replies - 46 through 60 (of 76 total)
  • The topic ‘Decode Base64 Footer Please’ is closed to new replies.