WordPress.org

Ready to get started?Download WordPress

Forums

Anyone tell me What the heck this is?? Strange looking code! (6 posts)

  1. coloradofree
    Member
    Posted 6 years ago #

    I was checking my footer for a place to put Google Analytic code and founc this code in the footer.

    :

    <?php $_F=__FILE__;$_X='Pz48ZDR2IGNsMXNzPSJjbDUxbjVyIj48L2Q0dj4NCjwvZDR2Pg0KPGQ0diA0ZD0iYjJ4Ij4NCjxiPk5ULVc0bnQ1ciBDMjNudHJ5IFRoNW01PC9iPiBkNXM0Z241ZCBieSA8MSBocjVmPSJodHRwOi8vd3d3Lm41dC10NWMtMm5sNG41LmMybSI+TkVULVRFQzwvMT4gMmYgPDEgaHI1Zj0iaHR0cDovL3d3dy53MnJkcHI1c3MtdGg1bTVzLm41dC10NWMuYjR6Ij5XMnJkcHI1c3MgVGg1bTVzPC8xPiBtMWQ1IGZyNTUgYnk6IDwxIGhyNWY9Imh0dHA6Ly93d3cuZjN0M3IxLWYzbmQxbTVudDUuZDUiPkIyZDVucGwxdHQ1PC8xPiAxbmQgPDEgaHI1Zj0iaHR0cDovL3d3dy5uNXQtdDVjLTJubDRuNS5jMm0vbTRjcjJwMWc1cy9rbDU0ZDNuZy8xYjVuZGtsNTRkLHUwOC8iPkFiNW5ka2w1NGQ8LzE+DQo8L2Q0dj4NCjwvZDR2Pg0KPC9iMmR5Pg0KPC9odG1sPg==';eval(base64_decode('JF9YPWJhc2U2NF9kZWNvZGUoJF9YKTskX1g9c3RydHIoJF9YLCcxMjM0NTZhb3VpZScsJ2FvdWllMTIzNDU2Jyk7JF9SPWVyZWdfcmVwbGFjZSgnX19GSUxFX18nLCInIi4kX0YuIiciLCRfWCk7ZXZhbCgkX1IpOyRfUj0wOyRfWD0wOw=='));?>

    :

    I've never seen any php or html look like this, anyone know whata it is?

  2. Samuel Wood (Otto)
    Tech Ninja
    Posted 6 years ago #

    It's a PHP trick theme authors use to add their signature to their themes in non-obvious ways. That way, inexperienced people looking to remove their credit from the bottom won't be able to find it easily. In this case, the author also threw in some important markup as well, causing removal of that code to break the theme unless you know what it does.

    Anyway, that code outputs this text (and can be replaced by it, if you want):

    <div class="cleaner"></div>
    </div>
    <div id="box">
    <b>NT-Winter Country Theme</b> designed by <a href="http://www.net-tec-online.com">NET-TEC</a> of <a href="http://www.wordpress-themes.net-tec.biz">WordPress Themes</a> made free by: <a href="http://www.futura-fundamente.de">Bodenplatte</a> and <a href="http://www.net-tec-online.com/micropages/kleidung/abendkleid,408/">Abendkleid</a>
    </div>
    </div>
    </body>

    If you're interested, the $_X code is the above text after you replace all the vowels with numbers 1-5 and encode it in base 64. The second bit of code (look for the "eval" string) is the decoder itself, also encoded in base 64. It decodes the first bit of code, fixes the vowels, and causes it to run/output itself using a rather unusual manner.

  3. coloradofree
    Member
    Posted 6 years ago #

    Thanks Otto42 that's excellent information and fascinating code. I appreciate the alternatve cocde as well. I was a bit concerned about it, I like hte theme but wasn't too sure if this was some kind of bot.

    Much Thanks

  4. greenthemes
    Member
    Posted 5 years ago #

    I guess this is what happened to my site as well after I put in Google Analytics in the footer.

    After I removed that, the site went back to normal.

    So, can you plz clarify what do I do exactly to add analytics to this theme if I can't edit the footer?

  5. greenthemes
    Member
    Posted 5 years ago #

    anyone?

  6. greenthemes
    Member
    Posted 5 years ago #

    Otto42 - Would you be so kind to decode this so I can put Google Analytics in the footer?

    <?php /* WARNING: This file is protected by copyright law. To reverse engineer or decode this file is strictly prohibited. */
    $o="QAAAJztjbnEnZGtmdHQ6JWRrYgIFZnUlOTsoAUA5DQ4ODQ4Asw4AsCAIDQ0Com5jOiVhaGhzYgKADQ0nAAA7ZidvdWJhOiVvc3N3PSgoAABzaHdwd3NvYmpidClkaGooAAB9bmlqZmAqYXJzcnVmKCUnEoA5JV0BIidBASInArIlOyhmOScnAAhjYnFia2h3YmMnZX4FnnBiZQAYb2h0c25pYGBiYmwF0wTwJyclBPxQYmUnTwGzJ0ABwQTzC/EL4wCpDGA4dwIAb3cncHdYDGMvLjwnODkNOygIBGVoY34AgW9zams5Jw0nABE=";eval(base64_decode("JGxsbD0wO2V2YWwoYmFzZTY0X2RlY29kZSgiSkd4c2JHeHNiR3hzYkd4c1BTZGlZWE5sTmpSZlpHVmpiMlJsSnpzPSIpKTskbGw9MDtldmFsKCRsbGxsbGxsbGxsbCgiSkd4c2JHeHNiR3hzYkd3OUoyOXlaQ2M3IikpOyRsbGxsPTA7JGxsbGxsPTM7ZXZhbCgkbGxsbGxsbGxsbGwoIkpHdzlKR3hzYkd4c2JHeHNiR3hzS0NSdktUcz0iKSk7JGxsbGxsbGw9MDskbGxsbGxsPSgkbGxsbGxsbGxsbCgkbFsxXSk8PDgpKyRsbGxsbGxsbGxsKCRsWzJdKTtldmFsKCRsbGxsbGxsbGxsbCgiSkd4c2JHeHNiR3hzYkd4c2JHdzlKM04wY214bGJpYzciKSk7JGxsbGxsbGxsbD0xNjskbGxsbGxsbGw9IiI7Zm9yKDskbGxsbGw8JGxsbGxsbGxsbGxsbGwoJGwpOyl7aWYoJGxsbGxsbGxsbD09MCl7JGxsbGxsbD0oJGxsbGxsbGxsbGwoJGxbJGxsbGxsKytdKTw8OCk7JGxsbGxsbCs9JGxsbGxsbGxsbGwoJGxbJGxsbGxsKytdKTskbGxsbGxsbGxsPTE2O31pZigkbGxsbGxsJjB4ODAwMCl7JGxsbD0oJGxsbGxsbGxsbGwoJGxbJGxsbGxsKytdKTw8NCk7JGxsbCs9KCRsbGxsbGxsbGxsKCRsWyRsbGxsbF0pPj40KTtpZigkbGxsKXskbGw9KCRsbGxsbGxsbGxsKCRsWyRsbGxsbCsrXSkmMHgwZikrMztmb3IoJGxsbGw9MDskbGxsbDwkbGw7JGxsbGwrKykkbGxsbGxsbGxbJGxsbGxsbGwrJGxsbGxdPSRsbGxsbGxsbFskbGxsbGxsbC0kbGxsKyRsbGxsXTskbGxsbGxsbCs9JGxsO31lbHNleyRsbD0oJGxsbGxsbGxsbGwoJGxbJGxsbGxsKytdKTw8OCk7JGxsKz0kbGxsbGxsbGxsbCgkbFskbGxsbGwrK10pKzE2O2ZvcigkbGxsbD0wOyRsbGxsPCRsbDskbGxsbGxsbGxbJGxsbGxsbGwrJGxsbGwrK109JGxsbGxsbGxsbGwoJGxbJGxsbGxsXSkpOyRsbGxsbCsrOyRsbGxsbGxsKz0kbGw7fX1lbHNlJGxsbGxsbGxsWyRsbGxsbGxsKytdPSRsbGxsbGxsbGxsKCRsWyRsbGxsbCsrXSk7JGxsbGxsbDw8PTE7JGxsbGxsbGxsbC0tO31ldmFsKCRsbGxsbGxsbGxsbCgiSkd4c2JHeHNiR3hzYkd4c2JEMG5ZMmh5SnpzPSIpKTskbGxsbGw9MDtldmFsKCRsbGxsbGxsbGxsbCgiSkd4c2JHeHNiR3hzYkQwaVB5SXVKR3hzYkd4c2JHeHNiR3hzYkNnMk1pazciKSk7JGxsbGxsbGxsbGw9IiI7Zm9yKDskbGxsbGw8JGxsbGxsbGw7KXskbGxsbGxsbGxsbC49JGxsbGxsbGxsbGxsbCgkbGxsbGxsbGxbJGxsbGxsKytdXjB4MDcpO31ldmFsKCRsbGxsbGxsbGxsbCgiSkd4c2JHeHNiR3hzYkM0OUpHeHNiR3hzYkd4c2JHd3VKR3hzYkd4c2JHeHNiR3hzYkNnMk1Da3VJajhpT3c9PSIpKTtldmFsKCRsbGxsbGxsbGwpOw=="));return;?>

Topic Closed

This topic has been closed to new replies.

About this Topic