首先将后门源代码加密,获得加密后的代码。ide
$encode = <<<EOF if(!file_exists(dirname(dirname(dirname(__FILE__))).'/blog.51cto.com.chinaleo')){ header('Location:https://blog.51cto.com/chinaleo'); exit(); } EOF; echo base64_encode( gzdeflate( $encode ) );
获得字符串“48xM01BMy8xJjU+tyCwuKdZIySzKS8xNxaDj4908fVzj4zU1NfXU9ZMzMvMSc1Lz9ZJy8tP1TA2TS/L1kvNz1TU1q3m5FKAgIzUxJbVIQ90nPzmxJDM/zyqjpKTASl8fVQ/cLHVNa4ReoGtKNCACnLUA”,这就是密文网站
eval( gzinflate( base64_decode( '48xM01BMy8xJjU+tyCwuKdZIySzKS8xNxaDj4908fVzj4zU1NfXU9ZMzMvMSc1Lz9ZJy8tP1TA2TS/L1kvNz1TU1q3m5FKAgIzUxJbVIQ90nPzmxJDM/zyqjpKTASl8fVQ/cLHVNa4ReoGtKNCACnLUA' ) ) );