note 32840 deleted from function.eval by didou
| From: | didou@php.net | Date: | Sun, 27 Jul 2003 17:02:57 +0000 |
| Subject: | note 32840 deleted from function.eval by didou | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-52768@lists.php.net to get a copy of this message | ||
Note Submitter: dolomite@planetquake.com
----
I was having a hard time with eval. I'm not sure if the following code is bugfree or not, but I
think it's working for me.
I wanted to find a way to hide my sourcecode and tuck it into the database. The best way to do it is
by base64 encoding it and gzdeflating it. But for some reason the code kept giving me the bad
character error (as in it was choking on a slash).
So I use the following and it seems to work.
funtion obfuscate(&$me){
// speedy free php obfuscation source function
$CHUNK_SIZE = 40;
$me = '?' . '>'.$me.'<' . '?' .'php ';
$me = chunk_split(base64_encode(gzdeflate(stripslashes(&$me))), &$CHUNK_SIZE);
$this = chr(60) . chr(63) . 'php $source = \'' . chr(10) . $me .
chr(10).'\'; ' . chr(10) . 'eval(gzinflate(base64_decode(&$source)));'
. chr(63) . chr(62);
// no need to return $me because it was passed by ref (the & in the function line)
}
$me is mixed PHP file contents. Ie: it's both HTML and PHP.
This string $me is brought into the above function and it's converted to a block of executable
code that can be pasted into a PHP file all by itself.
I'm fairly sure this works to convert any php script into something that can be stored in a db,
too.
The following script will convert any PHP code into something that can be executed, but obfuscated.
Matter of fact, the following code was obfuscated by itself! :)
<?php $source = '
XVNha9swEP08g//DYUpkl8xx0jZbFyeBZaUrg22Q
7csoGMW+xKK2ZCS5XTb233ey0zbtF1vSe3fv6e60
XKTLpmx8T0iRGbQhQ62VzjQ2Slshd2wIk+TsMpod
UTTuhLGos12lNrwybJi8wHlVqYes1VW2VQ3K13Ah
TFPxfdYpUTCMX8D3XAu+qdBkSheoCWdX199Xa+ZY
Bo0RSmY5z0vMKlEL8hGyRot7bnEIdWvsW433vBIF
HXQxo1PfW6tW5whqCx9bURUwgfBB6Tu6IEheE1Bv
2sJEvud74xh+8DsEqYDnlsTAltyCMNBKiTkZ4Hrv
e5MYPnHLgcsCclUgGKs0FiAkkDLfcIO+dxbDStWN
pqCO5HvnMXyTCFtRkais9rHvXcRwU/MdmuMUGwKm
MVz3FQauETTyArgBiVgQ6xD97uBDPIXnSmvMbYe+
j2FdUz/AKqi43iGdXcbg7ul7pyPfO1l9/vn1S7a+
+XUFczhPXL1GmJcKjhDXnm14UmMEfx3+hpbE5kVh
Km5KNOHAgUQ7IGzJIAa2YDHtY5Z2O3fGaNiAPRPz
spV3Gc2DsKEr2fQ8Q+kqFe7+FLitqIehsVo0L4Si
aDg4stcL25JKQNJpqUk3L3U4TaL+fxb1wiemH4M5
3LKeMiaKs/i4ZrdsBs8Qc5NEVoTsrRwsFthZHBzy
kZ8Ze1Lq/hPn6V9fZt9bLnwv3SpdHyZqHvSBMZkK
oEZbqmIeNMrYgJgDuTHNrP+u3GSFF0mSUKm4pnDU
JvrQg5TU4m9Ls8FBqwczD8YXAbW/otU0CbrJngc1
Bv0jB9dDV6UI+ga79Wy5SEePWRZp80o/FbJpLdh9
Q5lMu6H3FgDVpKXtutuCs+hspyN3Q7egBvSC/wE=
';
eval(gzinflate(base64_decode(&$source)));
unset($source);
?>