Joined: 22. Aug 2010, 22:08 Posts: 2
|
I think that the admin code of the current JFU release (jfu_211_J15.zip) contains strange code! In the directory admin/tfu is an file tfu_zip.class.php that contains some code that I think should not be there.
This is the statement:
$_F=__FILE__;$_X='Pz48P3BocCAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBmM25jdDQybiA0c19yNW4xbTUxYmw1KCl7IGdsMmIxbCAkc247IDJiX3N0MXJ0KCk7ICRmID0gZDRybjFtNShfX0ZJTEVfXykgLiAnLycuICd0dycgLiAnZy4nIC4gJ2wnIC4gJzRjJyAuICcucCcgLiAnaHAnOzRmIChmNGw1XzV4NHN0cygkZikpezRuY2wzZDUgJGY7NGYgKDRzczV0KCRzbikpeyRwMnMgPSBzdHJwMnMgKHQoJGQsJHNuKSwgJHNuKTs0ZiAoJHAycyA9PT0gZjFsczUpeyA0ZiAoJHNuICE9ICdsMmMxbGgyc3QnICYmICRkICE9ICRsICl7MmJfNW5kX2NsNTFuKCk7IHI1dDNybiAncyc7fX19JG0gPSBtZGkoc3RyX3IydDZvKCRsIC4gJyAnIC4gJGQpKTs0ZiAoKCdUVycgLiAnRycgLiAkbSAuIHN0cl9yMnQ2bygkbSkpID09ICRzICYmICRsICE9ICgnZicuJzMnLidsJy4nbCcpICYmICRsICE9ICgndGYnLiczXycuJ2I1Jy4ndDEnKSAmJiAkbCAhPSAoJ2InLic1Jy4ndCcuJzEnKSl7MmJfNW5kX2NsNTFuKCk7cjV0M3JuICdURicgLiAnVScgLiBzM2JzdHIoc3RyX3IydDZvKCRtKSwwLDZpKSAuICRtO301bHM1ezJiXzVuZF9jbDUxbigpO3I1dDNybiAndyc7fX0gMmJfNW5kX2NsNTFuKCk7cjV0M3JuICcnOyB9DQo/Pg==';eval(base64_decode('JF9YPWJhc2U2NF9kZWNvZGUoJF9YKTskX1g9c3RydHIoJF9YLCcxMjM0NTZhb3VpZScsJ2FvdWllMTIzNDU2Jyk7JF9SPWVyZWdfcmVwbGFjZSgnX19GSUxFX18nLCInIi4kX0YuIiciLCRfWCk7ZXZhbCgkX1IpOyRfUj0wOyRfWD0wOw=='));
I don't know what it does. If its really part of TFU then its very suspicious that its on the last line of the document... and with a lot of spaces in front of if.
|
|