Best Blackhat Forum

Full Version: NEW [GET] Sahifa 3.1.1
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Pages: 1 2 3 4
Sahifa - Responsive WordPress News,Magazine,Blog
Version 3.1.1 – Updated: 2 June 2013

[Image: 01_preview1.__large_preview.png]
[Image: sahifa-fatured3.jpg]
=Version 3.1.1 - 02-06-2013 ====================================
- Improved: Form elements styles.
- Improved: Slider Typography options .
- Improved: Site title and tagline typography options.
- Fixed: Sidebar Slider position.
- Fixed: Timeline page comments bug.
- And other improvements and minor bug fixes.

Sales page Demo

download
go : http://bestblackhatforum.com/Thread-GET-Sahifa-3-1-1

Please Don't Forgot To Thanks and Reputation !

thanks to update
Sahifa - Responsive WordPress News,Magazine,Blog
SHA256: 8b7f3e343539fe8924345816eef53acdcb7982b318acc37c833ddc0c3fb67d8d
File name: sahifa.zip
Detection ratio: 0 / 46
Analysis date: 2013-05-23 17:25:27 UTC ( 1 minute ago )

https://www.virustotal.com/en/file/8b7f3...369329927/
What is this

// nothing to worry about! :)
$imgData = base64_decode("R0lGODlhUAAMAIAAAP8AAP///yH5BAAHAP8ALAAAAABQAAwAAAJpjI+py+0Po5y0OgAMjjv01YUZ\nOGplhWXfNa6JCLnWkXplrcBmW+s​pbwvaVr/cDyg7IoFC2KbYVC2NQ5MQ4ZNao9Ynzjl9ScNYpneb\nDULB3RP6JuPuaGfuuV4fumf8PuvqFyhYtjdoe​FgAADs=");
Timthumb is an external plugin. (so its not a malicious code injection).
You can keep this file.( OR You can delete it without problems )
base64_decode is a php function which has certain genuine uses (besides its infamous uses). Here is the code excerpt from timthumb.php which uses this function to create a .gif image using php
The Base64 string is the encoded image. Furthermore some headers are set to prevent caching.
is possible to decode this to know that contains
(05-24-2013 05:52 AM)gokturk Wrote: [ -> ]What is this

// nothing to worry about! :)
$imgData = base64_decode("R0lGODlhUAAMAIAAAP8AAP///yH5BAAHAP8ALAAAAABQAAwAAAJpjI+py+0Po5y0OgAMjjv01YUZ\nOGplhWXfNa6JCLnWkXplrcBmW+s​pbwvaVr/cDyg7IoFC2KbYVC2NQ5MQ4ZNao9Ynzjl9ScNYpneb\nDULB3RP6JuPuaGfuuV4fumf8PuvqFyhYtjdoe​FgAADs=");
9.9 times out of 10 base64_decode is malicious...

Especially since it is only ever found in pirated themes.

Up to you, but I would probably trash the whole theme =/
Believe me the file is injected. It is encoded so that no one knows what it contains. and There is a well known Timthumb exploit of which i personally was a victime.

Be careful guys and that guy should be banned.
(05-24-2013 09:15 AM)robertelo Wrote: [ -> ]Believe me the file is injected. It is encoded so that no one knows what it contains. and There is a well known Timthumb exploit of which i personally was a victime.

Be careful guys and that guy should be banned.
you're right not trusted DOWNLOAD themes.
very little reliable sharing


Edit : DONT UPLOAD THEME

[Image: KNE50Bt.png]
Pages: 1 2 3 4
Reference URL's