You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

未知PHP混淆技术求助:类动态属性赋值逻辑解析疑问

Understanding Obfuscated PHP Dynamic Property Logic

Let me walk you through exactly what's going on here—this is a classic trick in obfuscated PHP code, so your confusion makes total sense!

Key Breakdowns

1. Why $x1528 isn't null when assigning x21a9

You start with public $x1528 = null;, but in the __construct() method, the code replaces that initial null with an empty StdClass object via something like:

$this->x1528 = new \StdClass();

StdClass is PHP's generic empty class, built specifically to let you add properties on the fly. So by the time $this->x1528->x21a9 = "getSingleton"; runs, $x1528 is a valid object, not null.

2. What x21a9 is (and why you can't find a prior reference)

x21a9 is a dynamically created property of the StdClass object stored in $x1528. Unlike regular class properties that need upfront declaration, StdClass lets you assign any property name at runtime—no prior definition required.

Obfuscators rely on this because:

  • Randomized property names (like x21a9, x1528) make the code harder to read and reverse-engineer.
  • It hides the real purpose of the property: here, it's storing the string "getSingleton", which is almost certainly a method name that will be called later in the obfuscated code.

3. What this pattern is usually used for

Behind the messy naming, this is almost certainly setting up a delayed method call. For example, the code might eventually execute something like (in obfuscated form):

// Hypothetical后续逻辑
$targetInstance = SomeObfuscatedClass::x9876();
call_user_func([$targetInstance, $this->x1528->x21a9]);
// Which translates to calling $targetInstance->getSingleton();

By storing the method name in a dynamic, randomly named property, the obfuscator avoids having plaintext method names visible, making it harder to trace the code's actual behavior.

4. Quick note on PHP versions

If you're testing this on PHP 8.2 or newer, dynamic properties are disabled by default. Obfuscated code will usually either target older PHP versions or include the #[AllowDynamicProperties] attribute on the class to bypass this restriction.

内容的提问来源于stack exchange,提问作者Quentin Le Caignec

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 04:30:03